05-03-2025 07:08 AM
Hi Experts,
I have setup where Clients connected on WLC-9800 SSID should get Vlans assignment from Cisco ISE authorization Profile, But it still clients gets IP from Access Policy configured on WLC-9800
AAA is configured on WLC with Mac Filtering and authorization list
AAA override and NAC state is selected
ISE is configured with authorization profile and with authorization plicy
Client MAC is added is Cisco ISE identity group
Strange this is ISE logs says that authorization success with correct authorization policy but actually VLans are not pushed to client
Can you guys please help me where i went wrong, If needed i will share config snaps
Thanks Guys
Solved! Go to Solution.
05-12-2025 09:17 AM
Hi Guys,
Thanks all for your support
Issue got resolved, actually there is no correct flex profile colled under site tag, after putting correct flex profile it works as expected
Thanks guys
05-03-2025 07:23 AM
- Start with a sanity check of the WLC-9800 configuration using the CLI command
show tech wireless and feed the output from that into Wireless Config Analyzer
(Use the full command denoted in green, it does not work with a simple show tech-support )
M
05-03-2025 07:25 AM
In wlc 9800 do you enable CoA and set password?
MHM
05-04-2025 05:26 AM
Yes, CoA is enabled with password
05-04-2025 05:35 AM
Point to check
1- aaa override must enable
2- if you use dyanmic vlan then you need to select vlan all under wlan profile
MHM
05-04-2025 06:43 AM
05-04-2025 07:17 AM
You want to make ISE dynamic assign vlan to wlan
So it matters
Check below link
MHM
05-04-2025 06:14 AM - edited 05-04-2025 06:14 AM
- What version of software are you using?
- Have you run a Radioactive Trace on the client MAC to confirm the WLC is receiving the AAA VLAN override from ISE?
Use Debug Analyzer (link below) to clean up the RA trace output.
05-04-2025 06:47 AM
1 - WLC Version - 17.12.4
Switch 3750 - 15.2.(4).E10
2 - Nope, But i will run radioactive test and check the logs
Thanks guys for help
05-04-2025 06:55 AM
- @surazb Execute the WirelessAnalyzer procedure from my initial reply also. Consider that mandatory ,
M.
05-04-2025 07:44 AM
05-04-2025 09:37 AM
One more important thing in addition to the suggestion been made by other experts - the vlan you would like to push via AAA override need to be present in the WLC switchport - if it is local mode AP/central switching or should be present in the AP switchport - if it is flex mode AP/local switching.
05-12-2025 09:17 AM
Hi Guys,
Thanks all for your support
Issue got resolved, actually there is no correct flex profile colled under site tag, after putting correct flex profile it works as expected
Thanks guys
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide