11-18-2024 03:57 AM
Hello!
We have virtual WLC with the latest software 8.10.196.0
One SSID is configured for web authentication without L2 authentication
When client moves around the office between access points with good signal strength, everything works without problems
Also works well if client leaves the coverage area instantly without delay or simply turns off Wi-Fi on the device
When client is in an area with a poor signal level for a couple of minutes, for example -80 dBm, the system requires re-authentication after switching AP ( Of course, in the process of staying in this area, the system tries to migrate the client, but all access points have an unsatisfactory signal )
The following options have been edited:
Maybe we're missing something, but why doesn't the system revert the client back to the old authorization session after they've been in that particular low signal place ?
Can something be done about it ?
I'll also add the client's debug log
*apfOpenDtlSocket: Nov 18 11:28:41.285: 3c:38:f4:c6:b9:05 Received management frame ACTION on BSSID e4:aa:5d:3e:ce:9b destination addr e4:aa:5d:3e:ce:9b slotid 1
*apfMsConnTask_3: Nov 18 11:28:41.285: 3c:38:f4:c6:b9:05 Got action frame from the client (ActionCategory:5), payloadLen:16
*apfMsConnTask_3: Nov 18 11:28:41.285: 3c:38:f4:c6:b9:05 Found RM action category code
*apfMsConnTask_3: Nov 18 11:28:41.285: 3c:38:f4:c6:b9:05 Station: 3C:38:F4:C6:B9:05 sent 802.11K neighbor request to AP E4:AA:5D:3E:CE:90
*apfMsConnTask_3: Nov 18 11:28:41.285: 3c:38:f4:c6:b9:05 Station: 3C:38:F4:C6:B9:05 requested neighbors on non XOR roam capable AP E4:AA:5D:3E:CE:90 Slot 1
*apfOpenDtlSocket: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Received management frame REASSOCIATION REQUEST on BSSID e4:aa:5d:60:14:4c destination addr e4:aa:5d:60:14:4c slotid 1
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Updating the client capabiility as 4
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Processing assoc-req station:3c:38:f4:c6:b9:05 AP:e4:aa:5d:60:14:40-01 ssid : Sigma-Guest thread:388c00b260
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Station: 3C:38:F4:C6:B9:05 trying to join WLAN with RSSI -82. Checking for XOR roam conditions on AP: E4:AA:5D:60:14:40 Slot: 1
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Station: 3C:38:F4:C6:B9:05 is associating to AP E4:AA:5D:60:14:40 which is not XOR roam capable
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Setting hasApChnaged Flag as true. It is a roam scenario.
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Client AVC Roaming context transfer needed? NO
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 req rcv on open Wlan
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Setting RTTS enabled to 0
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Reassociation received from mobile on BSSID e4:aa:5d:60:14:3a AP ap-lv-cisco2702-07
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Station: 3C:38:F4:C6:B9:05 trying to join WLAN with RSSI -82. Checking for XOR roam conditions on AP: E4:AA:5D:60:14:40 Slot: 1
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Station: 3C:38:F4:C6:B9:05 is associating to AP E4:AA:5D:60:14:40 which is not XOR roam capable
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Optimized Roaming : Client RSSI(-82) is lower than the association RSSI threshold(-74), reject the association request
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Client is triggering BSS Transition
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Global 200 Clients are allowed to AP radio
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Max Client Trap Threshold: 0 cur: 13
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Rf profile 600 Clients are allowed to AP wlan
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Updated local bridging VLAN to 160 while applying WLAN policy
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Updated session timeout to 28800 and Sleep timeout to 720 while applying WLAN policy
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 override for default ap group, marking intgrp NULL
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 apfApplyWlanPolicy: Apply WLAN Policy over PMIPv6 Client Mobility Type, Tunnel User - 0
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Check before Setting the NAS Id to WLAN specific Id 'lv-vwlc-01'
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Setting the NAS Id to WLAN specific Id 'lv-vwlc-01'
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Check the client SGT 0 policy and push it to AP e4:aa:5d:60:14:40
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 In processSsidIE:7685 setting Central switched to FALSE
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Disabling flexconnect central association for the client
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Applying site-specific Local Bridging override for station 3c:38:f4:c6:b9:05 - vapId 22, site 'Sigma-Lviv-2', interface 'sun-guest'
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Applying Local Bridging Interface Policy for station 3c:38:f4:c6:b9:05 - vlan 160, interface id 6, interface 'sun-guest', nasId:'lv-vwlc-01'
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Client roamed with existing IPv4/v6 address. Using original location Sigma-Lviv
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Client roamed with either Ipv4 Addr[192.168.206.55] or hasIPv6Addr:FALSE.
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 override from ap group, removing intf group from mscb
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Applying site-specific override for station 3c:38:f4:c6:b9:05 - vapId 22, site 'Sigma-Lviv', interface 'sun-guest'
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Not applying Local Bridge Policy because Site Specific Interface(sun-guest) Policy is already applied.
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Applying Interface(sun-guest) policy on Mobile, role Local. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 160
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Not re-applying interface policy for local switching Client
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 After applying Interface(sun-guest) policy on Mobile, role Local. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 160
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:3498)
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Changing Url ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255),Default action is '0' --- (caller apf_policy.c:3518)
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:3539)
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Values before applying NASID - interfacetype:3, ovrd:0, mscb nasid:lv-vwlc-01, interface nasid:, APgrpset:0
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Set Client Non AP specific Flexgroup apfMsAccessVlan = 160
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 This apfMsAccessVlan may be changed later from AAA after L2 Auth
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Cleared localSwitchingVlan, may be assigned later based on AAA override
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 processSsidIE statusCode is 0 and status is 0
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 processSsidIE ssid_done_flag is 0 finish_flag is 0
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 STA - rates (6): 152 36 48 72 96 108 0 0 0 0 0 0 0 0 0 0
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 suppRates statusCode is 0 and gotSuppRatesElement is 1
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 pemApfDeleteMobileStation2: APF_MS_PEM_WAIT_L2_AUTH_COMPLETE = 0.
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 the value of url acl preserve flag is 1 for mobile 3c:38:f4:c6:b9:05 (caller pem_api.c:5292)
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Deleted mobile LWAPP rule on AP [e4:aa:5d:3e:ce:90]
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Succesfully freed AID 9, slot 1 on AP e4:aa:5d:3e:ce:90, #client on this slot 20
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 New ctxOwnerMwarIp: 10.40.56.35 New ctxOwnerApMac: E4:AA:5D:60:14:40 New ctxOwnerApEthMac: EC:BD:1D:C5:80:70 New ctxOwnerApSlotId: 1
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Updated location for station old AP e4:aa:5d:3e:ce:90 oldSlot 1, new AP e4:aa:5d:60:14:40 newSlot 1, AID 0 MsType 0 MobilityRole 1
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Assigning flex webauth IPv4-ACL ID :1, IPv6-ACL ID:65535 for AP WLAN ID : 4
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Assigned flex post-auth IPv4-ACL ID :65535, IPv6-ACL ID:65535 for AP WLAN ID : 4
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Updating AID for REAP AP Client e4:aa:5d:60:14:40 - AID ===> 9
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Reassoc Req BSSID e4:aa:5d:60:14:3a AP(ap-lv-cisco2702-07) slot 1 ssid (Sigma-Guest) Tmstmp 829625 AID 9 stCode 0/0 apChngd 1 oldAp E4:AA:5D:3E:CE:90
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Authreqd flag unchanged 0 for mobile with macAuthType [0] pemSt 20 secWord 10
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Not changing skipL2auth flag with authReqd [0] macauth [0] pemSt 20 secWord 10
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Applied RADIUS override policy
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Mobility peer ip is 0, failed to get session type
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Adding Fast Path rule
type = Airespace AP Client
on AP e4:aa:5d:60:14:40, slot 1, interface = 1, QOS = 2
IPv4 ACL ID = 255, IPv6 ACL ID =
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Fast Path rule (contd...) 802.1P = 5, DSCP = 46, TokenID = 15206, IntfId = 6 Local Bridging Vlan = 160, Local Bridging intf id = 6
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Fast Path rule (contd...) AVC Ratelimit: AppID = 0 ,AppAction = 0, AppToken = 15206 AverageRate = 0, BurstRate = 0
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Fast Path rule (contd...) AVC Ratelimit: AppID = 0 ,AppAction = 0, AppToken = 15206 AverageRate = 0, BurstRate = 0
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Fast Path rule (contd...) AVC Ratelimit: AppID = 0 ,AppAction = 0, AppToken = 15206 AverageRate = 0, BurstRate = 0
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Initiating Accounting request(1) update for mobile
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Accounting NAI-Realm: [email protected], from Mscb username : [email protected]
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 PemLocationConfigured [1]Adding VSA with NAS update and Role[1] with state[0]
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Successfully plumbed mobile rule (IPv4 ACL ID 255, IPv6 ACL ID 255, L2 ACL ID 255,URL ACL ID 255,URL ACL Action 0)
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Updating info change db with CMX bitmap 0x0000
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Flex Central Auth Client
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Client already has IP 192.168.206.55, DHCP Not required on AP e4:aa:5d:60:14:40 vapId 22 apVapId 4
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Not Using WMM Compliance code qosCap 00
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 flex webauth acl id to be sent :1 name :Iron_WiFi_Auth_URLs client acl id :65535 name :
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 flex webauth ipv6 acl id to be sent :65535 name : client acl id :65535 name :
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Vlan while overriding the policy = -1
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 sending to spamAddMobile vlanId -1 aclName = , flexAclId 65535
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Sending OLD AP MAC address: e4:aa:5d:3e:ce:90as the client has roamed.
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Plumbed mobile LWAPP rule on AP e4:aa:5d:60:14:40 vapId 22 apVapId 4 flex acl-name:Iron_WiFi_Auth_URLs v6acl-name
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Change state to RUN (20) last state RUN (20)
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 apfPemAddUser2 (apf_policy.c:465) Changing state for mobile 3c:38:f4:c6:b9:05 on AP e4:aa:5d:60:14:40 from Associated to Associated
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 apfPemAddUser2:session timeout forstation 3c:38:f4:c6:b9:05 - Session Tout 28800, apfMsTimeOut '28800' and sessionTimerRunning flag is 1
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Scheduling deletion of Mobile Station: reasonCode 4 (callerId: 49) in 28800 seconds
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Func: apfPemAddUser2, Ms Timeout = 28800, Session Timeout = 28800
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Sending assoc-resp with status 0 station:3c:38:f4:c6:b9:05 AP:e4:aa:5d:60:14:40-01 on apVapId 4
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 VHT Operation IE: width 40/0 ch 100 freq0 0 freq1 0 msc0 0xff msc1 0xff
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Sending Assoc Response (status: '0') to station on AP ap-lv-cisco2702-07 on BSSID e4:aa:5d:60:14:4c ApVapId 4 Slot 1, mobility role 1
*apfMsConnTask_7: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 apfProcessAssocReq (apf_80211.c:13003) Changing state for mobile 3c:38:f4:c6:b9:05 on AP e4:aa:5d:60:14:40 from Associated to Associated
*pemReceiveTask: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 192.168.206.55 Removed NPU entry.
*pemReceiveTask: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 192.168.206.55 Added NPU entry of type 1, dtlFlags 0x0
*pemReceiveTask: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Pushing IPv6: fe80:0000:0000:0000:5d91:dc29:31f4:58ac , intfId:6 and MAC: 3C:38:F4:C6:B9:05 , Binding to Data Plane. SUCCESS !!
*spamApTask1: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Setting DEL_MOBILE (seqno 0, action 6) ack state for STA on AP e4:aa:5d:3e:ce:90
*spamApTask1: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Setting ADD_MOBILE (idx 7, seqno 180, action 6, count 180, last count 180) ack state for STA on AP e4:aa:5d:3e:ce:90
*spamApTask1: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Delete Mobile request with reason 'MN_DEL_INTER_AP_ROAM' on slot 1 sent to the AP e4:aa:5d:3e:ce:90 IP: 10.40.56.20:55303.
*aaaQueueReader: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 radiusServerFallbackPassiveStateUpdate: RADIUS server is ready 35.195.229.202 port 26840 index 9 active 1
*aaaQueueReader: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Found a server : 35.195.229.202 from the WLAN server list of radius server index 10
*aaaQueueReader: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Send Radius Acct Request with pktId:234 into qid:5 of server at index:9
*aaaQueueReader: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Sending the packet to v4 host 35.195.229.202:26840 of length 365
*aaaQueueReader: Nov 18 11:28:48.404: 3c:38:f4:c6:b9:05 Successful transmission of Accounting-Interim (pktId 234) to 35.195.229.202:26840 from server queue 5, proxy state 3c:38:f4:c6:b9:05-00:00
*spamApTask2: Nov 18 11:28:48.405: 3c:38:f4:c6:b9:05 Add SGT:0 to AP e4:aa:5d:60:14:40
*spamApTask2: Nov 18 11:28:48.405: 3c:38:f4:c6:b9:05 Add CTS mobile SGT - Encoded the capwap payload for the mobile with SGT 0
*spamApTask2: Nov 18 11:28:48.405: 3c:38:f4:c6:b9:05 MS IP NULL during AddMobile, not sending IP Distribution
*spamApTask2: Nov 18 11:28:48.405: 3c:38:f4:c6:b9:05 Flex Ipv6 pre-auth acl is not present, not Encoding Flex Ipv6 acl for add mobile Payload
*spamApTask2: Nov 18 11:28:48.405: 3c:38:f4:c6:b9:05 Flex Ipv6 post auth acl is not present, not updating add mobile Payload
*spamApTask2: Nov 18 11:28:48.405: 3c:38:f4:c6:b9:05 Encoding Old AP client(10.40.56.20) details to new AP for DNS ACL IP learning as the client has roamed.
*spamApTask2: Nov 18 11:28:48.405: 3c:38:f4:c6:b9:05 Encoded TLV_AP_FLEX_OLD_AP_PAYLOAD with len=70 , Old AP is 10.40.56.20.
*spamApTask2: Nov 18 11:28:48.405*iappSocketTask: Nov 18 11:29:18.018: 3c:38:f4:c6:b9:05 IAPP-IP-UPDATE(0):49 Bytes received for client
*apfReceiveTask: Nov 18 11:29:18.018: 3c:38:f4:c6:b9:05 Recieved MS IPv4 Addr= 192.168.206.55
*apfReceiveTask: Nov 18 11:29:18.018: 3c:38:f4:c6:b9:05 Recieved IPv6 addresses count: 1
*apfReceiveTask: Nov 18 11:29:18.018: 3c:38:f4:c6:b9:05 Updating MS IPv6[1] Addr= fe80:0000:0000:0000:5d91:dc29:31f4:58ac
*apfMsConnTask_7: Nov 18 11:29:57.156: 3c:38:f4:c6:b9:05 Client stats update: Time now in sec 1731929397, Last Acct Msg Sent at 1731929328 sec
*iappSocketTask: Nov 18 11:30:18.018: 3c:38:f4:c6:b9:05 IAPP-IP-UPDATE(0):49 Bytes received for client
*apfReceiveTask: Nov 18 11:30:18.018: 3c:38:f4:c6:b9:05 Recieved MS IPv4 Addr= 192.168.206.55
*apfReceiveTask: Nov 18 11:30:18.018: 3c:38:f4:c6:b9:05 Recieved IPv6 addresses count: 1
*apfReceiveTask: Nov 18 11:30:18.018: 3c:38:f4:c6:b9:05 Updating MS IPv6[1] Addr= fe80:0000:0000:0000:5d91:dc29:31f4:58ac
*apfOpenDtlSocket: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Received management frame REASSOCIATION REQUEST on BSSID e4:aa:5d:3e:ce:9b destination addr e4:aa:5d:3e:ce:9b slotid 1
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Updating the client capabiility as 4
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Processing assoc-req station:3c:38:f4:c6:b9:05 AP:e4:aa:5d:3e:ce:90-01 ssid : Sigma-Guest thread:388c0098e0
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Station: 3C:38:F4:C6:B9:05 trying to join WLAN with RSSI -79. Checking for XOR roam conditions on AP: E4:AA:5D:3E:CE:90 Slot: 1
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Station: 3C:38:F4:C6:B9:05 is associating to AP E4:AA:5D:3E:CE:90 which is not XOR roam capable
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Setting hasApChnaged Flag as true. It is a roam scenario.
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Client AVC Roaming context transfer needed? NO
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 req rcv on open Wlan
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Setting RTTS enabled to 0
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Reassociation received from mobile on BSSID e4:aa:5d:3e:ce:8a AP ap-lv-cisco2702-06
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Station: 3C:38:F4:C6:B9:05 trying to join WLAN with RSSI -79. Checking for XOR roam conditions on AP: E4:AA:5D:3E:CE:90 Slot: 1
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Station: 3C:38:F4:C6:B9:05 is associating to AP E4:AA:5D:3E:CE:90 which is not XOR roam capable
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Optimized Roaming : Client RSSI(-79) is lower than the association RSSI threshold(-74), reject the association request
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Client is triggering BSS Transition
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Global 200 Clients are allowed to AP radio
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Max Client Trap Threshold: 0 cur: 20
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Rf profile 600 Clients are allowed to AP wlan
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Updated local bridging VLAN to 160 while applying WLAN policy
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Updated session timeout to 28800 and Sleep timeout to 720 while applying WLAN policy
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 override for default ap group, marking intgrp NULL
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 apfApplyWlanPolicy: Apply WLAN Policy over PMIPv6 Client Mobility Type, Tunnel User - 0
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Check before Setting the NAS Id to WLAN specific Id 'lv-vwlc-01'
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Setting the NAS Id to WLAN specific Id 'lv-vwlc-01'
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Check the client SGT 0 policy and push it to AP e4:aa:5d:3e:ce:90
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 In processSsidIE:7685 setting Central switched to FALSE
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Disabling flexconnect central association for the client
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Applying site-specific Local Bridging override for station 3c:38:f4:c6:b9:05 - vapId 22, site 'Sigma-Lviv', interface 'sun-guest'
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Applying Local Bridging Interface Policy for station 3c:38:f4:c6:b9:05 - vlan 160, interface id 6, interface 'sun-guest', nasId:'lv-vwlc-01'
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Client roamed with existing IPv4/v6 address. Using original location Sigma-Lviv
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Client roamed with either Ipv4 Addr[192.168.206.55] or hasIPv6Addr:FALSE.
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 override from ap group, removing intf group from mscb
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Applying site-specific override for station 3c:38:f4:c6:b9:05 - vapId 22, site 'Sigma-Lviv', interface 'sun-guest'
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Not applying Local Bridge Policy because Site Specific Interface(sun-guest) Policy is already applied.
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Applying Interface(sun-guest) policy on Mobile, role Local. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 160
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Not re-applying interface policy for local switching Client
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 After applying Interface(sun-guest) policy on Mobile, role Local. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 160
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:3498)
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Changing Url ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255),Default action is '0' --- (caller apf_policy.c:3518)
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:3539)
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Values before applying NASID - interfacetype:3, ovrd:0, mscb nasid:lv-vwlc-01, interface nasid:, APgrpset:0
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Set Client Non AP specific Flexgroup apfMsAccessVlan = 160
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 This apfMsAccessVlan may be changed later from AAA after L2 Auth
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Cleared localSwitchingVlan, may be assigned later based on AAA override
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 processSsidIE statusCode is 0 and status is 0
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 processSsidIE ssid_done_flag is 0 finish_flag is 0
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 STA - rates (6): 152 36 48 72 96 108 0 0 0 0 0 0 0 0 0 0
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 suppRates statusCode is 0 and gotSuppRatesElement is 1
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 pemApfDeleteMobileStation2: APF_MS_PEM_WAIT_L2_AUTH_COMPLETE = 0.
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 the value of url acl preserve flag is 1 for mobile 3c:38:f4:c6:b9:05 (caller pem_api.c:5292)
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Deleted mobile LWAPP rule on AP [e4:aa:5d:60:14:40]
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 Succesfully freed AID 9, slot 1 on AP e4:aa:5d:60:14:40, #client on this slot 13
*apfMsConnTask_3: Nov 18 11:30:27.136: 3c:38:f4:c6:b9:05 New ctxOwnerMwarIp: 10.40.56.35 New ctxOwnerApMac: E4:AA:5D:3E:CE:90 New ctxOwnerApEthMac: EC:BD:1D:C5:80:70 New ctxOwnerApSlotId: 1
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Updated location for station old AP e4:aa:5d:60:14:40 oldSlot 1, new AP e4:aa:5d:3e:ce:90 newSlot 1, AID 0 MsType 0 MobilityRole 1
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Assigning flex webauth IPv4-ACL ID :1, IPv6-ACL ID:65535 for AP WLAN ID : 5
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Assigned flex post-auth IPv4-ACL ID :65535, IPv6-ACL ID:65535 for AP WLAN ID : 5
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Updating AID for REAP AP Client e4:aa:5d:3e:ce:90 - AID ===> 9
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Reassoc Req BSSID e4:aa:5d:3e:ce:8a AP(ap-lv-cisco2702-06) slot 1 ssid (Sigma-Guest) Tmstmp 829722 AID 9 stCode 0/0 apChngd 1 oldAp E4:AA:5D:60:14:40
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Authreqd flag unchanged 0 for mobile with macAuthType [0] pemSt 20 secWord 10
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Not changing skipL2auth flag with authReqd [0] macauth [0] pemSt 20 secWord 10
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Applied RADIUS override policy
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Mobility peer ip is 0, failed to get session type
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Adding Fast Path rule
type = Airespace AP Client
on AP e4:aa:5d:3e:ce:90, slot 1, interface = 1, QOS = 2
IPv4 ACL ID = 255, IPv6 ACL ID =
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Fast Path rule (contd...) 802.1P = 5, DSCP = 46, TokenID = 15206, IntfId = 6 Local Bridging Vlan = 160, Local Bridging intf id = 6
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Fast Path rule (contd...) AVC Ratelimit: AppID = 0 ,AppAction = 0, AppToken = 15206 AverageRate = 0, BurstRate = 0
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Fast Path rule (contd...) AVC Ratelimit: AppID = 0 ,AppAction = 0, AppToken = 15206 AverageRate = 0, BurstRate = 0
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Fast Path rule (contd...) AVC Ratelimit: AppID = 0 ,AppAction = 0, AppToken = 15206 AverageRate = 0, BurstRate = 0
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Initiating Accounting request(1) update for mobile
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Accounting NAI-Realm: [email protected], from Mscb username : [email protected]
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 PemLocationConfigured [1]Adding VSA with NAS update and Role[1] with state[0]
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Successfully plumbed mobile rule (IPv4 ACL ID 255, IPv6 ACL ID 255, L2 ACL ID 255,URL ACL ID 255,URL ACL Action 0)
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Updating info change db with CMX bitmap 0x0000
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Flex Central Auth Client
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) DHCP Not required on AP e4:aa:5d:3e:ce:90 vapId 22 apVapId 5for this client
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Not Using WMM Compliance code qosCap 00
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 flex webauth acl id to be sent :1 name :Iron_WiFi_Auth_URLs client acl id :65535 name :
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 flex webauth ipv6 acl id to be sent :65535 name : client acl id :65535 name :
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Vlan while overriding the policy = -1
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 sending to spamAddMobile vlanId -1 aclName = , flexAclId 65535
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Sending OLD AP MAC address: e4:aa:5d:60:14:40as the client has roamed.
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Plumbed mobile LWAPP rule on AP e4:aa:5d:3e:ce:90 vapId 22 apVapId 5 flex acl-name:Iron_WiFi_Auth_URLs v6acl-name
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 192.168.206.55 RUN (20) Change state to RUN (20) last state RUN (20)
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 apfPemAddUser2 (apf_policy.c:465) Changing state for mobile 3c:38:f4:c6:b9:05 on AP e4:aa:5d:3e:ce:90 from Associated to Associated
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 apfPemAddUser2:session timeout forstation 3c:38:f4:c6:b9:05 - Session Tout 28800, apfMsTimeOut '28800' and sessionTimerRunning flag is 1
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Scheduling deletion of Mobile Station: reasonCode 4 (callerId: 49) in 28800 seconds
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Func: apfPemAddUser2, Ms Timeout = 28800, Session Timeout = 28800
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Sending assoc-resp with status 0 station:3c:38:f4:c6:b9:05 AP:e4:aa:5d:3e:ce:90-01 on apVapId 5
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 VHT Operation IE: width 40/0 ch 36 freq0 0 freq1 0 msc0 0xff msc1 0xff
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Sending Assoc Response (status: '0') to station on AP ap-lv-cisco2702-06 on BSSID e4:aa:5d:3e:ce:9b ApVapId 5 Slot 1, mobility role 1
*apfMsConnTask_3: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 apfProcessAssocReq (apf_80211.c:13003) Changing state for mobile 3c:38:f4:c6:b9:05 on AP e4:aa:5d:3e:ce:90 from Associated to Associated
*pemReceiveTask: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 192.168.206.55 Removed NPU entry.
*pemReceiveTask: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 192.168.206.55 Added NPU entry of type 1, dtlFlags 0x0
*pemReceiveTask: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Pushing IPv6: fe80:0000:0000:0000:5d91:dc29:31f4:58ac , intfId:6 and MAC: 3C:38:F4:C6:B9:05 , Binding to Data Plane. SUCCESS !!
*spamApTask2: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Setting DEL_MOBILE (seqno 0, action 6) ack state for STA on AP e4:aa:5d:60:14:40
*spamApTask2: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Setting ADD_MOBILE (idx 82, seqno 139, action 6, count 139, last count 139) ack state for STA on AP e4:aa:5d:60:14:40
*spamApTask2: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Delete Mobile request with reason 'MN_DEL_INTER_AP_ROAM' on slot 1 sent to the AP e4:aa:5d:60:14:40 IP: 10.40.56.21:56648.
*aaaQueueReader: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 radiusServerFallbackPassiveStateUpdate: RADIUS server is ready 35.195.229.202 port 26840 index 9 active 1
*aaaQueueReader: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Found a server : 35.195.229.202 from the WLAN server list of radius server index 10
*aaaQueueReader: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Send Radius Acct Request with pktId:235 into qid:5 of server at index:9
*aaaQueueReader: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Sending the packet to v4 host 35.195.229.202:26840 of length 365
*aaaQueueReader: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Successful transmission of Accounting-Interim (pktId 235) to 35.195.229.202:26840 from server queue 5, proxy state 3c:38:f4:c6:b9:05-00:00
*apf80211vTask: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Setting Session Timeout to 4 sec - starting session timer for the mobile
*spamApTask1: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Add SGT:0 to AP e4:aa:5d:3e:ce:90
*spamApTask1: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Add CTS mobile SGT - Encoded the capwap payload for the mobile with SGT 0
*spamApTask1: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 MS IP NULL during AddMobile, not sending IP Distribution
*spamApTask1: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Flex Ipv6 pre-auth acl is not present, not Encoding Flex Ipv6 acl for add mobile Payload
*spamApTask1: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Flex Ipv6 post auth acl is not present, not updating add mobile Payload
*spamApTask1: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Encoding Old AP client(10.40.56.21) details to new AP for DNS ACL IP learning as the client has roamed.
*spamApTask1: Nov 18 11:30:27.137: 3c:38:f4:c6:b9:05 Encoded TLV_AP_FLEX_OLD_AP_PAYLOAD with len=70 , Old AP is 10.40.56.21.
*spamApTask1: Nov 18 11:30:27.138: 3c:38:f4:c6:b9:05 Successful transmission of LWAPP Add-Mobile to AP e4:aa:5d:3e:ce:90 slotId 1 idx@39
*spamApTask1: Nov 18 11:30:27.138: 3c:38:f4:c6:b9:05 Setting ADD_MOBILE (idx 40, action 0, last count 0) ack state for STA on AP e4:aa:5d:3e:ce:90
*apfMsConnTask_7: Nov 18 11:30:27.138: 3c:38:f4:c6:b9:05 Client stats update: Time now in sec 1731929427, Last Acct Msg Sent at 1731929427 sec
*apfMsConnTask_7: Nov 18 11:30:27.138: 3c:38:f4:c6:b9:05 Client stats update: Time now in sec 1731929427, Last Acct Msg Sent at 1731929427 sec
*spamApTask2: Nov 18 11:30:27.139: 3c:38:f4:c6:b9:05 Received add/del ack packet with sequence number: got 139 expected 139 action = 6
*iappSocketTask: Nov 18 11:30:27.211: 3c:38:f4:c6:b9:05 IAPP-IP-UPDATE(0):49 Bytes received for client
*apfReceiveTask: Nov 18 11:30:27.211: 3c:38:f4:c6:b9:05 Recieved MS IPv4 Addr= 0.0.0.0
*apfReceiveTask: Nov 18 11:30:27.211: 3c:38:f4:c6:b9:05 Recieved IPv6 addresses count: 1
*apfReceiveTask: Nov 18 11:30:27.211: 3c:38:f4:c6:b9:05 Updating MS IPv6[1] Addr= fe80:0000:0000:0000:5d91:dc29:31f4:58ac
*apfOpenDtlSocket: Nov 18 11:30:27.288: 3c:38:f4:c6:b9:05 Received management frame ACTION on BSSID e4:aa:5d:3e:ce:9b destination addr e4:aa:5d:3e:ce:9b slotid 1
*apfMsConnTask_3: Nov 18 11:30:27.288: 3c:38:f4:c6:b9:05 Got action frame from the client (ActionCategory:5), payloadLen:16
*apfMsConnTask_3: Nov 18 11:30:27.288: 3c:38:f4:c6:b9:05 Found RM action category code
*apfMsConnTask_3: Nov 18 11:30:27.288: 3c:38:f4:c6:b9:05 Station: 3C:38:F4:C6:B9:05 sent 802.11K neighbor request to AP E4:AA:5D:3E:CE:90
*apfMsConnTask_3: Nov 18 11:30:27.288: 3c:38:f4:c6:b9:05 Station: 3C:38:F4:C6:B9:05 requested neighbors on non XOR roam capable AP E4:AA:5D:3E:CE:90 Slot 1
*iappSocketTask: Nov 18 11:30:27.759: 3c:38:f4:c6:b9:05 IAPP-IP-UPDATE(0):49 Bytes received for client
*apfReceiveTask: Nov 18 11:30:27.759: 3c:38:f4:c6:b9:05 Recieved MS IPv4 Addr= 192.168.206.55
*apfReceiveTask: Nov 18 11:30:27.759: 3c:38:f4:c6:b9:05 Recieved IPv6 addresses count: 1
*apfReceiveTask: Nov 18 11:30:27.759: 3c:38:f4:c6:b9:05 Updating MS IPv6[1] Addr= fe80:0000:0000:0000:5d91:dc29:31f4:58ac
*osapiBsnTimer: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 Authentication session timer expired: mark mobile for immediate deletion
*osapiBsnTimer: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 apfMsSessionExpireCallback (apf_ms.c:762) Expiring Mobile!
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 apfMsExpireMobileStation (apf_ms.c:8148) Changing state for mobile 3c:38:f4:c6:b9:05 on AP e4:aa:5d:3e:ce:90 from Associated to Disassociated
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 Succesfully freed AID 9, slot 1 on AP e4:aa:5d:3e:ce:90, #client on this slot 20
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 apfSendDisAssocMsgDebug (apf_80211.c:4279) Changing state for mobile 3c:38:f4:c6:b9:05 on AP e4:aa:5d:3e:ce:90 from Disassociated to Disassociated
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 Sent Disassociate to mobile on AP e4:aa:5d:3e:ce:90-1 on BSSID e4:aa:5d:3e:ce:9b(reason 1, caller apf_ms.c:8233)
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 Setting active key cache index 8 ---> 8
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 Deleting the PMK cache when de-authenticating the client.
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 Global PMK Cache deletion failed.
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 Sent Deauthenticate to mobile on BSSID e4:aa:5d:3e:ce:9b slot 1 reason code 4 (caller apf_ms.c:8242)
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 Initiating Accounting request(2) update for mobile
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 Accounting NAI-Realm: [email protected], from Mscb username : [email protected]
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 PemLocationConfigured [1]Adding VSA with NAS update and Role[1] with state[0]
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 apfMsAssoStateDec
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 apfMsExpireMobileStation (apf_ms.c:8300) Changing state for mobile 3c:38:f4:c6:b9:05 on AP e4:aa:5d:3e:ce:90 from Disassociated to Idle
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 pemApfDeleteMobileStation2: APF_MS_PEM_WAIT_L2_AUTH_COMPLETE = 0.
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 the value of url acl preserve flag is 0 for mobile 3c:38:f4:c6:b9:05 (caller pem_api.c:5292)
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 192.168.206.55 START (0) Deleted mobile LWAPP rule on AP [e4:aa:5d:3e:ce:90]
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 Delete PMK cache along with client. Reason code: 4, Mobility Role: Local
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 0 PMK-remove groupcast messages sent
*apfReceiveTask: Nov 18 11:30:31.028: 3c:38:f4:c6:b9:05 Deleted global PMK cache and MSCB PMKID/PMK cache entry for the client
*apfReceiveTask: Nov 18 11:30:31.029: 3c:38:f4:c6:b9:05 Username entry '[email protected]' is deleted for mobile from the UserName table
*apfReceiveTask: Nov 18 11:30:31.029: 3c:38:f4:c6:b9:05 Username entry [email protected] deleted for mobile
*apfReceiveTask: Nov 18 11:30:31.029: 3c:38:f4:c6:b9:05 Deleting mobile on AP e4:aa:5d:3e:ce:90(1)
*apfReceiveTask: Nov 18 11:30:31.029: 3c:38:f4:c6:b9:05 apf_ms.c:5642 Clearing the SGT 0 of mobile
*apfReceiveTask: Nov 18 11:30:31.029: 3c:38:f4:c6:b9:05 Decrement the SGT 0 policy count reference by the clients 72
*aaaQueueReader: Nov 18 11:30:31.029: 3c:38:f4:c6:b9:05 radiusServerFallbackPassiveStateUpdate: RADIUS server is ready 35.195.229.202 port 26840 index 9 active 1
*aaaQueueReader: Nov 18 11:30:31.029: 3c:38:f4:c6:b9:05 Found a server : 35.195.229.202 from the WLAN server list of radius server index 10
*aaaQueueReader: Nov 18 11:30:31.029: 3c:38:f4:c6:b9:05 Send Radius Acct Request with pktId:236 into qid:5 of server at index:9
*aaaQueueReader: Nov 18 11:30:31.029: 3c:38:f4:c6:b9:05 Sending the packet to v4 host 35.195.229.202:26840 of length 371
*aaaQueueReader: Nov 18 11:30:31.029: 3c:38:f4:c6:b9:05 Successful transmission of Accounting-Stop (pktId 236) to 35.195.229.202:26840 from server queue 5, proxy state 3c:38:f4:c6:b9:05-00:00
*pemReceiveTask: Nov 18 11:30:31.029: 3c:38:f4:c6:b9:05 192.168.206.55 Removed NPU entry.
*spamApTask1: Nov 18 11:30:31.029: 3c:38:f4:c6:b9:05 Setting DEL_MOBILE (seqno 0, action 6) ack state for STA on AP e4:aa:5d:3e:ce:90
*spamApTask1: Nov 18 11:30:31.029: 3c:38:f4:c6:b9:05 Setting ADD_MOBILE (idx 40, seqno 213, action 6, count 213, last count 213) ack state for STA on AP e4:aa:5d:3e:ce:90
*spamApTask1: Nov 18 11:30:31.029: 3c:38:f4:c6:b9:05 Delete Mobile request with reason 'MN_DEL_REAUTH_TIMEOUT' on slot 1 sent to the AP e4:aa:5d:3e:ce:90 IP: 10.40.56.20:55303.
*spamApTask1: Nov 18 11:30:31.031: 3c:38:f4:c6:b9:05 Received add/del ack packet with sequence number: got 213 expected 213 action = 6
*radiusTransportThread: Nov 18 11:30:31.453: 3c:38:f4:c6:b9:05 Accounting-Response received from RADIUS server 35.195.229.202 (qid:5) with port:26840, pktId:235
*apfOpenDtlSocket: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Received management frame REASSOCIATION REQUEST on BSSID e4:aa:5d:3e:ce:94 destination addr e4:aa:5d:3e:ce:94 slotid 0
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Updating the client capabiility as 4
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Processing assoc-req station:3c:38:f4:c6:b9:05 AP:e4:aa:5d:3e:ce:90-00 ssid : Sigma-Guest thread:388c0098e0
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 apfCreateMobileStationEntryWrapper (apf_ms.c:4516) Changing state for mobile 3c:38:f4:c6:b9:05 on AP e4:aa:5d:3e:ce:90 from Idle to Idle
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Adding mobile on LWAPP AP e4:aa:5d:3e:ce:90(0)
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Created Acct-Session-ID (673b2557/3c:38:f4:c6:b9:05/7217) for the mobile
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Setting hasApChnaged Flag as true. It is a fresh assoc request.
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 req rcv on open Wlan
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Setting RTTS enabled to 0
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Reassociation received from mobile on BSSID e4:aa:5d:3e:ce:a5 AP ap-lv-cisco2702-06
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Station: 3C:38:F4:C6:B9:05 trying to join WLAN with RSSI -42. Checking for XOR roam conditions on AP: E4:AA:5D:3E:CE:90 Slot: 0
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Station: 3C:38:F4:C6:B9:05 is associating to AP E4:AA:5D:3E:CE:90 which is not XOR roam capable
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Global 200 Clients are allowed to AP radio
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Max Client Trap Threshold: 0 cur: 6
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Rf profile 600 Clients are allowed to AP wlan
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Updated local bridging VLAN to 160 while applying WLAN policy
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Updated session timeout to 28800 and Sleep timeout to 720 while applying WLAN policy
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 override for default ap group, marking intgrp NULL
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Applying Interface(sun-guest) policy on Mobile, role Unassociated. Ms NAC State 0 Quarantine Vlan 0 Access Vlan 0
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Not re-applying interface policy for local switching Client
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 After applying Interface(sun-guest) policy on Mobile, role Unassociated. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 0
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 0.0.0.0 START (0) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:3498)
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 0.0.0.0 START (0) Changing Url ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255),Default action is '0' --- (caller apf_policy.c:3518)
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 0.0.0.0 START (0) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:3539)
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Values before applying NASID - interfacetype:3, ovrd:0, mscb nasid:, interface nasid:, APgrpset:0
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 apfApplyWlanPolicy: Apply WLAN Policy over PMIPv6 Client Mobility Type, Tunnel User - 0
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Check before Setting the NAS Id to WLAN specific Id 'lv-vwlc-01'
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Setting the NAS Id to WLAN specific Id 'lv-vwlc-01'
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 apf_policy.c:2783 Assigning the SGT 0 to mobile (earlier sgt 0)
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Increment the SGT 0 policy count reference by the clients 73
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Check the client SGT 0 policy and push it to AP e4:aa:5d:3e:ce:90
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 In processSsidIE:7685 setting Central switched to FALSE
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Disabling flexconnect central association for the client
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Applying site-specific Local Bridging override for station 3c:38:f4:c6:b9:05 - vapId 22, site 'Sigma-Lviv', interface 'sun-guest'
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Applying Local Bridging Interface Policy for station 3c:38:f4:c6:b9:05 - vlan 160, interface id 6, interface 'sun-guest', nasId:'lv-vwlc-01'
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 override from ap group, removing intf group from mscb
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Applying site-specific override for station 3c:38:f4:c6:b9:05 - vapId 22, site 'Sigma-Lviv', interface 'sun-guest'
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Not applying Local Bridge Policy because Site Specific Interface(sun-guest) Policy is already applied.
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Applying Interface(sun-guest) policy on Mobile, role Unassociated. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 0
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Not re-applying interface policy for local switching Client
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 After applying Interface(sun-guest) policy on Mobile, role Unassociated. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 0
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 0.0.0.0 START (0) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:3498)
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 0.0.0.0 START (0) Changing Url ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255),Default action is '0' --- (caller apf_policy.c:3518)
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 0.0.0.0 START (0) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:3539)
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Values before applying NASID - interfacetype:3, ovrd:0, mscb nasid:lv-vwlc-01, interface nasid:, APgrpset:0
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Set Client Non AP specific Flexgroup apfMsAccessVlan = 160
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 This apfMsAccessVlan may be changed later from AAA after L2 Auth
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Cleared localSwitchingVlan, may be assigned later based on AAA override
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 processSsidIE statusCode is 0 and status is 0
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 processSsidIE ssid_done_flag is 0 finish_flag is 0
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 STA - rates (6): 152 36 48 72 96 108 0 0 0 0 0 0 0 0 0 0
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 suppRates statusCode is 0 and gotSuppRatesElement is 1
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Assigning flex webauth IPv4-ACL ID :1, IPv6-ACL ID:65535 for AP WLAN ID : 5
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Assigned flex post-auth IPv4-ACL ID :65535, IPv6-ACL ID:65535 for AP WLAN ID : 5
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Updating AID for REAP AP Client e4:aa:5d:3e:ce:90 - AID ===> 7
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Reassoc Req BSSID e4:aa:5d:3e:ce:a5 AP(ap-lv-cisco2702-06) slot 0 ssid (Sigma-Guest) Tmstmp 829727 AID 7 stCode 0/0 apChngd 0 oldAp 00:00:00:00:00:00
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 0.0.0.0 START (0) Initializing policy
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 0.0.0.0 START (0) Change state to AUTHCHECK (2) last state START (0)
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 apfVapSecurity=0x10 L2=0 SkipWeb=0
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 AuthenticationRequired = 1
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 0.0.0.0 AUTHCHECK (2) Change state to L2AUTHCOMPLETE (4) last state AUTHCHECK (2)
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Flex Central Auth Client
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 0.0.0.0 L2AUTHCOMPLETE (4) DHCP required on AP e4:aa:5d:3e:ce:90 vapId 22 apVapId 5for this client
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 Not Using WMM Compliance code qosCap 00
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 flex webauth acl id to be sent :1 name :Iron_WiFi_Auth_URLs client acl id :65535 name :
*apfMsConnTask_3: Nov 18 11:30:31.792: 3c:38:f4:c6:b9:05 flex webauth ipv6 acl id to be sent :65535 name : *radiusTransportThread: Nov 18 11:30:33.102: 3c:38:f4:c6:b9:05 Accounting-Response received from RADIUS server 35.195.229.202 (qid:5) with port:26840, pktId:236
*apfOrphanSocketTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 Orphan Packet from STA - IP 192.168.206.55
*apfOrphanSocketTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 Static IP client associated to interface sun-guest which can support client subnet.
*apfOrphanSocketTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 192.168.206.55 DHCP_REQD (7) Change state to WEBAUTH_REQD (8) last state DHCP_REQD (7)
*apfOrphanSocketTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 192.168.206.55 WEBAUTH_REQD (8) pemAdvanceState2 7854, Adding TMP rule
*apfOrphanSocketTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 Mobility peer ip is 0, failed to get session type
*apfOrphanSocketTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 192.168.206.55 WEBAUTH_REQD (8) Replacing Fast Path rule
type = Airespace AP Client - ACL passthru
on AP e4:aa:5d:3e:ce:90, slot 0, interface = 1, QOS = 2
IPv4 A
*apfOrphanSocketTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 192.168.206.55 WEBAUTH_REQD (8) Fast Path rule (contd...) 802.1P = 5, DSCP = 46, TokenID = 15206, IntfId = 6 Local Bridging Vlan = 160, Local Bridging intf id = 6
*apfOrphanSocketTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 192.168.206.55 WEBAUTH_REQD (8) Fast Path rule (contd...) AVC Ratelimit: AppID = 0 ,AppAction = 0, AppToken = 15206 AverageRate = 0, BurstRate = 0
*apfOrphanSocketTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 192.168.206.55 WEBAUTH_REQD (8) Fast Path rule (contd...) AVC Ratelimit: AppID = 0 ,AppAction = 0, AppToken = 15206 AverageRate = 0, BurstRate = 0
*apfOrphanSocketTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 192.168.206.55 WEBAUTH_REQD (8) Fast Path rule (contd...) AVC Ratelimit: AppID = 0 ,AppAction = 0, AppToken = 15206 AverageRate = 0, BurstRate = 0
*apfOrphanSocketTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 192.168.206.55 WEBAUTH_REQD (8) Successfully plumbed mobile rule (IPv4 ACL ID 255, IPv6 ACL ID 255, L2 ACL ID 255,URL ACL ID 255,URL ACL Action 0)
*apfOrphanSocketTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 Updating info change db with CMX bitmap 0x0000
*apfOrphanSocketTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 Plumbing web-auth redirect rule due to user logout
*apfOrphanSocketTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 SleepClient :0 :: apfMmRole :1
*apfOrphanSocketTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 192.168.206.55 WEBAUTH_REQD (8) NO release MSCB
*apfOrphanSocketTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 Assigning Address 192.168.206.55 to mobile
*pemReceiveTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 192.168.206.55 Added NPU entry of type 2, dtlFlags 0x0
*pemReceiveTask: Nov 18 11:30:34.908: 3c:38:f4:c6:b9:05 Pushing IPv6: fe80:0000:0000:0000:5d91:dc29:31f4:58ac , intfId:6 and MAC: 3C:38:F4:C6:B9:05 , Binding to Data Plane. SUCCESS !!
*iappSocketTask: Nov 18 11:30:35.131: 3c:38:f4:c6:b9:05 IAPP-IP-UPDATE(0):49 Bytes received for client
*apfReceiveTask: Nov 18 11:30:35.131: 3c:38:f4:c6:b9:05 Recieved MS IPv4 Addr= 192.168.206.55
*apfReceiveTask: Nov 18 11:30:35.131: 3c:38:f4:c6:b9:05 Recieved IPv6 addresses count: 1
*apfReceiveTask: Nov 18 11:30:35.131: 3c:38:f4:c6:b9:05 Updating MS IPv6[1] Addr= fe80:0000:0000:0000:5d91:dc29:31f4:58ac
*apfOpenDtlSocket: Nov 18 11:30:41.686: 3c:38:f4:c6:b9:05 Received management frame ACTION on BSSID e4:aa:5d:3e:ce:94 destination addr e4:aa:5d:3e:ce:94 slotid 0
*apfMsConnTask_3: Nov 18 11:30:41.687: 3c:38:f4:c6:b9:05 Got action frame from the client (ActionCategory:5), payloadLen:16
*apfMsConnTask_3: Nov 18 11:30:41.687: 3c:38:f4:c6:b9:05 Found RM action category code
*apfMsConnTask_3: Nov 18 11:30:41.687: 3c:38:f4:c6:b9:05 Station: 3C:38:F4:C6:B9:05 sent 802.11K neighbor request to AP E4:AA:5D:3E:CE:90
*apfMsConnTask_3: Nov 18 11:30:41.687: 3c:38:f4:c6:b9:05 Station: 3C:38:F4:C6:B9:05 requested neighbors on non XOR roam capable AP E4:AA:5D:3E:CE:90 Slot 0
Solved! Go to Solution.
11-18-2024 04:25 AM
Try to disable Optimized roaming
Optimized Roaming : Client RSSI(-79) is lower than the association RSSI threshold(-74), reject the association request
Optimized roaming will exclude the client if the RSSI is below the threshold thus required a new association and there fore a new authentiacation.
11-18-2024 04:07 AM
@Vladyslav Kmet wrote : >....I'll also add the client's debug log
Also have the client's debug log analyzed with Wireless Debug Analyzer
to get an high level analysis
M.
11-18-2024 04:25 AM
- Below you will find the result of the client's debug when analyzed with Wireless Debug Analyzer
It doesn't give me immediate insights
You can also have a checkup of the virtual controller configuration using
WirelessAnalyzer input (procedure) for AireOs controllers
and feed the output from that into Wireless Config Analyzer
M.
| Connection attempt #1 | |||
| Connection attempt #2 | |||
| Nov 18 11:28:48.404 | *apfMsConnTask_7 | Client roamed to AP/BSSID BSSID e4:aa:5d:60:14:3a AP ap-lv-cisco2702-07 | |
| Nov 18 11:28:48.404 | *apfMsConnTask_7 | Client expiration timer code set for 28800 seconds. The reason: Client is scheduled for session timeout deletion (wlan with webauth) | |
| Nov 18 11:28:48.404 | *apfMsConnTask_7 | WLC/AP is sending an Association Response to the client with status code 0 = Successful association | |
| Connection attempt #3 | |||
| Nov 18 11:30:27.136 | *apfMsConnTask_3 | Client roamed to AP/BSSID BSSID e4:aa:5d:3e:ce:8a AP ap-lv-cisco2702-06 | |
| Nov 18 11:30:27.137 | *apfMsConnTask_3 | Client expiration timer code set for 28800 seconds. The reason: Client is scheduled for session timeout deletion (wlan with webauth) | |
| Nov 18 11:30:27.137 | *apfMsConnTask_3 | WLC/AP is sending an Association Response to the client with status code 0 = Successful association | |
| Nov 18 11:30:31.028 | *apfReceiveTask | Client session has timed out | |
| Nov 18 11:30:31.028 | *apfReceiveTask | Client disassociation event has occured. Possible reasons may be due to AP Radio Reset usually due to channel change or wlan was manually disabled or Client unable to get valid DHCP IP for WLAN using DHCP required | |
| Nov 18 11:30:31.028 | *apfReceiveTask | Client has been deauthenticated | |
| Nov 18 11:30:31.028 | *apfReceiveTask | Client session has timed out | |
| Connection attempt #4 | |||
| Nov 18 11:30:31.792 | *apfMsConnTask_3 | Client roamed to AP/BSSID BSSID e4:aa:5d:3e:ce:a5 AP ap-lv-cisco2702-06 | |
| Nov 18 11:30:34.908 | *apfOrphanSocketTask | Received DHCP ACK, assigning IP Address 192.168.206.55 | |
11-18-2024 04:25 AM
Try to disable Optimized roaming
Optimized Roaming : Client RSSI(-79) is lower than the association RSSI threshold(-74), reject the association request
Optimized roaming will exclude the client if the RSSI is below the threshold thus required a new association and there fore a new authentiacation.
11-21-2024 07:22 AM
It seems that the problem was really in Optimized Roaming and also in RSSI Low Check
Didn't expect that their process would involve complete deauthentication
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide