I have a WLC 5508 controller running 22.214.171.124 and I am trying to move the access points off this controller to a 9800-l running ios-xe 16.12.3
When I move an AP from the 5508 to the 9800 it will not join.
I have checked the other posts with similar issues and I have enabled data encryption on the AP and on the 9800-L controller as per the documentation. but this didn't solve the issue.
In the packet capture on the 9800 I can see the
1. discover request and response
2. Client Hello and response
3. Client Key exchange followed by the change cipher from the controller with everything set to use DTLS 1.0
4. AP sends a capwap join request
5. the WLC responds with a encrypted alert message.
6 the ap tries to send data but the WLC does not respond.
within the packet capture taken of the join request I can see the mac address of the of the ap (WTP Board data Base MAC Address) This address is on the 9800.
At this stage I am stuck, as there is nothing in the 9800-l logs to prevent it from joining.
I will be very grateful for some assistance on the issue.
The Access points are 2800.
I have used a brand new unit and it connected successfully to the 9800 controller
I failed this to the 5800, and the AP associated fine.
I then went to reassociate the same ap back to the 9800 but will not join.
I have check the date and time settings and they are correct and in sync.
Do you have any other suggestions?
since it is in a remote location I have done a factory reset via the CLI
I haven't tried it with the mode button.
In the packet captures taken it discovers the WLC authenticates sends the join message, and receives an encrypted alert back from the WLC.
I do notice the CAPwap tunnel is using TLS1.0 but when connected to the 5508 it is using TLS1.2
Can you post show certificate all from 5508 controller?
Is this the only solution. Because I am also having a similar scenario. Wherein my customer has 2800/3800 series AP and 5508 WLC. Not the 5508 is running on 126.96.36.199 code which refers to 15.3(3)JF14 IOS version on AP and if I check the wireless compatibility matrix then I need to have 15.3.(3)JPJ10 IOS version on the AP to get the AP connected to C9800 WLC. So its obvious that to get the AP to 15.3(3)JPJ10 I need to also upgrade 5508 WLC which is not possible since the last code support for 5508 WLC is 188.8.131.52 which refers to 15.3(3)JF15. which will not help in the migration. So how can we upgrade only the IOS version of the AP that too in bulk option. Because the AP count is very high. Doing it one by one would take a lot of time.
Thanks Rasika. Your input helps. Also I did found one article wherein it is mentioned we can do pre download image on the AP using the WLANPoller tool. Not sure of this tool. Have not heard or used this before. Below is the link.