05-17-2022 02:25 PM
New to the community so if i say something wrong please have some mercy
Running a virtual WLC on VMWare ESXi, IW3702 AP. Have a couple of clients that are not connecting to my SSID. The WLC logs show this:
*Dot1x_NW_MsgTask_0: May 11 16:24:49.676: %DOT1X-3-PSK_CONFIG_ERR: 1x_ptsm.c:749 Client XX:XX:XX:XX:XX:40 may be using an incorrect PSK
*Dot1x_NW_MsgTask_0: May 11 16:24:49.676: %APF-6-MOBILE_EXCLUDED: apf_ms.c:7032 Excluded the mobile XX:XX:XX:XX:XX:40 Reason: "802.1X Failure"
We're not using the Radius server authentication therefore it's strange that i see 802.1X auth even mentioned.
Would this mean that the client tries to use the 802.1X authentication and obviously fails? Or is there some other meaning for "802.1X Failure"?
05-17-2022 02:47 PM
what WLC congtroller ? i mean code runnning (is this WLC 9800 ?), how is user authenticate using PSK ?
some troubleshoot messages :
05-17-2022 02:56 PM
Cisco vWLC AireOS 8.5.151
User uses WPA2-PSK.
i'll look into the troubleshooting messages linked above.
thanks.
05-17-2022 02:57 PM
is this issue with only 1 device all the devices ?
1. i will also do other side, update the latest drivers at client end
2. make sure PSK entered as expected or configured.
05-17-2022 03:02 PM
So far I've seen this happening with 2 users out of many. The client is not supposed to use 802.1X as they requested for PSK which we followed in WLC. I'm surprised to see 802.1X Failure in the logs.
Unfortunately i don't have any way to get the client's logs, that would've been helpful i guess in order to see the whole picture.
05-18-2022 01:52 AM
if only 2 users, i go more looking end point what is that user device ? compare to others ?
05-17-2022 03:09 PM - edited 05-17-2022 03:10 PM
Can we see L2 security config for this WLAN?
what are these two client OS ?
05-17-2022 03:04 PM
Hi
Run "debug client 'mac address' and share the output. Looking the log seems that the client tried to authenticate using radius. You can also check the client to see how is it configured.
For clients windows a good command would be "netsh wlan show interfaces" and "netsh wlan show networks"
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide