<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anchor WLC 9800CL and Foreigns WLC 9800 LF in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351867#M287737</link>
    <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Yes, I ran WLCCA for both WLC's. Detect the following situation in the Foreign (9800LF)&lt;/P&gt;
&lt;P&gt;DTLS_TRACE_MSG-3-X509_CERT_VERIFY_ERR Times Seen 376&lt;BR /&gt;First Seen 039900: Dec 2 05:34:38.090:&lt;BR /&gt;Last Seen 042646: Dec 2 13:22:39.243:&lt;BR /&gt;Text Chassis 1 R0/0: mobilityd: Cert verify Error, Session:192.168.254.22[16666], Certificate hash is invalid&lt;/P&gt;
&lt;P&gt;DTLS_TRACE_MSG-3-WLC_DTLS_ERR Times Seen 376&lt;BR /&gt;First Seen 039901: Dec 2 05:34:38.090:&lt;BR /&gt;Last Seen 042647: Dec 2 13:22:39.243:&lt;BR /&gt;Text Chassis 1 R0/0: mobilityd: DTLS Error, session:192.168.254.22[16666], Certificate validation failed&lt;/P&gt;
&lt;P&gt;In the Anchor (9800CL), the state of the DTLS Control Link Status is Init, and not showing errors in the WLCCA.&lt;/P&gt;
&lt;P&gt;I solved the situation usign the same SSC hash that generated by the 9800CL to stablish HASHING for both WLCs. Will this behavior be required when using mobility tunnels with a CLOUD-type anchor?&lt;/P&gt;</description>
    <pubDate>Wed, 03 Dec 2025 06:10:31 GMT</pubDate>
    <dc:creator>JesusSeijas</dc:creator>
    <dc:date>2025-12-03T06:10:31Z</dc:date>
    <item>
      <title>Anchor WLC 9800CL and Foreigns WLC 9800 LF</title>
      <link>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351260#M287686</link>
      <description>&lt;P&gt;Hello There,&lt;/P&gt;
&lt;P&gt;I'm in a new deployment with an Anchor 9800CL, where the mobility tunnels aren't fully establishing. I'm detecting the following errors on the WLC foreign.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;038011: Dec 1 23:25:16.095: %MM_NODE_LOG-4-DTLS_HANDSHAKE_FAIL: Chassis 1 R0/0: mobilityd: Mobility DTLS Ctrl handshake failed for IP: 192.168.254.22 HB is down, need to re-initiate DTLS handshake&lt;BR /&gt;038012: Dec 1 23:25:28.095: %MM_NODE_LOG-4-DTLS_HANDSHAKE_FAIL: Chassis 1 R0/0: mobilityd: Mobility DTLS Ctrl handshake failed for IP: 192.168.254.22 HB is down, need to re-initiate DTLS handshake&lt;BR /&gt;038013: Dec 1 23:25:37.096: %DTLS_TRACE_MSG-3-X509_CERT_VERIFY_ERR: Chassis 1 R0/0: mobilityd: Cert verify Error, Session:192.168.254.22[16666], Certificate hash is invalid&lt;BR /&gt;038014: Dec 1 23:25:37.096: %DTLS_TRACE_MSG-3-WLC_DTLS_ERR: Chassis 1 R0/0: mobilityd: DTLS Error, session:192.168.254.22[16666], Certificate validation failed&lt;/P&gt;
&lt;P&gt;Status of the tunnel from Foreign WLC&lt;/P&gt;
&lt;P&gt;Mobility Peer Info&lt;BR /&gt;===================&lt;BR /&gt;Ip Address : 192.168.254.22&lt;BR /&gt;Public Ip Address : 192.168.254.22&lt;BR /&gt;MAC Address : 11e.bdee.afff&lt;BR /&gt;Group Name : ANCHOR-WLC&lt;BR /&gt;Total Number of Clients on Peer : 0&lt;BR /&gt;Local Clients Exported to Peer : 0&lt;BR /&gt;Locally Anchored Peer Clients : 0&lt;BR /&gt;Data Link Encryption Status : Disabled&lt;BR /&gt;Keepalive Data Link Status : UP&lt;BR /&gt;Keepalive Control Link Status : UP&lt;BR /&gt;DTLS Data Link Cipher : TLS_NUM_NULL_WITH_NULL_NULL&lt;BR /&gt;DTLS Data Link Status : Disabled&lt;BR /&gt;DTLS Control Link Cipher : TLS_NUM_NULL_WITH_NULL_NULL&lt;BR /&gt;DTLS Control Link Status : Disabled&lt;BR /&gt;PMTU : 1385&lt;BR /&gt;Tunnel Plumbed : Yes&lt;BR /&gt;Tunnel IFID : 0xA0000B98&lt;BR /&gt;Number of Data Path Flaps : 0&lt;BR /&gt;Last Data Path Flap : Never&lt;/P&gt;
&lt;P&gt;Status of the tunnel from Anchor WLC&lt;/P&gt;
&lt;P&gt;Mobility Peer Info&lt;BR /&gt;===================&lt;BR /&gt;Ip Address : 172.16.131.180&lt;BR /&gt;Public Ip Address : 172.16.131.180&lt;BR /&gt;MAC Address : 18c6.5021.ce2f&lt;BR /&gt;Group Name : FOREIGN-WLC&lt;BR /&gt;Total Number of Clients on Peer : 446&lt;BR /&gt;Local Clients Exported to Peer : 0&lt;BR /&gt;Locally Anchored Peer Clients : 0&lt;BR /&gt;Data Link Encryption Status : Disabled&lt;BR /&gt;Keepalive Data Link Status : UP&lt;BR /&gt;Keepalive Control Link Status : UP&lt;BR /&gt;DTLS Data Link Cipher : TLS_NUM_NULL_WITH_NULL_NULL&lt;BR /&gt;DTLS Data Link Status : Disabled&lt;BR /&gt;DTLS Control Link Cipher : TLS_NUM_NULL_WITH_NULL_NULL&lt;BR /&gt;DTLS Control Link Status : Init&lt;BR /&gt;PMTU : 1385&lt;BR /&gt;Tunnel Plumbed : Yes&lt;/P&gt;
&lt;P&gt;WMI trustpoint Anchor WLC&lt;/P&gt;
&lt;P&gt;Anchor-WLC#show wire mana trustpoint &lt;BR /&gt;Trustpoint Name : Anchor-WLC_WLC_TP&lt;BR /&gt;Certificate Info : Available&lt;BR /&gt;Certificate Type : SSC&lt;BR /&gt;Certificate Hash : d1354d53a3d70a541b7c5e3097356e802f2eaa5d&lt;BR /&gt;Private key Info : Available&lt;BR /&gt;FIPS suitability : Not Applicable&lt;/P&gt;
&lt;P&gt;WMI trustpoint Foreign WLC&lt;/P&gt;
&lt;P&gt;Foreign-WLC01-V#show wire mana trustpoint &lt;BR /&gt;Trustpoint Name : CISCO_IDEVID_CMCA3_SUDI&lt;BR /&gt;Certificate Info : Available&lt;BR /&gt;Certificate Type : MIC&lt;BR /&gt;Certificate Hash : a35bde1f47bcce757a9911007b3634e6ac75dca3&lt;BR /&gt;Private key Info : Available&lt;BR /&gt;FIPS suitability : Not Applicable&lt;/P&gt;
&lt;P&gt;Any idea&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326193"&gt;@Scott Fella&lt;/a&gt;&amp;nbsp;?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 15:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351260#M287686</guid>
      <dc:creator>JesusSeijas</dc:creator>
      <dc:date>2025-12-01T15:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: Anchor WLC 9800CL and Foreigns WLC 9800 LF</title>
      <link>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351298#M287689</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; -&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1889250"&gt;@JesusSeijas&lt;/a&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;SPAN&gt;Use&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class="cCN_CmdName"&gt;&lt;STRONG&gt;show wireless management trustpoint&lt;/STRONG&gt;&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class="cCN_CmdName"&gt;&lt;STRONG&gt;show crypto pki trustpoints &lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/STRONG&gt;&lt;/CODE&gt;&lt;SPAN&gt;commands to verify your certificate information&amp;nbsp; on the&amp;nbsp;&lt;STRONG&gt;&amp;nbsp;WLC 9800CL&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Validate the complete configuration of this controller using the CLI command&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;FONT color="#008000"&gt;&lt;STRONG&gt; &amp;nbsp;show tech wireless&lt;/STRONG&gt; &lt;/FONT&gt;and feed the output from that into&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank"&gt;Wireless Config Analyzer&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Use the full command as outlined in green; it does not work with &lt;FONT color="#FF0000"&gt;&lt;EM&gt;show tech-support&lt;/EM&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; M.&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 17:27:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351298#M287689</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-12-01T17:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: Anchor WLC 9800CL and Foreigns WLC 9800 LF</title>
      <link>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351301#M287690</link>
      <description>&lt;P&gt;Are these both on the same campus? Do you have any FW in between?&lt;/P&gt;
&lt;P&gt;What code is running on both WLCs?&lt;/P&gt;
&lt;P&gt;Check the config and port requirement :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213912-configure-mobility-anchor-on-catalyst-98.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213912-configure-mobility-anchor-on-catalyst-98.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;depends on version check bug :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cisco.com/quickview/bug/CSCwe60294" target="_blank"&gt;https://bst.cisco.com/quickview/bug/CSCwe60294&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 17:38:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351301#M287690</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-12-01T17:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: Anchor WLC 9800CL and Foreigns WLC 9800 LF</title>
      <link>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351458#M287704</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;WMI trustpoint Anchor WLC (9800 CL)&lt;/P&gt;
&lt;P&gt;Anchor-WLC#show wire mana trustpoint&lt;BR /&gt;Trustpoint Name : Anchor-WLC_WLC_TP&lt;BR /&gt;Certificate Info : Available&lt;BR /&gt;Certificate Type : SSC&lt;BR /&gt;Certificate Hash : d1354d53a3d70a541b7c5e3097356e802f2eaa5d&lt;BR /&gt;Private key Info : Available&lt;BR /&gt;FIPS suitability : Not Applicable&lt;/P&gt;
&lt;P&gt;Anchor-WLC# show crypto pki trustpoints &lt;BR /&gt;Trustpoint SLA-TrustPoint:&lt;BR /&gt;Subject Name: &lt;BR /&gt;cn=Cisco Licensing Root CA&lt;BR /&gt;o=Cisco&lt;BR /&gt;Serial Number (hex): 01&lt;BR /&gt;Certificate configured.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Trustpoint TP-self-signed-2627895496:&lt;BR /&gt;Subject Name: &lt;BR /&gt;hostname=Anchor-WLC.dcdomain.com&lt;BR /&gt;cn=IOS-Self-Signed-Certificate-2627895496&lt;BR /&gt;Serial Number (hex): 01&lt;BR /&gt;Persistent self-signed certificate trust point&lt;BR /&gt;Using key label TP-self-signed-2627895496&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Trustpoint WLC_CA:&lt;BR /&gt;Subject Name: &lt;BR /&gt;o=Cisco Virtual Wireless LAN Controller&lt;BR /&gt;cn=CA-vWLC_Anchor-WLC&lt;BR /&gt;Serial Number (hex): 01&lt;BR /&gt;Certificate configured.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Trustpoint Anchor-WLC_WLC_TP:&lt;BR /&gt;Subject Name: &lt;BR /&gt;o=Cisco Virtual Wireless LAN Controller&lt;BR /&gt;cn=CA-vWLC_Anchor-WLC&lt;BR /&gt;Serial Number (hex): 01&lt;BR /&gt;Certificate configured.&lt;BR /&gt;SCEP URL: &lt;A href="http://192.168.254.22:80/cgi-bin" target="_blank"&gt;http://192.168.254.22:80/cgi-bin&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I did some debugs in Foreign WLC (9800 LF), and detect the possible issue. Maybe is it necessary to upload the Anchor 9800CL certificate to the foreign 9800LF?&lt;/P&gt;
&lt;P&gt;[mm-client] [16941]: (debug): MAC: 0000.0000.0000 Sending keepalive_ctrl_rsp of XID (132) to (ipv4: 192.168.254.22 )&lt;BR /&gt;[mm-keepalive] [16941]: (note): Peer IP: 192.168.254.22 Control link set state to UP (was DOWN)&lt;BR /&gt;[errmsg] [16941]: (note): %MM_NODE_LOG-5-KEEP_ALIVE: R0/0: mobilityd: Mobility Control tunnel to peer IP: 192.168.254.22 changed state to UP&lt;BR /&gt;ap-upgrade] [15872]: (note): Process mobility tunnel Up message : Upgrade rec not found. Report name: &lt;BR /&gt;[mm-dtls] [16941]: (note): Peer IP: 192.168.254.22 Port: 16666 DTLS_CLEAR_KEY: DTLS keys cleared from MNC and FMAN&lt;BR /&gt;[mm-dtls] [16941]: (note): Peer IP: 192.168.254.22 Port: 16666, Local IP: 172.16.131.180 Port: 16666 DTLS_CLOSE_CB: DTLS connection is closed&lt;BR /&gt;[ewlc-dtls-sess] [16941]: (info): release client sm resource&lt;BR /&gt;[ewlc-dtls-sess] [16941]: (note): Remote Host: 192.168.254.22[16666] DTLS session destroy&lt;BR /&gt;[mm-client] [16941]: (debug): MAC: 001e.bdee.afff Received keepalive_data, sub type: 0 of XID (0) from (ipv4: 192.168.254.22 )&lt;BR /&gt;[mm-dtls] [16941]: (debug): Peer IP: 192.168.254.22 Port: 16667 MM_KA_DTLS_START: DTLS not supported&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 05:14:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351458#M287704</guid>
      <dc:creator>JesusSeijas</dc:creator>
      <dc:date>2025-12-02T05:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Anchor WLC 9800CL and Foreigns WLC 9800 LF</title>
      <link>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351460#M287705</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What code is running on both WLCs?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Anchor WLC (9800CL) --&amp;gt;&amp;nbsp;17.15.4b&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Foreign WLC (9800LF) --&amp;gt;&amp;nbsp;17.9.6&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;There are in different locations.&amp;nbsp;Yes, we've different firewalls in the middle in this communication, it's permitted, keepalives communications in both WLC are OK.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Anchor WLC (9800CL)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Keepalive Data Link Status : UP&lt;BR /&gt;Keepalive Control Link Status : UP&lt;BR /&gt;DTLS Data Link Cipher : TLS_NUM_NULL_WITH_NULL_NULL&lt;BR /&gt;DTLS Data Link Status : Disabled&lt;BR /&gt;DTLS Control Link Cipher : TLS_NUM_NULL_WITH_NULL_NULL&lt;BR /&gt;DTLS Control Link Status : Init&lt;BR /&gt;PMTU : 1385&lt;BR /&gt;Tunnel Plumbed : Yes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Foreign WLC (9800LF)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Keepalive Data Link Status : UP&lt;BR /&gt;Keepalive Control Link Status : UP&lt;BR /&gt;DTLS Data Link Cipher : TLS_NUM_NULL_WITH_NULL_NULL&lt;BR /&gt;DTLS Data Link Status : Disabled&lt;BR /&gt;DTLS Control Link Cipher : TLS_NUM_NULL_WITH_NULL_NULL&lt;BR /&gt;DTLS Control Link Status : Disabled&lt;BR /&gt;PMTU : 1385&lt;BR /&gt;Tunnel Plumbed : Yes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I did some debugs in Foreign WLC (9800 LF), and detect the possible issue. Maybe is it necessary to upload the Anchor 9800CL certificate to the foreign 9800LF?&lt;/P&gt;
&lt;P&gt;[mm-client] [16941]: (debug): MAC: 0000.0000.0000 Sending keepalive_ctrl_rsp of XID (132) to (ipv4: 192.168.254.22 )&lt;BR /&gt;[mm-keepalive] [16941]: (note): Peer IP: 192.168.254.22 Control link set state to UP (was DOWN)&lt;BR /&gt;[errmsg] [16941]: (note): %MM_NODE_LOG-5-KEEP_ALIVE: R0/0: mobilityd: Mobility Control tunnel to peer IP: 192.168.254.22 changed state to UP&lt;BR /&gt;ap-upgrade] [15872]: (note): Process mobility tunnel Up message : Upgrade rec not found. Report name:&lt;BR /&gt;[mm-dtls] [16941]: (note): Peer IP: 192.168.254.22 Port: 16666 DTLS_CLEAR_KEY: DTLS keys cleared from MNC and FMAN&lt;BR /&gt;[mm-dtls] [16941]: (note): Peer IP: 192.168.254.22 Port: 16666, Local IP: 172.16.131.180 Port: 16666 DTLS_CLOSE_CB: DTLS connection is closed&lt;BR /&gt;[ewlc-dtls-sess] [16941]: (info): release client sm resource&lt;BR /&gt;[ewlc-dtls-sess] [16941]: (note): Remote Host: 192.168.254.22[16666] DTLS session destroy&lt;BR /&gt;[mm-client] [16941]: (debug): MAC: 001e.bdee.afff Received keepalive_data, sub type: 0 of XID (0) from (ipv4: 192.168.254.22 )&lt;BR /&gt;[mm-dtls] [16941]: (debug): Peer IP: 192.168.254.22 Port: 16667 MM_KA_DTLS_START: DTLS not supported&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 05:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351460#M287705</guid>
      <dc:creator>JesusSeijas</dc:creator>
      <dc:date>2025-12-02T05:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: Anchor WLC 9800CL and Foreigns WLC 9800 LF</title>
      <link>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351560#M287713</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1889250"&gt;@JesusSeijas&lt;/a&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp; Validate the complete configuration &lt;U&gt;both&lt;/U&gt; controllers using the CLI command&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#008000"&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;show tech wireless&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;and feed the output from that into&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank" rel="nofollow noopener noreferrer"&gt;Wireless Config Analyzer&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Use the full command as outlined in green; it does not work with&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;EM&gt;show tech-support&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; + Make sure to configure a unique mobility mac address&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; +&amp;nbsp; Check output from&amp;nbsp;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; show wireless mobility summary&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 10:26:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351560#M287713</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-12-02T10:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: Anchor WLC 9800CL and Foreigns WLC 9800 LF</title>
      <link>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351784#M287732</link>
      <description>&lt;P&gt;is this NAT 1:1 static NAT ?&lt;/P&gt;
&lt;P&gt;Make sure you configure external IP on the anchor configuration. and try packet capture.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/221707-configure-9800-wireless-lan-controller-m.html#toc-hId--1386946523" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/221707-configure-9800-wireless-lan-controller-m.html#toc-hId--1386946523&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 20:25:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351784#M287732</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-12-02T20:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: Anchor WLC 9800CL and Foreigns WLC 9800 LF</title>
      <link>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351867#M287737</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Yes, I ran WLCCA for both WLC's. Detect the following situation in the Foreign (9800LF)&lt;/P&gt;
&lt;P&gt;DTLS_TRACE_MSG-3-X509_CERT_VERIFY_ERR Times Seen 376&lt;BR /&gt;First Seen 039900: Dec 2 05:34:38.090:&lt;BR /&gt;Last Seen 042646: Dec 2 13:22:39.243:&lt;BR /&gt;Text Chassis 1 R0/0: mobilityd: Cert verify Error, Session:192.168.254.22[16666], Certificate hash is invalid&lt;/P&gt;
&lt;P&gt;DTLS_TRACE_MSG-3-WLC_DTLS_ERR Times Seen 376&lt;BR /&gt;First Seen 039901: Dec 2 05:34:38.090:&lt;BR /&gt;Last Seen 042647: Dec 2 13:22:39.243:&lt;BR /&gt;Text Chassis 1 R0/0: mobilityd: DTLS Error, session:192.168.254.22[16666], Certificate validation failed&lt;/P&gt;
&lt;P&gt;In the Anchor (9800CL), the state of the DTLS Control Link Status is Init, and not showing errors in the WLCCA.&lt;/P&gt;
&lt;P&gt;I solved the situation usign the same SSC hash that generated by the 9800CL to stablish HASHING for both WLCs. Will this behavior be required when using mobility tunnels with a CLOUD-type anchor?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 06:10:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351867#M287737</guid>
      <dc:creator>JesusSeijas</dc:creator>
      <dc:date>2025-12-03T06:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: Anchor WLC 9800CL and Foreigns WLC 9800 LF</title>
      <link>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351868#M287738</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, it's the same than the internal, it's that to say we're not applying NAT into the WLC and later on, because this communication can be established using private ip's.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I solved the situation usign the same SSC hash that generated by the 9800CL to stablish HASHING for both WLCs. Will this behavior be required when using mobility tunnels with a CLOUD-type anchor?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 06:12:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351868#M287738</guid>
      <dc:creator>JesusSeijas</dc:creator>
      <dc:date>2025-12-03T06:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: Anchor WLC 9800CL and Foreigns WLC 9800 LF</title>
      <link>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351875#M287739</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;-&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1889250"&gt;@JesusSeijas&lt;/a&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Yes , I think so&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 07:10:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351875#M287739</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-12-03T07:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: Anchor WLC 9800CL and Foreigns WLC 9800 LF</title>
      <link>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351898#M287744</link>
      <description>&lt;P&gt;Both sides always need the same HASH configuration if you're using that.&lt;/P&gt;
&lt;P&gt;Could you check the packet capture to see what is wrong? Once the configuration is verified?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 08:07:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/anchor-wlc-9800cl-and-foreigns-wlc-9800-lf/m-p/5351898#M287744</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-12-03T08:07:49Z</dc:date>
    </item>
  </channel>
</rss>

