Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Could you please advise me in Wireless ?

How I solve  a problem in this case ? and Log detaill as below

*Oct 13 14:05:56.936: %DOT1X-3-WPA_SEND_STATE_ERR: 1x_kxsm.c:1249 Unable to send EAPOL-key msg - invalid WPA state (0) - client 64:b9:e8:8a:2c:8a

Thanks in advance

2 REPLIES
Cisco Employee

Re: Could you please advise me in Wireless ?

Hi Peeravin,

You can obtain additional info on the error message from reference link:

http://www.cisco.com/en/US/docs/wireless/controller/message/guide/msgs4.html#wp1000139

Explanation Client authentication failed because the session was not in the correct state when attempting to send an EAPOL-key message.

-Is this related to specific client or all clients?

Please can you verify for latest client drivers/firmware

During problem replication ,You can also debug for a specific client from WLC cli:debug client

http://www.cisco.com/en/US/products/hw/wireless/ps430/products_tech_note09186a008091b08b.shtml

Also what is the AAA server in use, do you have any auth failure reports on AAA server logs?

Regards,

Alex

New Member

Re: Could you please advise me in Wireless ?

Hi.

We have the same issue.

This is isolated incidents (we have approx 2000 users). The vast majority is unaffected. This one particular user however has is struggeling with this problem several times a day. SOmetimes the connection comes throug, sometimes not. SOmetimes the user gets dis-associated after 20 minutes or less.

Model: Dell Latitude E5400
NV card: Intel WiFi Link 5100 AGN
OS: Windows Vista Home Basic
Driverversion: 13.3.0.24 (14. Juli 2010)

May 23 12:42:29.019: %DOT1X-3-WPA_SEND_STATE_ERR: 1x_kxsm.c:1249 Unable to send EAPOL-key msg - invalid WPA state (0) - client 00:22:fb:d0:f0:f8

Checked the logs in our RADIUS.The authentication attempt that failed is not in radius logs, but another successfull attempt approx 25 seconds after, is in the logs.

May 23 13:42:54 rad freeradius[20960]: Login OK: [xxxxx] (from client HIST_WLC1 port 29 cli 00-22-fb-d0-f0-f8 via TLS tunnel)
May 23 13:42:54 rad freeradius[20960]: Login OK: [xxxxx] (from client HIST_WLC1 port 29 cli 00-22-fb-d0-f0-f8)

Don't have debug-log from this user yet.

Any tips or hints?

-Erik.

1840
Views
9
Helpful
2
Replies
CreatePlease to create content