10-30-2023 08:49 AM - edited 10-31-2023 03:32 AM
Clients connecting to specific SSIDs of Cisco 5520 WLC (IOS 8.10.x) are not getting IP addresses and dynamically getting added to an exclusion list, the reason listed as "802.11 Assoc Failure".
Expected behaviour: users have to get a captive portal for entering credentials but these clients are not getting any portal or IP address.
10-30-2023 10:56 AM
- You need to get into the reason for the failure of the client to get an IP address ; for that have a checkup of the controller configuration according to : https://community.cisco.com/t5/networking-knowledge-base/show-the-complete-configuration-without-breaks-pauses-on-cisco/ta-p/3115114#toc-hId-1039672820 , you can have this analyzed with :
Wireless Config Analyzer
Further on you can debug clients using instructions mentioned in : https://www.cisco.com/c/en/us/support/docs/wireless/aironet-1200-series/100260-wlc-debug-client.html
You can have client debugs analyzed with : https://cway.cisco.com/tools/WirelessDebugAnalyzer/
Use latest advisory release : https://software.cisco.com/download/home/286284738/type/280926587/release/8.10.190.0
In theory you can disable client exclusion on a particular WLAN : https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-6/b_Cisco_Wireless_LAN_Controller_Configuration_Best_Practices.html#concept_5E9C14D0D3A249A2986A15B65866F48F
but that does not tackle the original problem ,
M.
10-30-2023 02:28 PM
How is the SSID configured?
Are any clients able to connect to it?
Are any clients connected to the wireless off this WLC at all?
10-31-2023 01:28 AM
SSID configured to allow clients based on MAC filtering & ISE authentication when clients enter credentials in a captive portal.
No clients able to connect to this SSID, other SSID working fine.
Yes, clients are connected to Internet sucessfully when trying on local Business SSID.
10-30-2023 02:44 PM
Is this happening to all WiFi clients attempting to associate to the SSID or just a handful?
On the SSID, is DHCP Address Assignment set to Required?
10-31-2023 01:25 AM
Yes, same for all clients connecting to this SSID. Other SSID (local Business SSID) is working fine. DHCP Address Assignment is set to Required.
11-04-2023 05:51 AM - edited 11-06-2023 04:22 AM
So it's obviously a problem with your SSID (WLAN) configuration. As Marce suggested already check your config, make sure your software is up to date and then debug a client and run the output through debug analyzer. That might reveal the answer straight away or at least show you where to start looking. You still didn't answer the question though about this SSID - is it open, WPA2 PSK or 802.1x?
More generally check your config against the config guides and best practice guide (link below).
Since the clients are never able to associate it must be failing at the MAB stage and never using fallback to web auth on MAC auth failure.
https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/wlan_security.html
https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/MAB/MAB_Dep_Guide.html
11-06-2023 04:23 AM
11-06-2023 04:23 AM
11-06-2023 05:19 AM
is your MAB authentication condition set to "continue" is the user is not found ?
11-06-2023 06:36 AM
>....New errors we are seeing for this SSID Clients
- Check the radius server's logs for these authentications ,
M.
11-06-2023 01:43 PM
Wireless Debug Analyzer should not be trusted at all. Read THIS.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide