Wireless Access

Reply
Occasional Contributor II
Posts: 39
Registered: ‎08-08-2011

Problems with a RAP-5WN Connecting Through a Cisco ASA

Like the subject says - I have a RAP-5WN, connecting to a public IP address on our Cisco ASA, the ASA has a static translation to the controller IP on the inside from the public IP address being used - port 4500 UDP is open - unable to hit the controller from the RAP. Anyone had the pleasure of this problem???

 

Thanks

James

MVP
Posts: 2,948
Registered: ‎10-25-2011

Re: Problems with a RAP-5WN Connecting Through a Cisco ASA

[ Edited ]

is this is a new rap? that has never connected to that controller?

Becuase is that is the case you need to open also the TFTP ports

 

These are the ports you need to open on your ASA

 

For Remote AP, the following are required:

1- TFTP (UDP 69) - when the AP has corrupted image or to download a new image

2- NATT (UDP 4500)

After the RAP IPSec connection is formed, all PAPI/GRE are tunneled through this IPSec nat-t session.
----------------------------------------------------
Product Manager - Aruba Networks
Alternetworks Corp
Guru Elite
Posts: 20,789
Registered: ‎03-29-2007

Re: Problems with a RAP-5WN Connecting Through a Cisco ASA

What does your permit statement for UDP4500 look like?

 



Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Occasional Contributor II
Posts: 39
Registered: ‎08-08-2011

Re: Problems with a RAP-5WN Connecting Through a Cisco ASA

Ok - was being dumb........i had a layer three boundary set up on my controller to bring VIA and RAP connections in through a seperate ADSL connection while I waited for an upgrade to our main internet connection......this ADSL connection was still the default gateway for the controller so requests were merrilly coming in one way then out the other.....DOH!!! Changed this and all seems happy now. Have suitably slapped myself for sillyness!!

 

;)

 

Thanks for taking the time to try to help!

Search Airheads
Showing results for 
Search instead for 
Did you mean: