Controllerless Networks

 View Only
last person joined: 16 hours ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

client connected without Internet

This thread has been viewed 139 times
  • 1.  client connected without Internet

    Posted Oct 28, 2021 03:14 AM
    Hi,
    I've a strange issue in a customer site: some client, random, show "connected without Internet". I'm getting mad about this.
    I cannot replicate the issue, I have checked the coverage 2.4 and 5G with my notebook, and I didn't find any problem.
    There are 8 IAP 305, with enterprise ssid and wpa2, connected in a dedicated vlan with microsoft dhcp server. I started from an 6.x firmware and updated till the last one (I've done about 5 upgrade..), but nothing seems to resolve.
    I have checked all networks configurations: switch, vlan, firewall, dhcp logs, etc. It seems to be all correct.
    I'v tried different configurations in the vc for this SSID, but nothing seems good.
    It happens, randomly, that one client (not ever the same) that was working fine, suddenly get "connected without Internet" in the display. It have a correct IP address, mask, gateway and dns. But it can't ping and it doesn't answer to ping. turning off and on again wifi connections resolve the problem, the client mantain same configurations (ip, etc.) and works fine. It coulded be a power managing problems, but there are very different client having the same issue.
    At the begin I was focus only on IOS clients, but they are also android (smarphone or tablet). 
    Customer believes that the problem is only on 5G band, but I can't be sure of that. If I set only 2.4 band on the ssid, clients are too slow to works, so I need 5 GHz for this SSID.

    Thanks.

    ------------------------------
    Emanuele Muneretto
    ------------------------------


  • 2.  RE: client connected without Internet

    EMPLOYEE
    Posted Oct 28, 2021 05:33 PM
    so what is the current firmware version on your cluster of 8x IAP-305s?

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------



  • 3.  RE: client connected without Internet

    Posted Oct 29, 2021 01:45 AM
    Hi,
    now the firmware is 8.9.0.0_81161.
    We passed through several version from 6.x to this one.

    Thanks

    ------------------------------
    Carabina5
    ------------------------------



  • 4.  RE: client connected without Internet

    EMPLOYEE
    Posted Oct 29, 2021 06:03 PM
    Do they have any wireless mgmt like Aruba Central or Airwave? with these mgmt tools you can check the amount of time it takes to associate, authenticate, get a DHCP IP addr and DNS resolution.

    I suggest to downgrade to either 8.8.0.2 or 8.7.1.6 which have resolved couple of datapath issues.

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------



  • 5.  RE: client connected without Internet

    Posted Nov 02, 2021 02:38 AM
    Hi,
    they don't have Aruba Central or Airwave.

    I'm quite sure we passed also through these versions too.

    Thanks

    ------------------------------
    Emanuele Muneretto
    ------------------------------



  • 6.  RE: client connected without Internet

    EMPLOYEE
    Posted Nov 02, 2021 06:01 PM
    ok if thats the case then it is best to open a support case with Aruba support.

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------



  • 7.  RE: client connected without Internet

    Posted Feb 10, 2022 08:40 AM
    hi, maybe you solved  this problem ?
    thanks

    ------------------------------
    Edgar Tyskevic
    ------------------------------



  • 8.  RE: client connected without Internet

    Posted Feb 10, 2022 09:11 AM


    Unfortunately not.
    We opened a ticket at the end of November, but it's still not solved.




    ------------------------------
    Carabina5
    ------------------------------



  • 9.  RE: client connected without Internet

    Posted Feb 10, 2022 09:25 AM
    please inform if you find a solution, i have the same problem with iap305

    thanks

    ------------------------------
    Edgar Tyskevic
    ------------------------------



  • 10.  RE: client connected without Internet

    Posted Feb 10, 2022 09:34 AM
    I sincerely hope to be able to find a solution.
    I escalated the ticket, but nothing has worked for now.

    I've been trying to figure out what exactly happens for months.
    We've thought of everything, including wired networking issues.

    What happens is surreal: a client that until recently was working, is no longer able to make traffic, while the others, on the same AP and on the same SSID, work without problems.
    If you can, contact the tac to report the problem, I hope that if we report it in more people they will take it more seriously.



    ------------------------------
    Carabina5
    ------------------------------



  • 11.  RE: client connected without Internet

    Posted Feb 11, 2022 10:08 AM
    i have the same problem with mobility controller 7005 and iap225.  My samsung galaxy s10 and s10+ both have this issue with the lastest android 11 firmware. 

    i notice the issue happens when 80Mhz and 40Mhz of 5GHz radio are enable in RF management profile, meanwhile 20Mhz will not lead to this issue but my phone's wifi max speed decreases from 866Mbps to 173Mbps which is terrible for me.

    i dont know why, it seems to be a s10 and s10+ wifi compatibility issue.  Using APs with wifi6 support  may solve this problem but i havent tried considering its price.

    ------------------------------
    wenbo yang
    ------------------------------



  • 12.  RE: client connected without Internet

    Posted Feb 14, 2022 01:35 AM
    Hi,
    I think this is the same, but not only for one kind of device, I have problem with IOS decices too.

    ------------------------------
    Carabina5
    ------------------------------



  • 13.  RE: client connected without Internet

    Posted Feb 23, 2022 10:27 AM
    Hi,
    still no solution is found...
    A survey and coverage check carried out, no problems highlighted.

    Here there is a trace from on test AP with the device affected, it seems that the ap is dropping packets, but support can't say the cause.



    Received packet from aruba002 (timestamp (2022-2-1 14:48:11:197758))
    [asap_firewall_forward(7732):firewall entry] len 86, vlan 0, egress CP, ingress aruba002:
    #mac: etype 0800 smac aa:bb:cc:dd:ee:86 dmac 80:ff:cc:dd:ee:86
    #ip: sip 192.168.13.44, dip 192.168.66.6, proto 17 hdr len 20
    len 72, id 16804, cksum e925, ttl 64, dscp 0
    dont fragment, last fragment, frag off 0
    #udp: sport 39631 dport 53 len 52
    #dns: message-type: standard query, txn id: 18608
    domain name: web.facebook.com.CDA.local, type: A(1), class: IN(1)
    [asap_firewall_forward(7979):vlan decision, tags 0] len 86, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8511):looking up pkt ingress/src bridge entry aa:bb:cc:dd:ee:86] len 86, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8561):Found ingress/src bridge entry aa:bb:cc:dd:ee:86 rechable via aruba002] len 86, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8917):bridge section, looking for dst bridge entry 80:ff:cc:dd:ee:86] len 86, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(9207):session section] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_session_fp_add_process(448):session not offload: session is null] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9497):fastpath session returned 1 opcode 4, snat none] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9513):slowpath section: opcode 4] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9609):slowpath match acl se -1 re -1 rt -1 dpi -1] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9821):back to fastpath, opcode 64] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10067):adduser section] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10110):drop due to add user fail] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(11343):dropping packet - opcode 64] len 86, vlan 13, egress bond0, ingress aruba002:

    Received packet from aruba002 (timestamp (2022-2-1 14:48:11:857298))
    [asap_firewall_forward(7732):firewall entry] len 80, vlan 0, egress CP, ingress aruba002:
    #mac: etype 0800 smac aa:bb:cc:dd:ee:86 dmac 80:ff:cc:dd:ee:86
    #ip: sip 192.168.13.44, dip 192.168.66.6, proto 17 hdr len 20
    len 66, id 16917, cksum e8ba, ttl 64, dscp 0
    dont fragment, last fragment, frag off 0
    #udp: sport 42951 dport 53 len 46
    #dns: message-type: standard query, txn id: 42931
    domain name: gateway.facebook.com, type: A(1), class: IN(1)
    [asap_firewall_forward(7979):vlan decision, tags 0] len 80, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8511):looking up pkt ingress/src bridge entry aa:bb:cc:dd:ee:86] len 80, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8561):Found ingress/src bridge entry aa:bb:cc:dd:ee:86 rechable via aruba002] len 80, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8917):bridge section, looking for dst bridge entry 80:ff:cc:dd:ee:86] len 80, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(9207):session section] len 80, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_session_fp_add_process(448):session not offload: session is null] len 80, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9497):fastpath session returned 1 opcode 4, snat none] len 80, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9513):slowpath section: opcode 4] len 80, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9609):slowpath match acl se -1 re -1 rt -1 dpi -1] len 80, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9821):back to fastpath, opcode 64] len 80, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10067):adduser section] len 80, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10110):drop due to add user fail] len 80, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(11343):dropping packet - opcode 64] len 80, vlan 13, egress bond0, ingress aruba002:

    Received packet from aruba002 (timestamp (2022-2-1 14:48:12:721019))
    [asap_firewall_forward(7732):firewall entry] len 79, vlan 0, egress CP, ingress aruba002:
    #mac: etype 0800 smac aa:bb:cc:dd:ee:86 dmac 80:ff:cc:dd:ee:86
    #ip: sip 192.168.13.44, dip 192.168.66.6, proto 17 hdr len 20
    len 65, id 17006, cksum e862, ttl 64, dscp 0
    dont fragment, last fragment, frag off 0
    #udp: sport 15873 dport 53 len 45
    #dns: message-type: standard query, txn id: 5709
    domain name: clients4.google.com, type: A(1), class: IN(1)
    [asap_firewall_forward(7979):vlan decision, tags 0] len 79, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8511):looking up pkt ingress/src bridge entry aa:bb:cc:dd:ee:86] len 79, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8561):Found ingress/src bridge entry aa:bb:cc:dd:ee:86 rechable via aruba002] len 79, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8917):bridge section, looking for dst bridge entry 80:ff:cc:dd:ee:86] len 79, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(9207):session section] len 79, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_session_fp_add_process(448):session not offload: session is null] len 79, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9497):fastpath session returned 1 opcode 4, snat none] len 79, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9513):slowpath section: opcode 4] len 79, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9609):slowpath match acl se -1 re -1 rt -1 dpi -1] len 79, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9821):back to fastpath, opcode 64] len 79, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10067):adduser section] len 79, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10110):drop due to add user fail] len 79, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(11343):dropping packet - opcode 64] len 79, vlan 13, egress bond0, ingress aruba002:

    Received packet from aruba002 (timestamp (2022-2-1 14:48:13:155176))
    [asap_firewall_forward(7732):firewall entry] len 91, vlan 0, egress CP, ingress aruba002:
    #mac: etype 0800 smac aa:bb:cc:dd:ee:86 dmac 80:ff:cc:dd:ee:86
    #ip: sip 192.168.13.44, dip 192.168.66.6, proto 17 hdr len 20
    len 77, id 17100, cksum e7f8, ttl 64, dscp 0
    dont fragment, last fragment, frag off 0
    #udp: sport 45459 dport 53 len 57
    #dns: message-type: standard query, txn id: 51126
    domain name: outlook.office365.com.CDA.local, type: A(1), class: IN(1)
    [asap_firewall_forward(7979):vlan decision, tags 0] len 91, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8511):looking up pkt ingress/src bridge entry aa:bb:cc:dd:ee:86] len 91, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8561):Found ingress/src bridge entry aa:bb:cc:dd:ee:86 rechable via aruba002] len 91, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8917):bridge section, looking for dst bridge entry 80:ff:cc:dd:ee:86] len 91, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(9207):session section] len 91, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_session_fp_add_process(448):session not offload: session is null] len 91, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9497):fastpath session returned 1 opcode 4, snat none] len 91, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9513):slowpath section: opcode 4] len 91, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9609):slowpath match acl se -1 re -1 rt -1 dpi -1] len 91, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9821):back to fastpath, opcode 64] len 91, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10067):adduser section] len 91, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10110):drop due to add user fail] len 91, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(11343):dropping packet - opcode 64] len 91, vlan 13, egress bond0, ingress aruba002:

    Received packet from aruba002 (timestamp (2022-2-1 14:48:13:738390))
    [asap_firewall_forward(7732):firewall entry] len 87, vlan 0, egress CP, ingress aruba002:
    #mac: etype 0800 smac aa:bb:cc:dd:ee:86 dmac 80:ff:cc:dd:ee:86
    #ip: sip 192.168.13.44, dip 192.168.66.6, proto 17 hdr len 20
    len 73, id 17206, cksum e792, ttl 64, dscp 0
    dont fragment, last fragment, frag off 0
    #udp: sport 19557 dport 53 len 53
    #dns: message-type: standard query, txn id: 12391
    domain name: BCMLS2.glpals.com.CDA.local, type: A(1), class: IN(1)
    [asap_firewall_forward(7979):vlan decision, tags 0] len 87, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8511):looking up pkt ingress/src bridge entry aa:bb:cc:dd:ee:86] len 87, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8561):Found ingress/src bridge entry aa:bb:cc:dd:ee:86 rechable via aruba002] len 87, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8917):bridge section, looking for dst bridge entry 80:ff:cc:dd:ee:86] len 87, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(9207):session section] len 87, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_session_fp_add_process(448):session not offload: session is null] len 87, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9497):fastpath session returned 1 opcode 4, snat none] len 87, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9513):slowpath section: opcode 4] len 87, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9609):slowpath match acl se -1 re -1 rt -1 dpi -1] len 87, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9821):back to fastpath, opcode 64] len 87, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10067):adduser section] len 87, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10110):drop due to add user fail] len 87, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(11343):dropping packet - opcode 64] len 87, vlan 13, egress bond0, ingress aruba002:

    Received packet from aruba002 (timestamp (2022-2-1 14:48:14:935794))
    [asap_firewall_forward(7732):firewall entry] len 100, vlan 0, egress CP, ingress aruba002:
    #mac: etype 0800 smac aa:bb:cc:dd:ee:86 dmac 80:ff:cc:dd:ee:86
    #ip: sip 192.168.13.44, dip 192.168.66.6, proto 17 hdr len 20
    len 86, id 17234, cksum e769, ttl 64, dscp 0
    dont fragment, last fragment, frag off 0
    #udp: sport 55301 dport 53 len 66
    #dns: message-type: standard query, txn id: 5681
    domain name: 21.ucp-ntfy.kaspersky-labs.com.CDA.local, type: AAAA(28), class: IN(1)
    [asap_firewall_forward(7979):vlan decision, tags 0] len 100, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8511):looking up pkt ingress/src bridge entry aa:bb:cc:dd:ee:86] len 100, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8561):Found ingress/src bridge entry aa:bb:cc:dd:ee:86 rechable via aruba002] len 100, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8917):bridge section, looking for dst bridge entry 80:ff:cc:dd:ee:86] len 100, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(9207):session section] len 100, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_session_fp_add_process(448):session not offload: session is null] len 100, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9497):fastpath session returned 1 opcode 4, snat none] len 100, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9513):slowpath section: opcode 4] len 100, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9609):slowpath match acl se -1 re -1 rt -1 dpi -1] len 100, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9821):back to fastpath, opcode 64] len 100, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10067):adduser section] len 100, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10110):drop due to add user fail] len 100, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(11343):dropping packet - opcode 64] len 100, vlan 13, egress bond0, ingress aruba002:

    Received packet from aruba002 (timestamp (2022-2-1 14:48:14:936284))
    [asap_firewall_forward(7732):firewall entry] len 100, vlan 0, egress CP, ingress aruba002:
    #mac: etype 0800 smac aa:bb:cc:dd:ee:86 dmac 80:ff:cc:dd:ee:86
    #ip: sip 192.168.13.44, dip 192.168.66.6, proto 17 hdr len 20
    len 86, id 17235, cksum e768, ttl 64, dscp 0
    dont fragment, last fragment, frag off 0
    #udp: sport 20182 dport 53 len 66
    #dns: message-type: standard query, txn id: 51015
    domain name: 21.ucp-ntfy.kaspersky-labs.com.CDA.local, type: A(1), class: IN(1)
    [asap_firewall_forward(7979):vlan decision, tags 0] len 100, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8511):looking up pkt ingress/src bridge entry aa:bb:cc:dd:ee:86] len 100, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8561):Found ingress/src bridge entry aa:bb:cc:dd:ee:86 rechable via aruba002] len 100, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8917):bridge section, looking for dst bridge entry 80:ff:cc:dd:ee:86] len 100, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(9207):session section] len 100, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_session_fp_add_process(448):session not offload: session is null] len 100, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9497):fastpath session returned 1 opcode 4, snat none] len 100, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9513):slowpath section: opcode 4] len 100, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9609):slowpath match acl se -1 re -1 rt -1 dpi -1] len 100, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9821):back to fastpath, opcode 64] len 100, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10067):adduser section] len 100, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10110):drop due to add user fail] len 100, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(11343):dropping packet - opcode 64] len 100, vlan 13, egress bond0, ingress aruba002:

    Received packet from aruba002 (timestamp (2022-2-1 14:48:14:975671))
    [asap_firewall_forward(7732):firewall entry] len 86, vlan 0, egress CP, ingress aruba002:
    #mac: etype 0800 smac aa:bb:cc:dd:ee:86 dmac 80:ff:cc:dd:ee:86
    #ip: sip 192.168.13.44, dip 192.168.66.6, proto 17 hdr len 20
    len 72, id 17236, cksum e775, ttl 64, dscp 0
    dont fragment, last fragment, frag off 0
    #udp: sport 1143 dport 53 len 52
    #dns: message-type: standard query, txn id: 8523
    domain name: gllto.glpals.com.CDA.local, type: A(1), class: IN(1)
    [asap_firewall_forward(7979):vlan decision, tags 0] len 86, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8511):looking up pkt ingress/src bridge entry aa:bb:cc:dd:ee:86] len 86, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8561):Found ingress/src bridge entry aa:bb:cc:dd:ee:86 rechable via aruba002] len 86, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8917):bridge section, looking for dst bridge entry 80:ff:cc:dd:ee:86] len 86, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(9207):session section] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_session_fp_add_process(448):session not offload: session is null] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9497):fastpath session returned 1 opcode 4, snat none] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9513):slowpath section: opcode 4] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9609):slowpath match acl se -1 re -1 rt -1 dpi -1] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9821):back to fastpath, opcode 64] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10067):adduser section] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10110):drop due to add user fail] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(11343):dropping packet - opcode 64] len 86, vlan 13, egress bond0, ingress aruba002:

    Received packet from aruba002 (timestamp (2022-2-1 14:48:15:361925))
    [asap_firewall_forward(7732):firewall entry] len 85, vlan 0, egress CP, ingress aruba002:
    #mac: etype 0800 smac aa:bb:cc:dd:ee:86 dmac 80:ff:cc:dd:ee:86
    #ip: sip 192.168.13.44, dip 192.168.66.6, proto 17 hdr len 20
    len 71, id 17313, cksum e729, ttl 64, dscp 0
    dont fragment, last fragment, frag off 0
    #udp: sport 27244 dport 53 len 51
    #dns: message-type: standard query, txn id: 38983
    domain name: api.weather.com.CDA.local, type: A(1), class: IN(1)
    [asap_firewall_forward(7979):vlan decision, tags 0] len 85, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8511):looking up pkt ingress/src bridge entry aa:bb:cc:dd:ee:86] len 85, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8561):Found ingress/src bridge entry aa:bb:cc:dd:ee:86 rechable via aruba002] len 85, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8917):bridge section, looking for dst bridge entry 80:ff:cc:dd:ee:86] len 85, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(9207):session section] len 85, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_session_fp_add_process(448):session not offload: session is null] len 85, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9497):fastpath session returned 1 opcode 4, snat none] len 85, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9513):slowpath section: opcode 4] len 85, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9609):slowpath match acl se -1 re -1 rt -1 dpi -1] len 85, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9821):back to fastpath, opcode 64] len 85, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10067):adduser section] len 85, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10110):drop due to add user fail] len 85, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(11343):dropping packet - opcode 64] len 85, vlan 13, egress bond0, ingress aruba002:

    Received packet from aruba002 (timestamp (2022-2-1 14:48:15:376852))
    [asap_firewall_forward(7732):firewall entry] len 86, vlan 0, egress CP, ingress aruba002:
    #mac: etype 0800 smac aa:bb:cc:dd:ee:86 dmac 80:ff:cc:dd:ee:86
    #ip: sip 192.168.13.44, dip 192.168.66.6, proto 17 hdr len 20
    len 72, id 17314, cksum e727, ttl 64, dscp 0
    dont fragment, last fragment, frag off 0
    #udp: sport 40965 dport 53 len 52
    #dns: message-type: standard query, txn id: 48211
    domain name: ds.kaspersky.com.CDA.local, type: A(1), class: IN(1)
    [asap_firewall_forward(7979):vlan decision, tags 0] len 86, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8511):looking up pkt ingress/src bridge entry aa:bb:cc:dd:ee:86] len 86, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8561):Found ingress/src bridge entry aa:bb:cc:dd:ee:86 rechable via aruba002] len 86, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8917):bridge section, looking for dst bridge entry 80:ff:cc:dd:ee:86] len 86, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(9207):session section] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_session_fp_add_process(448):session not offload: session is null] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9497):fastpath session returned 1 opcode 4, snat none] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9513):slowpath section: opcode 4] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9609):slowpath match acl se -1 re -1 rt -1 dpi -1] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9821):back to fastpath, opcode 64] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10067):adduser section] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(10110):drop due to add user fail] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(11343):dropping packet - opcode 64] len 86, vlan 13, egress bond0, ingress aruba002:

    Received packet from aruba002 (timestamp (2022-2-1 14:48:15:377262))
    [asap_firewall_forward(7732):firewall entry] len 86, vlan 0, egress CP, ingress aruba002:
    #mac: etype 0800 smac aa:bb:cc:dd:ee:86 dmac 80:ff:cc:dd:ee:86
    #ip: sip 192.168.13.44, dip 192.168.66.6, proto 17 hdr len 20
    len 72, id 17315, cksum e726, ttl 64, dscp 0
    dont fragment, last fragment, frag off 0
    #udp: sport 7041 dport 53 len 52
    #dns: message-type: standard query, txn id: 45830
    domain name: ds.kaspersky.com.CDA.local, type: AAAA(28), class: IN(1)
    [asap_firewall_forward(7979):vlan decision, tags 0] len 86, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8511):looking up pkt ingress/src bridge entry aa:bb:cc:dd:ee:86] len 86, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8561):Found ingress/src bridge entry aa:bb:cc:dd:ee:86 rechable via aruba002] len 86, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(8917):bridge section, looking for dst bridge entry 80:ff:cc:dd:ee:86] len 86, vlan 13, egress CP, ingress aruba002:
    [asap_firewall_forward(9207):session section] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_session_fp_add_process(448):session not offload: session is null] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9497):fastpath session returned 1 opcode 4, snat none] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9513):slowpath section: opcode 4] len 86, vlan 13, egress bond0, ingress aruba002:
    [asap_firewall_forward(9609):slowpath match acl se -1 re -1 rt -1 dpi -1] len 86, vlan 13, egress bond0, ingress aruba002:

    ------------------------------
    Carabina5
    ------------------------------



  • 14.  RE: client connected without Internet

    Posted Feb 28, 2022 07:07 AM
    hi , what settings you have in VC ->configuration->networks->your ssid->edit-> access.     and access rules is set to ?

    ------------------------------
    Edgar Tyskevic
    ------------------------------



  • 15.  RE: client connected without Internet

    Posted Feb 28, 2022 07:11 AM
    Hi,
    none, there aren't any block or access rule. In the same ssid all pcs are working fine. In the same time a phone is gettin the issue, all other mobiles are working fine, under the same access point.

    ------------------------------
    Carabina5
    ------------------------------



  • 16.  RE: client connected without Internet

    Posted Mar 17, 2022 10:20 AM
      |   view attached
    i changed from unrestricted to network-based and created a rule any to all destinations. and now is much better and no errors "no internet" can you try in your environment to do the same ?

    ------------------------------
    Edgar Tyskevic
    ------------------------------