<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: client roaming to prefered radio caused radius authentication event which failed in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40512#M2402</link>
    <description>Because we have a downtime based on this issue i open a GTAC Case to solve that - 01232203.&lt;BR /&gt;</description>
    <pubDate>Thu, 28 Jul 2016 15:11:00 GMT</pubDate>
    <dc:creator>M_Nees</dc:creator>
    <dc:date>2016-07-28T15:11:00Z</dc:date>
    <item>
      <title>client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40497#M2387</link>
      <description>Currently i have a very strange problem. &lt;BR /&gt;
We use EAP-TLS 802.1x Authentication for a internal SSID for notebooks. EWC is installed at the headquarter. 2x AP 3705 installed on the affected branch - we use V9.21.07. NAC Gateway 6.2.0.x installed also in the headquarter and is the RADIUS proxy to the NPS on the Windows AD 2008 Server. This working well over the last years. &lt;BR /&gt;
Now we change the WAN connection of this branch from MPLS to VPN with IPSec. After this change a lot of internal WLAN clients which connected before without problems are rejected from the NAC Gateway. All other branches working well. At wired switches we use only MAC Auth which is also not affected.&lt;BR /&gt;
&lt;BR /&gt;
Error:&lt;BR /&gt;
802.1x (identify) - Authentication became stale&lt;BR /&gt;
&lt;BR /&gt;
After some troubleshooting i realized that if the client roam within the AP to its prefered radio for that roaming event a radius request is triggered. The the first request (to the first radio) is always possitive (accepted) and then the AP internal switch to the prefered radio triggers a RADIUS request which is always rejected - with the above error message.&lt;BR /&gt;
&lt;BR /&gt;
For a temporary solution i disable radio 1! And then all client can login without problems!&lt;BR /&gt;
&lt;BR /&gt;
This is very strange.&lt;BR /&gt;
&lt;BR /&gt;
First question: &lt;BR /&gt;
Why do an switch from radio 2 to radio 1 trigger a radius event. Can i disable this new login request in the AP / EWC config?&lt;BR /&gt;
Second Question:&lt;BR /&gt;
If this request is needed why does it become stale and will be rejected?&lt;BR /&gt;
&lt;BR /&gt;
  &lt;BR /&gt;
Thanks for any advices.&lt;BR /&gt;
Regards&lt;BR /&gt;</description>
      <pubDate>Thu, 28 Jul 2016 01:14:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40497#M2387</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2016-07-28T01:14:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40498#M2388</link>
      <description>Hi    I would guess the issue is with MTU = check the config for your APs and your VPN    If I remember well the MACauthentication on the EWC does have option to configure if you want the reauth to happen or not. Go to the Wlan service =&amp;gt; authentication.    Regards</description>
      <pubDate>Thu, 28 Jul 2016 01:22:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40498#M2388</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2016-07-28T01:22:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40499#M2389</link>
      <description>Hi Zdenek,&lt;BR /&gt;
&lt;BR /&gt;
i check the MTU from headquarter to the AP with a "ping -f -l 1400 IP-of-the-AP" which is working fine with MTU of 1400. Also test with lower MTU which have no possitive effects.&lt;BR /&gt;
&lt;BR /&gt;
Within the internal  SSID is use 802.1x Privacy - no MAC Auth.&lt;BR /&gt;
&lt;BR /&gt;
i can not understand why an inter AP roaming will trigger a complete new authentication request ? And why is the request will on the second run ? The first run to the first radio is always accepted ?&lt;BR /&gt;
&lt;BR /&gt;
Regards &lt;BR /&gt;</description>
      <pubDate>Thu, 28 Jul 2016 01:28:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40499#M2389</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2016-07-28T01:28:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40500#M2390</link>
      <description>I assume radio preference is enabled and that is the reason the client is switching between radio 1&amp;amp;2 - correct ?&lt;BR /&gt;
&lt;BR /&gt;
I also vote for a MTU problem.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 28 Jul 2016 01:39:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40500#M2390</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2016-07-28T01:39:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40501#M2391</link>
      <description>Yes radio preference on the client is enabled.&lt;BR /&gt;
&lt;BR /&gt;
But the fact that after disabling radio 1 - to avoid the inter AP roaming the problem is solved speaks against the MTU problem! &lt;BR /&gt;
I also check the possible MTU size with different "ping -f -l max-packet-size"&lt;BR /&gt;
&lt;BR /&gt;
Are there any suggestions how to find the root cause ?&lt;BR /&gt;</description>
      <pubDate>Thu, 28 Jul 2016 01:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40501#M2391</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2016-07-28T01:53:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40502#M2392</link>
      <description>I would try to capture (packet capture) the authentication packets to see why the authentication became stale =&amp;gt; I expect that some packets are being lost. The question is where = client to ap, or AP to controller, or controller to radius server. (Can be configured as SITE = AP to radius server directly).</description>
      <pubDate>Thu, 28 Jul 2016 02:26:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40502#M2392</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2016-07-28T02:26:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40503#M2393</link>
      <description>If your MTU is 1400, what  value you have at your AP?</description>
      <pubDate>Thu, 28 Jul 2016 02:30:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40503#M2393</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2016-07-28T02:30:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40504#M2394</link>
      <description>Hi Zdenek,&lt;BR /&gt;
&lt;BR /&gt;
i testet with "ping -f -l 1400". So an MTU of 1400 Bytes are going through the network - so i configured the AP also with MTU = 1400.&lt;BR /&gt;
&lt;BR /&gt;
Do i something wrong ?&lt;BR /&gt;</description>
      <pubDate>Thu, 28 Jul 2016 02:30:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40504#M2394</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2016-07-28T02:30:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40505#M2395</link>
      <description>Reagrding the reauthentication, I believe it is part of standard that authentication-association to new BSSID means new encryption keys generation. If your client does support OKC then you can enable it.</description>
      <pubDate>Thu, 28 Jul 2016 02:34:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40505#M2395</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2016-07-28T02:34:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40506#M2396</link>
      <description>Oppertunistic Keying is enabled already on this WLAN Service.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 28 Jul 2016 02:34:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40506#M2396</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2016-07-28T02:34:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40507#M2397</link>
      <description>In my opinon it make sense to see a 2nd 802.1X authentication if radio preference is enabled as the client doesn't roam between the radios - it's a new connection.&lt;BR /&gt;
&lt;BR /&gt;
I think as a workaround you'd also disable radio preference and enable radio#1 again - I'm pretty sure that will work.&lt;BR /&gt;
Then enable it only on one AP so you'd troubleshoot the issue with the GTAC.</description>
      <pubDate>Thu, 28 Jul 2016 02:35:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40507#M2397</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2016-07-28T02:35:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40508#M2398</link>
      <description>Hi Ronald,&lt;BR /&gt;
&lt;BR /&gt;
we configure prefered radio on the client devices - windows driver settings.&lt;BR /&gt;
&lt;BR /&gt;
I see this is possible via AP "Load groups", but this is not configured.&lt;BR /&gt;
&lt;BR /&gt;
Regards  &lt;BR /&gt;</description>
      <pubDate>Thu, 28 Jul 2016 02:35:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40508#M2398</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2016-07-28T02:35:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40509#M2399</link>
      <description>Did you try enabling fast roaming?&lt;BR /&gt;
&lt;BR /&gt;
Regards</description>
      <pubDate>Thu, 28 Jul 2016 11:18:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40509#M2399</guid>
      <dc:creator>Frank_Veen</dc:creator>
      <dc:date>2016-07-28T11:18:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40510#M2400</link>
      <description>Matthias&lt;BR /&gt;
&lt;BR /&gt;
Do you have AP secure tunnel and is NAT involved?&lt;BR /&gt;
&lt;BR /&gt;
-Gareth</description>
      <pubDate>Thu, 28 Jul 2016 13:22:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40510#M2400</guid>
      <dc:creator>Gareth_Mitchell</dc:creator>
      <dc:date>2016-07-28T13:22:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40511#M2401</link>
      <description>Hi Gareth,&lt;BR /&gt;
&lt;BR /&gt;
Secure Tunnel is disabled completely. NAT is not involved!  &lt;BR /&gt;
Customers network is divided in Subnets in 10.x.x.x IP Range. HQ and Branch are connected via IP-Sec Tunnel without any kind of NAT.&lt;BR /&gt;
&lt;BR /&gt;
Regards &lt;BR /&gt;</description>
      <pubDate>Thu, 28 Jul 2016 13:22:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40511#M2401</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2016-07-28T13:22:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40512#M2402</link>
      <description>Because we have a downtime based on this issue i open a GTAC Case to solve that - 01232203.&lt;BR /&gt;</description>
      <pubDate>Thu, 28 Jul 2016 15:11:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40512#M2402</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2016-07-28T15:11:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40513#M2403</link>
      <description>Could it be related to... &lt;BR /&gt;
   &lt;A href="https://gtacknowledge.extremenetworks.com/articles/Solution/802-1x-client-authentication-takes-a-long-time-and-most-times-never-completes-at-all" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/Solution/802-1x-client-authentication-takes-a-lon...&lt;/A&gt;</description>
      <pubDate>Thu, 28 Jul 2016 20:01:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40513#M2403</guid>
      <dc:creator>JK</dc:creator>
      <dc:date>2016-07-28T20:01:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40514#M2404</link>
      <description>Hi Folks,&lt;BR /&gt;
&lt;BR /&gt;
this problem is still unresolved!!&lt;BR /&gt;
&lt;BR /&gt;
GTAC tell me this solution:&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/Solution/Apple-clients-take-very-long-time-to-get-their-certificate-from-radius-server" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/Solution/Apple-clients-take-very-long-time-to-get...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
i get a wireshark trace of a rejected end-system which emphases this guess:&lt;BR /&gt;
NPS is not possible to bring the Server certificate to the client! (and then the request is rejected)&lt;BR /&gt;
&lt;BR /&gt;
The problem of the above solution is that it only works if NPS will accept the RADIUS Request. So clients are still rejected (because of too big MTU). The reduced Framed-MTU will never reaches the problematic clients!&lt;BR /&gt;
&lt;BR /&gt;
If i debug the RADIUS request on NAC Gateway i see the Framed-MTU value is set to 1400 (Request from EWC). &lt;BR /&gt;
&lt;BR /&gt;
Can i change this value on the EWC? &lt;BR /&gt;
&lt;BR /&gt;
My first guess is this is calculated based on the used AP-MTU Size. But after i changed AP MTU to 1300 is see that the Framed-MTU does not changed (1400). So this seems to be fix in the EWC Config. But from my point of view this should be calculated in conjuntion of the set AP MTU!&lt;BR /&gt;
&lt;BR /&gt;
Regards&lt;BR /&gt;</description>
      <pubDate>Fri, 05 Aug 2016 12:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40514#M2404</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2016-08-05T12:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40515#M2405</link>
      <description>Hi Matthias,&lt;BR /&gt;
&lt;BR /&gt;
I do not quite understand the MTU problem. You wrote that you can ping the AP with a 1428B IP packet (1400B ICMP Echo Request data + ICMP header + IP header), and that a Framed-MTU of 1400 is used. That seems to fit.&lt;BR /&gt;
&lt;BR /&gt;
Additionally you write that authentication works fine with one radio disabled. That suggests that the network is able to transport the certificate.&lt;BR /&gt;
&lt;BR /&gt;
But then you write that the server certificate cannot be transported to the client.&lt;BR /&gt;
&lt;BR /&gt;
I would guess that one packet containing part of the certificate is lost on its way from the server (NAC) to the client (AP), ultimately resulting in a reject.&lt;BR /&gt;
&lt;BR /&gt;
It is interesting that there seems to be reliable packet loss with two back-to-back authentication attempts. As if that crossed some rate limiting threshold.&lt;BR /&gt;
&lt;BR /&gt;
HTH,&lt;BR /&gt;
Erik</description>
      <pubDate>Fri, 05 Aug 2016 14:48:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40515#M2405</guid>
      <dc:creator>Erik_Auerswald</dc:creator>
      <dc:date>2016-08-05T14:48:00Z</dc:date>
    </item>
    <item>
      <title>RE: client roaming to prefered radio caused radius authentication event which failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40516#M2406</link>
      <description>&lt;I&gt;Additionally you write that authentication works fine with one radio disabled.&lt;/I&gt;&lt;BR /&gt;
--&amp;gt; i believe that because there was an accept in NAC Manager GUI. &lt;BR /&gt;
This was a mistake by me. &lt;BR /&gt;</description>
      <pubDate>Fri, 05 Aug 2016 14:48:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/client-roaming-to-prefered-radio-caused-radius-authentication/m-p/40516#M2406</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2016-08-05T14:48:00Z</dc:date>
    </item>
  </channel>
</rss>

