cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
486
Views
1
Helpful
3
Replies

Changed C9800 hostname and APs stooped workin

jasonjefrey1
Level 1
Level 1

Hi everybody

APs appear as not Joined after deleting the controller hostname. I also removed crypto with the CLi command "no crypto pki trustpoint C9800_WLC_TP."

I then recreated the certificate with " C9800_1E #wireless config vwlc-ssc key-size 2048 signature-algo sha256 password zero xxxxxxxxxx"

Here is what I am getting: Configuring vWLC-SSC...
Script is completed

Now it appears as if I have two certificates the created earlier on the one created recently.

And my APs are no longer joining the controller. 

C9800_1E##sh wireless management trustp
Trustpoint Name : eWLC1_WLC_TP
Certificate Info : Not Available
Private key Info : Not Available
FIPS suitability : Not Applicable

C9800_1E#

Jason

3 Replies 3

marce1000
VIP
VIP

 

 - Have a checkup review of the controller configuration with the CLI command : show tech wireless , feed the output into :
                            https://cway.cisco.com/wireless-config-analyzer/

                 It is highly likely that the current configuration issue and or fault will be pointed out immediately , 

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Hi @marce1000 

Thank you I will try that!

Rich R
VIP
VIP

Have you carefully followed the guide?
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/trustpoints/b-configuring-trustpoints-on-cisco-catalyst-9800-series-controllers/c-workflow-to-configure-a-trustpoint-for-a-self-signed-certificate-on-catalyst-9800-cl.html

And from https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/guide-c07-743627.html#Configurationfilemanagement

  •       Delete the certificates which were copied along with the configuration. To do this, first check the existing certificates using the command “show crypto pki trustpoint”
  •       Delete the existing certificate authority “WLC_CA”:

no crypto pki server WLC_CA

  •       Delete existing device certificates:

no crypto pki trustpoint "<hostname>_WLC_TP"

  •       Create a new SSC for the management interface using the exec command:

wireless config vwlc-ssc key-size 2048 signature-algo sha256 password 0 <password>

 

Review Cisco Networking for a $25 gift card