WLC and AP

Hello guys,
I have an error when wlc trying to connect my 1042 access point
here is error
my wlc is nm-wlc intergrated module
ap and wlc have the same code version 7.0
%LINK-3-UPDOWN: Interface Dot11Radio0, changed state to up
*Apr 26 09:02:27.419: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset
*Apr 26 09:02:27.445:  status of voice_diag_test from WLC is false
*Apr 26 09:02:38.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 172.16.1.11 peer_port: 5246
*Apr 26 09:02:38.001: %CAPWAP-5-CHANGED: CAPWAP changed state to
*Apr 26 09:02:39.116: %CAPWAP-5-DTLSREQSUCC: DTLS connection created sucessfully peer_ip: 172.16.1.11 peer_port: 5246
*Apr 26 09:02:39.117: %CAPWAP-5-SENDJOIN: sending Join Request to 172.16.1.11
*Apr 26 09:02:39.118: %CAPWAP-5-CHANGED: CAPWAP changed state to JOIN
*Apr 26 09:02:39.291: %CAPWAP-5-CHANGED: CAPWAP changed state to CFG
*Apr 26 09:02:39.292: %DTLS-5-ALERT: Received WARNING : Close notify alert from 172.16.1.11
*Apr 26 09:02:39.293: %DTLS-5-PEER_DISCONNECT: Peer 172.16.1.11 has closed connection.
*Apr 26 09:02:39.293: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 172.16.1.11:5246
*Apr 26 09:02:39.346: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
*Apr 26 09:02:39.346: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
*Apr 26 09:02:39.447:  status of voice_diag_test from WLC is false
*Apr 26 09:02:49.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 172.16.1.11 peer_port: 5246
*Apr 26 09:02:49.001: %CAPWAP-5-CHANGED: CAPWAP changed state to
*Apr 26 09:02:50.114: %CAPWAP-5-DTLSREQSUCC: DTLS connection created sucessfully peer_ip: 172.16.1.11 peer_port: 5246
*Apr 26 09:02:50.115: %CAPWAP-5-SENDJOIN: sending Join Request to 172.16.1.11
*Apr 26 09:02:50.115: %CAPWAP-5-CHANGED: CAPWAP changed state to JOIN
*Apr 26 09:02:50.287: %CAPWAP-5-CHANGED: CAPWAP changed state to CFG
*Apr 26 09:02:50.289: %DTLS-5-ALERT: Received WARNING : Close notify alert from 172.16.1.11
*Apr 26 09:02:50.289: %DTLS-5-PEER_DISCONNECT: Peer 172.16.1.11 has closed connection.
*Apr 26 09:02:50.289: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 172.16.1.11:5246
*Apr 26 09:02:50.344: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
*Apr 26 09:02:50.344: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
*Apr 26 09:02:50.370: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to administratively down
*Apr 26 09:02:50.370: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to administratively down
*Apr 26 09:02:51.325: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset
*Apr 26 09:02:51.352:  status of voice_diag_test from WLC is false
*Apr 26 09:02:51.352: %LINK-3-UPDOWN: Interface Dot11Radio1, changed state to up
*Apr 26 09:02:51.360: %LINK-3-UPDOWN: Interface Dot11Radio0, changed state to up
*Apr 26 09:02:51.372: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to reset
*Apr 26 09:02:51.372: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to down
*Apr 26 09:02:51.386: %LINK-3-UPDOWN: Interface Dot11Radio1, changed state to up
*Apr 26 09:02:52.386: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to up
*Apr 26 09:03:02.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 172.16.1.11 peer_port: 5246
*Apr 26 09:03:02.001: %CAPWAP-5-CHANGED: CAPWAP changed state to
*Apr 26 09:03:03.109: %CAPWAP-5-DTLSREQSUCC: DTLS connection created sucessfully peer_ip: 172.16.1.11 peer_port: 5246
*Apr 26 09:03:03.110: %CAPWAP-5-SENDJOIN: sending Join Request to 172.16.1.11
*Apr 26 09:03:03.110: %CAPWAP-5-CHANGED: CAPWAP changed state to JOIN
*Apr 26 09:03:03.285: %CAPWAP-5-CHANGED: CAPWAP changed state to CFG
*Apr 26 09:03:03.287: %DTLS-5-ALERT: Received WARNING : Close notify alert from 172.16.1.11
Building configuration...
CAPWAP-3-ERRORLOG: Invalid event 38 & state 2 combination

Guys here is all diagnostics
WAP
#show inventory
NAME: "AP1040", DESCR: "Cisco Aironet 1040 Series (IEEE 802.11n) Access Point"
PID: AIR-AP1042N-E-K9  , VID: V02, SN: FCZ1537W1MW
WLC
show sysinfo
Manufacturer's Name.............................. Cisco Systems Inc.
Product Name..................................... Cisco Controller
Product Version.................................. 7.0.230.0
RTOS Version..................................... 7.0.230.0
Bootloader Version............................... 7.0.230.0
Emergency Image Version.......................... N/A
Build Type....................................... DATA + WPS
System Name...................................... Cisco_cc:c4:20
System Location..................................
System Contact...................................
System ObjectID.................................. 1.3.6.1.4.1.9.1.818
IP Address....................................... 172.16.1.10
System Up Time................................... 0 days 19 hrs 17 mins 2 secs
System Timezone Location.........................
Configured Country............................... US  - United States
State of 802.11b Network......................... Enabled
State of 802.11a Network......................... Enabled
--More-- or (q)uit
Number of WLANs.................................. 1
Number of Active Clients......................... 0
Burned-in MAC Address............................ 00:1E:BE:CC:C4:20
Maximum number of APs supported.................. 8
debug capwap events enable
>debug capwap events enable
(Cisco Controller) >*spamReceiveTask: Apr 26 16:30:25.589: 68:bc:0c:0b:ca:a0 DTLS connection not found, creating new connection for 172:16:100:132 (38305) 172:16:1:11 (5246)
*spamReceiveTask: Apr 26 16:30:26.715: 68:bc:0c:0b:ca:a0 DTLS Session established server (172.16.1.11:5246), client (172.16.100.132:38305)
*spamReceiveTask: Apr 26 16:30:26.715: 68:bc:0c:0b:ca:a0 Starting wait join timer for AP: 172.16.100.132:38305
d*spamReceiveTask: Apr 26 16:30:26.718: 68:bc:0c:0b:ca:a0 Join Request from 172.16.100.132:38305
*spamReceiveTask: Apr 26 16:30:26.718: 68:bc:0c:0b:ca:a0 Deleting AP entry 172.16.100.132:38305 from temporary database.
*spamReceiveTask: Apr 26 16:30:26.720: 68:bc:0c:0b:ca:a0 Join Version: = 117499392
*spamReceiveTask: Apr 26 16:30:26.720: 68:bc:0c:0b:ca:a0 Join resp: CAPWAP Maximum Msg element len = 91
*spamReceiveTask: Apr 26 16:30:26.720: 68:bc:0c:0b:ca:a0 Join Response sent to 172.16.100.132:38305
*spamReceiveTask: Apr 26 16:30:26.720: 68:bc:0c:0b:ca:a0 CAPWAP State: Join
*spamReceiveTask: Apr 26 16:30:26.720: 68:bc:0c:0b:ca:a0 capwap_ac_platform.c:1217 - Operation State 0 ===> 4
*apfReceiveTask: Apr 26 16:30:26.721: 68:bc:0c:0b:ca:a0 Register LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 0
*apfReceiveTask: Apr 26 16:30:26.721: WARP IEs: (12)
*apfReceiveTask: Apr 26 16:30:26.721:      [0000] dd 0a 00 c0 b9 01 00 00 00 08 01 01
*apfReceiveTask: Apr 26 16:30:26.721: 68:bc:0c:0b:ca:a0 Register LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 1
*apfReceiveTask: Apr 26 16:30:26.721: WARP IEs: (12)
*apfReceiveTask: Apr 26 16:30:26.721:      [0000] dd 0a 00 c0 b9 01 00 00 00 08 01 01
*spamReceiveTask: Apr 26 16:30:26.840: 68:bc:0c:0b:ca:a0 Configuration Status from 172.16.100.132:38305
*spamReceiveTask: Apr 26 16:30:26.840: 68:bc:0c:0b:ca:a0 CAPWAP State: Configure
*spamReceiveTask: Apr 26 16:30:26.840: Invalid channel 1 spacified for the AP AP7081.05c9.5a08, slotId = 0
*spamReceiveTask: Apr 26 16:30:26.840: Invalid channel 64 spacified for the AP AP7081.05c9.5a08, slotId = 1
*spamReceiveTask: Apr 26 16:30:26.840: 68:bc:0c:0b:ca:a0 Updating IP info for AP 68:bc:0c:0b:ca:a0 -- static 1, 10.0.0.4/255.255.255.0, gtw 172.30.30.1
*spamReceiveTask: Apr 26 16:30:26.841: 68:bc:0c:0b:ca:a0 Updated IP Domain info for AP 68:bc:0c:0b:ca:a0 -- set 0, Domain
*spamReceiveTask: Apr 26 16:30:26.841: 68:bc:0c:0b:ca:a0 Updating IP NamServer info for AP 68:bc:0c:0b:ca:a0 -- set 0, nameserver 0.0.0.0
*spamReceiveTask: Apr 26 16:30:26.841: 68:bc:0c:0b:ca:a0 Setting MTU to 1485
*spamReceiveTask: Apr 26 16:30:26.841: 68:bc:0c:0b:ca:a0 Finding DTLS connection to delete for AP (172:16:100:132/38305)
*spamReceiveTask: Apr 26 16:30:26.841: 68:bc:0c:0b:ca:a0 Disconnecting DTLS Capwap-Ctrl session 0xa0726f4 for AP (172:16:100:132/38305)
*spamReceiveTask: Apr 26 16:30:26.841: 68:bc:0c:0b:ca:a0 CAPWAP State: Dtls tear down
*spamReceiveTask: Apr 26 16:30:26.842: 68:bc:0c:0b:ca:a0 DTLS connection closed event receivedserver (172:16:1:11/5246) client (172:16:100:132/38305)
*spamReceiveTask: Apr 26 16:30:26.842: 68:bc:0c:0b:ca:a0 Entry exists for AP (172:16:100:132/38305)
*spamReceiveTask: Apr 26 16:30:26.842: 68:bc:0c:0b:ca:a0 apfSpamProcessStateChangeInSpamContext: Deregister LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 0
*spamReceiveTask: Apr 26 16:30:26.842: 68:bc:0c:0b:ca:a0 apfSpamProcessStateChangeInSpamContext: Deregister LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 1
*spamReceiveTask: Apr 26 16:30:26.842: 68:bc:0c:0b:ca:a0 No AP entry exist in temporary database for 172.16.100.132:38305
*apfReceiveTask: Apr 26 16:30:26.842: 68:bc:0c:0b:ca:a0 Deregister LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 0
*apfReceiveTask: Apr 26 16:30:26.842: 68:bc:0c:0b:ca:a0 Deregister LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 1
*spamReceiveTask: Apr 26 16:30:27.002: 68:bc:0c:0b:ca:a0 Discovery Request from 172.16.100.132:38306
*spamReceiveTask: Apr 26 16:30:27.002: 68:bc:0c:0b:ca:a0 Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 8, joined Aps =0
*spamReceiveTask: Apr 26 16:30:27.002: 68:bc:0c:0b:ca:a0 Discovery Response sent to 172.16.100.132:38306
*spamReceiveTask: Apr 26 16:30:37.243: 68:bc:0c:0b:ca:a0 DTLS connection not found, creating new connection for 172:16:100:132 (38306) 172:16:1:11 (5246)
*spamReceiveTask: Apr 26 16:30:38.365: 68:bc:0c:0b:ca:a0 DTLS Session established server (172.16.1.11:5246), client (172.16.100.132:38306)
*spamReceiveTask: Apr 26 16:30:38.365: 68:bc:0c:0b:ca:a0 Starting wait join timer for AP: 172.16.100.132:38306
*spamReceiveTask: Apr 26 16:30:38.368: 68:bc:0c:0b:ca:a0 Join Request from 172.16.100.132:38306
*spamReceiveTask: Apr 26 16:30:38.369: 68:bc:0c:0b:ca:a0 Deleting AP entry 172.16.100.132:38306 from temporary database.
*spamReceiveTask: Apr 26 16:30:38.370: 68:bc:0c:0b:ca:a0 Join Version: = 117499392
*spamReceiveTask: Apr 26 16:30:38.370: 68:bc:0c:0b:ca:a0 Join resp: CAPWAP Maximum Msg element len = 91
*spamReceiveTask: Apr 26 16:30:38.370: 68:bc:0c:0b:ca:a0 Join Response sent to 172.16.100.132:38306
*spamReceiveTask: Apr 26 16:30:38.370: 68:bc:0c:0b:ca:a0 CAPWAP State: Join
*spamReceiveTask: Apr 26 16:30:38.370: 68:bc:0c:0b:ca:a0 capwap_ac_platform.c:1217 - Operation State 0 ===> 4
*apfReceiveTask: Apr 26 16:30:38.371: 68:bc:0c:0b:ca:a0 Register LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 0
*apfReceiveTask: Apr 26 16:30:38.371: WARP IEs: (12)
*apfReceiveTask: Apr 26 16:30:38.371:      [0000] dd 0a 00 c0 b9 01 00 00 00 08 01 01
*apfReceiveTask: Apr 26 16:30:38.371: 68:bc:0c:0b:ca:a0 Register LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 1
*apfReceiveTask: Apr 26 16:30:38.371: WARP IEs: (12)
*apfReceiveTask: Apr 26 16:30:38.371:      [0000] dd 0a 00 c0 b9 01 00 00 00 08 01 01
*spamReceiveTask: Apr 26 16:30:38.490: 68:bc:0c:0b:ca:a0 Configuration Status from 172.16.100.132:38306
*spamReceiveTask: Apr 26 16:30:38.490: 68:bc:0c:0b:ca:a0 CAPWAP State: Configure
*spamReceiveTask: Apr 26 16:30:38.490: Invalid channel 1 spacified for the AP AP7081.05c9.5a08, slotId = 0
*spamReceiveTask: Apr 26 16:30:38.490: Invalid channel 157 spacified for the AP AP7081.05c9.5a08, slotId = 1
*spamReceiveTask: Apr 26 16:30:38.490: 68:bc:0c:0b:ca:a0 Updating IP info for AP 68:bc:0c:0b:ca:a0 -- static 1, 10.0.0.4/255.255.255.0, gtw 172.30.30.1
*spamReceiveTask: Apr 26 16:30:38.490: 68:bc:0c:0b:ca:a0 Updated IP Domain info for AP 68:bc:0c:0b:ca:a0 -- set 0, Domain
*spamReceiveTask: Apr 26 16:30:38.490: 68:bc:0c:0b:ca:a0 Updating IP NamServer info for AP 68:bc:0c:0b:ca:a0 -- set 0, nameserver 0.0.0.0
*spamReceiveTask: Apr 26 16:30:38.490: 68:bc:0c:0b:ca:a0 Setting MTU to 1485
*spamReceiveTask: Apr 26 16:30:38.491: 68:bc:0c:0b:ca:a0 Finding DTLS connection to delete for AP (172:16:100:132/38306)
*spamReceiveTask: Apr 26 16:30:38.491: 68:bc:0c:0b:ca:a0 Disconnecting DTLS Capwap-Ctrl session 0xa0727d8 for AP (172:16:100:132/38306)
*spamReceiveTask: Apr 26 16:30:38.491: 68:bc:0c:0b:ca:a0 CAPWAP State: Dtls tear down
*spamReceiveTask: Apr 26 16:30:38.491: 68:bc:0c:0b:ca:a0 DTLS connection closed event receivedserver (172:16:1:11/5246) client (172:16:100:132/38306)
*spamReceiveTask: Apr 26 16:30:38.491: 68:bc:0c:0b:ca:a0 Entry exists for AP (172:16:100:132/38306)
*spamReceiveTask: Apr 26 16:30:38.492: 68:bc:0c:0b:ca:a0 apfSpamProcessStateChangeInSpamContext: Deregister LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 0
*spamReceiveTask: Apr 26 16:30:38.492: 68:bc:0c:0b:ca:a0 apfSpamProcessStateChangeInSpamContext: Deregister LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 1
*spamReceiveTask: Apr 26 16:30:38.492: 68:bc:0c:0b:ca:a0 No AP entry exist in temporary database for 172.16.100.132:38306
*apfReceiveTask: Apr 26 16:30:38.492: 68:bc:0c:0b:ca:a0 Deregister LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 0
*apfReceiveTask: Apr 26 16:30:38.492: 68:bc:0c:0b:ca:a0 Deregister LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 1
*spamReceiveTask: Apr 26 16:30:39.795: 68:bc:0c:0b:ca:a0 Discovery Request from 172.16.100.132:38305
*spamReceiveTask: Apr 26 16:30:39.795: 68:bc:0c:0b:ca:a0 Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 8, joined Aps =0
*spamReceiveTask: Apr 26 16:30:39.795: 68:bc:0c:0b:ca:a0 Discovery Response sent to 172.16.100.132:38305
*spamReceiveTask: Apr 26 16:30:50.035: 68:bc:0c:0b:ca:a0 DTLS connection not found, creating new connection for 172:16:100:132 (38305) 172:16:1:11 (5246)
*spamReceiveTask: Apr 26 16:30:51.158: 68:bc:0c:0b:ca:a0 DTLS Session established server (172.16.1.11:5246), client (172.16.100.132:38305)
*spamReceiveTask: Apr 26 16:30:51.158: 68:bc:0c:0b:ca:a0 Starting wait join timer for AP: 172.16.100.132:38305
*spamReceiveTask: Apr 26 16:30:51.162: 68:bc:0c:0b:ca:a0 Join Request from 172.16.100.132:38305
*spamReceiveTask: Apr 26 16:30:51.162: 68:bc:0c:0b:ca:a0 Deleting AP entry 172.16.100.132:38305 from temporary database.
*spamReceiveTask: Apr 26 16:30:51.163: 68:bc:0c:0b:ca:a0 Join Version: = 117499392
*spamReceiveTask: Apr 26 16:30:51.163: 68:bc:0c:0b:ca:a0 Join resp: CAPWAP Maximum Msg element len = 91
*spamReceiveTask: Apr 26 16:30:51.164: 68:bc:0c:0b:ca:a0 Join Response sent to 172.16.100.132:38305
*spamReceiveTask: Apr 26 16:30:51.164: 68:bc:0c:0b:ca:a0 CAPWAP State: Join
*spamReceiveTask: Apr 26 16:30:51.164: 68:bc:0c:0b:ca:a0 capwap_ac_platform.c:1217 - Operation State 0 ===> 4
*apfReceiveTask: Apr 26 16:30:51.164: 68:bc:0c:0b:ca:a0 Register LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 0
*apfReceiveTask: Apr 26 16:30:51.164: WARP IEs: (12)
*apfReceiveTask: Apr 26 16:30:51.164:      [0000] dd 0a 00 c0 b9 01 00 00 00 08 01 01
*apfReceiveTask: Apr 26 16:30:51.164: 68:bc:0c:0b:ca:a0 Register LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 1
*apfReceiveTask: Apr 26 16:30:51.164: WARP IEs: (12)
*apfReceiveTask: Apr 26 16:30:51.164:      [0000] dd 0a 00 c0 b9 01 00 00 00 08 01 01
*spamReceiveTask: Apr 26 16:30:51.284: 68:bc:0c:0b:ca:a0 Configuration Status from 172.16.100.132:38305
*spamReceiveTask: Apr 26 16:30:51.284: 68:bc:0c:0b:ca:a0 CAPWAP State: Configure
*spamReceiveTask: Apr 26 16:30:51.284: Invalid channel 1 spacified for the AP AP7081.05c9.5a08, slotId = 0
*spamReceiveTask: Apr 26 16:30:51.284: Invalid channel 36 spacified for the AP AP7081.05c9.5a08, slotId = 1
*spamReceiveTask: Apr 26 16:30:51.284: 68:bc:0c:0b:ca:a0 Updating IP info for AP 68:bc:0c:0b:ca:a0 -- static 1, 10.0.0.4/255.255.255.0, gtw 172.30.30.1
*spamReceiveTask: Apr 26 16:30:51.285: 68:bc:0c:0b:ca:a0 Updated IP Domain info for AP 68:bc:0c:0b:ca:a0 -- set 0, Domain
*spamReceiveTask: Apr 26 16:30:51.285: 68:bc:0c:0b:ca:a0 Updating IP NamServer info for AP 68:bc:0c:0b:ca:a0 -- set 0, nameserver 0.0.0.0
*spamReceiveTask: Apr 26 16:30:51.285: 68:bc:0c:0b:ca:a0 Setting MTU to 1485
*spamReceiveTask: Apr 26 16:30:51.285: 68:bc:0c:0b:ca:a0 Finding DTLS connection to delete for AP (172:16:100:132/38305)
*spamReceiveTask: Apr 26 16:30:51.285: 68:bc:0c:0b:ca:a0 Disconnecting DTLS Capwap-Ctrl session 0xa0728bc for AP (172:16:100:132/38305)
*spamReceiveTask: Apr 26 16:30:51.285: 68:bc:0c:0b:ca:a0 CAPWAP State: Dtls tear down
*spamReceiveTask: Apr 26 16:30:51.286: 68:bc:0c:0b:ca:a0 DTLS connection closed event receivedserver (172:16:1:11/5246) client (172:16:100:132/38305)
*spamReceiveTask: Apr 26 16:30:51.286: 68:bc:0c:0b:ca:a0 Entry exists for AP (172:16:100:132/38305)
*spamReceiveTask: Apr 26 16:30:51.286: 68:bc:0c:0b:ca:a0 apfSpamProcessStateChangeInSpamContext: Deregister LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 0
*spamReceiveTask: Apr 26 16:30:51.286: 68:bc:0c:0b:ca:a0 apfSpamProcessStateChangeInSpamContext: Deregister LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 1
*spamReceiveTask: Apr 26 16:30:51.286: 68:bc:0c:0b:ca:a0 No AP entry exist in temporary database for 172.16.100.132:38305
*apfReceiveTask: Apr 26 16:30:51.286: 68:bc:0c:0b:ca:a0 Deregister LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 0
*apfReceiveTask: Apr 26 16:30:51.286: 68:bc:0c:0b:ca:a0 Deregister LWAPP event for AP 68:bc:0c:0b:ca:a0 slot 1
*spamReceiveTask: Apr 26 16:30:51.448: 68:bc:0c:0b:ca:a0 Discovery Request from 172.16.100.132:38306
*spamReceiveTask: Apr 26 16:30:51.448: 68:bc:0c:0b:ca:a0 Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 8, joined Aps =0
*spamReceiveTask: Apr 26 16:30:51.448: 68:bc:0c:0b:ca:a0 Discovery Response sent to 172.16.100.132:38306
(Cisco Controller) >debug capwap errors enable
(Cisco Controller) >*spamReceiveTask: Apr 26 16:32:02.548: 68:bc:0c:0b:ca:a0 AP 68:bc:0c:0b:ca:a0: Invalid country code ().
*spamReceiveTask: Apr 26 16:32:02.548: 68:bc:0c:0b:ca:a0 PHY_TX_POWER_PAYLOAD: Invalid Tx Power Level 0
*spamReceiveTask: Apr 26 16:32:02.548: 68:bc:0c:0b:ca:a0 AP 68:bc:0c:0b:ca:a0: Invalid country code ().
*spamReceiveTask: Apr 26 16:32:02.548: 68:bc:0c:0b:ca:a0 PHY_TX_POWER_PAYLOAD: Invalid Tx Power Level 0
*spamReceiveTask: Apr 26 16:32:02.548: 68:bc:0c:0b:ca:a0 Configured Static IP Address not valid for AP 68:bc:0c:0b:ca:a0
*spamReceiveTask: Apr 26 16:32:02.548: 68:bc:0c:0b:ca:a0 AP 68:bc:0c:0b:ca:a0: Invalid country code ().
*spamReceiveTask: Apr 26 16:32:02.548: 68:bc:0c:0b:ca:a0 Regulatory Domain Mismatch: AP 68:bc:0c:0b:ca:a0 not allowed to join. Regulatory Domain check failed.
Allow
*spamReceiveTask: Apr 26 16:32:02.549: 68:bc:0c:0b:ca:a0 Failed post decode processing of config status from 172.16.100.132:38305
*spamReceiveTask: Apr 26 16:32:02.549: 68:bc:0c:0b:ca:a0 State machine handler: Failed to process  msg type = 5 state = 5 from 172.16.100.132:38305
*spamReceiveTask: Apr 26 16:32:02.549: 68:bc:0c:0b:ca:a0 Failed to parse CAPWAP packet from 172.16.100.132:38305
*spamReceiveTask: Apr 26 16:32:02.550: 68:bc:0c:0b:ca:a0 Discarding non-ClientHello Handshake OR DTLS encrypted packet from  172.16.100.132:38305)since DTLS session is not established
*spamReceiveTask: Apr 26 16:32:14.196: 68:bc:0c:0b:ca:a0 AP 68:bc:0c:0b:ca:a0: Invalid country code ().
*spamReceiveTask: Apr 26 16:32:14.196: 68:bc:0c:0b:ca:a0 PHY_TX_POWER_PAYLOAD: Invalid Tx Power Level 0
*spamReceiveTask: Apr 26 16:32:14.196: 68:bc:0c:0b:ca:a0 AP 68:bc:0c:0b:ca:a0: Invalid country code ().
*spamReceiveTask: Apr 26 16:32:14.196: 68:bc:0c:0b:ca:a0 PHY_TX_POWER_PAYLOAD: Invalid Tx Power Level 0
*spamReceiveTask: Apr 26 16:32:14.196: 68:bc:0c:0b:ca:a0 Configured Static IP Address not valid for AP 68:bc:0c:0b:ca:a0
*spamReceiveTask: Apr 26 16:32:14.196: 68:bc:0c:0b:ca:a0 AP 68:bc:0c:0b:ca:a0: Invalid country code ().
*spamReceiveTask: Apr 26 16:32:14.196: 68:bc:0c:0b:ca:a0 Regulatory Domain Mismatch: AP 68:bc:0c:0b:ca:a0 not allowed to join. Regulatory Domain check failed.
Allow
*spamReceiveTask: Apr 26 16:32:14.197: 68:bc:0c:0b:ca:a0 Failed post decode processing of config status from 172.16.100.132:38306
*spamReceiveTask: Apr 26 16:32:14.197: 68:bc:0c:0b:ca:a0 State machine handler: Failed to process  msg type = 5 state = 5 from 172.16.100.132:38306
*spamReceiveTask: Apr 26 16:32:14.197: 68:bc:0c:0b:ca:a0 Failed to parse CAPWAP packet from 172.16.100.132:38306
*spamReceiveTask: Apr 26 16:32:14.198: 68:bc:0c:0b:ca:a0 Discarding non-ClientHello Handshake OR DTLS encrypted packet from  172.16.100.132:38306)since DTLS session is not established
debug capwap errors disable

Similar Messages

  • ISE 1.2 With WLC and AD

    Hi everyone,
    What is the steps and Procedure implement Wired and wireless authentication with ISE, WLC and AD for a LAB environment. currently the following are done.
    The wireless network is configured with 2 SSID (Staff and Guest) 
    Active Directory, DNS, DHCP, and  NTP configured & synced.
    ISE and AD running on C220 VMs, and WLC is 5760 Appliance.
    Please provide your thoughts and assistance.
    Regards

    You have to implement dot1x and radius between your NAD and ISE device.
    Using the switch 3850, that are the steps: 
    username RADIUS-HEALTH password radiusKey1 privilege 15
    aaa new-model
    aaa authentication login default local
    aaa authentication dot1x default group radius
    aaa authorization network default group radius
    aaa authorization auth-proxy default group radius
    aaa accounting update periodic 5
    aaa accounting auth-proxy default start-stop group radius
    aaa accounting dot1x default start-stop group radius
    !this password will be used to communicate with ISE and to verify reachability
    !between ISE and Switch
    aaa server radius dynamic-author
     client 172.16.1.18 server-key 7 radiuskey
     client 172.16.1.20 server-key 7 radiuskey
    ip domain-name lab.local
    ip name-server 172.16.1.1
    dot1x system-auth-control
    interface GigabitEthernet1/0/3
     switchport mode access
     switchport voice vlan 50
     switchport access vlan 10
     ip access-group ACL-ALLOW in
     authentication event fail action next-method
     authentication event server dead action authorize voice
     authentication event server alive action reinitialize
     authentication host-mode multi-auth
     authentication open
     authentication order dot1x mab
     authentication priority dot1x mab
     authentication port-control auto
     authentication periodic
     authentication timer reauthenticate server
     authentication violation restrict
     mab
     dot1x pae authenticator
     dot1x timeout tx-period 10
     spanning-tree portfast
    ip access-list extended ACL-ALLOW
     permit ip any any
    !the comm between radius and ise will occur on these Port
    ip radius source-interface Vlan100
    logging origin-id ip
    logging source-interface Vlan100
    logging host 172.16.1.20 transport udp port 20514
    logging host 172.16.1.18 transport udp port 20514
    ip radius source-interface Vlan100
    logging origin-id ip
    logging source-interface Vlan100
    logging host 172.16.1.20 transport udp port 20514
    logging host 172.16.1.18 transport udp port 20514
    snmp-server community ciscoro RO
    snmp-server community public RO
    snmp-server trap-source Vlan100
    snmp-server source-interface informs Vlan100
    radius-server attribute 6 on-for-login-auth
    radius-server attribute 8 include-in-access-req
    radius-server attribute 25 access-request include
    radius-server dead-criteria time 10 tries 3
    radius-server vsa send accounting
    radius-server vsa send authentication
    !defining ISE servers
    radius server ISE-RADIUS-1
     address ipv4 172.16.1.20 auth-port 1812 acct-port 1813
     automate-tester username RADIUS-HEALTH idle-time 15
     key radiusKey
    Please be sure that NTP servers and time are synchronized. 
    enable dot1X on windows machine, or using cisco NAM. 
    you can enable debugging on aaa authentication to see the events. 
    you have to create this user on ISE (RADIUS-HEALTH). 
    3850#test aaa group radius username password new-code 
    and observe the result. You are supposed to have user authenticated successfully. 
    You Must also have define these device in ISE on the radius interface.
    ip radius source-interface ..... use this interface ip address to define Ip address of the NAD device in ISE. 
    administration-->network resources -->Network Devices-->Add
    input the name
    input the Ip address for radius communication
    select the authentication settings and field the corresponding shared secret radius key
    select snmp settings and select version 2c. 
    snmp community : ciscoro
    you can customize the polling interval if you want and that all. 
    you are supposed to received message communication between your NAD and ISE. 
    After you can do the procedure for WLC device. 
    I will fill it after you have passed the first steps (3850 authentication). 

  • Problem share folder WLC and pc macbookpro

    I am doing a migration from my wireless network in the old network in the PC MacBookPro I can see shared files on the network. But when I connect to the SSID configured on the WLC and I can not see shared files on the network. I have no ACL configured on the SSID.

    Bonjour is a non-routabe multicast based service. A trick I use sometimes is to configure the WLAN to be in hreap mode if the ap is located locally to the target bonjour device.if your running in local mode, make sure they are on the same vlan and global multicast is enabled.
    Sent from Cisco Technical Support iPad App

  • Cisco 8510 WLC and RTU licence

    Hi Guys,
    I have a simular issue where is shows the status as active, not-in-use.
    What does this mean and how do I get this to be in use.
    This is a Controller with HA-SKU license.
    The licenses has been inherited from the Primary Controller.
    Any license on HA-SKU controller is disregarded.
    Feature name: ap_count (adder)
    License type: Permanent
    License state: Active, Not-In-Use
    License Nodelocked: No
    RTU License Count: 50
    Hope to hear from you soon.
    Regards,
    Clifton.

    Hi,
    since this is a HA-SKU WLC, and the license is inherited from the active then no need to have a permenant license on it.
    is the HA working fine?
    please review the following link for the HA licensing requirements
    http://www.cisco.com/en/US/products/ps10315/products_tech_note09186a0080bd3504.shtml#licensing

  • WLC and WCS conflict

    Hi I am currently using 21 X WLC with N+1 Redundancy and 1X WCS with 1000++ of LAP1020. If had been observed that the antenna type and power TX had been changed with no reason. Is there any settings that may affect with AP customized Tx Power and antenna settings other than using the WCS template to push the configure to the APs instead of the WLC.

    Sorry for jumping in on the question with another question but it seemed the right place.
    I have an AIR-CT5508-25-K9 WLC and +25AP license : L-LIC-CT5508-25A.
    As far as I understand it the WLC should already have a 25AP license installed and with the adder license I should have a count of 50 APs.
    However, after installing the adder license the count is still 25.
    Could you please let me know if it's just something wrong in my reasoning or should a case be opened?
    Thank you,
    Barbara

  • Guest-Anchor-WLC and NAC integration guide

    I was trying to find some design reference for the Guest-WLC and NAC integration guide. Anyone can share some experience/cisco docs/links?

    User traffic is locally bridged on a 1030 in REAP mode so packet forwarded to the default gtw would follow the NAT rules on the firewall but the real challenge is the LWAPP control channel. In that past using 1:1 NAT I was successful with a CP firewall but I had to play tricks with the mobility group and use the FW logs to track and define the right ports.

  • Cisco wlc and steel belted radius

    we have cisco wlc controller  that have  two ssid  one for user and one for guest
    we need the  user in ssid 1 take user name and password from  user group in active directory through steel belted radiu
    please send to me any integrated guide between cisco wlc and steel belted radius
    regards

    Hi                                                      Mohammad,
    I am unaware of a specific Steel Belted RADIUS intrgration guide for the WLCs, however the configuration process on the controller will be the same:
    Cisco WLC Configuration Guide 7.0 - Configuring RADIUS:
    http://www.cisco.com/en/US/docs/wireless/controller/7.0/configuration/guide/c70sol.html#wp1388328
    You may wish to contact your RADIUS vendor for additional configuration steps on the server.
    Best,
    Drew

  • WLC and LDAP

    Hi to all,
    i want to use local-eap+LDAP (microsoft AD) and i'm experiencing some issue.
    First of all i'm not able to bind WLC and LDAP...if a perform a debug aaa ldap enable i get this output:
    Any idea about how to solve this issue?
    Regards
    Ale

    It sounds like .... invalid credentials ? :-)
    Please post your LDAP config on WLC.
    Is your admin username with which you're binding within the search context that you defined ? this is very important

  • WLC and WLSE

    Hi Netpro
    what is the difference between the WLC and WLSE?
    thanks

    Basically the WLSE is no longer around:)  the WLSE was a management box for autonomous ap's.  The WLC manages lightweight access points and that is really what everyone is moving towards if not already.
    http://www.learnios.com/viewtopic.php?f=5&t=33687
    https://supportforums.cisco.com/thread/328073
    https://supportforums.cisco.com/thread/338936

  • WLC and IPv6

    Hi All,
    has anybody experiences with WLC and IPv6? I have activated the Check Box for IPv6 Support, but it does not work. Regards, Michael

    Hi ,
    Have you configued uplink router/sw to support ipv6 ; the sample config would look like this
    ipv6 unicast-routing
    interface FastEthernet0/0.6
    encapsulation dot1Q 56
    ip address 10.50.56.1 255.255.255.0
    ip access-group GNS2 in
    ip access-group GNS2 out
    ip helper-address 10.50.1.21
    ip pim sparse-dense-mode
    ip multicast ttl-threshold 1
    no snmp trap link-status
    ipv6 address 2006::/64 eui-64
    ipv6 address autoconfig
    ipv6 enable
    let me if this works for you or not
    regards
    Seema

  • WLC and LWAP Registration Log Question

    We have a Cisco 4404 WLC and and about 70 Cisco 1131 APs.  I am very new to the Cisco WLC and I need to know how to view its AP registration and unregistration logs.  We have a AP that has unregistered and we can't seem to find what switchport it was attached to.  It would be helpful to know the IP address and ideally any CDP information it had.  Unfortunately you can only view this information in the WLC if the AP is registered, but at this point it is not.  Any help would be appreciated.

    You will not be able to find that info unless you still see the information on the log about the AP. You would have to either review the switch cdp info as long as the AP is still functioning or else you will just need to physically track it down. If you have WCS or NCS, you should be able to review the past history and the maps would show you where that AP was located if the ap were positioned correctly.
    Thanks,
    Scott Fella
    Sent from my iPhone

  • WLC and AP in L3

    Hello everyone
    I hope if anyone can help me.
    a Building has 3 companies (A,B and C)
    and I have one WLC
    in each company there is 3 AP
    I want to configure WLC whereas any AP in company A cant communicate to other AP in company B and C
    and the same to all companies
    I mean totally separate in IP scheme (no routing between them)
    can that done with WLC and LWAP ??
    PLZ advice

    thank you all for your reply
    I would like to ask you another question fo another scenario.
    I have one WLC installed in one subnet, let's say in the head quarter network, while the LAPs are installed in the branches and there is WAN connectivity between the HQ and the branch and OSPF routing is enabled between this WAN network. How can I do my configuration in order to register the LAPs installed in the branch with WLC installed in the HQ?
    Thanks,

  • IPv6 for management and control plane on WLCs and LWAPs

    Good morning, everybody!
    I am trying to find answer to a question that has been previously asked by people but never successfully answered
    The question is about IPv6 support on Cisco Wireless LAN Controllers and access points... Does Cisco have a roadmap to include support for IPv6 used in CAPWAP, control plane and management? There are couple of posts on this topic that do not unfortunately provide any answer to this point.
    https://supportforums.cisco.com/message/3018843
    https://supportforums.cisco.com/docs/DOC-15667
    Infamous "Cisco IPv6 Solution" at http://www.cisco.com/en/US/partner/technologies/collateral/tk648/tk872/tk373/technologies_white_paper_09186a00802219bc_ps6553_Products_White_Paper.html briefly states "Wireless Solutions... In future, IPv6 control plane features may get added to those components."
    Has anyone heard of any more specific roadmap for IPv6 support for CAPWAP, control plane and management on WLCs and LWAPs?

    Full ipv6 support will never be available on the Wism and 440x controllers because they have a NPU to forward traffic and it was not designed with ipv6 in mind.
    The 5508 and Wism2 and all new controllers all have CPU based forwarding and ipv6 is coming in next releases.
    WLC 8.0 is only for december 2011/2012 and I have to say I don't know if it will support native ipv6.
    my 2 cents

  • 2106 WLC and 4 LWAPP (1252G)

    I have a 2106 WLC with 4 AP's (AIR-LAP1252AG-A-K9)
    One of the AP's (port 4) is only connecting at 10Mbps, not 100Mbps and I don't know why?
    All the ;ports are set on the controller to AUTO,  When I try to force that port to 100Mbps, the link drops.
    Could it be a cabling issue... or could I have a bad port on the 2106?    How to I troubleshoot this.  It's odd, because
    that particular AP is about 100ft from thte WLC and the closest to it.
    Any ideas?
    Joe
    Primary Software Version   7.0.116.0 
    Predownload Retry Count  
    Boot Version   12.4.18.1
    IOS Version   12.4(23c)JA2
    Mini IOS Version  3.0.51.0
    Primary Software Version   7.0.116.0 
    Predownload Retry Count  
    Boot Version   12.4.18.1
    IOS Version   12.4(23c)JA2
    Mini IOS Version  3.0.51.0

    Interesting...  I unplugged the LAP (data and power) and removed it from the wall of our training room 75ft from our computer room,  walked the AP into the computer room and with a 15' patch cord and power supply plugged it back into the WLC 2106.  Waited a min for the AP to reboot and now my port speed is showing 100Mbps connection.   
    The issue must be with the cable run...?  Thanks for pointing out the obvious.   This now begs another questions regarding 2106 best practices and the idea of connecting our 4 AP's directly into network switches and not the WLC 2106 itself.  That seems to be the recommendation.  Any comments?
    Joe

  • WLC and WCS licenses

    How many APs does wireless controller 5508 and WCS (version 7.0) supports?
    Cheers,

    Sorry for jumping in on the question with another question but it seemed the right place.
    I have an AIR-CT5508-25-K9 WLC and +25AP license : L-LIC-CT5508-25A.
    As far as I understand it the WLC should already have a 25AP license installed and with the adder license I should have a count of 50 APs.
    However, after installing the adder license the count is still 25.
    Could you please let me know if it's just something wrong in my reasoning or should a case be opened?
    Thank you,
    Barbara

  • Cisco WLC and Microsoft NAP

    Hi, I want to integrate my Cisco WLC directly into Microsoft NAP. Is this possible?
    Thanks

    follow the table in the link http://www.cisco.com/en/US/docs/security/nac-nap/1.0/release/notes/NACNAPRN.html#wp1134942 for the integration of WLC and Microsoft NAP

Maybe you are looking for