WLC Audit Status Mismatch
Hi,
We have two WLC 01 and 02, the WLC01 its the primary and all of AP has WLC01 as primary and WLC02 as secondary.
We've had network issues that have caused WLC01 to lose connectivity (temporarily) - this caused WLC02 to take the Active role, but some users are left without service (others are not affected).
We had to reboot WLC02 to force WLC01 to return to the Active role so all the users recover the service.
The only unusual sign we've noticed is a "Mismatch" Audit Status that shows up in the Configure -> Controllers window in the WCS.
What could be missing?
I have the WLC02 configuration (show run-config) and I can see that not all interfaces are configured, i mean configuration is missing on WLC02.
***But these interfaces appear reviewing the configuration of the WLC02 through the WCS (Configre->Controllers->WLC02->System->Interfaces)
If I run the refresh will fix the problem?
Similar Messages
-
NCS Prime 1.3 Controller Audit Status Mismatch
When performing an audit from NCS Prime 1.3 on our 5508 controllers (500 lic) we are getting mismatch messages from many of our 3602i AP's that say the following...
(Type)Configuration Name Audit Status Attribute Prime Infrastructure Value Controller Value
(AP APname, Interface) 802.11a/n Mismatch Spectrum Intelligence true false
These AP's are not configured as Spectrum Intelligence on the controllers, rather as local. It seems that NCS believes that they are supposed to be SI. We have refreshed the config from controller many times but this does not change.
The 5508's run v.7.2.111.3
Is there a change I can make on NCS or otherwise to make this mismatch go away? Is this a bug? It is not causing any problems (that we can see) but as most would rather not have these mismatches.
Much Thanks!Well when you do an audit, you specify what templates you want to audit the WLC's against. So take a look at when you perform an audit as to what tempted you have chosen. This could of been an old template and needs to be removed.
Sent from Cisco Technical Support iPhone App -
WLC Audits on WCS - Configuration names question
Hi Everyone,
I've been clearing up the config differences between my WCS and the WLCs and for the most part I've identified what each line in the audit report refers to. However the following has me stumped:
Configuration Name Audit Status Attribute Value in WCS Value in Controller
150.3.40.240/1 Mismatch interval 1 10
150.3.40.240/4 Mismatch interval 1 10
150.3.40.240/5 Mismatch interval 1 10
150.3.40.240/6 Mismatch interval 1 10
150.3.40.240/7 Mismatch interval 1 10
150.3.40.240/8 Mismatch interval 1 10
150.3.40.240/9 Mismatch interval 1 10
150.3.40.240/10 Mismatch interval 1 10
150.3.40.240/11 Mismatch interval 1 10
150.3.40.240/12 Mismatch interval 1 10
150.3.40.240/HR Not Present In WCS - - -
150.3.40.240/OM Not Present In WCS - - -
150.3.40.240/PK Not Present In WCS - - -
150.3.40.240/EG Not Present In WCS - - -
150.3.40.240/KZ Not Present In WCS - - -
150.3.40.240/BH Not Present In WCS - - -
150.3.40.240/VN Not Present In WCS - - -
150.3.40.240/EC Not Present In WCS - - -
150.3.40.240/KW Not Present In WCS - - -
150.3.40.240/PY Not Present In WCS - - -
150.3.40.240/PR Not Present In WCS - - -
150.3.40.240/CR Not Present In WCS - - -
150.3.40.240/DO Not Present In WCS - - -
It would be really easy to just do a "restore values from controller" to reslove the differences but I'd really like to find these within the configuration pages in order to increase my understanding of the CUWN.
Can anyone tell me what these entries are?
Many Thanks
ScottHi Sam,
Is that relevant? I was really looking for the location of these configuration options/parameters within either WCS or the WLCs.
thanks
Scott -
Problem with WCS Audit status missmatch after upgrade
We had problem with wcs Audit status missmatch after upgrade to 7.0.164.3 WLC : 6.0.188.0.
how I can fix the problem?Hi,
Try pinging the WCS from the WLC and vice versa and then try again to refresh config from controllers.. then follow the below if its still not happening..
Please forwrd the trace level logs from the WCS (Specifically WCS0.0.TXT logs) while recreating the issue!!
Regards
Surendra -
WLC audit reports on Lobby ambessador activities
Is there any way that we can get an audit trail report on the activities of user "Lobby ambesador" from wither WLC or WCS ?
Hi Nalaka,
Hope all is well :)
Maybe this is what you are looking for;
Logging the Lobby Ambassador Activities
The following activities are logged for each lobby ambassador account:
â¢Lobby ambassador login: WCS logs the authentication operation results for all users.
â¢Guest user creation: When a lobby ambassador creates a guest user account, WCS logs the guest user name.
â¢Guest user deletion: When a lobby ambassador deletes the guest user account, WCS logs the deleted guest user name.
â¢Account updates: WCS logs the details of any updates made to the guest user account. For example, increasing the life time.
Follow these steps to view the lobby ambassador activities.
Note You must have superuser status to open this window.
Step 1 Log into the Navigator or WCS user interface as an administrator.
Step 2 Click Administration > AAA, then click Groups in the left sidebar menu to display the All Groups window.
Step 3 On the All Groups windows, click the Audit Trail icon for the lobby ambassador account you want to view. The Audit Trail window for the lobby ambassador displays.
This window enables you to view a list of lobby ambassador activities over time.
â¢User: User login name
â¢Operation: Type of operation audited
â¢Time: Time operation was audited
â¢Status: Success or failure
Step 4 To clear the audit trail, choose Clear Audit Trail from the Select a command drop-down menu and click GO.
http://www.cisco.com/en/US/docs/wireless/wcs/4.2/configuration/guide/wcsmanag.html#wp1076868
http://www.cisco.com/en/US/docs/wireless/technology/guest_access/technical/reference/4.1/GAccess_41.html#wp1001609
Hope this helps!
Rob -
Batch Status - Status Mismatch
Hi,
When certain batches are transferred all the batch lines get transferred but the status of the batch continue to remain 'Status Mismatch'.
All the batch lines are converted into element entries but the Batch Header still has the status mismatch status.
Can anyone help me what could be the reason for this and please let me know how to prevent this?
Regards,
BalooIf you created batches through standard (seeded) functionality within the application (BEE) and transferred though a standard (seeded) process and you are getting the "Status Mismatch" error, please log a service request with Oracle Support. This would potential point to a product defect (which may already be identified and fixed).
If the all of the batches in error were created (loaded) through a custom process, this is most likely not a bug. Rather, the custom process should be modified to ensure the status mismatch does not occur. Even though you used the seeded BEE Process to transfer, the mismatch may have occurred prior to that point.
Regards,
Greg -
WLC 5508 duplex mismatch error
Hi I've got a WLC 5508 connected to a Catalyst 6000 switch. In the switch I've get a CDP duplex mismatch error every 30 min.
%CDP-4-DUPLEXMISMATCH:Full/half duplex mismatch detected on port 3/23
with the show port command I can see this:
Port Name Status Vlan Duplex Speed Type
3/23 WLC connected trunk full 1000 10/100/1000
With the show CDP neigh I see a duplex mismatch
C6K9> (enable) sh cdp neig 3/23 detail
Port (Our Port): 3/23
Holdtime: 142 sec
Capabilities: HOST
Version:
Manufacturer's Name: Cisco Systems Inc. Product Name: Cisco Controller Product Version: 7.0.116.0 RTOS Version: Erro Bootloader Version: 1.0.1 Build Type: DATA + WPS
Platform: AIR-CT5508-K9
Port-ID (Port on Neighbors's Device): GigabitEthernet0/0/1
VTP Management Domain: unknown
Native VLAN: unknown
Duplex: half (Mismatch)
But in the WLC console there is not half duplex
(WLC5508) show>port 1
STP Admin Physical Physical Link Link
Pr Type Stat Mode Mode Status Status Trap POE SFPType
1 Normal Forw Enable Auto 1000 Full Up Enable N/A 1000BaseTX
I don't have errors in the port counters
How I can resolve this duplex mismatch?Try upgrading the firmware of the WLC to 7.0.230.0.
-
Hello,
Is there an automated way to perform audit of Wlc from the Cisco Prime Infrastructure GUI? I use to go to Monitor->Controller, then check the box near one of the managed wlc, finally choosing 'Audit Now' on the top menu. It works fine, but when you have multiple wlcs, such operation takes a long time. I would like to retain the configuration which is on the wlc instead of the one on the PI database too.
Do you know if there is a better way to perform the audit?
Thanks
ThéophileHave you looked at the background task to see if there is an audit there? Are you really wanting to audit or just refresh the config from the WLC? If you do hate getting the mismatch and dine have all the templates for each of the WLC's, the audit only reviews what's in the templates. Refresh the config from the WLC is the easiest way as you can select all of your WLC and perform this task.
Sent from Cisco Technical Support iPhone App -
WLC - ACS TACACS+ mismatch shared secred
Hello,
I confgured TACACS+ Authentication on WLC 5.0.235.3 for management login.
On ACS 5.1.0.44 I get the message
"13011 invalid tacacs+ request packet - possibly mismatched shared secrets"
after login.
I compared the shared secrets (blanks) or created new secrets, the message still appears.
Some ideas?
Regard SvenHello David,
WLC Version is 7.0.235.3, sorry.
Authentication on WLC and ACS use TACACS not Radius.
On ACS:
Authentication Result
Type=Drop
Authen-Reply-Status=Error
Steps
Received TACACS Authentication START Request
Invalid TACACS request packet - possibly mismatched shared secrets
Output from WLC:
(Cisco Controller) >debug aaa tacacs enable
(Cisco Controller) >*tplusTransportThread: Feb 06 11:37:46.720: Exhausted all available servers for Auth/Author packet
*tplusTransportThread: Feb 06 11:53:34.728: Forwarding request to 10.54.159.11 port=49
*tplusTransportThread: Feb 06 11:53:34.732: AUTH Socket closed underneath
*tplusTransportThread: Feb 06 11:53:39.948: No auth response from: 10.54.159.11, retrying with next server
*tplusTransportThread: Feb 06 11:53:39.948: Preparing message for retransmit. Decrypting first
*tplusTransportThread: Feb 06 11:53:39.948: Forwarding request to 10.54.159.12 port=49
*tplusTransportThread: Feb 06 11:53:39.951: AUTH Socket closed underneath
*tplusTransportThread: Feb 06 11:53:45.164: No auth response from: 10.54.159.12, retrying with next server
*tplusTransportThread: Feb 06 11:53:45.164: Preparing message for retransmit. Decrypting first
*tplusTransportThread: Feb 06 11:53:45.164: Forwarding request to 10.54.159.11 port=49
*tplusTransportThread: Feb 06 11:53:45.166: AUTH Socket closed underneath
*tplusTransportThread: Feb 06 11:53:50.380: Exhausted all available servers for Auth/Author packet
(Cisco Controller) >*tplusTransportThread: Feb 06 11:55:55.564: Forwarding request to 10.54.159.11 port=49
*tplusTransportThread: Feb 06 11:55:55.566: AUTH Socket closed underneath
*tplusTransportThread: Feb 06 11:56:00.780: No auth response from: 10.54.159.11, retrying with next server
*tplusTransportThread: Feb 06 11:56:00.780: Preparing message for retransmit. Decrypting first
*tplusTransportThread: Feb 06 11:56:00.780: Forwarding request to 10.54.159.12 port=49
*tplusTransportThread: Feb 06 11:56:00.783: AUTH Socket closed underneath
*tplusTransportThread: Feb 06 11:56:05.996: No auth response from: 10.54.159.12, retrying with next server
*tplusTransportThread: Feb 06 11:56:05.996: Preparing message for retransmit. Decrypting first
*tplusTransportThread: Feb 06 11:56:05.996: Forwarding request to 10.54.159.11 port=49
*tplusTransportThread: Feb 06 11:56:05.998: AUTH Socket closed underneath
(Cisco Controller) >show tacacs ?
acct TACACS+ accounting server.
athr TACACS+ authorization server.
auth TACACS+ authentication server.
summary Displays TACACS+ summary.
(Cisco Controller) >show tacacs summary
Authentication Servers
Idx Server Address Port State Tout
1 10.54.159.11 49 Enabled 5
2 10.54.159.12 49 Enabled 5
Authorization Servers
Idx Server Address Port State Tout
Accounting Servers
Idx Server Address Port State Tout
(Cisco Controller) >show tacacs auth ?
statistics Displays TACACS+ authentication server statistics.
(Cisco Controller) >show tacacs auth stat
Authentication Servers:
Server Index..................................... 1
Server Address................................... 10.54.159.11
Msg Round Trip Time.............................. 0 (msec)
First Requests................................... 24
Retry Requests................................... 0
Accept Responses................................. 0
Reject Responses................................. 0
Error Responses.................................. 0
Restart Responses................................ 0
Follow Responses................................. 0
GetData Responses................................ 0
Encrypt no secret Responses...................... 0
Challenge Responses.............................. 0
Malformed Msgs................................... 0
Bad Authenticator Msgs........................... 0
Timeout Requests................................. 24
Unknowntype Msgs................................. 0
Other Drops...................................... 0
Server Index..................................... 2
--More-- or (q)uit
Server Address................................... 10.54.159.12
Msg Round Trip Time.............................. 0 (msec)
First Requests................................... 0
Retry Requests................................... 0
Accept Responses................................. 0
Reject Responses................................. 0
Error Responses.................................. 0
Restart Responses................................ 0
Follow Responses................................. 0
GetData Responses................................ 0
Encrypt no secret Responses...................... 0
Challenge Responses.............................. 0
Malformed Msgs................................... 0
Bad Authenticator Msgs........................... 0
Timeout Requests................................. 24
Unknowntype Msgs................................. 0
Other Drops...................................... 0 -
Status mismatch for GOA approval
Hello All,
Landscape SRM 4.0 connected with multiple backends R/3 4.7
Workflow WS90100022 for GOA BUS2000113.
In BBP_PD status is
HEADER I1015 Awaiting Approval
In Document display 'Approval Preview', I can see workflow started -> Result:Approved .
If I check the workitem under SWIA, I can see status 'completed'.
What could be the reason of this mismatch?
Pl give me pointers.
BR
DineshHello Dinesh
in bbp_pd BUS2000113 object id number
service objects
workflow overview
who is the last agent?
i dont see any this workflow WS90100022
BUS2000113 (Contract)
WS14000086 (Automatic approval)
WS14000088 (One-step approval)
WS10400022 (Contract alert)
WS14000148 (n-step approval
it is awkward situation .is it change version in GOA awaiting for approval?
however awaiting for approval means , we require to approve by some one .
did you try back end method swo1 - BUS2000113 - latest version change GOA guid- approved.
Muthu -
Prime, MSE and WLC NMSP Status
I have a 5508 WLC and have loaded a demo of Prime 2.1 and MSE 8.0.
The NMSP status is showing as inactive in Prime and MSE and therefore the clients are not showing on the map I have loaded.
Any ideas?MSE doesn't sync with WLC when added with PI 2.1.1
CSCup93101
Description
Symptom:
NMSP is not active between MSE and WLC when added using PI 2.1.1.
Conditions:
This applies to only MSE added Prime Infrastructure after upgrade to 2.1.1 on Prime Infrastructure.
If the MSE was already added to Prime Infrastructure in 2.1 or previous releases, and then upgrade to PI 2.1.1 was performed customers will not run into the NMSP problem between MSE and WLC after the PI upgrade to PI 2.1.1.
Workaround:
Push a template (Templates > Features and Technologies > Controller > Security > AAA > AP or MSE Authorization) with MSE MAC address and key hash.
Please contact Cisco TAC for a patch.
Last Modified:
Dec 11,2014
Status:
Fixed
Severity:
2 Severe
Product:
Network Level Service
Known Affected Releases:
(1)
2.1(1) -
Hi,
Following is brief summary of the issue:
General Business Process
Shopping Carts are created and ordered on a daily basis. we are using Extended Classic Scenario the follow on document is typically a local Purchase Order. For reporting purpose the data (SC and also PO) are extracted to BI. An initial extraction has been done and thus data is extracted using delta extraction to BI (every 8 hours)
Issue summary
For Shopping Carts a follow on document for all items is created (thus the technical status I1113 u2013 u2018Follow-on Document Createdu2019 is set for all items). Now the SC is extracted to BI, but there this status (I1113) is only displayed for some item, but not for all items (e.g. status I1113 is not set for item 1, but for item 2 &3 or status I1113 is not set for item 2, but item 1 &3).The issue occurs for all kind of SC, independent on the number of items (has been seen for SC with just 1 item, but also with 18 items and in between). The result is that there is a mismatch between SRM and BI. The document status is set correctly in the SRM database, the issue happens only for the data extraction. It works fine for the initial extraction, the issue above only occurs for delta extraction. Also issue is happening only in production system. Not able to replicate in quality or developement system.
Any suggestion or clue how rectify the mismatch status.Dear Poster
Your thread has had no response since it's creation over
2 weeks ago, therefore, I recommend that you either:
- Rephrase the question.
- Provide additional Information to prompt a response.
- Close the thread if the answer is already known.
Thank you for your compliance in this regard.
Jason Boggans
SAP SRM SDN Moderator -
Can anyone tell me or point me in the proper direction for the method to set the native vlan on the WLC? I have a 3750 that is showing a native vlan mismatch going to the 4402.
hello - have a look at this link
http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008070ba8f.shtml
explains config for WLC and uplink switch.
hth
andy -
Employment status mismatches in loan report
Hi,
I have just joined in a support project. Need some guidance to solve a issue.
The employee's loan report was taken from a Adhoc Query and it was found that the employment status is "Active" for the left employees. Pls let me know how to rectify this.
Find below the Action Infotype overview for the employee.
Find below the Query report on loan details:
Loan Infotype overview:
I found that when the employees where entered for loan they were given entry date and system generated end date as 31.12.9999. When the same employee left the Company, their action was changed to "Separation" and was given Employment status as"Withdrawn". Simultaneously the pending loans where also delimited with the same end date (date of leaving). Because of this the loan report entries for left employees showing Employment status "Active"
How to rectify the entries of Employment Status to"Withdrawn" in the loan report
ThanksHi Savni,
Empolyement status(STAT2) we have
ACTIVE- it means employee withcompany
INACTIVE-it means employee not with the company
as you said your client dose not have plans to implement PT and PY then it is okay you can use it.
it wont impact any thing.
but when you have scope of PT and PY then it impacts the PT and PY directly.
as Remi corretly said even if the employee is on LOA then there would be a record(s) in infotype 2001 for the duration of LOA.
Regards,
mohammed -
I deployed SCCM 2012 R2 CU1 client side update two months ago.
All clients have been updated to the CU1 verson but in Console:Monitoring-Deployments-R2 CU1-x64 client update,I find one client has been under "in progress" status for almost two months while the update has actually installed correctly
on it,this client also has passed health check.
I have tried re-sending status message manually but nothing happened.
How to work out this problem?Hi,
Have you check statemessage.log on the client? You could check this according scopeid.
MP_status on the MP also could be checked.
Best Regards,
Joyce
We
are trying to better understand customer views on social support experience, so your participation in this
interview project would be greatly appreciated if you have time.
Thanks for helping make community forums a great place.
Maybe you are looking for
-
I can't open pages doc that I created earlier.
Hello everyone, I'm completely new to Apple community, please forgive me if my question is dumb, but I haven't found any similar question/answer... So I recently bought the new Macbook pro 13" loaded with Maverick, and freely downloaded Pages, Number
-
How can I solve issues with moving mail to different folders?
I am not able to move certain files from one folder to another? I get a pop up that says, "unable to move message" and right underneath that it says, "the message could not be moved to the mailbox inbox". It will not allow me to move anything in that
-
I don't understand why I can't find posts about IOS 8 iMessage problems. I have had a great deal of difficulty with iMessage since I downloaded IOS 8. I have an iPhone 5S and a iPad mini. I have been having problems on both. I also have an iPad
-
Hello everyone, I am looking for Trading Partner configuration Steps for intercompany clearing. I will appriciate if some one can share the important steps. Thanks in Advance Krishna
-
Here's what I want to do: When the mouse is pressed (on mouseDown), set sprite.BlendLevel to a value (I know how to do this). When the mouse is lifted, begin a timer. If the mouse has not been pressed after 30 seconds, the sprite.BlendLevel value cha