cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
853
Views
2
Helpful
8
Replies

Access point not joined in Controller 9800

sufiyanmasood
Level 2
Level 2

we have two Cisco Access Points. One has successfully joined the controller, but the other is not joining. Both access points are connected to switch ports with the same configuration. we have also factory reset the AP, but it is still not joining the controller.

Can you please suggest what the issue might be?

2 Accepted Solutions

Accepted Solutions

ok the problem is resolved and the issue was, I was enabled the MAC address and IP Address Binding in AAA section I was disabled, after this the both was AP create capwap tunnel successfully.

View solution in original post

Yes @sufiyanmasood the clue was in the logs "Disjoined AP Auth Failure" - you enabled AP auth but did not allow that AP MAC address.

------------------------------
Please click Helpful if this post helped you and Accept as Solution (drop down menu at top right of this reply) if this answered your query.
------------------------------
TAC recommended codes for AireOS WLC's   and   TAC recommended codes for 9800 WLC's
Best Practices for AireOS WLC's,   Best Practices for 9800 WLC's   and   Cisco Wireless compatibility matrix
Check your 9800 WLC config with Wireless Config Analyzer using "show tech wireless" output or "config paging disable" then "show run-config" output on AireOS and use Wireless Debug Analyzer to analyze your WLC client debugs
Field Notice: FN63942 APs and WLCs Fail to Create CAPWAP Connections Due to Certificate Expiration
Field Notice: FN72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Required
Field Notice: FN72524 IOS APs stuck in downloading state after 4 Dec 2022 due to Certificate Expired
- Fixed in 8.10.196.0, latest 9800 releases, 8.5.182.12 (8.5.182.13 for 3504) and 8.5.182.109 (IRCM, 8.5.182.111 for 3504)
Field Notice: FN70479 AP Fails to Join or Joins with 1 Radio due to Country Mismatch, RMA needed
Field Notice: FN74383 APs Running 17.12.4/5/6/6a May Run Out of Flash Space Preventing Upgrades
How to avoid boot loop due to corrupted image on Wave 2 and Catalyst 11ax Access Points (CSCvx32806)
Field Notice: FN74035 - Wave2 APs DFS May Not Detect Radar After Channel Availability Check Time
Leo's list of bugs affecting 2800/3800/4800/1560 APs
Default AP console baud rate from 17.12.x is 115200 - introduced by CSCwe88390

View solution in original post

8 Replies 8

@sufiyanmasood 

Which is the Access Point model and WLC version?

The main reason for AP not join on the WLC is version mismatch. 

If you are sure about version being correct, you need to console into AP and share the logs while it is trying to join. 

controller shows this type of error
Mar 2 14:36:52.781: %CAPWAPAC_SMGR_TRACE_MESSAGE-5-AP_JOIN_DISJOIN: Chassis 1 R0/0: wncd: AP Event: AP Name: AP****.****.**** Mac: ****.****.**** Session-IP: 172.16.10.30[5275] 172.16.10.10[5246] Disjoined AP Auth Failure
WLC version is version 17.12

Whch AP model? 

balaji.bandi
Hall of Fame
Hall of Fame
we have two Cisco Access Points. One has successfully joined the controller, but the other is not joining. Both access points are connected to switch ports with the same configuration. we have also factory reset the AP, but it is still not joining the controller.

Can you please suggest what the issue might be?

One joined Controller and other Not joined same models ?

Are working one not working are same switch ?

can you check working one vs not working one same VLAN, and have enough PoE ?

Does to AP get DHCP IP address, how these Joining WLC, using Option 43 ?

in the last i will ask what IOS XE code running, if you are connected to AP console port post complete boot logs.

troubleshooting tips always works for me :

https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/218396-troubleshoot-catalyst-9800-ap-join-or-di.html

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

we are using option 150 ip .

What do you think about the other question I was asked?

Based on the recent logs you posted.

That specific log indicates your 9800 WLC is rejecting the AP during the DTLS/Join phase due to a certificate or credential mismatch. Since you mentioned a recent setup or lab environment, this is usually caused by the WLC not trusting the AP's SUDI (Secure Unique Device Identifier) or a clock drift

Are these brand new AP, or have they joined different controllers before?

Look Option 150 working, but DTLS handshake is failing.

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

ok the problem is resolved and the issue was, I was enabled the MAC address and IP Address Binding in AAA section I was disabled, after this the both was AP create capwap tunnel successfully.

Yes @sufiyanmasood the clue was in the logs "Disjoined AP Auth Failure" - you enabled AP auth but did not allow that AP MAC address.

------------------------------
Please click Helpful if this post helped you and Accept as Solution (drop down menu at top right of this reply) if this answered your query.
------------------------------
TAC recommended codes for AireOS WLC's   and   TAC recommended codes for 9800 WLC's
Best Practices for AireOS WLC's,   Best Practices for 9800 WLC's   and   Cisco Wireless compatibility matrix
Check your 9800 WLC config with Wireless Config Analyzer using "show tech wireless" output or "config paging disable" then "show run-config" output on AireOS and use Wireless Debug Analyzer to analyze your WLC client debugs
Field Notice: FN63942 APs and WLCs Fail to Create CAPWAP Connections Due to Certificate Expiration
Field Notice: FN72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Required
Field Notice: FN72524 IOS APs stuck in downloading state after 4 Dec 2022 due to Certificate Expired
- Fixed in 8.10.196.0, latest 9800 releases, 8.5.182.12 (8.5.182.13 for 3504) and 8.5.182.109 (IRCM, 8.5.182.111 for 3504)
Field Notice: FN70479 AP Fails to Join or Joins with 1 Radio due to Country Mismatch, RMA needed
Field Notice: FN74383 APs Running 17.12.4/5/6/6a May Run Out of Flash Space Preventing Upgrades
How to avoid boot loop due to corrupted image on Wave 2 and Catalyst 11ax Access Points (CSCvx32806)
Field Notice: FN74035 - Wave2 APs DFS May Not Detect Radar After Channel Availability Check Time
Leo's list of bugs affecting 2800/3800/4800/1560 APs
Default AP console baud rate from 17.12.x is 115200 - introduced by CSCwe88390
Review Cisco Networking for a $25 gift card