12-04-2023 01:49 AM
we have WLC 5508 S.W ver 7.6.110.0
and .AP 1602 i
suddenly ap can not goin with WLC
error massge
*Dec 4 06:14:22.139: %CAPWAP-3-ERRORLOG: Go join a capwap controller
*Dec 4 06:14:23.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 10.9.0.10 peer_port: 5246
*Dec 4 06:14:23.399: %DTLS-5-ALERT: Received FATAL : Certificate unknown alert from 10.9.0.10
*Dec 4 06:14:23.399: %CAPWAP-3-ERRORLOG: Bad certificate alert received from peer.
*Dec 4 06:14:23.399: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 10.9.0.10:5246
*Dec 4 06:14:23.399: %CAPWAP-3-ERRORLOG: Invalid event 40 & state 3 combination.
*Mar 1 00:01:27.455: %CAPWAP-3-ERRORLOG: Did not get log server settings from DHCP.
*Mar 1 00:01:28.055: %CAPWAP-3-ERRORLOG: Could Not resolve CISCO-CAPWAP-CONTROLLER
how i can solve it ?
.
regard<<<
12-04-2023 02:05 AM
- FYI : https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html
The controller software version installed is ancient ; as per https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html
use https://software.cisco.com/download/specialrelease/2702eede2b47a5c3bb40795bbe836af6
Then you can also use the workarounds from the field notice : ap cert-expiry-ignore {mic|ssc} enable
M.
12-04-2023 02:16 AM
where i execute ap cert-expiry-ignore {mic|ssc} enable?
12-04-2023 02:27 AM
Do it in
Cli of wlc
MHM
12-04-2023 03:26 AM
>...where i execute ap cert-expiry-ignore {mic|ssc} enable?
On the controller CLI but you need to upgrade first according to my initial reply because that command is only available starting from 8.3.x
M.
12-17-2023 09:28 PM
Dose this workaround solve the problem if the MIC is expired in both WLC and AP? OR it just solve the problem if the MIC of AP expired?
12-17-2023 10:43 PM
I think the AP not validation the expire date of WLC cert.
Only WLC do that validate
MHM
12-18-2023 07:20 AM
Both:
It takes effect on the WLC immediately (for expired AP cert).
It takes effect on the AP after the AP has downloaded the new software version, and joined the WLC to get the config update from the WLC (for expired WLC cert).
That's why you must follow all the steps, in the correct order, to get it fully fixed.
12-04-2023 06:21 AM
You need to follow the steps in the field notice carefully.
1. Turn off NTP and set WLC date/time back to before the certs expired - this is a temporary workaround.
2. Upgrade the WLC to 8.5.182.11. Because you are using such an old version it would be best to upgrade to 8.0.152.0 first and then upgrade to 8.5.182.11
3. Then enter the commands as advised by Marce (they are not supported on earlier code)
4. Allow all the APs to download the new software and the new commands from the WLC
5 When all APs are updated with new code and new config then you can re-enable NTP on the WLC to operate with correct time.
12-16-2023 10:25 PM
Dose this workaround solve the problem if the MIC is expired in both WLC and AP? OR it just solve the problem if the MIC of AP expired?
12-17-2023 07:49 AM
Both
12-04-2023 11:50 PM
my WLC 5508 - 7-6-110
what command i can use it to solve problem until upgrade WLC to 8.5?
12-05-2023 12:01 AM
>my WLC 5508 - 7-6-110
>what command i can use it to solve problem until upgrade WLC to 8.5?
None, you really need those upgrade(s) I mentioned to implement the workaround provided earlier ,
M.
12-05-2023 02:19 AM
Did you read the field notice or the summary steps I already provided above?
12-17-2023 07:50 AM
Did you read my reply above summarising the steps?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide