02-22-2022 05:23 AM
Im a troubleshooting a scenario below.
As part of troubleshooting I tried to modify the Option 43 on DHCP server to a different WLC IP, The AP appeared on WLC(2) without issue.
Anyone had the same issue?
Note: No issue joining and discovering AP under L2 broadcast
WLC 1 Version: 17.3.4c
WLC 2 Version: 17.3.2a
02-22-2022 06:05 AM
- You may start by having a sanity check of the C9800 configuration ,for that use (CLI) : show tech wireless , have the output analyzed by : https://cway.cisco.com/tools/WirelessAnalyzer/
M.
02-22-2022 06:23 AM
Since you have two 9800's and you have determined that the AP is connecting to WLC2, that means that the AP and WLC 2are fine and the issue is with WLC 1. I'm assuming that you are using an appliance not a VM? You have any ap's joined to the WLC 1, if not, then you need to look at the FW or any acl's that might be blocking the join. If the ap os joined to WLC 2, you can then go into that ap and change the high availability to point to WLC 1. If the ap doesn't join that way, then the issue again is with WLC 1 and or something blocking the join.
02-22-2022 06:54 AM
There are APs already joined in the WLC(1) however the method is via L2 Broadcast. And the issue is not with the joining, The issue is that the APs are not appearing in the dashboard of the AP (Monitoring > AP Statistics). Firewall flows has been opened to any as part of the troubleshooting. I also tried to perform PCAP on the WLC(1) but Im not able to see any request from the AP even if the AP has the configured the option 43 to point to WLC(1) when I issue ping from AP to WLC it is being seen in the PCAP.
02-22-2022 06:58 AM - edited 02-23-2022 07:24 AM
If the access point is not appearing in the dashboard, then there is an issue with joining. Only joined ap's will show up in the controller. Have you tried to put the ap in the same subnet so its a layer 2 broadcast discovery? Have you tried to connect an indoor ap on the same cable to see if that ap joins WLC 1? Have you tried to connect another ap to that same cable and connect it to WLC 2 and then change the ap high availability to point to WLC 1 to see if the ap joins? This will help you determine where the issue is.
02-22-2022 06:30 AM
Also, make sure you have trustpoint configured for AP DTLS connection.
If you have some issues with AP joining, that’s probably the first thing to start troubleshooting, and it’s recommended that you follow these steps:
● show wireless management trustpoint: verify if the trustpoint is set
● If not there: On the physical appliance simply reassign the MIC by using the following commands:
c9800(config)#no wireless management trustpoint
c9800(config)#wireless management trustpoint CISCO_IDEVID_SUDI
the validate it by issuing
c9800#wireless config validate
If possible, console into the AP and log the boot process and share.
CJ
/** Please rate all useful responses **/
02-23-2022 02:01 AM
What model are the 2 WLCs?
What do the join stats show for those APs? Did the WLC see the join requests and if they failed what was the reason?
If the WLC replied and the AP didn't receive the reply then despite what you think there is something blocking the traffic from WLC -> AP.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide