Getting disconnected randomly (5508 controller, 3300 series LAPs)

I am at one of our remote offices and I am noticing my laptop, despite excellent signal strength is periodically losing IP connectivity on the wireless network.  When it drops, all of my IP connectivity stops (pings fail, RDP sessions "await reconnection", etc...).  The lower right corner still shows I'm connected to the hidden WPA2 Enterprise SSID.  The only way to reconnect is to select disconnect on it, then click connect again.  Immediately everything IP based starts working.
There is a 5508 controller in the headquarters.  The site I am at has a 30mbps fiber point to point WAN to the headquarters.  This site has 2 x 3300 series LAPs which are very good coverage.  H-REAP mode is on so traffic terminates at the local office because it is more efficient than traversing the LAN twice for things like local file and print sharing, dhcp, proper active directory sites and services mapping, etc...
The 5508 has a 2008 R2 server running NPS to do radius authentication and it verifies a domain certificate.  To be on the wireless you have to be a member of the domain.
Seems to not give me any problems at the home office so any idea's?
On the 5508 I see this around the times I lose IP connectivity:
*Dot1x_NW_MsgTask_4: Jan 08 14:00:53.599: #DOT1X-3-INVALID_WPA_KEY_MSG_STATE: 1x_eapkey.c:861 Received invalid EAPOL-key M2 msg in START  state - invalid secure bit; KeyLen 24, Key type 1, client 88:53:2e:xx:xx:xx
*Dot1x_NW_MsgTask_4: Jan 08 14:00:52.551: #DOT1X-3-INVALID_WPA_KEY_MSG_STATE: 1x_eapkey.c:861 Received invalid EAPOL-key M2 msg in START  state - invalid secure bit; KeyLen 24, Key type 1, client 88:53:2e:xx:xx:xx
*Dot1x_NW_MsgTask_4: Jan 08 14:00:52.387: #DOT1X-3-ABORT_AUTH: 1x_bauth_sm.c:447  Authentication Aborted for client 88:53:2e:xx:xx:xx
I have 0 (unlimited) as the max for user login policies so not sure why Authentication Aborted message appears.
WLC Software version
7.4.100.0
On the NPS server (2008 R2) I just see my username granted access because it matches the network health policy.
Laptop Sony VAIO SE2
Intel Centrino Advanced-N 6230
Driver version 15.1.1.1 Date: 3/12/2012

Well I'm going to try to move the EAP-Broadcast Key Interval back.  It was set to 3600 which in seconds equals 1 hour.  Seems like not only my laptop but others now have been reporting that every hour on the dot, they stop passing IP traffic.  The regular users just reboot, while people "in the know" disconnect and reconnect, and they are good for an hour.
Towards the bottom of this thread here:
https://discussions.apple.com/thread/3753111?start=0&tstart=0
They suggested this.
I ran this
(Cisco Controller) >config advanced eap bcast-key-interval 86400
Now when I show advanced eap I get this:
EAP-Identity-Request Timeout (seconds)........... 30
EAP-Identity-Request Max Retries................. 2
EAP Key-Index for Dynamic WEP.................... 0
EAP Max-Login Ignore Identity Response........... enable
EAP-Request Timeout (seconds).................... 30
EAP-Request Max Retries.......................... 2
EAPOL-Key Timeout (milliseconds)................. 1000
EAPOL-Key Max Retries............................ 4
EAP-Broadcast Key Interval....................... 86400
I just will take note if this fixes the problem or  not.  If it does not maybe I will return it back to the default 3600.
Your idea of a hidden SSID in the clear to rule out auth issues is a good one, but security wise I don't want an open SSID - hidden or not for an hour in public places.  Sure I could throw it on a VLAN with just one server and run a continuous ping... but I'm at the home office now which never has this issue.
Seems like when it's time for the key to be renewed, I'm thinking the renewal handshake at remote sites is just not making it back to the controller.  However the initial key handshake when you first boot up or associate to the SSID goes over the WAN no issue.  I only say this because at the home office where the WLC is physically located, there is no issue.
The WANs are a minimum of 10mbps over a Ethernet Virtual Private Line which is a busness level service provided by Verizon.
Some WLC info:
Product Version.................................. 7.4.100.0
Bootloader Version............................... 1.0.16
Field Recovery Image Version..................... 6.0.182.0
Firmware Version................................. FPGA 1.7, Env 1.8, USB console 2.2
Build Type....................................... DATA + WPS

Similar Messages

  • [SOLVED] External USB HDD drive gets disconnected randomly

    Hi,
    I'm encountering problem with external HDD drive. Recently I've installed a new drive and reinstalled Arch. I use my old disk as external one connected by USB. Unfortunately it get's disconnected randomly. This is what I found in journal:
    journalctl
    lut 22 17:06:39 t61 kernel: usb 2-1: USB disconnect, device number 2
    lut 22 17:06:39 t61 udisksd[346]: Cleaning up mount point /run/media/kuba/ExtStorage (device 8:19 no longer exist)
    lut 22 17:06:39 t61 systemd-udevd[165]: error opening USB device 'descriptors' file
    lut 22 17:06:39 t61 kernel: Buffer I/O error on dev sdb3, logical block 33062912, lost sync page write
    lut 22 17:06:39 t61 kernel: JBD2: Error -5 detected when updating journal superblock for sdb3-8.
    lut 22 17:06:39 t61 udisksd[346]: Cleaning up mount point /run/media/kuba/ea5c6a7b-1f73-4527-b99c-29920084bd42 (device 8:17 no longer exist)
    lut 22 17:06:39 t61 kernel: Buffer I/O error on dev sdb1, logical block 5275648, lost sync page write
    lut 22 17:06:39 t61 kernel: JBD2: Error -5 detected when updating journal superblock for sdb1-8.
    lut 22 17:06:40 t61 kernel: usb 2-1: new high-speed USB device number 4 using ehci-pci
    uname -a
    Linux t61 3.18.6-1-ARCH #1 SMP PREEMPT Sat Feb 7 08:44:05 CET 2015 x86_64 GNU/Linux
    smartctl -a /dev/sdb
    smartctl 6.3 2014-07-26 r3976 [x86_64-linux-3.18.6-1-ARCH] (local build)
    Copyright (C) 2002-14, Bruce Allen, Christian Franke, www.smartmontools.org
    === START OF INFORMATION SECTION ===
    Model Family: Western Digital Scorpio Blue Serial ATA
    Device Model: WDC WD3200BEVT-00A23T0
    Serial Number: WD-WXG1AB002023
    LU WWN Device Id: 5 0014ee 2054a2f6c
    Firmware Version: 01.01A01
    User Capacity: 320,072,933,376 bytes [320 GB]
    Sector Size: 512 bytes logical/physical
    Rotation Rate: 5400 rpm
    Device is: In smartctl database [for details use: -P show]
    ATA Version is: ATA8-ACS (minor revision not indicated)
    SATA Version is: SATA 2.6, 3.0 Gb/s
    Local Time is: Sun Feb 22 20:46:13 2015 CET
    SMART support is: Available - device has SMART capability.
    SMART support is: Enabled
    === START OF READ SMART DATA SECTION ===
    SMART overall-health self-assessment test result: PASSED
    General SMART Values:
    Offline data collection status: (0x00) Offline data collection activity
    was never started.
    Auto Offline Data Collection: Disabled.
    Self-test execution status: ( 0) The previous self-test routine completed
    without error or no self-test has ever
    been run.
    Total time to complete Offline
    data collection: ( 7800) seconds.
    Offline data collection
    capabilities: (0x7b) SMART execute Offline immediate.
    Auto Offline data collection on/off support.
    Suspend Offline collection upon new
    command.
    Offline surface scan supported.
    Self-test supported.
    Conveyance Self-test supported.
    Selective Self-test supported.
    SMART capabilities: (0x0003) Saves SMART data before entering
    power-saving mode.
    Supports SMART auto save timer.
    Error logging capability: (0x01) Error logging supported.
    General Purpose Logging supported.
    Short self-test routine
    recommended polling time: ( 2) minutes.
    Extended self-test routine
    recommended polling time: ( 93) minutes.
    Conveyance self-test routine
    recommended polling time: ( 5) minutes.
    SCT capabilities: (0x7037) SCT Status supported.
    SCT Feature Control supported.
    SCT Data Table supported.
    SMART Attributes Data Structure revision number: 16
    Vendor Specific SMART Attributes with Thresholds:
    ID# ATTRIBUTE_NAME FLAG VALUE WORST THRESH TYPE UPDATED WHEN_FAILED RAW_VALUE
    1 Raw_Read_Error_Rate 0x002f 200 200 051 Pre-fail Always - 1
    3 Spin_Up_Time 0x0027 152 147 021 Pre-fail Always - 1375
    4 Start_Stop_Count 0x0032 096 096 000 Old_age Always - 4249
    5 Reallocated_Sector_Ct 0x0033 200 200 140 Pre-fail Always - 0
    7 Seek_Error_Rate 0x002e 100 253 000 Old_age Always - 0
    9 Power_On_Hours 0x0032 087 087 000 Old_age Always - 9983
    10 Spin_Retry_Count 0x0032 100 100 000 Old_age Always - 0
    11 Calibration_Retry_Count 0x0032 100 100 000 Old_age Always - 0
    12 Power_Cycle_Count 0x0032 096 096 000 Old_age Always - 4032
    192 Power-Off_Retract_Count 0x0032 200 200 000 Old_age Always - 113
    193 Load_Cycle_Count 0x0032 162 162 000 Old_age Always - 114798
    194 Temperature_Celsius 0x0022 115 096 000 Old_age Always - 28
    196 Reallocated_Event_Count 0x0032 200 200 000 Old_age Always - 0
    197 Current_Pending_Sector 0x0032 200 200 000 Old_age Always - 0
    198 Offline_Uncorrectable 0x0030 100 253 000 Old_age Offline - 0
    199 UDMA_CRC_Error_Count 0x0032 200 200 000 Old_age Always - 0
    200 Multi_Zone_Error_Rate 0x0008 100 253 000 Old_age Offline - 0
    SMART Error Log Version: 1
    No Errors Logged
    SMART Self-test log structure revision number 1
    Num Test_Description Status Remaining LifeTime(hours) LBA_of_first_error
    # 1 Short offline Completed without error 00% 7530 -
    # 2 Short offline Aborted by host 90% 7530 -
    # 3 Short offline Aborted by host 90% 6969 -
    # 4 Short offline Aborted by host 90% 5007 -
    # 5 Short offline Completed without error 00% 5006 -
    # 6 Short offline Completed without error 00% 3168 -
    # 7 Short offline Completed without error 00% 1270 -
    # 8 Short offline Completed without error 00% 944 -
    SMART Selective self-test log data structure revision number 1
    SPAN MIN_LBA MAX_LBA CURRENT_TEST_STATUS
    1 0 0 Not_testing
    2 0 0 Not_testing
    3 0 0 Not_testing
    4 0 0 Not_testing
    5 0 0 Not_testing
    Selective self-test flags (0x0):
    After scanning selected spans, do NOT read-scan remainder of disk.
    If Selective self-test is pending on power-up, resume after 0 minute delay.
    So it's like I want to continue watching a movie from external drive and then player crashes because my hard disk partitions got unmounted...
    I'm wondering if it can happen because disk is underpowered (it's connected only to one USB port because I lost my original USB cable which had two USB plugs). Anyway it would be strange as problem occurs also when disk is 'idle' so then the power consumption is also lower I assume. I can only say this disk was working just fine when used as internal drive. Any ideas?
    Last edited by jakub (2015-02-22 20:08:50)

    Your recommendation to check cable was just - a good recommendation I played a little bit with the B connector and disk immediately stopped working. OMG it was so simple ;p Thanks. I have to buy a new cable (I hope the case is all right).
    EDIT:
    Confirmed with portable mp3 player. Cable (B connector) is damaged.
    I just won't delete this thread as it's a perfect example to show that basic stuff and simplest things should be always checked first !
    Last edited by jakub (2015-02-22 20:28:26)

  • Airport Extreme 802.11n setup done but get disconnected randomly

    Dear friends,
    I have AirPort Exteme 802.11n WIFI
    I did complete set up as per the manual. I set up to use as Extended Network to my existing network.
    My PC is window 7 operating system and is updated. I reset my router also.
    After connecting to my existing network via LAN and complete setup, network available on my iphone 5
    Then I remove LAN cable, it keep ON for 2 or less hours and then gets disconnected and the Amber light on Airport starts blinkin.
    I did set up after default setting also.
    Please advise.
    Regards,
    Jayant Joshi

    Dear friends,
    I have AirPort Exteme 802.11n WIFI
    I did complete set up as per the manual. I set up to use as Extended Network to my existing network.
    My PC is window 7 operating system and is updated. I reset my router also.
    After connecting to my existing network via LAN and complete setup, network available on my iphone 5
    Then I remove LAN cable, it keep ON for 2 or less hours and then gets disconnected and the Amber light on Airport starts blinkin.
    I did set up after default setting also.
    Please advise.
    Regards,
    Jayant Joshi

  • 5508 WLC-6500 Series Switch Etherchannel

    Hi,
    I have a 5508 controller connected to a 6500 VSS pair. Below is the port channel configuration and port configuration.  I am just wondering whether we still have to configure a load balancing method as cisco recommends “port-channel load-balance src-dst-ip” as best practice.
    Does this still applicable for 5508 controller-6500 Series uplink  as the etherchannel is L2 etherchannel?
    Port Channel Config:
    interface Port-channel1
    description To 5508 WLC
    switchport
    switchport trunk encapsulation dot1q
    switchport trunk native vlan 9
    switchport trunk allowed vlan 10,11,12
    switchport mode trunk
    mls qos trust dscp
    end
    Interface Config:
    interface GigabitEthernet1/1/42
    description To 5508 WLC
    switchport
    switchport trunk encapsulation dot1q
    switchport trunk native vlan 9
    switchport trunk allowed vlan 10,11,12
    switchport mode trunk
    wrr-queue bandwidth 5 25 70
    wrr-queue queue-limit 5 25 40
    wrr-queue random-detect min-threshold 1 80 100 100 100 100 100 100 100
    wrr-queue random-detect min-threshold 2 80 100 100 100 100 100 100 100
    wrr-queue random-detect min-threshold 3 50 60 70 80 90 100 100 100
    wrr-queue random-detect max-threshold 1 100 100 100 100 100 100 100 100
    wrr-queue random-detect max-threshold 2 100 100 100 100 100 100 100 100
    wrr-queue random-detect max-threshold 3 60 70 80 90 100 100 100 100
    wrr-queue cos-map 1 1 1
    wrr-queue cos-map 2 1 0
    wrr-queue cos-map 3 1 4
    wrr-queue cos-map 3 2 2
    wrr-queue cos-map 3 3 3
    wrr-queue cos-map 3 4 6
    wrr-queue cos-map 3 5 7
    mls qos trust dscp
    channel-group 1 mode on
    end

    Hello,
    Please check to following link regarding load balancing between 5508 and WLC 6500:
    http://www.learnios.com/viewtopic.php?f=5&t=34555

  • IDEAPAD V460 - USB port disconnects randomly

    Hi Community,
    I am in a trouble with my IDEAPAD V460, 59 - 044185 (4th one from the beginning) which I purchased around a couple of years back. It was working fine without this annoying issue until recently. This partiular model comes with three USB ports, two on the left side, one on the right side.Since around last 15-20 days, any device plugged into any one of the two USB ports on the left hand side of the laptop is getting disconnected randomly. I use an iBall 4*1 USB hub to connect one keybaord, one mouse and one modem to any one of the USB ports on the left side. Initially I thought it to be a software issue. But reinstalling the OS or even switching over to other OS did not solve the issue. To probe more, I refrained from using the hub and connected two of the mentioned devices directly to the left side ports. Still, the problem persists, but the frequency of disconnection is less. Sometimes, the devices gets reconnected, sometimes do not. That is also in a random fashion.
    One of my friend having a Y500 model also having similar issue. As you can understand, given the number of USB devices we use everyday, it's hampering my day-to-day activity.
    Two years being passed, I am out of warranty. I found that there are so many people around here also having same or similar issues. Presently, my perception is that those to USB are not being able to pull out enough power to maintain +5V and causing this random disconnect. Any idea what to do?

    Hi
    Welcome To Lenovo Community
    We are really sorry to hear about the issue you are facing,  
     Please confirm if your experiencing same issue when you connect USB device on right side USB port
    Do give this a try and let us know  
    Hope This Helps
    Cheers!!!
    WW Social Media
    Important Note: If you need help, post your question in the forum, and include your system type, model number and OS. Do not post your serial number.
    Did someone help you today? Press the star on the left to thank them with a Kudo!
    If you find a post helpful and it answers your question, please mark it as an "Accepted Solution"!
    Follow @LenovoForums on Twitter!
    How to send a private message? --> Check out this article.
    English Community   Deutsche Community   Comunidad en Español

  • Wireless Lan Controller users randomly get disconnected

    Hi to all,
    We have issues where clients randomly get disconnected from the wireless network, i have a 4400 WLC with the version 4.2.176.0 and suddenly users are getting disconnected, what i've noticed is that the users are attached to one access point at 100% signal straight and at 54Mbps but suddenly the signal and the speed goes down and the client roams to another access point that is far away from the users location (the user never moves and is next to the access point that they should connect to).
    It seems that the Auto RF algoritm is not working correctly, I upgrade to the 6.0.182.0 release but the problem still remains.
    Any ideas of what else should i try??
    Thanks in advance

    Further on this investigation is that we are using Intel based Wireless adapters in our laptops across the company. All adapters that support 802.11n specifications had issues, except one particular model X200 running Windows XP SP3. Intel has also come up with a fix for the 802.11n clients dropping their connectivity and it is available here:
    http://www-307.ibm.com/pc/support/site.wss/MIGR-71056.html
    The specific section on this page is as below:
    Version 13.01.1000 (6MWC18WW)
    (New) Added support for Intel WiFi Link 5150.
    (Fix) Fixed an issue where wireless connection might be dropped in 802.11n mode.
    Would be curious to know what type of Wireless NICs is everyone else using. What is the driver version? Driver date?
    Thanks!

  • 5508 WLC on 7.4MR2- Clients getting Disconnected using CWA

    We are experiencing an issue with clients getting disconnected/time out from a wlan doing CWA.  The clients are iphones.  A debug client shows the error(Unknown Policy Timeout). This particular WLAN is used for provisioning with ISE. ISE shows the user authenticated the entuire time.  At first, we though it was the user idle timeout setting on the WLAN advanced tab, but after increasing that clients still get disconnected.  The disconnect occurs around 2 minutes.  Sometimes longer around 10 minutes.  Cisco seems to think we are hitting a bug introduced in 7.3.112 and will not be fixed until 8.0.  Below are the bug details and the debug output.  Has anyone seen this?  Any possible work-arounds? Thanks.
    (Cisco Controller) >debug *apfMsConnTask_7: Mar 20 17:19:02.573: Association request from the P2P Client Process P2P Ie and Upadte CB
    *apfMsConnTask_7: Mar 20 17:19:02.765: Association request from the P2P Client Process P2P Ie and Upadte CB
    *apfReceiveTask: Mar 20 17:20:40.442: 18:af:61:bb:55:2f 10.200.21.0 RUN (20) Unknown Policy timeout
    *apfReceiveTask: Mar 20 17:20:40.442: 18:af:61:bb:55:2f 10.200.21.0 RUN (20) Pem timed out, Try to delete client in 10 secs.
    *apfReceiveTask: Mar 20 17:20:40.443: 18:af:61:bb:55:2f Scheduling deletion of Mobile Station:  (callerId: 12) in 10 seconds
    *osapiBsnTimer: Mar 20 17:20:50.443: 18:af:61:bb:55:2f apfMsExpireCallback (apf_ms.c:615) Expiring Mobile!
    *apfReceiveTask: Mar 20 17:20:50.443: 18:af:61:bb:55:2f apfMsExpireMobileStation (apf_ms.c:5835) Changing state for mobile 18:af:61:bb:55:2f on AP 54:78:1a:2f:84:50 from Associated to Disassociated
    *apfReceiveTask: Mar 20 17:20:50.443: 18:af:61:bb:55:2f Scheduling deletion of Mobile Station:  (callerId: 45) in 10 seconds
    *osapiBsnTimer: Mar 20 17:21:00.442: 18:af:61:bb:55:2f apfMsExpireCallback (apf_ms.c:615) Expiring Mobile!
    *apfReceiveTask: Mar 20 17:21:00.443: 18:af:61:bb:55:2f Sent Deauthenticate to mobile on BSSID 54:78:1a:2f:84:50 slot 1(caller apf_ms.c:5929)
    *apfReceiveTask: Mar 20 17:21:00.443: 18:af:61:bb:55:2f Setting active key cache index 8 ---> 8
    *apfReceiveTask: Mar 20 17:21:00.443: 18:af:61:bb:55:2f Deleting the PMK cache when de-authenticating the client.
    *apfReceiveTask: Mar 20 17:21:00.443: 18:af:61:bb:55:2f Global PMK Cache deletion failed.
    *apfReceiveTask: Mar 20 17:21:00.443: 18:af:61:bb:55:2f apfMsAssoStateDec
    *apfReceiveTask: Mar 20 17:21:00.443: 18:af:61:bb:55:2f apfMsExpireMobileStation (apf_ms.c:5967) Changing state for mobile 18:af:61:bb:55:2f on AP 54:78:1a:2f:84:50 from Disassociated to Idle
    https://tools.cisco.com/bugsearch/bug/CSCul43158
    Symptom:Wireless devices are randomly disconnected every 5-10 minutes with unknown policy timeout message in debug client
    Conditions:Clients using Central Web Authentication (CWA).
    Workaround:none
    More Info:

    mine is with the following. Still trying to figure out why.
    *osapiBsnTimer: Mar 17 12:58:05.949: f8:16:54:07:a8:78 apfMsExpireCallback (apf_ms.c:626) Expiring Mobile!
    *apfReceiveTask: Mar 17 12:58:05.949: f8:16:54:07:a8:78 apfMsExpireMobileStation (apf_ms.c:6655) Changing state for mobile f8:16:54:07:a8:78 on AP 00:e1:6d:b2:a6:90 from Associated to Disassociated
    *apfReceiveTask: Mar 17 12:58:05.949: f8:16:54:07:a8:78 Scheduling deletion of Mobile Station:  (callerId: 45) in 10 seconds
    *annyway, i've tried increasing the Session Timeout to 8hours and still testing it .. As my problem is not consistent, i have to monitor and see if its solved.

  • Wifi clients get disconnected in WLC - LAP solution

    Hello all,
    I would like to know what are all possible reasons for wireless clients to get disconnected from LAP (to WLC) solution. We have WAN (MPLS) between LAP and WLC and on the remote site (where we only have LAP, since WLC is in central site) we have clients disconnecting
    This is the error that we see in the traplog:
    Decrypt errors occurred for client XX:XX:XX:XX:XX:XX:XX using WPA key on 802.11b/g interface of AP XX:XX:XX:XX:XX:XX:XX
    Can anyone tell me what can be wrong? Can packet loss cause this? Packet loss of which packets? Data packets or some other packets? Or can network delay produce this? I know we have fragmentation and maybe it can be that fragments are failing somewhere. But I would like to know what should happen in order for this message to be displayed and client to be disconnected
    Thanks
    Milos

    Hello,
    I find out the answer couple of days ago. I totally forgot about this post :)).
    Finally, problem was in fragmented packets that were lost in defragmentation in the devices in the middle (between Cisco WLC and LAPs)
    I found out very annoying fact that Cisco WLC is not supporting ICMP redirect messages. In my scenario, some switch was returning ICMP redirect to every client on network where WLC resides. But since WLC doesn't support ICMP redirects, it keep sending fragments to this switch and eventually we had a lot of duplicated fragments going through our firewalls.
    Those duplicated fragments were eventually start dropping and after this, we started having a lot of errors such this one, and also errors in log showing reply attacks and clients unable to authenticate.
    As soon as the network was redesign to aviod ICMP redirects to ever happen (moved other firewalls on separate LANs so only switch was the only gateway for WLC), this problem stopped
    Thanks
    Milos

  • Why do calls on my iPhone 5 keep getting disconnected at random intervals?

    My iPhone 5 is in a cover. Most of the time when I answer a call, it gets disconnected. Once, a person had to call me back 11 times! Is there something wrong with my iPhone? Why do calls (both outgoing and incoming) keep getting disconnected at random intervals?

    Hi, could be an error, if you back up your data and perform a reset to factory standard could sort it. But before doing this, explore the settings for sounds and vibration patterns see if there are different settings selected by mistake. hope this helps

  • 5508 - iPad getting disconnected from WLAN Using EAP-TLS

    We are seeing an issue with an ipad connecting to a WLAN configured for EAP-TLS using ISE 1.2, getting disconnected.  The ipad will hop top another SSID.  It will connect back to the other ssid when selected.  Any ideas? I have a debug client for when this happened.
    *apfMsConnTask_0: Apr 08 14:03:57.508: Association request from the P2P Client Process P2P Ie and Upadte CB
    *apfMsConnTask_7: Apr 08 14:04:57.855: Association request from the P2P Client Process P2P Ie and Upadte CB
    *apfMsConnTask_5: Apr 08 14:05:17.345: 04:54:53:7b:9e:7a Association received from mobile on BSSID 54:78:1a:2f:84:56
    *apfMsConnTask_5: Apr 08 14:05:17.345: 04:54:53:7b:9e:7a Global 200 Clients are allowed to AP radio
    *apfMsConnTask_5: Apr 08 14:05:17.345: 04:54:53:7b:9e:7a Max Client Trap Threshold: 0  cur: 4
    *apfMsConnTask_5: Apr 08 14:05:17.345: 04:54:53:7b:9e:7a Rf profile 600 Clients are allowed to AP wlan
    *apfMsConnTask_5: Apr 08 14:05:17.346: 04:54:53:7b:9e:7a 172.30.230.213 RUN (20) Skipping TMP rule add
    *apfMsConnTask_5: Apr 08 14:05:17.346: 04:54:53:7b:9e:7a apfMsRunStateDec
    *apfMsConnTask_5: Apr 08 14:05:17.346: 04:54:53:7b:9e:7a 172.30.230.213 RUN (20) Change state to DHCP_REQD (7) last state RUN (20)
    *apfMsConnTask_5: Apr 08 14:05:17.346: 04:54:53:7b:9e:7a 0.0.0.0 DHCP_REQD (7) State Update from Mobility-Complete to Mobility-Incomplete
    *apfMsConnTask_5: Apr 08 14:05:17.346: 04:54:53:7b:9e:7a 0.0.0.0 DHCP_REQD (7) Reached ERROR: from line 6355
    *apfMsConnTask_5: Apr 08 14:05:17.346: 04:54:53:7b:9e:7a pemApfDeleteMobileStation2: APF_MS_PEM_WAIT_L2_AUTH_COMPLETE = 0.
    *apfMsConnTask_5: Apr 08 14:05:17.346: 04:54:53:7b:9e:7a 0.0.0.0 DHCP_REQD (7) Deleted mobile LWAPP rule on AP [54:78:1a:2f:84:50]
    *apfMsConnTask_5: Apr 08 14:05:17.346: 04:54:53:7b:9e:7a Applying Interface policy on Mobile, role Unassociated. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 730
    *apfMsConnTask_5: Apr 08 14:05:17.346: 04:54:53:7b:9e:7a Re-applying interface policy for client 
    *apfMsConnTask_5: Apr 08 14:05:17.346: 04:54:53:7b:9e:7a 0.0.0.0 DHCP_REQD (7) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2018)
    *apfMsConnTask_5: Apr 08 14:05:17.346: 04:54:53:7b:9e:7a 0.0.0.0 DHCP_REQD (7) Changing IPv6 ACL 'none' (ACL ID 

    Use profiles for the wifi settings on the iPad
    A reset of network settings will clear the network history, but the profile will add it back in automatically
    http://images.apple.com/ipad/business/docs/iOS_Deployment_Technical_Reference_EN_Feb14.pdf
    Great Cisco doc for BP and troubleshooting of Apple devices:
    Enterprise Best Practices for Apple Mobile Devices on Cisco ...
    Make sure the app uses URIPersistWifi call 
    https://developer.apple.com/library/ios/documentation/iphone/conceptual/iphoneosprogrammingguide/PerformanceTuning/PerformanceTuning.html

  • AIR-CAP1602i cannot join a WLC 5508 controller

    Hello,
    I'm managing a large number of access points on a Cisco wlc 5508 controller.
    We've recently purchased a bunch of new AIR-CAP1602I-E-K9.
    note that we already have AIR-CAP1602I-E-K9 and other models in production.
    These A.P are not able to join the controller for some reason, I've tried a lot of different things but I am now at a loss.
    I have checked the regulatory domain, upgraded the FUS, manually upgraded the software version of the LAP to match the version on the other A.P.
    I even downgraded/upgraded the WLC code (version 7.4.x and 8.0)
    I use the dhcp option 43 to to send the controller IP.
    Here are the info that can help:
    errors:
    #on A.P
    *Dec 12 09:24:49.659: %CAPWAP-3-ERRORLOG: Invalid event 10 & state 5 combination.
    *Dec 12 09:24:49.659: %CAPWAP-3-ERRORLOG: CAPWAP SM handler: Failed to process message type 10 state 5.
    *Dec 12 09:24:49.659: %CAPWAP-3-ERRORLOG: Failed to handle capwap control message from controller
    #on WLC
    Lwapp join request rejected (WLC version 7.6.130.0)
    Failed to add database entry (WLC version 8.0)
    WLC sysinfo
    Manufacturer's Name.............................. Cisco Systems Inc.
    Product Name..................................... Cisco Controller
    Product Version.................................. 7.6.130.0
    Bootloader Version............................... 1.0.20
    Field Recovery Image Version..................... 7.6.101.1
    Firmware Version................................. FPGA 1.7, Env 1.8, USB console 2.2
    Build Type....................................... DATA + WPS
    System Name...................................... XXX
    System Location..................................
    System Contact...................................
    System ObjectID.................................. 1.3.6.1.4.1.9.1.1069
    Redundancy Mode.................................. Disabled
    IP Address....................................... XXX
    Last Reset....................................... Software reset
    System Up Time................................... 6 days 4 hrs 16 mins 27 secs
    System Timezone Location.........................
    System Stats Realtime Interval................... 5
    System Stats Normal Interval..................... 180
    Configured Country............................... Multiple Countries:CA,FR
    Operating Environment............................ Commercial (0 to 40 C)
    Internal Temp Alarm Limits....................... 0 to 65 C
    Internal Temperature............................. +41 C
    External Temperature............................. +22 C
    Fan Status....................................... OK
    State of 802.11b Network......................... Enabled
    State of 802.11a Network......................... Enabled
    Number of WLANs.................................. 7
    Number of Active Clients......................... 1977
    Burned-in MAC Address............................ A4:93:4C:B0:E4:C0
    Power Supply 1................................... Present, OK
    Power Supply 2................................... Present, OK
    Maximum number of APs supported.................. 250
    AP sh version
    AP58f3.9cb8.3701#sh version
    Cisco IOS Software, C1600 Software (AP1G2-K9W8-M), Version 15.2(4)JB6, RELEASE SOFTWARE (fc1)
    Technical Support: http://www.cisco.com/techsupport
    Copyright (c) 1986-2014 by Cisco Systems, Inc.
    Compiled Fri 22-Aug-14 10:56 by prod_rel_team
    ROM: Bootstrap program is C1600 boot loader
    BOOTLDR: C1600 Boot Loader (AP1G2-BOOT-M) LoaderVersion 15.2(2)JAX, RELEASE SOFTWARE (fc1)
    AP58f3.9cb8.3701 uptime is 31 minutes
    System returned to ROM by power-on
    System image file is "flash:/ap1g2-k9w8-mx.152-4.JB6/ap1g2-k9w8-mx.152-4.JB6"
    Last reload reason:
    This product contains cryptographic features and is subject to United
    States and local country laws governing import, export, transfer and
    use. Delivery of Cisco cryptographic products does not imply
    third-party authority to import, export, distribute or use encryption.
    Importers, exporters, distributors and users are responsible for
    compliance with U.S. and local country laws. By using this product you
    agree to comply with applicable laws and regulations. If you are unable
    to comply with U.S. and local laws, return this product immediately.
    A summary of U.S. laws governing Cisco cryptographic products may be found at:
    http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
    If you require further assistance please contact us by sending email to
    [email protected].
    cisco AIR-CAP1602I-E-K9 (PowerPC) processor (revision B0) with 229366K/32768K bytes of memory.
    Processor board ID FGL1832X5QU
    PowerPC CPU at 533MHz, revision number 0x2151
    Last reset from power-on
    LWAPP image version 7.6.100.0
    1 Gigabit Ethernet interface
    2 802.11 Radios
    32K bytes of flash-simulated non-volatile configuration memory.
    Base ethernet MAC Address: 58:F3:9C:B8:37:01
    Part Number                          : 73-14671-04
    PCA Assembly Number                  : 000-00000-00
    PCA Revision Number                  :
    PCB Serial Number                    : FOC183171L4
    Top Assembly Part Number             : 800-38552-01
    Top Assembly Serial Number           : FGL1832X5QU
    Top Revision Number                  : A0
    Product/Model Number                 : AIR-CAP1602I-E-K9
    AP sh inventory
    NAME: "AP1600", DESCR: "Cisco Aironet 1600 Series (IEEE 802.11n) Access Point"
    PID: AIR-CAP1602I-E-K9 , VID: V01, SN: FGL1832X5QU
    Thanks for your help !

    Hi Olivier,
    The error messages that you have on the debugs:
    *Dec 12 09:24:49.659: %CAPWAP-3-ERRORLOG: Invalid event 10 & state 5 combination.
    *Dec 12 09:24:49.659: %CAPWAP-3-ERRORLOG: CAPWAP SM handler: Failed to process message type 10 state 5.
    *Dec 12 09:24:49.659: %CAPWAP-3-ERRORLOG: Failed to handle capwap control message from controller
    It is related to the bug: CSCuh46442
    https://tools.cisco.com/bugsearch/bug/CSCuh46442/?referring_site=ss
    This bug is resolved in version : 8.0.100.0
    http://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/crn80.html#pgfId-1163951
    Can you please paste here "show ap auth-list" from the controller CLI?
    I suggest to enable MIC if it is not enabled, and then check if the AP's will join or not.
    Kind Regards
    Mohammad Setan

  • Third-Party access to AP health-information over 5508 controller

    Hello,
    Situation:
    Third-Party Tool (Whats up gold) has connectivity to a 5508 controller, only.
    There is no connectivity to the remote LAP access-points from the third-party tool.
    Is it possiply to get the health information (AP available or not) over a controller via SNMP?
    Sven

    Just to elaborate on what Steve is saying:
    The SNMP monitoring of APs is still through the WLC itself. You would be pulling this information out of the WLC not via reachability to the AP itself from your tool.
    Or you could use Whatsup for just an IP reachability (ping) of the AP which would require interaction with the WLC.
    Can Whatsup be a trap receiver? I believe the WLC will send TRAPs for AP up/down events which I would think you could query off of.....

  • Handhelds disconnects randomly

    Hi,
    We have a 4404 WLC. Handhelds are disconnecting randomly. I am getting :
    /* Style Definitions */
    table.MsoNormalTable
    {mso-style-name:"Table Normal";
    mso-tstyle-rowband-size:0;
    mso-tstyle-colband-size:0;
    mso-style-noshow:yes;
    mso-style-priority:99;
    mso-style-qformat:yes;
    mso-style-parent:"";
    mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
    mso-para-margin-top:0cm;
    mso-para-margin-right:0cm;
    mso-para-margin-bottom:10.0pt;
    mso-para-margin-left:0cm;
    line-height:115%;
    mso-pagination:widow-orphan;
    font-size:11.0pt;
    font-family:"Calibri","sans-serif";
    mso-ascii-font-family:Calibri;
    mso-ascii-theme-font:minor-latin;
    mso-fareast-font-family:"Times New Roman";
    mso-fareast-theme-font:minor-fareast;
    mso-hansi-font-family:Calibri;
    mso-hansi-theme-font:minor-latin;
    mso-bidi-font-family:"Times New Roman";
    mso-bidi-theme-font:minor-bidi;}
    *Dec 17 14:32:02.151: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:407 Max EAPOL-key M3 retransmissions exceeded for client 00:0b:6b:af:1b:as
    these logs. I set the EAPOL key timeout ve retries to maximum values but still getting the logs.
    We use like 30 handhelds. 7-8 of them disconnects randomly. The handhelds are reconnecting after 15 minutes which is along time for us. I have looked at the handheld logs it retransmits the key and gets timeout. I have tested the field with 3 handhelds while roaming. None of them disconnected but sometimes handhelds disconnects. Maybe this happens on same handhelds. I will look for it.
    I have searched the forum but couldn't find any solution. I use agressive load balancing. WPA/WPA PSK for authentication.
    Software Version                 6.0.196.0
    Any trick on handhelds or on WLC side that can be done?
    I found this article = http://intermec.custhelp.com/app/answers/detail/a_id/9432
    Will try to set these setting on the handhelds. Maybe some of you experience the problem.

    These bugs should be related to both 5508 and 4400, pls. see Cisco's software advisory:
    http://www.cisco.com/web/software/Wireless/Deferral/Software_Advisory_6_0_196_0.html
    You can try both versions to see if the bugs be fixed. If your problem still not fix after upgrade, you have to open debug(debug client xxx) in WLC, use some wireless analyzing tools to capture the packets and check what happened during the disconnection(always remember to use NTP to sync all the related equipments' time). And of course, call Cisco TAC.
    Before that, you definately should do some site survey to see if there's any coverage hole, also do some testing especially with simple environment as suggested by George. For example, firstly choose open, no ecryption for the WLAN, no session time out, no aironet extention, no dhcp(using static IP), enable low data rate such 1M/2M, etc. then test it, if problem disappear, then add more parameters towards your final enviroment to see which parameter cause the disconnection. If problem still exist, you need to check Intermec wlan driver, call TAC.

  • WLC 5508 - AP 1600 serie's are conecting with WLC but unable to regester with WLC and country is US no matter what I do, i can't change it

    Hello everyone!
    I have a controller of the 5508 series and Ap 1602.
    Ap manage to obtain IP addresses from the DHCP server that is the 5508 controller.
    but the Rev fail to register, please I really vesoin help.
    Below are some show:
    1.  AP:  sh version
    AP0006.f6d5.ea9c#sh version
    Cisco IOS Software, C1600 Software (AP1G2-RCVK9W8-M), Version 15.2(2)JB, RELEASE SOFTWARE (fc1)
    Technical Support: http://www.cisco.com/techsupport
    Copyright (c) 1986-2012 by Cisco Systems, Inc.
    Compiled Tue 11-Dec-12 04:52 by prod_rel_team
    ROM: Bootstrap program is C1600 boot loader
    BOOTLDR: C1600 Boot Loader (AP1G2-BOOT-M) LoaderVersion 15.2(2)JAX, RELEASE SOFTWARE (fc1)
    AP0006.f6d5.ea9c uptime is 38 minutes
    System returned to ROM by power-on
    System image file is "flash:/ap1g2-rcvk9w8-mx/ap1g2-rcvk9w8-mx"
    Last reload reason:
    This product contains cryptographic features and is subject to United
    States and local country laws governing import, export, transfer and
    use. Delivery of Cisco cryptographic products does not imply
    third-party authority to import, export, distribute or use encryption.
    Importers, exporters, distributors and users are responsible for
    compliance with U.S. and local country laws. By using this product you
    agree to comply with applicable laws and regulations. If you are unable
    to comply with U.S. and local laws, return this product immediately.
    A summary of U.S. laws governing Cisco cryptographic products may be found at:
    http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
    If you require further assistance please contact us by sending email to
    [email protected].
    cisco AIR-CAP1602E-E-K9    (PowerPC) processor (revision A0) with 98294K/32768K bytes of memory.
    Processor board ID FGL1709Z6PC
    PowerPC CPU at 533Mhz, revision number 0x2151
    Last reset from power-on
    LWAPP image version 7.4.1.37
    1 Gigabit Ethernet interface
    32K bytes of flash-simulated non-volatile configuration memory.
    Base ethernet MAC Address: 00:06:F6:D5:EA:9C
    Part Number                          : 73-14508-04
    PCA Assembly Number                  : 000-00000-00
    PCA Revision Number                  :
    PCB Serial Number                    : FOC17020MTR
    Top Assembly Part Number             : 800-38553-01
    Top Assembly Serial Number           : FGL1709Z6PC
    Top Revision Number                  : A0
    Product/Model Number                 : AIR-CAP1602E-E-K9
    Configuration register is 0xF
    2.  AP:  sh ip interface brief
    Interface                  IP-Address      OK? Method Status                Protocol
    BVI1                       unassigned      YES DHCP   up                    up
    GigabitEthernet0           unassigned      NO  unset  up                    up
    GigabitEthernet0.1         unassigned      YES unset  up                    up
    3.  AP:  sh inventory
    ---nothing---
    4.  WLC:  sh sysinfo
    (Cisco Controller) >show sysinfo
    Manufacturer's Name.............................. Cisco Systems Inc.
    Product Name..................................... Cisco Controller
    Product Version.................................. 7.3.101.0
    Bootloader Version............................... 1.0.1
    Field Recovery Image Version..................... 6.0.182.0
    Firmware Version................................. FPGA 1.3, Env 1.6, USB console 1.27
    Build Type....................................... DATA + WPS
    System Name...................................... WLC-EEML
    System Location..................................
    System Contact...................................
    System ObjectID.................................. 1.3.6.1.4.1.9.1.1069
    Redundancy Mode.................................. Disabled
    IP Address....................................... 10.10.10.1
    Last Reset....................................... Software reset
    System Up Time................................... 1 days 1 hrs 13 mins 37 secs
    System Timezone Location.........................
    Configured Country............................... US  - United States
    Operating Environment............................ Commercial (0 to 40 C)
    Internal Temp Alarm Limits....................... 0 to 65 C
    Internal Temperature............................. +39 C
    --More-- or (q)uit
    External Temperature............................. +25 C
    Fan Status....................................... OK
    State of 802.11b Network......................... Enabled
    State of 802.11a Network......................... Enabled
    Number of WLANs.................................. 1
    Number of Active Clients......................... 0
    Burned-in MAC Address............................ E0:2F:6D:5D:7D:C0
    Power Supply 1................................... Present, OK
    Power Supply 2................................... Absent
    Maximum number of APs supported.................. 25
    5.  WLC:  sh time
    Time............................................. Fri Jan  3 12:21:37 2014
    Timezone delta................................... 0:0
    Timezone location................................
    NTP Servers
        NTP Polling Interval.........................     86400
         Index     NTP Key Index     NTP Server      NTP Msg Auth Status
    also, I'm in africa but
    I can not change the country or the time zone
    thank you in advance for your help

    Hi,
    By CLI:
    Before change the country code on wlc , You must disable
    WLC > config 802.11a disable network
    WLC  >config 802.11b disable network
    WLC  >config country SA (...or wtever country u are in)
    And then enable both network again.
    WLC  >config 802.11a enable network
    WLC  >config 802.11b enable network
    By GUI:
    First disable both network 802.11a and 802.11b
    Follow these steps to disable the 802.11a and 802.11b/g networks as follows:
    a.          Choose Wireless> 802.11a/n > Network.
    b.          Unselect the 802.11a Network Status check box.
    c.          Click Apply to commit your changes.
    d.          Choose Wireless > 802.11b/g/n > Network.
    e.          Unselect the 802.11b/g Network Status check box.
    f.          Click Apply to commit your changes.
    Change country code on WLC now:
    Choose Wireless > Country
    after changing the country code please enable both networks(802.11a and 802.11b)
    Hope it helps.
    Regards
    Dont forget to rate helpful posts.

  • M451dn disconnects randomly

    Greetings!
    I have two printers over here, both M451dn's. One of the M451's will disconnect randomly from the computer. It does not disconnect completely, leaving the M451dn's printer object faded. Instead it creates a new "unknown device" and refuses to function after that. Every time it does this, it displays "HP Web Services" from its menu automatically. The solution (albeit temporary) is to restart the computer or printer, or replug-in the USB cable from either the printer or computer. After that the printer starts printing from the queue in Windows, and functions normally. It only takes a few hours of use for the printer to go back to its old behavior. 
    I have swapped power and usb cables. Reinstalled the driver, and even plugged the printer directly in to the wall instead of a power strip. Obviously,  I could test to see if it is the printer by swapping it for the other functioning printer. But, I wanted to post and see what HP's forum thought first.
    Thanks for your help!

    These bugs should be related to both 5508 and 4400, pls. see Cisco's software advisory:
    http://www.cisco.com/web/software/Wireless/Deferral/Software_Advisory_6_0_196_0.html
    You can try both versions to see if the bugs be fixed. If your problem still not fix after upgrade, you have to open debug(debug client xxx) in WLC, use some wireless analyzing tools to capture the packets and check what happened during the disconnection(always remember to use NTP to sync all the related equipments' time). And of course, call Cisco TAC.
    Before that, you definately should do some site survey to see if there's any coverage hole, also do some testing especially with simple environment as suggested by George. For example, firstly choose open, no ecryption for the WLAN, no session time out, no aironet extention, no dhcp(using static IP), enable low data rate such 1M/2M, etc. then test it, if problem disappear, then add more parameters towards your final enviroment to see which parameter cause the disconnection. If problem still exist, you need to check Intermec wlan driver, call TAC.

Maybe you are looking for

  • PARSING ADAPTER.SOAP_EXCEPTION

    Hi, I am Integrating Sap(RFC) with Webservice(Soap) using XI. I uploaded the FM and Wsdl file. For Wsdl I created Message Interface having Inbound Asychronous. I have done mapping,Interface mapping and Activated. For ID Part I am Using Two Business S

  • Javax packages not found for J2SDK 1.5.0

    Hi, I am very new to Java SDK. I just installed J2SDK 1.5.0 beta 2 and installed it on my RedHat 9.0 box with root permission at /usr/local/(java-home)/ I can compile simple applications which do not import extension packages. However, when I try to

  • Convert commas to decimal in oracle

    I have source table as create table test LoadId Number(10), Data varchar2(5) LoadID has inceremental values for 1,2,3,..... Data has values as given below 2 0,5 1.5 2,5 0 0 0 2,5 1 1,5 0,5 1,5 1,5 0,5 I want to select values from data field but while

  • How to add batch server group in script parameters

    Hi All, Is there any way to incorporate the "background server groups" directly in the script parameters in REDWOOD? There is an option to provide the target server in parameter TARGET_SERVER. But its not working if i maintain a server group. Any hel

  • CUCM integ with Imagilce billy blue billing

    hi, Can any one share any document, link or steps for integrating Imagilce Billy Blues Billing application with Cisco Call manager 10. 5 Regards