Problem Wlan Controller 5508

Friends,
I have a problem authenticate with AP AIR-LAP1131AG-AK9 to Wlan Controller 5508 (software versión of the Wlan Controller6.0.202.0 ). This AP always tries to authenticate with Wlan Controller. Maybe it tries to download the ios version.
Could be a hardware problem.
I am going to attach the log file.
Thank.
Marco.

*Nov 23 20:28:50.348: %APF-3-AID_UPDATE_FAILED: apf_80211.c:5744 Error updating Association ID for REAP AP Client64:00:f1:12:b1:d0 - AID 4
*Nov 23 20:28:50.348: %LWAPP-3-MAX_AID2: spam_api.c:1045 Reached max limit on the association ID for AP (max association ID 256)
Looks like a great case for TAC.
This is an HREAP AP?   It looks like it is associated fine with the WLC (no logs indicating it is trying) but instead it looks like Client Associations are breaking because it thinks it is up to 256 AIDs.....?
Maybe this is a common error, but it hasn't cross my path before...

Similar Messages

  • WLAN Controller 5508 - Latest IOS (april/2013)

    Dears,
    Can somebody confirm please what is the latest IOS version for the Wlan Controller 5508 ?
    Actually I am using
    Software Version
    7.3.102.0
    I see the folliwing at Cisco website
    Latest Releases
    7.2.115.1(ED)7.3.112.0(ED)
    7.0.240.0(ED)
    7.4.100.0(ED)
    Version 7.2.115 seems to be the latest one (release date 19-APR-2013)... then I see 7.3.112.0 w/ release date 30-JAN-2013...
    I thought the IOS 7.4.100 would be the latest one but that release date is 17-DEC-2012
    Thats very wierd coz my controller uses a 7.3.102.0.....
    Can someone help me ?
    What IOS is really the latest one ?
    What should be the best one for me ?
    Software Version
    7.3.102.0
    Field Recovery Image Version
    System Name
    XXX-XXXX-XXX
    Thanks in advance!!!

    Lets make it simple. There are different trains. 7.0 is one, 7.2 is another, 7.3 is another and 7.4 is another. So if your on 7.2.x, the latest for that version is the .x. Each one listed above is different as far as features so you need to look at the latest for train that your on.
    Sent from Cisco Technical Support iPhone App

  • Problem WLAN controller 4400

    There is a WLAN controller 4400 which controls the access points. There is a collapse of all access points from 00:00 to 00:12.
    The link is working properly, no problems with the AC, the point is not restarted.
    Logging
    1.  May 24 2010 00:01:08 CAPWAP 3 ECHO_ERR capwap_ac_sm.c:5116 Did not receive heartbeat reply; AP: 00:3a:98:5e:f7:80 *
    2.  May 24 2010 00:02:38 CAPWAP 3 ECHO_ERR capwap_ac_sm.c:5116 Did not receive heartbeat reply; AP: 00:26:ca:b7:ce:30 *
    3.  May 24 2010 00:02:49 DOT1X 3 ABORT_AUTH 1x_bauth_sm.c:447 Authentication aborted for client 00:15:70:f1:e4:b4 *
    4.  May 24 2010 00:03:07 APF 3 INVALID_RADIO_TYPE apf_api.c:27324 Invalid radio type 255 received. *
    5.  May 24 2010 00:06:50 APF 3 INVALID_RADIO_TYPE apf_api.c:27324 Invalid radio type 255 received. *
    6.  May 24 2010 00:06:50 APF 3 INVALID_RADIO_TYPE apf_api.c:27337 Invalid radio type 255 received. *
    7.  May 24 2010 00:06:50 APF 3 INVALID_RADIO_TYPE apf_api.c:27324 Invalid radio type 255 received. *
    8.  May 24 2010 00:06:50 APF 3 INVALID_RADIO_TYPE apf_api.c:27337 Invalid radio type 255 received. *
    9.  May 24 2010 00:07:03 APF 3 INVALID_RADIO_TYPE apf_api.c:27324 Invalid radio type 255 received. *
    10.  May 24 2010 00:07:03 APF 3 INVALID_RADIO_TYPE apf_api.c:27337 Invalid radio type 255 received. *
    11.  May 24 2010 00:07:10 APF 3 INVALID_RADIO_TYPE apf_api.c:27324 Invalid radio type 255 received. *
    12.  May 24 2010 00:07:10 APF 3 INVALID_RADIO_TYPE apf_api.c:27337 Invalid radio type 255 received.

    If your WLC firmware is 5.X then I would like to recommend you upgrade to 6.X.

  • AIR-LAP1310G-E-K9 acces point not joining to 5508 wlan controller

    Hi,
    I have Cisco AIR-LAP1310G-E-K9 access point and 5508 wlan controller with version 7.0.220 and it is joining to the WLAN controller.  I have enabled dhcp in the lan controller and i dont have external dns server. How to fix this issue?  Can this LAN controller version will support this access point? 
    My Lan Controller Management IP Address is 10.10.10.5
    Please find the below configuration of 1300 access point.
    AP001d.4513.dd68#reload
    Proceed with reload? [confirm]
    %SYS-5-RELOAD: Reload requested by console. Reload Reason: Reload Command.
    %LWAPP-5-CHANGED: LWAPP changed state to DOWNXmodem file system is available.
    flashfs[0]: 4 files, 2 directories
    flashfs[0]: 0 orphaned files, 0 orphaned directories
    flashfs[0]: Total bytes: 7741440
    flashfs[0]: Bytes used: 2052608
    flashfs[0]: Bytes available: 5688832
    flashfs[0]: flashfs fsck took 14 seconds.
    Base ethernet MAC Address: 00:1d:45:13:dd:68
    Initializing ethernet port 0...
    Reset ethernet port 0...
    Reset done!
    ethernet link up, 100 mbps, full-duplex
    Ethernet port 0 initialized: link is up
    Unable to get our ip address: no "IP_ADDR" variable set
    The system has been encountered and error initializing
    tftp file system. The system is ignoring the error and
    continuing boot. If you interrupt the system boot process,
    the following commands will set IP_ADDR, DEFAULT_ROUTER
    and NETMASK environment variables, initializing tftp file
    system, and finish loading the operating system software:
        set IP_ADDR
        set DEFAULT_ROUTER
        set NETMASK
        tftp_init
        boot
    Loading "flash:/c1310-rcvk9w8-mx/c1310-rcvk9w8-mx"...############################################################################################################################################################################################
    File "flash:/c1310-rcvk9w8-mx/c1310-rcvk9w8-mx" uncompressed and installed, entry point: 0x3000
    executing...
                  Restricted Rights Legend
    Use, duplication, or disclosure by the Government is
    subject to restrictions as set forth in subparagraph
    (c) of the Commercial Computer Software - Restricted
    Rights clause at FAR sec. 52.227-19 and subparagraph
    (c) (1) (ii) of the Rights in Technical Data and Computer
    Software clause at DFARS sec. 252.227-7013.
               cisco Systems, Inc.
               170 West Tasman Drive
               San Jose, California 95134-1706
    Cisco IOS Software, C1310 Software (C1310-RCVK9W8-M), Version 12.4(10b)JA3, RELEASE SOFTWARE (fc1)
    Technical Support: http://www.cisco.com/techsupport
    Copyright (c) 1986-2008 by Cisco Systems, Inc.
    Compiled Wed 19-Mar-08 19:09 by prod_rel_team
    Image text-base: 0x00003000, data-base: 0x003BE9E0
    Initializing flashfs...
    flashfs[1]: 4 files, 2 directories
    flashfs[1]: 0 orphaned files, 0 orphaned directories
    flashfs[1]: Total bytes: 7741440
    flashfs[1]: Bytes used: 2052608
    flashfs[1]: Bytes available: 5688832
    flashfs[1]: flashfs fsck took 2 seconds.
    flashfs[1]: Initialization complete....done Initializing flashfs.
    This product contains cryptographic features and is subject to United
    States and local country laws governing import, export, transfer and
    use. Delivery of Cisco cryptographic products does not imply
    third-party authority to import, export, distribute or use encryption.
    Importers, exporters, distributors and users are responsible for
    compliance with U.S. and local country laws. By using this product you
    agree to comply with applicable laws and regulations. If you are unable
    to comply with U.S. and local laws, return this product immediately.
    A summary of U.S. laws governing Cisco cryptographic products may be found at:
    http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
    If you require further assistance please contact us by sending email to
    [email protected].
    cisco AIR-LAP1310G-E-K9R   (PowerPCElvis) processor (revision A0) with 24566K/8192K bytes of memory.
    Processor board ID FHK1133E002
    PowerPCElvis CPU at 262Mhz, revision number 0x0950
    Last reset from reload
    LWAPP image version 3.0.51.0
    1 FastEthernet interface
    32K bytes of flash-simulated non-volatile configuration memory.
    Base ethernet MAC Address: 00:1D:45:13:DD:68
    Part Number                          : 73-8960-09
    PCA Assembly Number                  : 800-24963-06
    PCA Revision Number                  : A0
    PCB Serial Number                    : FOC113000V7
    Top Assembly Part Number             : 800-28479-05
    Top Assembly Serial Number           : FHK1133E002
    Top Revision Number                  : B0
    Product/Model Number                 : AIR-LAP1310G-E-K9R
    The name for the keys will be: ap.cisco.com
    % The key modulus size is 1024 bits
    % Generating 1024 bit RSA keys, keys will be non-exportable...[OK]
    ip ssh version 2
        ^
    % Invalid input detected at '^' marker.
    transport input ssh
                     ^
    % Invalid input detected at '^' marker.
    aaa new-model
    ^
    % Invalid input detected at '^' marker.
    aaa authentication login default enable local none
    ^
    % Invalid input detected at '^' marker.
    o
    ^
    % Invalid input detected at '^' marker.
    Press RETURN to get started!
    *Mar  1 00:00:05.442: %LINK-3-UPDOWN: Interface FastEthernet0, changed state to up
    *Mar  1 00:00:06.473: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0, changed state to up
    *Mar  1 00:00:07.817: %SYS-5-RESTART: System restarted --
    Cisco IOS Software, C1310 Software (C1310-RCVK9W8-M), Version 12.4(10b)JA3, RELEASE SOFTWARE (fc1)
    Technical Support: http://www.cisco.com/techsupport
    Copyright (c) 1986-2008 by Cisco Systems, Inc.
    Compiled Wed 19-Mar-08 19:09 by prod_rel_team
    Translating "CISCO-LWAPP-CONTROLLER"...domain server (255.255.255.255)
    transport input ssh
                     ^
    % Invalid input detected at '^' marker.
    *Mar  1 00:00:33.860: %LWAPP-3-CLIENTEVENTLOG: Performing DNS resolution for CISCO-LWAPP-CONTROLLER
    *Mar  1 00:00:33.860: %LWAPP-3-CLIENTERRORLOG: DNS Name Lookup: could not resolve CISCO-LWAPP-CONTROLLER
    *Mar  1 00:00:33.861: %LWAPP-5-CHANGED: LWAPP changed state to DISCOVERY
    logging origin-id string AP:001d.4513.dd68
             ^
    % Invalid input detected at '^' marker.
    logging 255.255.255.255
            ^
    % Invalid input detected at '^' marker.
    logging trap 3
            ^
    % Invalid input detected at '^' marker.
    *Mar  1 00:00:37.440: Logging LWAPP message to 255.255.255.255.
    AP001d.4513.dd68>
    %LWAPP-3-CLIENTEVENTLOG: Forcing AP to obtain IP address using DHCP
    %DHCP-6-ADDRESS_ASSIGN: Interface FastEthernet0 assigned DHCP address 10.10.10.46, mask 255.255.255.0, hostname AP001d.4513.dd68
    Translating "CISCO-LWAPP-CONTROLLER.CISCO-LWAPP-CONTROLLER.mydomain.com"...domain server (10.10.10.5)
    %LWAPP-3-CLIENTEVENTLOG: Did not get vendor specific options from DHCP.
    %LWAPP-3-CLIENTEVENTLOG: Did not get log server settings from DHCP.
    %LWAPP-3-CLIENTEVENTLOG: Performing DNS resolution for CISCO-LWAPP-CONTROLLER.CISCO-LWAPP-CONTROLLER.mydomain.com
    %LWAPP-3-CLIENTERRORLOG: DNS Name Lookup: could not resolve CISCO-LWAPP-CONTROLLER.CISCO-LWAPP-CONTROLLER.mydomain.com
    AP001d.4513.dd68>

    Your debug is very telling ..
    AP001d.4513.dd68>
    %LWAPP-3-CLIENTEVENTLOG: Forcing AP to obtain IP address using DHCP
    %DHCP-6-ADDRESS_ASSIGN: Interface FastEthernet0 assigned DHCP address 10.10.10.46, mask 255.255.255.0, hostname AP001d.4513.dd68
    Translating "CISCO-LWAPP-CONTROLLER.CISCO-LWAPP-CONTROLLER.mydomain.com"...domain server (10.10.10.5)
    %LWAPP-3-CLIENTEVENTLOG: Did not get vendor specific options from DHCP.
    %LWAPP-3-CLIENTEVENTLOG: Did not get log server settings from DHCP.
    %LWAPP-3-CLIENTEVENTLOG: Performing DNS resolution for CISCO-LWAPP-CONTROLLER.CISCO-LWAPP-CONTROLLER.mydomain.com
    %LWAPP-3-CLIENTERRORLOG: DNS Name Lookup: could not resolve CISCO-LWAPP-CONTROLLER.CISCO-LWAPP-CONTROLLER.mydomain.com
    AP001d.4513.dd68>
    What are you using to tell the AP where the contoller lives ? Since you are consoled into the ap you can use the -> capwap ap controller ip address
    This will point the ap to your controller
    "Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
    ‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."

  • 1510 Mesh A.P with 5508 WLAN Controller

    Hi everyone,
    I got a situation. We had our wireless mesh network running with 4400 Controller and 1510 A.Ps. Now that we have bought new 5508 Controller (with SW: 7.2) and 3600 Indoor APs, we are unable to add legacy APs on our new controller. After a wild googling I have found that for 1510 APs i need to be on SW ver: 4.0. But that will lead into another situation i-e I wont be able to have my 3600 APs on WLAN Controller.
    Any suggessions/wise words will be very very obliged....
    Thanks,
    Azhar...

    You would have to keep those 440's up and have all the WLC in the same mobility group. That is the only way to keep those 1510's up and running. Cusco usually supports mobility between different version but only really as far back as 2 versions. Might work though.
    Here is a compatibility guide that explains what devices work with what code.
    http://www.cisco.com/en/US/docs/wireless/controller/5500/tech_notes/Wireless_Software_Compatibility_Matrix.html
    Sent from Cisco Technical Support iPhone App

  • Cisco LWAP & WLAN Controller Flexconnect Across HP Switches

    Hello All, I'm looking for a little guidance in making the needed routing and switching configuration changes on our Corporate Network to accomadate flex connect functionality for Cisco Lightweight Access Points (LWAPs).  The LWAPs that are currently configured on our network only work when our WLAN Controller is up and running and I need for them to be disconnectable so that we can move the WLAN Controller to our virtual co-lo.  It should be known that I inhereted this network from the previous admin and have been working hard to map everything out to the best of my ability.  Also, the WLAN controller is already operating in our production network so it limits my ability to do much testing. 
    Just FYI, I'm a new Systems Admin promoted from a Desktop Support role and have my CCENT (Currently working on CCNA & MCITP Server Admin) so I have some knowledge but it is limited on the networking and switching side of things.  Unfortunately, the Senior Systems Admin has even less knowledge of networking than me and I don't really have anyone to turn to which is why I'm posting here.  I would have utilized GNS to help me simulate the configuration however there are HP switches in the mix and no means of emulating them.
    -Relevant Device List-
    (CONSA251) Sonicwall  NSA 240 - 10.1.1.251
      Interface Information 
    Interface    IP Address    Description   
    X0  ->  LAN
      10.1.1.251   LAN Interface  
    X1  ->  WAN
      *************   Time Warner WAN  
    X2  ->  DMZ
      *************   DMZ Interface  
    X3  ->  WAN
      *************   Sprint WAN  
    X0-V20  ->  LAN
      10.1.101.1   Corporate WLAN  
    X0-V30  ->  LAN
      192.168.1.1   Guest WLAN 
    (CORT250) Cisco 3845 - 10.1.1.250
    (CO-WLAN-CTRLER) Cisco 5508 Wireless Controller - 10.1.1.2
    (COSW240) HP Procurve 4108GL - 10.1.1.240
    (COSW238) HP Procurve 2510B-24 - 10.1.20.238
    (CORP-AP-MIS) AIR-LAP1131AG-A-K9 - 10.1.1.79
    (COSW239) HP1810G-24 - No IP (Inaccesible but being replaced)
    I will now go on to explain our network topology as it pertains to the WAPs and WLAN Controller and how I believe it needs to be configured in order to operate from my perspective. 
    Our Corporate and Guest Wireless Access is provided via the Sonicwall CONSA251 through a connection from the X0 interface to HP Switch COSW239 which is then connected to WLAN Controller CO-WLAN-CTRLER as detailed below:
    Device - Interface Name/Port
    CONSA251 - X0
    COSW239  - 2
    COSW239  - 18,19
    CO-WLAN-CTRLER - 2,3
    The WLAN Controller currently communicates with all the LWAPs via Layer 3 TCP\IP as I understand it and then routes all DHCP requests and traffic destine for the 10.1.101.1 (corporate WLAN) and 192.168.1.1 (Guest WLAN) to the Sonicwall and vice versa.
    Now what I am trying to do is VLAN the LWAP CORP-AP-MIS across the HP Switches to the X0 interface on the Sonicwall NSA240 where it will be able to route traffic via VLAN 20 & 30.  The problem lies in my inexperience with HP VLAN configurations and how the ports need to be configured on each device so it can route traffic to the Sonicwall when the WLAN Controller is shutdown.
    The LWAP CORP-AP-MIS layer 2 trace to the WLAN Controller is as shown below:
    Device - Interface Name/Port
    CORP-AP-MIS -  FA/0
    COSW238     - 16
    COSW238     - 25
    COSW240     - B4
    COSW240     - H6
    CORT250     - GigabitEthernet0/0
    CORT250     - Se1/0
    CONSA251    - X0
    Now for all intesive purposes the Corporate Router CORT250 should probably be handling the routing for our Corporate and Guest Wireless network however that was not the way it was originally setup and I have to work with what was inhereted.  The Corporate Router CORT250 has a default route to the Sonicwall and the Sonicwall CONSA251 has all the routing already in place for the Corporate & Guest WLANs.
    What I would like to do is VLAN off the X0-V20&V30 accross multiple switches and switchports to each LWAP in our building.  I do have the LWAP I'm testing on configured with Flex Connect which I understand is required for it to be disconnectable.
    Any guidance on how I would go about configuring this accross devices would be appreciated.  I know there are some difference between HP and Cisco Switching terms and how tagging, untagging, and trunking works however I lack the experience to apply this in practice especially in a production environment. 
    I will be happy to provide any additional information or clarification that is needed.  Thank you in advance for the help.

    Just to add about the ISE... you can profile, but having only one ssid might or might not work in your situation.  Also if you end up with remote sites or ap's in h-reap mode, currently ISE cant do any profiling.  If you go with the 7500 or 5508/WiSM2, they don't really do an active-active or active backup. They are both up and you can split the load or put all ap's on one, its up to you.  I usually split the load just to make sure both are working.  I don't want to all of a sudden loose the primary and then find out my secondary/backup is not working.

  • Multiple Wireless Controller 5508 in WCS 7.0

    I have two Wireless Controller 5508 that are IDENTICAL in configurations and they will work as an ACTIVE/STANDBY scenario because right now we only have 30 APs, which one of the controller should be fine dealing with them...
    Now, the way we used to work was everytime we had to add a new WLAN, or change an ACL, etc..we had to both controllers and do the exact same things, so both would be ready in case of a failure of the MAIN controller....so in order to avoid this extra work, we bought the WCS 7.0, thinking we would only have to do it once, and the WCS would update both WLC...but I cant find that option..Ive read all the configuration guide, and cant find a way to keep this two controller completaly sync......I read something about templates..but I still have to do "extra" work in order to keep them sync..
    How do you guys keep your WLC sync??
    THanks!

    Carlos, make sure you also look at config groups. When you place a template into a config group and if you enable the background task for nightly configuration audits you do get a tally of which controllers are "in sync" and which ones are not. Cisco does not automatically apply any configurations from WCS/NCS to controllers, nor would I ever want them to in all honesty.
    NCS is a nice product and has a lot in the roadmap that will hopefully add more value to having your switches loaded. I can see in the future being able to have port templates for voice, data, etc, and then applying those to switch ports at a help desk tech level, they don't need to know how to configure the port, they just need to select a port and then a template.

  • Virtual WLAN Controller Guest Anchor

    We are planning a WLAN upgrade and the security policy is to forward wireless Guest user traffic to the DMZ controllers. We are now considering the Virtual WLAN Controller and all AP's will register with the virtual controllers and we will use Flexconnect for Staff and internal traffic that will switch their traffic onto the local switch.
    We wish to forward the guest traffic to the DMZ Guest Anchor controller which will be a 5508 controller. This will also offer Office Extend AP service.
    I have looked at teh virtual controller docs and not very clear if this deployment model is supported. Below is a diagram of what we wish to deploy and can anyone advise if thsi is a supprted deployment model.

    Well you can use the vWLC to anchor to a 5508, but not the other way around. So if you use the DMZ 5508 for OfficeExtend, you will not be able to anchor the traffic back to the inside. Cisco doesn't support reverse anchoring for a Remote-LAN in OfficeExtend and requires you to actually have the OfficeExtend AP's connect to an inside WLC. In v7.0.x you were able to do this reverse anchor, but it was removed on later codes.
    Sent from Cisco Technical Support iPhone App

  • Single WLAN Controller Limitations

    Aside from redundancy, are there any other limitations to deploying a single Cisco 5508 WLAN Controller that I should be aware of?   The configuration guide states you need multiple controllers for the following:
    A multiple-controller system has the following additional features:
    •Autodetecting and autoconfiguring RF parameters as the controllers are added to the network.
    •Same-subnet (Layer 2) roaming and inter-subnet (Layer 3) roaming.
    •Automatic access point failover to any redundant controller with a reduced
    Is it true you can't have those roaming capabilities with a single controller?

    No... You have all those except for redundancy.
    Sent from my iPhone

  • VoWLAN Roaming without WLAN Controller (WLC)

    Hi,
    Need some advice here. I am trying to implement VoWLAN in a company using Cisco WAP4410n Access Point. The problem is, I've downloaded all Cisco WLAN Controller (WLC) data sheets and can't find any compatible WLAN Controller for this type of Access Point.
    Can I still implement VoWLAN without WLAN Controller? Is there any way to provide smooth intercell roaming without WLAN Controller?
    Thanks
    Regards

    I have designed the cells so they have 20% cells overlap. I've also designed the channels so they won't interfere with each other (I use 2 GHz channel here)
    But what could be used to replace WLC's role to manage these Access Points? maybe some kind of server?

  • WLAN CONTROLLER 2100

    We have have three different locations on three different subnets 172.17.0.0/16, 172.20.0.0/24 and 172.21.0.0/24.
    An MPLS connects all three offices together.
    All three routers are doing DHCP server for their respective LAN
    All internet traffic must pass through 172.17.0.0/16 where I have my sonic wall firewall.
    My aim is to deploy the WLAN controller on the 172.17.0.0/16 network.
    Then plug 1131LAP access points on each of the subnets.
    Access points are able connect to the controller but my challenge is that when a client connects to an any of the APs, dhcp is assigned from the 172.17.0.0/16 LAN irrespective of which location the client is connecting from.
    When I log in to the controller I can see that the APs are assigned ip address from the dhcp server at their location e.g AP at 172.21.0.0/24 gets an ip address of 172.21.0.42/24 from its local router but when a client connects to that same AP the client is given an ip from 172.17.0.0/16 network.

    Thanks Scot. Yes I configured a guest WLAN and allowed tunnel to WLC but I had problem in dealing with access rule configuration.Here is what I did;
    I created a "Guest" interface on physical port number 2,then assigned a completely different IP address of 192.168.0.2
    Create a guest SSID and assigned it to the guest interface.
    On the firewall device (NSA 2400) I configured a second physical interface (GUEST ZONE) 192.168.0.1 and defined a dhcp scope on this interface
    Create access rule that
    Denys traffic from GUEST > LAN and LAN > GUEST
    Allows traffic from GUEST to WAN and WAN to GUEST
    Then connect WLC port 2 to the guest interface port on NSA 2400 device.
    When clients connects to the guest SSID,ip is assigned correctly from the Firewall device.
    From windows connection icon I can that there is access to the Internet but it won't browse
    Also a ping to the WLC interface 192.168.0.2 replies fine but
    Ping to firewall 192.168.0.1 times out continuously.
    Is it possible for me to define acl within the WLC that will block traffic from the guest LAN to our corporate LAN so that I can forget about the access rule within the NSA 2400 .?
    Once again thank you so much your post has being very helpful
    Sent from Cisco Technical Support iPad App

  • WLAN Controller not changing channels

    We have a 2000 wireless controller with 4 1240 access points connected to it. The users would like to run their current non-cisco wireless network until all testing has been completed with the new cisco wireless installation. We have their old wireless on channel 11. It is my understanding that the WLAN Controller should see the old wireless gear and readjust itself so that there no interference. Well the problem is that the Cisco aps that can see the old wireless gear is setting itself with the same channel and not adjusting itself, it basically acts like it doesn't even care that the other wireless network is there. Is there a setting somewhere that I'm missing on the controller?? Any help would be greatly appreciated..

    Is "Avoid non-802.11b noise" also checked?
    On the controller if you go to management->trap logs, do you see any events that mention RF Manager changing channels? How about interference profile failed?
    How about in monitor->rogue APs. Does it see the existing APs there?
    In Wireless->802.11b/g radios, what channels and power levels do you see for your current ones?
    Sorry for so many questions, I haven't see this as an issue before. One thing you could try is setting channel selection to manual and kicking it off. It shouldn't matter, but you never know.
    -Eric

  • Wlan controller option 150

    Hi friend,
    Its posible enable option 150 (for phone) in wlan lan controller 5508, i want to create a DHCP POOL for my Wireless IP PHONE, but i can this option.
    other solución could be to use a DHCP externel ( like router), but the broadcast traffic dont pass from Wlan Controller to Router.
    Could you helpe me please.
    Marco.

    Marco,
         The DHCP server in the WLC is not fully functional.  You can only set the subnet, GW and DNS that the client uses.  You can't set any of the advanced features, like option 150 for the TFTP server.
    Now, under the interface for the phone subnet, what do you have set for the DHCP server?  if you set it to a router/switch/server the WLC will proxy the request to the device.  and the client will get the correct address.
    If you are using a secrity device, this won't work.  You'll need to disable DHCP proxy. 
    From the GUI Controller > Advanced > DHCP, and uncheck the box.
    From the CLI config dhcp proxy disable
    Once this is done, make sure you have the ip helper-address under the L3 interface and point to the DHCP server.
    HTH,
    Steve
    Please remember to rate helpful posts or to mark the question as answered so that it can be found later.

  • WLAN Controller Displays Interface IP in Web Authentication URL Instead of FQDN

    Hi,
    Can someone offer any help with the issue below please?
    I have a guest wlan configured on a Cisco 2106 WLAN controller. Guest users are redirected to a Web Authenticaion page when they try to access the internet through a web browser, and can only proceed by succesfully authenticating with the controller.
    The problem I have is that the guest users are presented with an SSL certficate error before they hit the web authentication page. I have installed an SSL certificate from Verisign on the controller, and have configured an FQDN for the interface that is used for the guest wlan. However, the certificate error still persists because when the user is re-redirected to the web auth page, the URL in the address bar is presented as the IP address of the interface instead of the FQDN, For example, when a user is redirected, the address bar in their web browser displays; https://1.1.1.5/ instead of https://guestwifi.domain.com/ The SSL certificate that is installed on the controller is securing the FQDN of the interface.
    I'm not sure if i'm missing something here, but i'm struggling to find how to get the FQDN to display instead of the IP.
    Thanks,
    Paul

    I'm not following what you mean when you sayd "FQDN for the interface that is used for the guest wlan"......
    I assume you configured the Virtual Interface  to have the dns entry as guestwifi.domain.com but clients are still being redirected to the virtual IP itself and not the dns name? 
    The only reason I can think of for that happening was if the WLC had not been rebooted since applying the DNS name to the Virtual Interface (it takes a reboot to modify client redirect stuff, the same goes for http vs https).
    so guestwifi.domain.com should have a DNS entry resolving to 1.1.1.5, that entry should be on your virtual interface, and upon reboot you should always redirect to guestwifi.domain.com unless you manually type https://1.1.1.5 in the browser.

  • WLAN Controller CDP

    CDP is a layer 2 protocol. Therefore, I have to assume that in a layer 3 routed architecture for a WLAN controller that the CDP information is tunneled back to the controller. What would cause the controller to NOT have accurate CDP information about all of its connected APs, assuming CDP is not globally and/or locally shut down?
    Regards,
    Scott

    Not directly related to your problem, but a good reason to upgrade and move away from 4.2.61.0 is a nasty bug I just ran into. Local account that expire are not removed from the controller's database (so they're still in there but not visible in your management interface nor CLI). Once the database fills up to the maximum configured (512 is the default) you can no longer create local accounts.
    CSCsm17944 :
    WLC does not recognize the expired lifetime of guest user accounts, so
    that the local user database is not cleared and can fill up with
    non-active entries, preventing any other local net users from being created.
    You can check the databse size and fill using the CLI command: Show database summary
    Just my 2 cents.
    Leo

Maybe you are looking for

  • Factory Unlocked Lumia 925 4G Disabled

    I was very excited to finally use LTE with my new Lumia 925 but found out that for some reason there is only an option for 2G or 3G.  The phone was purchased in the US as a GSM (UK) version (carrier version CV GBIE) and I live in Ontario. At the mome

  • How to replace first word after x in every line?

    Hi i have a a script which creates many tables/indexes each with diffrent INITIAL value. I need to grep for word INITIAL and replace the first word after initial ( which is number ) with 50K. how can i do this? some sample entries are INITIAL 2097152

  • CS5 Photoshop dissappears?!

    Hi, Ive started getting a really annoying bug that is driving me insane! Every now and again, usually when I've zoomed right into an image altho not always, my screen will go blank for a few seconds and when it returns Photoshop has dissappeared!! It

  • New MAC user, old Picasa user - need help!

    recently purchased my IMAC - and while I have loved it - I haven't loved used iphoto.  I'm an old picasa user and when I copied all of my picasa fotos in iphoto - while the pictures transfers all the names and dates of the folders that the pictures w

  • Errors 5006 and 1084

    hey, I'm getting errors 5006 and 1084 for my script, currently I'm making a game of brick breaker and can't figure out why I'm getting these errors. I get the 1084 error when auto formatting, and I get the 5006 error when exporting to a SWF my code i