AP Cannot Onboard the Controller

Onboarding an AP to the SmartZone controller is a straightforward process; however, specific scenarios can complicate the procedure. This topic describes the methods for collecting diagnostic data when an AP fails to onboard to a SmartZone controller. The collected data enables RUCKUS Support to identify the root cause and recommend corrective actions.

Data collection for troubleshooting onboarding issues should be initiated under the following circumstances:

  • The AP remains in a disconnected or setup state.
  • The AP fails to appear in the controller’s AP list.
  • The onboarding process stalls during firmware or configuration updates.
  • RUCKUS Support requests onboarding diagnostics.

Before collecting data:

  • Confirm that the AP is powered on and connected to the network.
  • Ensure the controller is reachable from the AP.
  • Verify that the AP model is supported by the current controller version.
  • Confirm that the controller has available AP licenses.

The table Data Collection Checklist outlines the essential data types you need to collect when troubleshooting an AP onboarding issue. This information helps identify the root cause and determine the necessary corrective actions.

Data Collection Checklist

Data Type Collection Method Notes
AP Status Select Network > Wireless > Access Points. Select the AP if available in the AP list and verify its current status. APs onboarding the controller can display statuses like Firmware upgrade failed, Failed to update configuration, Pending approval, and others that can provide you with a clue of the potential cause of the problem.
Controller Event Logs Select Monitor > Events & Alarms > Events. Look for events related to the AP in question either by the AP IP address or MAC address. The event logs can easily help you identify the root cause of the problem, such as whether it is related to license availability, system capacity, firmware version mismatch, and so on.
System Capacity Select Administration > System > System Info. Scroll to System Summary and compare the Total Capacity against the Connected AP. Each SZ controller has different AP and switch capacity based on the available system resources. If the system resources have reached the maximum capacity, add more resources in the case of virtual SmartZone, or upgrade the controller model in the case of physical SmartZone controllers.
Country Code Match Learn the country code configured in the AP, and verify both the global and the Zone configuration for the country code.

To learn the country code configured in the AP, open an SSH session to the AP and run the command get countrycode.

  • Global setting: Select Network > Wireless > AP Settings > General.
  • Zone setting: Select Network > Wireless > Access Points. Select the Zone and click . In the Edit Zone window, locate the section General Options.
For the AP to onboard to the controller, the country code setting must match both the AP and the destination Zone. To change the AP country code, enter the AP CLI command set countrycode country_code. Some APs have a fixed country code for which you cannot change this configuration, only the RUCKUS Support team. To find out if your AP has a fixed country code, enter the AP CLI command get boarddata, scroll to find the entry Fixed Ctry Code.
MAC OUI Validation Select Network > Wireless > AP Settings > AP MAC OUI Validation. If AP MAC OUI validation is enabled, ensure that the AP MAC is present in the MAC OUI rules. As a workaround, disable MAC OUI validation.
Certificate Status Log in to the AP CLI through SSH and run the command get rpki-cert validity If the certificate is expired, it must be replaced before the AP can successfully onboard. As a temporary workaround, you can disable certificate validation on the SmartZone controller. To do this, log in to the SmartZone CLI in config mode and run the command no ap-cert-expired-check. Alternatively, you can enter no ap-cert-check to disable all AP certificate validation. To re-enable these checks, enter the commands ap-cert-expired-check or ap-cert-check, respectively.
Firewall Port Access Double-check your firewall configuration. If your AP is in a remote office or the controller is behind a firewall configuration, ensure that ports like 443 or 22 are not blocked for the AP to contact the controller.
Firmware Compatibility Select Administration > System > System Info. In Support AP Model List, ensure your AP model is supported in the Zone where you want to onboard the AP. Either the Staging Zone, or the Default Zone must have an AP firmware version that supports the AP model. As a workaround, create an AP Registration Rule that places the AP in a Zone with the required AP firmware.
Note: For instructions to access the AP CLI, refer to Entering the AP CLI.