cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1451
Views
4
Helpful
4
Replies

APs not joining vWLC

ArSh21
Level 1
Level 1

Hello, 

I'm facing an issue of APs (different models) not joining a newly installed vWLC (v 8.10)

The APs were previously joined in WLC 2504, but the 2504 failed and we cannot repair it. 

So we configured a vWLC, but APs don't join. These are the logs I get from one of the APs (model 702i with IOS 15.3):

*May 17 13:41:35.999: %CAPWAP-3-EVENTLOG: Wait DTLS timer has expired
*May 17 13:41:35.999: %CAPWAP-3-EVENTLOG: Dtls session establishment failed
*May 17 13:41:35.999: %CAPWAP-3-EVENTLOG: CAPWAP State: DTLS Teardown.
*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: DTLS session cleanup completed. Restarting capwap state machine.
*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: Previous CAPWAP state was DTLS Setup,numOfCapwapDiscoveryResp = 3.
*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: Attempting to join next controller
*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: Go Join the next controller

*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: Calling wtpGetAcToJoin from timer expiry.
*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: Selected MWAR 'Cisco-000c.29a4.b9ae' (index 0).
*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: Ap mgr count=0
*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: Go Join the next controller

*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: Remove discovery response at index 0

*May 17 13:41:41.003: AP has SHA2 MIC certificate - Using SHA2 MIC certificate for DTLS.
Peer certificate verification failed 001A

*May 17 13:41:41.055: DTLS_CLIENT_ERROR: ../capwap/base_capwap/capwap/base_capwap_wtp_dtls.c:496 Certificate verified failed!

I checked the community the FN-63942 but the work around don't work. 

 

Any idea how to solve this? 

Thank You!

4 Replies 4

Hi

 I have a few things you can check.

Date and time on the WLC

Activate licensing (even evaluation licensing needs to be enable)

Make sure you enable the correct country for your APs.

make sure reachabilityis fine

Last factory reset one AP to test, in case all the above is OK.

 

Hello Flavio,

Date and time are correct (I even tried the workaround of changing the time).

License is activated (it is evaluation and it is enabled).

Country is correct.

Reachability is ok, both can ping each other.

I will factory reset the AP and get back to you. 

 

Thank You!

Rich R
VIP
VIP

@Flavio Miranda has summarised all the key points.
All I will add is make sure your software is up to date per TAC recommended (link below) - currently 8.10.185.0 - and review all the field notice links below.

PS: You might want to read FN63942 again carefully - you need to perform all the steps in the right order.
Workaround config on WLC
Set time back
AP joins, downloads new software and workaround config.
Only at that point is the AP "fixed".

ArSh21
Level 1
Level 1

Hello Rich,

Thank you very much! 

We actually dropped the vWLC and got an appliance.

The APs connected with the appliance right away. 

Thank you!

 

Review Cisco Networking for a $25 gift card