Guest client often disconnected

Hello, all!
I have an issue - one guest client is disconnecting often. 
WLC 5508. Open Guest WLAN with redirect to ISE. 50-60 clients working constantly and with no problems. 
One of them disconnecting every 5 miinutes. Help me please.
There are logs from client debugging:
*apfReceiveTask: Jan 29 11:57:50.721: 6c:88:14:f5:38:18 pemApfDeleteMobileStation2: APF_MS_PEM_WAIT_L2_AUTH_COMPLETE = 0.
*apfReceiveTask: Jan 29 11:57:50.721: 6c:88:14:f5:38:18 0.0.0.0 START (0) Deleted mobile LWAPP rule on AP [b4:14:89:d1:d5:c0]
*pemReceiveTask: Jan 29 11:57:50.721: 6c:88:14:f5:38:18 0.0.0.0 Removed NPU entry.
*apfReceiveTask: Jan 29 11:57:50.721: 6c:88:14:f5:38:18 Deleting mobile on AP b4:14:89:d1:d5:c0(0)
*apfMsConnTask_5: Jan 29 11:57:51.011: 6c:88:14:f5:38:18 Adding mobile on LWAPP AP b4:14:89:d1:d5:c0(0)
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Association received from mobile on BSSID b4:14:89:d1:d5:c3
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Global 200 Clients are allowed to AP radio
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Max Client Trap Threshold: 0  cur: 12
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Rf profile 600 Clients are allowed to AP wlan
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 override for default ap group, marking intgrp NULL
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Applying Interface policy on Mobile, role Unassociated. Ms NAC State 0 Quarantine Vlan 0 Access Vlan 0
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Re-applying interface policy for client
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 0.0.0.0 START (0) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2219)
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 0.0.0.0 START (0) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2240)
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 apfApplyWlanPolicy: Apply WLAN Policy over PMIPv6 Client Mobility Type
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 In processSsidIE:4796 setting Central switched to TRUE
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 In processSsidIE:4799 apVapId = 4 and Split Acl Id = 65535
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Applying site-specific Local Bridging override for station 6c:88:14:f5:38:18 - vapId 4, site 'MeetingRooms', interface 'guests-internet'
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Applying Local Bridging Interface Policy for station 6c:88:14:f5:38:18 - vlan 480, interface id 21, interface 'guests-internet'
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 override from ap group, removing intf group from mscb
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Applying site-specific override for station 6c:88:14:f5:38:18 - vapId 4, site 'MeetingRooms', interface 'guests-internet'
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Applying Interface policy on Mobile, role Unassociated. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 480
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Re-applying interface policy for client
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 0.0.0.0 START (0) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2219)
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 0.0.0.0 START (0) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2240)
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 processSsidIE  statusCode is 0 and status is 0
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 processSsidIE  ssid_done_flag is 0 finish_flag is 0
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 STA - rates (6): 24 36 176 72 96 108 0 0 0 0 0 0 0 0 0 0
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 suppRates  statusCode is 0 and gotSuppRatesElement is 1
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 0.0.0.0 START (0) Initializing policy
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 0.0.0.0 START (0) Change state to AUTHCHECK (2) last state START (0)
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 0.0.0.0 AUTHCHECK (2) Change state to L2AUTHCOMPLETE (4) last state AUTHCHECK (2)
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 Central switch is TRUE
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 Not Using WMM Compliance code qosCap 00
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 0.0.0.0 L2AUTHCOMPLETE (4) Plumbed mobile LWAPP rule on AP b4:14:89:d1:d5:c0 vapId 4 apVapId 4 flex-acl-name:
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 0.0.0.0 L2AUTHCOMPLETE (4) Change state to DHCP_REQD (7) last state L2AUTHCOMPLETE (4)
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 apfMsAssoStateInc
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 apfPemAddUser2 (apf_policy.c:333) Changing state for mobile 6c:88:14:f5:38:18 on AP b4:14:89:d1:d5:c0 from Idle to Associated
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 apfPemAddUser2:session timeout forstation 6c:88:14:f5:38:18 - Session Tout 0, apfMsTimeOut '0' and sessionTimerRunning flag is  0
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 Stopping deletion of Mobile Station: (callerId: 48)
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 Func: apfPemAddUser2, Ms Timeout = 0, Session Timeout = 0
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 Sending Assoc Response to station on BSSID b4:14:89:d1:d5:c3 (status 0) ApVapId 4 Slot 0
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 apfProcessAssocReq (apf_80211.c:8294) Changing state for mobile 6c:88:14:f5:38:18 on AP b4:14:89:d1:d5:c0 from Associated to Associated
*apfReceiveTask: Jan 29 11:57:51.014: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) State Update from Mobility-Incomplete to Mobility-Complete, mobility role=Local, client state=APF_MS_STATE_ASSOCIATED
*apfReceiveTask: Jan 29 11:57:51.014: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) pemAdvanceState2 5773, Adding TMP rule
*apfReceiveTask: Jan 29 11:57:51.014: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Adding Fast Path rule
  type = Airespace AP - Learn IP address
  on AP b4:14:89:d1:d5:c0, slot 0, interface = 1, QOS = 0
  IPv4 ACL ID = 255, IPv
*apfReceiveTask: Jan 29 11:57:51.014: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) 802.1P = 0, DSCP = 0, TokenID = 15206  Local Bridging Vlan = 480, Local Bridging intf id = 21
*apfReceiveTask: Jan 29 11:57:51.014: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Successfully plumbed mobile rule (IPv4 ACL ID 255, IPv6 ACL ID 255, L2 ACL ID 255)
*pemReceiveTask: Jan 29 11:57:51.014: 6c:88:14:f5:38:18 0.0.0.0 Added NPU entry of type 9, dtlFlags 0x0
*pemReceiveTask: Jan 29 11:57:51.014: 6c:88:14:f5:38:18 Sent an XID frame
*IPv6_Msg_Task: Jan 29 11:57:51.014: 6c:88:14:f5:38:18 Pushing IPv6 Vlan Intf ID 21: fe80:0000:0000:0000:45a0:6c41:35d9:f6a3 , and MAC: 6C:88:14:F5:38:18 , Binding to Data Plane. SUCCESS !! dhcpv6bitmap 0
*IPv6_Msg_Task: Jan 29 11:57:51.015: 6c:88:14:f5:38:18 Link Local address fe80::45a0:6c41:35d9:f6a3 updated to mscb. Not Advancing pem state.Current state: mscb in apfMsMmInitial mobility state and client state APF_MS_STATE_A
*apfMsConnTask_5: Jan 29 11:57:51.721: 6c:88:14:f5:38:18 Association received from mobile on BSSID b4:14:89:d1:d5:c3
*apfMsConnTask_5: Jan 29 11:57:51.721: 6c:88:14:f5:38:18 Global 200 Clients are allowed to AP radio
*apfMsConnTask_5: Jan 29 11:57:51.721: 6c:88:14:f5:38:18 Max Client Trap Threshold: 0  cur: 13
*apfMsConnTask_5: Jan 29 11:57:51.721: 6c:88:14:f5:38:18 Rf profile 600 Clients are allowed to AP wlan
*apfMsConnTask_5: Jan 29 11:57:51.721: 6c:88:14:f5:38:18 override for default ap group, marking intgrp NULL
*apfMsConnTask_5: Jan 29 11:57:51.721: 6c:88:14:f5:38:18 Applying Interface policy on Mobile, role Local. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 480
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 Re-applying interface policy for client
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2219)
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2240)
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 apfApplyWlanPolicy: Apply WLAN Policy over PMIPv6 Client Mobility Type
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 In processSsidIE:4796 setting Central switched to TRUE
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 In processSsidIE:4799 apVapId = 4 and Split Acl Id = 65535
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 Applying site-specific Local Bridging override for station 6c:88:14:f5:38:18 - vapId 4, site 'MeetingRooms', interface 'guests-internet'
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 Applying Local Bridging Interface Policy for station 6c:88:14:f5:38:18 - vlan 480, interface id 21, interface 'guests-internet'
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 override from ap group, removing intf group from mscb
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 Applying site-specific override for station 6c:88:14:f5:38:18 - vapId 4, site 'MeetingRooms', interface 'guests-internet'
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 Applying Interface policy on Mobile, role Local. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 480
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 Re-applying interface policy for client
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2219)
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2240)
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 processSsidIE  statusCode is 0 and status is 0
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 processSsidIE  ssid_done_flag is 0 finish_flag is 0
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 STA - rates (6): 24 36 176 72 96 108 0 0 0 0 0 0 0 0 0 0
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 suppRates  statusCode is 0 and gotSuppRatesElement is 1
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 apfMs1xStateDec
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Change state to START (0) last state DHCP_REQD (7)
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 pemApfAddMobileStation2: APF_MS_PEM_WAIT_L2_AUTH_COMPLETE = 0.
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 0.0.0.0 START (0) Initializing policy
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 START (0) Change state to AUTHCHECK (2) last state START (0)
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 AUTHCHECK (2) Change state to L2AUTHCOMPLETE (4) last state AUTHCHECK (2)
*pemReceiveTask: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 Removed NPU entry.
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 Central switch is TRUE
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 Not Using WMM Compliance code qosCap 00
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 L2AUTHCOMPLETE (4) Plumbed mobile LWAPP rule on AP b4:14:89:d1:d5:c0 vapId 4 apVapId 4 flex-acl-name:
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 L2AUTHCOMPLETE (4) Change state to DHCP_REQD (7) last state L2AUTHCOMPLETE (4)
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) pemApfAddMobileStation2 3451, Adding TMP rule
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Adding Fast Path rule
  type = Airespace AP - Learn IP address
  on AP b4:14:89:d1:d5:c0, slot 0, interface = 1, QOS = 0
  IPv4 ACL ID = 255, IPv
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) 802.1P = 0, DSCP = 0, TokenID = 15206  Local Bridging Vlan = 480, Local Bridging intf id = 21
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Successfully plumbed mobile rule (IPv4 ACL ID 255, IPv6 ACL ID 255, L2 ACL ID 255)
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) pemApfAddMobileStation2 3639, Adding TMP rule
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Replacing Fast Path rule
  type = Airespace AP - Learn IP address
  on AP b4:14:89:d1:d5:c0, slot 0, interface = 1, QOS = 0
  IPv4 ACL ID = 255,
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) 802.1P = 0, DSCP = 0, TokenID = 15206  Local Bridging Vlan = 480, Local Bridging intf id = 21
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Successfully plumbed mobile rule (IPv4 ACL ID 255, IPv6 ACL ID 255, L2 ACL ID 255)
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 apfPemAddUser2 (apf_policy.c:333) Changing state for mobile 6c:88:14:f5:38:18 on AP b4:14:89:d1:d5:c0 from Associated to Associated
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 apfPemAddUser2:session timeout forstation 6c:88:14:f5:38:18 - Session Tout 0, apfMsTimeOut '0' and sessionTimerRunning flag is  0
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 Stopping deletion of Mobile Station: (callerId: 48)
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 Func: apfPemAddUser2, Ms Timeout = 0, Session Timeout = 0
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 Sending Assoc Response to station on BSSID b4:14:89:d1:d5:c3 (status 0) ApVapId 4 Slot 0
*apfMsConnTask_5: Jan 29 11:57:51.724: 6c:88:14:f5:38:18 apfProcessAssocReq (apf_80211.c:8294) Changing state for mobile 6c:88:14:f5:38:18 on AP b4:14:89:d1:d5:c0 from Associated to Associated
*pemReceiveTask: Jan 29 11:57:51.724: 6c:88:14:f5:38:18 0.0.0.0 Added NPU entry of type 9, dtlFlags 0x0
*pemReceiveTask: Jan 29 11:57:51.724: 6c:88:14:f5:38:18 0.0.0.0 Added NPU entry of type 9, dtlFlags 0x0
*apfOrphanSocketTask: Jan 29 11:57:56.416: 6c:88:14:f5:38:18 Orphan Packet from STA - IP 10.10.48.26
*apfOrphanSocketTask: Jan 29 11:57:56.417: 6c:88:14:f5:38:18 Invalid MSCB state, regType=2, Dhcp required!
*apfOrphanSocketTask: Jan 29 11:57:56.417: 6c:88:14:f5:38:18 IPv4 Addr: 10:10:48:26
*DHCP Socket Task: Jan 29 11:58:04.793: 6c:88:14:f5:38:18 DHCP received op BOOTREQUEST (1) (len 308,vlan 501, port 1, encap 0xec03)
*DHCP Socket Task: Jan 29 11:58:04.793: 6c:88:14:f5:38:18 DHCP (encap type 0xec03) mstype 0ff:ff:ff:ff:ff:ff
*DHCP Socket Task: Jan 29 11:58:07.793: 6c:88:14:f5:38:18 DHCP received op BOOTREQUEST (1) (len 308,vlan 501, port 1, encap 0xec03)
*DHCP Socket Task: Jan 29 11:58:07.793: 6c:88:14:f5:38:18 DHCP (encap type 0xec03) mstype 0ff:ff:ff:ff:ff:ff
*SNMPTask: Jan 29 11:58:51.194: 6c:88:14:f5:38:18 Central Switch = TRUE
*SNMPTask: Jan 29 11:58:51.194: 6c:88:14:f5:38:18 Central Switch = TRUE
*SNMPTask: Jan 29 11:58:51.198: 6c:88:14:f5:38:18 Central Switch = TRUE
*SNMPTask: Jan 29 11:58:51.199: 6c:88:14:f5:38:18 Central Switch = TRUE
*DHCP Socket Task: Jan 29 11:59:17.382: 6c:88:14:f5:38:18 DHCP received op BOOTREQUEST (1) (len 308,vlan 501, port 1, encap 0xec03)
*DHCP Socket Task: Jan 29 11:59:17.382: 6c:88:14:f5:38:18 DHCP (encap type 0xec03) mstype 0ff:ff:ff:ff:ff:ff
*DHCP Socket Task: Jan 29 11:59:21.385: 6c:88:14:f5:38:18 DHCP received op BOOTREQUEST (1) (len 308,vlan 501, port 1, encap 0xec03)
*DHCP Socket Task: Jan 29 11:59:21.385: 6c:88:14:f5:38:18 DHCP (encap type 0xec03) mstype 0ff:ff:ff:ff:ff:ff
*apfReceiveTask: Jan 29 11:59:51.725: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) DHCP Policy timeout. Number of DHCP Discover 0, DHCP Request 0 from client
*apfReceiveTask: Jan 29 11:59:51.725: 6c:88:14:f5:38:18 Interface Group was NULL.Number of DHCP Discovery 0 from client
*apfReceiveTask: Jan 29 11:59:51.725: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Pem timed out, Try to delete client in 10 secs.
*apfReceiveTask: Jan 29 11:59:51.725: 6c:88:14:f5:38:18 Scheduling deletion of Mobile Station:  (callerId: 12) in 10 seconds
*osapiBsnTimer: Jan 29 12:00:01.725: 6c:88:14:f5:38:18 apfMsExpireCallback (apf_ms.c:626) Expiring Mobile!
*apfReceiveTask: Jan 29 12:00:01.725: 6c:88:14:f5:38:18 apfMsExpireMobileStation (apf_ms.c:6655) Changing state for mobile 6c:88:14:f5:38:18 on AP b4:14:89:d1:d5:c0 from Associated to Disassociated
*apfReceiveTask: Jan 29 12:00:01.725: 6c:88:14:f5:38:18 Scheduling deletion of Mobile Station:  (callerId: 45) in 10 seconds
*osapiBsnTimer: Jan 29 12:00:11.725: 6c:88:14:f5:38:18 apfMsExpireCallback (apf_ms.c:626) Expiring Mobile!
*apfReceiveTask: Jan 29 12:00:11.726: 6c:88:14:f5:38:18 Sent Deauthenticate to mobile on BSSID b4:14:89:d1:d5:c0 slot 0(caller apf_ms.c:6749)
*apfReceiveTask: Jan 29 12:00:11.726: 6c:88:14:f5:38:18 Setting active key cache index 8 ---> 8
*apfReceiveTask: Jan 29 12:00:11.726: 6c:88:14:f5:38:18 Deleting the PMK cache when de-authenticating the client.
*apfReceiveTask: Jan 29 12:00:11.726: 6c:88:14:f5:38:18 Global PMK Cache deletion failed.
*apfReceiveTask: Jan 29 12:00:11.726: 6c:88:14:f5:38:18 apfMsAssoStateDec
*apfReceiveTask: Jan 29 12:00:11.726: 6c:88:14:f5:38:18 apfMsExpireMobileStation (apf_ms.c:6787) Changing state for mobile 6c:88:14:f5:38:18 on AP b4:14:89:d1:d5:c0 from Disassociated to Idle
Then client go to authenticate again and this logs repeat

i like it when i get debugs :).
*apfReceiveTask: Jan 29 11:59:51.725: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Pem timed out, Try to delete client in 10 secs.
your issue is the client is not doing DHCP. is the dhcp required checkbox enabled on the wlan advanced tab?

Similar Messages

  • GUEST User gets disconnected on Guest Wlan on 2602 ap in Flexconnect mode

    Hey guys,
    I have configured a guest Wlan for guest users in remote site. The Ap's are in flexvonnect mode and authentication is web authentication where a lobby user generates and distributes passwords to guest. The guest devices however gets disconnected after 10-15 minutes and needs to be reauthenticated.
    I have disabled session timeout feature but still no relief.
    Any comments ???
    Thanks

    HI Sandeep,
    I think, it's a expected. client has to re-login/reauth after session timeout or deauth.
    http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008067489f.shtml
    Note: If clients are active after successful login, they will get           de-authenticated and entry can still be removed from the controller after the           session timeout period configured on that WLAN (for example,1800 seconds by           default and can be changed using this CLI command: config wlan           session-timeout ). When this           occurs, client entry is removed from the controller. If the client associates           again, it will move back in a Webauth_Reqd state.
    If clients are in Webauth_Reqd state, no matter if they are active or       idle, the clients will get de-authenticated after a web-auth required       timeout period (for example, 300 seconds and this time is non-user       configurable). All traffic from the client (allowed via Pre-Auth ACL) will be       disrupted. If the client associates again, it will move back to the       Webauth_Reqd state.
    There is an enhancement request filed esp. for your situation with Pre-auth ACL.
    CSCtj32812    DHCP Option to mitigate the problem of guest client rejoining network
    Regards
    Dont forget to rate helpful posts

  • 5508 WLC on 7.4MR2- Clients getting Disconnected using CWA

    We are experiencing an issue with clients getting disconnected/time out from a wlan doing CWA.  The clients are iphones.  A debug client shows the error(Unknown Policy Timeout). This particular WLAN is used for provisioning with ISE. ISE shows the user authenticated the entuire time.  At first, we though it was the user idle timeout setting on the WLAN advanced tab, but after increasing that clients still get disconnected.  The disconnect occurs around 2 minutes.  Sometimes longer around 10 minutes.  Cisco seems to think we are hitting a bug introduced in 7.3.112 and will not be fixed until 8.0.  Below are the bug details and the debug output.  Has anyone seen this?  Any possible work-arounds? Thanks.
    (Cisco Controller) >debug *apfMsConnTask_7: Mar 20 17:19:02.573: Association request from the P2P Client Process P2P Ie and Upadte CB
    *apfMsConnTask_7: Mar 20 17:19:02.765: Association request from the P2P Client Process P2P Ie and Upadte CB
    *apfReceiveTask: Mar 20 17:20:40.442: 18:af:61:bb:55:2f 10.200.21.0 RUN (20) Unknown Policy timeout
    *apfReceiveTask: Mar 20 17:20:40.442: 18:af:61:bb:55:2f 10.200.21.0 RUN (20) Pem timed out, Try to delete client in 10 secs.
    *apfReceiveTask: Mar 20 17:20:40.443: 18:af:61:bb:55:2f Scheduling deletion of Mobile Station:  (callerId: 12) in 10 seconds
    *osapiBsnTimer: Mar 20 17:20:50.443: 18:af:61:bb:55:2f apfMsExpireCallback (apf_ms.c:615) Expiring Mobile!
    *apfReceiveTask: Mar 20 17:20:50.443: 18:af:61:bb:55:2f apfMsExpireMobileStation (apf_ms.c:5835) Changing state for mobile 18:af:61:bb:55:2f on AP 54:78:1a:2f:84:50 from Associated to Disassociated
    *apfReceiveTask: Mar 20 17:20:50.443: 18:af:61:bb:55:2f Scheduling deletion of Mobile Station:  (callerId: 45) in 10 seconds
    *osapiBsnTimer: Mar 20 17:21:00.442: 18:af:61:bb:55:2f apfMsExpireCallback (apf_ms.c:615) Expiring Mobile!
    *apfReceiveTask: Mar 20 17:21:00.443: 18:af:61:bb:55:2f Sent Deauthenticate to mobile on BSSID 54:78:1a:2f:84:50 slot 1(caller apf_ms.c:5929)
    *apfReceiveTask: Mar 20 17:21:00.443: 18:af:61:bb:55:2f Setting active key cache index 8 ---> 8
    *apfReceiveTask: Mar 20 17:21:00.443: 18:af:61:bb:55:2f Deleting the PMK cache when de-authenticating the client.
    *apfReceiveTask: Mar 20 17:21:00.443: 18:af:61:bb:55:2f Global PMK Cache deletion failed.
    *apfReceiveTask: Mar 20 17:21:00.443: 18:af:61:bb:55:2f apfMsAssoStateDec
    *apfReceiveTask: Mar 20 17:21:00.443: 18:af:61:bb:55:2f apfMsExpireMobileStation (apf_ms.c:5967) Changing state for mobile 18:af:61:bb:55:2f on AP 54:78:1a:2f:84:50 from Disassociated to Idle
    https://tools.cisco.com/bugsearch/bug/CSCul43158
    Symptom:Wireless devices are randomly disconnected every 5-10 minutes with unknown policy timeout message in debug client
    Conditions:Clients using Central Web Authentication (CWA).
    Workaround:none
    More Info:

