05-17-2023 06:03 AM
Hello,
I'm facing an issue of APs (different models) not joining a newly installed vWLC (v 8.10)
The APs were previously joined in WLC 2504, but the 2504 failed and we cannot repair it.
So we configured a vWLC, but APs don't join. These are the logs I get from one of the APs (model 702i with IOS 15.3):
*May 17 13:41:35.999: %CAPWAP-3-EVENTLOG: Wait DTLS timer has expired
*May 17 13:41:35.999: %CAPWAP-3-EVENTLOG: Dtls session establishment failed
*May 17 13:41:35.999: %CAPWAP-3-EVENTLOG: CAPWAP State: DTLS Teardown.
*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: DTLS session cleanup completed. Restarting capwap state machine.
*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: Previous CAPWAP state was DTLS Setup,numOfCapwapDiscoveryResp = 3.
*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: Attempting to join next controller
*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: Go Join the next controller
*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: Calling wtpGetAcToJoin from timer expiry.
*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: Selected MWAR 'Cisco-000c.29a4.b9ae' (index 0).
*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: Ap mgr count=0
*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: Go Join the next controller
*May 17 13:41:41.003: %CAPWAP-3-EVENTLOG: Remove discovery response at index 0
*May 17 13:41:41.003: AP has SHA2 MIC certificate - Using SHA2 MIC certificate for DTLS.
Peer certificate verification failed 001A
*May 17 13:41:41.055: DTLS_CLIENT_ERROR: ../capwap/base_capwap/capwap/base_capwap_wtp_dtls.c:496 Certificate verified failed!
I checked the community the FN-63942 but the work around don't work.
Any idea how to solve this?
Thank You!
05-17-2023 06:34 AM
Hi
I have a few things you can check.
Date and time on the WLC
Activate licensing (even evaluation licensing needs to be enable)
Make sure you enable the correct country for your APs.
make sure reachabilityis fine
Last factory reset one AP to test, in case all the above is OK.
05-17-2023 06:42 AM
Hello Flavio,
Date and time are correct (I even tried the workaround of changing the time).
License is activated (it is evaluation and it is enabled).
Country is correct.
Reachability is ok, both can ping each other.
I will factory reset the AP and get back to you.
Thank You!
05-18-2023 04:32 PM - edited 05-18-2023 04:36 PM
@Flavio Miranda has summarised all the key points.
All I will add is make sure your software is up to date per TAC recommended (link below) - currently 8.10.185.0 - and review all the field notice links below.
PS: You might want to read FN63942 again carefully - you need to perform all the steps in the right order.
Workaround config on WLC
Set time back
AP joins, downloads new software and workaround config.
Only at that point is the AP "fixed".
05-21-2023 02:01 AM
Hello Rich,
Thank you very much!
We actually dropped the vWLC and got an appliance.
The APs connected with the appliance right away.
Thank you!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide