Wireless Access

Reply

RemoteAP to VMC (No cert? What should we configure?)

Hi AirHeads,

Good morning,

Recently We deployed VMC (Version 8.2.0.1) , My client requested RAP solution , But not like normal controller its seems that normal config process , VPN settings/IP Settings/Whitelisting isnt enough) what extra steps needed? (Please advise)

VPN POOL CONFIGURED

WHITELISTED ADDED

CONTROL PLANE SEC - AUTO CERT

PEF ENABLED

AP ENABLED

Controller log output

Nov 21 02:52:46  isakmpd[5116]: <103061> <5116> <ERRS> |ike|   IKE_CUSTOM_useCert: can't find Server-Cert
Nov 21 02:53:47  isakmpd[5116]: <103061> <5116> <ERRS> |ike|   IKE_CUSTOM_useCert: can't find Server-Cert

 

Please advise.

 

Regards,

 

Asa

 

*****************2Plus Wireless Solutions****************************
Aruba Airheads - Powered By community for empower the community
************ Don't Forget to Kudos + me,If i helped you******************
Super Contributor I

Re: RemoteAP to VMC (No cert? What should we configure?)

Hi Asa,

 

As the VMC has no TPM chip, you must first get the AP as CAP on the VMC. Then you provision the CAP to RAP with PSK and username/password,  or self signed CERT!.

 

https://www.arubanetworks.com/techdocs/ArubaOS_82_Web_Help/Content/ArubaFrameStyles/Remote_AP/Bringing_up_Certificate_Based_RAP_in_VMC.htm

 

Hope it helps.

 

 

Cheers, Frank
Aruba Partner Ambassador| AMFX#22| ACCX#613| ACMX#733| ACDX#744

If you like my posts, kudo's are welcome. If it solves your problem, please click 'Accept as Solution'
New Contributor

Re: RemoteAP to VMC (No cert? What should we configure?)

Asa, Frank

The procedure didn't work on my environment.

AP came UP as CAP and was managable.

After coverion to RAP mode with the same LMS-IP it didn't contact controller more.

Re: RemoteAP to VMC (No cert? What should we configure?)

After converting it to CAP on the VMC
Be sure that u got VPN settings / VPN pool .

Set the RAP to connect with user pass / key.
Please send me the show log security from the VMC after the RAP failed to contact .
*****************2Plus Wireless Solutions****************************
Aruba Airheads - Powered By community for empower the community
************ Don't Forget to Kudos + me,If i helped you******************

Re: RemoteAP to VMC (No cert? What should we configure?)

Also bear in mind that if you are using clustering, PSK-RAP is not supported (at least in 8.2 anyway...)


ACMP, ACSA, ACDX #985
If my post addresses your query, give kudos:)
Search Airheads
cancel
Showing results for 
Search instead for 
Did you mean: