01-04-2021 02:05 AM - edited 07-05-2021 12:58 PM
Hello,
i have a root - non root wireless bridge between an ap802 (root) and an ap1142 (non root with wirelss client) on the 2,4 GHz.
Basically the ap1142 connects to the ap802 and give access to a wireless device that in most of the case do not procuce traffic (it is a wi-fi speaker from Sonos); nothing is connected to the lan of the ap1142.
Inside the ap802 logs i found out:
Jan 4 10:45:02 CET: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station 1caa.0716.64b0 Reason: Sending station has left the BSS
Jan 4 10:45:03 CET: %DOT11-6-ASSOC: Interface Dot11Radio0, Station ap1142n 1caa.0716.64b0 Associated KEY_MGMT[WPAv2 PSK]
Jan 4 10:45:21 CET: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station 1caa.0716.64b0 Reason: Sending station has left the BSS
Jan 4 10:45:22 CET: %DOT11-6-ASSOC: Interface Dot11Radio0, Station ap1142n 1caa.0716.64b0 Associated KEY_MGMT[WPAv2 PSK]
and i cannot understand why it keed connecting and disconnecting.
Here is my running config
--- ap802 root bridge---
version 15.3
no service pad
service timestamps debug datetime msec
service timestamps log datetime localtime show-timezone
no service password-encryption
!
hostname ap802
!
!
logging buffered 20000 informational
logging rate-limit console 9
enable secret 9 .......
!
aaa new-model
!
!
aaa authentication login default local
aaa authorization exec default local
!
!
!
!
!
aaa session-id common
clock timezone CET 1 0
clock summer-time DST recurring last Sun Mar 2:00 last Sun Oct 3:00
clock save interval 8
no ip source-route
no ip cef
!
!
!
!
power inline negotiation prestandard source
dot11 pause-time 100
dot11 syslog
dot11 activity-timeout bridge default 70 maximum 120
dot11 vlan-name vlan10 vlan 10
dot11 vlan-name vlan11 vlan 11
!
dot11 ssid --Caos-WiFi-C--
vlan 10
authentication open
authentication key-management wpa version 2
guest-mode
wpa-psk ascii 0 9jbga80a2jagcp042oiu3loc
!
dot11 ssid WiFi-Bridge
vlan 11
authentication open
authentication key-management wpa version 2
wpa-psk ascii 0 9jbga80a2jagcp042oiu3loc
!
!
!
no ipv6 cef
!
!
username xxxxx privilege 15 secret 9 xxxxxxx
!
!
ip tftp blocksize 8192
!
bridge irb
!
!
!
interface Dot11Radio0
no ip address
no ip route-cache
load-interval 60
!
encryption vlan 11 mode ciphers aes-ccm
!
encryption mode ciphers aes-ccm
!
broadcast-key vlan 11 change 30
!
!
ssid WiFi-Bridge
!
vocera
antenna gain 5
beamform ofdm
speed 12.0 basic-18.0 24.0 36.0 48.0 54.0 m0. m1. m2. m3. m4. m5. m6. m7. m8. m9. m10. m11. m12. m13. m14. m15.
power local 10
packet retries 32 drop-packet
channel 2472
station-role root bridge
dot11 dot11r pre-authentication over-air
world-mode dot11d country-code US outdoor
keepalive 8
!
interface Dot11Radio0.1
encapsulation dot1Q 11 native
no ip route-cache
bridge-group 1
bridge-group 1 spanning-disabled
!
interface Dot11Radio0.10
encapsulation dot1Q 10
no ip route-cache
bridge-group 10
bridge-group 10 spanning-disabled
!
interface Dot11Radio1
no ip address
no ip route-cache
load-interval 60
!
encryption vlan 10 mode ciphers aes-ccm
!
encryption mode ciphers aes-ccm
!
broadcast-key vlan 10 change 30
!
!
ssid --Caos-WiFi-C--
!
antenna gain 3
peakdetect
no dfs band block
beamform ofdm
speed basic-12.0 18.0 basic-24.0 36.0 48.0 54.0 m0. m1. m2. m3. m4. m5. m6. m7. m8. m9. m10. m11. m12. m13. m14. m15.
power local 10
packet retries 32 drop-packet
packet max-retries 3 0 fail-threshold 100 500 priority 5 drop-packet
packet max-retries 3 0 fail-threshold 100 500 priority 6 drop-packet
channel width 40-below
channel 5700
station-role root
beacon privacy guest-mode
dot11 dot11r pre-authentication over-air
dot11 qos class background local
cw-min 6
fixed-slot 10
!
dot11 qos class video local
cw-max 5
fixed-slot 3
transmit-op 0
!
dot11 qos class voice local
cw-max 4
transmit-op 0
!
dot11 qos class background cell
cw-min 8
fixed-slot 12
!
dot11 qos class best-effort cell
cw-min 6
fixed-slot 5
!
dot11 qos class video cell
cw-min 4
cw-max 6
fixed-slot 5
transmit-op 0
!
dot11 qos class voice cell
cw-max 4
transmit-op 0
!
world-mode dot11d country-code US outdoor
!
interface Dot11Radio1.1
encapsulation dot1Q 11 native
no ip route-cache
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
!
interface Dot11Radio1.10
encapsulation dot1Q 10
no ip route-cache
no cdp enable
bridge-group 10
bridge-group 10 subscriber-loop-control
bridge-group 10 spanning-disabled
bridge-group 10 block-unknown-source
no bridge-group 10 source-learning
no bridge-group 10 unicast-flooding
!
interface GigabitEthernet0
no ip address
no ip route-cache
!
interface GigabitEthernet0.1
encapsulation dot1Q 11 native
no ip route-cache
bridge-group 1
bridge-group 1 spanning-disabled
!
interface GigabitEthernet0.10
encapsulation dot1Q 10
no ip route-cache
bridge-group 10
bridge-group 10 spanning-disabled
!
interface BVI1
mac-address 74a2.e652.73ac
ip address 192.168.2.2 255.255.255.0
ip helper-address 192.168.2.1
no ip route-cache
!
ip default-gateway 192.168.2.1
ip forward-protocol nd
ip http server
no ip http secure-server
ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
ip ssh version 2
!
!
!
bridge 1 protocol ieee
bridge 1 route ip
bridge 10 protocol ieee
bridge 10 route ip
!
!
alias exec qos0 show policy-map interface dot11Radio 0.1
alias exec qos1 show policy-map interface dot11Radio 1.1
alias exec busy0 dot11 dot11Radio 0 carrier busy
alias exec busy1 dot11 dot11Radio 1 carrier busy
alias exec asso sh dot11 associations
!
line con 0
privilege level 15
no activation-character
line vty 0 4
access-class 80 in
exec-timeout 30 0
length 0
transport preferred ssh
transport input ssh
transport output telnet
!
sntp server 192.168.2.1
sntp source-interface BVI1
cns dhcp
end--- ap1142 non-root bridge---
version 15.3
no service pad
service timestamps debug datetime msec
service timestamps log datetime localtime show-timezone
no service password-encryption
!
hostname ap1142n
!
!
logging buffered 20000 informational
logging rate-limit console 9
enable secret 9 ........
!
aaa new-model
!
!
aaa authentication login default local
aaa authorization exec default local
!
!
!
!
!
aaa session-id common
clock timezone CET 1 0
clock summer-time DST recurring last Sun Mar 2:00 last Sun Oct 3:00
clock save interval 8
no ip source-route
no ip cef
!
!
!
!
dot11 pause-time 100
dot11 syslog
dot11 activity-timeout bridge default 70 maximum 120
dot11 vlan-name vlan10 vlan 10
dot11 vlan-name vlan11 vlan 11
!
dot11 ssid --Caos-WiFi-C--2
vlan 10
authentication open
authentication key-management wpa version 2
guest-mode
wpa-psk ascii 0 9jbga80a2jagcp042oiu3loc
!
dot11 ssid WiFi-Bridge
vlan 11
authentication open
authentication key-management wpa version 2
infrastructure-ssid
wpa-psk ascii 0 9jbga80a2jagcp042oiu3loc
!
!
!
no ipv6 cef
!
!
username ...... privilege 15 secret 9 ..........
!
!
ip tftp blocksize 8192
bridge irb
!
!
!
interface Dot11Radio0
no ip address
no ip route-cache
!
encryption vlan 10 mode ciphers aes-ccm
!
encryption vlan 11 mode ciphers aes-ccm
!
encryption mode ciphers aes-ccm
!
broadcast-key vlan 10 change 30
!
broadcast-key vlan 11 change 30
!
!
ssid --Caos-WiFi-C--2
!
ssid WiFi-Bridge
!
vocera
antenna gain 4
beamform ofdm
parent 1 74a2.e622.fb20
speed 12.0 basic-18.0 24.0 36.0 48.0 54.0 m0. m1. m2. m3. m4. m5. m6. m7. m8. m9. m10. m11. m12. m13. m14. m15.
power local 11
packet retries 32 drop-packet
station-role non-root bridge wireless-clients
mobile station scan 2472
mobile station ignore neighbor-list
dot11 dot11r pre-authentication over-air
world-mode dot11d country-code US outdoor
keepalive 8
!
interface Dot11Radio0.1
encapsulation dot1Q 11 native
no ip route-cache
bridge-group 1
bridge-group 1 spanning-disabled
!
interface Dot11Radio0.10
encapsulation dot1Q 10
no ip route-cache
bridge-group 10
bridge-group 10 spanning-disabled
!
interface Dot11Radio1
no ip address
no ip route-cache
load-interval 60
shutdown
!
encryption vlan 10 mode ciphers aes-ccm
!
encryption mode ciphers aes-ccm
!
broadcast-key vlan 10 change 30
!
!
ssid --Caos-WiFi-C--2
!
antenna gain 3
peakdetect
no dfs band block
parent 1 74a2.e622.fb30
speed basic-12.0 18.0 basic-24.0 36.0 48.0 54.0 m0. m1. m2. m3. m4. m5. m6. m7. m8. m9. m10. m11. m12. m13. m14. m15.
power local 11
packet retries 32 drop-packet
packet max-retries 3 0 fail-threshold 100 500 priority 5 drop-packet
packet max-retries 3 0 fail-threshold 100 500 priority 6 drop-packet
channel 5180
station-role root
beacon privacy guest-mode
dot11 dot11r pre-authentication over-air
dot11 qos class background local
cw-min 6
fixed-slot 10
!
dot11 qos class video local
cw-max 5
fixed-slot 3
transmit-op 0
!
dot11 qos class voice local
cw-max 4
transmit-op 0
!
dot11 qos class background cell
cw-min 8
fixed-slot 12
!
dot11 qos class best-effort cell
cw-min 6
fixed-slot 5
!
dot11 qos class video cell
cw-min 4
cw-max 6
fixed-slot 5
transmit-op 0
!
dot11 qos class voice cell
cw-max 4
transmit-op 0
!
world-mode dot11d country-code US outdoor
!
interface Dot11Radio1.1
encapsulation dot1Q 11 native
no ip route-cache
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
!
interface Dot11Radio1.10
encapsulation dot1Q 10
no ip route-cache
no cdp enable
bridge-group 10
bridge-group 10 subscriber-loop-control
bridge-group 10 spanning-disabled
bridge-group 10 block-unknown-source
no bridge-group 10 source-learning
no bridge-group 10 unicast-flooding
!
interface GigabitEthernet0
no ip address
no ip route-cache
duplex auto
speed auto
!
interface GigabitEthernet0.1
encapsulation dot1Q 11 native
no ip route-cache
bridge-group 1
bridge-group 1 spanning-disabled
!
interface GigabitEthernet0.10
encapsulation dot1Q 10
no ip route-cache
bridge-group 10
bridge-group 10 spanning-disabled
!
interface BVI1
mac-address 4055.3997.ce7b
ip address 192.168.2.3 255.255.255.0
ip helper-address 192.168.2.1
no ip route-cache
!
ip default-gateway 192.168.2.1
ip forward-protocol nd
ip http server
no ip http secure-server
ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
ip ssh version 2
!
!
!
bridge 1 protocol ieee
bridge 1 route ip
bridge 10 protocol ieee
bridge 10 route ip
!
!
alias exec qos0 show policy-map interface dot11Radio 0.1
alias exec qos1 show policy-map interface dot11Radio 1.1
alias exec busy0 dot11 dot11Radio 0 carrier busy
alias exec busy1 dot11 dot11Radio 1 carrier busy
alias exec asso sh dot11 associations
!
line con 0
privilege level 15
no activation-character
line vty 0 4
access-class 80 in
exec-timeout 30 0
length 0
transport preferred ssh
transport input ssh
transport output telnet
!
sntp server 192.168.2.1
sntp source-interface BVI1
endPlease do you have any ideas?
01-05-2021 12:01 AM
i found this and it seem to be better.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide