cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
1081
Views
3
Helpful
3
Replies

Aironet 2800 access points and Catalyst 9800-40 with IOS XE 17.9.3

Bernd Nies
Level 1
Level 1

Hi,

We have some branch offices with Aironet 2700 and 2800 access points and old WLC 2504 running 8.5.151.0. As the WLC 2504 are beyond end of life and support for Aironet 2700 and 2800 has been re-introduced with 17.9.x we migrate our old access points to new Catalyst 9800-40 controller in the headquarter.

With the Aironet 2700 this went smooth. With the Airnet we hit this bug here: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe07802. 

Cisco 2800/3800/4800/1562 drop upstream EAP packets
CSCwe07802  

 

Symptom:EAP negotiations fail.  Client sends its certificate (CLIENT HELLO), but the AP fails to forward it to CAPWAP. Conditions:Seen with 2800/3800/4800/1562 series AP (no other models).  Problem may be more prevalent when using 80MHz wide rather than 20/40MHz. 

Workaround:Let the AP mode be mesh mode

Certificate based EAP/TLS authenticated sessions get timeouts and disconnect. Moving all APs to mesh authentication mode is not an option here.

Bug description says it is fixed in Cupertino-17.9.4 but that release is not yet flagged with a star in Cisco download portal. We've had bad experience using software not with a star from the download portal. Is 17.9.4 stable enough for production?

Regards,

Bernd

 

1 Accepted Solution

Accepted Solutions

Rich R
VIP
VIP

The TAC recommended list (below) is more authoritative (and comes with relevant advice) than the * designation on the download page but TAC generally won't promote a release till it's been in stable deployment (without any major issues reported) for at least 4 weeks.  17.9.4 was released 31st July so should replace 17.9.3 anytime soon in the next week or two.  I already have it deployed so I agree with Marce - yes.

View solution in original post

3 Replies 3

marce1000
VIP
VIP

 

                   >....Is 17.9.4 stable enough for production?
                         - Consider that a yes , 

 M.
  



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Rich R
VIP
VIP

The TAC recommended list (below) is more authoritative (and comes with relevant advice) than the * designation on the download page but TAC generally won't promote a release till it's been in stable deployment (without any major issues reported) for at least 4 weeks.  17.9.4 was released 31st July so should replace 17.9.3 anytime soon in the next week or two.  I already have it deployed so I agree with Marce - yes.

Bernd Nies
Level 1
Level 1

Thanks. Then we will wait migrating the branch offices with Aironet 2800 access points until the C9800-40 has been upgraded from 17.9.3 to 17.9.4.

Review Cisco Networking for a $25 gift card