cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9821
Views
1
Helpful
4
Replies

Control Path Down

scottwilliamson
Level 2
Level 2

Hi,

The control path between our Guest Anchor WLC4402 and one of our foreign controllers is down all other control paths are up as are all of the data paths. The Anchor is behind a firewall the configuration of which must be ok due to the other WLCs data and control paths being up. Can anyone tell me how I check that the WLCs are reciving each others mobility packets e.g. via debug.

Many Thanks

Scott

1 Accepted Solution

Accepted Solutions

weterry
Level 4
Level 4

debug mobility keepalive

you should see a "data path" keepalive every 10 seconds and a "control path" keepalive every 30 seconds.

I believe the Control Path will be a message about port 16666.

Run this from all controllers and verify who is sending the keepalive (I believe it is lowest mac address).

Bottom line is that if you see one controller send it, and the other doesn't recieve it, that sounds like it is getting lost along the way.

I've seen configuration before where if the DMZ Controller is the initiator of the keepalive (high mac address?), then the path may be down. It had to do with the firewall allowing the session from Trust to DMZ (and the return traffic), but not allowing the DMZ to initiate the session.

You could try an mping from both controllers and see if you can get a response....?

View solution in original post

4 Replies 4

weterry
Level 4
Level 4

debug mobility keepalive

you should see a "data path" keepalive every 10 seconds and a "control path" keepalive every 30 seconds.

I believe the Control Path will be a message about port 16666.

Run this from all controllers and verify who is sending the keepalive (I believe it is lowest mac address).

Bottom line is that if you see one controller send it, and the other doesn't recieve it, that sounds like it is getting lost along the way.

I've seen configuration before where if the DMZ Controller is the initiator of the keepalive (high mac address?), then the path may be down. It had to do with the firewall allowing the session from Trust to DMZ (and the return traffic), but not allowing the DMZ to initiate the session.

You could try an mping from both controllers and see if you can get a response....?

Hi Wesley,

Thanks for that you've helped me realise what the problem is: The Anchor was not sending udp port 16666 to the problem controller, it occured to me that the Service Port address of the Anchor was on the same subnet as the Manager interfaces of the controller it could not establish the EoIP tunnel with - I've changed the Service Port address and everything now works.

Thank you,

Scott

santoshrijala12
Level 1
Level 1

I am having the same issues and DMZ controller send keepalive messages to 9800 controller and when i check logging on 9800 Controller the peer link to DMZ is down.

on DMZ:

*mmMobility: Jun 20 11:33:17.758: Keepalive:VALID:ETHOIP_OP_REQ:Sent to 10.xxx.x.x:version=02:SeqNo=37744104:receiverStatusOnTransmitter=0

mmMobility: Jun 20 11:33:17.758: Keepalive: Mobility Data Ping response failed for the peer 10.xxx.x.x retryCount= 2

on 9800 logging:

Jun 20 10:38:09.095: %MM_INFRA_LOG-3-RECV_FAILED: Chassis 1 R0/0: mobilityd: Unable to receive mobility message pmk_update from ipv4: 192.168.xxx.x . reason: Peer link is down

 

 

@santoshrijala12 as @marce1000 has already said to you on duplicate post https://community.cisco.com/t5/wireless/mobility-link-down-after-update-17-3-3-on-9800-cl/m-p/5301162/highlight/true#M284210 - please open a new thread and provide complete details of your issue rather than trying to revive years old threads which could be on different hardware and versions of software and be of limited relevance now.

- What models of WLC at each end?
- What versions of software are the WLCs running?
- What troubleshooting have you performed?
- What caused it to stop working? What changes were made?
- Have you used the Config Analyser to check both the WLC configs? (see the link and tips below)

Review Cisco Networking for a $25 gift card