cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2453
Views
0
Helpful
6
Replies

Dear all, I m trying to configure AIR-AP2802I-D-K9 on cisco 5508 controller but i m getting below errors

[*01/14/2021 08:21:25.2478]CAPWAP State: DTLS Setup

[*01/14/2021 08:21:25.0004] dtls_connectionDB_add_connection: Number of DTLS connections exceeded two

[*01/14/2021 08:21:25.2478] dtls_load_ca_certs: LSC Root Certificate not present

[*01/14/2021 08:21:25.2508] dtls_verify_con_cert: Controller certificate verification error

[*01/14/2021 08:21:25.2508] dtls_process_packet: controller cert verification failed

[*01/14/2021 08:21:25.2512] DTLS: Received packet 0x11cf000 caused DTLS to close connection

[*01/14/2021 08:21:25.2512] sendPacketToDtls: DTLS: Closing connection 0x1189400.

[*01/14/2021 08:21:25.2512] Lost connection to the controller, going to restart CAPWAP...

[*01/14/2021 08:21:25.2513] Restarting CAPWAP State Machine.

[*01/14/2021 08:21:25.2514] Discarding msg CAPWAP_WTP_EVENT_REQUEST(type 9) in CAPWAP state: DTLS Setup(3).

[*01/14/2021 08:21:25.2519] Failed to disconnect DTLS-CTRL session.

[*01/14/2021 08:21:25.2520] CAPWAP State: DTLS Teardown

[*01/14/2021 08:21:25.2573] DTLS: Error while processing DTLS packet 0x11d3000.

[*01/14/2021 08:21:29.9413] No more AP manager addresses remain..

[*01/14/2021 08:21:29.9414] No valid AP manager found for controller 'MMWOR-WLC' (ip: 10.1.1.5)

[*01/14/2021 08:21:29.9414] Failed to join controller MMWOR-WLC.

[*01/14/2021 08:21:29.9414] Failed to join controller.

6 Replies 6

Leo Laohoo
Hall of Fame
Hall of Fame

@ansari.mohsin9121 wrote:

[*01/14/2021 08:21:29.9414] No valid AP manager found for controller 'MMWOR-WLC' (ip: 10.1.1.5)


Does the controller have enough licenses?

Yes still 15 licenses left

marce1000
VIP
VIP

 

 - What's the software version used on the 5508 ?

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

on controller 8.3.150.6

 

Depends what other APs you have but consider moving to 8.5 or later code.

https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html#anc10

https://www.cisco.com/c/en/us/td/docs/wireless/compatibility/matrix/compatibility-matrix.html#pgfId-590411

 

And have you reviewed field notice https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html and the associated bugs and workarounds?

 

And also try to factory default the AP then try again - sometimes that helps.

Chris C'Leon
Cisco Employee
Cisco Employee

This looks like a problem with LSC Root Certificate which disallow the AP to build the CAPWAP tunnel with the WLC.

Please check if this option- Accept Local Significant Certificate (LSC)

enabled under AP policies, if yes, please disable it and test.

 

Check out this guidelines to understand better how this cert works:

Locally Significant Certificates on Wireless LAN Controllers Configuration Example
https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/110141-loc-sig-cert.html#tshoot

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card