<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco CAPWAP AP stuck in Discovery in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-capwap-ap-stuck-in-discovery/m-p/412980#M92902</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/121123"&gt;@KevinJB&lt;/a&gt;&amp;nbsp;I'm having the same issue you're describing over SDWAN on a PA-220. Were you able to get it working?&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jun 2021 14:42:17 GMT</pubDate>
    <dc:creator>joseph.chen</dc:creator>
    <dc:date>2021-06-14T14:42:17Z</dc:date>
    <item>
      <title>Cisco CAPWAP AP stuck in Discovery</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-capwap-ap-stuck-in-discovery/m-p/406669#M92140</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone had problems with CAPWAP AP's separated from the WLC by a PA-220 firewall get stuck in a DISCOVERY OperationState?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;show capwap client rcb&lt;BR /&gt;AdminState : ADMIN_ENABLED&lt;BR /&gt;OperationState : DISCOVERY&lt;BR /&gt;Name : ***&lt;BR /&gt;SwVer : 8.5.151.0&lt;BR /&gt;HwVer : 1.0.0.0&lt;BR /&gt;MwarApMgrIp : 10.1.1.2&lt;BR /&gt;MwarName : CISCO-LWAPP-CONTROLLER&lt;BR /&gt;MwarHwVer : 0.0.0.0&lt;BR /&gt;Location : ***&lt;BR /&gt;ApMode : FlexConnect&lt;BR /&gt;ApSubMode : Not Configured&lt;BR /&gt;CAPWAP Path MTU : 1421&lt;BR /&gt;CAPWAP UDP-Lite : Enabled&lt;BR /&gt;IP Prefer-mode : IPv4&lt;BR /&gt;AP Link DTLS Encryption : OFF&lt;BR /&gt;AP TCP MSS Adjust : Enabled&lt;BR /&gt;AP TCP MSS size : 1250&lt;BR /&gt;LinkAuditing : disabled&lt;BR /&gt;Efficient Upgrade State : Disabled&lt;BR /&gt;Flex Group Name : ***&lt;BR /&gt;AP Group Name : default-group&lt;BR /&gt;Cisco Trustsec Config&lt;BR /&gt;AP Inline Tagging Mode : Disabled&lt;BR /&gt;AP Sgacl Enforcement : Disabled&lt;BR /&gt;AP Override Status : Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I do a clear session all filter source &amp;lt;IP of AP&amp;gt; the AP will shortly come online again so it does appear to be the PA220 that's causing the problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;show capwap client rcb&lt;BR /&gt;AdminState : ADMIN_ENABLED&lt;BR /&gt;OperationState : UP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even when the AP is offline I can ping the WLC just fine and interestingly if I add application capwap to the clear session filter it doesn't come back up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We did create an application-override rule for the capwap traffic but that hasn't helped and since clearing on the capwap session doesn't help and there isn't any other session from that IP I am very confused.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for any suggestions will also open a TAC case but they seem to take so long to respond these days with COVID and all.&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 00:57:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-capwap-ap-stuck-in-discovery/m-p/406669#M92140</guid>
      <dc:creator>KevinJB</dc:creator>
      <dc:date>2021-05-14T00:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco CAPWAP AP stuck in Discovery</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-capwap-ap-stuck-in-discovery/m-p/406682#M92142</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/121123"&gt;@KevinJB&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You honestly shouldn't even need an application-override entry to keep this operational and have it identified properly. CAPWAP is easily enabled solely by setting the application as capwap and setting the service to application-default without any sort of override in place. You aren't performing any sort of NAT on the traffic are you?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 02:49:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-capwap-ap-stuck-in-discovery/m-p/406682#M92142</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-05-14T02:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco CAPWAP AP stuck in Discovery</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-capwap-ap-stuck-in-discovery/m-p/407391#M92229</link>
      <description>&lt;P&gt;Nope, there is no NAT occurring to this traffic, it gets back to the WLC via a IPSec SDWAN Tunnel. Interestingly from the debugs it would appear the WLC is receiving the join from the client, it's the reply that never makes it back to the AP. Also since this was usually affecting one AP in particular I tried shutting down that one AP yesterday, but the problem just reoccurred on a different AP later that day.&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 22:12:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-capwap-ap-stuck-in-discovery/m-p/407391#M92229</guid>
      <dc:creator>KevinJB</dc:creator>
      <dc:date>2021-05-17T22:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco CAPWAP AP stuck in Discovery</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-capwap-ap-stuck-in-discovery/m-p/407687#M92248</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/121123"&gt;@KevinJB&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;So if the CAPWAP join request doesn't get a response that AP should sit there and continue to try and restart that CAPWAP discovery and join process repeatedly. Is the WLC not responding to any of those further join requests? I would take a capture from the WLC and see if it's responding to those join requests at all or not.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 01:47:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-capwap-ap-stuck-in-discovery/m-p/407687#M92248</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-05-19T01:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco CAPWAP AP stuck in Discovery</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-capwap-ap-stuck-in-discovery/m-p/412980#M92902</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/121123"&gt;@KevinJB&lt;/a&gt;&amp;nbsp;I'm having the same issue you're describing over SDWAN on a PA-220. Were you able to get it working?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 14:42:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-capwap-ap-stuck-in-discovery/m-p/412980#M92902</guid>
      <dc:creator>joseph.chen</dc:creator>
      <dc:date>2021-06-14T14:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco CAPWAP AP stuck in Discovery</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-capwap-ap-stuck-in-discovery/m-p/413131#M92930</link>
      <description>&lt;P&gt;Exact same situation, we had to create an application override:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVLCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVLCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;create an objects -&amp;gt; applications called capwap-override&lt;/P&gt;&lt;P&gt;Under Advanced Tab, Scanning untick all (maybe default?) - file types, viruses and data patterns&lt;/P&gt;&lt;P&gt;and then under policies -&amp;gt; application override create:&lt;/P&gt;&lt;P&gt;capwap-override&lt;/P&gt;&lt;P&gt;Source Zone: name of zone your AP's are in&lt;/P&gt;&lt;P&gt;Destination Zone:&amp;nbsp;zone-to-hub&lt;/P&gt;&lt;P&gt;Destination Address: IP of WLC&lt;/P&gt;&lt;P&gt;Protocol/Application:&lt;/P&gt;&lt;P&gt;UDP&lt;/P&gt;&lt;P&gt;Port: 5246-5247&lt;/P&gt;&lt;P&gt;Application:&amp;nbsp;capwap-override&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However after this we are still having some weird issues with wireless but having difficulty nailing down if they are related to connection reliability or more widespread so keen to hear back on your experience after making these changes.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 00:52:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-capwap-ap-stuck-in-discovery/m-p/413131#M92930</guid>
      <dc:creator>KevinJB</dc:creator>
      <dc:date>2021-06-15T00:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco CAPWAP AP stuck in Discovery</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-capwap-ap-stuck-in-discovery/m-p/413591#M92996</link>
      <description>&lt;P&gt;Thanks for the information.&amp;nbsp; Since the issue for us only started after we added a 2nd internet circuit, on the SDWAN policy, we classified CAPWAP&amp;nbsp; traffic to use a Top Down traffic distribution profile instead of best availability and it is working fine now.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Policies&amp;gt;SDWAN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;capwap SDWAN policy&lt;/P&gt;&lt;P&gt;SourceZone:&amp;nbsp; zone where your AP is&lt;/P&gt;&lt;P&gt;Source address:&amp;nbsp;&amp;nbsp; IP of your AP&lt;/P&gt;&lt;P&gt;Destination address:&amp;nbsp; IP of WLC or Any&lt;/P&gt;&lt;P&gt;Application:&amp;nbsp; capwap&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure how your connections are configured but this seemed to work for us.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 14:35:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-capwap-ap-stuck-in-discovery/m-p/413591#M92996</guid>
      <dc:creator>joseph.chen</dc:creator>
      <dc:date>2021-06-16T14:35:47Z</dc:date>
    </item>
  </channel>
</rss>

