I would like to share some results that I got from the lab.
To simulate connectivity problem between CAP and controller I used ACL to block any traffic.
1) After ACL gets installed I see that AP detects that tunnel to controller is down (in ~8 seconds) and starts bringing down SSIDs.
AP still tries to install control channel (via IPsec) to controller but fails. After 20 minutes AP reboots with following message:
sapd[683]: <311009> <DBUG> |AP Engines@172.17.7.11 sapd| |ap| ^[msg sapd_reboot: SAPD reboot called, msg - Unable to set up IPSec tunnel, Error:RC_ERROR_IKEV2_TIMEOUT ]
After reboot AP still tries to install control channel.
2) After ACL is removed AP starts broadcasting SSID in ~30 seconds (g-radio comes up first, after that in some seconds comes up a-radio). AP doesn't need to reboot.
Hope that will help somebody.
BTW, we are using ArubaOS 6.3.1.2 (build 41362).
/ Ruske