03-02-2026 09:01 AM
we have two Cisco Access Points. One has successfully joined the controller, but the other is not joining. Both access points are connected to switch ports with the same configuration. we have also factory reset the AP, but it is still not joining the controller.
Can you please suggest what the issue might be?
Solved! Go to Solution.
03-03-2026 09:51 AM
ok the problem is resolved and the issue was, I was enabled the MAC address and IP Address Binding in AAA section I was disabled, after this the both was AP create capwap tunnel successfully.
03-03-2026 03:01 PM
Yes @sufiyanmasood the clue was in the logs "Disjoined AP Auth Failure" - you enabled AP auth but did not allow that AP MAC address.
03-02-2026 09:06 AM
Which is the Access Point model and WLC version?
The main reason for AP not join on the WLC is version mismatch.
If you are sure about version being correct, you need to console into AP and share the logs while it is trying to join.
03-02-2026 06:49 PM - edited 03-02-2026 06:53 PM
controller shows this type of error
Mar 2 14:36:52.781: %CAPWAPAC_SMGR_TRACE_MESSAGE-5-AP_JOIN_DISJOIN: Chassis 1 R0/0: wncd: AP Event: AP Name: AP****.****.**** Mac: ****.****.**** Session-IP: 172.16.10.30[5275] 172.16.10.10[5246] Disjoined AP Auth Failure
WLC version is version 17.12
03-03-2026 09:26 AM
Whch AP model?
03-02-2026 09:46 AM
we have two Cisco Access Points. One has successfully joined the controller, but the other is not joining. Both access points are connected to switch ports with the same configuration. we have also factory reset the AP, but it is still not joining the controller.
Can you please suggest what the issue might be?
One joined Controller and other Not joined same models ?
Are working one not working are same switch ?
can you check working one vs not working one same VLAN, and have enough PoE ?
Does to AP get DHCP IP address, how these Joining WLC, using Option 43 ?
in the last i will ask what IOS XE code running, if you are connected to AP console port post complete boot logs.
troubleshooting tips always works for me :
=====️ Preenayamo Vasudevam ️=====
***** Rate All Helpful Responses *****
03-02-2026 06:51 PM
we are using option 150 ip .
03-03-2026 02:48 AM
What do you think about the other question I was asked?
Based on the recent logs you posted.
That specific log indicates your 9800 WLC is rejecting the AP during the DTLS/Join phase due to a certificate or credential mismatch. Since you mentioned a recent setup or lab environment, this is usually caused by the WLC not trusting the AP's SUDI (Secure Unique Device Identifier) or a clock drift
Are these brand new AP, or have they joined different controllers before?
Look Option 150 working, but DTLS handshake is failing.
=====️ Preenayamo Vasudevam ️=====
***** Rate All Helpful Responses *****
03-03-2026 09:51 AM
ok the problem is resolved and the issue was, I was enabled the MAC address and IP Address Binding in AAA section I was disabled, after this the both was AP create capwap tunnel successfully.
03-03-2026 03:01 PM
Yes @sufiyanmasood the clue was in the logs "Disjoined AP Auth Failure" - you enabled AP auth but did not allow that AP MAC address.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide