Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Problems with a RAP-5WN Connecting Through a Cisco ASA

This thread has been viewed 2 times
  • 1.  Problems with a RAP-5WN Connecting Through a Cisco ASA

    Posted Sep 04, 2012 11:32 AM

    Like the subject says - I have a RAP-5WN, connecting to a public IP address on our Cisco ASA, the ASA has a static translation to the controller IP on the inside from the public IP address being used - port 4500 UDP is open - unable to hit the controller from the RAP. Anyone had the pleasure of this problem???

     

    Thanks

    James



  • 2.  RE: Problems with a RAP-5WN Connecting Through a Cisco ASA

    Posted Sep 04, 2012 10:20 PM

    is this is a new rap? that has never connected to that controller?

    Becuase is that is the case you need to open also the TFTP ports

     

    These are the ports you need to open on your ASA

     

    For Remote AP, the following are required:

    1- TFTP (UDP 69) - when the AP has corrupted image or to download a new image

    2- NATT (UDP 4500)

    After the RAP IPSec connection is formed, all PAPI/GRE are tunneled through this IPSec nat-t session.


  • 3.  RE: Problems with a RAP-5WN Connecting Through a Cisco ASA

    EMPLOYEE
    Posted Sep 05, 2012 06:11 AM

    What does your permit statement for UDP4500 look like?

     



  • 4.  RE: Problems with a RAP-5WN Connecting Through a Cisco ASA

    Posted Sep 10, 2012 11:35 AM

    Ok - was being dumb........i had a layer three boundary set up on my controller to bring VIA and RAP connections in through a seperate ADSL connection while I waited for an upgrade to our main internet connection......this ADSL connection was still the default gateway for the controller so requests were merrilly coming in one way then out the other.....DOH!!! Changed this and all seems happy now. Have suitably slapped myself for sillyness!!

     

    ;)

     

    Thanks for taking the time to try to help!