Occasional Contributor I

Weird client deauth on an open split-tunnel network

Hello community!

We are having a weird issue with an "open" (no auth/ encrypt) network in split-tunnel mode.


Basically, clients get deauthenticated randomly and sometimes the same client could be connecting and getting deauth continuously for like almost an hour.


Our infrastructure consists of a 7210 (Aos and a bunch of 365 RAPs.

There are 3 RAPs per remote site and we have reports of all sites having the same issue.

Role for users are simple:

  • DHCP to the controller
  • Everything else route src-nat


This is the trail-info for one of the clients getting deauth. (it's always the same message "Denied; Ageout")



Enabled user-debug for some clients and this is the result after some disconnections (logs attached below).

Pay special attention to the "age 1000 deauth_reason 31" lines because they appear every time we got a disconnection.

We even changed that "age 1000" timeout value from the ssid to 3600 but the disconnections continued. Just this time logs shows "age 3600" instead of "1000". 


Some things we tried so far:

  • If we go with tunnel mode the issue can't be reproduced (it seems that it only happens with split-tunnel)
  • Lab with a 7005 controller (factory default) and got the same behavior.
  • Upgrade to (problem persists)
  • Downgrade to and (problem persists)
  • Used a 205 RAP instead of the 365 (problem persists)
  • Keeping just one RAP per site to mitigate "roaming problems"  (problem persists)
  • Disabled Client match (problem persists)
  • Tuned up and down Tx power (problem persists)
  • Created from scratch the AP group, ssid and profiles (problem persists)

We are getting pretty much out of things to try :(

Any help would be much appreciated.

Thanks in advance!

Occasional Contributor I

Re: Weird client deauth on an open split-tunnel network

So, after multiple remote sessions with the TAC we finally got our solution for this problem.


It was indeed some "bug" in the controller. 

Bug ID is: AOS-187171



TAC said the patch would be released with but it was actually added on

TAC also said they'll add this to newer releases but I don't know when that will be available. 


After downgrading the controller to the mentioned version all was good, no random disconnections were reported.


Hope this help someone with the same symptom :D



Search Airheads
Showing results for 
Search instead for 
Did you mean: