Wireless Access

 View Only
Expand all | Collapse all

client in guest vlan get ip address randomly for open ssid.

This thread has been viewed 62 times
  • 1.  client in guest vlan get ip address randomly for open ssid.

    Posted Apr 04, 2025 04:57 AM
      |   view attached

    Dear all,

    I have ArubaOS (MODEL: Aruba7210), Version 8.10.0.2 LSR. and it is configured for local authentication of guest user through open ssid and captive portal. We have windows server 2019 acting as dhcp server. and aruba 8320 cx core switches are acting as dhcp relay. client connect to guest ssid and got assigned to vlan 205. and then it gets ip from the dhcp server. sometime client get the ip and sometimes they don't. i have captured the debug output of 2 clients. one is getting the ip other is not. even the one which is getting ip, earlier it was not getting its ip and suddenly it got the ip. i can see in wireshark installed on client , it sends dhcp discover message but not getting any reply back. debug output is attached for both client. 

    Attachment(s)

    txt
    aruba client debug.txt   8 KB 1 version


  • 2.  RE: client in guest vlan get ip address randomly for open ssid.

    Posted Apr 06, 2025 12:43 PM

    We need the ACLs in the user role to determine what could be happening. 



    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    HPE Design and Deploy Guides: https://community.arubanetworks.com/support/migrated-knowledge-base?attachments=&communitykey=dcc83c62-1a3a-4dd8-94dc-92968ea6fff1&pageindex=0&pagesize=12&search=&sort=most_recent&viewtype=card
    ------------------------------



  • 3.  RE: client in guest vlan get ip address randomly for open ssid.

    Posted Apr 08, 2025 01:28 AM

    access-list List
    ----------------
    Position  Name                                     Type     Location
    --------  ----                                     ----     --------
    1         global-sacl                              session
    2         apprf-myorg-guest-guest-logon-sacl  session
    3         logon-control                            session
    4         captiveportal                            session
    5         Guest_Policy                             session
    6         v6-logon-control                         session
    7         captiveportal6                           session

    global-sacl
    -----------
    Priority  Source  Destination  Service  Application  Action  TimeRange  Log  Expired  Queue  TOS  8021P  Denylist  Mirror  DisScan  IPv4/6  Contract  Mark  Description
    --------  ------  -----------  -------  -----------  ------  ---------  ---  -------  -----  ---  -----  --------  ------  -------  ------  --------  ----  -----------
    apprf-svkm-myorg-guest-guest-logon-sacl
    ---------------------------------------
    Priority  Source  Destination  Service  Application  Action  TimeRange  Log  Expired  Queue  TOS  8021P  Denylist  Mirror  DisScan  IPv4/6  Contract  Mark  Description
    --------  ------  -----------  -------  -----------  ------  ---------  ---  -------  -----  ---  -----  --------  ------  -------  ------  --------  ----  -----------
    logon-control
    -------------
    Priority  Source  Destination              Service   Application  Action  TimeRange  Log  Expired  Queue  TOS  8021P  Denylist  Mirror  DisScan  IPv4/6  Contract  Mark  Description
    --------  ------  -----------              -------   -----------  ------  ---------  ---  -------  -----  ---  -----  --------  ------  -------  ------  --------  ----  -----------
    1         user    any                      udp 68                 deny                             Low                                           4
    2         any     any                      svc-icmp               permit                           Low                                           4
    3         any     any                      svc-dns                permit                           Low                                           4
    4         any     any                      svc-dhcp               permit                           Low                                           4
    5         any     any                      svc-natt               permit                           Low                                           4
    6         any     169.254.0.0 255.255.0.0  any                    deny                             Low                                           4
    7         any     240.0.0.0 240.0.0.0      any                    deny                             Low                                           4
    captiveportal
    -------------
    Priority  Source  Destination  Service          Application  Action        TimeRange  Log  Expired  Queue  TOS  8021P  Denylist  Mirror  DisScan  IPv4/6  Contract  Mark  Description
    --------  ------  -----------  -------          -----------  ------        ---------  ---  -------  -----  ---  -----  --------  ------  -------  ------  --------  ----  -----------
    1         user    controller   svc-https                     dst-nat 8081                           Low                                           4
    2         user    any          svc-http                      dst-nat 8080                           Low                                           4
    3         user    any          svc-https                     dst-nat 8081                           Low                                           4
    4         user    any          svc-http-proxy1               dst-nat 8088                           Low                                           4
    5         user    any          svc-http-proxy2               dst-nat 8088                           Low                                           4
    6         user    any          svc-http-proxy3               dst-nat 8088                           Low                                           4
    Guest_Policy
    ------------
    Priority  Source        Destination       Service  Application  Action  TimeRange  Log  Expired  Queue  TOS  8021P  Denylist  Mirror  DisScan  IPv4/6  Contract  Mark  Description
    --------  ------        -----------       -------  -----------  ------  ---------  ---  -------  -----  ---  -----  --------  ------  -------  ------  --------  ----  -----------
    1         any           10.155.45.1       svc-dns               permit                           Low                                           4
    2         any           192.168.25.1      svc-dns               permit                           Low                                           4
    3         guestnetwork  guestnetwork      any                   permit             Yes           Low                                           4
    4         any           internal_network  any                   deny                             Low                                           4
    v6-logon-control
    ----------------
    Priority  Source  Destination          Service      Application  Action  TimeRange  Log  Expired  Queue  TOS  8021P  Denylist  Mirror  DisScan  IPv4/6  Contract  Mark  Description
    --------  ------  -----------          -------      -----------  ------  ---------  ---  -------  -----  ---  -----  --------  ------  -------  ------  --------  ----  -----------
    1         user    any                  udp 546                   deny                             Low                                           6
    2         any     any                  svc-v6-icmp               permit                           Low                                           6
    3         any     any                  svc-v6-dhcp               permit                           Low                                           6
    4         any     any                  svc-dns                   permit                           Low                                           6
    5         any     fc00::/7             any-v6                    permit                           Low                                           6
    6         any     fe80::/64            any-v6                    permit                           Low                                           6
    7         any     ipv6-reserved-range  any-v6                    deny                             Low                                           6
    captiveportal6
    --------------
    Priority  Source  Destination  Service          Application  Action   TimeRange  Log  Expired  Queue  TOS  8021P  Denylist  Mirror  DisScan  IPv4/6  Contract  Mark  Description
    --------  ------  -----------  -------          -----------  ------   ---------  ---  -------  -----  ---  -----  --------  ------  -------  ------  --------  ----  -----------
    1         user    controller6  svc-https                     captive                           Low                                           6
    2         user    any          svc-http                      captive                           Low                                           6
    3         user    any          svc-https                     captive                           Low                                           6
    4         user    any          svc-http-proxy1               captive                           Low                                           6
    5         user    any          svc-http-proxy2               captive                           Low                                           6
    6         user    any          svc-http-proxy3               captive                           Low                                           6




  • 4.  RE: client in guest vlan get ip address randomly for open ssid.

    Posted Apr 07, 2025 04:54 AM

    Do you use controller redundancy such as clusters or HA groups?



    ------------------------------
    Regards,

    Waldemar
    ACCX # 1377, ACEP, ACX - Network Security
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 5.  RE: client in guest vlan get ip address randomly for open ssid.

    Posted Apr 07, 2025 06:26 AM

    yes we are using conductor redundancy.

    conductor-redundancy
    conductor-vrrp 10
    peer-ip-address "PEER IP Address" ipsec jnkdfnkl9238903249-




  • 6.  RE: client in guest vlan get ip address randomly for open ssid.

    Posted Apr 07, 2025 07:25 AM

    This is Conductor Layer 2 redundancy. The user traffic does not flow through mobility conductor, the redundancy does not effect the client behavior.

    What about the controller? If controller redundancy is used, the client sessions are assigned to different WLAN controllers by load balancing. If VLAN tagging is different in controller ports or in switch ports, it will explain the client behavior.

    Go to the WEB-GUI, find the 7210 controller in the configuration hierarchy and select it. Click on Configuration and then on Services. Is a cluster profile displayed at this point?

    Also check HA Groups. Leave the controller selected and click on Configuration, Redundancy. Do you see groups under HA Groups?



    ------------------------------
    Regards,

    Waldemar
    ACCX # 1377, ACEP, ACX - Network Security
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 7.  RE: client in guest vlan get ip address randomly for open ssid.

    Posted Apr 07, 2025 07:34 AM

    No there is no such HA and cluster configuration. Attached is the screenshot.




  • 8.  RE: client in guest vlan get ip address randomly for open ssid.

    Posted Apr 08, 2025 03:56 AM

    OK, I have to correct my statement, your screenshots tell me that you have two standalone mobility controllers - without mobility conductor. These controllers are set up with master-backup master redundancy.

    However, the client problems are probably due to the clients connecting to different controllers. Check whether the VLANs are tagged correctly on both controllers. As well as switchport tagging, where the controllers are connected.



    ------------------------------
    Regards,

    Waldemar
    ACCX # 1377, ACEP, ACX - Network Security
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 9.  RE: client in guest vlan get ip address randomly for open ssid.

    Posted Apr 08, 2025 04:13 AM
      |   view attached

    I have the exact same conf for both controllers, primary and secondary and also they are connected to core switches, which have same configuration. pfa


    Attachment(s)

    txt
    portconf.txt   2 KB 1 version


  • 10.  RE: client in guest vlan get ip address randomly for open ssid.

    Posted Apr 08, 2025 04:28 PM

    Your setup is correct in parts, but there's likely a small misconfig in:

    • Guest role rules

    • Switch relay setup

    • Or DHCP response path

    Fix these and your guest Wi-Fi will become stable.




  • 11.  RE: client in guest vlan get ip address randomly for open ssid.

    Posted Apr 09, 2025 01:31 AM
    Edited by manish16842 Apr 09, 2025 01:44 AM

    i have configured ip-helper under layer 3 vlan interface on core switch as follows:-

    interface vlan GuestVlanID
        vsx-sync active-gateways policies
        ip address CoreSwitch-1-AssignedIP
        active-gateway ip mac 02:02:00:00:17:00
        active-gateway ip CommonIP-BW-CoreSwitches
        ip helper-address DHCPServerIP

    Guest get assigned the PRELOGON ROLE before authentication, where it should get ip from dhcp. So respective ACLs(logon and captive portal) are allowed. i have attached those role ACLs in above thread.

    From core switch(acting as Dhcp relay) dhcp discover should go to dhcp server. Dhcp server is behind the firewall. but since some client are getting IPs, so it should have been working.

    Just to add, we are using tunnel mode. So all vlans data( guest and corporate) get encapsulated in one ap to controller vlan. Controller de-encapsulate that data and send to core switches according to respective vlan. i was trying to get the debug output for dhcp relay in aruba8320cx switches but not able to get using following commands:-

    debug destination buffer

    debug dhcprelay all

    sh logging -c dhcp-relay -r




  • 12.  RE: client in guest vlan get ip address randomly for open ssid.

    Posted Apr 09, 2025 03:56 AM
    You posted log output above. This log shows that both clients receive the same Preauthenticated Aruba User Role SVKM-NMIMS-GUEST-guest-logon. So it can't be due to the role. Furthermore, we see that both users are associated with the WLAN SVKM-NMIMS-GUEST and both are in VLAN 205. The WLAN controller has done its job at this point and bridged the packets to the switch.
     
    You must continue troubleshooting in the wired network. Check whether client MAC-ADDRESS are visible in the switch, whether the DHCP requests arrive at the firewall and at the DHCP server. Take  tcpdump on the firewall and DHCP server, then you will see more.


    ------------------------------
    Regards,

    Waldemar
    ACCX # 1377, ACEP, ACX - Network Security
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 13.  RE: client in guest vlan get ip address randomly for open ssid.

    Posted Apr 09, 2025 05:06 AM

    Thanks for sharing that. is there any other commond to check dhcp relay messages in aruba 8320x switches. 

    debug destination buffer

    debug dhcprelay all

    sh logging -c dhcp-relay -r




  • 14.  RE: client in guest vlan get ip address randomly for open ssid.

    Posted Apr 09, 2025 12:17 PM

    Thanks for sharing