Hi all
I have just observed some strange wireless behaviour, and just wanted to know if anyone else is seeing something like this.
I have boiled the network down to this (in order to keep it as simple as possible).
2 APs on the same switch (with the same wireless config of course). Both the APs are of course connected to trunk ports on the switch, so the appropriate VLAN for the client is available.
There is also a firewall that can route between VLANs, because we have a wired client on another VLAN continuously pinging the problematic client ( to keep "track" of when this problem occurs ) , and to keep it simple, "permit any any" is in effect on the firewall 🙂
The wireless client in question is of course always connected to the same VLAN.
So here is the problem / scenario:
Client authenticates to AP1 using iPSK.
ISE says everything is good.
Dashboard says the client is connected.
Client also says its connected.
The client can pass traffic to the network and everything is good.
- So far so good.
Client now moves to AP2 - and roams.
ISE says that the authentication is still good
Dashboard also says that the client is connected (now to AP2)
Even the client says its connected.
But no traffic is passed to the network, it just stops 😕
Doing a "ping" from the client page in dashboard (that in reality is not ICMP but ARP I think from the AP) gives a response from the client. But the PC on the other network can no longer ping the client.
If I then move back to AP1, when the client roams to AP1 - everything works again.
I have no idea what happens, and cause this to fail.
Everything says its ok. So I feel that something inside the AP fails.
When I change the client to a network running iPSK without Radius, or just plain PSK the roaming between the two APs work everytime.
------------------------------------------------------------------------------------------------------------------------------
Any suggestions ? - Or do anyone know of a known bug that could cause this kind of problem ?
NB: Equipment used : 2 x MR46E - 1 x MS120-8LP and 1 x MX68 and one ISE 🙂 In case anyone wants to replicate it 🙂 - The wireless client is setup with a static IP address (just wanted to mention this in case this could be a problem).