cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1710
Views
3
Helpful
15
Replies

Despite Flexconnect APs stop working when controller unreachable

safiullahtariq1
Level 1
Level 1

Hello

I have a very strange problem as I said in the subject, I have flexconnect enabled and other all related settings enabled but still when controller is unreachable, the APs stop showing SSID and stop working. 

Controller is: Cisco Catalyst 9800-CL Wireless Controller 17.13.1 (less than 50 APs) so no issue about licensing. 

APs are: 3802i with firmware version ap3g3-k9w8-tar.153-3.JPR

And this is kind of intermittent, when I turn on the AP while having a firewall rule to block the controller, it works fine. but when it is already ON and working and then the controller is not reachable, it stops beaconing the SSID and lights start changing color. I am attaching the startup config.

15 Replies 15

Mark Elsen
Hall of Fame
Hall of Fame

 

  - @safiullahtariq1           Check logs on the access point when it starts changing controller
                                        + Validate the  9800-CL controller configuration with the  CLI command
                                           show tech wireless and feed the output from that into Wireless Config Analyzer

  M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

@safiullahtariq1 

Upon checking you config file, the problem is related to " no capwap fallback" under AP profile. Disable it and test. 

 

@safiullahtariq1 FlexConnect APs stop broadcasting the SSID in standalone mode because 802.11r (Fast Transition) is currently enabled on WLAN, which is architecturally not supported in FlexConnect standalone mode or with Local Authentication -  therefore to allow the SSID to survive a WLC outage, u need to disable Fast Transition and ensure Local Authentication is applied

Stefan, thank you for the reply. Your reply makes me ask another question. If this is the case then how can I achieve smooth hands-off roaming if I disable Fast Transition? I dont want the user to be disconnected while making a transition from one AP to another. 

I request that you please check my existing settings and help me with that. Personally I am in strange state.

at the moment, when AP is started without controller, no issues (but i dont know the case of fast transition)

When AP is connected to the controller, well that works fine as it is suppose to.

When the AP is already booted and working and then the controller is unreachable, only then the issue arises the SSID does not survive a WLC outage.

but when during the A

 

  - @safiullahtariq1     Remember to execute the basic controller configuration validation procedure :
                                 with the  CLI command
                                           show tech wireless and feed the output from that into Wireless Config Analyzer
                                                      The above procedure is  always  mandatory at all times!

                                - Also use the controller CLI command : wireless config validate

                               + Enabling Syslog Messages in Access Points and Controller towards a  Syslog Server
                                  will provide additional info's , for instance when a flexconnect access point looses
                                  connection with the controller :
                                      https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/b_wl_16_10_cg/enabling-syslog-messages-in-access-points-and-controller-for-syslog-server.html

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

Today, I have tested and something very strange thing has happened. 

Controller Available: SSID Available (Console Cable connection, Flexconnect shifted to Local mode (I forgot the exact msg)). 

Controller Not Available during normal operation: SSID Available. (Console Cable connection, Flexconnect shifted to Local mode)

AP Powered On while there is NO Controller: SSID Available (Console Cable connection, Flexconnect shifted to Local mode).

Change Done: NONE. I dont know what is the matter. This time to be sure, I also made videos just to make sure that I am not doing something wrong and im not going nuts. I even went beyond and made firewall rules to and tested with them also so that controller is not available, still no issue.

What was happening previously and what I am unable to understand is, Controller is placed in my city, the issue I am facing is another building and in another building which is in another city (it is connected via VPN). Both lose the SSID.

The APs installed in my building, dont reboot nor lose SSID. I am completely baffled. Silly though that Controller might leave a reboot signal for APs when it is being rebooted but this also is false as the APs in building are not affected. 

 

oliviabrookss746
Community Member

If the APs stop beaconing when the controller becomes unreachable, it usually means they’re not truly operating in standalone FlexConnect mode.

Check that:

  • The WLAN is configured for FlexConnect local switching

  • The APs are in FlexConnect mode (not local mode)

  • AP fallback / standalone” behavior is properly enabled

  •  

Also verify there are no central auth dependencies (like RADIUS reachable only via controller path). If authentication or policy is centralized, SSIDs can drop when the WLC goes away.

Since it works when booted without the controller but fails after losing it, it sounds like they’re not fully falling back to standalone operation.

The options you said, kindly suggest what will be the best solution. I want the APs to work even without any issue even if the controller is not present. If present, its a plus. But I also want smooth hands off roaming of users. 

If you want APs to keep working even when the controller goes down, the best setup is FlexConnect with local switching and local authentication.

Make sure:

  • WLAN is set to FlexConnect local switching

  • APs are in FlexConnect mode

  • Authentication doesn’t depend on the controller (use PSK or local RADIUS)

This way, when the controller is available → normal roaming works.
If it goes offline → APs still broadcast SSID and users stay connected.

Basically: controller helps roaming, but shouldn’t be required for operation.

I will implement these setting tonight and contact back. 
You said 

This way, when the controller is available → normal roaming works.
If it goes offline → APs still broadcast SSID and users stay connected.

Basically: controller helps roaming, but shouldn’t be required for operation.

But what if controller is not available, will roaming will work somehow ?

Wireless Lab io
Level 2
Level 2

Post your wlan, policy profile and ap join profile config from show run for analysis, its difficult to say what is wrong without seeing the current config.

wirelesslab.io

Hi, I am pasting the complete running config. I just observed something else now. When the controller is lost, the SSID is not shown no matter if i powered on the AP with controller connection, which was not happening before. This is specifically for the "Userwise" SSID.

Config looks fine to me. Which site tag is assigned to the AP that you are testing?

wirelesslab.io
Review Cisco Networking for a $25 gift card