Locating failed wireless login attempts and which access point they're hitting

We have a cisco 5508 WLC with about 190 access points.  They use Cisco Secure ACS to authenticate Microsoft Active Directory logins.  We sometimes get non-normal accounts attempting to login to our wireless but are unable to figure out which access point they're hitting.  
When I look at the failed attempts in our Cisco Secure ACS 5.5 Radius Authentications report, I don't see an IP address, just the MAC address of the failing device.  Is their a way to configure either the WLC or the ACS box to report either the IP address or MAC address of the access point they're connecting to?

Is this something I need to set the ACS or WLC to send?  When I go to Other attributes in the "Authentications - RADIUS - Today" report, this is all I'm currently seeing.
Other Attributes:
ACSVersion=acs-5.5.0.46-B.723 
ConfigVersionId=3 
DetailedInfo=Invalid username or password specified, Retry is  allowed

Similar Messages

  • Failed user login attempts

    hi can u say  in which failed user login attempts will be stored.

    Hi,
    Configure the SAP audit system with TC SM19.
    Then use TC SM20 to see failed logins (and much more)
    cheers
      Jan

  • N95 Wifi, home network and hidden access points

    Hello-
    Just picked up a N95 and having some problems. First, my home network doesn't broadcast a SSID. I stumbled across the home network option and was able to configure it. However, it's never an option when I need an internet connection; e.g., it never shows up in the wlan list.
    So, how do I congigure a hidden access point so I can use it? The user guide says you should be able to do it manually, but doesn't go into any details.
    Secondly, exactly what is the home network setting for and why is it separate from the other wlan settings?
    Thanks,
    Jay

    Jay,
    I too have a hidden network (SSID not broadcast), the N95 seems to have a problem with this. It may or may not show up on the active standby screen (on my Voda N95, it shows up when I take my sim out!).
    To configure your accesss point :-
    Tools / Settings / Connection / Access Points
    then Options / New access point
    Connection name
    (enter a name, whatever you want to call it)
    Data bearer
    =wireless LAN
    WLAN network name
    (enter your SSID here)
    Network Status
    (public or hidden)
    WLAN network mode
    (Infrastructure or ad-hoc. If you're using a router, infracstructure should be the one you want)
    WLAN security mode
    (Open, WEP, 802.1x or WPA2. Check your router)
    WLAN security settings
    WPA/WPA2
    EAP or Pre-shared key (consult your router)
    EAP plug-in settings or Pre-shared key
    (which one you get depends on what you set above)
    WPA2 only mode
    (leave alone)
    Having done all this it still won't show on the active-standy screen (at least it doesn't on mine) in the WLAN section BUT if you know try and surf the web it should ask which access point you want to use - assuming you've got it set to 'always ask'. What this seems to do is only list the connections that it can find (i.e if you've got a 'Starbucks' and a 'home' connection defined, it'll only show 'home' at home and 'Starbucks' when you're getting your latte. The standby screen may show, how to decribe it, a four leaf clover near to the battery level indicator, this is the indication that it's either found or connected to your wireless lan.
    I think the 'Home netw.' option is for use with the Home Media Server application supplied on the CD. I haven't tried it so can't confirm for sure.
    Hope this helps,
    Simon
    E&OE
    Sony CMD-Z1, Nokia 8110, Nokia 6210, Nokia 6610 (returned within a week), Nokia 6600 (twice), N95, 3109c & N97.

  • Which access point do i use????

    ok then i know how to access the internet and live messenger when i am at home as i use my bt homehub as the access point.
    but when i am away from home i dont know which access point to choose, these are the options i get -
    02 MMS
    02 MOBILE WEB
    O2 PRE PAY MMS
    O2 PRE PAY WAP
    O2 WAP GPRS
    O2 WAP GPRS STREAM
    I am on o2 pay as you go. i think i managed to access it the other by accessing pre pay mms, but it used nearly £5-00 credit in just a few minutes.
    I really need to be able to acces the internet away from home, to use live messenger and also the pre installed satnav, as it always gives the message no route found, must connect to the internet to plan route

    Those with "MMS" are for sending and receiving multimedia messages (MMS = Multimedia Messaging Service).
    Those with "WAP" are for "Wireless Application Protocol" and the connection go through the network operator's WAP gateways, which may limit what protocols are passed through and they might also do something to the content.
    So, for regular Internet access, without knowing O2, the "O2 MOBILE WEB" is most likely to give to a straight-forward, pure Internet connection. No idea what kind of rates O2 will charge, though. Call them and ask, or check their web site.

  • Access Connections 5.61 - Which Access Point am I on?

    I have 3 access points in my area (a mobility center), and it appears only one of them is working. When I go near that one I can get connected but when I logoff and walk near the other two, nothing. I see all 3 listed at 100%, but is there a way to specifically connect to one access point, as it appears to always choose the closest (whether it works or not). I am using Access Connections 5.61. I just noticed there is a field where I can put the preferred MAC address in, but that secion is greyed out. Can I at least determine which access point I am connected through when I do get connected? Thanks in advance.

    Hi,
    You can do it in the way, that you configure 3 different wifi connection for each AP and then you configre the on, that you want to use to be always the prefered using following method:
    in this situation please configure AC in following way:
    - open Ac->Tools->Location Switching-> in the screen make sure, that the location switching in enabled and the key point is, that you specify the correct Wifi AP in the "Preferred WLAN profile".
    Let me know, if you have reached to this situation and cold configure it in the correct way.
    Cheers

  • Which Access Point?!

    I am assigned to implement a wireless network and i intend to use repeater mode in the building but, there is one problem, iam not sure which access point supports more than one MAC address to repeat to and the other to recieve (trying to input more than one MAC address in each AP for redundancy).
    Does anyone know a Cisco or non Cisco AP that supports more than one MAC address for repeating mode?
    Thanks.

    Depending on the size of the building, that approach may not work well in practice.
    Ignoring the potential bottleneck of the 100/1000 connection between the single AP and the WLC/Switch (depending if Autonomous or WLC), repeating the signal X amount of times also reduces the speed/throughput as mentioned by Leo above.
    If you only have a handful of clients using this Wireless Network, it may be fine but its definitely not suitable for a larger deployment where you expect to have maybe 10-15 people per AP.

  • Which access point does it please??!

    I am assigned to implement a wireless network and i intend to use repeater mode in the building but, there is one problem, iam not sure which access point supports more than one MAC address to repeat to and the other to recieve (trying to input more than one MAC address in each AP for redundancy).
    Does anyone know anAP that supports more than one MAC address for repeating mode?
    Thanks.

    Hi aeronav01,
    What pinkyzeny suggested is fine. Bridge mode configuration might not be the right one for the set up you want. WAP300N has a repeater mode. You just have to make sure that the access points configured as a repeater should be facing in different directions to avoid interference. Or you may just configure it as a plain access point and create different networks for each. You may also refer to this link for Bridge Mode . 
    Help, learn and share

  • Problem with PowerBook (but NOT MacBook) and two access points on network

    I recently installed a wall-plugged ethernet adapter system (Netgear XE104 and XE103) and plugged a wireless access point (Netgear WPN802) into one of the adapters (in the part of our house where we lacked a wireless signal) in order to extend the range of our (DSL) wireless network. I configured this new access point--disabled DHCP, assigned an IP address to the access point that does not fall into the wireless router's IP adress range, put the wireless router and access point on different channels (6 and 11), and made sure the router and access point had the same SSID.
    I have had no problems using the resulting setup with our new MacBook--everything goes as planned. BUT I am having a terrible time with my PowerBook G4. It has a really strong signal everywhere, but when I open my browser it says that I am not connected to the internet. The problem seems to be that my PowerBook refuses to change channels once it connects to one. I installed iStumbler to see if I could manually control which access point/channel the PowerBook uses, and, while I can track the signal strengths for both access points, I can't get my PowerBook to switch from one access point to the other.
    I've tried just about everything I can think of. I suppose I could try giving a different SSID to the access point (and then try to switch with the airport menu in the toolbar), but I would like to avoid this if possible.
    I would really appreciate any advice you have. Thank you!

    Can you connect if you temporarily turn off WEP or WPA?
    This will determine if it is a WEP or WPA issue.
    Does your PC support WPA, from both a hardware and a software perspective?
    The problem you are having probably lies with the encryption key.
    Accessing a Airport Network with a Windows XP PC or laptop (with XP SP2)
    http://tech.ifelix.net/1011.html
    Accessing a Airport Network with a Windows XP PC or laptop (with XP SP1)
    http://tech.ifelix.net/1010.html
    Problems connecting an XP PC to an Airport Base Station
    http://tech.ifelix.net/2002.html
    iFelix

  • Security questions, cloud, and multiple access points

    itunes:
    i can't buy anything becasue fo the ******* security questions. thoughts?
    also, can i download from itunes on my air, then, access the songs on both my mbpro and also, iphone4?
    why am i having to ask? siri needs to know.

    There is no way to tell your MacBook which access point to use. Since they all have the same SSID, they are seen as the same seamless network.

  • Dynamic VLAN Assignment with RADIUS Server and Aironet Access Points

    Hi Guys,
    I would like to go for "Dynamic VLAN Assignment with RADIUS Server and Aironet Access Points 1300". I want the AP to broadcast only 1 SSID. The client find the SSID ->put in his user credential->Raudius athentication->assign him to an specific vlan based on his groupship.
    The problem here is that I don't have a AP controller but only configurable Aironet Access Points 1300. I can connect to the radius server, but I am not sure how to confirgure the AP's port, radio port, vlan and SSID.
    http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008076317c.shtml#switch
    I go through some references:
    3.5  RADIUS-Based VLAN Access Control
    As discussed earlier, each SSID is mapped to a default VLAN-ID on the wired side. The IT administrator may wish to impose back end (such as RADIUS)-based VLAN access control using 802.1X or MAC address authentication mechanisms. For example, if the WLAN is set up such that all VLANs use 802.1X and similar encryption mechanisms for WLAN user access, then a user can "hop" from one VLAN to another by simply changing the SSID and successfully authenticating to the access point (using 802.1X). This may not be preferred if the WLAN user is confined to a particular VLAN.
    There are two different ways to implement RADIUS-based VLAN access control features:
    1. RADIUS-based SSID access control: Upon successful 802.1X or MAC address authentication, the RADIUS server passes back the allowed SSID list for the WLAN user to the access point or bridge. If the user used an SSID on the allowed SSID list, then the user is allowed to associate to the WLAN. Otherwise, the user is disassociated from the access point or bridge.
    2. RADIUS-based VLAN assignment: Upon successful 802.1X or MAC address authentication, the RADIUS server assigns the user to a predetermined VLAN-ID on the wired side. The SSID used for WLAN access doesn't matter because the user is always assigned to this predetermined VLAN-ID.
    extract from: Wireless Virtual LAN Deployment Guide
    http://www.cisco.com/en/US/products/hw/wireless/ps430/prod_technical_reference09186a00801444a1.html
    ==============================================================
    Dynamic VLAN Assignment with RADIUS Server and Wireless LAN Controller Configuration Example
    http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008076317c.shtml#switch
    ==============================================================
    Controller: Wireless Domain Services Configuration
    http://www.cisco.com/en/US/products/hw/wireless/ps4570/products_configuration_example09186a00801c951f.shtml
    Any help on this issue is appreicated.
    Thanks.

    I'm not sure if the Autonomous APs have the option for AAA Override.  On the WLC, I can go into the BSSID, Security, Advanced, and there's a checkbox that I would check to allow a Radius server to send back the VLAN.
    I did a little research and it looks like the 1300 may give this option but instead is defined as "VLAN Override".  I've found the release notes for 12.3(7)JA5 (not sure what version you're running) that give mention and a link to configuring EAP on page 4: http://www.ciscosystems.ch/en/US/docs/wireless/access_point/1300/release/notes/o37ja5rn.pdf
    Hope this helps

  • Wlc 5508 and 40 access point 1141n disturbance in the temp response

    Hello,
    i have a wlc 5508 and 40 access point 1141n
    there are 1500 users connected with this controller 5508.
    but when i ping at my gateway  ,there is a disturbance in the temp response .
    Here below a snapshot:
    Réponse de 172.16.1.1 : octets=32 temps=1 ms TTL=55
    Réponse de 172.16.1.1 : octets=32 temps=5 ms TTL=55
    Réponse de 172.16.1.1 : octets=32 temps=2 ms TTL=55
    Réponse de 172.16.1.1 : octets=32 temps=56 ms TTL=55
    Réponse de 172.16.1.1 : octets=32 temps=105 ms TTL=55
    Réponse de 172.16.1.1 : octets=32 temps=433 ms TTL=55
    Réponse de 172.16.1.1 : octets=32 temps=1 ms TTL=55
    Réponse de 172.16.1.1 : octets=32 temps=100 ms TTL=55
    Réponse de 172.16.1.1 : octets=32 temps=300 ms TTL=55
    Réponse de 172.16.1.1 : octets=32 temps=466 ms TTL=55
    Réponse de 172.16.1.1 : octets=32 temps=711 ms TTL=55
    Réponse de 172.16.1.1 : octets=32 temps=900 ms TTL=55
    Réponse de 172.16.1.1 : octets=32 temps=55 ms TTL=55
    Réponse de 172.16.1.1 : octets=32 temps=52 ms TTL=55
    Réponse de 172.16.1.1 : octets=32 temps=54 ms TTL=55
    Réponse de 172.16.1.1 : octets=32 temps=200 ms TTL=55
    Réponse de 172.16.1.1 : octets=32 temps=57 ms TTL=55
    Réponse de 172.16.1.1: octets=32 temps=800 ms TTL=55
    anyone help me?
    thx

    Looks to be wither a duplicate address issue or a configuration issue.  Try to test with only using the 2.4ghz and then again with only the 5ghz and see if you see a difference.
    Thanks,
    Scott
    Help out other by using the rating system and marking answered questions as "Answered"

  • Roaming between RV220W wireless router and WAP121 Access Point

    Hello, I have recently purchased a RV220W wireless router and a WAP121 access point and i would like to allow my users to "roam" between the two networks as needed (so when the user is closer to whichever one they connect to that one since it has a better signal). For the most part I only have experience in cisco IOS and in actual routers not the wireless stuff so my knowledge has not exactly transfered over well.

    William,
    WDS will not work between the RV220W and WAP121 due to incompatible chipsets. The RV220W can be repeated using WDS by another RV220W or RV180W only. You will need to plug the WAP121 into the RV220W or try WorkGroup Bridge mode to repeat the signal.
    Regarding roaming, the router or AP are not aware of each other and do not have the capability to disconnect a client and help them connect to the AP with the stronger signal. The client will switch to the stronger AP only when the original signal is lost.
    The Aironet (enterprise) devices have the ability to utilize a wireless LAN controller which can help keep devices connected to the stronger signal and allow truly seamless roaming between APs.
    - Marty

  • What do I do after "too many login attempts" and I have tried reset of password?

    I am required to have and login to an adobe account to read Overdrive eBooks via my local public library for my iPhone Overdrive app. I have downloaded Overdrive's app update and therefore need to re-login to Adobe to read ebooks again on my iPhone. When I try to login to adobe via my iPhone to do this, I got an error message something like "too many login attempts." I have tried reset of my password and I still get this message and still cannot login. Please help!!!! I am desparate!!!!

    Eliza. I have the same problem, I have replaced the batteries in my wireless keyboard but it is not working therefore I can't log in as I can't type my password.  (Doing this on my iPad). How did you solve yours please. Regards mfa

  • Which access point is better for hospital environments?

