Can't connect to wireless using certificate with Andorid device

Hi,
I'm trying to connect to my wireless network using an android device with certificate but with no success.
I'm using a WLC 4402 7.0.235.3
SSID Security (WPA2 Auth802.1X + CCKM)
Logs from WLC
(Cisco Controller) debug>*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 Association received from mobile on AP 00:3a:98:7d:cc:30
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 Clearing Address 10.10.168.3 on mobile
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 10.10.168.3 RUN (20) Skipping TMP rule add
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 apfMsRunStateDec
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 10.10.168.3 RUN (20) Change state to DHCP_REQD (7) last state RUN (20)
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 0.0.0.0 DHCP_REQD (7) State Update from Mobility-Complete to Mobility-Incomplete
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 0.0.0.0 DHCP_REQD (7) Reached FAILURE: from line 5154
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 Scheduling deletion of Mobile Station:  (callerId: 9) in 10 seconds
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 pemApfDeleteMobileStation2: APF_MS_PEM_WAIT_L2_AUTH_COMPLETE = 0.
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 0.0.0.0 DHCP_REQD (7) Deleted mobile LWAPP rule on AP [00:3a:98:7d:cc:30]
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 0.0.0.0 DHCP_REQD (7) Changing ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:1633)
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 Applying site-specific IPv6 override for station 20:02:af:a6:0a:85 - vapId 3, site 'BPA-SEDE', interface 'wifi - ip phones'
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 Applying IPv6 Interface Policy for station 20:02:af:a6:0a:85 - vlan 431, interface id 13, interface 'wifi - ip phones'
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 Applying site-specific override for station 20:02:af:a6:0a:85 - vapId 3, site 'BPA-SEDE', interface 'wifi - ip phones'
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 0.0.0.0 DHCP_REQD (7) Changing ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:1633)
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 STA - rates (8): 139 22 24 36 48 72 96 108 12 18 0 0 0 0 0 0
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 STA - rates (10): 139 22 24 36 48 72 96 108 12 18 0 0 0 0 0 0
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 Processing RSN IE type 48, length 20 for mobile 20:02:af:a6:0a:85
*apfMsConnTask_0: Jan 03 08:26:10.866: 20:02:af:a6:0a:85 Received RSN IE with 0 PMKIDs from mobile 20:02:af:a6:0a:85
*apfMsConnTask_0: Jan 03 08:26:10.867: 20:02:af:a6:0a:85 apfMs1xStateDec
*apfMsConnTask_0: Jan 03 08:26:10.867: 20:02:af:a6:0a:85 0.0.0.0 DHCP_REQD (7) Change state to START (0) last state DHCP_REQD (7)
*apfMsConnTask_0: Jan 03 08:26:10.867: 20:02:af:a6:0a:85 pemApfAddMobileStation2: APF_MS_PEM_WAIT_L2_AUTH_COMPLETE = 0.
*apfMsConnTask_0: Jan 03 08:26:10.867: 20:02:af:a6:0a:85 0.0.0.0 START (0) Initializing policy
*apfMsConnTask_0: Jan 03 08:26:10.867: 20:02:af:a6:0a:85 0.0.0.0 START (0) Change state to AUTHCHECK (2) last state DHCP_REQD (7)
*apfMsConnTask_0: Jan 03 08:26:10.867: 20:02:af:a6:0a:85 0.0.0.0 AUTHCHECK (2) Change state to 8021X_REQD (3) last state DHCP_REQD (7)
*apfMsConnTask_0: Jan 03 08:26:10.867: 20:02:af:a6:0a:85 0.0.0.0 8021X_REQD (3) DHCP Not required on AP 00:3a:98:7d:cc:30 vapId 3 apVapId 4for this client
*apfMsConnTask_0: Jan 03 08:26:10.867: 20:02:af:a6:0a:85 Not Using WMM Compliance code qosCap 00
*apfMsConnTask_0: Jan 03 08:26:10.867: 20:02:af:a6:0a:85 0.0.0.0 8021X_REQD (3) Plumbed mobile LWAPP rule on AP 00:3a:98:7d:cc:30 vapId 3 apVapId 4
*apfMsConnTask_0: Jan 03 08:26:10.867: 20:02:af:a6:0a:85 apfPemAddUser2 (apf_policy.c:223) Changing state for mobile 20:02:af:a6:0a:85 on AP 00:3a:98:7d:cc:30 from Associated to Associated
*apfMsConnTask_0: Jan 03 08:26:10.867: 20:02:af:a6:0a:85 Stopping deletion of Mobile Station: (callerId: 48)
*apfMsConnTask_0: Jan 03 08:26:10.867: 20:02:af:a6:0a:85 Sending Assoc Response to station on BSSID 00:3a:98:7d:cc:30 (status 0) ApVapId 4 Slot 0
*apfMsConnTask_0: Jan 03 08:26:10.867: 20:02:af:a6:0a:85 apfProcessAssocReq (apf_80211.c:5272) Changing state for mobile 20:02:af:a6:0a:85 on AP 00:3a:98:7d:cc:30 from Associated to Associated
*pemReceiveTask: Jan 03 08:26:10.873: 20:02:af:a6:0a:85 0.0.0.0 Removed NPU entry.
*dot1xMsgTask: Jan 03 08:26:10.874: 20:02:af:a6:0a:85 Station 20:02:af:a6:0a:85 setting dot1x reauth timeout = 0
*dot1xMsgTask: Jan 03 08:26:10.874: 20:02:af:a6:0a:85 Stopping reauth timeout for 20:02:af:a6:0a:85
*dot1xMsgTask: Jan 03 08:26:10.874: 20:02:af:a6:0a:85 dot1x - moving mobile 20:02:af:a6:0a:85 into Connecting state
*dot1xMsgTask: Jan 03 08:26:10.874: 20:02:af:a6:0a:85 Sending EAP-Request/Identity to mobile 20:02:af:a6:0a:85 (EAP Id 1)
*Dot1x_NW_MsgTask_0: Jan 03 08:26:10.880: 20:02:af:a6:0a:85 Received EAPOL EAPPKT from mobile 20:02:af:a6:0a:85
*Dot1x_NW_MsgTask_0: Jan 03 08:26:10.880: 20:02:af:a6:0a:85 Received Identity Response (count=1) from mobile 20:02:af:a6:0a:85
*Dot1x_NW_MsgTask_0: Jan 03 08:26:10.880: 20:02:af:a6:0a:85 EAP State update from Connecting to Authenticating for mobile 20:02:af:a6:0a:85
*Dot1x_NW_MsgTask_0: Jan 03 08:26:10.880: 20:02:af:a6:0a:85 dot1x - moving mobile 20:02:af:a6:0a:85 into Authenticating state
*Dot1x_NW_MsgTask_0: Jan 03 08:26:10.881: 20:02:af:a6:0a:85 Entering Backend Auth Response state for mobile 20:02:af:a6:0a:85
*Dot1x_NW_MsgTask_0: Jan 03 08:26:10.886: 20:02:af:a6:0a:85 Processing Access-Challenge for mobile 20:02:af:a6:0a:85
*Dot1x_NW_MsgTask_0: Jan 03 08:26:10.886: 20:02:af:a6:0a:85 Entering Backend Auth Req state (id=2) for mobile 20:02:af:a6:0a:85
*Dot1x_NW_MsgTask_0: Jan 03 08:26:10.886: 20:02:af:a6:0a:85 Sending EAP Request from AAA to mobile 20:02:af:a6:0a:85 (EAP Id 2)
*Dot1x_NW_MsgTask_0: Jan 03 08:26:10.888: 20:02:af:a6:0a:85 Received EAPOL EAPPKT from mobile 20:02:af:a6:0a:85
*Dot1x_NW_MsgTask_0: Jan 03 08:26:10.888: 20:02:af:a6:0a:85 Received EAP Response from mobile 20:02:af:a6:0a:85 (EAP Id 2, EAP Type 3)
*Dot1x_NW_MsgTask_0: Jan 03 08:26:10.889: 20:02:af:a6:0a:85 Entering Backend Auth Response state for mobile 20:02:af:a6:0a:85
*Dot1x_NW_MsgTask_0: Jan 03 08:26:10.891: 20:02:af:a6:0a:85 Processing Access-Reject for mobile 20:02:af:a6:0a:85
*Dot1x_NW_MsgTask_0: Jan 03 08:26:10.891: 20:02:af:a6:0a:85 Removing PMK cache due to EAP-Failure for mobile 20:02:af:a6:0a:85 (EAP Id 2)
*Dot1x_NW_MsgTask_0: Jan 03 08:26:10.891: 20:02:af:a6:0a:85 Sending EAP-Failure to mobile 20:02:af:a6:0a:85 (EAP Id 2)
*Dot1x_NW_MsgTask_0: Jan 03 08:26:10.891: 20:02:af:a6:0a:85 Entering Backend Auth Failure state (id=2) for mobile 20:02:af:a6:0a:85
*Dot1x_NW_MsgTask_0: Jan 03 08:26:10.891: 20:02:af:a6:0a:85 Setting quiet timer for 5 seconds for mobile 20:02:af:a6:0a:85
*Dot1x_NW_MsgTask_0: Jan 03 08:26:10.891: 20:02:af:a6:0a:85 dot1x - moving mobile 20:02:af:a6:0a:85 into Unknown state
*osapiBsnTimer: Jan 03 08:26:15.740: 20:02:af:a6:0a:85 802.1x 'quiteWhile' Timer expired for station 20:02:af:a6:0a:85 and for message = M0
*dot1xMsgTask: Jan 03 08:26:15.740: 20:02:af:a6:0a:85 quiet timer completed for mobile 20:02:af:a6:0a:85
*dot1xMsgTask: Jan 03 08:26:15.740: 20:02:af:a6:0a:85 dot1x - moving mobile 20:02:af:a6:0a:85 into Connecting state
*dot1xMsgTask: Jan 03 08:26:15.741: 20:02:af:a6:0a:85 Sending EAP-Request/Identity to mobile 20:02:af:a6:0a:85 (EAP Id 4)

Hi Scott,
I've made the change as you suggested and collected logs from MS NPS and I think that Authentication is failing
Authentication Details:
Connection Request Policy Name:          Use Windows authentication for all users
Network Policy Name:                    Wireless
Authentication Provider:                    Windows
Authentication Server:                    NPSServer.domain.local
Authentication Type:                    EAP
EAP Type:                              -
Account Session Identifier:                    -
Logging Results:                              Accounting information was written to the local log file.
Reason Code:                              22
Reason:                                        The client could not be authenticated  because the Extensible Authentication Protocol (EAP) Type cannot be processed by the server.
Best regards,
Alcides Miguel

Similar Messages

  • Can this be done? Airport extreme connected wireless in extend mode to connect a wireless Mac Pro with an ethernet cable from the extended airport extreme..

    Can this be done? Airport extreme connected wireless in extend mode to connect a wireless Mac Pro with an ethernet cable from the extended airport extreme.

    This will work.....IF....you also have an Apple AirPort router configured to provide your wireless network.
    In other words, you need to have two Apple AirPort routers to extend a wireless network.
    When the AirPort Extreme is configured to "extend" the wireless of the "main" AirPort, it will provide more wireless coverage and the Ethernet ports are enabled, so you could connect your Mac Pro to any of the Ethernet ports and use that as a network and Internet connection.

  • How can i connect my mac book pro with retina display 2014 Mid to 5.1 channel? what is the connector am i to use? i wonder if anybody could probably let me know?

    how can i connect my mac book pro with retina display 2014 Mid to 5.1 channel? what is the connector am i to use? i wonder if anybody could probably let me know?

    https://www.youtube.com/watch?v=72l_FLsXNAg
    I use Hercules found here http://www.hercules.com/us/Sound-Cards/bdd/p/123/gamesurround-muse-xl-pocket-lt3 /
    also read this helpful thread Outputting 5.1 Channel Surround Sound from your Mac

  • I'd like to know how can i connect my old iMac tiger with new one iMac lion. I wanna use the old one for external disk to collect files from there to new one.

    I'd like to know how can i connect my old iMac tiger with new one iMac lion. I wanna use the old one for external disk to collect files from there to new one.

    Hi mshields1162,
    Great question, and welcome to Apple Support Communities.
    First, you may want to choose to have the sidebar displayed for familiarity:
    iTunes 11: Frequently used features
    http://support.apple.com/kb/HT5649
    Afterwards, your device should be displayed if connected:
    We'll want to click on it, and choose the Music tab at the top. Let's make sure "Sync Music" is checked:
    Afterwards, you'll have the option to sync either the entire music library (for your first iPod), or "Selected playlists, artists, albums, and genres" (for the secondary device). Upon selecting this option, four larger option boxes will appear allowing you to pick and choose what content will be synced. For audiobooks, you may need to do the above in the "Books" section. For a visual instruction on how to do this, see the following:
    iTunes 10: Sync to your iPod
    http://support.apple.com/kb/VI72
    Thanks,
    Matt M.

  • How can i connect a Wireless Keyboard and a Trust mouse with a brand new Mac mini?

    How can i connect a Wireless Keyboard and a Trust mouse to a brand new Mac mini?

    Go to the Bluetooth icon on the menu bar and select "Set Up Bluetooth Device". Follow the wizard.
    Alternatively, if you haven't yet unboxed and setup the Mini, you can pair the keyboard to the Mini (and possibly the mouse). However, I would set up with a USB keyboard and mouse and pair the Bluetooth devices afterwards.

  • Calendar. Annoying pop-up message with Using calendar OS X Mavericks. When it tries to connect to iCloud it gives me VERY annoying pop-up message, that it can't connect and that server responds with CalDAVAddSubscriptionCalendarQueueableOperation: 400.

    Using calendar in OS X Mavericks. When it tries to connect to iCloud it gives me VERY annoying pop-up message, that it can't connect and that server responds with CalDAVAddSubscriptionCalendarQueueableOperation: 400.
    Help me please, really need my calendar!

    Hello Steve
    The simple and quick fix is right-clicking on that little Safe icon in the system tray (near the system clock) and choose Stop Backup/Synchronization. Do you see that icon?
    Turn it on and off as needed. Did this work for you?
    Scott

  • I'm trying to use a madcatz controller on the mac but it turns on for 2 seconds and turns off. the system profiler picks it up as a xbox 360 gamepad but says its not been configured. how can i allow my self use this with my games.

    i'm trying to use a madcatz controller on the mac but it turns on for 2 seconds and turns off. the system profiler picks it up as a xbox 360 gamepad but says its not been configured. how can i allow my self use this with my games!

    I have exactly the same problem.
    I'm a little peed-off with Microsoft on this. The original wireless controller I have doesn't work either since the cable I'm using is 'just' the charge and play cable, so a direct connection to my Mac won't work with this cable. It's a cable for god's sake. Why on EARTH put any limitations on this!?!?
    Next I learn I need an additional USB wireless receiver from Microsoft to get my original 360 controller to talk to my Mac. As I certainly don't want to fork any more microsoft dollars on this, this is not an option.
    Next I think, yes! I have a MadCatz 360 wired USB controller. This should surely do the trick just plugging it in and the way I go. But oh no, for some reason I plug my MadCatz Xbox360 controller in, it flashes a few times then switches off and can't be turned on again.
    The System Profiles recognizes it as a MadCatz 360 device controller but that is about it, but the ontroller software I download for the System Prefs (360Controller, USBOverdrive etc) don't even recognize the controller as being plugged in.
    What the **** Is The Microsoft Deal with all of this!?!?
    PS: Oh, and I forgot to mention, there are No drivers for device 4716 that I can find on the MadCatz website, or am I going blind?
    If anyone has a link, it would be appreciated.
    Message was edited by: nostrawaggus

  • Can't connect my new iPhone 4 with internet via Time Capsule. IP4 recognized TC but will not connect with it. (Password etc. is ok)

    Can't connect my new iPhone 4 with internet via Time Capsule. IP4 recognized TC but will not connect with it. (Password etc. is ok)

    Do the usual wireless things.
    Change the wireless name to simple name with only alphanumerics and no spaces.
    Set to manual and use channels 1, 6, 11 in turn.
    For testing take off the security altogether.
    The iphone only works on 2.4ghz so only that band is relevant.

  • Can I connect multiple displays using a mac mini

    Can I connect 2 displays using the mac mini? If so, are there any accessories that I need? Are there certain monitors or connections that I should use?

    Hello,
    Assuming this is a 2012 Mini...
    2nd Display Support:
    Dual/Mirroring*
    2nd Max. Resolution:
    2560x1600*
    Details:
    *This model simultaneously supports 1920x1200 on an HDMI or a DVI display (using the included HDMI-to-DVI adapter) and 2560x1600 on a Thunderbolt or Mini DisplayPort display or even a VGA display (with an optional Mini DisplayPort-to-VGA adapter, which is compatible with the Thunderbolt port).
    http://www.everymac.com/systems/apple/mac_mini/specs/mac-mini-core-i7-2.6-late-2 012-specs.html
    If you need more...
    http://eshop.macsales.com/item/NewerTech/VIDU3HDMIDV/
    http://eshop.macsales.com/item/NewerTech/VIDU2DVIA/

  • Can not connect outside of Lan to with rtsp PVC2300

    I have the following cameras set up at my office
    1 - PVC2300
    2 - WVC54GC
    3 - AXIS 225FD
    I have a BEFSR81 Router
    I have a computer on Windows XP running the surv software to record.  Everything with that is good.
    I also have 2 desktops.
    I have been playing around with the rtsp feed with the pvc2300, but have run into a few problems.
    1(a).  I can not connect outside of the LAN with RTSP with either the VLC player or quicktime.  It connects and asks for a password and then just hangs.
    The PVC 2300 local address is 192.168.1.102 with ports 554, 5000-5010, and 6970-6999 forwarded on the router.  What am I missing?
    1(b) I can successfully connect with my blackberry bold, although when I try to change the default port (554) to something else (I would like to RTSP my the AXIS camera as well,  so I will need a different port) it connects on my bold, but then says server is unresponsive. What am I missing here?
    2.  The voice with the PVC 2300  using http outside of the LAN (internet) lags quite baddly and is choppy.  This happens without fail when I have all 4 cameras running, which I understand is upload bandwidth problem.  But it also happens when I connect to just the PVC2300.  I do have a connection to all 4 cameras inside the LAN to the XP running the surv software, but that is it. Is the my router acting buggy?  I have unplugged the router for 5 sec, and it fixed it for a while, but it always comes back.  I have donwloaded the latest firmware for the router and PVC 2300 and that didnt seem ot fix it either.  Suggestions?
    3.  This is more of a question.  I know the mobile streaming of the PVC 2300 does not include voice.  Is there an app or way that I can just get it to my Blackberry.  Even if I didnt get the video, voice is sometimes more important to me.
    I hope Ive been clear enough in my description, Im very self taught (google is amazing), but I am in no way a techy.
    Thank you in advace for your help.
    Colin

    Glad to hear you are successfully using the SWVMS16. That program is really cool and useful. I just cant tell you how that model of Linksys Router can work for you here (that is not a model we support on this community as its not small business)
    Regarding RTSP access, are you also including the mobile.sdp in the URL?
    RTSP:///mobile.sdp   I noticed in the camera GUI with the newer firmware, you can specify an access code under mobile settings after checking the enable mobile streaming box.  That word may be what you have to include, so check that too...
    Try this locally first and then remotely is the easiest way to see if you got it right, then it just becomes a routing or firewall issue to figure out.
    But your forwarded ports look right and should be opened.
    Under advanced settings, you can define an alternate HTTP, HTTPS or RTSP port

  • Ipad2 -can i connect to internet  using a data card

    ipad2 -can i connect to internet  using a data card

    This article:
    http://edcommunity.apple.com/ali/story.php?itemID=18585&version=6330&pageID=1582 9
    depending on your experience level should tell you all you need to know.
    You don't need mobile me, you just need to know your mac's ip and have vnc
    client software of some sort running on the machine you are travelling with.
    Read the entire article, as once you get past the part about monitoring multiple machines there is some useful info.

  • Can I connect a MKP min AKAi with my Ipad mini retina ?

    Can I connect a MKP min AKAi with my Ipad mini retina ?

    Are you using a powered USB hub as recommended by the unit's manufacturers?
    http://www.noterepeat.com/products/akai-professional/mpd-and-mpk-series/39-conne cting-usb-audio-interfaces-midi-controllers-and-keyboards-to-the-ipad

  • How can I connect my 3gen apple tv with HDMI to my bush LCD32TV022HD which does not have an HDMI port but does have 1)S-Video I/P, 2)Video I/P, 3) L

    How can I connect my 3gen apple tv with HDMI to my BUSH LCD32TV022HD
    This does not have an HDMI port but does have:-
    1) S-Video I/P,
    2) Video I/P,
    3) Audio Input (Left & Right)
    4) Audio In jack (for VGA and DVI source)
    5) DVI input
    6) VGA input

    Welcome to the Apple community.
    The Apple TV doesn't officially support a DVI connection, however you may be able to get it to work. You will first need to check that your TV supports either 720p or 1080p as well as HDCP. If you are able to get the video working over the DVI connection, you may also require a DAC in order to connect with Apple TV's optical audio output to the TVs audio imput.
    You may well wish to make sure that the DVI connection works before spending any money on a DAC..

  • Can not connect my wireless printer to the new router.

    Can not connect my wireless printer to the new router.

    Can you please provide details:
    1.  The make and model of printer
    2.  Make and Model of Wireless Router
    3.  Is your printer connection wireless to router or a cable to PC
    4.  What have you done or attempted to do to establish a connection?
    5.  Any further info to assist

  • Can't connect macbook pro to internet with airport extreme

    Can't connect macbook pro to internet with airport extreme

    If you have ethernet still on your MBP plug it in by ethernet and tell me if that works.
    Tell me how the Airport is setup.. what broadband modem and router you have.
    What OS on the laptop? Yosemite I guess.. since it is the most troublesome.
    Did it work before whatever change was made? Has it worked in the past? When did it stop and what did you do that coincided with it stopping?
    Upgrade to Yosemite??

Maybe you are looking for