Why Does Roaming Fail in Direct Forwarding Mode After IPSG Is Configured on a GE Port?
After the IP Source Guard (IPSG) function is enabled using the ip source check user-bind enable command on a switch, some STAs may not initiate DHCP requests during roaming, thereby causing roaming failures.
If a STA roams from Ethernet 22 to Ethernet 23 and does not initiate a DHCP request, Ethernet 23 does not generate a snooping entry. In this case, all IP packets are discarded.
The following solutions are available:
Solution 1: Disable the IPSG function on the switch, because this function takes effect for wired users as well as wireless users in direct forwarding mode.
Solution 2: Set the forwarding mode to tunnel forwarding on the AC so that the IPSG function does not work for tunnel packets.