Wireless Access

 View Only
last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Issue with IAP and mobility controller : Can't get DHCP

This thread has been viewed 60 times
  • 1.  Issue with IAP and mobility controller : Can't get DHCP

    Posted Dec 27, 2021 07:59 AM
    Hello,
    We have issue with WIFI.
    It's new devices.

    Here's the schema.
    X
    We have a wifi employees with radius authentication and DHCP on REMOTE site > It works fine.

    Then, we have a guest SSID (no auth, no password, open), it pass through GRE tunnel to mobility controler. DHCP is on CENTRAL.
    Wifi is connected but no ip address.

    From IAP (Vitual controller) :
    AP# show vpn config

    Concentrator
    ------------
    Type Value
    ---- -----
    VPN Primary Server
    VPN Backup Server
    VPN Preemption disable
    VPN Preemption disable
    VPN Fast Failover disable
    VPN Hold Time 600
    VPN Monitor Pkt Send Freq 5
    VPN Monitor Pkt Lost Cnt 6
    VPN Reconnect Duration before Normal-Failover 30 Seconds
    VPN Ikepsk 14d0e4ced617a2102d1c8074fe317ef5
    VPN Username
    VPN Password 24a73d0d29b8fdd30af7f2314c8fec85
    NAT outside disable
    Source VLANs
    GRE outside vpn disable
    GRE Per AP Tunnel disable
    GRE Type 48
    GRE Primary Server 10.0.3.120
    GRE Primary IP Address 10.0.3.120
    GRE Backup Server
    GRE Backup IP Address 0.0.0.0
    GRE Reconnect User On Failover enable
    GRE Reconnect Time On Failover 60
    Reconnect User On Failover disable
    Reconnect Time On Failover 60

    Routing Table
    --------------
    Destination Netmask Gateway Metric Type Flag
    ----------- ------- ------- ------ ---- ----

    Number of Route Entries :0

    Route Flags: A = Active; D = in Datapath; M = to Master


    From Mobility controller :
    (MC) ^[mynode] #show datapath session table 10.110.3.50


    Datapath Session Table Entries
    ------------------------------

    Flags: F - fast age, S - src NAT, N - dest NAT
    D - deny, R - redirect, Y - no syn
    H - high prio, P - set prio, T - set ToS
    C - client, M - mirror, V - VOIP
    Q - Real-Time Quality analysis
    u - Upstream Real-Time Quality analysis
    I - Deep inspect, U - Locally destined
    E - Media Deep Inspect, G - media signal
    r - Route Nexthop, h - High Value
    A - Application Firewall Inspect
    J - SDWAN Default Probe stats used as fallback
    B - Permanent, O - Openflow
    L - Log, o - Openflow config revision mismatched

    Source IP or MAC Destination IP Prot SPort DPort Cntr Prio ToS Age Destination TAge Packets Bytes Flags CPU ID
    ----------------- --------------- ---- ----- ----- -------- ---- --- --- ----------- ---- ---------- ---------- --------------- -------

    There is no datas, but yesterday i ve seen traffic. There were packets from MC to VC but not from VC to MC.

    Another question : why authenticated WIFI disconnect when Mobility controller is off? Auth wifi should not pass through mobility controller.

    Thanks for help.
    Regards.

    ------------------------------
    Alexandre RAIMBAULT
    ------------------------------


  • 2.  RE: Issue with IAP and mobility controller : Can't get DHCP

    EMPLOYEE
    Posted Dec 27, 2021 04:35 PM
    so you want to to tunnel the Guest traffic to the MC in the Central site?
    in that case in addition to creating the VPN/GRE you need to configure the forwarding mode and finally reference it in the WLAN configuration
    https://www.arubanetworks.com/techdocs/Instant_87_WebHelp/Content/instant-ug/iap-vpn/iap-vpn-arch.htm

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------



  • 3.  RE: Issue with IAP and mobility controller : Can't get DHCP

    Posted Jan 03, 2022 03:46 AM
    Hello,
    Excuse me for delay, i was in holidays.
    Yes, i want to tunnel guest traffic from remote site to MC then send it to my firewall then internet.
    I will trie your link as soon as possible.
    Thanks.

    ------------------------------
    Alexandre RAIMBAULT
    ------------------------------



  • 4.  RE: Issue with IAP and mobility controller : Can't get DHCP

    Posted Dec 28, 2021 02:17 AM
    Hello Alexandre,

    Two questions.  First, AOS version?  I'm assuming AOS 8.6 or later, but if AOS 10, the rules change a bit.

    Second, are you using a Mobility Controller (7005, 7008, 7205, 7210, etc) or gateway (90xx), or are these really IAPs managed by a swarm/cluster Virtual Controller?  IAPs can be set to run in campus mode, so this does make a difference.

    You mention Central, so it's a bit unclear how this really would work.  Central will manage IAP swarms, or AOSv10 Gateways.  Your 7010 may be managing the IAPs if they are in Campus mode.  If this is the case, the default forwarding mode is "tunneled" meaning all traffic is sent back to the Mobility Controller for connectivity to the network.  An alternate is Bridged mode, where the MC participates in authentication, but the user traffic is placed on the network at the AP's switch port.

    Lack of DHCP often arises when the controller doesn't have an IP address in the VLAN in question, and the DHCP server is on a firewall or other switch.  If the controller is set up to attempt to proxy DHCP but doesn't have an IP address, problems occur.

    On my lab IAP configuration, no DHCP service or proxy is performed.  I have a layer 3 interface for my trusted subnets on my core switch, which runs DHCP service for them (Aruba 2830F).  The untrusted networks - guest, IoT - do not have a L3 interface.  Traffic passes through the core switch to my antique Cisco ASA, which has the L3 interfaces for these subnets, as well as running DHCP service.

    If I had a Windows Server or other DHCP server, I could set the DHCP proxy/helper address on the core switch for trusted networks, and the firewall for untrusted, to dereference that outside server.

    If controller-based, the rules change a bit.  Since the default is to tunnel back to the controller for distribution of traffic, you will either need to have an IP address and helper/proxy set up on the controller for each subnet/VLAN, or not place an IP address on the controller for the VLAN and perform a L2 pass-through so the core switch (trusted subnets) or firewall (untrusted subnets) can either provide DHCP service or proxy/helper functionality.

    Most important thing, at least or me to be confident in my reply, is knowing the actual management/AP function in use (IAP or CAP).  This reply tries to be general, so may be more difficult to decipher than if there was a clear definition of whether this network uses IAP/VC or CAP/MC.  The product being labeled IAP doesn't assure the mode is Instant.

    ------------------------------
    Timothy Leadbetter
    ACMP, ACSP, ACCA
    CWNA, CWDP
    ECSE-Design
    Not a current HPE/Aruba Employee
    ------------------------------



  • 5.  RE: Issue with IAP and mobility controller : Can't get DHCP

    Posted Jan 03, 2022 03:56 AM
    HEllo,
    Sorry for delay, i was in holiday.
    AOS version : 8.7.1.6

    Yes, MC 7010.
    There are remote APs, grouped in a Virtual Controller. For authenticated traffic (employees), it does not pass through MC (i mean).
    For guest network, it pass through MC.

    When i mean "central", i mean central site. YOu can see it in schema in my first post.

    MC has an IP in guest network. And DHCP helper is configured.
    DHCP is the firewall 
    We have a MSM720 which is worked.

    It's a bit complicated because i'm very new in aruba wifi network and the partner who preconfigured this architecture didn't know our network and made a lab which is not the same as we have. (sorry for my english).
    I will study you answer as soon as possible.

    REgards.


    ------------------------------
    Alexandre RAIMBAULT
    ------------------------------



  • 6.  RE: Issue with IAP and mobility controller : Can't get DHCP

    Posted Jan 04, 2022 03:26 AM
    Hello,
    I have deploy a new IAP on central site to test.
    With an authenticated WIFI with radius, it is ok.
    Guest WIFI with DHCP and mobility controller can't get IP.

    X

    This time, no GRE tunnel but an IPSEC tunnel.

    And the VPN can't mount.
    X.X.X.X is my mobility controller.
    Maybe this is why i can't get DHCP.

    IAP# show vpn status


    profile name:default
    --------------------------------------------------
    current using tunnel :unselected tunnel
    current tunnel using time :0
    ipsec is preempt status :disable
    ipsec is fast failover status :disable
    ipsec hold on period :600s
    ipsec tunnel monitor frequency (seconds/packet) :5
    ipsec tunnel monitor timeout by lost packet cnt :6
    ipsec reconnect duration (seconds) :30

    ipsec primary tunnel crypto type :Cert
    ipsec primary tunnel peer address :X.X.X.X
    ipsec primary tunnel peer tunnel ip :0.0.0.0
    ipsec primary tunnel ap tunnel ip :0.0.0.0
    ipsec primary tunnel using interface :
    ipsec primary tunnel using MTU :0
    ipsec primary tunnel profile index :0
    ipsec primary tunnel current sm status :Retrying
    ipsec primary tunnel tunnel status :Down
    ipsec primary tunnel tunnel retry times :1920
    ipsec primary tunnel tunnel uptime :0

    ipsec backup tunnel crypto type :Cert
    ipsec backup tunnel peer address :N/A
    ipsec backup tunnel peer tunnel ip :N/A
    ipsec backup tunnel ap tunnel ip :N/A
    ipsec backup tunnel using interface :N/A
    ipsec backup tunnel using MTU :N/A
    ipsec backup tunnel current sm status :Init
    ipsec backup tunnel tunnel status :Down
    ipsec backup tunnel tunnel retry times :0
    ipsec backup tunnel tunnel uptime :0

    Thanks for help.

    ------------------------------
    Alexandre RAIMBAULT
    ------------------------------



  • 7.  RE: Issue with IAP and mobility controller : Can't get DHCP

    EMPLOYEE
    Posted Jan 04, 2022 06:16 AM

    Hi, i think you are talking about an IAP VPN config, it might be useful if you could add a topology in order to understand this in deep

     

    Regards

     


    Jorge Calvi

    Systems Engineer - Argentina & Paraguay

    Aruba, a Hewlett Packard Enterprise company

    M: +54 91150633418

    AIRHEADS COMMUNITY FOLLOW US Twitter LinkedIn

     

    Este correo electrónico puede contener información confidencial y es para uso del destinatario exclusivamente. Cualquier revisión, distribución, revelación o uso por terceros de la información contenida en este mail está prohibida.  Si no es el destinatario de este correo, por favor contacte al remitente respondiendo a este mensaje y elimine todas las copias.

     

    This e-mail may contain confidential and privileged material for the sole use of the intended recipient. Any review, use, distribution or disclosure by others is strictly prohibited. If you are not the intended recipient (or authorized to receive for the recipient), please contact the sender by reply e-mail and delete all copies of this message.

     






  • 8.  RE: Issue with IAP and mobility controller : Can't get DHCP

    Posted Jan 04, 2022 08:11 AM
    Yes, i m talking about IAP VPN.
    I edited my last post with a schema.
    Regards.
    Alex

    ------------------------------
    Alexandre RAIMBAULT
    ------------------------------



  • 9.  RE: Issue with IAP and mobility controller : Can't get DHCP

    EMPLOYEE
    Posted Jan 04, 2022 08:25 AM

    OK, understood, and as you mentioned in previous email, IPSec VPN is down, you have to start there the diagnostics. You have some firewalls between and (i suppose) internet as a link.

     

    At this time, you might have at less

     

    • A public IP at central site
    • An udp 4500 nat from this public IP to the controller IP at central site
    • A firewall rule permiting at least DNS, & UDP 4500 going out from remote site firewall

     

    It might be useful to do a show datapath session table | include 4500 at the controller CLI, because you can se there if sessions from AP are coming, are established or out of sync.

     

    After you realice sessions on UDP 4500 are established other check commands might be sho crypto isakmp sa and sho crypto ipsec sa

     

    Regards,

     


    Jorge Calvi

    Systems Engineer - Argentina & Paraguay

    Aruba, a Hewlett Packard Enterprise company

    M: +54 91150633418

    AIRHEADS COMMUNITY FOLLOW US Twitter LinkedIn

     

    Este correo electrónico puede contener información confidencial y es para uso del destinatario exclusivamente. Cualquier revisión, distribución, revelación o uso por terceros de la información contenida en este mail está prohibida.  Si no es el destinatario de este correo, por favor contacte al remitente respondiendo a este mensaje y elimine todas las copias.

     

    This e-mail may contain confidential and privileged material for the sole use of the intended recipient. Any review, use, distribution or disclosure by others is strictly prohibited. If you are not the intended recipient (or authorized to receive for the recipient), please contact the sender by reply e-mail and delete all copies of this message.

     






  • 10.  RE: Issue with IAP and mobility controller : Can't get DHCP

    Posted Jan 04, 2022 08:48 AM
    Thanks for your answer.
    show datapath session table | include 4500
    Nothing displayed
    (MC-CARQ-01) [mynode] (Control Plane Security Profile) #show crypto isakmp sa
    % No active ISAKMP SA

    (MC-CARQ-01) [mynode] (Control Plane Security Profile) #show crypto ipsec sa
    % No active IPSEC SA

    And those logs in Mobility Controler.

    It can't mount VPN.
    Regards



    ------------------------------
    Alexandre RAIMBAULT
    ------------------------------



  • 11.  RE: Issue with IAP and mobility controller : Can't get DHCP

    EMPLOYEE
    Posted Jan 04, 2022 08:53 AM

    Its clear there are no sessions  reaching the mobility controller, now I think you have to go reverse investigating if those request reach your central site firewall, if not, if those are present at remote firewall

     


    Jorge Calvi

    Systems Engineer - Argentina & Paraguay

    Aruba, a Hewlett Packard Enterprise company

    M: +54 91150633418

    AIRHEADS COMMUNITY FOLLOW US Twitter LinkedIn

     

    Este correo electrónico puede contener información confidencial y es para uso del destinatario exclusivamente. Cualquier revisión, distribución, revelación o uso por terceros de la información contenida en este mail está prohibida.  Si no es el destinatario de este correo, por favor contacte al remitente respondiendo a este mensaje y elimine todas las copias.

     

    This e-mail may contain confidential and privileged material for the sole use of the intended recipient. Any review, use, distribution or disclosure by others is strictly prohibited. If you are not the intended recipient (or authorized to receive for the recipient), please contact the sender by reply e-mail and delete all copies of this message.

     






  • 12.  RE: Issue with IAP and mobility controller : Can't get DHCP

    Posted Jan 04, 2022 09:09 AM
    As i said, i m testing an IAP close to Mobility controler.
    X

    IAP is on the same network than mobility controller. It can ping it.
    If i try with a GRE tunnel, it is the same, IAP is not detected by Mobility controller.
    The firewall should not be the cause of this issue. 

    When you read logs from mobility controller, you can see that IAP try to make a tunnel but Mobility controlle reject it.

    So i have whitelisted this AP for Campus AP and Remote AP Whitelist :

    Now, when AP tries to make VPN, i get those errors :

    Regards.

    ------------------------------
    Alexandre RAIMBAULT
    ------------------------------



  • 13.  RE: Issue with IAP and mobility controller : Can't get DHCP

    EMPLOYEE
    Posted Jan 04, 2022 09:25 AM

    2 things to comment here, hope it help

     

    1 if you are working on a instant cluster APs you were not enable to provision that IAPs as campus or remote AP at the controller, those APs are working in Instant mode, it is only posible to make an IAP VPN in order to connect to central site by an internet link, in case you need to provision you can convert that to a Campus or Remote AP

     

    2 in case you are trying to establish an IAP VPN, this is an IPsec tunnel, it is a L3 tunnel, you might have an L3 connection btween controller & IPs.

     

    Regards

     


    Jorge Calvi

    Systems Engineer - Argentina & Paraguay

    Aruba, a Hewlett Packard Enterprise company

    M: +54 91150633418

    AIRHEADS COMMUNITY FOLLOW US Twitter LinkedIn

     

    Este correo electrónico puede contener información confidencial y es para uso del destinatario exclusivamente. Cualquier revisión, distribución, revelación o uso por terceros de la información contenida en este mail está prohibida.  Si no es el destinatario de este correo, por favor contacte al remitente respondiendo a este mensaje y elimine todas las copias.

     

    This e-mail may contain confidential and privileged material for the sole use of the intended recipient. Any review, use, distribution or disclosure by others is strictly prohibited. If you are not the intended recipient (or authorized to receive for the recipient), please contact the sender by reply e-mail and delete all copies of this message.

     






  • 14.  RE: Issue with IAP and mobility controller : Can't get DHCP

    Posted Jan 04, 2022 09:44 AM
    Ok i understand.
    Sorry, i m very new with this architecture and i don't have any tuturial or documentation..

    My issue is that when i connect to guest SSID, i can't reach DHCP.
    Tested with a GRE tunnel and IPSEC but no luck. unable to have an IP.

    Authenticated WIFI with a radius is working well.

    ------------------------------
    Alexandre RAIMBAULT
    ------------------------------



  • 15.  RE: Issue with IAP and mobility controller : Can't get DHCP

    EMPLOYEE
    Posted Jan 04, 2022 10:15 AM

    Ok understood, my question is, how are you offering LAN services to this network, and it stand for:

     

    How are you offering the guest vlan to this cluster is it locally, is it by a tunnel through the Mobility Controller who is in other physical site? If tunnel is the answer your issue now is to get an IAP VPN tunnel up and running, in this case this documentation may help

     

    https://support.arubanetworks.com/DesktopModules/Bring2mind/DMX/Download.aspx?TabId=77&DMXModule=512&Command=Core_Download&Method=attachment&EntryId=38514&PortalId=0

     

    but remember if you are trying to establish an IAP VPN tunnel you must define interesting traffic rules and you must have an L3 connection between APs and Controller, if you try to set up this in a L2 lab enviroment i think it wont work

     

    Regards

     


    Jorge Calvi

    Systems Engineer - Argentina & Paraguay

    Aruba, a Hewlett Packard Enterprise company

    M: +54 91150633418

    AIRHEADS COMMUNITY FOLLOW US Twitter LinkedIn

     

    Este correo electrónico puede contener información confidencial y es para uso del destinatario exclusivamente. Cualquier revisión, distribución, revelación o uso por terceros de la información contenida en este mail está prohibida.  Si no es el destinatario de este correo, por favor contacte al remitente respondiendo a este mensaje y elimine todas las copias.

     

    This e-mail may contain confidential and privileged material for the sole use of the intended recipient. Any review, use, distribution or disclosure by others is strictly prohibited. If you are not the intended recipient (or authorized to receive for the recipient), please contact the sender by reply e-mail and delete all copies of this message.

     






  • 16.  RE: Issue with IAP and mobility controller : Can't get DHCP

    EMPLOYEE
    Posted Jan 04, 2022 10:20 AM

    In case you need to have this running in a local site, you can avoid tunnels and share guest vlan in a trunk port, permiting thi vlan be present at the AP & at the controller, if DHCP services are hosted at controller, if not you must only give guest vlan at AP side and get confident this vlan is present in all links btween AP and router giving DHCP or acting as DHCP helper

     

    Regards

     


    Jorge Calvi

    Systems Engineer - Argentina & Paraguay

    Aruba, a Hewlett Packard Enterprise company

    M: +54 91150633418

    AIRHEADS COMMUNITY FOLLOW US Twitter LinkedIn

     

    Este correo electrónico puede contener información confidencial y es para uso del destinatario exclusivamente. Cualquier revisión, distribución, revelación o uso por terceros de la información contenida en este mail está prohibida.  Si no es el destinatario de este correo, por favor contacte al remitente respondiendo a este mensaje y elimine todas las copias.

     

    This e-mail may contain confidential and privileged material for the sole use of the intended recipient. Any review, use, distribution or disclosure by others is strictly prohibited. If you are not the intended recipient (or authorized to receive for the recipient), please contact the sender by reply e-mail and delete all copies of this message.

     






  • 17.  RE: Issue with IAP and mobility controller : Can't get DHCP

    Posted Jan 04, 2022 10:41 AM
    We need to offer guest access by a tunnel.
    guest SSID will be accessible from remote sites and from central site.

    All traffic from guest vlan shall be redirected to mobility controller, so that SSID won't be able to reach local networks.

    DHCP is on a firewall, and this firewall is also a gateway throught internet.
    I will check your doc. thanks.


    In addition, APs have to provide an authenticated SSID, where users are authenticated through radius (this part is working).

    Regards

    ------------------------------
    Alexandre RAIMBAULT
    ------------------------------



  • 18.  RE: Issue with IAP and mobility controller : Can't get DHCP

    Posted Jan 04, 2022 11:33 AM
    It seems to work.
    used this : https://community.arubanetworks.com/community-home/digestviewer/viewthread?MID=47300#bmfb9c7e7c-f6f7-4798-a42f-13e4c781c024

    I made a manual GRE tunnel.
    And what it missed was routing and virtual controller.

    I will edit this post if i have some other clues. 
    If there are users with questions, i can answer.

    Thanks for help.

    ------------------------------
    Alexandre RAIMBAULT
    ------------------------------



  • 19.  RE: Issue with IAP and mobility controller : Can't get DHCP

    Posted Jan 05, 2022 02:46 AM
    Ok, now it works fine with IAP in central site.

    Now in remote site, wifi guest DHCP not working.
    Mobility controller send packets to AP but AP is not responding.

    There is a vpn IPSEC between sites, which allows all protocols, all ports all services.

    Is there a command to debug a GRE tunnel in aruba OS?
    is there a possibility that my ipsec vpn is blocking something in GRE protocole?

    My GRE tunnel is a L2.
    REgards

    ------------------------------
    Alexandre RAIMBAULT
    ------------------------------



  • 20.  RE: Issue with IAP and mobility controller : Can't get DHCP

    Posted Jan 10, 2022 03:39 AM
    So, after some research, it seems that the issue is in MTU.
    I will make another case on the forum.
    Thanks everyone for help.

    ------------------------------
    Alexandre RAIMBAULT
    ------------------------------