09-14-2022 07:25 PM
Hi all,
I had some questions regarding on my FlexConnect C9105AXI-K does not able to perform local authentication when remote office was disconnected from EWC C9105AXI-K in HQ. While I had checked on the policy profile and found that the Central Authentication under "WLAN Switching Policy" was not able to disable. I am facing difficulties to connect client to the wireless SSID when disconnection between remote office and HQ.
Kindly need some advice that is there any CLI command that I can use to disable to central authentication or does my EWC C9105AXI-K support local authentication?
Thank you for your kind assistance.
09-15-2022 03:19 AM
- Check if this thread can contain hints : https://community.cisco.com/t5/wireless/cisco-wlc-flex-connect-ssid-radius-authentication-when-wlc-is/td-p/3792394
M.
09-17-2022 04:38 AM - edited 09-17-2022 04:40 AM
Not sure if it is supported - flex feature matrix suggests that it should be.
There is definitely a problem with that toggle on the web interface - I'd say it's a bug. If it wasn't supported that should not be shown at all.
But you can change it on CLI in the policy profile (the profile must be disabled/shutdown before you can change it):
C9120AXI-WLC#sh run | sec Test
wireless profile policy Test
no central association
no central authentication
no central dhcp
no central switching
description "Test local auth"
dhcp-tlv-caching
http-tlv-caching
no shutdown
C9120AXI-WLC#
You'll have to try it and test it ...
09-21-2022 12:10 AM
Hi rrudling,
Thank you for your advice and I am now able to disable the "central authentication" in the policy profile but after disabled I am still facing some issue to connect my handheld to the wireless network when AP in flex mode (disconnect from controller).
Kindly need your expertise to advice for any possible mistake or misconfiguration.
09-21-2022 12:46 AM
09-21-2022 12:49 AM
Besides, I had attached some configuration under the profile
wireless profile policy "Test"
no central association
no central authentication
no central dhcp
no central switching
description "Test"
no shutdown
wireless tag policy "Test"
description "Test"
wlan "Test Wireless SSID" policy "Test"
policy-tag "Test"
09-21-2022 01:56 AM
My only other suggestion is upgrade to 17.6.4 and if still not working then open a TAC case. It might be that they decided not to support "local auth" since the EWC is designed to sit on the same LAN/VLAN as the rest of the APs so it wouldn't really make much sense. EWC is not designed to work remotely (even though it does) so I suspect the way you're using it is not supported.
09-21-2022 12:32 AM
What type of authentication are you using?
What version of software are you using?
Do you have tag persistence enabled?
10-05-2022 02:51 AM
Hi rrudling,
The authentication was using WPA2+PSK (AES) and the tag persistence was enabled in the wireless controller.
The current version using was 17.6.1b and found that there was some bug on this version that will be resolved in 17.6.2 onwards as below. Unfortunately I am not able to access/view the bug ID.
CSCvy41272: Cisco IOS XE 17.6: 11k on FlexConnect mode is not working as expected.
I had tried to configure the "no central authentication", "no central association", "no central dhcp" and "no central switching" but still not working, kindly need some expertise advice on this.
10-05-2022 06:09 AM
CSCvy41272 is hidden for some reason so only TAC can give you the detail.
So you can:
1. Try upgrading to 17.6.4 or 17.9.1
2. Check your config on https://cway.cisco.com/wireless-config-analyzer/ using output of "show tech wireless"
3. Contact Cisco TAC
11-12-2022 01:32 AM
Managed to resolve the issue by "enabled" the fast transition instead of "adaptive enabled" as default.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide