cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2317
Views
0
Helpful
12
Replies

AP 1530 on 5ghz cannot associate

Marco Aresu
Level 1
Level 1

Hello all,

i have a problem on a bridge between two AP 1530.

Using dotradio0 interface with 2.4Ghz i can associate Non-root bridge with Root bridge while when i try to use Dotradio1 interface with 5Ghz i get the error message : %DOT11-4-CANT_ASSOC: Interface Dot11Radio0, cannot associate: No Response

Can someone help me?

thanks

Marco

12 Replies 12

mohanak
Cisco Employee
Cisco Employee
Error Message    DOT11-4-CANT_ASSOC: "Interface Dot11Radio 0, cannot associate."

Explanation    Parent does not support client MFP. This error message displays on the access point only in workgroup bridge, repeater, or non-root bridge mode and is seen if the WGB, repeater, or non-root is configured with Client MFP SD required (or mandatory) but root Client MFP is disabled.

Recommended Action    Check the configuration of the parent access point and this unit to make sure there is a match.

 

http://www.cisco.com/c/en/us/td/docs/wireless/access_point/12-4_3g_JA/configuration/guide/ios1243gjaconfigguide/s43err.html

IDS Client MFP is disabled on both sides and with 2.4 Ghz i don't have errors/problems.

Is it a feature to enable for 5Ghz?

 

Thanks

Marco

Freerk Terpstra
Level 7
Level 7

Are you still in the testing phase or is the hardware already currently deployed? Also could you share the configurations of both AP's?

BRIDGE_LANZONE29#sh run
Building configuration...

Current configuration : 8579 bytes
!
! Last configuration change at 16:20:56 +0100 Wed Oct 28 2015 by admin-net-ma
! NVRAM config last updated at 16:17:10 +0100 Wed Oct 28 2015
! NVRAM config last updated at 16:17:10 +0100 Wed Oct 28 2015
version 15.3
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname BRIDGE_LANZONE29
!
!
logging rate-limit console 9
enable secret 5 $1$WadC$bz77g8iN1By.bh3F7sUR01
!
aaa new-model
!
!
aaa authentication login default group radius local
aaa authorization exec default group radius if-authenticated
aaa authorization network default group radius
aaa authorization auth-proxy default group radius
aaa accounting exec default start-stop group radius
aaa accounting system default start-stop group radius
!
!
!
!
!
aaa session-id common
clock timezone +0100 1 0
no ip source-route
no ip cef
ip domain name unicatt.it
!
!
!
!
dot11 syslog
!
dot11 ssid VLAN1
vlan 1
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 154B04215C247C7711
!
dot11 ssid VLAN185
vlan 185
authentication open
authentication key-management wpa version 2
wpa-psk ascii 7 025F0B765308587275
!
dot11 ssid VLAN3
vlan 3
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 12400A3A4A055B5713
!
dot11 ssid VLAN39
vlan 39
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 005D1C2B5C555C5536
!
dot11 ssid VLAN47
vlan 47
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 035D54265E01761F77
!
dot11 ssid VLAN48
vlan 48
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 014A09290305515C18
!
dot11 ssid VLAN61
vlan 61
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 0402042B572F1B1D30
!
dot11 ssid VLAN63
vlan 63
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 144E1D26540A7D781D
!
dot11 ssid VLAN93
vlan 93
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 144E1D26540A7D781D
!
dot11 ssid bridge
authentication open
authentication key-management wpa version 2
wpa-psk ascii 7 123F573433595B257F0F730D6411064A234653
!
!
!
!
!
username CISCO password 7 096F471A1A0A
!
!
ip ssh version 2
!
class-map match-all _class_Voice_10
match ip precedence 1
!
policy-map Voice_1
class _class_Voice_10
set cos 6
!
bridge irb
!
!
!
interface Dot11Radio0
no ip address
no ip route-cache
!
encryption mode ciphers aes-ccm
!
encryption vlan 1 mode ciphers aes-ccm
!
encryption vlan 3 mode ciphers aes-ccm
!
encryption vlan 39 mode ciphers aes-ccm
!
encryption vlan 47 mode ciphers aes-ccm
!
encryption vlan 48 mode ciphers aes-ccm
!
encryption vlan 61 mode ciphers aes-ccm
!
encryption vlan 63 mode ciphers aes-ccm
!
encryption vlan 93 mode ciphers aes-ccm
!
encryption vlan 185 mode ciphers aes-ccm
!
ssid VLAN1
!
ssid VLAN185
!
ssid VLAN3
!
ssid VLAN39
!
ssid VLAN47
!
ssid VLAN48
!
ssid VLAN61
!
ssid VLAN63
!
ssid VLAN93
!
ssid bridge
!
antenna gain 0
packet retries 64 drop-packet
station-role root bridge
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
bridge-group 1 spanning-disabled
!
interface Dot11Radio0.3
encapsulation dot1Q 3
no ip route-cache
bridge-group 3
bridge-group 3 spanning-disabled
!
interface Dot11Radio0.39
encapsulation dot1Q 39
no ip route-cache
bridge-group 39
bridge-group 39 spanning-disabled
!
interface Dot11Radio0.47
encapsulation dot1Q 47
no ip route-cache
bridge-group 47
bridge-group 47 spanning-disabled
!
interface Dot11Radio0.48
encapsulation dot1Q 48
no ip route-cache
bridge-group 48
bridge-group 48 spanning-disabled
!
interface Dot11Radio0.61
encapsulation dot1Q 61
no ip route-cache
bridge-group 61
bridge-group 61 spanning-disabled
!
interface Dot11Radio0.63
encapsulation dot1Q 63
no ip route-cache
bridge-group 63
bridge-group 63 spanning-disabled
!
interface Dot11Radio0.93
encapsulation dot1Q 93
no ip route-cache
bridge-group 93
bridge-group 93 spanning-disabled
!
interface Dot11Radio0.185
encapsulation dot1Q 185
no ip route-cache
bridge-group 185
bridge-group 185 spanning-disabled
!
interface Dot11Radio1
no ip address
!
encryption vlan 1 mode ciphers aes-ccm
!
encryption vlan 185 mode ciphers aes-ccm
!
encryption vlan 3 mode ciphers aes-ccm
!
encryption vlan 39 mode ciphers aes-ccm
!
encryption vlan 47 mode ciphers aes-ccm
!
encryption vlan 48 mode ciphers aes-ccm
!
encryption vlan 61 mode ciphers aes-ccm
!
encryption vlan 63 mode ciphers aes-ccm
!
encryption vlan 93 mode ciphers aes-ccm
!
encryption mode ciphers aes-ccm
!
ssid VLAN1
!
ssid VLAN185
!
ssid VLAN3
!
ssid VLAN47
!
ssid VLAN48
!
ssid VLAN61
!
ssid VLAN63
!
ssid VLAN93
!
ssid bridge
!
antenna gain 0
peakdetect
no dfs band block
packet retries 64 drop-packet
channel dfs
station-role root bridge
!
interface Dot11Radio1.1
encapsulation dot1Q 1 native
bridge-group 1
bridge-group 1 spanning-disabled
!
interface Dot11Radio1.3
encapsulation dot1Q 3
bridge-group 3
bridge-group 3 spanning-disabled
!
interface Dot11Radio1.39
encapsulation dot1Q 39
bridge-group 39
bridge-group 39 spanning-disabled
!
interface Dot11Radio1.47
encapsulation dot1Q 47
bridge-group 47
bridge-group 47 spanning-disabled
!
interface Dot11Radio1.48
encapsulation dot1Q 48
bridge-group 48
bridge-group 48 spanning-disabled
!
interface Dot11Radio1.61
encapsulation dot1Q 61
bridge-group 61
bridge-group 61 spanning-disabled
!
interface Dot11Radio1.63
encapsulation dot1Q 63
bridge-group 63
bridge-group 63 spanning-disabled
!
interface Dot11Radio1.93
encapsulation dot1Q 93
bridge-group 93
bridge-group 93 spanning-disabled
!
interface Dot11Radio1.185
encapsulation dot1Q 185
bridge-group 185
bridge-group 185 spanning-disabled
!
interface GigabitEthernet0
no ip address
no ip route-cache
duplex auto
speed auto
!
interface GigabitEthernet0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
bridge-group 1 spanning-disabled
!
interface GigabitEthernet0.3
encapsulation dot1Q 3
no ip route-cache
bridge-group 3
bridge-group 3 spanning-disabled
service-policy input Voice_1
service-policy output Voice_1
!
interface GigabitEthernet0.39
encapsulation dot1Q 39
no ip route-cache
bridge-group 39
bridge-group 39 spanning-disabled
!
interface GigabitEthernet0.47
encapsulation dot1Q 47
no ip route-cache
bridge-group 47
bridge-group 47 spanning-disabled
!
interface GigabitEthernet0.48
encapsulation dot1Q 48
no ip route-cache
bridge-group 48
bridge-group 48 spanning-disabled
!
interface GigabitEthernet0.61
encapsulation dot1Q 61
no ip route-cache
bridge-group 61
bridge-group 61 spanning-disabled
!
interface GigabitEthernet0.63
encapsulation dot1Q 63
no ip route-cache
bridge-group 63
bridge-group 63 spanning-disabled
!
interface GigabitEthernet0.93
encapsulation dot1Q 93
no ip route-cache
bridge-group 93
bridge-group 93 spanning-disabled
!
interface GigabitEthernet0.185
encapsulation dot1Q 185
no ip route-cache
bridge-group 185
bridge-group 185 spanning-disabled
!
interface GigabitEthernet1
no ip address
duplex auto
speed auto
bridge-group 1
bridge-group 1 spanning-disabled
!
interface BVI1
mac-address 78da.6e60.7fcc
ip address 172.31.60.2 255.255.252.0
no ip route-cache
ipv6 address dhcp
ipv6 address autoconfig
ipv6 enable
!
ip forward-protocol nd
ip http server
no ip http secure-server
ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
!
!
snmp-server view dot11view ieee802dot11 included
snmp-server community public view dot11view RO
snmp-server community ZmbMctbdl! RO
snmp-server chassis-id BRIDGE-LANZONE32
snmp-server enable traps syslog
snmp-server host 172.31.63.197 ZmbMctbdl! syslog
!
radius server 172.31.63.240
address ipv4 172.31.63.240 auth-port 1812 acct-port 1813
key 7 13351601181B0B382F7479
!
access-list 1 permit 172.31.9.0 0.0.0.255
access-list 1 permit 172.31.60.0 0.0.3.255
bridge 1 route ip
!
!
!
line con 0
line vty 0 4
access-class 1 in
transport input ssh
transport output all
line vty 5 15
access-class 1 in
transport input ssh
transport output all
!
end

BRIDGE_LANZONE29#

------------------------------------------------------------------------------------------------------------------------

BRIDGE_LANZONE32#sh run
Building configuration...

Current configuration : 9627 bytes
!
! Last configuration change at 16:22:41 +0100 Wed Oct 28 2015
! NVRAM config last updated at 16:22:41 +0100 Wed Oct 28 2015
! NVRAM config last updated at 16:22:41 +0100 Wed Oct 28 2015
version 15.3
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname BRIDGE_LANZONE32
!
!
logging rate-limit console 9
enable secret 5 $1$cTi7$sIbYYeMJR2zegev13gSZc/
!
aaa new-model
!
!
aaa authentication login default group radius local
aaa authorization exec default group radius if-authenticated
aaa authorization network default group radius
aaa authorization auth-proxy default group radius
aaa accounting exec default start-stop group radius
aaa accounting system default start-stop group radius
!
!
!
!
!
aaa session-id common
clock timezone +0100 1 0
no ip source-route
no ip cef
ip domain name unicatt.it
!
!
!
!
dot11 syslog
!
dot11 ssid VLAN1
vlan 1
authentication open
authentication key-management wpa version 2
mbssid guest-mode
infrastructure-ssid
wpa-psk ascii 7 08784363511752442B
!
dot11 ssid VLAN185
vlan 185
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 07562E6116074E562E
!
dot11 ssid VLAN3
vlan 3
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 144E1D26540A7D781D
!
dot11 ssid VLAN39
vlan 39
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 08784363511752442B
!
dot11 ssid VLAN47
vlan 47
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 09154124410B404132
!
dot11 ssid VLAN48
vlan 48
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 025F0B765308587275
!
dot11 ssid VLAN61
vlan 61
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 005D1C2B5C555C5536
!
dot11 ssid VLAN63
vlan 63
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 154B04215C247C7711
!
dot11 ssid VLAN93
vlan 93
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 135C183F5302537912
!
dot11 ssid bridge
authentication open
authentication key-management wpa version 2
wpa-psk ascii 7 096A1C2A385740335E28530F7C000C6A117243
!
!
!
!
!
username UCSC privilege 15 secret 5 $1$1Bsk$/mPd1nq1MZcW4QR87RvgT.
username CISCO password 7 096F471A1A0A
!
!
ip ssh version 2
bridge irb
!
!
!
interface Dot11Radio0
no ip address
no ip route-cache
!
encryption mode ciphers aes-ccm
!
encryption vlan 1 mode ciphers aes-ccm
!
encryption vlan 3 mode ciphers aes-ccm
!
encryption vlan 39 mode ciphers aes-ccm
!
encryption vlan 47 mode ciphers aes-ccm
!
encryption vlan 48 mode ciphers aes-ccm
!
encryption vlan 61 mode ciphers aes-ccm
!
encryption vlan 63 mode ciphers aes-ccm
!
encryption vlan 93 mode ciphers aes-ccm
!
encryption vlan 185 mode ciphers aes-ccm
!
ssid VLAN1
!
ssid VLAN185
!
ssid VLAN3
!
ssid VLAN39
!
ssid VLAN47
!
ssid VLAN48
!
ssid VLAN61
!
ssid VLAN63
!
ssid VLAN93
!
ssid bridge
!
antenna gain 0
packet retries 64 drop-packet
station-role non-root bridge
mobile station scan 2412 2417 2422 2427 2432 2437 2442 2447 2452 2457 2462 2467 2472
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
bridge-group 1 spanning-disabled
!
interface Dot11Radio0.3
encapsulation dot1Q 3
no ip route-cache
bridge-group 3
bridge-group 3 spanning-disabled
!
interface Dot11Radio0.39
encapsulation dot1Q 39
no ip route-cache
bridge-group 39
bridge-group 39 spanning-disabled
!
interface Dot11Radio0.47
encapsulation dot1Q 47
no ip route-cache
bridge-group 47
bridge-group 47 spanning-disabled
!
interface Dot11Radio0.48
encapsulation dot1Q 48
no ip route-cache
bridge-group 48
bridge-group 48 spanning-disabled
!
interface Dot11Radio0.61
encapsulation dot1Q 61
no ip route-cache
bridge-group 61
bridge-group 61 spanning-disabled
!
interface Dot11Radio0.63
encapsulation dot1Q 63
no ip route-cache
bridge-group 63
bridge-group 63 spanning-disabled
!
interface Dot11Radio0.93
encapsulation dot1Q 93
no ip route-cache
bridge-group 93
bridge-group 93 spanning-disabled
!
interface Dot11Radio0.185
encapsulation dot1Q 185
no ip route-cache
bridge-group 185
bridge-group 185 spanning-disabled
!
interface Dot11Radio1
no ip address
shutdown
!
encryption vlan 1 mode ciphers aes-ccm
!
encryption vlan 185 mode ciphers aes-ccm
!
encryption vlan 3 mode ciphers aes-ccm
!
encryption vlan 39 mode ciphers aes-ccm
!
encryption vlan 47 mode ciphers aes-ccm
!
encryption vlan 48 mode ciphers aes-ccm
!
encryption vlan 61 mode ciphers aes-ccm
!
encryption vlan 93 mode ciphers aes-ccm
!
encryption mode ciphers aes-ccm
!
ssid VLAN1
!
ssid VLAN185
!
ssid VLAN3
!
ssid VLAN39
!
ssid VLAN47
!
ssid VLAN48
!
ssid VLAN61
!
ssid VLAN93
!
ssid bridge
!
antenna gain 0
peakdetect
no dfs band block
packet retries 64 drop-packet
channel dfs
station-role scanner
!
interface Dot11Radio1.1
encapsulation dot1Q 1 native
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
!
interface Dot11Radio1.3
encapsulation dot1Q 3
bridge-group 3
bridge-group 3 subscriber-loop-control
bridge-group 3 spanning-disabled
bridge-group 3 block-unknown-source
no bridge-group 3 source-learning
no bridge-group 3 unicast-flooding
!
interface Dot11Radio1.39
encapsulation dot1Q 39
bridge-group 39
bridge-group 39 subscriber-loop-control
bridge-group 39 spanning-disabled
bridge-group 39 block-unknown-source
no bridge-group 39 source-learning
no bridge-group 39 unicast-flooding
!
interface Dot11Radio1.47
encapsulation dot1Q 47
bridge-group 47
bridge-group 47 subscriber-loop-control
bridge-group 47 spanning-disabled
bridge-group 47 block-unknown-source
no bridge-group 47 source-learning
no bridge-group 47 unicast-flooding
!
interface Dot11Radio1.48
encapsulation dot1Q 48
bridge-group 48
bridge-group 48 subscriber-loop-control
bridge-group 48 spanning-disabled
bridge-group 48 block-unknown-source
no bridge-group 48 source-learning
no bridge-group 48 unicast-flooding
!
interface Dot11Radio1.61
encapsulation dot1Q 61
bridge-group 61
bridge-group 61 subscriber-loop-control
bridge-group 61 spanning-disabled
bridge-group 61 block-unknown-source
no bridge-group 61 source-learning
no bridge-group 61 unicast-flooding
!
interface Dot11Radio1.93
encapsulation dot1Q 93
bridge-group 93
bridge-group 93 subscriber-loop-control
bridge-group 93 spanning-disabled
bridge-group 93 block-unknown-source
no bridge-group 93 source-learning
no bridge-group 93 unicast-flooding
!
interface Dot11Radio1.185
encapsulation dot1Q 185
bridge-group 185
bridge-group 185 subscriber-loop-control
bridge-group 185 spanning-disabled
bridge-group 185 block-unknown-source
no bridge-group 185 source-learning
no bridge-group 185 unicast-flooding
!
interface GigabitEthernet0
no ip address
no ip route-cache
duplex auto
speed auto
!
interface GigabitEthernet0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
bridge-group 1 spanning-disabled
!
interface GigabitEthernet0.3
encapsulation dot1Q 3
no ip route-cache
bridge-group 3
bridge-group 3 spanning-disabled
!
interface GigabitEthernet0.39
encapsulation dot1Q 39
no ip route-cache
bridge-group 39
bridge-group 39 spanning-disabled
!
interface GigabitEthernet0.47
encapsulation dot1Q 47
no ip route-cache
bridge-group 47
bridge-group 47 spanning-disabled
!
interface GigabitEthernet0.48
encapsulation dot1Q 48
no ip route-cache
bridge-group 48
bridge-group 48 spanning-disabled
!
interface GigabitEthernet0.61
encapsulation dot1Q 61
no ip route-cache
bridge-group 61
bridge-group 61 spanning-disabled
!
interface GigabitEthernet0.63
encapsulation dot1Q 63
no ip route-cache
bridge-group 63
bridge-group 63 spanning-disabled
!
interface GigabitEthernet0.93
encapsulation dot1Q 93
no ip route-cache
bridge-group 93
bridge-group 93 spanning-disabled
!
interface GigabitEthernet0.185
encapsulation dot1Q 185
no ip route-cache
bridge-group 185
bridge-group 185 spanning-disabled
!
interface GigabitEthernet1
no ip address
duplex auto
speed auto
bridge-group 1
bridge-group 1 spanning-disabled
!
interface BVI1
mac-address 78da.6e60.8000
ip address 172.31.60.3 255.255.252.0
no ip route-cache
ipv6 address dhcp
ipv6 address autoconfig
ipv6 enable
!
ip forward-protocol nd
ip http server
no ip http secure-server
ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
!
!
snmp-server view dot11view ieee802dot11 included
snmp-server community public view dot11view RO
snmp-server community ZmbMctbdl! RO
snmp-server chassis-id BRIDGE-LANZONE29
snmp-server enable traps syslog
snmp-server host 172.31.63.197 ZmbMctbdl! syslog
radius-server host 172.31.63.240 auth-port 1812 acct-port 1813 key 7 13351601181B0B382F7479
!
access-list 1 permit 172.31.9.0 0.0.0.255
access-list 1 permit 172.31.60.0 0.0.3.255
bridge 1 route ip
!
!
!
line con 0
line vty 0 4
access-class 1 in
transport input ssh
transport output all
line vty 5 15
access-class 1 in
transport input ssh
transport output all
!
end

BRIDGE_LANZONE32#

Hi,

You need to use this command under int dot11radio1 on bridge:

interface Dot11Radio1
station-role non-root bridge

Regards

Dontf orget to rate helpful posts

Hello Sandeep,

cannot use "non-root bridge" command on both interfaces.

Only one radio interface can be "non-root".

Thanks

Marco

then remove from interface Dot11Radio0 and try to use this command on dot11radio1 interface to connect root to non root bridge via 5 Ghz.

Regards

Dont forget to rate helpful posts

here is the problem, i am receiving error message :

%DOT11-4-CANT_ASSOC: Interface Dot11Radio0, cannot associate: No Response

thanks

Marco

Must check remotely via team-viewer(if you only need then sent PM)

Regards

Thanks Sandeep. Are you able for a team-viewer session on next monday? Same hour.

Scott Fella
Hall of Fame
Hall of Fame

If you don't have then up in production, you should be able to bring pu the link on both.  Now if they are up and you only can associate on the 2.4ghz, maybe the range between the two bridges are too far to actually negotiate properly.

-Scott

-Scott
*** Please rate helpful posts ***

Hello Scott,

the range between two APs is 7 meters, is not too far.

thanks

Marco

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card