08-15-2013 12:09 PM - edited 07-04-2021 12:39 AM
Hello everyone I hope you can help me because I really need it.
I have two WLC 5508 and some AP's 1131 and 3602. I don't know why but my clients are lossing connection to WLAN here some logs from WLC.
[01:51:55 p.m.] Jonatan Sosa Franco: dot1xMsgTask: Aug 15 18:49:29.829: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:456 Max EAPOL-key M1 retransmissions exceeded for client 18:20:32:34:1c:42
*dot1xMsgTask: Aug 15 18:49:14.629: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:456 Max EAPOL-key M1 retransmissions exceeded for client 18:20:32:34:1c:42
*dot1xMsgTask: Aug 15 18:48:57.629: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:456 Max EAPOL-key M1 retransmissions exceeded for client 18:20:32:34:1c:42
*dot1xMsgTask: Aug 15 18:48:07.225: %DOT1X-3-MAX_EAP_RETRIES: 1x_auth_pae.c:3136 Max EAP identity request retries (3) exceeded for client 68:7f:74:68:2c:91
*dot1xMsgTask: Aug 15 18:46:35.421: %DOT1X-3-MAX_EAP_RETRIES: 1x_auth_pae.c:3136 Max EAP identity request retries (3) exceeded for client 00:23:14:bc:f4:c4
*spamApTask4: Aug 15 18:46:27.305: %CAPWAP-3-SEM_RELEASE_ERR: capwap_ac_db.c:103 The system could not release exclusive access of AP entry for 84:78:ac:c0:87:30 in the database
*spamApTask4: Aug 15 18:46:26.615: %LWAPP-3-RD_ERR6: spam_lrad.c:9849 APs (84:78:ac:c0:87:30) regulatory domain (-N) is not supported in country (US ), slot 80211a (1) supports -A
*apfReceiveTask: Aug 15 18:46:26.370: %RRM-3-RRM_LOGMSG: rrmChanUtils.c:289 RRM LOG: Airewave Director: Could not find valid channel lists for 802.11bg
*dot1xMsgTask: Aug 15 18:45:57.421: %DOT1X-3-MAX_EAP_RETRIES: 1x_auth_pae.c:3136 Max EAP identity request retries (3) exceeded for client 5c:e2:f4:f7:d1:72
*dot1xMsgTask: Aug 15 18:44:16.621: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:456 Max EAPOL-key M1 retransmissions exceeded for client cc:55:ad:6d:8f:47
*apfMsConnTask_3: Aug 15 18:44:13.455: %APF-3-CHECK_SUPP_RATES_FAILED: apf_utils.c:203 Could not check supported rates. Invalid Supported Rates from station . Length :0. Mobile MAC: cc:55:ad:6d:8f:47.
*dot1xMsgTask: Aug 15 18:43:33.221: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:456 Max EAPOL-key M1 retransmissions exceeded for client 18:20:32:34:1c:42
*dot1xMsgTask: Aug 15 18:43:18.222: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:456 Max EAPOL-key M1 retransmissions exceeded for client 18:20:32:34:1c:42
*dot1xMsgTask: Aug 15 18:43:15.021: %DOT1X-3-MAX_EAP_RETRIES: 1x_auth_pae.c:3136 Max EAP identity request retries (3) exceeded for client 00:23:6c:1c:63:36
*dot1xMsgTask: Aug 15 18:43:02.621: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:456 Max EAPOL-key M1 retransmissions exceeded for client 18:20:32:34:1c:42
*Dot1x_NW_MsgTask_6: Aug 15 18:42:35.732: %DOT1X-3-MAX_EAP_RETRIES: 1x_auth_pae.c:3136 Max EAP identity request retries (3) exceeded for client 00:13:02:3d:e7:f6
*Dot1x_NW_MsgTask_6: Aug 15 18:42:35.732: %DOT1X-3-ABORT_AUTH: 1x_bauth_sm.c:447 Authentication Aboted for client 00:13:02:3d:e7:f6
*dot1xMsgTask: Aug 15 18:42:26.821: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:456 Max EAPOL-key M1 retransmissions exceeded for client f4:0b:93:a5:f5:2f
*apfMsConnTask_7: Aug 15 18:42:23.606: %APF-3-CHECK_SUPP_RATES_FAILED: apf_utils.c:203 Could not check supported rates. Invalid Supported Rates from station . Length :0. Mobile MAC: f4:0b:93:a5:f5:2f.
*Dot1x_NW_MsgTask_6: Aug 15 18:42:05.699: %DOT1X-3-AAA_AUTH_SEND_FAIL: 1x_aaa.c:597 Unable to send AAA message for client 00:13:02:3d:e7:f6
*Dot1x_NW_MsgTask_6: Aug 15 18:42:05.697: %DOT1X-3-ABORT_AUTH: 1x_bauth_sm.c:447 Authentication Aboted for client 00:13:02:3d:e7:f6
*dot1xMsgTask: Aug 15 18:42:05.621: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:456 Max EAPOL-key M3 retransmissions exceeded for client 00:13:02:3d:e7:f6
*dot1xMsgTask: Aug 15 18:40:25.221: %DOT1X-3-MAX_EAP_RETRANS: 1x_ptsm.c:475 Max EAP retransmissions exceeded for client 18:e7:f4:7c:3b:88
*webauthRedirect: Aug 15 18:40:06.377: %EMWEB-3-READ_ERROR: webauth_redirect.c:938 read error on server socket
*dot1xMsgTask: Aug 15 18:39:51.621: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:456 Max EAPOL-key M1 retransmissions exceeded for client 18:20:32:34:1c:42
*dot1xMsgTask: Aug 15 18:39:36.621: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:456 Max EAPOL-key M1 retransmissions exceeded for client 18:20:32:34:1c:42
*dot1xMsgTask: Aug 15 18:39:19.821: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:456 Max EAPOL-key M1 retransmissions exceeded for client 18:20:32:34:1c:42
*dot1xMsgTask: Aug 15 18:39:16.221: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:456 Max EAPOL-key M1 retransmissions exceeded for client 4c:b1:99:ed:f3:5e
*dot1xMsgTask: Aug 15 18:39:02.021: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:456 Max EAPOL-key M1 retransmissions exceeded for client 4c:b1:99:ed:f3:5e
*dot1xMsgTask: Aug 15 18:38:47.621: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:456 Max EAPOL-key M1 retransmissions exceeded for client 4c:b1:99:ed:f3:5e
*dot1xMsgTask: Aug 15 18:38:45.821: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:456 Max EAPOL-key M1 retransmissions exceeded for client cc:55:ad:6d:8f:47
*apfMsConnTask_5: Aug 15 18:38:42.748: %APF-3-CHECK_SUPP_RATES_FAILED: apf_utils.c:203 Could not check supported rates. Invalid Supported Rates from station . Length :0. Mobile MAC: cc:55:ad:6d:8f:47.
*spamApTask3: Aug 15 18:38:34.872: %CAPWAP-3-SEM_RELEASE_ERR: capwap_ac_db.c:103 The system could not release exclusive access of AP entry for 84:78:ac:c0:87:30 in the database
*spamApTask3: Aug 15 18:38:34.185: %LWAPP-3-RD_ERR6: spam_lrad.c:9849 APs (84:78:ac:c0:87:30) regulatory domain (-N) is not supported in country (US ), slot 80211a (1) supports -A
*apfReceiveTask: Aug 15 18:38:33.938: %RRM-3-RRM_LOGMSG: rrmChanUtils.c:289 RRM LOG: Airewave Director: Could not find valid channel lists for 802.11bg
*apfMsConnTask_6: Aug 15 18:36:23.285: %APF-3-CHECK_SUPP_RATES_FAILED: apf_utils.c:203 Could not check supported rates. Invalid Supported Rates from station . Length :0. Mobile MAC: 80:60:07:fd:d4:f0.
*Dot1x_NW_MsgTask_3: Aug 15 18:36:05.902: %DOT1X-3-INVALID_REPLAY_CTR: 1x_eapkey.c:360 Invalid replay counter from client c4:85:08:89:f3:9b - got 00 00 00 00 00 00 00 01, expected 00 00 00 00 00 00 00 00
*dot1xMsgTask: Aug 15 18:35:41.817: %DOT1X-3-MAX_EAP_RETRANS: 1x_ptsm.c:475 Max EAP retransmissions exceeded for client 74:e1:b6:92:65:09
*apfMsConnTask_6: Aug 15 18:35:18.777: %APF-3-CHECK_SUPP_RATES_FAILED: apf_utils.c:203 Could not check supported rates. Invalid Supported Rates from station . Length :0. Mobile MAC: 80:60:07:fd:d4:f0.
*dot1xMsgTask: Aug 15 18:35:12.817: %DOT1X-3-MAX_EAP_RETRIES: 1x_auth_pae.c:3136 Max EAP identity request retries (3) exceeded for client 30:17:c8:43:0c:2d
*apfMsConnTask_5: Aug 15 18:34:12.772: %APF-3-CHECK_SUPP_RATES_FAILED: apf_utils.c:203 Could not check supported rates. Invalid Supported Rates from station . Length :0. Mobile MAC: 30:17:c8:43:0c:2d.
*dot1xMsgTask: Aug 15 18:33:58.217: %DOT1X-3-MAX_EAP_RETRIES: 1x_auth_pae.c:3136 Max EAP identity request retries (3) exceeded for client 5c:e2:f4:f7:d1:72
*dot1xMsgTask: Aug 15 18:33:49.217: %DOT1X-3-MAX_EAP_RETRANS: 1x_ptsm.c:475 Max EAP retransmissions exceeded for client c8:6f:1d:04:5d:5a
*apfMsConnTask_5: Aug 15 18:33:17.082: %APF-3-CHECK_SUPP_RATES_FAILED: apf_utils.c:203 Could not check supported rates. Invalid Supported Rates from station . Length :0. Mobile MAC: 30:17:c8:43:0c:2d.
*dot1xMsgTask: Aug 15 18:31:53.617: %DOT1X-3-MAX_EAP_RETRIES: 1x_auth_pae.c:3136 Max EAP identity request retries (3) exceeded for client 5c:e2:f4:f7:d1:72
*dot1xMsgTask: Aug 15 18:31:06.017: %DOT1X-3-MAX_EAP_RETRANS: 1x_ptsm.c:475 Max EAP retransmissions exceeded for client 88:53:2e:0f:99:66
*spamApTask4: Aug 15 18:29:18.178: %CAPWAP-3-SEM_RELEASE_ERR: capwap_ac_db.c:103 The system could not release exclusive access of AP entry for 84:78:ac:c0:87:30 in the database
*spamApTask4: Aug 15 18:29:17.491: %LWAPP-3-RD_ERR6: spam_lrad.c:9849 APs (84:78:ac:c0:87:30) regulatory domain (-N) is not supported in country (US ), slot 80211a (1) supports -A
*apfReceiveTask: Aug 15 18:29:17.246: %RRM-3-RRM_LOGMSG: rrmChanUtils.c:289 RRM LOG: Airewave Director: Could not find valid channel lists for 802.11bg
Regards...
Solved! Go to Solution.
08-15-2013 01:53 PM
Yes I would. This is how you setup PEAP and EAP-TLS on any radius.
Sent from Cisco Technical Support iPhone App
08-15-2013 02:06 PM
although I'm using ISE for Auth ?
08-15-2013 08:53 PM
Can you do a >show 802.11b on both controller and post
I noticed this:
*apfMsConnTask_7: Aug 15 18:42:23.606: %APF-3-CHECK_SUPP_RATES_FAILED: apf_utils.c:203 Could not check supported rates. Invalid Supported Rates from station . Length :0. Mobile MAC: f4:0b:93:a5:f5:2f.
__________________________________________________________________________________________
"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
__________________________________________________________________________________________
"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."
08-16-2013 05:52 AM
ok let me get this information ASAP and I let you know George
08-22-2013 06:28 AM
Hello Scott /George
I changed PEAP way authe and still having this problem. By the way I disable the speed 1,2,5.5, 11 for 802.11b devices keep out of the WLAN.
08-22-2013 06:39 AM
Post your show WLAN
Sent from Cisco Technical Support iPhone App
08-22-2013 06:43 AM
Let me get access to the WLC and I will
09-12-2013 07:07 PM
Hello Scott/Guys
Well finally tomorrow I will able to acces to WLC and I decided to start to new configuration. And I'm going to use wpa + wpa2 auth metod.
Clients still are disconnected so I have one questions I know I can do a backup trough cli. and I can paste this configuration if it would be necessary.
Does anyone wich is this command?
Thanks
09-12-2013 07:48 PM
"show run-config commands" will give you the most of config as configured
09-12-2013 07:53 PM
and when I get the output I can just paste it and It will working? or you think uploading downloading config is the best option?
09-12-2013 07:58 PM
Above will give most of the configured command (without advanced configuration). If you can taka a backup via TFTP that will be everything & best if you could have that.
Here is how you could take a backup via CLI.
transfer upload datatype config
transfer upload mode tftp
transfer upload serverip x.x.x.x <-TFTP server IP
transfer upload path .
transfer upload filename WLC-BACKUP.txt <- filename
transfer upload start
y
If you are restoring a backup always get config via TFTP & then download it to another controller
http://mrncciew.com/2013/01/25/backup-restore-wlc-configs/
HTH
Rasika
09-12-2013 08:11 PM
The show run-config commands will give you the commands, but you can't paste them as is. They are not in the proper order so some commands will fail. If you want to start clean, then start clean without doing a restore. Don't paste the show run-config command if you don't understand the commands as it will give you more issues. Build it from scratch.
Sent from Cisco Technical Support iPhone App
09-13-2013 06:30 AM
Ok I'm on my way to the site I will let you know.
Thanks
09-13-2013 09:08 AM
I noticed this in your log:
*spamApTask4: Aug 15 18:29:17.491: %LWAPP-3-RD_ERR6: spam_lrad.c:9849 APs (84:78:ac:c0:87:30) regulatory domain (-N) is not supported in country (US ), slot 80211a (1) supports -A
Is your controller in -A? I am not sure why this AP is reporting as it is from -N regulatory domain.
09-14-2013 11:29 PM
Hi Scott/Vlad
Well I checked the wlc configuration and yes the RF domain it was wrong, so I changed it to Mexico code.
I checked the 802.1x configuration and I changed it how Scott told me. I noticed too that 3 SSID were sharing the same dynamic Interface, so we created one interface for SSID and we created DHCP server for every SSID.
Our client will check the service next week, but I'm not sure if this issues could been the problem for this desconnection.
One intersting thing was that the client told me after I changed the RF Domain the cover area was improve it.
What do you think guys?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide