Consistent Roaming with WDS on AP1142n WAPs

Hi there
Background 
I have 3 Cisco AP1142n with one as the WDS and running local radius, the WDS then authenticates to an external FreeRadius server. The SSID is using EAP-TLS authentication. 
 The other 2 AP's are running as WDS clients and they have registered and authenticated fine against local radius on WDS AP
Problem
Users are able to roam however 90% of the time this does not work and users who are connected to a VPN lose their connection and have to re-ath to the SSID..  I am also seeing the pattern is that when users roam from WDS-Client AP 1 to WDS-Client AP2 , this does not work however when they then re-auth to WDS-Client AP2 and back to AP1 this works fine.
I have following debug enabled on the WDS device 
General OS:
  AAA Authentication debugging is on
  AAA Authorization debugging is on
dot11/wlccp authenticator:
  receive packet debugging is on
  transmit packet debugging is on
  state machine debugging is on
  process debugging is on
  Mac Authentication debugging is on
  Dispatcher debugging is on
 List of MNs with WDS events debugging enabled :
 b88d.1213.1b3a 
The question I have is the following line which I keep seeing in the output 
May 13 12:24:47.980: AAA/AUTHOR: auth_need : user= 'xxx' ruser= 'AP-WDS-01'rem_addr= '10.x.x.x' priv= 1 list= '' AUTHOR-TYPE= 'commands'
May 13 12:24:51.243: AAA/AUTHOR: auth_need : user= 'xxx' ruser= 'AP-WDS-01'rem_addr= '10..x.x.x' priv= 15 list= '' AUTHOR-TYPE= 'commands'
May 13 12:25:17.259: AAA/AUTHOR: auth_need : user= 'xxx' ruser= 'AP-WDS-01'rem_addr= '10.x.x.x' priv= 15 list= '' AUTHOR-TYPE= 'commands'
Do these lines tell me anything?
Also in addition 
WDS Statistics for last 4d19h:
    Current AP count:                3
    Current MN count:                0
    AAA Auth Attempt count:          12
    AAA Auth Success count:          12
    AAA Auth Failure count:          0
    MAC Spoofing Block count:        0
    Roaming without AAA Auth count:  15
    Roaming with full AAA Auth count:5
    Fast Secured Roaming count:      0
    MSC Failure count:               0
    KSC Failure count:               0
    MIC Failure count:               0
    RN Mismatch count:               0
What do the above bold lines tell me? 
Kind Regards

Agree with Rasika..
if you are using 802.1x, then only you would want to configure WDS for the key caching.
if you are using a PSK, then all you need to do is configure the AP exactly the same way, with the exception of the IP address on the BVI interface, as long as the ssid and encryption are the same, and there is overlap between the cells the client should roam between the AP
Regards

Similar Messages

  • Multiple SSIDs with WDS, custom DHCP addresses, & Web interface

    I just bought an Aiport Extreme Base station along with an Aiport Express. So far, everything is great, but I had a few of things I would like configure a certain way, and I am having a little problem.
    Just to let you know, I am using the base station as the main router/firewall (with my cable modem). I am using the express basically as a wireless bridge (via WDS).
    The way Apple takes care of things with WDS, is by assiging the same SSID to both the base station and express for seamless roaming. However, I would like them both to have their own SSID. I cannot seem to get this working, and I know that some other vendors allow this (Buffalo, Linksys).
    The other issue is regarding DHCP on the LAN side. I want to for example hand out IP addresses 192.168.2.50-60 to my internal clients, and I want the base station to have an address of 192.168.2.1 and the express to have 192.168.2.5. It seems this also I am having problems with. It seems like the base station is very rigid on what options I have in this regard.
    Lastly, I wondered if there is any other way to administer these guys (like a web browser). Sometimes I need to remotely make changes to the router, and don’t really want to install another app just for this purpose (especially at work, or some other remote location).
    Thanks
    Mac Mini 1.25 GHz   Mac OS X (10.4.3)   1 Gig of RAM

    The way Apple takes care of things with WDS, is by
    assiging the same SSID to both the base station
    and
    express for seamless roaming. However, I would
    like
    them both to have their own SSID.
    I don't know why you'd want that but if you are
    extending the range of your wireless network with WDS
    it isn't possible with Airports.
    The other issue is regarding DHCP on the LAN side.
    I
    want to for example hand out IP addresses
    192.168.2.50-60 to my internal clients, and I want
    the base station to have an address of 192.168.2.1
    and the express to have 192.168.2.5. It seems this
    also I am having problems with.
    You can set the DHCP range and then assign static
    IP's to anything that conforms to that network as
    long as it won't conflict with something
    automatically assigned by DHCP. As a router NAT must
    be enabled so if you want a unique range of numbers
    only DHCP is used which won't work in your case.
    In other words set the range at 192.168.1.1 and that
    is the address of the base station. That can be used
    for the statically IP'd device's router and DNS
    entries as well like this:
    Device 1 IP 192.168.1.101
    Device 1 subnet 255.255.255.0
    Device 1 router 192.168.1.1
    Device 1 DNS 192.168.1.1
    Device 2 IP 192.168.1.102
    Device 2 subnet 255.255.255.0
    Device 2 router 192.168.1.1
    Device 2 DNS 192.168.1.1
    etc...
    Lastly, I wondered if there is any other way to
    administer these guys (like a web browser).
    Not that I'm aware of. Airport Admin Utility is all
    there is. I have seen a java utility but it wasn't
    very friendly.
    Thanks for the answers. Despite these minor limitations, so far the Apple hardware is some of the best 802.11 stuff I have used (except for maybe a Cisco 1200).

  • Type 2 Virtual Machine in Hyper-V will not PXE boot with WDS

    Hi
    Bit of a wierd scenario this but I'm doing a bit of a lab experiment kind of thing. The setup is as follows:
    VMWare Workstation 10 with Windows Server 2012 R2 running as a virtual machine. In VMW10 I have a NAT network interface and a Bridging interface set to load with the virtual machine. These seem to work fine (although the NAT doesn't seem to want to connect
    to the internet but that's why the bridging one is there in addition).
    Server 2012 is configured with the following roles:
    ADDS, DHCP, DNS, Hyper-V, Printer, WDS
    I have correctly configured WDS to work on the same machine as DHCP and I can get PXE boot working with WDS on a Type1 Virtual Machine in Hyper-V using the Legacy Network adapter. My problem is when I try and PXE boot on a Type2 Virtual Machine (this type
    is new in R2 and should eliminate the need for a legacy network adapter) using the same network interface that I used for the Type1 machine, I get an IP address from DHCP but WDS doesn't seem to respond. Instead I get the "PXE-E16: No Offer Received"
    message. I have tried just about everything I can think of and spent the whole day trying to figure out why this is the case but came up with nothing. Has anyone else encountered this or can anyone shed any light on the matter? 
    Many thanks in advance

    "VMWare Workstation 10 with Windows Server 2012 R2"and "Server 2012 is configured with the following roles: ADDS, DHCP, DNS, Hyper-V, Printer, WDS"
    Hyper-V is not supported to be run as a VM.  It is a Type 1 hypervisor, which means it works on the bare metal.  You have it running as a VM on a Type-2 hypervisor, so it has no access to the bare metal.  Yes, VMware may have made it so some
    things work in that environment, but it is not a supported (or tested) environment for Hyper-V.
    .:|:.:|:. tim

  • How to roam with Lumia920 in Japan ?

    I bought Lumia920 in US, and I brought this in Japan.
    However, I cannot roam with this.
    In detail...
    [1] I selected [SETTINGS > cellular].
    [2] I selected 'Data connection' with 'on'.
    [3] I selected 'Data raming options' with 'roam'.
    [4] And then, I could select 'Network selection' with 'JP DOCOMO(forbidden)' or 'SoftBank(forbidden)'.
    Apparently, a reason that I cannot roam is in [4].
    However, I don'k know how to solve this.
    Please give me some hints.
    Attachments:
    IMG_0444.JPG ‏65 KB

    If I understand correctly, you are using your AT&T SIM card in Japan. In this case there are two possible reasons for what you are experiencing:
    1. AT&T does not have roaming agreements with these two network operators in Japan
    2. Your AT&T account does not have roaming services activated/allowed on it.
    In both cases you need to contact AT&T to resolve the problem. There is nothing wrong with your handset.

  • Connect more than 3 router with WDS

    hi,can i connect more than 3 router with WDS,in need to connect 8 wifi router with wireless, plz help me,Tnx

    Its not possible you can try the same with access points.

  • I recently upgraded to Lion, and immediately started having consistent problems with Open Office 12 (would hang, and need a Force quit to recover). Has anybody else seen these problems? Any solutions other than going back to Snow Leopard? (I did).

    I recently upgraded to Lion, and immediately started having consistent problems with Open Office 12 (would hang, and need a Force quit to recover). Has anybody else seen these problems? Any solutions other than going back to Snow Leopard? (I did). But I'd like to use iCloud with iPad.

    Hi Pete. The repair of disk permissions can help resolve  any application crashing or misbehaving.
    As for Lion and the two camps, I think that is a reasonable observation. In my office we have about a dozen Mac's and about one third of those Mac's had problems after updating from 10.6 to 10.7. The main problem for these Mac's was a loss of wifi stability. But for the other two-thirds, Lion was a smooth transition.
    Personally, my Lion experience was fine. But I did get a new i7 MacBook Pro with Lion already installed and only had to migrate my user data from a 10.6.8 TM backup.
    So I think that is a key for Lion's operational success. A clean install of Lion on a new Mac would not cause too many operational issues. But an installation, or more correctly, an update to Lion from SL increased the chances of failure for some users - especially when old software & plugins resided on the Mac. And I would say that they were the people that you saw at the Apple store.
    As for the "latest release of Lion fixed my problems" statement, my experience with these and other forums is that people mostly only go there to complain about the problems they are having. If they are having no problems then they either keep it to themselves or they try to help the users who are experiencing trouble...

  • RD with AD FS and WAP

    I'm trying to setup RD Web with or without RD Gateway with AD FS and WAP. All on 2012 R2.
    I have all the RD Roles on the same server inside the firewall and I would like to use the WAP server we are using for OWA for the same purpose for RD.
    I have seen some bits of info that tells me it's possible but nothing more.
    So any info would be greatly appreciated

    Hi,
    Thank you for posting in Windows Server Forum.
    Remote Desktop is a very common method to allow remote employees accessing legacy applications, usually rich applications that cannot be published using reverse proxies. In order to simplify the deployment experience for our customers, we have made a change
    in Web Application Proxy to enable publishing of Remote Desktop Gateway. This change allows RDG to pick up the session cookie that was used by RD Web Access so the RDP over HTTP traffic is authenticated.
    Please refer following article might helpful in your case.
    Introducing the next version of Web Application Proxy
    http://blogs.technet.com/b/applicationproxyblog/archive/2014/10/01/introducing-the-next-version-of-web-application-proxy.aspx
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    TechNet Community Support

  • Roaming with O2

    I am with O2 and based in the UK on a tariff which is basically unlimited. I'm going on holiday to Croatia for 12 days and O2 seem to want £23.50 per month for a minimum of 3 months to cover receiving and sending emails during this period. That is over £70.
    Does anyone know of a more efficent method of roaming with O2 please?

    If cellular data is off then the phone will not use any data. If iMessage is on it will periodically send invisible text messages to the iMessage activation server, but these use SMS, not cellular data.

  • Is it possible to disable intra-controller roaming with 1510AP

    Hi all,
    Is it possible to disable intra-controller roaming with 1510AP?
    Thanks

    Intra-controller roaming is enabled by default and cant be disabled.Refer URL
    http://cisco.com/en/US/products/ps6366/products_configuration_guide_chapter09186a008063f3b9.html#wp1093741

  • WDS and Roaming with 1130AG APs

    Hi there,
    I was wondering if someone could provide me with some insight into a configuration scenario i'm facing:
    Our office is situated in an old building and as such , wireless range is an issue as the walls are very thick and we have a mixture of clients from Laptops to android devices to iPhones that require access.
    we have 2 goals (first 2 are more important)
    1. to be able to roam anywhere in the building and pickup the wireless (fast roaming isn't really that necessary as voice isn't utilised)
    2. to have only 1 SSID for corporate access - Corp VLAN
    3. to have an SSID for guests to access - Guest VLAN
    The VLANs aren't an issue, i have an 1130AG setup which already has 2 SSIDs which does what i need.
    My main concern is around roaming, and i've read a lot about WDS, but this needs an external radius server, i've seen the articles that describe how to set up an AP as WDS and then add Infrastructure APs
    I've also seen that you can simply configure each AP exactly the same, but with different channells.
    I have 4 1130AGs at my disposal.
    What would you guys suggest is my best solution?
    Any help would be gratefully received.

    To get the best roaming, you need to make sure you have enough coverage. That usually means a good site survey was performed to specify how many access points and the locations of the access point. Without this piece, there is no guarantee of roaming.
    As far as WDS, you can setup an autonomous ap as a WDS server that is either dedicated as a WDS or is a WDS server and also serves clients.
    Sent from Cisco Technical Support iPhone App

  • Roaming with Airport Express (bridging) between two Airport Extreme AP's

    I have two Airport Extreme base stations set up on a company LAN that provide wireless coverage for our very large facility. Both are set up with the same SSID and WPA settings and they are 5 channels apart, 1 and 6. We have a cart with a computer and it uses an Airport Express / WDS to allow wired Ethernet bridging to our LAN via the wireless. I can't seem to get the Airport Express to "roam" between the two access points, ie, when one AP's signal gets too weak I would expect that the Airport Express would switch to the stronger of the two AP's. Is this a correct assumption?
    In the AirPort utility when you set an Airport Express as a remote it only allows you to specify one "main" AP, so I don't know if this is why I can't seem to get it to roam between both AP's. Anyone have any experience / success doing this? Thanks for any information you can provide.
    Joe Jenkins

    if possible, it sounds like you need to configure a "roaming" network, not a WDS. Of course, I am assuming that all your base stations have access to your LAN via ethernet...
    - Configure each base station with the same network name and authentication/password.
    - Put each base station in bridge mode (unless you need 1 of them to distribute ip addresses).
    - Each base station needs to be on a different channel - and make sure they spread apart, like 3 and 11, as opposed to 3 and 4.
    Basically make sure they are configured exactly the same except for the wireless channel.
    Roaming should improve.

  • Roaming with Multiple AE's connected to router.

    I can't find info on  my particular wireless layout.  I have three Airport Extremes connected to the LAN.  Each AE has a unique static IP LAN address.  NAT and DHCP is handled by the router.  What I am trying to do is set up a roaming wireless network.  I saw a thread on doing this with one AE connected to the WAN and the other AE's connected to it (http://support.apple.com/kb/HT4260), but this would be difficult to implement here.  I seem to remember reading that what I am trying to do can be done by setting each AE to 'Create a Wireless Network', and giving each the same Wireless Network Name, and password, which is what I am doing now.  This works, but is extremely slow.  Is there a better way to implement roaming, using my current AE wiring scheme; i.e. with each AE connect to the router?

    I thought I'd give your suggestion a try, but I'm in trouble.  Network is down and I can't figure out where I went wrong.  Can you give me a link for manual setup of an airport extreme wds network from scratch?
    I don't have such a link. A Google search can possible peace together all the info you need. Apple does provides guides in PDF format though. Try the link below.
    http://manuals.info.apple.com/en_US/Apple_AirPort_Networks_Early2009.pdf
    The newer 802.11n routers running the latest firmware don't use the WDS terminology anymore. They just use 'Create a wireless network' for the main router and 'Extend a wireless network' for the routers that connect to the main router if you are doing it all wirelessly.
    See this link for screen shots: https://discussions.apple.com/message/17475933#17475933
    I've managed to get wireless working for the main AE which is connected directly to the cable modem, but that's about it.  I have a static WAN address (actually I have 5, but that's another story).  The terminology is a bit different than I am use to. On the 'Internet Settings'  I assume 'IP address' is the static WAN address of the AE and 'Router Address' is the WAN  gateway address.  Where do I give the AE a LAN gateway address?  Half the stuff on my network uses static addressing so I need to establish a LAN gateway address.
    You have a small subnet and static addresses. Nice! I used to have one of those.
    You should be aware that Apple's AirPort routers are designed for a single static IP address at most. They are residential routers, not meant for a business setup as your service appears to be. If you can live with only using one of the five addresses you have available then the AirPort router will work for you. You can designate one of your LAN addresses as the default route for use with a server.
    If you require being able to use more than one of the static addresses you have available to create static routes to servers on your LAN then you'll need a business class router that can do Multi-NAT. Maybe the router you were using is more suited to this.
    I've set the 'main' AE to provide both NAT and DHCP.  I plugged the other two AE's into it, leaving them in bridge mode.  Airport utility incorretly shows all three AE's connected directly to the internet.  Lastly, the Airport Utility shows the internet status as disconnected, which also isn't true.

  • Basic question on roaming with 12XX APs

    Hello,
    We are installing 6 or so Autonomous 1242s which will be side by side with an already installed group of autonomous 1100 series. Does roaming between APs on the same SSID happen automatically as you reach a certain low level of signal, is there anything specific that has to be setup? I've read about WDS, but the clients are not using Cisco Aironet NICs and are using WEP. Any assistance on how the roaming takes place and how to make it as seamless as possible would be fantastic!
    Thanks,
    JG

    Roaming is the behavior of the wireless client. How and why a client roams is based on the driver largely. Some clients roam better than others and use different measurements to indicate when a client should roam.
    When a client hits its threshold it will send PSP (power save poll) frames to notify the access point to which it is already associated to, to buffer frames as the client goes off channel to find other access points to roam to. The client will flood all channels with probe request, access points within the range which hear the probe request will respond with probe responses.
    The client will then decided based on probe responses which access point it will then auth and ass to ..
    With all that being said… you want to make sure you have a proper survey done so you don't have access points to close or to far away to each other, thus causing co - adjacent channel interference.
    Normally you want your access points powered at the lowest client level. Again, you don't really want them very loud (reaching further than they need to) or to low where you have a ton of access points either.

  • Roaming with WRT54GX and WAP54GX?

    Hi,
    I have a WRT54GX, and want to add a WAP and automatically roam between them (effectively extending the range of my wireless network).
    So I was thinking of buying a WAP54GX (or similar), wiring it to one of the ethernet ports on the WRT54GX and setting up the WAP with the same SSID and security settings.
    As the WAP would be on the internal network, clients could still get a DHCP address from the WRT54GX.
    Questions:
    1) would this work, and if not how should it be done?
    2) does the WAP need to be on the same channel, or can it use another channel?
    3) can I use newer WAPs then the WAP54GX?
    Linksys WRT54GXv2 (2.00.20 firmware)

    Yes this should work. You should use WAP54GX and set the wireless settings exactly same as the router. You should be able to roam without any issues. No need to set different wireless channels.

  • PEAP support with WDS

    Hi,
    I understand that the WDS can provide fast roaming by caching the authenticated user credentials when using LEAP. But what if I use PEAP with certificates for both server and client authentication? I suppose the WDS won't be able to cache the certificates. Then, how doesn't it work? Or is PEAP supported by WDS? Thanks.

    WDS is a centralized method of security that can be used with any EAP method for the authentication of your clients. Refer
    http://www.cisco.com/en/US/products/hw/wireless/ps4570/products_configuration_example09186a00801c951f.shtml#backinfo

Maybe you are looking for

  • NF-e 3.10 - Nota SAP ausente - Função p/ conexão não-GRC

    Boa tarde, estamos fazendo a implementação da NF-e 3.10 com mensageria não-SAP. (Sem o uso do GRC). Após aplicação da Nota 1933985 ( NF-e new layout 3.10 ) a função que faz a conexão com mensageria ( J_1B_NFE_XML_OUT, que existe no ECC ) não é mais c

  • Firefox crashes when opening after upgrading to 6.0.2

    After upgrading firefox to 6.0.2 firefox crashes upon opening. When I try to open firefox the "Mozilla Crash Reporter" opens up. I tried all the sugestions on the support page. None of these worked. It will open with the computer in safe mode. I can

  • TS4147 How do I resolve duplicates resulting from contacts created from different accounts?

    I have duplicate contacts in my address book. I discovered by merging that the duplicate contacts were created from different accounts. How do I ID the account the contact was created from? Note: the duplicates are in my address book only. I do not h

  • To get only the error messages???

    Hi, When i compile my java code i am getting warning errors also . Is there anyway to get only the error messages only, not the warning using javac or java??? Thanks, JavaCrazyLover

  • Difference between LIKE & TYPE

    Can u please help me with this query .......how do we distinguish the declaration eg: VAR TYPE SPFLI-CARRID &    VAR LIKE SPFLI-CARRID when to use what? please suggest. Thanks. With regards, Narottam.