Wireless Access

Reply
Frequent Contributor I
Posts: 85
Registered: ‎04-05-2011

VLAN pool not evenly assigning users

As a follow up to this post here:

http://community.arubanetworks.com/t5/Unified-Wired-Wireless-Access/VLAN-Pooling-Best-Practice/td-p/217615

 

I had 1 vlan for my students, I ran out of room so i created a second vlan, and created a vlan pool.  I have the vlan pool assigned to the user role for students which is assigned via clearpass.  It is only assigning users to the old vlan and not to the new one.  If i assign either one by itself it works, but when i use the pool it does not.  Am i doing something wrong here?

 

Guru Elite
Posts: 20,966
Registered: ‎03-29-2007

Re: VLAN pool not evenly assigning users

mwallen,

 

Are you using the "Aruba-Named-User-Vlan" attribute?  Does it match (case sensitive) a named VLAN on your local controller?  Is that named VLAN defined to the correct VLANs on the local controller? 



Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Frequent Contributor I
Posts: 85
Registered: ‎04-05-2011

Re: VLAN pool not evenly assigning users

I am passing back the user role from clearpass to the controller.  On the controller i have the vlan pool assigned to the user role.  In the screenshot i attached you can see i have the vlan pool named "students" selected for the user role.

Guru Elite
Posts: 20,966
Registered: ‎03-29-2007

Re: VLAN pool not evenly assigning users

[ Edited ]

Mwallen,

 

A vlan derived from a role has the absolute least priority.  Which means if if the VLAN is being derived by a User Derivation rule or Server Derivation rule or Radius Server attribute, that will override a Role-Based VLAN.  In other words, you should probably just return the attribute via Radius with the VLAN name I mentioned above and Remove the VLAN Name from the Role.

 

If you setup debugging on a user, it will say why the user is getting that VLAN.

 



Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Frequent Contributor I
Posts: 85
Registered: ‎04-05-2011

Re: VLAN pool not evenly assigning users

I think i will need to put a call into TAC because i am not really sure how to do that.  When Aruba setup our sytem for us back when we first got it they did it with the vlans assigned at the role level, so i will need to redo alot of this to pass the vlans back from clearpass.  

 

Thanks.  

Guru Elite
Posts: 20,966
Registered: ‎03-29-2007

Re: VLAN pool not evenly assigning users

[ Edited ]

Well,

 

Here is an overview:

 

You can setup VLAN names, just like you do now, on your master controller.  On each local controller, you would define the actual VLANs that correspond to each name.  When the user authenticates, ClearPass Enforcement Profile should return the Attribute with the Role and the VLAN Name.  When the radius server responds, the controller will assign the user to the role and look on the local controller to see what VLANs are assigned to the named vlan:

 

named-vlan-vsa.png

 

A Radius VSA is the highest on the pecking chart, so this will override any other method of assigning Roles or VLANs on the controller side, and it is more flexible than hardcoding VLANs to user roles, because it is locally significant, based on what VLAN number(s) you have assigned to the VLAN name on the local controller.

 



Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Frequent Contributor I
Posts: 85
Registered: ‎04-05-2011

Re: VLAN pool not evenly assigning users

On the plus side, i feel a bit smarter now, because i had just tried doing what you showed in your screenshot before i saw you posted it!  

 

On the not so plus side, its still doing the same thing as before.  The users are still only getting assigned to the old vlan.  

 

If it changes anything, i only have 1 controller(for now at least, i have a second one but i have not gotten redundancy set up yet, its on the todo list)

Guru Elite
Posts: 20,966
Registered: ‎03-29-2007

Re: VLAN pool not evenly assigning users

[ Edited ]

You need to enable debugging for a single user and post it here, so we can figure out why it is getting that single VLAN.

 

In addition, if you are trying to authenticate a user who is already in the user table, it might not change VLANs.  You need to do a "aaa user delete <ip address of user>" to make sure the user is out of the user table, first.

 



Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Frequent Contributor I
Posts: 85
Registered: ‎04-05-2011

Re: VLAN pool not evenly assigning users

Here is the Debug Info, I am attaching it as well as pasting it so you can pick your poison as far as which one is easier to sort through.

My MAC address is: 60:45:bd:e9:7c:4c

At the start of the log you will see me logged in with the username mwallen which is my staff username, and then i reconnect using MarkTest which is in the student group in active directory. 

 

 

Nov 20 13:25:02 :522050: <INFO> |authmgr| MAC=60:45:bd:e9:7c:4c,IP=140.104.180.49 User data downloaded to datapath, new Role=logon/2, bw Contract=0/0, reason=Download driven by user role setting, idle-timeout=300
Nov 20 13:25:02 :522301: <DBUG> |authmgr| Auth GSM : USER publish for uuid 10059 mac 60:45:bd:e9:7c:4c name CARROLL_NT\mwallen role logon devtype Windows wired 0 authtype 0 subtype 0 encrypt-type 10 conn-port 8448 fwd-mode 0
Nov 20 13:25:02 :522301: <DBUG> |authmgr| Auth GSM : USER publish for uuid 10059 mac 60:45:bd:e9:7c:4c name role logon devtype Windows wired 0 authtype 0 subtype 0 encrypt-type 10 conn-port 8448 fwd-mode 0
Nov 20 13:25:02 :522038: <INFO> |authmgr| username=CARROLL_NT\mwallen MAC=60:45:bd:e9:7c:4c IP=140.104.180.49 Authentication result=Authentication Successful method=radius-accounting server=cp1
Nov 20 13:25:05 :527000: <DBUG> |mdns| mdns_parse_auth_userrole_message 273 Auth User ROLE: MAC:60:45:bd:e9:7c:4c, ROLE_NAME:logon
Nov 20 13:25:05 :527000: <DBUG> |mdns| amon_airgroup_user_status 384 operation=1; hostname:, ip=140.104.180.49, rolename=logon, username=mwallen, ap_name=ITS West - NE902, vlanid=44, username=mwallen
Nov 20 13:25:13 :522038: <INFO> |authmgr| username=marktest MAC=60:45:bd:e9:7c:4c IP=0.0.0.0 Authentication result=Authentication Successful method=802.1x server=cp1
Nov 20 13:25:13 :522044: <INFO> |authmgr| MAC=60:45:bd:e9:7c:4c Station authenticate(start): method=802.1x, role=logon///logon, VLAN=1/1, Derivation=7/1, Value Pair=1, flags=0x8
Nov 20 13:25:13 :522016: <INFO> |authmgr| MAC=60:45:bd:e9:7c:4c IP=?? Derived role 'student' from Aruba VSA
Nov 20 13:25:13 :522127: <DBUG> |authmgr| {L2} Update role from logon to student for IP=0.0.0.0.
Nov 20 13:25:13 :522049: <INFO> |authmgr| MAC=60:45:bd:e9:7c:4c,IP=N/A User role updated, existing Role=logon/logon, new Role=student/logon, reason=Station Authenticated with auth type: 4
Nov 20 13:25:13 :522128: <DBUG> |authmgr| download-L2: acl=77/0 role=logon, tunl=0x0x109ad, PA=0, HA=1, RO=0, VPN=0 L3MOB=0.
Nov 20 13:25:13 :522050: <INFO> |authmgr| MAC=60:45:bd:e9:7c:4c,IP=N/A User data downloaded to datapath, new Role=student/77, bw Contract=0/0, reason=Download driven by user role setting, idle-timeout=300
Nov 20 13:25:13 :522301: <DBUG> |authmgr| Auth GSM : USER publish for uuid 10059 mac 60:45:bd:e9:7c:4c name marktest role logon devtype Windows wired 0 authtype 4 subtype 0 encrypt-type 10 conn-port 8448 fwd-mode 0
Nov 20 13:25:13 :522258: <DBUG> |authmgr| "VDR - Add to history of user user 60:45:bd:e9:7c:4c vlan 0 derivation_type Reset Dot1x VLANs index 7.
Nov 20 13:25:13 :522254: <DBUG> |authmgr| VDR - mac 60:45:bd:e9:7c:4c rolename NULL fwdmode 0 derivation_type Dot1x Aruba VSA vp present.
Nov 20 13:25:13 :522021: <INFO> |authmgr| MAC=60:45:bd:e9:7c:4c Derived VLAN '58' from Aruba VSA
Nov 20 13:25:13 :522255: <DBUG> |authmgr| "VDR - set vlan in user for 60:45:bd:e9:7c:4c vlan 58 fwdmode 0 derivation_type Dot1x Aruba VSA.
Nov 20 13:25:13 :522258: <DBUG> |authmgr| "VDR - Add to history of user user 60:45:bd:e9:7c:4c vlan 58 derivation_type Dot1x Aruba VSA index 8.
Nov 20 13:25:13 :522253: <DBUG> |authmgr| VDR - mac 60:45:bd:e9:7c:4c derivation_type Dot1x Aruba VSA derived vlan 58.
Nov 20 13:25:13 :522254: <DBUG> |authmgr| VDR - mac 60:45:bd:e9:7c:4c rolename NULL fwdmode 0 derivation_type Dot1x MSFT Attributes vp present.
Nov 20 13:25:13 :522254: <DBUG> |authmgr| VDR - mac 60:45:bd:e9:7c:4c rolename NULL fwdmode 0 derivation_type Dot1x Server Rule vp present.
Nov 20 13:25:13 :522259: <DBUG> |authmgr| "VDR - Do Role Based VLAN Derivation user 60:45:bd:e9:7c:4c role student authtype 4 rolehow Aruba VSA.
Nov 20 13:25:13 :522254: <DBUG> |authmgr| VDR - mac 60:45:bd:e9:7c:4c rolename student fwdmode 0 derivation_type Dot1x Aruba VSA Role Contained vp not present.
Nov 20 13:25:13 :522255: <DBUG> |authmgr| "VDR - set vlan in user for 60:45:bd:e9:7c:4c vlan 58 fwdmode 0 derivation_type Dot1x Aruba VSA Role Contained.
Nov 20 13:25:13 :522258: <DBUG> |authmgr| "VDR - Add to history of user user 60:45:bd:e9:7c:4c vlan 58 derivation_type Dot1x Aruba VSA Role Contained index 9.
Nov 20 13:25:13 :522253: <DBUG> |authmgr| VDR - mac 60:45:bd:e9:7c:4c derivation_type Dot1x Aruba VSA Role Contained derived vlan 58.
Nov 20 13:25:13 :522161: <DBUG> |authmgr| Valid Dot1xct, remote:0, assigned:1, default:1, current:1,termstate:0, wired:0, dot1x enabled:1, psk:0 static:0 bssid=9c:1c:12:fe:d3:21.
Nov 20 13:25:13 :522255: <DBUG> |authmgr| "VDR - set vlan in user for 60:45:bd:e9:7c:4c vlan 58 fwdmode 0 derivation_type Current VLAN updated.
Nov 20 13:25:13 :522258: <DBUG> |authmgr| "VDR - Add to history of user user 60:45:bd:e9:7c:4c vlan 58 derivation_type Current VLAN updated index 10.
Nov 20 13:25:13 :522260: <DBUG> |authmgr| "VDR - Cur VLAN updated 60:45:bd:e9:7c:4c mob 0 inform 1 remote 0 wired 0 defvlan 1 exportedvlan 1 curvlan 58.
Nov 20 13:25:13 :522257: <DBUG> |authmgr| "VDR - send current vlan for user 60:45:bd:e9:7c:4c vlan 58 derivation_type Dot1x Aruba VSA trace new vlan: dot1x.
Nov 20 13:25:13 :522287: <DBUG> |authmgr| Auth GSM : MAC_USER publish for mac 60:45:bd:e9:7c:4c bssid 9c:1c:12:fe:d3:21 vlan 58 type 1 data-ready 0
Nov 20 13:25:13 :522095: <DBUG> |authmgr| 60:45:bd:e9:7c:4c: Sending STM new vlan info: vlan 58, AP 9c:1c:12:fe:d3:21 caller user_send_current_vlan_update
Nov 20 13:25:13 :522255: <DBUG> |authmgr| "VDR - set vlan in user for 60:45:bd:e9:7c:4c vlan 58 fwdmode 0 derivation_type VLAN exported.
Nov 20 13:25:13 :522258: <DBUG> |authmgr| "VDR - Add to history of user user 60:45:bd:e9:7c:4c vlan 58 derivation_type VLAN exported index 11.
Nov 20 13:25:13 :522029: <INFO> |authmgr| MAC=60:45:bd:e9:7c:4c Station authenticate: method=802.1x, role=logon///logon, VLAN=1/58, Derivation=7/17, Value Pair=1
Nov 20 13:25:13 :522127: <DBUG> |authmgr| {L3} Update role from logon to student for IP=140.104.180.49.
Nov 20 13:25:13 :522049: <INFO> |authmgr| MAC=60:45:bd:e9:7c:4c,IP=140.104.180.49 User role updated, existing Role=student/logon, new Role=student/student, reason=User authenticated with auth type:4 role derivation:7 l3 assigned role:student
Nov 20 13:25:13 :522122: <DBUG> |authmgr| Reset BWM contract: IP=140.104.180.49 role=student, contract= (0/0), type=Per role.
Nov 20 13:25:13 :522125: <DBUG> |authmgr| Could not create/find bandwidth-contract for user, return code (-11).
Nov 20 13:25:13 :522122: <DBUG> |authmgr| Reset BWM contract: IP=140.104.180.49 role=student, contract= (0/0), type=Per role.
Nov 20 13:25:13 :522125: <DBUG> |authmgr| Could not create/find bandwidth-contract for user, return code (-11).
Nov 20 13:25:13 :522128: <DBUG> |authmgr| download-L2: acl=77/0 role=student, tunl=0x0x109ad, PA=0, HA=1, RO=0, VPN=0 L3MOB=0.
Nov 20 13:25:13 :522050: <INFO> |authmgr| MAC=60:45:bd:e9:7c:4c,IP=140.104.180.49 User data downloaded to datapath, new Role=student/77, bw Contract=0/0, reason=Download driven by user role setting, idle-timeout=300
Nov 20 13:25:13 :522301: <DBUG> |authmgr| Auth GSM : USER publish for uuid 10059 mac 60:45:bd:e9:7c:4c name marktest role student devtype Windows wired 0 authtype 4 subtype 0 encrypt-type 10 conn-port 8448 fwd-mode 0
Nov 20 13:25:13 :522008: <NOTI> |authmgr| User Authentication Successful: username=marktest MAC=60:45:bd:e9:7c:4c IP=140.104.180.49 role=student VLAN=58 AP=ITS West - NE902 SSID=Carroll AAA profile=Carroll-SSID-AAA-Profile auth method=802.1x auth server=cp1
Nov 20 13:25:13 :522301: <DBUG> |authmgr| Auth GSM : USER publish for uuid 10059 mac 60:45:bd:e9:7c:4c name marktest role student devtype Windows wired 0 authtype 4 subtype 0 encrypt-type 10 conn-port 8448 fwd-mode 0
Nov 20 13:25:13 :522301: <DBUG> |authmgr| Auth GSM : USER publish for uuid 10059 mac 60:45:bd:e9:7c:4c name marktest role student devtype Windows wired 0 authtype 4 subtype 9 encrypt-type 10 conn-port 8448 fwd-mode 0
Nov 20 13:25:13 :522053: <DBUG> |authmgr| PMK Cache getting updated for 60:45:bd:e9:7c:4c, (def, cur, vhow) = (1, 58, 17) with vlan=58 vlanhow=17 essid=Carroll role=student rhow=7
Nov 20 13:25:13 :524129: <DBUG> |authmgr| dot1x_gsm_set_keycache(): MAC:60:45:bd:e9:7c:4c GSM: Successfully published Key-cache object.
Nov 20 13:25:13 :524134: <DBUG> |authmgr| dot1x_gsm_set_pmkcache(): MAC:60:45:bd:e9:7c:4c BSS:9c:1c:12:fe:d3:21 GSM: Successfully published PMK-cache object.
Nov 20 13:25:13 :524139: <DBUG> |authmgr| add_pmkcache():859: MAC:60:45:bd:e9:7c:4c BSS:9c:1c:12:fe:d3:21 Update:
Nov 20 13:25:13 :522297: <DBUG> |authmgr| Auth GSM : MAC_USER response event for user 60:45:bd:e9:7c:4c
Nov 20 13:25:13 :522038: <INFO> |authmgr| username=marktest MAC=60:45:bd:e9:7c:4c IP=140.104.180.49 Authentication result=Authentication Successful method=radius-accounting server=cp1
Nov 20 13:25:13 :522026: <INFO> |authmgr| MAC=60:45:bd:e9:7c:4c IP=140.104.212.79 User miss: ingress=0x109ad, VLAN=58 flags=0x8040
Nov 20 13:25:13 :522006: <INFO> |authmgr| MAC=60:45:bd:e9:7c:4c IP=140.104.212.79 User entry added: reason=Sibtye
Nov 20 13:25:13 :522270: <DBUG> |authmgr| During User miss marking the user 60:45:bd:e9:7c:4c with ingress 0x109ad, connection-type 2 as wireless, muxtunnel = no
Nov 20 13:25:13 :522169: <DBUG> |authmgr| Station inherit: IP=140.104.212.79 start bssid:9c:1c:12:fe:d3:21 essid: Carroll port:0x0x109ad (0x0x109ad).
Nov 20 13:25:13 :522008: <NOTI> |authmgr| User Authentication Successful: username=marktest MAC=60:45:bd:e9:7c:4c IP=140.104.212.79 role=student VLAN=58 AP=ITS West - NE902 SSID=Carroll AAA profile=Carroll-SSID-AAA-Profile auth method=802.1x auth server=cp1
Nov 20 13:25:13 :522171: <DBUG> |authmgr| station inherit IP=140.104.212.79 bssid:9c:1c:12:fe:d3:21 essid: Carroll auth:1 type:802.1x role:student port:0x0x109ad.
Nov 20 13:25:13 :522128: <DBUG> |authmgr| download-L2: acl=77/0 role=student, tunl=0x0x109ad, PA=0, HA=1, RO=0, VPN=0 L3MOB=0.
Nov 20 13:25:13 :522050: <INFO> |authmgr| MAC=60:45:bd:e9:7c:4c,IP=140.104.212.79 User data downloaded to datapath, new Role=student/77, bw Contract=0/0, reason=New user IP processing, idle-timeout=300
Nov 20 13:25:13 :522301: <DBUG> |authmgr| Auth GSM : USER publish for uuid 10059 mac 60:45:bd:e9:7c:4c name marktest role student devtype Windows wired 0 authtype 4 subtype 9 encrypt-type 10 conn-port 8448 fwd-mode 0
Nov 20 13:25:13 :527000: <DBUG> |mdns| rx_mdns_pkt_from_sos 481 Rcvd packet from SOS: vlan 58, len 179
Nov 20 13:25:13 :527000: <DBUG> |mdns| mdns_parse_packet_from_sos 677 pkt from SOS: vlan 58, mac 60:45:bd:e9:7c:4c ip 140.104.212.79
Nov 20 13:25:13 :527004: <INFO> |mdns| mdns_client_status 529 IP changed: MAC:60:45:bd:e9:7c:4c, old IP:140.104.180.49, new IP:140.104.212.79
Nov 20 13:25:13 :527000: <DBUG> |mdns| mdns_auth_userinfo_req_message 349 mac(60:45:bd:e9:7c:4c), ip(140.104.212.79)
Nov 20 13:25:13 :527000: <DBUG> |mdns| amon_airgroup_user_status 384 operation=1; hostname:, ip=140.104.212.79, rolename=, username=, ap_name=, vlanid=58, username=
Nov 20 13:25:13 :527000: <DBUG> |mdns| ag_send_query_packet_to_cluster 2483 Controller is not part of AG mct cluster
Nov 20 13:25:13 :527000: <DBUG> |mdns| ssdp_parse_query_packet 353 QUERY from client:60:45:bd:e9:7c:4c sid urn:schemas-upnp-org:device:InternetGatewayDevice:1 dropped: service not present!
Nov 20 13:25:13 :527000: <DBUG> |mdns| rx_mdns_pkt_from_sos 481 Rcvd packet from SOS: vlan 58, len 169
Nov 20 13:25:13 :527000: <DBUG> |mdns| mdns_parse_packet_from_sos 677 pkt from SOS: vlan 58, mac 60:45:bd:e9:7c:4c ip 140.104.212.79
Nov 20 13:25:13 :527000: <DBUG> |mdns| ag_send_query_packet_to_cluster 2483 Controller is not part of AG mct cluster
Nov 20 13:25:13 :527000: <DBUG> |mdns| ssdp_parse_query_packet 353 QUERY from client:60:45:bd:e9:7c:4c sid uuid:8d88e1ef-129d-9151-3a71-f0815c96e87a dropped: service not present!
Nov 20 13:25:13 :527000: <DBUG> |mdns| rx_mdns_pkt_from_sos 481 Rcvd packet from SOS: vlan 58, len 179
Nov 20 13:25:13 :527000: <DBUG> |mdns| mdns_parse_packet_from_sos 677 pkt from SOS: vlan 58, mac 60:45:bd:e9:7c:4c ip 140.104.212.79
Nov 20 13:25:13 :527000: <DBUG> |mdns| ag_send_query_packet_to_cluster 2483 Controller is not part of AG mct cluster
Nov 20 13:25:13 :527000: <DBUG> |mdns| ssdp_parse_query_packet 353 QUERY from client:60:45:bd:e9:7c:4c sid urn:schemas-upnp-org:device:InternetGatewayDevice:1 dropped: service not present!
Nov 20 13:25:13 :527000: <DBUG> |mdns| rx_mdns_pkt_from_sos 481 Rcvd packet from SOS: vlan 58, len 169
Nov 20 13:25:13 :527000: <DBUG> |mdns| mdns_parse_packet_from_sos 677 pkt from SOS: vlan 58, mac 60:45:bd:e9:7c:4c ip 140.104.212.79
Nov 20 13:25:13 :527000: <DBUG> |mdns| ag_send_query_packet_to_cluster 2483 Controller is not part of AG mct cluster
Nov 20 13:25:13 :527000: <DBUG> |mdns| ssdp_parse_query_packet 353 QUERY from client:60:45:bd:e9:7c:4c sid uuid:62094904-bf6a-4519-873c-a83437486098 dropped: service not present!
Nov 20 13:25:15 :527000: <DBUG> |mdns| mdns_parse_auth_userrole_message 273 Auth User ROLE: MAC:60:45:bd:e9:7c:4c, ROLE_NAME:student
Nov 20 13:25:15 :527000: <DBUG> |mdns| amon_airgroup_user_status 384 operation=1; hostname:, ip=140.104.212.79, rolename=student, username=marktest, ap_name=, vlanid=58, username=marktest
Nov 20 13:25:15 :527004: <INFO> |mdns| mdns_parse_auth_useradd_message 234 Auth User ADD: MAC:60:45:bd:e9:7c:4c, IP:140.104.212.79, VLAN:1, Role:student Name:marktest APName:ITS West - NE902 Type:1. Groups:
Nov 20 13:25:15 :527000: <DBUG> |mdns| amon_airgroup_user_status 384 operation=1; hostname:, ip=140.104.212.79, rolename=student, username=marktest, ap_name=ITS West - NE902, vlanid=1, username=marktest
Nov 20 13:25:15 :527000: <DBUG> |mdns| mdns_discover_service_client 4022 Discover client 60:45:bd:e9:7c:4c for a particular service
Nov 20 13:25:15 :527000: <DBUG> |mdns| mdns_send_packet_pseudo_mcast 509 MDNS Pkt to SOS: pkt_len=405, buf_len=14336. To=60:45:bd:e9:7c:4c, vlan=1
Nov 20 13:25:15 :527000: <DBUG> |mdns| ssdp_discover_service_client 628 SSDP:Discover client 60:45:bd:e9:7c:4c for a particular service
Nov 20 13:25:15 :527000: <DBUG> |mdns| mdns_send_packet_pseudo_mcast 509 MDNS Pkt to SOS: pkt_len=120, buf_len=14336. To=60:45:bd:e9:7c:4c, vlan=1
Nov 20 13:25:15 :527000: <DBUG> |mdns| mdns_send_packet_pseudo_mcast 509 MDNS Pkt to SOS: pkt_len=121, buf_len=14336. To=60:45:bd:e9:7c:4c, vlan=1
Nov 20 13:25:15 :527000: <DBUG> |mdns| mdns_parse_userinfo 380 UserInfo resp=1 ip=140.104.212.79, mac=60:45:bd:e9:7c:4c, apname=ITS West - NE902, role=student, username=marktest, vlan=1
Nov 20 13:25:15 :527000: <DBUG> |mdns| mdns_client_update 329 MDNS Client exists - flag wifi ap_name ITS West - NE902 client role - student
Nov 20 13:25:15 :527000: <DBUG> |mdns| mdns_parse_auth_userinfo_resp_message 405 UserInfo response completed for ip=140.104.212.79 mac=60:45:bd:e9:7c:4c
Nov 20 13:25:16 :527000: <DBUG> |mdns| rx_mdns_pkt_from_sos 481 Rcvd packet from SOS: vlan 58, len 179
Nov 20 13:25:16 :527000: <DBUG> |mdns| mdns_parse_packet_from_sos 677 pkt from SOS: vlan 58, mac 60:45:bd:e9:7c:4c ip 140.104.212.79
--More-- (q) quit (u) pageup (/) search (n) repeat Nov 20 13:25:16 :527000: <DBUG> |mdns| amon_airgroup_user_status 384 operation=1; hostname:, ip=140.104.212.79, rolename=student, username=marktest, ap_name=ITS West - NE902, vlanid=58, username=marktest
Nov 20 13:25:16 :527000: <DBUG> |mdns| ag_send_query_packet_to_cluster 2483 Controller is not part of AG mct cluster
Nov 20 13:25:16 :527000: <DBUG> |mdns| ssdp_parse_query_packet 353 QUERY from client:60:45:bd:e9:7c:4c sid urn:schemas-upnp-org:device:InternetGatewayDevice:1 dropped: service not present!
Nov 20 13:25:16 :527000: <DBUG> |mdns| rx_mdns_pkt_from_sos 481 Rcvd packet from SOS: vlan 58, len 179
Nov 20 13:25:16 :527000: <DBUG> |mdns| mdns_parse_packet_from_sos 677 pkt from SOS: vlan 58, mac 60:45:bd:e9:7c:4c ip 140.104.212.79
Nov 20 13:25:16 :527000: <DBUG> |mdns| ag_send_query_packet_to_cluster 2483 Controller is not part of AG mct cluster
Nov 20 13:25:16 :527000: <DBUG> |mdns| ssdp_parse_query_packet 353 QUERY from client:60:45:bd:e9:7c:4c sid urn:schemas-upnp-org:device:InternetGatewayDevice:1 dropped: service not present!
Nov 20 13:25:16 :527000: <DBUG> |mdns| rx_mdns_pkt_from_sos 481 Rcvd packet from SOS: vlan 58, len 169
Nov 20 13:25:16 :527000: <DBUG> |mdns| mdns_parse_packet_from_sos 677 pkt from SOS: vlan 58, mac 60:45:bd:e9:7c:4c ip 140.104.212.79
Nov 20 13:25:16 :527000: <DBUG> |mdns| ag_send_query_packet_to_cluster 2483 Controller is not part of AG mct cluster
Nov 20 13:25:16 :527000: <DBUG> |mdns| ssdp_parse_query_packet 353 QUERY from client:60:45:bd:e9:7c:4c sid uuid:8d88e1ef-129d-9151-3a71-f0815c96e87a dropped: service not present!
Nov 20 13:25:16 :527000: <DBUG> |mdns| rx_mdns_pkt_from_sos 481 Rcvd packet from SOS: vlan 58, len 179
Nov 20 13:25:16 :527000: <DBUG> |mdns| mdns_parse_packet_from_sos 677 pkt from SOS: vlan 58, mac 60:45:bd:e9:7c:4c ip 140.104.212.79
Nov 20 13:25:16 :527000: <DBUG> |mdns| ag_send_query_packet_to_cluster 2483 Controller is not part of AG mct cluster
Nov 20 13:25:16 :527000: <DBUG> |mdns| ssdp_parse_query_packet 353 QUERY from client:60:45:bd:e9:7c:4c sid urn:schemas-upnp-org:device:InternetGatewayDevice:1 dropped: service not present!
Nov 20 13:25:16 :527000: <DBUG> |mdns| rx_mdns_pkt_from_sos 481 Rcvd packet from SOS: vlan 58, len 169
Nov 20 13:25:16 :527000: <DBUG> |mdns| mdns_parse_packet_from_sos 677 pkt from SOS: vlan 58, mac 60:45:bd:e9:7c:4c ip 140.104.212.79
Nov 20 13:25:16 :527000: <DBUG> |mdns| ag_send_query_packet_to_cluster 2483 Controller is not part of AG mct cluster
Nov 20 13:25:16 :527000: <DBUG> |mdns| ssdp_parse_query_packet 353 QUERY from client:60:45:bd:e9:7c:4c sid uuid:62094904-bf6a-4519-873c-a83437486098 dropped: service not present!
Nov 20 13:25:19 :527000: <DBUG> |mdns| rx_mdns_pkt_from_sos 481 Rcvd packet from SOS: vlan 58, len 179
Nov 20 13:25:19 :527000: <DBUG> |mdns| mdns_parse_packet_from_sos 677 pkt from SOS: vlan 58, mac 60:45:bd:e9:7c:4c ip 140.104.212.79
Nov 20 13:25:19 :527000: <DBUG> |mdns| ag_send_query_packet_to_cluster 2483 Controller is not part of AG mct cluster
Nov 20 13:25:19 :527000: <DBUG> |mdns| ssdp_parse_query_packet 353 QUERY from client:60:45:bd:e9:7c:4c sid urn:schemas-upnp-org:device:InternetGatewayDevice:1 dropped: service not present!
Nov 20 13:25:20 :527000: <DBUG> |mdns| ssdp_discover_service_client 628 SSDP:Discover client 60:45:bd:e9:7c:4c for a particular service
Nov 20 13:25:20 :527000: <DBUG> |mdns| mdns_send_packet_pseudo_mcast 509 MDNS Pkt to SOS: pkt_len=120, buf_len=14336. To=60:45:bd:e9:7c:4c, vlan=1
Nov 20 13:25:20 :527000: <DBUG> |mdns| mdns_send_packet_pseudo_mcast 509 MDNS Pkt to SOS: pkt_len=121, buf_len=14336. To=60:45:bd:e9:7c:4c, vlan=1
Nov 20 13:25:22 :527000: <DBUG> |mdns| rx_mdns_pkt_from_sos 481 Rcvd packet from SOS: vlan 58, len 179
Nov 20 13:25:22 :527000: <DBUG> |mdns| mdns_parse_packet_from_sos 677 pkt from SOS: vlan 58, mac 60:45:bd:e9:7c:4c ip 140.104.212.79
Nov 20 13:25:22 :527000: <DBUG> |mdns| ag_send_query_packet_to_cluster 2483 Controller is not part of AG mct cluster
Nov 20 13:25:22 :527000: <DBUG> |mdns| ssdp_parse_query_packet 353 QUERY from client:60:45:bd:e9:7c:4c sid urn:schemas-upnp-org:device:InternetGatewayDevice:1 dropped: service not present!
Nov 20 13:25:25 :527000: <DBUG> |mdns| ssdp_discover_service_client 628 SSDP:Discover client 60:45:bd:e9:7c:4c for a particular service
Nov 20 13:25:25 :527000: <DBUG> |mdns| mdns_send_packet_pseudo_mcast 509 MDNS Pkt to SOS: pkt_len=120, buf_len=14336. To=60:45:bd:e9:7c:4c, vlan=1
Nov 20 13:25:25 :527000: <DBUG> |mdns| mdns_send_packet_pseudo_mcast 509 MDNS Pkt to SOS: pkt_len=121, buf_len=14336. To=60:45:bd:e9:7c:4c, vlan=1
Nov 20 13:25:25 :527000: <DBUG> |mdns| rx_mdns_pkt_from_sos 481 Rcvd packet from SOS: vlan 58, len 179
Nov 20 13:25:25 :527000: <DBUG> |mdns| mdns_parse_packet_from_sos 677 pkt from SOS: vlan 58, mac 60:45:bd:e9:7c:4c ip 140.104.212.79
Nov 20 13:25:25 :527000: <DBUG> |mdns| ag_send_query_packet_to_cluster 2483 Controller is not part of AG mct cluster
Nov 20 13:25:25 :527000: <DBUG> |mdns| ssdp_parse_query_packet 353 QUERY from client:60:45:bd:e9:7c:4c sid urn:schemas-upnp-org:device:InternetGatewayDevice:1 dropped: service not present!
Nov 20 13:25:28 :527000: <DBUG> |mdns| rx_mdns_pkt_from_sos 481 Rcvd packet from SOS: vlan 58, len 179
Nov 20 13:25:28 :527000: <DBUG> |mdns| mdns_parse_packet_from_sos 677 pkt from SOS: vlan 58, mac 60:45:bd:e9:7c:4c ip 140.104.212.79
Nov 20 13:25:28 :527000: <DBUG> |mdns| ag_send_query_packet_to_cluster 2483 Controller is not part of AG mct cluster
Nov 20 13:25:28 :527000: <DBUG> |mdns| ssdp_parse_query_packet 353 QUERY from client:60:45:bd:e9:7c:4c sid urn:schemas-upnp-org:device:InternetGatewayDevice:1 dropped: service not present!
Nov 20 13:25:30 :527000: <DBUG> |mdns| ssdp_discover_service_client 628 SSDP:Discover client 60:45:bd:e9:7c:4c for a particular service
Nov 20 13:25:30 :527000: <DBUG> |mdns| mdns_send_packet_pseudo_mcast 509 MDNS Pkt to SOS: pkt_len=120, buf_len=14336. To=60:45:bd:e9:7c:4c, vlan=1
Nov 20 13:25:30 :527000: <DBUG> |mdns| mdns_send_packet_pseudo_mcast 509 MDNS Pkt to SOS: pkt_len=121, buf_len=14336. To=60:45:bd:e9:7c:4c, vlan=1
Nov 20 13:25:31 :527000: <DBUG> |mdns| rx_mdns_pkt_from_sos 481 Rcvd packet from SOS: vlan 58, len 179
Nov 20 13:25:31 :527000: <DBUG> |mdns| mdns_parse_packet_from_sos 677 pkt from SOS: vlan 58, mac 60:45:bd:e9:7c:4c ip 140.104.212.79
Nov 20 13:25:31 :527000: <DBUG> |mdns| ag_send_query_packet_to_cluster 2483 Controller is not part of AG mct cluster
Nov 20 13:25:31 :527000: <DBUG> |mdns| ssdp_parse_query_packet 353 QUERY from client:60:45:bd:e9:7c:4c sid urn:schemas-upnp-org:device:InternetGatewayDevice:1 dropped: service not present!
Nov 20 13:25:34 :527000: <DBUG> |mdns| rx_mdns_pkt_from_sos 481 Rcvd packet from SOS: vlan 58, len 179
Nov 20 13:25:34 :527000: <DBUG> |mdns| mdns_parse_packet_from_sos 677 pkt from SOS: vlan 58, mac 60:45:bd:e9:7c:4c ip 140.104.212.79
Nov 20 13:25:34 :527000: <DBUG> |mdns| ag_send_query_packet_to_cluster 2483 Controller is not part of AG mct cluster
Nov 20 13:25:34 :527000: <DBUG> |mdns| ssdp_parse_query_packet 353 QUERY from client:60:45:bd:e9:7c:4c sid urn:schemas-upnp-org:device:InternetGatewayDevice:1 dropped: service not present!
Nov 20 13:25:37 :527000: <DBUG> |mdns| rx_mdns_pkt_from_sos 481 Rcvd packet from SOS: vlan 58, len 179
Nov 20 13:25:37 :527000: <DBUG> |mdns| mdns_parse_packet_from_sos 677 pkt from SOS: vlan 58, mac 60:45:bd:e9:7c:4c ip 140.104.212.79
Nov 20 13:25:37 :527000: <DBUG> |mdns| ag_send_query_packet_to_cluster 2483 Controller is not part of AG mct cluster
Nov 20 13:25:37 :527000: <DBUG> |mdns| ssdp_parse_query_packet 353 QUERY from client:60:45:bd:e9:7c:4c sid urn:schemas-upnp-org:device:InternetGatewayDevice:1 dropped: service not present!

Guru Elite
Posts: 20,966
Registered: ‎03-29-2007

Re: VLAN pool not evenly assigning users

mwallen,

 

did you do a "aaa user delete <ip address>" on your user before switching?  

 

Turn off the radio, then remove yourself from the user table.... Then authenticate with student credentials...

 

 



Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Search Airheads
Showing results for 
Search instead for 
Did you mean: