cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1009
Views
3
Helpful
7
Replies

Macbook - WLC9800/9130AX APs

PATRICK HARRIS
Level 4
Level 4

Seeing an issue with a couple of clients(Apple and Windows) connecting to SSIDs with WPA2+WPA3 and 802.1x authentication. Have recently migrated to a new WLC9800 with 9130AX APs. Clients appear to connect to the AP but then disconnects. Does not get to the RUN state for policy manager state, does not get an IP and no log messages appearing in the ISE Radius logs. Any input would be great.

7 Replies 7

Leo Laohoo
Hall of Fame
Hall of Fame

What does the authentication server say?

What firmware is the controller on?

There is no log messages generated.

Controller is on IOS 17.6.4

Bounce the AP.

marce1000
VIP
VIP

 

 - You can debug clients with https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity , client debugs can be analyzed with https://cway.cisco.com/tools/WirelessDebugAnalyzer/ , also review the controller configuration with https://cway.cisco.com/tools/WirelessAnalyzer/ , this tool needs the output of CLI show  tech wireless ,

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

marce1000
VIP
VIP

 

  -  Besides reply already given , also not that you can do online monitoring for a particular client with :
                                 monitor logging profile wireless filter mac <CLIENT MAC>
     (issue the command first and then let the particular client connect to the SSID)
Note that if you know the AP the client is connecting to then on the particular  AP  you can also use this command :
                                        show ap client-trace events mac <CLIENT MAC>

 Appendix : 
     You can debug clients with https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity , client debugs can be analyzed with https://cway.cisco.com/tools/WirelessDebugAnalyzer/ , also review the controller configuration with https://cway.cisco.com/tools/WirelessAnalyzer/ , this tool needs the output of CLI show  tech wireless ,

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Scott Fella
Hall of Fame
Hall of Fame

Don't use this unless you know that you are trying to transition to WPA3.  This can cause issue with devices that do not support WPA3.  WAP+WPA2 is what you should use.

-Scott
*** Please rate helpful posts ***

WAP or WPA @Scott Fella lol (obviously WPA folks)?

More seriously though - like Scott says some devices and some older drivers get confused by the WPA3 IE's so make sure all drivers are 100% up to date for a start.  Some devices that can't be updated will never work with WPA3 enabled.

Review Cisco Networking for a $25 gift card