05-30-2024 01:10 AM
After resetting the Access point AIR-CAP1602E-E-K9
It doesn't join the controller Cisco 2500
These are the logs from Console of the AP
*May 30 10:03:21.999: %CAPWAP-3-ERRORLOG: Go join a capwap controller
*May 30 10:02:17.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 172.16.10.50 peer_port: 5246
*May 30 10:02:17.275: %DTLS-5-ALERT: Received FATAL : Certificate unknown alert from 172.16.10.50
*May 30 10:02:17.275: %CAPWAP-3-ERRORLOG: Bad certificate alert received from peer.
*May 30 10:02:17.275: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 172.16.10.50:5246
*May 30 10:02:17.275: %CAPWAP-3-ERRORLOG: Invalid event 40 & state 3 combination.
05-30-2024 02:32 AM - edited 05-30-2024 02:35 AM
05-30-2024 07:46 AM
Upgrade the controller to 8.5.182.11 software (link below) and follow the procedures detailed in the field notices which Leo linked and below in my signature.
The first thing you'll have to do is disable NTP and set the date back to before the certificate(s) expired (could be AP and WLC certs expired) - that will let the AP join again. Then upgrade the software and apply the additional config to WLC from (config ap cert-expiry-ignore mic enable). Once WLC and AP software have been upgraded and new config applied to WLC and updated to AP then you can re-enable NTP.
06-03-2024 11:52 PM
I cannot upgrade my cisco WLC 2500 which is running 8.2.100.0, as I don't have any support contract active.
And I have 46 AP's currently working which is connected to the WLC,
AP Models connected are - AIR-CAP1602E-E-K9, AIR-AP1852I-E-K9, AIR-AP1852E-E-K9
06-04-2024 12:00 AM
>...I cannot upgrade my cisco WLC 2500 which is running 8.2.100.0, as I don't have any support contract active.
- Then the only thing you can do is disable NTP and set the controller time backwards.
M.
06-17-2024 06:58 AM
Find a recent security advisory that affects 8.5 code and find the section which says "Customers without Contracts" then email TAC (don't phone). You must quote the URL of the advisory, the paragraph just mentioned and the version and URL https://software.cisco.com/download/specialrelease/9a6a7cf84f9fdf04b95c76e2ac7820e7 for the software you want to download and the serial number of your WLC. You'll have to mention which platform you need it for (2504) because they have all of them there at that URL. Then TAC should publish the software to you directly.
This advisory should be suitable: Cisco Wireless LAN Controller AireOS Software FIPS Mode Denial of Service Vulnerability because CSCwa40778 : Bug Search Tool (cisco.com) is fixed in 8.5.182.12. (even though the advisory itself says upgrade to 8.10)
"Customers Without Service Contracts
Customers who purchase directly from Cisco but do not hold a Cisco service contract and customers who make purchases through third-party vendors but are unsuccessful in obtaining fixed software through their point of sale should obtain upgrades by contacting the Cisco TAC: https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html
Customers should have the product serial number available and be prepared to provide the URL of this advisory as evidence of entitlement to a free upgrade."
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide