Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Mac Computers w/ Radius


I'm receiving the following syslog messages on my WLC (WiSM2): " *dot1xMsgTask: Dec 04 11:51:53.944: %DOT1X-3-MAX_EAP_RETRIES:

1x_auth_pae.c:3136 Max EAP identity request retries (3) exceeded for XX:XX:XX:XX:XX " and it's for all of my Mac OSX users. I'm using Windows Server 2008 R2 as a Radius server and PEAP for auth. Any ideas ? Thanks!!

  • Security and Network Management

EAP-Identity-Request Max

  • EAP-Identity-Request Max Retries:

    The Max Retries value is the number of times the WLC will send the Identity Request to the client, before removing its entry from the MSCB. Once the Max Retries is reached, the WLC sends a de-authentication frame to the client, forcing them to restart the EAP process. Available value is 1 to 20.

    **The Max Retries works with the Identity Timeout. If you have your Identity Timeout set to 120, and your Max Retries to 20 how long does it takes 2400 (or 120 * 20). This means it would take 40 minutes for the client to be removed, and to start the EAP process over again. If you set the Identity Timeout to 5, with a Max Retries value of 12, then it will take 60 (or 5 * 12).

    Recommendations for the Max Retries is 12.


Please refer the link :https: