10-10-2020 06:59 AM - edited 07-05-2021 12:37 PM
Hi I am trying to setup a WLAN for the first time but the WAP does not show up in the WLC. This is error I am getting from the WAP. I can ping the WLC from the WAP and vice versa.
*Oct 10 14:54:52.085: %LWAPP-3-CLIENTERRORLOG: Peer certificate verification failed
*Oct 10 14:54:52.085: %CAPWAP-3-ERRORLOG: Certificate verification failed!
*Oct 10 14:54:52.085: DTLS_CLIENT_ERROR: ../capwap/capwap_wtp_dtls.c:348 Certificate verified failed!
*Oct 10 14:54:52.085: %DTLS-4-BAD_CERT: Certificate verification failed. Peer IP: 192.168.1.3
*Oct 10 14:54:52.085: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to 192.168.1.3:5246
*Oct 10 14:54:52.086: %DTLS-3-BAD_RECORD: Erroneous record received from 192.168.1.3: Malformed Certificate
*Oct 10 14:54:52.086: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 192.168.1.3:5246
*Oct 10 14:54:52.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.1.3 peer_port: 5246
*Oct 10 14:54:52.085: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed. The certificate (SN: 18EB5605000000263235
10-10-2020 09:11 AM
10-11-2020 01:33 AM
Controller 2100 series. Image version 6.0.196.0. AP model AIR-LAP1142N-E-K9. This is the only AP I have.
Show version ---
Cisco IOS Software, C1140 Software (C1140-K9W8-M), Version 12.4(23c)JA2, RELEASE SOFTWARE (fc3)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2011 by Cisco Systems, Inc.
Compiled Wed 13-Apr-11 12:50 by prod_rel_team
ROM: Bootstrap program is C1140 boot loader
BOOTLDR: C1140 Boot Loader (C1140-BOOT-M) Version 12.4(23c)JA, RELEASE SOFTWARE (fc3)
AP003a.99eb.61f8 uptime is 27 minutes
System returned to ROM by power-on
System image file is "flash:/c1140-k9w8-mx.124-23c.JA2/c1140-k9w8-mx.124-23c.JA2"
This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.
A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
If you require further assistance please contact us by sending email to
export@cisco.com.
----
AP003a.99eb.61f8#show inventory
NAME: "AP1140", DESCR: "Cisco Aironet 1140 Series (IEEE 802.11n) Access Point"
PID: AIR-LAP1142N-E-K9 , VID: V04, SN: FCZ1526W482
----
This is what happens as soon as the AP is booted up.
*Oct 11 09:30:42.164: %LINK-3-UPDOWN: Interface Dot11Radio0, changed state to up
*Oct 11 09:30:42.176: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to reset
*Oct 11 09:30:42.190: %LINK-3-UPDOWN: Interface Dot11Radio1, changed state to up
*Oct 11 09:30:52.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.1.3 peer_port: 5246
*Oct 11 09:30:52.000: %CAPWAP-5-CHANGED: CAPWAP changed state to
*Oct 11 09:30:52.085: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed. The certificate (SN: 18EB5605000000263235) has expired. Validity period ended on 01:21:08 UTC Jun 1 2020
*Oct 11 09:30:52.086: %LWAPP-3-CLIENTERRORLOG: Peer certificate verification failed
*Oct 11 09:30:52.086: %CAPWAP-3-ERRORLOG: Certificate verification failed!
*Oct 11 09:30:52.086: DTLS_CLIENT_ERROR: ../capwap/capwap_wtp_dtls.c:348 Certificate verified failed!
*Oct 11 09:30:52.086: %DTLS-4-BAD_CERT: Certificate verification failed. Peer IP: 192.168.1.3
*Oct 11 09:30:52.086: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to 192.168.1.3:5246
*Oct 11 09:30:52.087: %DTLS-3-BAD_RECORD: Erroneous record received from 192.168.1.3: Malformed Certificate
*Oct 11 09:30:52.087: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 192.168.1.3:5246
10-11-2020 02:51 AM
- https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html
However the particular ap-model is also very old. Consider using a more modern ap
M.
10-11-2020 10:06 AM
10-11-2020 12:10 AM
- Check compatibility parameters (ap-model. controller-model . software versions, ....) with :
https://www.cisco.com/c/en/us/td/docs/wireless/compatibility/matrix/compatibility-matrix.html
M.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide