cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
961
Views
5
Helpful
1
Replies

Cisco root - non-root wireless brigde - The non root keep deauthenticating and associateing

Luca Pecchiari
Level 1
Level 1

Hello,

 

i have a root - non root wireless bridge between an ap802 (root) and an ap1142 (non root with wirelss client) on the 2,4 GHz.

Basically the ap1142 connects to the ap802 and give access to a wireless device that in most of the case do not procuce traffic (it is a wi-fi speaker from Sonos); nothing is connected to the lan of the ap1142.

 

Inside the ap802 logs i found out:

 

Jan 4 10:45:02 CET: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station 1caa.0716.64b0 Reason: Sending station has left the BSS
Jan 4 10:45:03 CET: %DOT11-6-ASSOC: Interface Dot11Radio0, Station ap1142n 1caa.0716.64b0 Associated KEY_MGMT[WPAv2 PSK]
Jan 4 10:45:21 CET: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station 1caa.0716.64b0 Reason: Sending station has left the BSS
Jan 4 10:45:22 CET: %DOT11-6-ASSOC: Interface Dot11Radio0, Station ap1142n 1caa.0716.64b0 Associated KEY_MGMT[WPAv2 PSK]

 

and i cannot understand why it keed connecting and disconnecting.

 

Here is my running config

--- ap802 root bridge---

 

version 15.3
no service pad
service timestamps debug datetime msec
service timestamps log datetime localtime show-timezone
no service password-encryption
!
hostname ap802
!
!
logging buffered 20000 informational
logging rate-limit console 9
enable secret 9 .......
!
aaa new-model
!
!
aaa authentication login default local
aaa authorization exec default local
!
!
!
!
!
aaa session-id common
clock timezone CET 1 0
clock summer-time DST recurring last Sun Mar 2:00 last Sun Oct 3:00
clock save interval 8
no ip source-route
no ip cef
!
!
!
!
power inline negotiation prestandard source
dot11 pause-time 100
dot11 syslog
dot11 activity-timeout bridge default 70 maximum 120
dot11 vlan-name vlan10 vlan 10
dot11 vlan-name vlan11 vlan 11
!
dot11 ssid --Caos-WiFi-C--
   vlan 10
   authentication open
   authentication key-management wpa version 2
   guest-mode
   wpa-psk ascii 0 9jbga80a2jagcp042oiu3loc
!
dot11 ssid WiFi-Bridge
   vlan 11
   authentication open
   authentication key-management wpa version 2
   wpa-psk ascii 0 9jbga80a2jagcp042oiu3loc
!
!
!
no ipv6 cef
!
!
username xxxxx privilege 15 secret 9 xxxxxxx
!
!
ip tftp blocksize 8192
!
bridge irb
!
!
!
interface Dot11Radio0
 no ip address
 no ip route-cache
 load-interval 60
 !
 encryption vlan 11 mode ciphers aes-ccm
 !
 encryption mode ciphers aes-ccm
 !
 broadcast-key vlan 11 change 30
 !
 !
 ssid WiFi-Bridge
 !
 vocera
 antenna gain 5
 beamform ofdm
 speed  12.0 basic-18.0 24.0 36.0 48.0 54.0 m0. m1. m2. m3. m4. m5. m6. m7. m8. m9. m10. m11. m12. m13. m14. m15.
 power local 10
 packet retries 32 drop-packet
 channel 2472
 station-role root bridge
 dot11 dot11r pre-authentication over-air
 world-mode dot11d country-code US outdoor
 keepalive 8
!
interface Dot11Radio0.1
 encapsulation dot1Q 11 native
 no ip route-cache
 bridge-group 1
 bridge-group 1 spanning-disabled
!
interface Dot11Radio0.10
 encapsulation dot1Q 10
 no ip route-cache
 bridge-group 10
 bridge-group 10 spanning-disabled
!
interface Dot11Radio1
 no ip address
 no ip route-cache
 load-interval 60
 !
 encryption vlan 10 mode ciphers aes-ccm
 !
 encryption mode ciphers aes-ccm
 !
 broadcast-key vlan 10 change 30
 !
 !
 ssid --Caos-WiFi-C--
 !
 antenna gain 3
 peakdetect
 no dfs band block
 beamform ofdm
 speed  basic-12.0 18.0 basic-24.0 36.0 48.0 54.0 m0. m1. m2. m3. m4. m5. m6. m7. m8. m9. m10. m11. m12. m13. m14. m15.
 power local 10
 packet retries 32 drop-packet
 packet max-retries 3 0 fail-threshold 100 500 priority 5 drop-packet
 packet max-retries 3 0 fail-threshold 100 500 priority 6 drop-packet
 channel width 40-below
 channel 5700
 station-role root
 beacon privacy guest-mode
 dot11 dot11r pre-authentication over-air
 dot11 qos class background local
    cw-min 6
    fixed-slot 10
 !
 dot11 qos class video local
    cw-max 5
    fixed-slot 3
    transmit-op 0
 !
 dot11 qos class voice local
    cw-max 4
    transmit-op 0
 !
 dot11 qos class background cell
    cw-min 8
    fixed-slot 12
 !
 dot11 qos class best-effort cell
    cw-min 6
    fixed-slot 5
 !
 dot11 qos class video cell
    cw-min 4
    cw-max 6
    fixed-slot 5
    transmit-op 0
 !
 dot11 qos class voice cell
    cw-max 4
    transmit-op 0
 !
 world-mode dot11d country-code US outdoor
!
interface Dot11Radio1.1
 encapsulation dot1Q 11 native
 no ip route-cache
 bridge-group 1
 bridge-group 1 subscriber-loop-control
 bridge-group 1 spanning-disabled
 bridge-group 1 block-unknown-source
 no bridge-group 1 source-learning
 no bridge-group 1 unicast-flooding
!
interface Dot11Radio1.10
 encapsulation dot1Q 10
 no ip route-cache
 no cdp enable
 bridge-group 10
 bridge-group 10 subscriber-loop-control
 bridge-group 10 spanning-disabled
 bridge-group 10 block-unknown-source
 no bridge-group 10 source-learning
 no bridge-group 10 unicast-flooding
!
interface GigabitEthernet0
 no ip address
 no ip route-cache
!
interface GigabitEthernet0.1
 encapsulation dot1Q 11 native
 no ip route-cache
 bridge-group 1
 bridge-group 1 spanning-disabled
!
interface GigabitEthernet0.10
 encapsulation dot1Q 10
 no ip route-cache
 bridge-group 10
 bridge-group 10 spanning-disabled
!
interface BVI1
 mac-address 74a2.e652.73ac
 ip address 192.168.2.2 255.255.255.0
 ip helper-address 192.168.2.1
 no ip route-cache
!
ip default-gateway 192.168.2.1
ip forward-protocol nd
ip http server
no ip http secure-server
ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
ip ssh version 2
!
!
!
bridge 1 protocol ieee
bridge 1 route ip
bridge 10 protocol ieee
bridge 10 route ip
!
!
alias exec qos0 show policy-map interface dot11Radio 0.1
alias exec qos1 show policy-map interface dot11Radio 1.1
alias exec busy0 dot11 dot11Radio 0 carrier busy
alias exec busy1 dot11 dot11Radio 1 carrier busy
alias exec asso sh dot11 associations
!
line con 0
 privilege level 15
 no activation-character
line vty 0 4
 access-class 80 in
 exec-timeout 30 0
 length 0
 transport preferred ssh
 transport input ssh
 transport output telnet
!
sntp server 192.168.2.1
sntp source-interface BVI1
cns dhcp
end

--- ap1142 non-root bridge---

 

version 15.3
no service pad
service timestamps debug datetime msec
service timestamps log datetime localtime show-timezone
no service password-encryption
!
hostname ap1142n
!
!
logging buffered 20000 informational
logging rate-limit console 9
enable secret 9 ........
!
aaa new-model
!
!
aaa authentication login default local
aaa authorization exec default local
!
!
!
!
!
aaa session-id common
clock timezone CET 1 0
clock summer-time DST recurring last Sun Mar 2:00 last Sun Oct 3:00
clock save interval 8
no ip source-route
no ip cef
!
!
!
!
dot11 pause-time 100
dot11 syslog
dot11 activity-timeout bridge default 70 maximum 120
dot11 vlan-name vlan10 vlan 10
dot11 vlan-name vlan11 vlan 11
!
dot11 ssid --Caos-WiFi-C--2
   vlan 10
   authentication open
   authentication key-management wpa version 2
   guest-mode
   wpa-psk ascii 0 9jbga80a2jagcp042oiu3loc
!
dot11 ssid WiFi-Bridge
   vlan 11
   authentication open
   authentication key-management wpa version 2
   infrastructure-ssid
   wpa-psk ascii 0 9jbga80a2jagcp042oiu3loc
!
!
!
no ipv6 cef
!
!
username ...... privilege 15 secret 9 ..........
!
!
ip tftp blocksize 8192
bridge irb
!
!
!
interface Dot11Radio0
 no ip address
 no ip route-cache
 !
 encryption vlan 10 mode ciphers aes-ccm
 !
 encryption vlan 11 mode ciphers aes-ccm
 !
 encryption mode ciphers aes-ccm
 !
 broadcast-key vlan 10 change 30
 !
 broadcast-key vlan 11 change 30
 !
 !
 ssid --Caos-WiFi-C--2
 !
 ssid WiFi-Bridge
 !
 vocera
 antenna gain 4
 beamform ofdm
 parent 1 74a2.e622.fb20
 speed  12.0 basic-18.0 24.0 36.0 48.0 54.0 m0. m1. m2. m3. m4. m5. m6. m7. m8. m9. m10. m11. m12. m13. m14. m15.
 power local 11
 packet retries 32 drop-packet
 station-role non-root bridge wireless-clients
 mobile station scan 2472
 mobile station ignore neighbor-list
 dot11 dot11r pre-authentication over-air
 world-mode dot11d country-code US outdoor
 keepalive 8
!
interface Dot11Radio0.1
 encapsulation dot1Q 11 native
 no ip route-cache
 bridge-group 1
 bridge-group 1 spanning-disabled
!
interface Dot11Radio0.10
 encapsulation dot1Q 10
 no ip route-cache
 bridge-group 10
 bridge-group 10 spanning-disabled
!
interface Dot11Radio1
 no ip address
 no ip route-cache
 load-interval 60
 shutdown
 !
 encryption vlan 10 mode ciphers aes-ccm
 !
 encryption mode ciphers aes-ccm
 !
 broadcast-key vlan 10 change 30
 !
 !
 ssid --Caos-WiFi-C--2
 !
 antenna gain 3
 peakdetect
 no dfs band block
 parent 1 74a2.e622.fb30
 speed  basic-12.0 18.0 basic-24.0 36.0 48.0 54.0 m0. m1. m2. m3. m4. m5. m6. m7. m8. m9. m10. m11. m12. m13. m14. m15.
 power local 11
 packet retries 32 drop-packet
 packet max-retries 3 0 fail-threshold 100 500 priority 5 drop-packet
 packet max-retries 3 0 fail-threshold 100 500 priority 6 drop-packet
 channel 5180
 station-role root
 beacon privacy guest-mode
 dot11 dot11r pre-authentication over-air
 dot11 qos class background local
    cw-min 6
    fixed-slot 10
 !
 dot11 qos class video local
    cw-max 5
    fixed-slot 3
    transmit-op 0
 !
 dot11 qos class voice local
    cw-max 4
    transmit-op 0
 !
 dot11 qos class background cell
    cw-min 8
    fixed-slot 12
 !
 dot11 qos class best-effort cell
    cw-min 6
    fixed-slot 5
 !
 dot11 qos class video cell
    cw-min 4
    cw-max 6
    fixed-slot 5
    transmit-op 0
 !
 dot11 qos class voice cell
    cw-max 4
    transmit-op 0
 !
 world-mode dot11d country-code US outdoor
!
interface Dot11Radio1.1
 encapsulation dot1Q 11 native
 no ip route-cache
 bridge-group 1
 bridge-group 1 subscriber-loop-control
 bridge-group 1 spanning-disabled
 bridge-group 1 block-unknown-source
 no bridge-group 1 source-learning
 no bridge-group 1 unicast-flooding
!
interface Dot11Radio1.10
 encapsulation dot1Q 10
 no ip route-cache
 no cdp enable
 bridge-group 10
 bridge-group 10 subscriber-loop-control
 bridge-group 10 spanning-disabled
 bridge-group 10 block-unknown-source
 no bridge-group 10 source-learning
 no bridge-group 10 unicast-flooding
!
interface GigabitEthernet0
 no ip address
 no ip route-cache
 duplex auto
 speed auto
!
interface GigabitEthernet0.1
 encapsulation dot1Q 11 native
 no ip route-cache
 bridge-group 1
 bridge-group 1 spanning-disabled
!
interface GigabitEthernet0.10
 encapsulation dot1Q 10
 no ip route-cache
 bridge-group 10
 bridge-group 10 spanning-disabled
!
interface BVI1
 mac-address 4055.3997.ce7b
 ip address 192.168.2.3 255.255.255.0
 ip helper-address 192.168.2.1
 no ip route-cache
!
ip default-gateway 192.168.2.1
ip forward-protocol nd
ip http server
no ip http secure-server
ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
ip ssh version 2
!
!
!
bridge 1 protocol ieee
bridge 1 route ip
bridge 10 protocol ieee
bridge 10 route ip
!
!
alias exec qos0 show policy-map interface dot11Radio 0.1
alias exec qos1 show policy-map interface dot11Radio 1.1
alias exec busy0 dot11 dot11Radio 0 carrier busy
alias exec busy1 dot11 dot11Radio 1 carrier busy
alias exec asso sh dot11 associations
!
line con 0
 privilege level 15
 no activation-character
line vty 0 4
 access-class 80 in
 exec-timeout 30 0
 length 0
 transport preferred ssh
 transport input ssh
 transport output telnet
!
sntp server 192.168.2.1
sntp source-interface BVI1
end

Please do you have any ideas?

 

1 Reply 1
Review Cisco Networking for a $25 gift card