Cisco :: How To Configure 1131 AP To Use WPA2 Enterprise
May 2, 2012I have a Win2008 server set up as a radius server (192.168.32.71) and a stand alone AP (192.168.201.9) [code]
View 3 RepliesI have a Win2008 server set up as a radius server (192.168.32.71) and a stand alone AP (192.168.201.9) [code]
View 3 RepliesI, at work, have recently deployed a very small stub network in Papua New Guinea, an office that has no more than 7/8 users. This simple network consists of:
1 x 2611xm Router
1 x 2960 24port Catalyst Switch
1 x 1131ag AP
[Code].....
Not sure if this belongs here on in a different section. We are in the process of purchasing a new ACS 5.x appliance. I would like to take a look at implementing WPA2 Enterprise with our Cisco APs.
View 4 Replies View RelatedRecently bought a laptop HP Pavilion DM4 with Windows 7 home premium 64 bit for use in a college wireless environment. The school insists on WPA2 Enterprise connection, which is supposedly the recommended Microsoft security protocol for Win 7. I have all the correct settings, such that I can routinely connect to the wireless network but on this model HP I consistently get speeds way under 10kbs, while if I use EXACT same settings on a different Lenovo, Dell, or other models of HP get speeds of over 5MG. Yes 500x faster.Of course HP wanted to blame the network, but after sending 2 technicians to visit on campus, they agreed it was their hardware, so they sent a replacement unit. Unfortunately, the replacement unit has the EXACT same problem. BTW the problem computers do connect flawlessly to other wifi networks at full speed, just not the WPA2 Enterprise network.
View 1 Replies View RelatedSo I have been tasked with setting up WPA2-Enterprise on the network. Right now for testing I have a single Cisco 1240AP, and a test Windows Domain. The Windows domain is at 2003 functional level, but has been extended to have the Wireless policies, and we have a 2008 DC in the test network also.
Is there any definitive guide to setting up a WPA2-Enterprise wireless network? Most of what I find is mostly client side. I am trying to get the Group Policy setup to push down to the client machines.
We have 3 x WAP4410N at new office setup in Singapore. Customer asked us to setup those 3 AP to make client auth against an ACS 4.2 sitting in US office. All the user notebooks were joined to Windows domain in US office, before sent out to Singapore office. We configured APs with WPA2 Enterprise Mixed mode and entered radius server address and secrects correctly. Logging from ACS shows that users are authenticated successfully but, on the user notebooks, authentication never seems successful and keeps authenticating.
View 10 Replies View RelatedWe have a WAP4410N wireless ap configured for WPA2-Enterprise. Initially everything works. Issue the user the proper certificate and they sign on correctly but once they disconnect and try to reconnect later it get stuck on "Validating Identity". The request never get to RADIUS server (no success/failure log entry, no radius traffic). Once I reboot the access point everyone can connect again but as soon as they disconnect the problem happen again.We testing other security settings (WPA-ENT, RADIUS(!), WPA2-Personal etc) and no problems. With older firmware have the same issue.Operating system: XP SP3, RADIUS server: IAS. Firmware: 2.0.1.0
View 2 Replies View RelatedI have a WLC 2106 with two AP's connected, But have not set up any authentication. I don't have CSACS at my disposal, so I thought I would try FreeRadius on my Linux Server. I am looking for User/Password auth, and for now I would expect to have those accounts local to the FreeRadius engine. (baby steps before I try PAM/LDAP/AD/Certs )
I have seen a number of posts asking final step questions. I was looking for more of a where to begin How To.
I have read the docs on Free Radius, and believe I have the method worked out on how to make a small change, run in debug mod to observe my change, to verify that I don't spend too much time pulling out my hair. I am fairly adept at CSACS 5.3 but it hides the magic of Radius from me.
I have here a couple of APs with c1130-k9w7-mx.124-25d.JA1 loaded as firmware.
I want to configure them with 2 SSID: 1 encrypted, 1 public. Each should go to its own vlan, and thus should have a trunk towards the switch.
My wireless experience approaches zero however, and I cannot get the APs to even send out an unencrypted public SSID.
The config that is currently on the AP, after trying a lot of things is:
gibbs#show run
Building configuration...
Current configuration : 3272 bytes
!
version 12.4
[Code].....
configure WPA2 on a 1041 access point? I am trying to get it configured through the GUI and part way through I keep getting locked out of the AP due to WPA2 being partially configured..
View 1 Replies View RelatedI need to configure WPA or WPA2 authentication on cisco 1042N access points. But I believe that for this requirement I need to have either an internal or external RADIUS server, but my customer want to just a normal WPA/WPA2 authentication like what we configure on cisco WAP200 or WAP4410 accesspoints, is there any work arounds to configure WPA/WPA2 authentication in a simpler manner rather than configuring RADIUS server option?
View 2 Replies View RelatedI have the 1131 hardware manual and it is stating that this is caused by a boot loader issue or the AP did not get the IOS file from the controller. We have a Cisco 4404 controller that this AP reports to. It was one out of 30 and after a reboot it is working fine. What can i do in the future to catch this and prevent this from happening.
View 1 Replies View RelatedI have WLC 520 with software version 5.2.178. Currently we purchased Cisco AIR-LAP1131G access points and tried to join to WLC 520 but it is not joining. My question is WLC 520 will support 1131G access pont or not.?
View 1 Replies View RelatedI'm used to seeing DWDM and muxes being used in the service provider world, but when and why would an enterprise want to use this kind of gear?The two basically lets you combine streams of signaling from many different physical sources into one media, but can't a VLAN trunk or a routed link, for example, do the same? Sure, they all operate at different layers of the OSI model, but in all cases you're still getting separate streams of data from Point A, putting it all on one wire, and sending it to Point B.
View 8 Replies View RelatedI have several APs directly connected to a Cisco 3560 and each port is configured this way....
interface FastEthernet0/1
description Uplink To Access Point
switchport trunk encapsulation dot1q
[Code].....
The switch shows the AP under sho cdp niegh but when I go to the controller and look at AP neigh nothing shows up. I am currently running a WLC 4404 with 4.2.209 ( yes the upgrade happens tomorrow ).
why the switch shows the neigh. but not the AP when looking from the controller?
I have converted ap 1131 from autonomous to lwapp successfully by using upgrade utility tool but the AP does not join the WLC 2106. I can see it as a neighbor on the switch with no IP address.
View 19 Replies View RelatedCan I change the untagged vlan on a 1131 to a new vlan. I need to move my management vlan from 10.1.1.1 on vlan 1 , to 172.16.0.1 on vlan 200. I attempted several configuration options including removing the vlan1 ip, changing my new vlan200 to untagged and mirroring it on the switch, and adding my new ip to vlan 1 untagged and then untagging the switch with access vlan 200 on the connected port. Nothing worked.
Below is a sample of what I changed:
interface Dot11Radio1
no ip address
no ip route-cache
[Code]....
We're in the process of upgrading our Wireless AP's from autonomus to LWAP. We're doing the upgrades remotely (we have 100's of sites to do, and it's not possible to be there to console on to each one), using a local computer to upgrade them to LWAP's with the Cisco Upgrade Tool.Having some inconsistent bugs pop up though from time to time.The most common one is that it basically buggers up the IP address after applying the recovery firmware image. It's supposed to keep the IP it had according to the IPFile.txt (for example 172.25.25.4), but it does something very weird... it keeps the last two octets (so 25.4 from the e.g) but replaces the first two octets with a 192.168 address. So the final address in this example after the UpgradeTool has done its work, is 192.168.25.4 - which is compeltely wrong.
This causes it to be unable to talk to the WLC (obviously, with bogus IP information it will struggle), and gives us big problems in that it wont ever come up unless someone can console to the AP and fix it. We can usually resolve the issue by munging about on the switch - switching the port it's connected to between access and trunk and doing some shut/noshut cycles seems to do the trick mostly.
I recently had to deploy about 4 cisco 1131 AP's to one of our branch location. When configuring them on the controller, i needed to put them in HREAP mode. As soon as i do that and the AP needs to reboot, it will continue to reboot in a loop and indicate the following:
Unexpected exception to CPUvector 1100, PC = 5A9048
-Traceback= 0x5A9048 0x48A8A0 0x4361FC 0x42E078 0x44880C 0x42A280 0x42AA68 0x18A990
[Code]......
I've ran into an issue that I haven't seen before. A client of mine has a WLC that manages AP's at several different sites on the East Coast. They are all connected via a multilinked T1x2 connection. One site in particular contains 7 AP's, and users at this site are unable to connect. The remaining sites have no issue at all connecting. I noticed that when users began reporting this that all AP's had failed interference profiles. Also, when I instruct a user to attempt a connection, I don't ever see their mac address come across a debug session on the controller, which I find odd. Is it possible that a neighboring business is sending deauth packets and containing my AP's?
The client is running code version 4.2.61.0.
I have WLC 4402 with software IOS 5.2.157.0 and i am planing to upgrade the sofware to the latest one (7.0.235.0)
now my question are :
1 - is that software version will support APs [AIR LAP 1131 AG-E-K] ?
2- on down load page there 2 files :
a) Cisco Unified Wireless Network Controller Boot Software 7.0 for Cisco 4400 Series Wireless LAN Controllers.
b) Cisco Unified Wireless Network Software Release 7.0 for Cisco 4400 Series Wireless LAN Controllers. which file i need to upload on my WLC 4402
I have an AP(1131) that keeps disassociating from the controller. It stays alive for about 10 mins then it doens't work anymore. I tired changing the AP but that didn't make a difference. I also tried changing the port on your 500 POE switch. My last effort to fix it was to put the AP on a 3550 switch with a power injector. Still no luck.
I don't understand why its doing this. I am able to connected to it and surf the internet for about 10 mins. After that It leaves the controller and just cycles through different colors.
I have some questions about this AP and it's IOS. I have some AP's 1131 and they have IOS 12.34(3g) JA I'm working with a 4402 WLC I'm going to change this WLC for one 5508 but this WLC has a different version software it has 7.2.103. My questions is I need to do any upgrade to my AP's IOS for join to the new WLC ?
I found a compatibility Matrix, in this document I guess i nedd to do some upgrade: URLs
The WGB can be any autonomous access point that supports the workgroup bridge mode and is running Cisco IOS Release 12.4(3g)JA or later releases (on 32-MB access points) or Cisco IOS Release 12.3(8)JEB or later releases (on 16-MB access points). These access points include the AP1120, AP1121, AP1130, AP1231, AP1240, and AP1310. Cisco IOS releases prior to 12.4(3g)JA and 12.3(8)JEB are not supported.
I have one Flex WLC 7510 using software version 7.0.220, And all APs are 1131.
I have some sites with H-Reap, where H-Reap is configured properly.
The Access Points are set with AP Group. AP Group is configured properly too.
Each AP Group was configured for one site, and they was configured with 2 SSIDs. All sites has 2 differents SSIDs. During some basic tests, in one site with 9 APs, I saw:
1. When the Access Points are registred on WLC, all APs are working fine. All APs has your 2 SSID added on slot 0 (radio 0)
2. If I disable the link between WLC and Access Points, 7 access points delete SSIDs on your AP Groups and replace it with 16 SSIDs (SSIDs on Default Group) configured on WLC.
I have setup a 1131 with multiple ssid's, they show up, but neither one will connect. i need 2 ssid's, one open and one protected. this is the config i have so far:
[code]....
Trying to get an lightweight AP to register with a controller, never seen this one before where the Discovery request is going out to the controller, the discovery response is coming back, but then nothing. At this point the AP should then send a JOIN request, but it just doesnt.
I am using L3 LWAPP, and have the AP statically configured. its a 1131, connecting to a 5.1.151.0 in a WISM. I have run a wireshark and can see the discovery going out, its response coming back, but then nothing (the debugs below also back this up). I have also jumped on the controller and can see the discovery responces are going out but it says no JOIN's are coming in. I'm aware this is an old version of controller but still..
I've tried many different IOS on the AP, including the one it came with in the box, other previously successful IOS and the IOS that 5.1.151.0 dishes out to its registered AP's, multiple AP hardware resets, controller reboots, tried different controllers. etc... What would cause this? Possibly something in the response? See info below:
AP
LWAPP Static IP Configuration
IP Address 172.18.240.244
IP netmask 255.255.255.192
Default Gateway 172.18.240.193
[Code]....
I have tried everything including removing the system, changing the network settings, using cmd.exe, ect. they all say access denied and theres no possible way to get around this.
View 2 Replies View RelatedI want to create a network with a bunch of routers and switches to be used as a test network for company employees to remotely login and learn networking.I don't want this network to interfere with the rest of the network in any way.I am basically trying to create a stub network or a passive network!!
View 4 Replies View RelatedI want to reinstall the MSE image that was sent to me by Cisco TAC Team, however when I try to reinstall the MSE Application, however when I try to install it, the CD boots and show me the Red Hat enterprise image, then sends me black screen with the message "Kernel alive, Kernel direct mapping tables up to 480000000 @ 8000-1b000" and it stay there.
View 2 Replies View RelatedOPTEMAN: 3 routers connected via a private subnet (/29) over the OPTEMAN: Site A, Site B, and HQ. Site A is a 3560 that is the gateway for two subnets: siteA1 and siteA2. SiteB is a 2621, and HQ is a 6509 w/ MFSC.
HQ also connects to 4 other sites via MPLS: SiteC, SiteD, SiteE, and Site F.
HQ has the server subnet, Internet connection, and connection to other services via MPLS.
I have basic EIGRP setup on HQ, SiteA, and SiteB. So far only siteA and HQ are updating each other. Not sure why. I am looking for the best practice example of how I should setup my enterprise EIGRP. I currently use static routes between the sites. I would prefer to be able to setup EIGRP in parallel, the remove the static routes.
I'm looking for documentation on the Enterprise mesh solution based on 7.0 MR1...In this release e.g 802.11n APs are supported and clean air for the client radio etc...The current Cisco Mesh Access Points, Design and Deployment Guide is based on the previous 7.0 release.Apart from the configuration guide I can't find any additional guides.
View 1 Replies View RelatedHow to shut off wireless admin access on a 1131 AP? I only want to be able to administer the device via the wired LAN. I need to shut of http, ssh, and telnet.
I haven't been able to find anything in the GUI.
How to know the CLI commands?
I have a static IP given to me by the service provider, and I need to make the Access point as a DHCP server to provide me IPs inside my LAN.I have created a DHCP pool in the AP. But do I have to NAT the public IP onto the private DHCP range ? This setup is possible.
View 12 Replies View Related