Wireless Access

last person joined: 8 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Ping APs (again) CAP on Controller

This thread has been viewed 5 times
  • 1.  Ping APs (again) CAP on Controller

    Posted May 12, 2016 04:19 AM

    Hi,

    iam using 6.4.4.5 on 7010 and the APs are not pingable from other subnets. In the AP System Profile there is ap-uplink-acl (default) that normally allows ICMP. So i think this "issue" comes with CPSEC enabled and has something to do with the tunnel list for the AP. Is this a "issue" or a well known configuration and canthis behavior changed ?

     

    In my case we want to allow the DHCP Servers to ping the Clients to check the leases (ip adress conflict check, which is not possible if the device won't answer)

     

     

    Thanks for Feedback



  • 2.  RE: Ping APs (again) CAP on Controller

    EMPLOYEE
    Posted May 12, 2016 06:21 AM
    You should open a case. I think this should be fixed already.


  • 3.  RE: Ping APs (again) CAP on Controller

    Posted May 12, 2016 01:06 PM

    Would love to hear if this is fixed.

     

    We ran into this a few months ago.

    Don´t remember all details, but what worked was a ping from the controller.

    Anything outside the LAN where the AP is placed could not ping the AP.

     

    We opened a case and were told that this is a known behaviour and related to CPSEC.

     

    Christian

     

     



  • 4.  RE: Ping APs (again) CAP on Controller

    EMPLOYEE
    Posted May 12, 2016 01:58 PM

    Okay.  Let me check.



  • 5.  RE: Ping APs (again) CAP on Controller

    Posted May 13, 2016 02:38 AM

    Ticket is open... 



  • 6.  RE: Ping APs (again) CAP on Controller
    Best Answer

    Posted May 23, 2016 02:56 AM

    Feedback from TAC: You actually need your "Ports" on the controller enabled as "routed" Ports so the back way from Controller to the Subnet of the ICMP Source can be reached "routed".