Cisco Wireless :: 5508 Mobility Group And Re-authentication

Aug 15, 2012

I have to WLC's a 4402 and 5508   in a mobilty group. they are both running 7.0.116.0. They are configured to use Web Authentication. We are having complaints that Users are having to re-authenticate when moving around the office. My theory is they are moving from one WLC to the other and then requiring to re-authenticate.

View 5 Replies


ADVERTISEMENT

Cisco Wireless :: 5508 - Unable To Add New WLC To Mobility Group

Nov 30, 2011

I recently add a second CT5508 to the network, but when I tried to add the first 5508 to the mobilty group I received a message like this:
 
"error in creating member"
 
I've tried different mobility names, via GUI, via CLI and always the same error.
 
I've verified twice or more than twice connectivity issues or any error on the entering the MAC and IP of the controllers, everything is fine.
 
I'm using version 7.0.116.0

View 4 Replies View Related

Cisco Wireless :: Migrating 2 Standalone 5508 To One Mobility-group

Jan 23, 2012

for some reason our wlan-controllers were build up to be standalone instead of beeing one mobility-group. I would like to change this in order to use all features of HA.
 
let me describe our scenario: two WLCs 5508 running SW ver. 6

- same subnet

- both are running in master controller mode

- different hostnames, ip-addresses, etc

- all settings for WLANs and AP-groups (exept the APs themselves in these groups) are the same

- in total at this moment we are running around 100 LAPs configured one half on WLC#1, the other half on WLC#2
 
I don't know exactly why, but when that setting was installed, someone already configuredHA for each accesspoint... e.g.:

- AP#1 primary WLC#1, secondary WLC#2

- AP#2 primary WLC#2, secondary WLC#1 but without WLC#2 knowing the configuration for AP#1 it makes no sense, correct?
 
so my question is: how should I do the migration in the best way?
is it easy as:

- disabling master controller mode on WLC#2

- configuring both WLCs into one mobility group

--> WLCs are negotiating their configurations for the APs

View 5 Replies View Related

Cisco Wireless :: 5508 - Mobility Group Same Ssid Multiple WLC

Apr 7, 2013

I have a 4400 and a 5508 WLC in the same location We want to be able to roam between ap joined to both the 4400 and the 5508 using only one ssid
 
Do I only need to create a mobility group and add both WLC then create only one WLAN on one of the controllers and it will be shared across bot WLC.

View 5 Replies View Related

Cisco Wireless :: 5508 - Mobility / Roaming And Web Authentication?

Nov 27, 2011

I have two 5508, no anchor, only one SSID with internal web authentication using radius server.Under "Configuring Mobility Groups", Cisco guide says: "If a client roams in web authentication state, the client is considered as a new client on another controller instead of considering it as a mobile client".
 
I understand that if a client that has already autheticated via web roams between two LAPs that are associated with different WLCs, it has to reathenticate.

View 6 Replies View Related

Cisco :: 5508 - Mobility Group To Match On Internal WLC?

Feb 1, 2012

I am setting up officeexten. I have placed the officeextend wlc in the dmz with an mgmt ip of 192.168.10.2. in the process of anchoring this to the internal wlc. Also the ip on the firewall for this interface is 192.168.10.1
 
1. does the mobility group need to match the same on the internal wlc ?

2. Now do i need a NAT transnational on the firewall for the external WAN ip (AP primed address say 66.10.10.10) to NAT back to 192.168.10.2 ?

3. The 5508 WLC is running on ver6.0.199.4 (license level base) - will this support office extend?

View 14 Replies View Related

Cisco Wireless :: WLC 7.3.101.0 Mobility Group Peer Cannot Up

May 19, 2013

It seems the 7.3.101 version Mobility group peer cannot up,: refer to the attach,
 
Peer 1: version: 7.3.101
Peer 2: version 7.0.98
Peer3: version 7.2.103 
 
Today we got new two WLC for Anchor use, and config the mobility group, but it's failed and cannot up, the ping is ok.

View 13 Replies View Related

Cisco Wireless :: Mobility Group Between Controller 4400 And Virtual WLC

Mar 7, 2013

I read the configuration guide about the 7.3 release. And I figured out that you will need a hash key for establishing a mobility group relation between a controller and a virtual controller. The 7.3 release for the 5500 series works fine for me.But the latest release 7.0.235.0 for the wireless lan controller series 4400 does not have a functionality to add a hash key while creating a new mobility group member.The command "config mobility group member hash" is totally missing. How to establish a mobility group between a 4400 controller and a virtual then ?

View 2 Replies View Related

Cisco Wireless :: Max Number Of Mobility Member In Group With WISM 7.0

Dec 5, 2011

I have a customer buys 12 x WISM and build up a mobility, when I add the final WLC to mobility, it prompts that there mobility group has reached the max of mobility member, but the total member is 23, according the configuration guide, it should be allow to 24 member, do I hit some bug? My using version is 7.0.98.0.

View 5 Replies View Related

Cisco Wireless :: Mobility Group Between Controller 4400 And Virtual Wlc

Sep 3, 2012

I read the configuration guide about the 7.3 release. And I figured out that you will need a hash key for establishing a mobility group relation between a controller and a virtual controller. The 7.3 release for the 5500 series works fine for me.
 
But the latest release 7.0.235.0 for the wireless lan controller series 4400 does not have a functionality to add a hash key while creating a new mobility group member.
The command "config mobility group member hash" is totally missing.
 
how to establish a mobility group between a 4400 controller and a virtual then?

View 4 Replies View Related

Cisco :: WLC5500 Mobility Group Fail-over

Mar 22, 2012

I have a Question i am testing  mobility group with Failover for redundend connection between 2 Cisco 5500 Wlc.On both the controllers i got the mobility working And both the controllers have the same version.And configuration. But when i unplug the main controller the access-Points don't convers to the second one .The just keep on creaming can't find the main controllerAlso with this thus the second wlc need to have the same.Interface ip address like management.

View 8 Replies View Related

Cisco :: How Many 5508wlc Be Added To Mobility Group

Jun 23, 2011

How many WLCs 5508 can you add to the mobility group?

View 1 Replies View Related

Cisco Wireless :: 5508 Mobility Groups

Sep 1, 2012

1) Is it possible for 2 WLCs installed in seperate data centres with L3 seperation to be joined in a mobility group? We will have aps in the branch offices split between controllers so we want to make sure roaming work ok. Also all guest access should be anchored to data centre 2.
 
2) in flexconnect local switching mode, do I need to create flexconnect groups if I'm only using radius servers in the data centre with no requirement to use local radius as a backup?

View 6 Replies View Related

Cisco Wireless :: 5508 - Mobility Ping And SSH Errors After Upgrade To 7.2.110.0

Aug 7, 2012

After upgrading my 5508s to 7.2.110.0, they are reporting mobility data path errors to one of my WiSMs running 7.0.235.0.
 
I get these messages on the 5508s reporting that it can't send a ping to the affected WiSM:
 
*ethoipSocketTask: Aug 08 21:15:41.175: %ETHOIP-3-PKT_RECV_ERROR: ethoip.c:341 ethoipSocketTask: ethoipRecvPkt returned error
*ethoipSocketTask: Aug 08 21:15:41.175: %ETHOIP-3-PING_RESPONSE_TX_FAILED: ethoip_ping.c:312 Failed to tx a ping response to <ip address>, rc=5
 
But maybe there is another clue because I also see in the same log these errors referencing the same WiSM:
 
*bcastReceiveTask: Aug 08 21:15:45.310: %LOG-1-Q_IND: mm_dir.c:1969 Failed to recreate the SSH Rule for <ip address>.
*mmSSHPeerRegister: Aug 08 21:15:44.829: %MM-1-SSHRULE_CREATE_FAILED: mm_dir.c:1969 Failed to recreate the SSH Rule for <ip address>.
 
Why is the controller trying to SSH to another controller?  Was some SSH related feature added to 7.2 that has been accidentally enabled? 

View 4 Replies View Related

Cisco Wireless :: 5508 Mobility Service Engineer / WCS Required Or Not?

Feb 4, 2013

I have Cisco Wireless Lan Controller 5508 with 35 (3600 Series Access Points.  Do i need to purchase Mobility Service Engine for this or no need?  Do i need WCS server for this or no need?

View 1 Replies View Related

Cisco Wireless :: 5508 - Mobility Groups / Sync Controller Configuration

Jul 7, 2011

I have 2 5508 controllers in a mobility group. Any good way to keep the configuration between the 2 controllers synched up?
 
I thought about copying the config from my primary controller to the secondary controller, but I would think there is a more elegant way to make this happen.

