05-04-2021 11:00 AM - edited 07-05-2021 01:15 PM
Anyone ran into an odd behavior where Apple (Android works fine) constantly reconnect to an enterprise (EAP-TTLS) network? The controller shows everything is normal and client make it to the "RUN" state and then the controller receives a management action frame to DISACC (disassociate) from the device whereupon the process starts anew. From the user perspective, it just shows the SSID with a "blue check" disappear and reappear fully connected over and over again.
As for the wireless, we have WLCL 5520 (ha pair) and use flexconnect.
05-04-2021 12:48 PM
Here is some output of the repeating issue/log:
*apfOpenDtlSocket: Apr 21 08:38:34.639: [PA] 2e:3c:d2:9c:16:b7 Received management frame DISASSOC on BSSID 00:b7:71:77:59:4f destination addr 00:b7:71:77:59:4f
*apfMsConnTask_0: Apr 21 08:38:34.639: [PA] 2e:3c:d2:9c:16:b7 Got disassoc frame from 2E:3C:D2:9C:16:B7 BSSID= 00:B7:71:77:59:40 reasoncode = 8 dataLen = 13
*apfMsConnTask_0: Apr 21 08:38:34.639: [PA] 2e:3c:d2:9c:16:b7 Apple_IE: Subtype = 2 Version = 1 Reason = 9, Subreason = 0
*apfMsConnTask_0: Apr 21 08:38:34.639: [PA] 2e:3c:d2:9c:16:b7 Setting client ReasonCode from (0) to (121)
*apfMsConnTask_0: Apr 21 08:38:34.639: [PA] 2e:3c:d2:9c:16:b7 CL_EVENT_DISASSOC (17), reasonCode (121)
*apfMsConnTask_0: Apr 21 08:38:34.639: [PA] 2e:3c:d2:9c:16:b7 MS Associated AP 00:b7:71:77:59:40 slot 1 MFP Disabled , 11w Disabled
*apfMsConnTask_0: Apr 21 08:38:34.639: [PA] 2e:3c:d2:9c:16:b7 Ignoring received Dissoc frame on AP 00:b7:71:77:59:40 slot 1
*apfOpenDtlSocket: Apr 21 08:38:35.736: [PA] 2e:3c:d2:9c:16:b7 Received management frame ASSOCIATION REQUEST on BSSID 00:b7:71:77:59:4f destination addr 00:b7:71:77:59:4f
*apfMsConnTask_0: Apr 21 08:38:35.736: [PA] 2e:3c:d2:9c:16:b7 Updating 11r vendor IE
05-04-2021 03:52 PM
@jerrymatson1 wrote:
*apfMsConnTask_0: Apr 21 08:38:35.736: [PA] 2e:3c:d2:9c:16:b7 Updating 11r vendor IE
Disable 802.11k, v and r.
05-05-2021 06:05 AM
Already disabled: (FT disabled on security tab and 802.11 v (BSS Transition) not checked, and 802.11k (neighbor list) also not checked.)
05-04-2021 08:05 PM
did the issue start to happen after any specific change in network.
first, isolate WLAN config and client IOS(try different ios).
//try from open wlan and keep adding features to isolate the impacted feature.
it appear, 4-way handshake may be failing based on immediate disassoc.
https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/116493-technote-technology-00.html
check this section - Fast-Secure Roaming with 802.11r
05-05-2021 06:01 AM
No changes were made when this issue started and it seems to be happening in a single office (among hundreds all tied to the same controller).
05-05-2021 06:07 AM
Odd thing is that the issue seems to go away while the phone is locked (stays connected and stable) but will start reassociating repeatedly as soon as the user unlocks and starts using the phone. Only happening with Apple, all other devices (android, laptops) work fine.
05-05-2021 09:26 AM
1.Disable MAC randomization on the device and try.
2.Try on a device with a different ios version.
05-05-2021 09:48 AM
I don't see any mention of what version of AireOS you're using?
05-05-2021 10:00 AM - edited 05-05-2021 10:02 AM
yes no aireos code detail.
05-05-2021 11:49 PM
Just to add and also ask. You are using EAP-TTLS not EAP-TLS? Also did the issue start happening after Apple released the latest update? Have you identified that it is all iPhones no matter what model and or software version? Do these devices work fine on other SSID’s like open or psk or even EAP-PEAP? Have you looked at your HA failover status? Has there been a failover? Have you tried to force a failover?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide