cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1245
Views
1
Helpful
7
Replies

ap 9115 log

heyjunsun
Level 1
Level 1

hello 

I have a question about the ap log.

I'm trying to complete the ap set and connect, but this log has occurred and I can't connect.

 

log

"wncd:Authentication failed for client (f0f5.6444.93d8) with reason (AAA Server Down) on Interface capwap_90000003 AuditSessionID E70613AC00000016116C0DD1 *MAR 24 11:21:46.851 KST: %SESSION_MGR-5-FAIL: Chassis 1 R0/0: wncd: Authorization failed or unapplied for client (f0f5.6444.93d8) on interface capwap_90000003 AuditSessionID E76013AC00000016116C0DD1. Failure resaon: Authc fail. Authc Failure reasion:AAA Server Down."

What does this mean and what do I have to do to solve it? 

 

 

1 Accepted Solution

Accepted Solutions

Failure resaon: Authc fail. Authc Failure reasion:AAA Server Down

Can you ping your AAA server from WLC? 

This is a good blogpost to follow to configure 802.1x on 9800 WLC. https://lihaifeng.net/?p=699

You can also get "show tech wireless" output and get it analyzed by https://cway.cisco.com/tools/WirelessAnalyzer/  to check any configure errors.

Jagan Chowdam

/**Please rate helpful responses**/

 

View solution in original post

7 Replies 7

marce1000
Hall of Fame
Hall of Fame

 

 - What authorization schemes are you using for APs to be allowed on the controller ? Is the specific AP allowed in those ?

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Process authentication with the Redius server

example  

"radius server 000.000.000.000

address ipv4 000.000.000.000 auth-port 1645 acct-prot 1646

key 7 00000000000000000000000000000 "

Is that the answer you wanted?
 

This AP is autonomous not control via WLC ?

MHM

Failure resaon: Authc fail. Authc Failure reasion:AAA Server Down

Can you ping your AAA server from WLC? 

This is a good blogpost to follow to configure 802.1x on 9800 WLC. https://lihaifeng.net/?p=699

You can also get "show tech wireless" output and get it analyzed by https://cway.cisco.com/tools/WirelessAnalyzer/  to check any configure errors.

Jagan Chowdam

/**Please rate helpful responses**/

 

Rich R
VIP
VIP

Simply put that means the WLC could not contact your radius server. Possible reasons:
- Incorrect routing
- Wrong shared key
- Wrong ports - some radius run on 1812/1813 and some on 1645/1646
- Firewall/ACL blocking connection to radius
Check "show aaa servers" and use debug aaa to work out what the problem is.  Use packet capture on the WLC and on the radius server to confirm that radius packets are getting sent and received in both directions.

Rich R
VIP
VIP

So what was the problem you found then @heyjunsun ?
If you share your solution here it may help other people with the same problem.

https://lihaifeng.net/?p=699  

The items in this link are in order.
 
Review Cisco Networking for a $25 gift card