cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
671
Views
0
Helpful
0
Replies
Beginner

vWLC and ISE. vWLC service interface down.

Hello, randomly i can't access my vWLC by WebUI and also all clients on Dot.1x losing connection and can't re-authenticate. Non dot1x clients staying with network. This problem appears with low and high utilization in network at any time. I can access my vWLC by ssh on management port when service port down. 

I have couple of errors from syslog: Message: *Dot1x_NW_MsgTask_0: Feb 28 10:41:18.230: %DOT1X-3-INVALID_REPLAY_CTR: 1x_eapkey.c:451 Invalid replay counter from client xx:xx:xx:xx:xx - got 00 00 00 00 00 00 00 03, expected 00 00 00 00 00 00 00 04

Message: *Dot1x_NW_MsgTask_1: Feb 28 10:40:13.929: %DOT1X-3-ABORT_AUTH: 1x_bauth_sm.c:477 Authentication Aborted for client xx:xx:xx:xx:xx Abort Reason:DOT1X RESTARTED DUE TO EAPOL-START/CLIENT ROAM

Message: *spamApTask4: Feb 28 10:36:20.554: %LWAPP-3-REPLAY_ERR: spam_lrad.c:42155 The system has received replay error on slot 0, WLAN ID 1, count 1 from AP xx:xx:xx:xx:xx

Right now i don't have syslog from end to end when disconnects happens. I'm trying to collect it. 

I can't find reason why service port going down. I did not configure this system so i think maybe is there issue between Cisco ISE and vWLC, where ISE somehow disables interface on vWLC?. SNMP not enabled.

When i google this i found that when somebody writes sh port summary there's at least 2 interfaces showing. I have only one 
:  STP Admin Physical Physical Link Link
Pr Type Stat Mode Mode Status Status Trap POE
-- ------- ---- ------- ---------- ---------- ------ ------- ---------
1 Normal Forw Enable Auto 1000 Full Up Enable N/A

Another question: In ISE wlc configured with Service port is it right or need to be management?

Configuration
vWLC 8.3.112.0
ISE 2.2.0.470
16 AP

Sorry for errors in text. I will be glad to any answer.

Everyone's tags (3)
CreatePlease to create content
Content for Community-Ad