cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
707
Views
5
Helpful
10
Replies

Tablet with Static IP in RUN State on WLC, No MAC on AP Switchport

Sam Caprio
Level 1
Level 1

Hello Team,

I'm encountering an issue where a tablet device with a statically assigned IP address reaches the RUN state on the Wireless LAN Controller (WLC), but its MAC address does not appear on the switch port connected to the AP it's associated with. As a result, although the tablet shows as connected on the WLC, it's not functioning as expected.

Here’s what I’ve verified so far:

  1. FlexConnect and policy profile are correctly configured with the appropriate VLAN (200).

  2. VLAN 200 is allowed on the trunk port of the switch where the AP is connected.

  3. VLAN 200 is present in the switch database, and its spanning-tree state for that specific AP switch port is Forwarding.

Could you please help identify why the tablet's MAC address is not showing on the AP switch port and what might be causing this connectivity issue?

10 Replies 10

marce1000
Hall of Fame
Hall of Fame

 

 - Please note :  The wireless controller could be configured for  the WLAN with “DHCP Required” (kind of a standard) which forces clients to use a DHCP-assigned IP address. When this option is enabled, a device with a statically assigned IP may successfully complete the control plane procedures (resulting in a RUN state) but then get its data plane blocked because it doesn’t meet the DHCP criteria. Without data traffic flowing from the client, the AP will never see frames from that MAC address, and subsequently, the switch won’t learn it. So in that case you need to  disable  “DHCP Required”

  M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Hello Marce,

The DHCP Required option is already unchecked in the Advanced section of the policy profile associated with this SSID.

Additionally, the MAC address of the tablet device is not being learned in either of the following scenarios:

  1. Using DHCP: The tablet gets stuck in the IP Learn state, and no MAC address is learned on the AP's switchport—even though the DHCP is properly configured to assign an IP to the client.

  2. Using Static IP: The tablet transitions to the RUN state, but functionality remains broken as the MAC address is still not learned on the AP’s switchport.

 

  - Joining another reply : to determine a possible issue with this tablet; can other devices use that wireless setup ?

  M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

We tested other similar tablet but same issue. To test completely other device will be difficult

eglinsky2012
Spotlight
Spotlight

What model of WLC and AP, running what code version? Are other devices able to connect successfully to the same SSID using the same static config?

9800 WLC and 9130 Access Point. Code  17.9.5
Tested with other similar device. Same issue

Saikat Nandy
Cisco Employee
Cisco Employee

Looks like you are using 9800 WLC. 2 things - 

Inside the Policy Profile what's the status of 'Passive Client' & 'IP MAC Binding'? Note - If Passive Client is disabled, you need to enable that as this is a mandatory settings for the users with static IP address.

Passive client is disabled. I will try to test this on monday. I dont think it will solve the issue because its about the arp broadcast. I am not even getting mac address on the AP switchport
When I give static IP Address then it goes into the RUN State while with local DHCP its stuck in IP learn, both cases donot show mac of the client on the AP switchport.
I have other SSID which also use local DHCP and all works fine without the Passive client enabled.

 

@Sam Caprio        >...To test completely other device will be difficult
                          It shouldn't be with a simple laptop in my opinion ; anyway in this document :
                       https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/218395-troubleshoot-catalyst-9800-client-connec.html
                          you will find many useful commands for further troubleshooting, including for instance :
                                          show wireless client mac-address <client-mac-address> detail

           Look for error stats from the above on, (e.g.)

  M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Rich R
VIP
VIP

The use of static IPs and passive client is covered in the Best Practices guide:
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html#PassiveClients
It's a good idea to read through all the tips in the guide just to make sure there isn't something else you've missed.

But the fact that it doesn't work, even with DHCP, suggests you have something misconfigured.
You say "FlexConnect and policy profile are correctly configured with the appropriate VLAN (200)" but what makes you so sure that it's all correctly configured and you haven't made a mistake?

Have you used Config Analyzer (link below) to check your WLC config?  That will also highlight many Best Practice items you might have missed.

Do you want to share your WLC and switch port config for us to review and confirm we agree that it's configured correctly?

Code  17.9.5
See the TAC recommended code link below - you should probably update to a TAC recommended release just to make sure you are not hitting a bug that's already been fixed.

Review Cisco Networking for a $25 gift card