The "MFP Anomaly Detected" error message appears on the WLC
In a Management Frame Protection (MFP) configuration, the wireless LAN controllers (WLCs) use the Network Time Protocol (NTP), and the mobility group is configured. If one controller reloads, after it returns and the access points (APs) join, the other controllers in the mobility group start to generate MFP anomaly traps every five minutes. The traps point to the 11a radios of the AP in the reloaded controller. This problem is only generated by these APs:
The exact error message can read:
day month date time year MFP Anomaly Detected - 1 Invalid MIC event(s) found as violated by the radio 00:XX:XX:XX:XX and detected by the dot11 interface at slot 0 of AP 00:XX:XX:XX:XX in 300 seconds when observing Probe responses
Description AP12x0, 1130: corrupt IE 235 when broadcast SSID is disabled - CSCsg50343
Symptom: LWAPP IOS Access points may send management frames with a bogus IE 235, 166 bytes in length.
This may generate MFP alerts on the other controllers for the mobility group
Conditions: LWAPP IOS APs, controlled by a WLC running 4.0.179.*.
This is fixed in 126.96.36.199.
Known Fixed Releases:
MFP anomaly detected for 11a radios of reloaded controller in group - CSCse80121
In a MFP configuration: controllers have NTP working, mobility group is configured.
If one controller is reloaded, after it comes back and the APs join, the other controllers in the mobility group will start generating MFP anomaly traps each five minutes
The traps point to the 11a radios of the AP in the reloaded controller. It was observed in the lab, that only 12XX/1130 APs generated this problem
Example of messages:
3 Mon Jul 17 15:23:28 2006 MFP Anomaly Detected - 3023 Invalid MIC event(s) found as violated by the radio 00:XX:XX:XX:XX and detected by the dot11 interface at slot 0 of AP 00:XX:XX:XX:XX in 300 seconds when observing Probe responses, Beacon Frames
-MFP is enabled
-One controller in a mobility group is reloaded
-Reload all controllers
CSCse80121 has been superseded by CSCse56537 displayed below.
MFP errors when AP reverts to primary controller - CSCse56537
MFP errors when AP reverts to primary controller.
None but this appears cosmetic.
Hello, I have a network with 350 Cisco 1810W access points that are connected to Cisco 3650 PoE switches. I have noticed that the APs are drawing almost the full 30W per port. I believe these APs should only be drawing 8 to ...
Hello all masters of Cisco, I have a Cisco Access point 1852i. I tried to upgrade it on several different ways, via HTTP, via CLI, even via Cisco.com. But I wasn't successful. On HTTP I got a message "Transfer failed". In CLI via TFTP nothing happene...
Hello!We have WLC 2504(airos 8.5.130 ) with mix of AP1832 and AP1702I. Clients report sometimes slow performance and lags.I start test today - sit in direct AP vision and start ping controller and gw. I see same issue. Delay jump from 2ms to 80 -150...
Hello, I am in a situation where I need to rename a huge number of APs which wouldn't be feasible from the GUI. I spent a lot of time trying and searching for a how-to but to no avail!The commands listed under 'ap' don't include a rename! Is the...
I work for an MSP and also do sales into some enterprise clients, I have a client with 4x 3602 APs and another 17x 3702 APs ready to be installed.A colleague of his told him he needs a wireless controller now, he wants to know if that is a requirement, or...