Cisco Wireless :: 1142n - Multiple Vlans With Single SSID
Oct 12, 2011
I have two 1142n LWP ap converted into standalone, as client doesn't have any controller there. They just want to extend their network via wireless.
L3 switch (trunk port gig 1/48) -----> connected to AP1
L3 switch (trunk port 2/48) -----------> connected to AP2
client is looking for 3 vlans on the floor ( users might multiple vlans might associated same AP ). They have a dedicated DHCP/DNS server and he will be configuring 3 vlans on L3 switch with correct ip helper address on SVI interfaces.
I'm i allowed to created 3 SSID's on 1142n standalone AP ?
What would the various optiosn to achieve this requirement ? Is there any simplest way to achieve this ? Do i need to go for 802.1x ? I remember client told their users are authenticating by using AD for wired network. This is their first request for wireless environment
View 2 Replies
ADVERTISEMENT
Apr 2, 2013
I have around 60 , 1142 N APs . As of now i have only management VLAN ( for IP ) & one user vlan 350 configured on the access point . All the users connect to VLAN 350 and they get IP as required.However in our new set up there are couple of requirements have come up were in SSID will be the same however we have created many VLANs for different kind of user group and all these VLANs should be mapped to this single SSID and pick the IPs from their respective VLANs .
We have done configuration on the RADIUS server side were in we have mapped the users in their respective VLANs and they are getting authenticated via AD . Now how do i map my these 4-5 VLANs in a single SSID in Access Point.
View 16 Replies
View Related
Aug 26, 2012
Is it possible to assign a single ssid to multiple interface groups by assigning the ssid to multiple AP groups?
I have buildings geographically dispersed that are configured with multiple vlans in interface groups so that I can maintain an addressing scheme of dhcp assigned addresses per building. Each building is also further grouped as AP groups. I'd like to know if by assigning the same wlan ssid to each of the AP groups, will I maintain addressing integrity for each building? I'm thinking it will work.
Do the buildings have to be outside AP range of each other to avoid problems?
5508 controller
7.2.110.0 code
6 buildings
6 interface groups
1 ssid
View 4 Replies
View Related
Oct 21, 2012
how i can configure a second ssid for guest access in our environment. this is our network setup prior to this request: Internet----Firewall (not ASA)---ce520---C1131AG and CME router is also connecting to the ce520 switch. we only have two vlans: one for voice and two for data.
Presently, there is no vlan configured on the AP because it on broadcasting ont ssid and wireless users gets IP from a windows DHCP server on the LAN. the configuration on the ce520 switch port for the AP and other switches say access vlan is the DATA vlan which automatically becomes the native vlan for all trunk port connecting the AP and other Stiches to the network.
Now with this new requirement, i have made my research and i have configured the AP to broadcast both the production and the guest Vlans. The two vlans are 20-DATA and 60-Guest. I made the DATA vlan on the AP the native vlan since the poe switch is using the DATA vlan as native on the trunk ports. I configured the firewall to serve as DHCP server for the guest ssid and i have added the ip helper-address on the guest vlan interface on all switches while the windows server remains the dhcp server for the production DATA Vlan. I have confirmed that the AP, switches can ping the default gateway of the guest dhcp server which is another interface on the firewall. I can now see and connect to all broadcasted ssids but the problem is I am not getting IP addresses from both the production dhcp server and guest dhcp server when i connected to the ssid one at a time. My AP config is attached below.
Do i need to redesign the whole network to have a native vlan other nthan the data vlan? Does the access point need to be aware of the voice vlan? Do the native Vlan on the AP need to be in Bridge-group 1 or can i leave it in bridge-group 20?
View 1 Replies
View Related
Sep 18, 2012
My question is if I can configure 3 ssid, for 3 different VLAN and add the DHCP address from a WAP4410N AP, when you upgrade to the latest version of IOS I can have this functionality?
View 2 Replies
View Related
Feb 27, 2013
I read from this forum some discussion about the WLC VLAN Select feature. [URL]. I see that you can use this feature to have multiple VLANS (interfaces) to map to the same WLAN (SSID).
What I try to learn is under what scenarios would people need to have mutliple vlan mapped to single SSID?
In my environment, I have 50+ AP int he campus on 20+ Cisco 4500 switches. I have single WLAN and it is mapped to one subnet. All wireless users would be on that subnets, whereas wired users are on 20+ subnets of their own.
View 6 Replies
View Related
Apr 11, 2012
I would like to configure a 3750 switch port to be able to use two vlans. I know you can do this with a voice and data vlan, but what about two data vlans ? Say I have two devices, one on a 10 subnet and the other on a 172 subnet, but i only have one wall jack for both devices to plug into. So I use a mini switch to connect both devices and connect the switch to the wall jack; and of course this all leads back to one switch port. When I go to enter the switchport access vlan 172 cmd, how would I also make it so the device on the 10 subnet could route out ?
View 9 Replies
View Related
Feb 5, 2012
I need to create a firewalled segment that not only separates hosts from general population, but also from each other. The solitary confinement of firewalled segments.I know that I could create a bunch of sub-interfaces, one for each host or group that needs to be isolated, but I'd really rather not have to do that if possible. 1) It could become a management nightmare between ACLs and sub-interfaces and 2) it's a waste of IP addresses.s there any way that I can create a bunch of separate VLANs behind the firewall and have them all terminate at the firewall, using a single firewall IP address for the gateway?
VLAN 1 - hosts 1.1.1.5 and 1.1.1.6VLAN 2 - hosts 1.1.1.7
Firewall DMZ Interface - 1.1.1.1VLAN 3 - hosts 1.1.1.8 and 1.1.1.9
This way, the hosts are isolated and can't talk to each other unless they're on the same VLAN.I'm working with an ASA 5510 running 8.2.4(4).
View 1 Replies
View Related
Apr 7, 2013
I am running the demo of the virtual WLC and have one 1142N AP connected to it. I have two WLAN's created and they are configured to broadcast their SSID's. However, when I look on my laptop or Android, I cannot see either of them. I checked the AP to see if it has the WLAN's on it and it does. I did this by going to Wireless -> Access Points -> Radios -> 802.11a/n AP Interfaces -> Details. Under Station Configuration Parameters -> Number of WLAN's, there are 2, which is correct. I had this demo running on VMware workstation and had some bridging issues with it and thought that was the issue. I now have it running on ESX5.1 and am still having this issue. I am at a loss as to what is causing this problem.
View 2 Replies
View Related
Mar 17, 2013
I want to Single SSID in my network .I have 3 cisco 4410 WAP. ISP router Have the Wireless .How to get the single ssid in the network .same time i want to do configure in the isp router for wireless?
View 1 Replies
View Related
Jul 16, 2012
I am setting up a Cisco 5508 wireless controller and was looking for some feedback or assistance. Basically I already have my guest SSID configured and functioning. Created an interface group containing my vlans and applied the created ACL "Guest Policy - internet only", which is also working.I want to setup a second SSID called "staffstudent" and use RADIUS for authentication. I have already created two separate network policies on the radius server: staff and student. Each only allows certain user groups. I want to be able to differentiate on the controller side which profile they are logging in on and then apply the correct ACL. I have two currently configured: one for staff and one for student. It appears to me that since you have to apply the ACL at the interface level I cannot use both since my interface is accepting both staff and students. Is there a way I can filter them using RADIUS so that when they login RADIUS can return a "student" value and then apply the correct ACL? Same for staff?
View 2 Replies
View Related
Feb 22, 2013
I have more than 5000 sq. ft home and have some dead places other end of the house. Now I am looking for Range Extender/Repeater to boost signal. My primary wireless router is Motorola Surfboard SBG6580 and Secondary Linksys E3000 (planning to update firmware to DD-WRT). So I wanted something such that I can roam between the two routers without switching SSID (use single SSID name for primary and secondary DD-WRT routers) and connect automatically to whichever the best signal (or) strength router. In work place we have same thing like that single wireless SSID name which automatically connect wireless SSID from one end to another end of the building.
View 1 Replies
View Related
Nov 2, 2011
I've been searching high and low and although I've found many results of people having this same exact problem there doesn't seem to be a fix, or at least no one was kind enough to post one. I have many vlans but the 3 in question are 10, 20, 30.
-10 is for my laptops and desktops with an ip range of 192.168.10.10 - 192.168.10.50.
-20 is my home automation network with an orange of 192.168.20.20 - 192.168.20.150
-30 is my guest network with a orange of 192.168.30.84 - 192.168.30.89
I have a dell powerconnect configured with vlans as my core switch. I trunked a port on the switch assigning 3 vlans (10,20,30) and connected it to port 1 on the wrvs4400N. On the wrvs4400 I trunked port 1 tagging vlan 10,20,30. For some reason vlan 1 is untagged on port 1 and I don't know why. I also have a router connected to the powerconnect. Of the 3 vlans I mentioned vlan 10 and vlan 30 are the only ones with interfaces on the router. Vlan 20 is an internal network with a separate router and until I figure this out that router is physically turned off. Also the router currently turned on has no routes configured to connect my vlans. Currently there is no configured way to jump vlans.
No matter what ssid I connect to I get a dhcp response from vlan 10. all my test indicates that I'm actually on vlan 10. I get internet and I can hit all devices on vlan 10. If I connect to ssid guest and change my ip address to match vlan 30 I can not ping the gateway for vlan 30 and I have no internet access. Some times I get something different. Sometimes I get an ip address from vlan 1 on the powerconnect. If I renew my ip address then I'll grab one from vlan 10 but I should be getting one from 30 or none at all for vlan 20. The absolute crazy part is my droid sometimes gets a 192.168.4.x ip address. I don't have a 192.168.4.x network or dhcp scope anywhere on my network! If I physically plug into a port on the power connect I get to the correct network 10 out of 10 times. If I configure vlans on the other 3 ports on the wrvs4400 and physically plug in, I get to the correct network 10 out of 10 times. I've reset to factory a few times and I've been all inside and out of the wrvs4400. I have no clue what could be wrong with this thing.
View 1 Replies
View Related
May 28, 2013
i`m facing a problem configuring the mentioned access point to act as stand alone access point with multiple SSID assigned to differnet VLANs the problem is that
1) i`m not able to broadcast the both SSIDs in the same time from the Access point
2) i need to make the radius server to manage the SSID access for the wireless clients (trying to find a way in which the aceess point sends a log for the radius server containing the VLAN id /IP address of the the SSID) you may find the below info about the IOS ver. & the configuration?
i`m running IOS /c1100-k9w7-mx.123-8.JEE/c1100-k9w7-mx.123-8.JEE?
View 2 Replies
View Related
Sep 25, 2012
Setup a WAP321 with the new 1.0.1.10 firmware. Setup 2 SSIDS:
WIRELESS (vlan:1)
GUEST (vlan:99)
The wap is plugged directly into a port on my router so I configured the port and additional vlan99 port. I have a DHCP scope assigned on the router to both the port and port.99 interfaces.clients on WIRELESS have no problem and work correctly, however when a client joins guest...a packet capture on the router port shows that a dhcp request is being received for the same MAC on both untagged and tagged 99 interfaces....thus it appears the WAP is not handling the vlans properly
16:07:10.566932 PortA, IN: IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 84:c9:b2:78:fc:31, length 331
16:07:10.566947 PortA.99, IN: IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 84:c9:b2:78:fc:31, length 331
View 2 Replies
View Related
Mar 9, 2010
Is it possible to have multiple dhcp pools for multiple VLANs? The switch is a 6509 and/or 4506 catalyst. I don't want to use server-based products.
View 5 Replies
View Related
May 2, 2012
We are deploying 3600 AP's with a 2504 and would like to create multiple SSID's that are mapped to unique VLANs so we can control the traffic at the Firewall. We have the 2504 up and running with AP's but there appears to be no where in the 2504 controller Web GUI to configure a VLAN mapping to an SSID. Any pointers to documentation on how to configure?
View 1 Replies
View Related
Sep 8, 2009
Looking to setup 3-4 WAP4410N AP's but only want to use 1 SSID and one set of keys if possible.
View 15 Replies
View Related
Apr 29, 2003
On a 1200AP, I have set up multiple SSID's. Generally, broadcast is set on. Why can I only see the default SSID and not the others?
View 3 Replies
View Related
Jun 2, 2010
We just got a WAP4410n and cant seem to get multiple SSID's to show up when searching for them.Only SSID1 shows up in Kismet or any other type of Wifi detector software, is it supposed to be like this?I would imagine that it should display both SSID's
-Mynetwork1
-Mynetwork2
Instead of just Mynetwork1, I have tried everything i can think of to connect to the second one but nothing seems to work.
View 40 Replies
View Related
Jan 31, 2012
We have a secure ssid and a guest ssid. Is the a way to prompt for a single username and password and if that name is guest it will automatically connect to the guest ssid? If active directory user and password it will automatically use the secure ssid? we are using Microsoft NPS/Radius, 3502 ap's, and 5508 controller.
View 3 Replies
View Related
Aug 11, 2011
I have two WAP200's code level version 2.0.4.0 connected to two SFE2000 24port, one switch per building. I have 3 vlans that I want to bridge between those two switches. I know the trunks on the switch are setup correctly because I can connect them directly and test all vlans.
I am able to get the untagged Vlan 1 to work fine with the bridge, but I have issues with the tagged Vlans 2 and 3. I have checked that I have the correct SSID tied to the correct Vlan number. I cause the whole network to lock up when I try to add the other SSID MAC addresses to the AP Mode -> AP Mode -> Wireless Bridge -> "Remote Wireless Bridge's MAC Addresses:" section. The wireless lights and ethernet lights go solid.
Should I be adding the additional MACs there?Does the WAP200 even support multiple VLAN/SSID?
Network diagram: SFE2000 --trunk-- WAP200 --(((((3xSSIDs)))))--WAP200--trunk--SFE2000
View 2 Replies
View Related
Nov 18, 2012
I am using a Aironet 1100 series access point (AIR-AP1142N-N-K9) with IOS version c1140-k9w7-tar.124-21a.JA1. I want to create two seperate SSID's on the access point with WEP encryption. There is no VLAN configured and i want it to be like it. Also I need to broadcast both the SSID's at the same time, so the some of my users need to login with the first SSID and the others to login through the other.
View 2 Replies
View Related
Sep 26, 2011
I have come across a new problem with our WAP4410N. I have set up multiple SSID's for various groups of people and guests at our company, the first and main SSID has set security properly at WPA2-Personal with a 63 character password. So I went ahead and setup the other 3 SSID's with the same security (just to initially get security going was planning on taking down one of them for guest account), but when I boot up my testing laptop, it shows that SSID's 2-4 have no security what-so-ever.
I have re-checked my settings in the Wireless Security tab and they are all still set with the passwords.
I am using: PID VID: WAP4410N-A V02Software Version: 2.0.4.2.
View 1 Replies
View Related
Sep 26, 2012
On a wlc 5508-7.0.116, can I set up 2 ssids that map to one wlan/vlan/subnet. I thought you could but I don't have the means to test without breaking production.
My goal is this:
Ssid red open
Ssid blue wpa 2
But all clients on the same ip subnet
View 3 Replies
View Related
Aug 2, 2012
I have a Cisco AIR-AP1242AG-A-K9 Autonomous AP running firmware 12.4(25d)JA. I wish to set up multiple SSID's (2) each having their own separate security types. Both security types may end up being WPA2, but would have separate keys. I do not have a managed switch, the AP is connected to a "dumb" switch in an office environment, with no VLANS. Also this is only for 1 access point.
I have tried creating 2 SSID's, but my issue is that only one SSID will actually work at a time, meaning that only the native VLAN in the AP will actually allow wired traffic through it's SSID. How can I set up 2 different SSID's, with 2 independant security types and have them work simultaneously? Is this functionality supported by this AP?I feel that this is possible, as I can easily set this up on other access points from other manufacturers.
View 4 Replies
View Related
Feb 29, 2012
I have a situation where a user needs more than one office extend AP in his home. My office extend controller is a 5508 running 7.0.220.0. Are there any issues NATing multiple OE APs to a single address? My initial lab results indicate that each of the AP's associate with the controller and establish a DTLS tunnel. I see the SSIDs get pushed to the AP and then it seems to restart the process never being fully operational. Is there a workaround that will allow me to run mutliple OE APs?
View 12 Replies
View Related
Feb 11, 2013
I just bought a Linksys EA6500 (AC 1750). Now after a week, seems to stop rresponding at times and I am get 5+ MAC Addresses from 1 IP address. I have only one NIC installed and it is configured to have a static IP.
See attached screen capture. ( Server-PC, IP: 192.168.1.130)
View 8 Replies
View Related
Feb 20, 2008
I have two Cisco 1300's acting as bridges only. I have created an infrastructure ssid on VLAN 2 and assigned this to the radio. I am carrying multiple VLANs between the bridges (using subinterfaces on the fastethernet and radio ports).I have enabled WPA-PSK, but how do I check that this is being used between the bridges? Also - I have a switch connected at each end of the bridge. When I make VTP changes, the remote switch does not pick these up - is this because VTP goes over VLAN1 regardless of the Native VLAN (2 in my case)? Do I have to carry VLAN1 over the bridge to get VTP working, or is there an alternative solution?
View 7 Replies
View Related
Apr 7, 2013
I have a 4400 and a 5508 WLC in the same location We want to be able to roam between ap joined to both the 4400 and the 5508 using only one ssid
Do I only need to create a mobility group and add both WLC then create only one WLAN on one of the controllers and it will be shared across bot WLC.
View 5 Replies
View Related
Feb 3, 2013
I currently have an 867vae router and a 1131ag ap setup with 2 vlans and 2 ssid's. I am in the process of baby proofing the house and would like to use the cisco plsk400 homeplug system to relocate my wap. I use 2 networks to seperate and filter the kids internet traffic from my own. It also allows me to shut the kids vlan when they shouldnt be on the internet.
As far as i can tell the plsk400 homeplug doesnt support 802.1q.... so is there any way i can keep the seperate networks/SSID's and the abilty to filter and turn off one of them at will without a trunked link to the router?
View 2 Replies
View Related
Feb 17, 2013
i' ve got 2 cisco 1130 AG AP's , i want both of them to broadcast 2 ssid's per AP, i've done so far but my clients cannot get a ip adress from the dhcp server.
View 19 Replies
View Related
Mar 16, 2013
I have a wlc2112-k9. I have succesfully setup a WLAN with 802.1x authentication and dynamic VLAN assignment. The issue I have (and maybe it isn't an issue and just the way the controller works) is that if the vlan interfaces I have defined are connected to different ports from which the default interface for the WLAN it doesn't work.So for instance, I create my WLAN and set the interface to the management interface (which is connected to port 1). I then define all my other vlan interfaces that could be returned by my radius server.[code]
Port 1 is configured on the switch on vlan 21. If the radius server returns a VLAN ID of 102, 104 or 106 my client successfully connects to the WLAN but it gets put on VLAN 21. However if I move the vlan interfaces above over to port 1 the client correctly gets put on the correct VLAN.All ports on the switch are configured as trunk with the native vlan set to the corresponding value that is set on the WLC.
Is this just the way the controller functions? That it can't assign a client to a different interface that is connected to a different port from the default one setup when the WLAN is created? I would have just though that if the radius server returned VLAN 102 that it would find that interface and connect the user session via that interface regardless of the port it is configured on.
View 11 Replies
View Related