Wireless Access

last person joined: 20 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Clients get IP Address vom DHCP but no Network access

This thread has been viewed 2 times
  • 1.  Clients get IP Address vom DHCP but no Network access

    Posted Nov 01, 2017 06:29 AM

    Hello guys 

     

    I'm installing an VMC standalone on customer side and have a strange issue.

     

    DHCP are on the windows domain controller for all VLANs. 

    I have two SSIDs:

    Test 1 ; VLAN 10 ; default Role: authenticated

    Test 2 : VLAN 20 ; default Role : logon

     

    On both SSIDs the clients get an IP from the DHCP. Afterwards they cannot ping the gateway or other internal stuff even the internet.

     

    Have someone an idea what the issue can be?

     

    Thanks in advanced.



  • 2.  RE: Clients get IP Address vom DHCP but no Network access

    EMPLOYEE
    Posted Nov 04, 2017 02:04 PM

    On the controller the user is connected to, type "show datapath session table <ip address of user>" to see if traffic is being blocked.



  • 3.  RE: Clients get IP Address vom DHCP but no Network access

    Posted Nov 08, 2017 09:25 AM

    Thanks for replay and sorry for the late response.

    The traffic is not shown in the datapath table session:

     

     #show datapath session table 192.168.1.149
    
    
    Datapath Session Table Entries
    ------------------------------
    
    Flags: F - fast age, S - src NAT, N - dest NAT
           D - deny, R - redirect, Y - no syn
           H - high prio, P - set prio, T - set ToS
           C - client, M - mirror, V - VOIP
           Q - Real-Time Quality analysis
           u - Upstream Real-Time Quality analysis
           I - Deep inspect, U - Locally destined
           E - Media Deep Inspect, G - media signal
           r - Route Nexthop, h - High Value
           A - Application Firewall Inspect
           B - Permanent, O - Openflow
           L - Log
    
    Source IP       Destination IP  Prot SPort DPort Cntr     Prio ToS Age Destination TAge Packets    Bytes      Flags
    --------------- --------------- ---- ----- ----- -------- ---- --- --- ----------- ---- ---------  --------- ---------------
    192.168.1.149      192.168.1.255      17   137   137    0/0     0    0   1   tunnel 14   8f   46         3588       FC
    192.168.1.149      224.0.0.252     17   49755 5355   0/0     0    0   0   tunnel 14   2    2          104        FC
    192.168.1.149      224.0.0.252     17   64857 5355   0/0     0    0   0   tunnel 14   5    0          0          FC
    192.168.1.149      224.0.0.252     17   61096 5355   0/0     0    0   1   tunnel 14   12   0          0          FC
    192.168.1.149      224.0.0.252     17   63715 5355   0/0     0    0   0   tunnel 14   2    2          104        FC
    
    192.168.1.255      192.168.1.149      17   137   137    0/0     0    0   9   tunnel 14   90   0          0          FY

    Do you have another idea?



  • 4.  RE: Clients get IP Address vom DHCP but no Network access

    EMPLOYEE
    Posted Nov 08, 2017 09:41 AM

    That output does not match your command.  Is your user in the user table on the controller?



  • 5.  RE: Clients get IP Address vom DHCP but no Network access

    Posted Nov 08, 2017 09:45 AM

    Sorry, I forgot to change th IP Address. ;)

     

    The user is listet on the User Table.



  • 6.  RE: Clients get IP Address vom DHCP but no Network access

    EMPLOYEE
    Posted Nov 08, 2017 09:50 AM

    What are the ACLS on the client's role?

    Can the client ping the default gateway?



  • 7.  RE: Clients get IP Address vom DHCP but no Network access

    Posted Nov 08, 2017 09:56 AM
      |   view attached

    I tried with the default "authentication" role (see the Picture in the Attachment).

     

    No I can't reach any device in the network. Even the DHCP Server who gave the IP address.

     

    It's the first time I use a Virtual MC. All other installation are physical Applicances.

     

     

     



  • 8.  RE: Clients get IP Address vom DHCP but no Network access

    EMPLOYEE
    Posted Nov 08, 2017 10:07 AM

    Remove the first rule.  It is blocking everything.



  • 9.  RE: Clients get IP Address vom DHCP but no Network access

    Posted Nov 08, 2017 10:10 AM

    It's not possible:

    Capture.PNG

     

    I did try with a new role only with one rule "any any permit" already. With the same result. I can try it again...



  • 10.  RE: Clients get IP Address vom DHCP but no Network access

    Posted Nov 08, 2017 10:24 AM

    I tried with the new rule again.

    That is my ruleset:

    Capture.PNG

    Use it on the Wifi Profile:

    Capture1.PNG

    User assign to the new rule:

    Capture2.PNG

    I get the IP Address from the DHCP Server, but I can't pint the default gateway even the DHCP Server...

    Capture3.PNG

    there are no ARP entries in the arp-table as well.

     

    It's realy strange.

    I have another SSID - used default VLAN 1, with no issue!



  • 11.  RE: Clients get IP Address vom DHCP but no Network access

    Posted Nov 08, 2017 10:29 AM

    I assign the controller an IP address on this network (192.168.1.11).

    Now, I can ping from the client (192.168.1.160) the controller (192.168.1.11) but not the DHCP server (192.168.1.10) or another device (192.168.1.52)

     

    Other clients in the same Wifi it works as well. I guess there is an issue with the firewall on the controller. Is there an option to disable it completely?



  • 12.  RE: Clients get IP Address vom DHCP but no Network access

    Posted Nov 08, 2017 11:17 AM

    Your first post mentions this being a virtual mobility controller; and you later say that SSIDs on VLAN 1 work fine.     Do you have the VLAN tagging setup properly on the both the VMC interface as well as the host server environment? 

     

    Please share the port/vlan configuration for the interface you are using on the controller as well as the host server.



  • 13.  RE: Clients get IP Address vom DHCP but no Network access

    Posted Nov 09, 2017 01:49 AM

    Yes, that's true. My configuration on the VMC:

    vlan 4 description "clients"
    vlan 334 description "public-wifi"
    !
    controller-ip vlan 1
    interface mgmt
        ip address 192.168.61.250 255.255.255.0
    !
    !
    ip default-gateway mgmt 192.168.61.10
    !
    interface gigabitethernet 0/0/0
        description "GE0/0/0"
        trusted
        trusted vlan 1-4094
        no poe
        switchport mode trunk
        switchport trunk native vlan 1000
        no spanning-tree
    !
    
    interface gigabitethernet 0/0/1
        description "GE0/0/1"
        shutdown
        trusted
        trusted vlan 1-4094
        no poe
        no spanning-tree
    !
    
    interface gigabitethernet 0/0/2
        description "GE0/0/2"
        shutdown
        trusted
        trusted vlan 1-4094
        no poe
        no spanning-tree

    I requested the ESXi printscreen from the customer. 



  • 14.  RE: Clients get IP Address vom DHCP but no Network access

    Posted Nov 10, 2017 02:03 AM

    So, I got the printscreens from the customer:

    esx1.pngesx2.png

    Thanks for helping!



  • 15.  RE: Clients get IP Address vom DHCP but no Network access

    Posted Aug 17, 2020 01:55 PM

    I have to say i have been STRUGGLING with what seems to be the exact situation. I was excited to fine this discussion and sad to see it ended without a resolution.... any chance you found the solution and wish to share it?



  • 16.  RE: Clients get IP Address vom DHCP but no Network access

    EMPLOYEE
    Posted Aug 18, 2020 07:47 AM

    Your disappointment is noted.

     

    Please open a new thread so we can address your specific issue.  This thread is 3 years old, so we are closing it.