cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1085
Views
5
Helpful
10
Replies

WLC wrong DHCP assignement

ez9
Level 1
Level 1

Hello,

I have a setup with a WLC 5508. The APs are in local mode and I am using a radius server to autoassign VLAN and to authenticate the users via 802.1x. I have created all vlan interfaces on WLC controller.

Some of the clients are complaining that they haven't Internet access sometimes. After investigation I found out that as they are connected to the correct VLAN, they are getting wrong IP address from DHCP server. The DHCP server is not on WLC and in the interafaces on WLC I configured the DHCP proxy mode as: disabled.

I ran some debugs for one "problematic" client and I am getting the following output:

The correct VLAN is the 33(192.168.1.0/24) but I can see offers from VLAN 20 (192.168.200.0/22).

Any thoughts on this?

Thank you.

*Dot1x_NW_MsgTask_5: Oct 02 05:52:10.071: 38:87:d5:ea:20:ae Accounting NAI-Realm: <username>, from Mscb username : <username>
*Dot1x_NW_MsgTask_5: Oct 02 05:52:10.071: 38:87:d5:ea:20:ae 192.168.1.213 RUN (20) Successfully plumbed mobile rule (IPv4 ACL ID 255, IPv6 ACL ID 255, L2 ACL ID 255,URL ACL ID 255,URL ACL Action 0)
*Dot1x_NW_MsgTask_5: Oct 02 05:52:10.072: 38:87:d5:ea:20:ae 192.168.1.213 RUN (20) No 11v BTM
*Dot1x_NW_MsgTask_5: Oct 02 05:52:10.072: 38:87:d5:ea:20:ae 192.168.1.213 RUN (20) NO release MSCB
*Dot1x_NW_MsgTask_5: Oct 02 05:52:10.072: 38:87:d5:ea:20:ae Successfully Plumbed PTK session Keysfor mobile 38:87:d5:ea:20:ae
*pemReceiveTask: Oct 02 05:52:10.072: 38:87:d5:ea:20:ae 192.168.1.213 tokenID = 217
*pemReceiveTask: Oct 02 05:52:10.072: 38:87:d5:ea:20:ae 192.168.1.213 Added NPU entry of type 1, dtlFlags 0x0
*pemReceiveTask: Oct 02 05:52:10.072: 38:87:d5:ea:20:ae Pushing IPv6: fe80:0000:0000:0000:6dcd:0a45:b960:868d , intfId:12 and MAC: 38:87:d5:ea:20:ae , Binding to Data Plane. SUCCESS !!
*DHCP Socket Task: Oct 02 05:52:10.078: 38:87:d5:ea:20:ae DHCP received op BOOTREQUEST (1) (len 320,vlan 67, port 1, encap 0xec03, xid 0x289627c1)
*DHCP Socket Task: Oct 02 05:52:10.078: 38:87:d5:ea:20:ae DHCP (encap type 0xec03) mstype 0ff:ff:ff:ff:ff:ff
*DHCP Socket Task: Oct 02 05:52:10.078: 38:87:d5:ea:20:ae DHCP processing DHCP REQUEST (3)
*DHCP Socket Task: Oct 02 05:52:10.078: 38:87:d5:ea:20:ae DHCP op: BOOTREQUEST, htype: Ethernet, hlen: 6, hops: 0
*DHCP Socket Task: Oct 02 05:52:10.078: 38:87:d5:ea:20:ae DHCP xid: 0x289627c1 (680929217), secs: 0, flags: 8000
*DHCP Socket Task: Oct 02 05:52:10.078: 38:87:d5:ea:20:ae DHCP chaddr: 38:87:d5:ea:20:ae
*DHCP Socket Task: Oct 02 05:52:10.078: 38:87:d5:ea:20:ae DHCP ciaddr: 0.0.0.0, yiaddr: 0.0.0.0
*DHCP Socket Task: Oct 02 05:52:10.078: 38:87:d5:ea:20:ae DHCP siaddr: 0.0.0.0, giaddr: 0.0.0.0
*DHCP Socket Task: Oct 02 05:52:10.078: 38:87:d5:ea:20:ae DHCP requested ip: 192.168.1.213
*DHCP Socket Task: Oct 02 05:52:10.078: 38:87:d5:ea:20:ae DHCP Opt82 bridge mode insertion enabled, inserts opt82 if opt82 is enabled vlan=33, datalen =18, optlen=76
*DHCP Socket Task: Oct 02 05:52:10.078: 38:87:d5:ea:20:ae DHCP successfully bridged packet to DS
*DHCP Socket Task: Oct 02 05:52:10.078: 38:87:d5:ea:20:ae DHCP received op BOOTREQUEST (1) (len 320,vlan 20, port 1, encap 0xec00, xid 0x289627c1)
*DHCP Socket Task: Oct 02 05:52:10.078: 38:87:d5:ea:20:ae DHCP (encap type 0xec00) mstype 0ff:ff:ff:ff:ff:ff
*DHCP Socket Task: Oct 02 05:52:10.078: 38:87:d5:ea:20:ae DHCP dropping looped REQUEST from DS (encap type 0xec00)
*DHCP Socket Task: Oct 02 05:52:10.081: 38:87:d5:ea:20:ae DHCP received op BOOTREPLY (2) (len 308,vlan 33, port 1, encap 0xec00, xid 0x289627c1)
*DHCP Socket Task: Oct 02 05:52:10.081: 38:87:d5:ea:20:ae DHCP processing DHCP ACK (5)
*DHCP Socket Task: Oct 02 05:52:10.081: 38:87:d5:ea:20:ae DHCP op: BOOTREPLY, htype: Ethernet, hlen: 6, hops: 0
*DHCP Socket Task: Oct 02 05:52:10.081: 38:87:d5:ea:20:ae DHCP xid: 0x289627c1 (680929217), secs: 0, flags: 8000
*DHCP Socket Task: Oct 02 05:52:10.081: 38:87:d5:ea:20:ae DHCP chaddr: 38:87:d5:ea:20:ae
*DHCP Socket Task: Oct 02 05:52:10.081: 38:87:d5:ea:20:ae DHCP ciaddr: 0.0.0.0, yiaddr: 192.168.1.213
*DHCP Socket Task: Oct 02 05:52:10.081: 38:87:d5:ea:20:ae DHCP siaddr: 192.168.1.1, giaddr: 0.0.0.0
*DHCP Socket Task: Oct 02 05:52:10.081: 38:87:d5:ea:20:ae DHCP server id: 192.168.1.1 rcvd server id: 192.168.1.1
*DHCP Socket Task: Oct 02 05:52:10.082: 38:87:d5:ea:20:ae DHCP successfully bridged packet to STA
*DHCP Socket Task: Oct 02 05:52:10.082: 38:87:d5:ea:20:ae DHCP received op BOOTREPLY (2) (len 308,vlan 20, port 1, encap 0xec00, xid 0x289627c1)
*DHCP Socket Task: Oct 02 05:52:10.082: 38:87:d5:ea:20:ae DHCP processing DHCP NAK (6)
*DHCP Socket Task: Oct 02 05:52:10.082: 38:87:d5:ea:20:ae DHCP op: BOOTREPLY, htype: Ethernet, hlen: 6, hops: 0
*DHCP Socket Task: Oct 02 05:52:10.082: 38:87:d5:ea:20:ae DHCP xid: 0x289627c1 (680929217), secs: 0, flags: 8000
*DHCP Socket Task: Oct 02 05:52:10.082: 38:87:d5:ea:20:ae DHCP chaddr: 38:87:d5:ea:20:ae
*DHCP Socket Task: Oct 02 05:52:10.082: 38:87:d5:ea:20:ae DHCP ciaddr: 0.0.0.0, yiaddr: 0.0.0.0
*DHCP Socket Task: Oct 02 05:52:10.082: 38:87:d5:ea:20:ae DHCP siaddr: 0.0.0.0, giaddr: 0.0.0.0
*DHCP Socket Task: Oct 02 05:52:10.082: 38:87:d5:ea:20:ae DHCP server id: 192.168.200.1 rcvd server id: 192.168.200.1

10 Replies 10

marce1000
VIP
VIP

 

 - When processed by : https://cway.cisco.com/wireless-debug-analyzer/ , your debug comes down to (Show all flags checked) :

             Oct 02 05:52:10.078*DHCP Socket TaskReceived DHCP request from client

            Oct 02 05:52:10.078*DHCP Socket TaskReceived DHCP request from client

           Oct 02 05:52:10.081*DHCP Socket TaskReceived DHCP ACK from DHCP server

           Oct 02 05:52:10.082*DHCP Socket TaskReceived DHCP NAK from DHCP server

 - Check the DHCP server configuration.

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

ez9
Level 1
Level 1

thanks for the answer,

I will take a look on DHCP server. But in debug output I can see entries like:

DHCP received op BOOTREQUEST (1) (len 320,vlan 67, port 1, encap 0xec03, xid 0x289627c1)

DHCP received op BOOTREQUEST (1) (len 320,vlan 20, port 1, encap 0xec00, xid 0x289627c1)

DHCP received op BOOTREPLY (2) (len 308,vlan 33, port 1, encap 0xec00, xid 0x289627c1)

DHCP received op BOOTREPLY (2) (len 308,vlan 20, port 1, encap 0xec00, xid 0x289627c1)

The client is on VLAN 33. Why the bootrequests showing other VLANs? (vlan 20 is the guest VLAN-different SSID-no autoassignment via radius, Vlan 67 is the AP Management VLAN).

 

 - Beside other replies , I would also advice to have a checkup of the 5508 controller configuration with : https://cway.cisco.com/tools/WirelessAnalyzer/

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Arshad Safrulla
VIP Alumni
VIP Alumni

Hows the AP connecting switchport and WLC connecting switchport is configured? Are you using any Native VLAN for the trunks?

ez9
Level 1
Level 1

The WLC is connected in trunk mode. The native VLAN is the default (1). There is no SVI for VLAN 1. 

The APs are connected in trunk mode using the Management VLAN (67) as native.

I think this has something to do with your AAA server. Please check the policies and make sure that VLAN's are not sent as a part of Radius Accept message.

ez9
Level 1
Level 1

I don't know if this helping you somehow. I am attaching a screenshot from the policy that I configured on RADIUS server for VLAN assignement. 

nps.png

Rich R
VIP
VIP

Or you have a layer 2 loop somewhere such that DHCP request broadcasts are leaking onto other VLANs.
What version of software are you using?

ez9
Level 1
Level 1

Thanks for your input,

The version is the 8.5.182.0 (I think this is the latest version for 5508). I upgraded to this version just yesterday. Before the WLC had the 8.5.171.0. I found out the the 8.5.182.0 resolving the bug CSCvx61201. I don't know if this fits 100% my setup but I give it a chance.

I checked all switches. I am running RPVST everywhere. I wll take a capture just in case.

Rich R
VIP
VIP

Yes that looks like a good possible match - hopefully that resolves your problem.

Review Cisco Networking for a $25 gift card