Cisco :: 5508 - Wildcard Certificate Accepted By Wireless Lan Controller?

Feb 13, 2011

I have 3 WLC 5508 and a NAC guest server. We want to download a wildcard certificate after a few seconds at the download of this certificate I got the failure message download failed.
 
Accept the WLC wildcard certificates or must I generate a SAN (Subject Alternative Name) Certificate.

View 5 Replies


ADVERTISEMENT

Cisco Application :: CSS 11501 - Wildcard Certificate With Subject Alternative Names

Sep 6, 2012

I generated a wildcard certificate for my company type *. [URL] in a CSS 11501. For the site [URL] worked fine, for the site [URL] didn't worked. I read on the web that should generate a wildcard certificate with subject alternative names. Is it possible in CSS? how can I do it?

View 5 Replies View Related

Cisco :: Install GoDaddy Wildcard SSL On WLC 2504 Controller

Jan 28, 2013

I'm attempting to install a GoDaddy wildcard ssl certificate onto a WLC 2504 running version 7.4.100.0.
 
I am getting the error "#SSHPM-3-KEYED_PEM_DECODE_FAILED: sshpmcert.c:4055 Cannot PEM decode private key" when downloading the .pem file to the controller.
 
What I have attempted to do was to export the certificate from a Windows 2008 R2 server into a .pfx file. The file contained the private key and all possible root certficates (in this case a root and a intermediate cert). Now I took this .pfx file and attempted to create a .pem file with openssl using the following command: openssl pkcs12 -in myssl.pfx -out mynewssl.pem -passin pass:mypassword -passout pass:mypassword
 
Now I have opened the .pem file and verified it does contain the private key and the three certificates (wildcard, intermediate and root).

View 4 Replies View Related

Cisco Wireless :: 4404 Guest Anchor Controller With 5508 Foreign Controller?

Aug 12, 2012

I know that the 3600 series APs are not supported on the 4404 WLC.  However, would the following scenario be supported? I would like to use the 4404 (software rel. 7.0) as a guest anchor with a 5508 (software release 7.2) as the foreign controller supporting series 3600 APs.  I ask because the APs do not need to join the guest anchor.

View 7 Replies View Related

Cisco Wireless :: 5508 Foreign Controller And 4400 Anchor Controller?

Jun 2, 2013

We have a customer that have 2 5508 as primary and backup controller and a 4400 as an anchor controller.  We plan to upgrade the 5508 to 7.3.112.0 and the 4400 is already 7.0.116.0.  Will there be any issue if the anchor controller is not the same code as the foreign controller?  Do I also have to upgrade the acnhor controller to 7.0.240.0?

View 2 Replies View Related

Cisco Wireless :: WLC 5508 And Certificate For Ipad Users?

Jan 5, 2013

Have WLC 5508 running 7.4 code; have wlan setup to allow access to internal network. Users on ipads should be able to connect to this wlan and authenticated via certificate instead of PSK. We have setup laptops that are part of domain to use internal CA for authentication to WLAN. Ipads are not part of domain so we are not able to use the same model, or can we use the same model for authentication?How to setup WLC to authenticate ipad users via certificate instead of PSK while connecting to the WLAN?

View 1 Replies View Related

Cisco Wireless :: 5508 WLC Apply Certificate Without Reboot

Apr 10, 2013

get a installed certificate work on a 5508 WLC Controller without rebooting. Is there a way? Is it possible to just reload a process to get the certificate work?

View 1 Replies View Related

Cisco Wireless :: Putting A Certificate On 5508 WLC For Webauth?

Feb 12, 2013

I am using webauth and need to install a SSL cert to prevent the "There is a problem with this website's security certificate" message. I have a Wildcard cert that was issued by Network Solutions that I use on a couple web servers I run, and want to know if I can use that for the WLC? It's a pks cert and I think the WLC needs to use a pem cert, so I converted the wildcard to pem. Or do I need to purchase a cert that is not a wildcard and is in pem format?

View 7 Replies View Related

Cisco Wireless :: 5508 - Virtual WLC - Certificate Errors

Sep 13, 2012

I have just setup a vWLC for lab purposes and it´s up and running. I have a few used 1131 LAP:s that tries to join the AP but I just get DTLS certificate errors like these:
 
*Sep 14 13:25:27.229: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to up
*Sep 14 13:25:27.258: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to up
*Sep 14 13:25:36.198: %CAPWAP-3-ERRORLOG: Go join a capwap controller
*Sep 14 13:26:41.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.1.105 (code)
 
These AP:s (I have tried 2 so far) have earlier been in use connected to a cluster of 5508:s.

View 19 Replies View Related

Cisco Wireless :: 5508 Can Migrate Web Authentication Certificate Used For Guests

Sep 3, 2012

I am planning to migrate from an old 4400 to a new 5508. I am happy with migrating the access points but I need to know if I can migrate the web authentication certificate used for guests.The new WLC will have the same virtual interface and DNS name to match the CN on the current certificate. Will this work or will I need a new certificate?

View 2 Replies View Related

Cisco Wireless :: 5508 - Bypass / Remove Certificate Page For Guest User WLAN

Jul 24, 2012

When a guest user first trys to access the "guest" WLAN, they are presented with a "certificate page" before the web athentication page / login  is presented.  The WLC forces an internal redirect to https://1.1.1.1 causing the certificate page to appear.  Can this be bypassed?    I am runiing 5508 with   7.0.220.0. 

View 12 Replies View Related

Cisco :: 4402 Controller Not Working With Certificate Authentication

May 16, 2011

I am enabling our wireless controllers to use 802.1x authentication for our wireless clients. Both computer and user are provided with certificate from CA server.I have 9 APs and 2 controllers installed in my infrastucture, one of the controllers is working fine with setting specified above but the other one is not.Both has same configuration and both seems identical with same model and IOS.

View 3 Replies View Related

Cisco :: How To Chance Web Authentication Certificate On WLAN 2100 Controller

Feb 8, 2011

how to chance the web authentication certificte on WLAN 2100 controller. My users are complaining that they need to accept the security certificate before proceeding to the actual authentication?

View 4 Replies View Related

Cisco :: WLC 5508 - Possible To Support 1 Certificate For Each WLAN

Mar 27, 2013

We are moving forward with a mobility project which requires our network to authenticate/authorize based on certificates. 
 
WLAN_1 has 802.1x enabled passing the cert through to the MS CA which authorizes the cred, which in turn passes the AD creds of the user to the MS RADIUS server for authenticate/authorization.

Hardware: WLC 5508 running 7.2.110.0 3600 APs ACS 5.2 not used for AAA
 
1. As we turn up additional SSIDs, we need Mobile SSID to accept ONLY the Mobile Cert, our Internet SSID to only accept the Internal Cert and our GUEST SSID to deny ANY Cert issued by our CA.I know ISE makes this much easier, but I dont have it and need this to work as best we can until next fiscal cycle..

View 3 Replies View Related

Cisco Wireless :: 5508 / AP On Different Vlan Than Controller?

Sep 30, 2011

I have a 5508 controller at our headquarters and am installing some 3502 AP's at a remote branch.  Unfortunatly, the remote branch has a different Vlan setup for some reason and the vlan that is used for the WLC (90) is designated for telephony at this branch.  Can I put the AP's on a different VLAN (10) without having any issues?  I will still use DHCP option 43 to point them back to the controller. Below are the configs for the WLC interfaces and what I am proposing for the AP interfaces:
 
WLC Config
 
interface GigabitEthernet1/1/38
description WLC01
switchport
switchport trunk encapsulation dot1q
switchport trunk native vlan 90
switchport trunk allowed vlan 1,10,50,90,91,390,410-413,610-613,800,810,811
switchport mode trunk

[code]......

View 3 Replies View Related

Cisco Wireless :: Setting UP 5508 LAN Controller

Nov 13, 2012

Cisco 5508 Series Wireless Controller for up to 100 APs 802.11a/g/n Ctrlr-based AP w/CleanAir; Ext Ant; E Reg Domain..For Mobility i want to settup the device such that the SSID would be the same with thesame security key and in different subnet.

View 5 Replies View Related

Cisco Wireless :: WLC 5508 / Rejoin To Different Controller

Feb 10, 2013

I use WLC 5508 (ver 7.0.116.0) with aironet 1140. I need to connect my APs to different controller .After log in via ssh to AP i am trying to do:
 
capwap ap controller ip add x.x.x.x
reset
 
But after reload, AP is still joined to the old WLC. So another idea was to log to that WLC and put:
 
config ap primary-base WLC2 AP_NAME x.x.x.x
 
and after that:
 
config ap reset AP_NAME
 
But still nothing, it's joined to another controller although "show ap client config" shows that primary-base switch is x.x.x.x ?How can i force it to join to other controller?

View 3 Replies View Related

Cisco Wireless :: Upgrade 5508 Controller From 7.0.98.0 To 7.0.220.0

Jan 29, 2012

We are looking to upgrade our 5508 wireless controller from 7.0.98.0 to 7.0.220.0. Reason being, we have experienced a lot of access points disassociating from the controller as well as client authentication issues. Upgraded from 7.0.98.0 to 7.0.220.0 and any issues during the upgrade or after the upgrade?

View 3 Replies View Related

Cisco Wireless :: 5508 Anchor Controller In DMZ

Nov 26, 2012

We have a WLC (5508) in our main office in Brisbane that is hosting two WLANs. One provides wireless access to our internal network and the second provides wireless guest access. The guest WLAN is anchored to a controller sitting in the DMZ at our Data Centre.
 
In the DMZ the anchor controller has a management interface and an interface in the DMZ for the wireless guest access. I am using the DHCP server on the anchor DMZ to provide IPs etc to wireless guest clients. The default gateway is 10.8.144.1 which is a VIP or a pair of firewalls.
 
Initially everything works fine. Guests connect to the guest network, have to authenticate via a web portal (Cisco ISE server) and then can go on an use the internet. Works perfectly until the firewalls fail over and the secondary firewall takes over the VIP address. All access to the internet is lost at that point. If I try to disconnect and then reconnect a wireless client it connects, as in it will get an IP address, but DNS resolution stops and I do not get redirected to the web auth portal. If the firewalls are failed back to the primary then everything works again, no issues. However, if I reboot the WLC while the secondary firewall has the VIP IP everything will work fine as it did on the primary. If the firewalls now fail over to the primary again everything goes to ****. Until either the firewalls are failed back or the anchor WLC is rebooted.
 
Initially I thought this was an issue on the firewall, but this doesn't appear to be the case. When the firewall fails over it sends out a gratuitous ARP advising of the change in MAC address for the 10.8.144.1 IP address. The WLC seems to update its ARP table because if I run the command "show arp switch" it has the 10.8.144.1 IP address with the MAC address of the active firewall. From the client perspective I have run a wireshark and captured packets on the wireless interface when trying to connect. The laptop is continuously send ARP requests for 10.8.144.1 but gets not reply. Without this the client cannot send an ethernet frame to the gateway and hence get to the DNS server and WEB portal. Internet access breaks. Doing a TCP dump on the active firewall shows it receiving and then sending a reply to the ARP request. It just never gets to the wireless client. Debugging ARP packets on the anchor WLC seems to indicate that the controller is receiving the ARP replies from the firewall. So I'm at a loss as to why things should break when the firewalls fail over.
 
I have a 3750 switch in the DMZ with SVI of 10.8.144.4. I thought I could get a work around where I would make this the default gateway. The theory being that this interface MAC address would never change. However I was wrong. Even with this IP set as the gateway address for the wireless clients I see the exact same bahaviour when the firewalls fail over. I can't explain it other than to say that the gratuitous ARP sent by the firewalls seems to kill the ability of ARP replies to be sent back to the wireless client.

View 3 Replies View Related

Cisco Wireless :: 5508 - VPN / GRE Don't Show Up In Controller

Mar 6, 2012

Just replaced a 2106(ver 5.1) with a 5508 (ver.7.2)...Everything was OK.. AP's got on 5508 and we shut the 2106. (AP's are on L2 with controller)During some investigation of why new LAP's from a location via VPN/GRE don't show up in controller, i type the following command on 5508: test ap pmtu enable all....All AP's on 5508 is now in Not Joined state..Have powered up the old 2106 and put AP's on that .. This is OK  ....Have rebooted/downgraded/upgraded the 5508 controller but with same result.....No AP's can join this controller (exept from a oeap600)

View 8 Replies View Related

Cisco :: Getting 5508 Wireless Controller Configuration

Sep 15, 2011

So we have a Cisco 5508 controller that is managing 15 AP's in one of our buildings.I am running 2 wlans, one is internal access via (wpa) radius, peap and domain login...that works well now
 
The other is a guest lan, that is only allowed to surf the web.
 
The question from our security group, is there a way to restrict wireless access to ONLY a corporate approved list of devices.
 
As it stands right now, we only support Blackberry's as our mobility device. All local data is encrypted. The issue here is our testing shows that with an Iphone (not approved) it is very easy to connect to the WPA network if a user knows how to enter in their domain credentials. From there they can browse our internal web servers and download corporate data to a non approved, non encrypted device such as the iphone.

View 1 Replies View Related

Cisco Wireless :: 5508 - APs Not Joining Controller

Jul 28, 2011

I upgraded a controller yesterday 5508 it went from a low code version 6.x to 6.0.196.0 then to 7.0.116.0. However although all the access points joined code 6.0.196.0 they refused to join 7.0.116.0. The aps are all 1242s.
 
The country codes etc were all fine so I do not understand what was going on.

*spamApTask0: Jun 26 16:07:44.734: 00:3a:99:db:f3:20 Discovery Request from 10.0.0.183:55065
*spamApTask0: Jun 26 16:07:44.734: 00:3a:99:db:f3:20 Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 25, joined Aps =0*spamApTask0: Jun 26 16:07:44.735: 00:3a:99:db:f3:20 Discovery Response sent to 10.0.0.183:55065
[code] ......

View 5 Replies View Related

Cisco :: 5508 / 1142 - Machine Certificate Will Not Be Recognized

Dec 10, 2010

i have a Setup as Follows
 
- 5508/1142
- heterogenous Client with WZC, XP, SP3, SSO
- ACS 5.2, MS AD
 
Target is Songle Sign On wih Machine Cerificates against AD. For testing purpose we tested with EAP-PEAP/MS Chapv2 and Machine Auth, works fine. Now we installed a Machine cert in the Machine cert Store (no User Cert) and reconfigured the WZC for using certs and Machin Auth. What we see is an Error Message in the System Tray that there is no certificate available. We checked it again, the MMC shows us a Machine cert in the Store.

View 4 Replies View Related

Cisco :: 5508 Unable To Upload Signed Certificate

Jul 1, 2012

I have two Cisco WLC 5508 controllers that I'm trying to set-up for our new corporate WLAN. I've gone through most of the configuration fine but have ran into an issue uploading a signed certificate to one of my controllers. I should point out that I have managed to upload the certificate successfully to one of the controllers, I just can't seem to upload it to the second.The issue is as follows:
 
- I've logged into the controller, gone to Security -> Web Auth -> Certificate -> Download Certificate
- I've specified my tftp server details and selected apply
- the process begins and I can see through my tftp client that the controller is attempting to copy and install the certificate
- The controller tries to install the certificate but fails, reporting the same

View 9 Replies View Related

Cisco Wireless :: AP's Intermittently Joins WLC Controller 5508

Nov 27, 2012

Ap's at remote location intermittently joins unjoins the WLC controller 5508. AP's getting IP's from DHCP server located at locan end. [code]

View 8 Replies View Related

Cisco Wireless :: 5508 - LAP And Mesh AP With Controller Concepts

Jan 29, 2013

I have one controller 5508 that will hold 50 LAP 1262 and another Controller that will hold another 50 outdoor mesh access point 1552. Both controllers (not redundant) are at the HQ while the access points are distributed between HQ and 3 branches.
 
The requirements is to have the SAME 4 SSIDs on MESH and LAP each have a security type (, wep,wpa,dot1x...) on HQ and Branches. Now, in the HQ I don't think I will face a problem since the WLCs is on the same LAN, so 5 interface v lans will be configured one for the WLCs and access point and another 4 interface v lans for the 4 SSIDs.
 
Now, for the remote sites I need to create another vlan on the switch with DHCP and option 43 ..... for the access point to register with the controller.
 
But here, do I have to create another 4 interface v lans (4 different sub nets) that should be bidden to the SSID as in the HQ?

Or the Access point will encapsulate all the traffic including the client traffic? Note that I have outdoor mesh access point and Lightweight access point and the BW link between the HQ and branch is 100M.
 
Also Can I have roaming between the same SSID that broadcasted on MESH and LAP knowing that each have different controller.

View 3 Replies View Related

Cisco Wireless :: Redundacy - Controller 5508 Get Same Ip Addresses

May 8, 2013

[URL] I have one Controller 5508 is my Central Office and I have some Ap's working in local mode in my Central Office, additional I have more Ap's in a remote Office they're are working as H-REAP and I can handles across my WLC. Now my enterprise decided bouth another WLC and wants to deploy a active-passive scenario. This new Controller should manages all the AP's when the central WLC fails...

My questions are... I need to have the same ip addressing on both sites? or they can be different. I nedd to configure some on my Ap's that are working as local mode, for allow the secondary WLC manage them when mi central WLC fails

View 10 Replies View Related

Cisco Wireless :: 5508 Controller And Direct Connection

Feb 24, 2013

I received a 5508 WLC, that I wanted to configure as a guest anchor for our DMZ.  I stepped through the console configuration.  Now that the setup is complete, can I attach my laptop directly to the copper SFP, and access the WLC web portal?  I gave my laptop an IP address, in the same subnet, but still can't connect to the portal, or ping the WLC IP address. 

View 2 Replies View Related

Cisco :: 5508 - Upgrade WLC Wireless LAN Controller Version 6 To 7

Feb 28, 2013

I want to upgrade a 5508 WLC from version 6.0.196.0 to the most recent 7.4or 7.3  is it ok to skip so many versions, will this cause an issue?

View 9 Replies View Related

Cisco Wireless :: 5508 APs Joining Wrong Controller

Nov 5, 2012

We have 3 5508 WLCs  (A, B, & C) and several LAPs (1140, 3500, 3600). The APs learn the controllers IP addresses through DHCP Option 43.  When we setup a new site we put the IP address of the controller we want the AP to join first.  Lately, I've noticed that regardless of which WLC IP I put first when I setup Option 43 the LAPs are always joining a particular controller.

View 6 Replies View Related

Cisco Wireless :: Using LWAP With A 5508 Controller After AP Upgrade?

Aug 18, 2011

I have an AIR-AP1242AG-E-K9 which had c1240-k9w8-mx.124-21a.JA loaded, I followed the link below and upgraded with Cisco’s upgrade tool to c1240-rcvk9w8-mx with no problems at all, after the upgrade I could then see the LWAP on the 4402 controller and had it working a treat.Now the problems begin, I brought it into the office where we have 5508 controllers, plug in the LWAP into our management switch and boot it up I get an IP assigned from the DHCP server and the AP goes into discovery mode but never finds the controller.I have logged the boot process but this does not give much away, our other 1100 series AP’s boot fine,

[URL]
 
Console Boot Log.
Xmodem file system is available.
 flashfs[0]: 9 files, 3 directories
 flashfs[0]: 0 orphaned files, 0 orphaned directories
 flashfs[0]: Total bytes: 15998976

[code]....
 
And that is where she sits and does nothing more, I have noticed the DNS problems but the other 1100 series LWAP’s boot up after show that same issue.

View 2 Replies View Related

Cisco :: Wireless Controller 5508 Authentication To AD Server?

Sep 11, 2012

We just got a new 5508 wireless controller and the question we have is :  can we get wireless users to authenticate to an Active Directory server to get access to the network?  I know we can get the authentication done with an RSA server, but what about plain AD?

View 9 Replies View Related

Cisco Wireless :: How To Setup 5508 Series LAN Controller

Sep 23, 2010

how to setup the 5508 Series LAN wireless controller. The online documentation are not details. What different between Service Interface IP and  Management interface IP. The device IP is using what type service or management interface.

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved