Creating Dual SSID's

We are running phat architecture (WLSE, ACS, 1230 AP's) and PEAProtocol. I want to create additional SSID's on every AP (WPA-PSK) for vendors.
My questions is this: "Are there any good documents that discuss the creation of dual SSID's, VLAN/AP configuration, and/or best practice approaches?"

Hi Darin,
jep there are some documents.
Using VLANs with Cisco Aironet Wireless Equipment
http://www.cisco.com/en/US/products/hw/wireless/ps4570/products_configuration_example09186a00801d0815.shtml
For usage of a WLSE, PEAP and ACS have a look here
Protected EAP (PEAP) Application Note
http://www.cisco.com/en/US/products/hw/wireless/ps430/products_technical_reference_chapter09186a008025d6ee.html
Additional Information about WDS can be found here
Wireless Domain Services Configuration
http://www.cisco.com/en/US/products/hw/wireless/ps4570/products_configuration_example09186a00801c951f.shtml
These documents will give you the right hints for your task.
Best reagrds,
Frank

Similar Messages

  • Channel configuration on dual SSID

    I am installing a few aironet around a environment which requires dual SSID one for Guest and the other for business.
    When configuring the channel for each SSID should I make both SSIDs on the same aironet the same channel and then ensure the closest aironet with the same dual SSIDs is both on the same but different (non-overlapping) channels ?
    Or should both SSIDs on each aironet be on different channels?
    Thank you.

    Channel selection ... Hmmmm ... autonomous IOS ... Not a good combo.
    I mean the issue here is your 802.11b radio.  If you have neighborhood wifi around, smart money 802.11b is being used and  Channels 1, 6 and 11 are used too.  No issues with 802.11a since there are more channels to play with.
    It's OK if you have a WLC because of the Dynamic Channel Assignment feature.  But with autonomous WAP, you need to constantly monitor your neighbor.

  • Create hidden SSID in Windows 8/8.1

    I need to create hidden ssid in windows 8 using the netsh wlan command.Kindly help me to do the above.The process of creating the ssid details in in the following linkhttps://technet.microsoft.com/en-us/library/cc755301(v=ws.10).aspx

    Hi KeithWeisshar,
    WSD drivers are supplied and supported by Microsoft.  The version numbers and dates are not comparable to the numbers and dates for our drivers.  While WSD will provide you with basic printing capability and some features, to get the most from your printer, I recommend using the drivers found on our website. 
    If you have any other questions, please feel free to Contact Us!
    Did this answer your question? Please click the Accept as Solution button so that others may find the answer as well.

  • Trying to create dual boot with Windows 7 on Yoga 11s

    I was trying to install Windows 2008 server (I said Windows 7 in the title because it's essentially the same) on a Yoga 11s in dual boot configuration with the factory-installed  Windows 8 upgraded to 8.1, and as expected it's a pain in the butt.
    I ran into the catch-22 that you can only boot from a USB external optical drive in legacy mode, and then Windows refuses to install on a GPT-type partition.  Dead end there.
    As plan B, I tried installing from my MSDN DVD from within Windows 8.1.  It chugged along for a while, but then hung after the second restart.  It reached a state where the machine is dual boot, and goes into Windows 8.1 OK, but 2008 server hangs on startup even in safe mode.  Probably it's a driver problem.  I downloaded all Windows 7 drivers for the Yoga 11s from the Lenovo website, and they would work fine for 2008 server if there was a way to put them in place.
    I have been through the process twice before on previous machines.  After getting the server OS to install, none of the devices work well or at all, but I could patiently install the drivers using device manager.  This is the first time where I can't get the server OS to install to a bootable condition.  Is it hopless, or might there be documentation somewhere about how I could manually place drivers in the right folders to enable the OS to start?
    Plan C might be to follow Lenovo's instructions to create a UEFI bootable USB flash drive and try to install from that.  Would that work better than installing from within Windows 8.1, or just reach the same roadblock?

    Reformat that new drive with SL DVD.
    Go into SL DVD again, go to Utility Menu and choose DU.
    Then try repairing the drive or better yet, just erase the drive (not the volume) and try again.
    There are enough changes between Tiger partition scheme and SL that you would want to. RAID arrays built with Leopard will not allow installing SL, they have to be recreated (and can then have Leopard and SL).
    Go

  • Dual SSID's

    I am looking into purchasing 2 1131AG's. What I want to do is have 1 access point on each floor of my buidling, 2 floors total. Now I want to make sure that when an employee gets on with a wireless laptop, he can access the wireless network with full permissions. When a guest comes, I want him to access only the internet and no internal network.
    This brings me to create 2 seperate SSID's. One for Internal Network and one for Guests.
    Is it possible to setup 2 different SSID's on both Access points in this way so that a guest or employee walks between floors and has uninteruppted connectivity?
    These access points will be connected to Cisco 3750 Layer 3 switches in a Windows server 2003 environment.
    Users will have mixed vendor Wireless A G and B wireless network cards.
    Can this be possible ?

    Assuming you have the coverage you need with one AP per floor, yes, it's certainly possible.
    Set up two VLANs, assign an SSID to each. Set up your L3 switch for trunking the two VLANs. Forward the traffic from your guest VLAN to your Internet Gateway device, Send the traffic for the internal network to your network gateway device (putting that VLAN in a DMZ would be a good thing.
    Put in some ACLs for good measure, establish whatever encryption you feel appropriate, and you're good-to-go.
    The MS IAS can only handle PEAP, EAP-TLS, EAP-TTLS, and (probably) MD5. Using MS-CHAPv2 for internal auth is recommended. Microsoft has some pretty good white papers on setting all of this up on their site.
    Good Luck
    Scott

  • Creating dual monitor workspace

    I found one ancient message from September with absolutely no responses, so let's try again.....
    Bridge CS4. Dual monitors. HOW do I create and SAVE a workspace that takes advantage of both monitors? I want to put previews and some palettes on one monitor, and the rest on the other. But, I don't seem to be able to save the whole thing so it's the default setup.
    How do I do this?

    I don't believe you can. I do think the save workspaces feature is that
    smart or goes that far. At least when I have tried creating a dual monitor
    workspace and save it, it never comes up like a created it. I think what the
    problem is that when you create that secondary window for the other monitor
    it isn't just a window created by the main application but a second light
    copy of Bridge loaded in to memory so when you close bridge that is lost.
    This has been an issue since they added workspace capabilities to Bridge.
    It certainly would be nice if this worked however.
    Robert

  • Importance of precise colour temperature when creating dual-illuminant DNG profile

    I own an X-Rite ColorChecker Passport and would like to use it to create a dual-illuminant profile for my camera (and every lens combination) to use in LightRoom.
    After extensive research I have a few lingering questions:
    1)      How important is it to nail the colour temperature. Do you *absolutely have to* photograph the ColorChecker under Illuminant A and D65, respectively, down to the last Kelvin?
    2)      If I don’t nail it down that precisely, will the resulting profile be any less accurate?
    3)      If getting the respective colour temperatures exactly right is indeed that important, is it OK to use 2 diffused and gelled speedlites with Lee/Rosco color correcting gels to illuminate the Colorchecker? (The Lee / Rosco gels do not have the exact CTO gel for the 2850K specified in the DNG specification for Illuminant A, but it gets close)
    4)      If it will really aid profile accuracy, how does one get hold of reliable/certified light bulbs that produce the required colour temperatures? (I’m in the UK)
    Your advice will be greatly appreciated.

    The exact color temperatures (in Kelvin) are not that important within the standard daylight range (above 4000 K), because large number changes in color temperature actually represent small differences as far as camera color profiles go.
    What is more important (rather than the exact number) is the spectral characteristics of the illumination. This isn't easy to characterize for the end user, but you can think of it in terms of bulb type. Most compact fluorescents are spectrally very different from actual daylight (even if the bulb is indicated as being "full spectrum"), for instance. My recommendation is to create a profile for the type of lighting you will be under, rather than trying to match the exact numbers.

  • Dual SSID (with dual VLAN) on Cisco AiroNet 1130

    Cisco Community,
    I need some major help in figuring out how to change our wireless setup. Currently, we have 2 Cisco AiroNet 1130 WAP's in the office that go directly into the 2 POE ports on our Cisco ASA 5500. These WAP's have 1 SSID and are using WEP for security. After demonstrating the flaws of WEP to my boss, he has agreed that we should use something more secure and I've suggested WPA. We want visitors to our office to be able to hop on our wireless but on a separate guest SSID with WEP.
    I'd like the internal SSID to route to the ASA and take the default route to the internet (it will be our new fiber connection once it's installed in a couple weeks). The default route is whichever connection is working since our ASA 5500 will fail over when it detects an outage.
    I'd like the guest SSID to route to the ASA and then go over our existing cable connection. This connection will be our backup once the fiber connection is installed. Since we won't be using it very often, but will be paying for it, I advised that we send all guest wireless traffic over this connection since 50/5 is plenty for guests.
    I have no idea how to create a VLAN and implement it but I can generally figure things out with a little help. The current SSID (which will be the internal SSID) has no VLAN. We do currently have a few VLANS on our network, one for voice (.42) and one for data (.100) and the default (.0). What device to I create the VLAN on (Cisco 5500?) and how to I setup the WAP? I need very basic instructions to start and I'm also trying to do this without causing downtime if possible.
    I've attached a diagram of what it should look like. Red indicates our internal network and Blue indicates the guest network. I can send screenshots as well.
    Hope everyone is enjoying their holidays.
    Thanks,
    Cody

    Cody,
    Here is a good doc to follow... it explains multiple ssid's and vlans
    https://supportforums.cisco.com/docs/DOC-14496
    Sent from Cisco Technical Support iPad App

  • Create Dual Layer Video_TS folder?

    I don't have a Superdrive on this MacBook but I do on my other PC. I want to create a Dual Layer DVD Video_TS folder to transfer over to my PC and burn. The option is greyed out in the project properties window to select dual layer disc. I want to enable it somehow so I can see if my project will fit the Dual Layer disc limit.
    Any ideas?

    If you can create a DL disk image you can convert it over to an iso dimage either on the Mac or on the PC. There are a number of sites discussing it:
    macosxhints.com - Convert .dmg files to .iso files for burning ...
    convert iso dmg - Mac Support
    It all depends on whether you can create the disk image of the DL project. I don't know if you can.
    OT

  • Creating Dual Layer DVDs

    I'm trying to encode a dual layer DVD. I'm rendering the project with iDVD and creating a disk image of the DVD on my hard drive. I'm then using Disk Utility to burn the image to a DL disk. The DVD plays fine about half-way through on my DVD player and then freezes. I'm guessing the DVD player is having trouble transitioning to the second layer indicating there is a problem w/ the way it was encoded. The DVD player is functioning fine, as it does not have problems with other dual layered disks.
    Is Disk Utility capable of burning a disk image formatted for dual layers onto a DVD? I don't know if iDVD is creating a bad dual layer disk image or if Disk Utility is incapable of encoding a dual layer disk image to a DVD.
    Could someone please comment on what the best way to get a dual layer disk image transferred to a dl DVD using iDVD would be?
    Thanks in advance.

    I agree with Len. You'll have much better luck with Roxio Toast. Len is also very successful at burning from a disc image via Roxio Toast at 4x or slower. And this is really the best approach in my opinion. However I do want to point out exactly what the iDVD Help Menu states with regards to using a disc image and dual layer media. Pay special attention to the final paragraph below:
    Creating a disc image of a project
    You can create a disc image of your project so you can burn additional DVDs of your project without going through the encoding process each time.
    Saving a disc image of your project creates a file that is formatted just like a finished DVD, except it’s not actually burned on a disc. All the media is compressed into the format used on a DVD, and you can play it on your computer by double-clicking the disc image icon and opening DVD Player.
    To create a disc image:
    Choose File > Save As Disc Image.
    Type a name for the disc image.
    Choose where you want to store the disc image.
    Click Save.
    You can use Disk Utility in Mac OS X to burn the disc image to a DVD when you are ready.
    Note: If you burn your project to a double-layer disc, you should burn directly from iDVD rather than from a disc image. A disc-burning utility will not set the layer break according to DVD specifications and may cause playback issues.
    Hope this helps
    SDMacuser

  • How to use migration assistant without creating dual user accounts

    I want to use migration assistant to transfer apps, software & files on my macbook pro to my new macbook air. How can I do this without creating two user accounts for myself on the m-book air -- my account from the m-book pro & the one that the air makes me create as soon as I do start-up? Can I just use the same name & password for both? or will that make things go badly awry?
    Thanks!

    If you have not booted the MBA for the first time and gone through the Setup Assistant, then I would use the Setup Assistant to make the transfer before you even create another user account. However, if you've already created the new user account on the MBA, then create a new admine one with a different username than the account you will migrate. Log into this new account, delete the first account you made, then use Migration Assistant to transfer your account from the MBP.

  • Satellite Pro A200: How to create Dual boot; Vista & XP using Recovery CD

    I have just purchased a Satellite Pro A200 lap-top, which was supplied with Product Recovery disks for both Vista and XP.
    The Vista licence specifically also licences XP.
    Can I set up a dual boot so that I can boot to either Vista or XP ? If so, how?
    I would also like, as a third boot, Red Hat Linux 9.
    Any comments ?

    Hmmm. Usually its possible to use two or more operating systems on the computer but as far as I know the Toshiba Vista Recovery CD formats the whole HDD during the Vista installation and this will lead to losing of the installed OS's.
    Im not 100% sure about the XP Recovery CD The newest CD called RECO doesnt include expert mode which allows choosing between different partitions.
    So I presume every usage of the Recovery CD will format the HDD and will erase the installed data. But of course you could try to install both OS and to check if the XP recovery CD allows choosing second portion for the OS installation.
    If it will not function it seems that you will need either an original Microsoft XP CD or the original Vista CD to use both OS.
    Best regards

  • AP1200 dual SSID's with 128 bit encryption

    I trying to setup a AP1200 radio with two different SSID's with encryption.
    Each SSID must use a different 128 bit WEP encryption.
    Both SSID's must have simultaneous access to the wireless radio.
    I get the client & radio associated but can not pass
    data. And the Clients Link Speed is listed at 1Mbps.
    Any help on the would be greatly appreciated.

    I too have tried this (multiple SSIDs with multiple wep keys). After re-reading the document pointed to in the previous reply I still do not know how to set multiple WEP keys and assign them to the SSIDs. The document doesn't mention WEP keys at all.
    Anone have a sample config using more than 1 WEP key and multiple SSIDs?
    michael

  • Cisco 877W Dual SSID/VLAN Security Issue

    Hi All
    I have an issue with my 877W that is as fascinating as it is frustrating. I have two SSIDs/VLANs, one for trusted LAN users (PRIVATE), and one for guests (GUEST).  The PRIVATE network is secured from the GUEST nework by zone based firewall. Everything works fine, guest devices cannot access private devices, except for one thing - the BVI interface on the PRIVATE network is always accessible to guest devices, and all services open to attack eg telnet/ssh/http/dns etc. I've tried everything to secure this interface from the guest network, including putting deny any any on physical, BVI and VLAN interfaces
    Am I missing something obvious, or some fundamental architecture of the 877 that would stop this interface being secured? Any help aprreciated!
    P.S config has been pared down to basics below
    version 15.1
    no service pad
    service tcp-keepalives-in
    service tcp-keepalives-out
    service timestamps debug datetime msec
    service timestamps log datetime msec
    service password-encryption
    hostname ROUTER
    boot-start-marker
    boot-end-marker
    logging buffered 4096
    enable secret 5 $1$BdpF$r/mAhQGYs8LBlqEpANmke0
    no aaa new-model
    dot11 syslog
    dot11 ssid PRIVATE@123
     vlan 100
     authentication open
     authentication key-management wpa
     wpa-psk ascii 7 046B0A535A15441D2D0C11141A5A5F
    dot11 ssid VISITOR@123
     vlan 200
     authentication open
     authentication key-management wpa
     mbssid guest-mode
     wpa-psk ascii 7 03374C0A08392040420C00
    ip source-route
    no ip dhcp conflict logging
    ip dhcp excluded-address 172.16.1.1 172.16.1.10
    ip dhcp excluded-address 192.168.0.1 192.168.0.10
    ip dhcp pool GUEST
     utilization mark low 70 log
     network 172.16.1.0 255.255.255.0
     dns-server 192.168.0.1 61.9.242.33 61.9.226.33
     default-router 172.16.1.1
    ip dhcp pool PRIVATE
     utilization mark low 70 log
     network 192.168.0.0 255.255.255.0
     dns-server 192.168.0.1 61.9.242.33 61.9.226.33
     default-router 192.168.0.1
    ip cef
    no ipv6 cef
    multilink bundle-name authenticated
    username cisco privilege 15 password 7 073F205F5D1E491713
    policy-map type inspect PM-DENYGUEST
     class class-default
      drop
    zone security GUEST
    zone security PRIVATE
    zone-pair security GUEST-TO-PRIVATE source GUEST destination PRIVATE
     service-policy type inspect PM-DENYGUEST
    bridge irb
    interface ATM0
     no ip address
     shutdown
     no atm ilmi-keepalive
    interface FastEthernet0
     no ip address
    interface FastEthernet1
     switchport access vlan 100
     no ip address
    interface FastEthernet2
     switchport access vlan 100
     no ip address
    interface FastEthernet3
     no ip address
    interface Dot11Radio0
     no ip address
     encryption vlan 100 mode ciphers aes-ccm
     encryption vlan 200 mode ciphers aes-ccm
     broadcast-key vlan 100 change 30
     broadcast-key vlan 200 change 30
     ssid PRIVATE@123
     ssid VISITOR@123
     mbssid
     speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
     station-role root
    interface Dot11Radio0.100
     encapsulation dot1Q 100 native
     zone-member security PRIVATE
     bridge-group 1
     bridge-group 1 subscriber-loop-control
     bridge-group 1 spanning-disabled
     bridge-group 1 block-unknown-source
     no bridge-group 1 source-learning
     no bridge-group 1 unicast-flooding
    interface Dot11Radio0.200
     encapsulation dot1Q 200
     zone-member security GUEST
     bridge-group 2
     bridge-group 2 subscriber-loop-control
     bridge-group 2 spanning-disabled
     bridge-group 2 block-unknown-source
     no bridge-group 2 source-learning
     no bridge-group 2 unicast-flooding
    interface Vlan1
     no ip address
    interface Vlan100
     no ip address
     bridge-group 1
    interface Vlan200
     no ip address
     bridge-group 2
    interface Dialer0
     ip address negotiated
     ip access-group 101 out
     ip nat outside
     ip virtual-reassembly in
     encapsulation ppp
     dialer pool 1
     dialer-group 1
     ppp authentication chap callin
     ppp chap hostname [email protected]
     ppp chap password 7 10580A4F1C4005005B
    interface BVI1
     ip address 192.168.0.1 255.255.255.0
     ip nat inside
     ip virtual-reassembly in
     zone-member security PRIVATE
    interface BVI2
     ip address 172.16.1.1 255.255.0.0
     ip nat inside
     ip virtual-reassembly in
     zone-member security GUEST
    ip forward-protocol nd
    ip http server
    ip http access-class 2
    ip http authentication local
    ip http secure-server
    ip nat inside source list 1 interface Dialer0 overload
    ip route 0.0.0.0 0.0.0.0 Dialer0
    logging trap debugging
    logging 192.168.0.11
    control-plane
    bridge 1 protocol ieee
    bridge 1 route ip
    bridge 2 protocol ieee
    bridge 2 route ip
    line con 0
     exec-timeout 5 0
     no modem enable
     transport output all
    line aux 0
     exec-timeout 0 1
     no exec
     transport output none
    line vty 0 4
     exec-timeout 5 0
     login local
     transport input telnet ssh
     transport output none
    end

    Ignore that. self zone got me. Argh! phew!

  • Could we create 2 SSID in the same security WEB ?

    My customer needs to use the same SSID for 2 building. They would like to use the security WEB for 2 building and difference VLAN. Can they do that?

    Hi,
    You could use AP groups in order to achive the cutomer requirment. Below link details more information on the same.
    http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-vlan/71477-ap-group-vlans-wlc.html
    Hope that helps.
    Regards
    Najaf
    Please rate when applicable or helpful !!!

Maybe you are looking for

  • Hi I need a report

    Hi, I am having two tables as following I need a difference report as following. I was used to write a minus query to find the differences but I am asked to show a report as following. So can any one help me in this regard. Table1 ID Name 1 Nancy 2.

  • How to add integratio​n to a Labview 2.2 applicatio​n

    I run a labview 2.2 application and I want to work out the integral (numeric) of a waveform between two time points. Is it possible? How can I connect the waveform to the intergral VI?

  • How do I download a trial version of InDesign CS4?

    How do I download a trial version of CS4? I need it urgently to do some work for a client. Thanks!

  • All text in caps? CS5

    For any text box I place and type text in, all my text is in all caps. I don't have caps lock on and it's like this for every font. It's the same if I copy and paste text. What am I missing here? I feel like this is something easy that I'm just overl

  • Issue with populating documents with data connections

    Hi Guys I have two issues one we have set up an infopath document for browser enabled.  But when I upload it, it doesnt work in IE. Also how do you get the data connections working to the form? Thanks