<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic %DOT1X-3-INVALID_WPA_KEY_MSG_STATE ... iphone network failure inquiry in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/dot1x-3-invalid-wpa-key-msg-state-iphone-network-failure-inquiry/m-p/4092693#M31631</link>
    <description>&lt;P&gt;I have 300 ap on wlc 5520.&lt;BR /&gt;Some clients (only iPhones) are disconnected at unspecified times.&lt;BR /&gt;I did the analysis and the log below was checked.&lt;BR /&gt;% DOT1X-3-INVALID_WPA_KEY_MSG_STATE: 1x_eapkey.c: 1547 Received invalid EAPOL-key M2 msg in START state-invalid RSN IE; KeyLen 22, Key type 1, client aa: bb: cc: dd: ee: ff&lt;BR /&gt;In the log above, all mac addresses were confirmed as apple mac.&lt;BR /&gt;I did a community and bug search.&lt;BR /&gt;I tried applying all the methods I found in relation to this, but it did not resolve.&lt;/P&gt;&lt;P&gt;Only wpa2 / aes is set in wlan and there is no authentication server.&lt;BR /&gt;Both ft and pmf are not used for wlan.&lt;BR /&gt;I tried changing the value of EAP-Broadcast Key Interval to 86400, but the result was the same.&lt;BR /&gt;os version is 8.5.151 and ap is 1815, 1832.&lt;/P&gt;&lt;P&gt;We do not use a separate authentication server, do we need to see the EAP settings?&lt;BR /&gt;Where should I solve the problem?&lt;BR /&gt;I sincerely ask for your help from the community cisco.&lt;/P&gt;&lt;P&gt;thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 19:06:05 GMT</pubDate>
    <dc:creator>inb</dc:creator>
    <dc:date>2021-07-05T19:06:05Z</dc:date>
    <item>
      <title>%DOT1X-3-INVALID_WPA_KEY_MSG_STATE ... iphone network failure inquiry</title>
      <link>https://community.cisco.com/t5/wireless/dot1x-3-invalid-wpa-key-msg-state-iphone-network-failure-inquiry/m-p/4092693#M31631</link>
      <description>&lt;P&gt;I have 300 ap on wlc 5520.&lt;BR /&gt;Some clients (only iPhones) are disconnected at unspecified times.&lt;BR /&gt;I did the analysis and the log below was checked.&lt;BR /&gt;% DOT1X-3-INVALID_WPA_KEY_MSG_STATE: 1x_eapkey.c: 1547 Received invalid EAPOL-key M2 msg in START state-invalid RSN IE; KeyLen 22, Key type 1, client aa: bb: cc: dd: ee: ff&lt;BR /&gt;In the log above, all mac addresses were confirmed as apple mac.&lt;BR /&gt;I did a community and bug search.&lt;BR /&gt;I tried applying all the methods I found in relation to this, but it did not resolve.&lt;/P&gt;&lt;P&gt;Only wpa2 / aes is set in wlan and there is no authentication server.&lt;BR /&gt;Both ft and pmf are not used for wlan.&lt;BR /&gt;I tried changing the value of EAP-Broadcast Key Interval to 86400, but the result was the same.&lt;BR /&gt;os version is 8.5.151 and ap is 1815, 1832.&lt;/P&gt;&lt;P&gt;We do not use a separate authentication server, do we need to see the EAP settings?&lt;BR /&gt;Where should I solve the problem?&lt;BR /&gt;I sincerely ask for your help from the community cisco.&lt;/P&gt;&lt;P&gt;thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 19:06:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dot1x-3-invalid-wpa-key-msg-state-iphone-network-failure-inquiry/m-p/4092693#M31631</guid>
      <dc:creator>inb</dc:creator>
      <dc:date>2021-07-05T19:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: %DOT1X-3-INVALID_WPA_KEY_MSG_STATE ... iphone network failure inquiry</title>
      <link>https://community.cisco.com/t5/wireless/dot1x-3-invalid-wpa-key-msg-state-iphone-network-failure-inquiry/m-p/4092840#M31633</link>
      <description>&lt;P&gt;there are posts that pint to a bug in version 8.3&lt;/P&gt;
&lt;P&gt;read &lt;A href="https://community.cisco.com/t5/other-wireless-mobility-subjects/clients-losing-connectivity-dot1x-3-invalid-wpa-key-msg-state-1x/td-p/2916285" target="_self"&gt;this post that suggests the client driver or an intruder&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;it could just be the client prefers to connect using DOT1x first, and reverts to PSK second.&lt;/P&gt;
&lt;P&gt;(wild idea: does these clients use the same SSID name elsewhere with DOT1x enabled?)&lt;/P&gt;
&lt;P&gt;remove the wlan config from the client device and after some minutes re-add.&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 14:17:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dot1x-3-invalid-wpa-key-msg-state-iphone-network-failure-inquiry/m-p/4092840#M31633</guid>
      <dc:creator>pieterh</dc:creator>
      <dc:date>2020-05-27T14:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: %DOT1X-3-INVALID_WPA_KEY_MSG_STATE ... iphone network failure inquiry</title>
      <link>https://community.cisco.com/t5/wireless/dot1x-3-invalid-wpa-key-msg-state-iphone-network-failure-inquiry/m-p/4093200#M31634</link>
      <description>&lt;P&gt;We are using WPA2 AES (PSK) only for WLAN.&lt;BR /&gt;I do not use an authentication server and local EAP.&lt;BR /&gt;However, EAP related logs are generated. Is this normal operation?&lt;BR /&gt;I tried adjusting the EAP Timer, but the result is the same.&lt;/P&gt;&lt;P&gt;802.1x is not used.&lt;/P&gt;&lt;P&gt;There is no SSID of the same name using the authentication server.&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 02:13:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dot1x-3-invalid-wpa-key-msg-state-iphone-network-failure-inquiry/m-p/4093200#M31634</guid>
      <dc:creator>inb</dc:creator>
      <dc:date>2020-05-28T02:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: %DOT1X-3-INVALID_WPA_KEY_MSG_STATE ... iphone network failure inquiry</title>
      <link>https://community.cisco.com/t5/wireless/dot1x-3-invalid-wpa-key-msg-state-iphone-network-failure-inquiry/m-p/4093283#M31635</link>
      <description>&lt;P&gt;normally people take their phone everywhere, also outside your company.&lt;BR /&gt;and not only company phones are within reach of your wifi-network!&lt;/P&gt;
&lt;P&gt;there will be guests and strangers passing past the office.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;my suggestion is that some phone at some time outside your network, connected to a SSID with the same name.&lt;BR /&gt;and now comes within reach of your network and tries to authenticate using credentials configured for "the other network".&lt;BR /&gt;which of course fail..... and that is normal behaviour to show up in your logs.&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 06:07:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dot1x-3-invalid-wpa-key-msg-state-iphone-network-failure-inquiry/m-p/4093283#M31635</guid>
      <dc:creator>pieterh</dc:creator>
      <dc:date>2020-05-28T06:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: %DOT1X-3-INVALID_WPA_KEY_MSG_STATE ... iphone network failure inquiry</title>
      <link>https://community.cisco.com/t5/wireless/dot1x-3-invalid-wpa-key-msg-state-iphone-network-failure-inquiry/m-p/4093544#M31636</link>
      <description>&lt;P&gt;I don't think that's the problem.&lt;BR /&gt;I have a test AP in an enclosed space.&lt;BR /&gt;(2.4Ghz and 5Ghz signal absolutely free space)&lt;BR /&gt;I was connected to the WLAN in the latest OS of iPhone 11 pro.&lt;BR /&gt;If you repeatedly go out of sleep mode several times, communication with the outside is not possible even when connected to WLAN.&lt;BR /&gt;The condition of the iPhone's Wi-Fi antenna is full.&lt;BR /&gt;It does not occur on Android, MacBook, and laptops.&lt;BR /&gt;It only happens on the iphone.&lt;BR /&gt;5 ~ 6 years ago, there was a case where the iPhone could not communicate due to a similar problem.&lt;BR /&gt;At that time, IOS update or WLC OS update has been solved.&lt;BR /&gt;I'm not sure if this is the same problem again.&lt;BR /&gt;This time, a special log occurred in WLC.&lt;BR /&gt;I don't know what the cause is.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;&lt;FONT&gt;I understand your suggestion.&lt;BR /&gt;It is a university wireless network and there are only 200 people due to corona.&lt;BR /&gt;20 iphone clients a day have the same problem.&lt;BR /&gt;It seemed to have been resolved by going through a WLC OS update with a similar issue in early 2019, but it is said that it has recently begun to reappear.&lt;BR /&gt;When there are many people, I usually use up to 3000 people.&lt;BR /&gt;At this time, it is expected that 300 problems will occur simply by calculating.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;&lt;FONT&gt;This is a very big problem.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;&lt;FONT&gt;Thank you very much for your answer.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 12:08:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dot1x-3-invalid-wpa-key-msg-state-iphone-network-failure-inquiry/m-p/4093544#M31636</guid>
      <dc:creator>inb</dc:creator>
      <dc:date>2020-05-28T12:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: %DOT1X-3-INVALID_WPA_KEY_MSG_STATE ... iphone network failure inquiry</title>
      <link>https://community.cisco.com/t5/wireless/dot1x-3-invalid-wpa-key-msg-state-iphone-network-failure-inquiry/m-p/4094307#M31637</link>
      <description>There are some issues in the firmware you currently use, which might show this issue.&lt;BR /&gt;For this reason I suggest to upgrade to 8.5.161.0.&lt;BR /&gt;Release notes with the fixed bugs:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/crn85mr6.html#resolved-caveats_85mr6" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/crn85mr6.html#resolved-caveats_85mr6&lt;/A&gt;</description>
      <pubDate>Fri, 29 May 2020 11:27:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dot1x-3-invalid-wpa-key-msg-state-iphone-network-failure-inquiry/m-p/4094307#M31637</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2020-05-29T11:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: %DOT1X-3-INVALID_WPA_KEY_MSG_STATE ... iphone network failure inquiry</title>
      <link>https://community.cisco.com/t5/wireless/dot1x-3-invalid-wpa-key-msg-state-iphone-network-failure-inquiry/m-p/4103054#M31638</link>
      <description>&lt;P&gt;Eventually, it was confirmed to be an OS problem.&lt;BR /&gt;Thanks to everyone who helped. &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 02:40:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dot1x-3-invalid-wpa-key-msg-state-iphone-network-failure-inquiry/m-p/4103054#M31638</guid>
      <dc:creator>inb</dc:creator>
      <dc:date>2020-06-15T02:40:26Z</dc:date>
    </item>
  </channel>
</rss>

