05-06-2024 02:41 AM
Hi All,
I'm having a weird issue where I cannot access via CLI on the WLC 9800 using radius authentication user, while I can do so with the same user via GUI. I configured AAA servers and groups to match correctly and activated the HTTP and VTY access:
While trying to access via CLI, ISE give me the following log:
WLC is running on 17.9.3 , SSH is enabled and these are the AAA configs:
aaa new-model
aaa group server radius ISE_Cluster
aaa group server radius Radius_Servers
aaa group server radius CR_Radius-Server
aaa authentication login default local group radius group ISE_Cluster
aaa authentication login ISE_Authentication_Login local group ISE_Cluster
aaa authentication dot1x Radius_Authentication group Radius_Servers
aaa authentication dot1x ISE_Authentication group ISE_Cluster
aaa authentication dot1x CR_Radius_Authentication group CR_Radius-Server
aaa authorization exec default local
aaa authorization exec ISE_Authorization_Login local group ISE_Cluster
aaa authorization network ISE_Authorization group ISE_Cluster
aaa authorization credential-download wcm_loc_serv_cert local
aaa accounting identity ISE_Accounting start-stop group ISE_Cluster
05-06-2024 03:24 AM
- What ISE version are you using ?
M.
05-06-2024 03:32 AM
Hi Marce.
05-06-2024 03:48 AM
- Personally I would consider it too old for the 9800 environment because 2.7 is EOL , you may also want to check the radius server's logs too ,
M.
05-06-2024 03:58 AM
Ok thank your for noticing me about the release, I will check the logs as well to see if there's anythig usefull
05-06-2024 03:49 AM
i would cross check the config on ISE on the ise side as below - also can you post radius server information from WLC ? (you used different Radius ISE / RADIUS / CR Servers ?)
05-06-2024 04:06 AM
Hello Balaji,
No, once I configured the servers and the group i just made sure the associations were correct.
So here the outputs:
05-06-2024 07:00 AM
Make sure to configure shell:priv-lvl=15
Cisco-av-pair attribute under authorization profile. Like @balaji.bandi mentioned, have a look at the guide and compare it with your config.
Jagan Chowdam
05-06-2024 11:43 PM
Hello Jagan,
I've checked the suggested configuration but it is already setted in the authorization profile. I'm now opening a TAC case and see what will be found during the analisys.
Thank you all as always for your support
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide