cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
768
Views
0
Helpful
8
Replies

Trying to connect AIR-LAP1141N-A-K9

techcoora
Level 1
Level 1

Found  AIR-LAP1141N-A-K9 with a green LED but can not connect to the wirelessly to the AP. Since I did not know the username/password, I reset the AP. Find DHCP is working and an ip address is assigned. Not able to connect using a GUI and get connection refused. Getting the following errors: 

*Nov  4 02:53:32.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.1.232 peer_port: 5246

*Nov  4 02:53:33.421: %DTLS-5-ALERT: Received FATAL : Certificate unknown alert from 192.168.1.232

*Nov  4 02:53:33.421: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 192.168.1.232:5246

192.168.1.232 is a 25

1 Accepted Solution

Accepted Solutions

Roll back the date to, say, 2015 and reboot the AP.  See if this works.

View solution in original post

8 Replies 8

Leo Laohoo
Hall of Fame
Hall of Fame

@techcoora wrote:
*Nov  4 02:53:33.421: %DTLS-5-ALERT: Received FATAL : Certificate unknown alert from 192.168.1.232

Is there a WLC in the network? 

The error message means that a certificate in the AP has expired.  

I see the WLC part number was cut off. AIR-CT2504-K9 is the full part number.  The ip address is 192.168.1.232 that the AP was talking to. 

What do I do with the AP certificate is expired?  

On the WLC, post the complete output to the command "sh sysinfo". 

(Cisco Controller) >show sysinfo

Manufacturer's Name.............................. Cisco Systems Inc.
Product Name..................................... Cisco Controller
Product Version.................................. 8.3.150.0
Bootloader Version............................... 1.0.20
Field Recovery Image Version..................... 7.6.101.1
Firmware Version................................. PIC 20.0


OUI File Update Time............................. Sun Sep 07 10:44:07 IST 2014

Build Type....................................... DATA + WPS

System Name...................................... AIRCL2504#2
System Location..................................
System Contact...................................
System ObjectID.................................. 1.3.6.1.4.1.9.1.1279
IP Address....................................... 192.168.1.232
IPv6 Address..................................... ::
Last Reset....................................... Power on reset
System Up Time................................... 85 days 4 hrs 59 mins 47 secs
System Timezone Location......................... (GMT -8:00) Pacific Time (US and Canada)

--More-- or (q)uit
System Stats Realtime Interval................... 5
System Stats Normal Interval..................... 180

Configured Country............................... US - United States
Operating Environment............................ Commercial (0 to 40 C)
Internal Temp Alarm Limits....................... 0 to 65 C
Internal Temperature............................. +33 C
External Temperature............................. +35 C
Fan Status....................................... 3500 rpm

State of 802.11b Network......................... Enabled
State of 802.11a Network......................... Enabled
Number of WLANs.................................. 1
Number of Active Clients......................... 1

OUI Classification Failure Count................. 1131

Burned-in MAC Address............................ F8:A5:C5:85:84:80
Maximum number of APs supported.................. 75
System Nas-Id....................................
WLC MIC Certificate Types........................ SHA1/SHA2

(Cisco Controller) >

Roll back the date to, say, 2015 and reboot the AP.  See if this works.

techcoora_0-1699285895188.png

techcoora_1-1699286370999.png

 

Since the complaint was the certificate is dated later in time, I changed the WLC year to 2017, That changed allowed the AP to come online and I could connect a laptop. That is the solution for certificate. There was a second problem in when I try to use the GUI, the result is connection is refused. Did you want me to move that question to a new post?

techcoora
Level 1
Level 1

Looks like I can not use web.  1141 is not CAP but is lightweight LAP.

 

Scott Fella Hall of Fame

Console into the ap and issue a show version or let us know the model number of the AP. if the model starts with a AIR-CAP then it's a lightweight and you can't web into those.

Review Cisco Networking for a $25 gift card