12-12-2024 11:34 PM
Hello,
I'd like to ask if anyone knows how to enable message-authenticator attribute on Cisco WLC 3503 with 8.5 firmware version.
Thanks
12-12-2024 11:37 PM
Sorry for the typo, is 3504
12-12-2024 11:44 PM
I think you can't' so better from that is disable message-auth check in ISE
MHM
12-12-2024 11:48 PM
Hello,
Thanks for the reply, this has to do with the firmware version ? Have you found on Cisco official doc this ?
12-13-2024 12:02 AM
But this WLC is old and I dont think Cisco update it ver. Anymore.
So as I mention try disable option in ISE.
MHM
12-13-2024 12:12 AM
Hello,
I've enabled on Cisco ISE cause in one of our sites we have fortinet equipment (fortiswitches,FortiAP) and after upgrading fortinet firewall to 7.2.10 it requires from ISE to have this option enabled otherwise the connection between cisco ISE and Fortinet Firewall breaks. I've enabled it for eap-tls dot1x and everything works fine. Yesterday i've enabled it for mab also and i keep see logs on ISE rejecting MAB only from that specific wlc.
12-13-2024 12:22 AM - edited 12-13-2024 01:35 AM
The solution in ISE'
Make forti use defualt network access
And you config device called it WLC-3000 and edit it allow protocol and disable message-auth
MHM
12-13-2024 12:24 AM
Hello,
Sorry i do not get what you mean above, could you please elaborate more ?
12-13-2024 12:50 AM - edited 12-13-2024 12:53 AM
12-13-2024 01:14 AM
Hello,
Forti is already using default device, i don't get the meaning of your print screen you just show a custom name with all protocols allowed. How is this related to wlc ?
12-13-2024 01:37 AM
any device need message-auth will use default network access -> allow protocol with message-auth enable
WLC will use custom network access -> allow protocol with message-auth disable
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide