cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
13737
Views
10
Helpful
41
Replies

Cisco AIR-LAP1142N-E-K9 cannot join the vWLC.....

IgorFi
Level 1
Level 1

Ho Folks. I'm doing a degree work and I have some gear here to make some tests, but failing...

I bought a Cisco AIR-LAP1142N-E-K9 on ebay and using evaluation version of vWLC. I have already tried two various versions of vWLC: Air CTVM-7-3-101-0  and CTVM-K9-8-0-152-0.

 

They have same problem. The wWLC actually can see the LAP, but it tells Status "Not Joined".

It sees its IP address (but not MAC). The can ping each other. The vWLC evaluation is activated.

 

So  see the same thing:

 

picccc.JPG

So tired, i tried so many offers.

This some version screenshots:

version 1.JPGsystem 2.JPG

Some screens from the vWLC:

cert1.JPG

cert2.JPG

cert3.JPGI don't know if this is enough, The time i set everywhere.

Also, I said, the vWLC can see the LAP:

join.JPG

Could you help me with that? Thank yo.

2 Accepted Solutions

Accepted Solutions

I've got another trick up my sleeve: The RCV file the AP is running on is very, very, very, very old. Anyone can download CAPWAP file & there is no need to have a valid Service Contract.
Download the latest RCV file and load it into the AP and try again.

View solution in original post

Ah ok, in this case replace the .bin with .tar.

As they are tar files, you need to use the 'archive download-sw' command. Do you have that one in the recovery debug CLI mode?

If not, you probably have to use the ROMMON mode variant, which I linked before. 

If yes, here is the manual on how to use the archive download-sw command:

https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/107911-ios-upgrade.html#task2

 

So the command should be like this:

archieve download-sw /force-reload /overwrite tftp://192.168.0.22/cc1140-rcvk9w8-tar.152-4.JB6.tar

View solution in original post

41 Replies 41

Leo Laohoo
Hall of Fame
Hall of Fame
Post the complete output to the following vWLC commands:
1. sh sysinfo;
2. sh time
I don't see any signs the AP knows the WLC details via DHCP Option 43.

Hi Leo! Thank you for response.

I have installed the AIR-CTVM-K9-8-0-152.0  again.

Here is the information requested:

 

1) sh sysinfo

sys1.JPG

sys2.JPG

2) Sh time:

time.JPG

Interfaces:

Interface.JPG

And this is fro the LAP:

DHCP.JPG

And this is how Devices are connected:

 

vWLC is running on VMware Workstation 14. Two network interfaces are selected in VMware, both are Bridged to Host Ethernet Gigabit interface.

Host is wired to the home router (SkyHub3).

Cisco LAP is wired to the Homer router and there is a PoE injector between them.

USB to console cable is wired to the LAP.

Home router ip 192.168.0.1

Settings that I put when installed the vWLC on Workstation:

 

Service interface IP Address configuration: STATIC

Service interface IP address: 10.10.10.1 255.255.255.0

Management interface IP address: 192.168.0.55

Management interface default router: 192.168.0.1

Management Interface DHCP Server IP address 192.168.0.1

Virtual gateway IP address: 1.1.1.1

Configure NTP server now: NO

Configure system time now: YES

 

I'm not sure what else to post.


@IgorFi wrote:

Configure NTP server now: NO


This is where I suspect the problem is.  

Hi Leo.

I just configured the NTP on the vWLC GUI. But still the same thing.

 

ntp.JPGAs you see, I chose my Home router ip as NTP server.

Also, I hope that is not the reason:

low.JPG

This will be a problem for wireless connection, but shouldn't prevent the LAP from joying when wired.

Did you activate the AP license?
Maybe the vWLC doesn't have enough license to support the AP numbers?

The evaluation version says 200 aps. I have only one LAP.

Check https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html

It's also possible that the certificate on the 1142 was somehow corrupted. Can happen when doing the Autonomous -> LWAP conversion not correctly. 

You tried to factory reset the AP?

Hi Patorbeli. Yes, I did the factory reset a few times. Taking the ethernet cable out, then pressing the button, then putting the cable back. The light started flashing blue. Then the terminal shows how the LAP loading. So frustrated, as I bought it on eBay 2 months ago and now need to finish the uni degree project in three weeks. Maybe the LAP firmware is outdated? Where i can see it? Is it feasible to update the LAP firmware without joining the vWLC? Is it easy process? I didn't find any commands related to an update on the LAP.


@patoberli wrote:

It's also possible that the certificate on the 1142 was somehow corrupted.


I don't think the field notice applies because the age of the AP is only 8 years old.

You're right. On the first screenshot it looks like the AP is running on the recovery image.
@IgorFi, can you please attach the full boot log of the AP? It seems it's missing an image.
Also check this here for a similar case (with a different AP model): https://community.cisco.com/t5/wireless-and-mobility/wlc-5508-7-6-100-0-ap-invalidates-primary-backup-image-after/td-p/2369541
I don't remember anymore if it first attaches to the WLC or if it first tries to update the image anymore.

Oh and unrelated to this issue, don't use 1.1.1.1 as the virtual-interface address. This address is now being used in the internet and Chrome actually blocks the access if you use a guest portal on that address. Use a 10.x.x.x address.

Guys, thanks for help so far. Hare are some screen shoots upon booting the LAP. If this is what you asked me. I see only one image "rcv".Boot1.JPG

boot2.JPG

boot3.JPG

boot4.JPG

You miss the next ~30 lines of log file, the important ones :) Next it should try to connect to the WLC and do a software upgrade (which either fails because of the certificate issue, or some other problem).

If you connect via console, you could also copy&paste the log, instead of screenshots. That would be a little bit easier to read.
One the AP is booted and you waited some 3 more minutes, can you login to it and post the output of the 'dir' command?

Hi Patoberli. Here is the full boot process. (192.168.0.55 is the vWLC management interface)

 

WRDTR,CLKTR: 0x86000800 0x40000000
RQDC ,RFDC : 0x80000038 0x00000210

ddr init done

IOS Bootloader - Starting system.
Xmodem file system is available.

DDR values used from system serial eeprom.
WRDTR,CLKTR: 0x86000800, 0x40000000
RQDC, RFDC : 0x80000038, 0x00000210

PCIE0: link is up.
PCIE0: VC0 is active
PCIE1: link is up.
PCIE1: VC0 is active
PCIEx: initialization done
flashfs[0]: 32 files, 9 directories
flashfs[0]: 0 orphaned files, 0 orphaned directories
flashfs[0]: Total bytes: 32385024
flashfs[0]: Bytes used: 12569600
flashfs[0]: Bytes available: 19815424
flashfs[0]: flashfs fsck took 21 seconds.
Reading cookie from system serial eeprom...Done
Base Ethernet MAC address: 68:ef:bd:ff:06:0e
Ethernet speed is 100 Mb - FULL duplex
button pressed for 1 seconds
process_config_recovery: set IP address and config to default 10.0.0.1
Loading "flash:/c1140-rcvk9w8-mx/c1140-rcvk9w8-mx"...#######################################################################################################################################################################################################################

File "flash:/c1140-rcvk9w8-mx/c1140-rcvk9w8-mx" uncompressed and installed, entry point: 0x4000
executing...
enet halted

Restricted Rights Legend

Use, duplication, or disclosure by the Government is
subject to restrictions as set forth in subparagraph
(c) of the Commercial Computer Software - Restricted
Rights clause at FAR sec. 52.227-19 and subparagraph
(c) (1) (ii) of the Rights in Technical Data and Computer
Software clause at DFARS sec. 252.227-7013.

cisco Systems, Inc.
170 West Tasman Drive
San Jose, California 95134-1706

 

Cisco IOS Software, C1140 Software (C1140-RCVK9W8-M), Version 12.4(21a)JA, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2009 by Cisco Systems, Inc.
Compiled Mon 08-Jun-09 16:28 by prod_rel_team


Proceeding with system init

Proceeding to unmask interrupts
Initializing flashfs...

flashfs[1]: 31 files, 9 directories
flashfs[1]: 0 orphaned files, 0 orphaned directories
flashfs[1]: Total bytes: 32385024
flashfs[1]: Bytes used: 12569088
flashfs[1]: Bytes available: 19815936
flashfs[1]: flashfs fsck took 5 seconds.
flashfs[1]: Initialization complete....done Initializing flashfs.
Ethernet speed is 100 Mb - FULL duplex

This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

cisco AIR-LAP1142N-E-K9 (PowerPC405ex) processor (revision B0) with 98294K/32768K bytes of memory.
Processor board ID FCZ1418W0FA
PowerPC405ex CPU at 586Mhz, revision number 0x147E
Last reset from watchdog timer expired
LWAPP image version 3.0.51.0
1 Gigabit Ethernet interface

32K bytes of flash-simulated non-volatile configuration memory.
Base ethernet MAC Address: 68:EF:BD:FF:06:0E
Part Number : 73-11451-08
PCA Assembly Number : 800-30554-06
PCA Revision Number : A0
PCB Serial Number : FOC14150AV0
Top Assembly Part Number : 800-31273-04
Top Assembly Serial Number : FCZ1418W0FA
Top Revision Number : A0
Product/Model Number : AIR-LAP1142N-E-K9
% Please define a domain-name first.


Press RETURN to get started!


*Mar 1 00:00:06.596: *** CRASH_LOG = YES
Base Ethernet MAC address: 68:EF:BD:FF:06:0E

*Mar 1 00:00:06.780: %LWAPP-3-CLIENTEVENTLOG: Unable to open event log file flash:/event.log

*Mar 1 00:00:06.780: %LWAPP-3-CLIENTEVENTLOG: Read and initialized AP event log (contains, 0 messages)

*Mar 1 00:00:08.859: %LINK-3-UPDOWN: Interface GigabitEthernet0, changed state to up
*Mar 1 00:00:08.875: %SYS-5-RESTART: System restarted --
Cisco IOS Software, C1140 Software (C1140-RCVK9W8-M), Version 12.4(21a)JA, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2009 by Cisco Systems, Inc.
Compiled Mon 08-Jun-09 16:28 by prod_rel_team
*Mar 1 00:00:08.923: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
*Mar 1 00:00:09.859: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0, changed state to up
*Mar 1 00:00:18.256: %DHCP-6-ADDRESS_ASSIGN: Interface GigabitEthernet0 assigned DHCP address 192.168.0.60, mask 255.255.255.0, hostname AP68ef.bdff.060e

Translating "CISCO-CAPWAP-CONTROLLER.Home"...domain server (192.168.0.1)

Translating "CISCO-LWAPP-CONTROLLER.Home"...domain server (192.168.0.1)

*Mar 1 00:00:38.811: %CAPWAP-3-ERRORLOG: Did not get log server settings from DHCP.
*Mar 1 00:00:39.010: %CAPWAP-3-ERRORLOG: Could Not resolve CISCO-CAPWAP-CONTROLLER.Home
*Mar 1 00:00:39.067: %CAPWAP-3-ERRORLOG: Could Not resolve CISCO-LWAPP-CONTROLLER.Home
*Mar 1 00:00:49.068: %CAPWAP-3-ERRORLOG: Go join a capwap controller
*Aug 29 18:53:39.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.0.55 peer_port: 5246
*Aug 29 18:53:40.000: %CAPWAP-5-CHANGED: CAPWAP changed state to
*Aug 29 18:53:40.045: %LWAPP-3-CLIENTERRORLOG: Peer certificate verification failed
*Aug 29 18:53:40.045: %CAPWAP-3-ERRORLOG: Certificate verification failed!
*Aug 29 18:53:40.046: DTLS_CLIENT_ERROR: ../capwap/capwap_wtp_dtls.c:326 Certificate verified failed!
*Aug 29 18:53:40.046: %DTLS-4-BAD_CERT: Certificate verification failed. Peer IP: 192.168.0.55
*Aug 29 18:53:40.046: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to 192.168.0.55:5246
*Aug 29 18:53:40.046: %DTLS-3-BAD_RECORD: Erroneous record received from 192.168.0.55: Malformed Certificate
*Aug 29 18:53:40.046: %DTLS-5-SEND_ALERT: Send WARNING : Close notify Alert to 192.168.0.55:5246
*Aug 29 18:53:40.047: %CAPWAP-3-ERRORLOG: Invalid event 38 & state 3 combination.
*Aug 29 18:54:00.456: %CDP_PD-2-POWER_LOW: All radios disabled - NON_CISCO-NO_CDP_RECEIVED (0000.0000.0000)
*Aug 29 18:54:44.000: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
*Aug 29 18:54:44.000: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
*Aug 29 18:54:54.005: %CAPWAP-3-ERRORLOG: Go join a capwap controller
*Aug 29 18:54:53.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.0.55 peer_port: 5246
*Aug 29 18:54:53.000: %CAPWAP-5-CHANGED: CAPWAP changed state to
*Aug 29 18:54:53.071: %LWAPP-3-CLIENTERRORLOG: Peer certificate verification failed
*Aug 29 18:54:53.071: %CAPWAP-3-ERRORLOG: Certificate verification failed!
*Aug 29 18:54:53.071: DTLS_CLIENT_ERROR: ../capwap/capwap_wtp_dtls.c:326 Certificate verified failed!
*Aug 29 18:54:53.071: %DTLS-4-BAD_CERT: Certificate verification failed. Peer IP: 192.168.0.55
*Aug 29 18:54:53.071: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to 192.168.0.55:5246
*Aug 29 18:54:53.071: %DTLS-3-BAD_RECORD: Erroneous record received from 192.168.0.55: Malformed Certificate
*Aug 29 18:54:53.072: %DTLS-5-SEND_ALERT: Send WARNING : Close notify Alert to 192.168.0.55:5246
*Aug 29 18:54:53.072: %CAPWAP-3-ERRORLOG: Invalid event 38 & state 3 combination.

Go to the vWLC and enter the command "sh ap join stats summary all". Look for the MAC address of the AP.
Then issue the command "sh ap join stats detail <AP MAC address>". Post the entire output (don't use screenshots).
Review Cisco Networking for a $25 gift card