05-15-2023 04:05 AM
I have been receiving these error messages while I'm trying to join a LWAP to the WLC. I tried running the command config ap cert-expiry-ignore mic enable on the WLC, but it won't work.
WLC software version is 7.6.100.0.
AP model AIR-CAP3502I-E-K9
AP image /ap3g1-k9w8
*May 15 01:55:53.128: %CAPWAP-3-ERRORLOG: Certificate verification failed!
*May 15 01:55:53.132: DTLS_CLIENT_ERROR: ../capwap/base_capwap/capwap/base_capwap_wtp_dtls.c:467 Certificate verified failed!
*May 15 01:55:53.132: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to 192.168.10.6:5246
*May 15 01:55:53.132: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 192.168.10.6:5246
*May 15 01:55:53.132: %CAPWAP-3-ERRORLOG: Invalid event 38 & state 3 combination.
*May 15 01:56:58.003: %CAPWAP-3-ERRORLOG: Go join a capwap controller
*May 15 01:55:53.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.10.6 peer_port: 5246
*May 15 01:56:23.007: DTLS_CLIENT_ERROR: ../capwap/base_capwap/dtls/base_capwap_dtls_connection_db.c:2176 Max retransmission count reached!
*May 15 01:56:53.001: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 192.168.10.6:5246
*May 15 01:56:53.051: %LWAPP-3-CLIENTERRORLOG: LWAPP LED Init: incorrect led state 255
*May 15 01:56:53.073: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to administratively down
*May 15 01:56:53.073: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to administratively down
Solved! Go to Solution.
05-15-2023 05:07 AM
Hello,
7.6 is pretty old verion. This AP 3502 started with 8.1.122.0
Check the compatibility matrix:
https://www.cisco.com/c/en/us/td/docs/wireless/compatibility/matrix/compatibility-matrix.html
with this version you can join 1700 , 2700 ,3700
05-15-2023 09:14 AM - edited 05-15-2023 09:20 AM
Yes so then 8.5.182.7 (link below) and make sure all your AP models will still be supported.
3502 will be ok.
Review https://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/crn85mr8.html#software-rel-types-and-recommendations_85mr8 for any gotchas when upgrading across so many different releases.
Also see https://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/crn80mr5.html#pgfId-1373277 for going from 7.6 to 8.x
05-15-2023 05:07 AM
Hello,
7.6 is pretty old verion. This AP 3502 started with 8.1.122.0
Check the compatibility matrix:
https://www.cisco.com/c/en/us/td/docs/wireless/compatibility/matrix/compatibility-matrix.html
with this version you can join 1700 , 2700 ,3700
05-15-2023 08:29 AM
Read field notice 63942 (below) slowly, carefully and thoroughly!
AireOS 7.6.x does NOT have the fix/workaround capability for that command. That was added in 7.0.252.0, 7.4.140.0 & 8.1.102.0 so your only option is to upgrade to a recent 8.x release. Also take note of the other field notices below which may be relevant to you. You did not bother to mention what model of WLC you're using so I cannot make any more specific recommendations but you'll likely need to use 8.5.182.7 (link below) depending on what other APs you need to support - refer to the compatibility matrix (below and as linked by Flavio above).
05-15-2023 08:48 AM - edited 05-15-2023 08:50 AM
yeah, I forgot to add the model to the original post. My bad. It's 5508. I think it requires 8.5 as far as I could understand.
05-15-2023 09:14 AM - edited 05-15-2023 09:20 AM
Yes so then 8.5.182.7 (link below) and make sure all your AP models will still be supported.
3502 will be ok.
Review https://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/crn85mr8.html#software-rel-types-and-recommendations_85mr8 for any gotchas when upgrading across so many different releases.
Also see https://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/crn80mr5.html#pgfId-1373277 for going from 7.6 to 8.x
05-15-2023 08:42 AM
- If I recall correctly the minimum version to start with (supporting) that command is 8.3.x
M.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide