cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
695
Views
3
Helpful
14
Replies

webauth external web page + CoA , but CoA always failed

codingbiubiu
Level 1
Level 1
14 Replies 14

codingbiubiu
Level 1
Level 1

please ignore

marce1000
Hall of Fame
Hall of Fame

 

   - @codingbiubiu   Troubleshoot the issue from on the controller using : https://logadvisor.cisco.com/logadvisor/wireless/9800/9800CWA

                                 + It's always good practice to checkout the overall 9800-CL controller configuration using the
                                    CLI command show tech wireless and feed the output from that into Wireless Config Analyzer
                                                        Do not use a simple show tech-support as input for WirelessAnalyzer

  M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

codingbiubiu
Level 1
Level 1

Please ignore

You use clearPass ?

If yes then try change port from 3799 to 1700

Cisco use port 1700 only for CoA

MHM

Please ignore

Error-casue = 200 is meaning CoA request success 

  • Values 0-199 and 300-399 are reserved.
  • Values 200-299 represent successful completion, so that these values might only be sent within Disconnect-ACK or CoA-ACK message and MUST NOT be sent within a Disconnect-NAK or CoA-NAK.
  • Values 400-499 represent fatal errors committed by the RADIUS server, so that they CAN be sent within CoA-NAK or Disconnect-NAK messages and MUST NOT be sent within CoA-ACK or Disconnect-ACK messages.
  • Values 500-599 represent fatal errors that occur on a NAS or RADIUS proxy, so that they CAN be sent within CoA-NAK and Disconnect-NAK messages, and MUST NOT be sent within CoA-ACK or Disconnect-ACK messages. Error-Cause values SHOULD be logged by the RADIUS server.

https://www.cisco.com/c/en/us/support/docs/wireless/ggsn-gateway-gprs-support-node/119397-technote-radiusdm-00.html

if you face other issue please more detail what you face 

MHM

codingbiubiu
Level 1
Level 1

...

codingbiubiu
Level 1
Level 1

...

No not immediately

Wlc receive CoA and ask wifi client re-auth

The wifi client re-auth using only Open not webauth abd hence can access network.

MHM

If integrate with Cisco ISE, 
How does the user login?

codingbiubiu
Level 1
Level 1

...

Rich R
VIP
VIP

@codingbiubiu changing all your posts to "please ignore" or "..." is really not helpful to community or in the spirit of collaboration and sharing which is what this is all about!

Review Cisco Networking for a $25 gift card