On-site WX3840X performs MAC authentication + portal mac-trigger authentication with local forwarding. The issue observed is that terminals fail to obtain an address during initial connection, even though the wireless template has client-security ignore-authentication configured to disregard authentication results. After removing the MAC authentication configuration on-site, terminals can successfully obtain addresses and proceed with portal authentication.
The guest VLAN was also not used on-site.
View configuration:
wlan service-template XXX-guest
ssid XXX-Guest
vlan 198
client max-count 512
client forwarding-location ap
client-security authentication-mode mac
client-security ignore-authentication
mac-authentication domain domain_mac
undo bss transition-management enable
portal enable method direct
portal domain domain_portal
portal bas-ip 1.1.1.1
portal apply web-server newpt
service-template enable
Capture uplink packets on AC:
Only request found
The server does not respond, no reject.
In the absence of clear success or fail, meaning if the AAA server does not respond, the ignore command will not take effect. Thus, the verify result cannot be ignored.
Need to investigate the AAA side