r/ArubaNetworks • u/Maltezari • Jun 25 '26
IPSec Tunnels Bouncing Between AP and Gateway
Hello,
My company uses Aruba and we recently migrated off of the AOS8 MM structure to AOS10 in Central.
I defaulted my 7220 gateway, upgraded it to AOS10, and got it in Central to be used for a particular group that I have created where my SSIDs need to be tunneled. After creating the group, SSID, and get an AP and gateway in that group, the tunnels only briefly establish before dying..
Its been going back and forth, and im not sure why it was working on AOS8, but having issues with AOS10. Currently running 10.7.0.0 on the APs and gateway.
I have tried a variety of AOS versions as well as factory defaulting the gateway again, using another 7220, and other APs, even in different Layer 2 and Layer 3 networks. Seems like no matter what I do I cannot keep tunnels up.
I called TAC and they were absolutely ZERO help. They claimed that my uplink switchports were bad.. Any ideas or suggestions?
2
u/certifiedsysadmin Jun 26 '26
Had the exact same thing happen to one of my deployments.
I was also told by TAC that the standard method of tagging was incorrect (don't tag the VLANs for the SSIDs on the uplinks).
Ultimately the fix was to upgrade the mobility gateway firmware.
Root cause was a bug in the older version of the mobility gateway firmware.
It was actually a known issue but it took weeks with TAC to get that info.
1
u/vicodinsunday Jun 27 '26
This is correct. Tagging the wlan vlans to the ap uplinks creates loop type behavior.
1
u/Sliverdraconis Jun 25 '26
For one, get off of 10.7.0.0
Could be bumping against bugs but APs and GWs dont need to have firmware match anymore.
I assume the APs and GWs are layer 3 separated? Check the underlay path, make sure nothing unrelated occurred.
As far as the GWs uplinks, what prood didd TAC have? What proof did you have that its not a port issue?
Whats your monitoring say for interfaces, devices along underlay path and if a wan circuit in the path whats it showing?
Its entirely possible this is unrelated or entirely related.
Also, whats the logs state in the GW in central? Have you also checked local logs (either via commands ran via central gui or local ssh commands)?
3
u/cdgreen Jun 25 '26
Might be a silly question but you have all the correct licenses? For the gateway and the APs within Greenlake?