Cisco :: 5508 Controllers Not Redirecting Client Requests To ISE

Jun 5, 2013

Please find attached a simple BYOD/ISE document I uploaded to kick start my new Wireless setup. Its all configured on my ISE sever and Controller as per doc.My setup:
 
-3600 AP's
-Internal 5508 Controller
-DMZ 5508 Controller (acts as a DHCP server for wireless clients)
 
Controllers have established connectivity (mobility acnhors), as a client I can connect fine to my new SSID get a DHCP IP address back from DMZ WLC and at the moment can connect out to the Internet fine (using no WLAN Security as a test). So this part is working.I have now followed the document configured ISE, enabled AAA on the Internal WLC only and used the AAA override setting on WLAN as in the attached document.I connect to SSID expecting to be redirected to my ISE Guest Portal, nothing happens other than connecting to Internet WebPages.My question is, if I have followed this document correctly why is the Internal WLC not redirecting client requests to ISE, is this because my mobility anchors need to be re-configured, perhaps the AAA/ISE config needs to be applied to my DMZ WLC not internal WLC?
 
I would prefer the Internal WLC to redirect the login to ISE, doesn't make sense to traverse through the DMZ Firewall onto DMZ WLC back into the Internal Network again to the ISE to authenticate.Or am I missing something additionally to this document to make sure clients are directed to the ISE Guest portal login.

View 3 Replies


ADVERTISEMENT

Cisco Application :: 389 Vip Not Responding To Client Requests On ACE

Jan 4, 2012

client is unable to establish a connection to the backend servers via the vip on port 389 ,636 configured that servers are listening on these ports .even the probe is successful on port 389 but not getting any response back from the servers. [code]

View 1 Replies View Related

Cisco :: How Many Client Requests AP1252G-E-K9 Can Handle

Jul 17, 2012

how many clients simultaneously associate with Cisco AP 1252G.. right now when I try to connect more thn 25 rest unable to access the AP. Clients (smart phones plus laptops) are using  802.11b/g standard.

View 11 Replies View Related

Cisco VPN :: Bogus RADIUS Requests From ASA 5510 / VPN Client

Oct 30, 2011

I'm using Cisco VPN client 5.0.7 and Cisco ASA 5510 (7.4 and 8.4.2) VPN RAS solution. Clients are authenticated using certificates and AAA RADIUS (ACS 3.3) and AD.Each time, when client connects, ASA issues 2 RADIUS requests, first - correct one which is successfully authenticated by ACS and immediately - second which always fails. I couldn't find any information related to this strange behaivor. "Double authentication" feature (most likeable to its name) is accessible only to Anyconnect clients which we don't use. When I'm authenicated using group password, there is only one RADIUS request.What is the source of  such behavior?The negative impact is that my logs are filled with spurious failed auth attempts, and users are incrementig failed attemps counter in AD.
 
Debug from ASA:
----First request----
RDS 10/24/2011 16:16:01 D 0232 14884 Request from host 172.16.8.1:1645 code=1, id=22, length=145 on port 1025
RDS 10/24/2011 16:16:01 I 2519 14884     [001] User-Name                           value:  user1
RDS 10/24/2011 16:16:01 I 2519 14884     [002] User-Password                       value:  B2 A9 D0 2D 15 5F B8 BB DB 1E 3A 38 F5 24 72 B5
RDS 10/24/2011 16:16:01 I 2538 14884     [005] NAS-Port                            value:  -1072693248
RDS 10/24/2011 16:16:01 I 2538 14884     [006] Service-Type                        value:  2

[code]....

View 2 Replies View Related

Cisco Wireless :: WLC 5508 No Further RADIUS Authentication Requests?

Mar 18, 2013

I'm working on a project where a wi-fi client is tracked and located using RADIUS authentication requests. The problem I'm running into is that the WLC (5508) sends an RADIUS authentication request to my freeradiusd, which is ok so far, but if the client roams to another accesspoint (3602AG, 1131AG, 1252AG), the WLC does not send a further RADIUS auth. request - and the client is allowed to connect to the next ap.Is there an option like RADIUS-cache which I can disable, so that the WLC sends everytime an authentication request when a client tries to connect to an ap or roams from one ap to another one?

View 4 Replies View Related

Cisco :: 5508 Wireless Controllers Freezing?

Dec 6, 2011

Our controller get freezing every week at least twice, and do not know what is the reason. I am attaching the log for you to look at it. Last time happened was yesterday at around 13.00 pm.

View 15 Replies View Related

Cisco :: 4400 / 5508 Controllers - 802.1x Re-Authentication

Mar 28, 2012

Currently in the process of migrating from psk to 802.1x radius environment using a mix of 4400 and 5508 controllers with WCS using Microsoft ias.  The problem I have is there is a lot of shared iPads and tablets in the environment.  Is there a way to force these user to relogin to radius after a certain time period so they are not  sharing unames and passwords?

View 1 Replies View Related

Cisco Wireless :: 5508 - DHCP Requests Starts Failing

Feb 15, 2013

I have a school with 550 iPads.  We are using two 5508 WLCs sharing the number of APs.  The DHCP server and the default gateway for the network are on the firewall.  The clients are able to get a DCHP.  After some time, maybe about longer than a month, the clients are no longer able to get DCHP addresses.  A reboot of both controllers takes care of this.  Presently we are runing 7.2.110 OS.  I am going to upgrade to the latest 7.4.100, and reload tonight.

View 1 Replies View Related

Cisco Wireless :: Setting Up Redundant 5508 Controllers

Mar 10, 2013

I am setting up two 5508 controllers, one in HA mode, and one the primary for the remote sites in question. I plan to have these units service wireless for MPLS conected regional sites (each with their own local subnet). I was planning on using the cabled hosts network in each site for the wifi addressing and was thinking a different addressing for Guest Access, is this common? I'm obviously concerned with guest access clients but don't know enough how their trafiic is segregated from normal wifi traffic.
 
Also, when I stand up the controllers the management interface and ap-manager won't be in the same network as where the hosts or LWAP's will reside (routing access will exist though).

View 6 Replies View Related

Cisco Wireless :: 5508 - Replicating Between Controllers Automatically Without HA?

Jun 11, 2013

We have 2 Cisco 5508 WLCs, each wtih 50 licenses. What I would like to do is split the 50 odd APs between the 2 controllers load balancing the traffic. If a controller goes down or there is a break in the path all APs would failover to their configured secondary controller.  So far so good.
 
However there seems to be no way to 'replicate' the configurations between controllers unless I setup HA  , but as I understand it HA is Active /Passive, so essentially, unless you get a failover situaltion, completely 'redundant'.
 
Is there a way or either replicating between controllers automatically with out HA, or is there a way of making HA Active / Active?

View 3 Replies View Related

Cisco Wireless :: 5508 / Change Management IP On Controllers?

Sep 1, 2011

I have two 5508 and one WCS server, the controllers are in one mobility group.Now I have to change the management IP addresses on the controllers. What are the correct steps to do this?

View 9 Replies View Related

Cisco Wireless :: 5508 - Reduce Controllers Overall Footprint

Aug 12, 2012

I'm looking into upgrading our 4400 series controller to 5508's.  Currently we have a few sites that have 8-9 4404 100AP controllers and I'm looking to condense these down to either 3 5508-500 or 5 5508-250 depending on cost.  I'm wondering what a good port to AP ratio is for controllers with licenses that can handle over 100 AP's.  I know the general rule of thumb is 25 AP's per port, but that seems to me to be 4400 way of thinking.  I'm trying to also reduce the controllers overall footprint, i.e. ports on the uplink switch, power consumption, rack space etc. 

View 5 Replies View Related

Cisco Wireless :: WLC 5508 - Moving Controllers To Another Site

Aug 28, 2012

I am planning to move our WLC's (5508) from a branch site to HQ so that all branch site APs will just report centrally in the HQ. There are two WLCs working as Active/Standby. Plan is to move one then the other. I am not really inclined with wireless.

View 9 Replies View Related

Cisco :: Load Balance 2 5508 Wireless Controllers?

Aug 1, 2012

--- I have 2 WLC's 5500 that I have to set up on my network with the same configuration except I am not sure that they can be load balanced.

--  My only thought is to take a full class C and on each WLC set up a /25, thus each device can provision 120 IP's

--- This seems a bit archaeic, but is there anything else smarter to do? Can they be load balanced?

View 9 Replies View Related

Cisco Wireless :: 5508 Controllers - Single DNS Structure

Jun 21, 2012

We are installing a set of 5508 controllers at one site in Tennessee. At another divisional site we have another controller that covers that division.

Both sites utilize the same DNS structure and would like to use the DNS entry CISCO- CAPWAP- CONTROLLER entry for bringing new AP onto the controllers at their sites, how would we go about configuring this?

View 6 Replies View Related

Cisco Wireless :: 5508 WLC / Lobby Admin Guest Account With Two Controllers?

Feb 14, 2013

I have two 5508 WLCs.  Both have APs attached to them.  If I create a guest account with the lobby administrator on one, will that user account be able to log in to the network if the client is attached to the ohter WLC?  So far, I have found that I need to create the same user on both WLC's, in order to have the user login.

View 2 Replies View Related

Cisco Wireless :: 5508 Controllers - After 7.0.116.0 Upgrade Intel Wi-Fi Link Cards Fail

Nov 10, 2011

Just recently upgrade our 2 5508 controllers from 6.0.199.0 to 7.0.116.0.  Since that upgrade, I have a handful (8 to 10) of wireless laptops that now refuse to associate to any access points.  The thing these laptops all have in common is some variation of the Intel Wifi Link AGN cards.  I have about 200 other clients out there working just fine.
 
I've tried everything under the sun that I can think of.  Patches, drivers, the whole sh'bang. 
 
Is there a known issue with 7.0.116.0 and these particular cards?

View 17 Replies View Related

Cisco :: 5508 - DHCP Load Sharing With Redundant Guest Anchor Controllers

Jan 28, 2012

I have 2 x Redundant Guest Anchor Controllers (5508) located in 2 separate Data Centers with all the management and guest user VLAN spanned between two. Everything is working fine with the Guest WiFi access except the DHCP functionality as the Controllers are acting themselves as the internal DHCP Servers.
 
This is how I tried to distribute : 
network. 10.1.0.0/23
gateway: 10.1.1.254 
Controller 1, DHCP Server pool: 10.1.0.2 - 10.1.0.254 Gw: 10.1.1.254
Controller 2, DHCP Server pool: 10.1.1.2 - 10.1.1.254 Gw: 10.1.1.254
 
As the user load balancing between the Anchor Controllers cannot be controlled (i.e. they are active/active), the same client sometime getting 2 different IP addresses from both the Controllers (as they do not talk to each other in terms of DHCP) hence depleting the pool addresses.
 
I guess one way of solving this is to just run 1 DHCP server in one of the controllers but that defeats the purpose of having N+1 Controllers. Is there a better way of doing the DHCP load balancing and having full redundancy at the same time?

View 3 Replies View Related

Cisco Wireless :: Configure A Wired Guest Network With A Combination Of 5508 And 2504 Wireless Controllers?

Apr 7, 2013

Is there any way to configure a wired guest network with a combination of 5508 and 2504 wireless controllers? I am aware that the 2504 does not have wired guest functionality, however is it possible to set up a wired guest on the 5508 and using mobility anchors, transmit the l2 information through eoip to communicate with the remote vlan?Home built NAC solution, using 802.1x authentication on switchports for public areas. If user is an employee, communicates with the supplicant on their machine, and places them on an internal vlan.If user is a guest, user fails 802.1x check and is placed on a "guest" vlan with an ACL and external DNS.If placed on the guest vlan, the user has to accept a terms of use form.This is working currently with our 5508s without any issue, however we have some remote offices we'd like to roll this out to that are using 2504 controllers. I'm hoping there's a way that I can use the 5508 as an anchor or vice versa to make this work.

View 1 Replies View Related

Cisco :: Prevent Guest From Doing Peer-peer Communication On Guest 5508 Controllers

Jan 24, 2013

I want to prevent guest from doing peer - peer communication on my Guest (5508) controllers.  Is this a feature on the WLC or only by applying an ACL on the router interface?

View 2 Replies View Related

Cisco Wireless :: 5508 - Client Not Receiving The IP?

Apr 12, 2011

I have two number of WLC model 5508 running IOS version 7.0.98.0. And One WLC in DMZ with the same model and IOS version. AP model is 1141. The Two WLCs are integrated with ACS. I have a SSID named EMployee. The DHCP for the users are configured in a seperate DHCP server and i have mapped this DHCP server IP to the interaface Employee.And this interface is mapped to the SSID as well..  But my client is not receiving the DHCP IP. Attached are the debug logs from the client.

View 9 Replies View Related

Cisco :: WLC 5508 How To Enhance Client Security Authentication

Dec 20, 2012

Security during client authentication is enhanced by applying both 802.1X and Web Authentication for a WLAN." 

View 7 Replies View Related

Cisco Wireless :: 5508 Duplicate Client IP Address

Dec 1, 2012

I am using 2 anchor controllers 5508 as DHCP server. Anchor controller A is primary and anchor controller B is secondary. From time to time, client will complain "duplicate IP address error" when they try to connect guest wireless.First question: both anchor controller should have a recorder of IP address which is assigned to each PC, right?Second question: is there any way this type of issue can be avoided?

View 3 Replies View Related

Cisco Wireless :: Client Roaming With 5508 Controller

May 27, 2013

I am having some troubles with client roaming on a 5508 controller running firmware 7.3.101.0. As soon as a client roams outside the range of an AP they lose data flow and do not seem to transition to another AP for about 1 minute.This is a small network with 6 x AIRCAP3502E-N-K9 AP's (running in H-REAP mode) on the same floor and clients are a mix of HP notebooks, Mac Books, iMacs, iPads and iPhones. There are several seperate SSID's setup and the problem occurs on all. All are WPA2/AES with either a PSK or 802.1X. Both 2.4GHz and 5GHz radios are enabled with auto power and channel selection.
 
I have tried changing the roaming settings from default and also playing with the AP power settings to no avail.Is this normal behaviour or is there something I can do to improve the reconnection speed?

View 11 Replies View Related

Cisco Wireless :: Client Connection On 5508 / 1140 AP

Apr 23, 2013

I have one 5508 with Product version 6.0.199.4 and about 7 Cisco 1140 APs.We have a next problems. Go out of the connection on the clients PC, while physically a wireless connection to the workstations is not broken, but access to network resources is lost and restored after some time (up to about one minute).The logs on the controller at the same time see the following message.

View 3 Replies View Related

Cisco :: WLC 5508 - Client Association Failure Null

Feb 21, 2013

I am running WLC 5508 and WCS version 7.0.98.  We are noticing with some of our handheld devices that have Sychip Wireless cards that they constantly have issues communicating.  The error I see on the WCS side is shown below:     
 
Client '00:0b:6c:2f:d0:32 (0.0.0.0)' failed to associate with interface  '802.11b/g' of AP 'HO-BRSales'. The reason code is '0(null)'.

View 11 Replies View Related

Cisco :: 5508 - Client Isolation And The Bonjour Gateway On WLC 7.4.1?

Mar 4, 2013

I am considering upgrading our 5508 WLCs to version 7.4.1 to take advantage of the Bonjour gateway. What I want to do is allow clients on our guest wireless network to access things like the Apple TV in our conference rooms. My intention would be to have the Apple TVs on a separate vlan. Obviously, the Bonjour gateway would allow for access between these 2 networks. The question I have is this. If I have client isolation turned on my guest wireless network, is it still possible for these devices to access Apple TVs on another network?

View 2 Replies View Related

Cisco :: WLC 5508 Disable WLan Client Still Connected

Jul 2, 2011

I have one wlc 5508 running on latest IOS 7.116, there is one wlan abc which i have disable status and disable broadcast, but randomly still i can see from wlc dashboard there is one client connected to this wlan abc. The moment i check on the client details, there is no client connected to that wlan and when return to dashboard, no more client connected to that wlan abc.

View 3 Replies View Related

Cisco Wireless :: 5508 Client Gateway Setup

Dec 1, 2012

I've just installed a standard Cisco wireless install (5508, 3502i, local and flexconnect setups) all working swimmingly.
 
The customer has asked for a new WLAN for a particular group of staff that will route to a different gateway than the general wireless staff.
 
The 5508 is connected to a older Avaya L3 switch that is the customers core swtich, but it isn't capable of PBR so it routes on desitnation only and its default route is not where I need the new WLAN traffic to route to. An ASA will be connected to the Avaya switch (which is the alternate gateway I need to get the new WLAN users to). So my question is probably routing 101, but if the ASA interface, the Avaya swtich and the WLAN interface all reside in the same VLAN, can I give the wireless clients the ASA as their gateway via DHCP and successfully get their traffic to the ASA?

View 3 Replies View Related

Cisco WAN :: Outbound Port Forwarding And Redirecting 800 Series

Sep 18, 2011

I've tried a few different ways unsuccessfully so thought I'd ask here.I'm trying to forward an outgoing port on a Cisco 800 series router. ie. When a user inside the network connects to the router on port 1234, it opens up the same port on a server on the Internet.

View 2 Replies View Related

Cisco Firewall :: Redirecting Traffic To Proxy From ASA 5505

May 20, 2011

I have ASA 5505 with base license. I like to install proxy server in my network.I configured below commands to forward my traffic to proxy server from my ASA.

If there is any configuration that i need to configure.And if possible send me the configuration guide to setup SQUID server. ( Actually it was set up by the 3rd party vendor)

View 1 Replies View Related

Cisco Wireless :: 5508 WLC - Associate Client From AP If Idle For Certain Time

Sep 16, 2012

Is it possible to rename the default webauthentication URL from [URL] to something like [URL]. We are running on 7.0.98.0, is it possible to do http for web authentication and https for Mgmt access if we upgrade the controller software?
 
We configured our guest wireless with no layer 2 authetication so users can associate with an AP and get an ip adress but they can't go anywhere unless they have a valid username and password(web authentication) - does this affect the performance of an AP since there will be many people associated with each AP, is there any setting in the WLC to de associate a client from an AP  if its idle for certain time.

View 9 Replies View Related

Cisco Wireless :: 5508 Max EAPOL-key M5 Retransmissions Exceeded For Client

Feb 21, 2012

I have had several complaints from around the firm where by mobile devices are being bumped off the PSK secured network (All other SSID networks are operating A-OK). Both Android and iPhone devices are being affected, the device will just loop until it reconnects, sometimes up to 20 minutes of trying to establish a connection. It will eventually connect so the key is not the issue.I've attached a debug of a device which fails to connect and then shortly after is successful.
 
Controller 5508 v7.0.116.0
AP 3502i IOS 12.4(23c)JA2

View 4 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved