10-16-2014 01:43 AM - edited 07-05-2021 01:44 AM
Hi Guys,
Been tasked with investigating poor performance on one of our APs at a remote site. Reports are of clients 'dropping off the network'. Initial diagnostics shows ping times as below (local layer 3 switch svi to wireless device):
monl3s01#ping 10.140.201.112 repeat 50
Type escape sequence to abort.
Sending 50, 100-byte ICMP Echos to 10.140.201.112, timeout is 2 seconds:
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!.!!!
Success rate is 98 percent (49/50), round-trip min/avg/max = 8/136/1737 ms
But 5 minutes later, I get this:
monl3s01#ping 10.140.201.112 repeat 50
Type escape sequence to abort.
Sending 50, 100-byte ICMP Echos to 10.140.201.112, timeout is 2 seconds:
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Success rate is 100 percent (50/50), round-trip min/avg/max = 1/4/17 ms
monl3s01#
Yesterday when the problem was reported I got the following results from wireless device to local router:
30 packets sent, 3% loss, min 4ms, max 3842ms, avg 727ms
There are currently just five clients attached and the issue affects them all. Hardware is a Ct2504K9 WLC running software 7.6.120.0. For some reason (incompetence...) I cannot find the model number of the AP in question in the WLC GUI, is it there?
This is a new network to me and is in a different country so only minimal local testing possible through a local non techie. Unfortunately I also only have read access to the devices at present. I am new to Cisco wireless but have plenty of experience in general R&S.
Thanks for your help!
Graham
10-16-2014 03:18 AM
Hi Ghaham,
You have to log onto WLC (either GUI or CLI) & provide some more detail to help you.
In GUI, if you go to "wireless" tab you will see the AP information.
If possible SSH into WLC & get following information & attach it in next response.
1. show ap summary
2. show wlan summary
3. show wlan <wlan_id>
4. show client summary
5. show client detail <client_mac_address> For a client you have low performance.
HTH
Rasika
**** Pls rate all useful responses ****
10-16-2014 06:31 AM
Hello Rasika,
Thanks for the reply, AP is AIR-LAP1142N-E-K9, Primary Software Version 7.6.120.0 Boot Version 12.4.18.0 IOS Version 15.2(4)JB5$
The AP with the problem is MONAP01
The Client in the 'show client detail' output has the following response times:
monl3s01#ping 10.140.200.58 repeat 50
Type escape sequence to abort.
Sending 50, 100-byte ICMP Echos to 10.140.200.58, timeout is 2 seconds:
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Success rate is 100 percent (50/50), round-trip min/avg/max = 1/360/1535 ms
Output from commands below...
(Cisco Controller) >show ap summary
Number of APs.................................... 4
Global AP User Name.............................. admin
Global AP Dot1x User Name........................ Not Configured
AP Name Slots AP Model Ethernet MAC Location Country IP Address Clients
------------------ ----- -------------------- ----------------- ---------------- ------- --------------- -------
MONAP01 2 AIR-LAP1142N-E-K9 c4:7d:4f:39:ef:f4 Main Building ES 10.140.201.101 6
monapsap-01 2 AIR-LAP1242AG-E-K9 00:22:90:1c:26:9c New warehouse ES 10.140.201.83 8
MONAP02 2 AIR-LAP1142N-E-K9 00:22:bd:1a:ee:67 Mutua ES 10.140.200.20 7
monapmeetingroom0 2 AIR-CAP2602I-E-K9 3c:08:f6:f9:f3:89 Montmelo ES 10.140.201.110 7
(Cisco Controller) >
(Cisco Controller) >show wlan summary
Number of WLANs.................................. 3
WLAN ID WLAN Profile Name / SSID Status Interface Name
------- ------------------------------------- -------- --------------------
1 General_Laptops / eaptls Enabled vlan500
2 Guest_Internet_Access / GUEST Enabled management
3 <hidden>_Mobile_Devices / mobile Enabled vlan800
(Cisco Controller) >
(Cisco Controller) >show wlan 1
WLAN Identifier.................................. 1
Profile Name..................................... General_Laptops
Network Name (SSID).............................. eaptls
Status........................................... Enabled
MAC Filtering.................................... Disabled
Broadcast SSID................................... Enabled
AAA Policy Override.............................. Disabled
Network Admission Control
Client Profiling Status
Radius Profiling ............................ Disabled
DHCP ....................................... Disabled
HTTP ....................................... Disabled
Local Profiling ............................. Disabled
DHCP ....................................... Disabled
HTTP ....................................... Disabled
Radius-NAC State............................... Disabled
SNMP-NAC State................................. Disabled
Quarantine VLAN................................ 0
Maximum number of Associated Clients............. 0
Maximum number of Clients per AP Radio........... 200
--More-- or (q)uit
Number of Active Clients......................... 15
Exclusionlist.................................... Disabled
Session Timeout.................................. 86400 seconds
User Idle Timeout................................ Disabled
Sleep Client..................................... disable
Sleep Client Timeout............................. 12 hours
User Idle Threshold.............................. 0 Bytes
NAS-identifier................................... monwlc01
CHD per WLAN..................................... Disabled
Webauth DHCP exclusion........................... Disabled
Interface........................................ vlan500
Multicast Interface.............................. Not Configured
WLAN IPv4 ACL.................................... unconfigured
WLAN IPv6 ACL.................................... unconfigured
WLAN Layer2 ACL.................................. unconfigured
mDNS Status...................................... Enabled
mDNS Profile Name................................ default-mdns-profile
DHCP Server...................................... Default
DHCP Address Assignment Required................. Disabled
Static IP client tunneling....................... Disabled
Quality of Service............................... Silver
Per-SSID Rate Limits............................. Upstream Downstream
Average Data Rate................................ 0 0
--More-- or (q)uit
Average Realtime Data Rate....................... 0 0
Burst Data Rate.................................. 0 0
Burst Realtime Data Rate......................... 0 0
Per-Client Rate Limits........................... Upstream Downstream
Average Data Rate................................ 0 0
Average Realtime Data Rate....................... 0 0
Burst Data Rate.................................. 0 0
Burst Realtime Data Rate......................... 0 0
Scan Defer Priority.............................. 4,5,6
Scan Defer Time.................................. 100 milliseconds
WMM.............................................. Allowed
WMM UAPSD Compliant Client Support............... Disabled
Media Stream Multicast-direct.................... Disabled
CCX - AironetIe Support.......................... Enabled
CCX - Gratuitous ProbeResponse (GPR)............. Disabled
CCX - Diagnostics Channel Capability............. Disabled
Dot11-Phone Mode (7920).......................... Disabled
Wired Protocol................................... None
Passive Client Feature........................... Disabled
Peer-to-Peer Blocking Action..................... Disabled
Radio Policy..................................... All
DTIM period for 802.11a radio.................... 1
DTIM period for 802.11b radio.................... 1
--More-- or (q)uit
Radius Servers
Authentication................................ 10.140.104.10 1812
Authentication................................ 10.132.64.25 1812
Authentication................................ 10.128.64.25 1812
Accounting.................................... Disabled
Dynamic Interface............................. Disabled
Dynamic Interface Priority.................... wlan
Local EAP Authentication......................... Disabled
Security
802.11 Authentication:........................ Open System
FT Support.................................... Disabled
Static WEP Keys............................... Disabled
802.1X........................................ Disabled
Wi-Fi Protected Access (WPA/WPA2)............. Enabled
WPA (SSN IE)............................... Enabled
TKIP Cipher............................. Enabled
AES Cipher.............................. Enabled
WPA2 (RSN IE).............................. Enabled
TKIP Cipher............................. Enabled
AES Cipher.............................. Enabled
Auth Key Management
802.1x.................................. Enabled
--More-- or (q)uit
PSK..................................... Disabled
CCKM.................................... Disabled
FT-1X(802.11r).......................... Disabled
FT-PSK(802.11r)......................... Disabled
PMF-1X(802.11w)......................... Disabled
PMF-PSK(802.11w)........................ Disabled
FT Reassociation Timeout................... 20
FT Over-The-DS mode........................ Disabled
GTK Randomization.......................... Disabled
SKC Cache Support.......................... Disabled
CCKM TSF Tolerance......................... 1000
WAPI.......................................... Disabled
Wi-Fi Direct policy configured................ Disabled
EAP-Passthrough............................... Disabled
CKIP ......................................... Disabled
Web Based Authentication...................... Disabled
Web-Passthrough............................... Disabled
Conditional Web Redirect...................... Disabled
Splash-Page Web Redirect...................... Disabled
Auto Anchor................................... Disabled
FlexConnect Local Switching................... Disabled
flexconnect Central Dhcp Flag................. Disabled
flexconnect nat-pat Flag...................... Disabled
--More-- or (q)uit
flexconnect Dns Override Flag................. Disabled
flexconnect PPPoE pass-through................ Disabled
flexconnect local-switching IP-source-guar.... Disabled
FlexConnect Vlan based Central Switching ..... Disabled
FlexConnect Local Authentication.............. Disabled
FlexConnect Learn IP Address.................. Enabled
Client MFP.................................... Optional
PMF........................................... Disabled
PMF Association Comeback Time................. 1
PMF SA Query RetryTimeout..................... 200
Tkip MIC Countermeasure Hold-down Timer....... 60
Eap-params.................................... Disabled
AVC Visibilty.................................... Disabled
AVC Profile Name................................. None
Flow Monitor Name................................ None
Split Tunnel (Printers).......................... Disabled
Call Snooping.................................... Disabled
Roamed Call Re-Anchor Policy..................... Disabled
SIP CAC Fail Send-486-Busy Policy................ Enabled
SIP CAC Fail Send Dis-Association Policy......... Disabled
KTS based CAC Policy............................. Disabled
Assisted Roaming Prediction Optimization......... Disabled
802.11k Neighbor List............................ Disabled
--More-- or (q)uit
802.11k Neighbor List Dual Band.................. Disabled
Band Select...................................... Disabled
Load Balancing................................... Disabled
Multicast Buffer................................. Disabled
Mobility Anchor List
WLAN ID IP Address Status
------- --------------- ------
802.11u........................................ Disabled
MSAP Services.................................. Disabled
Local Policy
----------------
Priority Policy Name
-------- ---------------
(Cisco Controller) >
(Cisco Controller) >show client summary
Number of Clients................................ 30
RLAN/
MAC Address AP Name Slot Status WLAN Auth Protocol Port Wired PMIPV6 Role
----------------- ----------------- ---- ------------- ----- ---- ---------------- ---- ----- ------ ----------------
00:21:5c:92:4c:4f monapsap-01 0 Associated 1 Yes 802.11g 1 N/A No Local
00:27:10:6d:d7:a0 MONAP02 0 Associated 1 Yes 802.11g 1 N/A No Local
00:27:10:77:f8:20 MONAP02 0 Associated 1 Yes 802.11n(2.4 GHz) 1 N/A No Local
00:27:10:8b:09:b4 monapsap-01 0 Associated 1 Yes 802.11g 1 N/A No Local
04:48:9a:5d:b8:c2 MONAP01 0 Associated 3 Yes 802.11n(2.4 GHz) 1 N/A No Local
08:11:96:70:4b:0c monapsap-01 0 Associated 1 Yes 802.11g 1 N/A No Local
10:0b:a9:d6:93:98 monapsap-01 0 Associated 1 Yes 802.11g 1 N/A No Local
28:18:78:cb:39:75 monapmeetingroom0 0 Associated 1 Yes 802.11n(2.4 GHz) 1 N/A No Local
40:b3:95:cb:96:ab MONAP01 1 Associated 3 Yes 802.11n(5 GHz) 1 N/A No Local
58:94:6b:8a:a0:44 MONAP02 1 Associated 1 Yes 802.11n(5 GHz) 1 N/A No Local
Would you like to display more entries? (y/n) y
58:94:6b:8c:75:0c monapmeetingroom0 0 Associated 1 Yes 802.11n(2.4 GHz) 1 N/A No Local
78:6c:1c:e0:b3:85 monapmeetingroom0 0 Associated 3 Yes 802.11n(2.4 GHz) 1 N/A No Local
78:6c:1c:e8:89:44 monapmeetingroom0 0 Associated 3 Yes 802.11n(2.4 GHz) 1 N/A No Local
84:38:35:c9:41:ee MONAP01 0 Associated 3 Yes 802.11n(2.4 GHz) 1 N/A No Local
84:3a:4b:0a:74:44 monapmeetingroom0 0 Associated 1 Yes 802.11g 1 N/A No Local
84:3a:4b:71:74:94 monapsap-01 0 Associated 1 Yes 802.11g 1 N/A No Local
84:3a:4b:cf:86:24 monapsap-01 0 Associated 1 Yes 802.11g 1 N/A No Local
8c:70:5a:7b:16:f0 MONAP02 1 Associated 1 Yes 802.11a 1 N/A No Local
8c:70:5a:aa:13:52 MONAP02 1 Associated 1 Yes 802.11a 1 N/A No Local
90:cf:15:4b:05:3c MONAP01 0 Associated 2 Yes 802.11n(2.4 GHz) 1 N/A No Export foreign
94:eb:cd:34:92:28 monapsap-01 0 Associated 2 Yes 802.11g 1 N/A No Export foreign
a4:4e:31:4c:20:58 MONAP01 0 Associated 1 Yes 802.11g 1 N/A No Local
a8:8e:24:22:02:74 MONAP02 1 Associated 3 Yes 802.11n(5 GHz) 1 N/A No Local
a8:8e:24:30:b7:10 MONAP01 0 Associated 3 Yes 802.11n(2.4 GHz) 1 N/A No Local
b4:f0:ab:06:52:9b MONAP01 0 Associated 3 Yes 802.11n(2.4 GHz) 1 N/A No Local
Would you like to display more entries? (y/n) y
c8:6f:1d:7d:d2:56 monapsap-01 0 Associated 3 Yes 802.11g 1 N/A No Local
c8:e0:eb:e3:ba:ae monapmeetingroom0 0 Associated 3 Yes 802.11n(2.4 GHz) 1 N/A No Local
e0:c9:7a:6d:12:83 MONAP02 0 Associated 3 Yes 802.11n(2.4 GHz) 1 N/A No Local
f4:f1:5a:57:b7:dd MONAP01 0 Associated 3 Yes 802.11n(2.4 GHz) 1 N/A No Local
f8:16:54:13:34:2c MONAP02 0 Associated 1 Yes 802.11n(2.4 GHz) 1 N/A No Local
(Cisco Controller) >
(Cisco Controller) >show client detail A44E314C2058
Client MAC Address............................... a4:4e:31:4c:20:58
Client Username ................................. host/MXCL7JNSS2.global.<hidden>.com
AP MAC Address................................... c4:7d:4f:57:e0:a0
AP Name.......................................... MONAP01
AP radio slot Id................................. 0
Client State..................................... Associated
Client NAC OOB State............................. Access
Wireless LAN Id.................................. 1
Hotspot (802.11u)................................ Not Supported
BSSID............................................ c4:7d:4f:57:e0:a0
Connected For ................................... 479 secs
Channel.......................................... 1
IP Address....................................... 10.140.200.58
Gateway Address.................................. 10.140.200.1
Netmask.......................................... 255.255.254.0
IPv6 Address..................................... fe80::b0a9:8bb:3fd2:f065
Association Id................................... 90
Authentication Algorithm......................... Open System
Reason Code...................................... 1
Status Code...................................... 0
Client CCX version............................... 4
Client E2E version............................... 1
--More-- or (q)uit
Re-Authentication Timeout........................ Infinite
QoS Level........................................ Silver
Avg data Rate.................................... 0
Burst data Rate.................................. 0
Avg Real time data Rate.......................... 0
Burst Real Time data Rate........................ 0
802.1P Priority Tag.............................. disabled
CTS Security Group Tag........................... Not Applicable
KTS CAC Capability............................... No
WMM Support...................................... Enabled
APSD ACs....................................... BK BE VI VO
Power Save....................................... OFF
Current Rate..................................... 5.5
Supported Rates.................................. 1.0,2.0,5.5,11.0,6.0,9.0,
............................................. 12.0,18.0,24.0,36.0,48.0,
............................................. 54.0
Mobility State................................... Local
Mobility Move Count.............................. 0
Security Policy Completed........................ Yes
Policy Manager State............................. RUN
Policy Manager Rule Created...................... Yes
Audit Session ID................................. 0a8ccbdc00004519543fb2be
AAA Role Type.................................... none
--More-- or (q)uit
Local Policy Applied............................. none
IPv4 ACL Name.................................... none
FlexConnect ACL Applied Status................... Unavailable
IPv4 ACL Applied Status.......................... Unavailable
IPv6 ACL Name.................................... none
IPv6 ACL Applied Status.......................... Unavailable
Layer2 ACL Name.................................. none
Layer2 ACL Applied Status........................ Unavailable
mDNS Status...................................... Enabled
mDNS Profile Name................................ default-mdns-profile
No. of mDNS Services Advertised.................. 0
Policy Type...................................... WPA1
Authentication Key Management.................... 802.1x
Encryption Cipher................................ TKIP-MIC
Protected Management Frame ...................... No
Management Frame Protection...................... No
EAP Type......................................... EAP-TLS
Interface........................................ vlan500
VLAN............................................. 500
Quarantine VLAN.................................. 0
Access VLAN...................................... 500
Client Capabilities:
CF Pollable................................ Not implemented
--More-- or (q)uit
CF Poll Request............................ Not implemented
Short Preamble............................. Implemented
PBCC....................................... Not implemented
Channel Agility............................ Not implemented
Listen Interval............................ 90
Fast BSS Transition........................ Not implemented
Client Wifi Direct Capabilities:
WFD capable................................ No
Manged WFD capable......................... No
Cross Connection Capable................... No
Support Concurrent Operation............... No
Fast BSS Transition Details:
Client Statistics:
Number of Bytes Received................... 6635486
Number of Bytes Sent....................... 29457987
Total Number of Bytes Sent................. 29457987
Total Number of Bytes Recv................. 6635486
Number of Bytes Sent (last 90s)............ 0
Number of Bytes Recv (last 90s)............ 0
Number of Packets Received................. 35880
Number of Packets Sent..................... 42952
Number of Interim-Update Sent.............. 0
Number of EAP Id Request Msg Timeouts...... 0
--More-- or (q)uit
Number of EAP Id Request Msg Failures...... 0
Number of EAP Request Msg Timeouts......... 0
Number of EAP Request Msg Failures......... 0
Number of EAP Key Msg Timeouts............. 0
Number of EAP Key Msg Failures............. 0
Number of Data Retries..................... 15095
Number of RTS Retries...................... 0
Number of Duplicate Received Packets....... 385
Number of Decrypt Failed Packets........... 0
Number of Mic Failured Packets............. 0
Number of Mic Missing Packets.............. 0
Number of RA Packets Dropped............... 0
Number of Policy Errors.................... 0
Radio Signal Strength Indicator............ -83 dBm
Signal to Noise Ratio...................... 4 dB
Client Rate Limiting Statistics:
Number of Data Packets Recieved............ 0
Number of Data Rx Packets Dropped.......... 0
Number of Data Bytes Recieved.............. 0
Number of Data Rx Bytes Dropped............ 0
Number of Realtime Packets Recieved........ 0
Number of Realtime Rx Packets Dropped...... 0
Number of Realtime Bytes Recieved.......... 0
--More-- or (q)uit
Number of Realtime Rx Bytes Dropped........ 0
Number of Data Packets Sent................ 0
Number of Data Tx Packets Dropped.......... 0
Number of Data Bytes Sent.................. 0
Number of Data Tx Bytes Dropped............ 0
Number of Realtime Packets Sent............ 0
Number of Realtime Tx Packets Dropped...... 0
Number of Realtime Bytes Sent.............. 0
Number of Realtime Tx Bytes Dropped........ 0
Nearby AP Statistics:
monapsap-01(slot 0)
antenna0: 5606 secs ago.................. -91 dBm
monapsap-01(slot 1)
antenna0: 5740 secs ago.................. -81 dBm
antenna1: 5740 secs ago.................. -100 dBm
monapmeetingroom0(slot 0)
antenna0: 41 secs ago.................... -96 dBm
antenna1: 41 secs ago.................... -90 dBm
monapmeetingroom0(slot 1)
antenna0: 481 secs ago................... -96 dBm
antenna1: 481 secs ago................... -95 dBm
MONAP02(slot 0)
antenna0: 5601 secs ago.................. -87 dBm
--More-- or (q)uit
antenna1: 5601 secs ago.................. -91 dBm
MONAP01(slot 0)
antenna0: 41 secs ago.................... -81 dBm
antenna1: 41 secs ago.................... -90 dBm
MONAP01(slot 1)
antenna0: 52 secs ago.................... -88 dBm
antenna1: 52 secs ago.................... -89 dBm
DNS Server details:
DNS server IP ............................. 10.140.104.10
DNS server IP ............................. 10.128.64.25
Assisted Roaming Prediction List details:
Client Dhcp Required: False
Allowed (URL)IP Addresses
-------------------------
(Cisco Controller) >
10-16-2014 07:27 AM
The client you reference is pretty far from the ap
(Cisco Controller) >show client detail A44E314C2058
Current Rate..................................... 5.5
Radio Signal Strength Indicator............ -83 dBm
Signal to Noise Ratio...................... 4 dB
At this distance nose floor and slow rates should be expected. BTW this is what the AP hears the client at.
03-26-2015 07:20 AM
Was there a solution to this issue?
10-16-2014 10:37 AM
Hi Graham,
Thanks for these output. As George pointed out this client is having poor signal indicating he is not close enough to an AP. Make sure you have proper coverage in first place (at least -75dBm).
Under SSID, I would disable AES option under WPA & TKIP option under WAP2. If all your client supports WPA2, then I would completely disable WPA. (Note that given client connect with WPA-TKIP & you will never get 802.11n rates unless client connect in WPA2/AES in 802.1X)
Wi-Fi Protected Access (WPA/WPA2)............. Enabled
WPA (SSN IE)............................... Enabled
TKIP Cipher............................. Enabled
AES Cipher.............................. Enabled
WPA2 (RSN IE).............................. Enabled
TKIP Cipher............................. Enabled
AES Cipher.............................. Enabled
(Cisco Controller) >show client detail A44E314C2058
Policy Type...................................... WPA1
Authentication Key Management.................... 802.1x
Encryption Cipher................................ TKIP-MIC
2. It looks like client connected at 5.5Mbps, which is a 802.11b data rate.
Current Rate..................................... 5.5
You should disable all 802.11b data rates (under wireless -> 802.11b/g/n-> disable 1,2,5.5 & 11 Mbps & make 12Mbps mandatory, leave other rates as supported)
Also in 802.11a/n band disable 6,9Mbps & make 12 Mbps mandatory & other rates as supported
3. Enable bandselect to prefer 5GHz over 2.4GHz for dual band support clients.
Band Select...................................... Disabled
4. Finally plan for a upgrade your WLC code to 7.6.130.0 as 7.6.120.0 is having lots of bugs & it is not a recommended code to be run. Here is the release notes for 7.6.130.0
http://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/crn76mr03.html
HTH
Rasika
**** Pls rate all useful responses ****
10-16-2014 06:07 AM
WiFi is all about having a mental check box. Is the wifi designed right. Is the wireless configured correctly. Is the clients configured correctly and optimized.
What are your 5 clients and are they on the latest driver ? Do they all behaving the same way ? Is your WLAN on both 2.4 and 5 Ghz? If so, move to 5 GHz only and test.
When I hear slow networks. First thing that comes to mind is channel utilization .. This is where you might have interference that causes a degraded network. This interference can be co-channel or non wifi.
I would also plug into the switch the APs are attached to. What is your response ? Same ?
10-16-2014 06:42 AM
Hi George,
The clients are a variety of devices of different type and brands. Some are not company owned. Unfortunately I don't have access to the site nor any meaningful way of doing any tests locally expect that which I can do via SSH/GUI on the WLC. I've posted below the results of show commands as requested by Rasika.
The AP concerned is plugged directly into the core site L3 switch, ping times to the AP itself are fine:
monl3s01#ping monap01 repeat 500
Type escape sequence to abort.
Sending 500, 100-byte ICMP Echos to 10.140.201.101, timeout is 2 seconds:
Success rate is 100 percent (500/500), round-trip min/avg/max = 1/2/17 ms
monl3s01#
Thanks,
Graham
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide