07-09-2017
01:39 PM
- last edited on
07-05-2021
07:18 AM
by
cc_security_lab
Hi,
Have simple setup where the wlc uses ISE for Radius for AAA , and get this message
%APF-3-CLIENT_NO_ACCESS: Authentication failed for client: 74:8d:08:6a:f1:43. ACL override mismatch from AAA server
The authC policy checks wireless MAB and default network access and continue if user not found.
At this point the from the ISE does not show an error, but the wlc displays the above error in the log, and the user is not able to connect to the WLAN .
Any useful suggestions would be great
07-09-2017 02:34 PM
Hi
Is there a firewall between your ise and wlc?
They communicate for CoA over udp/1700.
What are the logs on ISE?
Was it working before?
Does the acl name between ISE profile and wlc are exactly the same (case sensitive).
Thanks
PS: Please don't forget to rate and mark as correct answer if this answered your question
07-09-2017 03:20 PM
Hi Franceso,
no f/w. yes it was working before. Will double check the acl names
thanks
07-10-2017 03:01 AM
Ok let us know. Otherwise gives us the full ISE log for that specific authentication into a text file.
Thanks
PS: Please don't forget to rate and mark as correct answer if this answered your question
07-10-2017 06:25 AM
Hi Franceso,
I've attached the log but no issues here but get this error in the wlc
*apfReceiveTask: Jul 10 13:14:36.368: %APF-3-CLIENT_NO_ACCESS: apf_80211.c:4395 Authentication failed for client: 74:8d:08:6a:f1:43. ACL override mismatch from AAA server.
when you try to associate to the ssid it disconnects you very quickly
Cheers
Tony
07-10-2017 10:55 AM
Hi Tony
This log is the 1st step when your user is redirected to the portal.
Are you redirected well to the portal?
The issue occurs after portal login right?
Do you have any logs on ISE regarding that step?
Thanks
07-10-2017 04:49 PM
Hi Franceso,
now resolved !
It was the acl on the wlc under
Can you believe that !
I well good learning curve for me on this one
ciao
07-11-2017 08:41 AM
Hi
Nice to hear that everything is good now.
Thanks
PS: Please don't forget to rate and mark as correct answer if this answered your question
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide