cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7446
Views
0
Helpful
0
Comments
Vinay Sharma
Level 7
Level 7

 

Introduction

Wireless Guest Client often Disconnected with Error - DHCP_REQD (7) Pem timed out.

Scenario

User reported an issue that one of their guest client is disconnecting often. 

Using WLC 5508, Open Guest WLAN with redirect to ISE.

50-60 clients working constantly and with no problems. 

One of them disconnecting every 5 minutes.

Debugs

*apfReceiveTask: Jan 29 11:57:50.721: 6c:88:14:f5:38:18 pemApfDeleteMobileStation2: APF_MS_PEM_WAIT_L2_AUTH_COMPLETE = 0.
*apfReceiveTask: Jan 29 11:57:50.721: 6c:88:14:f5:38:18 0.0.0.0 START (0) Deleted mobile LWAPP rule on AP [b4:14:89:d1:d5:c0]
*pemReceiveTask: Jan 29 11:57:50.721: 6c:88:14:f5:38:18 0.0.0.0 Removed NPU entry.
*apfReceiveTask: Jan 29 11:57:50.721: 6c:88:14:f5:38:18 Deleting mobile on AP b4:14:89:d1:d5:c0(0)
*apfMsConnTask_5: Jan 29 11:57:51.011: 6c:88:14:f5:38:18 Adding mobile on LWAPP AP b4:14:89:d1:d5:c0(0)
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Association received from mobile on BSSID b4:14:89:d1:d5:c3
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Global 200 Clients are allowed to AP radio
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Max Client Trap Threshold: 0  cur: 12
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Rf profile 600 Clients are allowed to AP wlan
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 override for default ap group, marking intgrp NULL
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Applying Interface policy on Mobile, role Unassociated. Ms NAC State 0 Quarantine Vlan 0 Access Vlan 0
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Re-applying interface policy for client
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 0.0.0.0 START (0) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2219)
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 0.0.0.0 START (0) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2240)
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 apfApplyWlanPolicy: Apply WLAN Policy over PMIPv6 Client Mobility Type
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 In processSsidIE:4796 setting Central switched to TRUE
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 In processSsidIE:4799 apVapId = 4 and Split Acl Id = 65535
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Applying site-specific Local Bridging override for station 6c:88:14:f5:38:18 - vapId 4, site 'MeetingRooms', interface 'guests-internet'
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Applying Local Bridging Interface Policy for station 6c:88:14:f5:38:18 - vlan 480, interface id 21, interface 'guests-internet'
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 override from ap group, removing intf group from mscb
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Applying site-specific override for station 6c:88:14:f5:38:18 - vapId 4, site 'MeetingRooms', interface 'guests-internet'
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Applying Interface policy on Mobile, role Unassociated. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 480
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 Re-applying interface policy for client
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 0.0.0.0 START (0) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2219)
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 0.0.0.0 START (0) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2240)
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 processSsidIE  statusCode is 0 and status is 0
*apfMsConnTask_5: Jan 29 11:57:51.012: 6c:88:14:f5:38:18 processSsidIE  ssid_done_flag is 0 finish_flag is 0
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 STA - rates (6): 24 36 176 72 96 108 0 0 0 0 0 0 0 0 0 0
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 suppRates  statusCode is 0 and gotSuppRatesElement is 1
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 0.0.0.0 START (0) Initializing policy
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 0.0.0.0 START (0) Change state to AUTHCHECK (2) last state START (0)
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 0.0.0.0 AUTHCHECK (2) Change state to L2AUTHCOMPLETE (4) last state AUTHCHECK (2)
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 Central switch is TRUE
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 Not Using WMM Compliance code qosCap 00
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 0.0.0.0 L2AUTHCOMPLETE (4) Plumbed mobile LWAPP rule on AP b4:14:89:d1:d5:c0 vapId 4 apVapId 4 flex-acl-name:
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 0.0.0.0 L2AUTHCOMPLETE (4) Change state to DHCP_REQD (7) last state L2AUTHCOMPLETE (4)
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 apfMsAssoStateInc
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 apfPemAddUser2 (apf_policy.c:333) Changing state for mobile 6c:88:14:f5:38:18 on AP b4:14:89:d1:d5:c0 from Idle to Associated
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 apfPemAddUser2:session timeout forstation 6c:88:14:f5:38:18 - Session Tout 0, apfMsTimeOut '0' and sessionTimerRunning flag is  0
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 Stopping deletion of Mobile Station: (callerId: 48)
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 Func: apfPemAddUser2, Ms Timeout = 0, Session Timeout = 0
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 Sending Assoc Response to station on BSSID b4:14:89:d1:d5:c3 (status 0) ApVapId 4 Slot 0
*apfMsConnTask_5: Jan 29 11:57:51.013: 6c:88:14:f5:38:18 apfProcessAssocReq (apf_80211.c:8294) Changing state for mobile 6c:88:14:f5:38:18 on AP b4:14:89:d1:d5:c0 from Associated to Associated
*apfReceiveTask: Jan 29 11:57:51.014: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) State Update from Mobility-Incomplete to Mobility-Complete, mobility role=Local, client state=APF_MS_STATE_ASSOCIATED
*apfReceiveTask: Jan 29 11:57:51.014: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) pemAdvanceState2 5773, Adding TMP rule
*apfReceiveTask: Jan 29 11:57:51.014: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Adding Fast Path rule
  type = Airespace AP - Learn IP address
  on AP b4:14:89:d1:d5:c0, slot 0, interface = 1, QOS = 0
  IPv4 ACL ID = 255, IPv
*apfReceiveTask: Jan 29 11:57:51.014: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) 802.1P = 0, DSCP = 0, TokenID = 15206  Local Bridging Vlan = 480, Local Bridging intf id = 21
*apfReceiveTask: Jan 29 11:57:51.014: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Successfully plumbed mobile rule (IPv4 ACL ID 255, IPv6 ACL ID 255, L2 ACL ID 255)
*pemReceiveTask: Jan 29 11:57:51.014: 6c:88:14:f5:38:18 0.0.0.0 Added NPU entry of type 9, dtlFlags 0x0
*pemReceiveTask: Jan 29 11:57:51.014: 6c:88:14:f5:38:18 Sent an XID frame
*IPv6_Msg_Task: Jan 29 11:57:51.014: 6c:88:14:f5:38:18 Pushing IPv6 Vlan Intf ID 21: fe80:0000:0000:0000:45a0:6c41:35d9:f6a3 , and MAC: 6C:88:14:F5:38:18 , Binding to Data Plane. SUCCESS !! dhcpv6bitmap 0
*IPv6_Msg_Task: Jan 29 11:57:51.015: 6c:88:14:f5:38:18 Link Local address fe80::45a0:6c41:35d9:f6a3 updated to mscb. Not Advancing pem state.Current state: mscb in apfMsMmInitial mobility state and client state APF_MS_STATE_A
*apfMsConnTask_5: Jan 29 11:57:51.721: 6c:88:14:f5:38:18 Association received from mobile on BSSID b4:14:89:d1:d5:c3
*apfMsConnTask_5: Jan 29 11:57:51.721: 6c:88:14:f5:38:18 Global 200 Clients are allowed to AP radio
*apfMsConnTask_5: Jan 29 11:57:51.721: 6c:88:14:f5:38:18 Max Client Trap Threshold: 0  cur: 13
*apfMsConnTask_5: Jan 29 11:57:51.721: 6c:88:14:f5:38:18 Rf profile 600 Clients are allowed to AP wlan
*apfMsConnTask_5: Jan 29 11:57:51.721: 6c:88:14:f5:38:18 override for default ap group, marking intgrp NULL
*apfMsConnTask_5: Jan 29 11:57:51.721: 6c:88:14:f5:38:18 Applying Interface policy on Mobile, role Local. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 480
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 Re-applying interface policy for client
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2219)
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2240)
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 apfApplyWlanPolicy: Apply WLAN Policy over PMIPv6 Client Mobility Type
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 In processSsidIE:4796 setting Central switched to TRUE
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 In processSsidIE:4799 apVapId = 4 and Split Acl Id = 65535
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 Applying site-specific Local Bridging override for station 6c:88:14:f5:38:18 - vapId 4, site 'MeetingRooms', interface 'guests-internet'
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 Applying Local Bridging Interface Policy for station 6c:88:14:f5:38:18 - vlan 480, interface id 21, interface 'guests-internet'
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 override from ap group, removing intf group from mscb
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 Applying site-specific override for station 6c:88:14:f5:38:18 - vapId 4, site 'MeetingRooms', interface 'guests-internet'
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 Applying Interface policy on Mobile, role Local. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 480
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 Re-applying interface policy for client
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2219)
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2240)
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 processSsidIE  statusCode is 0 and status is 0
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 processSsidIE  ssid_done_flag is 0 finish_flag is 0
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 STA - rates (6): 24 36 176 72 96 108 0 0 0 0 0 0 0 0 0 0
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 suppRates  statusCode is 0 and gotSuppRatesElement is 1
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 apfMs1xStateDec
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Change state to START (0) last state DHCP_REQD (7)
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 pemApfAddMobileStation2: APF_MS_PEM_WAIT_L2_AUTH_COMPLETE = 0.
*apfMsConnTask_5: Jan 29 11:57:51.722: 6c:88:14:f5:38:18 0.0.0.0 START (0) Initializing policy
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 START (0) Change state to AUTHCHECK (2) last state START (0)
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 AUTHCHECK (2) Change state to L2AUTHCOMPLETE (4) last state AUTHCHECK (2)
*pemReceiveTask: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 Removed NPU entry.
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 Central switch is TRUE
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 Not Using WMM Compliance code qosCap 00
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 L2AUTHCOMPLETE (4) Plumbed mobile LWAPP rule on AP b4:14:89:d1:d5:c0 vapId 4 apVapId 4 flex-acl-name:
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 L2AUTHCOMPLETE (4) Change state to DHCP_REQD (7) last state L2AUTHCOMPLETE (4)
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) pemApfAddMobileStation2 3451, Adding TMP rule
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Adding Fast Path rule
  type = Airespace AP - Learn IP address
  on AP b4:14:89:d1:d5:c0, slot 0, interface = 1, QOS = 0
  IPv4 ACL ID = 255, IPv
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) 802.1P = 0, DSCP = 0, TokenID = 15206  Local Bridging Vlan = 480, Local Bridging intf id = 21
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Successfully plumbed mobile rule (IPv4 ACL ID 255, IPv6 ACL ID 255, L2 ACL ID 255)
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) pemApfAddMobileStation2 3639, Adding TMP rule
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Replacing Fast Path rule
  type = Airespace AP - Learn IP address
  on AP b4:14:89:d1:d5:c0, slot 0, interface = 1, QOS = 0
  IPv4 ACL ID = 255,
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) 802.1P = 0, DSCP = 0, TokenID = 15206  Local Bridging Vlan = 480, Local Bridging intf id = 21
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Successfully plumbed mobile rule (IPv4 ACL ID 255, IPv6 ACL ID 255, L2 ACL ID 255)
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 apfPemAddUser2 (apf_policy.c:333) Changing state for mobile 6c:88:14:f5:38:18 on AP b4:14:89:d1:d5:c0 from Associated to Associated
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 apfPemAddUser2:session timeout forstation 6c:88:14:f5:38:18 - Session Tout 0, apfMsTimeOut '0' and sessionTimerRunning flag is  0
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 Stopping deletion of Mobile Station: (callerId: 48)
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 Func: apfPemAddUser2, Ms Timeout = 0, Session Timeout = 0
*apfMsConnTask_5: Jan 29 11:57:51.723: 6c:88:14:f5:38:18 Sending Assoc Response to station on BSSID b4:14:89:d1:d5:c3 (status 0) ApVapId 4 Slot 0
*apfMsConnTask_5: Jan 29 11:57:51.724: 6c:88:14:f5:38:18 apfProcessAssocReq (apf_80211.c:8294) Changing state for mobile 6c:88:14:f5:38:18 on AP b4:14:89:d1:d5:c0 from Associated to Associated
*pemReceiveTask: Jan 29 11:57:51.724: 6c:88:14:f5:38:18 0.0.0.0 Added NPU entry of type 9, dtlFlags 0x0
*pemReceiveTask: Jan 29 11:57:51.724: 6c:88:14:f5:38:18 0.0.0.0 Added NPU entry of type 9, dtlFlags 0x0
*apfOrphanSocketTask: Jan 29 11:57:56.416: 6c:88:14:f5:38:18 Orphan Packet from STA - IP 10.10.48.26
*apfOrphanSocketTask: Jan 29 11:57:56.417: 6c:88:14:f5:38:18 Invalid MSCB state, regType=2, Dhcp required!
*apfOrphanSocketTask: Jan 29 11:57:56.417: 6c:88:14:f5:38:18 IPv4 Addr: 10:10:48:26
*DHCP Socket Task: Jan 29 11:58:04.793: 6c:88:14:f5:38:18 DHCP received op BOOTREQUEST (1) (len 308,vlan 501, port 1, encap 0xec03)
*DHCP Socket Task: Jan 29 11:58:04.793: 6c:88:14:f5:38:18 DHCP (encap type 0xec03) mstype 0ff:ff:ff:ff:ff:ff
*DHCP Socket Task: Jan 29 11:58:07.793: 6c:88:14:f5:38:18 DHCP received op BOOTREQUEST (1) (len 308,vlan 501, port 1, encap 0xec03)

*DHCP Socket Task: Jan 29 11:58:07.793: 6c:88:14:f5:38:18 DHCP (encap type 0xec03) mstype 0ff:ff:ff:ff:ff:ff
*SNMPTask: Jan 29 11:58:51.194: 6c:88:14:f5:38:18 Central Switch = TRUE
*SNMPTask: Jan 29 11:58:51.194: 6c:88:14:f5:38:18 Central Switch = TRUE
*SNMPTask: Jan 29 11:58:51.198: 6c:88:14:f5:38:18 Central Switch = TRUE
*SNMPTask: Jan 29 11:58:51.199: 6c:88:14:f5:38:18 Central Switch = TRUE
*DHCP Socket Task: Jan 29 11:59:17.382: 6c:88:14:f5:38:18 DHCP received op BOOTREQUEST (1) (len 308,vlan 501, port 1, encap 0xec03)
*DHCP Socket Task: Jan 29 11:59:17.382: 6c:88:14:f5:38:18 DHCP (encap type 0xec03) mstype 0ff:ff:ff:ff:ff:ff
*DHCP Socket Task: Jan 29 11:59:21.385: 6c:88:14:f5:38:18 DHCP received op BOOTREQUEST (1) (len 308,vlan 501, port 1, encap 0xec03)
*DHCP Socket Task: Jan 29 11:59:21.385: 6c:88:14:f5:38:18 DHCP (encap type 0xec03) mstype 0ff:ff:ff:ff:ff:ff
*apfReceiveTask: Jan 29 11:59:51.725: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) DHCP Policy timeout. Number of DHCP Discover 0, DHCP Request 0 from client
*apfReceiveTask: Jan 29 11:59:51.725: 6c:88:14:f5:38:18 Interface Group was NULL.Number of DHCP Discovery 0 from client
*apfReceiveTask: Jan 29 11:59:51.725: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Pem timed out, Try to delete client in 10 secs.
*apfReceiveTask: Jan 29 11:59:51.725: 6c:88:14:f5:38:18 Scheduling deletion of Mobile Station:  (callerId: 12) in 10 seconds
*osapiBsnTimer: Jan 29 12:00:01.725: 6c:88:14:f5:38:18 apfMsExpireCallback (apf_ms.c:626) Expiring Mobile!
*apfReceiveTask: Jan 29 12:00:01.725: 6c:88:14:f5:38:18 apfMsExpireMobileStation (apf_ms.c:6655) Changing state for mobile 6c:88:14:f5:38:18 on AP b4:14:89:d1:d5:c0 from Associated to Disassociated
*apfReceiveTask: Jan 29 12:00:01.725: 6c:88:14:f5:38:18 Scheduling deletion of Mobile Station:  (callerId: 45) in 10 seconds
*osapiBsnTimer: Jan 29 12:00:11.725: 6c:88:14:f5:38:18 apfMsExpireCallback (apf_ms.c:626) Expiring Mobile!
*apfReceiveTask: Jan 29 12:00:11.726: 6c:88:14:f5:38:18 Sent Deauthenticate to mobile on BSSID b4:14:89:d1:d5:c0 slot 0(caller apf_ms.c:6749)
*apfReceiveTask: Jan 29 12:00:11.726: 6c:88:14:f5:38:18 Setting active key cache index 8 ---> 8
*apfReceiveTask: Jan 29 12:00:11.726: 6c:88:14:f5:38:18 Deleting the PMK cache when de-authenticating the client.
*apfReceiveTask: Jan 29 12:00:11.726: 6c:88:14:f5:38:18 Global PMK Cache deletion failed.
*apfReceiveTask: Jan 29 12:00:11.726: 6c:88:14:f5:38:18 apfMsAssoStateDec
*apfReceiveTask: Jan 29 12:00:11.726: 6c:88:14:f5:38:18 apfMsExpireMobileStation (apf_ms.c:6787) Changing state for mobile 6c:88:14:f5:38:18 on AP b4:14:89:d1:d5:c0 from Disassociated to Idle

