04-20-2016 08:18 AM - edited 07-05-2021 04:55 AM
We currently have several remote sites that connect back to our data center via dual IPSec VPN Tunnels. We are trying to installed the AP 3702i at these locations and they will not register to the WLC. I am able to ping the WLCs from the sites in question. We are connecting the AP's to a Cisco 3850 switch. The device that is handling the VPN tunnels is a Juniper Firewall. The Firewall is also the device that his assigning the LAN DHCP addresses. I can see that they devices are grabbing an address over and over. When I did a debug at the switch level, I could see the AP's continually reboot.
We have other working sites that are using the 3850 switches but they are primarily on MPLS using the same switches model
We are trying to get the VPN sites to work now until we are able to migrate them over to our MPLS network.
Any help would be appreciated!
04-20-2016 10:32 AM
normally when the AP fails to join the WLC via static ip and DHCP ip it will reboot .
so have you checked if the AP is able to discover the WLC ?
how does the AP learn the WLC ip address statically or from option 43 or other method?
are the capwap ports opened between the AP and the WLC ?
can you share AP logging ?
can you share "show ap join stats <AP name>" from the WLC
04-20-2016 10:36 AM
How do I determine if the AP is able to discover the WLC?
What capwap ports should be open between the AP and WLC?
AP logging shared from where and how do I get it?
I just use the MAC for the AP Name?
04-20-2016 10:38 AM
you can check on the WLC using command "show ap join stats <AP name>",
you can collect "show logging " from the AP .
you can collect "debug capwap client events" from the AP.
04-20-2016 10:43 AM
So, I would need to be directly connected to AP via console port, correct? What is the login name and password for console if the AP's are just right out of the box. Also, there are no join status on the WLC for the AP's I am working with
04-20-2016 10:43 AM
cisco/Cisco
04-20-2016 10:44 AM
I will give that a try and be back.
04-20-2016 11:25 AM
04-20-2016 12:51 PM
AP is unable to discover the WLC ip address .
try one of the below :
1)add DNS entery for :
CISCO-CAPWAP-CONTROLLER.SSG5-Serial <WLC ip>
2)issue this command on the AP :
debug capwap console cli
capwap ap controller ip address <WLC ip>
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide