Hello community!
We are having a weird issue with an "open" (no auth/ encrypt) network in split-tunnel mode.
Basically, clients get deauthenticated randomly and sometimes the same client could be connecting and getting deauth continuously for like almost an hour.
Our infrastructure consists of a 7210 (Aos 8.4.0.1) and a bunch of 365 RAPs.
There are 3 RAPs per remote site and we have reports of all sites having the same issue.
Role for users are simple:
- DHCP to the controller
- Everything else route src-nat
This is the trail-info for one of the clients getting deauth. (it's always the same message "Denied; Ageout")
Enabled user-debug for some clients and this is the result after some disconnections (logs attached below).
Pay special attention to the "age 1000 deauth_reason 31" lines because they appear every time we got a disconnection.
We even changed that "age 1000" timeout value from the ssid to 3600 but the disconnections continued. Just this time logs shows "age 3600" instead of "1000".
Some things we tried so far:
- If we go with tunnel mode the issue can't be reproduced (it seems that it only happens with split-tunnel)
- Lab with a 7005 controller (factory default) and got the same behavior.
- Upgrade to 8.4.0.2 (problem persists)
- Downgrade to 8.3.0.6 and 8.2.2.5 (problem persists)
- Used a 205 RAP instead of the 365 (problem persists)
- Keeping just one RAP per site to mitigate "roaming problems" (problem persists)
- Disabled Client match (problem persists)
- Tuned up and down Tx power (problem persists)
- Created from scratch the AP group, ssid and profiles (problem persists)
We are getting pretty much out of things to try :(
Any help would be much appreciated.
Thanks in advance!