cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2142
Views
0
Helpful
15
Replies

Clients to cisco 819 does not assign ip

xcelera
Level 1
Level 1

Hi, im new to cisco but im starting to learning myself.

I configure an Cisco 819 LTE Router witch DHCP and it worked good, after some days i configured my cisco switch with wlan tags to my AP.

After that i cant assign an ip when i connect my computer, to the router or the switch automatic,

if i run ipconfig /release and renew on the computer it will be assigned ad i should,

but in the beggining when i didnt changed som settings on the router everything worked perfectly, i have also tried to factory reset the switch without success.

 

Using 2908 out of 262136 bytes
!
! Last configuration change at 18:51:47 GMT Tue Sep 19 2017
!
version 15.4
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
no service password-recovery
!
hostname Router
!
boot-start-marker
boot-end-marker
!
!
enable secret 
!
no aaa new-model
clock timezone GMT 1 0
!
!
!
!
!
!
!
!
!
!


!
ip dhcp excluded-address 10.0.0.1
!
ip dhcp pool test
import all
network 10.0.0.0 255.255.255.0
dns-server 8.8.8.8 8.8.4.4
default-router 10.0.0.1
!
!
!
ip name-server 8.8.8.8
ip name-server 8.8.4.4
ip cef
no ipv6 cef
!
!
!
!
!
multilink bundle-name authenticated
!
!
chat-script lte "" "AT!CALL" TIMEOUT 20 "OK"
!
!
!
!
!
!
cts logging verbose
license udi pid C819G-4G-GA-K9 sn
!
!

!
!
!
!
!
controller Cellular 0
lte modem link-recovery rssi onset-threshold -110
lte modem link-recovery monitor-timer 20
lte modem link-recovery wait-timer 10
lte modem link-recovery debounce-count 6
!
vlan 1000
name RS10
!
!
!
!
!
!
!
!
!
!
!
!
interface Cellular0
ip address negotiated
ip nat outside
ip virtual-reassembly in
encapsulation slip
dialer in-band
dialer string lte
dialer-group 1
!
interface FastEthernet0
no ip address
!
interface FastEthernet1
no ip address
!
interface FastEthernet2
no ip address
!
interface FastEthernet3
no ip address
!
interface GigabitEthernet0
no ip address
shutdown
duplex auto
speed auto
!
interface Serial0
no ip address
shutdown
clock rate 2000000
!
interface Vlan1
ip address 10.0.0.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
!
ip forward-protocol nd
ip http server
ip http port 8080
no ip http secure-server
!
!
ip nat inside source list NAT interface Cellular0 overload
ip nat inside source static tcp 10.0.0.8 80 interface Cellular0 80
ip nat inside source static udp 10.0.0.8 80 interface Cellular0 80
ip nat inside source static tcp 10.0.0.8 3389 interface Cellular0 3389
ip nat inside source static tcp 10.0.0.8 8081 interface Cellular0 8081
ip nat inside source static udp 10.0.0.8 3389 interface Cellular0 3389
ip route 0.0.0.0 0.0.0.0 Cellular0
!
ip access-list extended NAT
permit ip 10.0.0.0 0.0.0.255 any
!
dialer-list 1 protocol ip permit
!
!
control-plane
!
!
mgcp behavior rsip-range tgcp-only
mgcp behavior comedia-role none
mgcp behavior comedia-check-media-src disable
mgcp behavior comedia-sdp-force disable
!
mgcp profile default
!
!
!
!
!
!
!
line con 0
no modem enable
line aux 0
line 2
no activation-character
no exec
transport preferred none
transport input all
stopbits 1
line 3
script dialer lte
no exec
rxspeed 100000000
txspeed 50000000
line vty 0 4
login
transport input none
!
scheduler allocate 20000 1000
ntp server ntp.lth.se
!
!
!
end

1 Accepted Solution

Accepted Solutions

One question the ports in the switch also got 192 adresses, isnt port 8 "isolated" enough?
--> Run 'show vlan brief' on the switch and check whether the switch ports connected to the camera are members of vlan 1. If so, change the vlan to a different vlan (eg. vlan 10) and test again.

interface GigabitEthernet0/1
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/2
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/3
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/4
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/5
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/6
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/7
switchport mode trunk
switchport nonegotiate
mls qos trust cos
macro description cisco-wireless
auto qos trust
spanning-tree portfast trunk
spanning-tree bpduguard enable
!
interface GigabitEthernet0/8
switchport trunk native vlan 5
switchport mode trunk
macro description cisco-switch
auto qos trust
spanning-tree portfast trunk
spanning-tree link-type point-to-point
!
interface GigabitEthernet0/9
no keepalive
!
interface GigabitEthernet0/10
switchport mode trunk
macro description cisco-switch
auto qos trust
spanning-tree portfast trunk
spanning-tree link-type point-to-point
!
interface GigabitEthernet0/11
!
interface GigabitEthernet0/12
!
interface Vlan1
ip address 10.0.0.10 255.255.255.0
!

Please make the appropriate changes on the 819 also and update us.

HTH,
Meheretab
HTH,
Meheretab

View solution in original post

15 Replies 15

Hi,
If you are getting IP address from the IP Pool on the router: 10.0.0.0/24 when you run ipconfig /release and ipconfig /renew on your computer, it indicates that the dhcp server in the router is working properly.
Did you try rebooting your computer? What switch model are you using?

HTH
Meheretab
HTH,
Meheretab

it does not help after reboot, and i have tried with several computers, and my cell phone wont get any ip at all, im using catalyst 2960-cx switch.

 

 

Edit: i tried to disable one of the port where i get an vlan to my other ssid on my ap and sudenly everything works.

 

Now i know the problem but how to fix it

i have to wan connections connected to 1 and 2 on the switch wan 1 is ADSL line and wan 2 is LTE fro my 819 router. and in port 3 i have an cisco AP and with dual SSID one is on vlan 1 and the other one is on vlan 2 so the problem is when both ports are enabled it is a conflict betwen te DHCP servers, hos is that possible when port 1 is on vlan 1 and port 2 is vlan 2

Can i run DHCP on vlan1 192.168.0.0 and vlan2 10.0.0.0?

 

Hello,

configure 'spanning-tree portfast' on any of the access ports where you have devices connected (on the 2960x as well as on the FastEthernet ports on the router...

Can i run DHCP on vlan1 192.168.0.0 and vlan2 10.0.0.0?

--> Yes, you can run multiple DHCP Servers. However, remember to configure the correct vlan information on the ports. Also, remember if you want to pass more than one vlan, you need to configure the port as 'trunk port'.

On the access ports (ports connected to a device):

 switchport access vlan x (where x is vlan number)

 switcport mode access

  spanning-tree portfast

 

On the trunk port (port connecting the 2960cx and the 819 -- if it carries more than 1 vlan):

 switchport mode trunk

 

HTH,

Meheretab

 

HTH,
Meheretab

Its still th same problem, when im connecting with my cellphone to 10.0.0.0 ssid the phone gets 192.168.1.6 adress :/

Please post your configurations for both 819 and 2960cx.

Thanks,
Meheretab
HTH,
Meheretab

Here are the cfgs, in this case port 8 and 10 in 2960 is the "wan ports" and in 819 Fastethernet0 is to 2960

 

2960-CX

primar#show conf
Using 2269 out of 524288 bytes
!
! Last configuration change at 00:06:01 UTC Wed Sep 20 2017
! NVRAM config last updated at 00:06:01 UTC Wed Sep 20 2017
!
version 15.2
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
service sequence-numbers
!
hostname primar
!
boot-start-marker
boot-end-marker
!
enable s
!
no aaa new-model
system mtu routing 1500
ip routing
!
!
!
!
!
!
!
udld aggressive

!
mls qos map cos-dscp 0 8 16 24 32 46 46 56
!
crypto pki trustpoint TP-self-signed-3528803072
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-3528803072
revocation-check none
rsakeypair TP-self-signed-3528803072
!
!
crypto pki certificate chain TP-self-signed-3528803072
certificate self-signed 01 nvram:IOS-Self-Sig#1.cer
!
spanning-tree mode rapid-pvst
spanning-tree loopguard default
spanning-tree extend system-id
auto qos srnd4
errdisable recovery cause link-flap
errdisable recovery interval 60
!
!
!
!
vlan internal allocation policy ascending
!
!
!
!
!
!
!
!
!
!
macro global description cisco-global
!
interface GigabitEthernet0/1
!
interface GigabitEthernet0/2
!
interface GigabitEthernet0/3
!
interface GigabitEthernet0/4
!
interface GigabitEthernet0/5
!
interface GigabitEthernet0/6
!
interface GigabitEthernet0/7
switchport mode trunk
switchport nonegotiate
mls qos trust cos
macro description cisco-wireless
auto qos trust
spanning-tree portfast trunk
spanning-tree bpduguard enable
!
interface GigabitEthernet0/8
switchport trunk native vlan 5
switchport mode trunk
macro description cisco-switch
auto qos trust
spanning-tree portfast trunk
spanning-tree link-type point-to-point
!
interface GigabitEthernet0/9
no keepalive
!
interface GigabitEthernet0/10
switchport mode trunk
macro description cisco-switch
auto qos trust
spanning-tree portfast trunk
spanning-tree link-type point-to-point
!
interface GigabitEthernet0/11
!
interface GigabitEthernet0/12
!
interface Vlan1
ip address 10.0.0.10 255.255.255.0
!
ip default-gateway 10.0.0.1
ip forward-protocol nd
ip http server
ip http secure-server
!
!
!
!
!
line con 0
line vty 0 4
password 
login
line vty 5 15
password 4U4All76e
login
!
end

 

 

819 Router

 

Using 2998 out of 262136 bytes
!
! Last configuration change at 22:34:46 GMT Tue Sep 19 2017
!
version 15.4
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
no service password-recovery
!
hostname Router
!
boot-start-marker
boot-end-marker
!
!
enable secret 5 $1$coYU$jiey1ggaeUJQ74Rwk0s7I0
!
no aaa new-model
clock timezone GMT 1 0
!
!
!
!
!
!
!
!
!
!


!
ip dhcp excluded-address 10.0.0.1
!
ip dhcp pool test
import all
network 10.0.0.0 255.255.255.0
dns-server 8.8.8.8 8.8.4.4
default-router 10.0.0.1
!
!
!
ip name-server 8.8.8.8
ip name-server 8.8.4.4
ip cef
no ipv6 cef
!
!
!
!
!
multilink bundle-name authenticated
!
!
chat-script lte "" "AT!CALL" TIMEOUT 20 "OK"
!
!
!
!
!
!
cts logging verbose
license udi pid C819G-4G-GA-K9 sn FCZ2039E1SS
!
!
vtp mode transparent
username admin privilege 15 secret 5 $1$U9bL$YxYfCHlqF9jvq0GtbSACj/
username jacob privilege 15 secret 5 $1$qjVD$00m.9wojqm2ioaL8PxKyv0
!
!
!
!
!
controller Cellular 0
lte modem link-recovery rssi onset-threshold -110
lte modem link-recovery monitor-timer 20
lte modem link-recovery wait-timer 10
lte modem link-recovery debounce-count 6
!
vlan 1000
name RS10
!
!
!
!
!
!
!
!
!
!
!
!
interface Cellular0
ip address negotiated
ip nat outside
ip virtual-reassembly in
encapsulation slip
dialer in-band
dialer string lte
dialer-group 1
!
interface FastEthernet0
switchport trunk allowed vlan 1,1002-1005
switchport mode trunk
no ip address
spanning-tree portfast
!
interface FastEthernet1
no ip address
!
interface FastEthernet2
no ip address
!
interface FastEthernet3
no ip address
!
interface GigabitEthernet0
no ip address
shutdown
duplex auto
speed auto
!
interface Serial0
no ip address
shutdown
clock rate 2000000
!
interface Vlan1
ip address 10.0.0.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
!
ip forward-protocol nd
ip http server
ip http port 8080
no ip http secure-server
!
!
ip nat inside source list NAT interface Cellular0 overload
ip nat inside source static tcp 10.0.0.8 80 interface Cellular0 80
ip nat inside source static udp 10.0.0.8 80 interface Cellular0 80
ip nat inside source static tcp 10.0.0.8 3389 interface Cellular0 3389
ip nat inside source static tcp 10.0.0.8 8081 interface Cellular0 8081
ip nat inside source static udp 10.0.0.8 3389 interface Cellular0 3389
ip route 0.0.0.0 0.0.0.0 Cellular0
!
ip access-list extended NAT
permit ip 10.0.0.0 0.0.0.255 any
!
dialer-list 1 protocol ip permit
!
!
control-plane
!
!
mgcp behavior rsip-range tgcp-only
mgcp behavior comedia-role none
mgcp behavior comedia-check-media-src disable
mgcp behavior comedia-sdp-force disable
!
mgcp profile default
!
!
!
!
!
!
!
line con 0
no modem enable
line aux 0
line 2
no activation-character
no exec
transport preferred none
transport input all
stopbits 1
line 3
script dialer lte
no exec
rxspeed 100000000
txspeed 50000000
line vty 0 4
login
transport input none
!
scheduler allocate 20000 1000
ntp server ntp.lth.se
!
!
!
end

I see what you are trying to do now.

Both WAN devices are listening on UDP port 67 for dhcp requests. In your case, one of the WAN devices connected to Switchport 8 on Cisco 2960 is responding for all dhcp requests. It seems to me that the AP is not configured correctly.
Please look at the following sample config: https://supportforums.cisco.com/t5/wireless-mobility-documents/multiple-ssid-with-multiple-vlans-configuration-example-on-cisco/ta-p/3118056

HTH,
Meheretab
HTH,
Meheretab

What Do you mean that only wan device on port 8 is listening for dhcp
request? Why isnt port 10 doing The same? why is port 8 answering for all DHCP requests

I got some ip cameras on port 3
and none of them is asigning any ip more, they should get an 10.0.0.0
adress, and I have followed that Accesspoint guide in and out,

ssid for vlan 5 is working perfectly, but ssid for vlan 1 is getting 192 ip first, like its some kind of conflict, if i relase and renew ip in the computer it works.

 

im sorry to be an such pain in the ass but i use LTE for my ip cameras in my summerhouse in italy and dsl for normal surfing, but with abbility to use lte wifi because dsl line allways go down in this country.

Whst Do you mean that only wan device on port 8 is listening for dhcp request? Why isnt port 10 doing The same?
--> I am not saying the DHCP Server on 819 is not listening. According to the information you provided earlier it is actually listening (as your devices got IP address from 10.0.0.0/24 network when you disable/ disconnect the other WAN connection). However, when both devices are connected the secondary WAN device is issuing IP addresses (192.168.1.0/24 block). As a result, I suspected that there might be mis-configuration on the AP side.
Could you also post the AP's config as well?

Thanks,
Meheretab
HTH,
Meheretab

ssid for vlan 5 is working perfectly, but ssid for vlan 1 is getting 192 ip first, like its some kind of conflict, if i relase and renew ip in the computer it works.

And the same problem is with cables connected to the switch

 

im sorry to be an such pain in the ass but i use LTE for my ip cameras in my summerhouse in italy and dsl for normal surfing, but with abbility to use lte wifi because dsl line allways go down in this country. and i would love to use LTE all the time but we dont got flat here 

Cisco Aironet 1142

 

!
! Last configuration change at 22:00:50 +0200 Tue Sep 19 2017 by cisco
! NVRAM config last updated at 22:00:50 +0200 Tue Sep 19 2017 by cisco
!
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname ap
!
logging rate-limit console 9
enable secret 5 $1$J6m
!
aaa new-model
!
!
!
aaa session-id common
clock timezone +0200 2
ip name-server 8.8.8.8
ip name-server 8.8.4.4
!
!
dot11 syslog
dot11 vlan-name Primar vlan 1
dot11 vlan-name test vlan 5
!
dot11 ssid casadelsale
   vlan 5
   authentication open 
   authentication key-management wpa version 2
   mbssid guest-mode
   wpa-psk ascii 7 13081E1E010D55737F74
!
!
!
username Cisco privilege 15 secret 5 $1$21QK$W2XSx5HjaEJGGuCG/t4JR1
!
!
bridge irb
!
!
interface Dot11Radio0
 no ip address
 no ip route-cache
 !
 encryption mode ciphers aes-ccm 
 !
 encryption vlan 5 mode ciphers aes-ccm 
 !
 ssid casadelsale
 !
 antenna gain 0
 mbssid
 station-role root
!
interface Dot11Radio0.1
 encapsulation dot1Q 1 native
 no ip route-cache
 bridge-group 1
 bridge-group 1 subscriber-loop-control
 bridge-group 1 block-unknown-source
 no bridge-group 1 source-learning
 no bridge-group 1 unicast-flooding
 bridge-group 1 spanning-disabled
!
interface Dot11Radio0.5
 encapsulation dot1Q 5
 no ip route-cache
 bridge-group 5
 bridge-group 5 subscriber-loop-control
 bridge-group 5 block-unknown-source
 no bridge-group 5 source-learning
 no bridge-group 5 unicast-flooding
 bridge-group 5 spanning-disabled
!
interface Dot11Radio1
 no ip address
 no ip route-cache
 !
 encryption mode ciphers aes-ccm 
 !
 encryption vlan 5 mode ciphers aes-ccm 
 !
 ssid casadelsale
 !
 antenna gain 0
 no dfs band block
 mbssid
 channel dfs
 station-role root
 bridge-group 1
 bridge-group 1 subscriber-loop-control
 bridge-group 1 block-unknown-source
 no bridge-group 1 source-learning
 no bridge-group 1 unicast-flooding
 bridge-group 1 spanning-disabled
!
interface Dot11Radio1.5
 encapsulation dot1Q 5
 no ip route-cache
 bridge-group 5
 bridge-group 5 subscriber-loop-control
 bridge-group 5 block-unknown-source
 no bridge-group 5 source-learning
 no bridge-group 5 unicast-flooding
 bridge-group 5 spanning-disabled
!
interface GigabitEthernet0
 no ip address
 no ip route-cache
 duplex auto
 speed auto
 no keepalive
!
interface GigabitEthernet0.1
 encapsulation dot1Q 1 native
 no ip route-cache
 bridge-group 1
 no bridge-group 1 source-learning
 bridge-group 1 spanning-disabled
!
interface GigabitEthernet0.5
 encapsulation dot1Q 5
 no ip route-cache
 bridge-group 5
 no bridge-group 5 source-learning
 bridge-group 5 spanning-disabled
!
interface BVI1
 ip address 10.0.0.20 255.255.255.0
 no ip route-cache
!
ip default-gateway 10.0.0.1
ip http server
no ip http secure-server
ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
bridge 1 route ip
!
!
!
line con 0
line vty 0 4
 transport input all
!
sntp server 130.235.20.67
sntp broadcast client
end

 

Ido not see the SSID for vlan1. Did I miss it?

I see the SSID for vlan5:
dot11 ssid casadelsale
vlan 5
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 xxxxxxxxxxxx
!
HTH,
Meheretab

I have removed it and dd it so many times, but i add it again and here it is. One question the ports in the switch also got 192 adresses, isnt port 8 "isolated" enough?

 

!
dot11 syslog
dot11 vlan-name Primar vlan 1
dot11 vlan-name test vlan 5
!
dot11 ssid Netec.se
   vlan 1
   authentication open 
   authentication key-management wpa version 2
   mobility network-id 1
   wpa-psk ascii 7 0448020B002F5F4F100A
!
dot11 ssid casadelsale
   vlan 5
   authentication open 
   authentication key-management wpa version 2
   mbssid guest-mode
   mobility network-id 5
   wpa-psk ascii 7 120A0C1A1D051F053338

One question the ports in the switch also got 192 adresses, isnt port 8 "isolated" enough?
--> Run 'show vlan brief' on the switch and check whether the switch ports connected to the camera are members of vlan 1. If so, change the vlan to a different vlan (eg. vlan 10) and test again.

interface GigabitEthernet0/1
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/2
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/3
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/4
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/5
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/6
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/7
switchport mode trunk
switchport nonegotiate
mls qos trust cos
macro description cisco-wireless
auto qos trust
spanning-tree portfast trunk
spanning-tree bpduguard enable
!
interface GigabitEthernet0/8
switchport trunk native vlan 5
switchport mode trunk
macro description cisco-switch
auto qos trust
spanning-tree portfast trunk
spanning-tree link-type point-to-point
!
interface GigabitEthernet0/9
no keepalive
!
interface GigabitEthernet0/10
switchport mode trunk
macro description cisco-switch
auto qos trust
spanning-tree portfast trunk
spanning-tree link-type point-to-point
!
interface GigabitEthernet0/11
!
interface GigabitEthernet0/12
!
interface Vlan1
ip address 10.0.0.10 255.255.255.0
!

Please make the appropriate changes on the 819 also and update us.

HTH,
Meheretab
HTH,
Meheretab
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card