cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2836
Views
10
Helpful
3
Replies

9800-CL Webauth issue "No Response from Client"

DW96
Level 1
Level 1

Hi All, Hoping this is something simple and it's just me doing something dumb. I'm setting up a Flexconnect environment with 3 SSID's

Corporate Network - Local Switching and Local Authentication using an external Windows NPS server

Mobile/BYOD Network - Same configuration as above

Guest Network - Local Switching and Central Authentication using the WLCs WebAuth portal

The Corporate and Mobile networks are fine and working as intended however I'm running into some issues with the Guest network. I have a AAA Method List of "Type - Login" & "Group Type - Local". I have a Guest User created on the WLC but when trying to use this to authenticate against the Guest Network I'm just getting Authentication failed on the client device and in the WLC logs the failure reason I'm seeing is "No Response from Client".

Any advice would be greatly appreciated.

1 Accepted Solution

Accepted Solutions

Mark Elsen
Hall of Fame
Hall of Fame

 

 -  Review your   9800-CL   configuration with the CLI command : show  tech   wireless , have the output analyzed by  https://cway.cisco.com/tools/WirelessAnalyzer/  , please note do not use classical show tech-support (short version) , use the command denoted in green for Wireless Analyzer.               Checkout all advisories!

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

View solution in original post

3 Replies 3

Mark Elsen
Hall of Fame
Hall of Fame

 

 -  Review your   9800-CL   configuration with the CLI command : show  tech   wireless , have the output analyzed by  https://cway.cisco.com/tools/WirelessAnalyzer/  , please note do not use classical show tech-support (short version) , use the command denoted in green for Wireless Analyzer.               Checkout all advisories!

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

Thanks for this, didn't realise this tool actually existed. Turns out I was missing the "aaa authentication network default local" command, once I got this configured it started working as intended.

Thanks for your help

Rich R
VIP
VIP

What version of software are you using?

You should use a TAC recommended release ideally.  See link below.

And run radioactive trace and/or get a packet capture to see what's actually happening.

Are you using a public certificate matching the DNS FQDN for your portal?

Review Cisco Networking for a $25 gift card