- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Wi-Fi disassociation reason code when password based RADIUS authentication fails
We use Cisco Meraki APs with WPA2 Enterprise authentication againsts remote RADIUS server with EAP-TTLS + PAP.
When user provides wrong credentials (bad password), RADIUS sends Access-Reject message to the AP.
AP the disassociates the endpoint providing reason code 8. Reason code 8 means "Disassociated because sending STA is leaving or has left Basic Service Set (BSS)." That is a very generic response. In the list of possible reason codes there is also code 23: "IEEE 802.1X authentication failed.". At first look this seems to be more appropriate code to send.
Questions:
- Is code 23 suitable for this situation?
- Is Cisco Meraki AP capable of sending code 23?
- Why does not AP send the code 23?
Solved! Go to solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey Raphael. Thank you for the reply.
I think I was mistaken (or confused or something has changed) because last time I tried (week ago) I got the correct reason code from Meraki AP.
So at this point I believe Apple and its UI is to blame.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sorry for the late reply.
What MR firmware are you running ?
Were you able to capture the frame and confirm that the AP is really sending a frame with code '8' ?
Could the client be getting a code '23' , upon receving that code simply leaves the AP with code '8' ?
I think you should open a ticket and reproduce the issue and provide them a capture.
EDITv3 : This was solved under 28.7 :
- When an Apple client enters an incorrect PSK the AP responds with a disassociation response instead of deauthentication response, resulting in multiple failed connection attempts from the client (Wi-Fi 5 Wave 2 APs)
Might be worth a try to upgrade and test it !
Good luck
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Update :
Took me a minute to find a code '23' :
MR 28.7.1
SSID configured with WPA enterprise and using Cisco ISE as Radius server. Client didn't provide a valid certificate.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey Raphael. Thank you for the reply.
I think I was mistaken (or confused or something has changed) because last time I tried (week ago) I got the correct reason code from Meraki AP.
So at this point I believe Apple and its UI is to blame.
