Cisco :: WLC 4.0 - Dynamic VLAN Assignment And DHCP

Jan 16, 2011

I have just upgraded our WLC from 4.0 to 7.0 (via 4.2). Before the upgrade we had our ACS returning a VLAN based on user group.  This seemed to be working without an issue.  Now that the WLC is on version 7 this is no longer working correctly.  The ACS is returning a VLAN and passing the user but the client can not get an IP from the DHCP server configured.
 
Example configuration:
 
SSID-----VLAN
 
PN-CSC-----CSCVlan: Works
PN-Others------OthersVlan: Works
 
PN-Others-----CSCVlan: No DHCP
 
When users are trying to be allocated to a vlan that is different from the native one the DHCP fails however both WLANs are configured to point to the management interface so dont have any real connection to the vlan other than by name.
 
Have there been any changes I haven't seen in the way the dynamic vlan allocation works in version 7?

View 8 Replies


ADVERTISEMENT

Cisco :: Dynamic Vlan Assignment With 1242AG And IAS Not Working

Dec 13, 2012

I'm having trouble getting the dynamic vlan assignment to work on my 1242AG Cisco Aironet APs. I've seen multiple cases with a similar setup and configuration where it works just fine.  I've tried everything I can think of. IAS and AD is running on Windows Server 2003.Everything works fine except the vlan assignment.  Wireless clients successfully authenticate through IAS and Active Directory, but instead of being switched to the appropriate vlan the client stays in whichever vlan/ssid it originally connected to.PEAP is the authentication method, using MS-CHAP v2.  Naturally I have the attributes in the policy set appropriately,[code] I've attached the config for the AP, which shows that I have two vlans/SSIDs set to cipher, aes, network eap, wpa, etc. I noticed that if the Tunnel-Pvt-Group-ID attribute is set to a vlan id that doesn't exist on the AP then the AP makes an event log saying so.

View 16 Replies View Related

Cisco Wireless :: WAP4410N 802.1x Dynamic VLAN Assignment?

Nov 27, 2012

Does the WAP4410N support Dynamic VLAN assignment by means of 802.1x authentication?
 
The reason why I ask this; I am able to configure a SSID on a WAP4410N with WPA2-Enterprise, in combination with 802.1x PEAP network authentication. I can succesfully connect Windows, Windows RT, Windows Phone, iOS and Android devices. But.. I am unable to designate them to another VLAN based on access/connection policies. For example; I want mobile devices such as iPhone and Windows Phone to be assigned to a specific VLAN. The Wireless Access Point (authenticator) must be able to support that.
 
This is my setup:
 
Spplicants: Windows 8 / iPad / ...
Authenticator: WAP4410N
Authentication Server: Microsoft NPS (Network Policy Server)
 
I used 802.1x PEAP (Protected EAP) with password (domain user) authentication. In fact, the suplicants communicate with 802.1x to the authenticator. The authenticator communicates with RADIUS to the authentication server. NAP is not in between. It's just plain 802.1x authentication.
 
wether dynamic VLAN assignment is supported?

View 5 Replies View Related

Cisco AAA/Identity/Nac :: ACS4.1 - Radius Dynamic VLAN Assignment Not Working?

Jan 28, 2013

When the users connect their laptop they are getting a authentication prompt but the switch is not changing the VLANs on the port after successful authentication.Below are the logs on the switch 
 
Jan 28 2013 17:21:32.417 CST: RADIUS:  Framed-MTU          [12]  6   1500
Jan 28 2013 17:21:32.417 CST: RADIUS:  Called-Station-Id   [30]  19  "E4-D3-F1-0B-C6-0A"
Jan 28 2013 17:21:32.417 CST: RADIUS:  Calling-Station-Id  [31]  19  "84-8F-69-A8-BD-1D"
Jan 28 2013 17:21:32.417 CST: RADIUS:  EAP-Message         [79]  45

[code]....

View 1 Replies View Related

Cisco Switches :: Dynamic VLAN Assignment And Layer 3 Switching On 300 Series?

Jul 11, 2012

I have a SG300-28P switch. I just read in the Administration Guide that, when in Layer 3 mode, the switch doesn't support MAC-based VLAN or Dynamic VLAN Assignment.
 
So, in order to assign a client to a VLAN based on their MAC or based on the response of a RADIUS server, we have to disable layer 3 features. Without layer 3 switching, the switch is unable to act as a default gateway and forward packets between VLANs. As a result, the VLANs can't communicate in any way, or access the internet, unless a separate router is connected to every VLAN. Right? Doesn't this limitation significantly reduce the usefulness of the DVA feature?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: 3750x / Dynamic VLAN Assignment For Wired Campus Network

Nov 23, 2012

I`m working on Dynamic Vlan Assigmenton the basis of end user authenticatedwhoc are part of specific AD Group in c ampus enviorment.Objective: Need to assign the vlan on switch port on the basis of authenticated users OU Group in Active Directory. Eg: There are 2 OU groups in AD, Sales and Administration. Authenticated user in Sales group should get Vlan 10 and user in Admininstration Group shoudl get Vlan 20.
 
Components:
 
Cisco 3750x/Cisco 4500
ACS Version 5.2
Microsoft AD

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Use 802.1x To Authenticate Clients On Network With Dynamic VLAN Assignment From RADIUS?

Apr 11, 2013

I'm trying to use 802.1x to authenticate clients on my network with dynamic VLAN assignment from RADIUS. We have IP-Phones(powered by PoE) that only supports EAP-MD5, and we would rather use MAB(it also uses LLDP-MED for some settings) to authenticate the phones using the MAC-range from the phones vendor. The following scenario works perfect:Connect the phone and let it boot up(takes a while) and authenticate with MAB.Connect a computer in the phones data-port and let it authenticate with 802.1x(or fail and reach guest-vlan) However, the following scenario doesn't work:The computer is already connected to the phoneThe phone is then connected to the switch What happends now is that the computer is authenticated using 802.1x before the phone boots up and get's authenticated with MAB. When the phone is ready, it's authenticated with MAB and everything works. However, after a short period(let's say a minute), using `debug authentication all`, we see a "NEW LL MAC: phones mac" message(which is weird since the mac has already been MAB-authenticated), and then we are unable to contact the phone using ping. When I check `show mac address-table` it has now moved the mac from `Port Gi 0/12` to `Port Drop`. However, if I check `show mab interface Gi 0/12` or `show authentication sessions` it lists the phones-mac as `mab auth sucess `.why the first scenario works, and not the second?
 
The switch is a 3560E PoE 24p with IOS 12.2.58SE2. Sample of the switch-config: network-policy profile 1voice vlan 90!interface GigabitEthernet0/12switchport mode accessnetwork-policy 1authentication control-direction inauthentication event fail retry 1 action authorize vlan 60authentication event server dead action authorize vlan 60authentication event no-response action authorize vlan 60authentication event server alive action reinitializeauthentication host-mode multi-domainauthentication order mab dot1xauthentication priority mab dot1xauthentication port-control autoauthentication periodicauthentication violation replacemabdot1x pae authenticatordot1x timeout tx-period 5dot1x max-reauth-req 1spanning-tree portfast!Btw, when we tried authenticating the phones using 802.1x too (EAP-MD5), there are NO problems in any of the scenarios. However, we want to use MAB instead of 802.1x to avoid the requirement of configuring the phones with a username and password. The RADIUS response was the same when using 802.1x as it is with MAB for the phones (including device-traffic-class=voice AV-pair).

View 2 Replies View Related

Cisco VPN :: ASA 8.2 - ACS 5.2 With Dynamic VPN IP Pool Assignment?

Aug 7, 2011

I have Remote Access VPN users (IPsec) who  are terminated on Cisco ASA 5520 (v8.2). For those users, AAA is done on the ACS.  Group-policies and tunnel groups are defined on ASA. Initialy I had all  VPN users defined on ASA and group policies were associated with each  user. Each group policy had it’s own IP pool for users. Now, I moved  users to ACS. How can I associate group policy, defined on ASA, with  users group defined on ACS? Is it possible that ACS send to ASA  information about IP pool for different group policy? Users will use ONE vpn profile BUT based on the Active Directory group they belong to they obtain a different IP address for each group.Can it be done ? ACS version is 5.2.

View 1 Replies View Related

Cisco :: WLC5500 - Disable Dynamic Channel Assignment (DCA) For Group

Jan 6, 2013

Is it possible to disable DCA for a couple of APs and manually force the channels assignment ?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ISE - WLC 7.2 VLAN Assignment?

Sep 10, 2012

The Wireless_Employees authorization profile,assign vlan 666 for wireless employees.ISE is passing VLAN 666 to the WLC - see attachement Radius Auth-VLAN666.jpg then I look on the WLC at a wireless employee who has successuflly connected to the network, WLC is still placing him in the pre-configured VLAN 7.

1. can VLAN be pushed from ISE to the WLC (code 7.2.103) for specific user session?

View 3 Replies View Related

Cisco Wireless :: VLAN Assignment Without ACS On 5508

Apr 8, 2013

I was wondering if it is possible to do dynamic VLAN assignment on the Cisco Wireless Controller 5508 without using Cisco ACS but use Microsoft NPS server instead?

View 3 Replies View Related

Cisco VPN :: ASA5510 - Remote IPsec VPN DHCP-Server IP Assignment?

May 5, 2010

i have configure a remote access ipsec vpn in asa5510 and it is working fine when i configure local dhcp address pool assignment. but not working in dhcp-server
 
below is my configuration
 
tunnel-group test type remote-accesstunnel-group test general-attributes default-group-policy test dhcp-server 10.1.1.200tunnel-group test ipsec-attributes pre-shared-key *
group-policy test internalgroup-policy test attributes dhcp-network-scope 192.168.135.0 ipsec-udp enable ipsec-udp-port 10000
 ---snapshot Ping test to DHCP-Server 10.1.1.200----
ciscoasa# ping 10.1.1.200Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 10.1.1.200, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
 
the DHCP server is working when i assign ip address to the LAN network.

View 20 Replies View Related

Cisco AAA/Identity/Nac :: Guest Vlan - Assignment Error On 3560 Switch?

May 18, 2013

I am configuring 802.1X in a 3560 Switch, my Radius server is a Microsoft IAS, when I connect a station of a guest user, the guest-vlan is not assigned in the port, and I have these logs:
 
May  8 21:23:02: dot1x-ev:Received an EAP Timeout on FastEthernet0/8 for mac 0000.0000.0000
May  8 21:23:02: dot1x-ev:dot1x_guest_vlan_applicable: Guest VLAN not

[Code].....

View 7 Replies View Related

Cisco :: 1130 AG - MBSSID And Dynamic Vlan

Jun 26, 2011

I have some 1130AG access point and I'd like to have :

- Multiple broadcasted SSIDs (because most of my clients are OSX and OSX doesn't deal with hidden SSID at all ! the clients have to enter the data each time which for WPA2 enterprise is really annoying)
- Dynamic VLAN assignement (so my clients don't have to know to which VLAN they belong and so I can easily change them from one to another).
 
As it turns out, it's apparently not supported to have both. But I can't understand WHY ? What exactly is the relation between those features ? What's the underlying technical constraint ?

I can understand the cipher suite must match between all the dynamic vlan because of the way wlan works, but for this, I really don't see what the problem is ... (Especially since I only have one of the SSID that needs dynamic assignement, the other is really the 'guest' one).

View 4 Replies View Related

Cisco Switches :: SG300-28 - Dynamic VLAN And Free Radius Log

Aug 21, 2012

I am using several SG300-28 Switches with firmware version 1.1.2.0.I have dynamic VLAN enabled. As RADIUS server I am using free radius 2.1.12.Authentication is only based on the MAC address. (I configured that on the switches)On the switches I created three VLANs. VLAN100 for the authenticated clients, VLAN200 for Management interface and VLAN300 as Guest VLAN. After a wrong authentication the clients should be put into this Guest VLAN immediately (I configured this on the switches). I am using Windows XP and Windows 7 clients in my network. I did not configure any EAP settings because I just wnat to use the MAC address. 

In most cases the dynamic VLAN assignment and authentication is working fine. The switch log says that the client is authenticated and the same I can see on free radius log. But in some (rare) cases the client is rejected. The CISCO log says "MAC aa:bb:cc:dd:ee:ff was rejected on port ge17" but when I look at the free radius log then this MAC address was successfully authorized.
 
The problem is that the client gets an IP address based on the Guest VLAN300 but after that the switch seems to "switch" the VLAN on the port and then the client is authenticated correctly on the right VLAN but the client does not request a new IP on the new VLAN. If I unplug and re-plug the LAN cable in most cases the client get the correct VLAN and the correct IP. This is happening randomly on nearly all my PCs.
 
Do I have to set some timers higher ? I don't think it is a problem between switch and RADIUS but a problem between communication of the host and the switch.

View 14 Replies View Related

D-Link DIR-600 :: No Devices Listed On Number Of Dynamic DHCP Clients

Jul 27, 2012

I recently noticed my 'Number of Dynamic DHCP Clients' on Network Settings is always empty. Before, it always registered a list since there are several devices that are connected to our wireless network (laptops, mobile phones, desktops).

View 3 Replies View Related

Cisco Switching/Routing :: Dynamic ARP 3560 Inspection On Single Vlan

Apr 22, 2013

I have enabled IP DHCP snooping on a 24 port 3560 switch (v small office) and let the database fill up, now I have added dynamic arp inspection on the single vlan and I amd getting these errors. 

Apr 23 16:15:34: %SW_DAI-4-DHCP_SNOOPING_DENY: 1 Invalid ARPs (Req) on Fa0/5, vlan 1.([5835.d9b0.b9d1/172.30.5.2/0000.0000.0000/172.30.5.3/16:15:33 BST Tue Apr 23 2013])
Apr 23 16:15:39: %SW_DAI-4-DHCP_SNOOPING_DENY: 1 Invalid ARPs (Req) on Fa0/8, vlan 1.([0004.f2be.55e4/172.30.5.5/0000.0000.0000/172.30.5.8/16:15:39 BST Tue Apr 23 2013])
Apr 23 16:15:40: %SW_DAI-4-DHCP_SNOOPING_DENY: 1 Invalid ARPs (Req) on Fa0/8, vlan 1.([0004.f2be.55e4/172.30.5.5/0000.0000.0000/172.30.5.8/16:15:40 BST Tue Apr 23 2013])
[Code] .....

View 2 Replies View Related

D-Link DIR-655 :: Unicasting Is Selected By Default In Dynamic IP (DHCP) Connection Type

Mar 31, 2012

'Use Unicasting' is selected by default in the Dynamic IP (DHCP) connection type.I turned it off based upon the router's support text since the router gets an IP address from my cable modem.I don't understand this option at all.  I've searched for data on the topic and I can't make sense of it.I think I made the correct selection by un-selecting 'Use Unicasting.'

View 14 Replies View Related

Cisco Switching/Routing :: 2560 Create Dynamic VLAN For Specific Group Of Users

Feb 6, 2012

We have Cisco Cat4503 series L3 Switch and Cisco L2 2560 Series Switches, some of the users want to have a dynamic VLAN membership, and connecting with the network as mobile users,
 
can it possible and create dynamic VLAN for specific group of users.

View 6 Replies View Related

Cisco :: DHCP Relay And VLAN Identification

Oct 15, 2012

I have a firewall that I want acting as a DHCP relay. This firewall has a number of VLAN interfaces serving clients. The DHCP relay destination is the IP address of a Windows 2012 Server running Microsoft DHCP which has multiple scopes configured, one for each client VLAN.What I'm finding confusing is how the DHCP will identify the client. Does the DHCP relay insert an identifier of some sort (opt. 54?) based on which VLAN the DHCPREQUEST comes from and then this identifier can be configured to be recognized on the DHCP server?

View 2 Replies View Related

Cisco WAN :: 5505 - Show DNS For DHCP VLAN?

Apr 14, 2013

I've got a 5505 and I'm getting a DHCP address from a cable modem. How can I show the DNS that the ASA is getting? show int vlan 2 is only givving me the IP and net mask.

View 2 Replies View Related

Cisco Switches :: 2620 DHCP Through VLAN

Jan 18, 2013

I have a 2620 Cisco Router plugged into a 2924 Cisco switch by a trunk.The vlan configuration works, I subdivide my router interface with dot1q and have virtual machines on different vlans and everything works perfectly.The problem comes with a DHCP request.Let's say that I have my local lan on the native VLAN 1. I create a VLAN 25 in the switch and create a fa0/0.25 in the router.In the switch, I plug the cable modem from my ISP in a port on vlan 25In the router, I go to fa0/0.25 and issue "ip address dhcp".The DHCP request goes out, but never comes back. The problem seems to be in the switch because if I try the same thing with a virtual machine I have on a trunked VMWare ESXi server, I get the exact same results. I just don't get the IP address from the ISP.The next step would be to monitor the port on which the cable modem is connected and sniff the packets to see if the DHCP request actually gets back through.

View 2 Replies View Related

Cisco LAN :: 3750G - DHCP Blocked By VLAN

Jan 22, 2012

We have a server that we remove from the rack. The only role it has is to give out DHCP on the wireless network. I tried enabling  the built in DHCP server on  the Airespace 4112, though a Catalyst 3750G, but I dont get an address when I'm connected to the wireless network even though the range is enabled. If I set an static IP on my wireless card I can access the network. I also tried enabling DHCP on a Sonicwall that is connected to the Catalyst 3750G.
 
 Do I need to link the DHCP scope to the wireless network? Is there anything on the switch that would be blocking DCHP since it on a VLAN? I have the last four ports in a VLAN for the AP's and the internet connection to the Sonciwall.

View 6 Replies View Related

Cisco Routers :: RV220W Second Vlan DHCP

Jan 2, 2013

I have a Cisco RV220W router (firmware version 1.0.4.17).

I would like to have two separate networks with the following specifications:
 
Netwrork1: address range for the network is 192.168.0.1-254. All devices should be able to reach eachother within this network and connect to the internet either on LAN or through Wifi. From this network I should also be able to reach the device management page of the router. Also the devices should get the ip addresses throgh DHCP.
 
Network2: address range for the network is 192.168.5.1-254. All devices within this network should not be able to reach the devices in network1. All devices on this network should reach the internet through Wifi only. Device management page should not be available on this network.
I have configured the router as shown in the attached screenshots but the problem is that in Network2, devices get IPs from the 192.168.0.1-254 range and not from the 192.168.5.1-254 range. Also there is no internet on these either.

View 8 Replies View Related

Cisco Switches :: DHCP Cable Modem On Vlan SF 300-8

May 19, 2011

I have Multiwan router with 1 port WAN and 4 DHCP Cable modem connected to SF 300-8. I want to connect 4 modem via VLAN through switch. I define Vlan2,3,4,5 on router also in Switch. port 1 on the router as trunk and the other port 2,3,4,5 as Vlan2,3,4,5 with VLAN mode Access. I tag port 1 on every VLAN also Untagged for each port. I having problem when I check the status from multiwan router. all IP address is the same (duplicate). what I want is each VLAN has own DHCP Address. Is that any miss configuration ?

View 6 Replies View Related

Cisco Switches :: 300 - VLAN DHCP Packets Not Passing?

Jul 29, 2012

I am seeing a problem with our Cisco 300 switches. We use these switches as access switches, with a stacked 3750-G at the core, two 2960-S at the distribution layer, and about 10 300 Series switches at the access layer (10 port and 28 ports, all PoE).

We use Voice VLAN (VLAN 14) for our Mitel phones – there is a DHCP server on the Mitel system. Phones come up, get tagged VLAN 14 (LLDP), Traffic flows (including Broadcast for DHCP etc…). The system works, and has worked for months.

One day, suddenly, I find that all the Mitel phones on a particular access switch are not working. I look on the Mitel system and the lease on DHCP has expired, and the phone is stuck on renewing its DHCP IP address. I run port mirroring on the switch for VLAN 14 to see what is happening. The phones are stuck on DHCP discover, and I see the DHCP Discover broadcast packets on the switch but nothing else, no DHCP offer packets – hence the phone stuck at boot cycle.

I then do a port mirror from another access switch (that is currently working) – I can see the broadcast packets from the Mitel phones on the broken switch, but on this switch I can also see the DHCP offer packets from the Mitel system. I run two port mirrors simultaneous from the two switches (one working, one not) and I can see that the DHCP offer packets are not coming through to the broken switch. Panic ensues – I look at the distribution layer and there is no problem what so ever.

For some strange reason, the Cisco 300 28 port has stopped passing DHCP broadcast packets on a particular VLAN, even though they are being sent. I power cycle the switch – and hey presto, DHCP offer packets are coming through, and the phones get an IP address and boot properly.

Forward a couple of weeks later, and to today. I have another phone that is showing the same symptoms, luckily it is the only phone on this particular Cisco 300 28 port. The same issue is occurring as described above. I gather as much diagnostic information I can then reboot the switch – but still no joy. I then remember that this switch is not directly attached to the distribution layer and instead gets trunked to another Cisco 300 28 port. I give that a reboot and 5 minutes later, DHCP broadcast offers are passing and the phone boots.

I am listing this problem as not just a ‘one off’ now, and is recurring. It has happened to two of my 300 28 port switches.

All Switches running 1.1.2.0. No link to up time – first instance of the problem, switch was up for 14 days – second instance (another switch) uptime of 39 days LLDP is working fine on the switches, as is Voice-VLAN (Port is tagged and broadcasts out DHCP Discover which is seen by other devices throughout network) Nothing in the log file on the access switch Nothing on the Dist/Core regarding STP – Spanning tree set up is fine throughout.

View 3 Replies View Related

Cisco Wireless :: WS-SVC-WISM-1-K9 / Getting The IP From Service-vlan DHCP?

Mar 20, 2012

WiSM WLAN Service Module WS-SVC-WISM-1-K9 in 6509e running VSS IOs s72033-ipservicesk9_wan-mz.122-33.SXI2a.bin having trouble to get the IP from service-vlan DHCP.The pertinent config is as follows.
 
!
vlan 300
name WiSM_Service_Vlan
!interface Vlan300
description *** WiSM Service-Vlan
ip address 192.168.200.1 255.255.255.0

[code]....

The service IP is supposed to have been populated with an address from the dhcp pool. I am also unable to connect to it by doing a session switch 1 slot 4 processor 1. I get the following upon attempting to do so:
 
HO2NET0001##session switch 1 slot 4 proc 1

The default escape character is Ctrl-^, then x. You can also type 'exit' at the remote prompt to end the session Trying 0.0.0.0 ...

View 5 Replies View Related

Cisco Wireless :: 2504 WLC And DHCP On Separate VLAN

Aug 8, 2012

My problem, in a nutshell, is that clients do not get an IP from an external DHCP server when connected to a guest VLAN.
 
My current setup is:
 
Native VLAN 1 (192.168.2.x)
2008 DHCP Servers
2504 WLC

[Code].....
 
The guest WLAN just uses WPA and a PSK and is set to interface vlan101 There rest of the 2504 config is default.
 
The ports that the WLC and APs are connected to are tagged on the correct VLANs. (is that even necessary for the AP now?)
 
Ive changed the interface config around a hundred times now with no luck. No matter what a client will not get an IP.
 
Could this be due to the 2504 and ASA both acting as DHCP relays? Ive tried setting the IP of the DHCP on the dynamic interface to many different things with no luck.

View 10 Replies View Related

Cisco Switching/Routing :: SG 300 VLAN Not Pulling DHCP?

Mar 31, 2013

I have a Cisco SG 300 28 port switch that I have set in Layer 3 mode. I set up a second VLAN on it (vlan 4). I also set up the scope for DHCP on a Windows server for both VLAN's. The problem I am having, is that VLAN 4 is not pulling DHCP at all. The DHCP server is connected to port 1 on the switch, and the specifics are as follows:
 
VLAN 1: 192.168.5.251 subnet 255.255.255.0
VLAN 4: 192.168.55.251 subnet 255.255.255.0
DHCP Server 192.168.5.1

[Code]......

View 6 Replies View Related

Cisco Routers :: WRVS4400Nv2 DHCP Relay On 2nd VLAN

Feb 24, 2011

Here's what I'm trying to figure out:
 
My network is set up such that I have a Wireless Network in VLAN 1, which is the primary network that we use.  The subnet is 10.5.1.x.
 
My goal is to set up a completely isolated Guest Wireless Network, however it would work best.  What I am trying to do now is I created a seperate VLAN (VLAN 2, IP range 10.5.2.x) and turned on DHCP on the WRVS4400N.  However, in the Guest Network, it is always picking up a 10.5.1.x IP which is handed out by the DHCP server (10.5.1.5, Win 2003) and still routing all of the traffic to/from our private network.
 
Here's What I have set:
 
Wireless>Security Settings>Guest Network (SSID 2)
Wireless Isolation (between SSID w/o VLAN): EnabledWireless Isolation (within SSID): EnabledSetup>LAN>VLAN 1
Router IP 10.5.1.1, WLAN IP 10.5.1.3DHCP Relay for 10.5.1.5Setup>LAN>VLAN 2
Router IP 10.5.2.1DHCP Enabled for 10.5.2.x subnetDHCP Relay option is grayed out (not sure why)Setup>Advanced Routing
Inter-VLAN Routing: Disabled 
Any way to solve this would be fine.  I just do not want traffic routing through our internal network.  Ideally, if I could get the Windows server to hand out 10.5.2.x addresses, that would be perfect, but I'm not sure how to configure it for such. 

View 17 Replies View Related

Cisco Switching/Routing :: 2950 To Assign DHCP With VLAN

Apr 27, 2012

Stumped again with my Catalyst 2950. Everything is working perfectly with wan/dhcp/router on fa 0/1 with all ports assigned to vlan1. All devices plugged in connect to the router correctly with ip's being assigned via dhcp.Instead of hooking up by console port I want to be able to SSH or telnet in to the switch using any port while still maintaining the above functionallity. Is it possible to assign a dhcp assigned ip address to vlan 2 and have vlan1 and 2 bridged? Or is there a better way of doing this ?

View 3 Replies View Related

Cisco Wireless :: DHCP Scope And VLAN Switch SG300?

Feb 16, 2012

I did the config below but unable to obtain the ip from the subnet scope 10.10.9.0. The switch is in the layer 3 mode.
 
no spanning-tree
vlan database
vlan 2
exit
voice vlan oui-table add 0001e3 Siemens_AG_phone________
voice vlan oui-table add 00036b Cisco_phone_____________
voice vlan oui-table add 00096e Avaya___________________

[code]....

View 1 Replies View Related

Cisco Routers :: RV220W Max DHCP Users (Max Connections) Per Vlan

Nov 19, 2011

We assign (reserve by MAC actually) static IPs to all of our devices.  Over time we have gotten rid of some devices but haven't begun (or finished really) re-using the old IPs.  On our WRVS4400N v2 routers we are able to set the max number of DHCP users per Vlan.  This prevents unauthorized devices trying to connect to our LAN.For example.  I set the range from 192.168.1.100 - 192.168.1.103.  IPs 100, 101, and 103 are in use (reserved via MAC address).  We set max number of DHCP users to 3.  This prevents someone from gaining access to 192.168.1.102.  Does this make sense?  Or at least this was the initial goal and it tested out successfully back when we implemented it.
 
How can I do the same for with the RV220W?  I can set the range, assign static IPs (reserve IPs by MAC address), but can't keep others from gaining accessing to our LAN via the unused IPs (not assigned a static IP).My initial thought was to create static IPs (for the unused IPs) using dummy MAC addresses.  I'm sure there is a much better way of accomplishing what I am trying to do.

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved