Skip to main content
Staff & Editor
October 24, 2022

Technical Tip: FortiNAC Guest users are rejected because to User-Password Attribute is not Send by Cisco Wireless Controller

  • October 24, 2022
  • 0 replies
  • 646 views
Description This article describes how to allow Cisco's wireless controller to send the User-Password attribute in the RADIUS Access-Request packet.
Scope FortiNAC.
Solution

Cisco WLC might sometimes not send the User-Password Attribute in the RADIUS Access-Request packet if a wrong RADIUS compatibility Mode is selected.

From the RADIUS logs, it is noticed that the NAS device (Cisco WLC) was not sending the User-Password attribute after a user is connected to the SSID.


Wed Sep 1 13:21:18 2022 : Auth: (36) Login incorrect

(rest:You set 'Auth-Type = REST' for a request that does not contain a User-Password attribute!):[112233445566] (from client 10.10.10.41 port 13 cli 11-22-33-44-55-66)

 

On the Cisco WLC, select the Security tab -> MAC Filtering and make sure the RADIUS compatibility Mode is 'Cisco ACS'.


Hawada1_0-1666538695630.png


In the MAC Filtering window, choose the type of RADIUS server under RADIUS Compatibility Mode to be 'Cisco ACS' (this mode will include User-Password AVP in the RADIUS Access-Request with MAC Authentication password as Client's MAC address).

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.