<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Client failed 802.1x/EAP authentication on wlan in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66386#M6006</link>
    <description>&lt;P&gt;Hi Alexandr,&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Quick guess - 802.11r enabled and Intel AC-xxxx card within the laptop?&lt;/P&gt; &lt;P&gt;Apparently, it might be helpful sometimes if you click on troubleshooting option in Windows when it pops up ‘unable to connect’. Then it will most probably fail but you can see detailed results and it shows at which point (from supplicant/STA point of view) it failed. It was really helpful to me when troubleshooting IdentiFi network once (and it was 11r case actually, so WPA2 4-way handshake couldn’t finish, I’m not sure if the logs here are relevant but just a guess).&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Hope that helps,&lt;/P&gt; &lt;P&gt;Tomasz&lt;/P&gt;</description>
    <pubDate>Fri, 14 Feb 2020 20:21:41 GMT</pubDate>
    <dc:creator>Tomasz</dc:creator>
    <dc:date>2020-02-14T20:21:41Z</dc:date>
    <item>
      <title>Client failed 802.1x/EAP authentication on wlan</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66383#M6003</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;WiNG 5.9&lt;/P&gt; &lt;P&gt;VX9000 + AP7632.&lt;/P&gt; &lt;P&gt;RADIUS in AP’s (Internal Self) with test user.&lt;/P&gt; &lt;P&gt;Smartphone normally connecting.&lt;/P&gt; &lt;P&gt;Lap-top with Win7 - no.&lt;/P&gt; &lt;P&gt;Could you please help - where to look at? How to debug this issue?&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;[ap7632-6F2CC7] 10:09:38.724: radius:RAD_MSG_AUTHENTICATOR (radius.c:1182)&lt;BR /&gt; [ap7632-6F2CC7] 10:09:38.724: radius:rx access-challenge from radius server for 00-13-E8-93-D4-19 (radius.c:3888)&lt;BR /&gt; [ap7632-6F2CC7] 10:09:38.724: eap:sending eap-code-request code 1, type 25 to 00-13-E8-93-D4-19 (eap.c:964)&lt;BR /&gt; [ap7632-6F2CC7] 10:09:38.724: eap:sending eap-req [eap_type:25(peap)] to 00-13-E8-93-D4-19 (eap.c:1001)&lt;BR /&gt; [ap7632-6F2CC7] 10:09:38.730: eap:rx eap pkt from 00-13-E8-93-D4-19 (eap.c:720)&lt;BR /&gt; [ap7632-6F2CC7] 10:09:38.731: radius:access-req sent to 127.0.0.1:1812 (attempt 1) for 00-13-E8-93-D4-19 (user:Extreme) (radius.c:3054)&lt;BR /&gt; [ap7632-6F2CC7] 10:09:38.736: radius:RAD_MSG_AUTHENTICATOR (radius.c:1182)&lt;BR /&gt;&lt;STRONG&gt;[ap7632-6F2CC7] 10:09:38.736: radius:rx access-reject for 00-13-E8-93-D4-19 (radius.c:3781)&lt;BR /&gt; [ap7632-6F2CC7] 10:09:38.736: eap:sending eap-failure to 00-13-E8-93-D4-19 (eap.c:1009)&lt;BR /&gt; [ap7632-6F2CC7] %%%%&amp;gt;10:09:38.736: radius:alarm num_eap_f ++ 1 (radius.c:3859)&lt;/STRONG&gt;&lt;BR /&gt; [ap7632-6F2CC7] 10:09:38.736: client:clearing cached credentials for 00-13-E8-93-D4-19 (credcache.c:241)&lt;BR /&gt;&lt;STRONG&gt;[ap7632-6F2CC7] 10:09:38.739: mgmt:tx deauthentication [reason: authentication rejected by radius server (code:23)] to 00-13-E8-93-D4-19 (mgmt&lt;/STRONG&gt;&lt;BR /&gt; [ap7632-6F2CC7] 10:09:38.739: client:wireless client 00-13-E8-93-D4-19 changing state from [802.1x/EAP Auth] to [Roaming] (mgmt.c:635)&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;AP config&lt;/P&gt; &lt;P&gt;!&lt;BR /&gt; aaa-policy "Onboard RADIUS"&lt;BR /&gt; &amp;nbsp;authentication server 1 onboard self&lt;BR /&gt; !&lt;BR /&gt; !&lt;BR /&gt; wlan Extreme802-1xTest&lt;BR /&gt; &amp;nbsp;ssid Extreme802-1xTest&lt;BR /&gt; &amp;nbsp;vlan 241&lt;BR /&gt; &amp;nbsp;bridging-mode local&lt;BR /&gt; &amp;nbsp;encryption-type ccmp&lt;BR /&gt; &amp;nbsp;authentication-type eap&lt;BR /&gt; &amp;nbsp;use aaa-policy "Onboard RADIUS"&lt;BR /&gt; !&lt;BR /&gt; !&lt;BR /&gt; radius-group 802-1xTestGroup&lt;BR /&gt; &amp;nbsp;policy vlan 241&lt;BR /&gt; !&lt;/P&gt; &lt;P&gt;!&lt;BR /&gt; radius-user-pool-policy Extreme802-1x&lt;BR /&gt; &amp;nbsp;user Extreme password 0 Extreme group 802-1xTestGroup&lt;BR /&gt; !&lt;BR /&gt; radius-user-pool-policy Guest&lt;BR /&gt; &amp;nbsp;user Test password 0 Test group Guests&lt;BR /&gt; !&lt;BR /&gt; radius-server-policy "Onboard RADIUS"&lt;BR /&gt; &amp;nbsp;use radius-user-pool-policy Extreme802-1x&lt;BR /&gt; &amp;nbsp;use radius-user-pool-policy Guest&lt;BR /&gt; &amp;nbsp;authentication eap-auth-type peap-mschapv2 #(also tryed with “All”)&amp;nbsp;&lt;BR /&gt; &amp;nbsp;chase-referral&lt;BR /&gt; !&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 18:58:56 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66383#M6003</guid>
      <dc:creator>Alexandr_P</dc:creator>
      <dc:date>2020-02-06T18:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: Client failed 802.1x/EAP authentication on wlan</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66384#M6004</link>
      <description>&lt;P&gt;I would ensure that the radius policy is ,mapped to the AP (no AP Profile and/or Self config provided). I am assuming that no certificates have been generated.&lt;/P&gt; &lt;P&gt;For Win7 supplicant, you will need to manually configure the profile and ensure under Security/Choose a network authentication method is configure for Microsoft: Protocol EAP (PEAP) and and un-check Validate server certificate. Under Select Authentication Method, ensure Secured password (EAP-MSCHAP-v2) is selected and click on Configure and un-check box (Auto use my Windows logon name and password).&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 00:50:45 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66384#M6004</guid>
      <dc:creator>Christopher_Fra</dc:creator>
      <dc:date>2020-02-07T00:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Client failed 802.1x/EAP authentication on wlan</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66385#M6005</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Christopher, all configuration steps we have&amp;nbsp;made within Win7?&lt;/P&gt; &lt;P&gt;[ap7632-6F2CC7] 09:00:57.12: mgmt:rx auth-req from 00-13-E8-93-D4-19 on radio 1 (mgmt.c:4032)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.12: mgmt:tx auth-rsp to 00-13-E8-93-D4-19 on radio 1. status: success (mgmt.c:1348)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.16: mgmt:rx association-req from 00-13-E8-93-D4-19 on radio ap7632-6F2CC7:R2 signal-strength is -52dBm (mgmt.c:4006)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.16: client:MU 00-13-E8-93-D4-19 panBU enab_cap=00 00 00 00, supp_cap=00 00 00 00 (mgmt.c:3195)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.16: client:using cached vlan 241 for wireless client 00-13-E8-93-D4-19 (mgmt.c:3442)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.16: mgmt:Client 00-13-E8-93-D4-19 negotiated WPA2-EAP on wlan (Extreme802-1xTest) (mgmt.c:3534)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.16: mgmt:tx association-rsp success to 00-13-E8-93-D4-19 on wlan (Extreme802-1xTest) (ssid:Extreme802-1xTest) with