Can't get Guest clients to associate

Unanswered Question
Aug 26th, 2010

Hi All,

This seems to have happened after upgrading to v7: I've a test guest SSID that my test client PC cannot connect to as it seems to immediately try to associate with the corporate secure SSID. The foreign controller debug showed a line that said something to the effect of "deleting client as SSID has changed" (I was not able to capture this unfortunately and I have not spotted it again), and it then goes on to produce debug outputs as it tries to connect to the corporte SSID. The anchor controller for the guest SSID does not seem to have the traffic passed to it.

Any suggestions?

Many Thanks


I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 4 (5 ratings)
Andrew Betz Tue, 09/07/2010 - 12:25

Hi Scott,

Would you mind capturing the following from both the foreign, and anchor WLCs:

debug client

Is the anchor WLC acting as the DHCP server?  If so, you may be hitting the following:

/* Style Definitions */ table.MsoNormalTable {mso-style-name:"Table Normal"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-priority:99; mso-style-qformat:yes; mso-style-parent:""; mso-padding-alt:0in 5.4pt 0in 5.4pt; mso-para-margin-top:0in; mso-para-margin-right:0in; mso-para-margin-bottom:10.0pt; mso-para-margin-left:0in; line-height:115%; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-fareast-font-family:"Times New Roman"; mso-fareast-theme-font:minor-fareast; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin; mso-bidi-font-family:"Times New Roman"; mso-bidi-theme-font:minor-bidi;}

CSCth68708    Clients are unableto get a DHCP offer from WLC internal DHCP scope

The debug client output will allow you to see if the client is obtaining an IP address as expected, and whether or not the Guest traffic is being tunneled properly to the anchor. If you're finding that the test client continually connects to your corporate WLAN, I would recommend removing all profiles but the Guest WLAN to ensure you're not fighting a supplicant issue.



scottwilliamson Wed, 09/08/2010 - 03:21

Hi Andrew,

I've attached the debug output from the Foreign WLC, I cannot get any output from the Anchor as the traffic isn't getting passed on. Other SSIDs from the same Foreign using the same Anchor work ok, so I'm starting to suspect that something has gone awry with the config of the SSID on the Foreign WLC, but I cannot see anything wrong; would you recommend deleting it and starting again?

Many Thanks,


Andrew Betz Wed, 09/08/2010 - 05:33

Hi Scott,

Thanks for attaching the debug.  So, it looks like this client is connecting to your corporate network (since we see a lot of EAP exchanges).  Can I have you test with another client that is not configured for the corporate WLAN?  Please be sure to run the debugs on both the anchor and foreign WLCs simutaniously.  It is also important to note that the configuration for the anchored WLAN must be identical on both.  If there is a slight difference, anchoring will fail.

Thanks again,


Andrew Betz Mon, 09/13/2010 - 05:52


Glad to hear you were able to locate that Windows XP SP2 patch for PEAP.

Take Care,



This Discussion

Related Content



Trending Topics - Security & Network