WLC 2504 AIR-CAP2702E

Hello everybody,
I'm trying to configure a light wireless topology but i get an issue when i'm trying to ping the switch vlan 26 ip from my client. (see below)
Here is my topology:

I finally tagged the port2 of the controller
Here is the arp table of the controller :
(Cisco Controller) >show arp sw
    MAC Address        IP Address     Port   VLAN   Type
2C:33:7A:41:DF:59   10.0.26.2       1      26     Client
28:80:23:5F:F5:00   10.0.26.250      2      26     Host

Similar Messages

  • WLC 2504 can't change WAP name or switch off CDP via WLC gui

    Hi All,
    Please can you assist? I have 1 x Cisco WLC 2504 & 2 x Cisco WAP AIR-CAP1602I-E-K9 running 7.4.100.60.
    All three devices are installed and working correcty within a corporate environment. However, there are a few tweaks that I would like to do, to tidy up the configuration and switch certain elements on or off. For example, my core networking hardware is Huawei and I would like to switch off 'CDP' on the WAP's as the associated error messages are filling up my logging buffer on my switch. So, I https to my WLC, locate the WAP in question, goto 'interfaces' and untick the box for 'CDP state' hit apply, then I get the following error message "controller name is mandatory when controller ip address is configured" and then the tick reappears!
    At present I have two WAP's. Both have static IP addresses and both are reachable on the network. The one WAP did allow me to change the name to something meaningful, but the other WAP would not let me and still has the default MAC address as its name. I have the same issue, when I try to change the name on the WAP it says "controller name is mandatory when controller ip address is configured"
    I have also tried to CLI directly in to the WAP to make these alterations, but as soon as i launch 'putty' it quits out. I guess this is locked down once the WAP's associate with the WLC.
    And around I go.... Someone must have been in this situation, what am i missing? Thanks in advance!

    Hi Andy,
    By default SSH & Telnet is disabled for WLC controlled APs. So you have to enable it first via WLC GUI in order to access the AP via telnet or SSH.
    Wireless -> Select your AP -> Advanced -> Tick Telnet/SSH boxes.
    If you could not change AP name via WLC GUI (it may be a bug), but as I said earlier try to change it via WLC CLI (not AP CLI itself). SSH  to your WLC & then try the following.Old AP name is the one with its mac address.
    (WLC) >config ap name
    (WLC) >save config      
    Are you sure you want to save? (y/n) y
    Configuration Saved
    HTH
    Rasika
    *** Pls rate all useful responses ****

  • AIR-CAP2702I-E-K9 not joining to WLC8500

    Hi there,
    I'm facing a strange issue as the CAPWAP AP is reporting problems while trying to associate the controller.
    These are the steps:
    AP with right IOS (ap3g2-rcvk9w8-xx)
    AP get the IP from DHCP
    AP get the controller IP through DHCP Option 43
    AP send CAPWAP request packet:*Mar  1 00:46:02.139: %CAPWAP-3-EVENTLOG: Discovery Request sent to a.b.c.d with discovery type set to 1
    *Mar  1 00:46:02.139: Sent Msg Type   :
    *Mar  1 00:46:02.139: CAPWAP Control mesg Sent to 255.255.255.255, Port 5246
    *Mar  1 00:46:02.139:   Msg Type   : CAPWAP_DISCOVERY_REQUEST
    *Mar  1 00:46:02.139:   Msg Length : 165
    *Mar  1 00:46:02.139:   Msg SeqNum : 0
    WLC recieve CAPWAP request and detect LWAPP AP and denies the petition
    *spamApTask3: Apr 17 13:34:34.370: a0:ec:f9:26:91:c4 Discovery Response sent to u.v.x.y:26909
    *spamApTask0: Apr 17 13:34:34.373: a0:ec:f9:26:91:c4 Received LWAPP DISCOVERY REQUEST to 10:05:ca:be:f7:a9 on port '4'
    *spamApTask0: Apr 17 13:34:34.373: a0:ec:f9:26:91:c4 Discarding discovery request in LWAPP from AP supporting CAPWAP
    AP receive the CAPWAP respond and get into a loop trying to associate endless.*Mar  1 00:46:02.171: CAPWAP Control mesg Recd from a.b.c.d, Port 5246
    *Mar  1 00:46:02.171:   HLEN 2,   Radio ID 0,    WBID 1
    *Mar  1 00:46:02.171:   Msg Type   : CAPWAP_DISCOVERY_RESPONSE
    *Mar  1 00:46:02.171:   Msg Length : 130
    *Mar  1 00:46:02.171:   Msg SeqNum : 0
    Attached you can find the captures from both AP console and controller.

    APa0ec.f926.91c4#sh version
    Cisco IOS Software, C2700 Software (AP3G2-RCVK9W8-M), Version 15.3(3)JA, RELEASE SOFTWARE (fc1)
    Technical Support: http://www.cisco.com/techsupport
    Copyright (c) 1986-2014 by Cisco Systems, Inc.
    Compiled Fri 15-Aug-14 12:27 by prod_rel_team
    ROM: Bootstrap program is C2700 boot loader
    BOOTLDR: C2700 Boot Loader (AP3G2-BOOT-M) LoaderVersion 15.2(4)JB5m, RELEASE SOFTWARE (fc2)
    APa0ec.f926.91c4 uptime is 46 minutes
    System returned to ROM by power-on
    System image file is "flash:/ap3g2-rcvk9w8-mx/ap3g2-rcvk9w8-xx"
    Last reload reason:
    This product contains cryptographic features and is subject to United
    States and local country laws governing import, export, transfer and
    use. Delivery of Cisco cryptographic products does not imply
    third-party authority to import, export, distribute or use encryption.
    Importers, exporters, distributors and users are responsible for
    compliance with U.S. and local country laws. By using this product you
    agree to comply with applicable laws and regulations. If you are unable
    to comply with U.S. and local laws, return this product immediately.
    A summary of U.S. laws governing Cisco cryptographic products may be found at:
    http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
    If you require further assistance please contact us by sending email to
    [email protected].
    cisco AIR-CAP2702I-E-K9 (PowerPC) processor (revision A0) with 376810K/134656K bytes of memory.
    Processor board ID FCW1847NH67
    PowerPC CPU at 800Mhz, revision number 0x2151
    Last reset from power-on
    LWAPP image version 8.0.72.236
    1 Gigabit Ethernet interface
    32K bytes of flash-simulated non-volatile configuration memory.
    Base ethernet MAC Address: A0:EC:F9:26:91:C4
    Part Number                          : 73-15824-03
    PCA Assembly Number                  : 000-00000-00
    PCA Revision Number                  :
    PCB Serial Number                    : FOC184672B9
    Top Assembly Part Number             : 068-100379-01
    Top Assembly Serial Number           : FCW1847NH67
    Top Revision Number                  : A0
    Product/Model Number                 : AIR-CAP2702I-E-K9  
    Configuration register is 0xF
    And for the controller:
    (wcontrollerbe1.bsch) >show sysinfo
    Manufacturer's Name.............................. Cisco Systems Inc.
    Product Name..................................... Cisco Controller
    Product Version.................................. 7.4.121.0
    RTOS Version..................................... 7.4.121.0
    Bootloader Version............................... 8.0.100.0
    Emergency Image Version.......................... 8.0.100.0
    Build Type....................................... DATA + WPS
    System Name...................................... wcontrollerbe1
    System Location.................................. CPD Este
    System Contact................................... Red Datos
    System ObjectID.................................. 1.3.6.1.4.1.9.1.1615
    Redundancy Mode.................................. Disabled
    IP Address....................................... a.b.c.d
    System Up Time................................... 35 days 16 hrs 20 mins 56 secs
    System Timezone Location......................... (GMT +1:00) Amsterdam, Berlin, Rome, Vienna
    System Stats Realtime Interval................... 5
    System Stats Normal Interval..................... 180
    Configured Country............................... ES  - Spain
    Operating Environment............................ Commercial (10 to 35 C)

  • WLC 2504 HA Configuration

    Hi Guys,
    What configuration should I use in order to configure HA using 2x Cisco WLC 2504 ?
    - Do I need to have licenses for 2x Controllers ? I have only one WLC with license installed.  
    At the moment I have the following scenario below.
    AIR-CT2504-K9 – Primary (30 Aps Supported)
    AIR-CT2504-HA-K9 – Secondary (0 license)
    Software Version - 7.6.130.0 (Both Controllers)
    Both controllers are going to be in the same place.
    Can anyone help me please ?
    Thanks,
    Everton

    Thanks Scott Fella !
    Just one more question.
    Should I use a crossover cable to connect the primary controller to the secondary ? Or should I use a switch to connect them ?
    Thanks,
    Everton

  • Compatible APs for Cisco WLC 2504

    Is the cisco wlc 2504 compatible with the AIR-CAP-3602l and if so what firmware would i need to be running on the WLC ? My firm rushed out and bought a mesh solution without doing their homework

    Hi Doug,
    Data sheet for 3602 access point shows it support 2500 series WLC. Please refer to the link below.
    http://www.cisco.com/en/US/prod/collateral/wireless/ps5678/ps11983/data_sheet_c78-686782.html
    You may need firmware version above 7.2 to support 3602.
    http://www.cisco.com/en/US/docs/wireless/controller/5500/tech_notes/Wireless_Software_Compatibility_Matrix.html
    Hope that  helps
    Regards
    Najaf
    Please rate when applicable or helpful !!!

  • Why LAP1131AG and LAP11412 cannot to join WLC 2504?

    I have WLC 2504, Cisco LAP1131AG and then Cisco LAP1142N. Why LAP1131AG and LAP11412 cannot to join WLC 2504?
    this is error code at the Cisco LAP1131AG
    *Sep 12 19:30:27.730: %CAPWAP-3-ERRORLOG: Go join a capwap controller 
    *Sep 12 19:30:27.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.100.10 peer_port: 5246
    *Sep 12 19:30:57.001: DTLS_CLIENT_ERROR: ../capwap/base_capwap/dtls/base_capwap_dtls_connection_db.c:2051 Max retransmission count reached!
    *Sep 12 19:31:27.000: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 192.168.100.10:5246
    *Sep 12 19:31:32.083: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to administratively down
    *Sep 12 19:31:32.083: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to administratively down
    *Sep 12 19:31:32.085: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to up
    *Sep 12 19:31:32.117: %CAPWAP-3-ERRORLOG: Not sending discovery request AP does not have an Ip !! 
    *Sep 12 19:31:32.118: %LINK-6-UPDOWN: Interface Dot11Radio1, changed state to up
    *Sep 12 19:31:33.083: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to down
    *Sep 12 19:31:33.112: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to down
    *Sep 12 19:31:33.117: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset
    *Sep 12 19:31:34.104: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to up
    *Sep 12 19:31:34.111: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to down
    *Sep 12 19:31:34.142: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to up
    *Sep 12 19:31:34.147: %LINK-6-UPDOWN: Interface Dot11Radio1, changed state to down
    *Sep 12 19:31:34.152: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to reset
    *Sep 12 19:31:35.141: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to up
    *Sep 12 19:31:35.146: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to down
    *Sep 12 19:31:35.170: %LINK-6-UPDOWN: Interface Dot11Radio1, changed state to up
    *Sep 12 19:31:36.171: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to up
    this is version LAP1131AG
    AP0018.18fc.fd58#sh version 
    Cisco IOS Software, C1130 Software (C1130-K9W8-M), Version 12.4(25e)JAO6, RELEASE SOFTWARE (fc1)
    Technical Support: http://www.cisco.com/techsupport
    Copyright (c) 1986-2014 by Cisco Systems, Inc.
    Compiled Fri 22-Aug-14 10:07 by prod_rel_team
    ROM: Bootstrap program is C1130 boot loader
    BOOTLDR: C1130 Boot Loader (C1130-BOOT-M) Version 12.3(7)JA1, RELEASE SOFTWARE (fc1)
    AP0018.18fc.fd58 uptime is 9 minutes
    System returned to ROM by power-on
    System image file is "flash:/c1130-k9w8-mx.124-25e.JAO6/c1130-k9w8-mx.124-25e.JAO6"
    and then this is version WLC2504
    (Cisco Controller) >show sysinfo 
    Manufacturer's Name.............................. Cisco Systems Inc.
    Product Name..................................... Cisco Controller
    Product Version.................................. 7.6.130.0
    Bootloader Version............................... 1.0.20
    Field Recovery Image Version..................... 7.6.101.1
    Firmware Version................................. PIC 16.0
    Build Type....................................... DATA + WPS
    System Name...................................... Cisco_47:19:c4
    System Location.................................. 
    System Contact................................... 
    System ObjectID.................................. 1.3.6.1.4.1.9.1.1279
    IP Address....................................... 192.168.100.10
    Last Reset....................................... Software reset
    System Up Time................................... 0 days 0 hrs 36 mins 45 secs
    System Timezone Location......................... 
    System Stats Realtime Interval................... 5
    System Stats Normal Interval..................... 180
    --More-- or (q)uit
    Configured Country............................... ID  - Indonesia
    Operating Environment............................ Commercial (0 to 40 C)
    Internal Temp Alarm Limits....................... 0 to 65 C
    Internal Temperature............................. +34 C
    External Temperature............................. +40 C
    Fan Status....................................... 4100 rpm
    State of 802.11b Network......................... Enabled
    State of 802.11a Network......................... Enabled
    Number of WLANs.................................. 1
    Number of Active Clients......................... 0
    Burned-in MAC Address............................ 24:E9:B3:47:19:C0
    Maximum number of APs supported.................. 5
    IP Address management WLC : 192.168.100.10/24
    IP Address LAP1142N :192.168.100.102/24
    IP Address LAP1131AG : 192.168.100.101/24
    Can anyone help my problem?

    A summary of U.S. laws governing Cisco cryptographic products may be found at:
    http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
    If you require further assistance please contact us by sending email to
    [email protected]
    cisco AIR-LAP1142N-A-K9 (PowerPC405ex) processor (revision A0) with 90102K/40960K bytes of memory.
    Processor board ID FGL1439S15W
    PowerPC405ex CPU at 586MHz, revision number 0x147E
    Last reset from reload
    LWAPP image version 7.6.130.0
    1 Gigabit Ethernet interface
    2 802.11 Radios
    32K bytes of flash-simulated non-volatile configuration memory.
    Base ethernet MAC Address: C8:4C:75:79:EB:E9
    Part Number                          : 73-12836-03
    PCA Assembly Number                  : 800-33767-03
    PCA Revision Number                  : A0
    PCB Serial Number                    : FOC14234D8Z
    Top Assembly Part Number             : 800-33775-02
    Top Assembly Serial Number           : FGL1439S15W
    Top Revision Number                  : A0
    Product/Model Number                 : AIR-LAP1142N-A-K9  
    cisco AIR-LAP1131AG-A-K9 (PowerPCElvis) processor (revision A0) with 27638K/5120K bytes of memory.
    Processor board ID FTX1026T46E
    PowerPCElvis CPU at 262Mhz, revision number 0x0950
    Last reset from power-on
    LWAPP image version 7.6.130.0
    1 FastEthernet interface
    2 802.11 Radio(s)
    32K bytes of flash-simulated non-volatile configuration memory.
    Base ethernet MAC Address: 00:18:18:FC:FD:58
    Part Number                          : 73-8962-09
    PCA Assembly Number                  : 800-24818-08
    PCA Revision Number                  : A0
    PCB Serial Number                    : FOC102513DE
    Top Assembly Part Number             : 800-25544-06
    Top Assembly Serial Number           : FTX1026T46E
    Top Revision Number                  : A0
    Product/Model Number                 : AIR-LAP1131AG-A-K9  
    Configuration register is 0xF

  • WLC 2504 sudden network instability

    Hello,
    we're running a WLC 2504 with two SSIDs on it. It is connected to to a small PoE switch. Standard untagged vlan. A handfull APs connected to it. No DHCP, the APs have all static IP addresses.
    All of a sudden we're having a number of issues with the network connection:
    APs restarting
    The APs restart every now and then reporting that their IP is being used by another device. Looking through the logs there are two MAC addresses that are reported as using the APs IP address. These two MAC addresses have unknown vendor IDs.
    Warning: AP with Base Radio MAC f8:72:ea:7c:9d:e3 has found  its IP Address 0.2.146.0 being used by a machine with MAC
    Address  04:c6:f8:40:00:00 (The other mac that is reported is 04:cc:90:40:00:00)
    AP 'AP5', MAC: 0c:68:03:dd:1b:80 disassociated previously due to Link Failure.  Uptime: 4 days, 00 h 48 m 50 s . Reason: Capwap WTP Event request.
    So: There are two MACs that use the IP addresses of 7 APs?!?! And there is no vendor to be found for these MACs?
    Ping timouts on the webGUI and CLI
    I have a ping running on the IP for managing the device. This is running fine for ages. As soon as I connect via webGUI or CLI I lose packets. Get timeouts etc. some packets get through some don't. More of the latter. So ping is fine but any other traffic seems to be impacted heavily.
    What we have done for troubleshooting
    Checked duplex/speed settings of the interfaces. Everything ok.
    Connected to another switchport. Same.
    Changed the IP address of the management port. Same.
    Swapped places with a laptop with the same IP address --> Worked fine.
    Plugged in a completely new device, installed the latest firmware (7.6) and uploaded the config from the other one. Same.
    Restarted the default gateway for the subnet the controler is on.
    So now we're at the end of our knowledge. It seems to be a non-physical network issue, but we're a small team and no one has changed anything they say :-/
    Any ideas what we could check next?
    Kat

    Hello,
    thanks for your suggestions. It's hard to find those two MAC addresses. As they seem to be virtual I cannot get a hint from the vendor ID. A show mac-address table on the switch the WLC is connected to doesn't show those two
    I found an error in the WLC AP config. AP1 had the same IP as AP5 and a wrong netmask. I changed that. Unfortunately that doesn't solve our problem.
    Here are some more messages from the WLC's log:
    AP 'AP3', MAC: 0c:68:03:dd:34:00 disassociated previously due to Link Failure.  Uptime: 4 days, 15 h 04 m 15 s . Reason: Capwap WTP Event request.
    AP Disassociated. Base Radio MAC:0c:68:03:dd:34:00
    AP's Interface:1(802.11a) Operation State Down: Base Radio MAC:0c:68:03:dd:34:00  Cause=Heartbeat Timeout Status:NA
    AP 'AP3', MAC: 0c:68:03:dd:34:00 disassociated previously due to Link Failure.  Uptime: 4 days, 15 h 00 m 45 s . Reason: Capwap WTP Event request.
    RF Manager updated TxPower for Base Radio MAC: 0c:68:03:dd:34:00 and slotNo: 0.  New Tx Power is: 2
    AP's Interface:0(802.11b) Operation State Down: Base Radio MAC:0c:68:03:dd:16:e0  Cause=Max Retransmission Status:NA
    IDS Signature attack detected. Signature Type: Standard, Name: Deauth flood,  Description: Deauthentication flood, Track: per-signature, Detecting AP Name:  AP7, Radio Type: 802.11b/g, Preced: 9, Hits: 500, Channel: 6, srcMac:  C2:9F:DB:21:47:60
    This is the sh run-config of our WLC including one AP:
    >show run-config
    System Inventory
    NAME: "Chassis"    , DESCR: "Cisco 2500 Series Wireless LAN Controller"
    PID: AIR-CT2504-K9,  VID: V01,  SN: PSZ17381EPZ
    Burned-in MAC Address............................ 50:17:FF:27:12:80
    Maximum number of APs supported.................. 15
    System Information
    Manufacturer's Name.............................. Cisco Systems Inc.
    Product Name..................................... Cisco Controller
    Product Version.................................. 7.4.110.0
    Bootloader Version............................... 1.0.18
    Field Recovery Image Version..................... 1.0.0
    Firmware Version................................. PIC 16.0
    Build Type....................................... DATA + WPS
    System Name...................................... UK-BRI-WFAPC
    System Location..................................
    System Contact...................................
    System ObjectID.................................. 1.3.6.1.4.1.9.1.1279
    IP Address....................................... 172.17.128.12
    Last Reset....................................... Power on reset
    System Up Time................................... 4 days 0 hrs 46 mins 6 secs
    System Timezone Location.........................
    System Stats Realtime Interval................... 5
    System Stats Normal Interval..................... 180
    Configured Country............................... GB  - United Kingdom
    Operating Environment............................ Commercial (0 to 40 C)
    Internal Temp Alarm Limits....................... 0 to 65 C
    Internal Temperature............................. +20 C
    External Temperature............................. +25 C
    Fan Status....................................... 4000 rpm
    State of 802.11b Network......................... Enabled
    State of 802.11a Network......................... Enabled
    Number of WLANs.................................. 3
    Number of Active Clients......................... 6
    Memory Current Usage............................. Unknown
    Memory Average Usage............................. Unknown
    CPU Current Usage................................ Unknown
    CPU Average Usage................................ Unknown
    Burned-in MAC Address............................ 50:17:FF:27:12:80
    Maximum number of APs supported.................. 15
    AP Bundle Information
    Primary AP Image    Size
    ap1g2            9568
    ap3g1            11288
    ap3g2            11196
    ap801            7164
    ap802            8568
    c1130            5072
    c1140            9416
    c1250            6944
    c1520            8044
    c602i            3736
    Secondary AP Image    Size
    ap3g1            5792
    ap801            5192
    ap802            5232
    c1100            3084
    c1130            4964
    c1140            4992
    c1200            3364
    c1240            4812
    c1250            5504
    c1310            3136
    c1520            6404
    c3201            4324
    c602i            3716
    Switch Configuration
    802.3x Flow Control Mode......................... Disable
    FIPS prerequisite features....................... Disabled
    secret obfuscation............................... Enabled
    Strong Password Check Features:
         case-check ...........Enabled
         consecutive-check ....Enabled
         default-check .......Enabled
         username-check ......Enabled
    Network Information
    RF-Network Name............................. RFGROUP
    Web Mode.................................... Disable
    Secure Web Mode............................. Enable
    Secure Web Mode Cipher-Option High.......... Disable
    Secure Web Mode Cipher-Option SSLv2......... Disable
    Secure Web Mode RC4 Cipher Preference....... Disable
    OCSP........................................ Disabled
    OCSP responder URL..........................
    Secure Shell (ssh).......................... Enable
    Telnet...................................... Disable
    Ethernet Multicast Forwarding............... Disable
    Ethernet Broadcast Forwarding............... Disable
    AP Multicast/Broadcast Mode................. Multicast   Address : 0.0.0.0
    IGMP snooping............................... Disabled
    IGMP timeout................................ 60 seconds
    IGMP Query Interval......................... 20 seconds
    MLD snooping................................ Disabled
    MLD timeout................................. 60 seconds
    MLD query interval.......................... 20 seconds
    User Idle Timeout........................... 300 seconds
    ARP Idle Timeout............................ 300 seconds
    Cisco AP Default Master..................... Disable
    AP Join Priority............................ Disable
    Mgmt Via Wireless Interface................. Disable
    Mgmt Via Dynamic Interface.................. Disable
    Bridge MAC filter Config.................... Enable
    Bridge Security Mode........................ EAP
    Mesh Full Sector DFS........................ Enable
    AP Fallback ................................ Enable
    Web Auth CMCC Support ...................... Disabled
    Web Auth Redirect Ports .................... 80
    Web Auth Proxy Redirect  ................... Disable
    Web Auth Captive-Bypass   .................. Disable
    Web Auth Secure Web  ....................... Enable
    Fast SSID Change ........................... Disabled
    AP Discovery - NAT IP Only ................. Enabled
    IP/MAC Addr Binding Check .................. Enabled
    CCX-lite status ............................ Disable
    oeap-600 dual-rlan-ports ................... Disable
    oeap-600 local-network ..................... Enable
    mDNS snooping............................... Disabled
    mDNS Query Interval......................... 15 minutes
    Port Summary
               STP   Admin   Physical   Physical   Link   Link
    Pr  Type   Stat   Mode     Mode      Status   Status  Trap     POE 
    1  Normal  Forw Enable  Auto       1000 Full  Up     Enable  N/A    
    2  Normal  Forw Enable  Auto       100 Full   Up     Enable  N/A    
    3  Normal  Forw Enable  Auto       1000 Full  Up     Enable  Enable  (Power Off)
    4  Normal  Disa Enable  Auto       Auto       Down   Enable  Enable  (Power Off)
    AP Summary
    Number of APs.................................... 7
    Global AP User Name.............................. Not Configured
    Global AP Dot1x User Name........................ Not Configured
    AP Name             Slots  AP Model              Ethernet MAC       Location          Port  Country  Priority
    AP7                  2     AIR-CAP1602I-E-K9     f8:72:ea:e4:9a:81  default location  1        GB       1
    AP1                  2     AIR-CAP1602I-E-K9     f8:72:ea:7c:9d:e3  default location  1        GB       1
    AP3                  2     AIR-CAP1602I-E-K9     f8:72:ea:e4:9c:57  default location  1        GB       1
    AP6                  2     AIR-CAP1602I-E-K9     f8:72:ea:e4:9a:90  default location  1        GB       1
    AP2                  2     AIR-CAP1602I-E-K9     f8:72:ea:7c:9b:63  default location  1        GB       1
    AP4                  2     AIR-CAP1602I-E-K9     f8:72:ea:e4:9a:9b  default location  1        GB       1
    AP5                  2     AIR-CAP1602I-E-K9     f8:72:ea:e4:9a:cb  default location  1        GB       1
    AP Tcp-Mss-Adjust Info
    AP Name              TCP State  MSS Size
    AP7                  disabled   -
    AP1                  disabled   -
    AP3                  disabled   -
    AP6                  disabled   -
    AP2                  disabled   -
    AP4                  disabled   -
    AP5                  disabled   -
    AP Location
    Total Number of AP Groups........................ 0   
    Site Name........................................ default-group
    Site Description.................................
    NAS-identifier................................... UK-BRI-WFAPC
    AP Operating Class............................... Not-configured
    RF Profile
    2.4 GHz band.....................................
    5 GHz band.......................................
    WLAN ID          Interface          Network Admission Control          Radio Policy
    1               corporate            Disabled                          None
    2               dirtynetwork         Disabled                          None
    3               dirtynetwork         Disabled                          None
    AP Name             Slots  AP Model             Ethernet MAC       Location          Port  Country  Priority
    AP7                  2     AIR-CAP1602I-E-K9    f8:72:ea:e4:9a:81  default location  1     GB       1
    AP1                  2     AIR-CAP1602I-E-K9    f8:72:ea:7c:9d:e3  default location  1     GB       1
    AP3                  2     AIR-CAP1602I-E-K9    f8:72:ea:e4:9c:57  default location  1     GB       1
    AP6                  2     AIR-CAP1602I-E-K9    f8:72:ea:e4:9a:90  default location  1     GB       1
    AP2                  2     AIR-CAP1602I-E-K9    f8:72:ea:7c:9b:63  default location  1     GB       1
    AP4                  2     AIR-CAP1602I-E-K9    f8:
    RF Profile
    Number of RF Profiles............................ 0
    Out Of Box State................................. Disabled
    RF Profile Name                    Band     Description                         11n-client-only
    AP Config
    Cisco AP Identifier.............................. 15
    Cisco AP Name.................................... AP7
    Country code..................................... GB  - United Kingdom
    Regulatory Domain allowed by Country............. 802.11bg:-E     802.11a:-E
    AP Country code..................
    ................ GB  - United Kingdom
    AP Regulatory Domain............................. -E
    Switch Port Number .............................. 1
    MAC Address...................................... f8:72:ea:e4:9a:81
    IP Address Configuration......................... Static IP assigned
    IP Address....................................... 172.17.128.24
    IP NetMask....................................... 255.255.128.0
    Gateway IP Addr.................................. 172.17.128.1
    Domain...............
    Name Server......................................
    NAT External IP Address.......................... None
    CAPWAP Path MTU.................................. 1485
    Telnet State..................................... Disabled
    Ssh State........................................ Disabled
    Cisco AP Location................................ default location
    Cisco AP Floor Label............................. 0
    Cisco AP Group Name.............................. default-group
    Primary Cisco Switch Name........................
    Primary Cisco Switch IP Address.................. Not Configured
    Secondary Cisco Switch Name......................
    Secondary Cisco Switch IP Address................ Not Configured
    Tertiary Cisco Switch Name.......................
    Tertiary Cisco Switch IP Address................. Not Configured
    Administrative State ............................ ADMIN_ENABLED
    Operation State ....
    ............................. REGISTERED
    Mirroring Mode .................................. Disabled
    AP Mode ......................................... Local
    Public Safety ................................... Disabled
    AP SubMode ...................................... Not Configured
    Remote AP Debug ................................. Disabled
    Logging trap severity level ..................... informational
    Logging syslog facility ..
    ....................... kern
    S/W  Version .................................... 7.4.110.0
    Boot  Version ................................... 15.2.2.0
    Mini IOS Version ................................ 7.4.1.37
    Stats Reporting Period .......................... 180
    Stats Collection Mode ........................... normal
    LED State........................................ 
    Enabled
    PoE Pre-Standard Switch.......................... Disabled
    PoE Power Injector MAC Addr...................... Disabled
    Power Type/Mode.................................. Power injector / Normal mode
    Number Of Slots.................................. 2
    AP Model......................................... AIR-CAP1602I-E-K9  
    AP Image...............................
    .......... C1600-K9W8-M
    IOS Version...................................... 15.2(2)JB2$
    Reset Button..................................... Enabled
    AP Serial Number................................. FGL1725W7F7
    AP Certificate Type.............................. Manufacture Installed
    AP User Mode..................................... AUTOMATIC
    AP User Name..................................... Not Configured
    AP Dot1x User Mode............................... Not Configured
    AP Dot1x User Name............................... Not Configured
    Cisco AP system loggi
    ng host..................... 255.255.255.255
    AP Up Time....................................... 3 days, 23 h 26 m 50 s
    AP LWAPP Up Time................................. 0 days, 00 h 14 m 12 s
    Join Date and Time............................... Tue Jan 28 18:11:43 2014
    Join Taken Time.................................. 0 days, 00 h 11 m 41 s
    Attributes for Slot  0
        Radio Type................................... RADIO_TYPE_80211n-2.4
        Administrative State ........................ ADMIN_ENABLED
        Operation State ............................. UP
        Radio Role .................................. ACCESS
        Radio Mode .................................. Local
        CellId ...................................... 0
        Station Configuration
          Configuration ............................. AU
    TOMATIC
          Number Of WLANs ........................... 3
          Medium Occupancy Limit .................... 100
          CFP Period ................................ 4
          CFP MaxDuration ........................... 60
          BSSID ..................................... 0c:68:03:dd:16:e0
          Operation Rate Set
            1000 Kilo Bits........................... MANDATORY
            2000 Kilo Bits........................... MANDATORY
            5500 Kilo Bits........................... MANDATORY
            11000 Kilo Bits.......................... MANDATORY
            6000 Kilo Bits........................... SUPPORTED
            9000 Kilo Bits........................... SUPPORTED
            12000 Kilo Bits.......................... SUPPORTED
            18000 Kilo Bits.......................... SUPPORTED
            24000 Kilo Bits.......................... SUPPORTED
    36000 Kilo Bits.......................... SUPPORTED
            48000 Kilo Bits.......................... SUPPORTED
            54000 Kilo Bits.......................... SUPPORTED
          MCS Set
            MCS 0.................................... SUPPORTED
            MCS 1.................................... SUPPORTED
            MCS 2.................................... SUPPORTED
            MCS 3.................................... SUPPORTED
            MCS 4.................................... SUPPORTED
            MCS 5.................................... SUPPORTED
            MCS 6.................................... SUPPORTED
            MCS 7.................................... SUPPORTED
            MCS 8.................................... SUPPORTED
            MCS 9.................................... SUPPORTED
            MCS 10................................... SUPPORTED
            MCS 11................................... SUPPORTED
            MCS 12..
    ................................. SUPPORTED
            MCS 13................................... SUPPORTED
            MCS 14................................... SUPPORTED
            MCS 15................................... SUPPORTED
            MCS 16................................... DISABLED
            MCS 17................................... DISABLED
            MCS 18................................... DISABLED
            MCS 19................................... DISABLED
            MCS 20................................... DISABLED
            MCS 21................................... DISABLED
            MCS 22................................... DISABLED
            MCS 23................................... DISABLED
          Beacon Period ............................. 100
          Fragmentation Threshold ................... 2346
          Multi Domain Capability Implemented ....... TRUE
          Multi Domain Capability Enabled ........... TRUE
          Country String ............................ GB
        Multi Domain Capability
          Configuration ............................. AUTOMATIC
          First Chan Num ............................ 1
          Number Of Channels ........................ 13
        MAC Operation Parameters
          Configuration ............................. AUTOMATIC
          Fragmentation Threshold ................... 2346
          Packet Retry Limit ........................ 64
        Tx Power
          Num Of Supported Power Levels ............. 4
          Tx Power Level 1 .......................... 16 dBm
          Tx Power Level 2 .......................... 13 dBm
          Tx Power Level 3 .......................... 10 dBm
          Tx Power Level 4 .......................... 7 dBm
          Tx Power Configuration .................... AUTOMATIC
          Current Tx Power Level .................... 3
          Tx Power Assigned By ...................... DTPC
        Phy OFDM parameters
          Configuration ............................. AUTOMATIC
          Current Channel ........................... 6
          Channel Assigned By ....................... DCA
          Extension Channel ......................... NONE
          Channel Width.............................. 20 Mhz
          Allowed Channel List....................... 1,2,3,4,5,6,7,8,9,10,11,12,
            ......................................... 13
          TI Threshold .............................. -50
          Legacy Tx Beamforming Configuration ....... CUSTOMIZED
          Legacy Tx Beamforming ..................... ENABLED
          Antenna Type............................... INTERNAL_ANTENNA
          Internal Antenna Gain (in .5 dBi units).... 8
          Diversity.................................. DIVERSITY_ENABLED
          802.11n Antennas
             A....................................... ENABLED
             B....................................... ENABLED
             C....................................... ENABLED
        Performance Profile Parameters
          Configuration ............................. AUTOMATIC
          Interference threshold..................... 10 %
          Noise threshold............................  -70 dBm
          RF utilization threshold................... 80 %
          Data-rate threshold........................ 1000000 bps
          Client threshold........................... 12 clients
          Coverage SNR threshold..................... 12 dB
          Coverage exception level................... 25 %
          Client minimum exception level............. 3 clients
        Rogue Containment Information
        Containment Count............................
        CleanAir Management Information
            CleanAir Capable......................... No
        Radio Extended Configurations
          Beacon period.............................. 100 milliseconds
          Beacon range............................... AUTO
          Multicast buffer........................... AUTO
          Multicast data-rate........................ AUTO
          RX SOP threshold........................... AUTO
          CCA threshold.............................. AUTO

  • Acs 5.3 and wlc 2504 config with restricted network access

    Hello,
    i submit you the following issue that i'm actually facing:
    i must configure a secured wireless network with access restriction based on SSID. the equipements are : cisco wlc 2504 (soft 7.3) cisco secure acs aplliance 1121 (soft 5.4) .
    the users that will connect to the network are regrouped by identity groups, each identity group having it's own SSID. Clearly each group of users must access only one SSID.
    i followed the procedure below to configure it:
    -- creating user identity groups;
    -- creating users and assigning them to the groups;
    --- creating authorization profiles for each SSID under policy element/ authorization and permission/network access/authorization profiles and putting the Airespace-Wlan-Id(the SSID number) in the radius tab.
    --- assigning the authorization profiles to the identity groups under access policies.
    after all these config the users can access the network using there userid/password configured. But the problem is Every user can access every SSID, seems like the restriction is so not very well configured.
    i found some documentation on this kind of config but the version of ACS used seems older than the one that i use, so menu are very different.
    Please can someone provide with the right steps to follow to achieve this kind of config.
    tkx in advance

    Yes.. you only have to add the end filter like what I posted... as far as the calling station id in the WLC security tab, it doesn't matter because that is not used when using 802.1x.  I would also try to not enable everything that you have just to start from the basic and make sure it works first.  The WAP Authentication Method might or might not work for you.  Uncheck that for now and when you have a successful authentication, look at the monitor log and see what radius attributes are being sent, because those attributes is what you can use to build your policies.
    Thanks,
    Scott
    Help out other by using the rating system and marking answered questions as "Answered"

  • WLAN Clients not browsing on Cisco Wireless Controller WLC NME-AIR-WLC12-K9

    HiI have a question and i need a solution and expert help.I have done a deployment which involves Security (ASA5540), Routing/voice gateway/wlc NME-AIR-WLC12-k9) and Switching (Cisco3845-ccme/k9)Below is the list of equipment used:1. Cisco ASA 5540 - which is connected at the edge to the ISP router
    2. Core Switch WS-C4948E as core and DHCP Server for all VLANs
    3. Access/Distribution Switches WS-C3560G-48PS-S connected as trunk to the core switch
    4. Router/Voice Gateway/WLC Cisco3845-CCME/K9 - This is the voice gateway and also the WLC
    5. Wireless APs AIR-LAP1242AG-E-K9 (12 qty)Here is the deployment scenario:1. G0/0 of the ASA is connected to a 7200 router from the ISP (Public IP Add)
    2. G0/1 of the ASA is connected to gig 1/3 on the Core Switch on VLAN 2 which is the management VLAN (Local IP 10.1.1.2)
    3. Port 3 of the Core switch is on vlan 2 connected to ASA - Management IP of Core Switch is 10.1.1.1. Core Switch is the DHCP Server for all VLANS on the network.
    4. All the Access/Distribution switches are configured with IP Addresses on VLAN 2
    5. Telephony Services is configured on the router and DHCP Pool for Access Points and Wireless Clients is running on the router.
    6. Two DHCP pools were created on the router for APs and Wireless Clients.
    7. G0/0 of the router is configured on the same network that issues dhcp ip to the AP and is connected to gig 1/1 on the core switch
    8 G0/1 of the router is configured as the voice port for the IP Telephony Services and is connected to G 1/2 on the core switch1. Clients receiving DHCP IP on the Core Switch can communicate with all vlans and can browse to the Internet.
    2. IP Telephony Services is running well.
    3. Client on wireless can get IP from the DHCP on the router but cannot browse.I have pings from the router to the core switch and firewall, but clients connected to the wireless
    cannot ping other vlans on the core switch and vice versa.The port connecting the router to the core switch is an Access Port, i have changed to to trunk but still no changes.My biggest problem now is how to make the clients on the wireless communicate with other clients on the network and be able to browse to the Internet.Below is the configs on the router and core switch.Router ConfigNimc_Voice_Router#sh run
    Building configuration...
    Current configuration : 10513 bytes
    ! Last configuration change at 13:03:55 Nigeria Mon Nov 29 2010 by admin
    ! NVRAM config last updated at 13:03:56 Nigeria Mon Nov 29 2010 by admin
    version 12.4
    service timestamps debug datetime msec
    service timestamps log datetime msec
    no service password-encryption
    hostname Nimc_Voice_Router
    boot-start-marker
    boot-end-marker
    ! card type command needed for slot/vwic-slot 0/2
    logging message-counter syslog
    enable secret
    aaa new-model
    ! aaa authentication login default local
    aaa session-id common
    clock timezone Nigeria 1
    dot11 syslog
    ip source-route
    ip dhcp excluded-address 10.1.12.1 10.1.12.10
    ip dhcp excluded-address 192.168.1.1 192.168.1.10
    ip dhcp pool LWAAP-AP
    network 10.1.12.0 255.255.255.0
    default-router 10.1.12.1
    option 43 hex f104.c0a8.0002
    dns-server 83.229.88.30 4.2.2.2 193.238.28.249
    option 60 ascii "Cisco AP c1240"
    ip dhcp pool Wireless
    network 192.168.1.0 255.255.255.0
    default-router 192.168.1.1
    dns-server 83.229.88.30 193.238.28.249 4.2.2.2
    ip cef
    no ip domain lookup
    ip domain name nimc.gov.ng
    ip name-server 83.229.88.30
    ip name-server 193.238.28.249
    ip name-server 4.2.2.2
    no ipv6 cef
    multilink bundle-name authenticated
    voice-card 0
    archive
    log config
    hidekeys
    interface GigabitEthernet0/0
    description Connection to AP
    ip address 10.1.12.1 255.255.255.0
    ip helper-address 192.168.0.2
    load-interval 30
    duplex auto
    speed auto
    media-type rj45
    interface Service-Engine0/0
    no ip address
    shutdown
    interface GigabitEthernet0/1
    ip address 10.1.2.2 255.255.255.0
    duplex auto
    speed auto
    media-type rj45
    interface FastEthernet0/0/0
    no ip address
    shutdown
    duplex auto
    speed auto
    interface Serial0/1/0
    no ip address
    shutdown
    no fair-queue
    clock rate 2000000
    interface Serial0/1/1
    no ip address
    shutdown
    clock rate 2000000
    interface Integrated-Service-Engine1/0
    ip address 192.168.0.1 255.255.255.0
    no keepalive
    interface Integrated-Service-Engine1/0.15
    encapsulation dot1Q 15
    ip address 192.168.1.1 255.255.255.0
    interface Integrated-Service-Engine1/0.100
    encapsulation dot1Q 100
    ip forward-protocol nd
    ip forward-protocol udp 12223
    ip route 10.1.0.0 255.255.255.0 10.1.1.1
    ip route 10.1.1.0 255.255.255.0 10.1.1.1
    ip route 10.1.2.0 255.255.255.0 10.1.1.1
    ip route 10.1.3.0 255.255.255.0 10.1.1.1
    ip route 10.1.4.0 255.255.255.0 10.1.1.1
    ip route 10.1.5.0 255.255.255.0 10.1.1.1
    ip route 10.1.6.0 255.255.255.0 10.1.1.1
    ip route 10.1.7.0 255.255.255.0 10.1.1.1
    ip route 10.1.8.0 255.255.255.0 10.1.1.1
    ip route 10.1.9.0 255.255.255.0 10.1.1.1
    ip route 10.1.10.0 255.255.255.0 10.1.1.1
    ip route 10.1.11.0 255.255.255.0 10.1.1.1
    ip route 10.1.12.0 255.255.255.0 10.1.1.1
    ip route 192.168.0.0 255.255.255.0 10.1.1.1
    ip route 192.168.1.0 255.255.255.0 10.1.1.1
    no ip http server
    ip http secure-server
    !Core Switch Configsh run
    Building configuration...Current configuration : 10622 bytes
    version 12.2
    no service pad
    service timestamps debug datetime msec
    service timestamps log datetime msec
    no service password-encryption
    service compress-config
    hostname Nimc_Core
    boot-start-marker
    boot-end-marker!
    aaa new-model
    aaa authentication login default local
    aaa session-id common
    storm-control broadcast include multicast
    ip subnet-zero
    no ip domain-lookup
    ip domain-name nimc.gov.ng
    ip dhcp excluded-address 10.1.2.1 10.1.2.10
    ip dhcp excluded-address 10.1.4.1 10.1.4.10
    ip dhcp excluded-address 10.1.5.1 10.1.5.10
    ip dhcp excluded-address 10.1.6.1 10.1.6.10
    ip dhcp excluded-address 10.1.7.1 10.1.7.10
    ip dhcp excluded-address 10.1.8.1 10.1.8.10
    ip dhcp excluded-address 10.1.9.1 10.1.9.10
    ip dhcp excluded-address 10.1.10.1 10.1.10.10
    ip dhcp excluded-address 10.1.3.1 10.1.3.10
    ip dhcp pool Voice
    network 10.1.2.0 255.255.255.0
    next-server 10.1.2.1
    option 150 ip 10.1.2.2
    default-router 10.1.2.1
    dns-server 83.229.88.30 193.238.28.249 4.2.2.2
    ip dhcp pool SF_DGs_Office
    network 10.1.3.0 255.255.255.0
    domain-name nimc.gov.ng
    default-router 10.1.3.1
    dns-server 81.199.3.7
    lease 10
    ip dhcp pool Admin_Process_Fac_Mgt
    network 10.1.4.0 255.255.255.0
    domain-name nimc.gov.ng
    default-router 10.1.4.1
    dns-server 83.229.88.30 193.238.28.249 4.2.2.2
    lease 10
    ip dhcp pool SF_IDD
    network 10.1.5.0 255.255.255.0
    domain-name nimc.gov.ng
    default-router 10.1.5.1
    dns-server 83.229.88.30 193.238.28.249 4.2.2.2
    lease 10
    ip dhcp pool Finance_Fin_Inv
    network 10.1.6.0 255.255.255.0
    domain-name nimc.gov.ng
    default-router 10.1.6.1
    dns-server 83.229.88.30 193.238.28.249 4.2.2.2
    lease 10
    ip dhcp pool Finance_CS
    network 10.1.7.0 255.255.255.0
    domain-name nimc.gov.ng
    default-router 10.1.7.1
    dns-server 83.229.88.30 193.238.28.249 4.2.2.2
    lease 10
    ip dhcp pool FF_Human_Capital_Mgt
    network 10.1.8.0 255.255.255.0
    domain-name nimc.gov.ng
    default-router 10.1.8.1
    dns-server 83.229.88.30 193.238.28.249 4.2.2.2
    lease 10
    ip dhcp pool FF_Legal_Services
    network 10.1.9.0 255.255.255.0
    domain-name nimc.gov.ng
    default-router 10.1.9.1
    dns-server 83.229.88.30 193.238.28.249 4.2.2.2
    lease 10
    ip dhcp pool SF_Procurement_Serv
    network 10.1.10.0 255.255.255.0
    domain-name nimc.gov.ng
    default-router 10.1.10.1
    dns-server 83.229.88.30 193.238.28.249 4.2.2.2
    lease 10
    ip vrf mgmtVrf
    errdisable recovery cause bpduguard
    errdisable recovery interval 180
    power redundancy-mode redundant
    spanning-tree mode mst
    spanning-tree portfast bpduguard default
    spanning-tree extend system-id
    spanning-tree mst configuration
    name xxxx
    revision 1
    instance 1 vlan 1-20
    spanning-tree mst 1 priority 0
    spanning-tree vlan 1-20 priority 0
    vlan internal allocation policy ascending
    interface FastEthernet1
    ip vrf forwarding mgmtVrf
    no ip address
    speed auto
    duplex auto
    interface GigabitEthernet1/1
    switchport trunk encapsulation dot1q
    switchport mode trunk
    interface GigabitEthernet1/2
    switchport access vlan 4
    switchport mode access
    spanning-tree portfast
    interface GigabitEthernet1/3
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/4
    switchport mode access
    spanning-tree portfast
    interface GigabitEthernet1/5
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/6
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/7
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/8
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast!
    interface GigabitEthernet1/9
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/10
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/11
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/12
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/13
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/14
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/15
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/16
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/17
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/18
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/19
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/20
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/21
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/22
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/23
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/24
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/25
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/26
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/27
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/28
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/29
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/30
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/31
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfastinterface GigabitEthernet1/32
    switchport access vlan 2
    switchport voice vlan 4
    interface GigabitEthernet1/33
    switchport mode access
    interface GigabitEthernet1/34
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/35
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/36
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/37
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/38
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/39
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/40
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/41
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/42
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/43
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/44
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/45
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/46
    switchport access vlan 2
    switchport mode access
    switchport voice vlan 4
    spanning-tree portfast
    interface GigabitEthernet1/47
    switchport trunk encapsulation dot1q
    switchport mode trunk
    interface GigabitEthernet1/48
    switchport trunk encapsulation dot1q
    switchport mode trunk
    interface Vlan1
    no ip address
    shutdown
    interface Vlan2
    description Management
    ip address 10.1.1.1 255.255.255.0
    interface Vlan3
    description Enterprise
    ip address 10.1.0.1 255.255.255.0
    interface Vlan4
    description Voice
    ip address 10.1.2.1 255.255.255.0
    interface Vlan5
    description SS_DGs_Office
    ip address 10.1.3.1 255.255.255.0
    interface Vlan6
    description Admin_Process_Fac_Management
    ip address 10.1.4.1 255.255.255.0
    interface Vlan7
    description SF_National_Identity_Database
    ip address 10.1.5.1 255.255.255.0
    interface Vlan8
    description Fin_Finance_Investment
    ip address 10.1.6.1 255.255.255.0
    interface Vlan9
    description Fin_Corporate_Services
    ip address 10.1.7.1 255.255.255.0
    interface Vlan10
    description FF_Human_Capital_Management
    ip address 10.1.8.1 255.255.255.0
    interface Vlan11
    description FF_Legal_services
    ip address 10.1.9.1 255.255.255.0
    interface Vlan12
    description SF_Procurement_Services
    ip address 10.1.10.1 255.255.255.0
    ip default-gateway 10.1.1.2
    ip route 0.0.0.0 0.0.0.0 10.1.1.2
    ip route 10.1.1.0 255.255.255.0 10.1.1.2
    ip route 10.1.2.0 255.255.255.0 10.1.1.2
    ip route 10.1.3.0 255.255.255.0 10.1.1.2
    ip route 10.1.4.0 255.255.255.0 10.1.1.2
    ip route 10.1.5.0 255.255.255.0 10.1.1.2
    ip route 10.1.6.0 255.255.255.0 10.1.1.2
    ip route 10.1.7.0 255.255.255.0 10.1.1.2
    ip route 10.1.8.0 255.255.255.0 10.1.1.2
    ip route 10.1.9.0 255.255.255.0 10.1.1.2
    ip route 10.1.10.0 255.255.255.0 10.1.1.2
    ip route 10.1.11.0 255.255.255.0 10.1.1.2
    ip http server
    --More--                 
    control-plane
    line con 0
    stopbits 1
    line vty 0 4
    end
    Please i need somebody to help me

    I wouldn't configure an ip address on the service engine subinterface.
    Try setting up a vlan interface on the router with that ip address and the subinterface will be linked to the vlan interface through the encapsulation command. A vlan interface will better work as a gateway for the wireless clients
    Nicolas

  • Client got not connection to wlan over wlc 2504 on 802.11b/g

    Hi everybody,
    We are using a wlc 2504 with 7.6.100.0 and AP 1532e.
    I have the strange observacion that only clients with 802.11n (2.4GHz) can connect to the WLAN. Clients thats works only with 802.11b/g, they can't connect to the WLAN. Affected are all machines which want to connect with 802.11b/g.
    This is a MESH WLAN with 5GHz backhaul and 2.4GHz for the user.
    During the debugging found the following:
    *apfMsConnTask_4: May 09 11:44:40.581: 00:1b:77:b4:34:e0 Sending Assoc Response to station on BSSID 18:9c:5d:71:34:50 (status 0) ApVapId 1 Slot 0
    *apfMsConnTask_4: May 09 11:44:40.581: 00:1b:77:b4:34:e0 apfProcessAssocReq (apf_80211.c:8292) Changing state for mobile 00:1b:77:b4:34:e0 on AP 18:9c:5d:71:34:50 from Associated to Associated
    *spamApTask6: May 09 11:44:40.584: 00:1b:77:b4:34:e0 Sent 1x initiate message to multi thread task for mobile 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: 00:1b:77:b4:34:e0 Creating a PKC PMKID Cache entry for station 00:1b:77:b4:34:e0 (RSN 2)
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: 00:1b:77:b4:34:e0 Resetting MSCB PMK Cache Entry 0 for station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: 00:1b:77:b4:34:e0 Setting active key cache index 8 ---> 8
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: 00:1b:77:b4:34:e0 Setting active key cache index 8 ---> 0
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: 00:1b:77:b4:34:e0 Adding BSSID 18:9c:5d:71:34:50 to PMKID cache at index 0 for station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: New PMKID: (16)
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584:      [0000] f6 3d 52 9f 2a de 52 90 1d a2 46 49 0f 14 f6 69
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: 00:1b:77:b4:34:e0 Initiating RSN PSK to mobile 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: 00:1b:77:b4:34:e0 EAP-PARAM Debug - eap-params for Wlan-Id :1 is disabled - applying Global eap timers and retries
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: 00:1b:77:b4:34:e0 dot1x - moving mobile 00:1b:77:b4:34:e0 into Force Auth state
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: 00:1b:77:b4:34:e0 EAPOL Header:
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: 00000000: 02 03 00 5f                                       ..._
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: 00:1b:77:b4:34:e0 Found an cache entry for BSSID 18:9c:5d:71:34:50 in PMKID cache at index 0 of station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: 00:1b:77:b4:34:e0 Found an cache entry for BSSID 18:9c:5d:71:34:50 in PMKID cache at index 0 of station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: Including PMKID in M1  (16)
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584:      [0000] f6 3d 52 9f 2a de 52 90 1d a2 46 49 0f 14 f6 69
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: 00:1b:77:b4:34:e0 Starting key exchange to mobile 00:1b:77:b4:34:e0, data packets will be dropped
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: 00:1b:77:b4:34:e0 Sending EAPOL-Key Message to mobile 00:1b:77:b4:34:e0
       state INITPMK (message 1), replay counter 00.00.00.00.00.00.00.00
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: 00:1b:77:b4:34:e0 Sending EAPOL-Key Message to mobile 00:1b:77:b4:34:e0
       state INITPMK (message 1), replay counter 00.00.00.00.00.00.00.00
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.584: 00:1b:77:b4:34:e0 Allocating EAP Pkt for retransmission to mobile 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.585: 00:1b:77:b4:34:e0 mscb->apfMsLwappLradNhMac = 78:da:6e:59:c9:8c mscb->apfMsLradSlotId = 0 mscb->apfMsLradJumbo = 0 mscb->apfMsintIfNum = 1
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.585: 00:1b:77:b4:34:e0  mscb->apfMsBssid = 18:9c:5d:71:34:50 mscb->apfMsAddress = 00:1b:77:b4:34:e0 mscb->apfMsApVapId = 1
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.585: 00:1b:77:b4:34:e0  dot1xcb->snapOrg = 00 00 00 dot1xcb->eapolWepBit = 0 mscb->apfMsLwappLradVlanId = 0 mscb->apfMsLwappMwarInet.ipv4.addr = -1062679171
    *Dot1x_NW_MsgTask_0: May 09 11:44:40.585: 00:1b:77:b4:34:e0  mscb->apfMsLwappMwarPort = 5246 mscb->apfMsLwappLradInet.ipv4.addr = -1062679163 mscb->apfMsLwappLradPort = 40089
    *osapiBsnTimer: May 09 11:44:42.649: 00:1b:77:b4:34:e0 802.1x 'timeoutEvt' Timer expired for station 00:1b:77:b4:34:e0 and for message = M2
    *dot1xMsgTask: May 09 11:44:42.649: 00:1b:77:b4:34:e0 Retransmit 1 of EAPOL-Key M1 (length 121) for mobile 00:1b:77:b4:34:e0
    *dot1xMsgTask: May 09 11:44:42.649: 00:1b:77:b4:34:e0 mscb->apfMsLwappLradNhMac = 78:da:6e:59:c9:8c mscb->apfMsLradSlotId = 0 mscb->apfMsLradJumbo = 0 mscb->apfMsintIfNum = 1
    *dot1xMsgTask: May 09 11:44:42.649: 00:1b:77:b4:34:e0  mscb->apfMsBssid = 18:9c:5d:71:34:50 mscb->apfMsAddress = 00:1b:77:b4:34:e0 mscb->apfMsApVapId = 1
    *dot1xMsgTask: May 09 11:44:42.649: 00:1b:77:b4:34:e0  dot1xcb->snapOrg = 00 00 00 dot1xcb->eapolWepBit = 0 mscb->apfMsLwappLradVlanId = 0 mscb->apfMsLwappMwarInet.ipv4.addr = -1062679171
    *dot1xMsgTask: May 09 11:44:42.649: 00:1b:77:b4:34:e0  mscb->apfMsLwappMwarPort = 5246 mscb->apfMsLwappLradInet.ipv4.addr = -1062679163 mscb->apfMsLwappLradPort = 40089
    *osapiBsnTimer: May 09 11:44:44.649: 00:1b:77:b4:34:e0 802.1x 'timeoutEvt' Timer expired for station 00:1b:77:b4:34:e0 and for message = M2
    *dot1xMsgTask: May 09 11:44:44.649: 00:1b:77:b4:34:e0 Retransmit 2 of EAPOL-Key M1 (length 121) for mobile 00:1b:77:b4:34:e0
    *dot1xMsgTask: May 09 11:44:44.649: 00:1b:77:b4:34:e0 mscb->apfMsLwappLradNhMac = 78:da:6e:59:c9:8c mscb->apfMsLradSlotId = 0 mscb->apfMsLradJumbo = 0 mscb->apfMsintIfNum = 1
    *dot1xMsgTask: May 09 11:44:44.649: 00:1b:77:b4:34:e0  mscb->apfMsBssid = 18:9c:5d:71:34:50 mscb->apfMsAddress = 00:1b:77:b4:34:e0 mscb->apfMsApVapId = 1
    *dot1xMsgTask: May 09 11:44:44.649: 00:1b:77:b4:34:e0  dot1xcb->snapOrg = 00 00 00 dot1xcb->eapolWepBit = 0 mscb->apfMsLwappLradVlanId = 0 mscb->apfMsLwappMwarInet.ipv4.addr = -1062679171
    *dot1xMsgTask: May 09 11:44:44.650: 00:1b:77:b4:34:e0  mscb->apfMsLwappMwarPort = 5246 mscb->apfMsLwappLradInet.ipv4.addr = -1062679163 mscb->apfMsLwappLradPort = 40089
    *osapiBsnTimer: May 09 11:44:46.649: 00:1b:77:b4:34:e0 802.1x 'timeoutEvt' Timer expired for station 00:1b:77:b4:34:e0 and for message = M2
    *dot1xMsgTask: May 09 11:44:46.649: 00:1b:77:b4:34:e0 Retransmit failure for EAPOL-Key M1 to mobile 00:1b:77:b4:34:e0, retransmit count 3, mscb deauth count 1
    *dot1xMsgTask: May 09 11:44:46.649: 00:1b:77:b4:34:e0 Resetting MSCB PMK Cache Entry 0 for station 00:1b:77:b4:34:e0
    *dot1xMsgTask: May 09 11:44:46.649: 00:1b:77:b4:34:e0 Removing BSSID 18:9c:5d:71:34:50 from PMKID cache of station 00:1b:77:b4:34:e0
    *dot1xMsgTask: May 09 11:44:46.649: 00:1b:77:b4:34:e0 Setting active key cache index 0 ---> 8
    *dot1xMsgTask: May 09 11:44:46.649: 00:1b:77:b4:34:e0 Sent Deauthenticate to mobile on BSSID 18:9c:5d:71:34:50 slot 0(caller 1x_ptsm.c:598)
    *dot1xMsgTask: May 09 11:44:46.649: 00:1b:77:b4:34:e0 Setting active key cache index 8 ---> 8
    *dot1xMsgTask: May 09 11:44:46.649: 00:1b:77:b4:34:e0 Deleting the PMK cache when de-authenticating the client.
    *dot1xMsgTask: May 09 11:44:46.649: 00:1b:77:b4:34:e0 Global PMK Cache deletion failed.
    *dot1xMsgTask: May 09 11:44:46.649: 00:1b:77:b4:34:e0 Scheduling deletion of Mobile Station:  (callerId: 57) in 10 seconds
    *dot1xMsgTask: May 09 11:44:46.649: 00:1b:77:b4:34:e0 Freeing EAP Retransmit Bufer for mobile 00:1b:77:b4:34:e0
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 Reassociation received from mobile on BSSID 18:9c:5d:71:34:50
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 Global 200 Clients are allowed to AP radio
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 Max Client Trap Threshold: 0  cur: 1
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 Rf profile 600 Clients are allowed to AP wlan
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 Applying Interface policy on Mobile, role Unassociated. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 1
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 Re-applying interface policy for client
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 0.0.0.0 START (0) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2202)
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 0.0.0.0 START (0) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2223)
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 apfApplyWlanPolicy: Apply WLAN Policy over PMIPv6 Client Mobility Type
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 In processSsidIE:4795 setting Central switched to TRUE
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 In processSsidIE:4798 apVapId = 1 and Split Acl Id = 65535
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 Applying site-specific Local Bridging override for station 00:1b:77:b4:34:e0 - vapId 1, site 'default-group', interface 'catodos'
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 Applying Local Bridging Interface Policy for station 00:1b:77:b4:34:e0 - vlan 1, interface id 12, interface 'catodos'
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 processSsidIE  statusCode is 0 and status is 0
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 processSsidIE  ssid_done_flag is 0 finish_flag is 0
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 STA - rates (8): 2 4 11 22 12 18 24 36 48 72 96 108 0 0 0 0
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 suppRates  statusCode is 0 and gotSuppRatesElement is 1
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 STA - rates (12): 2 4 11 22 12 18 24 36 48 72 96 108 0 0 0 0
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 extSuppRates  statusCode is 0 and gotExtSuppRatesElement is 1
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 Processing RSN IE type 48, length 20 for mobile 00:1b:77:b4:34:e0
    *apfMsConnTask_4: May 09 11:44:52.083: 00:1b:77:b4:34:e0 0.0.0.0 START (0) Initializing policy
    *apfMsConnTask_4: May 09 11:44:52.084: 00:1b:77:b4:34:e0 0.0.0.0 START (0) Change state to AUTHCHECK (2) last state START (0)
    *apfMsConnTask_4: May 09 11:44:52.084: 00:1b:77:b4:34:e0 0.0.0.0 AUTHCHECK (2) Change state to 8021X_REQD (3) last state AUTHCHECK (2)
    *apfMsConnTask_4: May 09 11:44:52.084: 00:1b:77:b4:34:e0 Central switch is TRUE
    *apfMsConnTask_4: May 09 11:44:52.084: 00:1b:77:b4:34:e0 Not Using WMM Compliance code qosCap 00
    *apfMsConnTask_4: May 09 11:44:52.084: 00:1b:77:b4:34:e0 0.0.0.0 8021X_REQD (3) Plumbed mobile LWAPP rule on AP 18:9c:5d:71:34:50 vapId 1 apVapId 1 flex-acl-name:
    *apfMsConnTask_4: May 09 11:44:52.084: 00:1b:77:b4:34:e0 apfPemAddUser2 (apf_policy.c:333) Changing state for mobile 00:1b:77:b4:34:e0 on AP 18:9c:5d:71:34:50 from Associated to Associated
    *apfMsConnTask_4: May 09 11:44:52.084: 00:1b:77:b4:34:e0 apfPemAddUser2:session timeout forstation 00:1b:77:b4:34:e0 - Session Tout 1800, apfMsTimeOut '1800' and sessionTimerRunning flag is  0
    *apfMsConnTask_4: May 09 11:44:52.084: 00:1b:77:b4:34:e0 Scheduling deletion of Mobile Station:  (callerId: 49) in 1800 seconds
    *apfMsConnTask_4: May 09 11:44:52.084: 00:1b:77:b4:34:e0 Func: apfPemAddUser2, Ms Timeout = 1800, Session Timeout = 1800
    *apfMsConnTask_4: May 09 11:44:52.084: 00:1b:77:b4:34:e0 Sending Assoc Response to station on BSSID 18:9c:5d:71:34:50 (status 0) ApVapId 1 Slot 0
    *apfMsConnTask_4: May 09 11:44:52.084: 00:1b:77:b4:34:e0 apfProcessAssocReq (apf_80211.c:8292) Changing state for mobile 00:1b:77:b4:34:e0 on AP 18:9c:5d:71:34:50 from Associated to Associated
    *spamApTask6: May 09 11:44:52.087: 00:1b:77:b4:34:e0 Sent 1x initiate message to multi thread task for mobile 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0 Creating a PKC PMKID Cache entry for station 00:1b:77:b4:34:e0 (RSN 2)
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0 Resetting MSCB PMK Cache Entry 0 for station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0 Setting active key cache index 8 ---> 8
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0 Setting active key cache index 8 ---> 0
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0 Adding BSSID 18:9c:5d:71:34:50 to PMKID cache at index 0 for station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: New PMKID: (16)
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087:      [0000] f6 3d 52 9f 2a de 52 90 1d a2 46 49 0f 14 f6 69
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0 Initiating RSN PSK to mobile 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0 EAP-PARAM Debug - eap-params for Wlan-Id :1 is disabled - applying Global eap timers and retries
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0 dot1x - moving mobile 00:1b:77:b4:34:e0 into Force Auth state
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0 EAPOL Header:
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00000000: 02 03 00 5f                                       ..._
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0 Found an cache entry for BSSID 18:9c:5d:71:34:50 in PMKID cache at index 0 of station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0 Found an cache entry for BSSID 18:9c:5d:71:34:50 in PMKID cache at index 0 of station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: Including PMKID in M1  (16)
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087:      [0000] f6 3d 52 9f 2a de 52 90 1d a2 46 49 0f 14 f6 69
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0 Starting key exchange to mobile 00:1b:77:b4:34:e0, data packets will be dropped
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0 Sending EAPOL-Key Message to mobile 00:1b:77:b4:34:e0
       state INITPMK (message 1), replay counter 00.00.00.00.00.00.00.00
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0 Sending EAPOL-Key Message to mobile 00:1b:77:b4:34:e0
       state INITPMK (message 1), replay counter 00.00.00.00.00.00.00.00
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0 Allocating EAP Pkt for retransmission to mobile 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0 mscb->apfMsLwappLradNhMac = 78:da:6e:59:c9:8c mscb->apfMsLradSlotId = 0 mscb->apfMsLradJumbo = 0 mscb->apfMsintIfNum = 1
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0  mscb->apfMsBssid = 18:9c:5d:71:34:50 mscb->apfMsAddress = 00:1b:77:b4:34:e0 mscb->apfMsApVapId = 1
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0  dot1xcb->snapOrg = 00 00 00 dot1xcb->eapolWepBit = 0 mscb->apfMsLwappLradVlanId = 0 mscb->apfMsLwappMwarInet.ipv4.addr = -1062679171
    *Dot1x_NW_MsgTask_0: May 09 11:44:52.087: 00:1b:77:b4:34:e0  mscb->apfMsLwappMwarPort = 5246 mscb->apfMsLwappLradInet.ipv4.addr = -1062679163 mscb->apfMsLwappLradPort = 40089
    *osapiBsnTimer: May 09 11:44:54.249: 00:1b:77:b4:34:e0 802.1x 'timeoutEvt' Timer expired for station 00:1b:77:b4:34:e0 and for message = M2
    *dot1xMsgTask: May 09 11:44:54.249: 00:1b:77:b4:34:e0 Retransmit 1 of EAPOL-Key M1 (length 121) for mobile 00:1b:77:b4:34:e0
    *dot1xMsgTask: May 09 11:44:54.249: 00:1b:77:b4:34:e0 mscb->apfMsLwappLradNhMac = 78:da:6e:59:c9:8c mscb->apfMsLradSlotId = 0 mscb->apfMsLradJumbo = 0 mscb->apfMsintIfNum = 1
    *dot1xMsgTask: May 09 11:44:54.249: 00:1b:77:b4:34:e0  mscb->apfMsBssid = 18:9c:5d:71:34:50 mscb->apfMsAddress = 00:1b:77:b4:34:e0 mscb->apfMsApVapId = 1
    *dot1xMsgTask: May 09 11:44:54.249: 00:1b:77:b4:34:e0  dot1xcb->snapOrg = 00 00 00 dot1xcb->eapolWepBit = 0 mscb->apfMsLwappLradVlanId = 0 mscb->apfMsLwappMwarInet.ipv4.addr = -1062679171
    *dot1xMsgTask: May 09 11:44:54.249: 00:1b:77:b4:34:e0  mscb->apfMsLwappMwarPort = 5246 mscb->apfMsLwappLradInet.ipv4.addr = -1062679163 mscb->apfMsLwappLradPort = 40089
    *osapiBsnTimer: May 09 11:44:56.249: 00:1b:77:b4:34:e0 802.1x 'timeoutEvt' Timer expired for station 00:1b:77:b4:34:e0 and for message = M2
    *dot1xMsgTask: May 09 11:44:56.249: 00:1b:77:b4:34:e0 Retransmit 2 of EAPOL-Key M1 (length 121) for mobile 00:1b:77:b4:34:e0
    *dot1xMsgTask: May 09 11:44:56.249: 00:1b:77:b4:34:e0 mscb->apfMsLwappLradNhMac = 78:da:6e:59:c9:8c mscb->apfMsLradSlotId = 0 mscb->apfMsLradJumbo = 0 mscb->apfMsintIfNum = 1
    *dot1xMsgTask: May 09 11:44:56.249: 00:1b:77:b4:34:e0  mscb->apfMsBssid = 18:9c:5d:71:34:50 mscb->apfMsAddress = 00:1b:77:b4:34:e0 mscb->apfMsApVapId = 1
    *dot1xMsgTask: May 09 11:44:56.249: 00:1b:77:b4:34:e0  dot1xcb->snapOrg = 00 00 00 dot1xcb->eapolWepBit = 0 mscb->apfMsLwappLradVlanId = 0 mscb->apfMsLwappMwarInet.ipv4.addr = -1062679171
    *dot1xMsgTask: May 09 11:44:56.249: 00:1b:77:b4:34:e0  mscb->apfMsLwappMwarPort = 5246 mscb->apfMsLwappLradInet.ipv4.addr = -1062679163 mscb->apfMsLwappLradPort = 40089
    *osapiBsnTimer: May 09 11:44:58.249: 00:1b:77:b4:34:e0 802.1x 'timeoutEvt' Timer expired for station 00:1b:77:b4:34:e0 and for message = M2
    *dot1xMsgTask: May 09 11:44:58.249: 00:1b:77:b4:34:e0 Retransmit failure for EAPOL-Key M1 to mobile 00:1b:77:b4:34:e0, retransmit count 3, mscb deauth count 2
    *dot1xMsgTask: May 09 11:44:58.249: 00:1b:77:b4:34:e0 Resetting MSCB PMK Cache Entry 0 for station 00:1b:77:b4:34:e0
    *dot1xMsgTask: May 09 11:44:58.249: 00:1b:77:b4:34:e0 Removing BSSID 18:9c:5d:71:34:50 from PMKID cache of station 00:1b:77:b4:34:e0
    *dot1xMsgTask: May 09 11:44:58.249: 00:1b:77:b4:34:e0 Setting active key cache index 0 ---> 8
    *dot1xMsgTask: May 09 11:44:58.250: 00:1b:77:b4:34:e0 Sent Deauthenticate to mobile on BSSID 18:9c:5d:71:34:50 slot 0(caller 1x_ptsm.c:598)
    *dot1xMsgTask: May 09 11:44:58.250: 00:1b:77:b4:34:e0 Setting active key cache index 8 ---> 8
    *dot1xMsgTask: May 09 11:44:58.250: 00:1b:77:b4:34:e0 Deleting the PMK cache when de-authenticating the client.
    *dot1xMsgTask: May 09 11:44:58.250: 00:1b:77:b4:34:e0 Global PMK Cache deletion failed.
    *dot1xMsgTask: May 09 11:44:58.250: 00:1b:77:b4:34:e0 Scheduling deletion of Mobile Station:  (callerId: 57) in 10 seconds
    *dot1xMsgTask: May 09 11:44:58.250: 00:1b:77:b4:34:e0 Freeing EAP Retransmit Bufer for mobile 00:1b:77:b4:34:e0
    *apfMsConnTask_4: May 09 11:45:03.768: 00:1b:77:b4:34:e0 Reassociation received from mobile on BSSID 18:9c:5d:71:34:50
    *apfMsConnTask_4: May 09 11:45:03.768: 00:1b:77:b4:34:e0 Global 200 Clients are allowed to AP radio
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 Max Client Trap Threshold: 0  cur: 1
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 Rf profile 600 Clients are allowed to AP wlan
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 Applying Interface policy on Mobile, role Unassociated. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 1
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 Re-applying interface policy for client
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 0.0.0.0 START (0) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2202)
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 0.0.0.0 START (0) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2223)
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 apfApplyWlanPolicy: Apply WLAN Policy over PMIPv6 Client Mobility Type
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 In processSsidIE:4795 setting Central switched to TRUE
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 In processSsidIE:4798 apVapId = 1 and Split Acl Id = 65535
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 Applying site-specific Local Bridging override for station 00:1b:77:b4:34:e0 - vapId 1, site 'default-group', interface 'catodos'
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 Applying Local Bridging Interface Policy for station 00:1b:77:b4:34:e0 - vlan 1, interface id 12, interface 'catodos'
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 processSsidIE  statusCode is 0 and status is 0
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 processSsidIE  ssid_done_flag is 0 finish_flag is 0
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 STA - rates (8): 2 4 11 22 12 18 24 36 48 72 96 108 0 0 0 0
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 suppRates  statusCode is 0 and gotSuppRatesElement is 1
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 STA - rates (12): 2 4 11 22 12 18 24 36 48 72 96 108 0 0 0 0
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 extSuppRates  statusCode is 0 and gotExtSuppRatesElement is 1
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 Processing RSN IE type 48, length 20 for mobile 00:1b:77:b4:34:e0
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 0.0.0.0 START (0) Initializing policy
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 0.0.0.0 START (0) Change state to AUTHCHECK (2) last state START (0)
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 0.0.0.0 AUTHCHECK (2) Change state to 8021X_REQD (3) last state AUTHCHECK (2)
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 Central switch is TRUE
    *apfMsConnTask_4: May 09 11:45:03.769: 00:1b:77:b4:34:e0 Not Using WMM Compliance code qosCap 00
    *apfMsConnTask_4: May 09 11:45:03.770: 00:1b:77:b4:34:e0 0.0.0.0 8021X_REQD (3) Plumbed mobile LWAPP rule on AP 18:9c:5d:71:34:50 vapId 1 apVapId 1 flex-acl-name:
    *apfMsConnTask_4: May 09 11:45:03.770: 00:1b:77:b4:34:e0 apfPemAddUser2 (apf_policy.c:333) Changing state for mobile 00:1b:77:b4:34:e0 on AP 18:9c:5d:71:34:50 from Associated to Associated
    *apfMsConnTask_4: May 09 11:45:03.770: 00:1b:77:b4:34:e0 apfPemAddUser2:session timeout forstation 00:1b:77:b4:34:e0 - Session Tout 1800, apfMsTimeOut '1800' and sessionTimerRunning flag is  0
    *apfMsConnTask_4: May 09 11:45:03.770: 00:1b:77:b4:34:e0 Scheduling deletion of Mobile Station:  (callerId: 49) in 1800 seconds
    *apfMsConnTask_4: May 09 11:45:03.770: 00:1b:77:b4:34:e0 Func: apfPemAddUser2, Ms Timeout = 1800, Session Timeout = 1800
    *apfMsConnTask_4: May 09 11:45:03.770: 00:1b:77:b4:34:e0 Sending Assoc Response to station on BSSID 18:9c:5d:71:34:50 (status 0) ApVapId 1 Slot 0
    *apfMsConnTask_4: May 09 11:45:03.770: 00:1b:77:b4:34:e0 apfProcessAssocReq (apf_80211.c:8292) Changing state for mobile 00:1b:77:b4:34:e0 on AP 18:9c:5d:71:34:50 from Associated to Associated
    *spamApTask6: May 09 11:45:03.772: 00:1b:77:b4:34:e0 Sent 1x initiate message to multi thread task for mobile 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0 Creating a PKC PMKID Cache entry for station 00:1b:77:b4:34:e0 (RSN 2)
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0 Resetting MSCB PMK Cache Entry 0 for station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0 Setting active key cache index 8 ---> 8
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0 Setting active key cache index 8 ---> 0
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0 Adding BSSID 18:9c:5d:71:34:50 to PMKID cache at index 0 for station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: New PMKID: (16)
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773:      [0000] f6 3d 52 9f 2a de 52 90 1d a2 46 49 0f 14 f6 69
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0 Initiating RSN PSK to mobile 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0 EAP-PARAM Debug - eap-params for Wlan-Id :1 is disabled - applying Global eap timers and retries
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0 dot1x - moving mobile 00:1b:77:b4:34:e0 into Force Auth state
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0 EAPOL Header:
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00000000: 02 03 00 5f                                       ..._
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0 Found an cache entry for BSSID 18:9c:5d:71:34:50 in PMKID cache at index 0 of station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0 Found an cache entry for BSSID 18:9c:5d:71:34:50 in PMKID cache at index 0 of station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: Including PMKID in M1  (16)
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773:      [0000] f6 3d 52 9f 2a de 52 90 1d a2 46 49 0f 14 f6 69
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0 Starting key exchange to mobile 00:1b:77:b4:34:e0, data packets will be dropped
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0 Sending EAPOL-Key Message to mobile 00:1b:77:b4:34:e0
       state INITPMK (message 1), replay counter 00.00.00.00.00.00.00.00
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0 Sending EAPOL-Key Message to mobile 00:1b:77:b4:34:e0
       state INITPMK (message 1), replay counter 00.00.00.00.00.00.00.00
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0 Allocating EAP Pkt for retransmission to mobile 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0 mscb->apfMsLwappLradNhMac = 78:da:6e:59:c9:8c mscb->apfMsLradSlotId = 0 mscb->apfMsLradJumbo = 0 mscb->apfMsintIfNum = 1
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0  mscb->apfMsBssid = 18:9c:5d:71:34:50 mscb->apfMsAddress = 00:1b:77:b4:34:e0 mscb->apfMsApVapId = 1
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0  dot1xcb->snapOrg = 00 00 00 dot1xcb->eapolWepBit = 0 mscb->apfMsLwappLradVlanId = 0 mscb->apfMsLwappMwarInet.ipv4.addr = -1062679171
    *Dot1x_NW_MsgTask_0: May 09 11:45:03.773: 00:1b:77:b4:34:e0  mscb->apfMsLwappMwarPort = 5246 mscb->apfMsLwappLradInet.ipv4.addr = -1062679163 mscb->apfMsLwappLradPort = 40089
    *osapiBsnTimer: May 09 11:45:05.849: 00:1b:77:b4:34:e0 802.1x 'timeoutEvt' Timer expired for station 00:1b:77:b4:34:e0 and for message = M2
    *dot1xMsgTask: May 09 11:45:05.849: 00:1b:77:b4:34:e0 Retransmit 1 of EAPOL-Key M1 (length 121) for mobile 00:1b:77:b4:34:e0
    *dot1xMsgTask: May 09 11:45:05.849: 00:1b:77:b4:34:e0 mscb->apfMsLwappLradNhMac = 78:da:6e:59:c9:8c mscb->apfMsLradSlotId = 0 mscb->apfMsLradJumbo = 0 mscb->apfMsintIfNum = 1
    *dot1xMsgTask: May 09 11:45:05.849: 00:1b:77:b4:34:e0  mscb->apfMsBssid = 18:9c:5d:71:34:50 mscb->apfMsAddress = 00:1b:77:b4:34:e0 mscb->apfMsApVapId = 1
    *dot1xMsgTask: May 09 11:45:05.849: 00:1b:77:b4:34:e0  dot1xcb->snapOrg = 00 00 00 dot1xcb->eapolWepBit = 0 mscb->apfMsLwappLradVlanId = 0 mscb->apfMsLwappMwarInet.ipv4.addr = -1062679171
    *dot1xMsgTask: May 09 11:45:05.849: 00:1b:77:b4:34:e0  mscb->apfMsLwappMwarPort = 5246 mscb->apfMsLwappLradInet.ipv4.addr = -1062679163 mscb->apfMsLwappLradPort = 40089
    *osapiBsnTimer: May 09 11:45:07.848: 00:1b:77:b4:34:e0 802.1x 'timeoutEvt' Timer expired for station 00:1b:77:b4:34:e0 and for message = M2
    *dot1xMsgTask: May 09 11:45:07.849: 00:1b:77:b4:34:e0 Retransmit 2 of EAPOL-Key M1 (length 121) for mobile 00:1b:77:b4:34:e0
    *dot1xMsgTask: May 09 11:45:07.849: 00:1b:77:b4:34:e0 mscb->apfMsLwappLradNhMac = 78:da:6e:59:c9:8c mscb->apfMsLradSlotId = 0 mscb->apfMsLradJumbo = 0 mscb->apfMsintIfNum = 1
    *dot1xMsgTask: May 09 11:45:07.849: 00:1b:77:b4:34:e0  mscb->apfMsBssid = 18:9c:5d:71:34:50 mscb->apfMsAddress = 00:1b:77:b4:34:e0 mscb->apfMsApVapId = 1
    *dot1xMsgTask: May 09 11:45:07.849: 00:1b:77:b4:34:e0  dot1xcb->snapOrg = 00 00 00 dot1xcb->eapolWepBit = 0 mscb->apfMsLwappLradVlanId = 0 mscb->apfMsLwappMwarInet.ipv4.addr = -1062679171
    *dot1xMsgTask: May 09 11:45:07.849: 00:1b:77:b4:34:e0  mscb->apfMsLwappMwarPort = 5246 mscb->apfMsLwappLradInet.ipv4.addr = -1062679163 mscb->apfMsLwappLradPort = 40089
    *osapiBsnTimer: May 09 11:45:09.848: 00:1b:77:b4:34:e0 802.1x 'timeoutEvt' Timer expired for station 00:1b:77:b4:34:e0 and for message = M2
    *dot1xMsgTask: May 09 11:45:09.849: 00:1b:77:b4:34:e0 Retransmit failure for EAPOL-Key M1 to mobile 00:1b:77:b4:34:e0, retransmit count 3, mscb deauth count 3
    *dot1xMsgTask: May 09 11:45:09.849: 00:1b:77:b4:34:e0 Blacklisting (if enabled) mobile 00:1b:77:b4:34:e0
    *dot1xMsgTask: May 09 11:45:09.849: 00:1b:77:b4:34:e0 0.0.0.0 8021X_REQD (3) Change state to START (0) last state 8021X_REQD (3)
    *dot1xMsgTask: May 09 11:45:09.849: 00:1b:77:b4:34:e0 0.0.0.0 START (0) Reached FAILURE: from line 5274
    *dot1xMsgTask: May 09 11:45:09.849: 00:1b:77:b4:34:e0 Scheduling deletion of Mobile Station:  (callerId: 9) in 10 seconds
    *apfMsConnTask_4: May 09 11:45:15.689: 00:1b:77:b4:34:e0 Reassociation received from mobile on BSSID 18:9c:5d:71:34:50
    *apfMsConnTask_4: May 09 11:45:15.689: 00:1b:77:b4:34:e0 Global 200 Clients are allowed to AP radio
    *apfMsConnTask_4: May 09 11:45:15.689: 00:1b:77:b4:34:e0 Max Client Trap Threshold: 0  cur: 1
    *apfMsConnTask_4: May 09 11:45:15.689: 00:1b:77:b4:34:e0 Rf profile 600 Clients are allowed to AP wlan
    *apfMsConnTask_4: May 09 11:45:15.689: 00:1b:77:b4:34:e0 Applying Interface policy on Mobile, role Unassociated. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 1
    *apfMsConnTask_4: May 09 11:45:15.689: 00:1b:77:b4:34:e0 Re-applying interface policy for client
    *apfMsConnTask_4: May 09 11:45:15.689: 00:1b:77:b4:34:e0 0.0.0.0 START (0) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2202)
    *apfMsConnTask_4: May 09 11:45:15.689: 00:1b:77:b4:34:e0 0.0.0.0 START (0) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2223)
    *apfMsConnTask_4: May 09 11:45:15.689: 00:1b:77:b4:34:e0 apfApplyWlanPolicy: Apply WLAN Policy over PMIPv6 Client Mobility Type
    *apfMsConnTask_4: May 09 11:45:15.689: 00:1b:77:b4:34:e0 In processSsidIE:4795 setting Central switched to TRUE
    *apfMsConnTask_4: May 09 11:45:15.689: 00:1b:77:b4:34:e0 In processSsidIE:4798 apVapId = 1 and Split Acl Id = 65535
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 Applying site-specific Local Bridging override for station 00:1b:77:b4:34:e0 - vapId 1, site 'default-group', interface 'catodos'
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 Applying Local Bridging Interface Policy for station 00:1b:77:b4:34:e0 - vlan 1, interface id 12, interface 'catodos'
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 processSsidIE  statusCode is 0 and status is 0
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 processSsidIE  ssid_done_flag is 0 finish_flag is 0
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 STA - rates (8): 2 4 11 22 12 18 24 36 48 72 96 108 0 0 0 0
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 suppRates  statusCode is 0 and gotSuppRatesElement is 1
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 STA - rates (12): 2 4 11 22 12 18 24 36 48 72 96 108 0 0 0 0
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 extSuppRates  statusCode is 0 and gotExtSuppRatesElement is 1
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 Processing RSN IE type 48, length 20 for mobile 00:1b:77:b4:34:e0
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 0.0.0.0 START (0) Initializing policy
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 0.0.0.0 START (0) Change state to AUTHCHECK (2) last state START (0)
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 0.0.0.0 AUTHCHECK (2) Change state to 8021X_REQD (3) last state AUTHCHECK (2)
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 Central switch is TRUE
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 Not Using WMM Compliance code qosCap 00
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 0.0.0.0 8021X_REQD (3) Plumbed mobile LWAPP rule on AP 18:9c:5d:71:34:50 vapId 1 apVapId 1 flex-acl-name:
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 apfPemAddUser2 (apf_policy.c:333) Changing state for mobile 00:1b:77:b4:34:e0 on AP 18:9c:5d:71:34:50 from Associated to Associated
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 apfPemAddUser2:session timeout forstation 00:1b:77:b4:34:e0 - Session Tout 1800, apfMsTimeOut '1800' and sessionTimerRunning flag is  0
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 Scheduling deletion of Mobile Station:  (callerId: 49) in 1800 seconds
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 Func: apfPemAddUser2, Ms Timeout = 1800, Session Timeout = 1800
    *apfMsConnTask_4: May 09 11:45:15.690: 00:1b:77:b4:34:e0 Sending Assoc Response to station on BSSID 18:9c:5d:71:34:50 (status 0) ApVapId 1 Slot 0
    *apfMsConnTask_4: May 09 11:45:15.691: 00:1b:77:b4:34:e0 apfProcessAssocReq (apf_80211.c:8292) Changing state for mobile 00:1b:77:b4:34:e0 on AP 18:9c:5d:71:34:50 from Associated to Associated
    *spamApTask6: May 09 11:45:15.693: 00:1b:77:b4:34:e0 Sent 1x initiate message to multi thread task for mobile 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.693: 00:1b:77:b4:34:e0 Creating a PKC PMKID Cache entry for station 00:1b:77:b4:34:e0 (RSN 2)
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.693: 00:1b:77:b4:34:e0 Resetting MSCB PMK Cache Entry 0 for station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.693: 00:1b:77:b4:34:e0 Removing BSSID 18:9c:5d:71:34:50 from PMKID cache of station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.693: 00:1b:77:b4:34:e0 Setting active key cache index 0 ---> 8
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.693: 00:1b:77:b4:34:e0 Setting active key cache index 8 ---> 0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.693: 00:1b:77:b4:34:e0 Adding BSSID 18:9c:5d:71:34:50 to PMKID cache at index 0 for station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.693: New PMKID: (16)
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.693:      [0000] f6 3d 52 9f 2a de 52 90 1d a2 46 49 0f 14 f6 69
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.693: 00:1b:77:b4:34:e0 Initiating RSN PSK to mobile 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.693: 00:1b:77:b4:34:e0 EAP-PARAM Debug - eap-params for Wlan-Id :1 is disabled - applying Global eap timers and retries
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.693: 00:1b:77:b4:34:e0 dot1x - moving mobile 00:1b:77:b4:34:e0 into Force Auth state
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.693: 00:1b:77:b4:34:e0 EAPOL Header:
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.694: 00000000: 02 03 00 5f                                       ..._
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.694: 00:1b:77:b4:34:e0 Found an cache entry for BSSID 18:9c:5d:71:34:50 in PMKID cache at index 0 of station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.694: 00:1b:77:b4:34:e0 Found an cache entry for BSSID 18:9c:5d:71:34:50 in PMKID cache at index 0 of station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.694: Including PMKID in M1  (16)
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.694:      [0000] f6 3d 52 9f 2a de 52 90 1d a2 46 49 0f 14 f6 69
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.694: 00:1b:77:b4:34:e0 Starting key exchange to mobile 00:1b:77:b4:34:e0, data packets will be dropped
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.694: 00:1b:77:b4:34:e0 Sending EAPOL-Key Message to mobile 00:1b:77:b4:34:e0
       state INITPMK (message 1), replay counter 00.00.00.00.00.00.00.00
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.694: 00:1b:77:b4:34:e0 Sending EAPOL-Key Message to mobile 00:1b:77:b4:34:e0
       state INITPMK (message 1), replay counter 00.00.00.00.00.00.00.00
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.694: 00:1b:77:b4:34:e0 Reusing allocated memory for  EAP Pkt for retransmission to mobile 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.694: 00:1b:77:b4:34:e0 mscb->apfMsLwappLradNhMac = 78:da:6e:59:c9:8c mscb->apfMsLradSlotId = 0 mscb->apfMsLradJumbo = 0 mscb->apfMsintIfNum = 1
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.694: 00:1b:77:b4:34:e0  mscb->apfMsBssid = 18:9c:5d:71:34:50 mscb->apfMsAddress = 00:1b:77:b4:34:e0 mscb->apfMsApVapId = 1
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.694: 00:1b:77:b4:34:e0  dot1xcb->snapOrg = 00 00 00 dot1xcb->eapolWepBit = 0 mscb->apfMsLwappLradVlanId = 0 mscb->apfMsLwappMwarInet.ipv4.addr = -1062679171
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.694: 00:1b:77:b4:34:e0  mscb->apfMsLwappMwarPort = 5246 mscb->apfMsLwappLradInet.ipv4.addr = -1062679163 mscb->apfMsLwappLradPort = 40089
    *apfMsConnTask_4: May 09 11:45:15.875: 00:1b:77:b4:34:e0 Reassociation received from mobile on BSSID 18:9c:5d:71:34:50
    *apfMsConnTask_4: May 09 11:45:15.875: 00:1b:77:b4:34:e0 Global 200 Clients are allowed to AP radio
    *apfMsConnTask_4: May 09 11:45:15.875: 00:1b:77:b4:34:e0 Max Client Trap Threshold: 0  cur: 1
    *apfMsConnTask_4: May 09 11:45:15.875: 00:1b:77:b4:34:e0 Rf profile 600 Clients are allowed to AP wlan
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 Applying Interface policy on Mobile, role Unassociated. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 1
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 Re-applying interface policy for client
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 0.0.0.0 8021X_REQD (3) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2202)
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 0.0.0.0 8021X_REQD (3) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2223)
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 apfApplyWlanPolicy: Apply WLAN Policy over PMIPv6 Client Mobility Type
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 In processSsidIE:4795 setting Central switched to TRUE
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 In processSsidIE:4798 apVapId = 1 and Split Acl Id = 65535
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 Applying site-specific Local Bridging override for station 00:1b:77:b4:34:e0 - vapId 1, site 'default-group', interface 'catodos'
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 Applying Local Bridging Interface Policy for station 00:1b:77:b4:34:e0 - vlan 1, interface id 12, interface 'catodos'
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 processSsidIE  statusCode is 0 and status is 0
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 processSsidIE  ssid_done_flag is 0 finish_flag is 0
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 STA - rates (8): 2 4 11 22 12 18 24 36 48 72 96 108 0 0 0 0
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 suppRates  statusCode is 0 and gotSuppRatesElement is 1
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 STA - rates (12): 2 4 11 22 12 18 24 36 48 72 96 108 0 0 0 0
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 extSuppRates  statusCode is 0 and gotExtSuppRatesElement is 1
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 Processing RSN IE type 48, length 20 for mobile 00:1b:77:b4:34:e0
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 0.0.0.0 8021X_REQD (3) Initializing policy
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 0.0.0.0 8021X_REQD (3) Change state to AUTHCHECK (2) last state 8021X_REQD (3)
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 0.0.0.0 AUTHCHECK (2) Change state to 8021X_REQD (3) last state AUTHCHECK (2)
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 Central switch is TRUE
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 Not Using WMM Compliance code qosCap 00
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 0.0.0.0 8021X_REQD (3) Plumbed mobile LWAPP rule on AP 18:9c:5d:71:34:50 vapId 1 apVapId 1 flex-acl-name:
    *apfMsConnTask_4: May 09 11:45:15.876: 00:1b:77:b4:34:e0 apfPemAddUser2 (apf_policy.c:333) Changing state for mobile 00:1b:77:b4:34:e0 on AP 18:9c:5d:71:34:50 from Associated to Associated
    *apfMsConnTask_4: May 09 11:45:15.877: 00:1b:77:b4:34:e0 apfPemAddUser2:session timeout forstation 00:1b:77:b4:34:e0 - Session Tout 1800, apfMsTimeOut '1800' and sessionTimerRunning flag is  0
    *apfMsConnTask_4: May 09 11:45:15.877: 00:1b:77:b4:34:e0 Scheduling deletion of Mobile Station:  (callerId: 49) in 1800 seconds
    *apfMsConnTask_4: May 09 11:45:15.877: 00:1b:77:b4:34:e0 Func: apfPemAddUser2, Ms Timeout = 1800, Session Timeout = 1800
    *apfMsConnTask_4: May 09 11:45:15.877: 00:1b:77:b4:34:e0 Sending Assoc Response to station on BSSID 18:9c:5d:71:34:50 (status 0) ApVapId 1 Slot 0
    *apfMsConnTask_4: May 09 11:45:15.877: 00:1b:77:b4:34:e0 apfProcessAssocReq (apf_80211.c:8292) Changing state for mobile 00:1b:77:b4:34:e0 on AP 18:9c:5d:71:34:50 from Associated to Associated
    *spamApTask6: May 09 11:45:15.878: 00:1b:77:b4:34:e0 Sent 1x initiate message to multi thread task for mobile 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0 Creating a PKC PMKID Cache entry for station 00:1b:77:b4:34:e0 (RSN 2)
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0 Resetting MSCB PMK Cache Entry 0 for station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0 Removing BSSID 18:9c:5d:71:34:50 from PMKID cache of station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0 Setting active key cache index 0 ---> 8
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0 Setting active key cache index 8 ---> 0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0 Adding BSSID 18:9c:5d:71:34:50 to PMKID cache at index 0 for station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: New PMKID: (16)
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879:      [0000] f6 3d 52 9f 2a de 52 90 1d a2 46 49 0f 14 f6 69
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0 Initiating RSN PSK to mobile 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0 EAP-PARAM Debug - eap-params for Wlan-Id :1 is disabled - applying Global eap timers and retries
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0 dot1x - moving mobile 00:1b:77:b4:34:e0 into Force Auth state
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0 EAPOL Header:
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00000000: 02 03 00 5f                                       ..._
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0 Found an cache entry for BSSID 18:9c:5d:71:34:50 in PMKID cache at index 0 of station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0 Found an cache entry for BSSID 18:9c:5d:71:34:50 in PMKID cache at index 0 of station 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: Including PMKID in M1  (16)
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879:      [0000] f6 3d 52 9f 2a de 52 90 1d a2 46 49 0f 14 f6 69
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0 Starting key exchange to mobile 00:1b:77:b4:34:e0, data packets will be dropped
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0 Sending EAPOL-Key Message to mobile 00:1b:77:b4:34:e0
       state INITPMK (message 1), replay counter 00.00.00.00.00.00.00.00
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0 Sending EAPOL-Key Message to mobile 00:1b:77:b4:34:e0
       state INITPMK (message 1), replay counter 00.00.00.00.00.00.00.00
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0 Reusing allocated memory for  EAP Pkt for retransmission to mobile 00:1b:77:b4:34:e0
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0 mscb->apfMsLwappLradNhMac = 78:da:6e:59:c9:8c mscb->apfMsLradSlotId = 0 mscb->apfMsLradJumbo = 0 mscb->apfMsintIfNum = 1
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0  mscb->apfMsBssid = 18:9c:5d:71:34:50 mscb->apfMsAddress = 00:1b:77:b4:34:e0 mscb->apfMsApVapId = 1
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0  dot1xcb->snapOrg = 00 00 00 dot1xcb->eapolWepBit = 0 mscb->apfMsLwappLradVlanId = 0 mscb->apfMsLwappMwarInet.ipv4.addr = -1062679171
    *Dot1x_NW_MsgTask_0: May 09 11:45:15.879: 00:1b:77:b4:34:e0  mscb->apfMsLwappMwarPort = 5246 mscb->apfMsLwappLradInet.ipv4.addr = -1062679163 mscb->apfMsLwappLradPort = 40089
    *osapiBsnTimer: May 09 11:45:18.048: 00:1b:77:b4:34:e0 802.1x 'timeoutEvt' Timer expired for station 00:1b:77:b4:34:e0 and for message = M2
    *dot1xMsgTask: May 09 11:45:18.049: 00:1b:77:b4:34:e0 Retransmit 1 of EAPOL-Key M1 (length 121) for mobile 00:1b:77:b4:34:e0
    *dot1xMsgTask: May 09 11:45:18.049: 00:1b:77:b4:34:e0 mscb->apfMsLwappLradNhMac = 78:da:6e:59:c9:8c mscb->apfMsLradSlotId = 0 mscb->apfMsLradJumbo = 0 mscb->apfMsintIfNum = 1
    *dot1xMsgTask: May 09 11:45:18.049: 00:1b:77:b4:34:e0  mscb->apfMsBssid = 18:9c:5d:71:34:50 mscb->apfMsAddress = 00:1b:77:b4:34:e0 mscb->apfMsApVapId = 1
    *dot1xMsgTask: May 09 11:45:18.049: 00:1b:77:b4:34:e0  dot1xcb->snapOrg = 00 00 00 dot1xcb->eapolWepBit = 0 mscb->apfMsLwappLradVlanId = 0 mscb->apfMsLwappMwarInet.ipv4.addr = -1062679171
    *dot1xMsgTask: May 09 11:45:18.049: 00:1b:77:b4:34:e0  mscb->apfMsLwappMwarPort = 5246 mscb->apfMsLwappLradInet.ipv4.addr = -1062679163 mscb->apfMsLwappLradPort = 40089
    *osapiBsnTimer: May 09 11:45:20.049: 00:1b:77:b4:34:e0 802.1x 'timeoutEvt' Timer expired for station 00:1b:77:b4:34:e0 and for message = M2
    *dot1xMsgTask: May 09 11:45:20.049: 00:1b:77:b4:34:e0 Retransmit 2 of EAPOL-Key M1 (length 121) for mobile 00:1b:77:b4:34:e0
    *dot1xMsgTask: May 09 11:45:20.049: 00:1b:77:b4:34:e0 mscb->apfMsLwappLradNhMac = 78:da:6e:59:c9:8c mscb->apfMsLradSlotId = 0 mscb->apfMsLradJumbo = 0 mscb->apfMsintIfNum = 1
    *dot1xMsgTask: May 09 11:45:20.049: 00:1b:77:b4:34:e0  mscb->apfMsBssid = 18:9c:5d:71:34:50 mscb->apfMsAddress = 00:1b:77:b4:34:e0 mscb->apfMsApVapId = 1
    *dot1xMsgTask: May 09 11:45:20.049: 00:1b:77:b4:34:e0  dot1xcb->snapOrg = 00 00 00 dot1xcb->eapolWepBit = 0 mscb->apfMsLwappLradVlanId = 0 mscb->apfMsLwappMwarInet.ipv4.addr = -1062679171
    *dot1xMsgTask: May 09 11:45:20.049: 00:1b:77:b4:34:e0  mscb->apfMsLwappMwarPort = 5246 mscb->apfMsLwappLradInet.ipv4.addr = -1062679163 mscb->apfMsLwappLradPort = 40089
    *osapiBsnTimer: May 09 11:45:22.048: 00:1b:77:b4:34:e0 802.1x 'timeoutEvt' Timer expired for station 00:1b:77:b4:34:e0 and for message = M2
    *dot1xMsgTask: May 09 11:45:22.049: 00:1b:77:b4:34:e0 Retransmit failure for EAPOL-Key M1 to mobile 00:1b:77:b4:34:e0, retransmit count 3, mscb deauth count 0
    *dot1xMsgTask: May 09 11:45:22.049: 00:1b:77:b4:34:e0 Resetting MSCB PMK Cache Entry 0 for station 00:1b:77:b4:34:e0
    *dot1xMsgTask: May 09 11:45:22.049: 00:1b:77:b4:34:e0 Removing BSSID 18:9c:5d:71:34:50 from PMKID cache of station 00:1b:77:b4:34:e0
    *dot1xMsgTask: May 09 11:45:22.049: 00:1b:77:b4:34:e0 Setting active key cache index 0 ---> 8
    *dot1xMsgTask: May 09 11:45:22.049: 00:1b:77:b4:34:e0 Sent Deauthenticate to mobile on BSSID 18:9c:5d:71:34:50 slot 0(caller 1x_ptsm.c:598)
    *dot1xMsgTask: May 09 11:45:22.049: 00:1b:77:b4:34:e0 Setting active key cache index 8 ---> 8
    *dot1xMsgTask: May 09 11:45:22.049: 00:1b:77:b4:34:e0 Deleting the PMK cache when de-authenticating the client.
    *dot1xMsgTask: May 09 11:45:22.049: 00:1b:77:b4:34:e0 Global PMK Cache deletion failed.
    *dot1xMsgTask: May 09 11:45:22.049: 00:1b:77:b4:34:e0 Scheduling deletion of Mobile Station:  (callerId: 57) in 10 seconds
    *dot1xMsgTask: May 09 11:45:22.049: 00:1b:77:b4:34:e0 Freeing EAP Retransmit Bufer for mobile 00:1b:77:b4:34:e0
    *osapiBsnTimer: May 09 11:45:32.048: 00:1b:77:b4:34:e0 apfMsExpireCallback (apf_ms.c:625) Expiring Mobile!
    *apfReceiveTask: May 09 11:45:32.049: 00:1b:77:b4:34:e0 apfMsExpireMobileStation (apf_ms.c:6632) Changing state for mobile 00:1b:77:b4:34:e0 on AP 18:9c:5d:71:34:50 from Associated to Disassociated
    *apfReceiveTask: May 09 11:45:32.049: 00:1b:77:b4:34:e0 Scheduling deletion of Mobile Station:  (callerId: 45) in 10 seconds
    Thanks for any advice

    In some of the big name brands of wireless, there is "no such thing" as 802.11n on a 2.4 Ghz.  No such thing because Cisco won't allow you (any more) to do channel bonding of 2.4 Ghz.  It doesn't make any sense to bond an already restricted 2.4 Ghz non-overlapping channel (three) and squeeze this number down to two.  
    Can you check to ensure that the data rates for 802.11b are enabled?  Maybe someone disabled data rates from 1 Mbps to 11 Mbps.

  • DHCP Error with WLC 2504 and Aironet 2600 setup across subnets

    Hey guys
    I have just setup a new WLC 2504 controller to manage a WiFi service that will span 6 geographic locations.  The local networks at each location are on different subnets (all 192.168.x.x) and are linked up via IPSEC VPN links, and there is Active Directory spanning the sites, with DNS and DHCP servers running at each location.
    I tested the WLC at our main office with a single AP, and it worked fine.  The AP set itself up, and wireless devices connect with no probs. Great!  Yesterday I headed out to one of our remote sites, and connected an AP to their network - and that seemed to work fine too.  Within a few minutes I was able to see the WiFi network I'd setup, and my smartphone connected to it straight away (as I'd rpeviously connected at the main office), so I was pretty happy that all was working well.
    This morning however I've had notification that wifi performance at the remote site isn't great.  I've got someone to check their ip address, and I've found that their IP address and default gateway match the LAN at the main office where the WLC is based - NOT the LAN where the wireless client is.  Obvioulsy this is not ideal!
    So I guess my question is, what have I done wrong?  (I guess I HAVE done something wrong!?).  And how can I get wireless clients at remote sites to pick up an IP from the DHCP server at THEIR site?
    Any help would be greatly appreciated! 
    Thanks!           

    Hello Tim,
    What mode your APs are in? Local mode? or FlexConnect mode?
    If local mode, then all the traffic will be tunnelled to the WLC and they'll be same as if you are connecting from the WLC location.
    If you use FlexConnect APs (which is recommended for remote sites) you can configure FlexConnect groups on the WLC and add each location in a specific group. In that group you can decide what VLAN the users should be in.
    Check this link for FlexConnect group configuration
    http://www.cisco.com/en/US/docs/wireless/controller/7.2/configuration/guide/cg_flexconnect.html#wp1230080
    HTH
    Amjad
    Rating useful replies is more useful than saying "Thank you"

  • Best practices for network design on WLC 2504 and 5508

    Dear all:
    I'm looking for some recommendations on WLC 2504 and 5508 about the the following:
    Maximum amount of AP per port
    The scenario when to use all ports in both WLC
    Maximum number of clients(users) per port
    Bandwidth comsumption of  management vs data in order to assign one port for management
    I've just found this:
    Cisco 5508 controllers have eight Gigabit Ethernet distribution system ports, through which the controller can manage multiple access points. The 5508-12, 5508-25, 5508-50, 5508-100, and 5508-250 models allow a total of 12, 25, 50, 100, or 250 access points to join the controller. Cisco 5508 controllers have no restrictions on the number of access points per port. However, Cisco recommends using link aggregation (LAG) or configuring dynamic AP-manager interfaces on each Gigabit Ethernet port to automatically balance the load. If more than 100 access points are connected to the 5500 series controller, make sure that more than one gigabit Ethernet interface is connected to the upstream switch.
    http://www.cisco.com/c/en/us/td/docs/wireless/controller/6-0/configuration/guide/Controller60CG/c60mint.html
    Thanks for your help.

    The 5508-12, 5508-25, 5508-50, 5508-100, and 5508-250 models allow a total of 12, 25, 50, 100, or 250 access points to join the controller.
    This is an old document.  5508 can now support up to 500 APs if you run firmware 7.X.  2504 can support up to 75 APs if you run firmware 7.4.X.
    I'm looking for some recommendations on WLC 2504 and 5508 about the the following:
    Best practice and recommendation is to LAG all ports so you will be able to form a link redundancy.  If one link goes down, you have other link to push traffic. 

  • Cisco WLC 2504 webportal for Server 2008 R2 DC LDAP or RADIUS

    HI,Friends.
    I want to get my mobile or Notebook clients connecting to wireless and use my Domain users ,Cisco WLC 2504 to authenticate via LDAP or  RADIUS to our Windows Server 2008 Domain Controllers
    question:
    one,i can use my domain one Organizational Unit ,such as cn=use01,ou=test,dc=lzh,dc=com. now, noly user01 can logon on web, But how I make all my domain users can use web log it ? 
    I was using radius authentication or ldap certification to do web authentication ?which is good. ???
    I specified child ou, ou its users superiors can not be landed on

    hi ,Scott Fella
    Thank you,I am very happy to receive your reply,  I finally binding domain user authentication LDAP authentication done successfully. but You say the combination of nps I did not do the radius authentication is successful, I do not know where the problems.
    the err:
    <Event><Timestamp data_type="4">07/27/2014 18:33:36.845</Timestamp><Computer-Name data_type="1">PDC-CQ</Computer-Name><Event-Source data_type="1">IAS</Event-Source><User-Name data_type="1">11</User-Name><Service-Type data_type="0">1</Service-Type><NAS-IP-Address data_type="3">10.10.10.253</NAS-IP-Address><NAS-Port data_type="0">1</NAS-Port><NAS-Identifier data_type="1">WLC-CNNEWCITY</NAS-Identifier><NAS-Port-Type data_type="0">19</NAS-Port-Type><Vendor-Specific data_type="2">00003763010600000001</Vendor-Specific><Calling-Station-Id data_type="1">10.12.0.11</Calling-Station-Id><Called-Station-Id data_type="1">10.10.10.253</Called-Station-Id><Client-IP-Address data_type="3">10.10.10.253</Client-IP-Address><Client-Vendor data_type="0">0</Client-Vendor><Client-Friendly-Name data_type="1">WLC</Client-Friendly-Name><Proxy-Policy-Name data_type="1">Use Windows authentication for all users</Proxy-Policy-Name><Provider-Type data_type="0">1</Provider-Type><SAM-Account-Name data_type="1">CNNEWCITY\11</SAM-Account-Name><Class data_type="1">311 1 10.10.10.1 07/27/2014 09:41:28 5</Class><Authentication-Type data_type="0">1</Authentication-Type><NP-Policy-Name data_type="1">Connections to other access servers</NP-Policy-Name><Quarantine-Update-Non-Compliant data_type="0">1</Quarantine-Update-Non-Compliant><Fully-Qualifed-User-Name data_type="1">cnnewcity.com/user/test/11</Fully-Qualifed-User-Name><Packet-Type data_type="0">1</Packet-Type><Reason-Code data_type="0">0</Reason-Code></Event>
    <Event><Timestamp data_type="4">07/27/2014 18:33:36.845</Timestamp><Computer-Name data_type="1">PDC-CQ</Computer-Name><Event-Source data_type="1">IAS</Event-Source><Class data_type="1">311 1 10.10.10.1 07/27/2014 09:41:28 5</Class><Fully-Qualifed-User-Name data_type="1">cnnewcity.com/user/test/11</Fully-Qualifed-User-Name><Quarantine-Update-Non-Compliant data_type="0">1</Quarantine-Update-Non-Compliant><Client-IP-Address data_type="3">10.10.10.253</Client-IP-Address><Client-Vendor data_type="0">0</Client-Vendor><Client-Friendly-Name data_type="1">WLC</Client-Friendly-Name><Proxy-Policy-Name data_type="1">Use Windows authentication for all users</Proxy-Policy-Name><Provider-Type data_type="0">1</Provider-Type><SAM-Account-Name data_type="1">CNNEWCITY\11</SAM-Account-Name><NP-Policy-Name data_type="1">Connections to other access servers</NP-Policy-Name><Authentication-Type data_type="0">1</Authentication-Type><Packet-Type data_type="0">3</Packet-Type><Reason-Code data_type="0">66</Reason-Code></Event>
    then,You gave two figures is that what you mean? what's the meaning it that services-type =login ?

  • WLC 2504 redundancy set up

    WLC: 2504
    Firmware: 7.6.100
    Hello,
    I'm getting very confused in how to set up redundancy with WLC 2504. Some sources talk about Client SSO, some about N+1.
    But it seems that although I should use Client SSO with firmware 7.6, the WLC 2504 doesn't support it.
    When I type config redundancy, I have no choice
    >config redundancy ?
    unit           Configure redundancy unit [primary | secondary]
    So I typed "config redundancy unit primary" on my 2504 and "config redundancy unit secondary" on my 2504-HA
    And when I issue this command I have very little information
    >show redundancy summary
    Type of the Unit = Primary
    Does someone has guidelines for redundancy with WLC 2504 on firmware 7.6 ?
    Thank you

    Hello,
    Thank you both for your answers.
    Something I didn't understand in the documentation is this.
    Is there a replication of configuration between the WLC primary and the HA ? I did read that they should have different network settings (IP addresses) so I understand that there is not a total replication, what about the rest of the configuration ?
    The only result I have when I issue a command on the WLC-HA is this
    >show redundancy summary
    Type of the Unit = Secondary
    It doesn't look exactly what I see in the documentation.
    Thank you

  • DEBUG-4-INVALID_MODULE on the WLC 2504 with version 7.6.100????

    Hi!!!  Please help with the solution.
    I have one WLC 2504, 4 Cisco 1141 APs and one AP 1602.
    Yesterday, I upgrade the WLC with version 7.5.102 to version 7.6.100.
    After the upgrade in Message Logs on the WLC at the same time see the following message:
    *RRM-MGR-5_0-GRP: Jan 23 08:44:25.449: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 08:35:41.189: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 08:34:17.373: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 08:25:32.125: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 08:24:09.309: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 08:15:23.013: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 08:14:01.213: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 08:05:13.949: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 08:03:53.149: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 07:55:04.905: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 07:53:45.086: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 07:44:55.813: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 07:43:37.010: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 07:34:46.749: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 07:33:28.930: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 07:24:37.669: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 07:23:20.865: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 07:14:28.593: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 07:13:12.789: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 07:04:19.529: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 07:03:04.729: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 06:54:10.493: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 06:52:56.689: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 06:44:01.445: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 06:42:48.645: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.
    *sntpReceiveTask: Jan 23 06:35:22.218: #LOG-4-Q_IND: debug.c:2636 Unhandled debug module 5005.[...It occurred 19 times.!]
    *RRM-MGR-2_4-GRP: Jan 23 06:33:48.070: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 06:32:36.266: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 06:23:39.030: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 06:22:28.226: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 06:13:29.986: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 06:12:20.186: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 06:03:20.930: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 06:02:12.130: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 05:53:11.890: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 05:52:04.090: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 05:43:02.838: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 05:41:56.039: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 05:32:53.790: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 05:31:47.986: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 05:22:44.758: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 05:21:39.950: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 05:12:35.718: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 05:11:31.910: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 05:02:26.670: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 05:01:23.859: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 04:52:17.606: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 04:51:15.794: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 04:42:08.566: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 04:41:07.750: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 04:31:59.506: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 04:30:59.703: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 04:21:50.450: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 04:20:51.646: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 04:11:41.402: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 04:10:43.598: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 04:01:32.326: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 04:00:35.522: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 03:51:23.258: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 03:50:27.442: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 03:41:14.182: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 03:40:19.378: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 03:31:05.106: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 03:30:11.302: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 03:20:56.042: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 03:20:03.242: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 03:10:46.978: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 03:09:55.178: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 03:00:37.902: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 02:59:47.102: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 02:50:28.826: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 02:49:39.026: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 02:40:19.782: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 02:39:30.983: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 02:30:10.742: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 02:29:22.942: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 02:20:01.698: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 02:19:14.886: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 02:09:52.646: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 02:09:06.842: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 01:59:43.587: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 01:58:58.783: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 01:49:34.546: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 01:48:50.742: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 01:39:25.494: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 01:38:42.687: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 01:29:16.454: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 01:28:34.642: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 01:19:07.402: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 01:18:26.594: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 01:08:58.362: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 01:08:18.554: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 00:58:49.322: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 00:58:10.514: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 00:48:40.266: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 00:48:02.467: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 00:38:31.222: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 00:37:54.411: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 00:28:22.174: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 00:27:46.374: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 00:18:13.106: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 00:17:38.306: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 23 00:08:04.062: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 23 00:07:30.262: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 22 23:57:55.022: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 22 23:57:22.222: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 22 23:47:45.958: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 22 23:47:14.158: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 22 23:37:36.906: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 22 23:37:06.106: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 22 23:27:27.826: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 22 23:26:58.026: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 22 23:17:18.762: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 22 23:16:49.962: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 20 times/sec!.]
    *RRM-MGR-2_4-GRP: Jan 22 23:07:09.686: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.[...It occurred 10 times/sec!.]
    *RRM-MGR-5_0-GRP: Jan 22 23:06:41.870: #DEBUG-4-INVALID_MODULE: debug.c:2636 Unhandled debug module 5005.
    With what may be the problem exists? Any suggestion?

    Have you upgraded the FUS to 1.8.0.0? What happens if you try to boot from v7.5 do you see the messages and maybe boot back to v7.6?
    Here is what the doc mentions about the error
    Error Message %DEBUG-4-INVALID_MODULE: Unhandled debug module [dec].
    Explanation This module cannot be debugged.
    Recommended Action Copy the message exactly as it appears on the console or in the system log. Research and attempt to resolve the issue using the tools and utilities provided at http://www.cisco.com/tac. With some messages, these tools and utilities will supply clarifying information. Search for resolved software issues using the Bug Toolkit at http://tools.cisco.com/Support/BugToolKit/. If you still require assistance, open a case with the Technical Assistance Center via the Internet at http://tools.cisco.com/ServiceRequestTool/create/launch.do, or contact your Cisco technical support representative and provide the representative with the information you have gathered.
    http://www.cisco.com/en/US/docs/wireless/controller/message/guide/msgs4.html#wp1000708
    Sent from Cisco Technical Support iPhone App

Maybe you are looking for

  • Problem in Display Dunning Letter - F150

    Dear Experts, While I run F150, for example for Customer XXXX. The Customer have 3 open item/ document number with different arrears (14, 60 and 180) which is the customer shoud be have 3 reminder letter (1, 2 and 3). But when I check the sample lett

  • Macbook reboots suddenly when I full screen video

    Hello I am having issues with my Macbook and hope someone can help. My Macbook shuts down and reboots randomly and suddenly under very specific circumstances. The fault only ever occurs either at a random point during full screen playback (this can b

  • Is there a limit to the number of subclips displayed in FCP7?

    I am editing a piece that has two large clips that I have divided into subclips based on the start and stop date and time. I can only display a little over 40 of these subclips in the project window. How can I see the rest of them?

  • How to use logic:present tag in struts el tag

    Hi I am trying to use struts el tags in the jsp page.I am struggling with the following exception: Cannot find bean: "result" in any scope.I couldn't understand why this error is coming even i had the property "result" in my ActionForm. ActionForm: p

  • I am getting about 50 mV of noise in a signal that ranges from 0V to 5V.

    I am using a BNC-2120 board with a PCI-6024E card and Labview 5.1.1. to aquire a voltage signal with a high limit of 5V and lower limit of 0V. The signal is noisy with about 50 mV of noise. Is there a way to get rid of this noise? Thank you for you h