KitsNet Network:LAN:absolut:CAPsMAN Migration: Difference between revisions

Peter A. Smode (talk | contribs)
Created page with "= CAPsMAN Migration Plan = Courvoisier → Absolut (CHR) == Objectives == # Move CAPsMAN control from '''Courvoisier''' to '''Absolut''' # Preserve current SSIDs and datapath behavior during migration # Ensure '''no client traffic passes through Absolut''' # Avoid network disruption # Allow immediate rollback # Perform datapath cleanup '''after migration''' ---- == Phase 0 — Pre-Migration Verification == Verify current operational state. === On Courvoisier === <..."
 
Peter A. Smode (talk | contribs)
 
(11 intermediate revisions by the same user not shown)
Line 1: Line 1:
= CAPsMAN Migration Plan =
Courvoisier → Absolut (CHR)


== Objectives ==
= CAPsMAN Migration: Courvoisier → Absolut =


# Move CAPsMAN control from '''Courvoisier''' to '''Absolut'''
This document describes the complete migration of CAPsMAN control from
# Preserve current SSIDs and datapath behavior during migration
'''courvoisier''' to the CHR instance '''absolut''' while preserving the existing
# Ensure '''no client traffic passes through Absolut'''
DHCP architecture and ensuring that wireless client traffic does not
# Avoid network disruption
traverse the CHR in the final design.
# Allow immediate rollback
 
# Perform datapath cleanup '''after migration'''
The migration is performed in two stages:
 
# '''Interim migration state''' – CAPsMAN moves to Absolut while Guest traffic may temporarily traverse the CHR.
# '''Final controller-only state''' – wireless client traffic no longer passes through Absolut.
 
----
== Supporting Configuration Patch Files ==
 
* [[File:Courvoisier-final-post-migration-patch.rsc.txt]]
* [[File:Absolut-final-controller-only-patch.rsc.txt]]
* [[File:Courvoisier-interim-guest-transport-patch.rsc.txt]]
* [[File:Absolut-interim-migration-patch.rsc.txt]]
----
 
== Architecture Context ==
 
{| class="wikitable"
! Component !! Role
|-
| '''absolut'''
| CAPsMAN controller (control plane only)
|-
| '''courvoisier'''
| edge router and Guest DHCP server
|-
| '''radix.kitsnet.us (192.168.15.1)'''
| DHCP server for main LAN and IoT network
|}
 
Wireless data traffic should remain on the physical LAN through the CAP
devices and should not traverse the CHR once migration is complete.
 
----
 
== SSID Design ==
 
{| class="wikitable"
! SSID !! Purpose !! DHCP Source
|-
| '''KitsNet'''
| trusted WLAN
| radix.kitsnet.us
|-
| '''KitsNetIN'''
| IoT network
| radix.kitsnet.us
|-
| '''KitsNetGN'''
| guest WLAN
| courvoisier
|}


----
----


== Phase 0 — Pre-Migration Verification ==
== Preconditions ==
 
Before beginning the migration verify:


Verify current operational state.
=== CAP registration ===


=== On Courvoisier ===
On '''courvoisier''':


<pre>
<pre>
Line 25: Line 75:
Expected:
Expected:


<pre>
* able – Run
identity="able"
* baker – Run
identity="baker"
 
state="Run"
=== CAP configuration ===
</pre>


=== On Able ===
On '''able''' and '''baker''':


<pre>
<pre>
Line 45: Line 94:
</pre>
</pre>


=== On Baker ===
=== Guest DHCP ===


Run the same command and confirm identical settings.
On '''courvoisier''':
 
=== Confirm Courvoisier owns the manager IP ===


<pre>
<pre>
/ip address print
/ip dhcp-server print detail
</pre>
</pre>


Verify:
Confirm the DHCP server is bound to bridge:


<pre>
<pre>
192.168.15.6/23
BWF.KitsNetG
</pre>
</pre>


----
----


== Phase 1 — Prepare Absolut ==
== CAPsMAN Certificate Migration ==


This phase does '''not impact the network'''.
The CAPsMAN controller identity must be preserved during migration.
The active CAPsMAN certificate and CA must be copied from '''courvoisier'''
to '''absolut'''.


=== Enable CAPsMAN ===
This avoids CAP authentication failures or WPA handshake problems.


On Absolut:
=== Step 1 – Identify certificates ===
 
On '''courvoisier''':


<pre>
<pre>
/caps-man manager set enabled=yes
[admin@Courvoisier] > /certificate print
Flags: K - PRIVATE-KEY; A - AUTHORITY; I - ISSUED; T - TRUSTED
Columns: NAME, COMMON-NAME, SKID
#      NAME                          COMMON-NAME                  SKID
0 KA T CAPsMAN-CA-488F5A87BE5A      CAPsMAN-CA-488F5A87BE5A      b96a4f946961524e913ad4703868303a0dd23c9b
1 K I  CAPsMAN-488F5A87BE5A          CAPsMAN-488F5A87BE5A          cf5b50d734e8ef10c1257577bb6783890c06b55c
2  I  CAP-08553163AC8E              CAP-08553163AC8E              71c4e6af7e09cf386dad50ec271c41f9e6a62e7a
3  I  CAP-08553163A40F              CAP-08553163A40F              d7123f8e1e7d616edbc4b7bda20a610ed5becd0b
4 KA T WiFi-CAPsMAN-CA-488F5A87BE5A  WiFi-CAPsMAN-CA-488F5A87BE5A  c65a58c80dd0ee06a84721ca46439882b5157fea
5 K I  WiFi-CAPsMAN-488F5A87BE5A    WiFi-CAPsMAN-488F5A87BE5A    caaa1c14fd8e0ee03458616e450cc81d85706cca
</pre>
</pre>


Verify:
Identify:


<pre>
* CAPsMAN certificate
/caps-man manager print
* CA certificate
</pre>


=== Verify CAPsMAN configuration objects exist ===
TWe want:


<pre>
<pre>
/caps-man configuration print
WiFi-CAPsMAN-CA-488F5A87BE5A
/caps-man provisioning print
WiFi-CAPsMAN-488F5A87BE5A
/caps-man datapath print
</pre>
</pre>


Ensure the following objects exist:
----
 
* able-2.4-KitsNet
* able-5.0-KitsNet
* baker-2.4-KitsNet
* baker-5.0-KitsNet
* slave-KitsNetGN
* slave-KitsNetIN


Do '''not modify datapaths yet'''.
=== Step 2 – Export certificates ===


=== Confirm forwarding behavior ===
On '''courvoisier''':


<pre>
<pre>
/caps-man datapath print
/certificate export-certificate WiFi-CAPsMAN-488F5A87BE5A export-passphrase=StrongPass
/certificate export-certificate WiFi-CAPsMAN-CA-488F5A87BE5A export-passphrase=StrongPass
</pre>
</pre>


Expected:
Generated files will appear in:


<pre>
<pre>
local-forwarding: yes
[admin@Courvoisier] > /file print
# NAME                                                                                  TYPE            SIZE LAST-MODIFIED
0 cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.key                                          .key file        497 2026-03-14 13:23:47
1 cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt                                          .crt file        672 2026-03-14 13:23:47
2 cert_export_WiFi-CAPsMAN-488F5A87BE5A.key                                              .key file        497 2026-03-14 13:23:07
3 cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt                                              .crt file        688 2026-03-14 13:23:07
4 flash                                                                                  disk                  2026-03-14 00:00:34
5 flash/Courvoisier-export.rsc                                                          script        29.7KiB 2026-03-14 00:00:34
6 flash/skins                                                                            directory            2106-02-07 02:28:42
7 flash/auto-before-reset.backup                                                        backup        18.7KiB 2106-02-07 02:28:48
8 flash/pub                                                                              directory            2020-09-11 01:10:52
9 flash/Courvoisier-daily.backup                                                        backup      114.3KiB 2026-03-14 00:00:01
</pre>
</pre>
Exported files:
* cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.key
* cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt
* cert_export_WiFi-CAPsMAN-488F5A87BE5A.key
* cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt


----
----


== Phase 2 — Copy Certificates ==
=== Step 3 – Transfer certificates to Absolut ===


Preserve CAP trust identity.
Copy the files to '''absolut''' using:


=== On Courvoisier ===
* WinBox file transfer
* SCP
* FTP


List certificates:
Example using SCP:


<pre>
<pre>
/certificate print
scp *.crt admin@absolut:/
</pre>
scp *.key admin@absolut:/
</pre>''This had to be done using a Linux system as a waystation because RouterOS had no scp client.''
----
 
=== Step 4 – Import certificates on Absolut ===


Export the CAPsMAN certificate and CA:
On '''absolut''':


<pre>
<pre>
/certificate export-certificate <capsman-cert> export-passphrase=StrongPass
/certificate import file-name=cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt passphrase=StrongPass
/certificate export-certificate <capsman-ca> export-passphrase=StrongPass
/certificate import file-name=cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.key passphrase=StrongPass
 
/certificate import file-name=cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt passphrase=StrongPass
/certificate import file-name=cert_export_WiFi-CAPsMAN-488F5A87BE5A.key passphrase=StrongPass
</pre>
</pre>


Files created:
Verify:


<pre>
<pre>
<cert>.crt
[admin@Absolut] > /certificate print
<cert>.key
Flags: K - PRIVATE-KEY; A - AUTHORITY; T - TRUSTED
<ca>.crt
Columns: NAME, COMMON-NAME, SKID
</pre>
#    NAME                                            COMMON-NAME                  SKID
0 KAT cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt_0  WiFi-CAPsMAN-CA-488F5A87BE5A  c65a58c80dd0ee06a84721ca46439882b5157fea
1 K T cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt_0    WiFi-CAPsMAN-488F5A87BE5A    caaa1c14fd8e0ee03458616e450cc81d85706cca
</pre>Note that the SKIDs on '''absolut''' match those on '''courvoisier'''.


=== Copy files to Absolut ===
''There were some crap autogenerated certificates from prior to migration, but i elected to remove those now.''
 
----
Use SCP, WinBox, or FTP.
 
=== On Absolut ===


Import certificates:
=== Step 5 – Assign certificates to CAPsMAN ===


<pre>
On '''absolut''':
/certificate import file-name=<cert>.crt
/certificate import file-name=<cert>.key
/certificate import file-name=<ca>.crt
</pre>
 
Assign them:


<pre>
<pre>
/caps-man manager
/caps-man manager set \
set certificate=<capsman-cert> ca-certificate=<capsman-ca>
certificate=cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt_0 \
ca-certificate=cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt_0 \
enabled=yes
</pre>
</pre>


Line 165: Line 240:


<pre>
<pre>
/caps-man manager print
[admin@Absolut] > /caps-man manager print
</pre>
                  enabled: yes
 
              certificate: cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt_0
            ca-certificate: cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt_0
              package-path:
            upgrade-policy: none
  require-peer-certificate: no
    generated-certificate: *2
  generated-ca-certificate: *1
</pre>The *1 and *2 references are the autogenerated certs that i removed. they are not used and this is supposed to be harmless.
----
----


== Phase 3 — Migration (One CAP First) ==
== Stage A – Interim Migration State ==


Move '''Able''' first.
During migration Guest traffic may temporarily traverse Absolut in order
to maintain connectivity with the Guest DHCP server on courvoisier.


=== On Able ===
=== Prepare Absolut ===


Change manager address:
Create temporary Guest bridge:


<pre>
<pre>
/interface wireless cap
/interface bridge add name=BWF.KitsNetG
set caps-man-addresses=<absolut-ip>
</pre>
</pre>


Example:
Create EoIP tunnel to courvoisier:


<pre>
<pre>
/interface wireless cap
/interface eoip add name=EOIP.KitsNetG.to.Courvoisier \
set caps-man-addresses=192.168.15.25
local-address=192.168.15.10 \
remote-address=192.168.15.6 \
tunnel-id=120
</pre>
</pre>


Expected behavior: within ~10 seconds Able disconnects from Courvoisier and connects to Absolut.
Attach the tunnel to the bridge:
 
----
 
== Phase 4 — Validate Able ==
 
=== On Absolut ===


<pre>
<pre>
/caps-man remote-cap print detail
/interface bridge port add bridge=BWF.KitsNetG interface=EOIP.KitsNetG.to.Courvoisier
</pre>
</pre>


Expected:
Update the Guest datapath:


<pre>
<pre>
identity="able"
/caps-man datapath set [find name="DP.KitsNetG"] local-forwarding=no bridge=BWF.KitsNetG
state="Run"
</pre>
</pre>


=== Verify radios ===
----


<pre>
=== Prepare Courvoisier ===
/caps-man interface print
</pre>


Expected:
Create the matching EoIP interface:


<pre>
<pre>
able-2.4-KitsNet
/interface eoip add name=EOIP.KitsNetG.to.Absolut \
able-5.0-KitsNet
local-address=192.168.15.6 \
slave-KitsNetGN
remote-address=192.168.15.10 \
slave-KitsNetIN
tunnel-id=120
</pre>
</pre>


=== Verify clients ===
Attach to Guest bridge:


<pre>
<pre>
/caps-man registration-table print
/interface bridge port add bridge=BWF.KitsNetG interface=EOIP.KitsNetG.to.Absolut
</pre>
</pre>


Test client connectivity for:
----


* KitsNet
== Migration Procedure ==
* KitsNetGN
* KitsNetIN


----
=== Step 1 – Move Able ===


== Phase 5 — Migrate Baker ==
On '''able''':
 
On Baker:


<pre>
<pre>
/interface wireless cap
/interface wireless cap set caps-man-addresses=192.168.15.10
set caps-man-addresses=<absolut-ip>
</pre>
</pre>


Line 251: Line 321:
<pre>
<pre>
/caps-man remote-cap print
/caps-man remote-cap print
/caps-man interface print
</pre>
</pre>


Expected:
Test:
 
* KitsNet connectivity
* Guest DHCP
* IoT connectivity
 
Rollback if needed:


<pre>
<pre>
able  Run
/interface wireless cap set caps-man-addresses=192.168.15.6
baker  Run
</pre>
</pre>


----
----


== Phase 6 — Validate Full Operation ==
=== Step 2 – Move Baker ===
 
On '''baker''':
 
<pre>
/interface wireless cap set caps-man-addresses=192.168.15.10
</pre>


Confirm:
Verify both CAPs:


<pre>
<pre>
/caps-man interface print
/caps-man remote-cap print
/caps-man registration-table print
/caps-man radio print
</pre>
</pre>


----
----


== Phase 7 — Disable CAPsMAN on Courvoisier ==
=== Step 3 – Disable CAPsMAN on Courvoisier ===


Once migration is stable:
Once both CAPs are stable:


<pre>
<pre>
Line 282: Line 362:
</pre>
</pre>


Lock CAPs:
<pre>
/interface wireless cap set lock-to-caps-man=yes
</pre>'''''We cannot lock to caps yet becuase we don't have certificate locking working. I tried this now and Able would not associate with CAPsMAN at all. this has to wait for a post-migration activity.'''''
----
----


== Phase 8 — Re-Lock CAPs ==
== Validation ==


On Able:
On '''absolut''':


<pre>
<pre>
/interface wireless cap
/caps-man registration-table print
set lock-to-caps-man=yes
</pre>
</pre>


On Baker:
On '''courvoisier''':


<pre>
<pre>
/interface wireless cap
/ip dhcp-server lease print
set lock-to-caps-man=yes
</pre>
</pre>
Verify:
* clients on KitsNet obtain DHCP from Radix
* guest clients obtain DHCP from Courvoisier
* CAPs remain connected to Absolut


----
----


== Phase 9 — Post-Migration Datapath Cleanup ==
== Rollback ==


This will be performed '''after the migration''' as a separate exercise.
If migration fails revert CAPs to Courvoisier.


Possible improvements:
On CAP:


* correct IoT datapath usage
<pre>
* enforce VLAN isolation
/interface wireless cap set caps-man-addresses=192.168.15.6
* ensure Able/Baker provisioning symmetry
</pre>
* validate forwarding model


No datapath changes are made during the migration.
Re-enable CAPsMAN:
 
<pre>
/caps-man manager set enabled=yes
</pre>


----
----


== Rollback Procedure ==
== Stage B – Final Controller-Only State ==


If anything fails:
After a permanent Guest L2 path exists outside the CHR:


On Able:
On '''absolut''':


<pre>
<pre>
/interface wireless cap
/caps-man datapath set [find name="DP.KitsNetG"] local-forwarding=yes
set caps-man-addresses=192.168.15.6
</pre>
</pre>


On Baker:
Remove temporary EoIP:


<pre>
<pre>
/interface wireless cap
/interface bridge port remove [find interface="EOIP.KitsNetG.to.Courvoisier"]
set caps-man-addresses=192.168.15.6
/interface eoip remove EOIP.KitsNetG.to.Courvoisier
/interface bridge remove BWF.KitsNetG
</pre>
</pre>


CAPs will reconnect to Courvoisier within seconds.
On '''courvoisier''':
 
<pre>
/interface bridge port remove [find interface="EOIP.KitsNetG.to.Absolut"]
/interface eoip remove EOIP.KitsNetG.to.Absolut
</pre>


----
----


== Final Sanity Checklist ==
== Final State ==
 
Before migration confirm:


* Absolut CAPsMAN enabled
* Absolut runs CAPsMAN only
* Certificates imported
* Courvoisier continues Guest DHCP
* CAPs unlocked
* Radix provides LAN DHCP
* Provisioning objects present
* CAPs locally forward client traffic
* Datapaths unchanged
* No wireless data traffic traverses the CHR
* Rollback command prepared

Latest revision as of 15:05, 14 March 2026

1 CAPsMAN Migration: Courvoisier → Absolut[edit | edit source]

This document describes the complete migration of CAPsMAN control from courvoisier to the CHR instance absolut while preserving the existing DHCP architecture and ensuring that wireless client traffic does not traverse the CHR in the final design.

The migration is performed in two stages:

  1. Interim migration state – CAPsMAN moves to Absolut while Guest traffic may temporarily traverse the CHR.
  2. Final controller-only state – wireless client traffic no longer passes through Absolut.

1.1 Supporting Configuration Patch Files[edit | edit source]


1.2 Architecture Context[edit | edit source]

Component Role
absolut CAPsMAN controller (control plane only)
courvoisier edge router and Guest DHCP server
radix.kitsnet.us (192.168.15.1) DHCP server for main LAN and IoT network

Wireless data traffic should remain on the physical LAN through the CAP devices and should not traverse the CHR once migration is complete.


1.3 SSID Design[edit | edit source]

SSID Purpose DHCP Source
KitsNet trusted WLAN radix.kitsnet.us
KitsNetIN IoT network radix.kitsnet.us
KitsNetGN guest WLAN courvoisier

1.4 Preconditions[edit | edit source]

Before beginning the migration verify:

1.4.1 CAP registration[edit | edit source]

On courvoisier:

/caps-man remote-cap print detail

Expected:

  • able – Run
  • baker – Run

1.4.2 CAP configuration[edit | edit source]

On able and baker:

/interface wireless cap print

Verify:

enabled: yes
lock-to-caps-man: no
caps-man-addresses: 192.168.15.6

1.4.3 Guest DHCP[edit | edit source]

On courvoisier:

/ip dhcp-server print detail

Confirm the DHCP server is bound to bridge:

BWF.KitsNetG

1.5 CAPsMAN Certificate Migration[edit | edit source]

The CAPsMAN controller identity must be preserved during migration. The active CAPsMAN certificate and CA must be copied from courvoisier to absolut.

This avoids CAP authentication failures or WPA handshake problems.

1.5.1 Step 1 – Identify certificates[edit | edit source]

On courvoisier:

[admin@Courvoisier] > /certificate print
Flags: K - PRIVATE-KEY; A - AUTHORITY; I - ISSUED; T - TRUSTED
Columns: NAME, COMMON-NAME, SKID
#      NAME                          COMMON-NAME                   SKID
0 KA T CAPsMAN-CA-488F5A87BE5A       CAPsMAN-CA-488F5A87BE5A       b96a4f946961524e913ad4703868303a0dd23c9b
1 K I  CAPsMAN-488F5A87BE5A          CAPsMAN-488F5A87BE5A          cf5b50d734e8ef10c1257577bb6783890c06b55c
2   I  CAP-08553163AC8E              CAP-08553163AC8E              71c4e6af7e09cf386dad50ec271c41f9e6a62e7a
3   I  CAP-08553163A40F              CAP-08553163A40F              d7123f8e1e7d616edbc4b7bda20a610ed5becd0b
4 KA T WiFi-CAPsMAN-CA-488F5A87BE5A  WiFi-CAPsMAN-CA-488F5A87BE5A  c65a58c80dd0ee06a84721ca46439882b5157fea
5 K I  WiFi-CAPsMAN-488F5A87BE5A     WiFi-CAPsMAN-488F5A87BE5A     caaa1c14fd8e0ee03458616e450cc81d85706cca

Identify:

  • CAPsMAN certificate
  • CA certificate

TWe want:

WiFi-CAPsMAN-CA-488F5A87BE5A
WiFi-CAPsMAN-488F5A87BE5A

1.5.2 Step 2 – Export certificates[edit | edit source]

On courvoisier:

/certificate export-certificate WiFi-CAPsMAN-488F5A87BE5A export-passphrase=StrongPass
/certificate export-certificate WiFi-CAPsMAN-CA-488F5A87BE5A export-passphrase=StrongPass

Generated files will appear in:

[admin@Courvoisier] > /file print
 # NAME                                                                                   TYPE             SIZE LAST-MODIFIED
 0 cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.key                                           .key file         497 2026-03-14 13:23:47
 1 cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt                                           .crt file         672 2026-03-14 13:23:47
 2 cert_export_WiFi-CAPsMAN-488F5A87BE5A.key                                              .key file         497 2026-03-14 13:23:07
 3 cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt                                              .crt file         688 2026-03-14 13:23:07
 4 flash                                                                                  disk                  2026-03-14 00:00:34
 5 flash/Courvoisier-export.rsc                                                           script        29.7KiB 2026-03-14 00:00:34
 6 flash/skins                                                                            directory             2106-02-07 02:28:42
 7 flash/auto-before-reset.backup                                                         backup        18.7KiB 2106-02-07 02:28:48
 8 flash/pub                                                                              directory             2020-09-11 01:10:52
 9 flash/Courvoisier-daily.backup                                                         backup       114.3KiB 2026-03-14 00:00:01

Exported files:

  • cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.key
  • cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt
  • cert_export_WiFi-CAPsMAN-488F5A87BE5A.key
  • cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt

1.5.3 Step 3 – Transfer certificates to Absolut[edit | edit source]

Copy the files to absolut using:

  • WinBox file transfer
  • SCP
  • FTP

Example using SCP:

scp *.crt admin@absolut:/
scp *.key admin@absolut:/

This had to be done using a Linux system as a waystation because RouterOS had no scp client.


1.5.4 Step 4 – Import certificates on Absolut[edit | edit source]

On absolut:

/certificate import file-name=cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt passphrase=StrongPass
/certificate import file-name=cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.key passphrase=StrongPass

/certificate import file-name=cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt passphrase=StrongPass
/certificate import file-name=cert_export_WiFi-CAPsMAN-488F5A87BE5A.key passphrase=StrongPass

Verify:

[admin@Absolut] > /certificate print
Flags: K - PRIVATE-KEY; A - AUTHORITY; T - TRUSTED
Columns: NAME, COMMON-NAME, SKID
#     NAME                                            COMMON-NAME                   SKID
0 KAT cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt_0  WiFi-CAPsMAN-CA-488F5A87BE5A  c65a58c80dd0ee06a84721ca46439882b5157fea
1 K T cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt_0     WiFi-CAPsMAN-488F5A87BE5A     caaa1c14fd8e0ee03458616e450cc81d85706cca

Note that the SKIDs on absolut match those on courvoisier.

There were some crap autogenerated certificates from prior to migration, but i elected to remove those now.


1.5.5 Step 5 – Assign certificates to CAPsMAN[edit | edit source]

On absolut:

/caps-man manager set \
certificate=cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt_0 \
ca-certificate=cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt_0 \
enabled=yes

Verify:

[admin@Absolut] > /caps-man manager print
                   enabled: yes
               certificate: cert_export_WiFi-CAPsMAN-488F5A87BE5A.crt_0
            ca-certificate: cert_export_WiFi-CAPsMAN-CA-488F5A87BE5A.crt_0
              package-path:
            upgrade-policy: none
  require-peer-certificate: no
     generated-certificate: *2
  generated-ca-certificate: *1

The *1 and *2 references are the autogenerated certs that i removed. they are not used and this is supposed to be harmless.


1.6 Stage A – Interim Migration State[edit | edit source]

During migration Guest traffic may temporarily traverse Absolut in order to maintain connectivity with the Guest DHCP server on courvoisier.

1.6.1 Prepare Absolut[edit | edit source]

Create temporary Guest bridge:

/interface bridge add name=BWF.KitsNetG

Create EoIP tunnel to courvoisier:

/interface eoip add name=EOIP.KitsNetG.to.Courvoisier \
 local-address=192.168.15.10 \
 remote-address=192.168.15.6 \
 tunnel-id=120

Attach the tunnel to the bridge:

/interface bridge port add bridge=BWF.KitsNetG interface=EOIP.KitsNetG.to.Courvoisier

Update the Guest datapath:

/caps-man datapath set [find name="DP.KitsNetG"] local-forwarding=no bridge=BWF.KitsNetG

1.6.2 Prepare Courvoisier[edit | edit source]

Create the matching EoIP interface:

/interface eoip add name=EOIP.KitsNetG.to.Absolut \
 local-address=192.168.15.6 \
 remote-address=192.168.15.10 \
 tunnel-id=120

Attach to Guest bridge:

/interface bridge port add bridge=BWF.KitsNetG interface=EOIP.KitsNetG.to.Absolut

1.7 Migration Procedure[edit | edit source]

1.7.1 Step 1 – Move Able[edit | edit source]

On able:

/interface wireless cap set caps-man-addresses=192.168.15.10

Verify on Absolut:

/caps-man remote-cap print
/caps-man interface print

Test:

  • KitsNet connectivity
  • Guest DHCP
  • IoT connectivity

Rollback if needed:

/interface wireless cap set caps-man-addresses=192.168.15.6

1.7.2 Step 2 – Move Baker[edit | edit source]

On baker:

/interface wireless cap set caps-man-addresses=192.168.15.10

Verify both CAPs:

/caps-man remote-cap print

1.7.3 Step 3 – Disable CAPsMAN on Courvoisier[edit | edit source]

Once both CAPs are stable:

/caps-man manager set enabled=no

Lock CAPs:

/interface wireless cap set lock-to-caps-man=yes

We cannot lock to caps yet becuase we don't have certificate locking working. I tried this now and Able would not associate with CAPsMAN at all. this has to wait for a post-migration activity.


1.8 Validation[edit | edit source]

On absolut:

/caps-man registration-table print

On courvoisier:

/ip dhcp-server lease print

Verify:

  • clients on KitsNet obtain DHCP from Radix
  • guest clients obtain DHCP from Courvoisier
  • CAPs remain connected to Absolut

1.9 Rollback[edit | edit source]

If migration fails revert CAPs to Courvoisier.

On CAP:

/interface wireless cap set caps-man-addresses=192.168.15.6

Re-enable CAPsMAN:

/caps-man manager set enabled=yes

1.10 Stage B – Final Controller-Only State[edit | edit source]

After a permanent Guest L2 path exists outside the CHR:

On absolut:

/caps-man datapath set [find name="DP.KitsNetG"] local-forwarding=yes

Remove temporary EoIP:

/interface bridge port remove [find interface="EOIP.KitsNetG.to.Courvoisier"]
/interface eoip remove EOIP.KitsNetG.to.Courvoisier
/interface bridge remove BWF.KitsNetG

On courvoisier:

/interface bridge port remove [find interface="EOIP.KitsNetG.to.Absolut"]
/interface eoip remove EOIP.KitsNetG.to.Absolut

1.11 Final State[edit | edit source]

  • Absolut runs CAPsMAN only
  • Courvoisier continues Guest DHCP
  • Radix provides LAN DHCP
  • CAPs locally forward client traffic
  • No wireless data traffic traverses the CHR