So many questions :) Thanks for all of the input folks! Here's some answers:
1. We changed from one controller to two during the summer and we also have ISE setting the VLAN depending on username type. Eight characters (ebarnett) gets one IP, name.name (eric.barnett) gets another. 2. No load balancer in the middle of anything. 3. We have four psn's and are having problems with all of them. 4. Reboots of the controller and ISE have no effect. 5. Using Microsoft AD and we have about 6000 users connected to our SSID right now. Thanks again for the interest! We're very, very stuck right now. --Eric -----Original Message----- From: The EDUCAUSE Wireless Issues Constituent Group Listserv [mailto:[email protected]] On Behalf Of Jason Wang Sent: Wednesday, August 27, 2014 2:28 PM To: [email protected] Subject: Re: [WIRELESS-LAN] Authentication failures at peak times (Cisco) We saw similar symptoms in the past. Our setup was a bit different though. What it came down to for us was that the EAP conversation would start on one backend RADIUS server, but it would jump to a different backend server part way through. The backend servers didn't share state, so when the EAP conversation changed backend servers, it would return a failure. In our case, it turned out to be a problem with the RADIUS load balancers that our controllers were pointed to. Do your controllers talk through an intermediate proxy/load balancer? Do the RADIUS servers themselves show access-rejects for those failed auths? Do those access-rejects show up on both (or all) of your RADIUS servers almost simultaneously? I don't know how ISE implements its RADIUS function, but do auths go directly against the server, or is there another intermediate layer? Some things you might be able to try for troubleshooting: - Have the controller point to only one RADIUS server directly (no proxies/load balancers) - Try a different RADIUS server Jason On 08/27/2014 01:11 PM, Eric T. Barnett wrote: > We've got a relatively small deployment compared to many on this list, but > we've run into a problem we just can't put our finger on. We're using 5508s > and ISE as a RADIUS server and we're having HUGE latencies on WPA2-Enterprise > PEAP authentication. There's times when almost no one can authenticate. > What's really weird is that the controllers show "AAA Authentication Error" > when this happens even though the username and password is correct. None of > the devices seem distressed and there's no network problems we can see. > Anyone ever seen this before or have any ideas how to troubleshoot? TAC so > far has been not incredibly useful but they have only been on the case for a > day or so now. I can hear my users sharpening the pitchforks... > > Thanks, > > Eric Barnett > Wireless Administrator > Information and Technology Services > Arkansas State University > 870 680 4243 > > ********** > Participation and subscription information for this EDUCAUSE Constituent > Group discussion list can be found at http://www.educause.edu/groups/. ********** Participation and subscription information for this EDUCAUSE Constituent Group discussion list can be found at http://www.educause.edu/groups/. ********** Participation and subscription information for this EDUCAUSE Constituent Group discussion list can be found at http://www.educause.edu/groups/.
