2504 with new-architecture enabled breaks MAC auth for guest access

Hello,
We have (2) 2504 WLC running version 7.6.120. WLC1 is the local controller and WLC2 is an achor controller for guest-access. We need to incorporate a 3850 for use with the WLC2 anchor. The guest access is currently working with Mac-Auth and Mac-Auth-Fail to Web-Auth.
When converged access is enabled on the WLC1 and WLC2, the MAc-Auth no longer works. That is, the previously authenticated user is now redirected to the Web-Auth page. The local controller shows the user as authenticated but the Anchor controller shows the state as WEb-Auth-REQD.
Rolling back using "config mobility new-architecture disable" and rebooting resolves the issue.
Does anyone what changes from the old to the new that would break this mac-auth/web-auth configuration?

You should reach TAC for these sort of issues. Not many people deploying this CA setup yet & you may not get direct feedback immediately.
HTH
Rasika

Similar Messages

  • I have created a new partition on the Mac HD for Lion as I would like to dual boot. Do I need to install Snow Leopard on that partition before installing Lion? If so, can I use one of my Time Machine backups to do this?

    I have created a new partition on the Mac HD for Lion as I would like to dual boot. Do I need to install Snow Leopard on that partition before installing Lion? If so, can I use one of my Time Machine backups to do this?

    zoominnana wrote:
    Can I set up 2 different time capsule backups? one for the lion partition and one for the snow leopard partition?
    No, you can't partition a Time Capsule's internal HD.  Both partitions will back up to the same sparse bundle. keeping the backups for each partition separate.
    Time Machine will not take the two OSX partitions as two different computers, but for best results, exclude the Snow Leopard drive from backups on the Lion partition, and exclude the Lion partition from backups on the Snow Leopard partition.
    There may be some files on the Lion partition that Time Machine on Snow Leopard won't like, among other things.  See #10 in  Time Machine - Frequently Asked Questions for details.

  • HT4623 if i am unhappy with new software then how to go for earlier version

    if i am unhappy with new software the how to go for earlier version

    Sorry, Apple has no approved method to downgrade the version of iOS on your iDevice. You can voice your displeasure with the iOS by leaving feedback at the appropriate subsection from the link below.
    http://www.apple.com/feedback/

  • When is new version of i mac due for release

    When is new version of I mac due for release

    Only Apple knows.  We users are the last to know.

  • E2500 with multiple APs for guest access

    I got 5 E2500 routers and the main one has setup to IP address 192.168.1.254 and the rest APs are programmed into the bridge mode with the IP address 192.168.1.245 through 248. The secured wireless network  works fine when I roaming between these APs but the only AP that I can get internet access for guest wireless network is the main (192.168.1.254) router; for every other APs, I will get the guest log on screen (prompt for guest access password) and no internet access after I type in the correct access password. Does the E2500 support multiple APs guest or it requires a special way to configure it? Please help...
    Jim

    Guest Access allows you to provide Internet connection to your guests, however, they will not have access to your computers or other personal data. When you set up your Valet or Linksys Wireless-N router, the Cisco Connect software will create two wireless networks with the same Wireless Network Name (SSID) that differs from one another by a -guest suffix to one of the wireless network names.
    So first of all remove all the networks from the preferred list of the computer and then try to connect.  

  • New iMac 24" or Mac Pro for Aperure

    Hi All,
    I only can get stock computers in COMPUSA or authorized resellers in PR.
    Which one do you recommend for Aperture, the new iMac 24" or the Mac Pro? It looks they both use the same video card...

    Sadly I have just asked Apple to take back my mac book pro 17" 2.16 because aperture was just to slow and it became annoying, after any adjustments to a photo the loupe tool would jump and jerk across the screen or the patch tool would do the same after around 3-4 patched dust marks, I came across to a mac purely for aperture, which incidently I think aperture is a great tool, if it would only run faster. If the MBP 17" 100gb 7200rpm HD 2 gb Ram and Radion X1600 with 256 mb memory has problems running this software what hardware setup was this programme actually built for.
    I will have to stay with my steam driven dell pc until I can make my mind up what to do, I must admit I am impressed by the mac itself and I found the service from apple outstanding, this laptop is my second machine in 3 weeks, first one had a warped top apple took it back and sent another one immediately, having also explained my problem and dissatisfaction with the second they have taken it back with full refund without any hassle whatsoever.
    Dave Hall

  • New GTX-7xx / Titan Mac Edition for cMP?

    Now that the 2010-2012 Mac Pro's 5.1 have been 'replaced' by the 2013 New Mac Pro 6.1, but there still are thousands of high-end users demanding more and more GPU power in their MP 5.1, I wonder if NVIDIA / EVGA will market a new "GTX-7xx / Titan Mac Edition". The last model is the GTX-680 2GB Mac Edition which is over one year old.
    Any insiders in the business here that would like to share their insights?
    ~ Cheers

    Berend de Meyer wrote:
    I wonder if NVIDIA / EVGA will market a new "GTX-7xx / Titan Mac Edition".
    You have to ask a different set of questions:  does it make financial sense for nVidia to bother engineering a down-clocked Titan reference card that can deal with the reduced power available in the Mac Pro?  Will they sell enough of them to make it worth their effort?  And how much effort would that actually take?

  • With new macbook I get iWork & iLife for free just for new products ?

    Why I  didn't get for all my devices?

    Even though the iWork for Mac & iWork for iOS apps now share similar file formats & user interfaces, they are separate programs created for separate operating systems. Activating a new iOS device after September 1 gets you the iOS versions of iWork & iLife. Purchasing a new OS X device after October 1 entitles you to the free OS X apps. Also, if you already purchased iWork '09 apps for the Mac you can update to the new versions for free. The same goes for the previous versions of the iOS apps. You can then install the apps on all of your devices with the same OS using your same Apple ID. BUT, getting the apps for one operating system does not get you the same apps for the other OS.

  • Using ISE for guest access together with anchor controller WLC in DMZ

    Hi there,
    I setup a guest WLAN in our LAB environment. I have one internal WLC connection to an anchor controller in our DMZ. I'm using the WLC integrated web-auth portal which works fine.
    To gain more flexibility regarding guest account provisioning and reporting my idea is to use Cisco Identity Services Engine (ISE) for web-authentication. So the anchor controller in the DMZ would redirect the guest clients to the ISE portal.
    As the ISE is located on the internal network while the guest clients end up in the DMZ network this would mean that I have to open the web-auth portal port of ISE for all guest client IPs in order to be able to authenticate.
    Does anyone know of a better solution for this ? Where to place the ISE for this scenario, etc ?
    Thx
    Frank

    So i ran into a similar scenario on a recent deployment:
    We had the following:
    WLC-A on private network (Inside)
    ISE Servers ISE01 and ISE02 (Inside)
    WLC-B Anchor in DMZ for Guest traffic (DMZ)
    ISE Server 3 (DMZ)
    ISE01 and ISE02 are used for 802.1X for the private network WLAN.
    Customer does not allow guest traffic to move from a less secure network to a more secure network (Compliance reasons).
    The foreign controller (WLC-A) must handle all L2 authentication and it must use the same policy node that the clients will hit for web auth.  Since we want to do CWA, we use Mac Filtering with ISE as the radius server.  If you send this traffic RADIUS authentication for Mac Filtering to ISE01/ISE02, it will use https://ise01.mydomain.com/... to redirect the client to.  Since we don't allow traffic to traverse from the DMZ with the anchor in it back inside to the network where ISE01 and ISE02 are, client redirection fails.  (This was a limitation of ISE 1.1.  Not sure if this persists in 1.2 or not.
    So what now?  In our deployment we decided to use a 3rd ISE policy node (ISE03 in the DMZ) for guest authentiction from the Foreign controller so that the client will use a DNS of https://ise03.mydomain.com/... to redirect the client to.  Once the session is authenticated, ISE03 will send a CoA back to the foreign which will remove the redirect for the session.  Note, you do have to allow ISE03 to send a CoA.
    In summary, if you can't allow guest traffic to head back inside the network to hit the CWA portal, you must add a policy node in a DMZ to use for the CWA portal so they have a resolvable and reachable policy node.

  • How to enable second HD DVR for remote access?

    I easily got my first HD DVR setup for remote access and it worked perfetly for 1 day, then it stopped working.  After 2 hours on the phone with tech support, we got it to work again.  However, we were unable to get my second DVR setup.  He said that I could only have one DVR setup for remote access, is that true?  If not, any assistance would be much appreciated. 
    Thank you!

    glcockrum wrote:
    I easily got my first HD DVR setup for remote access and it worked perfetly for 1 day, then it stopped working.  After 2 hours on the phone with tech support, we got it to work again.  However, we were unable to get my second DVR setup.  He said that I could only have one DVR setup for remote access, is that true?  If not, any assistance would be much appreciated. 
    Thank you!
    Are you speaking of Remote Access from the Web?  ...or from a mobile phone?
    For Web Access it is absolutely NOT TRUE!
    I have TWO DVRs.  I can access both remotely from the web and schedule or delete recordings.
    The tech MAY have been speaking of (or confused about) the MULTI-ROOM capability that the DVR's have.
    Only one of the DVRs can be (and is) a Home Media (or Multi-Room) DVR, and therefore can share recordings with my other NON-DVR STB and communicates with any computer on my home network for PC-based Audio, Vieo and Image files, as well as connecting to the certain Internet video streaming sites.
    The other DVR is a standalone machine is this regard, but regardless, it still has remote access to control it from the Web.
    (I do not know anything about the Remote Access from a mobile phone capability, since I do have a Verizon Wireless contract.  THAT Remote Access may indeed be limited to just a single DVR.)

  • New Set up of Airport Extreme with New Macbook and 'Old' Mac Mini

    I have wirelessly connected my new Mac Book to Airport Extreme, and have tested the connection by using a shared printer. I have connected my old Mac Mini (OSX 10.3.9) via Wired LAN.The MacMini does not recognise a connection to the Airport Extreme. I would like to share files between the MacBook and the Mini, but they do not 'See' each other. What have I not done correctly?
    Mac Mini   Mac OS X (10.3.9)  

    I have checked the IP addresses:
    Mac Book nn.n.n.200
    Mini nn.n.n.199
    Airport nn.n.n.1
    Al appear to be valid
    A restart did not change anything.
    I have been able to Ping each IP address succesfully from each machine, so the only aspect I can't understand is why each machine is not showing when I view the Network in Finder
    Mac Mini   Mac OS X (10.3.9)  

  • HT201628 Problems with new iTunes and old Mac

    i had to uninstall itunes from my Mac os x 10.6.5 but now i can't install the newest itunes because it requires a later version, 10.7. What do i do now?

    Mac OS X 10.6.8 Update v.1.1 - http://support.apple.com/kb/DL1400
    About the Mac OS X v10.6.8 Update - http://support.apple.com/kb/HT4561
    10.6.8 will let you install the newest iTunes.
    Back up your computer first, just to be safe.

  • My device - iPhones 4s is not showing up on my itunes, i have downloaded the new itunes to my mac but for some reason it says 'iPhone does not have itunes 10.5', please help?

    How do i get itunes 10.5 to my new iphone 4s? I have downloaded it to my mac, but when i open my itunes there is no device loacated on the left hand side of my screen? please help.

    Which Mac OS X do you have installed?
    With iTunes open, from the menu bar click iTunes > About iTunes
    The latest version is 10.5.2

  • New Two Slot USB Mac Reader for P2 at Panny Booth NAB2006

    Jan Crittenton mentioned that there is a USB Mac reader being developed that will work with the MacBook Pros.
    She indicated it was available for viewing at the Panasonic booth at NAB?
    Just another P2 store, or something different at a different price point?
    Jan didn't mention price or the difference between it and the p2 store.
    Anybody got the skinny on this device?

    The one I had at the booth was a five card reader. It was USB 2 and firewire 800. Currently there already is a 5 card reader that is USB 2.0...but they go for $2000...as will the new ones.
    Jan did say that they are working on a smaller one...a single or dual card reader. But there wasn't a mock up at the booth that I saw.
    Shane

  • Old computer crashed.  trying to sync my iphone with new computer but phone is looking for old computer.  how do i change it?

    old computer crashed.  iphone is looking for old computer so I can't get it to sync with my new computer.  Suggestions?

    See Recover your iTunes library from your iPod or iOS device.
    tt2

Maybe you are looking for

  • Acrobat Pro XI gives an error when trying to use the Get the Others to Sign feature.

    The error is "There is a system error. Please try again later." I use my Adobe ID for both Acrobat and EchoSign to log in but Acrobat will not connect to EchoSign.  I would like to send documents from Acrobat without having to load them into EchoSign

  • Datasource using com.evermind.sql.DriverManagerDataSource

    Is com.evermind.sql.DriverManagerDataSource still supported? If not can you direct me to documents on the new way of using datasources. In JDeveloper 10.1.3, "Embedded OC4J Server Preference -> Datasource" gives me three choices: Connection Pool,Mana

  • Trouble installing .air app on mac

    For the sake of people searching, or if the image gets removed on day, here is the error message as text: "Sorry, an error has occured.  The application cannot be installed due to a certificate problem.  The certificate does not match the installed a

  • Nano(4GB) stuffed!! No tunes will load, "do not disconnect" wont dissapear!

    Please help! Could someone please explain to me, step by step, how to fix the following problem: I accidently plugged my nano into a pc with shuffles software and that erased everything I had on my ipod. Now when my nano's plugged into the correct pc

  • ArrayCollection question in cairngorm

    Hi, I have a simple cfc, the function is like this,it get a department list <cffunction name="getDept" displayname="getDept" access="remote" output="false" returntype="query"> <cfquery name="getDepartment" datasource="bursary"> SELECT Id, Dept FROM t