01-17-2021 05:00 PM - edited 07-05-2021 01:01 PM
I am running Cisco 5520 Wireless Controller.
The AP model is AIR-AP1852I-Q-K9 , The IOS version is 8.8.130.0
There are 2 SSIDs configured
SSID#1 : INTRA_WIFI - For Internal Wireless LAN network : Uses certificate authentication
SSID#2 : GUESTWIFI - For guest Internet access : Uses username & password authentication : PSK (WAP2/WAP3 personal)
There are nearly 50 APs. We rebooted all the APs as part of maintenance.
After the APs are rebooted,
1. Users using iPhone/ipad are not able to connected to GUESTWIFI (Users got password incorrect msg)
2. Laptop users are able to connect to GUESTWIFI
3. Laptop Users are able to connect to INTRA_WIFI (iPhone users are not allowed to connected to INTRA_WIFI)
1. Users using iPhone/ipad are not able to connected to GUESTWIFI (Users got password incorrect msg)
Eventhough the password is correct users are not able to login via iPhone/ipad
We again rebooted all the APs & after that the users are not facing the same issue. The issue got resolved.
Is there any reason for this to happen? Below are some of the logs which I found in the WLC.
*Dot1x_NW_MsgTask_4: Jan 15 10:06:25.524: %DOT1X-3-PSK_CONFIG_ERR: 1x_ptsm.c:756 Client 8a:33:b9:93:e4:9c may be using an incorrect PSK
*Dot1x_NW_MsgTask_1: Jan 15 08:52:59.721: %DOT1X-3-PSK_CONFIG_ERR: 1x_ptsm.c:756 Client 56:fa:d5:01:e8:19 may be using an incorrect PSK
*Dot1x_NW_MsgTask_1: Jan 15 10:01:00.477: %DOT1X-3-INVALID_REPLAY_CTR: 1x_eapkey.c:452 Invalid replay counter from client 98:00:c6:d1:d4:19 - got 00 00 00 00 00 00 00 04, expected 00 00 00 00 00 00 00 00
01-17-2021 05:03 PM
01-17-2021 06:07 PM
01-17-2021 08:35 PM
01-17-2021 09:26 PM
I can not share the full debug logs.
Please find the logs related to the MAC address of the device which had the problem.
01-17-2021 09:36 PM - edited 01-17-2021 09:45 PM
@RS19 wrote:
I can not share the full debug logs.
Cool. Please contact Cisco TAC.
01-17-2021 11:31 PM
But any insights, what could be the possible reasons for this ?
Laptops are able to connect without any issue, but issues with iPhone/ipad devices
Some thing strange scenario & after reboot of the APs it started to work.
01-17-2021 11:48 PM
@RS19 wrote:
But any insights, what could be the possible reasons for this ?
Please contact Cisco TAC.
01-18-2021 02:23 AM
- One thing you may consider is upgrading to the current advisory release for the 5520 which is 8.10.130.0 , check if the problem persists afterwards.
M.
02-01-2022 01:53 PM
Hi Mate,
Is issue solved? If yes can you provide the solution for this? I have similar issue in my envi and looking on following parameters, in my case few IOS are connecting few are not.
let's have a look at the following parameters.
Problem statement : IOS devices are not connecting to Guest wifi( PSK, WPA2+ WPA3 SAE)
Points to checking:
1. When you run the debug the 4 way hand shake is completing?
2. Do you have WPA2 and WPA3 policies enabled? Under Guestwifi layer 2 security?
3. Users are having issue on both radios 2.4 n 5Ghz?
4. Fast transition is adaptive or enabled?
02-01-2022 02:58 PM
Might want to look at what is compatible right now with Apple device. This also shows what you need to configure on the wlan for it to work.
02-01-2022 05:47 PM
No one knows the status of this issue because the OP does not want to furnish debug information/logs.
It is better if you can create a new thread so we can do proper debugs and troubleshooting.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide