Autonomous or LWAPP for fast roaming

We are looking to deploy wifi to support Tablet PCs. The software we are using is very sensitive to loosing its connection to the SQL database. I am worried particually about roaming. We need to use 802.1x for security and would like to use the MS IAS servier with EAP-TLS for authentication. We have 4 locations which should each be well covered by 3 base stations at each location. Medical providers need to be able to move around the office without losing connections. Time is more important than money. An hour of lost provider time (and when our app crashes it crashes hard) is worth avoiding with addition money. My questions are the following:
1. Do we need LWAPP or will autonomous with WLSE work for us? (Specifically for fast secure roaming, or quick handoff, or whatever it is we need)
2. Do we need to use EAP-FAST (and thus a Cisco AAA server) or will EAP-TLS with IAS be enough?
3. If we use LWAPP do we need WCS or will managing each 2000 series WLAN controller be enough?
4. Will all this work with my HP switches and Andtran routers?

1. Do we need LWAPP or will autonomous with WLSE work for us? (Specifically for fast secure roaming, or quick handoff, or whatever it is we need)
A: Go with LWAPP, more reliable, and easier to work with.
2. Do we need to use EAP-FAST (and thus a Cisco AAA server) or will EAP-TLS with IAS be enough?
A: I'd recommend, PEAP. More secure, and with everything Cisco, much easier to support, since TAC does not support the IAS server.
3. If we use LWAPP do we need WCS or will managing each 2000 series WLAN controller be enough?
A: If you are only contemplatign using 2006 at 4 locations, WCS wouldn't be a necessity. If you expand beyond that and decide to do something else, then yes WCS.
4. Will all this work with my HP switches and Andtran router?
A: It probably will, and it should, but for best results, going Cisco for the whole solution works the best.
Now, why go with 2006's? They are nice boxes, but you would need 4 of them. If you are static at 4 locatiosn with out need for growth, I'd go with a 4402-25. This is a single controller that can handle up to 25 AP's. With this, if you purchase the 1242 or the 1131, you can do HREAP, and keep all the subnets locally switched, that way if the WAN goes out, or the controller goes out, then the WiFi stays up for the local subnets. Naturally anything acrosss the WAN is not accessable.
That beign said, if you are backhauling everything to a central site anyway, might as well go with one 4402-25, single point of controll, instead of 4. And if you do need to add another site, then you still have 13 more AP's that can join instead of having to purchase another controller.
my 2cents

Similar Messages

  • Converting 1250 APs between autonomous and LWAPP

    It took me a while to get this information, so thought I'd share. Here it is:
    You cannot use the upgrade tool to do the IOS to LWAPP for the 1250 APs.
    Here is a method to do the conversion.
    *Method 1 : ( Mode Button )*
    1. Install an external TFTP tool such as tftpd32 tool from http://tftpd32.jounin.net/
    2. Assign IP address in the range 10.0.0.x ( Ex : 10.0.0.3)to the server.
    3. Download the IOS to lwapp image onto the tftp's root directory. Use http://www.cisco.com
    4. Make sure you set the IP address on the BVI interface of the AP if
    not set.Set it in the 10.0.0.x range.
    5. Connect the Ethernet port on AP to your TFTP Server ( Laptop )
    5. Hold the mode button and power off the AP.
    6. Power back the AP while continually holding the mode button for 20-30
    seconds.
    *Method 2 : ( Archive Command )
    *1. Install an external TFTP tool such as tftpd32 tool from http://tftpd32.jounin.net/
    2. Assign IP address in the range 10.0.0.x ( Ex : 10.0.0.3)to the server.
    3. Download the IOS to lwapp image onto the tftp's root directory. Use http://www.cisco.com
    4. Make sure you set the IP address on the BVI interface of the AP if
    not set.Set it in the 10.0.0.x range.
    5. Connect the Ethernet port on AP to your TFTP Server ( Laptop )
    6. On AP, type archive download-sw /overwrite /force-reload tftp://192.168.5.210/c3201-k9w7-tar.124-3.JK2.tar
    Going the other way (lwapp to autonomous)
    http://www.cisco.com/en/US/docs/wireless/access_point/conversion/lwapp/upgrade/guide/lwapnote.html#wp161272
    If you need to manually "prime" the LWAPP:
    AP#lwapp ap ip address <IP address> <subnet mask>
    AP#lwapp ap ip default-gateway <IP-address>
    AP#lwapp ap controller ip address <IP-address>
    AP#lwapp ap hostname <name>
    (optional)
    Hope someone finds this useful!

    The problem here is that you can't have any fast roaming since you have autonomous and LAP's. The thing is... the phone is associated to a LAP and the mac is known on the trunk port of the wlc, then the phone roams to the autonomous AP and the LAP and IOS AP don't communicate so there is no smooth hand off. Phone has to re-associate or re-authenticate and the mac shows up on both ports until the arp times out. For VoIP, a mixed environment is not supported.

  • Autonomous to LWAPP - Air1261 APs

    Hi All,
    I have just download the Auto-to-LWAPP upgrade tool and it is saying that it does not upgrade Air1261 from Auto-to-LWAPP, is it so? If yes, then what is the procedure to convert Air 1261 APs from Autonomous to LWAPP?
    Also, when I start the upgrade tool, it says that a TFTP server is already running on the PC so it will start the application with "User external TFTP" option, however there is not TFTP running on my PC. Why this error is coming? Following is the snapshot of the error.
    Looking for valuable response.
    Regards,
    Sohail

    Take a look at these links as it will explain how to convert the AP's.
    Using a TFTP Server to Return to a Previous Release
    https://supportforums.cisco.com/docs/DOC-18268
    http://www.cisco.com/en/US/docs/wireless/access_point/conversion/lwapp/upgrade/guide/lwapnote.html#wp160918
    http://www.youtube.com/watch?v=QQ_NuxdRhQ4
    https://supportforums.cisco.com/docs/DOC-14960
    Sent from Cisco Technical Support iPhone App

  • Converting air-sap2602i-s-k9 from autonomous to LWAPP

    Hi guys,
        I need your expertise regarding how to convert from autonomous to LWAPP using AIR-SAP2602i-s-k9 with IOS version of ap3g2-k9w7-xx.152.-2.JA.
        I'm following these commands but it is not available
        debug capwap console cli or debug lwapp console cli
    I cannot proceed to convert it Did I miss something or the 2600 series doesn't support LWAPP convertion ?
    thank you
    Erik

    Hi Erik,
    Those commands aren;t going to work, they're debug commands for a lightweight AP.
    Here is the guide to upgrading:
    http://www.cisco.com/en/US/docs/wireless/access_point/conversion/lwapp/upgrade/guide/lwapnote.html
    It's pretty simple though, get the lightweight software follow the upgrade tool instructions to load new software.
    Though, you have a newer AP so you'd be ok just to load the new software on, if it's only for a small amount this is fine.
    Thanks
    Chris

  • CCKM/Fast Roaming CCXv3 and CCXv4 Clients

    I am trying to verify for sure if CCXv3 clients can connect to a wlan configured with 802.1X+CCKM, and security WPA2/AES and do fast roaming?
    It appears that CCXv3 clients do not support CCKM with 802.1X/EAP TLS.

    Keep in mind PMK is specific to an ap and client. If a client roams away from the ap and comes back it doesnt have to reauth becuase it uses the PMK. OKC, uses the orginal PMK generated during your first auth and then shares it with other aps to negate auth .. clients need to support OKC to take full advantage
    For flex ..
    FlexConnect Groups and CCKM
    FlexConnect Groups are required for CCKM fast roaming to work with FlexConnect access points. CCKM fast roaming is achieved by caching a derivative of the master key from a full EAP authentication so that a simple and secure key exchange can occur when a wireless client roams to a different access point. This feature prevents the need to perform a full RADIUS EAP authentication as the client roams from one access point to another. The FlexConnect access points need to obtain the CCKM cache information for all the clients that might associate so they can process it quickly instead of sending it back to the controller. If, for example, you have a controller with 300 access points and 100 clients that might associate, sending the CCKM cache for all 100 clients is not practical. If you create a FlexConnect that includes a limited number of access points (for example, you create a group for four access points in a remote office), the clients roam only among those four access points, and the CCKM cache is distributed among those four access points only when the clients associate to one of them.
    Note CCKM fast roaming among FlexConnect and non-FlexConnect access points is not supported. See the "Configuring WPA1 +WPA2" section for information on configuring CCKM.
    FlexConnect Groups and Opportunistic Key Caching
    Starting in the 7.0.116.0 release, FlexConnect groups enable Opportunistic Key Caching (OKC) to enable fast roaming of clients. OKC facilitates fast roaming by using PMK caching in access points that are in the same FlexConnect group.
    This feature prevents the need to perform a full authentication as the client roams from one access point to another. Whenever a client roams from one FlexConnect access point to another, the FlexConnect group access point calculates the PMKID using the cached PMK.
    To see the PMK cache entries at the FlexConnect access point, use the show capwap reap pmk command. This feature is supported on Cisco FlexConnect access points.
    Note The FlexConnect access point must be in connected mode when the PMK is derived during WPA2/802.1x authentication.
    When using FlexConenct groups for OKC or CCKM, the PMK-cache is shared only across the access points that are part of the same FlexConnect group and are associated to the same controller. If the access points are in the same FlexConnect group but are associated to different controllers that are part of the same mobility group, the PMK cache is not updated and CCKM roaming will fail.
    "Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
    ‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."
    "Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
    ‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."

  • Upgrade 1121 autonomous to LWAPP

    I have some access-points AIR-AP-1121G-TO-K9 and it would like to use them with a WLAN Controller. Is possible to change IOS for the software LWAPP to use with the WLAN Controller?
    I know that that is possible in another models of access-points, but I don't know if the 1121 support that upgrade.
    Regards.

    Hi Andre,
    Just to add a note to the good tips from Ankur. These AP's can be converted to LWAPP. We did this exact conversion last summer on about 30 1121G's with the **LWAPP upgrade tool**.
    Support for the 1121 was added in WLC version 4.0.155.0 Have a look at these related docs;
    Software release 4.0.155.0 New Features
    LWAPP for Cisco Aironet 1100 Series Access Points (802.11g radio only) Allows the Cisco Aironet 1100 Series Access Point to be upgraded from autonomous access point mode to lightweight mode using the autonomous to lightweight mode upgrade tool.
    Note You must install software release 4.0.155.0 on the controller before connecting 1100 series access points to the controller.
    http://www.cisco.com/en/US/products/ps6366/prod_release_note09186a00806e8989.html#wp147320
    LWAPP Upgrade Tool Troubleshoot Tips
    http://www.cisco.com/en/US/tech/tk722/tk809/technologies_tech_note09186a008072d9a1.shtml
    Access points must run Cisco IOS Release 12.3(7)JA or later before you use the upgrade tool.
    System Requirements
    You can use the Autonomous to Lightweight Mode upgrade tool to install Cisco IOS Release 12.3(11)JX on these access points:
    **All 1100 series access points containing MP21G (802.11g) radios
    All 1130, 1230, and 1240 series access points
    All modular 1200 series access points running Cisco IOS software and containing these supported radios:
    802.11g: MP21G, MP31G
    802.11a: AIR-RM21A-x-K9, AIR-RM22A-x-K9
    All 1300 series access points in access point mode
    http://www.cisco.com/en/US/docs/wireless/access_point/ios/release/notes/b311jx1.html
    Cisco has released a free tool called the "Autonomous to Lightweight Mode Upgrade Tool" that allows selected Cisco Aironet autonomous access point models to be configured for lightweight mode operation.
    The Autonomous to Lightweight Mode Upgrade Tool supports the following models:
    Cisco Aironet 1240AG Series access points
    Cisco Aironet 1230AG Series access points
    Cisco Aironet 1200 Series access points that contain 802.11g (AIR-MP21G-x-K9) and/or second-generation 802.11a radios (AIR-RM21A-x-K9 or AIR-RM22A-x-K9)
    Cisco Aironet 1130AG Series access points
    **Cisco Aironet 1100 Series Access Points that contain 802.11g radios (AIR-AP1121G-x-K9)
    Cisco Aironet 1300 Series Access Points/Bridges (AIR-BR1310G-x-K9 or AIR-BR1310G-x-K9-R). A Cisco Aironet 1300 Series operating in Lightweight Access Point Protocol (LWAPP) mode only operates as an access point. This series does not support LWAPP bridging mode.
    The Autonomous to Lightweight Mode Upgrade Tool supports a process to migrate an autonomous access point from autonomous mode to lightweight mode. Unlike a VxWorks to Cisco IOS Software upgrade, this process is a Cisco IOS Software upgrade to the existing Cisco IOS Software image-not an operating system "swapout". In converted access points operating in lightweight mode, Cisco IOS Software continues to run on the access point, while LWAPP is used to communicate with a wireless LAN controller. Since LWAPP supports automatic access point configuration, there is no need to retain or convert the original autonomous Cisco IOS Software access point configuration.
    http://www.cisco.com/en/US/netsol/ns340/ns394/ns348/ns337/networking_solutions_white_paper0900aecd804f1a23.shtml
    Cisco Aironet Access Point Support for Lightweight Access Point Protocol
    http://www.cisco.com/en/US/products/ps6521/prod_bulletin0900aecd80321a2c.html
    Upgrading Autonomous Cisco Aironet Access Points to Lightweight Mode
    http://www.cisco.com/en/US/products/hw/wireless/ps430/prod_technical_reference09186a00804fc3dc.html#wp157147
    Hope this helps!
    Rob

  • WPA2+CCKM fast roaming not happening

    Hello,
    I'm trying to test fast roaming using a Cisco 2100 Series controller and 2 1140 APs. The initial authentication succeeds fine and the wireless
    connection works ok using WPA2+CCKM and LEAP with a Cisco ACS radius server.
    The problem is that the client does not attempt to preauthenticate with the other AP because the RSN Capabilities IE in the AP beacons and probe responses do not set the RSN Preauthentication capable bit. I can't figure out what it takes to get the APs to indicate to clients that it can do preauthentication. I'm been crawling through all the documentation I can find, to no avail. Any ideas?
    Thanks
    - Bill

    Preauthentication has nothing to do with WPA2 Proactive key caching nor with CCKM.
    If you enable CCKM on the SSID you would expect the clients to use CCKM for roaming, no ?
    Most clients don't support WPA2 with CCKM combined as they have overlapping roaming mechanism. What are your test clients exactly ? Did you verify if they support WPA2 with cckm ?

  • Autonomous to LWAPP with Cisco Prime 2.2

    Hello, I need to know if exist any procedure to convert Autonomous to LWAPP  access point with Cisco Prime 2.2.

    Here are the Steps Cristian.
    To create an autonomous AP migration template, follow these steps:
    Step 1 Choose Design > Configuration > Wireless Configuration > Autonomous AP Migration Templates .
    Step 2 From the Select a command drop-down list, choose Add Template, then click Go . If you are updating an already existing template, click the applicable template in the Template Name column.
    Step 3 Complete the required fields. For information about the field descriptions, see: http://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/infrastructure/2-0/reference/guide/prime_infr_ref.html
    Step 4 To view the migration analysis summary, choose Operate > Wireless > Migration Analysis .
    Note: After an access point has been converted to lightweight, the previous status or configuration of the access point is not retained.
    Hope this will resolve your issue ;)

  • Autonomous vs LWAPP access point

    I am new to these 2 terms.
    What's the main difference between autonomous and LWAPP access point?
    Autonomous AP can work on it's own, while LWAPP need to be used with WNC?
    If I need to deploy an wireless enironment, I should use LWAPP, right?

    The main difference is autonomous do not require a controller to control the AP and it use WLSE for management software; the LWAPP require a WLC wireless controller to control all of the AP but provide ease of management for the communication / setting between APs, it use another management software call WCS.
    If you will deploy many APs, LWAPP will be better for easier management. If only a few APs, autonomous is fine because do not require additional WLC.
    LWAPP info. :
    http://www.cisco.com/en/US/netsol/ns340/ns394/ns348/ns337/networking_solutions_white_paper0900aecd802c18ee.shtml
    Hope this helps.

  • 1142 autonomous to lwapp

    hi folks:
    Has anyone of you tried to convert autonomous to lwapp mode? I used upgrade tool v3.4 and it said 1140 is not supported. Or is there any other way to do the conversion? Thanks.
    regards
    Alex

    Was it a LAP to begin with? If so, follow the "LWAPP revert to autonomous" steps using the recovery image as your file. Yes - I know you are going to LAP, not to autonomous. These steps worked great for me when going from autonomous back to LAP (without using the conversion tool):
    Step 1 The static IP address of the PC on which your TFTP server software runs should be between 10.0.0.2 and 10.0.0.30.
    Step 2 Make sure that the PC contains the access point image file (such as c1200-k9w7-tar.122-15.JA.tar for a 1200 series access point) in the TFTP server folder and that the TFTP server is activated.
    Step 3 Set the timeout value on the TFTP server to 30 seconds.
    Step 4 On the PC where the TFTP server is located, perform these steps:
    a. Disable any software firewall products, such as Windows firewall, ZoneAlarm firewall, McAffee firewall, or others.
    b. Ensure all Windows files are visible. From Windows Explorer, click Tools > Folder Options > View; then uncheck the Hide extensions for known file types check box.
    Step 5 Rename the access point image file in the TFTP server folder to c1200-k9w7-tar.default for a 1200 series access point, c1130-k9w7-tar.default for an 1130 series access point, c1240-k9w7-tar.default for a 1240 series access point, and c1250-k9w7-tar.default for a 1250 series access point.
    Step 6 Connect the PC to the access point using a Category 5 (CAT5) Ethernet cable.
    Step 7 Disconnect power from the access point.
    Step 8 Press and hold MODE while you reconnect power to the access point.
    Step 9 Hold the MODE button until the status LED turns red (approximately 20 to 30 seconds) and then release.
    Step 10 Wait until the access point reboots, as indicated by all LEDs turning green followed by the Status LED blinking green.
    Step 11 After the access point reboots, reconfigure it using the GUI or the CLI.

  • Upgrading 1252s from autonomous to LWAPP

    I need to upgrade several 1252s from autonomous to LWAPP.
    I have not been able to find the upgrade tool for 1250s or instructions for CLI upgrade.
    I wil be using NCS to do final configuration once the APs come online.
    Can someone assist?
    Thanks,
    Kristin                     

    So long as you pull the rcv file for the AP you should be able ti use NCS to do the conversion.
    Other than that a standard AP upgrade should work, with the rcv file as well.
    Steve
    Sent from Cisco Technical Support iPhone App

  • 1252 autonomous to LWAPP

    Hi
    I can't seem to find the image for upgrading a 1252 from autonomous to LWAPP. Please can someone point me in the right direction?
    Many thanks.

    Copy this whole link and try it out (pasting isn't exactly making the whole thing one link): http://tools.cisco.com/support/downloads/go/IPCheck.x?defAdv=N&sftAdv=N&image=c1250-rcvk9w8-tar.124-10b.JA3&filepath=/swc/esd/02/crypto/3DES/281235915/guest&filename=c1250-rcvk9w8-tar.124-10b.JA3&advUrl=null&isk=Y&defInd=N&mdfid=281235915&sftType=Autonomous%20To%20Lightweight%20Mode%20Upgrade%20Image&optPlat=&relVer=12.4(10b)JA3&fileId=271159&treeMdfId=278875243&treeName=Wireless
    Or search cisco.com for c1250-rcvk9w8-tar.124-10b.JA3
    I think this is what you are looking for.

  • How do you run to Drives on the same screen. I installed a ssd and a hhd to my mac but i can only view the content of the drive only if i boot of that drive. Im try to have my ssd for fast boots and hhd for my music,movies etc. Please help.

    I installed a samsung 840 pro SSD to my primary slot and relocated my 1.5 TB HDD to a data double where my optical drive was. I transfered my apps and Mac OS X to my SSD for fast boots and all my itunes movies, music, Iphoto etc to my HDD. I rebooted off my SSD then seen all the data on my HHD itunes movies, music, iphotos etc i cannot view on my SSD. So my question is how do you view all the content on both the ssd and hdd on the same screen with having to boot off one or the other?

    No, what I'm saying is that once you boot into OSX, you should be able to see both drives listed.  If you don't then either OSX is hiding the other drive because it sees it as a boot drive and is trying to protect the contents from novice users or there's another problem.  If it's the first thing (i.e. it's a protection thing), then your only option would be to boot into the old drive, copy off all your personal data to an external backup drive, then reboot into the SSD and go into Disk Utilities and wipe/reformat the second drive so that you can see it as a regular secondary drive.  Then when you see it as that, you can copy your data back to it.
    Be carefull poking around in Disk Utility as you can easily lose your data.  It's possible the Mac just isn't mounting that second drive because it sees it as another boot drive.  Whatever you do, don't accidentally erase it without getting a copy of your data off of it because you obviously don't have that on your SSD now.

  • Acrobat 9.3.4 (or 9.3.3.177): Save As with Optimize for Fast Web View

    When I do a Save As with Optimize For Fast Web View checked, the saving stops and an Adobe Acrobat dialog displays:
         The document could not be saved. There was a problem reading this document (111).
    If I uncheck Optimize For Fast Web View, the Save As seems to work.
    Is there a way to have Fast Web View work with Save As?
    Acrobat.exe is version 9.3.4 (or 9.3.3.177 in the properties). The Acrobat.DLL version is 9.3.4.218.

    Thanks.  I did submit a report at the site.  I hope somebody reads it as this is a big problem for us.
    Thanks again.

  • I bought a new iMac today. I'm using migration assistant to move all my software, but the time just keeps getting longer. It says connect an Ethernet cable for faster data transfer. I did, but that doesn't seem to help. Any ideas?

    I bought a new iMac today. I'm using migration assistant to move all my software, but the time just keeps getting longer. It says connect an Ethernet cable for faster data transfer. I did, but that doesn't seem to help. Any ideas?

    m1doc,
    Are you migrating from a Mac or a MS Window machine? Either way you probably should be in touch with AppleCare, you have 90 days of free AppleCare telephone support. They can usually help on issues like this. If you don't know the phone number please use http://support.apple.com/kb/HE57 to help find the number in your country.

Maybe you are looking for

  • Can't downloadthe drivers for Satellite C55-B1066

    Hi I can't downloadthe drivers software ??!! Could anybody help me.

  • Intel MacBook Gray screen

    I installed new RAM a month ago and everything was fine for 3 weeks then I got the gray screen with 3 beeps at startup indicating [I think] that there is a RAM-related issue. Thing is - if I hold down the power key on startup long enough I get a sing

  • Suggestion: make UTF8 as default encoding

    JDeveloper still uses "System default" encoding for editor and compiler, not UTF8. Other tools, like IDEA uses UTF8 more than 5 years. JDeveloper can be ajusted to use UTF8, but it is needed to make this in 3 places at last. If a new developer will n

  • Reg: Guidance

    Hello, I am beginner of oracle sql and plsql. I am searching job in related this technology. Please anyone can guide me and tell me how to get a job in these technology. Thank you.

  • Trouble with homepage settings

    On my old computer (PC, Windows 7) I had "http://www.hotmail.com" as my homepage. Firefox always remembered by password and when I clicked "home" it put me inside hotmail. I have a new computer (PC, Windows 7) and now if refuses to remember my passwo