<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC C9800-L-C-K9 not doing SSO switchover with RMI+RP in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-c9800-l-c-k9-not-doing-sso-switchover-with-rmi-rp/m-p/4580638#M240148</link>
    <description>&lt;P&gt;Both gateway check prerequisite look good: you are running above 17.1 and gateway check is enabled.&amp;nbsp;&lt;BR /&gt;page 30 and 31 in this document shows how it should behave&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/wireless/controller/9800/17-1/deployment-guide/c9800-ha-sso-deployment-guide-rel-17-1.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/td/docs/wireless/controller/9800/17-1/deployment-guide/c9800-ha-sso-deployment-guide-rel-17-1.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;i would recommend to contact support.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Mar 2022 11:56:48 GMT</pubDate>
    <dc:creator>Ambuj M</dc:creator>
    <dc:date>2022-03-29T11:56:48Z</dc:date>
    <item>
      <title>WLC C9800-L-C-K9 not doing SSO switchover with RMI+RP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-l-c-k9-not-doing-sso-switchover-with-rmi-rp/m-p/4579877#M240133</link>
      <description>&lt;P&gt;Hello Friends, i hope you all are very well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I´m having troubles with the RMI+RP configuration on a&amp;nbsp;C9800-L-C-K9 cluster, configured the following parameters:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;CHASSIS_HA_LOCAL_IP = 169.254.119.205&lt;BR /&gt;CHASSIS_HA_REMOTE_IP = 169.254.119.206&lt;BR /&gt;CHASSIS_HA_LOCAL_MASK = 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;RMI_INTERFACE_NAME = Vlan302&lt;BR /&gt;RMI_CHASSIS_LOCAL_IP = 10.220.119.205&lt;BR /&gt;RMI_CHASSIS_REMOTE_IP = 10.220.119.206&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WLC01#show redundancy states&lt;BR /&gt;my state = 13 -ACTIVE&lt;BR /&gt;peer state = 8 -STANDBY HOT&lt;BR /&gt;Mode = Duplex&lt;BR /&gt;Unit = Primary&lt;BR /&gt;Unit ID = 1&lt;/P&gt;&lt;P&gt;Redundancy Mode (Operational) = sso&lt;BR /&gt;Redundancy Mode (Configured) = sso&lt;BR /&gt;Redundancy State = sso&lt;BR /&gt;Maintenance Mode = Disabled&lt;BR /&gt;Manual Swact = enabled&lt;BR /&gt;Communications = Up&lt;/P&gt;&lt;P&gt;client count = 149&lt;BR /&gt;client_notification_TMR = 30000 milliseconds&lt;BR /&gt;RF debug mask = 0x0&lt;BR /&gt;Gateway Monitoring = Enabled&lt;BR /&gt;Gateway monitoring interval = 6 secs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The devices are connected via PortChannel to a C3560G, Active WLC (Two0/0/1-2 -&amp;gt; Gi0/3 - 4 **PortChannel 1) and StandBy&amp;nbsp;(Two0/0/1-2 -&amp;gt; Gi0/5 - 6 **PortChannel 2) for a HA test. The main problem comes when i perform a shutdown on the Po1, its expected that due to lost of connectivity to the default gateway (which is configured on the test switch, i will add some data in the next section) the WLC would perform a switchover to maintain connectivity to the DG, but is not happening:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Switch:&lt;/P&gt;&lt;P&gt;interface Vlan302&lt;BR /&gt;description *** Wireless Network ***&lt;BR /&gt;ip address 10.220.119.222 255.255.255.224&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Core01#show etherchannel summary&lt;BR /&gt;Flags: D - down P - bundled in port-channel&lt;BR /&gt;I - stand-alone s - suspended&lt;BR /&gt;H - Hot-standby (LACP only)&lt;BR /&gt;R - Layer3 S - Layer2&lt;BR /&gt;U - in use f - failed to allocate aggregator&lt;/P&gt;&lt;P&gt;M - not in use, minimum links not met&lt;BR /&gt;u - unsuitable for bundling&lt;BR /&gt;w - waiting to be aggregated&lt;BR /&gt;d - default port&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Number of channel-groups in use: 2&lt;BR /&gt;Number of aggregators: 2&lt;/P&gt;&lt;P&gt;Group Port-channel Protocol Ports&lt;BR /&gt;------+-------------+-----------+-----------------------------------------------&lt;BR /&gt;1 Po1(SU) - Gi0/3(P) Gi0/4(P)&lt;BR /&gt;2 Po2(SU) - Gi0/5(P) Gi0/6(P)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Active WLC:&lt;/P&gt;&lt;P&gt;WLC01#show run | inc default&lt;BR /&gt;ip default-gateway 10.220.119.222&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;WLC01#ping 10.220.119.222&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 10.220.119.222, timeout is 2 seconds:&lt;BR /&gt;.!!!!&lt;BR /&gt;Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/2 ms&lt;BR /&gt;SPC-OT-RG1-WLC01#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once that the Po1 is down, the WLC logs the link faiulre and the RMI link down is received but there is no switchover to the standby WLC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SPC-OT-RG1-WLC01#&lt;BR /&gt;*Mar 28 18:51:47.301: %LINEPROTO-5-UPDOWN: Line protocol on Interface Port-channel1, changed state to down&lt;BR /&gt;*Mar 28 18:51:48.298: %LINK-3-UPDOWN: Interface TwoGigabitEthernet0/0/1, changed state to down&lt;BR /&gt;*Mar 28 18:51:48.300: %LINK-3-UPDOWN: Interface TwoGigabitEthernet0/0/2, changed state to down&lt;BR /&gt;*Mar 28 18:51:48.302: %LINK-3-UPDOWN: Interface Vlan302, changed state to down&lt;BR /&gt;*Mar 28 18:51:48.303: %LINK-3-UPDOWN: Interface Port-channel1, changed state to down&lt;BR /&gt;*Mar 28 18:51:49.298: %LINEPROTO-5-UPDOWN: Line protocol on Interface TwoGigabitEthernet0/0/1, changed state to down&lt;BR /&gt;*Mar 28 18:51:49.301: %LINEPROTO-5-UPDOWN: Line protocol on Interface TwoGigabitEthernet0/0/2, changed state to down&lt;BR /&gt;*Mar 28 18:51:49.302: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan302, changed state to down&lt;BR /&gt;*Mar 28 18:52:15.707: %RIF_MGR_FSM-6-RMI_LINK_DOWN: Chassis 1 R0/0: rif_mgr: The RMI link is DOWN.&lt;BR /&gt;*Mar 28 18:52:15.777: %RIF_MGR_FSM-6-RMI_LINK_DOWN: Chassis 2 R0/0: rif_mgr: The RMI link is DOWN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WLC01#show chassis&lt;BR /&gt;Chassis/Stack Mac Address : f01d.2d39.1220 - Local Mac Address&lt;BR /&gt;Mac persistency wait time: Indefinite&lt;BR /&gt;Local Redundancy Port Type: Twisted Pair&lt;BR /&gt;H/W Current&lt;BR /&gt;Chassis# Role Mac Address Priority Version State IP&lt;BR /&gt;-------------------------------------------------------------------------------------&lt;BR /&gt;*1 Active f01d.2d39.1220 2 V02 Ready 169.254.119.205&lt;BR /&gt;2 Standby f01d.2d39.1060 1 V02 Ready 169.254.119.206&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this the expected behaviour under this scenario? probably i would need another switch to try a HSRP environment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;by the way, this is the IOS version:&lt;/P&gt;&lt;P&gt;WLC01#show version&lt;BR /&gt;Cisco IOS XE Software, Version 17.03.03&lt;BR /&gt;Cisco IOS Software [Amsterdam], C9800 Software (C9800_IOSXE-K9), Version 17.3.3, RELEASE SOFTWARE (fc7)&lt;BR /&gt;Technical Support: &lt;A href="http://www.cisco.com/techsupport" target="_blank" rel="noopener"&gt;http://www.cisco.com/techsupport&lt;/A&gt;&lt;BR /&gt;Copyright (c) 1986-2021 by Cisco Systems, Inc.&lt;BR /&gt;Compiled Thu 04-Mar-21 12:37 by mcpre&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cisco IOS-XE software, Copyright (c) 2005-2021 by cisco Systems, Inc.&lt;BR /&gt;All rights reserved. Certain components of Cisco IOS-XE software are&lt;BR /&gt;licensed under the GNU General Public License ("GPL") Version 2.0. The&lt;BR /&gt;software code licensed under GPL Version 2.0 is free software that comes&lt;BR /&gt;with ABSOLUTELY NO WARRANTY. You can redistribute and/or modify such&lt;BR /&gt;GPL code under the terms of GPL Version 2.0. For more details, see the&lt;BR /&gt;documentation or "License Notice" file accompanying the IOS-XE software,&lt;BR /&gt;or the applicable URL provided on the flyer accompanying the IOS-XE&lt;BR /&gt;software.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ROM: 16.12(3r)&lt;/P&gt;&lt;P&gt;SPC-OT-RG1-WLC01 uptime is 44 minutes&lt;BR /&gt;Uptime for this control processor is 46 minutes&lt;BR /&gt;System returned to ROM by IntelResetRequest&lt;BR /&gt;System image file is "bootflash:packages.conf"&lt;BR /&gt;Last reload reason: IntelResetRequest&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This product contains cryptographic features and is subject to United&lt;BR /&gt;States and local country laws governing import, export, transfer and&lt;BR /&gt;use. Delivery of Cisco cryptographic products does not imply&lt;BR /&gt;third-party authority to import, export, distribute or use encryption.&lt;BR /&gt;Importers, exporters, distributors and users are responsible for&lt;BR /&gt;compliance with U.S. and local country laws. By using this product you&lt;BR /&gt;agree to comply with applicable laws and regulations. If you are unable&lt;BR /&gt;to comply with U.S. and local laws, return this product immediately.&lt;/P&gt;&lt;P&gt;A summary of U.S. laws governing Cisco cryptographic products may be found at:&lt;BR /&gt;&lt;A href="http://www.cisco.com/wwl/export/crypto/tool/stqrg.html" target="_blank" rel="noopener"&gt;http://www.cisco.com/wwl/export/crypto/tool/stqrg.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you require further assistance please contact us by sending email to&lt;BR /&gt;export@cisco.com.&lt;/P&gt;&lt;P&gt;License Type: Smart License is permanent&lt;BR /&gt;License Level: adventerprise&lt;BR /&gt;Next reload license Level: adventerprise&lt;BR /&gt;AIR License Level: AIR DNA Advantage&lt;BR /&gt;Next reload AIR license Level: AIR DNA Advantage&lt;/P&gt;&lt;P&gt;The current crypto throughput level is 0 kbps&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Smart Licensing Status: Registration Not Applicable/Not Applicable&lt;/P&gt;&lt;P&gt;cisco C9800-L-C-K9 (KATAR) processor (revision KATAR) with 1702951K/6147K bytes of memory.&lt;BR /&gt;Processor board ID FCL255100TE&lt;BR /&gt;Router operating mode: Autonomous&lt;BR /&gt;2 Virtual Ethernet interfaces&lt;BR /&gt;4 2.5 Gigabit Ethernet interfaces&lt;BR /&gt;2 Ten Gigabit Ethernet interfaces&lt;BR /&gt;32768K bytes of non-volatile configuration memory.&lt;BR /&gt;16777216K bytes of physical memory.&lt;BR /&gt;26251263K bytes of eUSB flash at bootflash:.&lt;BR /&gt;26251263K bytes of eUSB flash at bootflash-2:.&lt;/P&gt;&lt;P&gt;Base Ethernet MAC Address : F0:1D:2D:39:12:20&lt;/P&gt;&lt;P&gt;Installation mode is INSTALL&lt;/P&gt;&lt;P&gt;Configuration register is 0x102&lt;/P&gt;&lt;P&gt;WLC01#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will appreciate very much any help with this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you all.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 19:03:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-l-c-k9-not-doing-sso-switchover-with-rmi-rp/m-p/4579877#M240133</guid>
      <dc:creator>jose.franco</dc:creator>
      <dc:date>2022-03-28T19:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: WLC C9800-L-C-K9 not doing SSO switchover with RMI+RP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-l-c-k9-not-doing-sso-switchover-with-rmi-rp/m-p/4580509#M240141</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- I am not sure if shutting down network links (or Port-channel) is a good methodology for testing failover, it may lead to split brain conditions only. Check if failover works if primary controller is shutdown completely. For the rest you may have an in-depth check of the configuration of the controller(s) with (&lt;STRONG&gt;CLI&lt;/STRONG&gt;) : &lt;STRONG&gt;show tech &lt;U&gt;wireless&lt;/U&gt;&lt;/STRONG&gt; , have&amp;nbsp; the output processes by :&amp;nbsp;&lt;A href="https://cway.cisco.com/tools/WirelessAnalyzer/" target="_blank"&gt;https://cway.cisco.com/tools/WirelessAnalyzer/&lt;/A&gt;&amp;nbsp;, &lt;FONT color="#008000"&gt;&lt;EM&gt;you will get&amp;nbsp; lots of useful&lt;STRONG&gt; advisories.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 07:30:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-l-c-k9-not-doing-sso-switchover-with-rmi-rp/m-p/4580509#M240141</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-03-29T07:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: WLC C9800-L-C-K9 not doing SSO switchover with RMI+RP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-l-c-k9-not-doing-sso-switchover-with-rmi-rp/m-p/4580638#M240148</link>
      <description>&lt;P&gt;Both gateway check prerequisite look good: you are running above 17.1 and gateway check is enabled.&amp;nbsp;&lt;BR /&gt;page 30 and 31 in this document shows how it should behave&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/wireless/controller/9800/17-1/deployment-guide/c9800-ha-sso-deployment-guide-rel-17-1.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/td/docs/wireless/controller/9800/17-1/deployment-guide/c9800-ha-sso-deployment-guide-rel-17-1.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;i would recommend to contact support.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 11:56:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-l-c-k9-not-doing-sso-switchover-with-rmi-rp/m-p/4580638#M240148</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2022-03-29T11:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: WLC C9800-L-C-K9 not doing SSO switchover with RMI+RP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-l-c-k9-not-doing-sso-switchover-with-rmi-rp/m-p/4581051#M240154</link>
      <description>&lt;P&gt;&lt;SPAN&gt;From Cisco IOS XE Amsterdam 17.2.1 onwards, the method to configure the gateway IP has been modified. The&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;ip default-gateway&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;gateway-ip&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;command is not used. Instead, the gateway IP is selected based on the static routes configured. From among the static routes configured, the gateway IP that falls in the same subnet as the RMI subnet is chosen. If no matching static route is found, gateway failover will not work (even if management gateway-failover is enabled).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can you verify the static routing config&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;CJ&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/** Please rate all useful responses**/&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 13:40:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-l-c-k9-not-doing-sso-switchover-with-rmi-rp/m-p/4581051#M240154</guid>
      <dc:creator>jagan.chowdam</dc:creator>
      <dc:date>2022-03-29T13:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: WLC C9800-L-C-K9 not doing SSO switchover with RMI+RP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-l-c-k9-not-doing-sso-switchover-with-rmi-rp/m-p/4581917#M240224</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319960"&gt;@jagan.chowdam&lt;/a&gt;&amp;nbsp;thank you very much!!! that was the issue, i was using the&amp;nbsp;&lt;SPAN class=""&gt;ip default-gateway&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;gateway-ip&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;command, i don't have too many experience with this device. But your reply was very helpfull, i was able to set properly the RMI+RP function and the HA tests were successful. When one member in the cluster is powered off and when the corresponding portchannel links are down (disconnection) the WLCs were able to switchover due to lost of connectivity with DG.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Again thank you very much for your help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best Regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;JF.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 13:11:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-l-c-k9-not-doing-sso-switchover-with-rmi-rp/m-p/4581917#M240224</guid>
      <dc:creator>jose.franco</dc:creator>
      <dc:date>2022-03-30T13:11:01Z</dc:date>
    </item>
  </channel>
</rss>

