Cisco :: 5508 Web-Auth Cert Crashing When Loaded

Sep 24, 2012

I have a cisco 5508 WLC that I have setup WebAuth on and trying to install the certificate on.  I have generated the csr and gotten my cert from Verisign (X.509, server platform=apache).  I have followed the instruction via the cisco documentation url...I found an error in uploading and find out how to encrypt mykey: url...

I am also having exactly the same issue with a certificate from Thawte.  I followed the unchained guide and have tried both with and without a password in the initial step key generation step, requesting a new cert each time. As with Jeensernchew's issue there are no errors in OpenSSL but when uploading the cert to the WLC get the following error. [code] The WLC is running version 6.0.196.0.  I am using OpenSSL 1.0.0 29 Mar 2010.
 
When I requested the cert from Thawte I was asked to specify the device type, I chose Cisco, but as all the work and conversion is being done by OpenSSL, should I have chosen differently? When I do this I can load the cert in the 5508, but the controller fails and doesn't allow that VLAN or config access to the wireless network.  I am at a loss of why I can load and it not work.  I have verified my hostname and password and those are good.

View 1 Replies


ADVERTISEMENT

Cisco :: Reloading Renewed 3rd Party Cert On WLC 5508?

Apr 22, 2012

So since my web auth cert is expiring I got it renewed from VeriSign and they sent me back the file.  Do I need to again combine the "myprivatekey.pem" file and the new one that I got and then load it on the WLC?  Can't find any guidelines and instructions from Cisco on this.  Or do I need to go through the whole regenration of CSR process again etc? 

View 3 Replies View Related

Cisco AAA/Identity/Nac :: 5508 ISE Integration With PEAP (Server Side Cert)

Oct 20, 2012

We are currently evaluating ISE and I am stuck with the PEAP authentication (with Server side Cert).Our current setup consists of two 5508 controllers, 30+ access point. For authentication we are using PEAP with (server side Cert). We have an IAS server which is also acting as a CA server. We are using Cisco’s NAM as a supplicant on Windows XP & 7 workstations. I would like to use ISE for authentication. I would like to use PEAP with Server side Cert (similar setup like IAS). I want ISE to perform the same function in addition to profiling etc.....
 
I was able to integrate ISE with Active Directory but could not get it working with PEAP (server side Cert). I would also like to know if they used Microsoft’s CA server or Open SSL CA server or a third party CA server (Go Daddy, VeriSign etc.)Can you we ISE as a CA server just the way we used Microsoft’s IAS Server as a CA Server?

View 8 Replies View Related

Cisco :: 5508 Anchor WLC Web-auth Secure Web

Mar 18, 2013

I am running into an issue with disabling the web-auth secure web on an 5508 anchor WLC running 7.2.110. After the WLC rebooted, the guest authentication portal didn't show up...I could see the IE tab showed Web Auth Redirect though...Changed again the web-auth secure web to enable and rebooted the WLC fixed the issue.

View 4 Replies View Related

Cisco :: 5508 - Disable HTTPS On Web-auth Passthrough

May 16, 2012

I have a guest wireless network setup on a 5508 WLC using 7.2.103.0 firmware. Under my guest WLAN>security>Layer3 tab I have "layer 3 security" as "none", "web policy" as check marked, "passthrough" selected, "over-ride global config" as check marked, "web auth type" as "customized(downloaded), "login page" and "login failure page" as "login.html" selected.
 
I haveI have 4402 WLC's using 7.0.116.0 firmware throughout my company that anchor back to the 5508 for the guest network. The 4402 WLC have the guest network configured as WLAN>security>Layer3 tab I have "layer 3 security" as "none", "web policy" as check marked, "passthrough" selected.
 
I would like to disable the HTTPS for the logon screen and I am not sure what steps need to be done for this. I researched and found the command "config network web-auth secureweb disable". I set the command on the 5508 only and rebooted. When I tested I got a blank webpage with "http://1.1.1.1/fs/customwebauth/login.html?switch_url=http://1.1.1.1/login.html" in the address bar and had no way of clicking the accept button to get to the Internet.
 
Everything works fine again if I enter "config network web-auth secureweb enable" and reboot. Do I need to run the "config network web-auth secureweb disable" command on all the 4402 WLC's that are anchored to the 5508? What could be breaking my login.html page while using only http?

View 3 Replies View Related

Cisco Wireless :: 5508 Customized Web-Auth Bundle

May 30, 2012

I am trying to upload a customized web-auth bundle to a WLC 5508 and having some issues.I have downloaded the web-auth bundle from Cisco and used this as a template to create the web pages.I seem to recall that there is only a couple of Windows tools that you can use to TAR the file such as TUGZIP and IZARC. Anyway I have tried both and I still cannot get the file to extract. I have tried to strip the file out so that I only send up the login.html page and even this does not work.I am using a software release 7.0.220.0.

View 6 Replies View Related

Cisco :: Export The Default Web Auth Portal With WLC 5508

Sep 19, 2012

I´m wondering if it`s possible to export the defualt web auth portal(web login page) via tftp to a computer from the Cisco WLC 5508 and then modify it and then import that customized portal to the WLC 5508?

View 6 Replies View Related

Cisco Wireless :: WLC 5508 - Web Auth DNS Host Name Section Not Resolved

Mar 8, 2012

We have recently implemented a 3rd party certificate for the guest access, currently have a WLC 5508 that has a Vlan directly connected to our DMZ firewall and NATed out. The problem is when I have installed a 3rd party certificate as per the following link URL
 
The DNS host name that I entered into the DNS Host name section is not resolved. If I remove the DNS name and leave the virtual ip address 1.1.1.1 then it works fine but just comes back with untrusted message.

View 34 Replies View Related

Cisco Wireless :: WLC 5508 Web Auth Splash Page - Possible To Place Download

Apr 16, 2012

I know it is possible to create custom web auth splash pages on the WLC 5508. Is it also possible to embedd a small document (less than 1MB) that users can download directly from the controller? I need this for providing the terms of use for the Guest WLAN.

View 3 Replies View Related

Cisco Wireless :: Why Is Web Page Auth On MAC Filter Failure Also Not Working On 5508

Jul 22, 2012

I have implemented a Guest WLAN solution as per the recommended design from Cisco. We have two internal WiSM2 controllers providing services for Internal secure SSIDs. Both these controllers are members of a Mobility and RF management group.
 
Two 5508 controllers have been installed in our DMZ for resilience and have been placed into a separate Mobility group. All controllers (internal and external) have been linked together as mobility neighbours in a full mesh and a new SSID for Web Guest traffic has been anchored to the controllers in the DMZ.
 
Web page authentication works perfectly fine, but I cannot for the life of me get the MAC filtering override to work, i.e. if a MAC address is present, do not redirect to the splash page for web auth. I know I can get around this by just creating two separate SSIDs. But the business is used to just having the one SSID for all guest traffic. Is this a known limitation when anchoring SSIDs to controllers in the DMZ ?

View 1 Replies View Related

Cisco Wireless :: 5508 - WebPage Auth On MAC Filter Failure Not Working On Anchor

Nov 1, 2011

I have implemented a Guest WLAN solution as per the recommended design from Cisco. We have two internal WiSM2 controllers providing services for Internal secure SSIDs. Both these controllers are members of a Mobility and RF management group.
 
Two 5508 controllers have been installed in our DMZ for resilience and have been placed into a separate Mobility group. All controllers (internal and external) have been linked together as mobility neighbours in a full mesh and a new SSID for Web Guest traffic has been anchored to the controllers in the DMZ.
 
Web page authentication works perfectly fine, but I cannot for the life of me get the MAC filtering override to work, i.e. if a MAC address is present, do not redirect to the splash page for web auth.

View 6 Replies View Related

Url Is Not Valid And Cannot Be Loaded?

Oct 26, 2011

url is not valid and cannot be loaded

View 1 Replies View Related

Cisco Firewall :: ASDM Cannot Be Loaded ASA 8.2

Feb 28, 2012

ASDM cannot be loaded. Click OK to exit ASDM. Server returned HTTP response code: 503 for URL...

I'm attempting to access the ASDM externally (where x.x.x.x is the external IP). I was able to access 3 days ago just fine. So far, I've found suggest a reboot.

ASA Version 8.2(1)  - I think the ASDM version is 6.2

View 11 Replies View Related

Network Is Connected But Nothing Is Loaded

May 6, 2012

I have a small network, that consists of a wireless router, a switch, three wired pc's, a couple of wireless pc's and an xbox.I have a switch wired to the router. There are three pc's (2 with XP and 1 with vista) and a xbox connected to the switch. All three pc's work fine as long as the xbox is turned off. When I log on with the xbox, one of the pc's (vista) refuses to work on the network.The network and sharing center shows I have a connection to the internet, but it won't load any pages or allow me to connect to the other pc's either.

View 6 Replies View Related

Cisco Wireless :: Possible To Have License Loaded On An AIR-CT5508-HA-K9

Apr 25, 2013

Is it possible to have a license loaded on an AIR-CT5508-HA-K9 in order to have it working as a stand alone controller?

View 4 Replies View Related

Cisco Switching/Routing :: Set 2950 IOS To Be Loaded From TFTP

Jan 11, 2012

2950 switch has a IOS on flash , but i would like to set the swith like...

1. switch IOS to be loaded from TFTP server .if it fails

2. Loaded from local flash IOS1 , if it fails

3. IOS loaded from local flash IOS2.
 
does 2950 switch support this feature.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.x Large Deployment Add-on License / When Should Be Loaded

Mar 24, 2012

I already have large deployment add-on license. I also have 3 ACS Servers. Now, my primary ACS server is now up and my two secondary ACS server will be put up soon.
 
Just want to ask, when should be the large deployment add-on license be loaded? Can I load it to my primary ACS server eventhough my secondary servers are still not up? Or should I load it to my primary ACS server when my two secondary servers are already up?

View 3 Replies View Related

Cisco :: How To Export Cert From WLC 4402

Apr 1, 2013

I installed a chained SSL cert on our anchor/guest 4402 a few years ago.We now have a need to replace the 4402 w/ a 5508, and I got everything configured, ready to go, except that darn cert.I can no longer locate the private key that was used to sign the original CSR.Is there any way to export the current cert from the 4402, so that I can import to the 5508? Or am I SOL?

View 3 Replies View Related

Cisco Switching/Routing :: RVO82 Web Pages Not Fully Loaded

Aug 14, 2011

I'm using a RV082 and have about a dozen users on my network.Occasionally, when a user is accesssing a website like yahoo.com, twitter.com, cnn .com, etc, the web page only loads half way. Most often the page is missing stylesheets and/or images. Called Cisco support and they adjusted the MTU size to 1492 from 1500.Have a looked at the bandwidth report from my ISP and it shows nothing out of the ordinary, no spikes or surges in d/u. Have set LAN port to high priority, 100 Mbps, full duplex.. Seeing an error count around 327282.. which I don't understand.Why sites only partially load using this router?

View 1 Replies View Related

Home Network :: Connect WRT54G DD-WRT Loaded To A DLINK DIR-655

Jan 6, 2012

I am having a tough time connecting these two routers wirelessly, i had connected a WRT54G Linksys software to the WRT54G DD-WRT router with no effort. But these two will just not connect.

View 1 Replies View Related

Cisco VPN :: Using A Publically Signed Cert On ASA 5505

May 1, 2013

I am wanting to use a cert signed by a digicert or verisign on my ASA so that anyconnect doesn't frreak out with the untrusted cert. I have created the CSR, and I uploaded the certificate, but it is still showing the old self signed untrusted cert.

View 5 Replies View Related

Cisco VPN :: Cut-n-paste Cert Enrollment With MS 2003 CA?

Aug 14, 2005

When trying to do a cut-n-paste enrollment of a cisco 3725 router with a microsoft windows server 2003 CA i get the following error on the CA.Certificate Services denied request 8675 because The request subject name is invalid or too long. 0x80094001 (-2146877439).  The request was for OID.1.2.840.113549.1.9.2=rtr31slied3.unit4agresso.com.  Additional information: Error Constructing or Publishing Certificate This is when i use the router or webserver certificate.The only template that does work is the user certificate but then you get error messages that the router name doesnt match the cert name.The 3725 is running ios version 12.3(14)T3.How can we get the right templates to work ?

View 3 Replies View Related

Cisco VPN :: ASA 5510 / Wildcard Cert - Only Have CER File

Dec 5, 2011

how to install a wildcard certificate with only the .cer file.  I've found quite a few things here in the forums, but everyone seems to also have a pkcs12 file, which I do not. 
 
This is an ASA 5510 on ver 8.4. 

View 6 Replies View Related

Cisco Application Networking :: CSS 11503 And SAN Cert

Oct 14, 2012

I know that CSRs cannot be generated with multiple names, but if the SAN is added after the cert is ordered from Geo Trust, Veri sign, etc. can the CSS support using the cert?

View 1 Replies View Related

Cisco Switching/Routing :: Can C3560-24PS Switch With 32 MB Flash Be Loaded With IOS 15

Jul 23, 2012

Can a C3560-24PS switch with 32 MB flash be loaded with IOS 15? Will it be able to execute the code and function properly?

View 2 Replies View Related

Cisco VPN :: ASA 5545-X / Cert And AD Authentication Using AnyConnect 3.0.xxxx?

May 29, 2012

I have a need to utilize two factor authentication using a machine certificate and users AD crednetials.  What we would like to do is to have the ASA and AnyConnect verify the certificate exists, check against our in house CA for validity, if valid pass the user credentials to the AD servers and establish the tunnel. If not valid quarantine the session and pop a message to the user to contact the help desk ASAP.  My guess is the following (using ASDM 6.6, ASA 8.6.1, ASA 5545-X):
 
1. under the connection profile I have select BOTH for authentication and added a AAA server group.

2. under Cert Management I have added the 3 certs that are present on all company mobile assets

     - Cert America
     - Cert Europe
     - Cert Root

3. I have an identity cert installed from the company CA and it is selected as the device cert under connection profiles

4.Local Cert Authority is Disabled

5.Under Remote Access>Advanced>Certs for AnyConnect>

- I have mapped DefaultCertifiateMap pri 10 to Company_Cert connection profile

- The mapping is looking for Subject: CN: <Contains> (string) ----where string is a common component of each Cert listed in #2.
 
Question #1 - Is this correct for utilizing certs and AD auth or have a missed any steps?
 
Users are directed to a an initial installation URL - where the AnyConnect client performs the installation and passes down the intial AC profile which auths using only AD creds.  On subsequent connections users who pass the certificate mapping check are migrated to the connection profile which uses the dual authentication method. 
 
Question #2 - When I attempt a new installation of AnyConnect using the two factor URL . I receive an error "certificate validation error" and the installation fails - for the life of me I can not figure out why????  The machine has all three certs, using IE9 as the browser.

View 3 Replies View Related

Cisco Firewall :: Installing A Wildcard Cert On ASA 5500

Apr 15, 2013

I am basically looking to install the wildcard on the outside interface for my ASA

View 1 Replies View Related

Cisco Security :: How To Renew Self-Signed ACS 3.3 Cert Used For PEAP

Mar 29, 2006

We currently are using a self-signed cert (for PEAP machine authentication) that was created on an ACS 3.3 appliance.  That cert was manually installed on our laptops when they were configured for wireless conenctivity.My problem is, that self-signed cert will soon be expiring and I am not sure what needs to be done to issue a new cert AND deploy it to my Windows XP Pro clients without a service interruption.  If possible, I'd like to leverage our exsiting AD infrastructure for this, but I need some direction, and time is of the essence!!

View 2 Replies View Related

Cisco VPN :: Anyconnect 3.1 Untrusted Server Cert With Wildcard

Jan 21, 2013

I've seen a bunch of discussions on the untrusted server cert error with self signed certs.  But I have a valid wildcard that I use on my ASA.  How do I make that work with out the untrusted server cert error?

View 5 Replies View Related

Cisco Wireless :: Installation Of PFX Cert On AIR-WLC2125-K9 Controller?

Mar 7, 2012

I have a client that needs to update a certificate on their 2125 controller. They have created a .pfx cert that does not work because of file type. I wanted to see what the best pratice would be for me to follow installing this cert and do I need any additional cert like a CA. I found a document but am not so sure that it is exactly what I need.

AIR-WLC2125-K9 : JMX1248K0EL
System Information
Manufacturer's  Name.............................. Cisco Systems Inc.
Product  Name..................................... Cisco Controller
Product  Version.................................. 6.0.188.0
RTOS  Version..................................... 6.0.188.0

[code]....

View 2 Replies View Related

Cisco Switching/Routing :: PIX515 To ASA5510 - Tries To Connect To Wireless Never Gets Page Loaded

Oct 13, 2012

Recently I  changed our default gateway from a pair of  PIX515 to ASA5510.  Since I changed the gateway anyone connecting to our wireless VLAN/network who tries to access the Internet may or may not get a page load.  If the page loads it is extremely slow and sometimes the browser page indicator will just spin like it is loading.  It's not our access points, if attach an ethernet cable to my laptop and put my switchport in the wireless VLAN I experience the same problem.  DNS resolves OK, ping responses are consistent with no drops and access to any internal resources are good.  All other LAN VLANs/networks work just fine, it's just Internet access on the wireless VLAN. I see the correct traffic flow in the ASA packet capture. Anything in the ASA Packet inspection related to wireless networking that could be blocked?  Is there a way to check for a routing loop possibly?

View 2 Replies View Related

Dell :: Optiplex 745c Computer Does Not Have Any Drivers Loaded For Installed NIC Card

Apr 7, 2013

My daughter bought a Dell Optiplex 745c from a company who is replacing their cmputers.  This particdular computer does not have any drivers loaded for the installed NIC card, so te machine will not talk to the intenet. Are the drivers in the 745 and the 755 the same?

View 1 Replies View Related

Cisco Application :: CSS-11500 - Use SSL Cert In Proxy List For Same VIP But On Different Port?

Aug 16, 2012

Am I able to use an SSL cert in the proxy list for the same VIP but on a different port?  

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved