ā08-31-2023 04:54 AM
Hi,
We have some branch offices with Aironet 2700 and 2800 access points and old WLC 2504 running 8.5.151.0. As the WLC 2504 are beyond end of life and support for Aironet 2700 and 2800 has been re-introduced with 17.9.x we migrate our old access points to new Catalyst 9800-40 controller in the headquarter.
With the Aironet 2700 this went smooth. With the Airnet we hit this bug here: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe07802.
Cisco 2800/3800/4800/1562 drop upstream EAP packets
CSCwe07802
Symptom:EAP negotiations fail. Client sends its certificate (CLIENT HELLO), but the AP fails to forward it to CAPWAP. Conditions:Seen with 2800/3800/4800/1562 series AP (no other models). Problem may be more prevalent when using 80MHz wide rather than 20/40MHz.
Workaround:Let the AP mode be mesh mode
Certificate based EAP/TLS authenticated sessions get timeouts and disconnect. Moving all APs to mesh authentication mode is not an option here.
Bug description says it is fixed in Cupertino-17.9.4 but that release is not yet flagged with a star in Cisco download portal. We've had bad experience using software not with a star from the download portal.
Regards,
Bernd
Solved! Go to Solution.
ā08-31-2023 07:15 AM
The TAC recommended list (below) is more authoritative (and comes with relevant advice) than the * designation on the download page but TAC generally won't promote a release till it's been in stable deployment (without any major issues reported) for at least 4 weeks. 17.9.4 was released 31st July so should replace 17.9.3 anytime soon in the next week or two. I already have it deployed so I agree with Marce - yes.
ā08-31-2023 05:12 AM
>....Is 17.9.4 stable enough for production?
- Consider that a yes ,
M.
ā08-31-2023 07:15 AM
The TAC recommended list (below) is more authoritative (and comes with relevant advice) than the * designation on the download page but TAC generally won't promote a release till it's been in stable deployment (without any major issues reported) for at least 4 weeks. 17.9.4 was released 31st July so should replace 17.9.3 anytime soon in the next week or two. I already have it deployed so I agree with Marce - yes.
ā08-31-2023 10:09 PM
Thanks. Then we will wait migrating the branch offices with Aironet 2800 access points until the C9800-40 has been upgraded from 17.9.3 to 17.9.4.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide