cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
444
Views
1
Helpful
5
Replies

Access point doesn't join the controller

shamik
Level 1
Level 1

After resetting the Access point AIR-CAP1602E-E-K9

It doesn't join the controller Cisco 2500

These are the logs from Console of the AP

*May 30 10:03:21.999: %CAPWAP-3-ERRORLOG: Go join a capwap controller
*May 30 10:02:17.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 172.16.10.50 peer_port: 5246
*May 30 10:02:17.275: %DTLS-5-ALERT: Received FATAL : Certificate unknown alert from 172.16.10.50
*May 30 10:02:17.275: %CAPWAP-3-ERRORLOG: Bad certificate alert received from peer.
*May 30 10:02:17.275: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 172.16.10.50:5246
*May 30 10:02:17.275: %CAPWAP-3-ERRORLOG: Invalid event 40 & state 3 combination.

5 Replies 5

Rich R
VIP
VIP

Upgrade the controller to 8.5.182.11 software (link below) and follow the procedures detailed in the field notices which Leo linked and below in my signature.

The first thing you'll have to do is disable NTP and set the date back to before the certificate(s) expired (could be AP and WLC certs expired) - that will let the AP join again.  Then upgrade the software and apply the additional config to WLC from (config ap cert-expiry-ignore mic enable).  Once WLC and AP software have been upgraded and new config applied to WLC and updated to AP then you can re-enable NTP.

shamik
Level 1
Level 1

I cannot upgrade my cisco WLC 2500 which is running 8.2.100.0, as I don't have any support contract active. 

And I have 46 AP's currently working which is connected to the WLC, 

AP Models connected are - AIR-CAP1602E-E-K9, AIR-AP1852I-E-K9, AIR-AP1852E-E-K9

 

 

         >...I cannot upgrade my cisco WLC 2500 which is running 8.2.100.0, as I don't have any support contract active. 
  - Then the only thing you can do is disable NTP and set the controller time  backwards.

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Find a recent security advisory that affects 8.5 code and find the section which says "Customers without Contracts" then email TAC (don't phone). You must quote the URL of the advisory, the paragraph just mentioned and the version and URL https://software.cisco.com/download/specialrelease/9a6a7cf84f9fdf04b95c76e2ac7820e7 for the software you want to download and the serial number of your WLC.  You'll have to mention which platform you need it for (2504) because they have all of them there at that URL.  Then TAC should publish the software to you directly.

This advisory should be suitable: Cisco Wireless LAN Controller AireOS Software FIPS Mode Denial of Service Vulnerability because CSCwa40778 : Bug Search Tool (cisco.com) is fixed in 8.5.182.12. (even though the advisory itself says upgrade to 8.10)

"Customers Without Service Contracts

Customers who purchase directly from Cisco but do not hold a Cisco service contract and customers who make purchases through third-party vendors but are unsuccessful in obtaining fixed software through their point of sale should obtain upgrades by contacting the Cisco TAC: https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html

Customers should have the product serial number available and be prepared to provide the URL of this advisory as evidence of entitlement to a free upgrade."

Review Cisco Networking for a $25 gift card