We have run into issues where only few clients cannot associate to our corporate SSID. Debug synopsis below
|Aug 08 11:55:18.039||*apfMsConnTask_3||Client made new Association to AP/BSSID BSSID a0:23:9f:fa:d5:62 AP NZCHC5NET55|
|Aug 08 11:55:18.041||*apfMsConnTask_3||The WLC/AP has found from client association request Information Element that claims PMKID Caching support|
|Aug 08 11:55:18.042||*apfMsConnTask_3||Client is entering the 802.1x or PSK Authentication state|
|Aug 08 11:55:18.042||*apfMsConnTask_3||Client expiration timer code set for 65335 seconds. The reason: Client deleted due to session timeout (wlan with webauth)|
|Aug 08 11:55:18.042||*apfMsConnTask_3||
WLC/AP is sending an Association Response to the client with status code 0 = Successful association
This is with Cisco 5508 controller running a non-broadcast SSID. The software version is 188.8.131.52 and AP is 3500 at a flex connect site. EAP timers are set to 3 seconds for association. Screenshot attached.
Any ideas what can be done? Approach TAC?
It appears to be a webauth SSID. Can you verify the client types which are facing this issue ? Are they Intel 8500 series ? Are you using CWA with ISE ?
If the same client is working fne for open SSID but not for this Webauth SSID , we probably need to troubleshoot it step by step. Like .. 802.11 association (plus MAC auth) >> DHCP IP assigment >> web portal page >> credential verification ..