Airport and Cisco Aironet over Radius

Does anybody know how to configure a MacBookPro with built in Airportcard to connect to Cisco Aironet 1231 WLAN Router with LEAP Authentication over Radius Server?? I can connect to it when no security is activated but if LEAP is on no connection and no request is on the Server from the Client??!! Thanks in advance.

Does anybody know how to configure a MacBookPro with
built in Airportcard to connect to Cisco Aironet 1231
WLAN Router with LEAP Authentication over Radius
Server?? I can connect to it when no security is
activated but if LEAP is on no connection and no
request is on the Server from the Client??!! Thanks
in advance.
I am having the same problem with my MacBookPro. Currently, I have supplied data to Apple's engineers from my machine as this is a known problem with MacBookPro's. AluminumG4 notebooks have no trouble authenticating; therefore, this may be a problem with the Atheros chipset. I am hopeful that the next version update will fix the problem, but don't have any information from Apple to support that optimism.
Good luck,
Norm

Similar Messages

  • How to configure AD and Token server (over radius) authentication

    Dear forum,
    I have a scenario where users should be allowed network access after their have given their AD credentials and a token (Blackshield Token server).
    The token server speaks over radius to the cisco ACS appliance. I have managed to get users authenticated by means of their AD credentials. I am how ever not able to use both means in order to have a successfull authentication.
    Does anyone have a configuration example for this scenario? Any help would be greatly appreciated.
    Thanks!!!

    Hi,
    I have had two deployments using this form of authentication.
    Just so we are on the same page, the token servers that I have integrated connect to an Active Directory server running NPS (MS radius), then the user will have to send their password+token and the token software will check the account password, and then the token to see if the users succeeds.
    Let me know if that is the design of your software. If it is, then all you need to do is configure the token software to run on radius and then set the policies up from there. From the network device standpoint it just needs to point to the radius server.
    Thanks,
    Tarik Admani
    *Please rate helpful posts*

  • IPhone4 and Cisco Aironet 1141 access point - fail using WPAv2 Personal

    I cannot get my iPhone4 (latest s/w) to connect to a Cisco Aironet 1141 access point if I specify WPAv2 Personal. It is a single access point without radius etc. I have no problems connecting using "no security", WEP or WPAv1. Is there a problem with the iPhone4 implementation of WPA2 as all my other PCs connect just fine on WPAv2?
    With the Aironet 1141 I can switch security between WPAv1 & WPAv2 while keeping all other settings identical. Thus I can clearly demonstrate how the iPhone4 connects when both devices are set to WPAv1 yet will fail to connect when I switch both to WPAv2. As I have said, all other PCs I have connect via WPAv2 without any issues.

    I cannot get my iPhone4 (latest s/w) to connect to a Cisco Aironet 1141 access point if I specify WPAv2 Personal. It is a single access point without radius etc. I have no problems connecting using "no security", WEP or WPAv1. Is there a problem with the iPhone4 implementation of WPA2 as all my other PCs connect just fine on WPAv2?
    With the Aironet 1141 I can switch security between WPAv1 & WPAv2 while keeping all other settings identical. Thus I can clearly demonstrate how the iPhone4 connects when both devices are set to WPAv1 yet will fail to connect when I switch both to WPAv2. As I have said, all other PCs I have connect via WPAv2 without any issues.

  • WLC 5508 and Cisco Aironet 1242 LWAPP AIR-LAP1242AG-A-K9

    i have deployed wlc 5508 ( image 7.0.98.0 ) with 1262N AP and all 45 AP's are working fine,
    at the same site i had AP1242 which i have converted to LWAPP (8 of them), these accesspoint are registerd perfectly with 5508 but non of the radio's are up. i have selected different countries according to the part numbers but unfortunaly non of the radio's are coming up, pleaes help
    Sathees

    Available:370.0(w)  Used:32.4(w)  Remaining:337.6(w)
    Interface  Admin    Oper     Power        Device           Class
                                (Watts)                           
    Fa0/1      auto  off           0.0  n/a                  n/a      
    Fa0/2      auto  off           0.0  n/a                  n/a      
    Fa0/3      auto  off           0.0  n/a                  n/a      
    Fa0/4      auto  off           0.0  n/a                  n/a      
    Fa0/5      auto  off           0.0  n/a                  n/a      
    Fa0/6      auto  off           0.0  n/a                  n/a      
    Fa0/7      auto  off           0.0  n/a                  n/a      
    Fa0/8      auto  off           0.0  n/a                  n/a      
    Fa0/9      auto  off           0.0  n/a                  n/a      
    Fa0/10     auto  off           0.0  n/a                  n/a      
    Fa0/11     auto  off           0.0  n/a                  n/a      
    Fa0/12     auto  off           0.0  n/a                  n/a      
    Fa0/13     auto  off           0.0  n/a                  n/a      
    Fa0/14     auto  off           0.0  n/a                  n/a      
    Fa0/15     auto  off           0.0  n/a                  n/a      
    Fa0/16     auto  off           0.0  n/a                  n/a      
    Fa0/17     auto  off           0.0  n/a                  n/a      
    Fa0/18     auto  off           0.0  n/a                  n/a      
    --More--                          
    Interface  Admin    Oper     Power        Device           Class
                                (Watts)                           
    Fa0/19     auto  off           0.0  n/a                  n/a      
    Fa0/20     auto  off           0.0  n/a                  n/a      
    Fa0/21     auto  off           0.0  n/a                  n/a      
    Fa0/22     auto  off           0.0  n/a                  n/a      
    Fa0/23     auto  off           0.0  n/a                  n/a      
    Fa0/24     auto  off           0.0  n/a                  n/a      
    Fa0/25     auto  off           0.0  n/a                  n/a      
    Fa0/26     auto  off           0.0  n/a                  n/a      
    Fa0/27     auto  off           0.0  n/a                  n/a      
    Fa0/28     auto  off           0.0  n/a                  n/a      
    Fa0/29     auto  off           0.0  n/a                  n/a      
    Fa0/30     auto  off           0.0  n/a                  n/a      
    Fa0/31     auto  off           0.0  n/a                  n/a      
    Fa0/32     auto  off           0.0  n/a                  n/a      
    Fa0/33     auto  off           0.0  n/a                  n/a      
    Fa0/34     auto  off           0.0  n/a                  n/a      
    Fa0/35     auto  off           0.0  n/a                  n/a      
    Fa0/36     auto  off           0.0  n/a                  n/a      
    Fa0/37     auto  off           0.0  n/a                  n/a      
    Fa0/38     auto  off           0.0  n/a                  n/a      
    Fa0/39     auto  off           0.0  n/a                  n/a      
    Fa0/40     auto  off           0.0  n/a                  n/a      
    Fa0/41     auto  on           15.0  cisco AIR-LAP1242AG  Class 3  
    --More--                          
    Interface  Admin    Oper     Power        Device           Class
                                (Watts)                           
    Fa0/42     auto  off           0.0  n/a                  n/a      
    Fa0/43     auto  on            5.8  cisco AIR-LAP1242AG  Class 3  
    Fa0/44     auto  off           0.0  n/a                  n/a      
    Fa0/45     auto  on            5.8  cisco AIR-LAP1242AG  Class 3  
    Fa0/46     auto  off           0.0  n/a                  n/a      
    Fa0/47     auto  on            5.8  cisco AIR-LAP1242AG  Class 3  
    Fa0/48     auto  off           0.0  n/a                  n/a     

  • Apple MAC Bonjour and Cisco Aironet 1142

    Hi All,
       Hope all is well.
       We have a strange issue with our two Aironet 1142s and how it interacts with our Apple laptops. When we try printing to a printer in one room connected to (let's call it Aironet 2) we can't. We attempt to browse using Bonjour (Apple's protocol) to the printer and can't. HOWEVER.. we can print and browse fine when we're using Aironet 1.
       Another strange thing is when we're on Aironet 2 we can ping to the printers just fine, just can't browse to is using Bonjour nor print of course.
    Please help! Any inputs appreciated.
    -Tom

    Natalia,
    You need to do the following to make Bonjour printing to work.
    Have multicast enabled on the wired side for all the vlans involved (management, ap manager, client, APs). if any of these vlans are not properly setup, then bonjour will not work.
    Wired Side:
    Router:
    ip multicast-routing (enable multicast globally)
    For each vlan interface enable ip pim sparse-dense-mode:
    conf t
    interface vlan x
    ip pim spare-dense-mode (there may be a syntax error, dont have router access at the moment)
    also you may need to configure a rendevouz point which you can set to layer 3 interface of the management vlan.
    For example (management ip 10.1.1.10 and g/w is 10.1.1.1)
    ip pim rp-address 10.1.1.1 (again syntax maybe incorrect)
    Note: you will have to configure the same on all routers in between the WLC and the APs
    Also make sure that the ipads/iphones and wireless printers are connected to the same ssid (same vlan). Bonjour uses link local address which are not routable.
    on the WLC, set up multicast multicast mode with a unique mutlicast ip address. Also, on the multicast tab, Controller > multicast > enable global multicast.
    There is a catch here. You will mostly likely have to turn off IGMP snooping on the controller (controller > multicast > disable igmp snooping).  I have learnt it the hard way that some of the apple devices dont send the igmp join reports.

  • Linksys WRT54G with Cisco Aironet antennas

    Hi Cisco users,
    I've got a small project:
    I need to provide a wireless network from a farmhous to a piggery:
    Distance about 40 metres, no obstructions
    Equipment:     Linksys WRT54G v3.1
    When i place the wrt54g to the most far point of the house (towards the piggery) i get a fairly stable signal of around 11Mbps
    I want to strengthen the signal via an external antenna, preferrably outdoor.
    i'm thinking of this antenna:
    Cisco Aironet 8.5-dBi Patch Antenna (AIR-ANT2485P-R)
    http://www.cisco.com/en/US/docs/wireless/antenna/installation/guide/ant2485.html
    or the same one as above only with 6 dBi.
    http://www.cisco.com/en/US/docs/wireless/antenna/installation/guide/ant2460.html
    Both the linksys and cisco aironet antenna's has RP-TNC connectors.
    My questions:
    1: Can cisco aironet antenna's work with a linksys wrt54G, based on the same connectors.
    2: Is the antenna strong enough? can i cover a distance of 40/50 meters with this antenna, or with the 6dBi version?
    3: it's a directional antenna. the piggery is straigh ahead of the farm house. How much beam width do i have on the end of the signal for coverage?
    4: maybe i need an extension cable. is this the right one?
    Cisco Aironet 5-ft, low-loss, 2.4-GHz RF cable with RP-TNC connectors (AIR-CAB005LL-R)
    http://www.comegacity.com/networking-wireless-b-bn/antennas-cables/cisco-air-cab005ll-r-aironet-5-low-loss-cable
    Thanks in advance.

    The connector has to be the same but also the impedance. Cisco APs are at 50 ohms. Not sure about linksys ...
    Otherwise if you put the antenna outdoor and there is no obstacle, 40/50m should be reached with those antennas. Take the lowest length of cable possible to put the antenna outdoor though as cable brings loss.
    I can't comment about if the 6dbi will be enough as this would require experience with the same hardware which I don't have.
    My 2 cents
    ===
    don't forget to rate answers that you find useful

  • Configuring Cisco Aironet 1140 for Radius and setting up a Radius server

    guys i need some help setting up my Radius to work with cisco aironet 1140, i am new at this however i was tasked with setting up a Radius server and setting our AP with WPA2- enterprise so users can log into our AP using AD credentials.
    When i try to setup on the AP a new SSID i do not see the option for WPA2- enterprise?

    Here are other links with examples:
    https://supportforums.cisco.com/thread/331581
    http://targetcisco.blogspot.com/2011/03/cisco-autonomous-access-point.html
    http://downloads.avaya.com/css/P8/documents/100041614
    Thanks,
    Scott
    Help out other by using the rating system and marking answered questions as "Answered"

  • Cisco Aironet and Apple Airport - Pb with roaming

    Hello,
    I'm having a problem with roaming between one Cisco Aironet 1232AG AP and one Airport Extreme basestation. Both AP are on the same subnet, hidden network and WEP 40bits.
    0->Cisco->Apple->Cisco->....... works fine
    0->Apple->Cisco doesn't works
    0-> means Pwk restarted
    Any clues?
    Thanks

    No. I tried with both AP on the same channel or on a different channel same issue. Also, same problem with WEP 128bits. However the issue disappears with WPA personal (TKIP or AES-CCMP)

  • Server 2008 R2 RADIUS Server with a Cisco Aironet 1040 Wireless AP

    I am trying to get Server 2008 R2 RADIUS Server to work with a Cisco Aironet 1040 Wireless AP. I have installed the RADIUS server by MS standards and performed some searches on Google to configure the Cisco Aironet. I see others using a Wireless LAN Controller, which I do not have. I found this post below:
    https://supportforums.cisco.com/discussion/11546056/wlc-2504-radius-2008-r2-server
    But I have yet to locate a good step by step document on how to set it up and I have found so many different ways that others have set it up, but none have yet to work. I am having authentication issues that I have know of and I do not see any errors in the Windows Event Viewer and I do not know where the Acess Point stores it logs for any sort of error. Keep in mind this is the first time I am doing this. I do not have a Wireless LAN Controller and all my network / domain services are on individually built servers and not on one single server as I have seen with most of the documentation they all say the same thing by putting the Certificate Services, Domain Services (AD / ADS, etc), and NPS. I do not want that configuration and my setup should not be any different, but something is not right. I know from reading that this is not rocket science, but from someone who has never done it before this is difficult as I keep reading on and so many people do it different ways including what I have been reading according to what Cisco says to configure in the environment. Does anyone know where I can find good step by step documentation along with where I can look for logs on either device? I find that all the documentation I see on Cisco's website and from searching that it is old and outdated and not been updated in a long time so it is hard to determine what works and what does not work. I am stumped here and have been doing this for several weeks now with no luck. Thank you in advance.

    I did configure the Server 2008 R2 RADIUS Server using this video below: 
    https://www.youtube.com/watch?v=g-0MM_tK-Tk
    I also referenced Technet to make sure it was configured correctly as well. I am still not sure if I am 100% setup correctly on the Windows Server side, but I for sure want to make sure I have the AP side setup correctly. Do you know of a better article for the Windows Server 2008 R2 setup? Does it matter that I do not have all the services installed on the same server? Instead I have them installed on multiple servers.
    I have image number c1140-k9w7-tar.124.25d.JA1 on the AP. The part that confused me in that article, which I have seen before was the part about "Setting up access point must be configured in the authentication server as an AAA client." What is the AAA Client? I also am not aware of having Cisco Secure ACS anywhere built into the AP as that part through me off completely. Do I need to skip these steps? Thank you for help on this.

  • Cisco aironet 2600 series AP configuration with windows 2008 R2 Radius server.

    I want to know the configuration of Cisco aironet 2600 series AP with windows 2008 R2 Radius server.  
    I have
    1. AD & DHCP Server
    2. Cisco Aironet 2600 Access Point.
    I want to connect wifi devices through this AP. Authentication should be through Radius server and AD.

    Hi , 
    Below link should support your requirement 
    http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/116584-configure-wirelesslan-00.html
    Minimal command : -
    AP(config)# aaa new-model
     AP(config)# radius-server host 172.20.0.1 auth-port 1645 acct-port 1645 key XXXXXX
     AP(config)# radius-server deadtime 10
    HTH
    Sandy

  • Multiple Cisco Aironet 1131AG access points and same SSID?

    We have multiple Cisco Aironet 1131AG devices, all wired on one Cisco L2 switch(2560)  who is connected to L3 switch (3550). We assigned one VLAN for access point in L3 switch who acts as vtp server (L2 switch is vtp client). All ap's will have static ip address and all will have same SSID and no security and they will be using multiple channels (ex. 1,6,11).  They will operate in 3 floor building for roaming wireless client. We won't using any wireless controller.
    So my question is this: How to configure APs-all the same with different ip's, can we use L3 switch to create dhcp server for access points VLAN (pool for clients, and the rest for static ip for ap's)? Can one of the ap's be WDS and in the same time local radius server with users without Cisco Secure ACS or similar controller or I didn't understand this quite well :-). I followed guide http://www.cisco.com/en/US/docs/wireless/access_point/12.3_2_JA/configuration/guide/s32roamg.html for WDS where the part abou Cisco ACS is a problem, so I can use same ap as Local Authenticator as in guide  http://www.cisco.com/en/US/docs/wireless/access_point/12.3_4_JA/configuration/guide/s34local.html#wp1035723.
    Many thanks...

    Well, just so you know, WDS and local RADIUS authentication is only needed if you're using authentication on your wireless connection.  You say you're not planning to use security, so this isn't necessary.  However, I'd highly recommend at least using a simple WPA2-PSK to lock down your connection, otherwise you might end up giving free Internet access at best, and at worst you might be giving access to company PCs and servers.  If you want to further use an 802.1x or WPA authentication method, then yes, you can use an AP as a RADIUS server and WDS to improve authenticated roaming, but this is far more limited than using a Cisco ACS.
    As for your other questions, yes, your APs can all be configured the same except for at least three parameters: IP address, channel, and hostname.  Configure your static IP addresses on the AP's BVI1 interface.  Don't place it on the Radio or Ethernet interfaces, because if either of these interfaces goes down you'll lose the ability to configure the AP, so it's best to use the BVI1 interface.
    And yes, configuring a DHCP scope for your clients on your L3 switch is a good design, or you could also use your DHCP server on a different subnet by using the ip helper-address command on the L3 interface.  I hope this helps!  Let me know if you need help configuring any of this.
    Merry Christmas!
    Jeff

  • Cisco Aironet 1250 - How to bridge two AP's and get Non-root to talk to Root AP

    /* Style Definitions */
    table.MsoNormalTable
    {mso-style-name:"Table Normal";
    mso-tstyle-rowband-size:0;
    mso-tstyle-colband-size:0;
    mso-style-noshow:yes;
    mso-style-priority:99;
    mso-style-qformat:yes;
    mso-style-parent:"";
    mso-padding-alt:0in 5.4pt 0in 5.4pt;
    mso-para-margin-top:0in;
    mso-para-margin-right:0in;
    mso-para-margin-bottom:10.0pt;
    mso-para-margin-left:0in;
    line-height:115%;
    mso-pagination:widow-orphan;
    font-size:11.0pt;
    font-family:"Calibri","sans-serif";
    mso-ascii-font-family:Calibri;
    mso-ascii-theme-font:minor-latin;
    mso-hansi-font-family:Calibri;
    mso-hansi-theme-font:minor-latin;
    mso-bidi-font-family:Arial;
    mso-bidi-theme-font:minor-bidi;}
          I have two buidlings acroos the street from each other.  I have two Cisco Aironet 1250 wireless AP's with the first one going in the main building with network backbone.  The Second AP goes across the street with the other wired network segment.  Both AP's have long range antenas 2.4 GHZ on top of each building.  I have configured the 1st one as the Root Bridge.  The one across the street is configured as non-root bridge.  I have both AP's configured with the same WEP key and also with the same SSID name with both set to broadcast it.   I am still unsure and confused as to how I get the non-root bridge to talk to and use the root bridge to get on the main network.
            1- It’s main to use the Root parent Mac address.
            2-  Is there another config that I am missing to get the signal? 
    Note: I still not getting any signal from the root although distance between root and non-root is 330m
    My root antenna is AIR-ANT24120 and non-root antenna is AIR-ANT1949 and attached files is my configuration files
    Thank you.

    1.  How are the AIR-ANT24120 and the AIR-ANT1949 installed?
    the AIR-ANT24120 is connected virtically on tower far 11m from the earth and AIR-ANT1949 is connected horizontally on tower far 10m from the earth
    2.  What is the distance between both APs?
    350 m
    3.  Do you have clear line-of-sight between the two?
    there is one tanker in the middle between them but it's far 7m from the earth
    4.  Is the two APs properly aligned?
    i think yes and changed the aligned many times without any news (I don't have any tools for alignment)
    5.  Which point are the antennas connected to?  Primary, Secondary or middle?
    I tried in the primary and secondary but never tried the middle antenna
    Thanks

  • Cisco aironet 1130 and Intermec CV30

    Hi to all,
    I've a little problem with three Cisco 1130 AP. Anticipately i tell you that i'm not a guru of cisco wireless, but my implementation is very simple. I need a roaming for the 3 AP. I only have Ap, so i configure one as Master Ap and the others like repeater with cisco aironet extension configured. All 3 on the same channel and only the Master one broadcast SSID. Wep security implemented. My Cv30 terminals randomly loose the signal also if they're near an AP. They use windows mobile but i think is only a wrong config problem. I need help. Thank you very much.
    Alex

    The device is using the LWAPP image.. please upgade the same to autonomous image and convert the same..
    Please use the below doc that i hv written and this will helpu!!
    https://supportforums.cisco.com/docs/DOC-14960
    Please dont forget to rate the usefull posts!!
    Regards
    Surendra

  • Airport Extreme and Cisco DPC3008 terrible Netflix Streaming

    I have an Airport Extreme Base Station, Originally released June 2011, and a Cisco DPC3008 modem on Charter. 
    My problem is that with my Airport Extreme hooked up directly to my modem according to a Netflix Tech there servers are only seeing about a 1.5 Mbs connection and the Netflix quality is terrible.  When I take the Airport out of the equation and connect directly to the Modem everything streams great and is in crystal clear HD.
    I purchased a Linksys E1200 to test with and with that hooked up to the modem instead of the Airport Extreme Netflix streams perfect also.  So for some reason with the Airport Extreme my Netfilx quality is terrible but with other routers it is fine.
    I have a 30 Mb connection and all other services work fine with the Airport Extreme hooked up.  I tested Hulu, HBO Go, and WatchESPN and they are fine.  Only Netfilx has the issue with the Airport Exterme.
    Here is a link from DSL Reports with a person that has the same problem...
    http://www.dslreports.com/forum/r28578294-Speed-Issues-airport-extreme-Cisco-DPC 3008
    Anybody have any suggestions?
    Thanks!

    Just an update. I had my Airport Exterme unplugged all night. Plugged it in and did a factory reset, restored it to firmware version 7.5.2 and then updated each version up to the newest on it and now everything is working great. I am going to give it a few days and see what happens. Maybe something on the Airport Extreme got screwed up and being off all night reset it. Got me.

  • Cisco aironet 1310G non_native vlan and dhcp

    hi evrybody
    i have problem with my cisco aironet 1310G
    non-native vlan can not get(dynamicly)ip address from cisco aironet 1310G
    this is all my configuration please can someone help me
    ip dhcp excluded-address 20.20.20.20
    ip dhcp excluded-address 20.0.0.0
    ip dhcp excluded-address 30.0.0.0
    ip dhcp excluded-address 30.30.30.30
    ip dhcp excluded-address 10.0.0.0
    ip dhcp excluded-address 10.0.0.10
    ip dhcp excluded-address 10.1.0.0
    ip dhcp excluded-address 10.1.0.10
    ip dhcp pool d01
    network 10.0.0.0 255.255.255.0
    default-router 10.0.0.10
    ip dhcp pool d02
    network 20.0.0.0 255.255.255.0
    default-router 20.20.20.20
    ip dhcp pool d03
    network 30.0.0.0 255.255.255.0
    default-router 30.30.30.30
    no aaa new-model
    dot11 ssid vlan01
    vlan 1
    authentication open
    dot11 ssid vlan02
    vlan 2
    authentication open
    dot11 ssid vlan3
    vlan 3
    authentication open
    username cisco password xxx
    bridge irb
    interface Dot11Radio0
    no ip address
    no ip route-cache
    broadcast-key vlan 2 change 100
    broadcast-key vlan 3 change 100
    ssid vlan01
    ssid vlan02
    ssid vlan3
    speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
    station-role root access-point
    interface Dot11Radio0.1
    encapsulation dot1Q 1 native
    no ip route-cache
    bridge-group 1
    bridge-group 1 subscriber-loop-control
    bridge-group 1 block-unknown-source
    no bridge-group 1 source-learning
    no bridge-group 1 unicast-flooding
    bridge-group 1 spanning-disabled
    interface Dot11Radio0.2
    encapsulation dot1Q 2
    no ip route-cache
    bridge-group 2
    bridge-group 2 block-unknown-source
    no bridge-group 2 source-learning
    no bridge-group 2 unicast-flooding
    interface Dot11Radio0.3
    encapsulation dot1Q 3
    no ip route-cache
    bridge-group 3
    bridge-group 3 subscriber-loop-control
    bridge-group 3 block-unknown-source
    no bridge-group 3 source-learning
    no bridge-group 3 unicast-flooding
    bridge-group 3 spanning-disabled
    interface FastEthernet0
    no ip address
    no ip route-cache
    hold-queue 80 in
    interface FastEthernet0.1
    encapsulation dot1Q 1 native
    no ip route-cache
    bridge-group 1
    no bridge-group 1 source-learning
    bridge-group 1 spanning-disabled
    interface FastEthernet0.2
    encapsulation dot1Q 2
    no ip route-cache
    bridge-group 2
    no bridge-group 2 source-learning
    bridge-group 2 spanning-disabled
    interface FastEthernet0.3
    encapsulation dot1Q 3
    no ip route-cache
    bridge-group 3
    no bridge-group 3 source-learning
    bridge-group 3 spanning-disabled
    interface BVI1
    ip address 10.0.0.10 255.255.255.0
    no ip route-cache
    interface BVI2
    ip address 20.20.20.20 255.255.255.0
    no ip route-cache
    interface BVI3
    ip address 30.30.30.30 255.255.255.0
    no ip route-cache
    control-plane
    bridge 1 priority 9000
    bridge 1 protocol ieee
    bridge 1 route ip
    bridge 2 priority 10000
    bridge 2 protocol ieee
    bridge 3 priority 3100
    bridge 3 protocol ieee
    line con 0
    line vty 0 4
    login local
    end

    hi friend
    i did what you sugested but it is styl not working so plz find below the show run and debug ip dhcp server in ordr to help us thanks for all your suport
    ip subnet-zero
    ip dhcp excluded-address 20.0.0.20
    ip dhcp excluded-address 30.0.0.30
    ip dhcp excluded-address 10.0.0.10
    ip dhcp pool d01
    network 10.0.0.0 255.255.255.0
    default-router 10.0.0.10
    ip dhcp pool d02
    network 20.0.0.0 255.255.255.0
    default-router 20.0.0.20
    ip dhcp pool d03
    network 30.0.0.0 255.255.255.0
    default-router 30.0.0.30
    aaa new-model
    dot11 ssid vlan01
    vlan 1
    authentication open
    guest-mode
    dot11 ssid vlan02
    vlan 2
    authentication open
    dot11 ssid vlan03
    vlan 3
    authentication open
    bridge irb
    interface Dot11Radio0
    no ip address
    no ip route-cache
    broadcast-key vlan 2 change 100
    broadcast-key vlan 3 change 100
    ssid vlan01
    ssid vlan02
    ssid vlan03
    station-role root access-point
    interface Dot11Radio0.1
    encapsulation dot1Q 1 native
    no ip route-cache
    bridge-group 1
    bridge-group 1 subscriber-loop-control
    bridge-group 1 block-unknown-source
    no bridge-group 1 source-learning
    no bridge-group 1 unicast-flooding
    bridge-group 1 spanning-disabled
    interface Dot11Radio0.2
    encapsulation dot1Q 2
    no ip route-cache
    bridge-group 2
    bridge-group 2 block-unknown-source
    no bridge-group 2 source-learning
    no bridge-group 2 unicast-flooding
    interface Dot11Radio0.3
    encapsulation dot1Q 3
    no ip route-cache
    bridge-group 3
    bridge-group 3 subscriber-loop-control
    bridge-group 3 block-unknown-source
    no bridge-group 3 source-learning
    no bridge-group 3 unicast-flooding
    bridge-group 3 spanning-disabled
    interface FastEthernet0
    no ip address
    no ip route-cache
    hold-queue 80 in
    interface FastEthernet0.1
    encapsulation dot1Q 1 native
    no ip route-cache
    bridge-group 1
    no bridge-group 1 source-learning
    bridge-group 1 spanning-disabled
    interface FastEthernet0.2
    encapsulation dot1Q 2
    no ip route-cache
    bridge-group 2
    no bridge-group 2 source-learning
    bridge-group 2 spanning-disabled
    interface FastEthernet0.3
    encapsulation dot1Q 3
    no ip route-cache
    bridge-group 3
    no bridge-group 3 source-learning
    bridge-group 3 spanning-disabled
    interface BVI1
    ip address 10.0.0.10 255.255.255.0
    no ip route-cache
    interface BVI2
    ip address 20.0.0.20 255.255.255.0
    no ip route-cache
    interface BVI3
    ip address 30.0.0.30 255.255.255.0
    ip helper-address 30.0.0.0
    no ip route-cache
    and debug ip dhcp server {events | packets | linkage}
    *Mar 1 01:06:37.054: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating
    Station 0011.a304.2b65 Reason: Sending station has left the BSS
    *Mar 1 01:06:40.140: %DOT11-6-ASSOC: Interface Dot11Radio0, Station 0011.a304
    .2b65 Associated KEY_MGMT[NONE]

Maybe you are looking for