cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1146
Views
10
Helpful
7
Replies

IOS-XE WLC : Radius config not visible through GUI (9800 and EWC)

Slabre
Level 1
Level 1

Hello,

 

Hardware : 9800, 9120 EWC

Software : 16.12.4a for 9800, 17.3.4 for 9120 EWC

 

We performed some AAA changes on our WLCs and we had to reset the AAA config with a "no aaa new-model".

At this point there were no AAA config at all visible either through CLI or GUI.

But we already had our first issue : all our RADIUS requests were sent to our ISE servers, even if none of them were configured on our WLCs. We still can't find out why.

 

Then we started to properly configure RADIUS through CLI.

The second issue is there : the RADIUS config is visible through CLI as expected, but absolutely not through GUI. This is still the case on many of our WLCs.

 

Then with or without our RADIUS config, our WLCs apprently continue to correctly send RADIUS requests.

I didn't find a bug for this, did I miss something else ? I don't think this behaviour is expected.

 

Thank you

7 Replies 7

HI

 Not expected at all.  You probably hit some undocumented bug. If I were you, I´d upgrade

We'll try that but I'm almost without hope since we have 17.3.4 on our EWC and the recommended is 17.4.3c, not a huge gap.

Arshad Safrulla
VIP Alumni
VIP Alumni

for 9800 WLC, you are running obsolete IOS-XE code. So the first recommendation would be to upgrade. Then since you are facing the similar issue in both EWC and 9800 WLC I doubt the issue may be coming from the web browser side, so clear the cache or use private mode, disable all the extensions and try again. I would also try to restart the boxes to make sure that this is not a temporary issue. If you don't want to restart then you can open a TAC case and definitely they will end up suggesting to try with another browser or upgrade to the latest. 

Not an issue from web browser or computer, several people tried and same results everywhere.

We opened a TAC case in parrallel, I'll update here. Thank you.

Rich R
VIP
VIP

We didn't get all our radius config working correctly till 17.6.1 - combination of bug fixes and feature implementations to achieve AireOS feature parity (more or less).  Beware that in earlier releases some radius commands are accepted on CLI and appear in the config but the WLC simply ignores them - they do nothing.

Well... I have to say, 9XXX WLCs are little bit annoying regarding the bugs or lack of features. We don't want to upgrade to a non-starred IOS version, so we won't be able to upgrade to 17.6.X.

Thanks for your feedback... even if it's a bad one !

Reading through this post, it makes me wonder.  I have multiple 9800's I use for testing with clients connected and I change the heck out of my config and especially the aaa for radius and tacacs.  I have never ran into that issue and had not had any issues with dot1x or tacacs.  Again, that could just be my environment, but I even just spun up a new vm running the latest code and just blew in my AAA and everything just worked.  I have taken my snippets of my config and pasted them in different versions of code with no issue.  

Now as far as what code to use.  If your system is working, then you stick with that version or code train unless there is a bug fix.  Features, once you have something working and working fine, is just a "want".  If your system is not working well, then you need to have someone review your configuration, or like what was mentioned, go through the config analyzer, or upgrade or downgrade.  This is why folks have extra equipment, so they can test.  I wouldn't go with a gold star code, if I have not tested it our and validated that there were no issues.  If I rolled out that code and later found an issue, you are back to step 1 to determine your changes in config or upgrade/downgrade.  

You are not tied to the gold code, just remember, if you choose that route, then you are stuck if something is broken until they star another version.  This route is not good due to how long it will take you to remediate any issues.

-Scott
*** Please rate helpful posts ***
Review Cisco Networking for a $25 gift card