cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1468
Views
3
Helpful
9
Replies

Adding new SSID & VLAN to Catalyst 9800CL Not Working

TerenceLockette
Level 1
Level 1

Hello,

I'm setting up a Catalyst 9800CL WLC and I have it working as needed with 2 SSIDs.  I'm adding a 3rd SSID just as I did the others along with a new VLAN (no SVIs on the 9800 as my ASA firewall is acting as the gateway and DHCP relay server for all networks requiring DHCP).  However, I am unable to obtain DHCP for this new SSID but can obtain it for the other 2 WLANs.  To add, I currently have a Meraki MR52 that serves the 3 VLANs I'm setting up on the 9800 and clients can get DHCP no issues from the Meraki.  The difference is that I'm using iPSK on the Meraki whereas I'm not on the 9800 because I'm not using a RADIUS server for the 9800.  So I know my firewall and networking is intact and functioning as it's supposed to.  The only thing I can think of is it has to be the 9800 WLC which is running Cupertino 17.9.3.  I've checked the release notes as well and couldn't find anything that resembles the current behavior.  Any thoughts as I can share any additional information you may need.

Thanks!

1 Accepted Solution

Accepted Solutions

marce1000
VIP
VIP

 

 - Have a checkup review of your 9800CL WLC  configuration with the CLI command show tech wireless ; feed the output into 
                                                    https://cway.cisco.com/wireless-config-analyzer/

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

View solution in original post

9 Replies 9

Hi

 Which authentication method are you using on the new ssid?

Hello Flavio,

All 3 SSIDs are using WPA2-Personal AES with PSK.  Nothing fancy such as Dot1X or AAA authentication.

Right. Let me ask you a few question and, with that ,maybe I can help you check any blind spot you may left behind.

The SSID is Local switching or Central switching? Same question for DHCP

Is this  new vlan or existing vlan?

You said the WLC is only layer2 right? no SVI, so the ASA is the layer3 ?

If you set a static IP address on one client, does it can ping the gateway?

Flavio,

I responded to your questions via email and thought they'd post here but I guess it didn't.  Here are my responses to your questions. Again, I really appreciate your responses on this:

Central switching and central DHCP for all SSIDs; no flex profile assigned to the site tag as the AP is operating in local mode.

The VLAN is an existing VLAN on my network and has been added to the 9800 WLC.

The WLC is layer 2 only with the ASA being layer 3 so no SVIs on the 9800; only the layer 2 VLAN IDs have been added.

If I assign a static IP or receive an IP via DHCP from the wired (switch) or wireless network (Meraki MR52), I can ping the gateway from any of those VLANs.

Here's another bit of detail I forgot to mention.  Although I can get DHCP for the 2 SSIDs on the 9800, I can't ping the DHCP server directly from the 9800; although there's a default route back towards my firewall (this could be an issue with ICMP not being allowed, however).

"Here's another bit of detail I forgot to mention. Although I can get DHCP for the 2 SSIDs on the 9800, I can't ping the DHCP server directly from the 9800; although there's a default route back towards my firewall (this could be an issue with ICMP not being allowed, however)."

  yeah, it could be the firewall blocking icmp. 

Does the WLC have trunk with firewall, right?  The vlan was added to trunk?

I know those are basic questions but sometimes small details are left behind.  After all, if you have 2 ssids working, we must consider that the overall configuration must be fine.

One last thing I would recomment is look on the logs while trying to connect to the network. The radioactive logs must show something interesting.

marce1000
VIP
VIP

 

 - Have a checkup review of your 9800CL WLC  configuration with the CLI command show tech wireless ; feed the output into 
                                                    https://cway.cisco.com/wireless-config-analyzer/

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Thank you!  I will give this a try and report any findings.

It doesn't make any sense to me but using this analyzer helped tremendously!  So, as I stated in my original post, I can get DHCP for the 2 existing SSIDs no problem but wasn't getting it for the 3rd (and final) SSID.  After running the analyzer, I had 1 error, 13 warnings, and 5 notices.  The error was stated as follows:

 

TerenceLockette_0-1688342380423.png

However, I knew I didn't have to add SVIs on the 9800 so what I did was check the Policy profile and removed the DHCP Server IP Address value shown here:

TerenceLockette_1-1688342511609.png

Once I removed this option, I tested the 3rd SSID and was able to get an address via DHCP immediately.  I would've never figured this seeing that the other two policy profiles for the other SSIDs also had this configured (but is now removed).  I have confirmed that I can associate to the SSIDs and receive IP info for the appropriate VLANs.  Thanks again for everyone's help on this and I'll be sure to bookmark that analyzer URL!

 

Terence Lockette

 

         @TerenceLockette             >....and I'll be sure to bookmark that analyzer URL!
  It's indeed advisable to use WirelessAnalyzer on a regular basis , especially after configuration changes and also after upgrades for instance , 

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '
Review Cisco Networking for a $25 gift card