<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Seemingly Simple Wireless Setup, confusing TAC also. 3 devices: WAP150 + DLink switch + ASA Firewall. in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/seemingly-simple-wireless-setup-confusing-tac-also-3-devices/m-p/2953953#M82464</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We're having a weird issue and wondering if someone can identify what's wrong. We've opened a TAC case with Small Business and after many hours &lt;BR /&gt;and tests we're still confused. It is a very basic set up but it appears like users in the WAP150 Guest network are sending all of their TCP &lt;BR /&gt;traffic to the Access point instead of routing it out to the internet. The BIG question noone has been able to answer: Why are the Guest wireless &lt;BR /&gt;users trying to send all TCP traffic on Layer 3 to the AP?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Topology:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;[ASA 5505 (Basic License) ] --------- [DLink DGS-1100-24P Switch] ---------[Cisco Wireless AP 150] ------ [Guest User connecting from computer or &lt;BR /&gt;cell phone]&lt;/P&gt;
&lt;P&gt;Here are the devices and info:&lt;/P&gt;
&lt;P&gt;ASA 5505:&lt;/P&gt;
&lt;P&gt;VLAN 1 - Inside&lt;/P&gt;
&lt;P&gt;VLAN 2 - Outside (Since The ASA 5505 has a basic license and can't do vlans, we have ethernet port 7 plugged into a port in the DLink switch for &lt;BR /&gt;only guest traffic that works for all Guest users but Guest Wireless users. We have ethernet port 1 plugged in for just Inside users connecting &lt;BR /&gt;to Office traffic.&lt;/P&gt;
&lt;P&gt;VLAN 5 - GuestWireless&lt;/P&gt;
&lt;P&gt;DHCP being supplied by ASA 5505&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;DLink DGS-1100-24P Switch&lt;/P&gt;
&lt;P&gt;Layer 2 Switch with VLANs 3(Office) and 5(Guest).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Cisco WAP150&lt;/P&gt;
&lt;P&gt;VLANs 3(Inside) and 5(Guest)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here is some quick information:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When trunking the Cisco WAP150(I've tried trunk port and Hybrid port for the WAP150 to connect to the DLink switch), the Office VLAN 3 works fine &lt;BR /&gt;and users route out with no issues. When trying to connect to the Guest. Guest users connect to Guest wireless, and can PULL a DHCP address from &lt;BR /&gt;the ASA in the proper VLAN(Correct Default Gateway,DNS, etc everything correct), AND can send DNS traffic out to the internet and resolve, BUT &lt;BR /&gt;web and TCP traffic is directed to the WAP150's IP address which is located in the Inside network. The ASA 5505 at this point says "No, we can't &lt;BR /&gt;do this because of of the no forward command between Guest and Inside networks due to license constraints of the basic license". The massive &lt;BR /&gt;question is, when someone connects to Guest Wireless and acceses a webpage on the internet, the log capture is showing the Guest users IP &lt;BR /&gt;(10.200.1.57, for example) going to the Access Points IP(10.40.222.240) with the traffic instead of routing it out to the internet (i.e logs show &lt;BR /&gt;many packets like 10.200.1.57.63246 &amp;gt; 10.40.222.240.443 ).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;???? Very confusing. This is a Layer 2 switch between them, it's the only device between them, the Firewall is only routing the packets.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here's the thing, when connecting wired cable to the DLink switch on a switchport on Vlan 5(Guest), they pull a Guest DHCP address no problem and &lt;BR /&gt;route out to the internet with no problems. Pull their hard wire cable out, connect them to Guest Wireless, and their Layer 3 IP traffic gets &lt;BR /&gt;sent to the Access Point instead of routed out. Does this make any sense to anyone why L3 traffic is sent to the access point specifically?&lt;/P&gt;
&lt;P&gt;I'm going to attach some packet captures for the Guest network on the ASA, ASA config, and DLink switch config.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I do not have Cisco WAP150 screenshots because they are currently unreachable after attempting to set the Management VLAN and untagged VLAN to VLAN 5 and then 1 which cut me off from being able to manage it until I can get permission to go back out there.&lt;/P&gt;
&lt;P&gt;To Summarize, the VLAN 3(Inside/Office) and VLAN 5(Guest) are configured on the Access points and broadcasting. VLAN 3 works fine with no issues, but VLAN Guest tries to route TCP/Web Traffic to Access Point instead of to the internet destinations.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Attached files:&lt;/P&gt;
&lt;P&gt;ASA Configuration.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASDM Capture log showing the "No forward" issue due to the basic license of the ASA 5505 that prohibits guest and inside from communicating.&lt;/P&gt;
&lt;P&gt;ASA Capture packet log (Note: We have several WAP150s we were going to cluster together. This log shows two: 10.40.222.240 and 10.40.222.242. If the guest connects and associates with the .240, it sends all its web traffic to the 240. If it associates with the 242, it sends all its web traffic/TCP traffic to the .242 AP.) Also, we plugged in a generic netgear Access point at 10.200.1.2 that connects to the Guest wireless VLAN and wireless clients send traffic fine from it. So you'll see that traffic routing out successfully with 10.200.1.2 on the internet.&lt;/P&gt;
&lt;P&gt;Screen shots of DLink config (Just for reference. Guest port is plugged into Port 23, Access Points were plugged into Port 1 and Port 2)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Let me know if I can explain anything better or if anything sparks any lightbulbs. &amp;nbsp; . &amp;nbsp;Godspeed &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 12:43:09 GMT</pubDate>
    <dc:creator>Mike Bowers</dc:creator>
    <dc:date>2021-07-05T12:43:09Z</dc:date>
    <item>
      <title>Seemingly Simple Wireless Setup, confusing TAC also. 3 devices: WAP150 + DLink switch + ASA Firewall.</title>
      <link>https://community.cisco.com/t5/wireless/seemingly-simple-wireless-setup-confusing-tac-also-3-devices/m-p/2953953#M82464</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We're having a weird issue and wondering if someone can identify what's wrong. We've opened a TAC case with Small Business and after many hours &lt;BR /&gt;and tests we're still confused. It is a very basic set up but it appears like users in the WAP150 Guest network are sending all of their TCP &lt;BR /&gt;traffic to the Access point instead of routing it out to the internet. The BIG question noone has been able to answer: Why are the Guest wireless &lt;BR /&gt;users trying to send all TCP traffic on Layer 3 to the AP?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Topology:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;[ASA 5505 (Basic License) ] --------- [DLink DGS-1100-24P Switch] ---------[Cisco Wireless AP 150] ------ [Guest User connecting from computer or &lt;BR /&gt;cell phone]&lt;/P&gt;
&lt;P&gt;Here are the devices and info:&lt;/P&gt;
&lt;P&gt;ASA 5505:&lt;/P&gt;
&lt;P&gt;VLAN 1 - Inside&lt;/P&gt;
&lt;P&gt;VLAN 2 - Outside (Since The ASA 5505 has a basic license and can't do vlans, we have ethernet port 7 plugged into a port in the DLink switch for &lt;BR /&gt;only guest traffic that works for all Guest users but Guest Wireless users. We have ethernet port 1 plugged in for just Inside users connecting &lt;BR /&gt;to Office traffic.&lt;/P&gt;
&lt;P&gt;VLAN 5 - GuestWireless&lt;/P&gt;
&lt;P&gt;DHCP being supplied by ASA 5505&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;DLink DGS-1100-24P Switch&lt;/P&gt;
&lt;P&gt;Layer 2 Switch with VLANs 3(Office) and 5(Guest).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Cisco WAP150&lt;/P&gt;
&lt;P&gt;VLANs 3(Inside) and 5(Guest)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here is some quick information:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When trunking the Cisco WAP150(I've tried trunk port and Hybrid port for the WAP150 to connect to the DLink switch), the Office VLAN 3 works fine &lt;BR /&gt;and users route out with no issues. When trying to connect to the Guest. Guest users connect to Guest wireless, and can PULL a DHCP address from &lt;BR /&gt;the ASA in the proper VLAN(Correct Default Gateway,DNS, etc everything correct), AND can send DNS traffic out to the internet and resolve, BUT &lt;BR /&gt;web and TCP traffic is directed to the WAP150's IP address which is located in the Inside network. The ASA 5505 at this point says "No, we can't &lt;BR /&gt;do this because of of the no forward command between Guest and Inside networks due to license constraints of the basic license". The massive &lt;BR /&gt;question is, when someone connects to Guest Wireless and acceses a webpage on the internet, the log capture is showing the Guest users IP &lt;BR /&gt;(10.200.1.57, for example) going to the Access Points IP(10.40.222.240) with the traffic instead of routing it out to the internet (i.e logs show &lt;BR /&gt;many packets like 10.200.1.57.63246 &amp;gt; 10.40.222.240.443 ).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;???? Very confusing. This is a Layer 2 switch between them, it's the only device between them, the Firewall is only routing the packets.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here's the thing, when connecting wired cable to the DLink switch on a switchport on Vlan 5(Guest), they pull a Guest DHCP address no problem and &lt;BR /&gt;route out to the internet with no problems. Pull their hard wire cable out, connect them to Guest Wireless, and their Layer 3 IP traffic gets &lt;BR /&gt;sent to the Access Point instead of routed out. Does this make any sense to anyone why L3 traffic is sent to the access point specifically?&lt;/P&gt;
&lt;P&gt;I'm going to attach some packet captures for the Guest network on the ASA, ASA config, and DLink switch config.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I do not have Cisco WAP150 screenshots because they are currently unreachable after attempting to set the Management VLAN and untagged VLAN to VLAN 5 and then 1 which cut me off from being able to manage it until I can get permission to go back out there.&lt;/P&gt;
&lt;P&gt;To Summarize, the VLAN 3(Inside/Office) and VLAN 5(Guest) are configured on the Access points and broadcasting. VLAN 3 works fine with no issues, but VLAN Guest tries to route TCP/Web Traffic to Access Point instead of to the internet destinations.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Attached files:&lt;/P&gt;
&lt;P&gt;ASA Configuration.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASDM Capture log showing the "No forward" issue due to the basic license of the ASA 5505 that prohibits guest and inside from communicating.&lt;/P&gt;
&lt;P&gt;ASA Capture packet log (Note: We have several WAP150s we were going to cluster together. This log shows two: 10.40.222.240 and 10.40.222.242. If the guest connects and associates with the .240, it sends all its web traffic to the 240. If it associates with the 242, it sends all its web traffic/TCP traffic to the .242 AP.) Also, we plugged in a generic netgear Access point at 10.200.1.2 that connects to the Guest wireless VLAN and wireless clients send traffic fine from it. So you'll see that traffic routing out successfully with 10.200.1.2 on the internet.&lt;/P&gt;
&lt;P&gt;Screen shots of DLink config (Just for reference. Guest port is plugged into Port 23, Access Points were plugged into Port 1 and Port 2)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Let me know if I can explain anything better or if anything sparks any lightbulbs. &amp;nbsp; . &amp;nbsp;Godspeed &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 12:43:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/seemingly-simple-wireless-setup-confusing-tac-also-3-devices/m-p/2953953#M82464</guid>
      <dc:creator>Mike Bowers</dc:creator>
      <dc:date>2021-07-05T12:43:09Z</dc:date>
    </item>
  </channel>
</rss>

