cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3453
Views
35
Helpful
5
Replies

DNA Center, wireless clients show Broadcast rekey failed messages

Philip Bosman
Level 1
Level 1

Hi, we are fairly new started with DNA Center and have been using Prime Infrastructure in parallel. What we see in DNA Center version 2.3.3.6 on 5520 WLC using 8.10.171 with 9120 APs that clients show broadcast rekey failed, we are using a WPA2 PSK but als WPA2 802.1X SSIDs. Some clients seem to show this almost every hour repeatedly, but same type of clients in the same environment only show every now and then these messages. There are multiple type of clients that show these messages where the clients don't report issues. It seems to be a cosmetic issue. 

PhilipBosman_0-1665048205376.png

Over time the red dots in the graph represent the rekey failed messages.

PhilipBosman_1-1665048232237.png

I cannot find any reports or additional information what this actually is so we created a case with our supplier to investigate, any other experience someone ?

5 Replies 5

JPavonM
VIP
VIP

I've been suffering these kind of EAP/EAPOL timeouts with some Mediatek chipsets MT7920/7921 using different driver versions (not seen on Intel), and the only way I've managed to stop from users complaining aboud disconnection (due to rekeying and M5-key timeouts) was to incrase EAP timeout manually on the C9800 with this command. This way, a rekey does not happen during business hours, unless a device keeps connected to the network for a whole day.

wireless security dot1x group-key interval 54000

Rich R
VIP
VIP

@JPavonM that looks like an IOS-XE command for 9800 but Philip says he's using AireOS 8.10.171.0 on 5520?

JPavonM
VIP
VIP

Sorry, as @Rich R mentioned that was for IOS-XE, this is for AireOS:

config advanced eap bcast-key-interval 54000

 

This would mean the failed message would occur on the regular rekey interval. Don't know if i mentionded that the client stays connected by theway. The thing is I upgraded one of these devices with a new firmware, and I don't see them anymore on that device. 

JPavonM
VIP
VIP

That's correct, this kind of issues happen on the client side so upgrading drivers/firmware is always the best way.

Review Cisco Networking for a $25 gift card