cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1917
Views
5
Helpful
8
Replies

Virtual Wireless LAN Contoller - AP cert error

john.blake
Level 1
Level 1

I am working to get a vWLC up and running and get the following error from the access point when attempting to authenticate with the controller.

Cert Verification FAILED with error 20 (unable to get local issuer certificate) at 0 depth...

Firmware versions are compatible on the controller and AP.  Controller is running 8.2.110.0

Time is set on both devices correctly and they are in the same time zone.

Anyone have a fix or ideas to correct this error?

JB

8 Replies 8

Scott Fella
Hall of Fame
Hall of Fame

What AP model do you have?

-Scott

-Scott
*** Please rate helpful posts ***

1832i

mohanak
Cisco Employee
Cisco Employee

Features Not Supported on Cisco Aironet 1830 and 1850 APs

  • Cisco Virtual Wireless Controller
  • Mesh mode
  • Flex mode
  • Monitor mode
  • Workgroup Bridge (WGB) mode
  • OfficeExtend mode
  • Enhanced Local Mode (ELM)
  • Integrated BLE
  • Basic spectrum analysis
  • USB-based Bluetooth Low Energy (BLE) device support
  • Cisco CleanAir
  • Cisco Wireless ClientLink 3.0
  • Rogue Location Discovery Protocol (RLDP)
  • Cisco Compatible eXtensions (CCX) Specification
  • 802.1x supplicant for AP authentication on the wired port
  • Static WEP key for TKIP or CKIP
  • Dynamic Transmit Power Control (DTPC)
  • Federal Information Processing Standard (FIPS) and Common Criteria
  • 40-MHz Rogue detection
  • Native IPv6
  • Telnet

http://www.cisco.com/c/en/us/td/docs/wireless/controller/release/notes/crn82.html#pgfId-1321954

Mohanak,

Thanks for this but within the same document which I reviewed yesterday is listed supported access points as noted below.  So how the H377 is anyone supposed to interpret that?????????

Supported Access Point Platforms

The following access point platforms are supported in this release:

  • Cisco Aironet 1040 Series Access Points
  • Cisco Aironet 1140 Series Access Points
  • Cisco Aironet 1260 Series Access Points
  • Cisco Aironet 1600 Series Access Points
  • Cisco Aironet 1700 Series Access Points
  • Cisco Aironet 1830 Series Access Points
  • Cisco Aironet 1850 Series Access Points
  • Cisco Aironet 2600 Series Access Points
  • Cisco Aironet 2700 Series Access Points
  • Cisco Aironet 3500 Series Access Points
  • Cisco Aironet 3600 Series Access Points
  • Cisco Aironet 3700 Series Access Points
  • Cisco Aironet 600 Series OfficeExtend Access Points
  • Cisco Aironet 700 Series Access Points
  • Cisco Aironet 700W Series Access Points
  • Cisco AP802 Integrated Access Point
  • Cisco AP803 Integrated Access Point
  • Cisco ASA 5506W-AP702
  • Cisco Aironet 1530 Series Access Points
  • Cisco Aironet 1550 Series Access Points
  • Cisco Aironet 1570 Series Access Points
  • Cisco Industrial Wireless 3700 Series Access Points

Same problem here!

Same AP model, same vWLC

Have u solved?

Divanoatuin,

Yes we found a solution.  First, it is true that the 1830 models are not supported using any software below 8.2.110 on the access points with the vWLC.  It took a lot of time and effort to figure this out with support from Cisco engineers.  Why I do not know, but that aside we were able to find a resolution as listed below.  Note that the new version of software for the vWLC is due out by the end of July (8.3.xxx) which will support the 1830 series with no issues.  That is according to Cisco engineers.

How we solved this issue:

1. Setup a hardware WLC on a public IP address running software version 8.2.111

2. Point the APs to this controller and allow time for them to upgrade to 8.2.111

3. After the APs upgrade, now point them to the vWLC IP address and they will connect

Good luck and good hunting.  If you do not have a hardware WLC sitting around, contact your local Cisco Sales Engineer and ask for assistance, they usually have a home lab that could be used temporarily.

Cheers,

JB

Hi and thanks for the answer!

Can u give some official documentation or some screen of the TAC/resolution?

I will need it to talk with my supplier!

If u cant, no problem at all, and thx anyway :)

Cheers,

Nico

Hey Nico,

I do not have anything official, a TAC case was not opened.  We worked directly with our Sales Engineering contacts for this project.

I would assume if you opened a case they would be able to help you, just be ready to do all the steps they require.

Good luck,

JB

Review Cisco Networking for a $25 gift card