11-25-2024 02:18 AM
As the title says, after upgrading to version 17.12.03 all APs (c9115AXI-B) in a remote office are looking to be en a constant boot loop and the error message shown is "DTLS close alert from peer". This is strange as it is just this one remote office while all other locations are OK. I am not very familiar with Wireless setups, could someone give me a few pointers on possible fixes for this. I have included the output for Radioactive Trace in the attached file.
11-25-2024 02:36 AM - edited 11-25-2024 02:37 AM
- Feed the debugTrace into Wireless Debug Analyzer and use the Show Original and Show All flags , when I did that myself I got besides the other stuff:
>...
>
2024/11/25 10:47:45.589 | apmgr-capwap-join | __unknown__ | Successfully processed Join request. AP name: AP004, Model: C9115AXI-B, radio slots: 2, rlan slots: 0, site tag name: US_Site, policy tag name: US_Res, rf tag name: US_RF |
2024/11/25 10:47:45.589 | capwapac-smgr-srvr | __unknown__ | Join Response generated with MTU 1005. as per MTU payload, update flag: 0 |
2024/11/25 10:47:45.589 | capwapac-smgr-srvr | __unknown__ | Join processing complete. AP in joined state |
2024/11/25 10:47:45.589 | capwapac-smgr-sess | __unknown__ | Mac: aaaa.bbbb.cccc Session-IP: 10.10.10.10[5249] 10.10.50.2 |
- So it's not clear what is not working ; check for instance : https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#anc4
Use Wireless Debug Analyzer yourself to get the full outputs for further investigation.
M.
11-25-2024 05:44 AM
I also noticed that there were messages of successful join followed immediately by dis-join messages. I will be opening a TAC case as I am at a loss as to what to do next.
I did run the show tech wireless output through the wireless debug analyzer and there were two errors related to SSID, but I find it hard to believe that would affect the join stability.
11-25-2024 06:04 AM
- @BoomShakaLak wrote : >... I will be opening a TAC case as I am at a loss as to what to do next.
It's always good to do that , but if it is with one office only , it looks not related to the 9800 controller and it's setup. Does that WAN link have special parameters such as a smaller MTU or lower throughput ?
M.
11-25-2024 12:18 PM
The office connects to the HQ via site to site VPN so MTU is lower. We also have an office in Asia where the MTU and speed are much worse, and that site had no issues after the upgrade. So I am wondering if there may be some cached values on the WLC that are interfering, but I do not know how to clear them if that is the case. I did to a reload of the WLC after the upgrade to see if that would clear up issue, but it did not.
11-25-2024 12:35 PM
- No direct inputs on that , use https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/218396-troubleshoot-catalyst-9800-ap-join-or-di.html
for further analysis and troubleshooting ,
M.
11-26-2024 01:02 AM
@BoomShakaLak As @marce1000 suggested open an Tac case . I have seen DTL issues in the past and had to raise a tac case.
11-26-2024 01:35 AM
- @srimal99 wrote : >...I have seen DTL issues in the past and had to raise a tac case.
Did they resolve it for you , if so how ?
M.
12-17-2024 05:31 AM
@marce1000 in response to your question. Issue related to WLC. Tac requested to RMA the wlc. Problematic wlc was a refurbished device.
11-27-2024 03:46 AM
Hi,
just to confirm that are you using access point authentication like MAC or serial number auth ?
11-28-2024 01:11 AM
@marce1000 will update once the resolution come from tac.
11-28-2024 01:23 AM
Please raise a TAC Case and ask if this is CSCwb13784.
11-28-2024 05:18 AM
CSCwb13784 is supposed to be fixed in 17.12.3 of course ...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide