Wireless Access

Reply
Occasional Contributor II
Posts: 16
Registered: ‎08-31-2010

Problem getting RAP5-WN up - sapd_check_hbt doing tunnel down.

So I have a controller on 6.1.2.5 with several RAP-2s and RAP-5s already up and working happily.

 

I got a new RAP5.  The firmware on both the boot and backup paritions is 5.0.4.5, so I should be able to get it to attach to my 6.x controller and upgrade it.

 

But when I try to get it to attach, everything seems ok at first.  The web browser on the attached client gets successfully though

 

Uplink Status

IP Information

Gateway Ping

TPM Certificates

 

When it hits Master Connectivity I get the message

 

IP X.X.X.X using Ethernet Aborted : sapd_check_hbt id doing tunnel down

 

It then proceeds to successfully pass "LMS Connectivity"

and then spins forever on "Continuing"

 

Any ideas how to start debugging this?  I would suspect a controller config error, but I have working good RAPs off the controller.

 

Jeff

 

 

 

Aruba Employee
Posts: 509
Registered: ‎07-03-2008

Re: Problem getting RAP5-WN up - sapd_check_hbt doing tunnel down.

Haven't seen that message before.  I'd probably start with factory resetting the RAP (pin the reset button) and starting over.

Occasional Contributor II
Posts: 16
Registered: ‎08-31-2010

Re: Problem getting RAP5-WN up - sapd_check_hbt doing tunnel down.

I've already done a factory reset sever times to no avail.

Aruba Employee
Posts: 100
Registered: ‎12-02-2011

Re: Problem getting RAP5-WN up - sapd_check_hbt doing tunnel down.

Is this RAP connected at the same location as other working RAPs?

 

I hope it is added to the whitelist on the master controller.

 

When AP is trying to come-up, do you see ISAKMP SA and IPSEC SA being formed? (chow crypto isakmp sa // show crypto ipsec sa)

 

If so, check "show user-table verbose" and make sure RAP falls into the AP-Role.

 

 

Occasional Contributor II
Posts: 13
Registered: ‎04-20-2012

Re: Problem getting ARPA-WAN up - Sapp_check_WBT doing tunnel down.

[ Edited ]
One of our customers has an office in China and when they try to connect a RAP to a MS in the UK they get the same error.

 

This is because the Government is doing a reform and they have completely locked down the internet.

 

Please see below link for the article.

 

http://asia.cnet.com/expect-slow-internet-this-week-in-china-62219398.htm

Regular Contributor I
Posts: 231
Registered: ‎05-04-2011

Re: Problem getting RAP5-WN up - sapd_check_hbt doing tunnel down.

I am getting same error with a RAP-2.

 

I've even taken the RAP-2 and defaulted and connected directly to my local LAN with the controller and I'm still getting same error. I also tried removing them from whitelist and try to let them come up as a normal AP but that isn't working either.

 

IPSEC SA shows them trying to connect and show user-table verbose shows them in the AP-Role.

 

Any suggestions?

Regular Contributor I
Posts: 231
Registered: ‎05-04-2011

Re: Problem getting RAP5-WN up - sapd_check_hbt doing tunnel down.

This is output with RAP connected directly to LAN with controller. RAP is on whitelist and is pointed towards the internal LAN address of the controller.

 

 

(ADK-620) (config) #show crypto isakmp sa

ISAKMP SA Active Session Information ------------------------------------ Initiator IP     Responder IP   Flags       Start Time      Private IP ------------     ------------   -----     ---------------   ---------- 10.0.0.133       10.0.0.11      r-m-c-y-R Feb  5 09:49:00   192.168.4.181

Flags: i = Initiator; r = Responder        m = Main Mode; a = Agressive Mode v2 = IKEv2        p = Pre-shared key; c = Certificate/RSA Signature; e =  ECDSA Signature        x = XAuth Enabled; y = Mode-Config Enabled; E = EAP Enabled        3 = 3rd party AP; C = Campus AP; R = RAP        V = VIA; S = VIA over TCP

Total ISAKMP SAs: 1

 

(ADK-620) (config) #show user-table verbose | include 2f:7b 192.168.4.182  00:00:00:00:00:00  00:0b:86:c3:2f:7b               ap-role        00:00:02    VPN            10.0.0.133  N/A                                                                                    tunnel                              Internal     1

 

(ADK-620) (config) #show crypto ipsec sa

IPSEC SA Active Session Information ----------------------------------- Initiator IP     Responder IP     InitiatorID         ResponderID         Flags    Start Time      Inner IP ------------     ------------     -----------         -----------         -----  ---------------   -------- 10.0.0.133       10.0.0.11        192.168.4.182/32    0.0.0.0/0           T      Feb  5 09:53:11   192.168.4.182

Flags: T = Tunnel Mode; E = Transport Mode; U = UDP Encap        L = L2TP Tunnel; N = Nortel Client; C = Client; 2 = IKEv2

Total IPSEC SAs: 1

(ADK-620) (config) #

 

 

When I connect pc to RAP-2 E1 is shows the following on the browser.

 

Successful eth0 interface up

Successful IP 10.0.0.133 mask 255.255.255.255.0 Gateway 10.0.0.7

Gateway Ping successfull

TPM Certificates successfull

Master Connectivity  IP 10.0.0.11 ((Controller LAN address)) using Eternet Aborthed sapd_check_hbt is doing funnel down

LMS Connectivity Successful LMS IP 10.0.0.11 using Ethernet

Aruba Employee
Posts: 4
Registered: ‎12-10-2013

Re: Problem getting RAP5-WN up - sapd_check_hbt doing tunnel down.

I am also experincing same issue. Could you let me know what is the current code version on the controller and RAP's backup partition?

Contributor II
Posts: 41
Registered: ‎06-07-2010

Re: Problem getting RAP5-WN up - sapd_check_hbt doing tunnel down.

[ Edited ]

We're seeing this error with controller ArubaOS 6.3.1.3 and RAP OS 5.0.4.0.

Occasional Contributor II
Posts: 13
Registered: ‎04-13-2009

Re: Problem getting RAP5-WN up - sapd_check_hbt doing tunnel down.

Hi, 

 

i have excatly the same pb with controller ArubaOS 6.3.1.3 and RAP5-WN OS 5.0.4.0....

Search Airheads
Showing results for 
Search instead for 
Did you mean: