Wireless Access

Reply
MVP
Posts: 330
Registered: ‎04-25-2013

RAP Redundancy won't work with VRRP

Hi,

i have configured RAP to work with the VRRP ip adresse , and i have done a NAT-T to the VRRP ip address.

i have provisioned my RAP with the VRRP IP address .

my RAP works very well with the master controller , but when the master goes down , my RAP don't establish the contact with the second controller

 

Raouf CHAHBOUNE
ICT Network & Security Engineer
CCNP R/S | CCNA Security | ACMP|ACDX



[If my post is helpful please give kudos, or mark as solved if it answers your post.]
Aruba Employee
Posts: 151
Registered: ‎02-14-2013

Re: RAP Redundancy won't work with VRRP

[ Edited ]

Hi, 

 

1. Have you configured an L2TP pool on the Standby Controller? 

2. I suppose it is a Cert based RAP. Is the RAP whitelist synced between the controllers? 

3. Are there enough Licenses on the Standby? 

 

Check the output of: 

1. show datapath session table | include <RAP-public-IP> 

2. show crypto isakmp sa 

3. show crypto ipsec sa 

4. show log all 100 | include <RAP-Name> 

 

Thanks, 
Rajaguru Vincent 

Thanks,
Rajaguru Vincent
Guru Elite
Posts: 20,821
Registered: ‎03-29-2007

Re: RAP Redundancy won't work with VRRP

It will not work if the VRRP is behind a NAT.  Instead you should (1) give both controllers individual public addresses and (2) have a DNS a-record with the two public address, where the RAP will have a single fqdn, and try the first address, then the second.  Please see herE:  http://community.arubanetworks.com/t5/Controller-Based-WLANs/Can-RAP-s-do-DNS-master-discovery/ta-p/175220

 

 

 



Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

MVP
Posts: 330
Registered: ‎04-25-2013

Re: RAP Redundancy won't work with VRRP

@Cjoseph ,i'm using NAT-T (the transversal NAT) and the VRRP virtual address.

in the RAP VRD they do not mention of this.

 

Raouf CHAHBOUNE
ICT Network & Security Engineer
CCNP R/S | CCNA Security | ACMP|ACDX



[If my post is helpful please give kudos, or mark as solved if it answers your post.]
MVP
Posts: 301
Registered: ‎04-03-2014

Re: RAP Redundancy won't work with VRRP

Hi!

 

Is this a master redundancy or a master-local setup?

 

You should check the things, Rajaguru mentioned. I´ve deployed several setup where we use a UDP 4500 port forward to an internal VRRP.

 

Cheers,

Christoffer Jacobsson | Aranya AB
Aruba: ACMX #537 ACCP | CWNP: CWNA CWDP CWSP
Search Airheads
Showing results for 
Search instead for 
Did you mean: