cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
628
Views
0
Helpful
2
Replies

2504 WLC users get Can't connect to this network

mithun_raam
Level 1
Level 1

Hi All

When connect to SSID, users intermittently gets "Can't connect to this network". Opened a case with TAC and was advised to change EAP timers.But the issue is still happening. Can you have a look and advise based on debug logs?

Thanks in advanse.

------------------------------------------------

(IMA-RADIOCONT-1) >*apfOpenDtlSocket: Sep 27 08:23:29.202: 84:14:4d:2c:0a:1f Recevied management frame ASSOCIATION REQUEST on BSSID dc:ce:c1:c8:a7:4f destination addr dc:ce:c1:c8:a7:4f
*apfMsConnTask_4: Sep 27 08:23:29.211: 84:14:4d:2c:0a:1f Processing assoc-req station:84:14:4d:2c:0a:1f AP:dc:ce:c1:c8:a7:40-01 ssid : IMA-WLAN thread:1a93a470
*apfMsConnTask_4: Sep 27 08:23:29.211: 84:14:4d:2c:0a:1f Created Acct-Session-ID (6332b301/84:14:4d:2c:0a:1f/226349) for the mobile
*apfMsConnTask_4: Sep 27 08:23:29.211: 84:14:4d:2c:0a:1f Adding mobile on LWAPP AP dc:ce:c1:c8:a7:40(1)
*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f Association received from mobile on BSSID dc:ce:c1:c8:a7:4f AP IMA-Radio-04
*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f Station: 84:14:4D:2C:0A:1F 11v BSS Transition not enabled on the AP DC:CE:C1:C8:A7:40
*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f Global 200 Clients are allowed to AP radio

*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f Max Client Trap Threshold: 0 cur: 4

*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f Rf profile 600 Clients are allowed to AP wlan

*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f override for default ap group, marking intgrp NULL
*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f Applying Interface(management) policy on Mobile, role Unassociated. Ms NAC State 0 Quarantine Vlan 0 Access Vlan 0

*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f Not re-applying interface policy for local switching Client

*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f 0.0.0.0 START (0) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2922)
*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f 0.0.0.0 START (0) Changing Url ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2942)
*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f 0.0.0.0 START (0) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2963)
*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f apfApplyWlanPolicy: Apply WLAN Policy over PMIPv6 Client Mobility Type, Tunnel User - 0
*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f In processSsidIE:6609 setting Central switched to FALSE
*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f Set Clinet MSCB as Central Association Disabled
*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f Applying site-specific Local Bridging override for station 84:14:4d:2c:0a:1f - vapId 1, site 'AP-Group-OA', interface 'management'
*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f Applying Local Bridging Interface Policy for station 84:14:4d:2c:0a:1f - vlan 0, interface id 0, interface 'management'
*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f override from ap group, removing intf group from mscb
*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f Applying site-specific override for station 84:14:4d:2c:0a:1f - vapId 1, site 'AP-Group-OA', interface 'management'
*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f Applying Interface(management) policy on Mobile, role Unassociated. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 0

*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f Not re-applying interface policy for local switching Client

*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f 0.0.0.0 START (0) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2922)
*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f 0.0.0.0 START (0) Changing Url ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2942)
*apfMsConnTask_4: Sep 27 08:23:29.212: 84:14:4d:2c:0a:1f 0.0.0.0 START (0) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2963)
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f Setting the NAS Id to AP group specific Id 'IMA-RADIOCONT-2'
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f Set Clinet Non AP specific WLAN apfMsAccessVlan = 13
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f This apfMsAccessVlan may be changed later from AAA after L2 Auth
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f Cleared localSwitchingVlan, may be assigned later based on AAA override
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f processSsidIE statusCode is 0 and status is 0
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f processSsidIE ssid_done_flag is 0 finish_flag is 0
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f STA - rates (8): 140 18 152 36 176 72 96 108 0 0 0 0 0 0 0 0
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f suppRates statusCode is 0 and gotSuppRatesElement is 1
*apfMsConnTask_4: Sep 27 08:23:29.213: RSNIE in Assoc. Req.: (22)

*apfMsConnTask_4: Sep 27 08:23:29.213: [0000] 01 00 00 0f ac 04 01 00 00 0f ac 04 01 00 00 0f

*apfMsConnTask_4: Sep 27 08:23:29.213: [0016] ac 01 3c 00 00 00

*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f Processing RSN IE type 48, length 22 for mobile 84:14:4d:2c:0a:1f
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f Selected Unicast cipher CCMP128 for client device
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f Received 802.11i 802.1X key management suite, enabling dot1x Authentication
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f RSN Capabilities: 60
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f Marking Mobile as non-11w Capable
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f Received RSN IE with 0 PMKIDs from mobile 84:14:4d:2c:0a:1f
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f Setting active key cache index 8 ---> 8
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f unsetting PmkIdValidatedByAp
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f Updating AID for REAP AP Client dc:ce:c1:c8:a7:40 - AID ===> 1
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f 0.0.0.0 START (0) Initializing policy
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f 0.0.0.0 START (0) Change state to AUTHCHECK (2) last state START (0)

*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f apfVapSecurity=0x4000 L2=16384 SkipWeb=0
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f AuthenticationRequired = 1
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f 0.0.0.0 AUTHCHECK (2) Change state to 8021X_REQD (3) last state AUTHCHECK (2)

*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f Encryption policy is set to 0x80000001
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f 0.0.0.0 8021X_REQD (3) DHCP required on AP dc:ce:c1:c8:a7:40 vapId 1 apVapId 1for this client
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f Not Using WMM Compliance code qosCap 00
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f Vlan while overriding the policy = -1
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f sending to spamAddMobile vlanId -1 flex aclName = , flexAclId 65535

*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f 0.0.0.0 8021X_REQD (3) Plumbed mobile LWAPP rule on AP dc:ce:c1:c8:a7:40 vapId 1 apVapId 1 flex-acl-name:
*apfMsConnTask_4: Sep 27 08:23:29.213: 84:14:4d:2c:0a:1f apfMsAssoStateInc
*apfMsConnTask_4: Sep 27 08:23:29.214: 84:14:4d:2c:0a:1f apfPemAddUser2 (apf_policy.c:416) Changing state for mobile 84:14:4d:2c:0a:1f on AP dc:ce:c1:c8:a7:40 from Idle to Associated

*apfMsConnTask_4: Sep 27 08:23:29.214: 84:14:4d:2c:0a:1f apfPemAddUser2:session timeout forstation 84:14:4d:2c:0a:1f - Session Tout 0, apfMsTimeOut '0' and sessionTimerRunning flag is 0
*apfMsConnTask_4: Sep 27 08:23:29.214: 84:14:4d:2c:0a:1f Stopping deletion of Mobile Station: (callerId: 48)
*apfMsConnTask_4: Sep 27 08:23:29.214: 84:14:4d:2c:0a:1f Func: apfPemAddUser2, Ms Timeout = 0, Session Timeout = 0

*apfMsConnTask_4: Sep 27 08:23:29.214: 84:14:4d:2c:0a:1f Sending assoc-resp with status 0 station:84:14:4d:2c:0a:1f AP:dc:ce:c1:c8:a7:40-01 on apVapId 1
*apfMsConnTask_4: Sep 27 08:23:29.214: 84:14:4d:2c:0a:1f Sending Assoc Response (status: '0') to station on AP IMA-Radio-04 on BSSID dc:ce:c1:c8:a7:4f ApVapId 1 Slot 1, mobility role 0
*apfMsConnTask_4: Sep 27 08:23:29.214: 84:14:4d:2c:0a:1f apfProcessAssocReq (apf_80211.c:11039) Changing state for mobile 84:14:4d:2c:0a:1f on AP dc:ce:c1:c8:a7:40 from Associated to Associated

*spamApTask0: Sep 27 08:23:29.214: 84:14:4d:2c:0a:1f Successful transmission of LWAPP Add-Mobile to AP dc:ce:c1:c8:a7:40
*spamApTask0: Sep 27 08:23:29.238: 84:14:4d:2c:0a:1f Received ADD_MOBILE ack - Initiating 1x to STA 84:14:4d:2c:0a:1f (idx 86)
*spamApTask0: Sep 27 08:23:29.238: 84:14:4d:2c:0a:1f Sent dot1x auth initiate message for mobile 84:14:4d:2c:0a:1f
*Dot1x_NW_MsgTask_7: Sep 27 08:23:29.241: 84:14:4d:2c:0a:1f reauth_sm state transition 0 ---> 1 for mobile 84:14:4d:2c:0a:1f at 1x_reauth_sm.c:47
*Dot1x_NW_MsgTask_7: Sep 27 08:23:29.242: 84:14:4d:2c:0a:1f EAP-PARAM Debug - eap-params for Wlan-Id :1 is disabled - applying Global eap timers and retries
*Dot1x_NW_MsgTask_7: Sep 27 08:23:29.242: 84:14:4d:2c:0a:1f Disable re-auth, use PMK lifetime.
*Dot1x_NW_MsgTask_7: Sep 27 08:23:29.242: 84:14:4d:2c:0a:1f Station 84:14:4d:2c:0a:1f setting dot1x reauth timeout = 0
*Dot1x_NW_MsgTask_7: Sep 27 08:23:29.242: 84:14:4d:2c:0a:1f Stopping reauth timeout for 84:14:4d:2c:0a:1f
*Dot1x_NW_MsgTask_7: Sep 27 08:23:29.242: 84:14:4d:2c:0a:1f dot1x - moving mobile 84:14:4d:2c:0a:1f into Connecting state
*Dot1x_NW_MsgTask_7: Sep 27 08:23:29.242: 84:14:4d:2c:0a:1f Sending EAP-Request/Identity to mobile 84:14:4d:2c:0a:1f (EAP Id 1)
*apfOpenDtlSocket: Sep 27 08:23:45.622: 84:14:4d:2c:0a:1f Recevied management frame ASSOCIATION REQUEST on BSSID dc:ce:c1:c8:a7:4f destination addr dc:ce:c1:c8:a7:4f
*apfMsConnTask_4: Sep 27 08:23:45.622: 84:14:4d:2c:0a:1f Processing assoc-req station:84:14:4d:2c:0a:1f AP:dc:ce:c1:c8:a7:40-01 ssid : IMA-WLAN thread:1a93a470
*apfMsConnTask_4: Sep 27 08:23:45.622: 84:14:4d:2c:0a:1f Station: 84:14:4D:2C:0A:1F 11v BSS Transition not enabled on the AP DC:CE:C1:C8:A7:40
*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f Association received from mobile on BSSID dc:ce:c1:c8:a7:4f AP IMA-Radio-04
*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f Station: 84:14:4D:2C:0A:1F 11v BSS Transition not enabled on the AP DC:CE:C1:C8:A7:40
*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f Global 200 Clients are allowed to AP radio

*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f Max Client Trap Threshold: 0 cur: 5

*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f Rf profile 600 Clients are allowed to AP wlan

*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f override for default ap group, marking intgrp NULL
*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f apfApplyWlanPolicy: Apply WLAN Policy over PMIPv6 Client Mobility Type, Tunnel User - 0
*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f In processSsidIE:6609 setting Central switched to FALSE
*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f Set Clinet MSCB as Central Association Disabled
*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f Applying site-specific Local Bridging override for station 84:14:4d:2c:0a:1f - vapId 1, site 'AP-Group-OA', interface 'management'
*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f Applying Local Bridging Interface Policy for station 84:14:4d:2c:0a:1f - vlan 0, interface id 0, interface 'management'
*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f override from ap group, removing intf group from mscb
*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f Applying site-specific override for station 84:14:4d:2c:0a:1f - vapId 1, site 'AP-Group-OA', interface 'management'
*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f Applying Interface(management) policy on Mobile, role Unassociated. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 13

*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f Not re-applying interface policy for local switching Client

*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f 0.0.0.0 8021X_REQD (3) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2922)
*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f 0.0.0.0 8021X_REQD (3) Changing Url ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2942)
*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f 0.0.0.0 8021X_REQD (3) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2963)
*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f Setting the NAS Id to AP group specific Id 'IMA-RADIOCONT-2'
*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f Set Clinet Non AP specific WLAN apfMsAccessVlan = 13
*apfMsConnTask_4: Sep 27 08:23:45.623: 84:14:4d:2c:0a:1f This apfMsAccessVlan may be changed later from AAA after L2 Auth
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f Cleared localSwitchingVlan, may be assigned later based on AAA override
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f processSsidIE statusCode is 0 and status is 0
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f processSsidIE ssid_done_flag is 0 finish_flag is 0
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f STA - rates (8): 140 18 152 36 176 72 96 108 0 0 0 0 0 0 0 0
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f suppRates statusCode is 0 and gotSuppRatesElement is 1
*apfMsConnTask_4: Sep 27 08:23:45.624: RSNIE in Assoc. Req.: (22)

*apfMsConnTask_4: Sep 27 08:23:45.624: [0000] 01 00 00 0f ac 04 01 00 00 0f ac 04 01 00 00 0f

*apfMsConnTask_4: Sep 27 08:23:45.624: [0016] ac 01 3c 00 00 00

*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f Processing RSN IE type 48, length 22 for mobile 84:14:4d:2c:0a:1f
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f Selected Unicast cipher CCMP128 for client device
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f Received 802.11i 802.1X key management suite, enabling dot1x Authentication
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f RSN Capabilities: 60
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f Marking Mobile as non-11w Capable
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f Received RSN IE with 0 PMKIDs from mobile 84:14:4d:2c:0a:1f
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f Setting active key cache index 8 ---> 8
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f unsetting PmkIdValidatedByAp
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f AID 1 in Assoc Req from flex AP dc:ce:c1:c8:a7:40 is same as in mscb 84:14:4d:2c:0a:1f
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f 0.0.0.0 8021X_REQD (3) Initializing policy
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f 0.0.0.0 8021X_REQD (3) Change state to AUTHCHECK (2) last state 8021X_REQD (3)

*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f apfVapSecurity=0x4000 L2=16384 SkipWeb=0
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f AuthenticationRequired = 1
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f 0.0.0.0 AUTHCHECK (2) Change state to 8021X_REQD (3) last state AUTHCHECK (2)

*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f Encryption policy is set to 0x80000001
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f 0.0.0.0 8021X_REQD (3) DHCP required on AP dc:ce:c1:c8:a7:40 vapId 1 apVapId 1for this client
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f Not Using WMM Compliance code qosCap 00
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f Vlan while overriding the policy = -1
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f sending to spamAddMobile vlanId -1 flex aclName = , flexAclId 65535

*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f 0.0.0.0 8021X_REQD (3) Plumbed mobile LWAPP rule on AP dc:ce:c1:c8:a7:40 vapId 1 apVapId 1 flex-acl-name:
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f apfPemAddUser2 (apf_policy.c:416) Changing state for mobile 84:14:4d:2c:0a:1f on AP dc:ce:c1:c8:a7:40 from Associated to Associated

*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f apfPemAddUser2:session timeout forstation 84:14:4d:2c:0a:1f - Session Tout 0, apfMsTimeOut '0' and sessionTimerRunning flag is 0
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f Stopping deletion of Mobile Station: (callerId: 48)
*apfMsConnTask_4: Sep 27 08:23:45.624: 84:14:4d:2c:0a:1f Func: apfPemAddUser2, Ms Timeout = 0, Session Timeout = 0

*apfMsConnTask_4: Sep 27 08:23:45.625: 84:14:4d:2c:0a:1f Sending assoc-resp with status 0 station:84:14:4d:2c:0a:1f AP:dc:ce:c1:c8:a7:40-01 on apVapId 1
*apfMsConnTask_4: Sep 27 08:23:45.625: 84:14:4d:2c:0a:1f Sending Assoc Response (status: '0') to station on AP IMA-Radio-04 on BSSID dc:ce:c1:c8:a7:4f ApVapId 1 Slot 1, mobility role 0
*apfMsConnTask_4: Sep 27 08:23:45.625: 84:14:4d:2c:0a:1f apfProcessAssocReq (apf_80211.c:11039) Changing state for mobile 84:14:4d:2c:0a:1f on AP dc:ce:c1:c8:a7:40 from Associated to Associated

*spamApTask0: Sep 27 08:23:45.625: 84:14:4d:2c:0a:1f Successful transmission of LWAPP Add-Mobile to AP dc:ce:c1:c8:a7:40
*spamApTask0: Sep 27 08:23:45.645: 84:14:4d:2c:0a:1f Received ADD_MOBILE ack - Initiating 1x to STA 84:14:4d:2c:0a:1f (idx 88)
*spamApTask0: Sep 27 08:23:45.645: 84:14:4d:2c:0a:1f Sent dot1x auth initiate message for mobile 84:14:4d:2c:0a:1f
*Dot1x_NW_MsgTask_7: Sep 27 08:23:45.645: 84:14:4d:2c:0a:1f reauth_sm state transition 1 ---> 0 for mobile 84:14:4d:2c:0a:1f at 1x_reauth_sm.c:53
*Dot1x_NW_MsgTask_7: Sep 27 08:23:45.645: 84:14:4d:2c:0a:1f EAP-PARAM Debug - eap-params for Wlan-Id :1 is disabled - applying Global eap timers and retries
*Dot1x_NW_MsgTask_7: Sep 27 08:23:45.645: 84:14:4d:2c:0a:1f Disable re-auth, use PMK lifetime.
*Dot1x_NW_MsgTask_7: Sep 27 08:23:45.645: 84:14:4d:2c:0a:1f dot1x - moving mobile 84:14:4d:2c:0a:1f into Connecting state

(IMA-RADIOCONT-1) >

------------------------------------------

2 Replies 2

marce1000
VIP
VIP

 

 - Below you will find output of your debug file from : https://cway.cisco.com/wireless-debug-analyzer/ , you can do that with other client debugs too (Show all flag was checked in this case). Further on you are not saying much about the wireless environment such as controller model  and software version , look into : https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html and apply , if applicable. For client , use latest version of wireless driver(s).  You may also try to disable fast roaming on the particular Wlan :

                 Note that  the various connection attempts 

TimeTaskTranslated

Connection attempt #1
Sep 27 08:23:29.212 *apfMsConnTask_4 Client made new Association to AP/BSSID BSSID dc:apfMsConnTask_4: Sep 27 08:23:29.211: 84:14:4d:2c:0a:1f Processing assoc-req station:84:14:4d:2c:0a:1f AP:dc:ce:c1:c8:a7:40-01 ssid : IMA-WLAN thread:1a93a470
Connection attempt #2
Sep 27 08:23:29.212 *apfMsConnTask_4 Client made new Association to AP/BSSID BSSID dc:ce:c1:c8:a7:4f AP IMA-Radio-04
Sep 27 08:23:29.213 *apfMsConnTask_4 The WLC/AP has found from client association request Information Element that claims PMKID Caching support
Sep 27 08:23:29.213 *apfMsConnTask_4 The Reassociation Request from the client comes with 0 PMKID
Sep 27 08:23:29.213 *apfMsConnTask_4 Client is entering the 802.1x or PSK Authentication state
Sep 27 08:23:29.213 *apfMsConnTask_4 Client has successfully cleared AP association phase
Sep 27 08:23:29.214 *apfMsConnTask_4 WLC/AP is sending an Association Response to the client with status code 0 = Successful association
Sep 27 08:23:29.242 *Dot1x_NW_MsgTask_7 Client will be required to Reauthenticate in 0
seconds
Sep 27 08:23:29.242 *Dot1x_NW_MsgTask_7 WLC/AP is sending EAP-Identity-Request to the client
Connection attempt #3
Sep 27 08:23:45.623 *apfMsConnTask_4 Client made new Association to AP/BSSID BSSID dc:ce:c1:c8:a7:4f AP IMA-Radio-04
Sep 27 08:23:45.624 *apfMsConnTask_4 The WLC/AP has found from client association request Information Element that claims PMKID Caching support
Sep 27 08:23:45.624 *apfMsConnTask_4 The Reassociation Request from the client comes with 0 PMKID
Sep 27 08:23:45.624 *apfMsConnTask_4 Client is entering the 802.1x or PSK Authentication state
Sep 27 08:23:45.625 *apfMsConnTask_4 WLC/AP is sending an Association Response to the client with status code 0 = Successful association

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Hi Marce

Thanks for the help and reply. Will try above suggestions

Controller model = 2504 (AIR-CT2504-K9) version = 8.3.143.0

Issue happens even when the users are on desk ( not moving).

I noticed from debug logs that, client is stuck at connecting state 
(moving mobile 84:14:4d:2c:0a:1f into Connecting state).

After that not moving to next step. 

 

Any other suggestions are appreciated.

Thank you

Mithun R

Review Cisco Networking for a $25 gift card