02-28-2023 03:56 AM
We're having issues with telemetry between our DNAC appliance and our two HA pairs of 9800 WLCs. In the past where telemetry has started acting up (resulting in all APs showing as "down" on heatmaps despite being "reachable" on the AP list, and "No Health" against each controller) a forced push of the telemetry settings has fixed things, but not this time.
Drilling down into the configuration task failure notification reveals the following error:-
Failing over the HA pair makes no difference.
Rebooting DNA Center makes no difference.
DNAC Version 2.3.3.6-70045
WLC IOS-XE version 17.3.6
Does anyone else have any suggestions to try, or should we TAC it?
Solved! Go to Solution.
07-10-2023 05:12 AM - edited 07-10-2023 05:13 AM
I forgot about this query. All fixed through TAC as the engineer had come across it before. Problem was down to DNAC's new system certificate being 8K. DNAC's happy with those, but 9800 controllers aren't. Replacing this with a 4K certificate fixed it all.
07-10-2023 02:44 AM
Same issue here. Same DNAC version except controller is running on 17.9.3
07-10-2023 03:01 AM
Hi @Martin Pritchard what I did was updated the Telemetry settings in DNAC then reprovision and it worked. Make sure the telemetry update is successful before you reprovision
07-10-2023 05:12 AM - edited 07-10-2023 05:13 AM
I forgot about this query. All fixed through TAC as the engineer had come across it before. Problem was down to DNAC's new system certificate being 8K. DNAC's happy with those, but 9800 controllers aren't. Replacing this with a 4K certificate fixed it all.
07-10-2023 05:33 AM
Do you have procedure on replacing the 4k certificate ?
07-10-2023 08:00 AM - edited 07-10-2023 08:02 AM
The certificate was generated by us, and as it can be a bit fiddly to get all the tickboxes right I opened a copy of the 8K certificate up in SSL Shopper's CSR Decoder to get all the details in the right place when requesting the 4K one to replace it.
Location in DNAC: System -> Settings -> Trust & Privacy -> System Certificates
Some key takeaways:-
Obviously replace ourdomain, etc. with your actual domain details. The above settings worked for us.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide