AOS8.4.0.4 cluster
I was doing some troubleshooting for a user today and noticed that if I look in the global-user-table on the MM and filter for his username he has hundreds of entries (so many that I cancelled the search before all of the entries had been listed) ("show global list | inc <username>"). However if I run "show global list name <username>" I see a much more sane output (1 entry per MAC as you'd expect).
He is connecting to a bridged dot1x SSID.
If I do the same test on my own username in both cases the output is pretty normal looking.
So I'm wondering if the fact that he has hundreds of entries is something to worry about? Is it an artefact of being connected to a bridged dot1x SSID? (Note that I am not connected to the same SSID, I am connected to a tunnelled dot1x SSID). What prompts an entry into the user-table?
Thanks
Guy
... as an addendum to this post, in the AP debug driver-log I see some entries for one of his devices:
[7369184.346211] asap_user_add_entry: 36 callbacks suppressed
[7369184.346239] asap_user_add_entry[1004]: User(ac:bc:32:7d:94:23 0) reach Max number
[7369184.567076] asap_user_add_entry[1004]: User(ac:bc:32:7d:94:23 0) reach Max number
[7369184.734326] asap_user_add_entry[1004]: User(ac:bc:32:7d:94:23 0) reach Max number
[7369185.029109] asap_user_add_entry[1004]: User(ac:bc:32:7d:94:23 0) reach Max number
[7369185.375181] asap_user_add_entry[1004]: User(ac:bc:32:7d:94:23 0) reach Max number
There are repeated similar entries for this device. There aren't similar entries for other devices. One thing that is unique about this particular device is that it is a laptop running 2 VMs (in fact it is this device that prompted the troubleshooting - the symptoms are that only one of the VMs ever has connectivity, one always fails to connect though it is 'seen' on the network (ie his local switches and router (this is an enterprise environment)). It isn't always the same VM. The VMs are set to bridging mode. I bumped up the "Max IPv4 for wireless user" limit on his AAA profile to 4 in case he was hitting into the previous limit of 2 but this hasn't changed anything.