cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
825
Views
2
Helpful
8
Replies

Vlan2 Guest Wifi issue on ws-c3750x-48

PeyLawro
Level 1
Level 1

Hi All,

I know this likely will be something straight forward and staring me right in the eyes.

We have a ws-c3750x-48 (config will show 2 but only 1 in use) and a bunch of unifi APs at one site.

Our secure network is functioning as expected and everyone is getting an IP on that which is 10.10.6.x, but our guest wifi on VLAN2 is giving 169. addresses which should be 10.30.30.x

The router on port 6 is configured for the guestwifi and plugging my laptop into the port directly gives a 10.30.30.x address.

Router is connected to switch on port 48 for the guest network and here is the config of the switch and Unfifi is set to use VLan2 for the guest network

CAB_G_SW_1-2#show run
Building configuration...

Current configuration : 12743 bytes
!
version 12.2
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
service sequence-numbers
!
hostname CAB_G_SW_1-2
!
boot-start-marker
boot-end-marker
!
logging console notifications
enable secret 5 xxxxxxxxxxxxxxxxxxx
!
username xxxx password 0 xxxxxxxxx
!
!
aaa new-model
!
!
!
!
!
aaa session-id common
switch 1 provision ws-c3750x-48p
switch 2 provision ws-c3750x-48
system mtu routing 1500
!
!
!
mls qos map cos-dscp 0 8 16 24 32 46 48 56
mls qos srr-queue input bandwidth 70 30
mls qos srr-queue input threshold 1 80 90
mls qos srr-queue input priority-queue 2 bandwidth 30
mls qos srr-queue input cos-map queue 1 threshold 2 3
mls qos srr-queue input cos-map queue 1 threshold 3 6 7
mls qos srr-queue input cos-map queue 2 threshold 1 4
mls qos srr-queue input dscp-map queue 1 threshold 2 24
mls qos srr-queue input dscp-map queue 1 threshold 3 48 49 50 51 52 53 54 55
mls qos srr-queue input dscp-map queue 1 threshold 3 56 57 58 59 60 61 62 63
mls qos srr-queue input dscp-map queue 2 threshold 3 32 33 40 41 42 43 44 45
mls qos srr-queue input dscp-map queue 2 threshold 3 46 47
mls qos srr-queue output cos-map queue 1 threshold 3 4 5
mls qos srr-queue output cos-map queue 2 threshold 1 2
mls qos srr-queue output cos-map queue 2 threshold 2 3
mls qos srr-queue output cos-map queue 2 threshold 3 6 7
mls qos srr-queue output cos-map queue 3 threshold 3 0
mls qos srr-queue output cos-map queue 4 threshold 3 1
mls qos srr-queue output dscp-map queue 1 threshold 3 32 33 40 41 42 43 44 45
mls qos srr-queue output dscp-map queue 1 threshold 3 46 47
mls qos srr-queue output dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23
mls qos srr-queue output dscp-map queue 2 threshold 1 26 27 28 29 30 31 34 35
mls qos srr-queue output dscp-map queue 2 threshold 1 36 37 38 39
mls qos srr-queue output dscp-map queue 2 threshold 2 24
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63
mls qos srr-queue output dscp-map queue 3 threshold 3 0 1 2 3 4 5 6 7
mls qos srr-queue output dscp-map queue 4 threshold 1 8 9 11 13 15
mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14
mls qos queue-set output 1 threshold 1 100 100 50 200
mls qos queue-set output 1 threshold 2 125 125 100 400
mls qos queue-set output 1 threshold 3 100 100 100 400
mls qos queue-set output 1 threshold 4 60 150 50 200
mls qos queue-set output 1 buffers 15 25 40 20
mls qos

!
spanning-tree mode rapid-pvst
spanning-tree extend system-id
auto qos srnd4
!
!
!
!
vlan internal allocation policy ascending
!
vlan 2
name guestwifi
!
vlan 3
name IPCameras
!
vlan 4
name VMotion
!
vlan 6
name SCADA
!
vlan 10
name DMZ
!
vlan 50
!
!
!
interface FastEthernet0
ip address 10.10.6.20 255.255.255.0
shutdown
!
interface GigabitEthernet1/0/1
spanning-tree portfast
!
interface GigabitEthernet1/0/2
spanning-tree portfast
!
interface GigabitEthernet1/0/3
spanning-tree portfast
!
interface GigabitEthernet1/0/4
spanning-tree portfast
!
interface GigabitEthernet1/0/5
spanning-tree portfast
!
interface GigabitEthernet1/0/6
!
interface GigabitEthernet1/0/7
spanning-tree portfast
!
interface GigabitEthernet1/0/8
spanning-tree portfast
!
interface GigabitEthernet1/0/9
spanning-tree portfast
!
interface GigabitEthernet1/0/10
spanning-tree portfast
!
interface GigabitEthernet1/0/11
spanning-tree portfast
!
interface GigabitEthernet1/0/12
spanning-tree portfast
!
interface GigabitEthernet1/0/13
spanning-tree portfast
!
interface GigabitEthernet1/0/14
spanning-tree portfast
!
interface GigabitEthernet1/0/15
spanning-tree portfast
!
interface GigabitEthernet1/0/16
spanning-tree portfast
!
interface GigabitEthernet1/0/17
spanning-tree portfast
!
interface GigabitEthernet1/0/18
spanning-tree portfast
!
interface GigabitEthernet1/0/19
spanning-tree portfast
!
interface GigabitEthernet1/0/20
spanning-tree portfast
!
interface GigabitEthernet1/0/21
spanning-tree portfast
!
interface GigabitEthernet1/0/22
spanning-tree portfast
!
interface GigabitEthernet1/0/23
spanning-tree portfast
!
interface GigabitEthernet1/0/24
spanning-tree portfast
!
interface GigabitEthernet1/0/25
spanning-tree portfast
!
interface GigabitEthernet1/0/26
spanning-tree portfast
!
interface GigabitEthernet1/0/27
spanning-tree portfast
!
interface GigabitEthernet1/0/28
spanning-tree portfast
!
interface GigabitEthernet1/0/29
spanning-tree portfast
!
interface GigabitEthernet1/0/30
spanning-tree portfast
!
interface GigabitEthernet1/0/31
spanning-tree portfast
!
interface GigabitEthernet1/0/32
spanning-tree portfast
!
interface GigabitEthernet1/0/33
spanning-tree portfast
!
interface GigabitEthernet1/0/34
spanning-tree portfast
!
interface GigabitEthernet1/0/35
spanning-tree portfast
!
interface GigabitEthernet1/0/36
spanning-tree portfast
!
interface GigabitEthernet1/0/37
!
interface GigabitEthernet1/0/38
!
interface GigabitEthernet1/0/39
!
interface GigabitEthernet1/0/40
spanning-tree portfast
!
interface GigabitEthernet1/0/41
spanning-tree portfast
!
interface GigabitEthernet1/0/42
spanning-tree portfast
!
interface GigabitEthernet1/0/43
spanning-tree portfast
!
interface GigabitEthernet1/0/44
spanning-tree portfast
!
interface GigabitEthernet1/0/45
switchport trunk allowed vlan 1,2
!
interface GigabitEthernet1/0/46
switchport trunk allowed vlan 1,2
!
interface GigabitEthernet1/0/47
switchport trunk allowed vlan 1,2
!
interface GigabitEthernet1/0/48
switchport access vlan 2
!
interface GigabitEthernet1/1/1
!
interface GigabitEthernet1/1/2
!
interface GigabitEthernet1/1/3
!
interface GigabitEthernet1/1/4
!
interface TenGigabitEthernet1/1/1
switchport trunk encapsulation dot1q
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
!
interface TenGigabitEthernet1/1/2
switchport trunk encapsulation dot1q
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
!
interface GigabitEthernet2/0/1
spanning-tree portfast
!
interface GigabitEthernet2/0/2
spanning-tree portfast
!
interface GigabitEthernet2/0/3
spanning-tree portfast
!
interface GigabitEthernet2/0/4
spanning-tree portfast
!
interface GigabitEthernet2/0/5
spanning-tree portfast
!
interface GigabitEthernet2/0/6
spanning-tree portfast
!
interface GigabitEthernet2/0/7
spanning-tree portfast
!
interface GigabitEthernet2/0/8
spanning-tree portfast
!
interface GigabitEthernet2/0/9
spanning-tree portfast
!
interface GigabitEthernet2/0/10
spanning-tree portfast
!
interface GigabitEthernet2/0/11
spanning-tree portfast
!
interface GigabitEthernet2/0/12
spanning-tree portfast
!
interface GigabitEthernet2/0/13
spanning-tree portfast
!
interface GigabitEthernet2/0/14
spanning-tree portfast
!
interface GigabitEthernet2/0/15
spanning-tree portfast
!
interface GigabitEthernet2/0/16
spanning-tree portfast
!
interface GigabitEthernet2/0/17
spanning-tree portfast
!
interface GigabitEthernet2/0/18
spanning-tree portfast
!
interface GigabitEthernet2/0/19
spanning-tree portfast
!
interface GigabitEthernet2/0/20
spanning-tree portfast
!
interface GigabitEthernet2/0/21
spanning-tree portfast
!
interface GigabitEthernet2/0/22
spanning-tree portfast
!
interface GigabitEthernet2/0/23
spanning-tree portfast
!
interface GigabitEthernet2/0/24
spanning-tree portfast
!
interface GigabitEthernet2/0/25
spanning-tree portfast
!
interface GigabitEthernet2/0/26
spanning-tree portfast
!
interface GigabitEthernet2/0/27
spanning-tree portfast
!
interface GigabitEthernet2/0/28
spanning-tree portfast
!
interface GigabitEthernet2/0/29
spanning-tree portfast
!
interface GigabitEthernet2/0/30
spanning-tree portfast
!
interface GigabitEthernet2/0/31
spanning-tree portfast
!
interface GigabitEthernet2/0/32
spanning-tree portfast
!
interface GigabitEthernet2/0/33
spanning-tree portfast
!
interface GigabitEthernet2/0/34
spanning-tree portfast
!
interface GigabitEthernet2/0/35
spanning-tree portfast
!
interface GigabitEthernet2/0/36
spanning-tree portfast
!
interface GigabitEthernet2/0/37
spanning-tree portfast
!
interface GigabitEthernet2/0/38
spanning-tree portfast
!
interface GigabitEthernet2/0/39
spanning-tree portfast
!
interface GigabitEthernet2/0/40
spanning-tree portfast
!
interface GigabitEthernet2/0/41
spanning-tree portfast
!
interface GigabitEthernet2/0/42
spanning-tree portfast
!
interface GigabitEthernet2/0/43
spanning-tree portfast
!
interface GigabitEthernet2/0/44
switchport trunk allowed vlan 2
spanning-tree portfast
!
interface GigabitEthernet2/0/45
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 1,2
switchport mode trunk
spanning-tree portfast
!
interface GigabitEthernet2/0/46
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 1,2
switchport mode trunk
spanning-tree portfast
!
interface GigabitEthernet2/0/47
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 1,2
switchport mode trunk
spanning-tree portfast
!
interface GigabitEthernet2/0/48
switchport access vlan 2
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 1,2
switchport mode trunk
spanning-tree portfast
!
interface GigabitEthernet2/1/1
!
interface GigabitEthernet2/1/2
!
interface GigabitEthernet2/1/3
!
interface GigabitEthernet2/1/4
!
interface TenGigabitEthernet2/1/1
!
interface TenGigabitEthernet2/1/2
!
interface Vlan1
ip address 10.10.6.20 255.255.255.0
!
interface Vlan2
description guestwifi
no ip address
no ip redirects
!
ip default-gateway 10.10.6.1
ip classless
ip http server
ip http secure-server
!
ip sla enable reaction-alerts
logging trap notifications


router config is here

ip dhcp excluded-address vrf CustVRF2 10.30.30.1 10.30.30.10

!

ip dhcp pool CLIENT

vrf CustVRF2

network 10.30.30.0 255.255.255.0

default-router 10.30.30.1

dns-server 79.79.79.78 195.74.130.35



Thanks for any advice

1 Accepted Solution

Accepted Solutions

 Where is the DHCP server?

And if you have only vlan 1 and 2, and vlan 2 needs to be native (it seems ). You dont need trunk.  Just put the port in access mode.

int gigabitEthernet 2/0/47

switchport mode access

switchport access vlan 2

 

View solution in original post

8 Replies 8

Hi

 Dont configure the port like this:


interface GigabitEthernet2/0/48
switchport access vlan 2
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 1,2
switchport mode trunk
spanning-tree portfast
!

Do this:

conf t

default interface GigabitEthernet2/0/48

int GigabitEthernet2/0/48

switchport mode trunk

switchport trunk encapsulation dot1q
switchport trunk allowed vlan 1,2
 
!

don't seem to be getting any ip address at all now. here is 2/0/48 now and also interface switchport for 2/0/48

interface GigabitEthernet2/0/48
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 1,2
switchport mode trunk



CAB_G_SW_1-2#show interfaces gigabitEthernet2/0/48 switchport
Name: Gi2/0/48
Switchport: Enabled
Administrative Mode: trunk
Operational Mode: trunk
Administrative Trunking Encapsulation: dot1q
Operational Trunking Encapsulation: dot1q
Negotiation of Trunking: On
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
Administrative private-vlan host-association: none
Administrative private-vlan mapping: none
Administrative private-vlan trunk native VLAN: none
Administrative private-vlan trunk Native VLAN tagging: enabled
Administrative private-vlan trunk encapsulation: dot1q
Administrative private-vlan trunk normal VLANs: none
Administrative private-vlan trunk associations: none
Administrative private-vlan trunk mappings: none
Operational private-vlan: none
Trunking VLANs Enabled: 1,2
Pruning VLANs Enabled: 2-1001
Capture Mode Disabled
Capture VLANs Allowed: ALL

Protected: false
Unknown unicast blocked: disabled
Unknown multicast blocked: disabled
Appliance trust: none

that´s because you need Native vlan.  Which means, your device is not able to tag the management traffic and will offer DHCP only in a untagged vlan. That´s why when you enter switchport access it works, because you are not using trunk but access.

 Do this:

interface GigabitEthernet2/0/48

switchport trunk native vlan 2

so config is now as follows is now as follows

CAB_G_SW_1-2#show interfaces gigabitEthernet 2/0/48 switchport
Name: Gi2/0/48
Switchport: Enabled
Administrative Mode: trunk
Operational Mode: trunk
Administrative Trunking Encapsulation: dot1q
Operational Trunking Encapsulation: dot1q
Negotiation of Trunking: On
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 2 (guestwifi)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
Administrative private-vlan host-association: none
Administrative private-vlan mapping: none
Administrative private-vlan trunk native VLAN: none
Administrative private-vlan trunk Native VLAN tagging: enabled
Administrative private-vlan trunk encapsulation: dot1q
Administrative private-vlan trunk normal VLANs: none
Administrative private-vlan trunk associations: none
Administrative private-vlan trunk mappings: none
Operational private-vlan: none
Trunking VLANs Enabled: 2
Pruning VLANs Enabled: 2-1001
Capture Mode Disabled
Capture VLANs Allowed: ALL

Protected: false
Unknown unicast blocked: disabled
Unknown multicast blocked: disabled
Appliance trust: none

interface GigabitEthernet2/0/48
switchport trunk encapsulation dot1q
switchport trunk native vlan 1,2
switchport trunk allowed vlan 2
switchport mode trunk


still 169. ip address when checking on unifi 


this is 47 on the switch if this is any help

show interfaces gigabitEthernet 2/0/47 switchport
Name: Gi2/0/47
Switchport: Enabled
Administrative Mode: trunk
Operational Mode: trunk
Administrative Trunking Encapsulation: dot1q
Operational Trunking Encapsulation: dot1q
Negotiation of Trunking: On
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
Administrative private-vlan host-association: none
Administrative private-vlan mapping: none
Administrative private-vlan trunk native VLAN: none
Administrative private-vlan trunk Native VLAN tagging: enabled
Administrative private-vlan trunk encapsulation: dot1q
Administrative private-vlan trunk normal VLANs: none
Administrative private-vlan trunk associations: none
Administrative private-vlan trunk mappings: none
Operational private-vlan: none
Trunking VLANs Enabled: 1,2
Pruning VLANs Enabled: 2-1001
Capture Mode Disabled
Capture VLANs Allowed: ALL

Protected: false
Unknown unicast blocked: disabled
Unknown multicast blocked: disabled
Appliance trust: none



 Where is the DHCP server?

And if you have only vlan 1 and 2, and vlan 2 needs to be native (it seems ). You dont need trunk.  Just put the port in access mode.

int gigabitEthernet 2/0/47

switchport mode access

switchport access vlan 2

 

Got it working \o/

in the end i ran default interface GigabitEthernet2/0/45-8

switchport trunk encapsulation dot1q
switchport mode trunk
spanning-tree portfast

on 45-47 

on 48
switchport access vlan 2
switchport trunk native vlan 2


and we are now getting 10.30.30.x ip addresses on the guest.

Appreciate the help Flavio, pushed me in the right directions

 I still dont agree with the config on port 48 hahaha....but....if worked that´s what matter. 

 Go for it!

Yes just to clarify what Flavio is saying:
switchport access vlan 2 only applies if the port is in mode access.
switchport trunk native vlan 2 only applies if the port is in mode trunk.
They both have the effect of ensuring that vlan 2 is untagged but only one of those commands will ever be active so applying both is pointless - only use the one which is appropriate to the switchport mode you're using.

Review Cisco Networking for a $25 gift card