Simcfc73 Posted September 6, 2020 Posted September 6, 2020 Hi, Apologies if this has been asked before. I've got some really weird WIFI issues in school. For some reason some of my AP's will stop responding to pings for long periods.. I say stopped responding but they reply once every 6th ping. I can't SSH into them either but they sometimes come back to working but its very random. Rebooting the AP doesn't help, it goes back to the weird pings. I was told about the weird broadcast issues with Unifi and Netgear switches which I have been round and sorted but its still happening. Its been suggested its a network loop somewhere but I've triple checked and I cant see one and STP is on everywhere. I would love to rip out the Netgear stuff and stick new UI switches in. I've got 25 Netgear switches left and 5 new UI ones so its a costly upgrade. It is very random but its ruining some of the WIFI areas. Its very random and Wireshark doesn't show anything obvious, I can see some Ubiquiti broadcast traffic but nothing OTT. I did get unifi involved and got to the stage of RMAing them back but I'd tested it off my network and the AP's act perfectly so something is definitely amiss. Anyone seen anything similar?
Davit2005 Posted September 7, 2020 Posted September 7, 2020 Suggest switching STP off on Unifi if you have no loops and no redundant connections that would cause a loop. It does sound like a STP issue and I have seen some strange behaviour with the Unifi switches before that have STP enabled
gh5000 Posted September 8, 2020 Posted September 8, 2020 Suggest switching STP off on Unifi if you have no loops and no redundant connections that would cause a loop. It does sound like a STP issue and I have seen some strange behaviour with the Unifi switches before that have STP enabledHi, Just checking, do you mean to switch off STP from all switches, or just on the ports that Unifi access points are connected to?
jslate1980 Posted September 8, 2020 Posted September 8, 2020 Hi, Just checking, do you mean to switch off STP from all switches, or just on the ports that Unifi access points are connected to?I had to turn mesh off between aps are rapid spanning tree protocol seem to confuse the switches.
Simcfc73 Posted September 9, 2020 Author Posted September 9, 2020 I've disabled STP but still weird. An example of pinging today.. then all of a sudden on its own it comes back to life. Stupid thing Reply from 192.168.100.185: bytes=32 time=2ms TTL=64Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Reply from 192.168.100.185: bytes=32 time=8ms TTL=64Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Reply from 192.168.100.185: bytes=32 time=1ms TTL=64Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Reply from 192.168.100.185: bytes=32 time=1ms TTL=64Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Reply from 192.168.100.185: bytes=32 time=1ms TTL=64Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Reply from 192.168.100.185: bytes=32 time<1ms TTL=64Request timed out.Request timed out.Reply from 192.168.100.185: bytes=32 time=2ms TTL=64Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Reply from 192.168.100.185: bytes=32 time=2ms TTL=64Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Reply from 192.168.100.185: bytes=32 time=3ms TTL=64Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Reply from 192.168.100.185: bytes=32 time=1ms TTL=64Reply from 192.168.100.185: bytes=32 time<1ms TTL=64Reply from 192.168.100.185: bytes=32 time=2ms TTL=64Reply from 192.168.100.185: bytes=32 time<1ms TTL=64Reply from 192.168.100.185: bytes=32 time=1ms TTL=64Reply from 192.168.100.185: bytes=32 time=2ms TTL=64Reply from 192.168.100.185: bytes=32 time=1ms TTL=64Reply from 192.168.100.185: bytes=32 time<1ms TTL=64Reply from 192.168.100.185: bytes=32 time=2ms TTL=64
Davit2005 Posted September 9, 2020 Posted September 9, 2020 Can you plug an AP directly into the switch port to negate any physical cable issues. Worth a try as you say you have tried the AP's off the network and they seem fine, just try and break it down to small steps. Do the APs that have issues all plug in Unifi switches or the Netgears or is it random.
Simcfc73 Posted September 9, 2020 Author Posted September 9, 2020 Its random. One area I always had issues with where the AP would vanish I ended up swapping for another AP.. same cable and switch and it seems to be much better but I reckon there's 4 doing similar things so I didn't think it would be a hardware issue. The other area that's terrible (from the ping above) is plugged into a UI switch now after being plugged into a Netgear one. I've used Wireshark to mirror the port but there's nothing obvious that's wrong.. I can see a ubiquiti multicast every now and again but nothing much to report. I've got it to work on an offline setup.. but when it goes online they break.. I've tried different cables, switches but they just act up. Its almost like there's something on the network that they don't like but I've checked everything and I can't see it.
Simcfc73 Posted September 23, 2020 Author Posted September 23, 2020 Hi, Just an update on this which has highlighted a situation but not a solution. If I have the access point on the network with no wireless networks attached to it then they ping perfectly. As soon as I add any wireless connections to them they start to act up. I've go 3 wireless networks. VLAN 1, 20 and 40 and I've experimented and it does it with them all.. even when I only add VLAN 1. I've just looked now an I can see the weird ping acting like below. As soon as I remove the wireless and reboot the switch it never misses a ping. Its been mentioned I may have a loop but I've checked and if there is I can't see it. I've tried port isolation.. stp off and on but nothing works. I actually thought it was something to do with my XG firewall as its routing from the VLAN to my main network for the intranet page but I've disabled that and its not that. I'm at the stage of moving the AP's and controller onto its own VLAN but its a bit of an effort when I don't even know if it will help. Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Reply from 192.168.100.183: bytes=32 time=1ms TTL=64Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Reply from 192.168.100.183: bytes=32 time=2ms TTL=64Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.
Davit2005 Posted September 24, 2020 Posted September 24, 2020 (edited) Hi, Just an update on this which has highlighted a situation but not a solution. If I have the access point on the network with no wireless networks attached to it then they ping perfectly. As soon as I add any wireless connections to them they start to act up. I've go 3 wireless networks. VLAN 1, 20 and 40 and I've experimented and it does it with them all.. even when I only add VLAN 1. I've just looked now an I can see the weird ping acting like below. As soon as I remove the wireless and reboot the switch it never misses a ping. Its been mentioned I may have a loop but I've checked and if there is I can't see it. I've tried port isolation.. stp off and on but nothing works. I actually thought it was something to do with my XG firewall as its routing from the VLAN to my main network for the intranet page but I've disabled that and its not that. I'm at the stage of moving the AP's and controller onto its own VLAN but its a bit of an effort when I don't even know if it will help. Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Reply from 192.168.100.183: bytes=32 time=1ms TTL=64Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Request timed out.Reply from 192.168.100.183: bytes=32 time=2ms TTL=64Request timed out.Request timed out.Request timed out.Request timed out.Request timed out. Separating the APs onto their own vlan with the controller would certainly be a good move and see if there are any issues and pinging directly on that network, it is worth the effort to split up and keeps the management traffic away from your normal data traffic. There is some weirdness going on there. Edited September 24, 2020 by Davit2005
Simcfc73 Posted September 24, 2020 Author Posted September 24, 2020 Here is some more weirdness. I stupidly updated my controller to v6 and this morning 6.0.23 came out so I installed it hoping it would fix at least some of the issues. On my VLAN 40 with the Guest Portal assigned to it clients now ignore the portal page and go directly to the Sophos XG page... so Radius SSO is ignored. When I look at the clients on the UNIFI they have the option to Authorise.... so they are connecting to the WIFI directly without having to logon. Maybe something has changed in the update but I can't see it. - - - Updated - - - PS, the UNIFI Community is imploding a bit... worrying messages coming from it.
Davit2005 Posted September 24, 2020 Posted September 24, 2020 (edited) Here is some more weirdness. I stupidly updated my controller to v6 and this morning 6.0.23 came out so I installed it hoping it would fix at least some of the issues. On my VLAN 40 with the Guest Portal assigned to it clients now ignore the portal page and go directly to the Sophos XG page... so Radius SSO is ignored. When I look at the clients on the UNIFI they have the option to Authorise.... so they are connecting to the WIFI directly without having to logon. Maybe something has changed in the update but I can't see it. - - - Updated - - - PS, the UNIFI Community is imploding a bit... worrying messages coming from it. Unifi has had a few bad updates recently 6.0.20 and 6.0.22 . Did not effect everyone but quite a few people have had issues. Take a look at Lawrence Systems YouTube channel, he is not affiliated with Unifi/Ubiquiti to my knowledge but has done some videos explaining some of the issues. Edited September 24, 2020 by Davit2005
Simcfc73 Posted September 24, 2020 Author Posted September 24, 2020 I've watched a few of his videos... and Crosstalk solutions who walked me through my SIP setups. I'm actually at the point of looking at outside help to get this sorted as the strangeness is baffling. Earlier today I was able to connect through the BYOD without being authorised... it hit the XG logon page so bypassed all the Radius SSO I have setup. I created a new wireless connection with the same radius auth and it went to the right logon page and authenticated with radius on the XG box. I do think there's something a bit weird going on with roaming and my DHCP. I've got it running on VLAN 40 which gets dished out by the XG box... I've just roamed now and it lost its connection.. when I try and connect its already authorised by the Unifi controller but has been disconnected by the XG so I have to sign in again. So for some reason I'm getting a disconnected in the XG box. I was tempted to buy a USG just for my VLANs so at least I knwo they will talk to each other nicely and 'should' integrate.
Simcfc73 Posted September 29, 2020 Author Posted September 29, 2020 I may be tempting fate but I may have fixed it.. abliet by opening up a bit too much which i am locking down as I type. I decided to move the APs onto a different management LAN and set a route back to the controller on VLAN 1. Worked really well (as soon as I remembered to set them to DHCP before setting the management VLAN), I set the Vlan and they picked u[p the new IP and registered with the controller. So now I need to work out what traffic to go between the VLANS, obviously the ports to register to the controller but I need to work out what to open up so the clients onthe VLAN get logged on via the portal and authenticated with my radius. Weird things too (probably not). If I set the port to the FW just with the VLAN tag it fails.. I have to tag them all. I thought it would work just with the port on the FW and the port connected to the switch on the same VLAN but it only works if VLAN 1 is tagged too.
Davit2005 Posted September 29, 2020 Posted September 29, 2020 I may be tempting fate but I may have fixed it.. abliet by opening up a bit too much which i am locking down as I type. I decided to move the APs onto a different management LAN and set a route back to the controller on VLAN 1. Worked really well (as soon as I remembered to set them to DHCP before setting the management VLAN), I set the Vlan and they picked u[p the new IP and registered with the controller. So now I need to work out what traffic to go between the VLANS, obviously the ports to register to the controller but I need to work out what to open up so the clients onthe VLAN get logged on via the portal and authenticated with my radius. Weird things too (probably not). If I set the port to the FW just with the VLAN tag it fails.. I have to tag them all. I thought it would work just with the port on the FW and the port connected to the switch on the same VLAN but it only works if VLAN 1 is tagged too. If the clients SSID vlan is not different it should not effect the portal, you have only moved the management of the APs to separate vlan? You will need to allow the radius ports through to the radius server though from the APs. Normally on the switch you would tagg the SSID vlan and just untagg the management vlan with Unifi. I have my Unifi Controller on the same vlan as the APs at home but that probably isn't necessary and may look at moving eventually. NOt sure if below would help https://help.ui.com/hc/en-us/articles/218506997-UniFi-Ports-Used
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now