cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2472
Views
0
Helpful
3
Replies

"External user not found" with EAP-TLS

udom_boon
Level 1
Level 1

Hi Guys,

I have problem for EAP-TLS.I have environment with AP 1121,ACS 4.2(0) Build 124 Trial,AD Replication,Enterprise CA Server,Client Windows XP install Certificate. Wireless Authecation type PEAP,EAP-TLS

Problem: User on AD can authentication PEAP Susscess but cannot authen EAP-TLS

failure code on ACS log saying Authen-Failure-Code "External user not found"

can you help me to explain the problem

3 Replies 3

Scott Fella
Hall of Fame
Hall of Fame

Make sure ACS is configured for EAP-TLS. Also look over the configuration on the policy n ACS for the user group. Is that all the logs sya's in ACS? What does the WLC log show? You can run a debug aaa all and see what actually fails.

http://www.cisco.com/en/US/docs/wireless/controller/4.1/command/reference/clic1.html#wp3494693

-Scott
*** Please rate helpful posts ***

I create local ACS user same AD Wireless can authen EAP-TLS Susscess.

I mapping group on AD same local ACS user.

I not user WLC.I user autonomous solution.

fburejsza
Level 1
Level 1

When I had this problem it was because ACS could not find the AD domain controller. The domain controller could not be found be cause the DNS servers were incorrectly specified in the IP setup.

You should be able to ping the domain by partial and fully quoalified doman name. If you can't then something, like DNS, needs to be fixed.

ie. ping domain or ping domain.dmnRoot.net

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card