WAP321 ignore global radius active server ip address

Hello everyone,
I have few WAP321 with a radius server listening on 2 different IPs (one for each SSID).
I configured the global radius server with theses two IPs.
Then I created 2 wireless networks with WPA enterprise, global radius settings.
I selected global radius "active server ip address 1" for the first network and global radius "active server ip address 2" for the second but it does not work. After saving the 2 networks only connect to the first IP of the radius and the select field only display "active server ip address 1" for both networks.
Is it a bug ? or something I haven't understood ?
Using firmware 1.0.5.3.
Thank you.

Hi flallart1
Personally I can't confirm this behavior as I have no WAP321 unit by hand. But I wanted to say something about your setup.
You've configured RADIUS server with two different IP's.
Each RADIUS IP provides different authentication rules - like different user database or different set of authorization rules.
You have added both RADIUS IPs inside Global RADIUS setting configuration.
And inside each SSID (Virtual Access Point) setting you kept "Use global RADIUS server settings" checked, but you have explicitly selected "Active Server" for that particular SSID for which is suited.
What "Active Server" means: Enables the administrative selection of the active RADIUS server, rather than having the WAP device attempt to contact each configured server in sequence and choose the first server that is up.
In reality this means that from existing pool of available RADIUS servers you can choose preferred server by your own. But in case that preferred RADIUS server is not reachable, another one will be used for that SSID. But this is not good behavior in your case - because once that situation happen and your WAP selected different IP for particular SSID, your authentication scheme will be completely different as second RADIUS IP provides different authentication/authorization rulebase. If that RADIUS IP change happen, all clients already connected to that SSID according rulebase of first RADIUS IP will be denied in few next minutes, because re-authentication will fail as now it will be done according rulebase of second RADIUS IP. Also new clients will not be able to connect which normally works for them.
In your case you should ignore global RADIUS settings and explicitly configure RADIUS IP inside each SSID (Virtual Access Point) - i.e. IP of RADIUS server which is only related to that SSID. In your scenario, there is no Backup RADIUS IP as both of them provides different authentication.

Similar Messages

  • 8320 with a problem with BES activation. Phone asking for Activation Server address.

    I have a remote user, whose BB 8320 is asking for am Activation Server address. I looked thru the forms and the KB and the only two suggestion are use the servers SMTP address or leave blank neither have worked. The user wiped the blackberry before trying to activate. The phone was using BIS prior to today, she had t-mobile change her to their Corp/BES plan.
    Help please.....
    I am going to cross post in the Blackberry Professional software forum.. Sorry

    Hello black jack 1986,
    For troubleshooting information on this, take a look at this article:
    iPhone: Troubleshooting activation issues
    http://support.apple.com/kb/ts3424
    Since the update or restore did not complete you may also want to look at:
    iOS: Unable to update or restore
    http://support.apple.com/kb/HT1808
    Hope this helps,
    Mario

  • Help me with my activation password and activation server address

    hei.. yesterday i tried to wipe my blackberry.. and then all of my data lost.. when I open my setup wizard, then open my email set up, i need activation password and activation server address.. but i don't know what mine.. how is it?
    please help me..

    Hi hikarisora
    Welcome to BlackBerry Support Forums
     Before going to email setup , try registrating your device with your wireless sevice provider .For that  : 
    On the Home screen of the BlackBerry smartphone, click Options, or click Settings > Options
    For BlackBerry Device Software 4.1 to 5.0, Advanced Options > Host Routing Table > 
    Press the Menu key and click Register Now
    Wait till a Registration messages comes in your message box.
    KB00510 How to register a BlackBerry smartphone with the wireless network
    After getting the registration message on your device try setup wizard again.
    Good Luck.
    Click " Like " if you want to Thank someone.
    If Problem Resolves mark the post(s) as " Solution ", so that other can make use of it.

  • Activation server is down, Design Premium blames me!

    This is pretty funny, so for some reason today I get an activation request from Photoshop CS5.1 eventhough I've used the product many times already, and have activated it. Yet today I opened it up and it told me activation has failed because I was not connected to the Internet. Lo and behold I am here posting this right now. So I see that Photoshop is trying to connect to https://activate.adobe.com/ which is down for me. So actually it's not my fault the product cannot activate, but something to do with Adobe's server obviously. It's pretty frustrating to be told I have 23 days left or my product will be disabled blah blah when it's not even my own fault that this is occurring.
    Doesn't Adobe have some kind of system in place to cope with their server having issues in this instance?

    Hi Rohan
    You may be right but are you sure? When we started striking problems a week ago, my first thought was that the server was down, but it didn't seem to be - I eventually worked out that Illustrator could access it ok but FM wouldn't.
    When you try to ping activate.adobe.com, does it return an IP address [192.150.16.69]? If so, I think the server's reachable, just not replying to pings. The knowledgebase http://kb2.adobe.com/cps/100/1008779.html says "If the test is successful, the string activate.adobe.com [ip address] is returned (You can ignore the other information returned.)" I think that means they've configured the server to not reply to pings and as long as you see the IP address, your contact with the server is ok.
    Have a look at the activation log. It's somewhere in Documents and Settings and is called amt3.log (sorry, I can't remember the path and I'm not on a work PC atm). Try another program in the CS suite and see if that manages to open ok. If so, the log will show it accessing the activation server. Or anyway, this is what it did for us.
    Cheers
    Rebecca

  • IPhone 4S could not be activated because the activation server is temporarily unavailable

    If you got the "scary" message that you could not activate iPhone 4S neither by Wi-Fi or iTunes, I want to share my experience:
    I decided to reset my iPhone 4S, and used "Erase All Content and Settings" under the reset menu (Settings/General/Reset), I was hoping that the erasing just does that, but for me the nightmare started!
    I was taken to the activation screens, and begun with the welcome one, choose language, choose location services (later on it also disappears) and selecting Wi-Fi and/or iTunes for activation.
    I chose a Wi-Fi network the process started, and gave me a message that it will take about three minutes to activate iPhone, few minutes later a screen with this message appears: "Your iPhone could not be activated because the activation server is temporarily unavailable."
    Then, I decided to try the activation using iTunes…
    Using iTunes, after few minutes, it shows the following message: "We could not complete your iTunes Store request. The iTunes Store is temporarily unavailable. Please try again later."
    I tried several times in both ways, trying 4 different Wi-Fi networks and 3 different computers in the whole process, and I was going desperate! I started to find out some info about this trouble over the Internet, and guess what? I was not alone! But I did not find any answer or solution either!
    Finally, I joined Apple Support Communities, and started searching with no good luck at all, until I found (many hours later)  this old (2009) solution:
    +Do a DFU recovery:+
    +1. Open iTunes.+
    +2. Connect the iPhone+
    +3 Press both the home and sleep/wake buttons until the Apple icon appears (ignore the red slider if it shows).+
    +4. Continue pressing the home button alone until iTunes sees your phone in recovery mode.+
    +5. Follow the prompts to restore the iPhone.+
    (THANKS A LOT!!! modular747 and Easily Easy, you saved me!!!)
    Then I suggest everyone to use this, of course it will erase everything, but you may be able to recover your data from your last backup, or you can also choose to configure iPhone as a new cell phone.
    The process took me about 92 minutes, but it was worth it, now I own an unlocked iPhone 4S (it was an AT&T when I purchased from Apple Store in November) and is working perfectly!
    Hope it is useful for all of you facing this trouble!
    Good luck and enjoy your iPhone then!

    I tried the process and was happy to note that there was some process that I managed to start because the process did start ...
    However to my disappointment,  landed back at the same status which says
    We're sorry, we are unable to continue with your activation at this time.
    Please try again later, or contact customer care
    I was using a GEVEY sim unlock with iOS 4.1 since (almost) last 2 yrs now in India on Vodafone. But as Apple designed it, there were several apps including Whatsapp, Facebook, Gmail and LinkedIn that stopped functioning due to the iOS updates and the subsequent (I guess 'mandatory' App updates). Finally yesterday I thought of updating to the iOS 6. As soon as I did that, I have been left with no choice but to see the above message.
    The process by jhidrowoh starts corectly but iTunes doesnt give you the option of restore only ... it is forcefully clubbed with update and the button that is displayed in the dialog box that appears on pressing 'Restore' in teh recovery mode, shows 'Restore and Update' and as soon as the iPhone is restored, it automatically updates the iOS as well to iOS 6 and hence leaves you hanging in the stale situation.
    Guys ... Need the data desperately ... Can anybody please help???

  • Tried to update to IOS6 and now my ipad is trying to restore -- getting error "activation server not available" help!  Have I lost all my video files?

    I was trying to do a simple udate of the ios software.  I connected to ITunes and the Ipad screen popped up saying there was an update available.  I clicked on the update and it started updating and also there was a message saying it was backing up.  But then I got a message to click here to complete the update -- with a restore.  I did that and now my IPad is n ot woking at all -- I get the initial startup screen and a message that says "your ipad cannot be activated because the activation server is not available"  I've tried connecting to itunes and get the same message -- server not available.  The devices menu option is grayed out so I cant sync, backup,, restore nothing.... HELP! please!  I only wanted to do a simple update -- now I think I've lost all my pictures and video files -- is there a way to get them back??

    Try restarting everything and then try to sync or reactivate. Quit iTunes, reboot your computer, reboot your iPad and then try again.
    Reboot the iPad by holding down on the sleep and home buttons at the same time for about 10-15 seconds until the Apple Logo appears - ignore the red slider if it appears on the screen - let go of the buttons. Let the iPad start up.

  • How to retrieve available (server)-IP addresses on a LAN

    Is there a method to get all/the available (server)-IP-address(es) on a LAN from the host program?
    As far as I understood the samples (e.g. in tcpex.llb) the host (or it's operator) has to know the IP-address of the server to start communication. However it would ease the usage of a host-program if all/the available server(s) could be selected e.g. from a list-box.
    I posted this question already yesterday with some additional explanations however couldn't find it in my "posted questions"-list. So I try again.

    You don't tell us enought about the type of "servers" you mean. Are these all LabVIEW programs? In this case it should be relatively easy for them to keep each other updated at regular interval, e.g. via UDP multicasts.
    Alternatively, your servers can announce themselves via a UDP packet to the subnet broadcast address and to a specific port.
    If these are servers with code not under your control, you need to probe them. This is not such a big deal on your private LAN and I don't think it will trigger IDS systems. Keep a short list of all possible server IPs, then try to connect at the specified port at regular intervals using a short timeout.
    Are you communicating with TCP or UDP?
    In the absence of firewall code, you can have 3 possible responses for TCP:
    (1) No response --> The server computer is down (or there is a stealth personal firewall running). You get a TCP timeout error.
    (2) Active rejections (TCP RST packet) --> The server computer is up, but the server program is not running. Nothing is listening on the target port. You'll get an error.
    (3) Accepted connection (SYN-ACK) packet. --> The server is up and listening for connections. The threeway handshake can be completed. No error.
    UDP is a bit trickier, because it is connectionless. Many UDP services are one-way. For example a syslog server just receives packets, it never acknowledges anything.
    It is easy to tell if the server computer is up, but the service is not listening. In this case you get an ICMP(3,3) response and an immediate error.
    If the service is listening, you either get nothing or a specific response, depending on the type of server. If you are waiting for return traffic, you'll get a timeout error in UDP read either way.
    (If you just want to check if the server computer is actually up, probe it on a unlikely high port that virtually guarantees an ICMP(3,3) response in the absence of a personal firewall program.)
    LabVIEW Champion . Do more with less code and in less time .

  • How to automatically detect server ip address

    does any one know how to automatically detect an ip address of a server from the client with a socket based connection ?
    instead of prompting the client to connect to the server ip address which is trouble some.

    You must start with some initial information and a known environment.
    There are several possibilities after that.
    - The server has a 'name'. This is not an ip address but a name like "yahoo.com". When you connect using that, even if the IP changes, the correct IP will be returned. (At least ignoring an annoying bug in some VMs)
    - A specific IP address
    - Use a methodoly to 'request' a server address. One version of this is to use a UDP broadcast another version uses a service manager (which itself must be found.)

  • H323 cisco attributes not being forwarded to Radius accounting server

    I have enabled a Radius server to gather AAA Accounting CDR records but I don't see any of the Cisco h323 attributes. The following is an example of the list I WANT to see.
    ATTRIBUTE h323-remote-address 23 string Cisco
    ATTRIBUTE h323-conf-id 24 string Cisco
    ATTRIBUTE h323-setup-time 25 string Cisco
    ATTRIBUTE h323-call-origin 26 string Cisco
    ATTRIBUTE h323-call-type 27 string Cisco
    ATTRIBUTE h323-connect-time 28 string Cisco
    ATTRIBUTE h323-disconnect-time 29 string Cisco
    ATTRIBUTE h323-disconnect-cause 30 string Cisco
    ATTRIBUTE h323-voice-quality 31 string Cisco
    ATTRIBUTE h323-gw-id 33 string Cisco
    ATTRIBUTE h323-incoming-conf-id 35 string Cisco
    I see a lot of stuff comming in, but I don't see any of the attributes above.
    PS. when I do a DEBUG AAA ACCOUNTING here's what I see.
    *Oct 8 18:00:19.681: AAA/ACCT/CONN(00001863): STOP protocol reply FAIL
    *Oct 8 18:00:19.681: AAA/ACCT(00001863): Accouting method=NOT_SET
    Here's my config
    aaa new-model
    aaa group server radius ACS
    server X.X.X.X auth-port 1645 acct-port 1646
    aaa authentication login h323 group ACS
    aaa authentication login no_rad local
    aaa accounting update newinfo
    aaa accounting exec default start-stop group ACS
    aaa accounting connection default start-stop group ACS
    aaa accounting connection h323 start-stop group ACS
    aaa session-id common
    gw-accounting aaa
    attribute acct-session-id overloaded
    attribute h323-remote-id resolved
    acct-template callhistory-detail
    radius-server host X.X.X.X auth-port 1645 acct-port 1646
    radius-server timeout 60
    radius-server key XXXXX
    radius-server authorization permit missing Service-Type
    radius-server vsa send accounting
    radius-server vsa send authentication
    dial-peer voice 447 voip
    destination-pattern 1647280....
    voice-class aaa 1
    session target ipv4:X.X.X.X
    Any ideas?
    thanks,
    Paul

    Try the following command:
    gw-accounting h323 vsa
    See here (http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122newft/122tcr/122tvr/vrg_g1.htm#wp1505752) for details.

  • CiscoWorks: Not receiving syslogs, since we change CiscoWorks server IP Address

    Hi,
    We  are using CiscoWorks 3.2.1. We have changed CiscoWorks server IP  Address, since then we are not receiving syslogs from Devices. Although  devices configurations have also been changed so that they log to new IP  Address e.g. logging new IP Address. But we are not getting syslogs now.
    Rest  all operations of CiscoWorks are working ok. E.g. We can access it from  IE, inventory/config collection working, we can deploy configs etc. But  we are not getting syslogs.
    Also :
    Test Collector Subscription Status
    SSL certificate status   SSL certificates are valid and properly imported
    Collector status       Collector Server_IP_Address is up and reachable.
    but I am not seeing any new alerts receiving here.
    When I do start the SyslogCollector.log/SyslogAnalyzer.log from server, I get below message;
    E:\Ciscoworks\log>net start crmlog
    The requested service has already been started.
    More help is available by typing NET HELPMSG 2182.
    E:\Ciscoworks\log>pdexec SyslogCollector.log
    ERROR: cmd failed. Server reason: Application SyslogCollector.log is not registe
    red.  All requests to operate on this application will be ignored.
    E:\Ciscoworks\log>pdexec SyslogAnalyzer.log
    ERROR: cmd failed. Server reason: Application SyslogAnalyzer.log is not register
    ed.  All requests to operate on this application will be ignored.
    E:\Ciscoworks\log>
    Please advise what need to be changed on CiscoWorks in reference to new IP Address.Its required urgently.
    Thanks

    We have already remove the logging on old IP from devices, and now about 4000 devices are logging to new IP.
    Above mentioned problem is on CiscoWorks only, as its not collecting the syslogs. Below error message might suggest some solution.
    E:\Ciscoworks\log>net start crmlog
    The requested service has already been started.
    More help is available by typing NET HELPMSG 2182.
    E:\Ciscoworks\log>pdexec SyslogCollector.log
    ERROR: cmd failed. Server reason: Application SyslogCollector.log is not registered.  All requests to operate on this application will be ignored.
    E:\Ciscoworks\log>pdexec SyslogAnalyzer.log
    ERROR: cmd failed. Server reason: Application SyslogAnalyzer.log is not registered.  All requests to operate on this application will be ignored.
    E:\Ciscoworks\log>

  • Global Automatic Activity - Process to Process

    Hi,
    How can we invoke another process from one process using a Global automatic activity..Is PAPI the only way? How can we use PAPI code inside of a Global Automatic Activity to call another process?v Any examples?
    Edited by: user647659 on Oct 27, 2008 11:02 PM
    Edited by: user647659 on Oct 28, 2008 11:49 AM

    I am not sure what you saying..Did u mean Global Creation ? But that would have a user to invoke the process..I want to invoke it automatically...I got a part of the answer...But it takes all instances..and creates multiple instances..I want to isolate the instances previously been transferred..What I am doing is ..Using a Global Automatic to invoke the other process.Writing a PAPI code to call the other process from this process...and Polling By Interval every 1m..
    Here is a code:-
    ProcessService ps;
    ps.connectTo(url : Fuego.Server.directoryURL, user : (String)BusinessParameter.getValue(name : "USER_NAME"), password : (String)BusinessParameter.getValue(name : "PASSWORD"));
    logMessage("Process Service connected--->" );
    businessProcess = ps.getProcess(process : "StartProcess");
    InstanceFilter instanceFilter;
    instanceFilter.create(processService : ps);
    SearchScope searchScope = new SearchScope(ParticipantScope.ALL,StatusScope.INPROCESS_AND_COMPLETED);
    instanceFilter.searchScope = searchScope;
    result2 = businessProcess.getInstancesByFilter(filter : instanceFilter);
    logMessage("Length ==>" +length(result2));
    length = length(result2);
    logMessage("Length Transferred==>" +length);
    test["name"] = "testing";
    if(length > 0)
         for(int i=0; i < length; i++)
              ProcessInstance.create(arguments : test, argumentsSetName : "BeginIn");
    else
         logMessage("length is-->" + length);
    length = 0;
    Any suggestions on how to isolate the previous obtained instances would be appreciated..
    Thanks,

  • Your IPad could not activate because the activation server is temporarily unavailable

    Hello!
    I bought a used Ipad model A1397. Connected it to Itunes and upgraded to 6.1.3.
    After that, I can not activate it because it is constantly writes:
      "Your IPad could not activate because the activation server is temporarily unavailable. Try connecting IPad to iTunes to activate, or try again in a few minutes." using WiFi and Itunes. The process of restoring the firmware also did not help ...
    PS Sorry for my bad English!

    Apple is experiencing tevhnical difficulties with APNs
    People in Asia reported this 13 hours ago (http://www.sophos.com/ja-jp/support/knowledgebase/119235.aspx) and people in Europe have been tweeting about it for a few hours. Seems like a global issue with Apple. Unfortunetly Apples services page doesnt list APNs: http://www.apple.com/support/systemstatus/
    MAybe try a little later

  • So i restarted my iPod and it is telling me that the activation server could not be reached! I don't know how to fix it. please help!

    So i restarted my iPod and it is telling me that the activation server could not be reached. And I don't know how to fix it. Please help!!

    Maybe this is applicable
    Try:
    - Powering off and then back on your router.
    - iTunes for Windows: iTunes cannot contact the iPhone, iPad, or iPod software update server
    - Change the DNS to either Google's or Open DNS servers
    Public DNS — Google Developers
    OpenDNS IP Addresses
    - For one user uninstalling/reinstalling iTunes resolved the problem
    - Try on another computer/network
    - Wait if it is an Apple problem
    This says the Activation Servers are on-line
    http://www.apple.com/support/systemstatus/

  • HT4097 Can not restore ipad 2. Unable to connect to activation server, server is temporarily unavailable??

    Can not restore ipad 2. Unable to connect to activation server, server is temporarily unavailable??

    Hi Anson/JimHdk,
    I triple checked to makes sure my SSID and passwords are right.
    I found the MAC Address filter is not turned on...
    I don't think there's maximum number of connection for the router (I turned my 2 other devices on Airplane mode when checking) and it still didn't work. 
    I don't know how to durn off DHCP and use static IP address....
    There's no firmware update available for my router as it's 8 years old....
    My brother says I will need to get a new router....   hopefully that will work....
    Thank you both for offering these additional checks!
    Mary

  • Debug radius local-server

    Hi all!
    Please help me/
    I'm use c181x-adventerprisek9-mz.151-4.M9.bin.
    I'm set AP with local radius server. In official documentation have "debug radius local-server", in ios command reference this command also exits.
    But in my router not have this command.
    This is bug?

    Are you running this command in Privileged EXEC mode, or global config mode? This is a Privileged EXEC command, so when you enter it, your prompt should look like this:
    RouterName# debug radius local-server
    And not like this:
    RouterName(config)# debug radius local-server
    Please also note that since this is a debug command, it will not appear in your device's running-config, and it may not continue running if you reload or power-cycle your device. It will just show debug messages at the console line and/or log them to the logging buffer and/or to an Syslog server, if configured.

Maybe you are looking for

  • How do I access a shared icloud calendar from a PC

    We have a friend with an ipad locked down so they cant add other apps.  They have a calendar they have shared with my gmail address.  the share email says I HAVE to have an icloud account to view the shared calendar so I signed up.  I can log in to i

  • Responses missing column headings

    Hi, My responses, when viewed using the "view responses" tab, or when downloaded as a .csv have lost most of their field headings. The form has 8 field headings.  The view responses / .csv has only two. See below. I understand there are no responses

  • Problem with 3.2.1 update question

    OK, I'm hoping the 'group mind' will have an idea on a solution to this. Short background- I have my iPads synced to my Dell desktop at home where we have Hughesnet satellite Internet, as we live in a rural area. I have my iPod Touch synced to my Ace

  • Why does Firefox not support Trusteer Rapport to download?

    Trusteer website states that Firefox does not support Rapport.

  • Bundeling META-INF\adf\scripts\ or META-INF\adf\images in adf library

    Hi, I need to be able to create an adf library that can also include the following directories. This is to include custom converters. I have not been able to do that. I can however create a regular jar deployment profile that will contain these direc