cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
550
Views
1
Helpful
14
Replies

WLC9800 not sending RADIUS Access-Request for particular clients

Hello,

After migrating from a Cisco WLC 5520 to a 9800 I am having a strange behavior for particular clients. On a given SSID with Do1x authentication I get clients able to authenticate and very particular one not. After some radioactive tracing I see on succesfull clients that the WLC is sending the RADIUS: Send Access-Request to xx.xx .. On the afected user it doesn't, it stops after a sucessful EAP identity exchange.

Success Client

DiogoFigueiredo_1-1750949903195.png

Failed Client

DiogoFigueiredo_0-1750949853263.png

A show tech wireless on the analyzer doesn't show any particular error and I think the logs above speak for themselves, I also have a PCAP showing the RADIUS request to the successful client:

DiogoFigueiredo_2-1750950036986.png

No RADIUS packet for the failed client though. Again same SSID and same Access Point. Did someone experienced something like that maybe?

Soft Version is 17.12.5 on the WLC9800

Note that when I move this Access Point to the old WLC it works, clients authenticate via dot1x successfully using EAP-TLS with the RADIUS which is an NPS server.

Thanks

BR

Diogo

14 Replies 14

Can you see error code of authc failed 

MHM

No although it says auth fail there was no authentication, the dot1x is not being fired after EAP exchange.

DiogoFigueiredo_0-1750949853263.png

the line in red, I need to see full line 

MHM 

Hi,

The message is this 

2025/06/26 14:13:09.967007944 {wncd_x_R0-0}{1}: [errmsg] [21811]: (note): %DOT1X-5-FAIL: R0/0: wncd: Authentication failed for client (c81c.fe63.79b4) with reason (Cred Fail) on Interface capwap_90000145 AuditSessionID 11015D0A00016D0BAC95D4B7 Username: xxxx

But this is very weired because no Dot1X request has been fired, sent, etc... Let me help you, I will post here bellow a successfull connection from another device in this SSID and another from the device which fails:

Success Device

DiogoFigueiredo_0-1751024576499.png

Failed Device same SSID as above, same Access Point

DiogoFigueiredo_1-1751024658748.png

If you compare both images you see that no RADIUS access request is being sent.

 

BR

Diogo

 

debug wireless mac <Client_MAC> 

can I see client to WLC debug

MHM 

The pictures above are from a radioactive trace on the successfull connected client and on the failed client.

debug wireless mac <Client_MAC> detail 

please this also for failed client 

MHM 

There are for some authc two inner and outer authc 

I need to know if outer authc is failed or inner

It failed as I search because of missing or wrong identity exchange between wlc abd client.

In SW we can see both events and packet here in wlc we see only events which usually not so usfull to identify problems.

MHM

marce1000
Hall of Fame
Hall of Fame

 

 -  @Diogo Figueiredo   Check logs on the NPS  radius server for the none working  clients; what is the authenticating status ?
                                     Debug the failing clients using : https://logadvisor.cisco.com/logadvisor/wireless/9800/9800APJoin
                                          You can have those debugs (so called RadioActive  Traces) analyzed with :
                                          Wireless Debug Analyzer

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Dot1x is not being fired after EAP exchange for the failed client as shown above... Again no RADIUS request are sent for that given client... However it works for other clients on the same SSID. EAP exchange seems to be the same though as you can see on the radioactive trace.

 

 - @Diogo Figueiredo   You can also feed the output from RadioActive Traces into Wireless Debug Analyzer
                                    for high level analysis

  M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

marce1000
Hall of Fame
Hall of Fame

 

  - @Diogo Figueiredo   Check if these info's are useful :  https://community.cisco.com/t5/wireless/radius-not-working-9800-l-with-windows-nps/m-p/4444871/highlight/true#M231927

  M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Saikat Nandy
Cisco Employee
Cisco Employee

Hi Diogo - I was going through the thread and I understood what you are saying. I think at this point apart from looking into the RA trace, it's quite fair to look a bit from the AP side too. My suggestion would be to take the followings for both working & non-working scenario and in sync (from same AP) - 
# WLC RA trace - with & without internal
# WLC EPC
# AP Client trace & debug - 

exec-timeout 0
config ap client-trace address add <client MAC addr>
config ap client-trace filter all enable
config ap client-trace output console-log enable
config ap client-trace start
debug client <client Mac addr>
term mon

Rich R
VIP
VIP

And one more question @Diogo Figueiredo - what are the clients?  Are they both identical?  If not what OS and version are they? (there have been some client specific bugs)

Review Cisco Networking for a $25 gift card