10-11-2022 05:48 AM
Hi,
Has anyone experienced this problem on C9800L? please suggest
%CAPWAPAC_SMGR_TRACE_MESSAGE-5-AP_JOIN_DISJOIN: Chassis 1 R/0: wncd: AP Event: AP Name: XXXX @~V Mac: xxxx.xxxx.xxxx
Session-IP: x.x.x.x[5272] x.x.x.x[5246] Disjoined Unexpected DTLS versionlic_sIm_event_notification: Received global event notification 16386
YAPMGR_TRACE_MESSAGE-3-WLC_GEN_ERR: Chassis 1 R0/0: wncd: Error in AP Join, XXXX , mac:xxxx.xxxx.xxxxModel AIR-AP18321-S-K9, AP negotiated unexpected DTLS version v1.0
10-11-2022 07:17 AM - edited 10-11-2022 07:19 AM
What version of firmware on your 9800 ?
May be AP came up with old image that uses DTLS 1.0. In typical 9800 deployments, I have seen AP uses DTLS v1.2. You can take PCAP on WLC GUI (Troubleshooting -> Packet Capture) to verify it.
HTH
Rasika
*** Pls rate all useful responses ***
10-11-2022 08:48 PM
In the previous event, these APs were used with the WLC2504, but after migrating to the C9800 there was a problem. Can we hard reset the AP or need to upgrade the AP image?
Or is there any other solution, please suggest.
10-12-2022 06:20 AM
@MM15 you did not answer @Rasika Nayanajith's question!
It's very difficult to provide accurate answers if you don't supply the correct detailed information!
Based on the very limited information you've provided I'd guess your AP has very old software and the 9800 has one of the newer 17.3 or later versions of IOS-XE which are not compatible.
Resetting the AP will not resolve that problem - you must upgrade the AP software.
10-13-2022 06:38 AM
I’m trying to upgrade AP image. 2504 using 8.5 and 9800 using 17.9. But if upgrading the AP image works, It would be difficult to upgrade one by one.
10-13-2022 01:45 PM
Hi Supakorn,
If you are talking about an WAVE1 AP, i am pretty certain that it doesn't support dtls 1.2. But considering that you are running 17.9 in 9800L Wave1 AP's are not supported.
I am not sure why this error is and I will not be worrying too much as long as AP registers to the 9800 WLC. If you have a security concern and wants to limit the dtls versions in use then you can hardcode your 9800 WLC using below command. (there is a possibilty either an unsupported AP trying to join the new WLC or an AP registered to 2504 trying to register the 17.9 with dtls v.1.0)
ap dtls-cipher <Choose the preferred cipher by using ?>
ap dtls-version <Chose the preferred dtls version>
Then you can use the below command to verify what ciphers and dtls versions ap has negotiated.
show wireless dtls connections
10-13-2022 06:55 AM - edited 10-13-2022 06:58 AM
> 2504 using 8.5
What version *exactly* is the 2504 running?
Anything older than 8.5.182.0 is almost certain to not work.
So you could try upgrading the 2504 to 8.5.182.0 if it isn't already.
If that doesn't work then you could downgrade the 9800 to the earliest release which it will support (which will probably work), migrate all the APs, and then upgrade the 9800 to your preferred release. Always remember to read the release notes carefully and note any warnings/caveats mentioned in https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html#anc10 and https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214749-tac-recommended-ios-xe-builds-for-wirele.html
Otherwise, you'll just have to do each AP individually.
10-16-2022 09:25 PM
That's good advice. I'll try upgrading to 2504 or downgrade 9800.
10-13-2022 03:19 PM
@Arshad Safrulla the output above shows it's an 1832 so it is wave 2 - I suspect running very old 8.5 code (if indeed it is running 8.5 as OP claims):
"YAPMGR_TRACE_MESSAGE-3-WLC_GEN_ERR: Chassis 1 R0/0: wncd: Error in AP Join, XXXX , mac:xxxx.xxxx.xxxxModel AIR-AP18321-S-K9, AP negotiated unexpected DTLS version v1.0
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide