Case Study: After a WLAN Device Is Upgraded from V200R007 to V200R019, Services Are Interrupted After the Access Control System Connects to the Wireless Network
Symptom
In a scenario where MAC address-prioritized Portal authentication is configured and a WLAN device is upgraded from V200R007 to V200R019, services are interrupted after the access control system connects to the wireless network.
Relevant Alarms and Logs
None
Cause Analysis
After an access control device is associated with a wireless network, the device does not proactively send ARP requests or receive unicast ARP packets.
The default configuration of the traffic-optimize bcmc unicast-send arp command varies on ACs of different versions. The details are as follows:
V200R007: By default, the function of converting broadcast or multicast DHCP packets to unicast DHCP packets on an air interface is not configured.
V200R019: By default, the function of converting broadcast or multicast packets to unicast packets on an air interface has been configured.
Procedure
- Manually configure an IP address for the access control device. Check the online information about the access control device on the AC. It is found that the device does not have an IP address.
- Use the trace function to check the STA login process and analyze MAC address authentication. The MAC address of the access control device is successfully authenticated, and the AP does not report the IP address of the access control device.
- Use the station-trace function to check the ARP packet exchange process of the STA. It is found that after the access control device goes online, ARP information is not sent and no other device performs ARP detection on the access control device.
[AC-diagnose] station-trace sta-mac sta-mac
- Compared with other STAs, such as mobile phones and PCs, the communication is normal after they are connected to the wireless network. It is suspected that the access control device does not support ARP unicast packets.
- Run the undo traffic-optimize bcmc unicast-send arp command in the traffic profile to disable the function of converting broadcast or multicast ARP packets to unicast ARP packets.
- Use the station-trace function to check the STA login process again. It is found that the ARP packet exchange between the access control system and the platform is normal and services are restored. Run the display station all command to display access information about STAs, which contains the IP address of the access control device.