Cisco AAA / Identity / Nac :: 1310 Bridges - FreeRadius Authentication Error

Mar 2, 2011

I have two 1310 bridges. one configured as root and the other as non-root. Authentication Settings: Open with EAP and Network EAP with no addition. Set up: when non-root bridge tries to associate with root bridge, root bridge checks with radius server if it's ok to associate with the non-root bridge.
 
I can see communication with the radius server (I'm using FreeRadius) and the radius server even sends a SUCCESS back to the root bridge. However I'm seeing this error on the non-root bridge: DOT1X_SHIM-3-PLUMB_KEY_ERR: Unable to plumb keys - Eap key struct is NULL and the bridges do not authenticate.

View 2 Replies


ADVERTISEMENT

Cisco Wireless :: 1310 Bridges Keep Losing Connection?

Nov 28, 2010

I have two 1310 bridges...one set as root and the other as non-root.For some reason they keep losing connection.  When I reboot the non-root bridge, link is established.Both bridges have an antenna connected with the right connector and they have the setting antenna transmit right antenna receive right
 
logs from root bridge
Nov 29 13:52:53.311: %DOT11-4-MAXRETRIES: Packet to client XXXX.XXXX.XXXX reached max retries, removing the clientNov 29 13:52:53.311: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station XXXX.XXXX.XXXX Reason: Previous authentication no longer validNov 29 13:52:53.568: %DOT11-6-ASSOC: Interface Dot11Radio0, Station Test XXX.XXXX.XXXX Reassociated KEY_MGMT[WPAv2 PSK]Nov 29 13:55:16.260: %DOT11-4-MAXRETRIES: Packet to client XXXX.XXXX.XXXX reached max retries, removing the clientNov 29 13:55:16.260: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station XXXX.XXXX.XXXX Reason: Previous authentication no longer validNov 29 13:55:16.550: %DOT11-4-MAXRETRIES: Packet to client XXXX.XXXX.XXXX reached max retries, removing the clientNov 29 13:55:16.550: Client XXXX.XXXX.XXXX failed: reached maximum retries
 
logs from non-root Nov 29 2010 13:52:55: %DOT11-4-UPLINK_DOWN: Interface Dot11Radio0, parent lost: Received deauthenticate (2) not validNov 29 2010 13:52:55: %LINK-3-UPDOWN: Interface Dot11Radio0, changed state to down The signal strength is around -84dBm Cisco IOS Software on both bridges is: C1310 Software (C1310-K9W7-M), Version 12.4(10b)JA1, RELEASE SOFTWARE (fc2)

View 12 Replies View Related

Cisco Wireless :: Combining 1310 Bridges With 5508 Controller

Jul 10, 2012

I have 2 campuses.  I have my 5508 wireless controller working beautifully on my main campus using LDAP.  (YAY!!)  Now for my problem.  My remote campus has 1310 bridges.  I was able to successfully upgrade one of them to work with the controller, however, I can't get the other two bridges to talk to the one that I upgraded and I can't get them to upgrade, it indicates that they need to be the root.  I have several small buildings on that remote campus, than need that remote bridging in order to be able to have network access. 

View 7 Replies View Related

Cisco Wireless :: WET200 FreeRadius EAP-TLS Authentication?

Feb 29, 2012

I have a new WET200 wireless bridge and cannot authenticate to our WPA2 EAP-TLS freeradius server. Here are the steps that I have taken so far:
 
1. Renamed my pkcs12 client certificate to .pfx extension and imported it into the WET200.

2. Used the client certificate import password as the "Private Key Password"

3. Typed in the client "Login Name"
 
The freeradius server recognizes the WET200 with the entered credentials but will not authenticate. The freeradius debug log gives the following error:
 
WARNING: !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
WARNING: !! EAP session for state 0x3e833be03884222b... did not finish!
WARNING: !! Please read [URL]
WARNING: !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
 
Normally, with other wireless devices the CA (ceritificate authority) certificate needs to be installed to the client as well as the pkcs12 client certificate? Is there a way to place a CA and client certificate into the WET200?What is the proper method to install certificates into the WET200 for FreeRadius EPA-TLS authentication?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Authentication Error In ACS 5.3

Sep 7, 2012

I configured ACS 5.3 and added AAA clients with TACACS+ server and shared secret key as cisco123. i did the below config on switch also. when i try to authenticate login with ACS it does not respond. Find the configuration and debug output.nd
 
In debug output it gives ruser and rem_addr is null. i did not understand why .
 
I am able to ping to ACS server and i used telnet 192.x.x.10 49 and it gives the proper output.
 
aaa new-model
aaa authentication login default group tacacs+ local
!
tacacs-server host 192.168.60.10 key cisco123
tacacs-server directed-request
ip tacacs source-interface Vlan172

View 2 Replies View Related

AAA/Identity/Nac :: 1841 Giving Error In Authentication

May 15, 2013

I have an 1841 that was working fine - I could SSH to it with my Radius login and console into it with local credentials ("Fred").I added another use ("Mike") with priv 15 so the end user could log in locally via console if needed.After that, we can both log in via console, but when we try to enter privileged mode we get "% Error in Authentication", before even entering the   password.I can still log in via Radius SSH with no problems and access privilege mode via SSH.What am I missing so we can have two different users be able to log in locally with different credentials and access privileged mode, and keep my ssh radius working?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2 / 2851 / There Is Authentication Failure With Error No 254

Nov 22, 2011

we have ACS 4.2 and 2851 router with IOS 15.0(1)M4. There is authentication failure with error no 254. Is there any compatibilty issue with 15.0(1)M4 IOS

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2.0 Error In ACS Authentication For Accessing Devices

Jun 11, 2012

We are using acs version 4.2.0 build 124 on windows server 2003. Our domain controller has been upgraded from 2003 to windows 2008 R2.Now we are facing following error in ACS authentication for accessing our devices.Error: AUTH  06/09/2012 11:55:40 E 1810 3316 0x8f21 External DB [NTAuthenDLL.dll]: Windows  authentication FAILED (error 1326L)if we restarted services of ACS server then users get authentiated fine.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: 5508 - NGS Guest Server Authentication Error

Apr 29, 2011

I installed NGS 2.0.2 for wireless guest user management and authentication. I implement webauth via webauth page on wlc deployed.One Branch with a WLC5508 version 7.0 wireless anchor controller is working on the NGS.But now I integrate next branch with WLC4402 version 6.0.188 and the authentication of users at the new branch gets an error, wrong user/password.
 
I double checked configuration and user/password but I can't find any configuration error. Also stopping and starting of radius service and reboot of NGS still does not work. I tried to debug the radius via web interface and watched for the loggfile and there is still a reject.I also tried the freeradius command radiusd -X but I got an error when starting the radiusd -X.
 
1.) How can I figure out, if I will get the correct password from my WLC ? Are there any debug options to see more ? e.g. some cli commands, radiustest utilities or how to get the received password from the chap challenge of the debug ?
 
2.) I have appended a part from my radius loggfile. How can I find the detailed error in the radius log file? Is it correct that the password in the debug file is empty ? raiuds logg line "[radius-user-auth] expand: %{User-Password} -> "

View 3 Replies View Related

Cisco :: 1310 - 802.1x Authentication Fail Through WLC But OK On Autonomous APs

Jun 5, 2013

I migrate 1310 APs from Autonomous to Lightweight. Migration is OK with Cisco Upgrade Tool, and AP are registered on my 2504 WLC.
 
Previously, a 802.1x network was broadcasted by autonomous APs, supplicants were identified on a freeradius server with MSCHAPv2/PEAP method.
 
But on the WLC, supplicants can't auth on Radius server.I configured a WLAN with WPA/TKIP/802.1x with my radius server in AAA tab.When clients try to authenticate, I get these messages where xxx is login:

-AAA Authentication Failure for UserName:821 User Type: WLAN USER
-AAA Authentication Failure for UserName:200 User Type: WLAN USER
-AAA Authentication Failure for UserName:209 User Type: WLAN USER
 
Security info on client page is:

Security Policy CompletedNo ###Policy TypeWPA###Encryption CipherTKIP-MIC###EAP TypePEAPSNMP NAC State Access ###Radius NAC State8021X_REQD .

What is strange, there are some clients which are OK in RUN State, and 50 other % which are not.

View 10 Replies View Related

Cisco AAA/Identity/Nac :: ACS V5.3 Identity Selection For Authentication?

Jan 16, 2012

I configured before ACS v4.2 to authenticate network devices using internal users at first, and if the user is not found use AD list users.  But with v5.3 I have some problems doing this, on identity policies I use rule based result selection option, I configured 2 polices for Identity source, one for Internal Users and other policy for AD user, but it only works with the first policy, internal users or AD, but works only for the first policy identity.  how to do that, if the user is not found on first policy, continue to the next policy.

View 7 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Identity Base Authentication

Jul 3, 2011

I need a specify users to allow access to particular devices and give privilege only for show command or show run. Here is how I tried to configured.
 
1. Configured two seperate Shell Profile and Command set with privilege level 4-5 and allowing only show run command

2. create seperate service selection rule with adding the require NDG and protocol TACACS and maching service "RestrictAccess"

3. In the RestrictAccess Service I have following configured; Identity: internal users, Group Mapping to a particular group where the user exists, authorization: matching the above created identity group, NDG, shell profile, command sets
 
All the steps are attached in the .doc file. However when I tried with the particular user he is able to access everything and he is not hitting the correct access rule.

View 6 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Error - 22056 Subject Not Found In Applicable Identity

Oct 6, 2012

I have two ACS v 5.2 (primary and secundary) and some users are in the internal stor and the others are in the AD.The local site topology is like this:
 
PC - AP - WLC - ACS - AD
 
Authentication method is PEAP(EAP-MSCHAPv2) and all user have the certificate company installed. The OS in the client users is Windows 7.Users was working fine but some users reports intranet disconnections. I see in the ACS log  many "22056 Subject not found in the applicable identity store(s)." and "24415 User authentication against Active Directory failed since user's account is locked out" alarms.I believed it was because user wasn´t in the AD data base, but some times the same user is authenticated successfull and other i see the "22056...." or "24415...." alarms.
 
I switched the role for ACS primary to works as secundary and we see the same alarms.

View 2 Replies View Related

Configuring Ip Pool In Freeradius?

Nov 27, 2012

How do we setup ip pools in freeradius?

View 1 Replies View Related

Cisco :: 2106 WLC And Freeradius Session-timeout

Jun 20, 2011

We are trying to configure our 2106 wireless lan controller to expire wireless users sessions so the user is not remembered indefinitely. We are using freeradius to validate the users login information and passing back a "session-timeout" avpair but the WLC seems to be ignoring this value.
 
How to configure the session expiration time of wireless users on a 2106?

View 2 Replies View Related

Cisco :: 4402 - WCS User Names Sometimes Incorrect With 802.1x FreeRadius

Feb 29, 2012

I'm not sure if this is a recent issue for our setup, but I've only just noticed it. Although most authenticated users are shown by their correct user names (which are required for 802.1x authentication), a few users show up in the WCS reports as "anonymous", and one as "anonymous@myabc.com", which are not valid usernames on our network.
 
I can track these users by MAC via our network registration database, but have not yet figured what makes their systems unique. All three in yesterday's report are Win 7. I don't see anything strange in the RADIUS logs, but have not yet caputured "debug" traces of wireless authentication from an anonymous user.
 
We are running WCS 7.0.172.0 , with a pair of WLC 4402 controllers running 7.0.116.0 . Our WPA2 Enterprise auth uses TTLS/PAP, with the SecureW2 supplicant for Windows.

View 1 Replies View Related

Cisco :: Wlc 4404 Showing Authentication Error

Sep 17, 2008

I got a WLC4404 running software version 5.1.151.0 with 40 LWAPPs (mostly 1242AG). We got new Dell Latitude E6500 Laptops with Intel 5100 NICs. After upgrading the bios to the latest version and installing the latest wlan driver, wireless is working the most time.After about 4 reboots I see the following message in the WLCs logfile: "Thu Sep 18 13:53:10 2008 AAA Authentication Failure for UserName:host/hostname.domain.name User Type: WLAN USER".After I disable the wlan-card, it's working again.

View 7 Replies View Related

Cisco VPN :: ACS 4.2 Authentication Server Not Responding / No Error?

Oct 25, 2011

I use PIX 8.0(4) and ACS 4.2 for VPN authentication. I got error as below even I'm able to ping to ACS server from PIX
 
RADIUS_SENT erver response timeout
RADIUS_DELETE
ERROR: Authentication Server not responding: No error
 
I tested aaa command from PIX and check configure on ACS (key and IP address) include restart ACS. The output still timeout and not responding from server.
 
PIX config:
=========
aaa-server AAA-VPN protocol radius
aaa-server AAA-VPN (MANAGEMENT) host 172.20.0.9
key xxxxxxx
 tunnel-group CGS-DR type remote-access
tunnel-group CGS-DR general-attributes
address-pool VPN-POOL
authentication-server-group AAA-VPN LOCAL
default-group-policy GR-CGS

View 2 Replies View Related

Cisco WAN :: ACS 5.3 - Authentication Rejected / Unspecified Error

Mar 14, 2012

i received the below output,how to start a troubleshooting? the aaa server is cisco ACS 5.3
 
ERROR: Authentication Rejected: Unspecified.

View 1 Replies View Related

Authentication Error Android Tablet?

Dec 30, 2012

I cannot connect to home WiFi while all other devices connected. Getthing "Authentication Error"

View 2 Replies View Related

D-Link DIR-825 :: Error / Authentication Failed IE9

Jul 7, 2012

When I try to log-in to my D-Link DIR-835 Router using IE9, I get an 'Authentication Failed' error. FireFox & Chrome work just fine. what I need to change or fix in IE9 so it will also log-in to my router?

View 13 Replies View Related

Cisco Wireless :: WLC 2504 Certificate Error Web Authentication

Dec 19, 2012

When I get the web authentication dialog from 1.1.1.1 it starts of with a certificate error. Is there a way to prevent this certificate error while using the self signed certificate?  I have not been successful installing certificates on my WLC - problems with OpenSSL and others.  Want to get this deployed but don't want users to have to encouter that error. 

View 1 Replies View Related

D-Link DIR-825 :: Samsung Galaxy S4 Authentication Error?

May 12, 2013

I just got a Samsung Galaxy S4. As I have always done with all of my devices that connect wirelessly, I went into the D-Link software and added my phone's MAC address to the network filter list. The security settings are WPA/WPA2. When I try to connect, the phone is able to see my Wi-Fi network, and it asks for my password, which I enter. It keeps trying to connect, but then it says an "authentication error occurred." I have checked and triple-checked the password, and it is correct. I have also checked and triple-checked the MAC address, and it is correct. I have rebooted the router and the phone several times each.

View 1 Replies View Related

Dell :: XPS L502X - Authentication Failed Error

Jul 22, 2012

I have have a XPS L502X. I decided to make a clean installation based on Windows 7 Ultimate.My problem is when I instal the driver for the "Dell Wireless HSPA 5540" it fails with then warning:

"Authentication failed. The .... driver cannot be installed on this computer...."

How to install driver for this ?

View 13 Replies View Related

Cisco VPN :: Authentication Error 5505 8.3 Setup Client Vpn To Windows

Nov 6, 2011

I'm trying to set up a 5505 (running 8.3) so that i can use the client vpn through RADIUS authentication.I have set up a new local RAIDUS windows box and used the ASDM asistant and a few other guides to setup the 5505.

View 3 Replies View Related

Security / Firewalls :: Authentication Error In Fortigate Firewall?

Dec 5, 2012

I have one Fortigate 200B Fire wall, which is using for wifi internet. i had configured one login page in the fourtigate .The path following below system > config > replacement message > authentication > login page.

it was working earlier. suddenly its not working. when i checked this path, that login page message colum was blanked. when i trying to put the message again its not pasting and am unble to type the message also.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: Web-authentication Using ASA And ACS 5.1

Feb 2, 2012

In order to restrict access to websites on our internal network, would we be able to put an ASA in front of the web server and force users to authenticate through the ASA and, once authenticated, allow only port 80 or 443 traffic for that use?  The ASA would query the ACS 5.1 server for authentication/authorization using AD as the identity store.  Is this even possible with TACACS? 

View 1 Replies View Related

Cisco AAA/Identity/Nac :: MAC OS-X And Authentication Via ACS 5.2?

Apr 1, 2012

My customer has a large installed base of MACs, all connected via controller-based (5508) WLAN. He wants to grant access to the network based on the device's mac addresses and move the WLAN-clients to a specific VLAN.I added all devices with their mac addresses to the ACS internal identity store for hosts.According to the following message the client sends the user-login credentials (chegger) within the RADIUS-request instead of the clients mac address and of course it has to fail.  After many configuration changes, I ended up always with the same result.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: EAP-TLS Authentication With ACS 5.2

Jun 13, 2012

I have question on EAP-TLS with ACS 5.2. If I would like to implement the EAP-TLS with Microsoft CA, how will the machine and user authentication take place? Understand that the cert are required on both client and server end, but is this certificate ties to the machine or ties to individual user?
 
If ties to user, and I have a shared PC which login by few users, is that mean every user account will have their own certificates?
 
And every individual user will have to manually get the cert from CA? is there any other method as my environment has more than 3000 PCs.
 
And also if it ties to user, all user can get their cert from CA with their AD login name and password, if they bring in their own device and try to get the cert from CA, they will be able to successfully install the cert into their device right?

View 7 Replies View Related

Cisco AAA/Identity/Nac :: AD Authentication In ACS 5.3

Jan 22, 2012

I have a new ACS 5.3 installation which I have joined to our AD Domain and added the directory groups into.  I have also added all our devices into ACS and their groups etc but I am still only able to authenticate on the our switches with an internal ACS account, when I try with an external AD account the log shows the following error   "Subject not found in the applicable identity Store (s)"

View 1 Replies View Related

Cisco Wireless :: 5508 Slow Roaming Or Re-authentication If There Is A Connection Error

Apr 29, 2013

I have a device manufacture there are requesting the following change on a customer's WLC 5508.
 
-config advanced eap identity-request-timeout 60
-config advanced eap request-timeout 60

I have studied many guides but I can't find out if there is a down-side to setting the timeout this high.Could it result in slow roaming or re-authentication if there is a connection error? The customer have large areas with high client density and some outdoor areas with low client density.

View 3 Replies View Related

Cisco Switching/Routing :: WS-C3750X-48T-S - Error On Default IOS / Authentication Fail

Feb 8, 2012

I am getting the below error on my new switch though I can’t find out A. why I am getting the error and obviously B. how to resolve said error as I need to ensure I am operating under the letter of the law and compliance.  The switch is a WS-C3750X-48T-S running C3750E-IPBASEK9-M, per my research IP base is the correct IOS for a T-S switch, the label on the outside of the switch matches the show ver (WS-C3750X-48T-S) so I know that IPBase is the right IOS for the hardware.  Could it be that I don’t have the license file installed? Below is what I get when I do a show license.  Lastly is there a place that I can find what IOS ships default with what switches, not version but type like c3750e-ipbasek9-mz.150-1.SE vs c3750e-ipbase-mz.150-1.SE
 
Error“%ILET-1-AUTHENTICATION_FAIL: This Switch may not have been manufactured by Cisco or with Cisco's authorization.  This product may contain software that was copied in violation of Cisco's license terms.  If your use of this product is the cause of a support issue, Cisco may deny operation of the product, support under your warranty or under a Cisco technical support program such as Smartnet.  Please contact Cisco's Technical Assistance Center for more information.”

[code].....

View 3 Replies View Related

Cisco Wireless :: 1552E / 5508 - Registration Process (AAA Authentication Error)

Dec 9, 2012

i have a problem with 1552E to register with 5508 WLC, and always got "AAA authentication error” in the WLC log, while AAA is not enabled.  so my question is , do i need to add the MAC address to the WLC MAC filter list even if i not enable the AAA server in the WLC.

View 9 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved