cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5523
Views
5
Helpful
21
Replies

Virtual WLC - AP 1600e

Luciano Vigano'
Level 2
Level 2

Hi all,

we have a lot of problem in joining AP 1600e lightw to a vWLC.

Following the details:

- vWLC: 7.4.100 (with SSC disabled)

- AP: ap1g2-rcvk9w8-tar.152-2.JB

We followed these steps:

- AP directly to vWLC: results: DTLS Error

     "*spamApTask3: Jul 18 13:16:26.389: #DTLS-3-HANDSHAKE_FAILURE: openssl_dtls.c:681 Failed to complete DTLS handshake with peer 10.143.174.200"

- AP to a 7.4 5508 WLC and then to vWLC: results as per previous point

Any clue?

Thanks in advance

Luciano

21 Replies 21

Okay... well verify the country code on the AP matches that on the WLC and then upload a new image to the 1602.

WIRELESS LAN LWAPP RECOVERY

ap1g2-rcvk9w8-tar.152-2.JB.tar

Thanks,

Scott

Help out other by using the rating system and marking answered questions as "Answered"

-Scott
*** Please rate helpful posts ***

Mhm... That's interesting.

So if your WLC is in Italy, and you have an AP for A regulatory domain, you would not be able to join WLC, because WLC uses Italy country code (Europe). Is there any workaround Scott?

you should be able to use multiple country codes.

http://nostringsattachedshow.com/2012/02/02/multiple-country-codes-with-the-cisco-wlc/

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

Oh , that's true Stephen!

I think this should be a solution for you Luciano Vigano

Ciao,

now we are in this situations: the AP is now try to connect to the vWLC

AP: loaded image

ap1g2-k9w8-mx.152-2.JB

Error on vWLC (with US and Canada Country code):

*spamApTask5: Jul 19 15:50:21.290: #DTLS-3-HANDSHAKE_FAILURE: openssl_dtls.c:681 Failed to complete DTLS handshake with peer 10.143.174.211

Error on AP

*Jul 19 15:52:05.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 10.143.174.196 peer_port: 5246

*Jul 19 15:52:05.059: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed.  The certificate (SN: 1000) has expired.    Validity period ended on 19:48:03 UTC Dec 14 2010Peer certificate verification failed 001A

*Jul 19 15:52:05.059: %CAPWAP-3-ERRORLOG: Certificate verification failed!

*Jul 19 15:52:05.059: DTLS_CLIENT_ERROR: ../capwap/base_capwap/capwap/base_capwap_wtp_dtls.c:447 Certificate verified failed!

*Jul 19 15:52:05.059: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to 10.143.174.196:5246

*Jul 19 15:52:05.059: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 10.143.174.196:5246

*Jul 19 15:52:05.059: %CAPWAP-3-ERRORLOG: Invalid event 38 & state 3 combination.

Luciano Vigano'
Level 2
Level 2

Ok,

with both RCV and not image still gets this annoing error:

*Jul 19 21:55:30.055: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed.  The certificate (SN: 1000) has expired.    Validity period ended on 19:48:03 UTC Dec 14 2010Peer certificate verification failed 001A

I just set the vWLC time before the date in the error.

AP0006.f6d6.06d1#show crypto pki certificates

CA Certificate

  Status: Available

  Certificate Serial Number (hex): 00D7D95C4945C3825D

  Certificate Usage: General Purpose

  Issuer:

    [email protected]

    cn=CA-vWLC-AIR-CTVM-K9-000C29AC707D

    o=Cisco Virtual Wireless LAN Controller

    l=San Jose

    st=California

    c=US

  Subject:

    [email protected]

    cn=CA-vWLC-AIR-CTVM-K9-000C29AC707D

    o=Cisco Virtual Wireless LAN Controller

    l=San Jose

    st=California

    c=US

  Validity Date:

    start date: 19:48:02 UTC Feb 4 2001

    end   date: 19:48:02 UTC Mar 6 2001

  Associated Trustpoints: virtual_wlc_trust_point

  Storage:

CA Certificate

  Status: Available

  Certificate Serial Number (hex): 00

  Certificate Usage: General Purpose

  Issuer:

    [email protected]

    cn=ca

    ou=none

    o=airespace Inc

    l=San Jose

    st=California

    c=US

  Subject:

    [email protected]

    cn=ca

    ou=none

    o=airespace Inc

    l=San Jose

    st=California

    c=US

  Validity Date:

    start date: 23:38:55 UTC Feb 12 2003

    end   date: 23:38:55 UTC Nov 11 2012

  Associated Trustpoints: airespace-old-root-cert

  Storage:

CA Certificate

  Status: Available

  Certificate Serial Number (hex): 00

  Certificate Usage: Signature

  Issuer:

    [email protected]

    cn=Airespace Root CA

    ou=Engineering

    o=Airespace Inc.

    l=San Jose

    st=California

    c=US

  Subject:

    [email protected]

    cn=Airespace Root CA

    ou=Engineering

    o=Airespace Inc.

    l=San Jose

    st=California

    c=US

  Validity Date:

    start date: 13:41:22 UTC Jul 31 2003

    end   date: 13:41:22 UTC Apr 29 2013

  Associated Trustpoints: airespace-new-root-cert

  Storage:

CA Certificate

  Status: Available

  Certificate Serial Number (hex): 03

  Certificate Usage: General Purpose

  Issuer:

    [email protected]

    cn=Airespace Root CA

    ou=Engineering

    o=Airespace Inc.

    l=San Jose

    st=California

    c=US

  Subject:

    [email protected]

    cn=Airespace Device CA

    ou=Engineering

    o=Airespace Inc.

    l=San Jose

    st=California

    c=US

  Validity Date:

    start date: 22:37:13 UTC Apr 28 2005

    end   date: 22:37:13 UTC Jan 26 2015

  Associated Trustpoints: airespace-device-root-cert

  Storage:

CA Certificate

  Status: Available

  Certificate Serial Number (hex): 5FF87B282B54DC8D42A315B568C9ADFF

  Certificate Usage: Signature

  Issuer:

    cn=Cisco Root CA 2048

    o=Cisco Systems

  Subject:

    cn=Cisco Root CA 2048

    o=Cisco Systems

  Validity Date:

    start date: 20:17:12 UTC May 14 2004

    end   date: 20:25:42 UTC May 14 2029

  Associated Trustpoints: Trustpool cisco-root-cert

  Storage:

Certificate

  Status: Available

  Certificate Serial Number (hex): 4B5B3E72000000269099

  Certificate Usage: General Purpose

  Issuer:

    cn=Cisco Manufacturing CA

    o=Cisco Systems

  Subject:

    Name: AP1G2-0006f6d606d1

    [email protected]

    cn=AP1G2-0006f6d606d1

    o=Cisco Systems

    l=San Jose

    st=California

    c=US

  CRL Distribution Points:

    http://www.cisco.com/security/pki/crl/cmca.crl

  Validity Date:

    start date: 21:41:51 UTC Mar 4 2013

    end   date: 21:51:51 UTC Mar 4 2023

  Associated Trustpoints: Cisco_IOS_MIC_cert

  Storage:

CA Certificate

  Status: Available

  Certificate Serial Number (hex): 6A6967B3000000000003

  Certificate Usage: Signature

  Issuer:

    cn=Cisco Root CA 2048

    o=Cisco Systems

  Subject:

    cn=Cisco Manufacturing CA

    o=Cisco Systems

  CRL Distribution Points:

    http://www.cisco.com/security/pki/crl/crca2048.crl

  Validity Date:

    start date: 22:16:01 UTC Jun 10 2005

    end   date: 20:25:42 UTC May 14 2029

  Associated Trustpoints: Trustpool Cisco_IOS_MIC_cert

  Storage:

Mybe reinstalling the vWLC ...

Luciano Vigano'
Level 2
Level 2

Finally found the problem!! The SSC was always expired, due to the fact that the ESXi time was xx/xx/2001 !!! It's seems that it is generated during the installation, before configuring the ntp.

WLC reinstalled, now it works fine 🙂

Is there any possibility to regenerate it without reinstall the vWLC??


Sent from Cisco Technical Support Android App

Review Cisco Networking for a $25 gift card