cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
144355
Views
100
Helpful
20
Replies

AP can't join. DTLS connection closed by controller

Saman Shamim
Level 1
Level 1

Hi guys,

1140 APs don't register with the 5508 controller. Here are some debug outputs:

AP's IP: 100.31

WLC's IP:100.2

debug capwap events enable

*spamApTask1: Nov 01 11:25:04.958: 30:e4:db:d3:a4:ca Discovery Request from 192.168.100.31:47690

*spamApTask1: Nov 01 11:25:04.958: 30:e4:db:d3:a4:ca Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 100, joined Aps =0

*spamApTask1: Nov 01 11:25:04.958: 30:e4:db:d3:a4:ca Discovery Response sent to 192.168.100.31:47690

*spamApTask1: Nov 01 11:25:04.958: 30:e4:db:d3:a4:ca Discovery Response sent to 192.168.100.31:47690

*spamApTask1: Nov 01 11:25:14.959: 30:e4:db:d3:a4:ca DTLS connection not found, creating new connection for 192:168:100:31 (47690) 192:168:100:2 (5246)

*spamApTask1: Nov 01 11:25:15.101: 30:e4:db:d3:a4:ca DTLS connection closed event receivedserver (192:168:100:2/5246) client (192:168:100:31/47690)

*spamApTask1: Nov 01 11:25:15.101: 30:e4:db:d3:a4:ca No entry exists for AP (192:168:100:31/47690)

*spamApTask1: Nov 01 11:25:15.101: 30:e4:db:d3:a4:ca No AP entry exist in temporary database for 192.168.100.31:47690

**************************************************************

debug capwap packet enable

>*spamApTask1: Nov 01 11:36:20.039: <<<<  Start of CAPWAP Packet  >>>>

*spamApTask1: Nov 01 11:36:20.039: CAPWAP Control mesg Recd from 192.168.100.31, Port 47690

*spamApTask1: Nov 01 11:36:20.039:              HLEN 4,   Radio ID 0,    WBID 1

*spamApTask1: Nov 01 11:36:20.039:              Msg Type   :   CAPWAP_DISCOVERY_REQUEST

*spamApTask1: Nov 01 11:36:20.039:              Msg Length : 73

*spamApTask1: Nov 01 11:36:20.039:              Msg SeqNum : 0

*spamApTask1: Nov 01 11:36:20.039:

*spamApTask1: Nov 01 11:36:20.039:       Type : CAPWAP_MSGELE_DISCOVERY_TYPE, Length 1

*spamApTask1: Nov 01 11:36:20.039:              Discovery Type : CAPWAP_DISCOVERY_TYPE_UNKNOWN

*spamApTask1: Nov 01 11:36:20.039:

*spamApTask1: Nov 01 11:36:20.039:       Type : CAPWAP_MSGELE_WTP_DESCRIPTOR, Length 40

*spamApTask1: Nov 01 11:36:20.039:              Maximum Radios Supported  : 0

*spamApTask1: Nov 01 11:36:20.039:              Radios in Use             : 0

*spamApTask1: Nov 01 11:36:20.039:              Encryption Capabilities   : 0x00 0x01

*spamApTask1: Nov 01 11:36:20.039:

*spamApTask1: Nov 01 11:36:20.039:       Type : CAPWAP_MSGELE_WTP_FRAME_TUNNEL, Length 1

*spamApTask1: Nov 01 11:36:20.039:              WTP Frame Tunnel Mode : NATIVE_FRAME_TUNNEL_MODE

*spamApTask1: Nov 01 11:36:20.039:

*spamApTask1: Nov 01 11:36:20.039:       Type : CAPWAP_MSGELE_WTP_MAC_TYPE, Length 1

*spamApTask1: Nov 01 11:36:20.039:              WTP Mac Type  : SPLIT_MAC

*spamApTask1: Nov 01 11:36:20.039:

*spamApTask1: Nov 01 11:36:20.039:       Type : CAPWAP_MSGELE_VENDOR_SPECIFIC_PAYLOAD, Length 10

*spamApTask1: Nov 01 11:36:20.039:              Vendor Identifier  : 0x00409600

*spamApTask1: Nov 01 11:36:20.039:

        IE            :   UNKNOWN IE 207

*spamApTask1: Nov 01 11:36:20.039:      IE Length     :   4

*spamApTask1: Nov 01 11:36:20.039:      Decode routine not available, Printing Hex Dump

*spamApTask1: Nov 01 11:36:20.039: 00000000: 01 00 00 01                                       ....

*spamApTask1: Nov 01 11:36:20.039: <<<<  End of CAPWAP Packet  >>>>

**************************************************************

debug capwap errors enable

*spamApTask1: Nov 01 11:45:15.244: 30:e4:db:d3:a4:ca Deleting AP 192.168.100.31 which has not been plumbed

*spamApTask1: Nov 01 11:45:15.245: 30:e4:db:d3:a4:ca DTLS connection was closed

**************************************************************

debug capwap detail enable

*spamApTask1: Nov 01 11:52:45.298: 30:e4:db:d3:a4:ca CAPWAP Control Msg Received from 192.168.100.31:47690

*spamApTask1: Nov 01 11:52:45.298: 30:e4:db:d3:a4:ca DTLS connection 0x1454bc38 closed by controller

*spamApTask1: Nov 01 11:52:45.299: CAPWAP DTLS connection closed msg

20 Replies 20

Hi Scott, thanks for your help i had the same problem it fixed.

Like most have said the issue was with the time, the ap can only sync with the controller if the date,time and country configured is the same on both ends.

Im moving from controller A to Controller B with the same version of software and any of the APs join to my new controller. Im getting the same debug outputs than this original POST.
I have to clear the prive config too?

El problema del post Original es que tiene incorrecta la fecha del WLC. En tu caso la fecha es correcta? tu nuevo WLC esta en el mismo segmento de red que el original?

Espero que la información haya sido útil y si no tienes más preguntas recuerda cerrar el topic, seleccionando la respuesta como "Respuesta correcta"
**Please rate the answer if this information was useful***
**Por favor si la información fue util marca esta respuesta como correcta**

Amit Singh
Cisco Employee
Cisco Employee

DTLS connection may fail due to expired license, check "show license all" and if you find license expired, go to Management-- software activation-- License and add new license.

 

Hi Cisco Team,

 

We have almost the same issue but it happens when we fail over the link from ISP 1 to ISP 2. The AP cannot join to WLC but from WLC side I can ping the access point. Please help us guys. Thanks

Review Cisco Networking products for a $25 gift card