09-24-2021 06:35 AM
Does anyone know if there's a bug on this code contributing to this problem we are experiencing?
Controller could not validate “PMKID” for fast roaming, and then association failed to 1Park-15FL-AP20, and controller then performed a client deletion due to client sending incorrect PMKID during EAPOL 4-way handshake, see snipit in Figure 1.
09-24-2021 10:17 AM
[dot11-validate] [19551]: (ERR): MAC: 8c8d.2844.b2c7 Failed to Dot11 validate dot11i pmkids. Pmkid validation failure, Type of pmk cache is not RSN
2021/09/23 14:25:48.816679 {wncd_x_R0-0}{1}: [client-orch-sm] [19551]: (info): MAC: 8c8d.2844.b2c7 Deleting the client, reason: 54, CO_CLIENT_DELETE_REASON_DOT11_INVALID_PMKID, Client state S_CO_L2_AUTH_IN_PROGRESS
2021/09/23 14:25:48.816710 {wncd_x_R0-0}{1}: [client-orch-sm] [19551]: (note): MAC: 8c8d.2844.b2c7 Client delete initiated. Reason: CO_CLIENT_DELETE_REASON_DOT11_INVALID_PMKID, fsm-state transition 18|28|33|42|44|46|48|4d|5c|5e|7f|82|8a|13|17|18|28|33|42|44|46|48|4d|5c|5e|7f|82|8a|13|14|2d|10|
Check this bug : https://cdetsng.cisco.com/summary/#/defect/CSCvx27626
Question : Is this seen on Apple clients?
see if this workaround works
<B>Workaround:</B> Disable 802.11r or Configure mobility group name after switchover to recover from the issue
09-26-2021 02:16 PM
cdets is only accessible to Cisco staff - we need to look at bug search tool: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx27626
Note that's fixed in 17.3.4 so if it is that bug causing the problem then you should be able to upgrade to 17.3.4 quite easily.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide