07-14-2021 07:25 AM
Hi everyone,
I´ve some strange situation with Android Smartphones in our Aerohive/Extreme Network (Mix of AP250 and 305C) environment.
The Android devices itself get´s an valid IP and authenticated to the Wifi but shows the information “maybe don´t have internet connection”.
Actual Workaround: Ping the device. The first 2 packages are lost, but than the device replies and shows connected.
I´ve started this discussion last year, but with Covid-19 the situation stuck.
I´ve also found that we are not the only one with this situation.
I can confirm that DNS port 53 and 853 is open for this dedicated Wifi VLAN on our firewall.
I´ve added the DNS ports for the native VLAN of the APs to this internal DNS server, now.
Does anyone has an idea, if this won´t help, how we could troubleshoot this?
Thankful for every idea!
Solved! Go to Solution.
09-07-2022 02:06 AM
Hi,
I want to send an update about this topic.
We found the root cause for our problem, but I´m unsure how to solve it.
The ARP-cache on our firewall which is also the Gateway for our Guest Network seems to get some wrong information from the Aerohive environment.
The Guest Wifi has a short Lease time on DHCP side (5min, increased to 15min now).
The client itself gets the correct IP from DHCP Server (same VLAN/subnet, Windows Server), but the Firewall still get´s the wrong information after a arp-cache clear.
We deleted the "wrong" client in the IQ Management and cleared the ARP-cache once again and the problem was solved for this device.
We found an option in the "Management Options" called "disable Proxy-ARP":
Would it make sense to activate this option in a Wifi environment?
Arp-Caches are written on the Gateway and Switch devices.
09-07-2022 02:06 AM
Hi,
I want to send an update about this topic.
We found the root cause for our problem, but I´m unsure how to solve it.
The ARP-cache on our firewall which is also the Gateway for our Guest Network seems to get some wrong information from the Aerohive environment.
The Guest Wifi has a short Lease time on DHCP side (5min, increased to 15min now).
The client itself gets the correct IP from DHCP Server (same VLAN/subnet, Windows Server), but the Firewall still get´s the wrong information after a arp-cache clear.
We deleted the "wrong" client in the IQ Management and cleared the ARP-cache once again and the problem was solved for this device.
We found an option in the "Management Options" called "disable Proxy-ARP":
Would it make sense to activate this option in a Wifi environment?
Arp-Caches are written on the Gateway and Switch devices.
09-01-2022 06:46 AM
set a rssi threshold to -70
disable band steering or load balancing
disable private wlan adress on client
08-19-2022 09:05 AM
09-01-2022 06:36 AM
Hi,
I´ve maybe found an workaround for that.
We still experience this situation in different locations.
The setup:
Firewall (VLAN as GW, tagged) -> Core switch VLan (Vlan tagged on Port) -> Access switch (Vlan tagged on Port)-> AP (SSID VLAN, tagged)
SSID: VLAN which uses the Firewall as Gateway.
DHCP: relay on Firewall for VLAN subnet
DNS: Google 8.8.8.8
DHCP Lease Time: 30min
What is seen in the logs:
Client gets an IP from DHCP and tries to contact DNS several times.
No more other traffic is generated than DNS.
Workaround:
Clear the ARP-Cache on the Firewall/Routing device.
in our case the command "clear arp-cache".
08-19-2022 08:05 AM
Hi,
we are using the Aerohive/Extreme APs in an enterprise environment with a licensed On-Prem management server v21.1.22.1-IQVA.
The newest AP firmware for that management is actually 10.3.r3.
Never seen the free version or Cloud version, but we need to change to the Cloud version because we get the information that the On-Prem is EOS in December 2022.
How is your Home use setup?
AP is connected via patch line to the ISP Router which is used for DHCP, DNS, Firewall and Gateway?
No VLAN etc?