HREAP with guest/secured WLANs

Here is the scenario:
I have a main site with WLC. VLAN 10 is mgmnt and AP-mgr, VLAN20 is secure user, VLAN30 for guests. There is a user-SSID and guest-SSID. Guest users get their IP from DHCP on WLC. APs and secure-users get their IPs from scopes on another DHCP server.
I need to deploy APs for a branch, with a high speed routed WAN connection and no local Internet.
I have created a separate AP-group for the branch.
Can I use the same SSID's for the branch? if yes, how?
Branch APs will be configured in HREAP mode and local switching.
I like to configure secure users in branch for central-auth/local-switching. Branch guests as central-auth/central switching.
Any information that helps accomplish above scenario will be appreciated.

Adding to Ramin's post, ifyou have a high speed WAN link, then run the ap's in local mode and use AP Groups.  If you just want the secure users to be local switched then on that ssid you would enable local switching and then when you set the ap to h-reap, you can set the native vlan which would be your management vlan the ap will be on and you will also define you ssid local vlan id.  I would keep vlan 20 the same on all branches too.

Similar Messages

  • Can't get secure wlan to work with new guest wlan

    Dear Support,
    I'm having a nightmare! where I can seem to get either one wlan to work or the other but not both together.
    I posted previously and reconfigured as per the suggestion, however the problem I get is that the secure wlan client associates, then de-associates after roughly 30 seconds with both a guest (no security) and secure (eap using ms ias as radius server)
    my previous post is;
    http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Wireless%20-%20Mobility&topic=Security%20and%20Network%20Management&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1ddcfe12
    and the log shows the following, obviously the client is set to connect automatically.
    *Mar 1 00:04:35.105: %DOT11-6-ASSOC: Interface Dot11Radio0, Station AP-CDC#2 00
    13.cefd.48ca Associated KEY_MGMT[NONE]
    *Mar 1 00:04:51.391: %DOT11-6-ASSOC: Interface Dot11Radio0, Station 000e.35f8
    .5d13 Associated KEY_MGMT[NONE]
    *Mar 1 00:04:51.506: %DOT11-4-MAXRETRIES: Packet to client 000e.35f8.5d13 reach
    ed max retries, removing the client
    *Mar 1 00:04:51.506: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating
    Station 000e.35f8.5d13 Reason: Previous authentication no longer valid
    *Mar 1 00:05:15.176: %DOT11-6-ASSOC: Interface Dot11Radio0, Station AP-CDC#2 00
    13.cefd.48ca Associated KEY_MGMT[NONE]
    *Mar 1 00:05:32.703: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating
    Station 0013.cefd.48ca Reason: Sending station has left the BSS
    *Mar 1 00:05:58.780: %DOT11-6-ASSOC: Interface Dot11Radio0, Station AP-CDC#2 00
    13.cefd.48ca Associated KEY_MGMT[NONE]
    *Mar 1 00:06:16.141: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating
    Station 0013.cefd.48ca Reason: Sending station has left the BSS
    *Mar 1 00:06:40.759: %DOT11-6-ASSOC: Interface Dot11Radio0, Station AP-CDC#2 00
    13.cefd.48ca Associated KEY_MGMT[NONE]
    *Mar 1 00:06:58.145: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating
    Station 0013.cefd.48ca Reason: Sending station has left the BSS
    *Mar 1 00:07:00.560: %DOT11-6-ASSOC: Interface Dot11Radio0, Station AP-CDC#2 00
    13.cefd.48ca Associated KEY_MGMT[NONE]
    *Mar 1 00:07:18.020: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating
    Station 0013.cefd.48ca Reason: Sending station has left the BSS
    *Mar 1 00:07:43.902: %DOT11-6-ASSOC: Interface Dot11Radio0, Station AP-CDC#2 00
    13.cefd.48ca Associated KEY_MGMT[NONE]
    *Mar 1 00:08:01.254: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating
    Station 0013.cefd.48ca Reason: Sending station has left the BSS
    *Mar 1 00:08:16.172: %DOT11-6-ASSOC: Interface Dot11Radio0, Station AP-CDC#2 00
    13.cefd.48ca Associated KEY_MGMT[NONE]
    *Mar 1 00:08:16.737: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating
    Station 0013.cefd.48ca Reason: Sending station has left the BSS
    *Mar 1 00:08:37.397: %DOT11-6-ASSOC: Interface Dot11Radio0, Station AP-CDC#2 00
    13.cefd.48ca Associated KEY_MGMT[NONE]
    *Mar 1 00:08:54.732: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating
    Station 0013.cefd.48ca Reason: Sending station has left the BSS
    *Mar 1 00:08:57.193: %DOT11-4-MAXRETRIES: Packet to client 0013.cefd.48ca reach
    ed max retries, removing the client
    Thanks in advance for your assistance.
    Any prompt reply will be greatfully received. I also rate responses.
    Thanks again, regards, Adrian

    Hi Ben,
    Please find attached AP config, I can access the switch at the moment, but the config is fairly basic, trunk port with two vlans and vlan 1 as the native.
    here's the ap config.
    AP-CDC#2#sh startup-config
    Using 2989 out of 32768 bytes
    version 12.3
    no service pad
    service timestamps debug datetime msec
    service timestamps log datetime msec
    service password-encryption
    hostname AP-CDC#2
    enable secret 5 $1$LQ1O$NKYZoYAeiahKw0805kLHg0
    clock timezone GMT 0
    clock summer-time BST recurring last Sun Mar 1:00 last Sun Oct 1:00
    ip subnet-zero
    ip domain name wlan.internal
    aaa new-model
    aaa group server radius rad_eap
    server 10.10.10.2 auth-port 1645 acct-port 1646
    aaa group server radius rad_mac
    aaa group server radius rad_acct
    aaa group server radius rad_admin
    aaa group server tacacs+ tac_admin
    aaa group server radius rad_pmip
    aaa group server radius dummy
    aaa authentication login eap_methods group rad_eap
    aaa authentication login mac_methods local
    aaa authorization exec default local
    aaa accounting network acct_methods start-stop group rad_acct
    aaa session-id common
    dot11 vlan-name dmz vlan 2
    dot11 ssid Secure
    vlan 1
    authentication open eap eap_methods
    authentication network-eap eap_methods
    dot11 ssid Guest
    vlan 2
    authentication open
    guest-mode
    username Cisco password 7 062506324F41
    bridge irb
    interface Dot11Radio0
    no ip address
    no ip route-cache
    encryption vlan 1 mode wep mandatory
    ssid Secure
    ssid Guest
    speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0
    54.0
    no preamble-short
    channel 2412
    station-role root
    interface Dot11Radio0.1
    encapsulation dot1Q 1 native
    no ip route-cache
    bridge-group 1
    bridge-group 1 subscriber-loop-control
    bridge-group 1 block-unknown-source
    no bridge-group 1 source-learning
    no bridge-group 1 unicast-flooding
    bridge-group 1 spanning-disabled
    interface Dot11Radio0.2
    encapsulation dot1Q 2
    no ip route-cache
    bridge-group 2
    bridge-group 2 subscriber-loop-control
    bridge-group 2 block-unknown-source
    no bridge-group 2 source-learning
    no bridge-group 2 unicast-flooding
    bridge-group 2 spanning-disabled
    interface FastEthernet0
    no ip address
    no ip route-cache
    duplex auto
    speed auto
    hold-queue 160 in
    interface FastEthernet0.1
    encapsulation dot1Q 1 native
    no ip route-cache
    bridge-group 1
    no bridge-group 1 source-learning
    bridge-group 1 spanning-disabled
    interface FastEthernet0.2
    encapsulation dot1Q 2
    no ip route-cache
    bridge-group 2
    no bridge-group 2 source-learning
    bridge-group 2 spanning-disabled
    interface BVI1
    ip address 10.10.10.49 255.255.255.0
    no ip route-cache
    ip default-gateway 10.10.10.253
    ip http server
    no ip http secure-server
    ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
    ip radius source-interface BVI1
    radius-server attribute 32 include-in-access-req format %h
    radius-server host 10.10.10.2 auth-port 1645 acct-port 1646 key 7 xyz
    radius-server vsa send accounting
    control-plane
    bridge 1 route ip
    line con 0
    line vty 0 4
    end
    AP-CDC#2#
    Thanks again, regards, Adrian

  • Nokia N9 can not connect with 802.1x WLAN security

    Hi,
    Can anybody please help me how to connect with 802.1x WLAN security network. All of other symbian devices N8, E7 can connect with it. I have the N9 latest phone from Nokia and it dont even support 802.1x in WLAN security options. I have searched through a lot of forums and this topic isn't even anywhere. Please help

    1st of all 802.1X is not even listed in Security method for of WLAN settings in Nokia N9 PR1.1. However same is listed in Symbian^3 for Nokia N8 and E7. 2ndly same settings works on N8 and E7 but not on N9. N9 showing me "something's wrong with network connection". In the syslog, i am getting these error msges.
    Feb 7 12:46:29 (2012) icd2 0.201.2+0m6[1271]: WLAN: Asked data for ssid "mobily" but got 5 results but no req ssid, ignoring all results (up=0x1249c)
    Feb 7 12:46:30 (2012) EAP[2691]: EAP 2.1.50+0m6 quitting.
    Feb 7 12:46:30 (2012) kernel: [ 465.324401] wl1271: down
    Feb 7 12:46:31 (2012) icd2 0.201.2+0m6[1271]: Removing active IAP 0x367b8/(nil)/(nil)/(nil)
    Feb 7 12:46:38 (2012) wlancond[1037]: Scan command failed: -100
    I am adding snapshots of Nokia E7 & N9 for comarison of settings
    Attachments:
    E7 1.jpg ‏40 KB
    E7 2.jpg ‏31 KB
    E7 3.jpg ‏50 KB

  • Cisco ISE or NAC Guest with web security (IronPort) integration

    All,
    We have a scenario where guests will be authenticated against the ISE or NAC Guest server, and customer will place an IronPort to provide web security, however, we can not find referentes whether IronPort can or cannot integrate with Guest Server, so that guests are not requested to be authenticated twice, one by the Guest Server, a one by the proxy. The idea is to keep it transparent for the guests with a single authentication.
    Has anyone there implemented such scenario?
    Thank you!

    I see. So, lets say we disable proxy authentication for the guest segment, can I still provide content filter for the segment, even though there is no proxy authentication? I assume customer will lose the reportinga and tracking granularity, but the scenario will work withou proxy authentication. This may be some sort of "man in the middle" only, but with content filter. Does it make sense?
    Thank you!

  • WLC2112 with Guest / Web-Auth and vlan

    Hi
    I'm trying to configure my WLC with guest SSID and vlan 10.
    The security is only set to Web-auth, and it is all working if the guest network is set to nativ vlan (1) But it seems that the http(s)://1.1.1.1/login.html is not reacheble from the guest SSID/VLAN??
    Please help.
    Management IP Address 192.168.14.252
    Software Version 6.0.182.0
    Emergency Image Version
    I have tried with ver. 5.2 also -

    I think that 1.1.1.1 is only reachable from a wireless client during webauth. They should not be able to reach that address once they have passed through the web auth page.
    Don't know if that helps, or not.

  • Satellite M100: Slow WLan data transfer with 3945ABG Intel Wlan card

    Have just popped a brand new M100 with XP upgraded to SP2 onto our network and am having trouble with the Wifi.
    Everything works, just really really slowly. Takes about 5 minutes to drag an MP3 off the file-server, web pages download at the speed of a dial-up modem and my beard doubles in length waiting for even a modest flash file to load.
    Have tried the following so far...
    - Speed is good on the ethernet cable, just not on the wifi.
    - Connection speed is good on the wifi (11Mbps) and signal strength is excellent.
    - All other laptops on the network are working fast
    - I have updated the drivers to the latest provided by intel, no change
    - I have applied all service packs and updates to XP (was a brand new box yesterday)
    - Disabling various modes on the driver make no difference
    - Switching off the QoS mode in the network panel doubled the trickle of data
    I see from earlier posts that I'm not the only one who has had this problem with the Intel 3945ABG chips, but I don't see a solution posted. Has anyone had success is solving this kind of problem.
    The data throughput is barely usable for internet access and quite inoperable for LAN filesharing or Skype.

    Sounds weird. If PCMCIA WLan card gives you good speed it means that there is nothing wrong with your Internet connection, just with built-in wlan card.
    You probably should use your warranty services or better yet to return it to the shop and get a new one straight away.
    In my country if something brakes within a few days after purchase you don't need to send it to repair under warranty because the shop usually agrees to replace it with new one if they have it in stock.
    There is one thing I think you better try: Take it to your friend who has wireless network or to the nearest free hot spot, connect to internet from there and see what speed you get.
    It could be, though longshot, that your router has compatibility issues with this specific built-in wlan card.
    For example I also have a slight compatibility issue between my d-link router and built-in intel wlan card, but it is about security protocols and not the speed.
    Overall it seems to me that this intel wlan card is not that good.

  • NAC Integrated with Guest Server

    Hi all,
    I encountered a problem which happened when I integrated NAC with Guest Server.
    Hope I can find solution here!
    When I create an account in Guest Server, the account will also be created in NAC as local user.
    If I chose "Time Profile - Start-End", the account will be created in NAC.
    But if I chose "Time Profile - from First Login", the account will not be created in NAC.
    So the guest can't login with this account using "Time Profile - from First Login".
    All the configuration in the document including "Radius Client and Accounting" was correctly configured.
    But I still can't find the solution.
    Please answer me if you know the answer. Thanks a lot!!!!
    Jet Li
    Taiwan SI

    Hi Jet Li,
    This should be expected since only time profiles with start-end are supported when integrating NGS with the NAC Appliance solution:
    http://www.cisco.com/en/US/docs/security/nac/guestserver/configuration_guide/20/g_guestpol.html#wp1063409
    "Cisco NAC Guest Server Version 2.0 supports only start/end and from creation profiles when used with Cisco NAC Appliances"
    Regards,
    Fede
    If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

  • Cannot access to any site with ssl connection and fail to open safari and keychain, unless restart computer and login in with Guest account.

    when Update to 10.7.2 ,I cannot access to any site with ssl connection and fail to open safari and keychain, unless restart computer and login in with Guest account.
    OS:10.7.2
    Macbook Pro 2010-mid 13inch

    I also have the same problem, however if I use Firefox or Opera sites with ssl connection work fine. Still, I can't use Google Chrome (ssl), Safari (ssl), the Mac app store (generally), or the iTunes store (generally). Both the iTunes store, Safari and the app store won't respond, and Chrome displays this error: (net::ERR_TIMED_OUT). The problem persists regardless of what network I'm using. Also, when trying to access the keychain or iCloud, the process will not start (will hang). I didn't have these problems at all before updating to 10.7.2.
    Sometimes rebooting helps, and sometimes not. If the problem disappears by rebooting, then it only lasts a few minutes before it reappears. It is very frustrating, especially since there doesn't seem to be any obvious or consistent way of which to fix it.
    I'm also using a Macbook Pro 13-inch mid 2010.

  • Problem with socket security

    Hi,
    I'm trying to make socket connection from within air application, but no way. I'm browsing google for almost 2 days, follow all possible solutions, but avidently I dont understund somthing cause I'm not able to do anything.
    Every time sandbox security violation.....  I need make some simple socket data exchange between my air, and OS. I do not have any web server and no any other kind of network ability. I write down stupid socket server, which is waiting for policy request, and for my other requests (it function 100%, tested with Telnet, so no way to have problem on my socket server side).
    The strange thing is that my application do not produce any request for socket policy file, neither at 843 port (for default), neither at my custom location with namual
    Security.loadPolicyFile("xmlsocket://ip:port"); call
    This is my primitive code:
    <?xml version="1.0" encoding="utf-8"?>
    <mx:WindowedApplication xmlns:mx="http://www.adobe.com/2006/mxml"
        layout="vertical">
        <mx:Script>
            <![CDATA[
                private var s:XMLSocket = null;
                private function test():void{
                    Security.loadPolicyFile("xmlsocket://127.0.0.1:25013");
                    if(!s){
                        s = new XMLSocket();
                        s.addEventListener(DataEvent.DATA, onData);
                        s.addEventListener(Event.ACTIVATE, onActivate);
                        s.addEventListener(Event.CONNECT, onConnect);
                        s.addEventListener(Event.DEACTIVATE, onDeactivate);
                        s.addEventListener(IOErrorEvent.IO_ERROR, onError);
                        s.addEventListener(SecurityErrorEvent.SECURITY_ERROR, onSecurity);
                    s.connect("127.0.0.1", 25013);
                private function onActivate(e:Event):void{
                    debug.text += "Activated\r";
                private function onConnect(e:Event):void{
                    debug.text += "Connected\r";
                    var o:XML = <request cmd="10"/>;
                    s.send(o);
                private function onDeactivate(e:Event):void{
                    debug.text += "Deactivated\r";
                private function onError(e:IOErrorEvent):void{
                    debug.text += e.text + "\r";
                private function onSecurity(e:SecurityErrorEvent):void{
                    debug.text += e.text + "\r";
                private function onData(e:DataEvent):void{
                    debug.text += e.data;
                    s.close();
            ]]>
        </mx:Script>
        <mx:Button label="Test" click="test()"/>
        <mx:TextArea id="debug" width="100%" height="100%"/>
    </mx:WindowedApplication>
    Any help will be apresciated.
    Ladislav.

    Hi,
    It pass some time but if i remember well, my problem was that i did
    not terminate stream output form my server vs air application, and it
    returns this security error.
    When I send  '\0' at the end of my message it work correctly. Yes the
    server was my own written socket server (c++ using boost libraries).
    Laco.
    Sorry late response I'm on hollydays
    Staney G ha scritto:
    So, how did you walk around the problem?  Did you have a control on how server responds?
    My test case failed similarly.  However, the target server is a public web service.
    Will appreciate your answers!
    >

  • Error on running reports with filters/security

    Post Author: mishel
    CA Forum: Publishing
    Hi,    I am trying to run a report with filters/security defined via Business View.  When I run the report as administrator, I am able to view successfully.  However, when I login as test/dummy account which filters my parameters, I am getting such error - "A request was cancelled.  The necessary security privileges could not be verified.  This indicates a problem with the security server."  Appreciate all the help I can get.Thank you,Michelle

    Hi onizga,
    According to your description that you are migrating SSRS 2008 R2 reports to SSRS 2012 SP2, after migration you got some error like “The Uri string is too long” which only occurred when accessing the drill-through actions, right?
    Usually, the issue can be caused when you try to pass some parameters that cause the URL length to exceed 65,520 characters for a Microsoft SQL Server 2012 Reporting Services (SSRS 2012), you cannot render the report, and you may receive the following error
    message:
    The value of parameter 'param' is not valid. (rsInvalidParameter).Invalid URI: The Uri string is too long.
    This is an known issue and already have the hotfix SQL Server 2012 Service Pack1 Cumulative Update 9 (CU9) as you know, you can try to reinstall this hotfix to fixed this issue:
    http://support.microsoft.com/kb/2916827 .Any issue after applying the update, please post it on the following thread or you can submit an feedback:
    http://connect.microsoft.com/SQLServer/feedback/details/788964/ssrs-2012-invalid-uri-the-uri-string-is-too-long 
    Similar threads for your reference:
    SSRS - The value of parameter 'param' is
    not valid. ---> System.UriFormatException: Invalid URI: The Uri string is too long.
    Microsoft.ReportingServices.Diagnostics.Utilities.InvalidParameterException:
    The value of parameter 'pSetOfScopes' is not valid. ---> System.UriFormatException: Invalid URI: The Uri string is too long
    If you still have any question, please feel free to ask
    Regards
    Vicky Liu
    If you have any feedback on our support, please click here

  • There is a problem with the security certificate of the proxy server. Error code 18 and 38.

    Hi All,
    After several hours and a short night of sleep I'm out of ideas and hopefully someone here can help me trying to solve this one. First of all the situation:
    Exchange 2013 on a remote location with a CA-certificate.
    Outlook 2010 and 2013 on different locations, locally installed and on RDS.
    When I open Outlook on my laptop all is fine, no errors, good sync, no problem. But when I open Outlook on our Remote Desktop Servers with Outlook 2013 I'm getting errors like "There is a problem with the security certificate of the proxy server. The
    name on the security certificate is invalid or does not match the name of the site. Outlook is unable to connect to this server. (Error code 18)". Opening Outlook 2010 the message is the same, but the error code now is 38.
    After this Outlook opens and is working, there's one more error though. After a while an security warning pops up with the message: "Information you exchange with this site cannot be viewed or changed by others. However, there is a problem with the
    site's security certificate. * The security certificate was issued by a company you have not chosen to trust. View the certificate to determine whether you want to trust the certifying authority. * The security certificate is valid. * The name on the security
    certificate is invalid or does not match the name of the site."
    Strangest thing is, it is the certificate of my RDS! It isn't my valid en officially bought certificate from my mailserver. What's going on? I'm out of options, what I've tried so far (in random order):
    - restarting mailserver and AD;
    - restarting switches;
    - restarting routers;
    - restarting RDS, AD and all other servers;
    - bypassed proxyserver for RDS;
    - created a new profile;
    - checked recently installed updates;
    - checked certificate on mailserver;
    - checked RDS on a different location, working fine.
    Nothing helped, what can I do next? Please advice.
    Regards.

    Found a thread that solves half my problem (https://social.technet.microsoft.com/Forums/office/en-US/70d18244-889a-4d95-ac3f-e234672a82b2/there-is-a-problem-with-the-proxy-servers-security-certificate-error-when-starting-outlook?forum=exchangesvrclients).
    The first message can be suppressed by adding this to the Exchange config:
    set-outlookprovider -Identity EXCH -CertprincipalName msstd:webmail.domain.tld
    set-outlookprovider -Identity EXPR -CertprincipalName msstd:webmail.domain.tld
    Giving the command get-outlookprovider, gives me empty information regarding the certprinipalname. Filled
    this and after recreating the profile or deleting the ost-file I still have the second alert with the local certificate of my RDS.
    Not completely where I want to be, any help regarding the second alert is greatly appreciated!

  • How can we handle browser settings while dealing with the security ?

    Hi ,
    how can we handle browser settings while dealing with the security ?When we configured security in web.xml , during the first request the container is asking for the authentication credentials once they are provided it go's on. but when the user gives a fresh request from the second window within the same browser that time it is not asking for authentication. How can we overcome this.Is there anything to do with server configurations?
    How can we make the container no to keep the things or act like session?

    Ya... I am taking a small example need not happen always but a kind of possibility i am thinking off.
    once the user sign out and just left without closing the browser and a friend (suppose not a good friend ... just kidding...) of that user may open the same jsp or file .This time the security is breached. If that feature or property exists....
    I know what you might say ... the user will log-out before leaving where a programer might invalidate the session at the time of log out.
    Consider the case of a bad Programing or just a programer might forget to invalidate,At that time as a application administrator how can he solve that issue.
    Thanks.......
    Edited by: user8483670 on Jun 6, 2011 1:08 AM
    Edited by: user8483670 on Jun 6, 2011 1:09 AM

  • SSPI handshake failed with error code 0x8009030c while establishing a connection with integrated security; the connection has be

    Hello, I have a sql 2005 server, and I am a developer, with the database on my own machine.  It alwayws works for me but after some minutes the other developer cant work in the application
    He got this error
    Login failed for user ''. The user is not associated with a trusted SQL Server connection. [CLIENT: 192.168.1.140]
    and When I see the log event after that error, it comes with another error.
    SSPI handshake failed with error code 0x8009030c while establishing a connection with integrated security; the connection has been closed. [CLIENT: 192.168.1.140]
    He has IIS5 and me too.
    I created a user on the domain called ASPSYS with password, then in the IIS on anonymous authentication I put that user with that password, and it works, on both machines.
    and in the connection string I have.
    <add key="sqlconn" value="Data Source=ESTACION15;Initial Catalog=GescomDefinitiva;Integrated Security=SSPI; Trusted_Connection=true"/>
    I go to the profiler, and I see that when he browses a page, the database is accesed with user ASPSYS, but when I browse a page, the database is accesed with user SE\levalencia.
    Thats strange.
    The only way that the other developer can work again on the project is to restart the whole machine. He has windows xp profession, I have windows 2000.
    If you want me to send logs please tellme

    Well here's my problem, maybe you can help. Intermittenly I get a login failed when connecting to a db engine through Server Management Studio using Windows authentication. When this happens the following entries are generated on the server's application event log:
    Event Type:        Error
    Event Source:    MSSQLSERVER
    Event Category:                (4)
    Event ID:              17806
    Date:                     1/14/2009
    Time:                     10:41:31 AM
    User:                     N/A
    Computer:          <server name>
    Description:
    SSPI handshake failed with error code 0x8009030c while establishing a connection with integrated security; the connection has been closed. [CLIENT: <ip address>]
    Event Type:        Failure Audit
    Event Source:    MSSQLSERVER
    Event Category:                (4)
    Event ID:              18452
    Date:                     1/14/2009
    Time:                     10:41:31 AM
    User:                     N/A
    Computer:          <server name>
    Description:
    Login failed for user ''. The user is not associated with a trusted SQL Server connection. [CLIENT: <ip address>]
    I've already ensured that the server is set to mixed authentication mode. Oddly enough, the workaround that I've found is that if I remote desktop into the server, log in and then log back out, Management Studio is suddenly able to connect again. No idea why it works. 
    As I said before, it is intermitten. Some days it errors on login, other days it doesn't and there are no configuration changes between them. Also, both client and server are in the same domain and same site so there is no VPN or anything in between. I'm really quite stumped. Any help would be great, or if you can point me in the right direction of where to look. Thank you in advance!

  • I have 2 ipod touch 3rd gen. Cannot connect to my wifi.  One will connect with neighbor's unsecure network..neither connect with my secured network

    I have 2 ipod touch 3rd generation.   Cannot connect to my wifi.   One will connect on and off to my neighbor's unsecure wifi but neither will connect to my secured wifi.   All my wireless computers connect plus my Ipad connects.    They did connect at one time but haven't used them for anything but audio books which connect through Itunes on my computer.   It shows my secured network name.   When I originally connected them it was another rather with other security but since then I have bought new equipment.   My Ipad and my printers just automatically connect.    I have put in the Ip information plus but still no luck.

    Try :                 
    - Reset the iOS device. Nothing will be lost
    Reset iOS device: Hold down the On/Off button and the Home button at the same time for at
    least ten seconds, until the Apple logo appears.
    - Power off and then back on the router
    - Reset network settings: Settings>General>Reset>Reset Network Settings
    - iOS: Troubleshooting Wi-Fi networks and connections
    - Wi-Fi: Unable to connect to an 802.11n Wi-Fi network
    - iOS: Recommended settings for Wi-Fi routers and access points
    - Restore from backup. See:
    iOS: How to back up
    - Restore to factory settings/new iOS device.
    If still problem make an appointment at the Genius Bar of an Apple store since it appears you have a hardware problem.
    Apple Retail Store - Genius Bar

  • Can't get Google CAL to work with iCAL "Server with a secure communication unavailable"

    I can't add my google account to iCal...
    Error message:
    "Server with a secure communication unavailable"
    "Your calendar acct isn't on a server that can receive your calendar information securely.."
    I have had this work just fine in the past, had to remove my accounts a while back, decided to add them back, and this error keeps popping up...
    Can anyone help??
    Googled and Searched this forum with no success. Found some suggestions but nothing worked.
    Thanks,

    I have used the CalDAV option from the pop list and the server option is : https://www.google.com/calendar/dav/[email protected]/user    , replace with your email the underlined
    I've found this here .

Maybe you are looking for

  • Sample portlets work in Repository page, but can't be added to a page

    Help, Portal 3.0.9.8.2. Apps 11.5.7 DB 8.1.7.3.0 I installed the JPDK and could see all samples from the Portlet Repository page. Every one works fine, except the Lottery only shows preview, not the balls. Then I try to add a portlet to a page. When

  • Home sharing now not working with Apple TV 6.0.1/ iTunes 11.1.3.8

    It was stupid of me to accept my Apple TV's notice of a new upgrade, which I accepted, and it is now version 6.0.1.  I upgraded my iTunes to 11.1.3.8.  Now my Apple TV doesn't recognize my Home Sharing with my computer.  I've reset the Apple TV to do

  • Primusrun crashes the system on exit

    Hi there im using bumblebee on my laptop for the optimus support. When i run any graphical application through bumblcee it crashes the whole system when i exit it. for example: $primusrun glxgears It works and diplays it, but when i press ESC to exit

  • Office document function

    I used Palm TX. My present problem Is : Palm is auto restart when I open any PDF file ( Power point file). May I ask where is problem come from ? Soft Ware Or Hardware  and which softwear? Can I Fix It ?  Please give me your advice What should I do ?

  • Placing a Webpage in a window subsection

    Hello, i have an application running. My wish is that when the user clicks on a LinkToUrl element (say to display a map), that the referred webpage be included into the present window and not be opened in a separate window. Is this technically possib