<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disable Client Exclusion on EWC in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/disable-client-exclusion-on-ewc/m-p/4774946#M251666</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- You may try :&amp;nbsp;&lt;SPAN class="ph"&gt;(Cisco EWC Controller) &amp;gt;&lt;/SPAN&gt;&lt;STRONG&gt;config wps client-exclusion all disable&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Feb 2023 07:50:46 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2023-02-14T07:50:46Z</dc:date>
    <item>
      <title>Disable Client Exclusion on EWC</title>
      <link>https://community.cisco.com/t5/wireless/disable-client-exclusion-on-ewc/m-p/4774567#M251657</link>
      <description>&lt;P&gt;Ran into a weird problem that all started when I changed the PSK a WLAN uses. The SSID of the WLAN stayed the same, only the PSK changed. Since changing the PSK, even though we went through and updated the password on the wireless devices connecting to the WLAN that changed, they all initially connected fine. But soon we noticed randomly, devices were disconnecting from the network. Watching logs on the controller it shows the clients are getting added to the exclusion list due to the wrong PSK. Eventually all those same devices time out of the exclusion list, then connect fine without issue. Some time passes and they get added to the exclusion list again. I can't figure out if the problem is due to an issue with the wireless APs/controller or the clients themselves. All i can say though is this is happening to multiple types of clients (computers, phones, smart devices (plugs, Alexa, etc.)) so there isn't any commonality there. Thinking it was a bug with the IOS, i upgraded the firmware but the problem persisted. Tried wiping the entire config of the APs/controller and added back the PSK with the new config but the problem remained. So now I'm out of ideas and want to instead figure out how to just disable the client exclusion feature hoping that keeps devices connected. I understand the security ramifications of this, but for now am running out of options. Any and all responses on either what might be causing clients to get added to the exclusion list or how to disable it all together are much appreciated!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running two&amp;nbsp;C9130AXI-B access points which are configured as an embedded wireless controller. Firmware version&amp;nbsp;Cisco IOS XE Software, Version 17.09.02.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 01:15:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/disable-client-exclusion-on-ewc/m-p/4774567#M251657</guid>
      <dc:creator>brentr678</dc:creator>
      <dc:date>2023-02-14T01:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Client Exclusion on EWC</title>
      <link>https://community.cisco.com/t5/wireless/disable-client-exclusion-on-ewc/m-p/4774946#M251666</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- You may try :&amp;nbsp;&lt;SPAN class="ph"&gt;(Cisco EWC Controller) &amp;gt;&lt;/SPAN&gt;&lt;STRONG&gt;config wps client-exclusion all disable&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 07:50:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/disable-client-exclusion-on-ewc/m-p/4774946#M251666</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-02-14T07:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Client Exclusion on EWC</title>
      <link>https://community.cisco.com/t5/wireless/disable-client-exclusion-on-ewc/m-p/4775260#M251696</link>
      <description>&lt;P&gt;Unfortunately i believe that command only works in AireOS. It doesn't accept the command on the EWC.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 12:57:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/disable-client-exclusion-on-ewc/m-p/4775260#M251696</guid>
      <dc:creator>brentr678</dc:creator>
      <dc:date>2023-02-14T12:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Client Exclusion on EWC</title>
      <link>https://community.cisco.com/t5/wireless/disable-client-exclusion-on-ewc/m-p/4775333#M251704</link>
      <description>&lt;P&gt;Haven't tried it myself but I see these in "show run all" (handy for looking for default config):&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;wireless wps client-exclusion all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;wireless wps client-exclusion dot11-assoc&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;wireless wps client-exclusion dot1x-auth&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;wireless wps client-exclusion dot1x-timeout&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;wireless wps client-exclusion ip-theft&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;wireless wps client-exclusion web-auth&lt;/FONT&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;BR /&gt;So try no xxxx on those?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 14:29:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/disable-client-exclusion-on-ewc/m-p/4775333#M251704</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-02-14T14:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Client Exclusion on EWC</title>
      <link>https://community.cisco.com/t5/wireless/disable-client-exclusion-on-ewc/m-p/4775427#M251715</link>
      <description>&lt;P&gt;I don't have an EWC but from a 9800 controller, you define this on the Policy Profile:&lt;/P&gt;
&lt;P&gt;wireless profile policy &amp;lt;your policy profile&amp;gt;&lt;BR /&gt;no exclusionlist &lt;BR /&gt;exclusionlist timeout 0&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 16:33:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/disable-client-exclusion-on-ewc/m-p/4775427#M251715</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2023-02-14T16:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Client Exclusion on EWC</title>
      <link>https://community.cisco.com/t5/wireless/disable-client-exclusion-on-ewc/m-p/4775431#M251716</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &lt;U&gt;&lt;EM&gt;&amp;nbsp; &amp;gt;...Unfortunately i believe that command only works in AireOS. It doesn't accept the command on the EWC.&amp;nbsp;&lt;/EM&gt;&lt;/U&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Check if these commands can provide more insights :&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;STRONG&gt;show wireless stats client detail&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; show wireless stats client delete reasons&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;STRONG&gt;show wireless client history disconnected summary&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;STRONG&gt;show logging&amp;nbsp; profile wireless filter &amp;lt;CLIENTMAC&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Also have a checkup of the EWC controller configuration&amp;nbsp;&lt;SPAN&gt;with the CLI command :&lt;/SPAN&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;FONT color="#008000"&gt;&lt;STRONG&gt;show&amp;nbsp; tech&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;&lt;U&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;wireless&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;, have the output analyzed by&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://cway.cisco.com/tools/WirelessAnalyzer/" target="_blank" rel="noopener nofollow noreferrer" data-saferedirecturl="https://www.google.com/url?q=https://cway.cisco.com/tools/WirelessAnalyzer/&amp;amp;source=gmail&amp;amp;ust=1662270212514000&amp;amp;usg=AOvVaw1v8X824xUFwNwiDM_o5Fxf"&gt;https://cway.cisco.com/&lt;WBR /&gt;tools/WirelessAnalyzer/&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp; , please note do not use classical&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;show tech-support&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;(short version) , use the command denoted in green for Wireless Analyzer.&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Checkout all advisories!&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; - Look into client debugging :&amp;nbsp;&lt;A href="https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity" target="_blank"&gt;https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity&lt;/A&gt;&amp;nbsp;, you can have client debugs analyzed with :&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-debug-analyzer" target="_blank"&gt;https://cway.cisco.com/wireless-debug-analyzer&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 16:42:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/disable-client-exclusion-on-ewc/m-p/4775431#M251716</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-02-14T16:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Client Exclusion on EWC</title>
      <link>https://community.cisco.com/t5/wireless/disable-client-exclusion-on-ewc/m-p/4775448#M251718</link>
      <description>&lt;P&gt;I tried&amp;nbsp; "no&amp;nbsp;&lt;SPAN&gt;wireless wps client-exclusion all" in global config and that didn't have any affect. On the actual wireless profile policy though "no exclusionlist" has seemed to work. Ill give it a day or so before calling it completely resolved, but so far watching the logs no clients have been added. Thank you all for the suggestions!&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 17:21:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/disable-client-exclusion-on-ewc/m-p/4775448#M251718</guid>
      <dc:creator>brentr678</dc:creator>
      <dc:date>2023-02-14T17:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: Disable Client Exclusion on EWC</title>
      <link>https://community.cisco.com/t5/wireless/disable-client-exclusion-on-ewc/m-p/5213522#M276833</link>
      <description>&lt;P&gt;Via cli, it asks to disable policy before that change, unfortunally.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 09:44:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/disable-client-exclusion-on-ewc/m-p/5213522#M276833</guid>
      <dc:creator>rui-b-rodrigues</dc:creator>
      <dc:date>2024-10-23T09:44:35Z</dc:date>
    </item>
  </channel>
</rss>

