<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Slow 802.1x authentication in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301720#M226919</link>
    <description>&lt;P&gt;I tested with different devices ( laptops Lenovo windows 10, iPhone, Android, Dell, Xiaomi redmi 9 pro ... ) and I have faced the same issue, sometimes the authentication takes a long time, sometimes the devices cannot even associate with the SSID, and sometimes the authentication passe seamless.&lt;/P&gt;&lt;P&gt;Remark new devices that want to join the network, fails many times before they succeed to access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there any recommendation to fix this issue,&amp;nbsp; or may be&amp;nbsp; I faced a bug in my wireless controller v 8.3.150&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Mar 2021 20:55:50 GMT</pubDate>
    <dc:creator>JlassiAhmed0345</dc:creator>
    <dc:date>2021-03-04T20:55:50Z</dc:date>
    <item>
      <title>Slow 802.1x authentication</title>
      <link>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301675#M226907</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two WLC 5520 on HA SOO&amp;nbsp; with flexconnect APs 702i, and I have configured SSID corporate flexconnect local switching with 802.1x authentication using ISE server 2.3 as AAA server. so when we tested the network, we have faced a problem of connectivity in corporate SSID, for example when the endpoint&amp;nbsp; (phone or desktop ) attempted to access the SSID and authenticate the network with the appropriate credentials, it takes a long time before letting it access and the most of times the devices fail to access to the network.&lt;/P&gt;&lt;P&gt;I tried to troubleshoot this issue and changed the EAP timers from the default to :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Identity Request timeout 30&lt;/P&gt;&lt;P&gt;Identity Request max retires 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;another problem for the devices that succeed the authentication, I remarked through the cmd that there is a loss of packets each 15-20 packets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any idea related to this issue dear Cisco community.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 20:19:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301675#M226907</guid>
      <dc:creator>JlassiAhmed0345</dc:creator>
      <dc:date>2021-07-05T20:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: Slow 802.1x authentication</title>
      <link>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301691#M226912</link>
      <description>&lt;P&gt;In dot1X, most time-consuming part is EAP exchanges. From ISE log or WLC debug, can you check how long it takes from "EAP-Identy Request" message to the "EAP-Success" message? Depend on where is your ISE server and where is your client, this can take a longer time and that could be the primary reason for Authentication delay.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Rasika&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 19:45:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301691#M226912</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2021-03-04T19:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: Slow 802.1x authentication</title>
      <link>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301696#M226914</link>
      <description>&lt;P&gt;Thanks, sir for your quick reply, the client and the ISE server are located in the same building, but this phenome is happening randomly same time you can access the network without any problem and same time when you want to re-enter the network with the same devices and the same credentials you will face an issue of the authentication.&lt;/P&gt;&lt;P&gt;i get a debug client from my wireless controller for a client that faced this problem, you can check it.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 20:00:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301696#M226914</guid>
      <dc:creator>JlassiAhmed0345</dc:creator>
      <dc:date>2021-03-04T20:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: Slow 802.1x authentication</title>
      <link>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301707#M226915</link>
      <description>&lt;P&gt;Here is the output parsed by debug Analyzer tool (you can do it yourself in the future when analyzing debug output)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://cway.cisco.com/wireless-debug-analyzer/" target="_self"&gt;https://cway.cisco.com/wireless-debug-analyzer/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can see multiple time client trying to connect, but he did not complete the process. In attempt #2, client failing in 4 way handshake, due to not respond to M3 message.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you test with different client devices and see all have the same problem (eg iphone, android phone, tablet, windows laptop &amp;amp; apple laptop)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&lt;STRONG&gt;Connection Attempt #1&lt;/STRONG&gt; &lt;BR /&gt;55:08.9 *apfMsConnTask_4 "Client made new Association to AP/BSSID BSSID 28:52:61:5d:e2:c0 AP AP0038.df0a.1566&lt;BR /&gt;"&lt;BR /&gt;55:08.9 *apfMsConnTask_4 WLC recognizes that the client is 802.11r-capable&lt;BR /&gt;55:08.9 *apfMsConnTask_4 The WLC/AP has found from client association request Information Element that claims PMKID Caching support&lt;BR /&gt;55:08.9 *apfMsConnTask_4 Client is entering the 802.1x or PSK Authentication state&lt;BR /&gt;55:08.9 *apfMsConnTask_4 WLC/AP is sending an Association Response to the client with status code 0 = Successful association&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Connection Attempt #2&lt;/STRONG&gt; &lt;BR /&gt;55:09.6 *apfMsConnTask_4 "Client made new Association to AP/BSSID BSSID 28:52:61:5d:e2:c0 AP AP0038.df0a.1566&lt;BR /&gt;"&lt;BR /&gt;55:09.6 *apfMsConnTask_4 WLC recognizes that the client is 802.11r-capable&lt;BR /&gt;55:09.6 *apfMsConnTask_4 The WLC/AP has found from client association request Information Element that claims PMKID Caching support&lt;BR /&gt;55:09.6 *apfMsConnTask_4 Client is entering the 802.1x or PSK Authentication state&lt;BR /&gt;55:09.6 *apfMsConnTask_4 WLC/AP is sending an Association Response to the client with status code 0 = Successful association&lt;BR /&gt;55:10.0 *Dot1x_NW_MsgTask_5 "Client will be required to Reauthenticate in 1800&lt;BR /&gt;seconds"&lt;BR /&gt;55:11.8 *Dot1x_NW_MsgTask_5 WLC/AP is sending EAP-Identity-Request to the client&lt;BR /&gt;55:11.8 *Dot1x_NW_MsgTask_5 WLC/AP is sending EAP-Identity-Request to the client&lt;BR /&gt;55:12.1 *Dot1x_NW_MsgTask_5 Client sent EAP-Identity-Response to WLC/AP&lt;BR /&gt;55:26.2 *Dot1x_NW_MsgTask_5 RADIUS Server permitted access&lt;BR /&gt;55:26.2 *Dot1x_NW_MsgTask_5 "Client will be required to Reauthenticate in 1800&lt;BR /&gt;seconds"&lt;BR /&gt;55:26.2 *Dot1x_NW_MsgTask_5 WLC creates a PMK cache entry for this client, which is used for FT with AKM:802.1xin this case, so the PMKID is computed with the AP MAC address&lt;BR /&gt;55:26.2 *Dot1x_NW_MsgTask_5 4-Way PTK Handshake, Sending M1&lt;BR /&gt;55:26.6 *Dot1x_NW_MsgTask_5 4-Way PTK Handshake, Received M2&lt;BR /&gt;55:26.6 *Dot1x_NW_MsgTask_5 4-Way PTK Handshake, Sending M3&lt;BR /&gt;55:27.6 *osapiBsnTimer "4-Way PTK Handshake, Client did not respond with M3&lt;BR /&gt;"&lt;BR /&gt;55:27.6 *Dot1x_NW_MsgTask_5 4-Way PTK Handshake, Retransmitting M3 retry #1&lt;BR /&gt;55:28.7 *osapiBsnTimer "4-Way PTK Handshake, Client did not respond with M3&lt;BR /&gt;"&lt;BR /&gt;55:28.7 *Dot1x_NW_MsgTask_5 4-Way PTK Handshake, Retransmitting M3 retry #2&lt;BR /&gt;55:29.7 *osapiBsnTimer &lt;FONT color="#FF0000"&gt;"4-Way PTK Handshake, Client did not respond with M3&lt;/FONT&gt;&lt;BR /&gt;"&lt;BR /&gt;55:29.7 *Dot1x_NW_MsgTask_5 &lt;FONT color="#FF0000"&gt;Client disassociation due to Authentication timeout. Auth or Key Exchange max-retransmissions reached. Check/update client driver, security config, certificates etc.&lt;/FONT&gt;&lt;BR /&gt;55:29.7 *Dot1x_NW_MsgTask_5 Client has been deauthenticated&lt;BR /&gt;55:29.7 *Dot1x_NW_MsgTask_5 "Client expiration timer code set for 10 seconds. The reason: Roaming failed due to WLAN security policy mismatch between controllers (configuration error). It can also be used to report EAPoL retry errors, and GTK rotation failure (in 8.5)&lt;BR /&gt;"&lt;BR /&gt;55:38.5 *Dot1x_NW_MsgTask_5 "Client will be required to Reauthenticate in 1800&lt;BR /&gt;seconds"&lt;BR /&gt;55:38.5 *Dot1x_NW_MsgTask_5 WLC/AP is sending EAP-Identity-Request to the client&lt;BR /&gt;55:40.1 *apfReceiveTask Client session has timed out&lt;BR /&gt;55:40.1 *apfReceiveTask "Client expiration timer code set for 10 seconds. The reason: Client was marked for deletion, and it was on associated, power save or blacklist state. Other message would provide reason for delete&lt;BR /&gt;"&lt;BR /&gt;&lt;STRONG&gt;Connection Attempt #3&lt;/STRONG&gt; &lt;BR /&gt;55:45.3 *apfMsConnTask_4 "Client made new Association to AP/BSSID BSSID 28:52:61:5d:fa:40 AP AP0038.df0a.16de&lt;BR /&gt;"&lt;BR /&gt;55:45.3 *apfMsConnTask_4 WLC recognizes that the client is 802.11r-capable&lt;BR /&gt;55:45.3 *apfMsConnTask_4 The WLC/AP has found from client association request Information Element that claims PMKID Caching support&lt;BR /&gt;55:45.3 *apfMsConnTask_4 Client is entering the 802.1x or PSK Authentication state&lt;BR /&gt;55:45.3 *apfMsConnTask_4 Client has successfully cleared AP association phase&lt;BR /&gt;55:45.3 *apfMsConnTask_4 WLC/AP is sending an Association Response to the client with status code 0 = Successful association&lt;BR /&gt;55:45.3 *Dot1x_NW_MsgTask_5 "Client will be required to Reauthenticate in 1800&lt;BR /&gt;seconds"&lt;BR /&gt;55:45.3 *Dot1x_NW_MsgTask_5 WLC/AP is sending EAP-Identity-Request to the client&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Connection Attempt #4&lt;/STRONG&gt; &lt;BR /&gt;55:45.6 *apfMsConnTask_4 "Client made new Association to AP/BSSID BSSID 28:52:61:5d:e2:c0 AP AP0038.df0a.1566&lt;BR /&gt;"&lt;BR /&gt;55:45.6 *apfMsConnTask_4 WLC recognizes that the client is 802.11r-capable&lt;BR /&gt;55:45.6 *apfMsConnTask_4 The WLC/AP has found from client association request Information Element that claims PMKID Caching support&lt;BR /&gt;55:45.6 *apfMsConnTask_4 Client is entering the 802.1x or PSK Authentication state&lt;BR /&gt;55:45.6 *apfMsConnTask_4 WLC/AP is sending an Association Response to the client with status code 0 = Successful association&lt;BR /&gt;55:48.6 *Dot1x_NW_MsgTask_5 WLC/AP is sending EAP-Identity-Request to the client&lt;BR /&gt;55:50.3 *Dot1x_NW_MsgTask_5 WLC/AP is sending EAP-Identity-Request to the client&lt;BR /&gt;55:55.5 *Dot1x_NW_MsgTask_5 WLC/AP is sending EAP-Identity-Request to the client&lt;BR /&gt;56:00.6 *Dot1x_NW_MsgTask_5 WLC/AP is sending EAP-Identity-Request to the client&lt;BR /&gt;56:05.8 *Dot1x_NW_MsgTask_5 WLC/AP is sending EAP-Identity-Request to the client&lt;BR /&gt;56:11.0 *Dot1x_NW_MsgTask_5 WLC/AP is sending EAP-Identity-Request to the client&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Connection Attempt #5&lt;/STRONG&gt; &lt;BR /&gt;56:11.7 *apfMsConnTask_4 "Client made new Association to AP/BSSID BSSID 28:52:61:5d:e2:c0 AP AP0038.df0a.1566&lt;BR /&gt;"&lt;BR /&gt;56:11.7 *apfMsConnTask_4 WLC recognizes that the client is 802.11r-capable&lt;BR /&gt;56:11.7 *apfMsConnTask_4 The WLC/AP has found from client association request Information Element that claims PMKID Caching support&lt;BR /&gt;56:11.7 *apfMsConnTask_4 Client is entering the 802.1x or PSK Authentication state&lt;BR /&gt;56:11.7 *apfMsConnTask_4 WLC/AP is sending an Association Response to the client with status code 0 = Successful association&lt;BR /&gt;56:11.8 *Dot1x_NW_MsgTask_5 WLC/AP is sending EAP-Identity-Request to the client&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Connection Attempt #6&lt;/STRONG&gt; &lt;BR /&gt;56:12.2 *apfMsConnTask_4 "Client made new Association to AP/BSSID BSSID 28:52:61:5d:e2:c0 AP AP0038.df0a.1566&lt;BR /&gt;"&lt;BR /&gt;56:12.2 *apfMsConnTask_4 WLC recognizes that the client is 802.11r-capable&lt;BR /&gt;56:12.2 *apfMsConnTask_4 The WLC/AP has found from client association request Information Element that claims PMKID Caching support&lt;BR /&gt;56:12.2 *apfMsConnTask_4 Client is entering the 802.1x or PSK Authentication state&lt;BR /&gt;56:12.2 *apfMsConnTask_4 WLC/AP is sending an Association Response to the client with status code 0 = Successful association&lt;BR /&gt;56:12.4 *Dot1x_NW_MsgTask_5 Client sent EAP-Identity-Response to WLC/AP&lt;BR /&gt;56:15.2 *Dot1x_NW_MsgTask_5 WLC/AP is sending EAP-Identity-Request to the client&lt;BR /&gt;56:15.6 *Dot1x_NW_MsgTask_5 Client sent EAP-Identity-Response to WLC/AP&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;56:18.7 *osapiBsnTimer "4-Way PTK Handshake, Client did not respond with M0&lt;/FONT&gt;&lt;BR /&gt;"&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What was the reason behind FlexConnect deployment if everything on the same site (ISE, WLC, AP)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;H TH&lt;/P&gt;
&lt;P&gt;Rasika&lt;/P&gt;
&lt;P&gt;*** Pls rate all useful devices***&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 20:29:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301707#M226915</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2021-03-04T20:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Slow 802.1x authentication</title>
      <link>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301711#M226916</link>
      <description>&lt;P&gt;can I know the type of the auth?&lt;/P&gt;&lt;P&gt;&amp;nbsp;is there roaming from one AP to other ? or you test under same AP?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 20:36:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301711#M226916</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-03-04T20:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: Slow 802.1x authentication</title>
      <link>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301715#M226918</link>
      <description>&lt;P&gt;Hi, the type of authentication is 802.1x with ISE 2.3 .&lt;/P&gt;&lt;P&gt;there is no roaming, we test under the many APs.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 20:45:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301715#M226918</guid>
      <dc:creator>JlassiAhmed0345</dc:creator>
      <dc:date>2021-03-04T20:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Slow 802.1x authentication</title>
      <link>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301720#M226919</link>
      <description>&lt;P&gt;I tested with different devices ( laptops Lenovo windows 10, iPhone, Android, Dell, Xiaomi redmi 9 pro ... ) and I have faced the same issue, sometimes the authentication takes a long time, sometimes the devices cannot even associate with the SSID, and sometimes the authentication passe seamless.&lt;/P&gt;&lt;P&gt;Remark new devices that want to join the network, fails many times before they succeed to access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there any recommendation to fix this issue,&amp;nbsp; or may be&amp;nbsp; I faced a bug in my wireless controller v 8.3.150&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 20:55:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301720#M226919</guid>
      <dc:creator>JlassiAhmed0345</dc:creator>
      <dc:date>2021-03-04T20:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: Slow 802.1x authentication</title>
      <link>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301722#M226920</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pure-edit.png" style="width: 647px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/105612iC07B1F8CA27F3AF7/image-size/large?v=v2&amp;amp;px=999" role="button" title="pure-edit.png" alt="pure-edit.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;do two SSID&amp;nbsp;&lt;BR /&gt;one with FT 802.1x enable and other without enable it,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think the client support this feature face some issue.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 21:10:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301722#M226920</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-03-04T21:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: Slow 802.1x authentication</title>
      <link>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301725#M226921</link>
      <description>&lt;P&gt;What was the reason behind FlexConnect deployment if everything on the same site (ISE, WLC, AP)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it's a choice to deploy flexconnect because we will add another APs that are located in the Branch site.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 21:17:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4301725#M226921</guid>
      <dc:creator>JlassiAhmed0345</dc:creator>
      <dc:date>2021-03-04T21:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Slow 802.1x authentication</title>
      <link>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4303316#M227022</link>
      <description>&lt;P&gt;Fast transition is not enabled, i still face the same issue&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 16:30:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4303316#M227022</guid>
      <dc:creator>JlassiAhmed0345</dc:creator>
      <dc:date>2021-03-08T16:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: Slow 802.1x authentication</title>
      <link>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4303367#M227031</link>
      <description>&lt;P&gt;&lt;A href="https://www.wiresandwi.fi/blog/configuring-fast-transition-ft-80211r-on-a-cisco-wlc" target="_blank"&gt;https://www.wiresandwi.fi/blog/configuring-fast-transition-ft-80211r-on-a-cisco-wlc&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;some client is FT and other is Not, so if I am right you need mix mode.&lt;BR /&gt;&lt;BR /&gt;from the debug you share there is indicate that WLC is detect that client support 802.11r and this 802.11r have different key management.&lt;BR /&gt;&lt;BR /&gt;so check the link above and see if it solve your issue or not.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 17:39:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4303367#M227031</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-03-08T17:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: Slow 802.1x authentication</title>
      <link>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4303469#M227035</link>
      <description>&lt;P&gt;Just for a simple test, see if you can put one AP into local mode and see the difference. At least in that way we can narrow down it is an issue only with FlexConnect mode&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Rasika&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 20:13:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4303469#M227035</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2021-03-08T20:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: Slow 802.1x authentication</title>
      <link>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4538659#M237565</link>
      <description>&lt;P&gt;Did you ever get this to work ? What if anything fixed it ? Seeing similar issue with painfully slow auths or failed auths on Windows 10 clients on code version 8.10.130.0. Sometimes they will connect other times not. Random.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 19:30:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4538659#M237565</guid>
      <dc:creator>Reginald Pugh</dc:creator>
      <dc:date>2022-01-25T19:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: Slow 802.1x authentication</title>
      <link>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4538717#M237569</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/257392"&gt;@Reginald Pugh&lt;/a&gt;&amp;nbsp;you should open a new thread to include your equipment and details on what you are seeing and how you are replicating the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 21:24:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/slow-802-1x-authentication/m-p/4538717#M237569</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2022-01-25T21:24:38Z</dc:date>
    </item>
  </channel>
</rss>

