LAP 1141N Join problem on WLC 4402 Ver 7.0

Hi All,
Please, I need your help with LAP join proccess:
70:ca:9b:25:5b:9d -> AP MAC
10.10.1.30 -> DNS
Thanks in advance!
debug capwap events:
*spamReceiveTask: Mar 07 11:23:14.661: 70:ca:9b:25:5b:9d Received LWAPP DISCOVERY REQUEST to ff:ff:ff:ff:ff:ff on port '1'
*spamReceiveTask: Mar 07 11:23:24.660: 70:ca:9b:25:5b:9d Received LWAPP DISCOVERY REQUEST to ff:ff:ff:ff:ff:ff on port '1'
*spamReceiveTask: Mar 07 11:23:34.660: 70:ca:9b:25:5b:9d Received LWAPP DISCOVERY REQUEST to ff:ff:ff:ff:ff:ff on port '1'
*spamReceiveTask: Mar 07 11:23:44.660: 70:ca:9b:25:5b:9d Received LWAPP DISCOVERY REQUEST to ff:ff:ff:ff:ff:ff on port '1'
*spamReceiveTask: Mar 07 11:23:54.660: 70:ca:9b:25:5b:9d Received LWAPP DISCOVERY REQUEST to ff:ff:ff:ff:ff:ff on port '1'
*spamReceiveTask: Mar 07 11:24:04.659: 70:ca:9b:25:5b:9d Discovery Request from 10.10.1.30:46525
*spamReceiveTask: Mar 07 11:24:04.660: 70:ca:9b:25:5b:9d Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 25, joined Aps =21
*spamReceiveTask: Mar 07 11:24:14.659: 70:ca:9b:25:5b:9d Discovery Request from 10.10.1.30:46525
*spamReceiveTask: Mar 07 11:24:14.659: 70:ca:9b:25:5b:9d Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 25, joined Aps =21
*spamReceiveTask: Mar 07 11:24:24.659: 70:ca:9b:25:5b:9d Discovery Request from 10.10.1.30:46525
*spamReceiveTask: Mar 07 11:24:24.659: 70:ca:9b:25:5b:9d Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 25, joined Aps =21
*spamReceiveTask: Mar 07 11:24:34.659: 70:ca:9b:25:5b:9d Discovery Request from 10.10.1.30:46525
*spamReceiveTask: Mar 07 11:24:34.659: 70:ca:9b:25:5b:9d Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 25, joined Aps =21
*spamReceiveTask: Mar 07 11:24:44.658: 70:ca:9b:25:5b:9d Discovery Request from 10.10.1.30:46525
*spamReceiveTask: Mar 07 11:24:44.659: 70:ca:9b:25:5b:9d Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 25, joined Aps =21
*spamReceiveTask: Mar 07 11:24:54.658: 70:ca:9b:25:5b:9d Discovery Request from 10.10.1.30:46525
*spamReceiveTask: Mar 07 11:24:54.658: 70:ca:9b:25:5b:9d Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 25, joined Aps =21
*spamReceiveTask: Mar 07 11:25:04.658: 70:ca:9b:25:5b:9d Discovery Request from 10.10.1.30:46525
*spamReceiveTask: Mar 07 11:25:04.658: 70:ca:9b:25:5b:9d Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 25, joined Aps =21
*spamReceiveTask: Mar 07 11:25:14.658: 70:ca:9b:25:5b:9d Discovery Request from 10.10.1.30:46525
*spamReceiveTask: Mar 07 11:25:14.658: 70:ca:9b:25:5b:9d Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 25, joined Aps =21
*spamReceiveTask: Mar 07 11:25:24.658: 70:ca:9b:25:5b:9d Discovery Request from 10.10.1.30:46525
*spamReceiveTask: Mar 07 11:25:24.658: 70:ca:9b:25:5b:9d Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 25, joined Aps =21
*spamReceiveTask: Mar 07 11:25:34.657: 70:ca:9b:25:5b:9d Discovery Request from 10.10.1.30:46525
*spamReceiveTask: Mar 07 11:25:34.658: 70:ca:9b:25:5b:9d Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 25, joined Aps =21

Thanks for answer.
Scott, I don't know the reason, I can't give an IP in the same subnet, do you know how configure manually an IP to AP?
3 subnet on the same vlan.
interface Vlan150
ip address 10.126.96.1 255.255.254.0 secondary
ip address 10.160.96.1 255.255.254.0 secondary  ->ap manager subnet
ip address 160.10.1.1 255.255.255.0  -> IP AP 160.10.1.50
ip helper-address 10.10.1.30
Stephen,
How know the code?
Interface summary:
Interface Name                   Port Vlan Id  IP Address      Type    Ap Mgr Guest
ap-manager                       1    untagged 10.160.96.11    Static  Yes    No
management                       1    untagged 10.160.96.10    Static  No     No
vlan 140                         1    140     10.125.96.30    Dynamic No     No
vlan 160                         1    160      10.160.18.2     Dynamic No     No
vlan 170                         1    170      10.160.10.2     Dynamic No     No
Debug:
*spamReceiveTask: Mar 07 17:36:33.442: 70:ca:9b:25:5b:9d Discovery Request from 160.10.1.50:46525
*spamReceiveTask: Mar 07 17:36:33.442: 70:ca:9b:25:5b:9d Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 25, joined Aps =21
*spamReceiveTask: Mar 07 17:36:33.442: 70:ca:9b:25:5b:9d Received a Discovery Request from 70:CA:9B:25:5B:9D via IP broadcast address but the source IP address (160.10.1.50) is not in any of the configured subnets. Dropping it
*spamReceiveTask: Mar 07 17:36:33.442: 70:ca:9b:25:5b:9d State machine handler: Failed to process  msg type = 1 state = 0 from 160.10.1.50:46525
*spamReceiveTask: Mar 07 17:36:33.442: 70:ca:9b:25:5b:9d Failed to parse CAPWAP packet from 160.10.1.50:46525

Similar Messages

  • No Join Response from WLC 4402 to LWAPP AP

    Hi,
    i have a problem with the 1242 LWAPP Access Points. It's not possible for a few access points to connect to the WLC.
    With some Access Points i get a join response.
    WLC image is 5.2.157.0
    AP's which i can't connect (no join response)
    image version:      3.0.51.0
    IOS version:         12.4(21a)JA2
    AP's which i can connect (join response)
    image version:      5.2.157.0
    IOS version:         12.4(18a)JA
    Can anybody help me? I can find a few topics in this community, but no one of these topics can help me in this case.
    in the following attachment no-join response.txt you can find the recording of the hyper terminal.
    Thanks in advance for answers.

    Problem is solved.
    I have upgraded the WCS und both WLC Controllers to Version 7.x.
    And for the "older" AP's with the image 3.x a secondary dns entry cisco-capwap-controller....

  • Inter-Controller and Inter-Subnet Roaming between WLC 4402 and 5508?

    Hi!
    Will it support roaming between WLC 5508 ver. 7.0 and WLC 4402 ver. 4.2?

    Here is the matrix for support of IRCM, but the answer is yes.
    http://www.cisco.com/en/US/docs/wireless/controller/5500/tech_notes/Wireless_Software_Compatibility_Matrix.html#wp116668
    Sent from Cisco Technical Support iPhone App

  • AP 1131ag not able to join with WLC 4402

    In some of my spare time, I've been trying to get this AP to join with this WLC. It's been about two weeks now. I'm not sure what the problem is. I think that there are a few possible issues, but I'm asking the more experienced & knowledgeable support community. I did convert the autonomous AP to a LAP. So here are some outputs:
    AP sh ver
    AP0014.6956.6926#sh ver
    Cisco IOS Software, C1130 Software (C1130-K9W8-M), Version 12.4(25e)JAO3, RELEASE SOFTWARE (fc1)
    Technical Support: http://www.cisco.com/techsupport
    Copyright (c) 1986-2013 by Cisco Systems, Inc.
    Compiled Wed 18-Dec-13 20:53 by prod_rel_team
    ROM: Bootstrap program is C1130 boot loader
    BOOTLDR: C1130 Boot Loader (C1130-BOOT-M) Version 12.3(2)JA3, RELEASE SOFTWARE (fc2)
    AP0014.6956.6926 uptime is 2 hours, 11 minutes
    System returned to ROM by power-on
    System image file is "flash:/c1130-k9w8-mx.124-25e.JAO3/c1130-k9w8-mx.124-25e.JAO3"
    This product contains cryptographic features and is subject to United
    States and local country laws governing import, export, transfer and
    use. Delivery of Cisco cryptographic products does not imply
    third-party authority to import, export, distribute or use encryption.
    Importers, exporters, distributors and users are responsible for
    compliance with U.S. and local country laws. By using this product you
    agree to comply with applicable laws and regulations. If you are unable
    to comply with U.S. and local laws, return this product immediately.
    A summary of U.S. laws governing Cisco cryptographic products may be found at:
    http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
    If you require further assistance please contact us by sending email to
    [email protected].
    cisco AIR-LAP1131AG-A-K9 (PowerPCElvis) processor (revision A0) with 27638K/5120K bytes of memory.
    Processor board ID FTX0924T1NR
    PowerPCElvis CPU at 262Mhz, revision number 0x0950
    Last reset from power-on
    LWAPP image version 7.3.1.72
    1 FastEthernet interface
    2 802.11 Radio(s)
    32K bytes of flash-simulated non-volatile configuration memory.
    Base ethernet MAC Address: 00:14:69:56:69:26
    Part Number                          : 73-8962-07
    PCA Assembly Number                  : 800-24818-06
    PCA Revision Number                  : C0
    PCB Serial Number                    : FOC092238UU
    Top Assembly Part Number             : 800-25544-01
    Top Assembly Serial Number           : FTX0924T1NR
    Top Revision Number                  : A0
    Product/Model Number                 : AIR-AP1131AG-A-K9  
    Configuration register is 0xF
    WLC sh sysinfo
    Manufacturer's Name.............................. Cisco Systems Inc.
    Product Name..................................... Cisco Controller
    Product Version.................................. 4.2.205.0
    RTOS Version..................................... 4.2.205.0
    Bootloader Version............................... 4.2.205.0
    Build Type....................................... DATA + WPS
    System Name...................................... wlcVA010a03a01
    System Location..................................
    System Contact...................................
    System ObjectID.................................. 1.3.6.1.4.1.14179.1.1.4.3
    IP Address....................................... 10.10.1.1
    System Up Time................................... 4 days 0 hrs 54 mins 42 secs
    Configured Country............................... US  - United States
    Operating Environment............................ Commercial (0 to 40 C)
    Internal Temp Alarm Limits....................... 0 to 65 C
    Internal Temperature............................. +39 C
    State of 802.11b Network......................... Enabled
    State of 802.11a Network......................... Enabled
    Number of WLANs.................................. 1
    3rd Party Access Point Support................... Disabled
    Number of Active Clients......................... 0
    Burned-in MAC Address............................ 00:18:73:35:DC:40
    Crypto Accelerator 1............................. Absent
    Crypto Accelerator 2............................. Absent
    Power Supply 1................................... Absent
    Power Supply 2................................... Present, OK
    WLC debug lwapp errors enable
    Fri Jan 24 16:55:15 2014: 00:13:5f:f8:94:f0 LWAPP Join Request does not include valid certificate in CERTIFICATE_PAYLOAD from AP 00:13:5f:f8:94:f0.
    Fri Jan 24 16:55:15 2014: 00:13:5f:f8:94:f0 Unable to free public key for AP 00:13:5f:f8:94:f0
    Fri Jan 24 16:55:15 2014: 00:13:5f:f8:94:f0 Decoding Join Request failed for AP 00:13:5f:f8:94:f0
    Fri Jan 24 16:55:20 2014: 00:13:5f:f8:94:f0 LWAPP Join Request does not include valid certificate in CERTIFICATE_PAYLOAD from AP 00:13:5f:f8:94:f0.
    Fri Jan 24 16:55:20 2014: 00:13:5f:f8:94:f0 Unable to free public key for AP 00:13:5f:f8:94:f0
    Fri Jan 24 16:55:20 2014: 00:13:5f:f8:94:f0 Decoding Join Request failed for AP 00:13:5f:f8:94:f0
    WLC debug lwapp events enable
    Fri Jan 24 16:52:20 2014: 00:13:5f:f8:94:f0 Received LWAPP DISCOVERY REQUEST from AP 00:13:5f:f8:94:f0 to ff:ff:ff:ff:ff:ff on port '1'
    Fri Jan 24 16:52:20 2014: 00:13:5f:f8:94:f0 Successful transmission of LWAPP Discovery Response to AP 00:13:5f:f8:94:f0 on port 1
    Fri Jan 24 16:52:20 2014: 00:13:5f:f8:94:f0 Received LWAPP DISCOVERY REQUEST from AP 00:13:5f:f8:94:f0 to ff:ff:ff:ff:ff:ff on port '1'
    Fri Jan 24 16:52:20 2014: 00:13:5f:f8:94:f0 Successful transmission of LWAPP Discovery Response to AP 00:13:5f:f8:94:f0 on port 1
    Fri Jan 24 16:52:31 2014: 00:13:5f:f8:94:f0 Received LWAPP JOIN REQUEST from AP 00:13:5f:f8:94:f0 to 06:0a:10:10:00:00 on port '1'
    Fri Jan 24 16:52:31 2014: 00:13:5f:f8:94:f0 LWAPP Join Request does not include valid certificate in CERTIFICATE_PAYLOAD from AP 00:13:5f:f8:94:f0.
    Fri Jan 24 16:52:31 2014: 00:13:5f:f8:94:f0 Unable to free public key for AP 00:13:5f:f8:94:f0
    Fri Jan 24 16:52:31 2014: 00:13:5f:f8:94:f0 Decoding Join Request failed for AP 00:13:5f:f8:94:f0
    Fri Jan 24 16:52:36 2014: 00:13:5f:f8:94:f0 Received LWAPP JOIN REQUEST from AP 00:13:5f:f8:94:f0 to 06:0a:10:10:00:00 on port '1'
    Fri Jan 24 16:52:36 2014: 00:13:5f:f8:94:f0 LWAPP Join Request does not include valid certificate in CERTIFICATE_PAYLOAD from AP 00:13:5f:f8:94:f0.
    Fri Jan 24 16:52:36 2014: 00:13:5f:f8:94:f0 Unable to free public key for AP 00:13:5f:f8:94:f0
    Fri Jan 24 16:52:36 2014: 00:13:5f:f8:94:f0 Decoding Join Request failed for AP 00:13:5f:f8:94:f0
    WLC debug pm pki enable
    Fri Jan 24 16:49:45 2014: sshpmGetIssuerHandles: invalid args (0x13d7edd0/0x13d7edd4/0x13d7edd8/0x30231b14/0)
    Fri Jan 24 16:49:45 2014: sshpmFreePublicKeyHandle: called with (nil)
    Fri Jan 24 16:49:45 2014: sshpmFreePublicKeyHandle: NULL argument.
    Fri Jan 24 16:49:50 2014: sshpmGetIssuerHandles: invalid args (0x13d91320/0x13d91324/0x13d91328/0x30231b14/0)
    Fri Jan 24 16:49:50 2014: sshpmFreePublicKeyHandle: called with (nil)
    Fri Jan 24 16:49:50 2014: sshpmFreePublicKeyHandle: NULL argument.
    Thanks!
    Leon

    cisco AIR-LAP1131AG-A-K9 (PowerPCElvis) processor (revision A0) with 27638K/5120K bytes of memory.WLC sh sysinfoManufacturer's Name.............................. Cisco Systems Inc.Product Name..................................... Cisco ControllerProduct Version.................................. 4.2.205.0RTOS Version..................................... 4.2.205.0Bootloader Version............................... 4.2.205.0Build Type....................................... DATA + WPSFri Jan 24 16:55:20 2014: 00:13:5f:f8:94:f0 LWAPP Join Request does not include valid certificate in CERTIFICATE_PAYLOAD from AP 00:13:5f:f8:94:f0.Fri Jan 24 16:52:36 2014: 00:13:5f:f8:94:f0 LWAPP Join Request does not include valid certificate in CERTIFICATE_PAYLOAD from AP 00:13:5f:f8:94:f0.
    adding to Above .
    Manually add self-signed certificates (SSCs) to a Cisco Wireless LAN (WLAN) Controller (WLC).
    you can manually add the SSC to the WLC.
    these kind problems occure with Lightweight AP Protocol (LWAPP)-converted AP.
    Via GUI:
    Choose Security > AP Policies and click Enabled beside Accept Self Signed Certificate.
    Select SSC from the Certificate Type drop-down menu.
    Enter the MAC address of the AP and the hash key, and click Add.
    Via CLI:
    Enable Accept Self Signed Certificate on the WLC. The command is config auth-list ap-policy ssc enable.
    (Cisco Controller) >config auth-list ap-policy ssc enable
    Add the AP MAC address and hash key to the authorization list,The command is config auth-list add ssc AP_MAC AP_key .
    (Cisco Controller) >config auth-list add ssc
    More to check here:
    http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a00806a426c.shtml.
    Also mention by Scott that this is very old version on WLC.Please upgrade it.
    Hope ite helps.
    REgards
    Dont forget to rate helpful posts

  • 1131 LWAP not join WLC 4402

    I am deploying WLC 4402 with LWAP 1131 but AP fail to join the WLC .The resone that I dont have DNS server.The error message in the AP is :
    AP001d.451f.8582>
    *Mar 1 00:00:38.005: %DHCP-6-ADDRESS_ASSIGN: Interface FastEthernet0 assigned D
    HCP address 172.26.5.12, mask 255.255.255.0, hostname AP001d.451f.8582
    Translating "CISCO-LWAPP-CONTROLLER"...domain server (255.255.255.255)
    *Mar 1 00:00:49.371: LWAPP_CLIENT_ERROR: lwapp_name_lookup - Could Not resolve
    I tried to configure the Controller address in LAP but I fail ,The error when I tried to configure AP is below:
    AP001d.451f.8582#lwapp ap controller ip address 172.26.5.10
    ERROR!!! Command is disabled.
    my question is :
    is it possible to make LAP join WLC with out DNS,if yes how ?

    Hi Yhab,
    There are other ways besides DNS to help in the AP and WLC Discovery process. Have a look in this good doc;
    Lightweight AP (LAP) Registration to a Wireless LAN Controller (WLC)
    http://www.cisco.com/en/US/tech/tk722/tk809/technologies_tech_note09186a00806c9e51.shtml#topic2
    For the Static entry problem;
    If this AP was ever registered you can use this command from the LAP CLI to clear the LWAPP configuration on the LAP:
    clear lwapp private-config
    This allows you to use the AP LWAPP static configuration commands again.
    Here is an example:
    Enable (enter password)
    AP1240#clear lwapp private-config
    AP1240#lwapp ap hostname AP1240
    AP1240#lwapp ap ip address 10.77.244.199 255.255.255.224
    AP1240#lwapp ap ip default-gateway 10.77.244.220
    AP1240#lwapp ap controller ip address 172.16.1.50
    Note: You cannot use the clear lwapp private-config command when the LAP is registered with the controller.
    http://www.cisco.com/en/US/products/hw/wireless/ps430/products_tech_note09186a00808e2d27.shtml#t2
    Hope this helps!
    Rob

  • WLC 4402 + LAP-1242AG + No DHCP

    Greetings to all,
    I am trying to get some LAP-1242 to join a 4402 controller without using any DHCP server. Is that possible?
    Thank you in advance

    Hi Stelios,
    Just thought I might add a note to the good info from Scott and Richard (5 points to both of you for this helpful info!)
    There is no danger of this AP reverting to Autonomous without a concerted effort on your part to reload an IOS :)
    Here is a summary;
    To clear or remove the manually entered controller information, you can use these EXEC mode CLI commands:
    clear lwapp ap ip address
    clear lwapp ip default-gateway
    clear lwapp controller ip address
    clear lwapp ap hostname
    Manually Resetting the Access Point to Defaults
    You can manually reset your access point to default settings using this EXEC mode CLI command:
    Note This command requires the controller configured Enable password to enter the CLI EXEC mode.
    clear lwapp private-config
    From this Troubleshooting doc;
    http://www.cisco.com/en/US/docs/wireless/access_point/1130/installation/guide/113h_c4.html#wp1091061
    If you enter the clear lwapp private-config command, you might see this error message:
    AP0017.5922.f384#clear lwapp private-config
    ERROR!!! Command is disabled.
    This error message indicates that the static configuration commands are locked out because either:
    This command was entered while the LAP is registered to a controller.
    ***The LAP was previously registered to a WLC, but the username/password was not changed from the default
    So try this;
    Once your LAP successfully registers with the WLC, the static LWAPP configuration commands (discussed in the previous section) are locked out and are no longer accessible. In order to re-enable the commands, you must have set the username and password while the LAP was joined to the previous controller.
    When the LAP is registered to a controller, use this controller CLI command to set the AP's username and password:
    config ap username password
    From this excellent doc :)
    Resetting the LWAPP Configuration on a Lightweight AP (LAP)
    http://www.cisco.com/en/US/products/hw/wireless/ps430/products_tech_note09186a00808e2d27.shtml
    Hope this helps!
    Rob

  • Wlc 4402 errors when trying to join ap

    Hello,
    I have a wlc 4402 controller with software version 6.0.199.4
    now i have problems adding 1131 aps to my controller.
    in the pas i added 15 access points (withouts problems) but
    now doesn't seems to work anymore.
    here's what i got from controller when trying to join
    *Nov 11 12:24:37.739: %LWAPP-3-RADIUS_ERR: spam_radius.c:138 Could not send join reply, AP authorization failed; AP:00:13:c4:93:c1:58
    here's what i got on the AP (console cable on my pc when booting)
    %LWAPP-3-CLIENTERRORLOG: LWAPP Crypto Init (SSC): no certs in the SSC Private File
    Got an idea on this ?
    thanks for help

    Was the AP in automatic mode before? Did you copy the LWAPP recovery image to the AP using tftp?
    All APs manufactured before 2005 or 2006 do not have MIC (manfacture install MIC) installed. You need to use LWAPP conversion tool to convert the AP to LWAPP/CAPWAP; so that the conversion tool will install SSC (Self Signed Certificates) to build the encrypt the LWAPP/CAPWAP control traffic:
    http://www.cisco.com/en/US/docs/wireless/access_point/conversion/lwapp/upgrade/guide/lwapnote.html
    As LWAPP discovery image is already there, you need to convert the AP back to autonomous mode and use LWAPP conversion tool to conver the AP:
    http://www.cisco.com/en/US/docs/wireless/access_point/12.3_8_JA/configuration/guide/s38trb.html#wp1058472
    I hope that the mode button is not disable on the AP. if it does, I hope that the break key is not disable. If both the mode button and break key are disable, you need to RMA the AP.

  • Problem to register upgraded AP 1242 to WLC 4402

    Hi,
    I am running a small Cisco WLAN with about 20 APs (all 1242) that are managed by two WLC 4402 (running v4.0.155.0).
    WLCs are in Mobility group, serveral WLANs/VLANs are configured (including 802.1x, guest access with WebAuthentication etc.). All APs are configured for the same WLC as primary and the other as secondary. Everthing was working fine until I tried to upgrade another AP from IOS to LWAPP using the Cisco Upgrade tool.
    After the AP was flashed and rebooted it started to discover a WLC but fails. The console messages look like this:
    *Mar 1 00:00:05.962: %CDP_PD-4-POWER_OK: Full power - AC_ADAPTOR inline power source
    *Mar 1 00:00:06.952: %LINK-3-UPDOWN: Interface FastEthernet0, changed state to up
    *Mar 1 00:00:07.952: %LINEPROTO-5-UPDOWN:
    ap> Line protocol on Interface FastEthernet0, changed state to up
    *Mar 1 00:00:25.960: %LWAPP-5-CHANGED: LWAPP changed state to DISCOVERY
    Translating "CISCO-LWAPP-CONTROLLER.xxx.yyy"...domain server (10.x.y.z)
    *Mar 1 00:00:35.348: %DHCP-6-ADDRESS_ASSIGN: Interface FastEthernet0 assigned DHCP address 10.x.y.z, mask 255.255.254.0, hostname AP0019.3076.fe30
    *Mar 1 00:00:36.349: LWAPP_CLIENT_ERROR: lwapp_name_lookup - Could Not resolve CISCO-LWAPP-CONTROLLER.xxx.yyy
    *Mar 1 00:00:46.398: %LWAPP-5-CHANGED: LWAPP changed state to JOIN
    *Mar 1 00:00:54.397: LWAPP_CLIENT_ERROR_DEBUG: spamHandleJoinTimer: Did not recieve the Join response
    *Mar 1 00:00:54.397: LWAPP_CLIENT_ERROR_DEBUG: No more AP manager IP addresses remain.
    *Mar 1 00:00:54.397: %SYS-5-RELOAD: Reload requested by LWAPP CLIENT. Reload Reason: DID NOT GET JOIN RESPONSE.
    *Mar 1 00:00:54.398: %LWAPP-5-CHANGED: LWAPP changed state to DOWN
    The switchport of the AP is configured for the same VLAN as the management and ap-management interface of the controller (not native VLAN), the primary controller is set to master controller mode and I see no other error messages (e. g. on the WLC).
    Does anyone know how to fix this problem?
    (even adding a "CISCO-LWAPP-CONTROLLER" host in the DNS does not help!!!)

    Hi Ankur,
    here the output of "dir flash:"
    dir flash:
    Directory of flash:/
    2 -rwx 1048 Aug 14 2007 14:29:38 +00:00 private-multiple-fs
    3 -rwx 314 Mar 1 2002 00:00:57 +00:00 env_vars
    156 drwx 128 Aug 14 2007 14:29:32 +00:00 c1240-rcvk9w8-mx
    10 drwx 256 Aug 15 2007 07:15:47 +00:00 c1240-k9w8-mx.123-11.JX
    15998976 bytes total (11196416 bytes free)
    AP0019.3076.fe30#
    Is there something wrong?
    Kind regards,
    Hagen

  • AP 2700 - 2 MAC addresses - problem with joining to the WLC

    Hi,
    I had a problem with joining my new AP 2700 to the controller. I've found workaround but I would like to ask you if you know if this behavior is a some kind of bug or maybe feature :)
    I have DHCP server which assigns IP address base on the binding MAC address with the IP address. Without binding, IP won't be assigned so I added MAC address from the AP sticker (MAC and SN number is on the sticker at the back of each AP) to the DHCP, connected AP to the switch port which was configured exactly the same way like other ports on this switch where older AP are working fine and.... nothing. IP address was not assigned. There was no DHCP request in the DHCP server logs.
    During the investigation I've found that AP present 2 MAC addresses on the switch interface:
    switch#sh mac address-table interface fa1/1
    Mac Address Table
    Vlan Mac Address Type Ports
    11 58f3.54c1.2cb3 DYNAMIC Fa1/1
    11 58f3.54c1.2cb4 DYNAMIC Fa1/1
    The first one (58f3.54c1.2cb3) is a "sticker" MAC address but the second one (58f3.54c1.2cb4) is something new. Looking in to the DHCP logs I've found log that this second MAC address (58f3.54c1.2cb4) tried to get IP address but it was not possible because this MAC was not binding with any IP address so DHCP server refuse. I added this second MAC (58f3.54c1.2cb4) to the DHCP server, AP get IP address, join to the WLC, download software, reboot and ... this MAC address disappear.
    switch#sh mac address-table interface fa1/1
    Mac Address Table
    Vlan Mac Address Type Ports
    11 58f3.54c1.2cb3 DYNAMIC Fa1/1
    Software I had on the AP before joining to the WLC was:
    Version :
    Cisco IOS Software, C2700 Software (AP3G2-RCVK9W8-M), Version 15.2(4)JB5, RELEASE SOFTWARE (fc1)
    now I have (after downloaded from the WLC)
    Version :
    Cisco IOS Software, C2700 Software (AP3G2-K9W8-M), Version 15.2(4)JB6, RELEASE SOFTWARE (fc1)
    Do anyone know what happen?

    (WLC1) >show sysinfo
    Manufacturer's Name.............................. Cisco Systems Inc.
    Product Name..................................... Cisco Controller
    Product Version.................................. 7.6.130.0
    Bootloader Version............................... 1.0.20
    Field Recovery Image Version..................... 7.6.95.16
    Firmware Version................................. FPGA 1.7, Env 1.8, USB console 2.2
    Build Type....................................... DATA + WPS
    System Name...................................... WLC1
    System Location..................................
    System Contact...................................
    System ObjectID.................................. 1.3.6.1.4.1.9.1.1069
    Redundancy Mode.................................. Disabled
    IP Address....................................... 10.10.10.10
    Last Reset....................................... Software reset
    System Up Time................................... 25 days 2 hrs 53 mins 5 secs
    System Timezone Location.........................
    System Stats Realtime Interval................... 5
    System Stats Normal Interval..................... 180
    Configured Country............................... US - United States
    Operating Environment............................ Commercial (0 to 40 C)
    Internal Temp Alarm Limits....................... 0 to 65 C
    Internal Temperature............................. +44 C
    External Temperature............................. +22 C
    Fan Status....................................... OK
    State of 802.11b Network......................... Enabled
    State of 802.11a Network......................... Disabled
    Number of WLANs.................................. 6
    Number of Active Clients......................... 25
    Burned-in MAC Address............................ XX:XX:XX:XX:XX:XX
    Power Supply 1................................... Present, OK
    Power Supply 2................................... Present, OK
    Maximum number of APs supported.................. 25
    (WLC1) >show time
    Time............................................. Thu Apr 9 13:51:00 2015
    Timezone delta................................... 0:0
    Timezone location................................
    NTP Servers
    NTP Polling Interval......................... 3600
    Index NTP Key Index NTP Server NTP Msg Auth Status
    1 0 10.10.10.11 AUTH DISABLED
    It's look like AP doesn't allow for console login or commands it just only show activity. After rebooting the WLC I get information:
    Cisco IOS Software, C2700 Software (AP3G2-RCVK9W8-M), Version 15.2(4)JB5, RELEASE SOFTWARE (fc1)

  • WLC-4402+AIR-LAP1142N problem

    Hello all,
    I've got a following problem with bringing up simple wireless configuration. There is a WLC-4402 controller and several remote locations (I am testing one so far). Two WLAN configured (one for employee and the other for guest access - no mobility anchoring used, guest is just mapper to VLAN restricted on the firewall). WLC serves DHCP pools for wireless clients. Problem I am experiencing at the moment is that user with laptop is able to connect to guest WLAN, got an IP but can communicate (ping) only its own IP, the controller IP in guest subnet and default gateway (which is the firewall interface). Traffic to any other destinations never hit gateway (I am running tcpdump on it to confirm). I double checked controller config but no luck so far. Could that be caused by missconfigured tunnel? No ACL or restriction set on WLC - see attached config.
    Thank you in advance,
    Peter

    Is this an open network or have you enabled layer 3 security? Web Auth? I can see you have created a lobby admin account so expect that you use this for guest account creation with web auth..
    When you associate/receieve IP address to the open guest network have you then opened a web browser and authenticated? Until you enter your login details created on the WLC I would imagine that you wouldn't be able to send any data.
    If you have authenticated already, can you check on the WLC that the client is associated/authenticated and is the Corp network ok? Also what is the topology between the WLC/Firewall/Remote sites.
    Cheers
    Mat

  • Only 47 APs join to WLC-4402-50

    Why only 47 APs join to the controller 4402-50, the debug capwap errors enable show this:
    (Cisco Controller) >
    *Sep 07 11:52:33.700: 00:3a:98:f0:f0:f0 Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 50, joined Aps =47
    *Sep 07 11:52:46.100: 00:3a:98:f0:f0:f0 Join resp: Unable to encode CAPWAP Control IPV4 Address
    *Sep 07 11:52:46.100: 00:3a:98:f0:f0:f0 Failed to encode Join response to 192.168.15.10:10738
    *Sep 07 11:52:46.101: 00:3a:98:f0:f0:f0 Config Response Failure: Unable to send Join response to 192.168.15.10:10738
    *Sep 07 11:52:46.103: 00:3a:98:f0:f0:f0 State machine handler: Failed to process  msg type = 3 state = 0 from 192.168.15.10:10738
    *Sep 07 11:52:46.103: 00:3a:98:f0:f0:f0 Failed to parse CAPWAP packet from 192.168.15.10:10738
    *Sep 07 11:52:46.105: 00:3a:98:f0:f0:f0 Discarding non-ClientHello Handshake OR DTLS encrypted packet from  192.168.15.10:10738)since DTLS session is not established
    Can anybody help me with this? When I disconect another AP the AP join succesfully and when i connect the disconnected AP not join, alway only 47 join, doesn't matter what AP, the first 47 in arrive join to the controller.
    Any idea?

    The limit Stephen is discussing was put into place to eliminate over subscription of a single sfp port utilizing only one AP manager interface. Enabling LAG equally distributes the traffic out one IP address using BOTH sfp ports from the physical layer perspective. You can also achieve this by adding a second AP manager interface and tying it to the second physical port. You must do one of these two to enable support for the additional 2 APs. When creating a new interface for the AP manager2 make sure that you allow it to dynamically manage the APs. If not, you will still have the same problem.

  • Hellp on Nokia E61i associating with Cisco WLC 4402

    I met some problem with associate Nokia's dual mode mobile phone E61i with Cisco WLC 4402, hope someone can help me on it:
    I setup a VOICE WLAN in 4402(v5.0.148), Layer2 security is WPA1+WPA2, Key management using 802.1x, WPA1 policy enable both TKIP and AES, Radius server using ACS engine(v4.1.1.23)(enable PEAP-MSCHAPv2);
    I can use my laptop to join this WLAN(my laptop configure with PEAP/MSCHAPv2, WPA-TKIP, not validate server certificate), but can't let E61i join it, each time it will remind me “unable to connect, WPA authenticate failed).
    In E61i, I select WPA/WPA2 as WLAN security mode, enable EAP-PEAP, under EAP-PEAP, I enable EAP-MSCHAPv2; however under Cipher, there's a lot of options such as “RSA,3EDS,SHA”, “RSA,AES,SHA”, but there's no TKIP, I have tried to enable all of them and tried only enable those items which include AES, but I failed each time with the same reminder “unable to connect, WPA authenticate failed”. I checked ACS's failed log, there's no record; In 4402, there also have no record.
    If I change the security to open or static WEP for VOICE WLAN, then the E61i can connect to the WLAN.
    I think the problem maybe relate to encryption or certificate, right now I just do the test in lab, not in customer's real environment, so I use ACS to generate a self signed certificate and installed it in ACS.
    Pls. help to point me what I need to adjust to make it work. Thanks!

    Hello,
    CCKM Key Management mode on Nokia E61i phone can be used
    against Cisco LWAPP AP's with TKIP encryption
    Nokia E61i (and other E-series WLAN enabled phones) are supporting CCKM key management method with both dynamic WEP and TKIP ciphers.
    On the phone configuration, 802.1X security mode needs to be in use in order to enable CCKM support. WPA/WPA2 security mode on the phone is dedicated to standards based WPA and WPA2 methods and it does not allow usage of proprietary CCKM key management method.
    Phone's 802.1X security mode does not mean that phone would only support dynamic WEP encryption method in this mode although in contexts term "802.1X" may be attached to pure dynamic WEP (legacy / pre WPA era)security methods.
     802.1X security mode can be seen on Nokia Eseries phones as sort of an "everything with EAP based authentication is allowed" mode, meaning that following key management and cipher configurations are supported:
    - WPA-Enterprise  = WPA Key Management (EAP based authentication) with TKIP encryption
    - WPA2-Enterprise = WPA2 Key Management (EAP based authentication) with AES encryption
    - Mixed WPA/WPA2-Enterprise = I.e. WPA/WPA2 Mode Migration WPA2 Key Management (EAP based authentication) with AES (for unicast data) and TKIP (for multicast data) ciphers
    - 802.1X dynamic WEP = legacy (pre-WPA era) 802.1X based dynamic WEP (EAP based authentication with dynamic WEP encryption)
    Supported:
    - CCKM with WEP = CCKM Key Management (EAP based authentication) with dynamic WEP encryption
    - CCKM with TKIP = CCKM Key Management (EAP based authentication) with TKIP encryption
    Not supported:
    - CCKM with AES = CCKM Key Management (EAP based authentication) with AES encryption
    Please note that CCKM-AES mode (CCKM Key Management with AES cipher) is not working properly due to some incompatibilities between Cisco and Nokia implementations thus it must not be listed as a supported combination on the current Nokia E-series devices. We are also seeing CCKM-Fast
    Re-authentication failures with Cisco autonomous AP's when AES encryption is used although initial authentication to autonomous AP's is successful. Nokia is currently working with Cisco to get CCKM-AES based authentications and roaming working properly with both LWAPP and autonomous Cisco AP's.
     Also note that Nokia E-Series does not support Cisco proprietary CKIP/CMIC encryption/data integrity methods. CKIP/CMIC is supported at least by Cisco autonomous AP's and it seems to be available also
    at least on LWAPP AP version 4.1.171.0.
     CCKM on E-Series devices has been tested against Cisco LWAPP (ver. 4.1.171.0) and it works when TKIP encryption is in use (WPA Policy + TKIP encryption in Cisco LWAPP configuration terms).
    In practice this means Cisco LWAPP is configured in a following manner: WLAN -> Edit -> Security-> 
    Layer 2 Security = WPA+WPA2
    WPA+WPA2 Parameters:
    -WPA Policy = enabled
    -WPA Encryption = TKIP enabled, AES disabled
    -WPA2 policy = disabled
    -Auth.Key Mgmt = CCKM
    Br,
    -Pasi-

  • Cisco AIR-LAP1041N-E-K9 not working with WLC 4402 version 7.0.116.0

    Hi All,
    appreciate your support for a problem i started facing today. i have a Cisco WLC 4402 running version 7.0.116.0 and it is working great with 25 Cisco 1252 APs. we have recieved a new 20 Cisco 1041N APs today and i installed one in our site but it doesn't work. it worked fine and loaded the image from flash and got the WLC ip address through DHCP option and started showing the below error:
    *Mar  1 00:00:10.021: %SOAP_FIPS-2-SELF_TEST_IOS_SUCCESS: IOS crypto FIPS self test passed
    *Mar  1 00:00:10.033: *** CRASH_LOG = YES
    *Mar  1 00:00:10.333: Port 1 is not presentSecurity Core found.
    Base Ethernet MAC address: C8:9C:1D:53:57:5E
    *Mar  1 00:00:11.373: %SOAP_FIPS-2-SELF_TEST_RAD_SUCCESS: RADIO crypto FIPS self test passed on interface Dot11Radio 0
    *Mar  1 00:00:11.465: %LWAPP-3-CLIENTEVENTLOG: Read and initialized AP event log (contains, 1088 messages)
    *Mar  1 00:00:11.494:  status of voice_diag_test from WLC is false
    *Mar  1 00:00:12.526: %LINK-3-UPDOWN: Interface GigabitEthernet0, changed state to up
    *Mar  1 00:00:13.594: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0, changed state to up
    *Mar  1 00:00:13.647: %SYS-5-RESTART: System restarted --
    Cisco IOS Software, C1040 Software (C1140-K9W8-M), Version 12.4(23c)JA2, RELEASE SOFTWARE (fc3)
    Technical Support: http://www.cisco.com/techsupport
    Copyright (c) 1986-2011 by Cisco Systems, Inc.
    Compiled Wed 13-Apr-11 12:50 by prod_rel_team
    *Mar  1 00:00:13.647: %SNMP-5-COLDSTART: SNMP agent on host APc89c.1d53.575e is undergoing a cold start
    *Mar  1 00:08:59.062: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
    *Mar  1 00:08:59.062: bsnInitRcbSlot: slot 1 has NO radio
    *Mar  1 00:08:59.138: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset
    *Mar  1 00:08:59.837: %SSH-5-ENABLED: SSH 2.0 has been enabled
    *Mar  1 00:09:00.145: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to down
    *Mar  1 00:09:09.136: %DHCP-6-ADDRESS_ASSIGN: Interface GigabitEthernet0 assigned DHCP address 172.16.26.81, mask 255.255.255.0, hostname APc89c.1d53.575e
    *Mar  1 00:09:17.912: %PARSER-4-BADCFG: Unexpected end of configuration file.
    *Mar  1 00:09:17.912:  status of voice_diag_test from WLC is false
    *Mar  1 00:09:17.984: Logging LWAPP message to 255.255.255.255.
    *Mar  1 00:09:19.865: %CDP_PD-4-POWER_OK: Full power - NEGOTIATED inline power source
    *Mar  1 00:09:19.886: %LINK-3-UPDOWN: Interface Dot11Radio0, changed state to up
    *Mar  1 00:09:20.873: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to up
    *Mar  1 00:09:20.874: %SYS-6-LOGGINGHOST_STARTSTOP: Logging to host 255.255.255.255 started - CLI initiated
    Translating "CISCO-CAPWAP-CONTROLLER.atheertele.com"...domain server (172.16.40.240)
    *Mar  1 00:09:29.029: %CAPWAP-5-DHCP_OPTION_43: Controller address 172.16.100.102 obtained through DHCP
    *May 25 08:27:02.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 172.16.100.101 peer_port: 5246
    *May 25 08:27:02.001: %CAPWAP-5-CHANGED: CAPWAP changed state to
    *May 25 08:27:03.175: %CAPWAP-5-DTLSREQSUCC: DTLS connection created sucessfully peer_ip: 172.16.100.101 peer_port: 5246
    *May 25 08:27:03.177: %CAPWAP-5-SENDJOIN: sending Join Request to 172.16.100.101
    *May 25 08:27:03.177: %CAPWAP-5-CHANGED: CAPWAP changed state to JOIN
    *May 25 08:27:03.329: %CAPWAP-5-CHANGED: CAPWAP changed state to CFG
    *May 25 08:27:03.333: %DTLS-5-ALERT: Received WARNING : Close notify alert from 172.16.100.101
    *May 25 08:27:03.333: %DTLS-5-PEER_DISCONNECT: Peer 172.16.100.101 has closed connection.
    *May 25 08:27:03.333: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 172.16.100.101:5246
    *May 25 08:27:03.378: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
    *May 25 08:27:03.378: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
    *May 25 08:27:03.378: bsnInitRcbSlot: slot 1 has NO radio
    *May 25 08:27:03.448:  status of voice_diag_test from WLC is false
    *May 25 08:27:14.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 172.16.100.101 peer_port: 5246
    *May 25 08:27:14.001: %CAPWAP-5-CHANGED: CAPWAP changed state to
    *May 25 08:27:15.185: %CAPWAP-5-DTLSREQSUCC: DTLS connection created sucessfully peer_ip: 172.16.100.101 peer_port: 5246
    *May 25 08:27:15.186: %CAPWAP-5-SENDJOIN: sending Join Request to 172.16.100.101
    *May 25 08:27:15.186: %CAPWAP-5-CHANGED: CAPWAP changed state to JOIN
    *May 25 08:27:15.330: %CAPWAP-5-CHANGED: CAPWAP changed state to CFG
    *May 25 08:27:15.333: %DTLS-5-ALERT: Received WARNING : Close notify alert from 172.16.100.101
    *May 25 08:27:15.334: %DTLS-5-PEER_DISCONNECT: Peer 172.16.100.101 has closed connection.
    *May 25 08:27:15.334: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 172.16.100.101:5246
    *May 25 08:27:15.379: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
    *May 25 08:27:15.379: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
    *May 25 08:27:15.379: bsnInitRcbSlot: slot 1 has NO radio
    *May 25 08:27:15.450:  status of voice_diag_test from WLC is false
    *May 25 08:27:26.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 172.16.100.101 peer_port: 5246
    *May 25 08:27:26.001: %CAPWAP-5-CHANGED: CAPWAP changed state to
    *May 25 08:27:27.182: %CAPWAP-5-DTLSREQSUCC: DTLS connection created sucessfully peer_ip: 172.16.100.101 peer_port: 5246
    *May 25 08:27:27.183: %CAPWAP-5-SENDJOIN: sending Join Request to 172.16.100.101
    *May 25 08:27:27.184: %CAPWAP-5-CHANGED: CAPWAP changed state to JOIN
    *May 25 08:27:27.329: %CAPWAP-5-CHANGED: CAPWAP changed state to CFG
    *May 25 08:27:27.333: %DTLS-5-ALERT: Received WARNING : Close notify alert from 172.16.100.101
    *May 25 08:27:27.333: %DTLS-5-PEER_DISCONNECT: Peer 172.16.100.101 has closed connection.
    *May 25 08:27:27.333: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 172.16.100.101:5246
    *May 25 08:27:27.377: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
    *May 25 08:27:27.377: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
    *May 25 08:27:27.377: bsnInitRcbSlot: slot 1 has NO radio
    *May 25 08:27:27.433: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to administratively down
    *May 25 08:27:27.446: %PARSER-4-BADCFG: Unexpected end of configuration file.
    *May 25 08:27:27.447:  status of voice_diag_test from WLC is false
    *May 25 08:27:27.448: %LINK-3-UPDOWN: Interface Dot11Radio0, changed state to up
    *May 25 08:27:27.456: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset
    *May 25 08:27:38.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 172.16.100.101 peer_port: 5246
    *May 25 08:27:38.001: %CAPWAP-5-CHANGED: CAPWAP changed state to
    *May 25 08:27:39.183: %CAPWAP-5-DTLSREQSUCC: DTLS connection created sucessfully peer_ip: 172.16.100.101 peer_port: 5246
    *May 25 08:27:39.184: %CAPWAP-5-SENDJOIN: sending Join Request to 172.16.100.101
    *May 25 08:27:39.184: %CAPWAP-5-CHANGED: CAPWAP changed state to JOIN
    *May 25 08:27:39.326: %CAPWAP-5-CHANGED: CAPWAP changed state to CFG
    *May 25 08:27:39.329: %DTLS-5-ALERT: Received WARNING : Close notify alert from 172.16.100.101
    *May 25 08:27:39.329: %DTLS-5-PEER_DISCONNECT: Peer 172.16.100.101 has closed connection.
    *May 25 08:27:39.330: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 172.16.100.101:5246
    *May 25 08:27:39.375: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
    *May 25 08:27:39.375: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
    *May 25 08:27:39.375: bsnInitRcbSlot: slot 1 has NO radio
    *May 25 08:27:39.446:  status of voice_diag_test from WLC is false
    *May 25 08:27:49.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 172.16.100.101 peer_port: 5246
    *May 25 08:27:49.001: %CAPWAP-5-CHANGED: CAPWAP changed state to
    *May 25 08:27:50.179: %CAPWAP-5-DTLSREQSUCC: DTLS connection created sucessfully peer_ip: 172.16.100.101 peer_port: 5246
    *May 25 08:27:50.180: %CAPWAP-5-SENDJOIN: sending Join Request to 172.16.100.101
    *May 25 08:27:50.180: %CAPWAP-5-CHANGED: CAPWAP changed state to JOIN
    *May 25 08:27:50.323: %CAPWAP-5-CHANGED: CAPWAP changed state to CFG
    *May 25 08:27:50.326: %DTLS-5-ALERT: Received WARNING : Close notify alert from 172.16.100.101
    *May 25 08:27:50.326: %DTLS-5-PEER_DISCONNECT: Peer 172.16.100.101 has closed connection.
    *May 25 08:27:50.326: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 172.16.100.101:5246
    *May 25 08:27:50.370: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
    *May 25 08:27:50.370: %CAPWAP-5-CHANGED: CAPWAP changed state to DISCOVERY
    *May 25 08:27:50.370: bsnInitRcbSlot: slot 1 has NO radio
    *May 25 08:27:50.425: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to administratively down
    *May 25 08:27:50.438: %PARSER-4-BADCFG: Unexpected end of configuration file.
    i searched for the regulatory domains difference between  AIR-LAP1041N-E-K9 and  AIR-LAP1041N-A-K9 and didn't find any difference that may affect the operation of this AP.
    just to mention that our configuration in WLC for regulatory domains is:
    Configured Country Code(s) AR 
    Regulatory Domain  802.11a:  -A
                                 802.11bg: -A
    My question is, should i only include my country in the WLC (IQ) to add the requlatry domain (-E) to solve this problem? or changing the country will affect the operation of all working APs??
    Appreciate your kind support,
    Wisam Q.

    Hi Ramon,
    thank you for the reply but as shown in the below link:
    http://www.cisco.com/en/US/docs/wireless/controller/release/notes/crn7.0.html#wp233793
    the WLC in version 7.0.116.0 supports Cisco 1040 seiries APs.
    Thanks,
    Wisam Q.

  • Wireless controller ha between wlc5508 and wlc 4402

    We have 2 wlc:  a wlc 5508 ( license 100 AP ) and  wlc 4402 ( license 12AP).
    We try to setup when 5508 down, 12 identify AP (important AP -Group A) will join 4402 and all other AP (not improtan AP -Group B)
    wont joint  wlc 4402.
    First, all AP join wlc 5508, 2 WLC have same mobility group.
    After that, we  config 12 APs belongto group A have primary and secondary wlc, group B only has primary wlc.
    When wlc 5508 down, some of APs of GroupA and   some of APs of GroupB join wlc 4402. We test many times and we have differnet result each times.
    is theare any way to resolve our problem?
    Thanks.

    Just to add, make sure that the WLC is running the same code, if not, then make sure the ap is supported on the code that is running on the 5508. The issue with mixed code is the ap will upgrade and downgrade very time they switch to a different WLC.
    http://www.cisco.com/en/US/docs/wireless/controller/5500/tech_notes/Wireless_Software_Compatibility_Matrix.html
    Sent from Cisco Technical Support iPhone App

  • Windows XP Home on WLC 4402

    Hi,
    I have a WLC 4402 Wireless LAN Controller with multiple 1231 AP on LWAPP. WLAN has security setting on WPA+WPA2 with PSK share key. All computers in domain are fine, wireless connections are steady. I have a group of students use Netbook on Windows XP Home SP3 got connection and drop situation. Event ID on XP has continuous 4201 and 4202 cases, and on WLC log I have also continuous log as
    *Apr 19 10:35:44.046: %DOT1X-3-MAX_EAPOL_KEY_RETRANS: 1x_ptsm.c:407 Max EAPOL-key M1 retransmissions exceeded for client 00:26:5e:eb:fd:0a
    I understand XP Home has no certificate from Domain environment therefore I didn't setup any AAA server service. How can this problem be resolved? Keep trying on security combination, but no luck. Please Help. Thanks.
    Attachment is WLC configuration file without encryption.

    Hi, Kayle
    Thanks for quick reply. Its not ASUS EeePC but ASUS s10e. The wireless LAN device is Broadcom 802.11g. I check with Lenono System Update, no newer driver available. Thanks.

Maybe you are looking for

  • Ipad no longer connecting to TV...help!

    With no update performed in the last week our ipad and iphone (both running IOs 7.0.1) no longer were connecting to the TV through a composite AV cable. I've read of many people having this issue with netflix 5.0 (which we have) but it's not only net

  • EXP-00105: parameter CONSISTENT is not supported for this user

    Hi, I have use Oracle 10g on unix platform i have export is taken from following command exp \'/ as sysdba\' file=t.dmp full=y buffer=10485760 log=0101.log CONSISTENT=y statistics=none export is sucessfull but one warning EXP-00105: parameter CONSIST

  • Data fetch from table GLPCA taking long .

    Hi Friends, I am fetching five fields from GLPCA table and i have RACCT and RPRCTR ( account Number and profit Centre res ) in the where condition. neither of these field is the primary key of the table GLPCA. I have around 161096,482 entries in the

  • PLS-00306: wrong number or types of arguments in call to 'PROCESS_CDR'

    hi i am trying to build a procedure which takes radius parameters as ip and than calculates some data and insert it back to the db this is my proc as NASIPADDRESS varchar2(50); USERNAME varchar2(50); ACCTSESSIONTIME number; CALLEDSTATIONID varchar2(5

  • Get SM20 Audit Log from remote call.

    Hi Experts, I'm working with SAP JCo driver, I'd like to ask, is there any possibility to receive filtered Audit Log from SM20? I couldn't find any BAPI or RFC interface, or information about specific table where information is stored. Thanks in adva