<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Clients Stuck on IP Learn (DHCP Troubleshooting) in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/clients-stuck-on-ip-learn-dhcp-troubleshooting/m-p/5290031#M283245</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;In my quest to get cisco 9800 deployed, i have encountered a issue with DHCP.&amp;nbsp; I am looking for some advice on how to move forward with&amp;nbsp; troubleshooting. I am able to get EAP/DOT1X traffic to ISE and see clients authenticate,&amp;nbsp; but they never leave the 'IP learn'.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently the device is setup for a single WMI with the default route pointing out, and a trunk link carrying L2 for vlans.&amp;nbsp; The SVI is on a "upstream" device and has holds the IP helper/relay. It is my understanding that with the 9800CL there is no need to disable any "dhcp proxy" setting as IOS XE will function in "bridge" mode automatically, if an interface with relay is not enabled. In the controller, i have "require dhcp" enabled (policy &amp;gt; advanced) but it is my understanding this is only required to force clients to need to use to dhcp, and therefore not allow any static addressing.&lt;/P&gt;&lt;P&gt;I've run a packet capture on the WMI interface and capture the capwap dhcp traffic. I've attached this below.&amp;nbsp; They are all discover broadcasts. I've run a capture on the SVI of the hosts and not seen any response traffic.&amp;nbsp;&amp;nbsp;In an effort to attempt to troubleshoot further, i also attempted a relay and created an interface with an ip in the host's range and set an ip helper there. This resulted in the same results.&amp;nbsp;I assume this is the only setup required for a relay. &amp;nbsp;I checked the DHCP server and see no hits for the clients mac in the leases.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; I would like to run a capture on the DHCP server's interface, unfortunately it is in a remote data center and i am unable to access the connected switch. We will check out the ACL/other issue when we travel there next.&amp;nbsp; However, i am wondering where else to possibly make captures or troubleshoot the DHCP issue, as it appears the discovers are not being answered.&lt;/P&gt;&lt;P&gt;Thank you for your input.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 12 May 2025 18:07:16 GMT</pubDate>
    <dc:creator>jbulloch</dc:creator>
    <dc:date>2025-05-12T18:07:16Z</dc:date>
    <item>
      <title>Clients Stuck on IP Learn (DHCP Troubleshooting)</title>
      <link>https://community.cisco.com/t5/wireless/clients-stuck-on-ip-learn-dhcp-troubleshooting/m-p/5290031#M283245</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;In my quest to get cisco 9800 deployed, i have encountered a issue with DHCP.&amp;nbsp; I am looking for some advice on how to move forward with&amp;nbsp; troubleshooting. I am able to get EAP/DOT1X traffic to ISE and see clients authenticate,&amp;nbsp; but they never leave the 'IP learn'.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently the device is setup for a single WMI with the default route pointing out, and a trunk link carrying L2 for vlans.&amp;nbsp; The SVI is on a "upstream" device and has holds the IP helper/relay. It is my understanding that with the 9800CL there is no need to disable any "dhcp proxy" setting as IOS XE will function in "bridge" mode automatically, if an interface with relay is not enabled. In the controller, i have "require dhcp" enabled (policy &amp;gt; advanced) but it is my understanding this is only required to force clients to need to use to dhcp, and therefore not allow any static addressing.&lt;/P&gt;&lt;P&gt;I've run a packet capture on the WMI interface and capture the capwap dhcp traffic. I've attached this below.&amp;nbsp; They are all discover broadcasts. I've run a capture on the SVI of the hosts and not seen any response traffic.&amp;nbsp;&amp;nbsp;In an effort to attempt to troubleshoot further, i also attempted a relay and created an interface with an ip in the host's range and set an ip helper there. This resulted in the same results.&amp;nbsp;I assume this is the only setup required for a relay. &amp;nbsp;I checked the DHCP server and see no hits for the clients mac in the leases.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; I would like to run a capture on the DHCP server's interface, unfortunately it is in a remote data center and i am unable to access the connected switch. We will check out the ACL/other issue when we travel there next.&amp;nbsp; However, i am wondering where else to possibly make captures or troubleshoot the DHCP issue, as it appears the discovers are not being answered.&lt;/P&gt;&lt;P&gt;Thank you for your input.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 18:07:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/clients-stuck-on-ip-learn-dhcp-troubleshooting/m-p/5290031#M283245</guid>
      <dc:creator>jbulloch</dc:creator>
      <dc:date>2025-05-12T18:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: Clients Stuck on IP Learn (DHCP Troubleshooting)</title>
      <link>https://community.cisco.com/t5/wireless/clients-stuck-on-ip-learn-dhcp-troubleshooting/m-p/5290102#M283252</link>
      <description>&lt;P&gt;I would like to ask/point out few things but before that would you mind to share 'show tech wireless' from controller so that I can just have a look how the configuration is.&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2025 00:28:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/clients-stuck-on-ip-learn-dhcp-troubleshooting/m-p/5290102#M283252</guid>
      <dc:creator>Saikat Nandy</dc:creator>
      <dc:date>2025-05-13T00:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: Clients Stuck on IP Learn (DHCP Troubleshooting)</title>
      <link>https://community.cisco.com/t5/wireless/clients-stuck-on-ip-learn-dhcp-troubleshooting/m-p/5290233#M283271</link>
      <description>&lt;P&gt;Hi saikat,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply again. I've attached the wireless. Is the 'central dhcp' slider in relation to local dhcp drop off? I suspected this morning this may be related, and am working to get a capture between here and the DHCP server. If a flex/local dhcp configuration is the issue, which settings are needed to be adjusted?&lt;/P&gt;&lt;P&gt;Again thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2025 11:45:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/clients-stuck-on-ip-learn-dhcp-troubleshooting/m-p/5290233#M283271</guid>
      <dc:creator>jbulloch</dc:creator>
      <dc:date>2025-05-13T11:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Clients Stuck on IP Learn (DHCP Troubleshooting)</title>
      <link>https://community.cisco.com/t5/wireless/clients-stuck-on-ip-learn-dhcp-troubleshooting/m-p/5290272#M283276</link>
      <description>&lt;P&gt;I have gone through your STW and I believe the issue is in the config. Here are the reasons -&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. You are using 9800-CL. So the best practise is to keep the APs is flex mode. However all the APs are in Local mode.&lt;BR /&gt;2. If you really want to keep your APs in local mode, create a SVI for WMI and use Gig1 or Gig2 or both for data connection. Make sure the required vlans are allowed in the trunk.&lt;BR /&gt;3. If you shift towards Flex mode APs, there is no need for client SVI 116.&lt;BR /&gt;4. Policy Profile 'SYLAN-S1F-POL' is having AAA override &amp;amp; NAC enabled - do you really need this?&lt;BR /&gt;5. If you shift to Flex mode APs, you need to tweak the Policy Profile config as well + Need to create Flex profile&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2025 13:38:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/clients-stuck-on-ip-learn-dhcp-troubleshooting/m-p/5290272#M283276</guid>
      <dc:creator>Saikat Nandy</dc:creator>
      <dc:date>2025-05-13T13:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Clients Stuck on IP Learn (DHCP Troubleshooting)</title>
      <link>https://community.cisco.com/t5/wireless/clients-stuck-on-ip-learn-dhcp-troubleshooting/m-p/5290302#M283280</link>
      <description>&lt;P&gt;Hi saikat, again thanks for the assistance. Not sure cisco is paying you enough. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Yes, i have decided to use local mode. Our AP's are all talking back to ISE for IBNS/8X/MAB, and we have single pair at the core. It is my understanding the AP's on flex will be unable to authenticate anyone depending on mode for flex, as modes will allow sessions that exist to timeout in basis, and none will allow new dot1x clients to stay connected without use of a preshare so i am not sure what benefit it would otherwise have for us unless we put nearby AP's into a bridge mode.&amp;nbsp; Since our DHCP is also local to same core, went with local deployment and not flex profile. If we move to AP's at some remote sites, then possibly we can move to flex profiles at that time.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had enabled 116 SVI in an effort to use relay, to no success. I was using GI1 with IP in our&amp;nbsp; "server" range and then just GI2 L2 trunk for vlan traffic, as i understood with local there was no need for SVI on device due to DHCP bridge being done by helper upstream.&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1&lt;BR /&gt;description WMI&lt;BR /&gt;no switchport&lt;BR /&gt;ip address 157.141.6.28 255.255.255.240&lt;BR /&gt;no ip redirects&lt;BR /&gt;no ip unreachables&lt;BR /&gt;negotiation auto&lt;BR /&gt;no mop enabled&lt;BR /&gt;no mop sysid&lt;BR /&gt;service-policy output AutoQos-4.0-wlan-Port-Output-Policy&lt;/P&gt;&lt;P&gt;Am i misunderstanding the SVI requirement here?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2025 14:33:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/clients-stuck-on-ip-learn-dhcp-troubleshooting/m-p/5290302#M283280</guid>
      <dc:creator>jbulloch</dc:creator>
      <dc:date>2025-05-13T14:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: Clients Stuck on IP Learn (DHCP Troubleshooting)</title>
      <link>https://community.cisco.com/t5/wireless/clients-stuck-on-ip-learn-dhcp-troubleshooting/m-p/5290307#M283283</link>
      <description>&lt;P&gt;I believe you're suggesting not to use a routed interface after reading the post once over.&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2025 14:44:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/clients-stuck-on-ip-learn-dhcp-troubleshooting/m-p/5290307#M283283</guid>
      <dc:creator>jbulloch</dc:creator>
      <dc:date>2025-05-13T14:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Clients Stuck on IP Learn (DHCP Troubleshooting)</title>
      <link>https://community.cisco.com/t5/wireless/clients-stuck-on-ip-learn-dhcp-troubleshooting/m-p/5290469#M283295</link>
      <description>&lt;P&gt;Under flex environment, you can have multiple scenarios and one of those is Central Auth - Local switching... means the client auth traffic will go from AP through the CAPWAP to WLC to AAA server and the same path will be followed for the return traffic as well. However the client traffic won't pass through CAPWAP and come to controller - it will pass from AP to switch to local core/router to internet and same path for return traffic. Traditionally people choose flex when they have controller and AP belonging to two different sites and talking to each other over SD-WAN, MPLS etc. But you can still do flexconnect even when AP and WLC belongs to the same site (in few cases this improves the endpoint throughput as well cz controller gets bypassed for data traffic). All you need is to ensure that required vlans are allowed in the AP switchport, rather than WLC switchport.&lt;BR /&gt;Since the issue is DHCP related, another very basic tshoot you can perform is by connecting a laptop directly to the switch where your APs are...put it in same vlan 116 and see if you are getting an IP address.&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2025 00:31:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/clients-stuck-on-ip-learn-dhcp-troubleshooting/m-p/5290469#M283295</guid>
      <dc:creator>Saikat Nandy</dc:creator>
      <dc:date>2025-05-14T00:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Clients Stuck on IP Learn (DHCP Troubleshooting)</title>
      <link>https://community.cisco.com/t5/wireless/clients-stuck-on-ip-learn-dhcp-troubleshooting/m-p/5291761#M283435</link>
      <description>&lt;P&gt;Did you make any progress on this&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1361495"&gt;@jbulloch&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;I believe you're suggesting not to use a routed interface after reading the post once over.&lt;/SPAN&gt;&lt;BR /&gt;SVI on WLC is not best practice (see the Best Practices link below)&lt;/P&gt;
&lt;P&gt;If you're running 9800-CL on VMware ESX have you applied the required config tweaks on ESX (see the 9800 Install and Setup guides) and also mentioned in Best Practices?&lt;/P&gt;
&lt;P&gt;Like&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/853834"&gt;@Saikat Nandy&lt;/a&gt;&amp;nbsp;said make sure a LAN connected user can get an IP address first.&amp;nbsp; If not, then you need to solve the DHCP issue before looking at the WLC.&lt;/P&gt;</description>
      <pubDate>Sun, 18 May 2025 22:06:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/clients-stuck-on-ip-learn-dhcp-troubleshooting/m-p/5291761#M283435</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2025-05-18T22:06:16Z</dc:date>
    </item>
  </channel>
</rss>

