Cisco :: WLC 5508 Mobility Groups And Internal DHCP

May 6, 2012

How do Mobility Groups work with internal DHCP scopes on a WLC 5508?We have a WLC 5508 with two internal DHCP scopes which redirect to captive portals for authentication. I am looking at putting in a second WLC in a mobility group setup to provide some WLC redundancy. The LWAPs will be setup so that every second AP is on the has the second WLC as its primary controller. If the primary WLC fails we want the secondary to be able to take over and issue IP's from the internal scope. How do you set this up with a Mobility group so the second WLC does not act as a rouge DHCP server while the primary WLC is still active?

View 6 Replies


ADVERTISEMENT

Cisco Wireless :: 5508 Mobility Groups

Sep 1, 2012

1) Is it possible for 2 WLCs installed in seperate data centres with L3 seperation to be joined in a mobility group? We will have aps in the branch offices split between controllers so we want to make sure roaming work ok. Also all guest access should be anchored to data centre 2.
 
2) in flexconnect local switching mode, do I need to create flexconnect groups if I'm only using radius servers in the data centre with no requirement to use local radius as a backup?

View 6 Replies View Related

Cisco :: 5508 - Failover For Multiple WLCs And Mobility Groups

Feb 14, 2013

We are in a warehouse type setting and have data centers on each side of warehouse with 5508 WLC's in each data center. Each side is on its own subnet with routing in between and a different set of SSID's for each set of WLC’s. Are goal is to have the ability to failover in the event that if one data center goes down AP’s will move to the controllers in the other DC and the clients will still be able to operate.
 
Our thought was to implement mobility groups between the controllers. While I saw documentation on setting this up when the controllers are on the same vlan, I didnt see any setup config when controllers are in different vlans. So I am wondering if mobility groups are even an option for what we want to accomplish. For the most part clients stay on their respected sides of the warehouse and so we are not necessarily needing roaming for clients between controllers in DC1 and DC2. But that does raise another question in that we do have a planned voice wlan that we would like to have the ability to roam between each side of the warehouse. But we have seen ip issues with this. In the past we have had both SSID's setup on each side and ran to issues with clients not renewing their IP address when moving to the controllers on the different subnets.
 
Can we setup mobility groups between controllers on different vlans/subnets? For failover purposes will mobility groups assist in our setup with 2 DC’s and different subnets/vlans? If the answer is yes we can setup mobility groups between different subnets, is there a way to setup the SSID's on all controllers and have the ability for clients to roam and renew their IP’s when moving to a different controller on a different subnet?

View 3 Replies View Related

Cisco Wireless :: 5508 - Mobility Groups / Sync Controller Configuration

Jul 7, 2011

I have 2 5508 controllers in a mobility group. Any good way to keep the configuration between the 2 controllers synched up?
 
I thought about copying the config from my primary controller to the secondary controller, but I would think there is a more elegant way to make this happen.

View 5 Replies View Related

Cisco :: 5508 - Mobility Group To Match On Internal WLC?

Feb 1, 2012

I am setting up officeexten. I have placed the officeextend wlc in the dmz with an mgmt ip of 192.168.10.2. in the process of anchoring this to the internal wlc. Also the ip on the firewall for this interface is 192.168.10.1
 
1. does the mobility group need to match the same on the internal wlc ?

2. Now do i need a NAT transnational on the firewall for the external WAN ip (AP primed address say 66.10.10.10) to NAT back to 192.168.10.2 ?

3. The 5508 WLC is running on ver6.0.199.4 (license level base) - will this support office extend?

View 14 Replies View Related

Cisco Wireless :: WLC 5508 Internal DHCP

Aug 22, 2011

The two controllers are having two internal DHCP servers with the same range in LAN (enx1,enx2). but i have specified which is primary DHCP server(enx3) in WLAN interface.
 
Now if a new user added into network, will he get IP address from primary dhcp(WLC) or AP connected WLC.
 
if two users connected to 2 diff AP's which are connected to 2 WLC will get the same IP address? since having same address pool configured.

View 11 Replies View Related

Cisco Wireless :: 5508 - Internal DHCP / Two SSID?

Jun 28, 2012

We created the management interface, an internal DHCP scope in same subnet, and Two SSID tied to the same management interface:
 
- when we connect to the first SSID we have and IP address
 
- but when we connect to the secone SSID: impossible to get an ip address - auth and association are OK

View 11 Replies View Related

Cisco Wireless :: WLC 5508 Internal DHCP Server

May 7, 2012

I am hoping to get your feedback around the dhcp issues I am facing with Two Centrally Switched Wireless LANs. The setup is as follows:

- I have a WLC 5508 which has been configured with 4 SSIDs, out of which 2 are using Central Authentication and Switching. - I have an LWAP connected to the WLC in HREAP mode. - WLC is configured as the DHCP server for clients connecting to the SSID 'Guest'. For the rest, I am using external dhcp server. - Only one scope for Guest Interface is setup on the WLC. 
 
Problems:
1. As far as I know, for WLC to act as internal dhcp server, it is mandatory to have the proxy enabled, but the Clients connecting to SSID 'Internet' are unable to get an ip address from the external dhcp server, if dhcp proxy is enabled on the WLC. If i disable the proxy, it all works fine.
2. DHCP does not release the ip addresses assigned to clients even after they are logged out.
3. If a machine which was earlier connected to 'Guest' SSID connects to the 'Internet' SSID, it requests the same ip it was assigned by the WLC which it was assigned under 'Guest', but gets tagged with the V LAN configured on the management interface.  
 
************Output from the Controller********************
(Cisco Controller) >show sysinfo
Manufacturer's Name............. Cisco Systems Inc.Product Name................ Cisco Controller Product Version................. 7.0.116.0Bootloader Version................ 1.0.1Field Recovery Image Version..................... 6.0.182.0Firmware Version..... FPGA 1.3, Env 1.6, USB console 1.27Build Type.......... DATA + WPS + LDPE
[code]...

View 12 Replies View Related

Cisco Wireless :: 5508 Internal DHCP Server

Jul 21, 2012

A client wants us to use the internal DHCP server on a 5508 instead of Windows DHCP. They will have 15 APs initially and upto 25 later. The docs on the 7.2 WLC make it sound like this is discouraged: Internal DHCP Server.

The controllers contain an internal DHCP server. This server is typically used in branch offices that do not already have a DHCP server. The wireless network generally contains 10 access points or fewer, with the access points on the same IP subnet as the controller.
 
In this case, the APs will not be in the same subnet as the Managment Internet.Is it a mistake to use the internal DHCP with upto 25 APs (3 WLANs)? 

View 3 Replies View Related

Cisco Wireless :: Mobility Groups Between WLC 2106 And 5500?

Sep 10, 2012

Can I configure a mobility groups between 2106  Wireless LAN Controller and 5500 Wireless LAN Controllers?

View 8 Replies View Related

Cisco Wireless :: 2500 Series Support Mobility Groups?

Dec 1, 2011

Do you know if the new 2500 series controller supports things like mobility groups? Could I use 2 of these and do inter-controller roaming. Also do you know if this would work with a 2106 controller and a 2505 controller or are they 2 completely independent controllers only knowing about their own APs??

View 12 Replies View Related

Cisco Wireless :: 6500 Configure Mobility Groups For Guarantee A High Availability / Also Redundancy Of Controllers

Mar 24, 2012

What consequences could i have if i install a WiSM-2 module into a pair of 6500 configured in VSS and another WiSM-2 module into other pair of 6500 configured in VSS for serving a 300  APs??...in this case, do i need to configure mobility groups for guarantee a high availability and also redundancy of controllers?Under the best practices, is much better having the two WiSM-2 modules into a single pair of 6500 configured in VSS??

View 4 Replies View Related

Cisco :: 5508 Is There A Way For Internal DHCP Scope To Release Scope Addresses

Apr 7, 2013

DHCP scope is configured on a WLC 5508.I'm checking if there' a way for WLC to clear the dhcp leasing when a user is diconnected from wireless?

View 2 Replies View Related

Cisco Wireless :: 5508 Assign Single Ssid To Multiple Interface Groups By Assigning Ssid To Multiple AP Groups

Aug 26, 2012

Is it possible to assign a single ssid to multiple interface groups by assigning the ssid to multiple AP groups? 
 
I have buildings geographically dispersed that are configured with multiple vlans in interface groups so that I can maintain an addressing scheme of dhcp assigned addresses per building.  Each building is also further grouped as AP groups.  I'd like to know if by assigning the same wlan ssid to each of the AP groups, will I maintain addressing integrity for each building?  I'm thinking it will work.
 
Do the buildings have to be outside AP range of each other to avoid problems?

5508 controller
7.2.110.0  code
6 buildings
6 interface groups
1 ssid

View 4 Replies View Related

Cisco Wireless :: 5508 - Unable To Add New WLC To Mobility Group

Nov 30, 2011

I recently add a second CT5508 to the network, but when I tried to add the first 5508 to the mobilty group I received a message like this:
 
"error in creating member"
 
I've tried different mobility names, via GUI, via CLI and always the same error.
 
I've verified twice or more than twice connectivity issues or any error on the entering the MAC and IP of the controllers, everything is fine.
 
I'm using version 7.0.116.0

View 4 Replies View Related

Cisco Wireless :: 5508 - Mobility / Roaming And Web Authentication?

Nov 27, 2011

I have two 5508, no anchor, only one SSID with internal web authentication using radius server.Under "Configuring Mobility Groups", Cisco guide says: "If a client roams in web authentication state, the client is considered as a new client on another controller instead of considering it as a mobile client".
 
I understand that if a client that has already autheticated via web roams between two LAPs that are associated with different WLCs, it has to reathenticate.

View 6 Replies View Related

Cisco Wireless :: 5508 Mobility Group And Re-authentication

Aug 15, 2012

I have to WLC's a 4402 and 5508   in a mobilty group. they are both running 7.0.116.0. They are configured to use Web Authentication. We are having complaints that Users are having to re-authenticate when moving around the office. My theory is they are moving from one WLC to the other and then requiring to re-authenticate.

View 5 Replies View Related

Cisco Wireless :: 5508 - Mobility Ping And SSH Errors After Upgrade To 7.2.110.0

Aug 7, 2012

After upgrading my 5508s to 7.2.110.0, they are reporting mobility data path errors to one of my WiSMs running 7.0.235.0.
 
I get these messages on the 5508s reporting that it can't send a ping to the affected WiSM:
 
*ethoipSocketTask: Aug 08 21:15:41.175: %ETHOIP-3-PKT_RECV_ERROR: ethoip.c:341 ethoipSocketTask: ethoipRecvPkt returned error
*ethoipSocketTask: Aug 08 21:15:41.175: %ETHOIP-3-PING_RESPONSE_TX_FAILED: ethoip_ping.c:312 Failed to tx a ping response to <ip address>, rc=5
 
But maybe there is another clue because I also see in the same log these errors referencing the same WiSM:
 
*bcastReceiveTask: Aug 08 21:15:45.310: %LOG-1-Q_IND: mm_dir.c:1969 Failed to recreate the SSH Rule for <ip address>.
*mmSSHPeerRegister: Aug 08 21:15:44.829: %MM-1-SSHRULE_CREATE_FAILED: mm_dir.c:1969 Failed to recreate the SSH Rule for <ip address>.
 
Why is the controller trying to SSH to another controller?  Was some SSH related feature added to 7.2 that has been accidentally enabled? 

View 4 Replies View Related

Cisco Wireless :: Migrating 2 Standalone 5508 To One Mobility-group

Jan 23, 2012

for some reason our wlan-controllers were build up to be standalone instead of beeing one mobility-group. I would like to change this in order to use all features of HA.
 
let me describe our scenario: two WLCs 5508 running SW ver. 6

- same subnet

- both are running in master controller mode

- different hostnames, ip-addresses, etc

- all settings for WLANs and AP-groups (exept the APs themselves in these groups) are the same

- in total at this moment we are running around 100 LAPs configured one half on WLC#1, the other half on WLC#2
 
I don't know exactly why, but when that setting was installed, someone already configuredHA for each accesspoint... e.g.:

- AP#1 primary WLC#1, secondary WLC#2

- AP#2 primary WLC#2, secondary WLC#1 but without WLC#2 knowing the configuration for AP#1 it makes no sense, correct?
 
so my question is: how should I do the migration in the best way?
is it easy as:

- disabling master controller mode on WLC#2

- configuring both WLCs into one mobility group

--> WLCs are negotiating their configurations for the APs

View 5 Replies View Related

Cisco Wireless :: 5508 Mobility Service Engineer / WCS Required Or Not?

Feb 4, 2013

I have Cisco Wireless Lan Controller 5508 with 35 (3600 Series Access Points.  Do i need to purchase Mobility Service Engine for this or no need?  Do i need WCS server for this or no need?

View 1 Replies View Related

Cisco Wireless :: 5508 - Mobility Group Same Ssid Multiple WLC

Apr 7, 2013

I have a 4400 and a 5508 WLC in the same location We want to be able to roam between ap joined to both the 4400 and the 5508 using only one ssid
 
Do I only need to create a mobility group and add both WLC then create only one WLAN on one of the controllers and it will be shared across bot WLC.

View 5 Replies View Related

Cisco Wireless :: 1242 / How To Force Clients DHCP Renew On Mobility Event

Aug 24, 2011

I have a (single) client (it is a cisco IOS router) behind a wireless workgroup bridge (cisco1242).The client's IP address is obtained via DHCP from the wired network.Now, when roaming occurs, the Client will never have knowledge about this event,and hence will not renew its IP address until lease expiers. This is not a problem of course when Layer 2 roam occurs, but with Layer 3
roam it will interrupt the traffic.
 
The cisco's IP Mobile implementation does have this issue addressed in DCCoA scenario: the WGB is configured to send an SNMP trap on its dotradio state change;the cisco mobile router is configured with snmp-server manager to process this trap and start DHCP renew on the Down/Up event. Unfortunately, this works in Mobile IP scenario only because I cannot make it work without the mobile router registered with a home agent.

how to force DHCP renew on a client (cisco IOS router) in such a situation - event scripting, SLA,  or ...?

View 5 Replies View Related

Cisco :: How Many AP Will Wlc 5508 Support In HREAP Groups

Nov 20, 2011

I have a new deployment of 44 3502i AP's in 3 buildings at one of my campus'.The 5508 wlc is running latest 7.0.116.0 code.I have some users who take their work with them as they go from location to location on this campus.They need to be able to smoothly switch from AP to AP without having to reauthenticate each time the next AP takes over in the handoff.On the ssid in question we run 802.1x back to 1 auth server; there is no failover auth server.All APs are in one AP Group.My thought is to add all 44 of the APs to one HREAP Group.

View 4 Replies View Related

Cisco :: 5508 - How Many AP Groups Can Be Created By One Controller

Mar 15, 2011

Did any know that how many AP Groups can be created by one Controller? (5508) May I have 100 AP Groups?

View 3 Replies View Related

Cisco :: WLC 4404 / 5508 Web Authentication By AD Security Groups

May 3, 2012

web authenticate users within a specific Active Directory Security Group. I tried to authenticate over Radius with Cisco Secure ACS and Network Access Restrictions. But NAR only works with Layer 2 authentication. And Web Authentication over LDAP can only be used with User Objects.

View 5 Replies View Related

Cisco Wireless :: H-Reap Vlan Mapping Groups On WLC 5508

Feb 29, 2012

Im configuring a WLC 5508 ( version 7 ) with h-reap local switching.All is working , yet i wonder if the vlan mapping can be done better.Currently i need to go into each Lightweight Access point , enable h-reap, then set the native vlan , with the final step to map the vlan. This needs to be done for each AP. In an environment of 100's of APs i would take forever. ( i thought one of the main points of the WLC is centralized management).

View 1 Replies View Related

Cisco Firewall :: 5510 Vpn Client Groups Configured / DHCP Server Stops Giving Network Service

Feb 20, 2013

I have a asa 5510 vpn client groups configured and connected to the internal network DHCP server stops giving network service dhcp and the network goes down.

View 6 Replies View Related

Cisco :: LMS 4.1 No User Defined Groups Shown In Fault Notification Groups?

Dec 12, 2011

I created some User Defined Groups in LMS 4.1, now I want to apply certain fault notification groups to Event Sets.
   
Unfortunately the Groups I configured are not in the Group Selector of the Fault Notification Group: Admin > Network > Notification and Action Settings > Fault Notification Group

View 3 Replies View Related

Cisco :: 881-W DHCP Conflict With Internal AP?

Jun 13, 2012

DHCP conflict on 881-W with the internal AP?I have (12) 881-W chassis in the field.  They are running DHCP services to the wired users as well as to the internal AP for reachability / management / etc.  The scope for the internal AP is a /30 so only one address is in the scope and it is intended for the internal AP. This serves a a point to point link between the internal AP and the internal Router inside the 881-W chassis.       
 
Somehow the 881-W DHCP server is getting out of synch and a conflict is occurring.  It seems at some point, either at boot-up or lease expiration/renewal,  the DHCP server is performing a ping to verify that the address is not in use.  The AP has this address assigned prior and replies to the ping causing a conflict.  I noticed an AP down today, checked the 881-W uptime and the conflict correlates to the same time.   I have to manually clear the conflict and everything works as it should.The existing 12 881-w's could grow to 100's over time, so the manual intervention of clearing the conflict is not going to scale.  I really want to stay away from static reservations. 

View 1 Replies View Related

Cisco Wireless :: 2504 - Using Both External And Internal DHCP On WLC

Nov 25, 2012

I am wondering if the folowing is a valid configuration:

WLC2504
AP2600
 
I need 3 SSID/VLAN, 1 for corporate devices, 1 for coporate smartphones, 1 for guest.

Port 1 on the 2504 should be used for management and corporate devices and connect to the corp network. Port 2 is for smartphones/guest and will be connected to a Cisco ASA 5515 that is connected to a second ISP.
 
Corp devices should get IP from an Windows DHCP. Smartphones/guest should get IP from the WLC. Is this possilbe? I read this in a document "To use the WLC as a dhcp, you need to enable DHCP proxy as it is required." Some how I am imagining that this will mess with the Windows DHCP. Is it better to use the ASA as DHCP for smartphones/guest?

View 4 Replies View Related

Cisco Firewall :: ASA5510 - Use Internal DHCP Throughout VPN IPSEC

Oct 19, 2011

I've a question about VPN IPSEC on ASA5510
 
In the LAN network , we use a DHCP on a Windows2003Server. Is it Possible to Configure the remote VPN Clients to use this DCHPserver throughout the VPN IPSEC and Assigned Automatically IP when the connection is done?

View 1 Replies View Related

Cisco Wireless :: 5508 Office Extend Internal External?

Dec 18, 2011

I am having an issue with internal and external clients. When we have the nat ip configured on the controller we cannot connect internal ap's at all. When we take the nat ip out it works fine. We are on code 7.0.220. I have tried the following command  <config network ap-discovery nat-ip-only disable> and it did nothing.

View 1 Replies View Related

Cisco Wireless :: 5508 - Remote AP Connecting To NAT Address Instead Of Internal IP

Jun 2, 2013

We have a 5508 with 7.4.100.0 vor Internal APs and OEAPs. till now every thing is ok. Now we have to connect an AP (local) in a remote office, connected to the WLC by a VPN Tunnel. The problem is that the AP in the remote office uses the NAT Address to connect to the WLC, so the traffic goes over the Internet, not trough the VPN Tunnel. On the controller I have the following setting:

AP Discovery - NAT IP Only ................. Disabled
On the AP:
AP Link Latency.................................. Disabled
 
How to force the AP to use the internal IP Address of the WLC?

View 7 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved