One AP cannot join WLC after configured with static ip address

One ap 1140 can join wlc4402 but ap 3500 cannot join. Both ap are configured with the same config except its ip address via console. Please see below:

AP1140#sho capwap ip config
LWAPP Static IP Configuration
IP Address         10.10.10.100  
IP netmask         255.255.255.0  
Default Gateway    10.10.10.10    

AP3500#show capwap ip config
LWAPP Static IP Configuration
IP Address         10.10.10.201  
IP netmask         255.255.255.0  
Default Gateway    10.10.10.10    
Primary Controller 10.10.10.11

And below message is from AP3500 console. Is there certificate issue?

*Feb 24 18:01:09.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 10.10.10.2 peer_port: 5246
*Feb 24 18:01:09.088: %PKI-3-CERTIFICATE_INVALID_EXPIRED: Certificate chain validation has failed.  The certificate (SN: 6F2E8AB40000001E29EA) has expired.    Validity period ended on 12:52:22 UTC Jul 10 2017
*Feb 24 18:01:09.091: %LWAPP-3-CLIENTERRORLOG: Peer certificate verification failed
*Feb 24 18:01:09.091: %CAPWAP-3-ERRORLOG: Certificate verification failed!
*Feb 24 18:01:09.091: DTLS_CLIENT_ERROR: ../capwap/capwap_wtp_dtls.c:348 Certificate verified failed!
*Feb 24 18:01:09.091: %DTLS-4-BAD_CERT: Certificate verification failed. Peer IP: 10.10.10.2
*Feb 24 18:01:09.091: %DTLS-5-SEND_ALERT: Send FATAL : Bad certificate Alert to 10.10.10.2:5246
*Feb 24 18:01:09.091: %DTLS-3-BAD_RECORD: Erroneous record received from 10.10.10.2: Malformed Certificate
*Feb 24 18:01:09.091: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 10.10.10.2:5246
*Feb 24 18:01:09.091: %CAPWAP-3-ERRORLOG: Invalid event 38 & state 3 combination.

(WLC-1) >show interface summary

Interface Name                   Port Vlan Id  IP Address      Type    Ap Mgr Guest
-------------------------------- ---- -------- --------------- ------- ------ -----
ap-manager                       2    10       10.10.10.2      Static  Yes    No  
management                       2    10       10.10.10.11     Static  No     No
eemoonAsked:
Who is Participating?
 
Craig BeckCommented:
Ok at the WLC CLI try this...

config ap lifetime-check mic enable
0
 
Craig BeckCommented:
What version of code is on your AP and WLC?
0
 
eemoonAuthor Commented:
Thank you so much for your fast reply.
WLC version is 7.0.252.0
AP 3500 is LWAPP image version 7.0.112.74
AP 1140 is LWAPP image version 7.0.252.0
0
On-Demand: Securing Your Wi-Fi for Summer Travel

Traveling this summer?Check out our on-demand webinar to learn about the importance of Wi-Fi security and 3 easy measures you can start taking immediately to protect your private data while using public Wi-Fi. Follow us today to learn more!

 
eemoonAuthor Commented:
Below is what I did, but I have not seen it take effect yet

(WLC-1) >config ap lifetime-check mic enable
Expire MIC Mode allow is already configured.
0
 
Craig BeckCommented:
Have a look through this then...

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuu02970/?referring_site=bugquickviewredir

You may be hitting that bug.
0
 
eemoonAuthor Commented:
Thank you! It began to work after changing time. even after changing time back to normal, it still works well!
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.