Wireless Access

last person joined: 21 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

AP 105 in Bridge Mode

This thread has been viewed 2 times
  • 1.  AP 105 in Bridge Mode

    Posted Mar 10, 2015 04:26 AM

    Hi all,

     

    We have AP 105
    We have a virtual AP profile setup in bridge mode with settings:-

    VLAN:13, Forward mode:bridge

    The controller is untagged vlan 1 and tagged vlan 13.

    DHCP is on the controller and give address on Vlan 13.

     

    The APs are connected to network switches and those connected ports are with vlan 1 untagged and vlan 13 tagged.

     

    The address ip is well received but I can't access to network vlan 13 (ping gateway give no responses, no internet access etc).


    I've checked in AP-Group> AP> System Profile> Native VLAN and is 1 which is configured. So it must taged the packet in vlan 13.

     

    If I plug a cable on the port instead the AP and at the other end a laptop , everithing works fine.

    I must have missed something but I can't find what I have missed.

    Thanks in advance for any help.



  • 2.  RE: AP 105 in Bridge Mode

    Posted Mar 10, 2015 07:57 AM

    Hi,

    Please clarify the following for better understanding your issue.

     

    1. What type of link you have between Switch and the AP ( Access or Trunk ) ?

    2. Controller is the gateway ?

     

     

    Clarify the above and feel free for any help on this.



  • 3.  RE: AP 105 in Bridge Mode

    Posted Mar 10, 2015 11:01 AM

    Hi,

     

    Thanks for you reply.

     

    1. The AP are access in vlan 10 and trunk in vlan 13

    2. No, the gateway is our firewall.

     

     



  • 4.  RE: AP 105 in Bridge Mode

    Posted Mar 10, 2015 11:07 AM

    Is your AP configured as a campus AP ?

    Do you have CPSec enabled ?



  • 5.  RE: AP 105 in Bridge Mode

    Posted Mar 10, 2015 11:25 AM

    Hi,

    As per my understanding,

    1. APs are connected to a Switch and Aruba controller is reachable from the AP.

    2. APs are getting IP address from VLAN 1 subnet

    3. There is one SSID on bridge mode and clients connected to this SSID are not getting IP , right ?

     

    Please ensure the following cofig is in place,

     

    1. The switch port where AP is connected should be a trunk link ( coz client traffic will go out of the tunnel) and VLAN 13 should be allowed.

    2. As victor said, CPSec should be enabled in order to bring up Bridge mode SSID.

    3.DHCP should be reachable from the switch where AP is connected ( Ensure the IP Helper is configured as per the requirement)

     

    If you fulfill all the above, when a client connected to a bridge mode SSID, AP will forward the DHCP traffic of the client over the uplink port ( will not go through the GRE tunnel) hence DHCP traffic will reach the Switch where AP is connected.

     

    Hope you got some clarity on this.

     



  • 6.  RE: AP 105 in Bridge Mode

    Posted Mar 10, 2015 11:52 AM

    Thanks for you reply

     

    @Victor :

    Yes ap are configured as campus AP

     

    And Yes CPSEC is enabled.

     

    @dhanraj : To clarify

     

    1. yes

    2. No, from vlan 10 (DHCP is controller)

    3. There is another SSID in Tunnel Mode which works fine.

     Clients who connect to ssid in bridge mode get addess ip in the good vlan (13) but cannot communicate with the gateway, controller etc.  and of course don't have internet access



  • 7.  RE: AP 105 in Bridge Mode

    Posted Mar 10, 2015 12:01 PM

    So clients can get an IP address from the switch.


    Do clients shows any devices in their arp cache when you try to ping your gateway or the switch?

     

    from CLI on the client try

     

    # arp -a

     

    You Also said:

     

    "If I plug a cable on the port instead the AP and at the other end a laptop , everithing works fine."

     

    Wouldn't this laptop default to the native vlan? Can you try configuring a switch port to access vlan 13 and see if you client gets an IP and network access that way? Unless i just misunderstood and thats what was tried.



  • 8.  RE: AP 105 in Bridge Mode

    Posted Mar 10, 2015 12:27 PM

    Yes clients get an ip address from the switch.

     

    I can't try the command today. I will do this friday. 

     

    For my test I put the VLAN ID 13 in my network card (advanced options) on my laptop and then plug my laptop instead of the AP and everything works fine (access to network, internet etc.)



  • 9.  RE: AP 105 in Bridge Mode

    Posted Mar 10, 2015 12:33 PM

    One other thing to check. What role does the client get? As i understand in Bridge mode the AP still enforcement the roles Firewall policy on the user. If the user is falling in to a logon role or some restricted role they might get DHCP but then no actual network access.

     

    Just another thought



  • 10.  RE: AP 105 in Bridge Mode

    Posted Mar 16, 2015 11:07 AM

    Hi,

     

    So I tried "arp -a" after a ping command and nothing appears, just the brodcast address of the network of the new SSID.

     

    I've also checked the roles and nothing seems to stop the traffic.

     

    Any ideas ?

     

    Thanks,



  • 11.  RE: AP 105 in Bridge Mode

    Posted Apr 13, 2015 08:45 AM

    up !



  • 12.  RE: AP 105 in Bridge Mode

    Posted Jan 22, 2018 03:09 PM

    What was the solution to your problem?  We are experiencing a similar problem on our bridged networks.



  • 13.  RE: AP 105 in Bridge Mode

    Posted Apr 11, 2019 08:50 PM
    What was your solution????

    I am having this same exact issue ! Been on this for weeks

    Please help !


  • 14.  RE: AP 105 in Bridge Mode

    EMPLOYEE
    Posted Apr 11, 2019 09:37 PM

    That original post was from 4 years ago!   Please open your own thread with your issue.