09-20-2020 08:45 PM - edited 07-05-2021 12:32 PM
Hi Team,
I met a issue that the mobility tunnel can't be built between WLC3504 and WLC9800-40, their version meet the ICRM requirement, I suspect the issue happens since certificate using by DTLS, I saw the logging information as follow:
--------------------------------------------- Last Reboot MsgLog & Traplog ---------------------------------------------
Sys Name: Melco-Test
Model: AIR-CT3504-K9
Version: 8.8.120.0
Primary Boot Image: 8.8.120.0 (default) (active)
Backup Boot Image: 8.8.125.0
LastReset Reason: Planned Reset
Timestamp: Mon Jul 13 07:07:01 2020
SystemUpTime: 19 days 20 hrs 16 mins 8 secs
-------------------------------------------------------MsgLog Dump ------------------------------------------------------------
*mobilityCapwapSocketTask: Jul 13 07:06:48.342: %DTLS2-3-HANDSHAKE_FAILURE: dtls2.c:1500 DTLS handshake failed for link 10.124.112.178:16666 <-> 10.79.247.224:16666
Certificate issuer :Airespace 13 07:06:48.342: %SSHPM-3-GENERIC_CERT_ERROR: sshpmPkiApi.c:2241 Certificate validation failed! Reason Failure to extract MAC from certificate, Certificate type : MIC
*mobilityCapwapSocketTask: Jul 13 07:06:18.589: %DTLS2-3-HANDSHAKE_FAILURE: dtls2.c:1500 DTLS handshake failed for link 10.124.112.178:16666 <-> 10.79.247.224:16666
Certificate issuer :Airespace 13 07:06:18.588: %SSHPM-3-GENERIC_CERT_ERROR: sshpmPkiApi.c:2241 Certificate validation failed! Reason Failure to extract MAC from certificate, Certificate type : MIC
*mobilityCapwapSocketTask: Jul 13 07:05:48.834: %DTLS2-3-HANDSHAKE_FAILURE: dtls2.c:1500 DTLS handshake failed for link 10.124.112.178:16666 <-> 10.79.247.224:16666
Certificate issuer :Airespace 13 07:05:48.834: %SSHPM-3-GENERIC_CERT_ERROR: sshpmPkiApi.c:2241 Certificate validation failed! Reason Failure to extract MAC from certificate, Certificate type : MIC
*mobilityCapwapSocketTask: Jul 13 07:05:19.082: %DTLS2-3-HANDSHAKE_FAILURE: dtls2.c:1500 DTLS handshake failed for link 10.124.112.178:16666 <-> 10.79.247.224:16666
Certificate issuer :Airespace 13 07:05:19.081: %SSHPM-3-GENERIC_CERT_ERROR: sshpmPkiApi.c:2241 Certificate validation failed! Reason Failure to extract MAC from certificate, Certificate type : MIC
*capwapPingSocketTask: Jul 13 06:42:50.238: %CAPWAPPING-3-PKT_RECV_ERROR: capwapping_shim_wlc.c:800 capwapPingSocketTask: capwappingRecvPkt returned error
*capwapPingSocketTask: Jul 13 06:42:50.238: %LOG-3-Q_IND: capwapping_shim_wlc.c:800 capwapPingSocketTask: capwappingRecvPkt returned error
*capwapPingSocketTask: Jul 13 06:42:40.331: %CAPWAPPING-3-PKT_RECV_ERROR: capwapping_shim_wlc.c:800 capwapPingSocketTask: capwappingRecvPkt returned error
*capwapPingSocketTask: Jul 13 06:42:40.330: %DTLS2-3-HANDSHAKE_FAILURE: dtls2.c:1500 DTLS handshake failed for link 10.124.112.178:16667 <-> 10.79.247.224:16667
tificate issuer :Airespace 13 06:42:40.330: %SSHPM-3-GENERIC_CERT_ERROR: sshpmPkiApi.c:2241 Certificate validation failed! Reason Failure to extract MAC from certificate, Certificate type : MIC, Ce
*capwapPingSocketTask: Jul 13 06:42:40.330: %LOG-3-Q_IND: capwapping_shim_wlc.c:800 capwapPingSocketTask: capwappingRecvPkt returned error[...It occurred 3 times.!]
*capwapPingSocketTask: Jul 13 06:42:40.320: %CAPWAPPING-3-PKT_RECV_ERROR: capwapping_shim_wlc.c:800 capwapPingSocketTask: capwappingRecvPkt returned error
how to troubleshoot the issue? Thanks
09-20-2020 10:41 PM
09-20-2020 10:43 PM
09-20-2020 11:42 PM
09-21-2020 12:13 AM
09-21-2020 12:37 AM
10-01-2020 07:45 PM
Did you figure this out? I'm having the same issue.
10-08-2020 05:50 PM
04-25-2023 12:15 PM
Hey @yaoszhan how did you fix the issue?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide