Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

CPSec issue?

This thread has been viewed 16 times
  • 1.  CPSec issue?

    Posted May 26, 2015 06:50 AM

    Hi All,

     

    Scenario...

    Controller running 6.4.2.5.

    CPsec enabled - auto cert provisioning on

     

    AP connect to the controller but the status in cpsec is certified-hold-factory-cert. When changing the status to certified-factory-cert the AP reboots and the status changes back to certified-hold-factory-cert!

     

    Here's what the controller says:

    May 26 11:46:49 <sapd 311020> <ERRS> |AP 94:b4:0f:c8:da:c0@xxx.xxx.xxx.xxx sapd| An internal system error has occurred at file sapd_redun.c function redun_retry_tunnel line 4461 error redun_retry_tunnel: Switching to clear. Error:RC_ERROR_ISAKMP_N_RSA_DECRYPTION_FAILED. Ipsec not successful after reboot.
    May 26 11:48:14 <nanny 303086> <ERRS> |AP 94:b4:0f:c8:da:c0@xxx.xxx.xxx.xxx nanny| Process Manager (nanny) shutting down - AP will reboot!
    May 26 11:49:42 <sapd 311020> <ERRS> |AP 94:b4:0f:c8:da:c0@xxx.xxx.xxx.xxx sapd| An internal system error has occurred at file sapd_redun.c function redun_retry_tunnel line 4456 error redun_retry_tunnel: Ipsec not successful to saved lms. Error:RC_ERROR_ISAKMP_N_RSA_DECRYPTION_FAILED. rebooting.
    May 26 11:49:44 <nanny 303086> <ERRS> |AP 94:b4:0f:c8:da:c0@xxx.xxx.xxx.xxx nanny| Process Manager (nanny) shutting down - AP will reboot!
    May 26 11:51:13 <sapd 311020> <ERRS> |AP 94:b4:0f:c8:da:c0@xxx.xxx.xxx.xxx sapd| An internal system error has occurred at file sapd_redun.c function redun_retry_tunnel line 4461 error redun_retry_tunnel: Switching to clear. Error:RC_ERROR_ISAKMP_N_RSA_DECRYPTION_FAILED. Ipsec not successful after reboot.
    May 26 11:52:38 <nanny 303086> <ERRS> |AP 94:b4:0f:c8:da:c0@xxx.xxx.xxx.xxx nanny| Process Manager (nanny) shutting down - AP will reboot!

     

    Can anyone shed light on this?

     

    Cheers

    James



  • 2.  RE: CPSec issue?

    Posted May 26, 2015 06:55 AM

    Have also tried deleting the AP entry and rebooting the AP, the same thing occurrs.



  • 3.  RE: CPSec issue?

    EMPLOYEE
    Posted May 26, 2015 07:27 AM

    JrWhitehead,

     

    What model of access point is this?

     



  • 4.  RE: CPSec issue?

    Posted May 26, 2015 07:29 AM

    It's an AP225.



  • 5.  RE: CPSec issue?

    EMPLOYEE
    Posted May 26, 2015 07:32 AM

    JrWhitehead,

     

    If CPSEC never worked previously with this access point, it is looking like there is a problem with the built-in certificate on this AP.



  • 6.  RE: CPSec issue?

    Posted May 26, 2015 08:01 AM

    I got the same result from 2 different AP225's. Hope they're both not broken. :(



  • 7.  RE: CPSec issue?

    EMPLOYEE
    Posted May 26, 2015 08:02 AM

    How many access points do you already have connected to the controller successfully with CPSEC?

    Do you have a redundant configuration?

     

    Please execute "show whitelist-db cpsec-status"

     



  • 8.  RE: CPSec issue?

    Posted May 26, 2015 08:05 AM

    None. CPSec is disabled.

     

    We have 2 controllers in a master-standby configuration.



  • 9.  RE: CPSec issue?

    EMPLOYEE
    Posted May 26, 2015 08:10 AM

    So, to be clear, you are trying to enable CPSEC with no access points connected to the controller(s), and then connecting the AP225s?

     



  • 10.  RE: CPSec issue?

    Posted May 26, 2015 09:18 AM

    Yes that's correct.



  • 11.  RE: CPSec issue?

    Posted Nov 09, 2015 04:17 AM

    Any update whit this problem?. I have the same issue.

     

    Two AP 225 working fine, and if I try to enable CPSec is there no way for the AP to connect to controller.

     

    Regards,



  • 12.  RE: CPSec issue?

    MVP EXPERT
    Posted Nov 09, 2015 04:29 AM

    Hi,


    Are you able paste the output of the below command?

     

    #show control-plane-security

     

    You'll need to check if the AP is in the whitelist and if the certificate has been approved or not. I believe the controller will approve the ceritifcate after a few minutes which will then cause the AP to reboot.

     

    What version of code are you running?



  • 13.  RE: CPSec issue?

    Posted Nov 09, 2015 09:48 AM

    Hi,

     

    (Aruba7210) (config) #show control-plane-security

    Control Plane Security Profile
    ------------------------------
    Parameter Value
    --------- -----
    Control Plane Security Enabled
    Auto Cert Provisioning Enabled
    Auto Cert Allow All Enabled
    Auto Cert Allowed Addresses N/A

     

    AP is in the white list but in "hold" state. I have tried to set approved state manually but I still have the same error

     

    Regards



  • 14.  RE: CPSec issue?

    Posted Nov 09, 2015 09:49 AM

    Forget to say code version: 6.4.2.13

     

    Regards



  • 15.  RE: CPSec issue?

    Posted Nov 18, 2015 11:19 AM

    Any update on this?

     

    I have the same issue. 90 APs out 100 were shown hold in the whitelist. Rebooting APs didn't help. Manually changed APs to factory certified state, still not up. APs are 104 and 135. Controller is 6.1.3.6.

     

    Then upgraded controller to 6.4.2.12. Same. Deleting AP entry in the whitelist and rebooting AP, same issue. Controller keeps saying:

     

    Nov 18 17:48:10 stm[2366]: <305048> <WARN> |stm| Dropping unsecure AP message code 16121 from AP at 192.168.17.253 (MAC address 6c:f3:7f:c2:a6:16)

     

    Nov 18 17:47:52 sapd[832]: <311020> <ERRS> |AP TMPB01WA02@192.168.17.253 sapd| An internal system error has occurred at file sapd_redun.c function redun_retry_tunnel line 3233 error redun_retry_tunnel: Switching to clear. Error:RC_ERROR_IKEP1. Ipsec not successful after reboot.

     

     



  • 16.  RE: CPSec issue?

    EMPLOYEE
    Posted Nov 18, 2015 11:21 AM

    @pydiao wrote:

    Any update on this?

     

    I have the same issue. 90 APs out 100 were shown hold in the whitelist. Rebooting APs didn't help. Manually changed APs to factory certified state, still not up. APs are 104 and 135. Controller is 6.1.3.6.

     

    Then upgraded controller to 6.4.2.12. Same. Deleting AP entry in the whitelist and rebooting AP, same issue. Controller keeps saying:

     

    Nov 18 17:48:10 stm[2366]: <305048> <WARN> |stm| Dropping unsecure AP message code 16121 from AP at 192.168.17.253 (MAC address 6c:f3:7f:c2:a6:16)

     

    Nov 18 17:47:52 sapd[832]: <311020> <ERRS> |AP TMPB01WA02@192.168.17.253 sapd| An internal system error has occurred at file sapd_redun.c function redun_retry_tunnel line 3233 error redun_retry_tunnel: Switching to clear. Error:RC_ERROR_IKEP1. Ipsec not successful after reboot.

     

     


    How many controllers do you have?  At a maintenence window, you should try turning off control plane security, or opening a TAC case.

     



  • 17.  RE: CPSec issue?

    Posted Nov 18, 2015 11:25 AM

    Only one controller. M3.

     

    I tried disabling CPSEC. However, from the wired packet capture from AP port, it still shows the AP sending ISAKMP to the controller. The controller doesn't reply at all. And AP still shown as down.

     

    Just a question: does the AP keep the CPSEC config even after reboot? What's the AP startup procedure? Say it was CPSEC to controller before, then always CPSEC? I think this is not right.

     



  • 18.  RE: CPSec issue?

    EMPLOYEE
    Posted Nov 18, 2015 11:50 AM

    When the AP comes out of the box, it tries to connect without CPSEC.  The controller will tell it to use CPSEC and then it will have to accept a certificate and then use CPSEC.  This process takes about 15 minutes.  When you turn off CPSEC, the APs will continue to try with CPSEC, and then fall back to unencrypted.  Please give it 15 minutes for this to complete.  CPSEC is really only needed if you want to bridge AP traffic using Campus APs.  If all of you traffic is tunneled, you do not need CPSEC.  Give it 15 or 20 minutes until all of your APs come up without CPSEC, and you could sidestep whatever issue you are having.

     

     

     



  • 19.  RE: CPSec issue?

    Posted Nov 18, 2015 11:56 AM

    Thanks.

     

    Sounds more logical. After disabling CPSEC, it's been hours and the down APs couldn't be up. Then I did the wire capture and found the AP still used ISAKMP. (I didn't clear the APs from the whitelist)

     

    Maybe should do this: 1) disable CPSEC; 2) clear all AP entries in whitelist; 3) reboot the APs? 4) wait for 15 mins?



  • 20.  RE: CPSec issue?

    EMPLOYEE
    Posted Nov 18, 2015 12:21 PM

    Yes.  If that doesn't work, you should contact TAC.



  • 21.  RE: CPSec issue?

    Posted Nov 19, 2015 03:53 AM

    Hi.

     

    In my case Aruba support had to connect to my controller an reinstall default controller certicate. The default certificate was corrupt so IPSEC couldn't get stablished.

     

    Regards,