WRVS4400N v2 WLAN clients dropping
I purchased a WRVS4400N for my home to replace an older router. Since I started using the Cisco router, WLAN clients drop. I can sometimes get them back after initiating a ping to a static LAN IP, but it takes a few seconds.
This issue impacts Win Vista, Win7, Mac, Android, and Linux machines...so basically anything that does WiFi. There seem to be many complaints here with no resolution. Has anyone fixed this problem in their network? I'd really hate to return this thing, but it's becoming unusable.
Mr. Cameron,
Hi, My name is Eric Moyers. I am a Network Support Engineer in the Cisco Small Business Support Center. I am truly sorry to hear about your issue you are having with your router.
Have you called into the Small Business Support Center for help on this? If you have may I have your case number so that I can pull your case and review it to see if there is anything I can do for you.
If you have not called in, I would like to strongly encourage you to call in and get a case created and let one of our agents help you with this issue. THe WRVS4400N is a very good router and I want to make sure that we do everything we can to keep your business.
Thanks
Eric Moyers
Cisco Network Support Engineer
1-866-606-1866
Similar Messages
-
My customer is using WLC4400(4.0.179.11) and LAP1130(12.3jx1). Before converting IOS to LWAPP, the WLAN service is not problem.
But after changing to LWAPP based,the customer is complain about disconnecting problem.
Intel centrino and other vendor's wlan cards are dropping, cisco wlan cards are no problem.
After all we have to fall back to IOS version. Is there any Bug report about WLC4400?There are some issues with the Intel adapters. I would try downloading the latest driver version to see if that helps. You can navigate to the Intel support page and view the documented disconnect issues.
-Mark -
ISE Certificate Chain Not Trusted By WLAN Clients
We are running ISE 1.1.3 using Entrust cert signed by Entrust sub CA L1C, which is signed by Entrust.net 2048, which is in all major OS stores as trusted (Windows, Android, iOS).
We have installed a concatenated PEM file with all of the certificates from the chain, as described in the ISE User Guides. The ISE GUI shows all of the certs in the chain individually after the import (i.e. the chain works and is good). However, we are not sure if the ISE is sending the entire chain to the WLAN clients during EAP authentication or just the ISE cert because of the error message we get on ALL client types which state that the certifiicate is not trusted.
So the question is if the ISE is really sending the whole chain or just its own cert with out the rest of the certs in the chain (which would explain why the WLAN clients complain about the certificate trust.)
Anyone out there know if the ISE code is not up to sending the cert chain in version 1.1.3 yet or if there is some other explanation? Screenshot attached of iPhone prompting for cert verification.Thanks hardiklodhia, your post confirms what we are seeing - the Windows clients have no issue as long as they are set to either NOT validate the EAP server cert or they are set to trust the signing CA cert from the local store by specifically selecting the signing CA (i.e. tick next to "Validate Serverr Certificate" and then another tick next to the signing CA cert in the box below.)
The iOS clients ALWAYS prompt for verification (thanks Apple.)
Note: we are using 1.1.3 and the cert chain import using a concatenated PEM file with ALL of the certs in the chain works fine. We are seeing the whole chain on the clients and the ISE extracts each PEM file into its local store.
The PEM file format is not adequately described in the user guides rather a vague description of cert order is provided.
The file should look like this:
-------------------------Top of page-----------------------------
Root CA PEM FILE
Intermediate CA 1 PEM FILE
Intermediate CA 2 PEM FILE
ETC
ISE CERT PEM FILE
------------------------Bottom of page-------------------------
By "PEM FILE" I mean the actual base64 encoded PEM output from openssl when you convert a .crt or .der file to PEM, including the words "-----BEGIN CERTIFICATE-----" and "-----END CERTIFICATE-----" for each PEM FILE above,
e.g.
-----BEGIN CERTIFICATE-----
MIIE2DCCBEGgAwIBAgIEN0rSQzANBgkqhkiG9w0BAQUFADCBwzELMAkGA1UEBhMC
VVMxFDASBgNVBAoTC0VudHJ1c3QubmV0MTswOQYDVQQLEzJ3d3cuZW50cnVzdC5u
ZXQvQ1BTIGluY29ycC4gYnkgcmVmLiAobGltaXRzIGxpYWIuKTElMCMGA1UECxMc
KGMpIDE5OTkgRW50cnVzdC5uZXQgTGltaXRlZDE6MDgGA1UEAxMxRW50cnVzdC5u
ZXQgU2VjdXJlIFNlcnZlciBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw05OTA1
MjUxNjA5NDBaFw0xOTA1MjUxNjM5NDBaMIHDMQswCQYDVQQGEwJVUzEUMBIGA1UE
ChMLRW50cnVzdC5uZXQxOzA5BgNVBAsTMnd3dy5lbnRydXN0Lm5ldC9DUFMgaW5j
MAwGA1UdEwQFMAMBAf8wGQYJKoZIhvZ9B0EABAwwChsEVjQuMAMCBJAwDQYJKoZI
hvcNAQEFBQADgYEAkNwwAvpkdMKnCqV8IY00F6j7Rw7/JXyNEwr75Ji174z4xRAN
95K+8cPV1ZVqBLssziY2ZcgxxufuP+NXdYR6Ee9GTxj005i7qIcyunL2POI9n9cd
2cNgQ4xYDiKWL2KjLB+6rQXvqzJ4h6BUcxm1XAX5Uj5tLUUL9wqT6u0G+bI=
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIEnzCCBAigAwIBAgIERp6RGjANBgkqhkiG9w0BAQUFADCBwzELMAkGA1UEBhMC
VVMxFDASBgNVBAoTC0VudHJ1c3QubmV0MTswOQYDVQQLEzJ3d3cuZW50cnVzdC5u
ZXQvQ1BTIGluY29ycC4gYnkgcmVmLiAobGltaXRzIGxpYWIuKTElMCMGA1UECxMc
VeSB0RGAvtiJuQijMfmhJAkWuXAwHwYDVR0jBBgwFoAU8BdiE1U9s/8KAGv7UISX
8+1i0BowGQYJKoZIhvZ9B0EABAwwChsEVjcuMQMCAIEwDQYJKoZIhvcNAQEFBQAD
gYEAj2WiMI4mq4rsNRaY6QPwjRdfvExsAvZ0UuDCxh/O8qYRDKixDk2Ei3E277M1
RfPB+JbFi1WkzGuDFiAy2r77r5u3n+F+hJ+ePFCnP1zCvouGuAiS7vhCKw0T43aF
SApKv9ClOwqwVLht4wj5NI0LjosSzBcaM4eVyJ4K3FBTF3s=
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIE9TCCA92gAwIBAgIETA6MOTANBgkqhkiG9w0BAQUFADCBtDEUMBIGA1UEChML
RW50cnVzdC5uZXQxQDA+BgNVBAsUN3d3dy5lbnRydXN0Lm5ldC9DUFNfMjA0OCBp
bmNvcnAuIGJ5IHJlZi4gKGxpbWl0cyBsaWFiLikxJTAjBgNVBAsTHChjKSAxOTk5
IEVudHJ1c3QubmV0IExpbWl0ZWQxMzAxBgNVBAMTKkVudHJ1c3QubmV0IENlcnRp
EN551lZqpHgUSdl87TBeaeptJEZaiDQ9JifPaUGEHATaGTgu24lBOX5lH51aOszh
DEw3oc5gk6i1jMo/uitdTBuBiXrKNjCc/4Tj/jrx93lxybXTMwPKd86wuinSNF1z
/6T98iW4NUV5eh+Xrsm+CmiEmXQ5qE56JvXN3iXiN4VlB6fKxQW3EzgNLfBtGc7e
mWEn7kVuxzn/9sWL4Mt8ih7VegcxKlJcOlAZOKlE+jyoz+95nWrZ5S6hjyko1+yq
wfsm5p9GJKaxB825DOgNghYAHZaS/KYIoA==
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIFKjCCBBKgAwIBAgIETB9GEzANBgkqhkiG9w0BAQUFADCBsTELMAkGA1UEBhMC
VVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xOTA3BgNVBAsTMHd3dy5lbnRydXN0
Lm5ldC9ycGEgaXMgaW5jb3Jwb3JhdGVkIGJ5IHJlZmVyZW5jZTEfMB0GA1UECxMW
KGMpIDIwMDkgRW50cnVzdCwgSW5jLjEuMCwGA1UEAxMlRW50cnVzdCBDZXJ0aWZp
yhHR/hYfdVM88hBXXypACgrxBv/JFlKzSEDwKydJeT1tcP//nG4jv1WWgLk6O2Mi
0oE0fnGmuf9fTX4+CdapG2gTDFJ29Chv3kavJDNtB85A7CK8oWI8Qav78Rvaz7nA
LiRMLBQ1RkqUrQFL2WHx4mJkCddPXzOeOVJlUTGJ
-----END CERTIFICATE-----
The last PEM output (the one directly above) is the ISE cert in PEM format. The first PEM output (the one at the top) is the Root CA cert in PEM format. The ones in the middle are intermediate signing CAs in order (from root to leaf). -
RLDP enabled on WLC causes client drops?
The release notes for WLC code 4.0.206.0 states, "Enabling RLDP may cause access points connected to the controller to lose connectivity with their
clients for up to 30 seconds." Does anyone have more information about this? I don't like the word "may" in there. I need to enable RLDP but I can't afford to have clients dropping. Is this something that will work differently in a new release?There's no may about it. If clients are on an AP that decides to go rogue-hunting they will be told to "get out of the pool" (de-authenticated) to facilitate their going elsewhere. The same applies to DCA - Dynamic Channel Allocation - part of Auto-RF. If you don't have AP density, clients that use fast roaming, or tolerant apps, you would be best served to turn these features off (or On-Damand).
-
All clients drop association at the same time
We are seeing clients dropping their association with few APs all at the same time and would not connect back for several minutes (or even hours). And all of a sudden, they are start to connect back normally.
Wondering what can cause these kind of frequent client disconnects? Only a section of the building is affected and the remaining areas are fine.
Also, at times, I see the signal strength varies between Excellent and Poor within few seconds.
We are using LAPs and WiSM.
Any help would be appreiciated.
Thank you,
MohanIts in the 2.4 GHz band. I have observed this behavior. It works well for a day or two and suddenly a couple of APs only drop all the clients all at the same time. After few minutes (or hours) they are connect back to the APs fine.
This repeats 3 or 4 times in a week.
Thanks,
Mohan -
Hello,
For a couple of years I'm using the rv110w wireless firewall. A few weeks ago I noticed that the WLAN bandwidth drops to 1 - 2 Mbps and only if I restart the router or switch to other WiFi channel fixes the issue. This seems to happen on regular basis amd I havent't made any changea to the router config and there are no errors in the log.
Also the WPS is disabled and I'm using only 802.11n devices.
Looking forward forsuggestions.
Regards
Alexthere is no way to tell if profile ok without the results of btspeedtester diagnostic test with your download speed below 2mb that could suggest that your profile is 2mb and may be stuck especially as you now have 5 days conenction time and profile should have reset to correct level of 7.15mb by now
if conghestion you would expect download speed to be 6mb during the day at off peak and lower at night
check your exchgange here http://usertools.plus.net/exchanges/mso.php
http://usertools.plus.net/exchanges/?
http://btbusiness.custhelp.com/app/service_status
http://bt.custhelp.com/app/answers/detail/a_id/15036
http://community.plus.net/exchange-information/
If you like a post, or want to say thanks for a helpful answer, please click on the Ratings star on the left-hand side of the post.
If someone answers your question correctly please let other members know by clicking on ’Mark as Accepted Solution’. -
Lync 2010 client - Drop down entreis are grey instead of black
We are having Lync 2010 environment. Few users, in Lync 2010 client - Drop down entreis are grey instead of black. Could anyone of you suggest, what needs to be done to fix it?
Thanks
FunnyghostCAS shutdown shouldn't cause issues. If you type the number you see into the Lync search box, does it normalize to E.164 format? If you type in an E.164 number into the dropdown and try to call that, do you see the number there in black?
Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question please click "Mark As Answer".
SWC Unified Communications -
Force WLAN client to renew ip on WLC with dynamic interfaces
Hi there
we would like to have a "two tier" authentication for the corporate WLAN clients:
Requirements
1. Machine Authentication
The client gets machine authenticated based on the machine account in the Active Directory with PEAP. At this stage, the client will get a IP from VLAN A. VLAN A has limited access to the corporate infrastructure (DNS, AD, some volumes / shares, and so on). The filtering is done with an IP access list on the layer 3 VLAN interface on the core switches.
2. User Authentication
The users logs in on the client and gets user authenticated based on his user account in the Active Directory with PEAP - only users with a valid Machine Access Restriction (MAR) are allowed to login. Now the client is moved to another VLAN B. VLAN B has full access to the corporate infrastructure, here is no IP access list.
Infrastructure
We have the following:
2 x WLC 5508 with 7.3.101.0
2 x ACS 5.3.0.40.6
Problem
Now we have the problem, that the Windows client sometimes takes up to 3 minutes to connect to the WLAN after the users loggs in. In the debug, I can see that this happens because the client is stuck in DHCP renewal:
1. After the machine has been authenticated it has an IP assigned from VLAN A. This works pretty well if the client gets rebooted.
2. If the user loggs in the first time after the reboot, the users gets connected within 10 seconds, what is pretty good. The client has now an IP in VLAN B.
3. Now the user logs out of Windows and I can see in the debug, that the client is putted into VLAN A (machine authentication) again, but the client still tries to DHCPREQUEST the IP address from VLAN B (user authentication). Because this request is sent out on the wrong dynamic interface on WLC, the DHCPREQUEST is not acknowleged an the client get stuck in this situation.
4. If the user or another users logs in again shortly after the logout, the client still tries to DHCPREQUEST the IP of VLAN B and now the "3 times DHCP failure on WLC" comes into play, because WLC thinks that the DHCP server is not reachable -> but it only does not answer a wrong DHCPREQUEST.
Question
On ISE there is a way to force the client to renew the DHCP address (via CoA, but this has its limitations too --> need to install Active X or Java applet). I think there is now way to force the client to renew its IP with ACS, but my question is, is there a workaround and are there any others, that maybe already solved this problem?
Alternative
If there is now way to bring this to work with two different VLAN's, I could try to realize this with only one VLAN. After the machine authentication I could apply a WLC ACL to restrict access to the corporate infrastructure. If the user authentication happens, I could "remove" this ACL to grant full access for this user / client. But I am still interested in the other solution ;-)
Thanks in advance for any advise and best regards
DominicYour second option is what you should do. Changing the vlan on a client that already has an IP address especially on wireless will not know it has been put in a different vlan and that's why it breaks. If There was a way to change the vlan and send something to the WLC to disassociate the client, that might work.
Sent from Cisco Technical Support iPhone App -
Cisco 876w: wlan client - routing problem
I configured a Cisco 876w to connect to an existing WLAN as a client. Now I would like to connect 3 PCs to the 876w which should be able to access the internet via the 876w.
Problem:
Being at the console (ssh) of the 876w, I can ping hosts in the internet (even with their name like www.google.com) but when I'm using a client PC, I can't... What am I missing here? Could it be a NAT problem?
Config:
Internet <---> DSL Router 192.168.1.1 (and WLAN AccessPoint) <---> Cisco 876w (gets IP per DHCP, VLAN1 IP: 10.10.10.1) <---> PC (10.10.10.101)
Current configuration : 9897 bytes
version 12.4
no service pad...dot11 vlan-name wlan-lan vlan 1
dot11 ssid WLAN
vlan 1
authentication open
authentication key-management wpa
wpa-psk ascii 7 0923467F1B2E52789807132F7A202E3D31
no ip source-route
ip dhcp excluded-address 10.10.10.1 10.10.10.9
ip dhcp excluded-address 10.10.10.101 10.10.10.254
ip dhcp pool ccp-pool1
import all
network 10.10.10.0 255.255.255.0
default-router 10.10.10.1
domain-name cisco.test.com
dns-server 208.67.222.222
ip cef
no ip bootp server
ip domain name test.com
ip name-server 208.67.222.222ip ddns update method sdm_ddns1
HTTP
add http://[email protected]/nic/update?system=dyndns&hostname=//[email protected]/nic/update?system=dyndns&hostname=<h>&myip=<a>
remove http://[email protected]/nic/update?system=dyndns&hostname=//[email protected]/nic/update?system=dyndns&hostname=<h>&myip=<a>
no ipv6 cef
multilink bundle-name authenticated
isdn switch-type basic-net3
username admin privilege 15 secret 5 $1$uiouLKjbLIUBlKbj
username service privilege 15 secret 5 $1$LKjblkJNBLKkjlbkm
archive
log config
hidekeys
ip tcp synwait-time 10
ip ssh time-out 60
ip ssh authentication-retries 2
class-map type inspect match-all sdm-cls--1
match access-group name AllowAny
policy-map type inspect sdm-policy-sdm-cls--1
class type inspect sdm-cls--1
inspect
class class-default
drop
zone security wan
zone security lan
zone-pair security sdm-zp-lan-wan source lan destination wan
service-policy type inspect sdm-policy-sdm-cls--1
interface BRI0
description <--
no ip address
ip flow ingress
ip virtual-reassembly
encapsulation ppp
shutdown
dialer pool-member 1
isdn switch-type basic-net3
isdn point-to-point-setup
ppp multilink!
interface ATM0
backup interface BRI0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
shutdown
no atm ilmi-keepalive
interface ATM0.3 point-to-point
description <--
ip flow ingress
shutdown
pvc 1/32
pppoe-client dial-pool-number 2
interface FastEthernet0
interface FastEthernet1
interface FastEthernet2
interface FastEthernet3
interface Dot11Radio0
description <--
no ip address
no ip proxy-arp
ip flow ingress
ip virtual-reassembly
no ip route-cache cef
no ip route-cache
encryption mode ciphers aes-ccm
encryption vlan 1 mode ciphers aes-ccm
ssid WLAN
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role non-root
no cdp enable
interface Dot11Radio0.1
encapsulation dot1Q 1 native
ip address dhcp
ip nat outside
ip virtual-reassembly
no ip route-cache
no cdp enable
interface Vlan1
description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$ES_LAN$$FW_INSIDE$
ip address 10.10.10.1 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
ip nat inside
ip virtual-reassembly
zone-member security lan
ip tcp adjust-mss 1412
interface Dialer0
ip ddns update hostname blahblah.dnsalias.com
ip ddns update sdm_ddns1
ip address negotiated
ip nat outside
ip virtual-reassembly
zone-member security wan
encapsulation ppp
shutdown
dialer pool 1
dialer idle-timeout 600
dialer string 01919214124
dialer load-threshold 20 outbound
dialer watch-group 1
dialer-group 1
no cdp enable
ppp authentication chap pap callin
ppp chap hostname asfa
ppp chap password 7 128763520
ppp pap sent-username asfa password 7 0302141555
ppp multilink
interface Dialer2
ip ddns update sdm_ddns1
ip address negotiated
ip mtu 1452
ip nat outside
ip virtual-reassembly
zone-member security wan
encapsulation ppp
dialer pool 2
dialer-group 2
no cdp enable
ppp authentication chap pap callin
ppp chap hostname gast
ppp chap password 7 095B239876473F06090A
ppp pap sent-username gast password 7 1239847629873693D
router rip
network 10.0.0.0
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 192.168.1.1
ip http server
ip http access-class 23ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 105 interface Dialer0 overload
ip nat inside source list 106 interface Dot11Radio0.1 overload
ip access-list extended AllowAny
remark CCP_ACL Category=128
permit ip 10.10.10.0 0.0.0.255 any
ip access-list extended nix
remark tut nix
remark CCP_ACL Category=2
permit tcp any any
permit udp any any
permit icmp any any
permit ip any any
logging trap debugging
access-list 1 remark INSIDE_IF=Vlan1
access-list 1 remark CCP_ACL Category=2
access-list 1 permit 10.10.10.0 0.0.0.255
access-list 100 remark CCP_ACL Category=2
access-list 100 permit ip any any
access-list 101 remark CCP_ACL Category=2
access-list 101 permit ip 10.10.10.0 0.0.0.255 any
access-list 102 remark CCP_ACL Category=2
access-list 102 permit ip 10.10.10.0 0.0.0.255 any
access-list 103 remark CCP_ACL Category=2
access-list 103 permit ip 10.10.10.0 0.0.0.255 any
access-list 105 remark Alles
access-list 105 remark CCP_ACL Category=2
access-list 105 permit ip 10.10.10.0 0.0.0.255 any
access-list 105 permit icmp 10.10.10.0 0.0.0.255 any
access-list 105 permit udp 10.10.10.0 0.0.0.255 any
access-list 105 permit tcp 10.10.10.0 0.0.0.255 any
access-list 106 remark NAT wlan
access-list 106 remark CCP_ACL Category=2
access-list 106 permit ip 10.10.10.0 0.0.0.255 any
access-list 106 permit icmp 10.10.10.0 0.0.0.255 any
access-list 106 permit udp 10.10.10.0 0.0.0.255 any
access-list 106 permit tcp 10.10.10.0 0.0.0.255 any
dialer watch-list 1 ip 208.67.222.222 255.255.255.255
dialer-list 1 protocol ip permit
no cdp run
radius-server attribute 32 include-in-access-req format %h
radius-server vsa send accounting
control-plane
banner exec ^C
% Password expiration warning.
Cisco Configuration Professional (Cisco CP) is installed on this device
and it provides the default username "cisco" for one-time use. If you have
already used the username "cisco" to login to the router and your IOS image
supports the "one-time" user option, then this username has already expired.
You will not be able to login to the router with this username after you exit
this session.
It is strongly suggested that you create a new username with a privilege level
of 15 using the following command.
username <myuser> privilege 15 secret 0 <mypassword>
Replace <myuser> and <mypassword> with the username and password you
want to use.
^C
banner login ^CAuthorized access only!
Disconnect IMMEDIATELY if you are not an authorized user!^C
line con 0
no modem enable
transport output telnet
line aux 0
transport output telnet
line vty 0 4
transport input telnet ssh
scheduler max-task-time 5000
scheduler allocate 4000 1000
scheduler interval 500
end
#sh ip int brief
ndrmedienturm#sh ip int brief
Interface IP-Address OK? Method Status Protocol
FastEthernet0 unassigned YES unset up up
FastEthernet1 unassigned YES unset up down
FastEthernet2 unassigned YES unset up down
FastEthernet3 unassigned YES unset up down
BRI0 unassigned YES NVRAM standby mode/disabled down
BRI0:1 unassigned YES unset administratively down down
BRI0:2 unassigned YES unset administratively down down
Dot11Radio0 unassigned YES TFTP up up
Dot11Radio0.1 unassigned YES DHCP up up
ATM0 unassigned YES NVRAM administratively down down
ATM0.3 unassigned YES unset administratively down down
SSLVPN-VIF0 unassigned NO unset up up
Vlan1 10.10.10.1 YES NVRAM up up
NVI0 unassigned YES unset administratively down down
Dialer0 unassigned YES NVRAM administratively down down
Dialer2 unassigned YES NVRAM up up
Virtual-Dot11Radio0 unassigned YES TFTP up up
Virtual-Dot11Radio0.1 192.168.1.54 YES DHCP up upHi,
Just check it out few things from client are you able to ping the wan interface of the cisco 876w and when you ping the internt address from client pc what is the out put of the nat translation in router.
The command to check the same is show ip nat translation is packet is gettin translated or not.
Hope to Help !!
Ganesh.H -
Hi Community
I am new to the forum but really desparate.
My first Cisco product and trouble trouble trouble.
I bought a WRVS4400N with the actual Firmware V2.008.ETSI
I am connected to the Internet by cable, cablemodem is plugged into my new Cisco router then goes to a Gigabit Switch (3Com), House ist equipped with cat. 7 Gigabit cable.
My Problem:
Modem and router up an running on a 7/24 hour basis.
Problem 1:
I am using Wlan functionality but every other day, the Wlan loses internet connectivity meaning I have contact to LAN bot WAN (internet) is dead, all W7 clients show me the "!" in the internet connection. If I switch to cable (gigabit) connection, everything works fine. Log into the router (via LaN), do a reset of the router and everything (cable and Wlan) is up an running again.
Problem 2:
Sometimes (not often) also cable shows the "!", no log in to the router is possible, have to reset the router and up an running again.
I am very confused, I switched the cable modem (from a 100mb to a gigabit lan) but the problem persists.
As Wlan and Lan can be affected, I think there must be a problem with the router, I am using the standard setup with a hidden wlan name, changed the wlan connection types from all to G only no luck.
It seems that the router "loses" connectivity to internet on purpose.
Can someone give me a tip?
If you need more specification feel free to ask.
Thank you very much for your time.
Best
AndreasI have had similar problems - more relating to the Access Policy rather than the IP rules. Try rebooting. That has fixed it for me. I suspect that some form of CRON or timer stops after a while. This, BTW is a security issue as the router will not stop Internet Access at the correct time once this happens.
If that does not work try turning all the Access Policies off, save setting then turn just one on.
Don't forget that the Access Policies will only work for the first machine macth. ie. If a system matches in the List of PCs no other Access Policies will be matched.
Let us know how this goes...,
David -
WLAN Clients unable to access the Gateway when more than 2 clients connect
Hi,
I have a problem with a 2106 WLAN Contoller.
The clients can connect and associate to the WLAN and get their IP details via DHCP from the internal DHCP server. However, only 2 clients can get out through the gateway at any one time. All other clients that connect will get their DHCP addresses(that match the config of the 1st 2 clients), but they cannot get to the gateway. They can ping any client on the WLAN and the controller.Hi,
Please post the IP configuration for your gateway, the working clients and the clients having problems.
Regards,
Kristofer -
4400 WLC Layer 3 Authentication Status for WLAN Clients
We have 3 4400 series WLC's(wireless LAN controllers). Two 4404 WLC's are on the "inside" of our network and all AP's (access points) on our network use these two WLC's as the primary or secondary controller. The 4402 WLC Anchor controller resides in our DMZ and is used for WLANs that are more oriented for guest usage. These guest WLANs are configured on the inside controllers also, but are "anchored" to the 4402. On the anchor controller we are using layer 3 Web Authentication for the WLAN "Guest". This WLAN uses the internal web-auth page within the anchor controller and a username/password combo that is locally defined on the anchor controller.
Functionally there is no issue. Users connecting to the WLAN are presented with the web-auth page upon connecting to the WLAN and opening a web browser. The issue is how the layer 3 authentication information is presented on the Monitor Clients page of the "inside" WLC's management screen as compared to the "anchor" WLC.
For example, if we log in to the anchor controller and then click Monitor, then Client, then Change Filter and choose any WLAN requiring layer 3 authentication on the Anchor controller, there will be a list of all clients currently associated. In the Column with the "Auth" heading it shows the Layer 3 Authentication status of the clients. For example, if there are 15 clients associated to WLAN SSID "Guest", but only 5 of them have opened their web browsers and correctly logged in, then this will be correctly displayed. The 5 who have logged in will show "Yes" and the other 10 will show "No" in the Auth column.
Now...the problem...on the inside controllers...if we do the same thing (monitor, clients, filter for WLAN SSID "Guest"), all 15 will show "Yes" under the Auth column. In most cases the 15 clients will be distributed accross both controllers (maybe 6 on one, and 9 on the other WLC), but both inside controllers will display all clients as having a layer 3 authentication status of "Yes". We have proven over and over that this is not accurate. This is very inconvenient because the "Client Count" reports we run on the WCS server reflect the same information as the "inside" controllers. The WSC reports will show all 15 as Authenticated and they are not. We have proven many times that the anchor WLC is the only controller accuratly conveying this info.
Also, the engineers who helped with our network install have reproduced the same behavior in a lab with an anchor and inside controller directly connected. They suggested it may be a code bug with the 4400 series WLC. We are running controller Software Version 6.0.188.0 on all 3 controllers.
Please let me know what you think may be causing this issue. Any help or advice is greatly appreciated!Hi,
We run version 7.0 on the WCS and WLCs but I thought I'd try the report and see what I got. The result is a line graph with the number of associated and authenticated clients superimposed. I'm not sure how useful a report of this nature is.
It doesn't inspire confidence: when I specifiy the guest wireless SSID I get zero clients! I know there have been guest clients authenticated during the report period I spec'd.
Scott -
WLC 5508 disable wlan client still connected
I have one wlc 5508 running on latest IOS 7.116, there is one wlan abc which i have disable status and disable broadcast, but randomly still i can see from wlc dashboard there is one client connected to this wlan abc. The moment i check on the client details, there is no client connected to that wlan and when return to dashboard, no more client connected to that wlan abc. This happened in randomly, it is bug or something else?
I would guess that the client entry also indicates "probing" as status. It means that the client is not connected. It is actually probing, so it"s looking for that SSID that it probably associated to in the past (so it remembers about it)
-
Hello all,
My company has deployed AnyConnect Secure Mobility Client 3.1.04059 and we use Windows 7
The client works fine most of the time, but all of a sudden the connection drops. I can see both the Windows Network and Sharing Center and Cisco AnyConnect suddenly disconnected. This happens most of the times that I change to another location with a different wi-fi network. With my past Windows 2003 and AnyConnect versions (not sure which one that was), the VPN connection would be recovered shortly after re-connecting to the new wi-fi, but with this version it will never allow me to connect to the new wi-fi. Sometimes, if I use the troubleshoot manager from Windows, it will reset my network adapter and that will allow me to connect to the new wi-fi network. Most of the times it won't.
In those cases, I need to close all programs, log off and log back into Windows. Some other times that will not work either and I will need to restart the whole machine. Restarting the Anyconnect related services alone does not help.
I am worried because today I lost the connection all of a sudden in my own home, while any other device could easily connect to the wifi. Anyconnect will simply say that it is unable to connect. After many tests I had to reset the computer.
Am I the only one seeing this problem? Any advice anyone can give me?
Thanks in advance,
AntonioSo it seems that I was barking at the wrong tree :)
After a bit more research on-line, I found that changing the Power management options for the Wireless network adapter resolved the problem.
I went to Control Panel> Device Manager> right-click on Wireless Network Adapter> Properties > Power Management tab > Uncheck 'Allow the computer to turn off this device to save power'
So far so good. Hope this helps others.
Best,
Antonio -
Multiple airport express clients dropping iTunes
Hello, I'm new to the board and appreciate the resource and any feedback you guys can provide.
My music is stored on the iMac and I'm trying to stream iTunes to two AX's and the music drops out often. They are both set up as clients. I have searched this forum extensively and think I have isolated the problem as one of the following:
Something to do with UDP protocal
Linksys WRT51AB router settings
512Mb RAM on iMac--too little?
Here's my troubleshooting thus far:
Both airport expresses work by themselves in their current locations.
Locations are close to computer, 1st within 10 feet (1 wall), 2nd another 10-15 feet (2 walls)
Checked firewall settings and "Block UDP" box is unchecked
I tried to forward Port 6000 on my Linksys router based on some advice in another thread here to no avail
AX Firmware 6.3
iTunes 6.0.4
OSX 10.4.6
Thanks for the help
G4 PB & Intel iMac Mac OS X (10.4.6)Thanks for the suggestion. I had not tried that option as I had read somewhere that there is only one Linksys router that supports this setup and it's not the one I have.
I will try the solution and report back. I assume an AX configured as a range extender can also function to stream iTunes?
Also, for clarification, I am using two airport expresses both of which to stream music. They access my network through my Linksys router hardwired to the iMac.
Thanks.
Maybe you are looking for
-
Unable to retrive the data using self join
I am trying to find the time taken to close a ticket. The ticket goes through various stages: NEW, INPROCESS, CLOSED, REOPENED. If the ticket is reopened then the next stage would be INPROCESS and then CLOSED. The CC_TICKET_INFO table contains inform
-
When importing an iPhoto event into iDVD (iLife '11 versions of both) by dragging it from iPhoto to iDVD, the sequence of the photos is far different in the iDVD project than in the iPhoto event, without any apparent rhyme or reason for the change.
-
Additional Links in ToolAreaiView
I´d like to have additional Links in the ToolAreaiView such as "Impressum" and "Kontakt". To add a link is simple. But how do I code it, that the content is displayed in the Content Area of my Frameworkpage?
-
How to provide view selection dropdown like ALV
Hi all, As you know, ALV can save your own view but it's embeded in component SALV_WD_TABLE. And I want to provide such a dropdown on selection screen before searching. Can I reference this dropdown directly? I've found out the db tables that store t
-
Getting Error- Desktop\WSDL1\main.wsdl The system cannot find the path spec
Hai to every one ! iam using wsdl file which is downloaded "wsdlzip" file from wsnavigator to my desktop. Extracted zip file . i used main.wsdl file as adaptive webservice model in webdynpro application. I developed application then iam not getting o