Hi there
Seeing strange one over the last few days. We have a teachers iPad that constantly drops the network every few seconds for about 3 or 4 goes and then eventually gives up and just doesn't connect. Turn wifi off and on and same thing happens again.
Same iPad connecting to different AP is stable. Different iPad connecting to same IP is stable.
Seems to be this iPad on this AP that is the issue.
Done so far : Set Logging Level debugging use-debug and watched the logs.
The first time it did this I got an error message that deauth was due to Client Match
Feb 17 16:15:56 :522008: <NOTI> |authmgr| User Authentication Successful: username=kw MAC=84:85:06:cf:9b:e4 IP=10.1.191.22 role=authenticated VLAN=133 AP=JNR_L2_Base1 SSID=Wireless@TTS AAA profile=TTS@Clearpass-aaa_prof auth method=802.1x auth server=Clearpass-Server
Feb 17 16:15:56 :522053: <DBUG> |authmgr| PMK Cache getting updated for 84:85:06:cf:9b:e4, (def, cur, vhow) = (133, 133, 16) with vlan=133 vlanhow=16 essid=Wireless@TTS role=authenticated rhow=7
Feb 17 16:15:56 :522026: <INFO> |authmgr| MAC=84:85:06:cf:9b:e4 IP=0.0.0.0 User miss: ingress=0x10156, VLAN=133 flags=0x48
Feb 17 16:16:17 :501105: <NOTI> |stm| Deauth from sta: 84:85:06:cf:9b:e4: AP 10.1.120.157-24:de:c6:d1:9d:81-JNR_L2_Base1 Reason Client Match
Feb 17 16:16:17 :522234: <DBUG> |authmgr| Setting idle timer for user 84:85:06:cf:9b:e4 to 300 seconds (idle timeout: 300 ageout: 0).
Feb 17 16:16:17 :501000: <DBUG> |stm| Station 84:85:06:cf:9b:e4: Clearing state
Turned wireless off and on and got the same deauth - but each time for reason 255 - could not get it to say Client Match again - 10 times went through this and each time said = reason 255
Feb 17 16:16:35 :522254: <DBUG> |authmgr| VDR - mac 84:85:06:cf:9b:e4 rolename logon fwdmode 0 derivation_type Initial Role Contained vp not present.
Feb 17 16:16:35 :522258: <DBUG> |authmgr| "VDR - Add to history of user user 84:85:06:cf:9b:e4 vlan 0 derivation_type Reset Role Based VLANs index 16.
Feb 17 16:16:35 :524124: <DBUG> |authmgr| dot1x_supplicant_up(): MAC:84:85:06:cf:9b:e4, pmkid_present:False, pmkid:N/A
Feb 17 16:16:35 :522243: <DBUG> |authmgr| MAC=84:85:06:cf:9b:e4 Station Updated Update MMS: BSSID=24:de:c6:d1:9d:89 ESSID=Wireless@TTS VLAN=133 AP-name=JNR_L2_Base1
Feb 17 16:16:36 :501114: <NOTI> |stm| Deauth from sta: 84:85:06:cf:9b:e4: AP 10.1.120.157-24:de:c6:d1:9d:89-JNR_L2_Base1 Reason 255
SO I thought - OK - Client Match makes sense if there is an issue so looked at Airwave it had a warning that the AP had too many clients (30 clients - as there was a set of iPads in the class in use).
Now moving the teacher iPad makes sense if ARM and client match are doing there job but what doesn't make sense is:
- If the iPad is de-authed - from Base1 why did it not associate to 1 of the the other 7 AP's in the nearby bases - which are easily within range
- Why was it only de-authing this iPad and not any others (there were 30 in the room after all).
- When I moved the class iPads to another room powered down the AP clearing all associations. I cycled the wireless on the Ipad and it joined the AP in Base 2 next door and stayed stable...seen here:
Feb 17 16:51:10 :522260: <DBUG> |authmgr| "VDR - Cur VLAN updated 84:85:06:cf:9b:e4 mob 0 inform 1 remote 0 wired 0 defvlan 133 exportedvlan 0 curvlan 133.
Feb 17 16:51:10 :522029: <INFO> |authmgr| MAC=84:85:06:cf:9b:e4 Station authenticate: method=802.1x, role=authenticated/authenticated//logon, VLAN=133/133, Derivation=7/16, Value Pair=1
Feb 17 16:51:10 :522008: <NOTI> |authmgr| User Authentication Successful: username=kw MAC=84:85:06:cf:9b:e4 IP=10.1.191.22 role=authenticated VLAN=133 AP=JNR_L2_Base2 SSID=Wireless@TTS AAA profile=TTS@Clearpass-aaa_prof auth method=802.1x auth server=Clearpass-Server
Feb 17 16:51:10 :522053: <DBUG> |authmgr| PMK Cache getting updated for 84:85:06:cf:9b:e4, (def, cur, vhow) = (133, 133, 16) with vlan=133 vlanhow=16 essid=Wireless@TTS role=authenticated rhow=7
Feb 17 16:51:11 :522026: <INFO> |authmgr| MAC=84:85:06:cf:9b:e4 IP=0.0.0.0 User miss: ingress=0x10051, VLAN=133 flags=0x48
- When I powered back up the AP in Base 1 and cycled the iPad it rejoined this troublesome AP in Base 1 and seemed stable (for the 5 minutes before I headed home for the day).
- My gut feel is this will come back tomorrow as it has for the past few days...
So big picture remains - any idea why this iPad is deauthing and why it wouldn't auto join the next nearest AP?
Note - the remainder of the 7 AP's at this year level only had 1 client each on them at the time.
Wally