LAG for two WLC 4400
Hello everyone,
I installed for a client two WLC4400 (one is used for redundancy).
I wish I could make the aggregate links between these two controllers to spread the load.
In this configuration, there won't be primary and secondary controllers,
APs will be associated with one or the other WLC when they will be
discovered and by the number of AP on each controller.
Is this configuration possible?
And how to do that?
Thank you in advance,
Adeline
Hi,
You don’t need aggregate links between the two controller to balance the load. Just let the access points discover both controllers and they will take care of the load balancing. The AP collects all information about the controllers they found during the discovery, and then choose the controller with the leased load. And, make sure that you don't configure primary and secundary controller on the APs, they will only load balance if they don't have this configured.
//Johan
Similar Messages
-
Snmp error for guest access ticket on two WLC
Hi,
I have one wcs (5.0.56.2) and two wlc 4400 ( 5.0.148.2). When i try to create a ticket for guest access on the two wlc without time restriction, it works well. But when I defined time restriction for the ticket, i have a snmp error on the passive wlc (snmp operation to device failed, attempt to set conflicting attribute value) and not on the active xlc.
Thks.The lobby ambassador can specify the amount of time that the guest user accounts remain active. After the specified time elapses, the guest user accounts expire automatically.
The local user database is limited to a maximum of 2048 entries and is set to a default value of 512 entries (on the Security > General page). This database is shared by local management users (including lobby ambassadors), net users (including guest users), MAC filter entries, and disabled clients. Together these cannot exceed the configured database size.
For the configuration following URL may help you
http://www.cisco.com/en/US/docs/wireless/controller/5.0/configuration/guide/c5users.html -
WLC 4400 series OID for Current Clients
Can someone advise what is the OID for the number of current clients for the WLC 4400 series appliance.
Thanks.Based on the results of your walk, I would say it's reports all of the instances on that particular controller...and I say this because only one instance is reported. I would think that if you have multiple WLANS on that WLC, you would get multiple instances reported back, so, (maybe, like you) I'm confused by the description in the MIB object where it states:
"No of Mobile Stations currently associated with the WLAN."
which to me looks like "the WLAN" is used in the singular.
At this point, I think the best thing to do would be to open a TAC case with all of this info, and we can get with our developers for confirmation.
Hope this has been somewhat helpful, and please rate these posts.
Thanks,
-Joe -
How to disable Password Recovery in WLC 4400
Hi All,
I need your help to disable the password Recovery for the WLC 4400, in case of the hardware stolen or hacking by internal hacker,
Thanks in advanced for your help,
AhmedGee whiz. This is the second post you've made in regards to disable password-recovery mechanism. For the WLC, I agree with Nic, it's not possible. And, for the record, there are ways to bypass a disable-password-recovery mechanism. This is mainly due to prevent un-authorized use of this mechanism by, for example, a disguntled network administrator from shutting down a network.
-
Two WLC over the same SUBNET - selection from AP for determinate WLC
Hi
I have the next problem, my company have two WLC (WISM1 - IOS 7.0 and WLC2504 - IOS 7.4), and we have 4 types of APs (1131, 1242, 1040 and 1600), well the WISM 1 manages the old APs 1131, 1040 and 1242, the 2504 manages the 1600, this because the WISM 1 don't support the 1600
Well my question its how i can assigned to APs 1131, 1242 and 1040 to connect to WISM1 and not to 2504 , both are on the same subnet and the Ip its send for DHCP with option 43, others for DNS and apparently some of my APs connected to the 2504, I wish only connect to WISM 1
How i can set priority in the AP for conect to WISM1?, i read the High Availability on the AP, this is enough or should we make any extra settings the WLC
Thanks for the response
RegardsTo understand the working of HA kindly study the following link .It will provide you step by step solution to the query
Hi Kashif,
I don't think you understand the nature of this thread. It is IMPOSSIBLE to configure a 2504 & a WiSM-1 for HA (AP SSO). -
Hello
Following customer request/desire I am exploring a "strange" CT5508 config.
Before diving in to it deeply I would like to know if my idea is possible at all.
This is what I need to start from:
1. Network is divided in two pieces , let's say "LEFT" and "RIGHT". The two pieces can only communicate through Firewall.
2. CT5508 will be installed physically close to two switches, one in each LEFT and RIGHT network.
3. Access Points will be present in both LEFT and RIGHT network and need to be controlled by single CT5508
4. We need to keep wifi/capwap traffic in both networks as much as possible separated
This is my idea:
1. No LAG
2. Have CT5508 SFP Distr Ports 1 through 4 connected to switch in LEFT network; ports 5 through 8 connected to switch in RIGHT network
2. Have AP Manager intf 1 through 4 associated to distr ports 1 through 4
IP Addresses of AP manager Intf 1 through 4 from IP Subnet 1 and VLAN LEFT
3. Have AP Manager intf 5 through 8 associated to distr ports 5 through 8
IP Addresses of AP manager 5 through 8 from IP Subnet 2 and VLAN RIGHT
4. Have different DHCP servers assigned/defined for LEFT and RIGHT network.
With this setup the question I can not answer from the CT5508 documentation is this one:
DHCP discover copies from AP in "LEFT" network come in over distr interfaces 1 through 4.
On which distri ports will CT5508 reply/offer to this DHCP discover from AP?
I hope this reply to go out over only distr ports 1 through 4 so that the DHCP-based Controller selection in the AP can select among AP manager intfs dedicated to the LEFT network.
Correct?
Going one step further: is this approach compatible with e redundant controller setup?
Thanks a lot for your help and any observation/warning on the subject.
Regards
FredNot possible, if you do LAG, all physical ports connect to a single switch (if dual switch, then it has to be VSS pair)
If customer require this sort of seperation, advise them to buy two WLC
HTH
Rasika
**** Pls rate all useful responses **** -
Can we do the same thing with WCL 4400 and 5500 series for failover? We have 1 existing 4400 WLC and we wanted to purchase another 1 for fail-over as well as backup. But right now, 4400 is EOL already. The only option is to have the 5500 WLC.
So if you do have previous set-up like this, so I would need your inputs.. Otherwise, same as usual, will gonna test to work this out.You can have both in a primary and backup, but make sure they are on the same code version. I'm assuming that you also have the configuration correct for the two wlc to communicate.
I would put them both on the 7.0.220.0.
Sent from Cisco Technical Support iPhone App -
IDS feature on WLC 4400 series
Hi Everyone,
I'd like to ask about the IDS feature on WLC 4400 series.
What will the WLC do if it detects an attack specified in the Standard IDS signature ? Will the WLC shutdown the client or just report it ?
Thank youThe intrusion-detection-system (IDS) signature engine on controllers and on the Cisco WCS automatically eliminates duplicate alerts for rogue access points, rogue clients, and IDS signatures that previously occurred when two or more access points detected the same attacker. Now instead of one IDS alert from each detecting access point, a single alert is generated for the attack.
Intrusion detection, location, and containment preserve the integrity of wireless networks and sensitive corporate information. When an associated client sends malicious traffic, a Cisco wired IDS device detects the attack and sends shun requests to Cisco Wireless LAN Controllers, which then disassociate the client device. -
Performance Lag for higher resolution
I have developed a touch based flash application with a resolution of 5120x1440.
There is performance lag in two areas.
1) FPS is low (below 33) and Graphic lag is high (sometimes hitting > 80 ms)
2) Touch response is slow (using touchlib)
I'm using a PC of the following specs.
CPU: Intel i7-4770 3.4GHz
RAM: Kingston 8GB
Motherboard: Gigabyte Z87X-OC
GPU: 4x Gigabyte Geforce GT630 2GB
PSU: 1000W
Currently, the GPU Load is hitting at most 20% and the CPU usage is most of time below 50%. If I keep invoking the touch events, the app will ocassionally freeze and GPU Load drops to 0% for a while before coming back to normal and app becomes responsive again.
Is there a hardware compatilbility issue? Is there any way to improve on the touch responsiveness?
Thanks...If the computer recognized the three monitors as three
monitors, and not one really wide monitor, then you could run three
full screen flash programs at the same time, one on each screen,
also syncing them with localConnection. It could be pretty easy to
sync content if you created a movie clip to hold all your animation
(the movie clip can be 4080 px wide) and then animated everything
so that a very wide clip had the entire animation. Then use a stage
with a width of 1360 and move this clip to x positions 0, -1360,
and -2720, each time saving the movie and publishing. If you have
one that sends localConnection cues to the others, then it should
be able to sync things up.
This is much easier said than done of course, as I dunno what
kind of content you're running, audio, video, etc. Plus, I think
you're dealing with a situation where you have a computer that sees
one big screen and not 3 smaller ones, so the second solution might
not work.
You could try a similar thing and drop all of them in a
Director shell, which will do 4080 pixels wide, and use the same
technique, but that could be a big performance hit, and it adds
another (expensive) pieces of software. -
I have a Problem with my new AIRLAP 1242 to connect with WLC 4400
after debug in my airlap it shows :
Reset done!
ethernet link up, 100 mbps, full-duplex
Ethernet port 0 initialized: link is up
Loading "flash:/c1240-k9w8-mx.123-7.JX8/c1240-k9w8-mx.123-7.JX8"...######################################################################################################################################################################################################################################
File "flash:/c1240-k9w8-mx.123-7.JX8/c1240-k9w8-mx.123-7.JX8" uncompressed and installed, entry point: 0x3000
executing...
Restricted Rights Legend
Use, duplication, or disclosure by the Government is
subject to restrictions as set forth in subparagraph
(c) of the Commercial Computer Software - Restricted
Rights clause at FAR sec. 52.227-19 and subparagraph
(c) (1) (ii) of the Rights in Technical Data and Computer
Software clause at DFARS sec. 252.227-7013.
cisco Systems, Inc.
170 West Tasman Drive
San Jose, California 95134-1706
Cisco IOS Software, C1240 Software (C1240-K9W8-M), Version 12.3(7)JX8, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2007 by Cisco Systems, Inc.
Compiled Mon 19-Mar-07 01:42 by hqluong
Image text-base: 0x00003000, data-base: 0x004051E0
Initializing flashfs...
flashfs[1]: 9 files, 3 directories
flashfs[1]: 0 orphaned files, 0 orphaned directories
flashfs[1]: Total bytes: 15998976
flashfs[1]: Bytes used: 5062144
flashfs[1]: Bytes available: 10936832
flashfs[1]: flashfs fsck took 4 seconds.
flashfs[1]: Initialization complete....done Initializing flashfs.
cisco AIR-LAP1242AG-E-K9 (PowerPCElvis) processor (revision A0) with 24566K/8192K bytes of memory.
Processor board ID FCW1411U0FZ
PowerPCElvis CPU at 266Mhz, revision number 0x0950
Last reset from power-on
1 FastEthernet interface
2 802.11 Radio(s)
32K bytes of flash-simulated non-volatile configuration memory.
Base ethernet MAC Address: 68:EF:BD:5F:9A:18
Part Number : 73-10256-07
PCA Assembly Number : 800-26918-06
PCA Revision Number : A0
PCB Serial Number : FOC14093XU3
Top Assembly Part Number : 800-29152-03
Top Assembly Serial Number : FCW1411U0FZ
Top Revision Number : A0
Product/Model Number : AIR-LAP1242AG-E-K9
Press RETURN to get started!
*Mar 1 00:00:05.608: %SOAP_FIPS-2-SELF_TEST_IOS_SUCCESS: IOS crypto FIPS self test passed
*Mar 1 00:00:06.858: %DOT11-2-VERSION_INVALID: Interface Dot11Radio0, unable to find required radio version 581.18
*Mar 1 00:00:06.858: Interface Dot11Radio0, Accepting as a test version of radio firmware
*Mar 1 00:00:06.878: %SOAP_FIPS-2-SELF_TEST_RAD_SUCCESS: RADIO crypto FIPS self test passed on interface Dot11Radio 0
*Mar 1 00:00:07.234: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to reset
*Mar 1 00:00:08.212: %DOT11-2-VERSION_INVALID: Interface Dot11Radio1, unable to find required radio version 581.18
*Mar 1 00:00:08.212: Interface Dot11Radio1, Accepting as a test version of radio firmware
*Mar 1 00:00:08.232: %SOAP_FIPS-2-SELF_TEST_RAD_SUCCESS: RADIO crypto FIPS self test passed on interface Dot11Radio 1
*Mar 1 00:00:09.278: %SYS-6-LOGGERSTART: Logger process started
*Mar 1 00:00:09.326: %SYS-5-RESTART: System restarted --
Cisco IOS Software, C1240 Software (C1240-K9W8-M), Version 12.3(7)JX8, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2007 by Cisco Systems, Inc.
Compiled Mon 19-Mar-07 01:42 by hqluong
*Mar 1 00:00:09.332: %CDP_PD-4-POWER_OK: Full power - AC_ADAPTOR inline power source
*Mar 1 00:00:09.388: %DOT11-6-FREQ_SCAN: Interface Dot11Radio0, Scanning frequencies for 32 seconds
*Mar 1 00:00:10.271: %LINK-3-UPDOWN: Interface FastEthernet0, changed state to up
*Mar 1 00:00:10.332: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to down
*Mar 1 00:00:10.332: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to down
*Mar 1 00:00:11.271: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0, changed state to up
*Mar 1 00:00:28.331: %LWAPP-5-CHANGED: LWAPP changed state to DISCOVERY
*Mar 1 00:00:28.361: %DOT11-6-FREQ_USED: Interface Dot11Radio0, frequency 2462 selected
*Mar 1 00:00:28.362: %LINK-3-UPDOWN: Interface Dot11Radio0, changed state to down
*Mar 1 00:00:28.363: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset
*Mar 1 00:00:28.369: %DOT11-6-FREQ_USED: Interface Dot11Radio1, frequency 5260 selected
*Mar 1 00:00:28.372: %LINK-3-UPDOWN: Interface Dot11Radio1, changed state to up
*Mar 1 00:00:28.398: %LINK-3-UPDOWN: Interface Dot11Radio0, changed state to up
*Mar 1 00:00:28.399: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to reset
*Mar 1 00:00:28.465: %LINK-3-UPDOWN: Interface Dot11Radio1, changed state to up
*Mar 1 00:00:29.398: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to up
*Mar 1 00:00:29.465: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to up
Translating "CISCO-LWAPP-CONTROLLER.ekahospital.com"...domain server (202.134.0.155)
*Mar 1 00:00:38.351: %DHCP-6-ADDRESS_ASSIGN: Interface FastEthernet0 assigned DHCP address 172.31.xxx.xxx, mask 255.255.255.0, hostname AP68ef.bd5f.9a18
*Mar 1 00:00:38.820: %DOT11-6-FREQ_USED: Interface Dot11Radio0, frequency 2417 selected
*Mar 1 00:00:38.827: %DOT11-6-FREQ_USED: Interface Dot11Radio1, frequency 5200 selected (203.130.196.5)
*Mar 1 00:00:49.835: %DOT11-6-FREQ_USED: Interface Dot11Radio0, frequency 2422 selected
*Mar 1 00:00:49.842: %DOT11-6-FREQ_USED: Interface Dot11Radio1, frequency 5220 selected
*Mar 1 00:00:49.851: %LWAPP-5-CHANGED: LWAPP changed state to JOIN
*Mar 1 00:00:49.852: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to administratively down
*Mar 1 00:00:49.852: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to administratively down
*Mar 1 00:00:50.852: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to down
*Mar 1 00:00:50.852: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to down
*Sep 18 07:02:25.504: %LWAPP-5-CHANGED: LWAPP changed state to CFG
*Sep 18 07:02:29.288: LWAPP_CLIENT_ERROR: lwapp_name_lookup - Could Not resolve CISCO-LWAPP-CONTROLLER.MYDOMAIN.com
*Sep 18 07:02:30.504: LWAPP_CLIENT_ERROR_DEBUG: spamHandleCfgReqTimer: Did not recieve the Config response
*Sep 18 07:02:30.551: %SYS-5-RELOAD: Reload requested by LWAPP CLIENT. Reload Reason: DID NOT GET CONFIG RESPONSE.
*Sep 18 07:02:30.551: %LWAPP-5-CHANGED: LWAPP changed state to DOWNXmodem file system is available.
flashfs[0]: 9 files, 3 directories
flashfs[0]: 0 orphaned files, 0 orphaned directories
flashfs[0]: Total bytes: 15998976
flashfs[0]: Bytes used: 5062144
flashfs[0]: Bytes available: 10936832
flashfs[0]: flashfs fsck took 26 seconds.
Base ethernet MAC Address: 68:ef:bd:5f:9a:18
Initializing ethernet port 0...
Reset ethernet port 0...
Reset done!
and after that i check in my WLC that shows
AP with Base Radio MAC xx:xx:xx:xx:xx:xx (APxxxx.xxxx.xxxx) is unable to associate.
The reulatory domain configured on it '-e' does not match the controller's country
code: USA
i found that the problem about the region.
question :
1. is it possible to change the region in AIRLAP 1242 or in WLC?
2. if possible how to change it?
INFO :
my first AIRLAP Product/Model Number : AIR-LAP1242AG-A-K9 and my new AIRLAP Product/Model Number : AIR-LAP1242AG-E-K9WLC GUI >> Wireless >> Country >> Select the country.
Regards
Surendra -
WLC 4400 and multiple authentication servers e.g. RADIUS, ACS
WLC 4400 and multiple authentication servers e.g. RADIUS, ACS
Can the WCL 4400 be set up to use multiple RADIUS servers? The user accounts for accessing wireless would use a RADIUS server. The administrative accounts for the WLC would reside on an ACS server.Yes, that is correct. You can set acs to use both radius and tacacs.
For this you need to add WLC twice in acs-->network configuration. But you need to keep host name different.
eg 1) Host name WLC --->IP x.x.x.x -->Auth using -->radius
2) Host name WLC1--->IP x.x.x.x --->Auth using -->Tacacs.
You need to set up tacacs commands on WLC along with radius commands.
Regards,
~JG
Please rate helpful posts -
Up until now, my experience has been with 5500 controllers and ISE.
My customer is using 4400 controller, on 7.0.240 code.
I cannot locate any documents referencing 4400 controller configuration for webauth, named ACLs, posturing, etc...
Does anyone know of any documents, or have experience that can assist with this configuration?Michael,
Depending on the version of ISE software you are running, you may be in luck. The information below is for 1.1.x. If you are using v 1.2, you may have to tweak a bit.
In this first document, you can see the WLC 4400 is supported and Local Web Auth is supported, with the following caveat: “Wireless (An ISE Inline Posture node is required if the WLC does not support CoA as discussed in Footnote #4. WLCs with the code specified in this table do support CoA without an ISE Inline Posture node)”
http://www.cisco.com/en/US/docs/security/ise/1.1/compatibility/ise_sdt.html#wp55038
Of course, with an IPN, your posturing (and CoA) is handled here.
DACLs are also supported on the WLC 4400.
Per User ACLs are covered in the following document:
http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a00808b041e.shtml
I think you will find that if you substitute the ACS pages with the corresponding ISE interface pages, this can be done.
Please feel free to ask any additional or follow-up questions.
Also, please let me know if this fixes your issue. If it does, please rate this answer and mark your question as Answered.
Charles Moreton -
We have a site with a WLC 4400 and we would like to setup a Controller failover. The WLC 4400 is EOS/EOL and the replacement available is WLC 5508. Can someone advice me on how to configure these units in Primary /Secondary mode so that if any of the Controllers fail, the other one can take over?
Thanks,Hi Akil,
You are most welcome
Yes, you can configure 4400's and 5500's in a redundant configuration, but both should be runningthe
same code version. I believe the latest version that is compatible for both is 7.0.220.0.
this is the last version that supports the 4400 series.
Here's a note that reflects the support;
Note
Controllers do not have to be of the same model to be a member of a mobility group. Mobility groups can be comprised of any combination of controller platforms.
http://www.cisco.com/en/US/docs/wireless/controller/7.0/configuration/guide/c70mobil.html
Cheers!
Rob
"Show a little faith, there's magic in the night" - Springsteen -
Dear All,
We have two WLC 5508 in HA mode with 100 supported AP, we need additional 25 ap support license,
the question is I need to buy license for 125 AP or i need to buy license for 25 AP and somehow add it to 100 we have now? is it possible?,Hi,
You just top-up the licenses, i.e. only buy the extra licenses you need.
I refer you to this document, in here you will find an example explaining how increasing licenses works.
http://www.cisco.com/c/en/us/td/docs/wireless/controller/7-0/configuration/guide/c70/c70ccfg.html#wp1879749
HTH
Mike -
I have two WLC 2504 controllers. These controllers are for two different buildings. But they share a VLAN, and network address range.
How can I control the access points to the register selected only at a specific controller.
Example:
AP 1 -> WLC 1
AP 2 -> WLC 2
AP 3 -> WLC 1
Since the buildings also broadcast in different SSID.
The two controllers are in a mobility group.I also ran into an install similar to yours. My client had a flat network and each wlc had licenses for the amount of APs in a particular building. What I did to make sure the APs never join the other wlc, is to use a Mac list. This allowed me to enter the APs base Mac address on the wlc and I enabled under the ap policy to verify authorization using Mac list. You can also do what AA mentioned which is good practice, but you have a chance that APs might join the other wlc. If the other wlc has different configurations, it might cause issues until the ap falls back to its primary.
Sent from Cisco Technical Support iPad App
Maybe you are looking for
-
Hypothetically... I have an image drawn on a JPanel, say, a line running through a circle. How do I go about capturing this particular image, w/out getting other images that mau be present? Also, is there a way for me to allow the user to selct an im
-
After LR 5.3 update external editors stop working. PS , NIK collection
I updated lightroom from 5.2 to 5.3 and my external editors NIK and Photoshop CC stop working. I click on them, but nothing happens the applications do not open. In the case of Photoshop I make sure that I had everything updated including camera raw
-
Help! I lost half my movies
Hello, I upgraded my Power PC G5 tower 1.6 mghz to a new '11 Mac mini. During transfer, only about 80 out of 140 movies actually transfered to the new computer. I went to the old computer to see what was missing. The movies on the old computer now ha
-
Hi guys, I wanted to know the best way to look for a startup SAP job. I have alot of experience using SAP, it runs in my family and it is something that has always interested me. However, after spending hours looking for suitable jobs nearly all lis
-
help.. help.. HP Mini 1000.. reset bios!!![edited Serial Number by Moderator] Thank all>>>>> This question was solved. View Solution.