11-23-2019 07:41 AM - edited 07-05-2021 11:20 AM
Hello Team,
i am trying to deploy the two C9800-40-K9 controller in the network
1- Before connecting the both controller to the network
i had given one ip adress 10.91.225.80 ip to the Gi0 of WLC1 and connected the cable between SP port and laptop with static ip address 10.91.225.82
2.from laptop i am able to take the https acess of the WLC1 , i upgraded the IOS for WLC1 to the 16.11.01
3.same thing i did for the WLC2 upgraded the IOS and 10.91.225.81
4.during the configuration of WLC1 and WLC2 i used Gi0 as the wireless Managment interface
5. Then we connected the both the WLC1 and WLC2 to the network but during this time i didnt check the connectivity of the WLC from coreswitch
6. Both WLC RP Port is in L2 vlan 498
7.after rackmounting Both WLC by connecting to the SP to the laptop from the browser i configured the HA between two WLC , HA form properly , i did the failover test it was working properly
8. but when i try to connect from the different vlan2 or Vlan 50 from other switch ports i am not able to take the https access of both controller , i am getting ERR_SSL_PROTOCOL_ERROR in the browser
9. can i help me what may go worng ?
10.i have license file but i didnt uploaded them on any WLC?
11. as Gi0 is not pinging from other network i changed Gi0 ip to the interface vlan 50 and wireless mgmt to int vlan 50 but still i am not able to ping the int vlan 50 ip
can somebody help did we are doing something wrong
Now we are not able to ping the int vlan 50 from outside network
we have given another int vlan 2 ip in WLC1 and this ip we are able to ping but when we try to take the browser with the interface vlan 2 of WLC i am getting the ERR_SSL_PROTOCOL_ERROR
attached is the diagram and attached is the error screenshot
Thanks all
Shrikant Gaikwad
11-24-2019 02:37 AM
- I can only presume that your Intranet and or inter-vlan networking setup isn't consistent and does not allow full ssl access to the wireless controller. Please check and verify.
M.
12-04-2019 01:01 PM
I have the same issue accessing a Cisco 9800 via HTTPS. I can reach several AirOS and on other 9800 controller on the same subnet.
12-04-2019 11:54 PM
12-08-2019 04:15 AM
12-05-2019 09:13 AM
12-06-2019 12:32 PM
Thanks, this worked for me.
12-08-2019 02:00 AM
12-08-2019 04:31 AM
Thank you so much for all your time and solution and sorry for the late reply
Last week we disable https access and only permitted http access to get the browser,
we got the http access of primary WLC and showing HA is not working properly so we break the HA between two WLC and factory reset both the WLC and try to do basic setup like before(with the day 0 setup) but now both the WLC is giving the internal error during day 0 setup as we try add the country FR to complete the basic setup.
we discover we faced issue CSCvq01830
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvq01830
as per the above link we disable both radios from CLI and we able to finish the day 0 setup.
we upgraded the controller now in Bundle mode to 16.12.1s and everything is working properly
Many thanks @Scott Fella
02-07-2020 08:54 AM
Thanks Scott. this worked for me.
Is this known issue/bug ? do we have any permanent solution ?
I am also going ask TAC guys.
03-04-2020 10:11 AM
03-09-2020 11:47 AM
This procedure also worked for me, thank you very much.
01-29-2021 03:31 AM
This worked for me. Thank you.
04-04-2022 10:51 PM
hi Scott,
My scenario is C9800-L-F-K9 * 2
Current Active is Unit 2
IOS - 17.3.2a
Unable to access GUI for management from most of the servers and internal network.
Noticed able to access this from one management server alone. But another server in the same range returns error.
Site is connected over VSAT and has like 800+ms latency. Please let me know if you need more details. Can i follow still same process?
Cheers
Royce
01-21-2025 05:42 PM
I had the same exact issue on a lab controller sitting on the bench. Last time I used it, about a year ago, I could browse from the 192.168.1.x /24 network and configure it, etc. That's the g0 interface.
I tried today, and I get the same error as the title of this thread.
c9800_Pod_10#sh run | inc crypto
crypto pki trustpoint TP-self-signed-2305082738
crypto pki trustpoint SLA-TrustPoint
crypto pki certificate chain TP-self-signed-2305082738
crypto pki certificate chain SLA-TrustPoint
config t
no crypto pki trustpoint TP-self-signed-2305082738
answered yes.
no ip http server
no ip http secure-server
ip http server
ip http secure-server
ip http authentication
No browsing.
Secure Connection Failed
An error occurred during a connection to 192.168.1.250. PR_END_OF_FILE_ERROR
Error code: PR_END_OF_FILE_ERROR
The page you are trying to view cannot be shown because the authenticity of the received data could not be verified.
Please contact the website owners to inform them of this problem.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide