cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
638
Views
0
Helpful
2
Replies

Mac Computers w/ Radius

Hello!

I'm receiving the following syslog messages on my WLC (WiSM2): " *dot1xMsgTask: Dec 04 11:51:53.944: %DOT1X-3-MAX_EAP_RETRIES:

1x_auth_pae.c:3136 Max EAP identity request retries (3) exceeded for XX:XX:XX:XX:XX " and it's for all of my Mac OSX users. I'm using Windows Server 2008 R2 as a Radius server and PEAP for auth. Any ideas ? Thanks!!

2 Replies 2

Saurav Lodh
Level 7
Level 7
  • EAP-Identity-Request Max Retries:

    The Max Retries value is the number of times the WLC will send the Identity Request to the client, before removing its entry from the MSCB. Once the Max Retries is reached, the WLC sends a de-authentication frame to the client, forcing them to restart the EAP process. Available value is 1 to 20.

    **The Max Retries works with the Identity Timeout. If you have your Identity Timeout set to 120, and your Max Retries to 20 how long does it takes 2400 (or 120 * 20). This means it would take 40 minutes for the client to be removed, and to start the EAP process over again. If you set the Identity Timeout to 5, with a Max Retries value of 12, then it will take 60 (or 5 * 12).

    Recommendations for the Max Retries is 12.

mohanak
Cisco Employee
Cisco Employee
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card