10-24-2011 08:01 AM - edited 07-03-2021 08:58 PM
Hi,
i have a problem with Cisco WLC 2106 (SW: 7.0.98.0) and LAP1262.
The client roams to new AP, associates with the new AP and authentication (WPA2 with EAP-TLS) runs fine until WPA2 key exchange.
The first WPA2-Key-paket from AP (1 / 4) is sent twice. On a closer look at those pakets with Wireshark, i've found out the first is encapsulated into a 11n-frame (A-MSDU). The resent frame isn't.
This figure shows the first WPA-Key-paket:
The next figure shows the 2nd key-paket, without 11n-encapsulation:
The problem, that occurs a very long roaming-time with about 5 seconds. As you can see on second figure, the second wpa-key is sent 5 seconds after the first.
Does Anyone know this problem? Or is it well knows at Cisco?
Some details:
Client: Tablet PC with Intel 6230 agn
Controller: Cisco WLC 2106
AP: LAP 1262
Controller SW: 7.0.98.0
Encryption: WPA2-AES
Authentication: EAP-TLS
This problem occurs just on 5-GHz interface with 40 MHz channel bandwidth.
Thanks in advance for any reply!!!
Kind regards!
10-24-2011 09:11 AM
Im curious, do you have CCKM enabled?
10-24-2011 10:00 AM
No, CCKM isn't enabled. And I don't want it enabled, special reasons. should also work this way.
10-24-2011 10:11 AM
It makes me wonder if your client is actually using RSN with PKI cache, thus why I asked. Did you capture to see if a PKI-ID was renewed or a new one was created during the roam process?
10-24-2011 10:26 AM
Well, actually i don't know.
But it also doesn't seem to be the problem. The contents of those two frames I've posted above are the same, just one is encapsulated.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide