Subsets of ssid on LWAP on same controller

I was wondering if it is possible to determine which SSID's are available on a group of LWAP. If I want a special SSID to only appear in a certain small group of LWAP (say a single building), but there are many more LWAP on the same WLC that I dont want that SSID to appear on. I only seem able to put enable or disable an SSID across all LWAP.
I have a WiSM, 90x 1130AG, and WCS. Each SSID is it's own VLAN.
Regards.

Hi Mike,
Ankur is most correct here (5 points for this Ankur and nice to see you back here posting great answers!)
I just wanted to add a little more reference material;
Enabling WLAN Override
By default, access points transmit all defined WLANs on the controller. However, you can use the WLAN Override option to select which WLANs are transmitted and which ones are not on a per access point basis. For example, you can use WLAN override to control where in the network the guest WLAN is transmitted or you can use it to disable a specific WLAN in a certain area of the network.
From this doc;
http://www.cisco.com/en/US/products/ps6366/products_configuration_guide_chapter09186a008076cbfd.html#wp1114777
Once you create a new WLAN, the WLAN > Edit page for the new WLAN appears. In this page you can define various parameters specific to this WLAN including General Policies, RADIUS Servers, Security Policies, and 802.1x Parameters.
**Check Admin Status under General Policies to enable the WLAN. If you want the AP to broadcast the SSID in its beacon frames, check Broadcast SSID.
Note: You can configure up to sixteen WLANs on the controller. The Cisco WLAN Solution can control up to sixteen WLANs for Lightweight APs. Each WLAN has a separate WLAN ID (1 through 16), a separate WLAN SSID (WLAN name), and can be assigned unique security policies. Lightweight APs broadcast all active Cisco WLAN Solution WLAN SSIDs and enforce the policies that you define for each WLAN.
From this good doc;
http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a0080665d18.shtml#c3
The most popular way to mitigate the problem of having to access each AP individually (when using WLAN Override) is to use WCS Templates for common requirement AP's. This way the WLAN Override function can be applied at the Template level and then pushed out to the various groups.
http://www.cisco.com/en/US/docs/wireless/wcs/4.0/configuration/guide/wcstemp.html#wp1072198
Hope this helps!
Rob

Similar Messages

  • Trouble accessing another SSID on same controller

    I recently inherited a Wi-Fi network that's having a number of issues however I bring you one today.
    I currently have 5 SSID's on a Cisco 5508, the problem is I can join just one of those SSID's.  When I switch to one of the other SSID and enter the password I get this error message "Network Security Key Mismatch".  I am toll "All SSID's" have worked in the pass but one day they started having an issue connecting to all except one.  I am also told by someone who's memory fails them that 3 engineers or so more before me told them it had to do with either the user MAC was tied too long to the DHCP address it was issued and they had to go in and manually clear/remove before they could rollover...  Or that they had to issue some release command to be able to then access the other SSID and then the same thing to go back to the original SSID...  Anyone have such and issue and have a fix?

    Hi Rohan,
    Do you know if Fast SSID change is enabled ?
    if not, you can enable it controller > Fast SSID Change 
    See below:
    Fast SSID change
                  Disabled              Enabled        
    Also, as a rule of thumb, please restrict number of SSIDs to 3 or less unless it is really required.
    By reducing the number of SSIDs the available air quality can be improved and hence better wireless performance.
    Also, you can validate your WLC configuration using Cisco WLC configuration Analyser to make sure all the recommended features are enabled/disabled on your WLC.
    https://supportforums.cisco.com/document/7711/wlc-config-analyzer
    Hope the above helps to fix your wireless issue!
    Cheers,
    VB

  • Multiple SSID's on the same subnet?

    Can you have Multiple SSID's on the same subnet?
    SSID1 authenticates clients via radius.
    Our corporation bought printers with wireless cards that only support WPA-PSK so we created SSID2 for the printers. We can connect to both SSID's and ping from SSID1 to SSID2 but we can not perform other functions such as view the printer management interface with a browser. Should it be possibe to communicate between SSID1 and SSID2 on the same subnet?

    Yes you should have no issue, but the only thing is that you are using a lower security method... so either you put them on different subnets so you can control the traffic via acl's or might as well use the same security method to make it easier. The fact that you can ping sounds like you should be able to http to the device.

  • Calling the same controller in Weblogic portal 10.3.2

    In weblogic 8.1 calling the same controller instance (different action) is very simple.... just pass on the jpfScopeId in the request parameter as per the code below
    function openActionInNewWindow(index){
    <%
    PortletPresentationContext ppc = PortletPresentationContext.getPortletPresentationContext(request);
    String jpfScopeId = ppc.getInstanceLabel();
    %>
    url = "/someApp/portlets/somePath/someAction.do?index="+index;
    url += '&jpfScopeID='+'<%=jpfScopeId%>';
    alert(url);
    extWindow = window.open(url, 'second', 'title=Breaking News,width=650, height=300,toolbar=no,status=no,scrollbars=yes,location=no,menubar=no,directories=no,resizable=yes');
    extWindow.focus();
    How do we do the same in Weblogic portal 10.3.2? I tried the above code but its invoking a new instance of the controller. I want to call the same controller instance as some instance variables in the controller are being used across different actions.

    No, there isn't problem show in log. I don't know why... Please suggest me or help me.
    Thanks in advance!
    Best Regards,
    Coy.

  • To call same controller in return

    ModelAndView nextView = new ModelAndView(getSuccessView());
    ante success ki return avutundi kada,success ki vellakunda controller should be in same page(ante next view lo kuda same controller ni call cheyali) ante ela ivvali syntax
    means it is returning success.but my requirement is i would like to stay in the same page after success also,for that i have to call same controller in return,can any body help me for this

    ante success ki return avutundi kada,success ki vellakunda controller should be in same page(ante next view lo kuda same controller ni call cheyali) ante ela ivvali syntaxPlease post in english.
    Not only in characters, but also in meaning!

  • Gamestop Red Samurai controller - same controller different result

    I'm using a new Gamestop Red Samurai controller paired via bluetooth to my mac, and it's been working great. I can play a PS1 emulator and map all the keys and it's excellent. So I thought "How about getting some 2 player action going", and I bought another controller (same brand and model number). The new controller will not stay connected to the mac for longer than 5 seconds. The original doesn't disconnect until I manually turn it off. When I bought the new controller I actually bought 2 because a friend also wanted one. I tested his and it's the same issue of 5 seconds, then the connection goes away. I can hit any button on the controller and it will connect again, but in another 5 seconds it's gone. I can manually reconnect via my mac settings, but again in 5 seconds, you can guess what happens. So is there anything I can try to get this new controller to stay connected. I've tried using the controllers gaming mode and keyboard mode (switch on the back) but the connection continues to drop either way. I've removed all previous controllers from my mac bluetooth preferences, but it still will only stay connected to the original controller when I add them back 1 by 1. I'm completely stumped by how 2 out of 3 seemingly identical products could behave so differently. If there were any more in store, I'd go try them out and find another that stays connected, but it's a big gamble to buy online hoping for better luck. I'm open to any possible solutions.
    I'm on Mavericks 10.9.5. I should also mention that both controllers pair with my amazon fire tv stick, and stay connected just fine. The new controller that disconnects from the mac, also stayed paired to a windows computer just fine.

    Hi Matt,
    Just to add a note to the great info from Scott. You can use the WCS to push this info out to all the WLC's using this method;
    Configuring an Access Point Authorization Template
    Follow these steps to add an access point authorization template or make changes to an existing template. These templates are devised for Cisco 11xx/12xx series access points converted from IOS to LWAPP or for 1030 access points connecting in bridge mode.
    Step 1 Choose Configure > Controller Templates.
    Step 2 From the Security selections in the left sidebar menu, choose AP authorization.
    Step 3 If you want to add a new template, choose Add Template from the Select a command drop-down menu and click GO. To make modifications to an existing template, click a MAC address in the AP Base Radio MAC column. The AP Authorization Template appears (see Figure 9-12), and the number of controllers the template is applied to automatically populates.
    Step 4 Select the Import from File check box if you want to import a file containing access point MAC addresses.
    
    Note You can only import a .csv file. Any other file formats are not supported.
    Step 5 Enter the file path from where you want to import the file.
    Step 6 Click Save.
    From this doc;
    http://www.cisco.com/en/US/docs/wireless/wcs/4.0/configuration/guide/wcstemp.html#wp1072945
    Hope this helps!
    Rob

  • 1131ag LWAP in WLAN controller 4402

    Hi, i have 1131ag but at controller 4402 i see Number of radio interfaces 2, 802.11b/g/n admin status enable, oper status up and regulatory domain supported, but en 802.11a/n admin status enable, oper status down and regulatory domain not supported, why 802.11a is not supported?

    hello, AP is the model AIR-LAP1131AG-A-K9 and I configured the controller with the code of mexico MX. Now try the U.S. code, but it is the same result.
    Juan Ramon
    thanks....

  • 1142 AP behaving differently to an 1130AP when on the same controller.

    Hi there, I have a new WLC 2504 running  7.6.120.0, I have two AP's connected to it one is AIR-LAP1142N-E-K9 IOS Version 15.2(4)JB5$ the other is a AIR-LAP1131AG-E-K9 IOS Version 12.4(25e)JAO5$
    When I try to connect to my SSID I have created I can connect to it fine when the 1131 is broadcasting the SSID, however if I disable that and enable the 1142 it cannot connect. I am at a loss to see what the issue is as the WLC should be doing the authentication for the AP's so the results should be the same.
    On the console of the 1142 I get
    *Oct  7 13:20:33.239: %LWAPP-3-CLIENT_ACL_ENTRY_NOT_EXIST: Deleting Mobile for 0026.c64f.30e2: CLIENT ACL not exist on AP
    *Oct  7 13:20:34.565: %LWAPP-3-CLIENT_ACL_ENTRY_NOT_EXIST: Deleting Mobile for 0026.c64f.30e2: CLIENT ACL not exist on AP
    *Oct  7 13:20:36.318: %LWAPP-3-CLIENT_ACL_ENTRY_NOT_EXIST: Deleting Mobile for 0026.c64f.30e2: CLIENT ACL not exist on AP
    *Oct  7 13:20:37.881: %LWAPP-3-CLIENT_ACL_ENTRY_NOT_EXIST: Deleting Mobile for 0026.c64f.30e2: CLIENT ACL not exist on AP
    Which I take to mean its not getting the downloadable ACL to it. As the 1131 works I am not sure what could be causing this. Any ideas?

    In both debugs the client gets an access accept from the WLC, and should move to getting a DHCP address.  In the 1142 debug the client attempts to reassociate immediately. 
    what NIC and driver is your test client running? If you are using an Intel 7200 you should be on 16.
    HTH,
    Steve

  • Can Xgrid controller and agent run on the same controller?

    I am trying to setup an Xgrid on 2 Mac OS X Leopard computers. My intention was setting up one computer as a controller/agent and other computer as an agent so that I can have a grid with 2 agents running on different computers. I setup my grid with xgridctl and using Xgrid Admin, I am able to view the grid on a GUI program. In Xgrid Admin, I also see 2 computers (One is local, other one is remote computer) listed with their IP addresses. Only the remote computer's status is "Available". Local computer's status is "Unavailable".
    I was about to conclude that you can not have controller and agent on the same computer but I decided to shoot an email to apple mailing list and expect some clarification.
    Thanks in advance for the support,
    Umut Tezduyar

    You might get a better response to this in either the [OS X Server forum|http://discussions.apple.com/category.jspa?categoryID=96] or even the [Xgrid area!|http://discussions.apple.com/forum.jspa?forumID=722]

  • WLC 7.4.110.0 where native vlan and SSID vlan is the same vlan

    Hi
    We have app. 1500 accespoints in app. 500 locations. WLCs are WiSM2s running 7.4.110.0. The AP are 1131LAPs.In a FlexConnect configuration we use vlan 410 as native vlan and the ssid (LAN) also in vlan 410. This works fine, never had any problems with this.
    Now we have started use 1602 APs and the client connection on ssid LAN becomes unstable.
    If we configure an different ssid, using vlan 420 and native vlan as 410, everything works fine.
    I can't find any recommandations regarding the use of native vlan/ssid vlan
    Is there anyone experiencing similar problems? Is this a problem with my configuration or is it a bug wittin 1602 accespoints?
    Regards,
    Lars Christian

    It is the recomended design to put FlexConnect AP mgt into native vlan & user traffic to a tagged vlan.
    From the QoS perspective if you want to enforce WLC QoS profile values, you have to tag SSID traffic to a vlan (other than native vlan) & trust CoS on the switch port connected to FlexConnect AP (usually configured as trunk port)
    HTH
    Rasika
    **** Pls rate all useful responses ****

  • LWAP not joining controller, but has downloaded software

    Hi All,
    I have four APs that when I powered on individually, they went into the downloading state and rebooted, now have the mac address APxxxx.xxxx.xxxx.cisco.com and can see this on my switch and cdp is working, but has not joined the controller?
    I know that DHCP is set correctly as I have another AP on the switch/VLAN that is working?
    Any ideas?
    Many thx indeed,
    Ken

    To answer your specific question, there's no need to clear anything on the WLC. The access points should simply connect.
    Did you upgrade these access points, and could this be a certificate issue? If they are upgraded 1100s or 1200s, you may need to add the SSCs generated during the upgrade process into the controller. This can be done under the Security tab.
    If that's not the issue, I would try to connect the access points more directly by placing them on the management subnet. This will hopefully tell you whether there's a problem with your discovery method.
    Have you looked at the access points to see their status according to their LEDs? Are they still seeking a controller? Is it possible that they've found a different controller somewhere else on the network?

  • Both SAS and SATA RAID on same controller

    Can I install both SAS and SATA raid on an RD240 with 8708EM2 controller?
    I want to install first volume mirrored 600 GB SAS and second volume mirrored 2 TB SATA drives.

    welcome to the forum!
    both SAS and SATA arrays are supported simultaneously on the PHYs but it's not recommended to mix the two within an array (ie: creating a SAS+SATA disk RAID 1).   per your question you can have a SAS+SAS RAID 1 plus a SATA+SATA RAID 1 concurrently on the LSI 1078 chipset.
    ThinkStation C20
    ThinkPad X1C · X220 · X60T · 600

  • RAID set and JBOD on same controller card?

    I'm planning to update my RAID from the current 4-disc software 0 in my MacPro to a RAID 5 with dedicated controller (for now) and here's what I'm planning (tentatively)
    • RAID 5 consisting of 8 discs, 4 inside 5.1 MacPro with MaxUpgrade's kit in use for SAS connectivity , and 4 more discs in a 1U rackmount SAS chassis, possibly OWC's new 'trayless' unit, or another similar chassis.
    • Areca RAID controller ARC-1880ix-12 is what I'm leaning towards at this time.
    I don't have the cash or demand (yet) for a system in a huge expansion chassis and 24 drives, but my the main thing I want to know, (since I've never had this many discs to play around with before) is when I create an 8 disc RAID 5 Array for storage, can I also connect another external chassis to the controller as a JBOD unit and have those drives therein function independently, with swap capability of single volumes? This would be very handy for individual cleint-drive backups and would free up my eSATA interface for file ingest and more flexibility.
    I do know I would have to get an adapter to run more than one external SAS connection cause the Card only has one External SAS port as is. I may go with a different card with more channels for more future expansion, but it will more than likely have more internal ports than external.

    l_elephant wrote:
    your system is on that RAID0?
    do you regularly clone your system, for when, (not in case), the RAID0 fails?
    Yes, when working I backup the data ideally after every time I add footage to the RAID, if not at least once daily.
    have you considered the added security of RAID6 (if your going to have that many drives . . .)
    I have, and it will probably be the next step if I go to a RAID larger than 8 discs. IF I do start getting the need for 16+ I may go to a RAID 10.
    when you mean storage, do you mean like archival, past projects type storage, or current working projects drive space?
    Working projects. Also will look into LTO for archival in the future if the demand necessitates it.
    can I also connect another external chassis to the controller as a JBOD unit and have those drives therein function independently, with swap capability of single volumes?
    yes
    Thank you, this is the main question I had, do you have a specific experience such as this you would share?
    I do know I would have to get an adapter to run more than one external SAS connection cause the Card only has one External SAS port as is. I may go with a different card with more channels for more future expansion, but it will more than likely have more internal ports than external.
    you're describing SAS expander. You can easily have more than 200 drives connected.
    No I'm describing a PCI plate SFF-8087 to SFF-8088 Adapter, like this one:
    http://www.pc-pitstop.com/sascablesadapters/AD8788-4.asp
    Like I said, most of the cards I'm looking at have more internal 8087 ports than the external 8088 ports.
    what kind of work are you doing? Vidéo, audio? One project at a time, or parallel projects? Alone or with others (colleagues, employees)? The Caldigit system looks nice for large teams of people.
    This would be a mobile installation, with me as a single operator handling digital video footage, so this would be direct attached storage, no network interface necessary. Usually one project at a time, but if I get busier hopefully more than one.

  • Broadcasting SSID to specific APs connected to same WLC

    Hello all,
    I just have a quick question.  Is it possible to broadcast specific SSIDs to specific access points that are connected to the same controller?  For example, SSID-A is for wireless clients located in building A within the campus; same for SSID-B and so forth?  My assumption is that all LWAPs will broadcast all SSIDs configured on the WLC.
    Regards,
    Terence

    If WLAN ID number is  between 1-16 & AP belongs to "default-ap-group" WLC will broadcast all those SSID via APs on that ap-group..
    You can do what you required easily by defining a AP-GROUP. Once you defined AP-Group you can selectively advertised SSID on particular APs. Also you can give different subnets for same SSID based on your grouping requirement.
    Here is a reference for AP group configuration. It may help to understand this
    http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008073c723.shtml
    HTH
    Rasika
    **** Pls rate all useful responses ****

  • Using multiple SSIDs with same name but different PSKs

    I have a central WLC 2504 controller that is being used for remote site FlexConnect 1141 APs. They all advertise three different SSIDs. One SSID is a global SSID that is the same at every office. One is a hidden SSID using 802.1x machine auth.
    The one I am trying to get working is the local office guest network. These SSIDs are all the same at each office but should have different PSKs. They are local to the office, therefore would only ever be applied to a specific FlexConnect group.
    I understand why in theory this is generally not a good idea but given these are for remote sites I'd like it to be possible. I always get this message though:
    "WLAN with duplicate SSID and L2 security policy found"
    Is there a way around this? New WLC code that allows it maybe?

    I was able to configure three (more I think possible) WLANs with same SSID name and all are WPA2-AES-PSK on the same WLC and all are enabled at hte same time.
    Note that you can not have any of those broadcasting on same AP group. Each WLAN can be only broadcasted on a separate AP group. For your sites, It will probably need you to define an AP group for each site to broadcast different WLANs on different sites.
    You can do that if all your WLANs have an ID of 17 or higher. (the reason is, WLANs of 1-16 are by default broadcasted on the default AP group. and because those can not be on the same AP group - including the default one - then you can't have them with WLAN IDs 1-16. i.e on same - default - AP group)
    HTH
    Amjad
    rating useful replies is more useful than saying "Thank you"

Maybe you are looking for