<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA SSO Switchover isn't triggerd when activ WLC loses default-gw in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/5374968#M289007</link>
    <description>&lt;P&gt;And some additional monitoring commands from 17.18:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-18/config-guide/b_wl_17_18_cg/m_vewlc_high_availability.html#concept_z1r_ljq_vfc" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-18/config-guide/b_wl_17_18_cg/m_vewlc_high_availability.html#concept_z1r_ljq_vfc&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Mar 2026 09:06:11 GMT</pubDate>
    <dc:creator>Rich R</dc:creator>
    <dc:date>2026-03-06T09:06:11Z</dc:date>
    <item>
      <title>HA SSO Switchover isn't triggerd when activ WLC loses default-gw</title>
      <link>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/4780906#M252084</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I am currently configuring HA SSO&amp;nbsp; with RMI+RP on a&amp;nbsp;Catalyst 9800-L (Firmware 17.06.04) Wireless controller.&lt;/P&gt;&lt;P&gt;The peering works perfectly:&lt;/P&gt;&lt;P&gt;WLC#sh chassis Rmi&lt;BR /&gt;Chassis/Stack Mac Address : 0845.d117.c840 - Local Mac Address&lt;BR /&gt;Mac persistency wait time: Indefinite&lt;BR /&gt;Local Redundancy Port Type: Twisted Pair&lt;BR /&gt;H/W Current&lt;BR /&gt;Chassis# Role Mac Address Priority Version State IP RMI-IP&lt;BR /&gt;--------------------------------------------------------------------------------------------------------&lt;BR /&gt;*1 Active 0845.d117.c840 2 V02 Ready 169.254.0.13 10.10.0.13&lt;BR /&gt;2 Standby 0845.d117.0960 1 V02 Ready 169.254.0.14 10.10.0.14&lt;/P&gt;&lt;P&gt;The switchover also works perfectly when the active WLC goes off. Now I want when the active WLC loses connectivity to the default-gateway, the switchover is triggered as well. Here is what I configured:&lt;/P&gt;&lt;P&gt;management gateway-failover enable&lt;/P&gt;&lt;P&gt;ip default-gateway &amp;lt;ip&amp;gt;&lt;/P&gt;&lt;P&gt;Here the redundancy state of the WLC&lt;/P&gt;&lt;P&gt;WLC#sh redundancy states&lt;BR /&gt;my state = 13 -ACTIVE&lt;BR /&gt;peer state = 8 -STANDBY HOT&lt;BR /&gt;Mode = Duplex&lt;BR /&gt;Unit = Primary&lt;BR /&gt;Unit ID = 1&lt;/P&gt;&lt;P&gt;Redundancy Mode (Operational) = sso&lt;BR /&gt;Redundancy Mode (Configured) = sso&lt;BR /&gt;Redundancy State = sso&lt;BR /&gt;Maintenance Mode = Disabled&lt;BR /&gt;Manual Swact = enabled&lt;BR /&gt;Communications = Up&lt;/P&gt;&lt;P&gt;client count = 150&lt;BR /&gt;client_notification_TMR = 30000 milliseconds&lt;BR /&gt;RF debug mask = 0x0&lt;BR /&gt;Gateway Monitoring = Enabled&lt;BR /&gt;Gateway monitoring interval = 8 secs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now my problem. When I unplug the uplink (RP is still plugged) nothing happens and I don't why. After the Cisco documentation, the switchover should be triggered.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/wireless/controller/9800/17-1/deployment-guide/c9800-ha-sso-deployment-guide-rel-17-1.pdf" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/dam/en/us/td/docs/wireless/controller/9800/17-1/deployment-guide/c9800-ha-sso-deployment-guide-rel-17-1.pdf&lt;/A&gt;&amp;nbsp;(page 30).&lt;/P&gt;&lt;P&gt;The access points goes down because the active WLC is no more reachable. I also see logs that the RMI link is no more reachable on both (active and standby) WLCs. The RMI links don't have to be UP in order that the switchover is triggered, right? Otherwise, what could it be?&lt;/P&gt;&lt;P&gt;I already say thanks to the people who will take time to answer this post.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2023 21:45:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/4780906#M252084</guid>
      <dc:creator>Shiden</dc:creator>
      <dc:date>2023-02-22T21:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: HA SSO Switchover isn't triggerd when activ WLC loses default-gw</title>
      <link>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/4781203#M252085</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;U&gt;&lt;EM&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;gt;....&amp;nbsp;Now I want when the active WLC loses connectivity to the default-gateway,...&lt;/EM&gt;&lt;/U&gt;&lt;BR /&gt;&amp;nbsp; - In general HA SSO is not designed for that , it is designed to provide wireless service on a &lt;STRONG&gt;'box failure'&lt;/STRONG&gt; ; with &lt;STRONG&gt;RMI+RP&lt;/STRONG&gt; you may have failover for a local link failure too , but not for a default gateway ; that is an &lt;EM&gt;external network problem&lt;/EM&gt; so to speak ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 09:18:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/4781203#M252085</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-02-23T09:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: HA SSO Switchover isn't triggerd when activ WLC loses default-gw</title>
      <link>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/4781389#M252100</link>
      <description>&lt;P&gt;Make sure tht the mobility mac address is configured. Is RMI IP part of the same subnet as WMI interface? (Recommendation is that it must be part of the same subnet).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ip default-gateway&amp;nbsp;must be configured and it should be the gateway of the RMI Interface. (In your case&amp;nbsp;10.10.0.0 network)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Post the below outputs if you need for assitance&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;show run all | i redun&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;show run | i redun&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;show run interface Vlan &amp;lt;WMI interface VLAN&amp;gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;Most importantly make sure that the garp is enabled where the Gateway resides and upstream switchports connecting to the WLC are properly configured (great if you can post the config, recommendations- no native vlan, only allow wireless vlans, spanning tree portfast edge added to the ports)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 13:14:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/4781389#M252100</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2023-02-23T13:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: HA SSO Switchover isn't triggerd when activ WLC loses default-gw</title>
      <link>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/4782058#M252157</link>
      <description>&lt;P&gt;Actually&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;- the feature is supported from 17.1 (and 17.4 for IPv6) and designed to work exactly that way:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-4/config-guide/b_wl_17_4_cg/m_vewlc_high_availability.html#id_109520" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-4/config-guide/b_wl_17_4_cg/m_vewlc_high_availability.html#id_109520&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/wireless/controller/9800/17-6/deployment-guide/c9800-ha-sso-deployment-guide-rel-17-6.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/td/docs/wireless/controller/9800/17-6/deployment-guide/c9800-ha-sso-deployment-guide-rel-17-6.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;"Default Gateway check is done by periodically sending Internet Control Message Protocol (ICMP) ping to&lt;BR /&gt;the gateway. Both the active and the standby controllers use the RMI IP as the source IP. These messages&lt;BR /&gt;are sent at 1 second interval. If there are 8 consecutive failures in reaching the gateway, the controller will&lt;BR /&gt;declare the gateway as non-reachable.&lt;BR /&gt;After 4 ICMP Echo requests fail to get ICMP Echo responses, ARP requests are attempted. If there is no&lt;BR /&gt;response for 8 seconds (4 ICMP Echo Requests followed by 4 ARP Requests), the gateway is assumed to&lt;BR /&gt;be non-reachable.&lt;BR /&gt;IPv6 default gateway detection is supported starting release 17.4. Instead of ICMP and ARP in IPv4, IPv6&lt;BR /&gt;shall use ICMP to detect gateway failure."&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 13:54:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/4782058#M252157</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-02-24T13:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: HA SSO Switchover isn't triggerd when activ WLC loses default-gw</title>
      <link>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/4782220#M252175</link>
      <description>&lt;P&gt;Does the primary ever reboot allowing the secondary unit to take over?&amp;nbsp; With a hardware failure or just powering down the primary, the secondary just moves in right away, but not in the scenario.&amp;nbsp; If the primary never reboots, I would suspect some configuration issue or something broken in the back end.&amp;nbsp; You might also try to rebuild the SSO.&lt;/P&gt;
&lt;P&gt;I was never a fan of SSO, I have always tested it and have ran into production issues, which now I have stayed to an N+1.&amp;nbsp; By no means am I saying SSO stinks, N+1 to me is manageable and your environment might be different.&lt;/P&gt;
&lt;P&gt;Open a TAC case since I would think that you have support on this and let us know how it was fixed.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 17:57:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/4782220#M252175</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2023-02-24T17:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: HA SSO Switchover isn't triggerd when activ WLC loses default-gw</title>
      <link>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/4782687#M252200</link>
      <description>&lt;P&gt;Agree with&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326193"&gt;@Scott Fella&lt;/a&gt;&amp;nbsp;- if you're sure you've followed the config guide correctly and it's not working then time for a TAC case.&lt;BR /&gt;We've generally found SSO very reliable.&amp;nbsp; The only thing we have had occasional trouble with is the gateway reachability test failing and triggering switchover when it shouldn't.&amp;nbsp; Then different Cisco BU's fight over who lost the checks - WLC or router.&amp;nbsp; Don't think we've seen that yet with 9800 though so maybe only an AireOS problem.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Feb 2023 15:38:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/4782687#M252200</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-02-25T15:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: HA SSO Switchover isn't triggerd when activ WLC loses default-gw</title>
      <link>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/4789658#M252783</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/465548"&gt;@Arshad Safrulla&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sorry for my late reply, I have been on vacation for almost 2 weeks. When I came back, I checked the config again and had basically the same configuration that you mentioned. I tried to configure a default gateway as an IP route like this "ip route 0.0.0.0 0.0.0.0 10.10.0.1" because I saw on another forum, this could fix the problem. I tried again to unplug the uplinks, and it finally worked. To be sure this was the reason, I disabled the route again and try the same, but it also worked. Actually I am a confused with HA SSO, it's like, if you are lucky this day it will work. I don't get what was the issue before, but anyway it seems to work now&lt;/SPAN&gt;. So I know what you mean&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326193"&gt;@Scott Fella&lt;/a&gt;. &lt;SPAN&gt;Additionally, sometimes the WLC is frozen after a switchover and has to be manually restarted.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I thank you all for your answers. I will accept this one because these are excellent advices for a HA SSO.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 15:07:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/4789658#M252783</guid>
      <dc:creator>Shiden</dc:creator>
      <dc:date>2023-03-08T15:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: HA SSO Switchover isn't triggerd when activ WLC loses default-gw</title>
      <link>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/5374917#M289003</link>
      <description>&lt;P&gt;All you need is&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Example:&lt;/P&gt;&lt;P&gt;interface Vlan100&lt;BR /&gt;ip address 10.0.0.160 255.255.255.0&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.0.0.1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;management gateway-failover enable&lt;BR /&gt;&lt;BR /&gt;So when routing is enabled (which it is on the 9800), the default route handles all off-subnet traffic.&lt;BR /&gt;&lt;BR /&gt;Make sure the gateway IP is a redundant address (for example using Hot Standby Router Protocol or Virtual Router Redundancy Protocol) so the controller doesn’t fail over just because a single router fails.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2026 06:38:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/5374917#M289003</guid>
      <dc:creator>besart-rexhepi</dc:creator>
      <dc:date>2026-03-06T06:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: HA SSO Switchover isn't triggerd when activ WLC loses default-gw</title>
      <link>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/5374968#M289007</link>
      <description>&lt;P&gt;And some additional monitoring commands from 17.18:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-18/config-guide/b_wl_17_18_cg/m_vewlc_high_availability.html#concept_z1r_ljq_vfc" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-18/config-guide/b_wl_17_18_cg/m_vewlc_high_availability.html#concept_z1r_ljq_vfc&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2026 09:06:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ha-sso-switchover-isn-t-triggerd-when-activ-wlc-loses-default-gw/m-p/5374968#M289007</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2026-03-06T09:06:11Z</dc:date>
    </item>
  </channel>
</rss>

