Wireless Access

last person joined: 3 hours ago 

Access network design for branch, remote, outdoor and campus locations with Aruba access points, and mobility controllers.
Expand all | Collapse all

Intermittently Clients not getting IP Address when moved /reconnect to new AP on WLC 7010

Jump to Best Answer
  • 1.  Intermittently Clients not getting IP Address when moved /reconnect to new AP on WLC 7010

    Posted Mar 27, 2018 08:01 AM

    WLC 7010 (OS: 6.5.4.3) and AP-325 (2 Qty)

     

    Hi now our staff complaints as, Intermittently mobile devices or laptop not getting ip address from controller (dhcp server configured on 7010 controller itself) when they moved to new ap or if they disconnected wifi and reconnect immediately.

    after couple of minutes same user (device) able to get the ip address and have network access.

     

    recently we have created a new AP group (select existing group and save with new name) and moved both APs to new group, created new VAP and attached existing SSIDs (otherthan no changes).



  • 2.  RE: Intermittently Clients not getting IP Address when moved /reconnect to new AP on WLC 7010

    Posted Mar 27, 2018 08:26 AM

    make sure the user has "any any svc-dhcp permit" in the ACL attached to the user role.



  • 3.  RE: Intermittently Clients not getting IP Address when moved /reconnect to new AP on WLC 7010

    Posted Mar 27, 2018 08:49 AM
      |   view attached

    ok, now we added the "any any svc-dhcp permit" to user ACL (attached the screenshot, erlier the ACL entry was "user any svc-dhcp permit".

     

    we will check and update you.

     

     



  • 4.  RE: Intermittently Clients not getting IP Address when moved /reconnect to new AP on WLC 7010

    Posted Mar 27, 2018 12:22 PM

    wireless clients getting IP address from controller, but when users disconnect the wifi and immediately reconnectd or users moved to nearby office and device trying to connect to this office AP wireless clients not getting IP, after sometime (couple of minutes) device getting IP using the same AP or different AP.

     

    We suspect that when clients /devices roaming between the station (that means first client connect to ssid on AP-01, getting ip and network access , then moved to next office and trying to connect same ssid on AP-02) & also disconnect the wifi and immediately connected again, controller maintain the previces connection details after a timeout duration /session clearing time only controller allow the wireless client device to get the IP Address and communication.

     

    could you please help me to get the solution for this. 



  • 5.  RE: Intermittently Clients not getting IP Address when moved /reconnect to new AP on WLC 7010
    Best Answer

    Posted Mar 27, 2018 12:25 PM

    You have to add the any any service dhcp ACL to the production role, as well.  Not just the initial role.



  • 6.  RE: Intermittently Clients not getting IP Address when moved /reconnect to new AP on WLC 7010

    Posted Mar 27, 2018 12:30 PM

    hi cjoseph, sorry i couldn't able to understand what it means "production role" where we caan assig this role.

     

     



  • 7.  RE: Intermittently Clients not getting IP Address when moved /reconnect to new AP on WLC 7010

    Posted Mar 27, 2018 01:58 PM

    When you first associate to the WLAN, the clients gets into the initial role.  AFTER the client authenticates to the guest network, they switch to a "production" role.  You need to make sure that the "any any service dhcp" is in the ACL for both roles.



  • 8.  RE: Intermittently Clients not getting IP Address when moved /reconnect to new AP on WLC 7010

    Posted Mar 27, 2018 02:01 PM
    That means on post authentication role we need add this rule(any any dhcp allow), am I correct.
    Pls don't misunderstand me, I need to clear my doubts.


  • 9.  RE: Intermittently Clients not getting IP Address when moved /reconnect to new AP on WLC 7010

    Posted Mar 27, 2018 02:14 PM

    Correct.

     

    Having a user any svc-dhcp means a user will only get an ip address if he is currently in the user table.  That means returning users possibly won't get an ip address until they get a 169.x.x.x address and enter the user table.



  • 10.  RE: Intermittently Clients not getting IP Address when moved /reconnect to new AP on WLC 7010

    Posted Mar 27, 2018 02:51 PM
      |   view attached

    Thanks now this part is clear, if possible could you pease clarify me about Post Authentication Role assignment for SSID with Preshared Key.

     

    we are configured as SSID with preshared key only (no MAC /L2 and user based authentication), for this situation Post authentication role need to assign on initial role of respective (currently mapped the ssid)  AAA Profile, am i correct.

    if yes as per our AAA profile (attached) access list (any any dhcp permit) need to add on "Auth" role.

     

    am i correct, please do correct me.



  • 11.  RE: Intermittently Clients not getting IP Address when moved /reconnect to new AP on WLC 7010

    Posted Mar 27, 2018 02:53 PM

    For the PSK SSID, it would be the initial role.  Yes.



  • 12.  RE: Intermittently Clients not getting IP Address when moved /reconnect to new AP on WLC 7010

    Posted Mar 27, 2018 03:11 PM

    Thank you very much, i will check this and update you asap.