cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
949
Views
5
Helpful
4
Replies

Solved: 9120AIX and EWC 17.7: VLAN1 and no WLAN connection

Tenere
Level 1
Level 1

Hello there,

in my homelab I play with a Catalyst 9120AIX and EWC 17.7.

I configured a WLAN on VLAN1 and configured a Policy Profile. Under "Advanced" I entered a DHCP server IP adress from which the client should receive an IP address.

The client cannot connect to the WLAN and get the message "invalid passwort" even if the password is definitely correct ("12345678").

On one occasion (I have to admit I have no idea what was different) I had a connect but there was no IP from DHCP server. A wired client got an IP. I configured the DHCP server address in the Policy Profile but without success.

WLANs wit internal DHCP server and different VLANs are working properly.

I'm grateful for any hints.

 

Regards,

Joerg

 

4 Replies 4

Arshad Safrulla
VIP Alumni
VIP Alumni

17.7 is not a stable code, consider downgrading to either 17.6.3 or 17.3.5.

Then what authentication have you enabled under the WLAN profile? Do you have FT enabled? Do you have PMF enabled? If yes disable both options and try. Can you sanitize and paste the wlan, policy, flex profiles. It is not recommended configuring DHCP server IP under the policy profile. You can refer the below document from Cisco for better configuration guidelines

https://www.cisco.com/c/en/us/td/docs/wireless/controller/ewc/17-6/config-guide/ewc_cg_17_6.html

Connecting switchport must be trunk with native vlan set as the management VLAN. All EWC AP's behave similar to Flexconnect AP's (only local switching)

Rich R
VIP
VIP

"I configured the DHCP server address in the Policy Profile"
Why? If the DHCP server is on the local VLAN there's no need to do DHCP relay.  Or is your DHCP server remote?  And if it is then does the AP have a route to get to it?

Agreed with Leo - fall back to 17.6.3 (soon 17.6.4) or try 17.9.1 which is the next extended support release (which I have my home 9120 EWC running on now).

Hi there and sorry for the delayed reply. Real life (aka 19month old kid) messes with my spare time

"Why? If the DHCP server is on the local VLAN there's no need to do DHCP relay. Or is your DHCP server remote? And if it is then does the AP have a route to get to it?"

Because it didn't worked in first place with no DHCP server entry...

I now switched to C9800 17.9.1 and have similar problems. This seems to hint that I have a general config problem.

What did I do:

  • Setup C9800-CL on ESXi
  • connected all interfaces (for testing) to a vSwitch with VLAN 4095 (aka all VLANs allowed) configured
  • assigned IP to GE1, no IP for GE2 and GE3 (VLAN1 for management and data)
  • setup VLANs and setup SVI for VLANs (20, 30 and 100); VLAN1 SVI is not assigned and operational down (because of no assigned IP address? Can't assign IP in same subnet like GE1 (subnet overlap))
  • setup a WLAN for VLAN1 via Configuration -> Wireless -> Advanced, result is that wireless clients stuck in "IP learn"; DHCP server is in same subnet like GE1; hands out IPs for old vWLC 8.3.150 perfectly
  • setup WLAN with internal DHCP on VLAN100; result: working like a charm
  • setup WLAN (exactly like WLAN on VLAN100) on VLAN 20; result: not working ("IP learn")
  • VLANs 20, 30, 100 and GE1 can ping from CL9800 through all switches to router and 8.8.8.8

Especially since the setup for the WLANs and VLAN 20 and 100 are identical, I have no idea what is missing.

 

I appreciate ANY hints and help.

Thanks in advance,

Joerg

 

Tenere
Level 1
Level 1

Hi all,

thanks for your hints,

I just deleted the whole VM and setup a clean installation. Now it works nearly without glitch.

 

Thanks again

Review Cisco Networking for a $25 gift card