cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
504
Views
1
Helpful
4
Replies

Cisco 9800 Azure Hosted - Flex for Local VLANs

michaelbirrer
Level 1
Level 1

Hi There

I got a WLAN Controll 9800 hosted in Azure. At the on premise locations got different VLANs. For example: 900 for smartphones. so they are autheticated by PSK and it works fine. I got another office vlan 800 with 802.x1 -> Radius authentication (certificates).
On the local Firewall / Router of VLAN 800 on premise i got an dhcp server. But it looks like the clients (notebooks) arent able to get an IP Address, once they are authenticaed by the controller on Radius.
Anyone an idea, why Clients arent able to get an DHCP lease?

4 Replies 4

ammahend
VIP
VIP

does the notebook gets an IP when you put it in 900 vlan ? 

-hope this helps-

hi ammahend, thanks for the great response time!

The setup is as following:
- SUBNET (vlan 900): Guests... dhcp server on router. => All clients, wired connected OR wireless connected to WLAN_GUEST (vlan 900 via flex config):  DHCP Server provides an IP Address and clients are able to use network

- SUBNET (vlan 800): I see following traffic on Firewall from the client device. Seems not getting an IP. Also i see on management trace of Firewall (traffic from AP <> Controller) following
:4c:03:4f:5c:9f:a4 > ff:ff:ff:ff:ff:ff Null Unnumbered, xid, Flags [Command], length 42: 80 00

 

Strange is, that for around 30 min. i had seen 1812 radius traffic going to the NPS Server also in azure. But then, without reconfiguring anything, the controller stopped to send radius requests to server.

you are stating 2 problems, one is L2 another is L3.

DHCP (L3) will only work is 802.1X (L2) authentication has passed, so basically the problem is not DHCP its 802.1X authentication, is that correct ?

-hope this helps-

Rich R
VIP
VIP

I agree with @ammahend analysis of your problem.
DHCP process can only start after 802.1x authentication is complete.

- What version of software are you using?
- Have you run and analysed radioactive trace for one of those clients?

Review Cisco Networking for a $25 gift card