Hello, randomly i can't access my vWLC by WebUI and also all clients on Dot.1x losing connection and can't re-authenticate. Non dot1x clients staying with network. This problem appears with low and high utilization in network at any time. I can access my vWLC by ssh on management port when service port down.
I have couple of errors from syslog: Message: *Dot1x_NW_MsgTask_0: Feb 28 10:41:18.230: %DOT1X-3-INVALID_REPLAY_CTR: 1x_eapkey.c:451 Invalid replay counter from client xx:xx:xx:xx:xx - got 00 00 00 00 00 00 00 03, expected 00 00 00 00 00 00 00 04
Message: *Dot1x_NW_MsgTask_1: Feb 28 10:40:13.929: %DOT1X-3-ABORT_AUTH: 1x_bauth_sm.c:477 Authentication Aborted for client xx:xx:xx:xx:xx Abort Reason:DOT1X RESTARTED DUE TO EAPOL-START/CLIENT ROAM
Message: *spamApTask4: Feb 28 10:36:20.554: %LWAPP-3-REPLAY_ERR: spam_lrad.c:42155 The system has received replay error on slot 0, WLAN ID 1, count 1 from AP xx:xx:xx:xx:xx
Right now i don't have syslog from end to end when disconnects happens. I'm trying to collect it.
I can't find reason why service port going down. I did not configure this system so i think maybe is there issue between Cisco ISE and vWLC, where ISE somehow disables interface on vWLC?. SNMP not enabled.
When i google this i found that when somebody writes sh port summary there's at least 2 interfaces showing. I have only one
: STP Admin Physical Physical Link Link
Pr Type Stat Mode Mode Status Status Trap POE
-- ------- ---- ------- ---------- ---------- ------ ------- ---------
1 Normal Forw Enable Auto 1000 Full Up Enable N/A
Another question: In ISE wlc configured with Service port is it right or need to be management?
Configuration
vWLC 8.3.112.0
ISE 2.2.0.470
16 AP
Sorry for errors in text. I will be glad to any answer.