11-04-2023 11:53 AM
Found AIR-LAP1141N-A-K9 with a green LED but can not connect to the wirelessly to the AP. Since I did not know the username/password, I reset the AP. Find DHCP is working and an ip address is assigned. Not able to connect using a GUI and get connection refused. Getting the following errors:
*Nov 4 02:53:32.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.1.232 peer_port: 5246
*Nov 4 02:53:33.421: %DTLS-5-ALERT: Received FATAL : Certificate unknown alert from 192.168.1.232
*Nov 4 02:53:33.421: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 192.168.1.232:5246
192.168.1.232 is a 25
Solved! Go to Solution.
11-05-2023 07:57 PM
Roll back the date to, say, 2015 and reboot the AP. See if this works.
11-04-2023 03:58 PM
@techcoora wrote:
*Nov 4 02:53:33.421: %DTLS-5-ALERT: Received FATAL : Certificate unknown alert from 192.168.1.232
Is there a WLC in the network?
The error message means that a certificate in the AP has expired.
11-05-2023 10:23 AM
I see the WLC part number was cut off. AIR-CT2504-K9 is the full part number. The ip address is 192.168.1.232 that the AP was talking to.
What do I do with the AP certificate is expired?
11-05-2023 02:39 PM
On the WLC, post the complete output to the command "sh sysinfo".
11-05-2023 07:13 PM
(Cisco Controller) >show sysinfo
Manufacturer's Name.............................. Cisco Systems Inc.
Product Name..................................... Cisco Controller
Product Version.................................. 8.3.150.0
Bootloader Version............................... 1.0.20
Field Recovery Image Version..................... 7.6.101.1
Firmware Version................................. PIC 20.0
OUI File Update Time............................. Sun Sep 07 10:44:07 IST 2014
Build Type....................................... DATA + WPS
System Name...................................... AIRCL2504#2
System Location..................................
System Contact...................................
System ObjectID.................................. 1.3.6.1.4.1.9.1.1279
IP Address....................................... 192.168.1.232
IPv6 Address..................................... ::
Last Reset....................................... Power on reset
System Up Time................................... 85 days 4 hrs 59 mins 47 secs
System Timezone Location......................... (GMT -8:00) Pacific Time (US and Canada)
--More-- or (q)uit
System Stats Realtime Interval................... 5
System Stats Normal Interval..................... 180
Configured Country............................... US - United States
Operating Environment............................ Commercial (0 to 40 C)
Internal Temp Alarm Limits....................... 0 to 65 C
Internal Temperature............................. +33 C
External Temperature............................. +35 C
Fan Status....................................... 3500 rpm
State of 802.11b Network......................... Enabled
State of 802.11a Network......................... Enabled
Number of WLANs.................................. 1
Number of Active Clients......................... 1
OUI Classification Failure Count................. 1131
Burned-in MAC Address............................ F8:A5:C5:85:84:80
Maximum number of APs supported.................. 75
System Nas-Id....................................
WLC MIC Certificate Types........................ SHA1/SHA2
(Cisco Controller) >
11-05-2023 07:57 PM
Roll back the date to, say, 2015 and reboot the AP. See if this works.
11-06-2023 08:00 AM
11-06-2023 11:27 AM
Since the complaint was the certificate is dated later in time, I changed the WLC year to 2017, That changed allowed the AP to come online and I could connect a laptop. That is the solution for certificate. There was a second problem in when I try to use the GUI, the result is connection is refused. Did you want me to move that question to a new post?
11-06-2023 01:27 PM
Looks like I can not use web. 1141 is not CAP but is lightweight LAP.
Scott Fella Hall of Fame
Console into the ap and issue a show version or let us know the model number of the AP. if the model starts with a AIR-CAP then it's a lightweight and you can't web into those.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide