Cisco Wireless :: AES128 - Traffic From Guest User Encrypted?

Sep 12, 2011

The design is typical Cisco unified wireless solution. In such a implementation, is the traffic from the guest user who has successfully authenticated via WEB-AUTH encrypted? If so, what is the standard used, AES128 or TKIP?

View 6 Replies


ADVERTISEMENT

Cisco :: VPN Client Traffic Encrypted Check

Oct 12, 2012

How can we check when we connect using VPN client software if traffic is getting encrypted ?

View 7 Replies View Related

Cisco VPN :: ASA 5505 - No Return Traffic Is Being Encrypted

May 26, 2012

I've configured an ASA5505 to be  Lan to Lan VPN tunnel endpoint, peering with a linux box.  The ASA is full licensed so that side isn't an issue.PROBLEM:When the tunnel is initialised from the linux box everything comes up okay except the ASA isn't encapsulation any packets.  It is decrypted the packets received from the Linux box okay but no return traffic is being encrypted.When the tunnel is initialised from the ASA, nothing happens.After some troubleshooting I've found that the ACL defining interesting traffic nor the ACL defining NO_NAT aren't being hit at all.
 
ACL for NO_NAT:
access-list NO_NAT line 1 remark ACL USED TO DEFINE WHAT TRAFFIC NOT TO NAT OVER THE VPN
access-list NO_NAT line 2 extended permit ip host PAMS_SERVER object-group LINUX-BOXES 0xc736d5fb
access-list NO_NAT line 2 extended permit ip host PAMS_SERVER 10.11.228.0 255.255.255.0 (hitcnt=0)

[code]....
 
I've checked with the administrator of the linux box and the definition for interesting traffic is exactly the same (except in reverse as should be the case).The firewall is doing other things like NATs and such like too but those NATs have nothing to do with this VPN.  The setup is a LAN to LAN connection with no natting in between.The main parts of the config are attached, i've deleted things that should have a bearing on this however if you think it necessary i can sanitise the config and re-post.  I think it will be working fine as long as the traffic hits those ACLs, however they're not and I'm unsure why.At this time i'm not seeing anything at all when doing an debug cry ipsec or debug cry isa.  The ACL's aren't being hit so i'm guessing it's not even trying to form the VPN as it can't see any traffic that constitutes being 'interesting'.

View 4 Replies View Related

Cisco VPN :: C6509E - Limitation For Encrypted Traffic

Sep 14, 2011

I have
MLS : C6509-E
SUP : VS-S720-10G
PFC : VS-F6K-PFC3CXL
 
I'm trying to find out what is its limitation for encrypted traffic via SVTI there .
 
I don't have a SPA for the ip sec .

View 2 Replies View Related

Cisco Wireless :: Allow User To User Traffic On WLC 5500?

Nov 21, 2012

Is it configurable to allow wifi user to user traffic on WLC 5508?

View 4 Replies View Related

Cisco Wireless :: WLC 2504 - Guest User Life Time?

Sep 19, 2012

Cant we create a guest user login with more than 30 days lifetime? In the lifetime field we can enter maximum 99 but it only allows up to 30

View 5 Replies View Related

Cisco Wireless :: WCS Creates User Guest Access On WLC 5508

Feb 23, 2012

In my Wireless network, I have two appliances WLC 5508 running version 7.0.116.0.I have a WCS running version 7.0.172.0, deployed on a windows 2003 server.I've imported the two WLCs in my WCS in order to centralize the monitoring and the configuration tasks.Now I'm facing an issue when I want to create a guest user from the WCS, rather than creating this user access on each WLC. The creation of the user account is working good, the replication is done on the both WLCs, but on one of my WLC the guest user account is deleted after one hour(around).On the second WLC, the same user account remains during all its life time.In attachment a screen shot of the advanced parameter of the guest user.You can see that the user was created on the both WLC but is only active on one ... and unfortunately the wrong because the AP is associated with the other WLC.

View 2 Replies View Related

Cisco Wireless :: 5508 - Export Guest User Accounts To New WLC

Dec 19, 2012

I've got a WLC5508 (7.0.116.0) that is managed by WCS (7.0.172.0). I set up another WLC5508 with the same code and managed by the same WCS. Now I'd like to export all the 800 guest user accounts with the passwords from the old WLC and import them into the new WLC.

View 10 Replies View Related

Linksys Wireless Router :: Guest / User Authentication E2000?

Jul 7, 2011

E2000 has the guest account feature.  Not sure if all guests shares the same login credentials.  I would like to have guests account use seperate logins.  Is this feature available?  Another thing, I read the manual and it is indicated that only up to 10 maximum guest acccounts is allowed.  I am looking for more than 10 - kinda like a hotspot software.
 
I've been looking everywhere.  I've seen hotspot system, ddwrt, chillspot, etc.  But it's complicated as firmware needed to be flashed.

View 1 Replies View Related

Cisco Wireless :: 3502 - WLC User Rate Limit On Guest SSID Anchor Controller

Jul 30, 2012

We have been deploying 3502 APs remotely to locations with full T1s that backhaul to where I sit at HQ. Both the foreign and anchor controller are here at my location.
 
I am seeking to rate limit per user the bandwidth each client will get on the guest internet ssid. As you know this traffic is encapsulated in capwap between the AP and the controller so I cant use a standard ACL on the switch or router.
 
We are trying to keep the guest internet access usage in check on the T1 at any given site so the other ssid's & local lan traffic is not overly competing for the bandwidth.
 
I found the place to edit the default profiles in the controller but the documentation really isnt clear on best practices.
 
So I put it to you my fellow wireless engineers to suggest how you are implementing bandwidth management on your wireless guest internet.
      
Oh and here is my hardware & software levels.
 
5508wlc - forgeign
4402wlc - anchor
Software Version7.0.230.0

View 3 Replies View Related

Cisco Wireless :: 5508 - Bypass / Remove Certificate Page For Guest User WLAN

Jul 24, 2012

When a guest user first trys to access the "guest" WLAN, they are presented with a "certificate page" before the web athentication page / login  is presented.  The WLC forces an internal redirect to https://1.1.1.1 causing the certificate page to appear.  Can this be bypassed?    I am runiing 5508 with   7.0.220.0. 

View 12 Replies View Related

Cisco Wireless :: WLC 5508 - Segregate Traffic Log Guest

Dec 30, 2012

We have Cisco WLC 5508 in our network and right now ,this WLC is connected to two ports of each core switches.Both CORP and GUEST SSID are configured on this WLC. Now we want to segregate the traffic log GUEST to on core switches from WLC. SO my question is ,how can we achieve this without using guest anchor controller ? Can i use one interface Cisco WLC 5508 and connect it to the firewall or any device ?

View 17 Replies View Related

Cisco :: 5508 - Guest Wireless Traffic To Blue Coat Web Proxy

Jan 17, 2012

In my lab I have a Guest Wireless network setup and fully functional. Here is a brief diagram:
 
Client -> AP -> LAN switch and WLC-Foreign -> Core router -> DMZ switch and WLC-Anchor -> Edge Router -> Internet

I have NME for credential management on the LAN as well.The WLC-Foreign is a 5508.In my DMZ, I have two networks - 1 for normal DMZ management and 1 for Guest Wireless.
 
I now have to add a Blue Coat web proxy appliance into the DMZ and have Guest Wireless traffic pass through it. I have tried multiple scenarios including connecting the WLC-Anchor to the Blue Coat directly and making the Blue Coat the gateway for my Guest Wireless network. Any good design for the DMZ networks and/or routing to enable the Guest Wireless traffic to go to the Blue Coat and then out to the Internet?

View 11 Replies View Related

Cisco Wireless :: WAP321 - Isolate Traffic Of Guest Captive Portal From LAN?

Oct 14, 2012

I have 1 WAP321 for guest access. Now I need to isolate traffic of guest captive portal from my LAN.How can I do this?

View 1 Replies View Related

No Wifi Connection For Guest User

Oct 30, 2011

i am loaning my laptop to a friend to use while traveling and I have created a "guest user" account so he doesn't have to go through my home pages and personal files. Well, whenever this account is being used, there is no WiFi connection logo and so it cannot be connected to the internet via WiFi...

View 1 Replies View Related

Cisco Wireless :: WAP4410N Does VLAN Tag Setting Need To Be On Tagged To Determine Private From Guest Traffic

Mar 6, 2012

We are trying to setup a WAP4410N with 2 SSID's.  One SSID for our private network and the other for guest internet access.  On the VLAN and QoS page there is a setting for priority.  What would be the suggested values for this setting?  We obviously want our private network to receive priority over our guest network.Also, does VLAN Tag setting need to be on Tagged to determine private from guest traffic?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: Can Use ACS 5.2 As Guest User Authentication Server?

Jun 5, 2012

Can use ACS 5.2 as Guest user authentication server?

View 3 Replies View Related

Cisco :: 2100 Can Create A Guest User Directly On ISE

Oct 10, 2011

I have an instance of ISE and NCS with a WLC 2100 plus a couple of LWAPs. This is an evaluation POC lab to sell ISE and NCS to our management to make our life easier.The problem I have amoungst many is I can create a guest user directly on the ISE and the guest can login, the ISE monitor shows the guest authenticates but the clients webpage passes them back to the login page not onto the original client url. The web auth is pointed at the ISE/guestportal/portal.jsp page.If I point the web auth at the internal WLC page using a WLC local user account it works.If I set the guest access to pass through it works without issues getting dhcp and dns. On the ISE is there a policy needed to say if guests are web authenticated give them access? The need is for AD authenticated users to be able tocreate guest users. The AD authentication works for sponsorship and guest creation its just the guest access redirection I am having issues with.

View 1 Replies View Related

Cisco :: WLC 4400 - Create Guest User Accounts

Jun 13, 2011

(WLC 4400) which enables employees to browse to a custom made webpage, where they can create an account for company vistors to access the internet. It's important for the employees not use any login credentials, they arrive on a webpage where they specify the login & password which the vistor will enter to browse the internet. Is there any good link to documention about this topic?

View 3 Replies View Related

Cisco :: WLC 5508 / Guest User Session Validation Failed

May 31, 2012

I am running a guest wireless network on a Cisco 5508 WLC with 6.0.202.0 code. My syslog is filling up with the following error message:

WLC: *May 15 12:32:59.244: %AAA-3-VALIDATE_GUEST_SESSION_FAILED: file_db.c:3968 Guest user session validation failed for guest_user10. Index provided is out of range..
 
The user that is assigned to the guest_user10 account works fine and has no idea this error is occurring.
 
This error message is occuring exactly every 15 minutes 24x7.
 
I believe I have a rogue user who has setup a device to try and login to the guest network automatically, every 15 minutes with the guest_user10 credentials. I need to track this device down. I need a way to find either the MAC or IP address of the device that is causing this error message. I have tried turning on AAA debugging on the controller but I dont get anything more than the above error. I have also tried using WCS to look at the client history but it only show the normal activity.

View 3 Replies View Related

Cisco :: ASA 5520 - Don't Allow Guest Traffic Access Internal Network

Feb 28, 2013

I have created a new sub-interface on our ASA 5520 for guest internet access.

My goal is to allow access to a few specific services hanging off some dmz interfaces on the same firewall and full unrestricted access to the internet only. Everything else should be out of bounds.

The order of the rules I plan to setup on the guest interface inbound are:

#1. <rules to allow access to specific services in the dmz>

#2. <block any ip access to the entire private network ip address space>

#3. <permit ip any any>

#1. These rules will give access to the guest user to services located in the dmz

#2. This rule will block all access to any services in the private ip address space (thus blocking access to all internal services)

#3. This rule is to allow access to any other services i.e. the internet.

Is this the best way to achieve my goal in the most secure way or is there a better way? i.e. is there a way to force the traffic by default to only go out the outside interface unless there is a specific rule allowing it go elsewhere?

(Of course Dynamic PAT will also be configured for traffic coming from the guest interface to the outside interface.)

View 2 Replies View Related

Cisco :: 5508 WLC / Block Guest MDNS Traffic On Business LAN?

Jun 19, 2012

For my company, I am running a Cisco 5508 WLC with a 4400 WLC as a guest anchor in our DMZ.  There is a guest SSID and several business SSID's for internal equipment.  Guest traffic should be tunneled out to the 4400 controller where [the client] gets its IP address and is sent out to the internet.  No internal corporate access is possible.  However, when I do a packet capture from my wired PC, I'm seeing traffic generated by different iPhones.  It appears to be mostly IPv6 mDNS or ICMPv6 traffic.  How would this traffic make it onto the corporate wired network, when it should be staying on the guest network?  None of the iPhones have been setup on the business SSIDs, so I know it isn't legit traffic.  Is there a setting in the WLC that will block this?  Will an ACL work?
 
These are examples of some of the traffic that wireshark is capturing:
 
349          7.794875          fe80::e77:1aff:fe3c:f81          ff02::fb          MDNS          253          Standard query response PTR, cache flush Tonyas-iPhone-2.local PTR, cache flush Tonyas-iPhone-2.local
 356          7.802667          fe80::e77:1aff:fe3c:f81          ff02::fb          MDNS          151          Standard query ANY Tonyas-iPhone-2.local, "QU" question ANY Tonyas-iPhone-2.local, "QU" question
 361          7.806964          fe80::e77:1aff:fe3c:f81          ff02::fb          MDNS          151          Standard query ANY Tonyas-iPhone-2.local, "QM" question ANY Tonyas-iPhone-2.local, "QM" question
 
Both controllers are running software version 6.0.196.0.  I also have a WCS server running version 7.0.220.

View 3 Replies View Related

Cisco Firewall :: ASA 5505 - All Traffic From Guest VLans To Always Go To Outside Interface

Mar 15, 2013

I have a ASA 5505 with the security plus license. I have 7 vlans, 2 are guest vlans for wireless and wired connections.  I am allowing traffic from the guest vlans to any with the http & https protocols I have ACL's in place before the allow all rule that do not allowed traffic from the guest vlans to the other vlans. Is there any way to have all traffic from the guest vlans to always go to the outside interface for the http & https traffic in stead of trying to go to the other vlans first, I know I have the ACL's in place to prevent the traffic but if I would feel better if I had this in place as well.

View 5 Replies View Related

Cisco VPN :: ASA 8.4 - Limit IPSec User Traffic Volume

Nov 22, 2012

Is there anyway to limit a user's traffic volume on ASA8.4? if there is, how?

View 3 Replies View Related

Laptop Won't Connect To Any Encrypted WPA2 Wireless?

Jan 13, 2012

This is a 5-year-oldish Gateway MX-6124 laptop running under Win XP 2002, SP3. I'm using SureWest DSL, with an ISP-supplied ComTrend NexusLink 5631 Modem/Router. The router is set up as a Secure Network, using WPA encryption. The laptop wireless operation light toggles off/on correctly using Fn-F2 control keys.I can connect to an open or non-secured wireless router, & have verified that at my church, at the Public Library, and at Starbucks. However, I cannot successfully connect to a passworded secured wireless source. I tried to use a secured network connection at my church yesterday, and could not connect. It "tries & tries" and eventually gives up and displays a cannot-connect type of message.

The laptop has worked correctly for several years on my home wireless network. It only stopped working about 3 or 4 weeks ago. I cannot recall changing anything in setup; I probably did it accidentally.I've spent about 2 hours in a couple of sessions with SureWest tech support. They diagnosed router setup using direct connect to the router, plus they talked me through several attempts at configuring the wireless config setup on the laptop. Everything I reported to them on the config settings appeared to be just fine. They also deduced that the wireless config on the desktop & router was correct.SureWest techs finally concluded that something was wrong with my laptop software config or the hardware, disabling it from making a encrypted connection. That sounds right to me, now having witnessed the secured connection failure described above, at my church wireless site.

I've looked at all the refs & things I can think of, plus followed step-by-step directions a couple of times with the SureWest techs. They rightfully pointed out that they could not make a tech support repair call on what did not appear to be a SureWest-related problem.I can easily make screenshots of any config screens needed on the laptop & upload to this forum.

View 5 Replies View Related

Cisco VPN :: ASA 5510 - How To Enforce User Internet Traffic To Tunnel

Jun 4, 2011

here is my situation:
 
home users ------ internet ------ ASA 5510----- CORP LAN
 
we have anyconnect VPN and remote Ipsec VPN, i think the solution should works on both of them. my question is : "How to enforce home user internet traffic to VPN tunnel ?" we have "split tunnel" to pass only ""interesting traffic" to VPN tunnel access CORP LAN. but now , i need enforce all user traffic (internet +CORP LAN) pass through VPN tunnel. so far , i did what i know :

1. remove "split tunnle" from group-policy

2. the address in "remote VPN user address pool" are could be NAT/PAT through ASA5510

but i don't get that why it doesn't work.

View 9 Replies View Related

NSA 2400 - Tool To Monitor Web Traffic For One Specific User?

Feb 5, 2013

I am trying to find a tool that will monitor the web traffic for one specific user. If it is capable of bundling it into a report that would also be a benefit. I have searched, but not come up with much aside from broad network monitoring tools. All that is really needed is to capture all the activity from http traffic for this one specific user/PC (since she uses the same PC all the time). We have a Sonicwall NSA 2400 as our internet filter, but I was not able to locate anything on there for specific user reporting.

View 2 Replies View Related

Cisco Switching/Routing :: 3750 - Route Traffic From Server To End User?

Jun 3, 2013

Actually i have a design from my customer who have ( Cisco core switch 3750 (allports fiber ports) which is connected to L2 switches , these switches carry servers and end users .the only routing protocol on the access switches is static route ,
 
My question how can i route the traffic from the server to the end user , as the the server is not direct connect to the core switch.

View 6 Replies View Related

Cisco WAN :: 1921 Traffic Shaping Feature Is Not Supported In User Defined Class

Oct 29, 2011

I make qos on VPN Tunnel, but i make command service-policy output name, it show the error below Traffic Shaping feature is not supported in user defined class of parent level policy.My cisco router 1921, IOS : c1900-universalk9-mz.SPA.150-1.M5.bin

View 1 Replies View Related

Dell :: Inspiron 7520 Unable To Connect To Encrypted Wireless Connection

Nov 30, 2012

I have a new Inspiron 7520 and having issues with connecting to my secure network.   In trying to troubleshoot the issue,  I've discovered I can connect to my network when the connection is unsecured.  When its encrypted, my connection is only limited (no IP address assign).   I've also downloaded and installed the latest drivers with no resolution to my issue.   

PC and Network Specifics:
PC - Inspiron 7520Wireless Router = Netgear N600 - model WNDR3700Wireless Network - 2.4GHz b/g/n, WPA2-PSK [AES]
System - Windows 8, 64-bitWindows IP Configuration

[Code]......

View 3 Replies View Related

Linksys Wireless Router :: EA4500 Guest Network - Losing Guest Clients After About 24 Hours

Oct 17, 2012

Any problems with the guest network on the ea4500 with the cloud firmware?   I am losing guest clients after about 24 hours and the re-authentication fails. you enter the guest  password and nothing happens until you reboot the router. 

View 2 Replies View Related

Network Is Showing Up As Encrypted?

Sep 23, 2011

I reloaded XP on an old laptop I have, a Toshiba Satellite, and it works fine. Problem is when I try to connect to my wireless network, it comes up as being security protected...and it isn't...and never has been. I have other computers connecting just fine, but I can't seem to figure this one out. I don't have a key to enter as there isn't one! I installed a USB wireless adapter, and it works fine, but I don't want to use the adapter on the laptop.

View 6 Replies View Related

Cisco VPN :: ISR1921 PPTP VPN With Encrypted Password

Sep 19, 2011

I am actualy trying to make a remote access VPN between a ISR1921 and Windows 7 pro. I already managed to put a PPTP VPN with an authentication against our LDAP databse via radius. But our password are in SHA1 in our LDAP, so I had to let the password unencrypted on the network using pap and this is bad.If I don't use pap, it simply doesn't work since all the other method need unencrypted password for the challenge authentication.Does that mean that every remote access VPN keep our password unencrypted ? Maybe use EAP (but I can't find a howto or good documentation about it)? Can I add a certificate or something?

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved