Date: Thu, 28 Mar 2024 16:02:49 +0100 (CET) Message-ID: <1827610745.5902.1711638169637@k5115.pixsoftware.de> Subject: Exported From Confluence MIME-Version: 1.0 Content-Type: multipart/related; boundary="----=_Part_5901_485235762.1711638169636" ------=_Part_5901_485235762.1711638169636 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Content-Location: file:///C:/exported.html
Description:
Config Sync is used to synchronize the configurations between two VPN ga= teways or two WLAN controllers: When both devices have identical configurat= ions, the slave can fully take over the functions if the master fails. If t= he synchronization stops working and changes are made to the master configu= ration, they will not be transferred to the slave. A failure of the master = could cause communications to be restricted.
This article describes the steps to take if the Config Sync stops workin= g.
To set up configuration synchronization between two WLAN controllers, se= lect one of the two WLAN controllers in LANconfig and drag & drop it on= to the other device.
How to manually setup the configuration synchronization between two VPN = gateways is described in this article.
Requirements:
Procedure:
1) Use the same firmwar= e on both devices:
In principle, the Config Sync will work on devices with different firmwa= re versions. However, if a firmware version implements a new feature and th= e addition of a new column to the command-line path, a conflict may arise s= ince the entry is no longer unambiguous (see point 4).
For this reason we recommend that you use the same firmware version on b= oth devices.
2) Check the Config Sync certificate:
Using SSH, connect to both devices and enter the CLI command Check the following parameters: 2.1) Non-matching certificates on the two WLAN controllers: Reset the slave to its factory settings and, in LANconfig, drag it onto =
the master again. This sets up the Config Sync anew and the certificate is =
obtained once again. 2.2) Non-matching certificates on the two VPN gateways:=
Reset the slave to its factory settings and reconfigure it as described =
in this know=
ledge base article starting from step 2. 3) Check for error messages in Config Sync: Connect to the master via SSH and enter the command ls /Sta=
tus/Config/Sync/New-Cluster. In this example an error has occurred:
4) LCOS as of version 10.40 on a VPN gateway: Adjustment of the =
"Ignored rows" table required On a VPN gateway, the default route is usually excluded from synchroniza=
tion by using the menu Management =E2=86=92 Synchronization =E2=86=
=92 Ignored rows. After a firmware update to version 10.40 or higher the =
following error message is output (also see point 3):
In this case the row index needs to be supplemented with a 0 because the administrative distance=
was added as a new feature with firmware 10.40. The entry must therefore b=
e 255.255.255.255 0.0.0.0 0 0. The firmware update must be carried out on both devices, otherwise only =
one of the two devices will support the admin=
istrative distance feature, which would lead to a conflict.
5) When using the table=
"Access stations" the IP address of the other cluster member has to be sto=
red as well: When using the table "A=
ccess stations" in the menu Management =E2=86=92=
Admin =E2=86=92 Access settings =E2=86=92 Configuration access w=
ays the IP address (e.g. IP address 192.1=
68.1.1 Netmask 255.255.255.255) or the whole netw=
ork of the other WLAN Controller (e.g. IP address =
192.168.1.0 Netmask 255.255.255.0) has to be entered in the table =
in order for the devices to be able to communicate with each other!<=
/p>
Possible statuses and troubleshooting: