Please open a case with TAC on this.
Original Message:
Sent: Oct 10, 2024 02:56 PM
From: mvanoverbeek
Subject: RAP issues
What also strikes me as odd is that both tunnels have the same inner IP address
Is the AP to VPNC a point-to-multipoint tunnel?
VMC2
------------------------------
Martijn van Overbeek
Architect, Netcraftsmen a BlueAlly Company
------------------------------
Original Message:
Sent: Oct 10, 2024 02:47 PM
From: mvanoverbeek
Subject: RAP issues
I set it to 1300 initially because my Verizon FWA has an MTU of 1428.
I actually did notice that by turning of my VMC1 (still with an MTU 1300) the VMC2 (MTU1500) eventually did stabilize.
When I turned on VMC1 again VMC1 started with the alternating flapping
I will change the MTU but do want to point out that it appears to be the AP that has the flags Rc2SID that flaps.
The AP with Rc2r (VMC2) appears to be stable.
------------------------------
Martijn van Overbeek
Architect, Netcraftsmen a BlueAlly Company
Original Message:
Sent: Oct 10, 2024 02:05 PM
From: mvanoverbeek
Subject: RAP issues
I thought it was a safe number, I also noticed something about fragmentation in the IKE debugging messages.
I changed it back to 1500
And see if that helps
------------------------------
Martijn van Overbeek
Architect, Netcraftsmen a BlueAlly Company
Original Message:
Sent: Oct 10, 2024 01:38 PM
From: chulcher
Subject: RAP issues
Why did you change the MTU?
------------------------------
Carson Hulcher, ACEX#110
Original Message:
Sent: Oct 10, 2024 01:32 PM
From: mvanoverbeek
Subject: RAP issues
I followed the guidelines and setup two controllers in a cluster with two separate IP addresses
I set the MTU on the VLAN to 1300
I used a DNS record to point to two separate Public IP addresses
When the IPSEC tunnel gets established VMC1 (Spectrum Cable Internet) seems to be fine
VMC2 (Google Fiber) however keeps flapping
I reviewed the configurations and could find a whole lot of differences
Left side is the snippet from VMC1 that is working while right side is from VMC2 that is not working.
When issueing show ap database the tunnel keeps flapping
Below a screenshot of some of the logs that might give in indication where this is coming from. Hope anyone has an idea.
Below the raw logs, appreciate some feedback
Thank you
------------------------------
Martijn van Overbeek
Architect, Netcraftsmen a BlueAlly Company
Original Message:
Sent: Oct 08, 2024 01:38 PM
From: chulcher
Subject: RAP issues
LMS/B-LMS configuration allows the administrator to move the device to other VPNCs as needed.
LMS for RAP is usually best pointed at a DNS A record configured for round robin, using all of the public IP addresses for the one cluster or all of the VPNC at a single datacenter. Utilize B-LMS if necessary to fail over to a secondary VPNC or datacenter. Use a cluster or VRRP to provide redundancy within a single datacenter.
------------------------------
Carson Hulcher, ACEX#110
Original Message:
Sent: Oct 08, 2024 01:26 PM
From: mvanoverbeek
Subject: RAP issues
Update:
I actually have it working now finally
Initially I did not have the Public IP address configured in the RAPGROUP under LMS
I also did not use the command allowlist-db rap add mac-address 90:4c:81:c0:f6:e2 ap-group RAPGROUP
Initially these commands did not do anything. Eventually I rebooted my Verizon 5G router and that did the trick. Maybe the NAT table was saturated, unclear but at least it works.
Question though, it is really necessary to configure the LMS in the RAP group? Curious how that works if you have multiple Public IP addresses. Because this only seems to store two at most.
------------------------------
Martijn van Overbeek
Architect, Netcraftsmen a BlueAlly Company