12-04-2013 03:23 PM - last edited on 03-09-2022 11:25 PM by smallbusiness
Hello!
I'm receiving the following syslog messages on my WLC (WiSM2): " *dot1xMsgTask: Dec 04 11:51:53.944: %DOT1X-3-MAX_EAP_RETRIES:
1x_auth_pae.c:3136 Max EAP identity request retries (3) exceeded for XX:XX:XX:XX:XX " and it's for all of my Mac OSX users. I'm using Windows Server 2008 R2 as a Radius server and PEAP for auth. Any ideas ? Thanks!!
07-11-2014 04:16 AM
EAP-Identity-Request Max Retries:
The Max Retries value is the number of times the WLC will send the Identity Request to the client, before removing its entry from the MSCB. Once the Max Retries is reached, the WLC sends a de-authentication frame to the client, forcing them to restart the EAP process. Available value is 1 to 20.
**The Max Retries works with the Identity Timeout. If you have your Identity Timeout set to 120, and your Max Retries to 20 how long does it takes 2400 (or 120 * 20). This means it would take 40 minutes for the client to be removed, and to start the EAP process over again. If you set the Identity Timeout to 5, with a Max Retries value of 12, then it will take 60 (or 5 * 12).
Recommendations for the Max Retries is 12.
07-18-2014 05:11 AM
Please refer the link :
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: