C-17
Cisco IOS Software Configuration Guide for Cisco Aironet Access Points
OL-11350-01
AppendixC Error and Event Messages
802.11 Subsystem Messages
Error Message DOT11-3-TKIP_MIC_FAILURE_REPEATED: “Two TKIP Michael MIC failures were
detected within %s seconds on %s interface. The interface will be put on MIC
failure hold state for next %d seconds”
Explanation Two TKIP Michael MIC failures were detected within the indicated time on the
indicated interface. Because this usually indicates an active attack on your network, the interface
will be put on hold for the indicated time. During this hold time, stations using TKIP ciphers are
disassociated and cannot reassociate until the hold time ends. At the end of the hold time, the
interface operates normally.
Recommended Action MIC failures usually indicate an active attack on your network. Search for and
remove potential rogue devices from your wireless LAN. If this is a false alarm and the interface
should not be on hold this long, use the countermeasure tkip hold-time command to adjust the hold
time.
Error Message DOT11-4-TKIP_REPLAY: “TKIP TSC replay was detected on a packet (TSC
0x%ssx received from %e).”
Explanation TKIP TSC replay was detected on a frame. A replay of the TKIP TSC in a received
packet almost indicates an active attack.
Recommended Action None.
Error Message DOT11-4-WLAN_RESOURCE_LIMIT: “WLAN limit exceeded on interface %s and
network-id %d.”
Explanation This access point has reached its limit of 16 VLANs or WLANs.
Recommended Action Unconfigure or reduce static VLANS if access point is trying to associate with
RADIUS assigned Network-ID turned on.
Error Message SOAP-3-WGB_CLIENT_VLAN_SOAP: “Workgroup Bridge Ethernet client VLAN
not configured.”
Explanation No VLAN is configured for client devices attached to the workgroup bridge.
Recommended Action Configure a VLAN to accommodate client devices attached to the workgroup
bridge.
Error Message DOT11-4-NO_VLAN_NAME: “VLAN name %s from RADIUS server is not
configured for station %e.”
Explanation The VLAN name returned by the RADIUS server must be configured in the access
point.
Recommended Action Configure the VLAN name in the access point.