Link to home
Start Free TrialLog in
Avatar of operationsIT
operationsIT

asked on

Some wireless users on Windows 7 intermittently cannot connect to wireless. WLC error #DOT1X-3-INVALID_WPA_KEY_MSG_STATE:

Hello EE,

I see several errors in my WLC #DOT1X-3-INVALID_WPA_KEY_MSG_STATE: 1x_eapkey.c:848 Received invalid EAPOL-key M2 msg in START  state - invalid secure bit; KeyLen 40, Key type 1, client <MAC>

It appears some users can't get on wireless, but reloading drivers often resolves or reinstalling VPN.  Cisco reviewed and gave me this, but wondering if any others are having it or know of why it happens when other SSIDs do work would think it's WLC configuration but client seems to be the issue

Error Message    %DOT1X-3-INVALID_WPA_KEY_MSG_STATE: Received invalid [chars] msg in[chars] state - [chars]; len [int], key type [int], client[hex]:[hex]:[hex]:[hex]:[hex]:[hex]
 
Explanation    Client authentication failed because of an authentication protocol error between the client and access point.
 
Recommended Action    If the problem persists, try upgrading the client driver software or using different client software to isolate the cause. Also investigate possible intruder activity.
 
Reference Link: http://www.cisco.com/c/en/us/td/docs/wireless/controller/message/guide/controller_smg/msgs4.html
ASKER CERTIFIED SOLUTION
Avatar of Satyendra Sharma
Satyendra Sharma
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Which version of code are you running on the WLC (and which WLC model do you have)?
Avatar of operationsIT
operationsIT

ASKER

We have the 5508 controller and confirmed we were on the latest recommendation by cisco last week
Ok, which version did they recommend?
8.0.120.0
That's the latest 'stable' release but that doesn't mean it's bug-free.

Have you tried with a different version?
Not yet as we were told to upgrade because of the issue and it didn't fix it so before I do it again with same results wanted to ping others to see of they had similar issues and what they experienced or did to resolve
So you had the issue with a previous version, then you upgraded?

What version were you running before the upgrade?
Yes with both versions

I believe it was 7.3.112 or 113
Normally I would say ok fair enough, but 7.3 is probably the worst version ever! 8.0 isnt without its issues either.

If it were me I'd be putting 7.6.130.0 or 7.4.121.0 on the WLC to test, then if it's still the same try getting some help from the client's NIC vendor.
Have you experienced this as I"m curious as Satyendra Sharma indicated and I've been hearing from others as well regarding driver related.
Have you tried updating driver yet?
I have seen issues with 7.3.  Cisco pulled it pretty quickly actually.  You can't download it any more.

I've seen a few support issues with 8.x code which relate to similar issues.

If there is a readily available driver that you can try which is different to what you have on the clients now you should try that.  Otherwise you'll have to approach the vendor to see if they can provide a custom driver for you to try.
Updating the driver did it but I'm wondering if anyone knows why when I can connect to other SSID fine is this the resolve?
Only resolve so far is driver update