02-12-2024 06:01 AM
Hi,
I have some APs which are not connecting to 9800 controllers.
Reason for last AP connection failure is showing as "DTLS close alert from peer" or "DTLS handshake expired." Can anybody please explain how to resolve this issue?
Thanks in advance.
02-12-2024 06:05 AM - edited 02-12-2024 06:07 AM
What IOS XE code running on Cat 9800 (worth upgrading 17.9.4a) most problem Fixed
what AP Model ? Hope you have Licenses.
is the AP and WLC in same VLAN - is there any Firewall between then you need to Open some ports for the AP to register with WLC.
APWAP uses the UDP Ports 5246 (for CAPWAP Control) and 5247 (for CAPWAP Data).
connect console to AP and post complete boot log until failed to register to WLC.
check the AP joining process :
also try clearing the config on AP :
# clear lwapp private-config
02-13-2024 02:48 AM
The WLC is 9800-40 series and code is 17.9.4. Most of the AP models are 2802I-B-K9 and 2802E-B-K9
02-13-2024 01:57 PM
How many APs are currently connected to the controller?
02-20-2024 02:01 PM
Around 215 APs are currently connected to WLC.
02-13-2024 04:29 PM
None of them joining to WLC or only few, can you connect the console to AP post complete boot logs
02-20-2024 02:00 PM
Only few APs are not joining, like 5 to 10 APs.
02-18-2024 02:25 AM
Do you have the latest SMUs and APSP installed?
17.9.5 is released now and contains all those same fixes plus some extra ones so might also want to consider that.
02-20-2024 01:58 PM - edited 02-20-2024 02:25 PM
Yes, we have installed latest SMUs. Regarding APSP I'm not sure. I am not able see any file added in APSP tab under Software Management tab in the controller.
02-20-2024 05:23 PM - edited 02-20-2024 05:24 PM
"show install summ"
APSP8 is CSCwi44524
https://software.cisco.com/download/home/286316412/type/286325254/release/17.9.4
"sh ap image file summ" will show AP image version 17.9.4.208 for APSP8.
If you don't have the APSP installed then you're missing numerous AP fixes.
https://www.cisco.com/web/software/286325254/165945/C9800-universalk9_wlc.17.09.04.CSCwi44524.txt
https://www.cisco.com/web/software/286325254/165945/Release_Notes_9800_APSP_17_9_4.pdf
02-12-2024 06:43 AM
You can also check the following AP join process troubleshooting guide to verify the issue
4.- In case the errors are seen in the DTLS phase we can check which type of certificate and ciphers are used for AP DTLS handshake.
show wireless certification config !! Check DTLS version and cipher suite
show wireless management trustpoint !! Type of certificate used
show wireless dtls connections !! Show if DTLS is established for capwap control/data ports used
Jagan Chowdam
/**Please rate helpful responses**/
02-12-2024 02:05 PM
What are the model of APs involved?
How many APs does the controller currently have?
What firmware is the controller on?
What is the uptime of the controller?
02-20-2024 11:31 PM
- Have a checkup of the 9800 controller(s) configuration(s) with the CLI command show tech wireless and feed the output into
Wireless Config Analyzer
- Use commands from : https://logadvisor.cisco.com/logadvisor/wireless/9800/9800APJoin
for further troubleshooting
- Checkout AP stats using : https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#anc4
M.
07-15-2024 10:23 PM
In my case, it was due to IP address conflict / duplicate IP address of APs
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide