01-30-2024 11:30 PM
hello
I have a question about the ap log.
I'm trying to complete the ap set and connect, but this log has occurred and I can't connect.
log
"wncd:Authentication failed for client (f0f5.6444.93d8) with reason (AAA Server Down) on Interface capwap_90000003 AuditSessionID E70613AC00000016116C0DD1 *MAR 24 11:21:46.851 KST: %SESSION_MGR-5-FAIL: Chassis 1 R0/0: wncd: Authorization failed or unapplied for client (f0f5.6444.93d8) on interface capwap_90000003 AuditSessionID E76013AC00000016116C0DD1. Failure resaon: Authc fail. Authc Failure reasion:AAA Server Down."
What does this mean and what do I have to do to solve it?
Solved! Go to Solution.
01-31-2024 05:16 AM
Failure resaon: Authc fail. Authc Failure reasion:AAA Server Down
Can you ping your AAA server from WLC?
This is a good blogpost to follow to configure 802.1x on 9800 WLC. https://lihaifeng.net/?p=699
You can also get "show tech wireless" output and get it analyzed by https://cway.cisco.com/
Jagan Chowdam
/**Please rate helpful responses**/
01-30-2024 11:54 PM
- What authorization schemes are you using for APs to be allowed on the controller ? Is the specific AP allowed in those ?
M.
01-31-2024 12:53 AM
Process authentication with the Redius server
example
"radius server 000.000.000.000
address ipv4 000.000.000.000 auth-port 1645 acct-prot 1646
key 7 00000000000000000000000000000 "
01-31-2024 05:46 AM
This AP is autonomous not control via WLC ?
MHM
01-31-2024 05:16 AM
Failure resaon: Authc fail. Authc Failure reasion:AAA Server Down
Can you ping your AAA server from WLC?
This is a good blogpost to follow to configure 802.1x on 9800 WLC. https://lihaifeng.net/?p=699
You can also get "show tech wireless" output and get it analyzed by https://cway.cisco.com/
Jagan Chowdam
/**Please rate helpful responses**/
01-31-2024 08:23 AM - edited 01-31-2024 08:23 AM
Simply put that means the WLC could not contact your radius server. Possible reasons:
- Incorrect routing
- Wrong shared key
- Wrong ports - some radius run on 1812/1813 and some on 1645/1646
- Firewall/ACL blocking connection to radius
Check "show aaa servers" and use debug aaa to work out what the problem is. Use packet capture on the WLC and on the radius server to confirm that radius packets are getting sent and received in both directions.
02-01-2024 12:27 AM
So what was the problem you found then @heyjunsun ?
If you share your solution here it may help other people with the same problem.
02-01-2024 12:59 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide