cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3185
Views
5
Helpful
9
Replies

Syslog client Authentication

Hi EveryOne!
the Cisco Wireless controller Does not syslog the WiFi client association (users) on successfull !!!
Do i need an extrat config to satisfy that!!, if yes how !!!

Best Regards.

1 Accepted Solution

Accepted Solutions

balaji.bandi
Hall of Fame
Hall of Fame

try below :

 

Configure the syslog facility for client by entering this command:

config logging syslog facility client {assocfail | associate | authentication | authfail | deauthenticate | disassociate | excluded} {enable | disable}

where:

  • assocfail : 802.11 association fail syslog for clients.

  • authentication : Authentication success syslog for clients

  • authfail : 802.11 authentication fail syslog for clients

  • deauthenticate : 802.11 deauthentication syslog for clients

  • disassociate : 802.11 disassociation syslog for clients

  • excluded : Excluded syslog for clients

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

9 Replies 9

balaji.bandi
Hall of Fame
Hall of Fame

Since we do not know what WLC controller and version of code running, also do you have ISE in place for authentication or not

 

in general, you can enable log as below mentioned document :

 

https://www.cisco.com/c/en/us/support/docs/wireless/4100-series-wireless-lan-controllers/107252-WLC-Syslog-Server.html

 

If you have using ISE, ISE does have a very good logging system you can to push that logs to SYSLOG Server.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi Sir!
sorry for not given much details!
wlc 3504 and no ISE used, Im using syslog server only!


here the APs Syslog config from the WLC:

 

(wlc) >show ap config global

AP global system logging host.................... 10.XX.YY.ZZ
AP global system logging level................... informational
AP Telnet Settings............................... Globally Configured (Disabled)
AP SSH Settings.................................. Globally Configured (Disabled)
Diminished TX power Settings..................... Globally Configured (Disabled)

AP Broken Antenna Failure Detection - Status..... Disabled

balaji.bandi
Hall of Fame
Hall of Fame

try below :

 

Configure the syslog facility for client by entering this command:

config logging syslog facility client {assocfail | associate | authentication | authfail | deauthenticate | disassociate | excluded} {enable | disable}

where:

  • assocfail : 802.11 association fail syslog for clients.

  • authentication : Authentication success syslog for clients

  • authfail : 802.11 authentication fail syslog for clients

  • deauthenticate : 802.11 deauthentication syslog for clients

  • disassociate : 802.11 disassociation syslog for clients

  • excluded : Excluded syslog for clients

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

hi, Sir!
this is exactly what im looking for, just one small detail:
i was connected then i did : [1: disassociation | 2: association then | 3: disassociation]
i only receive on my syslog server this

 

*apfMsConnTask_3: Jan 05 13:48:49.758: %APF-3-ASSOC_TRAP: apf_80211.c:19384 Client Association: MACAddress:aa:aa:aa:aa:aa:aa Base Radio MAC:yy:yy:yy:yy:yy:yy Slot:1 User Name:unknown Ip Address:10.ii:oo:pp

 

*apfReceiveTask: Jan 05 13:54:14.418: %APF-3-DISASSOC_TRAP: apf_80211.c:19394 Client Disassociated: MACAddress:aa:aa:aa:aa:aa:aa Base Radio MAC:yy:yy:yy:yy:yy:yy Slot:1 User Name:unknown Ip Address:10.ii:oo:pp Reason:Disassociated due to inactivity ReasonCode:4

 

i did not receive trap for the first disassociation and the second one is sent after almost 6min, ==>> is this normal !!!

Cordially!

Does anyone know what is the equivalent config for the 9800 WLCs?

If anyone ever stumbles on this, I got it working on the 9800 WLC with:

 

wireless client syslog-detailed

Thank you very much for this tip!

balaji.bandi
Hall of Fame
Hall of Fame

Some time Log shipping may be due to waiting time, but you should see both the logs in syslog if they configured same way.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

when disassociate the client, the led-state goes green after blue in  6sec. the client is disassociated after almost 6min.
i verify with : #show client summary

by the way, how can i refresh the clients in the #show client summary using #CLI! (to not wait 5min )

Cordially

Review Cisco Networking for a $25 gift card