KitsNet Network:LAN:absolut:CAPsMAN Migration: Difference between revisions

Peter A. Smode (talk | contribs)
No edit summary
Peter A. Smode (talk | contribs)
No edit summary
Line 1: Line 1:


= CAPsMAN Migration Plan (Interim → Final) =
= CAPsMAN Migration: Courvoisier → Absolut =
Courvoisier → Absolut (CHR)


This revision reflects the updated priority:
This document describes the complete migration of CAPsMAN control from
'''courvoisier''' to the CHR instance '''absolut''' while keeping wireless client
traffic off the CHR in the final state.


# Complete the CAPsMAN migration first
The migration is performed in two stages:
# Temporary Guest-path inefficiency during migration is acceptable
 
# By the final state, client traffic must stay off Absolut
# '''Interim migration state''' – CAPsMAN moves to Absolut while Guest traffic temporarily traverses the CHR.
# Courvoisier must continue serving the KitsNetGN guest DHCP scope
# '''Final controller‑only state''' – client traffic no longer traverses Absolut.
# Main SSID DHCP continues to come from radix.kitsnet.us (192.168.15.1)
# Avoid mixing large redesign work into the controller cutover


----
----


== Why this staged plan is needed ==
== Architecture Context ==
 
Final architecture goals:
 
{| class="wikitable"
! Component !! Role
|-
| '''absolut'''
| CAPsMAN controller (control plane only)
|-
| '''courvoisier'''
| edge router and Guest DHCP server
|-
| '''radix.kitsnet.us (192.168.15.1)'''
| DHCP server for main and IoT WLAN
|}


The current configuration shows:
Wireless data traffic must remain on the physical network and must not
traverse the CHR once the migration is complete.


* Courvoisier central‑forwards Guest to BWF.KitsNetG and serves Guest DHCP there.
----
* Main SSID traffic lives on the main bridge where Radix provides DHCP.
* Absolut currently has datapaths configured for local forwarding and does not yet replicate the Guest bridge design.
* Baker 2.4 GHz provisioning lacks the IoT SSID compared with Able.


Because of this the migration uses two stages:
== SSID Design ==


* '''Interim state''' – Guest traffic temporarily traverses Absolut but is bridged back to Courvoisier so DHCP remains there.
{| class="wikitable"
* '''Final state''' – Guest traffic no longer traverses Absolut once an off‑CHR L2 path exists.
! SSID !! Purpose !! DHCP Source
|-
| KitsNet
| trusted WLAN
| radix.kitsnet.us
|-
| KitsNetIN
| IoT devices
| radix.kitsnet.us
|-
| KitsNetGN
| guest WLAN
| courvoisier
|}


----
----


== Stage A — Interim Migration State ==
== Preconditions ==


=== Design intent ===
Before beginning the migration verify:


* '''KitsNet''' – locally forwarded; DHCP from Radix on the LAN
=== CAP state ===
* '''KitsNetIN''' – unchanged during migration
* '''KitsNetGN''' – temporarily central‑forwarded via Absolut then bridged back to Courvoisier


This keeps the network functional while moving CAPsMAN.
On Courvoisier:
 
<pre>
/caps-man remote-cap print detail
</pre>


=== Interim prerequisites ===
Expected:


# Import Courvoisier CAPsMAN certificate and CA into Absolut
* able – Run
# Enable CAPsMAN on Absolut
* baker – Run
# Create temporary Guest EoIP link between Absolut and Courvoisier
# Set DP.KitsNetG to central forwarding during migration
# Keep DP.KitsNet locally forwarded
# Correct Baker 2.4 GHz provisioning symmetry


=== Interim cutover sequence ===
=== CAP configuration ===


# Prepare Guest EoIP bridge on both routers
On Able and Baker:
# Verify Absolut CAPsMAN configuration
# Move Able to Absolut
# Validate Able
# Move Baker to Absolut
# Validate Baker
# Disable CAPsMAN on Courvoisier
# Re‑lock CAPs


=== Interim success criteria ===
<pre>
/interface wireless cap print
</pre>


* Able and Baker show '''Run''' on Absolut
Verify:
* KitsNet clients obtain DHCP from Radix
* KitsNetGN clients obtain DHCP from Courvoisier
* IoT devices remain functional
* Only Guest traffic temporarily traverses Absolut


----
<pre>
enabled: yes
lock-to-caps-man: no
caps-man-addresses: 192.168.15.6
</pre>


== Stage B — Final Controller‑Only State ==
=== Guest DHCP ===


=== Design intent ===
On Courvoisier:


By the end state, Absolut acts only as the CAPsMAN controller.
<pre>
/ip dhcp-server print detail
</pre>


Requirements:
Confirm DHCP server bound to bridge:


* DP.KitsNetG changed back to '''local‑forwarding=yes'''
<pre>
* Temporary EoIP bridge removed
BWF.KitsNetG
* Guest L2 path provided elsewhere on the wired network
</pre>


=== Final transition sequence ===
----


# Prepare off‑CHR Guest L2 transport
== Stage A – Interim Migration State ==
# Change DP.KitsNetG back to local forwarding
# Remove temporary EoIP bridge on Absolut
# Remove EoIP on Courvoisier
# Validate Guest DHCP and isolation


=== Final success criteria ===
During migration Guest traffic may temporarily traverse Absolut.
This allows the CAPsMAN controller to move while keeping Guest DHCP
hosted on Courvoisier.


* CAPs remain attached to Absolut
=== Design ===
* Main SSID DHCP still provided by Radix
 
* Guest DHCP still provided by Courvoisier
* KitsNet → local forwarding → Radix DHCP
* No client traffic passes through Absolut
* KitsNetIN → unchanged during migration
* Temporary EoIP removed
* KitsNetGN → temporarily central forwarded to Absolut and bridged back to Courvoisier


----
----


== Detailed Execution ==
== Prepare Absolut ==


=== Phase 0 — Pre‑checks ===
On Absolut:


On Courvoisier:
<pre>
/caps-man manager set enabled=yes
</pre>
 
Import CAPsMAN certificates copied from Courvoisier.
 
Create temporary Guest bridge:
 
<pre>
/interface bridge add name=BWF.KitsNetG
</pre>
 
Create EoIP transport to Courvoisier:


<pre>
<pre>
/caps-man remote-cap print detail
/interface eoip add name=EOIP.KitsNetG.to.Courvoisier \
/caps-man datapath print detail
local-address=&lt;ABSOLUT_IP&gt; \
/ip dhcp-server print detail
remote-address=192.168.15.6 \
/ip address print
tunnel-id=120
</pre>
</pre>


Confirm both CAPs connected and Guest DHCP bound to BWF.KitsNetG.
Attach EoIP to bridge:
 
<pre>
/interface bridge port add bridge=BWF.KitsNetG interface=EOIP.KitsNetG.to.Courvoisier
</pre>


On Able and Baker:
Change Guest datapath:


<pre>
<pre>
/interface wireless cap print
/caps-man datapath set [find name="DP.KitsNetG"] local-forwarding=no bridge=BWF.KitsNetG
</pre>
</pre>


Verify:
----
 
== Prepare Courvoisier ==
 
Create matching EoIP interface:


<pre>
<pre>
enabled: yes
/interface eoip add name=EOIP.KitsNetG.to.Absolut \
lock-to-caps-man: no
local-address=192.168.15.6 \
caps-man-addresses: 192.168.15.6
remote-address=&lt;ABSOLUT_IP&gt; \
tunnel-id=120
</pre>
</pre>


On Absolut:
Attach to Guest bridge:


<pre>
<pre>
/caps-man manager print
/interface bridge port add bridge=BWF.KitsNetG interface=EOIP.KitsNetG.to.Absolut
/caps-man datapath print detail
/caps-man provisioning print detail
</pre>
</pre>


----
----


=== Phase 1 — Prepare Absolut ===
== Migration Procedure ==


Apply the interim Absolut migration patch which:
=== Step 1 – Move Able ===


* enables CAPsMAN
On Able:
* creates temporary Guest bridge
* creates EoIP tunnel
* sets Guest datapath to central forwarding
* fixes Baker provisioning


----
<pre>
/interface wireless cap set caps-man-addresses=&lt;ABSOLUT_IP&gt;
</pre>


=== Phase 2 — Prepare Courvoisier ===
Verify on Absolut:


Apply the interim Guest transport patch.
<pre>
/caps-man remote-cap print
/caps-man interface print
</pre>


This creates the matching EoIP interface and adds it to BWF.KitsNetG.
Test:
 
* KitsNet connectivity
* KitsNetGN guest DHCP
* IoT connectivity


----
----


=== Phase 3 — Migrate Able ===
=== Step 2 – Move Baker ===
 
On Baker:


<pre>
<pre>
Line 165: Line 209:
</pre>
</pre>


Validate on Absolut:
Verify both CAPs on Absolut:


<pre>
<pre>
/caps-man remote-cap print
/caps-man remote-cap print
/caps-man interface print
/caps-man registration-table print
</pre>
</pre>


Rollback if necessary:
----
 
=== Step 3 – Disable Courvoisier CAPsMAN ===
 
Once both CAPs are stable:
 
<pre>
/caps-man manager set enabled=no
</pre>
 
Lock CAPs:


<pre>
<pre>
/interface wireless cap set caps-man-addresses=192.168.15.6
/interface wireless cap set lock-to-caps-man=yes
</pre>
</pre>


----
----


=== Phase 4 — Migrate Baker ===
== Validation ==
 
On Absolut:
 
<pre>
/caps-man registration-table print
</pre>
 
On Courvoisier:


Repeat the same command on Baker.
<pre>
/ip dhcp-server lease print
</pre>
 
Confirm:
 
* clients on KitsNet obtain DHCP from Radix
* guest clients obtain DHCP from Courvoisier
* both CAPs remain connected to Absolut


----
----


=== Phase 5 — Retire Courvoisier CAPsMAN ===
== Rollback ==
 
If migration fails revert CAPs to Courvoisier.
 
On CAP:


<pre>
<pre>
/caps-man manager set enabled=no
/interface wireless cap set caps-man-addresses=192.168.15.6
</pre>
</pre>


Then re‑lock the CAPs.
Re-enable CAPsMAN on Courvoisier if necessary:
 
<pre>
/caps-man manager set enabled=yes
</pre>


----
----


=== Phase 6 — Final cleanup later ===
== Stage B – Final Controller‑Only State ==


After the off‑CHR Guest path exists:
After a permanent Guest L2 path exists outside the CHR:


# Apply Absolut final controller patch
On Absolut:
# Apply Courvoisier cleanup patch
# Verify DHCP and isolation


----
<pre>
/caps-man datapath set [find name="DP.KitsNetG"] local-forwarding=yes
</pre>
 
Remove temporary EoIP:
 
<pre>
/interface bridge port remove [find interface="EOIP.KitsNetG.to.Courvoisier"]
/interface eoip remove EOIP.KitsNetG.to.Courvoisier
/interface bridge remove BWF.KitsNetG
</pre>


== Scope notes ==
On Courvoisier:


Included:
<pre>
/interface bridge port remove [find interface="EOIP.KitsNetG.to.Absolut"]
/interface eoip remove EOIP.KitsNetG.to.Absolut
</pre>


* CAPsMAN migration
----
* Temporary Guest bridge
* Baker provisioning fix


Deferred:
== Final State ==


* VLAN redesign
* Absolut runs CAPsMAN only
* IoT policy redesign
* Courvoisier serves Guest DHCP
* channel plan changes
* Radix serves LAN DHCP
* CAPs locally forward all client traffic
* no wireless data traffic transits the CHR

Revision as of 18:12, 12 March 2026

1 CAPsMAN Migration: Courvoisier → Absolut[edit | edit source]

This document describes the complete migration of CAPsMAN control from courvoisier to the CHR instance absolut while keeping wireless client traffic off the CHR in the final state.

The migration is performed in two stages:

  1. Interim migration state – CAPsMAN moves to Absolut while Guest traffic temporarily traverses the CHR.
  2. Final controller‑only state – client traffic no longer traverses Absolut.

1.1 Architecture Context[edit | edit source]

Final architecture goals:

Component Role
absolut CAPsMAN controller (control plane only)
courvoisier edge router and Guest DHCP server
radix.kitsnet.us (192.168.15.1) DHCP server for main and IoT WLAN

Wireless data traffic must remain on the physical network and must not traverse the CHR once the migration is complete.


1.2 SSID Design[edit | edit source]

SSID Purpose DHCP Source
KitsNet trusted WLAN radix.kitsnet.us
KitsNetIN IoT devices radix.kitsnet.us
KitsNetGN guest WLAN courvoisier

1.3 Preconditions[edit | edit source]

Before beginning the migration verify:

1.3.1 CAP state[edit | edit source]

On Courvoisier:

/caps-man remote-cap print detail

Expected:

  • able – Run
  • baker – Run

1.3.2 CAP configuration[edit | edit source]

On Able and Baker:

/interface wireless cap print

Verify:

enabled: yes
lock-to-caps-man: no
caps-man-addresses: 192.168.15.6

1.3.3 Guest DHCP[edit | edit source]

On Courvoisier:

/ip dhcp-server print detail

Confirm DHCP server bound to bridge:

BWF.KitsNetG

1.4 Stage A – Interim Migration State[edit | edit source]

During migration Guest traffic may temporarily traverse Absolut. This allows the CAPsMAN controller to move while keeping Guest DHCP hosted on Courvoisier.

1.4.1 Design[edit | edit source]

  • KitsNet → local forwarding → Radix DHCP
  • KitsNetIN → unchanged during migration
  • KitsNetGN → temporarily central forwarded to Absolut and bridged back to Courvoisier

1.5 Prepare Absolut[edit | edit source]

On Absolut:

/caps-man manager set enabled=yes

Import CAPsMAN certificates copied from Courvoisier.

Create temporary Guest bridge:

/interface bridge add name=BWF.KitsNetG

Create EoIP transport to Courvoisier:

/interface eoip add name=EOIP.KitsNetG.to.Courvoisier \
 local-address=<ABSOLUT_IP> \
 remote-address=192.168.15.6 \
 tunnel-id=120

Attach EoIP to bridge:

/interface bridge port add bridge=BWF.KitsNetG interface=EOIP.KitsNetG.to.Courvoisier

Change Guest datapath:

/caps-man datapath set [find name="DP.KitsNetG"] local-forwarding=no bridge=BWF.KitsNetG

1.6 Prepare Courvoisier[edit | edit source]

Create matching EoIP interface:

/interface eoip add name=EOIP.KitsNetG.to.Absolut \
 local-address=192.168.15.6 \
 remote-address=<ABSOLUT_IP> \
 tunnel-id=120

Attach to Guest bridge:

/interface bridge port add bridge=BWF.KitsNetG interface=EOIP.KitsNetG.to.Absolut

1.7 Migration Procedure[edit | edit source]

1.7.1 Step 1 – Move Able[edit | edit source]

On Able:

/interface wireless cap set caps-man-addresses=<ABSOLUT_IP>

Verify on Absolut:

/caps-man remote-cap print
/caps-man interface print

Test:

  • KitsNet connectivity
  • KitsNetGN guest DHCP
  • IoT connectivity

1.7.2 Step 2 – Move Baker[edit | edit source]

On Baker:

/interface wireless cap set caps-man-addresses=<ABSOLUT_IP>

Verify both CAPs on Absolut:

/caps-man remote-cap print

1.7.3 Step 3 – Disable Courvoisier CAPsMAN[edit | edit source]

Once both CAPs are stable:

/caps-man manager set enabled=no

Lock CAPs:

/interface wireless cap set lock-to-caps-man=yes

1.8 Validation[edit | edit source]

On Absolut:

/caps-man registration-table print

On Courvoisier:

/ip dhcp-server lease print

Confirm:

  • clients on KitsNet obtain DHCP from Radix
  • guest clients obtain DHCP from Courvoisier
  • both CAPs remain connected to Absolut

1.9 Rollback[edit | edit source]

If migration fails revert CAPs to Courvoisier.

On CAP:

/interface wireless cap set caps-man-addresses=192.168.15.6

Re-enable CAPsMAN on Courvoisier if necessary:

/caps-man manager set enabled=yes

1.10 Stage B – Final Controller‑Only State[edit | edit source]

After a permanent Guest L2 path exists outside the CHR:

On Absolut:

/caps-man datapath set [find name="DP.KitsNetG"] local-forwarding=yes

Remove temporary EoIP:

/interface bridge port remove [find interface="EOIP.KitsNetG.to.Courvoisier"]
/interface eoip remove EOIP.KitsNetG.to.Courvoisier
/interface bridge remove BWF.KitsNetG

On Courvoisier:

/interface bridge port remove [find interface="EOIP.KitsNetG.to.Absolut"]
/interface eoip remove EOIP.KitsNetG.to.Absolut

1.11 Final State[edit | edit source]

  • Absolut runs CAPsMAN only
  • Courvoisier serves Guest DHCP
  • Radix serves LAN DHCP
  • CAPs locally forward all client traffic
  • no wireless data traffic transits the CHR