Wireless Access

Reply
Contributor I
Posts: 30
Registered: ‎06-09-2013

Aruba AP status is down. it works for only 10 min after rebooting, then it is down again

Hi, 

 

I have 7 AP with 1 650 mobility controller. one of the AP goes down. it works for 10 minutes after rebooting, then goes down. with the power led flashing green and the ethernet, wireless led is off.

 

I am checking the status on the controller, it says that the AP is down. I don't know where to start on troubleshooting the problem, so any help is really appreciated. 

 

regards

MVP
Posts: 4,271
Registered: ‎07-20-2011

Re: Aruba AP status is down. it works for only 10 min after rebooting, then it is down again

[ Edited ]

Do the following :

 

- show log system all | include <apmac address>

- logging level debug ap-debug <apmac address>

- show log all <apmac address>

 

do a show ap license-usage to make sure you have enough licenses 

Do you have cpsec on ? show control-plane-security 

 

You could also console into the AP to make sure it's getting the right DHCP information or it can reach the right controller (master)

 

Make sure you haven't execeed the amount of APs that the controller is able to support :
www.arubanetworks.compdfproductsDS_A650651.png

 

Make sure that AP is getting PoE on the switch is connected

 

What LEDs are showing ?

 

Thank you

Victor Fabian
Lead Mobility Engineer @ Integration Partners
AMFX | ACMX | ACDX | ACCX | CWAP | CWDP | CWNA
Aruba
Posts: 233
Registered: ‎11-19-2009

Re: Aruba AP status is down. it works for only 10 min after rebooting, then it is down again

Hi Fayez,

Can we check if this AP is crashing as all other AP`s are working fine?

Below command will give that info.

show ap debug crash-info ap-name <name of the ap>

 

Make sure port connected to the AP doesnt show up errors or not going up & down.

 

Below command will provide what traffic comes in from AP itself.

show datapath session table ap-name <name of the ap>

Reason for reboot:-

==============

show ap debug system-status ap-name <name of the ap>

 

Could you please post the show log system all | include <ap-name> as this will fetch you more information about AP itself.

 

Thank you,

Sriram S

Technical Support Engineer

srirams@arubanetworks.com

408.585.1928

 

Contributor I
Posts: 30
Registered: ‎06-09-2013

Re: Aruba AP status is down. it works for only 10 min after rebooting, then it is down again

hi, 

 

here is the output of the commands. 

 

(Aruba650) #show log system all | include 24:de:c6:c0:17:d5
Jun 20 04:48:44 :305049: <WARN> |stm| Unsecure AP "24:de:c6:c0:17:d5" (MAC 24:de:c6:c0:17:d5, IP 192.168.0.209) has been denied access because Control Plane Security is enabled and the AP is not approved.
Jun 20 04:49:02 :305049: <WARN> |stm| Unsecure AP "24:de:c6:c0:17:d5" (MAC 24:de:c6:c0:17:d5, IP 192.168.0.209) has been denied access because Control Plane Security is enabled and the AP is not approved.
Jun 20 04:49:25 :305049: <WARN> |stm| Unsecure AP "24:de:c6:c0:17:d5" (MAC 24:de:c6:c0:17:d5, IP 192.168.0.209) has been denied access because Control Plane Security is enabled and the AP is not approved.
Jun 20 04:50:32 :305048: <WARN> |stm| Dropping unsecure AP message code 16121 from AP at 192.168.0.209 (MAC address 24:de:c6:c0:17:d5)
Jun 20 04:50:35 :311002: <WARN> |AP 24:de:c6:c0:17:d5@192.168.0.209 sapd| Rebooting: SAPD: Rebooting after installing trust update. Factory Cert present
Jun 20 04:50:35 :303086: <ERRS> |AP 24:de:c6:c0:17:d5@192.168.0.209 nanny| Process Manager (nanny) shutting down - AP will reboot!
Jun 20 04:51:55 :311020: <ERRS> |AP 24:de:c6:c0:17:d5@192.168.0.209 sapd| An internal system error has occurred at file sapd_redun.c function redun_init_tunnel_master line 3048 error Unable to open /tmp/num_ipsec.
Jun 24 06:10:52 :311020: <ERRS> |AP 24:de:c6:c0:17:d5@192.168.0.209 sapd| An internal system error has occurred at file sapd_redun.c function sapd_proc_redun_msg line 4319 error Error: Received RC_OPCODE_ERROR lms 192.168.0.248 tunnel 0.0.0.0 RC_ERROR_ISAKMP_N_VERSION2_SUPPORTED.
Jun 24 06:11:43 :311020: <ERRS> |AP 24:de:c6:c0:17:d5@192.168.0.209 sapd| An internal system error has occurred at file sapd_redun.c function sapd_proc_redun_msg line 4319 error Error: Received RC_OPCODE_ERROR lms 192.168.0.248 tunnel 0.0.0.0 RC_ERROR_ISAKMP_N_VERSION2_SUPPORTED.
Jun 24 06:15:47 :311020: <ERRS> |AP 24:de:c6:c0:17:d5@192.168.0.209 sapd| An internal system error has occurred at file sapd_redun.c function sapd_proc_redun_msg line 4319 error Error: Received RC_OPCODE_ERROR lms 192.168.0.248 tunnel 0.0.0.0 RC_ERROR_ISAKMP_N_VERSION2_SUPPORTED.
Jul 9 20:06:56 :311020: <ERRS> |AP 24:de:c6:c0:17:d5@192.168.0.209 sapd| An internal system error has occurred at file sapd_redun.c function sapd_proc_redun_msg line 4319 error Error: Received RC_OPCODE_ERROR lms 192.168.0.248 tunnel 0.0.0.0 RC_ERROR_ISAKMP_N_VERSION2_SUPPORTED.

(Aruba650) # show control-plane-security

Control Plane Security Profile
------------------------------
Parameter Value
--------- -----
Control Plane Security Enabled
Auto Cert Provisioning Disabled
Auto Cert Allow All Enabled
Auto Cert Allowed Addresses N/A

 

control plane security is enabled, and there seems a problem with the security of the AP.

MVP
Posts: 4,271
Registered: ‎07-20-2011

Re: Aruba AP status is down. it works for only 10 min after rebooting, then it is down again

[ Edited ]

 

You can add the mac address of that AP into the CPSec whitelist but there's other options like a certain range of IPs or auto cert validation , here's the guide :

 

http://www.arubanetworks.com/techdocs/ArubaOS_60/UserGuide/control_plane.php

Thank you

Victor Fabian
Lead Mobility Engineer @ Integration Partners
AMFX | ACMX | ACDX | ACCX | CWAP | CWDP | CWNA
Aruba
Posts: 233
Registered: ‎11-19-2009

Re: Aruba AP status is down. it works for only 10 min after rebooting, then it is down again

Below command would tell you the status of the AP. 

 

Here is the below command.

 

(Aruba) #show whitelist-db cpsec


Control-Plane Security Whitelist-entry Details
----------------------------------------------
MAC-Address Enable State Cert-Type Description Revoke Text Last Updated
----------- ------ ----- --------- ----------- ----------- ------------
00:24:6c:c8:68:7f Enabled certified-factory-cert factory-cert Mon Jul 8 21:28:49 2013
00:0b:86:68:bc:01 Enabled unapproved-no-cert switch-cert 00:0b:86:68:bc :01 Tue Mar 12 11:44:13 2013

 

You can manually add the mac address to see if that helps 

 

(Aruba) (config) #whitelist-db cpsec add mac-address 00:0b:86:68:bc:01 description 00:0b:86:68:bc:01

 

If you have console access to the AP, you can also reset the AP to see how it goes.

 

Thank you,

Sriram S

Techincal Support Engineer

srirams@arubanetworks.com

408.585.1928

 

 

 

Contributor I
Posts: 30
Registered: ‎06-09-2013

Re: Aruba AP status is down. it works for only 10 min after rebooting, then it is down again

The AP point mac address is there in the campus ap whitelist. and cert type is factory-certificate, also state is certified-switch-cert, and revoked is NO. 

 

 

 

I have no Idea why in the logs it says that the AP is not approved. also it says if you check the logs further down "enternal system error has occured"

 

MVP
Posts: 4,271
Registered: ‎07-20-2011

Re: Aruba AP status is down. it works for only 10 min after rebooting, then it is down again

 

I noticed this :

Auto Cert Provisioning Disabled

 

You already manually added the mac to the cpsec whitelist ?

 

 

Thank you

Victor Fabian
Lead Mobility Engineer @ Integration Partners
AMFX | ACMX | ACDX | ACCX | CWAP | CWDP | CWNA
MVP
Posts: 4,271
Registered: ‎07-20-2011

Re: Aruba AP status is down. it works for only 10 min after rebooting, then it is down again

 

Try to clear it / delete it from the list and readd it again

Thank you

Victor Fabian
Lead Mobility Engineer @ Integration Partners
AMFX | ACMX | ACDX | ACCX | CWAP | CWDP | CWNA
Aruba
Posts: 233
Registered: ‎11-19-2009

Re: Aruba AP status is down. it works for only 10 min after rebooting, then it is down again

 

Hi Fayez,

 

Please let me know if you still have issues after we reset, clear and re-enable the auto-cert provisioning parameter.

 

You can also reach me at my desk 408.585.1928

 

 

 

Thank you,

 

Sriram Subramanian

 

Technical Support Engineer

 

srirams@arubanetworks.com

 

408.585.1928..

 

Search Airheads
Showing results for 
Search instead for 
Did you mean: