Wireless Access

Reply
Regular Contributor I
Posts: 187
Registered: ‎03-27-2013

Large number of errors on firewall's interface due to WiFi Clients Traffic

Hi,
I have configured two 7005 controllers in VRRP with 10 AP215.
All works fine, clients passes the authentication (if credential are correct) and has access to WiFi.
I have configured 2 SSID: Internal and Guest.

The default gateway for clients isn't the controller but the internal Firewall, in this case a Palo Alto PA-500.

 

The controller and the Palo Alto are linked to the switch through a trunk,This trunk contains the SSID's VLAN.

 

I verified that the interface of the firewall receiver a large number of error, that continue to increase.

With a packet capture and wireshark I discovered that this traffic is produced by WiFi client.
In the capture I can see a very high number of retransmit packet for Wifi Client traffic.

Have you any idea about the cause of this issue??

 

initially i supposed hat can be the MTU and i verified that is the same on all infrastructure, so i have exclude it by possible root cause.

 

Thanks in advance.

 

Andrea
Guru Elite
Posts: 20,821
Registered: ‎03-29-2007

Re: Large number of errors on firewall's interface due to WiFi Clients Traffic

What kind of errors?

 



Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Regular Contributor I
Posts: 187
Registered: ‎03-27-2013

Re: Large number of errors on firewall's interface due to WiFi Clients Traffic

Hi,

if you use the command "Show interface <interface name>" of the PaloAlto, you can see this output:

 

Hardware interface counters read from CPU:

--------------------------------------------------------------------------------
bytes received 16124834033
bytes transmitted 121738489678
packets received 84736569
packets transmitted 110269171
receive errors 24481870
packets dropped 0

--------------------------------------------------------------------------------

 

With wireshark you can see that there are a very large number of retransimt packet.

 

Kind regards

Andrea

Andrea
Guru Elite
Posts: 20,821
Registered: ‎03-29-2007

Re: Large number of errors on firewall's interface due to WiFi Clients Traffic

Andrea,

 

If the firewall does not tell us what kind of errors, we do not know why it is having a problem with transmitted packets/frames  We need to know that first.

 



Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Regular Contributor I
Posts: 187
Registered: ‎03-27-2013

Re: Large number of errors on firewall's interface due to WiFi Clients Traffic

Hi,

By Wireshark i can see thate there are duplicated packets but unfortunatelly i cannot have the confirmation that the issue is related to it.

I think that the issue may due to STP or LLDP protocol, today I'll try to disable it and verify the situation.

in the while can you indicate to me some best practice to increase the quality of comunication between APs and the Controller and avoid problem with traffic, for example recomended MTU.

Best regards
Andrea

Andrea
Guru Elite
Posts: 20,821
Registered: ‎03-29-2007

Re: Large number of errors on firewall's interface due to WiFi Clients Traffic

I would inspect the cabling between the controller and the infrastructure.



Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Regular Contributor I
Posts: 187
Registered: ‎03-27-2013

Re: Large number of errors on firewall's interface due to WiFi Clients Traffic

Hi,

i have tryed to change and verify the cabling and it is ok

 

 

Andrea
Guru Elite
Posts: 20,821
Registered: ‎03-29-2007

Re: Large number of errors on firewall's interface due to WiFi Clients Traffic

The firewall vendor needs to advise you about why there are errors on their product.


Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Regular Contributor I
Posts: 187
Registered: ‎03-27-2013

Re: Large number of errors on firewall's interface due to WiFi Clients Traffic

HI,
after some investigation i discovere what can be the cause of the issue.

i see that the counter of palo alto are incremented by this type of issue.

- Packets dropped: 802.1q tag not configured

On the firewall seems to be correct and on the controller also.

idea?

 

thanks 

Andrea

Andrea
Guru Elite
Posts: 20,821
Registered: ‎03-29-2007

Re: Large number of errors on firewall's interface due to WiFi Clients Traffic

Do you have the connection to the Palo Alto configured as a trunk?


Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Search Airheads
Showing results for 
Search instead for 
Did you mean: