cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
941
Views
2
Helpful
13
Replies

wlc 9800 with windows server 2022 nps problems

Leo TI
Level 1
Level 1

Hello, I'm having a problem configuring my WLC 9800 with Windows NPS 2022 using 802.1x. I can't establish communication. I don't even see a log of attempts in Windows. However, it works with other devices, such as the Airos controller. Here's the configuration I have between Windows and the 9800.

LeoTI_0-1750942951135.png

LeoTI_1-1750942992894.png

LeoTI_2-1750943053913.png

LeoTI_3-1750943134573.png

LeoTI_4-1750943184712.png

Configuration windows server

LeoTI_5-1750943249492.png

LeoTI_6-1750943285921.png

LeoTI_9-1750943341440.png

LeoTI_10-1750943380540.png

LeoTI_11-1750943410567.png

LeoTI_12-1750943485737.png

No authentication attempts are seen in Windows.

LeoTI_13-1750943631834.png

with the airos it is different

LeoTI_14-1750943775448.png

LeoTI_15-1750943823507.png

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

13 Replies 13

Mark Elsen
Hall of Fame
Hall of Fame

 

 @Leo TI  Start with on overall checkup of your 9800 controller configuration with the CLI command : show tech wireless

  And feed the output from that intovhttps://cway.cisco.com/wireless-config-analyzer/

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

Hi marce1000
This is the document I extracted, but I'm not sure which part I should review.

 

 - @Leo TI   The WLCRESULTS are mostly OK and don't give any indicators for this  issue ;
                   Checkout : https://community.cisco.com/t5/wireless/radius-not-working-9800-l-with-windows-nps/m-p/4444871/highlight/true#M231927

  M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

Select interface from which wlc 9800 connect to NPS

Use mgmt vlan as source.

MHM

hi, MHM This is where it says to make the change, right? It doesn't work yet, I don't see any activity in Windows.

 

LeoTI_1-1750952312146.png

LeoTI_2-1750952383202.png

LeoTI_3-1750952429070.png

Can I see from wlc 9800

Show aaa server 

MHM

LeoTI_0-1750953912172.png

 

The transaction is failed

Reason 

1- share key wrong

2- radius port are wrong 

MHM

I reconfigured the key on both devices, both WLC and Windows, the ports are also the ones used: 1812 and 1813, but it doesn't work.

RADIUS: id 2, priority 2, host 172.22.4.195, auth-port 1812, acct-port 1813, hostname serverleo
State: current UP, duration 4294967s, previous duration 0s
Dead: total time 0s, count 0
Platform State from SMD: current UP, duration 4294967s, previous duration 0s
SMD Platform Dead: total time 0s, count 0
Platform State from WNCD (1) : current UP
Platform State from WNCD (2) : current UP
Platform State from WNCD (3) : current UP
Platform State from WNCD (4) : current UP
Platform State from WNCD (5) : current UP
Platform State from WNCD (6) : current UP
Platform State from WNCD (7) : current UP
Platform State from WNCD (8) : current UP, duration 162s, previous duration 0s
WNCD Platform Dead: total time 0s, count 0UP
Quarantined: No
Authen: request 23, timeouts 9, failover 10, retransmission 7
Response: accept 0, reject 11, challenge 0
Response: unexpected 0, server error 0, incorrect 0, time 97ms
Transaction: success 14, failure 2
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Dot1x transactions:
Response: total responses: 11, avg response time: 191ms
Transaction: timeouts 1, failover 6
Transaction: total 12, success 0, failure 12
MAC auth transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
Author: request 0, timeouts 0, failover 0, retransmission 0
Response: accept 0, reject 0, challenge 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
MAC author transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
Account: request 0, timeouts 0, failover 0, retransmission 0
Request: start 0, interim 0, stop 0
Response: start 0, interim 0, stop 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Elapsed time since counters last cleared: 17w3h43m
Estimated Outstanding Access Transactions: 0
Estimated Outstanding Accounting Transactions: 0
Estimated Throttled Access Transactions: 0
Estimated Throttled Accounting Transactions: 0
Maximum Throttled Transactions: access 0, accounting 0
Consecutive Response Failures: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Consecutive Timeouts: total 6
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 3, current 0 total 3
IOSD Platform : max 3, current 0 total 3
Requests per minute past 24 hours:
high - 3 hours, 42 minutes ago: 0
low - 3 hours, 42 minutes ago: 0
average: 0 

What is l2 or l3 authc of wlan you use ?

MHM

LeoTI_0-1750968851007.png

LeoTI_1-1750968865097.png

LeoTI_2-1750968883928.png

 

 

 

I can not know what issue is 
so try packet capture to capture packet between the WLC and NPS 
https://www.youtube.com/watch?v=7TXVqm3Rpmw

how to use packet capture is shown in video 
share capture here 

Saikat Nandy
Cisco Employee
Cisco Employee

Most of the time it will be either shared secret or port but as you have mentioned both are verified, could you please take an EPC in WLC and see if you are seeing the radius packets going out from the WLC?

Review Cisco Networking for a $25 gift card