cancel
Showing results for 
Search instead for 
Did you mean: 

After Moving to Aerohive NG management platform we are having clients keeping their old IP address from other locations. This is causing the clients to stay connected but not access anything internal or external.

After Moving to Aerohive NG management platform we are having clients keeping their old IP address from other locations. This is causing the clients to stay connected but not access anything internal or external.

wendland_jm
New Contributor

We are running 10.0r7a on 98% of our AP250 and AP230. Some Background info, we have most of our building segmented on different subnets but using the same SSID for all buildings and are using an external radius server for authentication. All APs in a building are issuing the same subnet scope and VLAN. We have already tried GRE Tunneling (this made the issue worse). We have done a VLAN Probe test and the AP successfully passes the test for its Building VLAN. 

 

The issue is when a client is connected in building A on VLAN-A and IP address int subnet A and the client moves to building B the clients stays connected but has no access to anything due to the client keeping their IP address form building A. This is happening on all devices (apple,android,windows,chrome) but it does not happen all the time. A client can move from building A to B (no issue) then to building C and have the issue. Suggestions would be a great help.

 

Thank you.

15 REPLIES 15

dparsons
Contributor

And unfortunately you will continue to have issues. The device cannot tell that it has moved to a new VLAN since from what it can tell it is on the same network. The only option is to set you DHCP life time to a few seconds (Windows minimum is one minute) but that is going to flood your network. In short this is not a good design. I have to ask why you did this?

 

We ran into the same issue with two separate sites using the same SSID but different VLANs due to the site being on the end of a VPN and no means to retain the same VLAN. In the end we had to change the SSID at the remote site so the devices could determine that it was a different network and ask for a new IP. Recent updates to windows has made it even worse.

 

On Windoze when the device connect to a wireless network that it has connected before it will use the IP address that was issued to it during the prior session unless it has expired. It speeds up the connection process. Just think if every time a device changed APs (same building or not) that it had to do a DHCP request. The device has no means to detect what VLAN is behind the SSID it is connecting to (yeah I said it again).

 

 

GTM-P2G8KFN