Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Can't join "AIR-CAP3502I-E-K9" to WLC 5508

Dear my friends 

According to my last project I would like to setup the wireless LAN in my office that it could be the most changeable project that I have ever had. There fore, I would be appreciated to answer my question in this interesting way. as far as, my devises that I used in this project were  

1- WLC 5508

2-AIR-CAP3502I-E-K9

3-Switch WS-C3750X-24P

However, CAPWAP could not joined to WLC and it faced to this log "Erroneous record received from 192.168.10.2: Duplicate (replayed) record" in AP.

Additionally, the other  obstacle is a error log that is on WLC in which  "regulatory domain check has failed for the AP ".

Lastly. I have attached my config .I look forward to hearing form you soon. 

regards 

************************************************

************************************************

3750#show run
Building configuration...

Current configuration : 4138 bytes
!
version 12.2
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname 3750
!
boot-start-marker
boot-end-marker
!
enable secret 5 $1$aiSC$XuJiuR5usmC5V.xvrluf10
!
!
!
no aaa new-model
switch 1 provision ws-c3750x-24p
system mtu routing 1500
ip routing
ip dhcp excluded-address 192.168.5.0 192.168.5.100
!
ip dhcp pool mypool1
   network 192.168.5.0 255.255.255.0
   domain-name lab.com
   dns-server 192.168.10.4
   default-router 192.168.5.1
   option 60 ascii Cisco AP c3500
   option 43 hex f104.c0a8.0a02
!
!
!
!
crypto pki trustpoint TP-self-signed-3391407104
 enrollment selfsigned
 subject-name cn=IOS-Self-Signed-Certificate-3391407104
 revocation-check none
 rsakeypair TP-self-signed-3391407104
!
!
crypto pki certificate chain TP-self-signed-3391407104
 certificate self-signed 01
  3082023D 308201A6 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
  31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
  69666963 6174652D 33333931 34303731 3034301E 170D3933 30333031 30303031
  31395A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
  4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 33393134
  30373130 3430819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
  8100B86E CDA0B7D2 F5826CF4 2963CD3F EE26B03C 05C7F82D 9B32E144 BE5DBBBB
  B993D6E6 790DDC91 4D5F5652 C752C736 9F073D5B F13DC187 92A19EA7 5610AFC9
  D1506787 F0BF6B76 E36D0197 2C59CC37 9AC53A9E EF9AABC6 06B61A4C 6C21F51F
  F2E1FE96 2ED596E4 815AA981 2B16BAE5 0D820827 D46B19C9 0C1EB502 B7D9713A
  B3290203 010001A3 65306330 0F060355 1D130101 FF040530 030101FF 30100603
  551D1104 09300782 05333735 302E301F 0603551D 23041830 1680142E D4354E3E
  3B62BA82 E8C2C4A7 8462DD3E 2CF47E30 1D060355 1D0E0416 04142ED4 354E3E3B
  62BA82E8 C2C4A784 62DD3E2C F47E300D 06092A86 4886F70D 01010405 00038181
  0040B92A 2F62A1A5 3E189315 912656FE 71C90DE0 D464C042 081DDA7B B8B7689B
  3ABBD561 CF07D10D F7F8A46D AFF01DE3 A65BFA73 4C46BFE0 EE403942 1BB317CD
  4FF64A1F 6FC3B256 E4091F62 F4EB71A5 84CF58B8 38CB75D4 BBB1DE68 0848B616
  41175CAB 1CD2BE8C 95B17215 A9ABDCC7 DEAA4757 1AF93263 C4A83597 4DA1FE0B C0
  quit
spanning-tree mode pvst
spanning-tree extend system-id
!
!
!
!
vlan internal allocation policy ascending
!
!
!
interface FastEthernet0
 no ip address
 no ip route-cache cef
 no ip route-cache
 no ip mroute-cache
!
interface GigabitEthernet1/0/1
 description connect to WLC
 switchport trunk encapsulation dot1q
 switchport trunk native vlan 10
 switchport trunk allowed vlan 5,10
 switchport mode trunk
!
interface GigabitEthernet1/0/2
 description connect to AP
 switchport access vlan 5
 switchport mode access
!
interface GigabitEthernet1/0/3
!
interface GigabitEthernet1/0/4
!
interface GigabitEthernet1/0/5
!
interface GigabitEthernet1/0/6
!
interface GigabitEthernet1/0/7
!
interface GigabitEthernet1/0/8
!
interface GigabitEthernet1/0/9
!
interface GigabitEthernet1/0/10
!
interface GigabitEthernet1/0/11
!
interface GigabitEthernet1/0/12
!
interface GigabitEthernet1/0/13
!
interface GigabitEthernet1/0/14
!
interface GigabitEthernet1/0/15
!
interface GigabitEthernet1/0/16
!
interface GigabitEthernet1/0/17
!
interface GigabitEthernet1/0/18
!
interface GigabitEthernet1/0/19
!
interface GigabitEthernet1/0/20
!
interface GigabitEthernet1/0/21
!
interface GigabitEthernet1/0/22
!
interface GigabitEthernet1/0/23
!
interface GigabitEthernet1/0/24
 description connect to PC
 switchport access vlan 10
 switchport mode access
!
interface GigabitEthernet1/1/1
!
interface GigabitEthernet1/1/2
!
interface GigabitEthernet1/1/3
!
interface GigabitEthernet1/1/4
!
interface TenGigabitEthernet1/1/1
!
interface TenGigabitEthernet1/1/2
!
interface Vlan1
 no ip address
!
interface Vlan5
 ip address 192.168.5.1 255.255.255.0
!
interface Vlan10
 description managment Vlan
 ip address 192.168.10.1 255.255.255.0
!
ip classless
ip http server
ip http secure-server
!
ip sla enable reaction-alerts
!
!
end

*************************************************

2 ACCEPTED SOLUTIONS

Accepted Solutions
Hall of Fame Super Gold

"regulatory domain check has

"regulatory domain check has failed for the AP ".

This means your WLC is configured for a different set of countries and your AP is designed for a different set of countries (like Europe) and they are in direct conflict.  

 

You need to resolve this because regulatory domain mismatch is the most common causes of APs not joining the WLC.

Gold

Hi,Couple of things to check

Hi,

Couple of things to check here.

 

1) Check if you are able to ping the AP ip address from WLC

2) Make sure the time is set on the WLC and matches with AP

3) Make sure the WLC country code matches that of AP country code.

4) Access the AP through console and run the command "capwap ap controller ip address x.x.x.x"

Hope that helps.

Regards

Najaf

7 REPLIES
Hall of Fame Super Gold

"regulatory domain check has

"regulatory domain check has failed for the AP ".

This means your WLC is configured for a different set of countries and your AP is designed for a different set of countries (like Europe) and they are in direct conflict.  

 

You need to resolve this because regulatory domain mismatch is the most common causes of APs not joining the WLC.

Gold

Hi,Couple of things to check

Hi,

Couple of things to check here.

 

1) Check if you are able to ping the AP ip address from WLC

2) Make sure the time is set on the WLC and matches with AP

3) Make sure the WLC country code matches that of AP country code.

4) Access the AP through console and run the command "capwap ap controller ip address x.x.x.x"

Hope that helps.

Regards

Najaf

VIP Purple

paste the output of these

paste the output of these commands:

from WLC: sh sysinfo

From AP: sh version

 

 

Regards

New Member

HI dear NajafThank you for

HI dear Najaf

Thank you for your answer and time, 

I would like to ask you it possible to check the first item but it's notice that my AP's mod is LWAP then it is not possible to put my command ( number 4). actually, I should say that I had access to the AP through console  

Gold

Hi Jack,Are you saying that

Hi Jack,

Are you saying that point number 1 (ping to AP from WLC) is working and you are not able to try point number 4?

What version of IOS you are using on WLC? Also share "sh sysinfo" from WLC

Do you get any error when you try point 4? If capwap ap controller ip address x.x.x.x is not working you could try "lwap ap controller ip address x.x.x.x"

Let us know show it goes?

Regards

Najaf

New Member

Hi Dear my friends

Hi Dear my friends 

fortunately, I have returned and checked all the points that you referred and I could solve this obstacle as well as possible. Therefore, I would be appreciated for your time and help specially my good friend Najaf. I like to say that my problem have been solved by correction of WLC's regional.

Regards

Jack    

Gold

Hi Jack,Glad to here that

Hi Jack,

Glad to hear that things are working fine now and thanks for marking the answer as correct.

Regards

Najaf

741
Views
10
Helpful
7
Replies