WLC Physical COnnection and security

Currently our wireless environment inclued 1200ap and a wds. we have maxed our and want to upgrade to a more conrolled environment. I am suggesting and putting togather a diag. for 4404 wlc and the ap will work with the version 12.3.7 version. My question is about the physical design. Will all 4 ethernet port on the WLC connect to the switch? all on the same vlan as the AP's? also we are using eap-tls Want to migrate to eap-Fast does this require a foot print on the client laptop?

The ports on the 4404 will trunk with the switch. You can put them in LAG mode which is the equivilent of ehterchannel. You will have to put the switch ports in trunk mode either way.
You don't have to connect all 4 ports, but it is recommended for failover & maximum possible AP support. You will need assign the management interface on the 4404 (ap-management interface if operating Layer-3 mode) to a vlan/subnet that
the APs will reside in. All other dynamic interfaces that you create on the controller to bind with wlans will reside in other vlans that get pushed thru the trunk links between the 4404 & the switch(s). be sure to prune out any vlans that you don't need or want to cross the trunk to the 4404. for lwapp APs assign the switch-ports that the APs connect to the same vlan as the management ports on 4404. Not sure about your 1200s. It will work if you trunk the interfaces to the APs as well, but that is more of a shotgun approach for lwapps APs. the last time I had to work with an autonomous AP, it was a stand alone unit and not combined with a WLC. That scenario required a trunk link.
have you confirmed that you can convert your 1200s to lwapp mode?
Correct me if I am wrong, but I believe you will need to place a cert on the client laptops for eap-tls. I did this a while back using XP & freeradius and got it to work, but it has been a while.

Similar Messages

  • How to find the Connection and Security Code for iPad?

    I have a Canon ImageRunner 3025 at the office. I want to connect it with my iPad. I've downloaded the Canon Print & Scan App, but the app requires a Connection code and Security code.  Where can I find this on the printer? 

    Hi, thanks for posting! Canon does not provide direct support for imageRUNNER series products, but your dealer will be able to help you! If you don't have a dealer, please call us at 1-800-OKCANON (652-2666) and we will be happy to provide dealers who are in your area.

  • Web connectivity and security in Oracle 8i

    How can i make Web Connectivity with Oracle 8i database.
    Junaid Tareen

    <BLOCKQUOTE><font size="1" face="Verdana, Arial">quote:</font><HR>Originally posted by [email protected] ():
    What do you mean by data level security?
    Can you give an example and explain your query?<HR></BLOCKQUOTE>
    When giving him permissions to users on a table I want that the user can manipulate only certain columns and that the others are restricted for him. If it is connected by application, SQL, ODBC, etc. That it always has activates the restrictions on the data of those columns.
    Ej.
    I have a table with 5 columns, need to give permissions him of select to users on that table but single desire to show the users columns to him the 1,2 and 3.Las others will remain restricted for those users until it is decided to assign them.

  • I use Time Capsule and Airport for my wireless connection and my speeds stink!

    I am getting horrible speeds (250K downloads) any suggestions. I have the time capsule and the Airport for my wireless connection and I have a new MacBook Pro. My download speeds are about 250K. I have turned off my wireless and plugged into my network with a physical connection and I get great speeds so something is wrong wiht my wireless connection /setup......any suggestions?

    Yep much better.
    I recommend the following ..
    Set wireless and TC names to SMB standard.. short, no spaces.. pure alphanumeric.
    Lock the wireless channels and set a different name for 5ghz and also lock its channel.
    Use only WPA2 Personal security with a decent passkey.. generally 8-12 characters is plenty. Still follow the rules.. pure alphanumeric mix of upper lower case and numerals..
    If that does not improve things.. how old is the TC.. the wireless output does seem to slide as they age.
    A simple WAP connected to the TC can provide far superior wireless for very little money.

  • ITunes keeps popping up fr no reason with nothing connected and it is driving me insane, any suggestions?

    iTunes keeps popping up for no reason with nothing connected and it is driving me insance, any suggestion?
    I have tried rebooting and this hasnt helped.

    vivianalozano wrote:
    I assume that a neighbour has an iphone that tries to sync to my itunes repeteadly making the window pop up every 5 minutes...
    That really is not likely since the device would have to have at one time been physically connected and synced to your computer, AND Wi-Fi sync enabled while connected to your library, AND they'd have to be on your Wi-Fi network.  Unless you have someone who did all this and lives within Wi-Fi range, and knows your network password, that's not what's happening.
    Do you have any auxillary software add-ons to iTunes (e.g. Last.fm scrobbler)?  Sometimes those get in the way of shutting iTunes down and it will re-open unless you shut the other software down first.

  • 2125 WLC Dynamic interfaces and their physical interface

    I'm trying to broadcast multiple SSIDs per AP. I would like the new second SSID to be on a different VLAN. I have been reading this article http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a00805e7a24.shtml#dyn-interface and it looks like you create a trunk port on the switch that the WLC is connected to, which makes sense to me. A friend however told me to use a seperate physical interface on the WLC and assign the dynamic interface to it and connect it to the desired VLAN, instead of using the interface that is currently in production. I liked this idea because I would have downtime trying to reconfigure the port as a trunk that's in production.
    So I guess my question is, if I use a secondary port on the WLC to connect to a different network than what the AP is on how will communication work? When the AP sends data to the WLC will everything be encapsulated in CAPWAP? How about the primary link connecting the WLC to the primary production network? Will this data to and from the WLC on the switch retain it's CAPWP encapsulation? Now that I'm thinking about it I guess it would have to since the WLC is what decapsulates the CAPWAP data and not the switch...
    I would just like some advice on if I'm doing this correctly. Thanks a lot!  -Mark

    We generally recomment one trunk port to be configured for different VLAN (for management and AP inetreface) but we can use other ethernet port also on WLC for any differnt VLAN config.
    For all your port related queries please find the attach link with the diagramme.:-
    http://www.cisco.com/en/US/docs/wireless/controller/7.0/configuration/guide/c70mint.html
    Q. How does a WLC switch packets?
        A. All the client (802.11) packets are encapsulated in a LWAPP packet by the LAP and sent to the WLC. WLC descapsulates the LWAPP packet and acts based on the destination IP address in the 802.11 packet. If the destination is one of the wireless clients associated to the WLC, it encapsulates the packet again with the LWAPP and sends it to the LAP of the client, where it is decapsulated and sent to the wireless client. If the destination is on the wired side of the network, it removes the 802.11 header, adds the Ethernet header, and forwards the packet to the connected switch, from where it is sent to the wired client. When a packet comes from the wired side, WLC removes the Ethernet header, adds the 802.11 header, encapsulates it with LWAPP, and sends it to the LAP, where it is decapsulated, and the 802.11 packet is delivered to the wireless client. For more information about this, refer to the LWAPP Fundamentals section of the document Deploying Cisco 440X Series Wireless LAN Controllers.
    Q. What are the various options available to access the WLC?
        A. This is the list of options available to access the WLC:
            GUI access with HTTP or HTTPS
            CLI access with Telnet, SSH, or console access
            Access through service port
        For more information on how to enable these modes, refer to the Using the Web-Browser and CLI Interfaces section of the document Cisco Wireless LAN Controller Configuration Guide, Release 5.1. Usually, the management interface IP address is used for GUI and CLI access. Wireless clients can access the WLC only when the optionEnable Controller Management to be accessible from Wireless Clients is checked. In order to enable this option, click the Management menu of the WLC, and click Mgmt via Wireless on the left-hand side. WLC can also be accessed with one of its dynamic interface IP addresses. Use the config network mgmt-via-dynamic-interface command to enable this feature. Wired computers can have only CLI access with the dynamic interface of the WLC. Wireless clients have both CLI and GUI access with the dynamic interface.

  • Deploying and testing an app without physical connect

    Hello,
    under https://developer.apple.com/library/ios/documentation/IDEs/Conceptual/AppDistrib utionGuide/TestingYouriOSApp/TestingYouriOSApp.html
    there is a chapter:
    Installing Your App on Test Devices
    Before you distribute your app to testers, follow the steps that testers use to install and run the app on their devices. Use iTunes to install the app on a nondevelopment device. iOS extracts the embedded ad hoc provisioning profile in your app and installs it on the device for you. Then test your app on the device.
    Follow these steps to install the app on a testing device.
    Finally, send the iOS App Store Package file to testers......
    Is it possible testing and deploying an app without physical connection to a computer (security risk etc.)?
    An example: Upload the app-file to a developer-environment in the app-store and then download to the iPhone.
    Thanks and greets
    Oliver

    Ok I figured this one out with help form Kapil (thanks Kapil).
    Here are a few lines of code that is needed:
    <s:HTTPService id="myPersonalInfo" fault="faultHandler(event) resultFormat="e4x" result"personalInfo(event)"/>
    Then create a function e.g.
    private function requestPersonalInfo():void{
    domainUrl="your url.com";
    personalInfoRequest="";
    personalInfoRequest=domainUrl+api_xml_string;
    personalInfoRequest+="common-info";
    myPersonalInfo.url=personalInfoRequest;
    myPersonalInfo.send();
    private funtion personalInfo(event:ResultEvent):void{
    personalName=event.result.common.user.name;
    Username.text="Welcome" + personalName;
    Thats it.

  • Clients unable to connect and get DHCP - LAP1142N AP and 5508 WLC

    Hi,
    I have 19 locations, each with 1 or more LAP1142N AP's in FlexConnect mode, AP's are primed using CAPWAP to my 5508 WLC at the datacenter. The AP's join the WLC without issue every time. I have two WLAN's, one guest and one staff, the guest network is open and obtains DHCP from a WatchGuard XTM33 firewall at each of the remote locations. The staff side is WPA2/RADIUS and DHCP is assigned from the WLC. Each AP is assigned a static IP that is not in the DHCP scope. For example: DHCP scope on the branch firewall is 192.168.1.10-250 the AP will be assigned static IP of 192.168.1.1.. The AP's are connected to a HP procurve switch that has a untagged VLAN, the firewall is using the native vlan 1 and so is the AP.
    I have been running this network for over a year and it has not had a single issue until the last two weeks. Nothing on the network has changed or has been upgraded.
    Now for the issue: The issue I am seeing is that clients are no longer able to connect to the AP and do not get DHCP assigned to them. I am able to get it working, if I remove the static IP from the AP, the AP will reboot, join the controller, then begin working, users can connect and DHCP is assigned from the firewall as it should. However, If the AP then reboots, the AP will join back to the controller but no clients can connect nor do they get a DHCP address. So, I then reassign a static IP to the AP again and it reboots, connects to the controller and clients then can connect and get DHCP.
    Attached is a running config from one of the APs
    I've found several posts on this topic, in fact the patch of unassigning or reassigning static IP is one that I found. However, I wanted to post this to see if there is any further assistance I can get on this. I am also waiting on my SmartNet to start up and will be contacting Cisco support as well.
    Thanks for any help.

    Alright, so I finally figured out the issue with this. I had a Mobility Anchor set on the guest WLAN and once I removed that all started working again.
    What is Mobility Anchor?
    A. Mobility Anchor, also referred to as Guest tunneling or Auto Anchor Mobility, is a feature where all the client traffic that belongs to a WLAN (Specially Guest WLAN) is tunneled to a predefined WLC or set of controllers that are configured as Anchor for that specific WLAN. This feature helps to restrict clients to a specific subnet and have more control over the user traffic. Refer to the Configuring Auto-Anchor Mobility section of Cisco Wireless LAN Controller Configuration Guide, Release 7.0 for more information on this feature.

  • The HP (USB connected) and Epson (wireless) printers keep losing their connection with my Mac mini.  I have to physically disconnect the HP and then reconnect for the Mac to find it.  Turning off the wireless Epson doesn't work.  All software is updated.

    My HP (USB connected) and Epson (wireless) printers keep losing their connection with my Mac mini.  I have to physically disconnect the HP and then reconnect for the Mac to find it.  Turning off the wireless Epson doesn't resolve anything.  All software/drivers have been updated.

    My HP (USB connected) and Epson (wireless) printers keep losing their connection with my Mac mini.  I have to physically disconnect the HP and then reconnect for the Mac to find it.  Turning off the wireless Epson doesn't resolve anything.  All software/drivers have been updated.

  • All websites including Firefox have security warning "the information you entered is to be sent over an unencrypted connection and could be seen by a third party" Firefox is not safe date started July 1, 2010 even when I remmove the security warnings the

    security warning "the information you have entered is to be sent over an unencrypted connection and could be seen by a third party" this warning appears on ALL websites, including all Firefox sites, happened after a MSupdate on July 1, 2010. I wont use Firefox is is not safe - hwat happened?
    == This happened ==
    Every time Firefox opened
    == july 1, 2010

    Ignore that warning. Report it to the Website Developers of the websites on which you are seeing this message. Ask them to deploy Secure HTTP Connection. And use secure Websites (https) addresses.
    Site Identity Button
    * https://support.mozilla.com/en-US/kb/Site%20Identity%20Button

  • UPD, Black Screen, and Securing connection

    Hello All,
    I have configured a Server 2012 R2 RDS setup. I have the RDCB's in HA and have allowed access to the collection (Pooled Desktop) via the RDWA server. All of the connections come from Windows 8.1 to windows 8.1 stations in the pool. UPD's are configured and
    hosted on a share on a secondary server. Most of the time everything works correctly; however, when I do have issues it is one of the following 3.
    1. The user logs in and gets a temporary profile. The cause is that the UPD is locked from the last log on. There is no way to remove the lock without restarting the UPD server; however, this causes every now log on to get a temp profile until the server
    is back on line.
    2. The user logs into the system and instead of the desktop are presented with a black screen and a mouse pointer. I found a reference to this being linked to the loading of the UPD as well but I have not been able to prove this yet. (http://jjstellato.blogspot.ca/2014/06/are-you-thinking-of-using-user-profile.html)
    3. The last issue is when a user clicks the collection icon on the RDWA page it starts to load the rdp connection and it gets stuck at securing connection. It will just sit a securing connection forever. I am using a wildcard certificate for this setup that
    we have purchased. 
    All of these issue are intermittent and usually hard to reproduce on a consistent basis, so if anyone has any ideas on any of these please let me know.
    Thanks,
    Scott 

    Hi Scott,
    For temporary profile issue you can delete the registry key once and then check the result as per bow article.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
    ProfileImagePath: Find specified user name and delete it and restart to verify the result.
    RDS 2012: Profile Disks and Temp Profiles
    As you have purchase wildcard certificate, but please check that the certificate is placed under local computer/Personal store folder and also place under “Trusted root certificate” check the box “Allow the Certificate to be added to the Trusted Root Certification
    Authorities store on the destination computers. Please go through this article for certificate related case.
    - Configuring RDS 2012 Certificates and SSO
    - Certificate Requirements for Windows 2008 R2 and Windows 2012 Remote Desktop Services
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • Physical Connectivity from Fabric Interconnect to MDS and Failover please suggest

    Dear Team
    We have 2 FI and 2 MDS 1 SAN
    Currenlty the connectivity is
    2 direct physical connections from FI-A to MDS1
    2 direct physical Connections from FI-B to MDS2
    From MDS 1 connection to SAN Primary controller
    From MDS 1 connection to SAN Secondary controller
    From MDS 2 connection to SAN primary controller
    From MDS 2 connection to SAN Secondary controller
    Hope the above connectivty is fine?
    we had looked at
    http://www.cisco.com/en/US/prod/collateral/ps4159/ps6409/ps5990/white_paper_c11_586100.html (as team always preferred to go via cisco standards)
    In FI we have to cluster the FI and Primary and Subordinate,likewise here for MDS to we need to? or will it be done via FIs ?
    If not these 2 MDs they work independent but sharing the configs that happens among them?
    Now what ever changes (Zone Creation)we make on MDS1 hope that will get relpicated to MDS2 via FIs?
    If MDS1 Fails will all the configuration be available on MDS2 and still the infra will be smooth running ? and vice versa?
    Any additional steps to be done to achieve it?
    Which is the best way to achieve it please suggest
    Thanks and Regards
    Jose

    Hi Jose.
    Physically your connectivity is good.
    On the UCS side, the 'Primary' and 'Subordinate' role refer only to the Management of the system and which device is actually running UCS Manager.
    Each MDS device will have separate configuration (zoning).  It's different between the 2 devices.
    The blade itself will have a connection out each side, or 'SAN Fabric'.
    e.g.
               +----+
           +---+    +-----+
           |   |    |     |
           |   |    |     |
           |   |SAN |     |
           | +->----<--+  |
           | |         |  |
           | |         |  |
       +---+-+-+    +--+--+--+
       |       |    |        |
       |MDS-A  |    |MDS-B   |
       +--^-^--+    +---^-^--+
          | |           | |
       +--+-+--+    +---+-+--+
       |       |    |        |
       |UCS-A  |    | UCS-B  |
       +--+----+    +-----+--+
          |               |
          |               |
    VSAN100    +-----+    | VSAN200
          |    |     |    |
          +---->     <----+
               |Blade|
               +-----+
    The blade will have a HBA on FabricA (VSAN100) and FabricB (VSAN200)
    Each HBA will have a different WWPN, and on the SAN array, each controller will have a WWPN
    So on MDS-A, the zoning will be:
    Blade WWPN A
    Storage WWPN Primary A
    Storage WWPN Secondary A
    MDS-B, the zoning will be:
    Blade WWPN B
    Storage WWPN Primary B
    Storage WWPN Secondary B
    So the configuration is *not* synced between the two MDS devices, but they each have visibility to the blades vHBA device.  At the blade level, the Multipathing software on the Operating System will handle any failover.
    On the UCS, we would generally use a Port Channel up to the MDS.

  • How do I physically connect the SCXI 1180 when using a 1520 and 1346 adapter?

    Here's my current configuration:
    SCXI 1000 chassis
    x2 SCXI 1520 Bridge Modules (Slot 1, and Slot 2)
    1180 Feedthrough panel.
    I recently purchased a 1346 adapter so I can use the feedthrough to access AI channels on the DAQ card.
    My question is, how do I physically connect the ribbon cable of the 1180? Does it plug into the BACK of the last module in the chassis (ie. bridge module2 in slot 2) or does it plug into the other 49pin connector on the 1346 adapter?
    If you read the installation manual for the 1180 http://www.ni.com/pdf/manuals/371062a.pdf (Page 2-3)
    And the installation manual for the 1346 http://www.ni.com/pdf/manuals/320722b.pdf (page 2)
    it seems the instruction contradict eachother. The 1180 manual says connect it to the back of the module
    the note under Fig.2 on page 2 of the 1346 says you cannot have anything plugged into the module next to the one that has the 1346 plugged into it; in my case that's module 2...
    SCXI- 1000 Chassis w/ 1346 adapter
    PCI 6281 DAQ card
    SCXI- 1520 Bridge Board w/ 1314 Terminal Block (x2)
    SCXI- 1180 Feedthrough Panel w/ 1302 Block
    Signal Express 2014.
    Win7 Enterprise

    I have the 1346 plugged into the first module in slot 1.
    But let me try and clairfy what you're saying...
    "Then the cable from the 1346 kind of loops back into the chassis and through the 1180". So this is my answer? But I'm actually taking  the cable from the 1180 and plugging it into the other 49-pin connector on the 1346. Sorry, symantics...
    "...it must be on the first card when using a 1520". By "it" are you referring to the 1346 (which is how it's currently configured) or the 1180 cable?
    and lastly; why does the 1180 need to go into slot 2? I can currently fill both slots (1&2) with the 1520's and with the 1346 plugged into module1/slot1, I can pass the ribbon cable around back of module2 and into the 1346.
    Is there some other reason beside potential space limitations that you'd use the feedthrough in slot2?
    Thanks for your info and patience!
    Message Edited by OKors on 03-31-2010 12:50 PM
    SCXI- 1000 Chassis w/ 1346 adapter
    PCI 6281 DAQ card
    SCXI- 1520 Bridge Board w/ 1314 Terminal Block (x2)
    SCXI- 1180 Feedthrough Panel w/ 1302 Block
    Signal Express 2014.
    Win7 Enterprise

  • JEditorPane and Secure Connection failed

    Hello,
    I have created a simple application that shows the resulting HTML page from a URL connection using JEditorPane. This works fine except when I try to connect to a URL that needs a user name and password.
    Using a straing URL connection I am able to connect but when I try to use the JEditorPane there is no method, as far as I know to get the connection and pass it to the EditorPane to use. I have tried the following :
    context is with in a class that Extends the JEditorPane:
    setContentType("text/html");
    InputStream is = getSecureInputStream(username,password,tmpStr); // returns an input stream from
    // a URL connection
    HTMLDocument doc = (HTMLDocument)getDocument();
    this.read(is,doc); // try to get the JEditorPane to
    // read from the input stream
    I get the following error:
    error:Must insert new content into body element-
    java.lang.RuntimeException: Must insert new content into body element-
    at javax.swing.text.html.HTMLDocument$HTMLReader.generateEndsSpecsForMidInsert(HTMLDocument.java:1878)
    at javax.swing.text.html.HTMLDocument$HTMLReader.<init>(HTMLDocument.java:1854)
    at javax.swing.text.html.HTMLDocument$HTMLReader.<init>(HTMLDocument.java:1729)
    at javax.swing.text.html.HTMLDocument$HTMLReader.<init>(HTMLDocument.java:1724)
    at javax.swing.text.html.HTMLDocument.getReader(HTMLDocument.java:125)
    at javax.swing.text.html.HTMLEditorKit.read(HTMLEditorKit.java:228)
    at javax.swing.JEditorPane.read(JEditorPane.java:504)
    at javax.swing.JEditorPane.read(JEditorPane.java:478)
    at com.UrlChecker.EditorPane._$10273(EditorPane.java:98)
    Thank you

    i can't find how to fix in the See Secure Connection Failed page, that's why i post my question.someone helps me pls!!!

  • Safari and secure connections

    Hi all
    My MacBook has quite literally in the last few minutes developed an issue which I thought was long dead. It won't connect to secure sites. I couldn't even post this message using Safari as I couldn't log in!
    Has anyone had this on Tiger? Fixed it? Really could do without this problem!

    Well guys
    After rebooting 4 times but making no changes of any kind... it's now accessing secure sites, although very slowly. At the moment this computer appears to be going through some kind of episode, simple things aren't working properly or going very slowly.
    For example, Apple+w to close a windows on everything... bar a finder window lol
    I'm beginning to think the unthinkable... a reinstall of OS X! Behaviour appears to be more erratic over the last few hours after I ran a software update and installed a fair bit updates as it hasn't been updated in a while.
    Oh well.

Maybe you are looking for