Try and try, we have been unable to use WPA2 (Pre-shared Key aka Personal) to connect to a Cisco1811w.
This works fine if we turn off encryption.
What we see in debug messages is (debug dot11 station connection failure).
*Dec 18 21:17:05.041 CST: Client c417.fed5.8522 failed: Dot1x MIC mismatch
*Dec 18 21:17:05.137 CST: Client c417.fed5.8522 failed: Dot1x MIC mismatch
*Dec 18 21:17:05.237 CST: Client c417.fed5.8522 failed: Dot1x MIC mismatch
*Dec 18 21:17:05.337 CST: %DOT11-7-AUTH_FAILED: Station c417.fed5.8522 Authentication failed
We have tried an 8 character and 11 character pre-shared key. Same results. Why are we getting Dot1x MIC mismatch?
Can someone please help us find what is wrong?
Cisco IOS Software, C181X Software (C181X-ADVENTERPRISEK9-M), Version 12.4(24)T3
! config parts
aaa authentication login default local
aaa authentication login VPN local
aaa authorization exec default local
aaa authorization network VPN local
dot11 ssid ACDinternet
authentication key-management wpa
wpa-psk ascii 7 010013165D0E141F205E5A10
no ip address
encryption vlan 98 mode ciphers aes-ccm tkip
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
no cdp enable
encapsulation dot1Q 98
no cdp enable
bridge-group 98 subscriber-loop-control
bridge-group 98 spanning-disabled
bridge-group 98 block-unknown-source
no bridge-group 98 source-learning
no bridge-group 98 unicast-flooding
bridge 98 protocol ieee
bridge 98 route ip
ip address 192.168.98.1 255.255.255.0
ip access-group 198 in
ip nat inside
ip tcp adjust-mss 1452
Thanks for any support you can provide!
I understand it's a Cisco router, but the commands are the same for the AP. Try to manually configure the client for wpa/tkip and see if your client connects. If it does, then the configuration is not for WPA2. Usually if that is not an option, it means the radio/ios doesn't support wpa2.
Sent from my iPhone