cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
798
Views
20
Helpful
4
Replies

After power outage, WLC not correctly transacting with RADIUS server.

After power outage WLC AIR-CT5508-100-K9 is not correctly communicating with RADIUS server. IP communication between 2 devices is intact. Cisco APs are up but clients failing communication because of authentication. Aruba APs connected to same WLC are up and servicing wireless clients fine.

1. Why is WLC not correctly communicating with RADIUS server?

2. How can I make this connection healthy again?

Thank you.

1 Accepted Solution

Accepted Solutions

Thank you all for your input. I appreciate it indeed.

The problem is solved...

The WLC's were authenticating through an AD network policy server to a radius server. After the power outage it is unknown why the AD radius server authentication is failing.

The solution was to eliminate the authentication path through the AD network policy server, and instead connect the WLC’s directly to RADIUS servers.

Thank you all.

 

View solution in original post

4 Replies 4

Hi

 "Aruba APs connected to same WLC are up and servicing wireless clients fine." 

Tell me  more about it please. 

 

I can try to guess here what might be happening but will not help you. We need logs to help you. Connect to the WLC, choose one failing client and issue "debug client 'mac address' . Save the output while trying to connect. Then, share the result.

 

And share the output of "show radius auth statistics " from the WLC.

WLC loss client auth data but radius still have it?

check this point 

Rich R
VIP
VIP

Was the WLC config saved before the power failure?  Maybe it's using the wrong radius secret for example?

Get a packet capture to see what is happening.

What do the radius server logs show?

Try to re-apply the correct secret. 

Thank you all for your input. I appreciate it indeed.

The problem is solved...

The WLC's were authenticating through an AD network policy server to a radius server. After the power outage it is unknown why the AD radius server authentication is failing.

The solution was to eliminate the authentication path through the AD network policy server, and instead connect the WLC’s directly to RADIUS servers.

Thank you all.

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card