02-26-2026 11:22 AM
Hello
I have a very strange problem as I said in the subject, I have flexconnect enabled and other all related settings enabled but still when controller is unreachable, the APs stop showing SSID and stop working.
Controller is: Cisco Catalyst 9800-CL Wireless Controller 17.13.1 (less than 50 APs) so no issue about licensing.
APs are: 3802i with firmware version ap3g3-k9w8-tar.153-3.JPR
And this is kind of intermittent, when I turn on the AP while having a firewall rule to block the controller, it works fine. but when it is already ON and working and then the controller is not reachable, it stops beaconing the SSID and lights start changing color. I am attaching the startup config.
02-26-2026 11:36 AM
- @safiullahtariq1 Check logs on the access point when it starts changing controller
+ Validate the 9800-CL controller configuration with the CLI command
show tech wireless and feed the output from that into Wireless Config Analyzer
M.
02-26-2026 12:20 PM
Upon checking you config file, the problem is related to " no capwap fallback" under AP profile. Disable it and test.
02-26-2026 02:13 PM
@safiullahtariq1 FlexConnect APs stop broadcasting the SSID in standalone mode because 802.11r (Fast Transition) is currently enabled on WLAN, which is architecturally not supported in FlexConnect standalone mode or with Local Authentication - therefore to allow the SSID to survive a WLC outage, u need to disable Fast Transition and ensure Local Authentication is applied
02-27-2026 04:29 AM - edited 02-27-2026 04:31 AM
Stefan, thank you for the reply. Your reply makes me ask another question. If this is the case then how can I achieve smooth hands-off roaming if I disable Fast Transition? I dont want the user to be disconnected while making a transition from one AP to another.
I request that you please check my existing settings and help me with that. Personally I am in strange state.
02-27-2026 04:40 AM
at the moment, when AP is started without controller, no issues (but i dont know the case of fast transition)
When AP is connected to the controller, well that works fine as it is suppose to.
When the AP is already booted and working and then the controller is unreachable, only then the issue arises the SSID does not survive a WLC outage.
but when during the A
02-27-2026 04:52 AM
- @safiullahtariq1 Remember to execute the basic controller configuration validation procedure :
with the CLI command
show tech wireless and feed the output from that into Wireless Config Analyzer
The above procedure is always mandatory at all times!
- Also use the controller CLI command : wireless config validate
+ Enabling Syslog Messages in Access Points and Controller towards a Syslog Server
will provide additional info's , for instance when a flexconnect access point looses
connection with the controller :
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/b_wl_16_10_cg/enabling-syslog-messages-in-access-points-and-controller-for-syslog-server.html
M.
03-02-2026 02:34 PM
Today, I have tested and something very strange thing has happened.
Controller Available: SSID Available (Console Cable connection, Flexconnect shifted to Local mode (I forgot the exact msg)).
Controller Not Available during normal operation: SSID Available. (Console Cable connection, Flexconnect shifted to Local mode)
AP Powered On while there is NO Controller: SSID Available (Console Cable connection, Flexconnect shifted to Local mode).
Change Done: NONE. I dont know what is the matter. This time to be sure, I also made videos just to make sure that I am not doing something wrong and im not going nuts. I even went beyond and made firewall rules to and tested with them also so that controller is not available, still no issue.
What was happening previously and what I am unable to understand is, Controller is placed in my city, the issue I am facing is another building and in another building which is in another city (it is connected via VPN). Both lose the SSID.
The APs installed in my building, dont reboot nor lose SSID. I am completely baffled. Silly though that Controller might leave a reboot signal for APs when it is being rebooted but this also is false as the APs in building are not affected.
02-26-2026 02:58 PM - edited 03-01-2026 02:47 PM
If the APs stop beaconing when the controller becomes unreachable, it usually means they’re not truly operating in standalone FlexConnect mode.
Check that:
The WLAN is configured for FlexConnect local switching
The APs are in FlexConnect mode (not local mode)
“AP fallback / standalone” behavior is properly enabled
Also verify there are no central auth dependencies (like RADIUS reachable only via controller path). If authentication or policy is centralized, SSIDs can drop when the WLC goes away.
Since it works when booted without the controller but fails after losing it, it sounds like they’re not fully falling back to standalone operation.
02-27-2026 04:42 AM
The options you said, kindly suggest what will be the best solution. I want the APs to work even without any issue even if the controller is not present. If present, its a plus. But I also want smooth hands off roaming of users.
02-27-2026 05:03 AM
If you want APs to keep working even when the controller goes down, the best setup is FlexConnect with local switching and local authentication.
Make sure:
WLAN is set to FlexConnect local switching
APs are in FlexConnect mode
Authentication doesn’t depend on the controller (use PSK or local RADIUS)
This way, when the controller is available → normal roaming works.
If it goes offline → APs still broadcast SSID and users stay connected.
Basically: controller helps roaming, but shouldn’t be required for operation.
02-27-2026 05:38 AM
I will implement these setting tonight and contact back.
You said
This way, when the controller is available → normal roaming works.
If it goes offline → APs still broadcast SSID and users stay connected.
Basically: controller helps roaming, but shouldn’t be required for operation.
But what if controller is not available, will roaming will work somehow ?
02-27-2026 07:40 AM
Post your wlan, policy profile and ap join profile config from show run for analysis, its difficult to say what is wrong without seeing the current config.
02-27-2026 11:21 AM
03-03-2026 03:09 AM
Config looks fine to me. Which site tag is assigned to the AP that you are testing?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide