We migrated to version 14.1.1 on our PMP450 network about a week ago and noticed that some SM units doesn't always authenticate on their respective Access points. When I mean by some , it's really like 2 to 4% ... Really not that many.
I'm still troubleshooting the issue but it seems like the AP isn't sending the authentication packet to Radius for the SM in question .. I was running radius in Debug mode at the time and couldn't see any incoming records for the SM units mac address.
However , the AP still sends authentication packets for other SM units connected to it . I tested this by simply rebooting an SM that's currently connected. The problem seems to go away for a while when
Another thing worth mentioning is that when I change the SM units color code to an adjacent AP it registers , even with a much weaker signal.
Right now I'm thinking that the SM might have a stuck session on the AP since the SM actually registers when I reboot the AP. Although , the AP doesn't show any idle or stuck session on under the AP session tab.
I'm using the cambium wisp toolbox which seems to be using freeradius . I might be speaking under correction but I thin k it's using EAP-TLS... Well , that's at least what I gathered from looking at what Radius is returning when a SM authenticates. I'll capture some data the next time I run into this ... thankfully it seems like a rare event and only happend three or four times since I've activated radius authentication.... well , which I know of :) Which isn't bad taking in consideration that there's over 3K canopies on our network.
Hi Steph, When it happen next time , Please send some log as attachment on AP 1) Go-to Logs -> AP Session /Logs → AP Authorization State Machine / Logs → AP Authentication State Machine 2) Select SM LUID which is having problem 3) Copy the logs text. On a side note: I see you are using old VSA , can you try to configure using newly supported Cambium VSA? Refer to dictionary file, First do this on a test network before deploying widely.
I've run into this again but unfortunately one of my support guys rebooted the AP while I was busy doing a CNUT capture using the support tool so I'll have to wait for another oppertunity.
Anyway , there was no entries under the AP Authorization or AP Authentication logs for the SM that's trying to register. The only information I found for this particular unit were under the Statistics->SM Registration failures. Also , the SM registered emediatly once the AP came back online.
MAC : 0a-00-3e-a2-d2-52 No VCs 02/10/2016 : 16:43:45 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-a2-d2-52 No VCs 02/10/2016 : 16:27:56 SAST : Status : 7 Flag : 0
Also , not sure whether this is worth mentioning but the SM was first registered on another AP but with a much poorer signal so the technical guys re-aligned the SM to one of our other high sites which then resulted in the SM not registering under the new AP. It's like the AP isn't even trying to authenticate the SM against Radius since I'm not seeing any incomming sessions when Radius is running in Debug mode.
Hi Steph, Please check AP Eval page on SM to make sure that SM is actually seeing the AP, because once it see it should send a RADIUS access packet and from there we should see it.
Yup , I made sure when I spoke to the technician that the SM are able to see the actual AP.. Just jumped between registering / Scanning the whole time .. I also had my eyes on Radius while speaking to the tech and couldn't see any authentication requests while the SM tried to register.
Like I said , the only logging data I could find on the AP were these two records which corrosponded with the time the tech were there.
MAC : 0a-00-3e-a2-d2-52 No VCs 02/10/2016 : 16:43:45 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-a2-d2-52 No VCs 02/10/2016 : 16:27:56 SAST : Status : 7 Flag : 0
What's the memory corruption bug about mentioned in the patch notes for version 14.1.2(build 4) ? Any chance it's related to the issue I'm experiencing from time to time?
I'm busy doing a CNUT support capture for you for this specific AP , should have it ready in 20mins or so.
Also , you aske d me whether I've configured high priority vc for our SM units and at first I was rather sure I've disabled this but then when I looked under the Data VC tab found under statistics I noticed packets under the High priority queue. Shouldn't this be zero if high priority is disabled? ... Or am I missing something?
Can you please check session status list(Home → Session Status->Session Status List) tab , that will give clear picture of SM having Hi Priority VC or not. Under Power -> Downlink Rate , if Hi Priority Channel is there you should see VC 255 or lower number. Also check Event Log and AP Session Logs of AP to see if there are some error for that troubled LUID?
I'm presuming to check whether High priority Queue is enabled I should check
Home ->Session Status->Session Status List/configuration tab ? If so , then it's marked as NA on both High CIR (kbps) and High Priority Queue.
When I got to the Power Tab->Downlink Rate the VC number starts at VC18 and go up to VC134
The only really issue I'm seeing is with an SM we had issues with earlier... I did a CNUT capture while this was happing. The SM emediatly registed once the AP got rebooted.
MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 14:32:53 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 14:17:45 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 14:02:16 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 13:45:38 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 13:30:48 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 13:15:39 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 13:01:20 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 12:45:56 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 12:30:50 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 12:16:18 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 12:00:55 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 11:46:24 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 11:31:11 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 11:14:45 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 10:59:52 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 10:45:15 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-0f-5a RegReq no time ref 02/17/2016 : 10:27:20 SAST : Status : 20 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 10:26:42 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 10:10:47 SAST : Status : 7 Flag : 0 MAC : 0a-00-3e-b2-c6-e1 No VCs 02/17/2016 : 09:55:43 SAST : Status : 7 Flag : 0
Also , my event_log has some weird logs in it ... well weird like besides or the normal messages there's some content in there that I've never seen or noticed on some of our other access points.
Here's the log.
02/04/2016 : 09:26:15 SAST : :user=root; *System Log Cleared*; 02/04/2016 : 10:43:45 SAST : :Web user; user=root; Reboot from Webpage; 02/04/2016 : 10:43:50 SAST : :Forced reset; 02/04/2016 : 10:43:50 SAST : ******System Startup****** System Reset Exception -- User Initiated Reset Software Version : CANOPY 14.1.1 AP-DES Board Type : P12 Device Setting : 5.4GHz MIMO OFDM - Access Point - 0a-00-3e-a2-ec-eb - 5480.0 MHz - 20.0 MHz - 1/16 - CC 216 - 5.0 ms FPGA Version : 110815 FPGA Features : DES, Sched, US/ETSI; 02/04/2016 : 10:44:41 SAST : Acquired sync pulse from Power Port. 02/04/2016 : 15:15:21 SAST : :SESPARQ_PTYPE: Invalid luid 3066 02/04/2016 : 15:15:21 SAST : :Buf ptr = 0x0183d000