cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
484
Views
6
Helpful
14
Replies

FlexConnect user disconnected after the AP disjoined the WLC

qsosan20
Level 1
Level 1

Hello Expert ,

As per my understanding the FlexConnect with central auth and local switch , will keep the clients "thats already authenticated" connected , however i had the situation where already authenticated users were disconnected from AP when AP disjoined the WLC ,

with the reason : 
CO_CLIENT_DELETE_REASON_CAPWAP_DOWN

Can you please confirm if this is the expected behavior or not  ?

I will attach the logs during the issue for your reference .

14 Replies 14

marce1000
Hall of Fame
Hall of Fame

 

   - @qsosan20                             Probably shouldn't happen :
                                 1)  Check if the AP really is in flexconnect mode
                                 2)  Enable syslog messages for APs and controller according to :
                                           https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/b_wl_16_10_cg/enabling-syslog-messages-in-access-points-and-controller-for-syslog-server.html
                                                   Then check the logs on the AP and controller
                                3)   Get more info's from : https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#toc-hId-866973845
                                4) Check the controller software version and or are you on a recent release ?

    You didn't attach any logs

   M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

marce1000
Hall of Fame
Hall of Fame

 

  - @qsosan20    Last but not least ; checkout & validate the 9800 WLC configuration using the CLI command
                           show tech wireless and feed the output from that into Wireless Config Analyzer

  M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

This log from wlc or AP

If it from wlc then it normal

If it from AP  then it not normal' client must be connected until session timeout end 

MHM

Rich R
VIP
VIP

What model of WLC @qsosan20 ?
What model of AP?
What version of software?
What are the complete details of the WLAN? You confirmed central auth, local switch - but what about DHCP, what type of auth and other features are you using on that WLAN?  It's a complex interplay of features and many features will not allow clients to remain connected on central auth WLAN in standalone mode?

https://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/112042-technote-wlc-00.html
For example MAC Filtering is not supported on FlexConnect access points in standalone mode.

qsosan20
Level 1
Level 1

Logs are from WLC attached,
WLC version and model : C9800-CL-K9 , 17.03.05b

AP version and model : C9115AXI-I , 17.3.5.43

WLAN Auth type : WPA2 , 802.1X
WLAN : central Auth , local switching , local DHCP

It ok then 

Wlc can not anymore monitor client session so it delete client info when capwap down

The wifi client must continue connect 

MHM

Make sense as logs from WLC ,

But does not make sense the client disconnected from AP , i have to enable AP debugs based on your suggestions during the issue to check what's happening as WLC logs are not that helpful ,

Yes reason of disassociate of client are

1- the wifi client doing roaming 

2- the wifi client need to re-auth' and since wlc capwap is down the auth failed and it disassociate 

MHM

Agreed @qsosan20  - you need AP client debugs (not WLC) and we need to see the complete WLAN and Profile Policy config to see what features are being used for that SSID.

 

 - @qsosan20                 >....WLC version and model : C9800-CL-K9 , 17.03.05b
                              The   controller software version is way too old  ; you should upgrade to a current advisory such
                              as 17.12.5

                              Also I had WLC-Logs.txt processed with WLC version and model : Wireless Debug Analyzer
                              (result attached)
                              One message I noted : client deleted due to capwap tunnel failure.
                              That could be an intermediate  issue (BUG)  not directly related to flexconnect , so that combined with the controller software version being too old   ==> UPGRADE FIRST ,!
  
   M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Agreed with @marce1000 you should not be trying to troubleshoot on 17.3 which was known for having a lot of bugs and is rapidly approaching last date of support and is already well past most milestones:
https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-xe-17/ios-xe-17-3-x-eol.html

orwin01
Level 1
Level 1

Yes, this is expected. When the AP disconnects from the WLC, authenticated clients can be dropped due to the CAPWAP tunnel going down.

This should not happen for FlexConnect Clients ,

This should not happen for FlexConnect Clients ,
Unless you're using a feature which is not supported in standalone mode.

Review Cisco Networking for a $25 gift card