Wireless Access

last person joined: 20 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Control Plane Security issue

This thread has been viewed 2 times
  • 1.  Control Plane Security issue

    Posted Apr 16, 2013 07:28 PM

    I have a master/local setup. When I enable the CPSec, I get the following error on the master.

    "An internal system error has occurred at file sapd_redun.c function redun_init_tunnel_master line 3080 error Unable to open /tmp/num_ipsec"

    The controllers are running version 6.1.3.7.

    If I disable control plane security, everything works fine. Has anyone seen or experienced the error above?

     



  • 2.  RE: Control Plane Security issue

    EMPLOYEE
    Posted Apr 17, 2013 12:58 AM

    It is actually cosmetic and should only be seen the first time that access points come up.

     

     



  • 3.  RE: Control Plane Security issue

    Posted Apr 17, 2013 10:37 AM

    Here's the issue though:

     

    When CPsec is enabled, the master controller IP becomes the switch IP of the APs, not the local controller. In the AP system profile, the LMS IP points to the local controller.

    If I disable CPsec, the APs are pointed to the local controller and everything works fine. 



  • 4.  RE: Control Plane Security issue

    EMPLOYEE
    Posted Apr 17, 2013 10:57 AM
    The access points point to the master to get their CPSEC certificate. This process takes 8 to 10 minutes. When they are done, it should go to the proper controller.


  • 5.  RE: Control Plane Security issue

    Posted Apr 17, 2013 11:51 AM

    Well, it has been more than 10 minutes and the switch IP of the APs is still the master's IP. How can I tell where it is failing?



  • 6.  RE: Control Plane Security issue

    EMPLOYEE
    Posted Apr 17, 2013 01:14 PM
    The ap system profile has the local as the lms-ip?


  • 7.  RE: Control Plane Security issue

    Posted Apr 17, 2013 01:34 PM

    Yes. Like I said, as soon as I disable the CPsec and reboot the APs, APs are pointed to the Local controller. The auto cert provisioning is already enabled.