Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

DHCP issue over Instant-VPN: Centralized L2 Mode

This thread has been viewed 5 times
  • 1.  DHCP issue over Instant-VPN: Centralized L2 Mode

    Posted Oct 07, 2016 03:35 AM
      |   view attached

     

    Hi there,

    I am assisting a customer with a POC and I am having issues with DHCP over an Instant-VPN to a 7005 Cloud Services Controller. The VPN between the IAP and 7005 controller is operating correctly but I cannot for the life of me get DHCP working.

     

    I have set up a DHCP scope on Cloud Services Controller (VLAN 400 - 10.10.10.0 /24) which also has a VLAN 400 interface with IP address of 10.10.10.1. The 7005 Controller is also the Default Gateway for this subnet.

     

    The SSID is VC assigned to VLAN 400, The DHCP scope is set to L2-Centralized specifiying VLAN 400. It does not matter if I enable DHCP relay or not.

     

    The client simply never gets an IP address. The debugs show it constantly sending out DHCP request with no reply. Configuring the DHCP server locally on the IAP using local mode or distributed works fine.

     

    Any ideas?

     

    -Brett

    Attachment(s)

    txt
    Client Debug.txt   60 KB 1 version


  • 2.  RE: DHCP issue over Instant-VPN: Centralized L2 Mode

    Posted Oct 07, 2016 09:36 AM

    If you configure a static IP address on your client connected to the IAP, can you successfully ping the controllers interface on VLAN 400?

     

    What Instant version are you running?

     

    What uplink type do you have on your IAP?

     

    Cheers,



  • 3.  RE: DHCP issue over Instant-VPN: Centralized L2 Mode

    Posted Oct 07, 2016 12:27 PM

    How are you tunnelling back to the controller?

    Per iAP or from the VC?

    When I was setting up my Guest VLAN, I had a similar experience.

    I learned that in the VC-sourced-tunnel I would need to put the VLAN into the switch-fabric so that the client's DHCP request and the DHCP server's response could get from the VC to the client's AP over that fabric.

    In per-iAP tunnels, the DHCP exchange passes from client to AP over tunnel and back smoothly.

     



  • 4.  RE: DHCP issue over Instant-VPN: Centralized L2 Mode

    Posted Oct 07, 2016 09:32 PM

    Hi Matthew,

     

    Thanks for the response. I was wondering whether I need to tag VLAN 400 on the switching network, but there there will only be a single AP per site, so clients will connect directly to the IAP/VC. This solution is also for a guest network.

     

    -Brett

     



  • 5.  RE: DHCP issue over Instant-VPN: Centralized L2 Mode

    Posted Oct 07, 2016 09:38 PM

    Hi Christoffer,

     

    I will have to try pinging the Controller on Monday. It was late Friday evening here in Australia and didn't even think of using a static IP as the other DHCP methods worked locally. I will try ping the controller from the client on Monday.

     

    Uplink type is IPSEC, single IAP.

     

    IAP version is 6.5.0.0-4.3.0.0. This was setup by the local Aruba SE leading the POC.

     

    -Brett



  • 6.  RE: DHCP issue over Instant-VPN: Centralized L2 Mode

    Posted Oct 14, 2016 07:54 PM

    I'm running iAP: 6.4.2.6-4.1.1.8_50989

    and Controller: 6.4.2.8

     

    My configuration has the controller as a layer-2 connection to the switch and router for VLAN 100, which may be a significant difference between our configurations.

     

    Here are my settings in case it helps your thinking...

     

    Here's the iAP configurations:

    SSID-VLAN.png

    DHCP-Servers.png

    Tunnel-Controllers.png

    Tunnel-Routing.png

     

    And the Controller settings:

    Controller-tunnel.png

     



  • 7.  RE: DHCP issue over Instant-VPN: Centralized L2 Mode
    Best Answer

    Posted Oct 15, 2016 03:45 AM

    Thank you all for the feedback. It turns out the VLAN interface on the Mobility Controller was administraively shut down. TAC advised that it can only be brought back up via the CLI. Is this really the case?

     

    -Brett



  • 8.  RE: DHCP issue over Instant-VPN: Centralized L2 Mode
    Best Answer

    EMPLOYEE
    Posted Oct 15, 2016 07:04 AM

    If it is not tied to a physical interface, yes, that is the case.



  • 9.  RE: DHCP issue over Instant-VPN: Centralized L2 Mode

    Posted Oct 15, 2016 01:39 PM

    Go into the vlan interface and issue the command operstate up or something like that =)

     

    Cheers,