cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3795
Views
15
Helpful
9
Replies

%DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to xxx.xxx.xxx.xxx

03300209
Level 1
Level 1

background:

1852I in ME mode. 1702I flash to correct version as matrix list.

from 8.10 , 8.8, 8.5 , until 8.2

used JPN , JF10 until JC15.

both have the problem on 1702I joined in vWLC on 1852I, 

"%DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to xxx.xxx.xxx.xxx"

How to fix it? Thanks. 

my target: all 1852I in ME, can vWLC, and all 1752I at least can capwap in vWLC.

9 Replies 9

marce1000
Hall of Fame
Hall of Fame

 

 - Check logs on the controller too , when the access point tries to join.

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

spamApTask0: Sep 22 11:26:03.453: %CAPWAP-3-CCO_ASD_LOG_ERROR: spam_lrad.c:94457 CCO ASD logging failed on AP-MAC 00:2c:c8:62:17:50, reason: Index not found unable to delete tmp log
*spamApTask0: Sep 22 11:26:03.452: %CAPWAP-3-DTLS_CON_CLOSED: capwap_ac_dtls.c:149 Not sending DTLS session closed notification to CAPWAP for AP 2c:5a:0f:53:2c:e0
*spamApTask0: Sep 22 11:26:03.452: %CAPWAP-3-DTLS_CLOSED_ERR: capwap_ac_sm.c:7130 2c:5a:0f:53:2c:e0: DTLS connection closed forAP 10:228:135:13 (57718), Controller: 10:228:135:1 (5246) Multiple Join Request
*osapiBsnTimer: Sep 22 11:26:00.170: %SIM-3-ARP_SND_FAIL: sim.c:1692 Unable to send ARP Request. Local MAC: 68:CA:E4:40:20:60.Ip Addr: 1.135.228.10Interface # 1. Vlan Id: 0
*sntpReceiveTask: Sep 22 11:26:00.076: %DNS-3-GETADDRINFO_ERR: dns_query.c:240 Internal Error: getaddrinfo failed for 2.ciscome.pool.ntp.org
*sntpReceiveTask: Sep 22 11:26:00.076: %DNS-3-GETADDRINFO_ERR: dns_query.c:240 Internal Error: getaddrinfo failed for 1.ciscome.pool.ntp.org
*sntpReceiveTask: Sep 22 11:26:00.075: %DNS-3-GETADDRINFO_ERR: dns_query.c:240 Internal Error: getaddrinfo failed for 0.ciscome.pool.ntp.org
*spamApTask0: Sep 22 11:25:58.457: %LWAPP-3-LWAPP_JOIN_AP_JOIN_ERR: capwap_ac_sm.c:4953 The system has received a join request from AP 10.228.135.13 that doesn'tsupport image download through GUI. Change the image downloadmode to either TFTP or CCO

 

 - Could you start by using and or configuring a 'local' NTP server on the 1852 , such as you use on the intranet and that the controller can reach (too).

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

 

 - As for , >...%SIM-3-ARP_SND_FAIL , please check this thread : https://community.cisco.com/t5/wireless/strange-error-sim-3-arp-snd-fail-in-logging/td-p/1180653 , check if actions mentioned can help.

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Rich R
VIP
VIP

Let's clarify some info.  You're trying to join a 1702 AP to a WLC right?
You mention ME and vWLC (completely different products) - what model is your WLC?
What version of software is your WLC running? (you mentioned 4 different release trains but not what you're actually using)

So based on the logs you provided I'm guessing you are in fact using ME not vWLC.  The logs actually TELL you what the problem is: "AP 10.228.135.13 that doesn'tsupport image download through GUI. Change the image downloadmode to either TFTP or CCO"
- you need to set the image download mode to TFTP and you need to provide a TFTP server with the correct images available for download.  You need to download the ME image zip file for your software version from cisco.com and unzip that file on your TFTP server where the AP can download the AP image from.

8.5.171  should be JF14 , I checked matrix. I mentioned different release, that should be a test. diff release should be have a master and supporting list to 18xx 16xx 17xx.

as I mentioned, I have 2500 in current wlc, and I want to use ME to build connection on 18xx to 16xx and 17xx.

of course in diff vlan

The system has received a join request from AP 10.228.135.13 that doesn'tsupport image download through GUI. Change the image downloadmode to either TFTP or CCO

whether I need to use a degrade verson on 1700, then can be auto upgrade during the connected with ME?

ap3g2 ap3g2-k9w8-mx.153-3.JF14

AIR-AP1850-K9-ME-8-5-171-0

my 2500 also 8.5.171, I tested. connected 1700 to 2500 , then get JF14 version from controller, reset all config, change connection to ME. still have same issue on DLTS...

03300209
Level 1
Level 1

*osapiBsnTimer: Sep 26 10:03:27.345: %SIM-3-ARP_SND_FAIL: sim.c:1692 Unable to send ARP Request. Local MAC: 68:CA:E4:40:20:60.Ip Addr: 1.135.228.10Interface # 1. Vlan Id: 0
*emWeb: Sep 26 10:03:25.555: %CLI-3-LOGIN_FAILED: cliutil.c:709 Login failed. User:MagnaXMas22509, Service type:-8. Username/Password length must be between 3 and 128 characters.
*spamApTask0: Sep 26 10:03:18.269: %CAPWAP-3-CCO_ASD_LOG_ERROR: spam_lrad.c:94457 CCO ASD logging failed on AP-MAC 00:2c:c8:62:17:50, reason: Index not found unable to delete tmp log
*spamApTask0: Sep 26 10:03:18.269: %CAPWAP-3-DTLS_CON_CLOSED: capwap_ac_dtls.c:149 Not sending DTLS session closed notification to CAPWAP for AP 2c:5a:0f:53:2c:e0
*spamApTask0: Sep 26 10:03:18.268: %CAPWAP-3-DTLS_CLOSED_ERR: capwap_ac_sm.c:7130 2c:5a:0f:53:2c:e0: DTLS connection closed forAP 10:228:135:13 (8566), Controller: 10:228:135:1 (5246) Multiple Join Request
*osapiBsnTimer: Sep 26 10:03:17.423: %SIM-3-ARP_SND_FAIL: sim.c:1692 Unable to send ARP Request. Local MAC: 68:CA:E4:40:20:60.Ip Addr: 1.135.228.10Interface # 1. Vlan Id: 0
*spamApTask0: Sep 26 10:03:13.269: %LWAPP-3-LWAPP_JOIN_AP_JOIN_ERR: capwap_ac_sm.c:4953 The system has received a join request from AP 10.228.135.13 that doesn'tsupport image download through GUI. Change the image downloadmode to either TFTP or CCO
*spamApTask0: Sep 26 10:03:13.010: %CAPWAP-3-CCO_ASD_LOG_ERROR: spam_lrad.c:94457 CCO ASD logging failed on AP-MAC 00:2c:c8:62:17:50, reason: Index not found unable to delete tmp log
*spamApTask0: Sep 26 10:03:13.009: %CAPWAP-3-DTLS_CON_CLOSED: capwap_ac_dtls.c:149 Not sending DTLS session closed notification to CAPWAP for AP 2c:5a:0f:53:2c:e0
*spamApTask0: Sep 26 10:03:13.009: %CAPWAP-3-DTLS_CLOSED_ERR: capwap_ac_sm.c:7130 2c:5a:0f:53:2c:e0: DTLS connection closed forAP 10:228:135:13 (8566), Controller: 10:228:135:1 (5246) Multiple Join Request

Arshad Safrulla
VIP Alumni
VIP Alumni

Hi,

ME is not a full fledged WLC, therefor you cannot expect it to behave like 2504. When you connect an AP to 2504 WLC, WLC itself will push the image to the AP so both WLC and AP will run the same image. But in Mobility express due to resource shortage AP running ME doesn't have storage and also processing power to perform this function. So you need to rely on 3rd party TFTP server running in your environment to push the images. As @Rich R mentioned download and extract the image files from cisco.com to tftp root and configurethe ttp path in your ME WLC. So joining AP's know here to go and grab the corresponding image. Otherwise you need to manually upgrade the AP image to match the ME image.

use the below link for more info

https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-2/b_Mobility_Express_Deployment_guide/b_Mobility_Express_Deployment_guide_chapter_01000.html#task_4387C8D3ADCA4D9EA365763A1DA5B2E2:~:text=Controller)%20%3Eshow%20time-,Updating%20C...

Hello Arshad,

Thanks. As @Rich R mentioned, I find out the zip file as before, ap3g2-k9w8-mx.153-3.JF14 that is the target package in zip file ap3g2, however, that still not correct. I mean, that should be not a version problem. 

you can see, in 8.10.xxx.x , 1850 still can mount a 1700. (1600 should be can be use in previous version, 8.5.xxx.x)

03300209_0-1664238963608.png

03300209_1-1664239173533.png

from AP side, you can see, there should be a problem on DTLS-5-SEND_ALERT duing the sendjoin...

The Contoller should be close the DTLS with some reason.

*Sep 22 03:32:37.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 10.228.135.1 peer_port: 5246
*Sep 22 03:32:37.251: %CAPWAP-5-DTLSREQSUCC: DTLS connection created sucessfully peer_ip: 10.228.135.1 peer_port: 5246
*Sep 22 03:32:37.255: %CAPWAP-5-SENDJOIN: sending Join Request to 10.228.135.1
*Sep 22 03:32:42.251: %CAPWAP-5-SENDJOIN: sending Join Request to 10.228.135.1
*Sep 22 03:32:42.255: %DTLS-5-ALERT: Received WARNING : Close notify alert from 10.228.135.1
*Sep 22 03:32:42.255: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 10.228.135.1:5246
*Sep 22 03:32:42.255: AP has SHA2 MIC certificate - Using SHA2 MIC certificate for DTLS.

I mentioned, I tried 2500 as controller, 1700 can be enrolled. I think that should be not a problem on AP. maybe on ME Controller.

 

Review Cisco Networking for a $25 gift card