03-21-2023 10:04 AM - edited 03-21-2023 11:29 AM
We are about to start to migration from 5520 AireOS to 9800-40 IOS-XE
To test, I attempted to move couple of 2702I APs by blocking AP communication to old WLCs, because AP's just won't forget old controllers.
With current clock time APs won't register to new WLC and gets stuck in downloading and AP log shows image verification failed because Cert expired on Dec 4 2022
DTLS cert for capwap has start date of 24 Dec 2022, which allows for capwap tunnel to be established for image downloading.
AP keeps repeating this process in a loop.
How its working for me
If there is no other way I would have to repeat the same for all the 150+ APs. I am also thinking of upgrading old WLCs to 8.10.183 for mobility tunnel, maybe that is the way to go and resolves certificate issues aswell. I am not sure.
I also saw another issue, when upgrading WLC to 17.3.6 from 17.3.4, APs that were on 17.3.4 would still exhibit same behavior and I had to move the clocks again, which I thought would get resolved after upgrading to 17.3.4 from 8.5.161.
I also notice AP's still continue to attempt to reach old controllers even after they have successfully registered to new WLC
Any help to ease the process and any potential future upgrade issues.
Thanks
Solved! Go to Solution.
03-21-2023 12:03 PM
Refer below
I would upgrade 5520 to 8.10.183.0 which got the fix for cert issue.
Regarding 9800 code version, I would suggest go to 17.9.3 as it support Wave 1 APs. (17.3.x last supported 31st March 2023 and no more maintenance releases expected)
https://mrncciew.com/2023/03/20/9800-wave-1-ap-support/
HTH
Rasika
*** Pls rate all useful responses ***
03-21-2023 12:03 PM
Refer below
I would upgrade 5520 to 8.10.183.0 which got the fix for cert issue.
Regarding 9800 code version, I would suggest go to 17.9.3 as it support Wave 1 APs. (17.3.x last supported 31st March 2023 and no more maintenance releases expected)
https://mrncciew.com/2023/03/20/9800-wave-1-ap-support/
HTH
Rasika
*** Pls rate all useful responses ***
03-22-2023 12:16 AM
@Rasika Nayanajith I upgraded WLC's to 17.9.3 and I am able to join APs to 9800 now, without having to change NTP. Thanks for pointing to that.
Would there be any reason to still upgrade old WLCs to 8.10.183?
03-22-2023 12:41 PM
if you ever want to use 5520 as a back up then I would get it upgraded to 8.10.183.0. Otherwise simply migrate APs to 9800 & without worrying about 5520 code upgrade
HTH
Rasika
*** Pls rate all useful responses ***
07-13-2023 04:34 PM
Hi @rajitoor55
07-14-2023 12:21 AM
Yes, 5520 & 9800 got two different AP images for APs, in that way it needs to get image from 9800
HTH
Rasika
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide