<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How WLC calculate dirty interface in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/how-wlc-calculate-dirty-interface/m-p/3887583#M242</link>
    <description>&lt;P&gt;are you using webauth on SSID ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If yes then adjust the timeout on WLC including sleeping client feature.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Dont forget to rate helpful posts&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jul 2019 09:00:21 GMT</pubDate>
    <dc:creator>Sandeep Choudhary</dc:creator>
    <dc:date>2019-07-10T09:00:21Z</dc:date>
    <item>
      <title>How WLC calculate dirty interface</title>
      <link>https://community.cisco.com/t5/wireless/how-wlc-calculate-dirty-interface/m-p/3887541#M241</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have some issue with the interface group setup.&lt;/P&gt;&lt;P&gt;Scenario :&lt;/P&gt;&lt;P&gt;Cisco WLC 5520 running 8.5.140 code.&lt;/P&gt;&lt;P&gt;15 interface in 1 interface group.&lt;/P&gt;&lt;P&gt;Open authentication SSID&lt;/P&gt;&lt;P&gt;Authentication in Firewall. Allowed 7 days for each client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, my question is, how do the WLC determine my VLAN is dirty and is there any ways to override this configuration so that my WLC will follow the firewall configuration which is 7 days for each client. Some of my client get the authentication page before 7days.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advanced.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 17:41:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-wlc-calculate-dirty-interface/m-p/3887541#M241</guid>
      <dc:creator>Safwan Hashan</dc:creator>
      <dc:date>2021-07-05T17:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: How WLC calculate dirty interface</title>
      <link>https://community.cisco.com/t5/wireless/how-wlc-calculate-dirty-interface/m-p/3887583#M242</link>
      <description>&lt;P&gt;are you using webauth on SSID ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If yes then adjust the timeout on WLC including sleeping client feature.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Dont forget to rate helpful posts&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 09:00:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-wlc-calculate-dirty-interface/m-p/3887583#M242</guid>
      <dc:creator>Sandeep Choudhary</dc:creator>
      <dc:date>2019-07-10T09:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: How WLC calculate dirty interface</title>
      <link>https://community.cisco.com/t5/wireless/how-wlc-calculate-dirty-interface/m-p/3887605#M243</link>
      <description>&lt;P&gt;No, im not using webauth. Im using open authentication,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 09:46:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-wlc-calculate-dirty-interface/m-p/3887605#M243</guid>
      <dc:creator>Safwan Hashan</dc:creator>
      <dc:date>2019-07-10T09:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: How WLC calculate dirty interface</title>
      <link>https://community.cisco.com/t5/wireless/how-wlc-calculate-dirty-interface/m-p/3888966#M244</link>
      <description>&lt;P&gt;When you say "VLAN is dirty", do you mean DHCP exhaustion?&amp;nbsp; If so, then the answer is that the WLC listens for DHCP Replies and if none is received, then the WLC calculates a new hash value to select a different interface. Then same algorithm runs again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 07:30:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-wlc-calculate-dirty-interface/m-p/3888966#M244</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-07-12T07:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: How WLC calculate dirty interface</title>
      <link>https://community.cisco.com/t5/wireless/how-wlc-calculate-dirty-interface/m-p/3888973#M245</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The client shouldn't be authenticate before 7 days because the mac address of the client is stored in firewall.&lt;/P&gt;&lt;P&gt;The only reason client get re-authenticate before 7 days is because the client is changing its IP address.&lt;/P&gt;&lt;P&gt;So, when the client get re-authenticate before 7 days, i check the WLC and it shows as below output.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Cisco Controller) &amp;gt;show interface group detailed &amp;lt;int group&amp;gt;&lt;/P&gt;&lt;P&gt;Interface Group Name............................. &amp;lt;int group&amp;gt;&lt;BR /&gt;Quarantine ...................................... No&lt;BR /&gt;Number of Wlans using the Interface Group........ 2&lt;BR /&gt;Number of AP Groups using the Interface Group.... 122&lt;BR /&gt;Number of Interfaces Contained................... 16&lt;BR /&gt;mDNS Profile Name................................ Unconfigured&lt;BR /&gt;Failure-Detect Mode.............................. Aggressive&lt;BR /&gt;Interface Group Description......................&lt;BR /&gt;Interfaces Contained in this group ..............&lt;BR /&gt;pool 701&lt;BR /&gt;pool 702&lt;BR /&gt;pool 703&lt;BR /&gt;pool 704&lt;BR /&gt;pool 705&lt;BR /&gt;pool 706&lt;BR /&gt;pool 707&lt;BR /&gt;pool 708&lt;BR /&gt;pool 709&lt;BR /&gt;pool 710&lt;BR /&gt;pool 711&lt;BR /&gt;pool 712&lt;BR /&gt;pool 713&lt;BR /&gt;pool 714 *&lt;BR /&gt;pool 715&lt;BR /&gt;pool 716&lt;BR /&gt;Interface marked with * indicates DHCP dirty interface&lt;BR /&gt;Interface list sorted based on vlan:&lt;/P&gt;&lt;P&gt;Index Vlan Interface Name Dirty Failures DirtyTime(s)&lt;BR /&gt;----- ---- -------------------------------- ----- ------------- ---------&lt;BR /&gt;0 701 pool 701 No 0 0&lt;BR /&gt;1 702 pool 702 No 0 0&lt;BR /&gt;2 703 pool 703 No 0 0&lt;BR /&gt;3 704 pool 704 No 0 0&lt;BR /&gt;4 705 pool 705 No 0 0&lt;BR /&gt;5 706 pool 706 No 0 0&lt;BR /&gt;6 707 pool 707 No 0 0&lt;BR /&gt;7 708 pool 708 No 0 0&lt;BR /&gt;8 709 pool 709 No 0 0&lt;BR /&gt;9 710 pool 710 No 0 0&lt;BR /&gt;10 711 pool 711 No 0 0&lt;BR /&gt;11 712 pool 712 No 0 0&lt;BR /&gt;12 713 pool 713 No 0 0&lt;BR /&gt;13 714 pool 714 Yes 7 863&lt;BR /&gt;14 715 pool 715 No 0 0&lt;BR /&gt;15 716 pool 716 No 0 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any ways to turn this dirty interface off?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advanced.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 07:37:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-wlc-calculate-dirty-interface/m-p/3888973#M245</guid>
      <dc:creator>Safwan Hashan</dc:creator>
      <dc:date>2019-07-12T07:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: How WLC calculate dirty interface</title>
      <link>https://community.cisco.com/t5/wireless/how-wlc-calculate-dirty-interface/m-p/3892916#M246</link>
      <description>&lt;P&gt;I think you´re misinterpreting concepts here. Dirty interface, as mentioned above, is an flap indicating that something is not good on the DHCP service. This can become Dirty because you DHCP scope is full, or the DHCP request send on that interface it not reaching the DHCP server. After some failing attempt in a specific interface, WLC mark that interface as Dirty and stop asking DHCP on that interface for a while. You can see a counter on the interface Dirty.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Re-Authentication and DHCP renew are different things. You can have a lease time let´s say of 5 minutes and a Session time out of 60 minutes. Which means, IP address will be renewed many times until the re-authentication take place.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;You can configure Session timeout as 0 "zero" and then disable Session timeout.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Valid ranges to Session timeout are:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Configurable session timeout range is:&lt;BR /&gt;• 300-86400 for 802.1x.&lt;BR /&gt;• 0-65535 for all other security types.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If in your case you care using Open Authentication, you can use up to 65535 seconds which means 18 hours.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2019 15:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-wlc-calculate-dirty-interface/m-p/3892916#M246</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2019-07-18T15:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: How WLC calculate dirty interface</title>
      <link>https://community.cisco.com/t5/wireless/how-wlc-calculate-dirty-interface/m-p/3900419#M247</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Thanks. We disable the session timeout but the issue is still there.&lt;BR /&gt;&lt;BR /&gt;So, i'm changing the configuration for interface group to non-aggressive and we dont have any interface dirty anymore.&lt;BR /&gt;</description>
      <pubDate>Wed, 31 Jul 2019 03:02:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-wlc-calculate-dirty-interface/m-p/3900419#M247</guid>
      <dc:creator>Safwan Hashan</dc:creator>
      <dc:date>2019-07-31T03:02:41Z</dc:date>
    </item>
  </channel>
</rss>

