Cisco :: 4400 / 5508 Controllers - 802.1x Re-Authentication

Mar 28, 2012

Currently in the process of migrating from psk to 802.1x radius environment using a mix of 4400 and 5508 controllers with WCS using Microsoft ias.  The problem I have is there is a lot of shared iPads and tablets in the environment.  Is there a way to force these user to relogin to radius after a certain time period so they are not  sharing unames and passwords?

View 1 Replies


ADVERTISEMENT

Cisco :: 4400 Controllers Which Support 50 Access Points Each

Jun 25, 2011

We have two 4400 controllers which support 50 Access points each and wcs with 100 base license.Now we added 5508 controller supports 50 access points.wcs is upgraded with another 50 ap license.The 5508 controller is joined to wcs and the licence showing permanent.WCS showing all aps and showing both 100 and 50 licence as permanent.But the issue is while loging into the wcs it showing the error message as"The system is in violation of license.The number of APs registered is greater then licensed."

View 5 Replies View Related

Cisco Wireless :: Roaming Between 4400 And 5500 Controllers

Oct 11, 2012

Actually we have a 4402 controller with 1120 APs both of which are marked as EoL products, we want to jump over the new 2600 APs and 5508 Controller for increase signal coverage but we have the following deals:Last firmware for 4402 controller is 7.0.Firmware needed for 5508 to support 2600 APs is 7.3.Is it possible to configure mobility between 4402 and 5508 even with different firmware branch?

View 3 Replies View Related

Cisco :: Deploying 4400 Controller As An Anchor For 5500 Controllers?

Jun 7, 2011

in one of the sites, the client has an exisiting 4402 controller which he moved to the DMZ in order to set it as an anchor & he purchased two new 5508 controllers to control the corporate APs.  I configured all the parameters needed for the guest anchoring & then I tested the connection but there was an issue. (all the controllers are running the same firmware version)after testing the setup, the guest users could get an IP from the internal DHCP of the anchor controller (in DMZ), but then they cannot reach the internet or anything outside the anchor controller.Cisco confirmed that the 4400 is fully compatible with the 5500 to work in an anchor-foreign secnario as long as they are running the same firmware version. yet, when I temporarily used one of the 5500 controller in the DMZ as an anchor & I applied the exact same configurations on it as the 4400, it worked perfectly without any issues.
 
note:  on the anchor controller (4400), the management & AP-manager interfaces reside on the same subnet & the wireless guest SSID is also mapped to the management interface.  (may be this setup is causing the issue) but on the 5500 it is working just fine?

View 2 Replies View Related

Cisco Wireless :: To Switch Which Of 2 WLAN Controllers 4400 And 5500

Aug 23, 2012

I have 2 WLAN controllers, a 4400 series and 5500 series controller.  The 4400 series has 100 seat limit on it, with 74 Access Points currently connected.  The 5500 series has a 250 max, but we bought it with only 50 licenses, and it is max'd out at 50.The 5500 controller is the controller that has a DNS entry so that the Access Points will know to find that controller as they're being added.  BUT, because we've reached our limit of 50 licenses, I'd like to be able to set the 4400 series controller to be the controller that new Access Points try to connect to.  By going back to the 4400 as the controller that new Access Points connect to buys me time to plan for more licenses on next years budget for the 5500 controller.

View 29 Replies View Related

Cisco :: 5508 Wireless Controllers Freezing?

Dec 6, 2011

Our controller get freezing every week at least twice, and do not know what is the reason. I am attaching the log for you to look at it. Last time happened was yesterday at around 13.00 pm.

View 15 Replies View Related

Cisco :: Can't Do Radius Authentication Via WLC 4400

Jan 3, 2013

I am configuring an old WLC4400 with V4.2.130.0. I added a new sub-interface for VLAN 50 with proper IP for the subnet and then add the Radius server(Windows server 2008 with NPS) onto WLC4400. I then created new WLAN with WPA+WPA2 Encryption and 802.1x key management and selected the Radius server under AAA for authentication.
 
Configured the test XP with WPA-Enterprise and PEAP as EAP method. I purposely configured computer to prompt for username and password.
 
When I try to connect, I did get prompt for username and password. However after that nothing happens. It seems like laptop just keep trying to authenticate.
 
I checked windows event log and do not see anything under NPS. I know this windows server NPS setup works as it is also the authentication server for our remotevpn.
 
is there any special option I need to turn on for WLC in order for Radius authentication work? Or is there any known bug with V4.2.130.

View 13 Replies View Related

Cisco :: WLC 4400 - Web Authentication Using LDAP

Mar 14, 2011

I have some problems integrating WLC 4400 with AD using ldap. The the WLC LDAP Server and W LAN for Web Authentication are configured according to [URL].
 
when I connect to SSID the laptop is given the ip address, then I can see the web-page with lo gin and password - it seems to be OK, but when I enter lo gin and pass it tells me, that it's incorrect.  
 
The attributes of the LDAP server:
 
Server Address                              *.*.*.*
Port Number                                 389        
User Base DN                                ou=ORG,dc=domain,dc=local
User Attribute                              userPrincipalName         
User Object Type                            Person
 
the test user is located in AD folder ORG, but this folder also contains a lot of sub trees
 
There are some questions:

1) Is it obligatory to use value "Authenticated" in the Simple Bind option or it can be Anonymous?
2) Is the Controller capable for searching the users located in User Base DN sub trees?
  
Here is some debug from the controller:
 
667: LDAP_CLIENT: UID Search (base=.....
669: LDAP_CLIENT: ldap_search_ext_s returns 0 85
669: LDAP_CLIENT: Returned 1 msgs including 0 references
[Code]....

View 6 Replies View Related

Cisco :: 5508 Controllers Not Redirecting Client Requests To ISE

Jun 5, 2013

Please find attached a simple BYOD/ISE document I uploaded to kick start my new Wireless setup. Its all configured on my ISE sever and Controller as per doc.My setup:
 
-3600 AP's
-Internal 5508 Controller
-DMZ 5508 Controller (acts as a DHCP server for wireless clients)
 
Controllers have established connectivity (mobility acnhors), as a client I can connect fine to my new SSID get a DHCP IP address back from DMZ WLC and at the moment can connect out to the Internet fine (using no WLAN Security as a test). So this part is working.I have now followed the document configured ISE, enabled AAA on the Internal WLC only and used the AAA override setting on WLAN as in the attached document.I connect to SSID expecting to be redirected to my ISE Guest Portal, nothing happens other than connecting to Internet WebPages.My question is, if I have followed this document correctly why is the Internal WLC not redirecting client requests to ISE, is this because my mobility anchors need to be re-configured, perhaps the AAA/ISE config needs to be applied to my DMZ WLC not internal WLC?
 
I would prefer the Internal WLC to redirect the login to ISE, doesn't make sense to traverse through the DMZ Firewall onto DMZ WLC back into the Internal Network again to the ISE to authenticate.Or am I missing something additionally to this document to make sure clients are directed to the ISE Guest portal login.

View 3 Replies View Related

Cisco Wireless :: Setting Up Redundant 5508 Controllers

Mar 10, 2013

I am setting up two 5508 controllers, one in HA mode, and one the primary for the remote sites in question. I plan to have these units service wireless for MPLS conected regional sites (each with their own local subnet). I was planning on using the cabled hosts network in each site for the wifi addressing and was thinking a different addressing for Guest Access, is this common? I'm obviously concerned with guest access clients but don't know enough how their trafiic is segregated from normal wifi traffic.
 
Also, when I stand up the controllers the management interface and ap-manager won't be in the same network as where the hosts or LWAP's will reside (routing access will exist though).

View 6 Replies View Related

Cisco Wireless :: 5508 - Replicating Between Controllers Automatically Without HA?

Jun 11, 2013

We have 2 Cisco 5508 WLCs, each wtih 50 licenses. What I would like to do is split the 50 odd APs between the 2 controllers load balancing the traffic. If a controller goes down or there is a break in the path all APs would failover to their configured secondary controller.  So far so good.
 
However there seems to be no way to 'replicate' the configurations between controllers unless I setup HA  , but as I understand it HA is Active /Passive, so essentially, unless you get a failover situaltion, completely 'redundant'.
 
Is there a way or either replicating between controllers automatically with out HA, or is there a way of making HA Active / Active?

View 3 Replies View Related

Cisco Wireless :: 5508 / Change Management IP On Controllers?

Sep 1, 2011

I have two 5508 and one WCS server, the controllers are in one mobility group.Now I have to change the management IP addresses on the controllers. What are the correct steps to do this?

View 9 Replies View Related

Cisco Wireless :: 5508 - Reduce Controllers Overall Footprint

Aug 12, 2012

I'm looking into upgrading our 4400 series controller to 5508's.  Currently we have a few sites that have 8-9 4404 100AP controllers and I'm looking to condense these down to either 3 5508-500 or 5 5508-250 depending on cost.  I'm wondering what a good port to AP ratio is for controllers with licenses that can handle over 100 AP's.  I know the general rule of thumb is 25 AP's per port, but that seems to me to be 4400 way of thinking.  I'm trying to also reduce the controllers overall footprint, i.e. ports on the uplink switch, power consumption, rack space etc. 

View 5 Replies View Related

Cisco Wireless :: WLC 5508 - Moving Controllers To Another Site

Aug 28, 2012

I am planning to move our WLC's (5508) from a branch site to HQ so that all branch site APs will just report centrally in the HQ. There are two WLCs working as Active/Standby. Plan is to move one then the other. I am not really inclined with wireless.

View 9 Replies View Related

Cisco :: Load Balance 2 5508 Wireless Controllers?

Aug 1, 2012

--- I have 2 WLC's 5500 that I have to set up on my network with the same configuration except I am not sure that they can be load balanced.

--  My only thought is to take a full class C and on each WLC set up a /25, thus each device can provision 120 IP's

--- This seems a bit archaeic, but is there anything else smarter to do? Can they be load balanced?

View 9 Replies View Related

Cisco Wireless :: 5508 Controllers - Single DNS Structure

Jun 21, 2012

We are installing a set of 5508 controllers at one site in Tennessee. At another divisional site we have another controller that covers that division.

Both sites utilize the same DNS structure and would like to use the DNS entry CISCO- CAPWAP- CONTROLLER entry for bringing new AP onto the controllers at their sites, how would we go about configuring this?

View 6 Replies View Related

Cisco :: Wireless 4400 - Customized Web Authentication

Aug 4, 2011

I posted a few days ago but don't have a good response.  I've dig high and low and haven't come across a solution yet.  I've been trying to get a customized web Authentication typed.  I didn't need a user name or password to get through.  All I need is a web pass through and an accept button at the end of the HTML agreement policy or splash page.
 
I was able to create a log in.HTML and download to the wireless controller, but my problem is how would I get an agree button and when a user click on it and it would redirect to a website. I've followed the following link but no luck. {URL}. the link doesn't tell me weather I should create an accept button manually or is there a setting on the controller that need to check?  the link also provide some info. about: Configure Client Machine for Web Pass through, but where should I download the Cisco Aironet Desktop Utility?  I've download ACUv502005.exe file for my windows 7 but after the installation it didn't work for me. if you know how to configure the web-pass through.  I been working for this for a week now and didn't find the info. that I was looking for.

View 1 Replies View Related

Cisco Wireless :: 5508 WLC / Lobby Admin Guest Account With Two Controllers?

Feb 14, 2013

I have two 5508 WLCs.  Both have APs attached to them.  If I create a guest account with the lobby administrator on one, will that user account be able to log in to the network if the client is attached to the ohter WLC?  So far, I have found that I need to create the same user on both WLC's, in order to have the user login.

View 2 Replies View Related

Cisco Wireless :: 5508 Controllers - After 7.0.116.0 Upgrade Intel Wi-Fi Link Cards Fail

Nov 10, 2011

Just recently upgrade our 2 5508 controllers from 6.0.199.0 to 7.0.116.0.  Since that upgrade, I have a handful (8 to 10) of wireless laptops that now refuse to associate to any access points.  The thing these laptops all have in common is some variation of the Intel Wifi Link AGN cards.  I have about 200 other clients out there working just fine.
 
I've tried everything under the sun that I can think of.  Patches, drivers, the whole sh'bang. 
 
Is there a known issue with 7.0.116.0 and these particular cards?

View 17 Replies View Related

Cisco :: 5508 - DHCP Load Sharing With Redundant Guest Anchor Controllers

Jan 28, 2012

I have 2 x Redundant Guest Anchor Controllers (5508) located in 2 separate Data Centers with all the management and guest user VLAN spanned between two. Everything is working fine with the Guest WiFi access except the DHCP functionality as the Controllers are acting themselves as the internal DHCP Servers.
 
This is how I tried to distribute : 
network. 10.1.0.0/23
gateway: 10.1.1.254 
Controller 1, DHCP Server pool: 10.1.0.2 - 10.1.0.254 Gw: 10.1.1.254
Controller 2, DHCP Server pool: 10.1.1.2 - 10.1.1.254 Gw: 10.1.1.254
 
As the user load balancing between the Anchor Controllers cannot be controlled (i.e. they are active/active), the same client sometime getting 2 different IP addresses from both the Controllers (as they do not talk to each other in terms of DHCP) hence depleting the pool addresses.
 
I guess one way of solving this is to just run 1 DHCP server in one of the controllers but that defeats the purpose of having N+1 Controllers. Is there a better way of doing the DHCP load balancing and having full redundancy at the same time?

View 3 Replies View Related

Cisco :: Migrating APs From WLC 4400 V.4.0.179.11 To WLC 5508 V.7.2.110.0

Jun 11, 2012

I am replacing an old 4400 series WLC running version 4.0.179.11 to a new 5508 WLC running version 7.2.110.0.
 
We currently have 70 x 1131 Access points on the 4400 WLC.
 
With this upgrade, do i need to upgrade the old 4400 to version 6.0 so the AP's get an up to date IOS or can i directly migrate all AP's over to the new 5508 without any version incompatabilities on the AP's?
 
I am abit worried that the AP's are running a very old IOS on the 4400 v.4.0.179.11 to go straight to the new 5508 v.7.2.110.0.

View 3 Replies View Related

Cisco Wireless :: 4400 / 5508 - Upgrade From 7.0.116.0 To 7.2.103.0?

Apr 2, 2012

I want to upgrade all my controllers (a mix of 4400 and 5508) to 7.2.103.0 from 7.0.116.0. Can I make that jump or should I do incremental?

View 7 Replies View Related

Cisco :: Enable Guest Network Authentication In Network With WLC 4404 Controllers And No WCS?

Feb 18, 2013

What's the least expensive way to enable Guest Network authentication in a network with WLC 4404 controllers and no WCS? Management would like guests to register with a valid email address and enter a 'password du jour' to keep unauthenticated users from chewing up bandwith with automatic connections. 

View 4 Replies View Related

Cisco :: 4400 / 5508 - Config Paging Enable / Disable

Oct 19, 2011

I have WLC 4400/5508 I stumbled across this config paging disable command to stop page breaks, works great for the one session I am logged in but it do not work for other users..

View 1 Replies View Related

Cisco Wireless :: Configure A Wired Guest Network With A Combination Of 5508 And 2504 Wireless Controllers?

Apr 7, 2013

Is there any way to configure a wired guest network with a combination of 5508 and 2504 wireless controllers? I am aware that the 2504 does not have wired guest functionality, however is it possible to set up a wired guest on the 5508 and using mobility anchors, transmit the l2 information through eoip to communicate with the remote vlan?Home built NAC solution, using 802.1x authentication on switchports for public areas. If user is an employee, communicates with the supplicant on their machine, and places them on an internal vlan.If user is a guest, user fails 802.1x check and is placed on a "guest" vlan with an ACL and external DNS.If placed on the guest vlan, the user has to accept a terms of use form.This is working currently with our 5508s without any issue, however we have some remote offices we'd like to roll this out to that are using 2504 controllers. I'm hoping there's a way that I can use the 5508 as an anchor or vice versa to make this work.

View 1 Replies View Related

Cisco Wireless :: 5508 Foreign Controller And 4400 Anchor Controller?

Jun 2, 2013

We have a customer that have 2 5508 as primary and backup controller and a 4400 as an anchor controller.  We plan to upgrade the 5508 to 7.3.112.0 and the 4400 is already 7.0.116.0.  Will there be any issue if the anchor controller is not the same code as the foreign controller?  Do I also have to upgrade the acnhor controller to 7.0.240.0?

View 2 Replies View Related

Cisco :: Prevent Guest From Doing Peer-peer Communication On Guest 5508 Controllers

Jan 24, 2013

I want to prevent guest from doing peer - peer communication on my Guest (5508) controllers.  Is this a feature on the WLC or only by applying an ACL on the router interface?

View 2 Replies View Related

Cisco Security :: OOB NAC And 5508 WLC Don't Get Any Authentication

Nov 22, 2010

I have a 5508 wlc trunked to a 6500 switch. Also trunked to the switch on both eth0 and eth1 is the CAS. The CAM is connected with an access port.

The CAS and CAM are on seperate VLANs and the CAS was added to the CAM without issue. I followed the example document for OOB WLAN (VLANs and mapping etc)  but I don't get any authentication going on. The client associates and the WLAN interface is the quarantine VLAN However it seems the client can connect to the network without issue (can web browse to a server internaly to the campus)
 
The client is shown in the wireless clients on the device page of the CAM, If i close down either of the CAS interfaces the client connectivity is broken.
 
Just once, randomly the Clean Access Login Page appeared on the client (battery had died and waited about an hour) but when I rebooted the CAS to check it was consistent it never came back.

View 6 Replies View Related

Cisco :: 5508 Web Authentication Timeout?

Aug 1, 2011

If any authenticated user uses protocol other than (http, https) within timeout period, that user #is deuthenticated

View 1 Replies View Related

Cisco :: 5508 - 802.1x Authentication On PSK Key Management?

Aug 20, 2009

I'm setting up a new 5508 WLC (the first wlc I have ever setup) and I have my WLAN setup with our existing WPA/TKIP ssid for transitioning our clients from our existing autonomous system to the wlc.  I have selected PSK as the key mgmt and I can get the client's to connect for a few minutes but I keep seeing these errors:
 
Fri Aug 21 08:50:05 2009 Client Excluded: MACAddress:00:21:00:f9:dd:50 Base Radio MAC :00:23:eb:27:e3:b0 Slot: 1 User Name: unknown Ip Address: unknown Reason:802.1x Authentication failed 3 times. ReasonCode: 4
 
I don't have nor do I want 802.1x enabled.  Is there something I need to disable either on the client or the controller?

View 20 Replies View Related

Cisco :: Web Authentication Over HTTP Instead Of HTTPS On Wlc 5508?

Mar 26, 2011

I have follow below URL to disable the https over web authentication:
 
[URL]
 
What i want to achieve is disable https over web authentication due to certificate issue, but it seems like even we have disable the http over web management as above URL describe, still https while doing web authentication. Or it is possible to configure use port other than 80, like 8080 for web authentication? (need to reboot the wlc?)Is there any bug that related to this CSCsy32145?
 
WLC Software Version                 6.0.196.0

View 8 Replies View Related

Cisco :: 5508 WLC - Concept Of Association And Authentication

Sep 15, 2010

We have a 5508 WLC with a few WAP's (1131's and 1242's).  Our wireless clients use certificate base authentication against our AD (i.e. both computer cert and user cert are required).  However, from time to time I see clients being associated but not authenticated as reported by the WLC.  Could it be possible, as some literatures indicate that a client can only be "associated" after it's successfully authenticated?  Perhaps I'm not quite clear about the concept.

View 7 Replies View Related

Cisco :: 5508 / Radius Authentication Not Working?

Apr 8, 2013

I have a 5508 controller running 7.4.100 and have a WLAN where I have radius configured. On my controller the client machine I'm using appears but the radius authentication doesn't appear to be working. Is there anything on the controller I can do to verify that the request is even being sent to my Microsoft IAS server? The log on the server doesn't show any requests from the controller so my early days guess is the controller isn't actually sending it.

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved