<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MFP problem in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226457#M216603</link>
    <description>&lt;P&gt;Security&lt;/P&gt;
&lt;P&gt;802.11 Authentication:........................ Open System&lt;BR /&gt; FT Support.................................... Disabled&lt;BR /&gt; Static WEP Keys............................... Disabled&lt;BR /&gt; 802.1X........................................ Disabled&lt;BR /&gt; Wi-Fi Protected Access (WPA/WPA2)............. Enabled&lt;/P&gt;
&lt;P&gt;--More-- or (q)uit&lt;BR /&gt; WPA (SSN IE)............................... Disabled&lt;BR /&gt; WPA2 (RSN IE).............................. Enabled&lt;BR /&gt; TKIP Cipher............................. Disabled&lt;BR /&gt; AES Cipher.............................. Enabled&lt;BR /&gt; CCMP256 Cipher.......................... Disabled&lt;BR /&gt; GCMP128 Cipher.......................... Disabled&lt;BR /&gt; GCMP256 Cipher.......................... Disabled&lt;BR /&gt; OSEN IE.................................... Disabled&lt;BR /&gt; Auth Key Management&lt;BR /&gt; 802.1x.................................. Disabled&lt;BR /&gt; PSK..................................... Disabled&lt;BR /&gt; CCKM.................................... Disabled&lt;BR /&gt; FT-1X(802.11r).......................... Disabled&lt;BR /&gt; FT-PSK(802.11r)......................... Disabled&lt;BR /&gt; PMF-1X(802.11w)......................... Disabled&lt;BR /&gt; PMF-PSK(802.11w)........................ Enabled&lt;BR /&gt; OSEN-1X................................. Disabled&lt;BR /&gt; SUITEB-1X............................... Disabled&lt;BR /&gt; SUITEB192-1X............................ Disabled&lt;BR /&gt; FT Reassociation Timeout................... 20&lt;BR /&gt; FT Over-The-DS mode........................ Enabled&lt;BR /&gt; GTK Randomization.......................... Disabled&lt;BR /&gt; SKC Cache Support.......................... Disabled&lt;/P&gt;</description>
    <pubDate>Mon, 04 Dec 2017 12:43:01 GMT</pubDate>
    <dc:creator>Alexey Kurchenko</dc:creator>
    <dc:date>2017-12-04T12:43:01Z</dc:date>
    <item>
      <title>MFP problem</title>
      <link>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226374#M216597</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a problem with configure MFP on WLС 2504. The firmware version 8.5.105.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I set up the PMF PSK, but in the management and control frames in the RSN fields do not contain PMF records.&lt;/P&gt;
&lt;P&gt;The screenshot shows a fragment of the bacon frame.&lt;/P&gt;
&lt;P&gt;What can be wrong?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 14:56:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226374#M216597</guid>
      <dc:creator>Alexey Kurchenko</dc:creator>
      <dc:date>2021-07-05T14:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: MFP problem</title>
      <link>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226401#M216598</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/249229"&gt;@Alexey Kurchenko&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;First MFP and PMF are two different features, although they have similar objectives.&lt;/P&gt;
&lt;P&gt;Let´s assume that you are looking for PMF (802.11w). Did you enabled it on WLAN from "Optional" to "Required"?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 11:17:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226401#M216598</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-12-04T11:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: MFP problem</title>
      <link>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226412#M216599</link>
      <description>&lt;P&gt;Yes.&amp;nbsp;I turned on&amp;nbsp;&amp;nbsp;"Required"&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Management Frame Protection&lt;BR /&gt; Global Infrastructure MFP state................ Enabled&lt;BR /&gt; AP Impersonation detection..................... Disabled&lt;BR /&gt; Controller Time Source Valid................... False&lt;/P&gt;
&lt;P&gt;WLAN Client&lt;BR /&gt;WLAN ID WLAN Name&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Status&amp;nbsp; &amp;nbsp; &amp;nbsp; Protection&lt;BR /&gt;------- ------------------------- --------- ----------&lt;BR /&gt;1 WIFI-LAB&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Enabled&amp;nbsp; &amp;nbsp; &amp;nbsp;Required&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 11:33:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226412#M216599</guid>
      <dc:creator>Alexey Kurchenko</dc:creator>
      <dc:date>2017-12-04T11:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: MFP problem</title>
      <link>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226432#M216600</link>
      <description>&lt;P&gt;Interesting. This link is very clear that, by enabling this feature, you are able to see this information on beacons:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/5700/software/release/ios_xe_33/11rkw_DeploymentGuide/b_802point11rkw_deployment_guide_cisco_ios_xe_release33/b_802point11rkw_deployment_guide_cisco_ios_xe_release33_chapter_0100.html" target="_self"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/5700/software/release/ios_xe_33/11rkw_DeploymentGuide/b_802point11rkw_deployment_guide_cisco_ios_xe_release33/b_802point11rkw_deployment_guide_cisco_ios_xe_release33_chapter_0100.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;8.5 version is very new, I'm always a bit skeptical&amp;nbsp; when it comes to too new release. If you are able to, you can try open a TAC, maybe this is a bug. Or you can try another WLC version as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 12:00:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226432#M216600</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-12-04T12:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: MFP problem</title>
      <link>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226441#M216601</link>
      <description>&lt;P&gt;Thanks Flavio.&lt;/P&gt;
&lt;P&gt;I tried the old version too.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(Cisco Controller) &amp;gt;show boot&lt;BR /&gt;Primary Boot Image............................... 8.5.105.0 (default) (active)&lt;BR /&gt;Backup Boot Image................................ 8.2.110.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 12:13:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226441#M216601</guid>
      <dc:creator>Alexey Kurchenko</dc:creator>
      <dc:date>2017-12-04T12:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: MFP problem</title>
      <link>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226454#M216602</link>
      <description>&lt;P&gt;&amp;nbsp;I didn't ask but WPA/WPA2 is enable, right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here some relevant informations:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Cisco's legacy Management Frame Protection is not related to the 802.11w standard that is implemented in the 7.4 release.&lt;BR /&gt;-The 802.11w standard is supported on all 802.11n capable APs except those that are configured for FlexConnect operation.&lt;BR /&gt;-The 802.11w standard is supported on the following Cisco Wireless LAN Controller model series: 2500, 5500, 8500, and WiSM2.&lt;BR /&gt;-The 802.11w standard is not supported on the following Cisco Wireless LAN Controller models: Flex 7500 and Virtual Wireless LAN Controller.&lt;BR /&gt;-802.11w cannot be applied on an open WLAN, WEP-encrypted WLAN, or a TKIP-encrypted WLAN.&lt;BR /&gt;-The WLAN on which 802.11w is configured must have either WPA2-PSK or WPA2-802.1x security configured.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sure you are in compliance with everything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 12:34:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226454#M216602</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-12-04T12:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: MFP problem</title>
      <link>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226457#M216603</link>
      <description>&lt;P&gt;Security&lt;/P&gt;
&lt;P&gt;802.11 Authentication:........................ Open System&lt;BR /&gt; FT Support.................................... Disabled&lt;BR /&gt; Static WEP Keys............................... Disabled&lt;BR /&gt; 802.1X........................................ Disabled&lt;BR /&gt; Wi-Fi Protected Access (WPA/WPA2)............. Enabled&lt;/P&gt;
&lt;P&gt;--More-- or (q)uit&lt;BR /&gt; WPA (SSN IE)............................... Disabled&lt;BR /&gt; WPA2 (RSN IE).............................. Enabled&lt;BR /&gt; TKIP Cipher............................. Disabled&lt;BR /&gt; AES Cipher.............................. Enabled&lt;BR /&gt; CCMP256 Cipher.......................... Disabled&lt;BR /&gt; GCMP128 Cipher.......................... Disabled&lt;BR /&gt; GCMP256 Cipher.......................... Disabled&lt;BR /&gt; OSEN IE.................................... Disabled&lt;BR /&gt; Auth Key Management&lt;BR /&gt; 802.1x.................................. Disabled&lt;BR /&gt; PSK..................................... Disabled&lt;BR /&gt; CCKM.................................... Disabled&lt;BR /&gt; FT-1X(802.11r).......................... Disabled&lt;BR /&gt; FT-PSK(802.11r)......................... Disabled&lt;BR /&gt; PMF-1X(802.11w)......................... Disabled&lt;BR /&gt; PMF-PSK(802.11w)........................ Enabled&lt;BR /&gt; OSEN-1X................................. Disabled&lt;BR /&gt; SUITEB-1X............................... Disabled&lt;BR /&gt; SUITEB192-1X............................ Disabled&lt;BR /&gt; FT Reassociation Timeout................... 20&lt;BR /&gt; FT Over-The-DS mode........................ Enabled&lt;BR /&gt; GTK Randomization.......................... Disabled&lt;BR /&gt; SKC Cache Support.......................... Disabled&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 12:43:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226457#M216603</guid>
      <dc:creator>Alexey Kurchenko</dc:creator>
      <dc:date>2017-12-04T12:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: MFP problem</title>
      <link>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226463#M216604</link>
      <description>&lt;P&gt;Can you run "debug pmf events enable" and share ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 12:50:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226463#M216604</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-12-04T12:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: MFP problem</title>
      <link>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226475#M216605</link>
      <description>&lt;P&gt;Done. Only "debug&amp;gt;11w-pmf events enable" command.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 13:13:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226475#M216605</guid>
      <dc:creator>Alexey Kurchenko</dc:creator>
      <dc:date>2017-12-04T13:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: MFP problem</title>
      <link>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226482#M216606</link>
      <description>&lt;P&gt;Alright. Attach logs here when you're done.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 13:23:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3226482#M216606</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-12-04T13:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: MFP problem</title>
      <link>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3227139#M216607</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;SPAN&gt;&amp;nbsp; Flavio.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I reset the wlc settings and re-configured it. Debug file in attach.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-message-author-with-avatar"&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-Red lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 05 Dec 2017 13:00:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3227139#M216607</guid>
      <dc:creator>Alexey Kurchenko</dc:creator>
      <dc:date>2017-12-05T13:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: MFP problem</title>
      <link>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3227155#M216608</link>
      <description>&lt;P&gt;This log is interesting:&lt;/P&gt;
&lt;P&gt;"Marking Mobile as non-11w Capable"&lt;/P&gt;
&lt;P&gt;So, looks like you are testing with a non-11w capable device. Well, this should not be the cause in my opinion. I believe AP should send the 802.11w on its beacons anyway.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Just make sure the packet you got is send from AP and not from Client, and if possible, try to test with a 802.11w capable device.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 13:11:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3227155#M216608</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-12-05T13:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: MFP problem</title>
      <link>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3227159#M216609</link>
      <description>&lt;P&gt;Yes.&amp;nbsp;I see that this works correctly. Perhaps Airmagnet (soft&amp;nbsp;for packet capture) show the packets incorrectly?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 13:19:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3227159#M216609</guid>
      <dc:creator>Alexey Kurchenko</dc:creator>
      <dc:date>2017-12-05T13:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: MFP problem</title>
      <link>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3227161#M216610</link>
      <description>&lt;P&gt;That´s one good shot. You may try another sniffer to make sure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I said, although WLC reports Client as not 802.11w capable, beacons should be send with 802.11w flag enable as you enabled 802.11w on the WLC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 13:21:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3227161#M216610</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-12-05T13:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: MFP problem</title>
      <link>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3227162#M216611</link>
      <description>&lt;P&gt;Thank you, Flavio.&amp;nbsp; I'll try.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 13:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3227162#M216611</guid>
      <dc:creator>Alexey Kurchenko</dc:creator>
      <dc:date>2017-12-05T13:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: MFP problem</title>
      <link>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3297759#M216612</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello Flavio.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The problem was in Air Magnet. Wireshark shows the packets correctly.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2017 10:21:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mfp-problem/m-p/3297759#M216612</guid>
      <dc:creator>Alexey Kurchenko</dc:creator>
      <dc:date>2017-12-18T10:21:50Z</dc:date>
    </item>
  </channel>
</rss>

