Wireless Access

last person joined: 10 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

rap connected through vpn upgraded to 8.6.0.4 woes

This thread has been viewed 4 times
  • 1.  rap connected through vpn upgraded to 8.6.0.4 woes

    Posted Jul 09, 2020 10:59 AM

    Hi,

     

    we have rap 115's connected through vpn connections (checkpoint) to the controller at HQ.  We're in the process of upgrading to arubaos 8.6.0.4.  I have a problem with these rap's.  They upgrade, appear in the 8.6 environment for a few minutes and then go down.  I see them going up and down constantly in the 'show ap database' output.  I called one site, and they confirmed they did no longer have wifi.

     

    I can use ap's without any problem, and rap's connected through a public ip without any problem.  These vpn connected rap's worked fine in aos 6.5.  I know we had to disable centerplane security to get this working (encrypted aruba trafic would conflict with encrypted checkpoint trafic) so this was also disabled in aos 8.6.  But still we're having issues.  I see : 

     

    Jul 9 16:42:02 isakmpd[3579]: <103103> <3579> <WARN> |ike| IPSec SA Deletion: IPSEC_delSa SPI:96e5d800 OppSPI:ea7ccf00 Dst:192.168.11.98 Src:192.168.101.248 flags:1001 dstPort:0 srcPort:0
    Jul 9 16:42:08 isakmpd[3579]: <103103> <3579> <WARN> |ike| IKE SA Deletion: IKE2_delSa peer:192.168.11.99:49154 id:3112840465 errcode:OK saflags:0x30100059 arflags:0x5
    Jul 9 16:42:08 isakmpd[3579]: <103103> <3579> <WARN> |ike| IPSec SA Deletion: IPSEC_delSa SPI:8b496400 OppSPI:9d869600 Dst:192.168.11.99 Src:192.168.101.248 flags:1001 dstPort:0 srcPort:0
    Jul 9 16:42:47 isakmpd[3579]: <103103> <3579> <WARN> |ike| IKE SA Deletion: IKE2_delSa peer:192.168.12.13:49154 id:3112840466 errcode:OK saflags:0x30100059 arflags:0x5
    Jul 9 16:42:47 isakmpd[3579]: <103103> <3579> <WARN> |ike| IPSec SA Deletion: IPSEC_delSa SPI:147e0a00 OppSPI:59975700 Dst:192.168.12.13 Src:192.168.101.248 flags:1001 dstPort:0 srcPort:0

     

    Anyone having an idea?



  • 2.  RE: rap connected through vpn upgraded to 8.6.0.4 woes
    Best Answer

    Posted Jul 13, 2020 04:14 AM

    Found the issue.  Need to disable the cluster in AOS 8.6.  This one expects rap's to connect on a public ip.  Which is difficult when a rap connects through private vpn.