<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LWAP - push ca cert to access point in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/lwap-push-ca-cert-to-access-point/m-p/3908378#M11782</link>
    <description>&lt;P&gt;Hello team&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to push a CA cert (Root / Sub) to an AP?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What we're trying to achieve is AP 802.1x authentication with ISE who's certs have been issued by a private PKI issuing CA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since the AP attempts to validate the ISE device cert during the mutual authn phase prior to 802.1x EAP/EAP-TLS transactions, the AP does not trust the cert presented by ISE and prevents the AP from initiating dot1x AuthN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;one approach we're considering is to push a CA cert down to the AP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ISE Live Logs:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV&gt;&lt;SPAN&gt;Event&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV&gt;5411 Supplicant stopped responding to ISE&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;&lt;SPAN&gt;Failure Reason&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV&gt;12931 Supplicant stopped responding to ISE after sending it the first EAP-TLS message&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;&lt;SPAN&gt;Resolution&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV&gt;Verify that supplicant is configured properly to conduct a full EAP conversation with ISE.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;Verify that NAS is configured properly to transfer EAP messages to/from supplicant.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;Verify that supplicant or NAS does not have a short timeout for EAP conversation.&amp;nbsp;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;Check the network that connects the Network Access Server to ISE.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;&lt;SPAN&gt;Root cause&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV&gt;Supplicant stopped responding to ISE after sending it the first EAP-TLS message&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for any guidance or recommendations.&lt;/P&gt;
&lt;P&gt;Regan&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 17:51:37 GMT</pubDate>
    <dc:creator>rdediana</dc:creator>
    <dc:date>2021-07-05T17:51:37Z</dc:date>
    <item>
      <title>LWAP - push ca cert to access point</title>
      <link>https://community.cisco.com/t5/wireless/lwap-push-ca-cert-to-access-point/m-p/3908378#M11782</link>
      <description>&lt;P&gt;Hello team&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to push a CA cert (Root / Sub) to an AP?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What we're trying to achieve is AP 802.1x authentication with ISE who's certs have been issued by a private PKI issuing CA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since the AP attempts to validate the ISE device cert during the mutual authn phase prior to 802.1x EAP/EAP-TLS transactions, the AP does not trust the cert presented by ISE and prevents the AP from initiating dot1x AuthN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;one approach we're considering is to push a CA cert down to the AP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ISE Live Logs:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV&gt;&lt;SPAN&gt;Event&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV&gt;5411 Supplicant stopped responding to ISE&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;&lt;SPAN&gt;Failure Reason&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV&gt;12931 Supplicant stopped responding to ISE after sending it the first EAP-TLS message&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;&lt;SPAN&gt;Resolution&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV&gt;Verify that supplicant is configured properly to conduct a full EAP conversation with ISE.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;Verify that NAS is configured properly to transfer EAP messages to/from supplicant.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;Verify that supplicant or NAS does not have a short timeout for EAP conversation.&amp;nbsp;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;Check the network that connects the Network Access Server to ISE.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;&lt;SPAN&gt;Root cause&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV&gt;Supplicant stopped responding to ISE after sending it the first EAP-TLS message&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for any guidance or recommendations.&lt;/P&gt;
&lt;P&gt;Regan&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 17:51:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/lwap-push-ca-cert-to-access-point/m-p/3908378#M11782</guid>
      <dc:creator>rdediana</dc:creator>
      <dc:date>2021-07-05T17:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: LWAP - push ca cert to access point</title>
      <link>https://community.cisco.com/t5/wireless/lwap-push-ca-cert-to-access-point/m-p/3908713#M11783</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Refer to:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-2/config-guide/b_cg82/b_cg82_chapter_01001.html#ID1638" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-2/config-guide/b_cg82/b_cg82_chapter_01001.html#ID1638&lt;/A&gt;&lt;/P&gt;&lt;H3&gt;Downloading Device Certificates (GUI)&lt;/H3&gt;&lt;H4&gt;Procedure&lt;/H4&gt;&lt;HR /&gt;&lt;DIV class="tableContainer"&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;1&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SF_StepFirst-84708D9F"&gt;Copy the device certificate to the default directory on your server.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;2&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;Choose&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Commands&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Download File&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to open the Download File to Controller page.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;3&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;From the File Type drop-down list, choose&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Vendor Device Certificate&lt;/STRONG&gt;.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;4&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;In the Certificate Password text box, enter the password that was used to protect the certificate.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;5&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;From the Transfer Mode drop-down list, choose from the following options:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN class="ph uicontrol"&gt;TFTP&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="ph uicontrol"&gt;FTP&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="ph uicontrol"&gt;SFTP&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(available in 7.4 and later releases)&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;6&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;In the IP Address text box, enter the IP address of the server.&lt;/P&gt;&lt;P class="p B1_Body1-F9CE5028"&gt;If you are using a TFTP server, the default values of 10 retries and 6 seconds for the Maximum Retries and Timeout text boxes should work correctly without any adjustment. However, you can change these values.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;7&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;Enter the maximum number of times that the TFTP server attempts to download the certificate in the Maximum Retries text box and the amount of time (in seconds) that the TFTP server attempts to download the certificate in the Timeout text box.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;8&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;In the File Path text box, enter the directory path of the certificate.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;9&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;In the File Name text box, enter the name of the certificate.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;10&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;If you are using an FTP server, follow these steps:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P class="ph cmd SsF_StepsubFirst-9DE09F38"&gt;In the Server Login Username text box, enter the username to log into the FTP server.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class="ph cmd SsN_StepsubNext-30777A2C"&gt;In the Server Login Password text box, enter the password to log into the FTP server.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class="ph cmd SsN_StepsubNext-30777A2C"&gt;In the Server Port Number text box, enter the port number on the FTP server through which the download occurs. The default value is 21.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;11&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Download&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to download the device certificate to the controller. A message appears indicating the status of the download.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;12&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;After the download is complete, choose&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph menucascade"&gt;&lt;SPAN class="ph uicontrol"&gt;Commands&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Reboot&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Reboot&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;13&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;If prompted to save your changes, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Save and Reboot&lt;/STRONG&gt;.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;14&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to confirm your decision to reboot the controller.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;HR /&gt;&lt;H3&gt;Downloading Device Certificates (CLI)&lt;/H3&gt;&lt;H4&gt;Procedure&lt;/H4&gt;&lt;HR /&gt;&lt;DIV class="tableContainer"&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;1&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SF_StepFirst-84708D9F"&gt;Log onto the controller CLI.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;2&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;Specify the transfer mode used to download the config file by entering this command:&lt;/P&gt;&lt;P class="p B1_Body1-F9CE5028"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;transfer download mode&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;{&lt;SPAN class="keyword kwd"&gt;tftp&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;|&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="keyword kwd"&gt;ftp&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;|&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="keyword kwd"&gt;sftp&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;}&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;3&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;Specify the type of the file to be downloaded by entering this command:&lt;/P&gt;&lt;P class="p B1_Body1-F9CE5028"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;transfer download datatype eapdevcert&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;4&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;Specify the certificate’s private key by entering this command:&lt;/P&gt;&lt;P class="p B1_Body1-F9CE5028"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;transfer download certpassword&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;password&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;5&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;Specify the IP address of the TFTP or FTP server by entering this command:&lt;/P&gt;&lt;P class="p B1_Body1-F9CE5028"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;transfer download serverip&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;server-ip-address&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;6&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;Specify the name of the config file to be downloaded by entering this command:&lt;/P&gt;&lt;P class="p B1_Body1-F9CE5028"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;transfer download path&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;server-path-to-file&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;7&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;Specify the directory path of the config file by entering this command:&lt;/P&gt;&lt;P class="p B1_Body1-F9CE5028"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;transfer download filename&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;filename.pem&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;8&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd SN_StepNext-8DFF4E90"&gt;(Optional) If you are using a TFTP server, enter these commands:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class="p Bu1_Bullet1-CC106A77"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;transfer download tftpMaxRetries retries&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class="p Bu1_Bullet1-CC106A77"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;transfer download tftpPktTimeout timeout&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;The default values of 10 retries and a 6-second timeout should work correctly without any adjustment. However, you can change these values. To do so, enter the maximum number of times that the TFTP server attempts to download the software for the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;retries&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;parameter and the amount of time (in seconds) that the TFTP server attempts to download the software for the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;timeout&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;parameter.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;9&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd"&gt;If you are using an FTP server, enter these commands (skip this step if you are not using FTP server):&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class="p Bu1_Bullet1-CC106A77"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;transfer download username&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;username&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class="p Bu1_Bullet1-CC106A77"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;transfer download password&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;password&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class="p Bu1_Bullet1-CC106A77"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;transfer download port&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;port&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;The default value for the port parameter is 21.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;10&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd"&gt;View the updated settings by entering the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;transfer download start&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;command. Answer&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;y&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;when prompted to confirm the current settings and start the download process.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Step&amp;nbsp;11&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="ph cmd"&gt;Reboot the controller by entering this command:&lt;/P&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;reset system&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;***Please mark as accepted solution if it helped you***&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 15 Aug 2019 15:40:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/lwap-push-ca-cert-to-access-point/m-p/3908713#M11783</guid>
      <dc:creator>superego</dc:creator>
      <dc:date>2019-08-15T15:40:30Z</dc:date>
    </item>
  </channel>
</rss>

