cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2825
Views
7
Helpful
17
Replies

not goin

maged altwaiti
Level 1
Level 1

we have WLC 5508 S.W ver 7.6.110.0

and  .AP 1602 i

suddenly ap can not goin with WLC 

error massge 

*Dec 4 06:14:22.139: %CAPWAP-3-ERRORLOG: Go join a capwap controller
*Dec 4 06:14:23.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 10.9.0.10 peer_port: 5246
*Dec 4 06:14:23.399: %DTLS-5-ALERT: Received FATAL : Certificate unknown alert from 10.9.0.10
*Dec 4 06:14:23.399: %CAPWAP-3-ERRORLOG: Bad certificate alert received from peer.
*Dec 4 06:14:23.399: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 10.9.0.10:5246
*Dec 4 06:14:23.399: %CAPWAP-3-ERRORLOG: Invalid event 40 & state 3 combination.
*Mar 1 00:01:27.455: %CAPWAP-3-ERRORLOG: Did not get log server settings from DHCP.
*Mar 1 00:01:28.055: %CAPWAP-3-ERRORLOG: Could Not resolve CISCO-CAPWAP-CONTROLLER

 

how i can solve it ?

.

 

regard<<<

17 Replies 17

Mark Elsen
Hall of Fame
Hall of Fame

 

 - FYI : https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html
    The controller software version installed is ancient ; as per https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html
             use https://software.cisco.com/download/specialrelease/2702eede2b47a5c3bb40795bbe836af6

    Then you can also use the workarounds from the field notice : ap cert-expiry-ignore {mic|ssc} enable

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

where i execute  ap cert-expiry-ignore {mic|ssc} enable?

 

Do it in

Cli of wlc

MHM

 

                                      >...where i execute  ap cert-expiry-ignore {mic|ssc} enable?
  On the controller CLI but  you need to upgrade first according to my initial reply because that command is only available starting from 8.3.x

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

Dose this workaround solve the problem if the MIC is expired in both WLC and AP?  OR it just solve the problem if the MIC of AP expired?

I think the AP not validation the expire date of WLC cert. 

Only WLC do that validate 

MHM

Both:
It takes effect on the WLC immediately (for expired AP cert).
It takes effect on the AP after the AP has downloaded the new software version, and joined the WLC to get the config update from the WLC (for expired WLC cert).

That's why you must follow all the steps, in the correct order, to get it fully fixed.

Rich R
VIP
VIP

You need to follow the steps in the field notice carefully.
1. Turn off NTP and set WLC date/time back to before the certs expired - this is a temporary workaround.
2. Upgrade the WLC to 8.5.182.11.  Because you are using such an old version it would be best to upgrade to 8.0.152.0 first and then upgrade to 8.5.182.11
3. Then enter the commands as advised by Marce (they are not supported on earlier code)
4. Allow all the APs to download the new software and the new commands from the WLC
5 When all APs are updated with new code and new config then you can re-enable NTP on the WLC to operate with correct time.

Dose this workaround solve the problem if the MIC is expired in both WLC and AP?  OR it just solve the problem if the MIC of AP expired?

 

maged altwaiti
Level 1
Level 1

my WLC 5508 - 7-6-110

what command i can use it to solve problem until upgrade WLC to 8.5?

 

 

                 >my WLC 5508 - 7-6-110
                 >what command i can use it to solve problem until upgrade WLC to 8.5?
   None, you really need those upgrade(s) I mentioned to implement the workaround provided earlier , 

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

Did you read the field notice or the summary steps I already provided above?

Did you read my reply above summarising the steps?

Review Cisco Networking for a $25 gift card