10-03-2025 07:41 AM
Hello community,
I just spun up a Cisco Catalyst 9800-CL Wireless Controller 17.18.1 on ESXi in my home lab, and I have a brand new CW9178I out of the box.
Once I finished setting up the controller I plugged the AP into my switch on a port that can see the controller. The AP sends the discovery request to the controller, the AP then starts DTLS setup, then is tears down the DTLS setup.
From what I understand the DTLS handshake is failing because the WLC is not presenting a usable certificate. So i created a trust point and a self-signed certificate on the WLC via CLI (I attached a screenshot below of the command I did).
The certificate is showing as being created, available, and assigned to the trust point I created. However when I "show wireless management trust-point" it says the cert and kay are not available.
I'm pretty sure this is what's stopping the AP from being able to join the controller. Any thoughts?
Solved! Go to Solution.
10-03-2025 11:51 AM
- @Bradley Rousseau The one about HTTP access not configured (restricting) is not important (indeed)
but the output of show wireless management trustpoint.... is not correct
there are no info's about the certificate (and or hash)
Could you re-create and or according to the procedure outlined in :
https://www.ciscolive.com/c/dam/r/ciscolive/global-event/docs/2024/pdf/BRKEWN-2094.pdf
wireless config vwlc-ssc key-size 2048 signature-algo sha256 password 0 <your pwd>
show wireless management trustpoint
Actually read from WMI’s trustpoint
(to get the complete info's)
The WirelessAnalyzer procedure should always be used again after configuration changes!!
M.
10-03-2025 07:57 AM
- @Bradley Rousseau >....However when I "show wireless management trust-point" it says the cert and kay are not available.
Then the configuration of the 9800-CL controller is not correct :
Issue the command show tech wireless and feed the output from that into Wireless Config Analyzer
(Use the full command as outlined in green; it does not work with show tech-support)
M.
10-03-2025 10:20 AM
10-03-2025 10:28 AM
- @Bradley Rousseau For starters , when you for instance download the Excel version of the report then
all errors red flagged in the wlc_results tab, must be corrected.
To get assistance with those, if needed , this document can be useful
https://www.ciscolive.com/c/dam/r/ciscolive/global-event/docs/2024/pdf/BRKEWN-2094.pdf
M.
10-03-2025 11:29 AM
10-03-2025 11:51 AM
- @Bradley Rousseau The one about HTTP access not configured (restricting) is not important (indeed)
but the output of show wireless management trustpoint.... is not correct
there are no info's about the certificate (and or hash)
Could you re-create and or according to the procedure outlined in :
https://www.ciscolive.com/c/dam/r/ciscolive/global-event/docs/2024/pdf/BRKEWN-2094.pdf
wireless config vwlc-ssc key-size 2048 signature-algo sha256 password 0 <your pwd>
show wireless management trustpoint
Actually read from WMI’s trustpoint
(to get the complete info's)
The WirelessAnalyzer procedure should always be used again after configuration changes!!
M.
10-03-2025 08:04 AM
Can you post the show run from WLC and connect the Console cable to the AP, and post the complete boot log to understand what is wrong?
1. Make sure NTP correct
2. make sure management interface reachable ?
3. is the AP and WLC in same VLAN ?
4. check region settings.
5. show logging from control and post here.
check configuration analyser and debug analyser :
https://developer.cisco.com/docs/wireless-troubleshooting-tools/wireless-config-analyzer
=====Preenayamo Vasudevam=====
***** Rate All Helpful Responses *****
10-03-2025 08:13 AM
good recommendations, also check "show crypto pki trustpoint <TP name> status"
make sure all state at end is Yes, if any of them is No then regenerate key pair and new trustpoint with new key pair.
10-05-2025 05:34 AM
9800-CL WMI SSC is also covered in the Best Practices document (link below).
For the global use (WiFi 7) APs read through the https://www.cisco.com/c/en/us/td/docs/wireless/access_point/technical-reference/global-use-ap-dg.html guide carefully. In particular note the AP country setting - I've just addressed this in another reply:
https://community.cisco.com/t5/wireless/wlc-9800-version-17-17-1-lt-gt-cisco-switch-9200-lt-gt-cisco/m-p/5335823/highlight/true#M286693
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide