I have both vSZ & Data Plane instances installed. I have an issue where when enabled in tunnel mode, it stops broadcasting the SSID for some strange reason. However when I do disable the tunneling method in vSZ - the AP starts to broadcast the SSID again. I have these instances installed on a bare metal @ a colocation center.
Any ideas about what it could be? I read a post on here about doing the:
However I'm not entirely sure what it is that I'm looking for in this output. It says on that post that the AP may not be able to see the controller when doing data plane functionality?
I'm currently running this environment in Essentials mode.
The first step to see what the issue is would be to make ping and trace-router from AP to external vDP address (NAT IP), and from vDP to AP (external) IP address. From your description is not clear how AP is connected to the network.
Typical multisite configuration is that both sides (vSZ + vDP) and AP are behind Firewall with NAT. Management tunnel from AP to vSZ uses different ports and different destination IP (vSZ NAT IP). It works as much as I understand.
Data tunnel need to be established from AP internal IP through firewall with NAT to external vDP address (vDP NAT IP) and it uses different port. So you need to check all route -- if local firewall permits outgoing connection on ports UDP 23233/23233, if on vSZ/vDP side firewall allows this connection in and NATs it to vDP internal IP, that default route is set properly on vDP data interface, so it can send a reply to AP and firewall allows it... You have to look on both firewalls if tunnel setup actually is initiated and if replies are sent and received.
There will be 3 tunnel formed.
Make sure these devices can reach each other for each tunnel.
I'm able to ping the vSZ from the vDP. As well as from vDP to vSZ.
Doing the "Get scg" command via the AP:
------ SCG Information ------
SCG Service is enabled.
AP is managed by SCG.
Server List: 192.168.8.7,PUBLIC-IP
SSH tunnel connected to PUBLIC-IP
Failover List: Not found
Failover Max Retry: 2
DHCP Opt43 Code: 6
Server List from DHCP (Opt43/Opt52): Not found
SCG default URL: RuckusController
SCG config|heartbeat intervals: 30|30
SCG gwloss|serverloss timeouts: 1800|7200
Controller Cert Validation : disable
From the AP itself, these are located remotely. It shows the LAN IP 192.168.8.7 (vSZ) in the server list, but that's the LAN IP from the controller itself behind a router located at our colo.
My server is a different IP than the NAT IP I assigned my vSZ. So do I need to remove the PUBLIC-IP of the controller above, and make that the server IP (which is my router) ?
Router <--- 220.127.116.11 - 18.104.22.168 (5 IP Block)
vSZ <---- LAN 192.168.8.7 -- (WAN)22.214.171.124
vDP <---- LAN 192.168.8.11
My H510 (at a location) is pointed at the controller: 126.96.36.199
The LAN side behind my router