Capwap Active Sessions in 2 ISP topology

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Capwap Active Sessions in 2 ISP topology

L2 Linker

Kind regards

Team

We currently have a topology in which the remote site has 2 VPNS configured (each VPN established by a different channel). The VPNs are configured against our Perimeter FW and the switching between them is done with Path Monitoring. The remote site has some Access Points that established a session (Capwap) against a controller that is located behind our Perimeter FW. The situation we present is the following.

1. When the APs connect to the controller, a Capwap session is established through tunnel 1. (Everything is fine up to there)
2. When tunnel 1 goes down, the new traffic begins to be routed through tunnel 2, however, we have seen that the Capwap sessions are being activated on tunnel 1 causing the APs to lose connectivity with the controller and the remote site's wifi is affected.
3. The way to solve this has been manually clearing all the Capwap sessions that were active so that when it tries to establish the capwap with the controller again it does so through the tunnel active at the time.

According to the evidence, we see that there are active Capwap sessions that will last up to 2 days or even more.

The question is, is there any way to modify the Capwap application timers so that the FW identifies or closes those active sessions?

Or what possible solutions could be evaluated?

1 REPLY 1

Cyber Elite
Cyber Elite

Hi @afalfaro ,

 

There is a way to override application timeouts with custom services.  https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/app-id/service-based-session-timeouts

 

Here is another doc that describes your problem very well and provides a unique solution of sending an API call to itself!  https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBmqCAG  I would clear all sessions filtered by destination-port, e.g. your tunnel interface, instead of UDP, but it is a great doc nonetheless.

 

Please let us know if any of these solutions work for you!

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.
  • 59 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!