KitsNet Network:LAN:absolut:CAPsMAN Migration: Difference between revisions

Peter A. Smode (talk | contribs)
Tags: Reverted Visual edit
Peter A. Smode (talk | contribs)
Undo revision 2081 by Psmode (talk)
Tag: Undo
Line 16: Line 16:


* [[File:Courvoisier-final-post-migration-patch.rsc.txt]]
* [[File:Courvoisier-final-post-migration-patch.rsc.txt]]
* @Courvoisier-final-post-migration-patch.rsc.txt
* [[File:Absolut-final-controller-only-patch.rsc.txt]]
* [[File:Absolut-final-controller-only-patch.rsc.txt]]
* [[File:Courvoisier-interim-guest-transport-patch.rsc.txt]]
* [[File:Courvoisier-interim-guest-transport-patch.rsc.txt]]

Revision as of 13:10, 14 March 2026

1 CAPsMAN Migration: Courvoisier → Absolut[edit | edit source]

This document describes the complete migration of CAPsMAN control from courvoisier to the CHR instance absolut while preserving the existing DHCP architecture and ensuring that wireless client traffic does not traverse the CHR in the final design.

The migration is performed in two stages:

  1. Interim migration state – CAPsMAN moves to Absolut while Guest traffic may temporarily traverse the CHR.
  2. Final controller-only state – wireless client traffic no longer passes through Absolut.

1.1 Supporting Configuration Patch Files[edit | edit source]


1.2 Architecture Context[edit | edit source]

Component Role
absolut CAPsMAN controller (control plane only)
courvoisier edge router and Guest DHCP server
radix.kitsnet.us (192.168.15.1) DHCP server for main LAN and IoT network

Wireless data traffic should remain on the physical LAN through the CAP devices and should not traverse the CHR once migration is complete.


1.3 SSID Design[edit | edit source]

SSID Purpose DHCP Source
KitsNet trusted WLAN radix.kitsnet.us
KitsNetIN IoT network radix.kitsnet.us
KitsNetGN guest WLAN courvoisier

1.4 Preconditions[edit | edit source]

Before beginning the migration verify:

1.4.1 CAP registration[edit | edit source]

On courvoisier:

/caps-man remote-cap print detail

Expected:

  • able – Run
  • baker – Run

1.4.2 CAP configuration[edit | edit source]

On able and baker:

/interface wireless cap print

Verify:

enabled: yes
lock-to-caps-man: no
caps-man-addresses: 192.168.15.6

1.4.3 Guest DHCP[edit | edit source]

On courvoisier:

/ip dhcp-server print detail

Confirm the DHCP server is bound to bridge:

BWF.KitsNetG

1.5 CAPsMAN Certificate Migration[edit | edit source]

The CAPsMAN controller identity must be preserved during migration. The active CAPsMAN certificate and CA must be copied from courvoisier to absolut.

This avoids CAP authentication failures or WPA handshake problems.

1.5.1 Step 1 – Identify certificates[edit | edit source]

On courvoisier:

/certificate print

Identify:

  • CAPsMAN certificate
  • CA certificate

Typical names:

CAPsMAN-488F5A87BE5
auto-ca-488F5A87BE5

1.5.2 Step 2 – Export certificates[edit | edit source]

On courvoisier:

/certificate export-certificate CAPsMAN-488F5A87BE5 export-passphrase=StrongPass
/certificate export-certificate auto-ca-488F5A87BE5 export-passphrase=StrongPass

Generated files will appear in:

/file print

Typical exported files:

  • CAPsMAN-488F5A87BE5.crt
  • CAPsMAN-488F5A87BE5.key
  • auto-ca-488F5A87BE5.crt

1.5.3 Step 3 – Transfer certificates to Absolut[edit | edit source]

Copy the files to absolut using:

  • WinBox file transfer
  • SCP
  • FTP

Example using SCP:

scp *.crt admin@absolut:/
scp *.key admin@absolut:/

1.5.4 Step 4 – Import certificates on Absolut[edit | edit source]

On absolut:

/certificate import file-name=CAPsMAN-488F5A87BE5.crt passphrase=StrongPass
/certificate import file-name=CAPsMAN-488F5A87BE5.key passphrase=StrongPass
/certificate import file-name=auto-ca-488F5A87BE5.crt

Verify:

/certificate print

1.5.5 Step 5 – Assign certificates to CAPsMAN[edit | edit source]

On absolut:

/caps-man manager set enabled=yes \
 certificate=CAPsMAN-488F5A87BE5 \
 ca-certificate=auto-ca-488F5A87BE5

Verify:

/caps-man manager print

1.6 Stage A – Interim Migration State[edit | edit source]

During migration Guest traffic may temporarily traverse Absolut in order to maintain connectivity with the Guest DHCP server on courvoisier.

1.6.1 Prepare Absolut[edit | edit source]

Create temporary Guest bridge:

/interface bridge add name=BWF.KitsNetG

Create EoIP tunnel to courvoisier:

/interface eoip add name=EOIP.KitsNetG.to.Courvoisier \
 local-address=<ABSOLUT_IP> \
 remote-address=192.168.15.6 \
 tunnel-id=120

Attach the tunnel to the bridge:

/interface bridge port add bridge=BWF.KitsNetG interface=EOIP.KitsNetG.to.Courvoisier

Update the Guest datapath:

/caps-man datapath set [find name="DP.KitsNetG"] local-forwarding=no bridge=BWF.KitsNetG

1.6.2 Prepare Courvoisier[edit | edit source]

Create the matching EoIP interface:

/interface eoip add name=EOIP.KitsNetG.to.Absolut \
 local-address=192.168.15.6 \
 remote-address=<ABSOLUT_IP> \
 tunnel-id=120

Attach to Guest bridge:

/interface bridge port add bridge=BWF.KitsNetG interface=EOIP.KitsNetG.to.Absolut

1.7 Migration Procedure[edit | edit source]

1.7.1 Step 1 – Move Able[edit | edit source]

On able:

/interface wireless cap set caps-man-addresses=<ABSOLUT_IP>

Verify on Absolut:

/caps-man remote-cap print
/caps-man interface print

Test:

  • KitsNet connectivity
  • Guest DHCP
  • IoT connectivity

Rollback if needed:

/interface wireless cap set caps-man-addresses=192.168.15.6

1.7.2 Step 2 – Move Baker[edit | edit source]

On baker:

/interface wireless cap set caps-man-addresses=<ABSOLUT_IP>

Verify both CAPs:

/caps-man remote-cap print

1.7.3 Step 3 – Disable CAPsMAN on Courvoisier[edit | edit source]

Once both CAPs are stable:

/caps-man manager set enabled=no

Lock CAPs:

/interface wireless cap set lock-to-caps-man=yes

1.8 Validation[edit | edit source]

On absolut:

/caps-man registration-table print

On courvoisier:

/ip dhcp-server lease print

Verify:

  • clients on KitsNet obtain DHCP from Radix
  • guest clients obtain DHCP from Courvoisier
  • CAPs remain connected to Absolut

1.9 Rollback[edit | edit source]

If migration fails revert CAPs to Courvoisier.

On CAP:

/interface wireless cap set caps-man-addresses=192.168.15.6

Re-enable CAPsMAN:

/caps-man manager set enabled=yes

1.10 Stage B – Final Controller-Only State[edit | edit source]

After a permanent Guest L2 path exists outside the CHR:

On absolut:

/caps-man datapath set [find name="DP.KitsNetG"] local-forwarding=yes

Remove temporary EoIP:

/interface bridge port remove [find interface="EOIP.KitsNetG.to.Courvoisier"]
/interface eoip remove EOIP.KitsNetG.to.Courvoisier
/interface bridge remove BWF.KitsNetG

On courvoisier:

/interface bridge port remove [find interface="EOIP.KitsNetG.to.Absolut"]
/interface eoip remove EOIP.KitsNetG.to.Absolut

1.11 Final State[edit | edit source]

  • Absolut runs CAPsMAN only
  • Courvoisier continues Guest DHCP
  • Radix provides LAN DHCP
  • CAPs locally forward client traffic
  • No wireless data traffic traverses the CHR