Wired Intelligent Edge

last person joined: yesterday 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution

Need Help!! Tunneled Node Vanish in 6 Mins

This thread has been viewed 0 times
  • 1.  Need Help!! Tunneled Node Vanish in 6 Mins

    Posted May 28, 2017 04:23 AM

    The Switch has been connected with Controller by Tunneled-node Feature 

    Aruba-2930F-48G-PoEP-4SFPP(eth-31)# show tunneled-node-server state

     Tunneled Node Port State

     Active Controller IP Address  : 10.1.255.9

     Port   State
     ------ -------------------------
     31     Complete

     

     

     

    And I have configure UDR for the IP_Phone as follow the below link

    http://community.arubanetworks.com/t5/Wired-Networks/How-to-configure-VOIP-vlan-with-tunnel-node-ports-in-Mobility/ta-p/216017

     

    every think work fine but the tunnel is gone in 6 Mins and need to unplug to create the new tunnel. 

    The Below is my configure

     

    ip access-list session ACL-VOICE

      any any any  permit

     

    user-role voice

     vlan 100

     

     access-list session ACL-VOICE

     

    aaa derivation-rules user YEALINK

      set role condition macaddr starts-with "00:15:65" set-value voice

     

    aaa profile "Employee-aaa_prof"

       authentication-dot1x "dot1x_prof-lzi20"

       dot1x-default-role "authenticated"

       dot1x-server-group "Employee_srvgrp-xmp29"

       radius-accounting "Employee_srvgrp-xmp29"

       rfc-3576-server "10.1.0.111"

       user-derivation-rules "YEALINK"

     

    When i plug the phone in tunneld switch

    (Aruba7205) #show user

    Users
    -----
        IP            MAC            Name     Role      Age(d:h:m)  Auth  VPN link  AP name   Roaming  Essid/Bssid/Phy                   Profile            Forward mode  Type  Host Name
    ----------   ------------       ------    ----      ----------  ----  --------  -------   -------  ---------------                   -------            ------------  ----  ---------
    10.1.100.90  00:15:65:b3:e6:e6            voice     00:00:00                    tunnel 9  Wired    10.1.255.10:31/00:fd:45:1d:83:00  Employee-aaa_prof  tunnel         

    User Entries: 1/1
     Curr/**bleep** Alloc:1/17 Free:0/16 Dyn:1 AllocErr:0 FreeErr:0

     

    after 6 Mins

    (Aruba7205) #show user

    Users
    -----
    IP MAC Name Role Age(d:h:m) Auth VPN link AP name Roaming Essid/Bssid/Phy Profile Forward mode Type Host Name
    ---------- ------------ ------ ---- ---------- ---- -------- ------- ------- --------------- ------- ------------ ---- ---------

    User Entries: 0/0
    Curr/**bleep** Alloc:1/19 Free:0/18 Dyn:1 AllocErr:0 FreeErr:0

     

    The log said

    May 28 15:03:41  stm[4111]: <304009> <4111> <WARN> |stm|  enet_move_tunnel: Tunnel 65545 not found
    May 28 15:05:28  authmgr[4108]: <132197> <4108> <ERRS> |authmgr|  Maximum number of retries was attempted for station  00:15:65:b3:e6:e6 01:80:c2:00:00:03, deauthenticating the station
    May 28 15:05:28  authmgr[4108]: <132197> <4108> <ERRS> |authmgr|  Maximum number of retries was attempted for station  00:15:65:b3:e6:e6 01:80:c2:00:00:03, deauthenticating the station
    May 28 15:11:17  authmgr[4108]: <132197> <4108> <ERRS> |authmgr|  Maximum number of retries was attempted for station  00:15:65:b3:e6:e6 01:80:c2:00:00:03, deauthenticating the station
    May 28 15:11:17  authmgr[4108]: <132197> <4108> <ERRS> |authmgr|  Maximum number of retries was attempted for station  00:15:65:b3:e6:e6 01:80:c2:00:00:03, deauthenticating the station
    May 28 15:18:06  authmgr[4108]: <132197> <4108> <ERRS> |authmgr|  Maximum number of retries was attempted for station  00:15:65:b3:e6:e6 01:80:c2:00:00:03, deauthenticating the station
    May 28 15:18:06  authmgr[4108]: <132197> <4108> <ERRS> |authmgr|  Maximum number of retries was attempted for station  00:15:65:b3:e6:e6 01:80:c2:00:00:03, deauthenticating the station

     

     

    Please help to advise