Wireless Access

last person joined: 8 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

VRRP problem

This thread has been viewed 5 times
  • 1.  VRRP problem

    Posted Jun 21, 2016 07:42 AM
    hi everyone. I faced a problem in configuring Aruba equipment. So, I have 5 controllers in Master/local config mode (2 masters and 3 locals). They are using VRRP to provide redundancy and everything seems to be ok, exept of few APs. I found, that everything is working fine if APs are provisioned to use any of controllers as master. But they are going down while they are provisioned as VRRP VirtualIP as master controller IP address. Also, note that such behavior refers to a few APs, all other are in normal operatipnal state using VRRP VIP. All the controllers are in the same vlan, thay all are 3000 models and using ArubaOS 6.3.1.13


  • 2.  RE: VRRP problem

    Posted Jun 21, 2016 08:28 AM

    Are the problem APs by chance an IAP converted to campus AP? 

     

    Also, have you manually set any of the env parameters?.



  • 3.  RE: VRRP problem

    Posted Jun 21, 2016 08:33 AM
    No, there are regular APs. They are not converted from IAPs. Also, I tried to to change env settings. I found, that there is a problem with one VRRP instance at one controller. But I cann't understand the problem because others APs are working fine on current VRRP instance.


  • 4.  RE: VRRP problem

    EMPLOYEE
    Posted Jun 21, 2016 09:55 AM
    What is the difference e between those access points and the others? It could be anything like an incorrect t subnet mask....


  • 5.  RE: VRRP problem

    Posted Jun 21, 2016 10:13 AM

    Do you have the ability to compare a "bad" AP boot sequence to a "good" AP boot sequence?



  • 6.  RE: VRRP problem

    Posted Jun 21, 2016 02:29 PM

    We need to understand the working and non-working scenarios. What exactly few AP`s are doing when it doesnt come up. As Jamie mentioned, console logs cna give some inputs to understand behavior. Wondering, what happens when you reset one of the AP and point the master to VIP address ?

     

    Thank you,

    Sriram



  • 7.  RE: VRRP problem

    Posted Jun 22, 2016 02:27 AM
    Hi, everyone I'm sure that everything is ok with TCP/IP configuration of AP. I'll try to get boot sequence logs from APs and post it here later. Also, I found that bad APs are trying to make IPsec tunnels to VIP. I checked IPsec and ISAKMP SA and found that bad APs cannot build a tunnel. IPsec SA for that APs appears for a while and goes down.. So APs don't reboot because thay can reach the controller but cannot connect to it. If I'm using just an controllers IP address as master for bad APs everything is ok.


  • 8.  RE: VRRP problem

    Posted Jun 23, 2016 04:21 AM

    Output from APs boot are in attachments.
    I found them equal. The only differense is that AP connected to XXX.XXX.XXX.30 master is ok, instaed AP connected to XXX.XXX.XXX.17.
    APs are placed in the same branch and the same vlan, both refers the same AP group.

    Attachment(s)

    txt
    AP_in_DOWN_state.txt   5 KB 1 version
    txt
    AP_in_UP_state.txt   5 KB 1 version


  • 9.  RE: VRRP problem

    Posted Jun 23, 2016 07:58 AM

    Can you get a printenv off of each one also?

     

    These APs are not doing DHCP. So there has to be an error or dissimilar configuration. 

     

    Got all network params from APboot env. Skipping DHCP
    XXX.XXX.XXX.XXX XXX.XXX.XXX.XXX XXX.XXX.XXX.XXX
    Running ADP...Done. Master is XXX.XXX.XXX.30

     

    Got all network params from APboot env. Skipping DHCP
    XXX.XXX.XXX.XXX XXX.XXX.XXX.XXX XXX.XXX.XXX.XXX
    Running ADP...Done. Master is XXX.XXX.XXX.17 

     

    Have you tried purgeenv on one of the bad APs?



  • 10.  RE: VRRP problem

    Posted Jun 23, 2016 08:02 AM
    jamie, I'll post printenv output later. I have to get it from APs, which are placed in branches. I was trying purgeenv and factory_reset commands but results was the same.


  • 11.  RE: VRRP problem

    Posted Jun 23, 2016 08:07 AM
    Understand.

    When you purge the APs are you rebooting and letting them do their thing (DHCP, ADP, etc) or are you having reconfigure them statically?

    I'm assuming .17 and .30 are in the same subnet correct?



    [aruba-hp-signature-2_160x105.jpg]

    Jamie R. Easley
    Community Administrator, ACMP, CWNA, Security + | Southeast
    M: 706.889.2719 | @Jamie_easley | SKYPE: jamie_easley
    1344 Crossman Ave | Sunnyvale , CA

    community.arubanetworks.com


  • 12.  RE: VRRP problem

    Posted Jun 23, 2016 08:18 AM
    Actually, I was trying both methods (dhcp option is also included for master discovery)... Result was the same. Yes, .17 and .30 are in the same subnet. Also, all controllers are in the same subnet, but are placed geographically distantly. OTP technology is used to combine controllers in the same vlan. So, .17 VRRP VIP address is distributed across two locations.