05-13-2025 01:37 AM
Good day.
Catalyst 9800-CL 17.15.3. AP4800 -FlexConnect.
FPR 1120 management via FDM
There is a main local network 192.168.3.0\24 – inside ip 192.168.3.30
There is a subnet for WIFI-Work 192.168.17.0\24 (vlan17), WIFI Guests 192.168.14.1/24(vlan14)
For the WIFI Work and WIFI Guests subnets, two sub interfaces have been created in the inside interface
Ip 192.168.17.1 (vlan17), and 192.168.14.1 (vlan14).
Catalyst management port in the network 192.168.3.0.
For WIFI Work clients, a rule has been made in ACCESS CONTROL to access the main network servers. Clients are authorized via RADIUS SERVER in the main network (192.168.3.0.24). WIFI Guest clients use a key for authorization (PSK) and have access only to the Internet. The problem is that WIFI WORK clients periodically drop out. That is, the connection with the access points is simply lost, especially when moving from one place to another, not immediately. Then it reappears. At the same time, guest network clients never have such problems. Ping from the main network to WIFI WORK clients periodically shows packet loss. But not always. Ping to the access points themselves goes without anomalies. What could be the problem?
05-13-2025 03:55 AM
- Check client overall health using : https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#toc-hId-866973845
Always evaluate the configuration of the 9800-CL using the CLI command show tech wireless and feed
the output from that into Wireless Config Analyzer
If clients lose connection while moving , then check for sufficient wireless coverage,
M.
05-13-2025 04:59 AM
05-13-2025 06:18 AM
What I can summarise from your statement is that you have roaming problem. There can be multiple reasons for roaming to not work as expected. The first step for you would be to take RA trace reproducing the issue - https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213949-wireless-debugging-and-log-collection-on.html
05-13-2025 12:01 PM
There is another message like this. how can this be fixed? c9800 is installed on hyper-v:
Chassis 1 F0: cpp_cp_svr: Dynamic mac E4C7.67B5.25E3 from GigabitEthernet3 conflict with WlClient, please check the network topology and make sure there is no loop.QFP:0.0 Thread:001 TS:00000000071256505707
05-18-2025 04:15 PM
Those messages are normal if the MAC can be expected to be seen on both network segments - for example if there is another controller the client could roam to connected to the same VLAN. Make sure the WLC ports have only the correct VLANs allowed.
05-18-2025 04:27 PM - edited 05-18-2025 04:28 PM
@Denis Negik
FlexConnect - is that with central or local authentication?
"For WIFI Work clients, a rule has been made in ACCESS CONTROL to access the main network servers. Clients are authorized via RADIUS SERVER" - do you mean that the Work SSID is using 802.1x authentication?
Have you reviewed https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html#Enable80211rFastTransition ?
Also see https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-15/config-guide/b_wl_17_15_cg/m_okc.html and if using Flex Local Authentication then https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-15/config-guide/b_wl_17_15_cg/m_dot11r.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide