IAS admin authentication

Unanswered Question
Apr 22nd, 2009
User Badges:
  • Cisco Employee,

I hope you can help as I am sure I am missing something basic.


Using IAS to authenticate admin and Lobby ambassador to a wlc running 4.2.


Created a group wlc Admin in windows ad.


Added a user to the group to test. The user works pw etc as I have tested this.


Event log from IAS is here


User test was denied access.

Fully-Qualified-User-Name = WIRELESSDATANET\test

NAS-IP-Address = 192.168.1.200

NAS-Identifier = WLAN-LAB

Called-Station-Identifier = <not present>

Calling-Station-Identifier = <not present>

Client-Friendly-Name = WLAN-LAB

Client-IP-Address = 192.168.1.200

NAS-Port-Type = <not present>

NAS-Port = <not present>

Proxy-Policy-Name = Use Windows authentication for all users

Authentication-Provider = Windows

Authentication-Server = <undetermined>

Policy-Name = <undetermined>

Authentication-Type = PAP

EAP-Type = <undetermined>

Reason-Code = 16

Reason = Authentication was not successful because an unknown user name or incorrect password was used.


The request is getting to the IAS server but not being authenticated.


The logs on the wlc are below


AAA Authentication Failure for UserName:test User Type: WLAN USER


Problem is it is IAS is not even authenticating a client I know has a correct password. The test client is only in the WLC Admin group


I am not sure if its the attributes though the wlc is in as a client with cisco attribute

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
mchin345 Tue, 04/28/2009 - 11:58
User Badges:
  • Silver, 250 points or more

Are you trying to access WLC as an AAA Client on the MS IAS?

Peter Nugent Tue, 04/28/2009 - 12:15
User Badges:
  • Cisco Employee,

Hi mchin I managed to resolve the issue, thanks for replying

Actions

This Discussion

 

 

Trending Topics: Other Wireless Mobility

client could not be authenticated
Network Analysis Module (NAM) Products
Cisco 6500 nam
reason 440 driver failure
Cisco password cracker
Cisco Wireless mode