Prevent certain APs from associating with WLC

Hi, we have the following situation which I'd appreciate assistance with.
We have 9 WLCs around a corporate network.  Each of the WLCs was in the same mobility group for failover purposes, and to permit APs to reconnect back to their primary WLC in the event of a failover.
However one of the sites has now been sold and pending separation of the LAN infrastructure the APs need to be isolated and prevented from associating with any WLC other than their primary (on site).  From our experience once the APs know about other WLCs they retain this list in NVRAM even if the secondary WLC is removed from the configuration they will still associate with one of the known APs if possible (Cisco document this).
WLC v 8.1.185.
Does anyone have any recommendations to achieve this?  My thoughts are:
1) configure WAN router to deny outgoing LWAPP / CAPWAP packets.  Router is a managed service which will entail negotiations and cost with the service provider.
2) completely default all APs on site.  69 APs mounted in the roof of a large distribution depot.
3) Use ACLs on the other WLCs to prevent ones from this subnet connecting to them.  May be the easiest because it is all in our control.  But I'm unsure of the implications of this.
4) any other?
Thoughts?
Thanks
R

It's not that simple.  If simply changing the config from the controller stopped the APs  from associating to an unwanted controller outside their own network  then I wouldn't be here asking for help.  But that is not the case.
These APs (LAP1242s) keep a list of known controllers in the NVRAM that is not part of the running configuration from the controller - as I recall it is in the environment variables, but all the APs I have here in the office have been defaulted (which includes deleting the ENV_VARS file from flash) so I can't illustrate it.
As I said above, blocking the ports at the router involves managed routers and change requests which we can do but takes it two levels outside our control.
Hence the request for help about using ACLs to deny access to the WLCs from a specific network.
Thanks
Robin

Similar Messages

  • How to prevent certain Users from deleting a resource while in the project?

    We are currently using P6.2 client; We are setting up a new resource dictionary and have been searching to find a way to prevent certain users from deleting resources while in the project. Is there a way to do that? I have created Global profiles and Project profiles under the Admin security profile and have tried clicking off of rights to delete a resource but when I log into as that user I can still delete the resource. Please Help!

    Are you talking about preventing users from deleting resource assignments within a project? Or preventing them from deleting resources from the global resource dictionary?
    For global resource dictionary in Global Profile you would turn off:
    -Delete Resources
    And likely:
    -Add resources
    -Edit Resources
    -Edit Roles
    -Edit Resource Calendars
    For resource assignments on activities in Project Profiles you would turn off:
    -Add/Edit Project Activities Except Relationship
    Note: this will disable more then just the ability to alter resource assignments.

  • APs not associating with Controller after upgrade

    This is pretty bad.
    I've been upgrading our controllers to 4.2.209.0 without any problems untill today. The controller upgraded fine but, the APs aren't showing up anywhere. They aren't associating with any controller. I've shut/no shut the PoE ports. They show connected. The WCS says they are not associated with any controller. What should I do. Roll back the image? Will this help?
    Thanks Pat.

    Surendra,
    Thanks for the response. I got this from debug dhcp detail
    DHCP: QScan: Timed out Selecting state%Unknown DHCP problem.. No allocation possible
    I was pretty desparate at the time so, I wasn't able to trouble-shoot any further. After I saw the DHCP debug I deleted the normal DHCP server address, created a scope for the APs and configured it on the AP management interface and the APs got addresses. After the APs got their addresses, the clients got their addresses from the regular DHCP server. I will try again with the upgrade as I rolled back to 4.2.112.0. Atleast I know I can get an ip from the controller if I need.
    Do you know of any reason why my APs weren't getting addresses. Even when I rolled back they weren't getting addresses. The config hadn't changed.
    Thanks, Pat.

  • Apple TV Won't airplay certain songs from Macbook with itunes 11

    I have a MBPro running Mountain Lion and itunes 11. My apple TV is second generation with the latest software. When I am airplaying music to my apple TV it works just fine, but randomly it will stop at the beginning of certain songs and won't skip to the next song or play the song it is on. It just stays at 0:00. What is strange is I have a Philips Fidelio that airplays the same songs just fine. Also, the songs play fine when I use my computer speakers. It is just when I am airplaying to apple TV and just for certain songs. I even tried deleting and redownloading the songs from itunes match, and the problem persists. I have looked everywhere for an answer but haven't found anything.

    Go into Itunes, turn on home sharing.
    Verify your Airplay icon in your menu bar
    http://support.apple.com/kb/TS5209

  • APs not registering with WLC

    Hi guys, i'll try to explain our trouble as best as i can:
    Im trying to do some basic scenario here. Picture this: One L3 Switch connecting a 4402 Controller, 3 Administrative Vlans for APs (63, 93 and 127) and 3 Vlans for clients (one for each Administrative vlan, 16, 64 and 95 respectively). Also, in one of the administrative vlans (63) lives the Management and AP Manager interfaces of the controller. The L3 Switch does the DHCP business also, including giving the Controller IP (option 43).
    Here is the deal: When i try to connect one LWAP AP in to the same VLAN as the controller (63) it does gets an IP address of the segment and also gets the Controller IP. BUT, it cannot reach the Controller Management interface, not by ping nor by registering. (i connected a laptop to chek this behavior and it cant ping the Management Interface either)
    Then, if i connect the same AP to another VLAN (say.. 93)it will get an IP address of the segment, IP of the controller and it will reach the Controller by means of PING and also discovery request/discovery response. BUT, it wont register with the controller. In both cases, the L3 switch can ping just fine the APs and the Management Interface.
    After sniffing little bit I can see that the AP does in fact send the Join request message to the AP Manager interface of the Controller, but it wont get an answer. Then, in the CLI of the Controller (debug lwapp events enable) i can see that the controller does recive the discovery request and send the discovery response messages, but never sees the join request frome the AP.
    Configs of the switch and controller attached.
    Also, i checked the date of the controller and its up to date, the certificates of the APs should be fine, they will expire in 2 o 3 more years.
    Oh, and the Controller its not directly connected to the Switch, its connected to another 3500 switch using a GBIC, but its just used as a media converter... after that switch its connected to a trunk in the L3 Switch.. and yes, the Switch with the controller has all the needed vlans configured so they can be seen on the trunks.
    Any help would be greately appretiated.

    Hi again... guess what? I came to work today, turned on all the equipment.. and it works! God knows why but now the APs can register. For your information I did reset the devices before, so i dont know what happened.
    Anyway there is still a problem. If the APs are in the same VLAN as the controller, they cant see it. And this goes for every device, if I have 2 APs and one laptop in the same vlan they cant ping each other but can ping their GW. Any comments on this?
    Thanks in advance!

  • Selectively Prevent Certain files from Syncing?

    I have some enormous mp3 files (~300MB) in my iTunes library (ambient background sounds that I use with my cans) And I would like to prevent these from auto syncing with my ipod.
    I am aware of two methods of doing this, however neither of these methods really do what I want.
    1. Have unchecked songs not sync to ipod.
    - This is what I typically use to selectively keep stuff on my 8GB nano, however the problem is that I am effectively no longer able to use these unchecked songs in iTunes like in playlists or shuffle mode, unless I specifically double-click on the file. Most importantly the files wont repeat even if that option is selected, and the file is manually double clicked.
    2. Manually Manage songs on ipod.
    - This is a real drag, considering that I only have 5~6 files that cause issue due to their colossal file size.
    Are there any other exclusion methods that I am unaware of?
    Thanks for the help.

    You could just put all the music you want synced to your ipod into a playlist and tell your ipod to just sync to that playlist.

  • Can I prevent certain words from being hyphenated or split?

    I have a client that is real picky about the title of their business which is 2 words from being separated with the first word on one line and the next word on the line below.  There are other times like names of people that will get hyphenated and they dont want that either.  I know I can turn off all hyphens but I still want them, just not with certain words.  Is there a way to control both of these?

    Hello,
    Just to throw in another option, I sometimes do this through find and change.
    I just type the word in the Find what field that I don't want to hyphenate,  and then I go to the change format area on the bottom of the dialog box and click the no break check box in the basic character formats area,  and then I change all in the document.
    Hope that helps too..
    babs

  • How can I prevent personal contacts from syncing with Exchange corporate email?

    I have my phone synching with my work Exchange server over ActiveSync, and have 2 personal email accounts (POP and IMAP).  The 2 personal accounts are also configured in Outlook 2010 on my home computer.  Itunes is also installed on this computer. 
    I want my contacts from my 2 personal accounts to sync to my phone (which is working), but not have them sync to my work account (this part is not working the way I want).  I now have all my personal contacts uploaded to my work account.  How can I remove the contacts from my work account without removing them from my phone?

    Unless you are in the same household, the agreement for Mountain Lion does not allow the setup you have now.
    You need to spend another US$30 and buy an additional copy and get that other MacBook on its own unique Apple_ID.

  • How to read only files with a certain format from folder with java

    I have this folder on the server and I only want to read files from this folder on the server... I only want to read files with the files format starting with error_ and ending with xml... an example of a file would be..
    error_123.xml
    I want something like this
    if(fileName.startsWith("error_") && fileName.endsWith(".xml")){
    but which java package will I have to use to read the file from the directory...

    Create an implementation of the java.io.FilenameFilter interface to match the pattern you need.
    Create a java.io.File object for the folder.
    Use the File.listFiles(FilenameFilter) method to get an array of File objects for the files in the folder that match the pattern.
    For each file in the array, create a FileInputStream, wrap it in an InputStreamReader, and wrap that in a BufferedReader (assuming you want to read the XML files as character streams).

  • Prevent Certain Users From Shutting Down the Mac

    Hello,
    I have a group of Mac Minis which are secured in an equipment rack. When someone shuts the computer off, the rack has to be moved and the Mac powered-on, manually. This is not as easy as it may seem. Is there a way to remove the "Shutdown" item from the Apple menu. I need the "Logoff" and "Reboot" the options to still be available. I do nt have an OS X server, from which to project these settings from Workgroup Manager. Is there some .plist I can edit, or permission I can change?
    Thanks

    Not possible without hacking the system and even then it is not foolproof. If you Google something like mac os x disable shutdown you'll get an idea of the situation.
    And if you could remove the command from the Apple menu there is still the key combination to deal with.
    If this is a social problem, users mistakenly shutting down the system then maybe education would be a better approach to take.
    If it is willful or the inconvenience of this being done is very great then maybe you should suggest getting the serve for $20 just to have the ability to handle this.
    regards
    Message was edited by: Frank Caggiano - it does appear that tinkertool says it does address the 'shutdown option in the finder'. Interesting to see if this is the Apple menu. Worth a shot

  • How can I prevent a macbook from syncing with my ical alerts.

    I was attempting to share a photo stream from my ipod touch with a friend. At one point when I was trying to figure out how she could access it, I believe I entered my apple ID on her macbook to connect to the icloud.  She is now receiving alerts from my calendar.  How can we stop that?  What does she need to do on her end to disconnect?  Thanks.

    If you go to Settings>General>Restrictions>Accounts (near the bottom) and set it to Don't Allow Changes it will disable the ability to change any of the iCloud settings, or settings for other accounts including email accounts, FaceTime, FaceBook, Twitter, the iTunes & App store ID, etc.  That would be your only option.  Also, as you may know, if you set restrictions make sure you write down the passcode; if you ever forget it you will need to restore the device as new, without using an backup (or restore a backup made before the restrictions passcode was set), in order to remove it.

  • How to prevent PowerPoint 2013 from mucking with my laptop display mode?

    I have an EliteBook 8570p in a docking station, with an external monitor and keyboard attached.
    I typically have my display mode as "duplicate", with the same thing  showing on both my laptop screen and external monitor.  I use the external monitor as the main screen. This might be uncommon, but I prefer it this way.  I've
    been working this way for quite a while.
    I very recently started using MS PowerPoint 2013.  Today I discovered an annoying bug (feature?) with this combination.  I was in "slideshow mode" for a pptx I was working on, and I pressed ESC to get back to editing the doc.  What
    happened was that the external monitor just showed my background wallpaper, and the laptop screen showed the normal display, along with my background wallpaper.  I then had to slide over to my laptop keyboard and press Fn-F4 and set it to "Duplicate",
    and that restored my external monitor display.
    I don't like this behavior.  I also noticed that when I go into slideshow mode, the display on the laptop screen is different from what I see on the external monitor. It looks like it's showing an "intelligent" view of the slideshow, with
    a big panel showing the current page, and the next page in a smaller panel. That's interesting, but I don't want it to do that if I'm in "Duplicate" display mode.
    Is there a way to get the "older" behavior from PowerPoint 2013?

    Thanks Milan for the explanation.
    And the mentioned option can be found by going to the "SLID SHOW" tab>"Monitors" section on the ribbon in PowerPoint 2013.
    Regards,
    Ethan Hua
    TechNet Community Support
    It's recommended to download and install
    Configuration Analyzer Tool (OffCAT), which is developed by Microsoft Support teams. Once the tool is installed, you can run it at any time to scan for hundreds of known issues in Office
    programs.

  • I WANT TO PREVENT CERTAIN SITE FROM AUTOMATICALLY OPENING

    Certain web site and pop-up windows keep opening: the web site open on a new page. Te do this without my request or consent. How can I stop them doing this - I know the web sites' addresses?

    When does this happen?
    You can check for recently installed suspicious or unknown extensions.
    *https://support.mozilla.org/kb/Troubleshooting+extensions+and+themes
    *https://itunes.apple.com/us/app/bitdefender-virus-scanner/id500154009?mt=12
    *http://www.clamxav.com/download.php

  • Any way to prevent purchased items from syncing with iPhone music?

    My kids buy a ton of crap music. I have configured my iPhone to only sync selected artists, playlists, and albums. But the purchased crap still shows up and I have to navigate through them.
    Is there a setting where I can filter these out from the sync process?

    By purchased crap you mean this music on your iPhone includes an iCloud icon?
    If so, on your iPhone go to Settings > Music > Show All Music > Off.

  • When trying to update using help in LR from "Help" menue  a dialogue box appears saying not possible as it does not have a programme associated with it

    When trying to download latest version of software fro "Help" menue. a box appears saying there isn't a programme associated with so the action cannot be completed. please install a programme in the Default Programmes Control panel.

    Hello jaybearden,
    Thanks for the question. After reviewing your post, it sounds like you are not able to restore the iOS device since you get an error 9. I would recommend that you read this article, it may be able to help the issue.
    Resolve iOS update and restore errors - Apple Support
    Check your security software
    Related errors: 2, 4, 6, 9, 1000, 1611, 9006. Sometimes security software can prevent your device from communicating with either the Apple update server or with your device.
    Check your security software and settings to make sure that they aren't preventing a connection to the Apple servers.
    Thanks for using Apple Support Communities.
    Have a nice day,
    Mario

Maybe you are looking for

  • My iPod Nightmare (won't restore in itunes 7)

    My iPod Nightmare My specs: Windows XP Service Pack 2 (fully updated) iTunes 7.0 iPod Video 60GB 5th Generation Problems started about a month ago. At first, I stopped being able to eject the iPod, from iTunes or from Windows directly. This lasted fo

  • Session not being clean up by JRun

    My application is using IPlanet WebServer and JRun3.02 Application server. I am having a problem with active session not getting cleaned up by the App Server. When the user goes through the application and finishes the process, I invalidate the sessi

  • When useing av cable to a projector, I want the sound to come out headphone jack.

    I am using the av cable to connect the video out to a projector and the headphone jack to speackers. If I unplug the av cable the headphone jack provides sound to speakers and  I have volume slider under the play button. When I plug in the av cable t

  • Running JSP applications on Oracle iAS (release 1.0.0.0.0) on HP unix

    Does anyone know how to run JSP applications on iAS (1.0.0.0.0) on Unix ? I want to know where to put all the .jsp, .jar, .class, .gif, .html files and how to configure ? If someone knows of any document on Metalink please pass me the doc id asap. Th

  • F340 scanner unavailable dis improper disconnect

    I was using Preview to scan. A scan completed and I walked off with the computer unplugging the USB cable. I Saved the scan and went back to scan another image. But I got the Scanner Unavailable message. I have:       unpluggged the printer from the