WLC4402: same VLAN, different subnet - can it work?

Hi,
I bumped into a interesting issue with WLC4402. Management interface and prod-interface were in a same vlan, but they have different subnets. It seems that "there are two subnets in a same vlan" - 192.168.66.0/24 is defined as primary network in the router and 192.168.72.0/24 as secondary. See the pic attached.
At the moment there is v.4.2.176.0 running and it works. When I tried to upgrade it to v.6.0.199.4 something goes wrong. Controller changed prod-interface port to 0 and I can't change it back to 1 or 2. My best quess is that the WLC is not able to handle this kind of setup...but why is it working at the moment??
Any comments would be most appreciated. Thank you.
-Petri

It's actually a wonder/miracle that someone was able to configure this in the first place, to my opinion.
Maybe it was configured with an old WLC release and survived with the upgrade to 4.2
For sure, this is definitely something that the WLC now prevents you to configure. It's not supposed to work, just an example, if you get layer 2 traffic on that vlan (arp for example), where to reply ? you can't know from which subnet it comes from. So it basically means that you are bridging the 2 subnets together and then why not just giving them the same vlan id then ? effect would be the same.
It's anyway going against the linux routing engine, so I'm still wondering how it was working on 4.2
It was probably bridging vlans and doing some unefficient forwarding without you realizing it. So definitely something you should avoid configuring.

Similar Messages

  • I have an iPod mini 6GB and want to use it with a Sony CD Boombox but the adapter is different. Can it work?

    I have an iPod mini, 6 GB and want to use it with a Sony CD Boombox but the adapter is different. Can it still work? Don't want to try and break iPod.

    Do you mean that the iPod mini won't fit on the "dock" because of shape (of the iPod), or is the docking connection a different type from the "30-pin" dock connector on the iPod mini?

  • Why the same UI login script can't work with OS X 10.7 but 10.6 fine

    HI everyone,I can use a script as
    /usr/bin/osascript <<AppleScript
    tell application "System Events"
    keystroke "username"
    keystroke return
    delay 1.0
    keystroke "password"
    delay 1.0
    keystroke return
    end tell
    AppleScript
    to remote log in via UI when I'm in mac 10.6, but now it can't work with Lion,
    got an "execution error:An error of type -10810 has occurred.(-10810)" message
    then try another one which also works fine in 10.6:
    osascript<<EOT
    tell application "System Events"
    tell process "SecurityAgent"
    set value of text field 1 of group 1 of window 1 to "root"
    set value of text field 2 of group 1 of window 1 to "password"
    delay 0.5
    key code 36
    delay 0.5
    key code 36
    end tell
    end tell
    EOT
    still got error,need your help ,thanks a lot ~

    Either purchase Snow Leopard (if it will run on your computer) and then upgrade to iOS 7 or return the Nano.

  • While in Hotmail, Firefox crashed & now I can't open or delete messages, however, on the same computer-different account- my Hotmail works fine.

    While a request to print a sent email was being executed (successfully), my attention was diverted away from the computer screen. When I returned, the Firefox "crash" notice was on the screen, but everything appeared fine so I didn't file a report. I exited Hotmail and later signed in and found out I can not open or delete any messages. I exited Hotmail, switched computer user accounts and opened my Hotmail under the computer's administrative account. Under the adm. account my Hotmail works without a problem. Switched back to my computer user account, signed in to Hotmail and the original problem still exists. What can I do to get Hotmail to work in my computer user account?

    Clear the cache and the cookies from sites that cause problems.
    "Clear the Cache":
    * Tools > Options > Advanced > Network > Offline Storage (Cache): "Clear Now"
    "Remove Cookies" from sites causing problems:
    * Tools > Options > Privacy > Cookies: "Show Cookies"
    Start Firefox in <u>[[Safe Mode]]</u> to check if one of the extensions or if hardware acceleration is causing the problem (switch to the DEFAULT theme: Firefox (Tools) > Add-ons > Appearance/Themes).
    *Don't make any changes on the Safe mode start window.
    *https://support.mozilla.com/kb/Safe+Mode
    Thunderbird

  • Finder - All Movies - same movies, different extensions, can I delete ?

    Hi,
    Cleaning my HD I go to Finder - All Movies and see the same file in different names and sizes. Like .MOV - .MP4 - IMG_
    Same movie can have different sizes / volumes. From 8.5MB up to 55 MB for the same.
    I can find them back in Imovie, Iphoto.
    Is it useful to delete to create some space on my HD and which one should I delete. Most of them uploaded via an Iphone 4.
    Thanks
    Speedyf

    It all depends how you want to use the files in future, if they are going back to a phone or an AppleTV then keep the .m4v format, if you're going to edit them with iMovie or similar keep the .mov format.
    The larger the file the better the quality and resolution most likely so if in doubt keep the 'best' copy and discard the rest (you can always convert them to other formats at a later date if needed)
    How did you get multiple formats of the same thing in the first place ?

  • Same socket, different core, will it work?

    I actually did not find any article saying does it work or not. Assuming it does not work, so I have not tried it out. But will a my northwood mobo support prescott? same 478 pins, rite?

    http://www.msi.com.tw/program/products/mainboard/mbd/pro_mbd_cpu_support_detail.php?UID=387&kind=1

  • ACS 5.0 having issues with different subnet AAA Clients

    Dear All,
    I am getting weird issue. My ACS 5.0 is in subnet 10.1.1.0/24. All the AAA clients which are in the same subnet can communicate with the ACS but different subnet cannot.
    I have checked the firewall between them, Its allow any any with all services.
    One more thing I have faced today is that now from only one switch (10.1.2.10) can access ACS but switches in the same subnet (10.1.2.0/24) cant access ACS as same previous issue.
    Following are the logs of one switch(10.1.2.10) in different subnet can access ACS :
    Working Switch with Same configuration:
    SW-A#test aaa group tacacs+ test cisco legacy
    Attempting authentication test to server-group tacacs+ using tacacs+
    User was successfully authenticated.
    SW-A#
    *Nov 17 00:05:52.041: AAA: parse name=<no string> idb type=-1 tty=-1
    *Nov 17 00:05:52.041: AAA/MEMORY: create_user (0x1B1FD04) user='test' ruser='NULL' ds0=0 port='' rem_addr='NULL' authen_type=ASCII service=LOGIN priv=1 initial_task_id='0', vrf= (id=0)
    *Nov 17 00:05:52.041: TAC+: send AUTHEN/START packet ver=192 id=3237327729
    *Nov 17 00:05:52.041: TAC+: Using default tacacs server-group "tacacs+" list.
    *Nov 17 00:05:52.041: TAC+: Opening TCP/IP to 10.1.1.2/49 timeout=5
    *Nov 17 00:05:52.041: TAC+: Opened TCP/IP handle 0x1B44D48 to 10.1.1.2/49
    *Nov 17 00:05:52.041: TAC+: 10.1.1.2 (3237327729) AUTHEN/START/LOGIN/ASCII queued
    SW-A#
    *Nov 17 00:05:52.243: TAC+: (3237327729) AUTHEN/START/LOGIN/ASCII processed
    *Nov 17 00:05:52.243: TAC+: ver=192 id=3237327729 received AUTHEN status = GETPASS
    *Nov 17 00:05:52.243: TAC+: send AUTHEN/CONT packet id=3237327729
    *Nov 17 00:05:52.243: TAC+: 10.1.1.2 (3237327729) AUTHEN/CONT queued
    *Nov 17 00:05:52.444: TAC+: (3237327729) AUTHEN/CONT processed
    *Nov 17 00:05:52.444: TAC+: ver=192 id=3237327729 received AUTHEN status = PASS
    *Nov 17 00:05:52.444: AAA/MEMORY: free_user (0x1B1FD04) user='test' ruser='NULL' port='' rem_addr='NULL' authen_type=ASCII service=LOGIN priv=1 vrf= (id=0)
    Logs from the same subnet switch (10.1.2.20) which cannot access ACS:
    SW-B#test aaa group tacacs+ test cisco legacy
    Attempting authentication test to server-group tacacs+ using tacacs+
    No authoritative response from any server.
    SW-B#
    *Oct 20 00:54:12.834: AAA: parse name=<no string> idb type=-1 tty=-1
    *Oct 20 00:54:12.842: AAA/MEMORY: create_user (0x1A6F3F0) user='test' ruser='NULL' ds0=0 port='' rem_addr='NULL' authen_type=ASCII service=LOGIN priv=1 initial_task_id='0', vrf= (id=0)
    *Oct 20 00:54:12.842: TAC+: send AUTHEN/START packet ver=192 id=3281146755
    *Oct 20 00:54:12.842: TAC+: Using default tacacs server-group "tacacs+" list.
    *Oct 20 00:54:12.842: TAC+: Opening TCP/IP to 10.1.1.2/49 timeout=5
    *Oct 20 00:54:12.842: TAC+: Opened TCP/IP handle 0x1B1E888 to 10.1.1.2/49
    *Oct 20 00:54:12.842: TAC+: 10.1.1.2 (3281146755) AUTHEN/START/LOGIN/ASCII queued
    SW-B#
    *Oct 20 00:54:12.943: TAC+: (3281146755) AUTHEN/START/LOGIN/ASCII processed
    *Oct 20 00:54:12.943: TAC+: received bad AUTHEN packet: type = 0, expected 1
    *Oct 20 00:54:12.943: TAC+: Invalid AUTHEN/START/LOGIN/ASCII packet (check keys).
    *Oct 20 00:54:12.943: TAC+: Closing TCP/IP 0x1B1E888 connection to 10.1.1.2/49
    *Oct 20 00:54:12.943: TAC+: Using default tacacs server-group "tacacs+" list.
    *Oct 20 00:54:12.943: AAA/MEMORY: free_user (0x1A6F3F0) user='test' ruser='NULL' port='' rem_addr='NULL' authen_type=ASCII service=LOGIN priv=1 vrf= (id=0)
    Waiting for your responses.
    Regards,
    Anser

    Ok, cool,
    So this usually means that the switch is sourcing the requests from a difernet interface that is configured on the ACS.
    I would guess that the ACS is reporting unknown NAS...
    Can you please use the "ip tacacs source-interface" command to make sure the switch will source the Tacacs+ packets from the interface with the IP address for which you have the ACS configured to?
    HTH,
    Tiago
    If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

  • The loading bar can't work correctly!

    hello, everybody, i creat a loading bar, but it can't work
    correctly, the code is that:
    as u see, the"will_load.swf" is in the same file

    thanks for your help!!
    i do test this on line,but can u tell me how ,i send the two
    files in the same files,but it can't work well!
    my email is [email protected]
    can u send me a sample file?
    i really thanks your help!

  • AP groups with same vlans , same ssid but different subnet.

    Hi Members,
    I have a Cisco Flex 7500 in my datacenter and I need to connect 100 sites , each site with 2-3 APs , each side has its own network and is independent of other sites , the site only need to comunity locally and do not need to access any centralized applications.
    I am trying to achieve this by Creating 100  different AP groups and assiging 2-3 AP in each groups for each branch, I will achieve WAN failover resiliency by creating flexconnect groug , the issue I am facing are as below .
    1.Since all the sites has same setup , the AP and clients on all sites are in vlan 2 , so when I try to create 2 or more AP group with same vlan, it restricts me of doing so , I cannot create diffrent AP groups mapped to same Vlan .
    2.If I keep the APs and Clients in the same subnet , I dont think it should be a problem , but I need your second opinion.
    to give you an even better picture , look at the topology enclosed , and my question is if both STAFF and STUDENT APs are in same vlan but in 2 different broadcast domain , how would I create the AP groups.
    Thank you

    Thanks for the reply Jenn , here is my situation.
    I have 2 sites lets day , site A in virginia ,  site B in Maryland.
    SiteA - 10.1.1.0/24 - vlan 2
               10.1.2.0/24 - vlan 3
               10.1.3.0/30 - WAN to central site where controller sits.
    SiteB - 10.2.1.0/24 - vlan 2
               10.2.2.0/24 - vlan 3
               10.2.3.0/30 - WAN to central site where controller sits.
    both the sites will have a single ssid "XYZ" and will switch locally only.
    howin my understanding the way I will deploy this is as below
    1.I will create WLAN with ssid "XYZ".
    2.I will create 2 AP groups lets say "Site-A" and "Site-B"
    3.I will map the APs in site A to AP group "Site-A" and APs in Site B to "Site-B"
    4.I will create 2 dynamic interfaces one for each AP group , now this is where I am facing problem , when I am creating dynamin interfaces , I need to specify the subnet and vlans when creating dynamic interfaces , since the vlans used is same on both sites , its not letting me create 2 interfaces with same vlan id.
    in my understanding HREAP is only majorly used for WAN failover and local authentication so I am not concerned about that right not , my prime work is to udnerstand the AP group and working.
    if you still need print shot let me know I will have to go at site.
    also validate if my thinking is right on the 4 steps I have mentioned above , I am new to wireless and whatever I have learned I have learned in last 10 days .
    Appreciate your help.
    Thank you

  • Can EJB work acrros different NetWorks(subnets)...

    I have deployed EJB in OAS 4.0.8.2 which works fine with LAN environment. But the same refuse to do so, when hosted with ISP.
    Applet is my client to EJB.
    The LOOKUP failure occurs(CORBA.COMM_FAILURE). When discussed, I got these infos.
    1. EJB may be a layer 2 protocol which does not allow it to work across different subnets.
    2. Applet-EJB connectivity can not by bass the socket layer.
    3. Firewalls, doesnot allow the EJB connections to be performed.
    This means EJB can not work in Internet scenario... Is that so....
    Can any one help me???
    Thanks for the efforts u will be taking...
    Serin.
    null

    You can actually use one linksyssmartwifi accounts to multiple routers as long as you were able to associate those routers with your account. So even if you are at your office, home or vice versa; you can still access your router remotely as long as your account and the routers have been associated.

  • Single VLAN can have different subnets????????

    single VLAN can have different subnet

    Hi Devang,
    Yes your single vlan can have different subnet but they will not talk to each other on ip (layer 3) till the time you configure routing on your layer 3 device using secondary ip address on same logical interface.
    But your answer is yes single vlan can have different subnet.
    HTH
    Ankur

  • Folder is empty on second computer. I have installed adobe CC on two different computers for same account so I can work at two different places. I uploaded files to it yesterday and I can't find it on the CC folder on second computer. What can I do?

    I have installed adobe CC on two different computers for same account so I can work at two different places. I uploaded files to it yesterday and I can't find it on the CC folder on second computer. What can I do?

    Hi DeafScientist,
    Please try the below mentioned links.
    Creative Cloud Help | Browse, sync, and manage assets
    Error: "Unable to sync files"
    Creative Cloud File Sync | Known issues
    Kindly revert if you are unable to sync files.
    Thanks,
    Atul Saini

  • Multiple RAC databases on same GI using different subnets for Public i/face

    Hello. We are configuring a 2 node cluster. That cluster will host several RAC databases. For security reasons our networking team want to create separate subnets for the application traffic to each specific RAC database on the cluster.
    E.g. application 1 has 2 application servers that will connect to RAC database PROD1 via one subnet, application 2 has 3 application servers that will connect to RAC database PROD2 via a different subnet, etc.
    In addition the networking team want to configure a separate management subnet that DBAs etc. will use to administer all RAC databases and infrastructure in the cluster.
    Grid Infrastructure version 11.2.0.2. Database versions will vary from 10.2.0.x to 11.2.0.2. All databases will utilise RAC.
    We want to take advantage of SCAN listener functionality to support connectivity to all databases on the cluster. Forum thread 2199620 [https://cn.forums.oracle.com/forums/thread.jspa?threadID=2199620] suggests that 11gR2 supports multiple subnets, which looks to be exactly the feature we need. Please can you confirm how this works and point us to any documentation (standard docs, white papers, MOS, etc.) that might help us configure this.
    Document referenced in thread 2199620 was not exactly what we were looking for, and didn't translate too well in Google Translate.
    Any guidance much appreciated. Thanks, Rich.
    Similar threads:
    https://cn.forums.oracle.com/forums/thread.jspa?messageID=9846298? (Dual SCAN on multi homed cluster)
    https://cn.forums.oracle.com/forums/thread.jspa?threadID=2199620 (scan listener in OAM VLAN)
    Edited by: 887449 on 26-Sep-2011 01:41

    Thanks Levi. Your advice is very much appreciated.
    Your statement that we can only have one SCAN listener listening on one public network is actually the clarification I was looking for.
    For anyone else reading this thread I believe this gives us 3 options:
    1) Configure a SCAN listener and have all applications, and all management/administration, connecting to the corresponding database on the same cluster via that SCAN listener, all on the same subnet.
    2) Configure a SCAN listener for use by all applications connecting to the corresponding database on the same cluster, and use TNSNAMES/VIP for management/administration traffic, both on separate subnets (by configuring the LISTENER_NETWORKS parameter)
    3) Configure a SCAN listener for use by applications connecting to one of the databases on the cluster via one subnet, use TNSNAMES/VIP for all other applications connecting to other databases, each using their own subnet. Plus, the management/administration could be via another subnet utilising TNSNAMES/VIP.
    From our perspective we will work out the best one for us and implement accordingly.
    Thanks again for your timely and comprehensive response.

  • Load balancing within the same ACE across two different contexts residing on the same vlan

    I'm working on a design that requires traffic be sent to a different context in the same ACE. The question I have is can this be done when both reside on the same VLAN. Would the traffic in this case be handled at layer 2 instead of layer 7. Would I have to create a seperate subnet in order to provide loadbalancing?
    |__________________|
    |   | vlan 5         |         |
        |                  |
        |                  |
    Context A        |
                           |
                           |
                        Context B
    Thanks, Jerilyn

    by design, two contexts on the same box in the same vlan can't communicate. You have to use an external L3 device.
    A workaround may be to use two diferent vlans and then bridge between them with a loopback cable.

  • Can ARD 3 now share a screen across 2 different subnets

    We have one central office. Clients access that office via a VPN. We can then share our screen with them as we work on a proof of a project.
    It's a great solution, however, we can't with ARD 2.2 get it to work with two clients at once over the VPN.
    An old Kbase article said that it wasn't possible to route screen sharing to two different subnets in the 2.2 version. But rather required all clients be on the same subnet.
    Does anyone know or have the ability to test to see if this is different is 3.0. I'm hopeful that it is, as I can no longer find the old Kbase article saying that it wasn't possible.
    Thanks,
    Greg

    Still no reply as to if this was resolved. I'm not so much worried about the move on the client side. As once we upgrade we have the luxury of upgrading everyone at once. I think that will be a smooth process.
    However, our motivation to upgrade is dependant on wether or not the ability to route traffice over multiple subents is fixed or not. So we'll wait and see. If anyone can easily test this. I'd love to know. Sounds like a few other people are hoping to hear something as well.
    Thanks in advance,
    Greg

Maybe you are looking for

  • Streaming wifi and bluetooth at the same time is it possible in air play from iPod

    Streaming bluetooth and wifi at the same. Is it possible?

  • Ipod Classic 80 gb

    When the battery finally dies on my favorite iPod, will it be replacable? thanks if you know

  • Photos Wont Open Even After Restart

    Every time I open up Photos it says "Unexpected error occurred please quit and restart the application." I click the quit button which quits the program and when I reopen it, the same message comes back up. I have shut down my computer, restarted my

  • Custom Top creation in oracle applications

    Hi When we create a custom top in oracle applications 11i/R12, is it mandatory to run autoconfig? Are there any manual entry steps to be performed in adding custom top entry other than xml file like topfile.txt????

  • 6i to 10g Font Problems

    We have a lot of reports running in 6i with The title having 3 lines in it. The first line's font is courier new 8 italic The second line's font is courier new 11 Bold The third line's font is courier new 10 Bold In 6i the first line does not print i