Guest access to the Internet with Guest Anchor Controller

Hi;
We are doing our initial implementation of an enterprise wireless system.  I deployed a WLC 5508 connected to our data center core switch using LAG.  The 5508 is configured in FlexConnect mode since it is serving APs deployed to a handful of remote offices.  Employee wireless access has been rolled out and is working well.
I am designing guest access.  As is typical, I want to enforce a policy that guest wireless traffic is forwarded to the Internet Edge in our DMZ and directed out to the Internet.  We do not plan to deploy a Guest Anchor controller in the first phase of the roll out.
What is the best way to enforce forwarding of guest traffic towards the Internet Edge once the guest traffic arrives at the 5508?  A guest VLAN between the core switch and the Internet Edge isn't feasible since there is a firewall between the core and DMZ that is configured in Routed mode.
Thanks for the assistance!  Glenn Morrison

you'd have to do a VLAN between the core and the firewall for the guest traffic until you get the anchor installed.
HTH,
Steve

Similar Messages

  • I'm not able to access to the internet with my ipod ..help! Non riesco a connettermi su internet via wi-fi !

    Salve, ho appena comprato il mio ipod di 8G..  connettendomi wi-fi al router di casa mia, aprendo safari (o le altre applicazioni che richiedono la connessione internet) spunta la finestra con scritto "Impossibile aprire pagine, Safari non può aprire la pagina perché non è connesso a Internet" Ho provato e riprovato, ma niente! Spero possiate aiutarmi, grazie! :)
    Hello, I've just bought my ipod (8Gb)... even with the wi-fi I'm not able to access to the internet, opening any app that needs internet my ipod shows this " Cannot open page, Safari cannot open the page because it is not connected to the internet"  I tried and I tried but it was useless..! I hope You can help me! Thank you and sorry if my english isn't right

    I can connect to the site using another computer on my network. It's completely isolated to my iMac.

  • IPhone 4s with ios 6 shows full wifi signal but can't access to the internet while other idevice can

    Hi everyone,
    I updated my iphone 4s to ios 6 a few months ago and there was no problem until I change my sim card to other carriers last two days.  This second sim card is the same sim card that I used it earlier this year with no problem.  But the problem I face is when my iphone goes to sleep mode I realised that I can't receive any push notification from imessage, Whatsapp, and Line.  When the phone is awake the wifi signal is back and I have to go to each application in order to get the message.  I have tried the following methods but it didn't work: reset all network settings, restore as new iphone, push home and power button together, switch off my iphone, turn on airplane mode, and even change my router.  At the moment I have restored my iphone as new for the 5th times.
    Now the problem is worsen, after the phone is sleep for about 5 minutes and when I awake my iphone it shows the wifi signal.  But I can't access to the internet at all.  It shows no working internet on Whatsapp. Safari can't load any web page, the weather app can't update temperature etc.  I have to switch off and switch on wifi in setting menu so that I can use the internet. And when I leave my iphone four about 5 - 10 minuetes then the problem start again. While I can't access to the internet on my iphone 4s, I used my dad's iphone 4s with ios 5.0.1 and it works just fine with the internet. My laptop can also access to the internet with the same wifi network but not my iphone.
    Does anybody know what's going on with my iphone 4s? Is it the bug from IOS 6 or my iphone is broken? Please help me.
    Thank you.

    Any update will cause problems for a few users. And those users will rush here and post "the sky is falling" stories about their experience. The 99.99% of people who have no problems after an update won't bother to post here; indeed, most of them don't even know ASC exists. FWIW, I had no problems with iOS 7 on my 4S. Your problem is most likely not related to iOS 6, but you should probably update anyway. For addressing the battery issue see this outstanding article: http://www.overthought.org/blog/2014/the-ultimate-guide-to-solving-ios-battery-d rain

  • How do I connect to the internet with Airport Expess?

    In Airport Utility I get an orange icon and the Airport Express light is green. In the internet box
    coming from the globe picture it says Interent connection Disconnected and there is no router address
    and no DNS server information shown.

    As a minimum, in order to gain access to the Internet with an AirPort Express base station, you will need an Internet Service Provider (ISP) AND an Internet modem or gateway device.
    What is the make & model of the Internet modem or gateway device that you have the AirPort Express directly connected to by Ethernet? What exact model of Express do you have?

  • How do I connect to the internet with Airport for the first time?

    I just got my Airport express and I've been trying to configure it to connect to the internet but it doesn't work and I can't find info on the configurations. I have an ethernet "modem" which I used to connect the cable coming from it to the computer and now I connect it to my Airport. Although the green light is on and in network preferences, it tells me I'm connected to the internet, I can't browse the internet with Safari, etc. I've been trying to find information on how to configure the base station in Airport Admin Utility but there is no specific information. Is there anyone who could help me telling me how to set up the IP adress, if I need one, DHCP, preferences in Airport Admin Utility?? If the ethernet cable is connected to the computer directly I don't need a user ID or anything... It's all setup automatically.

    As a minimum, in order to gain access to the Internet with an AirPort Express base station, you will need an Internet Service Provider (ISP) AND an Internet modem or gateway device.
    What is the make & model of the Internet modem or gateway device that you have the AirPort Express directly connected to by Ethernet? What exact model of Express do you have?

  • Wired guest access on WLC 4400 with SW 7.0.240.0

    Hello,
    after we upgrade our Wlan-controller 4400 from software 7.0.116.0 to 7.0.240.0
    wired guest access don't work anymore.
    All other things works fine, incl. WLAN guest access!
    When we try wired guest access, we get the web-authentication page and can log in.
    On the controller we can see that the Policy Manager State changes from WEBAUTH_REQD
    to RUN.
    But then there is no access to the internet.
    We tried also SW 7.0.250.0, same problem!
    Log Analysis on the WCS:
    Time :03/12/2014 14:21:23 MEZ Severity :INFO Controller IP :10.101.200.11 Message :The WLAN to which client is connecting does not require 802 1x authentication.
    Time :03/12/2014 14:21:23 MEZ Severity :INFO Controller IP :10.101.200.11 Message :Client does not have an IP address yet.
    Time :03/12/2014 14:21:23 MEZ Severity :INFO Controller IP :10.101.200.11 Message :Client L3 authentication is required
    Time :03/12/2014 14:21:23 MEZ Severity :INFO Controller IP :10.101.200.11 Message :Client Moved to DHCP Required State.
    Time :03/12/2014 14:21:26 MEZ Severity :INFO Controller IP :10.101.200.11 Message :Mobility role update request. from Unassociated to Local Peer = 0.0.0.0, Old Anchor = 0.0.0.0, New Anchor = 10.101.200.11
    Time :03/12/2014 14:21:26 MEZ Severity :INFO Controller IP :10.101.200.11 Message :Mobility role changed. State Update from Mobility-Incomplete to Mobility-Complete, mobility role=Local, client state=APF_MS_STATE_ASSOCIATED
    Time :03/12/2014 14:21:26 MEZ Severity :INFO Controller IP :10.101.200.11 Message :DHCP successful.
    Time :03/12/2014 14:21:26 MEZ Severity :ERROR Controller IP :10.101.200.11 Message :Client got an IP address successfully and the WLAN requires Web Auth or Web Auth pass through.
    Time :03/12/2014 14:21:26 MEZ Severity :INFO Controller IP :10.101.200.11 Message :Client IP address is assigned.
    Time :03/12/2014 14:22:01 MEZ Severity :INFO Controller IP :10.101.200.11 Message :Webauth user logged in to the network. manni
    Time :03/12/2014 14:22:01 MEZ Severity :INFO Controller IP :10.101.200.11 Message :AAA response message sent.
    Time :03/12/2014 14:22:01 MEZ Severity :INFO Controller IP :10.101.200.11 Message :Client has completed Web Auth successfully.
    Time :03/12/2014 14:22:01 MEZ Severity :INFO Controller IP :10.101.200.11 Message :Client has completed Web Auth successfully.
    Trying http://www.google.de .... doesnt work. No Log Entries. Next entries while logging out.
    Time :03/12/2014 14:36:20 MEZ Severity :INFO Controller IP :10.101.200.11 Message :Web auth is being triggered again.
    Time :03/12/2014 14:36:20 MEZ Severity :INFO Controller IP :10.101.200.11 Message :Client L2 authentication has been completed successfully.
    Time :03/12/2014 14:36:20 MEZ Severity :INFO Controller IP :10.101.200.11 Message :Client Moved to DHCP Required State.
    Time :03/12/2014 14:36:20 MEZ Severity :INFO Controller IP :10.101.200.11 Message :WebAuth user Logged out from network.
    Has someone a idea how to solve this problem?
    Regards
    Manfred

    Hi
    Yes got it resolved. It turns out that the connection from the wired guest access port to the WLC must be L2. That is the switch that the wired guest acces sport is connected and WLC are connected to must be L2 only. We were using a single switch to do the testing and it was also doing the routing for the test LAN. Even though there was no L3 VLAN interface configured for the VLAN that the guest access port was on for some reason this breaks it. Absolu Didnt have chance to work out the exact limitations of this as we simply made the switch L2 only and configured an 802.1Q trunk to the Internet router and made subinterfaces on the router for the wired and wireless egress ports and it worked then. No config change was needed on the WLC at all.
    The only thing I can think of is that it's something about the way the WLC joins the wired guest access ingress VLAn and egress VLAN. The WLC isn't a reall router it says so in the documentation. I think the packet coming from the wired access port is being bridged to the egress VLAn not routed and this is what screws it up (remeber with a router the source and destination MAC addresses would be changed with a bridge they aren't). Got to be something along those lines. If you have a bigger newtork with a guest anchor WLC handling this function you dont run into this as the traffic is coming over an EOIP tunnle from the remote WLC so the switch with the guest anchor WLC doesnt see the MAC address of the wired guest PC.

  • Allowing Airwatch MDM access to the Captive-Portal guest users in pre-auth role for android and BB?

    Requirement:
    How to allow Airwatch MDM access to the Captive-Portal guest users in pre-authentication role for Android and Blackberry devices?
    What is Airwatch MDM?
    Airwatch MDM is Mobile Device Management. The Airwatch is an enterprise which helps to manage and secure data traveling through the mobile devices like Laptops, Tablets, Android, iPhones, iPads etc.
    Solution:
    Why we need to allow access to Airwatch MDM?
    The network administrator can force the guest users to register to Airwatch MDM before they get authenticated and access the internet. So that the network administrator could manage the guest devices through Airwatch Management tool. This can be achieved by CPPM server. To download the Airwatch MDM app and register with the Airwatch MDM server certain domains should be permitted in the captive portal pre-authentication role. This KB provides the configuration steps to allow the guest users to download the Airwatch MDM app and register with the Airwatch MDM server.
    Configuration:
    Below is the configuration
    Configuration steps:
    1. Create the following netdestinations
    netdestination Airwatch
      name *.awagent.com
      name *.awmdm.com
      name air-watch.com
    netdestination Google-Play
      name android.clients.google.com
      name .ggpht.com
      name gstatic.com
      name accounts.google.com
      name clients1.google.com
      name clients2.google.com
      name clients3.google.com
      name clients4.google.com
      name i.ytimg.com
      name google-analytics.com
      name .1e100.net
      name android.l.google.com
      name mtalk.google.com
      name clients.l.google.com
      name googleapis.com
      name gvt1.com
    netdestination BlackBerry
      name *.blackberry.com
    2. Now define the rules in the session acl and map it to the pre-authentication Role of the captive portal.
    ip access-list session Airwatch_Access
      any   alias Airwatch svc-http  permit
      any   alias Airwatch svc-https  permit
    ip access-list session Google-Play-Store
                   any   alias Google-Play any permit
    ip access-list session BlackBerry-Access
                   any   alias BlackBerry any permit
    3. Now map the session ACLs to captive-portal pre-authentication Role as follows
    user-role Guest-Pre-Auth-Role
     access-list session Airwatch_Access
     access-list session Google-Play-Store
     access-list session BlackBerry-Access
     access-list session logon-control
     access-list session captiveportal
    4. Now whitelist the list of domain names in the Captive Portal profle
    aaa authentication captive-portal Airwatch-Captive-Portal-Profile
    white-list Airwatch
    white-list Google-Play                                                                                ------------>Netdestinations where you defined the Domains.
    white-list BlackBerry
    Verification
    Now the user will be placed under the "Guest-Pre-Auth-Role" before the authentication. The user can now go the Google Play-Store or BlackBerry Appworld to download the Airwatch MDM and register to Airwatch Management Server.

    Thanks so much getting these names listed out. I have been working on this very issue for a few weeks and was basing my firewall rules on IP's. It was not going well. Now access is working and testing can commence!  Thanks,Chris

  • How do I Set up a LAN with no access to the Internet?

    I have a Solaris 10 (08/07) [No longer can acess the internet]
    full install on one system, and Solaris 10 Developer Edition (09/07) on another system. Each has been auto-configured upon installation, and have reached the Internet, and registered at Sun Microsystems, from behind a router and cable modem.
    I want to create a Local Area Network, using a 4 port Netgear Ethernet Hub, model EN104tp, Each of the Solaris 10 systems, a Windows XP Pro system, and a Windows Media Edition LapTop. +(Which I want to have additional admin control, and access to the Server, from!)+
    My problem is this!
    1) Do I have to change any files to eliminate, the access to the internet from the two Solaris machines via router and cable modem? If so which, and, how do I? +(I intend for the LAN to be isolated from the internet)+
    2) What are the step by step, to set up a LAN?
    I can't seem to find that info anywhere. Maybe I am looking in all the wrong places...
    I appreciate and Thank You in advance for any help...

    The only difference between LAN and Internet is the size.
    Depends on how you define LAN -- it may be multiple subnets glued with routers or just one big or small subnet with bridges, switches and/or hubs or simply a crossed UTP-cable..
    If you don't have routers then you won't need a /etc/defaultrouter (rm -f /etc/defaultrouter; /usr/sbin/route -fn)
    You should use RFC-1918 addresses; i.e. chunks with a suitable mask of your choice as parts or whole of 10./8 (10.0.0.0 - 10.255.255.255), 172.16/12 (172.16.0.0 - 172.31.255.255) and/or 192.168/16 (192.168.0.0 - 192.168.255.255). Example 10.0.0.0/255.255.255.0 for a (256-2=)254-node subnet; 10.20.30.40/255.255.255.252 would suite a crossed-cable subnet perfectly.
    A DHCP-server would be nice for PC's. Solaris can do that (/usr/sadm/admin/bin/dhcpmgr).

  • How to connect my Macbook with an ipad mini in order to have an access to the internet on my iPad?

    Dear fellows, I am having a trouble in how to connect my mac with an iPad mini in order to have an access to the internet.

    If you are attempting to share your iPad mini's cellular data connection with the MacBook, please check out the following Apple Support article for additional details on how to do so.

  • I can't access the internet with Firefox on my computer (Windows 7 PC). I have used Firefox as my browser for 1 year but 5 days ago it stopped working even though Internet Explorer worked fine. I can't solve the problem and need some help.Randy Brown

    September 26, 2011
    Dear Mozilla,
    I am having some difficulty accessing the internet with Firefox on one of my PC computers. I normally use Mozilla Firefox as my web browser and google is my homepage and gmail is my email system. The operating system is Windows 7. For over a year this system worked perfectly but a few days ago it stopped working. When I launch Firefox now I get the message that that website (www.google.com) is unavailable. In fact, I can’t access any website and I am blocked from the internet entirely within Firefox. My internet connection is fine because Internet Explorer works fine. I can access google and any other website within that web browser. I have investigated all the security issue I can manage and found no smoking gun. I’ve tried uninstalling and reinstalling Firefox to no avail. Is Windows 7 compromising the effectiveness of Firefox? Any suggestions or other assistance you can offer would be appreciated.
    Sincerely,
    Randy Brown
    [email protected]

    You only have to clone your mac when using certain cable modem.  You don't clone your mac when using dsl.
    Greetings from Northern Ontario, Canada

  • HT4410 I have just installed Windows 7 64-bit full version Home Premium using Bootcamp and cannot get access to the internet. I installed on a Macbook Air Mid 2012 with Mountain Lion. Are there some drivers that are missing from the Windows 7

    Dear Apple. I have just installed Windows 7 64-bit full version Home Premium using Bootcamp and cannot get access to the internet. I installed on a Macbook Air Mid 2012 with Mountain Lion. Are there some drivers that are missing from the Windows 7 bootcamp install download from Apple

    It is a Total Misconception that the Support files are installed when you are installing Windows, even if the USB drive that holds them is inserted in the system when doing the Windows install.
    You must always Run the Setup.exe files from the support files or run the drivers individually once Windows has finished installing and booted to the desktop.
    Also you really need to run the Boot Camp Control Panel Applet and check for updates as not all the newest drivers for full function of all the hardware is included with the original support download. That download is basically a generic version to get the system working and without doing the updates not everything will work properly.

  • TS3406 I have a connection in the top left hand corner and can access the internet with and without internet on my iphone 5c but I can't receive and create texts and calls, someone please help have tried everything!

    I have a connection in the top left hand corner and can access the internet with and without internet on my iphone 5c but I can't receive and create texts and calls, someone please help have tried everything!

    YOu will need to contact your cell phone provider to resolve those issue, those are carrier features.

  • I can't get the Siri dictation tool to work when I access the Internet via Wi-Fi at work. It will work if I access the Internet with a cellular connection. What can I do to get it to work on the Wi-Fi?

    I can't get the Siri dictation tool to work when I access the Internet via Wi-Fi at work. It will work if I access the Internet with a cellular connection. What can I do to get it to work on the Wi-Fi?

    Thanks for your note. My tech dept could not come up with any explanation for the dictation tool not working. We have about 1,000 employees in our office - I think I will send an all employee message to see if anyone else has the issue.

  • I uninstalled Norton 360 under windows xp and now I'm getting this problem that firefox will no longer load pages. IE and Outlook still work and I can access the internet with them, I can ping any website I like successfully but Firefox won't load any pa

    I uninstalled Norton 360 under windows xp and now I'm getting this problem that firefox will no longer load pages. IE and Outlook still work and I can access the internet with them, I can ping any website I like successfully but Firefox won't load any pages ... N
    == This happened ==
    Every time Firefox opened
    == I uninstalled Norton 360 ==
    == User Agent ==
    Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.0.3705; .NET CLR 1.1.4322; .NET CLR 2.0.50727; Media Center PC 4.0; .NET CLR 3.0.04506.30; .NET CLR 3.0.04506.648; InfoPath.2; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)

    I found a fix for this, not only firefox but several other networking programs were broken as well (Outlook and IE were ok for some reason) so I reasoned that the Norton uninstall was incomplete somehow - I had done it from the add/remove programs in the control panel. Sure enough that's not enough to release Norton's tentacles in your system, there's an uninstall tool on their website (a whole set of them actually) that managed to carve it out completely and after a restart everything was back to normal. My machines will definitely be Norton-free from now on ... N

  • Cannot access the internet with Safari

    Safari locked up and made me restart the computer. When I did, I could no longer access the internet with Safari. I could still get into the ITunes store, had internet contect come over my dashboard, but cannot get online. I spent two hours with customer service, emptying caches, re-installing Safari, etc. but still have no luck as of today. Any help is greatly appreciated.

    Hi
    Welcome to  Discussions
    I grew up in the Delaware Valley - Delaware County/Media.
    Do you remember specifically what you were doing in Safari when it locked up, locking up your entire system. It's rare this happens in OS X.
    Also, which version of OS X Tiger are you using - the latest is 10.4.9? You can determine such by going to the Apple Menu in the upper left of the screen and selecting "about this Mac". The next panel will show you your OS X version, plus other information about your system.
    Regarding the inability to connect, try Safari from another User Account. In case you require it, here's how to set up another account:
    Here is guidance from Apple on how to set up the account. You can ignore step 7 in the article.
    Also, on the system preference>Accounts panel, click on "log-in" options. There, select "fast user switching". This allows you to go back and forth between user accounts via an icon in your Menu Bar at the top of the computer screen.
    Log-on to the new account and start Safari. If Safari connects to the internet in the new account, then your problem is specific to your regular user account. Otherwise, similar response means a system-wide problem.
    Post back

Maybe you are looking for

  • Setting color codes for more than one photo at a time

    Is there any way to set color codes for more than one photo at a time?

  • Cannot install updates

    I go through the process of installing updates but when I start sqldeveloper again they are not applied because of the following errors. About Oracle SQL Developer 3.0.04 Version 3.0.04 Build MAIN-04.34 Copyright © 2005, 2011 Oracle. All Rights Reser

  • HELP! My hard drive crashed, can I copy my iTunes library files to a new PC

    My hard drive crashed, but I attached it as a slave drive using an older PC and I can see all of my files but I can't start any programs (iTunes) from this slave drive. How can I copy iTunes music files and library to a removable drive, and then use

  • Connecting to MySQL from another machine.

    I use following code to connect to my database.it works String databaseUrl = "jdbc:mysql://localhost:3306/test"; but when i use String databaseUrl = "jdbc:mysql://192.168.0.205:3306/test";{ it gives error (192.168.0.205 being my ip address) error mes

  • Wired keyboard not found

    Hi I just did an update (stupidly didnt check wat the update was) of my 10.8.3 OSX (14th May 2013) on a brand new imac and now the wired keyboard isnt found - maybe it's a faulty keyboard but we are talking less than 2 weeks old and i had no problems