ā04-18-2016 06:34 AM - edited ā07-05-2021 04:54 AM
Hi guys.
I tried to connect my AP 3702 to the wlc 2504. WLC software version is 8.2.100.0. Unfortunately, ap can't to join in WLC. There is DTLS error
i started debug "debug capwap errors enable" and i'm looking next messages.
*spamApTask1: Apr 18 16:08:05.801: d8:b1:90:84:1c:48 Releasing lock for 0x1885d690
*spamApTask1: Apr 18 16:08:15.797: d8:b1:90:94:d0:50 ApModel: AIR-CAP3702E-I-K9
*spamApTask1: Apr 18 16:08:15.797: Could not find image version of bundled AP(apType: 35)!!!
*spamApTask1: Apr 18 16:08:15.797: Unable to get AP Bundled Version. Using Controller Version!!!
Do you know is it software bug of something else?
ā04-18-2016 08:42 AM
Try this troubleshooting guide.
ā04-19-2016 04:13 AM
HI,
For me also same problem
1.my lightweight AP(3502i) is not joining with virtual Wireless Lan Controller
my Ap is getting IP from DHCP , but it shows not joined in wlc, can you please tell me what was the problem,
2.is it possible to install new image in lightweight AP(3502i) .
* [Lightweight AccessPoint (3502I) Version 12.4(23c)JA5 "flash:/ap3g1-rcvk9w8-mx/ap3g1-rcvk9w8-mx"]
* Virtual Wireless Controller (8.2.100.0)
APa44c.11d3.3ae9#sh version
Cisco IOS Software, C3500 Software (AP3G1-RCVK9W8-M), Version 12.4(23c)JA3, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2011 by Cisco Systems, Inc.
Compiled Tue 18-Oct-11 15:02 by prod_rel_team
ROM: Bootstrap program is C3500 boot loader
BOOTLDR: C3500 Boot Loader (AP3G1-BOOT-M) Version 12.4(23c)JA5, RELEASE SOFTWARE (fc1)
APa44c.11d3.3ae9 uptime is 24 minutes
System returned to ROM by power-on
System image file is "flash:/ap3g1-rcvk9w8-mx/ap3g1-rcvk9w8-mx"
This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.
A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
If you require further assistance please contact us by sending email to
export@cisco.com.
cisco AIR-CAP3502I-E-K9 (PowerPC460exr) processor (revision A0) with 81910K/49152K bytes of memory.
Processor board ID FCZ1623W0UL
PowerPC460exr CPU at 666Mhz, revision number 0x18A8
Last reset from power-on
LWAPP image version 7.0.112.74
1 Gigabit Ethernet interface
32K bytes of flash-simulated non-volatile configuration memory.
Base ethernet MAC Address: A4:4C:11:D3:3A:E9
Part Number : 73-12175-05
PCA Assembly Number : 800-32268-05
PCA Revision Number : A0
PCB Serial Number : FOC16175AYN
Top Assembly Part Number : 800-32891-01
Top Assembly Serial Number : FCZ1623W0UL
Top Revision Number : A0
Product/Model Number : AIR-CAP3502I-E-K9
Configuration register is 0xF
APa44c.11d3.3ae9#
*Apr 16 07:12:23.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 10.100.3.72 peer_port: 5246
*Apr 16 07:12:23.003: %LWAPP-3-CLIENTERRORLOG: Peer certificate verification failed
*Apr 16 07:12:23.003: %CAPWAP-3-ERRORLOG: Certificate verification failed!
*Apr 16 07:12:23.003: DTLS_CLIENT_ERROR: ../capwap/capwap_wtp_dtls.c:348 Certificate verified failed!
*Apr 16 07:12:23.003: %DTLS-4-BAD_CERT: Certificate verification failed. Peer IP: 10.100.3.72
*Apr 16 07:12:23.003: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to 10.100.3.72:5246
*Apr 16 07:12:23.003: %DTLS-3-BAD_RECORD: Erroneous record received from 10.100.3.72: Malformed Certificate
*Apr 16 07:12:23.003: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 10.100.3.72:5246
*Apr 16 07:12:23.003: %CAPWAP-3-ERRORLOG: Invalid event 38 & state 3 combination.
-----------------------------
from wlc
(Cisco Controller) >show ap join stats summary all
Number of APs.............................................. 2
Base Mac AP EthernetMac AP Name IP Address Status
67:58:34:01:00:00 N A N A 10.100.3.7 Not Joined
a4:4c:11:d3:3a:e9 N A APa44c.11d3.3ae9 10.100.3.7 Not Joined
(Cisco Controller) >show sysinfo
Manufacturer's Name.............................. Cisco Systems Inc.
Product Name..................................... Cisco Controller
Build Name....................................... Engg Special Image
Product Version.................................. 8.2.100.0
RTOS Version..................................... 8.2.100.0
Bootloader Version............................... 8.2.100.0
Emergency Image Version.......................... 8.2.100.0
Build Type....................................... DATA + WPS
System Name...................................... Cisco_66:e5:93
System Location..................................
System Contact...................................
System ObjectID.................................. 1.3.6.1.4.1.9.1.1631
IP Address....................................... 10.100.3.72
IPv6 Address..................................... ::
System Up Time................................... 0 days 0 hrs 30 mins 58 secs
System Timezone Location.........................
System Stats Realtime Interval................... 5
System Stats Normal Interval..................... 180
--More-- or (q)uit
Configured Country............................... US - United States
State of 802.11b Network......................... Enabled
State of 802.11a Network......................... Enabled
Number of WLANs.................................. 2
Number of Active Clients......................... 0
Burned-in MAC Address............................ 00:0C:29:66:E5:93
Maximum number of APs supported.................. 200
System Nas-Id....................................
WLC MIC Certificate Types........................ SHA1
Licensing Type................................... RTU
vWLC config...................................... Small
ā04-22-2016 07:16 AM
Hi guys.
I resolved my issue. There is one bug CSCur43050. I upgraded the software till the special release 8.0.104.0, added lap's mac to AP policies. All works fine
http://www.my80211.com/home/2015/1/16/field-notice-fn-63916-aireos-801000-or-cisco-ios-xe-360e-ap.html
ā11-18-2016 05:06 AM
Hi,
even I am facing the same issue.
Ap is getting IP from DHCP on switch. IP is pingable from controller
am try for AP to join controller. Its not passing the join phase.
AP is brand new AP (3802I) and controller is 5520 software version is 8.2
I am seeing discovery response sent after that its throwing below error
*spamApTask5: Nov 18 13:56:59.142: apType: Ox34 bundleApImageVer:
*spamApTask5: Nov 18 13:56:59.142: Could not find image version of bundled AP(apType: 52)!!!
*spamApTask5: Nov 18 13:56:59.142: Unable to get AP Bundled Version. Using Controller Version!!!
ā04-18-2016 08:45 AM
Have you definitely configured the right country code on the controller?
ā04-19-2016 04:17 AM
Hi Philip.
Country code was correct.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide