06-21-2005 05:35 AM - edited 07-04-2021 10:55 AM
Hi , I have had continously message of this in a syslog :
Jun 18 11:11:46 192.168.4.216 5595: *Mar 3 21:03:39.726: %DOT11-4-TKIP_MIC_FAILURE_REPORT: Received TKIP Michael MIC failure report from the station 000f.f778.e28a on the packet (TSC=0x1600000000000000) encrypted and protected by group key.
How I can interpreter this syslog message ? How can be solved ?
Many thanks,
06-21-2005 10:28 AM
Update the Intel drivers on the client to the most recent.
Also note that two MIC failures in 60 seconds can (did, in my case) shut down the radio.
The MIC failures are viewed as an attack, so by spec, the radio is shut down to prevent entry (I don't know how long it drops, but I suspect it's ~ minute or two).
The CWNP book says some / many / most AP vendors will provide an option to ignore this error because it could be used as a DOS attack. I haven't found (haven't looked) to see if Cisco has this parameter override.
I had this on my Lab network with a WDS of a couple AP1200s. One of the clients was running an Intel Centrino NIC, was throwing MIC checks, and killing the associated AP1200 (running 12.3(4)JA)).
FWIW
Scott
06-23-2005 02:44 AM
To turn it off try
int d0
countermeasures tkip hold-time 0
07-04-2005 12:21 AM
Many thanks.
David S.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide