cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2395
Views
0
Helpful
9
Replies

Wireless Bridge Deauthenticationing

scottsassin
Level 1
Level 1

I have a customer with a point to point wireless bride using two 1240 ap's.  Every 12 minutes or so, the MAXRETRIES: maximim is reached, the client is deauthenticated becasue the previous authentication is not valid.  The client then reassociates.  This happens 4 or 5 times every 10 minutes until the whole thing settles down, and is stable. 

9 Replies 9

Amjad Abdullah
VIP Alumni
VIP Alumni

You have to make sure about two main things:

- The line of sight is maintained and is not being blocked by some barrier that interrupts the connection.

- The RF status is healthy and does not have high noise/interference. Check possible sources of noise/interference along the path between the two bridges when the problem is happening.

HTH

Amjad

Rating useful replies is more useful than saying "Thank you"

Rating useful replies is more useful than saying "Thank you"

There are antennas, pictured here.  I believe that these are both Omni Directional.  Although they are pointing towards each other.  Later in the week, I will be moving them so that the beem with is more in the direction of each other.  Now, I believe that the signal is bouncing between the builings.

Looks like a yagi.... can be an issue with water getting into the antenna or the cable getting erroded. 

Thanks,

Scott

Help out other by using the rating system and marking answered questions as "Answered"

-Scott
*** Please rate helpful posts ***

At first I thought that the antennas were omni directional, and would have to move them to a better position.  Now that I know that they are yagis, they are pointed in the proper direction.  Where can I search now, to find out the reason for the max retries occuring 4 times in a row, then settling down, then disassociating every 10 minutes:

Apr 26 14:37:56: %DOT11-6-ADD: Interface Dot11Radio1, Station 003a.9954.3520 Associated to Parent 003a.9951.f000

Apr 26 14:54:31: %DOT11-4-MAXRETRIES: Packet to client 003a.9951.f000 reached max retries, removing the client

Apr 26 14:54:31: %DOT11-6-DISASSOC: Interface Dot11Radio1, Deauthenticating Station 003a.9951.f000 Reason: Previous authentication no longer valid

Apr 26 14:54:31: %DOT11-6-DISASSOC: Interface Dot11Radio1, Deauthenticating Station 003a.9954.3520 

Apr 26 14:54:31: %DOT11-6-ASSOC: Interface Dot11Radio1, Station WGroup-Bridge-D 003a.9951.f000 Reassociated KEY_MGMT[WPAv2 PSK]

Apr 26 14:54:32: %DOT11-6-ADD: Interface Dot11Radio1, Station 003a.9954.3520 Associated to Parent 003a.9951.f000

Apr 26 14:55:26: %DOT11-4-MAXRETRIES: Packet to client 003a.9951.f000 reached max retries, removing the client

Apr 26 14:55:26: %DOT11-6-DISASSOC: Interface Dot11Radio1, Deauthenticating Station 003a.9951.f000 Reason: Previous authentication no longer valid

Apr 26 14:55:26: %DOT11-6-DISASSOC: Interface Dot11Radio1, Deauthenticating Station 003a.9954.3520 

Apr 26 14:55:26: %DOT11-6-ASSOC: Interface Dot11Radio1, Station WGroup-Bridge-D 003a.9951.f000 Reassociated KEY_MGMT[WPAv2 PSK]

Apr 26 14:55:27: %DOT11-6-ADD: Interface Dot11Radio1, Station 003a.9954.3520 Associated to Parent 003a.9951.f000

Apr 26 14:57:36: %DOT11-4-MAXRETRIES: Packet to client 003a.9951.f000 reached max retries, removing the client

Apr 26 14:57:36: %DOT11-6-DISASSOC: Interface Dot11Radio1, Deauthenticating Station 003a.9951.f000 Reason: Previous authentication no longer valid

Apr 26 14:57:36: %DOT11-6-DISASSOC: Interface Dot11Radio1, Deauthenticating Station 003a.9954.3520 

Apr 26 14:57:38: %DOT11-6-ASSOC: Interface Dot11Radio1, Station WGroup-Bridge-D 003a.9951.f000 Reassociated KEY_MGMT[WPAv2 PSK]

Apr 26 14:57:39: %DOT11-6-ADD: Interface Dot11Radio1, Station 003a.9954.3520 Associated to Parent 003a.9951.f000

Apr 26 14:57:40: %DOT11-4-MAXRETRIES: Packet to client 003a.9951.f000 reached max retries, removing the client

Apr 26 14:57:40: %DOT11-6-DISASSOC: Interface Dot11Radio1, Deauthenticating Station 003a.9951.f000 Reason: Previous authentication no longer valid

Apr 26 14:57:40: %DOT11-6-DISASSOC: Interface Dot11Radio1, Deauthenticating Station 003a.9954.3520 

Apr 26 14:57:40: %DOT11-6-ASSOC: Interface Dot11Radio1, Station WGroup-Bridge-D 003a.9951.f000 Reassociated KEY_MGMT[WPAv2 PSK]

Apr 26 14:57:41: %DOT11-6-ADD: Interface Dot11Radio1, Station 003a.9954.3520 Associated to Parent 003a.9951.f000

Apr 26 14:57:44: %DOT11-4-MAXRETRIES: Packet to client 003a.9951.f000 reached max retries, removing the client

Apr 26 14:57:44: %DOT11-6-DISASSOC: Interface Dot11Radio1, Deauthenticating Station 003a.9951.f000 Reason: Previous authentication no longer valid

Apr 26 14:57:44: %DOT11-6-DISASSOC: Interface Dot11Radio1, Deauthenticating Station 003a.9954.3520 

Apr 26 14:57:47: %DOT11-6-ASSOC: Interface Dot11Radio1, Station WGroup-Bridge-D 003a.9951.f000 Reassociated KEY_MGMT[WPAv2 PSK]

Apr 26 14:57:48: %DOT11-6-ADD: Interface Dot11Radio1, Station 003a.9954.3520 Associated to Parent 003a.9951.f000

Apr 26 14:57:48: %DOT11-4-MAXRETRIES: Packet to client 003a.9951.f000 reached max retries, removing the client

Apr 26 14:57:48: %DOT11-6-DISASSOC: Interface Dot11Radio1, Deauthenticating Station 003a.9951.f000 Reason: Previous authentication no longer valid

Apr 26 14:57:48: %DOT11-6-DISASSOC: Interface Dot11Radio1, Deauthenticating Station 003a.9954.3520 

Apr 26 14:57:51: %DOT11-6-ASSOC: Interface Dot11Radio1, Station WGroup-Bridge-D 003a.9951.f000 Reassociated KEY_MGMT[WPAv2 PSK]

Apr 26 14:57:51: %DOT11-6-ADD: Interface Dot11Radio1, Station 003a.9954.3520 Associated to Parent 003a.9951.f000

Question is, it was working and then it's starting to fail. If so, you need to check the antenna and or cabling if nothing on the configurations have changes. Was anything built in between the two bridges recently.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

Can you post the run-config of the root/non-root bridge?  Do you have any maximum retries configured on the dot11radio 1 interface?  If this is not set, then the AP will continue to re-transmit to the point it will deauthenticate the client (non-root bridge) as it's not responding.  You can use a lower retries value with drop option to at least prevent the "deauthentication" from occuring, but you would not be determining the root cause, and re-transmissions (layer 4) would come in to play resulting in decreased throughput across your link.

Can you also output a "show dot11 associations" at your root bridge so we can see the perceived signal strength of the non-root bridge?

I agree with Scott, if this was working and is not now, then it would seem something is dynamic about the RF environment, causing a change in performance; whether it's cabling/alignment, or other obstructions coming in to play between the links.

Can you confirm that no other changes have been made to the AP(s) prior to the issue surfacing.  Config changes, Code upgrades, etc?

Agreed, check output of "sho dot11 associations" and look for signal strength and signal to noise.  Also, is the channel used on the bridge radio set or negotiated  to use least congested at startup?  I would guess deteriorating hardware/cabling as mentioned earlier or a source of new interference on channel used. If configured for least congester, a simple reload of the root bridge will cycle through that selection again.  Adventurous, break out a spectrum analyzer and see what's going on and this should result in a channel selection that you can hard code into the radios. Thx //art

I am sorry but I am not able to see the picture correctly. Can you please provide another one from a wider angle?

Rating useful replies is more useful than saying "Thank you"

Rating useful replies is more useful than saying "Thank you"

Abhishek Abhishek
Cisco Employee
Cisco Employee

Hello Scott,

As per your query i can suggest you the following solution-

You can also implement WGB functionality with the use of a normal AP. You can configure APs as WGBs. In WGB mode, the unit associates to another AP as a client. The unit provides a network connection for the devices that are connected to its Ethernet port.

For example, if you need to provide wireless connectivity for a group of network printers, you can perform these steps:

1.Connect the printers to a hub.

2.Connect the hub to the AP Ethernet port.

3.Configure the AP as a WGB.

For more information on how to configure please refer to the link-

http://www.cisco.com/en/US/products/hw/wireless/ps430/products_configuration_example09186a00805b9b87.shtml

Hope this will help you.

Review Cisco Networking for a $25 gift card