Wireless

 View Only
last person joined: 15 hours ago 

Expand all | Collapse all

Virtual controller assigned DHCP Guest client -- no internet

This thread has been viewed 42 times
  • 1.  Virtual controller assigned DHCP Guest client -- no internet

    Posted Aug 18, 2022 11:14 PM
    Hi guys,

    I am having an issue were, my virtual controller assigned dhcp and vlan to my guest ssid clients are getting dhcp but not getting internet connectivity.
    My setup:

    ssid: Guest
    Vlan: 12
    dhcp server (local) on VC: 192.168.12.0/24 scope

    The document Configuring Local DHCP Scopes
    Arubanetworks remove preview
    Configuring Local DHCP Scopes
    You can configure Local, Local, L2, and Local, L3 DHCP scopes through the Instant UI or CLI. -In this mode, the Virtual Controller acts as both the DHCP Server and the default gateway. The configured subnet and the corresponding DHCP scope are independent of subnets configured in other IAP clusters.
    View this on Arubanetworks >

    says  all I Need to do is assign the VLAN to it and it will nat to local traffic. This does not seem to work for me.
    Would appreciate any feedback please.



  • 2.  RE: Virtual controller assigned DHCP Guest client -- no internet

    EMPLOYEE
    Posted Aug 19, 2022 04:51 AM
    You may be missing a route back from your network to your VLAN 12/192.168.12.0/24?

    The recommended method for Guest traffic is to use 'Virtual Controller Managed' in the VLAN assignment:


    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Virtual controller assigned DHCP Guest client -- no internet

    Posted Aug 23, 2022 12:09 AM

    Hi Herman,

     

    Thanks for your response.

    I have configured it as suggested, still not getting internet.

    I am using clearpass server as captive portal.

    Could you please advice?

     

     

     






  • 4.  RE: Virtual controller assigned DHCP Guest client -- no internet

    EMPLOYEE
    Posted Aug 23, 2022 03:01 AM
    Can you reach your ClearPass?
    Can you login through your ClearPass?
    If you can successful login, what is the role the client has after authentication?
    Does the client receive an IP?
    Does the client receive DNS server information?
    Does DNS work on the client?
    Can you ping your default gateway from the client?

    Have you removed all the DHCP config after you moved to 'VC managed'?
    VLAN is set to Default for the Guest Network SSID config?

    Does the config work if you configure Network Assigned + Default VLAN?
    Note that Guest traffic will exit the AP from the (native) management VLAN. Your firewall (if there is one) should allow internet traffic from the AP's management IPs.

    If you have access to an Aruba Partner or Aruba support, it may be best to work with someone who can do interactive troubleshooting. There are too many options here, and going forth/back may take a long time.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: Virtual controller assigned DHCP Guest client -- no internet

    Posted Aug 23, 2022 08:00 AM

    Hi Herman,

     

    Please see below:

     

    Can you reach your ClearPass? è yes, I get to the captive portal page and session showing on Access Tracker
    Can you login through your ClearPass?
    è Yes I can logon via captive portal to hit clearpass guest URL
    If you can successful login, what is the role the client has after authentication? è Role is "Authenticated"
    Does the client receive an IP?
    è DHCp leases an Ip from scope (at all times è whether it is from VC or from external dhcp)
    Does the client receive DNS server information?
    è (yep they receive dns)
    Does DNS work on the client?
    è I cannot ping public ips (eg 8.8.8.8) so I am guessing Internet access is blocked somehow
    Can you ping your default gateway from the client? è NO I cannot ping default gateway, but I definitely get a lease from dhcp server

    Have you removed all the DHCP config after you moved to 'VC managed'?
    è yes and I did the same for "external dhcp" (only seems to happen when I go through clearpass)
    VLAN is set to Default for the Guest Network SSID config?
    è Vlan is set to "12" è static

    Does the config work if you configure Network Assigned + Default VLAN?
    è Only works when going through "internal server"  and "cloud" captive portal, but does not work when going through CPPM/Guest captive portal
    Note that Guest traffic will exit the AP from the (native) management VLAN. Your firewall (if there is one) should allow internet traffic from the AP's management IPs. è I am using a static vlan è vlan 12 ( does not work regardless)

     

     

    Many thanks for your prompt feedback

     

    Please advise further.

     






  • 6.  RE: Virtual controller assigned DHCP Guest client -- no internet

    EMPLOYEE
    Posted Aug 23, 2022 08:43 AM
    What is VLAN12? Do you have that configured on your switches? Do you have a router, NAT, etc, for VLAN12? If you put a wired client in a switch port on VLAN12, does that have internet access?

    It's also strange that you see a role Authenticated, because that is used in controller deployment, where in Instant deployments that role is equal to the SSID name.

    There are more or less two options that work:
    1) Use VC Managed address assignment, and put clients in the Default VLAN
    2) Use Network managed, and put clients in a VLAN (12 for example), and make sure all APs have VLAN 12 tagged, and you have a router/NAT device that issues the dhcp and offers connectivity.

    When you are in the captive portal role, before login, the Instant AP will perform NAT on all of the traffic, which may be why you can reach ClearPass and not reach anything after authentication. I would prefer the option 1; and if it doesn't work with that, put a client directly in the management VLAN to verify if that can have internet access. Or create an SSID (PSK or so) directly in VLAN12, without captive portal and make that work first.

    I would recommend that you find someone who can have a look with you, because it is hard to make a good judgement without having interactive access. Your Aruba partner or Aruba Support would be good candidates for that.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 7.  RE: Virtual controller assigned DHCP Guest client -- no internet

    Posted Aug 23, 2022 09:32 PM

    Hi Herman,

     

    Thanks for your response .

    Tested using internal captive portal on both external dhcp / static vlan 12 and internal dhcp/ inter vlan è works fine

    Whenever I use the CPPM as guest portal though it breaks.

    Seems to be an issue with CPPM blocking internet access.

     

    VLAN 12è 192.168.12.1

    All network L2/L3 working as I get to my dhcp on through a relay.

    Yep, I tested wired è all working dhcp and internet access

     

     

     

     






  • 8.  RE: Virtual controller assigned DHCP Guest client -- no internet

    Posted Aug 23, 2022 09:34 PM

    Would there be any setting on ClearPass on VC that would stop guest users from accessing the internet?

     

     

     

     






  • 9.  RE: Virtual controller assigned DHCP Guest client -- no internet

    Posted Aug 24, 2022 12:05 AM

    Hi Herman,

     

    I have attached config on VC and Clearpass.

    Please have a look and let me know if I have missed anything.

     

     






  • 10.  RE: Virtual controller assigned DHCP Guest client -- no internet

    EMPLOYEE
    Posted Aug 24, 2022 04:01 AM
    ClearPass is not 'in-line', so not capable of blocking internet traffic. ClearPass can return a role, which in the Instant AP may block internet traffic. That is why I asked for the client's user-role.

    What I can imagine is that the user-role does not switch, or switches to a wrong role, or the VLAN you are in does not offer all internet access. I would strongly recommend to use external DHCP servers for you guests, unless you are using the VC Managed/Default, which has automatic DHCP and should be kept default. But the details of your deployment may justify deviating from the standards, in which case you should well understand the use-case or let it be configured by someone who fully understands the solution.

    I didn't see any attached configuration, but also it's hard to get from just configuration to 'how to fix'. It's just easier to have a look at the equipment when the issue happens. Your Aruba partner or Aruba Support can probably do that.

    Also, in this video series you can see how to setup Instant + ClearPass captive portal (see the guest access section), and it may be good to remove config and rebuild it after that example. There also is a video on how the guest workflow should work, and how to troubleshoot it.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 11.  RE: Virtual controller assigned DHCP Guest client -- no internet

    Posted Aug 25, 2022 07:08 AM
    Hi Herman,

    I finally got internet access, but had to change mac auth guest policy enforcement to allow all.
    However my captive portal does not pop up when I do so. Any reason why I have this experience?

    Also why does clear pass create the  "MAC-caching" guest service if it never uses it?


    FYI: I am unable to get support access directly from Aruba at the moment. I am doing a Proof of Concept and thus the Ap I am using only has warranty agreement, but no support at the moment.

    So would gladly appreciate all help if and when you can.

    Please see services and images below.

    enforcement default ==> Allow access" data-title="Guest-mac auth ==> enforcement default ==> Allow access" width="300" data-modalsrc="https://higherlogicdownload.s3.amazonaws.com/HPE/UploadedImages/hSmXogCRNqfu8jvyVDc8_ArubaIssueHerman.png" data-imgbase="https://higherlogicdownload.s3.amazonaws.com/HPE/UploadedImages/hSmXogCRNqfu8jvyVDc8_ArubaIssueHerman.png" data-imgthumbnail="https://higherlogicdownload.s3.amazonaws.com/HPE/UploadedImages/hSmXogCRNqfu8jvyVDc8_ArubaIssueHerman-T.png" data-imgmedium="https://higherlogicdownload.s3.amazonaws.com/HPE/UploadedImages/hSmXogCRNqfu8jvyVDc8_ArubaIssueHerman-M.png" data-imglarge="https://higherlogicdownload.s3.amazonaws.com/HPE/UploadedImages/hSmXogCRNqfu8jvyVDc8_ArubaIssueHerman-L.png">









  • 12.  RE: Virtual controller assigned DHCP Guest client -- no internet

    EMPLOYEE
    Posted Aug 25, 2022 08:07 AM
    Please check the guest part in the video series mentioned in my previous answer. It shows that the MAC Auth should be used (but you may have a ordering/service categorization issue in ClearPass), and what the different roles mean.

    If ClearPass returns a role that does not exist on the Instant AP, you may get in a denyall situation (depending on other settings). The guest workflow may be somewhat confusing if you don't fully understand the steps and how the roles work together.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 13.  RE: Virtual controller assigned DHCP Guest client -- no internet

    Posted Aug 25, 2022 06:09 PM
    Thanks Herman. 
    I have watched the videos several times. 
    I don't think you went into the explanation of toles from clearpass to Iap. 

    Please correct me if I am wrong. 







  • 14.  RE: Virtual controller assigned DHCP Guest client -- no internet

    EMPLOYEE
    Posted Aug 29, 2022 04:57 AM
    That concept was covered in an earlier video.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 15.  RE: Virtual controller assigned DHCP Guest client -- no internet

    Posted Sep 22, 2022 12:26 AM
    Hi Herman,

    Fixed this issue. 
    Only thing missing was an ssl cert for guestportal access. 
    After that, all working as intended. 

    Thanks so much for your videos and correspondence. 

    Champ