RE: Cisco WLC Stable code in 8.5 train

2020-06-26 Thread Bryn Jones
We have been running 8.5.161.0 for the last 30 days without incident.

We are in the same situation as you with regards to the 3500/3600 models 
restricting us going any higher.

Regards
]

Bryn

Bryn Jones
IT Technical Lead
University of Leeds (UK)
@home

From: Tariq Adnan
Sent: 26 June 2020 06:30
To: 
WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: [WIRELESS-LAN] Cisco WLC Stable code in 8.5 train

Hello everyone,

We are running code 8.5.135.0 on one of our WLC 8540 pair. We can’t go past 8.5 
because of presence of 3500 and 3600 model Aps which are not supported beyond 
code 8.5.

What code you are running in 8.5 train and how satisfied you are with it?

Is anyone running code 8.5.161.0 recommended by Cisco TAC? How stable is it? 
Have you encountered any major issues in your environment?

Has anyone tried 8.5.16.4 (escalation code)?

Thanks in advance for your responses 

-
Cheers,
Tariq

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


RE: Cisco WLC Stable code in 8.5 train

2020-06-26 Thread Scharloo, Gertjan
Hi all,

 

We have some serious issues with 8.5.161.x . We are now trying 8.5.161.5 )

 

Zoom / Team / Skype4Business customers are complaining . We see Drops on our 
Access-switch (port) <-> Access-Points 2802

 

packet drops could be explained by CSCvq90572 Receive throughput degrades for 
2800/3800/4800/1560 - AP fails to send block ACKs

 

I think this bug is not solved yet and is present in all version of 8.5.16x

 

8.5.161.5 

 

…..

CSCvq99108 Cisco 3700 AP series reloads unexpectedly due to reason 44 

 

8.5.161.4 

…..

CSCvp69474 Access point reloads unexpectedly generating capwapd core dumps 

CSCvq90572 Receive throughput degrades for 2800/3800/4800/1560 - AP fails to 
send block ACKs 

CSCvo33808 Cisco 2802,3802,4800,1562 AP reloads unexpectedly with radio 
firmware crash 

CSCvp06909 DOT11-2-RADIO_FAILED, Not Beaconing for too long, 
get_vap_mcast_q_len: invalid interface 

CSCvt53819 CPU increases to 90+% with hight volume traffic. 

CSCvo10708 Cisco 2800, 3800 APs exhibit choppiness with the Vocera client 
during the multicast voice call 

CSCvp54103 IOS APs reloads unexpectedly with 'Unexpected exception to CPU' in 
logs 

CSCvq76143 Cisco 2800 AP reloads unexpectedly on Sxpd process 

CSCvs38511 5508 silent crash 

CSCvs41893 3702 AP running 8.5.151.0 release software reloads unexpectedly 

….

 

Etc etc…

 

 

ICT Services

Netwerkbeheer – draadloos

 

Gertjan Scharloo

ICT consultant

_

 

Universiteit van Amsterdam | Hogeschool van Amsterdam

 

Leeuwenburg | kamer A10.20

Weesperzijde 190 | 1097 DZ Amsterdam

Tel: +31(0)20 525 4885

Mobiel: +31(0) 61013-5880

  www.uva.nl

uva.nl/profile/g.scharloo

  https://time.is/nl/CET 

 Je kunt mij ook bereiken via Skype for Business 

at https://www.educause.edu/community 

  


**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


smime.p7s
Description: S/MIME cryptographic signature


RE: Cisco WLC Stable code in 8.5 train

2020-06-26 Thread Tariq Adnan
Thanks Bryn for the reply.

Just curious, did you run the WLAN Poller before upgrade and were there any Aps 
identified having flash corruption issue?


-
Cheers,

Kind regards,
Tariq Adnan  |  Senior Network Engineer
ICT, Campus Network Services

THE UNIVERSITY OF SYDNEY
316 Abercrombie Street, (G17) | The University of Sydney | NSW | 2006
T +61 2 8627 7885 |  M +61 478 492 080
E tariq.ad...@sydney.edu.au  |  W 
http://sydney.edu.au

From: The EDUCAUSE Wireless Issues Community Group Listserv 
 On Behalf Of Bryn Jones
Sent: Friday, 26 June 2020 6:39 PM
To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: Re: [WIRELESS-LAN] Cisco WLC Stable code in 8.5 train

We have been running 8.5.161.0 for the last 30 days without incident.

We are in the same situation as you with regards to the 3500/3600 models 
restricting us going any higher.

Regards
]

Bryn

Bryn Jones
IT Technical Lead
University of Leeds (UK)
@home

From: Tariq Adnan
Sent: 26 June 2020 06:30
To: 
WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: [WIRELESS-LAN] Cisco WLC Stable code in 8.5 train

Hello everyone,

We are running code 8.5.135.0 on one of our WLC 8540 pair. We can’t go past 8.5 
because of presence of 3500 and 3600 model Aps which are not supported beyond 
code 8.5.

What code you are running in 8.5 train and how satisfied you are with it?

Is anyone running code 8.5.161.0 recommended by Cisco TAC? How stable is it? 
Have you encountered any major issues in your environment?

Has anyone tried 8.5.16.4 (escalation code)?

Thanks in advance for your responses 

-
Cheers,
Tariq

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community


**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


RE: Cisco WLC Stable code in 8.5 train

2020-06-26 Thread Sullivan, Don
We are running 8.5.161.0 and have experienced no issues. We did not run the 
WLAN poller before the upgrade.

Don Sullivan
Network Administrator
Technology Services

205-726-2111 | office
dsulli...@samford.edu
LinkedIn
www.samford.edu
800 Lakeshore Drive
Birmingham, AL 
35229

[Samford Samford University Logo]

From: The EDUCAUSE Wireless Issues Community Group Listserv 
 On Behalf Of Tariq Adnan
Sent: Friday, June 26, 2020 05:46
To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: [EXTERNAL]Re: [WIRELESS-LAN] Cisco WLC Stable code in 8.5 train

Thanks Bryn for the reply.

Just curious, did you run the WLAN Poller before upgrade and were there any Aps 
identified having flash corruption issue?


-
Cheers,

Kind regards,
Tariq Adnan  |  Senior Network Engineer
ICT, Campus Network Services

THE UNIVERSITY OF SYDNEY
316 Abercrombie Street, (G17) | The University of Sydney | NSW | 2006
T +61 2 8627 7885 |  M +61 478 492 080
E tariq.ad...@sydney.edu.au  |  W 
http://sydney.edu.au

From: The EDUCAUSE Wireless Issues Community Group Listserv 
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>> 
On Behalf Of Bryn Jones
Sent: Friday, 26 June 2020 6:39 PM
To: 
WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: Re: [WIRELESS-LAN] Cisco WLC Stable code in 8.5 train

We have been running 8.5.161.0 for the last 30 days without incident.

We are in the same situation as you with regards to the 3500/3600 models 
restricting us going any higher.

Regards
]

Bryn

Bryn Jones
IT Technical Lead
University of Leeds (UK)
@home

From: Tariq Adnan
Sent: 26 June 2020 06:30
To: 
WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: [WIRELESS-LAN] Cisco WLC Stable code in 8.5 train

Hello everyone,

We are running code 8.5.135.0 on one of our WLC 8540 pair. We can’t go past 8.5 
because of presence of 3500 and 3600 model Aps which are not supported beyond 
code 8.5.

What code you are running in 8.5 train and how satisfied you are with it?

Is anyone running code 8.5.161.0 recommended by Cisco TAC? How stable is it? 
Have you encountered any major issues in your environment?

Has anyone tried 8.5.16.4 (escalation code)?

Thanks in advance for your responses 

-
Cheers,
Tariq

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community


**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 

RE: Cisco WLC Stable code in 8.5 train

2020-06-26 Thread Kushner, Jeff
We had to upgrade to 8.5.161.4 due to issues we experienced with the 8.5.161.0. 
We had a problem where an AP would allow clients to associate but they would 
not pass traffic. The new code, as recommended by TAC appears to have fixed the 
issue, we have been running it for 36 days. But we won’t know for sure until we 
get our normal client levels back with the return of students to campus.

Jeff

From: The EDUCAUSE Wireless Issues Community Group Listserv 
 On Behalf Of Tariq Adnan
Sent: Friday, June 26, 2020 1:30 AM
To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: [WIRELESS-LAN] Cisco WLC Stable code in 8.5 train

*Message sent from a system outside of UConn.*

Hello everyone,

We are running code 8.5.135.0 on one of our WLC 8540 pair. We can’t go past 8.5 
because of presence of 3500 and 3600 model Aps which are not supported beyond 
code 8.5.

What code you are running in 8.5 train and how satisfied you are with it?

Is anyone running code 8.5.161.0 recommended by Cisco TAC? How stable is it? 
Have you encountered any major issues in your environment?

Has anyone tried 8.5.16.4 (escalation code)?

Thanks in advance for your responses 

-
Cheers,
Tariq

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


RE: WLC 8.10.121 Deferred

2020-06-26 Thread Tariq Adnan
Hello Dennis,

You are hitting a bug 
CSCvu24770:


  1.  Some Android 10 devices having issues connecting to wireless network
 *   Some devices from Nokia, Sony and Xiaomi running Android 10 and having 
specific Qualcomm chipsets having issues
 *   The issue is due to a firmware bug in some Qualcomm chipsets.

i. Qaulcomm is fixing 
it per device model with new security patches (Mi10 received it with April 2020 
security 
Patch).



-
Cheers,

Kind regards,
Tariq Adnan  |  Senior Network Engineer

From: The EDUCAUSE Wireless Issues Community Group Listserv 
 On Behalf Of Dennis Xu
Sent: Saturday, 27 June 2020 2:45 AM
To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

We have upgraded to 8.10.121.0 for one month. We have seen some devices not 
able to connect. When they run into this issue, we don’t see any association 
requests from the devices. There are something in the beacon which are not 
liked by the devices so they do not want to join. Not a lot of devices 
affected, mainly from Android 10 devices(from MI, Huawei and Nokia vendors).  I 
also have two Windows 10 laptops having similar issue but they were able to 
connect after a wireless driver upgrade. We only have WPA2 checked for WLAN 
security. I opened a TAC case. The only workaround for Android 10 is to set FT 
to enable instead of Adaptive, but I did not accept that as I am afraid it will 
cause bigger problem for other devices. My TAC engineer said Cisco is working 
on a fix for this issue and ETA of the release is in July.

Dennis

From: The EDUCAUSE Wireless Issues Community Group Listserv 
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>> 
On Behalf Of Christina Klam
Sent: Friday, June 26, 2020 12:19 PM
To: 
WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

CAUTION: This email originated from outside of the University of Guelph. Do not 
click links or open attachments unless you recognize the sender and know the 
content is safe. If in doubt, forward suspicious emails to 
ith...@uoguelph.ca

All,

FYI:   I noticed that  "over-the-ds" setting changed when we upgraded from 8.5 
to 8.10.121.0.  There may be other settings that changed as well.


Christina Klam
Network Engineer
Institute for Advanced Study
1 Einstein Dr
Princeton, NJ 08540
(m) +1 609-751-7899
(o) +1 609-734-8154
ck...@ias.edu


From: "Mallon, Jason" mailto:jemal...@ua.edu>>
To: "The EDUCAUSE Wireless Issues Community Group Listserv" 
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>>
Sent: Friday, June 26, 2020 10:24:20 AM
Subject: Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

Paul,
Are you by any chance running WPA2 + WPA3 Enterprise with both the WPA2 and 
WPA3 boxes checked?  We are currently on 8.10.121 and seeing this issue as well 
primarily with Windows devices.  I have not seen any issues with Macs and 
authentication.


Jason Mallon

Network Engineer III, OIT

The University of Alabama
jemal...@ua.edu



From: The EDUCAUSE Wireless Issues Community Group Listserv 
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>> 
on behalf of Paul Smith mailto:psmi...@marian.edu>>
Sent: Friday, June 26, 2020 9:44 AM
To: 
WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU 
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>>
Subject: [EXTERNAL] Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

We were running 8.10.121 on our 5520 and began having authentication issues. It 
is weird because radius isn't even seeing the attempts (or weren't logging 
rejections). The behavior persists even using local authentication. Eventually 
we can get the clients to connect, but it takes a number of attempts. It's very 
frustrating.

Cisco had us upgrade to 8.10.122, but the problem still persists. We would roll 
back, but we have 9130's on the campus now and we need 8.10.122 to manage them.

Such a headache right now.

Paul Smith
Network Administrator
Marian University
psmi...@marian.edu
317.955.6069

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the 

RE: [WIRELESS-LAN] WLC 8.10.121 Deferred

2020-06-26 Thread Paul Smith
Q. Are you by any chance running WPA2 + WPA3 Enterprise with both the WPA2 and 
WPA3 boxes checked?  We are currently on 8.10.121 and seeing this issue as well 
primarily with Windows devices.  I have not seen any issues with Macs and 
authentication.

A. No. WPA2 + WPA3, but only WPA2 is checked. I will experiment with this when 
I get back to the office. The big problem is it's impacting Windows 10 PCs. We 
have not seen the issue with iPhones or Android devices, but there may not be 
enough of them on campus right now to say for sure (we don't have a summer 
semester). We do have Mac's having a similar issue, but forgetting the SSID and 
re-selecting fixes any auth issues we see there.

Q. FYI:   I noticed that  "over-the-ds" setting changed when we upgraded from 
8.5 to 8.10.121.0.  There may be other settings that changed as well.

A. One of the engineers mentioned another setting was different (sorry, can't 
remember which it was), but then he called me right back and said that wasn't 
the issue. I believe there was something he found in the logs based on the 
conversation, so hopefully we'll have more info soon. It might've been beacon 
related, but I could have that planted in my head from an earlier post.

Q. There was a memory leak in the AP. Clients were not moving from 
authentication to the AP through the association phase on the controller.(these 
terms seem backwards to me backwards -- authentication is finding the AP, 
association is the 802.1x/radius part). The AP was not forwarding the 
association PDU to the controller (so the radius servers never got to see 
request let alone send a rejection). Rebooting the AP at the time /might/ fix 
the problem, but if a large number of clients immediately connected to the 
newly rebooted AP it ran out memory and became semi-operational again. I'd 
check the AP rather than the controller logs to see what it's reporting.

A. There's not an AP model on the campus that we've found the behavior any 
different. In our office where we test, it's a 2802 ... but the issue exists 
with the 3800's and even the new 9100's as well.

Q. Have you tested your Android devices with FT disabled? (instead of FT 
Adaptive). I would be curious to hear what results you get.

A. We haven't seen any issues with Android devices (yet), but we don't have 
enough on the campus to say for sure. We did go Adaptive at the suggestion of 
Cisco and a Presidio engineer because of some issues with iPads. So, I wouldn't 
be keen to change that.

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


Re: [EXTERNAL] Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

2020-06-26 Thread Mallon, Jason
We have WPA2 and WPA3 checked at this time.  The only issue we have seen have 
been with Windows 10 devices.  We have a handful of Android 10 devices that as 
far as I know are mainly Pixel and Samsung that have not had issues.  No Mac 
issues that I have heard about.

Jason Mallon
Network Engineer, OIT
The University of Alabama
jemal...@ua.edu

On Jun 26, 2020 5:12 PM, Paul Smith  wrote:
Q. Are you by any chance running WPA2 + WPA3 Enterprise with both the WPA2 and 
WPA3 boxes checked?  We are currently on 8.10.121 and seeing this issue as well 
primarily with Windows devices.  I have not seen any issues with Macs and 
authentication.

A. No. WPA2 + WPA3, but only WPA2 is checked. I will experiment with this when 
I get back to the office. The big problem is it's impacting Windows 10 PCs. We 
have not seen the issue with iPhones or Android devices, but there may not be 
enough of them on campus right now to say for sure (we don't have a summer 
semester). We do have Mac's having a similar issue, but forgetting the SSID and 
re-selecting fixes any auth issues we see there.

Q. FYI:   I noticed that  "over-the-ds" setting changed when we upgraded from 
8.5 to 8.10.121.0.  There may be other settings that changed as well.

A. One of the engineers mentioned another setting was different (sorry, can't 
remember which it was), but then he called me right back and said that wasn't 
the issue. I believe there was something he found in the logs based on the 
conversation, so hopefully we'll have more info soon. It might've been beacon 
related, but I could have that planted in my head from an earlier post.

Q. There was a memory leak in the AP. Clients were not moving from 
authentication to the AP through the association phase on the controller.(these 
terms seem backwards to me backwards -- authentication is finding the AP, 
association is the 802.1x/radius part). The AP was not forwarding the 
association PDU to the controller (so the radius servers never got to see 
request let alone send a rejection). Rebooting the AP at the time /might/ fix 
the problem, but if a large number of clients immediately connected to the 
newly rebooted AP it ran out memory and became semi-operational again. I'd 
check the AP rather than the controller logs to see what it's reporting.

A. There's not an AP model on the campus that we've found the behavior any 
different. In our office where we test, it's a 2802 ... but the issue exists 
with the 3800's and even the new 9100's as well.

Q. Have you tested your Android devices with FT disabled? (instead of FT 
Adaptive). I would be curious to hear what results you get.

A. We haven't seen any issues with Android devices (yet), but we don't have 
enough on the campus to say for sure. We did go Adaptive at the suggestion of 
Cisco and a Presidio engineer because of some issues with iPads. So, I wouldn't 
be keen to change that.

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

2020-06-26 Thread Ciesinski, Nick
Interesting. For us it’s like one particular area with one particular mode of 
AP we don’t have anyplace else.  It magically went away again today too. 

Nick 

Sent from my iPhone

> On Jun 26, 2020, at 5:12 PM, Paul Smith  wrote:
> 
> *EXTERNAL EMAIL*
> 
> Q. Are you by any chance running WPA2 + WPA3 Enterprise with both the WPA2 
> and WPA3 boxes checked?  We are currently on 8.10.121 and seeing this issue 
> as well primarily with Windows devices.  I have not seen any issues with Macs 
> and authentication.
> 
> A. No. WPA2 + WPA3, but only WPA2 is checked. I will experiment with this 
> when I get back to the office. The big problem is it's impacting Windows 10 
> PCs. We have not seen the issue with iPhones or Android devices, but there 
> may not be enough of them on campus right now to say for sure (we don't have 
> a summer semester). We do have Mac's having a similar issue, but forgetting 
> the SSID and re-selecting fixes any auth issues we see there.
> 
> Q. FYI:   I noticed that  "over-the-ds" setting changed when we upgraded from 
> 8.5 to 8.10.121.0.  There may be other settings that changed as well.
> 
> A. One of the engineers mentioned another setting was different (sorry, can't 
> remember which it was), but then he called me right back and said that wasn't 
> the issue. I believe there was something he found in the logs based on the 
> conversation, so hopefully we'll have more info soon. It might've been beacon 
> related, but I could have that planted in my head from an earlier post.
> 
> Q. There was a memory leak in the AP. Clients were not moving from 
> authentication to the AP through the association phase on the 
> controller.(these terms seem backwards to me backwards -- authentication is 
> finding the AP, association is the 802.1x/radius part). The AP was not 
> forwarding the association PDU to the controller (so the radius servers never 
> got to see request let alone send a rejection). Rebooting the AP at the time 
> /might/ fix the problem, but if a large number of clients immediately 
> connected to the newly rebooted AP it ran out memory and became 
> semi-operational again. I'd check the AP rather than the controller logs to 
> see what it's reporting.
> 
> A. There's not an AP model on the campus that we've found the behavior any 
> different. In our office where we test, it's a 2802 ... but the issue exists 
> with the 3800's and even the new 9100's as well.
> 
> Q. Have you tested your Android devices with FT disabled? (instead of FT 
> Adaptive). I would be curious to hear what results you get.
> 
> A. We haven't seen any issues with Android devices (yet), but we don't have 
> enough on the campus to say for sure. We did go Adaptive at the suggestion of 
> Cisco and a Presidio engineer because of some issues with iPads. So, I 
> wouldn't be keen to change that.
> 
> **
> Replies to EDUCAUSE Community Group emails are sent to the entire community 
> list. If you want to reply only to the person who sent the message, copy and 
> paste their email address and forward the email reply. Additional 
> participation and subscription information can be found at 
> https://www.educause.edu/community

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


RE: WLC 8.10.121 Deferred

2020-06-26 Thread Dennis Xu
Hi Hector,

The FT disabled option does not help. The only way to get these Android devices 
connected is to use FT enabled.

Dennis


From: The EDUCAUSE Wireless Issues Community Group Listserv 
 On Behalf Of Rios, Hector J
Sent: Friday, June 26, 2020 2:32 PM
To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

CAUTION: This email originated from outside of the University of Guelph. Do not 
click links or open attachments unless you recognize the sender and know the 
content is safe. If in doubt, forward suspicious emails to 
ith...@uoguelph.ca

Dennis,

Have you tested your Android devices with FT disabled? (instead of FT 
Adaptive). I would be curious to hear what results you get.

Thanks,

Hector Rios, Wireless Network Architect
The University of Texas at Austin



From: The EDUCAUSE Wireless Issues Community Group Listserv 
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>> 
On Behalf Of Dennis Xu
Sent: Friday, June 26, 2020 11:45 AM
To: 
WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

We have upgraded to 8.10.121.0 for one month. We have seen some devices not 
able to connect. When they run into this issue, we don’t see any association 
requests from the devices. There are something in the beacon which are not 
liked by the devices so they do not want to join. Not a lot of devices 
affected, mainly from Android 10 devices(from MI, Huawei and Nokia vendors).  I 
also have two Windows 10 laptops having similar issue but they were able to 
connect after a wireless driver upgrade. We only have WPA2 checked for WLAN 
security. I opened a TAC case. The only workaround for Android 10 is to set FT 
to enable instead of Adaptive, but I did not accept that as I am afraid it will 
cause bigger problem for other devices. My TAC engineer said Cisco is working 
on a fix for this issue and ETA of the release is in July.

Dennis

From: The EDUCAUSE Wireless Issues Community Group Listserv 
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>> 
On Behalf Of Christina Klam
Sent: Friday, June 26, 2020 12:19 PM
To: 
WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

CAUTION: This email originated from outside of the University of Guelph. Do not 
click links or open attachments unless you recognize the sender and know the 
content is safe. If in doubt, forward suspicious emails to 
ith...@uoguelph.ca

All,

FYI:   I noticed that  "over-the-ds" setting changed when we upgraded from 8.5 
to 8.10.121.0.  There may be other settings that changed as well.


Christina Klam
Network Engineer
Institute for Advanced Study
1 Einstein Dr
Princeton, NJ 08540
(m) +1 609-751-7899
(o) +1 609-734-8154
ck...@ias.edu


From: "Mallon, Jason" mailto:jemal...@ua.edu>>
To: "The EDUCAUSE Wireless Issues Community Group Listserv" 
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>>
Sent: Friday, June 26, 2020 10:24:20 AM
Subject: Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

Paul,
Are you by any chance running WPA2 + WPA3 Enterprise with both the WPA2 and 
WPA3 boxes checked?  We are currently on 8.10.121 and seeing this issue as well 
primarily with Windows devices.  I have not seen any issues with Macs and 
authentication.


Jason Mallon

Network Engineer III, OIT

The University of Alabama
jemal...@ua.edu



From: The EDUCAUSE Wireless Issues Community Group Listserv 
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>> 
on behalf of Paul Smith mailto:psmi...@marian.edu>>
Sent: Friday, June 26, 2020 9:44 AM
To: 
WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU 
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>>
Subject: [EXTERNAL] Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

We were running 8.10.121 on our 5520 and began having authentication issues. It 
is weird because radius isn't even seeing the attempts (or weren't logging 
rejections). The behavior persists even using local authentication. Eventually 
we can get the clients to connect, but it takes a number of attempts. It's very 
frustrating.

Cisco had us upgrade to 8.10.122, but the problem still persists. We would roll 
back, but we have 9130's on the campus now and we need 8.10.122 to manage them.

Such a headache right now.

Paul Smith
Network Administrator
Marian University
psmi...@marian.edu
317.955.6069

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

**
Replies to EDUCAUSE Community Group emails are sent to the 

RE: WLC 8.10.121 Deferred

2020-06-26 Thread Dennis Xu
We have upgraded to 8.10.121.0 for one month. We have seen some devices not 
able to connect. When they run into this issue, we don’t see any association 
requests from the devices. There are something in the beacon which are not 
liked by the devices so they do not want to join. Not a lot of devices 
affected, mainly from Android 10 devices(from MI, Huawei and Nokia vendors).  I 
also have two Windows 10 laptops having similar issue but they were able to 
connect after a wireless driver upgrade. We only have WPA2 checked for WLAN 
security. I opened a TAC case. The only workaround for Android 10 is to set FT 
to enable instead of Adaptive, but I did not accept that as I am afraid it will 
cause bigger problem for other devices. My TAC engineer said Cisco is working 
on a fix for this issue and ETA of the release is in July.

Dennis

From: The EDUCAUSE Wireless Issues Community Group Listserv 
 On Behalf Of Christina Klam
Sent: Friday, June 26, 2020 12:19 PM
To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

CAUTION: This email originated from outside of the University of Guelph. Do not 
click links or open attachments unless you recognize the sender and know the 
content is safe. If in doubt, forward suspicious emails to 
ith...@uoguelph.ca

All,

FYI:   I noticed that  "over-the-ds" setting changed when we upgraded from 8.5 
to 8.10.121.0.  There may be other settings that changed as well.


Christina Klam
Network Engineer
Institute for Advanced Study
1 Einstein Dr
Princeton, NJ 08540
(m) +1 609-751-7899
(o) +1 609-734-8154
ck...@ias.edu


From: "Mallon, Jason" mailto:jemal...@ua.edu>>
To: "The EDUCAUSE Wireless Issues Community Group Listserv" 
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>>
Sent: Friday, June 26, 2020 10:24:20 AM
Subject: Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

Paul,
Are you by any chance running WPA2 + WPA3 Enterprise with both the WPA2 and 
WPA3 boxes checked?  We are currently on 8.10.121 and seeing this issue as well 
primarily with Windows devices.  I have not seen any issues with Macs and 
authentication.


Jason Mallon

Network Engineer III, OIT

The University of Alabama
jemal...@ua.edu



From: The EDUCAUSE Wireless Issues Community Group Listserv 
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>> 
on behalf of Paul Smith mailto:psmi...@marian.edu>>
Sent: Friday, June 26, 2020 9:44 AM
To: 
WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU 
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>>
Subject: [EXTERNAL] Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

We were running 8.10.121 on our 5520 and began having authentication issues. It 
is weird because radius isn't even seeing the attempts (or weren't logging 
rejections). The behavior persists even using local authentication. Eventually 
we can get the clients to connect, but it takes a number of attempts. It's very 
frustrating.

Cisco had us upgrade to 8.10.122, but the problem still persists. We would roll 
back, but we have 9130's on the campus now and we need 8.10.122 to manage them.

Such a headache right now.

Paul Smith
Network Administrator
Marian University
psmi...@marian.edu
317.955.6069

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


RE: WLC 8.10.121 Deferred

2020-06-26 Thread Rios, Hector J
Dennis,

Have you tested your Android devices with FT disabled? (instead of FT 
Adaptive). I would be curious to hear what results you get.

Thanks,

Hector Rios, Wireless Network Architect
The University of Texas at Austin



From: The EDUCAUSE Wireless Issues Community Group Listserv 
 On Behalf Of Dennis Xu
Sent: Friday, June 26, 2020 11:45 AM
To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

We have upgraded to 8.10.121.0 for one month. We have seen some devices not 
able to connect. When they run into this issue, we don’t see any association 
requests from the devices. There are something in the beacon which are not 
liked by the devices so they do not want to join. Not a lot of devices 
affected, mainly from Android 10 devices(from MI, Huawei and Nokia vendors).  I 
also have two Windows 10 laptops having similar issue but they were able to 
connect after a wireless driver upgrade. We only have WPA2 checked for WLAN 
security. I opened a TAC case. The only workaround for Android 10 is to set FT 
to enable instead of Adaptive, but I did not accept that as I am afraid it will 
cause bigger problem for other devices. My TAC engineer said Cisco is working 
on a fix for this issue and ETA of the release is in July.

Dennis

From: The EDUCAUSE Wireless Issues Community Group Listserv 
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>> 
On Behalf Of Christina Klam
Sent: Friday, June 26, 2020 12:19 PM
To: 
WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

CAUTION: This email originated from outside of the University of Guelph. Do not 
click links or open attachments unless you recognize the sender and know the 
content is safe. If in doubt, forward suspicious emails to 
ith...@uoguelph.ca

All,

FYI:   I noticed that  "over-the-ds" setting changed when we upgraded from 8.5 
to 8.10.121.0.  There may be other settings that changed as well.


Christina Klam
Network Engineer
Institute for Advanced Study
1 Einstein Dr
Princeton, NJ 08540
(m) +1 609-751-7899
(o) +1 609-734-8154
ck...@ias.edu


From: "Mallon, Jason" mailto:jemal...@ua.edu>>
To: "The EDUCAUSE Wireless Issues Community Group Listserv" 
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>>
Sent: Friday, June 26, 2020 10:24:20 AM
Subject: Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

Paul,
Are you by any chance running WPA2 + WPA3 Enterprise with both the WPA2 and 
WPA3 boxes checked?  We are currently on 8.10.121 and seeing this issue as well 
primarily with Windows devices.  I have not seen any issues with Macs and 
authentication.


Jason Mallon

Network Engineer III, OIT

The University of Alabama
jemal...@ua.edu



From: The EDUCAUSE Wireless Issues Community Group Listserv 
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>> 
on behalf of Paul Smith mailto:psmi...@marian.edu>>
Sent: Friday, June 26, 2020 9:44 AM
To: 
WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU 
mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU>>
Subject: [EXTERNAL] Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

We were running 8.10.121 on our 5520 and began having authentication issues. It 
is weird because radius isn't even seeing the attempts (or weren't logging 
rejections). The behavior persists even using local authentication. Eventually 
we can get the clients to connect, but it takes a number of attempts. It's very 
frustrating.

Cisco had us upgrade to 8.10.122, but the problem still persists. We would roll 
back, but we have 9130's on the campus now and we need 8.10.122 to manage them.

Such a headache right now.

Paul Smith
Network Administrator
Marian University
psmi...@marian.edu
317.955.6069

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

This message is from an external sender. Learn more about why this 

RE: WLC 8.10.121 Deferred

2020-06-26 Thread Letts, Richard J
We had that problem with 350x series AP ~ 18 months ago. I'll have to dig out 
the exact version number number but it was on the 8.3/8.5 train.

There was a memory leak in the AP. Clients were not moving from authentication 
to the AP through the association phase on the controller.
(these terms seem backwards to me backwards -- authentication is finding the 
AP, association is the 802.1x/radius part)

The AP was not forwarding the association PDU to the controller (so the radius 
servers never got to see request let alone send a rejection). Rebooting the AP 
at the time /might/ fix the problem, but if a large number of clients 
immediately connected to the newly rebooted AP it ran out memory and became 
semi-operational again.

I'd check the AP rather than the controller logs to see what it's reporting.

/RjL

-Original Message-
From: The EDUCAUSE Wireless Issues Community Group Listserv 
 On Behalf Of Paul Smith
Sent: Friday, June 26, 2020 10:45 AM
To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU
Subject: Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

We were running 8.10.121 on our 5520 and began having authentication issues. It 
is weird because radius isn't even seeing the attempts (or weren't logging 
rejections). The behavior persists even using local authentication. Eventually 
we can get the clients to connect, but it takes a number of attempts. It's very 
frustrating.

Cisco had us upgrade to 8.10.122, but the problem still persists. We would roll 
back, but we have 9130's on the campus now and we need 8.10.122 to manage them.

Such a headache right now.

Paul Smith
Network Administrator
Marian University
psmi...@marian.edu
317.955.6069

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

2020-06-26 Thread Christina Klam
All, 

FYI: I noticed that "over-the-ds" setting changed when we upgraded from 8.5 to 
8.10.121.0. There may be other settings that changed as well. 


Christina Klam 
Network Engineer 
Institute for Advanced Study 
1 Einstein Dr 
Princeton, NJ 08540 
(m) +1 609-751-7899 
(o) +1 609-734-8154 
ck...@ias.edu 



From: "Mallon, Jason"  
To: "The EDUCAUSE Wireless Issues Community Group Listserv" 
 
Sent: Friday, June 26, 2020 10:24:20 AM 
Subject: Re: [WIRELESS-LAN] WLC 8.10.121 Deferred 

Paul, 
Are you by any chance running WPA2 + WPA3 Enterprise with both the WPA2 and 
WPA3 boxes checked? We are currently on 8.10.121 and seeing this issue as well 
primarily with Windows devices. I have not seen any issues with Macs and 
authentication. 



Jason Mallon 

Network Engineer III, OIT 

[ https://www.ua.edu/ | The University of Alabama 
 ] [ mailto:jemal...@ua.edu | jemal...@ua.edu ] 


From: The EDUCAUSE Wireless Issues Community Group Listserv 
 on behalf of Paul Smith 
 
Sent: Friday, June 26, 2020 9:44 AM 
To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU  
Subject: [EXTERNAL] Re: [WIRELESS-LAN] WLC 8.10.121 Deferred 
We were running 8.10.121 on our 5520 and began having authentication issues. It 
is weird because radius isn't even seeing the attempts (or weren't logging 
rejections). The behavior persists even using local authentication. Eventually 
we can get the clients to connect, but it takes a number of attempts. It's very 
frustrating. 

Cisco had us upgrade to 8.10.122, but the problem still persists. We would roll 
back, but we have 9130's on the campus now and we need 8.10.122 to manage them. 

Such a headache right now. 

Paul Smith 
Network Administrator 
Marian University 
psmi...@marian.edu 
317.955.6069 

** 
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at [ 
https://www.educause.edu/community | https://www.educause.edu/community ] 


** 
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at [ 
https://www.educause.edu/community | https://www.educause.edu/community ] 

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


RE: WLC 8.10.121 Deferred

2020-06-26 Thread Paul Smith
We were running 8.10.121 on our 5520 and began having authentication issues. It 
is weird because radius isn't even seeing the attempts (or weren't logging 
rejections). The behavior persists even using local authentication. Eventually 
we can get the clients to connect, but it takes a number of attempts. It's very 
frustrating.

Cisco had us upgrade to 8.10.122, but the problem still persists. We would roll 
back, but we have 9130's on the campus now and we need 8.10.122 to manage them.

Such a headache right now.

Paul Smith
Network Administrator
Marian University
psmi...@marian.edu
317.955.6069

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


Re: WLC 8.10.121 Deferred

2020-06-26 Thread Mallon, Jason
Paul,
Are you by any chance running WPA2 + WPA3 Enterprise with both the WPA2 and 
WPA3 boxes checked?  We are currently on 8.10.121 and seeing this issue as well 
primarily with Windows devices.  I have not seen any issues with Macs and 
authentication.


Jason Mallon

Network Engineer III, OIT

The University of Alabama
jemal...@ua.edu



From: The EDUCAUSE Wireless Issues Community Group Listserv 
 on behalf of Paul Smith 

Sent: Friday, June 26, 2020 9:44 AM
To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU 
Subject: [EXTERNAL] Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

We were running 8.10.121 on our 5520 and began having authentication issues. It 
is weird because radius isn't even seeing the attempts (or weren't logging 
rejections). The behavior persists even using local authentication. Eventually 
we can get the clients to connect, but it takes a number of attempts. It's very 
frustrating.

Cisco had us upgrade to 8.10.122, but the problem still persists. We would roll 
back, but we have 9130's on the campus now and we need 8.10.122 to manage them.

Such a headache right now.

Paul Smith
Network Administrator
Marian University
psmi...@marian.edu
317.955.6069

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


Re: [WIRELESS-LAN] WLC 8.10.121 Deferred

2020-06-26 Thread Christina Klam
We had the EXACT same issue in April. TAC was useless. We just rolled back to 
the earlier train, 8.5.161 in order to get everyone connecting again. 

As we are hoping to move back to the 8.10.X train this summer to get the DNAC 
benefits again, I will continue to watch this thread. 

Christina Klam 
Network Engineer 
Institute for Advanced Study 
1 Einstein Dr 
Princeton, NJ 08540 
(m) +1 609-751-7899 
(o) +1 609-734-8154 
ck...@ias.edu 



From: "Paul Smith"  
To: "The EDUCAUSE Wireless Issues Community Group Listserv" 
 
Sent: Friday, June 26, 2020 9:44:32 AM 
Subject: Re: [WIRELESS-LAN] WLC 8.10.121 Deferred 

We were running 8.10.121 on our 5520 and began having authentication issues. It 
is weird because radius isn't even seeing the attempts (or weren't logging 
rejections). The behavior persists even using local authentication. Eventually 
we can get the clients to connect, but it takes a number of attempts. It's very 
frustrating. 

Cisco had us upgrade to 8.10.122, but the problem still persists. We would roll 
back, but we have 9130's on the campus now and we need 8.10.122 to manage them. 

Such a headache right now. 

Paul Smith 
Network Administrator 
Marian University 
psmi...@marian.edu 
317.955.6069 

** 
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community 

**
Replies to EDUCAUSE Community Group emails are sent to the entire community 
list. If you want to reply only to the person who sent the message, copy and 
paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community