Wired Intelligent Edge (Campus Switching and Routing)

Reply
Frequent Contributor I

Aruba OS 8.3.0.1 - problem self-signed cert for CPsec, AP 303 as Campus

Hi

We have installed virtual controller with 8.3.0.1 soft and campus AP 303.

We have problem with connecting AP to VMC with CPSec. We can provision APs and then they are rebooting twice and after that there is an error in Logs and this process starts once more i loop and so on.

 

In logs we have:

Rebooting: Unable to set up IPSec tunnel to saved lms, Error:RC_ERROR_ISAKMP_N_CERT_SELFSIGNED_VERIFY_FAILED

 When we turn off CPSec Everything is ok - APs starts and join controller normally.

 

Someone has similar problem ? Any help will be very appreciated. 

 

I have tried to genertae new self-sined cert, but without effect. I have also tried to change whitelist-db cert state - the same. 

APs and controler are in the same vlan - directly connected.

 

best regards

 

Karol

 

 

 

Occasional Contributor I

Re: Aruba OS 8.3.0.1 - problem self-signed cert for CPsec, AP 303 as Campus

Did you ever solve this?  I'm having the same issue - APs connect fine to a HW controller but fail to VMC with the same error message you see.

Frequent Contributor I

Re: Aruba OS 8.3.0.1 - problem self-signed cert for CPsec, AP 303 as Campus

Hi

 

Yes, the problem was resolved in new firmware version 

At this moment I have 8.4.0.0 and it is working fine 

What version do You have ?

 

regards

 

Karol

Occasional Contributor I

Re: Aruba OS 8.3.0.1 - problem self-signed cert for CPsec, AP 303 as Campus

I'm using 8.5.0.0 currently... bleeding edge so maybe a bug, still troubleshooting.

Frequent Contributor I

Re: Aruba OS 8.3.0.1 - problem self-signed cert for CPsec, AP 303 as Campus

Hi

 

So realy strange

So try to downgrade to 8.4.0.0. I have not yet tested  AP 303 on 8.5.0.0

 

The other difference maybe I have standalone version on VMWare

 

Be careful also about configuration in VMware. You must gone through all recommendation that are in Installation Guide (promiscous mode and so on) 

I had also problem with wrong configuration of virtual environmemt. Physical NIC was aggregated but only from server site not from switch site, which was not correct.

 

regards

 

Karol

MVP Expert

Re: Aruba OS 8.3.0.1 - problem self-signed cert for CPsec, AP 303 as Campus

There is no TPM (and Certificate) on Controller vm..




PowerArubaSW: Powershell Module to use Aruba Switch API for Vlan, VlanPorts, LACP, LLDP... More info


PowerArubaCP: Powershell Module to use ClearPass API (create NAD, Guest...) More info


PowerArubaCX: Powershell Module to use ArubaCX API (get interface/vlan/ports info)


PowerArubaIAP: Powershell Module to use Aruba Instant AP




ACMP 6.4 / ACMX #107 / ACCP 6.5
Frequent Contributor I

Re: Aruba OS 8.3.0.1 - problem self-signed cert for CPsec, AP 303 as Campus

Hi alagoutte

 

Thank You for info 

 

regards

 

Karol 

Search Airheads
cancel
Showing results for 
Search instead for 
Did you mean: