01-29-2024 03:32 PM
Hello Team,
I'm moving from my old Cisco WC controller model 5508 to new 9800, Actually I finish everything with AP's and ISE and Radius as well,
for the guest user we use Captive portal from ISE and special DHCP server (accessible only thraught the FW), so now I'm facing w small problem that from the main site I can get IP adress from the that DHCP server, but from distant site the guest user's didn't get IP adress,
I check in the old conroller I found the DHCP realy is checked and also virtual interface is added with adress 1.1.1.1 so when user's connect to guest network (from old WC always) they get an IP address,
Suffixe DNS propre à la connexion. . . : Guest-Network
Description. . . . . . . . . . . . . . : Intel(R) Wi-Fi 6 AX201 160MHz
Adresse physique . . . . . . . . . . . : 8C-XX-XX-XX-XX
DHCP activé. . . . . . . . . . . . . . : Oui
Configuration automatique activée. . . : Oui
Adresse IPv6 de liaison locale. . . . .: fe80::
Adresse IPv4. . . . . . . . . . . . . .: 192.2.1.134(préféré)
Masque de sous-réseau. . . . . . . . . : 255.255.224.0
Bail obtenu. . . . . . . . . . . . . . : 23 janvier 2024 13:04:38
Bail expirant. . . . . . . . . . . . . : 23 janvier 2024 21:04:37
Passerelle par défaut. . . . . . . . . : 192.2.0.1
Serveur DHCP . . . . . . . . . . . . . : 1.1.1.1
IAID DHCPv6 . . . . . . . . . . . : 176969034
DUID de client DHCPv6. . . . . . . . : 0
Serveurs DNS. . . . . . . . . . . . . : 192.1.3.11
NetBIOS sur Tcpip. . . . . . . . . . . : Activé
I don't know where I can align the configuration as the big difference between controllers,
Solved! Go to Solution.
02-04-2024 04:04 PM
hi @Rich R
thank you for your support,
according my knowledge ye it's centrally switched,
- Are you using the same WLAN and client interface for the local and remote sites?
--> I don't understand so much the question, what you mean the client interface ?
okay I'll describe the environnement with more dertails to help you understand the issue :
Totally we're talking about 4 Vlans :
the 100 and 110 are present every where and propaged, and on every distant site we found on the router the VLAN interface for those VLAN
the 990 and 991 : we found the VLAN on all site but the inteface of those Vlan is on the FW (the main Firewall on Main office) and on Wireless Controller
so to resume to Guest Vlan 990 : 192.17.0.1/19 and the DHCP server for that network is on another Vlan 991 : 172.16.0.1/24 and in the FW manage the traffic between them,
so to resume if I'm an corporate user anywhere in the company I can connect to domain ssid and get the IP from main dhcp server based on HQ, Vlan 110, and when I'm a guest user in HQ I get IP from vlan 990, but I'm in a distant site I got nothing,
the thing that add huge trouble in my brain that with the old controller it's work and I don't know whyyyyyyyyyyy and how,
02-04-2024 04:42 PM - edited 02-04-2024 04:42 PM
> the DHCP server for that network is on another Vlan 991 : 172.16.0.1/24
> ip helper-address 192.17.0.1
One of those is wrong. 192.17.0.1 is not in the 172.16.0.1/24 subnet! So maybe the reason your DHCP server isn't working is because you typed the IP address incorrectly?
02-04-2024 04:48 PM
192.17.0.1 is the interface 990 in the main Firewall and inside It we use DHCP Relay for 192.16.3.11
edit "ININV-990"
set vdom "MinaVDOM"
set dhcp-relay-service enable
set ip 192.17.0.1 255.255.224.0
set allowaccess ping
set netflow-sampler both
set description "INSID_INVITE"
set role lan
set snmp-index 28
set dhcp-relay-ip "192.16.3.11"
set interface "INSIDE"
set vlanid 990
02-05-2024 05:23 AM
You cannot relay to a relay (double relay) - that will always fail.
The client WLAN interface on the same broadcast domain as the client (either SVI on WLC or gateway interface on switch/router/firewall) needs to relay the client DHCP to the server.
02-05-2024 07:45 AM
Hello,
I change it with the DHCP server IP @ 192.16.3.11 but always same behaviour
I'm sure there is something in routing but I don't know where to start ?
for example in VPN site to site is there a Vlans to add or something like rules or route ?
02-02-2024 07:53 PM
Hello Cisco Community,
I'm still in the trouble for the second weeks, I did some analyse and i found some strange thing, to simplify I did it with ping
From the DHCP server I can ping correctly the old controller, but impossible to ping the new one,
I capture the packet I found that the ping reach the New controller but don't found where to go, probably because the SVI don't have a gateway then the traffic go for another interface (wrong one) and the, no response for my ping,
and the same thing for dhcp server, as the client keep send discover but without any response,
how I can turn around and tell the traffic coming where to go, for example if traffic coming for guest SVI must go for it not for managment vlan,
thanks in advance
02-03-2024 12:10 AM
- Have a checkup of the 9800 WLC configuration with the CLI command show tech wireless ; feed the output into :
Wireless Config Analyzer
M.
02-03-2024 02:57 AM - edited 02-03-2024 05:39 AM
AireOS and IOS-XE are completely different in their handling of client DHCP.
AireOS proxies the DHCP and all communication to client uses the virtual IP while all communication to the server is done on the client VLAN with the interface address as source.
IOS-XE does standards based DHCP relay. It relays the client request to the server (following the routing table) and routes the reply back to the client, does not proxy the request like AireOS.
This is why SVI is not recommended on 9800 because there is no isolation between client interfaces and global routing table of 9800.
This means that just like on any other IOS router or switch you must specify the source interface to use for relay and make sure the 9800 has a route to reach the DHCP server. By default it will simply follow the default route. Similarly the DHCP server must have a return route to the WLC relay source address and the client address.
Either switch to using layer 2 with DHCP relay done on the external network or re-design for the 9800 architecture. This is one of the major differences between AireOS and IOS-XE.
https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/guide-c07-743627.html#DHCPproxy
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-9/config-guide/b_wl_17_9_cg/m_dhcp_wlan_9800.html
02-03-2024 07:38 PM
Hello Rich,
I respond to you 2 times today but the reponse deleted (like it's SPAM)
It's very clear there is a big difference between AIreOS and IOS-XE, and I configure everything according to cisco recommandation,
so in the main site users can connect correctly, the domain user have the SSID, the guest users too they get IP and go for captive portal and then connect to wireless, in the distant site the domain users connect the wireless as well as, but guest users can't
I followed the recommandation and I configure SVI as recommanded below the command show run interface : for your information the ip 192.17.0.1 is the IP address of FW interface of this network and inside the interface we define also the DHCP Relay
9800wlc1-9800#show run interface Vlan990
Building configuration...
Current configuration : 219 bytes
!
interface Vlan990
description Internet
ip dhcp relay information trusted
ip dhcp relay source-interface Vlan990
ip address 192.17.0.4 255.255.224.0
ip helper-address 192.17.0.1
no mop enabled
no mop sysid
endI'm going to send you the design example in private because I can't post it here,
02-04-2024 03:37 AM
You posts are coming through ok - it's more likely a problem with your browser and Cisco cookies which are very badly managed by Cisco. Clear your browser cache and cookies then restart the browser before accessing the site again.
02-13-2024 06:44 AM
Hello Community,
I want inform you that my problem has been resolved, it was stupid thing in my controller that we forget to activate or we ignore,
also not mentionned in the official Cisco documentation,
in fact in the policy of guest wireless I need to enable Central DHCP and Central Authentication, then the guest directly give IP @ and move to captive portal.
thank you all for your support,
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide