WLC4402 and ACS receives double authentication request with MS client

Unanswered Question
Jul 5th, 2007
User Badges:

I have a 4402 wlc, ACS 3.3 and we use Microsoft client with WPA-TKIP/MSChapv2.

We hardly connect to the WLAN, but after 10 minutes we are disconnected.

We are migrating from LEAP to PEAP, so we create two profiles in the WLC.

LEAP connects good, but PEAP fails.

In the ACS log I can see a double authentication request.

Any idea?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
rochopra Thu, 07/05/2007 - 14:47
User Badges:
  • Cisco Employee,


Try increasing timeout on WLC for radius.

Try checking/ unchecking Fast Reconnect on clients and ACS server.


Rohit Chopra

Dominic Stalder Mon, 02/04/2008 - 05:02
User Badges:

I try to use two SSID's with different EAP-Authentication on the ACS. How did you configure the two Profiles exactly?

Thanks in advance

moises.rodriguez Mon, 02/04/2008 - 07:02
User Badges:

Create two profiles with differente name and same SSID, then you can assign one of them with 802.1x and dynamic wEP, and the second with 802.1x with WPA. The firmware versión should be 4.1.217 or higher

Dominic Stalder Mon, 02/04/2008 - 08:42
User Badges:

but that doesen't solve the problem on the ACS right?! On the ACS I have to configure the device with the ip address and the EAP type (ex. "Cisco Aironet" for LEAP or "Cisco IOS/PIX" for PEAP), and how do that?

Thanks for your feedback


This Discussion



Trending Topics - Security & Network