    mine is with the following. Still trying to figure out why.
    *osapiBsnTimer: Mar 17 12:58:05.949: f8:16:54:07:a8:78 apfMsExpireCallback (apf_ms.c:626) Expiring Mobile!
    *apfReceiveTask: Mar 17 12:58:05.949: f8:16:54:07:a8:78 apfMsExpireMobileStation (apf_ms.c:6655) Changing state for mobile f8:16:54:07:a8:78 on AP 00:e1:6d:b2:a6:90 from Associated to Disassociated
    *apfReceiveTask: Mar 17 12:58:05.949: f8:16:54:07:a8:78 Scheduling deletion of Mobile Station:  (callerId: 45) in 10 seconds
    *annyway, i've tried increasing the Session Timeout to 8hours and still testing it .. As my problem is not consistent, i have to monitor and see if its solved.

  • ISE Posture to guest clients

    Hi Guys,
    i'd like to know if is it possible to make a posture to Guest Clients using the Web Agent  after they had been login into the portal.
    thanks

    Of Course it is possible. For detailed information please review the following guide
    Configuring Client Posture Policies
    http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_client_prov.html
    You can also create posture-specific authorization policies for all wired, wireless, and guest deployments by
    specifying the Session:PostureStatus attribute in the authorization policies. This attribute has three
    values, unknown, compliant, and noncompliant, which you can use n the authorization policies
    Regards,
    Ashok

  • RDS 2012 - Slow Perforamance, random disconnects - The RDP protocol component X.224 detected an error (0) in the protocol stream and the client was disconnected.

    We have an RDS environment configured on server 2012 with approx. 20 users connecting for remote app utilization across 4 different locations that are connected via VPN. Server 2012 has great resources from the virtual host so system resource allocation
    shouldn't be an issue. I'm thinking these errors are correlating with the performance problems. Any recommendations on how to effectively end these errors or to boost performance?
    RDS Log File
    Log Name:      Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational
    Source:        Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
    Date:          3/3/2015 7:47:51 PM
    Event ID:      97
    Task Category: RemoteFX module
    Level:         Warning
    Keywords:     
    User:          NETWORK SERVICE
    Computer:      REMOTE1.mzltg.local
    Description: The RDP protocol component X.224 detected an error (0) in the protocol stream and the client was disconnected.
    System Log Error Log Name:      System
    Source:        Schannel
    Date:          3/4/2015 10:42:02 AM
    Event ID:      36887
    Task Category: None
    Level:         Error
    Keywords:     
    User:          SYSTEM
    Computer:      REMOTE1.mzltg.local
    Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 49.

    Hi Shane,
    Do you have any progress at the moment?
    Regarding the TLS error code 49, it indicates a valid certificate was received, but when access control was applied, the sender did not proceed with negotiation.
    More information for you:
    SSL/TLS Alert Protocol & the Alert Codes
    http://blogs.msdn.com/b/kaushal/archive/2012/10/06/ssl-tls-alert-protocol-amp-the-alert-codes.aspx
    Best Regards,
    Amy
    Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

  • Is there a way for internal DHCP Scope to release scope addresses when the wifi client has disconnected?

    DHCP scope is configured on a WLC 5508.
    I'm checking if there' a way for WLC to clear the dhcp leasing when a user is diconnected from wireless?

    Unless the client sends a DHCP Release upon disconnect, which is not mandaded in the protocol, the lease will simply remain until it has expired.  If you're concerned with running out of leases, you only have 2 options. 
    1. reduce the lease time of your dhcp scope
    2. increase the network size to accomodate more usable addresses.
    There isn't a way to force a DHCP address lease to be "cleared" from the WLC simply because the client was disconnected.

  • Maximum number of wired guest clients ??

    Does anybody knows which is the maximum number of simultaneous wired guest clients on a 5508? And in a 2112 controller?
    Wired clients count as wireless clients??
    What about anchoring limitations, what is the effect of wired guest clients on the anchor controller?

    2100 series WLC do not support Wired Guest Access.. 5500 wlc supports.. and i guess 5508 WLC can support max 150 simultaneous logins..
    Lemme know if this naswered ur question and please dont forget to rate the usefull posts!!
    Regards
    Surendra

  • Message server hogs CPU when clients are disconnected

    Hi, I have a problem where java process for the Sun One Message Queue (3.0.1) hogs the cpu when a client is disconnected. I am trying to use the MQ in an environment where clients might crash and try to reconnect in an unpredictable fashion. Most of the time, when I kill the client and restart it, I do not see the problem. Sometimes, however, doing so makes the java process of mq take almsot 100% of Cpu and it does not go down unless i kill the mq process.
    I am using asynchrnous message listeners with transactions, on a persisted queue, although i saw this problem when transaction was disabled.
    Does anyone have any idea what might be the source of the problem? I hope it's just a matter of configuring MQ correctly, but i could figure it out. Help would be greatly appreciated.

    Are you running the enterprise edition and
    using round-robin queues with multiple
    receivers ?
    If so, you may be running into a timing related bug
    in multiple receivers that has been fixed in service
    pack releases of the software
    You should contact sun support to discuss testing with
    the lastest service pack.
    If not, can you provide more information (platform,
    # and type of receivers, etc) on how you are using
    the product
    Thanks

  • Server Cannot Detect that the Client is disconnected, why?

    From what I've read, in order to make server "know" that a client is disconnected, you have to make server "write" to client socket to eventually catch an ioexception.
    So I write a simple server program and a simple client program. The server "writes" to the client every 10 secs. Now I start the server and client, I can tell on the client side that for about every 10 secs, the client gets the message.
    Now I terminate the client program. The server still keeps writing to the client. It's my understanding that after 1 min or so I should see an ioexception. However, 10 minutes passed and the server still keeps writing...
    Why is this happening? Did I miss something?

    I think it happens because the port is still open
    even after the client is closed.And you should not
    get IOException when you send a packet over a open
    port.Err, no, you should get a SocketException when you send data to a port which has already been closed or reset by the peer.

  • Hello, is it normal that my connection wifi is often disconnected, my configuration is a imac under mountain lion which I bought yesterday, sorry for my english im french

    Hello, is it normal that my connection wifi is often disconnected, my configuration is a imac under mountain lion which I bought yesterday, sorry for my english im french,
    thanks for the help and for your answers

    Résolution des problèmes Wi-Fi

  • My icloud'mail is often disconnected

    I don't why my acount iCloud is often disconnected in Mail / MacBook Pro?

    Hello ^=,
    I recommend reviewing the sections titled "If you can't send mail in OS X Mail" and "If you can't receive mail in OS X Mail" in the following article for the issue you described:
    iCloud: Troubleshooting iCloud Mail
    http://support.apple.com/kb/ts4002
    Thank you for using Apple Support Communities.
    Best,
    Sheila M.

  • Call FM destination often disconnected after calling failed

    Dears,
      when i call RFC registered in .net with sap connector, it is often disconnected auto. after calling failed.
      then we should re-start RFC server in .NET, and the connection (RFC destination)will be ok then
      what tools could i use to trace these and any advice ?
    BR

    Hi,
      when i execute RFC with empty table parameters, it is ok.
    But it give error 'data not received' when set some data in the table parameter and then the connection is shutdown.
      ths for your tool .

  • Total throughput and client limitations per guest anchor controller; 7,000 guest clients

    When I read the specs of a Cisco 5508WLC I read the following : 
    Cisco 5508 Wireless LAN Controller (WLC) – 8 Gbps and 7,000 guest clients
    What happens when client 7001 tries to connect ? Is this a hardcoded like the max 500AP's limit ? Or is this just a guideline ?

    7000 is the number of entries it can handle in its client database. So you cannot have more than 7000 clients in single 5508.
    HTH
    Rasika
    **** Pls rate all useful resposnes ****

  • Guest client disconnect non guest clients

    Hi,
    I have 2 WiSM in the branch office and 1 4404 working as Anchor in a DMZ all with the 6.0.188 version. In this moment just 1 AP 1242 is working, in a testing environment with 2 SSID:
    1. internal WLAN with WPA+WPA2 802.1x with certificates
    2. Open guestnet in a EoIP tunnel
    Internal users working correctly, but when other clients start to connect to the guest network, clients connected to the internal network are disconnected.
    Do you know some way to assign to the ssid a priority or what can I do to mitigate this problem,
    Thanks

    i like it when i get debugs :).
    *apfReceiveTask: Jan 29 11:59:51.725: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Pem timed out, Try to delete client in 10 secs.
    your issue is the client is not doing DHCP. is the dhcp required checkbox enabled on the wlan advanced tab?

  • Can't get Guest clients to associate

    Hi All,
    This seems to have happened after upgrading to v7: I've a test guest SSID that my test client PC cannot connect to as it seems to immediately try to associate with the corporate secure SSID. The foreign controller debug showed a line that said something to the effect of "deleting client as SSID has changed" (I was not able to capture this unfortunately and I have not spotted it again), and it then goes on to produce debug outputs as it tries to connect to the corporte SSID. The anchor controller for the guest SSID does not seem to have the traffic passed to it.
    Any suggestions?
    Many Thanks
    Scott

    Hi Scott,
    Would you mind capturing the following from both the foreign, and anchor WLCs:
    debug client
    Is the anchor WLC acting as the DHCP server?  If so, you may be hitting the following:
    /* Style Definitions */
    table.MsoNormalTable
    {mso-style-name:"Table Normal";
    mso-tstyle-rowband-size:0;
    mso-tstyle-colband-size:0;
    mso-style-noshow:yes;
    mso-style-priority:99;
    mso-style-qformat:yes;
    mso-style-parent:"";
    mso-padding-alt:0in 5.4pt 0in 5.4pt;
    mso-para-margin-top:0in;
    mso-para-margin-right:0in;
    mso-para-margin-bottom:10.0pt;
    mso-para-margin-left:0in;
    line-height:115%;
    mso-pagination:widow-orphan;
    font-size:11.0pt;
    font-family:"Calibri","sans-serif";
    mso-ascii-font-family:Calibri;
    mso-ascii-theme-font:minor-latin;
    mso-fareast-font-family:"Times New Roman";
    mso-fareast-theme-font:minor-fareast;
    mso-hansi-font-family:Calibri;
    mso-hansi-theme-font:minor-latin;
    mso-bidi-font-family:"Times New Roman";
    mso-bidi-theme-font:minor-bidi;}
    CSCth68708    Clients are unableto get a DHCP offer from WLC internal DHCP scope
    http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCth68708
    The debug client output will allow you to see if the client is obtaining an IP address as expected, and whether or not the Guest traffic is being tunneled properly to the anchor. If you're finding that the test client continually connects to your corporate WLAN, I would recommend removing all profiles but the Guest WLAN to ensure you're not fighting a supplicant issue.
    Cheers,
    Drew

Maybe you are looking for

  • Has anyone found the way to fix Mavericks from turning their MBP into a snail?

    I have an early 2011 MBP.  2.0ghz with 4gb of RAM.  I have plenty of space on my HDD(140GB) which is not "failing".  Just like about 90% of other users, my mac has slowed way way down since "upgrading" to Mavericks.  Easily half the speed it was sinc

  • Fund Management User Manual

    Dear All, Can anyone give fund management user manual? Regards, Mohan.M Moderator: http://help.sap.com

  • Moving Home option does not work

    I try to use option "Moving Home" but after i enter all details and click continue page reload and stop in same place. I enter details few times, change date, continue and still nothing.

  • Captivate 6 keeps not responding

    I constantly keep getting Captivate 6 not responding message on the title bar when I am working with the timeline transitions.  Can anyone help Cheers Mandy

  • Offline Connectivity in Sybase Uniwired Platform

    Hi All, I need offline connectivity to my Mobile application  developed in SUP.What all configuration ,I have to do to get offline connectivity to my Mobile Application.In my client device what product I have to use to sync? Regards Nidhideep Bhandar