cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9065
Views
6
Helpful
6
Comments
jegan_rajappa
Level 1
Level 1

Hi, I am seeing below error message in 9800 WLAN controller for few clients, DNA Center says group key update timeout.

APs are 3802's, any advise would be much appreciated. 


2020/08/13 10:16:49.912058 {wncd_x_R0-0}{1}: [client-keymgmt] [17829]: (ERR): MAC: 7470.fd48.9879  Keymgmt: Failed to eapol key m5 retrasmit failure. Max retries for M5 over

 


 

Capture.PNG

6 Comments
robertbrink1
Level 1
Level 1

I've also seen this on my DNA-C for a WPA2-PSK network..reason to worry?

h36395andy
Level 1
Level 1

I am seeing this on our DNAC assurance as well. We have some battery operated devices that are losing connectivity at 2 of 3 sites where we have 9800/4800 deployed. The 3rd site also has the same devices but they are not having any issues and I am NOT seeing the timeout in DNAC for the 3rd site.

 

Here is an excerpt for a device having issues;

 

DNAC-bad.png

 

 

 

 

 

Here is the same type of device at the working site;

 

DNAC-good.png

 

 

 

 

 

 

 

 

 

 

O_H
Level 1
Level 1

Have you found the reason for this?

xzatech123
Level 1
Level 1

I am also seeing this and would to know if anyone has come to an understandable conclusion as to what could be causing this.

Rich R
VIP
VIP

@xzatech123 those previous posts are quite old now.  9800 was quite new then and there have been many new software releases since then with hundreds of bug fixes.  Also this is a blog space so not really suited to problem questions - you should think about posting to https://community.cisco.com/t5/wireless/bd-p/discussions-wireless instead.  If you do, then make sure you state: WLC model, software version, AP model(s), WLAN configuration, full details of any logs, debugs and troubleshooting, packet captures you've already done.  It's also a good idea to make sure your software is up to date because you might be hitting a bug which has already been fixed (see TAC recommended link below) and that you've been through the best practice guide.  And check your config with the config analyser https://cway.cisco.com/wireless-config-analyzer/ using the output of "show tech wireless" (not regular show tech) and run your debugs through https://cway.cisco.com/wireless-debug-analyzer/

___________________________________________
TAC recommended codes for AireOS WLC's
Best Practices for AireOS WLC's
TAC recommended codes for 9800 WLC's
Best Practices for 9800 WLC's
Cisco Wireless compatibility matrix
Field Notice: FN72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Recommended
WARNING - see CSCwd37092 Throughput degraded after upgrading to code 8.10.181.0/17.3.6 - 2800/3800/4800 series
- The fix for CSCwd37092 is now released in 8.10.181.3 AireOS 8.10MR8 Escalation Special and
- For IOS-XE 17.3.6 select controller model, go to IOS XE Software AP Service Pack, select CSCwd40096 17.3.6 APSP2
Field Notice: FN63942 Lightweight APs and WLCs Fail to Create CAPWAP Connections Due to Certificate
                     Expiration - Software Upgrade Recommended
___________________________________________

JPavonM
VIP
VIP

The default timeout and maximum retries for EAP identity requests are set to address the majority of use cases, but due to strange disconnection issues I observed with some Mediatek based laptops been reported as group-key timeout, I increased the Group Key timeout to a value where devices won't have to renegotiate it during business hours.

This solved the issue, in reality the isue was still there but only affecting laptops which were left behind at the office. Then after the new driver version was released for the Mediatek ones, I asked IT to perform the upgrade and the issue disappeared completely. This is the command to modify it:
wireless security dot1x group-key interval 54000

NOTE: I would recommend to set all timeouts for SSIDs providing access to laptops to the same 54k value to be consistent, but never use value=0 to disable it.

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

French webcast-routing