cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1712
Views
0
Helpful
5
Replies

AP not showing up WLC

danwilko16
Level 1
Level 1

Hi I am trying to setup a WLAN for the first time but the WAP does not show up in the WLC. This is error I am getting from the  WAP. I can ping the WLC from the WAP and vice versa. 

 

*Oct 10 14:54:52.085: %LWAPP-3-CLIENTERRORLOG: Peer certificate verification failed
*Oct 10 14:54:52.085: %CAPWAP-3-ERRORLOG: Certificate verification failed!
*Oct 10 14:54:52.085: DTLS_CLIENT_ERROR: ../capwap/capwap_wtp_dtls.c:348 Certificate verified failed!
*Oct 10 14:54:52.085: %DTLS-4-BAD_CERT: Certificate verification failed. Peer IP: 192.168.1.3
*Oct 10 14:54:52.085: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to 192.168.1.3:5246
*Oct 10 14:54:52.086: %DTLS-3-BAD_RECORD: Erroneous record received from 192.168.1.3: Malformed Certificate
*Oct 10 14:54:52.086: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 192.168.1.3:5246
*Oct 10 14:54:52.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.1.3 peer_port: 5246
*Oct 10 14:54:52.085: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed. The certificate (SN: 18EB5605000000263235

5 Replies 5

Scott Fella
Hall of Fame
Hall of Fame
You need to provide more details. What controller model and image version, what ap model? Are there any aps joined? Also provide the show version and show inventory from the ap. Make sure the time is set on the controller. You should also post the output from the console of the ap while booting up the ap.
-Scott
*** Please rate helpful posts ***

Controller 2100 series. Image version 6.0.196.0. AP model AIR-LAP1142N-E-K9. This is the only AP I have.

 

Show version ---

Cisco IOS Software, C1140 Software (C1140-K9W8-M), Version 12.4(23c)JA2, RELEASE SOFTWARE (fc3)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2011 by Cisco Systems, Inc.
Compiled Wed 13-Apr-11 12:50 by prod_rel_team

ROM: Bootstrap program is C1140 boot loader
BOOTLDR: C1140 Boot Loader (C1140-BOOT-M) Version 12.4(23c)JA, RELEASE SOFTWARE (fc3)

AP003a.99eb.61f8 uptime is 27 minutes
System returned to ROM by power-on
System image file is "flash:/c1140-k9w8-mx.124-23c.JA2/c1140-k9w8-mx.124-23c.JA2"


This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

----

AP003a.99eb.61f8#show inventory
NAME: "AP1140", DESCR: "Cisco Aironet 1140 Series (IEEE 802.11n) Access Point"
PID: AIR-LAP1142N-E-K9 , VID: V04, SN: FCZ1526W482

----

This is what happens as soon as the AP is booted up. 

*Oct 11 09:30:42.164: %LINK-3-UPDOWN: Interface Dot11Radio0, changed state to up
*Oct 11 09:30:42.176: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to reset
*Oct 11 09:30:42.190: %LINK-3-UPDOWN: Interface Dot11Radio1, changed state to up
*Oct 11 09:30:52.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.1.3 peer_port: 5246
*Oct 11 09:30:52.000: %CAPWAP-5-CHANGED: CAPWAP changed state to
*Oct 11 09:30:52.085: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed. The certificate (SN: 18EB5605000000263235) has expired. Validity period ended on 01:21:08 UTC Jun 1 2020
*Oct 11 09:30:52.086: %LWAPP-3-CLIENTERRORLOG: Peer certificate verification failed
*Oct 11 09:30:52.086: %CAPWAP-3-ERRORLOG: Certificate verification failed!
*Oct 11 09:30:52.086: DTLS_CLIENT_ERROR: ../capwap/capwap_wtp_dtls.c:348 Certificate verified failed!
*Oct 11 09:30:52.086: %DTLS-4-BAD_CERT: Certificate verification failed. Peer IP: 192.168.1.3
*Oct 11 09:30:52.086: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to 192.168.1.3:5246
*Oct 11 09:30:52.087: %DTLS-3-BAD_RECORD: Erroneous record received from 192.168.1.3: Malformed Certificate
*Oct 11 09:30:52.087: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 192.168.1.3:5246

 

 - https://www.cisco.com/c/en/us/support/docs/field-notices/639/fn63942.html

 However the particular ap-model is also very old. Consider using a more modern ap

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Wow... that is a very old controller! You have the compatibility matrix that marce has already posted. What you also need to know is that you need to be able to download software, which requires a support contract. If you don’t have a contract, these devices are useless. So look at the matrix and see what code you ap requires and then look at if the 2100 supports that code or not. If it’s not compatible, then there is nothing you can do. Find a 2504 on eBay if you really want to have a controller for cheap. Again, you need to be able to obtain the image which is not free.
-Scott
*** Please rate helpful posts ***

marce1000
VIP
VIP

 

 - Check compatibility parameters (ap-model. controller-model . software versions, ....)  with :

            https://www.cisco.com/c/en/us/td/docs/wireless/compatibility/matrix/compatibility-matrix.html

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '
Review Cisco Networking for a $25 gift card