ft&lt;BR /&gt;&lt;STRONG&gt;[ap7632-6F2CC7] 09:00:57.17: client:no pmkid from client 00-13-E8-93-D4-19 (mgmt.c:1243)&lt;/STRONG&gt;&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.17: client:state MU_STATE_DOT1X for client 00-13-E8-93-D4-19 (mgmt.c:1252)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.17: client:wireless client 00-13-E8-93-D4-19 changing state from [Roaming] to [802.1x/EAP Auth] (mgmt.c:635)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.17: eap:sending eap-code-request code 1, type 1 to 00-13-E8-93-D4-19 (eap.c:964)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.17: eap:sending eap-id-req to 00-13-E8-93-D4-19 (eap.c:993)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.17: client:transmitting roam notification for 00-13-E8-93-D4-19 (mgmt.c:349)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.17: client:os-info in credcache for 00-13-E8-93-D4-19 (OS:Unknown/Browser:Unknown/Type:Unknown) (credcache.c:1221)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.17: client:user-info in credcache for 00-13-E8-93-D4-19 (loyalty_app:0) (credcache.c:1306)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.54: eap:rx eap-start from 00-13-E8-93-D4-19 (eap.c:655)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.54: eap:sending eap-code-request code 1, type 1 to 00-13-E8-93-D4-19 (eap.c:964)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.54: eap:sending eap-id-req to 00-13-E8-93-D4-19 (eap.c:993)&lt;BR /&gt;&lt;STRONG&gt;[ap7632-6F2CC7] 09:00:57.64: client:rx deauthentication from 00-13-E8-93-D4-19 on radio 1 (mgmt.c:4043)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.64: mgmt:rx deauthentication (unspecified error (code:1)) from wireless client 00-13-E8-93-D4-19 on bss DC-B8-08-46-E&lt;/STRONG&gt;&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.64: client:wireless client 00-13-E8-93-D4-19 changing state from [802.1x/EAP Auth] to [Roaming] (mgmt.c:635)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.64: client:starting hold timer for 00-13-E8-93-D4-19 (mgmt.c:703)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.64: client:update_app_policy_name_to_credcache (credcache.c:1408)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.64: client:Adding app_policy_name to credcache and sync00-13-E8-93-D4-19 (credcache.c:1409)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.65: client:Credcache updated with app_policy None, for MU 00-13-E8-93-D4-19 (credcache.c:1423)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.65: client:cleared packet counters on client 00-13-E8-93-D4-19 (mgmt.c:764)&lt;BR /&gt; [ap7632-6F2CC7] 09:00:57.65: client:CHD: chd_stop_mu (chd.c:635)&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Any ideas?&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 17:07:42 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66385#M6005</guid>
      <dc:creator>Alexandr_P</dc:creator>
      <dc:date>2020-02-10T17:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: Client failed 802.1x/EAP authentication on wlan</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66386#M6006</link>
      <description>&lt;P&gt;Hi Alexandr,&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Quick guess - 802.11r enabled and Intel AC-xxxx card within the laptop?&lt;/P&gt; &lt;P&gt;Apparently, it might be helpful sometimes if you click on troubleshooting option in Windows when it pops up ‘unable to connect’. Then it will most probably fail but you can see detailed results and it shows at which point (from supplicant/STA point of view) it failed. It was really helpful to me when troubleshooting IdentiFi network once (and it was 11r case actually, so WPA2 4-way handshake couldn’t finish, I’m not sure if the logs here are relevant but just a guess).&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Hope that helps,&lt;/P&gt; &lt;P&gt;Tomasz&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 20:21:41 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66386#M6006</guid>
      <dc:creator>Tomasz</dc:creator>
      <dc:date>2020-02-14T20:21:41Z</dc:date>
    </item>
    <item>
      <title>Re: Client failed 802.1x/EAP authentication on wlan</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66387#M6007</link>
      <description>&lt;P&gt;Hi, Tomasz!&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;From Client side no specific info “missing keywords&lt;BR /&gt; use the search to find solutions to fix”.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;It’s enabled “Fast BSS Transition over DS” and disabled “Fast BSS Transition”.&lt;BR /&gt; But if I’ll disable 802.11r - it&amp;nbsp;will decrease time of client’s roaming.&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 20:58:38 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66387#M6007</guid>
      <dc:creator>Alexandr_P</dc:creator>
      <dc:date>2020-02-14T20:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: Client failed 802.1x/EAP authentication on wlan</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66388#M6008</link>
      <description>&lt;P&gt;Hi Aleksandr,&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;I see… I’ll be blind guessing right now. The best would be to somehow extract wireless module logs from the client device…&lt;/P&gt; &lt;P&gt;We see that it started authentication on 9:00:57. Within the same second (in about 500ms) it decided to deauth with reason code that tells nothing to the AP (&lt;A href="https://www.aboutcher.co.uk/2012/07/linux-wifi-deauthenticated-reason-codes/" target="_blank" rel="nofollow noreferrer noopener"&gt;https://www.aboutcher.co.uk/2012/07/linux-wifi-deauthenticated-reason-codes/&lt;/A&gt; ). At the same moment it changes its state from dot1x/EAP to roaming state. Is it possible that the wireless environment provides good and/or changing signal from multiple APs and client’s ‘roaming aggressiveness’ is set to high? I didn’t experience this kind of issue so far but seems to me like the device decided to roam before responding to eap-id-req (thus, before fulfilling the authentication). Same situation gives you “802.1X (Identity)” in Extreme Access Control if I remember well.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Hope that helps,&lt;/P&gt; &lt;P&gt;Tomasz&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 02:10:19 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66388#M6008</guid>
      <dc:creator>Tomasz</dc:creator>
      <dc:date>2020-02-19T02:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: Client failed 802.1x/EAP authentication on wlan</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66389#M6009</link>
      <description>&lt;P&gt;Hi, Tomasz!&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;About&amp;nbsp;‘roaming aggressiveness’:&lt;/P&gt; &lt;UL&gt;&lt;LI&gt;where I can see/configure it?&lt;/LI&gt; &lt;LI&gt;Interesting that I’m testing this with only 1 AP (second APP was off) and disabled forced 5GHz using. And still appear log messages about roaming. Why so?&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;[ap7632-6F2CC7] 09:17:46.907: client:wireless client 00-13-E8-93-D4-19 changing state from [Init] to [802.1x/EAP Auth] (mgmt.c:635)&lt;BR /&gt; [ap7632-6F2CC7] 09:17:46.907: eap:sending eap-code-request code 1, type 1 to 00-13-E8-93-D4-19 (eap.c:964)&lt;BR /&gt; [ap7632-6F2CC7] 09:17:46.907: eap:sending eap-id-req to 00-13-E8-93-D4-19 (eap.c:993)&lt;BR /&gt;&lt;STRONG&gt;[ap7632-6F2CC7] 09:17:46.907: client:transmitting roam notification for 00-13-E8-93-D4-19 (mgmt.c:349)&lt;/STRONG&gt;&lt;BR /&gt; [ap7632-6F2CC7] 09:17:46.907: client:os-info in credcache for 00-13-E8-93-D4-19 (OS:Unknown/Browser:Unknown/Type:Unknown) (credcache.c:1221)&lt;BR /&gt; [ap7632-6F2CC7] 09:17:46.907: client:user-info in credcache for 00-13-E8-93-D4-19 (loyalty_app:0) (credcache.c:1306)&lt;BR /&gt; [ap7632-6F2CC7] 09:17:47.21: eap:rx eap-start from 00-13-E8-93-D4-19 (eap.c:655)&lt;/P&gt; &lt;P&gt;…&lt;/P&gt; &lt;P&gt;[ap7632-6F2CC7] 09:18:02.155: mgmt:tx deauthentication [reason: authentication rejected by radius server (code:23)] to 00-13-E8-93-D4-19 (mgmt&lt;BR /&gt;&lt;STRONG&gt;[ap7632-6F2CC7] 09:18:02.156: client:wireless client 00-13-E8-93-D4-19 changing state from [802.1x/EAP Auth] to [Roaming] (mgmt.c:635)&lt;/STRONG&gt;&lt;BR /&gt; [ap7632-6F2CC7] 09:18:02.156: client:starting hold timer for 00-13-E8-93-D4-19 (mgmt.c:703)&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Also within this client issued messages:&lt;/P&gt; &lt;P&gt;[ap7632-6F2CC7] 09:18:02.135: radius:rx access-challenge from radius server for 00-13-E8-93-D4-19 (radius.c:3888)&lt;BR /&gt; [ap7632-6F2CC7] 09:18:02.136: eap:sending eap-code-request code 1, type 25 to 00-13-E8-93-D4-19 (eap.c:964)&lt;BR /&gt; [ap7632-6F2CC7] 09:18:02.136: eap:sending eap-req [eap_type:25(peap)] to 00-13-E8-93-D4-19 (eap.c:1001)&lt;BR /&gt; [ap7632-6F2CC7] 09:18:02.140: eap:rx eap pkt from 00-13-E8-93-D4-19 (eap.c:720)&lt;BR /&gt; [ap7632-6F2CC7] 09:18:02.141: radius:access-req sent to 127.0.0.1:1812 (attempt 1) for 00-13-E8-93-D4-19 (user:Extreme) (radius.c:3054)&lt;BR /&gt; [ap7632-6F2CC7] 09:18:02.142: radius:RAD_MSG_AUTHENTICATOR (radius.c:1182)&lt;BR /&gt; [ap7632-6F2CC7] 09:18:02.143: radius:rx access-challenge from radius server for 00-13-E8-93-D4-19 (radius.c:3888)&lt;BR /&gt; [ap7632-6F2CC7] 09:18:02.143: eap:sending eap-code-request code 1, type 25 to 00-13-E8-93-D4-19 (eap.c:964)&lt;BR /&gt; [ap7632-6F2CC7] 09:18:02.143: eap:sending eap-req [eap_type:25(peap)] to 00-13-E8-93-D4-19 (eap.c:1001)&lt;BR /&gt; [ap7632-6F2CC7] 09:18:02.148: eap:rx eap pkt from 00-13-E8-93-D4-19 (eap.c:720)&lt;BR /&gt; [ap7632-6F2CC7] 09:18:02.149: radius:access-req sent to 127.0.0.1:1812 (attempt 1) for 00-13-E8-93-D4-19 (user:Extreme) (radius.c:3054)&lt;BR /&gt; [ap7632-6F2CC7] 09:18:02.153: radius:RAD_MSG_AUTHENTICATOR (radius.c:1182)&lt;BR /&gt;&lt;STRONG&gt;[ap7632-6F2CC7] 09:18:02.153: radius:rx access-reject for 00-13-E8-93-D4-19 (radius.c:3781)&lt;BR /&gt; [ap7632-6F2CC7] 09:18:02.153: eap:sending eap-failure to 00-13-E8-93-D4-19 (eap.c:1009)&lt;BR /&gt; [ap7632-6F2CC7] %%%%&amp;gt;09:18:02.153: radius:alarm num_eap_f ++ 1 (radius.c:3859)&lt;/STRONG&gt;&lt;BR /&gt; [ap7632-6F2CC7] 09:18:02.153: client:clearing cached credentials for 00-13-E8-93-D4-19 (credcache.c:241)&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 15:51:39 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66389#M6009</guid>
      <dc:creator>Alexandr_P</dc:creator>
      <dc:date>2020-02-19T15:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: Client failed 802.1x/EAP authentication on wlan</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66390#M6010</link>
      <description>&lt;P&gt;Hi Alexandr,&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Roaming aggressiveness can be found in advanced settings of a WLAN adapter (at least if it’s Intel). Not sure of the second behavior…&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;In the logs you pasted now we see RADIUS rejects this time:&lt;/P&gt; &lt;P&gt;[ap7632-6F2CC7] 09:18:02.155: mgmt:tx deauthentication [reason: authentication rejected by radius server (code:23)]&lt;/P&gt; &lt;P&gt;and in the second block of logs:&lt;/P&gt; &lt;P&gt;[ap7632-6F2CC7] 09:18:02.153: radius:rx access-reject for 00-13-E8-93-D4-19 (radius.c:3781)&lt;/P&gt; &lt;P&gt;What is the authentication method? Credential-based? Are the credentials provided correctly, are they derived automatically from Windows user login, is the supplicant set for user authentication only?&lt;/P&gt; &lt;P&gt;You can also go to the RADIUS server to check for the reasons of these rejects.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Hope that helps,&lt;/P&gt; &lt;P&gt;Tomasz&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 16:27:36 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66390#M6010</guid>
      <dc:creator>Tomasz</dc:creator>
      <dc:date>2020-02-19T16:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Client failed 802.1x/EAP authentication on wlan</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66391#M6011</link>
      <description>&lt;P&gt;Internal RADIUS with internal base.&lt;/P&gt; &lt;P&gt;Win10 and Android clients normally connecting.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;!&lt;BR /&gt; aaa-policy "Onboard RADIUS"&lt;BR /&gt; &amp;nbsp;authentication server 1 onboard self&lt;BR /&gt; !&lt;BR /&gt; !&lt;BR /&gt; wlan Extreme802-1xTest&lt;BR /&gt; &amp;nbsp;ssid Extreme802-1xTest&lt;BR /&gt; &amp;nbsp;vlan 241&lt;BR /&gt; &amp;nbsp;bridging-mode local&lt;BR /&gt; &amp;nbsp;encryption-type ccmp&lt;BR /&gt; &amp;nbsp;authentication-type eap&lt;BR /&gt; &amp;nbsp;use aaa-policy "Onboard RADIUS"&lt;BR /&gt; &amp;nbsp;ip arp trust&lt;BR /&gt; &amp;nbsp;ip dhcp trust&lt;BR /&gt; !&lt;/P&gt; &lt;P&gt;!&lt;BR /&gt; radius-group 802-1xTestGroup&lt;BR /&gt; &amp;nbsp;policy vlan 241&lt;BR /&gt; !&lt;/P&gt; &lt;P&gt;!&lt;BR /&gt; radius-user-pool-policy Extreme802-1x&lt;BR /&gt; &amp;nbsp;user Extreme password 0 Extreme group 802-1xTestGroup&lt;BR /&gt; !&lt;/P&gt; &lt;P&gt;!&lt;BR /&gt; radius-server-policy "Onboard RADIUS"&lt;BR /&gt; &amp;nbsp;use radius-user-pool-policy "AAA MAC auth"&lt;BR /&gt; &amp;nbsp;use radius-user-pool-policy Extreme802-1x&lt;BR /&gt; &amp;nbsp;use radius-user-pool-policy Guest&lt;BR /&gt; &amp;nbsp;no ldap-group-verification&lt;BR /&gt; !&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 16:33:57 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/client-failed-802-1x-eap-authentication-on-wlan/m-p/66391#M6011</guid>
      <dc:creator>Alexandr_P</dc:creator>
      <dc:date>2020-02-19T16:33:57Z</dc:date>
    </item>
  </channel>
</rss>

