10-03-2021 11:24 PM - edited 10-04-2021 06:57 AM
Hi,
We are facing an issue where all guest clients are taking too long time (2 or 3 minutes) to load the web portal, or simply fail to load it in the first try. Then after the first try, everything works fine if clients disconnect and connect againt, and they are able to load the web portal pretty fast. When we detect the issue in the first try, I cannot see any traffic reaching the ISE, and if I try to ping the client from the local router, I cannot reach the client, despite of the client getting an IP address from DHCP server (which is the local router).
Are you aware of a bug or some parameter which could bring this issue?
The Guest WLAN is configured in Local Switching, and redirect ACL is correctly configured according to the lastest section in this guide:
Thanks.
EDIT: Adding more information:
C9800-CL - IOS: 7.3.3
AP1832I
Comparing the WLC debugs, the output is the same when it fails, compate to when it works fine.
Currently checking the issue with the TAC but without success.
10-04-2021 06:56 AM
get a packet capture (radioactive trace) on a client to see what's not working.
10-04-2021 07:00 AM
I have just edited the original message. Radioactive Trace does not show anything which could explain the issue. Both traces (when it works and when it does not) are identical, and the last message is: L3 Authentication initiated. CWA.
10-04-2021 07:53 AM
Have you tried a packet capture on the client?
10-04-2021 08:01 AM - edited 10-04-2021 08:07 AM
Yes, I got captures with wireshark. The client got an IP, and was trying to send traffic to the right default gateway's MAC address but without success. Then everything started working fine after some time for some reason (same happens with any device we try to connect to the guest network for first time, or if we connect the device again after some hours disconnected). I have been thinking that it is maybe something related to the LAN switches, but I really cannot find any valid reasoning about why this is happening. Maybe something related to STP, but it would be really weird that some ports would go to block state during some time, but this is something I am going to check in the next tests.
We do not have any kind of port security, so STP is the only thing which could bring this issue, but it would be really weird though. Thanks for answering.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: