<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 9800L-F / 2802i Flexconnected AP / VPN: Guest SSID Users can't con in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/9800l-f-2802i-flexconnected-ap-vpn-guest-ssid-users-can-t/m-p/5203706#M276266</link>
    <description>&lt;P&gt;I have taken pcaps &amp;amp; debugs on the 9800. &amp;nbsp;The device that use MAC auth gets an IP but is still prevented from accessing network despite being in Run state. &amp;nbsp;The Firewall does complain about some Identity Awareness issue. &amp;nbsp;I’m working with that 3rd party TAC on that issue. &amp;nbsp;The other client uses Web Auth and I still see the DHCP Discover &amp;amp; Offer on the 9800. &amp;nbsp;But the client is stuck in IP Learn and doesn’t get the IP address or display the login web page for the Guest network&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 05 Oct 2024 00:06:29 GMT</pubDate>
    <dc:creator>perrymcgrew</dc:creator>
    <dc:date>2024-10-05T00:06:29Z</dc:date>
    <item>
      <title>9800L-F / 2802i Flexconnected AP / VPN: Guest SSID Users can't connect</title>
      <link>https://community.cisco.com/t5/wireless/9800l-f-2802i-flexconnected-ap-vpn-guest-ssid-users-can-t/m-p/5202541#M276168</link>
      <description>&lt;P&gt;9800L-F running 17.12.02 in the Corp Data center.&amp;nbsp; Large WAN sites connected via Cisco 8x00 SD-WAN devices. Small sites have S2S VPN connection to the corp datacenter using 3rd party Firewall.&amp;nbsp; &amp;nbsp;All remote sites APs are Flexconnected and registered to 9800L-F.&amp;nbsp; &amp;nbsp;The Guest SSID subnet lives in the Corp Datacenter and DHCP assigned by the data center core.&amp;nbsp; &amp;nbsp;Guest SSID uses MAC Auth and Web Auth w/ external redirect.&amp;nbsp; &amp;nbsp;The MAC auth is used for devices that can't display Web Auth splash page like ROKUs etc.&amp;nbsp; &amp;nbsp;Web Auth is for devices that can.&amp;nbsp; Neither auth method is working for the S2S VPN clients.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, the SD-WAN sites all work for Guest SSID.&amp;nbsp; &amp;nbsp;The sites that are connected with S2S VPN do not.&amp;nbsp; &amp;nbsp; The Guest clients at the VPN sites are stuck in IP Learn state.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;So took a debug and PCAP on the 9800L-F.&amp;nbsp; &amp;nbsp;In the PCAP I see the DHCP DIscover and the DHCP Offer for the failing client.&amp;nbsp; The DHCP Offer does not make it back to the client.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't see any drops in the Firewall logs -- but since I believe the traffic is inside the CAPWAP tunnel between the 9800 and the site's Flexconnected AP makes it hidden from running captures on the Firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;TAC says it's the Firewall since the 9800 is seeing the DHCP traffic.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone have ideas what the cause is or where to look next?&amp;nbsp;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 18:00:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800l-f-2802i-flexconnected-ap-vpn-guest-ssid-users-can-t/m-p/5202541#M276168</guid>
      <dc:creator>perrymcgrew</dc:creator>
      <dc:date>2024-10-02T18:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: 9800L-F / 2802i Flexconnected AP / VPN: Guest SSID Users can't con</title>
      <link>https://community.cisco.com/t5/wireless/9800l-f-2802i-flexconnected-ap-vpn-guest-ssid-users-can-t/m-p/5202558#M276169</link>
      <description>&lt;P&gt;If it flexconn then traffic not pass to wlc unless you use dhcp central&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 18:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800l-f-2802i-flexconnected-ap-vpn-guest-ssid-users-can-t/m-p/5202558#M276169</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-02T18:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: 9800L-F / 2802i Flexconnected AP / VPN: Guest SSID Users can't con</title>
      <link>https://community.cisco.com/t5/wireless/9800l-f-2802i-flexconnected-ap-vpn-guest-ssid-users-can-t/m-p/5202598#M276173</link>
      <description>&lt;P&gt;All The remote SD-WAN flexconn sites get DHCP for Guest SSID. Central DHCP is activated in the Guest Policy.&amp;nbsp; Plus, the pcap taken on the 9800-L-F clearly showed the DHCP Discover and Offer from the remote site's device trying to access Guest SSID.&amp;nbsp; The device stays in IP Learn state.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 19:28:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800l-f-2802i-flexconnected-ap-vpn-guest-ssid-users-can-t/m-p/5202598#M276173</guid>
      <dc:creator>perrymcgrew</dc:creator>
      <dc:date>2024-10-02T19:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: 9800L-F / 2802i Flexconnected AP / VPN: Guest SSID Users can't con</title>
      <link>https://community.cisco.com/t5/wireless/9800l-f-2802i-flexconnected-ap-vpn-guest-ssid-users-can-t/m-p/5202664#M276177</link>
      <description>&lt;P&gt;you can do a packet capture at the WLC to see traffic going through it&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 23:33:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800l-f-2802i-flexconnected-ap-vpn-guest-ssid-users-can-t/m-p/5202664#M276177</guid>
      <dc:creator>Haydn Andrews</dc:creator>
      <dc:date>2024-10-02T23:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: 9800L-F / 2802i Flexconnected AP / VPN: Guest SSID Users can't con</title>
      <link>https://community.cisco.com/t5/wireless/9800l-f-2802i-flexconnected-ap-vpn-guest-ssid-users-can-t/m-p/5203706#M276266</link>
      <description>&lt;P&gt;I have taken pcaps &amp;amp; debugs on the 9800. &amp;nbsp;The device that use MAC auth gets an IP but is still prevented from accessing network despite being in Run state. &amp;nbsp;The Firewall does complain about some Identity Awareness issue. &amp;nbsp;I’m working with that 3rd party TAC on that issue. &amp;nbsp;The other client uses Web Auth and I still see the DHCP Discover &amp;amp; Offer on the 9800. &amp;nbsp;But the client is stuck in IP Learn and doesn’t get the IP address or display the login web page for the Guest network&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 00:06:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800l-f-2802i-flexconnected-ap-vpn-guest-ssid-users-can-t/m-p/5203706#M276266</guid>
      <dc:creator>perrymcgrew</dc:creator>
      <dc:date>2024-10-05T00:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: 9800L-F / 2802i Flexconnected AP / VPN: Guest SSID Users can't con</title>
      <link>https://community.cisco.com/t5/wireless/9800l-f-2802i-flexconnected-ap-vpn-guest-ssid-users-can-t/m-p/5211696#M276768</link>
      <description>&lt;P&gt;Did you make any progress on this?&lt;BR /&gt;It seems clear the problem must be the 3rd party firewall but it could also be an MTU and/or fragmentation issue.&lt;BR /&gt;Can't you do a pcap on the egress from the firewall to confirm the packets are leaving the firewall (or not)?&amp;nbsp; As long as you don't have CAPWAP data encryption turned on you should be able to see all the packets in the CAPWAP data tunnel.&amp;nbsp; If you do have CAPWAP data encryption turned on (pointless if you're running it over a VPN anyway) then turn it off for troubleshooting at least.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Oct 2024 11:46:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800l-f-2802i-flexconnected-ap-vpn-guest-ssid-users-can-t/m-p/5211696#M276768</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-10-20T11:46:23Z</dc:date>
    </item>
  </channel>
</rss>

