11-18-2021 09:45 AM
9800 CL having mac filtering SSID, where its working with local site but not working with remote location.
user mac address shows web-auth pending on the WLC. its says connected with no internet.
this issue only with remote locations.
11-20-2021 06:19 AM
- What version of IOS-XE?
- How is WLAN configured, AP in flex or local mode, central/local switching, what authentication?
We found that with the MAC filtering, authentication handled via radius the device association would timeout before getting radius access accept.
Cisco TAC advised this is not configurable (this was on AireOS - haven't checked IOS-XE) and the recommended workaround (which we've used ever since) is to make sure the AP is always in flex mode. That changes the built-in hard coded timers and eliminates the problem.
So if your problem sounds similar then make sure the AP is in flex mode.
11-20-2021 07:24 AM
WLC version is 16.12.5
AP were in Flexmode, locally switched profile with central authentication.
upon checking the WLC logs radius accept is success , L2 webuth authentication is successfully, L3 web authentication intiated, Ip is learning on the user machine as well.
11-21-2021 04:34 PM
Well I'd recommend getting onto a current release for a start: https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214749-tac-recommended-ios-xe-builds-for-wirele.html#anc7
16.12 will be end fo software maintenance in a few months so you should be thinking about that anyway.
If you still see problems then TAC case.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide