getXML('<?xml version="1.0" encoding="UTF-8"?><ActiveMessages>Security and Network Management5084<Community id=".ee6b2b0" title="Networking Professionals">  <Forum id=".ee6e8b6" title="Wireless - Mobility"><Topic id=".ee6e8c0" private="" title="Security and Network Management"><Conversation id=".2cd4d91e" messages="2" subscribed="yes" title="Reason:802.11 Association failed repeatedly. ReasonCode: 2"><Message attachment="no" canreply="yes" id=".2cd4d91e" level="">      <Author authinfo="Network Engineer, TRENDGLOBAL LDA">artur.pinto</Author><Timestamp>Nov 2, 2009, 4:32am PST</Timestamp><Msgbody>Hi,&lt;br /&gt;&lt;br /&gt;I have a costumer that has a wireless network with a WLC 4400 (ver 6.0.182.0) and several Aironet APs (1250 version 12.4).&lt;br /&gt;He also has a Wireless IP Phone. The IP Phone loses the communication with the LAN very often.&lt;br /&gt;In the WLC logs we can see the following error:&lt;br /&gt;Client Excluded: MACAddress:00:24:c4:55:11:58 Base Radio MAC :00:25:84:89:fe:20 Slot: 0 &lt;br /&gt;User Name: unknown Ip Address: 10.70.18.113 Reason:802.11 Association failed repeatedly. ReasoCode: 2&lt;br /&gt;In the documentation I did not see any information regarding this error, anybody has a clue about the meaning of this error? How can I fix it?&lt;br /&gt;Best Regards,&lt;br /&gt;&lt;br /&gt;Artur Pinto &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4d91e/0" level="1." new="yes">            <Author authinfo=" CISCO SYSTEMS">dancampb</Author><Timestamp>Nov 2, 2009, 6:58am PST</Timestamp><Msgbody>If memory serves correct reason code 2 means that a duplicate IP address was detected.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" editable="yes" id=".2cd4d91e/1" level="1.1" new="yes">      <Author authinfo="Sr Information Center Analyst, Munson Healthcare">lotten1981</Author><Timestamp>Nov 17, 2009, 9:24am PST</Timestamp><Msgbody>I&apos;m getting this also a 1252 AP attached to a WiSM running 5.2</Msgbody><Attachment/></Message></Reply></Reply></Replies></Conversation><Conversation id=".2cd4f302" messages="0" subscribed="no" title="Mac Filtering"><Message attachment="no" canreply="yes" id=".2cd4f302" level=""><Author authinfo=" Me">tdrumond@almavivadobrasil.com.br</Author><Timestamp>Nov 17, 2009, 6:05am PST</Timestamp><Msgbody>Hi all,&lt;br /&gt;I would like to configure MAC filtering on my 851W Router. I mean, only certain MAC address could have access to the wirelless network.&lt;br /&gt;Is that possible?&lt;br /&gt;How is the best way to do that on this router?&lt;br /&gt;&lt;br /&gt;Thank you&lt;br /&gt;Regards</Msgbody> <Attachment/></Message></Conversation><Conversation id=".2cd4ef2d" messages="2" subscribed="no" title="How to generate WEP key automatically for client?"><Message attachment="no" canreply="yes" id=".2cd4ef2d" level=""><Author authinfo=" PT MASTERSYSTEM INFOTAMA">Charles_Chi4</Author><Timestamp>Nov 14, 2009, 12:11am PST</Timestamp><Msgbody>Hi,&lt;br /&gt;&lt;br /&gt;I just set up PEAP for my client with WEP encryption with EAP. Then the client ask me to eliminate any key before prompting user&apos;s credential.&lt;br /&gt;&lt;br /&gt;I tried to remove encryption but the EAP itself won&apos;t work with encryption disabled. Then my client look into windows wirelesss NIC setting and found that below "network key" there&apos;s a option for "The key is provided for me automatically"&lt;br /&gt;&lt;br /&gt;For that reason, Access Point should be able to generate WEP key without user entering it. Does any body knows how to enable this feature?</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4ef2d/0" level="1." new="yes"><Author authinfo=" Science Applications International Corporation">Robert.N.Barrett</Author><Timestamp>Nov 15, 2009, 10:10am PST</Timestamp><Msgbody>How are you performing your PEAP authentication?  That would help us answer your question.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ef2d/1" level="1.1" new="yes">            <Author authinfo=" SyCom Roanoke">swyatt@sycomtech.com</Author><Timestamp>Nov 16, 2009, 1:32pm PST</Timestamp><Msgbody>To support dynamic wep you will need to setup a RADIUS server for authentication. You would then configure PEAP or EAP-TLS for athentication. IAS (Server 2000, 2003) or NPS (Server 2008) is free, but if you are going to dynamic WEP why not go with WPA.</Msgbody><Attachment/></Message></Reply></Reply></Replies></Conversation><Conversation id=".2cd4ebbf" messages="5" subscribed="no" title="Apple MAC Cannot Connect on Wireless Using PEAP Auth"><Message attachment="no" canreply="yes" id=".2cd4ebbf" level="">            <Author authinfo=" Reliance Industries Limited">yusuf.ujjainwala</Author><Timestamp>Nov 12, 2009, 6:47am PST</Timestamp><Msgbody>I have a WLAN setup using the Cisco WiSM, Cisco ACS 4.1.3 as the Radius Server. We are using PEAP as the WLAN Security. THe issue is that all the clients who have Windows OS are able to connect to the WLAN and PEAP works fine.However the users who have Apple MAC OS are unable to connect to the WLAN that has PEAP as the Security setting. The MAC has OS 10.5.6 and I tried upgrading the image however the prob persists. On the ACS server I get in the Failed Log as "Internal Error". &lt;br /&gt;Can someone help what does the Error mean , and any resolution for the issue.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4ebbf/0" level="1." new="yes"><Author authinfo=" Science Applications International Corporation">Robert.N.Barrett</Author><Timestamp>Nov 12, 2009, 8:07am PST</Timestamp><Msgbody>Can you provide some detail about how you created the user profile on the Mac?  Also - did you put the ACS server&apos;s certificate into the Mac&apos;s System store so that the Mac will trust the ACS server (or configure the PEAP profile on the Mac to ignore the ACS server&apos;s certificate)?</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ebbf/1" level="1.1" new="yes">            <Author authinfo=" Reliance Industries Limited">yusuf.ujjainwala</Author><Timestamp>Nov 12, 2009, 10:45pm PST</Timestamp><Msgbody>I went to the Airport Network Preferences and created the profile. I have configured the PEAP profile to ignore the ACS&apos;s certificate.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ebbf/2" level="1.1.1" new="yes"><Author authinfo=" Science Applications International Corporation">Robert.N.Barrett</Author><Timestamp>Nov 13, 2009, 4:47am PST</Timestamp><Msgbody>Don&apos;t know of any reason why it wouldn&apos;t work.  I have clients with hundreds of Macs using PEAP (with user credentials, not machine credentials).&lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Reply></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd4ebbf/3" level="2." new="yes"><Author authinfo=" CISCO SYSTEMS">weterry</Author><Timestamp>Nov 15, 2009, 8:26pm PST</Timestamp><Msgbody>Perhaps your ACS is configured to only allow PEAP-MSChapv2? Don&apos;t Apples use PEAP-GTC?&lt;br /&gt;&lt;br /&gt;Doesn&apos;t explain the error though...</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd4ebbf/4" level="3." new="yes"><Author authinfo=" Science Applications International Corporation">Robert.N.Barrett</Author><Timestamp>Nov 16, 2009, 12:32pm PST</Timestamp><Msgbody>Something in the back of my mind is reminding of an "Internal Error" message in the ACS logs when the Active Directory user account is disabled.</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4f19e" messages="0" subscribed="no" title="WLC ACL - Management"><Message attachment="no" canreply="yes" id=".2cd4f19e" level="">            <Author authinfo=" Network Group, AEGIS MEDIA AMERICAS, INC.">john.judge@carat.com</Author><Timestamp>Nov 16, 2009, 12:31pm PST</Timestamp><Msgbody>Hi,&lt;br /&gt;Has anyone been able to configure restrictive access to the Management interface?  I created an ACL that specifies our Management VLAN and set the action to "permit".  I then added this ACL to the management interface, but I&apos;m still able to login from any IP.  The WLC is running  	 4.2.176.0 and to my knowledge there are no known bugs related to this.  Thank you.&lt;br /&gt;-John</Msgbody> <Attachment/></Message></Conversation><Conversation id=".2cd4f14d" messages="0" subscribed="no" title="need WAP running SSH-2.0-OpenSSH_4.0"><Message attachment="no" canreply="yes" id=".2cd4f14d" level=""><Author>jhansen@qualys.com</Author><Timestamp>Nov 16, 2009, 9:26am PST</Timestamp><Msgbody>In order to replicate a bug, I&apos;m looking to add a Cisco WAP to my lab which has an ssh banner of SSH-2.0-OpenSSH_4.0.&lt;br /&gt;Does anyone know of a hardware / software version which runs this version of SSH?&lt;br /&gt;I have a 350, 1100 and 1220B but they are all running SSH-1.5-Cisco-1.25&lt;br /&gt;Thanks!</Msgbody> <Attachment/></Message></Conversation><Conversation id=".2cd4ec63" messages="3" subscribed="no" title="ACL in Controller 4404"><Message attachment="no" canreply="yes" id=".2cd4ec63" level="">      <Author authinfo="SUPPORT ANALYST, DATASUS">paulo.s</Author><Timestamp>Nov 12, 2009, 10:52am PST</Timestamp><Msgbody>Hi.&lt;br /&gt;I read CWCS Configuration Guide release 5.1 about ACL, applied ACL to WLAN, but didn&apos;t work.&lt;br /&gt;&lt;br /&gt;I want to restrict wireless client access any networks.&lt;br /&gt;&lt;br /&gt;If anyone knows, please help me.&lt;br /&gt;&lt;br /&gt;Thks.&lt;br /&gt;&lt;br /&gt;Paulo Maurício</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4ec63/0" level="1." new="yes">            <Author authinfo=" CISCO SYSTEMS">dancampb</Author><Timestamp>Nov 12, 2009, 11:15am PST</Timestamp><Msgbody>Keep in mind with ACLs on the controller they are written with the assumption that you are on the controller and traffic is coming from the wireless clients in regards to the inbound and outbound directions.  Also you need to write an inbound and outbound rule for each condition.  They aren&apos;t like IOS ACLs that will automatically allow the return traffic through.&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a00807810d1.shtml&apos;)"&gt;http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a00807810d1.shtml&lt;/A&gt;&lt;br /&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ec63/1" level="1.1" new="yes">      <Author authinfo="SUPPORT ANALYST, DATASUS">paulo.s</Author><Timestamp>Nov 12, 2009, 11:41am PST</Timestamp><Msgbody>Thks for help. &lt;br /&gt;&lt;br /&gt;I will test.&lt;br /&gt;</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd4ec63/2" level="1.2" new="yes">      <Author authinfo="SUPPORT ANALYST, DATASUS">paulo.s</Author><Timestamp>Nov 13, 2009, 6:44am PST</Timestamp><Msgbody>Ok, it works!!!&lt;br /&gt;&lt;br /&gt;I found the error. I was configuring by WCS, and when I configured protocol to ANY, returned this message: Protocol : 256 : Value for this attribute is invalid. (Valid Range: is 0 &lt;&gt; 255 )&lt;br /&gt;&lt;br /&gt;My WCS version is Version 5.1.64.0, and controller software version is 4.2.112.0.&lt;br /&gt;&lt;br /&gt;Thks for help.</Msgbody><Attachment/></Message></Reply></Reply></Replies></Conversation><Conversation id=".2cd45fdb" messages="11" subscribed="no" title="802.1x authentication on PSK key mgmt?"><Message attachment="no" canreply="yes" id=".2cd45fdb" level=""><Author authinfo=" Border Land School Division">danletkeman</Author><Timestamp>Aug 21, 2009, 6:01am PST</Timestamp><Msgbody>Hello,&lt;br /&gt;&lt;br /&gt;I&apos;m setting up a new 5508 WLC (the first wlc I have ever setup) and I have my WLAN setup with our existing WPA/TKIP ssid for transitioning our clients from our existing autonomous system to the wlc.  I have selected PSK as the key mgmt and I can get the client&apos;s to connect for a few minutes but I keep seeing these errors:&lt;br /&gt;&lt;br /&gt; Fri Aug 21 08:50:05 2009 Client Excluded: MACAddress:00:21:00:f9:dd:50 Base Radio MAC :00:23:eb:27:e3:b0 Slot: 1 User Name: unknown Ip Address: unknown Reason:802.1x Authentication failed 3 times. ReasonCode: 4&lt;br /&gt;&lt;br /&gt;I don&apos;t have nor do I want 802.1x enabled.  Is there something I need to disable either on the client or the controller?&lt;br /&gt;&lt;br /&gt;Thanks.&lt;br /&gt;Dan.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd45fdb/0" level="1." new="yes"><Author authinfo=" Science Applications International Corporation">Robert.N.Barrett</Author><Timestamp>Aug 21, 2009, 7:12am PST</Timestamp><Msgbody>Congrats on getting your first controller set up.  Since you don&apos;t have any 802.1X configured, could it be that the client in question is trying to use an incorrect PSK?</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd45fdb/1" level="1.1" new="yes"><Author authinfo=" Border Land School Division">danletkeman</Author><Timestamp>Aug 21, 2009, 8:39am PST</Timestamp><Msgbody>I don&apos;t think so.  All of the clients connect, but then get disconnected with the 802.1x error message.&lt;br /&gt;&lt;br /&gt;Dan.</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd45fdb/2" level="1.2" new="yes"><Author authinfo=" Border Land School Division">danletkeman</Author><Timestamp>Aug 21, 2009, 9:36am PST</Timestamp><Msgbody>If I click on the client and look at the client details it shows under the policy manager state that 802.1x is required.  Is there something configured wrong on the client?&lt;br /&gt;&lt;br /&gt;Clients &gt; Detail&lt;br /&gt;	&lt;br /&gt;Client Properties&lt;br /&gt;MAC Address 	                00:21:00:f9:dd:50&lt;br /&gt;IP Address 	&lt;br /&gt;Client Type 	&lt;br /&gt;WGB MAC Address 	&lt;br /&gt;Number of Wired Client(s) 	&lt;br /&gt;User Name 	&lt;br /&gt;Port Number 	&lt;br /&gt;Interface 	&lt;br /&gt;VLAN ID 	&lt;br /&gt;CCX Version 	&lt;br /&gt;E2E Version 	&lt;br /&gt;Mobility Role 	&lt;br /&gt;Mobility Peer IP Address 	&lt;br /&gt;Policy Manager State 	           8021X_REQD&lt;br /&gt;Management Frame Protection 	</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd45fdb/3" level="1.2.1" new="yes"><Author authinfo=" Border Land School Division">danletkeman</Author><Timestamp>Aug 22, 2009, 1:41pm PST</Timestamp><Msgbody>I have come across some more information reguarding my problem.&lt;br /&gt;&lt;br /&gt;When the lap cannot connected to the wlc then everything works!  The clients can connect just fine without problems.  As soon as I take the acl of the switch port and allow the lap to connect back to the controller, the client&apos;s cannot connect.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd45fdb/4" level="1.2.1.1" new="yes"><Author authinfo=" Border Land School Division">danletkeman</Author><Timestamp>Aug 22, 2009, 3:11pm PST</Timestamp><Msgbody>Just another note.&lt;br /&gt;&lt;br /&gt;When i set the Wlan to no authentication (open system) then I can connect to the ap when it is in h-reap mode and communicating with the controller.  When i have the Wlan set to wpa/aes/psk i cannot connect.&lt;br /&gt;&lt;br /&gt;Is there a know bug in 6.0.182.0?&lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Reply></Reply></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd45fdb/5" level="2." new="yes">            <Author authinfo=" CYGATE AB">kristoferheyl</Author><Timestamp>Aug 25, 2009, 11:08pm PST</Timestamp><Msgbody>I had a similar problem a while ago, caused by WCS not setting the PSK correctly on the WLC. Cisco TAC informed me that the error message not necessary is a dot1x error message, it can also indicate a PSK error (wrong key).&lt;br /&gt;&lt;br /&gt;Are you using WCS to push the PSK to the WLC?</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd45fdb/6" level="2.1" new="yes"><Author authinfo=" Border Land School Division">danletkeman</Author><Timestamp>Aug 26, 2009, 9:41am PST</Timestamp><Msgbody>No I am not using WCS.  I contacted TAC and it looks like it might be a bug in the 6.x software.  There next step was to re-create it in there lab.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd45fdb/7" level="2.1.1" new="yes"><Author authinfo=" Science Applications International Corporation">Robert.N.Barrett</Author><Timestamp>Aug 26, 2009, 8:44pm PST</Timestamp><Msgbody>If you are using WPA with AES, then I would change that setting - either use WPA with TKIP, or use WPA2 with AES (even if that does not solve your problem).  Even though you are supposed to be able to mix and match WPA/WPA2 and TKIP/AES, I have seen some clients that work better using WPA/TKIP or WPA2/AES.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd45fdb/8" level="2.1.1.1" new="yes"><Author authinfo=" Border Land School Division">danletkeman</Author><Timestamp>Aug 27, 2009, 9:41am PST</Timestamp><Msgbody>It&apos;s not that either.  I have tried every combination of WPA and WPA2...the only ones that work is WEP or Open System.&lt;br /&gt;&lt;br /&gt;WPA and WPA2 work when the ap connection to the controller is lost.  So it looks like the ap is not operating in H-Reap mode when it has a connection to the controller.&lt;br /&gt;&lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Reply></Reply></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd45fdb/9" level="3." new="yes">            <Author authinfo=" CISCO SYSTEMS">mcoverdi</Author><Timestamp>Nov 12, 2009, 10:28pm PST</Timestamp><Msgbody>Does your PSK have any numbers, special characters or is it exceptionally long? Try temporarily changing the PSK to something short with lower case characters only to see if that allows you to connect.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd45fdb/10" level="3.1" new="yes"><Author authinfo=" Border Land School Division">danletkeman</Author><Timestamp>Nov 13, 2009, 6:01am PST</Timestamp><Msgbody>I fixed the problem a while ago with a restart of the controller.  I had never restarted it after the initial bootup.</Msgbody><Attachment/></Message></Reply></Reply></Replies></Conversation><Conversation id=".2cd4ed0b" messages="0" subscribed="no" title="ASA5505 - Remove VPN Connections"><Message attachment="no" canreply="yes" id=".2cd4ed0b" level="">      <Author authinfo="Sr Network Engineer, Systemmetrics" ccie="yes">robert-ho</Author><Timestamp>Nov 12, 2009, 6:29pm PST</Timestamp><Msgbody>hey all, have a simple question.&lt;br /&gt;&lt;br /&gt;the page below indicates that it can handle up to 10 vpn connections with a base license. does it mean that we can only configure 10 vpn user/pass credentials? or, we can create, say 50 user/pass accounts, but only 10 can remote in at the same time.&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/products/ps6120/prod_models_comparison.html&apos;)"&gt;http://www.cisco.com/en/US/products/ps6120/prod_models_comparison.html&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;thanks for the help.&lt;br /&gt;-robert</Msgbody> <Attachment/></Message></Conversation><Conversation id=".2cd4ec85" messages="1" subscribed="no" title="use Active Directory as a external User database for Wism&apos;s access"><Message attachment="no" canreply="yes" id=".2cd4ec85" level="">            <Author authinfo=" jem COnsulting, II">janet.maxwell</Author><Timestamp>Nov 12, 2009, 11:48am PST</Timestamp><Msgbody>Hello,  I am looking into the ability to Use Active directory to Login to the wism controllers.  I have been looking on Cisco website and It does not seem to be supported.  It seems Like you can use LDAP to query the Controllers for credientials.  However, LDAP is only supported if the LDAP server is set up to return a clear-text password. My controllers are version 4.2.185 we cant upgrade at this time we have legacy 1020AP. Can AD be Used?</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4ec85/0" level="1." new="yes">            <Author authinfo=" CISCO SYSTEMS">dancampb</Author><Timestamp>Nov 12, 2009, 12:47pm PST</Timestamp><Msgbody>The controllers can only talk directly to AD through LDAP.  The other option to use AD is to go trough a Radius server.  Since you have Windows servers why not just enable IAS?</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4ec62" messages="0" subscribed="no" title="Need help configuring multiple VLANs and SSIDs"><Message attachment="no" canreply="yes" id=".2cd4ec62" level=""><Author authinfo=" ILER NETWORKING AND COMPUTING">gary@iler.com</Author><Timestamp>Nov 12, 2009, 10:51am PST</Timestamp><Msgbody>Hi, &lt;br /&gt;&lt;br /&gt;We bought a Cisco SGE2000P 24Port switch and 10 WAP4410N access points. Our intent is to provide a secure network to our LAN, and a guest network to the Internet. &lt;br /&gt;&lt;br /&gt;We are thinking 3 VLANs would be best for this: VLAN 100 connected to the LAN, VLAN 1000 for the Internet Router and Filter, and VLAN 1100 for the Guest Wireless access. &lt;br /&gt;&lt;br /&gt;We have the switch configured for all three of these, and 1 initial access point configured for the VLANS, too. &lt;br /&gt;&lt;br /&gt;We have not yet moved the current Internet connection to VLAN 1000 because we aren&apos;t sure how to setup routing between VLANS. &lt;br /&gt;&lt;br /&gt;Here are some specifics on how the traffic needs to route: &lt;br /&gt;1. We have the DHCP server, which is the PDC, handling both scopes for the LAN and Guest VLAN. &lt;br /&gt;2. The web filter in VLAN 1100 needs to authenticate with the DHCP server as there are different filter rules based on authenticated user. Any users coming from VLAN 1100 will have a default filter rule without requiring any authentication. &lt;br /&gt;3. Certain traffic coming in from the Internet needs to be able to get to VLAN 100. The router has a built-in firewall that handles NAT and port forwarding, so as long as traffic can be forwarded to VLAN 100 we should be good. &lt;br /&gt;4. Traffic on VLAN 1100 (guest Wireless network) should only be allowed to go to Internet (VLAN 1000). &lt;br /&gt;&lt;br /&gt;Right now I have the VLANs configured and the ports assigned to the Access Points are set for TAGGED and on VLAN 100 and VLAN 1100. &lt;br /&gt;&lt;br /&gt;The SGE2000P has the following IP addresses assigned to the VLANS: &lt;br /&gt;10.7.3.252 – VLAN 100 &lt;br /&gt;10.7.40.254 – VLAN 1000 &lt;br /&gt;192.168.254.254 – VLAN 1100 &lt;br /&gt;&lt;br /&gt;Has anyone been able to setup a similar configuration? We have scoured the Internet for documentation but it seems to be very difficult to find! &lt;br /&gt;&lt;br /&gt;Thank you! &lt;br /&gt;&lt;br /&gt;Gary Smith&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Attachment Keywords : &lt;/b&gt; &lt;br /&gt;1) Visio-Wireless_Configuration.pdf&lt;br /&gt;</Msgbody> <Attachment><Document><FileName>Visio-Wireless_Configuration.pdf</FileName><DocID>123511</DocID><ContentType>application/pdf</ContentType><InternalType>pdf</InternalType><Size>91352</Size><ExpirationDate>11/12/2014</ExpirationDate><IsExpired>no</IsExpired></Document></Attachment></Message></Conversation><Conversation id=".2cd4e78b" messages="2" subscribed="no" title="WCS and ACS View"><Message attachment="no" canreply="yes" id=".2cd4e78b" level=""><Author authinfo=" MHIS">ybilteryst</Author><Timestamp>Nov 10, 2009, 5:57am PST</Timestamp><Msgbody>Hello.&lt;br /&gt;&lt;br /&gt;we are in evaluating process to purchase WCS and ACS View. At the beginning of the POC with WCS evaluation software and ACS View on VMware, we were able to have in WCS all Authentication records coming from ACS View, but now, don&apos;t know why, each time we try, we have the errror "Unable to connect to any ACS View server.java.lang.NullPointerException"&lt;br /&gt;In attachment, a screenshoot. ACS View is functioning properly and WCS too except this funectionality.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thanks in advance for your help.&lt;br /&gt;Yab&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Attachment Keywords : &lt;/b&gt; &lt;br /&gt;1) WCS.JPG&lt;br /&gt;</Msgbody> <Attachment><Document><FileName>WCS.JPG</FileName><DocID>123434</DocID><ContentType>image/jpg</ContentType><InternalType>image</InternalType><Size>33529</Size><ExpirationDate>11/10/2014</ExpirationDate><IsExpired>no</IsExpired></Document></Attachment></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4e78b/0" level="1." new="yes">      <Author authinfo="Customer Support Engineer, Cisco" ccie="yes">lavramov</Author><Timestamp>Nov 10, 2009, 9:29am PST</Timestamp><Msgbody>Can you set your logging in WCS on trace, reproduce the issue and attach the wcs-log file containing the timestamp when you did the recreate.&lt;br /&gt;&lt;br /&gt;Provide me your ACS / ACS view versions and you seem to be using WCS 6.0 is that correct?&lt;br /&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4e78b/1" level="1.1" new="yes"><Author authinfo=" MHIS">ybilteryst</Author><Timestamp>Nov 12, 2009, 1:38am PST</Timestamp><Msgbody>Hi,&lt;br /&gt;&lt;br /&gt;I just did the test.&lt;br /&gt;Here in attachement the trace logs&lt;br /&gt;&lt;br /&gt;WCS is 6.0.132.0&lt;br /&gt;ACS View is 4.0.1&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Attachment Keywords : &lt;/b&gt; &lt;br /&gt;1) logs.zip&lt;br /&gt;</Msgbody><Attachment><Document><FileName>logs.zip</FileName><DocID>123491</DocID><ContentType>application/x-zip-compressed</ContentType><InternalType>zip</InternalType><Size>2601140</Size><ExpirationDate>11/12/2014</ExpirationDate><IsExpired>no</IsExpired></Document></Attachment></Message></Reply></Reply></Replies></Conversation><Conversation id=".2cd4ea5a" messages="1" subscribed="no" title="Query on LobbyAdmin/Guest Access"><Message attachment="no" canreply="yes" id=".2cd4ea5a" level=""><Author authinfo=" PLANNET 21 COMMUNICATIONS LTD">eoinwhite</Author><Timestamp>Nov 11, 2009, 11:03am PST</Timestamp><Msgbody>Normally when i&apos;m configuring guest access for customers who dont want to go putting an anchor WLC in the DMZ first I ensure the guest VLAN is locked down and then go ahead and create a guest WLAN with Layer 3 Web authentication and use LobbyAdmin to hand out guest accounts from WCS or the WLC.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;My question is this ... do you think this is secure enough? As the over the air traffic is unencrypted is it possible for someone to sniff the guest user-name &amp; password and gain unauthorized access to the guest network.&lt;br /&gt;&lt;br /&gt;Is it possible to encrypt over the air traffic dynamically without having to set a static pre shared key aswell as using layer 3 authentication?&lt;br /&gt;&lt;br /&gt;Just curious more than anything.&lt;br /&gt;&lt;br /&gt;Cheers</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4ea5a/0" level="1." new="yes">            <Author authinfo=" PARALLEL TECHNOLOGIES, INC.">klein425@hotmail.com</Author><Timestamp>Nov 11, 2009, 6:38pm PST</Timestamp><Msgbody>Assuming you left the SSL settings to default (on), then the guest authentication page uses a self-signed cerficate when passing the username and password.  You can upload a real cert to the WLC if you are concerned.  &lt;br /&gt;&lt;br /&gt;You could create a VLAN with no layer 3 interface on your production equipment and add a cable modem/router from another ISP and route all guest traffic to it (and of course block any traffic to your private net).&lt;br /&gt;&lt;br /&gt;I always create guest networks with the assumption that someone will gain access to it.  Then decide whether your security policies will hold from there.  If not, more security (anchoring, physically separate access points, etc.)</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4e8f0" messages="1" subscribed="no" title="I need to start using security with my AP&apos;s, where do I start?"><Message attachment="no" canreply="yes" id=".2cd4e8f0" level=""><Author authinfo=" DELCASTLE VOTECH SCHOOL">william.hostetler</Author><Timestamp>Nov 10, 2009, 4:25pm PST</Timestamp><Msgbody>I have not used security with my APs as the enviroment has been fairly small and it is a school setting where the "hackers" if there were any would be the students anyways.&lt;br /&gt;&lt;br /&gt;Now that we have wireless almost deployed across 4 buildings with about 200 APs. I&apos;m thinking I would like to get started. &lt;br /&gt;&lt;br /&gt;I am running the 6.0 software on 2 5508s and a 4402. I will be instituing WCS but that will be awhile off.&lt;br /&gt;&lt;br /&gt;I do not want to touch almost 1000 laptops to configure them for security. Am I best to try to just have the users use a name and password everytime, ldap auth., keys, etc. so that the controller knows the laptop is friendly?&lt;br /&gt;&lt;br /&gt;Later on I want to do guest access but first things first.&lt;br /&gt;&lt;br /&gt;I&apos;m open to suggestions.&lt;br /&gt;&lt;br /&gt;Gary</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4e8f0/0" level="1." new="yes">            <Author authinfo=" EDS (AUSTRALIA) PTY LIMITED">leolaohoo</Author><Timestamp>Nov 11, 2009, 1:17pm PST</Timestamp><Msgbody>Five Steps to Securing Your Wireless LAN and Preventing Wireless Threats&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/solutions/collateral/ns339/ns639/ns642/net_implementation_white_paper0900aecd804909a5.pdf&apos;)"&gt;http://www.cisco.com/en/US/solutions/collateral/ns339/ns639/ns642/net_implementation_white_paper0900aecd804909a5.pdf&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;Five Ways to Improve Your Wireless Security&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/solutions/collateral/ns339/ns639/ns642/net_brochure0900aecd80491099.html&apos;)"&gt;http://www.cisco.com/en/US/solutions/collateral/ns339/ns639/ns642/net_brochure0900aecd80491099.html&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;Hope this helps.</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4ea84" messages="0" subscribed="no" title="WLC, AAA, ACS and Ipsec paramaters"><Message attachment="no" canreply="yes" id=".2cd4ea84" level="">            <Author authinfo=" B-A-C ZAO">misha_bac</Author><Timestamp>Nov 11, 2009, 12:43pm PST</Timestamp><Msgbody>Hello, on "new AAA" WLC configuration page i see ipsec parameters, but i can&apos;t find how to use them with Cisco ACS - does it support ipsec connection?</Msgbody> <Attachment/></Message></Conversation><Conversation id=".2cd4ac33" messages="4" subscribed="no" title="Experiencing &apos;Load Threshold Violated&apos; alerts, and some Security alerts"><Message attachment="no" canreply="yes" id=".2cd4ac33" level="">            <Author authinfo=" University of Winnipeg">jpeterson6</Author><Timestamp>Oct 7, 2009, 9:00am PST</Timestamp><Msgbody>The wireless environment has been growing quickly at the university campus I work at. From roughly 500 users a couple years ago to nearly 1000 today.&lt;br /&gt;&lt;br /&gt;This is starting to cause issues. Clients are reporting that they can &apos;associate&apos; but they are unable to browse to any website.&lt;br /&gt;&lt;br /&gt;WCS (v4.2.128.0, WiSM is v4.2.207.0 on both controllers) is reporting several load threshold violations, which is to be expected with so many extra clients.&lt;br /&gt;&lt;br /&gt;- What are the best steps to help resolve the issue?&lt;br /&gt;- I have Aggressive Load Balancing turned on with a threshold of 12- should I increase the threshold?&lt;br /&gt;- How do I set the actual &apos;load threshold&apos; of the individual APs, if possible?&lt;br /&gt;&lt;br /&gt;We don&apos;t have very many APs to deploy unfortunately, as our current campus-wide model is the 1010, which is EoS/EoL. At most we can deploy 1 or 2 in the busiest areas.&lt;br /&gt;&lt;br /&gt;----&lt;br /&gt;&lt;br /&gt;Also, I&apos;m getting several critical security alerts reporting &apos;large NAV fields&apos;, &apos;broadcast floods&apos; and &apos;NULL probe responses&apos;.&lt;br /&gt;&lt;br /&gt;I included this problem with my initial questions because I have a hunch that its a direct result of the load issues, but I may be wrong.&lt;br /&gt;&lt;br /&gt;- Do these seem like a result of association issues due to load (ie, false alarms)?&lt;br /&gt;- If they are actual attacks, what&apos;s the best course of action?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thanks in advance. </Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4ac33/0" level="1." new="yes">      <Author authinfo=", Fast Lane">jeromehenry</Author><Timestamp>Oct 7, 2009, 1:45pm PST</Timestamp><Msgbody>Hi,&lt;br /&gt;Unfortunately, there is not much tuning you can do on your controller if you have too many users. Basically your issue is that there are too many users for the given available wireless space. What you need is more wireless space (more APs, especially in 5 Ghz, but also in 2.4 Ghz wherever you can add them without interfering with the others).&lt;br /&gt;You can change the Aggressive Load Balancing threshold, but this will do is simply to change the threshold (number of users) from which you controller will consider the AP as overloaded... but then the users have to be sent somewhere else, which supposes 2 factors:&lt;br /&gt;1. That other access points in the neighboring environment hear the incoming new clients, with a signal good enough to take them onboard (in other words, that you have enough APs in this area, which does not seem to be the case).&lt;br /&gt;2. That the clients are not "sticky", that is to say that when the receive the Authentication Deny - reason 17 from the first AP, that they actually try the second best AP, which is not always the case. Many clients will stick to the first heard AP and Aggressive Load Balancing will not work.&lt;br /&gt;So here the only solution is again more wireless space, i.e. more APs on unused channels.&lt;br /&gt;&lt;br /&gt;You cannot set the load threshold per AP, as it is a controller wide collective effort...&lt;br /&gt;&lt;br /&gt;Large NAV are very often the clear sign of the load excess you describe. Every time you send an 802.11 frame and fail (collisions / no ACK from the AP), you basically double your NAV and retry. Large NAVs usually are the sign that you re-try too many times without success, which is a sign of important interferences or too many users per AP.&lt;br /&gt;Broadcasts floods and NULL probe responses can be many different things ranging from PC misconfiguration to real attacks. Too many users per AP is one possibility. If these messages come from the same APs that have too many clients, I would try to solve the too many users issue first.&lt;br /&gt;Technically, the best fix is unfortunately probably not on the controller, but in the wireless coverage...&lt;br /&gt;Hope it helps&lt;br /&gt;&lt;br /&gt;Jerome</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ac33/1" level="1.1" new="yes">            <Author authinfo=" University of Winnipeg">jpeterson6</Author><Timestamp>Oct 9, 2009, 6:49am PST</Timestamp><Msgbody>Hmm.&lt;br /&gt;&lt;br /&gt;Thanks, that gives me a few things to think about. Also thanks for the confirmation of my hunch (about the NAV field alerts).&lt;br /&gt;&lt;br /&gt;I suppose it&apos;s time I look into ordering new model APs. We&apos;re running the latest version of 4.2, so we&apos;ll need to use LWAPP still. &lt;br /&gt;&lt;br /&gt;Are the 1100 models considered acceptable &apos;replacements&apos; for the 1000 model APs? Do they play well together when associated to the same controller?</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd4ac33/2" level="1.2" new="yes">      <Author authinfo="Sr Network Engineer, Austin Convention Center">ericgarnel</Author><Timestamp>Oct 12, 2009, 6:52am PST</Timestamp><Msgbody>Jerome,&lt;br /&gt;&lt;br /&gt;Well said... You touch on a lot of points that tend to get overlooked in high-density deployments and key issues to look for trouble-shooting&lt;br /&gt;&lt;br /&gt;5 points to you&lt;br /&gt;&lt;br /&gt;-Eric</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4ac33/3" level="1.2.1" new="yes">            <Author authinfo=" KOFAX POOLING AG">noc@kofax.com</Author><Timestamp>Nov 11, 2009, 12:29pm PST</Timestamp><Msgbody>Does anyone know what the load threshold is on these APs in terms of users, or is it determined by some other metrics?</Msgbody><Attachment/></Message></Reply></Reply></Reply></Replies></Conversation><Conversation id=".2cd426d7" messages="17" subscribed="no" title="PEAP Machine Authentication fails"><Message attachment="no" canreply="yes" id=".2cd426d7" level="">      <Author authinfo="Senior Enterprise Engineer, COMPUTACENTER (U K) LTD" ccie="yes">colin.lynch</Author><Timestamp>Jul 21, 2009, 6:42am PST</Timestamp><Msgbody>Hi All&lt;br /&gt;I am using PEAP with the following setup&lt;br /&gt;&lt;br /&gt;WLC 4404&lt;br /&gt;ACS Solutions Engine 4.01 (self signed cert)&lt;br /&gt;Windows AD database.&lt;br /&gt;&lt;br /&gt;PEAP user authentication works fine.&lt;br /&gt;&lt;br /&gt;The issue is, I need to only allow machines which are in AD as such I have configued Machine authentication.&lt;br /&gt;&lt;br /&gt;However this is failing with the below log.&lt;br /&gt;&lt;br /&gt;host/wks1.lnd.uk  Authen failed    EAP-TLS or PEAP authentication failed during SSL handshake&lt;br /&gt;&lt;br /&gt;I have configured the ACS for PEAP machine auth in all required places and on the client. I have read lots of info saying I need to configure AD to allow Machine Authentications, and cert auto enrollment etc.., is this the case and if so whats the easiest way to do it?&lt;br /&gt;&lt;br /&gt;Thanks in advance&lt;br /&gt;Colin</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd426d7/0" level="1." new="yes">      <Author authinfo="Senior Enterprise Engineer, COMPUTACENTER (U K) LTD" ccie="yes">colin.lynch</Author><Timestamp>Jul 21, 2009, 12:57pm PST</Timestamp><Msgbody>May have made some progress, as far as I can tell as long as the ACS cert is copied to the client and put in the Local Computer store. That I believe should be enough.&lt;br /&gt;I think when I installed the ACS cert on the client I went with the default which is NOT the Local Computer store.&lt;br /&gt;(This is not the same as installing an idependant cert on the client, but rather just the Local machine, trusting the ACS)&lt;br /&gt;Thats my thoughts anyway, I&apos;ll give it a try tomorrow.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd426d7/1" level="1.1" new="yes">      <Author authinfo="Senior Enterprise Engineer, COMPUTACENTER (U K) LTD" ccie="yes">colin.lynch</Author><Timestamp>Jul 22, 2009, 1:21am PST</Timestamp><Msgbody>OK&lt;br /&gt;Logged into the laptop as a local admin and imported the ACS self signed cert in to: Physical Store: Trusted Root Cert Auths&gt;Local Computer.&lt;br /&gt;&lt;br /&gt;This had the effect that my Machine Auth now no longer fails with the SSL error but now fails with "External DB user invalid or bad password"&lt;br /&gt;&lt;br /&gt;Unknown user policy is working as Domain user authentication is still working fine.&lt;br /&gt;&lt;br /&gt;Anyone got any ideas?</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd426d7/2" level="1.1.1" new="yes">      <Author authinfo="Engineer, Instructor, MasterLink Corp. / ieMentor Corp." ccie="yes">roman.rodichev@iementor.com</Author><Timestamp>Jul 22, 2009, 5:49am PST</Timestamp><Msgbody>What username do you see in that "External DB User invalid" error in Failed Attempts log? Maybe it&apos;s "CN=&lt;user&gt;"? </Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd426d7/3" level="1.1.1.1" new="yes">      <Author authinfo="Senior Enterprise Engineer, COMPUTACENTER (U K) LTD" ccie="yes">colin.lynch</Author><Timestamp>Jul 28, 2009, 3:31am PST</Timestamp><Msgbody>username in failure log is host/FQDM&lt;br /&gt;ie host/laptop.x.x</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd426d7/4" level="1.1.1.1.1" new="yes"><Author authinfo=" WIPRO ARABIA LIMITED">pandapritam</Author><Timestamp>Aug 4, 2009, 2:35am PST</Timestamp><Msgbody>Hi colin, &lt;br /&gt;will u able to solve the problem if yes then can you share the solution among us</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd426d7/5" level="1.1.1.1.1.1" new="yes">      <Author authinfo="Senior Enterprise Engineer, COMPUTACENTER (U K) LTD" ccie="yes">colin.lynch</Author><Timestamp>Aug 4, 2009, 2:43am PST</Timestamp><Msgbody>Hi Yes &lt;br /&gt;Did solve the problem, in my case I just loaded the Agent on another server and all Machine Auth is now working perfectly and all login scripts etc run ok. So it must have been an issue between the Agent and the server which happened to be a DC. Another company had tried getting this working before and failed so I suspect they messed around with the Agent privilages on the DC.&lt;br /&gt;I have drawn up a diagram showing all PEAP components end to end and what needs to be configured and how. If you want a copy let me know ur E-mail address.&lt;br /&gt;Regards&lt;br /&gt;Colin</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd426d7/6" level="1.1.1.1.1.1.1" new="yes"><Author authinfo=" WIPRO ARABIA LIMITED">pandapritam</Author><Timestamp>Aug 4, 2009, 8:57pm PST</Timestamp><Msgbody>hi colin,&lt;br /&gt;&lt;br /&gt;thanks 4 the reply. i desperately need ur help.&lt;br /&gt;&lt;br /&gt;MY Emailid :&lt;A HREF="mailto:pritam.panda1@wipro.com"&gt;pritam.panda1@wipro.com&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;Thanks again...</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd426d7/7" level="1.1.1.1.1.1.2" new="yes">      <Author authinfo="Network Engineer, MFEC PUBLIC COMPANY LIMITED">lacushime</Author><Timestamp>Aug 4, 2009, 9:55pm PST</Timestamp><Msgbody>Hi,&lt;br /&gt;I&apos;m experience quite same problem with machine authen failed with host/ in another Domain Forest. Anyway could you also send me your diagram and how to setup agent.&lt;br /&gt;&lt;br /&gt;Thank you.&lt;br /&gt;&lt;A HREF="mailto:nuttea@mfec.co.th"&gt;nuttea@mfec.co.th&lt;/A&gt;</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd426d7/8" level="1.1.1.1.1.1.3" new="yes">      <Author authinfo="Corporate Network Architect, TATA Communications US Inc">kamlesh.patel</Author><Timestamp>Aug 21, 2009, 11:25am PST</Timestamp><Msgbody>Hi Colin,&lt;br /&gt;&lt;br /&gt;Please send me @&lt;br /&gt;&lt;br /&gt;&lt;A HREF="mailto:k.patel@tatacommunications.com"&gt;k.patel@tatacommunications.com&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;Thx</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd426d7/9" level="1.1.1.1.1.1.3.1" new="yes">            <Author authinfo=" Canadian Tire Corporation">jimcantire</Author><Timestamp>Aug 30, 2009, 9:17pm PST</Timestamp><Msgbody>Hi Colin,&lt;br /&gt;&lt;br /&gt;Please send me a copy @:&lt;br /&gt;&lt;br /&gt;&lt;A HREF="mailto:jimhuangca@yahoo.ca"&gt;jimhuangca@yahoo.ca&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;Thanks</Msgbody><Attachment/></Message></Reply></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd426d7/11" level="1.1.1.1.1.1.4" new="yes"><Author authinfo=" ">patgeo1984</Author><Timestamp>Sep 29, 2009, 4:04pm PST</Timestamp><Msgbody>I&apos;m in the process of implementing the same site, and I have presented a problem similar to yours I be able to obtain a copy of your diagram &lt;br /&gt;&lt;br /&gt;&lt;A HREF="mailto:pgonzalez@coasin.cl"&gt;pgonzalez@coasin.cl&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;Thank you very much</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd426d7/12" level="1.1.1.1.1.1.5" new="yes"><Author authinfo=" PRESIDIO NETWORKED SOLUTIONS">edunn@mtm.com</Author><Timestamp>Oct 21, 2009, 5:43am PST</Timestamp><Msgbody>Can you please send me a copy of that diagram to &lt;A HREF="mailto:ernandcorb@msn.com"&gt;ernandcorb@msn.com&lt;/A&gt;.  Thanks</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd426d7/15" level="1.1.1.1.1.1.6" new="yes">      <Author authinfo="Network Engineer, University Hospitals">chuckdillon</Author><Timestamp>Nov 3, 2009, 7:11pm PST</Timestamp><Msgbody>Hi Colin, Could you please send me a copy of your diagram to &lt;A HREF="mailto:charlespdillon@gmail.com"&gt;charlespdillon@gmail.com&lt;/A&gt;&lt;br /&gt;Thanks </Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd426d7/16" level="1.1.1.1.1.1.7" new="yes"><Author authinfo=" FUJITSU ASIA PTE LTD">jason_majie</Author><Timestamp>Nov 9, 2009, 6:13pm PST</Timestamp><Msgbody>Hi Colin, Could you also send me the solution? thanks a lot.&lt;br /&gt;my email is &lt;A HREF="mailto:jason.majie@gmail.com"&gt;jason.majie@gmail.com&lt;/A&gt;</Msgbody><Attachment/></Message></Reply></Reply></Reply></Reply></Reply></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd426d7/14" level="1.2" new="yes"><Author authinfo=" Science Applications International Corporation">Robert.N.Barrett</Author><Timestamp>Oct 24, 2009, 10:51am PST</Timestamp><Msgbody>removed - wrong thread...sorry</Msgbody><Attachment/></Message></Reply></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd426d7/10" level="2." new="yes"><Author authinfo=" BC Ferry Services Inc.">spirotsares</Author><Timestamp>Sep 15, 2009, 2:33pm PST</Timestamp><Msgbody>I&apos;m in the process of deploying the same setup. Would I be  able to get a copy of your diagram @&lt;br /&gt;&lt;br /&gt;&lt;A HREF="mailto:mrspiro@gmail.com"&gt;mrspiro@gmail.com&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;Thanks&lt;br /&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd426d7/13" level="2.1" new="yes">            <Author authinfo=" GTSI CORPORATION">fmirza007</Author><Timestamp>Oct 23, 2009, 6:40am PST</Timestamp><Msgbody>I am also trying to implement the same solution, would I be able to get a copy as &lt;A HREF="mailto:well....farhan.mirza@gtsi.com"&gt;well....farhan.mirza@gtsi.com&lt;/A&gt;..&lt;br /&gt;&lt;br /&gt;Thanks</Msgbody><Attachment/></Message></Reply></Reply></Replies></Conversation><Conversation id=".2cd4d3d5" messages="13" subscribed="no" title="LAP 1240 won&apos;t join WLC across subnets"><Message attachment="no" canreply="yes" id=".2cd4d3d5" level="">      <Author authinfo="Network Administrator, CAMBRIAN COLLEGE">dmcushing</Author><Timestamp>Oct 29, 2009, 5:10am PST</Timestamp><Msgbody>I am having a problem getting LAPs that are in other subnets to join our WLC.  If I take the LAP and place it on the same VLAN/subnet as the WLC, it joins as expected.  If I move it to another subnet, I get the following:&lt;br /&gt;&lt;br /&gt;*Mar  1 00:00:13.065: %SYS-5-RESTART: System restarted --&lt;br /&gt;Cisco IOS Software, C1200 Software (C1200-K9W8-M), Version 12.4(13d)JA, RELEASE SOFTWARE (fc2)&lt;br /&gt;Technical Support: &lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/techsupport&apos;)"&gt;http://www.cisco.com/techsupport&lt;/A&gt;&lt;br /&gt;Copyright (c) 1986-2008 by Cisco Systems, Inc.&lt;br /&gt;Compiled Fri 08-Feb-08 17:24 by prod_rel_team&lt;br /&gt;*Mar  1 00:00:13.119: %SSH-5-ENABLED: SSH 2.0 has been enabled&lt;br /&gt;*Mar  1 00:00:13.519: %LINK-5-CHANGED: Interface Dot11Radio1, changed state to reset&lt;br /&gt;*Mar  1 00:00:14.519: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to down&lt;br /&gt;*Mar  1 00:00:14.536: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset&lt;br /&gt;*Mar  1 00:00:14.545: %DOT11-6-FREQ_SCAN: Interface Dot11Radio0, Scanning frequencies for 24 seconds&lt;br /&gt;*Mar  1 00:00:15.536: %LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to down&lt;br /&gt;*Mar  1 00:00:28.133: %LWAPP-5-CHANGED: LWAPP changed state to DISCOVERY&lt;br /&gt;*Mar  1 00:00:28.171: %LINK-3-UPDOWN: Interface Dot11Radio0, changed state to up&lt;br /&gt;*Mar  1 00:00:28.177: %LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset&lt;br /&gt;*Mar  1 00:00:28.192: SSC Load Current Size crypto_mykey 120, offset 9389, Saved Size soap_cert_crypto_mykey 124&lt;br /&gt;*Mar  1 00:00:28.390: %LINK-3-UPDOWN: Interface Dot11Radio1, changed state to up&lt;br /&gt;*Mar  1 00:00:28.892: Logging LWAPP message to 255.255.255.255.&lt;br /&gt;&lt;br /&gt;%LINK-3-UPDOWN: Interface Dot11Radio0, changed state to up&lt;br /&gt;%SYS-6-LOGGINGHOST_STARTSTOP: Logging to host 255.255.255.255 started - CLI initiated&lt;br /&gt;%LINK-5-CHANGED: Interface Dot11Radio1, changed state to reset&lt;br /&gt;%LINK-3-UPDOWN: Interface Dot11Radio1, changed state to up&lt;br /&gt;%LINK-5-CHANGED: Interface Dot11Radio0, changed state to reset&lt;br /&gt;%LINK-3-UPDOWN: Interface Dot11Radio0, changed state to up&lt;br /&gt;%LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to up&lt;br /&gt;%LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to up&lt;br /&gt;%DHCP-6-ADDRESS_ASSIGN: Interface FastEthernet0 assigned DHCP address 192.168.115.75, mask 255.255.255.192, hostname AP0013.c3a7.bf97&lt;br /&gt;&lt;br /&gt;Translating "CISCO-LWAPP-CONTROLLER.mydomain.here"...domain server (X.X.X.X) [OK]&lt;br /&gt;&lt;br /&gt;%LWAPP-3-CLIENTEVENTLOG: Did not get vendor specific options from DHCP.&lt;br /&gt;%LWAPP-3-CLIENTEVENTLOG: Did not get log server settings from DHCP.&lt;br /&gt;%LWAPP-3-CLIENTEVENTLOG: Performing DNS resolution for CISCO-LWAPP-CONTROLLER.mydomain.here&lt;br /&gt;%LWAPP-3-CLIENTEVENTLOG: Controller address Y.Y.Y.Y obtained through  DNS&lt;br /&gt;%LWAPP-5-CHANGED: LWAPP changed state to JOIN&lt;br /&gt;%LINK-5-CHANGED: Interface Dot11Radio0, changed state to administratively down&lt;br /&gt;%LINK-5-CHANGED: Interface Dot11Radio1, changed state to administratively down&lt;br /&gt;%LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio0, changed state to down&lt;br /&gt;%LINEPROTO-5-UPDOWN: Line protocol on Interface Dot11Radio1, changed state to down&lt;br /&gt;%LWAPP-3-CLIENTERRORLOG: Join Timer: did not recieve join response (controller - 2169-WLC4402-1)&lt;br /&gt;%LWAPP-3-CLIENTERRORLOG: Set Transport Address: no more AP manager IP addresses remain&lt;br /&gt;%SYS-5-RELOAD: Reload requested by LWAPP CLIENT. Reload Reason: DID NOT GET JOIN RESPONSE.&lt;br /&gt;%LWAPP-5-CHANGED: LWAPP changed state to DOWN&lt;br /&gt;&lt;br /&gt;I have checked the WLC for any messages that look like crypto or other problems, but I don&apos;t see anything that stands out.  Any suggestions or pointers would be greatfully accepted.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4d3d5/0" level="1." new="yes">      <Author authinfo=", Fast Lane">jeromehenry</Author><Timestamp>Oct 29, 2009, 11:22am PST</Timestamp><Msgbody>I would try to ping the controller from the AP CLI. I can get the same message when there is asymmetric routing between the AP and the controller (so the controller gets the join request, but the AP never gets the join response).&lt;br /&gt;I would also do a debug lwapp events enable on the controller to see if the AP is seen and how the controller reacts to that join request.&lt;br /&gt;I would bet 2 cents on asymmetric routing issue...&lt;br /&gt;:-)</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4d3d5/3" level="1.1" new="yes">      <Author authinfo="Network Administrator, CAMBRIAN COLLEGE">dmcushing</Author><Timestamp>Oct 30, 2009, 4:03am PST</Timestamp><Msgbody>My core routers use GLBP - do you think that would that cause any problems? Other than that, I don&apos;t think there is any asymmetric routing (we only have routing at the core).&lt;br /&gt;&lt;br /&gt;Unfortunately, once I converted the AP to an LWAPP, I cannot access the cli (or if I can, I do not know the credentials I am supposed to use).&lt;br /&gt;&lt;br /&gt;I did run the lwapp events enable, but didn&apos;t see anything unusual.  I will capture and post that in case I am missing something that someone with more experience may catch.  Thanks for the help.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4d3d5/9" level="1.1.1" new="yes">      <Author authinfo="Network Consultant, ANNESE &amp; ASSOCIATES, INC">j.boyers</Author><Timestamp>Nov 9, 2009, 6:59am PST</Timestamp><Msgbody>I looked at this again, and yes, GLBP appears to be the issue.  Per the release notes for 5.0.148.0, GLBP is not supported.  &lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/docs/wireless/controller/release/notes/crn501480.html&apos;)"&gt;http://www.cisco.com/en/US/docs/wireless/controller/release/notes/crn501480.html&lt;/A&gt;.  I just took a quick look and there are no versions 4.2 and above that support it.  So, you will need to have a fixed IP address for your wireless management subnet.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4d3d5/11" level="1.1.1.1" new="yes">      <Author authinfo="Network Administrator, CAMBRIAN COLLEGE">dmcushing</Author><Timestamp>Nov 9, 2009, 7:27am PST</Timestamp><Msgbody>I must&apos;ve missed that when I did the upgrade (sigh).  RTFM bites me again.  Thanks very much for the help.</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd4d3d5/12" level="1.1.1.2" new="yes">      <Author authinfo="Network Administrator, CAMBRIAN COLLEGE">dmcushing</Author><Timestamp>Nov 9, 2009, 7:35am PST</Timestamp><Msgbody>I&apos;ve confirmed that GLBP is the issue.  Once I pointed the AP Manager interface to a static IP, the AP was able to join properly.  Thanks for the good catch - hope this thread helps someone else out too.</Msgbody><Attachment/></Message></Reply></Reply></Reply></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd4d3d5/1" level="2." new="yes">            <Author authinfo=" EDS (AUSTRALIA) PTY LIMITED">leolaohoo</Author><Timestamp>Oct 29, 2009, 7:13pm PST</Timestamp><Msgbody>%LWAPP-3-CLIENTERRORLOG: Set Transport Address: &lt;b&gt;no more AP manager IP addresses remain&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Can you provide more information such as: &lt;br /&gt;&lt;br /&gt;1.  How many APs can the WLC4402 support and how many are currently joined? &lt;br /&gt;&lt;br /&gt;2.  What is your WLC&apos;s firmware? &lt;br /&gt;&lt;br /&gt;3.  Is there a possibility of a duplicate IP address in your network?