FAQ and Troubleshooting Guide for the CiscoWorks Wireless LAN Solution Engine, 2.9
Fault Descriptions
Downloads: This chapterpdf (PDF - 319.0KB) The complete bookPDF (PDF - 1.2MB) | Feedback

Fault Descriptions

Table Of Contents

Fault Descriptions

Access Point /Bridge Faults

Radio Interface Faults

WLSE Faults

AAA Server Faults

Switch Faults

Router Fault


Fault Descriptions


This section provides the following information on the faults displayed in Faults > Display Faults. The following information is provided:

Fault—The fault as it appears in the Display Faults table.

Explanation—An explanation as to why the fault occurred.

Related Setting—The threshold or policy you assigned to devices under Faults > Manage Fault Settings, when applicable.

Recommended Action—An action that can be taken to clear the displayed fault.

Fault tables are provided for each device type:

Access Point /Bridge Faults

Radio Interface Faults

WLSE Faults

AAA Server Faults

Switch Faults

Router Fault

Access Point /Bridge Faults

Table 2-1 Access Point Faults 

Fault Description
Type
Explanation
Related Setting
Recommended Action

AP is in a Degraded state number associated clients

Non-IOS

The fault threshold set for the degraded state has been exceeded.

When this fault is cleared, the following message displays: AP is in OK state.

Manage Fault Settings > Access Point/Bridge Thresholds > Associated Clients

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

AP is in an Overloaded state number associated clients

Non-IOS

The fault threshold set for the overloaded state has been exceeded.

When this fault is cleared, the following message displays: AP is in OK state.

Manage Fault Settings > Access Point/Bridge Thresholds> Associated Clients

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

AP is not registered with any WDS

IOS

The managed IOS access point is not registered with any WDS.

For Radio Manager functionality to work, all IOS access points must register with a WDS. If an access point is not registered, it will be excluded from all the Radio Manager procedures, which will provide incorrect results.

Manage Fault Settings > Access Point/Bridge > Registration Error

Verify that the WLCCP AP credentials are configured correctly so that the AP can register with a WDS in its subnet.

For more information, see the managing devices information in the online help or the User Guide for the CiscoWorks Wireless LAN Solution Engine Express, Release 2.9.

AP registered with an Unmanaged WDS: ipAddressOfTheUnManagedWDS

IOS

AP is registered with a WDS but that WDS is not managed by WLSE.

When this fault is cleared, the following message displays: AP registered with a managed WDS.

Manage Fault Settings > Access Point/Bridge > Registration Error

Manage the WDS.

Broadcast Key Rotation is disabled

Non-IOS and IOS

The broadcast key rotation has been disabled.

When this fault is cleared, the following message displays: Broadcast Key Rotation is enabled.

Manage Fault Settings > Access Point/Bridge Policies > Key Rotation per VLAN

Log in to the access point and enable the broadcast key rotation interval.

Device state is rogue access point

IOS

The WLSE detected a rogue access point. (This is an access point that is not being managed and is unknown to the WLSE.)

Manage Network-Wide Settings > Rogue AP Detection

Use the fault details page to mark it friendly if the AP is known, or to delete it from the WLSE database if it is an unknown AP.

Device was not reachable via SNMP

Non-IOS and IOS

The SNMP Agent could be down.

When this fault is cleared, the following message displays: Device was reachable via SNMP.

Manage Fault Settings > Access Point/Bridge Thresholds > SNMP Reachable

Make sure SNMP is enabled on the device and that the agent is not down.

Take a MIB walk of the device to make sure sysup time is returning 0, which indicates Device is reachable.

The SNMP community string in the access point has been changed, and then a discovery job is run.

Not applicable.

Change the SNMP community string on the WLSE to match the new community string on the access point, then run discovery again.

EAP per SSID for Cisco-Supplicant is disabled

Non-IOS and IOS

The Network EAP or the Open authentication is disabled on this SSID.

When this fault is cleared, the following message displays: EAP per SSID for Cisco Supplicant is enabled.

Manage Fault Settings > Access Point/Bridge Policies > EAP Per SSID Enforced for Cisco-
Supplicant

Log in to the access point and enable both Network EAP and Open authentication on that SSID.

EAP per SSID for Non-Cisco-Supplicant is disabled

Non-IOS and IOS

The Network EAP or the Open authentication is disabled on this SSID.

When this fault is cleared, the following message displays: EAP per SSID for Non-Cisco Supplicant is enabled.

Manage Fault Settings > Access Point/Bridge Policies > EAP Per SSID Enforced for Non-Cisco-
Supplicant

Log in to the access point and enable both Network EAP and Open authentication on that SSID.

EAP per SSID for Mixed-Cisco-Supplicant is disabled

Non-IOS and IOS

The Network EAP or the Open authentication is disabled on this SSID.

When this fault is cleared, the following message displays: EAP per SSID for Cisco Supplicant is enabled.

Manage Fault Settings > Access Point/Bridge Policies > EAP Per SSID Enforced for Mixed-Cisco-
Supplicant

Log in to the access point and enable both Network EAP and Open authentication on that SSID.

Ethernet bandwidth utilization is Degraded (utilization %)

Non-IOS and IOS

The fault threshold set for the degraded state has been exceeded.

When this fault is cleared, the following message displays: Ethernet bandwidth utilization is OK.

Manage Fault Settings > Access Point/Point Thresholds > Ethernet Port Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Ethernet bandwidth utilization is Overloaded (utilization %)

Non-IOS and IOS

The fault threshold set for the overloaded state has been exceeded.

When this fault is cleared, the following message displays: Ethernet bandwidth utilization is OK.

Manage Fault Settings > Access Point/Bridge Thresholds > Ethernet Port Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Firmware version policy violation (version number)

Non-IOS and IOS

The wrong version number for policy checking has been entered.

When this fault is cleared, the following message displays: Firmware version is valid.

Manage Fault Settings > Access Point/Bridge Policies > Firmware Version

Make sure that the firmware version that is entered in the policy setting matches the firmware version on the access point.

The access point is running an unauthorized firmware version.

When this fault is cleared, the following message displays: Firmware version is valid.

Make sure that you have entered authorized versions in the policy setting.

Update the firmware on the access point to an authorized version.

HotStandBy is active

Non-IOS and IOS

The access point that is configured for hot standby has become active.

The following conditions could cause the hot standby access point to become active: the primary access point is down, the Ethernet port is down, or the Radio port is down.

When this fault is cleared, the following message displays: HotStandBy is disabled.

Manage Fault Settings > Access Point/Bridge Policies > HotStandby Status

For non-IOS access points:

1. Check the primary access point, the Ethernet port, or the Radio port to see why the hot standby access point has been activated.

2. Correct the condition. For example, if the Radio Port on the formerly active access point was in a disabled state, then enable it using the access point GUI.

3. Launch the GUI for access point that is currently in Active Takeover mode.

4. Select the Hot Standby section and click Start Hot Standby mode to reconfigure the access point to Hot Standby mode.

       

For IOS access points:

1. Check the primary access point, the Ethernet port, or the Radio port to see why the hot standby access point has been activated.

2. Correct the condition. For example, if the Radio Port on the formerly active access point was in a disabled state, then enable it using the access point GUI.

3. Launch the GUI for access point that is currently in Active Takeover mode.

4. Select Hot Standby, click Disabled , then click Apply.

5. Click Enabled, then enter the Radio MAC address of Monitored Radio Port, leave the Polling interval and Timeout for Each Polling fields blank,.

6. Click Apply to reconfigure the access point to Hot Standby mode.

HTTP access is enabled

Non-IOS

HTTP has been enabled on the access point.

When this fault is cleared, the following message displays: HTTP access is disabled.

Manage Fault Settings > Access Point/Bridge Policies > HTTP Disabled

Log in to the access point and disable HTTP access.

HTTP access without login is enabled

Non-IOS

The allowBrowseWithoutLogin setting on the access point is set.

When this fault is cleared, the following message displays: HTTP access without login is disabled.

Manage Fault Settings > Access Point/Bridge Policies > HTTP Authentication (NonIOS)

Log in to the access point and disable the allowBrowseWithoutLogin setting.

MIC is disabled for the VLAN number

IOS

MIC is not enabled for the selected VLAN on the access point.

When the fault is cleared, the following message displays: MIC is enabled.

Manage Fault Settings > Access Point/Bridge Policies > MIC per Vlan (IOS)

Log into the access point and enable the VLAN. Then, using the WLSE fault settings, enable the MIC for that VLAN.

PSPF is disabled

Non-IOS

The PSPF port has been disabled.

PSPF (Publicly Secure Packet Forwarding) is a feature that prevents client devices associated to a bridge or access point from inadvertently sharing files with other client devices on the wireless network.

When the fault is cleared, the following message displays: The PSPF is enabled.

Manage Fault Settings > Access Point/Bridge Policies > PSPF Enabled (Non-IOS)

Log in to the access point and enable the PSPF setting.

SNMP query received authorization error response

Non-IOS

The access point's user community strings do not have Admin, Ident, Firmware, SNMP privileges. The WLSE might not be able to access some SNMP information from the access point that requires these privileges.

When the fault is cleared, the following message displays: Device was reachable via SNMP.

Manage Fault Settings > Access Point/Bridge Thresholds > SNMP Reachable

Make sure the SNMP community string set on the WLSE (Devices > Discover > Device Credentials > SNMP Communities) is the same as the string set on the access point (Setup > Security > User Information).

Telnet access is enabled

Non-IOS

Telnet has been enabled on the access point.

When this fault has been cleared, the following message displays: Telnet access is disabled

Manage Fault Settings > Access Point/Bridge Policies > Telnet Disabled

Log in to the access point and disable the Telnet access setting.

User capabilities are not enforced

Non-IOS

The enableUserMgr setting is not set on the access point.

When this fault has been cleared, the following message displays: User capabilities are enforced.

Manage Fault Settings > Access Point/Bridge Policies > User Manager Enforced (NonIOS)

Log in to the access point and enable the User Mgr setting.

Vlan WEP key length policy violation

Non-IOS and IOS

The WEP key length for the selected VLAN setting has been violated.

When this fault has been cleared, the following message displays: Vlan WEP key length is ok.

Manage Fault Settings > Access Point/Bridge Policies > WEP Encryption per Vlan

Make sure the WEP key length selected in the policy setting matches the access point settings.

WDS appears down.

IOS

The WLSE failed to receive "keep active" messages from the WDS. This happens when the WDS is down or when the network is down.

Manage Fault Settings > WDS > WLSE-WDS Link Status

Check the network connectivity, and the WDS status.

WEP is disabled

IOS

WEP is not enabled for the VLAN defined on the access point. (Note that the VLAN number is displayed in the Type column under Faults > Display Faults.)

When the fault is cleared, the following message displays: WEP is enabled.

Manage Fault Settings > Access Point/Bridge Policies > WEP per Vlan (IOS)

Make sure you have set the policy correctly for the VLAN.

WNM failed to authenticate with WDS.

IOS

Authentication required to open a WLCCP channel between the WLSE and the WDS failed.

Manage Fault Settings > WDS > Authentication Failures

Verify that the WLSE credentials used to authenticate with the WDS are correct.

For more information, see the managing devices information in the online help or the User Guide for the CiscoWorks Wireless LAN Solution Engine Express, Release 2.9.


Radio Interface Faults

Table 2-2 Radio Interface Faults 

Fault Description
Type
Explanation
Related Setting
Recommended Action

802.11-B/G Interference Detected

- or -

802.11-A Interference Detected

IOS

The WLSE detected a non-802.11 interference.

Manage Network-Wide Settings > Interference Detection

Look at the fault description to determine which AP reported the interference, then take corrective action by removing the interference source.

Ad-hoc network creation detected

Non-IOS and IOS

An ad-hoc network was formed by some wireless clients. One of your infrastructure APs or other clients sent this information to the WLSE via your WDS setup.

Manage Network-Wide Settings > Ad-hoc Network Detection

If the information is available, the WLSE will show the clients that are participating in the network (and that it can detect) in the fault details page. Use the Location Manager to find these APs and verify that this is not a security issue.

AP is in a Degraded state number associated clients

IOS

The fault threshold set for the degraded state has been exceeded.

When this fault is cleared, the following message displays: AP is in OK state.

Manage Fault Settings > Radio-802.11x Thresholds > Associated Clients (IOS)

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

AP is in an Overloaded state number associated clients

Non-IOS and IOS

The fault threshold set for the overloaded state has been exceeded.

When this fault is cleared, the following message displays: AP is in OK state.

Manage Fault Settings > Thresholds > Access Point > Associated Clients

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Auto Resite Survey Performance Degradations

IOS only

There was a 20% difference in the base and current performance values.

The fault will clear when there are no longer any buildings or any floors with 20% differences in the performance values.

Network-Wide Settings > Auto Re-Site Survey

Select the document with the eyeglasses in the detail view of the fault condition. A list of all buildings and floors that have performance degradations is displayed.

First, check the details for the floor and if needed, run Radio Manager Assisted Configuration. Then select Auto Re-Site Survey to set the new base values.

Broadcast SSID is enabled.

Non-IOS and IOS

The broadcast mode for the SSID on the interface has been disabled.

When this fault is cleared, the following message displays: Broadcast SSID is disabled.

Manage Fault Settings > Radio-802.11x Policies > Broadcast Disabled

Log in to the access point and disable the broadcast mode.

Broadcast is enabled for Radio-x SSID ssid fault.

IOS

An SSID, which you do not want broadcast, is being broadcast.

When this fault is cleared, the following message displays: Broadcast is disabled for Radio-x SSID ssid fault.

Manage Fault Settings > Radio-802.11x Policies > Broadcast SSID (IOS)

Log in to the access point and make sure that the that the SSID, which is in WLSE's "Do not Broadcast SSID" list is not selected for Broadcast on the access point.

Number of CCMP Replay Discarded is degraded.

IOS

The fault threshold set for the degraded state has been exceeded.

When the fault is cleared, the following message displays: Number of CCMP Replay Discarded is OK.

Manage Fault Settings > Radio-802.11x Policies > CCMP Replay Discarded (IOS)

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Number of CCMP Replay Discarded is overloaded.

The fault threshold set for the overloaded state has been exceeded.

When the fault is cleared, the following message displays: Number of CCMP Replay Discarded is OK.

Client association rate is Degraded number per minute

Non-IOS and IOS

The fault threshold set for the degraded state has been exceeded.

When this fault is cleared, the following message displays: Client association rate is OK.

Manage Fault Settings > Radio-802.11x Thresholds > Association Rate

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Client association rate is Overloaded number per minute

Non-IOS and IOS

The fault threshold set for the overloaded state has been exceeded.

When this fault is cleared, the following message displays: Client association rate is OK.

Manage Fault Settings > Radio-802.11x Thresholds > Association Rate

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Client authentication error rate is Degraded number per minute

Non-IOS and IOS

The fault threshold set for the degraded state has been exceeded.

When this fault is cleared, the following message displays: Client association error rate is OK.

Manage Fault Settings > Radio-802.11x Thresholds > Authentication Error Rate

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Client authentication error rate is Overloaded number per minute

Non-IOS and IOS

The fault threshold set for the overloaded state has been exceeded.

When this fault is cleared, the following message displays: Client association error rate is OK.

Manage Fault Settings > Radio-802.11x Thresholds > Authentication Error Rate

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

EAP is disabled

Non-IOS and IOS

The EAP per SSID has been disabled.

When this fault is cleared, the following message displays: EAP is enabled

Manage Fault Settings > Radio-802.11x Policies >
EAP Enforced for
Cisco Supplicant/
Non-Cisco Supplicant/
Mixed-Cisco Supplicant

Log in to the access point and enable the Network EAP and Open authentication.

Infrastructure SSID policy violation

IOS

The infrastructure SSID does not match the infrastructure SSID set on the access point.

When this fault is cleared, the following message displays: Infrastructure SSID is valid .

Manage Fault Settings > Radio-802.11x Policies > Infrastructure SSID (IOS)

Log in to the access point and make sure the WLSE's Infrastructure SSID matches the access point infrastructure SSID

Packet Error is in Degraded state (error rate %)

Non-IOS and IOS

The fault threshold set for the degraded state has been exceeded.

When this fault is cleared, the following message displays: Packet Error is in OK state.

Manage Fault Settings > Radio-802.11x Thresholds > RF Port Packet Errors

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

The radio interfaces on the devices may be very under utilized, which can trigger the degradation problem.

For example, if a total of three packets are sent over the radio, and two of them are corrupt, the percentage would be 2/3 = 66%, and could trigger the alarm.

Remove the alarm from the profile associated with these devices.

Packet Error is in is in Overloaded state (error rate %)

Non-IOS and IOS

The fault threshold set for the overloaded state has been exceeded.

When this fault is cleared, the following message displays: Packet Error is in OK state.

Manage Fault Settings > Radio-802.11x Thresholds > RF Port Packet Errors

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Port is administratively set to down

Non-IOS and IOS

The port has been set to Down by the administrator.

When this fault is cleared, the following message displays: Port is up

Manage Fault Settings > Radio-802.11x Thresholds > RF Port Status

There is no action necessary; the port has been deliberately shut down.

Port is down

Non-IOS and IOS

The port is operationally down.

When this fault is cleared, the following message displays: Port is up

Manage Fault Settings > Radio-802.11x Thresholds > RF Port AdminStatus

Check the device to determine why the port is down.

If you have added or removed an interface from an access point, the WLSE might generate an erroneous fault. See What are the results of adding or removing an interface from an access point?.

PSPF is disabled

IOS

The PSPF port has been disabled.

PSPF (Publicly Secure Packet Forwarding) is a feature that prevents client devices associated to a bridge or access point from inadvertently sharing files with other client devices on the wireless network.

When the fault is cleared, the following message displays: The PSPF is enabled.

Manage Fault Settings > Access Point/Bridge Policies > PSPF Enabled (IOS)

Log in to the access point and enable the PSPF setting.

Radio (macaddress(es)) appears down - triggered self healing

IOS

The indicated radio appeared down on this AP, so other APs were modified to maintain coverage.

After self healing has been applied to the other AP, this fault indicates the AP that had the failure.

Not applicable.

Select the document with the eyeglasses in the detail view of the fault condition. A list of the APs that were modified with the old and new power settings is displayed.

Check the radio to determine why it is down. Then either replace it or clear the fault and rerun AP Radio Scan. Or if you like the new setup, just clear the fault.

Retry Count rate is Degraded number per minute

Non-IOS and IOS

The fault threshold set for the degraded state has been exceeded.

When the fault is cleared, the following message displays: Retry Count rate is OK

Manage Fault Settings > Radio-802.11x Thresholds > Max Retry Count

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Retry Count rate is Overloaded number per minute

Non-IOS and IOS

The fault threshold set for the overloaded state has been exceeded.

When the fault is cleared, the following message displays: Retry Count rate is OK

Manage Fault Settings > Radio-802.11x Thresholds > Max Retry Count

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

RF bandwidth utilization is Degraded (utilization %)

Non-IOS and IOS

The fault threshold set for the degraded state has been exceeded.

When the fault is cleared, the following message displays: RF bandwidth utilization is OK

Manage Fault Settings > Radio-802.11x Thresholds > RF Port Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

RF bandwidth utilization is Overloaded (utilization %)

Non-IOS and IOS

The fault threshold set for the overloaded state has been exceeded.

When the fault is cleared, the following message displays: RF bandwidth utilization is OK

Manage Fault Settings > Radio-802.11x Thresholds > RF Port Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Self Healing finished with errors: message

IOS

An error occurred while attempting self healing. For example, a power change cannot be applied to an AP.

1) The community strings for the device are wrong

2) AP is down

3) Wrong configuration set on the AP

Not applicable.

Determine the action necessary to clear the fault condition.

Self Healing In Progress

IOS

The WLSE determined that a radio was down.

When self healing is complete, a fault is applied against the AP that had the failure.

Not applicable.

There is no action necessary; self healing is attempting to adjust the power on other radios on the floor to maintain coverage.

Serving and non-serving channel Radio Monitoring must be enabled.

IOS

Radio Monitoring is not enabled for serving and non-serving channels.

When the fault is cleared, the following message displays: Qualifies for Self Healing Monitoring.

Not applicable.

Enable Radio Monitoring for both serving and non-serving channels.

Number of TKIP replay errors is degraded.

IOS

The fault threshold set for the degraded state has been exceeded.

When the fault is cleared, the following message displays: Number of TKIP replay errors is OK.

Manage Fault Settings > Radio-802.11x Thresholds >TKIP Replay (IOS)

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Number of TKIP replay errors is overloaded.

The fault threshold set for the overloaded state has been exceeded.

When the fault is cleared, the following message displays: Number of TKIP replay errors is OK.

Number of TKIP counter measure is degraded.

IOS

The fault threshold set for the degraded state has been exceeded.

When the fault is cleared, the following message displays: Number of TKIP replay errors is OK.

Manage Fault Settings > Radio-802.11x Thresholds >TKIP Counter Measure (IOS)

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Number of TKIP counter measure is overloaded.

The fault threshold set for the overloaded state has been exceeded.

When the fault is cleared, the following message displays: Number of TKIP replay errors is OK.

Unregistered Client(s) present

IOS

One or more unregistered clients are present in the wireless network and are unsuccessfully attempting to authenticate with the APs. This fault occurs when, during the observation interval, the number of failed attempts crosses the threshold defined by the administrator.

This fault is cleared when no registration attempts are detected during the observation interval (the client leaves the wireless network or is not seen or reported by any Scanning APs).

Faults > Manage Network-Wide Settings > Scanning AP.

Set the priority of the fault to be generated and the threshold for the failed authentication attempts by the client.

Make a physical check near the scanning AP that reported this fault to see if there are any rogue clients.

WEP Error is in Degraded state (error rate %)

Non-IOS and IOS

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: WEP Error is in OK state

Manage Fault Settings > Radio-802.11x Thresholds > RF Port WEP Errors

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

WEP Error is in Overloaded state (error rate %)

Non-IOS and IOS

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: WEP Error is in OK state

Manage Fault Settings > Radio-802.11x Thresholds > RF Port WEP Errors

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

WEP is disabled

Non-IOS and IOS

WEP has been disabled.

When this fault has been cleared, the following message displays: WEP is enabled.

Manage Fault Settings > Radio-802.11x Policies > WEP Enforced (Non-IOS)

Log in to the access point and enable WEP.

WEP key length policy violation

Non-IOS and IOS

The WEP key length setting has been violated.

When this fault has been cleared, the following message displays: WEP key length is OK.

Manage Fault Settings > Radio-802.11x Policies > WEP Key Length

Check the WEP key settings on the interface to make sure they match the WLSE settings.


WLSE Faults

Table 2-3 WLSE Fault 

Fault Description
Explanation
Related Setting
Recommended Action

Dot11mib view is not enabled on some Access Points. Please consult online help for details

The device is not configured with the iso (dot11 mib) view, and cannot be managed effectively by the WLSE.

This can cause some WLSE report information to be missing and some WLSE faults may not be generated.

When this fault has been cleared, the following message displays: No Dot11mib view misconfigurations detected.

Manage Fault Settings > Thresholds > WLSE > Dot11mib view enabled

Configure the devices and the WLSE as described in Access points are placed in Misconfigured Devices group after discovery and dot11mib fault is displayed..

Duplicate IP Detection

During discovery, an AP with a duplicate IP is found and placed in the Duplicate IP folder under Devices > Managed > Manage/Unmanage.

This folder contains access points that are in the pending state. A device becomes pending and is placed in this folder when:

The same IP address is assigned to more than one access point.

An access point's IP address changes.

You replace a managed access point.

The IP address shown for a device in this folder is the last known address for the device, before the address change occurred.

Manage Fault Settings > Thresholds > WLSE > Duplicate IP detection

For information on how to move devices from the Duplicate IP folder, see the topic: Handling Duplicate IP Addresses on Access Points in the Managing Devices chapter of the User Guide for the CiscoWorks Wireless LAN Solution Engine, 2.9. or in the online help.


AAA Server Faults

Table 2-4 AAA Server Faults 

Fault Description
Server Type
Explanation
Related Setting
Recommended Action

Authentication failed. Please check EAP-FAST, EAP-MD5, LEAP, PEAP, or RADIUS credentials

All AAA Servers

The server is reachable but the credentials are incorrect.

When this fault has been cleared, the following message displays: Authentication succeeded

Manage Fault Settings > AAA > EAP-FAST/
EAP-MD5 /LEAP/
PEAP/RADIUS> Response Time

Make sure that the credentials are set correctly by selecting Devices > Discover > AAA Server.

EAP-FAST server is not available

EAP-FAST

This fault can be caused by any of the following reasons:

The WLSE IP Address is not configured as a NAS on the server.

The shared secret key does not match with the key configured on the server.

The server is unreachable.

When this fault has been cleared, the following message displays: EAP-MD5 server is available

Manage Fault Settings > AAA > EAP-FAST > Response Time

Check the server configuration to make sure that:

The WLSE IP address is configured as NAS on the server.

The shared secret key matches the key configured on the server

EAP-FAST server is Degraded

EAP-FAST

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: EAP-FAST server is OK

Manage Fault Settings > AAA > EAP-FAST > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

EAP-FAST server is Overloaded

EAP-FAST5

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: EAP-FAST server is OK

Manage Fault Settings > AAA > EAP-FAST > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

EAP-MD5 server is not available

EAP-MD5

This fault can be caused by any of the following reasons:

The WLSE IP Address is not configured as a NAS on the server.

The shared secret key does not match with the key configured on the server.

The server is unreachable.

When this fault has been cleared, the following message displays: EAP-MD5 server is available

Manage Fault Settings > AAA > EAP-MD5 > Response Time

Check the server configuration to make sure that:

The WLSE IP address is configured as NAS on the server.

The shared secret key matches the key configured on the server

EAP-MD5 server is Degraded

EAP-MD5

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: EAP-MD5 server is OK

Manage Fault Settings > AAA > EAP-MD5 > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

EAP-MD5 server is Overloaded

EAP-MD5

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: EAP-MD5 server is OK

Manage Fault Settings > AAA > EAP-MD5 > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

LEAP server is not available

LEAP

This fault can be caused by any of the following reasons:

This can be caused if you have enabled this policy and you are using a non-Cisco client with EAP.

The WLSE IP Address is not configured as a NAS on the server.

The shared secret key does not match with the key configured on the server.

The server is unreachable.

When this fault has been cleared, the following message displays: LEAP server is available

Manage Fault Settings > AAA > LEAP > Response Time

Check the server configuration and make sure that:

The WLSE IP address is configured as NAS on the server.

The shared secret key matches the key configured on the server

LEAP server is Degraded

LEAP

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: LEAP server is OK.

Manage Fault Settings > AAA > LEAP > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

LEAP server is Overloaded

LEAP

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: LEAP server is OK.

Manage Fault Settings > AAA > LEAP > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

PAC is either invalid or expired. Please reimport new PAC file

EAP-FAST

PAC file used is either invalid or expired.

This fault is not generated based on a threshold violation.

Generate a new PAC file from the EAP-FAST server you are trying to monitor and make sure that the expiry time is set properly when generating the PAC file.

PEAP server is not available

PEAP

This fault can be caused by any of the following reasons:

PEAP monitoring is not enabled.

The WLSE IP Address is not configured as a NAS on the server.

The shared secret key does not match with the key configured on the server.

The server is unreachable.

EAP-GTC is required for reports and faults.

When this fault has been cleared, the following message displays: PEAP server is available

Manage Fault Settings > AAA > PEAP > Response Time

Check the server configuration and make sure that:

PEAP monitoring is enabled under Manage Fault Settings > AAA> PEAP > Response time.

The WLSE IP address is configured as NAS on the authentication server.

If both NICs in the WLSE are assigned an IP, then both should be added as NAS in the PEAP authentication server.

The shared secret key matches the key configured on the server.

The WLSE requires EAP-GTC for PEAP monitoring, which is used for PEAP-related reports and faults. They will not work with MS-CHAPV2.

PEAP server is Degraded

PEAP

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: PEAP server is OK.

Manage Fault Settings > AAA > PEAP > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

PEAP server is Overloaded

PEAP

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: PEAP server is OK

Manage Fault Settings > AAA > PEAP > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

RADIUS server is not available

PEAP

This fault can be caused by any of the following reasons:

The WLSE IP Address is not configured as a NAS on the server.

The shared secret key does not match with the key configured on the server.

The server is unreachable.

When this fault has been cleared, the following message displays: RADIUS server is available

Manage Fault Settings > AAA > RADIUS > Response Time

Check your server configuration and make sure that:

The WLSE IP address is configured as NAS on the server.

The shared secret key matches the key configured on the server

RADIUS server is Degraded

PEAP

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: RADIUS server is OK.

Manage Fault Settings > AAA > RADIUS > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

RADIUS server is Overloaded

PEAP

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: RADIUS server is OK.

Manage Fault Settings > AAA > RADIUS > Response Time

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.


Switch Faults

Table 2-5 Switch Faults 

Fault Description
Explanation
Related Setting
Recommended Action

CPU utilization is Degraded (utilization %)

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: CPU utilization is Ok.

Manage Fault Settings > Switch > CPU Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

CPU utilization is Overloaded (utilization %)

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: CPU utilization is Ok.

Manage Fault Settings > Switch > CPU Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Device was not reachable via SNMP

The SNMP Agent on the switch is down.

When this fault has been cleared, the following message displays: Device was reachable via SNMP.

Manage Fault Settings > Switch > SNMP Reachable

Make sure that the switch SNMP agent is active.

Module is down

The module is down.

When this fault has been cleared, the following message displays: Module is up.

Manage Fault Settings > Switch > Module Status

Check the module in the switch and correct the problem.

Port could not agree with other end on duplex mode

The port could not agree with the far end on port duplex, and is in disagree(3) mode.

When this fault has been cleared, the following message displays: Port duplex state is OK.

Not applicable.

Make sure the duplex mode on both ends match.

Switch memory utilization is Degraded (utilization %)

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: Switch memory utilization is Ok.

Manage Fault Settings > Switch > Memory Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Switch memory utilization is Overloaded (utilization %)

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: Switch memory utilization is Ok.

Manage Fault Settings > Switch > Memory Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Switch Port bandwidth utilization is Degraded (utilization %)

The fault threshold set for the degraded state has been exceeded.

When this fault has been cleared, the following message displays: Switch port bandwidth utilization is Ok.

Manage Fault Settings > Switch > Port Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.

Switch Port bandwidth utilization is Overloaded (utilization %)

The fault threshold set for the overloaded state has been exceeded.

When this fault has been cleared, the following message displays: Switch port bandwidth utilization is Ok.

Manage Fault Settings > Switch > Port Utilization

Verify that the fault threshold is set correctly.

If the threshold is set correctly, review your network to determine the action necessary to clear the fault condition.


Router Fault

Table 2-6 Router Fault 

Fault Description
Explanation
Related Setting
Recommended Action

Device was not reachable via SNMP

The SNMP Agent on the switch is down.

When this fault has been cleared, the following message displays: Device was reachable via SNMP.

Manage Fault Settings > Router > SNMP Reachable

Make sure that the router SNMP agent is active.