Skip to main content
BSHcow
New Member
September 29, 2023
Question

Aruba SSL Issue

  • September 29, 2023
  • 4 replies
  • 4189 views

Fortigate 81F v7.4.1

 

I have some Aruba APs at a new site.  7 of the 12 connect to Aruba Central without a problem, but 5 of them give a certificate error.  All APs connect through the same switch, VLAN and DHCP scope.  All can ping externally using DNS and by IP

 

The APs are trying to connect to device-uswest4.central.arubanetworks.com.  I found that the working ones resolve that to 44.226.202.64 and the non-working ones resolve to 208.91.112.55, which seems to be fortinet-block-page-55.fortinet.com.

 

I have tried all the default SSL inspection security profiles and have removed all other security profiles.

 

Why would some APs be resolving to this Fortinet block page?

 

Screenshot 2023-09-29 101212.png

4 replies

xshkurti
Staff
Staff
September 29, 2023

@BSHcow 
What are DNS settings of your 5 non-working Aruba APs? Do they have the same DNS configuration?
If you check from Fortigate
# exe ping device-uswest4.central.arubanetworks.com
what ip is resolved?

ytech
New Member
November 14, 2023

Did you find the solution? Having the same problem with FG80F v7.2.6.
Tried different DNS servers/settings on Fortigate, with UTP enabled and disabled.
All Aruba access points are connections directly to Fortinet block page 55 IP address.

ap01# ping device-eucentral2.central.arubanetworks.com
Press 'q' to abort.
PING 208.91.112.55 (208.91.112.55): 56 data bytes
64 bytes from 208.91.112.55: icmp_seq=0 ttl=56 time=36.8 ms
64 bytes from 208.91.112.55: icmp_seq=1 ttl=56 time=36.7 ms
64 bytes from 208.91.112.55: icmp_seq=2 ttl=56 time=36.5 ms
64 bytes from 208.91.112.55: icmp_seq=3 ttl=56 time=36.6 ms
64 bytes from 208.91.112.55: icmp_seq=4 ttl=56 time=36.6 ms

--- 208.91.112.55 ping statistics ---
5 packets transmitted, 5 packets received, 0% packet loss
round-trip min/avg/max = 36.5/36.6/36.8 ms

 

pminarik
Staff
Staff
November 14, 2023

208.91.112.55 is the default IP address used for blocking domains by DNS filter.

 

Carefully review the policies used by your APs, especially for DNS traffic. Make sure they either don't have DNS profiles enabled, or review those profiles and check if they have any configuration that could lead to blocking those domain names.

 

If the APs are using some internal server for DNS, check relevant policies for that server's own upstream DNS traffic as well.

 

If everything looks fine, consider restarting the APs, maybe they've just cached a previously-blocked result that isn't being blocked anymore.

Sheikh
Staff
Staff
November 14, 2023

Hi, are these problematic and working APs have same DNS settings ? If yes and still getting same errors on some of the APs, you can try creating a static DNS entry pointing towards 44.226.202.64.

 

regards,

 

Sheikh

If you have found a solution, please like and mark it as solved to make it easily accessible for everyone.
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!