cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1407
Views
0
Helpful
6
Replies

control path between 9800 and 5520 shows down

atifali.zaidi1
Level 1
Level 1

Hi folks i have the following scenario

 

5520 anchor wlc running 8.5.164.0 IRCM image

9800 foreign wlc running 17.3.3

 

I have configured mobility tunnels between the two and enabled secure mobility , there is a firewall between the two but the capwap and EOIP ports are open, the control path shows up as "down"

took some debugs on the 5520 and saw the following , i have tried disabling secure mobility but then the control and data patch both go down.

 

*capwapPingSocketTask: Aug 04 13:41:39.590: returning rc 0 for ping packet from peer x.x.x.x
*mobilityCapwapSocketTask: Aug 09 05:46:14.205: Cannot retrieve ID cert
*mobilityCapwapSocketTask: Aug 09 05:47:14.245: Cannot retrieve ID cert
*mobilityCapwapSocketTask: Aug 09 05:47:14.245: Failed to fetch credential for DTLS handshake
*mobilityCapwapSocketTask: Aug 09 05:47:14.245: Failed to create a server connection
*mobilityCapwapSocketTask: Aug 09 05:48:14.261: Cannot retrieve ID cert
*mobilityCapwapSocketTask: Aug 09 05:48:14.261: Failed to fetch credential for DTLS handshake
*mobilityCapwapSocketTask: Aug 09 05:48:14.261: Failed to create a server connection
*mobilityCapwapSocketTask: Aug 09 05:49:14.293: Cannot retrieve ID cert
*mobilityCapwapSocketTask: Aug 09 05:49:14.293: Failed to fetch credential for DTLS handshake

6 Replies 6

marce1000
VIP
VIP

 

 - Check this thread :

            https://community.cisco.com/t5/wireless/inter-release-controller-mobility-ircm-with-5508-fail-control/td-p/4273720

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

this post is about a 5508 and not a 5520 , i also have a 5508 and i had to use to cert expiry command on the to bring the mobility UP between 5508 and 9800.

 

but what is the fix for 5520 ?

 

                      >... i had to use to cert expiry command on the to bring the mobility UP between 5508 and 9800.

  That  denotes that the fix described from Grendizer in  the mentioned-thread may very well be needed on your 9800 too , I would give it a try (meaning start with the 9800-side first   with the command-actions described in the resolving-port of the thread mentioned, see what comes 'up' (...) )

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

hi, this command has already been tried on the 9800 (and thats how we brought mobility UP with another 5508), also the "HTTPS" certificate has expired on the 5520 aireos wlc, will this cause an issue ?

 

                    - The resolving-reply in the mentioned thread exactly deals with that.

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Rich R
VIP
VIP

Might want to think about moving to 8-5-176-2 on the 5520 - has a whole lot of fixes in it:

https://software.cisco.com/download/home/286284738/type/280926587/release/8.5IRCM

Review Cisco Networking for a $25 gift card