cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
13344
Views
0
Helpful
14
Replies

Wireless clients don't receive IP addresses (DHCP)

Sam_I_Am.
Level 1
Level 1

Hello,

I have a 3502i ap and a WLC 5508, software version 8.0.100.0, currently under configuration.  After following configuration guides and trying to get clients to function on the wireless network, I came to a roadblock with the client being recognized by the controller but not receiving an IP address.  I get a "Acquiring network address" whenever I try to connect on the client laptop and it doesn't move from there.  The WLC does recognize the client's MAC address, but the IP reads 0.0.0.0.

On the WLAN, I don't have Layer 2 or Layer 3 security turned on.  I have clients for the Interface/Interfaces Group(G).  I do not have the DHCP Override radio button turned on because it's to my understanding it is for internal DHCP, which is disabled.  As for the Controller, the interface named "clients" is on a seperate vlan than the management and APs.  The primary and secondary DHCP servers on this interface are the client vlan's IP and the helper address on the vlan (the helper address points to a GUI accessible Infoblox, which has a scope of available IPs).  DHCP proxy is disabled and so is option 82.  I have no form of IPv6 turned on that I could check for.  I'm not sure if it's hurting, but the same DHCP parameters are set for the management interface; it's just the interface itself is set for a different subnet.

I tried to search through this forum for the answer, but it seems each situation is unique and with different variables involved.  Or at least I'm interpeting them differently.

1 Accepted Solution

Accepted Solutions

So how are clients going to get a DHCP assigned IP when you're having to manually assign them to the same clients on the wire?  Are the wireless clients also statically assigned?  If so, do you have "DHCP Required" un-checked on the WLAN's Advanced tab? 

Is there supposed to be DHCP or not?  If so, when the wired clients can pull an IP address via DHCP properly on that same VLAN of that switch, then your wireless clients should follow suit.

View solution in original post

14 Replies 14

David Watkins
Level 4
Level 4

Can you show a client debug?  Also

 

#config paging disable

#show WLAN <id>

#show interface summary

#show interface group detailed <iface-group-name.

 

David,

In the above response to Steven Rodriguez, I posted the >show interface results.  Pasted below here are the debug results:

 

*DHCP Socket Task: Dec 15 14:32:59.747: 00:0e:35:0a:0c:35 DHCP successfully bridged packet to DS

*emWeb: Dec 16 13:56:51.818:  Configuring IPv6 ACL for WLAN:2, aclName passed is NULL

*apfMsConnTask_7: Dec 16 13:57:04.257: 00:0e:35:0a:0c:35 Processing assoc-req station:00:0e:35:0a:0c:35 AP:70:10:5c:b0:b3:20-00 thread:150e50c0

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 Adding mobile on LWAPP AP 70:10:5c:b0:b3:20(0)

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 Association received from mobile on BSSID 70:10:5c:b0:b3:21 AP 1622_1st

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 Global 200 Clients are allowed to AP radio

 

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 Max Client Trap Threshold: 0  cur: 0

 

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 Rf profile 600 Clients are allowed to AP wlan

 

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 override for default ap group, marking intgrp NULL

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 Applying Interface policy on Mobile, role Unassociated. Ms NAC State 0 Quarantine Vlan 0 Access Vlan 0

 

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 Re-applying interface policy for client

 

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 0.0.0.0 START (0) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2385)

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 0.0.0.0 START (0) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2406)

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 apfApplyWlanPolicy: Apply WLAN Policy over PMIPv6 Client Mobility Type

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 In processSsidIE:5680 setting Central switched to TRUE

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 In processSsidIE:5683 apVapId = 2 and Split Acl Id = 65535

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 Applying site-specific Local Bridging override for station 00:0e:35:0a:0c:35 - vapId 2, site 'default-group', interface 'clients'

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 Applying Local Bridging Interface Policy for station 00:0e:35:0a:0c:35 - vlan 13, interface id 12, interface 'clients'

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 processSsidIE  statusCode is 0 and status is 0

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 processSsidIE  ssid_done_flag is 0 finish_flag is 0

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 STA - rates (8): 130 132 139 12 18 150 24 36 0 0 0 0 0 0 0 0

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 suppRates  statusCode is 0 and gotSuppRatesElement is 1

*apfMsConnTask_7: Dec 16 13:57:04.258: 00:0e:35:0a:0c:35 STA - rates (12): 130 132 139 12 18 150 24 36 48 72 96 108 0 0 0 0

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 extSuppRates  statusCode is 0 and gotExtSuppRatesElement is 1

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 0.0.0.0 START (0) Initializing policy

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 0.0.0.0 START (0) Change state to AUTHCHECK (2) last state START (0)

 

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 0.0.0.0 AUTHCHECK (2) Change state to L2AUTHCOMPLETE (4) last state AUTHCHECK (2)

 

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 Not Using WMM Compliance code qosCap 00

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 Sending 11w Flag 0 for Client 00:0E:35:0A:0C:35

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 0.0.0.0 L2AUTHCOMPLETE (4) Plumbed mobile LWAPP rule on AP 70:10:5c:b0:b3:20 vapId 2 apVapId 2 flex-acl-name:

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 0.0.0.0 L2AUTHCOMPLETE (4) Change state to DHCP_REQD (7) last state L2AUTHCOMPLETE (4)

 

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 apfMsAssoStateInc

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 apfMsOpenStateInc

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 apfPemAddUser2 (apf_policy.c:352) Changing state for mobile 00:0e:35:0a:0c:35 on AP 70:10:5c:b0:b3:20 from Idle to Associated

 

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 apfPemAddUser2:session timeout forstation 00:0e:35:0a:0c:35 - Session Tout 1800, apfMsTimeOut '1800' and sessionTimerRunning flag is  0

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 Scheduling deletion of Mobile Station:  (callerId: 49) in 1800 seconds

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 Func: apfPemAddUser2, Ms Timeout = 1800, Session Timeout = 1800

 

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 Sending assoc-resp with status 0 station:00:0e:35:0a:0c:35 AP:70:10:5c:b0:b3:20-00 on apVapId 2

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 Sending Assoc Response to station on BSSID 70:10:5c:b0:b3:21 (status 0) ApVapId 2 Slot 0

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 apfProcessAssocReq (apf_80211.c:9452) Changing state for mobile 00:0e:35:0a:0c:35 on AP 70:10:5c:b0:b3:20 from Associated to Associated

 

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 Mobility query, PEM State: DHCP_REQD

 

*apfMsConnTask_7: Dec 16 13:57:04.259: 00:0e:35:0a:0c:35 Building Mobile Announce :

 

*apfMsConnTask_7: Dec 16 13:57:04.260: 00:0e:35:0a:0c:35   Building Client Payload:

 

*apfMsConnTask_7: Dec 16 13:57:04.260: 00:0e:35:0a:0c:35     Client Ip: 0.0.0.0

 

*apfMsConnTask_7: Dec 16 13:57:04.260: 00:0e:35:0a:0c:35     Client Vlan Ip: 10.10.3.254 Vlan mask : 255.255.255.0

 

*apfMsConnTask_7: Dec 16 13:57:04.260: 00:0e:35:0a:0c:35     Client Vap Security: 0

 

*apfMsConnTask_7: Dec 16 13:57:04.260: 00:0e:35:0a:0c:35     Virtual Ip: 1.1.1.1

 

*apfMsConnTask_7: Dec 16 13:57:04.260: 00:0e:35:0a:0c:35     ssid: Diddly

 

*apfMsConnTask_7: Dec 16 13:57:04.260: 00:0e:35:0a:0c:35   Building VlanIpPayload.

 

*apfReceiveTask: Dec 16 13:57:04.260: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) mobility role update request from Unassociated to Local

  Peer = 0.0.0.0, Old Anchor = 0.0.0.0, New Anchor = 10.10.6.128

*apfReceiveTask: Dec 16 13:57:04.260: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) State Update from Mobility-Incomplete to Mobility-Complete, mobility role=Local, client state=APF_MS_STATE_ASSOCIATED

*apfReceiveTask: Dec 16 13:57:04.260: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) pemAdvanceState2 6102, Adding TMP rule

*apfReceiveTask: Dec 16 13:57:04.260: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Adding Fast Path rule

  type = Airespace AP - Learn IP address

  on AP 70:10:5c:b0:b3:20, slot 0, interface = 1, QOS = 0

  IPv4 ACL ID = 255, IPv

*apfReceiveTask: Dec 16 13:57:04.260: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) 802.1P = 0, DSCP = 0, TokenID = 15206, IntfId = 12  Local Bridging Vlan = 13, Local Bridging intf id = 12

*apfReceiveTask: Dec 16 13:57:04.260: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) AVC Ratelimit:  AppID = 0 ,AppAction = 0, AppToken = 15206  AverageRate = 0, BurstRate = 0

 

*apfReceiveTask: Dec 16 13:57:04.260: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) AVC Ratelimit:  AppID = 0 ,AppAction = 0, AppToken = 15206  AverageRate = 0, BurstRate = 0

 

*apfReceiveTask: Dec 16 13:57:04.260: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) AVC Ratelimit:  AppID = 0 ,AppAction = 0, AppToken = 15206  AverageRate = 0, BurstRate = 0

 

*apfReceiveTask: Dec 16 13:57:04.260: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Successfully plumbed mobile rule (IPv4 ACL ID 255, IPv6 ACL ID 255, L2 ACL ID 255)

*pemReceiveTask: Dec 16 13:57:04.261: 00:0e:35:0a:0c:35 0.0.0.0 Added NPU entry of type 9, dtlFlags 0x0

*pemReceiveTask: Dec 16 13:57:04.261: 00:0e:35:0a:0c:35 Sent an XID frame

*apfMsConnTask_7: Dec 16 13:57:04.264: 00:0e:35:0a:0c:35 Processing assoc-req station:00:0e:35:0a:0c:35 AP:70:10:5c:b0:b3:20-00 thread:150e50c0

*apfMsConnTask_7: Dec 16 13:57:04.318: 00:0e:35:0a:0c:35 Processing assoc-req station:00:0e:35:0a:0c:35 AP:70:10:5c:b0:b3:20-00 thread:150e50c0

*apfMsConnTask_7: Dec 16 13:57:04.318: 00:0e:35:0a:0c:35 Association received from mobile on BSSID 70:10:5c:b0:b3:21 AP 1622_1st

*apfMsConnTask_7: Dec 16 13:57:04.318: 00:0e:35:0a:0c:35 Global 200 Clients are allowed to AP radio

 

*apfMsConnTask_7: Dec 16 13:57:04.318: 00:0e:35:0a:0c:35 Max Client Trap Threshold: 0  cur: 1

 

*apfMsConnTask_7: Dec 16 13:57:04.318: 00:0e:35:0a:0c:35 Rf profile 600 Clients are allowed to AP wlan

 

*apfMsConnTask_7: Dec 16 13:57:04.318: 00:0e:35:0a:0c:35 override for default ap group, marking intgrp NULL

*apfMsConnTask_7: Dec 16 13:57:04.318: 00:0e:35:0a:0c:35 Applying Interface policy on Mobile, role Local. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 13

 

*apfMsConnTask_7: Dec 16 13:57:04.318: 00:0e:35:0a:0c:35 Re-applying interface policy for client

 

*apfMsConnTask_7: Dec 16 13:57:04.318: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2385)

*apfMsConnTask_7: Dec 16 13:57:04.318: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2406)

*apfMsConnTask_7: Dec 16 13:57:04.318: 00:0e:35:0a:0c:35 apfApplyWlanPolicy: Apply WLAN Policy over PMIPv6 Client Mobility Type

*apfMsConnTask_7: Dec 16 13:57:04.318: 00:0e:35:0a:0c:35 In processSsidIE:5680 setting Central switched to TRUE

*apfMsConnTask_7: Dec 16 13:57:04.318: 00:0e:35:0a:0c:35 In processSsidIE:5683 apVapId = 2 and Split Acl Id = 65535

*apfMsConnTask_7: Dec 16 13:57:04.318: 00:0e:35:0a:0c:35 Applying site-specific Local Bridging override for station 00:0e:35:0a:0c:35 - vapId 2, site 'default-group', interface 'clients'

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 Applying Local Bridging Interface Policy for station 00:0e:35:0a:0c:35 - vlan 13, interface id 12, interface 'clients'

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 processSsidIE  statusCode is 0 and status is 0

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 processSsidIE  ssid_done_flag is 0 finish_flag is 0

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 STA - rates (8): 130 132 139 12 18 150 24 36 48 72 96 108 0 0 0 0

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 suppRates  statusCode is 0 and gotSuppRatesElement is 1

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 STA - rates (12): 130 132 139 12 18 150 24 36 48 72 96 108 0 0 0 0

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 extSuppRates  statusCode is 0 and gotExtSuppRatesElement is 1

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 apfMs1xStateDec

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Change state to START (0) last state DHCP_REQD (7)

 

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 pemApfAddMobileStation2: APF_MS_PEM_WAIT_L2_AUTH_COMPLETE = 0.

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 0.0.0.0 START (0) Initializing policy

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 0.0.0.0 START (0) Change state to AUTHCHECK (2) last state START (0)

 

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 0.0.0.0 AUTHCHECK (2) Change state to L2AUTHCOMPLETE (4) last state AUTHCHECK (2)

 

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 Not Using WMM Compliance code qosCap 00

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 Sending 11w Flag 0 for Client 00:0E:35:0A:0C:35

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 0.0.0.0 L2AUTHCOMPLETE (4) Plumbed mobile LWAPP rule on AP 70:10:5c:b0:b3:20 vapId 2 apVapId 2 flex-acl-name:

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 0.0.0.0 L2AUTHCOMPLETE (4) Change state to DHCP_REQD (7) last state L2AUTHCOMPLETE (4)

 

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) pemApfAddMobileStation2 3735, Adding TMP rule

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Adding Fast Path rule

  type = Airespace AP - Learn IP address

  on AP 70:10:5c:b0:b3:20, slot 0, interface = 1, QOS = 0

  IPv4 ACL ID = 255, IPv

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) 802.1P = 0, DSCP = 0, TokenID = 15206, IntfId = 12  Local Bridging Vlan = 13, Local Bridging intf id = 12

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) AVC Ratelimit:  AppID = 0 ,AppAction = 0, AppToken = 15206  AverageRate = 0, BurstRate = 0

 

*apfMsConnTask_7: Dec 16 13:57:04.319: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) AVC Ratelimit:  AppID = 0 ,AppAction = 0, AppToken = 15206  AverageRate = 0, BurstRate = 0

 

*apfMsConnTask_7: Dec 16 13:57:04.320: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) AVC Ratelimit:  AppID = 0 ,AppAction = 0, AppToken = 15206  AverageRate = 0, BurstRate = 0

 

*apfMsConnTask_7: Dec 16 13:57:04.320: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Successfully plumbed mobile rule (IPv4 ACL ID 255, IPv6 ACL ID 255, L2 ACL ID 255)

*apfMsConnTask_7: Dec 16 13:57:04.320: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) pemApfAddMobileStation2 3923, Adding TMP rule

*apfMsConnTask_7: Dec 16 13:57:04.320: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Replacing Fast Path rule

  type = Airespace AP - Learn IP address

  on AP 70:10:5c:b0:b3:20, slot 0, interface = 1, QOS = 0

  IPv4 ACL ID = 255,

*apfMsConnTask_7: Dec 16 13:57:04.320: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) 802.1P = 0, DSCP = 0, TokenID = 15206, IntfId = 12  Local Bridging Vlan = 13, Local Bridging intf id = 12

*apfMsConnTask_7: Dec 16 13:57:04.320: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) AVC Ratelimit:  AppID = 0 ,AppAction = 0, AppToken = 15206  AverageRate = 0, BurstRate = 0

 

*apfMsConnTask_7: Dec 16 13:57:04.320: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) AVC Ratelimit:  AppID = 0 ,AppAction = 0, AppToken = 15206  AverageRate = 0, BurstRate = 0

 

*apfMsConnTask_7: Dec 16 13:57:04.320: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Fast Path rule (contd...) AVC Ratelimit:  AppID = 0 ,AppAction = 0, AppToken = 15206  AverageRate = 0, BurstRate = 0

 

*apfMsConnTask_7: Dec 16 13:57:04.320: 00:0e:35:0a:0c:35 0.0.0.0 DHCP_REQD (7) Successfully plumbed mobile rule (IPv4 ACL ID 255, IPv6 ACL ID 255, L2 ACL ID 255)

*apfMsConnTask_7: Dec 16 13:57:04.320: 00:0e:35:0a:0c:35 apfPemAddUser2 (apf_policy.c:352) Changing state for mobile 00:0e:35:0a:0c:35 on AP 70:10:5c:b0:b3:20 from Associated to Associated

 

*apfMsConnTask_7: Dec 16 13:57:04.320: 00:0e:35:0a:0c:35 apfPemAddUser2:session timeout forstation 00:0e:35:0a:0c:35 - Session Tout 1800, apfMsTimeOut '1800' and sessionTimerRunning flag is  0

*apfMsConnTask_7: Dec 16 13:57:04.320: 00:0e:35:0a:0c:35 Scheduling deletion of Mobile Station:  (callerId: 49) in 1800 seconds

*apfMsConnTask_7: Dec 16 13:57:04.320: 00:0e:35:0a:0c:35 Func: apfPemAddUser2, Ms Timeout = 1800, Session Timeout = 1800

 

*pemReceiveTask: Dec 16 13:57:04.320: 00:0e:35:0a:0c:35 0.0.0.0 Removed NPU entry.

*apfMsConnTask_7: Dec 16 13:57:04.320: 00:0e:35:0a:0c:35 Sending assoc-resp with status 0 station:00:0e:35:0a:0c:35 AP:70:10:5c:b0:b3:20-00 on apVapId 2

*apfMsConnTask_7: Dec 16 13:57:04.320: 00:0e:35:0a:0c:35 Sending Assoc Response to station on BSSID 70:10:5c:b0:b3:21 (status 0) ApVapId 2 Slot 0

*apfMsConnTask_7: Dec 16 13:57:04.320: 00:0e:35:0a:0c:35 apfProcessAssocReq (apf_80211.c:9452) Changing state for mobile 00:0e:35:0a:0c:35 on AP 70:10:5c:b0:b3:20 from Associated to Associated

 

*pemReceiveTask: Dec 16 13:57:04.321: 00:0e:35:0a:0c:35 0.0.0.0 Added NPU entry of type 9, dtlFlags 0x0

*pemReceiveTask: Dec 16 13:57:04.321: 00:0e:35:0a:0c:35 0.0.0.0 Added NPU entry of type 9, dtlFlags 0x0

*DHCP Socket Task: Dec 16 13:57:07.372: 00:0e:35:0a:0c:35 DHCP received op BOOTREQUEST (1) (len 312,vlan 16, port 1, encap 0xec03)

*DHCP Socket Task: Dec 16 13:57:07.372: 00:0e:35:0a:0c:35 DHCP (encap type 0xec03) mstype 0ff:ff:ff:ff:ff:ff

*DHCP Socket Task: Dec 16 13:57:07.372: 00:0e:35:0a:0c:35 DHCP processing DHCP DISCOVER (1)

*DHCP Socket Task: Dec 16 13:57:07.372: 00:0e:35:0a:0c:35 DHCP   op: BOOTREQUEST, htype: Ethernet, hlen: 6, hops: 0

*DHCP Socket Task: Dec 16 13:57:07.372: 00:0e:35:0a:0c:35 DHCP   xid: 0xd8947c74 (3633609844), secs: 0, flags: 0

*DHCP Socket Task: Dec 16 13:57:07.372: 00:0e:35:0a:0c:35 DHCP   chaddr: 00:0e:35:0a:0c:35

*DHCP Socket Task: Dec 16 13:57:07.372: 00:0e:35:0a:0c:35 DHCP   ciaddr: 0.0.0.0,  yiaddr: 0.0.0.0

*DHCP Socket Task: Dec 16 13:57:07.372: 00:0e:35:0a:0c:35 DHCP   siaddr: 0.0.0.0,  giaddr: 0.0.0.0

*DHCP Socket Task: Dec 16 13:57:07.372: 00:0e:35:0a:0c:35 DHCP   requested ip: 169.254.99.106

*DHCP Socket Task: Dec 16 13:57:07.372: 00:0e:35:0a:0c:35 DHCP Opt82 bridge mode insertion enabled, inserts opt82 if opt82 is enabled vlan=13, datalen =18, optlen=68

*DHCP Socket Task: Dec 16 13:57:07.372: 00:0e:35:0a:0c:35 DHCP successfully bridged packet to DS

*DHCP Socket Task: Dec 16 13:57:11.375: 00:0e:35:0a:0c:35 DHCP received op BOOTREQUEST (1) (len 312,vlan 16, port 1, encap 0xec03)

*DHCP Socket Task: Dec 16 13:57:11.375: 00:0e:35:0a:0c:35 DHCP (encap type 0xec03) mstype 0ff:ff:ff:ff:ff:ff

*DHCP Socket Task: Dec 16 13:57:11.375: 00:0e:35:0a:0c:35 DHCP processing DHCP DISCOVER (1)

*DHCP Socket Task: Dec 16 13:57:11.375: 00:0e:35:0a:0c:35 DHCP   op: BOOTREQUEST, htype: Ethernet, hlen: 6, hops: 0

*DHCP Socket Task: Dec 16 13:57:11.375: 00:0e:35:0a:0c:35 DHCP   xid: 0xd8947c74 (3633609844), secs: 1024, flags: 0

*DHCP Socket Task: Dec 16 13:57:11.375: 00:0e:35:0a:0c:35 DHCP   chaddr: 00:0e:35:0a:0c:35

*DHCP Socket Task: Dec 16 13:57:11.375: 00:0e:35:0a:0c:35 DHCP   ciaddr: 0.0.0.0,  yiaddr: 0.0.0.0

*DHCP Socket Task: Dec 16 13:57:11.375: 00:0e:35:0a:0c:35 DHCP   siaddr: 0.0.0.0,  giaddr: 0.0.0.0

*DHCP Socket Task: Dec 16 13:57:11.375: 00:0e:35:0a:0c:35 DHCP   requested ip: 169.254.99.106

*DHCP Socket Task: Dec 16 13:57:11.375: 00:0e:35:0a:0c:35 DHCP Opt82 bridge mode insertion enabled, inserts opt82 if opt82 is enabled vlan=13, datalen =18, optlen=68

*DHCP Socket Task: Dec 16 13:57:11.375: 00:0e:35:0a:0c:35 DHCP successfully bridged packet to DS

*DHCP Socket Task: Dec 16 13:57:20.378: 00:0e:35:0a:0c:35 DHCP received op BOOTREQUEST (1) (len 312,vlan 16, port 1, encap 0xec03)

*DHCP Socket Task: Dec 16 13:57:20.379: 00:0e:35:0a:0c:35 DHCP (encap type 0xec03) mstype 0ff:ff:ff:ff:ff:ff

*DHCP Socket Task: Dec 16 13:57:20.379: 00:0e:35:0a:0c:35 DHCP processing DHCP DISCOVER (1)

*DHCP Socket Task: Dec 16 13:57:20.379: 00:0e:35:0a:0c:35 DHCP   op: BOOTREQUEST, htype: Ethernet, hlen: 6, hops: 0

*DHCP Socket Task: Dec 16 13:57:20.379: 00:0e:35:0a:0c:35 DHCP   xid: 0xd8947c74 (3633609844), secs: 3328, flags: 0

*DHCP Socket Task: Dec 16 13:57:20.379: 00:0e:35:0a:0c:35 DHCP   chaddr: 00:0e:35:0a:0c:35

*DHCP Socket Task: Dec 16 13:57:20.379: 00:0e:35:0a:0c:35 DHCP   ciaddr: 0.0.0.0,  yiaddr: 0.0.0.0

*DHCP Socket Task: Dec 16 13:57:20.379: 00:0e:35:0a:0c:35 DHCP   siaddr: 0.0.0.0,  giaddr: 0.0.0.0

*DHCP Socket Task: Dec 16 13:57:20.379: 00:0e:35:0a:0c:35 DHCP   requested ip: 169.254.99.106

*DHCP Socket Task: Dec 16 13:57:20.379: 00:0e:35:0a:0c:35 DHCP Opt82 bridge mode insertion enabled, inserts opt82 if opt82 is enabled vlan=13, datalen =18, optlen=68

*DHCP Socket Task: Dec 16 13:57:20.379: 00:0e:35:0a:0c:35 DHCP successfully bridged packet to DS

*DHCP Socket Task: Dec 16 13:57:20.379: 00:0e:35:0a:0c:35 Interface Group was NULL.Number of DHCP Discovery 3 from client

*DHCP Socket Task: Dec 16 13:57:36.382: 00:0e:35:0a:0c:35 DHCP received op BOOTREQUEST (1) (len 312,vlan 16, port 1, encap 0xec03)

*DHCP Socket Task: Dec 16 13:57:36.383: 00:0e:35:0a:0c:35 DHCP (encap type 0xec03) mstype 0ff:ff:ff:ff:ff:ff

*DHCP Socket Task: Dec 16 13:57:36.383: 00:0e:35:0a:0c:35 DHCP processing DHCP DISCOVER (1)

*DHCP Socket Task: Dec 16 13:57:36.383: 00:0e:35:0a:0c:35 DHCP   op: BOOTREQUEST, htype: Ethernet, hlen: 6, hops: 0

*DHCP Socket Task: Dec 16 13:57:36.383: 00:0e:35:0a:0c:35 DHCP   xid: 0xd8947c74 (3633609844), secs: 7424, flags: 0

*DHCP Socket Task: Dec 16 13:57:36.383: 00:0e:35:0a:0c:35 DHCP   chaddr: 00:0e:35:0a:0c:35

*DHCP Socket Task: Dec 16 13:57:36.383: 00:0e:35:0a:0c:35 DHCP   ciaddr: 0.0.0.0,  yiaddr: 0.0.0.0

*DHCP Socket Task: Dec 16 13:57:36.383: 00:0e:35:0a:0c:35 DHCP   siaddr: 0.0.0.0,  giaddr: 0.0.0.0

*DHCP Socket Task: Dec 16 13:57:36.383: 00:0e:35:0a:0c:35 DHCP   requested ip: 169.254.99.106

*DHCP Socket Task: Dec 16 13:57:36.383: 00:0e:35:0a:0c:35 DHCP Opt82 bridge mode insertion enabled, inserts opt82 if opt82 is enabled vlan=13, datalen =18, optlen=68

 

 

Ok, so I can see where the WLC is saying it is sending the packet to the wire:successfully bridged packet to DS

But there is no response from the DHCP server. 

There are option 82 messages:

 Opt82 bridge mode insertion enabled, inserts opt82 if opt82 is enabled vlan=13

 Opt82 bridge mode insertion enabled, inserts opt82 if opt82 is enabled vlan=16

 

Did you have option 82 enabled at some point? If so, did you save config and reboot the WLC?

Can you try to reboot the WLC?

 

--

Steve

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

I double checked the interfaces and all instances of Opt 82 are disabled.  I rebooted the controller and attempted to connect, but I got the same result.

Can you post the config of the switch port(s) the WLC is connected to ?

 

--

Steve

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

interface GigabitEthernet9/2
 switchport
 switchport trunk encapsulation dot1q
 switchport mode trunk
end
 

So if you take a "wired" client and place it in an access port on that same switch via VLAN 113; does it pull an IP address?  I would make that work first, then take a look at the WLC next.

I have a local switch trunked to a 6500 (where the vlan is configured).  On the local switch, I have access ports with the vlan and the client works on them only if I assign a static IP to the client.

So how are clients going to get a DHCP assigned IP when you're having to manually assign them to the same clients on the wire?  Are the wireless clients also statically assigned?  If so, do you have "DHCP Required" un-checked on the WLAN's Advanced tab? 

Is there supposed to be DHCP or not?  If so, when the wired clients can pull an IP address via DHCP properly on that same VLAN of that switch, then your wireless clients should follow suit.

Good point.  I'll get on that and let you know of the results tomorrow at the earliest.

Thanks for being blunt.   I got the issue resolved.  There was a misconfiguration on the Infoblox not allowing leasing of IPs.

Stephen Rodriguez
Cisco Employee
Cisco Employee

So, DHCP Override in the WLAN configuration is used to supersede the configured DHCP server at the interface level.

 

Now, did you globally disable  DHCP Proxy? or is it just under the interface/wlan?

are you able to sniff the WLC port and see if the DHPC request is being sent out?

 

and of course are you allowing the client VLAN across the trunk like to the WLC? IF you do a show interface < interface to the WLC > trunk is the VLAN allowed and not pruned?

 

--

Steve

 

--

Steve

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

I have the proxy disabled both on the VLAN and under the Advanced tab. I debugged the client while it was searching for an IP. I will paste the client debug for David Watkins below.  But here are the >show interface results:

 

(Cisco Controller) >show interface summary

 Number of Interfaces.......................... 6

Interface Name                   Port Vlan Id  IP Address      Type    Ap Mgr Guest

-------------------------------- ---- -------- --------------- ------- ------ -----

clients                          1    113      10.10.3.254  Dynamic No     No

management                       1    116      10.10.6.128  Static  Yes    No

redundancy-management            1    116      0.0.0.0         Static  No     No

redundancy-port                  -    untagged 0.0.0.0         Static  No     No

service-port                     N/A  N/A      172.16.0.1      Static  No     No

virtual                          N/A  N/A      1.1.1.1         Static  No     No

 

(Cisco Controller) >show interface detailed management

Interface Name................................... management

MAC Address...................................... 4c:4e:35:7e:42:c0

IP Address....................................... 10.10.6.128

IP Netmask....................................... 255.255.255.0

IP Gateway....................................... 10.10.6.1

External NAT IP State............................ Disabled

External NAT IP Address.......................... 0.0.0.0

Link Local IPv6 Address.......................... fe80::4e4e:35ff:fe7e:42c0/64

STATE ........................................... REACHABLE

Primary IPv6 Address............................. ::/128

STATE ........................................... NONE

Primary IPv6 Gateway............................. ::

Primary IPv6 Gateway Mac Address................. 00:00:00:00:00:00

STATE ........................................... INCOMPLETE

VLAN............................................. 116

Quarantine-vlan.................................. 0

Active Physical Port............................. 1

Primary Physical Port............................ 1

Backup Physical Port............................. 2

DHCP Proxy Mode.................................. Disabled

Primary DHCP Server.............................. 10.10.3.1

Secondary DHCP Server............................ 10.10.5.5

DHCP Option 82................................... Disabled

DHCP Option 82 bridge mode insertion............. Disabled

IPv4 ACL......................................... Unconfigured

IPv6 ACL......................................... Unconfigured

mDNS Profile Name................................ Unconfigured

AP Manager....................................... Yes

Guest Interface.................................. No

L2 Multicast..................................... Enabled

 

(Cisco Controller) >show interface detailed clients

Interface Name................................... clients

MAC Address...................................... 4c:4e:35:7e:42:c4

IP Address....................................... 10.10.3.254

IP Netmask....................................... 255.255.255.0

IP Gateway....................................... 10.10.3.1

External NAT IP State............................ Disabled

External NAT IP Address.......................... 0.0.0.0

VLAN............................................. 113

Quarantine-vlan.................................. 0

NAS-Identifier................................... ARL_Wireless

Active Physical Port............................. 1

Primary Physical Port............................ 1

Backup Physical Port............................. Unconfigured

DHCP Proxy Mode.................................. Disabled

Primary DHCP Server.............................. 10.10.3.1

Secondary DHCP Server............................ 10.10.5.5

DHCP Option 82................................... Disabled

DHCP Option 82 bridge mode insertion............. Disabled

IPv4 ACL......................................... Unconfigured

mDNS Profile Name................................ Unconfigured

AP Manager....................................... No

Guest Interface.................................. No

L2 Multicast..................................... Enabled

Also, my mistake from earlier....I meant to say I have Layer 2 & 3 turned OFF on my WLAN.  I wanted it as basic as possible just to get the clients onto the network.  Then, I'll start adding security.

Review Cisco Networking for a $25 gift card