cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
544
Views
2
Helpful
3
Replies

PEAP Client Authentication Problem WLC 9800 AP9115 Flex connect mode

friedelkg
Level 1
Level 1

Hi,

we have a problem with client authentication

I started "debug client [MAC] on AP, but I can't find any output despcription.

debug client a893.4a02.c15f
[1718176130:834361] [LDBV-Freyung-38] [a8:93:4a:02:c1:5f] <apr0v0> [U:W] DOT11_AUTHENTICATION : (.)
CLSM[A8:93:4A:02:C1:5F]: US Auth(b0) seq 4 IF 23 slot 0 vap 0 len 30 state NULL
CLSM[A8:93:4A:02:C1:5F]: DS Auth len 30 slot 0 vap 0
CLSM[A8:93:4A:02:C1:5F]: Driver send mgmt frame success Radio 0 Vap 0
CLSM[A8:93:4A:02:C1:5F]: client moved from UNASSOC to AUTH
[1718176130:835877] [LDBV-Freyung-38] [a8:93:4a:02:c1:5f] <apr0v0> [D:W] DOT11_AUTHENTICATION : (. )
[1718176130:836215] [LDBV-Freyung-38] [a8:93:4a:02:c1:5f] <apr0v0> [U:W] DOT11_ASSOC_REQUEST : (.)
CLSM[A8:93:4A:02:C1:5F]: US Assoc Req(0) seq 5 IF 23 slot 0 vap 0 len 188 state AUTH
CLSM[A8:93:4A:02:C1:5F]: DS Assoc Resp(10) IF 0 slot 0 vap 0 state AUTH, generated by AP
CLSM[A8:93:4A:02:C1:5F]: Driver send mgmt frame success Radio 0 Vap 0
CLSM[A8:93:4A:02:C1:5F]: client moved from AUTH to ASSOC
CLSM[A8:93:4A:02:C1:5F]: [handle_hapd_failure] association error status 43 , Send Deauth
[1718176130:840044] [LDBV-Freyung-38] [a8:93:4a:02:c1:5f] <apr0v0> [D:W] DOT11_ASSOC_RESPONSE : (. )
CLSM[A8:93:4A:02:C1:5F]: Send Deauth - Radio 0 Vap 0 success
CLSM[A8:93:4A:02:C1:5F]: Client delete initiated with timeout of 3 seconds
CLSM[A8:93:4A:02:C1:5F]: Remove success from ClientIPTable on apr0v0
CLSM[A8:93:4A:02:C1:5F]: Sent DELETE_MOBILE with reason CLIENT_DEL_SUB_CLSM_ASSOC_RESP_WITH_FAILURE_STATUS(278)
CLSM[A8:93:4A:02:C1:5F]: client moved from ASSOC to DELETE_PENDING
[1718176130:948065] [LDBV-Freyung-38] [a8:93:4a:02:c1:5f] <apr0v0> [U:W] EAPOL_START
[1718176130:948542] [LDBV-Freyung-38] [a8:93:4a:02:c1:5f] <apr0v0> [D:W] DOT11_DEAUTHENTICATION : (.)
CLSM[A8:93:4A:02:C1:5F]: Delete timeout

Can anyone help me to find the reason?

regards, Thomas

 

3 Replies 3

marce1000
Hall of Fame
Hall of Fame

 

 - You can also engage on client debugging on the controller using :
                     https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity
   The resulting client debugs (so called RadioActive Traces) can be analyzed with Wireless Debug Analyzer

 - Have a checkup of the WLC 9800 configuration using the CLI command show tech wireless
    and feed the output from that into Wireless Config Analyzer

 - What software version is the WLC 9800 running ?

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

friedelkg
Level 1
Level 1

Hi Marc,

thanks for your response.

We could find the reason:

handle_hapd_failure] association error status 43  - Invalid AKMP - explained in  https://community.cisco.com/t5/wireless-mobility-knowledge-base/802-11-association-status-802-11-deauth-reason-codes/ta-p/3148055

On WLAN SSID we allowed  FT + 802.1x as Auth Key Mgmt only. Now we enabled 802.1x as well and it works.

Regards, Thomas

 

 

Rich R
VIP
VIP

That's what Cisco call Mixed Mode - see https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html#Enable80211rFastTransition

Review Cisco Networking for a $25 gift card