Wireless Access

last person joined: 2 days ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Protocol used for master-redundancy

This thread has been viewed 0 times
  • 1.  Protocol used for master-redundancy

    Posted Jan 08, 2019 03:40 AM
      |   view attached

    We just installed two Mobility Masters in KVM platform which work as master-standby mode, then I found that the database synchronization is always failed. These two Masters belong to two different secure group in KVM,  TCP/UDP/ICMP/VRRP/ESP  are permitted.

    Do you guys happen to know which protocol is used for master-redundancy database synchronization?



  • 2.  RE: Protocol used for master-redundancy

    Posted Jan 08, 2019 03:52 AM

    For vMware you need to adjust certain default settings in order to get this to work. I'm not sure about KVM.

     

    Are there any of these settings also available on KVM?

     

    On the vSwitch: Select Promiscuous Mode and Forged Transmits check box and Accept from the drop-down list.

     

    See page 14: 

    https://community.arubanetworks.com/aruba/attachments/aruba/unified-wired-wireless-access/73285/2/Aruba%20Mobility%20Master%20and%20VMC%20Install%20Guide.pdf

     



  • 3.  RE: Protocol used for master-redundancy

    MVP EXPERT
    Posted Jan 08, 2019 04:02 AM

    Just a note, make sure if you have other VRRP instances in the same broadcast domain they are using a different VRRP ID. I had a massive headache once setting up MM's once due to the customer having another device in the same broadcast domain using the same VRRP ID that the MM's were using! :)



  • 4.  RE: Protocol used for master-redundancy

    Posted Jan 08, 2019 04:26 AM

    Hi Fabian,

     

    Thanks for you reply. Because the configuration could be synced, I think this is not caused by port configuration in vSwitch. I want to add the 'permit any any' policy for these two masters in the secure group, but the security team didn't agree to do that. So I have to tell them what protocol should be allowed exactly.