cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1053
Views
6
Helpful
12
Replies

Cisco ISE authorization

surazb
Level 1
Level 1

Hi Experts, 

I have setup where Clients connected on WLC-9800 SSID should get Vlans assignment from Cisco ISE authorization Profile, But it still clients gets IP from Access Policy configured on WLC-9800

AAA is configured on WLC with Mac Filtering and authorization list
AAA override and NAC state is selected
ISE is configured with authorization profile and with authorization plicy
Client MAC is added is Cisco ISE identity group
Strange this is ISE logs says that authorization success with correct authorization policy but actually VLans are not pushed to client 

Can you guys please help me where i went wrong, If needed i will share config snaps 
Thanks Guys

1 Accepted Solution

Accepted Solutions

surazb
Level 1
Level 1

Hi Guys, 
Thanks all for your support 
Issue got resolved, actually there is no correct flex profile colled under site tag, after putting correct flex profile it works as expected 
Thanks guys


View solution in original post

12 Replies 12

marce1000
Hall of Fame
Hall of Fame

 

  - Start with a sanity check of the  WLC-9800 configuration using the CLI command
     show tech wireless and feed the output from that into Wireless Config Analyzer
          (Use the full command denoted in green, it does not work with a simple show tech-support )

    M



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

In wlc 9800 do you enable CoA and set password?

MHM

Yes, CoA is enabled with password

Point to check

1- aaa override must enable 

2- if you use dyanmic vlan then you need to select vlan all under wlan profile

MHM

1 - Yes, AAA override is enable
2- I want ISE to push vlans through Authorization Profile so
locally configured vlan under wlan will does not matter

You want to make ISE dynamic assign vlan to wlan

So it matters 

Check below link

https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/217043-configure-dynamic-vlan-assignment-with-c.html

MHM

Rich R
VIP
VIP

- What version of software are you using?

- Have you run a Radioactive Trace on the client MAC to confirm the WLC is receiving the AAA VLAN override from ISE?
Use Debug Analyzer (link below) to clean up the RA trace output.

1 - WLC Version - 17.12.4
      Switch 3750 - 15.2.(4).E10

2 - Nope, But i will run radioactive test and check the logs 

Thanks guys for help

 

 - @surazb  Execute the WirelessAnalyzer procedure from my initial reply also. Consider that mandatory ,

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

1 - WLC version - 17.12.4
Switch 3750 - 15.2.(4).E10

2. Nope, i will do Radioactive trace and observe logs

Thanks for help guys

One more important thing in addition to the suggestion been made by other experts - the vlan you would like to push via AAA override need to be present in the WLC switchport - if it is local mode AP/central switching or should be present in the AP switchport - if it is flex mode AP/local switching.

surazb
Level 1
Level 1

Hi Guys, 
Thanks all for your support 
Issue got resolved, actually there is no correct flex profile colled under site tag, after putting correct flex profile it works as expected 
Thanks guys


Review Cisco Networking for a $25 gift card