cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1336
Views
0
Helpful
8
Replies

authentication distance issues

bwilliams
Community Member

hello,

I have the same issues on multiple access points (all cisco 1200s - in different sites) in which users cannot authenticate until they walk close to the AP. (a site survey was done before installation) - and I get good link quality from the users cards. (always in the green) but for some reason they cannot authenticate until they get closer to the AP. After they authenticate they are able to roam anywhere with good signal strength.

I am running:

WPA w/ tkip, with EAP (GTC is the second stage) with the certificate stored in the correct store on the client.

"Best Range" has been selected in the settings page of the radio. (require 1 mb/sec and enable all the other speeds)

CCK and OFDM transmit power are both set to "Max" on the same page.

Limit Client Power is set to max also.

anybody have any ideas?

thanks in advance,

Blaine

8 Replies 8

umedryk
Level 11
Level 11

What is the exact error message it throws when the authentication fails ?

thanks for your reply.

here is the message I get:

Station 0040.96a4.ea43 Authentication failed

I have also checked the ACS server that it authenticates the client to and it does not have any record of being contacted. (either failed or successful)

thanks,

Blaine

what is the IOS version of the WDS AP?

magnumpi83
Community Member

Blaine,

How did you make out? I have the same problem but it's not with all my APs installed, just a few of them..

Thanks...

I have upgraded all APs to:

12.3 2 JA

(c1200-k9w7-tar.123-2.JA.tar)

All APs were previously running:

12.2 15 JA

(c1200-k9w7-tar.122-15.JA.tar)

including the WDS AP

this seems to help most of the time.

my users are still testing..

thanks,

Blaine

looks like my problems didn't go away totally.

Most of the time we are fine but sometimes it is still not working.

Blaine

Are you using multiple vlans and DHCP? We had a similar problen; the root cause was failue of the client to receive an IP. On the AP that the client is associating with you can issue the command

sh wlccp wds mn

to see if the client is reciving an IP although my prefered way is to watch the network connection progress displayed by windows.

Did you have this problem with 12.2(15)JA?

Yes, I am using multiple vlans and using DHCP.

My native VLAN is actually my voice vlan, and obviously not the one that the laptops connect with.

Could this present problems?

It is weird because sometime users will get in first try..other times 8-10 tries.

I did have the problem with 12.2(15)JA also.

Review Cisco Networking for a $25 gift card