STAs Cannot Obtain IP Addresses Occasionally
Fault Symptom
The auto-defend action deny timer 60 punish action is configured on the ACU2 serving as a DHCP relay. The ACU2 periodically discards packets from the DHCP server, causing STAs' failures to obtain IP addresses.
Procedure
- Check whether attack source punish is configured.
Error-prone configuration:
<AC6605> display current-configuration | include cpu-defend
Suggestion: Check whether DHCP packet attack exists, and take caution when configuring punish actions.
- Check whether VLAN 1 is configured as a service VLAN.
Error-prone configuration:
<AC6605> display current-configuration | include service-vlan
Suggestion: Properly plan service VLANs and avoid configuring VLAN 1 as a service VLAN.
[AC6605-wlan-view] vap-profile name vap1 [AC6605-wlan-vap-prof-vap1] service-vlan vlan-id 101