12-12-2024 03:15 AM - edited 12-12-2024 03:26 AM
Hello, We have a WLC 9800 where some of the users are unable to connect to Guest SSID all of a sudden, it keeps on loading and says 'no internet, connected'. When I check the mac it says 'IP learn' in WLC client logs and hosts will be assigned with APIPA. Attached is the radioactive trace for one of the mac. Below is the version WLC is running on. We have a meraki at site which acts as a DHCP, core switch vlan is configured with dhcp relay.
Please advise
---------
sh version
Cisco IOS XE Software, Version 17.09.03
Cisco IOS Software [Cupertino], C9800 Software (C9800_IOSXE-K9), Version 17.9.3, RELEASE SOFTWARE (fc6)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2023 by Cisco Systems, Inc.
EDIT: RADIOACTIVE TRACE ATTACHED
Solved! Go to Solution.
12-15-2024 10:28 PM
ok I figured it out, looks like I had to add ip helper address config on SVI configured on WLC too. Adding just on core switch wasnt enough. My bad
12-12-2024 03:21 AM
Nothing wrong
You face dhcp pool exhaust
Reduce lease time or enlarge the Pool
MHM
12-12-2024 03:23 AM - edited 12-12-2024 03:23 AM
hello, right now the pool is /23 and we have around 500 users at site. Lease time is 12 hours- hope this is ok
12-12-2024 03:26 AM
500 users not meaning 500 IP' the one guest can get multi IP when it conn-disconn.
So double check the dhcp pool ip lease see how many IP free.
MHM
12-12-2024 04:35 AM
- APIPA stands for Automatic Private IP Addressing , (a link local address was assigned)
meaning that no effective DHCP server could be reached.
Feed the debugTrace........ into Wireless Debug Analyzer
For further insights,
M.
12-12-2024 09:40 PM
Hello Marce, Looks like Client is stuck in IP learn State
2024/12/12 16:26:14.850 | client-orch-sm | Client roamed to a new AP/BSSID: BSSID 6cd6.e375.1a2f, WLAN TxGuest, Slot 1 AP 6cd6.e375.1a20, TIPL_AP_2F_IT, old BSSID 6cd6.e375.1a20 |
2024/12/12 16:26:14.850 | client-orch-state | Entering IP learn state |
2024/12/12 16:26:14.850 | dot11 | Association success for client, assigned AID is: 10. Client performed fast roam. |
2024/12/12 16:26:14.856 | client-auth | Client successfully completed Pre-shared Key authentication. Assigned VLAN: 889 |
2024/12/12 16:26:14.856 | client-orch-state | Starting Mobility Anchor discovery for client |
2024/12/12 16:26:14.856 | client-orch-state | Entering IP learn state |
2024/12/12 16:27:15.116 | client-orch-sm | Controller initiated client deletion with code: CO_CLIENT_DELETE_REASON_CLIENT_DHCP_FAILURE. Explanation: Client reported DHCP error on deauth frame. Actions: Check DHCP server, and collect RA trace |
12-12-2024 10:51 PM
- Client can 'not reach' the DHCP server ; check if it can be reached from the VLAN , the guests are arriving in,
M.
12-12-2024 09:58 PM
Hello Marce, I configured LAN port with Guest VLAN and I was able to get the IP address. The device is not getting IP only on Wireless
12-13-2024 01:31 AM
I will send you PM check it
MHM
12-15-2024 10:28 PM
ok I figured it out, looks like I had to add ip helper address config on SVI configured on WLC too. Adding just on core switch wasnt enough. My bad
12-15-2024 11:46 PM
You are welcome
MHM
12-24-2024 02:44 AM
Why are you using SVI on 9800?
It is only required for specific features and introduces additional security risks and problems on the controller.
The recommended design for 9800 is pure layer 2 VLAN config on the controller with all helpers and other layer 3 config on the connected switch/router network.
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html#Wirelessclientinterfaces
SVI is required if you must do DHCP relay on the 9800 but note that there is a serious bug CSCwm73020 in 9800 if you relay to more than 1 DHCP server which can cause client failures (no IP).
Refer to https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html#DHCPbridgingandDHCPrelay
> Cisco IOS XE Software, Version 17.09.03
Refer to TAC recommended releases link below and consider upgrading to a TAC recommended release.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide