cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
585
Views
1
Helpful
2
Replies

DTLS Handshake Failure in 9800-CL Mobility Group

Dilip Rehan
Level 1
Level 1

I have two Cisco 9800-CL WLCs in the same mobility group:

  • WLC-1: 192.168.138.130/24

  • WLC-2: 192.168.138.132/24

UDP 16666 is allowed between them, DTLS is enabled, and keepalives are exchanged.

However, I keep getting:

33.png

I’ve checked mobility peer cofig, NTP sync, MTU, connectivity, and firewall logs. Both WLCs can ping each other.

Has anyone seen this before? Are additional ports/settings needed beyond UDP 16666?

2 Accepted Solutions

Accepted Solutions

Mark Elsen
Hall of Fame
Hall of Fame

 

 - @Dilip Rehan  Verify the configuration of both controllers with the CLI command : show tech wireless 

 And feed the output from that into : https://cway.cisco.com/wireless-config-analyzer/

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

View solution in original post

Thank you so much. The issue was with certficate mismacted. Regenreated a new One from both controllers and the mobility groups is up. 

View solution in original post

2 Replies 2

Mark Elsen
Hall of Fame
Hall of Fame

 

 - @Dilip Rehan  Verify the configuration of both controllers with the CLI command : show tech wireless 

 And feed the output from that into : https://cway.cisco.com/wireless-config-analyzer/

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

Thank you so much. The issue was with certficate mismacted. Regenreated a new One from both controllers and the mobility groups is up. 

Review Cisco Networking for a $25 gift card