Sizing number of SFP ports on the WLC

Any comments on determining how many SFP ports should be utilized on a 4404? The hard limit appears to be no more the 48 APs are allowed per SFP port on the WLC. More pertinent, has anyone loaded up 48 APs per port on the WLC and what has been the result in terms of performance?
In the Cisco WCS/WLC class, the rule-of-thumb given was to light up one SFP for every 24 access points.
Some of the factors that I am thinking of that would impact this number are that we are intending to run only 802.11b/g (no 802.11a). That should cut the expected bandwidth coming from the APs in half (almost, not accounting for LWAP control traffic).
Does anyone happen know what the LWAP control traffic bandwidth is (between each AP and WLC) - or at least a rule of thumb to use?
Again, if you have run 48 APs on a single port, have there been any performance issues? Were you running both 802.11a and b/g?
Thanks.

There is an imposed limitation of 48 APs per port on any 440x platform to mitigate against oversubscription based on an assumption of ~20MB per AP. Obviously, dual-mode Cisco APs are capable of handling over double that in good RF environments. So take your environment, applications, and what kind of tolerance for oversubscription you have into account.
To scale beyond 48 ports, you have 2 options:
1. Use LAG on the controller
2. Use multiple AP Manager interfaces (each assigned to a different port)
I usually recommend you go with option 1 if possible, if only because it's simpler. The WLC handles the load-balancing of traffic across the ports dynamically.
For (2), keep in mind that LWAPP will dynamically load balance the APs across the AP managers. So be careful because you're still statically mapping your dynamic WLAN interfaces to a port on the WLC. The traffic has to go in and go out of the controller so you could potentially oversubscribe a port.

Similar Messages

  • Number of LAN ports on the router

    What is the best way of extebnding the number of ports on the router? Every router has like 4 LAN ports so is using the switch option for extending it so you can have more ports?

    there is this one but it looks very expensive.....its almost the price of the router itself..
    http://www.tigerdirect.ca/applications/SearchTools/item-details.asp?EdpNo=2424193&csid=_61

  • How to change the Number of IVR ports in a UCCX?

    I know this question has been asked before but it needs to be asked again, as previous answers do not seem to apply.   The simple quesiton is:  If you have a UCCX and if after install you check you check License information and you note that you have 150 IVR ports; how do you increase the number of ports to 300?  
    I have been told that the number of ports is set by the class of the machine hardware and is not a license issue.   Others have suggested it is a license issue?   At the end of the day, however, I want a step by step procedure for adding more IVR ports to my deployment.   Even if that means buying more licenses (though I can not find a SKU).
    I have several clients that have UCCX and are having calls that exceed the number of IVR ports.   Before we get into a discussion of CTI ports or Call Controll Groups, let me identify that I think they are the same.    I can create a CTI Call Control Group with 300 paths, but if I only have 150 IVR ports I am in serious trouble on the 151 call!
    I had a lab system that installed under vmware with 150 ports.  No matter how I tried to configure the CVA it always came up 150 ports!   I added a NFR license to my lab and magically it turned it into a 12 IVR system, so licensing does have something to do with it!  
    I have htis experience on Version 8 and now on Version 9!   I need more IVR ports than appear in the installation.  I want to know exactly the steps needed to increase the number of IVR ports to the maxium of 300 for an enhanced system!
    I can refer CISOC TAC to several tickets I have opened on this subject all with unsatisactory answers!  Most recently 626743961
    Peter Buswell (aka DrVoIP)
    http://blog.drvoip.com       

    Here's the long answer
    Peter Buswell wrote:I know this question has been asked before but it needs to be asked again, as previous answers do not seem to apply.   The simple quesiton is:  If you have a UCCX and if after install you check you check License information and you note that you have 150 IVR ports; how do you increase the number of ports to 300?  
    Since I see below that you mentioned that the system in question is Enhanced, the answer is simply, install on faster hardware.  Presently the best hardware you can get is VMWare ESXi with the 400 Agent License OVA, which gives you 400 IVR Port Licenses.
    Standard licensing works the same as Enhanced, as far as IVR Port licenses go.
    If you were wondering about Premium, then it's a 1:2 ratio of agent:ports.  You cannot buy Premium ports directly, instead you buy them indirectly through the process of buying Premium Agent seats.  So if you had a Premium UCCX with 100 Agents, you would have 200 ports, and if you desired to have 250 ports, you simply buy 25 more Premium Agent seats.  Premium does still need to adhere to the hardware limits.  I have seen partners sell someone an Enhanced UCCX which gave them 300 ports, but they only had like 50 Agents.  A year later, the customer upgraded to Premuim, but only bought 50 seats, and thus downgraded their port license count to 100.  A third of what they had!  The solution?  Buy 100 more Premium Agent seats so your total goes up to 150 Agents, and thus your ports go up to 300.
    Peter Buswell wrote:I have been told that the number of ports is set by the class of the machine hardware and is not a license issue.   Others have suggested it is a license issue?
    These are both correct statements.  Just remember, that it's licensed based first for Premium, then hardware limited.  Standard and Enhanced are hardware limited only.
    Peter Buswell wrote:At the end of the day, however, I want a step by step procedure for adding more IVR ports to my deployment.   Even if that means buying more licenses (though I can not find a SKU).
    Again, for Standard and Enhanced, you need to move to bigger/better hardware to get more ports, assuming you're not already at the meximum of 400.
    Here is the document which walks you through moving to bigger hardware: Disaster Recovery Guide
    And for Premium, you need to purchase the SKU for a Premium Agent Seat license.  It's a 1:2 ratio for agents:ports.
    Peter Buswell wrote:I have several clients that have UCCX and are having calls that exceed the number of IVR ports.
    I'm not a partner, nor in sales, but I thought there was an A2Q process which validates CC designs for sales people.  At any rate, it sounds like they were either under sized or outgrew their overhead, and something needs to be done.
    Sometimes you can simply dump excess calls off.  Think about playing a high call volume message to callers and then drop them.
    Other times you can drop them into voicemail, and come back to it later.
    I've seen some basic call back functionality implemented with an external data source, which could alleviate ports.
    Lastly, I've seen improperly designed scripts which loop on themselves or other scripts, causing a high port usage.
    My point is that there's a few options here, outside of simply increasing the size of the server or purchasing new licenses.  There's no one size fits all answer though.
    Peter Buswell wrote:Before we get into a discussion of CTI ports or Call Controll Groups, let me identify that I think they are the same.
    Are you saying that CTI Ports and Call Control Groups are the same?  Or that CTI Ports/CCG's are the same as IVR Port Licenses?  Cause the former is true, while the latter is not.  Think "oversubscribed" CTI Ports.
    Sometimes it is advantageous to oversubscribe your CTI Ports, to achieve a more dynamic environment.  E.g., I have 100 ports, and all 100 are used for inbound calls.  I develope a single inbound app, which is limited to 10 ports, and handles small bursts of calls.  What happens is that, if the new inbound app is running, the most it can "steal" from the inbound calls is 10 ports.  However, if the app is not running (because it doesn't run all day, it's mostly bursty in nature), I can still have my regular inbound calls go all the way up to 100.
    Peter Buswell wrote:I can create a CTI Call Control Group with 300 paths, but if I only have 150 IVR ports I am in serious trouble on the 151 call!
    This is true.  Again, you need to decide if you really need the extra ports, of if there is some solution to solving this problem without making a hardware/license purchase.  These kinds of problems still exist for customers at the 400 port level, and they don't have the option to "buy more."
    Well, that's not entirely true.  While you cannot grow past the 400 port limit today, you could install another UCCX instance on the same CUCM cluster, effectively doubling your capacity, but breaking your administration into two separate domains.
    Peter Buswell wrote:I had a lab system that installed under vmware with 150 ports.  No matter how I tried to configure the CVA it always came up 150 ports!
    What's CVA?
    Peter Buswell wrote:I added a NFR license to my lab and magically it turned it into a 12 IVR system, so licensing does have something to do with it!  
    The NFR is most likely a Premium license.  Refer back to the 1:2 ratio, and that would tell me you have an NFR license for 6 Premium Agents.  Installing a higher level license on a lower level licensed system brings the whole system up to the higher level.  Recall my partner story about the Enhanced to Premium upgrade scenario.
    Peter Buswell wrote:I have htis experience on Version 8 and now on Version 9!
    The licensing doesn't change from 8x to 9x.
    Peter Buswell wrote:I need more IVR ports than appear in the installation.  I want to know exactly the steps needed to increase the number of IVR ports to the maxium of 300 for an enhanced system!
    You buy bigger/better hardware, and use the link I provided above for moving to that new hardware.
    Peter Buswell wrote:I can refer CISOC TAC to several tickets I have opened on this subject all with unsatisactory answers!  Most recently 626743961
    I would be surprised if there is a single Cisco TAC person who doesn't understand this simply IVR Port licensing model.  Perhaps there was some miscommunication about what was being asked, and what answer was being given.
    I hope that helped to clarify some things for you.  Also, if you are a partner, reach out to your CAM and ask for a one on one with a UCCX guru who can sit down with you.  Cisco would want you to be successful with selling their products.
    Anthony Holloway
    Please use the star ratings to help drive great content to the top of searches.

  • SG500X-24 Switch SFP ports

    Hi,
    i have a question about the max number of sfp ports available on the SG500X-24 Switch. I need to configure a Stack with 2 SG500X-24 units: can i use 5G ports and have 4 SFP as network ports. In the quick start guide i read that i can use i couple for stack and only 1 couple of ports for standard network, while around Internet i read different. So my question is: can i use all the 6 SFP ports of the switches? 2 5G ports for stacking and 4 SFP ports for normal network operation ?
    Thank you,
    Roberto

    Hi Rob, the switch has 4 10 gig ports. There is also 2 5 gig ports. The 5 gig ports are combo ports meaning you can use either xg3 and xg4 OR the 5g ports.
    -Tom
    Please mark answered for helpful posts

  • CGS-2520-16S-8PC only half of SFP Ports forwarding Traffic

    HI all,
    we have two CGS-2520-16S-8PC with links in different directions. All SFP Ports are UP but only the half of it forwarding Traffic. We need all Ports .
    In one of the Cisco documents I found this hind : "The100BASE-FX SFP ports and the 10/100 PoE ports are grouped in pairs. The first member of the pair (port 1) is above the second member (port 2) on the left. Port 3 is above port 4, and so on. The dual-purpose ports are numbered 1 and 2. "
    But more about it is not found in the documemnts. So i have no clue how to bring all Ports to forward traffic.
    Have some one an idea ?
    Philipp

    Sorry but a gigabit-only transceiver will not work on 100 Mbps-only SFP ports.
    There's almost always a good reason why something is not listed in the compatibility table.

  • C2960S switches reset SFP+ ports hourly

    We have several C2960S switches that seem to reset their uplink SFP+ ports at the same time each hour. It looks like it's only a brief reset but any Cisco phones we have attached to these switches will lose their connectivity to our Subscriber and reset. Has anyone else seen this? We are running iOS 15.2(2a)E1 due to a different error we were having (%ENTROPY errors), and Cisco TAC recommended we upgrade to the latest code. I included a "sho log" to demonstrate what I'm talking about. The interface in question is Gi1/0/49 which has a GLC-T in it that uplinks to our Data Center switches.

    I see you have 2960s, but there is know bug for the 2960-X series regarding GLC-T and other SFPs.
    So, this maybe effecting your switch as well but not sure.
    here is the bug id and link:
    CSCur56395
    https://tools.cisco.com/bugsearch/bug/CSCur56395/?reffering_site=dumpcr
    HTH

  • SFP Port Disabled?

    Hi I have a link between:
    Switch A (3750G PS48)
    and
    Switch B (2 stacked 3750G TS24)
    These are connected via fiber through their SFP ports using the SFP GLC-SX-MM tranceivers.
    On Switch A, one of the SFP ports (poort 50) indicates that it is disabled from the Cisco Device Manager web page and it is showing an amber light.
    On switch B, both SFP ports have green LEDs.
    Any ideas on how to enable this port?

    Not able to do a show interface "port" for ports 49 and 50 (dont know why). Is it because these are SFP ports?
    Anyway, I did a show interface and shown below is the output for 49 and 50. 49 is showing greed, while 50 is amber:
    GigabitEthernet1/0/49 is up, line protocol is up (connected)
    Hardware is Gigabit Ethernet, address is 0016.c7f7.a831 (bia 0016.c7f7.a831)
    MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec,
    reliability 255/255, txload 1/255, rxload 1/255
    Encapsulation ARPA, loopback not set
    Keepalive not set
    Full-duplex, 1000Mb/s, link type is auto, media type is 1000BaseSX SFP
    input flow-control is off, output flow-control is unsupported
    ARP type: ARPA, ARP Timeout 04:00:00
    Last input 00:00:01, output 00:00:17, output hang never
    Last clearing of "show interface" counters never
    Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
    Queueing strategy: fifo
    Output queue: 0/40 (size/max)
    5 minute input rate 1000 bits/sec, 1 packets/sec
    5 minute output rate 1000 bits/sec, 1 packets/sec
    83696 packets input, 15488039 bytes, 0 no buffer
    Received 46220 broadcasts (0 multicast)
    0 runts, 0 giants, 0 throttles
    0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
    0 watchdog, 30403 multicast, 0 pause input
    0 input packets with dribble condition detected
    162927 packets output, 71484021 bytes, 0 underruns
    0 output errors, 0 collisions, 5 interface resets
    0 babbles, 0 late collision, 0 deferred
    0 lost carrier, 0 no carrier, 0 PAUSE output
    0 output buffer failures, 0 output buffers swapped out
    GigabitEthernet1/0/50 is up, line protocol is up (connected)
    Hardware is Gigabit Ethernet, address is 0016.c7f7.a832 (bia 0016.c7f7.a832)
    MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec,
    reliability 255/255, txload 1/255, rxload 1/255
    Encapsulation ARPA, loopback not set
    Keepalive not set
    Full-duplex, 1000Mb/s, link type is auto, media type is 1000BaseSX SFP
    input flow-control is off, output flow-control is unsupported
    ARP type: ARPA, ARP Timeout 04:00:00
    Last input 00:00:00, output 00:00:23, output hang never
    Last clearing of "show interface" counters never
    Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
    Queueing strategy: fifo
    Output queue: 0/40 (size/max)
    5 minute input rate 0 bits/sec, 0 packets/sec
    5 minute output rate 0 bits/sec, 0 packets/sec
    118803 packets input, 9003642 bytes, 0 no buffer
    Received 118281 broadcasts (0 multicast)
    0 runts, 0 giants, 0 throttles
    0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
    0 watchdog, 113959 multicast, 0 pause input
    0 input packets with dribble condition detected
    29254 packets output, 10447720 bytes, 0 underruns
    0 output errors, 0 collisions, 1 interface resets
    0 babbles, 0 late collision, 0 deferred
    0 lost carrier, 0 no carrier, 0 PAUSE output
    0 output buffer failures, 0 output buffers swapped out
    Any ideas?

  • ASR 9001 SFP+ ports compatibility

    Hi,
    will the SFP+ ports on the 9001 chassis support a 1 Gbps SFP?
    which one?
    Thanks a lot.
    Regards,
    J

    Hi Jordi,
    The ports only do 10Gbps.
    For 1Gbps you will need the 20x1GE MPA.
    Thanks,
    Sam

  • Virtual WLC Ports Confusion -or- ADDING ports to the vWLC

    I am a struggling with configuring a virtual wireless controller (vWLC).
    I am working with the newest vWLC, 8.0.100.0
    I currently own an elderly 2504 WLC with 4 ports. (four physical interfaces on the box)
    On this 2504, I use one port for the management of the WLC and for WLC to communicate with the APs.
    The APs are on the same network as the 2504. The other port is the interface that all my wireless traffic from the clients use.
    Now with this vWLC, the virtual machine has two network interface, but once I get to a point that I am able to login to the vWLC, I only see one 'port'. According to this posting, I am suppose to take the service port and point it too a dummy virtual switch or a 'Black Hole' https://supportforums.cisco.com/document/12098556/vwlc-getting-started-key-points-and-common-issues.
    Okay, I've done this and it works, but it not what I am accustomed to.
    I enjoy having the web console of the WLC and the AP on separate networks from the wireless clients.
    To complicate things my desire is for this new vWLC and my 2504 to work together.
    I want over time to migrate APs from the 2504 to the vWLC without re-addressing them.
    Can I add "ports" to my vWLC controller? Do I need to rethink my wireless infrastructure?
    I am confused and am seeking your help, advice, suggestions, opinions and flames.
    Bryan Smith
    Butler, Indiana

    I think you need to re-look at your wireless design. I would prefer the 2504 over a vWLC, but that's me. I would not of separated the ports also on the WLC.  No real reason to, to be honest. Keep AP's on a seperate subnet and the traffic to and from the WLC is tunneled using capwap. Breaking up ports was an old design to be honest and that was also done back them with the 4400's. You have to also look at the pro's and con's of FlexConnect AP's vs local mode.  I never create an ap manager interface on the newer WLC's. I have always kept the dynamic ap manager in the managemt. Traffic is tunneled and you control user traffic when it leaves the WLC. 
    Scott

  • Can the number of ethernet ports be increased from 3?

    Clearly I know that we cant weld another port onto the airport extreme but, I have 5 devices I need to run through the wireless network and the box only has 3. Is there any way to increase this number with perhaps a splitter or some add on device? All 5 will never be active at the same time but, the thought of having to go behind the port daily and swap out cables is not an option. THX

    Will the ports enabled by this product also be capable of "n" speeds if I purchase the new N router?
    Sounds like you got wireless and wired a bit mixed up. The Ethernet (wired) ports on the AirPort Extreme Base Station (AEBS) are rated at 10/100 Mbps. The AEBS's wireless is 802.11a/b/g/(pre-n)-compliant...meaning that theoretically it can handle speeds from 11 Mbps to 540 Mbps.
    Adding an Ethernet switch to one of the AEBS's 10/100 Mbps Ethernet ports, will only provide 10/100 Mbps throughput, not 802.11n speeds.
    Anything that is a little more aesthetically pleasing than that big blue box? Anyone else make such a device?
    Linksys has several other models, as well as, Belkin, D-Link, & Netgear (to name a few).

  • Configuring a 5508 via the SFP ports

    Is there anyway to configure a 5508 via the SFP ports?  Or do you have to use the service port for autoinstall or NCS auto provisioning?  It looks like it grabs a DHCP address but it doesn't seem to like telnet,ssh ,http or https.  There isn't anyone onsite.

    Thanks,  I got it figured out.  The 5508 was plugged up to a switch that was configured for lag (for the 5508 that was hooked up before).  I changed the port channel to put the native vlan on one that hands out DHCP.  The blank 5508 grabbed an ip but wasn't working.  I ended up disabling the other ports connecting to the 5508.  I defaulted the switchport that was connected to the 5508's SFP port 1 and put it in the right access vlan.  I was then able to ping the IP it grabbed and http in to it.
    thanks though!

  • What is the minimal number of open ports needed to use forms apps

    Hi,
    Our network administrators are doing a network segmentation / security project and they want to make it so that only authorized users can ping or see my oracle EBS server on the network, but they also want to lock down all ports that users can see, except for port 8000, which is the port we use to serve EBS on apache. I am having an argument with them. Because we use forms in socket mode, I am arguing that we need to keep all ports open because forms uses a port range and creates a socket with the users's PC in addition to holding/maintaining the Apache connection. My network administrator is saying no, it holds the socket connection in the background and they only need "access" to port 8000. I would agree with them if I was using servlet mode, but I don't think they are correct in socket mode. What port range do I need to make sure they allow through in addition to port 8000? BTW we use all the standard ports in EBS (eg 8000 is the out-of-the-box Apache port). Note also we have have single tier 11.5.10.2 installation on a solaris sparc server, so the ports that the 11i apps needs to interact / connect with itself is not relevant to the question. Also, the IT group (me) will still have access to all ports to do telnet, ssh, ping etc, we are only talking about from our end users's PCs. They are telling me to install Wireshark to find out more, and do some testing which I will - but I want to know what to expect.
    Thanks Marv

    Hussein,
    Ok I have read the above documentation extensively. One thing that is quite clear is that if I switched to servlet mode, then all traffic goes through the Apache port (in my case 8000) and that would be the only port users need access too -- and this would be like setting up a DMZ or firewall inside the intranet. However, given that I am having performance issues, I need to know how to do this using forms in socket mode.
    So for example in MOS 414439.1 it lists the entire ports and port pools. So I've taken that list, and separated it into groups One and Two (see below). My question is: To access EBS in the intranet by users, which of the ports in Group One is needed? And are all of the ports in group Two NOT needed? thanks in advance. Marv.
    Group One of Port Pool
    Web Listener Port s_webport      8000 ---> this is needed for sure.
    Forms Listener Port s_formsport 9000 -------> this seems to be needed for sure.
    Forms Servlet Port Range      s_forms_servlet_portrange      18000-18009 --> is this needed in socket mode?
    Forms Start Port      s_frmStartPort      20000 --> is this needed?
    Group Two of Port Pool - I believe that users do not need to have access to these ports for EBS, even
    in forms socket mode..
    Database Port      s_dbport      1521      
    RPC Port      s_rpcport      1626      
    Reports Port      s_repsport      7000      
    OPROC Manager Port      s_oprocmgr_port      8100
    Web PLSQL Port      s_webport_pls      8200
    Servlet Port      s_servletport      8800      
    Metrics Server Data Port      s_metdataport      9100      
    Metrics Server Req. Port      s_metreqport      9200
    JTF Fulfillment Server Port      s_jtfuf_port      9300      
    iMeeting Collaboration Server Port      s_imtsrvport      9500      
    iMeeting Recording Server Port      s_imtrecport      9600      
    iMeeting Monitor (iMon) Port      s_imtimonport      9700      
    Map Viewer Servlet Port      s_mapviewer_port      9800      
    OEM Web Utility Port      s_oemweb_port      10000
    VisiBroker OrbServer Agent Port      s_osagent_port      10100      
    MSCA Server Port      s_mwaPortNo      10200      
    MSCA Dispatcher Port      s_mwaDispatcherPort      10300      
    TCF Port      s_tcfport      15000      
    OACORE Servle Port Range      s_oacore_servlet_portrange      16000-16009      
    Discoverer Servlet Port Range      s_disco_servlet_portrange      17000-17009           
    XMLSVCS Servlet Port Range      s_xmlsvcs_servlet_portrange      19000-19009      
    Java Object Cache Port      s_java_object_cache_port      12345      
    -- end of port pool list--

  • Can you expand the number of LAN ports the Time Capsule has?

    I have a recently purchased a Time Capsule and am wondering if you could use something like a splicer to add more LAN ports to the device.

    You can install a Gigabit Ethernet switch to add as many ports as you need. Switches come in 5-port, 8-port, 16-port etc. varieties.
    Why a switch and not a hub?  A switch will deliver full bandwidth to each connected device. A hub will divide or split up the bandwidth to connected devices.
    Any electronics / computer superstore will have models to choose from. Recommended brands are Netgear and Cisco, among others.

  • Link Problem with port 2 in WLC 4402

    Hi,
    I have a problem with port 2 in Wireless Lan Controler 4402. The problem is that the distribution port 2 of the WLC not link with the switch (3750). We receive the WLC and we follow the autostart wizard and we enable LAG. The wizard finish, I restart the system and all works fine. The two distribution ports of WLC, 1 and 2 appears UP and the LAG works correctly. After this we upgrade the firmware of the WLC to the version AIR-WLC4400-k9-6-0-182-0.aes and we restart the system again but at this time port 2 does not link and port 1 link OK. We do not know the reason why port 2 doesn´t link? Could you help me ?
    Thank in advance.
    Regards.

    Does it properly refuse authentication ? Or does the login page stop appearing or something ?
    There was a bug with the webauth dying under heavy load, regardless of number of identical accounts used.
    One good way for you to check would be, when problem occurs, to create a second backup guest user and see if that would start working. If it doesn't, the account is not the problem.
    I'm not aware of any maximum of usage of the same account.
    Which 4.2 exactly are you running ?

  • How to join the AP to the WLC

    Hi All,
    I am new to Cisco wireless solution and would like to ask how to add the AP to the WLC properly. All Cisco 1041 and Cisco 2500 WLC are new. I connect those AP and WLC to the switch without any VLAN tag and the AP can gain the IP address from our DHCP correctly. However, the AP 1041 could not join the WLC successfully. Here is the log. I really do not have any idea about that and hope someone can help. Many thanks.
    WLC: Cisco 2500
    IP Address: 192.168.1.225
    version: 7.4.100.0
    AP: 1041
    IP Address (DHCP): 192.168.1.195
    version: 15.2(2)JB
    I also checked the following item.
    - WLC already enable Accept Manufactured Installed Certificate (MIC) in WLC -> Security -> AP Policy
    - WLC can ping AP and vice versa
    - WLC has 5 AP license
    - All configuration are default setting
    - Tried to issued join command in AP manually but no luck "lwapp ap controller ip add 192.168.1.225"
    AP 1041 Log
    *May 16 14:02:41.145: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to administratively down*May 16 14:02:41.180: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to up*May 16 14:02:42.145: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to down*May 16 14:02:42.172: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to down*May 16 14:02:42.176: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset*May 16 14:02:43.197: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to up*May 16 14:02:44.197: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to up*May 16 14:02:51.178: %CAPWAP-3-ERRORLOG: Go join a capwap controller *May 16 14:02:52.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.1.225 peer_port: 5246*May 16 14:02:52.905: %CAPWAP-5-DTLSREQSUCC: DTLS connection created sucessfully peer_ip: 192.168.1.225 peer_port: 5246*May 16 14:02:52.906: %CAPWAP-5-SENDJOIN: sending Join Request to 192.168.1.225
    *May 16 14:02:52.908: %CAPWAP-3-ERRORLOG: Invalid event 10 & state 5 combination.*May 16 14:02:52.908: %CAPWAP-3-ERRORLOG: CAPWAP SM handler: Failed to process message type 10 state 5.*May 16 14:02:52.909: %CAPWAP-3-ERRORLOG: Failed to handle capwap control message from controller*May 16 14:02:52.909: %CAPWAP-3-ERRORLOG: Failed to process encrypted capwap packet from 192.168.1.225., 1)16 14:03:11.059: %CAPWAP-3-ERRORLOG: Retransmission count for packet exceeded max(UNKNOWN_MESSAGE_TYPE (5)*May 16 14:03:11.059: %CAPWAP-3-ERRORLOG: GOING BACK TO DISCOVER MODE*May 16 14:03:11.060: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 192.168.1.225:5246*May 16 14:03:11.111: %LWAPP-3-CLIENTERRORLOG: LWAPP LED Init: incorrect led state 255*May 16 14:03:11.111: bsnInitRcbSlot: slot 1 has NO radio*May 16 14:03:11.132: %CAPWAP-3-ERRORLOG: Binding Config Initialization failed for binding 1*May 16 14:03:11.138: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to administratively down*May 16 14:03:11.174: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to up*May 16 14:03:12.138: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to down*May 16 14:03:12.165: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to down*May 16 14:03:12.170: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset*May 16 14:03:13.190: %LINK-6-UPDOWN: Interface Dot11Radio0, changed state to up*May 16 14:03:14.190: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to up
    APbc16.65d6.7e4b#show ip int briefInterface                  IP-Address      OK? Method Status                ProtocolBVI1                       192.168.1.195   YES DHCP   up                    up      Dot11Radio0                unassigned      NO  unset  up                    up      GigabitEthernet0           unassigned      NO  unset  up                    up      GigabitEthernet0.1         unassigned      YES unset  up                    up     
    WLC 2500
    (Cisco Controller) >show sysinfoManufacturer's Name.............................. Cisco Systems Inc.Product Name..................................... Cisco ControllerProduct Version.................................. 7.4.100.0Bootloader Version............................... 1.0.16Field Recovery Image Version..................... 1.0.0Firmware Version................................. PIC 16.0Build Type....................................... DATA + WPSSystem Name...................................... S_HK_AC_CT2504_1System Location.................................. System Contact................................... System ObjectID.................................. 1.3.6.1.4.1.9.1.1279IP Address....................................... 203.85.90.225Last Reset....................................... Power on resetSystem Up Time................................... 1 days 0 hrs 29 mins 1 secsSystem Timezone Location......................... System Stats Realtime Interval................... 5System Stats Normal Interval..................... 180
    (Cisco Controller) >show ap join stats summary allNumber of APs.............................................. 3 Base Mac             AP EthernetMac       AP Name                 IP Address         Statusbc:16:65:d6:7e:40    bc:16:65:d6:7e:40    APbc16.65d6.7e4b        192.168.1.195      Not Joinedbc:16:65:d6:7e:4b    N A                  N A                     192.168.1.195      Not Joinedf4:1f:c2:d0:bb:20    bc:16:65:d6:7e:4b    APbc16.65d6.7e4b        192.168.1.195      Not Joined
    (Cisco Controller) >show interface summary Number of Interfaces.......................... 3Interface Name                   Port Vlan Id  IP Address      Type    Ap Mgr Guest-------------------------------- ---- -------- --------------- ------- ------ -----management                       1    untagged 192.168.1.225   Static  Yes    No   virtual                          N/A  N/A      1.1.1.1         Static  No     No  
    Rgds,
    Jacky

    leolaohoo wrote:Something is missing from the output to the command "sh sysinfo".  What country code did you enable? On the AP, post the output to the command "sh version" and "sh inventory".
    Hi Leolaohoo, thanks for your prompt reply. Please it below. I am using Hong Kong as the country code in WLC. Thanks.
    WLC
    (Cisco Controller) >show sysinfoManufacturer's Name.............................. Cisco Systems Inc.Product Name..................................... Cisco ControllerProduct Version.................................. 7.4.100.0Bootloader Version............................... 1.0.16Field Recovery Image Version..................... 1.0.0Firmware Version................................. PIC 16.0Build Type....................................... DATA + WPSSystem Name...................................... S_HK_AC_CT2504_1System Location.................................. System Contact................................... System ObjectID.................................. 1.3.6.1.4.1.9.1.1279IP Address....................................... 192.168.1.225Last Reset....................................... Power on resetSystem Up Time................................... 1 days 1 hrs 15 mins 49 secsSystem Timezone Location......................... System Stats Realtime Interval................... 5System Stats Normal Interval..................... 180--More-- or (q)uitConfigured Country............................... HK  - Hong KongOperating Environment............................ Commercial (0 to 40 C)Internal Temp Alarm Limits....................... 0 to 65 CInternal Temperature............................. +31 CExternal Temperature............................. +36 CFan Status....................................... 4100 rpmState of 802.11b Network......................... DisabledState of 802.11a Network......................... DisabledNumber of WLANs.................................. 2Number of Active Clients......................... 0Memory Current Usage............................. UnknownMemory Average Usage............................. UnknownCPU Current Usage................................ UnknownCPU Average Usage................................ UnknownBurned-in MAC Address............................ F0:29:29:88:98:20Maximum number of APs supported.................. 5
    AP
    APbc16.65d6.7e4b#show verCisco IOS Software, C1040 Software (C1140-K9W8-M), Version 15.2(2)JB, RELEASE SOFTWARE (fc1)Technical Support: http://www.cisco.com/techsupportCopyright (c) 1986-2012 by Cisco Systems, Inc.Compiled Tue 11-Dec-12 04:03 by prod_rel_teamROM: Bootstrap program is C1040 boot loaderBOOTLDR: C1040 Boot Loader (C1140-BOOT-M) Version 12.4(23c)JA6, RELEASE SOFTWARE (fc1)APbc16.65d6.7e4b uptime is 20 hours, 32 minutesSystem returned to ROM by reloadSystem image file is "flash:/c1140-k9w8-mx.152-2.JB/c1140-k9w8-mx.152-2.JB"Last reload reason: This product contains cryptographic features and is subject to UnitedStates and local country laws governing import, export, transfer anduse. Delivery of Cisco cryptographic products does not implythird-party authority to import, export, distribute or use encryption.Importers, exporters, distributors and users are responsible forcompliance with U.S. and local country laws. By using this product youagree to comply with applicable laws and regulations. If you are unableto comply with U.S. and local laws, return this product immediately.A summary of U.S. laws governing Cisco cryptographic products may be found at:http://www.cisco.com/wwl/export/crypto/tool/stqrg.htmlIf you require further assistance please contact us by sending email [email protected] AIR-LAP1041N-E-K9    (PowerPC405ex) processor (revision B0) with 81910K/49152K bytes of memory.Processor board ID FGL1718S4RMPowerPC405ex CPU at 333Mhz, revision number 0x147ELast reset from reloadLWAPP image version 7.4.100.01 Gigabit Ethernet interface1 802.11 Radio32K bytes of flash-simulated non-volatile configuration memory.Base ethernet MAC Address: BC:16:65:D6:7E:4BPart Number                          : 73-14034-06PCA Assembly Number                  : 800-34273-07PCA Revision Number                  : A0PCB Serial Number                    : FOC17160EPLTop Assembly Part Number             : 800-34284-05Top Assembly Serial Number           : FGL1718S4RMTop Revision Number                  : A0Product/Model Number                 : AIR-LAP1041N-E-K9   Configuration register is 0xF
    APbc16.65d6.7e4b#show inventoryNAME: "AP1040", DESCR: "Cisco Aironet 1040 Series (IEEE 802.11n) Access Point"PID: AIR-LAP1041N-E-K9 , VID: V05, SN: FGL1718S4RM
    Thanks and Best Regards,
    Jacky

Maybe you are looking for