Cisco Wireless :: 4404 Guest Anchor Controller With 5508 Foreign Controller?

Aug 12, 2012

I know that the 3600 series APs are not supported on the 4404 WLC.  However, would the following scenario be supported? I would like to use the 4404 (software rel. 7.0) as a guest anchor with a 5508 (software release 7.2) as the foreign controller supporting series 3600 APs.  I ask because the APs do not need to join the guest anchor.

View 7 Replies


ADVERTISEMENT

Cisco Wireless :: 5508 Foreign Controller And 4400 Anchor Controller?

Jun 2, 2013

We have a customer that have 2 5508 as primary and backup controller and a 4400 as an anchor controller.  We plan to upgrade the 5508 to 7.3.112.0 and the 4400 is already 7.0.116.0.  Will there be any issue if the anchor controller is not the same code as the foreign controller?  Do I also have to upgrade the acnhor controller to 7.0.240.0?

View 2 Replies View Related

Cisco Wireless :: 4400 - Guest Anchor / Foreign Controller Control Path Down?

Aug 16, 2012

We have a Cisco 4400 series wireless controller deployed as a Guest Anchor in a private DMZ.  We have 13 foreign controllers anchored to this for Guest Wireless.  We recently anchored 17 additional controllers to this Anchor controller. Since we have done that, periodically on just 3 of the foreign controllers, the control path shows down on the mobility peer, then comes back up.  We have had this issue in the past, but it resolved itself.  However, now we are seeing this issue again. Are we reaching a limit on EoIP tunnels?  I have read that there is a max of 71, and that is per controller, not SSID. We do have a firewall in the middle but all necessary ports are open.
 
We have had this issue for quite sometime, it just does not happen frequently.  Since we have added the additional controllers, it is now happpening very often, but only with 3 controllers.  There is not much in common with these 3 controllers.  2 are 4400 series, and 1 is a 5508.  All 3 are local on a campus LAN, different networks.  Could it have anything to do with memory or utilization?

View 15 Replies View Related

Cisco Wireless :: 5508 - Anchor And Guest Controller IOS Version

Dec 5, 2011

I know that the recommendation from Cisco for the mobility anchor feature to work well  is to use the same IOS version on the anchor WLC and local WLC controller. Now I´ll install on a new site a 5508 local WLC with a newer IOS version which is installed on the other controllers ( Guest and local ). Later I´ve planned to update also the other controllers to the same IOS version. Now my question is, must I upgrade all other controller at the same time ?

View 4 Replies View Related

Cisco Wireless :: 4402 Guest Anchor Controller 5508 Software 7.2

Nov 6, 2012

We currently have all of our foreign AP controllers on software version 7.0.116.  This consists of a mixture of 4400 and 5508 WLC's.  Our guest anchor is a 4402 on version 7.0.116.  We are replacing the guest anchor with a 5508.  We are also upgrading our 5508 wireless controllers to version 7.2 to support the 3600 series AP's.  My question is what is the recommeded code that the anchor controller should be on?  Should it also be upgraded to 7.2?  If we upgrade the anchor controller to version 7.2, will this affect anchoring to 4400 series foreign controllers still on7.0.116?                 

View 9 Replies View Related

Cisco Wireless :: 5508 / Virtual WLAN Controller Guest Anchor?

Dec 6, 2012

We are planning a WLAN upgrade and the security policy is to forward wireless Guest user traffic to the DMZ controllers. We are now considering the Virtual WLAN Controller and all AP's will register with the virtual controllers and we will use Flexconnect for Staff and internal traffic that will switch their traffic onto the local switch.
 
We wish to forward the guest traffic to the DMZ Guest Anchor controller which will be a 5508 controller. This will also offer Office Extend AP service.I have looked at teh virtual controller docs and not very clear if this deployment model is supported. Below is a diagram of what we wish to deploy and is this a supported deployment model.

View 2 Replies View Related

Cisco Wireless :: WLC 5508 / Guest VLAN Unable To Get DHCP IP Address From Anchor Controller

Feb 23, 2012

In our test set up, we have two WLC 5508 Controllers connected via Checkpoint UTM-1 firewall Inside and DMZ Interfaces. Both the WLC controllers are connected to the firewall via Cisco 3750 switch. On the Local (Inside) Controller, guest SSID is enabled and attached to the wireless management Interface. On the remote anchor controller, guest SSID is enabled and attached to the Management Interface as well. The following configs are replicated on both the Controllers.
 
SSID Name - guest
Interface - Management ( VLAN 10 on Local and VLAN 20 on remote) -
Mobility Group: Same configs at both ends
SSID Anchor : Anchor SSID on local and local SSID on Anchor.
AP: CAPWAP 3502 Management Subnet

[code]....

Is there any thing missing in the wireless configs and or the firewall rules as i could not see DHCP request back from the Anchor Controller. Also, after DHCP is obtained, the web authentication request will be redirected to an Amigopod device for authentication. In this case is the redirect URL congiguration to be performed only on the Anchor Controller or is this to be replicated on both the Local and Anchor Controllers.

View 8 Replies View Related

Cisco Wireless :: 5508 Anchor Controller In DMZ

Nov 26, 2012

We have a WLC (5508) in our main office in Brisbane that is hosting two WLANs. One provides wireless access to our internal network and the second provides wireless guest access. The guest WLAN is anchored to a controller sitting in the DMZ at our Data Centre.
 
In the DMZ the anchor controller has a management interface and an interface in the DMZ for the wireless guest access. I am using the DHCP server on the anchor DMZ to provide IPs etc to wireless guest clients. The default gateway is 10.8.144.1 which is a VIP or a pair of firewalls.
 
Initially everything works fine. Guests connect to the guest network, have to authenticate via a web portal (Cisco ISE server) and then can go on an use the internet. Works perfectly until the firewalls fail over and the secondary firewall takes over the VIP address. All access to the internet is lost at that point. If I try to disconnect and then reconnect a wireless client it connects, as in it will get an IP address, but DNS resolution stops and I do not get redirected to the web auth portal. If the firewalls are failed back to the primary then everything works again, no issues. However, if I reboot the WLC while the secondary firewall has the VIP IP everything will work fine as it did on the primary. If the firewalls now fail over to the primary again everything goes to ****. Until either the firewalls are failed back or the anchor WLC is rebooted.
 
Initially I thought this was an issue on the firewall, but this doesn't appear to be the case. When the firewall fails over it sends out a gratuitous ARP advising of the change in MAC address for the 10.8.144.1 IP address. The WLC seems to update its ARP table because if I run the command "show arp switch" it has the 10.8.144.1 IP address with the MAC address of the active firewall. From the client perspective I have run a wireshark and captured packets on the wireless interface when trying to connect. The laptop is continuously send ARP requests for 10.8.144.1 but gets not reply. Without this the client cannot send an ethernet frame to the gateway and hence get to the DNS server and WEB portal. Internet access breaks. Doing a TCP dump on the active firewall shows it receiving and then sending a reply to the ARP request. It just never gets to the wireless client. Debugging ARP packets on the anchor WLC seems to indicate that the controller is receiving the ARP replies from the firewall. So I'm at a loss as to why things should break when the firewalls fail over.
 
I have a 3750 switch in the DMZ with SVI of 10.8.144.4. I thought I could get a work around where I would make this the default gateway. The theory being that this interface MAC address would never change. However I was wrong. Even with this IP set as the gateway address for the wireless clients I see the exact same bahaviour when the firewalls fail over. I can't explain it other than to say that the gratuitous ARP sent by the firewalls seems to kill the ability of ARP replies to be sent back to the wireless client.

View 3 Replies View Related

Cisco Wireless :: 5508 Anchor Configuration With One Controller In DMZ

Feb 2, 2012

Any link that will give configuration examples of a wireles anchor config with one controller in a DMZ. I have tried this on my own and have some problems in my test enviorment. I believe my issues were with the firewall but not exactly sure.

View 4 Replies View Related

Cisco Wireless :: 3502 - WLC User Rate Limit On Guest SSID Anchor Controller

Jul 30, 2012

We have been deploying 3502 APs remotely to locations with full T1s that backhaul to where I sit at HQ. Both the foreign and anchor controller are here at my location.
 
I am seeking to rate limit per user the bandwidth each client will get on the guest internet ssid. As you know this traffic is encapsulated in capwap between the AP and the controller so I cant use a standard ACL on the switch or router.
 
We are trying to keep the guest internet access usage in check on the T1 at any given site so the other ssid's & local lan traffic is not overly competing for the bandwidth.
 
I found the place to edit the default profiles in the controller but the documentation really isnt clear on best practices.
 
So I put it to you my fellow wireless engineers to suggest how you are implementing bandwidth management on your wireless guest internet.
      
Oh and here is my hardware & software levels.
 
5508wlc - forgeign
4402wlc - anchor
Software Version7.0.230.0

View 3 Replies View Related

Cisco Wireless :: DHCP With Anchor Controller With 2504 And 5508

Nov 7, 2012

All controllers are in version 7.2.111.3.C1 is a 5508, it is ou anchor controller.C2 is a 5508, it is a big site controller.C3 is a 2504, it is a small site controller. C2 and C3 are in the same mobility group than C1 (and all is up up in mobilty managment). When "DHCP Addr. Assignment" is enable on C1 : Clients on C2 received their IP address by our external DHCP server via C1 and the guest tunneling betwenn C1 and C2 and all is working fine. Clients on C3 don't received their IP address by our external DHCP server via C1 and the guest tunneling betwenn C1 and C3, so nothing work.

View 4 Replies View Related

Cisco Wireless :: Multiple Anchor Tunnels On One 5508 Controller

Jan 2, 2012

I'm trying to research the tunnel limits on a 5508 controller if you're terminating controllers to two different SSID's.  For example.  In my DMZ i have  a GUEST SSID for contractors and guests and then I have another SSID used by employees so that tablet and mobile phone users can access the interenet.   Because we don't trust any of these devices we have that SSID is termiated just as we do our GUEST SSID. 
 
To reduce the number of anchor controllers I deploy, I wanted to start with one 5508 Controller. (then move up to about 3)  This controller would have two SSID's, GUEST & MOBILE.  On the Foreign controllers when I setup anchor tunneling I will be anchoring to the same controller however to two different SSID's. 
 
Per the 5508 specs it supports 71 tunnels.
 
So my question to the group is, will the 5508 see this anchoring as one tunnel each? Or does it support 71 Tunnels per SSID?

View 14 Replies View Related

Cisco Wireless :: WLC 5508 HA / Anchor Controller Software Versions

Feb 12, 2013

We have Internal Wireless Controllers to be set up for HA (AP SSO) and wireless traffic from Guest SSID will be terminated on a Guest Anchor Controller inside Firewall DMZ. The Internal WLC controllers are installed with software versions 7.3.101.0, and the Guest Anchor controller is installed with software version 7.2.103.0. Just wondering if the Guest Anchor controller needs an upgrade to match the software versions on the HA controllers. Also, Cisco provides  a new version of code, 7.3.112.0 now. So is it recommended to install the new software version on the HA controllers as well as the Guest Anchor Controller.

View 8 Replies View Related

Cisco Switching/Routing :: 2125 Wireless Controller Without Anchor Controller Just Using Existing Hardware

Dec 6, 2012

I am looking to configure a wired and wireless guest network. I have industrial barcode scanners that connect to one SSID and then there is the business network on the office SSID (no vlan seperation for these devices just different SSIDs). There is not really a need to seperate the business network from the scanners in any case. However, there are needs for a guest network and this needs to be seperated. At the bare minumum I would like to have the wireless guest network. Here is what I have: 2125 Wireless LAN controller managing 18 LAPs (1 indoor and 17 outdoors)Cisco Cat 2950 switches (2 x 24 port and soon to be replaced with 2 x 48 port 2960's with 802.1x capability) Sonicwall TZ210 firewallOne existing wired and trunked vlan for PLC infrastructure. One ESXi hosting Windows server guests (soon to be 2 with vMotion) The reason for the wired guest access network is tp prevent anyone from plugging into the wall jack in the office with thier home laptops or anyone else from being on the same subnet as our domain machines. Granted they would be unathenticaed but there would be no layer 2 seperation and that is what I think would be best.
 
How would I go about doing this on the wireless controller without an anchor controller just using my existing hardware? I would like to have the Guest SSID only availible in the front office. Is it possible to offer a guest network while still servicing the business network SSID on the same access point? Then might I be able to have the guest network be treated as it should at the controller? However this might present another issue altogether as the guest traffic will be over the same wire as the business SSID until it hits the controller for management.

View 1 Replies View Related

Cisco :: Use A 5508 WLC As Anchor Controller?

Apr 21, 2013

I want to use a 5508 as an anchor controller for a wireless guest deployment....but the client has internal 4402's controllers, with software version 7.0.235.0...is it possible tu mix these two controllers for a Wireless Guest Access Deployment??

View 3 Replies View Related

Cisco Wireless :: 5508 Second Guest SSID On Controller Not Giving DHCP Out

Feb 28, 2013

i have two 5508 ver 7.3.0, one is the primary and one is the guest controller. mobility is up and running. i have an exising guest ssid working with wpa2-psk and web authentication and its working fine but i require a second guest ssid that only uses a wpa2-psk for ipod/ipads as i cant use passive client on primary controller. i presently have the one vlan range and dhcp setup on the guest controller to give addressing to either ssid. i know you can have multiple ssid setup on the guest controller but in other sites i have only had one guest connection comming from the primary controller, just a primary controller on each sites was only creating one link to the same guest controler.

View 3 Replies View Related

Cisco :: Wireless 5508 Controller - Guest Wlan Time Of Day Restrictions?

Oct 2, 2011

Looking to add time of day restrictions to our Guest WLAN that is currently in its pilot phase.
 
Is there a way to config time of day access to a WLAN ?

View 7 Replies View Related

Cisco :: Secure Guest Access With 5508 Controller?

Apr 2, 2012

I have a requirement to set up a guest SSID for contractor so that they can use the internet while in the office.

Security say that all traffic on this SSID should be isolated and directed straight to the firewall, with no chance of contamination into the company network infrastructure.
 
With the 5508, my understanding is using the setting up a guest account functionality built in will achieve this, but all traffic would end up at the wireless controller. How do I then put a direct forward for all traffic to the firewall which will only affect the guest traffic?

View 7 Replies View Related

Cisco Wireless :: 44xx / 55xx - Anchor Controller Redundancy

Sep 23, 2012

I am in process of replacing our 44xx controllers with new 55xx controllers.  During the upgrade, I would like to add redundancy to our guest controllers that reside in the DMZ and had a question about regarding the setup.
 
If I remember correctly, I would place both guest controllers on the same mobilty group, and then add both of the controllers to the foreign controllers. The foreign controllers will form mobility with both anchors, but choose the one with the lowest MAC address as primary.  On the foreign controller, if the lowest MAC addressed anchor controller does not respond, it will connect to the second controller.  Is that still true? or is there a better way to go about it?
 
Also, I was wondering, do I need to put different guest network ranges on each of the Anchor controller? or can I use the same exact range on both anchor controller (since if a controller goes down, the clients would be reconnecting to the second controller anyways?)
 
Any best way to setup redundant Anchor (guest) controllers).

View 22 Replies View Related

Cisco Wireless :: 2504 Originating More Than 1 EoIP Tunnel To An Anchor Controller

Feb 26, 2013

I'm attempting to set up (for testing purposes) a 2nd 'guest' SSID on an internal WLC (WLC-A), and terminate it in a DMZ on an anchor controller (WLC-B).  We already have a guest SSID originating on WLC-A and terminating on WLC-B though.  Is it possible to originate a 2nd guest SSID on WLC-A?
 
WLC-A - 2504 (7.2.x)
WLC-B - 5508 (7.2.x)
 
The problem I'm seeing is I'm getting no DHCP address assigned on the test SSID.  If I statically assign IP information I still have no connectivity.  It's as if the EoIP tunnel for the 2nd test SSID isn't functional.

View 2 Replies View Related

Cisco :: Wireless Lan Controller 4404 Exclusion Setting?

Nov 12, 2012

I have a Cisco 4404 wireless lan controller managing about 85 AP's.
 
The wireless side is setup for a private wlan and a public wlan.  On the public side, users are directed to a captive-portal agreement page before they can get on the internet.  My question is if there is a way for a single client, specified by either mac address or static IP , can be connected to this wlan without being prompted for the agreement page?  I would like to setup a wireless printer for guests connected to this public side.                  

View 2 Replies View Related

Cisco Wireless :: 4404 Controller Compatibility With Nexus

Oct 9, 2012

I have two questions -

1) Is it possible to connect Cisco 4404 Controller (or ny other controller) to Nexus 7K series.

2) If yes, then what will be the configuration. Will it be similar to link Aggregation with Catalyst 6500 Neighbor Switch.

View 1 Replies View Related

Cisco Wireless :: Can't Join 1121-AG To Controller 4404 WLC

Jan 4, 2012

Iam having trouble to conect my 1121-AG AP`s to my 4404 WLC.
 
My WLC version is 7.0.116.0.
 
I can see he AP is getting an IP address from the controller(internal DHCP). But from some reason they can`t connect to the WLC. I have tried many things such as:

1)reset to default settings

2) move the AP to Autonumos mode and back to LWAPP mode --  didnt work.

1 of my AP 1121AG is working properly.

View 11 Replies View Related

Cisco Wireless :: 4404 - Changing WLAN ID On Controller

Jun 17, 2012

Our company has 8 4404-100 Cisco wireless controllers and each WLC has 8 W LANs configured. They are all working fine. However, the WLAN ID sequence is not consistent. I'm wondering if it's possible to change the WLAN ID on these WLCs without (or slightly) impacting the users. I don't want to re-configure all the WLAN profiles.

View 13 Replies View Related

Cisco Wireless :: 4404 / Error When Adding Controller To NCS

Sep 10, 2012

This is what the Log shows when I try adding a 4404 to NCS 
 
[2012-09-11 12:37:04,199] [ICE Service[ 1]Thread: 7] [inventory] [INFO ] - Complete inventory for deviceid 11020009 at Tue Sep 11 12:37:04 EST 2012. Total time taken to collect inventory in milliseconds = 1304
[2012-09-11 13:48:41,707] [http-443-10] [inventory] [INFO ] - Device with id 11020010 is managed state now, initial inventory collection started
[2012-09-11 13:48:41,768] [http-443-10] [inventory] [INFO ] - Initial inventory collection completed for device with id 11020010 without exception
[2012-09-11 13:48:41,822] [ICE Service[ 1]Thread: 8] [inventory] [INFO ] - Enter collect inventory for deviceid 11020010 at Tue Sep 11 13:48:41 EST 2012
[2012-09-11 13:48:41,960] [ICE Service[ 1]Thread: 8] [inventory] [INFO ] -  Called InventoryCollectorEngineXdeImpl.call()for device ID = 11020010.
[2012-09-11 13:48:42,045] [ICE Service[ 1]Thread: 8] [inventory] [INFO ] - Invoking FeatureRunner [returned result: mib2-bootstrap] for MNE collection of device: 11020010)
[2012-09-11 13:48:42,159] [ICE Service[ 1]Thread: 8] [inventory] [ERROR] - 192.168.12.77 No matching device profile found.......

[code]....

View 3 Replies View Related

Cisco :: 5508 - Import Guest Anchor WLC Into WCS

Jul 26, 2011

I have the following

WCS: Version 7.0.164.3  and WLC 5508 Software Version7.0.116.0 And cannot import it. I have 2 more WLC 5508 (same version) already imported in WCS with no issue. Have run debug on the DMZ WLC and can see the snmp request coming through when I try to import it. Firewall rules are fine, ran a tcpdump and the WLC returns snmp values back. snmp credentials and routing is fine, can ping both in both ways.

Always comes up with the following error.

IP Address TypeStatus 203.14.70.91Failed to add device to WCS Reason: Object not found in device 

View 2 Replies View Related

Cisco Wireless :: 1250 AP - How Many SSID Can Be Created In 4404 Controller

Jul 7, 2011

How many SSID can be create in a 4404 controller and also in standalone 1250  AP? How many VLANs can be created in eac one?

View 2 Replies View Related

Cisco Wireless :: 4404 / Remote Mesh AP With Centralized Controller?

Jan 2, 2010

we are in the midst of designing a wireless Mesh AP solution for our customer.
 
Customer Requirement:-
 
1. Customer wants to deploy REmote MEsh APs (1500 Series) with a centralized 4404 Controller at HQ site.

2. The Remote and HQ site is linked thru a leased line with 2 routers in between
 
Based on cisco's document REAP and HREAP is not supported in LWAPP Mesh APs. So if the Mesh APs were to be deployed at Remote sites (3 total). How this be achieved?

View 4 Replies View Related

Cisco :: 5508 - Set Up Guest SSID With Auto-Anchor Feature

Mar 7, 2013

I am trying to set up a guest SSID which will be separate from other corp SSIDs. I have read about this auto-anchor feature and I have a basic idea. Here are some questions about the network design
 
1. Can Cisco 5508 with 7.2.111.3 code do NAT? I mean can I use the anchor controller also as a gateway to Internet or do I need another device such as FW or router to do the job?
 
2. I want the guests to get IP address in 192.168.0.0/24 range. On the anchor controller I will need an interface in this range, correct? However on the internal controller I won't need this interface. The guest ssid will be associated with the management interface on the internal controller, correct?
 
3. I want the guests to get IP address from general DHCP server. Does DHCP request have to come out of the new interface in the 192.168.0.0/24 range? However this interface will be connecting with the FW. It won't have connection back to the internal network to reach the DHCP server. The management interface will have the route to the DHCP server. Is it possible to use management interface for this SSID but still let traffic to pass through the Guest interface?

View 3 Replies View Related

Cisco :: Deploying 4400 Controller As An Anchor For 5500 Controllers?

Jun 7, 2011

in one of the sites, the client has an exisiting 4402 controller which he moved to the DMZ in order to set it as an anchor & he purchased two new 5508 controllers to control the corporate APs.  I configured all the parameters needed for the guest anchoring & then I tested the connection but there was an issue. (all the controllers are running the same firmware version)after testing the setup, the guest users could get an IP from the internal DHCP of the anchor controller (in DMZ), but then they cannot reach the internet or anything outside the anchor controller.Cisco confirmed that the 4400 is fully compatible with the 5500 to work in an anchor-foreign secnario as long as they are running the same firmware version. yet, when I temporarily used one of the 5500 controller in the DMZ as an anchor & I applied the exact same configurations on it as the 4400, it worked perfectly without any issues.
 
note:  on the anchor controller (4400), the management & AP-manager interfaces reside on the same subnet & the wireless guest SSID is also mapped to the management interface.  (may be this setup is causing the issue) but on the 5500 it is working just fine?

View 2 Replies View Related

Cisco Wireless :: Adding 1200 And 1130 Access Points To 4404 Controller

Mar 17, 2010

We recently acquired a 4404 Cisco controller for our network and have been adding our 1200 and 1130 Access points to the controller.This was accomplished by upgrading the APs to LWAPP and then they would automatically be discovered by the controller and then join. Lately, new 1131 APs that have undergone the same process, are not joining the controller. They are discovered but then the close the connection. We are running a flat network so all devices are in the same subnet.Software Version of the controller 6.0.188.0. [code]

View 5 Replies View Related

Cisco Wireless :: 2600 Series Access Points Compatible With 4404 Controller

Mar 4, 2013

If the 2600 series access points are compatible with a 4404 controller running 7.0.235.3 code? I was looking for a compatibilty matrix for the AP to controller to code comparison but couldn't find one.                  

View 1 Replies View Related

Cisco :: 5508 - DHCP Load Sharing With Redundant Guest Anchor Controllers

Jan 28, 2012

I have 2 x Redundant Guest Anchor Controllers (5508) located in 2 separate Data Centers with all the management and guest user VLAN spanned between two. Everything is working fine with the Guest WiFi access except the DHCP functionality as the Controllers are acting themselves as the internal DHCP Servers.
 
This is how I tried to distribute : 
network. 10.1.0.0/23
gateway: 10.1.1.254 
Controller 1, DHCP Server pool: 10.1.0.2 - 10.1.0.254 Gw: 10.1.1.254
Controller 2, DHCP Server pool: 10.1.1.2 - 10.1.1.254 Gw: 10.1.1.254
 
As the user load balancing between the Anchor Controllers cannot be controlled (i.e. they are active/active), the same client sometime getting 2 different IP addresses from both the Controllers (as they do not talk to each other in terms of DHCP) hence depleting the pool addresses.
 
I guess one way of solving this is to just run 1 DHCP server in one of the controllers but that defeats the purpose of having N+1 Controllers. Is there a better way of doing the DHCP load balancing and having full redundancy at the same time?

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved