Migrate to PA firewall cause WIFI roaming issue

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Migrate to PA firewall cause WIFI roaming issue

L3 Networker

Hi Support,

We just recently migrate the PA Firewall from cisco firewall. PA Firewall will act as gateway and provide DHCP.
however we counter issue with roaming WIFI where client connected to AP A and change location to AP B without disconnect causing loss internet connection. We don't see any drop at all in firewall logs. so we not sure how to troubleshoot this.  as previously cisco firewall is working fine with WIFI roaming.  The WLC and AP we use Ruckus vendor (virtual smartZone)

 

Any idea, or experience on similar issue much appreciate if you can share with us.

 

Thank you

 

 

3 REPLIES 3

Cyber Elite
Cyber Elite

how are both your AP connected in relation to the firewall? do they 'join' in the middle on a switch or are they plugged into their own respective port on the firewall?

does the user retain the same IP when hopping AP? you could try running a filtered packet-diag to see what is happening once they hop

 

debug dataplane packet-diag clear all  
debug dataplane packet-diag set filter match source x.x.x.x
debug dataplane packet-diag set filter on

show counter global filter delta yes packet-filter yes 

run that last command several times during the transition to see if any drop counters pop up 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L2 Linker

Hmm,

 

I have a similar setup with Ruckus and having issues.  I kept thinking it was my Ruckus configuration.  I'll keep an eye on this post.

 

Raul Trujillo

Hi Tom 

 

Thank you for input.

 

1. how are both your AP connected in relation to the firewall? do they 'join' in the middle on a switch or are they plugged into their own respective port on the firewall?
-- The AP is connected to the switch but not directly into firewall port. They connected to the switch that had another uplink until their packet arrived at firewall. Maybe we can call it ' join' in the midlle ?

2. does the user retain the same IP when hopping AP?
-- yes, the user retain the same IP when hopping AP

 

3. i am collecting the packet diag but Should the x.x.x.x filled with my AP ip subnet ? for example 192.168.24.0 ?

Thank you 

Fariq

 

  • 715 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!