- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-23-2023 08:51 PM
Hello,
I am using a WLC 9800 and I recently replaced my Aironet 2702's with Aironet 3802's. With the 2702's we had no issues and little downtime. However, since replacing them with 3802's, we're having a problem where randomly during the day, all of our end users disconnect from the wifi and when they try to log back in, it says "incorrect password". There is no indication as to why this is happeneing. It happens on all devices including iPhones and windows PC's. Resetting all of the AP's fixes the issue until it inevitably occurs again a couple days later. Could this be a bug, or could it be a configuration or hardware issue?
Thankyou for the help.
Solved! Go to Solution.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-24-2023 11:23 PM
Agreed with @marce1000 - you really need to get that IOS upgraded!
16.12 is already past the end of security fixes milestone (last year):
https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-xe-16/eos-eol-notice-c51-744154.html
So you're already running at risk and you will not get any more bug fixes for it so you need to move to a fully supported version of code. 17.9.3 is the latest extended support release and includes support for your 2702 APs. (17.3 is already going end of life so stay away from that).
The TAC recommended list (below) hasn't been updated with 17.9.3 yet but will be soon. You can check the release notes:
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-9/release-notes/rn-17-9-9800.html#whats-new-1793
But also note that you will need to upgrade to 17.3.5 or 17.6 before upgrading to 17.9.3 so I'd upgrade to 17.6.5 and then to 17.9.3:
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-9/release-notes/rn-17-9-9800.html#Cisco_Concept.dita_59a2987f-2633-4630-8c7b-a8e8aecdeaf7
Please click Helpful if this post helped you and Select as Solution (drop down menu at top right of this reply) if this answered your query.
------------------------------
TAC recommended codes for AireOS WLC's and TAC recommended codes for 9800 WLC's
Best Practices for AireOS WLC's, Best Practices for 9800 WLC's and Cisco Wireless compatibility matrix
Check your 9800 WLC config with Wireless Config Analyzer using "show tech wireless" output or "config paging disable" then "show run-config" output on AireOS and use Wireless Debug Analyzer to analyze your WLC client debugs
Field Notice: FN63942 APs and WLCs Fail to Create CAPWAP Connections Due to Certificate Expiration
Field Notice: FN72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Required
Field Notice: FN72524 IOS APs stuck in downloading state after 4 Dec 2022 due to Certificate Expired
- Fixed in 8.10.196.0, latest 9800 releases, 8.5.182.12 (8.5.182.13 for 3504) and 8.5.182.109 (IRCM, 8.5.182.111 for 3504)
Field Notice: FN70479 AP Fails to Join or Joins with 1 Radio due to Country Mismatch, RMA needed
How to avoid boot loop due to corrupted image on Wave 2 and Catalyst 11ax Access Points (CSCvx32806)
Field Notice: FN74035 - Wave2 APs DFS May Not Detect Radar After Channel Availability Check Time
Leo's list of bugs affecting 2800/3800/4800/1560 APs
Default AP console baud rate from 17.12.x is 115200 - introduced by CSCwe88390
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-23-2023 11:14 PM
What firmware is the controller running on?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-23-2023 11:50 PM
- Use https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity when this happens , you can have radioactive traces from clients analyzed with : https://cway.cisco.com/tools/WirelessDebugAnalyzer/ also check the logs for these failed connections on your authenticating environment, such as radius logs 2) Have a checkup of the controller configuration with the CLI command show tech wireless , have the output analyzed with https://cway.cisco.com/tools/WirelessAnalyzer/
3) Go for IOS-XE 17.9.3 (which also has support for Wave1 APs)
M.
-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-24-2023 09:41 PM
The controller's software version is 16.12.08.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-24-2023 11:41 PM - edited 04-25-2023 03:51 AM
@ts7575 wrote:
The controller's software version is 16.12.08.
Uhhhh ... Wut? And WHY? 16.12.X is well accepted and well known to be buggy, unreliable and unstable across all Technologies: Wired, Wireless, Routing.
Upgrade to 17.9.3.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-24-2023 10:25 PM
According to the debug analyzer, all the clients are getting this error, "Controller initiated client deletion with code: CO_CLIENT_DELETE_REASON_KEY_XCHNG_TIMEOUT. Code means: Maximum retransmissions of M1 during 4-Way Handshake".
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-24-2023 11:07 PM
- FYI : https://bst.cloudapps.cisco.com/bugsearch?pf=prdNm&kw=CO_CLIENT_DELETE_REASON_KEY_XCHNG_TIMEOUT&bt=custV&sb=anfr , upgrade to IOS-XE 17.9.3 and try again ,
M.
-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-24-2023 11:23 PM
Agreed with @marce1000 - you really need to get that IOS upgraded!
16.12 is already past the end of security fixes milestone (last year):
https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-xe-16/eos-eol-notice-c51-744154.html
So you're already running at risk and you will not get any more bug fixes for it so you need to move to a fully supported version of code. 17.9.3 is the latest extended support release and includes support for your 2702 APs. (17.3 is already going end of life so stay away from that).
The TAC recommended list (below) hasn't been updated with 17.9.3 yet but will be soon. You can check the release notes:
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-9/release-notes/rn-17-9-9800.html#whats-new-1793
But also note that you will need to upgrade to 17.3.5 or 17.6 before upgrading to 17.9.3 so I'd upgrade to 17.6.5 and then to 17.9.3:
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-9/release-notes/rn-17-9-9800.html#Cisco_Concept.dita_59a2987f-2633-4630-8c7b-a8e8aecdeaf7
Please click Helpful if this post helped you and Select as Solution (drop down menu at top right of this reply) if this answered your query.
------------------------------
TAC recommended codes for AireOS WLC's and TAC recommended codes for 9800 WLC's
Best Practices for AireOS WLC's, Best Practices for 9800 WLC's and Cisco Wireless compatibility matrix
Check your 9800 WLC config with Wireless Config Analyzer using "show tech wireless" output or "config paging disable" then "show run-config" output on AireOS and use Wireless Debug Analyzer to analyze your WLC client debugs
Field Notice: FN63942 APs and WLCs Fail to Create CAPWAP Connections Due to Certificate Expiration
Field Notice: FN72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Required
Field Notice: FN72524 IOS APs stuck in downloading state after 4 Dec 2022 due to Certificate Expired
- Fixed in 8.10.196.0, latest 9800 releases, 8.5.182.12 (8.5.182.13 for 3504) and 8.5.182.109 (IRCM, 8.5.182.111 for 3504)
Field Notice: FN70479 AP Fails to Join or Joins with 1 Radio due to Country Mismatch, RMA needed
How to avoid boot loop due to corrupted image on Wave 2 and Catalyst 11ax Access Points (CSCvx32806)
Field Notice: FN74035 - Wave2 APs DFS May Not Detect Radar After Channel Availability Check Time
Leo's list of bugs affecting 2800/3800/4800/1560 APs
Default AP console baud rate from 17.12.x is 115200 - introduced by CSCwe88390
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-28-2023 02:17 AM
I successfully upgraded today, but didn’t fully read your reply and missed the link for the bug about older AP’s remaining in the downloading state. Since we are still using a couple of 2700’s in our network, I had to roll back to 16.12 for now. I will attempt the upgrade again next week and implement the work around, so we can keep our 2700’s online. Then I will have to wait a couple days to see if we get the authentication issue again or not.
Also, an additional question. Under Wireless>Access Points>General, it says our boot version for the 3800’s is 1.1.2.4. What exactly is the “boot version”?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-28-2023 03:05 AM
- Note that 17.9.3 will support the 2700 and other older Wave APs again. It was done because of many customers having those.
M.
-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-28-2023 06:19 AM
What version did you try to upgrade to?
17.3.7 and 17.9.3 both have the fix integrated already.
Please click Helpful if this post helped you and Select as Solution (drop down menu at top right of this reply) if this answered your query.
------------------------------
TAC recommended codes for AireOS WLC's and TAC recommended codes for 9800 WLC's
Best Practices for AireOS WLC's, Best Practices for 9800 WLC's and Cisco Wireless compatibility matrix
Check your 9800 WLC config with Wireless Config Analyzer using "show tech wireless" output or "config paging disable" then "show run-config" output on AireOS and use Wireless Debug Analyzer to analyze your WLC client debugs
Field Notice: FN63942 APs and WLCs Fail to Create CAPWAP Connections Due to Certificate Expiration
Field Notice: FN72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Required
Field Notice: FN72524 IOS APs stuck in downloading state after 4 Dec 2022 due to Certificate Expired
- Fixed in 8.10.196.0, latest 9800 releases, 8.5.182.12 (8.5.182.13 for 3504) and 8.5.182.109 (IRCM, 8.5.182.111 for 3504)
Field Notice: FN70479 AP Fails to Join or Joins with 1 Radio due to Country Mismatch, RMA needed
How to avoid boot loop due to corrupted image on Wave 2 and Catalyst 11ax Access Points (CSCvx32806)
Field Notice: FN74035 - Wave2 APs DFS May Not Detect Radar After Channel Availability Check Time
Leo's list of bugs affecting 2800/3800/4800/1560 APs
Default AP console baud rate from 17.12.x is 115200 - introduced by CSCwe88390
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-31-2023 09:55 AM
I would like to report that I am also having this problem on my Catalyst 9800 WLC. Code is 17.12.1
I have all Catalyst 9130 WAP's in my environment.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-31-2023 10:09 AM
@t3rebello Start a new thread , describe the problem(s) as you are experiencing it/them , and don't forget to include the mentioned wireless environment parameters (models , software versions).
M.
-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-31-2023 10:13 AM
I will do that, thank you
