08-28-2023 01:40 AM
Hi, I am trying to access SSID through AD authentication with C9800 WLC, Active Directory, C9115.
Each equipment version
C9800: 17.3.3 (vWLC)
AD: This is an AD created on a Windows server, and there is no problem with AD itself because it is currently being used in the office.
C9115AXI: It is registered with vWLC and transmits even the wireless signal well.
1. By enabling WebAuth in the LDAP settings and WLAN settings in the AAA configuration, when connecting to SSID, it is redirected to the virtual IP for WebAuth, and the ID/PW input page seems to work well.
2. However, even with the AD Admin account, Authentication Failed is displayed.
How can I proceed with troubleshooting?
Are there any problems with WLC's certificate?
Below are the documents currently referenced.
how to set up a WLAN with 802.1x security on C9800 Series Wireless Controllers - Part 4
*****I proceeded while looking at the documentation related to the certificate, but could not proceed below the Import Device Cert.. part.
Since this is a test environment, there is no equipment certificate from CA.
Solved! Go to Solution.
08-28-2023 02:41 AM
- You have 4 WLC errors from WirelessAnalyzer for the file you attached, these should at least be corrected , if you make corrections then run WirelessAnalyzer again and make sure that they have disappeared ,
M.
08-28-2023 01:54 AM
>...Since this is a test environment, there is no equipment certificate from CA.
- A good placed to start is to have a global checkup of the current configuration on the C9800 (vWLC ) ; for that use the CLI command
show tech wireless
Feed the output into :
https://cway.cisco.com/wireless-config-analyzer/
M.
08-28-2023 02:20 AM
Hi marce1000.
I checked the current overall settings on the website you informed me of, and confirmed that several alerts are coming out.
However, even though most of the alerts have been taken care of, the same problem is still showing.
I have a question, do I have to upload CA's certificate to WLC for WebAuth using LDAP?
This is because "Certificate unknown" was shown in what appears to be a packet to enter ID/PW and receive authentication when capturing packets.
I don't think the WLC made it mandatory to get a certificate from a CA to authenticate via the company's AD.
I attached a show tech wireless.txt
Thanks.
08-28-2023 02:41 AM
- You have 4 WLC errors from WirelessAnalyzer for the file you attached, these should at least be corrected , if you make corrections then run WirelessAnalyzer again and make sure that they have disappeared ,
M.
08-29-2023 10:01 PM
Hi marce1000
I've currently found an issue with AD integration.
Through WLC's built-in packet capture tool, we confirmed that the invalidCredentials packet came out in response to bindRequest.
The strange thing is that AD information is received under the same conditions through the LDAP client program.
Are the settings incorrect?
thank you.
+ The base-DN value was applied to WLC the same as the value verified in the LDAP program. ( Using LDAP Admin program)
08-28-2023 06:32 AM
And do yourself a favour - update to 17.6.5 or 17.9.4.
If, for some reason, you feel a need to stay on 17.3 then at least update to 17.3.7 but remember 17.3 is approaching end of life so you should already be planning update to 17.9 regardless.
08-29-2023 10:34 PM
Hi Rich R
I've currently found an issue with AD integration.
Through WLC's built-in packet capture tool, we confirmed that the invalidCredentials packet came out in response to bindRequest.
The strange thing is that AD information is received under the same conditions through the LDAP client program.
Are the settings incorrect?
thank you.
+ The base-DN value was applied to WLC the same as the value verified in the LDAP program. ( Using LDAP Admin program)
08-30-2023 06:05 AM
> The strange thing is that AD information is received under the same conditions through the LDAP client program.
Well if they were indeed the same then the result would be the same so there must be a difference
> Are the settings incorrect?
I've never used LDAP integration myself so can't offer any extra advice on this. You'll have to look through all available info on community etc to see what gotchas others have encountered. And make sure your software is up to date just in case you're hitting a known bug in the older software.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide