1 CAPsMAN Migration Plan[edit | edit source]
Courvoisier → Absolut (CHR)
1.1 Objectives[edit | edit source]
- Move CAPsMAN control from Courvoisier to Absolut
- Preserve current SSIDs and datapath behavior during migration
- Ensure no client traffic passes through Absolut
- Avoid network disruption
- Allow immediate rollback
- Perform datapath cleanup after migration
1.2 Phase 0 — Pre-Migration Verification[edit | edit source]
Verify current operational state.
1.2.1 On Courvoisier[edit | edit source]
/caps-man remote-cap print detail
Expected:
identity="able" identity="baker" state="Run"
1.2.2 On Able[edit | edit source]
/interface wireless cap print
Verify:
enabled: yes lock-to-caps-man: no caps-man-addresses: 192.168.15.6
1.2.3 On Baker[edit | edit source]
Run the same command and confirm identical settings.
1.2.4 Confirm Courvoisier owns the manager IP[edit | edit source]
/ip address print
Verify:
192.168.15.6/23
1.3 Phase 1 — Prepare Absolut[edit | edit source]
This phase does not impact the network.
1.3.1 Enable CAPsMAN[edit | edit source]
On Absolut:
/caps-man manager set enabled=yes
Verify:
/caps-man manager print
1.3.2 Verify CAPsMAN configuration objects exist[edit | edit source]
/caps-man configuration print /caps-man provisioning print /caps-man datapath print
Ensure the following objects exist:
- able-2.4-KitsNet
- able-5.0-KitsNet
- baker-2.4-KitsNet
- baker-5.0-KitsNet
- slave-KitsNetGN
- slave-KitsNetIN
Do not modify datapaths yet.
1.3.3 Confirm forwarding behavior[edit | edit source]
/caps-man datapath print
Expected:
local-forwarding: yes
1.4 Phase 2 — Copy Certificates[edit | edit source]
Preserve CAP trust identity.
1.4.1 On Courvoisier[edit | edit source]
List certificates:
/certificate print
Export the CAPsMAN certificate and CA:
/certificate export-certificate <capsman-cert> export-passphrase=StrongPass /certificate export-certificate <capsman-ca> export-passphrase=StrongPass
Files created:
<cert>.crt <cert>.key <ca>.crt
1.4.2 Copy files to Absolut[edit | edit source]
Use SCP, WinBox, or FTP.
1.4.3 On Absolut[edit | edit source]
Import certificates:
/certificate import file-name=<cert>.crt /certificate import file-name=<cert>.key /certificate import file-name=<ca>.crt
Assign them:
/caps-man manager set certificate=<capsman-cert> ca-certificate=<capsman-ca>
Verify:
/caps-man manager print
1.5 Phase 3 — Migration (One CAP First)[edit | edit source]
Move Able first.
1.5.1 On Able[edit | edit source]
Change manager address:
/interface wireless cap set caps-man-addresses=<absolut-ip>
Example:
/interface wireless cap set caps-man-addresses=192.168.15.25
Expected behavior: within ~10 seconds Able disconnects from Courvoisier and connects to Absolut.
1.6 Phase 4 — Validate Able[edit | edit source]
1.6.1 On Absolut[edit | edit source]
/caps-man remote-cap print detail
Expected:
identity="able" state="Run"
1.6.2 Verify radios[edit | edit source]
/caps-man interface print
Expected:
able-2.4-KitsNet able-5.0-KitsNet slave-KitsNetGN slave-KitsNetIN
1.6.3 Verify clients[edit | edit source]
/caps-man registration-table print
Test client connectivity for:
- KitsNet
- KitsNetGN
- KitsNetIN
1.7 Phase 5 — Migrate Baker[edit | edit source]
On Baker:
/interface wireless cap set caps-man-addresses=<absolut-ip>
Verify on Absolut:
/caps-man remote-cap print
Expected:
able Run baker Run
1.8 Phase 6 — Validate Full Operation[edit | edit source]
Confirm:
/caps-man interface print /caps-man registration-table print /caps-man radio print
1.9 Phase 7 — Disable CAPsMAN on Courvoisier[edit | edit source]
Once migration is stable:
/caps-man manager set enabled=no
1.10 Phase 8 — Re-Lock CAPs[edit | edit source]
On Able:
/interface wireless cap set lock-to-caps-man=yes
On Baker:
/interface wireless cap set lock-to-caps-man=yes
1.11 Phase 9 — Post-Migration Datapath Cleanup[edit | edit source]
This will be performed after the migration as a separate exercise.
Possible improvements:
- correct IoT datapath usage
- enforce VLAN isolation
- ensure Able/Baker provisioning symmetry
- validate forwarding model
No datapath changes are made during the migration.
1.12 Rollback Procedure[edit | edit source]
If anything fails:
On Able:
/interface wireless cap set caps-man-addresses=192.168.15.6
On Baker:
/interface wireless cap set caps-man-addresses=192.168.15.6
CAPs will reconnect to Courvoisier within seconds.
1.13 Final Sanity Checklist[edit | edit source]
Before migration confirm:
- Absolut CAPsMAN enabled
- Certificates imported
- CAPs unlocked
- Provisioning objects present
- Datapaths unchanged
- Rollback command prepared