xlab: persist CAPWAP DF-clear so Cisco APs can join the WLC over the wg tunnel
The lab 3802 (b08b.cfa8.4fa8) joins the C9800 (10.0.10.10) via opt43/DNS, but its
DTLS cert is a ~1469B DON'T-FRAGMENT packet that blackholes on the 1420-MTU
wg-to-wgnet tunnel (AP ignores PMTUD + DHCP interface-mtu). Add a systemd service
that clears DF on UDP->10.0.10.10 at bond.lan254 ingress (tc pedit) so the cert
fragments through and the WLC reassembles it. With this live the AP reached
Operation Status: Registered. See memory cisco-wlc-discovery.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
1 parent cbcb310 commit c2cd3c5e725963465693ad48bc2b4cc9d7dd8215
@Dixiao-L Dixiao-L authored on 20 Jun
Showing 1 changed file
View
hosts/xlab-gateway/default.nix