Controllerless Networks

last person joined: yesterday 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget

Can't ping IAPs from LAN over IPSec Tunnel

This thread has been viewed 0 times
  • 1.  Can't ping IAPs from LAN over IPSec Tunnel

    Posted Sep 01, 2016 09:57 AM

    Hello,

     

    I have created an IPSEC VPN tunnel between my IAP cluster and the Aruba Mobility Controller. I can see that an inner IP address has been assigned to the IAP VC by the IAP pool I have configured on the Mobility Controller.

     

    #show iap table

    Trusted Branch Validation: Disabled
    IAP Branch Table
    ----------------
    Name            VC MAC Address     Status  Inner IP       Assigned Subnet  Assigned Vlan
    ----            --------------     ------  --------       ---------------  -------------
    Aruba-LAB-WLC1  f0:5c:19:c1:0e:b0  UP      192.168.69.10  172.16.4.0/24

     

    I have added a static route on the core switch (All SVIs live off the core) to say 192.168.69.0/24 with next hop to the Mobility Controller. The core switch is connected to the Mobility Controller. The Mobility Controller's default gateway is pointing to the core switch. Unfortunately, when I ping the IP 192.168.69.10 from either the core switch or a host on LAN subnet, I'm getting ping timeouts.

     

    I've also tried creating a VLAN and it's L3 interface on the Mobility Controller with IP address picked from a spare IP in the IAP pool but didn't make any difference apart from being able to ping to the L3 interface on the LAN.

     

    Not sure where the problem is as it looks as though the routing is OK. The objective is to confirm connectivity from the LAN to the IAPs first before I can configure Airwave communicate with them.

     

    Your assistance is  much appreciated.