cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3314
Views
7
Helpful
25
Replies

Config between Cisco WC 5508 & 9800

Nenday
Level 1
Level 1

Hello Team, 

I'm moving from my old Cisco WC controller model 5508 to new 9800, Actually I finish everything with AP's and ISE and Radius as well, 

for the guest user we use Captive portal from ISE and special DHCP server (accessible only thraught the FW), so now I'm facing w small problem that from the main site I can get IP adress from the that DHCP server, but from distant site the guest user's didn't get IP adress, 

I check in the old conroller I found the DHCP realy is checked and also virtual interface is added with adress 1.1.1.1 so  when user's connect to guest network (from old WC always) they get an IP address, 

 

   Suffixe DNS propre à la connexion. . . : Guest-Network
   Description. . . . . . . . . . . . . . : Intel(R) Wi-Fi 6 AX201 160MHz
   Adresse physique . . . . . . . . . . . : 8C-XX-XX-XX-XX
   DHCP activé. . . . . . . . . . . . . . : Oui
   Configuration automatique activée. . . : Oui
   Adresse IPv6 de liaison locale. . . . .: fe80::
   Adresse IPv4. . . . . . . . . . . . . .: 192.2.1.134(préféré)
   Masque de sous-réseau. . . . . . . . . : 255.255.224.0
   Bail obtenu. . . . . . . . . . . . . . : 23 janvier 2024 13:04:38
   Bail expirant. . . . . . . . . . . . . : 23 janvier 2024 21:04:37
   Passerelle par défaut. . . . . . . . . : 192.2.0.1
   Serveur DHCP . . . . . . . . . . . . . : 1.1.1.1
   IAID DHCPv6 . . . . . . . . . . . : 176969034
   DUID de client DHCPv6. . . . . . . . : 0
   Serveurs DNS. . .  . . . . . . . . . . : 192.1.3.11
   NetBIOS sur Tcpip. . . . . . . . . . . : Activé


I don't know where I can align the configuration as the big difference between controllers, 

 

25 Replies 25

hi @Rich R 

thank you for your support, 

according my knowledge ye it's centrally switched, 

- Are you using the same WLAN and client interface for the local and remote sites?

--> I don't understand so much the question, what you mean the client interface ? 

okay I'll describe the environnement with more dertails to help you understand the issue : 

Totally we're talking about 4 Vlans : 

  • 100 : Management Vlan for Wontroller 
  • 110 : Corporate user (domain user ) who can connect to the main SSID 
  • 990 : Guest Vlan 
  • 991 : Guuest VLAN for DHCP server 

the 100 and 110 are present every where  and propaged, and on every distant site we found on the router the VLAN interface for those VLAN

the 990 and 991 : we found the VLAN on all site but the inteface of those Vlan is on the FW (the main Firewall on Main office) and on Wireless Controller 

so to resume to Guest Vlan 990 : 192.17.0.1/19  and the DHCP server for that network is on another Vlan 991 : 172.16.0.1/24 and in the FW manage the traffic between them, 

so to resume if I'm an corporate user anywhere in the company I can connect to domain ssid and get the IP from main dhcp server based on HQ, Vlan 110, and when I'm a guest user in HQ I get IP from vlan 990, but I'm in a distant site I got nothing, 

the thing that add huge trouble in my brain that with the old controller it's work and I don't know whyyyyyyyyyyy and how, 

 

 

the DHCP server for that network is on another Vlan 991 : 172.16.0.1/24

 

> ip helper-address 192.17.0.1

 

 One of those is wrong.  192.17.0.1 is not in the 172.16.0.1/24 subnet!  So maybe the reason your DHCP server isn't working is because you typed the IP address incorrectly?

192.17.0.1 is the interface 990 in the main Firewall and inside It we use DHCP Relay for 192.16.3.11

 

edit "ININV-990"
set vdom "MinaVDOM"
set dhcp-relay-service enable
set ip 192.17.0.1 255.255.224.0
set allowaccess ping
set netflow-sampler both
set description "INSID_INVITE"
set role lan
set snmp-index 28
set dhcp-relay-ip "192.16.3.11"
set interface "INSIDE"
set vlanid 990

You cannot relay to a relay (double relay) - that will always fail.

The client WLAN interface on the same broadcast domain as the client (either SVI on WLC or gateway interface on switch/router/firewall) needs to relay the client DHCP to the server.

Hello, 

I change it with the DHCP server IP @ 192.16.3.11  but always same behaviour 

I'm sure there is something in routing but  I don't know where to start ? 
for example in VPN site to site is there a Vlans to add or something like rules or route ? 

 

 

Nenday
Level 1
Level 1

Hello Cisco Community, 

I'm still in the trouble for the second weeks, I did some analyse and i found some strange thing, to simplify I did it with ping 

 

From the DHCP server I can ping correctly the old controller, but impossible to ping the new one, 

I capture the packet I found that the ping reach the New controller but don't found where to go, probably because the SVI don't have a gateway then the traffic go for another interface (wrong one) and the, no response for my ping, 

and the same thing for dhcp server, as the client keep send discover but without any response, 

how I can turn around and tell the traffic coming where to go, for example if traffic coming for guest SVI must go for it not for managment vlan, 

 

thanks in advance

 

 -    Have a checkup of the 9800 WLC configuration with the CLI command show tech wireless ; feed the output into :
                         Wireless Config Analyzer

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

AireOS and IOS-XE are completely different in their handling of client DHCP.
AireOS proxies the DHCP and all communication to client uses the virtual IP while all communication to the server is done on the client VLAN with the interface address as source.
IOS-XE does standards based DHCP relay.  It relays the client request to the server (following the routing table) and routes  the reply back to the client, does not proxy the request like AireOS.
This is why SVI is not recommended on 9800 because there is no isolation between client interfaces and global routing table of 9800.
This means that just like on any other IOS router or switch you must specify the source interface to use for relay and make sure the 9800 has a route to reach the DHCP server.  By default it will simply follow the default route.  Similarly the DHCP server must have a return route to the WLC relay source address and the client address.

Either switch to using layer 2 with DHCP relay done on the external network or re-design for the 9800 architecture.  This is one of the major differences between AireOS and IOS-XE.  

https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/guide-c07-743627.html#DHCPproxy
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-9/config-guide/b_wl_17_9_cg/m_dhcp_wlan_9800.html

Hello Rich, 
I respond to you 2 times today but the reponse deleted (like it's SPAM) 
It's very clear there is a big difference between AIreOS and IOS-XE,  and I configure everything according to cisco recommandation, 
so in the main site users can connect correctly, the domain user have the SSID, the guest users too they get IP and go for captive portal and then connect to wireless, in the distant site the domain users connect the wireless as well as, but guest users can't 

I followed the recommandation and I configure SVI as recommanded below the command show run interface : for your information the ip 192.17.0.1 is the IP address of FW interface of this network and inside the interface we define also the DHCP Relay 

9800wlc1-9800#show run interface Vlan990
Building configuration...

Current configuration : 219 bytes
!
interface Vlan990
 description Internet
 ip dhcp relay information trusted
 ip dhcp relay source-interface Vlan990
 ip address 192.17.0.4 255.255.224.0
 ip helper-address 192.17.0.1
 no mop enabled
 no mop sysid
end

I'm going to send you the design example in private because I can't post it here, 

 

 

 

You posts are coming through ok - it's more likely a problem with your browser and Cisco cookies which are very badly managed by Cisco.  Clear your browser cache and cookies then restart the browser before accessing the site again.

Nenday
Level 1
Level 1

Hello Community, 

I want inform you that my problem has been resolved, it was stupid thing in my controller that we forget to activate or we ignore, 

also not mentionned in the official Cisco documentation, 

in fact in the policy of guest wireless I need to enable Central DHCP and  Central Authentication, then the guest directly give IP @ and move to captive portal.

 

thank you all for your support, 

Review Cisco Networking for a $25 gift card