05-01-2022 08:38 AM
Dear Community,
I have been running a network over a number of years (remotely) which has a Cisco 2504 WLC with LAP1042N-E Access Points (x5) and one AP (CAP1602I-E). The users have reported a problem of poor connectivity, once we have investigated the issue we are not seeing 3 of the 6 APs on the WLC. Strange thing is that we can ping all 6 APs???
Not sure what is going on. Happy to provide logs/dumps etc but I am working remotely however I have had one of thWLC, AP1042N,e (faulty) APs shipped to my house.
Solved! Go to Solution.
05-01-2022 04:04 PM
I suspect the WLC is running a fairly old firmware, probably early 8.0, and the APs have rebooted or crashed.
05-01-2022 09:25 AM
You may see AP on the network but not on the WLC. And you may see AP on the WLC but not propagating wireless signal.
Make sure the AP is properly configured on the switch. Check vlan and port mode.
Access the AP remotely and try to Ping the wlc
05-02-2022 12:12 PM
Thanks, but it used to work and nothing has changed on the switch, the other 3 APs are continuing to work.
05-01-2022 09:33 AM
check if AP join WLC,
check AP Certificate may be it expire.
05-01-2022 04:04 PM
I suspect the WLC is running a fairly old firmware, probably early 8.0, and the APs have rebooted or crashed.
05-02-2022 12:41 PM
Hi Leo, yes the Software Version is 7.6.100.0. What version would be recommended to fix this issue please?
05-02-2022 01:14 PM
In doing some more digging you seem to be correct (although I have not fixed this yet). Once I set the clock back in time on my Wireless Controller the APs started to come back. I am working remotely so I am not sure if I need to console into the APs to apply a permanent fix. Exploring further...
05-02-2022 01:26 PM
As I mention in first my comment, the issue is certificate
other workaround is using
ap cert-expiry-ignore mic enable
05-02-2022 03:56 PM - edited 05-02-2022 03:56 PM
@g.ghir wrote:
Hi Leo, yes the Software Version is 7.6.100.0. What version would be recommended to fix this issue please?
What APs are there?
1042 and 1600. Any other models?
05-02-2022 05:19 PM
If just the 1042 and 1600 then the highest version you can run is
8.3.150.0
As per the wireless compatibility matrix
https://www.cisco.com/c/en/us/td/docs/wireless/compatibility/matrix/compatibility-matrix.html
Then:
You will need to follow these steps:
Solution for Expired WLC Certificates
Situation: The WLC does not run a fixed software version and some APs cannot join.
Situation: The WLC runs fixed software, but some APs cannot join.
Alternatively as a work around before the upgrade you can roll the WLC clock manually back to before the certificate expired
Further details here: https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html
05-03-2022 02:37 AM
05-01-2022 04:19 PM
agree with @Leo Laohoo more than likely APs hitting MIC certificate expiry
05-02-2022 12:44 PM
Thanks Haydn,
I looked at the article but I have not worked on controllers so I need to do a bit more study. When I look at the logs I notice this error:
*spamApTask2: May 02 18:03:29.307: #DTLS-3-HANDSHAKE_FAILURE: openssl_dtls.c:698 Failed to complete DTLS handshake with peer
Does this have something to do with the issue?
05-07-2022 05:21 AM
Yes - the field notice tells you exactly what to do and @Haydn Andrews has even summarised that for you above.
You need to upgrade the WLC to a version with the fix/workaround (8.3.150.0 as Hayden suggested) and then apply the correct config as per the instructions.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: