Showing results for 
Search instead for 
Did you mean: 

AIR-AP3802E does not join WLC 9800-L-F

Hussein Mahmoud
Level 1
Level 1

Hi all,

I have WLC 9800-L-F and AIR-AP3802E-E-K9


WLC Configuration

 Country Code : KE

DP-WLC#show running-config
Building configuration...

Current configuration : 9669 bytes
! Last configuration change at 08:42:21 UTC Thu Jun 16 2022
version 16.12
service timestamps debug datetime msec
service timestamps log datetime msec
service call-home
platform qfp utilization monitor load 80
platform punt-keepalive disable-kernel-core
hostname DP3-WLC
vrf definition Mgmt-intf
address-family ipv4
address-family ipv6
enable secret 9
aaa new-model
aaa session-id common
vtp domain MOG.LY
vtp mode transparent
! If contact email address in call-home is configured as
! the email address configured in Cisco Smart License Portal will be used as contact email address to send SCH notifications.
profile "CiscoTAC-1"
destination transport-method http
no destination transport-method email
ip domain name MOG
login on-success log
subscriber templating
no device-tracking logging theft
multilink bundle-name authenticated
crypto pki trustpoint TP-self-signed-1134387968
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1134387968
revocation-check none
rsakeypair TP-self-signed-1134387968
crypto pki trustpoint SLA-TrustPoint
enrollment pkcs12
revocation-check crl

license udi pid C9800-L-F-K9 sn XXXXXXXXXX
memory free low-watermark processor 171098
diagnostic bootup level minimal
mode sso
vlan internal allocation policy ascending
vlan 100
name Wireless_Management
vlan 201
class-map match-any AVC-Reanchor-Class
match protocol cisco-jabber-audio
match protocol cisco-jabber-video
match protocol webex-media
match protocol webex-app-sharing
match protocol webex-control
match protocol webex-meeting
match protocol wifi-calling
interface TwoGigabitEthernet0/0/0
Description (Connected to SW)
switchport mode trunk
negotiation auto
no snmp trap link-status
interface TwoGigabitEthernet0/0/1
negotiation auto
no snmp trap link-status
interface TwoGigabitEthernet0/0/2
negotiation auto
no snmp trap link-status
interface TwoGigabitEthernet0/0/3
negotiation auto
no snmp trap link-status
interface TenGigabitEthernet0/1/0
no negotiation auto
no snmp trap link-status
interface TenGigabitEthernet0/1/1
no negotiation auto
no snmp trap link-status
interface GigabitEthernet0
vrf forwarding Mgmt-intf
ip address
negotiation auto
interface Vlan1
no ip address
interface Vlan100
ip address
interface Vlan201
ip address
ip forward-protocol nd
ip http server
ip http authentication local
ip http secure-server
ip route
wireless aaa policy default-aaa-policy
wireless cts-sxp profile default-sxp-profile
no wireless ipv6 ra wired
wireless management interface Vlan100
wireless profile airtime-fairness default-atf-policy 0
wireless profile flex default-flex-profile
description "default flex profile"
wireless profile mesh default-mesh-profile
description "default mesh profile"
wireless profile policy default-policy-profile
description "default policy profile"
wireless tag site default-site-tag
description "default site tag"
wireless tag policy default-policy-tag
description "default policy-tag"
wireless tag rf default-rf-tag
description "default RF tag"
wireless fabric control-plane default-control-plane
ap dot11 24ghz rf-profile Low_Client_Density_rf_24gh
coverage data rssi threshold -90
coverage level 2
coverage voice rssi threshold -90
description "pre configured Low Client Density rfprofile for 2.4gh radio"
high-density rx-sop threshold low
tx-power v1 threshold -65
no shutdown
ap dot11 24ghz rf-profile High_Client_Density_rf_24gh
description "pre configured High Client Density rfprofile for 2.4gh radio"
high-density rx-sop threshold medium
rate RATE_11M disable
rate RATE_12M mandatory
rate RATE_1M disable
rate RATE_2M disable
rate RATE_5_5M disable
rate RATE_6M disable
tx-power min 7
no shutdown
ap dot11 24ghz rf-profile Typical_Client_Density_rf_24gh
description "pre configured Typical Client Density rfprofile for 2.4gh radio"
rate RATE_11M disable
rate RATE_12M mandatory
rate RATE_1M disable
rate RATE_2M disable
rate RATE_5_5M disable
rate RATE_6M disable
no shutdown
ap dot11 5ghz rf-profile Low_Client_Density_rf_5gh
coverage data rssi threshold -90
coverage level 2
coverage voice rssi threshold -90
description "pre configured Low Client Density rfprofile for 5gh radio"
high-density rx-sop threshold low
tx-power v1 threshold -60
no shutdown
ap dot11 5ghz rf-profile High_Client_Density_rf_5gh
description "pre configured High Client Density rfprofile for 5gh radio"
high-density rx-sop threshold medium
rate RATE_6M disable
rate RATE_9M disable
tx-power min 7
tx-power v1 threshold -65
no shutdown
ap dot11 5ghz rf-profile Typical_Client_Density_rf_5gh
description "pre configured Typical Density rfprofile for 5gh radio"
no shutdown
ap country KE
ap tag-source-priority 2 source filter
ap tag-source-priority 3 source ap
ap profile default-ap-profile
description "default ap profile"

DP-WLC#show running-config
Building configuration...

Current configuration : 9669 bytes
! Last configuration change at 08:42:21 UTC Thu Jun 16 2022
version 16.12
service timestamps debug datetime msec
service timestamps log datetime msec
service call-home
platform qfp utilization monitor load 80
platform punt-keepalive disable-kernel-core
hostname DP3-WLC
vrf definition Mgmt-intf
address-family ipv4
address-family ipv6
enable secret 9
aaa new-model
aaa session-id common
vtp domain MOG.LY
vtp mode transparent
! If contact email address in call-home is configured as
! the email address configured in Cisco Smart License Portal will be used as contact email address to send SCH notifications.
profile "CiscoTAC-1"
destination transport-method http
no destination transport-method email
ip domain name MOG
login on-success log
subscriber templating
no device-tracking logging theft
multilink bundle-name authenticated
crypto pki trustpoint TP-self-signed-1134387968
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1134387968
revocation-check none
rsakeypair TP-self-signed-1134387968
crypto pki trustpoint SLA-TrustPoint
enrollment pkcs12
revocation-check crl

license udi pid C9800-L-F-K9 sn XXXXXXXXXX
memory free low-watermark processor 171098
diagnostic bootup level minimal
mode sso
vlan internal allocation policy ascending
vlan 100
name Wireless_Management
vlan 201
class-map match-any AVC-Reanchor-Class
match protocol cisco-jabber-audio
match protocol cisco-jabber-video
match protocol webex-media
match protocol webex-app-sharing
match protocol webex-control
match protocol webex-meeting
match protocol wifi-calling
interface TwoGigabitEthernet0/0/0
Description (Connected to SW)
switchport mode trunk
negotiation auto
no snmp trap link-status
interface TwoGigabitEthernet0/0/1
negotiation auto
no snmp trap link-status
interface TwoGigabitEthernet0/0/2
negotiation auto
no snmp trap link-status
interface TwoGigabitEthernet0/0/3
negotiation auto
no snmp trap link-status
interface TenGigabitEthernet0/1/0
no negotiation auto
no snmp trap link-status
interface TenGigabitEthernet0/1/1
no negotiation auto
no snmp trap link-status
interface GigabitEthernet0
vrf forwarding Mgmt-intf
ip address
negotiation auto
interface Vlan1
no ip address
interface Vlan100
ip address
interface Vlan201
ip address
ip forward-protocol nd
ip http server
ip http authentication local
ip http secure-server
ip route
wireless aaa policy default-aaa-policy
wireless cts-sxp profile default-sxp-profile
no wireless ipv6 ra wired
wireless management interface Vlan100
wireless profile airtime-fairness default-atf-policy 0
wireless profile flex default-flex-profile
description "default flex profile"
wireless profile mesh default-mesh-profile
description "default mesh profile"
wireless profile policy default-policy-profile
description "default policy profile"
wireless tag site default-site-tag
description "default site tag"
wireless tag policy default-policy-tag
description "default policy-tag"
wireless tag rf default-rf-tag
description "default RF tag"
wireless fabric control-plane default-control-plane
ap dot11 24ghz rf-profile Low_Client_Density_rf_24gh
coverage data rssi threshold -90
coverage level 2
coverage voice rssi threshold -90
description "pre configured Low Client Density rfprofile for 2.4gh radio"
high-density rx-sop threshold low
tx-power v1 threshold -65
no shutdown
ap dot11 24ghz rf-profile High_Client_Density_rf_24gh
description "pre configured High Client Density rfprofile for 2.4gh radio"
high-density rx-sop threshold medium
rate RATE_11M disable
rate RATE_12M mandatory
rate RATE_1M disable
rate RATE_2M disable
rate RATE_5_5M disable
rate RATE_6M disable
tx-power min 7
no shutdown
ap dot11 24ghz rf-profile Typical_Client_Density_rf_24gh
description "pre configured Typical Client Density rfprofile for 2.4gh radio"
rate RATE_11M disable
rate RATE_12M mandatory
rate RATE_1M disable
rate RATE_2M disable
rate RATE_5_5M disable
rate RATE_6M disable
no shutdown
ap dot11 5ghz rf-profile Low_Client_Density_rf_5gh
coverage data rssi threshold -90
coverage level 2
coverage voice rssi threshold -90
description "pre configured Low Client Density rfprofile for 5gh radio"
high-density rx-sop threshold low
tx-power v1 threshold -60
no shutdown
ap dot11 5ghz rf-profile High_Client_Density_rf_5gh
description "pre configured High Client Density rfprofile for 5gh radio"
high-density rx-sop threshold medium
rate RATE_6M disable
rate RATE_9M disable
tx-power min 7
tx-power v1 threshold -65
no shutdown
ap dot11 5ghz rf-profile Typical_Client_Density_rf_5gh
description "pre configured Typical Density rfprofile for 5gh radio"
no shutdown
ap country KE
ap tag-source-priority 2 source filter
ap tag-source-priority 3 source ap
ap profile default-ap-profile
description "default ap profile"


AP Configuration

AP-1#show running-config

AP Name : AP-1
Admin State : Enabled
AP Mode : Local
AP Submode : Not Configured
Location : default location
Reboot Reason : Reload command
Primary controller name : DP3-WLC
Primary controller IP :
Secondary controller name :
Tertiary controller name :
AP join priority : 1
IP Prefer-mode : Unconfigured
CAPWAP UDP-Lite : Unconfigured
Last Joined Controller name:
DTLS Encryption State : Disabled
Discovery Timer : 10
Heartbeat Timer : 30
CDP State : Enabled
Watchdog monitoring : Enabled
IOX : Disabled
RRM State : Enabled
LSC State : Disabled
SSH State : Disabled
AP Username : Cisco
Session Timeout : 300
Extlog Host :
Extlog Flags : 0
Extlog Status Interval : 0
Syslog Host :
Syslog Facility : 0
Syslog Level : errors
Core Dump File Compression : Disabled
Core Dump Filename :
Client Trace Status : Enabled(All)
Client Trace All Clients : Enabled
Client Trace Filter : 0x0000000E
Client Trace Out ConsoleLog: Disabled
WLC Link LAG status : Disabled
AP Link LAG status : Disabled
AP WSA Mode : Disabled
Vlan Interface : Disabled

AP-1#show ip interface brief
Interface            IP-Address                     Method                Status           Protocol          Speed Duplex
wired0                static                up  up                 1000                  full
wired1               unassigned                    unset                down down       n/a                   unknown
apphostintf1       unassigned                   unset                 up up                 n/a                    n/a
wifi0                      n/a                            n/a                     up up                 n/a                    n/a
wifi1                      n/a                            n/a                     up up                 n/a                     n/a


The Logs when start up the AP:

[*06/15/2022 09:38:07.8120] CAPWAP State: Discovery
[*06/15/2022 09:38:07.8153] Discovery Request sent to, discovery type STATIC_CONFIG(1)
[*06/15/2022 09:38:07.8180] Discovery Request sent to, discovery type STATIC_CONFIG(1)
[*06/15/2022 09:38:07.8208] Discovery Request sent to, discovery type UNKNOWN(0)
[*06/15/2022 09:38:18.2688] ipv6 gw config loop in discovery timer expiry
[*06/15/2022 09:38:20.2690] ipv6 gw config loop in discovery timer expiry
[*06/15/2022 09:38:22.2692] ipv6 gw config loop in discovery timer expiry
[*06/15/2022 09:38:24.2693] ipv6 gw config loop in discovery timer expiry
[*06/15/2022 09:38:26.2695] ipv6 gw config loop in discovery timer expiry
[*06/15/2022 09:38:28.2701] ipv6 gw config loop in Ac discovery
[*06/15/2022 09:38:30.2703] ipv6 gw config loop in Ac discovery
[*06/15/2022 09:38:32.2704] ipv6 gw config loop in Ac discovery
[*06/15/2022 09:38:34.2706] ipv6 gw config loop in Ac discovery
[*06/15/2022 09:38:36.2708] ipv6 gw config loop in Ac discovery



How to solve this issue

Thanks so much for any support.

15 Replies 15


 From the AP, can you ping the WLC? 

The logs shows some capwap discovery but it does not seems to get reply.

hi Miranda,

yes ,I can ping form AP to to WLC and AP to SW

Can you run?


show ap support-bundle summary




 -  Review the 9800 L-F  configuration with the CLI command : show  tech wireless , have the output analyzed by  , please note do not use classical show tech-support (short version) , use the command denoted in green for Wireless Analyzer


-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '


the resalt for this command # show tech wireless  


If your country code is (KE Korea), then you need to have -K regulatory domain AP. 




*** Pls rate all useful responses ***

hi Nayanajith ,

Screenshot 2022-06-17 074038.png



            - Is the controller configured to support the particular country code too ?


-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '


yes the WLC #AP Country KE


The Logs when write command 


WLC(config)#no ap dot11 24ghz shutdown
% switch-1:dbm:wireless:802.11b network not supported for this Country Code
WLC(config)#no ap dot11 5ghz shutdown
% switch-1:dbm:wireless:802.11a network not supported for this Country Code



                                                Remember to execute this :

  -  Review the 9800 L-F  configuration with the CLI command : show  tech wireless , have the output analyzed by  , please note do not use classical show tech-support (short version) , use the command denoted in green for Wireless Analyzer

        Further more review this thread :



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

As @Rasika Nayanajith has already explained you are trying to use a Europe (-E) AP with Korea (-K) country code - it will not work.

Those error messages are TELLING you that too.  

Configuring a fake country code to make it work is not supported and could be illegal in your country because the country codes ensure compliance with the channels and RF signal strengths etc allowed for each country.

For Korea you need a -K model of AP.


the AIR-AP3802E-E-K9  that mean Korea 


Screenshot 2022-06-17 074038.png

NO, It should be AIR-AP3802E-K-K9 for Korea. As AP belongs to -E in your case, the country configured KE does not work.





Thanks for your effort ,

Country code must be changed for WLC 

Review Cisco Networking for a $25 gift card