2 weeks ago
Hi
I have vx9000 as virtual controller to multisite, release 7.7.1.3-005R, various APs type
One site, AP305cx, every first of the mounth every APs reboot or disconnect from controller and re-adopt disconnect and re-adopt many time for 20 minutes.
From event history i see many log like this:
CONFIG_REVISION Configuration revision updated to 11 from 12
2026-01-02 02:44:04 AP42-Mag-Vercelli SYSTEM CONFIG_REVISION Configuration revision updated to 11 from 11
2026-01-02 02:44:04 AP06-Mag-Vercelli SYSTEM CONFIG_COMMIT Configuration commit by user 'cfgd' (update own config) from '127.0.0.1'
2026-01-02 02:44:04 AP42-Mag-Vercelli SYSTEM CONFIG_COMMIT Configuration commit by user 'cfgd' (update own config) from '127.0.0.1'
2026-01-02 02:44:04 AP06-Mag-Vercelli CFGD ACL_RULE_ALTERED USER: cfgd session 87: ACL BROADCAST-MULTICAST-CONTROL rule is getting altered
2026-01-02 02:44:04 AP42-Mag-Vercelli CFGD ACL_RULE_ALTERED USER: cfgd session 23: ACL BROADCAST-MULTICAST-CONTROL rule is getting altered
2026-01-02 02:44:04 AP06-Mag-Vercelli DEVICE ADOPTED_TO_CONTROLLER Joined successfully with controller 'ARSBARWARECTL'(12.BA.08.E9)
2026-01-02 02:44:04 AP42-Mag-Vercelli DEVICE ADOPTED_TO_CONTROLL
Issue resolved without any action to the vx9000.
What can i check?
2 weeks ago
As already assumed, the controller is sending a config update to the AP and due to this update, the AP is dropping it's adoption.
"Jan 06 23:26:48 2026: %USER-3-ERR: main.pyo: * * ERROR: receive update error: timed out"
"Jan 02 04:00:10 2026: %USER-3-ERR: main.pyo: * * ERROR: check config failed; error : not-adopted"
This may have several reasons.
If you like you can attach the full VX9000 config to this thread and I will have a look.
But you should remove or hide any passworts, keys, etc...
Actually my best guess is a wrong configured firewall policy (Jan 07 06:59:16 2026: %DATAPLANE-4-DOSATTACK: BAD_PACKET: Bcast/Mcast ICMP not allowed : Src IP : 10.58.114.20, Dst IP: 10.58.115.255, Src Mac: 48-9E-BD-31-05-BF, Dst Mac: FF-FF-FF-FF-FF-FF, ICMP type = 3, ICMP code = 3, Proto = 1) or wrong IP settings (ip default-gateway 10.58.119.254).
But the full config would be the best.
a week ago
Hi
Little update, I discovered that these APs (Type A-Warehouse) are in the same area of other Extreme APs (Type B-Office).
Type A have native vlan 603, all other vlans allowed on interface
Type B have native vlan 14, all other vlans allowed on interface
Type A and Type B can see together in VLAN1 and i think that this is the first issue because mint protocol works in L2 in ISO-OSI pile.
In 07/01/2026 I deleted VLAN1 from allowed vlan on both profile and they can't see each other.
Tonight APs reboot again, and the last thing to have is delete all vlans that i don't use with SSID or management of Access Point.
I think that ethernet cable interface of AP opened to all vlans is not good practice because it can listen to all vlan broadcast domains.
Don't you agree?
a week ago
I totally agree.
Get your VLAN's sorted and all should work well.
I was already wondering why the default gateway in your AP profile shows as "10.58.119.254" and the event history was showing firewall error with "Dst IP: 10.58.115.255"...
Good luck!
2 weeks ago
This issue sounds very familiar to me.
There is some error in the AP configuration on the controller, which will break the adoption once the AP receives it's configuration from the controller.
What happens?
To proof my guess please use the CLI command "show adoption config-errors AP42-Mag-Vercelli" in the VX9000.
You should some error messages.
Please post those together with the AP profile and the AP override and I will have a look for the configuration error.