OC300 cannot adopt EAP670

OC300 cannot adopt EAP670

OC300 cannot adopt EAP670
OC300 cannot adopt EAP670
Wednesday
Model: OC300  
Hardware Version: V1
Firmware Version: 1.30.7 Build 20250704 Rel.78617

I suddenly have problems adopting my 3 APs throuch the controller Web UI.

 

My APs are all

EAP670 1.0

Firmware: 1.1.1 Build 20250326 Rel. 61737(4555)

 

  • I have a management network on vlan 100
  • I have configured the port on the switch that wires directly to the AP with "All" profile.
  • There no ACLs at all configured
  • All Networks are interfaces with a specified vlan number
  • I resetted all APs (web UI shows wizard)
    • So currently no dedicated management vlan is set on the AP standalone config
  • All devices can be reached by ping (also intermediate switches)
  • My topology is
    • Router
      • Controller
      • Switch MAIN
        • Switch AP
          • AP 1
          • AP 2
          • AP 3

 

When I am in the user vlan (different than management) with my workstation I can ping the APs, but I cannot reach the UI of the APs. When I am in the Management network with my workstation I can ping and reach the web ui.

 

The APs pop up in the list of devices as PENDING, but when I try to adopt the adoption fails because "the AP dis not react to adoption commands".

 

If I go through the wizard and set the controller ip in the APs settings, I first get an adoption error because of the uasername/password (expected), if then enter them in the window in the controller ui, i get the same error as above.

 

This setup worked for > 2 years. suddenly connection to the APs where broken, I tried to forget them and re-provision and now i am in this situation.

 

What can I do to solve this? How can I debug?

 

I restarted every device in the network, all firmwares are up to date.

  0      
  0      
#1
Options
12 Reply
Re:OC300 cannot adopt EAP670
Wednesday
The port on the router that is connected to the controller is configured with PVID 100 (management)
  0  
  0  
#2
Options
Re:OC300 cannot adopt EAP670
Wednesday
All switches are omada switches: Switch Main: SX3016F v1.20 Switch AP: TL-SG3210XHP-M2 v2.0
  0  
  0  
#3
Options
Re:OC300 cannot adopt EAP670
Thursday

Hi  @Lukas12343333 

 

Thanks for posting here.

What's the IP addresses did  the EAPs get? Are they in the VLAN 100, or the default VLAN, or else?

Could you please give us a screenshot of the controller's Device page?

The error message means that the communication between EAP and Hardware Controller is blocked.

Omada Software Controller/ Hardware Controller communicates with Omada EAP via TCP/UDP port 29810-29816. Some anti-virus programs or firewalls may block this kind of packet. You can disable the anti-virus or firewalls in your network first for checking. And you need to open TCP/UDP port 29810-29816 in the anti-virus/firewalls.


 

 

  0  
  0  
#4
Options
Re:OC300 cannot adopt EAP670
Thursday

  @Lukas12343333 

 

The IP of the EAPs must reside in the management vlan that the controller lives in - it cannot adopt them cross-vlan.  You will need to set them up with the right management vlan in standalone mode first

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
  0  
  0  
#5
Options
Re:OC300 cannot adopt EAP670
Thursday

  @Vincent-TP 

 

The APs get a ip from the management network (vlan=100, management vlan).

The ports on which the APs a wired are configured with "All" Profile.

There are only Omada components in the network and they are all configured by the controller.

There is no ACL configured for Gateway, Switch, AP.

The AP in its standalone settings has no management vlan configured, if I do that they become inaccessible, I guess because although controller and AP has both management network ips, the vlan flag is not set, but it is management network by beeing untagged.

 

 

There are 2 more APs which I currently have deactivated because they are open otherwise.

  0  
  0  
#6
Options
Re:OC300 cannot adopt EAP670
Thursday

  @GRL 

Then web ui access is lost...

  0  
  0  
#7
Options
Re:OC300 cannot adopt EAP670
Friday - last edited Friday

Hi  @Lukas12343333 

Thanks for the reply.

What's the profile of the OC300 port? What's the IP address of the OC300?

 

Did you check anti-virus software or firewall of the workstation? 

Is it possible to try these via a different PC?

  0  
  0  
#8
Options
Re:OC300 cannot adopt EAP670
Friday

  @Vincent-TP 

 

Controller gets an IP from the management network. It is on a router lan port with the following settings:

 

 

The whole experience happens equally on different client workstations. There is no Anti-Virus Software and only totally standard Windows Firewall.

  0  
  0  
#9
Options
Re:OC300 cannot adopt EAP670
Friday

  @Vincent-TP 

 

I disabled Windows Firewall. Does not help anything.

  0  
  0  
#10
Options
Re:OC300 cannot adopt EAP670
Friday - last edited Friday

Hi  @Lukas12343333 

 

All switches stays connected, only those EAP having the problem, right?

 

Do you mind factory reset one EAP and try to adopt it again?

  0  
  0  
#11
Options