Cisco :: Limit What Users Able To Do And View In Webconsole Of WLC 5508 Via ACS?
Jun 16, 2012
Is it possible to limit what users are able to do and view in the webconsole of a WLC 5508 via ACS. I have ACS setup to restrict what commands can be run depending on user on the CLI however when they log into the webconsole they can access everything?
View 2 Replies
ADVERTISEMENT
Jan 8, 2013
what would be the best method to limit some users/workstations from accesing the internet on a vlan that has access to the internet?
I was thinking of just creating a whole new VLAN for those few workstations that doesnt access the internet or using ACLs on the ASA.
View 2 Replies
View Related
Nov 17, 2012
I am using ASA Version 8.2(1) , I want to limit the vpn users to use less bandwidth of my Interlink to access something on inside network
example : source vpn pool
Destn : inside network
how can achive this with QOS config.
View 2 Replies
View Related
Jul 1, 2012
we have TACACS+ based AAA on our network equipment, authenticating against internal user database on a network of ACS 5.3s.What I want is to limit certain AAA users (namely automated tools) to be only permitted to authenticate from a list of known IPs.I can do this for authorization, easily, that isn't a problem. The problem is to only accept authentication attempts coming from certain IPs and ignore the rest. My problem is, as it is currently, the automated tools are prone to a sort of a DoS attack - if I attempt logging in to any device using the tool's user account and a wrong password, I can get the account disabled in five tries.
I want to ignore all authentication attempts, unless they are coming from well known source IPs.Ex: netmon user is the user for a tool running on server 10.20.30.40. If I try to log in from my own laptop with user netmon, it should fail, and the attempt ignored. Currently after five (or whatever is configured) failed attempts, the user will be disabled. Oly attempts from 10.20.30.40 should be considered for user netmon.I can't use ACLs on the devices, as I want other users to be able to log in from other IPs.
View 4 Replies
View Related
Aug 12, 2011
how to limit the bandwidth in digicom router?
View 2 Replies
View Related
Feb 28, 2012
Is it possible to configure WLC so that only one user can connect to wireless network at a time with one login? We have WLC5508 (7.2.103.0) web authentication with LDAP (Active Directory).
View 2 Replies
View Related
May 14, 2013
I have a 2504 Controller (os version 7.0)with 7 access poins attached and with 2 vlans. one for regular users and another for gues users.
View 10 Replies
View Related
Sep 28, 2011
I've got an HP Microserver, running server 2008 R2 foundation, and I'm using it for file sharing. All files are in a single folder with subfolders, and located in drive C.
The problem is that the server limits the number of LAN connections to it to 31. I've already changed the max. number of connections to the maximum, but doesn't seem to work. Network discovery and file sharing are on, firewall is off, full access rights for everyone.
The error I get when trying to access the shared folder is: 'Microsoft Windows Network: No more connections can be made to this remote computer at this time because there are already as many connections as the computer can accept'
View 3 Replies
View Related
Jul 19, 2012
I used the following commands to limit users on my wireless network (WLC 5500) and a Nexus 7000. The previous cisco doc only covers the 6500 and some commands have changed. Tested and working except the PIR gives an error, post up if you know why, otherwise enjoy!
Note Wireless Network assumed to be 172.21.0.0/16.Note This will limit each wireless user to 1 MbpsNote The PIR (Peak Infomation rate, also know as burst) is ignored in following commands, unknown at this time why.Create ACLs:
ip access-list acl-wireless-downstream 10 permit ip any 172.21.0.0/16 ip access-list acl-wireless-upstream 10 permit ip 172.21.0.0/16 any class-map type qos match-all class-wireless-upstream match access-group name acl-wireless-upstreamclass-map type qos match-all class-wireless-downstream match access-group name acl-wireless-downstreampolicy-map type qos police-wireless-upstream class class-wireless-upstream police cir 1 mbps bc 200 ms pir 1536 kbps be 200 ms conform transmit exceed drop violate droppolicy-map type qos police-wireless-downstream class class-wireless-downstream police cir 1 mbps bc 200 ms pir 1536 kbps be 200 ms conform transmit exceed drop violate drop
1.Apply police-wireless-upstream on the incoming port from the controller.
interface port-channel130 description *** LAG for WLC1 *** switchport mode trunk switchport trunk allowed vlan 80,130,255,600 service-policy type qos input police-wireless-upstream
2.Apply policy-wireless-downstream on the uplink LAN/WAN ports.
interface port-channel101 description *** L3 Port Channel to Core VDC *** no switchport service-policy type qos input police-wireless-downstream ip address 10.70.10.18/30 ip router eigrp 10
View 5 Replies
View Related
Oct 4, 2011
Just finishing up a small install of a 5508 controller and WCS.Approx 30 AP's across 2 buildings.2 WLANS - 1 prod wpa2 and 1 guest which is completely open to internet only.Our security group is asking if there is a way to determine who is accessing the Prod WLAN. Currently it is setup to work with eap and the users AD account which is working well.I noticed under the client tab in WCS that there is a Vendor name and it shows me intel and even RIM when someone with their Blackberry is connected. BUT when we connect via an IPAD it show "unknown" as vendor name. Is there a way to get the IPAD to register under the vendor name ?
View 1 Replies
View Related
Nov 17, 2011
Need implementation of an OID to view the number of connected clients per Access-Point? I am using a 5508 WLC.
View 4 Replies
View Related
Dec 4, 2012
I would like to set a time limit for how long a client can be continously connected to the WLAN that provides my guest internet access. The user name/password is hosted on my ACS and authentication is provided by my Cisco NAC. I am using 5508 controllers (7.02) and WCS.
Somewhere in this combination of stuff, there has to be a way to set a two hour time limit.
View 7 Replies
View Related
Dec 20, 2011
The behavior of some mobile devices ( as Iphone , Itouch, not Blackberry, not labtops ) with WL Controller (5508) is that, when the client doesn't use it, it disconnects after 480 sec.
The idle timeout configured is 900 sec.
Why the behavior is different in this type of devices? Increase the idle timeout is a solution?
View 2 Replies
View Related
Sep 12, 2012
I would like to be able to allow a specific client to only associate at 6mbit/s -is this possible using the wlc controller 5508? Another option would be to limit a whole w lan ssid to 6mbit/s but i can't find a way to do that either.
Other w lan ssid's on the same access points/controller need full data rates, so i guess i can't use the RF-profiling for this.
View 2 Replies
View Related
Apr 4, 2013
I am using web authentication with my Wlc 5508 and I would like to check all users currently connected (ip, login used, MAC address, ...) with SNMP.
I am using an external web server and my client are authenticated with ldap.
I know I can receive these information with traps, but I would like to create a short program which will check all users when I click on a button.
View 2 Replies
View Related
Sep 25, 2011
Having an issue with Cisco ACS v5.1.0.44 and the Cisco WLC 5508. Cannot get users to authenticate and keep getting error messages referring to EAP session timeouts from WLC filling our logs. Seems to be with this model WLC because we have Cisco 4400 WLCs pointing to the same ACS with no issues. Is there a bug or special configuration that is necessary to marry the 5508 with ACS v5.1.0.44?
View 9 Replies
View Related
Jul 6, 2012
I have WLC 5508 and 18 1242 APs are connected to WLC. I am getting following error messages in all APs.
*Jul 3 02:53:18.263: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to reset
*Jul 3 02:53:18.320: %LINK-3-UPDOWN: Interface Dot11Radio1, changed state to up
*Jul 3 02:53:18.326: %LINK-3-UPDOWN: Interface Dot11Radio0, changed state to
[Code]......
View 11 Replies
View Related
Jan 5, 2013
Have WLC 5508 running 7.4 code; have wlan setup to allow access to internal network. Users on ipads should be able to connect to this wlan and authenticated via certificate instead of PSK. We have setup laptops that are part of domain to use internal CA for authentication to WLAN. Ipads are not part of domain so we are not able to use the same model, or can we use the same model for authentication?How to setup WLC to authenticate ipad users via certificate instead of PSK while connecting to the WLAN?
View 1 Replies
View Related
Jul 10, 2011
We are required to change passwords every so often at my job. I am trying to change the password for one of the local user accounts on a 5508 WLC running 7.0.98.218 - How can I accomplish this task? The option I get is to remove the users.
View 1 Replies
View Related
Dec 3, 2012
We are implementing a WLC infrastructure in our company following the below scenario:
- WLC 5508, OS 7.2
- APs AIR-LAP1142N-T-K9
- 3 Wlans (1Open w/ Web Auth, 1 WPA2 and 1 802.1x)
Issues:Everything seems to be fine, but some users loses connectivity (when connected to 802.1x network) at least 3 times by day.
- I cannot see anything at WLC logs concerning the association/deassociation of any of these users.
- Only strange line in the logs is "RADIUS server 172.21.44.50:1646 deactivated in global list" (authorization server config)
- Also I see some "Coverage hole pre alarm for client" but that doesn't look like a problem...
View 6 Replies
View Related
Mar 22, 2010
Have a WLC 5508 running 6.x code with LAP's providing wireless for our internal laptops (WPA2 and EAP-TLS). I want to provide guest wireless which goes out a different port on the WLC to a guest firewall/cable modem. However, we want to prevent our internal laptops from being able to use the guest wireless. I have RADIUS (IAS) and LDAP for my AD available. We would prefer not to have use Lobby Ambassador and just have the guests use a simple password or web passthru. Guests may be laptops or smartphones. What options are available? I have tried a test setup using dynamic vlan assignments from RADIUS using the IETF flags, but can't seem to get it to work. Is there a way to identify the SSID is being used at the RADIUS server?
View 13 Replies
View Related
Sep 29, 2012
I have a wireless 5508 with license base to 50 aps, i use a deployment flex connect. I already registered all my access points, I use web authentication to authenticate users guest, and the service dhcp is in the central site.
My issue is the users in each remote site, can not get an ip address by dhcp from the central site, they can authenticate in the guest ssid, but any users can not get an ip. The request is passing by the wan in this way
Central Site DHCP - Router WAN - Remote Site - Users with notebooks. I use flex connect central deployment (all the traffic consulting to the wlc) .
perhaps i should use local deploy? The wireless is in the central site.
View 17 Replies
View Related
Jan 18, 2013
I work at a campus and use the WCS to control access to my network for staff and only internet access for students. The Staff are assigned Username/password thru active directory and the student uses another SSID with only WPA --a password for all. I was tasked with adding more securing for students -- by adding a user/password. I do not want them connecting to my Active Directory for two reason--security risk and I have too many to input (over 1000). So, I wanted to use our internal database to validate users. I create a webpage with "WebAuth" that opens my logon page from my site and validates the login fields against the database. It works and this allows the user to navigate thru my website but not outside the site. If they try an outside url it redirect them to my logon script. I now understand why, so I'm looking for code I can add to my logon page that would allow me to redirect me to the controller's (once users are authenticated by my database) to call the WCS controller so I can enter a preset username/password so the policy management file would allow them access. I presently use "External" and don't know if "Custom" would work. Finding a way in using a database instead of adding one person at a time?
View 3 Replies
View Related
Mar 13, 2012
Recently i have setup a WLAN with inside and anchor 5508 controllers. Standard setup. However, one issue I have is I wish to extend the length of time between password changes for users connected in on the guest wlan. At the moment, 30 is max. I dont have an option on the controller to creat accounts for any longer than that. How to I extend it to 90 days or 120 days?
View 1 Replies
View Related
Jul 18, 2012
I have a Cisco 5508 running version 7.0.116.0. This controller hosts an open public wifi that requires users to accept a terms agreement via a Web-Passthrough setup that redirects them to the terms splash page. For most people this works without any issue. However, if a user has their homepage for their default browser set to a https site, such as [url]..., then they are never redirected to the terms splash page. The page will just spin and spin until finally they get a timeout error.
View 7 Replies
View Related
Apr 12, 2013
I am trying to setup 4 cameras to view with remote live view. I set up my server with IP addresses of 192.168.1.80 .... 85. The screen has only the option for 1 video channel. I have seen on-line screen shots that have options for channel 1 through 8. I want to assign each camera to a different channel so I will be able to use remote live view to show all 4 cameras at the same time. I can only show one at a time. Do I need a different version than 3.3 or some obscure windows 7 setting?
View 5 Replies
View Related
Oct 28, 2012
I am planning to buy a router for my hotel and I would like to know is it possible to limit the bandwidth limit to the guests? And the admin computer can utilize the maximum speed? it it possible to create a login page paper when some one enters my wifi connection?
View 7 Replies
View Related
Oct 31, 2012
need to know the OSPF best design. I have a customer currently running their OSPF only in two area. Area 0 is provider reside and area 1 reside 700 hundred over of router including HQ router and remote branch router connecting to metro-E 10Mbps networks. Is this design have any weakness? Area 1 about 800 hundred router reside in, the HQ model is cisco router 7200 and remote end is cisco router 1841.Let's say they want a solution, for 3G remote router connect back to the HQ using Lease line with a fixed IP. Using DMVPN and OSPF communicating back to HQ. What should we aware when designing and implementing for the OSPF best practice. They have 700 hundred over remote branch need to terminate back to their HQ. I read cisco recommend an area should not be more than 50 router and per-area no more than 28 area.
View 4 Replies
View Related
Feb 10, 2013
when any user logs into LMS #1, GUI says "user not authorized to view devices". All of my users are set to "full permissions" so it seems to be some disconnect here. I'm using ACS for auth, that seems to be working OK. I have a second system LMS#2, setup exactly the same, which works properly, all "full permission" users can access all device menus.
View 1 Replies
View Related
Oct 10, 2012
we have installed a new appliance of LMS 4.2.2 in our VmWare environment. The platform is running licensed to work with 1300 devices. We have approximately 500 devices in DCR, most of them are small switches ranging from Catalyst 2950 to Catalyst 3750, and also a bunch of Nexus 5548 switches.CiscoView is not working for any of them, we get an error message which we cannot interpret. We have updated to the newest possible device packages, but all to no avail.
View 2 Replies
View Related
Nov 21, 2012
We have installed LMS 2.5.We are not able to view TOC(Table of Contents of RME(4.0.3).
View 2 Replies
View Related
Oct 15, 2012
I am trying to access the cisco view but a message appears notifying me to install the devices packages, i have tried to do an online update from the software center, but it did not work.
the devices that i have are, 2960 switches and 6500 switches and 3560 switches.
View 1 Replies
View Related
Jul 1, 2012
my laptop only has hdmi port and my tv only supports s-video and scart connection but i've an old pc that has s-video connection and i was wondering if i can "send the screen" from my laptop to my old pc via lan is there a way of doing that at high fps? remote desktoping works but it's very slow.
View 2 Replies
View Related