08-26-2025 01:45 PM
I am in the middle of migrating WLC 5520 (8.10.190.0) to C9800-CL (17.12.05) while APs remain the same (3802i). AAA servers are ISE 3.4 patch 2. We use centralized switching (no Flex mode). I have an 802.1X SSID allowing both EAP-TLS and PEAP+MSCHAPv2. The SSID on WLC 5520 works for pretty much all devices we have. The same SSID on C9800-CL works for most devices I tested so far but one particular Windows laptop.
It’s interesting to notice the captured packets are between the C9800-CL and the AP, but 802.1X authentication is between the supplicant (laptop) and the AP (BSSID MAC). On a successful connection, after the supplicant sends Response with Identity (host/xxxxxx), the AP sends a EAP-TLS Request, and after quite a few EAP packets exchange authentication succeeds.
On a failed connection, after the supplicant sends Response with Identity (host/xxxxxx), the AP just sends a Failure EAP packet and never sends a 802.1X proposal:
This explains why ISE never sees a Radius request for this particular laptop. I’ve tested 5 Windows laptops and a few iOS/Android devices so far, and found only one problematic laptop, but I don’t know how many more out of about 1000 laptops may experience the same issue.
A TAC ticket is going nowhere, and the engineer insists something is wrong with the laptop but doesn’t know what exactly is wrong. I’ve seen some similar issues online and it seems nobody was able to explain why there is no logs on Radius servers. Has anyone seen this?
09-03-2025 12:10 PM
Yeah I don't buy that - it's a bug in the Cisco code or the Windows/NIC driver code.
09-03-2025 12:14 PM
Actually there are dozens of bugs which say the 9800 based wireless infrastructure does not always work perfectly....
09-03-2025 12:12 PM
Exactly - the wireless infrastructure simply provides the transport (over radius) - the EAP is end to end between client supplicant and AAA server. That doesn't mean the wireless infrastructure can't break it (and often does) but isn't involved in what method is used.
09-03-2025 12:27 PM - edited 09-03-2025 12:28 PM
totally correct
can you send me the capture as PM
both capture bad and good from wlc 9800
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide