WLC Flex connect local authentication does not work

Hi guys,.

I'll give you a brief description of our current flexconnect configuration. We have APs configured mode flexconnect in the remote office and in local mode in the local office. Wireless LANs are the same in both locations and we have detected a problem in one specific SSID. It is a voice SSID and configured in 802.1 x mode that authenticates to a RADIUS server in the remote desktop.

We detected only when the WAN line gets collapsed the IP phones unplugged wireless SSID and when the WAN line become free, reconnected.

We have seen that we can configure Flexconnect local auth mode to avoid this problem, but it of esn can't work properly. We have set up APs in remote site with an IP address static and configured as NAS in the RADIUS server, but we did not see any which authenticayion in th RADIUS server package when change us the SSID to «FlexConnect auth» local

Can you give me an idea to help solve this problem?

Thanks in advance.

Joel

I suppose that clients connected by access points Flexconnect have problems where the WAN connection is down (?)

It depends on your current configuration and security policy what are the feasible options in this scenario. If there is an available RADIUS server - who can still authenticate your users while the WAN line is down, you can configure your access points to access this server directly. You must use a FlexConnect for this group and configure the external server on the general tab, in the menu "AAA". You already made the point of access-static IP addresses and add them as clients on the RADIUS server, then it should work.

Another option is that in the event of failure, access points to will authenticate the client based on a local data base and/or certificate. Also, this requires a FlexConnect group and the option 'Enable local authentication AP'. For example: If you are using PEAP and a specific user for VoWLAN account you can download the server and the certificates of CA to the WLC and add the credentials of this account to build the same configuration with the external server. Downside of this is the lack of central logging that may not match your security policy.

Remember that the access point itself can't remember the relationship between the access point and FlexConnect group, in both scenarios, you need to configure all controllers manually with these MAC to the Group mappings. This behavior is different in comparison with the "groups of AP" what access point you remember during the passage of the controllers.

The "FlexConnect local authentication" option on the SSID itself forces always use local authentication that has been configured on the FlexConnect group even if the connection with the WLC is available. I don't think that it is feasible to use it in your scenario.

Please rate helpful messages... :-)

Tags: Cisco Wireless

Similar Questions

  • My labtop sound works, but when connect the headphones does not work

    My labtop sound works, but when connect the headphones does not work. Note that the headset before 1 HR was working.

    Hello

    ·         Are these USB headset or headphone jack analog standard?

    ·         What version of the operating system is installed on the system?

    If you continue Windows 7 or Windows Vista refer to the procedure in method provided below and check if they help to resolve the issue.

    Method 1:

    Step 1:

    You can check if the headphones are activated as a playback device. To do this, see the following steps:

    (a) the Pearl-click Start and type Sound in the start search box.

    (b) in the Start Menu Options, select change adapter settings .

    (c) then, on the Read tab, right-click and select Show hidden devices and Show disconnected devices if they are available.

    (d) select headphones and select

    Step 2:

    Also try to put headphones of default device and check, follow the steps below.

    (a) go to Start and click on Panel.

    (b) click Sound, and then a new window will open.

    (c) in the new window click on the "Playback" tab and right-click in the window and click on Show disabled devices.

    (d) now check if headphone is listed there and right-click on it and choose activate.

    (e) highlight this helmet and click on "as default'.»»

  • I am trying to create a VPN connection, but it does not work

    I am trying to create a VPN connection, but it does not work
    The wizard cannot establish a connection. And if I try to record simply does not connect
    It does not work. If I try to click on find the problem, there simply
    do nothing.
    I tried it on another pc, where it worked. So the problem is not the
    router or data network. And the curious thing is that I installed it before, but only from one day to the other, the VPN connection was missing.

    It does not create even a the connection icon
    Thank you

    Try a system restore to a Date before the problem began:

    Restore point:

    http://www.howtogeek.com/HOWTO/Windows-Vista/using-Windows-Vista-system-restore/

    Do Safe Mode system restore, if it is impossible to do in Normal Mode.

    Try typing F8 at startup and in the list of Boot selections, select Mode safe using ARROW top to go there > and then press ENTER.

    Try a restore of the system once, to choose a Restore Point prior to your problem...

    Click Start > programs > Accessories > system tools > system restore > choose another time > next > etc.

    http://www.windowsvistauserguide.com/system_restore.htm

    Read the above for a very good graph shows how backward more than 5 days in the System Restore Points by checking the correct box.

    See you soon.

    Mick Murphy - Microsoft partner

  • Fonts/text resize function works on my local machine, does not work on others.

    I have embedded fonts (and yet he's pushing me always missing fonts by saying whenever I open the flash, but not the fonts that are not correctly resize)

    I have a function that takes in a textfield, resizes the police to adapt to the text box, works fine on my local machine, does NOT work on other machines.

    Does he know about reasons why it does not work? Here's the function

    function fontSizeChanger(dtb,myWidth)
    {
         dtb.embedFonts = true;
         
         var myFormat:TextFormat = dtb.getTextFormat();
         var metrics:Object = myFormat.getTextExtent(dtb.text); 
         
         while (metrics.textFieldWidth>myWidth) 
         { 
              myFormat.size--; 
              metrics = myFormat.getTextExtent(dtb.text);
         } 
         
         dtb.setTextFormat(myFormat);
         dtb.embedFonts = true;
    }
    

    Please mark this thread as answered, if you can.

  • Wireless connects, but internet does not work

    My wifi signal is strong. My computer says that it is connected. Diagnosis shows the signal is stable, but when I open a browser, it does not connect. It just seems to take forever, but nothing ever happens in Safari. Chrome has said, "there no internet connection. Your computer is offline. "and that Firefox says: 'server not found '.

    I tried the Ethernet connection, but it's the same story. Computer indicates recognition signal, but it will never truly connect. It will connect in Safe Mode, however.

    I don't know if this is related, but iTunes does not work either. I open and just get the reel spinning forever. It is said he is unresponsive, and I force quit.

    Here is some information that might be useful:

    -iPhones and MacBook in the House are fine to connect to Internet.

    -My internet company just came and installed a new router/modem. We had a few problems before (this is why they came to reinstall the hardware), so I don't know if this has something to do with him or not.

    iMac

    OS X El Capitan 10.11.6

    3.2 GHz Intel Core i5

    Deselect if selected proxy.

    System Preferences > network > advanced > proxies tab

    Unlock the lock if you have to.

    Under "Select the Protocol", uncheck all box if marked cheque.

    Click 'OK' and then 'apply '.

  • wireless connected but internet does not work

    Since yesterday my laptop has had problems connecting to the internet. It will say that it is connected to the internet but yet when I open a browser or any other program requiring internet, it does not work. However, when I use the same connection from another laptop, the internet works.

    I tried to use the option diagnose & repair and he always tells me that everything is fine. I also tried to restart my laptop and check my firewall settings, which did not help either. any help would be greatly appreciated!

    Hello

    Turn off the router or the modem (unplug the power supply) - wait 3 minutes, then the power restore - restart the computer.

    If necessary:

    Two methods - I would try 1. first and use 2. only if necessary because with 2 it can come back.

    1.

    Your router could be suspicious here, you have successfully updated its firmware as a possible solution? And I would like to
    Update your WiFi drivers on computers. How you are positioned in the router? Are there
    obstacles in the path?

    Actually try updating your driver and disabling the network logon. If you usually use WiFi try a wire
    and if you usually use a wire try WiFi. Update, one being not used 1.

    Control Panel - network - write down of the brand and the model of the Wifi - double click top - tab of the driver - write
    version - click the driver update (cannot do something that MS is far behind the pilots of certification). Then
    Right click on the Wifi device and UNINSTALL - Reboot - it will refresh the driver stack.

    Look at the sites of the manufacturer for drivers - and the manufacturer of the device manually.
    http://pcsupport.about.com/od/driverssupport/HT/driverdlmfgr.htm

    How to install a device driver in Vista Device Manager
    http://www.Vistax64.com/tutorials/193584-Device-Manager-install-driver.html

    Download - SAVE - go where you put it - right click – RUN AS ADMIN.

    You can download several at once however restart after the installation of each of them.

    After watching the system manufacturer, you can check the manufacturer of the device an even newer version. (The
    manufacturer of system become your backup policies).

    Repeat for card (NIC) network and is a good time to get the other updated drivers as Vista like
    updated drivers.

    I would also turn off auto update for the drivers. If the updates Windows suggests a just HIDE as they
    are almost always old, and you can search drivers manually as needed.

    How to disable automatic driver Installation in Windows Vista - drivers
    http://www.AddictiveTips.com/Windows-Tips/how-to-disable-automatic-driver-installation-in-Windows-Vista/
    http://TechNet.Microsoft.com/en-us/library/cc730606 (WS.10) .aspx

    ------------------------------------------------------

    Make sure you know the details of connection to your router wireless and wired - SSID and password.

    You lose connection when you do and have to redo your logon.

    Control Panel - Network & Sharing Center - right, click Customize - page set of network locations.
    lower left click on merge or delete network locations - REMOVE all instances of your network (and the
    others you don't use anymore) - REBOOT. Start - Connect To log on to the network.

    -----------------------------------------------------

    Check this box:

    Strange problem with Internet under Vista
    http://www.catonett.com/blog/archives/194

    Windows Vista cannot obtain an IP address from certain routers or some non-Microsoft DHCP servers
    http://support.Microsoft.com/kb/928233/en-us

    ----------------------------------------------------

    And:

    Network connection problems
    http://windowshelp.Microsoft.com/Windows/en-us/help/33307acf-0698-41ba-B014-ea0a2eb8d0a81033.mspx

    ==============================================

    2.

    Do a system restore before it happened.

    How to make a Vista system restore
    http://www.Vistax64.com/tutorials/76905-System-Restore-how.html
    I hope this helps. Rob - bicycle - Mark Twain said it is good.

  • I try to click on 'connect', this option does not work.

    Hello

    I tried to download a free trial version for Adobe photoshop and the option "Log" for it does not work on my desktop. What I would do in this regard?

    Thank you.

    Debopreeti Mukherjee

    Please run the vacuum cleaner to remove traces of CC and Adobe Application Manager, and then reinstall it again.

    1. remove the cloud creative app.

    2. install Creative Cloud app - https://helpx.adobe.com/creative-cloud/help/install-apps.html

    Let us know if you use the cleanup tool and remove Cloud Creative & AAM.

  • Follow this procedure when the Sansa Connect recovery tool does not work!

    Hey people;

    This thread is just to consolidate the info from a lot a longer wire, earlier.

    Currently, the Sansa Connect recovery tool may or may not work for you.  You can see an error like 'failed to connect to the Internet' or "cannot retrieve the device, SanDisk contact technical support for assistance."  If Yes, it's probably because the recovery tool is unable to download the firmware images he needs zing.net.  SanDisk has not (yet) recognized this problem.  The strange thing is that * sometimes * recovery tool works, if you already have images of the firmware on the drive... but usually it doesn't.

    So here's what you do (with thanks to Larlos for providing the firmware images and order lines to their installation).  This assumes that you're 'stuck' to the "necessary recovery" post on your connection.  If not and you are in the regular menu of Sansa Connect, first follow steps 2 and 3 in this paper: http://mp3support.sandisk.com/tools/connect-recovery-instructions.pdf, do the following:

    (1) download the zip file containing the images of the http://www.megaupload.com/?d=UNLDGZ1N firmware

    (2) search for the following files in the zip file, and then copy them into the directory of your drive "C:\Program Updater Connect Device Recovery\cmdline":

    • everest_initrd_ext_prod_1.1.1.50239.SRR.e
    • everest_vmlinux_ext_prod_1.1.1.50239.SRR.e
    • yeverest_zap_ota_rel_1.1.2.65799.tar.gz.e
    • yeverest_zap_ota_rel_ext_prod_1.1.2.65799.SIG

    (3) in the same directory, create a file named recovery.bat that contains the following three lines:

    zsi_fw.exe w everest_vmlinux_ext_prod_1.1.1.50239.srr.e everest_initrd_ext_prod_1.1.1.50239.srr.e

    zaprecover.exe t 600000 f yeverest_zap_ota_rel_1.1.2.65799.tar.gz.e yeverest_zap_ota_rel_ext_prod_1.1.2.65799.sig

    pause

    (4) connect your Sansa Connect USB.

    (5) run the recovery.bat file (double-click it in Windows Explorer, or run from a DOS command prompt).  The line of 'pause' is there only so you can see the results of running if you run it from Windows Explorer.  Expect the recovery to the end; at the end of that your connection will restart.  If Windows displays the hardware wizard detected during this process, simply cancel the wizard.

    whturner wrote:

    Thanks for the help - it updated my white box to connect to the WiFi and after registration on Yahoo (without choosing any service, just updated my old email and user ID) I now INet radio with a number of stations that work fine on my home wireless network. To do this, DND to explore and syncs with WMP OK. A few quirks that I wonder about.        (1) after the firmware update, my ZAP showed that 1.2.0.58335r and OS = 1.2.0.58835 - NOW (the next day), it changed to ZAP = 1.1.2.65799r and 1.1.1.50239 = OS. Every thing seems to work even though; I have a firmware download while I was playing with the INet radio?     2) there is also a new menu item "Server Zing" that lists the name of the module, the version, and the primary and secondary server. Is this normal?  (3) what Yahoo service I - I see a small Y! symbol at the top right of the screen.                                                                                                                                               Thank you very much and congratulations Warren

    (1) no; you see the version numbers are associated with the files of the firmware (names starting with "everest" and "yeverest" files) that you have either downloaded when you ran the recovery tool, or download in megaupload.com zip file.

    (2) Yes, it's normal.  Zing is the company that allows you to manage authentication of audio stream and firmware for the connection.

    (3) the Y! symbol indicates just that when you use the Internet Radio feature, you are streaming audio of Yahoo (in fact, now owned by CBS Radio).  There is also a function of Flickr photos, which is associated with Yahoo.

  • Classic connection Add-In does not work - db selection did not get recognized.

    Hi all

    With my client, many users work with the classic Essbase Add-In on their computers. The Add-In is distributed and installed with a software package. Out of these facilities, a machine makes problems. Excel version 2010 begins and the Addin too. Then under Add-Ins > Essbase > Connect the login window appears. The user name and password are given and OK button. See a list of Applications and databases. When a database is selected and you press the OK button, the selection changes to the database at the top of the page and the window does not disappear.

    This also happens with another user that can run on a different machine (so no access rights).

    The Add-in is turned off and on again. Problem stays.

    All other add-ins are disabled. Problem stays.

    Anyone seen elsewhere or have a suggestion?

    Thanks in advance.

    Kind regards

    Philip Hulsebosch

    Saw this problem occurs when there is a space at the end of the name of the server, for example

    "my.essbase.server" (the quotation marks to highlight where space is) caused the behavior that you describe.  We found that some microsoft products copy happily a space at the end when copy and pasted from outlook or word or etc... So we always adovate by manually typing in the name of the server

    Let me know if this helps - took us forever to understand.

  • HTTP GET with authentication does not work in Adobe Indesign javascript

    Hello

    This is the code I am trying to run in the Indesign script. The URL http://localhost:4502/content/geometrixx/en/company/news/articles.html works directly in a browser, it renders the content. But when I try running the below in Indesign, it gives the following result. It does not really give the conent return.

    InDesign script code:

    response = "";

    Conn = new Socket;

    access the Adobe homepage

    If (conn.open ("localhost:4502")) {}

    var request = "GET /content/geometrixx/en/company/news/articles.html HTTP/1.0\n\n ' +.

    "Authorization: basic admin:admin\n"

    Conn.Write (request); and read the response from the server

    response = conn.read (999999);

    Alert (Reply);

    Conn.Close ();

    }

    Output in Indesign:

    HTTP/1.1 404 not found

    Connection: close

    Server: Day-Servlet-Engine/4.1.12

    Content-Type: text/html; Charset = UTF-8

    Content-Length: 387

    Date: Wednesday, December 7, 2011 03:05:26 GMT

    <! DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0 / / BY" > ".

    < html > < head >

    < title > 404 not found < /title >

    < / head > < body >

    Found < H1 > < / h1 >

    < p > the requested URL /content/geometrixx/en/company/news/articles.html was not found on this server. < /p >

    < hr >

    < address > ApacheSling/2.2 (Java hotspot Server VM 64 1.6.0_29;) Mac OS X 10.7.2 x86_64) < / address >

    < body / > < / html >

    Hello

    Your code has problems.

    1 HTTP request closed 1st line. Server wait and get the data so that come from "\n\n".

    2. name and password of the user authorization string must be base64 encoding.

    You can read as a reference:

    http://en.Wikipedia.org/wiki/Basic_access_authentication

    Here's an example query:

    var request = "GET /autharea/index.html HTTP/1.1\n '.

    + "Host: (servername) \n".

    + "Content-Type: text/html;" Charset = UTF - 8\n ".

    + "Authorization: basic" + encodedData + "\n\n";

    and work with function base64 code

    var authStr = "name";

    var encodedData = base64 (authStr);

    var response = "";

    var conn = new Socket;

    var request = "GET /autharea/index.html HTTP/1.1\n '.

    + "Host: (serverName) \n"

    + "Content-Type: text/html;" Charset = UTF - 8\n ".

    + "Authorization: basic" + encodedData + "\n\n";

    If (conn.open ('130.1.6.46:80', 'UTF-8')) {}

    Conn.Write (request);

    response = conn.read (999999);

    Conn.Close ();

    Alert (Reply);

    }

    function base64 (binaryString) {}

    var keyStr = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789 + / =";

    var encoded = "";

    var c1, c2, c3;

    var e1, e2, e3, e4;

    var i = 0;

    While (i< binarystring.length)="">

    C1 = binaryString.charCodeAt(i++);

    C2 is equal to binaryString.charCodeAt(i++);

    C3 = binaryString.charCodeAt(i++);

    E1 = c1 > 2;

    e2 = ((c1 & 3) < 4)="" |="" (c2="">> 4);

    E3 = ((c2 & 15) < 2)="" |="" (c3=""> > 6);

    E4 = c3 & 63;

    If (isNaN (c2)) {}

    E3 = e4 = 64;

    } Else if (isNaN (c3)) {}

    E4 = 64;

    }

    encoded = code + keyStr.charAt (e1) + keyStr.charAt (e2) +.

    keyStr.charAt (e3) + keyStr.charAt (e4);

    }

    return encoded;

    }

    Ten

  • ePrint-&gt; connected HP migration does not work

    The printer I use is the HP Officejet 6500 has more.

    Given that my router does not support Hello and I was able to print using ePrint with my Iphone, I was a little freaked out to see that it no longer works.

    When I logged in the center successfully ePrint (I saw my printer in a Flash details) from the link in my server Web integrated, I was automatically instantly redirected to HPconnected.com

    VERY unfortunately, the redirect page http://hpconnected.com/nl/nl and http://hpconnected.com give a blank page with the other "not found" on it.

    I am not able to enter the centre of ePrint more, it keeps redirecting me to this site not wonderful.

    What should do?

    Hello

    Please click the link in the yellow circle when go to ePrint:

    or this direct link:

    https://www.hpconnected.com/us/en/#catalog/

    Kind regards.

  • NAC appliance local authentication does not

    Hello

    I try a test for the NAC scenario. It's the gateway virtual oob

    I get the login page when trying to access the web, but when I try to authenticate to the local db that I get an error message and I am on the authentication screen.

    I listened with tcpdump on both interfaces. on the unreliable side, I see traffic but on the side confidence no difference in traffic doesn't appear (but maybe that's normal)

    can someone please help with detailed steps that follows authentication

    not only host--> nas--> nam (localdb)

    or some ideas

    Thank you!

    check the teporary certificates that you generated and set the field of domain name FULL to the nas ip address and so the nam

  • computer starts but nothing works. OneCare has been stopped, restart, no network connection found, office does not work. Analysis now with the malicious software removal tool, but nothing happens.

    OneCare was 'arrested' will not restart
    Wireless networks - does not and cannot correct
    No program will run if I'm in safe mode
    I did a virus scan with the malicious software removal tool, nothing was found.
    I write this on my netbook - I can't have my laptop online.
    I have no idea what to try next.  I need my laptop!  Help, please

    Hello laughingpaws,

    To help resolve this issue, use the System File Checker (SFC.exe) tool to determine which file is causing the problem and then replace the file. To do this, follow these steps:

    1. Open an elevated command prompt. To do this, click Start, click principally made programs, Accessories, right-click guest, and then click run as administrator. If you are prompted for an administrator password or a confirmation, type the password, or click allow.
    2. Type the following command and press ENTER: sfc/scannow sfc/scannow command analyzes all protected system files and replaces incorrect versions with appropriate Microsoft versions.

    Hope this helps you. Let us know anyway. Make it a great day!

    "And in the end the love you take, is equal to The Love You Make" (The Beatles last song from their latest album, Abbey Road.)

  • Custom authentication does not work after upgrade to 4.1

    Hi, are there problems with authentication in 4.1? I can't get my new authentication scheme to work for some reason any. I was wondering, is that there are problems with 4.1?

    Thank you

    Published by: Andyindo on Sep 17, 2011 14:57

    Hi Andyindo,

    Name your packagename.function in your custom authentication as the below and check.

    >return final_users_security.valid_user

    Brgds,
    Mini

    -----------------
    Mark responds promptly

  • How the process in two steps of authentication does not work if you are not in an area of cellular service

    Outside cellular service areas, IS those who know how the two step aunthicatuon process works in an iPhone 6, using the operating system iOS 9.3.4?  Would a being completely locked out of their iphone and apple services until they could find themselves in a cell service area? Or can it be accessed by a public wifi? Who beg to differ on whether or not it is beneficial to use when you travel?

    I did a little research to see if all Apple items shed light...

    See "How it works" in the Apple ID - Apple Support for two-factor authentication - a time that a device is approved, he'll never ask again unless you perform one or more of several things to "break the connection.

    If I were you, I would spend it TURNED off if you fear that one of these things could happen while you might not be able to obtain the code by SMS

    Frequently asked questions about the audit in two steps for Apple ID - Apple Support

    I'm confused as to why Apple would use two different expressions for what seems to be the same:

    • "Two -authentication"- and
    • "Two -step".

    The above two articles begin with a statement like: [underlining is unique, "BOLD" is synonymous with]

    "Two-factor authentication is just an extra layer of security of your ID Apple aiming to sure you are the only person who can access to your account, even if someone knows your password."

    «The two-step verification is an additional security feature for your Apple which designed to prevent anyone to access or use your account, same ID is they know your password.»

    Maybe someone with more experience can shed some light on your question and MY confusion?

Maybe you are looking for