Wireless Operations · Runbook RB-WLC-9800
Day-2 operations, incident playbooks, and IOS-XE upgrade / bring-up procedures for the campus wireless controller pair. Commands assume install mode, RMI+RP HA SSO, and local-mode APs.
| Platform | C9800-40 / C9800-80 |
| Redundancy | HA SSO (RMI + RP) |
| Owner | NOC / Wireless team |
| Last reviewed | 2026-09-08 |
| Review cycle | quarterly |
The values below are an example campus. Replace with your rack's real addressing before using this runbook operationally, then keep this table as the single source of truth.
| Item | Value (example — replace) |
|---|---|
| Pair name | WLC-9800-PAIR-01 |
| Chassis 1 | wlc01a · priority 2 · intended Active |
| Chassis 2 | wlc01b · priority 1 · intended Standby-Hot |
| Wireless mgmt (VIP) | 10.20.0.10 /24 · VLAN 20 · gw 10.20.0.1 |
| RMI addresses | 10.20.0.11 (ch1) / 10.20.0.12 (ch2) — same subnet as mgmt |
| RP link | Dedicated RP port, back-to-back or same L2 domain · 169.254.x auto |
| Running / target IOS-XE | 17.12.4 → 17.15.6 |
| AAA (ISE) | 10.30.0.21 / 10.30.0.22 · auth 1812 · acct 1813 |
| NTP | 10.30.0.5, 10.30.0.6 |
| Mobility group | CAMPUS |
| AP estate | ~180 × C9130/C9120 · Local mode · 2 sites |
| Country / reg domain | BR · -A domain APs |
| Mgmt access | SSH + HTTPS (WebUI) from jump host 10.30.0.40 only |
wlc01a# — run on the Active chassis. In HA SSO the standby has no usable exec; config and install always run on Active and sync automatically.‹angle brackets› — substitute a real value.show version | include INSTALL.⚠️ Change control
Anything in §4 (upgrade) and §5 (bring-up), plus RF profile / DCA / country changes in §2.5, requires an approved change window. Day-2 read-only checks in §2.1 do not.
Routine checks and low-risk changes. Everything here runs on the Active chassis over SSH.
Daily — 2 minutes
show redundancy states — Active + Standby-Hot, both in sso, "Communications Up"show chassis rmi — both RMI IPs reachable, gateway reachableshow ap summary — joined AP count matches expected (±0 unless known outage)show wireless client summary — client count within normal daily bandshow wireless stats ap join summary — no APs stuck in Discovery/DTLS/Joinshow processes cpu platform sorted | exclude 0.0 — no runaway process; control-plane CPU < 60% sustainedshow logging | include %|Traceback since last check — triage anything newwlc01a# — daily snapshot:
show redundancy states
show chassis rmi
show ap summary
show wireless client summary
show wireless stats ap join summary
show wireless stats client delete reasons ! spikes = auth/DHCP/RF problem
show processes cpu platform sorted 1min | exclude 0.0
show platform hardware chassis fantray detail ! -40/-80 only
Weekly — 15 minutes
show ap uptime — flag any AP rebooting repeatedly (uptime resets)show wireless stats client delete reasons — top reasons vs. last weekshow ap auto-rf dot11 5ghz — channel/power churn, high co-channelshow wireless mobility summary — all peers Updir bootflash: | include free — > 3 GB free before any upgrade cycleshow crypto pki certificates | include Trustpoint|end date — WLC + AP MIC/LSC expiry > 90 days outℹ️ Baseline first
Record "normal" values for client count, AP count, control-plane CPU and top client-delete reasons in your NOC wiki. Health checks are only useful against a known baseline.
Two mechanisms — run both.
On-demand — wlc01a#:
copy running-config startup-config
copy running-config tftp://10.30.0.40/wlc01-run-$(date +%Y%m%d).cfg
show tech wireless | redirect tftp://10.30.0.40/wlc01-tech-$(date).txt ! only when opening a TAC case
Scheduled archive (set once, verify weekly) — wlc01a(config)#:
archive
path tftp://10.30.0.40/wlc01-archive
time-period 1440 ! minutes = daily
write-memory ! also archive on every 'wr'
⚠️ Also back up outside the box
Export the AP inventory (show ap config general), the tag/profile assignment (show ap tag summary) and the WLAN summary to the wiki. If you rebuild from bare metal you need the AP-name-to-tag mapping, and that is tedious to reconstruct from memory.
wlc01a# — HA verification:
show redundancy states ! my state ACTIVE / peer STANDBY HOT, unit ID, SSO
show redundancy | include Duplex|state|Uptime
show chassis ! priority, MAC, state, both chassis Ready
show chassis rmi ! RMI reachability + default-gw check
show romvar | include SWITCH_PRIORITY|CHASSIS ! persisted priority per chassis
show logging process stack_mgr ! RP link / stack events
| Symptom | Action |
|---|---|
Peer = DISABLED / STANDBY COLD |
Check RP link (physical + show platform software stack-mgr). Standby auto-reloads to re-bulk-sync. If stuck, reload the standby chassis only: redundancy reload peer. |
| Both chassis think they are Active (split-brain) | RP link is down but RMI is up — the lower-priority chassis reloads itself by design (RMI dual-active detection). Fix the RP link, then it rejoins as Standby. Never power both up on an isolated RP. |
| Recovery-mode chassis after gateway loss | RMI detected default-gw unreachable and forced a switchover. The old Active sits in recovery until you chassis ‹n› recovery-reload or reload it. Confirm the gateway/uplink is actually healthy first. |
| Planned failover test | redundancy force-switchover on Active during a window. Expect ~sub-second control-plane, AP CAPWAP stays up, clients keep their sessions (AP SSO). Verify with show wireless stats ap join summary after. |
🛑 Do not reload the pair to "fix" HA
A full pair reload is a total wireless outage. Standby issues are almost always resolved by reloading the standby only (redundancy reload peer). Only the Active carries service.
The 9800 config model: an AP gets one policy tag (WLAN → policy-profile bindings), one site tag (AP join profile + local/flex + local-site), one RF tag (2.4/5/6 GHz RF profiles). Change behaviour by moving the AP to a different tag, not by editing shared profiles under load.
wlc01a# — inspect before change:
show ap tag summary
show ap name ‹AP-NAME› config general | include Tag
show wlan summary
show wireless profile policy summary
show ap tag summary | include Misconfigured|Default ! must be empty
wlc01a(config)# — move one AP to a tag:
ap ‹AP-MAC-addr›
policy-tag ‹POLICY-TAG-NAME›
site-tag ‹SITE-TAG-NAME›
rf-tag ‹RF-TAG-NAME›
! the AP does a quick CAPWAP re-config (radios bounce ~10-20s). Not hitless.
⚠️ Site-tag change = AP reboots
Changing an AP's site tag (especially local↔flex, or a different AP join profile) causes a full AP reload, not just a radio reset. Batch these into a window. Policy/RF tag changes only bounce radios.
Add a WLAN (SSID)
dhcp-required for dot1x SSIDs.wlan ‹profile› policy ‹policy-profile›.wlc01a# — RF state:
show ap auto-rf dot11 5ghz
show ap dot11 5ghz summary ! per-AP channel / width / tx power / clients
show wireless rrm dca status
show ap auto-rf dot11 5ghz | include Interference|Noise|Utilization
show ap name ‹AP› auto-rf dot11 5ghz ! neighbours, RSSI, why this channel
show wireless rrm dot11 5ghz group ! RF grouping / leader
| Task | Command (config unless noted) |
|---|---|
| Force one DCA run now | ap dot11 5ghz rrm dca now (exec) — off-peak only |
| Change DCA channel set | ap dot11 5ghz rrm channel dca ‹chan› / no ... to remove UNII-2e/DFS |
| Static channel/power on one AP | ap name ‹AP› dot11 5ghz radio role manual client-serving then ap name ‹AP› dot11 5ghz channel ‹n› |
| Assign RF profile | via RF tag: wireless tag rf ‹RF-TAG› → dot11-5ghz-rf-policy ‹profile› |
| Data-rate / min-RSSI tuning | in the RF profile, not globally |
ℹ️ Hot / humid, high-density campus
Prefer 40 MHz on 5 GHz (not 80) for density; disable 2.4 GHz radios on ~⅓ of APs via an RF profile with "Coverage" → low; keep DCA on with DFS channels enabled unless you have a radar-heavy neighbour. Re-evaluate after any AP add/move.
Each playbook: triage commands → likely causes → fix. The universal deep-dive tool is RadioActive Tracing — always the second step for any single-client problem.
wlc01a# — RadioActive Tracing, always-on-hand:
debug wireless mac ‹CLIENT-MAC› monitor-time 1800
! ... reproduce the failure (reconnect the client) ...
no debug wireless mac ‹CLIENT-MAC›
dir bootflash: | include ra_trace
more bootflash:ra_trace_‹MAC›_‹ts›.txt ! full assoc/auth/DHCP/mobility state machine
! AP-side: show ap name ‹AP› client-trace status
Triage — wlc01a#:
show wireless client mac ‹MAC› detail ! state, WLAN, AP, policy, failure reason
show wireless client summary | count ‹SSID›
show wireless stats client delete reasons
show wlan id ‹n› ! Enabled? security? method-list?
show ap name ‹AP› tag detail
debug wireless mac ‹MAC› monitor-time 600 ! then reproduce
Likely causes
show wireless client mac ‹MAC› detail | include Exclusion).Fix
Act on the failure reason in the RA trace. Clear a stuck session with clear wireless client mac-address ‹MAC›. Remove an accidental exclusion with wireless client mac-address ‹MAC› ap-policy exclude ... reversal or disable exclusion policy on the WLAN.
Triage — wlc01a#:
show wireless stats ap join summary ! which phase it's stuck in
show ap name ‹AP› join stats detailed
show wireless stats ap discovery
show wireless management trustpoint ! WLC cert used for DTLS
show ap crash-file / show ap name ‹AP› tech-support
Likely causes
CISCO-CAPWAP-CONTROLLER pointing at the wrong VIP.Fix
Correct NTP first, then re-test. Set ap country ‹BR› matches domain. Verify the AP resolves the mgmt VIP (not an RMI IP — APs join the VIP). Clear a wedged AP: ap name ‹AP› reset (from WLC) or power-cycle.
Triage — wlc01a#:
show aaa servers | include RADIUS|state|Dead|requests
test aaa group ‹AAA-GRP› ‹user› ‹pass› new-code ! forces a live probe
show wireless client mac ‹MAC› detail | include Auth|AAA|Policy
show run aaa | section radius|method ! server-group, method-list, dead-criteria
debug wireless mac ‹MAC› monitor-time 600
Likely causes
ip radius source-interface).automate-tester / dead-criteria and reachability on 1812/1813 + CoA 1700/3799.Fix
Fix the secret / NAD entry, confirm ip radius source-interface Vlan20. If servers wrongly marked dead: clear aaa counters servers all. Cross-check the ISE Live Log for the same MAC/timestamp — the reject reason there is usually definitive.
Triage — wlc01a#:
show wireless client mac ‹MAC› detail | include IP|VLAN|State|Mobility
show wireless client mac ‹MAC› stats
debug wireless mac ‹MAC› monitor-time 600 ! watch DHCP DISCOVER/OFFER/REQUEST/ACK
show wireless profile policy detailed ‹POL› | include DHCP|VLAN|Switching
Likely causes
Fix
Match policy-profile VLAN to a trunked, DHCP-served VLAN. Add ip helper-address on the SVI. Temporarily disable dhcp-required only to prove it's a DHCP-path problem, then fix the path.
Triage — wlc01a#:
show wireless client mac ‹MAC› detail | include RSSI|SNR|Rate|Retries|Channel
show wireless client mac ‹MAC› mobility history
show ap name ‹AP› auto-rf dot11 5ghz | include Interference|Noise|Util|Clients
show ap dot11 5ghz summary | include ‹AP›
show wireless stats client delete reasons | include roam|idle
Likely causes
show ap auto-rf shows recent channel changes.Fix
Tune via the RF profile: raise min-RSSI / min data rate to shed cell-edge clients, cap channel width, set tx-power range. Enable 802.11k/v to assist roaming. Physical fix (add/move AP) if it's a true coverage hole — RRM can't fill a gap.
wlc01a#:
show wireless mobility summary ! peer state must be Up
show wireless mobility ap-list
show wireless mobility controller client summary
! reachability of the mobility tunnel:
show wireless mobility summary | include Multicast|Group
ping ‹peer-mobility-ip›
Causes: UDP 16666 (control, DTLS) / 16667 (data) blocked between controllers; mismatched mobility group name or MAC/IP in the peer config; PMK not transferring (different group).
Fix: open 16666/16667, confirm identical group name, re-add the peer, verify Up.
wlc01a#:
show processes cpu platform sorted 5min
show processes memory platform sorted
show platform software status control-processor brief
show wireless stats client delete reasons ! auth storms churn CPU
show logging | include MALLOC|MEMLEAK|CPUHOG
Causes: auth/deauth storm (misbehaving SSID or ISE flap), SNMP/telemetry polling too aggressively, an mDNS/Bonjour gateway with huge cache, a known leak on the running build.
Fix: throttle external polling, contain the storm at its source, check the release notes / TAC-recommended page for a fixed build. Open a TAC case with show tech wireless if it's a leak.
ℹ️ For any TAC case
show tech wireless+ the relevantra_tracefile +show ap name ‹AP› tech-support(for AP issues) + the ISE Live Log export (for auth). Attach the exact client MAC and a UTC timestamp of a reproduction.
Full-image upgrade of the pair. Plan a maintenance window: activation reloads both chassis together — this is a wireless outage of a few minutes unless you run ISSU (see note).
Always take the target from Cisco's live TAC-recommended releases page, not from this runbook. As of the August 2026 security-hardening cycle:
| Situation | Target |
|---|---|
| Standard estate, no Wi-Fi 7 | 17.15.6 (or 17.15.5 as the prior recommended) |
| Wi-Fi 7 APs in use | 17.18.3 |
| Must stay on 17.12 (e.g. 802.11ac Wave 1 APs) | 17.12.8 (17.12.7a prior) |
| On 17.9 | 17.9 is End of Software Maintenance — plan migration off it |
⚠️ Check the upgrade path
Confirm a supported direct upgrade from the running build in the target's release notes. Long jumps (e.g. 17.3 → 17.15) may need an intermediate hop. Also check AP-model support and any COP/APDP SMU requirements.
show redundancy states = Active + Standby-Hot, SSO, comms upshow install summary — state is C (committed), no pending/inactive imagesshow version | include INSTALL — install mode confirmeddir bootflash: | include free — ≥ 3 GB free on both chassis (dir stby-bootflash:)verify /md5 or show file hash after copyshow ap image — note current AP image, all APs "Primary"show wireless stats ap join summary — no APs mid-joinwlc01a#:copy tftp://10.30.0.40/C9800-80-universalk9_wlc.17.15.06.SPA.bin bootflash:
dir bootflash: | include 17.15.06
dir stby-bootflash: | include 17.15.06 ! confirm it synced
wlc01a#:install add file bootflash:C9800-80-universalk9_wlc.17.15.06.SPA.bin
show install summary ! new pkg shows state 'I' (inactive/added)
wlc01a#:ap image predownload
show ap image ! watch 'Predownload Status' -> Complete for all APs
show ap image summary
ℹ️ Wait for 100%
Do not activate until every AP shows the new image predownloaded. APs without it will download after reload and take far longer to rejoin.
🛑 This step reloads both chassis
Standardinstall activateon an HA SSO pair reloads Active and Standby. Expect APs to drop CAPWAP and rejoin (2–8 min depending on estate + whether predownload completed). Clients disconnect. Do it inside the window.
wlc01a#:install activate ! prompts to proceed; both chassis reload
! ---- pair reloads; reconnect via console/SSH ----
wlc01a#:show version | include Version
show redundancy states ! Active + Standby-Hot, SSO — MUST be back
show install summary ! new pkg state 'U' (activated, uncommitted)
show ap summary ! AP count back to baseline
show wireless stats ap join summary
show ap image summary ! all APs on new image, 'Primary'
show logging | include %|Traceback
wlc01a#:install commit
show install summary ! state 'C' committed
Up.ℹ️ One-shot alternative
install add file bootflash:‹img› activate commitdoes all three in one command — but you lose the verification checkpoint between activate and commit, and there is no auto-rollback safety net. Use the staged 3-step flow for production.
C9800-40/80/CL support ISSU within qualified release pairs (check the target release notes for the supported "from" versions). It upgrades the standby, switches over, then upgrades the ex-active — clients and CAPWAP largely survive.
wlc01a# — ISSU:
install add file bootflash:‹img›
ap image predownload
install activate issu
! monitor: show issu state detail
install commit
show issu state detail ! 'Finished' / no in-progress
⚠️ ISSU caveats
Only between qualified versions; not for every long jump; RRM/mesh/some feature states may still blip. If the "from/to" pair isn't on the supported ISSU list, use the standard reload flow.
wlc01a#:
show install rollback
install rollback to committed ! back to the last committed image (pre-upgrade)
! or if activated but NOT committed and something's wrong:
install abort ! reverts the activation, reloads to old image
! auto-abort also fires on its own if you never commit before the timer
If rollback via install fails (rare, filesystem issue), boot the previous packages.conf / image from ROMMON on console and re-stage.
Order matters: base + reachability → HA SSO → country/regulatory → AAA → tags/profiles → AP join → mobility. Use the WebUI Day-0 wizard for the first pass, then CLI for the rest.
ntp server ×2 — clock correct before anything cert-related10.20.0.10/24, wireless management interface Vlan2010.20.0.1ip ssh, AAA login, ACL to jump host; disable Telnetcrypto pki self-signed / CA trustpoint for the WebUI + AP DTLS (MIC is default; deploy LSC if required)wlc01a(config)#:chassis redundancy ha-interface GigabitEthernet 3 ! -CL; on 40/80 the RP port is fixed/dedicated
chassis 1 redundancy-management interface Vlan20 10.20.0.11
chassis 2 redundancy-management interface Vlan20 10.20.0.12
chassis 1 priority 2
chassis 2 priority 1
redundancy
mode sso
wlc01a#:show chassis
show redundancy states
show chassis rmi ! both RMI up, gateway reachable
show romvar | include PRIORITY
ℹ️ RMI gateway monitoring
RMI uses the mgmt-subnet default gateway as the failover health probe. Make sure10.20.0.1is a real, always-up SVI/HSRP address — if it flaps, RMI will force switchovers.
wlc01a(config)#:
ap dot11 5ghz shutdown
ap dot11 24ghz shutdown
wireless country BR
ap dot11 5ghz channel dca ... ! set allowed channels incl. DFS policy
no ap dot11 5ghz shutdown
no ap dot11 24ghz shutdown
AP regulatory domain (-A, -E, -Z …) must be legal for BR. Mismatched APs join but keep radios down.
wlc01a(config)#:
radius server ISE-1
address ipv4 10.30.0.21 auth-port 1812 acct-port 1813
key ‹secret›
automate-tester username probe-user probe-on
radius server ISE-2
address ipv4 10.30.0.22 auth-port 1812 acct-port 1813
key ‹secret›
!
aaa group server radius ISE-GRP
server name ISE-1
server name ISE-2
deadtime 5
!
aaa authentication dot1x ISE-DOT1X group ISE-GRP
aaa authorization network ISE-DOT1X group ISE-GRP
aaa accounting identity ISE-DOT1X start-stop group ISE-GRP
!
ip radius source-interface Vlan20 ! must match the NAD IP in ISE
aaa server radius dynamic-author ! CoA
client 10.30.0.21 server-key ‹secret›
client 10.30.0.22 server-key ‹secret›
Add the WLC (mgmt VIP) as a Network Device in ISE with the matching secret. Test: test aaa group ISE-GRP ‹user› ‹pass› new-code.
ISE-DOT1X or PSK).dhcp-required, AAA-override, session/idle timeouts, ACLs.local-site (local mode) or flex profile.CISCO-CAPWAP-CONTROLLER.‹domain› → VIPshow ap summary), then assign tags in bulk (filter/rule or per-AP)show ap tag summary — no "Misconfigured" / "Default-*" tags remainingwlc01a(config)# — bulk tag assignment by rule:
wireless tag-source-priority ... ! or:
ap filter name SITE-A
ap filter-name SITE-A tag-source filter
...
! or static per AP as in §2.4
wlc01a(config)#:
wireless mobility group name CAMPUS
wireless mobility group member ip 10.21.0.10 public-ip 10.21.0.10 group CAMPUS ! peer WLC
! open UDP 16666 (control) + 16667 (data) between controllers
wlc01a#:
show wireless mobility summary ! peer -> Up
| Purpose | Protocol / port |
|---|---|
| CAPWAP control / data (AP ↔ WLC) | UDP 5246 / 5247 |
| Mobility control (DTLS) / data | UDP 16666 / 16667 |
| RADIUS auth / acct | UDP 1812 / 1813 |
| RADIUS CoA (dynamic-author) | UDP 1700 or 3799 |
| RMI keepalive / dual-active | mgmt subnet (uses default gateway as probe) |
| RP (redundancy) link | dedicated port, 169.254.0.0/16 auto |
| Mgmt | SSH 22, HTTPS 443, NTP 123, syslog 514, SNMP 161, NETCONF 830 |
| Command | Use |
|---|---|
show redundancy states |
HA role + SSO status — the single most important check |
show chassis rmi |
RMI reachability + gateway health |
show ap summary |
joined AP count / IP / mode |
show ap tag summary |
tag assignment + misconfig flag |
show wireless client summary |
client count / state |
show wireless client mac ‹m› detail |
one client: state, WLAN, AP, RF, failure reason |
show wireless stats client delete reasons |
why clients disconnect — trend it |
show wireless stats ap join summary |
AP join phase breakdown |
show ap image summary |
AP image / predownload status |
show install summary |
image states (I/U/C) for upgrades |
show ap auto-rf dot11 5ghz |
RRM: channel, power, interference, noise |
show wireless mobility summary |
mobility peer state |
show aaa servers |
RADIUS server state / dead detection |
debug wireless mac ‹m› |
RadioActive Tracing — per-client deep dive |
show tech wireless |
TAC bundle |
⚠️ This runbook is a starting point
Command syntax varies slightly by IOS-XE release. Validate §4 and §5 against the config guide and HA SSO guide for your exact target version before running them in production. Keep §1 current.
RB-WLC-9800 · Catalyst 9800-40/80 HA SSO · last reviewed 2026-09-08 · owner: NOC / Wireless · example addressing throughout — replace §1 before operational use.