Instant On - Wired

 View Only
  • 1.  Local Management - HTTPS redirects to IP instead of Hostname

    Posted 10-25-2020 07:26 AM

    I have a 48-Port 1930 Switch (JL686A) and use the local management interface. I would like to use HTTPS with a proper certificate, but the switch keeps redirecting me to its IP address instead of continuing to use the hostname.

    For example, when you access the switch via a hostname:

    https://switch.mynetwork.com

    The switch will immediately redirect you (with HTTP 302) to https://10.1.1.1 which will break TLS, because the certificate is only issued for switch.mynetwork.com. The redirect will occur regardless of whether accessing the management interface via HTTP or HTTPS. This is a new behaviour and was not present with older Aruba switches (e.g. the 1920S does not do this).

    Is there any way to turn this off?


    #localmanagement
    #https
    #redirect


  • 2.  RE: Local Management - HTTPS redirects to IP instead of Hostname

    Posted 10-26-2020 08:37 AM

    Hi jnsp,

    I'm not 100% sure, but just using a DNS name with http results in similar behaviour. So I don't think it's an https specific problem. That said, it does create more of an issue using TLS / certs.



  • 3.  RE: Local Management - HTTPS redirects to IP instead of Hostname

    Posted 10-26-2020 08:44 AM

    Hi @MrFixit ,

    yes, this is not an issue with only HTTPS. The switch redirects to its IP address regardless of whether it is accessed via HTTP or HTTPS. It should not happen either way and I don't understand the reasoning behind the redirect.

     



  • 4.  RE: Local Management - HTTPS redirects to IP instead of Hostname

    Posted 12-15-2020 12:40 PM
    Has this issue been fixed? Oh, wait ...... no it hasn't!

    ------------------------------
    Colin Fieldgate
    ------------------------------



  • 5.  RE: Local Management - HTTPS redirects to IP instead of Hostname

    Posted 01-18-2022 09:53 AM
    Happy 2022!

    This issue is still not fixed!!!! What gives????


  • 6.  RE: Local Management - HTTPS redirects to IP instead of Hostname

    Posted 01-24-2022 04:53 PM
    Hi Colin,

    The 2.5.0 release will include the new behavior and resolve the issue described.

    ------------------------------
    Aruba Instant On Communications
    ------------------------------



  • 7.  RE: Local Management - HTTPS redirects to IP instead of Hostname

    Posted 01-25-2022 06:41 AM
    Isn't the 2.5.0 release just for cloud managed switches? Perhaps you mean 1.0.8? If so, when will this be coming?

    https://community.arubainstanton.com/browse/blogs/blogviewer?blogkey=8aac4e14-50d9-4991-8c72-602a4d87768d


  • 8.  RE: Local Management - HTTPS redirects to IP instead of Hostname

    Posted 06-30-2022 10:52 AM
    We are still waiting on this fix. It causes issues for us as we remotely manage a lot of switches for clients. Is there an ETA on this being fixed in the locally managed firmware?

    ------------------------------
    Adam Harm
    ------------------------------



  • 9.  RE: Local Management - HTTPS redirects to IP instead of Hostname

    Posted 21 days ago

    Dear All, did this one ever get solved? I have one 1960 (JL805A) which is running firmware 2.9.1.17 (latest one I assume, not the easiest to find for some reason) and in the GUI you have the option to set DNS for the switch which I assume means that thihgs like this will work. But I also have three 1930's and they do not have the DNS server option at all which means NTP etc. won't work with FQDN only IP and hence issues with all other advanced featutures like this that requires DNS. I've tried with the latest firmware (same version number as for the 1960 at 2.9.1.17, I've just tried with an older release (2.8.1.35) but same issue, not possible to configure a DNS server. I even managed to find the config command for it in the config file from the 1960 "ip name-server 8.8.8.8" and added that to the config for a 1930 and tried it but of course no luck there either. I'm currently looking into deploying ADCS with NDES/SCEP which, assuming I get it up and running, won't work due to this. The 1930 series of switches are really nice otherwise as a fairly cheap entry/medium level switch with enterprise features, or so I thought. So any news on when this will be fixed or how to fix it now if that is possible? Thanks



    ------------------------------
    Mikael Cogne
    ------------------------------



  • 10.  RE: Local Management - HTTPS redirects to IP instead of Hostname

    Posted 20 days ago

    Hi,

    On my 1830s, running 2.9.1, running local management, I don't experience the redirect to IP address problem.

    I used "lets encrypt" certificates on these switches for a while , it worked ok but it's a bit painful as you have to request the certificates on another device, e g. A Debian VM & then convert to correct format & upload the certificates to the switch using the web gui.

    There are no apis or CLI on 1830 so the process has to be manually repeated every time the certificate expires.



    ------------------------------
    Travis Thorne
    ------------------------------