Cloud Managed Networks

 View Only
Expand all | Collapse all

AOS8 to 10 Migration - Pre-Validate Failure (dns error)

This thread has been viewed 86 times
  • 1.  AOS8 to 10 Migration - Pre-Validate Failure (dns error)

    Posted Mar 29, 2024 07:51 AM
    Edited by MH33 Mar 29, 2024 08:10 AM

    The controller and APs are currently running 8.10.0.5 LSR

    We are migrating AOS8 Campus APs to Central. When trying to do a pre-validate check from the controller all APs are failing with the following error message :  

    Pre Validate Failed  dns error(Central) device-uswest4.central.arubanetworks.com  

    I was able to SSH into the AP and confirmed that it can resolve DNS, including the central FQDN, and also reach the internet

    As an extra validation, I ran a capture on the APs switchport. During the pre-validation, I see the AP resolve the record, but then it never attempted to reach out to any of the returned IPs.   It only reaches out to devices.arubanetworks.com

    I opened a TAC case, and they responded that they don't support migrations from AOS8 to AOS10???  We would need to involve Aruba professional services, even though this is a specific question about the documented process.

    Has anyone seen this error in the past and/or have recommendations on how to proceed?   Is it possible its a bug in the AOS8 code they are on (8.10.0.5).  I searched the defect database but could not find any documented bugs. 

    My only idea now is to upgrade to a later 8.10 version.

    If the documented method of converting AOS8 controller-managed APs doesn't work, what other methods are there to migrate a few hundred APs?



  • 2.  RE: AOS8 to 10 Migration - Pre-Validate Failure (dns error)

    Posted Mar 30, 2024 08:18 AM

    The documented method does work, we have done over 100 of them.  I have seen this error once or twice.  I got around it by changing the native VLAN on the port so the AP gets a fresh set of info from the DHCP server.  Then do a clear and use no-prevalidation on the ap convert command.  The ap convert process isn't perfect but it does work.  I'm guessing it's a bug too.  



    ------------------------------
    DanOBrien
    ------------------------------



  • 3.  RE: AOS8 to 10 Migration - Pre-Validate Failure (dns error)

    Posted Mar 31, 2024 07:22 AM

    I did some testing with 345 and a 503r using a virtual controller. 
    What I noticed on my firewall is that you need to open DNS, NTP and HTTPS. For NTP and DNS you can get away with running it locally as well. I did not run into any issues. Was running aid 8.9.

    There is a thread about it. What did your firewall report?



    ------------------------------
    Martijn van Overbeek
    Architect, Netcraftsmen a BlueAlly Company
    ------------------------------



  • 4.  RE: AOS8 to 10 Migration - Pre-Validate Failure (dns error)

    Posted Mar 31, 2024 09:28 AM

    Our Aruba SE replicated the issue in his lab, so I know it is not an issue with this specific environment.   I know it is not a firewalling issue because a capture of the switch port never sees the AP trying to communicate out.

    The workaround right now is forgoing the pre-validation and forcing the migration without the checks.

    The APs I have tested with so far have been successful, but unfortunately, without the pre-validation, we run the risk of an AP not being properly added to Greenlakes and having to track it down.

    For anyone in the future, the command is:  ap convert active specific-aps local-flash "image-name" no-pre-validation

    I'm waiting to hear back if this is a bug in just 8.10.0.5 or if potentially other 8.10 releases are impacted. 




  • 5.  RE: AOS8 to 10 Migration - Pre-Validate Failure (dns error)

    Posted Oct 17, 2024 04:00 AM

    Hey everyone, I'm facing the same issue while migrating APs from AOS8 to AOS10. Following Aruba's guidance, I'm updating the APs to ArubaOS_Hercules_10.4.1. I've used the no-pre-validation command to force the migration, but I've noticed that the APs aren't properly registering in Aruba Central after the process, unless I perform a physical reset. This isn't a viable option since I have hundreds of APs to migrate. Has anyone managed to solve this issue without needing to physically reset the APs? Or is there any update regarding a fix for this bug in version 8.10.x?




  • 6.  RE: AOS8 to 10 Migration - Pre-Validate Failure (dns error)

    Posted Oct 17, 2024 09:13 AM

    What we eventually did was just convert the APs to Instant Access on AOS 8 through the controller and then do the upgrades through Aruba Central, that worked fine.

     

    Martijn Paul van Overbeek
    Architect
    Work 443-333-5809
    Mobile 984-528-1279
    Email mvanoverbeek@blueally.com

     






  • 7.  RE: AOS8 to 10 Migration - Pre-Validate Failure (dns error)

    Posted Oct 17, 2024 09:41 AM

    Thanks for the suggestion, Martijn. Unfortunately, I'm dealing with AP 315 models, which don't support conversion to Instant AP directly on version 8 of my controller. That's why Aruba Support recommended updating them to version 10.x. However, I encountered this issue during the migration, where the APs don't register in Aruba Central unless I perform a physical reset. Any ideas or workarounds for AP 315 models that could help in this situation?




  • 8.  RE: AOS8 to 10 Migration - Pre-Validate Failure (dns error)

    Posted Oct 17, 2024 01:10 PM

    I am not familiar with the 315 versions but aren't you able to upgrade to an 8.x release that will be able to act as an Instant Access?

    Converting APs to Instant APs (arubanetworks.com). Again I am not familiar with the 315 though.

     

    Martijn Paul van Overbeek
    Architect
    Work 443-333-5809
    Mobile 984-528-1279
    Email mvanoverbeek@blueally.com

     






  • 9.  RE: AOS8 to 10 Migration - Pre-Validate Failure (dns error)

    Posted Oct 17, 2024 01:17 PM
    Thanks for the response. I received guidance from Aruba Support to upgrade the AP 315 models to version 10.x, as they aren't compatible with IAP on version 8. I'm currently following that procedure, but I've run into this DNS and NTP error during the migration. Any insights on how to address this issue would be greatly appreciated


    Att,

    Leandro Silva (SAO)
    IT Infrastructure Analyst






  • 10.  RE: AOS8 to 10 Migration - Pre-Validate Failure (dns error)

    Posted Oct 17, 2024 01:28 PM

    What I find strange is that the Aruba Support page says that for instance 8.11.1.2 is supported by the AP 315.

    Again we converted the AP on the controller to an IAP AP. If that is not possible the only thing I can think of is using that procedure I shared with an 8.x release and then convert in Aruba Central. I see online that the 315 is supported on several releases in the AOS 8 series.

     

     

    Martijn Paul van Overbeek
    Architect
    Work 443-333-5809
    Mobile 984-528-1279
    Email mvanoverbeek@blueally.com

     






  • 11.  RE: AOS8 to 10 Migration - Pre-Validate Failure (dns error)

    Posted Oct 18, 2024 02:42 AM

    AP-315 is supported on 8.x versions. I have several of them running Instant in my lab and many more at customers. Controller conversion should work on these APs. At least it did in my case. 

    You can try staging Hercules image locally instead of going through Activate. 

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2024
    ------------------------------



  • 12.  RE: AOS8 to 10 Migration - Pre-Validate Failure (dns error)

    Posted Oct 18, 2024 07:00 AM

    Thanks again for the input, Gorazd. Just to clarify, my controller is running version 8.10.0.12 LSR, and when I select the AP 315 to convert it to Instant, I get an error saying that the command is not supported for this AP model. Due to this, Aruba Support recommended that I upgrade the AP 315 to version 10.x to then migrate them to Aruba Central, as a physical reset is not a viable solution given the scale of the deployment. I am trying to upgrade to ArubaOS_Hercules_10.4.1.4_90528 and encountered a pre-check error related to NTP and DNS. I appreciate your suggestion, and I'll try staging the Hercules image locally. Any additional insights are very welcome.