Aruba Instant & Cloud Wi-Fi

Reply
Occasional Contributor II
Posts: 34
Registered: ‎12-12-2013

Client placed in wrong VLAN 4.1

[ Edited ]

I updated to 4.1 last week and have one strange issue. I have 1 client that keeps getting a IP from the manegment VLAN.

See screenshot. They are joining our guest network which has 1 statically assigned vlan and use's wpa2

 

Any ideas? Is this just a wierd bug?

 

Alex

MVP
Posts: 4,077
Registered: ‎07-20-2011

Re: Client placed in wrong VLAN 4.1

What's the IP assignment setup under the network ?

 

Static or network assigned ?

 

Can you confirm the wired settings to make sure that the VLAN is allow ?

Thank you

Victor Fabian
Lead Mobility Engineer @ Integration Partners
AMFX | ACMX | ACDX | ACCX | CWAP | CWDP | CWNA
Occasional Contributor II
Posts: 34
Registered: ‎12-12-2013

Re: Client placed in wrong VLAN 4.1

[ Edited ]

The Vlan is static, DHCP is from network. Wired settings is allow all vlans.

 

Alex

MVP
Posts: 1,404
Registered: ‎10-25-2011

Re: Client placed in wrong VLAN 4.1

Can you post the config?
Pasquale Monardo | Senior Network Solutions Consultant
ACDX #420 | ACMP
[If you found my post helpful, please give kudos!]
Occasional Contributor II
Posts: 34
Registered: ‎12-12-2013

Re: Client placed in wrong VLAN 4.1

Here is the guest access config:

 

wlan ssid-profile Guest enable index 0 type employee essid LogosGuest wpa-passphrase  opmode wpa2-psk-aes max-authentication-failures 0 vlan 20 auth-server InternalServer rf-band all captive-portal disable dtim-period 1 inactivity-timeout 1000 broadcast-filter arp g-min-tx-rate 5 multicast-rate-optimization dynamic-multicast-optimization dmo-channel-utilization-threshold 90 local-probe-req-thresh 0 max-clients-threshold 64

 

and wierd port confuigs

 

wired-port-profile default_wired_port_profile switchport-mode trunk allowed-vlan all native-vlan 1 shutdown access-rule-name default_wired_port_profile speed auto duplex full no poe type employee captive-portal disable no dot1x wired-port-profile wired-instant switchport-mode access allowed-vlan all native-vlan guest no shutdown access-rule-name wired-instant speed auto duplex auto no poe type guest captive-portal disable no dot1x enet0-port-profile default_wired_port_profile uplink preemption enforce none failover-internet-pkt-lost-cnt 10 failover-internet-pkt-send-freq 30 failover-vpn-timeout 180

New Contributor
Posts: 3
Registered: ‎09-16-2013

Re: Client placed in wrong VLAN 4.1

Check to see if spanning tree is blocking that VLAN on your switch 

Occasional Contributor II
Posts: 34
Registered: ‎12-12-2013

Re: Client placed in wrong VLAN 4.1

I was finally able to get a hold of one of the laptops. I wandered around to multiple areas served by competely different switches and AP's and was not able to make it get a correct IP address. This weekend I set a allow to any except for the managemnt vlan rule. I will see today if that prevents this from happening. Althouhg I belive it is a bug because it never happened before and that should really not be necessary.

 

Alex

Aruba Employee
Posts: 200
Registered: ‎07-14-2013

Re: Client placed in wrong VLAN 4.1

I noticed that in your SSID configuration, there were the following:

 

wlan ssid-profile Guest
...

essid LogosGuest

 

May I ask how the ssid-profile name and the essid name is different?  Was this configured through CLI instead of UI?

 

Thanks,

 

Yan

Occasional Contributor II
Posts: 34
Registered: ‎12-12-2013

Re: Client placed in wrong VLAN 4.1

That was my sanitizing effort to keep the compnays name out of my post. I missed the essid. They are both the same.

 

This problem is still happening. Even with access control rules set to expilcity deny access to that network. Is this good enough for a bug report or is there a better way for me to report this?

 

Alex

MVP
Posts: 1,404
Registered: ‎10-25-2011

Re: Client placed in wrong VLAN 4.1

I guess at this point, if you haven't already is to open a TAC case to dig deeper.
This is definitely strange behavior.
Pasquale Monardo | Senior Network Solutions Consultant
ACDX #420 | ACMP
[If you found my post helpful, please give kudos!]
Search Airheads
Showing results for 
Search instead for 
Did you mean: