03-06-2020 08:04 PM
Hello all, I’m not too familiar with the EWC setup at my company so bear with me.
C5210 controller with 3825i AP’s
I’m logged into the wireless controller and am looking at EWC Events - all. There are multiple daily entries that say x.509 Certificate (CN=x.x.x.x.crt) has expired.
In addition to that I see multiple AP session timeouts for AP’s in our building. I’m not sure which is worse or considered “normal”. I have gotten random calls from users having wireless IP/voip issues but sometimes an AP reboot fixes that problem.
Any ideas?
Solved! Go to Solution.
03-09-2020 01:48 PM
Hello David,
It sounds like there is a captive portal Topology/interface with a CA signed certificate installed, that has expired. For anyone using this network, the certificate avoids an error message in the browser when the portal page is shown.
For an expired certificate, it probably just needs a renewal and then having the new signed certificate uploaded to the Topology. If a new certificate is needed, this knowledge article will help - https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-Install-Certificates-for-Captive-Po...
However, the certificate error should not cause client reboots or wireless client connectivity issues. If this is occurring most likely there is another reason for that and would require further investigation.
Regards,
Jason
03-10-2020 03:09 PM
Hi David,
I would suggest giving a call to open a case - AP disconnects can be caused by various reasons and GTAC can assist with that.
It would be helpful to gather any trace logs from AP’s that have disconnected. This KB shows where to download those - https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-Collect-Access-Point-Logging-Inform...
Thanks,
Jason
03-10-2020 12:36 PM
Hi Jason, I appreciate the input. I’ll go over the link you provided.
I looked over the logs again this morning and see continues AP disconnects. Should I call in a support ticket for this or do you guys have some options I should look into first?
03-09-2020 01:48 PM
Hello David,
It sounds like there is a captive portal Topology/interface with a CA signed certificate installed, that has expired. For anyone using this network, the certificate avoids an error message in the browser when the portal page is shown.
For an expired certificate, it probably just needs a renewal and then having the new signed certificate uploaded to the Topology. If a new certificate is needed, this knowledge article will help - https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-Install-Certificates-for-Captive-Po...
However, the certificate error should not cause client reboots or wireless client connectivity issues. If this is occurring most likely there is another reason for that and would require further investigation.
Regards,
Jason