03-05-2014 12:30 AM - edited 07-05-2021 12:20 AM
Hi,
I have reciently attmepted to upgrade our 5508 DMZ WLC to 7.6.100.0 from 7.2.x - we are using Cisco NAC Guest Server version 2.0.3 for web portal authentication.
Upon completing the upgrade to the WLC guest users were not able to authenticate and I was seeing the following log message on the NAC server.
_SYSTEM_ ( - 10.3.240.10) User trying to authenticate from invalid location: user@user.com 2709 05-Mar-2014 18:30:58
I have seen CSCsq86376 but we are using the IP Address as the attribute.
Has any one else run into this problem before or could perhaps point me in the right diretion of potential configuraiton to change/further trouble shooting?
Thank you in advance.
03-05-2014 05:27 AM
You might have to look at your pre-auth ACL's on the WLC. You can also post on the security AAA forum and see if there was a change in the WLC code that affected external webauth... make sure on the WLC WLAN AAA tab that you don't have this enabled:
Radius Server Overwrite interface
Or on the WLAN General tab that the NAS-ID is still the hostname of the WLC. This requires a reboot if you change it.
Thanks,
Scott
*****Help out other by using the rating system and marking answered questions as "Answered"*****
11-11-2014 03:08 AM
Just done the same as the above, but then reverted back to 7.5 and put original config on.
But still got the same issue.
Any help would be much appreciated
Has the upgrade changed the webauth files.??
11-11-2014 04:12 AM
I have done many upgrades to v7.6 and never had any issue with WebAuth failing. Since you downgraded and also restored your config, the only thing that would of changed is the WebAuth or certificates that isn't part of the restore. Are you using an external authentication server, has that changed? You might be better off opening a TAC case, because something else must of happen if you did a restore and it's still broke.
Scott
11-11-2014 04:26 AM
Scott.
Thank for the prompt reply.
No we are not using a external Auth server, just local.
The portal does use https and it prompts you to accept cert.
Think a TAC case it will have to be.
11-11-2014 04:31 AM
So the WebAuth is pretty straight forward. Local auth and you don't have a 3rd party cert so you will get a certificate error. So what is the issue? All users are not working, or just certain one?
Scott
11-11-2014 04:36 AM
Scott.
All I get is User trying to authenticate from invalid location: on the nac guest server.
11-11-2014 04:42 AM
Nothing changed on the NAC server? You should do a file compare of the config from when it was working and now. The NGS should have a detailed error that you can look at also. Make sure your NGS and WLC shared secret is correct. Might be a good idea to enter that again.
Scott
11-12-2014 01:05 AM
Scott.
Thanks for the help.
Got this sorted as per abwahid in a previous post above.
Just totally missed this when I checked config.
But on WLC under Security/Radius Authentication Servers.
At the top the "Auth Call Station ID Type" was set to system mac address.
Set to IP Address and booom...working.
07-02-2014 06:28 AM
We had the same problem after upgrading fra 7.4.121 to 7.6.120.
The CSCsq86376 fixed the problem for us.
07-09-2014 03:38 AM
Hi,
Any customer that has the calling-station-id attribute on their controller set to MAC address will not pass any authentications, change the attribute to use the IP address instead of the MAC address and then try.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide