Question order AAA

Hi can someone explain me how the WLC (4402) decides which server to use for AAA?

I have two servers set up as servers AAA, one with an index of 1 server and the other with an index of 2

Index 1 = x.x.x.70

Index 2 = x.x.x.38

AAA of one of my wireless networks tab I listed them as:

Server 1 = x.x.x.38

Server 2 = x.x.x.70

This is the Index number that is the deciding factor? What is the order in which they are listed AAA tab in wlan config page?

See you soon

Dylan

Hello

There are two ways to set the priority of the Radius server. If you have servers Radius defined under the WLAN will serve first of all the server defined as server 1, Server 2 will be used then, and so forth. If you do not have the Radius servers, listed under the WLAN, they will be used in the order that they appear in the global configuration (index).

Backup RADIUS configuration will come also into play.  If you have RADIUS rescue disabled when the Radius primary server goes down the startup using secondary controller, but it goes back to primary school up until high school fails or the controller is restarted. If you have activated the controller will start using the primary server when it becomes available again.

So, in addition to my head, these are the things that are coming...

Can you please check the logs failed on the server to make sure that there are not all messages concerning requests for the controller?  May be that the shared secret key is not matching or the controller is not defined in the server.

Even try to ping the server of WLC and see the connectivity...

or even...

check if there is no firewall problem between the WLC and the RADIUS server.

Let me know if this answers your question!

Concerning

Surendra

====

Please do not forget to note the useful post that answered your question or was useful

Tags: Cisco Wireless

Similar Questions

  • ESSCMD - question order IMPORT

    Hello

    I use EMP 11.1.2.2. In the Esscmd for importing, I use Text file has the type of file to load the data and I have no error, but the technical reference guide says Essbase text file is not supported. Can you please clarrify.

    IMPORT the data file digital fileType y/n y/n [ErrorFile] rulobjName ruleLoc

    file type of the data file file. Values:

    1 - Excel file

    2 - lotus 2 file (no longer supported)

    3 - file lotus 3 (no longer supported)

    4 - text file (no longer supported)

    5 - lotus 4 file (no longer supported)

    Thanks for your help.

    His true right there in the documentation - it may well work well.   MaxL is documented to work using .txt files!

    import of database sample.basic data of data_file '' $ARBORPATH\\app\\sample\\basic\\calcdat.txt' ' error abortion;

    import data from database sample.basic

    of data_file ' / data / calcdat.txt'

    using rules_file ' / data / rulesfile.rul'

    Error writing to ' / logs/dimbuild.log ';

  • simple actionscript code question order

    Hello everyone. I'm just

    Learing actionscript. I can't find how to insert simple

    commands in my animations, like play() and stop(). I have to do something fundamentally wrong. One thing I noticed in the tutorials that I am studying, it's tutorials seem to be able to create a 'actions' layer and assign an actionscript command to individual images on the line of action of different clips.  When I try to do, I see the same script command action on EACH frame of the movie clip, and of course, the commands do not work.  I want my video to play until the last image and stop, without loop, but it loop just permanently.

    Anyone have any ideas what I am doing wrong?

    Thanks in advance!

    Yes, you must create a 'key' on this last picture image.

    then, return to this movieclip and remove the stop that you added. There is therefore no stop() at all in this timeline.  now, right-click on the last image of the Assembly of your movieclip and click 'insert a keyframe.  now, while this keyfame is still selected in your properties panel, type:

    Stop();

    Repeat the test.

  • Nexus, authorization to order with GANYMEDE.

    Hello.

    Can anyone provide an example of configuration to use Cisco Secure ACS 4.2 to enable permission to order with GANYMEDE.

    Thank you.

    Kind regards.

    Andrea

    Hello Andrea,

    We moved to GBA 5.3 now - but we had our 5520 Nexus running against our old 4.2 ACS before this - so I chose the relevant bits of the config below:

    username admin password network-admin role; user local administrator

    feature Ganymede +; turn on Ganymede

    radius-server host key; set the key for RADIUS server
    AAA server Ganymede group + Ganymede; create the group called "Ganymede".
    Server; set the IP address of the RADIUS server
    the vrf use management; tell him to use the default 'management' vrf to send queries for Ganymede
    source-interface mgmt0;... .and send mgmt interface

    AAA authentication login default group Ganymede; Use Ganymede for auth login
    AAA authentication login console Group Ganymede; Use Ganymede for auth login console
    AAA authorization config-commands by default local group Ganymede; use Ganymede for permission to config command
    AAA authorization by default Ganymede local group orders; use Ganymede for normal control authorization
    Default accounting AAA group Ganymede; Send documents to Ganymede

    I hope that works for you!

    (This may change a bit, when you move to ACS 5.x - that we chose not to do complex auth command (using only shell profiles) to remedy this you go back as a nexus for the 5 k - and it makes the command auth (operator network vs network-admin) based on the one - if you just do not configure authorization to order aaa on the 5 k)

    Rob...

  • ACS5 / ISE: PEAP authentication - first then machine user

    Hi on board,

    I have a simple question about AAA with ISE or ACS5 and PEAP.

    As we all know, is the big drawback with the PEAP Protocol, you cannot apply that property of the company not authenticates on the network.

    Example:

    Computer Windows - authentication domain and user PEAP. During GINA of Windows, the computer account is used - after login, the user account is used.

    If I bring my own iPad to society, I just have to activate WLAN, enter my domain credentials and voila! I am!

    Some companies want to restrict the network only for devices of the company.

    Therefore, is a simple solution for this, EAP - TLS - but we know all that some guys do not want to put in place an infrastructure to full blown public key...

    So here's the question:

    Is is possible to enforce an order of authentication in ISE or ACS.

    If a request for a certain MAC address of the client authentication happens (Calling station ID), this identity must authenticate with a first computer account (the prefix "host\") and that once the machine authentication is successful, the authentication of the user is authorized.

    If someone wants to connect with a user account, then this is not possible, if there was not a sign of the old machine.

    So is this possible with the ACS or ISE?

    Thanks in advance!

    Johannes,

    You can prevent ipads to connect forcing the machine authentication check the authentication of the user policy.

    http://www.Cisco.com/en/us/docs/security/ISE/1.0/user_guide/ise10_authz_polprfls.html#wp1116684

    You can also use the profiling feature in ISE to reject apple devices to access the network.

    Thank you

    Tarik Admani
    * Please note the useful messages *.

  • R5500 fanless video and high output

    I have a R5500 with dual processor.  today I went to do a reboot after an update of windows, and he never came back.  Essentially and now have attached a monitor:

    1. Lights.
    2. Digital lights go from 1 to 2 to 3 to 4
    3. End up with 3 and 4 illuminated.  Think that it always does.
    4. Hear hard disks turning upward.
    5. Fans of start low nothing in video.
    6. Wait a minute, fans start gets carried away a little bit.
    7. No video.
    8. Fans start yelling again nothing.  No hard drive no light activity either.

    Ideas what is happening here?  I can say that at some point I saw in the case log (have dell monitor installed if questions order) it shows a failure of the raid that seemed weird that hard drives did not work and only the raid I have in this device at the moment is the PERC 6 / i.

    Have had problems before where I had to pull on the power cord briefly and plug it in again so he can turn it on.  I have a new food there so not food I guess.

    Can say that when I take off the cover, three fans on the left side are running fast and those on the right are running more slowly.  Don't know the last time I checked this system, a CPU was idle at 55 degrees, the other at 35 degrees.  Can be nothing but trying to provide all the information.

    Thoughts?

    Thank you.

    Steve

    You probably never noticed it but most of the systems with diags stop LED on various strains of numbers - 34, 12 etc. - during the POST that the system checks components are there, no failure etc.

    Once the MESSAGE confirms that everything works ok it allows starting system in the o/s as usual and the LEDS go off on this model. If there is a problem during POST, the system stops on what caused the problem and goes no further until it is resolved. This is where the LEDs numbers; They let you know what has failed.

    So to confirm. That your system is loading the operating system and the LEDs are out, this means that the system is now working properly

    Hope that explains it for you

  • Changing servers GANYMEDE

    We have added a new server running 5.2 and from 3.3 RADIUS.

    I lose router access when you remove the old server IP info and orders AAA? The router is out of State and do not want to lose the access while making these changes.

    Example of config:

    Ganymede old router config:

    AAA new-model

    AAA authentication login default group Ganymede + local

    AAA authentication login console_line local

    authorization AAA console

    AAA authorization config-commands

    AAA authorization exec default group Ganymede + authenticated if

    AAA authorization commands 0 default group Ganymede + local

    AAA authorization commands 1 default group Ganymede + local

    AAA authorization commands 15 default group Ganymede + local

    AAA accounting exec default start-stop Ganymede group.

    orders accounting AAA 15 by default start-stop Ganymede group.

    !

    AAA - the id of the joint session

    Ganymede IP source-interface Loopback0

    radius-server host 10.1.1.31

    radius-server host 10.2.1.9

    RADIUS-server application made

    RADIUS-server key 7 0835185A5C1053051D080717

    New configuration of router Ganymede (currently)

    AAA new-model

    !

    !

    AAA server Ganymede group + TTI_ACS_GROUP

    Server 10.1.1.253

    Server 10.1.1.252

    Ganymede IP source-interface GigabitEthernet0/0

    !

    Group AAA authentication login TTI_ACS_GROUP default

    the AAA authentication enable default group TTI_ACS_GROUP

    Group default AAA authorization exec if authenticated TTI_ACS_GROUP

    !

    Ganymede IP source-interface Loopback0

    radius-server host 10.1.1.253

    radius-server host 10.1.1.252

    RADIUS-server application made

    RADIUS-server t4t5i6rocks key

    Thank you!

    -Nick C.

    We have improved some time ago to ACS 4.2 to 5.3, I kept the router config to pretty much the same, and had a key to the Ganymede even server for all, so just added new hosts of Ganymede in the existing configuration server and then off the old server, everything was good.

    don't forget if you are worried about losing the connection and then the "reload in 005" is always good to do before making any changes so if you do a config that is not loved and you lose the connection that the router will reload and as not saved config arrived with working config. "."

  • DHCP Radius account management

    We tried to apply DHCP using RADIUS accounting. All of the configuration made as in http://www.cisco.com/en/US/products/sw/iosswrel/ps1839/products_feature_guide09186a00801543c7.html

    but it seems that appointed accountant lists do not work att.

    I.e.

    Group of power for the RADIUS-GROUP1 RGROUP-1 AAA accounting network

    IP dhcp WIRELESS-POOL pool

    accounting RADIUS-GROUP1

    does not. How can I properly configure DHCP accounting? An example of work?

    PS: 7206, c7200 - is - mz.123 - 16.bin

    In this network of Accountants order aaa RADIUS-arrhythmic GROUP1 group RGROUP-1 tent with various options instead of the word network. See the following URL for more information

    http://www.Cisco.com/univercd/CC/TD/doc/product/software/ios122/122newft/122T/122t15/ftdhcpac.htm#wp1086397

  • Configuration of the Cisco ACS 5.3 AnyConnect VPN and management of a Cisco ASA 5500.

    We have configured a Cisco ASA 5505 as a VPN endpoint for one of our user groups.  It works, but it works too well.

    We have a group called XXX we need to have access to the Cisco AnyConnect Client.  We have selected this group of our Active Directory and added to our ACS configuration.  We've also added a group called YYY that will manage the ASA. However, this group has no need to access the VPN.

    We added XXX movies for the elements of the policy of access to the network-> authorization profiles.  We also have a profile of YYY.

    She continues to knock on our default Service rule that says allow all.

    We have also created a default network access rule. for this.

    I am at a loss.  I'm sure I missed a checkbox or something.

    Any help would be really appreciated.

    Dwane

    We use Protocol Management GANYMEDE ASA and Ray for VPN access?

    For administration, you must change the device by default admin access strategy and create a permission policy. Even by the way, you can change the network access by default for vpn access and create a respective policy for that too.

    On the SAA, you must configure Ganymede and Ray both as a server group.

    For the administration, you can set Ganymede as an external authentication under orders aaa Server

    AAA-server protocol Ganymede GANYMEDE +.

    Console HTTP authentication AAA GANYMEDE

    Console Telnet AAA authentication RADIUS LOCAL

    authentication AAA ssh console LOCAL GANYMEDE

    Console to enable AAA authentication RADIUS LOCAL

    For VPN, you must set the authentication radius under the tunnel-group.

    I hope this helps.

    Kind regards

    Jousset

    The rate of useful messages-

  • from NLS_DATE_FORMAT to rman

    Hello

    Oracle 10.2.0.4 on Linux

    On my Linux box I run rman off shell with the following scripts:

    export NLS_DATE_FORMAT='DD-MON-YYYY HH24:MI:SS' 


    What Suppose that Works to get all the ' data and present ", but unfortunately get on date; y no time in most of the rman report and list.

    But in case where export NLS_DATE_FORMAT = 'DD-MON-YY HH24:MI:SS' at the OS level I can get the time.

    Please advice according to the scripts mentioned... 

    Which translates

    RMAN > list backup;

    Backup list

    ===============

    S LV TY Device Type delay #Pieces compressed #Copies Tag key

    ------- -- -- - ----------- --------------- ------- ------- ---------- ---

    177. A DISC 29 OCTOBER 15 1 1 no TAG20151029T110406

    178. A DISC 29 OCTOBER 15 1 1 no TAG20151029T110423

    180. A DISC 29 OCTOBER 15 1 1 no TAG20151029T110427

    181. A DRIVE 30 OCTOBER 15 1 1 no TAG20151030T221559

    RMAN > backup from the list of files.

    using the control file of the target instead of recovery catalog database

    Backup of data file list

    ========================

    Key TY LV S cash YVERT have Time compressed #Copies Tag #Pieces file

    ---- ------- -  -- - ---------- --------- ------- ------- ---------- ---

    1 238 F a 77189943 8 NOVEMBER 15 1 1 no TAG20151108T143403

    234 B F a 8 77189355 NOVEMBER 15 1 1 no TAG20151108T141638

    230 B F a 8 77185865 NOVEMBER 15 1 1 no TAG20151108T133004

    226 B F a 8 77185113 NOVEMBER 15 1 1 no TAG20151108T130505

    222 B F a 5 77060848 NOVEMBER 15 1 1 no TAG20151105T160737

    218 B F a 5 77060620 NOVEMBER 15 1 1 no TAG20151105T1603

    will be mentioned the rman.sh (main script) and run.sh (run the main script)

    #rman.sh

    =========

    #! / bin/sh

    a = "START AT RMAN BACKUP:" date'"

    Export NLS_DATE_FORMAT = 'DD-mon-YYYY HH24:MI:SS.

    #export NLS_DATE_FORMAT

    #echo $now

    CD/backup/RMANBACKUP /.

    #mkdir $now

    #cd $now

    #rm f/backup/RMANBACKUP / *.

    /backup/RMANBACKUP/mkdir $ now

    RMAN < < EOF

    connect the target

    run

    {

    overlap backupset;

    overlap archivelog all;

    allocate channel t1 device type disk format ' / backup/RMANBACKUP/$now/y.db_%d_t%t_s%s_p%p';

    Configure controlfile autobackup on;

    # Delete noprompt disc of obsolete device type;

    SQL 'alter system archive log current;

    backup database;

    backup ARCHIVELOG all delete them input format ' / backup/RMANBACKUP/$now/arch_%d_%u_%s';

    current backup controlfile as ' / backup/RMANBACKUP/$now/y.CNTRL_%d_t%t_s%s_p%p';

    output channel t1;

    SQL 'alter system archive log current;

    }

    EXPRESSIONS OF FOLKLORE

    b = "END of the RMAN BACKUP to:" date'"

    ECHO $a

    echo $b

    ============

    #run.sh

    --------

    #! / bin/bash

    now = $(date + "% d_ m_ % Y_ %T"))

    #now = $('date +%d-%m-%Y\ % H: % m: %S"))

    logName = $full_back_ {ORACLE_SID}-$now.log

    export now

    ./RMAN.sh > $logname

    Kind regards

    Dr.Anty wrote:

    But Iam confused little on to your point "If you are not exporting NLS_DATE_FORMAT, you will see the formatted date in whatever the following default value specified NLS_DATE_FORMAT value control.»

    (1) - how can I know the 'ext default value specified NLS_DATE_FORMAT control'?

    Go back and re-read the article.  From the paragraph titled NLS_DATE_FORMAT.  Here, I explain that nls_date_format defined as a database parameter is substituted by the setting on the client OS, which is overridden by connection making an ALTER SESSION, overridden by use of the TO_CHAR TO_DATE, as appropriate.  Of course, those at last are not available within rman.

    (2) - I can understand that the only way to view the backup command list "time" is export NLS_DATE_FORMAT = 'DD-mon-YYYY HH24:MI:SS' at the OS level before the backup of question order list?

    Who starts as a statement, but ends with a question.    Yes, the only way to obtain rman to display the component "hour" in the production of reports (such as the backup from the list) is NLS_DATE_FORMAT value during the session of os command before calling rman.

    3. I put the NLS_DATE_FORMAT = "DD-mon-YYYY HH24:MI:SS" in .bash_profile to see the times 'backup from the list.

    To see the time in your "backup from the list", you must have established NLS_DATE_FORMAT in your session before calling rman. Put in your .bash_profile is a way that accomplish.

    Kind regards

  • Wipe a drive of oraceleasm

    Version of the grid: 11.2.0.4

    OS: OEL 6.4

    I know that the gurus here are not fond of ASMLib. But it's something I have to live with that.

    I need to reuse the oracleasm discs I dropped Diskgroup x so that I can add these drives to Diskgroup Y.

    -Removed RECO_D7 and RECO_D8 drives

    SQL > drop ALTER DISKGROUP RECO_DG disk RECO_D7;

    Modified DiskGroup.

    SQL > drop ALTER DISKGROUP RECO_DG disk RECO_D8;

    Modified DiskGroup.

    After the above, DROP order, v$ asm_disk. HEADER_STATUS for the above discs became 'OLD '.

    SQL > select name, path, State, mount_status, header_status, total_mb, free_mb v$ asm_disk where HEADER_STATUS! = "MEMBER";

    STATE OF PATH NAME TOTAL_MB FREE_MB HEADER_STATUS MOUNT_STATUS

    -------------------- -------------------------- -------- -------------------- -------------------- ---------- ----------

    NORMAL CLOSED OLD 0 ORCL:RECO_D7 0

    NORMAL CLOSED OLD 0 ORCL:RECO_D8 0

    To "clean" the oracleasm discs, that's what I understand from Googling.

    Step 1. # If dd \u003d/dev/zero of = / dev/sdmna1 bs = 1024 count = 100

    Step 2. # /etc/init.d/oracleasm deletedisk RECO_D7

    -Now, hopefully I should be able to use the disk partition to create a new disk oracleasm

    Step 3. # /etc/init.d/oracleasm DATA78/dev/sdmna1 createdisk

    Are my steps above in the correct order?  Alternatively, step 2 should be performed before the step1? I'm a little confused on why the zeros (dd command) before running the command oracleasm deletedisk ?

    Hello

    Are two different things.

    1 - remove ASMDISK ASM

    2 - ASMLib rename disk

    First of all:

    1-

    If the ASM DISK (LUN) is assigned to a Diskgroup, you must remove this DISC ASM or Drop DISKGROUP.

    Add the 'old' drive to new diskgroup

    After removing this ASMDISK the State will be OLD. Which means:

    "Disc was once part of a disk group, but has been removed itself from the group. It can be added to a new group of disks with the ALTER DISKGROUP statement. »

    2-

    If you want to rename LUN used by ASMLib just question order below.

    /etc/init.d/oracleasm force-renamedisk RECO_D7 DATA78

    You must use dd command in any stage.

    Please avoid using the dd command.

  • Not able to see the number of applications on SO-&gt; extra line information

    Hello

    I'm on R12.1.2.

    I created an internal application that turned into an internal sales order.

    When I am questioning orders and goes to the lines-> extra line-> Applications tab information, I am able to see the command line information, but the requisition number is not posting.

    I think that in previous versions, I was able to see the number of applications and information in line while in R12, its only showing me command line information. Strange!

    Any idea on this feature / problem?

    With respect,
    Vishal husband

    Hello
    You can see the number of requisition and the line in the line of SO main tab itself. Check if you see the "Order reference Source" field and order line reference Source "on the main line tab.

    VKPK

  • Question about pre-ordered Album, (first time)

    For my birthday my sister gave me a $ 25 Itunes gift card and I went and pre-ordered the new Album of Metallica Deluxe, (The Set 3 disc) and I confirmed my purchases of 14.99 and my question is,.

    Has paid for the entire album in full, or each track when you click on the pre-ordered button? I am responsible for the 1.29 for the first single and again here second single, (two songs)

    Will need me even more money or the 14.99 will always cover the entire album?

    Will need me even more money or the 14.99 will always cover the entire album?

    14.99 + tax will cover it.

    When you pre-order, you pay for the titles as they become available and then pay the balance when the full album is available.  In the end, you have the complete album for the price of the correct album.

  • you forgot to answer the secret questions on APP Store too, I lost your e-mail account in order to find the answers

    I forgot to answer the secret questions on APP Store also, I lost my email account in order to find the answers

    You have to ask Apple to reset your security questions. To do this, click here and choose a method; If this page does not list one for your country or if you are unable to call, complete and submit this form.

    (136721)

  • Order General questioning of IEC 60870-5-104

    Dear all,

    I use the NI Communications toolkit to create slave IEC 60870-5-104 (station controlled).

    I use s/w of Triangel microworks part and use it as the master for the same. I am able to send and receive the bulk of orders with the examples provided with the Toolkit to "C:\Program NIUninstaller Instruments\LabVIEW 2012\examples\IEC60870-5,

    I am not able to find a way to capture the "questioning general command" from the server.

     

    Can someone help me how to proceed with this.

    Thank you.

    Hi Frabto,

    The development team has had some great insights below. I have bad informed you (sorry!) behavior, that the command general question should be processed automatically in the communication stack.

    First the order of query sent to control the station may request the complete(station interrogation) or a subset (group interview) of all the data points on the control station. NEITHER 60870-5 to the command station supports the command when the control station receives an order of questioning of the station, it will reply with all the values of the data points. If the Group interrogation command, it will reply with the values of the data points that belong to the group. Users are not able to detect whether the query command is received or not, is automatically handled inside the battery, it allows users of the VI called "Set Group.vi" inside the VI polymorphic "set Property.vi" to set a point to be one of the 16 groups and you can see the usage with the example 'Interrogate information in Group.vi objects' in the folder of the example 60870-5.

    You shouldn't need to do anything to respond to a command of the interrogation. The station will automatically answer. I hope that I did not cause you too much confusion on this point.

Maybe you are looking for

  • Search engine Google which is integrated in the browser settings

    Search engine Google is integrated into the browser. How can I set it so the search results will be shown on a new window, as the fact of the toolbar Google and in the same window (after entry)?

  • S video, no color image on Qosmio G10

    By getting only a B & W picture on G10 when connected the STB to watch in the port with switching SCART to S video cable.Have the value monitor in sVideo in utilities development photo Tosh & TV in PAL (such as the United Kingdom).In the disposition

  • Problem HP 50 g radical (cubic root)

    I'm having a problem with regard to obtaining the correct value for the cubic root of-8.The calc is list 2• ((1+i•cube root 3)/2) where I want to get-2.Why I get a different value and how I can change the settings for the response of assimilate-2?

  • SERIAL NUMBER NOT FOUND ERROR

    I have a mini 1151nr of hp... I bought at Verizon... About 6 months after purchase, I had to drop it to have the motherboard replaced / while it was under warranty.  When she came back to me everything worked as before, but I noticed that MS Works wa

  • printer Laserjet 1020 upgraded to windows 8.1 will not print PC HP Envy H8-1503

    Hello was wondering if anyone has problems printing of victory 8.1, used doctor HP printing and scanning and said everything's fine but a test page does not print as I can't print anything from another category windows 8.1. using windows 8 that I had