cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1394
Views
2
Helpful
4
Replies

Freeradius WLC wrong User-Password

Support ACME
Level 3
Level 3

Dear ALL,

 

I'm implement the WLC + Freeradius for MAC auth, but i found the WLC always sending the "secret" as User-Password in "User-Password" attribute, the Freeradius will show "Access-Reject", if the freeradius attribute’s Cleartext-Password to “secret”, the AAA test result is show “Access-Accept” with any password, it very strange.

 

anyone can help?

 

(Cisco Controller) >test aaa radius username c21506d39b6e password c21506d39b6e wlan-id 22

 

Radius Test Request

Wlan-id........................................ 22

ApGroup Name................................... none

 

Attributes Values

---------- ------

User-Name c21506d39b6e

Called-Station-Id 10.2.254.196

Calling-Station-Id 00:11:22:33:44:55

Nas-Port 0x00000008 (8)

Nas-Ip-Address 10.2.254.196

Nas-Ipv6-Address 2002:dfff:8302:2::2

NAS-Identifier WLC

Airespace / WLAN-Identifier 0x00000016 (22)

User-Password secret

Service-Type 0x00000008 (8)

Framed-MTU 0x00000514 (1300)

Nas-Port-Type 0x00000013 (19)

Tunnel-Type 0x0000000d (13)

Tunnel-Medium-Type 0x00000006 (6)

Tunnel-Group-Id 0x00000065 (101)

 

--More-- or (q)uit

Cisco / Audit-Session-Id 0a02fec4001f1f5b64a7c743

Acct-Session-Id 64a7c743/00:11:22:33:44:55/2223857

 

 

test radius auth request successfully sent. Execute 'test aaa show radius' for response

 

(Cisco Controller) >

 

 

 

 

 

 

 

 

 

1 Accepted Solution

Accepted Solutions

Mark Elsen
Hall of Fame
Hall of Fame

 

               - Adding          : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuc21803

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

View solution in original post

4 Replies 4

Mark Elsen
Hall of Fame
Hall of Fame

 

 - Have a checkup review of the controller configuration according to https://community.cisco.com/t5/networking-knowledge-base/show-the-complete-configuration-without-breaks-pauses-on-cisco/ta-p/3115114#toc-hId-1039672820 , have the output analyzed with https://cway.cisco.com/wireless-config-analyzer/ 
       Also look into https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html  , especially if you are currently on an older release it would be strongly advised to upgrade and  test again , 

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

Mark Elsen
Hall of Fame
Hall of Fame

 

               - Adding          : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuc21803

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

Hi @Support ACME 

 There is this document available by cisco on how to setup freeradius and wlc, in case you did not see yet.

https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/211263-Configure-802-1x-PEAP-with-FreeRadius.html

 

Rich R
VIP
VIP

What version of software are you using?

------------------------------
Please click Helpful if this post helped you and Accept as Solution (drop down menu at top right of this reply) if this answered your query.
------------------------------
TAC recommended codes for AireOS WLC's   and   TAC recommended codes for 9800 WLC's
Best Practices for AireOS WLC's,   Best Practices for 9800 WLC's   and   Cisco Wireless compatibility matrix
Check your 9800 WLC config with Wireless Config Analyzer using "show tech wireless" output or "config paging disable" then "show run-config" output on AireOS and use Wireless Debug Analyzer to analyze your WLC client debugs
Field Notice: FN63942 APs and WLCs Fail to Create CAPWAP Connections Due to Certificate Expiration
Field Notice: FN72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Required
Field Notice: FN72524 IOS APs stuck in downloading state after 4 Dec 2022 due to Certificate Expired
- Fixed in 8.10.196.0, latest 9800 releases, 8.5.182.12 (8.5.182.13 for 3504) and 8.5.182.109 (IRCM, 8.5.182.111 for 3504)
Field Notice: FN70479 AP Fails to Join or Joins with 1 Radio due to Country Mismatch, RMA needed
Field Notice: FN74383 APs Running 17.12.4/5/6/6a May Run Out of Flash Space Preventing Upgrades
How to avoid boot loop due to corrupted image on Wave 2 and Catalyst 11ax Access Points (CSCvx32806)
Field Notice: FN74035 - Wave2 APs DFS May Not Detect Radar After Channel Availability Check Time
Leo's list of bugs affecting 2800/3800/4800/1560 APs
Default AP console baud rate from 17.12.x is 115200 - introduced by CSCwe88390
Review Cisco Networking for a $25 gift card