Network Management

last person joined: yesterday 

Keep an informative eye on your network with HPE Aruba Networking network management solutions
Expand all | Collapse all

SSL Error between RAP and airwave

This thread has been viewed 1 times
  • 1.  SSL Error between RAP and airwave

    Posted Jan 12, 2018 12:12 PM

    Hi all

    Since a few months, I have a strange issue with some RAP (3WN): when a RAP is factory reset, sometime I no longer able to communicate with my airwave server. A "show log provision" show   "Error establishing SSL connection to AMP server at ip xx.xx.xx.xx: ASN no signer error to confirm failure" "show log ap-debug" say: "Failed to establish SSL connection: Error code is -1:ASN no signer error to confirm failure". 

    I have about 3500 RAPs and only a few one (about 20) have this behavior.

    Someone any Idea?

    Thanks

     Allan



  • 2.  RE: SSL Error between RAP and airwave

    EMPLOYEE
    Posted Jan 12, 2018 02:13 PM

    I haven't observed this behavior, seems like it might get better traction in a support case.



  • 3.  RE: SSL Error between RAP and airwave

    EMPLOYEE
    Posted Jan 12, 2018 03:23 PM

    We would have to confirm that the device had access to NTP and got the correct time.  If the time is incorrect, it would think that the Airwave server's certificate is not yet valid.  On the other hand, a A RAP5WN can only be connected to a controller as a RAP, and not to Airwave.  Are you sure you have that model correct and what method are you using to connect the AP.



  • 4.  RE: SSL Error between RAP and airwave

    Posted Jan 16, 2018 09:56 AM

    Hi

     To clear some things (may be my vocabulary isn't exact). I'm talking about the Device type: RAP-3WN. We use them as remote access points with following deployment process:

    1. The RAP3-WN connects first to activate.arubanetworks.com and gets its provisioning rule: IAP to Airwave. (this part is working)
    2. The RAP3-WN connect to our Airwave server and ask about its configuration. (Here is our Problem – the 2 devices are able to communicate – I can see traffic with tcpdump. But the RAP3-WN gets the mentioned errors)
    3. When the RAP-3WN has its configuration, it connect to one of our controller and build up the VPN tunnel.

     NTP is accessible by ping and show clock display the exact time. Activate and the airwave server are reachable.

    A support case was already open, but after weeks of troubleshooting the “problem-devices” have been replaced (RMA), and now I’ve got some new devices with this problem.



  • 5.  RE: SSL Error between RAP and airwave

    EMPLOYEE
    Posted Jan 16, 2018 10:07 AM

    You should continue working with TAC.

     

    How did you execute "show clock" on the AP?  Do you have a console cable?



  • 6.  RE: SSL Error between RAP and airwave

    Posted Jan 16, 2018 10:09 AM

    "How did you execute "show clock" on the AP?  Do you have a console cable?"

     

    Yes.



  • 7.  RE: SSL Error between RAP and airwave

    EMPLOYEE
    Posted Jan 16, 2018 10:18 AM

    What version of InstantOS does the RAP-3WN have on them if they cannot contact Activate/Airwave?



  • 8.  RE: SSL Error between RAP and airwave

    Posted Jan 16, 2018 11:19 AM

    RAP-3WN : 6.4.4.8-4.2.4.5_57965

    Airwave : 8.2.4

    And as I already told, I've got about 3500 RAPs working fine. The "problem RAPs" were also working fine until I did a factory reset.



  • 9.  RE: SSL Error between RAP and airwave