Wireless Access

last person joined: 16 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Help with RAP-2WG-US

This thread has been viewed 0 times
  • 1.  Help with RAP-2WG-US

    Posted Dec 23, 2013 11:23 AM

    I was given a RAP that I have been tasked with trying to get it connected to our controller.  For some reason I am having great difficulty, and an extra set of eyes would be more than helpful at this point.

     

     I am given a "RC_ERROR_IKEP2_PKT1" error when attempting to connect to the controller from our internal network (just to try to get things working first)..  After asking google, I found that the RAP may not be connecting to the controller, and followed instructions I found elsewhere to troubleshoot. My output is as follows:

     

    (Aruba) #show datapath session table | include 4500
    X.X.X.X    X.X.X.X       17   4500  4500   0/0     0 0   0   1/1         1c   1      1      F
    X.X.X.X    X.X.X.X       17   4500  4500   0/0     0 0   0   1/1         1c   0      0      FC

    I followed the AP wizard, and set my configuration to AP specific for this AP.

    The RAP is whitelisted (tried with and without an IP assigned)

    Under VPN Services I have L2TP & XAuth enabled.  Authentication Protocals is PAP only.  DNS info is listed, address pool is setup.  Nat-T is enabled.

     

    Any guidance would be appreciated!

     

     

     



  • 2.  RE: Help with RAP-2WG-US

    EMPLOYEE
    Posted Dec 23, 2013 11:30 AM

    Execute these commands:

    config t
    logging level debugging security subcat ike logging level debugging security process aaa logging level debugging security process authmgr logging level debugging security subcat l2tp logging level debugging security subcat vpn

     Boot up the RAP2Wg.  When it fails, type "show log security 50" to see what happened.



  • 3.  RE: Help with RAP-2WG-US

    Posted Dec 23, 2013 11:42 AM

             



  • 4.  RE: Help with RAP-2WG-US

    Posted Dec 23, 2013 11:31 AM

     

    What AOS do you have installed ?

     

    please run the following command :
    show crypto ipsec sa

    show crypto isakmp sa

     

     



  • 5.  RE: Help with RAP-2WG-US

    Posted Dec 23, 2013 11:46 AM

    @victorfabian wrote:

     

    What AOS do you have installed ?

     

    please run the following command :
    show crypto ipsec sa

    show crypto isakmp sa

     

     



    ArubaOS (MODEL: Aruba3600-US), Version 6.1.3.3

    show crypto ipsec sa

    % No active IPSEC SA

     

    show crypto isakmp sa

    % No active ISAKMP SA



  • 6.  RE: Help with RAP-2WG-US



  • 7.  RE: Help with RAP-2WG-US

    Posted Dec 23, 2013 03:42 PM

    I took the RAP to the subnet that the controller is on, and it did an upgrade automatically.  The software version on the RAP is now: ArubaOS Version 6.1.3.3 Build# 34156.

     

    The RAP now shows in the controller after upgrade, so that is at least a step forward.  From here i've tried provisioning the AP like our 105's (but also selecting remote AP).  Status will say AP Rebooting...   and never change on the RAP end after provisioning.  I can not get the RAP to do anything even after 15 minutes.  I reset and let it upgrade again.  I set a manual address this time.  Now the RAP says "Continuing......."  with nothing else showing.  AP rebooted twice while I let it sit.  AP does not show in controller.  Finally I reset again, let it upgrade, and only entered the controller IP.  It showed in the controller, but disapeared after entering the IP on the RAP.  RAP says "Continuing..."  and nothing more :(.

     

    I won't be able to look at this again until thursday morning.  Thanks for your help thus far. :)



  • 8.  RE: Help with RAP-2WG-US

    Posted Dec 26, 2013 09:09 AM

    I will be around today if anyone has any more suggestions.

     

    Thanks in advance!



  • 9.  RE: Help with RAP-2WG-US
    Best Answer

    EMPLOYEE
    Posted Dec 26, 2013 10:57 AM

    Put the RAP on the same subnet that the controller is on and let it connect to it.  After some time, run the command "show ap image version" and see if the backup partition is 5.x ".  If it is only 3.x, you will have to contact support to get help to upgrade it to 5.x, UNLESS youhave a controller that is on 5.x.  You cannot upgrade the backup partition with a controller that is 6.x.  See the article here:  https://arubanetworkskb.secure.force.com/pkb/articles/HowTo/R-1425 

     

     



  • 10.  RE: Help with RAP-2WG-US

    Posted Dec 26, 2013 11:12 AM

    @cjoseph wrote:

    Put the RAP on the same subnet that the controller is on and let it connect to it.  After some time, run the command "show ap image version" and see if the backup partition is 5.x ".  If it is only 3.x, you will have to contact support to get help to upgrade it to 5.x, UNLESS youhave a controller that is on 5.x.  You cannot upgrade the backup partition with a controller that is 6.x.  See the article here:  https://arubanetworkskb.secure.force.com/pkb/articles/HowTo/R-1425 

     

     


    Thank you for that information :)



  • 11.  RE: Help with RAP-2WG-US

    Posted Dec 31, 2013 09:42 AM
      |   view attached

    Once again, I appreciate the help thus far.  I was able downgrade the controller and upgrade the backups to 5.0.4.13 on our two RAPS.  We are now back at 6.1.3.3 again.  I have one RAP that I setup to test with internal IP of controller.  It seems to connect properly, and the wireless light turns on.  It shows in the controller, everything looks great (but can't fully test wireless connection because I can't distinguish this AP's SSID vs. our live network).


    Since everything looked great on that rap, I tried the other rap from an outside cable modem using our external address of controller.  We had success up until it rebooted.  The device reboots, Eth1 gets a self assigned ip.  Can't connect to RAP's webpage to see status.   Status light on rap continues to blink, and no wireless light comes on.  I have attached a picture for reference.  Any guidance would be appreciated.

     

    Thanks!



  • 12.  RE: Help with RAP-2WG-US
    Best Answer

    EMPLOYEE
    Posted Dec 31, 2013 09:44 AM

    Try "show ap database" when that RAP is connecting to see its status

     

    HOLD ON:

     

    You are saying that it does not work externally?  In the ap-group of the RAP, in the AP system profile of that ap-group, do you have an LMS-IP?  If you do, remove it.



  • 13.  RE: Help with RAP-2WG-US

    Posted Dec 31, 2013 12:04 PM

    Yes, that seems to have done the trick!  Thank You!

     

    I added a new ssid so I can see that it is working apart from our normal network, and it is working properly.  At this point I am happy to have it working wirelessly, but the only thing not 100% is port E1.  After being assigned an internal address, if I go to the web it still points me toward the RAP website that does not load.  Again wireless works fine.  Thanks again :)



  • 14.  RE: Help with RAP-2WG-US
    Best Answer

    EMPLOYEE
    Posted Dec 31, 2013 12:20 PM

    @ucf wrote:

    Yes, that seems to have done the trick!  Thank You!

     

    I added a new ssid so I can see that it is working apart from our normal network, and it is working properly.  At this point I am happy to have it working wirelessly, but the only thing not 100% is port E1.  After being assigned an internal address, if I go to the web it still points me toward the RAP website that does not load.  Again wireless works fine.  Thanks again :)


     

    In the Wired AP profile, you need to make sure it is enabled and Trusted Under Ethernet Interface port 1 configuration:

    wired.png



  • 15.  RE: Help with RAP-2WG-US

    Posted Dec 31, 2013 04:02 PM

    cjoseph, I can't thank you enough for your assistance.  I overlooked the trusted check box, and works perfectly now with it checked.  If I can ever return the favor, please let me know.

     

    Thanks!

    ucf



  • 16.  RE: Help with RAP-2WG-US

    EMPLOYEE
    Posted Dec 31, 2013 04:33 PM

    You are welcome, and happy new year, ucf!