Cisco :: 5508 - Mobility Group To Match On Internal WLC?

Feb 1, 2012

I am setting up officeexten. I have placed the officeextend wlc in the dmz with an mgmt ip of 192.168.10.2. in the process of anchoring this to the internal wlc. Also the ip on the firewall for this interface is 192.168.10.1
 
1. does the mobility group need to match the same on the internal wlc ?

2. Now do i need a NAT transnational on the firewall for the external WAN ip (AP primed address say 66.10.10.10) to NAT back to 192.168.10.2 ?

3. The 5508 WLC is running on ver6.0.199.4 (license level base) - will this support office extend?

View 14 Replies


ADVERTISEMENT

Cisco Wireless :: 5508 - Unable To Add New WLC To Mobility Group

Nov 30, 2011

I recently add a second CT5508 to the network, but when I tried to add the first 5508 to the mobilty group I received a message like this:
 
"error in creating member"
 
I've tried different mobility names, via GUI, via CLI and always the same error.
 
I've verified twice or more than twice connectivity issues or any error on the entering the MAC and IP of the controllers, everything is fine.
 
I'm using version 7.0.116.0

View 4 Replies View Related

Cisco Wireless :: 5508 Mobility Group And Re-authentication

Aug 15, 2012

I have to WLC's a 4402 and 5508   in a mobilty group. they are both running 7.0.116.0. They are configured to use Web Authentication. We are having complaints that Users are having to re-authenticate when moving around the office. My theory is they are moving from one WLC to the other and then requiring to re-authenticate.

View 5 Replies View Related

Cisco Wireless :: Migrating 2 Standalone 5508 To One Mobility-group

Jan 23, 2012

for some reason our wlan-controllers were build up to be standalone instead of beeing one mobility-group. I would like to change this in order to use all features of HA.
 
let me describe our scenario: two WLCs 5508 running SW ver. 6

- same subnet

- both are running in master controller mode

- different hostnames, ip-addresses, etc

- all settings for WLANs and AP-groups (exept the APs themselves in these groups) are the same

- in total at this moment we are running around 100 LAPs configured one half on WLC#1, the other half on WLC#2
 
I don't know exactly why, but when that setting was installed, someone already configuredHA for each accesspoint... e.g.:

- AP#1 primary WLC#1, secondary WLC#2

- AP#2 primary WLC#2, secondary WLC#1 but without WLC#2 knowing the configuration for AP#1 it makes no sense, correct?
 
so my question is: how should I do the migration in the best way?
is it easy as:

- disabling master controller mode on WLC#2

- configuring both WLCs into one mobility group

--> WLCs are negotiating their configurations for the APs

View 5 Replies View Related

Cisco Wireless :: 5508 - Mobility Group Same Ssid Multiple WLC

Apr 7, 2013

I have a 4400 and a 5508 WLC in the same location We want to be able to roam between ap joined to both the 4400 and the 5508 using only one ssid
 
Do I only need to create a mobility group and add both WLC then create only one WLAN on one of the controllers and it will be shared across bot WLC.

View 5 Replies View Related

Cisco :: WLC 5508 Mobility Groups And Internal DHCP

May 6, 2012

How do Mobility Groups work with internal DHCP scopes on a WLC 5508?We have a WLC 5508 with two internal DHCP scopes which redirect to captive portals for authentication. I am looking at putting in a second WLC in a mobility group setup to provide some WLC redundancy. The LWAPs will be setup so that every second AP is on the has the second WLC as its primary controller. If the primary WLC fails we want the secondary to be able to take over and issue IP's from the internal scope. How do you set this up with a Mobility group so the second WLC does not act as a rouge DHCP server while the primary WLC is still active?

View 6 Replies View Related

Cisco :: WLC5500 Mobility Group Fail-over

Mar 22, 2012

I have a Question i am testing  mobility group with Failover for redundend connection between 2 Cisco 5500 Wlc.On both the controllers i got the mobility working And both the controllers have the same version.And configuration. But when i unplug the main controller the access-Points don't convers to the second one .The just keep on creaming can't find the main controllerAlso with this thus the second wlc need to have the same.Interface ip address like management.

View 8 Replies View Related

Cisco :: How Many 5508wlc Be Added To Mobility Group

Jun 23, 2011

How many WLCs 5508 can you add to the mobility group?

View 1 Replies View Related

Cisco Wireless :: WLC 7.3.101.0 Mobility Group Peer Cannot Up

May 19, 2013

It seems the 7.3.101 version Mobility group peer cannot up,: refer to the attach,
 
Peer 1: version: 7.3.101
Peer 2: version 7.0.98
Peer3: version 7.2.103 
 
Today we got new two WLC for Anchor use, and config the mobility group, but it's failed and cannot up, the ping is ok.

View 13 Replies View Related

Cisco VPN :: To Match Tunnel Group With ASA 8.2 And VPN Client IPSec Authorization

Apr 15, 2010

I have configured a lab for RA VPNs with a ASA5510 software version 8.2 and VPN Client 5 using digital certificates with Microsoft CA on a Windows 2003 server. I did the configuration based on this document from Cisco website: URL
 
Now the vpn works just fine, but now I need to configure different tunnel-groups so I can provide different services to different users. The problem I have now is that I don't know how to configure it so the certificate matches the tunnel-group name. If i do a debug crypto isakmp on ASA I get this error messages:
 
%ASA-7-713906: IP = 165.98.139.12, Trying to find group via OU...%ASA-3-713020: IP = 165.98.139.12, No Group found by matching OU(s) from ID payload:   Unknown%ASA-7-713906: IP = 165.98.139.12, Trying to find group via IKE ID...%ASA-3-713020: IP = 165.98.139.12, No Group found by matching OU(s) from ID payload:   Unknown%ASA-7-713906: IP = 165.98.139.12, Trying to find group via IP ADDR...%ASA-7-713906: IP = 165.98.139.12, Trying to find group via default group...%ASA-7-713906: IP = 165.98.139.12, Connection landed on tunnel_group DefaultRAGroup

So basically when using certificates I always connect the RA VPN only with the default group DefaultRAGroup. Do I need to use a different web enrollment template for certificate request instead of the user template??? How can I define the OU on the User certificate so it matches the tunnel-group???

View 3 Replies View Related

Cisco Wireless :: Mobility Group Between Controller 4400 And Virtual WLC

Mar 7, 2013

I read the configuration guide about the 7.3 release. And I figured out that you will need a hash key for establishing a mobility group relation between a controller and a virtual controller. The 7.3 release for the 5500 series works fine for me.But the latest release 7.0.235.0 for the wireless lan controller series 4400 does not have a functionality to add a hash key while creating a new mobility group member.The command "config mobility group member hash" is totally missing. How to establish a mobility group between a 4400 controller and a virtual then ?

View 2 Replies View Related

Cisco Wireless :: Max Number Of Mobility Member In Group With WISM 7.0

Dec 5, 2011

I have a customer buys 12 x WISM and build up a mobility, when I add the final WLC to mobility, it prompts that there mobility group has reached the max of mobility member, but the total member is 23, according the configuration guide, it should be allow to 24 member, do I hit some bug? My using version is 7.0.98.0.

View 5 Replies View Related

Cisco Wireless :: Mobility Group Between Controller 4400 And Virtual Wlc

Sep 3, 2012

I read the configuration guide about the 7.3 release. And I figured out that you will need a hash key for establishing a mobility group relation between a controller and a virtual controller. The 7.3 release for the 5500 series works fine for me.
 
But the latest release 7.0.235.0 for the wireless lan controller series 4400 does not have a functionality to add a hash key while creating a new mobility group member.
The command "config mobility group member hash" is totally missing.
 
how to establish a mobility group between a 4400 controller and a virtual then?

View 4 Replies View Related

Cisco Wireless :: 5508 Mobility Groups

Sep 1, 2012

1) Is it possible for 2 WLCs installed in seperate data centres with L3 seperation to be joined in a mobility group? We will have aps in the branch offices split between controllers so we want to make sure roaming work ok. Also all guest access should be anchored to data centre 2.
 
2) in flexconnect local switching mode, do I need to create flexconnect groups if I'm only using radius servers in the data centre with no requirement to use local radius as a backup?

View 6 Replies View Related

Cisco Wireless :: 5508 - Mobility / Roaming And Web Authentication?

Nov 27, 2011

I have two 5508, no anchor, only one SSID with internal web authentication using radius server.Under "Configuring Mobility Groups", Cisco guide says: "If a client roams in web authentication state, the client is considered as a new client on another controller instead of considering it as a mobile client".
 
I understand that if a client that has already autheticated via web roams between two LAPs that are associated with different WLCs, it has to reathenticate.

View 6 Replies View Related

Cisco Wireless :: 5508 - Mobility Ping And SSH Errors After Upgrade To 7.2.110.0

Aug 7, 2012

After upgrading my 5508s to 7.2.110.0, they are reporting mobility data path errors to one of my WiSMs running 7.0.235.0.
 
I get these messages on the 5508s reporting that it can't send a ping to the affected WiSM:
 
*ethoipSocketTask: Aug 08 21:15:41.175: %ETHOIP-3-PKT_RECV_ERROR: ethoip.c:341 ethoipSocketTask: ethoipRecvPkt returned error
*ethoipSocketTask: Aug 08 21:15:41.175: %ETHOIP-3-PING_RESPONSE_TX_FAILED: ethoip_ping.c:312 Failed to tx a ping response to <ip address>, rc=5
 
But maybe there is another clue because I also see in the same log these errors referencing the same WiSM:
 
*bcastReceiveTask: Aug 08 21:15:45.310: %LOG-1-Q_IND: mm_dir.c:1969 Failed to recreate the SSH Rule for <ip address>.
*mmSSHPeerRegister: Aug 08 21:15:44.829: %MM-1-SSHRULE_CREATE_FAILED: mm_dir.c:1969 Failed to recreate the SSH Rule for <ip address>.
 
Why is the controller trying to SSH to another controller?  Was some SSH related feature added to 7.2 that has been accidentally enabled? 

View 4 Replies View Related

Cisco Wireless :: 5508 Mobility Service Engineer / WCS Required Or Not?

Feb 4, 2013

I have Cisco Wireless Lan Controller 5508 with 35 (3600 Series Access Points.  Do i need to purchase Mobility Service Engine for this or no need?  Do i need WCS server for this or no need?

View 1 Replies View Related

Cisco :: 5508 - Failover For Multiple WLCs And Mobility Groups

Feb 14, 2013

We are in a warehouse type setting and have data centers on each side of warehouse with 5508 WLC's in each data center. Each side is on its own subnet with routing in between and a different set of SSID's for each set of WLC’s. Are goal is to have the ability to failover in the event that if one data center goes down AP’s will move to the controllers in the other DC and the clients will still be able to operate.
 
Our thought was to implement mobility groups between the controllers. While I saw documentation on setting this up when the controllers are on the same vlan, I didnt see any setup config when controllers are in different vlans. So I am wondering if mobility groups are even an option for what we want to accomplish. For the most part clients stay on their respected sides of the warehouse and so we are not necessarily needing roaming for clients between controllers in DC1 and DC2. But that does raise another question in that we do have a planned voice wlan that we would like to have the ability to roam between each side of the warehouse. But we have seen ip issues with this. In the past we have had both SSID's setup on each side and ran to issues with clients not renewing their IP address when moving to the controllers on the different subnets.
 
Can we setup mobility groups between controllers on different vlans/subnets? For failover purposes will mobility groups assist in our setup with 2 DC’s and different subnets/vlans? If the answer is yes we can setup mobility groups between different subnets, is there a way to setup the SSID's on all controllers and have the ability for clients to roam and renew their IP’s when moving to a different controller on a different subnet?

View 3 Replies View Related

Cisco Wireless :: 5508 - Mobility Groups / Sync Controller Configuration

Jul 7, 2011

I have 2 5508 controllers in a mobility group. Any good way to keep the configuration between the 2 controllers synched up?
 
I thought about copying the config from my primary controller to the secondary controller, but I would think there is a more elegant way to make this happen.

View 5 Replies View Related

Cisco :: 5508 Separate RF Group For Every Location

Mar 5, 2012

I'm looking for some input on RRM.  I personally have NOT used it in a LONG TIME, since probably the 4.0 days and then very shortly due to massive issues it was causing and admittedly, in part due to my ignorance at the time.  So, every since that point, I have always set all my channels and power manually but now feel I am getting to some points where RRM may be required / beneficial.  So, I've invested some time and have begun researching and trying to get the ends and outs on it but I'm forseeing a potential issue in myworld anyways and am hoping for some clarification.  Lets take the below example:

-WLC5508a and b - (2 100ap license controllers) - these hold the majority of the AP's for the main hospital.Lets say, 140AP's.

-WLC5508c and d - (1 100ap and 1 50ap licensed controllers) -  These tend to hold our smaller sites and and buildings, not all connected and some a few miles from each other

-WLC4402a and b - (failover ready)

So, with RRM, I can set setting it up on the 5508A/B with out issue as this is one big large building. However,what about C and D?  I suppose I can make them a separate RF Group, but how would RRM respond when it has16 AP's in Building X and then 3 AP's in Building Y 30 AP's in Building Z and sporadic buildings with 1's and 2's?  Everything I've read so far, leads me to believe if these devices are separated it probably won't be an issue, however, I just don't want something causing a change in Building Z and Building X be affected because RRM decided it would try to fix it. My point is, I can't afford to have a separate RF Group (meaning separate controllers) for every location.

View 1 Replies View Related

Cisco Wireless :: 5508 Can't Add 3600 Series AP To Group

Jul 22, 2012

I have an AP group on a Cisco 5508 WLAN controller.  Currently, it is populated with 13 Cisco 1142 lightweight access points.  When I try to add a Cisco 3602i access point to the group, I get the following error in NCS: Error: OfficeExtend requires primary, secondary, or tertiary controller management IP to be set.I am using DNS to allow my AP's to find the controller and they work just fine.  Is there a reason I can't add the 3600 series AP's to the AP group?

View 13 Replies View Related

Cisco :: WLC 5508 AP Group - Clients Using Wrong VLAN

Feb 14, 2011

I have a network setup as live-ssid.  It is using the Interface for VLAN 14.  All APs under the default-group AP Group obviously allows clients to DHCP an address from VLAN 14.  This is working fine.
 
I created a new AP Group called 3rd Floor.  This has the live-ssid setup, but instead of using the Interface for VLAN 14 it is setup for the Interface for VLAN 50.  I have all the APs on this floor moved to the 3rd Floor AP Group.
 
The problem is that 95% of the clients on 3rd Floor are still picking up DHCP addresses from VLAN 14.  I checked and all the clients are connected to the APs on the 3rd Floor.  Only 4 Clients are getting an address from VLAN 50.
 
I'm not sure if something is configured wrong or not since some devices pick up the new VLAN and the rest don't.  I've manually reboot the APs on the 3rd floor to see if that would fix it.

View 2 Replies View Related

Cisco Wireless :: 5508 AP Group VLANs Feature Enable

Apr 7, 2012

i have a WLC (5508) - trying to enable AP group vlans based on instructions from: url...however, my problem is that i don't have the 'ap group vlans feature enable' checkbox.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Host Internal Identity Store / Per Group Modification

Jan 24, 2012

I'm currently looking for a solution in order to restrict the modification of the host internal identity store (add or delete MAC host) per group. The default administrator roles does not include "per group restriction". Under the ACS I defined one group per department? My objective it to allow each department to access their ACS MAC database to add or delete MAC addresses as required.

How to restrict internal identity store per group?Do I need to create new roles? and how?I was not able to get an answer from the ACS ADMIN manual.

View 1 Replies View Related

Cisco Wireless :: WLC 5508 Internal DHCP

Aug 22, 2011

The two controllers are having two internal DHCP servers with the same range in LAN (enx1,enx2). but i have specified which is primary DHCP server(enx3) in WLAN interface.
 
Now if a new user added into network, will he get IP address from primary dhcp(WLC) or AP connected WLC.
 
if two users connected to 2 diff AP's which are connected to 2 WLC will get the same IP address? since having same address pool configured.

View 11 Replies View Related

Cisco Wireless :: 5508 - Internal DHCP / Two SSID?

Jun 28, 2012

We created the management interface, an internal DHCP scope in same subnet, and Two SSID tied to the same management interface:
 
- when we connect to the first SSID we have and IP address
 
- but when we connect to the secone SSID: impossible to get an ip address - auth and association are OK

View 11 Replies View Related

Cisco Wireless :: WLC 5508 Internal DHCP Server

May 7, 2012

I am hoping to get your feedback around the dhcp issues I am facing with Two Centrally Switched Wireless LANs. The setup is as follows:

- I have a WLC 5508 which has been configured with 4 SSIDs, out of which 2 are using Central Authentication and Switching. - I have an LWAP connected to the WLC in HREAP mode. - WLC is configured as the DHCP server for clients connecting to the SSID 'Guest'. For the rest, I am using external dhcp server. - Only one scope for Guest Interface is setup on the WLC. 
 
Problems:
1. As far as I know, for WLC to act as internal dhcp server, it is mandatory to have the proxy enabled, but the Clients connecting to SSID 'Internet' are unable to get an ip address from the external dhcp server, if dhcp proxy is enabled on the WLC. If i disable the proxy, it all works fine.
2. DHCP does not release the ip addresses assigned to clients even after they are logged out.
3. If a machine which was earlier connected to 'Guest' SSID connects to the 'Internet' SSID, it requests the same ip it was assigned by the WLC which it was assigned under 'Guest', but gets tagged with the V LAN configured on the management interface.  
 
************Output from the Controller********************
(Cisco Controller) >show sysinfo
Manufacturer's Name............. Cisco Systems Inc.Product Name................ Cisco Controller Product Version................. 7.0.116.0Bootloader Version................ 1.0.1Field Recovery Image Version..................... 6.0.182.0Firmware Version..... FPGA 1.3, Env 1.6, USB console 1.27Build Type.......... DATA + WPS + LDPE
[code]...

View 12 Replies View Related

Cisco Wireless :: 5508 Internal DHCP Server

Jul 21, 2012

A client wants us to use the internal DHCP server on a 5508 instead of Windows DHCP. They will have 15 APs initially and upto 25 later. The docs on the 7.2 WLC make it sound like this is discouraged: Internal DHCP Server.

The controllers contain an internal DHCP server. This server is typically used in branch offices that do not already have a DHCP server. The wireless network generally contains 10 access points or fewer, with the access points on the same IP subnet as the controller.
 
In this case, the APs will not be in the same subnet as the Managment Internet.Is it a mistake to use the internal DHCP with upto 25 APs (3 WLANs)? 

View 3 Replies View Related

Cisco Wireless :: 5508 Office Extend Internal External?

Dec 18, 2011

I am having an issue with internal and external clients. When we have the nat ip configured on the controller we cannot connect internal ap's at all. When we take the nat ip out it works fine. We are on code 7.0.220. I have tried the following command  <config network ap-discovery nat-ip-only disable> and it did nothing.

View 1 Replies View Related

Cisco Wireless :: 5508 - Remote AP Connecting To NAT Address Instead Of Internal IP

Jun 2, 2013

We have a 5508 with 7.4.100.0 vor Internal APs and OEAPs. till now every thing is ok. Now we have to connect an AP (local) in a remote office, connected to the WLC by a VPN Tunnel. The problem is that the AP in the remote office uses the NAT Address to connect to the WLC, so the traffic goes over the Internet, not trough the VPN Tunnel. On the controller I have the following setting:

AP Discovery - NAT IP Only ................. Disabled
On the AP:
AP Link Latency.................................. Disabled
 
How to force the AP to use the internal IP Address of the WLC?

View 7 Replies View Related

Cisco :: WLC 5508 - Keeping Internal Users Off Guest Wireless

Mar 22, 2010

Have a WLC 5508 running 6.x code with LAP's providing wireless for our internal laptops (WPA2 and EAP-TLS). I want to provide guest wireless which goes out a different port on the WLC to a guest firewall/cable modem. However, we want to prevent our internal laptops from being able to use the guest wireless. I have RADIUS (IAS) and LDAP for my AD available. We would prefer not to have use Lobby Ambassador and just have the guests use a simple password or web passthru. Guests may be laptops or smartphones. What options are available? I have tried a test setup using dynamic vlan assignments from RADIUS using the IETF flags, but can't seem to get it to work. Is there a way to identify the SSID is being used at the RADIUS server?

View 13 Replies View Related

Cisco Wireless :: WLC 5508 Not Able To Activate Internal DHPC Server

Sep 27, 2012

I recently installed 2 wlc 5508 with the latest software 7.3.101.0. I am not able to activate the Internal DHPC Server. The following message appears: "Error in setting dhcp scop leasetime".

View 5 Replies View Related

Cisco :: 5508 Is There A Way For Internal DHCP Scope To Release Scope Addresses

Apr 7, 2013

DHCP scope is configured on a WLC 5508.I'm checking if there' a way for WLC to clear the dhcp leasing when a user is diconnected from wireless?

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved