08-02-2023 04:34 AM
Hi
The Cisco air-lap1252ag-e-k9 access point was damaged at the facility we service. In its place, we installed another one from service stock, but the administrator has a problem with adding it to the controller. He said the AP currently has firmware 3.0.51.0 and 8.0.120.0 is required for it to work properly with the controller. Where can I find the appropriate firmware, I know that the device is no longer supported, but does this mean that all files related to it have been removed?
Thank you for any advice, this is an old system that I hope will be modernized soon and we need to fix bugs
08-02-2023 04:54 AM
Once the device is retired, cisco remove the download option.
What you can try, based on this log "Peer certificate verification failed" is run the command:
config ap cert-expiry-ignore mic enable
Run this on the WLC and test.
08-02-2023 04:56 AM
Hi @maciejzurawek,
From the logs it looks like there is a certificate validation error. You may want to upgrade the AP with the latest code version from CCO with image recovery. It may also be that the controller time is outside the certificate validity interval, see link below to fix it.
08-04-2023 06:51 AM - edited 08-04-2023 06:52 AM
> He said the AP currently has firmware 3.0.51.0
No - it is currently running a recovery image (purely allows software download) version 12.4(10b)JA1.
It will need to download 12.4(25e)JAP4 software from the WLC running 8.0.120.0 as per the compatibility matrix below.
As the others have pointed out the AP cannot join because the WLC certificate has expired (AP cert has almost certainly expired too). This is fully explained in FN63942 below but briefly:
On the WLC you need to configure (if not already done):
config ap cert-expiry-ignore ssc enable
config ap cert-expiry-ignore mic enable
On the WLC you need to disable NTP, then change the date to before the WLC cert expired.
This will allow the AP to join the WLC, download the software from WLC and pick up the config change telling it to ignore the expired WLC cert, after it has reloaded onto the new software.
After the AP has the new software and config you can re-enable NTP on the WLC.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide