cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
706
Views
5
Helpful
3
Replies

web-passthrough issue when changing time on WLCs

Fespino1
Level 1
Level 1

We have 6 WLCs 3 on two of our major locations running 8.3.150 software version. We will be replacing our wireless gear so we will not be updating these WLCs and we are changing vendors. We will not be upgrading the gear until probably at the end of the year, unfortunately a lot of our APs are pretty old and we are seeing a lot of APs unregistering due to expired certs. Due to budget reason we are pretty much in survival mode right now so we decided to change the time on all of our WLCs after we tested and knew this workaround worked to get the APs registered again, but we are running into an issue with our guest network. Now, i know the other solution is to upgrade the software to 8.5 but we have a lot of APs and also i dont know if they have a service contract with CIsco, i hope they do (sr net eng).  We lose the ability to web into the controllers and some users are unable to connect - they get an error when the web-auth page comes up. we first tried to go back to 2019 keeping the same date just changed the year. this worked and we made the change around 1pm but around 11pm-1am we a lot of people were unable to connect to the guest network and we realized we couldnt web into one of our controller (the main WLC), and everything came back to normal when we updating the time again, this time to 2020. the same thing happened, the issue resolved and then after a few hours we noticed the issue again, and i had to set the current time. this is happening on all of the controllers but not at the same time, some lasted 1 day, another still working with the time set back to 2020 but im pretty sure i will have to change the time again. 

we have spare APs sadly i will have to replace 5 APs on one of our small remote sites when i have to change the time in the WLC to 2021. I know the command to check the APs cert but we have about a 1000 APs so it is not a small number.

Any thoughts? we have cisco router with a DHCP pool that hands out the IP address to the guest network and connects to the internet. 

why it this workaround only works for a few hours? 

 

Thanks for your help in advance

 

1 Accepted Solution

Accepted Solutions

Rich R
VIP
VIP

Have you read through https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html very carefully and applied config ap cert-expiry-ignore {mic|ssc} on the wlc's?

Changing the time should only be a temporary workaround - long enough to enable APs to join WLC so that you can deploy the config change to the APs.

Without more specifics on APs and WLCs involved it's hard to make any more detailed recommendation.

The cert is only checked when the AP joins WLC or re-negotiates the DTLS connection so that might explain what you're seeing.

View solution in original post

3 Replies 3

Rich R
VIP
VIP

Have you read through https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html very carefully and applied config ap cert-expiry-ignore {mic|ssc} on the wlc's?

Changing the time should only be a temporary workaround - long enough to enable APs to join WLC so that you can deploy the config change to the APs.

Without more specifics on APs and WLCs involved it's hard to make any more detailed recommendation.

The cert is only checked when the AP joins WLC or re-negotiates the DTLS connection so that might explain what you're seeing.

Thank you very much. Yes after I posted this I read again and did see that changing the time should only be temporary.  I'm about to post another question in the forum but I'm wondering if you know the answer to this. Is the a way to check all the AP MICs using cisco prime infrastructure (ncs)? I now thr command to check the cert on the AP itself when I console into jt but was wondering if there a better way to do it through ncs where I can see all of them and create a report. 

Don't know about Prime/NCS but the field notice includes a link to https://community.cisco.com/t5/wireless-mobility-documents/access-point-certificate-check-tool-apcertcheck/ta-p/3155582 which is a python script for doing exactly that. 

But if you just make sure all your WLC are running AireOS/IOS-XE with the workaround/fix and have the commands applied then you shouldn't have any more problems.

As I recall there were some very old AP and WISM combinations where it didn't work but if you still have those (all more than 6 years past end of support) then you have bigger problems ...

Review Cisco Networking for a $25 gift card