WLC Mobility Auto-Anchor Code Matrix

Hi guys,
I am involved with a project where I will be upgrading WiSM1s with WiSM2s and moving to the 7.2 code to support the funky new 3600 APs
The question I have is that there are some other foreign controllers of differing flavours 5508/4402 and maybe others that are tunnelled back to the WiSM1s and using these as an auto-anchor - So what are the compatibility options I have here for code support please?
I have been told there is a compatibility matrix but all I can find is the software compatibility matrix, but this does not have anchor specific code details. Maybe this means it dosen't matter but I know it had certain limitations in the past and is now opened up to differing code support since 5.2 (I think), but just not sure now whether things may change again given the next generation 7.2 code now being out.
Thanks
Rocky

Hi Scott,
Thanks for that, I was hoping someone had already set it up!
I was looking at that matrix earlier but it didn't look right to me as according to the table it is supported back to 4.2? I am positive I read this feature only kicked in at 5.2.
Thanks again
Rocky
Sent from my BlackBerry® wireless device

Similar Messages

  • Replace WLC Mobility Group Anchor

    We have 2 5508 and 1 4402 WLCs and all belong to the same mobility group. The 4402 does not have any access points and does nothing more than serve as a mobility anchor for our public wireless SSID. We are planning to replace the 4402 with a new 2504 unit which will have the same configuration including IP as the 4402. Is there anything I need to do with the mobility groups when we remove the 4402?
    Thanks for any help.
    Jeff

    you'll need to add the MAC of the 2504 to the mobility group, and remove the entry for the 4402.
    Out of Curiosity...how many concurrent guest users to you have usually?
    Steve

  • Layer 2 security with WLAN auto-anchor mobility

    Hello,
    I was wondering if Layer 2 security can be used with auto-anchored WLANs.
    I need to deploy two new isolated WLANs which will terminate in two DMZ environments.
    I was hoping to use the existing WCS-managed infrastructure with 4404 and 4402 WLCs and just throw on a couple more WLANs.
    However, I've built a little test environment and while I can get the new VLAN traffic tunneled and origininating from the correct anchor controller with no layer 2 security - as soon as I turn on WEP or WPA security options it stops working. I can't find anything in documents or this forum to show auto-anchor mobility with anyhing other than unsecured guest WLANs.
    Am I trying to do somethng unsupported or is it just an error on my part?

    Hi Greg,
    no, the users are internal so I only want to use L2 security. I can't see that L3 should be a problem to add on though. I'm using 3.2.x of the WLC code - so there is no "Guest LAN" mode - I was playing with the new versions and it looks like L2 security is disabled in that mode?
    If you want to see how I got my bit working I would be happy to share my doco when I'm done.
    regards,
    Aaron

  • AP-manager ip for mobility and anchor?

    I'm setting up wlan solution for a client. It involves mobility group, anchor and without LAG. Anchors are placed in DMZ. Anchors management interfaces are blocked from sending any packet to corporate network wlc.
    Is it possible to configure mobility group using AP-manager IP. If WLCs management interfaces are not connected & only used for management purpose(bloody corporate policy), is it possible to setup wlan using AP-manager ip addresses. Will it have any impact in wlan?
    mobility group member add ----> can we specify ap-manager ip here?
    mobility group anchor wlan add  ---> anchor ap-manager ip here?

    Ramesh,
    If you're talking about a 4400 based controller as your Anchor, then yes, you effectively have an AP-Manager interface taking an IP address.    I've never tried this with respect to an anchor, but it is feasible to have your AP-MGR in a different vlan than your Management interface.  In theory, if you absolutely had no IP address to spare, maybe you could black hole the AP-MGR in a fictitious vlan?    I personally wouldn't do it though, as I'm not sure what the behavior would be if your AP-MGR was never able to talk to its gateway...
    If you're talking about the 5500 based controller (and any future controller that supports being an anchor), you should not have to have an AP-MGR. In fact, the only time you'd have an AP-MGR interface is if you were doing what I said above regarding an AP-MGR in a different vlan.
    Make sense?
    -Wesley Terry

  • FlexConnect (aka H-REAP) and Auto-Anchor functionality

    Hi Board,
    I never did H-REAP on my wireless deployments. Now, I have an H-REAP (FlexConnect) requirement for branch offices.
    Also there is the requirement for guest access at the same time.
    From my understanding those features (FlexConnect and Auto-Anchor) should work together.
    Please refer to the following exibit:
    There is a FlexConnect AP at my branch office. The traffic from internal users (SSID "Internal") should be switches locally at the LAP (Lightweight Access Point). At the same time the guest SSID (SSID "Guest") should be tunneled back via CAPWAP to the controller to which the LAP is associated ("Central Controller"). The guest traffic should not emerge (switched) at the "Central Controller", instead it should be tunneled to an anchor controller in a DMZ via an "Ethernet Over IP tunnel" (Auto-Anchor functionality).
    First question: Does this work (FlexConnect in conjunction with Auto-Anchor functionality)?
    If this works, where's the web portal for guest authentication hosted (if using the internal web auth on WLC)? On the "central controller" or the Anchor controller? (I guess at the Anchor Controller in the DMZ, right?)
    Is it possible to leave the guest SSID "open" with no webauth and still using the Anchor Controller? This would be needed if I have an external web authentication service, which would be hosted by a provider.
    Thanks in advance for all your replies!
    Johannes

    The Flex 7500 deployment guide ("
    http://www.cisco.com/en/US/products/ps11635/products_tech_note09186a0080b7f141.shtml
    ") states:
    "The Cisco FlexConnect Solution also supports  Central Client Data Traffic, but it should be limited to Guest data  traffic only."
    later in the document there is a section about Guest access that states "Flex 7500 will allow and continue to support creation of EoIP tunnel to your guest anchor controller in DMZ."
    Hope that helps.

  • WLC2x06 auto-anchor to 4400 appears to fail

    Hi, has anyone seen this problem, or is this a bug:
    Auto-anchor is configured for guest mobility and has been working fine on a number of 4400 controllers in a mobility group. Guests get auto-anchored to a 4400 with access to the guest DMZ
    we have now introduced both 2006 and 2106 controllers into the mobility group, however clients are net getting DHCP when coming through these controllers.
    debugs show an apparent disinterest on the part of the 4400 to respond to mobility anchor requests from the 2x06, and mobility statistics report increase in 'ignored' requests
    mobility debug on 4400 for unsuccessful request from 2106:
    Wed May 23 15:31:34 2007: Mobility packet received from:
    Wed May 23 15:31:34 2007: 192.168.156.2, port 16666, Switch IP: 192.168.156.2
    Wed May 23 15:31:34 2007: type: 3(MobileAnnounce) subtype: 0 version: 1 xid: 200 seq: 200 len 120
    Wed May 23 15:31:34 2007: group id: dedbb34b 687b56c2 633f1d4d 73ed6709
    Wed May 23 15:31:34 2007: mobile MAC: 00:19:d2:d5:eb:39, IP: 0.0.0.0, instance: 0
    Wed May 23 15:31:34 2007: VLAN IP: 192.168.156.2, netmask: 255.255.255.0
    Wed May 23 15:31:35 2007: Mobility packet received from:
    Wed May 23 15:31:35 2007: 192.168.156.2, port 16666, Switch IP: 192.168.156.2
    Wed May 23 15:31:35 2007: type: 3(MobileAnnounce) subtype: 0 version: 1 xid: 200 seq: 200 len 120
    Wed May 23 15:31:35 2007: group id: dedbb34b 687b56c2 633f1d4d 73ed6709
    Wed May 23 15:31:35 2007: mobile MAC: 00:19:d2:d5:eb:39, IP: 0.0.0.0, instance: 0
    Wed May 23 15:31:35 2007: VLAN IP: 192.168.156.2, netmask: 255.255.255.0
    Wed May 23 15:31:36 2007: Mobility packet received from:
    Wed May 23 15:31:36 2007: 192.168.156.2, port 16666, Switch IP: 192.168.156.2
    Wed May 23 15:31:36 2007: type: 16(MobileAnchorExport) subtype: 0 version: 1 xid: 201 seq: 201 len 244
    Wed May 23 15:31:36 2007: group id: dedbb34b 687b56c2 633f1d4d 73ed6709
    Wed May 23 15:31:36 2007: mobile MAC: 00:19:d2:d5:eb:39, IP: 0.0.0.0, instance: 0
    Wed May 23 15:31:36 2007: VLAN IP: 192.168.156.2, netmask: 255.255.255.0
    Wed May 23 15:31:36 2007: Received Anchor Export request: 00:19:d2:d5:eb:39
    from Switch IP: 192.168.156.2
    Mobility debug on 4400 with successful request/resonse from another controller:
    Wed May 23 15:31:41 2007: Mobility packet received from:
    Wed May 23 15:31:41 2007: 192.168.160.13, port 16666, Switch IP: 192.168.160.13
    Wed May 23 15:31:41 2007: type: 16(MobileAnchorExport) subtype: 0 version: 1 xid: 243028 seq: 29509 len 244
    Wed May 23 15:31:41 2007: group id: dedbb34b 687b56c2 633f1d4d 73ed6709
    Wed May 23 15:31:41 2007: mobile MAC: 00:12:f0:82:57:00, IP: 0.0.0.0, instance: 0
    Wed May 23 15:31:41 2007: VLAN IP: 192.168.160.13, netmask: 255.255.255.0
    Wed May 23 15:31:41 2007: Received Anchor Export request: 00:12:f0:82:57:00
    from Switch IP: 192.168.160.13
    Wed May 23 15:31:41 2007: Received Anchor Export policy update, valid mask 0x0:
    Qos Level: 3, DSCP: 0, dot1p: 0 Interface Name: , ACL Name:
    Wed May 23 15:31:41 2007: Mobility packet sent to:
    Wed May 23 15:31:41 2007: 192.168.160.13, port 16666, Switch IP: 192.168.160.12
    Wed May 23 15:31:41 2007: type: 17(MobileAnchorExportAck) subtype: 0 version: 1 xid: 243028 seq: 40918 len 272
    Wed May 23 15:31:41 2007: group id: dedbb34b 687b56c2 633f1d4d 73ed6709
    Wed May 23 15:31:41 2007: mobile MAC: 00:12:f0:82:57:00, IP: 192.168.191.16, instance: 1
    Wed May 23 15:31:41 2007: VLAN IP: 192.168.191.2, netmask: 255.255.255.192
    Wed May 23 15:31:41 2007: 00:12:f0:82:57:00 192.168.191.16 WEBAUTH_REQD (8) Plumbing duplex mobility tunnel to 192.168.160.13
    as Export Anchor (VLAN 191)
    all help appreciated!
    Graeme

    Hello
    I don?t think the 20x6 controller support that.
    http://www.cisco.com/en/US/docs/wireless/controller/release/notes/crn40216.html#wp44028
    These software features are not supported on 2000 and 2100 series controllers:
    ?Termination of guest controller tunnels (origination of guest controller tunnels is supported)

  • Is local EAP + Web Authentication possible in Auto Anchor Configuration

    Hi,
    I have a wireless network setup in an auto-anchor configuration with the foreign and anchor controllers. Due to the foreign controller being owned and managed by another company, I have an interesting authentication scenerio I would like to acheive. We can't implement full EAP-TLS as we would have to allow authentications from the foreign controller which is owned and managed by another company.
    Currently Web Authentication is working correctly for the Wireless Network. As another layer of security, I want to know if its possible for the wireless clients to trust a certificate installed on the foreign controller?  If so, are you able to point me in the direction of a user guide to implement.
    I found the following document which describes local EAP configuration . Would this work with Web Authentication?
    Thanks

    so, kinda but no.  EAP is a layer 2 authentication that uses encryption as well.
    WebAuth is a layer3 authentication only.
    Now the kinda....you can create guest/network users on the WLC local database, and if someone logins to the webauth portal with those credentials they will be able to get on.
    I'm not really sure what you are looking to do based on your post.
    Personally, if I had users that were going to roam to this controller, I'd work with that companies IT and get it linked to my AAA server and keep the EAP-TLS that I had working already going. Just because that WLC would be able to communicate to your AAA doesn't mean their users would be able to get on, as they wouldn't have the machine or client certificate nor the Root CA cert on their machines.
    HTH,
    Steve

  • Auto generated code in makefile

    For our product we have a TCL script that reads a series of text files and generates C++ classes for easy access to database records. Our code has been in use for make years and works very well. We have always used a solaris command prompt dmake to compile, which first generates the C++ files then complies them. It uses a series of enviroment variables which a user must set before compilation.
    I recently tried to create a Sun Studio Express based on NetBeans 6.5.rc1 project from a make file. This has worked for every other makefile except for this one. The others do not have any auto generated code.
    To run sun studio I in a command prompt source in the environments then run netbeans. Then I choose to build the product but I get an error. I then try to copy the command it is running into telnet window and it works fine. Does anyone have an idea on why in the sun studio I get and error while the telnet window works fine.

    I think the problem is that the SunStudio IDE runs the build command in a wrong directory.
    Can you verify that the working directory is correct?
    (it is in project properties: Build > Make)
    Also you can find this directory in the message in the output, when you try to build the project.
    That's the message, that you copied to the terminal window.
    Thanks,
    Nik

  • Flash Builder 4.5 Auto-Gen Code For PHP Data Service Produces Errors

    Hello
    I'm currently running a fresh install of MAMP on my Mac and when I start a new flex project, add a php data service that pulls from a mysql database I have. Everything works fine until I try to compile. The error I'm getting is 'uid' being the primary key which is a bigint(20). The file _Super_Users.as (auto-gen based on the user table below) reports 2 errors: [Managed] requires uid to be of type 'String'. (same error on 2 lines of code) Now the MySQL table wants it to be a int, the auto gen code seems to want it to be an int as well but for some reason its putting in these requires for String on the getter and setters for 'uid'. The is before I even add any of my own code, just auto-gen then compile.
         * data/source property getters
    [Bindable(event="propertyChange")]
        public function get uid() : int /*error line*/
            return _internal_uid;
         * data/source property setters
        public function set uid(value:int) : void /*error line*/
            var oldValue:int = _internal_uid;
            if (oldValue !== value)
                _internal_uid = value;
    This is what my database looks when I export it:
    CREATE TABLE `users` (
      `uid` bigint(20) unsigned NOT NULL,
      `name` varchar(150) NOT NULL,
      `first_name` varchar(50) NOT NULL,
      `middle_name` varchar(50) NOT NULL,
      `last_name` varchar(50) NOT NULL,
      `gender` tinyint(1) NOT NULL,
      `locale` varchar(5) NOT NULL,
      `link` varchar(255) NOT NULL,
      `username` varchar(50) NOT NULL,
      `email` varchar(255) NOT NULL,
      `picture` varchar(255) NOT NULL,
      `friends` text NOT NULL,
      `created` datetime NOT NULL,
      `updated` datetime NOT NULL,
      PRIMARY KEY (`uid`)
    ) ENGINE=InnoDB DEFAULT CHARSET=latin1;
    It's empty right now...
    Apache 2.0.64
    MySQL 5.5.9
    PHP 5.2.17 & 5.3.5
    APC 3.1.7
    eAccelerator 0.9.6.1
    XCache 1.2.2 & 1.3.1
    phpMyAdmin 3.3.9.2
    Zend Optimizer 3.3.9
    SQLiteManager 1.2.4
    Freetype 2.4.4
    t1lib 5.1.2
    curl 7.21.3
    jpeg 8c
    libpng-1.5.0
    gd 2.0.34
    libxml 2.7.6
    libxslt 1.1.26
    gettext 0.18.1.1
    libidn 1.17
    iconv 1.13
    mcrypt 2.5.8
    YAZ 4.0.1 & PHP/YAZ 1.0.14
    I tried to give as much info as possible, if you need more let me know...

    I discovered my problem was uid seems to be a built in global or something and was filling in that data field with a bunch of letters and number, like the device id. Because of the letters flex was throwing a fit. So if you're using Facebook API in flex be sure to not go with uid for the user id, which is was facebook api calls it.

  • Cisco Auto Anchor Web Authentication - NAS IP Address

    Hi,
    I've setup auto anchor web authentication for my guest network. I want my Web Authentication requests to be authenticated by ISE however need the authenticating device to be the Anchor Controller.
    I setup the WLAN to authenticate against ACS4.2 and it works correctly, the NAS IP address is the Anchor controller. When changing the WLAN to auth again my ISE 1.2 server, authentications are sourced from the foreign controller.
    Has anyone come across this or know why ISE is seeing the NAS IP Address as the foreign wireless controller?
    Thanks,

    Hi,
    I've setup auto anchor web authentication for my guest network. I want my Web Authentication requests to be authenticated by ISE however need the authenticating device to be the Anchor Controller.
    I setup the WLAN to authenticate against ACS4.2 and it works correctly, the NAS IP address is the Anchor controller. When changing the WLAN to auth again my ISE 1.2 server, authentications are sourced from the foreign controller.
    Has anyone come across this or know why ISE is seeing the NAS IP Address as the foreign wireless controller?
    Thanks,

  • WLC 5508 multiple country codes, limitations

    Hi CSC,
    Currently we are running 2x 5508 (7.2.111.3) in our Regional DC and all AP's from APAC are connected in H-REAP mode.
    On each WLC the following country codes are configured:
    Configured Country Code(s):
    CN, ID, IN, J2, J3, J4, JP, KE, KR, PH, PH2, TH, TW
    Regulatory Domain:
    802.11a:      -ACEJKNPTU
    802.11bg:    -ACEJP
    We have some sites (mainly China), which facing issues on WLAN recently (slow performance, weak signal..etc.
    RF & power level are 'managed' by WLC.
    After reviewieing some sites with our vendor, the feedback to improve stability/perfromace, was to either run just 1 country code/WLC..or set RF/power level manually for each AP. (which of course would be an admin nightmare!!)
    I havent found the same information on cisco.com & thought connecting AP's from different country's to the same WLC works well (incl. having the WLC manage power/rf)?
    Are there any limitations, when having multiple country codes on same WLC?
    Appreciate your feedback.
    Thanks,
    Stefan

    As far as I remember, every AP with a different country code have different permissible level of power and a regulatory authority board monitors these. So in case you wanna mix the AP with different codes, it will choose the ones with lower power level and operate which might not be to your advantage since the users might want to operate at higher power level. So, you can find out the permissible level of Transmission power and group AP with same level together and get another WLC. Also, run a site survey to check for interference. Might help
    Posted by WebUser Shalini Menon from Cisco Support Community App

  • HT4993 hello i would like to ask .. how much need to know mobile phone's code? thank you

    i would like to ask .. how much need to know mobile phone's code? thank you

    Did you already try the suggestions from this article?
    Symptoms
    In certain situations, iPhone may present one of the following symptoms:
    "Invalid SIM" or "No SIM Card installed" alert appears intermittently.
    Status bar displays "No Service", "No SIM" or "Searching" in a location with good network coverage.
    Resolution
    If you encounter any of the above symptoms on your iPhone, try these steps to attempt to resolve the issue:
    Update your iPhone to the latest version of iOS.
    Toggle Airplane mode On and Off.
    Try turning iPhone off and then on again.
    Check for a carrier settings update. Tap Settings > General > About. If an update is available, a prompt will appear.
    Remove the SIM Card and verify that it is a valid, carrier-manufactured SIM. Also verify that it is not damaged, worn, or modified. Then reinsert it.
    Restore the iPhone.
    copied from iPhone: Troubleshooting No Service or No SIM

  • WLC Channel Auto setting vs. Channel Manual

    Hi,
    Regarding the subject, anyone can enlighten me which one is better for setting the channel assignment of Lightweight on WLC?
    Does it better to use "Auto" or manually setting the channel/power on each individual AP.
    Thanks,

    Thanks Scott.
    Wondering about the accuracy of WLC's auto settings.
    I observe two adjacent APs got a same channel and power assignment from the Controller. I am worry about interference caused by channel overlapping.
    Sent from Cisco Technical Support iPhone App

  • Mobile Scanning/QR codes in ATG 10.1

    Hey all,
    Does everyone know if ATG 10.1 supports Mobile Scanning/QR codes OOTB with their Mobile Ref App? Or is this something that will require significant extension/customization?
    Thanks

    Hi,
    I'm the product manager for the ATG 10.1 mobile reference applications. Need to clarify some serious misunderstandings about the product posted in this thread.
    1. The ATG mobile 10.1 solution is NOT based on the Endeca mobile solution.
    2. The ATG mobile 10.1 solution is NOT integrated with the Endeca solution.
    3. Endeca has a mobile solution that is a separate SKU on the price list (Endeca for Mobile).
    4. We are working on an integrated ATG and Endeca mobile solution but that is a future roadmap item. The integrated solution will be available at a TBD date.
    5. The ATG mobile storefronts are based on the ATG Commerce Reference Store.
    6. The ATG mobile 10.1 storefronts do NOT contain the QR code/mobile scanning feature -- that is a high-priority roadmap item.
    Nivedita

  • Can I make auto layout of Matrix Chart after setting fixed rows/columns ?

    Can I make auto layout of Matrix Chart after setting fixed rows/columns ?
    I want to make Matrix Chart to auto layout to zooming out a chart of filter.
    Matrix Chart's layout is AUTO layout at creating.
    Matrix Chart layout can fix specfic rows / columns from layout toolbar.
    BUT fixed layout's Matrix Chart does not zoom a chart of filter.
    Regards,
    Yoshihiro Kawabata
     

    Hi Yoshihiro - at the moment if a specific number of row/columns has been set for small multiples the chart will maintain these proportions even after filtering.
    If the chart hasn't had a set row/column dimensions set it will automatically be re-laid out when filtered however.

Maybe you are looking for

  • Here's my experience

    So My b210 for some unknown reason has stopped working with my ipad I reset to factory It tells me to log on to eprint I go to log on Hp eprint tells me i ***HAVE*** to combine by existing snapfish account that i never even knew i had let alone used.

  • HT2589 Getting an error when updating my iphone user id already in use

    I recently got my iphone and after I updated the new IOS6 version , I keep getting an error message. This Apple ID is already in use and it asks me to reset my password which I have done a couple of times. Any idea how I can fix this ?

  • Lost mozilla symbol on startup.Can'tgo to website. HELP

    the symbol on the startup,that you click to go to the website is suddenly gone and I can't figure out how to get the symbol back.Thanks for any help

  • B2B - HIPAA 834

    Te requirement is to send - 004010X095A1 in GS08 of 834 file (Outbound) When I choose EDI , X12 , 4010 as the specification it generates 004010 in GS08 We are using BPEL , even if i override the internal properties , it still generates 004010 in GS08

  • Access pre-insert data using ViewObjects

    Hi, I'm trying to access pre-insert data (before super.doCommit() execution) using viewobjects, but I only obtain committed data. Is it possible to obtain pre-insert data using viewobjects? Here the Java code: String amDef = "oracle.srdemo.model.AppM