Wireless Access

last person joined: 21 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

IAP103 - No Internet for clients connected to guest SSID

This thread has been viewed 6 times
  • 1.  IAP103 - No Internet for clients connected to guest SSID

    Posted Jul 05, 2017 09:06 AM

    Good day,

    as the title says, last week I installed a IAP103 to a customer (upgraded to the latest firmware 6.5.3.1), and configured two SSIDs: the one with DHCP managed by the network works fine, despite the guest SSID with IP assigned by virtual controller doesn't allow Internet to be accessed.

    Clients connect correctly, the IP is assigned (172.31.99.x) but on different smartphones the saeìme message "no Internet" appears.

    I tried both with no restrictions and also allowing only dhcp and dns services, but it's still the same.

    I tried adding another guest network, with no success.

    Any suggestion?

    Thanks in advance.

     

    Alain



  • 2.  RE: IAP103 - No Internet for clients connected to guest SSID

    EMPLOYEE
    Posted Jul 05, 2017 09:11 AM

    Network traffic for guests that are on a Virtual Controller assigned VLAN would be natted out of the ip address of the Master Virtual Controller.  If the ip address of that master controller does not have permission on your external firewall to go to the internet, your guests will not have any connectivity..



  • 3.  RE: IAP103 - No Internet for clients connected to guest SSID

    Posted Jul 05, 2017 09:18 AM
    I already allowed the only ap to access the internet.

    Alain Pasquali - SISTEC S.r.l

    ________________________________

    Hai bisogno di assistenza tecnica?

    Registrati ed accedi al portale helpdesk.sistec.net oppure invia una mail a helpdesk@sistec.net
    Per l'assistenza remota, utilizza Teamviewer scaricandolo dal seguente indirizzo: https://get.teamviewer.com/rw6pa5h

    ________________________________

    --
    Questo messaggio e' stato analizzato da Libra ESVA ed e' risultato non infetto.
    This message was scanned by Libra ESVA and is believed to be clean.
    Per informazioni: http://helpdesk.sistec.net


  • 4.  RE: IAP103 - No Internet for clients connected to guest SSID

    EMPLOYEE
    Posted Jul 05, 2017 09:38 AM

    You should do a trace on your firewall to see if you see traffic from that IAP.  If you have configured a Virtual IP address, that would be the address the traffic is coming from..



  • 5.  RE: IAP103 - No Internet for clients connected to guest SSID

    Posted Jul 05, 2017 09:40 AM
    Thank you, I'm going to try in a few minutes.

    Alain Pasquali - SISTEC S.r.l

    ________________________________

    Hai bisogno di assistenza tecnica?

    Registrati ed accedi al portale helpdesk.sistec.net oppure invia una mail a helpdesk@sistec.net
    Per l'assistenza remota, utilizza Teamviewer scaricandolo dal seguente indirizzo: https://get.teamviewer.com/rw6pa5h

    ________________________________

    --
    Questo messaggio e' stato analizzato da Libra ESVA ed e' risultato non infetto.
    This message was scanned by Libra ESVA and is believed to be clean.
    Per informazioni: http://helpdesk.sistec.net


  • 6.  RE: IAP103 - No Internet for clients connected to guest SSID

    Posted Jul 06, 2017 02:57 AM

    Hi,

    yesterday I wasn’t able to do the trace on the firewall, but I can tell you that only guest network (with addresses assigned by the virtual controller) aren’t able to access the Internet.

    It seems that the firewall (router, is an old Funkwerk R3000) doesn’t let the guest network pass, even if it arrives “natted” by the virtual controller.

    Any suggestion?

    Thanks



  • 7.  RE: IAP103 - No Internet for clients connected to guest SSID

    Posted Jul 06, 2017 05:01 AM

    Hi,

    I just collected a trace of the firewall's traffic with a client connected to the guest network, and looking at it with Wireshark I wasn't able to find anything related to the virtual controller's IP.

     



  • 8.  RE: IAP103 - No Internet for clients connected to guest SSID

    EMPLOYEE
    Posted Jul 06, 2017 05:30 AM

    @pasky wrote:

    Good day,

    as the title says, last week I installed a IAP103 to a customer (upgraded to the latest firmware 6.5.3.1), and configured two SSIDs: the one with DHCP managed by the network works fine, despite the guest SSID with IP assigned by virtual controller doesn't allow Internet to be accessed.

    Clients connect correctly, the IP is assigned (172.31.99.x) but on different smartphones the saeìme message "no Internet" appears.

    I tried both with no restrictions and also allowing only dhcp and dns services, but it's still the same.

    I tried adding another guest network, with no success.

    Any suggestion?

    Thanks in advance.

     

    Alain


    Is this only a single IAP or multiple IAPs?  Can you share the SSID configuration for the guest SSID?



  • 9.  RE: IAP103 - No Internet for clients connected to guest SSID

    Posted Jul 06, 2017 05:46 AM

    There is only one IAP installed in the environment.

    The guest SSID network is configured with:

    - no start page

    - WPA2-PSK

    - Virtual Controller-managed DHCP

    Access rules are configured as follows:

    1) DNS, DHCP access granted to any destination

    2) traffic to LAN denied

    3) traffic to any granted

     



  • 10.  RE: IAP103 - No Internet for clients connected to guest SSID

    EMPLOYEE
    Posted Jul 06, 2017 06:10 AM

    I see in your first post that you also tried it with no restrictions.  When you try that, can you ping anywhere outside of the IAP?



  • 11.  RE: IAP103 - No Internet for clients connected to guest SSID

    Posted Jul 06, 2017 06:16 AM

    Unfortunately I didn't make that test, and now I'm away from the customer.

    Yesterday I tried to make the same test with the rules I mentioned above, and I was able to reach only the VC (with IP 172.31.98.1), no local IP addresses nor public IPs neither public hostnames.

     



  • 12.  RE: IAP103 - No Internet for clients connected to guest SSID

    EMPLOYEE
    Posted Jul 06, 2017 06:21 AM

    If you SSH into the IAP during the test, you should be able to type "show datapath session table" to see what traffic the client is attempting to send and if it is getting blocked by the IAP.  That test will only work if you have rules applied on your guest clients.  If you have it as "unrestricted" it will not work, so just have a single rule allowing all traffic before you try that command.

     

    You can also use the "debug pkt" method to trace network traffic coming out of that AP from that client:  http://community.arubanetworks.com/t5/Controller-less-WLANs/Debugging-DHCP-packets-on-Aruba-Instant-IAP/ta-p/179058



  • 13.  RE: IAP103 - No Internet for clients connected to guest SSID

    Posted Jul 06, 2017 06:27 AM

    Thanks a lot for your suggestions, I will try ASAP.



  • 14.  RE: IAP103 - No Internet for clients connected to guest SSID

    Posted Jul 06, 2017 07:32 AM

    I've just noticed that the AP is rebooting itself every about 5 minutes...it's connected to an HP 2530-8G PoE switch (that is working fine).

    I'm trying to update the firmware of the switch, in case of PoE issues.



  • 15.  RE: IAP103 - No Internet for clients connected to guest SSID

    Posted Jul 06, 2017 08:32 AM

    I confirm what I told before: the IAP is rebooting itself every 5 minutes. I suppose it has some kind of hardware issue, what do you think?

    Thanx in advance.



  • 16.  RE: IAP103 - No Internet for clients connected to guest SSID

    EMPLOYEE
    Posted Jul 06, 2017 09:05 AM

    "show version" will say why it rebooted.  That might give you a clue...



  • 17.  RE: IAP103 - No Internet for clients connected to guest SSID

    Posted Jul 06, 2017 09:11 AM

    I think I found the solution: in the customer's network someone gave static addresses to applicances not managed by me, which are included in the DHCP pool. The IAP103 took an address already assigned to some kind of appliance, and that is causing all the issues.

    I've no confirmation at the moment, the IP assigned by DHCP to the IAP answers also when the AP is rebooting... :-)

     



  • 18.  RE: IAP103 - No Internet for clients connected to guest SSID
    Best Answer

    Posted Jul 06, 2017 09:45 AM

    After creating a DHCP exclusion for the IP manually assigned and (obviously) automatically given to the IAP103, and assigning a static IP to the AP, all problems have been solved.

    Thanks a lot for your help.