Cisco :: WLC 5508 Cannot Have Similar User Logged Twice
Aug 26, 2012
I was having users on a Cisco WLC 440x controllers. Some service accounts were logged several time with the same AD-Account.Since I migrated them on the new controller (5508), it seems that we cannot have the same AD user logged several time.
I changed the Radius server with the one we were using on the old 440x but situation seems to be same,I checked the error message when trying to start a second similar connection they looks like :
*Dot1x_NW_MsgTask_4: Aug 24 14:04:51.558: %DOT1X-3-MAX_EAP_RETRIES: 1x_auth_pae.c:3062 Max EAP identity request retries (3) exceeded for client xxxxxxxxxxx
*Dot1x_NW_MsgTask_4: Aug 24 14:04:51.558: %DOT1X-3-ABORT_AUTH: 1x_bauth_sm.c:447
Authentication aborted for client xxxxxxxxxxx
If I move back to the other 440x similar logins are allowed without any problems.
View 3 Replies
ADVERTISEMENT
Aug 22, 2011
how to find the current logged on user on a domain network? I tried nbtscan but it gives me ip address, machine name and mac address. In the server column it gives <server> and in the user name column it give <unknown>.
View 1 Replies
View Related
Sep 9, 2012
After upgrade to ACS 5.2 appliance , we are trying to configure AAA between Ciscoworks and ACS. Authentication is working but authorization fails , logged user cannot access to admin parameters. I've configured attributes manually but it doesn't work.Does ACS 5.2 support integration with CiscoWorks?
View 1 Replies
View Related
Feb 12, 2011
I have been testing WiFi devices such as the iPhones and iPads connectivity with the following setup:
1. 3502i AP
2. WLC 5508 SW 7.0.98
3. NGS
The i-devices have iOS v4.2
My goal is to have the guest user i-devices maintain the credentials (username and password) when they login again to the wireless network. Like if the device sleep, I think definitely they would loose those IP address issued by the DHCP. Once the guest user uses them again and connect them to the wireless network the user would not need to type-in those credentials on the Web Authentication page directed by the WLC.
The credentials are issued by the sponsor who created them on the NGS. It seems that there are WiFi problems with these i-devices. But somehow, I'm looking for a solution that would automated the logins like a checkbox if you want to be kept signed in, on Yahoo or Stay signed in for GMail.
View 6 Replies
View Related
Dec 2, 2012
I have a 5508 WLC running on 7.0.116, I need to be able to pull all configured users off the WLC and import into excel, I have 900 odd users configured. When I run a show net user summary it only displays a third of users. I'm hitting space to tab through each page, then eventually I just get dumped back to the command prompt.
View 5 Replies
View Related
Oct 8, 2012
I have a user authentication issue with our WLAN deployment. My issue relates to the guest access WLAN. First a brief descrition of our setup. We have a local WLC in the branch office (5508) with two SSIDs configured, CorpNet for the internal network and GuestNet of external guest access. We also have a WLC (5508) in the DMZ to provide the guest access. We are using Cisco ISE server to authenticate guest users via a web portal.
The authentication process works as it should. An external client gets an IP in the DMZ and is redirected to the web portal to authenticate their account. When they do they are able to access and browse the internet. No problems. My issue is that if we disable their account (ie suspend or delete it) in ISE it does not seem to terminate the users session and they can continue to have internet access. What I would like to happen is that when the account is disabled in ISE then the associated device's access to the internet is removed.
View 2 Replies
View Related
Apr 18, 2012
I'm on WLC 5508 . It doesn't matter if passive client feature is turned on or turned off , when you try to increase "User Idle Timeout" you can see this message:
In our network, a lot of clients gets deauthenticated. I thought it would be useful to enable "Passive-client" feature, or increase "user idle timeout" , but how these works with each other?
View 15 Replies
View Related
Feb 23, 2012
In my Wireless network, I have two appliances WLC 5508 running version 7.0.116.0.I have a WCS running version 7.0.172.0, deployed on a windows 2003 server.I've imported the two WLCs in my WCS in order to centralize the monitoring and the configuration tasks.Now I'm facing an issue when I want to create a guest user from the WCS, rather than creating this user access on each WLC. The creation of the user account is working good, the replication is done on the both WLCs, but on one of my WLC the guest user account is deleted after one hour(around).On the second WLC, the same user account remains during all its life time.In attachment a screen shot of the advanced parameter of the guest user.You can see that the user was created on the both WLC but is only active on one ... and unfortunately the wrong because the AP is associated with the other WLC.
View 2 Replies
View Related
Dec 19, 2012
I've got a WLC5508 (7.0.116.0) that is managed by WCS (7.0.172.0). I set up another WLC5508 with the same code and managed by the same WCS. Now I'd like to export all the 800 guest user accounts with the passwords from the old WLC and import them into the new WLC.
View 10 Replies
View Related
May 31, 2012
I am running a guest wireless network on a Cisco 5508 WLC with 6.0.202.0 code. My syslog is filling up with the following error message:
WLC: *May 15 12:32:59.244: %AAA-3-VALIDATE_GUEST_SESSION_FAILED: file_db.c:3968 Guest user session validation failed for guest_user10. Index provided is out of range..
The user that is assigned to the guest_user10 account works fine and has no idea this error is occurring.
This error message is occuring exactly every 15 minutes 24x7.
I believe I have a rogue user who has setup a device to try and login to the guest network automatically, every 15 minutes with the guest_user10 credentials. I need to track this device down. I need a way to find either the MAC or IP address of the device that is causing this error message. I have tried turning on AAA debugging on the controller but I dont get anything more than the above error. I have also tried using WCS to look at the client history but it only show the normal activity.
View 3 Replies
View Related
Jul 24, 2012
I just get to hands-on on my new WLC 5508?
1) I'm using a single subnet eg 192.168.1.0/24 for my wireless clients and i'm assigning them via the DHCP server from the WLC. As the clients are however made up of laptops and scanners, i would like to assign a range from 50-150 for the laptops and 151-250 for the scanners for easier identification. But it seems that from the WLC DHCP menu i'm not able to do this unless i segment them into a different network with different gateways.
2) Is there anyway to change the WLC user accounts password too? I dont seems to be able to find the option unless i delete the account and re-create it with the new password.
View 5 Replies
View Related
Aug 12, 2011
how to set WLC 5508 to allow single create web authentication user account to get connected in a same time. i found that i can use the same username and password combo to be login in 2 machine in the same time.
View 4 Replies
View Related
Jan 18, 2013
I work at a campus and use the WCS to control access to my network for staff and only internet access for students. The Staff are assigned Username/password thru active directory and the student uses another SSID with only WPA --a password for all. I was tasked with adding more securing for students -- by adding a user/password. I do not want them connecting to my Active Directory for two reason--security risk and I have too many to input (over 1000). So, I wanted to use our internal database to validate users. I create a webpage with "WebAuth" that opens my logon page from my site and validates the login fields against the database. It works and this allows the user to navigate thru my website but not outside the site. If they try an outside url it redirect them to my logon script. I now understand why, so I'm looking for code I can add to my logon page that would allow me to redirect me to the controller's (once users are authenticated by my database) to call the WCS controller so I can enter a preset username/password so the policy management file would allow them access. I presently use "External" and don't know if "Custom" would work. Finding a way in using a database instead of adding one person at a time?
View 3 Replies
View Related
Aug 28, 2012
I wanted to ask if there is a collection filter in the ISE similar to ACS 5.3, where I can filter out unwanted syslogs.
View 2 Replies
View Related
Aug 20, 2012
This first started when a user said they were getting disconnected and reconnected a few times a day to our wireless network. He is in a remote office with a 1142 which is set to H-Reap talking back to our 5508. Our WLC is running 7.0.166 The laptop has an intel ulitmate 6300agn wireless card with the latest 15.x drivers.
We are using an SSID with wpa2 and 802.1x auth back to our ACS server using PEAP with our windows credentials.attached is what i am seeing on the wcs troubleshooting page.When i do a debug client on the WLC i see many reauthentications coming from the client on the different radio.
*apfMsConnTask_2: Aug 22 12:59:36.762: 00:24:d7:d1:16:6c Reassociation received from mobile on AP 0c:85:25:f3:7d:40
*apfMsConnTask_2: Aug 22 12:59:36.762: 00:24:d7:d1:16:6c 10.24.8.108 RUN (20) Changing ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:1621)
*apfMsConnTask_2: Aug 22 12:59:36.762: 00:24:d7:d1:16:6c Applying site-specific IPv6 override for station 00:24:d7:d1:16:6c - vapId 512, site 'VH-GasWorks', interface 'management'
*apfMsConnTask_2: Aug 22 12:59:36.762: 00:24:d7:d1:16:6c Applying IPv6 Interface Policy for station 00:24:d7:d1:16:6c - vlan 2, interface id 0, interface 'management'
*apfMsConnTask_2: Aug 22 12:59:36.762: 00:24:d7:d1:16:6c Applying site-specific override for station 00:24:d7:d1:16:6c - vapId 512, site 'VH-GasWorks', interface 'management'
*apfMsConnTask_2: Aug 22 12:59:36.762: 00:24:d7:d1:16:6c 10.24.8.108 RUN (20) Changing ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:1621)
*apfMsConnTask_2: Aug 22 12:59:36.762: 00:24:d7:d1:16:6c STA - rates (8): 140 18 24 36 48 72 96 108 48 72 96 108 0 0 0 0
*apfMsConnTask_2: Aug 22 12:59:36.762: 00:24:d7:d1:16:6c Processing RSN IE type 48, length 38 for mobile 00:24:d7:d1:16:6c
[code]....
Now this may be not be the issue thats causing our dropouts a couple times a day as this is happening every 5 mins.
View 12 Replies
View Related
May 25, 2013
I have 5508 controller in my lab. I am working on a project to set up a public internet but with some condition.
- User should able to connect to the SSID without any authentication.
- Once user will connec to the SSID it should redirect to an external URL which indicates terms and condition and email address field.
- User should enter his/her email address in email addrss filed and click I accept button.
- Once that is done then he/she is allowed to access internet.
We are not sure how can we achive this as I do not know what should be the return value for WLC to allow that user to go through or what should be the settings on the WLC to redirect to the page.
I have seen a settings on web authentication for external URL but I guess it is only for username passwor or Radius authentication. While in this case I do not want to use any authentication just an accept buttor or Decline button and all good to go.
View 2 Replies
View Related
Jul 24, 2012
When a guest user first trys to access the "guest" WLAN, they are presented with a "certificate page" before the web athentication page / login is presented. The WLC forces an internal redirect to https://1.1.1.1 causing the certificate page to appear. Can this be bypassed? I am runiing 5508 with 7.0.220.0.
View 12 Replies
View Related
Oct 31, 2011
I currently have 2 WAN links, a 20MB Ethernet BGP MPLS and a bonded T1. I have a 2800 at each end configured to automatically fail over to the T1 in the event that the MPLS goes gown. I put a high AD on the T1 connection with static routes. If the MPLS goes down the T1 does kick in, however users are dropped from their applications and VOIP calls are disconnected.
I was looking into Fat Pipe appliances and they supposidly will fail over a connection without any packet loss - therefore not dropping a VOIP call or kicking anyone off the database application. In addition they will provide aggregated bandwidth.
Is there any way to achieve a similar failover without packet loss with just the routers? Do I really need to purchase the Fat Pipe to achieve this? Are there any alternatives?
View 3 Replies
View Related
Mar 9, 2011
Any Cisco command similar to Junipers monitor interface interface type / number. It's handy seeing real time interface stats. monitor interface?
View 5 Replies
View Related
Sep 9, 2012
I have a 2600 Router that has been donated to my use for some lab work. The thing was locked down pretty well. I have console access to it (obviously) but there is a console PW assigned. How can I reset the silly thing back to factory defaults including wiping the con PW? I cannot get to it to reset the boot register from 2102 to 2142 or similar. Is there a way to bypass this and reset the device?
View 4 Replies
View Related
Apr 17, 2012
Do Cisco Catalyst (IOS) and specially Cisco SG300/500 support a similar feature to HP's Loop Protection or DLINK's Loopback Detection? This is an interesting feature to avoid loops caused by unmanaged switches.
View 6 Replies
View Related
Oct 30, 2012
Is there a Cisco wall-plate model? Something similar to HP E-MSM317 and Ruckus 7025? I had look on the web but couldn't find anything.
View 3 Replies
View Related
May 6, 2013
after upgrading about 35 Catalyst 2960 and Catalyst 2960S to IOS 15.0(2)SE2, we experience a memory leak on several switches. After some days / weeks the switches are not accessible via Console/Telnet/SSH/Web any more. Only SNMP seems to work properly.Attached users do not experience any decrease in service.
