SAP 1602 Wireless bridge issue. Non root bridge loses it's configuration

Hi guys,
Today I tried to configure wireless link between two autonomous AP 1602 APs.
There is a problem with Non-root bridge. I configured it with this command:
AP2(config-if)#station-role non-root wireless-clients
Non-root bridge successfully joins the root bridge (root AP). Anyway, this configuration does not work, if I reload my non-root bridge. Even without reload, If I check my non-root bridge configuration it looks like this:
interface Dot11Radio1
no ip address
no ip route-cache
encryption vlan 1 mode ciphers aes-ccm
ssid WiFi-Bridge
antenna gain 0
stbc
beamform ofdm
Command "station-role non-root wireless-clients" is missing here. But I just configured it few seconds ago... Does anyone know, where could be a problem?

Okay... Everything works with OPEN ssid. Not with my WPA 2 configuration.
On both APs configuration looks like this:
dot11 ssid Private
   vlan 10
   authentication open
   authentication key-management wpa version 2
   guest-mode
   wpa-psk ascii 7 01100F175804575D72
interface Dot11Radio0
encryption vlan 10 mode ciphers aes-ccm
ssid Private
infrastructure-client ( on Root AP)
station-role root bridge wireless-clients ( on Root AP)
Few debugs:
*Mar  2 09:57:30.554: %DOT11-6-ASSOC: Interface Dot11Radio0, Station  9c02.986d.9675 Reassociated KEY_MGMT[WPAv2 PSK]
*Mar  2 09:57:30.938: dot11_auth_client_abort: Received abort request for client 9c02.986d.9675
*Mar  2 09:57:30.938: dot11_auth_client_abort: No client entry to abort: 9c02.986d.9675 for application 0x1
*Mar  2 09:57:30.938: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station 9c02.986d.9675 Reason: Sending station has left the BSS
*Mar  2 09:57:30.986: %DOT11-6-ASSOC: Interface Dot11Radio0, Station  9c02.986d.9675 Reassociated KEY_MGMT[WPAv2 PSK]
*Mar  2 09:57:31.350: dot11_auth_client_abort: Received abort request for client 9c02.986d.9675
*Mar  2 09:57:31.350: dot11_auth_client_abort: No client entry to abort: 9c02.986d.9675 for application 0x1
*Mar  2 09:57:31.350: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station 9c02.986d.9675 Reason: Sending station has left the BSS
*Mar  2 09:57:31.398: %DOT11-6-ASSOC: Interface Dot11Radio0, Station  9c02.986d.9675 Reassociated KEY_MGMT[WPAv2 PSK]
*Mar  2 09:57:31.766: dot11_auth_client_abort: Received abort request for client 9c02.986d.9675
Everything works with android device and WPA2 if I change configuration to this:
dot11 ssid Private
   vlan 10
   authentication open
   authentication key-management wpa version 2
   mbssid guest-mode
   wpa-psk ascii 7 01100F175804575D72
interface Dot11Radio0
encryption vlan 10 mode ciphers aes-ccm
ssid Private
station-role root
mbssid

Similar Messages

  • Root-Bridge and Non-Root Bridge Support

    I was wondering if the ISR Routers (Cisco 1811w) support the root-bridge and non-root-bridge feature. If not is there another device apart from the 1310 and 1410 bridges that support this feature?
    Thank You,
    VT

    Hi VT,
    The ISR AP supports both of these roles;
    Access Point Link Role Flexibility
    Access Point Link Role Flexibility allows access point radios to operate in a combination of radio roles,
    such as access point root, bridge root (with or without clients), bridge nonroot (with or without clients).
    This provides a more flexible deployment scheme to support the various applications requirement. Note
    that the ISR AP does not support access point repeater and WGB.
    Wireless Non-Root Bridge
    The wireless non-root bridge allows the access point radio to operate as the remote node in a point to
    point or point to multi-point network.
    Wireless Root Bridge
    The wireless root bridge role provides support for both point-to-point or point to multi-point bridging.
    http://www.cisco.com/en/US/docs/ios/12_4/12_4x/release/notes/rn1800xj.html
    Hope this helps!
    Rob

  • 1300 Root-Bridge and Non-Root Bridge setup

    I have two 1300s that I am trying to set up as Root Bridge and Non-Root Bridge, however, everytime i specify one of them as a Non-Root bridge, the radio0 interface becomes disabled. The only option that i am able to pick that enables the radio0 interface is "Access Point", which is what am trying to avoid it being.
    Can anybody help me figure out how to go about this

    A non-root's radio will show as disabled if it cannot find the root AP to associate to. Make sure you have "infrastructure-ssid" configured under the SSID on both the root and non-root bridges. Also depending on code versions you may have to configure the distance command under the radio interface on the root.

  • 1310 Root Bridge will not Authenticate with 350 Non Root Bridge

    I've exhausted myself solving this issue.
    I have a 1310 set as a root bridge using WEPS. I have a 350 set as a non root bridge/without clients, also using WEPS (they both use the same SSID)
    The 350 will not authenticate to the 1310. After doing a Carrier Busy Test, it is clear the 350 see's the 1310 with signal strengh of 100 percent.
    (I have a test lab setup in my office)
    If I make the 350 the Root Bridge and the 1310 the Non Root, The 1310 will authenticate to the 350.
    I hoping someone else has seen this problem and can enlighten me.
    Thank you.

    I have successfully configured a 1310 Bridge as a Root Bridge and a BR350 Bridge and a Non Root Bridge/with Clients. I also had to force the 1310 to operate at 11MB only.
    As soon as I make the BR350 Bridge a Non Root Bridge/without Clients, the authentication is dropped between the two.
    I was hoping I could transition to the 1310 one unit at a time since I have over a dozen 350's to replace.

  • Wireless Root Bridge - Non Root Bridge

    I've been reading a lot about bridge configuration for wireless AP but i cannot make it work the following scenario:
    PC -- ethernet port --> Non-Root-Bridge -----------> Root Bridge ---------> Switch
    vlan111                     native 18 - vlan111           native 18 - vlan111      vlan native 18,111
    Its pinging fine between switch and Non-Root. But when i put vlan111 on Non-Root the two AP's stop responding to the network.
    What am i doing wrong? Plz i need some help!! I have two 1242.
    ------------------------ Root Config ----------------------
    dot11 syslog
    dot11 vlan-name JGS111 vlan 111
    dot11 vlan-name JGS18 vlan 18
    dot11 ssid WGB
       vlan 18
       authentication open
       guest-mode
       infrastructure-ssid
    username Cisco password 7 047802150C2E
    bridge irb
    interface Dot11Radio0
    no ip address
    no ip route-cache
    ssid WGB
    station-role root bridge
    infrastructure-client
    interface Dot11Radio0.18
    encapsulation dot1Q 18 native
    no ip route-cache
    bridge-group 1
    bridge-group 1 spanning-disabled
    interface Dot11Radio0.111
    encapsulation dot1Q 111
    no ip route-cache
    bridge-group 111
    bridge-group 111 spanning-disabled
    interface Dot11Radio1
    no ip address
    no ip route-cache
    shutdown
    dfs band 3 block
    channel dfs
    station-role root
    bridge-group 1
    bridge-group 1 subscriber-loop-control
    bridge-group 1 block-unknown-source
    no bridge-group 1 source-learning
    no bridge-group 1 unicast-flooding
    bridge-group 1 spanning-disabled
    interface FastEthernet0
    no ip address
    no ip route-cache
    duplex auto
    speed auto
    interface FastEthernet0.18
    encapsulation dot1Q 18 native
    no ip route-cache
    bridge-group 1
    bridge-group 1 spanning-disabled
    interface FastEthernet0.111
    encapsulation dot1Q 111
    no ip route-cache
    bridge-group 111
    bridge-group 111 spanning-disabled
    interface BVI1
    ip address 10.1.8.50 255.255.255.0
    no ip route-cache
    ip default-gateway 10.1.8.254
    ip http server
    no ip http secure-server
    ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
    bridge 1 route ip
    ------------- Non-Root-Bridge -------------
    ot11 syslog
    dot11 vlan-name JGS111 vlan 111
    dot11 vlan-name JGS18 vlan 18
    dot11 ssid WGB
       vlan 18
       authentication open
       guest-mode
       infrastructure-ssid
    username Cisco password 7 14341B180F0B
    bridge irb
    interface Dot11Radio0
    no ip address
    no ip route-cache
    ssid WGB
    station-role non-root bridge
    infrastructure-client
    interface Dot11Radio0.18
    encapsulation dot1Q 18 native
    no ip route-cache
    bridge-group 1
    bridge-group 1 spanning-disabled
    interface Dot11Radio0.111
    encapsulation dot1Q 111
    no ip route-cache
    bridge-group 111
    bridge-group 111 spanning-disabled
    interface Dot11Radio1
    no ip address
    no ip route-cache
    shutdown
    dfs band 3 block
    channel dfs
    station-role root
    bridge-group 1
    bridge-group 1 subscriber-loop-control
    bridge-group 1 block-unknown-source
    no bridge-group 1 source-learning
    no bridge-group 1 unicast-flooding
    bridge-group 1 spanning-disabled
    interface FastEthernet0
    no ip address
    no ip route-cache
    duplex auto
    speed auto
    interface FastEthernet0.18
    encapsulation dot1Q 18 native
    no ip route-cache
    bridge-group 1
    bridge-group 1 spanning-disabled
    interface FastEthernet0.111
    encapsulation dot1Q 111
    no ip route-cache
    bridge-group 111
    bridge-group 111 spanning-disabled
    interface BVI1
    ip address 10.1.8.51 255.255.255.0
    no ip route-cache
    ip default-gateway 10.1.8.254
    ip http server
    no ip http secure-server
    ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
    bridge 1 route ip

    Try this:
    interface Dot11Radio0.18
    encapsulation dot1Q 18 native
    no ip route-cache
    bridge-group 1
    bridge-group 1 subscriber-loop-control
    bridge-group 1 block-unknown-source
    no bridge-group 1 source-learning
    no bridge-group 1 unicast-flooding
    bridge-group 1 spanning-disabled
    interface Dot11Radio0.111
    encapsulation dot1Q 111
    no ip route-cache
    bridge-group 111
    bridge-group 111 subscriber-loop-control
    bridge-group 111 block-unknown-source
    no bridge-group 111 source-learning
    no bridge-group 111 unicast-flooding
    bridge-group 111 spanning-disabled
    interface FastEthernet0.18
    encapsulation dot1Q 10 native
    no ip route-cache
    bridge-group 1
    no bridge-group 1 source-learning
    bridge-group 1 spanning-disabled
    interface FastEthernet0.111
    encapsulation dot1Q 111
    no ip route-cache
    bridge-group 111
    no bridge-group 111 source-learning
    bridge-group 111 spanning-disabled
    Make sure your switchort is setup similar
    interface GigabitEthernet0/7
    description 1242 AP Bridge
    switchport trunk encapsulation dot1q
    switchport trunk native vlan 18
    switchport trunk allowed vlans 18,111
    switchport mode trunk
    Thanks,
    Scott
    Help out other by using the rating system and marking answered questions as "Answered"

  • Root Bridge vs. Non-Root Bridge

    Hi,
    I want to understand the Root Bridge vs. the Non-Root Bidge when using Autonomous 1131 AP's on the same /24 network. Does that command matter in Autonomous? I have many devices working without issues on the same /24 network and all have the Root Bridge set,
    Clearly confused...
    Thanks,

    The command is used on point to point links deployments
    A non root bridge becomes a client and connect to another ap in order to do wireless bridging.
    Sent from Cisco Technical Support iPhone App

  • Cannot Associate 1532 Bridges in Non-Root role

    Hello,
    Can someone please tell me what I am missing and why I cannot bring up 2 bridges in "Root" and "Non-Root" roles?
    I have similarly configured bridges in a Root / Non-Root role several times before with older AP's and never had any issues... although it was always just 1 SSID, 1 Vlan, and no subinterfaces...
    The only way I was able to get these 2 bridges to associate was to put the Non-Root bridge into a Workgroup Bridge role and then *BANG* everything worked perfectly.  I tried getting rid of the authentication and tried using the Parent command but neither helped.  Prior to entering Station Role Workgroup Bridge, the only message I would receive was showing on the Non-Root side and all it said was:
    *Mar  1 07:27:13.867 GMT: %DOT11-4-CANT_ASSOC: Interface Dot11Radio0, cannot associate: No Response
    *Mar  1 07:27:28.891 GMT: %DOT11-4-CANT_ASSOC: Interface Dot11Radio0, cannot associate: Rcvd response from 544a.0005.8030 channel 3 2815
    What am I missing or what have I incorrectly configured on my Non-Root config?
    Bridges are both 1532i with the Autonomous Image 15.2(4)JB5
    Attached are the configs prior to changing the Non-Root AP to a station role of Workgroup Bridge.
    Thanks!

    Hi,
    This should work with multiple sub-interfaces.
    Few more suggestions
    1. Remove this from your BRIDGE SSID & check
    mobility network-id 1
    This is only require when you configure L3 roaming & WDS in place.
    http://www.cisco.com/c/en/us/support/docs/wireless/aironet-1200-series/8103-ap-faq.html
    2. Try to set WPA version 2 & only AES encryption.
    Also try to Associate your Bridges using Open Auth first (as shown in my blog post initial section) & then try to add security.
    HTH
    Rasika
    **** Pls rate all useful responses ****

  • Can one Root Bridge support multiple non-root bridges?

    Hey gang,
    I have a pretty simple question here I think
    I have a wireless bridge currently setup to support a separate office building on our property about 200 yards away from the main building.  The wireless bridge has been working great and was a much cheaper solution when compared to the cost of making a fiber drop to this building.  The needs of our business have changed (go figure), to include a warehouse building also on the backside of the property.  It's not feasible to run a cable between these two building either.  So I need to create another wireless bridge to this back warehouse as well.  My question is can I just use another non-root bridge to link to the root bridge already in place, or does each wireless bridge require one root bridge and one non-root bridge?
    I have good LoS to both buildings from where the current root bridge is, so if two non-root bridges can talk to one root bridge I should be able to just an additional non-root bridge and be good to go.  But if wireless bridges are meant to be a one to one setup, then I'll need to setup an additional root bridge to link to the new non-root bridge?
    It seems like you should be able to have one root bridge link to multiple non-root bridges but I haven't been able to find any clear examples of this being done.
    Thanks in advance for the help!

    That was just too easy.
    I copied the configuration from the working non-root bridge to my laptop.  I changed out the ip address of the BVI interface.  I uploaded the configuration to the new 1300 bridge.  I plugged it in and pointed the yagi antenna in the general direction of the original root bridge and started pinging the new 1300.  Success!
    I'll use my spare 1300 to get service up and running in the warehouse by the end of the week and I'll just need to order one more 1300 to make sure I have spare on hand if needed.
    Thanks again!

  • Non-root bridge association problem

    I have an installation using Cisco 1242 Access Points (IOS) as bridges
    in 5Ghz band, and as AP in 2,4 GHz band. Sometimes I get problems
    with the non-root bridges, after mains outage, they will not
    associate to the root bridge. Command "dot11 do 1 carrier busy"
    issued to the non-root bridge helps, but sometimes I have to use it
    several times. Have anybody any idea about possible cause?
    Thanks

    Hi Frank,
    I think I have found the reason of my troubles. It is the following configuration command:
    (interface Dot11Radio1)
    world-mode dot11d country CZ outdoor
    which is not only not-needed on the non-root bridge AP, it prevents associating the non-root bridge to the root-bridge AP. It does not cause the troubles on each root non-root couple. The troubles are more frequent with IOS version 12.3(11)JA or 12.3(8)JEA than with 12.3(8)JA2.
    Regards
    Frantisek Opravil

  • Root Bridge+Clients with Non-Root Bridge+Clients Howto?

    Hi, i have two 1242AG access points. I would like to setup a bridge between the two to bridge ethernet lan segments, furthermore i would like to be able to connect wireless clients to either of the access points so i can get maximum range.
    I did what i thought was correct, created the first access point a 'root bridge with wireless clients', and assigned the ssid.
    I set the second access point to 'non-root bridge with wireless clients' amd set the same ssid as the first access point.
    I cant even get the root bridge to work, i turn it on, it brings the radio interface up but i cannot connect with my wireless clients, infact i cannot even see the SSID!
    Do i need to 'Set Single Guest Mode SSID' for the radios? What does that command do?
    Any ideas? A link to config example would be much apreciated.
    Thanks,
    Chris

    Hi, first, thanks for the help.
    Second, this incompatibility is only valid
    for RFC1042 or it is valid for 802.11g?
    Third, If I configure my 1242 as Acess Point, and the 340 series as Client or Brigde_only, they should not talk too?
    Sorry for the bad english...

  • Non-root bridge 1242AG with root 340 bridge series

    I have a configuration with a root bridge 340 series and about 5 non-root bridge 340 series. I want to add a 1242 non root bridge, but the new device can't see the others, and neither the others can see the 1242.
    Is there an issue in connecting these two devices in this configuration?

    Hi, first, thanks for the help.
    Second, this incompatibility is only valid
    for RFC1042 or it is valid for 802.11g?
    Third, If I configure my 1242 as Acess Point, and the 340 series as Client or Brigde_only, they should not talk too?
    Sorry for the bad english...

  • Root-bridge non-root bridge security

    Using AP1231, I have a point-to-point configuration with the option "without wireless clients". I have enabled WPA2-PSK/AES-CCMP to the infrastructureSSID/nativeVLAN.
    Does this security automatically apply to the other SSID/VLAN I have configured? Or do I need to configure additional security on the other SSID/VLAN? Please advise. Thanks!

    From your diagram, AP3 is the root bridge because it is connected to ISP, so AP2 will be a repeater, but 1242 can't work both as repeater and AP. So the diagram won't work. you have 3 alternative options:
    1. not let AP2 to connect wireless clients, only configure AP2 as a repeater.
    2. If AP1 can connect to AP3 directly, then configure AP3 as root-bridge with wireless clients, configure both AP1 and AP2 as non-root bridge withe wireless clients.
    3. If AP1 can't connect to AP3 directly, you need to add an additional AP4 to have back-to-back connection with AP2, configure AP1 and AP4 as non-root bridge with wireless clients, configure AP2 and AP3 as root-bridge with wireless clients; ap1 peered with AP2, AP4 peered with AP3, AP2 and AP4 are interconnected by ethernet port.

  • 1310 Non-Root Bridge Accessing Different Subnets

    From this non-root 1310 bridge, we are connecting to an old BR500 root bridge via wireless.
    Clients inside the non-root bridge are able to access devices anywhere on the subnet (servers, workstations, etc.) via the bridge (wireless connection) with no problems. But, these clients cannot access the default gateway of the subnet or pass through the router (I can't even ping the default gateway router interface from the 1310 bridge; yet from the bridge, I can ping anything else on the same subnet).
    Of course, clients on the wired LAN are able to browse the Internet, etc. -- it is only clients behind this bridge that cannot seem to "get out" so to speak.
    This is a small LAN -- so everything is VLAN1 with a router at the boundary.
    I have even ran a "sh ip arp" on the 1310 to ensure that a MAC entry is in the table for the default gateway IP, and it is there.
    Any ideas?

    Make sure there is no access list confiugred on the router blocking the access. Save the configurations and restart the bridge .

  • 1242 Root or Non-Root Bridge

    Greetings,
    I have a small network that uses 1242 APs for clients machines. Our wired WAN link can be unreliable, so I would like to configure one of the 1242s as a bridge and connect it to one of the many wireless networks we have in our neighborhood.
    I understand the 1242 APs can also operate in a bridge mode that could allow us to connect our network to one of these other wireless LANs. A couple of questions:
    -Does the remote WLAN have to be a compatible cisco device in order for the 1242 to be able to bridge successfully?
    -Which 'Role in Radio Network' do I choose for our 1242?
    -How do I see what the SSIDs of the remote WLANS are and enter the relevant passwords (WEP, WPA, 802.1x, or WPA2)
    -If this is not possible, what is the right device to use to connect our LAN to a remote WLAN without being able to control the hardware at 'both' ends of the bridge.
    TIA

    Can you please provide me with a network topology of what it is you would like to achieve. If you want the radio interfaces to associate to one another, then it is recommended to have them on the same channel, but for roaming instances, it is recommended that you have then at least 5 channels apart on the g radio so as to avoid any interference.
    The 802.11A radios on the APs would be configured as bridges (one as
    a "root" and the other two as "non-root") and the 802.11G radios
    would service clients. Only one of the APs would require wired
    connectivity in this scenario, as long as all of the APs are
    communicating to each other on the 802.11A side. An important
    consideration is that the 802.11A radios that are configured as "non-
    root bridges" need only to communicate with the 802.11A radio that is
    configured as the "root bridge". It is not necessary for the "non-
    root bridges" to see each other. However, it is imperative that the
    802.11A radio that is configured as the "root bridge" be able to
    communicate with BOTH of the 802.11A "non-root" bridges. Therefore,
    the antennas you choose for the devices is important.

  • 7920 associates to root bridge but not to non-root bridge

    I have 7920s using open authentication with WEP128 cipher. I have two 1300 root AP's (with client support) and three non-root AP's (also client support) in the same lab area. The root AP's and non-Root AP's associate and link to each other no problem. However, the 7920's will only associate with the Root APs. If I power down the root APs, the 7920s show "no AP found". I've verified SSID and WEP128 keys. I've also noted that the root AP does have a channel specified under dot11radio0 but the non-roots do not. Do the 7920's just scan for any channel until it finds an association or do I need to specify a channel in the non-root bridges?
    Thanks,
    Mike.

    With static WEP, the authentication is happening at the AP level. Will want to ensure non-root is associated to a root though otherwise the interface may be in "reset" state.
    The 7920 will look at these 2 as individual APs regardless of channel. Non-roots should have the same channel as the root, otherwise will not be able to communicate.

Maybe you are looking for

  • Getting jrew.exe error while installing oracle 9i in windows vista

    Hello experts I'm using windows vista..I installed oracle 9i in my system..While installing third CD of oracle 9i I got error like jrew.exe error and the installation was aborted.. Is any solution to solve this issue..Pls help me

  • Reverse telnet to a specific line, based on AAA credentials

    I want to setup a console server like a 2600 or something with a 16 or 32 port async module and allow users to access only certain ports/lines by reverse telnet based on login credentials. For example, user joe can reverse telnet to ports 1 and 2, wh

  • OS error in starting service OracleMTSRecoveryService

    I am facing the Following Problem when Installing Oracle 11g Release2 database at Microsoft Window 32-bidt OS error in starting service OracleMTSRecoveryService Note: Once I have already ionstalled this database on same machine and after that I delet

  • Upgraded to Yosemite can I upgrade cs2 to cs5 and get it to work

    I just upgraded my computer not realizing cs2 would no longer run on Yosemite, can I upgrade my software and get it to work or do I need to buy the whole new software?  I am not looking to go to the cloud. Thanks.

  • Bb msn only works with wifi

    Hi, i have a BB Pearl 8120 and it has a problem! I can send BB messages, but i can't receive them if I don't have wifi connection! (but i do send without wifi connection) Sometimes I can connect with internet (browser icon) sometimes I can't I alread