10-02-2023 12:38 PM
Hi Guys,
We have a IW9167EH-B access point unable to join a 9800-40 WLC. The 9800 IOS version is 17.9.3
The error we are getting is "Received AAA authorization failed response for AP MAC auth"
Thanks in advanced.
Solved! Go to Solution.
10-04-2023 07:26 PM - edited 10-04-2023 07:28 PM
@fuhrersk8 wrote:
Does anywhere in IW9167s documentation states that they are factory set as mesh?
In the Bill of Material.
By default, all outdoor APs are configured for MESH from the factory. If the BoM does not specify the firmware loaded will be local-mode, then then AP will arrive in MESH.
The only way to convert it back to local is to either console into the AP or get the AP to join the controller (by adding the MAC address) and change the mode to local.
10-02-2023 01:08 PM - edited 10-02-2023 01:11 PM
Take a look at the matrix. This will show you want image is compatible with what access point. 17.11.1 is the first image supported by the model you have.
--UPDATE--
Looks like 17.9.3 is the minimum if that is the correct model number you have. Also, take a look at the port configuration because that looks like a MAB error. You can also connect a good know ap to the same port to see if the ap joins or not, that will help isolate the issue.
10-02-2023 01:29 PM
Thanks for your reply Scott.
Port configuration is not an issue.
Thanks again.
10-02-2023 01:51 PM - edited 10-02-2023 01:51 PM
Have you tried anything else? Have you tried another ap on the same port? Are you using MAB on the switch port?
10-02-2023 01:57 PM
Yes. There was a 9130AXI connected to the same port and registered to the WLC, no issues.
Regards,
10-02-2023 02:21 PM
Okay, well your best bet is to console into the ap and power the ap up. The logs will tell you what the issue is.
10-02-2023 03:26 PM
On the AP, post the output to the command "sh capwap client rcb".
10-03-2023 12:36 AM
>...The 9800 IOS version is 17.9.3
Ref : https://www.cisco.com/c/en/us/td/docs/wireless/compatibility/matrix/compatibility-matrix.html
You will need 17.11.1 at minimum
M.
10-03-2023 03:35 AM
10-03-2023 04:44 AM
- Ref : >...Received AAA authorization failed response for AP MAC auth (from initial post)
- It seems that you are authorizing APs on the controller by MAC address ; make sure that the particular AP is authorized as such ,
M.
10-03-2023 08:09 AM
Like mentioned earlier, you need to post the output from the console with info when the ap boots up. This is the only way folks here can help you. You should also post your port confg and any debug from the switch.
10-03-2023 04:08 PM
Take a look at https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213916-catalyst-9800-wireless-controllers-ap-au.html for AP MAC auth
10-04-2023 11:30 AM
Hi Guys,
Still working the case via Cisco TAC. Executed the command no ap auth-list method-list default but same result.
Thanks.
10-04-2023 12:49 PM
I am sure you get better support with TAC. If AP came up with Mesh image, you need to add AP Ethernet MAC address into 9800 database.
Configuration > Security > AAA > Advanced > Device Authentication
HTH
Rasika
*** Pls rate all useful responses ***
10-04-2023 01:00 PM
Hi Rasika,
Yes, that was what I first thought of, but it did not made any difference.
Thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide