We are not running patch 1. Maybe TAC will identify a bug that is fixed in patch 1? Thanks for the heads up.
On Thu, Sep 4, 2014 at 10:43 AM, Trent Hurt <[email protected]> wrote: > I’m running 1.2.1 patch 1 and I haven’t had these issues. (fingers > crossed) I have 4 psns with the controllers configured to balance the > load. Have you applied patch 1 to your 1.2.1? > > > > *From:* The EDUCAUSE Wireless Issues Constituent Group Listserv [mailto: > [email protected]] *On Behalf Of *Joe Roth > *Sent:* Thursday, September 04, 2014 10:39 AM > > *To:* [email protected] > *Subject:* Re: [WIRELESS-LAN] Authentication failures at peak times > (Cisco) > > > > Eric, > > Are you running 1.2 fully patched, or 1.2.1? We are seeing some serious > issues right now with 1.2.1. We ended the Spring semester on 1.2 and things > worked great, but our start up with 1.2.1 has gone terrible. We are seeing > high radius/PEAP latency on our policy nodes. What is odd is that if we > reboot a policy node and it comes back up but cannot synchronize, there is > no latency at all, authentications go through. > > > > On Tue, Sep 2, 2014 at 5:14 PM, Eric T. Barnett <[email protected]> > wrote: > > You are right, that command can cause some serious problems. > > > > The good news is that we moved to a Microsoft RADIUS server as a temporary > check. It works great! I still need to wait until tomorrow morning for full > peak, but during medium load today it worked perfectly. It wasn’t working > well even during this load with ISE. The bad news is apparently something > is very wrong with our ISE installation. At least I’ve got my users off of > my back for a bit while we figure out what’s wrong with ISE. > > > > --Eric > > > > *From:* The EDUCAUSE Wireless Issues Constituent Group Listserv [mailto: > [email protected]] *On Behalf Of *Jeffrey Sessler > *Sent:* Tuesday, September 02, 2014 9:46 AM > > > *To:* [email protected] > *Subject:* Re: [WIRELESS-LAN] Authentication failures at peak times > (Cisco) > > > > I don't know if it was mentioned here, but you may want to look at this if > you have defined more than on raidus server on your controlers: > > > > *config radius aggressive-failover disable* > > > > This turns off the aggressive failover of RADIUS - this prevents the > situation where a unknown user attempts to connect, and the controllers > consider the delay in response (or no response) as a failure. The > controller will then switch to the other RADIUS server. This results in a > ping-pong between radius servers. With the feature disabled, the controller > only fails over to the next AAA server if there are three consecutive > clients that fail to receive a response from the RADIUS server. > > > > Jeff > > > >>> On Tuesday, September 02, 2014 at 5:21 AM, in message < > [email protected]>, "Case, > Brandon J" <[email protected]> wrote: > > Don, > > > > Yep the Timeout Requests counter on the controllers ticks up for the > particular RADIUS server they’re talking to. I’ve also noticed the Pending > Request timer increase at times but eventually it drops back to 0 when > usage levels go down. Which vendor supported RADIUS appliances did you > switch to? > > > > Thanks, > > Brandon > > > > *From:* The EDUCAUSE Wireless Issues Constituent Group Listserv [ > mailto:[email protected] > <[email protected]>] *On Behalf Of *Wright, Don > *Sent:* Monday, September 01, 2014 9:17 PM > *To:* [email protected] > *Subject:* Re: [WIRELESS-LAN] Authentication failures at peak times > (Cisco) > > > > Brandon, > > Can you see any radius issues based on stats on your controllers, > timeouts, etc. We were seeing these on our FR servers last fall before we > moved to our vendor support radius appliances. > > - > > Don Wright > > Lead Network Operations Engineer > > Brown University > > > > > > On Wed, Aug 27, 2014 at 3:21 PM, Case, Brandon J <[email protected]> wrote: > > Would you be able to elaborate on the improvements you did over the > summer? We have a similar setup with regards to the backend, although ours > is just freeradius -> ldap without the F5. Our usage levels are just a bit > higher than yours but we're receiving lots of user reports of the inability > to authenticate but nothing consistent enough to isolate and test > repeatedly. > > Thanks, > Brandon > > > -----Original Message----- > From: The EDUCAUSE Wireless Issues Constituent Group Listserv [mailto: > [email protected]] On Behalf Of Wang, Yu > Sent: Wednesday, August 27, 2014 3:15 PM > To: [email protected] > > Subject: Re: [WIRELESS-LAN] Authentication failures at peak times (Cisco) > > Where are all your user accounts hosted? What kind of user database that > serves the wireless system? Do you have a rough number of how many > concurrent users at peak time? > > We had peak time wireless authentication failure issues in the past Spring > semester. We did performance tests in the summer and found out it was the > backend (F5 + LDAP). We did improvements in the summer and we have not seen > the issue in the first three days of Fall semester. Yesterday's wireless > usage set a new record with over 32k unique users and over 15k concurrent > users. > > We use Aruba wireless with 802.1X, WPA2-Ent, PEAP, MSCHAPv2 + freeradius + > F5 + ldap. It's different than yours but from the error you mentioned, it's > likely the backend was congested. > > > > Yu Wang > ____________________________ > Network Architect > Information Technology Services > The Florida State University > 850-645-6810 > [email protected] > > > -----Original Message----- > From: The EDUCAUSE Wireless Issues Constituent Group Listserv [mailto: > [email protected]] On Behalf Of Eric T. Barnett > Sent: Wednesday, August 27, 2014 2:12 PM > To: [email protected] > Subject: [WIRELESS-LAN] Authentication failures at peak times (Cisco) > > We've got a relatively small deployment compared to many on this list, but > we've run into a problem we just can't put our finger on. We're using 5508s > and ISE as a RADIUS server and we're having HUGE latencies on > WPA2-Enterprise PEAP authentication. There's times when almost no one can > authenticate. What's really weird is that the controllers show "AAA > Authentication Error" when this happens even though the username and > password is correct. None of the devices seem distressed and there's no > network problems we can see. Anyone ever seen this before or have any ideas > how to troubleshoot? TAC so far has been not incredibly useful but they > have only been on the case for a day or so now. I can hear my users > sharpening the pitchforks... > > Thanks, > > Eric Barnett > Wireless Administrator > Information and Technology Services > Arkansas State University > 870 680 4243 > > ********** > Participation and subscription information for this EDUCAUSE Constituent > Group discussion list can be found at http://www.educause.edu/groups/. > > ********** > Participation and subscription information for this EDUCAUSE Constituent > Group discussion list can be found at http://www.educause.edu/groups/. > > ********** > Participation and subscription information for this EDUCAUSE Constituent > Group discussion list can be found at http://www.educause.edu/groups/. > > > > ********** Participation and subscription information for this EDUCAUSE > Constituent Group discussion list can be found at > http://www.educause.edu/groups/. > > ********** Participation and subscription information for this EDUCAUSE > Constituent Group discussion list can be found at > http://www.educause.edu/groups/. > > > > > -- > > Joe Roth > Network Manager > Binghamton University > Ph. 607-777-7528 > Fax 607-777-4009 > > ********** Participation and subscription information for this EDUCAUSE > Constituent Group discussion list can be found at > http://www.educause.edu/groups/. > -- Joe Roth Network Manager Binghamton University Ph. 607-777-7528 Fax 607-777-4009 ********** Participation and subscription information for this EDUCAUSE Constituent Group discussion list can be found at http://www.educause.edu/groups/.
