Client drops - Tuning EAP timers?

I have had some clients complaining (laptop users) about being dropped from the WiFi and this appears to correlate with the events in the WLC log for DOT1X-4-MAX_EAPOL_KEY_RETRANS for those clients.
Drops are more frequent when the network and neighbours networks are under load during the day.
What would your advice be on tuning this? I based my settings off a guide found here:
https://supportforums.cisco.com/document/46101/eap-timers-wireless-lan-controllers
The way I interpret this is that the settings present a bit of a tradeoff between the risk of being dropped and the time it takes to get back in if you are dropped.
We have a WLC 2500 with 2700 APs running 7.6.130.0.
Below are the current settings that we have set:
Edit: Table did not paste correctly
Local Auth Active Timeout1 (in secs) "300"
Identity Request Timeout (in secs) "5"
Identity request Max Retries "12"
Dynamic WEP Key Index "0"
Request Timeout (in secs) "30"
Request Max Retries "2"
Max-Login Ignore Identity Response "enable"
APOL-Key Timeout (in milliSeconds) "1000"
EAPOL-Key Max Retries "2"
EAP-Broadcast Key Interval(in secs) "3600"
Local Auth Active Timeout1 (in secs)
Identity Request Timeout (in secs)
Identity request Max Retries
Dynamic WEP Key Index
Request Timeout (in secs)
Request Max Retries
Max-Login Ignore Identity Response
             disable             enable          
EAPOL-Key Timeout (in milliSeconds)
EAPOL-Key Max Retries
EAP-Broadcast Key Interval(in secs)

I should have mentioned that this is on WPA2 also.
What I'm told is that the drops may occur 2-3 times per day by some users. Other's don't have this issue or aren't bothered enough by it to notice. There is no definite correlation between equipment or area although proximity to APs does influence this (drops are more likely with increased distance) but we still have users without such drops at the same location as users experiencing them. Drops only seem to occur during busy office hours and not outside of them despite this being a 24/7 access office with a considerable amount of people staying late.
I could probably attempt a cli client debug capture and see if something else shows up although the problem is not very frequent so it will be a long day.
Another question would be what is withing the tolerances of how WiFi should perform in this situation. Is it reasonable for this to happen in a WiFi congested spot.
Entries for an affected client in wlc-syslog set to debug (not the cli debug tool) may look like this during a day for the mac aa:bb:cc:aa:bb:cc:
Cisco_ac: 3c:44: *dot1xMsgTask: Mar 13 11:57:34.645: #DOT1X-4-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:508 Max EAPOL-key M1 retransmissions exceeded for client aa:bb:cc:aa:bb:cc
Cisco_ac: 3c:44: *dot1xMsgTask: Mar 13 11:57:41.045: #DOT1X-4-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:508 Max EAPOL-key M1 retransmissions exceeded for client aa:bb:cc:aa:bb:cc
Cisco_ac: 3c:44: *dot1xMsgTask: Mar 13 11:57:47.045: #DOT1X-4-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:508 Max EAPOL-key M1 retransmissions exceeded for client aa:bb:cc:aa:bb:cc
Cisco_ac: 3c:44: *dot1xMsgTask: Mar 13 11:58:25.265: #DOT1X-4-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:508 Max EAPOL-key M1 retransmissions exceeded for client aa:bb:cc:aa:bb:cc
Cisco_ac: 3c:44: *dot1xMsgTask: Mar 13 11:58:32.065: #DOT1X-4-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:508 Max EAPOL-key M1 retransmissions exceeded for client aa:bb:cc:aa:bb:cc
Cisco_ac: 3c:44: *dot1xMsgTask: Mar 13 11:58:38.065: #DOT1X-4-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:508 Max EAPOL-key M1 retransmissions exceeded for client aa:bb:cc:aa:bb:cc

Similar Messages

  • RLDP enabled on WLC causes client drops?

    The release notes for WLC code 4.0.206.0 states, "Enabling RLDP may cause access points connected to the controller to lose connectivity with their
    clients for up to 30 seconds." Does anyone have more information about this? I don't like the word "may" in there. I need to enable RLDP but I can't afford to have clients dropping. Is this something that will work differently in a new release?

    There's no may about it. If clients are on an AP that decides to go rogue-hunting they will be told to "get out of the pool" (de-authenticated) to facilitate their going elsewhere. The same applies to DCA - Dynamic Channel Allocation - part of Auto-RF. If you don't have AP density, clients that use fast roaming, or tolerant apps, you would be best served to turn these features off (or On-Damand).

  • All clients drop association at the same time

    We are seeing clients dropping their association with few APs all at the same time and would not connect back for several minutes (or even hours). And all of a sudden, they are start to connect back normally.
    Wondering what can cause these kind of frequent client disconnects? Only a section of the building is affected and the remaining areas are fine.
    Also, at times, I see the signal strength varies between Excellent and Poor within few seconds.
    We are using LAPs and WiSM.
    Any help would be appreiciated.
    Thank you,
    Mohan

    Its in the 2.4 GHz band. I have observed this behavior. It works well for a day or two and suddenly a couple of APs only drop all the clients all at the same time. After few minutes (or hours) they are connect back to the APs fine.
    This repeats 3 or 4 times in a week.
    Thanks,
    Mohan

  • Lync 2010 client - Drop down entreis are grey instead of black

    We are having Lync 2010 environment. Few users, in Lync 2010 client - Drop down entreis are grey instead of black. Could anyone of you suggest, what needs to be done to fix it?
    Thanks
    Funnyghost

    CAS shutdown shouldn't cause issues.  If you type the number you see into the Lync search box, does it normalize to E.164 format?  If you type in an E.164 number into the dropdown and try to call that, do you see the number there in black?
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question please click "Mark As Answer".
    SWC Unified Communications

  • WRVS4400N v2 WLAN clients dropping

    I purchased a WRVS4400N for my home to replace an older router. Since I started using the Cisco router, WLAN clients drop. I can sometimes get them back after initiating a ping to a static LAN IP, but it takes a few seconds.
    This issue impacts Win Vista, Win7, Mac, Android, and Linux machines...so basically anything that does WiFi. There seem to be many complaints here with no resolution. Has anyone fixed this problem in their network? I'd really hate to return this thing, but it's becoming unusable.

    Mr. Cameron,
    Hi, My name is Eric Moyers. I am a Network Support Engineer in the Cisco Small Business Support Center. I am truly sorry to hear about your issue you are having with your router.
    Have you called into the Small Business Support Center for help on this? If you have may I have your case number so that I can pull your case and review it to see if there is anything I can do for you.
    If you have not called in, I would like to strongly encourage you to call in and get a case created and let one of our agents help you with this issue. THe WRVS4400N is a very good router and I want to make sure that we do everything we can to keep your business.
    Thanks
    Eric Moyers
    Cisco Network Support Engineer
    1-866-606-1866

  • My Anyconnect Secure Mobility Client drops the connection suddently and is unable to re-connect until I restart my laptop

    Hello all,
    My company has deployed AnyConnect Secure Mobility Client 3.1.04059 and we use Windows 7
    The client works fine most of the time, but all of a sudden the connection drops. I can see both the Windows Network and Sharing Center and Cisco AnyConnect suddenly disconnected. This happens most of the times that I change to another location with a different wi-fi network. With my past Windows 2003 and AnyConnect versions (not sure which one that was), the VPN connection would be recovered shortly after re-connecting to the new wi-fi, but with this version it will never allow me to connect to the new wi-fi. Sometimes, if I use the troubleshoot manager from Windows, it will reset my network adapter and that will allow me to connect to the new wi-fi network. Most of the times it won't.
    In those cases, I need to close all programs, log off and log back into Windows. Some other times that will not work either and I will need to restart the whole machine. Restarting the Anyconnect related services alone does not help.
    I am worried because today I lost the connection all of a sudden in my own home, while any other device could easily connect to the wifi. Anyconnect will simply say that it is unable to connect. After many tests I had to reset the computer.
    Am I the only one seeing this problem? Any advice anyone can give me?
    Thanks in advance,
    Antonio

    So it seems that I was barking at the wrong tree :)
    After a bit more research on-line, I found that changing the Power management options for the Wireless network adapter resolved the problem.
    I went to Control Panel> Device Manager> right-click on Wireless Network Adapter> Properties > Power Management tab > Uncheck 'Allow the computer to turn off this device to save power'
    So far so good. Hope this helps others.
    Best,
    Antonio

  • Multiple airport express clients dropping iTunes

    Hello, I'm new to the board and appreciate the resource and any feedback you guys can provide.
    My music is stored on the iMac and I'm trying to stream iTunes to two AX's and the music drops out often. They are both set up as clients. I have searched this forum extensively and think I have isolated the problem as one of the following:
    Something to do with UDP protocal
    Linksys WRT51AB router settings
    512Mb RAM on iMac--too little?
    Here's my troubleshooting thus far:
    Both airport expresses work by themselves in their current locations.
    Locations are close to computer, 1st within 10 feet (1 wall), 2nd another 10-15 feet (2 walls)
    Checked firewall settings and "Block UDP" box is unchecked
    I tried to forward Port 6000 on my Linksys router based on some advice in another thread here to no avail
    AX Firmware 6.3
    iTunes 6.0.4
    OSX 10.4.6
    Thanks for the help
    G4 PB & Intel iMac   Mac OS X (10.4.6)  

    Thanks for the suggestion. I had not tried that option as I had read somewhere that there is only one Linksys router that supports this setup and it's not the one I have.
    I will try the solution and report back. I assume an AX configured as a range extender can also function to stream iTunes?
    Also, for clarification, I am using two airport expresses both of which to stream music. They access my network through my Linksys router hardwired to the iMac.
    Thanks.

  • Client Drops - No Exception Thrown

    Hi All,
    I have a client server application which has been tested extensively and works fine. I have recently migrated the server to a linux environment (it was on windows) and now am experiencing a problem.
    Any exception thrown in the client is programmed to be caught and displayed, as well as emailed to me. I am experiencing problems with one of the clients, they are being dropped after sending and receiving a couple of objects to the server - no exception is thown and no error log is created. It is at the same point every time - about 2 seconds after they connect. On the server side a java.net.SocketException: Broken pipe is thrown when it tries to send the second object to the client (the first data transfer always goes through fine). This is the only client experiencing this issue, it happens at the same spot everytime for them and it works for them when the server is hosted on a windows machine. It's frustrating because even when I run this client from the command line no exception is thrown (even though the part where it fails is in a try catch block), and no error log is created - it simply stops running therefore I don't know how to debug it.

    Presumably you are catching throwable.
    It is quite possible that one end is closing down correctly (so no exception) while the other end is expecting something else to happen and thus an exception occurs.
    If you are sending messages, not data, and there are no message errors then this is not a problem. Simply catch the exception, note in the code that it not a problem, and eat it.

  • EA6900 - Wifi clients dropped, can't reconnect

    I had a chat session recently with support regarding a strange issue with my router.  It seems at least once a week a collection of my wireless clients all disconnect at the same time. it looks like its possible that only certain clients are disconnected.  Today, I wasn't able to connect via the 2.4g network, but the 5g network was still working.  Whenever this happens, the wired connections are just fine (PC, XBox, etc...)
    When I chatted with support, they suggest restarting the router, or even hitting the reset button on the back of the router.  The last time I had this problem, I went ahead and did a total reset.  That hasn't seemed to help.  I'm simply not satisfied that resetting/rebooting the router is a good solution. 
    I'm fairly advanced with router technology and I'm certain that I've got this thing setup correctly... and with consideration of competing signals in the neighborhood.
    So, here is the wierd part.  When this happens, the some wireless clients still show they are connected to the router, but the router doesn't recognize they are online... and the hard-wired clients (PC, XBOX One, etc...) are all working just fine.  Its just the wireless clients that get disconnected.
    Does anyone else see wireless clients getting disconnected on a regular basis and being forced to reboot or restart the wireless signals?  Should I somehow RMA this router?
    Thanks,
    -joe

    I was able to talk to Linksys support again and the person on the phone told me this was the first time she'd heard of this router dropping wireless clients (all the while the wired router was just fine).  I found that comforting in a way, because perhaps I simply have a bad device and an RMA will fix the issue.
    However, before we begin the RMA process, I'm trying one more change to my environment.  She asked that I switch the security setting from 'WPA2 Personal' to 'WPA2/WPA Mixed Personal'.   We'll see if that helps with the problem and then move on.
    Djmanecke, I don't know what to tell you, but perhaps you are having the same problem as I am?  When this happens to you, do you know if wired clients are just fine?  Do you have a way of connecting to the administration page?  If so, I found that simply turning the wifi off and on again is enough to get my wireless clients back online.  If you could script that out, then perhaps you could keep your devices alive?  Problem is, with no usable log whatsoever, you are shooting in the dark.  The lack of a competent log in this device is mind blowing.
    I will say this about Linksys support on this one... the chat session I had with support felt like the analyst was simply reading from que-cards.  I never like that, but I do understand.  The woman on the phone last night read the chat session and really did seem to talk to me with a bit more intelligence than reading from a script.  I appreciated that I felt I was in a conversation and not simply being forced through a rigid decision tree.
    I'll post back to this forum if the last change has done anything to keep this from happening.  It might be worth noting that I have 7-10 wireless devices online at any one time... I think I'll post another thread asking how many clients people have connected.
    Thanks,
    -joe

  • EM 10.1.0 Windows client - Is Tuning Pack available?

    I installed 10g Client-Adminstrator which gives me EM on my Windows machine. I know that the tuning pack is on the EM web version, but is it not available on the client version?

    Does anybody know about this?

  • No "Adobe email Service" in Client drop down list

    I'd like to use Gmail to send photos, but all I have is "mail" in the list.  I'm using a Mac.

    Set default web-based client
    For web-based email service like Google or Yahoo Mail, you can use the Adobe email Service to send Photo Mail directly to recipients.
    Select Edit > Preferences > Sharing (Windows), or Adobe Elements Organizer 11 > Preferences > Sharing (Mac OS).
    Select Adobe E-mail Service from the E-mail Client menu.
    Enter your name and email address.
    Click OK. The first time you use Adobe E-mail Service, a verification email is sent to the address you entered in the Preferences dialog box.
    In the body of the email, you’ll see a Sender Verification code. When prompted to enter the code, copy the code from the verification email, paste it into the dialog box, and then click OK.
    When your email is verified, click OK. Now you can send email directly from Elements Organizer whenever you’re connected to the Internet.
    But this is wrong. Mail.app is your only option via pse in OS X, and there is no photomail at all on a mac, only attachments. That part of the help file is correct.

  • 10.4.6 clients dropping 10.3.9 server home folder

    For over a year our school had many 10.3.x clients authenticating against a win2k AD, and then finding their home folders via AFP on an OS X server 10.3.x. Worked very, very well.
    Now we upgraded one lab of our clients to 10.4.6 and the process breaks.
    What happens is now a student will log on successfuly (against the AD), their home folder will connect. In the finder they will be able to go to their document folder or their desktop or where ever and all is good. Then they run apps. Now their "Documents" folder in the left edge becomes un reachable. If they opened a file from there, then try to just save again, it will say the file is locked.
    However if the use the "Network", then "Servers" then specific stuff they can still see their home folder, and then their documents folder and can save a new copy of their document to the server!
    For 90% of the students this means they cannot work. It's too many steps. I can't even get my staff to follow the Network>servers>studentserver>share path.
    Especially the save while working being broken. It loses most of them.
    Please help!

    Have you tried creating a brand new user on your server and seeing if that one works properly? I had a lot of trouble with a few people in the office here but making new accounts for them and moving their stuff across did the trick.
    I also have to ask: those people aren't going from 10.3 to 10.4 workstations are they? I had a few machines running 10.3 when I set up the server based home folders but realised that various preferences and such weren't compatible between the two: Mail did all sorts of wierd things. I made sure that those 10.3 machines weren't used for server based people until I could upgrade them.

  • WLAN client dropping problem

    My customer is using WLC4400(4.0.179.11) and LAP1130(12.3jx1). Before converting IOS to LWAPP, the WLAN service is not problem.
    But after changing to LWAPP based,the customer is complain about disconnecting problem.
    Intel centrino and other vendor's wlan cards are dropping, cisco wlan cards are no problem.
    After all we have to fall back to IOS version. Is there any Bug report about WLC4400?

    There are some issues with the Intel adapters. I would try downloading the latest driver version to see if that helps. You can navigate to the Intel support page and view the documented disconnect issues.
    -Mark

  • AirPort Express-es clients drop out after idling for 5mn...  Green light on

    Hi,
    Just bought a couple of AEBS' (and upgraded them both to latest firmware v6.3) to stream audio to different rooms in my house (actually bought 3 of them but one was DOA.)
    I got a Verizon/D-Link VDI-624 (latest firmware from Verizon) and configured the AirPort Express' as clients thereof, since the D-Link does not support WDS (anyway WDS would consume some bandwidth I do not need to give away) I am using static addresses for anything but the client laptops (which get pre-allocated addresses from the D-Link router DHCP server.) I use WPA-PSK TKIP for security.
    This all seems to work good, at least for a little while...
    My issue is that after just about 5mn of idle time (after I stop streaming audio, basically) the 2 AirPorts seem to vanish from the network. Green lights still on. But I cannot ping them anymore neither from the laptops nor from the D-Link router. AirPort Admin utility loses track of them as well (could see them for a while, then after stopping audio and coffee break, poof... no more AirPorts in the list!) The kicker is that they won't come back until I power cycle **one of them**. Then more often than not, both seem to come back. Sometimes only the one that was power-cycled. Sometimes, I have to do it again...
    Switched the D-Link for a NetGear WNR-854T and the same problem occurred, so I'd be careful to blame the base router here... I'd rather believe the Apple's devices aren't playing ball with the outer world. Particularly since some other threads around here mention similar issues, albeit with earlier firmware versions...
    Any ideas/sympathetic comments/suggestions/... ?
    Thanks for listening... (sigh!)
    -- Wirelessly over-frustrated OHM.

    Ohm62,
    I am a mac newby. I have a imac 24 inch and I also have the airport. I experienced the same problem for the first couple of days. What I found out is that my cable modem needed resetting. Once I did this my network is up an running fine. Now here is one small catch, when I am away for a while or using bootcamp (to switch over to Vista), it does take a couple of extra seconds for my system to aquire the signal from the network. Hope this helps.
    Tins

  • Debug of client dropping

    Could someone take a look at the output from this debug?
    I attached a notepad of the debug output of a laptop roaming between access-points. At around "Wed Aug 17 07:54:26 2011" on the debug I see what appears to a be client disconnecting and requesting dhcp. I also shoud mention that the device lost 3 pings during this time. Any clues to why this is happening?
    Thanks, Pat

    This is wat i see from the Debug..
    Wed Aug 17 07:54:23 2011: 00:40:96:a1:e9:e3 Association received from mobile on AP 00:25:83:37:51:e0
    Wed Aug 17 07:55:00 2011: 00:40:96:a1:e9:e3 Reassociation received from mobile on AP 00:0b:85:54:f5:10
    The Client was connected to the AP with the MAC 00:25:83:37:51:e0 and all of a sudden the client sends a reassociation to the AP 00:0b:85:54:f5:10
    Are these APs near to each other and are they hearing each other loudly and creating the confusion to the client on whether to join this or the other ?? like i will be connected to the first AP and all of a sudden i get a better signal from the other and i am tryingto join the second AP by getting disconnected to the first??
    Regards
    Surendra

Maybe you are looking for

  • Is there a way to create a custom screensaver with pics/slides that display for different amounts of time?

    Is there a way to create a custom screensaver with pics/slides that display for different amounts of time? Or even add a "video slide" into the screensaver? My business has 3 TVs displayed in our lobby, each with its own apple TV and they are all lin

  • Defined FTP filename but no working....

    Hi, Experts, I try to name the target filename but always no working.... Please kindly help to check anything wrong with my codes & setting, many many thanks~ The format of intended file name is "A1111-" + ID + ".XML" For Example: YC101-4347298442342

  • Handling Multiple web items

    Hi, How do i code multiple web items for: a) Web printing - i've referred to the HOW TO GUIDE.. however it shows illustration of a single table item. I have multiple web items including graphs/chart that I would like to print. Also some columns are n

  • Requesting thoughts on Documentum, Sharepoint, and CMS with FrameMaker

    My company is considering getting a CMS to be used with structured FrameMaker. We now have version 9 but willing to upgrade to version 10. I know that version 10 has the ability to connect to Documentum and Sharepoint. I would like to know others' ex

  • Mailbox Folders Not Showing Mail Correctly

    Hello, I am kind of baffled at what my mail is doing. Here is a screenshot of what my mailboxes look like. When I send a message it doesn't show up in the "sent" or "sent mesages folder", those only show select messages that were sent weeks ago. Also