Monday, October 29, 2018

Interesting issue with Palo Alto firewall and Cisco wireless controller.

All,

I know networking advice isn't cheap so I will try to be as succinct as possible.

I have a PA-820 with a very simple setup that includes a vlan object and a virtual router with a DHCP server. My LAN is 192.168.1.254/24, subnet 255.255.255.0, gateway 192.168.192.254.

In theory my DHCP server is 192.168.1.254, and when I connect devices, I receive leases as expected from the above IP.

However, when I hooked up a Cisco 2504 WLC and configured it, I pointed the gateway to 192.168.1.254, left the DHCP server to 'undefined' so it acts as a pass-through, but I can't get any Cisco 3802i APs to connect to save my life.

I'm not a network engineer by trade, and didn't have a serial port accessory available, but whether I used a DHCP proxy, pass-through, or internal to the WLC, the AP would not connect.

My setup is:

Fiber -> PA-820 -> Cisco 3850 -> 2504 & 3802.

Is this anything to do with my PA firewall blocking the capwap requests?



No comments:

Post a Comment