View 5 Replies View Related

Cisco :: WLC 5508 Mobility Groups And Internal DHCP

May 6, 2012

How do Mobility Groups work with internal DHCP scopes on a WLC 5508?We have a WLC 5508 with two internal DHCP scopes which redirect to captive portals for authentication. I am looking at putting in a second WLC in a mobility group setup to provide some WLC redundancy. The LWAPs will be setup so that every second AP is on the has the second WLC as its primary controller. If the primary WLC fails we want the secondary to be able to take over and issue IP's from the internal scope. How do you set this up with a Mobility group so the second WLC does not act as a rouge DHCP server while the primary WLC is still active?

View 6 Replies View Related

Cisco :: 5508 - Failover For Multiple WLCs And Mobility Groups

Feb 14, 2013

We are in a warehouse type setting and have data centers on each side of warehouse with 5508 WLC's in each data center. Each side is on its own subnet with routing in between and a different set of SSID's for each set of WLC’s. Are goal is to have the ability to failover in the event that if one data center goes down AP’s will move to the controllers in the other DC and the clients will still be able to operate.
 
Our thought was to implement mobility groups between the controllers. While I saw documentation on setting this up when the controllers are on the same vlan, I didnt see any setup config when controllers are in different vlans. So I am wondering if mobility groups are even an option for what we want to accomplish. For the most part clients stay on their respected sides of the warehouse and so we are not necessarily needing roaming for clients between controllers in DC1 and DC2. But that does raise another question in that we do have a planned voice wlan that we would like to have the ability to roam between each side of the warehouse. But we have seen ip issues with this. In the past we have had both SSID's setup on each side and ran to issues with clients not renewing their IP address when moving to the controllers on the different subnets.
 
Can we setup mobility groups between controllers on different vlans/subnets? For failover purposes will mobility groups assist in our setup with 2 DC’s and different subnets/vlans? If the answer is yes we can setup mobility groups between different subnets, is there a way to setup the SSID's on all controllers and have the ability for clients to roam and renew their IP’s when moving to a different controller on a different subnet?

View 3 Replies View Related

Cisco Wireless :: 5508 Can't Add 3600 Series AP To Group

Jul 22, 2012

I have an AP group on a Cisco 5508 WLAN controller.  Currently, it is populated with 13 Cisco 1142 lightweight access points.  When I try to add a Cisco 3602i access point to the group, I get the following error in NCS: Error: OfficeExtend requires primary, secondary, or tertiary controller management IP to be set.I am using DNS to allow my AP's to find the controller and they work just fine.  Is there a reason I can't add the 3600 series AP's to the AP group?

View 13 Replies View Related

Cisco Wireless :: 5508 AP Group VLANs Feature Enable

Apr 7, 2012

i have a WLC (5508) - trying to enable AP group vlans based on instructions from: url...however, my problem is that i don't have the 'ap group vlans feature enable' checkbox.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2 - Network Group Authentication

Apr 25, 2011

I'm sure it can be done just haven't been able to find it.  I'm running ACS 4.2 and have 2 network groups, one is wireless where I have a WLC and the other is the default where vpn users authenticate with their tokens.  Is there a way to have the Wireless network group authenticate using AD and the other group use RSA?  I can't find the switch or switches I need. 

View 1 Replies View Related

Cisco VPN :: ASA 5520 Authentication Using Windows NT AD Group?

Feb 3, 2011

I am configuring windows nt authentication on asa 5520 firewall for clientless web vpn. is there a way i can specify to only authentication from the specific AD group only using windows nt or other way?

View 1 Replies View Related

Cisco VPN :: OpenLDAP Group Authentication With ASA5520 RA-VPN

Jul 24, 2011

I've configured RA VPN on ASA5520 with OpenLDAP server authentication. It works fine for all the users existed in LDAP database, but my requirement is I want one particular group to be able to access VPN and not all the users. I have checked most of Cisco documents but all are leading to Microsoft's AD and LDAP attribute map creation. Is there any way to achieve the same thing with OpenLDAP server and not with AD?

View 4 Replies View Related

Cisco VPN :: ASA 8.2.2 Locking Down Anyconnect Authentication To AD Group

Nov 28, 2011

I can't seem to find any documentation to how to get this working. I'm trying to make it so that only users of a certain AD group are authenticated for my Anyconnect VPN on my ASA 8.2.2
 
I've found the documentation on how to prevent logins using the  msNPAllowDialin attribute, but not how to base it on group membership (memberOf) [code] I need to do any kind of restrictions inside the actual group-policy TESTGROUP ?

View 2 Replies View Related

Cisco :: 5508 - AD Authentication For Wireless Networks

Mar 12, 2013

We've recently boughten new equipment to upgrade/replace some of our aging wireless hardware. We're moving to a pair of 5508 controllers and changing over to ACS 5.4. Currently we're just doing MAC filtering with ACS 4.2 and local users. I'd like to move most of our SSIDs to some type of AD authentication. Are there any all encompassing guides that layout the design behind that? So far I haven't had much luck finding one!
 
Also, would it be possible to maintain some of the local ACS users/MAC filtering? We have some mechanical equipment that connects to our network (separate SSID) but cannot join a domain.

View 5 Replies View Related

Cisco Wireless :: WLC 5508 - Web Authentication With Gingerbread 2.3.6?

Jan 7, 2013

I having some troubles with Web Authentication in a WLC 5508 version 7.2 to make authentication with the corporative phones, ANDROID GingerBread 2.3.6 model SAMSUNG GT-S7500L. When I try to connect to the VisitorsWirelessLAN in order to authenticate with web authentication the page never comes, in fact the phone never gets the IP. I have an iPhone and I have not problems, I have a Samsung Galaxy S2 with ICS 4.0.1 and works perfect, is only with gingerbread

View 2 Replies View Related

Cisco Wireless :: 5508 - AAA Authentication Failure

Aug 3, 2011

I've set up several local network users (Security > Local Net Users) on the WLC (5508 running 7.0.98.0). Whenever I try to connect with one of these user accounts (I'm testing this out for now), the attempt is unsuccessful and I see an "AAA Authentication Failure for UserName: xxxxxxx User Type: WLAN USER" in the Trap Log. I thought that after trying to authenticate through a RADIUS server, the local user database would be polled and then a user account in that database would be able to authenticate.

View 1 Replies View Related

Cisco Wireless :: 5508 / How To Configure Web Authentication

Jun 9, 2012

Can we configure the wireless controller 5508 to authenticate the clients using both of MAC address Filtering (layer 2 security) and Web authentication (layer 3 security). and what is the difference between (Web policy --> authentication) and (Web policy --> on MAC filter failure)

View 6 Replies View Related

Cisco VPN :: ASA 5510 - Group-Lock Not Working With Web VPN And RADIUS Authentication

May 16, 2013

I'm on an ASA 5510 running 8.2(5)41. I have clientless WebVPN configured to authenticate against an RSA RADIUS server, which has users assigned to RADIUS Class attribute 25 to match the group-lock values assigned to each ASA group-policy. This of course is to ensure users can only access the login page's drop-down VPN profiles they are assigned to by the RADIUS server. I have two other ASA 5510s (same code level) using the same RADIUS server with group-lock enabled but for IPSec remote access VPN's, and the group-lock feature works fine.

WebVPN, however, is authenticating any user to any VPN profile without regard to the RADIUS Class attribute 25 they are assigned. If I configure the VPN profiles to authenticate locally and assign group-lock to individual ASA user accounts, group-lock works. As soon as I point it back to the RADIUS server, group-lock does nothing. From the 'debug aaa' below for user 'corpvpnstp', you can see the RADIUS server sends back the attribute 25 values of "ou=stp.Client;" and "ou=stp.ClientDRC;" for this user. The ASA profile this user has attempted to connect to is "EMS-Admin", which should get denied by the ASA. Instead, the ASA successfully authenticates the user.

View 4 Replies View Related

Cisco :: WLC 2106 - Take Group B And Point It To A Radius Server For Authentication

Dec 13, 2011

In the WLC there are two groups (say A and B).  How would I take group B and point it to a RADIUS server for authentication? The server is ping reachable.  I have searched  but did not see any definitive answer.

View 3 Replies View Related

Cisco Firewall :: ASA 5510 - Multiple Pools / Group Authentication?

Apr 8, 2011

can i have on asa 5510 multiple pools and multiple group authentication for various departments along with restricted access if any

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS5.1.0.44 Authentication Base AD Group Member

Nov 25, 2012

I had a problem about authentication use AD group member.  Below webiside is the way I config on ACS.

[URL]

I'm using ACS 5.1.0.44 and this version has a bug , ACS cannot read AD group.  I have to add it manually .    After I change the access policy from Internal user to AD1. I can use anyone AD ID to pass authenticaiton. I finished all config from the website had same result.

I checked the access polices -- default device admin -- authorization  , the new rules I created had no hit count.  How can I make sure that I make a right config ?

View 2 Replies View Related

Cisco :: Wireless Controller 5508 Authentication To AD Server?

Sep 11, 2012

We just got a new 5508 wireless controller and the question we have is :  can we get wireless users to authenticate to an Active Directory server to get access to the network?  I know we can get the authentication done with an RSA server, but what about plain AD?

View 9 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved