Flexconnect - Number of AP pr. Flexconnect Group ?

Hi All
I was searching for this question.
How many APs can you put into a single Flexconnect Group ?
I know that this varies by platform and software release, but I cannot find the numbers anywhere.
In the relase notes it is only mentioned that the number of groups have increased (7.2).
In the configuration guide (7.2), it only says how many APs you can join to a group on the 7500, not any of the other platforms.
Is there a "FlexConnect Feature Matrix" like page where this information is available ?

From the 8.0 Configuration guide :
The number of FlexConnect groups and access point support depends on the platform that you are using. You can configure the following:
Up to 100 FlexConnect groups and 25 access points per group for a Cisco 5500 Series Controller.
Up to 1000 FlexConnect groups and 50 access points per group for a Cisco Flex 7500 Series Controller in the 7.2 release.
Up to 2000 FlexConnect groups and 100 access points per group for Cisco Flex 7500 and Cisco 8500 Series Controllers in the 7.3 release.
Up to 20 FlexConnect groups and up to 25 access points per group for the remaining platforms
No mention of WiSM2 or 2504 (but i guess that those numbers are the same as 5508 since they share software).
The vWLCs numbers are : Supports up to 200 Cisco FlexConnect groups and 100 access points in each FlexConnect group. <- Taken from the vWLC datasheet.

Similar Messages

  • Clients can't connect to AP in flexconnect group

    we are converting a large number of AP's from autonomous to lightweight and will be using flexconnect groups on a 7510.  The flexconnect groups also have flexconnect ACL's which we are using for redirecting NAC & posture traffic.  We have tried pre-staging the AP mac's into the flexconnect groups using the command "config flexconnect group_name ap add ap_mac".  We then convert the AP to unified mode and it joins the WLC.  That all appears to work fine.  We see the AP on the WLC and in the flexconnect group.  It says Joined in the flexconnect group. 
    The issue we have is that clients cannot connect.  The client status will say 'POSTURE_REQD'.   The only solution we found was to remove the AP from the flexconnect group and then re-add it back.  After that, it works fine.  Anyone have any suggestions or insight?

    we are converting a large number of AP's from autonomous to lightweight and will be using flexconnect groups on a 7510.  The flexconnect groups also have flexconnect ACL's which we are using for redirecting NAC & posture traffic.  We have tried pre-staging the AP mac's into the flexconnect groups using the command "config flexconnect group_name ap add ap_mac".  We then convert the AP to unified mode and it joins the WLC.  That all appears to work fine.  We see the AP on the WLC and in the flexconnect group.  It says Joined in the flexconnect group. 
    The issue we have is that clients cannot connect.  The client status will say 'POSTURE_REQD'.   The only solution we found was to remove the AP from the flexconnect group and then re-add it back.  After that, it works fine.  Anyone have any suggestions or insight?

  • What is the advantages of using Flexconnect groups

    what is the advantages of using Flexconnect groups in WLC?
    Reg,
    Ezra.

    Pls refer this document for more detail about these features
    http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Mobility/emob73dg/emob73/ch7_HREA.html#wp1091114
    FlexConnect is one mode an AP can operate, typically deployed in Branch setup where you do not have a controller at branch site. Those AP can register to a controller at your HQ or main site. So traffic will terminate at your branch switch instead of tunnel back to HQ-WLC.
    If you want roaming within your branch FlexConnect AP then you have to put those AP into a FlexConnect Group. Then only key information shared among those AP to facilitate fast roaming.
    Pls do not forget to rate our responses if you find them useful.
    HTH
    Rasika

  • ISE AuthZ policy based on FlexConnect Group

    Hi all,
    I understand that it is possible to have the WLC send different NAS-ID attributes to the CIsco ISE so that I can create specific AuthZ policies based on that NAS-ID attribute.
    The only thing is that I cannot see anywhere in the FlexConnect AP Group config that allows me to choose the format for the RADIUS request. I can only see it when adding a RADIUS server in Global Configuration.
    So how can I define the attribute that is sent to the ISE?
    Thanks
    Mario

    I don't remember there being a NAS-ID attribute for FlexConnect groups. There is one for AP Group and WLAN.

  • Roaming between Flexconnect groups for scaling

    I have a customer that needs flexconnect at each of his 10 locations to access local servers and printers. The customer has a pair of 5508 WLCs running 7.6.130.0.
    While the customer currently has 25 and under AP count per site, they are considering an expansion to 50 - 60 per site.
    We are considering the mobility agent on 3650/3850/4500 switches, but the multi-hop restriction will drive the cost too high.
    What is the downside for defining multiple flexconnect groups per site?
    The customer is also considering Unified Communications. For example, would the voice RTP stream on a wireless IP phone roaming between APs on different flexconnect groups appear to be seamless?

    If you plan on utilizing any real-time applications such as voice, you would not want these devices to be roaming between FlexConnect Groups.  There will be a full re-authentication of the client; with the exception of OKC capable machines, which "may" roam more cleanly.  This means some standard data clients may perform a fast roam, or at least not notice much of a hiccup even with a full re-auth. 
    In either scenario, you would want to make sure this is NOT a L3 mobility roam (ie. FlexConnect WLAN/VLAN mapping to different networks).  This will cause major problems for all your clients as they will most likely end up talking on the new VLAN with their old IP address.
    Mobility / Roaming Scenarios
    WLAN Configuration
    Local Switching
    Central Switching
    CCKM
    PMK (OKC)
    Others
    CCKM
    PMK (OKC)
    Others
    Mobility Between Same Flex Group
    Fast Roam(1)
    Fast Roam(1)
    Full Auth(1)
    Fast Roam
    Fast Roam
    Full Auth
    Mobility Between Different Flex Group
    Full Auth(1)
    Fast Roam(1)
    Full Auth(1)
    Full Auth
    Fast Roam
    Full Auth
    Inter Controller Mobility
    N/A
    N/A
    N/A
    Full Auth
    Fast Roam
    Full Auth
    (1) Provided WLAN is mapped to the same VLAN (same subnet).

  • FlexConnect Groups

    I have several 2602 AP's that I want to operate in FlexConnect mode.  The WLC is at a central HQ and the Ap's are remote.  There are central radius servers at the HQ for the wlans.  At the remote lcoation, there is a local radius server we want to use for the primary radius server for these AP's.   This radius server has been added to the WLC.  I have setup a FlexConnect Group, designated the the primary and secondary servers, and then added the AP's to the group.  It does not look like radius requests are being sent to the local controller.
    For this to work, do we have to check the box under the wlan for FlexConnect Local Auth?  Currently, we only have FlexConnect local switching selected.

    Sorry I have not got back on this. 
    Can someone please confirm if intermittent high latency from the central location where the WLC is located to the remote site where the Flexconnect AP's are located could cause intermittent issues with client connectivity?  I am noticing that at some of our remote sites that are on a 3MB mpls network, some clients have issues where they cannot access the netowrk.  From the WLC, it appears that the client is authenticated and associated, but they are not getting an IP Address.  I have a debug client when this was happening.  I have attached it below.  Thank you for all of the great input an feedback.
    I did notice that while I was troubleshooting, this location was experiencing higher latency than normal, around 300 to 500ms.
    *apfMsConnTask_5: Apr 15 15:21:19.561: Association request from the P2P Client Process P2P Ie and Upadte CB
    *apfMsConnTask_3: Apr 15 15:21:26.093: 24:77:03:16:ce:48 Association received from mobile on AP 08:cc:68:0a:55:c0
    *apfMsConnTask_3: Apr 15 15:21:26.093: 24:77:03:16:ce:48 Global 200 Clients are allowed to AP radio
    *apfMsConnTask_3: Apr 15 15:21:26.093: 24:77:03:16:ce:48 Max Client Trap Threshold: 0 cur: 5
    *apfMsConnTask_3: Apr 15 15:21:26.093: 24:77:03:16:ce:48 Applying Interface policy on Mobile, role Local. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 177
    *apfMsConnTask_3: Apr 15 15:21:26.093: 24:77:03:16:ce:48 Re-applying interface policy for client
    *apfMsConnTask_3: Apr 15 15:21:26.093: 24:77:03:16:ce:48 172.29.72.15 RUN (20) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:1851)
    *apfMsConnTask_3: Apr 15 15:21:26.093: 24:77:03:16:ce:48 172.29.72.15 RUN (20) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2018)
    *apfMsConnTask_3: Apr 15 15:21:26.093: 24:77:03:16:ce:48 In processSsidIE:3937 setting Central switched to FALSE
    *apfMsConnTask_3: Apr 15 15:21:26.094: 24:77:03:16:ce:48 Applying site-specific Local Bridging override for station 24:77:03:16:ce:48 - vapId 1, site 'WPA-LEAP-Remote-1', interface 'remote_wpa_1'
    *apfMsConnTask_3: Apr 15 15:21:26.094: 24:77:03:16:ce:48 Applying Local Bridging Interface Policy for station 24:77:03:16:ce:48 - vlan 177, interface id 17, interface 'remote_wpa_1'
    *apfMsConnTask_3: Apr 15 15:21:26.094: 24:77:03:16:ce:48 Applying site-specific override for station 24:77:03:16:ce:48 - vapId 1, site 'WPA-LEAP-Remote-1', interface 'remote_wpa_1'
    *apfMsConnTask_3: Apr 15 15:21:26.094: 24:77:03:16:ce:48 Applying Interface policy on Mobile, role Local. Ms NAC State 2 Quarantine Vlan 0 Access Vlan 180
    *apfMsConnTask_3: Apr 15 15:21:26.094: 24:77:03:16:ce:48 Re-applying interface policy for client
    *apfMsConnTask_3: Apr 15 15:21:26.095: 24:77:03:16:ce:48 172.29.72.15 RUN (20) Changing IPv4 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:1851)
    *apfMsConnTask_3: Apr 15 15:21:26.095: 24:77:03:16:ce:48 172.29.72.15 RUN (20) Changing IPv6 ACL 'none' (ACL ID 255) ===> 'none' (ACL ID 255) --- (caller apf_policy.c:2018)
    *apfMsConnTask_3: Apr 15 15:21:26.095: 24:77:03:16:ce:48 processSsidIE statusCode is 0 and status is 0
    *apfMsConnTask_3: Apr 15 15:21:26.095: 24:77:03:16:ce:48 processSsidIE ssid_done_flag is 0 finish_flag is 0
    *apfMsConnTask_3: Apr 15 15:21:26.095: 24:77:03:16:ce:48 STA - rates (8): 130 132 139 150 12 18 24 36 48 72 96 108 0 0 0 0
    *apfMsConnTask_3: Apr 15 15:21:26.095: 24:77:03:16:ce:48 suppRates statusCode is 0 and gotSuppRatesElement is 1
    *apfMsConnTask_3: Apr 15 15:21:26.095: 24:77:03:16:ce:48 STA - rates (12): 130 132 139 150 12 18 24 36 48 72 96 108 0 0 0 0
    *apfMsConnTask_3: Apr 15 15:21:26.095: 24:77:03:16:ce:48 extSuppRates statusCode is 0 and gotExtSuppRatesElement is 1
    *apfMsConnTask_3: Apr 15 15:21:26.095: 24:77:03:16:ce:48 Processing RSN IE type 48, length 22 for mobile 24:77:03:16:ce:48
    *apfMsConnTask_3: Apr 15 15:21:26.095: 24:77:03:16:ce:48 Received RSN IE with 0 PMKIDs from mobile 24:77:03:16:ce:48
    *apfMsConnTask_3: Apr 15 15:21:26.095: 24:77:03:16:ce:48 Found an cache entry for BSSID 70:10:5c:e6:4a:10 in PMKID cache at index 0 of station 24:77:03:16:ce:48
    *apfMsConnTask_3: Apr 15 15:21:26.095: 24:77:03:16:ce:48 Removing BSSID 70:10:5c:e6:4a:10 from PMKID cache of station 24:77:03:16:ce:48
    *apfMsConnTask_3: Apr 15 15:21:26.095: 24:77:03:16:ce:48 Resetting MSCB PMK Cache Entry 0 for station 24:77:03:16:ce:48
    *apfMsConnTask_3: Apr 15 15:21:26.095: 24:77:03:16:ce:48 Setting active key cache index 0 ---> 8
    *apfMsConnTask_3: Apr 15 15:21:26.095: 24:77:03:16:ce:48 unsetting PmkIdValidatedByAp
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 pemApfDeleteMobileStation2: APF_MS_PEM_WAIT_L2_AUTH_COMPLETE = 0.
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 172.29.72.15 RUN (20) Deleted mobile LWAPP rule on AP [70:10:5c:e6:4a:10]
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 Updated location for station old AP 70:10:5c:e6:4a:10-0, new AP 08:cc:68:0a:55:c0-0
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 apfMsRunStateDec
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 apfMs1xStateDec
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 172.29.72.15 RUN (20) Change state to START (0) last state RUN (20)
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 pemApfAddMobileStation2: APF_MS_PEM_WAIT_L2_AUTH_COMPLETE = 0.
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 172.29.72.15 START (0) Initializing policy
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 172.29.72.15 START (0) Change state to AUTHCHECK (2) last state START (0)
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 172.29.72.15 AUTHCHECK (2) Change state to 8021X_REQD (3) last state AUTHCHECK (2)
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 172.29.72.15 8021X_REQD (3) DHCP required on AP 08:cc:68:0a:55:c0 vapId 1 apVapId 1for this client
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 Not Using WMM Compliance code qosCap 00
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 172.29.72.15 8021X_REQD (3) Plumbed mobile LWAPP rule on AP 08:cc:68:0a:55:c0 vapId 1 apVapId 1 flex-acl-name:
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 apfPemAddUser2 (apf_policy.c:273) Changing state for mobile 24:77:03:16:ce:48 on AP 08:cc:68:0a:55:c0 from Associated to Associated
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 Stopping deletion of Mobile Station: (callerId: 48)
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 Func: apfPemAddUser2, Ms Timeout = 0, Session Timeout = 0
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 Sending Assoc Response to station on BSSID 08:cc:68:0a:55:c0 (status 0) ApVapId 1 Slot 0
    *apfMsConnTask_3: Apr 15 15:21:26.096: 24:77:03:16:ce:48 apfProcessAssocReq (apf_80211.c:6719) Changing state for mobile 24:77:03:16:ce:48 on AP 08:cc:68:0a:55:c0 from Associated to Associated
    *apfMsConnTask_3: Apr 15 15:21:26.145: 24:77:03:16:ce:48 Updating AID for REAP AP Client 08:cc:68:0a:55:c0 - AID ===> 3
    *dot1xMsgTask: Apr 15 15:21:26.146: 24:77:03:16:ce:48 Disable re-auth, use PMK lifetime.
    *dot1xMsgTask: Apr 15 15:21:26.146: 24:77:03:16:ce:48 dot1x - moving mobile 24:77:03:16:ce:48 into Connecting state
    *dot1xMsgTask: Apr 15 15:21:26.146: 24:77:03:16:ce:48 Sending EAP-Request/Identity to mobile 24:77:03:16:ce:48 (EAP Id 1)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.260: 24:77:03:16:ce:48 Received EAPOL EAPPKT from mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.260: 24:77:03:16:ce:48 Received Identity Response (count=1) from mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.260: 24:77:03:16:ce:48 EAP State update from Connecting to Authenticating for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.260: 24:77:03:16:ce:48 dot1x - moving mobile 24:77:03:16:ce:48 into Authenticating state
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.260: 24:77:03:16:ce:48 Entering Backend Auth Response state for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.265: 24:77:03:16:ce:48 Processing Access-Challenge for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.265: 24:77:03:16:ce:48 Entering Backend Auth Req state (id=2) for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.265: 24:77:03:16:ce:48 Sending EAP Request from AAA to mobile 24:77:03:16:ce:48 (EAP Id 2)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.404: 24:77:03:16:ce:48 Received EAPOL EAPPKT from mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.404: 24:77:03:16:ce:48 Received EAP Response from mobile 24:77:03:16:ce:48 (EAP Id 2, EAP Type 13)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.404: 24:77:03:16:ce:48 Entering Backend Auth Response state for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.405: 24:77:03:16:ce:48 Processing Access-Challenge for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.405: 24:77:03:16:ce:48 Entering Backend Auth Req state (id=3) for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.405: 24:77:03:16:ce:48 Sending EAP Request from AAA to mobile 24:77:03:16:ce:48 (EAP Id 3)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.464: 24:77:03:16:ce:48 Received EAPOL EAPPKT from mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.464: 24:77:03:16:ce:48 Received EAP Response from mobile 24:77:03:16:ce:48 (EAP Id 3, EAP Type 13)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.464: 24:77:03:16:ce:48 Entering Backend Auth Response state for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.465: 24:77:03:16:ce:48 Processing Access-Challenge for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.465: 24:77:03:16:ce:48 Entering Backend Auth Req state (id=4) for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.465: 24:77:03:16:ce:48 Sending EAP Request from AAA to mobile 24:77:03:16:ce:48 (EAP Id 4)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.532: 24:77:03:16:ce:48 Received EAPOL EAPPKT from mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.532: 24:77:03:16:ce:48 Received EAP Response from mobile 24:77:03:16:ce:48 (EAP Id 4, EAP Type 13)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.532: 24:77:03:16:ce:48 Entering Backend Auth Response state for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.533: 24:77:03:16:ce:48 Processing Access-Challenge for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.533: 24:77:03:16:ce:48 Entering Backend Auth Req state (id=5) for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.533: 24:77:03:16:ce:48 Sending EAP Request from AAA to mobile 24:77:03:16:ce:48 (EAP Id 5)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.590: 24:77:03:16:ce:48 Received EAPOL EAPPKT from mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.590: 24:77:03:16:ce:48 Received EAP Response from mobile 24:77:03:16:ce:48 (EAP Id 5, EAP Type 13)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.590: 24:77:03:16:ce:48 Entering Backend Auth Response state for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.591: 24:77:03:16:ce:48 Processing Access-Challenge for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.592: 24:77:03:16:ce:48 Entering Backend Auth Req state (id=6) for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.592: 24:77:03:16:ce:48 Sending EAP Request from AAA to mobile 24:77:03:16:ce:48 (EAP Id 6)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.687: 24:77:03:16:ce:48 Received EAPOL EAPPKT from mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.687: 24:77:03:16:ce:48 Received EAP Response from mobile 24:77:03:16:ce:48 (EAP Id 6, EAP Type 13)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.687: 24:77:03:16:ce:48 Entering Backend Auth Response state for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.689: 24:77:03:16:ce:48 Processing Access-Challenge for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.689: 24:77:03:16:ce:48 Entering Backend Auth Req state (id=7) for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.689: 24:77:03:16:ce:48 Sending EAP Request from AAA to mobile 24:77:03:16:ce:48 (EAP Id 7)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.737: 24:77:03:16:ce:48 Received EAPOL EAPPKT from mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.737: 24:77:03:16:ce:48 Received EAP Response from mobile 24:77:03:16:ce:48 (EAP Id 7, EAP Type 13)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.737: 24:77:03:16:ce:48 Entering Backend Auth Response state for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.738: 24:77:03:16:ce:48 Processing Access-Challenge for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.738: 24:77:03:16:ce:48 Entering Backend Auth Req state (id=8) for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.739: 24:77:03:16:ce:48 Sending EAP Request from AAA to mobile 24:77:03:16:ce:48 (EAP Id 8)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.802: 24:77:03:16:ce:48 Received EAPOL EAPPKT from mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.802: 24:77:03:16:ce:48 Received EAP Response from mobile 24:77:03:16:ce:48 (EAP Id 8, EAP Type 13)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.802: 24:77:03:16:ce:48 Entering Backend Auth Response state for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.813: 24:77:03:16:ce:48 Processing Access-Challenge for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.813: 24:77:03:16:ce:48 Entering Backend Auth Req state (id=9) for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.813: 24:77:03:16:ce:48 Sending EAP Request from AAA to mobile 24:77:03:16:ce:48 (EAP Id 9)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.876: 24:77:03:16:ce:48 Received EAPOL EAPPKT from mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.876: 24:77:03:16:ce:48 Received EAP Response from mobile 24:77:03:16:ce:48 (EAP Id 9, EAP Type 13)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.876: 24:77:03:16:ce:48 Entering Backend Auth Response state for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.877: 24:77:03:16:ce:48 Processing Access-Accept for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.877: 24:77:03:16:ce:48 Resetting web IPv4 acl from 255 to 255
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.877: 24:77:03:16:ce:48 Resetting web IPv4 Flex acl from 65535 to 65535
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.877: 24:77:03:16:ce:48 Setting re-auth timeout to 1800 seconds, got from WLAN config.
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.877: 24:77:03:16:ce:48 Station 24:77:03:16:ce:48 setting dot1x reauth timeout = 1800
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.877: 24:77:03:16:ce:48 Creating a PKC PMKID Cache entry for station 24:77:03:16:ce:48 (RSN 2)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.878: 24:77:03:16:ce:48 Resetting MSCB PMK Cache Entry 0 for station 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.878: 24:77:03:16:ce:48 Setting active key cache index 8 ---> 8
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.878: 24:77:03:16:ce:48 Setting active key cache index 8 ---> 0
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.878: 24:77:03:16:ce:48 Adding BSSID 08:cc:68:0a:55:c0 to PMKID cache at index 0 for station 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.878: New PMKID: (16)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.878: [0000] 00 b9 ff 20 8f eb 43 b2 6f 20 50 a1 29 99 85 a3
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.878: 24:77:03:16:ce:48 Disabling re-auth since PMK lifetime can take care of same.
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.878: 24:77:03:16:ce:48 unsetting PmkIdValidatedByAp
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.878: 24:77:03:16:ce:48 PMK sent to mobility group
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.878: 24:77:03:16:ce:48 Sending EAP-Success to mobile 24:77:03:16:ce:48 (EAP Id 9)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.878: 24:77:03:16:ce:48 Found an cache entry for BSSID 08:cc:68:0a:55:c0 in PMKID cache at index 0 of station 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.878: 24:77:03:16:ce:48 Found an cache entry for BSSID 08:cc:68:0a:55:c0 in PMKID cache at index 0 of station 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.878: Including PMKID in M1 (16)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.878: [0000] 00 b9 ff 20 8f eb 43 b2 6f 20 50 a1 29 99 85 a3
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.878: 24:77:03:16:ce:48 Starting key exchange to mobile 24:77:03:16:ce:48, data packets will be dropped
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.878: 24:77:03:16:ce:48 Sending EAPOL-Key Message to mobile 24:77:03:16:ce:48
    state INITPMK (message 1), replay counter 00.00.00.00.00.00.00.00
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.878: 24:77:03:16:ce:48 Entering Backend Auth Success state (id=9) for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.879: 24:77:03:16:ce:48 Received Auth Success while in Authenticating state for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.879: 24:77:03:16:ce:48 dot1x - moving mobile 24:77:03:16:ce:48 into Authenticated state
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.937: 24:77:03:16:ce:48 Received EAPOL-Key from mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.937: 24:77:03:16:ce:48 Ignoring invalid EAPOL version (1) in EAPOL-key message from mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.937: 24:77:03:16:ce:48 Received EAPOL-key in PTK_START state (message 2) from mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.937: 24:77:03:16:ce:48 PMK: Sending cache add
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.937: 24:77:03:16:ce:48 Stopping retransmission timer for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.937: 24:77:03:16:ce:48 Sending EAPOL-Key Message to mobile 24:77:03:16:ce:48
    state PTKINITNEGOTIATING (message 3), replay counter 00.00.00.00.00.00.00.01
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.987: 24:77:03:16:ce:48 Received EAPOL-Key from mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.987: 24:77:03:16:ce:48 Ignoring invalid EAPOL version (1) in EAPOL-key message from mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.987: 24:77:03:16:ce:48 Received EAPOL-key in PTKINITNEGOTIATING state (message 4) from mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.987: 24:77:03:16:ce:48 Stopping retransmission timer for mobile 24:77:03:16:ce:48
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.987: 24:77:03:16:ce:48 apfMs1xStateInc
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.987: 24:77:03:16:ce:48 172.29.72.15 8021X_REQD (3) Change state to L2AUTHCOMPLETE (4) last state 8021X_REQD (3)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.987: 24:77:03:16:ce:48 172.29.72.15 L2AUTHCOMPLETE (4) DHCP required on AP 08:cc:68:0a:55:c0 vapId 1 apVapId 1for this client
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.987: 24:77:03:16:ce:48 Not Using WMM Compliance code qosCap 00
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.987: 24:77:03:16:ce:48 172.29.72.15 L2AUTHCOMPLETE (4) Plumbed mobile LWAPP rule on AP 08:cc:68:0a:55:c0 vapId 1 apVapId 1 flex-acl-name:
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.987: 24:77:03:16:ce:48 apfMsRunStateInc
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.987: 24:77:03:16:ce:48 172.29.72.15 L2AUTHCOMPLETE (4) Change state to RUN (20) last state L2AUTHCOMPLETE (4)
    *Dot1x_NW_MsgTask_0: Apr 15 15:21:26.989: 24:77:03:16:ce:48 172.29.72.15 RUN (20) Reached PLUMBFASTPATH: from line 5982
    *apfMsConnTask_1: Apr 15 15:21:30.000: Association request from the P2P Client Process P2P Ie and Upadte CB
    *apfMsConnTask_7: Apr 15 15:22:28.508: Association request from the P2P Client Process P2P Ie and Upadte CB
    *apfMsConnTask_0: Apr 15 15:22:52.690: Association request from the P2P Client Process P2P Ie and Upadte CB
    *apfMsConnTask_5: Apr 15 15:23:00.276: Association request from the P2P Client Process P2P Ie and Upadte CB

  • Wireless FlexConnect Group

    Hi folks,
    due wifi 802.1x implementation our customer decided to implement CCKM for fast roaming of cisco 7925 wifi phones.
    At the same time customer have an Headquarter, and about 300 remote sites all of them implement FlexConnet tecnology with local switching.
    For every sites he got a 5508 WLC with ver 7.4, and a 5508 in Headquarter as well acting as a backup WLC for remote sites.
    Using FlexConnect and CCKM for remote sites requires FlexConnect Grouping.
    From Release Notes
    http://www.cisco.com/c/en/us/td/docs/wireless/controller/7-2/configuration/guide/cg/cg_flexconnect.html#wp1241304
    I've noted there is some limit for this configuration that I'd like to be confirmed:
    1) 25 APs for FlexConnect group -> true for 5508 WLC?
    2) 100 FC Group for 5508 -> is still true in ver 7.4 or higher?
    Third question:
    I'd like to implement PMK/OKC instead CCKM. How can I do it? I'm missing configuration in GUI menus.
    Last question: How can I resolve the FlexConnect Group Limit in my Headquarter due the fact I got more than 100 Groups to create? Is really necessary to add new 5508? No other way?
    Thanks a lot

    Hi
    Typically FlexConnect design is for a branch wireless where you DO NOT have a local WLC to terminate CAPWAP.
    If you have a WLC at branch & still you deploy FlexConnect at that branch then it is a waste of WLC resource.
    Here is my feedback for your points
    1) allowing WAN QoS for Voice/Data wifi client. Local switching allows voice packet to follow same routing and QoS of wired IP Phone. Analogue reason for PC data traffic. And is more useful when in backup/centralized auth mode. Encapsulate all traffic in CAPWAP tunnel doesn't allow us QoS implementation.
    I understand Wireless QoS is tricky to implement & you will never get same policy for wired/wireless  (that's where Unified Access or Converged Access design come onto play-by the way I am not telling you have to go for CA ) You need to assess pros & cons of going for FlexConnect design & I am not sure this QoS is purely justifying go for it.
    2) now 5508 are present for 80 sites but could growing. All remaining sites are managed by old 2106 WLC. For this purpose in next plan maybe we'll decide for a Centralized WLC. No plan at this moment.
    My view is
    All sites you have WLC - Deploy local mode AP with primary WLC as branch & back  up as HQ WLC.
    All sites you do not have a WLC - Deploy FlexConnect local switching mode with Central Auth where HQ WLC used.
    3) so, what's the limit for FC Group in 5508 WLC?
    100 (refer the given Ciscolive presentation)
    4) OKC allows PKI AP cache as well CCKM. But OKC release fast roaming between different Flexconnect Groups while CCKM not. For sites with more than 30 APs should be very usuful, expecially considering 7925 phones.
    When it comes to fast roaming CCKM is the best if it is CCX clients, otherwise 802.11r which is IEEE standard & supported by multivendor  clients. OKC is  a way vendors implemented prior to 802.11r ratified  as a way of fast roaming. So you should not look at OKC  over 802.11r or CCKM(if it is for cisco clients)
    I think since you are lock-down to this FlexConnect design, you try to overcome the limitations of that design, rather look at high level to see "flexconnect is the best way to go or not" . In my view if it is fastroaming 802.11r is the way forward (CCKM is must if you are 100% cisco clients)
    Refer this Ciscolive material for FlexConnect design
    BRKEWN-2016 Architecting Network for Branch with Cisco Unified Wireless
    Do not forget to rate our responses if that is useful.
    HTH
    Rasika

  • List accesspoints flexconnect groups from a WLC

    Hi!
    Is it possible for all accesspoints that is configured as lightweight from a WLC to LIST all accesspoints that is not assigned to a flexconnect group? I would actually love to know if its possble both from the GUI Prime / WLC and the CLI.
    I've tried to figure this one out myself, however I'm stuck. Its not hard to setup groups etc, its just the list AP that isn't assigned to a flexconnect group that I find troublesome.
    Anyone? :)

    Configuring FlexConnect Groups (GUI)
    Step 1 Choose Wireless > FlexConnect Groups to open the FlexConnect Groups page.
    Figure 15-6 FlexConnect Groups Page
    This page lists any FlexConnect groups that have already been created.
    Note If you want to delete an existing group, hover your cursor over the blue drop-down arrow for that group and choose Remove.
    http://www.cisco.com/c/en/us/td/docs/wireless/controller/7-2/configuration/guide/cg/cg_flexconnect.html#wp1226724

  • Flexconnect Group Name - SNMP OID/MIB

    Hi,
    Does anyone happen to know if an SNMP MIB/OID exists for the Flexconnect configuration on a WLC?  Specifically I'm looking to return the name of the Flexconnect Group that a particular AP is a member of.  I've accomplished this for the AP group, but I can't find a way to return the Flexconnect Group name.
    Appreciate any pointers,
    Thanks
    Peter Moorey.

    Hi,
    Thank you for taking the time to reply.  I found that OID during my research, for some reason it's 'Not Accessible' according to the Cisco documentation.  I don't know why that is the case, but when I issue an SNMP walk it doesn't work, backing up the statement Cisco published online.
    http://tools.cisco.com/Support/SNMP/do/BrowseOID.do?local=en&translate=Translate&objectInput=1.3.6.1.4.1.9.9.517.1.3.1.1.1#oidContent 
    Pete.

  • How do I change the number in a Top N Group Sort

    I have a report that I have grouped on a particular field (Cust.Name specifically). I then used the group sort expert and selected the Top N selection in the combo box under the Cust.Name tab. I put in a default number of 20. What I want to do is to set this number for the Top N group sort via .NET. Does anyone know the correct method for doing this in either VB.NET or C#.NET. I am using VS 2005 Pro and the embedded Crystal Reports engine for VS.NET. Thank you.
    Ed Cohen

    Hello, Edgar;
    In the bundled version of Crystal Reports 10.2 in Visual Studio .NET 2005 you will need to use the following code:
    Private Sub Set_TopN()
            Dim TopNSortField As TopBottomNSortField
            'Get the Sort field by index
            'Cast it as a TopBottomNSortField
            If TypeOf crReportDocument.DataDefinition.SortFields.Item(0) Is TopBottomNSortField Then
                TopNSortField = crReportDocument.DataDefinition.SortFields.Item(0)
                TopNSortField.NumberOfTopOrBottomNGroups = 10
            Else
                TopNSortField = Nothing
            End If
        End Sub
    In a full version of Crystal Reports there is an option to create a parameter as a number such as {?TopN} and then pass the value to it at runtime.
    In the Crystal Reports designer you need to create the parameter and then go to Report|Group Sort Expert.
    Choose TopN based on your field.
    Where N is... You will need a number there. I used 1. But then I clicked on the Formula editor [X+2] and added the parameter field {?TopN}.
    Passing the parameter at runtime ran the number I requested.
    Elaine
    Edited by: Elaine Dove on Mar 3, 2009 12:12 PM

  • How can I get a number of items from a group

    I'm trying to load assets into a library. Most of the assets are groups. I'd like to label each asset with number of items from that specific group.
    Here is my code:
    var d=app.activeDocument;
    //create empty library
    var library = app.libraries.add(File('mylibrary.indl'));
    for(myCounter = 0; myCounter < d.pages.length; myCounter ++){
        if(d.pages[myCounter].groups.length > 0){
             //how do I get number of items from a group?
             var item_count = ?????
        }else{
             var item_count = '1';
        library.store(d.pages[myCounter].allPageItems);
        library.assets[0].name=item_count;
    Thanks for your help and Happy New Year!!!

    I figured it out!!!
    Here is the solve that worked for me:
    var elems = d.pages[myCounter].groups[0].pageItems.everyItem().getElements();
    var item_count = elems.length;

  • Can I know the name, type, total number of column in Record Group?

    I created a record group with query dynamically.
    And then populated it.
    I don't know the column' count, type, name befause I get the query from user at runtime.
    Can I know the name, type, total number of column in Record Group?

    Unfortunately, there is no way to query the record group (RG) to get the metadata you are looking for. RGs are best used as data sources to an LOV or List Item rather than as an Array to hold the resultset of a dynamic query. For this, I would recommend you use a Collection type of construct (PL/SQL Table of Records, VArray, etc).
    Craig...

  • Using Mountain Lion (OS 10.8), in Contacts, how can I show a count of number of contacts total and/or number of contacts in a group?

    Using Mountain Lion (OS 10.8), in Contacts, how can I show a count of number of contacts total and/or number of contacts in a group?

    If you scroll the list to the bottom, there might be a count. I haven't figured out why you sometimes get a count and other times you don't.

  • Setting a sequential number to records placed into groups?

    Hello I have one table with records which can be grouped and I want to know if I can set an ordinal number to each record and when the group breaks set 1 again to the first record of the group and then 2 to next...3 to next....until group breaks again.....
    the first thing I need is order the records according the group then number each record inside the group sequentially from 1 to ..n (numbers or records of the group).
    Can I do this???
    Thanks in advance

    Hello
    you can use the row_number analytic function
    WITH gp AS
    (   SELECT 1 id, 1 family_id,to_date('29/06/1966','dd/mm/yyyy') dob from dual union all
        SELECT 2 id, 1 family_id,to_date('22/06/1986','dd/mm/yyyy') dob from dual union all
        SELECT 3 id, 2 family_id,to_date('04/03/1975','dd/mm/yyyy') dob from dual union all
        SELECT 4 id, 3 family_id,to_date('01/04/1990','dd/mm/yyyy') dob from dual union all
        SELECT 5 id, 3 family_id,to_date('10/01/1996','dd/mm/yyyy') dob from dual union all
        SELECT 6 id, 3 family_id,to_date('21/09/2000','dd/mm/yyyy') dob from dual
    SELECT
        id,
        family_id,
        dob,
        ROW_NUMBER() OVER(PARTITION BY family_id ORDER BY DOB) rn,
        ROW_NUMBER() OVER(PARTITION BY family_id ORDER BY DOB DESC) rn_desc
    FROM
        gp
            ID  FAMILY_ID DOB                          RN    RN_DESC
             1          1 29-JUN-1966 00:00:00          1          2
             2          1 22-JUN-1986 00:00:00          2          1
             3          2 04-MAR-1975 00:00:00          1          1
             4          3 01-APR-1990 00:00:00          1          3
             5          3 10-JAN-1996 00:00:00          2          2
             6          3 21-SEP-2000 00:00:00          3          1
    6 rows selected.which gives you the ability to generate the numbers as you have requested. The important parts are the PARTITION which is the group of rows over which the function will be applied, and the ORDER BY which will determine the order in which the function is applied to those rows. You can see that I called the function twice, once with ORDER BY DOB and the other with ORDER BY DOB DESC and the difference in the output.
    HTH
    David

  • Is there a way of combining a large number of materials into a grouping cod

    Greetings,
    Is there a way of combining a large number of materials into a grouping code, so that and end-user can manage this grouping... adding and removing materials... for auctions?
    The materials will likely span material groups in R/3, and there could be thousands of materials. Shopping cart templates would be cumbersome.
    I was thinking about a special catalog characteristic with defined names to manage the various groups of materials.
    I appreciate any advice... also in awarding points.
    Jessica

    Hi Jessica
    This is my understanding:
    - You want to 'Specially group' materials other than material group. Each special group, may consists of materials from many material groups.
    - User(s) pick materials from this group during 'Auction' creation or 'shopping cart' creation.
    Am I right ?
    Looks like using 'Catalog' is the option.
    - MDM Catalog 'mask' or other Catalogs views to have user specific catalog view
    - Maintenance of this catalog by user could become a problem. Then, you need to give content mgmt rights to user
    Best regards
    Ramki

Maybe you are looking for

  • Is there a way to delete ALL of my music off of my iTunes/computer EXCEPT for the music that's on my iPod touch?

    I have old music that I have deleted from my iPod that I no longer wish to have on there, but it reappeared in my iTunes. All of the music on my iPod I want to keep, and one other CD I've gotten since then. Is there any way to delete everything (for

  • Could not initialize Photoshop because the file is empty.

    I tried to start Photoshop 5.1 64bit today, and it shows the blue intro screen with the reading and loading, and then it goes to a popup error message that reads, "Could not initialize Photoshop because the file is empty." I can run the 32bit version

  • Need help on how forms developer is used

    to everyone: im actually new at forms developer 2000,at really wondering how to use it though i have a background in SQL.If you have any data that you can share to me explaining the whole environment of Developer 200 please send it to me. Any help is

  • Flash Player Has Stopped Working!

    All of a sudden, flash player has stopped working on my computer. I have a 64-bit PC, running Windows 7. Flash was running perfectly one day; the next it was not. Hasn't worked since. I've tried downloading the latest version and even installing an o

  • How do I rotate a video in osmf?

    I have a video file that I am playing with osmf. I want to rotate it by 90 degrees. How? It's using StageVideo, if that matters. I have tried setting the rotation property on MediaPlayer/MediaPlayerSprite/MediaElement but that doesn't work.