cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1427
Views
10
Helpful
15
Replies

2802i Failing to Join 9800-CL

scottbreslin
Level 1
Level 1

Hi,

I have a 2802i that will not sustain a connection to a 9800-CL.   The WLC is running version 17.03.04 software release.  The AP join the WLC and broadcasts SSID for a few seconds  but then drops the connection.

I have trustpoint configured on WLC:

WLC#show wireless management trustpoint
Trustpoint Name : WLC_WLC_TP
Certificate Info : Available
Certificate Type : SSC
Certificate Hash : 5e470c136e2b1ecd0fee05dac60f057742ba12f0
Private key Info : Available
FIPS suitability : Not Applicable

Output from AP:

[*10/06/2022 12:19:39.0788] Discovery Response from 192.168.1.201
[*10/06/2022 12:19:39.0792] Discovery Response from 192.168.1.201
[*10/06/2022 12:19:48.0003]
[*10/06/2022 12:19:48.0003] CAPWAP State: DTLS Setup
[*10/06/2022 12:19:48.8927] First connect to vWLC, accept vWLC by default
[*10/06/2022 12:19:48.8927]
[*10/06/2022 12:19:48.9447]
[*10/06/2022 12:19:48.9447] CAPWAP State: Join
[*10/06/2022 12:19:48.9479] Sending Join request to 192.168.1.201 through port 5264
[*10/06/2022 12:19:49.0494] Join Response from 192.168.1.201
[*10/06/2022 12:19:49.0494] AC accepted join request with result code: 0
[*10/06/2022 12:19:49.0730] Received wlcType 0, timer 30
[*10/06/2022 12:19:49.2144]
[*10/06/2022 12:19:49.2144] CAPWAP State: Image Data
[*10/06/2022 12:19:49.2148] AP image version 17.3.5.43 backup 17.6.4.56, Controller 17.3.5.43
[*10/06/2022 12:19:49.2148] Version is the same, do not need update.
[*10/06/2022 12:19:49.2434] upgrade.sh: Script called with args:[NO_UPGRADE]
[*10/06/2022 12:19:49.3012] do NO_UPGRADE, part2 is active part
[*10/06/2022 12:19:49.3079]
[*10/06/2022 12:19:49.3079] CAPWAP State: Configure
[*10/06/2022 12:19:50.4192] DOT11_CFG[1]: Starting radio 1
[*10/06/2022 12:19:51.1120] DOT11_DRV[1]: Started Radio 1
[*10/06/2022 12:19:51.1126] DOT11_CFG[0]: Starting radio 0
[*10/06/2022 12:19:51.7759] DOT11_DRV[0]: Started Radio 0
[*10/06/2022 12:19:52.0913] Null cert id for TLV_AP_CACERTS_CONFIG_PAYLOAD
[*10/06/2022 12:19:52.2590]
[*10/06/2022 12:19:52.2590] CAPWAP State: Run
[*10/06/2022 12:19:52.2887] AP has joined controller
[*10/06/2022 12:19:53.8342] Previous AP mode is 0, change to 0
[*10/06/2022 12:19:54.0608] chpasswd: password for user changed
[*10/06/2022 12:19:54.2214]
[*10/06/2022 12:19:54.2214] Same LSC mode, no action needed
[*10/06/2022 12:19:54.2215] TLV ID 2584 not found
[*10/06/2022 12:19:54.2215] TLV-DEC-ERR-1: No proc for 2584
[*10/06/2022 12:19:54.8366] TLV ID 1356 not found
[*10/06/2022 12:19:54.8366] TLV-DEC-ERR-1: No proc for 1356
[*10/06/2022 12:19:55.7979] Got WSA Server config TLVs
[*10/06/2022 12:19:56.6013] AP tag change to Lab_TAG
[*10/06/2022 12:19:56.6816] flags value is 1
[*10/06/2022 12:19:57.1770] Powering down BLE radio
[*10/06/2022 12:20:19.9320] set cleanair [slot0][band0] enabled
[*10/06/2022 12:20:19.9736] set cleanair [slot0][band1] enabled
[*10/06/2022 12:20:19.9969] set cleanair [slot1][band1] enabled
[*10/06/2022 12:21:43.2191] FOUND CONFIGURED WLC (Primary) REDISCOVER TO CONNECT WITH THAT.
[*10/06/2022 12:21:43.2926]
[*10/06/2022 12:21:43.2926] CAPWAP State: DTLS Teardown
[*10/06/2022 12:21:43.3625] DOT11_DRV[0]: Stopped Radio 0
[*10/06/2022 12:21:43.3824] DOT11_DRV[1]: Stopped Radio 1
[*10/06/2022 12:21:44.4663] upgrade.sh: Script called with args:[ABORT]
[*10/06/2022 12:21:44.5233] do ABORT, part2 is active part
[*10/06/2022 12:21:44.5387] upgrade.sh: Cleanup tmp files ...
[*10/06/2022 12:21:44.5728] Dropping dtls packet since session is not established. Peer 192.168.1.201-5246, Local 192.168.1.207-5264, conn (nil)
[*10/06/2022 12:21:44.5730] Discarding msg CAPWAP_WTP_EVENT_REQUEST(type 9) in CAPWAP state: DTLS Teardown(4).
[*10/06/2022 12:21:44.5730] Discarding msg CAPWAP_WTP_EVENT_REQUEST(type 9) in CAPWAP state: DTLS Teardown(4).

Can someone please advise?

Thanks

15 Replies 15

Haydn Andrews
VIP Alumni
VIP Alumni

Do other APs join the WLC?

*****Help out other by using the rating system and marking answered questions as "Answered"*****
*** Please rate helpful posts ***

I only have this AP to hand, as its part of a Lab setup

Leo Laohoo
Hall of Fame
Hall of Fame

"sh run | include wireless management".  Is there an output to this command?

check this thread if you are in scenario like flex connect or highly overloaded network.

https://community.cisco.com/t5/wireless/capwap-state-dtls-teardown/td-p/4160587

 

Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB

reccon
Level 1
Level 1

[*10/06/2022 12:21:43.2191] FOUND CONFIGURED WLC (Primary) REDISCOVER TO CONNECT WITH THAT.

According to that message I would assume that there is primary controller configured on the AP and it's tying to connect to this controller instead of 192.168.1.201

Did you check that on the AP?

Rich R
VIP
VIP

Yep I thought the same as @reccon - check the primary/secondary/tertiary controllers set on the AP.
Or just do a factory default reset on the AP to clear out whatever is set.

scottbreslin
Level 1
Level 1

Thank you for all the replies.  I have now sorted the issue, basically I had created the certificate on the vwlc before configuring NTP.  Therefore, I think there was some sort of mismatch with the date and time stamp.  Adding NTP and then re-creating the certificate has now rectified the issue.

Forgive my ignorance, but can you show us how to re-create the certificate, what should we do?

Thank you in advance,

Dardan

 

 @dardan.behluli : FYI ; https://community.cisco.com/t5/wireless/unable-to-create-trustpoint-on-9800-cl/m-p/4098545#M198609

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html#Configurationfilemanagement

dardan.behluli
Level 1
Level 1

Thank you, Mr. Marce1000, but I still have no idea why is this happening and how to solve it. What should I do, what password should I put?

This is funny, and it is my usual experience with Cisco. I am troubleshooting this AIR-AP2802I-E-K9 that is registering with the WLC 9800, but it's wireless interfaces stay down. From the console I get the messages TLV ID 2584 not found; TLV-DEC-ERR-1: No proc for 2584; CLSM[00:00:00:00:00:00]: U3 Client RSSI Stats feature is deprecated; can no longer be enabled; TLV ID 1356 not found; TLV-DEC-ERR-1: No proc for 1356.

Cisco-ing this I find out that they say that the issue is with NTP and/or certificate. Why I'm not seeing this issue with quite a few of other APs of the same model in the same policy, site, RF?

I'm running out of time for this event and I have one AP with it's interfaces down. This one is powered through the power injector, the others get their power through the poe switch.

Thank you

 

 @dardan.behluli - Check if the controller has a correct country code configured for all involved APs
                             + Verify controller software version and AP compatibility with : https://www.cisco.com/c/en/us/td/docs/wireless/compatibility/matrix/compatibility-matrix.html
                             + Have a checkup of the 9800 controller configuration with the CLI command
                               show tech wireless and feed the output from that into Wireless Config Analyzer
                               (do not use simple show tech as input for this procedure)

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

dardan.behluli
Level 1
Level 1

40 of AIR-AP2802I-E-K9 are registered and with all of their interfaces up, only 2, one in my office (connected to a cisco 4507 switch, from where it gets it's power via poe) and one with a power injector. Why should the power injector cause any issue?

I ran the show tech wireless through your WCA, got 5 errors:
1. Management: HTTP server does not have an access class set;
2. and 3. are about FT;

4. Syslog: AP join profile with Syslog facility not set to FACILITY_KERN.

5. RF: AP has high channel change count (more than 10) per day on 5GHz radio

Any ideas,

Dardan

 

> This one is powered through the power injector, the others get their power through the poe switch.
> one in my office (connected to a cisco 4507 switch, from where it gets it's power via poe)
> Why should the power injector cause any issue?
Because the AP does not have enough power for the radios.  As per https://www.cisco.com/c/en/us/products/collateral/wireless/aironet-2800-series-access-points/datasheet-c78-736497.html

Input power requirements

●  802.3at PoE+, Cisco Universal PoE (Cisco UPOE ®)
●  802.3at power injector (AIR-PWRINJ6=)

So if your 4507 and the power injector do not provide 30W PoE and support LLDP or CDP (necessary for the AP to negotiate 30W PoE) then the radios will remained DISABLED.  If this is the case it will be clearly stated in the AP logs.  Power the AP off then on and collect the complete console log and save as a text file (.txt) then attach here for us to check.

Review Cisco Networking for a $25 gift card