12-19-2023 02:02 AM
We are to migrate WLC from AireOS to 9800. but we are getting an issue on the delay the client is getting an IP.
The setup is WLC with dot1x authn and ISE posture.
the comparison is when using 9800, it takes 10seconds longer on the posture assessment and IP acquisition than using the aireos wlc. which is not acceptable with the client that's why we can't proceed with the migration.
12-19-2023 04:34 AM - edited 12-19-2023 04:42 AM
- Start with a checkup of the 9800 (current) configuration with the CLI command show tech wireless and feed the output into
Wireless Config Analyzer
- For DHCP client provisioning use these advices as being best practice(s) : https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/guide-c07-743627.html#DHCPbridgingandDHCPrelay
- Debug clients according to https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity (correctedx2) , you can have client debugs , so called RadioActive Traces , analyzed with : https://cway.cisco.com/tools/WirelessDebugAnalyzer/
- Monitor overall client behavior and or check for improvement with commands mentioned in : https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#anc5
M.
12-19-2023 05:40 AM
So in end the client auth or not?
Are you use dual dhcp subnet pool ?
MHM
12-19-2023 05:39 PM
yes,the client authenticates, we are using the same dhcp server for different subnets.
12-19-2023 07:22 AM
What version of IOS-XE are you using on the 9800?
Hint: refer to TAC recommended link below.
12-19-2023 05:40 PM
version is 17.9.4a
12-19-2023 05:41 PM
Ok that's a good start.
And have you done a radioactive trace on a client to understand what is causing that delay?
12-19-2023 10:24 PM
right now what we do is to connect the client in a different AP. result is its faster compared to the other AP. but question is, they have the same firmware version and model, same tags and profile so what may be the cause why it's longer to connect on the other AP?
12-19-2023 10:58 PM
not sure what to look exactly on teh RA trace regarding delay.
12-20-2023 01:46 AM
Then best to open a TAC case and let them work through it with you.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide