Cloud Managed Networks

 View Only
  • 1.  5406Rzl2, user-based tunneling and aruba central template

    Posted Jul 08, 2024 10:07 AM
    Edited by Gonz Jul 08, 2024 10:17 AM

    Hi!

    I'm having some issues with 5406Rzl2 and using user based tunneling. We are deploying template based config in aruba central.

    When trying to apply user based tunneling using downloadable user roles we get this error:

    "Redirect to user-based tunnel can only be configured for V3 blade."

    So we tried:

    no allow-v2-modules

    But! When applying this in template the switch gets stuck in a never ending reboot loop. Seems like it applies this line in the config everytime the config syncs, regardless if the line is in running-config already.

    Anyone knows how to use user based tunnling on 5406 using template ?

    This what I tested to validate:

    conf
    aaa authorization user-role name test
    tunneled-node-server-redirect secondary-role "test"

    Redirect to user-based tunnel can only be configured for V3 blade.

    If v2-modules are allowed trying to apply DUR with user-based tunnel we get this in the logs:

    downloaded user role XXX-... is not valid
    as CLI execution Error.

    Faulty line: tunneled-node-server-redirect
    secondary-role

    edit: here is the show modules info:



  • 2.  RE: 5406Rzl2, user-based tunneling and aruba central template

    Posted Jul 08, 2024 10:54 AM

    You may try to execute the command outside of the template. So leave the template as is, but login, enable 'aruba-central support-mode', run the command, disable support mode.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: 5406Rzl2, user-based tunneling and aruba central template

    Posted Jul 11, 2024 06:13 AM

    Yeah I tried doing that but since we use templates the setting get overwritten after reboot when sync happens.

    Must be a prefered way to do this ?

    Might it be because we initially had a v2 module inserted on first connection with central. Maybe we need to reset the switch just to be sure ?