Introduction
Access Points (AP's) not registering with 5508 controller running Latest 7.2.103.0 Version/code.
Scenario
3602i AP's are not getting register with 5508 controller which is running 7.2.103.0 code.
Error on WLC
We keep seeing an error in the log on the WLC "AAA Authentication Failure for UserName:c4xxxc08xx2 User Type: WLAN USER"
Error on Access Point
*Mar 7 15:20:40.503: %CAPWAP-5-SENDJOIN: sending Join Request to 1x.3y.247.4x
*Mar 7 15:20:40.515: %DTLS-5-ALERT: Received WARNING : Close notify alert from 1x.3y.247.4x
*Mar 7 15:20:40.515: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 1x.3y.247.4x:5246
*Mar 7 15:20:40.515: %CAPWAP-3-ERRORLOG: Go join a capwap controller
*Mar 7 15:20:40.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_i p: 1x.3y.247.4x peer_port: 5246
*Mar 7 15:20:40.487: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio 0, changed state to down
*Mar 7 15:20:40.507: %CAPWAP-5-DTLSREQSUCC: DTLS connection created successfully peer_ip: 1x.3y.247.4x peer_port: 5246
*Mar 7 15:20:40.507: %CAPWAP-5-SENDJOIN: sending Join Request to 1x.3y.247.4x
*Mar 7 15:20:40.687: status of voice_diag_test from WLC is false
Also we have entered the CAPWAP ap controller ip address directly into the AP so it shouldn't be an option 43 DHCP issue.
Solution
We have experienced same issue while adding some 1142's and found that they had a mesh configure on them out of the box for some odd reason. Take a look at your AP, sh flash: and check. 3602i AP's were delivered in MESH mode so with the advice of Cisco TAC we added the AP's to the MAC filtering table under security. Once the AP's registered we were able to change them to LOCAL mode and they came up as normal.
Reference
This document was generated from the following discussion: Air 3602i not registering with 5508 controller