H-REAP Local Authentication eap-fast not working

Hi, I'm using a central Radius Server and have leap and eap-fast working fine, but when the wan link fail(local authentication) the new user that try to conect via leap get authenticated but eap-fast fail.
any ideas?. Im using wlc 5.01

If your radius is centrally located and your WAN links goes down, any authentication thats need to go back centrally will fail, unless you have local authentication. Don't know why LEAP would still work if authentication to the radius server has stopped.
Howerver, if you are using local EAP configured on the WLC, then you still will fail authentication because your wlc is centrally located.

Similar Messages

  • I would like to know why when i make a web page and test in my local browser it works fine then when i tranfer to my server i does not work fine example i used javascript to put a prompt bar on a page and it worked fine local but on server not working

    how come when i make a web site and i test it in my local server it works fine when i tranfer to server certain things do not work example i used javascript to put in a prompt bar for a newsletter page at the server it did not work but at local it did also it works at MOZZILLA but not internet explorer i also have cs4 was wondering if there is a way to test a page in dreamweaver and then transfer   THANK YOU X-FACTOR-MEDIA

    In future, please try to make the subject line of your posts shorter. In this case the following would have been sufficient: "JavaScript works locally, but not on remote server".
    Short, but meaningful subject lines make it easier for others to identify what your question is about, and often bring faster help.

  • Authentication and Debugging not working -- since Saturday, July 12

    Hi everyone,
    Since Saturday (July 12), the iTunes U launcher that my institution uses (a Moodle block) has ceased successfully authenticating users. From all the looking I've done, nothing has changed from our side, although I am having to do the investigation remotely, and can only be about 95% certain of that so far.
    I'm also not able to use the debug string to see what credentials are being sent to iTunes U, because there appears to be no difference in the launcher process, whether debugging is enabled or not.
    Is anyone aware of any changes or glitches in the system in the last few days? Any information at all will be very greatly appreciated.
    -JR

    Woolamaloo lives to help with such problems. Woolamaloo is an application specifically designed to access your iTunes U site without any CGI, BlackBoard or Moodle building blocks, etc. It accesses your site directly ... using any credential you supply. In effect, you can use it to "be" any user at your site. It can even show you Apple's debug webpage (if you want to see it). You can use Woolamaloo to verify that your site is not working ... or that it is and you have a local problem. You can find out and download the app here:
    http://itunes.uic.edu/Woolamaloo.html
    It comes in both a Windows and Mac OS version (though I admit to having a Mac OS X bias).

  • Question on H-REAP local authentication

    Hi Guys,
    I am having some trouble understanding local authenticaiton for H-REAP APs with 802.1x authentication and wonder if this is a supported feature, when the AP enters into local auth/local switching mode when the WAN link is down or controller is not reachable.
    in the configuration guide, it says:
    ==================================
    When a hybrid-REAP access point enters standalone mode, WLANs that are configured for open, shared, WPA-PSK, or WPA2-PSK authentication enter the "local authentication, local switching" state and continue new client authentications. In controller software release 4.2 or later releases, this configuration is also correct for WLANs that are configured for 802.1X, WPA-802.1X, WPA2-802.1X, or CCKM, but these authentication types require that an external RADIUS server be configured. You can also configure a local RADIUS server on a HREAP access point to support 802.1X in a standalone mode or with local authentication.
    =====================================
    also from the diagram provided in the configuration guide, there is a RADIUS server on the remote site, which might indicate 802.1x authentication is supported when the link between H-REAP AP and controller fails.
    however from the "enterprise mobility design guide 4.1". it seems 802.1x  auth is not supported for H-REAP APs in local auth / local switching mode.
    can you please clarify if this is a supported feature or not?
    also with the latest WLC image 7.0.116.0, there is one more check box called "local auth" under "advanced" WLAN option, is this button introduing some new features compared with previous 7.0.98.0 release? what would be the difference compared with only "local switching" configured as in previous release?
    when we use local authentication, under local switching / local auth mode, with H-REAP group configured, if 802.1x is supported under this mode, do I just add the local radius server information on the WLC and select it as primary radius server in the H-REAP group for local 802.1x authentication? and the authentication process would be local RADIUS --> local database?
    thanks in advance for your help.

    so if we need a local RADIUS server to do the authentication, we only
    need to check the "enable AP local authentication" box under H-REAP
    group configuration, and configure H-REAP APs as AAA clients in the
    RADIUS server, and we add all H-REAP APs in RADIUS server? Right..also
    I noticed there is one more button "H-REAP Local Auth" under WLAN
    advanced tab, this button is not availabel in previous releases, so what
    extra function does this option introduce compare with previous
    releases? Unfortunately, I cant remember that one and I dont have a WLC at hand right now.Usually all new features are reported on the release notes for each version.Thanks in advance for your time and help.
    Sorry fot my delay I forgot to answer you before :-s

  • EAP-TLS not working with IOS 4.1

    Hello,
    I've lot of iPhone in my enterprise,
    I've configured it putting user certificate and authenticate on the wireless network using EAP-TLS mode, choosing user certificate and give the username, and it was working.
    sometime "can't connect to network" append, but after lot of tries, it work.
    when the network is configured, it's working all the time.
    since 4.1.3, I can't configure this network, I can't approve my server radius certificate (so I succeed to authenticate from server)
    I've already tried to put my root CA certificate in iPhone, doesn't change anything (It should be trusted ! all servers certificate are from this CA)
    I've tried to preconfigure this wireless network with iphone configuration utility, not working.
    Iphone 3GS, iphone 4 since IOS 4.1.3

    Here is the dump log obtened via Iphone configuration utility, with certificate deployed but configuration manually
    Oct 14 15:40:41 unknown wifid[29] <Error>: WiFi:[340292441.191866]: Processing link event UP
    Oct 14 15:40:41 unknown kernel[0] <Debug>: AppleBCMWLANCore::setDISASSOCIATE() [wifid]:
    Oct 14 15:40:41 unknown kernel[0] <Debug>: AppleBCMWLANCore::setASSOCIATE() [wifid]:  lowerAuth = AUTHTYPE_OPEN, upperAuth = AUTHTYPE_WPA2_8021X, key = CIPHER_NONE    , 802.1X .
    Oct 14 15:40:41 unknown kernel[0] <Debug>: [6225.861292541]: AppleBCMWLANNetManager::prepareToBringUpLink(): Delaying powersave entry in order to get an IP address
    Oct 14 15:40:41 unknown kernel[0] <Debug>: AppleBCMWLAN Joined BSS:     @ 0xc0befa00, BSSID = 00:15:70:e6:6d:90, rssi = -41, rate = 54 (100%), channel =  1, encryption = 0x8, ap = 1, failures =   0, age = 9, ssid[11] = "TAO_Employe"
    Oct 14 15:40:41 unknown kernel[0] <Debug>: AirPort: Link Up on en0
    Oct 14 15:40:41 unknown kernel[0] <Debug>: en0: BSSID changed to 00:15:70:e6:6d:90
    Oct 14 15:40:41 unknown eapolclient[410] <Notice>: eaptls_verify_server: server certificate not trusted, status 3 0
    Oct 14 15:40:41 unknown Preferences[101] <Warning>: -[WiFiManager(Private) _enterpriseAssociationResult:withInfo:]: User Information required
    Oct 14 15:40:41 unknown Preferences[101] <Warning>: -[APOtherNetworkController keyboardWillShow:]
    Oct 14 15:40:42 unknown kernel[0] <Debug>: AppleBCMWLANCore::setCIPHER_KEY() [eapolclient]: type = CIPHER_PMK, index = 0, flags = 0x0, key lenght 0, key rsc lenght 0
    Oct 14 15:40:43 unknown Preferences[101] <Warning>: -[VPNBundleController _vpnConfigurationChanged:] (0x278960:<VPNBundleController: 0x278960>): _serviceCount(3), serviceCount(3), toggleInRootMenu(0), RootMenuItem(1)
    Oct 14 15:40:45 unknown wifid[29] <Error>: WiFi:[340292445.893128]: Already associating, will not queue request.
    Oct 14 15:40:46 unknown UserEventAgent[12] <Warning>: Unable to cancel system wake for 2011-10-14 15:40:31 +0200. IOPMCancelScheduledPowerEvent() returned 0xe00002c2
    Oct 14 15:40:51 unknown kernel[0] <Debug>: [6235.874083208]: AppleBCMWLANNetManager::handleDelayedPowerManagementTimeout(): Timed out waiting for IP address, entering powersave mode: 2

  • Locale setting for spanish not working in flex plugin

    I am using the following flex compiler setting in Flex builder 3 and it works fine to support Spanish Locale.
    -locale=en_US,es_US
    But the same setting is not working in eclipse installed with flex4 plugin running on flex 3.5 SDK. I am unable to build project with this setting. If i remove es)US then it works fine.
    Here is my whole compiler setting
    -locale=en_US,es_US -allow-source-path-overlap=true -source-path=locale/{locale}

    you might have to restart eclipse but you shouldn't have too.
    I'd check that Eclipse is actually looking at the sdk you think it is (Eclispe might be pointing to a different sdk than FlashBuilder 3)
    otherwise I am out of ideas
    do you have the error message?

  • Local Adjustment Brush does not work in Windows 7, 64-bit

    All other tools and functions work OK.  My issue is just with the Adjustment Brush;  The Adjustment Panel opens when the brush is selected and the brush moves, but none of the adjustments are applied to the image.  The problem is clearly related to the new operating system.  This was just confirmed, by removing the hard drive with the Windows 7, 64-bit OS,  and inserting an old hard drive with Windows Vista, 32-bit installed. The adjustment brush works fine with the old OS and the same version of PS.
    My normal monitor resolution is 1920 x 1200 with a DPI of 151; however, this DPI is not compatible with PS, so I reset it to 149 evey time I use PS.  Lower screen resolutions and DPI settings don't resolve the problem. I mention this only because of a previous cursor problem that was resolved by changing the DPI.
    I'm using CS4 with Camera Raw version 5.6.  Version 5.5 also does not work.
    Can anyone offer suggestions?

    Problem solved.  One of the recent upgrades to Camera Raw reset the flow rate to zero, which I did not notice until after posting the message.
    Sorry for the error.

  • IPAD 802.1x EAP-GTC not working

    I am trying to connect to wifi enterprise 802.1x   rsa 802.11agn (WPA2,AESCCMP,PEAPv1(EAP-GTC)). 
    Our setup
    Trapeze_AP-M522 -> Trapeze_MX200R (7.3.4.4.0) -> Cisco ACS (5.1) -> RSA
    It's working with windows pc and android (phone, tablet)  . When we use EAP-MSCHAPv2 it's working BUT I need 2 factors. 
    We traced the handshake in the cisco ACS, the ipad first try MSCHAPv2 then send another packet not recongnise as a GTC and then failed.
    Any help and / or a sample ICU .mobileconfig would be very apreciated.
    In ICU we select WPA/Enterprise ,  protocol PEAP,  Authentication  Ask for a password with each connection.
    Thanks

    Im having the same issue. Have you been able to resolve it?

  • [SOLVED] vsftpd on Local Mirror, running but not working

    I'm building a Local Mirror on a vm (vbox) with bridged adapter and fix-ip by following this wiki.
    http://wiki.archlinux.org/index.php/Loc … cal_mirror
    After the painful rsync and those setup, I tried pacman -Syu from another Arch vm (no firewall).  I received the following error.
    :: Synchronizing package databases...
    error: failed retrieving file 'core.db.tar.gz' from 192.168.100.100 : Service not available, closing control connection
    I've tried by nmap on the hosting PC and find that the vsftpd should be running.
    Starting Nmap 4.62 ( http://nmap.org ) at 2010-08-27 01:03 HKT
    Interesting ports on 192.168.100.100:
    Not shown: 1714 closed ports
    PORT   STATE SERVICE
    21/tcp open  ftp
    MAC Address: 08:00:27:76:33:1C (Cadmus Computer Systems)
    Nmap done: 1 IP address (1 host up) scanned in 1.318 seconds
    In the wiki, it suggests to use "ftp" to replace "mirror" for ftp_username & nopriv_user.  I tried both.
    I also find that there is no "archlinux" under my /home/mirror/files as "suggested" by the following statement in vsftpd.conf
    # Chroot directory for anonymous user
    anon_root=/home/mirror/files/archlinux
    I tried both (1) amend the vsftpd.conf to remove the "archlinux", and (2) manually add that directory with owner/group=mirror.
    Meanwhile, I only find under /home/mirror/files 6 items - community core extra community.lastsync core.lastsync extra.lastsync.  Have I completed the rsync successfully?  Or, something is missing.  Is the directory structure correct?
    Is the sample vsftpd.conf in the Local Mirror wiki updated?  I've cross reference it with the vsftpd wiki but I'm not knowledgable enough to find things useful.
    What else should I check?
    I love ArchLinux so much that I really hope that it can work.
    Please help.
    Thanks.
    Last edited by dboat (2010-08-27 15:38:14)

    I have tried couple of Linux distro to learn Linux/Network.  I like ArchLinux's "simple" concept, light weight, updated packages, nice document and fast bootup/shutdown.  I have installed over ten times ArchLinux in different virtualmachines and netbook in the past week.  I will keep some, delete some and create more.  I don't have a fast internet connection and that's why I would like to set up my local mirror.  I am a newbie here, so please feel free to let me know if I am taking too much (bandwidth) from the community, and it is not encouraged for my case.  And sorry if I have already created any trouble.
    Well, back to my problem.
    1. After the rsync, including everything, the / now occupies 14G harddisk space.  Is it a normal size for a local mirror?
    2. I have inserted "Server = file:///home/mirror/files/$repo/os/i686" as the first line in its /etc/pacman.d/mirrorlist
        pacman -Syy  looks fine.
        pacman -Syu  gives a list of warning (xxx: local is newer than core), end with "there is nothing to do"
        pacman -S mplayer  starts installtion normally, but need mirrors on internet cause a large portion of software is missing/inaccessible on my local mirror.
    3. I have tried to login by FileZilla from an Ubuntu vm, and receive this error message (on FileZilla)
    Status:    Connecting to 192.168.100.100:21...
    Status:    Connection established, waiting for welcome message...
    Response:    421 Service not available.
    Error:    Could not connect to server
    Seems I have issues on both the mirror and the vsftpd.  I prefer to resolve the vsftpd problem first, but all suggestion/comment are very welcome.
    Lastly, did I post my question in a wrong place?  If yes, please let me know.

  • EAP-TLS not working

    Hello,
    I have deployed PEAP working well, but not able to make EAP-TLS work. I've followed the deployment guide from Cisco. I can't see anything in the ACS log, and with a debug radius in the AP i can only see a loop sending Access-request and Access-Challenge all the time. I can't see the exchange of certificates between the ACS and the supplicant. I have XP SP2 installed, maybe a problem with SP2?
    Should I issue the certificate of the client to the same person who is actually logged in the machine? Should I put a domain in the supplicant?
    I'm using ACS database authentication.
    If you need more info please let me know.
    Thanks,
    Ruben

    Jason,
    Can you authenticate from the XP clients using LEAP or something other then EAP-TLS?
    If not i would look at upgrading the 350 card drivers on the XP machines to the latest.
    I have had problems before using the cardbus pcmcia adapters on XP, when i installed the latest drivers it worked.
    Let me know how you get on?
    Rgds,
    Paddy

  • Apache, authentication required, key not working

    I'm trying to set up my PC with Apache Server. If i try to access it from my laptop in our home, it serves on 192.168.1.102 I went to no-ip.biz because we have a dynamic IP here. when i try to remotely access the server, i get a screen that says: Authentication required Enter username and password for "linksys BEFW11S4 V.2" at http://XXXXXX.no-ip.biz (xxx being my subdomain i requested) the screen will not accept any 'admin' or the network key i use. Any advice?

    Hi
    You should use port forwarding and forward your apache port (usually 80) to the ip address of the machine that has apached installed
    Hope this works
    Cheers

  • EAP-TLS not working on WinXP client, but does work on W2k?

    Hi
    So I've got EAP-TLS setup using a W2K IAS server as RADIUS, W2K certificate server and cisco 1100 APs. I've got computer certs on four notebooks of which 2 are W2k and the other two are XP. On the W2k PCs I am able to pop in my wireless 350 card and get an IP before logging in (as seen via the dhcp server) and then once logged in, the user cert is used to further authenticate and remain connected to the network (as seen via the IAS logs). Yet when I try to pop in my wireless card on the XP PCs, I get no IP address and nothing ever shows up in the IAS logs...the 1100 ap says that its associated but nothing more. Does anyone have any ideas. Thanks
    Jason

    Jason,
    Can you authenticate from the XP clients using LEAP or something other then EAP-TLS?
    If not i would look at upgrading the 350 card drivers on the XP machines to the latest.
    I have had problems before using the cardbus pcmcia adapters on XP, when i installed the latest drivers it worked.
    Let me know how you get on?
    Rgds,
    Paddy

  • Command line authentication "/ap" is not working on the Mac

    I am trying to connect to my media server using the Mac version of FMLE, but my server has authentication and I cannot connect to it using the command line. I use the /ap command line option with the username:password string, it works on Windows, but not on the Mac.
    Do anyone else have this problem? If someone made it work somehow using command line authentication, could you please tell me how you made it work? Thank you.

    It's working for me.
    Are you using the right credentials? What's the error fmle gives?

  • Edit locally option using Applet not working

    Hi ,
    We do not want to use Activex control for editing a document locally,
    so we are left with Applet option.
    The steps we have followed for using the Applet:
    1) Configuration -- Content Management -- Utilities -- Editing ,
    Active component : Applet, Java Runtime version : 1.4
    2) We have followed the note : 594980 but could find the
    htmlb.properties file at the path specified in the note, so we searched
    for it in our portal, we could find htmlb.properties file in the below
    mentioned path:
    /usr/sap/xxx/JC00/J2ee/cluster/server0/apps/sap.com/irj/servlet_jsp/irj/root/web-inf/portal/portalapps/com.sap.portal.htmlb/lib/htmlb.properties
    we have given codebaseV14 as
    http://java.sun.com/products/plugin/autodl/jinstall-1_4_1-windows-
    i586.cab#version=1,4,1,0 and restarted the server. We got operation
    failed error.
    Please let us know if we are missing some step in between.
    Thanks
    Som

    Hi Karol,
    Yes, it worked fine.
    Here are the steps you need to follow:
    1) Install JRE 1.4 on the client PC where you want to edit the document locally
    2) Follow the OSS note # 879494
    You are also set to edit a document locally..
    let me know if it works..
    Som

  • Printing locally from remote desktop not working

    i have a client who recently upgraded his computers from xp to win7.  he has a multi store quickbooks pos setup where he has to log in to a remote desktop connection onto a server in another store.  he used to just login and run his reports and
    then print them locally.  since the upgrade, he has not been able to do this.  the work around i found was to keep the xp laptop just for printing reports.  well, now he is separating from the other store and going out on his own.  he needs
    to run some reports and save them to the local machine in order to bring the databases to his store.  first, i need to know how to make the win 7 computer print the reports locally, so that he can run them (the xp laptop crashed).  second, i need
    to know how to copy the files onto his local computer (in server 2008 i can drag and drop them, not in 2003). 
    the win 7 is 64 bit, the server 2003 is 32.  i tried installing the print drivers locally onto the server, but it's the wrong architecture.  i also tried installing the 32 bit drivers onto the win 7 machine, same thing.  i found several things
    to try, but really need to get this fixed asap.  when i try to install the printer, it shows up, and adds just fine.  i am really  having a fit here.
    the copying thing is an absolute must also.  i may be able to get by without the print issue fixed, but would like to know what happened just for my own information.  thanx in advance.

    Hi,
    Firstly you can check whether print spooler service is not stopped. Also ensure that printer driver is compatible\supported by Windows 7 and by server. If you are using printer redirection then might happen that it’s not configure properly. The client must
    have enough permission and also check client requirement for printer redirection (RDP 6.1 or above, .Net 3.5or above).
    More information:
    Terminal Server and Printer Redirection
    Five reasons printer redirection causes Windows printing problems in RDS
    For this can you describe little more”second, i need to know how to copy the files onto his local computer (in server 2008 i can drag and drop them, not in 2003).” Do you want to copy from remote session to local computer?
    Hope it helps!
    Thanks,
    Dharmesh

Maybe you are looking for