06-23-2020 04:03 PM - edited 07-05-2021 12:12 PM
Hi,
we´ve a SSID with 802.1x authentication. Windows Devices needs a little bit time, but works fine.
iPhones need two tries to connect. On the first try you can see nothing with debug client <MAC>
it looks like the iPhone do nothing, but on the device you can see that the iphones try to connect.
At the end of the first try you get the following:
apfOpenDtlSocket: Jun 23 22:51:05.572: 78:4f:43:1c:a1:5d Received management frame ACTION on BSSID mac adr destination addr mac adr
*apfMsConnTask_0: Jun 23 22:51:05.572: 78:4f:43:1c:a1:5d Received management action frame (category code:5) from the client.
*apfMsConnTask_0: Jun 23 22:51:05.572: 78:4f:43:1c:a1:5d Found RM action category code
*apfOpenDtlSocket: Jun 23 22:51:19.799: 78:4f:43:1c:a1:5d Received management frame ACTION on BSSID mac adr destination addr mac adr
*apfMsConnTask_0: Jun 23 22:51:19.799: 78:4f:43:1c:a1:5d Received management action frame (category code:6) from the client.
*apfMsConnTask_0: Jun 23 22:51:19.799: 78:4f:43:1c:a1:5d no PMK cache entry for this client. Can't do preauth.
*apfOpenDtlSocket: Jun 23 22:51:21.161: 78:4f:43:1c:a1:5d Received management frame DISASSOC on BSSID mac adr destination addr mac adr
*apfOpenDtlSocket: Jun 23 22:51:23.943: 78:4f:43:1c:a1:5d Received management frame ASSOCIATION REQUEST on BSSID mac adr destination addr mac adr
*apfMsConnTask_0: Jun 23 22:51:23.943: 78:4f:43:1c:a1:5d Updating 11r vendor IE
After that the iPhone stops to try wait one second and then it tries again. And after one second it works and you can see the normal authentication process in the debug.... Sometimes we will receive an error message between the first and the second try "Error, unable to connect to <SSID>"
I´ve try many things, but without any solution.
- Disable FT
- Disable 802.11k
- Disable 2,4GHz
- try different Radius Server (the radius works fine)
- try different iphones with different IOS Versions
I´ve no more ideas. Can anyone help me ?
Thanks a lot M
Solved! Go to Solution.
08-19-2020 08:13 AM
Hi,
after long time with many debug sessions together with cisco we found the solution:
It was a combination of newer iOS Versions on the Apple devices and a bug in the WLC OS.
IOS Versions older than 13 or older AP´s (1700/2700) works fine, but IOS13+ and AP´s 1852 make many problems.
With an other version of the WLC OS everything works fine....
06-23-2020 11:49 PM
Hi,
Enable Fast SSID Change if not enabled and try again.
Regards
Dont forget to rate helpful posts
06-24-2020 12:54 AM
Hi,
FAST SSID CHANGE is already enabled....
BR M
07-02-2020 02:20 PM
I´ve done some more troubleshooting.
What I can see, that the WLC requests via EAP Authetication information but the iPhone doesn´t answer.
After 3 times the Iphone sends a dissac and an assoc packet and it works fine....
does anyone have an idea ?
07-02-2020 03:52 PM
08-19-2020 08:13 AM
Hi,
after long time with many debug sessions together with cisco we found the solution:
It was a combination of newer iOS Versions on the Apple devices and a bug in the WLC OS.
IOS Versions older than 13 or older AP´s (1700/2700) works fine, but IOS13+ and AP´s 1852 make many problems.
With an other version of the WLC OS everything works fine....
01-22-2022 06:11 PM
Hello, I know this is an old trend, but I have a similar problem, could you tell me which version of WLC is the one with the bug?
01-24-2022 01:52 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide