<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AP7632 connection problem in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/ap7632-connection-problem/m-p/98571#M9358</link>
    <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;Dear experts, i need your kindly advice, please..&amp;nbsp;I have an AP7632i access point, which operates in a bridge mode. It looks like AP works fine, but some kinds of clients can't receive an IP address from the gateway through this AP. As a result, this kind of clients can't establish Internet connection.&lt;/P&gt;&lt;P&gt;PCs, laptops, tablets, cell phones - all of them works fine (can authenticate on AP, get an IP address from the gateway and operate normally). But we have some smart wireless devices (kind of voice assistants) and some of them can't get an IP address from GW. I'm 100% sure, that the problem is related with AP, cuz if I change AP7632 to some Mikrotik AP (for example) this clients can connect to wi-fi and they work fine (with same gateway).&lt;/P&gt;&lt;P&gt;I'm little bit confused about it, cuz i tried to do a full factory reset, I configured minimum/basic configuration on AP and got the same result.&lt;/P&gt;&lt;P&gt;We use very simple configuration (Internet-&amp;gt;Juniper SRX210H GW-&amp;gt;D-Link PoE Switch-&amp;gt;Extreme AP7632i-&amp;gt;Clients). We do not use and dot1x or something special.. All options are on their defaults..&lt;/P&gt;&lt;P&gt;Please, help to understand, what is a problem?&lt;/P&gt;&lt;P&gt;Here our AP's config:&lt;/P&gt;&lt;LI-SPOILER&gt;AP-01.361*#sho run&lt;BR /&gt;!&lt;BR /&gt;! Configuration of AP7632 version 7.7.0.0-018R&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;version 2.7&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;client-identity-group default&lt;BR /&gt;load default-fingerprints&lt;BR /&gt;!&lt;BR /&gt;ip access-list BROADCAST-MULTICAST-CONTROL&lt;BR /&gt;permit ip any any rule-precedence 10 rule-description "permit all IP traffic"&lt;BR /&gt;permit tcp any any rule-precedence 11 rule-description "permit all TCP traffic"&lt;BR /&gt;permit udp any eq 67 any eq dhcpc rule-precedence 12 rule-description "permit DHCP replies"&lt;BR /&gt;deny udp any range 137 138 any range 137 138 rule-precedence 21 rule-description "deny windows netbios"&lt;BR /&gt;deny ip any 224.0.0.0/4 rule-precedence 22 rule-description "deny IP multicast"&lt;BR /&gt;deny ip any host 255.255.255.255 rule-precedence 23 rule-description "deny IP local broadcast"&lt;BR /&gt;deny ip any any rule-precedence 102&lt;BR /&gt;!&lt;BR /&gt;mac access-list PERMIT-ARP-AND-IPv4&lt;BR /&gt;permit any any type ip rule-precedence 10 rule-description "permit all IPv4 traffic"&lt;BR /&gt;permit any any type arp rule-precedence 20 rule-description "permit all ARP traffic"&lt;BR /&gt;!&lt;BR /&gt;ip snmp-access-list default&lt;BR /&gt;permit any&lt;BR /&gt;!&lt;BR /&gt;firewall-policy default&lt;BR /&gt;no ip dos tcp-sequence-past-window&lt;BR /&gt;no stateful-packet-inspection-l2&lt;BR /&gt;ip tcp adjust-mss 1400&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;mint-policy global-default&lt;BR /&gt;!&lt;BR /&gt;meshpoint-qos-policy default&lt;BR /&gt;!&lt;BR /&gt;wlan-qos-policy default&lt;BR /&gt;qos trust dscp&lt;BR /&gt;qos trust wmm&lt;BR /&gt;!&lt;BR /&gt;radio-qos-policy default&lt;BR /&gt;!&lt;BR /&gt;wlan wlan1&lt;BR /&gt;ssid AP-01.361&lt;BR /&gt;vlan 1&lt;BR /&gt;bridging-mode local&lt;BR /&gt;encryption-type tkip-ccmp&lt;BR /&gt;authentication-type none&lt;BR /&gt;no multi-band-operation&lt;BR /&gt;no protected-mgmt-frames&lt;BR /&gt;wpa-wpa2 psk 0 ........................&lt;BR /&gt;!&lt;BR /&gt;wlan wlan2&lt;BR /&gt;ssid smartnet&lt;BR /&gt;vlan 1&lt;BR /&gt;bridging-mode local&lt;BR /&gt;encryption-type tkip-ccmp&lt;BR /&gt;authentication-type none&lt;BR /&gt;no multi-band-operation&lt;BR /&gt;no protected-mgmt-frames&lt;BR /&gt;wpa-wpa2 psk 0 .........................&lt;BR /&gt;!&lt;BR /&gt;smart-rf-policy default&lt;BR /&gt;no select-shutdown&lt;BR /&gt;!&lt;BR /&gt;wips-policy default&lt;BR /&gt;!&lt;BR /&gt;radius-server-policy default&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;management-policy default&lt;BR /&gt;telnet&lt;BR /&gt;no http server&lt;BR /&gt;https server&lt;BR /&gt;rest-server&lt;BR /&gt;ssh&lt;BR /&gt;user admin password 1 .................. role superuser access all&lt;BR /&gt;no snmp-server manager v3&lt;BR /&gt;!&lt;BR /&gt;event-system-policy default&lt;BR /&gt;!&lt;BR /&gt;nsight-policy default&lt;BR /&gt;!&lt;BR /&gt;profile ap7632 361&lt;BR /&gt;ip name-server 192.168.163.1&lt;BR /&gt;ip name-server 8.8.8.8&lt;BR /&gt;ip default-gateway 192.168.163.1&lt;BR /&gt;autoinstall configuration&lt;BR /&gt;autoinstall firmware&lt;BR /&gt;crypto ikev1 policy ikev1-default&lt;BR /&gt;isakmp-proposal default encryption aes-256 group 2 hash sha&lt;BR /&gt;crypto ikev2 policy ikev2-default&lt;BR /&gt;isakmp-proposal default encryption aes-256 group 2 hash sha&lt;BR /&gt;crypto ipsec transform-set default esp-aes-256 esp-sha-hmac&lt;BR /&gt;crypto ikev1 remote-vpn&lt;BR /&gt;crypto ikev2 remote-vpn&lt;BR /&gt;crypto auto-ipsec-secure&lt;BR /&gt;crypto load-management&lt;BR /&gt;crypto remote-vpn-client&lt;BR /&gt;interface radio1&lt;BR /&gt;wlan wlan1 bss 1 primary&lt;BR /&gt;wlan wlan2 bss 2 primary&lt;BR /&gt;antenna-mode 2x2&lt;BR /&gt;interface radio2&lt;BR /&gt;wlan wlan1 bss 1 primary&lt;BR /&gt;antenna-mode 2x2&lt;BR /&gt;interface bluetooth1&lt;BR /&gt;shutdown&lt;BR /&gt;mode le-sensor&lt;BR /&gt;interface ge1&lt;BR /&gt;interface vlan1&lt;BR /&gt;ip address dhcp&lt;BR /&gt;ip address zeroconf secondary&lt;BR /&gt;ip dhcp client request options all&lt;BR /&gt;interface pppoe1&lt;BR /&gt;no use firewall-policy&lt;BR /&gt;use client-identity-group default&lt;BR /&gt;logging on&lt;BR /&gt;service pm sys-restart&lt;BR /&gt;router ospf&lt;BR /&gt;adoption-mode controller&lt;BR /&gt;!&lt;BR /&gt;rf-domain default&lt;BR /&gt;location "361"&lt;BR /&gt;contact admin&lt;BR /&gt;timezone Asia/Tashkent&lt;BR /&gt;country-code uz&lt;BR /&gt;ad-wips-wireless-mitigation disable&lt;BR /&gt;ad-wips-wired-mitigation disable&lt;BR /&gt;use nsight-policy default&lt;BR /&gt;!&lt;BR /&gt;ap7632 B4-2D-56-8A-88-90&lt;BR /&gt;use profile 361&lt;BR /&gt;use rf-domain default&lt;BR /&gt;hostname AP-01.361&lt;BR /&gt;no mint mlcp vlan&lt;BR /&gt;no mint mlcp ip&lt;BR /&gt;interface vlan1&lt;BR /&gt;description "Virtual Interface for LAN by Wizard"&lt;BR /&gt;ip address 192.168.163.3/24&lt;BR /&gt;ip address zeroconf secondary&lt;BR /&gt;no ip dhcp client request options all&lt;BR /&gt;no virtual-controller&lt;BR /&gt;no rf-domain-manager capable&lt;BR /&gt;no adoption-mode&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;end&lt;BR /&gt;AP-01.361*#&lt;/LI-SPOILER&gt;</description>
    <pubDate>Sat, 23 Dec 2023 13:40:49 GMT</pubDate>
    <dc:creator>AmirA</dc:creator>
    <dc:date>2023-12-23T13:40:49Z</dc:date>
    <item>
      <title>AP7632 connection problem</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/ap7632-connection-problem/m-p/98571#M9358</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;Dear experts, i need your kindly advice, please..&amp;nbsp;I have an AP7632i access point, which operates in a bridge mode. It looks like AP works fine, but some kinds of clients can't receive an IP address from the gateway through this AP. As a result, this kind of clients can't establish Internet connection.&lt;/P&gt;&lt;P&gt;PCs, laptops, tablets, cell phones - all of them works fine (can authenticate on AP, get an IP address from the gateway and operate normally). But we have some smart wireless devices (kind of voice assistants) and some of them can't get an IP address from GW. I'm 100% sure, that the problem is related with AP, cuz if I change AP7632 to some Mikrotik AP (for example) this clients can connect to wi-fi and they work fine (with same gateway).&lt;/P&gt;&lt;P&gt;I'm little bit confused about it, cuz i tried to do a full factory reset, I configured minimum/basic configuration on AP and got the same result.&lt;/P&gt;&lt;P&gt;We use very simple configuration (Internet-&amp;gt;Juniper SRX210H GW-&amp;gt;D-Link PoE Switch-&amp;gt;Extreme AP7632i-&amp;gt;Clients). We do not use and dot1x or something special.. All options are on their defaults..&lt;/P&gt;&lt;P&gt;Please, help to understand, what is a problem?&lt;/P&gt;&lt;P&gt;Here our AP's config:&lt;/P&gt;&lt;LI-SPOILER&gt;AP-01.361*#sho run&lt;BR /&gt;!&lt;BR /&gt;! Configuration of AP7632 version 7.7.0.0-018R&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;version 2.7&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;client-identity-group default&lt;BR /&gt;load default-fingerprints&lt;BR /&gt;!&lt;BR /&gt;ip access-list BROADCAST-MULTICAST-CONTROL&lt;BR /&gt;permit ip any any rule-precedence 10 rule-description "permit all IP traffic"&lt;BR /&gt;permit tcp any any rule-precedence 11 rule-description "permit all TCP traffic"&lt;BR /&gt;permit udp any eq 67 any eq dhcpc rule-precedence 12 rule-description "permit DHCP replies"&lt;BR /&gt;deny udp any range 137 138 any range 137 138 rule-precedence 21 rule-description "deny windows netbios"&lt;BR /&gt;deny ip any 224.0.0.0/4 rule-precedence 22 rule-description "deny IP multicast"&lt;BR /&gt;deny ip any host 255.255.255.255 rule-precedence 23 rule-description "deny IP local broadcast"&lt;BR /&gt;deny ip any any rule-precedence 102&lt;BR /&gt;!&lt;BR /&gt;mac access-list PERMIT-ARP-AND-IPv4&lt;BR /&gt;permit any any type ip rule-precedence 10 rule-description "permit all IPv4 traffic"&lt;BR /&gt;permit any any type arp rule-precedence 20 rule-description "permit all ARP traffic"&lt;BR /&gt;!&lt;BR /&gt;ip snmp-access-list default&lt;BR /&gt;permit any&lt;BR /&gt;!&lt;BR /&gt;firewall-policy default&lt;BR /&gt;no ip dos tcp-sequence-past-window&lt;BR /&gt;no stateful-packet-inspection-l2&lt;BR /&gt;ip tcp adjust-mss 1400&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;mint-policy global-default&lt;BR /&gt;!&lt;BR /&gt;meshpoint-qos-policy default&lt;BR /&gt;!&lt;BR /&gt;wlan-qos-policy default&lt;BR /&gt;qos trust dscp&lt;BR /&gt;qos trust wmm&lt;BR /&gt;!&lt;BR /&gt;radio-qos-policy default&lt;BR /&gt;!&lt;BR /&gt;wlan wlan1&lt;BR /&gt;ssid AP-01.361&lt;BR /&gt;vlan 1&lt;BR /&gt;bridging-mode local&lt;BR /&gt;encryption-type tkip-ccmp&lt;BR /&gt;authentication-type none&lt;BR /&gt;no multi-band-operation&lt;BR /&gt;no protected-mgmt-frames&lt;BR /&gt;wpa-wpa2 psk 0 ........................&lt;BR /&gt;!&lt;BR /&gt;wlan wlan2&lt;BR /&gt;ssid smartnet&lt;BR /&gt;vlan 1&lt;BR /&gt;bridging-mode local&lt;BR /&gt;encryption-type tkip-ccmp&lt;BR /&gt;authentication-type none&lt;BR /&gt;no multi-band-operation&lt;BR /&gt;no protected-mgmt-frames&lt;BR /&gt;wpa-wpa2 psk 0 .........................&lt;BR /&gt;!&lt;BR /&gt;smart-rf-policy default&lt;BR /&gt;no select-shutdown&lt;BR /&gt;!&lt;BR /&gt;wips-policy default&lt;BR /&gt;!&lt;BR /&gt;radius-server-policy default&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;management-policy default&lt;BR /&gt;telnet&lt;BR /&gt;no http server&lt;BR /&gt;https server&lt;BR /&gt;rest-server&lt;BR /&gt;ssh&lt;BR /&gt;user admin password 1 .................. role superuser access all&lt;BR /&gt;no snmp-server manager v3&lt;BR /&gt;!&lt;BR /&gt;event-system-policy default&lt;BR /&gt;!&lt;BR /&gt;nsight-policy default&lt;BR /&gt;!&lt;BR /&gt;profile ap7632 361&lt;BR /&gt;ip name-server 192.168.163.1&lt;BR /&gt;ip name-server 8.8.8.8&lt;BR /&gt;ip default-gateway 192.168.163.1&lt;BR /&gt;autoinstall configuration&lt;BR /&gt;autoinstall firmware&lt;BR /&gt;crypto ikev1 policy ikev1-default&lt;BR /&gt;isakmp-proposal default encryption aes-256 group 2 hash sha&lt;BR /&gt;crypto ikev2 policy ikev2-default&lt;BR /&gt;isakmp-proposal default encryption aes-256 group 2 hash sha&lt;BR /&gt;crypto ipsec transform-set default esp-aes-256 esp-sha-hmac&lt;BR /&gt;crypto ikev1 remote-vpn&lt;BR /&gt;crypto ikev2 remote-vpn&lt;BR /&gt;crypto auto-ipsec-secure&lt;BR /&gt;crypto load-management&lt;BR /&gt;crypto remote-vpn-client&lt;BR /&gt;interface radio1&lt;BR /&gt;wlan wlan1 bss 1 primary&lt;BR /&gt;wlan wlan2 bss 2 primary&lt;BR /&gt;antenna-mode 2x2&lt;BR /&gt;interface radio2&lt;BR /&gt;wlan wlan1 bss 1 primary&lt;BR /&gt;antenna-mode 2x2&lt;BR /&gt;interface bluetooth1&lt;BR /&gt;shutdown&lt;BR /&gt;mode le-sensor&lt;BR /&gt;interface ge1&lt;BR /&gt;interface vlan1&lt;BR /&gt;ip address dhcp&lt;BR /&gt;ip address zeroconf secondary&lt;BR /&gt;ip dhcp client request options all&lt;BR /&gt;interface pppoe1&lt;BR /&gt;no use firewall-policy&lt;BR /&gt;use client-identity-group default&lt;BR /&gt;logging on&lt;BR /&gt;service pm sys-restart&lt;BR /&gt;router ospf&lt;BR /&gt;adoption-mode controller&lt;BR /&gt;!&lt;BR /&gt;rf-domain default&lt;BR /&gt;location "361"&lt;BR /&gt;contact admin&lt;BR /&gt;timezone Asia/Tashkent&lt;BR /&gt;country-code uz&lt;BR /&gt;ad-wips-wireless-mitigation disable&lt;BR /&gt;ad-wips-wired-mitigation disable&lt;BR /&gt;use nsight-policy default&lt;BR /&gt;!&lt;BR /&gt;ap7632 B4-2D-56-8A-88-90&lt;BR /&gt;use profile 361&lt;BR /&gt;use rf-domain default&lt;BR /&gt;hostname AP-01.361&lt;BR /&gt;no mint mlcp vlan&lt;BR /&gt;no mint mlcp ip&lt;BR /&gt;interface vlan1&lt;BR /&gt;description "Virtual Interface for LAN by Wizard"&lt;BR /&gt;ip address 192.168.163.3/24&lt;BR /&gt;ip address zeroconf secondary&lt;BR /&gt;no ip dhcp client request options all&lt;BR /&gt;no virtual-controller&lt;BR /&gt;no rf-domain-manager capable&lt;BR /&gt;no adoption-mode&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;end&lt;BR /&gt;AP-01.361*#&lt;/LI-SPOILER&gt;</description>
      <pubDate>Sat, 23 Dec 2023 13:40:49 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/ap7632-connection-problem/m-p/98571#M9358</guid>
      <dc:creator>AmirA</dc:creator>
      <dc:date>2023-12-23T13:40:49Z</dc:date>
    </item>
  </channel>
</rss>

