04-11-2021 07:45 PM - edited 07-05-2021 01:07 PM
We have 6 WLCs 3 on two of our major locations running 8.3.150 software version. We will be replacing our wireless gear so we will not be updating these WLCs and we are changing vendors. We will not be upgrading the gear until probably at the end of the year, unfortunately a lot of our APs are pretty old and we are seeing a lot of APs unregistering due to expired certs. Due to budget reason we are pretty much in survival mode right now so we decided to change the time on all of our WLCs after we tested and knew this workaround worked to get the APs registered again, but we are running into an issue with our guest network. Now, i know the other solution is to upgrade the software to 8.5 but we have a lot of APs and also i dont know if they have a service contract with CIsco, i hope they do (sr net eng). We lose the ability to web into the controllers and some users are unable to connect - they get an error when the web-auth page comes up. we first tried to go back to 2019 keeping the same date just changed the year. this worked and we made the change around 1pm but around 11pm-1am we a lot of people were unable to connect to the guest network and we realized we couldnt web into one of our controller (the main WLC), and everything came back to normal when we updating the time again, this time to 2020. the same thing happened, the issue resolved and then after a few hours we noticed the issue again, and i had to set the current time. this is happening on all of the controllers but not at the same time, some lasted 1 day, another still working with the time set back to 2020 but im pretty sure i will have to change the time again.
we have spare APs sadly i will have to replace 5 APs on one of our small remote sites when i have to change the time in the WLC to 2021. I know the command to check the APs cert but we have about a 1000 APs so it is not a small number.
Any thoughts? we have cisco router with a DHCP pool that hands out the IP address to the guest network and connects to the internet.
why it this workaround only works for a few hours?
Thanks for your help in advance
Solved! Go to Solution.
04-13-2021 07:41 AM - edited 04-13-2021 07:54 AM
Have you read through https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html very carefully and applied config ap cert-expiry-ignore {mic|ssc} on the wlc's?
Changing the time should only be a temporary workaround - long enough to enable APs to join WLC so that you can deploy the config change to the APs.
Without more specifics on APs and WLCs involved it's hard to make any more detailed recommendation.
The cert is only checked when the AP joins WLC or re-negotiates the DTLS connection so that might explain what you're seeing.
04-13-2021 07:41 AM - edited 04-13-2021 07:54 AM
Have you read through https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html very carefully and applied config ap cert-expiry-ignore {mic|ssc} on the wlc's?
Changing the time should only be a temporary workaround - long enough to enable APs to join WLC so that you can deploy the config change to the APs.
Without more specifics on APs and WLCs involved it's hard to make any more detailed recommendation.
The cert is only checked when the AP joins WLC or re-negotiates the DTLS connection so that might explain what you're seeing.
04-13-2021 11:53 AM
Thank you very much. Yes after I posted this I read again and did see that changing the time should only be temporary. I'm about to post another question in the forum but I'm wondering if you know the answer to this. Is the a way to check all the AP MICs using cisco prime infrastructure (ncs)? I now thr command to check the cert on the AP itself when I console into jt but was wondering if there a better way to do it through ncs where I can see all of them and create a report.
04-14-2021 01:52 AM - edited 04-14-2021 02:02 AM
Don't know about Prime/NCS but the field notice includes a link to https://community.cisco.com/t5/wireless-mobility-documents/access-point-certificate-check-tool-apcertcheck/ta-p/3155582 which is a python script for doing exactly that.
But if you just make sure all your WLC are running AireOS/IOS-XE with the workaround/fix and have the commands applied then you shouldn't have any more problems.
As I recall there were some very old AP and WISM combinations where it didn't work but if you still have those (all more than 6 years past end of support) then you have bigger problems ...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide