07-09-2025 08:20 AM
Hello Expert ,
As per my understanding the FlexConnect with central auth and local switch , will keep the clients "thats already authenticated" connected , however i had the situation where already authenticated users were disconnected from AP when AP disjoined the WLC ,
with the reason :
CO_CLIENT_DELETE_REASON_CAPWAP_DOWN
Can you please confirm if this is the expected behavior or not ?
I will attach the logs during the issue for your reference .
07-09-2025 09:24 AM
- @qsosan20 Probably shouldn't happen :
1) Check if the AP really is in flexconnect mode
2) Enable syslog messages for APs and controller according to :
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/b_wl_16_10_cg/enabling-syslog-messages-in-access-points-and-controller-for-syslog-server.html
Then check the logs on the AP and controller
3) Get more info's from : https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#toc-hId-866973845
4) Check the controller software version and or are you on a recent release ?
You didn't attach any logs
M.
07-09-2025 09:28 AM
- @qsosan20 Last but not least ; checkout & validate the 9800 WLC configuration using the CLI command
show tech wireless and feed the output from that into Wireless Config Analyzer
M.
07-09-2025 09:36 AM
This log from wlc or AP
If it from wlc then it normal
If it from AP then it not normal' client must be connected until session timeout end
MHM
07-10-2025 07:13 AM
What model of WLC @qsosan20 ?
What model of AP?
What version of software?
What are the complete details of the WLAN? You confirmed central auth, local switch - but what about DHCP, what type of auth and other features are you using on that WLAN? It's a complex interplay of features and many features will not allow clients to remain connected on central auth WLAN in standalone mode?
https://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/112042-technote-wlc-00.html
For example MAC Filtering is not supported on FlexConnect access points in standalone mode.
07-11-2025 04:35 AM
07-11-2025 04:38 AM
It ok then
Wlc can not anymore monitor client session so it delete client info when capwap down
The wifi client must continue connect
MHM
07-11-2025 04:42 AM
Make sense as logs from WLC ,
But does not make sense the client disconnected from AP , i have to enable AP debugs based on your suggestions during the issue to check what's happening as WLC logs are not that helpful ,
07-11-2025 04:46 AM
Yes reason of disassociate of client are
1- the wifi client doing roaming
2- the wifi client need to re-auth' and since wlc capwap is down the auth failed and it disassociate
MHM
07-11-2025 05:01 AM
Agreed @qsosan20 - you need AP client debugs (not WLC) and we need to see the complete WLAN and Profile Policy config to see what features are being used for that SSID.
07-11-2025 07:05 AM
- @qsosan20 >....WLC version and model : C9800-CL-K9 , 17.03.05b
The controller software version is way too old ; you should upgrade to a current advisory such
as 17.12.5
Also I had WLC-Logs.txt processed with WLC version and model : Wireless Debug Analyzer
(result attached)
One message I noted : client deleted due to capwap tunnel failure.
That could be an intermediate issue (BUG) not directly related to flexconnect , so that combined with the controller software version being too old ==> UPGRADE FIRST ,!
M.
07-11-2025 07:29 AM
Agreed with @marce1000 you should not be trying to troubleshoot on 17.3 which was known for having a lot of bugs and is rapidly approaching last date of support and is already well past most milestones:
https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-xe-17/ios-xe-17-3-x-eol.html
07-11-2025 04:38 AM
Yes, this is expected. When the AP disconnects from the WLC, authenticated clients can be dropped due to the CAPWAP tunnel going down.
07-11-2025 04:43 AM
This should not happen for FlexConnect Clients ,
07-11-2025 05:02 AM
> This should not happen for FlexConnect Clients ,
Unless you're using a feature which is not supported in standalone mode.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide