WRT54G Bridges, VPN's, Captive Portals, etc. (Advanced FAQ)

These questions are only in relation to the above Wireless Router (v6, FW-v1.02 [2010]) :
1. What is an Ethernet Bridge (the basic authoritative definition), and besides gaming, what are they generally used for in a business setting?
2. What are VPN settings in a Router used for, and can a VPN be configured on a remote PC without them?
3.  Utilizing bridging, etc., can I utilize my WRT54G as a makeshift Range Expander as long as the primary router doesnt have WEP key requirements?  The current WIFI doesnt reach my PC, so I thought I could configure my router midway in hopes of extending the other routers' signal, via some kind of bridging if necessary.  Naturally, there would only be a wireless connection between routers.
4.  How can I setup a simple Captive Portal on this router?
If more expedient, provide any definitive links to answer these questions, preferrably at Cisco sites.  Thanks.

Re 1. Where did you find this? The WRT is switch not a bridge. Technically, the switch does the same as the bridge, only better. It connects two or more ethernet segments and joins them into a single ethernet network.
Re 2. The VPN settings are used when you have VPN connections running through the router (i.e. not as endpoint). If it's possible to connect without them depends on the kind of VPN you are trying to establish. Some will work and some won't unless you have enabled the corresponding passthrough.
3. ethernet bridging and wireless bridging are completely different things. The WRT won't connect wirelessly to other routers.
4. You can't.

Similar Messages

  • WAP-321, Captive Portal and Wi-FI repeaters

    Hi,
    So I am currently deploying a Wi-Fi Network based around Cisco WAP-321. I use the CP function with a Radius server to authentify my users. So far so good, when a user connect to one of the AP and uses his credentials, he can login and access Internet without any trouble. But I also use some Wi-Fi repeaters (Netgear WN-1000RP) to extend the range of my wireless network in places I can't install an AP. The repeaters effectively extends the range of my network, and I can connect on them without any trouble when the CP is turned off. However, when I turn on the CP, I access the login web page and enter my credentials, but no matter what, I can't login while connected on the repeater. After some research, it looks like I have to manually enter the MAC address in the MAC trough list of the AP. Except such a feature doesn't seem to exist on the WAP-321. I have tried using WDS bridge and Workgroup bridge, but without success, since I think it's only compatible with WAP-321 and WAP-121 devices.
    So I am kind of running out of ideas to make this work, and I would be very grateful if someone could help me out.
    Thanks in advance, do not hesitate to ask me for more informations if needed.

    My name Eric Moyers. I am an Engineer in the Small Business Support Center.
    I am sorry to hear that you are experiencing this issue. 
    While what I am fixing to share is not in any way a great solution, It can be utilized as a workaround.
    With the WAP321, after trying a few different scenarios that didn’t work. I simply created two vlans, leave the Untagged vlan as main vlan and changed the Management vlan to the second. I then attached the guest SSID to the Management VLAN. This allowed me to authenticate to my guest captive portal and get an IP and get out to the internet. The Main SSID still worked normally.
    Now for some caveats:
    Problem: If a wireless client knows the IP of the WAP and the username and password they could get into the WAP.
    Solution: Setup Management Access Control to an IP outside the DHCP scope for that VLAN and have a Strong Password.
    Problem: Management of the WAP321 can only be from an IP on the Management VLAN. (In my case 2)
    Solution: Setup Management Access Control to an IP outside the DHCP scope for that VLAN and have a Strong Password.
    Not the very best solution, but the only workaround I can come up with for now.
    Eric Moyers
    .:|:.:|:. CISCO | Cisco Presales Technical Support | Wireless Subject Matter Expert
    Please rate helpful Posts and Let others know when your Question has been answered.

  • Anyconnect 3.1 Captive Portal False Alert Stops Users Connecting.

    Hi All,
    I am having problems with a customer's ASA 5505 with Anyconnect 3.1 - it is generating captive portal false-alerts which are stopping users from connecting.
    This issue began when I upgraded from Anyconnect 2.4 to 3.1, and it appears like this: A user downloads and installs the Anyconnect client and is able to connect fine, to begin with. However, once they reboot their computer and try to reconnect, the VPN session will not come up and they receive the error message below.
    "The service provider in your current location is restricting access to the internet. You need to log on with the service provider before you can establish a VPN session. You can try this by visiting any website with your browser."
    Reading other posts, it seems this message appears when a captive portal is restricting internet access. It must be a false alert in this case as there is nothing of the sort here. Apparently, Anyconnect 3.1 can generate a false alert like so if the name of the firewall's SSL certificate doesn't match the CName listed on the Client Profile. I've set this up to match, to no avail.
    Although users can connect by reauthenticating through the SSL VPN login web page, I am stumped as to how to get rid of this captive portal error that pops up when they try to use the Anyconnect client.
    Any advice would be appreciated, just let me know what extra details to post if needed.
    Many thanks,
    Josh Campbell

    Hi Joshua,
    The below information could be located at
    www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect31/administration/guide/ac03vpn.html
    False Captive Portal Detection
    AnyConnect can falsely assume it is in a captive portal in the following situations.
    •If AnyConnect attempts to contact an ASA with a certificate containing an incorrect server name (CN), then the AnyConnect client will think it is in a "captive portal" environment.
    To prevent this, make sure the ASA certificate is properly configured. The CN value in the certificate must match the name of the ASA server in the VPN client profile.
    •If there is another device on the network before the ASA, and that device responds to the client's attempt to contact an ASA by blocking HTTPS access to the ASA, then the AnyConnect client will think it is in a "captive portal" environment. This situation can occur when a user is on an internal network, and connects through a firewall to connect to the ASA.
    If you need to restrict access to the ASA from inside the corporation, configure your firewall such that HTTP and HTTPS traffic  to the ASA's address does not return an HTTP status. HTTP/HTTPS access to the ASA should either be allowed or completely  blocked (also known as black-holed) to ensure that HTTP/HTTPS requests sent
    There is also a bug filed for this. Just for your reference,
    CSCud17825 - Anyconnect captive portal
    Regards,
    Srikanth K S.

  • ISE captive portal timeouts and radio policy

    Hello!
    I have two questions.
    First, have some of you guys worked with the captive portal in ISE (guestportal)?
    I have set up a new wireless network for a customer and they want to use the guest portal for som users.
    The problem that I am expering is that on a particular site with many small buildings user complains that they have to reauthenticate using the webportal when moving between the buildnings.
    I have tired extending the idle user timeout on that particular wlan in the cisco 5508, but I still having this problem.
    I would actually like if the user login via the guestportal at the beginning of the work day and after say 4-5 hours they have to reautencitcate.
    And if they loose network connectivity (moving between buildings, iphone/andriod shutting down wifi adapter, etc) they shuld be fine connecting again because they have aldready authecnticated once during the last 4-5 hours.
    Is this possible via the ISE?
    My second question deals with 2.4 and 5 Ghz band.
    I use AP groups on each of my distribution areas. All groups have the same SSID but diffrenet egress interfaces (interfaces groups).
    And in some of these I want to save the 5 GHz band for voice over wlan and in others i would like to use both bands.
    Do I have to create diffrent wlan profiles with diffrent radio policys and same SSID or could I do this in the AP group settings using RF-profiles?
    Hope for some help!
    //Simon

    Your first answer  is there is no such option in ISE till now there you can specify the login time fix for a client. If the client disconnect from the network and reconnect again, it require re-authentication Every time.
    2nd : You can use the AP group settings using RF-profiles to achieve this task.1st: There is no such option in ISE till now there you can specify the login time fix for a client. If the client disconnect from the network and reconnect again, it require re-authentication Every time.
    your seconde answer : You can use the AP group settings using RF-profiles to achieve this task.

  • How can I change the re-direct URL on the WebKit for Captive Portals?

    Hi,
    I have a guest network at the office that is configured with a captive portal for authentication. My MBP detects that it is behind a Captive Portal when the HTTP WISPr request fails and launches the WebKit (ie. the CNA) as designed and displays the login page. When the login is successful, the Captive Portal displays a success and the WebKit then proceeds to re-direct the browser to http://www.apple.com
    Of late, Apple's homepage has become graphic rich and more often than not, loading the page without caching (since the webkit does not cache the webpage loaded) loading Apple's homepage on the guest network takes over 30-90 seconds depending on the traffic on the network. The OS does not allow me to use the network till the page on the webkit has successfully loaded and the "Done" button appears on the webkit and this often becomes irritating.
    Is there a method to change the redirect URL to something less resource hungry like http://www.google.com or a less graphic rich Apple page (like http://www.apple.com/library/test/success.html)?
    I understand that there is a method to disable Captive Portal Handling, ie.
    sudo defaults write /Library/Preferences/SystemConfiguration/com.apple.captive.control Active -boolean false
    However, I don't want to disable Captive Portal Handling in the OS as I don't believe Apps that require internet access will handle the lack of the internet well.
    Any hints would be appreciated.
    Cheers!

    Hey again,
    I did have a look at it and the Settings.plist file isn't very helpful for the issue I have.
    The file defines the probes and exceptions. So you have the default probe WISPr URL in there (http://www.apple.com/library/test/success.html) and the exceptions for specific SSIDs, as an example, attwifi is in the exception list and uses an alternate probe WISPr URL (http://attwifi.apple.com/library/test/success.html). The configuration does not have parameters that would be used by the CNA for the redirect to http://www.apple.com after a succesful Captive Portal login.
    Give it a shot on your laptop, get to a random public wifi like ATT Wifi/Starbucks/Guest Wifi's at office spaces/Boingo etc. and after the successful login, your CNA Webkit will re-direct to http://www.apple.com and the "Done" button won't appear till the page has completely loaded and stays as "Cancel" till the page is loaded.

  • Allowing Airwatch MDM access to the Captive-Portal guest users in pre-auth role for android and BB?

    Requirement:
    How to allow Airwatch MDM access to the Captive-Portal guest users in pre-authentication role for Android and Blackberry devices?
    What is Airwatch MDM?
    Airwatch MDM is Mobile Device Management. The Airwatch is an enterprise which helps to manage and secure data traveling through the mobile devices like Laptops, Tablets, Android, iPhones, iPads etc.
    Solution:
    Why we need to allow access to Airwatch MDM?
    The network administrator can force the guest users to register to Airwatch MDM before they get authenticated and access the internet. So that the network administrator could manage the guest devices through Airwatch Management tool. This can be achieved by CPPM server. To download the Airwatch MDM app and register with the Airwatch MDM server certain domains should be permitted in the captive portal pre-authentication role. This KB provides the configuration steps to allow the guest users to download the Airwatch MDM app and register with the Airwatch MDM server.
    Configuration:
    Below is the configuration
    Configuration steps:
    1. Create the following netdestinations
    netdestination Airwatch
      name *.awagent.com
      name *.awmdm.com
      name air-watch.com
    netdestination Google-Play
      name android.clients.google.com
      name .ggpht.com
      name gstatic.com
      name accounts.google.com
      name clients1.google.com
      name clients2.google.com
      name clients3.google.com
      name clients4.google.com
      name i.ytimg.com
      name google-analytics.com
      name .1e100.net
      name android.l.google.com
      name mtalk.google.com
      name clients.l.google.com
      name googleapis.com
      name gvt1.com
    netdestination BlackBerry
      name *.blackberry.com
    2. Now define the rules in the session acl and map it to the pre-authentication Role of the captive portal.
    ip access-list session Airwatch_Access
      any   alias Airwatch svc-http  permit
      any   alias Airwatch svc-https  permit
    ip access-list session Google-Play-Store
                   any   alias Google-Play any permit
    ip access-list session BlackBerry-Access
                   any   alias BlackBerry any permit
    3. Now map the session ACLs to captive-portal pre-authentication Role as follows
    user-role Guest-Pre-Auth-Role
     access-list session Airwatch_Access
     access-list session Google-Play-Store
     access-list session BlackBerry-Access
     access-list session logon-control
     access-list session captiveportal
    4. Now whitelist the list of domain names in the Captive Portal profle
    aaa authentication captive-portal Airwatch-Captive-Portal-Profile
    white-list Airwatch
    white-list Google-Play                                                                                ------------>Netdestinations where you defined the Domains.
    white-list BlackBerry
    Verification
    Now the user will be placed under the "Guest-Pre-Auth-Role" before the authentication. The user can now go the Google Play-Store or BlackBerry Appworld to download the Airwatch MDM and register to Airwatch Management Server.

    Thanks so much getting these names listed out. I have been working on this very issue for a few weeks and was basing my firewall rules on IP's. It was not going well. Now access is working and testing can commence!  Thanks,Chris

  • Bug in wifi/wireless connection with captive portal in UK/London ?

    With my macbook pro (10.6.4) & iphone (iOS 4), I do not manage to have an easy connect on free wifi captive portals in London. They all are new connections (unknown networks before).
    * dhcpd lease seems to be instable. I can get wifi connection (with good wifi signal strength) but most of the time get a "non-allocated" lease like 169.254.57.x/24 without any router/dns. A few rare times, the dhcp server give a me a complete ip connection.
    * in the rare case where IP connection could established, I was not redirected to the captive portal. I had to manually enter its address (in my case <IP>:8000, you need to guess) and even after authentication, I can't browse the Internet. In one of my test, I managed to resolve dns entry but can't browse the web.
    I tried during an hour and I couldn't make it on work on my Macbook. work a small time with the iPhone.
    tested in McDo free wifi and Airbox Public Wifi of EasyHotel (Airbox system). also have problem with "Wifi Zone - The Cloud".
    ok in Starbucks and in St Pancras Free Wifi.
    Found these threads which could be related but no real solutions:
    http://discussions.apple.com/thread.jspa?messageID=11875166&#11875166
    This is probably the router's fault but I can't check this.

    Hmm...pretty interesting. What redirection mode did you use for m0n0wall? (http or dns) Have you tried disabling the NAT on the router as well as unchecking the block anonymous internet requests on the security tab?
    I have a similar setup on a T1----media converter----WRT54G setup. Basically, the router was able to get public wan ip addresses on the status page. So do the computers behind it (wired and wireless) but they aren't online. We pinged the three dns numbers on the router, only 1 replied. Now, the ISP has Cisco all-access installed on the converter (quite similar to captive portal) and it shows up on every computer when we try to go online. We open up the browser, it prompts for the authentication. We fill-in the details but still it doesn't go online. Bottom line was we cloned the mac of the main computer and they didn't need to authenticate...but then again it defeats the purpose of the software.
    Also, the router was set as a DHCP server with NAT enabled. I'm thinking that the router's firewall still blocks your computers even when it's already set as a switch. Try to disable the NAT and see if it works.

  • Setting UP Captive Portal ON 5508 WLC

    Dear All,
    I do know that captive portal could be setup on cisco 5508, such that internet users could login as follows:
    Username, password , login duration  etc.
    however i would like to know whether the above configuration would work with just 5508 and MS Active directory.or do we need any other device to achieve this.
    secondly can we upload a customised login web page from which users can login and gain access to the internet ?
    Jude.

    1. i would like to know whether the above configuration would work with just 5508 and MS Active directory
    Yes, you would need to configure an LDAP server on the WLC pointed to your MS AD, binding properly.  Then, make sure your L3 authentication priority is configured to query LDAP first.  This works pretty well in a L3 web-auth scenario, but is limited when using LOCAL EAP
    http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a0080a03e09.shtml
    2. can we upload a customised login web page from which users can login and gain access to the internet ?
    Yes; start by downloading the webauth_bundle.zip for your respective release/platform. 
    http://www.cisco.com/en/US/docs/wireless/controller/7.0MR1/configuration/guide/cg_user_accts.html#wp1049404

  • Trouble accessing a "Captive Portal"

    Recently I was unable to access a WiFi network at a commercial location. Their tech services were baffled because other users were having no trouble at all. They told me that several other Mac users had been unable to log on as well. After I got home I read up on this and found that they were using a Captive Portal to redirect my log on. Googling these terms I find others with Macs asking for help but getting no response. One poster suggested it was a problem that began with an upgrade to Snow Leopard.
    I'm using 10.6.6 and frustrated with my inability to log in. Can anyone suggest a solution.
    MacTrekker

    I can't say for certain what is going wrong in your case but I can confirm it is possible to do an ARD connection i.e. Screen Sharing to a remote user connected via a VPN. The way we do this is to get the user to connect to the VPN server (a Mac OS X Server), then on the Mac OS X Server in Server Admin see what IP address they have been allocated by the VPN server, then tell ARD Admin to connect to that IP address.
    This works fine for me.
    The IP address will be a 'local'  to the ARD and VPN machines IP address it would not be the remote public or private IP addresses.

  • IE11 - Captive Portal Pages Not Working

    Recently, I have had several complaints from Windows 7 users that are trying to connect to hotspots at the airports and hotels and they are getting page cannot be displayed error in IE11. They are actually getting two, one is the standard error check connections and whatnot and the other says Turn on TLS1.0, TLS1.1 and TLS1.2 in the Advanced settings and try connecting to https://www.google.com again.I checked the settings and all TLS versions. I do have a GPO that is disabling SSL 3.0 and in the Advanced settings menu, it displays "Some settings are managed by your system administrator." The word settings is a link and when I click it, the captive portal page actually loads and allows me to accept the terms and conditions and access the internet.Anyone else see this?
    This topic first appeared in the Spiceworks Community

    I have had my TP since July and have connected to the internet via wifi at airports, hotels, coffee shops ect. You should not be waiting for HP to fix the OS. You need to decide if the problem is you or your TP. If it is your TP then get it fixed.

  • Captive Portal spinner is ultra small

    Please refer to attachment. Not annoying stuff but a little of strange there.

    Hmm...pretty interesting. What redirection mode did you use for m0n0wall? (http or dns) Have you tried disabling the NAT on the router as well as unchecking the block anonymous internet requests on the security tab?
    I have a similar setup on a T1----media converter----WRT54G setup. Basically, the router was able to get public wan ip addresses on the status page. So do the computers behind it (wired and wireless) but they aren't online. We pinged the three dns numbers on the router, only 1 replied. Now, the ISP has Cisco all-access installed on the converter (quite similar to captive portal) and it shows up on every computer when we try to go online. We open up the browser, it prompts for the authentication. We fill-in the details but still it doesn't go online. Bottom line was we cloned the mac of the main computer and they didn't need to authenticate...but then again it defeats the purpose of the software.
    Also, the router was set as a DHCP server with NAT enabled. I'm thinking that the router's firewall still blocks your computers even when it's already set as a switch. Try to disable the NAT and see if it works.

  • Captive Portal Help

    Hello All,
    working with the RV180W and a Ubuntu server I have established a FreeRADIUS server and have it setup for PEAP authentication based on a users file with NTLM encrypted passwords.  This is working pretty well, however I have one problem.  My certificates are self-signed and windows freaks out over it (all mobile OS's, OSX, and Linux work fine).  I'm trying to investigate other options and right now I'm curious, is there any way for the RV180W to use a captive portal setup that isn't the one built in? or is there any way to have the users be authenticated against the radius server I already have rather than setting them up on the router?  I'm open to other suggestions, but I'm trying to avoid paying for certs (I know they aren't incredibly expensive but this is mostly for home use/development/learning) so paying for certs aren't worth it and wanted to see if this was an option.  I will also accept the option of hosting a wireless network that is open but only goes to a page to download an XML & batch file which can be run to add the wireless network to the system (I have this working from USB atm, but trying to develop self-serve options)
    Thanks in advance... P.S. very happy with this router so far! its great!

    Hi Lucas,
    I was looking for a solution with my colleagues from the Support Center, but I am afraid the answer of what you ask is no - you can only use the internal database of the router, when using the Captive portal.
    Can you use a Captive portal that isnt' the build in? Theoretically yes, if the users in the LAN has as gateway a machine with a captive portal, which will make the radius authentication and only after that will forward the trafic to RV180 and inet.. Unfortunately I cant offer you a practical configuration on this.
    If meanwhile you find another solution, please chare it with us
    Regards,
    Kremena

  • Captive Portal

    my customer is educational istitution,they have Cisco 1252 AP (autonomous).i want to setup a captive portal, i can build a linux based server..
    they cannot spend much... is there a way out..
    Thanks in advance
    Mak

    Hi,
    Setting a specific web page for the clients everytime when they connect to the AP is not possible
    by using the AP only. AP only has the option to redirect all the client traffic to any other IP
    on the network and thenfurther the device associated to that IP can provide the Web page for the
    clients that will be displayed on their client screens. That device can be a
    BBSM(Building Broadband Service Manager) or a Cisco NAC Appliance.
    As per the below link, BBSM is out of sale:
    http://www.cisco.com/en/US/prod/collateral/netmgtsw/ps5689/ps533/ps5463/prod_end-of-life_notice0900aecd805aeb23.html
    In order to configure a SSID/VLAN to open a particular website when any user
    connects to it, you need to connect a BBSM(Building Broadband Service
    Manager) or a Cisco NAC Appliance to any one of the Access ports on the
    switch which is a part of that VLAN. We can configure the BBSM device or the
    NAC device to open a specific webpage and after that we can configure the AP
    to forward all the packets coming from client connected to that specific
    SSID/VLAN to the IP address of the BBSM server with the help of "IP
    redirect" command we can configure on the AP. Here is a document for the
    same:
    http://www.cisco.com/en/US/docs/wireless/access_point/12.3_4_JA/configuratio
    n/guide/s34ssid.html#wp1049571
    Here is an application note about the list of APs which support IP redirection
    http://www.cisco.com/en/US/docs/wireless/technology/ip-redirect/technical/re
    ference/ipredir.html
    Most of the cases that we have seen on "IP redirection" go way back to when
    BBSM was available.  Nowadays, this is deployed using WLCs for the guest
    access.
    I hope the above answered your question.
    Regards
    Surendra

  • Captive portal on rv220w?

    Hello
    Does the cisco rv220w have captive portal like the rv180w does, or will it be supported in future firmware?
    Sorry for my bad English
    Thanks in advance
    Dennis

    I've not seem anything in the RV220W firmware, You can setup multiple APs on the router and have a "guest" account for free users, but dont think the is a real captive portal.
    Take a look here incase i missed something. 
    http://www.cisco.com/web/sbtg/gui_mockups/RV220W_v1/home.htm
    Regards Simon
    http://www.linksysinfo.org

  • Configuration of AP 561 for captive portal.

    Can i use a single 561 accesspoint as a captive portal for whole network?
    I would like to install linksys APs in my network & single 561 AP along with linksys accesspoints. So, can I use 561 as a captive portal for my entire network?

    Ok. Here are the answers:
    1. Basic steps for Portal Configuration
       > Download ESS/MSS Business Package, it has two parts Business Package for ERP 2005 (Contains iviews, Roles etc) and XSS 5.0 or 6.0 depending upon the version of the ECC.
      > Make sure that you have SAP_HR and EA_HR component installed on your ECC box.
      > Also make sure that there is no compatibility mismatch between version of SAP_HR, EA_HR and XSS.
      > Configure the JCo Destinations, create required system definition and establish SSO between ECC and Portal.
      > Assign the role to the users
    > After doing these steps you can see the SAP provided iviews etc working PROVIDED configuration on HR side are already done.  (This is just to get initial configuration work)
    2. I need some docs for configuring ESS and MSS...
    > Provided by Bala above
    3. a) After configuring ESS and MSS, wat needs to be done.. suppose my client is asking for Leave Request in ESS, whether i need to create that application in webdynpro java or webdynpro abap in backend and i've to call that application in portal throgh iview...
    > Look for that application in WebDynpro (identify the component from iView properties) and show it to the client.
    If they are Ok with the basic things then fine else they need to specify the kind of customisation they want in this component
    Options available if we need to modify the components
    >>Copy the component in your namespace and do the modification using NWDINWDS
    >>If some field need to be disabled, you can do the same using Self service administration.
    b) or by doing the configuration of ESS, by default i will get all the aplications(e,g, Leave Request, Travel Managemetn ....) from that package and it will display in iview...
    Hope this helps. ...

Maybe you are looking for

  • Home directories loosing access rights - Urgent help required

    We have just migrated around 2000 user accounts onto a new xserve server and we have just set up these user accounts so that there home directory is stored on the server as opposed to locally on each machine. To get past a serious performance issue w

  • Sending E-mail from BI Publisher without using Bursting Option

    Hi All, "While clicking on Send Button and selecting E-mail as Delivery option in BI Publisher for a particular Report, we want that To, CC, BCC  and the Body part should get populated  with the Email id's and Static text(for Body )  from database .

  • Costcentre and profit centre customizing

    Dear SAP Guru's, Hi I have a problem for profit centre wise balance sheet. The scenario is follows. a)     Our client has two business line industry and institution                                       b)     Under each business line have 4 Region f

  • Variable length ByteBuffer?

    I have a client sending a ByteBuffer to a server. I know the size of the ByteBuffer on the client based on the file I'm reading in. However when I'm on the server reading in the ByteBuffer I don't know the size. Since the file size on the client can

  • Illustrator document with positive photoshop (.tif, .psd) file prints negative. How do I fix this?

    I placed a positive grayscale photoshop file (.tif, .psd format) in an illustrator document that I painted in a spot color, when I print it, it outputs as inverse, negative. How do I fix this problem. It looks fine on the screen, but when I print it