cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
606
Views
5
Helpful
3
Replies

TKIP

davidsr25
Community Member

Hi , I have had continously message of this in a syslog :

Jun 18 11:11:46 192.168.4.216 5595: *Mar 3 21:03:39.726: %DOT11-4-TKIP_MIC_FAILURE_REPORT: Received TKIP Michael MIC failure report from the station 000f.f778.e28a on the packet (TSC=0x1600000000000000) encrypted and protected by group key.

How I can interpreter this syslog message ? How can be solved ?

Many thanks,

3 Replies 3

scottmac
Level 11
Level 11

Update the Intel drivers on the client to the most recent.

Also note that two MIC failures in 60 seconds can (did, in my case) shut down the radio.

The MIC failures are viewed as an attack, so by spec, the radio is shut down to prevent entry (I don't know how long it drops, but I suspect it's ~ minute or two).

The CWNP book says some / many / most AP vendors will provide an option to ignore this error because it could be used as a DOS attack. I haven't found (haven't looked) to see if Cisco has this parameter override.

I had this on my Lab network with a WDS of a couple AP1200s. One of the clients was running an Intel Centrino NIC, was throwing MIC checks, and killing the associated AP1200 (running 12.3(4)JA)).

FWIW

Scott

To turn it off try

int d0

countermeasures tkip hold-time 0

Many thanks.

David S.

Review Cisco Networking for a $25 gift card