cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
778
Views
0
Helpful
6
Replies

MFP Anomaly

rduke
Level 1
Level 1

Ever since upgrading my 4404 and WiSM controllers, I keep getting a bunch of MFP errors like the one below. Is anyone else seeing the same thing ? I have MFP set to optional. It is occurring in multiple cities.

Thanks,

Randy

----------------------------------

Message

MFP Anomaly Detected - 582 'Invalid MIC' violation(s) have originated from the AP with BSS '00:1c:0e:40:ba:6f'. This was detected by the radio with Slot ID '1' of the AP with MAC '00:1a:e2:10:e0:80' when observing 'Beacon, Disassociation, and Deauthentication' frames.

6 Replies 6

Rob Huffman
Hall of Fame
Hall of Fame

Hi Randy,

Just thought you might want to see this recent post where these same errors are ocurring after an upgrade to 4.2.61.0. Maybe you could piggyback on this TAC Case;

http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Wireless%20-%20Mobility&topic=General&CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.2cbf0293/0#selected_message

Hope this helps!

Rob

Rob,

Actually that was my post, but thanks anyhow. I did talk to Cisco about it yesterday since they were slow about getting back to me. I had the call open since Dec 13th, but they said they are working on it so maybe we will see a fix. In the meantime the workaround is to turn off MFP if you don't want to see the errors.

Randy

Hi Randy,

Sorry about that my friend! My eyes must have been half-closed when I sent that. My appologies :)

Take care,

Rob

Randy:

I have been seeing this as well and have chalked it up to Cisco's needing a serious refresh on their wireless IDS.

I have spent so much time cumulatively on trying to get them to resolve these false alarms that I ought to send them a bill!

- John

psiegling
Level 1
Level 1

Randy,

Have you been getting calls from users regarding loss of connection to the APs on the wireless network?

We upgraded to 4.2.217 on our 4404 WLC two week ago. The MFP messages started showing up then. Also, users are only able to stay attached for about 30 min. The must manually reconnect.

Thank you,

Phil

Hi Phil,

I was curious if you were still having issues with wireless clients staying connected for longer than 30 minutes? I am currently having a similar issue however I am not sure if it is really the same. Clients with certain Intel chipsets lose their DHCP information after 30 minutes (half of the 1 hour lease) and they have to disable/enable the wireless connection in order to reconnect.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card