cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
871
Views
3
Helpful
11
Replies

No DHCP WLC Guest user wlc -clear pass

athan1234
Level 3
Level 3

My customer has attempted to connect but has received a DHCP problem. in the guest user
The scenario is clear pass mac-cahing with wlc

I'm not sure what the issue is. Clear pass setup appears to be in order as I verify it. I tried to put the static ip but the client had no internet connection as I tried to understand the procedure when the clients obtain dhcp.

DHCP Socket Task: May 08 13:07:49.626: [SA] bc:a5:8b:2a:23:ca DHCP transmitting DHCP DISCOVER (1)
*DHCP Socket Task: May 08 13:07:49.626: [SA] bc:a5:8b:2a:23:ca DHCP   op: BOOTREQUEST, htype: Ethernet, hlen: 6, hops: 1
*DHCP Socket Task: May 08 13:07:49.626: [SA] bc:a5:8b:2a:23:ca DHCP   chaddr: bc:a5:8b:2a:23:ca
*DHCP Socket Task: May 08 13:07:49.627: [SA] bc:a5:8b:2a:23:ca DHCP ARPing for 172.16.62.1 (SPA 172.16.62.2, vlanId 62)
*DHCP Socket Task: May 08 13:07:49.627: [SA] bc:a5:8b:2a:23:ca DHCP Dropping the Packet as ARP is not resolved

 

*DHCP Socket Task: May 08 13:07:49.627: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 2 - control block settings:
                        dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
                        dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2  VLAN: 62
*DHCP Socket Task: May 08 13:07:49.627: [SA] bc:a5:8b:2a:23:ca DHCP selected relay 2 - NONE (server address 0.0.0.0,local address 0.0.0.0, gateway 172.16.62.1, VLAN 62, port 1)
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP received op BOOTREQUEST (1) (len 306,vlan 200, port 1, encap 0xec03, xid 0xc7bbe5ba)
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP (encap type 0xec03) mstype 0ff:ff:ff:ff:ff:ff
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 1 - control block settings:
                        dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
                        dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2  VLAN: 62
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP selected relay 1 - 172.16.62.1 (local address 172.16.62.2, gateway 172.16.62.1, VLAN 62, port 1)
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 2 - control block settings:
                        dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
                        dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2  VLAN: 62
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP selected relay 2 - NONE (server address 0.0.0.0,local address 172.16.62.2, gateway 172.16.62.1, VLAN 62, port 1)
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca Setting DHCP ReasonCode from (226) to (226)
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 1 - control block settings:
                        dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
                        dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2  VLAN: 62
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP transmitting DHCP DISCOVER (1)
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP   op: BOOTREQUEST, htype: Ethernet, hlen: 6, hops: 1
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP   chaddr: bc:a5:8b:2a:23:ca
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP   ciaddr: 0.0.0.0,  yiaddr: 0.0.0.0
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP ARPing for 172.16.62.1 (SPA 172.16.62.2, vlanId 62)
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP Dropping the Packet as ARP is not resolved

 

*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 2 - control block settings:
                        dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
                        dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2  VLAN: 62
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP selected relay 2 - NONE (server address 0.0.0.0,local address 0.0.0.0, gateway 172.16.62.1, VLAN 62, port 1)
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP received op BOOTREQUEST (1) (len 306,vlan 200, port 1, encap 0xec03, xid 0xc7bbe5ba)
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP (encap type 0xec03) mstype 0ff:ff:ff:ff:ff:ff
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 1 - control block settings:
                        dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
                        dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2  VLAN: 62
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP selected relay 1 - 172.16.62.1 (local address 172.16.62.2, gateway 172.16.62.1, VLAN 62, port 1)
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 2 - control block settings:
                        dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
                        dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2  VLAN: 62
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP selected relay 2 - NONE (server address 0.0.0.0,local address 172.16.62.2, gateway 172.16.62.1, VLAN 62, port 1)
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca Setting DHCP ReasonCode from (226) to (226)
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 1 - control block settings:
                        dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
                        dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2  VLAN: 62
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP selected relay 1 - 172.16.62.1 (local address 172.16.62.2, gateway 172.16.62.1, VLAN 62, port 1)
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP transmitting DHCP DISCOVER (1)
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP   xid: 0xbae5bbc7 (3135617991), secs: 3840, flags: 0
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP   chaddr: bc:a5:8b:2a:23:ca
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP   ciaddr: 0.0.0.0,  yiaddr: 0.0.0.0
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP ARPing for 172.16.62.1 (SPA 172.16.62.2, vlanId 62)
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP Dropping the Packet as ARP is not resolved

