cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
163
Views
0
Helpful
1
Replies
jakkapan meeon
Beginner

WLC embed AP 9800 cisco integreat with Active Directory not working

Dear All

I did configuration follow config guide this link "https://www.cisco.com/c/en/us/td/docs/wireless/controller/ewc/17-2/config-guide/ewc_cg_17_2/secure_ldap_.html"

 

but i don't see log request or receive from WLC to LDAP

 

 

================================
Server name :xx.xx.xx.xx
Server Address :xx.xx.xx.xx
Server listening Port :xxx
Bind Root-dn :xxxx
Server mode :Secure-TLS
Cipher Suite :0x00
Authentication Seq :Search first. Then Bind/Compare password next
Authentication Procedure:Bind with user password
xx xx xx
Object Class :sAMAccountName
Object Class :Person
Request timeout :20
Deadtime in Mins :0
State :ALIVE
---------------------------------
* LDAP STATISTICS *
Total messages [Sent:0, Received:0]
Response delay(ms) [Average:0, Maximum:0]
Total search [Request:0, ResultEntry:0, ResultDone:0]
Total bind [Request:0, Response:0]
Total extended [Request:0, Response:0]
Total compare [Request:0, Response:0]
Search [Success:0, Failures:0]
Bind [Success:0, Failures:0]
Missing attrs in Entry [0]
----------------------------------
No. of active connections :0

1 REPLY 1
rrudling
Rising star

> Request timeout :20 - so clearly sending requests and not seeing any (valid) reply

So request might not reach LDAP server or LDAP server ignores request because it's invalid (certificate for example) or response doesn't reach WLC or WLC ignores response because it's invalid (certificate for example) 

- Does your WLC have a route to the LDAP server?

- Does the LDAP server have a route back to the WLC?

- Are there any firewalls or ACLs in the path which could be blocking?

- Have you configured valid/trusted certificates on both ends?

 

Bit suspicious that you have 20 request timeouts but zero LDAP messages sent in stats so maybe nothing has even been sent?  You can use packet capture to confirm what's being sent and received.

Content for Community-Ad