<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Test 9800-CL Wireless Controller setup and configuration as a third controller in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/test-9800-cl-wireless-controller-setup-and-configuration-as-a/m-p/3947194#M202042</link>
    <description>Hi Mr Dude,&lt;BR /&gt;&lt;BR /&gt;Thanks for the suggestion. I ran the command as you suggested and indeed I do not have any Trustpoint listed. However, I can't seem to get the controller into config mode. Config t. conf t. doesn't seem to work and enable isn't accepted either. I tried to run it and got the following:&lt;BR /&gt;&lt;BR /&gt;v000002&amp;gt;wireless config vwlc-ssc key-size 2048 signature-algo sha256 password superpassword&lt;BR /&gt;^&lt;BR /&gt;% Invalid input detected at '^' marker.&lt;BR /&gt;&lt;BR /&gt;Am I doing something really silly?&lt;BR /&gt;&lt;BR /&gt;Thanks.</description>
    <pubDate>Thu, 24 Oct 2019 10:41:04 GMT</pubDate>
    <dc:creator>Group IT</dc:creator>
    <dc:date>2019-10-24T10:41:04Z</dc:date>
    <item>
      <title>Test 9800-CL Wireless Controller setup and configuration as a third controller</title>
      <link>https://community.cisco.com/t5/wireless/test-9800-cl-wireless-controller-setup-and-configuration-as-a/m-p/3946313#M202040</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought I was getting to grips with the wireless world but I am finding that I am a little out of my depth setting up a test&amp;nbsp;Cisco Catalyst 9800-CL Wireless Controller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This will be my third controller, this one I am testing in a VMWare ESXi environment which sits on my live network.&lt;/P&gt;&lt;P&gt;So I have controller one at our HQ "CISCO-CAPWAP-CONTROLLER" is on 10.11.0.230, controller two is in a datacentre "CISCO-CAPWAP-CONTROLLER" and is on 10.11.202.230. I have introduced controller three which is the test&amp;nbsp;9800-CL Wireless Controller at our HQ also&amp;nbsp;"CISCO-CAPWAP-CONTROLLER" and is on IP 10.11.0.199.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a test C9120AXI-E which is plugged into a trunked port. Quite rightly so, the older controllers are rejecting it, but it never seems to attempt to connect to the&amp;nbsp;9800-CL. It seems to just repeat the following process:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt; CAPWAP State: Discovery
[*10/23/2019 14:04:17.6470] IP DNS query for CISCO-CAPWAP-CONTROLLER.mydomain.local
[*10/23/2019 14:04:17.6500] DNS resolved CISCO-CAPWAP-CONTROLLER.mydomain.local
[*10/23/2019 14:04:17.6500] DNS discover IP addr: 10.11.0.199
[*10/23/2019 14:04:17.6500] DNS discover IP addr: 10.11.0.230
[*10/23/2019 14:04:17.6500] DNS discover IP addr: 10.11.202.230
[*10/23/2019 14:04:17.6510] Discovery Request sent to 10.11.0.199, discovery type DNS(3)
[*10/23/2019 14:04:17.6520] Discovery Request sent to 10.11.202.230, discovery type DNS(3)
[*10/23/2019 14:04:17.6530] Discovery Request sent to 10.11.0.230, discovery type DNS(3)
[*10/23/2019 14:04:17.6540] Discovery Request sent to 255.255.255.255, discovery type UNKNOWN(0)
[*10/23/2019 14:04:17.6560] Discovery Response from 10.11.0.230
[*10/23/2019 14:04:17.6610] Discovery response from MWAR 'wlc-h003214' running version 8.5.151.0 is rejected.
[*10/23/2019 14:04:17.6610] Failed to decode discovery response(status = 4).
[*10/23/2019 14:04:17.6610] CAPWAP SM handler: Failed to process message type 2 state 2.
[*10/23/2019 14:04:17.6610] Failed to handle capwap control message from controller - status 4
[*10/23/2019 14:04:17.6610] Failed to process unencrypted capwap packet 0x55a0066000 from 10.11.0.230
[*10/23/2019 14:04:17.6610] Failed to send message to CAPWAP state machine, msgId 0
[*10/23/2019 14:04:17.6610] Failed to send capwap message 0 to the state machine. Packet already freed.
[*10/23/2019 14:04:17.6610] IPv4 wtpProcessPacketFromSocket returned 4
[*10/23/2019 14:04:17.6620] Discovery Response from 10.11.202.230
[*10/23/2019 14:04:17.6650] Discovery response from MWAR 'wlc-h000453' running version 8.5.151.0 is rejected.
[*10/23/2019 14:04:17.6650] Failed to decode discovery response(status = 4).
[*10/23/2019 14:04:17.6650] CAPWAP SM handler: Failed to process message type 2 state 2.
[*10/23/2019 14:04:17.6650] Failed to handle capwap control message from controller - status 4
[*10/23/2019 14:04:17.6650] Failed to process unencrypted capwap packet 0x55a0064000 from 10.11.202.230
[*10/23/2019 14:04:17.6650] Failed to send message to CAPWAP state machine, msgId 0
[*10/23/2019 14:04:17.6650] Failed to send capwap message 0 to the state machine. Packet already freed.
[*10/23/2019 14:04:17.6650] IPv4 wtpProcessPacketFromSocket returned 4&lt;/PRE&gt;&lt;P&gt;So from what I can see, DNS is configured correctly so that the AP can see all of the available controllers but I doesn't seem to be requesting to join the 9800-CL.&lt;/P&gt;&lt;P&gt;Can anyone advise what step I have missed or where I can check whats going wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 18:11:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/test-9800-cl-wireless-controller-setup-and-configuration-as-a/m-p/3946313#M202040</guid>
      <dc:creator>Group IT</dc:creator>
      <dc:date>2021-07-05T18:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: Test 9800-CL Wireless Controller setup and configuration as a third controller</title>
      <link>https://community.cisco.com/t5/wireless/test-9800-cl-wireless-controller-setup-and-configuration-as-a/m-p/3947096#M202041</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Can you check the wireless management trustpoint?&lt;BR /&gt;&lt;BR /&gt;show wireless management trustpoint&lt;BR /&gt;&lt;BR /&gt;It should look something like:&lt;BR /&gt;Trustpoint Name : CISCO_IDEVID_SUDI&lt;BR /&gt;Certificate Info : Available&lt;BR /&gt;Certificate Type : MIC&lt;BR /&gt;Private key Info : Available&lt;BR /&gt;FIPS suitability : Not Applicable&lt;BR /&gt;&lt;BR /&gt;If this isn't the case you can generate it with: wireless config vwlc-ssc key-size 2048 signature-algo sha256 password ThisisaPassword01</description>
      <pubDate>Thu, 24 Oct 2019 08:17:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/test-9800-cl-wireless-controller-setup-and-configuration-as-a/m-p/3947096#M202041</guid>
      <dc:creator>MrDude</dc:creator>
      <dc:date>2019-10-24T08:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: Test 9800-CL Wireless Controller setup and configuration as a third controller</title>
      <link>https://community.cisco.com/t5/wireless/test-9800-cl-wireless-controller-setup-and-configuration-as-a/m-p/3947194#M202042</link>
      <description>Hi Mr Dude,&lt;BR /&gt;&lt;BR /&gt;Thanks for the suggestion. I ran the command as you suggested and indeed I do not have any Trustpoint listed. However, I can't seem to get the controller into config mode. Config t. conf t. doesn't seem to work and enable isn't accepted either. I tried to run it and got the following:&lt;BR /&gt;&lt;BR /&gt;v000002&amp;gt;wireless config vwlc-ssc key-size 2048 signature-algo sha256 password superpassword&lt;BR /&gt;^&lt;BR /&gt;% Invalid input detected at '^' marker.&lt;BR /&gt;&lt;BR /&gt;Am I doing something really silly?&lt;BR /&gt;&lt;BR /&gt;Thanks.</description>
      <pubDate>Thu, 24 Oct 2019 10:41:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/test-9800-cl-wireless-controller-setup-and-configuration-as-a/m-p/3947194#M202042</guid>
      <dc:creator>Group IT</dc:creator>
      <dc:date>2019-10-24T10:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: Test 9800-CL Wireless Controller setup and configuration as a third controller</title>
      <link>https://community.cisco.com/t5/wireless/test-9800-cl-wireless-controller-setup-and-configuration-as-a/m-p/3948085#M202043</link>
      <description>&lt;P&gt;Hi, it looks like you need to go in to enable mode first. You shouldn't have to go in to configuration terminal to run the command.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 12:01:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/test-9800-cl-wireless-controller-setup-and-configuration-as-a/m-p/3948085#M202043</guid>
      <dc:creator>MrDude</dc:creator>
      <dc:date>2019-10-25T12:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: Test 9800-CL Wireless Controller setup and configuration as a third controller</title>
      <link>https://community.cisco.com/t5/wireless/test-9800-cl-wireless-controller-setup-and-configuration-as-a/m-p/3992622#M202044</link>
      <description>&lt;P&gt;Hey sorry! I have only just got back round to taking a look at this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think the problem was the the command to generate certificate had not specified an encryption level but still after it does not report any trustpoint.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;wireless config vwlc-ssc key-size 2048 signature-algo sha256 password 7 ThisisaPassword0&lt;BR /&gt;&lt;BR /&gt;wlc&amp;gt;show wireless management trustpoint&lt;BR /&gt;Trustpoint Name :&lt;BR /&gt;Certificate Info : Not Available&lt;BR /&gt;Private key Info : Not Available&lt;BR /&gt;FIPS suitability : Not Applicable&lt;/PRE&gt;</description>
      <pubDate>Tue, 03 Dec 2019 10:15:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/test-9800-cl-wireless-controller-setup-and-configuration-as-a/m-p/3992622#M202044</guid>
      <dc:creator>Group IT</dc:creator>
      <dc:date>2019-12-03T10:15:54Z</dc:date>
    </item>
  </channel>
</rss>

