08-01-2008 06:28 AM - edited 07-03-2021 04:16 PM
Hello NetPro gurus!
I am currently troubleshooting an issue we are having with our Guest (completely open) WLAN in which it seems certain clients are losing their layer 3 connectivity while staying 'connected' to the LWAP(s). These certain clients lose their layer 3 configuration and are not able to access internal or external resources until they disable/enable their wireless connection.
I specifically have this problem, and it's only on the Guest WLAN that this occurs. I am using a Lenovo T61 with an Intel 4965AG internal wireless chipset. I know this chipset is relatively new and I have tried multiple drivers, all with the same result. Not all machines have this issue. MacPro laptops do not seem to have this issue nor do machines with Intel Pro 2200BG chipsets. I tested with a Netgear PCMCIA card and did not have this issue either.
Here's some more background information:
We have 5 WLCs (2 WiSM blades each in a Catalyst 6509 and 1 WLC 4402) and 7 WLANs. The 4 WiSM controllers have each WLAN configured on it, and the 4402 WLC only knows about one Guest wireless network (it is a completely open WLAN i.e. no security). This is the particular network we see this issue with. We have approximately 200 LWAP 1131AG's (47 in one building, 154 in another) all broadcasting the Guest SSID. Our server core Catalyst 6509's each have seperate VLANs (with Port-channels in them) for the WiSM blades. The Guest WLC 4402 is in the DMZ in its own VLAN. Each WLC is providing DHCP for each of the WLANs.
The issue that seems to be occuring is the fact that during our troubleshooting I lose all layer 3 connectivity. I continue to stay "connected" to the AP and signal strength is excellent however my continuous pings to the Guest WLC (192.168.0.x network) time out and I cannot get out to the Web. I noticed the following error on my laptop (Lenovo T61 w/ an Intel 4965AG wireless chipset) in the system event viewer:
Description:
The system detected that network adapter Intel(R)...Link 4965AG - Packet Scheduler Miniport was disconnected from the network, and the adapter's network configuration has been released. If the network adapter was not disconnected, this may indicate that it has malfunctioned. Please contact your vendor for updated drivers.
This occured at the exact time I lost my layer 3 connectivity. A co-worker and I did some research and determined that this was exactly one half of the way through my 1-hour DHCP lease from the Guest WLC (the 4402). The DHCP leases are set to expire at 1 hour as we have a lot of clients on the Guest WLAN that come and go and only have one network configured for the Guest WLAN w/ 229 available IP's to be handed out. We were wondering if it was an issue with the DHCP renewal process from the WLC. This does not occur on the Internal WLANs configured with strict authentication security.
We tested with a few machines, such as an Apple laptop, an older laptop with an Intel Pro 2200BG chipset, and even my same laptop with a Netgear PCMCIA WiFi card none of which exhibited this problem. Connectivity at layer 3 was not interrupted. I have tried multiple drivers as well, all with the same result.
Now, we are not sure if it is an issue with the WLC itself or a chipset issue. The Intel 4965AG chipset is rather new but we have a lot of WLAN clients with this chipset on the network. That also doesn't explain why this issue ONLY occurs on the Guest WLAN.
We were thinking of placing a small DHCP server on the network to take over DHCP responsibilities from the Guest WLC to see if that makes a difference. Another idea we had was to increase the DHCP scope to two Class B networks (191.168.0.0 - 191.168.1.255 /23 to give us 510 hosts so we can extend the DHCP lease time).
I plan on doing further testing today by placing a few more machines on the Guest WLAN with multiple chipsets and taking note of which ones exhibit the problem.
Any and all help is MUCH appreciated. Thanks!
Shane
Solved! Go to Solution.
08-20-2008 01:17 PM
Brian - that seems to have fixed my problem as well. I set it to 60 on one of our WiSM controllers to which the particular AP I was associated to was registered. I saw the problem occur in 30 seconds. I have then set it to 65535 and am testing again, however I am convinced that was the case. Something with these Intel chipsets and the timeout value was screwing with the DHCP renewal.
THANKS!
Shane
03-06-2009 07:30 AM
same issue here.. i'll try setting it to 65535 and see if it resolves the issue.. did you set the timers on all the WLC's, ie the local WLC & Anchor WLC ??
Raj
03-06-2009 07:35 AM
Hi Raj -
I set that timer number on all WLC's that support the WLAN in question. In this case, it was the Guest WLAN which was configured over 4 WiSM's and a 4402.
I'm curious if this helps you as well. Let me know.
Shane
03-06-2009 08:03 AM
Shane
you had changed the session timeout right (default 1800) ? not the client exclusion timeout , which is defaulted to 60 secs ? I have increased the session timeout to 3600, instead of putting it to 65535.. do u think this would work ?
and i also saw a bug in 5.1.163 which relates to our problem:
CSCsq26446-Clients using a WLAN with web authentication enabled might disconnect every 5 minutes. The "pem timed out" message appears in the controller logs.
Workaround: Authenticate the clients using another WLAN.
03-06-2009 12:06 PM
Yes, the session timeout. I would suspect that changing your value to 3600 would delay this issue from occuring, but if it completely resolves the problem is dependent on how long your wireless users are connected at any given time. The workaround for that bug wouldn't help me in my scenario as we only have one guest WLAN. The others are internal 802.1x-secured WLANs.
03-06-2009 12:10 PM
Yeah... with 3600, the client was connected for 1 hour 4 mins, before getting disconnected... this seems really strange to me ! now, I have increased this to 65535.. lets see.. but the security team isnt going to accept 65535 value for sure :) he he..
Has this bug been resolved in any of the latest IOS trains ? Did Cisco TAC answer you on this ? The other bug that I had shown in my previous post, hasnt been solved till 5.2.178 !!!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide