cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1204
Views
5
Helpful
5
Replies

Cisco vWLC 9800 .11r cache information not propagated from WLC to APs

Kalin Hristov
Level 1
Level 1

Hello,

I hope you can help me stop banging my head about very strange problem.

I have a test setup with vWLC 9800 and two APs, 9120AX and 9130AX. I have WLAN that is doing dot1x with TLS and RADIUS server, which works fine. The only problem is that 801.11r is not working properly. For some reason the PMK cache information is not propagated from the WLC to the APs and as you can imagine the roaming does not work. When I try to move to another AP, the AP complains about PMK-r0 is not found in the cache and 802.11i slow roaming occurs. 

When I check at the controller everything looks fine:

WLC#show wireless pmk-cache
Number of PMK caches in total : 3

Type Station Entry Lifetime VLAN Override IP Override Accounting-Session-Id Audit-Session-Id Username
-------------------------------------------------------------------------------------------------------------------------------------------------------------------
DOT11R 50ed.3c2c.a723 669 1 0x00000000 FD0AA8C0000042C52D8EFE7B apple
DOT11R 64b5.f2cc.a861 1480 1 0x00000000 FD0AA8C0000042C42D897BB9 samsung

But then on the AP:

9120AX#show flexconnect pmk

Total number of PMK cache entries: 0

HW Address Life Time(s) BSSID vlanOverride aclOverride ipv6AclOverride qosOverride iPSK
9120AX#show flexconnect dot11r

Total number of DOT11R cache entries: 0

HW Address Life Time(s) BSSID R0KhId R1KhId vlanOverride aclOverride ipv6AclOverride qosOverride iPSK

Both APs are in the same FlexConnect group and site tag. If I disable FT+802.1x and enable 802.1x+AES256, the devices are doing 802.11i fast roaming without any problems.

I am testing with Samsung S23 (Qualcomm) and Samsung S21 (Exynos) and the behavior is the same

What I am missing?

 

Thanks

5 Replies 5

Scott Fella
Hall of Fame
Hall of Fame

Don't know what version you are on, but make sure you look at this guide as some items are specific if using FlexConnect.

Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE Dublin 17.10.x - 802.11r BSS Fast Transition [Cisco Catalyst 9800 Series Wireless Controllers] - Cisco

-Scott
*** Please rate helpful posts ***

Hi

Thanks for the reply. I am using 17.10.1, yes with WPA3

Am I understanding correctly this document implies, that for .11r and dot1x+ft I need to use only local auth. Now I have central auth, with local switching flexconnect?

Kalin Hristov
Level 1
Level 1

Okay,

I found the problem. I just created a new site tag and assigned the APs to it. For some reason, the WLC does not want to propagate .11r information to default site tag 

Rich R
VIP
VIP

That's a general rule with 9800 ...
https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/guide-c07-743627.html#Designingwithsitetagsinmind
1.     Use custom site tags and not the default site tag

Make sure you're familiar with everything in that guide.

For large deployments, yes

But I don't see anywhere in this document, that if I use default site tag, the controller will not propagate cache information

Review Cisco Networking for a $25 gift card