<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Control path down - between Intranet &amp;lt;&amp;gt; DMZ in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483502#M78593</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your fast reply,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We agree that the Default Mobility Domain Name should be different in Intranet WLCs and in DMZ WLCs for security reasons ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is just important to create the anchor by specifying the Domain name configured on the destination controller ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 07 Mar 2014 17:57:03 GMT</pubDate>
    <dc:creator>holzhirt1</dc:creator>
    <dc:date>2014-03-07T17:57:03Z</dc:date>
    <item>
      <title>Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483500#M78591</link>
      <description>&lt;P&gt;We are about the deploy 2 WLCs 5508 in the DMZ to ensure traffic on mobile devices will be going thru Internet directly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Between the Intranet and the DMZ we have a firewall, we did a lot of tests and the following is occuring :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;normal pings between Intranet &amp;lt;&amp;gt; DMZ are fine&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;epings between Intranet &amp;lt;&amp;gt; DMZ are fine&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;mpings are not working between Intranet &amp;lt;&amp;gt; DMZ.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We checked carefully that the firewall is having IP Protocol 97 and UDP 16666 open but even with that in place mpings are still failing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We opened completely the firewall during a couple of minutes same problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We checked the logs and we had the impression that IP Protocol 97 was clearly visible on the logs but not UDP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I verified that WLCs in Intranet and / or DMZ are not using ACLs and it is not the case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A debug mobility keep-alive show the same, IP Protocol 97 is ok but not UDP 16666...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my anchor stays at Control path Down on both ends.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We don't have also ACLs on the switches in between...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running out of ideas here and I would be very glad to have more information how to process further on that...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Update 14.03.2014 : I finally found the solution, it seems that when the network route is defined to widely this could affect the management interfaces during the tunnel mounting. This is not normal and not properly documented, usually network should serve only service port as the default gateway option is not configurable. Cisco will try to add this in the TAC knowledge bade for helping other people facing the same to spare some time in troubleshooting &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;in my case i simply changed the route to be really specific and the tunnel mounted immediately.&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;but thanks all for the suggestions and support provided.&lt;/B&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 07:22:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483500#M78591</guid>
      <dc:creator>holzhirt1</dc:creator>
      <dc:date>2021-07-05T07:22:29Z</dc:date>
    </item>
    <item>
      <title>Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483501#M78592</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Delete the mobility group from both WLC's and add it back on.&amp;nbsp; Sometimes that is the issue especially if the FW is wide open.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt; &lt;BR /&gt;Scott &lt;BR /&gt; &lt;BR /&gt;*****Help out other by using the rating system and marking answered questions as "Answered"*****&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 17:17:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483501#M78592</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2014-03-07T17:17:26Z</dc:date>
    </item>
    <item>
      <title>Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483502#M78593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your fast reply,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We agree that the Default Mobility Domain Name should be different in Intranet WLCs and in DMZ WLCs for security reasons ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is just important to create the anchor by specifying the Domain name configured on the destination controller ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 17:57:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483502#M78593</guid>
      <dc:creator>holzhirt1</dc:creator>
      <dc:date>2014-03-07T17:57:03Z</dc:date>
    </item>
    <item>
      <title>Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483503#M78594</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The mobility domain name should be different... best practice and you should specify the mobility domain name when creating the anchor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt; &lt;BR /&gt;Scott &lt;BR /&gt; &lt;BR /&gt;*****Help out other by using the rating system and marking answered questions as "Answered"*****&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 17:59:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483503#M78594</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2014-03-07T17:59:02Z</dc:date>
    </item>
    <item>
      <title>Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483504#M78595</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok I removed the anchor on both and recreated it, but it is the same &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Control path down&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try also to reboot the WLC's in the DMZ but same problem,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would be something else to check in order to mount up the EoIP tunnel properly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 18:01:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483504#M78595</guid>
      <dc:creator>holzhirt1</dc:creator>
      <dc:date>2014-03-07T18:01:54Z</dc:date>
    </item>
    <item>
      <title>Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483505#M78596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only way to test if the FW is dropping the traffic is to mount the WLC in the inside for testing and create your mobility anchor.&amp;nbsp; If this works, then something is dropping UDP 16666/16667.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Post your show mobility summary from both&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt; &lt;BR /&gt;Scott &lt;BR /&gt; &lt;BR /&gt;*****Help out other by using the rating system and marking answered questions as "Answered"*****&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 18:10:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483505#M78596</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2014-03-07T18:10:39Z</dc:date>
    </item>
    <item>
      <title>Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483506#M78597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok this was my thought maybe &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I realized something else,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the DMZ the WLCs are connected to switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a trunk (2 Vlans configured one for management and one for users traffic) and WLCs are in LAG mode. 4 interfaces on 8 are connected currently.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use a subnet like 172.21.1.xxx for the management interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default GW of the management interface is the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But since a couple of hours the mobility anchor is instead of up / up is Data Path Down,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As the subnet is the same they should not use the default GW between them, why now the Data Path is down...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything special to verify / configure on the switches ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here the output :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ WLC 1 = 172.21.2.6 :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mobility Architecture ........................... Flat&lt;BR /&gt;Mobility Protocol Port........................... 16666&lt;BR /&gt;Default Mobility Domain.......................... DMZ_SG_MOBILITY&lt;BR /&gt;Multicast Mode .................................. Disabled&lt;BR /&gt;Mobility Domain ID for 802.11r................... 0xe8e1&lt;BR /&gt;Mobility Keepalive Interval...................... 10&lt;BR /&gt;Mobility Keepalive Count......................... 3&lt;BR /&gt;Mobility Group Members Configured................ 3&lt;BR /&gt;Mobility Control Message DSCP Value.............. 0&lt;/P&gt;&lt;P&gt;Controllers configured in the Mobility Group&lt;BR /&gt; MAC Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Group Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Multicast IP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status&lt;BR /&gt; 70:81:05:1f:e4:40&amp;nbsp; 10.136.10.36&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SG_MOBILITY&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Control Path Down&lt;BR /&gt; 78:da:6e:8a:ee:20&amp;nbsp; 172.21.2.5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ_SG_MOBILITY&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Data Path Down&lt;BR /&gt; 78:da:6e:8b:14:60&amp;nbsp; 172.21.2.6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ_SG_MOBILITY&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Intranet WLC 1 = 10.136.10.36&amp;nbsp; :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Cisco Controller) &amp;gt;show mobility summary &lt;/P&gt;&lt;P&gt;Mobility Architecture ........................... Flat&lt;BR /&gt;Mobility Protocol Port........................... 16666&lt;BR /&gt;Default Mobility Domain.......................... SG_MOBILITY&lt;BR /&gt;Multicast Mode .................................. Disabled&lt;BR /&gt;Mobility Domain ID for 802.11r................... 0xd9f7&lt;BR /&gt;Mobility Keepalive Interval...................... 10&lt;BR /&gt;Mobility Keepalive Count......................... 3&lt;BR /&gt;Mobility Group Members Configured................ 5&lt;BR /&gt;Mobility Control Message DSCP Value.............. 0&lt;/P&gt;&lt;P&gt;Controllers configured in the Mobility Group&lt;BR /&gt; MAC Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Group Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Multicast IP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status&lt;/P&gt;&lt;P&gt; 70:81:05:1f:e4:40&amp;nbsp; 10.136.10.36&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SG_MOBILITY&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Up&lt;BR /&gt; 78:da:6e:8b:14:60&amp;nbsp; 172.21.2.6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ_SG_MOBILITY&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Control Path Down&lt;BR /&gt; cc:ef:48:0c:85:80&amp;nbsp; 10.136.10.32&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SG_MOBILITY&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Up&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 18:17:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483506#M78597</guid>
      <dc:creator>holzhirt1</dc:creator>
      <dc:date>2014-03-07T18:17:34Z</dc:date>
    </item>
    <item>
      <title>Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483507#M78598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;mping&lt;/STRONG&gt; verify the control path between two WLC. It use the UDP 16666 &amp;amp; in your case it is not working &amp;amp; hence control path is down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;eping&lt;/STRONG&gt; verify the data path between two WLCs &amp;amp; uses EoIP. Since it is working for you no issue with EoIP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls post the output of "&lt;STRONG&gt;show mobility summary&lt;/STRONG&gt;" &amp;amp; "&lt;STRONG&gt;show sysinfo&lt;/STRONG&gt;" of both WLCs to see any config issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Rasika&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**** Pls rate all useful responses ****&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 18:29:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483507#M78598</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2014-03-07T18:29:35Z</dc:date>
    </item>
    <item>
      <title>Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483508#M78599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show mobility summary is posted above, here the show sysinfo :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Intranet WLC 1 10.136.10.36 :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manufacturer's Name.............................. Cisco Systems Inc.&lt;BR /&gt;Product Name..................................... Cisco Controller&lt;BR /&gt;Product Version.................................. 7.4.100.0&lt;BR /&gt;Bootloader Version............................... 1.0.1&lt;BR /&gt;Field Recovery Image Version..................... 6.0.182.0&lt;BR /&gt;Firmware Version................................. FPGA 1.3, Env 1.6, USB console 1.27&lt;BR /&gt;Build Type....................................... DATA + WPS&lt;/P&gt;&lt;P&gt;System Name...................................... xxxxx&lt;/P&gt;&lt;P&gt;System Location.................................. xxxx&lt;/P&gt;&lt;P&gt;System Contact................................... xxxxx&lt;BR /&gt;System ObjectID.................................. 1.3.6.1.4.1.9.1.1069&lt;BR /&gt;Redundancy Mode.................................. Disabled&lt;BR /&gt;IP Address....................................... 10.136.10.36&lt;BR /&gt;Last Reset....................................... Software reset&lt;BR /&gt;System Up Time................................... 369 days 10 hrs 47 mins 44 secs&lt;BR /&gt;System Timezone Location......................... (GMT +1:00) Amsterdam, Berlin, Rome, Vienna&lt;BR /&gt;System Stats Realtime Interval................... 5&lt;BR /&gt;System Stats Normal Interval..................... 180&lt;/P&gt;&lt;P&gt;Configured Country............................... Multiple Countries:AU,BE,CH,CN,DE,FR,GB,HK,IT,J2,MX,NL,RU,SG,TH,TR,US,ZA&lt;/P&gt;&lt;P&gt;--More-- or (q)uit&lt;BR /&gt;Operating Environment............................ Commercial (0 to 40 C)&lt;BR /&gt;Internal Temp Alarm Limits....................... 0 to 65 C&lt;BR /&gt;Internal Temperature............................. +40 C&lt;BR /&gt;External Temperature............................. +20 C&lt;BR /&gt;Fan Status....................................... OK&lt;/P&gt;&lt;P&gt;State of 802.11b Network......................... Enabled&lt;BR /&gt;State of 802.11a Network......................... Enabled&lt;BR /&gt;Number of WLANs.................................. 5&lt;BR /&gt;Number of Active Clients......................... 128&lt;/P&gt;&lt;P&gt;Memory Current Usage............................. Unknown&lt;BR /&gt;Memory Average Usage............................. Unknown&lt;BR /&gt;CPU Current Usage................................ Unknown&lt;BR /&gt;CPU Average Usage................................ Unknown&lt;/P&gt;&lt;P&gt;Burned-in MAC Address............................ 70:81:05:1F:E4:40&lt;BR /&gt;Power Supply 1................................... Present, OK&lt;BR /&gt;Power Supply 2................................... Present, OK&lt;BR /&gt;Maximum number of APs supported.................. 500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ WLC 1 172.21.2.6 :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manufacturer's Name.............................. Cisco Systems Inc.&lt;BR /&gt;Product Name..................................... Cisco Controller&lt;BR /&gt;Product Version.................................. 7.4.110.0&lt;BR /&gt;Bootloader Version............................... 1.0.18&lt;BR /&gt;Field Recovery Image Version..................... 7.6.95.16&lt;BR /&gt;Firmware Version................................. FPGA 1.7, Env 1.8, USB console 2.2&lt;BR /&gt;Build Type....................................... DATA + WPS&lt;/P&gt;&lt;P&gt;System Name...................................... xxxx&lt;/P&gt;&lt;P&gt;System Location.................................. &lt;BR /&gt;System Contact................................... &lt;BR /&gt;System ObjectID.................................. 1.3.6.1.4.1.9.1.1069&lt;BR /&gt;Redundancy Mode.................................. Disabled&lt;BR /&gt;IP Address....................................... 172.21.2.6&lt;BR /&gt;Last Reset....................................... Software reset&lt;BR /&gt;System Up Time................................... 0 days 1 hrs 54 mins 0 secs&lt;BR /&gt;System Timezone Location......................... &lt;BR /&gt;System Stats Realtime Interval................... 5&lt;BR /&gt;System Stats Normal Interval..................... 180&lt;/P&gt;&lt;P&gt;Configured Country............................... CH&amp;nbsp; - Switzerland&lt;BR /&gt;Operating Environment............................ Commercial (0 to 40 C)&lt;/P&gt;&lt;P&gt;--More-- or (q)uit&lt;BR /&gt;Internal Temp Alarm Limits....................... 0 to 65 C&lt;BR /&gt;Internal Temperature............................. +45 C&lt;BR /&gt;External Temperature............................. +33 C&lt;BR /&gt;Fan Status....................................... OK&lt;/P&gt;&lt;P&gt;State of 802.11b Network......................... Disabled&lt;BR /&gt;State of 802.11a Network......................... Disabled&lt;BR /&gt;Number of WLANs.................................. 0&lt;BR /&gt;Number of Active Clients......................... 0&lt;/P&gt;&lt;P&gt;Memory Current Usage............................. Unknown&lt;BR /&gt;Memory Average Usage............................. Unknown&lt;BR /&gt;CPU Current Usage................................ Unknown&lt;BR /&gt;CPU Average Usage................................ Unknown&lt;/P&gt;&lt;P&gt;Burned-in MAC Address............................ 78:DA:6E:8B:14:60&lt;BR /&gt;Power Supply 1................................... Present, OK&lt;BR /&gt;Power Supply 2................................... Present, OK&lt;BR /&gt;Maximum number of APs supported.................. 12&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your support &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 18:34:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483508#M78599</guid>
      <dc:creator>holzhirt1</dc:creator>
      <dc:date>2014-03-07T18:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483509#M78600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the inputs, configs looks ok to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does all these WLCs having same virtual interface IP ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though it may not related, I can see lots of conflicting regulatory domain country codes configured on your DMZ controller ? Does this something you purposely configured ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On a side note the software version (7.4.100.0) you are running on intranet WLCs are too buggy &amp;amp; recommend you to upgrade them to 7.4.121.0.&amp;nbsp; Upgrade FUS to 1.9.0.0 as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Rasika&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 18:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483509#M78600</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2014-03-07T18:48:17Z</dc:date>
    </item>
    <item>
      <title>Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483510#M78601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In fact they were having the same virtual IP but I changed it, I just reverted back for all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Intranet WLCs is serving several countries, so yes it is on purpose that we have several regulatory domains &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the tip about the version, how do you upgrade FUS by the way ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 18:58:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483510#M78601</guid>
      <dc:creator>holzhirt1</dc:creator>
      <dc:date>2014-03-07T18:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483511#M78602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Holzhirt1,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PFB link for FUS upgrade.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Expect a downtime of 30-40 mins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/fus_rn_OL-31390-01.pdf" rel="nofollow"&gt;http://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/fus_rn_OL-31390-01.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ashish.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 19:11:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483511#M78602</guid>
      <dc:creator>Ashish Chandra</dc:creator>
      <dc:date>2014-03-07T19:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483512#M78603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;In fact they were having the same virtual IP but I changed it, I just reverted back for all.&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;Is there any difference made by that ? &lt;SPAN style="font-size: 10pt;"&gt;You should have same virtual IP address in order to mobility to work properly. So make sure it is same everywhere.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Intranet WLCs is serving several countries, so yes it is on purpose that we have several regulatory domains &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is not ideal configuring conflicting regulatory domain country codes in single WLC (could impact channels, power levels for certain APs, sometime certain AP radio band won't come up). Best would be having unique controller to serve same regulatory domain country code APs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Thanks for the tip about the version, how do you upgrade FUS by the way ?&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the link to FUS 1.9.0.0 upgrade. Keep note that this will take 30-40min of downtime to your wireless &amp;amp; get a sufficient outage window to do this.&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/fus_rn_OL-31390-01.html" rel="nofollow"&gt;http://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/fus_rn_OL-31390-01.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the below thread I have posted CLI commands for this upgrade with respect to 2504. You can follow that with required image downloads for 5508&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/thread/2270290" rel="nofollow"&gt;https://supportforums.cisco.com/thread/2270290&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Rasika&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**** Pls rate all useful responses ****&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 19:12:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483512#M78603</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2014-03-07T19:12:10Z</dc:date>
    </item>
    <item>
      <title>Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483513#M78604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Now I have same virtual IPs on all but it is the same,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mpings are not going thru....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will try again to remove mobility groups and re-create it...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the links Rasika&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 19:25:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483513#M78604</guid>
      <dc:creator>holzhirt1</dc:creator>
      <dc:date>2014-03-07T19:25:03Z</dc:date>
    </item>
    <item>
      <title>Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483514#M78605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If that still doesn't work, move the one to the inside and reconfigure the management for testing.&amp;nbsp; Make sure that it works..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You also have two DMZ SLC's, so put them in the same mobility group to test and see if both the control and data comes up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt; &lt;BR /&gt;Scott &lt;BR /&gt; &lt;BR /&gt;*****Help out other by using the rating system and marking answered questions as "Answered"*****&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 19:28:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483514#M78605</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2014-03-07T19:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483515#M78606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By having a different mobility name saves on mobility exchanges meaning less packets .. Imagine all your controllers have the same name .. Your anchor would get mobility messages from all your anchors which isn't needed.&lt;BR /&gt;&lt;BR /&gt;I would sniff the fw interface and the interface outside the WLC interface .. Do you see the control packet ..&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 19:33:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483515#M78606</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2014-03-07T19:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483516#M78607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;did you checked the logs on the firewall , why it's dropping the mpings ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 22:11:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483516#M78607</guid>
      <dc:creator>Ali Aqrabawi</dc:creator>
      <dc:date>2014-03-07T22:11:45Z</dc:date>
    </item>
    <item>
      <title>Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483517#M78608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First of all thanks all for your tips and contributions, really appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dear Ali odd enough only Ethernet IP 97 are coming into the FW, no UDP 16666 visible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I realized something else,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the DMZ the WLCs are connected to switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a trunk (2 Vlans configured one for management and one for users traffic) and WLCs are in LAG mode. 4 interfaces on 8 are connected currently.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use a subnet like 172.21.1.xxx for the management interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default GW of the management interface is the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But since a couple of hours the mobility anchor between DMZ WLCs is instead of up / up is Data Path Down,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Epings are not passing thru....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As the subnet is the same they should not use the default GW between them, why now the Data Path is down...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything special to verify / configure on the switches ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As we will have at least 2 Vlans we need to have trunk on the switches, I have no native Vlan configured and pings between DMZ WLCs are working...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Mar 2014 09:37:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483517#M78608</guid>
      <dc:creator>holzhirt1</dc:creator>
      <dc:date>2014-03-08T09:37:29Z</dc:date>
    </item>
    <item>
      <title>Control path down - between Intranet &lt;&gt; DMZ</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483518#M78609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;one thing to check on the switchport , the portchannel load-balance should be src-dst-ip,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Mar 2014 11:17:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483518#M78609</guid>
      <dc:creator>Ali Aqrabawi</dc:creator>
      <dc:date>2014-03-08T11:17:56Z</dc:date>
    </item>
    <item>
      <title>I changed the management IPs</title>
      <link>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483519#M78610</link>
      <description>&lt;P&gt;I changed the management IPs on the DMZ WLCs and reacreated the anchor&amp;nbsp;strangely I was able to mount the tunnel immediately, before it was not passing thru for epings (Data Path Down), now it is up / up. Even if in my opinion it was not passing thru a FW.&lt;/P&gt;&lt;P&gt;However the link with the Intranet is still showing the same issue "Control Path Down".&lt;/P&gt;&lt;P&gt;I will have a look again with my colleague about the Firewall and if we can see at least UDP 16666 packets coming from one end or the other.&lt;/P&gt;&lt;P&gt;If this is not leading to something, I will follow the recommendation to mount it internall and see how the tunnel is reacting...&lt;/P&gt;&lt;P&gt;I keep you posted,&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2014 15:46:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/control-path-down-between-intranet-lt-gt-dmz/m-p/2483519#M78610</guid>
      <dc:creator>holzhirt1</dc:creator>
      <dc:date>2014-03-10T15:46:30Z</dc:date>
    </item>
  </channel>
</rss>

