cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1108
Views
0
Helpful
3
Replies

Suddenly few users are not authenticating through AAA

banavathkiran
Level 1
Level 1

I have two radius servers configured in cisco wlc 2504, few users are unable to authenticate and connect to WLAN. For some uses Im getting these logs

71 Mon Aug 5 12:54:58 2013 RADIUS server 172.16.100.254:1812 failed to respond to request (ID 208) for client 00:22:fa:98:a4:68 / user 'unknown'

72 Mon Aug 5 12:54:56 2013 RADIUS server 172.16.100.254:1812 failed to respond to request (ID 197) for client 00:00:01:d7:00:00 / user 'unknown'

73 Mon Aug 5 12:54:27 2013 RADIUS server 172.16.100.254:1812 failed to respond to request (ID 183) for client 00:22:fa:98:a4:68 / user 'unknown'

74 Mon Aug 5 12:54:26 2013 RADIUS server 172.16.100.254:1812 activated in global list

75 Mon Aug 5 12:54:26 2013 RADIUS server 172.16.100.200:1812 deactivated in global list

76 Mon Aug 5 12:54:26 2013 RADIUS server 172.16.100.200:1812 deactivated in global list

77 Mon Aug 5 12:54:26 2013 RADIUS server 172.16.100.200:1812 failed to respond to request (ID 171) for client 00:00:01:d7:00:00 / user 'unknown'

78 Mon Aug 5 12:54:02 2013 Rogue AP : 1a:87:96:8d:0f:cd removed from Base Radio MAC : 00:24:97:15:69:90 Interface no:0(802.11n(2.4 GHz))

79 Mon Aug 5 12:54:02 2013 Rogue AP : 1a:87:96:8d:0f:cd removed from Base Radio MAC : 00:21:a0:26:64:d0 Interface no:0(802.11n(2.4 GHz))

80 Mon Aug 5 12:54:02 2013 Rogue AP : 1a:87:96:8d:0f:cd removed from Base Radio MAC : 00:21:a0:28:57:10 Interface no:0(802.11n(2.4 GHz))

81 Mon Aug 5 12:53:56 2013 RADIUS server 172.16.100.254:1812 failed to respond to request (ID 140) for client 00:22:fa:98:a4:68 / user 'unknown'

Please let me what is cause for this problem. my radius servers are over WAN.

Fallback is OFF before, I have confgired it to Active now but same problem persists.

1 Accepted Solution

Accepted Solutions

Scott Fella
Hall of Fame
Hall of Fame

Check your radius server logs

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

View solution in original post

3 Replies 3

Scott Fella
Hall of Fame
Hall of Fame

Check your radius server logs

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

Hi scott Thank you for the rply.

The primary radius server services got hanged up because of which clients are unable to authenticate.

I have disabled my primary server then only clients are able to authenticate using secondary server.

scott , what do you recommend failover to be OFF or Active or Passive?

And after as I have pasted the logs above, even now I cloud able to see those longs again

71 Mon Aug 5 12:54:58 2013 RADIUS server 172.16.100.254:1812 failed to  respond to request (ID 208) for client 00:22:fa:98:a4:68 / user  'unknown'

What does this mean? controller is unable to send the username and password to radius server? This is why servers in failing to respond?

Amjad Abdullah
VIP Alumni
VIP Alumni

Scott just guided you to the right spot.

You may also make sure that the credentials are valid on the machines that fail authentication. (in case you don't have direct access to the radius server).

Rating useful replies is more useful than saying "Thank you"

Rating useful replies is more useful than saying "Thank you"
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card