Trying to connect to the console, we get following error message:
"% Low on memory; try again later"
The only (temporary) solution is to reboot the switch. The behavior is similar to Bug CSCts52797.With regards to the Bug notes this bug should only affect Catalyst 2960 with 64MB of RAM and should already be solved with IOS 15.0(2)SE2.
We experience the erroneous behavior with
-WS-C2960-48TC-S running IOS 15.0(2)SE2
-WS-C2960S-48LPS-L running IOS 15.0(2)SE2
View 7 Replies
View Related
Aug 28, 2012
I've noticed a strange behaviour in my 2960s regarded to CPU.
CPU level is very high, 70-75% when nobody is logged by vty or console, but it drops drastically to 40% when sombebody logs in. I've been able to discover that this is due to CPU interrupt level, as it shows the output of sh process cpu sort 5sec, just logged in.
RH0A01-SW1-10G#sh proces cpu sorted 5sec
CPU utilization for five seconds: 68%/37%; one minute: 67%; five minutes: 50%
...Some seconds after logged in...
RH0A01-SW1-10G#sh proces cpu sorted 5sec
CPU utilization for five seconds: 35%/11%; one minute: 52%; five minutes: 48%
View 3 Replies
View Related
Mar 27, 2011
Some1 browse my PC via LogMeIn Hamachi, so i need 2 know who did that , how 2 see the log list?
View 1 Replies
View Related
Aug 30, 2012
how can i find out who logged in and out of my laptop
View 1 Replies
View Related
Jan 28, 2012
I just bought the Dir-655 with 2.00 firmware. I am having trouble with my NAT on my game system and I have tried everything but I have everything setup on my router where it needs to be. I read somewhere, where a guy was having my same trouble and he upgraded his firmware to 2.03na. I have tried with no success whatsoever.
Downloading the file from the d-link website with no problems. But i keep getting the same message when i try to upgrade the router saying the file may be corrupt, the router is to busy, or I am not logged in as an Admin. I am the only one using the internet and I am logged into my router as the admin. it wont even start uploading the firmware to my router..
View 9 Replies
View Related
Jan 3, 2012
In case I view the crashinfo file with more crashinfo:data, there is a "Log buffer:" section, which has logged all the commands executed by users.
View 4 Replies
View Related
Sep 5, 2011
After some time no using Cisco ACS5.1, I still don't know how I can see all logged in users. I can see logging and check why an log in goes wrong, but in ACS 3.2 I just clicked on Reports and Activity and I could choose to see logged in users, or failed attempts, etc.
View 2 Replies
View Related
Aug 7, 2011
I have a DIR-655. Whenever I log into the router to review settings, I get kicked back to the login screen. I can't get to any of the menus. I'm running the A3 hardware version and 1.35 firmware on the router. I recently upgraded my computer from Vista 64-bit to Windows 7 64-bit. The problem occurs with Microsoft and Firefox browsers. I was able to access the router using another machine on my home network running Vista 32-bit
View 16 Replies
View Related
May 7, 2013
Is it possible to see device information for equipmnet that is logged into the AP541N access point? I was able to determine a specific IP address was eating a significant amount of bandwidth and was hoping to get the device information (name, type, etc) in the hopes of tracking down who it was.
View 1 Replies
View Related
Apr 9, 2012
What I got is a 5505 ASA firewall and I'm connected to it via VPN. I'm pulling an 192.168.169.x address because that's what we set their company's internet LAN to. Which is what we want. What I can't do while I'm VPN'd in is ping from the internet network to the DMZ, and the same when I try and ping from the DMZ to the internal network.
The DMZ is on a 196.0.0.x network.The internet network is 192.168.169.x network.
I don't need them to have internet access on the DMZ I just want to be able to access it from the internal network. What is going on is we need them to be able to VPN into the DMZ and access their equipment. At this point it would just make me happy to be able to ping from the internal network to the DMZ and I can figure it out from there I've setup rules and applied them and when I wasn't having success I referred back to defaults. Right now the rules are set at default, any thing in and anything out, on both internal and DMZ. I'm using a VPN client and going through Cisco ASDM Launcher to setup the rules and static routes, I haven't done anything with the command line. All the research I've done everyone does it command line, I find it easier to do it GUI. This is my first time working with an ASA firewall.
View 2 Replies
View Related
Sep 13, 2011
is there a way to see who logged on my network at any time during the day/week/month?
View 1 Replies
View Related