<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mobility link down after update 17.3.3 on 9800-CL in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4505055#M235699</link>
    <description>&lt;P&gt;deleted message&lt;/P&gt;</description>
    <pubDate>Thu, 18 Nov 2021 16:19:42 GMT</pubDate>
    <dc:creator>j.rambeau</dc:creator>
    <dc:date>2021-11-18T16:19:42Z</dc:date>
    <item>
      <title>Mobility link down after update 17.3.3 on 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4304861#M227122</link>
      <description>&lt;P&gt;After updating wlc 9800-CL (17.3.1) to 17.3.3 the mobility link with wlc Aireos 8.5.164.0 went down. Trying to rebuild it failed.&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 20:21:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4304861#M227122</guid>
      <dc:creator>Frank Benders</dc:creator>
      <dc:date>2021-07-05T20:21:33Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility link down after update 17.3.3 on 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4305094#M227130</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- How does it fail (which error messages are observed) -&amp;gt; And or check the &lt;STRONG&gt;logs&lt;/STRONG&gt; of &lt;U&gt;both&lt;/U&gt; controllers, when trying to rebuild.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2021 18:01:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4305094#M227130</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2021-03-10T18:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility link down after update 17.3.3 on 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4305507#M227151</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for replying:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You're right: always check your log files...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;After updating wlc 9800-CL (17.3.1) to 17.3.3 the mobility link with wlc Aireos 8.5.164.0 went down. Trying to rebuild it failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Errors repeatedly on a 5508 wlc:&lt;/P&gt;&lt;P&gt;2&lt;FONT face="terminal,monaco"&gt;021-03-10T10:31:42.858177+01:00 err 5508wlc-01 wlc-01: *mobilityCapwapSocketTask: Mar 10 10:31:42.921: %DTLS2-3-HANDSHAKE_FAILURE: dtls2.c:1502 DTLS handshake failed for link xxx.xx.xxx.244:16666 &amp;lt;-&amp;gt; xxx.xx.xxx.250:16666 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="terminal,monaco"&gt;2021-03-10T10:31:42.646138+01:00 err 5508wlc-01 wlc-01: *mobilityCapwapSocketTask: Mar 10 10:31:42.707: %SSHPM-3-GENERIC_CERT_ERROR: sshpmPkiApi.c:2243 Certificate validation failed! Reason , Certificate type : MIC, Certificate issuer :Other&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="terminal,monaco"&gt;2021-03-10T10:31:42.646138+01:00 err 5508wlc-01 wlc-01: *mobilityCapwapSocketTask: Mar 10 10:31:42.707: %SSHPM-3-UNKNOWN_CERT_ISSUER: sshpmPkiApi.c:2022 Invalid AP certificate. Issuer unknown&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Errors on the 9800-CL wlc:&lt;/P&gt;&lt;P&gt;Mar 11 09:39:49.370: %DTLS_TRACE_MSG-3-WLC_DTLS_ERR: Chassis 1 R0/0: mobilityd: DTLS Error, session:xxx.xx.xxx.244[16666], Certificate validation failed&lt;/P&gt;&lt;P&gt;Mar 11 09:39:49.370: %CERT_MGR_ERRMSG-3-CERT_VALIDATION_ERR: Chassis 1 R0/0: mobilityd: Certificate Validation Error, Cert validation status:pki_ssl_status@pki_ssl_status:PKI_SSL_ERROR&lt;/P&gt;&lt;P&gt;Mar 11 09:39:49.368: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed. The certificate (SN: 2AEEACF9000000139ADE) has expired. Validity period ended on &lt;FONT color="#FF6600"&gt;2020-11-30T11:27:53Z&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Mar 11 09:39:38.421: %MM_INFRA_LOG-3-RECV_FAILED: Chassis 1 R0/0: mobilityd: Unable to receive mobility message aplist_update from ipv4: xxx.xx.xxx.244 . reason: Peer link is down&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The problem is in the Validity period of the certificate. Should be nice to have a workaround for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In november last year this command: config ap cert-expiry-ignore mic enabled&lt;BR /&gt;AP's are returning to 5508wlc-01.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Must be the security part of mobility path which, I believe, is mandatory on the 9800-series.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 10:03:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4305507#M227151</guid>
      <dc:creator>Frank Benders</dc:creator>
      <dc:date>2021-03-11T10:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility link down after update 17.3.3 on 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4305521#M227153</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Check if the &lt;FONT color="#008000"&gt;&lt;STRONG&gt;resolving&lt;/STRONG&gt;-reply&lt;/FONT&gt; from this thread can help :&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://community.cisco.com/t5/wireless/inter-release-controller-mobility-ircm-with-5508-fail-control/td-p/4273720" target="_blank"&gt;https://community.cisco.com/t5/wireless/inter-release-controller-mobility-ircm-with-5508-fail-control/td-p/4273720&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 10:51:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4305521#M227153</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2021-03-11T10:51:00Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility link down after update 17.3.3 on 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4307394#M227304</link>
      <description>&lt;P&gt;Thanks for this reply and your time, followed these steps:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;9800-CL#conf t&lt;BR /&gt;Enter configuration commands, one per line. End with CNTL/Z.&lt;BR /&gt;9800-CL(config)#crypto pki certificate map map1 1&lt;BR /&gt;9800-CL(ca-certificate-map)#issuer-name co Cisco Manufacturing CA&lt;BR /&gt;9800-CL(ca-certificate-map)#exit&lt;BR /&gt;9800-CL(config)#crypto pki trustpool policy&lt;BR /&gt;9800-CL(ca-trustpool)#match certificate map1 allow expired-certificate&lt;BR /&gt;9800-CL(ca-trustpool)#end&lt;BR /&gt;9800-CL#&lt;/P&gt;&lt;P&gt;next try rebuilding mobility-path:&lt;/P&gt;&lt;P&gt;Errors repeatedly on a 5508 wlc:&lt;/P&gt;&lt;P&gt;2021-03-15T10:24:47.062173+01:00 err 5508wlc-01 wlc-01: *mobilityCapwapSocketTask: Mar 15 10:24:47.104: %DTLS2-3-HANDSHAKE_FAILURE: dtls2.c:1502 DTLS handshake failed for link xxx.xx.xxx.244:16666 &amp;lt;-&amp;gt; xxx.xx.xxx.250:16666&lt;BR /&gt;2021-03-15T10:24:47.062044+01:00 err 5508wlc-01 wlc-01: *mobilityCapwapSocketTask: Mar 15 10:24:47.103: %SSHPM-3-GENERIC_CERT_ERROR: sshpmPkiApi.c:2243 Certificate validation failed! Reason , Certificate type : MIC, Certificate issuer :Other&lt;BR /&gt;2021-03-15T10:24:47.061849+01:00 err 5508wlc-01 wlc-01: *mobilityCapwapSocketTask: Mar 15 10:24:47.103: %SSHPM-3-UNKNOWN_CERT_ISSUER: sshpmPkiApi.c:2022 Invalid AP certificate. Issuer unknown&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Errors on the 9800-CL wlc:&lt;/P&gt;&lt;P&gt;Mar 15 09:21:24.716: %MM_INFRA_LOG-3-RECV_FAILED: Chassis 1 R0/0: mobilityd: Unable to receive mobility message aplist_update from ipv4: xxx.xx.xxx.244 . reason: Peer link is down&lt;BR /&gt;Mar 15 09:20:47.036: %MM_NODE_LOG-5-KEEP_ALIVE: Chassis 1 R0/0: mobilityd: Mobility Control tunnel to peer IP: xxx.xx.xxx.244 changed state to UP&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Link still down. But no certificate message anymore.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 10:37:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4307394#M227304</guid>
      <dc:creator>Frank Benders</dc:creator>
      <dc:date>2021-03-15T10:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility link down after update 17.3.3 on 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4307422#M227306</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Try to reboot the 5508 , check if that helps , if not try to upgrade to the latest&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;8.5.164.x&lt;/STRONG&gt; version available for the 5508&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;M.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 11:30:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4307422#M227306</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2021-03-15T11:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility link down after update 17.3.3 on 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4308163#M227355</link>
      <description>&lt;P&gt;Thanks for your help. I rebuild the mobility path again and now it works. Didn't have to reboot the controller.&lt;/P&gt;&lt;P&gt;Used this manual:&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-9/config-guide/b_cg89/encrypted_mobility_tunnel.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-9/config-guide/b_cg89/encrypted_mobility_tunnel.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Mar 2021 14:07:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4308163#M227355</guid>
      <dc:creator>Frank Benders</dc:creator>
      <dc:date>2021-03-16T14:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility link down after update 17.3.3 on 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4505055#M235699</link>
      <description>&lt;P&gt;deleted message&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 16:19:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4505055#M235699</guid>
      <dc:creator>j.rambeau</dc:creator>
      <dc:date>2021-11-18T16:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility link down after update 17.3.3 on 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4505065#M235701</link>
      <description>&lt;P&gt;I had the same issue and solved the problem thanks to the documentation. Solution is: if you are running a 9800-CL version, don't forget to configure the 9800 SSC Hash on the AireOS controller:&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;config mobility group member hash peer-ip-addr 40-digit-ssc-hash-key &lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;SSC hash is needed on for peers that do not use a MIC certificate. For example: Cisco Catalyst 9800-CL Wireless Controllers.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 18 Nov 2021 16:18:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/4505065#M235701</guid>
      <dc:creator>j.rambeau</dc:creator>
      <dc:date>2021-11-18T16:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility link down after update 17.3.3 on 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/5301162#M284210</link>
      <description>&lt;P&gt;I am having the same issues and DMZ controller send keepalive messages to 9800 controller and when i check logging on 9800 Controller the peer link to DMZ is down.&lt;/P&gt;&lt;P&gt;on DMZ:&lt;/P&gt;&lt;P&gt;*mmMobility: Jun 20 11:33:17.758: Keepalive:VALID:ETHOIP_OP_REQ:Sent to 10.xxx.x.x:version=02:SeqNo=37744104:receiverStatusOnTransmitter=0&lt;/P&gt;&lt;P&gt;mmMobility: Jun 20 11:33:17.758: Keepalive: Mobility Data Ping response failed for the peer 10.xxx.x.x retryCount= 2&lt;/P&gt;&lt;P&gt;on 9800 logging:&lt;/P&gt;&lt;P&gt;Jun 20 10:38:09.095: %MM_INFRA_LOG-3-RECV_FAILED: Chassis 1 R0/0: mobilityd: Unable to receive mobility message pmk_update from ipv4: 192.168.xxx.x . reason: Peer link is down&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2025 16:27:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/5301162#M284210</guid>
      <dc:creator>santoshrijala12</dc:creator>
      <dc:date>2025-06-20T16:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility link down after update 17.3.3 on 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/5301163#M284211</link>
      <description>&lt;P&gt;Hash should be configured if 9800 controller is virtual controller , right?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2025 16:31:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/5301163#M284211</guid>
      <dc:creator>santoshrijala12</dc:creator>
      <dc:date>2025-06-20T16:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: Mobility link down after update 17.3.3 on 9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/5301166#M284212</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; -&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1834050"&gt;@santoshrijala12&lt;/a&gt;&amp;nbsp; &amp;nbsp;-&lt;EM&gt; Start a&lt;FONT color="#008000"&gt;&lt;STRONG&gt; new&lt;/STRONG&gt; thread&lt;/FONT&gt;&lt;/EM&gt; ; describe your issue from scratch (again), &lt;EM&gt;with all the information you have,&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2025 16:38:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/5301166#M284212</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-06-20T16:38:56Z</dc:date>
    </item>
  </channel>
</rss>