 

*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP selecting relay 2 - control block settings:
                        dhcpServer: 0.0.0.0, dhcpNetmask: 0.0.0.0,
                        dhcpGateway: 0.0.0.0, dhcpRelay: 172.16.62.2  VLAN: 62
*DHCP Socket Task: May 08 13:08:02.261: [SA] bc:a5:8b:2a:23:ca DHCP selected relay 2 - NONE (server address 0.0.0.0,local address 0.0.0.0, gateway 172.16.62.1, VLAN 62, port 1)

 

///////////////////////

After puted dhcp proxy enable

 

*apfReceiveTask: May 08 13:57:43.815: [SA] bc:a5:8b:2a:23:ca Scheduling deletion of Mobile Station:  (callerId: 45) in 10 seconds
*osapiBsnTimer: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca apfMsExpireCallback (apf_ms.c:657) Expiring Mobile!
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Succesfully freed AID 136, slot 0 on AP 00:27:90:4b:c4:a0, #client on this slot 5
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca apfSendDisAssocMsgDebug (apf_80211.c:4001) Changing state for mobile bc:a5:8b:2a:23:ca on AP 00:27:90:4b:c4:a0 from Disassociated to Disassociated

 

*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Sent Disassociate to mobile on AP 00:27:90:4b:c4:a0-0 on BSSID 00:27:90:4b:c4:a0(reason 1, caller apf_ms.c:8095)
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Setting active key cache index 8 ---> 8
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Deleting the PMK cache when de-authenticating the client.
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Global PMK Cache deletion failed.
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca CL_EVENT_DEAUTH (14), reasonCode (0)
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Sent Deauthenticate to mobile on BSSID 00:27:90:4b:c4:a0 slot 0(caller apf_ms.c:8103)
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca apfMsAssoStateDec
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca apfMsExpireMobileStation (apf_ms.c:8161) Changing state for mobile bc:a5:8b:2a:23:ca on AP 00:27:90:4b:c4:a0 from Disassociated to Idle

 

*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca pemApfDeleteMobileStation2: APF_MS_PEM_WAIT_L2_AUTH_COMPLETE = 0.
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca the value of url acl preserve flag is 0 for mobile bc:a5:8b:2a:23:ca (caller pem_api.c:5148)
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca 0.0.0.0 START (0) Deleted mobile LWAPP rule on AP [00:27:90:4b:c4:a0]
*pemReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca 0.0.0.0 Removed NPU entry.
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca 0 PMK-remove groupcast messages sent
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Deleted global PMK cache and MSCB PMKID/PMK cache entry for the client
*spamApTask6: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Setting DEL_MOBILE (seqno 0, action 6) ack state for STA on AP 00:27:90:4b:c4:a0
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca CL_EVENT_DELETE (11), reasonCode (0)
*apfReceiveTask: May 08 13:57:54.019: [SA] bc:a5:8b:2a:23:ca Resetting All reasonCodes
*apfReceiveTask: May 08 13:57:54.020: [SA] bc:a5:8b:2a:23:ca Deleting mobile on AP 00:27:90:4b:c4:a0(0)
*apfReceiveTask: May 08 13:57:54.020: [SA] bc:a5:8b:2a:23:ca apf_ms.c:5590 Clearing the SGT 0 of mobile
*apfReceiveTask: May 08 13:57:54.020: [SA] bc:a5:8b:2a:23:ca Decrement the SGT 0 policy count reference by the clients 461

 

 

 

 

11 Replies 11

Hi @athan1234 

  Which WLC is it? 

The first log seems to be for a client but the second (after  dhcp proxy arp) seems to be from one Access Point trying to join.

Make sure you have the DHCP server on the dynamic Interface like the example below

FlavioMiranda_0-1683555267891.png

 

Now, I have one observation.  For guest users, it is not expected the WLC to be the  DHCP proxy. Usually the Guest SSID is flexconnect and the Client take IP address on the local network. First cilent gets one IP on the local subnet and then it try to reach the portal for authentication.

 

 

Yes I have the DHCP on the dynamic interface .

Primary DHCP 172.16.62.1

Thank you. I noted in a post that someone had mentioned enabling proxy, so I did that on the controller.

Proxy makes the  WLC DHCP client. Which means, the WLC will go to the DHCP server, ask for an IP address and hand it out to the clients. If no proxy  enable the client will request DHCP to the DHCP server directly.

*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP ARPing for 172.16.62.1 (SPA 172.16.62.2, vlanId 62)
*DHCP Socket Task: May 08 13:07:53.978: [SA] bc:a5:8b:2a:23:ca DHCP Dropping the Packet as ARP is not resolved

this two logs above makes me think that something is not right over there.  If the DHCP server is a remote network . you need to have ip helper-address on the core switch.

 

I am going to check it . Thanks

The ip-helper 172.16.62.1 has not been configured on the core in the vlan. It will be set up by Mu clients. It doesn't resolve the issue.

Any idea . Do you have any test, debug, or other suggestions?

No point doing any debugs until the helper has been configured.

You have not yet answered my questions below ...

I set up the ip-helper adrress and my customer continuos without get ip address

And you still haven't answered my questions below!  I'll repeat them here:
What model of WLC?
What model of AP?
What version of software?
How is the WLAN configured? (central/local switching, what type of auth or open etc)

 Hi @athan1234 

 If the DHCP server is remote, which means, in another network, you need the helper-address on the gateway, which I believe is the core. Or, if the clients is requesting DHCP locally, the DHCP helper must be on the Layer3 closer to the client. As you mentioned Guest clients, they probably is getting IP from the local network.

 The debug I can suggest is "debug client <mac address>  while joining the network but take the whole conversation.

marce1000
Hall of Fame
Hall of Fame

 

 - Below you will find the output of your debug file when processed with : https://cway.cisco.com/wireless-debug-analyzer/ , actually I would advice to run it again with another  native debug session because the one you posted may have been  a bit garbled , check if that can provide insights , 

 M.

 

TimeTaskTranslated
May 08 13:07:49.626 *DHCP Socket Task Sending DHCP Discover to DHCP Server CP through gateway ransmitting DHCP DISCOVER (1)
on VLAN ARPing for 172.16.62.1 (SPA 172.16.62.2, vlanId 62)
May 08 13:07:53.978 *DHCP Socket Task Received DHCP request from client
May 08 13:07:53.978 *DHCP Socket Task Sending DHCP Discover to DHCP Server CP through gateway ropping the Packet as ARP is not resolved



on VLAN received op BOOTREQUEST (1) (len 306,vlan 200, port 1, encap 0xec03, xid 0xc7bbe5ba)
May 08 13:08:02.261 *DHCP Socket Task Sending DHCP Discover to DHCP Server CP through gateway ropping the Packet as ARP is not resolved



on VLAN duling deletion of Mobile Station: (callerId: 45) in 10 seconds
May 08 13:57:54.019 *apfReceiveTask Client disassociation event has occured. Possible reasons may be due to AP Radio Reset usually due to channel change or wlan was manually disabled or Client unable to get valid DHCP IP for WLAN using DHCP required
May 08 13:57:54.019 *apfReceiveTask Client has been deauthenticated
May 08 13:57:54.019 *apfReceiveTask Client session has timed out


-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Rich R
VIP
VIP

What model of WLC?
What model of AP?
What version of software?
How is the WLAN configured?

Review Cisco Networking for a $25 gift card