cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
446
Views
1
Helpful
2
Replies

End users can't connect to SSIDs

Coco Liu
Level 1
Level 1

Hi All,

We have 5 SSIDs configured on APs and WLC. All of our end users can only access to one, but can't access to the other 4.

Those 4 can't be connected are using SAML authentication.

Part of the logs are attached.(MAC-address has been deleted).

Could any one suggested for how to solve it please?

 

Thanks

 

 

 

1 Accepted Solution

Accepted Solutions

marce1000
VIP
VIP

 

 - Have a checkup of the 5500 controller configuration according to https://community.cisco.com/t5/networking-knowledge-base/show-the-complete-configuration-without-breaks-pauses-on-cisco/ta-p/3115114#toc-hId-1039672820 (procedure on top of page).  Have the output analyzed with Wireless Config Analyzer

 - For clients not able to connect use client debugging according to https://www.cisco.com/c/en/us/support/docs/wireless/aironet-1200-series/100260-wlc-debug-client.html , you can have client debugs analyzed with https://cway.cisco.com/tools/WirelessDebugAnalyzer/

 - As per https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html , use the recommended release corresponding to your controller model  , 

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

View solution in original post

2 Replies 2

marce1000
VIP
VIP

 

 - Have a checkup of the 5500 controller configuration according to https://community.cisco.com/t5/networking-knowledge-base/show-the-complete-configuration-without-breaks-pauses-on-cisco/ta-p/3115114#toc-hId-1039672820 (procedure on top of page).  Have the output analyzed with Wireless Config Analyzer

 - For clients not able to connect use client debugging according to https://www.cisco.com/c/en/us/support/docs/wireless/aironet-1200-series/100260-wlc-debug-client.html , you can have client debugs analyzed with https://cway.cisco.com/tools/WirelessDebugAnalyzer/

 - As per https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html , use the recommended release corresponding to your controller model  , 

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Rich R
VIP
VIP

What model of WLC are you using?  5500 is not a model - that could mean 5508 (old) or 5520 (newer).
What version of AireOS is it running? As Marce said you should be using latest available which supports your APs and WLC - that's probably 8.5.182.11 (download link below) or 8.10.190.0

If SAML is the problem then presume that means you're using web auth?
So the users can connect but not complete web auth - is that right?
There are a variety of different ways you can use web auth so without more detail on the WLAN setup, the auth for the WLAN etc hard to say any more.
Looking at those logs maybe you're using 802.1x?  In which case check the radius server logs too.
Do a debug on a client MAC while they try to connect and see what that shows.  You can use the debug analyzer (link below) to sanitise and present the debug logs.

Review Cisco Networking for a $25 gift card