<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intermittent authentication problems in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/intermittent-authentication-problems/m-p/4510065#M236012</link>
    <description>&lt;P&gt;I would recommend to disable Aironet IE extensions first, that is more or less unneeded today.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then you seem to have unsupported APs in your environment:&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;*spamApTask3: Nov 25 10:54:33.232: %CAPWAP-3-JOIN_UNSUPP_AP: [PA]capwap_ac_sm.c:5104 The system has received a join request from an unsupported AP 20:3a:07:85:45:a0 CEL000A015 (model AIR-LAP1261N-E-K9), dropping the packet&lt;/PRE&gt;
&lt;P&gt;Could it be that you have more than one WLC in use here with different software versions and the problems happen when they try to roam from one WLC to another?&lt;/P&gt;
&lt;P&gt;Then there are also a few updates for the firmware out, which do fix some specific authentication issues with one specific AP series, see:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/crn85mr8.html#resolved-caveats" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/crn85mr8.html#resolved-caveats&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Nov 2021 15:57:11 GMT</pubDate>
    <dc:creator>patoberli</dc:creator>
    <dc:date>2021-11-29T15:57:11Z</dc:date>
    <item>
      <title>Intermittent authentication problems</title>
      <link>https://community.cisco.com/t5/wireless/intermittent-authentication-problems/m-p/4508394#M235943</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a WLC 8510 - 8.5.171.0 - we have several clients that are sometimes unable to authenticate properly against a radius server.&amp;nbsp; We have multiple WLANs with 802.1x and CCKM enabled and clients logs in SSIDs with username and password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WLAN configuration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;WLAN Identifier.................................. xx&lt;BR /&gt;Profile Name..................................... xxx_name&lt;BR /&gt;Network Name (SSID).............................. xxx_name&lt;BR /&gt;Status........................................... Enabled&lt;BR /&gt;MAC Filtering.................................... Disabled&lt;BR /&gt;Broadcast SSID................................... Enabled&lt;BR /&gt;AAA Policy Override.............................. Disabled&lt;BR /&gt;Network Admission Control&lt;BR /&gt;Client Profiling Status&lt;BR /&gt;Radius Profiling ............................ Disabled&lt;BR /&gt;DHCP ....................................... Disabled&lt;BR /&gt;HTTP ....................................... Disabled&lt;BR /&gt;Local Profiling ............................. Disabled&lt;BR /&gt;DHCP ....................................... Disabled&lt;BR /&gt;HTTP ....................................... Disabled&lt;BR /&gt;Radius-NAC State............................... Disabled&lt;BR /&gt;SNMP-NAC State................................. Disabled&lt;BR /&gt;Quarantine VLAN................................ 0&lt;BR /&gt;Maximum Clients Allowed.......................... Unlimited&lt;BR /&gt;Security Group Tag............................... Unknown(0)&lt;BR /&gt;&lt;BR /&gt;--More-- or (q)uit&lt;BR /&gt;Maximum number of Clients per AP Radio........... 200&lt;BR /&gt;ATF Policy....................................... 0&lt;BR /&gt;Number of Active Clients......................... 3&lt;BR /&gt;Exclusionlist Timeout............................ 60 seconds&lt;BR /&gt;Session Timeout.................................. 21600 seconds&lt;BR /&gt;User Idle Timeout................................ Disabled&lt;BR /&gt;Sleep Client..................................... disable&lt;BR /&gt;Sleep Client Timeout............................. 720 minutes&lt;BR /&gt;Web Auth Captive Bypass Mode..................... None&lt;BR /&gt;User Idle Threshold.............................. 0 Bytes&lt;BR /&gt;NAS-identifier................................... none&lt;BR /&gt;CHD per WLAN..................................... Disabled&lt;BR /&gt;Webauth DHCP exclusion........................... Disabled&lt;BR /&gt;Interface........................................ if_vlan_xxx&lt;BR /&gt;Multicast Interface.............................. Not Configured&lt;BR /&gt;WLAN IPv4 ACL.................................... unconfigured&lt;BR /&gt;WLAN IPv6 ACL.................................... unconfigured&lt;BR /&gt;WLAN Layer2 ACL.................................. unconfigured&lt;BR /&gt;mDNS Status...................................... Enabled&lt;BR /&gt;mDNS Profile Name................................ default-mdns-profile&lt;BR /&gt;DHCP Server...................................... Default&lt;BR /&gt;Central NAT Peer-Peer Blocking................... Unknown&lt;BR /&gt;DHCP Address Assignment Required................. Disabled&lt;BR /&gt;&lt;BR /&gt;CCX - AironetIe Support.......................... Enabled&lt;BR /&gt;CCX - Gratuitous ProbeResponse (GPR)............. Disabled&lt;BR /&gt;CCX - Diagnostics Channel Capability............. Disabled&lt;BR /&gt;Dot11-Phone Mode (7920).......................... Disabled&lt;BR /&gt;Wired Protocol................................... 802.1P (Tag=0)&lt;BR /&gt;Passive Client Feature........................... Disabled&lt;BR /&gt;Peer-to-Peer Blocking Action..................... Disabled&lt;BR /&gt;Radio Policy..................................... All&lt;BR /&gt;DTIM period for 802.11a radio.................... 1&lt;BR /&gt;DTIM period for 802.11b radio.................... 1&lt;BR /&gt;Radius Servers&lt;BR /&gt;Authentication................................ xxx.xxx.xxx.xx 1812 *&lt;BR /&gt;Accounting.................................... xxx.xx.x.xxx 1813 *&lt;BR /&gt;Interim Update............................. Enabled&lt;BR /&gt;Interim Update Interval.................... 0&lt;BR /&gt;Framed IPv6 Acct AVP ...................... Prefix&lt;BR /&gt;Dynamic Interface............................. Disabled&lt;BR /&gt;Dynamic Interface Priority.................... wlan&lt;BR /&gt;Local EAP Authentication......................... Disabled&lt;BR /&gt;Radius NAI-Realm................................. Disabled&lt;BR /&gt;Mu-Mimo.......................................... Enabled&lt;BR /&gt;Security&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;--More-- or (q)uit&lt;BR /&gt;802.11 Authentication:........................ Open System&lt;BR /&gt;FT Support.................................... Disabled&lt;BR /&gt;Static WEP Keys............................... Disabled&lt;BR /&gt;802.1X........................................ Disabled&lt;BR /&gt;Wi-Fi Protected Access (WPA/WPA2)............. Enabled&lt;BR /&gt;WPA (SSN IE)............................... Disabled&lt;BR /&gt;WPA2 (RSN IE).............................. Enabled&lt;BR /&gt;TKIP Cipher............................. Disabled&lt;BR /&gt;AES Cipher.............................. Enabled&lt;BR /&gt;CCMP256 Cipher.......................... Disabled&lt;BR /&gt;GCMP128 Cipher.......................... Disabled&lt;BR /&gt;GCMP256 Cipher.......................... Disabled&lt;BR /&gt;OSEN IE.................................... Disabled&lt;BR /&gt;Auth Key Management&lt;BR /&gt;802.1x.................................. Enabled&lt;BR /&gt;PSK..................................... Disabled&lt;BR /&gt;CCKM.................................... Enabled&lt;BR /&gt;FT-1X(802.11r).......................... Disabled&lt;BR /&gt;FT-PSK(802.11r)......................... Disabled&lt;BR /&gt;PMF-1X(802.11w)......................... Disabled&lt;BR /&gt;PMF-PSK(802.11w)........................ Disabled&lt;BR /&gt;OSEN-1X................................. Disabled&lt;BR /&gt;SUITEB-1X............................... Disabled&lt;BR /&gt;&lt;BR /&gt;--More-- or (q)uit&lt;BR /&gt;SUITEB192-1X............................ Disabled&lt;BR /&gt;FT Reassociation Timeout................... 20&lt;BR /&gt;FT Over-The-DS mode........................ Enabled&lt;BR /&gt;GTK Randomization.......................... Disabled&lt;BR /&gt;SKC Cache Support.......................... Disabled&lt;BR /&gt;CCKM TSF Tolerance......................... 1000&lt;BR /&gt;Wi-Fi Direct policy configured................ Disabled&lt;BR /&gt;EAP-Passthrough............................... Disabled&lt;BR /&gt;CKIP ......................................... Disabled&lt;BR /&gt;Web Based Authentication...................... Disabled&lt;BR /&gt;Web Authentication Timeout.................... 300&lt;BR /&gt;Web-Passthrough............................... Disabled&lt;BR /&gt;Mac-auth-server............................... 0.0.0.0&lt;BR /&gt;Web-portal-server............................. 0.0.0.0&lt;BR /&gt;qrscan-des-key................................ &lt;BR /&gt;Conditional Web Redirect...................... Disabled&lt;BR /&gt;Splash-Page Web Redirect...................... Disabled&lt;BR /&gt;Auto Anchor................................... Disabled&lt;BR /&gt;FlexConnect Local Switching................... Disabled&lt;BR /&gt;FlexConnect Central Association............... Disabled&lt;BR /&gt;flexconnect Central Dhcp Flag................. Disabled&lt;BR /&gt;flexconnect nat-pat Flag...................... Disabled&lt;BR /&gt;flexconnect Dns Override Flag................. Disabled&lt;BR /&gt;&lt;BR /&gt;--More-- or (q)uit&lt;BR /&gt;flexconnect PPPoE pass-through................ Disabled&lt;BR /&gt;flexconnect local-switching IP-source-guar.... Disabled&lt;BR /&gt;FlexConnect Vlan based Central Switching ..... Disabled&lt;BR /&gt;FlexConnect Local Authentication.............. Disabled&lt;BR /&gt;FlexConnect Learn IP Address.................. Enabled&lt;BR /&gt;Client MFP.................................... Optional&lt;BR /&gt;PMF........................................... Disabled&lt;BR /&gt;PMF Association Comeback Time................. 1&lt;BR /&gt;PMF SA Query RetryTimeout..................... 200&lt;BR /&gt;Tkip MIC Countermeasure Hold-down Timer....... 60&lt;BR /&gt;Eap-params.................................... Disabled&lt;BR /&gt;AVC Visibilty.................................... Disabled&lt;BR /&gt;AVC Profile Name................................. None&lt;BR /&gt;OpenDns Profile Name............................. None&lt;BR /&gt;OpenDns Wlan Mode................................ ignore&lt;BR /&gt;Flow Monitor Name................................ None&lt;BR /&gt;Split Tunnel Configuration&lt;BR /&gt;Split Tunnel................................. Disabled&lt;BR /&gt;Call Snooping.................................... Disabled&lt;BR /&gt;Roamed Call Re-Anchor Policy..................... Disabled&lt;BR /&gt;SIP CAC Fail Send-486-Busy Policy................ Enabled&lt;BR /&gt;SIP CAC Fail Send Dis-Association Policy......... Disabled&lt;BR /&gt;KTS based CAC Policy............................. Disabled&lt;BR /&gt;&lt;BR /&gt;--More-- or (q)uit&lt;BR /&gt;Assisted Roaming Prediction Optimization......... Disabled&lt;BR /&gt;802.11k Neighbor List............................ Disabled&lt;BR /&gt;802.11k Neighbor List Dual Band.................. Disabled&lt;BR /&gt;802.11v Directed Multicast Service............... Disabled&lt;BR /&gt;802.11v BSS Max Idle Service..................... Enabled&lt;BR /&gt;802.11v BSS Transition Service................... Disabled&lt;BR /&gt;802.11v BSS Transition Disassoc Imminent......... Disabled&lt;BR /&gt;802.11v BSS Transition Disassoc Timer............ 200&lt;BR /&gt;802.11v BSS Transition OpRoam Disassoc Timer..... 40&lt;BR /&gt;DMS DB is empty&lt;BR /&gt;Band Select...................................... Disabled&lt;BR /&gt;Load Balancing................................... Disabled&lt;BR /&gt;Multicast Buffer................................. Disabled&lt;BR /&gt;Universal Ap Admin............................... Disabled&lt;BR /&gt;Broadcast Tagging................................ Disabled&lt;BR /&gt;PRP.............................................. Disabled&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EAP PArameters:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;EAP-Identity-Request Timeout (seconds)........... 3&lt;BR /&gt;EAP-Identity-Request Max Retries................. 10&lt;BR /&gt;EAP Key-Index for Dynamic WEP.................... 0&lt;BR /&gt;EAP Max-Login Ignore Identity Response........... enable&lt;BR /&gt;EAP-Request Timeout (seconds).................... 3&lt;BR /&gt;EAP-Request Max Retries.......................... 10&lt;BR /&gt;EAPOL-Key Timeout (milliseconds)................. 1000&lt;BR /&gt;EAPOL-Key Max Retries............................ 2&lt;BR /&gt;EAP-Broadcast Key Interval....................... 3600&lt;BR /&gt;RSN Capability Validation........................ enable&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sometimes, the client authenticates correctly but after 30 minutes or roams to another AP, the autentication fails and they cant re-authenticate on the same SSID.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the WLC log, we can see the following logs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:57:15.016: %DOT1X-3-ABORT_AUTH: [PA]1x_bauth_sm.c:487 Authentication Aborted for client 84:ad:8d:bd:a1:04 Abort Reason:DOT1X RESTARTED DUE TO EAPOL-START/CLIENT ROAM&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:57:13.511: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 1 failed; port status 1, key available 0, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:57:10.392: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Nov 25 10:57:10.349: %DOT1X-3-PSK_CONFIG_ERR: [PA]1x_ptsm.c:749 Client a8:91:3d:84:c1:88 may be using an incorrect PSK&lt;BR /&gt;*Dot1x_NW_MsgTask_6: Nov 25 10:57:04.480: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*spamApTask3: Nov 25 10:57:02.768: %CAPWAP-3-DTLS_CLOSED_ERR: [PA]capwap_ac_sm.c:7130 20:3a:07:85:45:a0: DTLS connection closed forAP 77:26:73:5 (53978), Controller: 10:35:0:78 (5246) Join Request Process Failed&lt;BR /&gt;*spamApTask3: Nov 25 10:57:02.768: %CAPWAP-3-JOIN_UNSUPP_AP: [PA]capwap_ac_sm.c:5104 The system has received a join request from an unsupported AP 20:3a:07:85:45:a0 CEL000A015 (model AIR-LAP1261N-E-K9), dropping the packet&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:57:01.899: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_6: Nov 25 10:57:01.061: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*apfMsConnTask_7: Nov 25 10:57:00.946: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:57:00.885: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 25 10:56:57.992: %DOT1X-3-INVALID_REPLAY_CTR: [PA]1x_eapkey.c:452 Invalid replay counter from client f4:f5:db:c4:d8:8f - got 00 00 00 00 00 00 00 00, expected 00 00 00 00 00 00 00 01&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:56:57.613: %DOT1X-3-ABORT_AUTH: [PA]1x_bauth_sm.c:487 Authentication Aborted for client 84:ad:8d:bd:a1:04 Abort Reason:DOT1X RESTARTED DUE TO EAPOL-START/CLIENT ROAM&lt;BR /&gt;*Dot1x_NW_MsgTask_2: Nov 25 10:56:57.396: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_3: Nov 25 10:56:56.881: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_6: Nov 25 10:56:52.852: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:56:52.605: %DOT1X-3-AAA_AUTH_SEND_FAIL: [PA]1x_aaa.c:848 Unable to send AAA message for client 84:ad:8d:bd:a1:04&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:56:52.593: %DOT1X-3-ABORT_AUTH: [PA]1x_bauth_sm.c:487 Authentication Aborted for client 84:ad:8d:bd:a1:04 Abort Reason:DOT1X RESTARTED DUE TO EAPOL-START/CLIENT ROAM&lt;BR /&gt;*dot1xMsgTask: Nov 25 10:56:51.362: %DOT1X-3-WPA_SEND_STATE_ERR: [PA]1x_kxsm.c:1724 Unable to send EAPOL-key msg - invalid WPA state (0) - client e4:76:84:aa:cf:c7&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:56:50.499: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;&lt;BR /&gt;--More-- or (q)uit&lt;BR /&gt;*spamApTask3: Nov 25 10:56:48.066: %LWAPP-3-REPLAY_ERR: [PA]spam_lrad.c:45310 The system has received replay error on slot 1, WLAN ID 2, count 1 from AP 00:d7:8f:8c:62:b0&lt;BR /&gt;*Dot1x_NW_MsgTask_2: Nov 25 10:56:45.198: %DOT1X-3-PSK_CONFIG_ERR: [PA]1x_ptsm.c:749 Client 3c:f8:62:0d:91:a2 may be using an incorrect PSK&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Nov 25 10:56:44.762: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:56:43.763: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:56:39.144: %DOT1X-3-ABORT_AUTH: [PA]1x_bauth_sm.c:487 Authentication Aborted for client 58:e6:ba:05:2d:1d Abort Reason:DOT1X RESTARTED DUE TO EAPOL-START/CLIENT ROAM&lt;BR /&gt;*Dot1x_NW_MsgTask_6: Nov 25 10:56:38.965: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:56:38.910: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*apfMsConnTask_7: Nov 25 10:56:38.791: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:56:38.747: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:56:34.137: %DOT1X-3-AAA_AUTH_SEND_FAIL: [PA]1x_aaa.c:848 Unable to send AAA message for client 58:e6:ba:05:2d:1d&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:56:34.129: %DOT1X-3-ABORT_AUTH: [PA]1x_bauth_sm.c:487 Authentication Aborted for client 58:e6:ba:05:2d:1d Abort Reason:DOT1X RESTARTED DUE TO EAPOL-START/CLIENT ROAM&lt;BR /&gt;*haSSOServiceTask1: Nov 25 10:56:32.850: %APF_HA-3-SYNC_RETRANSMIT_FAIL: [PA]apf_ha.c:4483 Maximum retransmission exceeded for client (c0:bd:c8:d8:f2:f9 )data sync block:0x80000. Retry after 150 secs.&lt;BR /&gt;*Dot1x_NW_MsgTask_1: Nov 25 10:56:32.081: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Nov 25 10:56:30.580: %DOT1X-3-INVALID_REPLAY_CTR: [PA]1x_eapkey.c:452 Invalid replay counter from client fc:18:3c:54:b5:d0 - got 00 00 00 00 00 00 00 00, expected 00 00 00 00 00 00 00 01&lt;BR /&gt;*dot1xMsgTask: Nov 25 10:56:30.577: %DOT1X-3-WPA_SEND_STATE_ERR: [PA]1x_kxsm.c:1724 Unable to send EAPOL-key msg - invalid WPA state (0) - client 4c:f2:02:3a:55:fe&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:56:29.086: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:56:26.829: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*Dot1x_NW_MsgTask_2: Nov 25 10:56:26.651: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:56:26.623: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:56:23.714: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*dot1xMsgTask: Nov 25 10:56:23.373: %DOT1X-3-WPA_SEND_STATE_ERR: [PA]1x_kxsm.c:1724 Unable to send EAPOL-key msg - invalid WPA state (0) - client ea:c0:b0:de:e5:9e&lt;BR /&gt;*Dot1x_NW_MsgTask_2: Nov 25 10:56:19.334: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 25 10:56:18.845: %DOT1X-3-INVALID_REPLAY_CTR: [PA]1x_eapkey.c:452 Invalid replay counter from client b2:4e:26:af:fd:d7 - got 00 00 00 00 00 00 00 01, expected 00 00 00 00 00 00 00 02&lt;BR /&gt;&lt;BR /&gt;--More-- or (q)uit&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:56:18.425: %DOT1X-3-PSK_CONFIG_ERR: [PA]1x_ptsm.c:749 Client 4a:91:f0:e6:d9:15 may be using an incorrect PSK&lt;BR /&gt;*dot1xMsgTask: Nov 25 10:56:17.395: %DOT1X-3-WPA_SEND_STATE_ERR: [PA]1x_kxsm.c:1724 Unable to send EAPOL-key msg - invalid WPA state (0) - client 5a:84:0e:bc:f2:ee&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:56:15.766: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*Dot1x_NW_MsgTask_1: Nov 25 10:56:15.079: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_3: Nov 25 10:56:14.242: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 1 failed; port status 1, key available 0, key tx enabled 1&lt;BR /&gt;*dot1xMsgTask: Nov 25 10:56:10.591: %DOT1X-3-WPA_SEND_STATE_ERR: [PA]1x_kxsm.c:1724 Unable to send EAPOL-key msg - invalid WPA state (0) - client 04:f1:28:75:70:cc&lt;BR /&gt;*spamApTask1: Nov 25 10:56:07.214: %LWAPP-3-REPLAY_ERR: [PA]spam_lrad.c:45310 The system has received replay error on slot 0, WLAN ID 2, count 3 from AP 58:97:bd:08:0c:f0&lt;BR /&gt;*Dot1x_NW_MsgTask_1: Nov 25 10:56:05.518: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:56:04.651: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*spamApTask5: Nov 25 10:56:01.729: %LWAPP-3-REPLAY_ERR: [PA]spam_lrad.c:45310 The system has received replay error on slot 1, WLAN ID 4, count 1 from AP d8:b1:90:f2:95:d0&lt;BR /&gt;*dot1xMsgTask: Nov 25 10:56:00.695: %DOT1X-3-WPA_SEND_STATE_ERR: [PA]1x_kxsm.c:1724 Unable to send EAPOL-key msg - invalid WPA state (0) - client a0:57:e3:90:7d:6b&lt;BR /&gt;*Dot1x_NW_MsgTask_3: Nov 25 10:55:58.095: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:55:57.208: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 1 failed; port status 1, key available 0, key tx enabled 1&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:55:54.110: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*Dot1x_NW_MsgTask_3: Nov 25 10:55:50.535: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*spamApTask7: Nov 25 10:55:49.009: %LWAPP-3-REPLAY_ERR: [PA]spam_lrad.c:45310 The system has received replay error on slot 1, WLAN ID 6, count 106 from AP d8:b1:90:d3:cb:60&lt;BR /&gt;*Dot1x_NW_MsgTask_1: Nov 25 10:55:48.232: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*spamApTask3: Nov 25 10:55:48.000: %CAPWAP-3-DTLS_CLOSED_ERR: [PA]capwap_ac_sm.c:7130 20:3a:07:85:45:a0: DTLS connection closed forAP 77:26:73:5 (53978), Controller: 10:35:0:78 (5246) Join Request Process Failed&lt;BR /&gt;*spamApTask3: Nov 25 10:55:48.000: %CAPWAP-3-JOIN_UNSUPP_AP: [PA]capwap_ac_sm.c:5104 The system has received a join request from an unsupported AP 20:3a:07:85:45:a0 CEL000A015 (model AIR-LAP1261N-E-K9), dropping the packet&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 25 10:55:47.005: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_3: Nov 25 10:55:46.699: %DOT1X-3-AAA_AUTH_SEND_FAIL: [PA]1x_aaa.c:848 Unable to send AAA message for client e4:a7:c5:ad:98:43&lt;BR /&gt;*Dot1x_NW_MsgTask_2: Nov 25 10:55:46.453: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:55:45.552: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;&lt;BR /&gt;--More-- or (q)uit&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:55:42.722: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*spamApTask6: Nov 25 10:55:42.060: %LWAPP-3-REPLAY_ERR: [PA]spam_lrad.c:45310 The system has received replay error on slot 0, WLAN ID 3, count 10 from AP 00:fe:c8:2d:97:20&lt;BR /&gt;*spamApTask6: Nov 25 10:55:39.114: %LWAPP-3-REPLAY_ERR: [PA]spam_lrad.c:45310 The system has received replay error on slot 0, WLAN ID 1, count 6 from AP cc:46:d6:ea:27:70&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:55:37.590: %DOT1X-3-ABORT_AUTH: [PA]1x_bauth_sm.c:487 Authentication Aborted for client 46:5a:96:e3:99:bd Abort Reason:DOT1X RESTARTED DUE TO EAPOL-START/CLIENT ROAM&lt;BR /&gt;*spamApTask5: Nov 25 10:55:35.526: %LWAPP-3-REPLAY_ERR: [PA]spam_lrad.c:45310 The system has received replay error on slot 0, WLAN ID 0, count 1 from AP 58:97:bd:80:8e:40&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 25 10:55:33.778: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:55:32.581: %DOT1X-3-AAA_AUTH_SEND_FAIL: [PA]1x_aaa.c:848 Unable to send AAA message for client 46:5a:96:e3:99:bd&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:55:32.572: %DOT1X-3-ABORT_AUTH: [PA]1x_bauth_sm.c:487 Authentication Aborted for client 46:5a:96:e3:99:bd Abort Reason:DOT1X RESTARTED DUE TO EAPOL-START/CLIENT ROAM&lt;BR /&gt;*Dot1x_NW_MsgTask_3: Nov 25 10:55:31.490: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_1: Nov 25 10:55:30.963: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:55:30.646: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Nov 25 10:55:28.039: %DOT1X-3-AAA_AUTH_SEND_FAIL: [PA]1x_aaa.c:848 Unable to send AAA message for client 2c:33:61:88:82:58&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Nov 25 10:55:28.031: %DOT1X-3-ABORT_AUTH: [PA]1x_bauth_sm.c:487 Authentication Aborted for client 2c:33:61:88:82:58 Abort Reason:DOT1X RESTARTED DUE TO EAPOL-START/CLIENT ROAM&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:55:20.418: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*Dot1x_NW_MsgTask_2: Nov 25 10:55:18.754: %DOT1X-3-PSK_CONFIG_ERR: [PA]1x_ptsm.c:749 Client 3c:f8:62:0d:91:a2 may be using an incorrect PSK&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:55:18.304: %DOT1X-3-AAA_AUTH_SEND_FAIL: [PA]1x_aaa.c:848 Unable to send AAA message for client 46:5a:96:e3:99:bd&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:55:18.295: %DOT1X-3-ABORT_AUTH: [PA]1x_bauth_sm.c:487 Authentication Aborted for client 46:5a:96:e3:99:bd Abort Reason:DOT1X RESTARTED DUE TO EAPOL-START/CLIENT ROAM&lt;BR /&gt;*Dot1x_NW_MsgTask_1: Nov 25 10:55:14.132: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:55:13.283: %DOT1X-3-ABORT_AUTH: [PA]1x_bauth_sm.c:487 Authentication Aborted for client 46:5a:96:e3:99:bd Abort Reason:DOT1X RESTARTED DUE TO EAPOL-START/CLIENT ROAM&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Nov 25 10:55:12.492: %DOT1X-3-INVALID_REPLAY_CTR: [PA]1x_eapkey.c:452 Invalid replay counter from client 52:9a:3a:c2:b6:68 - got 00 00 00 00 00 00 00 03, expected 00 00 00 00 00 00 00 04&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Nov 25 10:55:12.492: %DOT1X-3-INVALID_REPLAY_CTR: [PA]1x_eapkey.c:452 Invalid replay counter from client 52:9a:3a:c2:b6:68 - got 00 00 00 00 00 00 00 02, expected 00 00 00 00 00 00 00 04&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Nov 25 10:55:10.928: %DOT1X-3-INVALID_REPLAY_CTR: [PA]1x_eapkey.c:452 Invalid replay counter from client 62:68:20:d1:0f:a8 - got 00 00 00 00 00 00 00 02, expected 00 00 00 00 00 00 00 03&lt;BR /&gt;*spamApTask4: Nov 25 10:55:10.876: %LWAPP-3-VENDOR_PLD_VALIDATE_ERR: [PA]spam_lrad.c:12016 Validation of SPAM_VENDOR_SPECIFIC_PAYLOAD(185) with length=9 failed - AP 5c:83:8f:f3:7b:90&lt;BR /&gt;&lt;BR /&gt;--More-- or (q)uit&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:55:08.590: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:55:08.394: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:55:08.275: %DOT1X-3-AAA_AUTH_SEND_FAIL: [PA]1x_aaa.c:848 Unable to send AAA message for client 46:5a:96:e3:99:bd&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:55:08.268: %DOT1X-3-ABORT_AUTH: [PA]1x_bauth_sm.c:487 Authentication Aborted for client 46:5a:96:e3:99:bd Abort Reason:DOT1X RESTARTED DUE TO EAPOL-START/CLIENT ROAM&lt;BR /&gt;*dot1xMsgTask: Nov 25 10:55:06.772: %DOT1X-3-WPA_SEND_STATE_ERR: [PA]1x_kxsm.c:1724 Unable to send EAPOL-key msg - invalid WPA state (0) - client be:ea:df:16:61:3f&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:55:06.234: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:55:02.098: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:55:00.126: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:54:57.943: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:54:57.293: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:54:51.970: %DOT1X-3-ABORT_AUTH: [PA]1x_bauth_sm.c:487 Authentication Aborted for client 46:5a:96:e3:99:bd Abort Reason:DOT1X RESTARTED DUE TO EAPOL-START/CLIENT ROAM&lt;BR /&gt;*Dot1x_NW_MsgTask_2: Nov 25 10:54:48.331: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_6: Nov 25 10:54:48.129: %DOT1X-3-INVALID_WPA_KEY_STATE: [PA]1x_eapkey.c:2909 Received EAPOL-key message while in invalid state (4) - version 1, type 3, descriptor 2, client e2:19:6c:7c:91:be&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:54:46.842: %DOT1X-3-AAA_AUTH_SEND_FAIL: [PA]1x_aaa.c:848 Unable to send AAA message for client 46:5a:96:e3:99:bd&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:54:46.833: %DOT1X-3-ABORT_AUTH: [PA]1x_bauth_sm.c:487 Authentication Aborted for client 46:5a:96:e3:99:bd Abort Reason:DOT1X RESTARTED DUE TO EAPOL-START/CLIENT ROAM&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Nov 25 10:54:46.718: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 1 failed; port status 1, key available 0, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Nov 25 10:54:46.143: %DOT1X-3-INVALID_REPLAY_CTR: [PA]1x_eapkey.c:452 Invalid replay counter from client e0:aa:96:cf:1e:88 - got 00 00 00 00 00 00 00 00, expected 00 00 00 00 00 00 00 01&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:54:43.124: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:54:42.169: %APF-3-PREAUTH_FAILURE: [PA]apf_80211.c:14799 There is no PMK cache entry for clientfa:8d:29:c8:f7:d7. Can't do preauth&lt;BR /&gt;*dot1xMsgTask: Nov 25 10:54:39.210: %DOT1X-3-WPA_SEND_STATE_ERR: [PA]1x_kxsm.c:1724 Unable to send EAPOL-key msg - invalid WPA state (0) - client b4:86:55:62:48:16&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:54:39.009: %DOT1X-3-PSK_CONFIG_ERR: [PA]1x_ptsm.c:749 Client c2:af:b7:6c:c1:d5 may be using an incorrect PSK&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:54:36.330: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_3: Nov 25 10:54:35.265: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;&lt;BR /&gt;--More-- or (q)uit&lt;BR /&gt;*spamApTask2: Nov 25 10:54:33.741: %CAPWAP-3-DTLS_CLOSED_ERR: [PA]capwap_ac_sm.c:7130 5c:83:8f:f3:7b:90: DTLS connection closed forAP 85:152:137:39 (54443), Controller: 10:35:0:78 (5246) AP Message Timeout&lt;BR /&gt;*spamApTask2: Nov 25 10:54:33.741: %CAPWAP-3-MAX_RETRANSMISSIONS_REACHED: [PA]capwap_ac_sm.c:7677 Max retransmissions reached on AP(5c:83:8f:f3:7b:90),message (CAPWAP_CONFIGURATION_UPDATE_REQUEST&lt;BR /&gt;),number of pending messages(2)&lt;BR /&gt;*spamApTask3: Nov 25 10:54:33.232: %CAPWAP-3-JOIN_UNSUPP_AP: [PA]capwap_ac_sm.c:5104 The system has received a join request from an unsupported AP 20:3a:07:85:45:a0 CEL000A015 (model AIR-LAP1261N-E-K9), dropping the packet&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:54:32.158: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*Dot1x_NW_MsgTask_2: Nov 25 10:54:29.891: %DOT1X-3-INVALID_REPLAY_CTR: [PA]1x_eapkey.c:452 Invalid replay counter from client ae:07:de:6a:f1:0a - got 00 00 00 00 00 00 00 02, expected 00 00 00 00 00 00 00 03&lt;BR /&gt;*haSSOServiceTask1: Nov 25 10:54:26.610: %APF_HA-3-SYNC_RETRANSMIT_FAIL: [PA]apf_ha.c:4483 Maximum retransmission exceeded for client (c0:bd:c8:d8:f2:f9 )data sync block:0x80000. Retry after 120 secs.&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Nov 25 10:54:24.267: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:54:20.981: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Nov 25 10:54:12.823: %DOT1X-3-PSK_CONFIG_ERR: [PA]1x_ptsm.c:749 Client a8:91:3d:84:c1:88 may be using an incorrect PSK&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:54:09.897: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:54:07.948: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Nov 25 10:54:04.784: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:54:04.131: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:53:59.774: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 25 10:53:58.610: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_2: Nov 25 10:53:56.499: %DOT1X-3-INVALID_REPLAY_CTR: [PA]1x_eapkey.c:452 Invalid replay counter from client fa:1b:24:3d:5f:f2 - got 00 00 00 00 00 00 00 02, expected 00 00 00 00 00 00 00 03&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Nov 25 10:53:55.996: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*dot1xMsgTask: Nov 25 10:53:55.417: %DOT1X-3-WPA_SEND_STATE_ERR: [PA]1x_kxsm.c:1724 Unable to send EAPOL-key msg - invalid WPA state (0) - client e6:93:e8:fa:a3:55&lt;BR /&gt;*Dot1x_NW_MsgTask_2: Nov 25 10:53:54.961: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_2: Nov 25 10:53:53.979: %DOT1X-3-PSK_CONFIG_ERR: [PA]1x_ptsm.c:749 Client 3c:f8:62:0d:91:a2 may be using an incorrect PSK&lt;BR /&gt;*Dot1x_NW_MsgTask_2: Nov 25 10:53:53.891: %DOT1X-3-INVALID_REPLAY_CTR: [PA]1x_eapkey.c:452 Invalid replay counter from client 58:20:59:8e:73:5a - got 00 00 00 00 00 00 00 02, expected 00 00 00 00 00 00 00 03&lt;BR /&gt;*Dot1x_NW_MsgTask_5: Nov 25 10:53:53.568: %DOT1X-3-PSK_CONFIG_ERR: [PA]1x_ptsm.c:749 Client 4a:91:f0:e6:d9:15 may be using an incorrect PSK&lt;BR /&gt;&lt;BR /&gt;--More-- or (q)uit&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Nov 25 10:53:52.212: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 25 10:53:50.694: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_6: Nov 25 10:53:50.419: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*apfMsConnTask_4: Nov 25 10:53:48.957: %APF-3-VALIDATE_DOT11i_CIPHERS_FAILED: [PA]apf_rsn_utils.c:1212 Could not validate Dot11i security IE. Received an unsupported Multicast 802.11i OUI code from mobile.Mobile:84:b5:41:fe:aa:f0&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Nov 25 10:53:44.727: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;BR /&gt;*Dot1x_NW_MsgTask_3: Nov 25 10:53:43.203: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have to say that this is a large deployment where the WLC and APs are not in the same city and I think the issue could be due to congestion regarding these events:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;*Dot1x_NW_MsgTask_3: Nov 25 16:31:32.312: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know the reason for these logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The following link does not help to find the root cause:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-6/message/guide/sysmsg76/dot1d_dot1q_dot1x_dot3ad_msgs8.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-6/message/guide/sysmsg76/dot1d_dot1q_dot1x_dot3ad_msgs8.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 15:29:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/intermittent-authentication-problems/m-p/4508394#M235943</guid>
      <dc:creator>david.chicote</dc:creator>
      <dc:date>2021-11-25T15:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent authentication problems</title>
      <link>https://community.cisco.com/t5/wireless/intermittent-authentication-problems/m-p/4509737#M236002</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know the reason for these events?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;*Dot1x_NW_MsgTask_3: Nov 25 16:31:32.312: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 07:26:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/intermittent-authentication-problems/m-p/4509737#M236002</guid>
      <dc:creator>david.chicote</dc:creator>
      <dc:date>2021-11-29T07:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent authentication problems</title>
      <link>https://community.cisco.com/t5/wireless/intermittent-authentication-problems/m-p/4510065#M236012</link>
      <description>&lt;P&gt;I would recommend to disable Aironet IE extensions first, that is more or less unneeded today.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then you seem to have unsupported APs in your environment:&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;*spamApTask3: Nov 25 10:54:33.232: %CAPWAP-3-JOIN_UNSUPP_AP: [PA]capwap_ac_sm.c:5104 The system has received a join request from an unsupported AP 20:3a:07:85:45:a0 CEL000A015 (model AIR-LAP1261N-E-K9), dropping the packet&lt;/PRE&gt;
&lt;P&gt;Could it be that you have more than one WLC in use here with different software versions and the problems happen when they try to roam from one WLC to another?&lt;/P&gt;
&lt;P&gt;Then there are also a few updates for the firmware out, which do fix some specific authentication issues with one specific AP series, see:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/crn85mr8.html#resolved-caveats" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/crn85mr8.html#resolved-caveats&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 15:57:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/intermittent-authentication-problems/m-p/4510065#M236012</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2021-11-29T15:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent authentication problems</title>
      <link>https://community.cisco.com/t5/wireless/intermittent-authentication-problems/m-p/4510394#M236033</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We will test it by disabling that feature.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We know that issue that there are APs that are not supported but this is not the issue we are facing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been reading bugs you sent me but I cannot relate it to the following event:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;*Dot1x_NW_MsgTask_2: Nov 25 10:53:54.961: %DOT1X-3-AUTHKEY_TX_TRANS_ERR: [PA]1x_kxsm.c:130 Authentication state transition to state 0 failed; port status 0, key available 1, key tx enabled 1&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 08:33:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/intermittent-authentication-problems/m-p/4510394#M236033</guid>
      <dc:creator>david.chicote</dc:creator>
      <dc:date>2021-11-30T08:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent authentication problems</title>
      <link>https://community.cisco.com/t5/wireless/intermittent-authentication-problems/m-p/4510397#M236035</link>
      <description>It's more related to the question if you have multiple WLC in use, maybe with different software releases.&lt;BR /&gt;</description>
      <pubDate>Tue, 30 Nov 2021 08:39:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/intermittent-authentication-problems/m-p/4510397#M236035</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2021-11-30T08:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent authentication problems</title>
      <link>https://community.cisco.com/t5/wireless/intermittent-authentication-problems/m-p/4510404#M236036</link>
      <description>&lt;P&gt;We only have one WLC. Some APs may not be supported because, a few weeks ago, we upgraded the WLC to 8.5.171, Cisco recommended version for 8510 platform. We have to disconnect these unsupported APs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 08:49:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/intermittent-authentication-problems/m-p/4510404#M236036</guid>
      <dc:creator>david.chicote</dc:creator>
      <dc:date>2021-11-30T08:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent authentication problems</title>
      <link>https://community.cisco.com/t5/wireless/intermittent-authentication-problems/m-p/4515574#M236363</link>
      <description>Ok, so the roaming / authentication fails within the WLC. That does remove one possible error source.&lt;BR /&gt;I found this document regarding the error:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-6/message/guide/sysmsg76/dot1d_dot1q_dot1x_dot3ad_msgs8.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-6/message/guide/sysmsg76/dot1d_dot1q_dot1x_dot3ad_msgs8.html&lt;/A&gt;&lt;BR /&gt;As this is a fairly rare message, I suggest opening a TAC for this.&lt;BR /&gt;Could you create a debug of one of the affected clients with "debug client macaddressofclient"? Then we can parse it with &lt;A href="https://cway.cisco.com/wireless-debug-analyzer/" target="_blank"&gt;https://cway.cisco.com/wireless-debug-analyzer/&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 08 Dec 2021 23:14:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/intermittent-authentication-problems/m-p/4515574#M236363</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2021-12-08T23:14:09Z</dc:date>
    </item>
  </channel>
</rss>

