<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Take a look at the following in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/lightweight-ap-3500-fail-to-join-capwap-lwapp/m-p/3030029#M55652</link>
    <description>&lt;P&gt;Take a look at the following link:&amp;nbsp;https://supportforums.cisco.com/document/12453081/lightweight-ap-fail-create-capwaplwapp-connection-due-certificate-expiration&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also disable your NTP server.&lt;/P&gt;</description>
    <pubDate>Fri, 20 Jan 2017 17:01:18 GMT</pubDate>
    <dc:creator>Emerson Rodrigues</dc:creator>
    <dc:date>2017-01-20T17:01:18Z</dc:date>
    <item>
      <title>Lightweight AP 3500 fail to join capwap/lwapp</title>
      <link>https://community.cisco.com/t5/wireless/lightweight-ap-3500-fail-to-join-capwap-lwapp/m-p/3030028#M55651</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;I just took an old, never used 2012 manufactured AP 3502i-E out of the box (it had image 7.0.114.40 (or something like this) preinstalled) and was unable to join it to any of my controllers. It's unable to build the DTLS connection to the controller.&lt;/P&gt;
&lt;P&gt;What I tried so far:&lt;/P&gt;
&lt;P&gt;manually upgrade the image in recovery on the AP to ap3g1-k9w8-mx.153-3.JD (from the 8.3.x release)&lt;/P&gt;
&lt;P&gt;changed the clock on an old WiSM running 7.0.252.0 to the year 2012&lt;/P&gt;
&lt;P&gt;set this command on the old controller "config ap lifetime-check mic enable&amp;nbsp;"&lt;/P&gt;
&lt;P&gt;also tested with the newer command on a WLC 5520 running 8.2.141.0 (but didn't change the clock on the 5520).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So far nothing of this helped.&lt;/P&gt;
&lt;P&gt;Here's the boot output from the ap. Controller with the IP 172.16.102.24 is the WiSM with the old date.&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;r WRDTR,CLKTR: 0x8200083f 0x40000000 &lt;BR /&gt;r RQDC ,RFDC : 0x80000033 0x00000212&lt;BR /&gt;using&amp;nbsp; eeprom values&lt;BR /&gt;WRDTR,CLKTR: 0x8200083f 0x40000000 &lt;BR /&gt;RQDC ,RFDC : 0x80000033 0x00000212&lt;BR /&gt;using MCNG ddr static values from serial eeprom&lt;BR /&gt;ddr init done&lt;BR /&gt;Running Normal Memtest...&lt;BR /&gt;Passed.&lt;BR /&gt;IOS Bootloader - Starting system.&lt;BR /&gt;FLASH CHIP:&amp;nbsp; Numonyx P33&lt;BR /&gt;Checking for Over Erased blocks&lt;BR /&gt;......................................................................................................................................................................................................................................................&lt;BR /&gt;Xmodem file system is available.&lt;BR /&gt;DDR values used from system serial eeprom.&lt;BR /&gt;WRDTR,CLKTR: 0x8200083f, 0x40000000&lt;BR /&gt;RQDC, RFDC : 0x80000033, 0x00000212&lt;BR /&gt;PCIE0: link is up.&lt;BR /&gt;PCIE0: VC0 is active&lt;BR /&gt;PCIE1: link is up.&lt;BR /&gt;PCIE1: VC0 is active&lt;BR /&gt;64bit PCIE devices&lt;BR /&gt;PCIEx: initialization done&lt;BR /&gt;flashfs[0]: 42 files, 8 directories&lt;BR /&gt;flashfs[0]: 0 orphaned files, 0 orphaned directories&lt;BR /&gt;flashfs[0]: Total bytes: 31739904&lt;BR /&gt;flashfs[0]: Bytes used: 10029568&lt;BR /&gt;flashfs[0]: Bytes available: 21710336&lt;BR /&gt;flashfs[0]: flashfs fsck took 9 seconds.&lt;BR /&gt;Reading cookie from system serial eeprom...Done&lt;BR /&gt;Base Ethernet MAC address: a4:93:4c:f3:1d:8b&lt;BR /&gt;Ethernet speed is 1000 Mb - FULL duplex&lt;BR /&gt;Loading "flash:/ap3g1-k9w8-mx.153-3.JD/ap3g1-k9w8-mx.153-3.JD"...###############&lt;BR /&gt;File "flash:/ap3g1-k9w8-mx.153-3.JD/ap3g1-k9w8-mx.153-3.JD" uncompressed and installed, entry point: 0x4000&lt;BR /&gt;executing...&lt;BR /&gt;enet halted&lt;BR /&gt;IOS Secondary Bootloader - Starting system.&lt;BR /&gt;FLASH CHIP:&amp;nbsp; Numonyx P33&lt;BR /&gt;Checking for Over Erased blocks&lt;BR /&gt;......................................................................................................................................................................................................................................................&lt;BR /&gt;Xmodem file system is available.&lt;BR /&gt;DDR values used from system serial eeprom.&lt;BR /&gt;WRDTR,CLKTR: 0x8200083f, 0x40000000&lt;BR /&gt;RQDC, RFDC : 0x80000033, 0x00000212&lt;BR /&gt;PCIE0: link is up.&lt;BR /&gt;PCIE0: VC0 is active&lt;BR /&gt;PCIE1: link is up.&lt;BR /&gt;PCIE1: VC0 is active&lt;BR /&gt;Radio 0 : Vendor 0x11AB, Device 0x8350&lt;BR /&gt;64bit PCIE devices&lt;BR /&gt;Radio 1 : Vendor 0x11AB, Device 0x8324&lt;BR /&gt;PCIEx: initialization done&lt;BR /&gt;flashfs[0]: 42 files, 8 directories&lt;BR /&gt;flashfs[0]: 0 orphaned files, 0 orphaned directories&lt;BR /&gt;flashfs[0]: Total bytes: 31739904&lt;BR /&gt;flashfs[0]: Bytes used: 10029568&lt;BR /&gt;flashfs[0]: Bytes available: 21710336&lt;BR /&gt;flashfs[0]: flashfs fsck took 10 seconds.&lt;BR /&gt;Reading cookie from system serial eeprom...Done&lt;BR /&gt;Base Ethernet MAC address: a4:93:4c:f3:1d:8b&lt;BR /&gt;Creating Test Kernel diagnostic commands&lt;BR /&gt;Radio 0 : Vendor 0x11AB, Device 0x8324&lt;BR /&gt;Radio 1 : Vendor 0x11AB, Device 0x8350&lt;BR /&gt;Radio 2 : Vendor 0x8909, Device 0x40&lt;BR /&gt;Radio 3 : Vendor 0x1204, Device 0x841&lt;BR /&gt;******** AUTOMATIC DDR CALIBRATION UPGRADE LOGIC *********&lt;BR /&gt;=== 1. Is original FCS bootloader in BS:?&amp;nbsp; If not, skip upgrade ===&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---&amp;gt; original FCS bootloader not detected -- skip upgrade&lt;BR /&gt;Boot CMD: 'boot&amp;nbsp; flash:/ap3g1-k9w8-mx.153-3.JD/ap3g1-k9w8-xx.153-3.JD;flash:/ap3g1-k9w8-mx.153-3.JD/ap3g1-k9w8-xx.153-3.JD'&lt;BR /&gt;Loading "flash:/ap3g1-k9w8-mx.153-3.JD/ap3g1-k9w8-xx.153-3.JD"...####################################&lt;BR /&gt;File "flash:/ap3g1-k9w8-mx.153-3.JD/ap3g1-k9w8-xx.153-3.JD" uncompressed and installed, entry point: 0x100000&lt;BR /&gt;executing...&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Restricted Rights Legend&lt;BR /&gt;Use, duplication, or disclosure by the Government is&lt;BR /&gt;subject to restrictions as set forth in subparagraph&lt;BR /&gt;(c) of the Commercial Computer Software - Restricted&lt;BR /&gt;Rights clause at FAR sec. 52.227-19 and subparagraph&lt;BR /&gt;(c) (1) (ii) of the Rights in Technical Data and Computer&lt;BR /&gt;Software clause at DFARS sec. 252.227-7013.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; cisco Systems, Inc.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 170 West Tasman Drive&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; San Jose, California 95134-1706&lt;BR /&gt;Cisco IOS Software, C3500 Software (AP3G1-K9W8-M), Version 15.3(3)JD, RELEASE SOFTWARE (fc3)&lt;BR /&gt;Technical Support: &lt;A href="http://www.cisco.com/techsupport" target="_blank"&gt;http://www.cisco.com/techsupport&lt;/A&gt;&lt;BR /&gt;Copyright (c) 1986-2016 by Cisco Systems, Inc.&lt;BR /&gt;Compiled Fri 29-Jul-16 03:37 by prod_rel_team&lt;BR /&gt;Initializing flashfs...&lt;BR /&gt;FLASH CHIP:&amp;nbsp; Numonyx P33&lt;BR /&gt;Checking for Over Erased blocks&lt;BR /&gt;......................................................................................................................................................................................................................................................&lt;BR /&gt;flashfs[2]: 42 files, 8 directories&lt;BR /&gt;flashfs[2]: 0 orphaned files, 0 orphaned directories&lt;BR /&gt;flashfs[2]: Total bytes: 31481856&lt;BR /&gt;flashfs[2]: Bytes used: 10029568&lt;BR /&gt;flashfs[2]: Bytes available: 21452288&lt;BR /&gt;flashfs[2]: flashfs fsck took 9 seconds.&lt;BR /&gt;flashfs[2]: Initialization complete.&lt;BR /&gt;flashfs[4]: 0 files, 1 directories&lt;BR /&gt;flashfs[4]: 0 orphaned files, 0 orphaned directories&lt;BR /&gt;flashfs[4]: Total bytes: 11999232&lt;BR /&gt;flashfs[4]: Bytes used: 1024&lt;BR /&gt;flashfs[4]: Bytes available: 11998208&lt;BR /&gt;flashfs[4]: flashfs fsck took 1 seconds.&lt;BR /&gt;flashfs[4]: Initialization complete.&lt;BR /&gt;Copying radio files from flash: to ram:&lt;BR /&gt;Copy in progress...CCC&lt;BR /&gt;Copy in progress...CCC&lt;BR /&gt;Copy in progress...CC&lt;BR /&gt;Uncompressing radio files...&lt;BR /&gt;...done Initializing flashfs.&lt;BR /&gt;Ethernet speed is 1000 Mb - FULL duplex&lt;BR /&gt;Radio0&amp;nbsp; present 8364B 8000 B8020000 0 B8030000 10&lt;BR /&gt;Rate table has 300 entries (16 legacy/64 11n/220 11ac)&lt;BR /&gt;POWER TABLE FILENAME = ram:/Z2.bin&lt;BR /&gt;Radio1&amp;nbsp; present 8364B 8000 B0020000 0 B0030000 C&lt;BR /&gt;POWER TABLE FILENAME = ram:/Z5.bin&lt;BR /&gt;This product contains cryptographic features and is subject to United&lt;BR /&gt;States and local country laws governing import, export, transfer and&lt;BR /&gt;use. Delivery of Cisco cryptographic products does not imply&lt;BR /&gt;third-party authority to import, export, distribute or use encryption.&lt;BR /&gt;Importers, exporters, distributors and users are responsible for&lt;BR /&gt;compliance with U.S. and local country laws. By using this product you&lt;BR /&gt;agree to comply with applicable laws and regulations. If you are unable&lt;BR /&gt;to comply with U.S. and local laws, return this product immediately.&lt;BR /&gt;A summary of U.S. laws governing Cisco cryptographic products may be found at:&lt;BR /&gt;&lt;A href="http://www.cisco.com/wwl/export/crypto/tool/stqrg.html" target="_blank"&gt;http://www.cisco.com/wwl/export/crypto/tool/stqrg.html&lt;/A&gt;&lt;BR /&gt;If you require further assistance please contact us by sending email to&lt;BR /&gt;export@cisco.com.&lt;BR /&gt;cisco AIR-CAP3502I-E-K9 (PowerPC460exr) processor (revision A0) with 98294K/32768K bytes of memory.&lt;BR /&gt;Processor board ID FCZ1626Z02N&lt;BR /&gt;PowerPC460exr CPU at 666Mhz, revision number 0x18A8&lt;BR /&gt;Last reset from reload&lt;BR /&gt;LWAPP image version 8.3.102.0&lt;BR /&gt;1 Gigabit Ethernet interface&lt;BR /&gt;2 802.11 Radios&lt;BR /&gt;32K bytes of flash-simulated non-volatile configuration memory.&lt;BR /&gt;Base ethernet MAC Address: A4:93:4C:F3:1D:8B&lt;BR /&gt;Part Number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 73-14857-01&lt;BR /&gt;PCB Serial Number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : FOC16232K2Z&lt;BR /&gt;Top Assembly Part Number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 800-32891-02&lt;BR /&gt;Top Assembly Serial Number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : FCZ1626Z02N&lt;BR /&gt;Top Revision Number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : B0&lt;BR /&gt;Product/Model Number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : AIR-CAP3502I-E-K9&amp;nbsp;&amp;nbsp; &lt;BR /&gt;% Please define a domain-name first.&lt;BR /&gt;&lt;BR /&gt;Press RETURN to get started!&lt;BR /&gt;&lt;BR /&gt;*Mar&amp;nbsp; 1 00:00:12.894: %SOAP_FIPS-2-SELF_TEST_IOS_SUCCESS: IOS crypto FIPS self test passed (15)&lt;BR /&gt;*Mar&amp;nbsp; 1 00:00:12.897: *** CRASH_LOG = YES&lt;BR /&gt;*Mar&amp;nbsp; 1 00:00:12.897: 64bit PCIE devices&lt;BR /&gt;*Mar&amp;nbsp; 1 00:00:14.004: %SOAP_FIPS-2-SELF_TEST_HW_SUCCESS: HW crypto FIPS self test passed (1-6)&lt;BR /&gt;*Mar&amp;nbsp; 1 00:00:14.004: Security Core found.&lt;BR /&gt;*Mar&amp;nbsp; 1 00:00:14.017: Registering HW DTLS&lt;BR /&gt;Base Ethernet MAC address: A4:93:4C:F3:1D:8B&lt;BR /&gt;*Mar&amp;nbsp; 1 00:00:16.244: %LINK-6-UPDOWN: Interface GigabitEthernet0, changed state to up&lt;BR /&gt;*Mar&amp;nbsp; 1 00:00:17.575: %SOAP_FIPS-2-SELF_TEST_RAD_SUCCESS: RADIO crypto FIPS self test passed on interface Dot11Radio 0 (4)&lt;BR /&gt;*Mar&amp;nbsp; 1 00:00:17.581: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0, changed state to up&lt;BR /&gt;*Mar&amp;nbsp; 1 00:00:17.701: loading Power Tables from ram:/Z2.bin. Class = E&lt;BR /&gt;*Mar&amp;nbsp; 1 00:00:17.701:&amp;nbsp; record size of 2ss: 404 read_ptr: 2868DF8&lt;BR /&gt;*Mar&amp;nbsp; 1 00:00:20.884: %SOAP_FIPS-2-SELF_TEST_RAD_SUCCESS: RADIO crypto FIPS self test passed on interface Dot11Radio 1 (4)&lt;BR /&gt;*Mar&amp;nbsp; 1 00:00:20.934: loading Power Tables from ram:/Z5.bin. Class = E&lt;BR /&gt;*Mar&amp;nbsp; 1 00:00:20.934:&amp;nbsp; record size of 2ss: 404 read_ptr: 2868DF8&lt;BR /&gt;*Jan 20 12:21:15.088: %DOT11-5-EXPECTED_RADIO_RESET: Restarting Radio interface Dot11Radio0 due to hostname change&lt;BR /&gt;*Jan 20 12:21:15.088: %DOT11-5-EXPECTED_RADIO_RESET: Restarting Radio interface Dot11Radio1 due to hostname change&lt;BR /&gt;*Jan 20 12:21:15.106: %SYS-5-RESTART: System restarted --&lt;BR /&gt;Cisco IOS Software, C3500 Software (AP3G1-K9W8-M), Version 15.3(3)JD, RELEASE SOFTWARE (fc3)&lt;BR /&gt;Technical Support: &lt;A href="http://www.cisco.com/techsupport" target="_blank"&gt;http://www.cisco.com/techsupport&lt;/A&gt;&lt;BR /&gt;Copyright (c) 1986-2016 by Cisco Systems, Inc.&lt;BR /&gt;Compiled Fri 29-Jul-16 03:37 by prod_rel_team&lt;BR /&gt;*Jan 20 12:21:15.106: %SNMP-5-COLDSTART: SNMP agent on host APa493.4cf3.1d8b is undergoing a cold start&lt;BR /&gt;*Jan 20 12:21:15.235: %DOT11-5-EXPECTED_RADIO_RESET: Restarting Radio interface Dot11Radio0 due to interface reset&lt;BR /&gt;*Jan 20 12:21:15.239: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to up&lt;BR /&gt;*Jan 20 12:21:15.242: %DOT11-5-EXPECTED_RADIO_RESET: Restarting Radio interface Dot11Radio1 due to interface reset&lt;BR /&gt;*Jan 20 12:21:15.402: %SSH-5-ENABLED: SSH 2.0 has been enabled&lt;BR /&gt;*Jan 20 12:21:15.402: %LINK-6-UPDOWN: Interface Dot11Radio1, changed state to uplwapp_crypto_init: MIC Present and Parsed Successfully&lt;BR /&gt;*Jan 20 12:21:16.163: %LINEPROTO-5-UPDOWN: Line protocol on Interface BVI1, changed state to up&lt;BR /&gt;*Jan 20 12:21:32.314: %DHCP-6-ADDRESS_ASSIGN: Interface BVI1 assigned DHCP address 172.16.102.235, mask 255.255.255.0, hostname APa493.4cf3.1d8b&lt;BR /&gt;*Jan 20 12:21:32.776: Currently running a Release Image&lt;BR /&gt;validate_sha2_block: Failed to get certificate chain&lt;BR /&gt;*Jan 20 12:21:32.798: Using SHA-1 signed certificate for image signing validation.%Default route without gateway, if not a point-to-point interface, may impact performance&lt;BR /&gt;*Jan 20 12:21:38.341: AP image integrity check PASSED&lt;BR /&gt;*Jan 20 12:21:38.350: Non-recovery image. PNP Not required.&lt;BR /&gt;*Jan 20 12:21:38.410:&amp;nbsp; validate_sha2_block:No SHA2 Block present on this AP.&lt;BR /&gt;*Jan 20 12:21:38.441: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset&lt;BR /&gt;*Jan 20 12:21:38.441: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to reset&lt;BR /&gt;*Jan 20 12:21:48.473: %SYS-6-LOGGINGHOST_STARTSTOP: Logging to host 255.255.255.255 port 0 CLI Request Triggered&lt;BR /&gt;Translating "CISCO-CAPWAP-CONTROLLER.[removed]"...domain server (152.96.20.10) [OK]&lt;BR /&gt;*Jan 20 12:22:03.091: %DOT11-5-EXPECTED_RADIO_RESET: Restarting Radio interface Dot11Radio0 due to interface reset&lt;BR /&gt;*Jan 20 12:22:03.091: %DOT11-5-EXPECTED_RADIO_RESET: Restarting Radio interface Dot11Radio1 due to interface reset&lt;BR /&gt;*Jan 20 12:22:03.091: %CDP_PD-4-POWER_OK: Full power - NEGOTIATED inline power source&lt;BR /&gt;*Jan 20 12:22:04.189: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to up&lt;BR /&gt;*Jan 20 12:22:05.190: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to up&lt;BR /&gt;*Jan 20 12:22:05.281: %LINK-6-UPDOWN: Interface Dot11Radio1, changed state to up&lt;BR /&gt;*Jan 20 12:22:06.281: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to up&lt;BR /&gt;*Jan 20 12:24:38.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 172.16.102.24 peer_port: 5246&lt;BR /&gt;*Jan 20 12:25:08.088: DTLS_CLIENT_ERROR: ../capwap/base_capwap/dtls/base_capwap_dtls_connection_db.c:2214 Max retransmission count reached for Connection 0x543B5F0!&lt;BR /&gt;*Jan 20 12:25:38.001: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 172.16.102.24:5246&lt;BR /&gt;*Jan 20 12:25:38.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 172.16.102.24 peer_port: 5246&lt;BR /&gt;*Jan 20 12:26:08.085: DTLS_CLIENT_ERROR: ../capwap/base_capwap/dtls/base_capwap_dtls_connection_db.c:2214 Max retransmission count reached for Connection 0x543B5F0!&lt;BR /&gt;*Jan 20 12:26:09.372: %CDP_PD-4-POWER_OK: Full power - NEGOTIATED inline power source&lt;BR /&gt;*Jan 20 12:26:38.001: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 172.16.102.24:5246&lt;BR /&gt;*Jan 20 12:26:45.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 172.16.102.11 peer_port: 5246&lt;BR /&gt;*Jan 20 12:26:51.017: DTLS_CLIENT_ERROR: ../capwap/base_capwap/dtls/base_capwap_dtls_record.c:394 BD is not of DTLS Change Cipher Spec type&lt;BR /&gt;*Jan 20 12:26:51.017: %DTLS-5-SEND_ALERT: Send FATAL : Internal error Alert to 172.16.102.11:5246&lt;BR /&gt;*Jan 20 12:26:51.017: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 172.16.102.11:5246&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm open for more ideas, besides doing an RMA.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 13:24:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/lightweight-ap-3500-fail-to-join-capwap-lwapp/m-p/3030028#M55651</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2021-07-05T13:24:41Z</dc:date>
    </item>
    <item>
      <title>Take a look at the following</title>
      <link>https://community.cisco.com/t5/wireless/lightweight-ap-3500-fail-to-join-capwap-lwapp/m-p/3030029#M55652</link>
      <description>&lt;P&gt;Take a look at the following link:&amp;nbsp;https://supportforums.cisco.com/document/12453081/lightweight-ap-fail-create-capwaplwapp-connection-due-certificate-expiration&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also disable your NTP server.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2017 17:01:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/lightweight-ap-3500-fail-to-join-capwap-lwapp/m-p/3030029#M55652</guid>
      <dc:creator>Emerson Rodrigues</dc:creator>
      <dc:date>2017-01-20T17:01:18Z</dc:date>
    </item>
    <item>
      <title>Forgot to add that I disabled</title>
      <link>https://community.cisco.com/t5/wireless/lightweight-ap-3500-fail-to-join-capwap-lwapp/m-p/3030030#M55653</link>
      <description>&lt;P&gt;Forgot to add that I disabled NTP before I changed the date to 2012.&lt;/P&gt;
&lt;P&gt;I also thought it's that issue. But my AP was produced (based on the serial) in 2012, so it shouldn't be affected. This is what is confusing me.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2017 07:53:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/lightweight-ap-3500-fail-to-join-capwap-lwapp/m-p/3030030#M55653</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2017-01-23T07:53:07Z</dc:date>
    </item>
    <item>
      <title>This is the DTLS debug, if</title>
      <link>https://community.cisco.com/t5/wireless/lightweight-ap-3500-fail-to-join-capwap-lwapp/m-p/3030031#M55654</link>
      <description>&lt;P&gt;This is the DTLS debug, if anybody is curious.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2017 08:02:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/lightweight-ap-3500-fail-to-join-capwap-lwapp/m-p/3030031#M55654</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2017-02-07T08:02:52Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/wireless/lightweight-ap-3500-fail-to-join-capwap-lwapp/m-p/3030032#M55655</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Frankly speaking cant find the exact reason of failure but just go the below bug which has the same issue...&lt;/P&gt;
&lt;PRE class="prettyprint prettyprinted"&gt;&lt;SPAN class="pun"&gt;*&lt;/SPAN&gt;&lt;SPAN class="typ"&gt;Jan&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;SPAN class="lit"&gt;20&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;SPAN class="lit"&gt;12&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;26&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;51.017&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; DTLS_CLIENT_ERROR&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;SPAN class="pun"&gt;../&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;capwap&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;/&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;base_capwap&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;/&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;dtls&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;/&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;base_capwap_dtls_record&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;c&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:&lt;/SPAN&gt;&lt;SPAN class="lit"&gt;394&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; BD &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;is&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;not&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; of DTLS &lt;/SPAN&gt;&lt;SPAN class="typ"&gt;Change&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;SPAN class="typ"&gt;Cipher&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;SPAN class="typ"&gt;Spec&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; type&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;Check these two bugs has slimier errors:&lt;/P&gt;
&lt;P&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuy15766/?referring_site=bugquickviewredir&lt;/P&gt;
&lt;P&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCut21564/?referring_site=bugquickviewclick&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt; I think reload to WLC will resolve your problem.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Dont forget to rate helpful post&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2017 12:20:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/lightweight-ap-3500-fail-to-join-capwap-lwapp/m-p/3030032#M55655</guid>
      <dc:creator>Sandeep Choudhary</dc:creator>
      <dc:date>2017-02-07T12:20:16Z</dc:date>
    </item>
    <item>
      <title>I tested with three different</title>
      <link>https://community.cisco.com/t5/wireless/lightweight-ap-3500-fail-to-join-capwap-lwapp/m-p/3030033#M55656</link>
      <description>&lt;P&gt;I tested with three different WLCs (one on 7.0.252.0, one on 8.0.131.40 and one on 8.2.141.0), it doesn't connect to any of those. The first two WLCs don't have a single AP connected (those are my old ones, replaced by the 8.2 based one), so it's probably not CPU load (which is at 0%).&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2017 12:24:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/lightweight-ap-3500-fail-to-join-capwap-lwapp/m-p/3030033#M55656</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2017-02-07T12:24:08Z</dc:date>
    </item>
    <item>
      <title>Then best is to</title>
      <link>https://community.cisco.com/t5/wireless/lightweight-ap-3500-fail-to-join-capwap-lwapp/m-p/3030034#M55657</link>
      <description>&lt;P&gt;Then best is to&lt;/P&gt;
&lt;P&gt;Step1:raise a TAC case with cisco if you have a vlaid service contract&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;or Step2: RMAed it.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Dont forget to rate helpful posts&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2017 12:29:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/lightweight-ap-3500-fail-to-join-capwap-lwapp/m-p/3030034#M55657</guid>
      <dc:creator>Sandeep Choudhary</dc:creator>
      <dc:date>2017-02-07T12:29:02Z</dc:date>
    </item>
    <item>
      <title>I feared that. The RMA costs</title>
      <link>https://community.cisco.com/t5/wireless/lightweight-ap-3500-fail-to-join-capwap-lwapp/m-p/3030035#M55658</link>
      <description>&lt;P&gt;I feared that. The RMA costs are sadly nearly as high as a new one and it's not anymore really worth for this old model. Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2017 12:30:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/lightweight-ap-3500-fail-to-join-capwap-lwapp/m-p/3030035#M55658</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2017-02-07T12:30:18Z</dc:date>
    </item>
  </channel>
</rss>

