<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: C9800 HA SSO pair broken in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/c9800-ha-sso-pair-broken/m-p/5322341#M285635</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; -&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1631942"&gt;@Redguy&lt;/a&gt;&amp;nbsp; &amp;nbsp;There is too much going on &lt;FONT color="#FF6600"&gt;&lt;EM&gt;beyond your exact control.&lt;/EM&gt;&lt;/FONT&gt; Mistakes can not be excluded.&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; I can only advice to check logs on the controllers&amp;nbsp; when things are going wrong (&lt;STRONG&gt;show logging&lt;/STRONG&gt;).&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Also take a look at :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-wireless-controllers-cloud/218438-verify-support-vmware-vsphere-vmotion-wi.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-wireless-controllers-cloud/218438-verify-support-vmware-vsphere-vmotion-wi.html&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;It contains a few tables about what is allowed or not when&amp;nbsp; moving controllers between platforms&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;U&gt;&amp;nbsp; Also from the same document :&lt;/U&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;gt;...&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Recommendation&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;: For best results, it is recommended to configure RP port keepalives to at least twice the default 100 ms keepalive (set it to 200 ms). If the network between storage and hosts can become busy and increase latency, consider to set the keepalives timer to 300 ms. To configure the keepalive timer on the GUI, go to Administration &amp;gt; Device &amp;gt; Redundancy:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;gt;...&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="lia-code-sample  language-markup"&gt;&lt;CODE&gt;C9800-SSO#chassis redundancy keep-alive timer 3 &lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; M.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Aug 2025 08:41:27 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2025-08-20T08:41:27Z</dc:date>
    <item>
      <title>C9800 HA SSO pair broken</title>
      <link>https://community.cisco.com/t5/wireless/c9800-ha-sso-pair-broken/m-p/5321965#M285621</link>
      <description>&lt;P&gt;We have been using a pair of vmWare based Cisco C9800 WLC's in HA-SSO for a few years now.&amp;nbsp;&lt;BR /&gt;Apart from the fact that the VM's dont like being vMotioned or have backup snapshots taken, they have been functioning quite well.&lt;/P&gt;&lt;P&gt;Our server guys recently built a new vmWare cluster and tried to move the WLC VMs to the new cluster, which failed. The WLC they moved responded to SSH CLI and Web GUI but lost all configuration somehow. Our whole wifi environment went offline.&lt;/P&gt;&lt;P&gt;After restoring the VM's on the old cluster things came back online, but when checking the status of the HA pair of it turned out that the primary WLC VM is doing what it should be doing, but it reports its standby member as "removed" with a mac address 0000.0000.0000 (show chassis)&lt;/P&gt;&lt;P&gt;The standby VM console shows it is carrying the hostname of the primary, and reports it is a standalone WLC. Clearly the 2 VM's ended up in a split brain situation or something. The server guys told me that at the moment they moved the first WLC, the network between the 2 clusters connecting them might not have been configured fully yet.&lt;/P&gt;&lt;P&gt;This creates 3 problems for me :&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;How do I repair the HA SSO pair without interrupting our wifi networks (if possible)&lt;/LI&gt;&lt;LI&gt;What is the best procedure to move the WLC (cluster) to another vmWare cluster ?&lt;/LI&gt;&lt;LI&gt;For some reason the WLC VMs (installed by an external vendor) still have the .ISO mounted. Is this normal and should this remain like this ? Or can we just remove the mounted .ISO frm the VM's ?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I wonder if it might be a lot easier to revert the primary to a standalone WLC, move that, and then add a newly created WLC VM as standby ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 13:07:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-ha-sso-pair-broken/m-p/5321965#M285621</guid>
      <dc:creator>Redguy</dc:creator>
      <dc:date>2025-08-19T13:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 HA SSO pair broken</title>
      <link>https://community.cisco.com/t5/wireless/c9800-ha-sso-pair-broken/m-p/5321973#M285622</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; -&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1631942"&gt;@Redguy&lt;/a&gt;&amp;nbsp; &amp;nbsp;You have lots of parameters undefined and possibly leading to trouble such as :&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;FONT color="#FF6600"&gt;&lt;EM&gt; &amp;nbsp; &amp;nbsp;&amp;gt;...&lt;/EM&gt;&lt;/FONT&gt;&lt;SPAN&gt;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;and &lt;STRONG&gt;tried&lt;/STRONG&gt; to move the WLC VMs to the new cluster,&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;But technical details on what was tried is left out. It's a bit the same with&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;FONT color="#FF6600"&gt;&lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;gt;...After&lt;STRONG&gt; restoring&lt;/STRONG&gt; the VM's on the old cluster&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; No technical details provided here.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; Skipping to :&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;What is the best procedure to move the WLC (cluster) to another vmWare cluster&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; You probably can't do that in a transparent manner because officially the HA SSO&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; is only supported on a 'single cell' vmware cluster.&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; I would indeed more look into building the new cluster on the new vmware environment and using that&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;as an&lt;FONT color="#008000"&gt;&lt;STRONG&gt; N+1&lt;/STRONG&gt; 'HA partner'&lt;/FONT&gt; for the current environment. Giving APs the ability to fallback&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;to the new environment when the current cluster is abandoned. Then you can also&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;prepare the new environment on a relaxed basis first&amp;nbsp; and check it out.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;STRONG&gt;Appendix 1):&amp;nbsp;&lt;/STRONG&gt; Always validate a new environment (controller) with the CLI command&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;FONT color="#008000"&gt;&lt;STRONG&gt; &amp;nbsp; show tech wireless&lt;/STRONG&gt;&lt;/FONT&gt; and feed the output from that into&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank"&gt;Wireless Config Analyzer&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;&amp;nbsp;Appendix&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;2):&lt;/STRONG&gt; &lt;U&gt;below are some useful CLI commands for troubleshooting HA SSO&lt;/U&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT color="#008000"&gt;test wireless redundancy rping&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;show redundancy | i ptime|Location|Current Software state|Switchovers&lt;BR /&gt;show chassis &lt;BR /&gt;show chassis detail&lt;BR /&gt;show chassis ha-status local &lt;BR /&gt;show chassis ha-status active &lt;BR /&gt;show chassis ha-status standby &lt;BR /&gt;&lt;STRONG&gt;show chassis rmi&lt;/STRONG&gt;&lt;BR /&gt;show redundancy &lt;BR /&gt;show redundancy history &lt;BR /&gt;&lt;STRONG&gt;show redundancy switchover history&lt;/STRONG&gt; &lt;BR /&gt;show tech wireless redundancy&lt;BR /&gt;show redundancy states &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 13:28:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-ha-sso-pair-broken/m-p/5321973#M285622</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-08-19T13:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 HA SSO pair broken</title>
      <link>https://community.cisco.com/t5/wireless/c9800-ha-sso-pair-broken/m-p/5321978#M285623</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I wonder if it might be a lot easier to revert the primary to a standalone WLC, move that, and then add a newly created WLC VM as standby ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This good but need some correction'&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Break SSO and move the secondary WLC'&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Then force AP to join secondary WLC one by one or as groups&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Then move primary to other site after you sure all AP join secondary wlc&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Last re config SSO again&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213915-configure-catalyst-9800-wireless-control.html#toc-hId--121408849" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213915-configure-catalyst-9800-wireless-control.html#toc-hId--121408849&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 13:51:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-ha-sso-pair-broken/m-p/5321978#M285623</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-19T13:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 HA SSO pair broken</title>
      <link>https://community.cisco.com/t5/wireless/c9800-ha-sso-pair-broken/m-p/5322286#M285634</link>
      <description>&lt;P&gt;Additional information :&amp;nbsp;&lt;/P&gt;&lt;P&gt;From what understand from the server guys : They moved the primary WLC VM (S901) by doing a storage move to the new vmWare cluster (with it's own venter etc), so no vMotion. They were counting on the standby WLC to take over while the primary was being moved.&lt;/P&gt;&lt;P&gt;However, the needed networks for the S901 VM were not yet fully configured on the new cluster &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; So the moved S901 booted without being able to contact it standby peer S902 or the APs. They completed the network settings a few minutes later. At that moment our wifi environment was already offline. Most of our SSID's need authentication via radius which did not work since that goes via the WLC first.&amp;nbsp;&lt;/P&gt;&lt;P&gt;At that moment in time the server guys finally told me about what they were doing because trouble tickets were pouring into our service desk. (We had a very stern discussion about why the &amp;lt;bleep&amp;gt; they did this during regular office hours and without talking to "networks"" first. But too little too late)&lt;/P&gt;&lt;P&gt;I logged in to the S901 (i thought, but i think it was the S902 in hindsight) and noticed that it was running but all APs etc were gone. I wanted to restore the config from backup, but the server guys beat me to it by restoring the S901 WLC vm on the old cluster and booting that (and killing the moved S901).&amp;nbsp;This restore action worked, our users were able to work again. Panic over.&lt;/P&gt;&lt;P&gt;Later, while trying to figure out what happened exactly and checking if everything was okay for now, i noticed that the HA was broken :&lt;/P&gt;&lt;P&gt;xxx-xxx-S901#show chassis&lt;BR /&gt;Chassis/Stack Mac Address : xxxx.xxxx.xxxx - Local Mac Address&lt;BR /&gt;Mac persistency wait time: Indefinite&lt;BR /&gt;H/W Current&lt;BR /&gt;Chassis# Role Mac Address Priority Version State IP&lt;BR /&gt;-------------------------------------------------------------------------------------&lt;BR /&gt;*1 Active x.x.x.x 2 V02 Ready 169.254.24.7&lt;BR /&gt;2 Member 0000.0000.0000 0 V02 Removed 169.254.24.8&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The S902 VM was not responding via the network at all, so i checked the console via vmWare.&lt;/P&gt;&lt;P&gt;This showed that the S902 is now called the S901. The show chassis command showed that chassis #2 is in the Active role and in the ready state. IP 169.254.24.8&amp;nbsp;But it showed only the "S902" chassis in the list, no HA partner was visible at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So that is the status at the moment. The S901 vm is running on the "old" cluster, doing what it should be doing. No HA standby though. The S902 vm (also still on the old cluster) can be booted but it comes up as the S901 and thinks it is a standalone WLC even though that "show chassis" shows it as chassis# *2.&lt;/P&gt;&lt;P&gt;I kee the S902 vm offline to make sure we get no duplicate IP or a split brain fight between the 2 vm's.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 06:23:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-ha-sso-pair-broken/m-p/5322286#M285634</guid>
      <dc:creator>Redguy</dc:creator>
      <dc:date>2025-08-20T06:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 HA SSO pair broken</title>
      <link>https://community.cisco.com/t5/wireless/c9800-ha-sso-pair-broken/m-p/5322341#M285635</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; -&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1631942"&gt;@Redguy&lt;/a&gt;&amp;nbsp; &amp;nbsp;There is too much going on &lt;FONT color="#FF6600"&gt;&lt;EM&gt;beyond your exact control.&lt;/EM&gt;&lt;/FONT&gt; Mistakes can not be excluded.&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; I can only advice to check logs on the controllers&amp;nbsp; when things are going wrong (&lt;STRONG&gt;show logging&lt;/STRONG&gt;).&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Also take a look at :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-wireless-controllers-cloud/218438-verify-support-vmware-vsphere-vmotion-wi.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-wireless-controllers-cloud/218438-verify-support-vmware-vsphere-vmotion-wi.html&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;It contains a few tables about what is allowed or not when&amp;nbsp; moving controllers between platforms&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;U&gt;&amp;nbsp; Also from the same document :&lt;/U&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;gt;...&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Recommendation&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;: For best results, it is recommended to configure RP port keepalives to at least twice the default 100 ms keepalive (set it to 200 ms). If the network between storage and hosts can become busy and increase latency, consider to set the keepalives timer to 300 ms. To configure the keepalive timer on the GUI, go to Administration &amp;gt; Device &amp;gt; Redundancy:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;gt;...&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="lia-code-sample  language-markup"&gt;&lt;CODE&gt;C9800-SSO#chassis redundancy keep-alive timer 3 &lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 08:41:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-ha-sso-pair-broken/m-p/5322341#M285635</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-08-20T08:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 HA SSO pair broken</title>
      <link>https://community.cisco.com/t5/wireless/c9800-ha-sso-pair-broken/m-p/5322374#M285636</link>
      <description>&lt;P&gt;I am totally with &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This beyond your control.&lt;/P&gt;
&lt;P&gt;And for Vmotion' what is this relate to migrate wlc from one vm to other ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 09:55:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-ha-sso-pair-broken/m-p/5322374#M285636</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-20T09:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 HA SSO pair broken</title>
      <link>https://community.cisco.com/t5/wireless/c9800-ha-sso-pair-broken/m-p/5322441#M285644</link>
      <description>&lt;P&gt;I think there's a good chance they removed the WLC-required network changes (Promiscuous mode and Forged Transmits) for the S902 and probably also forgot to configure them for the new VMs (our lab team did this when moving things around recently even after I had reminded them).&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html#C9800CLconsiderations" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html#C9800CLconsiderations&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Check the Best Practices guide for the rest of the 9800-CL considerations and also make sure everything in the installation and setup guide is covered too.&lt;/P&gt;
&lt;P&gt;You should have been able to move them if it had all been set up correctly in advance and timing of the moves had been done right but given the current situation you have - agreed that you would be best reverting to standalone WLC (break HA-SSO), move the standalone server (during a maintenance window for planned outage) and then re-create the backup and re-establish HA-SSO.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or if you don't want the outage then build a new WLC as N+1. Move the APs to the new WLC - the advantage being that you can move 1 or 2 APs first and test to make sure it's working.&amp;nbsp; When you're happy it's good move the rest of the APs.&amp;nbsp; Then either move the old one or build a new one to join to the other new one as HA-SSO pair.&lt;/P&gt;
&lt;P&gt;Depending on what version you're running now you might be better off building new VMs with larger bootflash partitions to accommodate the larger disk size required on newer versions.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 12:42:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-ha-sso-pair-broken/m-p/5322441#M285644</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2025-08-20T12:42:42Z</dc:date>
    </item>
  </channel>
</rss>

