FAQ and Troubleshooting Guide for the CiscoWorks WLSE and WLSE Express, 2.11
Fault Descriptions
Downloads: This chapterpdf (PDF - 416.0KB) The complete bookPDF (PDF - 1.52MB) | Feedback

Fault Descriptions

Table Of Contents

Fault Descriptions

Access Point /Bridge Faults

Radio Interface Faults

IDS (Intrusion Detection System) Faults

WLSE Faults

AAA Server Faults

Switch Faults

Router Fault


Fault Descriptions


This section provides the following information on the faults displayed in Faults > Display Faults. The following information is provided:

Fault—The fault as it appears in the Display Faults table.

Explanation—An explanation as to why the fault occurred.

Related Setting—The threshold or policy you assigned to devices under Faults > Manage Fault Settings or IDS > Manage IDS Settings, when applicable.

Recommended Action—An action that can be taken to clear the displayed fault.

Fault tables are provided for each device type:

Access Point /Bridge Faults

Radio Interface Faults

IDS (Intrusion Detection System) Faults

WLSE Faults

AAA Server Faults

Switch Faults

Router Fault

Access Point /Bridge Faults

Table 2-1 Access Point Faults 

Fault Description
Type
Explanation
Related Setting
Recommended Action

AP CPU utilization is Degraded (utilization %)

IOS

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: AP CPU utilization is Ok.

Manage Fault Settings > Access Point/Bridge Thresholds > CPU Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

AP CPU utilization is Overloaded (utilization %)

IOS

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: CPU utilization is Ok.

Manage Fault Settings > Access Point/Bridge Thresholds > CPU Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

AP is in a Degraded state number associated clients

Non-IOS

The fault threshold set for the degraded state has been exceeded.

When this fault is cleared, the following message displays: AP is in OK state.

Manage Fault Settings > Access Point/Bridge Thresholds > Associated Clients

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

AP is in an Overloaded state number associated clients

Non-IOS

The fault threshold set for the overloaded state has been exceeded.

When this fault is cleared, the following message displays: AP is in OK state.

Manage Fault Settings > Access Point/Bridge Thresholds> Associated Clients

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

AP is not registered with a WDS

IOS

The managed IOS access point is not registered with any WDS.

For Radio Manager functionality to work, all IOS access points must register with a WDS. If an access point is not registered, it will be excluded from all the Radio Manager procedures, which will provide incorrect results.

Manage Fault Settings > Access Point/Bridge > Registration Error

Verify that the WLCCP AP credentials are configured correctly so that the AP can register with a WDS in its subnet.

For more information, see the managing devices information in the online help or the User Guide for the CiscoWorks Wireless LAN Solution Engine, Release 2.11.

AP memory utilization is Degraded (utilization %)

IOS

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: AP memory utilization is Ok.

Manage Fault Settings > Access Point/Bridge Thresholds > Memory Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

AP memory utilization is Overloaded (utilization %)

IOS

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: AP memory utilization is Ok.

Manage Fault Settings > Access Point/Bridge Thresholds > Memory Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

AP registered with an Unmanaged WDS: ipAddressOfTheUnManagedWDS

IOS

AP is registered with a WDS but that WDS is not managed by WLSE.

When this fault is cleared, the following message displays: AP registered with a managed WDS.

Manage Fault Settings > Access Point/Bridge > Registration Error

Manage the WDS.

Broadcast Key Rotation is disabled

Non-IOS and IOS

The broadcast key rotation has been disabled.

When this fault is cleared, the following message displays: Broadcast Key Rotation is enabled.

Manage Fault Settings > Access Point/Bridge Policies > Key Rotation per VLAN

Log in to the access point and enable the broadcast key rotation interval.

Device state is rogue access point

IOS

The WLSE detected a rogue access point. (This is an access point that is not being managed and is unknown to the WLSE.)

IDS > Manage IDS Settings > Rogue AP Detection

or

IDS > Manage Rogues

Use the fault details page to mark it friendly if the AP is known, or to delete it from the WLSE database if it is an unknown AP.

Device was not reachable via SNMP

Non-IOS and IOS

The SNMP Agent could be down.

Using the SNMP threshold setting, you configure the WLSE to poll the sysUpTime MIB object periodically. If at any time the WLSE fails to poll this MIB object, the WLSE generates this fault.

Also, if while polling any other MIB objects for other fault policies or thresholds associated with the device, the WLSE observes the device is SNMP unreachable, it generates this fault.

And lastly, during rediscovery if a previously-discovered device is found to be SNMP unreachable, the WLSE generate this fault.

When this fault is cleared, the following message displays: Device was reachable via SNMP.

Manage Fault Settings > Access Point/Bridge Thresholds > SNMP Reachable

Make sure SNMP is enabled on the device and that the agent is not down.

Take a MIB walk of the device and ensure that the sysUpTime returns a non-zero value, which indicates that the device is reachable.

The SNMP community string in the access point has been changed, and then a discovery job is run.

Not applicable.

Change the SNMP community string on the WLSE to match the new community string on the access point, then run discovery again.

EAP per SSID for Cisco-Supplicant is disabled

Non-IOS and IOS

The Network EAP or the Open authentication is disabled on this SSID.

When this fault is cleared, the following message displays: EAP per SSID for Cisco Supplicant is enabled.

Manage Fault Settings > Access Point/Bridge Policies > EAP Per SSID Enforced for Cisco-
Supplicant

Log in to the access point and enable both Network EAP and Open authentication on that SSID.

EAP per SSID for Non-Cisco-Supplicant is disabled

Non-IOS and IOS

The Network EAP or the Open authentication is disabled on this SSID.

When this fault is cleared, the following message displays: EAP per SSID for Non-Cisco Supplicant is enabled.

Manage Fault Settings > Access Point/Bridge Policies > EAP Per SSID Enforced for Non-Cisco-
Supplicant

Log in to the access point and enable both Network EAP and Open authentication on that SSID.

EAP per SSID for Mixed-Cisco-Supplicant is disabled

Non-IOS and IOS

The Network EAP or the Open authentication is disabled on this SSID.

When this fault is cleared, the following message displays: EAP per SSID for Cisco Supplicant is enabled.

Manage Fault Settings > Access Point/Bridge Policies > EAP Per SSID Enforced for Mixed-Cisco-
Supplicant

Log in to the access point and enable both Network EAP and Open authentication on that SSID.

Ethernet bandwidth utilization is Degraded (utilization %)

Non-IOS and IOS

The fault threshold set for the degraded state has been exceeded.

When this fault is cleared, the following message displays: Ethernet bandwidth utilization is OK.

Manage Fault Settings > Access Point/Point Thresholds > Ethernet Port Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Ethernet bandwidth utilization is Overloaded (utilization %)

Non-IOS and IOS

The fault threshold set for the overloaded state has been exceeded.

When this fault is cleared, the following message displays: Ethernet bandwidth utilization is OK.

Manage Fault Settings > Access Point/Bridge Thresholds > Ethernet Port Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Excessive frame counts:

Action

Association

Authentication

Deauthentication

Disassociation

Probe

Reassociation

 

See IDS (Intrusion Detection System) Faults

   

Firmware version policy violation (version number)

Non-IOS and IOS

The wrong version number for policy checking has been entered.

When this fault is cleared, the following message displays: Firmware version is valid.

Manage Fault Settings > Access Point/Bridge Policies > Firmware Version

Make sure that the firmware version that is entered in the policy setting matches the firmware version on the access point.

The access point is running an unauthorized firmware version.

When this fault is cleared, the following message displays: Firmware version is valid.

Make sure that you have entered authorized versions in the policy setting.

Update the firmware on the access point to an authorized version.

HotStandBy is active

Non-IOS and IOS

The access point that is configured for hot standby has become active.

The following conditions could cause the hot standby access point to become active: the primary access point is down, the Ethernet port is down, or the Radio port is down.

When this fault is cleared, the following message displays: HotStandBy is disabled.

Manage Fault Settings > Access Point/Bridge Policies > HotStandby Status

For non-IOS access points:

1. Check the primary access point, the Ethernet port, or the Radio port to see why the hot standby access point has been activated.

2. Correct the condition. For example, if the Radio Port on the formerly active access point was in a disabled state, then enable it using the access point GUI.

3. Launch the GUI for access point that is currently in Active Takeover mode.

4. Select the Hot Standby section and click Start Hot Standby mode to reconfigure the access point to Hot Standby mode.

       

For IOS access points:

1. Check the primary access point, the Ethernet port, or the Radio port to see why the hot standby access point has been activated.

2. Correct the condition. For example, if the Radio Port on the formerly active access point was in a disabled state, then enable it using the access point GUI.

3. Launch the GUI for access point that is currently in Active Takeover mode.

4. Select Hot Standby, click Disabled , then click Apply.

5. Click Enabled, then enter the Radio MAC address of Monitored Radio Port, leave the Polling interval and Timeout for Each Polling fields blank,.

6. Click Apply to reconfigure the access point to Hot Standby mode.

HTTP access is enabled

Non-IOS

HTTP has been enabled on the access point.

When this fault is cleared, the following message displays: HTTP access is disabled.

Manage Fault Settings > Access Point/Bridge Policies > HTTP Disabled

Log in to the access point and disable HTTP access.

HTTP access without login is enabled

Non-IOS

The allowBrowseWithoutLogin setting on the access point is set.

When this fault is cleared, the following message displays: HTTP access without login is disabled.

Manage Fault Settings > Access Point/Bridge Policies > HTTP Authentication (NonIOS)

Log in to the access point and disable the allowBrowseWithoutLogin setting.

Inconsistent state found for query queryType

IOS

One or more configuration values of the AP/BR are either out-of-range or are in conflict with another configuration value. The fault description and corresponding swan.log entry provide details about the suspect value.

When a device is declared to have an inconsistent configuration, it cannot be manipulated by Radio Management. The situation is especially problematic if the questionable device is a WDS because that, indirectly, means that all APs registered with that WDS are not available to Radio Management either.

Not applicable.

To resolve an inconsistent configuration, several possibilities exist:

It is possible that the most recent Inventory failed for the device. Re-running inventory might clear the condition.

If the configuration value being contested is user-editable, you can correct the problem using the WLSE templates, the AP/BR GUI, or the AP/BR CLI.

If the configuration value being contested is not user-editable, this is probably an IOS error. You will need to upgrade the affected AP/BR to the most recent version of IOS.

MIC is disabled for the VLAN number

IOS

MIC is not enabled for the selected VLAN on the access point.

When the fault is cleared, the following message displays: MIC is enabled.

Manage Fault Settings > Access Point/Bridge Policies > MIC per Vlan (IOS)

Log into the access point and enable the VLAN. Then, using the WLSE fault settings, enable the MIC for that VLAN.

PSPF is disabled

Non-IOS

The PSPF port has been disabled.

PSPF (Publicly Secure Packet Forwarding) is a feature that prevents client devices associated to a bridge or access point from inadvertently sharing files with other client devices on the wireless network.

When the fault is cleared, the following message displays: The PSPF is enabled.

Manage Fault Settings > Access Point/Bridge Policies > PSPF Enabled (Non-IOS)

Log in to the access point and enable the PSPF setting.

Radar Detected on Channel origChannel

IOS

On its current channel, the AP detected likely contention with a radar device, so it needs to leave that channel and find another. The AP will automatically scan for another channel, but might be unable to accept associations for one minute. This one minute delay is the required scan time on another Dynamic Frequency Selection channel that must elapse before the AP can accept associations.

When this fault is cleared, the following message displays: No radar detected on new channel newChannel

Manage Fault Settings > Radio-802.11a Policies > Dynamic Frequency Selection (DFS)

The WLSE will automatically handle the assignment of another channel for those APs affected by the Radar Detection. However, if these faults become common, you should re-run Assisted Configuration (RPG) soon after a DFS event has occurred (or just manually deselect the DFS channel from the Assisted Config Wizard). This will reorganize the site to avoid the affected channel and make future conflicts likely.

SNMP query received authorization error response

Non-IOS

The access point's user community strings do not have Admin, Ident, Firmware, SNMP privileges. The WLSE might not be able to access some SNMP information from the access point that requires these privileges.

When the fault is cleared, the following message displays: Device was reachable via SNMP.

Manage Fault Settings > Access Point/Bridge Thresholds > SNMP Reachable

Make sure the SNMP community string set on the WLSE (Devices > Discover > Device Credentials > SNMP Communities) is the same as the string set on the access point (Setup > Security > User Information).

Telnet access is enabled

Non-IOS

Telnet has been enabled on the access point.

When this fault has been cleared, the following message displays: Telnet access is disabled

Manage Fault Settings > Access Point/Bridge Policies > Telnet Disabled

Log in to the access point and disable the Telnet access setting.

User capabilities are not enforced

Non-IOS

The enableUserMgr setting is not set on the access point.

When this fault has been cleared, the following message displays: User capabilities are enforced.

Manage Fault Settings > Access Point/Bridge Policies > User Manager Enforced (NonIOS)

Log in to the access point and enable the User Mgr setting.

Vlan WEP key length policy violation

Non-IOS and IOS

The WEP key length for the selected VLAN setting has been violated.

When this fault has been cleared, the following message displays: Vlan WEP key length is ok.

Manage Fault Settings > Access Point/Bridge Policies > WEP Encryption per Vlan

Make sure the WEP key length selected in the policy setting matches the access point settings.

WDS appears down.

IOS

The WLSE failed to receive "keep active" messages from the WDS. This happens when the WDS is down or when the network is down.

Manage Fault Settings > WDS > WLSE-WDS Link Status

Check the network connectivity, and the WDS status.

WDS Registered with another WLSE (IPaddress)

IOS

The WDS is registered with a different WLSE.

Manage Fault Settings > WDS > Authentication Failures

Determine which WLSE is supposed to manage that WDS from an RM perspective. Then modify the wnm configuration on the WDS to point to the correct WLSE.

For more information, see the managing devices information in the online help or the User Guide for the CiscoWorks Wireless LAN Solution Engine, Release 2.11.

WEP is disabled

IOS

WEP is not enabled for the VLAN defined on the access point. (Note that the VLAN number is displayed in the Type column under Faults > Display Faults.)

When the fault is cleared, the following message displays: WEP is enabled.

Manage Fault Settings > Access Point/Bridge Policies > WEP per Vlan (IOS)

Make sure you have set the policy correctly for the VLAN.

WLSE failed to authenticate with WDS.

IOS

Authentication required to open a WLCCP channel between the WLSE and the WDS failed.

Manage Fault Settings > WDS > Authentication Failures

Verify that the WLSE credentials used to authenticate with the WDS are correct.

For more information, see the managing devices information in the online help or the User Guide for the CiscoWorks Wireless LAN Solution Engine, Release 2.11.


Radio Interface Faults

Table 2-2 Radio Interface Faults 

Fault Description
Type
Explanation
Related Setting
Recommended Action

AP is in a Degraded state number associated clients

IOS

The fault threshold set for the degraded state has been exceeded.

When this fault is cleared, the following message displays: AP is in OK state.

Manage Fault Settings > Radio-802.11x Thresholds > Associated Clients (IOS)

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

AP is in an Overloaded state number associated clients

Non-IOS and IOS

The fault threshold set for the overloaded state has been exceeded.

When this fault is cleared, the following message displays: AP is in OK state.

Manage Fault Settings > Thresholds > Access Point > Associated Clients

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Appeared up|down. Compensated for by Up/Down radio(s).

WLSE

The indicated radio appeared up or down on this AP, so other radios were modified to maintain coverage.

After self healing has been applied to the other AP, this fault indicates the radio that had the failure.

Radio Manager > Self Healing > Finish

Display the Self Healing fault details page, then select the document with the eyeglasses. A list of radios with the old and new power settings is displayed. These radios can compensate for the downed or recovered radio. If self healing is configured to automatically apply changes, then these are the values that were applied. If self healing is configured for manual application of the compensation calculations, then the recommended values are shown with an option to apply them to the indicated radios.

Check the radio to determine why it is down and resolve the problem.

Broadcast SSID is enabled.

Non-IOS and IOS

The broadcast mode for the SSID on the interface has been disabled.

When this fault is cleared, the following message displays: Broadcast SSID is disabled.

Manage Fault Settings > Radio-802.11x Policies > Broadcast Disabled

Log in to the access point and disable the broadcast mode.

Broadcast is enabled for Radio-x SSID ssid fault.

IOS

An SSID, which you do not want broadcast, is being broadcast.

When this fault is cleared, the following message displays: Broadcast is disabled for Radio-x SSID ssid fault.

Manage Fault Settings > Radio-802.11x Policies > Broadcast SSID (IOS)

Log in to the access point and make sure that the that the SSID, which is in WLSE's "Do not Broadcast SSID" list is not selected for Broadcast on the access point.

Client association rate is Degraded number per minute

Non-IOS and IOS

The fault threshold set for the degraded state has been exceeded.

When this fault is cleared, the following message displays: Client association rate is OK.

Manage Fault Settings > Radio-802.11x Thresholds > Association Rate

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Client association rate is Overloaded number per minute

The fault threshold set for the overloaded state has been exceeded.

When this fault is cleared, the following message displays: Client association rate is OK.

Compensation determination is in progress

WLSE

The WLSE determined that a radio was down or back up. Self Healing is attempting to compensate for the failed or recovered radio.

Not applicable.

There is no action necessary; Self Healing is attempting to adjust the power on other neighboring radios (which can be on other floors) to maintain coverage.

Compensation calculation did not complete due to errors

WLSE

Errors forced the cancellation of Self Healing compensation calculations.

Not applicable.

Display the Self Healing fault details page, then select the document with the eyeglasses. The error messages displayed on this page will explain the problem.

Determine the action necessary to clear the fault condition.

Compensation finished with errors

WLSE

Self Healing compensation calculations finished but there were errors. For example, a power change cannot be applied to a radio because:

1) The community strings for the device are wrong for the AP.

2) AP is down or unreachable

3) Wrong configuration set on the radio

Not applicable.

Determine the action necessary to clear the fault condition.

For example, if WLSE determines that five radios are needed to compensate for a down radio and only one has bad community strings, the changes to the other four radios will take place.

Compensation did not complete due to timeout of timeout (mins)

WLSE

Self Healing compensation calculations took longer than 30 minutes.

Not applicable.

Display the Self Healing fault details page, then select the document with the eyeglasses. The error messages displayed on this page will explain the problem.

Determine the action necessary to clear the fault condition.

EAP is disabled

Non-IOS and IOS

The EAP per SSID has been disabled.

When this fault is cleared, the following message displays: EAP is enabled

Manage Fault Settings > Radio-802.11x Policies >
EAP Enforced for
Cisco Supplicant/
Non-Cisco Supplicant/
Mixed-Cisco Supplicant

Log in to the access point and enable the Network EAP and Open authentication.

Infrastructure SSID policy violation

IOS

The infrastructure SSID does not match the infrastructure SSID set on the access point.

When this fault is cleared, the following message displays: Infrastructure SSID is valid .

Manage Fault Settings > Radio-802.11x Policies > Infrastructure SSID (IOS)

Log in to the access point and make sure the WLSE's Infrastructure SSID matches the access point infrastructure SSID

Not Monitored because: reason, Ignored

WLSE

To qualify for Self Healing, an AP must:

Enable Radio Monitoring on both Serving and Non-Serving channels.

Be configured with a WDS that is authenticated with the WLSE (link status must be okay too).

 

The faults will clear when the WDS/WLSE is reauthenicated and Radio Monitoring is enabled correctly.

Number of CCMP Replay Discarded is Overloaded.

IOS

The fault threshold set for the overloaded state has been exceeded.

When the fault is cleared, the following message displays: Number of CCMP Replays Discarded is OK.

IDS > Manage IDS Settings > IDS-802.11x > CCMP Replays Discarded [IOS]

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Packet Error is in Degraded state (error rate %)

Non-IOS and IOS

The fault threshold set for the degraded state has been exceeded.

When this fault is cleared, the following message displays: Packet Error is in OK state.

Manage Fault Settings > Radio-802.11x Thresholds > RF Port Packet Errors

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

The radio interfaces on the devices may be very under utilized, which can trigger the degradation problem.

For example, if a total of three packets are sent over the radio, and two of them are corrupt, the percentage would be 2/3 = 66%, and could trigger the alarm.

Remove the alarm from the profile associated with these devices.

Packet Error is in Overloaded state (error rate %)

The fault threshold set for the overloaded state has been exceeded.

When this fault is cleared, the following message displays: Packet Error is in OK state.

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Port is administratively set to down

Non-IOS and IOS

The port has been set to Down by the administrator.

When this fault is cleared, the following message displays: Port is up

Manage Fault Settings > Radio-802.11x Thresholds > RF Port Status

There is no action necessary; the port has been deliberately shut down.

Port is down

Non-IOS and IOS

The port is operationally down.

When this fault is cleared, the following message displays: Port is up

Manage Fault Settings > Radio-802.11x Thresholds > RF Port AdminStatus

Check the device to determine why the port is down.

If you have added or removed an interface from an access point, the WLSE might generate an erroneous fault. See What are the results of adding or removing an interface from an access point?.

The fault RF Port AdminStatus is enabled by default and must remain enabled with a default polling time of 5 minutes. Self healing ignores any radio set as administratively down, but this can only be detected if fault polling is enabled.

PSPF is disabled

IOS

The PSPF port has been disabled.

PSPF (Publicly Secure Packet Forwarding) is a feature that prevents client devices associated to a bridge or access point from inadvertently sharing files with other client devices on the wireless network.

When the fault is cleared, the following message displays: The PSPF is enabled.

Manage Fault Settings > Access Point/Bridge Policies > PSPF Enabled (IOS)

Log in to the access point and enable the PSPF setting.

Requires healing: %reason%.

WLSE

The indicated radio appeared up or down on this AP. Self Healing has been started.

After compensation results have been for other radios, this fault indicates the radio that had the failure.

Not applicable.

There is no action necessary; Self Healing will attempt to adjust the power on other radios on the floor to maintain coverage.

Possible reasons self healing is required:

An applicable radio is avoiding or no longer avoiding radar.

An AP has unregistered or re-registered with its WDS

A radio that had its beacons heard by other radios has not been heard by any radio (and vice-versa)

Retry Count rate is Degraded number per minute

Non-IOS and IOS

The retry count rate alarm indicates if the wireless medium is congested. The alarm will be raised if the MSDU retransmission rate per minute is greater than the specified threshold. For example, if the overloaded state is set to greater than 90, a fault will be raised for an interface that has more than 90 MSDUs that required retransmission in a minute.

When the fault is cleared, the following message displays: Retry Count rate is OK.

Manage Fault Settings > Radio-802.11x Thresholds > Max Retry Count

Verify the threshold settings. There could be too many clients or access points located near the radio interface for which fault is raised. Clear the alarm and increase the threshold, or reduce the polling time.

Retry Count rate is Overloaded number per minute

RF bandwidth utilization is Degraded (utilization %)

Non-IOS and IOS

The fault threshold set for the degraded state has been exceeded.

When the fault is cleared, the following message displays: RF bandwidth utilization is OK

Manage Fault Settings > Radio-802.11x Thresholds > RF Port Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

RF bandwidth utilization is Overloaded (utilization %)

The fault threshold set for the overloaded state has been exceeded.

When the fault is cleared, the following message displays: RF bandwidth utilization is OK

Serving and non-serving channel Radio Monitoring must be enabled

WLSE

For Self Healing to work, all radios on the floor must be configured with Radio Monitoring. The fault will indicate which radios need to be configured with both serving and non serving radio monitoring.

When the fault is cleared, the following message displays: Qualifies for Self Healing Monitoring.

Not applicable.

Enable Radio Monitoring for both serving and non-serving channels.

Or, use the Location Manager tool, Verify RM Capability.

WEP Error is in Degraded state (error rate %)

Non-IOS and IOS

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: WEP Error is in OK state

Manage Fault Settings > Radio-802.11x Thresholds > RF Port WEP Errors

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

WEP Error is in Overloaded state (error rate %)

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: WEP Error is in OK state

WEP is disabled

Non-IOS and IOS

WEP has been disabled.

When this fault has been cleared, the following message displays: WEP is enabled.

Manage Fault Settings > Radio-802.11x Policies > WEP Enforced (Non-IOS)

Log in to the access point and enable WEP.

WEP key length policy violation

Non-IOS and IOS

The WEP key length setting has been violated.

When this fault has been cleared, the following message displays: WEP key length is OK.

Manage Fault Settings > Radio-802.11x Policies > WEP Key Length

Check the WEP key settings on the interface to make sure they match the WLSE settings.


IDS (Intrusion Detection System) Faults

Table 2-3 IDS Faults 

Fault Description
Type
Explanation
Related Setting
Recommended Action

802.11-B/G Interference Detected

- or -

802.11-A Interference Detected

IOS

The WLSE detected a non-802.11 interference.

IDS > Manage IDS Settings > Interference Detection

Look at the fault description to determine which AP reported the interference, then take corrective action by removing the interference source.

Ad-hoc network creation detected

Non-IOS and IOS

An ad-hoc network was formed by some wireless clients. One of your infrastructure APs or other clients sent this information to the WLSE via your WDS setup.

IDS > Manage IDS Settings > Ad-hoc Network Detection

If the information is available, the WLSE will show the clients that are participating in the network (and that it can detect) in the fault details page. Use the Location Manager to find these APs and verify that this is not a security issue.

CCMP DecryptErrorsClient is detected

IOS

The fault threshold set has been exceeded.

IDS > Manage IDS Settings > CcmpDecryptErrorsClient (IOS)

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

CCMP Replay Client is detected

IOS

The fault threshold set has been exceeded.

When this fault is cleared, the following message displays: There is no CCMP Replay detected

IDS > Manage IDS Settings > General Settings > CcmpReplaysClient (IOS)

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Client association rate is Degraded number per minute

Non-IOS and IOS

The fault thresholds been exceeded.

When this fault is cleared, the following message displays: Client association rate is OK.

IDS > Manage IDS Settings > IDS-802.11x > Authentication Error Rate

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition

Client authentication error rate is Degraded number per minute

Non-IOS and IOS

The fault threshold set for the degraded state has been exceeded.

When this fault is cleared, the following message displays: Client association error rate is OK.

IDS > Manage IDS Settings > IDS-802.11x > Authentication Error Rate

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Client authentication error rate is Overloaded number per minute

The fault threshold set for the overloaded state has been exceeded.

When this fault is cleared, the following message displays: Client association error rate is OK.

Client TKIP RemoteMICFailure is detected

IOS

A wireless client has detected a MIC failure. The MIB value that is polled is cDot11WidsTkipRemoteMicFailures.

When this fault is cleared, the following message displays: There is no TKIP RemoteMICFailure detected.

IDS > Manage IDS Settings > General IDS Settings > TkipRemoteMicFailureClient (IOS)

Occasionally MIC failures can occur during key rotation. To diagnose the problem, you should:

Check the IOS version.

Enable 802.1x logs on the AP.

Perform an SNMP walk of cDot11WidsProtectFailClientTable to determine which clients are reporting the TKIP MIC failure. If just one client is reporting the failure, it could be a client issue.

EAPOL FLOOD is detected (Flood count: floodcount)

IOS

The fault threshold has been exceeded.

When this fault is cleared, the following message displays: There is no EAPOL Flood detected.

IDS > Manage IDS Settings > General IDS Settings > EAPOL Detection [IOS}

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition

Excessive Action Frames in Channel: channel [Frames: framecount,Interval:windowsize]

IOS

The fault thresholds been exceeded.

When this fault is cleared, the following message displays: Excessive Action Frames not present in Channel.

IDS > Manage IDS Settings > General IDS Settings > Excessive Management Frame Detection

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Excessive Action Frames from STA: station [Frames: framecount,Interval:windowsize]

IOS

The fault thresholds been exceeded.

When this fault is cleared, the following message displays: Excessive Action Frames from STA: station not present

IDS > Manage IDS Settings > General IDS Settings > Excessive Management Frame Detection

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Excessive Association Frames in Channel: channel [Frames: framecount,Interval:windowsize]

IOS

The fault thresholds been exceeded.

When this fault is cleared, the following message displays: Excessive Association Frames not present in Channel: channel

IDS > Manage IDS Settings > General IDS Settings > Excessive Management Frame Detection

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Excessive Association Frames from STA: station [Frames: framecount,Interval:windowsize]

IOS

The fault thresholds been exceeded.

When this fault is cleared, the following message displays: Excessive Association Frames from STA: station not present

IDS > Manage IDS Settings > General IDS Settings > Excessive Management Frame Detection

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Excessive Authentication Frames in Channel: channel [Frames: framecount,Interval:windowsize]

IOS

The fault thresholds been exceeded.

When this fault is cleared, the following message displays: Excessive Authentication Frames not present in Channel.

IDS > Manage IDS Settings > General IDS Settings > Excessive Management Frame Detection

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Excessive Authentication Frames from STA: station [Frames: framecount,Interval:windowsize]

IOS

The fault thresholds been exceeded.

When this fault is cleared, the following message displays: Excessive Authentication Frames from STA: station not present

IDS > Manage IDS Settings > General IDS Settings > Excessive Management Frame Detection

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Excessive Deauthentication Frames in Channel: channel [Frames: framecount,Interval:windowsize]

IOS

The fault thresholds been exceeded.

When this fault is cleared, the following message displays: Excessive Deauthentication Frames not present in Channel.

IDS > Manage IDS Settings > General IDS Settings > Excessive Management Frame Detection

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Excessive Deauthentication Frames from STA: station [Frames: framecount,Interval:windowsize]

IOS

The fault thresholds been exceeded.

When this fault is cleared, the following message displays: Excessive Deauthentication Frames from STA: station not present

IDS > Manage IDS Settings > General IDS Settings > Excessive Management Frame Detection

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Excessive Disassociation Frames in Channel: channel [Frames: framecount,Interval:windowsize]

IOS

The fault thresholds been exceeded.

When this fault is cleared, the following message displays: Excessive Disassociation Frames not present in Channel.

IDS > Manage IDS Settings > General IDS Settings > Excessive Management Frame Detection

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Excessive Disassociation Frames from STA: station [Frames: framecount,Interval:windowsize]

IOS

The fault thresholds been exceeded.

When this fault is cleared, the following message displays: Excessive Disassociation Frames from STA: station not present

IDS > Manage IDS Settings > General IDS Settings > Excessive Management Frame Detection

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Excessive Probe Frames in Channel: channel [Frames: framecount,Interval:windowsize]

IOS

The fault thresholds been exceeded.

When this fault is cleared, the following message displays: Excessive Probe Frames not present in Channel.

IDS > Manage IDS Settings > General IDS Settings > Excessive Management Frame Detection

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Excessive Probe Frames from STA: station [Frames: framecount,Interval:windowsize]

IOS

The fault thresholds been exceeded.

When this fault is cleared, the following message displays: Excessive Probe Frames from STA: station not present

IDS > Manage IDS Settings > General IDS Settings > Excessive Management Frame Detection

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Excessive Reassociation Frames in Channel: channel [Frames: framecount,Interval:windowsize]

IOS

The fault thresholds been exceeded.

When this fault is cleared, the following message displays: Excessive Reassociation Frames not present in Channel.

IDS > Manage IDS Settings > General IDS Settings > Excessive Management Frame Detection

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Excessive Reassociation Frames from STA: station [Frames: framecount,Interval:windowsize]

IOS

The fault thresholds been exceeded.

When this fault is cleared, the following message displays: Excessive Reassociation Frames from STA: station not present

IDS > Manage IDS Settings > General IDS Settings > Excessive Management Frame Detection

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Number of CCMP Replay Discarded is Degraded.

IOS

The fault threshold set for the degraded state has been exceeded.

When the fault is cleared, the following message displays: Number of CCMP Replays Discarded is OK.

IDS > Manage IDS Settings > IDS-802.11x >CCMP Replays Discarded (IOS)

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Number of CCMP Replay Discarded is Overloaded.

The fault threshold set for the overloaded state has been exceeded.

When the fault is cleared, the following message displays: Number of CCMP Replays Discarded is OK.

Number of EAPOL Flood Count is Degraded

IOS

The fault threshold set for the degraded state has been exceeded.

When this fault is cleared, the following message displays: EAPOL Flood Count is OK.

IDS > Manage IDS Settings > General IDS Settings > EAPOL Detection (IOS)

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Number of EAPOL Flood Count is Overloaded

The fault threshold set for the overloaded state has been exceeded.

When this fault is cleared, the following message displays: EAPOL Flood Count is OK.

Number of TKIP counter measure is Degraded.

IOS

The fault threshold set for the degraded state has been exceeded.

When the fault is cleared, the following message displays: Number of TKIP Counter Measure is OK.

IDS > Manage IDS Settings > IDS-802.11x >TKIP Counter Measure Invoked (IOS)

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Number of TKIP counter measure is Overloaded.

The fault threshold set for the overloaded state has been exceeded.

When the fault is cleared, the following message displays: Number of TKIP Counter Measure is OK.

Number of TKIP Local MIC failures is Degraded.

IOS

The fault threshold set for the degraded state has been exceeded.

When the fault is cleared, the following message displays: Number of TKIP Local MIC failures is OK.

IDS > Manage IDS Settings > IDS-802.11x >TKIP Local MIC failures (IOS)

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Number of TKIP Local MIC failures is Overloaded.

The fault threshold set for the overloaded state has been exceeded.

When the fault is cleared, the following message displays: Number of TKIP Local MIC failures is OK.

Number of TKIP Remote MIC failures is Degraded.

IOS

The fault threshold set for the degraded state has been exceeded.

When the fault is cleared, the following message displays: Number of TKIP Remote MIC failures is OK.

IDS > Manage IDS Settings > IDS-802.11x >TKIP Remote MIC failures (IOS)

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Number of TKIP Remote MIC failures is Overloaded.

The fault threshold set for the overloaded state has been exceeded.

When the fault is cleared, the following message displays: Number of TKIP Remote MIC failures is OK.

Number of TKIP replay errors is Degraded.

IOS

The fault threshold set for the degraded state has been exceeded.

When the fault is cleared, the following message displays: Number of TKIP replay errors is OK.

IDS > Manage IDS Settings > IDS-802.11x >TKIP Replays Detected (IOS)

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Number of TKIP replay errors is Overloaded.

The fault threshold set for the overloaded state has been exceeded.

When the fault is cleared, the following message displays: Number of TKIP replay errors is OK.

TKIP Replay is detected

IOS

The fault threshold set has been exceeded.

When this fault is cleared, the following message displays: There is no TKIP Replay detected.

IDS > Manage IDS Settings > General IDS Settings > TkipReplayClient (IOS)

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

TKIP LocalMICFailure is detected

IOS

The fault threshold set has been exceeded.

When this fault is cleared, the following message displays: There is no TKIP LocalMICFailure detected.

IDS > Manage IDS Settings > General IDS Settings > TkipLocalMicFailureClient[IOS]

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Unregistered Client(s) present

IOS

One or more unregistered clients are present in the wireless network and are unsuccessfully attempting to authenticate with the APs. This fault occurs when, during the observation interval, the number of failed attempts crosses the threshold defined by the administrator.

This fault is cleared when no registration attempts are detected during the observation interval (the client leaves the wireless network or is not seen or reported by any Scanning APs).

IDS > Manage IDS Settings > General IDS Settings > Unregistered Client

Set the priority of the fault to be generated and the threshold for the failed authentication attempts by the client.

Make a physical check near the scanning AP that reported this fault to see if there are any rogue clients.

Wireless Client MAC spoofing detected

IOS

The WLSE has detected a spoofed MAC address.

Whenever the WDS detects an authentication taking place for a known MAC address, it verifies that the same user ID is being used. If the user ID does not match, the authentication is rejected and a fault is issued.

When this fault is cleared, the following message displays: No Wireless Client MAC Spoofing Detected.

IDS > Manage IDS Settings > General IDS Settings > Wireless Client MAC Spoofing (IOS)

Review your network to determine the action necessary to clear the fault condition.


WLSE Faults

Table 2-4 WLSE Faults 

Fault Description
Explanation
Related Setting
Recommended Action

Data may not have been successfully restored from active.

The standby WLSE has detected a failure in the active WLSE and is becoming active before it successfully synchronized with the active WLSE.

Not applicable.

Make sure the WLSEs are correctly configured and functioning properly.

Dot11mib view is not enabled on some Access Points. Please consult online help for details

The device is not configured with the iso (dot11 mib) view, and cannot be managed effectively by the WLSE.

This can cause some WLSE report information to be missing and some WLSE faults may not be generated.

When this fault has been cleared, the following message displays: No Dot11mib view misconfigurations detected.

Manage Fault Settings > Thresholds > WLSE > Dot11mib view enabled

Configure the devices and the WLSE as described in Access points are placed in Misconfigured Devices folder after discovery and dot11mib fault is displayed..

Duplicate IP Detection

During discovery, an AP with a duplicate IP is found and placed in the Duplicate IP folder under Devices > Managed > Manage/Unmanage.

This folder contains access points that are in the pending state. A device becomes pending and is placed in this folder when:

The same IP address is assigned to more than one access point.

An access point's IP address changes.

You replace a managed access point.

The IP address shown for a device in this folder is the last known address for the device, before the address change occurred.

Manage Fault Settings > Thresholds > WLSE > Duplicate IP detection

For information on how to move devices from the Duplicate IP folder, see the topic: Handling Duplicate IP Addresses on Access Points in the Managing Devices chapter of the User Guide for the CiscoWorks Wireless LAN Solution Engine, 2.11. or in the online help.

Lost connectivity with router.

The WLSE is unable to ping the default router.

Not applicable.

Make sure that:

Connectivity from the WLSE to the gateway router is okay.

The gateway router is functioning properly.

Lost connectivity with standby on ip_address.

The standby WLSE indicated by the IP address is down.

Not applicable.

Make sure that:

The standby WLSE is up and running.

The standby WLSE is network accessible.

Redundancy has been correctly setup on the Active WLSE.

Other node is running a different version. Redundancy will be turned off.

A mismatch of WLSE software version has been detected between the active and the standby WLSEs.

Not applicable.

Make sure the correct WLSE software has been installed on both the active and standby WLSEs.

Redundancy active mode enabled

The WLSE sending this message is now active.

Not applicable.

Confirm that both WLSEs are functioning respectively as Active and Standby.

Redundancy standby mode.

The WLSE sending this message is now in standby mode.

Not applicable.

Confirm that both WLSEs are functioning respectively as Active and Standby.

Redundancy turned off.

Redundancy has been disabled.

Not applicable.

Make sure the WLSEs are correctly configured and functioning properly.

Regained connectivity with router.

The WLSE that sent this message is now able to ping the default router.

Not applicable.

Confirm that both WLSEs are functioning respectively as Active and Standby.

Regained connectivity with standby on ip_address

The Standby WLSE is up.

Not applicable.

Confirm that both WLSEs are functioning respectively as Active and Standby.

System check failed on ip_address for reason: reason.

The system check failed.

Not applicable.

Make sure the WLSEs are correctly configured and functioning properly.


AAA Server Faults

Table 2-5 AAA Server Faults 

Fault Description
Server Type
Explanation
Related Setting
Recommended Action

Authentication failed. Please check EAP-FAST, EAP-MD5, LEAP, PEAP, or RADIUS credentials

All AAA Servers

The server is reachable but the credentials are incorrect.

When this fault has been cleared, the following message displays: Authentication succeeded

Manage Fault Settings > AAA > EAP-FAST/
EAP-MD5 /LEAP/
PEAP/RADIUS> Response Time

Make sure that the credentials are set correctly by selecting Devices > Discover > AAA Server.

EAP-FAST server is not available

EAP-FAST

This fault can be caused by any of the following reasons:

The WLSE IP Address is not configured as a NAS on the server.

The shared secret key does not match with the key configured on the server.

The server is unreachable.

When this fault has been cleared, the following message displays: EAP-MD5 server is available

Manage Fault Settings > AAA > EAP-FAST > Response Time

Check the server configuration to make sure that:

The WLSE IP address is configured as NAS on the server.

The shared secret key matches the key configured on the server

EAP-FAST server is Degraded

EAP-FAST

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: EAP-FAST server is OK

Manage Fault Settings > AAA > EAP-FAST > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

EAP-FAST server is Overloaded

EAP-FAST5

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: EAP-FAST server is OK

Manage Fault Settings > AAA > EAP-FAST > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

EAP-MD5 server is not available

EAP-MD5

This fault can be caused by any of the following reasons:

The WLSE IP Address is not configured as a NAS on the server.

The shared secret key does not match with the key configured on the server.

The server is unreachable.

When this fault has been cleared, the following message displays: EAP-MD5 server is available

Manage Fault Settings > AAA > EAP-MD5 > Response Time

Check the server configuration to make sure that:

The WLSE IP address is configured as NAS on the server.

The shared secret key matches the key configured on the server

EAP-MD5 server is Degraded

EAP-MD5

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: EAP-MD5 server is OK

Manage Fault Settings > AAA > EAP-MD5 > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

EAP-MD5 server is Overloaded

EAP-MD5

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: EAP-MD5 server is OK

Manage Fault Settings > AAA > EAP-MD5 > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

LEAP server is not available

LEAP

This fault can be caused by any of the following reasons:

This can be caused if you have enabled this policy and you are using a non-Cisco client with EAP.

The WLSE IP Address is not configured as a NAS on the server.

The shared secret key does not match with the key configured on the server.

The server is unreachable.

When this fault has been cleared, the following message displays: LEAP server is available

Manage Fault Settings > AAA > LEAP > Response Time

Check the server configuration and make sure that:

The WLSE IP address is configured as NAS on the server.

The shared secret key matches the key configured on the server

LEAP server is Degraded

LEAP

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: LEAP server is OK.

Manage Fault Settings > AAA > LEAP > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

LEAP server is Overloaded

LEAP

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: LEAP server is OK.

Manage Fault Settings > AAA > LEAP > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

PAC is either invalid or expired. Please reimport new PAC file

EAP-FAST

PAC file used is either invalid or expired.

This fault is not generated based on a threshold violation.

Generate a new PAC file from the EAP-FAST server you are trying to monitor and make sure that the expiry time is set properly when generating the PAC file.

PEAP server is not available

PEAP

This fault can be caused by any of the following reasons:

PEAP monitoring is not enabled.

The WLSE IP Address is not configured as a NAS on the server.

The shared secret key does not match with the key configured on the server.

The server is unreachable.

EAP-GTC is required for reports and faults.

When this fault has been cleared, the following message displays: PEAP server is available

Manage Fault Settings > AAA > PEAP > Response Time

Check the server configuration and make sure that:

PEAP monitoring is enabled under Manage Fault Settings > AAA> PEAP > Response time.

The WLSE IP address is configured as NAS on the authentication server.

If both NICs in the WLSE are assigned an IP, then both should be added as NAS in the PEAP authentication server.

The shared secret key matches the key configured on the server.

The WLSE requires EAP-GTC for PEAP monitoring, which is used for PEAP-related reports and faults. They will not work with MS-CHAPV2.

PEAP server is Degraded

PEAP

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: PEAP server is OK.

Manage Fault Settings > AAA > PEAP > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

PEAP server is Overloaded

PEAP

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: PEAP server is OK

Manage Fault Settings > AAA > PEAP > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

RADIUS server is not available

PEAP

This fault can be caused by any of the following reasons:

The WLSE IP Address is not configured as a NAS on the server.

The shared secret key does not match with the key configured on the server.

The server is unreachable.

When this fault has been cleared, the following message displays: RADIUS server is available

Manage Fault Settings > AAA > RADIUS > Response Time

Check your server configuration and make sure that:

The WLSE IP address is configured as NAS on the server.

The shared secret key matches the key configured on the server

RADIUS server is Degraded

PEAP

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: RADIUS server is OK.

Manage Fault Settings > AAA > RADIUS > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

RADIUS server is Overloaded

PEAP

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: RADIUS server is OK.

Manage Fault Settings > AAA > RADIUS > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.


Switch Faults

Table 2-6 Switch Faults 

Fault Description
Explanation
Related Setting
Recommended Action

CPU utilization is Degraded (utilization %)

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: CPU utilization is Ok.

Manage Fault Settings > Switch > CPU Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

CPU utilization is Overloaded (utilization %)

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: CPU utilization is Ok.

Manage Fault Settings > Switch > CPU Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Device was not reachable via SNMP

The SNMP Agent on the switch is down.

When this fault has been cleared, the following message displays: Device was reachable via SNMP.

Manage Fault Settings > Switch > SNMP Reachable

Make sure that the switch SNMP agent is active.

Module is down

The module is down.

When this fault has been cleared, the following message displays: Module is up.

Manage Fault Settings > Switch > Module Status

Check the module in the switch and correct the problem.

Port could not agree with other end on duplex mode

The port could not agree with the far end on port duplex, and is in disagree(3) mode.

When this fault has been cleared, the following message displays: Port duplex state is OK.

Not applicable.

Make sure the duplex mode on both ends match.

Port is administratively set to down

The port has been set to down by the administrator.

When this fault is cleared, the following message displays: Port is UP.

Manage Fault Settings > Switch > Port Status

Confirm that the switch port has been deliberately shut down, and that it is not down due to some other accidental operation.

Port is down.

The port is operationally down.

When this fault is cleared, the following message displays: Port is UP.

Manage Fault Settings > Switch > Port Status

Check the switch to determine why the port is down.

Switch memory utilization is Degraded (utilization %)

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: Switch memory utilization is Ok.

Manage Fault Settings > Switch > Memory Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Switch memory utilization is Overloaded (utilization %)

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: Switch memory utilization is Ok.

Manage Fault Settings > Switch > Memory Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Switch Port bandwidth utilization is Degraded (utilization %)

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: Switch port bandwidth utilization is Ok.

Manage Fault Settings > Switch > Port Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Switch Port bandwidth utilization is Overloaded (utilization %)

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: Switch port bandwidth utilization is Ok.

Manage Fault Settings > Switch > Port Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.


Router Fault

Table 2-7 Router Fault 

Fault Description
Explanation
Related Setting
Recommended Action

Device was not reachable via SNMP

The SNMP Agent on the switch is down.

When this fault has been cleared, the following message displays: Device was reachable via SNMP.

Manage Fault Settings > Router > SNMP Reachable

Make sure that the router SNMP agent is active.