Thanks. Appreciate the response. We will dig deeper into the packet captures and see what we can find out.
-------------------------------------------
Original Message:
Sent: Jan 21, 2026 09:50 PM
From: chulcher
Subject: Captive portal redirect issues, Aruba 7220 controllers
There shouldn't be, no. That's why the packet capture is important for troubleshooting this, you have to validate that the discover is leaving and that the offer is reaching the controller. Or if you can validate that the issue is specifically tied to a software version, then you have something else to look at or give to TAC.
We have had bugs that matched this description in the past, we've also had customers report similar behavior and be able to narrow the issue down to a specific client chipset and driver version.
------------------------------
Carson Hulcher, ACEX#110
------------------------------
Original Message:
Sent: Jan 21, 2026 09:40 PM
From: j_alston
Subject: Captive portal redirect issues, Aruba 7220 controllers
Ok I guess thats what I was asking. Is there any reason or any possible way a controller could be blocking dhcp packets, other than an ACL?
Original Message:
Sent: Jan 21, 2026 04:51 PM
From: chulcher
Subject: Captive portal redirect issues, Aruba 7220 controllers
The controller is always snooping the DHCP in order to populate the user table and datapath information with the correct mapping, but there is zero action that should ever be blocking any one client from the DHCP process unless you've applied an ACL to their user role that is blocking that specific traffic.
DHCP isn't a requirement unless you have marked the option for DHCP enforcement i.e., enforce dhcp.
Upgrading to the latest is always a good option, or even downgrading to the version you feel was working well in order to validate that such was the case.
About the only thing that could be done for troubleshooting is to do the captures to see where the process is breaking down, to make sure that the DHCP packet is always being sent out by the server and being presented to the controller.
------------------------------
Carson Hulcher, ACEX#110
Original Message:
Sent: Jan 21, 2026 04:33 PM
From: j_alston
Subject: Captive portal redirect issues, Aruba 7220 controllers
Yeah its something we are working on changing. Originally the wired part of the vlan was only for printers, but others have jumped on it with their wired devices.
TAC pointed out its a DHCP problem, but doesn't think its related to the controller since we are not doing DHCP on the controller. We do DHCP on a hyper-v server. We had a TAC case open for about a month, but I closed it last week because we went about 5 days without any reports of more problems. The engineer we worked with looked everything over and was at the point that we were just going to do more packet captures to see if we could uncover any more information.
I'm just looking to see if anyone else out there has any ideas what could cause something like this, because we are kind of lost right now. Like is there some kind of DHCP snooping like you have on Cisco switches that would block certain DHCP packets? Or something that would block a specific mac for a certain time?
My only other idea is to upgrade up to 8.10.0.20 or 21 since we did not see this issue until we upgraded. Hoping maybe its a bug in the software.
Original Message:
Sent: Jan 21, 2026 02:20 PM
From: chulcher
Subject: Captive portal redirect issues, Aruba 7220 controllers
FYI, generally we'd really rather not see you commingle wired and wireless users in the same VLAN when those wired users aren't coming through the controllers.
Are you working with TAC for the missing IP addresses on clients?
------------------------------
Carson Hulcher, ACEX#110