Guest use of a Aironet 1131AG Access Point

I have 2 WLAN's using (mostly) D-Link products - one is for staff only and the other is for guests, and is totally separate from our LAN.
I'm disappointed with D-Link and want to change-over to all-Cisco AP's. I'm fairly satisfied with the 1131 and wish to build on it.
The manual mentions a guest SSID, but I have reservations about network security. (I am thinking of using a single WLAN with multiple SSID's to handle the staff and guests.) What is the opinion on this forum on this issue? (I'm very new to Cisco and classify myself as little more than a beginner with wireless in general.)
Mike Webb
1-man IT shop for a conservation non-profit in central Nebraska

Here's an overview of Cisco's "Granular Guest Access Management and Provisioning" (http://www.cisco.com/en/US/prod/collateral/wireless/ps5678/ps6973/ps8382/prod_brochure0900aecd806b8a72_ps6087_Product_Solution_Overview.html).
Here's is a document on how to configure Guest Access on an Autonomous AP:
VLANs on Aironet Access Points Configuration Example
http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a0080665ceb.shtml

Similar Messages

  • Multiple Cisco Aironet 1131AG access points and same SSID?

    We have multiple Cisco Aironet 1131AG devices, all wired on one Cisco L2 switch(2560)  who is connected to L3 switch (3550). We assigned one VLAN for access point in L3 switch who acts as vtp server (L2 switch is vtp client). All ap's will have static ip address and all will have same SSID and no security and they will be using multiple channels (ex. 1,6,11).  They will operate in 3 floor building for roaming wireless client. We won't using any wireless controller.
    So my question is this: How to configure APs-all the same with different ip's, can we use L3 switch to create dhcp server for access points VLAN (pool for clients, and the rest for static ip for ap's)? Can one of the ap's be WDS and in the same time local radius server with users without Cisco Secure ACS or similar controller or I didn't understand this quite well :-). I followed guide http://www.cisco.com/en/US/docs/wireless/access_point/12.3_2_JA/configuration/guide/s32roamg.html for WDS where the part abou Cisco ACS is a problem, so I can use same ap as Local Authenticator as in guide  http://www.cisco.com/en/US/docs/wireless/access_point/12.3_4_JA/configuration/guide/s34local.html#wp1035723.
    Many thanks...

    Well, just so you know, WDS and local RADIUS authentication is only needed if you're using authentication on your wireless connection.  You say you're not planning to use security, so this isn't necessary.  However, I'd highly recommend at least using a simple WPA2-PSK to lock down your connection, otherwise you might end up giving free Internet access at best, and at worst you might be giving access to company PCs and servers.  If you want to further use an 802.1x or WPA authentication method, then yes, you can use an AP as a RADIUS server and WDS to improve authenticated roaming, but this is far more limited than using a Cisco ACS.
    As for your other questions, yes, your APs can all be configured the same except for at least three parameters: IP address, channel, and hostname.  Configure your static IP addresses on the AP's BVI1 interface.  Don't place it on the Radio or Ethernet interfaces, because if either of these interfaces goes down you'll lose the ability to configure the AP, so it's best to use the BVI1 interface.
    And yes, configuring a DHCP scope for your clients on your L3 switch is a good design, or you could also use your DHCP server on a different subnet by using the ip helper-address command on the L3 interface.  I hope this helps!  Let me know if you need help configuring any of this.
    Merry Christmas!
    Jeff

  • IPhone4 and Cisco Aironet 1141 access point - fail using WPAv2 Personal

    I cannot get my iPhone4 (latest s/w) to connect to a Cisco Aironet 1141 access point if I specify WPAv2 Personal. It is a single access point without radius etc. I have no problems connecting using "no security", WEP or WPAv1. Is there a problem with the iPhone4 implementation of WPA2 as all my other PCs connect just fine on WPAv2?
    With the Aironet 1141 I can switch security between WPAv1 & WPAv2 while keeping all other settings identical. Thus I can clearly demonstrate how the iPhone4 connects when both devices are set to WPAv1 yet will fail to connect when I switch both to WPAv2. As I have said, all other PCs I have connect via WPAv2 without any issues.

    I cannot get my iPhone4 (latest s/w) to connect to a Cisco Aironet 1141 access point if I specify WPAv2 Personal. It is a single access point without radius etc. I have no problems connecting using "no security", WEP or WPAv1. Is there a problem with the iPhone4 implementation of WPA2 as all my other PCs connect just fine on WPAv2?
    With the Aironet 1141 I can switch security between WPAv1 & WPAv2 while keeping all other settings identical. Thus I can clearly demonstrate how the iPhone4 connects when both devices are set to WPAv1 yet will fail to connect when I switch both to WPAv2. As I have said, all other PCs I have connect via WPAv2 without any issues.

  • Securing Aironet 350 Access Point

    Hello -
    My small network is operating correctly using the Aironet 350 Access Point and multiple clients. However, the setup is not secure.
    How is it possible to secure access to our AP?
    Specifically: I would like to establish a WEP key, as some devices (i.e. pocket-pc's) do not support more advanced security schemes.
    Thanks,

    Extensible Authentication Protocol (EAP) authentication, also called 802.1x authentication, provides dynamic WEP keys to wireless users. Dynamic WEP keys are more secure than static, or unchanging, WEP keys.
    For more details on configuring both types of WEP refer the following document,
    http://www.cisco.com/univercd/cc/td/doc/product/wireless/airo1100/accsspts/i12215ja/i12215sc/s15wep.htm

  • Blackberry Z10 connection with an Aironet Cisco Access Point 1200

    Hi everybody,
    I'm trying without success a connection between a Blackberry Z10 and an Aironet Cisco Access Point 1200.
    We have no BB Server, we would like just to connect the WIFI.
    I've checked this points during the activation of the device:
    There's no LEAP protocolle.
    There's an EAP-Fast possibility.
    There's Mac Address recognition possibility.
    When we try to use the EAP-Fast possibility, we generate a .pac file, but i don't know where i can put this file so that the Blackberry recognize this file. I've search the whole day and didn't find anything... there's simply no explanation with the Z10 around the .pac file without a BB Server.
    I've try the Mac Address recognition and it simply doesn't work (no error the search time is too long)
    Every other older smartphones - Blackberry (there's 4 devices) are working.
    Anyone have an idea about? a suggestion? a list of compatible WIFI Devices?
    Thank you ahead.
    Have a nice day.
    Joel.

    Sorry i don't understand your answer.
    I'm not a developper but a system administrator.
    I just would like to use a Balckberry Z10 with our Wifi/Router Aironet Access Point 1200.
    not more.
    Best regards,
    Joel

  • Can an Aironet WiFi Access Point bridge multiple internal VLANs?

    I have Cisco Aironet 2700e access points.  Historically they were configured with a single SSID on both radios with WEP 128bit security.
    I now need to add new WiFi devices to the network that have limited flexibility.  They must be associated only with a specific radio (2.4ghz or 5ghz) and WPA2PSK security.
    My thought was to create two additional SSIDs on the 2700 access points, one for 2.4gz WPA2PSK and the other for 5ghz WPA2PSK.  The pre-existing SSID will continue to use 128bit WEP.  To do that  I need to use VLANs on the 2700e.
    I have no other VLANS on my network.  I only need VLANs on the 2700e because I have different physical devices that support different WiFi frequencies and security options.  I don't need to segment the network.
    How do I bridge the VLANs on the 2700e?
    Devices that connect to the non-native VLANs appear to be isolated from the rest of the network (as I would suspect with VLANs).  But that's not what I want .  I'm only using VLANs because I need multiple SSIDs, and I need multiple SSIDs because I have different physical devices that want different WiFI access point configurations.  I can't seem to find any way to configure the 2700e to bridge the VLANs for the multiple SSIDs.
    Any guidance would be appreciated.  I could buy additional access points but that seems to be defeating the purpose of having a device like the 2700e.
    Any help would be appreciated.
    Thank you.

    I made these changes to the example here:
    https://supportforums.cisco.com/document/55561/multiple-ssid-multiple-vlans-configuration-example-cisco-aironet-aps
    and it seems to be working.  (By "working" I mean that I can now ping to/from devices connected on different SSIDs.) I had to make these changes from the CLI.  There does not seem to be a way to make these changes from the GUI.  Is that correct? If there is a way to make these changes from the GUI please let me know.
    The changes I made were to make the sub interface for Dot11 radio 0 on the VLANs part of bridge-group 1.  So assuming the config in the example:
    ap(config)#interface Dot11Radio0.2
    ap(config-subif)#no bridge-group 2
    ap(config-subif)#bridge-group 1
    ap(config-subif)#exit
    ap(config)#interface Dot11Radio0.3
    ap(config-subif)#no bridge-group 3
    ap(config-subif)#bridge-group 1
    ap(config-subif)#exit
    I did not change the bridge group on the Ethernet interface.
    Questions:
    1. Did I create any new problems making this change? It seems to work, but am I going to get myself in trouble somewhere else?  Intuitively it makes sense to me: the VLANs are now part of the same bridge group (1, the native VLAN).  So all traffic should be bridged together.  Correct?
    2. I didn't change the Ethernet sub interfaces.  I don't seem to need to make that change.  I also don't like things sitting out there that I don't understand.  Should I do anything to clean up the Ethernet interfaces?
    3. The original configuration was made entirely from the GUI.  This change needs to be made from the CLI.  Can it be done from the GUI?  I can't seem to find a way to change bridge groups for a sub interface from the GUI. It worried me that it can't be done from the GUI.
    Thank you.
    Larry

  • Aironet 350 Access Point needs security

    I have been asked to help a fledgling school lock down their wireless network.  The network is currently setup as 3 Aironet 350 Access Points with operating on the same subnet distributed around the school.
    These have NOT been updated or touched since the day they were installed, by all acounts.  I think they are running VXworks.  My issue is that most support links that might prove helpful seem to be broken.
    A few simple questions:
    Can the Aironet 350 be secured and then used with a simple shared key?  This link seems to say no, that you must have Cisco software on the user computer as well.  that certainly can't be right, can it?
    I'm clearly out of my comfort zone with these, but they just don't have anyone to do this for them.  It looks like they need to be flashed to IOS and then able to use WPA but not WPA2?  I'm having trouble finding a firmware lik for the 350 as well because it's EOL.
    Basically, any help or information is welcome!  I'm ready to just pull the plug on them and call them secure!

    350 APs (not bridges) can be converted to IOS.  Then they can do WPA-PSK TKIP.  Downside is they only have 802.11b radios.  The latest IOS they can run is old but could probably be setup with WDS using an internal RADIUS server on one.
    The upgrade tool and image are still available for download.  I'm attaching a .pdf of instructions.
    You need these files:
    Aironet-AP-Cisco-IOS-Conversion-Tool-v2.1.exe
    AP350-Cisco-IOS-Upgrade-Image-v2.img

  • Configuring Cisco Aironet 1100 Access Point. Please help!

    Hi all,
    I have dozens of Cisco Aironet 1100 access points, each is managing its own wi-fi with DHCP.
    I had to disable dhcp on them because they are on a wired subnet where I am using the static IPs and don't want my wired clients to get DHCP addresses, nor someone to be able to plug the wire into own laptop and get on the network.
    It's been working fine with one exception - I need to be able to ping my access points from the central site, and I can't.
    What IOS command would enable ICMP echo on my access points in this case?
    Please help!

    Hi all,
    I have dozens of Cisco Aironet 1100 access points, each is managing its own wi-fi with DHCP.
    I had to disable dhcp on them because they are on a wired subnet where I am using the static IPs and don't want my wired clients to get DHCP addresses, nor someone to be able to plug the wire into own laptop and get on the network.
    It's been working fine with one exception - I need to be able to ping my access points from the central site, and I can't.
    What IOS command would enable ICMP echo on my access points in this case?
    Please help!

  • Can I use this as a wireless access point for my network

    can I use this as a wireless access point for my network

    umm... use what?
    A Time Capsule? Sure. It's just like many other wireless base stations. It can run in either bridge or route mode - in bridge mode it's just like an access point linking the wired and wireless networks together.

  • Is it possible to use an E90 as an access point?

    Since the E90 has a WIFI card, I was wondering if it was possible to use an E90 as an access point. The reasoning is that I want to be able to use a wifi only device (such as an Apple touch) to connect through the E90 to get to the internet.
    Any help would be greatly appreciated.

    11-Dec-2007 11:52 PM
    daiichi wrote:
    11-Dec-200708:26 PM
    crrrazy wrote:
    I don't think that will work ...
    Darn, I didn't think so, but it was worth a try. If only Apple saw fit enough to put bluetooth on the Apple Touch.
    Rumor has it BT is there, just not activated (yet).
    By the way, there is a solution that works to allow you to connect your E90 to your iPod Touch and control basic phone operations.
    Show the KUDOS button some love.... Hit that bad boy.... It don't hurt....
    Apple iPhone 5,
    Retina MacBook Pro, iPad Mini, Nikon D4

  • Using old Sky router as Access Point

    Hello, I am new to the forum so I hope have posted correctly. Having recently moved house I have switched to BT from Sky and have been supplied with the HH5 and the Infinity package. Due to house lay out wifi signal is not great throughout. I am wanting to use my old Sky (Sagem 2504n, I think) router as an access point. Is this possible or would need to flash the old sky router in order to do this. My first attempt did not work (when I try to set ip in sky router to within HH range I get an error message). Basically it would be good to know if I need to flash the firmware or if it is possible to do with the sky router as is before I aware too much more time.. Any help much appreciated!
    Thanks
    Solved!
    Go to Solution.

    You should be able to use it as a wired access point provided you change the IP address, and disable DHCP.
    This guide, for a Voyager router, should give you some idea of the settings to use.
    Using an old BT Voyager modem as an additional wireless access point.
    There are some useful help pages here, for BT Broadband customers only, on my personal website.
    BT Broadband customers - help with broadband, WiFi, networking, e-mail and phones.

  • Newbie help with Aironet 1200 access point

    Hello everybody,
    We "inherited" an Aironet 1200 access point with antenna's throughout our building. This was installed by a company that thought they would make money selling Wi-Fi access but now they have gone bankrupt.
    We eliminated their router and installed one of our own, and we have it handing out IP addresses. When I plug it into the Aironet 1200 it works just fine. Users are able to connect wirelessly and access the internet.
    I would like to change the SSID however so that it no longer reflects the now defunct companies name.
    I cannot determine what IP address is assigned to the access point so I can't figure out how to access the management page.
    I tried connecting to the ethernet port via a DB9 to RJ45 cable and hyper terminal. After connecting the cable and powering up the access point I am still unable to connect.
    I realize once I get connected I will probably run into password issues, but I'd like to figure out how to get at least that far.
    Any ideas?

    since ur gonna change the ssid and there is a password...
    1. reset the ap. before plugging power to ap, press hold the mode button for 3 sec or until the led becomes orange or amber, then release.
    2. the ap is reset to default setting with ip address 10.0.0.1
    3. either console or gui the ap and change the bvi to ur preferred ip address.
    4. configure everything else as you want.

  • Using Mac mini as an access point for home network

    Hi
    I'm looking for some help on using my mac mini as an access point on my home network.
    I have a G5 tower which is wired in to my router and acts as a home server. It has all my itunes library, films, etc
    I stream these to various machines in the house, one of which is a mac mini in our living room.
    The mini is connected to the network via powerline adapters meaning the airport is left free.
    So i set up internet sharing on the mini via airport so I can use the machine as an access point for the living room.
    If I connect another machine to the mini via airport, Internet is working fine but for some reason I can't see the any other machines on the network.
    All I see in the sidebar is the mini, not the server.
    I've tried it on both mine and my friends macbook but had no luck.
    Am I doing this the wrong way?
    How would you go about doing this?
    Cheers

    Internet Sharing may not be providing an address via DHCP, It also may not be providing a subnet Mask that can get you to communicate with the other computers on your local Network.
    Take a look at what IP addresses are being used by the various computers on the network. I would expect you have a Router that may be using 192.168.0.1 as its base "private" address, and issuing DHCP Addresses in that range and higher with a subnet mask of 255.255.255.0, meaning anything with the same three high octets can communicate freely without Router intervention.
    But what addresses are bing used for the Wireless Shared computer(s)? and what subnet mask?

  • Help with using the WRT54G as an Access Point

    Ever since I've been using the WRT54G as an access point behind another router I have been experiencing intermittent disconnects and reconnects from the internet anywhere from once every 5 to 60 minutes.  I get the message notifcation that the Local Area Network is disconnected for a split second before everything reconnects and works fine.  This has been happening on my desktop which is wired directly to the WRT54G which itself is wired directly to the other router, but I have also experienced these disconnects with my iPhone and laptops which have been using the wireless signal. 
    When I was connected directly to the original router I hadn't experienced any of these problems.  I've also tried changing settings and even disabling the wireless broadcast of the WRT54G but to no avail.  I can't figure out what the issue is, but it seems to also be affecting the wireless broadcast of the original router. 
    I've updated firmware for the Linksys, and I've done a reset for the Linksys as well.
    Any help would be much appreciated to get rid of these disconnects.

    OK, so I've tried a different setting to see if it'll work. 
    Previously I had not configured the WAN of the Linksys router at all and left it on Auto (DHCP) even though I disabled the DHCP for the LAN.  I've now set the WAN up to a random Static IP and hopefully this will solve the problem, but I'm not sure as of yet, if anyone could look over the settings to see if they're correct please let me know.
    Router 1- (Router)
    WAN - Configured to ISP
    LAN - DHCP
    IP: 192.168.1.1
    Subnet: 255.255.255.0
    IP Range: 192.168.1.100 - 192.168.1.150
    Router 2 - Linksys (AP)
    WAN - Static IP
    IP: 64.XXX.XXX.1 (made up value)
    Subnet: 255.255.255.0
    Gateway: 64.XXX.XXX.254 (made up value)
    DNS: XX.XXX.XXX.X (made up value)
    LAN - DHCP disabled
    IP: 192.168.1.2
    Subnet: 255.255.255.252
    The WRT54G was a bit of a pain in terms of what Static IP and Gateway values they would accept, so I had to randomly put in values until I found something that worked.  So far no disconnects, but it's only been half an hour.  I can't seem to access the admin page for my Linksys router at 192.168.1.2 anymore though.

  • Can i use ipad as a mobile access point

    I have a ipad 3g model and wondering if i can use is as a mobile access point or is that only possible with an ipad2?

    It's not possible on either iPad - currently only the iPhone 4 and 3GS models can be used as mobile hotspots

Maybe you are looking for

  • Bold 9650 Calendar does not sync with PC after upgrading to OS 6

    BB Model - Bold 9650 Carrier/country - Verizon / United States Device OS level  - 6.0.0.432 PC OS version - XP RIM Desktop Software version - v6.0.1 B21 Outlook version - 2007 The symptoms - When syncing, events in Outlook transfer to device, but the

  • Quick Time Pro in Windows 7

    I have quick time pro 7 but use it in Windows not Mac.  I can't find a way to play a .wma file in quick time pro.  All I can see online is codec software to allow wma files to play in quick time if you have a mac.  This doesn't help if you are trying

  • Photosmart C6280 Can't bypass the warnings and print only in black

    I have a photosmart C6280 printer and i want to print in black only, but i can not bypass the "low ink" errors and "expired cartridge" errors to proceed.  I've changed the preferences in my print options to black only but the printer is still flashin

  • Jsp and database

    I am new to jsp can anyone tell me what is the best way to connect to database like should I created on java class for that and import it into the jsp

  • Navigate previous record,next record by entering key-up and key-down

    Hi , JDeveloper11g_ I am trying to solve of how to navigate previous record,next record by entering key-up and key-down in ADF Table. If any of you have this solution by JScript of Backing Bean please help me. Thanks zakir ===