08-07-2018 07:12 PM - edited 07-05-2021 08:57 AM
We have run into issues where only few clients cannot associate to our corporate SSID. Debug synopsis below
Aug 08 11:55:18.039 | *apfMsConnTask_3 | Client made new Association to AP/BSSID BSSID a0:23:9f:fa:d5:62 AP NZCHC5NET55 |
Aug 08 11:55:18.041 | *apfMsConnTask_3 | The WLC/AP has found from client association request Information Element that claims PMKID Caching support |
Aug 08 11:55:18.042 | *apfMsConnTask_3 | Client is entering the 802.1x or PSK Authentication state |
Aug 08 11:55:18.042 | *apfMsConnTask_3 | Client expiration timer code set for 65335 seconds. The reason: Client deleted due to session timeout (wlan with webauth) |
Aug 08 11:55:18.042 | *apfMsConnTask_3 |
WLC/AP is sending an Association Response to the client with status code 0 = Successful association
|
This is with Cisco 5508 controller running a non-broadcast SSID. The software version is 8.3.141.0 and AP is 3500 at a flex connect site. EAP timers are set to 3 seconds for association. Screenshot attached.
Any ideas what can be done? Approach TAC?
Thanks
Jeet
08-07-2018 08:23 PM
08-08-2018 03:42 AM
Hi Jeet,
It appears to be a webauth SSID. Can you verify the client types which are facing this issue ? Are they Intel 8500 series ? Are you using CWA with ISE ?
If the same client is working fne for open SSID but not for this Webauth SSID , we probably need to troubleshoot it step by step. Like .. 802.11 association (plus MAC auth) >> DHCP IP assigment >> web portal page >> credential verification ..
Cheers,
Manish
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide