Cisco ISE & Cisco Meraki Wireless Access Points

Shadius
Building a reputation

Cisco ISE & Cisco Meraki Wireless Access Points

Hi all,

 

I'm having issues with getting Cisco ISE to work with the Cisco Meraki Wireless Access Points.

 

All the access points have been added into Cisco ISE. When testing connectivity to the wireless network a few weeks back, it all worked flawlessly. Now, I am prompted for a username and password and when I enter it, it doesn't connect. While connecting to the wireless network, it will just say "Can't connect to this network." I'm not sure what's going on. Nothing has changed.

 

I have some access points able to communicate with Cisco ISE and some are alerting that it cannot connect.

 

What can I check to begin troubleshooting?

7 Replies 7
PhilipDAth
Kind of a big deal
Kind of a big deal

Is Cisco ISE seeing the authentication attempts?

If so, does it say that it is allowing or denying them?

Shadius
Building a reputation

@PhilipDAth 

 

So I'm seeing some PermitAccess and others show blank.

 

I just ran the test from the Meraki Dashboard and I see the two access points that are alerting show the Identity as USERNAME and under the Authorization Profiles, it's blank. The access points that went through show my Identity as my username and show PermitAccess for the Authorization Profiles.

Shadius
Building a reputation

I am totally lost with this.

 

Some access points seem healthy and some display alerts with RADIUS.

 

How can it be half and half?

MilesMeraki
Head in the Cloud

Check the Radius logs/logging on ISE and see if you're getting RADIUS logging attempts. If you are you can troubleshoot based on the error messages.

 

If the logs aren't showing it could be that RADIUS isn't hitting ISE. I'd then look at any firewall/network changes which may have impacted the RADIUS traffic from APs to ISE.

Eliot F | Simplifying IT with Cloud Solutions
Found this helpful? Give me some Kudos! (click on the little up-arrow below)
Matlyna
Conversationalist

Did you add them via a range? 

Meraki needs to have each device added individually or you'll get some odd behavior with some users and not all users.

 

Stacked switches need to have each switch added manually. (Can copy another profile; change ip, change hostname)

Add each wireless device individually. (Can copy another profile; change ip, change hostname)

Shadius
Building a reputation

I've added each Cisco Meraki wireless access point into Cisco ISE individually.

Johnmccsi
Comes here often

Interesting behavior needing to be added individually. What were the issues that you were experiencing with using a Range as a device.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels