Hi,
I did the migration and seems like works but i got some issues:
I must change to the "trusted" (forgot this step in the procedure o I have a unidentified issue?) the uplink port (done).
The "country code" problem appears and some AP that was working now does not works:
(aruba-master) #show ap database local long flags E
AP Database
-----------
Name Group AP Type IP Address Status Flags Switch IP Wired MAC Address Serial # Port FQLN Outer IP User
---- ----- ------- ---------- ------ ----- --------- ----------------- -------- ---- ---- -------- ----
AP-Bib.Nivel-2.Edificio-3.H default 135 14.25.5.1 Up 2m:33s E 14.25.1.1 6c:XX:XX:XX:XX XXXXXXXX N/A N/A N/A
IAPN-AulaPS.Nivel-3.Edificio-8.H APsDNs 135 14.25.9.23 Up 2m:32s E 14.25.1.1 6c:XX:XX:XX:XX XXXXXXXX N/A N/A N/A
...........................
........................
Flags: U = Unprovisioned; N = Duplicate name; G = No such group; L = Unlicensed
I = Inactive; D = Dirty or no config; E = Regulatory Domain Mismatch
X = Maintenance Mode; P = PPPoE AP; B = Built-in AP
R = Remote AP; R- = Remote AP requires Auth; C = Cellular RAP;
c = CERT-based RAP; 1 = 802.1x authenticated AP; 2 = Using IKE version 2
u = Custom-Cert RAP
M = Mesh node; Y = Mesh Recovery
Port information is available only on 6xx controller.
Total APs:41
I check some things but seems like i need to change the "Country" from "US" to "MX":
(aruba-master) #show country
Country:US
Model:Aruba7220
Hardware:Unrestricted
(aruba-master) #
I have to remark that in the 6000 controller that AP was working fine and in first setup i put "MX" in the country code.
I check in the “Advanced Services > All Profile Management > AP > Regulatory Domain: “profile” move to MX reboot the AP and works (No E flag).
I have users and I test with my phone on one of the essid in production and works with the “Dynamic WPA,WPA2 8021X AES” essid used.
But when I check the user (connected/associated/authenticated) I saw in different roles that usually was just:
(Guest and authenticated roles), I check with the “GUI”: Security > Access Control > User Roles and I saw that some roles (802.1x) does not appears and other roles appears but without firewall polices “No configured”
I must to go to rollback because the time and concern about what if something more was deleted or modified.
Any Idea what was wrong?
We are thinking in do the config from scratch but I don´t have idea how to don´t modify some essids like “mesh clusters” or other profiles that have WPA-PSK key in the config…
Any idea how to do “preserve” the WPA-PSK config and cluster profiles (extract the block config of the old one config & insert in the new one?)?
Best regards.
#7220