05-08-2023 06:57 AM
My customer has attempted to connect but has received a DHCP problem. in the guest user
The scenario is clear pass mac-cahing with wlc
I'm not sure what the issue is. Clear pass setup appears to be in order as I verify it. I tried to put the static ip but the client had no internet connection as I tried to understand the procedure when the clients obtain dhcp.
DHCP Socket Task: May 08 13:07:49.626: [SA] bc:a5:8b:2a:23:ca DHCP transmitting DHCP DISCOVER (1)
*DHCP Socket Task: May 08 13:07:49.626: [SA] bc:a5:8b:2a:23:ca DHCP op: BOOTREQUEST, htype: Ethernet, hlen: 6, hops: 1
*DHCP Socket Task: May 08 13:07:49.626: [SA] bc:a5:8b:2a:23:ca DHCP chaddr: bc:a5:8b:2a:23:ca
*DHCP Socket Task: May 08 13:07:49.627: [SA] bc:a5:8b:2a:23:ca DHCP ARPing for 172.16.62.1 (SPA 172.16.62.2, vlanId 62)
*DHCP Socket Task: May 08 13:07:49.627: [SA] bc:a5:8b:2a:23:ca DHCP Dropping the Packet as ARP is not resolved
*DHCP Socket Task: May 08 13:07:49.627: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 2 - control block settings:
dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2 VLAN: 62
*DHCP Socket Task: May 08 13:07:49.627: [SA] bc:a5:8b:2a:23:ca DHCP selected relay 2 - NONE (server address 0.0.0.0,local address 0.0.0.0, gateway 172.16.62.1, VLAN 62, port 1)
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP received op BOOTREQUEST (1) (len 306,vlan 200, port 1, encap 0xec03, xid 0xc7bbe5ba)
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP (encap type 0xec03) mstype 0ff:ff:ff:ff:ff:ff
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 1 - control block settings:
dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2 VLAN: 62
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP selected relay 1 - 172.16.62.1 (local address 172.16.62.2, gateway 172.16.62.1, VLAN 62, port 1)
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 2 - control block settings:
dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2 VLAN: 62
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP selected relay 2 - NONE (server address 0.0.0.0,local address 172.16.62.2, gateway 172.16.62.1, VLAN 62, port 1)
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca Setting DHCP ReasonCode from (226) to (226)
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 1 - control block settings:
dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2 VLAN: 62
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP transmitting DHCP DISCOVER (1)
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP op: BOOTREQUEST, htype: Ethernet, hlen: 6, hops: 1
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP chaddr: bc:a5:8b:2a:23:ca
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP ciaddr: 0.0.0.0, yiaddr: 0.0.0.0
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP ARPing for 172.16.62.1 (SPA 172.16.62.2, vlanId 62)
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP Dropping the Packet as ARP is not resolved
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 2 - control block settings:
dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2 VLAN: 62
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP selected relay 2 - NONE (server address 0.0.0.0,local address 0.0.0.0, gateway 172.16.62.1, VLAN 62, port 1)
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP received op BOOTREQUEST (1) (len 306,vlan 200, port 1, encap 0xec03, xid 0xc7bbe5ba)
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP (encap type 0xec03) mstype 0ff:ff:ff:ff:ff:ff
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 1 - control block settings:
dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2 VLAN: 62
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP selected relay 1 - 172.16.62.1 (local address 172.16.62.2, gateway 172.16.62.1, VLAN 62, port 1)
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 2 - control block settings:
dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2 VLAN: 62
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP selected relay 2 - NONE (server address 0.0.0.0,local address 172.16.62.2, gateway 172.16.62.1, VLAN 62, port 1)
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca Setting DHCP ReasonCode from (226) to (226)
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 1 - control block settings:
dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2 VLAN: 62
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP selected relay 1 - 172.16.62.1 (local address 172.16.62.2, gateway 172.16.62.1, VLAN 62, port 1)
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP transmitting DHCP DISCOVER (1)
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP xid: 0xbae5bbc7 (3135617991), secs: 3840, flags: 0
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP chaddr: bc:a5:8b:2a:23:ca
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP ciaddr: 0.0.0.0, yiaddr: 0.0.0.0
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP ARPing for 172.16.62.1 (SPA 172.16.62.2, vlanId 62)
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP Dropping the Packet as ARP is not resolved
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 2 - control block settings:
dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2 VLAN: 62
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP selected relay 2 - NONE (server address 0.0.0.0,local address 0.0.0.0, gateway 172.16.62.1, VLAN 62, port 1)
///////////////////////
After puted dhcp proxy enable
*apfReceiveTask: May 08 13:57:43.815: [SA] bc:a5:8b:2a:23:ca Scheduling deletion of Mobile Station: (callerId: 45) in 10 seconds
*osapiBsnTimer: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca apfMsExpireCallback (apf_ms.c:657) Expiring Mobile!
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Succesfully freed AID 136, slot 0 on AP 00:27:90:4b:c4:a0, #client on this slot 5
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca apfSendDisAssocMsgDebug (apf_80211.c:4001) Changing state for mobile bc:a5:8b:2a:23:ca on AP 00:27:90:4b:c4:a0 from Disassociated to Disassociated
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Sent Disassociate to mobile on AP 00:27:90:4b:c4:a0-0 on BSSID 00:27:90:4b:c4:a0(reason 1, caller apf_ms.c:8095)
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Setting active key cache index 8 ---> 8
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Deleting the PMK cache when de-authenticating the client.
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Global PMK Cache deletion failed.
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca CL_EVENT_DEAUTH (14), reasonCode (0)
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Sent Deauthenticate to mobile on BSSID 00:27:90:4b:c4:a0 slot 0(caller apf_ms.c:8103)
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca apfMsAssoStateDec
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca apfMsExpireMobileStation (apf_ms.c:8161) Changing state for mobile bc:a5:8b:2a:23:ca on AP 00:27:90:4b:c4:a0 from Disassociated to Idle
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca pemApfDeleteMobileStation2: APF_MS_PEM_WAIT_L2_AUTH_COMPLETE = 0.
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca the value of url acl preserve flag is 0 for mobile bc:a5:8b:2a:23:ca (caller pem_api.c:5148)
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca 0.0.0.0 START (0) Deleted mobile LWAPP rule on AP [00:27:90:4b:c4:a0]
*pemReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca 0.0.0.0 Removed NPU entry.
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca 0 PMK-remove groupcast messages sent
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Deleted global PMK cache and MSCB PMKID/PMK cache entry for the client
*spamApTask6: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Setting DEL_MOBILE (seqno 0, action 6) ack state for STA on AP 00:27:90:4b:c4:a0
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca CL_EVENT_DELETE (11), reasonCode (0)
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Resetting All reasonCodes
*apfReceiveTask: May 08 13:57:54.020: [SA] bc:a5:8b:2a:23:ca Deleting mobile on AP 00:27:90:4b:c4:a0(0)
*apfReceiveTask: May 08 13:57:54.020: [SA] bc:a5:8b:2a:23:ca apf_ms.c:5590 Clearing the SGT 0 of mobile
*apfReceiveTask: May 08 13:57:54.020: [SA] bc:a5:8b:2a:23:ca Decrement the SGT 0 policy count reference by the clients 461
05-08-2023 07:20 AM
Hi @athan1234
Which WLC is it?
The first log seems to be for a client but the second (after dhcp proxy arp) seems to be from one Access Point trying to join.
Make sure you have the DHCP server on the dynamic Interface like the example below
Now, I have one observation. For guest users, it is not expected the WLC to be the DHCP proxy. Usually the Guest SSID is flexconnect and the Client take IP address on the local network. First cilent gets one IP on the local subnet and then it try to reach the portal for authentication.
05-08-2023 07:55 AM
Yes I have the DHCP on the dynamic interface .
Primary DHCP 172.16.62.1
Thank you. I noted in a post that someone had mentioned enabling proxy, so I did that on the controller.
05-08-2023 08:09 AM - edited 05-08-2023 08:11 AM
Proxy makes the WLC DHCP client. Which means, the WLC will go to the DHCP server, ask for an IP address and hand it out to the clients. If no proxy enable the client will request DHCP to the DHCP server directly.
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP ARPing for 172.16.62.1 (SPA 172.16.62.2, vlanId 62)
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP Dropping the Packet as ARP is not resolved
this two logs above makes me think that something is not right over there. If the DHCP server is a remote network . you need to have ip helper-address on the core switch.
05-08-2023 11:29 PM
I am going to check it . Thanks
05-10-2023 11:53 PM
The ip-helper 172.16.62.1 has not been configured on the core in the vlan. It will be set up by Mu clients. It doesn't resolve the issue.
Any idea . Do you have any test, debug, or other suggestions?
05-11-2023 02:06 AM
No point doing any debugs until the helper has been configured.
You have not yet answered my questions below ...
05-11-2023 03:41 AM
I set up the ip-helper adrress and my customer continuos without get ip address
05-11-2023 04:07 AM
And you still haven't answered my questions below! I'll repeat them here:
What model of WLC?
What model of AP?
What version of software?
How is the WLAN configured? (central/local switching, what type of auth or open etc)
05-11-2023 04:25 AM
Hi @athan1234
If the DHCP server is remote, which means, in another network, you need the helper-address on the gateway, which I believe is the core. Or, if the clients is requesting DHCP locally, the DHCP helper must be on the Layer3 closer to the client. As you mentioned Guest clients, they probably is getting IP from the local network.
The debug I can suggest is "debug client <mac address> while joining the network but take the whole conversation.
05-08-2023 09:28 AM
- Below you will find the output of your debug file when processed with : https://cway.cisco.com/wireless-debug-analyzer/ , actually I would advice to run it again with another native debug session because the one you posted may have been a bit garbled , check if that can provide insights ,
M.
May 08 13:07:49.626 | *DHCP Socket Task | Sending DHCP Discover to DHCP Server CP through gateway ransmitting DHCP DISCOVER (1) on VLAN ARPing for 172.16.62.1 (SPA 172.16.62.2, vlanId 62) |
May 08 13:07:53.978 | *DHCP Socket Task | Received DHCP request from client |
May 08 13:07:53.978 | *DHCP Socket Task | Sending DHCP Discover to DHCP Server CP through gateway ropping the Packet as ARP is not resolved on VLAN received op BOOTREQUEST (1) (len 306,vlan 200, port 1, encap 0xec03, xid 0xc7bbe5ba) |
May 08 13:08:02.261 | *DHCP Socket Task | Sending DHCP Discover to DHCP Server CP through gateway ropping the Packet as ARP is not resolved on VLAN duling deletion of Mobile Station: (callerId: 45) in 10 seconds |
May 08 13:57:54.019 | *apfReceiveTask | Client disassociation event has occured. Possible reasons may be due to AP Radio Reset usually due to channel change or wlan was manually disabled or Client unable to get valid DHCP IP for WLAN using DHCP required |
May 08 13:57:54.019 | *apfReceiveTask | Client has been deauthenticated |
May 08 13:57:54.019 | *apfReceiveTask | Client session has timed out |
05-09-2023 06:03 AM
What model of WLC?
What model of AP?
What version of software?
How is the WLAN configured?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide