09-02-2017 08:21 PM - edited 07-05-2021 07:36 AM
New to Wireless...trying to setup home lab. The WLC config is attached.
AP has the following outputs:
Boot Output
IOS Bootloader - Starting system. flash is writable Tide XL MB - 40MB of flash Xmodem file system is available. flashfs[0]: 77 files, 9 directories flashfs[0]: 0 orphaned files, 0 orphaned directories flashfs[0]: Total bytes: 41158656 flashfs[0]: Bytes used: 39028224 flashfs[0]: Bytes available: 2130432 flashfs[0]: flashfs fsck took 12 seconds. Base Ethernet MAC address: 00:81:c4:0a:85:c0 Ethernet speed is 1000 Mb - FULL Duplex Loading "ap3g2-rcvk9w8-mx/ap3g2-rcvk9w8-mx"...ap3g2-rcvk9w8-mx/ap3g2-rcvk9w8-mx: permission denied Error loading "ap3g2-rcvk9w8-mx/ap3g2-rcvk9w8-mx" Interrupt within 5 seconds to abort boot process. Loading "flash:/ap3g2-rcvk9w8-mx/ap3g2-rcvk9w8-mx"...######################### File "flash:/ap3g2-rcvk9w8-mx/ap3g2-rcvk9w8-mx" uncompressed and installed, entry point: 0x2003000 executing... Secondary Bootloader - Starting system. Montserrat Board 40MB format Tide XL MB - 40MB of flash Xmodem file system is available. flashfs[0]: 77 files, 9 directories flashfs[0]: 0 orphaned files, 0 orphaned directories flashfs[0]: Total bytes: 41158656 flashfs[0]: Bytes used: 39028224 flashfs[0]: Bytes available: 2130432 flashfs[0]: flashfs fsck took 13 seconds. flashfs[1]: 0 files, 1 directories flashfs[1]: 0 orphaned files, 0 orphaned directories flashfs[1]: Total bytes: 12257280 flashfs[1]: Bytes used: 1024 flashfs[1]: Bytes available: 12256256 flashfs[1]: flashfs fsck took 0 seconds. Base Ethernet MAC address: 00:81:c4:0a:85:c0 Boot CMD: 'boot ap3g2-rcvk9w8-mx/ap3g2-rcvk9w8-xx;flash:/ap3g2-rcvk9w8-mx/ap3g2-rcvk9w8-xx' Loading "ap3g2-rcvk9w8-mx/ap3g2-rcvk9w8-xx"...ap3g2-rcvk9w8-mx/ap3g2-rcvk9w8-xx: permission denied Error loading "ap3g2-rcvk9w8-mx/ap3g2-rcvk9w8-xx" Interrupt within 5 seconds to abort boot process. Unable to locate IOS image with name **xx**. Boot CMD: 'flash:/ap3g2-rcvk9w8-mx/ap3g2-rcvk9w8-xx' Loading "flash:/ap3g2-rcvk9w8-mx/ap3g2-rcvk9w8-xx"...############################# File "flash:/ap3g2-rcvk9w8-mx/ap3g2-rcvk9w8-xx" uncompressed and installed, entry point: 0x1003000 executing... Restricted Rights Legend Use, duplication, or disclosure by the Government is subject to restrictions as set forth in subparagraph (c) of the Commercial Computer Software - Restricted Rights clause at FAR sec. 52.227-19 and subparagraph (c) (1) (ii) of the Rights in Technical Data and Computer Software clause at DFARS sec. 252.227-7013. cisco Systems, Inc. 170 West Tasman Drive San Jose, California 95134-1706 Cisco IOS Software, C3700 Software (AP3G2-RCVK9W8-M), Version 15.3(3)JF, RELEASE SOFTWARE (fc4) Technical Support: http://www.cisco.com/techsupport Copyright (c) 1986-2017 by Cisco Systems, Inc. Compiled Tue 25-Jul-17 02:20 by prod_rel_team Montserrat Board 40MB format Tide XL MB - 40MB of flash Initializing flashfs... flashfs[2]: WARNING - Unable to allocate backup blocks. Please free some space on the flash file system. flashfs[2]: 77 files, 9 directories flashfs[2]: 0 orphaned files, 0 orphaned directories flashfs[2]: Total bytes: 41029632 flashfs[2]: Bytes used: 39028224 flashfs[2]: Bytes available: 2001408 flashfs[2]: flashfs fsck took 13 seconds. flashfs[2]: Initialization complete. flashfs[3]: 0 files, 1 directories flashfs[3]: 0 orphaned files, 0 orphaned directories flashfs[3]: Total bytes: 11999232 flashfs[3]: Bytes used: 1024 flashfs[3]: Bytes available: 11998208 flashfs[3]: flashfs fsck took 0 seconds. flashfs[3]: Initialization complete....done Initializing flashfs. This product contains cryptographic features and is subject to United States and local country laws governing import, export, transfer and use. Delivery of Cisco cryptographic products does not imply third-party authority to import, export, distribute or use encryption. Importers, exporters, distributors and users are responsible for compliance with U.S. and local country laws. By using this product you agree to comply with applicable laws and regulations. If you are unable to comply with U.S. and local laws, return this product immediately. A summary of U.S. laws governing Cisco cryptographic products may be found at: http://www.cisco.com/wwl/export/crypto/tool/stqrg.html If you require further assistance please contact us by sending email to export@cisco.com. cisco AIR-AP3702I-UXK9 (PowerPC) processor (revision A0) with 376814K/134656K bytes of memory. Processor board ID FCW2024N8Z3 PowerPC CPU at 800Mhz, revision number 0x2151 Last reset from power-on LWAPP image version 8.5.103.0 Access Point Type: World Mode 1 Gigabit Ethernet interface 32K bytes of flash-simulated non-volatile configuration memory. Base ethernet MAC Address: 00:81:C4:0A:85:C0 Part Number : 73-15243-01 PCB Serial Number : FOC20234V8S Top Assembly Part Number : 068-100398-04 Top Assembly Serial Number : FCW2024N8Z3 Top Revision Number : A0 Product/Model Number : AIR-AP3702I-UXK9 % Please define a domain-name first. Press RETURN to get started! *Mar 1 00:00:15.779: %LWAPP-3-CLIENTERRORLOG: Load nvram:/lwapp_ap.cfg config failed, trying backup... *Mar 1 00:00:15.779: %LWAPP-3-CLIENTERRORLOG: Load nvram:/lwapp_ap.cfg.bak config failed... *Mar 1 00:00:15.983: SCHED: Ethernet Bridge Process: install watched boolean System Initialized(4172444), os:1 ah:0 *Mar 1 00:00:17.083: %LWAPP-4-CLIENTEVENTLOG: PnP waiting for capwap init *Mar 1 00:00:17.083: %LINK-6-UPDOWN: Interface GigabitEthernet0, changed state to up *Mar 1 00:00:17.947: %SYS-5-RESTART: System restarted -- Cisco IOS Software, C3700 Software (AP3G2-RCVK9W8-M), Version 15.3(3)JF, RELEASE SOFTWARE (fc4) Technical Support: http://www.cisco.com/techsupport Copyright (c) 1986-2017 by Cisco Systems, Inc. Compiled Tue 25-Jul-17 02:20 by prod_rel_team *Mar 1 00:00:17.947: %SNMP-5-COLDSTART: SNMP agent on host ap is undergoing a cold start *Mar 1 00:00:18.003: SCHED: Ethernet Bridge Process: remove watched boolean System Initialized(4172444) *Mar 1 00:00:18.003: SCHED: Ethernet Bridge Process: install watched queue Soap BVI input queue(4165E84), os:0 ah:0 *Mar 1 00:00:18.071: %LWAPP-3-CLIENTERRORLOG: Load nvram:/lwapp_ap.cfg config failed, trying backup... *Mar 1 00:00:18.075: %LWAPP-3-CLIENTERRORLOG: Load nvram:/lwapp_ap.cfg.bak config failed... *Mar 1 00:00:18.079: %CAPWAP-5-AP_EASYADMIN_INFO: AP Easy Admin information - EASY_ADMIN is not set, turn off easy admin service! *Mar 1 00:00:18.079: %CAPWAP-5-AP_EASYADMIN_INFO: AP Easy Admin information - Easy Admin is not enabled, turn it off! *Mar 1 00:00:18.079: spamInitRadCfg: recovery image default mode 0 lwapp_crypto_init: MIC Present and Parsed Successfully *Mar 1 00:00:18.243: %SSH-5-ENABLED: SSH 2.0 has been enabled *Mar 1 00:00:19.003: %LINEPROTO-5-UPDOWN: Line protocol on Interface BVI1, changed state to up *Mar 1 00:00:22.887: DPAA Initialization Complete *Mar 1 00:00:22.887: %SYS-3-HARIKARI: Process DPAA INIT top-level routine exited *Mar 1 00:00:23.887: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0, changed state to up *Mar 1 00:00:25.887: %LINK-6-UPDOWN: Interface BVI1, changed state to down *Mar 1 00:00:26.887: %LINEPROTO-5-UPDOWN: Line protocol on Interface BVI1, changed state to down *Mar 1 00:00:30.007: %LINK-6-UPDOWN: Interface BVI1, changed state to up *Mar 1 00:00:31.007: %LINEPROTO-5-UPDOWN: Line protocol on Interface BVI1, changed state to up *Mar 1 00:00:33.127: %DHCP-6-ADDRESS_ASSIGN: Interface BVI1 assigned DHCP address 172.20.20.78, mask 255.255.255.0, hostname AP0081.c40a.85c0 %Default route without gateway, if not a point-to-point interface, may impact performance *Mar 1 00:00:36.799: %LWAPP-3-CLIENTERRORLOG: Load nvram:/lwapp_ap.cfg config failed, trying backup... *Mar 1 00:00:36.799: %LWAPP-3-CLIENTERRORLOG: Load nvram:/lwapp_ap.cfg.bak config failed... *Mar 1 00:00:36.803: %CAPWAP-3-EVENTLOG: No Config Present. PNP required *Mar 1 00:00:36.803: Cert ISSUER (39): cn=Cisco Manufacturing CA SHA2,o=Cisco %Error opening flash:/capwap-saved-config (No such file or directory) %Error opening flash:/capwap-saved-config-bak (No such file or directory)creating PnP template view Not in Bound state. *Mar 1 00:00:57.451: %DHCP-6-ADDRESS_ASSIGN: Interface BVI1 assigned DHCP address 172.20.20.79, mask 255.255.255.0, hostname AP0081.c40a.85c0 *Mar 1 00:01:08.123: %CDP_PD-4-POWER_OK: Full power - NEGOTIATED inline power source Not in Bound state. *Mar 1 00:01:27.331: %LWAPP-4-CLIENTEVENTLOG: Invoking capwap discovery *Mar 1 00:01:32.451: %DHCP-6-ADDRESS_ASSIGN: Interface BVI1 assigned DHCP address 172.20.20.80, mask 255.255.255.0, hostname AP0081.c40a.85c0 %No matching route to delete *Mar 1 00:01:38.331: %CAPWAP-5-DHCP_OPTION_43: Controller address 172.20.100.5 obtained through DHCP *Mar 1 00:01:57.331: AP has SHA2 MIC certificate - Using SHA2 MIC certificate for DTLS. *Sep 3 03:07:20.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 172.20.100.5 peer_port: 5246 *Sep 3 03:07:20.039: %PKI-3-CERTIFICATE_INVALID_NOT_YET_VALID: Certificate chain validation has failed. The certificate (SN: 1000) is not yet valid Validity period starts on 06:12:18 UTC Sep 3 2017Peer certificate verification failed 001A *Sep 3 03:07:20.039: DTLS_CLIENT_ERROR: ../capwap/base_capwap/capwap/base_capwap_wtp_dtls.c:509 Certificate verified failed! *Sep 3 03:07:20.039: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to 172.20.100.5:5246 *Sep 3 03:07:20.039: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 172.20.100.5:5246 *Sep 3 03:07:28.471: %CDP_PD-4-POWER_OK: Full power - NEGOTIATED inline power source *Sep 3 03:08:20.011: Delete of backup image not donewith status 1
This is
Cisco IOS Software, C3700 Software (AP3G2-RCVK9W8-M), Version 15.3(3)JF, RELEASE SOFTWARE (fc4) Technical Support: http://www.cisco.com/techsupport Copyright (c) 1986-2017 by Cisco Systems, Inc. Compiled Tue 25-Jul-17 02:20 by prod_rel_team ROM: Bootstrap program is C3700 boot loader BOOTLDR: C3700 Boot Loader (AP3G2-BOOT-M) LoaderVersion 15.2(4)JB, RELEASE SOFTWARE (fc1) AP0081.c40a.85c0 uptime is 4 minutes System returned to ROM by power-on System image file is "flash:/ap3g2-rcvk9w8-mx/ap3g2-rcvk9w8-xx" Last reload reason: This product contains cryptographic features and is subject to United States and local country laws governing import, export, transfer and use. Delivery of Cisco cryptographic products does not imply third-party authority to import, export, distribute or use encryption. Importers, exporters, distributors and users are responsible for compliance with U.S. and local country laws. By using this product you agree to comply with applicable laws and regulations. If you are unable to comply with U.S. and local laws, return this product immediately. A summary of U.S. laws governing Cisco cryptographic products may be found at: http://www.cisco.com/wwl/export/crypto/tool/stqrg.html If you require further assistance please contact us by sending email to export@cisco.com. cisco AIR-AP3702I-UXK9 (PowerPC) processor (revision A0) with 376814K/134656K bytes of memory. Processor board ID FCW2024N8Z3 PowerPC CPU at 800Mhz, revision number 0x2151 Last reset from power-on LWAPP image version 8.5.103.0 Access Point Type: World Mode 1 Gigabit Ethernet interface 32K bytes of flash-simulated non-volatile configuration memory. Base ethernet MAC Address: 00:81:C4:0A:85:C0 Part Number : 73-15243-01 PCB Serial Number : FOC20234V8S Top Assembly Part Number : 068-100398-04 Top Assembly Serial Number : FCW2024N8Z3 Top Revision Number : A0 Product/Model Number : AIR-AP3702I-UXK9 Configuration register is 0xF
Inventory
AP0081.c40a.85c0>show inventory NAME: "AP3700", DESCR: "Cisco Aironet 3700 Series (IEEE 802.11ac) Access Point" PID: AIR-AP3702I-UXK9 , VID: V04, SN: FCW2024N8Z3
Capwap info:
AP0081.c40a.85c0>show capwap client detailrcb Control packet retransmission interval: 255 Control packet retransmission count: 255 Radio 0 ------------------------------------------------------------------ ATE Mode: 0 ATE Violation: 0 ATE Stealing: 0 ------------------------------------------------------------------ RLDP State = 0 TxPower NumOfVaps : 0 BSSID : 0 :0 :0 :0 :0 :0 All WLANs Radio 1 ------------------------------------------------------------------ ATE Mode: 0 ATE Violation: 0 ATE Stealing: 0 ------------------------------------------------------------------ RLDP State = 0 TxPower NumOfVaps : 0 BSSID : 0 :0 :0 :0 :0 :0 All WLANs Radio 2 ------------------------------------------------------------------ ATE Mode: 0 ATE Violation: 0 ATE Stealing: 0 ------------------------------------------------------------------ RLDP State = 0 TxPower NumOfVaps : 0 BSSID : 0 :0 :0 :0 :0 :0 All WLANs Band Select Count 0, Threshold 0, Ageout 0, MinRSSI 0, MidRSSI 0, DualAgeOut 0 Band Select client 0, aged-out 0, replaced 0 Dual Band client 0, added 0, aged-out 0,replaced 0, detected 0 Install On Backhaul: 0 Backhaul Resilient: 0 ATE Buckets: 0:0 1:0 2:0 3:0 4:0 5:0 6:0 7:0 8:0 9:0 10:0 11:0 12:0 13:0 14:0 15:0
09-02-2017 09:27 PM
WTF. This looks like CSCur43050 but your AP was manufactured in 2016.
Kindly post the complete output to the following commands:
1. WLC: sh sysinfo; and
2. WLC: sh time
09-03-2017 09:44 AM
I figured it out, I am completely baffled why it did this but the vWLC generated a self significat cert thats validity didnt start for 12 hours...
I spun up the vWLC at 6PM EST but the cert wasnt valid until 6AM the next day in the future so the AP was failing the cert validation against the WLC.
Odd...if anyone has an explantion on how to avoid this I would love to know as in the setup process I saw no place to change this and there isnt much documentation around it.
Best,
Dan
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide