Cisco :: Flex 7500 Supported RADIUS Servers?
Mar 29, 2012What is the maximum number of supported RADIUS servers on the Flex 7500 Cloud Controller?
View 2 RepliesWhat is the maximum number of supported RADIUS servers on the Flex 7500 Cloud Controller?
View 2 RepliesI am planning an HREAP deployment; a data centre with multiple remote sites. HREAP has been evaluated and meets our requirements. We are now looking at buying some equipment for this deployment. For controllers, we are considering either the 5508 or the new 7500. Other than cost, scalability and different hardware what are the differences between the platforms? So far I have found:AP's in local mode not supported on 7500, the 5508 supports AP's in local mode.The 7500 cannot be used as a guest anchor controller, the 5508 can.
View 3 Replies View RelatedJust want to know if it is possible to have a 7500 Flex Controller Cluster in different Locations, like Germany an Australia?
This should be deployed as a redundant system, in case of a failure in one location the remaining Cluster can take over. Also the main maintenance/management should be done in the Headquarter (Germany). Is it possible to configure Guest Access via Web Interface.
Last question: how many AP`s can be managed, example: with one Controller 500 AP can I then manage 1000 with two controller?
We use a Flex7500 with local switching and centeral authentication. My question is can i use the Customer's radius server in order to authenticate? or should my WLC have IP conncetivity to any radius server im adding?I guess what i'm really asking is should my WLC know the radius server or does the request can go back to the AP and from there to customer radius on his subnet?
View 6 Replies View RelatedI have RADIUS servers configured to authenticate administrative users and authorize them at a low level. This is working well. I also have a local level-15 user in case all of my RADIUS servers time out and someone needs to change something. This also works well. The issue I'm having is that a low-level user can log on using the RADIUS severs, then issue the "login" command and enter the local level-15 user's credentials and then operate at level 15.
I do not want the local account to work at all, except in the case that all RADIUS servers are unavailable. What I've described above works around this. How to disable the "login" command or force it to try RADIUS servers first? This is for ASA 8.2
I have 4 Cisco AP541N access points in a a cluster, and everything has been working great. We have been directed by our parent company to change our wireless to utilize RADIUS authentication with our wireless. I have been able to take an AP541N as a standalone (not clustered) and configure it to their standards, configure the 2 RADIUS servers they use with the RADIUS keys I was given for this access point, and everything works great with it. I was able to get them to setup their RADIUS server (which I have no access to) to allow authentication from the 3 other access points now, but they all have different RADIUS keys. I'm finding that when they are clustered they all seem to share the same RADIUS key, but I need them to have different ones.
So the question is, can I cluster 4 AP541N access points together, but allow each one to have it's own unique RADIUS key?
If not, then I think I'll either need to get the RADIUS admins to make them all the same key (which is not likely), or I'll have to uncluster them.
I have several controllers, including a 4402 running 6.0.188.0 software and I need to modify the Radius servers that it uses. Currently I have three servers listed;
1 - 10.246.194.16
2 - 10.200.31.78
3 - 10.247.50.56
I would like to delete server 1 which is being retired and replace it with a new server 1. I suspect, once i get servwe 1 deleted, the server 1 option would become available when I create a new server. I went into the controller and disabled server one, but every time I try and delete it, I get the "Server in use either on a specific WLAN or Mesh Radius Server Configuration" error. I can't find anywhere this server is still in service and being used, either by a WLAN or a Mesh. I've tried several different variances to modify this. What I hope to avoid is the need to reset the controller. I have a total of seven controllers that I need to make this modification to, and It will be ugly if I have to reboot these units. Hospital mission critical stuff.
I have a customer that wants to restrict SSIDs that groups get based on their AD credentials. Currently, he is using Windows 2008 Radius Server and AD with Cisco 5508 WLCs. I found examples that shows this is possible but my question is if I have 2 user groups (teachers and students) in AD and apply a policy for the Radius to send SSID x to teachers and SSID y to students. Upon successfully authentication, would this deny teachers access to SSID y and students access to SSID x?
View 10 Replies View RelatedI have to setup my first flex stack and wanted to make sure I do it right. I have the physical aspect of the stack down. From what I gathered I have to setup the master switch as the highest priority and then provision the other two switches. But I have configs on the other two switches, do I have to delete them? And do I have to setup individual ips for the two slave switches, because from what I saw the master switch is the only one with an ip address? The master switch is a poe 2960S-48LPS and the two other switches are 2960G-48TD
View 5 Replies View RelatedI had configured one access point CAP3602E in flex connect mode through a WLC 5508 after deploying the access point in flex control mode the local mac-filering is not working. before it was working when ap was in local mode. any body have to know is the mac-filtering working in flex-control mode ?
View 2 Replies View RelatedOne of my customer has an Apple IPAD 2.The IPAD is getting registerd through Cisco WLC 7.2.The APs that are being used is AP 1252 & AP 1242. The AP are configured in flex mode. The issue that we are facing is all the laptops and IPADs other then Apple IPAD are working but the Apple IPAD are not working through AES WPA2.It gives him a dismiss message and at time it gets connected but take a long time to get connected. Incase when the IPAD gets connected the following happens.
While connecting to the SSID it will ask for the preshared keyAfetr entering the preshared key it takes time to acquire an IP addressAfter the IP address is assigned it gives a dismiss message. If we do not click on the dismiss message then it will take anothere 30 seconds or so and get connected.
I have a wireless 5508 with license base to 50 aps, i use a deployment flex connect. I already registered all my access points, I use web authentication to authenticate users guest, and the service dhcp is in the central site.
My issue is the users in each remote site, can not get an ip address by dhcp from the central site, they can authenticate in the guest ssid, but any users can not get an ip. The request is passing by the wan in this way
Central Site DHCP - Router WAN - Remote Site - Users with notebooks. I use flex connect central deployment (all the traffic consulting to the wlc) .
perhaps i should use local deploy? The wireless is in the central site.
We are planning to implement Cisco wireless in our central office and branch office using Cisco 2504 WLC and Cisco 1602i Ap. Our branch office is connected via ip vpn and a separate broadband connection for urgent requirements. Usually all users are allowed to browse through central proxy server.I have been trying to find any possibility of giving guest access (web authentication) for branch office guests utilizing only the broadband connection which is connected to the branch office. Is there a possibility that Central WLC is reached using NAT from the BranchOffice AP and allowing guests to authenticate and surf the web at times IP VPN is unreachable.
View 4 Replies View RelatedI have one cisco wlc 2112 with ios 7.0.230.0 with license to support 12 access points. My access points are nine (9) lap1231ag and one (1) lap1310.I just have one wlan (ssid). My scenario of deployment is in layer 3. I have one interface management and ap manager in the WLC. All my Access Points have differents ip address that WLC. I need to configure a unique ssid to associate my six (6) dynamics interfaces (each dymanic interface with different vlan subnet).Each wlan profile (ssid) should have the same security in phase 2 (wpa2/psk). My cisco access points don't support hreap. My wlc support only (4) interface into an interface group, and i need six (6) dynamics interfaces.
View 6 Replies View RelatedI created a LAP Template in NCS to configure some new 1142 LAPs that were installed in a remote office. These LAPs need to be in Flex Connect mode with V LAN support. The template is being applied with partial success on every access point. Details of the partial success say the Flex Connect Parameters fail with the following error.
Provision Failure: { URL}.Object Not Found Exception cannot be cast to [URL]
Am I doing something wrong? The Flex Connect portion of the template has V LAN Support enabled, Native V LAN ID, and the Profile Name- V LAN Mappings configured.
Prime NCS version 1.1.1.24 Access Points are AIR-LAP1142N-A-K9s running 7.2.110.0
As per my understanding, Cisco Nexus 2232 can only connect to HP c7000 Chassis if we are using a Pass Through Switch in the HP c7000. Cisco Nexus 2232 can only connect to End Hosts and not to a switch. Is there a New Feature added in Nexus 2232, which enables it to connect to a Switch like HP Flex Fabric ?
View 1 Replies View RelatedWe are planning to split the Private servers from the DMZ Servers and configure an additional Interface and segment for this purpose.
Private Servers Segment: 192.168.4.0/24 (there is no DHCP all servers' IPs are statically configured)
DMZ Segment: 192.168.3.0/24 (This is a future deployment)
LAN Segment: 172.17.0.0/16
Both, Private Servers and DMZ Servers are in a collocation as well as the ASA5520. There are multiple Branch offices that uses subnets within the 172.17.0.0/16 Network and they are connected to the ASA5520 via Metro-E.
I do not know if this is possible but what I want to do is this:
In order to avoid the change of internal DNS records I want to mask the DMZ servers with a Private Server IP when a Private server or LAN host wants to access it like this:
The FTP server in the DMZ has the IP address: 192.168.3.100. But when a PC from the LAN wants to reach the FTP server it should points to its old IP: 192.168.4.100. This way the PC sends a packet to the ftp.corporate.net (192.168.4.100) the ASA recieves the packet and translate it to the (192.168.3.100) and send it out through the DMZ Interface.
Also if the Private Servers wants to reach the same FTP the ASA will act like a proxy-ARP and send the paquet to the DMZ by means of the translation of the IP.
I Have exented vlan 120,121 from DC-1 to DC-2,the DC-1 and DC-2 are connected using L2 Trunk over fiber terminated on Cisco 6513 on both site ,the distance around 40 Km ,on the DC-2 i just assigned server-1 TO VLAN 120 while server-2 in vlan 121 ,but these servers unable to communicate neither with DC-1 Servers or betwen them locally on DC-2 ,pls note that the servers at dc-2 rely on DC-1 for routing.
View 7 Replies View Relatedit seems there is no option for flexconnect registered AP's to work with external accounting server.I am using zeroshell server to authenticate with the radius server,which works perfectly!but there is no option under flexconnect security group to specify accounting server.is there a way to redierct AP to a local acoouting+authentication radius ?
View 5 Replies View RelatedAfter upgrading, ping times from clients has gone from ~10ms to ~2500ms. I have a Cisco 7500 Flex controller, when running controller code version 7.0.220.0 client performance was as expected. When using code 7.2.103.0 performance is terrible. I have tried upgrade to 7.2.103.0 and clean configuration (reset) with 7.2.103.0 with the same results.
I have tested using 3502i APs with the signal metrics (from AP) reported by the clients (all testing close to these figures):
Signal Strength : -48 dBm
Signal to Noise : 49 dB
AP's are in HREAP/Flex mode. The WLANs use HREAP/FlexConnect local switching. I have tested WLAN's with WPA2-PSK and 802.1x/WPA2 with the same results. I have tested several clientsoperatign systems , laptops, ipads, iphone. All experience consitent poor ping latency peformance on both 2.4Ghz and 5 Ghz when using controller code 7.2.103.0.
I have switched between 7.0.220.0 and 7.2.103.0 several times and the results are consistent; good performance on 7.0.220.0 and terrible performance on 7.2.103.0. I would like to use 7.2.103.0 for its enhanced FlexConnect features but this is a real show stopper.
i have a westell 6110 that i want to upgrade to westell 7500; how to do this ?
View 1 Replies View RelatedHow do I open my NAT on my westell 7500
View 3 Replies View RelatedI have a Cisco Flex 7500 in my datacenter and I need to connect 100 sites , each site with 2-3 APs , each side has its own network and is independent of other sites , the site only need to comunity locally and do not need to access any centralized applications.
I am trying to achieve this by Creating 100 different AP groups and assiging 2-3 AP in each groups for each branch, I will achieve WAN failover resiliency by creating flexconnect groug , the issue I am facing are as below .
1.Since all the sites has same setup , the AP and clients on all sites are in vlan 2 , so when I try to create 2 or more AP group with same vlan, it restricts me of doing so , I cannot create diffrent AP groups mapped to same Vlan .
2.If I keep the APs and Clients in the same subnet , I dont think it should be a problem , but I need your second opinion.
to give you an even better picture , look at the topology enclosed , and my question is if both STAFF and STUDENT APs are in same vlan but in 2 different broadcast domain , how would I create the AP groups.
i'm trying to connect 5 servers together to create a private network.Each server has a network of it's own and i'm trying to make all 5 servers communicate with each other to share and search data simultaneously..
View 16 Replies View RelatedI have been running routers and port forwarding for like the last 8 years and I am absolutely stumped why this router will not do it.I have a host/remote app where the remote accesses the host on port 7777 but it will not work even after adding that in the router admin.I also set the firewall to allow everything to make sure it is not part of the problem.
View 13 Replies View RelatedAny issues connecting a DIR-645 router to a Westell 7500 router? I can connect a WRT54G router to the Westel; using 2 different SSIDs and 2 different channels and all is well, but I'm ready to just throw out this POS DIR-645. Not sure why/who gave it all these 'rave reviews'! Documentation is horrible and D-LInk is hopeless.
View 8 Replies View Relatednew 7500 asks for password but won't take password from Verizon
View 1 Replies View RelatedI am trying to navigate to the port forwarding page but cannot get to it. Some admin pages on this load and others do not, unless you click them about 15 times.
Here is the page I am trying to get on it now. [URL] And all i get is a blank page on the browser.
My westell 7500 my be on the same freq. as my microwave because every time that I turn on the microwave my speakers go out or make all kinds of noise
View 2 Replies View RelatedTried E2 port IP 192.168.1.1 unable to connect what am I doing wrong. Petro-stuff
View 1 Replies View RelatedWe have an existing RVS4000 that has been coexisting peacefully with an ISP managed Netopia 2241N. That configuration has worked fine for over a year.The company is switching to using Verizon DSL instead. Verizon sent a Westell Model 7500 router. The router works fine with a standalone PC but, in none of the modes can I get internet connectivity through the Westell to the RVS4000. I can't ping the gateway or the DNS addresses and there is zero activity. I've tried the default "routed bridge" settings on the modem as well as the "bridge" settings. I can only get these working directly on a PC but as soon as I put the RVS4000 in between nothing seems to be getting through. I've tried turning off all Firewall features in both devices but hasn't worked.
There is a single, static IP. What specific modes and settings should be in the RVS4000 to communicate with the Westell Model 7500 in "bridge" mode?What adjustments should be made to the Westell to pass along the necessary ports that will be needed?Even though it is a business account, Verizon refuses any assistance beyond getting the unit functioning with a single computer and, if requested, setting their Westell to "bridge" mode.
I have a cable modem but need to hook up 2-3 computers. I cant get internet through my d link router, but can still use it for home networking. I tried getiing into the d link with 192.168.2.1 but failed...resetting does nothing. I also have a westell 7500 dsl modem/router but it also fails to supply any comp with internet, although only my xp comp can access it. I can not get into the routers. Resetting does nothing.
View 11 Replies View RelatedI have a Westell 7500 wireless modem that I would like to bridge to my Dlink DIR-628.
View 1 Replies View Related