Cisco :: WLC 5508 SW 7.0.98 - Keeping Mobile Devices Logged In Using NGS Web Authentication

Feb 12, 2011

I have been testing WiFi devices such as the iPhones and iPads connectivity with the following setup:
 
1. 3502i AP
2. WLC 5508 SW 7.0.98
3. NGS
 
The i-devices have iOS v4.2
 
My goal is to have the guest user i-devices maintain the credentials (username and password) when they login again to the wireless network. Like if the device sleep, I think definitely they would loose those IP address issued by the DHCP. Once the guest user uses them again and connect them to the wireless network the user would not need to type-in those credentials on the Web Authentication page directed by the WLC.
 
The credentials are issued by the sponsor who created them on the NGS. It seems that there are WiFi problems with these i-devices. But somehow, I'm looking for a solution that would automated the logins like a checkbox if you want to be kept signed in, on Yahoo or Stay signed in for GMail.

View 6 Replies


ADVERTISEMENT

Cisco :: WLC 5508 - Keeping Internal Users Off Guest Wireless

Mar 22, 2010

Have a WLC 5508 running 6.x code with LAP's providing wireless for our internal laptops (WPA2 and EAP-TLS). I want to provide guest wireless which goes out a different port on the WLC to a guest firewall/cable modem. However, we want to prevent our internal laptops from being able to use the guest wireless. I have RADIUS (IAS) and LDAP for my AD available. We would prefer not to have use Lobby Ambassador and just have the guests use a simple password or web passthru. Guests may be laptops or smartphones. What options are available? I have tried a test setup using dynamic vlan assignments from RADIUS using the IETF flags, but can't seem to get it to work. Is there a way to identify the SSID is being used at the RADIUS server?

View 13 Replies View Related

Cisco :: WLC 5508 Cannot Have Similar User Logged Twice

Aug 26, 2012

I was having users on a Cisco WLC 440x controllers. Some service accounts were logged several time with the same AD-Account.Since I migrated them on the new controller (5508), it seems that we cannot have the same AD user logged several time.
 
I changed the Radius server with the one we were using on the old 440x but situation seems to be same,I checked the error message when trying to start a second similar connection they looks like :
 
*Dot1x_NW_MsgTask_4: Aug 24 14:04:51.558: %DOT1X-3-MAX_EAP_RETRIES: 1x_auth_pae.c:3062 Max EAP identity request retries (3) exceeded for client xxxxxxxxxxx
*Dot1x_NW_MsgTask_4: Aug 24 14:04:51.558: %DOT1X-3-ABORT_AUTH: 1x_bauth_sm.c:447
Authentication aborted for client xxxxxxxxxxx
 
If I move back to the other 440x similar logins are allowed without any problems.

View 3 Replies View Related

Mobile Devices Cutting Out Internet?

Jun 25, 2012

I have a Belkin Wireless N1 router and it works great with my laptops and desktop computers.But! Whenever I connect up my iPad 2, mobile phone (Nexus S) or any other mobile phone, Apple TV or PS3 - the internet works and then after about 10-15 minutes (maybe more, maybe less) the internet cuts out and I can't connect on any device. The PS3 works great when hooked up through ethernet, but wirelessly the connection doesn't last very long at all. Both my parents and brother have an android based smartphone and when at home they'd like to use our WiFi instead of their mobile data - and when it comes to online gaming on the PS3, I don't want to have to trail an ethernet cable all the way to my PS3 set-up. I have full signal strength throughout the house so range isn't an issue - I've also tried connection up whilst next to the router and the connection still cuts out. To resolve this I have to pull the power cable and re-boot the router.

I have cable broadband and the modem still indicates that I have a connection, and when the internet is cut from the modem the router shows a message saying that "No internet connection can be found". The screen still indicates that it still has an internet connection but it just isn't broadcasting it...I've altered the broadcast channels but this hasn't done anything. I can connect up to my friends Belkin ADSL Wireless router with no problems and it doesn't cut out. He has his PS3 connected wirelessly too and it's all good...

View 2 Replies View Related

Cisco VPN :: ASA 5510 Use Mobile Devices (iOS / Android) With AnyConnect

Sep 27, 2012

I'm a bit lost with licensing.I have an ASA 5510 and I would like to be able to use mobile devices (iOS/Android) with anyconnect. [code]
 
my cisco contact said me : "you need only ASA-AC-M-5510"

View 1 Replies View Related

Cisco Application :: 4710 ACE Chain Certificates In Mobile Devices

Oct 2, 2012

I'm having an issue with intermediate certificates from GoDaddy when connecting from some browsers of mobile devices:Browser in Android 2.3.3;Safari in iOS 4.2.1;Chrome 18 in Android 4.0.In a PC there's no problem, only from the above mobile devices. The intermediate certificate isn't downloaded from the ACE 4710 resulting in a "SSL Certificate Not Trusted" error.Since GoDaddy has no instructions to resolve the issue from a Cisco ACE.

View 6 Replies View Related

Extend A SSH Tunnel / HTTP Proxy Over Connectify For Mobile Devices

Sep 4, 2012

I currently reside in a university which has firewall restrictions. I use a SSH tunnel to connect to the internet. I managed to get my wifi up and running on my mobile device using Connectify but the only the sites which are accesible through wifi are the ones that are accesible through the university firewall. Anyway i can extend the SSH proxy to the mobile device via the Laptop?

View 1 Replies View Related

Linksys Access Point :: WAP610N - Random Disconnections With Mobile Devices

May 17, 2012

I have installed 4 of these units in a commercial premises offering free wifi. Since the day they were installed (5Months ago) we had connectivity issues with mobile devices. This was somewhat resolved in the latest FW 1.0.04 but we are still having random disconnections on the units every 2 - 4 days and have to reboot the units. Lately the units have become unresponsive and reset themselves back to factory settings.
 
What we have done so far:
 
Changed router models - No change
Changed from Static IPs & DHCP - No change
Turned on isolation - No change
Performed a wifi analysis to pick the best channel for each unit - Slight signal gain but still disconnects
Changed to 20Mhz only (And all other variations) - No change
 
I think I am left with no option but to return these for some other brand. I'm really regretting buying these units at the minute...

View 8 Replies View Related

Linksys Wireless Router :: EA3500 / Facebook On Mobile Devices With Android OS Using Both Apps And Browser?

Jun 4, 2012

Recently purchased the EA3500 router.  Everything seems to work great except for Facebook on mobile devices with Android OS using both apps and browser.  I can access FB using a laptop's browser. 

View 9 Replies View Related

Cisco Wireless :: WLC 4404 Authentication Of Devices To Wi-Fi Network

Aug 2, 2012

I'm facing a problem related to devices authenticating to our wireless network. Below are how it is setup:WLC 4404 pass authentication to ACS 5.3 (PEAP + MsChapV2) then to AD server.Client can get stock in this status and it keeps repeating from 1 to 20.

View 4 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2.0 Error In ACS Authentication For Accessing Devices

Jun 11, 2012

We are using acs version 4.2.0 build 124 on windows server 2003. Our domain controller has been upgraded from 2003 to windows 2008 R2.Now we are facing following error in ACS authentication for accessing our devices.Error: AUTH  06/09/2012 11:55:40 E 1810 3316 0x8f21 External DB [NTAuthenDLL.dll]: Windows  authentication FAILED (error 1326L)if we restarted services of ACS server then users get authentiated fine.

View 1 Replies View Related

Wifi Disappearing Refusing Authentication From Multiple Devices

Aug 17, 2012

The original network had a Zylex router, Netgear Switch. There was 2 pc's, one XP and Win 7. There is also 3 tills connected too. There is VPN network connected too. This emits a wireless signal to connect to a scanning gun and is also used to administrate the entire network. I was told by the Administrator of that network that it shouldn't interfere with the wifi network.

The job I was requested to do was to install 3 new wall plates as the Win 7 pc was using a Belkin wireless adapter. There was 2 put inside the office where the XP and Win7 pc's are located. The 3rd was just outside the office.

Now all the ethernet connections work 100%. The wifi is another story though. It will show up in the connect too, when you try connect it will disappear/no response from AP/connect then disappear, these are random too. No order to when each is error is displayed. Even when I put in another router the exact same issues happen.

I have tried to connect to both routers wifi when it wasn't plugged into the switch. Just the router's turned on with no cables plugged in separately of course, no joy same issue with both.

View 2 Replies View Related

Cisco Security :: OOB NAC And 5508 WLC Don't Get Any Authentication

Nov 22, 2010

I have a 5508 wlc trunked to a 6500 switch. Also trunked to the switch on both eth0 and eth1 is the CAS. The CAM is connected with an access port.

The CAS and CAM are on seperate VLANs and the CAS was added to the CAM without issue. I followed the example document for OOB WLAN (VLANs and mapping etc)  but I don't get any authentication going on. The client associates and the WLAN interface is the quarantine VLAN However it seems the client can connect to the network without issue (can web browse to a server internaly to the campus)
 
The client is shown in the wireless clients on the device page of the CAM, If i close down either of the CAS interfaces the client connectivity is broken.
 
Just once, randomly the Clean Access Login Page appeared on the client (battery had died and waited about an hour) but when I rebooted the CAS to check it was consistent it never came back.

View 6 Replies View Related

Cisco :: 5508 Web Authentication Timeout?

Aug 1, 2011

If any authenticated user uses protocol other than (http, https) within timeout period, that user #is deuthenticated

View 1 Replies View Related

Cisco :: 5508 - 802.1x Authentication On PSK Key Management?

Aug 20, 2009

I'm setting up a new 5508 WLC (the first wlc I have ever setup) and I have my WLAN setup with our existing WPA/TKIP ssid for transitioning our clients from our existing autonomous system to the wlc.  I have selected PSK as the key mgmt and I can get the client's to connect for a few minutes but I keep seeing these errors:
 
Fri Aug 21 08:50:05 2009 Client Excluded: MACAddress:00:21:00:f9:dd:50 Base Radio MAC :00:23:eb:27:e3:b0 Slot: 1 User Name: unknown Ip Address: unknown Reason:802.1x Authentication failed 3 times. ReasonCode: 4
 
I don't have nor do I want 802.1x enabled.  Is there something I need to disable either on the client or the controller?

View 20 Replies View Related

Cisco :: Web Authentication Over HTTP Instead Of HTTPS On Wlc 5508?

Mar 26, 2011

I have follow below URL to disable the https over web authentication:
 
[URL]
 
What i want to achieve is disable https over web authentication due to certificate issue, but it seems like even we have disable the http over web management as above URL describe, still https while doing web authentication. Or it is possible to configure use port other than 80, like 8080 for web authentication? (need to reboot the wlc?)Is there any bug that related to this CSCsy32145?
 
WLC Software Version                 6.0.196.0

View 8 Replies View Related

Cisco :: 5508 WLC - Concept Of Association And Authentication

Sep 15, 2010

We have a 5508 WLC with a few WAP's (1131's and 1242's).  Our wireless clients use certificate base authentication against our AD (i.e. both computer cert and user cert are required).  However, from time to time I see clients being associated but not authenticated as reported by the WLC.  Could it be possible, as some literatures indicate that a client can only be "associated" after it's successfully authenticated?  Perhaps I'm not quite clear about the concept.

View 7 Replies View Related

Cisco :: 5508 / Radius Authentication Not Working?

Apr 8, 2013

I have a 5508 controller running 7.4.100 and have a WLAN where I have radius configured. On my controller the client machine I'm using appears but the radius authentication doesn't appear to be working. Is there anything on the controller I can do to verify that the request is even being sent to my Microsoft IAS server? The log on the server doesn't show any requests from the controller so my early days guess is the controller isn't actually sending it.

View 3 Replies View Related

Cisco :: 5508 - AD Authentication For Wireless Networks

Mar 12, 2013

We've recently boughten new equipment to upgrade/replace some of our aging wireless hardware. We're moving to a pair of 5508 controllers and changing over to ACS 5.4. Currently we're just doing MAC filtering with ACS 4.2 and local users. I'd like to move most of our SSIDs to some type of AD authentication. Are there any all encompassing guides that layout the design behind that? So far I haven't had much luck finding one!
 
Also, would it be possible to maintain some of the local ACS users/MAC filtering? We have some mechanical equipment that connects to our network (separate SSID) but cannot join a domain.

View 5 Replies View Related

Cisco Wireless :: WLC 5508 - Web Authentication With Gingerbread 2.3.6?

Jan 7, 2013

I having some troubles with Web Authentication in a WLC 5508 version 7.2 to make authentication with the corporative phones, ANDROID GingerBread 2.3.6 model SAMSUNG GT-S7500L. When I try to connect to the VisitorsWirelessLAN in order to authenticate with web authentication the page never comes, in fact the phone never gets the IP. I have an iPhone and I have not problems, I have a Samsung Galaxy S2 with ICS 4.0.1 and works perfect, is only with gingerbread

View 2 Replies View Related

Cisco Wireless :: 5508 - AAA Authentication Failure

Aug 3, 2011

I've set up several local network users (Security > Local Net Users) on the WLC (5508 running 7.0.98.0). Whenever I try to connect with one of these user accounts (I'm testing this out for now), the attempt is unsuccessful and I see an "AAA Authentication Failure for UserName: xxxxxxx User Type: WLAN USER" in the Trap Log. I thought that after trying to authenticate through a RADIUS server, the local user database would be polled and then a user account in that database would be able to authenticate.

View 1 Replies View Related

Cisco :: Controller 5508 With RADIUS Authentication

May 6, 2013

I'm a trainee in Network and Telecommunication, and I have to do a "model" with a controller, an AP, and a RADIUS server. Communication and configuration of the lightweight AP has been done.
 
I use an autonomous access point 1220 as the RADIUS server (no considering it as an AP), and I'm a beginner in RADIUS configuration. I get a "Processing AAA Error 'No Server' (-7) for mobile 00:24:d6:8f:2c:7e" when I launch a debug targetting my PC, connecting to the LAP.
 
Precursory : 10.137.125.71 is the IP address of the ap1220, working as the RADIUS server 10.137.125.15 is the IP address of the controller. 00:24:d6:8f:2c:7e  is the MAC address of my PC, connecting to the Wi-Fi. ping works to the RADIUS, to the controller. Each devices are connected by a layer 3 Switch, and ping each others. The Wi-Fi works when I don't use 802.1X (or when I don't use RADIUS authentication at all)
 
What I did on the RADIUS server (ap1220 autonomous) :
 
aaa new-model
radius-server local
nas 10.137.125.15 key password

[Code]......

View 5 Replies View Related

Cisco :: WLC 5508 And LDAP Web-Authentication (Routing)?

Aug 13, 2012

I have two WLC5508 controllers configured with multiple SSIDs and a VLAN associated to each of them. Now I am deploying a pilot for Web-Authentication and everything seems to be fine except for the LDAP authentication part. I have done all the steps for enabling anonymous bind on Active Directory (AD) and the configuration on the controller is properly in place. I know the configuration is working fine because I have isolated the problem to some sort of routing or communication problem:
 
Controller Interfaces:
 
Management Interface - Vlan 1, (X.X.148.99)
Student Interface - Vlan 2 (X.X.132.99)
Mobile Devices interface - Vlan 28
Web authentication interface - Vlan 31
 
AD is on Vlan 2 (Student Interface range)Each interface has its own IP in a different IP range.
 
If there is an IP address configured on the Vlan2 interface, LDAP wont work. If there isnt an IP address on the Vlan 2 Interface LDAP works!So you may think I just should not configure an IP for that particular Vlan, but if do this, the controller wont allow to associate any WLAN to that particular Vlan interface and unfortunately I am using it.
 
I think the Controller uses the Management interface to send traffic to the LDAP server and it gets confused of getting a reply from a device which belongs to the Vlan 2 Interface IP range (AD is on Vlan 2).
 
I know the controller is a Layer 2 device, so I am not sure why it should need an IP address to be configured for each interface, I read it is used just for roaming purposes but it seems to be somehow related to LDAP communication process as well.
 
The strange thing is that I can access the management interface IP from the Vlan 2 range and there is not problem at all.
 
PD: Controller 5508, Software version: 7.0.230.0

View 6 Replies View Related

Cisco Wireless :: 5508 / How To Configure Web Authentication

Jun 9, 2012

Can we configure the wireless controller 5508 to authenticate the clients using both of MAC address Filtering (layer 2 security) and Web authentication (layer 3 security). and what is the difference between (Web policy --> authentication) and (Web policy --> on MAC filter failure)

View 6 Replies View Related

Cisco :: 4400 / 5508 Controllers - 802.1x Re-Authentication

Mar 28, 2012

Currently in the process of migrating from psk to 802.1x radius environment using a mix of 4400 and 5508 controllers with WCS using Microsoft ias.  The problem I have is there is a lot of shared iPads and tablets in the environment.  Is there a way to force these user to relogin to radius after a certain time period so they are not  sharing unames and passwords?

View 1 Replies View Related

Zylex Router - Wifi Disappearing / Refusing Authentication From Multiple Devices?

Sep 15, 2012

The original network had a Zylex router, Netgear Switch. There was 2 pc's, one XP and Win 7. There is also 3 tills connected too.There is VPN network connected too. This emits a wireless signal to connect to a scanning gun and is also used to administrate the entire network. I was told by the Administrator of that network that it shouldn't interfere with the wifi network.The job I was requested to do was to install 3 new wall plates as the Win 7 pc was using a Belkin wireless adapter. There was 2 put inside the office where the XP and Win7 pc's are located. The 3rd was just outside the office.Now all the ethernet connections work 100%. The wifi is another story though. It will show up in the connect too, when you try connect it will disappear/no response from AP/connect then disappear, these are random too. No order to when each is error is displayed. Even when I put in another router the exact same issues happen.I have tried to connect to both routers wifi when it wasn't plugged into the switch. Just the router's turned on with no cables plugged in separately of course, no joy same issue with both.

View 2 Replies View Related

Cisco Wireless :: 5508 - Apple IOS Devices

Jun 14, 2012

I'm seeing a problem with Apple IOS devices connecting from one SSID and then connecting immediately to another. I've tried to replicate this fault with non Apple IOS devices, but I'm unable. 

Environment:
Single 5508 WLC running 7.2.110.0 AIR-LAP1142N-A-K9 AP's
 
WLC is in clients head office, MPLS to their branch sites. AP's are in Flex Connect mode, with AP and Flex Connect groups for the AP's at the branch. 3 x SSIDs; Corporate (802.1X), Guest (Web-Auth) & Non-Corp (PSK).
 
Scenario:
Client is connected to the Corporate SSID with his iPad (new model, running iOS 5.1.1). No problem with access, he is able to roam throughout the building with good SNR/RSSI. He wants to test the other SSID's, he attempts to connect directly to the Guest or Non-Corp and gets an error message on the client saying 'Unable to Connect' or 'Unable to Join'. Debugs on the WLC for the client shows no connection attempt, no errors. I can see the client disconnect from the Corporate SSID, but nothing for the Guest or Non-Corp SSID.
 
If the client then disconnects and forgets the Corporate SSID from the wireless profiles on their i Pad, waits 20-30 seconds (I can see the client disconnect cleanly from the WLC) and then attempts to connect to the Guest or Non-Corp SSID's - he doesn't have a problem. He immediately associates, and is able to connect. If he then tries to connect directly to another SSID, while still associated to another from the same WLC/AP – he gets the error again. Forget/wait 20-30 seconds, attempt to connect – no problem. We've tested with several i Phones (4 & 4S), i Pads (2 & new model) - all running the same Apple IOS (5.1.1).
 
I unfortunately can't do much troubleshooting with TAC on this as the client is no longer onsite, and I don't have a 5508 in our lab that I can currently test with. I've tried playing with beacon intervals, etc to no avail.

View 3 Replies View Related

Cisco :: WLC 5508 How To Enhance Client Security Authentication

Dec 20, 2012

Security during client authentication is enhanced by applying both 802.1X and Web Authentication for a WLAN." 

View 7 Replies View Related

Cisco AAA/Identity/Nac :: Endless Prompt For Authentication On WLC 5508

Jan 9, 2012

Having issue with WLC 5508 using ACS 5.2 tacacs+ protocol to do device management.The problem statement is after key in the username and password on the WLC login page, it is endlessly prompt for authentication on WLC. Whilst on ACS monitoring and reporting i able to see it is successfully authenticated, shown at AAA protocol > TACACS+ Authentication.On ACS, the shell profile for this is setting role1 , value = ALL.

View 3 Replies View Related

Cisco :: Wireless Controller 5508 Authentication To AD Server?

Sep 11, 2012

We just got a new 5508 wireless controller and the question we have is :  can we get wireless users to authenticate to an Active Directory server to get access to the network?  I know we can get the authentication done with an RSA server, but what about plain AD?

View 9 Replies View Related

Cisco :: 5508 - Web Authentication Login Page Does Not Show

Oct 21, 2011

I am configuring my 5508 WLCs with SW version 7.0.116.0. I configured a guest ssid with web-authentication enabled, but I cannot retrieve the login page on the controller. I configured the virtual interface with the addredd 1.1.1.1 SSID Layer 2 security: None SSID Layer 3 security: Web Policy enabled
 
I join the ssid with clients, receive the IP address correctly however when I try to open a web page, the login page does not appear. When I check the client status I see that it stuck in WEBAUTH_REQD state.

View 16 Replies View Related

Cisco Wireless :: 5508 - EAP-FAST Authentication In WLC With ACS-LDAP

May 9, 2012

We are using WLC-5508 in our corporate. For authenication we have implemented ACS with LDAP configured as external user database. We can able to get authenicated for Web based authenication. When it is configured for EAP-FAST, authenitication is not happening.

View 3 Replies View Related

Cisco :: WLC 4404 / 5508 Web Authentication By AD Security Groups

May 3, 2012

web authenticate users within a specific Active Directory Security Group. I tried to authenticate over Radius with Cisco Secure ACS and Network Access Restrictions. But NAR only works with Layer 2 authentication. And Web Authentication over LDAP can only be used with User Objects.

View 5 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved