Cisco Firewall :: To Set Up The Network And Configure 2504

Oct 2, 2011

I am new in networking. All my knowledge is based on books and no real life experience.At my job I am required to set up the network and configure all apparatus I never worked,before with.We have regular cable internet in the office. Modem is connected to Apple router (time capsule). No trouble. Now we are getting fibre optic in the office. Mngmnt has abought the following Cisco:

Cisco Wireless Controller 2504
Cisco 3501 AP 802.11g/n Ctrlr based AP
Cisco  ASA 5510 Firewall appliance
Cisco Power Injector AP3500 Series

View 1 Replies


ADVERTISEMENT

Cisco Wireless :: Configure A Wired Guest Network With A Combination Of 5508 And 2504 Wireless Controllers?

Apr 7, 2013

Is there any way to configure a wired guest network with a combination of 5508 and 2504 wireless controllers? I am aware that the 2504 does not have wired guest functionality, however is it possible to set up a wired guest on the 5508 and using mobility anchors, transmit the l2 information through eoip to communicate with the remote vlan?Home built NAC solution, using 802.1x authentication on switchports for public areas. If user is an employee, communicates with the supplicant on their machine, and places them on an internal vlan.If user is a guest, user fails 802.1x check and is placed on a "guest" vlan with an ACL and external DNS.If placed on the guest vlan, the user has to accept a terms of use form.This is working currently with our 5508s without any issue, however we have some remote offices we'd like to roll this out to that are using 2504 controllers. I'm hoping there's a way that I can use the 5508 as an anchor or vice versa to make this work.

View 1 Replies View Related

Cisco Wireless :: Configure 2 SSID With WLC 2504 And LAP 1042n?

Nov 3, 2012

It,a possible configure 2 ssid with wlc 2504 and lap 1042n? It,s possible configure 2 ssid with support 802.11n?

View 1 Replies View Related

Cisco Wireless :: Configure Ports And Interfaces On WLC 2504

Oct 26, 2012

I have WLC 2504 controller and six access points AIR-LAP1042N. I reading Cisco 2500 Series Wireless Controller Deployment Guide url...trying to set up along the lines.
 
It is also possible to have multiple AP-managers in a different subnet than the management interface. However, in this case, it is recommended that you disable the AP-manager from the management interface and create another AP-manager interface on different physical ports in a different subnet than the management interface. All multiple AP-managers in this scenario should be in the same subnet.

I maping management interface on physical port 1 and disabled ap-manager on it. Set up 192.168.7.0 subnet with non tagged vlan. This iface/port I want to use only for access to WLC web-interface. Then I create dynamic interface ‘dynamic1’, map him on port 2, enable ap-manager on him, and set up 192.168.110.0 subnet with vlan 10. Then I tryed map wlan1 to this iface, but I can’t because in the choice was only management iface to map wlan1.
 
There is three dynamic interfaces on same subnet and vlan, in example above. But when I try to add dynamic iface with the same vlan/subnet as an existing dynamic interface, I get an error, and can’t adding.

View 5 Replies View Related

Cisco Wireless :: 2504 -configure MAC Authentication With Certificate Based

Jan 8, 2013

I have cisco 2504 WLAN controller with 7.4 IOS. My query is can I configure the MAC authentication with certificate based. And without using any external servers like Radius, ACS and LDAP.
 
May I know, If there is a option on WLC…

View 4 Replies View Related

Cisco :: 2504 Configure Rogue Detector AP And Trunk Port?

Dec 14, 2012

I'm using a 2504 controller.  I dont have WCS.My questions are about the best way to configure a Rogue Detector AP.
 
In my lab environment I setup the WLC with 2 APs.  One AP was in local mode, and I put the other in Rogue Detector mode.The Rogue Detector AP was connected to a trunk port on my switch.  But the AP needed to get its IP address from the DHCP server running on the WLC.  So I set the native vlan of the trunk port to be the vlan on which the WLC management interface resides.  If the trunk port was not configured with a native vlan, the AP couldn't get an address through DHCP, nor could the AP communicate with the WLC.  This makes sense because untagged traffic on the trunk port will be delivered to the native vlan.  So I take it that the AP doesn't know how to tag frames.Everything looked like it was working ok.
 
So I connected an autonomous AP (to be used as the rogue), and associated a wireless client to it.  Sure enough it showed up on the WLC as a rogue AP, but it didn't say that it was connected on the wire.  From the rogue client I was able to successfully ping the management interface of the WLC.
But the WLC never actually reported the rogue AP as being connected to the wired network.So my questions are:
 
1. What is the correct configuration for the trunk port?  Should it not be configured with a native vlan?  If not, then I'm assuming the rogue detector AP will have to have a static IP address defined, and it would have to be told which vlan it's supposed to use to communicate with the WLC.
 
2.  Assuming there is a rogue client associated with the rogue AP, how long should it reasonably take before it is determined that the rogue AP is connected to the wired network?  I know this depends on if the rogue client is actually generating traffic, but in my lab environment I had the rogue client pinging the management interface of the WLC and still wasn't being picked up as an on-the-wire rogue.

View 4 Replies View Related

Cisco Wireless :: Configure Multiple SSID On Aironet 3600i AP Via 2504 Controller

Apr 3, 2012

Can I configure Multiple SSID (Guest/Corporative) on Cisco Aironet 3600i AP via Cisco 2504 Wireless controller?

View 1 Replies View Related

Cisco Firewall :: ASA 5505 - Configure Communication From Inside Network To DMZ

Nov 30, 2011

ASA 5505 and DMZ, I have a Base License.
 
What do I need to do for access inside network to DMZ?
 
I successfully configure, internet Access for DZM and inside network, web server can be accessed from internet, but I have problem to configure communication from inside network to DMZ.

View 14 Replies View Related

Cisco Wireless :: Two WLC 2504 In Same Network?

Aug 15, 2012

I have two WLC 2504 controllers. These controllers are for two different buildings. But they share a VLAN, and network address range. How can I control the access points to the register selected only at a specific controller.
 
Example:
 
AP 1 -> WLC 1
AP 2 -> WLC 2
AP 3 -> WLC 1
 
Since the buildings also broadcast in different SSID. The two controllers are in a mobility group.

View 4 Replies View Related

Cisco :: 2504 Upgrading / Growing Our Wi-Fi Network

Sep 5, 2012

We are planning for a modest expansion of our wifi network.  Here is what we currently have, and what we are doing:
 
-2 1100 B/G AP's; a "primary" and a repeater.  Both have a single SSID. 
 
-1 1142 B/G/N; autonomous, with a different SSID
 
What we would like to do:
 
-Purchase a 2504 WLC and two more AP.  Looking at a 3602 simply for future growth, but are not sold on the idea of such an AP.  Would consider two more 1142.  At any rate, we are looking for two more AP. 
 
-Still keep our current AP's in use.

-Is a 5 access point wifi network, all controlled by a 2504 feasible?
 
-Will our existing investment of older 1100's and the single 1142 play nice with eiither a pair of 3600 (or 3500 or even 1142)?
 
-Can we go to a single SSID using all of this equipment, and clients connect at whatever speed is possible with whatever AP they are joined with?

View 10 Replies View Related

Cisco :: 2504 WLC On Edge Network For Guest Wi-Fi?

Jan 21, 2013

I have a 2504 WLC with a 1042 AP and I have it placed on my edge Cisco 3750 switch. I have the management interface of the WLC set on my WAN IP 71.x.x.x subnet range, and I have the WLC doing DHCP duties with a DHCP scope of 192.168.X.0. I have my DNS servers set on external DNS servers out on the Internet.I have two Cisco 3845 Routers on my edge network - one for each ISP with BGP protocol.
 
Since my native VLAN is 71.x.x.x, I added a sub interface on my main core router and gave it a 192.168.x.1 255.255.255.0 address for the gateway. Also, I added ip prefix-list iBGP seq 10 permit 192.168.x.0/24 le 32 to my main core router. On my secondary ISP router I added ip prefix-list iBGP seq 10 permit 192.168.X.0/24 le 32, and ip prefix-list OUT seq 10 permit 192.168.x.0/24 statements.
 
I added VLAN 10 to my edge switch and gave it IP 192.168.x.2 255.255.255.0, and the switchports that my core router and my WLC are connected to the edge switch, are in trunk mode with encapsulation dot1q 10. The switchport on my edge switch that the AP is connected to is in switchport access mode.
 
I can connect to the wifi with a 192.168.x.x IP address on my laptop, but I cannot get any Internet access. Is it possible to have the DHCP scope be in a different subnet than my WAN IP subnet, and allow guests to get to the external Internet only? Do I need to put the WLC somewhere internal on my network i.e. the DMZ and then tunnel the traffic out to the Internet with no Internal network access?

View 5 Replies View Related

Cisco :: ACS 5.3 And WLC 2504 Configuration With Restricted Network Access?

May 29, 2013

i must configure a secured wireless network with access restriction based on SSID. the equipements are : cisco wlc 2504 (soft 7.3) cisco secure acs aplliance 1121 (soft 5.4) . the users that will connect to the network are regrouped by identity groups, each identity group having it's own SSID. Clearly each group of users must access only one SSID. i followed the procedure below to configure it:

-- creating user identity groups;

-- creating users and assigning them to the groups;

--- creating authorization profiles for each SSID under policy element/ authorization and permission/network access/authorization profiles and putting the Airespace-Wlan-Id(the SSID number) in the radius tab.

--- assigning the authorization profiles to the identity groups under access policies.

after all these config the users can access the network using there userid/password configured. But the problem is Every user can access every SSID, seems like the restriction is so not very well configured.

i found some documentation on this kind of config but the version of ACS used seems older than the one that i use, so menu are very different.

View 8 Replies View Related

Cisco Wireless :: 2504 Controller - Best Way To Have Internet Only Wi-Fi Network

Nov 29, 2012

Our current way of configuration for this is standalone ap's with multiple ssid's. The main network ssid's are on the 10.0.0.0 networks. The internet only ssid is on the 192.168.1.0 network. ( this is a wireless network only,no wired) They all get there dhcp address from a layer 3 switch. To prevent the wireless 192.168.1.0 intenet only network from getting to the 10.0.0.0 networks, we just put a simple source & destination deny acl on the in vlan interface of the 192.168.1.0 network on the layer 3 switch.Now that we are impementing a Cisco 2504 controller, the management and ap manger are both on the 10.0.0.0 network.( both on port 1 with dynamic ap manager enabled)  I can setup as many ssid's on the 10.0.0.0 network and they all work fine. But when I setup the 192.168.1.0 internet only ssid it will not connect. I'm assuming that its because the 192.168.1.0 network or anyone trying to connect and use that network has to go through the controller located on the 10.0.0.0 network. I'm thinking that the acl on the vlan interafce is the problem.So, if I'm correct, what is the best way to setup a separate internet only network through the private networks?

View 7 Replies View Related

Cisco Wireless :: 2504 - Network Computers Not Showing Up

Jun 16, 2013

Cisco 2504 wlc, 1142n ap, windows radius server.
 
When I click on Network, the only computer that shows up is mine. If I am hardwired then everything shows up (Servers, other workstations). Is this a problem with the radius server or something on the controller?

View 2 Replies View Related

Cisco :: 2504 WLC / 1142 APs - Guest And Secure Network

Nov 19, 2012

I have a 2504 WLC and x6 1142 AP's and currently have this working on our corporate network (still in test phase). So far so good and looking at authentication via radius next for this.
 
We have a separate ADSL connection that is external to the corporate network and what i would like to do is based on SSID (in this case i'll use "Guest Access") i would like any clients etc that visit to be able to connect to our wireless but not be able to connect to our corporate network.

View 4 Replies View Related

Cisco Wireless :: 2504 - Guest Network Completely Isolated From LAN

Jan 28, 2013

I recently got my Cisco wireless system working a few days ago and am back with a guest network. Our wireless system includes one 2504 controller and 2 2602i access points. So, I want a wireless guest network completely isolated from the LAN.
 
Here is what I have done.
 
I have created a new internal network and assigned 192.168.2.1 to an unused port on the firewall and 2.2 to a new controller interface with vlan 10.  I can ping both 2.1 and 2.2 from the firewall and the controller.  Basic network connectivity is working.  The DHCP server is setup on this same firewall and configured only for this port.  This address is referenced in the controllers interface.
 
A new w lan was setup and enabled.  The proper interface group was selected on the w lan.  I have left the default layer2 security.
 
As far as AAA servers tab in this wlan, this is where I am a little confused.  I wish to just have a single log in for this guest network.  I wasn't sure what to do so I went over to the Security tab and created a "local net users" account.  I do not know how to reference the use of this under wlan, security, aaa servers.  Should I check the box that says "local eap authentication"??  If so, I don't have a profile name in the drop down.  What I'm looking for is the username/password to be stored locally on the controller itself since there will be only 1 account.
 
Under wlan, advanced tab, I do not have "Allow AAA override" checked.  Should I?
 
Lastly, when I try to connect the client, it is not pulling a dhcp address.  I wasn't sure if authentication was required before dhcp or the other way around so I'm not sure what to trouble shoot first, authentication or dhcp.

View 8 Replies View Related

Cisco Wireless :: WLC 2504 / Apple Devices Dropping Off Wi-Fi Network?

Jul 25, 2012

I have recently deployed a wireless network using a WLC 2504 with 21 Light APs. All seems fine except that Apple Devices drop their connections every 15 minutes or so. A couple of minutes later they can reconnect but obviously something is wrong.

View 2 Replies View Related

Cisco Firewall :: How To Configure Firewall Access For ASA 5510

Nov 4, 2012

This is my first time to use the Cisco ASA 5500 family. I have a request from a user to create an access rule, to allow all LAN traffic to Destination IP address 165.241.29.17, 165.241.31.254 with Destination TCP port 5060,5061,5070 and UDP port 50000-52399.

View 9 Replies View Related

Cisco WAN :: 1841 WIC To Configure BRI Interface In Network Protocol Emulate Network

Apr 5, 2011

I'm trying to configure my BRI interface in "network protocol-emulate network" and "layer1-emulate network" but i don't have this second command.Is someone have allready to that with this type of interface ?I've to configure this because the ISDN line of my telco is in user mode only.

View 5 Replies View Related

Cisco Firewall :: How To Configure PBR For ASA 8.4

Aug 12, 2012

We heard that ASA ver 8.4 has PBR. Do we have some guidelines on how to configure PBR for ASA and can it do routing based on URL?

View 2 Replies View Related

Cisco Firewall :: How To Configure ASA Failover For 8.4

Nov 23, 2011

How to configure ASA failover for 8.4.

View 1 Replies View Related

Cisco Firewall :: How To Configure ASA 5510

Sep 11, 2011

I'm having a problem configuring an ASA 5510.  A previous employee started the config and left abruptly. He established a VPN Tunnel between two of our sites and that's working without an issue.  The problem is, the network behind the 5510 at the remote location cannot access the internet. 

ASA Version 8.2(1)
!
hostname PH-Firewall
domain-name pleasehelpme.com
enable password HXrQty4kqW8s8yeE encrypted
passwd ucA.qrYJWD9UyIFz encrypted
names

[code]....

View 12 Replies View Related

Cisco Firewall :: Configure Dmz On ASA5505

Dec 20, 2011

I have a asa 5505 Sec plus with 3vlan, inside, outside and dmz.
 
On the outside i have 5 ip's for my use, and in the dmz i have a webserver that need to communicate with one sql server on the inside.
 
The "sql" also needs to be accessible from outside and thus has a static nat with a dynamic nat so it replies from same ip as on nat ie 72.72.72.5 webserver is natted with 72.72.72.6
 
sql inside ip is 192.168.1.2, gw 192.168.1.1
webserver ip is 192.168.2.100 gw 192.168.2.1 
sec lvl on inside is 100 and on dmz 50
 
with a dynamic policy  running inside-net/24 to dmz-network/24 translagt to dmz 192.168.2.2 i can get it to ping 1 way from inside to dmz, but not the other way around...
 
All i need is to open 1 port  ie 6677 both ways for this communication to work.
 
I'm not very familiar with the CLI and do most stuf in GUI  (know i should learn CLI, but time doesnt let me)...

on access rules i have just added everything from any to any using , ip, icmp, tcp and udp just to be sure...  :-)

View 47 Replies View Related

Cisco Firewall :: Configure DMZ On ASA 5510

Mar 3, 2013

I am confiuging a DMZ on my ASA 5510 but I have run out of physical ports, since I have dual Wan ports configured.  I plan to implement a DMZ using subinterfaces.  I have 2 questions:
 
1) Do I need to configure a Vlan to complete this task?

2) Do I need to re-configure the other interfaces for subinterfaces and/or vlans as well?

View 4 Replies View Related

Cisco Firewall :: How To Configure PAT On ASA 5545x

Nov 15, 2012

Do you know how to configure PAT on Cisco ASA 5545x?

View 2 Replies View Related

Cisco Firewall :: ASA 5520 - Configure QoS

Mar 10, 2011

We have Cisco ASA 5520 firewall. ASA Version - 8.0(4). ASDM Version - 6.1(3). Firewall Mode - Routed.
 
We want to configure QoS for some subnets and enable policing such that they cannot use more than 1mb of bandwidth. I think we cannot create more than 1 policy for it. In that case i created a policy with QoS enabled and configured the Input and Output policing with Commited Rate of 1024000 bits/second. But it does not seem to work.
 
how can i create such policy in the ASA to limit certain subnets to 1mb bandwidth ?

View 1 Replies View Related

Cisco Firewall :: How To Configure ASA 5510 8.2(1)

Jul 25, 2011

I'm trying to configure an asa 5510 8.2(1)?I have a range of pub ips 3*.108.234.145-150
 
>>> E0/0  3*.108.234.146 outside public     
>>> E0/1  192.168.1.1  inside       
>>> E0/2  192.168.3.1  dmz          
 
would like to map dmz host 192.168.3.107 to external 3*.108.234.147 on port 5000 and 50001 LOCAL LAN should also be able to get to dmz host ports.i've tried a few configs and also following this example:
 
[URL]
 
without any luck, here is my config, also posted the out put of show arp which is able to see and ping the host on dmz, also the output of show access-list which shows hits to it.
  
prophase-pix(config-if)# show running-config
: Saved
:
ASA Version 8.2(1)
!
hostname prophase-pix
enable password  encrypted

[code]....

View 2 Replies View Related

Cisco Firewall :: Configure ASA 5520 With 2 ISP?

Mar 18, 2012

i'm trying to configure an ASA with two ISP to be reached from internet for vpn access, the objective is that the user can use any of the Public address attached to ASA to connect to the company. Is this possible? i'm facing some problems because i can not use two different default routes (same AD) pointing to two different interfaces, this is the message that i receive "ERROR: Cannot add route entry, possible conflict with existing routes" and when i change the AD of one of the default routes i just can reach one ISP.

View 1 Replies View Related

Windows XP Pro - How To Configure AVG Firewall

Aug 30, 2012

I'm using windows XP Pro , in a local Lan, internet connection through a DHCP, and System software on IP 192.168.0.254. I'm the Admin of my PC, I just want to use the Internet and the System program. I want to block any user from accessing my PC or viewing my Processes by other programs like (Ideal Admin.). How to configure the AVG Firewall to do that ??

View 11 Replies View Related

Cisco :: Configure 1841 Router And Firewall?

Feb 11, 2013

Configuring Cisco 1841 router and firewall.My provider has put their equipment and given me 2 subnets with public ip address. I am used to getting just one Subnet and connecting my firewall straight to the hand off. But in this case I am a bit confused. I assume I will need to put a router and configure it with before I connect my firewall. [code] I also have a firewall that I would like to be on the subnet 2 at 200.xxx.97.130 and have my private network 192.168.xxx.xxx behind it.

View 2 Replies View Related

Cisco Firewall :: Pix 515E Could Configure The Device

Oct 2, 2012

We just switched over from a T1 line to 50/4 Mbps cable Internet.  The speed was fine with the T1, but when we switched over to cable, the  download speeds didn't increase.  I'm getting 2-3 Mbps up and still only 1.5 Mbps down.  I inherited this network a few years ago, so I didn't configure the Pix initially but I have been managing it and can't find a setting limiting the bandwidth for the liffe of me.  I know it's not the Internet because when I connect a computer straight to the modem, the speed is great.  As soon as I put it through the Pix though, it slows way down. 

View 8 Replies View Related

Cisco Firewall :: Configure The ASA5510 In HA Mode?

Jun 4, 2012

configure the firewall Cisco ASA5510 in HA Mode.Enclosed Network diagram.

View 14 Replies View Related

Cisco Firewall :: Configure Dual ISP On 5505 8.4

Mar 27, 2013

I am attempting to set up failover dual ISP on a 5505 running 8.4(4) with the Sec Plus  license. Everything i have been able to reference so far, points to old commands not available or relevant in 8.4
 
For instance:
 
global (backup) 1 interface
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0
route outside 0.0.0.0 0.0.0.0 20.20.20.1 1
route backup 0.0.0.0 0.0.0.0 30.30.30.1 10
 
What is the new syntax that should be used to mimic these commands?  I have the sla and trach reachability configuration already set up.

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved