Introduces SAE client exclusion visibility, enabling controllers to access client exclusion list data in Flex central authentication deployments with SAE-enabled WLANs, and reducing the need for manual log collection for enhanced operational efficiency.
SAE client exclusion visibility is a feature that
-
addresses a limitation in Flex central authentication deployments with SAE-enabled WLANs
-
makes client exclusion list data available on the controller, and
-
reduces manual log collection for customers.
In FlexConnect central authentication deployments with SAE enabled WLANs, the controller does not have access to client exclusion list data because SAE authentication messages are processed at the AP, and authentication failures are not reported to the controller. As a result, you must collect logs manually, which increases operational costs. This feature provides a solution to this issue.
This feature addresses only Flex central authentication, WPA3 + SAE/FT-SAE/SAE-EXT-KEY/FT-SAE- EXT-KEY WLANs.
Feature history for SAE client exclusion visibility
| Feature Name |
Release Information |
Feature Description |
|---|---|---|
| SAE client exclusion visibility |
Cisco IOS XE 17.18.2 |
The SAE authentication client exclusion feature overcomes the limitations of Flex central authentication deployments with SAE-enabled WLANs. The feature reports client authentication failures and exclusion data to the controller. It generates syslog messages for these events and allows administrators to configure the duration that a client remains excluded. It centralizes troubleshooting information that was previously only available on individual APs, reducing the need for manual log collection. |