cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1063
Views
2
Helpful
7
Replies

DTLS-3-HANDSHAKE_FAILURE | AIR-CT2504-K9

at@ps
Level 1
Level 1

Hey All,

I have a AIR-CT2504-K9 WLC [version = 8.5.105.0] with 17 APs mix from these AP Models:

AIR-AP2802I-E-K9

AIR-CAP1532E-I-K9

AIR-CAP1832E-I-K9

AIR-AP2702I-E-K9 

I got this error: "DTLS-3-HANDSHAKE_FAILURE: openssl_dtls.c:844 Failed to complete DTLS handshake."

Then all APs with AIR-AP2702I-E-K9 Model became unreachable from the WLC.

I searched about this issue and the issue may be one of three options:

1. firmware update is needed

2. OR NTP misconfigured, {I run show ntp status} but it does not work!

3. OR regenerate the MIC certificate, {I don't know how to check the cert status nor how to regenerate it !!}

Could you please help!

I think the upgrade to 8.5.182.0 is needed since the current firmware is ancient!! Also, all current APs compatible with it.

7 Replies 7

Hi,

You could troubleshooting this issue refer to the link as below..

https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Rps-Cheers | If it solves your problem, please mark as answer. Thanks !

marce1000
Hall of Fame
Hall of Fame

 

  - Try (on the controller ) :  ap cert-expiry-ignore ssc enable 
                                           ap cert-expiry-ignore mic enable 

  M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

I tried this command, but it solves the issue temporarily.

I need to solve it permanently!

 

 - What do you mean by temporarily : explain what you ate observing ?

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

I tried the command you mentioned yesterday at the first time the error came up and the AP reach the WLC successfully. today the same issue occurred again!

 

 - at@ps   Remember to always save the configuration after making changes on the controller.
                    If the issue  happens again , then check the controller configuration with the
                   CLI command show run-config  
                               ; check if the directives are still present,

   M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Rich R
VIP
VIP

Yes - you need to upgrade to 8.5.182.12 (link below) and refer to all the Field Notices linked in my signature below.

In particular you need to follow all the steps, in the right order, in FN63942 to solve the problem permanently.

Review Cisco Networking for a $25 gift card