<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EAP ID mismatch in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/eap-id-mismatch/m-p/4722433#M248302</link>
    <description>&lt;P&gt;If you are only selecting the SSID on the operating system to connect to, try to manually set the WLAN profile in the OS with the correct configuration. Sometimes automatic connections use improper EAP ID and you need to create the profile manually. This happen to me using Android with public signed certificates, and some legacy Windows ones.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Nov 2022 12:19:23 GMT</pubDate>
    <dc:creator>JPavonM</dc:creator>
    <dc:date>2022-11-16T12:19:23Z</dc:date>
    <item>
      <title>EAP ID mismatch</title>
      <link>https://community.cisco.com/t5/wireless/eap-id-mismatch/m-p/4719325#M248094</link>
      <description>&lt;P&gt;Hi ,, I am facing connection problems with laptops when try to conect to the WiFi , I am not facing same issue with Mobiles.&lt;/P&gt;&lt;P&gt;when a laptop tries to connect to the WiFi it is often failed and after trying for many times it succeed.&lt;/P&gt;&lt;P&gt;I did debug and I figured out that the problem is the laptops are replaying too late that the server increment EAP ID&amp;nbsp; before they send the response&amp;nbsp; with older EAP ID causing ID mismatch.&lt;/P&gt;&lt;P&gt;Is there a way to maybe disable this check or any other work around.&lt;/P&gt;&lt;P&gt;or if my conclusion is wrong , please advise me .&lt;/P&gt;&lt;P&gt;below is the debugging output :&lt;/P&gt;&lt;P&gt;*apfOpenDtlSocket: Nov 10 11:44:10.906: 18:cf:5e:11:38:d7 Recevied management frame ASSOCIATION REQUEST on BSSID 08:ec:f5:cb:e4:c0 destination addr 08:ec:f5:cb:e4:c0&lt;BR /&gt;*spamApTask2: Nov 10 11:44:10.910: 18:cf:5e:11:38:d7 Received ADD_MOBILE ack - Initiating 1x to STA 18:cf:5e:11:38:d7 (idx 90)&lt;BR /&gt;*spamApTask2: Nov 10 11:44:10.910: 18:cf:5e:11:38:d7 APF Initiating 1x to STA 18:cf:5e:11:38:d7&lt;BR /&gt;*spamApTask2: Nov 10 11:44:10.910: 18:cf:5e:11:38:d7 Sent dot1x auth initiate message for mobile 18:cf:5e:11:38:d7&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:10.910: 18:cf:5e:11:38:d7 dot1xProcessInitiate1XtoMobile to mobile station 18:cf:5e:11:38:d7 (mscb 2, msg 2)&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:10.910: 18:cf:5e:11:38:d7 reauth_sm state transition 1 ---&amp;gt; 0 for mobile 18:cf:5e:11:38:d7 at 1x_reauth_sm.c:53&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:10.910: 18:cf:5e:11:38:d7 EAP-PARAM Debug - eap-params for Wlan-Id :2 is disabled - applying Global eap timers and retries&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:10.910: 18:cf:5e:11:38:d7 Disable re-auth, use PMK lifetime.&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:10.910: 18:cf:5e:11:38:d7 dot1x - moving mobile 18:cf:5e:11:38:d7 into Connecting state&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:10.910: 18:cf:5e:11:38:d7 Sending EAP-Request/Identity to mobile 18:cf:5e:11:38:d7 (EAP Id 1)&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:11.277: 18:cf:5e:11:38:d7 Received EAPOL START from mobile in dot1x state = 2&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:11.277: 18:cf:5e:11:38:d7 Reset the reauth counter since EAPOL START has been received!!!&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:11.277: 18:cf:5e:11:38:d7 reauth_sm state transition 0 ---&amp;gt; 1 for mobile 18:cf:5e:11:38:d7 at 1x_reauth_sm.c:47&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:11.277: 18:cf:5e:11:38:d7 Received EAPOL START from mobile 18:cf:5e:11:38:d7&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:11.277: 18:cf:5e:11:38:d7 dot1x - moving mobile 18:cf:5e:11:38:d7 into Connecting state&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:11.277: 18:cf:5e:11:38:d7 Sending EAP-Request/Identity to mobile 18:cf:5e:11:38:d7 (EAP Id 2)&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:11.277: 18:cf:5e:11:38:d7 Received EAPOL EAPPKT from mobile 18:cf:5e:11:38:d7&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:11.277: 18:cf:5e:11:38:d7 Received EAP Response packet with mismatching id (currentid=2, eapid=1) from mobile 18:cf:5e:11:38:d7&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:11.422: 18:cf:5e:11:38:d7 Received EAPOL EAPPKT from mobile 18:cf:5e:11:38:d7&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:11.422: 18:cf:5e:11:38:d7 Received Identity Response (count=1) from mobile 18:cf:5e:11:38:d7&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:11.422: 18:cf:5e:11:38:d7 Resetting reauth count 1 to 0 for mobile 18:cf:5e:11:38:d7&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:11.423: 18:cf:5e:11:38:d7 EAP State update from Connecting to Authenticating for mobile 18:cf:5e:11:38:d7&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:11.423: 18:cf:5e:11:38:d7 dot1x - moving mobile 18:cf:5e:11:38:d7 into Authenticating state&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:11.423: 18:cf:5e:11:38:d7 Entering Backend Auth Response state for mobile 18:cf:5e:11:38:d7&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:42.523: 18:cf:5e:11:38:d7 Processing AAA Error 'Timeout' (-5) for mobile 18:cf:5e:11:38:d7&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:42.523: 18:cf:5e:11:38:d7 Setting active key cache index 8 ---&amp;gt; 8&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:42.523: 18:cf:5e:11:38:d7 Deleting the PMK cache when de-authenticating the client.&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:42.523: 18:cf:5e:11:38:d7 PMK: Sending Flexconnect group cache delete message to spam task&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:42.523: 18:cf:5e:11:38:d7 Removing PMK cache entry for station 18:cf:5e:11:38:d7&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:42.523: 18:cf:5e:11:38:d7 Succesfully freed AID 15, slot 0 on AP 08:ec:f5:cb:e4:c0, #client on this slot 4&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:42.523: 18:cf:5e:11:38:d7 Sent Deauthenticate to mobile on BSSID 08:ec:f5:cb:e4:c0 slot 0(caller 1x_auth_pae.c:1888)&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Nov 10 11:44:42.523: 18:cf:5e:11:38:d7 Scheduling deletion of Mobile Station: (callerId: 65) in 10 seconds&lt;BR /&gt;*osapiBsnTimer: Nov 10 11:44:52.358: 18:cf:5e:11:38:d7 apfMsExpireCallback (apf_ms.c:645) Expiring Mobile!&lt;BR /&gt;*apfReceiveTask: Nov 10 11:44:52.358: 18:cf:5e:11:38:d7 apfMsExpireMobileStation (apf_ms.c:7869) Changing state for mobile 18:cf:5e:11:38:d7 on AP 08:ec:f5:cb:e4:c0 from Associated to Disassociated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 13:33:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-id-mismatch/m-p/4719325#M248094</guid>
      <dc:creator>enghassanf9009</dc:creator>
      <dc:date>2022-11-10T13:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: EAP ID mismatch</title>
      <link>https://community.cisco.com/t5/wireless/eap-id-mismatch/m-p/4719349#M248095</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Below is the output from your debugging session when analyzed with :&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-debug-analyzer/" target="_blank"&gt;https://cway.cisco.com/wireless-debug-analyzer/&lt;/A&gt;&amp;nbsp;(&lt;STRONG&gt;Show all&lt;/STRONG&gt; flag was checked) :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;TimeTaskTranslated&lt;/P&gt;
&lt;TABLE class="table table--striped table--wrapped table--bordered"&gt;
&lt;THEAD&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Nov 10 11:44:10.910&lt;/TD&gt;
&lt;TD&gt;*Dot1x_NW_MsgTask_7&lt;/TD&gt;
&lt;TD&gt;WLC/AP is sending EAP-Identity-Request to the client&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Nov 10 11:44:11.277&lt;/TD&gt;
&lt;TD&gt;*Dot1x_NW_MsgTask_7&lt;/TD&gt;
&lt;TD&gt;WLC/AP is sending EAP-Identity-Request to the client&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Nov 10 11:44:11.422&lt;/TD&gt;
&lt;TD&gt;*Dot1x_NW_MsgTask_7&lt;/TD&gt;
&lt;TD&gt;Client sent EAP-Identity-Response to WLC/AP&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Nov 10 11:44:42.523&lt;/TD&gt;
&lt;TD&gt;*Dot1x_NW_MsgTask_7&lt;/TD&gt;
&lt;TD&gt;Client has been deauthenticated&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Nov 10 11:44:42.523&lt;/TD&gt;
&lt;TD&gt;*Dot1x_NW_MsgTask_7&lt;/TD&gt;
&lt;TD&gt;Client expiration timer code set for 10 seconds. The reason: &lt;FONT color="#FF0000"&gt;AAA error during dot1x auth (&lt;STRONG&gt;server timeout&lt;/STRONG&gt;&lt;/FONT&gt;, &lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;no server&lt;/STRONG&gt; found, etc&lt;/FONT&gt;), &lt;U&gt;triggering client delete&lt;/U&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Nov 10 11:44:52.358&lt;/TD&gt;
&lt;TD&gt;*apfReceiveTask&lt;/TD&gt;
&lt;TD&gt;&lt;FONT color="#FF6600"&gt;Client session has&lt;STRONG&gt; timed out&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Thu, 10 Nov 2022 14:28:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-id-mismatch/m-p/4719349#M248095</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-11-10T14:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: EAP ID mismatch</title>
      <link>https://community.cisco.com/t5/wireless/eap-id-mismatch/m-p/4719352#M248096</link>
      <description>&lt;P&gt;Hi Sir , thanks a lot for your replay .&lt;/P&gt;&lt;P&gt;This means that the problem is the authentication server is not available ?&lt;/P&gt;&lt;P&gt;if Yes why I dont face this issue with mobiles ?&lt;/P&gt;&lt;P&gt;the problem has nothing to do with EAP ID mismatch ?&lt;/P&gt;&lt;P&gt;Pardon my questions but I am trying to understand .&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 14:34:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-id-mismatch/m-p/4719352#M248096</guid>
      <dc:creator>enghassanf9009</dc:creator>
      <dc:date>2022-11-10T14:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: EAP ID mismatch</title>
      <link>https://community.cisco.com/t5/wireless/eap-id-mismatch/m-p/4719405#M248100</link>
      <description>&lt;P&gt;Have you tried to upgrade wNIC drivers to latest ones?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 16:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-id-mismatch/m-p/4719405#M248100</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2022-11-10T16:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: EAP ID mismatch</title>
      <link>https://community.cisco.com/t5/wireless/eap-id-mismatch/m-p/4719415#M248102</link>
      <description>&lt;P&gt;Is there a command to make it &amp;nbsp;ignore &amp;nbsp;the ID mismatch ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 16:42:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-id-mismatch/m-p/4719415#M248102</guid>
      <dc:creator>enghassanf9009</dc:creator>
      <dc:date>2022-11-10T16:42:53Z</dc:date>
    </item>
    <item>
      <title>Re: EAP ID mismatch</title>
      <link>https://community.cisco.com/t5/wireless/eap-id-mismatch/m-p/4719424#M248105</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;EM&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;U&gt;&amp;nbsp; &amp;gt;...This means that the problem is the authentication server is not available ?&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- It depends&amp;nbsp; , lookup the mac address of&amp;nbsp; the laptop&amp;nbsp; in the authenticating&amp;nbsp; logs of the authorization server and see how the authentication for the particular mac is processed. If it can not be found then the laptop may not be able to reach the authentication server, as other user said make sure &lt;EM&gt;&lt;FONT color="#008000"&gt;wireless drivers are&lt;U&gt;&amp;nbsp; up to date.&lt;/U&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 17:02:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-id-mismatch/m-p/4719424#M248105</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-11-10T17:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: EAP ID mismatch</title>
      <link>https://community.cisco.com/t5/wireless/eap-id-mismatch/m-p/4722424#M248300</link>
      <description>&lt;P&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;Is there a command to make it &amp;nbsp;ignore &amp;nbsp;the ID mismatch ?&lt;/SPAN&gt;&lt;BR /&gt;No - that would break the security of the protocol!&lt;/P&gt;
&lt;P&gt;What model of controller?&lt;BR /&gt;What version of software?&lt;BR /&gt;What model of AP?&lt;BR /&gt;What make and model of network adapter on laptop?&lt;BR /&gt;What version is the network adapter driver?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 12:00:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-id-mismatch/m-p/4722424#M248300</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-11-16T12:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: EAP ID mismatch</title>
      <link>https://community.cisco.com/t5/wireless/eap-id-mismatch/m-p/4722433#M248302</link>
      <description>&lt;P&gt;If you are only selecting the SSID on the operating system to connect to, try to manually set the WLAN profile in the OS with the correct configuration. Sometimes automatic connections use improper EAP ID and you need to create the profile manually. This happen to me using Android with public signed certificates, and some legacy Windows ones.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 12:19:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-id-mismatch/m-p/4722433#M248302</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2022-11-16T12:19:23Z</dc:date>
    </item>
  </channel>
</rss>

