11-24-2023 04:13 AM - edited 11-24-2023 04:15 AM
Hi All,
We have 5 SSIDs configured on APs and WLC. All of our end users can only access to one, but can't access to the other 4.
Those 4 can't be connected are using SAML authentication.
Part of the logs are attached.(MAC-address has been deleted).
Could any one suggested for how to solve it please?
Thanks
Solved! Go to Solution.
11-24-2023 04:40 AM
- Have a checkup of the 5500 controller configuration according to https://community.cisco.com/t5/networking-knowledge-base/show-the-complete-configuration-without-breaks-pauses-on-cisco/ta-p/3115114#toc-hId-1039672820 (procedure on top of page). Have the output analyzed with Wireless Config Analyzer
- For clients not able to connect use client debugging according to https://www.cisco.com/c/en/us/support/docs/wireless/aironet-1200-series/100260-wlc-debug-client.html , you can have client debugs analyzed with https://cway.cisco.com/tools/WirelessDebugAnalyzer/
- As per https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html , use the recommended release corresponding to your controller model ,
M.
11-24-2023 04:40 AM
- Have a checkup of the 5500 controller configuration according to https://community.cisco.com/t5/networking-knowledge-base/show-the-complete-configuration-without-breaks-pauses-on-cisco/ta-p/3115114#toc-hId-1039672820 (procedure on top of page). Have the output analyzed with Wireless Config Analyzer
- For clients not able to connect use client debugging according to https://www.cisco.com/c/en/us/support/docs/wireless/aironet-1200-series/100260-wlc-debug-client.html , you can have client debugs analyzed with https://cway.cisco.com/tools/WirelessDebugAnalyzer/
- As per https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html , use the recommended release corresponding to your controller model ,
M.
11-24-2023 09:50 AM - edited 11-24-2023 09:55 AM
What model of WLC are you using? 5500 is not a model - that could mean 5508 (old) or 5520 (newer).
What version of AireOS is it running? As Marce said you should be using latest available which supports your APs and WLC - that's probably 8.5.182.11 (download link below) or 8.10.190.0
If SAML is the problem then presume that means you're using web auth?
So the users can connect but not complete web auth - is that right?
There are a variety of different ways you can use web auth so without more detail on the WLAN setup, the auth for the WLAN etc hard to say any more.
Looking at those logs maybe you're using 802.1x? In which case check the radius server logs too.
Do a debug on a client MAC while they try to connect and see what that shows. You can use the debug analyzer (link below) to sanitise and present the debug logs.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide