Flexconnect AP with auto anchor at head office

hi All,
  I have a head quarters with two WLC5508 anchored to another 5508 on the DMZ. Now we want to roll out wireless guest to the branches with local switching of guest wireless traffic. The guest ssid used at head quarters is anchored to the guest controller and using webauthentication.
Question 1: Can i use the same guest SSID for branch also in this case ?
Question 2 : If i only enable "HREAP local switching" feature on the guest SSID, will the other HQ SSID's still be broadcast in the HREAP branch AP's ?
I am assuming the guest ssid at branch will take IP address from local IP subnet since its local switched, webauthentication will happen on the HQ guest controller ? and once webauth completes, guest SSID traffic will be locally switched . Is this correct ?
regards
Joe

1. client sends DHCP request and gets IP on locally defined VLAN on the HREAP AP
during this, the controller get to know of the client association via the CAPWAP control message from HREAP AP
Yes, but the WLC will not get any client data since the traffic isn't going back to the WLC.
2. Client opens browser and enter website address (google.com) and gets the controller webauth login page
is this step happening in the capwap tunnel or outside it ? the TCP communication between client and WLC
This happens all inside the mobility tunnel back to the anchor wlc.
3. Client enters username and password for webauth
but the wlc virtual IP is not routed anywhere, so how will the username and password reach the wlc ? (through the capwap tunnel ? )
The WLC uses it VIP, client doesn't care.  If you have a 3rd party certificate, you need to make sure the FQDN is resolvable with the VIP address or you will get a certificate error.
4. controller checks the username/password eiither locally defined or can be on a nac guest server or ISE ?
if the username/password reaches the controller, it should be able to verify the credentials wtih an external entity like NGS oR ISE ?
Well what is hosting the webauth... the WLC or NGS or ISE.... only one can do this and that is what you have to decide.
Thanks,
Scott
Help out other by using the rating system and marking answered questions as "Answered"

Similar Messages

  • FlexConnect (aka H-REAP) and Auto-Anchor functionality

    Hi Board,
    I never did H-REAP on my wireless deployments. Now, I have an H-REAP (FlexConnect) requirement for branch offices.
    Also there is the requirement for guest access at the same time.
    From my understanding those features (FlexConnect and Auto-Anchor) should work together.
    Please refer to the following exibit:
    There is a FlexConnect AP at my branch office. The traffic from internal users (SSID "Internal") should be switches locally at the LAP (Lightweight Access Point). At the same time the guest SSID (SSID "Guest") should be tunneled back via CAPWAP to the controller to which the LAP is associated ("Central Controller"). The guest traffic should not emerge (switched) at the "Central Controller", instead it should be tunneled to an anchor controller in a DMZ via an "Ethernet Over IP tunnel" (Auto-Anchor functionality).
    First question: Does this work (FlexConnect in conjunction with Auto-Anchor functionality)?
    If this works, where's the web portal for guest authentication hosted (if using the internal web auth on WLC)? On the "central controller" or the Anchor controller? (I guess at the Anchor Controller in the DMZ, right?)
    Is it possible to leave the guest SSID "open" with no webauth and still using the Anchor Controller? This would be needed if I have an external web authentication service, which would be hosted by a provider.
    Thanks in advance for all your replies!
    Johannes

    The Flex 7500 deployment guide ("
    http://www.cisco.com/en/US/products/ps11635/products_tech_note09186a0080b7f141.shtml
    ") states:
    "The Cisco FlexConnect Solution also supports  Central Client Data Traffic, but it should be limited to Guest data  traffic only."
    later in the document there is a section about Guest access that states "Flex 7500 will allow and continue to support creation of EoIP tunnel to your guest anchor controller in DMZ."
    Hope that helps.

  • Layer 2 security with WLAN auto-anchor mobility

    Hello,
    I was wondering if Layer 2 security can be used with auto-anchored WLANs.
    I need to deploy two new isolated WLANs which will terminate in two DMZ environments.
    I was hoping to use the existing WCS-managed infrastructure with 4404 and 4402 WLCs and just throw on a couple more WLANs.
    However, I've built a little test environment and while I can get the new VLAN traffic tunneled and origininating from the correct anchor controller with no layer 2 security - as soon as I turn on WEP or WPA security options it stops working. I can't find anything in documents or this forum to show auto-anchor mobility with anyhing other than unsecured guest WLANs.
    Am I trying to do somethng unsupported or is it just an error on my part?

    Hi Greg,
    no, the users are internal so I only want to use L2 security. I can't see that L3 should be a problem to add on though. I'm using 3.2.x of the WLC code - so there is no "Guest LAN" mode - I was playing with the new versions and it looks like L2 security is disabled in that mode?
    If you want to see how I got my bit working I would be happy to share my doco when I'm done.
    regards,
    Aaron

  • Indesign Bug with Auto-Size and fitting in Anchored frames

    Hi,
    Steps to reproduce:
    1. Create a text frame with 2 Anchored text frames with the same width.
    2. Make the anchored frames Auto-Size --> Vertical only
    3. insert text to the first frame, when type enter to the next line the frame become higher but the next frame remain in the same position. just after typing the first character in the second line the next frame adjust in the right position.
    4. The same happen when pasting text that make the frame bigger.
    5. The same happen without Auto-Size when fit frame to content.
    Does anyone knows about it?
    Any idea how to bypass?
    Thanks

    This is a user to user forum with "some" Adobe staff participation, report bugs at this link
    https://www.adobe.com/cfusion/mmform/index.cfm?name=wishform for bugs or feature requests

  • Proper way to install windows update on Exchange 2010 DAG with one mailbox server in Head Office and 1 mailbox server in DR site both are members of 1 DAG

    Hi Guyz,
    I have this setup in my exchange environment.
    1 DAG with 2 members
    - One member is located in Head Office and the other member is located in DR site. All of the mailbox databases are located only in HO (Plan to add additional second member in HO soon). Now what is the proper way to install windows patches on the
    member in HO? I don't want to move the databases to DR site as much as possible.
    Appreciate your feedback and Many thanks in advance guyz..
    More power to all!
    Regards,

    Hi,
    To update the DAG members with new patches, the update process should be managed to prevent all of the DAG members from being offline at the same time.
    To do this, I recommend you move the active mailbox databases off a particular server so that it can be patched, and if necessary rebooted, without causing any downtime for mailbox users on that database.
    For detailed steps, here is an article for your reference.
    How to Install Updates on Exchange Server 2010 Database Availability Groups
    http://exchangeserverpro.com/how-to-install-updates-on-exchange-server-2010-database-availability-groups/
    Note: Microsoft is providing this information as a convenience to you. The site is not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. Please make
    sure that you completely understand the risk before retrieving any suggestions from the above link.
    Hope it helps.
    Best regards,
    Amy Wang
    TechNet Community Support

  • Please, REAL Nokia Head Office open you eyes with...

    SAWASDEE (hello) , from Bkk, Thailand
    This is my experience from Nokia X3-02 and after that from their service ....
    For Nokia X3-02 in bkk, thailand is around 195 us$. 
    This is some inconvenience I found at the first time till NOW .....
    Just after I bought X3-02 on 15th February...... 
    I just picked 2 calls for 30mins each, and on facebook just for a few times during work in evening then battery is empty and again on next day even it was charged 6-8hrs/time. 
    Then I went to power buy (a big electric dealer) and asked for a new battery on 18th February, but still had a same problem. Finally I had to change a new X3-02 on 22nd February.
    That happend in 6days after bought it. ***BUT ITS NOT OVER...!!!! Still got battery problem and more*** 
    I went to Nokia Care on 28th February, and found X3-02 couldnt on wifi even I was in Nokia Care, I showed them and we found the touch screen didnt work too. Couldnt push any bottom.
    Had to switch off only !!!!
    I had to go to Nokia Care in another department store for a few times, and then back to the place that I bought X3-02 for a few times toooo. Do you know what is trouble traffic in BKK and how is far between 2 department stores?  Really wasted my time and took some energy with not good feelings ....!!!
    How much does the COST that I paid for a new mobile, not only MONEY  ...??? 
    I like to stay on Nokia and always recommend to my friends. After these
                                                                  .... I am not sure ...
    I REALLY GIVE UP WITH NOKIA X3-02 ..... I SENT IT BACK TO NOKIA CARE AND REQUEST FOR ANOTHER MODEL INSTEAD.
    I got a few calls from Nokia Head Office Thailand.
    On 4 th March, they called me and we found an agreement for us that I will get Nokia E5. In eveing on the same day he said " I will got E63 instead BECAUSE E5 is quite new model and we still dont get more feedback from customer ... on Wednesday.  
    The recently call is that mobile will ready for me at 4pm. on Friday 11th, March.
    Why they needed more one week to sent a new one to me ?
    Where is the head office of Nokia Thailand...??? Is it in Bkk...??? Or in Finland ...?????
    I bought X3-02 on 15 FEBRUARY 2011 !!!!
    And my new smart phone is at Nokia Care since 28 FEBRUARY...
    What do you think ...with those things that happened to me ?
     I am so DISAPPOINTED ....with their product and service.
    Just would like to let you know......
    i got E63 with 2 million pixel ONLY and with less function than  X3-02 with 5 million pixel camera and more function...
         ******* Is it FAIR to give me E63 instead of X3-02 ......???? ****** 
    I said I want good quality camera and many options even it is old version .... But I got only 2 mpixels + no edit photo with basic smart phone ....
                     ...... Sorry for these, but I really  can not ACCEPT ....
    Nokia Thailand always said "we would be happy to help you" ......
    But only words that I got ...and make me UNHAPPY to have E63 till now. 
    And now here is my question: what would you do in my case ? Or what can Nokia do to make a customer as me to be happy again ?
    regards
    your customer

    For the record, I don't think I am able to upgrade to the current software version.
    My phone model is 05411312 (N73 on UK T-Mobile), and NSU won't let me update beyond v. 3.0704.1.0.1
    I really want to be able to upgrade, I'm quite annoyed that I can't add all of the amazing new features that Nokia announced for S60 phones a month ago because of this - I want to try the official MSN client, Music Store, etc. I wouldn't have bothered trying to upgrade the software if it wasn't for trying to add these features.

  • Invoic & GSVERF IDocs with Head & Office Branch office relationship

    Hi ,
    We have maintained Head office & branch office relationship in vendor master.
    Based on this master data set up, all accounting documents are getting posted to Head office account. Currently we are facing the below issue:
    We have created purchase order for Branch office vendor (Eg. B) and as required accounting document is getting posted to Head office vendor(Eg. H). We are using Idoc Msg type 'Invoic' for this invoice verificaiton and using Idoc msg type 'GSVERF' to send acknowledgement for that Invoice.In this case, Acknowledgement IDoc has been getting transmitted to Head office vendor (H) and not the Branch vendor (B) who
    has originally sent the Invoice.
    Kindly let me know whether it is possible to forward acknowledgement vendor to branch account instead of Head office.
    Thanks
    Hari

    Moved from SAP ERP Sales and Distribution (SAP SD) to SAP ERP Financials
    G. Lakshmipathi

  • Integrating branches with the head office

    Hi,
    my client is having 1 head office and 2 branch offices ,
    both in the head office and in the branch office also they want use sap business one ,
    what is the best solution to integrate the branch and head office ,
    can any one please suggest the best possible way to do this
    thanks for any suaggeations,
    naresh k .

    Naresh,
    You can look at using B1iSN, but the integration of B1 to B1 is not standard "out-of-the-box" and would need to be created.  For more information on B1iSN ... you can go to this link ...
    SAP Business One Integration for SAP NetWeaver (B1iSN) [original link is broken]
    ...for examples of B1 to B1 integration using B1iSN ... you can see this link ...
    https://www.sdn.sap.com/irj/sdn/softwaredownload&download=/irj/servlet/prt/portal/prtroot/com.sap.km.cm.docs/business_packages/a1-8-4/Business_One_Live_Expert_Sessions/SAP_Business_One_Integration_Technology.zip
    Eddy

  • Please give me idea now I compile all branch data in head office only new r

    Hi master
    Sir I have 5 office In different city and one head office in Karachi all branch have same oracle system my question is how I get new data and compile for accumulative reporting
    I want only new record and modify record not old record
    Old record already I import
    When I use oracle import and export tool that no give me right result
    If xxx table exists in database then import tool not replace and no insert or no replace with previous data with new modify data
    Such as
    First time
    V_no=897 have debit amount 3998 is Islamabad branch and i export form Islamabad and import in Karachi office
    Next time
    Islamabad office change v_no=897 debit amount with 76555 and add many new record
    I export form Islamabad and import in Karachi office but system no change and not add new record in Karachi office
    Please give me idea now I compile all branch data in head office only new record and modify record
    Thanks
    aamir

    Here a very simple example with table EMP, assuming source table has a primary key. Firstly you create a materialized view log on source table (necessary for fast refresh) :
    SYS@db102 SQL> conn test/test
    Connected.
    TEST@db102 SQL> create materialized view log on emp including new values;
    Materialized view log created.
    TEST@db102 SQL> then at destination DB/user :
    TEST@db102 SQL> conn scott/tiger@test10
    Connected.
    SCOTT@test10 SQL> create database link test
      2  connect to test identified by test
      3  using 'db102';
    Database link created.
    SCOTT@test10 SQL> create materialized view emp_mv
      2  refresh fast
      3  as select * from emp@test;
    Materialized view created.
    SCOTT@test10 SQL>Now emp_mv is the exact copy of emp. To refresh the MV, to reflect changes :
    SCOTT@test10 SQL> exec dbms_mview.refresh('EMP_MV','F');
    PL/SQL procedure successfully completed.
    SCOTT@test10 SQL>                                                                  ...but I strongly recommend you to read the documentation...

  • SUN .... When....  JRE 1.4.0 international with auto update

    SUN .... When.... JRE 1.4.0 international with auto update
    When will you deliver .........
    We have a dead line and our product needs the international version 1.4 to be updated on our exsiting user base, one of our customers has over 700 workstations.
    If the solution is to manually dowload and install this version then Web Start totally fails as a web centric solution.
    I see that creating our own servlet breaches SUN's license agreement, so give us a developer servlet we can use.

    The auto download servlet supports both international and us-only versions of Java 1.4.0.
    Java Web Start includes the current locale in the request to the servlet, and it returns the
    US only version if the locale is en_US , or the international version otherwise.
    Curently there is no way to get the servlet to download the international version when the
    clients locale is en_US.Sorry but havent you just anwsered the question I put, either the servlet supports international clients or it dosent and your anwser just puts more wood on the fire, it dosent, but it could.
    Also we recognize that there is a problem when an application needs the international version, and >>the client already has the US version installed. In this case Java Web Start will not attempt
    to contact the servlet since it thinks it has an appropriate version allready.Also if you client requires an international version of the JRE it is because it requires that version period, hence if the version tag within the JNLP file specifies JRE1.4 international, then it dosent matter what Web Start may or may not think, the JNLP file written for the application by the author should determine its fate.
    The only reason Web Start should determine locale on a target machine would be the text displayed for the dialog interface between the end user.
    Its a simple case of checking do I have 1.4 international, "Yes or No", at this point I dont care if 1.4 English is installed, or locale is English, JNLP file asked Web Start, if 1.4 international was installed, "No", Ok then call servlet and request 1.4 international. Simple....
    The JRE license agreement allows customers to repackage and redistribute the JRE.
    Many customers are redistributing a JRE with their app. Im sure many are, please read my previous post , if you can get sun to offically confirm this, then I stand corrected.

  • IHC FINSTA Bank Statement not created in head office IHC account

    Hi,
    This is regarding Incoming Receipt for subsidiary in IHC.
    I uploaded electronic bank statement with payment notes indicating it is a incoming receipt for subsidiary 3000.
    IHC document is generated while executing FF_5.
    FINSTA bank statement available in Subsidiary IHC account 3000010.
    However there is no IHC bank statement available for head office 100010.
    No Payment order is created in IHC0.
    Appreciate the IHC experts out there to help me with this issue.
    Cheers.

    Hello Anya,
    Yes I got it fixed by scheduling FEBP as job after bank statement generation in my IHC day end processing. Now the statements are getting posted.
    Thanks for your post.
    Regards
    Ashish

  • Head office and branch office accounts

    HI sap gurus,
    can any explain the configuration steps for head office and branch office accounts in vendor and customer master accounts and how to post an invoice in this configuration
    Regards,
    Umesh

    I am assuming u are using SD integration for the billing . Therefore, please go to VD02 for the Child Customer profile under the correct sales org,distbn channel, div.
    Then under the Partner functions tab set the SP Sold to party as the Child, BP Bill to Party as Parent,PY Payer as Parent and SH Ship to party as Child.
    If its only for FI documents config then proceed in FD02 only, else if its integrated then use XD02.
    Then under the Company code data in the Account management Tab set the Head office as the Parent . Then all the future postings will have Acct = Parent but Branch = Child.
    If you want some examples which we have discussed before then go to
    Re: Customer Master -- Parent + Child Relationship
    Link between Branch Accounts and Head Office Account
    To link branch accounts to a head office account, you must enter the number of the head office account in the Head office field in the branch account master record. This field is contained in the company code area of the master record.
    The head office account can be any vendor account except one-time accounts or branch accounts themselves. Branch accounts and head office accounts must belong to the same company code.
    Line Item Display
    When you are entering the parameters for line item display, you should note the following: for head office accounts, enter the key 004 in the field Sort key. This instructs the system to display the line items for the head office account sorted by branch. This key is defined in the table for allocation rules.
    For more information on line item display and the Sort key field, see Sorting Line Items
    Correspondence
    You can set up your system to cater for written correspondence with vendors a) for the head office, broken down per branch or b) for each branch individually. If you want to create correspondence (such as dunning notices and account statements) for the individual branches instead of the head office, you have to select the Local processing field in the vendor master record of the head office on the Create Customer: Correspondence screen.
    You can also define payment methods in the master records of the branches and head offices. For example, if you want to have certain payment methods for particular branches, enter these in the master records of the branches concerned and do not enter any payment method in the head office master record. If you enter payment methods in both head office and branch master records, all payment methods are possible.

  • Define Head office in Oracle HRMS R12

    Hi,
    Please I need to know how to define the head office of a group the best way:
    I have a defined business group under which is already defined many companies. I need now to define the head office with its own employees.
    Please advice.
    Thanks

    As my understanding you have requirement to create organization wity Type "Head Office" In a Business Group.
    you can create a number of organization with Type Head Office in Business Group and there you can assign employees.
    Change or Include "Head Office" in ORG_TYPE lookups for your requirement.
    Thanks

  • F110 head office customer/vendor

    Hi
    when I do a payment by the F110 and I am using head office and subsidiary which is also a costumer the system doesn't show the open departures of customers. How can i do the meeting between  the branch and customer.

    Hello,
    To give some more clarity on this.
    You can have branch and head office in your system as customers. In the branch master data, you can assign the head office.
    You specify this account number only for branch accounts. Items that you post using the branch account number are automatically posted to the head office account. The system records the branch account number in the line items.
    Neither transactions nor balances are kept in the branch account.
    There you can have number of branches which can be integrated with its head office and you can CENTRALLY have transactions with head office only. More easy and single point of contact.
    Regards,
    Ravi

  • Head Office account in FBL5N

    Hi there!
    We have an head office account. When we viewed it in FBL5N with the following paramters: Customer, Company code and Open item as of xx.xx.xxxx. The result of which for example is 50000USD. Then we tried to use FBL5N but with different parameter. We select from the dynamic selection - head office and indicate the account, open item as of xx.xx.xxxx. The result was 35000USD.
    Can you provide possible reasons why the result is different?
    Thanks a lot.

    Head office account number (in branch accounts)
    This field contains the account number of the head office.
    This account number is only specified for branch accounts. All postings for which the account number of the branch is specified, are automatically posted to the head office account. The account number of the branch affected is noted in the line items.
    No line items or balances are managed in the branch account.
    It is due to this.

Maybe you are looking for