cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1395
Views
2
Helpful
12
Replies

Cisco WLC 9800 filter mac Authorization not working

Leo TI
Level 1
Level 1

hi

I'm setting up a wireless network with mac filtering, but I get this error.

 

Dec 4 21:08:42.786: %SESSION_MGR-5-FAIL: Chassis 1 R0/0: wncd: Authorization failed or unapplied for client (b894.e7a0.8677) on Interface capwap_9000000d AuditSessionID 320A16AC000081229380F15D. Failure reason: Authc fail. Authc failure reason: AAA Server Down.

 

LeoTI_1-1733347363748.png

LeoTI_2-1733347525484.pngLeoTI_3-1733347541873.pngLeoTI_4-1733347545317.png

LeoTI_5-1733347617506.png

LeoTI_6-1733347666968.png

 

 

 

 

 

 

 

1 Accepted Solution

Accepted Solutions

You've made the common mistake of entering your MAC address incorrectly!
https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213922-configure-mac-authentication-ssid-on-cis.html#toc-hId-228841407

The MAC addresses must be entered all in lower case and with NO punctuation.
No dots (.), no dashes (-), no colons (:).
Otherwise it will never match.

View solution in original post

12 Replies 12

@Leo TI 

Seems like the WLC is not communicating with your Radius server "AAA Server Down."

I'm not using radius server it's an open network that has mac filtering

But the WLC is trying to reach the radius. Double check the configuration then.

One thing I can not see is do you have aaa-override enabled on the SSID?

https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213922-configure-mac-authentication-ssid-on-cis.html#toc-hId-228841407 

*****Help out other by using the rating system and marking answered questions as "Answered"*****
*** Please rate helpful posts ***

I enabled it but still have the same problem

LeoTI_0-1733350615824.png

LeoTI_1-1733350675685.png

 

 

I saw you have authorization list configured but you did not select here.

FlavioMiranda_0-1733350957885.png

 

FlavioMiranda_0-1733350857059.png

 

But there I see the lists of dot1x groups, which in the case of an open network with mac filtering would not be necessary.

You've made the common mistake of entering your MAC address incorrectly!
https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213922-configure-mac-authentication-ssid-on-cis.html#toc-hId-228841407

The MAC addresses must be entered all in lower case and with NO punctuation.
No dots (.), no dashes (-), no colons (:).
Otherwise it will never match.

 

Thank you very much, that was it

LeoTI_0-1733509550816.png

 

Thanks 

 

MHM

Review Cisco Networking for a $25 gift card