Cisco Wireless :: 602AP Does Not Work Correctly With 5508 Controller
Aug 16, 2011
Does Cisco 602 office connect AP working correctly with a 5508 controller? As cannot get it to work as having random problems. Ie I see the SSID broadcast on the AP, but no authentication messages for clients on the controller.I have the same configuration setup on a 1142 office extend access point and works fine.The other 602AP i have is seen by the controller, but will not even broadcast the SSID.
E4200v2 DMZ does not appear to work correctly?I have two e4200v2 both with latest firmware and it appears to me that the DMZ setting does not work. I continue to have to apply many port forwarding and triggering rules to make needed ports accessible.
I just upload firmware1.0.1.10 on 2 WAP121. After the update and reboot, I was able to confirm the firmware version in the System Summary menu. The update is uneventful.However, the functions WDS Bridge and WorkGroup Bridge no longer works on two WAP121:
- For WDS Bridge, when I configure a Remote MAC Address with WPA Encryption and then I click on the Save button, nothing happens there. But it works well when I choose without Encryption.
- For WorkGroup Bridge, when I click on the Save button (even without changing the configuration), I have a message "Certificate file uploaded successfully" and another error message in the background: "error occured for query you send path . device.sync ... "
1.0.0.3 firmware is not available on your site, it is imposible for me to go back.
I know that the 3600 series APs are not supported on the 4404 WLC. However, would the following scenario be supported? I would like to use the 4404 (software rel. 7.0) as a guest anchor with a 5508 (software release 7.2) as the foreign controller supporting series 3600 APs. I ask because the APs do not need to join the guest anchor.
I have done this before on this exact model about a month ago, so it's still fresh in my mind on port forwarding. (note, I'm using firmware version: 1.0.00) I am running a windows 7 computer wirelessly using this router.What I do for port forwarding is type in router IP (192.168.2.1) in internet explorer, type in "default" as username and "admin" as password. I click the "applications and gaming" link which brings me to port range forwarding.
I fill in my port info, in this case a mine craft server running on 25565. I set up two of the same ports, different names both at the same port, one running TCP and the other UDP, when it worked previously the "both" option did not work correctly. (I used to have a private network that a buddy of mine set up a while back, and I doubt he remembers what to do and I don't know where the manual is to make a new one, searching the internet sends me spam of people asking questions.)
I read somewhere it may have something to do with DHCP server settings conflicting with my IP. My IPv4 address reads 192.168.2.100, and the DHCP settings says the same.
We have a customer that have 2 5508 as primary and backup controller and a 4400 as an anchor controller. We plan to upgrade the 5508 to 7.3.112.0 and the 4400 is already 7.0.116.0. Will there be any issue if the anchor controller is not the same code as the foreign controller? Do I also have to upgrade the acnhor controller to 7.0.240.0?
I am trying to get the ACS 5.3 to work with NCS but cannot make it work correctly. url...But this does not show how the ACS referencing AD groups would work when determining which custom attributes to use.
On the ACS 5.3 i have set up the following .The ad is working and in Users and identity stores/External identity stores/Active Directory then my AD test works fine.I have set up the Users and Identity stores/Identity Groups with appropriate ip s.I have configured the Network Device Groups/Network Devices and AAA Clients with the ip address and Authenication optionsA.In Policy Elements/Authorisation and Permissions/device administration/shell profiles.I have creeated a shell profile called network shell pro which das a common tasks of def priv = 0 and max priv = 15
Now i can get into the NCS but i do not see any of the administration buttons on NCS - so this means the custom attributes are not working.i shouldnt need a user for this on the ACS as its using AD.
Ok so our company has a VPN set up on our workstation laptops for employees to be able to connect to the office network from home.We use CISCO VPN CLIENT, and a pre-setting .pcf file to upload our vpn into the client. The settings are correct completely to allow the VPN to work from home. All of our older workstations (Latitude D510-D630's) work with Windows XP SP3 32b. Recently i purchased new laptops (Latitude E6410's) and have started issuing them out with Windows 7 Enterprise 64b.A couple employees from home cannot get their VPN to work correctly at home with the New Laptops. Their old laptops work fine with the VPN, but the new ones dont. They are running a Frontier DSL modem with wireless.The VPN connects just fine on the new laptops, but the problem is... Nothing works. Outlook does not connect, They cannot access any of our network shares or drives. And cannot use any of our company's software that requires our network access.
I tried uninstalling the the CISCO Client, and reinstalling it, No Go.I tried changing the MTU Settings on the client and network adapters and wireless adapters, No Go.And it seems to be just an ISSUE with employees trying to VPN through a dsl connection using the new laptops, where others with the new laptops can VPN in fine through a time warner connection. But remind you, their old laptops work fine.. which seems kind of odd to me.
I am user of Dell Inspiron 1545 and I have problem with Internet. Till yesterday everything just worked great, when I was turning on a wi fi, it always found a network I wanted to. Yesterday, the current has been cut of. (?) and I lost connection to internet. After current camer back, everyone got internet back, but not me. My wi fi is still finding almost all networks except one, the most important one.
I have a problems with one SA520W.The LAN port don't work correctly. If i connect PC directly via ethernet cable (i try 2 different cable and 2 different PC) the DHCP don't assign an IP. If i reset to factory default and manual insert IP (192.168.75.1) don't work.
I have hardware version B1, firmware version 2.00NA and several computers (wired & wireless) with Vista & Win 7 x64 and a Brother HL1440 printer.When I print something it comes out scrambled, images missing or cut off, empty pages, etc. This same setup worked fine when it was directly into one computer, then shared on the network though windows sharing. The problem was that computer had to be running to print off the network. I got the dir655 since it had printer sharing but so far its not been of any luck.
First off, my router is a D-Link DIR-655, firmware v2.07. I'm trying to port forward port 25565.
My port forward settings are this:
However, when I use this open port checker, it claims that I don't have that port open. It looks like this, without the blurred out parts:
Added note: The way I want to use it is by my IP (xxx.xxx.xxx.154:25565). I have the software installed to do so (I'm using a minecraft server, connecting through minecraft), but I can't enter my IP in the IP address field, it says that it's out of the range of the LAN.
Im having a issue with that any of my computers without a wireless connection have been incapable of getting out on the internet with the new router that i got myself, i know the cables works etc, since they work perfectly fine with the old modem alone, but wont work at all with this unless on a computer with wireless connection
I have a 5508 controller at our headquarters and am installing some 3502 AP's at a remote branch. Unfortunatly, the remote branch has a different Vlan setup for some reason and the vlan that is used for the WLC (90) is designated for telephony at this branch. Can I put the AP's on a different VLAN (10) without having any issues? I will still use DHCP option 43 to point them back to the controller. Below are the configs for the WLC interfaces and what I am proposing for the AP interfaces:
Cisco 5508 Series Wireless Controller for up to 100 APs 802.11a/g/n Ctrlr-based AP w/CleanAir; Ext Ant; E Reg Domain..For Mobility i want to settup the device such that the SSID would be the same with thesame security key and in different subnet.
I use WLC 5508 (ver 7.0.116.0) with aironet 1140. I need to connect my APs to different controller .After log in via ssh to AP i am trying to do:
capwap ap controller ip add x.x.x.x reset
But after reload, AP is still joined to the old WLC. So another idea was to log to that WLC and put:
config ap primary-base WLC2 AP_NAME x.x.x.x
and after that:
config ap reset AP_NAME
But still nothing, it's joined to another controller although "show ap client config" shows that primary-base switch is x.x.x.x ?How can i force it to join to other controller?
We are looking to upgrade our 5508 wireless controller from 7.0.98.0 to 7.0.220.0. Reason being, we have experienced a lot of access points disassociating from the controller as well as client authentication issues. Upgraded from 7.0.98.0 to 7.0.220.0 and any issues during the upgrade or after the upgrade?
We have a WLC (5508) in our main office in Brisbane that is hosting two WLANs. One provides wireless access to our internal network and the second provides wireless guest access. The guest WLAN is anchored to a controller sitting in the DMZ at our Data Centre.
In the DMZ the anchor controller has a management interface and an interface in the DMZ for the wireless guest access. I am using the DHCP server on the anchor DMZ to provide IPs etc to wireless guest clients. The default gateway is 10.8.144.1 which is a VIP or a pair of firewalls.
Initially everything works fine. Guests connect to the guest network, have to authenticate via a web portal (Cisco ISE server) and then can go on an use the internet. Works perfectly until the firewalls fail over and the secondary firewall takes over the VIP address. All access to the internet is lost at that point. If I try to disconnect and then reconnect a wireless client it connects, as in it will get an IP address, but DNS resolution stops and I do not get redirected to the web auth portal. If the firewalls are failed back to the primary then everything works again, no issues. However, if I reboot the WLC while the secondary firewall has the VIP IP everything will work fine as it did on the primary. If the firewalls now fail over to the primary again everything goes to ****. Until either the firewalls are failed back or the anchor WLC is rebooted.
Initially I thought this was an issue on the firewall, but this doesn't appear to be the case. When the firewall fails over it sends out a gratuitous ARP advising of the change in MAC address for the 10.8.144.1 IP address. The WLC seems to update its ARP table because if I run the command "show arp switch" it has the 10.8.144.1 IP address with the MAC address of the active firewall. From the client perspective I have run a wireshark and captured packets on the wireless interface when trying to connect. The laptop is continuously send ARP requests for 10.8.144.1 but gets not reply. Without this the client cannot send an ethernet frame to the gateway and hence get to the DNS server and WEB portal. Internet access breaks. Doing a TCP dump on the active firewall shows it receiving and then sending a reply to the ARP request. It just never gets to the wireless client. Debugging ARP packets on the anchor WLC seems to indicate that the controller is receiving the ARP replies from the firewall. So I'm at a loss as to why things should break when the firewalls fail over.
I have a 3750 switch in the DMZ with SVI of 10.8.144.4. I thought I could get a work around where I would make this the default gateway. The theory being that this interface MAC address would never change. However I was wrong. Even with this IP set as the gateway address for the wireless clients I see the exact same bahaviour when the firewalls fail over. I can't explain it other than to say that the gratuitous ARP sent by the firewalls seems to kill the ability of ARP replies to be sent back to the wireless client.
Just replaced a 2106(ver 5.1) with a 5508 (ver.7.2)...Everything was OK.. AP's got on 5508 and we shut the 2106. (AP's are on L2 with controller)During some investigation of why new LAP's from a location via VPN/GRE don't show up in controller, i type the following command on 5508: test ap pmtu enable all....All AP's on 5508 is now in Not Joined state..Have powered up the old 2106 and put AP's on that .. This is OK ....Have rebooted/downgraded/upgraded the 5508 controller but with same result.....No AP's can join this controller (exept from a oeap600)
So we have a Cisco 5508 controller that is managing 15 AP's in one of our buildings.I am running 2 wlans, one is internal access via (wpa) radius, peap and domain login...that works well now
The other is a guest lan, that is only allowed to surf the web.
The question from our security group, is there a way to restrict wireless access to ONLY a corporate approved list of devices.
As it stands right now, we only support Blackberry's as our mobility device. All local data is encrypted. The issue here is our testing shows that with an Iphone (not approved) it is very easy to connect to the WPA network if a user knows how to enter in their domain credentials. From there they can browse our internal web servers and download corporate data to a non approved, non encrypted device such as the iphone.
I upgraded a controller yesterday 5508 it went from a low code version 6.x to 6.0.196.0 then to 7.0.116.0. However although all the access points joined code 6.0.196.0 they refused to join 7.0.116.0. The aps are all 1242s.
The country codes etc were all fine so I do not understand what was going on.
*spamApTask0: Jun 26 16:07:44.734: 00:3a:99:db:f3:20 Discovery Request from 10.0.0.183:55065 *spamApTask0: Jun 26 16:07:44.734: 00:3a:99:db:f3:20 Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 25, joined Aps =0*spamApTask0: Jun 26 16:07:44.735: 00:3a:99:db:f3:20 Discovery Response sent to 10.0.0.183:55065 [code] ......
I have one controller 5508 that will hold 50 LAP 1262 and another Controller that will hold another 50 outdoor mesh access point 1552. Both controllers (not redundant) are at the HQ while the access points are distributed between HQ and 3 branches.
The requirements is to have the SAME 4 SSIDs on MESH and LAP each have a security type (, wep,wpa,dot1x...) on HQ and Branches. Now, in the HQ I don't think I will face a problem since the WLCs is on the same LAN, so 5 interface v lans will be configured one for the WLCs and access point and another 4 interface v lans for the 4 SSIDs.
Now, for the remote sites I need to create another vlan on the switch with DHCP and option 43 ..... for the access point to register with the controller.
But here, do I have to create another 4 interface v lans (4 different sub nets) that should be bidden to the SSID as in the HQ?
Or the Access point will encapsulate all the traffic including the client traffic? Note that I have outdoor mesh access point and Lightweight access point and the BW link between the HQ and branch is 100M.
Also Can I have roaming between the same SSID that broadcasted on MESH and LAP knowing that each have different controller.
[URL] I have one Controller 5508 is my Central Office and I have some Ap's working in local mode in my Central Office, additional I have more Ap's in a remote Office they're are working as H-REAP and I can handles across my WLC. Now my enterprise decided bouth another WLC and wants to deploy a active-passive scenario. This new Controller should manages all the AP's when the central WLC fails...
My questions are... I need to have the same ip addressing on both sites? or they can be different. I nedd to configure some on my Ap's that are working as local mode, for allow the secondary WLC manage them when mi central WLC fails
I received a 5508 WLC, that I wanted to configure as a guest anchor for our DMZ. I stepped through the console configuration. Now that the setup is complete, can I attach my laptop directly to the copper SFP, and access the WLC web portal? I gave my laptop an IP address, in the same subnet, but still can't connect to the portal, or ping the WLC IP address.
We have 3 5508 WLCs (A, B, & C) and several LAPs (1140, 3500, 3600). The APs learn the controllers IP addresses through DHCP Option 43. When we setup a new site we put the IP address of the controller we want the AP to join first. Lately, I've noticed that regardless of which WLC IP I put first when I setup Option 43 the LAPs are always joining a particular controller.
I have an AIR-AP1242AG-E-K9 which had c1240-k9w8-mx.124-21a.JA loaded, I followed the link below and upgraded with Cisco’s upgrade tool to c1240-rcvk9w8-mx with no problems at all, after the upgrade I could then see the LWAP on the 4402 controller and had it working a treat.Now the problems begin, I brought it into the office where we have 5508 controllers, plug in the LWAP into our management switch and boot it up I get an IP assigned from the DHCP server and the AP goes into discovery mode but never finds the controller.I have logged the boot process but this does not give much away, our other 1100 series AP’s boot fine,
[URL]
Console Boot Log. Xmodem file system is available. flashfs[0]: 9 files, 3 directories flashfs[0]: 0 orphaned files, 0 orphaned directories flashfs[0]: Total bytes: 15998976
[code]....
And that is where she sits and does nothing more, I have noticed the DNS problems but the other 1100 series LWAP’s boot up after show that same issue.
We just got a new 5508 wireless controller and the question we have is : can we get wireless users to authenticate to an Active Directory server to get access to the network? I know we can get the authentication done with an RSA server, but what about plain AD?
how to setup the 5508 Series LAN wireless controller. The online documentation are not details. What different between Service Interface IP and Management interface IP. The device IP is using what type service or management interface.
how an AP 3500 get to be registered in a controller 5508??, so, i have seen a lot of information of wireles deployment guide but i haven't understood yet how the process or flow is for getting the AP to be registered in a controller 5508, what exactly basic configuration must be done in a controller for doing it?
Our 5508 Wireless Controller will drop MAC addresses clean out of the system. Addresses that are in use everyday just disappear. It is not a limitation issue because we are adding iPads everyday. And it is not a daily occurance, but maybe once or twice a week. Everything has been updated and it is more of a hassle than anything, I am just trying to understand what is happening.
I am having some troubles with client roaming on a 5508 controller running firmware 7.3.101.0. As soon as a client roams outside the range of an AP they lose data flow and do not seem to transition to another AP for about 1 minute.This is a small network with 6 x AIRCAP3502E-N-K9 AP's (running in H-REAP mode) on the same floor and clients are a mix of HP notebooks, Mac Books, iMacs, iPads and iPhones. There are several seperate SSID's setup and the problem occurs on all. All are WPA2/AES with either a PSK or 802.1X. Both 2.4GHz and 5GHz radios are enabled with auto power and channel selection.
I have tried changing the roaming settings from default and also playing with the AP power settings to no avail.Is this normal behaviour or is there something I can do to improve the reconnection speed?