12.5 Troubleshooting Wireless Clients and Network Access

Key Takeaways

  • Client problems are isolated by following the connection journey: association, authentication, IP addressing, DNS, and application, then roaming.

  • On AOS-CX ports, show port-access clients detail and show aaa authentication port-access interface <port> client-status show each client's method, status, and role, and show radius-server confirms RADIUS reachability.

  • An Access-Reject from ClearPass applies the reject role, an unreachable RADIUS server applies the critical role, and a client over the client limit is never onboarded.

  • Bridged SSIDs fail when the client VLAN is missing on the AP's switch port or trunks; tunneled SSIDs depend on the gateway cluster and its VLANs instead.

  • Roaming problems in AOS 10 involve 802.11r/OKC settings and the Key Management Service; Central client views, events, and UXI results show where the journey breaks.

Last updated: October 2026

12.5 Troubleshooting Wireless Clients and Network Access

Quick Summary: "Wi-Fi is down" and "my port doesn't work" are symptoms, not diagnoses. The fastest way to the cause is to follow the connection journey: did the client associate (wireless) or link up (wired), did it authenticate, did it get the right IP address, does DNS work, and does the application work? The first failed step tells you which layer and which system to investigate: the RF, the switch port, the RADIUS server, DHCP, DNS, or the application.


The Connection Journey

Loading diagram...
Failed stepLikely causesWhere to look
1. AssociationSSID not offered in that band, client lacks WPA3/6 GHz support, weak signal, AP downCentral AP and SSID status; client capabilities; signal strength
2. AuthenticationWrong credentials, untrusted server certificate, expired account, RADIUS shared-secret mismatch, switch or gateway not defined as a RADIUS client, RADIUS unreachableClearPass Access Tracker; show port-access clients detail; show radius-server
3. Role / VLANRole name returned by ClearPass not defined locally, VLAN missing on the switch or trunk, wrong gateway cluster VLANshow port-access role; show vlan; Central client details
4. DHCPMissing helper on the gateway SVI, exhausted scope, DHCP snooping dropping offers on an untrusted uplinkshow ip helper-address; show dhcp-relay; show dhcp-snooping statistics
5. DNSWrong DNS servers, firewall blocking UDP 53Ping by IP versus by name (Section 12.3)
6. ApplicationServer, firewall, or ACL problemTraceroute, ACL counters, application owners
7. RoamingFast roaming not enabled, client lacks 802.11r support, sticky clientsCentral events, ClientMatch steer events, roaming settings

Wired Authentication on AOS-CX

CommandWhat it tells you
show port-access clientsEach client's MAC address, port, authentication method, status, and role
show port-access clients detailDetailed per-client information, including the applied role and VLAN
show aaa authentication port-access interface 1/1/14 client-statusThe authentication state of every client on one port
show radius-serverConfigured RADIUS servers and their reachability
show radius dyn-authorizationCoA and Disconnect counters, to confirm role changes from ClearPass arrive
show port-access roleLocally defined roles, to confirm the role name ClearPass returns exists

How the special roles help you read the situation (AOS-CX Security Guide):

  • Reject role applied: ClearPass is reachable and returned an Access-Reject. Check the reason in ClearPass (wrong password, expired certificate, policy mismatch).
  • Critical role applied: the RADIUS server was unreachable or timed out. Check routing to the server, the shared secret, and whether the switch is defined as a RADIUS client.
  • Pre-auth role during onboarding: with concurrent onboarding, the client waits in the pre-auth role until a method succeeds or all fail.
  • Second device never onboards: the port's client limit (aaa authentication port-access client-limit, default 1) may be lower than the number of devices, such as a phone plus a PC.

Remember the quiet period: after failed attempts, AOS-CX waits 60 seconds by default before processing that client again, so retries right after a fix may appear to fail.


Wireless-Specific Checks

Bridged versus tunneled SSIDs

  • Bridged: the client's VLAN must be tagged on the AP's switch port and every trunk to its gateway. A missing VLAN gives a client that authenticates but never gets an address.
  • Tunneled: client VLANs live on the gateway cluster. Check that the cluster is up and that the user VLAN exists there; the access switch only needs the AP management VLAN (Section 7.2).

Security mismatches

  • A 6 GHz SSID requires WPA3 or Enhanced Open (OWE); clients that support only WPA2 will not join it.
  • WPA3 requires Protected Management Frames; older clients without PMF support cannot join a WPA3-only SSID.
  • MPSK Local supports WPA2-PSK-AES and up to 24 passphrases per SSID; a device using the wrong passphrase simply fails the four-way handshake.

Roaming

  • In AOS 10, fast roaming relies on 802.11r or OKC plus the Key Management Service in Central distributing keys to AirMatch neighbor APs. AP CLI show ap pmkcache shows the cached keys on an AP (AOS 10 TechDocs).
  • If Central is unreachable, existing clients can still fast-roam to neighbors that already have their keys, but new clients perform full authentication when roaming.
  • Sticky clients and band problems are ClientMatch's job; Central's ClientMatch steer events show whether steering is happening.

Central and UXI

  • Central's client view shows each client's status, SSID, band, role, VLAN, and recent events, which usually reveals the failing step immediately.
  • AI Insights may already have flagged the pattern, for example a spike in 802.1X failures or slow DHCP.
  • UXI sensors report which journey step failed (Wi-Fi, authentication, DHCP, DNS, or application), separating network faults from service faults (Section 11.3).

A Worked Example

Symptom: New laptops on floor 3 connect to the bridged SSID LAB but show a 169.254.x.x address.

  1. Association and authentication succeed (Central shows the client authenticated with role LAB_USER).
  2. The role assigns VLAN 40. The client gets no DHCP address, so step 4 fails.
  3. Because the SSID is bridged, check VLAN 40 on the AP's switch port and uplinks: show vlan port 1/1/41 shows that VLAN 40 is not tagged on the AP port.
  4. Fix: add VLAN 40 to the AP port trunk, verify with a test client, and update the port map.

Common Exam Traps

  • Blaming RF for authentication failures. Strong signal with EAP timeouts points to RADIUS, certificates, or the network path to the server.
  • Confusing reject and critical roles. Reject means the server answered "no"; critical means the server did not answer.
  • Forgetting that bridged SSIDs need switch VLANs. Tunneled SSIDs do not; bridged SSIDs do.
Test Your Knowledge

Users on a bridged SSID authenticate successfully, Central shows the correct role and VLAN 40, but the clients receive 169.254.x.x addresses. Other VLANs work on the same APs. What should the technician check first?

A

Whether the RADIUS shared secret on Central matches the one on ClearPass

B

Whether VLAN 40 is tagged on the AP's switch port and the trunks to its gateway

C

Whether the clients support WPA3-SAE on the bridged SSID's security mode

D

Whether the APs are using 80 MHz channels that some clients do not support

Test Your Knowledge

On an AOS-CX access port, 802.1X clients are placed in the critical role. What does this indicate?

A

The RADIUS server was unreachable or the requests timed out

B

ClearPass returned an Access-Reject for the clients' credentials

C

The clients exceeded the port's configured client limit

D

The clients are still waiting to complete a captive portal login

Test Your Knowledge

A desk port has an IP phone and a PC daisy-chained behind it. The phone authenticates, but the PC never appears in show port-access clients. Which AOS-CX setting is the most likely cause?

A

The port uses the default client-mode authentication for all its devices

B

The port's port-access client limit is still at the default of 1

C

The switch has DHCP snooping enabled on the PC's data VLAN

D

The voice VLAN is flagged with the voice command in the VLAN context

Sections you finish are checked off in the contents.