05-23-2022 04:19 AM
After power outage WLC AIR-CT5508-100-K9 is not correctly communicating with RADIUS server. IP communication between 2 devices is intact. Cisco APs are up but clients failing communication because of authentication. Aruba APs connected to same WLC are up and servicing wireless clients fine.
1. Why is WLC not correctly communicating with RADIUS server?
2. How can I make this connection healthy again?
Thank you.
Solved! Go to Solution.
05-23-2022 08:05 AM
Thank you all for your input. I appreciate it indeed.
The problem is solved...
The WLC's were authenticating through an AD network policy server to a radius server. After the power outage it is unknown why the AD radius server authentication is failing.
The solution was to eliminate the authentication path through the AD network policy server, and instead connect the WLC’s directly to RADIUS servers.
Thank you all.
05-23-2022 04:34 AM
Hi
"Aruba APs connected to same WLC are up and servicing wireless clients fine."
Tell me more about it please.
I can try to guess here what might be happening but will not help you. We need logs to help you. Connect to the WLC, choose one failing client and issue "debug client 'mac address' . Save the output while trying to connect. Then, share the result.
And share the output of "show radius auth statistics " from the WLC.
05-23-2022 05:07 AM - edited 05-23-2022 08:26 AM
WLC loss client auth data but radius still have it?
check this point
05-23-2022 07:13 AM
Was the WLC config saved before the power failure? Maybe it's using the wrong radius secret for example?
Get a packet capture to see what is happening.
What do the radius server logs show?
Try to re-apply the correct secret.
05-23-2022 08:05 AM
Thank you all for your input. I appreciate it indeed.
The problem is solved...
The WLC's were authenticating through an AD network policy server to a radius server. After the power outage it is unknown why the AD radius server authentication is failing.
The solution was to eliminate the authentication path through the AD network policy server, and instead connect the WLC’s directly to RADIUS servers.
Thank you all.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide