cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1344
Views
5
Helpful
6
Replies

Client not getting DHCP IP on WLC9800

eeebbunee
Level 1
Level 1

Hello Professionals,

Client can't get DHCP IP from DHCP server through the WLC9800, and here is my network.
my.PNG

 - When Client connects to SSID:SVI-60, able to get DHCP IP from Core switch. : works!

 - When Client connects to SSID:SVR-100, Not get DHCP IP from DHCP Server(Firepower).

WLANs, SVI, setting relay IP configuration in WLC9800 are all same, but I couldn't get IP address from firepower.
When I google it, it looks like bug#CSCvr86538. (https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvr86358)

The solution of this bug is :
 - Delete SVI IP address and Make L2 bridging

What does that mean 'making L2 bridge'. Does it mean that I put no ip address for SVI?

Current score is no luck..

DHCP Relay Statistics
---------------------

DHCP Server IP : 192.168.100.1

Message Count
--------------------------
DHCPDISCOVER : 188
BOOTP FORWARD : 188
BOOTP REPLY : 0
DHCPOFFER : 0
DHCPREQUEST : 0
DHCPACK : 0
DHCPNAK : 0
DHCPDECLINE : 0
DHCPRELEASE : 0
DHCPINFORM : 0

Tx/Rx Time :
------------
LastTxTime : 14:30:05
LastRxTime : 18:00:00

Should I enable one physical port and provide access vlan 100 (and match with switch port to be access vlan 100) seperately?
or even if I configure new physical port, is it still communicating with wireless-mgmt VLAN50?

 

Thank you so much for providing your time.

 

1 Accepted Solution

Accepted Solutions

SVI-60 only need to be on your core switch. 

On your 9800, you need to have VLAN 60 (just L2 vlan defined on 9800) & trunk to your core switch. No SVI-60 on 9800

Is that the configuration you got ?

HTH
Rasika
*** Pls rate all useful responses ***

View solution in original post

6 Replies 6

You only require management SVI (vlan 50) on your 9800 controller. Remove all other client SVIs from 9800 & check it.

HTH
Rasika
*** Pls rate all useful responses ***

Hello Sir,

When I just remove all SVIs except managemet (VLAN50), I failed to access SVI-60.
Is there any steps that I deeply look into it?

Thank you.

SVI-60 only need to be on your core switch. 

On your 9800, you need to have VLAN 60 (just L2 vlan defined on 9800) & trunk to your core switch. No SVI-60 on 9800

Is that the configuration you got ?

HTH
Rasika
*** Pls rate all useful responses ***

Hello Rasika,

Thank you so much!!! Client finally got the DHCP IP from the firewall for Guest network.

I made one more Ethernet port for guest VLAN and made L2, then it works.

I appreciate your comment..!

 

 

marce1000
VIP
VIP

 

 - Look at best practices for DHCP setup(s) here : https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/guide-c07-743627.html#DHCPbridgingandDHCPrelay

   Have a checkup of the  WLC9800 configuration too ; with the CLI command show tech wireless ; feed the output into :
                                https://cway.cisco.com/wirele
ss-config-analyzer/
    This procedure is strongly adviced

M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Rich R
VIP
VIP

And refer to the 9800 Best Practice guide - link below.

As Rasika has said already - there is no need to configure SVI on the 9800 for client VLANs.

You've also not mentioned what version of IOS-XE you're using - refer to TAC recommended releases (below) - currently 17.9.4 (which also fixes the bug you referenced which is quite old).

Review Cisco Networking for a $25 gift card