cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1274
Views
0
Helpful
5
Replies

C9800-WLAN MAC filter use wrong Radius Server

Bill lo
Level 1
Level 1

Hi  community

 

it seem a software BUG .....,

Has anyone had the same experience?

 

Environment

WLC modle :9800-L-C

Version : 17.3.2a

Imapct device : Laptop (with  OS window10)   x  3 

 

SSID Details

WLANs ProfileSecurityRadius Server
300302802.1x/Mac Filterx.x.x.59
300309802.1x/Mac Filterx.x.x.159

 

 

Situation

After testing the ISE-Posture function ( use SSID:300309), The client (three staff) cannot go back use 300302;

the Client status is stuck in "Associating" ,and used  wrong Radius-Server x.x.x.159 (the correct one is x.x.x.59)

as shown below:

20210812(2).png

 

we have tried:

   1/ Trun down/up the Wlan profile 

   2/  Restart the AP

   3/ Client PC reboot

not work, still can't use the SSID back , But others endpoint used the  SSID:300302 well,

Only the three devices that have connect the testing SSID:300309  imapcted.

 

Finally we reboot the WLC , and the Devic  connect   the SSID:300302 success

 

best regards

Bill

 

5 Replies 5

Arshad Safrulla
VIP Alumni
VIP Alumni

Can you post a Radio Active trac while the issue is observed?

FYI

Arshad Safrulla
VIP Alumni
VIP Alumni

Deleting the client, reason: 166, CO_CLIENT_DELETE_REASON_MACAUTH_CONNECT_TIMEOUT, Client state S_CO_MACAUTH_IN_PROGRESS

 

Is the MAC auth done locally in the WLC or by ISE, Is it possible to remove MAC Auth to test with .1x only. Also what the IOS-XE code running?

Hi Arshadsaf

 

1. MAC auth done is done in  ISE ( But for WLC GUI info( Client status-general ) , it's taken wrong Radius Server .

      ex:  SSID 300302 use ISE01 ,   SSID 300309 use ISE02

2 After WLC reboot , the the problem is solved ( the Deive connect the SSID 300302 success;

   Next time when the issue happen, we could make a try :remove MAC Auth to test with .1x only

3 .the Code :17.3.2a

 

 

thx

Bill

Rich R
VIP
VIP

That definitely sounds like a bug. You should be talking to TAC.

Review Cisco Networking for a $25 gift card