LAP not joining the controller

Gents
I have 1 AP out of ten not joining the controller. I connected the access point to the network and I checked its boot. the access point reaches LWAPP Discovery" and then give me console input. I hard reset the access point and I hard coded an IP address for the AP the AP joins the controller, but when I reset it to assign it to another controller it did not join again.
why the discovery process is not showing the DHCP option 43 configured and DNS for CISCO-LWAPP-CONTROLLER configured on the DNS. All the access point is operating normally except this one. it has many certificate inside, why a hard reset did not work to solve the problem?
Please advise
Thanks,

Does the LAP have a valid IP address?
Can the LAP ping the WLC managment IP address?
Console into the LAP and in enable mode, type the command "lwapp ap controller ".

Similar Messages

  • LWAPP 1231 does not join the controller

    I have LWAPP AIR-AP1231G-A-K9 that was moved from one site to the other one. It has now a different IP address taken from DHCP and its former controller does not exist any more.
    I am trying to join it to the same kind of controller which is AIR-WLC4402-12-K9 with  7.0.98.0.
    However the AP cannot join the controller, first I got these on the controller
    0 Wed Jul 3 14:12:56 2013 AAA Authentication Failure for UserName:0014694b3ab2 User Type: WLAN USER
    1 Wed Jul 3 14:12:56 2013 Failed to authorize AP with Base Radio MAC 00:14:69:4b:3a:b2. Authorization entry does not exist in Controller's AP Authorization List.
    I added the MAC address of the AP into MAC filtering, and now getting these
    AAA Authentication Failure for UserName:0014694b3ab2 User Type: WLAN USER
    I am reading several discussions, but they seem to be related to mesh OS mismatch.
    My AP is for sure not with mesh OS as it was connected to the controller before the move.
    System image file is "flash:/c1200-k9w8-mx.124-23c.JA/c1200-k9w8-mx.124-23c.JA"
    #sh capwap client config
    swVer                   7.0.98.0
    Does anyone know what to do to get the AP joined to the controller ?
    I had another AP where I tried to reset the LWAPP config - clear lwapp private-config, but this did not help and this AP is now constantly rebooting without allowing me to login. It looks like the only way how to wake it up would be to convert to autonomous and then back to LWAPP which is something I cannot do as I am too far from it.
    Thanks,
    Vlad

    Hello George,
    Many thanks. I have not converted the AP from autonomous to lwapp, it has been lwapp since the very beginning. We just moved this AP from one site where it was successfully joined the controller as lwapp to other site where I am trying to join the same kind of controller with the same OS, same general settings but different IPs.
    I do not understand what could happen to the AP as for sure it was just shipped and not touched IT wise.
    Anyway, I will try the excersise described in the link above.
    Thanks,
    Vlad

  • APs randomly will not join the controller

    Hi all,
    In short, APs will join the controller immediately using the recovery image, but once it downloads 7.6.100 and reboots, it either cannot join the controller or will take up to 40 minutes.
    The AP is in local mode. The AP 1040 eventually joined the controller, 40 minutes after we deleted all the files off the flash which is unacceptable.
    *Apr  9 15:38:15.842: %CAPWAP-5-SENDJOIN: sending Join Request to 10.10.10.10
    *Apr  9 15:38:15.851: %CAPWAP-3-ERRORLOG: Invalid event 10 & state 5 combination.
    *Apr  9 15:38:15.851: %CAPWAP-3-ERRORLOG: CAPWAP SM handler: Failed to process message type 10 state 5.
    *Apr  9 15:38:15.851: %CAPWAP-3-ERRORLOG: Failed to handle capwap control message from controller
    *Apr  9 15:38:15.851: %CAPWAP-3-ERRORLOG: Failed to process encrypted capwap packet from 10.10.10.10
    *Apr  9 15:38:16.304: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to down
    *Apr  9 15:38:16.362: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset
    *Apr  9 15:38:16.427: %CAPWAP-5-JOINEDCONTROLLER: AP has joined controller CONTROLLER-DC
    I also had our technician console into a 2602 and we were seeing exact same errors.
    SUMMARY OF THIS CASE:
    --AP is 1042 and wlc is on 7.6.100.0
    --using dhcp option 43 but the AP has static ip
    --checked the private config on the AP and it was not sending the discovery request to the desired  WLC
    --cleared the private config
    --primed the AP to desired WLC
    --AP sending join request but receiving the following errors:
    Apr  4 14:37:47.000: CAPWAP-3-ERRORLOG Go join a capwap controller
    *Apr  4 14:36:47.000: CAPWAP-5-DTLSREQSEND DTLS connection request sent peer_ip: 10.10.10.11 peer_port: 5246
    *Apr  4 14:36:47.169: DTLS_CLIENT_ERROR: ../capwap/base_capwap/dtls/base_capwap_dtls_handshake.c:90 First fragment for seq 2 is missing
    *Apr  4 14:37:17.205: DTLS_CLIENT_ERROR: ../capwap/base_capwap/dtls/base_capwap_dtls_connection_db.c:2176 Max retransmission count reached!
    --cleared the flash except rcv
    --ap started downloading the image from the wlc but once it reboots the same errors appear again
    --research made on the error message and apparently we are hitting a bug:
    https://tools.cisco.com/bugsearch/bug/CSCul08933/?reffering_site=dumpcr

    Hi Leo,
    Next the information, I omitted some serial number and descriptions due to confidentiality matters.
    (Cisco Controller) >show sysinfo
    Manufacturer's Name.............................. Cisco Systems Inc.
    Product Name..................................... Cisco Controller Product Version.................................. 7.6.100.0 Bootloader Version............................... 1.0.1 Field Recovery Image Version..................... 6.0.182.0 Firmware Version................................. FPGA 1.3, Env 1.6, USB console 1.27 Build Type....................................... DATA + WPS
    System Name...................................... ABCDEF System Location..................................
    System Contact...................................
    System ObjectID.................................. 1.3.6.1.4.1.9.1.1069 Redundancy Mode.................................. Disabled IP Address....................................... XXXXXXX Last Reset....................................... Software reset System Up Time................................... 32 days 14 hrs 1 mins 41 secs System Timezone Location......................... (GMT -5:00) Eastern Time (US and Canada) System Stats Realtime Interval................... 5 System Stats Normal Interval..................... 180
    Configured Country............................... CA  - Canada Operating Environment............................ Commercial (0 to 40 C)
    Internal Temp Alarm Limits....................... 0 to 65 C Internal Temperature............................. +40 C External Temperature............................. +21 C Fan Status....................................... OK
    State of 802.11b Network......................... Enabled State of 802.11a Network......................... Enabled Number of WLANs.................................. 5 Number of Active Clients......................... 2215
    Burned-in MAC Address............................ F0:F7:55:2B:4A:80 Power Supply 1................................... Present, OK Power Supply 2................................... Absent Maximum number of APs supported.................. 500
    (Cisco Controller) >show time
    Time............................................. Mon Apr 14 08:40:08 2014
    Timezone delta................................... 0:0 Timezone location................................ (GMT -5:00) Eastern Time (US and Canada)
    NTP Servers
        NTP Polling Interval.........................     36000
         Index     NTP Key Index                  NTP Server                  NTP Msg Auth Status
           1              0                                              A.B.C.D                        AUTH DISABLED
    AP>sh ver
    Cisco IOS Software, C3500 Software (AP3G1-K9W8-M), Version 15.2(4)JB3, RELEASE SOFTWARE (fc1) Technical Support: http://www.cisco.com/techsupport Copyright (c) 1986-2013 by Cisco Systems, Inc.
    Compiled Wed 18-Dec-13 21:36 by prod_rel_team
    ROM: Bootstrap program is C3500 boot loader
    BOOTLDR: C3500 Boot Loader (AP3G1-BOOT-M), Version 15.2 [chayan-apn-0411 116]
    AP uptime is 2 days, 17 hours, 15 minutes System returned to ROM by reload System image file is "flash:/ap3g1-k9w8-mx.152-4.JB3/ap3g1-k9w8-xx.152-4.JB3"
    Last reload reason:
    cisco AIR-CAP3502I-A-K9 (PowerPC460exr) processor (revision A0) with 98294K/32768K bytes of memory.
    Processor board ID XXXXXXXX
    PowerPC460exr CPU at 666Mhz, revision number 0x18A8 Last reset from reload LWAPP image version 7.6.100.0
    1 Gigabit Ethernet interface
    2 802.11 Radios
    32K bytes of flash-simulated non-volatile configuration memory.
    Base ethernet MAC Address: 70:81:05:9E:F7:36
    Part Number                          : 73-12175-05
    PCA Assembly Number                  : 800-32268-05
    PCA Revision Number                  : A0
    PCB Serial Number                    : XXXXXXX
    Top Assembly Part Number             : 800-32891-01
    Top Assembly Serial Number           : FGL1534S7LP
    Top Revision Number                  : A0
    Product/Model Number                 : AIR-CAP3502I-A-K9  
    Configuration register is 0xF
    AP>sh ip int br
    Interface                  IP-Address      OK? Method Status                Protocol
    BVI1                       X.Y.W.Z                YES TFTP   up                    up     
    Dot11Radio0                unassigned      NO  unset  up                    up     
    Dot11Radio1                unassigned      NO  unset  up                    up     
    GigabitEthernet0           unassigned      NO  unset  up                    up     
    GigabitEthernet0.1         unassigned      YES unset  up                    up     
    AP>sh inventory
    NAME: "AP3500", DESCR: "Cisco Aironet 3500 Series (IEEE 802.11n) Access Point"
    PID: AIR-CAP3502I-A-K9 , VID: V01, SN: XXXXXXX

  • AIR-CAP3501I access point not joining the Cisco 2100 Wireless Lan controller.

    Hello All,
    I am installing a new LAP (AIR-CAP3501I ) through the wireless lan controller (AIR-WLC2112-K9) with software version 7.0. I have an external ADSL modem which will act as the DHCP server for the wireless clients and the LAP.
    Please find my network setup as below:
    The ISP ADSL modem , WLC and LAP are connected to a unmanaged POE switch. The LAP gets its power through the POE switch. When i connect the LAP and the WLC to the switch along with the ADSL modem, the LAPs are getting the ip address from the ADSL modem, however they are not joining the WLC for further process.
    ADSL Modem ip address: 192.168.1.254
    Management ip address on the LAP: 192.168.1.1 ( Assigned to port 1, untagged Vlan).
    Ap Manager ip address: 192.168.1.1 ( Assigned to the same port i.e port1, Untagged Vlan).
    The LAP is getting an IP address from the ADSL modem in the range of the DHCP scope.
    I will paste the logs very soon.
    Please let me know if i am doing anything wrong oe what will be the issue.
    Thanks in advance,
    Mohammed Ameen

    Hello All,
    Please find the logs for  "debug capwap event" from the WLC below:
    *spamReceiveTask: Sep 26 19:44:59.196: e8:04:62:0a:3f:10 Join Version: = 117465600
    *spamReceiveTask: Sep 26 19:44:59.197: e8:04:62:0a:3f:10 Join resp: CAPWAP Maximum Msg element len = 92
    *spamReceiveTask: Sep 26 19:44:59.197: e8:04:62:0a:3f:10 Join Response sent to 192.168.1.156:45510
    *spamReceiveTask: Sep 26 19:44:59.197: e8:04:62:0a:3f:10 CAPWAP State: Join
    *spamReceiveTask: Sep 26 19:44:59.197: e8:04:62:0a:3f:10 capwap_ac_platform.c:1216 - Operation State 0 ===> 4
    *apfReceiveTask: Sep 26 19:44:59.198: e8:04:62:0a:3f:10 Register LWAPP event for AP e8:04:62:0a:3f:10 slot 0
    *spamReceiveTask: Sep 26 19:44:59.341: e8:04:62:0a:d1:20 DTLS connection not found, creating new connection for 192:168:1:158 (45644) 192:168:1:2 (5246)
    *spamReceiveTask: Sep 26 19:45:00.119: e8:04:62:0a:d1:20 DTLS Session established server (192.168.1.2:5246), client (192.168.1.158:45644)
    *spamReceiveTask: Sep 26 19:45:00.119: e8:04:62:0a:d1:20 Starting wait join timer for AP: 192.168.1.158:45644
    *spamReceiveTask: Sep 26 19:45:00.121: e8:04:62:0a:d1:20 Join Request from 192.168.1.158:45644
    *spamReceiveTask: Sep 26 19:45:00.123: e8:04:62:0a:d1:20 Join Version: = 117465600
    *spamReceiveTask: Sep 26 19:45:00.123: e8:04:62:0a:d1:20 Join resp: CAPWAP Maximum Msg element len = 92
    *spamReceiveTask: Sep 26 19:45:00.124: e8:04:62:0a:d1:20 Join Response sent to 192.168.1.158:45644
    *spamReceiveTask: Sep 26 19:45:00.124: e8:04:62:0a:d1:20 CAPWAP State: Join
    *spamReceiveTask: Sep 26 19:45:00.124: e8:04:62:0a:d1:20 capwap_ac_platform.c:1216 - Operation State 0 ===> 4
    *apfReceiveTask: Sep 26 19:45:00.125: e8:04:62:0a:d1:20 Register LWAPP event for AP e8:04:62:0a:d1:20 slot 0
    *spamReceiveTask: Sep 26 19:45:00.273: e8:04:62:0a:d1:20 Configuration Status from 192.168.1.158:45644
    *spamReceiveTask: Sep 26 19:45:00.273: e8:04:62:0a:d1:20 CAPWAP State: Configure
    *spamReceiveTask: Sep 26 19:45:00.273: Invalid channel 1 spacified for the AP APf866.f2ab.24b6, slotId = 0
    *spamReceiveTask: Sep 26 19:45:00.274: e8:04:62:0a:d1:20 Updating IP info for AP e8:04:62:0a:d1:20 -- static 0, 192.168.1.158/255.255.255.0, gtw 192.168.1.254
    *spamReceiveTask: Sep 26 19:45:00.274: e8:04:62:0a:d1:20 Updating IP 192.168.1.158 ===> 192.168.1.158 for AP e8:04:62:0a:d1:20
    *spamReceiveTask: Sep 26 19:45:00.274: e8:04:62:0a:d1:20 Setting MTU to 1485
    *spamReceiveTask: Sep 26 19:45:00.274: e8:04:62:0a:d1:20 Finding DTLS connection to delete for AP (192:168:1:158/45644)
    *spamReceiveTask: Sep 26 19:45:00.274: e8:04:62:0a:d1:20 Disconnecting DTLS Capwap-Ctrl session 0xa06d6a4 for AP (192:168:1:158/45644)
    *spamReceiveTask: Sep 26 19:45:00.274: e8:04:62:0a:d1:20 CAPWAP State: Dtls tear down
    *spamReceiveTask: Sep 26 19:45:00.277: spamProcessGlobalPathMtuUpdate: Changing Global LRAD MTU to 576
    *spamReceiveTask: Sep 26 19:45:00.277: e8:04:62:0a:d1:20 DTLS connection closed event receivedserver (192:168:1:2/5246) client 192:168:1:158/45644).
    The Acess point joins the Controller for 2-3 seconds and then unjoins again. I am not sure what i am doing wrong here. The access points are getting the IPs from the ADSL modem through the switch, then it talks to the WLC, however it does not join the controller for further process.
    Note:
    The Managemnet interface and the AP manager interface are assigned to the same port 1 with unassigned Vlan as mention above.

  • 1142LAP not joing the controller after conversion

    I have some remote 1142s that I converted to LAP last night.  They are not joing a WLC, but I they are online and I can ping them.  Telnet or SSH is disabled by default (WHY???). What can I do to figure out why these access points are not joining the controller?                  

    How are the APs getting IP address information and controller IP information?
    The APs have static IP addresses and should be getting controller IP info through DNS. There is an entry cisco-capwap-controller pointing to one of our WLCs and I can ping it from the switch where the AP is connected. I also have DHCP Option 43 setup should the LAP decide to relase its static IP and get a DHCP IP address.
    Your switch ports were probably configured as trunk ports. Have you changed them to access ports?
    The switchports were configured trunks. I've since changed one to an access port.
    Can the VLAN interface at the remote site ping the management interface of the controller?
    Not sure how to do this from the specific VLAN interface at the remote site.  I can ping the management interface from the switch that host the VLAN interfaces.
    What's the controller type and code?
    5508  ver 7.3.101.0
    Can you console into an AP, reboot it and capture the output and post it on here? I assume this will be a problem since they are remote.
    AP is in a remote location. YES THIS IS THE PROBLEM...
    I need to get several of these APs converted at several locations.  It's a roll of the dice with ever AP I try to convert.  Theres got to be an easier way that doesn't involve several road trips.

  • How do i ensure the new access point is joined the controller or not

    How do i ensure the new access point is joined the controller or not

    To Verifying that Access Points Join the Controller or not there are two ways as below.
    Please go through the step by step to find the APs joined state
    When replacing a controller, you need to make sure that access points join the new controller.
    Using the GUI to Verify that Access Points Join the Controller
    Follow these steps to ensure that access points join the new controller.
    Step 1 Follow these steps to configure the new controller as a master controller.
    a. Click Controller > Advanced > Master Controller Mode to open the Master Controller Configuration page.
    b. Check the Master Controller Mode check box.
    c. Click Apply to commit your changes.
    d. Click Save Configuration to save your changes.
    Step 2 (Optional) Flush the ARP and MAC address tables within the network infrastructure. Ask your network administrator for more information about this step.
    Step 3 Restart the access points.
    Step 4 Once all the access points have joined the new controller, configure the controller not to be a master controller by unchecking the Master Controller Mode check box on the Master Controller Configuration page.
    Using the CLI to Verify that Access Points Join the Controller
    Follow these steps to ensure that access points join the new controller.
    Step 1 To configure the new controller as a master controller, enter this command:
    config network master-base enable
    Step 2 (Optional) Flush the ARP and MAC address tables within the network infrastructure. Ask your network administrator for more information about this step.
    Step 3 Restart the access points.

  • LAP 2702 %CAPWAP-1-ARP_ERROR: Could not arp the controller ip address, retry later

    I am reusing one of the AP which was previously connected to WLC2504. 
    So I rename the AP and reconfigure the IP address to point to a new WLC8510. The AP and WLC is under same vlan 252.
    At first it has joined the new WLC but it keeps disconnected from wlc and reconnect again after awhile.
    AP is showing this error :
    %CAPWAP-1-ARP_ERROR: Could not arp the controller ip address, retry later
    My AP ip address is 172.16.54.171/23
    If i try to ping the ip from the same subnet, the AP has no timeout. but if I telnet into this AP and ping to wlc, it is intermittent. 
    Any idea what is the issue?

    Rasika,
    I have the same issue on my home 2504 with these 2700 UX, I have tried code 8.0.100.0, 8.0.110.0 (Docs say this is the min version supported), and even 8.0.115.0 (latest available) still no dice. The AP won't register, and gives the error stated above. I am seeing 2 images available for the AP, the AP shipped with the later image but  I AP recovery isn't working because it say's unable to find image with XX in the name? I see the TFTP logs, and name the file accordingly no dice, then the unable to find file name -XX pops up too. As you know I am busy during the day this week, but let's jump on a skype and take a look later maybe you have seen something I haven't?
    For good measure, also attempted to join a 3650 here at the house IOS-XE 3.6 no dice, going to try 3.7 too tomorrow, It worked for the 3700 UX AP's we had??

  • AIR-CAP3502I-E-K9 does not join preferred controller

    I have an AIR-CAP3502I-E-K9 AP that is configured for two WLAN controllers with preferred order. However the AP does not join the primary controller, but uses the secondary one instead. I have a bunch of these AIR-CAP3502I-E-K9s , majority work fine, but three of them not.
    I have tried commands according to
    https://supportforums.cisco.com/docs/DOC-24917
    In the controller's GUI  the order is properly configured. I also tried to use 'Clear All Config" option on the controller and configured the AP from the scratch, but this did not help.
    Here is what I have
    XXXX#sh capwap client config
    configMagicMark         0xF1E2D3C4
    chkSumV2                30883
    chkSumV1                1073
    swVer                   7.2.111.3
    adminState              ADMIN_ENABLED(1)
    name                    XXXX
    location                YYYY
    group name
    mwarName                ZZZZ1
    mwarIPAddress           192.168.1.1
    mwarName                ZZZZ2
    mwarIPAddress           192.168.1.2
    mwarName
    mwarIPAddress           0.0.0.0
    ssh status              Enabled
    Telnet status           Enabled
    numOfSlots              2
    spamRebootOnAssert      1
    spamStatTimer           180
    randSeed                0xBAC2
    transport               SPAM_TRANSPORT_L3(2)
    transportCfg            SPAM_TRANSPORT_DEFAULT(0)
    initialisation          SPAM_PRODUCTION_DISCOVERY(1)
    ApMode                  Local
    ApSubMode               Not Configured
    AP Rogue Detection Mode Enabled
    OfficeExtend AP         [0] Disabled
    OfficeExtend AP JoinMode[0] Standard
    Discovery Timer         10 secs
    Heart Beat Timer        30 secs
    Led State Enabled       1
    Primed Interval         0
    AP ILP Pre-Standard Switch Support Disabled
    AP Power Injector Disabled
    Infrastructure MFP validation Disabled
    Configured Switch 1 Addr 192.168.1.2
    Configured Switch 2 Addr 192.168.1.1
    non-occupancy channels:
    Ethernet (Duplex/Speed) auto/auto
    *Mar  1 00:14:23.001: %CAPWAP-3-ERRORLOG: Selected MWAR 'ZZZZ2'(index 1).
    *Mar  1 00:14:23.001: %CAPWAP-3-ERRORLOG: Go join a capwap controller
    *Aug 22 12:21:57.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.1.2 peer_port: 5246
    *Aug 22 12:21:57.581: %CAPWAP-5-DTLSREQSUCC: DTLS connection created sucessfully peer_ip: 192.168.1.2 peer_port: 5246
    *Aug 22 12:21:57.581: %CAPWAP-5-SENDJOIN: sending Join Request to 192.168.1.2
    My primary one is 192.168.1.1 and secondary is 192.168.1.2, but the AP joins always the secondary one.
    The lines above
    Configured Switch 1 Addr 192.168.1.2
    Configured Switch 2 Addr 192.168.1.1
    seem to be suspicious, I would expect the reverse order, but do not know how the code did it.
    The only guess is that in the very beginning the AP joined 192.168.1.2, and this was the controller I configured the AP initially from. The AP seems to maybe somehow remember this.
    OS version is
    swVer                   7.2.111.3
    Thanks,
    Vlad

    Yes, this is what I am trying all the time - configure the AP to point to the WLCs I want it to join.
    Firstly I did through GUI, did not work.
    Secondly I  used 'Clear All Config" option on the controller and configured the AP from the scratch through GUI, did not work.
    Thirdly I tried through command line on the AP, did not work.
    I used these commands
    XXXX#capwap ap  primary-base ZZZZ1 192.168.1.1
    XXXX#capwap ap  secondary-base ZZZZ2 192.168.1.2
    XXXX#sh capwap client config
    configMagicMark         0xF1E2D3C4
    chkSumV2                30883
    chkSumV1                1072
    swVer                   7.2.111.3
    adminState              ADMIN_ENABLED(1)
    name                    XXXX
    location                YYYY
    group name
    mwarName                ZZZZ1
    mwarIPAddress           192.168.1.1
    mwarName                ZZZZ2
    mwarIPAddress           192.168.1.2
    mwarName
    mwarIPAddress           0.0.0.0
    ssh status              Enabled
    Telnet status           Enabled
    numOfSlots              2
    spamRebootOnAssert      1
    spamStatTimer           180
    randSeed                0xBAC2
    transport               SPAM_TRANSPORT_L3(2)
    transportCfg            SPAM_TRANSPORT_DEFAULT(0)
    initialisation          SPAM_PRODUCTION_DISCOVERY(1)
    ApMode                  Local
    ApSubMode               Not Configured
    AP Rogue Detection Mode Enabled
    OfficeExtend AP         [0] Disabled
    OfficeExtend AP JoinMode[0] Standard
    Discovery Timer         10 secs
    Heart Beat Timer        30 secs
    Led State Enabled       1
    Primed Interval         0
    AP ILP Pre-Standard Switch Support Disabled
    AP Power Injector Disabled
    Infrastructure MFP validation Disabled
    Configured Switch 1 Addr 192.168.1.2
    Configured Switch 2 Addr 192.168.1.1
    non-occupancy channels:
    Ethernet (Duplex/Speed) auto/auto
    XXXX#sh log
    Syslog logging: enabled (1 messages dropped, 8 messages rate-limited,
                    0 flushes, 0 overruns, xml disabled, filtering disabled)
        Console logging: level debugging, 61 messages logged, xml disabled,
                         filtering disabled
        Monitor logging: level debugging, 0 messages logged, xml disabled,
                         filtering disabled
        Buffer logging: level debugging, 67 messages logged, xml disabled,
                        filtering disabled
        Logging Exception size (4096 bytes)
        Count and timestamp logging messages: disabled
        Trap logging: level emergencies, 0 message lines logged
            Logging to 255.255.255.255(global) (udp port 514, audit disabled,  link down), 0 message lines logged, xml disabled,
                   filtering disabled
    Log Buffer (1048576 bytes):
    *Mar  1 00:00:09.424: %SOAP_FIPS-2-SELF_TEST_IOS_SUCCESS: IOS crypto FIPS self test passed
    *Mar  1 00:00:09.434: *** CRASH_LOG = YES
    *Mar  1 00:00:09.434: 64bit PCIE devicesSecurity Core found.
    Base Ethernet MAC address: E0:5F:B9:A8:00:7F
    *Mar  1 00:00:12.482: %LINK-3-UPDOWN: Interface GigabitEthernet0, changed state to up
    *Mar  1 00:00:13.731: %SOAP_FIPS-2-SELF_TEST_RAD_SUCCESS: RADIO crypto FIPS self test passed on interface Dot11Radio 0
    *Mar  1 00:00:13.797: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0, changed state to up
    *Mar  1 00:00:16.996: %SOAP_FIPS-2-SELF_TEST_RAD_SUCCESS: RADIO crypto FIPS self test passed on interface Dot11Radio 1
    *Mar  1 00:00:17.052: %LWAPP-3-CLIENTEVENTLOG: Read and initialized AP event log (contains, 1024 messages)
    *Mar  1 00:00:17.068:  status of voice_diag_test from WLC is false
    *Mar  1 00:00:19.182: %SYS-5-RESTART: System restarted --
    Cisco IOS Software, C3500 Software (AP3G1-K9W8-M), Version 12.4(25e)JA2, RELEASE SOFTWARE (fc1)
    Technical Support: http://www.cisco.com/techsupport
    Copyright (c) 1986-2012 by Cisco Systems, Inc.
    Compiled Fri 14-Sep-12 19:13 by prod_rel_team
    *Mar  1 00:00:19.182: %SNMP-5-COLDSTART: SNMP agent on host XXXX is undergoing a cold start
    *Mar  1 00:13:33.342: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to reset
    *Mar  1 00:13:33.342: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset
    *Mar  1 00:13:33.493:  status of voice_diag_test from WLC is false
    *Mar  1 00:13:33.632: %SSH-5-ENABLED: SSH 2.0 has been enabledlwapp_crypto_init: MIC Present and Parsed Successfully
    *Mar  1 00:13:33.956: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0, changed state to up
    *Mar  1 00:13:34.343: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to down
    *Mar  1 00:13:34.343: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to down
    *Mar  1 00:13:36.029: %LINEPROTO-5-UPDOWN: Line protocol on Interface BVI1, changed state to up
    *Mar  1 00:13:41.484: %DHCP-6-ADDRESS_ASSIGN: Interface BVI1 assigned DHCP address 192.168.1.21, mask 255.255.255.0, hostname XXXX
    *Mar  1 00:13:51.981: Logging LWAPP message to 255.255.255.255.
    *Mar  1 00:14:01.997: %CAPWAP-3-ERRORLOG: Did not get log server settings from DHCP.
    *Mar  1 00:14:06.099: %CDP_PD-4-POWER_OK: Full power - NEGOTIATED inline power source
    *Mar  1 00:14:07.190: %LINK-3-UPDOWN: Interface Dot11Radio1, changed state to up
    *Mar  1 00:14:08.191: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to up
    *Mar  1 00:14:08.288: %LINK-3-UPDOWN: Interface Dot11Radio0, changed state to up
    *Mar  1 00:14:09.289: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to up
    *Mar  1 00:14:11.000: %CAPWAP-3-ERRORLOG: Could Not resolve CISCO-CAPWAP-CONTROLLER
    *Mar  1 00:14:23.001: %CAPWAP-3-ERRORLOG: Selected MWAR 'ZZZZ2'(index 1).
    *Mar  1 00:14:23.001: %CAPWAP-3-ERRORLOG: Go join a capwap controller
    *Aug 23 06:07:13.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.1.2 peer_port: 5246
    *Aug 23 06:07:13.578: %CAPWAP-5-DTLSREQSUCC: DTLS connection created sucessfully peer_ip: 192.168.1.2 peer_port: 5246
    *Aug 23 06:07:13.578: %CAPWAP-5-SENDJOIN: sending Join Request to 192.168.1.2
    *Aug 23 06:07:14.025: %LINK-3-UPDOWN: Interface Dot11Radio0, changed state to down
    *Aug 23 06:07:14.091: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset
    *Aug 23 06:07:14.094: %CAPWAP-5-JOINEDCONTROLLER: AP has joined controller ZZZZ2
    *Aug 23 06:07:14.154: %LINK-3-UPDOWN: Interface Dot11Radio0, changed state to up
    What I think might be the key to the problem is this
    Configured Switch 1 Addr 192.168.1.2
    Configured Switch 2 Addr 192.168.1.1
    This is not changing no matter what I do.
    Thanks,
    Vlad

  • AP 3702 not join the WLC

    Hi,
    I have two WLC 8500 working in SSO and with nat enable feature configure in management interface.
    SSO is working, but i have to configure NAT before SSO becasuse when SSO is up, ip address and nat are greyed out in managemente interface.
    Some AP's must join the controller in the private address of the management interface and others AP must join in the public ip address configured in NAT address. 
    for some reason, there are a lot of AP's that can't join the controller, i have 3 ap's joined in the public ip address and 3 ap's joined in the private ip address
    config network ap-discovery nat-only disable is already configured, from the console of one AP that can't not join i see the following:
    *Sep 10 12:32:48.115: %CAPWAP-3-ERRORLOG: Selected MWAR 'GI12WLC001A'(index 0).
    *Sep 10 12:32:48.115: %CAPWAP-3-ERRORLOG: Go join a capwap controller
    *Sep 10 12:35:48.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 212.89.5.130 peer_port: 5246
    *Sep 10 12:36:17.999: DTLS_CLIENT_ERROR: ../capwap/base_capwap/dtls/base_capwap_dtls_connection_db.c:2176 Max retransmission count reached!
    *Sep 10 12:36:47.999: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 212.89.5.130:5246
    *Sep 10 12:36:47.999: %CAPWAP-3-ERRORLOG: Selected MWAR 'GI12WLC001A'(index 0).
    *Sep 10 12:36:47.999: %CAPWAP-3-ERRORLOG: Go join a capwap controller
    *Sep 10 12:35:48.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 10.35.0.78 peer_port: 5246
    the AP is trying both private and public ip address to join the WLC but can't join properly.
    From the WLC console:
    debug capwap errors enable:
    *spamApTask4: Sep 10 13:13:49.837: 00:10:db:ff:50:06 Discarding non-ClientHello Handshake OR DTLS encrypted packet from  10.35.1.13:47807)since DTLS session is not established 
    *spamApTask3: Sep 10 13:13:49.958: 1c:6a:7a:5b:e0:30 ApModel: AIR-CAP3702I-E-K9
    *spamApTask3: Sep 10 13:13:49.958: Unknown AP type. Using Controller Version!!!
    *spamApTask3: Sep 10 13:13:49.958: Unknown AP type. Using Controller Version!!!
    *spamApTask3: Sep 10 13:13:49.958: 1c:6a:7a:5b:e0:30 ApModel: AIR-CAP3702I-E-K9
    *spamApTask3: Sep 10 13:13:49.958: Unknown AP type. Using Controller Version!!!
    *spamApTask3: Sep 10 13:13:49.958: Unknown AP type. Using Controller Version!!!
    *spamApTask2: Sep 10 13:13:52.103: 00:10:db:ff:50:06 Discarding non-ClientHello Handshake OR DTLS encrypted packet from  10.35.1.11:21207)since DTLS session is not established 
    *spamApTask1: Sep 10 13:13:52.224: 1c:6a:7a:5e:0f:10 ApModel: AIR-CAP3702I-E-K9
    *spamApTask1: Sep 10 13:13:52.224: Unknown AP type. Using Controller Version!!!
    *spamApTask1: Sep 10 13:13:52.224: Unknown AP type. Using Controller Version!!!
    *spamApTask1: Sep 10 13:13:52.224: 1c:6a:7a:5e:0f:10 ApModel: AIR-CAP3702I-E-K9
    *spamApTask1: Sep 10 13:13:52.224: Unknown AP type. Using Controller Version!!!
    *spamApTask1: Sep 10 13:13:52.224: Unknown AP type. Using Controller Version!!!
    the AP model are the same, this is not the problem, but for some reason there are AP's that have problems with the NAT configuration, if i disable NAT option, every AP with private ip address config can join the WLC.
    I've tried to break SSO, desconfigure NAT, and private ip address AP join the controller without problem.
    anybody can give me a clue?
    Regards!

    it seens like DTLS connection can't be stablished between AP and WLC.
    The AP sends discovery request
    the WLC respond with two discovery responds, the firts one, contains the public ip address of the WLC and the second one contains the private ip address.
    once discovery proccess is complete, the AP tries to send DTLS hello packet to the WLC, but this packet never arrives to WLC.
    because hello doesn't arrive, the AP sends a close notify alert to the WLC and tries to send the DTLS hello packet to the WLC private address with same result.
    the AP get into a loop trying to send DTLS hello packets to both private and public address.
    DTLS hello packet never arrive, but close notify alert arrive to WLC.
    theres is FW in the middle doing NAT, but i can understand why close notify alert packets error arrives WLC and Hello DTLS packets don't. this packets uses the same protocol UDP and the same port.
    Regards

  • AP1242 Not joining 4404 controller

    Hi all
    Can anyone please help, my 1242 access points will not join my controller, I have done a debug and can see the Access point sending a discovery request, then the controller says discovery request sent, but then nothing happens, any ideas what this could be? I can ping the AP fine.
    cheers
    Carl

    There are a number of things that could cause the join request to not show up.  If there are no other controllers that the AP could be sending its join request to check to make sure there isn't a duplicate IP with your AP manager interface.  Next if you are running LAG make sure the port-channel load-balancing on the switch that the controller is connected to is set to src-dst-ip.

  • Lap not joining over a wan link

    hi
    i have 2 wism running on 6509 chassis and i have access points in remote branches. the lap is not joining the wism. here is the situation:
    lap can ping the controllers
    lap is getting ip address
    option 43 is there on the vlan
    dns entry for the wlc is there.
    however, when i checked the lap boot: it s getting an ip address and gives the command prompt.
    the below debugging on the wlc gives nothing:
    debug capwap events
    debug capwap errors
    debug mac addr <mac addr>
    the wan link is private wan running ospf on both routers from each end.
    I see no point why this lap is not joining
    any idea?

    Hi,
    According to your description, I understand that all attachments in Outlook are opened slowly since updating Outlook 2003 to 2013. Please confirm whether all users encounter this issue. Also check whether the issue continues in cached mode and in OWA.
    Based on your post, I suggest we can try to disable the following add-ins to check whether the issue persists:
    Acrobat PDFMaker office com addin
    symantec endpoint protection outlook addin
    If there is any updates, please feel free to let us know.
    Thanks,
    Winnie Liang
    TechNet Community Support

  • AP is unable to associate. The Regulatory Domain '-E' configured on interface '802.11a' does not match the Controller Regulatory Domain '-C'

    Hi,
    There are three different types of APs associated with controller and working fine.
    1.       AIR-LAP1252AG-E-K9
    2.       AIR-LAP1522AG-E-K9
    3.       AIR-CAP1552E-C-K9
    WLC is AIR-CT5508-K9. Software version is 7.4.100.0. Field Recovery Image is 7.0.112.21. Firmware version is FPGA 1.7, Env 1.8, USB console 2.2. WCS is 7.0.240.0 for Windows.
    WCS is sending alarms for AIR-LAP1522AG-E-K9:
    Message: AP is unable to associate. The Regulatory Domain '-E' configured on interface '802.11a' does not match the Controller Regulatory Domain '-C'.
    Before Controller was 7.2.4 (not sure).
    Country configured on WLC is AE and shows -CE regulatory domain. Mesh APs are also associated.
    I believe this Critical alarm should not come.
    how much is this alarm important? What should be done to resolve this?

    Typically you still need to make sure that the country codes are indeed configured on the WLC. Thing can change when you upgrade code as standards might of changed and regulations also. If your AP's are functional, then you should be okay and I wouldn't worry too much about it, but if after the upgrade, the WLC complains about country code stuff, then you just need to verify that the AP's country code is defined on the WLC. May times the AP will not join and if it does join, the radios might be disabled or in a down status.
    Sent from Cisco Technical Support iPad App

  • Our service upgraded to 4g but now my Mac computer will not join the network, It sees the network but will not join

    Our service just upgraded to 4g. Now my Mac computer will not join the network. It "sees" the network but will not "join"

        Hi Hojo38,
    That's not good! What happens when you attempt to make the connection? Do you receive an error message? What device is the computer making a connection to? Send details please.
    Thanks,
    PamelaF_VZW
    Tweet us @vzwsupport

  • Workstations not Joining the Domain after OSD

    I have a sporadic problem happening in my Environment.   OSD Deployments for the most part finish successful , workstation joins the domain with no issues.   At certain locations  occasionally the workstation does not join the
    domain.     Have you seen this happen before?  are there logs on the DC or DP which might explain why this is happening?

    While you are at it grab setupact.log and setuperr.log from two locations, c:\windows\panther and c:\windows\panther\unattendGC. These logs will give more details on why the domain join fails.
    Daniel Ratliff | http://www.PotentEngineer.com
    Also take a look at C:\Windows\debug\NetSetup.log.
    Cheers
    Paul | sccmentor.wordpress.com

  • Why can I not join the wifi in the hotel when I am out of the country UK with data roaming turned off, Why can I not join the wifi in the hotel when I am out of the country UK with data roaming turned off

    Why can I not join the wi fi in the hotel on my I.phone using iso7 ???? I have turned off data roaming any ideas?????

    is it free or do you have to sign up and pay and is there a password
    Havee you asked the hotel ???

Maybe you are looking for

  • Airplay doesn't fit screen! (pictures included)

    I've just installed a new 1080p projector and connected my iPad 3 to it. When using Apples standard VGA Adapter the iPad fills the whole screen on the projector, see picture: https://www.dropbox.com/s/mqhpyrfv6d7omgn/VGA.JPG But when im connecting an

  • Parked document could not be posted 00 S 349 BSEG-BEWAR

    Hello Friends , Users have parked Journal entries which has vendor , customer and GL line items . the documents were getting posted through workflow till sometime back . suddenly  , we have started to get the error message as    " Parked document cou

  • Lion OS keeps crashing after the update...

    Hi. I upgraded to Lion yesterday but since then the system keeps crashing (that grey screen asking for manually reboot the system). I believe it happnes only when itunes is playing... Can someone please help me with this? Thanks. here is the report:

  • ORA-01017: invalid username/password;

    Hi there, I have set up an Inbound Data Exchange Session so that my program can send alerts to be displayed on OEM(Oracle Enterprise Manager), as specified in http://download-uk.oracle.com/docs/cd/B16240_01/doc/em.102/b32521/em_data_ex.htm. I have su

  • User exit to change the storage section indicator (MLVS-LGBKZ)

    Hi. I'm looking for a user exit which be able to change the storage section indicator (field MLVS-LGBKZ) proposed by the material master data in the process of creating a TO (transaction LT06). I haven't found any user exit for this. Do you know any