Activation of RADIUS Auth/Acct on WLAN controller 4402

Hi all

Just need to activate authentication RADIUS and accounting on Cisco 4402 WLAN controller, so this controller WLAN what admins can be authenticated through a RADIUS server.

I want to assure you that I could connect via the console or the local user account, if the RADIUS auth/acct on WLAN controller does not work for some reason any. I don't want me locked out if RADIUS auth/acct does not work.

I have set up RDIUS for switches cisco 3750 and works very well.

any suggestions please.

Thank you very much.

Keita.

You must set the order

Security > priority > user management

Network user is for wireless authentication.

~ BR
Jatin kone

* Does the rate of useful messages *.

Tags: Cisco Security

Similar Questions

  • WLAN controller redundancy

    What is the method to provide redundancy to the WLAN controller

    the function?

    The unified access point allows a backup controller WLAN? In this case, the configuration of the two controllers is automatically synchronized?

    Hi Andres,

    The world of WLC is how an AP is covered in case of failure of a WLC. It is not without some "down time" in case of failure, but two controllers are active. You must keep in mind that the AP cannot be certified a WLC both so it of the best you can do when a WLC fails AP then must re - register with the backup, it is not a process completely seamless.

    This has some really good info;

    WLAN controllers to access tipping points light Configuration example

    http://www.Cisco.com/en/us/Tech/tk722/tk809/technologies_configuration_example09186a008064a294.shtml#C4

    For more recent versions of release WLC (there are also)

    Controller LAN wireless and lightweight external Tipping Points access the sample Configuration of mobility group

    http://www.Cisco.com/en/us/Tech/tk722/tk809/technologies_configuration_example09186a00809817ca.shtml

    See you soon!

    Rob

    Thank you to support CSC helps Haiti

    https://supportforums.Cisco.com/docs/doc-8895

    https://supportforums.Cisco.com/docs/doc-8727

  • Inconsistent WLAN controller with AP 'AIR-LAP1142N-E-K9.

    Hi all

    We have awireless LAN Controller "Cisco 4402 with software version 3.2.150.10" we use the Access Point 'AIR-LAP1242AG-E' and his works fine, we bought the new APs with the model "AIR-LAP1142N-E-K9" but its not working with our controller and restart continuously. I connected the console and checked the logs from the console that is given below. Please let me know is this controller WLAN is compatible with the APs new or not, or do I need to upgrade the operating system of the LAN Controller and if I upgrade the operating system of the WLAN controller it will support the old APs or not.

    Thank you in advance for your response and support.

    32K bytes memory simulated by flash not volatile configuration.
    Basic Ethernet MAC address: C4:7 D: 4F:3 A: 9E:D0
    Part number: 73-11451-08
    Kit numbered PCA: 800-30554-06
    Revision number of PCA: A0
    Serial number of PCB: FOC14080B1U
    Top Assembly part number: 800-31273-04
    Top of page the Assembly serial number: FCZ1414W1X5
    Top of page revision number: A0
    Product/model number: AIR-LAP1142N-E-K9
    % Please first set a domain name.

    Press RETURN to get started!

    * 00:00:06.561 Mar 1: * CRASH_LOG = YES
    MAC Ethernet address of base: C4:7 D: 4F:3 A: 9E:D0

    * 00:00:06.749 Mar 1: % LWAPP-3-CLIENTEVENTLOG: reading and initialized event AP log (contains 82 messages)

    * 00:00:08.794 Mar 1: % LINK-3-UPDOWN: Interface GigabitEthernet0, changed State to
    * 00:00:08.810 Mar 1: % SYS-5-RESTART: System restarted.
    Software Cisco IOS, C1140 Software (C1140-RCVK9W8-M), Version 12.4 JA (21 a), RELEASE SOFTWARE (fc1)
    Technical support: http://www.cisco.com/techsupport
    Copyright (c) 1986-2009 by Cisco Systems, Inc.
    Updated Tuesday 8 June 09 16:28 by prod_rel_team
    * 00:12:08.010 Mar 1: % CAPWAP-5-CHANGED: CAPWAP changed state of DISCOVERY
    * 00:12:08.982 Mar 1: % LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0, changed State to
    * 00:12:18.211 Mar 1: % ADDRESS_ASSIGN-6-DHCP: Interface GigabitEthernet0 assigned address DHCP 172.20.20.228, mask 255.255.255.0, hostname APc47d.4f3a.9ed0

    * 00:12:28.972 Mar 1: % CDP_PD-2-POWER_LOW: all disabled radios - WS-C3560G-48PS NEGOTIATED (0026.98a6.2786)
    Translate "CISCO-CAPWAP-CONTROLLER"... the domain server (192.151.106.8) (192.151.106.6)

    Translate "CISCO-LWAPP-CONTROLLER"... the domain server (192.151.106.8) (192.151.106.6)

    * 00:12:37.968 Mar 1: % 3-CAPWAP-ERRORLOG: did not get the server DHCP server log settings.
    * 00:12:37.971 Mar 1: % 3-CAPWAP-ERRORLOG: could not resolve CISCO-CAPWAP-CONTROLLER
    * 00:12:37.973 Mar 1: % 3-CAPWAP-ERRORLOG: could not resolve CISCO-LWAPP-CONTROLLER
    * 00:12:47.974 Mar 1: % 3-CAPWAP-ERRORLOG: go join a lwapp controller
    * 00:12:47.974 Mar 1: % LWAPP-3-CLIENTERRORLOG: put AddressCalled of Transport
    Writing of the
    * 00:12:47.981 Mar 1: % LWAPP-5-CHANGED: CAPWAP changed State to ADHERE
    * Jun 29 16:32:00.616: % SYS-4-PUPDATECLOCK: periodic update clock with ROMMON failed because size left in ROMMON (4294967295), large (29), error code (- 1).
    * Jun 29 16:32:00.616: % SYS-5-RELOAD: reload LWAPP CUSTOMER the request. Reason for charging: CONTROLLER INCOMPATIBLE VERSION.
    * Jun 29 16:32:00.616: % LWAPP-5-CHANGED: CAPWAP changed state at the bottom of the event log in NVRAM...

    using the values from the eeprom

    WRDTR, CLKTR: 0 X 86000800 0X40000000
    RQDC, RFDC: 0X8000003B 0X0000020F

    init done DDR

    IOS Bootloader - start System.
    XMODEM file system is available.

    DDR used values of the system serial eeprom.
    WRDTR, CLKTR: 0 X 86000800, 0 X 40000000
    RQDC, RFDC: 0X8000003B, 0X0000020F

    PCIE0: the connection is established.
    PCIE0: VC0 is active
    PCIE1: the connection is established.
    PCIE1: VC0 is active
    PCIEx: initialization done
    flashfs [0]: 5 files, 2 folders
    flashfs [0]: 0 orphaned files, orphaned directories 0
    flashfs [0]: Total number of bytes: 32385024
    flashfs [0]: bytes used: 2271744
    flashfs [0]: available bytes: 30113280
    flashfs [0]: flashfs fsck took 16 seconds.
    The system eeprom read cookie series... Fact
    MAC Ethernet address of base: c4:7 d: 4f:3's: 9e:d0
    Ethernet speed is 1000 MB - FULL duplex
    Loading "flash:/c1140-rcvk9w8-mx/c1140-rcvk9w8-mx"...#######################################################################################################################################################################################################################

    File "flash: / c1140-rcvk9w8-mx/c1140-rcvk9w8-mx" unzipped and installed, point of entry: 0x4000
    execution of...
    ENET stopped

    If you have login valid ORC, go to Support > download software > > Cisco Wireless LAN Controller 4402 Wireless > Wireless LAN Controller Software

    Release notes for the controllers wireless LAN Cisco and Points of light access for version 7.0.98.0

    http://www.Cisco.com/en/us/docs/wireless/controller/release/notes/crn7.0.html

    Upgrading to a new version of the software

    http://www.Cisco.com/en/us/docs/wireless/controller/release/notes/crn7.0.html#wp472449

    Remember messages useful rate.  Thank you.

  • WLAN controller download

    Hello

    I bought a new controller (model 2500) Cisco wlan and a point of access from a provider certified Cisco. Can I register the controller on the

    Site Web of Cisco to enable access download software associated with this controller? I want to download the latest version of the software "AIR-CTVM-K9-8-0-100-0.aes".

    but I'm not allowed according to my profile.

    So, how can I access the latest version of the software for my 2500 WLAN controller?

    Concerning

    Gideon

     Can I register the controller on the Cisco website to enable access to download software related to this controller?

    Yes and no.

    The quick answer is no. your authorized reseller of Cisco should be able to "join" the serial number of your WLC in your Service Agreement and your Service agreement is attached to your CCO login.

    If you go direct to Cisco, it will take time to get to the bottom of the details, you need to provide a lot of information so it's best to get your Cisco reseller to contact them.

  • 2112 WLan controller and Point of access LAP1042n issue

    Hello

    I recently bought a 2112 a Wlan controller a number of LAP1042n Ap of the AP will not join the command and the message I get in the console of the AP, it is that the AIR-WLC2100-K9-6-0-199-4.aes firmware does not support this model?  Can someone please verify that this is the case?

    Firmware AIR-WLC2100-K9-7-0-98-0.aes to overcome this problem?

    Thanks in advance

    David

    Yes, 7.0 doesn't suppoert he...

    CHECK THE RELEASE NOTES for more details...

    http://www.Cisco.com/en/us/docs/wireless/controller/release/notes/crn7.0.html

  • [WLAN controller] Unplug the PC Client in AP

    Hi guys,.

    How can I disconnect client PC to help AP Wireless LAN controller 4402? Only, I can disconnect my APs but not the client of the AP.

    Thanks in advance.

    You're not the only one who is busy! :)

    When you choose to "CONTAIN" an AP, client or something, it means that up to 4 of your KNEES, will adopt an approach of Robin and transmit a massive amount to authenticate the package for the poor bastard. Basically, he's got a back and the target will not be able to authenticate on your wireless network until you raise containment. So be sure you want to do this.

    The main Web page, Ad - Hoc Snape. You can find the MAC address of your target customer wireless. Click on this. In a new page, you will find a number of drop-down menus. Choose "external", "malicious" and choose the number of APs, and then you choose contains.

    \Hope this helps.

  • Upgrade of Cisco Wireless Controller 4402

    We have a 4402 WLAN controller with a bunch of AP in 6 locations. The software is installed on a Windows Server 2003 server - since our society must be in accordance with various compliance agencies, we are in the process of getting rid of all 2003 servers in our infrastructure as they will be supported are more early next year.

    I created a new server (2012 R2) and tried to install, but get the error that it is only supported on Server 2003 or Red Hat.

    Is there a way to get this installed on one different platform other than 2003?

    Thank you!

    Yes, you can keep the same equipment (WLCs and AP).

    I was just saying about upgradation WCS to the CNS / prime infrastructure

    NCC/WCS are just a management for wireless LAN controllers APs. so if you change the WCS to the CNS, then it will affect any service.

    Concerning

    Remember messages useful rates

  • Problem upgrading controller 4402

    I've updated all our 5508 controllers without problems, but when I try to upgrade our controller 4402 I get error "Failed storing Flash TFTP!".

    Tftp tried different programs including the tftpd32 and tftpd64 on the local network.

    The current Firmware is 7.0.98.0 update to 7.0.240.0

    I looked for answers, but everyone says to use tftpd on LAN which I do.

    Update *.

    Even if copied to the controller and extracted firmware, it seems that my error was due to a corrupted file.

    I downloaded the firmware again and it worked successfully.

    Thanks sprocket, is that simple, repeated measures for each file.

    Tell me, I just download the TFTP file and I see the message on the controller, is - right below? Should I just wait to complete the installation?

    "TFTP receive full... extraction of components."

  • Bundle of Web authentication on a WLAN controller integrated Catalyst 3750

    We have set up a wifi zone based on a few 1131AG access points and a few Cisco 3750 integrated WLAN controllers. We are now trying to use web authentication for our comments area. No problem by defining a WLAN of COMMENTS and the associated VLAN. We have also managed to download a custom controller authentication web page.

    However, when I try to display the custom page, both controllers of show me the internal default page (preview and during the phase of actual authentication).

    Global web authentication settings are the following: Security--> Auth Web--> Web Login Page--> custom (downloaded).

    On the controller software version is 4.2.112.0, and the page is an HTML page.

    Reveal any help be appreciated.

    Kind regards

    Sonia

    What you need to do is set internally (by default) and hit apply, then play again to custom and click on apply. You can still see the defaul if you use the preview, but if you associate the SSID and open your web browser, you should get the webauth page. I hope this helps.

  • RADIUS Auth Login and VPN is in conflict...

    Hello

    Im trying to setup a 7204 to authentication radius connection, even if the router is also configured with RADIUS for VPN access. How can I configure it for both using 2 raidus different servers? the connection through RADIUS works fine on another router, although this one does not have VPN access so there is no conflict.

    My config:

    / * Style definitions * / table. MsoNormalTable {mso-style-name : « Table Normal » ; mso-tstyle-rowband-taille : 0 ; mso-tstyle-colband-taille : 0 ; mso-style-noshow:yes ; mso-style-priorité : 99 ; mso-style-parent : » « ;" mso-rembourrage-alt : 0 à 5.4pt 0 à 5.4pt ; mso-para-marge-top : 0 ; mso-para-marge-droit : 0 ; mso-para-marge-bas : 10.0pt ; mso-para-marge-left : 0 ; ligne-hauteur : 115 % ; mso-pagination : widow-orphelin ; police-taille : 11.0pt ; famille de police : « Calibri », « sans-serif » ; mso-ascii-font-family : Calibri ; mso-ascii-theme-font : minor-latin ; mso-hansi-font-family : Calibri ; mso-hansi-theme-font : minor-latin ; mso-bidi-font-family : « Times New Roman » ; mso-bidi-theme-font : minor-bidi ;} rayon de serveur AAA groupe RADIUS_AUTH
    Server x.x.3.11 auth-port 1645 acct-port 1646

    / * Style definitions * / table. MsoNormalTable {mso-style-name : « Table Normal » ; mso-tstyle-rowband-taille : 0 ; mso-tstyle-colband-taille : 0 ; mso-style-noshow:yes ; mso-style-priorité : 99 ; mso-style-parent : » « ;" mso-rembourrage-alt : 0 à 5.4pt 0 à 5.4pt ; mso-para-marge-top : 0 ; mso-para-marge-droit : 0 ; mso-para-marge-bas : 10.0pt ; mso-para-marge-left : 0 ; ligne-hauteur : 115 % ; mso-pagination : widow-orphelin ; police-taille : 11.0pt ; famille de police : « Calibri », « sans-serif » ; mso-ascii-font-family : Calibri ; mso-ascii-theme-font : minor-latin ; mso-hansi-font-family : Calibri ; mso-hansi-theme-font : minor-latin ; mso-bidi-font-family : « Times New Roman » ; mso-bidi-theme-font : minor-bidi ;} radius AAA authentication connexion networkaccess groupe local

    / * Style definitions * / table. MsoNormalTable {mso-style-name : « Table Normal » ; mso-tstyle-rowband-taille : 0 ; mso-tstyle-colband-taille : 0 ; mso-style-noshow:yes ; mso-style-priorité : 99 ; mso-style-parent : » « ;" mso-rembourrage-alt : 0 à 5.4pt 0 à 5.4pt ; mso-para-marge-top : 0 ; mso-para-marge-droit : 0 ; mso-para-marge-bas : 10.0pt ; mso-para-marge-left : 0 ; ligne-hauteur : 115 % ; mso-pagination : widow-orphelin ; police-taille : 11.0pt ; famille de police : « Calibri », « sans-serif » ; mso-ascii-font-family : Calibri ; mso-ascii-theme-font : minor-latin ; mso-hansi-font-family : Calibri ; mso-hansi-theme-font : minor-latin ; mso-bidi-font-family : « Times New Roman » ; mso-bidi-theme-font : minor-bidi ;} groupe par défaut AAA autorisation exec RADIUS_AUTH if-authentifié

    / * Style definitions * / table. MsoNormalTable {mso-style-name : « Table Normal » ; mso-tstyle-rowband-taille : 0 ; mso-tstyle-colband-taille : 0 ; mso-style-noshow:yes ; mso-style-priorité : 99 ; mso-style-parent : » « ;" mso-rembourrage-alt : 0 à 5.4pt 0 à 5.4pt ; mso-para-marge-top : 0 ; mso-para-marge-droit : 0 ; mso-para-marge-bas : 10.0pt ; mso-para-marge-left : 0 ; ligne-hauteur : 115 % ; mso-pagination : widow-orphelin ; police-taille : 11.0pt ; famille de police : « Calibri », « sans-serif » ; mso-ascii-font-family : Calibri ; mso-ascii-theme-font : minor-latin ; mso-hansi-font-family : Calibri ; mso-hansi-theme-font : minor-latin ; mso-bidi-font-family : « Times New Roman » ; mso-bidi-theme-font : minor-bidi ;} rayon-serveur hôte x.x.3.11 auth-port 1645 acct-port 1646 clé xxxxxx

    line vty 0 15

    / * Style definitions * / table. MsoNormalTable {mso-style-name : « Table Normal » ; mso-tstyle-rowband-taille : 0 ; mso-tstyle-colband-taille : 0 ; mso-style-noshow:yes ; mso-style-priorité : 99 ; mso-style-parent : » « ;" mso-rembourrage-alt : 0 à 5.4pt 0 à 5.4pt ; mso-para-marge-top : 0 ; mso-para-marge-droit : 0 ; mso-para-marge-bas : 10.0pt ; mso-para-marge-left : 0 ; ligne-hauteur : 115 % ; mso-pagination : widow-orphelin ; police-taille : 11.0pt ; famille de police : « Calibri », « sans-serif » ; mso-ascii-font-family : Calibri ; mso-ascii-theme-font : minor-latin ; mso-hansi-font-family : Calibri ; mso-hansi-theme-font : minor-latin ; mso-bidi-font-family : « Times New Roman » ; mso-bidi-theme-font : minor-bidi ;}      login authentication networkaccess

    The line below is used for VPN authentication:

    RADIUS-server host x.x.8.12 auth-port 1812 acct-port 1813 key xxxxxx

    AAA of authentication ppp default local
    Ray of AAA to authenticate ppp vpdn group

    AAA authorization network default local
    RADIUS AAA authorization network vpdn group
    Group AAA authorization auth-proxy default RADIUS
    AAA accounting delay start
    accounting AAA periodic update 5
    start-stop radius group AAA accounting network default

    For some reason, it does not. I can't access the router and authenticate via radius x.x.3.11 server. I think there is a conflict between the VPN and authentication of connection but im not sure how to solve this problem.

    any help would be greatly appreciated.

    "ray of aaa of ppp authentication vpdn group.

    'radius of group' means 'take any server radius from the global list'.

    Change it to 'group mygroup' and boom, you give it a subset of radius servers

  • Satellite Pro 6050: WLan controller does not seem to be in Device Manager

    I'm a novice guy with computers.

    Well, I re-formated my laptop and re-installed all the drivers, but my wirless lan controller does not seem to be in my device manager.
    I was just wondering, if the driver needed to be installed in a certain order. I also had my add on the Vodaphone mobile card plugged into slot on the side that would make a difference?

    in any well any help would be great
    Dane :-)

    Hello

    As far as I know that the WLan card was optional on this unit. In this case, if you bought the device with wireless network card that WLAN should appears in Device Manager. But if you bought the laptop without the WLan card you won't find it in Device Manager.

    PS: The recovery CD already includes the WLan driver and you don't need to t in addition no driver to install.

  • Restrict the use of data - WLAN controller

    Hello

    I am designing a solution for a hotel WiFi facility. This is mainly to provide access to the visitors of the hotel.

    I wonder bandwidth throughput on a per customer basis - which I know can be done on the controller.

    I was also asked to verify if the use of data restrictions may be implemented by the customer.

    For example, they want that the restriction of the use of 1 GB / 2 GB on their visitors, after which they are not able to access the network without additional authorization.

    Is there a way to do this on a Cisco controller?

    Thank you

    Rahul Nair.

    This doco is convenient for the speed limit:

    http://www.Cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/113682-BDR-limit-guide-00.html

    In addition, Rasika explains very well vs TCP UDP in a blog:

    https://mrncciew.com/2013/05/01/per-user-rate-limit-in-WLAN/

    Regarding limiting the total data of a user; I don't think it's possible with just a Cisco WLC. You would probably need some kind of third-party tool... I can't find much except this post earlier which is probably still very relevant:

    https://supportforums.Cisco.com/discussion/12101991/guest-WiFi-solution-hotel-industry

  • WLAN controller

    Hi all

    I always thought that we need two WLAN controllers for reliable connectivity, just in case where a single controller down APs can reach the second controller (backup). one of the reference expertise Cisco, that no two controllers need after APs connect same controller down APs will continue to work. Can you someone confirm please?
    My understanding if the controller of down and APs power recycling would be down. Any help would be appreciated.

    Thank you

    Kumaran

    I always thought we need two WLAN controllers for reliable connectivity just in case one controller goes down APs can join the second controller (backup).
    Fix.
    one of Cisco expert mention that no need for two controllers after APs connect even controller go down APs will continue to work.
    IF the access points are in mode FlexConnect (and a local authentication server is present), it is possible, as long as the APs are NOT restarted.
  • How many active paths by a LUN on the controller use Active/Active array.

    Hi all

    I have a symmetrical controller active/active table and two HBAs on the host ESXi (also two SAN switch).

    In this case, I have 4 paths per LUN, right!

    I wonder how active paths by a logic unit number exist at the same time, when I put the round robin PSP.

    and also how much marketshares of controller active/active table against active-passive array controller in production about.

    Thank you all.

    VAAI provides a provisioning also with many other functions.

    Discount in State of TP is disabled ESXi5 U1 and more, due to the performance bugs (bad enough). See the following KB: http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=2007427

    It is rehabilitation possible storage when I delete some files on the virtual machine (not delete any VM storage vMotion)?

    No - TP reclaramtion only works on removing a VMDK set.

    In other words, VAAI with Thin Provisioning supports retrieval based on storage when vDisk VM has been diminished?

    N °

    If so, how VAAI note thereon made vDisk was decreased?

    This isn't.

  • Satellite L750 - WLan controller driver is not installed

    Hello

    I formatted the laptop above using the hidden partition.
    Since that the wireless network controller is not installed and I can not find the drivers for it.

    Could someone help, please

    Thank you
    Dave.

    Hello

    Can you please post model mobile exact please?

    Back to your problem: what did you do exactly? Have you installed original recovery image and try to reuse for laptop with factory settings?

    Sorry for this question but I m confused a little. In General, after recovery image installation, all drivers must be installed correctly.
    What is the status of your WIFI card in Device Manager?

Maybe you are looking for

  • Cannot load 60% of Web pages

    I am running El Capitan 10.11.3 on an iMac 21.5 "(end of 2009) What follows is true on the browsers Chrome (52.0.27), Firefox (45.0.2) and Safari (9.0.3): browser does not open 60% of websites attempt, NYtimes, google scholar, include chase, jadefitn

  • Remove (adware) Firefox 38.

    I have a bug that overwrites the data in the Start Page for Firefox 38. There is a link. I really want to get rid of it. Ran Ad-aware, Malware - didn't find it. It only happens in Firefox. Can you help me?

  • Qosmio X 770-107 Bootmgr missing

    Greetings,had to reinstall my Qosmio and used the solution of recovery for that, unfortunately, the process was interrupted because of an error. I couldn t boot my system later because "Bootmgr is missing". There was no bootcd in Accessories for lapt

  • Problem writing to / reading a binary file in a loop

    Hello As you can see in the image of rasthaus, I try to write a 2 * 202 data set in each iteration of the loop the loop, but when I try to read the data (on the second picture) I only have the first (or, I guess) set of data, up to 202 index. I neede

  • Microsoft updates installation gives me an error 800706BE

    I had just reinstalled Windows 7 Enterprise 64-bit on a reformatted hard drive. The first thing I did once inside, ran Windows Update and start installation updates one by one (with a system reboot between each of them, even if it was not necessary).