Cisco Wireless :: 1262 Multiple SSIDs And ACLs On Autonomous AP
Dec 2, 2012
I have the need to run a few autonomous APs (1262) for some sites on satellite links. At a bare minimum I need to run two WLANs. One is wide open, and the other with an ACL that heavily restricts access. Is there any way to tie two WLANs to a single VLAN, while applying an ACL to just one WLAN?
I am trying to provision three 1142 AP's so they broadcast multiple SSIDs. I have set the following commands, but I am not able to get more than one SSID to broadcast. As you can see I added the "guest-mode" command to one of the SSIDs which took it without problems. That other SSID does not accept the command.
I am running a WiFi network built on Cisco 1262 APs and Cisco WLC 5508. My APs broadcast two SSIDs, let call them "WiFi_Pay" and "WiFi_Free". I have a problem: when users migrate from "WiFi_Pay" to "WiFi_Free" (not moving, connecting to the same AP), the connection fails. If they try for second time, it is always successful. My task is to ensure that such migrations run smoothly and be successful from the first attempt.
we have 1262 (AIR-LAP1262N-E-K9) and we dont have WLC..and i want to convert it to Autonomous mode..i did the below steps... with using this file (ap3g1-k9w7-tar.152-2.JB.tar) download it from Cisco site. Step 1 The static IP address of the PC on which your TFTP server software runs should be between 10.0.0.2 and 10.0.0.30. Step 2 Make sure that the PC contains the access point image file (such as c1200-k9w7-tar.122-15.JA.tar for a 1200 series access point) in the TFTP server folder and that the TFTP server is activated. Step 3 Set the timeout value on the TFTP server to 30 seconds. Step 4 On the PC where the TFTP server is located, perform these steps.
I am trying to build a new network from scratch, I have the WLC 5508 w/ Aironet 3600e APs connected to my Netgear Smart Switches and a Linksys RV082 router that I'm using as my DHCP server with several VLANs for several stuff on my Switches.
I have 2 questions:
1. Can I have 5 Interfaces configured on 5 different VLANs, each SSID on each a different Port:
Port 1: Controller management only=> 192.168.x.x /24 Port 2: SSID 1: WiFi Internal=> 172.16.x.x/12 (Radius Auth with no sharing) Port 3: SSID 2: WiFi Internal w/ sharing=> 192.168.x.x/24 (Radius Auth with sharing) Port 4 :SSID 3: WiFi Guest=> 10.0.x.x/8 (Web Auth) Port 5: SSID 4: WiFi IT=> 192.168.x.x/24 ( Radius or certificate Auth with access to the controller management interface)
2. How can I use the Controller as the DHCP server for all the WiFi traffic, and how should that be configured to work with my other DHCP server?
I need to configure a WAP4410N for use on a small, very simple business network. There should be a corporate WLAN and a guest WLAN. The corporate WLAN should allow anyone connectd to it to access resources on the domain.
In front of the WAP is a cable modem/router and a basic Level 2 (web managed) switch. What do i have to do to segregate the corporate and guest networks.
I thought I would add the corporate WLAN to VLAN1 (assuming the default VLAN in the switch is VLAN1). Then I figured I could create the guest WLAN and assign it to VLAN2 which which will be controlled entirely by the 4410N (DHCP, DNS, etc.) Does this sound like the right way of going about things?
Currently my company has 1 primary SSID that is used throughout both floors of the building. We have 1252 LAPs which have 2.4 and 5Ghz antennas. I'm not sure if this issue is only with XP or perhaps it's the computer's drivers but we run into problems with end users going to a different location and having a very weak signal or nothing at all, yet coverage is fine. I believe the problem is the end user's machine selecting the strongest signal and it I have the feeling that switching bands isn't being done as it should when it's in range. So my question,
Should I split up our 1 SSID and created multiple SSIDs according to the location and include 5Ghz or 2.4Ghz in the SSID name so it's easier to ensure that users are connected to the proper signal? I want to ask if multiple SSIDs would still enable users to freely roam (as long as the ssids are configured) throughout the building without noticing a loss of signal but currently just having 1 SSID isn't really enabling people to freely roam around without connection issues.I don't believe having multiple SSIDs will be useful for the computer's choose their connection any more efficiently but allowing the user to manually see what they're connected to and pick something better according to their location.
I have two buildings that I'm trying to configure a bridge in between them using 2 1242AG APs.
Building A PCOFFICE SSID on VLAN 200 Radio G ROOT_1 SSID on Native VLAN 1 Radio A Root Bridge
Building B FDAPC SSID on Native VLAN 1 Radio G ROOT_1 SSID on Native VLAN 1 Radio A
We are using directional antenna. I know they are lined up properly because I have them both down and in front of me. I'm getting an error on the Building B AP that says " No SSID with VLAN configured. Dot11Radio1 not started." and I'm unable to get this to work. The bridge was working before I added the VLAN and encryption/WPA information for the PCOFFICE and FDAPC SSIDs
I am in the process of installing an Aironet 1140 standalone AP. I have not worked with these AP's before. I will be connecting it to one of the PoE ports on the existing ASA 5505. My goal is to have 2 SSID's, one for internal network and one for guest internet only, no access to internal LAN. I want to have the internal wifi clients and the guest clients on seperate IP networks. The internal clients obtain DHCP from the existing server and use the ASA DHCP server for the guest clients. And of course, I would like the ability to manage the AP from the internal network. I am providing copies of my current configs for both the ASA and Aironet.
I just got the E3200 and it's a pretty good router. Configured it to have 1 SSID as the 5Ghz SSID and the other as the 2.4 Ghz SSID. Since there are 2 SSIDs broadcasted, I was expecting machines connected to each distinct SSID to not be able to see each other, ie expecting the 5Ghz SSID to be a private LAN1 and the 2.4 Ghz SSID to be LAN2? It turns out machines on either SSID can see each other, so it looks like it on 1 big LAN even though there are 2 SSIDs.Doesn't a SSID map to a unique LAN even though they are in the same router?
I have recently purchase Aironet Access Point. I'm pretty new to Cisco systems and what i'm try to do is have the access point broadcast multiple SSIDs lets call them Guest and Admin. My problems is when i config router to have a DHCP address it works perfectly fine but when i assign a static IP it shows all the any connected device as unkown with IP 0.0.0.0. So i'm guessing i will need to setup a dhcp server. Is there a way access point can have its own DHCP server and IP address ( i don't want to use any from my STATIC ip subnet as i dont know alot of empty ones left) like home wifi router where they assign each device an IP like 192.168.0.1. Is this possible?
I'm having a bit of trouble determining the best way to do this... I have 12 V LAN's set up (sub interfaces on a redundant group of two NICs) on my ASA 5510. On several of these, I want them to be able to access the internet but not access other V LAN's.
By default, they have a rule like "any to any less secure", and since the outside interface has a lower security level, this works great. But if I create an ACL on the interface, this rule disappears. I can restore internet access by adding an "any to any" or "(this interface's sub net) to any" rule, but this seems to imply that it allows access to any v LAN. Do I have to create a set of "deny" rules for each V LAN, on each V LAN, followed by an any-any rule to allow internet access, or is there a cleaner approach?
So far so good. Now we need to extend the Range of the Wireless and bought an AIR-AP1141N. And this AccessPoint works like a charm, BUT only with one SSID,
I configured in the Port Management Area of the SRP526 both VLANs on one Port and configured the Access Point for multiple SSID use, but i don't get an IP from the DHCP Server Range of the VLAN100.
Could it be possible, that die Access Point can not get the tag Information?
I have a Cisco 877W-K9 router, and I for the life of me can not work out how to enable multiple SSIDs on the AP whilst keeping them all to the same VLAN?
I know this may seem silly but basically for our clients we setup WPA-Enterprise for one SSID and WPA-PSK for the other to help ease migration between the two etc, however all I can seem to do at the moment is create multiple VLANs and use ip unnumbered vlan1 to sync them all into one, but this seems really silly.
I have a problem with DHCP. I have two 2960 connected with a port channel on ports 47 and 48 as trunk with native vlan 10. I only have this one vlan. In port 1 of sw 1, I have a C800 as DHCP server.
I have an AP autonomous with single ssid on vlan 10. When I connect the AP to sw1, I receive dhcp with no problems.When I connect the AP to sw 2, I’m not getting IP by DHCP.I have DHCP snooping working on vlan 10 on both devices.
The ports where I connect the AP are access ports on vlan 10 config as trusted.The trunk ports are also configured as trusted.The port 1 of ws 1 that goes to the C800 is also configured as trusted.
figure out why I’m not getting IP by DHCP when I connect the AP to the SW 2.The only I notice is that when I connect the AP to sw 2, I get on SW 1 the message of packet drop by option 82, but even after configuring ip dhcp snooping information option allow-untrusted on both switches, the problem persists.
I just installed a brand new AP541N-A-K9 (running AP541N-K9-2.0(1) software) and cannot seem to add a SSID. I've tried both from CCA and directly from the Web interface (Wireless:Wireless Network Setup menu). The Add Another button doesn't seem to do anything. I've even tried multiple browser versions.
I am setting up a Cisco 5508 wireless controller and was looking for some feedback or assistance. Basically I already have my guest SSID configured and functioning. Created an interface group containing my vlans and applied the created ACL "Guest Policy - internet only", which is also working.I want to setup a second SSID called "staffstudent" and use RADIUS for authentication. I have already created two separate network policies on the radius server: staff and student. Each only allows certain user groups. I want to be able to differentiate on the controller side which profile they are logging in on and then apply the correct ACL. I have two currently configured: one for staff and one for student. It appears to me that since you have to apply the ACL at the interface level I cannot use both since my interface is accepting both staff and students. Is there a way I can filter them using RADIUS so that when they login RADIUS can return a "student" value and then apply the correct ACL? Same for staff?
I have a 1262 that will be setup as a WGB and wirelessly connect to a Cisco MESH AP. A switch and clients will hang off of the 1262 WGB. How many clients can a 1262 WGB support?
We have two cisco 1262 AP and a 4402 WLC, the AP cannot join the WLC. The AP gets the address from dchp
I cannot ping the AP address from the WLC, but i can ping the default gateway and other VLAN addresses.
I already read the info on the this link : [URL] Still our AP cannot join the WLC no matter what i have tried.
Setup
- VLAN setup on a Cisco 3560 48 port poe Switch - tunk configured btwn the Gi Interface and the Management physical port - WLC mode is configured for Layer 3 - AP Manager and Management are in the same Subnet - Option 43 is configured for the with the AP Manager's IP address - Opotion 60 is also configured with AP Manager's IP address - the port connected to the APs are in the AP Manager VLAN
I have new 1262 APs, this have Gig Interface, when I connect the AP in my 6500 with PoE Gig Interface, the AP turn on, but the interface never get up. I need to change the speed to 100 in the 6500 switch port, when I do this, the interface become UP.
This is the model of the card WS-X6148A-GE-45AF This is the Switch IOS s3223-ipservicesk9_wan-mz.122-18.SXF11.bin
The controller is 5500 version 7.2
This is the interface config: interface GigabitEthernet4/36 switchport switchport access vlan 308
I have a cisco AIR-LAP1262N-A-K9 and AIR-LAP1142N-A-K9, and i would like to join to Cisco WLC2106 (software version 7.0.98.0)My ap 1262N have 3 antennas externals with 7dbi of ganancy,Is possible to do it?
All antennas have to be in the same direction on the AP and I guess when the old 1230 is working well the 1262 will be only better . Attached u see how I plan to mount the new AP versus the old one...
Our scenario requires some customization in Wireless network. We have moving Forklift machines fitted with network devices. The network device in forklift acts as a client. But it doesn't have a wireless adapter and no provisions to add a wireless adapter. There is one ethernet port.
So we have a plan to attach one AP(1262) to each forklift. this AP needs to talk to the AP whcih is connected to Wired network. The network deivce in the forklift need to talk to the root AP(1262) through the AP directly connected to it over Ethernet.
I'm having this weird problem with an IP phone behind a WGB. The setup is like this: Cisco controller -> Switch -> switch -> AP (Air LAP1142) -> WGB (Air LAP 1262) -> switch -> IP phone.
The phone works, sometimes. Sometime for days, sometime for hours, then it disconnects and what I have to do then to get it working again is to run this command on the bridge. "no workgroup-bridge unified-vlan-client", then wait for it to disassociate, then run "workgroup-bridge unified-vlan-client" and after that it gets a stable connection (for a undetermined amount of time).
Here´s the WGB config: version 15.2 no service pad service timestamps debug datetime msec [Code]....
I have a 4404 with 3 SSID's configured on it. I only want all SSID's to be available on one floor in one building and not on any other AP's in any other building or floor.I thought the way to do it was via AP group but have not had any luck getting that to work. I setup a group for the AP's that I do not want all SSID's and then assigned those AP's to that group. However, I can still see all three SSID's where I only want to see 2 SSID's.
I want to split the usage of the AP so that visitors are on their own wireless connnection and VLAN.We have 2 WAP4410N APs. One AP acts as a repeater for the another AP.They are both in 4.0.4.2 firmware.We are using WPA2 RADIUS authentication, and would like for visitors to use WPA2 PSK. Under Wireless tab, I have 1 SSID, but the other 3 available boxes for SSIDs are greyed out.When I click in them, they will not allow me to type an ID.I watched a video of how to add SSIDs and VLANs, and it looked simple enough.He just clicked in the box and was able to add more IDs.Could my current config be preventing me from adding additional SSIDs?
I am trying to configure WLC 2504 with the following setup:
- three WLAN SSIDs - management/ap-manager interface on VLAN 10 - guest WLAN on dynamic interface VLAN 20 - main WLAN on dynamic interface VLAN 30 - WLAN for tablet and smartphone devices VLAN 40
At this point switch trunking is configured and three WLANs are mapped to three dynamic different interfaces. I can see all associated APs (which are on the same subnet as management interface on VLAN 10), and can ping each of the APs as well as gateways on L3 switch Catalyst 3750-x. Also, on the WLC interface I see that all WLANs are enabled and SSIDs are set to broadcast, all AP radio is in 'up' mode. DHCPs are configured on management interface and on all dynamic interfaces. L3 switch gateways all have ip helper-address pointing to main DHCP. 'sh vlan' and 'sh int trunk' commands on the connected switches show correct settings.
However, I see absolutely no any SSIDs to connect to on any PC or Mac computer I tested.
We recently received our WLC 5508, AP and switches to setup our WLAN but I'm having trouble getting it all to work. It's been months since the course and I'm having trouble troubleshooting the problem.I've setup the WLC, AP and switches and I have network connectivity to all. The WLC see's my AP and I have all my WLAN and interfaces configured (SSID broadcast is enabled) but I still don't see any SSID coming from the AP.