12.5 Troubleshooting Wireless Clients and Network Access
Key Takeaways
Client problems are isolated by following the connection journey: association, authentication, IP addressing, DNS, and application, then roaming.
On AOS-CX ports,
show port-access clients detailandshow aaa authentication port-access interface <port> client-statusshow each client's method, status, and role, andshow radius-serverconfirms RADIUS reachability.An Access-Reject from ClearPass applies the reject role, an unreachable RADIUS server applies the critical role, and a client over the client limit is never onboarded.
Bridged SSIDs fail when the client VLAN is missing on the AP's switch port or trunks; tunneled SSIDs depend on the gateway cluster and its VLANs instead.
Roaming problems in AOS 10 involve 802.11r/OKC settings and the Key Management Service; Central client views, events, and UXI results show where the journey breaks.
12.5 Troubleshooting Wireless Clients and Network Access
Quick Summary: "Wi-Fi is down" and "my port doesn't work" are symptoms, not diagnoses. The fastest way to the cause is to follow the connection journey: did the client associate (wireless) or link up (wired), did it authenticate, did it get the right IP address, does DNS work, and does the application work? The first failed step tells you which layer and which system to investigate: the RF, the switch port, the RADIUS server, DHCP, DNS, or the application.
The Connection Journey
| Failed step | Likely causes | Where to look |
|---|---|---|
| 1. Association | SSID not offered in that band, client lacks WPA3/6 GHz support, weak signal, AP down | Central AP and SSID status; client capabilities; signal strength |
| 2. Authentication | Wrong credentials, untrusted server certificate, expired account, RADIUS shared-secret mismatch, switch or gateway not defined as a RADIUS client, RADIUS unreachable | ClearPass Access Tracker; show port-access clients detail; show radius-server |
| 3. Role / VLAN | Role name returned by ClearPass not defined locally, VLAN missing on the switch or trunk, wrong gateway cluster VLAN | show port-access role; show vlan; Central client details |
| 4. DHCP | Missing helper on the gateway SVI, exhausted scope, DHCP snooping dropping offers on an untrusted uplink | show ip helper-address; show dhcp-relay; show dhcp-snooping statistics |
| 5. DNS | Wrong DNS servers, firewall blocking UDP 53 | Ping by IP versus by name (Section 12.3) |
| 6. Application | Server, firewall, or ACL problem | Traceroute, ACL counters, application owners |
| 7. Roaming | Fast roaming not enabled, client lacks 802.11r support, sticky clients | Central events, ClientMatch steer events, roaming settings |
Wired Authentication on AOS-CX
| Command | What it tells you |
|---|---|
show port-access clients | Each client's MAC address, port, authentication method, status, and role |
show port-access clients detail | Detailed per-client information, including the applied role and VLAN |
show aaa authentication port-access interface 1/1/14 client-status | The authentication state of every client on one port |
show radius-server | Configured RADIUS servers and their reachability |
show radius dyn-authorization | CoA and Disconnect counters, to confirm role changes from ClearPass arrive |
show port-access role | Locally defined roles, to confirm the role name ClearPass returns exists |
How the special roles help you read the situation (AOS-CX Security Guide):
- Reject role applied: ClearPass is reachable and returned an Access-Reject. Check the reason in ClearPass (wrong password, expired certificate, policy mismatch).
- Critical role applied: the RADIUS server was unreachable or timed out. Check routing to the server, the shared secret, and whether the switch is defined as a RADIUS client.
- Pre-auth role during onboarding: with concurrent onboarding, the client waits in the pre-auth role until a method succeeds or all fail.
- Second device never onboards: the port's client limit (
aaa authentication port-access client-limit, default 1) may be lower than the number of devices, such as a phone plus a PC.
Remember the quiet period: after failed attempts, AOS-CX waits 60 seconds by default before processing that client again, so retries right after a fix may appear to fail.
Wireless-Specific Checks
Bridged versus tunneled SSIDs
- Bridged: the client's VLAN must be tagged on the AP's switch port and every trunk to its gateway. A missing VLAN gives a client that authenticates but never gets an address.
- Tunneled: client VLANs live on the gateway cluster. Check that the cluster is up and that the user VLAN exists there; the access switch only needs the AP management VLAN (Section 7.2).
Security mismatches
- A 6 GHz SSID requires WPA3 or Enhanced Open (OWE); clients that support only WPA2 will not join it.
- WPA3 requires Protected Management Frames; older clients without PMF support cannot join a WPA3-only SSID.
- MPSK Local supports WPA2-PSK-AES and up to 24 passphrases per SSID; a device using the wrong passphrase simply fails the four-way handshake.
Roaming
- In AOS 10, fast roaming relies on 802.11r or OKC plus the Key Management Service in Central distributing keys to AirMatch neighbor APs. AP CLI
show ap pmkcacheshows the cached keys on an AP (AOS 10 TechDocs). - If Central is unreachable, existing clients can still fast-roam to neighbors that already have their keys, but new clients perform full authentication when roaming.
- Sticky clients and band problems are ClientMatch's job; Central's ClientMatch steer events show whether steering is happening.
Central and UXI
- Central's client view shows each client's status, SSID, band, role, VLAN, and recent events, which usually reveals the failing step immediately.
- AI Insights may already have flagged the pattern, for example a spike in 802.1X failures or slow DHCP.
- UXI sensors report which journey step failed (Wi-Fi, authentication, DHCP, DNS, or application), separating network faults from service faults (Section 11.3).
A Worked Example
Symptom: New laptops on floor 3 connect to the bridged SSID LAB but show a 169.254.x.x address.
- Association and authentication succeed (Central shows the client authenticated with role LAB_USER).
- The role assigns VLAN 40. The client gets no DHCP address, so step 4 fails.
- Because the SSID is bridged, check VLAN 40 on the AP's switch port and uplinks:
show vlan port 1/1/41shows that VLAN 40 is not tagged on the AP port. - Fix: add VLAN 40 to the AP port trunk, verify with a test client, and update the port map.
Common Exam Traps
- Blaming RF for authentication failures. Strong signal with EAP timeouts points to RADIUS, certificates, or the network path to the server.
- Confusing reject and critical roles. Reject means the server answered "no"; critical means the server did not answer.
- Forgetting that bridged SSIDs need switch VLANs. Tunneled SSIDs do not; bridged SSIDs do.
Users on a bridged SSID authenticate successfully, Central shows the correct role and VLAN 40, but the clients receive 169.254.x.x addresses. Other VLANs work on the same APs. What should the technician check first?
Whether the RADIUS shared secret on Central matches the one on ClearPass
Whether VLAN 40 is tagged on the AP's switch port and the trunks to its gateway
Whether the clients support WPA3-SAE on the bridged SSID's security mode
Whether the APs are using 80 MHz channels that some clients do not support
On an AOS-CX access port, 802.1X clients are placed in the critical role. What does this indicate?
The RADIUS server was unreachable or the requests timed out
ClearPass returned an Access-Reject for the clients' credentials
The clients exceeded the port's configured client limit
The clients are still waiting to complete a captive portal login
A desk port has an IP phone and a PC daisy-chained behind it. The phone authenticates, but the PC never appears in show port-access clients. Which AOS-CX setting is the most likely cause?
The port uses the default client-mode authentication for all its devices
The port's port-access client limit is still at the default of 1
The switch has DHCP snooping enabled on the PC's data VLAN
The voice VLAN is flagged with the voice command in the VLAN context
Sections you finish are checked off in the contents.