Last edited 6 months ago
by Peter A. Smode

KitsNet Network:LAN:absolut:CAPsMAN Migration

Revision as of 17:43, 12 March 2026 by Peter A. Smode (talk | contribs) (Created page with "= CAPsMAN Migration Plan = Courvoisier → Absolut (CHR) == Objectives == # Move CAPsMAN control from '''Courvoisier''' to '''Absolut''' # Preserve current SSIDs and datapath behavior during migration # Ensure '''no client traffic passes through Absolut''' # Avoid network disruption # Allow immediate rollback # Perform datapath cleanup '''after migration''' ---- == Phase 0 — Pre-Migration Verification == Verify current operational state. === On Courvoisier === <...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

1 CAPsMAN Migration Plan[edit | edit source]

Courvoisier → Absolut (CHR)

1.1 Objectives[edit | edit source]

  1. Move CAPsMAN control from Courvoisier to Absolut
  2. Preserve current SSIDs and datapath behavior during migration
  3. Ensure no client traffic passes through Absolut
  4. Avoid network disruption
  5. Allow immediate rollback
  6. Perform datapath cleanup after migration

1.2 Phase 0 — Pre-Migration Verification[edit | edit source]

Verify current operational state.

1.2.1 On Courvoisier[edit | edit source]

/caps-man remote-cap print detail

Expected:

identity="able"
identity="baker"
state="Run"

1.2.2 On Able[edit | edit source]

/interface wireless cap print

Verify:

enabled: yes
lock-to-caps-man: no
caps-man-addresses: 192.168.15.6

1.2.3 On Baker[edit | edit source]

Run the same command and confirm identical settings.

1.2.4 Confirm Courvoisier owns the manager IP[edit | edit source]

/ip address print

Verify:

192.168.15.6/23

1.3 Phase 1 — Prepare Absolut[edit | edit source]

This phase does not impact the network.

1.3.1 Enable CAPsMAN[edit | edit source]

On Absolut:

/caps-man manager set enabled=yes

Verify:

/caps-man manager print

1.3.2 Verify CAPsMAN configuration objects exist[edit | edit source]

/caps-man configuration print
/caps-man provisioning print
/caps-man datapath print

Ensure the following objects exist:

  • able-2.4-KitsNet
  • able-5.0-KitsNet
  • baker-2.4-KitsNet
  • baker-5.0-KitsNet
  • slave-KitsNetGN
  • slave-KitsNetIN

Do not modify datapaths yet.

1.3.3 Confirm forwarding behavior[edit | edit source]

/caps-man datapath print

Expected:

local-forwarding: yes

1.4 Phase 2 — Copy Certificates[edit | edit source]

Preserve CAP trust identity.

1.4.1 On Courvoisier[edit | edit source]

List certificates:

/certificate print

Export the CAPsMAN certificate and CA:

/certificate export-certificate <capsman-cert> export-passphrase=StrongPass
/certificate export-certificate <capsman-ca> export-passphrase=StrongPass

Files created:

<cert>.crt
<cert>.key
<ca>.crt

1.4.2 Copy files to Absolut[edit | edit source]

Use SCP, WinBox, or FTP.

1.4.3 On Absolut[edit | edit source]

Import certificates:

/certificate import file-name=<cert>.crt
/certificate import file-name=<cert>.key
/certificate import file-name=<ca>.crt

Assign them:

/caps-man manager
set certificate=<capsman-cert> ca-certificate=<capsman-ca>

Verify:

/caps-man manager print

1.5 Phase 3 — Migration (One CAP First)[edit | edit source]

Move Able first.

1.5.1 On Able[edit | edit source]

Change manager address:

/interface wireless cap
set caps-man-addresses=<absolut-ip>

Example:

/interface wireless cap
set caps-man-addresses=192.168.15.25

Expected behavior: within ~10 seconds Able disconnects from Courvoisier and connects to Absolut.


1.6 Phase 4 — Validate Able[edit | edit source]

1.6.1 On Absolut[edit | edit source]

/caps-man remote-cap print detail

Expected:

identity="able"
state="Run"

1.6.2 Verify radios[edit | edit source]

/caps-man interface print

Expected:

able-2.4-KitsNet
able-5.0-KitsNet
slave-KitsNetGN
slave-KitsNetIN

1.6.3 Verify clients[edit | edit source]

/caps-man registration-table print

Test client connectivity for:

  • KitsNet
  • KitsNetGN
  • KitsNetIN

1.7 Phase 5 — Migrate Baker[edit | edit source]

On Baker:

/interface wireless cap
set caps-man-addresses=<absolut-ip>

Verify on Absolut:

/caps-man remote-cap print

Expected:

able   Run
baker  Run

1.8 Phase 6 — Validate Full Operation[edit | edit source]

Confirm:

/caps-man interface print
/caps-man registration-table print
/caps-man radio print

1.9 Phase 7 — Disable CAPsMAN on Courvoisier[edit | edit source]

Once migration is stable:

/caps-man manager set enabled=no

1.10 Phase 8 — Re-Lock CAPs[edit | edit source]

On Able:

/interface wireless cap
set lock-to-caps-man=yes

On Baker:

/interface wireless cap
set lock-to-caps-man=yes

1.11 Phase 9 — Post-Migration Datapath Cleanup[edit | edit source]

This will be performed after the migration as a separate exercise.

Possible improvements:

  • correct IoT datapath usage
  • enforce VLAN isolation
  • ensure Able/Baker provisioning symmetry
  • validate forwarding model

No datapath changes are made during the migration.


1.12 Rollback Procedure[edit | edit source]

If anything fails:

On Able:

/interface wireless cap
set caps-man-addresses=192.168.15.6

On Baker:

/interface wireless cap
set caps-man-addresses=192.168.15.6

CAPs will reconnect to Courvoisier within seconds.


1.13 Final Sanity Checklist[edit | edit source]

Before migration confirm:

  • Absolut CAPsMAN enabled
  • Certificates imported
  • CAPs unlocked
  • Provisioning objects present
  • Datapaths unchanged
  • Rollback command prepared