<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 9800 ARP in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251051#M280061</link>
    <description>&lt;P&gt;&lt;SPAN&gt;client is brought down and added to the exclusion list &amp;lt;&amp;lt;- check why client is add to exclusion' moslty it casue by mismatch of re-auth timer and/or aaa server&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jan 2025 16:22:05 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-01-22T16:22:05Z</dc:date>
    <item>
      <title>9800 ARP</title>
      <link>https://community.cisco.com/t5/wireless/9800-arp/m-p/5250938#M280046</link>
      <description>&lt;P&gt;Hello ALL&lt;BR /&gt;Morning&lt;BR /&gt;We are facing many disconections from clients, all points to Windows behaviour, but double checking this kind of log was identified in 9800 logging.&lt;BR /&gt;&lt;BR /&gt;Have you guys faced this issue before?&lt;BR /&gt;&lt;BR /&gt;WLC#show logging | i 28a0.6bXXXXXX&lt;BR /&gt;Jan 22 11:42:14.632: &lt;STRONG&gt;%SISF-4-EXCESS_ARP_ACTIVITY:&lt;/STRONG&gt; Chassis 1 R0/3: wncd: Excessive ARP activity detected for the client 28a0.6bXXXXXX. client is brought down and added to the exclusion list&lt;BR /&gt;Jan 22 11:42:14.633: &lt;STRONG&gt;%CLIENT_EXCLUSION_SERVER-5-ADD_TO_EXCLUSIONLIST_REASON_DYNAMIC:&lt;/STRONG&gt; Chassis 1 R0/0: wncmgrd: Client MAC: 28a0.6bXXXXXX was added to exclusion list associated with AP Name:XXXXX, BSSID:MAC: XXXXX, reason:&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;U&gt;Excessive ARP activity&lt;BR /&gt;&lt;BR /&gt;&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt;Update: APs are running as Local Mode, using inteface on /23 subnet&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2025 17:04:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-arp/m-p/5250938#M280046</guid>
      <dc:creator>yuricyrino</dc:creator>
      <dc:date>2025-01-24T17:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 ARP</title>
      <link>https://community.cisco.com/t5/wireless/9800-arp/m-p/5250940#M280047</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- What software version is the 9800 controller running ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 12:18:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-arp/m-p/5250940#M280047</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-01-22T12:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 ARP</title>
      <link>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251040#M280058</link>
      <description>&lt;P&gt;First make sure your software version is up to date as per the TAC recommended list (link below).&lt;/P&gt;
&lt;P&gt;Then make sure you have ARP proxy configured as per best practice guide:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html#AddressResolutionProtocolARPproxy" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html#AddressResolutionProtocolARPproxy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Also make sure the Windows wireless drivers are up to date.&amp;nbsp; If using Intel see:&lt;BR /&gt;&lt;A href="https://www.intel.com/content/www/us/en/download/19351/intel-wireless-wi-fi-drivers-for-windows-10-and-windows-11.html" target="_blank"&gt;https://www.intel.com/content/www/us/en/download/19351/intel-wireless-wi-fi-drivers-for-windows-10-and-windows-11.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;And finally check your WLC config with the Config Analyzer (link below) for any other possible issues.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 15:59:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251040#M280058</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2025-01-22T15:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 ARP</title>
      <link>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251051#M280061</link>
      <description>&lt;P&gt;&lt;SPAN&gt;client is brought down and added to the exclusion list &amp;lt;&amp;lt;- check why client is add to exclusion' moslty it casue by mismatch of re-auth timer and/or aaa server&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 16:22:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251051#M280061</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-22T16:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 ARP</title>
      <link>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251052#M280062</link>
      <description>&lt;P&gt;No more PM promise you.&lt;/P&gt;
&lt;P&gt;I am so respect you and Mr &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;
&lt;P&gt;Have a nice day.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 16:23:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251052#M280062</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-22T16:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 ARP</title>
      <link>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251069#M280064</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;The log already tells us the answer:&amp;nbsp;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;reason:Excessive ARP activity&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 16:46:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251069#M280064</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2025-01-22T16:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 ARP</title>
      <link>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251073#M280065</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;Here is the version&lt;BR /&gt;&lt;BR /&gt;#sh ver&lt;BR /&gt;Cisco IOS XE Software, Version V1712_4_ESW13&lt;BR /&gt;Cisco IOS Software [Dublin], C9800 Software (C9800_IOSXE-K9), Version 17.12.4, C UST-SPECIAL:V1712_4_ESW13&lt;BR /&gt;This software is supported for a limited time under special agreement with Cisco Systems, Inc. ESW13&lt;BR /&gt;Copyright (c) 1986-2024 by Cisco Systems, Inc.&lt;BR /&gt;Compiled Thu 21-Nov-24 09:34 by mcpre&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 16:50:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251073#M280065</guid>
      <dc:creator>yuricyrino</dc:creator>
      <dc:date>2025-01-22T16:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 ARP</title>
      <link>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251075#M280066</link>
      <description>&lt;P&gt;Exclusion reason are&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1- authc failure&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2- IP-theft&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I.e. there is no mention about arp rate led to exclusion.&lt;/P&gt;
&lt;P&gt;He need to check authc failure if not&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then he will check ip theft'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cisco recommends to reduce idle timeout of ssid to solve complicate of ip theft&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 16:54:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251075#M280066</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-22T16:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 ARP</title>
      <link>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251085#M280067</link>
      <description>&lt;P&gt;&lt;FONT face="courier new,courier"&gt;9800#show wireless wps summary&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Client Exclusion Policy&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Excessive 802.11-association failures : Disabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Excessive 802.1x-authentication : Enabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Mac and IP-theft : Enabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Excessive Web authentication failure : Disabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Failed Qos Policy : Enabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Excessive NDP Activity : Enabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;Excessive ARP Activity : Enabled&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;But ARP seems to be always on by default because it is not configurable:&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;9800(config)#wireless wps client-exclusion ?&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; all Configure response to all of these events&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; dot11-assoc Configure response to excess 802.11 association failures&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; dot1x-auth Configure response to excess 802.1x credential failures&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; dot1x-timeout Configure response to excess 802.1x authentication timeout&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; ip-theft Configure response to IP theft or re-use&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; web-auth Configure response to excess web authentication failures&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;but it's &lt;STRONG&gt;definitely&lt;/STRONG&gt; a whole lot more than just IP theft and auth failure &amp;lt;wink&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 17:08:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251085#M280067</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2025-01-22T17:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 ARP</title>
      <link>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251089#M280068</link>
      <description>&lt;P&gt;Well&amp;nbsp;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;17.12.4 ESW13&lt;/FONT&gt;&lt;/STRONG&gt;&amp;nbsp;is fully up to date so that's good.&lt;/P&gt;
&lt;P&gt;So check out the other things I mentioned below in my previous reply.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 17:10:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251089#M280068</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2025-01-22T17:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 ARP</title>
      <link>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251096#M280069</link>
      <description>&lt;P&gt;He can more clarify reason by do&lt;/P&gt;
&lt;P&gt;Show wireless exclusionlist &amp;lt;&amp;lt;- check if it ip theft or arp&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 17:14:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251096#M280069</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-22T17:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 ARP</title>
      <link>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251125#M280070</link>
      <description>&lt;P&gt;and:&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;9800#show wireless exclusionlist client mac-address&amp;nbsp;&lt;SPAN&gt;28a0.6ba9.c21b&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;but I expect that will just show exactly what the logs already say.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 18:09:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-arp/m-p/5251125#M280070</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2025-01-22T18:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 ARP</title>
      <link>https://community.cisco.com/t5/wireless/9800-arp/m-p/5252232#M280184</link>
      <description>&lt;P&gt;Hello All&lt;BR /&gt;&lt;BR /&gt;Thanks for the tips.&lt;BR /&gt;We identified an behaviour in a software named Adaptiva, that is responsible for Windows Updates inside the company, the application downloads the patches from a central location. The distribution happens P2P betwen neighbors computers, the discovering process use ARP.&lt;BR /&gt;The appication was configured to seach in a &lt;STRONG&gt;/20&lt;/STRONG&gt; subnet &lt;STRONG&gt;4096&lt;/STRONG&gt; IPs to perform ARP.&lt;BR /&gt;After a change to &lt;STRONG&gt;/24&lt;/STRONG&gt;&amp;nbsp;subnet &lt;STRONG&gt;256&lt;/STRONG&gt; IPs, there is no issues reported anymore.&lt;BR /&gt;&lt;BR /&gt;In my point of view, we need do create a kind os assignature to classify the application to not identify like a theath.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;9800#show wireless wps summary&lt;BR /&gt;Client Exclusion Policy&lt;BR /&gt;Excessive 802.11-association failures : Enabled&lt;BR /&gt;Excessive 802.1x-authentication : Enabled&lt;BR /&gt;Mac and IP-theft : Enabled&lt;BR /&gt;Excessive Web authentication failure : Enabled&lt;BR /&gt;Failed Qos Policy : Enabled&lt;BR /&gt;Excessive NDP Activity : Enabled&lt;BR /&gt;&lt;STRONG&gt;Excessive ARP Activity : Enabled&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Management Frame Protection&lt;BR /&gt;Global Infrastructure MFP state : Enabled&lt;BR /&gt;AP Impersonation detection : Enabled&lt;BR /&gt;Key refresh interval : 24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2025 14:32:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-arp/m-p/5252232#M280184</guid>
      <dc:creator>yuricyrino</dc:creator>
      <dc:date>2025-01-24T14:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 ARP</title>
      <link>https://community.cisco.com/t5/wireless/9800-arp/m-p/5252239#M280186</link>
      <description>&lt;P&gt;Another badly designed application written by a developer that doesn't understand networks! &amp;lt;sigh&amp;gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2025 15:05:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-arp/m-p/5252239#M280186</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2025-01-24T15:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 ARP</title>
      <link>https://community.cisco.com/t5/wireless/9800-arp/m-p/5252689#M280247</link>
      <description>&lt;P&gt;You are so welcome,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for update us&lt;/P&gt;
&lt;P&gt;Have a nice weekend&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jan 2025 20:21:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-arp/m-p/5252689#M280247</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-25T20:21:35Z</dc:date>
    </item>
  </channel>
</rss>

