Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

IPSEC tunnels down and APs rebooting

This thread has been viewed 2 times
  • 1.  IPSEC tunnels down and APs rebooting

    Posted Jul 11, 2014 05:42 PM

    I currently have an M3 as a master, M3 as local 1, and a 3600 as local2 all connected to a switch via trunk ports.  When i set up the IPSEC tunnels between the controllers without being connected to the existing LAN everything works fine.  As soon as I plug in my firewall connection and connection to the LAN to let the APs ride to the controller the IPSEC tunnels go down and the APs on the management VLAN all start flapping.  I am thinking this is a loop in the network.  Any input on this would be appreciated.


    #3600


  • 2.  RE: IPSEC tunnels down and APs rebooting

    EMPLOYEE
    Posted Jul 11, 2014 05:44 PM
    Do you have spanning-tree enabled?


  • 3.  RE: IPSEC tunnels down and APs rebooting

    Posted Jul 11, 2014 05:50 PM

    Yes, Spanning-tree is enabled on the controllers



  • 4.  RE: IPSEC tunnels down and APs rebooting

    EMPLOYEE
    Posted Jul 11, 2014 05:58 PM
    On the upstream switch, please check the spanning tree status to ensure nothing is being blocked.


  • 5.  RE: IPSEC tunnels down and APs rebooting

    Posted Jul 11, 2014 06:14 PM

    Upstream switch is forwarding on spanning-tree



  • 6.  RE: IPSEC tunnels down and APs rebooting

    EMPLOYEE
    Posted Jul 11, 2014 07:03 PM

    @WVTinSC wrote:

    I currently have an M3 as a master, M3 as local 1, and a 3600 as local2 all connected to a switch via trunk ports.  When i set up the IPSEC tunnels between the controllers without being connected to the existing LAN everything works fine.  As soon as I plug in my firewall connection and connection to the LAN to let the APs ride to the controller the IPSEC tunnels go down and the APs on the management VLAN all start flapping.  I am thinking this is a loop in the network.  Any input on this would be appreciated.


    If all 3 controllers are connected to the same switch, what are the IPSEC tunnnels used for?



  • 7.  RE: IPSEC tunnels down and APs rebooting

    Posted Jul 13, 2014 10:01 PM

     

    Verify on the controllers that IPSEC endpoint IPs on the controllers ARP to the correct MAC addresses.  If not, look for proxy ARP problems, e.g., check that the firewall and routers on the distribution network agree with the netmasks assigned to the vlan and are not seeing packets that they think need fixup with proxy-ARP, as hairpins through a firewall are likely to be administratively prohibited.