<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/8021x-reqd-problem-in-wlc-5520-8-2-code/m-p/3048802#M38511</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Thank you for your information. Very helpful.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Arie&lt;/P&gt;</description>
    <pubDate>Wed, 26 Apr 2017 03:33:45 GMT</pubDate>
    <dc:creator>Arie --</dc:creator>
    <dc:date>2017-04-26T03:33:45Z</dc:date>
    <item>
      <title>8021x_reqd Problem in WLC 5520 (8.2 code)</title>
      <link>https://community.cisco.com/t5/wireless/8021x-reqd-problem-in-wlc-5520-8-2-code/m-p/3048798#M38507</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I've found interesting issue when a client tries to connect to wireless system.&lt;/P&gt;
&lt;P&gt;Here are the devices:&lt;/P&gt;
&lt;P&gt;-. Cisco WLC 5520 running 8.2 code&lt;/P&gt;
&lt;P&gt;-. AP 3802I&lt;/P&gt;
&lt;P&gt;-. Laptop as a client (&lt;SPAN&gt;f4:8c:50:2b:c6:2c)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The SSID A is configured as below:&lt;/P&gt;
&lt;P&gt;-. Flexconnect local switching, centralized auth&lt;/P&gt;
&lt;P&gt;-. FT Support enable, over the DS&lt;/P&gt;
&lt;P&gt;-. Re-association timeout in FT = 20 sec&lt;/P&gt;
&lt;P&gt;-. WPA2, AES&lt;/P&gt;
&lt;P&gt;-. 802.1X, CCKM, FT802.1x&lt;/P&gt;
&lt;P&gt;-. AAA override&lt;/P&gt;
&lt;P&gt;-. Session timeout= 36000 sec&lt;/P&gt;
&lt;P&gt;-. Client exclusion= 330&lt;/P&gt;
&lt;P&gt;-. NAC State= ISE NAC&lt;/P&gt;
&lt;P&gt;-. optional MFP Client protection&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;EAP Advanced parameter:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;EAP-Identity-Request Timeout (seconds)........... 30&lt;/LI&gt;
&lt;LI&gt;EAP-Identity-Request Max Retries................. 20&lt;/LI&gt;
&lt;LI&gt;EAP Key-Index for Dynamic WEP.................... 0&lt;/LI&gt;
&lt;LI&gt;EAP Max-Login Ignore Identity Response........... enable&lt;/LI&gt;
&lt;LI&gt;EAP-Request Timeout (seconds).................... 30&lt;/LI&gt;
&lt;LI&gt;EAP-Request Max Retries.......................... 2&lt;/LI&gt;
&lt;LI&gt;EAPOL-Key Timeout (milliseconds)................. 1000&lt;/LI&gt;
&lt;LI&gt;EAPOL-Key Max Retries............................ 4&lt;/LI&gt;
&lt;LI&gt;EAP-Broadcast Key Interval....................... 86400&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The problem is, the client can't be in the RUN state and always stuck with 8021x_REQD.&lt;/P&gt;
&lt;P&gt;I have done the debug client and debug AAA events, and I found this:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The client is associated:&amp;nbsp;&lt;EM&gt;apfProcessAssocReq (apf_80211.c:10507) Changing state for mobile f4:8c:50:2b:c6:2c on AP 2c:5a:0f:3b:9d:20 from Associated to Associated&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;There is access-challenge:&amp;nbsp;&lt;EM&gt;Access-Challenge received from RADIUS server 10.24.134.187 (qid:12) with port:1812, pktId:23 for mobile f4:8c:50:2b:c6:2c receiveId = 6&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;There are several access-challenge packets till access-accept:&amp;nbsp;&lt;EM&gt;Access-Accept received from RADIUS server 10.24.134.187 (qid:12) with port:1812, pktId:31 for mobile f4:8c:50:2b:c6:2c receiveId = 6&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Username is inputted, EAP &amp;nbsp;Success:&amp;nbsp;S&lt;EM&gt;ending EAP-Success to mobile f4:8c:50:2b:c6:2c (EAP Id 237)&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Mobile in authenticated state:&amp;nbsp;&lt;EM&gt;dot1x - moving mobile f4:8c:50:2b:c6:2c into Authenticated state&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;L2AUTH Complete:&lt;BR /&gt;&lt;EM&gt;Mobility query, PEM State: L2AUTHCOMPLETE&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Building Mobile Announce :&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Building Client Payload:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Client Ip: 10.21.244.177&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Client Vlan Ip: 10.23.41.100, Vlan mask : 255.255.255.0 &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Client Vap Security: 278592&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Virtual Ip: 1.1.1.1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ssid: Test&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Building VlanIpPayload.&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Until the client has received the RUN State:&lt;BR /&gt;&lt;EM&gt;10.21.244.177 L2AUTHCOMPLETE (4) Change state to RUN (20) last state L2AUTHCOMPLETE (4)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10.21.244.177 RUN (20) Reached PLUMBFASTPATH: from line 6760&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10.21.244.177 RUN (20) Change state to RUN (20) last state RUN (20)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10.21.244.177 RUN (20) mobility role update request from Unassociated to Local&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10.21.244.177 RUN (20) State Update from Mobility-Incomplete to Mobility-Complete, mobility role=Local, client state=APF_MS_STATE_ASSOCIATED&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;10.21.244.177 RUN (20) Reached PLUMBFASTPATH: from line 6324&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Let say the RUN state occured at 18:20:09.668&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;And suddenly at 18:20:09.673, the client is DELETED:&lt;/STRONG&gt;&amp;nbsp;&lt;EM&gt;f4:8c:50:2b:c6:2c Received DELETE mobile, reason MN_AP_AUTH_STOP, from AP 2c:5a:0f:3b:9d:20, slot 1 ...cleaning up mscb&lt;BR /&gt;f4:8c:50:2b:c6:2c apfMsDeleteByMscb Scheduling mobile for deletion with deleteReason 15, reasonCode 1&lt;BR /&gt;f4:8c:50:2b:c6:2c Scheduling deletion of Mobile Station: (callerId: 30) in 1 seconds&lt;BR /&gt;f4:8c:50:2b:c6:2c Processing assoc-req station:f4:8c:50:2b:c6:2c AP:2c:5a:0f:3b:9d:20-01 thread:18d026e8&lt;BR /&gt;f4:8c:50:2b:c6:2c Processing assoc-req station:f4:8c:50:2b:c6:2c AP:2c:5a:0f:3b:9d:20-01 thread:18d026e8&lt;BR /&gt;f4:8c:50:2b:c6:2c Ignoring 802.11 assoc request from mobile pending deletion&lt;BR /&gt;f4:8c:50:2b:c6:2c Sending assoc-resp with status 12 station:f4:8c:50:2b:c6:2c AP:2c:5a:0f:3b:9d:20-01 on apVapId 1&lt;BR /&gt;f4:8c:50:2b:c6:2c Sending assoc-resp with status 12 station:f4:8c:50:2b:c6:2c AP:2c:5a:0f:3b:9d:20-01 on apVapId 1&lt;BR /&gt;f4:8c:50:2b:c6:2c VHT Operation IE: width 20/0 ch 161 freq0 0 freq1 0 msc0 0x3f msc1 0x3f&lt;BR /&gt;f4:8c:50:2b:c6:2c Sending Assoc Response to station on BSSID 2c:5a:0f:3b:9d:2f (status Assoc denied unspecified) ApVapId 1 Slot 1&lt;BR /&gt;f4:8c:50:2b:c6:2c apfMsExpireCallback (apf_ms.c:638) Expiring Mobile!&lt;BR /&gt;f4:8c:50:2b:c6:2c apfMsExpireMobileStation (apf_ms.c:7394) Changing state for mobile f4:8c:50:2b:c6:2c on AP 2c:5a:0f:3b:9d:20 from Associated to Disassociated&lt;BR /&gt;f4:8c:50:2b:c6:2c apfMsExpireMobileStation (apf_ms.c:7394) Changing state for mobile f4:8c:50:2b:c6:2c on AP 2c:5a:0f:3b:9d:20 from Associated to Disassociated&lt;BR /&gt;f4:8c:50:2b:c6:2c apfSendDisAssocMsgDebug (apf_80211.c:3459) Changing state for mobile f4:8c:50:2b:c6:2c on AP 2c:5a:0f:3b:9d:20 from Disassociated to Disassociated&lt;BR /&gt;f4:8c:50:2b:c6:2c apfSendDisAssocMsgDebug (apf_80211.c:3459) Changing state for mobile f4:8c:50:2b:c6:2c on AP 2c:5a:0f:3b:9d:20 from Disassociated to Disassociated&lt;BR /&gt;f4:8c:50:2b:c6:2c Sent Disassociate to mobile on AP 2c:5a:0f:3b:9d:20-1 (reason 1, caller apf_ms.c:7490)&lt;BR /&gt;f4:8c:50:2b:c6:2c Sent Deauthenticate to mobile on BSSID 2c:5a:0f:3b:9d:2f slot 1(caller apf_ms.c:7492)&lt;BR /&gt;f4:8c:50:2b:c6:2c Resetting MSCB PMK Cache Entry 0 for station f4:8c:50:2b:c6:2c&lt;BR /&gt;f4:8c:50:2b:c6:2c Resetting MSCB PMK Cache Entry 0 for station f4:8c:50:2b:c6:2c&lt;BR /&gt;f4:8c:50:2b:c6:2c Removing BSSID 2c:5a:0f:3b:9d:2f from PMKID cache of station f4:8c:50:2b:c6:2c&lt;BR /&gt;f4:8c:50:2b:c6:2c Removing BSSID 2c:5a:0f:3b:9d:2f from PMKID cache of station f4:8c:50:2b:c6:2c&lt;BR /&gt;&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The RADIUS-NAC is using Cisco ISE, but I don't have the detail about the version and configuration.&lt;/P&gt;
&lt;P&gt;Do you think the problem is in the Cisco ISE when user profiling? Or in WLC? Or client device?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any comments and answers are appreciated!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Arie&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 13:53:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/8021x-reqd-problem-in-wlc-5520-8-2-code/m-p/3048798#M38507</guid>
      <dc:creator>Arie --</dc:creator>
      <dc:date>2021-07-05T13:53:26Z</dc:date>
    </item>
    <item>
      <title>Which version of 8.2? There</title>
      <link>https://community.cisco.com/t5/wireless/8021x-reqd-problem-in-wlc-5520-8-2-code/m-p/3048799#M38508</link>
      <description>&lt;P&gt;Which version of 8.2? There were a LOT of issues fixed in the last three releases in combination with 3802 APs. Also if the client is containing an Intel Wi-Fi adapter which is 802.11ac capable, upgrade the driver to 19.40 or newer, as they also contain many bug fixes with 802.11ac Wave2 APs (like the 3802).&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 14:15:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/8021x-reqd-problem-in-wlc-5520-8-2-code/m-p/3048799#M38508</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2017-04-19T14:15:16Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/wireless/8021x-reqd-problem-in-wlc-5520-8-2-code/m-p/3048800#M38509</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;The version is&amp;nbsp;8.2.131.40 and backup version is&amp;nbsp;8.1.102.0.&lt;/P&gt;
&lt;P&gt;Yeah, I think the client adapter is Intel Wi-Fi adapter, since I looked at Cisco PI.&lt;/P&gt;
&lt;P&gt;Do you have the useful link that contain information of Intel driver to support 802.11ac W2 AP?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;Arie&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 02:58:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/8021x-reqd-problem-in-wlc-5520-8-2-code/m-p/3048800#M38509</guid>
      <dc:creator>Arie --</dc:creator>
      <dc:date>2017-04-20T02:58:12Z</dc:date>
    </item>
    <item>
      <title>It seems you run an interims</title>
      <link>https://community.cisco.com/t5/wireless/8021x-reqd-problem-in-wlc-5520-8-2-code/m-p/3048801#M38510</link>
      <description>&lt;P&gt;It seems you run an interims (Beta) version currently on the controller. Because of this, I suggest you to upgrade to 8.2.151.0 (unless the bug isn't fixed in 8.2.141.0 and 8.2.151.0, because of which you installed 8.2.131.40). Release notes:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/crn82mr5.html&lt;/P&gt;
&lt;P&gt;It does have various fixed for the x8xx AP series. Also your beta release might contain other bugs, introduced in the beta.&lt;/P&gt;
&lt;P&gt;You might find some information in the two following bugs: CSCvb26086 (for the 8260-AC) or CSCva52991 (for the 7265-AC). Both issues are fixed with a combination of 8.2.151.0 and Intel driver package 19.40 or newer.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 06:45:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/8021x-reqd-problem-in-wlc-5520-8-2-code/m-p/3048801#M38510</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2017-04-20T06:45:05Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/wireless/8021x-reqd-problem-in-wlc-5520-8-2-code/m-p/3048802#M38511</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Thank you for your information. Very helpful.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Arie&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2017 03:33:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/8021x-reqd-problem-in-wlc-5520-8-2-code/m-p/3048802#M38511</guid>
      <dc:creator>Arie --</dc:creator>
      <dc:date>2017-04-26T03:33:45Z</dc:date>
    </item>
  </channel>
</rss>

