|
xlab: persist CAPWAP DF-clear so Cisco APs can join the WLC over the wg tunnel
The lab 3802 (b08b.cfa8.4fa8) joins the C9800 (10.0.10.10) via opt43/DNS, but its DTLS cert is a ~1469B DON'T-FRAGMENT packet that blackholes on the 1420-MTU wg-to-wgnet tunnel (AP ignores PMTUD + DHCP interface-mtu). Add a systemd service that clears DF on UDP->10.0.10.10 at bond.lan254 ingress (tc pedit) so the cert fragments through and the WLC reassembles it. With this live the AP reached Operation Status: Registered. See memory cisco-wlc-discovery. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> |
|---|
|
|
| hosts/xlab-gateway/default.nix |
|---|