<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AP rejected on vSG &amp;quot;because of ACL setting&amp;quot; in SmartZone and Virtual SmartZone</title>
    <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19728#M1213</link>
    <description>Hi Jim,&lt;BR /&gt;The ACL setting referred to here is for the lwapp2scg conversion utility that allows ZD-based APs to connect to the SZ. In the SZ CLI, you can change this setting:&lt;BR /&gt;


&lt;P&gt;&lt;B&gt;vSZ#&lt;/B&gt; config&lt;/P&gt;
&lt;P&gt;&lt;B&gt;vSZ (config)#&lt;/B&gt; lwapp2scg&lt;/P&gt;
&lt;B&gt;vSZ (config-lwapp2scg)#&lt;/B&gt; policy accept-all&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If the problem persists after this, try (just for confirmation) to change the policy to "accept" and then enter a rule (vSZ (config-lwapp2scg)# &lt;I&gt;acl-ap...&lt;/I&gt;) to add an allow rule for that specific AP.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Also, can you share what build you are working from?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;thanks,&lt;BR /&gt;Marcus&amp;nbsp; &amp;nbsp;</description>
    <pubDate>Thu, 18 Jan 2018 19:32:29 GMT</pubDate>
    <dc:creator>marcus_burton</dc:creator>
    <dc:date>2018-01-18T19:32:29Z</dc:date>
    <item>
      <title>AP rejected on vSG "because of ACL setting"</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19727#M1212</link>
      <description>I am unable to add multiple R600 APs at a remote site to our vSZ. I'm moving them from a local (to them) ZD to a remote (central location) vSZ, but the procedure I've used many times no longer works. I factory defaulted the AP, then "set director ip xxx.xxx.xxx.xxx" and rebooted, and it does contact the vSZ, but the controller is rejecting it with this error:&lt;BR /&gt;&lt;BR /&gt;"&lt;BR /&gt;ZD-AP [obscured] model [R600] is not being upgraded with Virtual SmartZone AP firmware because of ACL setting."&lt;BR /&gt;&lt;BR /&gt;I then tried upgrading the AP to 100.x standalone firmware, but same results... it gets rejected with that error. Any idea what is wrong? I've added APs from remote sites&amp;nbsp; with no problem, so this is a first for me.</description>
      <pubDate>Thu, 18 Jan 2018 18:34:04 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19727#M1212</guid>
      <dc:creator>jim_michael</dc:creator>
      <dc:date>2018-01-18T18:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: AP rejected on vSG "because of ACL setting"</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19728#M1213</link>
      <description>Hi Jim,&lt;BR /&gt;The ACL setting referred to here is for the lwapp2scg conversion utility that allows ZD-based APs to connect to the SZ. In the SZ CLI, you can change this setting:&lt;BR /&gt;


&lt;P&gt;&lt;B&gt;vSZ#&lt;/B&gt; config&lt;/P&gt;
&lt;P&gt;&lt;B&gt;vSZ (config)#&lt;/B&gt; lwapp2scg&lt;/P&gt;
&lt;B&gt;vSZ (config-lwapp2scg)#&lt;/B&gt; policy accept-all&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If the problem persists after this, try (just for confirmation) to change the policy to "accept" and then enter a rule (vSZ (config-lwapp2scg)# &lt;I&gt;acl-ap...&lt;/I&gt;) to add an allow rule for that specific AP.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Also, can you share what build you are working from?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;thanks,&lt;BR /&gt;Marcus&amp;nbsp; &amp;nbsp;</description>
      <pubDate>Thu, 18 Jan 2018 19:32:29 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19728#M1213</guid>
      <dc:creator>marcus_burton</dc:creator>
      <dc:date>2018-01-18T19:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: AP rejected on vSG "because of ACL setting"</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19729#M1214</link>
      <description>Thank you! This solved my problem immediately. Appreciate the help,.</description>
      <pubDate>Thu, 18 Jan 2018 20:01:18 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19729#M1214</guid>
      <dc:creator>jim_michael</dc:creator>
      <dc:date>2018-01-18T20:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: AP rejected on vSG "because of ACL setting"</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19730#M1215</link>
      <description>I have met same problem.&lt;BR /&gt;&lt;BR /&gt;At that time, I did diabling&amp;nbsp; and re-enabling the command as "policy accept-all".&lt;BR /&gt;&lt;BR /&gt;As a result this solved.&lt;BR /&gt;&lt;BR /&gt;It may a bit bug becaue default setting is "policy accept-all".</description>
      <pubDate>Fri, 19 Jan 2018 04:09:31 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19730#M1215</guid>
      <dc:creator>hyosang_choi</dc:creator>
      <dc:date>2018-01-19T04:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: AP rejected on vSG "because of ACL setting"</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19731#M1216</link>
      <description>Solved our problem as well - thank you!</description>
      <pubDate>Fri, 20 Jul 2018 04:56:53 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19731#M1216</guid>
      <dc:creator>new_life_it</dc:creator>
      <dc:date>2018-07-20T04:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: AP rejected on vSG "because of ACL setting"</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19732#M1217</link>
      <description>Yep, same here. Thanks!&amp;nbsp;</description>
      <pubDate>Sat, 18 Aug 2018 21:01:44 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19732#M1217</guid>
      <dc:creator>greg_marcoux</dc:creator>
      <dc:date>2018-08-18T21:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: AP rejected on vSG "because of ACL setting"</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19733#M1218</link>
      <description>I hope I'm not hi jacking this thread I thought this was my issue as well becuase of the "ACL" error which is &lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ZD-AP [MAC/Serial #]&amp;nbsp; model [R600] is not being upgraded with Virtual SmartZone AP firmware because of ACL setting.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;BUT the recommended change to the Smartzone lwapp2scg policy, did not solve my problem.&amp;nbsp; I have an open support case on this but they haven't been very responsive thus far.&amp;nbsp; I have tried both accept-all and accept (along with adding the MAC of the AP).&amp;nbsp; In both cases and all along here is what the get syslog log on the AP is showing:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;-------Begin AP Log----&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Oct 30 16:04:12 RuckusAP local2.err syslog: (ap state) AP begin to join ac.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Oct 30 16:04:25 RuckusAP daemon.err wsgclient[486]: httpRecv:315 http status is 400&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Oct 30 16:04:25 RuckusAP daemon.err wsgclient[486]: crHttpRequestWithAuth:472 ret:116&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Oct 30 16:04:25 RuckusAP daemon.err wsgclient[486]: registration:676 Failed to send Discovery packet! ret:116&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Oct 30 16:04:57 RuckusAP daemon.err wsgclient[486]: httpRecv:315 http status is 400&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Oct 30 16:04:57 RuckusAP daemon.err wsgclient[486]: crHttpRequestWithAuth:472 ret:116&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Oct 30 16:04:57 RuckusAP daemon.err wsgclient[486]: registration:676 Failed to send Discovery packet! ret:116&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Oct 30 16:05:16 RuckusAP local2.err syslog: Proceed to IDLE state from JOIN state, no resp after 15 re-transmits&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;-------End AP Log-------&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I migrated 21 APs but the 22nd isn't wanting to move(actually it was the 12th or 13th ap to migrate, just saying I moved all but 1 by using the following commands:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Manually upgrade ZD aps to a new smart zone controller:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Establish an SSH connection to an AP&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;set factory&lt;/P&gt;

&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;reboot&lt;/P&gt;

&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;&amp;nbsp;Reconnect with SSH&lt;/P&gt;

&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;fw set host
172.xxx.xxx.xxx&lt;/P&gt;

&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;fw set proto tftp&lt;/P&gt;

&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;fw set user
xxxxxxxxx&lt;/P&gt;

&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;fw set password
xxxxxxx&lt;/P&gt;

&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;fw set port 69&lt;/P&gt;

&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;fw set control
R600_104.0.0.0.1347.bl7&lt;/P&gt;

&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;fw update&lt;/P&gt;

&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;set director ip
172.xxx.xxx.xxx&lt;/P&gt;

reboot&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;And TADA for all except 1....&amp;nbsp; I have 2 more locations to move and I have to stagger them.&amp;nbsp; Fortunately it is only one AP in 1 facility thus far that has this issue but I need to resolve it and I'm sure I have a dead/weak spot.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Thanks</description>
      <pubDate>Wed, 30 Oct 2019 18:32:07 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19733#M1218</guid>
      <dc:creator>john_duling</dc:creator>
      <dc:date>2019-10-30T18:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: AP rejected on vSG "because of ACL setting"</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19734#M1219</link>
      <description>So ...There is also a certificate check that might need to be disabled apparently:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;A alt="" href="https://support.ruckuswireless.com/articles/000005390" name="" rel="nofollow" target="" title="" type="" value=""&gt;https://support.ruckuswireless.com/articles/000005390&lt;/A&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I forget the exact command I think it was SSH to SZC enter configure mode and type &amp;gt;&amp;gt; &lt;BR /&gt;ap-cert-check&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I could be wrong on the exact command, that is what I recall though.&amp;nbsp; Once disabled the AP was able to register and connect fine.&amp;nbsp; After all APs are connected I will then need to go to System &amp;gt;&amp;gt; Certificates &amp;gt;&amp;gt; AP Certification Replacement and update the certificates for any aps that don't pass the check correctly.&amp;nbsp; When I do update the ap certificate, there is the possibility of some downtime on the aps that must update their certificate, if I understood support correctly.</description>
      <pubDate>Thu, 31 Oct 2019 18:56:18 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19734#M1219</guid>
      <dc:creator>john_duling</dc:creator>
      <dc:date>2019-10-31T18:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: AP rejected on vSG "because of ACL setting"</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19735#M1220</link>
      <description>Hello cdshow,&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I am adding the correct commands , on the AP side to validate if the certificate is correct you can execute below command,&amp;nbsp;If the output contains the string "RuckusPKI", it means the AP has the new certificate, otherwise,it has the old certificate.&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;rkscli:&amp;nbsp; get rpki-cert issuer&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;*The old certificate looks like below :&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;rkscli: get rpki-cert issuer&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Issuer: Ruckus Wireless, Inc.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;OK&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;*Whereas the new certificate is as below :&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;rkscli:&amp;nbsp; get rpki-cert issuer&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Issuer: RuckusPKI-DeviceSubCA-2&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;OK&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;*For disabling the Cert check from the controller (to connect AP with old cert) you can run the command:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vszh-251&amp;gt; enable&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Password: ***********&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vszh-251# config&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vszh-251(config)# no ap-cert-check&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Do you want to continue to disable (or input 'no' to cancel)? [yes/no] yes&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vszh-251(config)# exit&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;*For enabling the Cert check from the controller you can run the command:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vszh-251&amp;gt; enable&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Password: ***********&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vszh-251# config&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vszh-251(config)# ap-cert-check&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Successful operation&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vszh-251(config)# exit&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;At last to validate the cert check config on controller :&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vszh-251# show running-config ap-cert-check&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Best Regards&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Vineet&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Mon, 04 Nov 2019 12:00:53 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/AP-rejected-on-vSG-quot-because-of-ACL-setting-quot/m-p/19735#M1220</guid>
      <dc:creator>Vineet_nejwala</dc:creator>
      <dc:date>2019-11-04T12:00:53Z</dc:date>
    </item>
  </channel>
</rss>

