Hello,
My clients aren't retaining their vlan association after re-authentication on a WPA2-PSK SSID (our .1x SSID is working perfectly). I have a 3600 controller and a mixture of primarily AP-105s and AP-135s. We have two Windows Server 2012r2 machines that handle DHCP/DNS/Domain Controller roles. The "clients" are HP P1102w laserjet printers that can't do 802.1x so we had to create a WPA2-PSK SSID for them.
Here's our reproducable scenario:
1. Ensure there are no existing DHCP leases for the printer
2. Turn on the printer and configure it to connect to the printer SSID
3. Observe the printer gets a vlan 40 IP
4. Power off the printer, wait for it to fall asleep, or become deauthenticated from the AP
5. Power on the printer
6. Observe the printer "gets stuck" in an Initializing state
7. Log in to a DHCP server and observe the printer has been assigned an IP from vlan 1
8. Additionally, observe the Aruba Controller has 0.0.0.0 listed as the client IP for the MAC
Here's the SSID, virtual-ap, and user role config for the printer SSID:
wlan ssid-profile "printer"
essid "Printer"
opmode wpa2-psk-aes
hide-ssid
! wpa-passphrase <removed>
!
wlan virtual-ap "printer"
aaa-profile "printer"
ssid-profile "printer"
vlan 40
steering-mode balance-bands
no mobile-ip
preserve-vlan
!
user-role printer
vlan 40
dpi disable
web-cc disable
access-list session global-sacl
access-list session apprf-printer-sacl
access-list session allowall
!
(master01) #show interface gigabitethernet 1/0 switchport
Name: GE1/0
Switchport: Enabled
Administrative mode: trunk
Operational mode: trunk
Administrative Trunking Encapsulation: dot1q
Operational Trunking Encapsulation: dot1q
Access Mode VLAN: 0 ((Inactive))
Trunking Native Mode VLAN: 1 (Default)
Trunking Vlans Enabled: ALL
Trunking Vlans Active: 1,10,20,30,40,60
And, on the switch side (Aruba MAS S3500 stack)-
interface-profile switching-profile "trunk"
switchport-mode trunk
!
interface gigabitethernet "1/0/25"
description "GE 1/0/25 - Aruba-Master"
switching-profile "trunk"
!
I've swapped the AP forward mode from tunnel to bridge mode and still get the same symptoms.
Any help or troubleshooting tips to possibly find the root cause of this would be fantastic.