cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2880
Views
3
Helpful
5
Replies

Cisco 9800 and Microsoft NPS dot1x

CSCO11177789
Level 1
Level 1

Hi,

We are trying to upgrade environment wlc5508 to 9800. On dot1x related wlans we have issues. we use microsoft nps for radius. Regarding to 9800 AAA document we made configurations but although radius server seems up (form cli "sh aaa servers" command) there is no any request logs on 9800 and nps side when client try to connect. so tried to automate-tester command under nps definition and see logs..but nothing more. Our auth method is peap/mschapv2 with active directory user.

Is there any guide about this ? What do you suggest ?

Thanks

 

5 Replies 5

JPavonM
VIP
VIP

Apart from adding your new C9800s as RADIUS clients, if you are not filtering by NAS Identifier in your NPS policy, and if so, and that NAS identifier includes the WLC name, look at that. Otherwise, it should work fine, nothing special to C9800.

On the WLC side, the standard configuration to enable dot1x should work.

https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213919-configure-802-1x-authentication-on-catal.html

https://www.labminutes.com/wl0054_9800_wlc_l2_security_wpa2_dot1x_1

 

Hi,

I read the docs and watch the video but still no progressing between nps and 9800. meanwhile i captured debug from client when trying to connect. i couldnt find out what am i missing..please find attached file

best regards

Hi

 "wlan_profile Not Found : Device information attributes not populated"

 I would take a look on why this message is happening.

https://www.wwt.com/article/demystifying-the-new-cisco-catalyst-9800

this link might help you.

And don't forget to use https://cway.cisco.com/wireless-debug-analyzer/
You can use the radioactive trace output from 9800 in the analyzer.

As @Flavio Miranda says that wlan_profile Not Found is probably something to look at - config error or something your radius is returning.  Do the radioactive trace and then run it through debug analyzer.

Thank you, i'll try...in fact we make configuration on microsoft nps server as same as working cisco wlc 5500 - nps integration

Review Cisco Networking for a $25 gift card