1 CAPsMAN Migration: Courvoisier → Absolut[edit | edit source]
This document describes the complete migration of CAPsMAN control from courvoisier to the CHR instance absolut while preserving the existing DHCP architecture and ensuring that wireless client traffic does not traverse the CHR in the final design.
The migration is performed in two stages:
- Interim migration state – CAPsMAN moves to Absolut while Guest traffic may temporarily traverse the CHR.
- Final controller-only state – wireless client traffic no longer passes through Absolut.
1.1 Supporting Configuration Patch Files[edit | edit source]
- File:Courvoisier-final-post-migration-patch.rsc.txt
- @Courvoisier-final-post-migration-patch.rsc.txt
- File:Absolut-final-controller-only-patch.rsc.txt
- File:Courvoisier-interim-guest-transport-patch.rsc.txt
- File:Absolut-interim-migration-patch.rsc.txt
1.2 Architecture Context[edit | edit source]
| Component | Role |
|---|---|
| absolut | CAPsMAN controller (control plane only) |
| courvoisier | edge router and Guest DHCP server |
| radix.kitsnet.us (192.168.15.1) | DHCP server for main LAN and IoT network |
Wireless data traffic should remain on the physical LAN through the CAP devices and should not traverse the CHR once migration is complete.
1.3 SSID Design[edit | edit source]
| SSID | Purpose | DHCP Source |
|---|---|---|
| KitsNet | trusted WLAN | radix.kitsnet.us |
| KitsNetIN | IoT network | radix.kitsnet.us |
| KitsNetGN | guest WLAN | courvoisier |
1.4 Preconditions[edit | edit source]
Before beginning the migration verify:
1.4.1 CAP registration[edit | edit source]
On courvoisier:
/caps-man remote-cap print detail
Expected:
- able – Run
- baker – Run
1.4.2 CAP configuration[edit | edit source]
On able and baker:
/interface wireless cap print
Verify:
enabled: yes lock-to-caps-man: no caps-man-addresses: 192.168.15.6
1.4.3 Guest DHCP[edit | edit source]
On courvoisier:
/ip dhcp-server print detail
Confirm the DHCP server is bound to bridge:
BWF.KitsNetG
1.5 CAPsMAN Certificate Migration[edit | edit source]
The CAPsMAN controller identity must be preserved during migration. The active CAPsMAN certificate and CA must be copied from courvoisier to absolut.
This avoids CAP authentication failures or WPA handshake problems.
1.5.1 Step 1 – Identify certificates[edit | edit source]
On courvoisier:
/certificate print
Identify:
- CAPsMAN certificate
- CA certificate
Typical names:
CAPsMAN-488F5A87BE5 auto-ca-488F5A87BE5
1.5.2 Step 2 – Export certificates[edit | edit source]
On courvoisier:
/certificate export-certificate CAPsMAN-488F5A87BE5 export-passphrase=StrongPass /certificate export-certificate auto-ca-488F5A87BE5 export-passphrase=StrongPass
Generated files will appear in:
/file print
Typical exported files:
- CAPsMAN-488F5A87BE5.crt
- CAPsMAN-488F5A87BE5.key
- auto-ca-488F5A87BE5.crt
1.5.3 Step 3 – Transfer certificates to Absolut[edit | edit source]
Copy the files to absolut using:
- WinBox file transfer
- SCP
- FTP
Example using SCP:
scp *.crt admin@absolut:/ scp *.key admin@absolut:/
1.5.4 Step 4 – Import certificates on Absolut[edit | edit source]
On absolut:
/certificate import file-name=CAPsMAN-488F5A87BE5.crt passphrase=StrongPass /certificate import file-name=CAPsMAN-488F5A87BE5.key passphrase=StrongPass /certificate import file-name=auto-ca-488F5A87BE5.crt
Verify:
/certificate print
1.5.5 Step 5 – Assign certificates to CAPsMAN[edit | edit source]
On absolut:
/caps-man manager set enabled=yes \ certificate=CAPsMAN-488F5A87BE5 \ ca-certificate=auto-ca-488F5A87BE5
Verify:
/caps-man manager print
1.6 Stage A – Interim Migration State[edit | edit source]
During migration Guest traffic may temporarily traverse Absolut in order to maintain connectivity with the Guest DHCP server on courvoisier.
1.6.1 Prepare Absolut[edit | edit source]
Create temporary Guest bridge:
/interface bridge add name=BWF.KitsNetG
Create EoIP tunnel to courvoisier:
/interface eoip add name=EOIP.KitsNetG.to.Courvoisier \ local-address=<ABSOLUT_IP> \ remote-address=192.168.15.6 \ tunnel-id=120
Attach the tunnel to the bridge:
/interface bridge port add bridge=BWF.KitsNetG interface=EOIP.KitsNetG.to.Courvoisier
Update the Guest datapath:
/caps-man datapath set [find name="DP.KitsNetG"] local-forwarding=no bridge=BWF.KitsNetG
1.6.2 Prepare Courvoisier[edit | edit source]
Create the matching EoIP interface:
/interface eoip add name=EOIP.KitsNetG.to.Absolut \ local-address=192.168.15.6 \ remote-address=<ABSOLUT_IP> \ tunnel-id=120
Attach to Guest bridge:
/interface bridge port add bridge=BWF.KitsNetG interface=EOIP.KitsNetG.to.Absolut
1.7 Migration Procedure[edit | edit source]
1.7.1 Step 1 – Move Able[edit | edit source]
On able:
/interface wireless cap set caps-man-addresses=<ABSOLUT_IP>
Verify on Absolut:
/caps-man remote-cap print /caps-man interface print
Test:
- KitsNet connectivity
- Guest DHCP
- IoT connectivity
Rollback if needed:
/interface wireless cap set caps-man-addresses=192.168.15.6
1.7.2 Step 2 – Move Baker[edit | edit source]
On baker:
/interface wireless cap set caps-man-addresses=<ABSOLUT_IP>
Verify both CAPs:
/caps-man remote-cap print
1.7.3 Step 3 – Disable CAPsMAN on Courvoisier[edit | edit source]
Once both CAPs are stable:
/caps-man manager set enabled=no
Lock CAPs:
/interface wireless cap set lock-to-caps-man=yes
1.8 Validation[edit | edit source]
On absolut:
/caps-man registration-table print
On courvoisier:
/ip dhcp-server lease print
Verify:
- clients on KitsNet obtain DHCP from Radix
- guest clients obtain DHCP from Courvoisier
- CAPs remain connected to Absolut
1.9 Rollback[edit | edit source]
If migration fails revert CAPs to Courvoisier.
On CAP:
/interface wireless cap set caps-man-addresses=192.168.15.6
Re-enable CAPsMAN:
/caps-man manager set enabled=yes
1.10 Stage B – Final Controller-Only State[edit | edit source]
After a permanent Guest L2 path exists outside the CHR:
On absolut:
/caps-man datapath set [find name="DP.KitsNetG"] local-forwarding=yes
Remove temporary EoIP:
/interface bridge port remove [find interface="EOIP.KitsNetG.to.Courvoisier"] /interface eoip remove EOIP.KitsNetG.to.Courvoisier /interface bridge remove BWF.KitsNetG
On courvoisier:
/interface bridge port remove [find interface="EOIP.KitsNetG.to.Absolut"] /interface eoip remove EOIP.KitsNetG.to.Absolut
1.11 Final State[edit | edit source]
- Absolut runs CAPsMAN only
- Courvoisier continues Guest DHCP
- Radix provides LAN DHCP
- CAPs locally forward client traffic
- No wireless data traffic traverses the CHR