Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Clients keep deauthenticating from autonomous AP 1602E

Hi Guys,

I've got 5 autonomous APs 1602E deployed and i'm testing them now, however, I've met one problem: the clients keep deauthenticating from the AP, clients can just connect to the first AP the the other 4 keeps showing the logs as bellows:

Nov 27 15:51:02.135: %DOT11-6-ASSOC: Interface Dot11Radio0, Station   e4ce.8fb9.27e0 Reassociated KEY_MGMT[WPAv2 PSK]

Nov 27 15:51:02.815: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station e4ce.8fb9.27e0 Reason: Previous authentication no longer valid

Nov 27 15:51:04.695: %DOT11-6-ASSOC: Interface Dot11Radio0, Station   e4ce.8fb9.27e0 Associated KEY_MGMT[WPAv2 PSK]

Nov 27 15:51:04.815: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station e4ce.8fb9.27e0 Reason: Previous authentication no longer valid

Nov 27 15:51:06.343: %DOT11-6-ASSOC: Interface Dot11Radio0, Station   e4ce.8fb9.27e0 Associated KEY_MGMT[WPAv2 PSK]

Nov 27 15:51:06.815: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station e4ce.8fb9.27e0 Reason: Previous authentication no longer valid

Nov 27 15:51:08.447: %DOT11-6-ASSOC: Interface Dot11Radio0, Station   e4ce.8fb9.27e0 Associated KEY_MGMT[WPAv2 PSK]

Nov 27 15:51:08.815: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station e4ce.8fb9.27e0 Reason: Previous authentication no longer valid

Nov 27 15:51:10.415: %DOT11-6-ASSOC: Interface Dot11Radio0, Station   e4ce.8fb9.27e0 Associated KEY_MGMT[WPAv2 PSK]

Nov 27 15:51:10.815: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station e4ce.8fb9.27e0 Reason: Previous authentication no longer valid

Nov 27 15:51:12.495: %DOT11-6-ASSOC: Interface Dot11Radio0, Station   e4ce.8fb9.27e0 Associated KEY_MGMT[WPAv2 PSK]

Nov 27 15:51:12.815: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station e4ce.8fb9.27e0 Reason: Previous authentication no longer valid

Nov 27 15:51:14.594: %DOT11-6-ASSOC: Interface Dot11Radio0, Station   e4ce.8fb9.27e0 Associated KEY_MGMT[WPAv2 PSK]

Nov 27 15:51:14.814: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station e4ce.8fb9.27e0 Reason: Previous authentication no longer valid

Nov 27 15:51:16.662: %DOT11-6-ASSOC: Interface Dot11Radio0, Station   e4ce.8fb9.27e0 Associated KEY_MGMT[WPAv2 PSK]

Nov 27 15:51:16.814: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station e4ce.8fb9.27e0 Reason: Previous authentication no longer valid

It really troubles me a lot, here is my configuration and show version info of the AP:

SIAS-PD-C1602E-01#

SIAS-PD-C1602E-01#sh run

Building configuration...

Current configuration : 2243 bytes

!

! Last configuration change at 02:00:42 UTC Mon Mar 1 1993

version 15.2

no service pad

service timestamps debug datetime msec

service timestamps log datetime msec

service password-encryption

!

hostname SIAS-PD-C1602E-01

!

!

logging rate-limit console 9

enable secret 5 $1$P/z5$V9aL2cCWi7faKCoOyqdF7/

!

no aaa new-model

ip cef

!

!

!

dot11 syslog

dot11 vlan-name Wireless-2GHz vlan 50

!

dot11 ssid SIAS-AP-2GHz

   vlan 50

   authentication open

   authentication key-management wpa version 2

   guest-mode

   wpa-psk ascii 7 115A495107040C5E56797D

!

!

dot11 wpa handshake timeout 2000

crypto pki token default removal timeout 0

!

!

username Cisco privilege 15 password 7 123A0C041104

!

!

bridge irb

!

!

!

interface Dot11Radio0

no ip address

!       

encryption vlan 50 mode ciphers aes-ccm

!

ssid SIAS-AP-2GHz

!

antenna gain 0

stbc

beamform ofdm

station-role root

no dot11 extension aironet

!

interface Dot11Radio0.50

description For Wireless LAN 2GHz User

encapsulation dot1Q 50 native

bridge-group 1

bridge-group 1 subscriber-loop-control

bridge-group 1 spanning-disabled

bridge-group 1 block-unknown-source

no bridge-group 1 source-learning

no bridge-group 1 unicast-flooding

!

interface Dot11Radio1

no ip address

shutdown

!

encryption vlan 60 mode ciphers aes-ccm

antenna gain 4

stbc

station-role root

bridge-group 1

bridge-group 1 subscriber-loop-control

bridge-group 1 spanning-disabled

bridge-group 1 block-unknown-source

no bridge-group 1 source-learning

no bridge-group 1 unicast-flooding

!

interface GigabitEthernet0

description Ge int to SW2960SPOE-01

no ip address

duplex auto

speed auto

!

interface GigabitEthernet0.50

description 2GHz Wireless User

encapsulation dot1Q 50 native

bridge-group 1

bridge-group 1 spanning-disabled

no bridge-group 1 source-learning

!

interface BVI1

ip address 10.169.20.1 255.255.255.0

!

ip default-gateway 10.169.20.254

ip forward-protocol nd

ip http server

no ip http secure-server

ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag

ip route 0.0.0.0 0.0.0.0 10.169.20.254

!

bridge 1 route ip

!

!

!

line con 0

password 7 096F471A1A0A

line vty 0 4

exec-timeout 5 0

password 7 062506324F41

login

transport input all

!

end

SIAS-PD-C1602E-01#  

SIAS-PD-C1602E-01#show version

Cisco IOS Software, C1600 Software (AP1G2-K9W7-M), Version 15.2(2)JB, RELEASE SOFTWARE (fc1)

Technical Support: http://www.cisco.com/techsupport

Copyright (c) 1986-2012 by Cisco Systems, Inc.

Compiled Tue 11-Dec-12 04:30 by prod_rel_team

ROM: Bootstrap program is C1600 boot loader

BOOTLDR: C1600 Boot Loader (AP1G2-BOOT-M) LoaderVersion 15.2(2)JAX, RELEASE SOFTWARE (fc1)

SIAS-PD-C1602E-01 uptime is 2 hours, 21 minutes

System returned to ROM by power-on

System image file is "flash:/ap1g2-k9w7-mx.152-2.JB/ap1g2-k9w7-mx.152-2.JB"

Last reload reason:

This product contains cryptographic features and is subject to United

States and local country laws governing import, export, transfer and

use. Delivery of Cisco cryptographic products does not imply

third-party authority to import, export, distribute or use encryption.

Importers, exporters, distributors and users are responsible for

compliance with U.S. and local country laws. By using this product you

agree to comply with applicable laws and regulations. If you are unable

to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:

http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to

export@cisco.com.

cisco AIR-SAP1602E-C-K9    (PowerPC) processor (revision B0) with 98294K/32768K bytes of memory.

Processor board ID FGL1726X71M

PowerPC CPU at 533Mhz, revision number 0x2151

Last reset from power-on

1 Gigabit Ethernet interface

2 802.11 Radios

32K bytes of flash-simulated non-volatile configuration memory.

Base ethernet MAC Address: F8:72:EA:7C:A0:2B

Part Number                          : 73-14508-04

PCA Assembly Number                  : 000-00000-00

PCA Revision Number                  :

PCB Serial Number                    : FOC17227R3C

Top Assembly Part Number             : 800-38553-01

Top Assembly Serial Number           : FGL1726X71M

Top Revision Number                  : A0

Product/Model Number                 : AIR-SAP1602E-C-K9  

Configuration register is 0xF

SIAS-PD-C1602E-01#

Can anybody help me with that? THX!!

Savi

1 ACCEPTED SOLUTION

Accepted Solutions
VIP Purple

Clients keep deauthenticating from autonomous AP 1602E

Hi Savi,

High error counters on radio interfaces on the client, the access point or bridge indicate the effects of RF interference.

Certain clients using WPA/WPA2 key management and power save can take many attempts to authenticate or, in some cases, fail to authenticate. Any SSID that is defined to use authentication key-management WPA, together with clients using power save mode and authenticating using WPA/WPA2, can experience this problem.

so Try this command and check it.

dot11 wpa handshake timeout 2000

If still not works then please identify your RF interference.

Regards

Dont forget to rate hlpful post.

5 REPLIES
VIP Purple

Clients keep deauthenticating from autonomous AP 1602E

HI Savi,

First these types error occurs when u have singnal problem

2nd: please disable aironet extension by using this command:

Under the dot11radio interface you should enter;

'no dot11 extension aironet' command.This command works unless the radio interface is in bridge or wgb mode.

Regards

Dont forget to rate hlpful post.

New Member

Clients keep deauthenticating from autonomous AP 1602E

Hi Sandeep,

Thanks for your reply.

I just stand under the AP, the signal seems good and i've already tried the "no dot11 extension aironet" as i posted above. Howevere, the situation does not get better with both iphone and samsung.

Savi

VIP Purple

Clients keep deauthenticating from autonomous AP 1602E

Hi Savi,

High error counters on radio interfaces on the client, the access point or bridge indicate the effects of RF interference.

Certain clients using WPA/WPA2 key management and power save can take many attempts to authenticate or, in some cases, fail to authenticate. Any SSID that is defined to use authentication key-management WPA, together with clients using power save mode and authenticating using WPA/WPA2, can experience this problem.

so Try this command and check it.

dot11 wpa handshake timeout 2000

If still not works then please identify your RF interference.

Regards

Dont forget to rate hlpful post.

New Member

Clients keep deauthenticating from autonomous AP 1602E

Hi Sandeep,

I think the error has little to do with the power save because phones can connect to the AP1 succfully but cannot connect to any of the other APs. After rebooting all of the APs, phones can connect to AP5 if AP5 boots up first. And i have already tried the "dot11 wpa handshake timeout 2000" but no use. I'm wondering if the 5 APs will interfere each other themselves.

Regards,

Savi

New Member

Clients keep deauthenticating from autonomous AP 1602E

Update here: I just restarted the AP several times and then everything goes fine... So i think i should contact the TAC for the support.

997
Views
6
Helpful
5
Replies