Solution

Error *apfReceiveTask: Jan 29 11:59:51.725: 6c:88:14:f5:38:18 0.0.0.0 DHCP_REQD (7) Pem timed out, Try to delete client in 10 secs

Usually means that issue is the client is not doing DHCP. Make sure that the dhcp required checkbox is enabled on the wlan advanced tab.

In case if it already checked and you are still facing this issue, as a workaround, try to uncheck and check it back.

The WLAN advance configuration has an option that requires users to pass DHCP before going into the RUN state (a state where the client will be able to pass traffic through the controller). This option requires the client to do a full or half DHCP request. The main thing the controller is looking from the client is a DHCP request and an ACK coming back from the DHCP server. As long as the client does these steps, the client will pass the DHCP required step and move to the RUN state.

Note

If you want to require all clients to obtain their IP addresses from a DHCP server, check the DHCP Addr. Assignment Required check box. When this feature is enabled, any client with a static IP address is not allowed on the network. The default value is disabled.

More Information

Using the GUI to Configure DHCP

Follow these steps to configure DHCP using the GUI.

Step 1 Follow the instructions in the "Using the GUI to Configure the Management, AP-Manager, Virtual, and Service-Port Interfaces" section on page 3-10 or "Using the GUI to Configure Dynamic Interfaces" section on page 3-16 to configure a primary DHCP server for a management, AP-manager, or dynamic interface that will be assigned to the WLAN.

Note When you want to use the internal DHCP server, you must set the management interface IP address of the controller as the DHCP server IP address.

Step 2 Click WLANs to access the WLANs page.
Step 3 Click the profile name of the WLAN for which you wish to assign an interface. The WLANs > Edit (General) page appears.
Step 4 On the General tab, uncheck the WLAN Status check box and click Apply to disable the WLAN.
Step 5 Re-click the profile name of the WLAN.
Step 6 On the General tab, choose the interface for which you configured a primary DHCP server to be used with this WLAN from the Interface drop-down box.

Step 7 Click the Advanced tab to access the WLANs > Edit (Advanced) page.

Step 8 If you want to define a DHCP server on the WLAN that will override the DHCP server address on the interface assigned to the WLAN, check the DHCP Server Override check box and enter the IP address of the desired DHCP server in the DHCP Server IP Addr edit box. The default value for the check box is disabled.

Note The preferred method for configuring DHCP is to use the primary DHCP address assigned to a particular interface instead of the DHCP server override.
Step 9 If you want to require all clients to obtain their IP addresses from a DHCP server, check the DHCP Addr. Assignment Required check box. When this feature is enabled, any client with a static IP address is not allowed on the network. The default value is disabled.

Step 10 Click Apply to commit your changes.
Step 11 On the General tab, check the WLAN Status check box and click Apply to re-enable the WLAN.
Step 12 Click Save Configuration to save your changes.

Using the CLI to Configure DHCP

Follow these steps to configure DHCP using the CLI.

Step 1 Follow the instructions in the "Using the CLI to Configure the Management, AP-Manager, Virtual, and Service-Port Interfaces" section on page 3-12 or "Using the CLI to Configure Dynamic Interfaces" section on page 3-18 to configure a primary DHCP server for a management, AP-manager, or dynamic interface that will be assigned to the WLAN.

Step 2 To disable the WLAN, enter this command:

config wlan disable wlan-id

Step 3 To specify the interface for which you configured a primary DHCP server to be used with this WLAN, enter this command:

config wlan interface wlan-id interface-name

Step 4 If you want to define a DHCP server on the WLAN that will override the DHCP server address on the interface assigned to the WLAN, enter this command:

config wlan dhcp_server wlan-id dhcp-server-ip-address

Note The preferred method for configuring DHCP is to use the primary DHCP address assigned to a particular interface instead of the DHCP server override. If you enable the override, you can use the show wlan command to verify that the DHCP server has been assigned to the WLAN.
Step 5 To re-enable the WLAN, enter this command:

config wlan enable wlan-id

Reference

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: