cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1737
Views
0
Helpful
7
Replies

7925G - Failled Authentication during roaming

Wellington L
Level 1
Level 1

Hello,

I have a environment with 90 Access Points and 2 controllers working with the same configuration.

When i connect 7925G i can make calls when connected in one Access Point and when i realize the roaming to another i have problems and in my screen shows Failled Authentication and i lost my call during few seconds and after i can talk again. It happens all places in all Access Points.

My SSID was configured with WPA2+AES+802.1X+CCKM and i configured it with the best pratices.

I tried with WPA+TKIP+802.1X+CCKM but i had the same result.

My 7925G is using the FW CP7925G-1.4.1SR1 and my controllers are in 7.2.103.0

Thank You.

1 Accepted Solution

Accepted Solutions

Wellington,

Did you by any chance enable Flexconnect? If so, I would suggest that you bunch the APs into the Flexconnect group. This caches the client's PMK and hence there is no need for authentication during roaming.

View solution in original post

7 Replies 7

Stephen Rodriguez
Cisco Employee
Cisco Employee

try using just WPA/TKIP/CCKM, and see how that works.

Prior to the install, was a voice site survey done? 

HTH,
Steve

-----------------------------------------
Please remember to rate useful posts, and mark questions as answered

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

A voice site survey was done.

I did the configurations and i had the same problems, when i'm connected in one Access Point i can call normally and when i roam to another the failled authentication appears and the 7925G authenticates again.

migilles
Cisco Employee
Cisco Employee

Upgrade the 792x phones to 1.4.3.4 and WLC to 7.2.110.0.

Also may want to look at the CCKM timestamp deviation config.

But 792x firmware 1.4(2) should be a big help.

Sent from Cisco Technical Support iPhone App

Wellington,

Did you by any chance enable Flexconnect? If so, I would suggest that you bunch the APs into the Flexconnect group. This caches the client's PMK and hence there is no need for authentication during roaming.

Osita,

I realized this configuration and the phones are working very well now.

Thanks.

Migilles,

I made the upgrade too for the last version and my environment is working very well.

I have 90 Access Points and i can't put these in the same FlexConnect Group, so i will put these segmenting by building.

Thanks.

migilles


I will try the upgrade for the last version available in both.

Osita

I will try that too.

My Access Points are working with Flex Connect Central Switching in the voice SSID and i have two 7500 WLCs.

I have too a SSID for guest users and another to users from company who authenticate in Radius.

I'm doing a pilot in the central site and after put in the branches, because in the branches i have another SSID with Local Switching.

I configured AP Groups but not FlexConnect Groups.

I will try to put my Access Points in the central site on the same FlexConnect Group.

Thanks.

It's nice to know your problem is sorted. Others with similar problems will learn from the posts.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: