Jump to content

Wireless Clients not Authenticating with CISCO and RAIDUS


Recommended Posts

Posted

Hi Guys,

 

I have a CISCO Wireless system which uses RAIDUS to authenticate computers. I am currently have issues were the computers are not connecting to the Wireless Network. There are no errors showing up on the RAIDUS Server and the Wireless Controller is able to pint the RAIDUS Server. Also the Wireless Controller is showing the following error; *Dot1x_NW_MsgTask_7: Oct 20 14:53:53.071: %DOT1X-3-MAX_EAP_RETRIES: 1x_auth_pae.c:3136 Max EAP identity request retries (3) exceeded for client 1c:3e:84:9b:8b:e7.

 

This is an example log which is repeated but for different MAK Addresses.

 

Does anyone have any suggestion as to why this might be happening.

Posted

That error means the WLC is sending EAP identity requests to the client, but the client is not responding.

 

Are there any other errors being shown?

 

It could be that the certificate in use is not in the client's root certificate store, and therefore the client is rejecting it.

Posted

Hi There,

 

I can't find any Certificates on the Laptops (which is strange) and here are some of the other errors that are showing up.

 

*dot1xMsgTask: Oct 20 15:17:38.523: %DOT1X-3-MAX_EAP_RETRIES: 1x_auth_pae.c:3136 Max EAP identity request retries (3) exceeded for client 44:6d:57:62:d9:dc

*Dot1x_NW_MsgTask_0: Oct 20 15:17:37.544: %DOT1X-3-MAX_EAP_RETRIES: 1x_auth_pae.c:3136 Max EAP identity request retries (3) exceeded for client c4:85:08:04:53:d0

*Dot1x_NW_MsgTask_0: Oct 20 15:17:37.543: %DOT1X-3-ABORT_AUTH: 1x_bauth_sm.c:447 Authentication Aboted for client c4:85:08:04:53:d0

*Dot1x_NW_MsgTask_7: Oct 20 15:17:34.566: %DOT1X-3-MAX_EAP_RETRIES: 1x_auth_pae.c:3136 Max EAP identity request retries (3) exceeded for client 1c:3e:84:9b:8b:e7

*Dot1x_NW_MsgTask_7: Oct 20 15:17:34.566: %DOT1X-3-ABORT_AUTH: 1x_bauth_sm.c:447 Authentication Aboted for client 1c:3e:84:9b:8b:e7

 

I found this in the TrapLog

 

AAA Authentication Failure for UserName:host/TL0840.Ashdown.internal User Type: WLAN USER

Posted

Hi Guys,

 

A new bit of information that I have fund out. On our wireless Network we were using AES Encryption if we change to TKIP the network start working Again. Is there something in a AES Policy that Expires or needs to be updated to ensure that the connection continue to work? This is across all our networks even the ones that use a Pre-Shared Key.

 

Kind Regards

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...