<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Flexconnect over IPSEC in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391796#M95809</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you looked at this post?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/message/4137649#4137649"&gt;https://supportforums.cisco.com/message/4137649#4137649&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt; &lt;BR /&gt;Scott &lt;BR /&gt; &lt;BR /&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Jan 2014 17:23:38 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2014-01-29T17:23:38Z</dc:date>
    <item>
      <title>Flexconnect over IPSEC</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391795#M95808</link>
      <description>&lt;P&gt;I have a deployment of 1602 AP's in flexconnect mode connected to a controller over IPSEC. I am assigning the controller address to the AP's via DHCP option 43 and this works without an issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I set a static IP on one of the AP's and use DNS method to assign controller address, the association never happens.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From AP:&lt;/P&gt;&lt;P&gt;*Jan 29 17:02:36.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip:x.x.x.x peer_port: 5246&lt;/P&gt;&lt;P&gt;*Jan 29 17:03:35.999: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to x.x.x.x:5246&lt;/P&gt;&lt;P&gt;*Jan 29 17:03:46.055: %CAPWAP-3-ERRORLOG: Go join a capwap controller&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From Controller:&lt;/P&gt;&lt;P&gt;*spamApTask0: Jan 29 12:13:02.633: xx:xx:xx:xx:xx:xx Discovery Response sent to y.y.y.y:62551&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I remove IPSEC and go straight layer 3, the AP associates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I saw some posts about MTU issues in older versions, but I was under the impression they were resolved in newer versions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone had the same issue or does anyone have any tips?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 07:03:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391795#M95808</guid>
      <dc:creator>Daniel Graham</dc:creator>
      <dc:date>2021-07-05T07:03:59Z</dc:date>
    </item>
    <item>
      <title>Flexconnect over IPSEC</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391796#M95809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you looked at this post?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/message/4137649#4137649"&gt;https://supportforums.cisco.com/message/4137649#4137649&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt; &lt;BR /&gt;Scott &lt;BR /&gt; &lt;BR /&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 17:23:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391796#M95809</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2014-01-29T17:23:38Z</dc:date>
    </item>
    <item>
      <title>Flexconnect over IPSEC</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391797#M95810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I didn't read that post, I'm not having an issue with client connections, just ap to controller communication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am going all local switching, so I'd rather not affect the client mtu size.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 17:55:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391797#M95810</guid>
      <dc:creator>Daniel Graham</dc:creator>
      <dc:date>2014-01-29T17:55:22Z</dc:date>
    </item>
    <item>
      <title>Flexconnect over IPSEC</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391798#M95811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;* I am doing local switching.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 17:57:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391798#M95811</guid>
      <dc:creator>Daniel Graham</dc:creator>
      <dc:date>2014-01-29T17:57:09Z</dc:date>
    </item>
    <item>
      <title>Flexconnect over IPSEC</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391799#M95812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only thing that I can think of is if IPSEC is breaking the CAPWAP UPD 5246 &amp;amp; 5247.&amp;nbsp; Since when you remove the IPSEC and the AP joins, then something over the IPSEC is preventing the the join.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt; &lt;BR /&gt;Scott &lt;BR /&gt; &lt;BR /&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 18:23:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391799#M95812</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2014-01-29T18:23:30Z</dc:date>
    </item>
    <item>
      <title>Flexconnect over IPSEC</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391800#M95813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just thought it was odd that if the AP gets its IP from DHCP it works but when set static and using DNS to resolve controller address it doesnt work. I am going to change my topology to use layer3 without IPSEC tunnel, but idealy I would continue using IPSEC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 20:19:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391800#M95813</guid>
      <dc:creator>Daniel Graham</dc:creator>
      <dc:date>2014-01-29T20:19:27Z</dc:date>
    </item>
    <item>
      <title>Flexconnect over IPSEC</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391801#M95814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Once the AP knows of the WLC, it doesn't need option 43 anymore nor DNS, it will keep and know of the last WLC it joined.&amp;nbsp; This is the thing.... if the AP already has joined the WLC and when you enable IPSEC and the AP then can't join the WLC, there is an issue with UDP 5246 and UDP 5247 as these are the ports that the WLC and AP uses for the join.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt; &lt;BR /&gt;Scott &lt;BR /&gt; &lt;BR /&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 20:22:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391801#M95814</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2014-01-29T20:22:26Z</dc:date>
    </item>
    <item>
      <title>Flexconnect over IPSEC</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391802#M95815</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I see. Thanks for the additional clarification. I will invetigate further and see what I can figure out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 20:34:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391802#M95815</guid>
      <dc:creator>Daniel Graham</dc:creator>
      <dc:date>2014-01-29T20:34:20Z</dc:date>
    </item>
    <item>
      <title>Flexconnect over IPSEC</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391803#M95816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From what you have tested, makes it seem like those ports are being blocked.&amp;nbsp; The good part is that they have joined on the same site with a layer 3 connections, so that rules out a lot of other testing:)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt; &lt;BR /&gt;Scott &lt;BR /&gt; &lt;BR /&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 20:37:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-over-ipsec/m-p/2391803#M95816</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2014-01-29T20:37:23Z</dc:date>
    </item>
  </channel>
</rss>

