Re: 802.1x with ACS 5.0 and WLC PEAP/MSCHAPv2

From: Alexei Monastyrnyi <alexeim73_at_gmail.com>
Date: Wed, 22 Jul 2009 20:11:19 +1000

Hey Lora.

I haven't seen ACS 5 live but from what you have told us, this shouldn't
be a version-specific issue.

I'd check the following:
- if there is a port mismatch on WLC vs ACS, i.e. 1645 vs 1812 or the
other way around.
- if you block those ports somewhere in between.
- if your WLC IP address is AAA client for ACS with correct shared secret.
- if your logging for failed attempts is configured correctly on ACS (it
is all right by default)

I'd also try to download some RADIUS authentication test tool, plenty of
them, just google for one.

HTH,
A.

Lora Ganeva wrote:
> Dear experts,
>
>
>
> I am facing problems with the following setup:
>
>
>
> Cisco WLC with light weight APs and the latest ACS 5.0.
>
> I am trying to put a successful PEAP session, but for some reason RADIUS
> requests are sent from the WLC towards the ACS, but there is no response
> from the Radius. One additional problem with troubleshooting is the fact
> that my ACS fails to log this communication. The ACS is trial and I
> cannot contact the TAC for support. Do you have any experience in
> scenarios like this?
>
> Clients are windows XP SP3 computers with all the Microsoft settings and
> hotfixes applied, incl. registry settings, etc.
>
>
>
> Any help will be appreciated,
>
>
>
> Thanks in advance,
>
> Lora
>
>
> Blogs and organic groups at http://www.ccie.net
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html

Blogs and organic groups at http://www.ccie.net
Received on Wed Jul 22 2009 - 20:11:19 ART

This archive was generated by hypermail 2.2.0 : Sat Aug 01 2009 - 13:10:23 ART