cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1205
Views
0
Helpful
5
Replies

AP Not Joining request Failed

Hi guys.

AP 1562E-not joining vWlc. I have attached the logs.

Kindly suggest.

dtls_verify_con_cert: vWLC Certificate verification error
dtls_process_packet: Controller certificate verification failed
sendPacketToDtls: DTLS: Closing connection 0x2147c00.
Lost connection to the controller, going to restart CAPWAP (reason : dtls_rc_connection_closed)...
DTLS: Error while processing DTLS packet 0x21b1000.
Restarting CAPWAP State Machine.
Discarding msg CAPWAP_WTP_EVENT_REQUEST(type 9) in CAPWAP state: DTLS Setup(3).
Failed to disconnect DTLS-CTRL session.

CAPWAP State: DTLS Teardown
No more AP manager addresses remain..
No valid AP manager found for controller 'cisco-vWLC' (ip: 172.168.81.218)
Failed to join controller cisco-vWLC.
Failed to join controller.

CAPWAP State: Discovery
Discovery Request sent to 172.168.81.xxx, discovery type STATIC_CONFIG(1)
Discovery Request sent to 172.168.81.xxx, discovery type STATIC_CONFIG(1)
Discovery Request sent to 255.255.255.255, discovery type UNKNOWN(0)
Discovery Response from 172.168.81.xxx
Unsupported vendor spec payload TLV_VENDOR_SPECIFIC_PAYLOAD(215) for msgtype 2
Discovery Response from 172.168.81.xxx
Unsupported vendor spec payload TLV_VENDOR_SPECIFIC_PAYLOAD(215) for msgtype 2

 

5 Replies 5

balaji.bandi
Hall of Fame
Hall of Fame

what is the version vWLC ? do you have any other AP joined or are none of them working?

Do you have enough License?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi,

Vwlc version is -8.10.181.

No other AP has joined

It's showing 200 AP supported 

 

 

KyoCode
Level 1
Level 1

Hi,

check this one out https://community.cisco.com/t5/wireless-mobility-knowledge-base/lightweight-ap-fail-to-create-capwap-lwapp-connection-due-to/ta-p/3155111

If AP is fairly new, you can try checking a few things:

 1. Version might be better to be at the same number.

2. Config WLC to accept those new certificates not yet installed in the WLC (which is tearing down the TLS):

For 7.0.252.0:
(WLC)>config ap lifetime-check {mic|ssc} enable

For 7.4.140.0 and later:
(WLC)>config ap cert-expiry-ignore {mic|ssc} enable

3. NTP might be an issue, try checking the clock in the AP which should be close to the WLC one, if not, apply a NTP field in the DHCP for the AP so it can be up to date and connect to the WLC.

hope that helps,

AIV

Leo Laohoo
Hall of Fame
Hall of Fame

Post the complete output to the following commands: 

  1. WLC:  sh sysinfo
  2. WLC:  sh time
  3. AP:  sh capwap client rcb
  4. AP:  sh version


 wrote:@Rohatash Singh
AP Image type : MOBILITY EXPRESS IMAGE

The 1562 is loaded with Mobility Express firmware.