04-11-2023 11:11 PM - edited 04-11-2023 11:12 PM
Hi All,
I am facing EWLC WebGui access issue in my environment. We are using DNAC (2.3.3.6), Border/WLC role enable switch (9300 - 17.3.3) & EWLC concept for local sites. But somehow unable to access the EWLC through WebGUI & getting SSL error. Could you please help me out how to resolve that issue.
Please find the below some reference command output
ABC1#sh run | i http
http
enrollment url http://XX.XX.XX.XX:80/ejbca/publicweb/apply/scep/sdnscep
ip http server
ip http authentication local
ip http secure-server
ip http max-connections 16
ip http active-session-modules none
ip http client source-interface Loopback0
destination transport-method http
http-tlv-caching
http-tlv-caching
http-tlv-caching
ABC1#sh run | i crypto
crypto pki trustpoint TP-self-signed-XXXXXX
crypto pki trustpoint SLA-TrustPoint
crypto pki trustpoint sdn-network-infra-iwan
crypto pki trustpoint DNAC-CA
crypto pki certificate chain TP-self-signed-XXXXXX
crypto pki certificate chain SLA-TrustPoint
crypto pki certificate chain sdn-network-infra-iwan
crypto pki certificate chain DNAC-CA
crypto pki certificate pool
04-11-2023 11:40 PM
- What kind of SSL error are you getting (and or post screenshot) ?
M.
04-11-2023 11:45 PM
04-12-2023 12:00 AM
- Have a checkup of the controller configuration with the CLI command : show tech wireless , feed that output into :
https://cway.cisco.com/wireless-config-analyzer/
Also check the logs on the controller when the WebGui access is attempted ,
M.
04-12-2023 12:38 AM - edited 04-12-2023 12:44 AM
I checked in WLC logs, no such messages "WebGui access is attempted" found.
04-12-2023 01:36 AM
- Anything else in the logs when the WebGui access is attempted (?) , also reminder use this procedure too
Have a checkup of the controller configuration with the CLI command : show tech wireless , feed that output into :
https://cway.cisco.com/wireless-config-analyzer/
M.
04-12-2023 01:38 AM
Nothing is there related to WebGui.
04-12-2023 01:59 AM
- Have a checkup of the controller configuration with the CLI command : show tech wireless , feed that output into :
https://cway.cisco.com/wireless-config-analyzer/
M.
04-12-2023 02:05 AM
Yes, I pasted the output in given URL of show tech wireless. But nothing found in WLC logs related to WebGui access.
| 6 |
| Apr 12 2023 06:31:27.252 UTC: |
| Apr 12 2023 06:39:18.673 UTC: |
| Switch 1 R0/0: fed: Failed to allocate hardware resource for fib entry due to hardware resource exhaustion - rc:2054 |
| 1 |
| Apr 12 2023 01:43:29.445 UTC: |
| Apr 12 2023 01:43:29.445 UTC: |
| Switch 2 R0/0: dmiauthd: User 'dnac' authenticated successfully from XX.XX.XX.XX):36241 and was authorized for netconf over ssh. External groups: PRIV15 |
| 72 |
| Apr 12 2023 01:53:20.717 UTC: |
| Apr 12 2023 07:03:08.144 UTC: |
| Switch 2 R0/0: sessmgrd: Authentication failed for client (ec01.d568.1aec) with reason (No Response from Client) on Interface Gi2/0/25 AuditSessionID 21C3400A000000A671874CF6 |
| 3 |
| Apr 12 2023 04:35:21.011 UTC: |
| Apr 12 2023 06:11:01.146 UTC: |
| DHCP_SNOOPING drop message with mismatched source interface, the binding is not updated, message type: DHCPRELEASE, MAC sa: 48a2.e659.f34b |
| 3 |
| Apr 12 2023 05:29:47.094 UTC: |
| Apr 12 2023 07:04:36.633 UTC: |
| Login Success [user: rancid] [Source: XX.XX.XX.XX)] [localport: 22] at 05:29:47 UTC Wed Apr 12 2023 |
| 323 |
| Apr 12 01:43:14.503: |
| Apr 12 07:05:45.056: |
| catchall: show platform software flow switch 7 FP active ios monitor name dnacmonitor cache filter 0 0 0 0 0 timestamp 51127F2C0 |
| 3 |
| Apr 12 2023 01:51:03.839 UTC: |
| Apr 12 2023 06:03:38.064 UTC: |
| User dnac has exited tty session 1(10.76.17.16) |
| 1 |
| Apr 12 2023 06:03:38.063 UTC: |
| Apr 12 2023 06:03:38.063 UTC: |
| (exec timer expired, tty 1 (XX.XX.XX.XX)), user dnac |
04-12-2023 03:29 AM
- Try the procedure mentioned by Scott Fella from this thread :
https://community.cisco.com/t5/wireless/cisco-9800-wreless-controller-not-getting-the-http-or-https/td-p/3988305
M.
04-13-2023 06:07 AM - edited 04-13-2023 06:08 AM
Have you tried a different browser?
What browser and version are you using?
Is WLC and PC time both set correctly (NTP)?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide