<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I have an intermittent issue between Set of WLCs and a 3rd Party. in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/i-have-an-intermittent-issue-between-set-of-wlcs-and-a-3rd-party/m-p/4633194#M243311</link>
    <description>&lt;P&gt;I know the guy was correct, as it was me who set it up , well my side anyway&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunetly I can't get access to the other firewall as it belongs to the 3rd party&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jun 2022 13:44:14 GMT</pubDate>
    <dc:creator>craiglebutt</dc:creator>
    <dc:date>2022-06-16T13:44:14Z</dc:date>
    <item>
      <title>I have an intermittent issue between Set of WLCs and a 3rd Party.</title>
      <link>https://community.cisco.com/t5/wireless/i-have-an-intermittent-issue-between-set-of-wlcs-and-a-3rd-party/m-p/4633075#M243291</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 3 main sites with 5520 and 8500 in HA, these all connect to 4 external Mobility anchors and 3 internal anchors on DMZ.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have upgraded to 8.5.182.104 and 8.10.171.0 , issues was happening before and after&lt;/P&gt;&lt;P&gt;The issue I have is with WLCs on Site 3 going to 3rd Party Company 1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The 5520 and 8500 on Site 3 seem to drop for split second at different times not at the same time, no patterns.&amp;nbsp; Each HA pair goes at different times&lt;/P&gt;&lt;P&gt;They are both on the same 10Gb blade, the connection to the Firewall is on a 1Gb Port on the same Distribution&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All WLANs are configured exactly the same across the board&lt;/P&gt;&lt;P&gt;If a SFP or fibre issue would affect all 2000+ devices at the same time on that uplink.&lt;/P&gt;&lt;P&gt;Not a issue between Dist and Firewall as would affect the other 2 sites&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no issues with the other Mobility Anchors to other organisations our DMZ WLCs.&lt;/P&gt;&lt;P&gt;Radius is configured correctly&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know how anchors work, been configuring for years, so no epings or mpings the anchors are up 99.99999% of the day&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2022-06-16 08:18:57&amp;nbsp;&amp;nbsp; Local7.Warning&amp;nbsp; 10.*.*.*&amp;nbsp;&amp;nbsp; host00WLC: *mmMobility: Jun 16 08:18:58.162: %MM-4-INET_MEMBER_DOWN: [PA]mm_heartbeat.c:531 Data path to mobility member 192.168.226.10 is DOWN.&lt;/P&gt;&lt;P&gt;2022-06-16 08:18:57&amp;nbsp;&amp;nbsp; Local7.Alert&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.*.*.*&amp;nbsp;&amp;nbsp; host00WLC: *mmMobility: Jun 16 08:18:58.162: %MM-1-ANCHORS_DOWN: [PA]mm_heartbeat.c:730&amp;nbsp; All Export-Anchors are down on WLAN 20&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;TAC has looked at the 3rd party site, cant find a issue&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 10:31:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/i-have-an-intermittent-issue-between-set-of-wlcs-and-a-3rd-party/m-p/4633075#M243291</guid>
      <dc:creator>craiglebutt</dc:creator>
      <dc:date>2022-06-16T10:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: I have an intermittent issue between Set of WLCs and a 3rd Party.</title>
      <link>https://community.cisco.com/t5/wireless/i-have-an-intermittent-issue-between-set-of-wlcs-and-a-3rd-party/m-p/4633100#M243292</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;At first sight, Firewall is my suspicious. They are all the same firewall vendor, model and version?&amp;nbsp; I´ve seen CheckPoint problem where the permit rule was there but the traffic failed to pass but not totally. I saw they adding aditional command on the cli and also applying&amp;nbsp; patch to fix the problem.&amp;nbsp; I am mentioning this because Firewall guys sometimes stick on the rule sreen shot to tell that all is good from their sides but actually not even them are seing the problem.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 11:05:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/i-have-an-intermittent-issue-between-set-of-wlcs-and-a-3rd-party/m-p/4633100#M243292</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2022-06-16T11:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: I have an intermittent issue between Set of WLCs and a 3rd Party.</title>
      <link>https://community.cisco.com/t5/wireless/i-have-an-intermittent-issue-between-set-of-wlcs-and-a-3rd-party/m-p/4633142#M243297</link>
      <description>&lt;P&gt;They are Fortigate 200, old, but only used between 2 companys.&amp;nbsp; Ruled out the firewall as it would be down all the time if a rule issue.&amp;nbsp; They are at the latest codes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 12:02:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/i-have-an-intermittent-issue-between-set-of-wlcs-and-a-3rd-party/m-p/4633142#M243297</guid>
      <dc:creator>craiglebutt</dc:creator>
      <dc:date>2022-06-16T12:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: I have an intermittent issue between Set of WLCs and a 3rd Party.</title>
      <link>https://community.cisco.com/t5/wireless/i-have-an-intermittent-issue-between-set-of-wlcs-and-a-3rd-party/m-p/4633157#M243301</link>
      <description>&lt;P&gt;&lt;SPAN&gt;"Ruled out the firewall as it would be down all the time if a rule issue"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;That something a firewall guy usually say. As I mentioned above,&amp;nbsp; I have too much experience on this to buy this statement.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 12:53:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/i-have-an-intermittent-issue-between-set-of-wlcs-and-a-3rd-party/m-p/4633157#M243301</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2022-06-16T12:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: I have an intermittent issue between Set of WLCs and a 3rd Party.</title>
      <link>https://community.cisco.com/t5/wireless/i-have-an-intermittent-issue-between-set-of-wlcs-and-a-3rd-party/m-p/4633194#M243311</link>
      <description>&lt;P&gt;I know the guy was correct, as it was me who set it up , well my side anyway&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunetly I can't get access to the other firewall as it belongs to the 3rd party&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 13:44:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/i-have-an-intermittent-issue-between-set-of-wlcs-and-a-3rd-party/m-p/4633194#M243311</guid>
      <dc:creator>craiglebutt</dc:creator>
      <dc:date>2022-06-16T13:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: I have an intermittent issue between Set of WLCs and a 3rd Party.</title>
      <link>https://community.cisco.com/t5/wireless/i-have-an-intermittent-issue-between-set-of-wlcs-and-a-3rd-party/m-p/4633490#M243340</link>
      <description>&lt;P&gt;Based on the mobility log, the tunnel went down because of a lack of mobility keep alive so the WLC thinks the other end is down, I've seen many times that the network may see one way communication for mobility tunnels, so I would recommend debugging mobility keep alive exchange messages between the problematic controllers to see what if there is any error in the debug logs or if there is 1 way communication, you should run these commands on two of the problematic WLC (one anchor and one foreign) and wait for the tunnel to go down then compare the logs:&lt;/P&gt;&lt;P&gt;Debug mobility keepalive enable&lt;BR /&gt;debug mobility peer-ip &amp;lt;IP-address&amp;gt; enabled&lt;/P&gt;&lt;P&gt;I agree with &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt;&amp;nbsp;about the firewall guys, they often say everything is ok based on the firewall rules and don't take a deeper look, I know there is a very old Cisco document that explains that firewalls could cause a "route loop" inside the firewall due to its architecture and that triggers the one way communication, unfortunately, I couldn't find the document, but I know that the workaround is to clear the session in the firewall for the mobility tunnel so a new session is created and everything works again.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 21:16:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/i-have-an-intermittent-issue-between-set-of-wlcs-and-a-3rd-party/m-p/4633490#M243340</guid>
      <dc:creator>jonathga94</dc:creator>
      <dc:date>2022-06-16T21:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: I have an intermittent issue between Set of WLCs and a 3rd Party.</title>
      <link>https://community.cisco.com/t5/wireless/i-have-an-intermittent-issue-between-set-of-wlcs-and-a-3rd-party/m-p/4685308#M245922</link>
      <description>&lt;P&gt;Thanks both, I'll keep looking in to it&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 10:38:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/i-have-an-intermittent-issue-between-set-of-wlcs-and-a-3rd-party/m-p/4685308#M245922</guid>
      <dc:creator>craiglebutt</dc:creator>
      <dc:date>2022-09-12T10:38:29Z</dc:date>
    </item>
  </channel>
</rss>

