04-04-2025 05:49 AM
Hello Guys.
I am established lab Wireless Topology for testing purposes . I am using vWLC(8.10.196.0) with 2xAPs AIR-LAP1042N-E-K9 (Cisco IOS Software, C1040 Software (C1140-RCVK9W8-M), Version 12.4(23c)JA). am getting following error during AP joining to vWLC. Is there any possibilty to joins olds APs with vWLC.
***********************************************************************
*Apr 4 13:27:55.999: %CAPWAP-3-ERRORLOG: Go join a capwap controller
*Apr 4 13:26:51.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.0.150 peer_port: 5246
*Apr 4 13:26:51.014: %LWAPP-3-CLIENTERRORLOG: Peer certificate verification failed
*Apr 4 13:26:51.014: %CAPWAP-3-ERRORLOG: Certificate verification failed!
*Apr 4 13:26:51.014: DTLS_CLIENT_ERROR: ../capwap/capwap_wtp_dtls.c:333 Certificate verified failed!
*Apr 4 13:26:51.014: %DTLS-4-BAD_CERT: Certificate verification failed. Peer IP: 192.168.0.150
*Apr 4 13:26:51.014: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to 192.168.0.150:5246
*Apr 4 13:26:51.014: %DTLS-3-BAD_RECORD: Erroneous record received from 192.168.0.150: Malformed Certificate
*Apr 4 13:26:51.015: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 192.168.0.150:5246
*Apr 4 13:26:51.015: %CAPWAP-3-ERRORLOG: Invalid event 38 & state 3 combination.
Translating "CISCO-CAPWAP-CONTROLLER"...domain server (255.255.255.255)
*Apr 4 13:27:56.000: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
*Apr 4 13:27:56.000: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
*Apr 4 13:27:56.017: %CAPWAP-3-ERRORLOG: Could Not resolve CISCO-CAPWAP-CONTROLLER
*Apr 4 13:28:06.018: %CAPWAP-3-ERRORLOG: Go join a capwap controller
*Apr 4 13:29:14.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.0.150 peer_port: 5246
*Apr 4 13:29:14.000: %CAPWAP-5-CHANGED: CAPWAP changed state to
*Apr 4 13:29:14.010: %LWAPP-3-CLIENTERRORLOG: Peer certificate verification failed
*Apr 4 13:29:14.010: %CAPWAP-3-ERRORLOG: Certificate verification failed!
*Apr 4 13:29:14.010: DTLS_CLIENT_ERROR: ../capwap/capwap_wtp_dtls.c:333 Certificate verified failed!
*Apr 4 13:29:14.011: %DTLS-4-BAD_CERT: Certificate verification failed. Peer IP: 192.168.0.150
*Apr 4 13:29:14.011: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to 192.168.0.150:5246
*Apr 4 13:29:14.011: %DTLS-3-BAD_RECORD: Erroneous record received from 192.168.0.150: Malformed Certificate
*Apr 4 13:29:14.011: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 192.168.0.150:5246
**************************************************************************************************
04-04-2025 05:53 AM
04-04-2025 06:41 AM
FYI : https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html
M.
04-04-2025 04:46 PM
1040/1140 last firmware support is 8.4.X.X.
04-07-2025 02:48 AM
It means that I should go with Cisco IOS vWLC 8.4 or below right. ? or still any further workaround be there. ?
*****************************************************
AP#show capwap ip config
LWAPP Static IP Configuration
IP Address 192.168.0.211
IP netmask 255.255.255.0
Default Gateway 192.168.0.1
Primary Controller 192.168.0.150
Translating "CISCO-CAPWAP-CONTROLLER"...domain server (255.255.255.255)
*Apr 7 09:48:05.999: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 192.168.0.150:5246
*Apr 7 09:48:06.059: %LWAPP-3-CLIENTERRORLOG: LWAPP LED Init: incorrect led state 255
*Apr 7 09:48:06.097: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to administratively down
*Apr 7 09:48:06.098: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to administratively down
*Apr 7 09:48:06.100: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to up
*Apr 7 09:48:06.190: %LINK-6-UPDOWN: Interface Dot11Radio1, changed state to up
*Apr 7 09:48:06.195: %CAPWAP-3-ERRORLOG: Could Not resolve CISCO-CAPWAP-CONTROLLER
*Apr 7 09:48:07.097: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to down
*Apr 7 09:48:07.126: %LINK-6-UPDOWN: Interface Dot11Radio1, changed state to down
*Apr 7 09:48:07.131: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to reset
*Apr 7 09:48:08.121: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to up
*Apr 7 09:48:08.126: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to down
*Apr 7 09:48:08.153: %LINK-6-UPDOWN: Interface Dot11Radio1, changed state to up
*Apr 7 09:48:08.159: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to down
*Apr 7 09:48:08.164: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset
*Apr 7 09:48:09.153: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to up
*Apr 7 09:48:09.159: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to down
*Apr 7 09:48:09.185: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to up
*Apr 7 09:48:10.185: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to up
*Apr 7 09:48:16.198: %CAPWAP-3-ERRORLOG: Selected MWAR 'ciscovwlc'(index 0).
*Apr 7 09:48:16.198: %CAPWAP-3-ERRORLOG: Go join a capwap controller
*Apr 7 09:48:18.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.0.150 peer_port: 5246
*Apr 7 09:48:18.812: %CAPWAP-5-DTLSREQSUCC: DTLS connection created sucessfully peer_ip: 192.168.0.150 peer_port: 5246
*Apr 7 09:48:18.813: %CAPWAP-5-SENDJOIN: sending Join Request to 192.168.0.150
*Apr 7 09:48:23.812: %CAPWAP-5-SENDJOIN: sending Join Request to 192.168.0.150
**********************************************************
AP#show version | inc flash
System image file is "flash:/c1140-k9w8-mx.152-4.JB5/c1140-k9w8-mx.152-4.JB5"
32K bytes of flash-simulated non-volatile configuration memory.
**********************************************************
04-07-2025 03:06 AM
04-07-2025 06:27 AM
Now I have vWLC version 8.2.170.0 and AP has following IOS. any suggestions to test vWLC features on lab eviornmwent. I can upgrade/degrade IOS from both APs/vWLCs.
Cisco IOS Software, C1040 Software (C1140-K9W8-M), Version 15.2(4)JB5, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2014 by Cisco Systems, Inc.
Compiled Thu 01-May-14 23:13 by prod_rel_team
ROM: Bootstrap program is C1040 boot loader
BOOTLDR: C1040 Boot Loader (C1140-BOOT-M) Version 12.4(23c)JA3, RELEASE SOFTWARE (fc1)
AP6c20.5648.ebad uptime is 42 minutes
System returned to ROM by reload
System image file is "flash:/c1140-k9w8-mx.152-4.JB5/c1140-k9w8-mx.152-4.JB5"
********************************************************************
AP6c20.5648.ebad#show capwap ip config
LWAPP Static IP Configuration
IP Address 192.168.0.211
IP netmask 255.255.255.0
Default Gateway 192.168.0.1
Primary Controller 192.168.0.91
******************************************************************************************************
*Apr 7 14:04:27.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.0.91 peer_port: 5246
*Apr 7 14:04:27.814: %CAPWAP-5-DTLSREQSUCC: DTLS connection created sucessfully peer_ip: 192.168.0.91 peer_port: 5246
*Apr 7 14:04:27.816: %CAPWAP-5-SENDJOIN: sending Join Request to 192.168.0.91
*Apr 7 14:04:32.814: %CAPWAP-5-SENDJOIN: sending Join Request to 192.168.0.91
Translating "CISCO-CAPWAP-CONTROLLER"...domain server (255.255.255.255)
*Apr 7 14:05:26.999: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 192.168.0.91:5246
*Apr 7 14:05:27.058: %LWAPP-3-CLIENTERRORLOG: LWAPP LED Init: incorrect led state 255
*Apr 7 14:05:27.096: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to administratively down
*Apr 7 14:05:27.097: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to administratively down
*Apr 7 14:05:27.100: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to up
*Apr 7 14:05:27.188: %LINK-6-UPDOWN: Interface Dot11Radio1, changed state to up
*Apr 7 14:05:27.190: %CAPWAP-3-ERRORLOG: Could Not resolve CISCO-CAPWAP-CONTROLLER
*Apr 7 14:05:28.096: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to down
*Apr 7 14:05:28.126: %LINK-6-UPDOWN: Interface Dot11Radio1, changed state to down
*Apr 7 14:05:28.131: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to reset
*Apr 7 14:05:29.120: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to up
*Apr 7 14:05:29.126: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to down
*Apr 7 14:05:29.152: %LINK-6-UPDOWN: Interface Dot11Radio1, changed state to up
*Apr 7 14:05:29.158: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to down
*Apr 7 14:05:29.163: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset
*Apr 7 14:05:30.152: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to up
*Apr 7 14:05:30.158: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to down
*Apr 7 14:05:30.184: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to up
*Apr 7 14:05:31.184: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to up
*Apr 7 14:05:37.193: %CAPWAP-3-ERRORLOG: Selected MWAR 'vWLC8.2'(index 0).
*Apr 7 14:05:37.193: %CAPWAP-3-ERRORLOG: Go join a capwap controller
*Apr 7 14:05:39.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.0.91 peer_port: 5246
*Apr 7 14:05:39.811: %CAPWAP-5-DTLSREQSUCC: DTLS connection created sucessfully peer_ip: 192.168.0.91 peer_port: 5246
*Apr 7 14:05:39.812: %CAPWAP-5-SENDJOIN: sending Join Request to 192.168.0.91
AP6c20.5648.ebad#show ip int br
Interface IP-Address OK? Method Status Protocol
BVI1 192.168.0.211 YES TFTP up up
Dot11Radio0 unassigned NO unset up up
Dot11Radio1 unassigned NO unset up up
GigabitEthernet0 unassigned NO unset up up
***************************************************
04-07-2025 03:58 PM
What is the serial number of the AP?
04-08-2025 12:18 AM
sent per message. regards
04-08-2025 01:20 AM
Let's try this: Roll back the year of the WLC to 2020 and reboot the AP.
04-13-2025 05:21 AM
Did you get it working @uni1389 ?
Even with the right software you still need to follow all the instructions in FN63942, in the right order.
Did you configure config ap cert-expiry-ignore mic enable on the WLC?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide