cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1915
Views
10
Helpful
3
Replies

Access Point are not registering with 2500 WLC

coppolino97
Level 1
Level 1

Hi all,
I have two Cisco AP AIR-CAP2602I-E-K9 and a Cisco WLC 2500.
WLC is running firmware version 8.5.171.0

In this moment AP and WLC are in the same VLAN.

I get this error messages from Access Point CLI (I connected it to my laptop using serial cable):

%DTLS-3-HANDSHAKE_FAILURE: openssl_dtls.c:981 Failed to complete DTLS handshake with peer X.X.X.X
*Oct 21 09:45:05.007: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to X.X.X.X:5246
*Oct 21 09:45:05.007: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to X.X.X.X:5246
*Oct 21 09:45:05.007: %CAPWAP-3-ERRORLOG: Invalid event 38 & state 3 combination.
*Oct 21 10:06:57.007: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed. The certificate (SN: 5B866A600000001E2FF0) has expired.
Validity period ended on 02:16:14 UTC Feb 23 2022Peer certificate verification failed 001A*Oct 21 10:06:57.007: DTLS_CLIENT_ERROR: ../capwap/base_capwap/capwap/base_capwap_wtp_dtls.c:496 Certificate verified failed!
*Oct 21 10:06:57.007: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to X.X.X.X:5246
*Oct 21 10:06:57.007: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to X.X.X.X:5246

I already configured on Cisco WLC these parameters, however nothing change in fact AP are still not registering to WLC.

config ap cert-expiry-ignore mic enable
config ap cert-expiry-ignore ssc enable

I would avoid to change NTP configuration on WLC side.
WLC is running in a production environment so I have to avoid network disservices.

Any suggestions?
Federico

3 Replies 3

marce1000
VIP
VIP

 

 - FYI : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs22835  , you may need to fallback to disable NTP and set clock backwards in time.

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Rich R
VIP
VIP

The instructions are all in the field notice but for some reason people can't be bothered to read it and then wonder why they get stuck!  So I'll summarise it for the umpteenth time:
1. Upgrade to latest version which supports your APs and WLC - probably 8.5.182.0
https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html#anc10
2. Apply the config workaround on the WLC
3. Disable NTP and set time manually to before your certs expired
4. Allow all the APs to join, download new code, pick up the config workaround
5 Re-enable NTP

Review Cisco Networking for a $25 gift card