Ruckus VSZ Unable to find new R510 AP

  • 1
  • Question
  • Updated 2 months ago
  • Answered
I am running VSZ version 3.4.0.0.976. I have currently 21 AP. I purchased 5 AP and configured 4 of them without an issue, when setting up the last one it is not showing up in the vSZ.
Everything has been done over the same physical port with no configuration changes. I am able to ping the VSZ from the AP. The AP is running firmware 110.0.0.0.663. Currently i have 1 license free of 21 in the vSZ. I have tried resetting and reconfiguring the AP from CLI over SSH and over the browser. Any ideas what else to try?
I have attached the picture of my VSZ licenseses.
Photo of Jako Nurges

Jako Nurges

  • 9 Posts
  • 1 Reply Like

Posted 2 months ago

  • 1
Photo of Said Sanoussi

Said Sanoussi

  • 25 Posts
  • 8 Reply Likes
is the vSZ-E or H deployement. If H deployement you need to take a look at the staging zone. If it's an E deployement you should see the AP's where you need to approve them before they will join
Photo of Jako Nurges

Jako Nurges

  • 9 Posts
  • 1 Reply Like
Hi,
it is an H enviornment. The thing is the AP does not appear in the list where i should approve it. That is the problem i am having. It seems it is not getting connected to the VSZ-H
(Edited)
Photo of Said Sanoussi

Said Sanoussi

  • 25 Posts
  • 8 Reply Likes
make sure it is connected to the same subnet. just to test it. Otherwise set the ip adres of your vSZ via SSH by typing: set scg ip <ipaddress controller> and reboot the ap. this may force a tunnel to the controller
Photo of David Saez

David Saez, Employee

  • 7 Posts
  • 1 Reply Like
Hi Jako,

have you tried factory resetting the AP?

Thanks.
David.
Photo of Jako Nurges

Jako Nurges

  • 9 Posts
  • 1 Reply Like
Hi,
I have factory reset it. I can access the VSZ from the AP itself. The network config is fine since i was able to configure the other 20 AP with everything being the same. I had a typo above i am running essentials of VSZ. The thing is all AP after enableing the scg ip "controller ip" have become visible in the smart zone under AP where i accept them. Except this one, this AP just doesent show up there.

I have tried resetting it from browser and physically holding down the reset button until it blinks from red to green. and configuring it again.

I have tried replacing the cable it is connected with.
i have tried connecting it to another switch. I have tried configuring it over the POE and regular port with/without external power source.

Additionally after adding the IP and rebooting the AP the CTL LED blinks slowly - it should blink fast (indicating that the vsz has been found and it has been connected there needing approval).
(Edited)
Photo of David Saez

David Saez, Employee

  • 7 Posts
  • 1 Reply Like
Hi Jako,
can you check the events and alarms of the vSZ GUI?

Also launch these commands on the AP and paste the output here:
get scg
get sshtunnel

Thanks.
David.
 
Photo of Jako Nurges

Jako Nurges

  • 9 Posts
  • 1 Reply Like
Hi,
there are no events or alarms triggered when the AP is rebooted and should be connecting to the vSZ.
The only alarm i have is icense threshold exceeded
Critical
Outstanding
[AP Capacity License] limit reached at [90%].
But since i have still 1 license unused it should not be the problem

AP gives the response to commands:

  • get scg
  • SCG Service is enabled.
  • AP is not managed by SCG.
  • State: DISC_REQ_STATE
  • Server List: 192.168.174.11
  • No SSH tunnel exists
  • Failover List: Not found
  • Failover Max Retry: 2
  • DHCP Opt43 Code: 6
  • Server List from DHCP (Opt43/Opt52): Not found
  • SCG default URL: RuckusController
  • SCG config|heartbeat intervals: 30|30
  • SCG gwloss|serverloss timeouts: 1800|7200


  • get sshtunnel
  • SSH tunnel service is enabled
  • No SSH tunnel exists
  • Cipher for SSH tunnel: 128
  • OK

(Edited)
Photo of David Saez

David Saez, Employee

  • 7 Posts
  • 1 Reply Like
Hi Jako,

Confirm that both port 22 and 443 (TCP) are open for access from the AP subnet. You can test this by a simple telnet command from a host within the AP subnet, to the control IP of the vSCG:
telnet x.x.x.x 443
telnet x.x.x.x 22

Please, also launch this command:
get syslog log

Scroll until reference to the wsgclient application is noted, similar to these messages:
Oct 14 08:15:29 AP02-LS-EG-Check-In daemon.err /usr/sbin/wsgclient[687]: httpRecv 277 http status is 0
Oct 14 08:15:29 AP02-LS-EG-Check-In daemon.err /usr/sbin/wsgclient[687]: crHttpRequestWithAuth 564
ret:9798
Oct 14 08:15:29 AP02-LS-EG-Check-In daemon.err /usr/sbin/wsgclient[687]: registration 390 Failed to
send Discovery packet! ret:9798

Thanks.

David.
Photo of Jako Nurges

Jako Nurges

  • 9 Posts
  • 1 Reply Like
Hi,
ports are opened i am able to telnet from that port when inside that subnet.

syslog below:
Oct 10 11:36:04 RuckusAP daemon.err wsgclient[707]: curl_https_request:1060 curl                                                                                                                                                      _easy_perform failed:[35][SSL connect error].
Oct 10 11:36:06 RuckusAP daemon.info channel-wifi1: init: (18:4b:0d:29:85:4c) in                                                                                                                                                      terval=15
Oct 10 11:36:06 RuckusAP daemon.info channel-wifi0: init: (18:4b:0d:29:85:48) in                                                                                                                                                      terval=15
Oct 10 11:36:06 RuckusAP daemon.info channel-wifi1: unable to find active wlan d                                                                                                                                                      evice for wifi1
Oct 10 11:36:06 RuckusAP daemon.info channel-wifi0: unable to find active wlan d                                                                                                                                                      evice for wifi0
Oct 10 11:36:10 RuckusAP daemon.err wsgclient[707]: curl_https_request:1060 curl                                                                                                                                                      _easy_perform failed:[35][SSL connect error].
Oct 10 11:36:11 RuckusAP daemon.info hub_registrar: OCSP: 'Good' via ocsp-check                                                                                                                                                       - querying registrar @ ap-registrar.ruckuswireless.com
Oct 10 11:36:12 RuckusAP user.notice hub_registrar: query result - ''
Oct 10 11:36:14 RuckusAP daemon.warn Eved: Last Reboot Reason: user reboot
Oct 10 11:36:16 RuckusAP daemon.err wsgclient[707]: curl_https_request:1060 curl                                                                                                                                                      _easy_perform failed:[35][SSL connect error].
Oct 10 11:36:22 RuckusAP daemon.err wsgclient[707]: curl_https_request:1060 curl                                                                                                                                                      _easy_perform failed:[35][SSL connect error].
Oct 10 11:36:23 RuckusAP daemon.info hub_registrar: OCSP: APR lookup timer expir                                                                                                                                                      ed
Oct 10 11:36:28 RuckusAP daemon.err wsgclient[707]: curl_https_request:1060 curl                                                                                                                                                      _easy_perform failed:[35][SSL connect error].
Oct 10 11:36:28 RuckusAP local2.err syslog: Parameter value L2 is invalid for pa                                                                                                                                                      rameter Tunnel-Mode
Oct 10 11:36:29 RuckusAP daemon.info hub_registrar: OCSP: 'Good' via ocsp-check                                                                                                                                                       - querying registrar @ ap-registrar.ruckuswireless.com
Oct 10 11:36:30 RuckusAP local2.err syslog: Failed to retrieve get poe power mod                                                                                                                                                      e
Oct 10 11:36:30 RuckusAP user.notice hub_registrar: query result - ''
Oct 10 11:36:34 RuckusAP daemon.err wsgclient[707]: curl_https_request:1060 curl                                                                                                                                                      _easy_perform failed:[35][SSL connect error].
Oct 10 11:36:40 RuckusAP daemon.err wsgclient[707]: curl_https_request:1060 curl                                                                                                                                                      _easy_perform failed:[35][SSL connect error].
Oct 10 11:36:46 RuckusAP daemon.err wsgclient[707]: curl_https_request:1060 curl                                                                                                                                                      _easy_perform failed:[35][SSL connect error].
Oct 10 11:36:46 RuckusAP daemon.info hub_registrar: OCSP: 'Good' via ocsp-check                                                                                                                                                       - querying registrar @ ap-registrar.ruckuswireless.com
Oct 10 11:36:48 RuckusAP user.notice hub_registrar: query result - ''
Oct 10 11:36:52 RuckusAP daemon.err wsgclient[707]: curl_https_request:1060 curl                                                                                                                                                      _easy_perform failed:[35][SSL connect error].
Oct 10 11:36:58 RuckusAP daemon.err wsgclient[707]: curl_https_request:1060 curl                                                                                                                                                      _easy_perform failed:[35][SSL connect error].
Oct 10 11:37:02 RuckusAP local2.err syslog: (ap state) AP begin to join ac.
Oct 10 11:37:04 RuckusAP daemon.err wsgclient[707]: curl_https_request:1060 curl                                                                                                                                                      _easy_perform failed:[35][SSL connect error].
Oct 10 11:37:04 RuckusAP daemon.info hub_registrar: OCSP: 'Good' via ocsp-check                                                                                                                                                       - querying registrar @ ap-registrar.ruckuswireless.com
Oct 10 11:37:05 RuckusAP user.notice hub_registrar: query result - ''
Photo of David Saez

David Saez, Employee

  • 7 Posts
  • 1 Reply Like
Hi Jako,

this could be a HW problem with the AP. Could you please log a case to Ruckus Support? We need to troubleshoot this in deeper detail.

There seems to be a problem when creating the ssh tunnel:
Oct 10 11:36:34 RuckusAP daemon.err wsgclient[707]: curl_https_request:1060 curl                                                                                                                                                      _easy_perform failed:[35][SSL connect error].

Thanks.
David.
Photo of Jako Nurges

Jako Nurges

  • 9 Posts
  • 1 Reply Like
Hi all,
got a completely new device from factory as replacement, same issue. The last device tested in another enviornment worked fine so the issue must be with the management. Thing is it stopped working after 20 licenses were consumed, maybe its related? Even tho i have 1 AP license free so it is extremely confusing.
Photo of Jako Nurges

Jako Nurges

  • 9 Posts
  • 1 Reply Like
Hi,
as a conclusion i was able to get the device to the management console. I had to downgrade the AP firmware from 110 to 104.xx and after that it was accepted from the management.
Photo of Michael Brado

Michael Brado, Official Rep

  • 2588 Posts
  • 353 Reply Likes
Thanks for sharing your solution!