<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Resolving CSCwh68219 - 91xx AP not processing EAP-TLS server Hello in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/4983980#M264677</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;- I don't have much details on those AP(SP) versioning issues , but what I &lt;U&gt;can&lt;/U&gt; advice is to run WirelessAnalyzer (again after and or always upon an upgrade too) : Procedure CLI : &lt;FONT color="#008000"&gt;&lt;STRONG&gt;show tech wireless&lt;/STRONG&gt; &lt;/FONT&gt;and feed the output into&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank"&gt;Wireless Config Analyzer&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Also follow up on the performance&amp;nbsp; of all&amp;nbsp; APs using :&amp;nbsp;&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#anc4" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#anc4&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Dec 2023 20:10:27 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2023-12-22T20:10:27Z</dc:date>
    <item>
      <title>Resolving CSCwh68219 - 91xx AP not processing EAP-TLS server Hello</title>
      <link>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/4983887#M264668</link>
      <description>&lt;P&gt;I have a maintenance window next week for patching our 9800 WLCs. They are on 17.9.4 with no SMU or APSP. My plan was to install the 17.9.4 SMU for the HTTP vulnerability and then APSP8. However, version 17.9.4a specifically has an SMU available for &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwh68219" target="_self"&gt;CSCwh68219&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;We don't use EAP-TLS currently, but are going to implement it sometime in January, so that bug is concerning. I was wondering if anyone knows anything else about this and if those of you who are using EAP-TLS have experienced it. Does it only affect local mode and not FlexConect or vice versa? Is PEAP also affected?&lt;/P&gt;&lt;P&gt;I ask because I'm on 17.9.4 and have a planned maintenance window for the HTTPS SMU and APSP, but the SMU for this bug is not available yet for 17.9.4 (TAC says there will be one), and upgrading to 17.9.4a first would require more time for maintenance.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2023 16:12:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/4983887#M264668</guid>
      <dc:creator>eglinsky2012</dc:creator>
      <dc:date>2023-12-22T16:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: Resolving CSCwh68219 - 91xx AP not processing EAP-TLS server Hello</title>
      <link>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/4983961#M264674</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;EM&gt;&amp;nbsp; &amp;gt;...&amp;nbsp;17.9.4a first would require more time for maintenance.&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp; - I would go for &lt;FONT color="#008000"&gt;17.9.4&lt;U&gt;&lt;STRONG&gt;a&lt;/STRONG&gt;&lt;/U&gt;&lt;/FONT&gt; anyway because of the &lt;FONT color="#008000"&gt;&lt;EM&gt;HTTP bugfix and the EAP-TLS bugfix &lt;U&gt;included ,&lt;/U&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2023 19:18:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/4983961#M264674</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-12-22T19:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: Resolving CSCwh68219 - 91xx AP not processing EAP-TLS server Hello</title>
      <link>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/4983967#M264676</link>
      <description>&lt;P&gt;Yeah, I've thought about it more and that's what I'll do. I've received approval to extend the maintenance window.&lt;/P&gt;&lt;P&gt;I performed the upgrade on our lab controllers, and oddly, only two of six APs actually predownloaded software. I couldn't figure out how to verify for sure, but I suspect it was the 1815W and the 9105W. I know there was an early APSP specifically for 9105W, so maybe that update was included in 17.9.4a, whereas the other models (2700, 2800, 1562, 9166) had no updates built in?&lt;/P&gt;&lt;P&gt;Of note is that the version the APs were running after the upgrade was still 17.9.4.27, same as on 17.9.4 (non-a), even on the 1815W and 9105W. After the APSP, all are on 17.9.4.208 except the 2700 (the APSP only applies to COS APs, not IOS).&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2023 19:35:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/4983967#M264676</guid>
      <dc:creator>eglinsky2012</dc:creator>
      <dc:date>2023-12-22T19:35:47Z</dc:date>
    </item>
    <item>
      <title>Re: Resolving CSCwh68219 - 91xx AP not processing EAP-TLS server Hello</title>
      <link>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/4983980#M264677</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;- I don't have much details on those AP(SP) versioning issues , but what I &lt;U&gt;can&lt;/U&gt; advice is to run WirelessAnalyzer (again after and or always upon an upgrade too) : Procedure CLI : &lt;FONT color="#008000"&gt;&lt;STRONG&gt;show tech wireless&lt;/STRONG&gt; &lt;/FONT&gt;and feed the output into&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank"&gt;Wireless Config Analyzer&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Also follow up on the performance&amp;nbsp; of all&amp;nbsp; APs using :&amp;nbsp;&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#anc4" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#anc4&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2023 20:10:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/4983980#M264677</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-12-22T20:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: Resolving CSCwh68219 - 91xx AP not processing EAP-TLS server Hello</title>
      <link>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/4984046#M264682</link>
      <description>&lt;P&gt;&lt;STRONG&gt;IMPORTANT&lt;/STRONG&gt;:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since the controller is on 17.9.4, do not use "Hitless AP Upgrade".&amp;nbsp; Wireless TAC in Sydney (Australia), has confirmed and was able to successfully replicate the unexpected behaviour (five times out of five attempts) when we performed a disastrous "Hitless AP Upgrade" from 17.9.4.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Instead of "hitless", 17.9.4 will &lt;FONT color="#FF0000"&gt;&lt;EM&gt;violently&lt;/EM&gt; &lt;/FONT&gt;move the APs to the secondary unit by rebooting all of them at the same time.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Dec 2023 23:59:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/4984046#M264682</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2023-12-23T23:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: Resolving CSCwh68219 - 91xx AP not processing EAP-TLS server Hello</title>
      <link>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/4984049#M264683</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/314036"&gt;@eglinsky2012&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;SPAN&gt;We don't use EAP-TLS currently, but are going to implement it sometime in January, so that bug is concerning. I was wondering if anyone knows anything else about this and if those of you who are using EAP-TLS have experienced it. Does it only affect local mode and not FlexConect or vice versa? Is PEAP also affected?&lt;/SPAN&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;17.9.5 scheduled for February 2024.&amp;nbsp; It is best to reach out to your Cisco Account Manager, Wireless SE or Wireless PSS &amp;amp;/or TAC developer &amp;amp;/or WNBU because the developers have time to put this bug fix into 17.9.5.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Dec 2023 00:00:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/4984049#M264683</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2023-12-23T00:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: Resolving CSCwh68219 - 91xx AP not processing EAP-TLS server Hello</title>
      <link>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/4984063#M264684</link>
      <description>&lt;P&gt;Thanks for the heads-up on the hitless upgrade. I had an issue with ISSU as well. Between that and previous comments from you, Rich, and others, I stick with an old fashioned upgrade with predownload. I have 3 WLC pairs in a mobility group and all are configured with secondary and tertiary WLCs, so when the primary goes down, they just move to the next one on the list then back once the primary comes back up. Perfectly acceptable for a maintenance window. ISSU would be great if it were reliable, especially once we move the res halls to the 9800s, but I digress.&lt;/P&gt;&lt;P&gt;I suspect that if it’s fixed in the SMU for 17.9.4a it will be for 17.9.5 also.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Dec 2023 02:21:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/4984063#M264684</guid>
      <dc:creator>eglinsky2012</dc:creator>
      <dc:date>2023-12-23T02:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: Resolving CSCwh68219 - 91xx AP not processing EAP-TLS server Hello</title>
      <link>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/4984138#M264698</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;gt; I suspect that if it’s fixed in the SMU for 17.9.4a it will be for 17.9.5 also.&lt;BR /&gt;&lt;/SPAN&gt;Agreed but ask TAC to confirm for you.&lt;/P&gt;
&lt;P&gt;Regarding AP image versions - use "show ap image file summary" to see what version each AP image is (base and SP).&lt;/P&gt;
&lt;P&gt;Having messed up with the AP image version on 17.9.4a APSP6 (17.9.4.201) they've gone back to normal convention (17.9.4.208) with APSP8.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Dec 2023 14:54:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/4984138#M264698</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-12-23T14:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: Resolving CSCwh68219 - 91xx AP not processing EAP-TLS server Hello</title>
      <link>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/5011986#M266151</link>
      <description>&lt;P&gt;Forgot to follow up. I ended up doing the 17.9.4a upgrade and APSP8 upgrade in one maintenance window.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 14:33:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/resolving-cscwh68219-91xx-ap-not-processing-eap-tls-server-hello/m-p/5011986#M266151</guid>
      <dc:creator>eglinsky2012</dc:creator>
      <dc:date>2024-02-02T14:33:47Z</dc:date>
    </item>
  </channel>
</rss>

