Wireless Access

last person joined: 15 hours ago 

Access network design for branch, remote, outdoor and campus locations with Aruba access points, and mobility controllers.
Expand all | Collapse all

master-local connection

  • 1.  master-local connection

    Posted Mar 23, 2018 08:59 AM

    I have to add a local into a group of controllers (setup by someone else) but the connection between the new local and the master doesn't seem to be coming up. The existing locals have certs but the new one doesn't - would this be an issue. I've tried setting up a local ipsec key with 0.0.0.0 (the one used by the other locals and also with the IP of the new local. still not working - would appreciate any ideas.



  • 2.  RE: master-local connection

    Posted Mar 23, 2018 10:16 AM

    I am seeing this on the local -

    Mar 23 14:02:51  cert_dwnld[3818]: <355002> <DBUG> |cert_dwnld|  cert_downld_master_ip_resp_hdlr: Got reply from CFGM with ip x.x.x.x role 3
    Mar 23 14:02:51  cert_dwnld[3818]: <355002> <DBUG> |cert_dwnld|  cert_downld_master_ip_resp_hdlr: Setting Master ip x.x.x.x
    Mar 23 14:03:06  cert_dwnld[3818]: <355002> <DBUG> |cert_dwnld|  cert_downld_master_ip_resp_hdlr: Got reply from CFGM with ip x.x.x.x role 3
    Mar 23 14:03:06  cert_dwnld[3818]: <355002> <DBUG> |cert_dwnld|  cert_downld_master_ip_resp_hdlr: Setting Master ip x.x.x.x

     

     

    And this on the master -

    Mar 23 14:11:30  isakmpd[3803]: <103060> <DBUG> |ike|  x.x.x.x:4500-> ike_quick_mode.c:checkIpsecSelectors_LocalMaster:3893 ipsec_map peer IP:x.x.x.x SA IP:x.x.x.x map_name default-local-master-ipsecmapx.x.x.x
    Mar 23 14:11:30  isakmpd[3803]: <103063> <DBUG> |ike|  x.x.x.x:4500-> checkIpsecSelectors_LocalMaster map default-local-master-ipsecmapx.x.x.x  v:1
    Mar 23 14:11:30  isakmpd[3803]: <103063> <DBUG> |ike|  x.x.x.x:4500-> checkIpsecSelectors_LocalMaster map default-local-master-ipsecmapx.x.x.x  v:1



  • 3.  RE: master-local connection

    Posted Mar 23, 2018 11:38 AM

    You need to gain access to the configuration on the master.  It is possible that the master has specific keys for the ip address of each local.



  • 4.  RE: master-local connection

    Posted Mar 23, 2018 11:56 AM

    Hi Colin,

        I do have access to the master that is how I was able to add in the individual IP of the new local - previous the localip was configured as 0.0.0.0 - I could not get it to work with either the 0.0.0.0 or the individual IP.