Wireless Access

last person joined: 15 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Bridged vlan SSID clients no network

This thread has been viewed 3 times
  • 1.  Bridged vlan SSID clients no network

    Posted Apr 12, 2019 08:32 AM
    Bridge forwarding mode SSID clients only receiving DHCP from gateway which is the firewall at this location

    Firewall is the gateway and DHCP it's tagged 251 to a Aruba 2920 layer 2 switch and AP 275 tagged 251

    SSID has vlan 251

    Eth 0 bridged forward - native 1, tagged 251 (same throughout the set up)

    Clients connect get dhcp but have no access to anything else not even ping. did packet tracing and see things coming through but they are lost

    Only Arp allowed

    the switch sees the Mac addresses of the clients on the SSID the firewall also see the same.

    Any thoughts???


  • 2.  RE: Bridged vlan SSID clients no network

    Posted Apr 12, 2019 08:39 AM
    As I understand correctly the client doesn't get an IP address.
    Do you see a DHCP offer for the client from the firewall?


  • 3.  RE: Bridged vlan SSID clients no network

    Posted Apr 12, 2019 08:40 AM
    Client does receive DHCP

    It will receive an IP address default gateway and DNS


  • 4.  RE: Bridged vlan SSID clients no network

    EMPLOYEE
    Posted Apr 12, 2019 08:42 AM

    EDIT:  someone else answered.



  • 5.  RE: Bridged vlan SSID clients no network

    Posted Apr 12, 2019 08:49 AM
    And what is not working?


  • 6.  RE: Bridged vlan SSID clients no network

    Posted Apr 12, 2019 08:53 AM
    The SSID clients who receive a DHCP address are not able to reach the internet (8.8.8.8),ping their gateway (fw) or devices on the vlan.

    The firewall which gave them the DHCP address is not able to ping them either.



  • 7.  RE: Bridged vlan SSID clients no network

    Posted Apr 12, 2019 08:58 AM
    Could this be a user role issue?

    Even though they are bridged and not tunneling back to the controller , does initial user role apply here?



  • 8.  RE: Bridged vlan SSID clients no network

    Posted Apr 12, 2019 09:01 AM
    Yes the initial role is here also applied


  • 9.  RE: Bridged vlan SSID clients no network

    Posted Apr 12, 2019 09:16 AM
    I'm going to make the use a role authenticated , I'll see what happens here


  • 10.  RE: Bridged vlan SSID clients no network

    Posted Apr 12, 2019 09:30 AM
    This did not work


  • 11.  RE: Bridged vlan SSID clients no network

    Posted Apr 12, 2019 09:52 AM
    Which role is applied now?
    Please check this also with the command show user-table


  • 12.  RE: Bridged vlan SSID clients no network
    Best Answer

    Posted Apr 12, 2019 11:45 AM
    Solution!

    Found an policy entry was put in the valid user table denying that vlan

    Removed the deny from the valid user table.

    Clients are now connected to network and internet



  • 13.  RE: Bridged vlan SSID clients no network

    Posted Apr 12, 2019 09:01 AM
    Does the client have an ARP entry for the firewall?
    Is there any firewall rule configured within the user role?
    Do you see some traffic reaching the firewall?


  • 14.  RE: Bridged vlan SSID clients no network

    Posted Apr 12, 2019 09:13 AM
    Yes we see ARP entries

    Rules to allow any any

    Firewall only sees ARP traffic