cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2339
Views
20
Helpful
11
Replies

WLC 3504 HA-SSO. I can access HTTPS/SSH but I cannot ping the management-ip

amalitol81
Level 1
Level 1

Hi guys,

I have 2xWLCs 3504 on HA-SSO configuration.

WLC1 is the primary

WLC2 is the standby-hot

 

For some reason I CANNOT ping WLC1 management and redundancy-management interfaces, but I CAN access WLC1 management interface via HTTPS/SSH.

 

On the other hand, I CAN ping WLC2 management and redundancy-management interface (It's the standby-hot WLC).

 

I'm using LAG and I have 5 ports on each WLC connected to 2xN9K switches in VPC mode. 

So far everything is working fine except for that PING issue.

 

Do you have any ideas about what could be the cause of this issue ?

 

Thank you in advance,

 

 

 

 

 

 

 

 

1 Accepted Solution

Accepted Solutions

Yes... one wlc per switch. You should test with one connection first then if that works, connect another port and see if it breaks. Might be how traffic is passing on each port on the switch. The wlc expects traffic to leave and come back on the same port.
-Scott
*** Please rate helpful posts ***

View solution in original post

11 Replies 11

Management IP address is shared by WLC1 & WLC2, so should not have unique mgt IP for two of them.

 

If you failover to WLC2 what happens ? still you cannot ping mgt IP address ?

 

HTH

Rasika

*** Pls rate all useful responses ***

Thank you for your response. Sorry for my previous post

What is actually happening is the following:
I just can ping redundancy-management IPs for both WLCs (Primary and Standby-Hot).
I can not ping the PRIMARY management IP, but I have HTTPS/SSH access.





Irrespective of which unit is active, you can't ping its management IP address, is that right ?

 

I would try put your PC/Laptop on same vlan as WLC management & see you can ping it.

 

Regards

Rasika

mmm interesting

 

Yes, it worked.  

 

From the VLAN where the management interface is defined I could ping :

management interface WLC1

redundancy-management interface WLC1

redundancy-management interface WLC2

 

 

Those are the ip’s which should be able to ping from any subnet as long as ping is not being blocked.
-Scott
*** Please rate helpful posts ***

That is right. 

Those are the IPs that should be able to ping but I just can ping the redundancy-management IPs from another subnet.

Guys,

 

This is really weird, but I think I found the solution but not the cause of the issue. 

Few days ago I connected the ports 1-to-4 on WLC1 and WLC2 with links to 2 x Nexus SWs on VPC mode. Previous it was just connected to port 5 on both WLCs to the same N9K switches. 

The configuration is LAG for ports 1-to-5  and I used two port-channels for each WLC allowing the same VLANs, including the management vlan. So it's a big TRUNK covering all the ports on the WLCs and it has all the VLANs (management + users). sEE THE TOPOLOGY IN THE PICTURE.

Instead of the PING I also had other issues. Ex:

> The WLC1 GUI crashes after few minutes and I should reload the management GUI to continue working on it.

> Any laptop that was trying to connected to the WiFi experimented a really slowness process after logged in trying to reach the Domain Controllers.. more than 1 minute. 

 

The think is that I just disconnected the links on Port 5 on each WLC and magically everything is working fine now.

 

What could be the explanation for that ??

I think it could be great for people trying to use WLCs and N9K on VPC mode.

 

Thank you everyone 

One port channel should be used. You should not split the connection.
-Scott
*** Please rate helpful posts ***

I notice that.

 

But in this case the suggestion is to define 2 different port-channels, 1 per N9K (** no VPC) and then connect each one of these port-channels to a specific WLC. No split.

 

Am I right ? 

 

https://community.cisco.com/t5/wireless-and-mobility/connecting-5520s-wlc-to-nexus-7706s/td-p/2875712

 

https://community.cisco.com/t5/wireless-and-mobility/enabling-lag-on-wlc-5508-with-two-nexus-7k-switches-connected-in/td-p/2879385

Yes... one wlc per switch. You should test with one connection first then if that works, connect another port and see if it breaks. Might be how traffic is passing on each port on the switch. The wlc expects traffic to leave and come back on the same port.
-Scott
*** Please rate helpful posts ***

You should be using src-dst-ip load balancing method.
-Scott
*** Please rate helpful posts ***
Review Cisco Networking products for a $25 gift card