Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

"External user not found" with EAP-TLS

Hi Guys,

I have problem for EAP-TLS.I have environment with AP 1121,ACS 4.2(0) Build 124 Trial,AD Replication,Enterprise CA Server,Client Windows XP install Certificate. Wireless Authecation type PEAP,EAP-TLS

Problem: User on AD can authentication PEAP Susscess but cannot authen EAP-TLS

failure code on ACS log saying Authen-Failure-Code "External user not found"

can you help me to explain the problem

Hall of Fame Super Silver

Re: "External user not found" with EAP-TLS

Make sure ACS is configured for EAP-TLS. Also look over the configuration on the policy n ACS for the user group. Is that all the logs sya's in ACS? What does the WLC log show? You can run a debug aaa all and see what actually fails.

*** Please rate helpful posts ***
New Member

Re: "External user not found" with EAP-TLS

I create local ACS user same AD Wireless can authen EAP-TLS Susscess.

I mapping group on AD same local ACS user.

I not user WLC.I user autonomous solution.

New Member

Re: "External user not found" with EAP-TLS

When I had this problem it was because ACS could not find the AD domain controller. The domain controller could not be found be cause the DNS servers were incorrectly specified in the IP setup.

You should be able to ping the domain by partial and fully quoalified doman name. If you can't then something, like DNS, needs to be fixed.

ie. ping domain or ping