cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1756
Views
0
Helpful
1
Replies

7925G EAP-FAST connection failed

Jason Aarons
Level 6
Level 6

4.0.217.0

Everything works great with a Lenovo T61 laptop running EAP-FAST using the IBM Access Connections client.

However a new out of box 7925G SCCP 1.3(3) phone shows "connection failed" onscreen to WLC 4.0.217.0 and ACS 5.1

Here is what the RADIUS log on Cisco Secure ACS 5.1 shows, TAC verified the ACS is good.

11001  Received RADIUS Access-Request

11017  RADIUS created a new session

Evaluating Service Selection Policy

15004  Matched rule

15012  Selected Access Service - 7925s

11507  Extracted EAP-Response/Identity

12100  Prepared EAP-Request proposing EAP-FAST with challenge

11006  Returned RADIUS Access-Challenge

11001  Received RADIUS Access-Request

11018  RADIUS is re-using an existing session

12102  Extracted EAP-Response containing EAP-FAST challenge-response and accepting EAP-FAST as negotiated 12800  Extracted first TLS record; TLS handshake started.

12805  Extracted TLS ClientHello message.

12806  Prepared TLS ServerHello message.

12808  Prepared TLS ServerKeyExchange message.

12810  Prepared TLS ServerDone message.

12105  Prepared EAP-Request with another EAP-FAST challenge

11006  Returned RADIUS Access-Challenge

5411  EAP session timed out

1 Reply 1

John Cook
Level 1
Level 1

Did you change the eap timeout to a higher value?  I know this is for a 7921, but I believe that the 7925 has the same issue.

"config advanced eap request-timeout 20"

http://www.cisco.com/en/US/docs/solutions/Enterprise/Mobility/vowlan/41dg/vowlan_ch10.html#wp1048186

John

Review Cisco Networking products for a $25 gift card