    Folks,
    I have a customer in hospital, who requires to have wireless deployed everywhere. The fact is , customer is budget concious, so I designed in such a way to place it in corridors , so that wireless coverage could get inside the rooms, but the doors are fire-proof which blocks RF .
    What are the best practices in deploying AP's in hospital, for eg: is it safe to install AP's next to Medical Imaging Room or other devices which may cause interference
    Which model is suitable for this sort of installation?
    Thanks,
    SID

    Hi SID,
    Please consider in your budget for a Wireless LAN Site Survey. WLAN Site Survey will allow you to better understand WHERE to deploy your AP's and HOW MANY AP's to deploy. When deploying an AP, also bear in mind for AP failures. You can address this issues with either keeping "spare" stocks or putting additional AP's per floor so when an AP would fail, the WLC will calculate and increase the transmission power to cover the loss of an AP.
    In regards to what models to buy, I'd recommend looking at the 1140 or the 1250. These AP's are geared up for Draft N (2.0 Ratified).
    For AP's that are geared up for 802.11N (Draft 2.0):
    Data Sheet Cisco Aironet 1140 Series Access Point
    http://www.cisco.com/en/US/prod/collateral/wireless/ps5678/ps10092/datasheet_c78-502793.html
    Data Sheet Cisco Aironet 1250 Series Access Point Data Sheet
    http://www.cisco.com/en/US/prod/collateral/wireless/ps5678/ps6973/ps8382/product_data_sheet0900aecd806b7c5c.html
    If you are going to choose the 1250, note that the Antennaes are optional. Here's some information regarding them.
    Antenna Product Portfolio for Cisco Aironet 1250 Series Access Points
    http://www.cisco.com/en/US/prod/collateral/wireless/ps7183/ps469/at_a_glance_c45-513837.pdf
    The AP1250, when operating with 2 radio modules on Autonomous IOS, requires a minimum of 18.5 watts (ePoE). So you'll need either a Power Injector or PoE switch that will support enhanced PoE such as the 3560-E or 3750-E.
    Cisco Nurse Connect Solution
    http://www.cisco.com/web/strategy/docs/healthcare/nurse_connect_aag.pdf
    Hope this helps.

  • Third Party Signal Repeaters/Wireless Extenders for Boosting Cisco Access Points Indoors

    We are have some buildings that have access points (Cisco 2602e with 6dBi Terrawave omni antennas) in the hallways, in which the clients residing in rooms aren't receiving a strong enough signal to connect at suitable rates. The main reason for this is the large thick doors utilized for the client rooms reducing the strength of the signal, and we weren't authorized to place APs inside the rooms. Nor are we able to modify the structure of the building, such as changing the doors. We can't ask or expect the clients to keep their doors open to rcv a stronger signal. I've tweaked the Tx power for the APs, and lowered the mandatory rates on the WLC for this location under the RF profile created for it, but this isn't resolving the issue with the weak signal.
    One band aid solution idea was to place signal repeaters (low profile) inside each room, behind the wall/door area facing the hallway. I've seen a few third party products online, but they seem to only come in support of the 2.4GHz band. If this is a feasible solution, then it looks like we wouldn't be able to support clients on the 5GHz band on our AP, as clients would most likely connect to the 2.4 GHz band due to a stronger signal, limiting our load balancing on the AP. Anyone have experience with using signal repeaters that work properly with Cisco APs.
    Not the ideal situation, but have the hands strapped on what we can do.

    If you've got a WLC, then disable TPC and crank up the power to full.  

Maybe you are looking for

  • Custom fields in SRM 7.0

    Hi all, Im working on SRM 7.0.I need to add few custom fields in SC and PO screen at header level.I have worked on similar requirement in SRM 5.0 but not on SRM 7.0.Can anybody explain what are the differences in the proceudre for addition of custom

  • How to calcualte opening balance of supplier for given period

    Hi all, i have to develoed suppler ledger report.please help me how to calculate opening balance of supplier. Thanks and regards,

  • Can I connect Oracle Forms Builder 10g to MS Access Database

    Hi, I have Oracle forms builder installed in my PC. I downloaded the Oracle Database Server from the oracle website and installed that as well. But due to the installation of Database server, my system has become very slow. In order to avoid this I w

  • Very urgent - java frame ticker in the taskbar

    hi all , i want a typical feature.i am using UI frame(window) for my application.when i put a task in the UI running and minimize in the taskbar.the window should glow(ticker like real player)indicating that some task is running in the window and it

  • Insert an image within a clip

    How can I insert an image within a clip so to have it only on the left half and the clip on the right?