&lt;br /&gt;&lt;br /&gt;Troubleshoot a Lightweight Access Point Not Joining a Wireless LAN Controller&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/products/ps6366/products_tech_note09186a00808f8599.shtml&apos;)"&gt;http://www.cisco.com/en/US/products/ps6366/products_tech_note09186a00808f8599.shtml&lt;/A&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4d3d5/2" level="2.1" new="yes">      <Author authinfo="Network Administrator, CAMBRIAN COLLEGE">dmcushing</Author><Timestamp>Oct 30, 2009, 3:58am PST</Timestamp><Msgbody>1. The WLC can support 50, there are currently 38 joined.&lt;br /&gt;&lt;br /&gt;2. WLC firmware is 5.0.148.0&lt;br /&gt;&lt;br /&gt;3. I&apos;ve tried the LWAPP on multiple subnets with DHCP, all failed.  The only subnet that works is the same subnet the WLC is on.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4d3d5/4" level="2.1.1" new="yes">            <Author authinfo=" EDS (AUSTRALIA) PTY LIMITED">leolaohoo</Author><Timestamp>Nov 1, 2009, 1:28pm PST</Timestamp><Msgbody>What&apos;s your trunk port configurations like?  Is the VLAN of the AP and WLC allowed?</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4d3d5/5" level="2.1.1.1" new="yes">      <Author authinfo="Network Consultant, ANNESE &amp; ASSOCIATES, INC">j.boyers</Author><Timestamp>Nov 2, 2009, 7:47pm PST</Timestamp><Msgbody>Actually, if the AP is on a different VLAN than the AP manager, you don&apos;t want to trunk that APs VLAN to the WLC.  The AP will think that it can connect, but the WLC won&apos;t be able to respond since it receives the request from a VLAN that is not the AP manager VLAN.  If you have the AP VLAN trunked to the WLC, remove the VLAN and see if that fixes the issue.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4d3d5/8" level="2.1.1.1.1" new="yes">      <Author authinfo="Network Administrator, CAMBRIAN COLLEGE">dmcushing</Author><Timestamp>Nov 9, 2009, 6:50am PST</Timestamp><Msgbody>The APs that I am having a problem with are on a VLAN that is not trunked to the WLC.  The AP VLAN (ie. 200) *has* to go through L3 routing at the core (dual 7206 routers with GLBP).  No matter what VLAN or router I have tried, the WLC fails to see the packet from the AP.&lt;br /&gt;&lt;br /&gt;If the AP is on the same VLAN as the WLC (ie. the AP Management VLAN) there is no problem.</Msgbody><Attachment/></Message></Reply></Reply></Reply></Reply></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd4d3d5/6" level="3." new="yes">            <Author authinfo=" NETEAM CORPORATION">j.metzger</Author><Timestamp>Nov 9, 2009, 6:12am PST</Timestamp><Msgbody>You do have the controller configured for Layer 3 mode don&apos;t you (controller, general settings)?</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4d3d5/7" level="3.1" new="yes">      <Author authinfo="Network Administrator, CAMBRIAN COLLEGE">dmcushing</Author><Timestamp>Nov 9, 2009, 6:44am PST</Timestamp><Msgbody>Yes, I have it configured in L3 mode :)  Thanks for getting me to double check though.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4d3d5/10" level="3.1.1" new="yes">            <Author authinfo=" NETEAM CORPORATION">j.metzger</Author><Timestamp>Nov 9, 2009, 7:24am PST</Timestamp><Msgbody>Have you tried to change the AP VLAN gateway from GLBP to static or HSRP?&lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Reply></Reply></Replies></Conversation><Conversation id=".2cd4e404" messages="5" subscribed="no" title="WCS Map Editor Won&apos;t Load"><Message attachment="no" canreply="yes" id=".2cd4e404" level=""><Author authinfo="IT Architec">m.bailey7@ntlworld.com</Author><Timestamp>Nov 7, 2009, 7:01am PST</Timestamp><Msgbody>Hi,&lt;br /&gt;&lt;br /&gt;Have just installed WCS 6.0.132.0 as part of a new installation.&lt;br /&gt;&lt;br /&gt;Have defined my buildings and loaded floor plans (PNG) however every time I try and use the Map Editor it just hangs at "Loading(%) 0%" and nothing happens.&lt;br /&gt;&lt;br /&gt;Have ensured flash is installed.&lt;br /&gt;&lt;br /&gt;Any ideas?</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4e404/0" level="1." new="yes">      <Author authinfo="Customer Support Engineer, Cisco" ccie="yes">lavramov</Author><Timestamp>Nov 7, 2009, 9:46am PST</Timestamp><Msgbody>Yes, this is a bug I filed : &lt;br /&gt;CSCtc41084    WCS map import from file fails and does not provide an error message &lt;br /&gt;&lt;br /&gt;The problem is that images over 72 dpi are not yet supported in WCS 6.0. The next wcs release should fix this.&lt;br /&gt;&lt;br /&gt;In the meantime, your workaround is to save the image under a different format or the same format but not over 72 dpi resolution.&lt;br /&gt;&lt;br /&gt;BTW, feel free to post any WCS questions at the ASK THE EXPERT SECTION and I will answer there.&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;forum=Wireless%20-%20Mobility&amp;topic=Security%20and%20Network%20Management&amp;topicID=.ee6e8c0&amp;fromOutline=&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd4e34e&apos;)"&gt;http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;forum=Wireless%20-%20Mobility&amp;topic=Security%20and%20Network%20Management&amp;topicID=.ee6e8c0&amp;fromOutline=&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cd4e34e&lt;/A&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4e404/1" level="1.1" new="yes"><Author authinfo="IT Architec">m.bailey7@ntlworld.com</Author><Timestamp>Nov 7, 2009, 10:58am PST</Timestamp><Msgbody>Thanks, slightly frustrating as every piece of image editting software I have saves at 96 dpi and when I try to reduce to 72 dpi they become unreadable.&lt;br /&gt;&lt;br /&gt;Will have to keep on trying I suppose or buy alternate image software!&lt;br /&gt;&lt;br /&gt;Thanks again</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4e404/2" level="1.1.1" new="yes">      <Author authinfo="Customer Support Engineer, Cisco" ccie="yes">lavramov</Author><Timestamp>Nov 7, 2009, 5:44pm PST</Timestamp><Msgbody>Or save them as jpeg, that may work</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4e404/3" level="1.1.1.1" new="yes"><Author authinfo="IT Architec">m.bailey7@ntlworld.com</Author><Timestamp>Nov 8, 2009, 1:27am PST</Timestamp><Msgbody>No luck I&apos;m afraid, saved to 72dpi JPG as attached and map editor still doesn&apos;t do anything as attached.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Attachment Keywords : &lt;/b&gt; &lt;br /&gt;1) image_properties_72dpi.JPG&lt;br /&gt;2) map_editor_hung.JPG&lt;br /&gt;</Msgbody><Attachment><Document><FileName>image_properties_72dpi.JPG</FileName><DocID>123307</DocID><ContentType>image/pjpeg</ContentType><InternalType>image</InternalType><Size>14760</Size><ExpirationDate>11/08/2014</ExpirationDate><IsExpired>no</IsExpired></Document><Document><FileName>map_editor_hung.JPG</FileName><DocID>123308</DocID><ContentType>image/pjpeg</ContentType><InternalType>image</InternalType><Size>25700</Size><ExpirationDate>11/08/2014</ExpirationDate><IsExpired>no</IsExpired></Document></Attachment></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4e404/4" level="1.1.1.1.1" new="yes"><Author authinfo="IT Architec">m.bailey7@ntlworld.com</Author><Timestamp>Nov 8, 2009, 10:07am PST</Timestamp><Msgbody>Sorted now - problem with the client.&lt;br /&gt;&lt;br /&gt;Used a different client with IE7 (original only had IE6) and with 72dpi image all is fine.&lt;br /&gt;&lt;br /&gt;Thanks</Msgbody><Attachment/></Message></Reply></Reply></Reply></Reply></Reply></Replies></Conversation><Conversation id=".2cd4e07a" messages="3" subscribed="no" title="Adding a Cert to WCS"><Message attachment="no" canreply="yes" id=".2cd4e07a" level=""><Author authinfo=" CITY OF EVANSTON">thanmad</Author><Timestamp>Nov 5, 2009, 8:50am PST</Timestamp><Msgbody>I&apos;m trying to get our cert onto the WCS but it&apos;s proving difficult.  Does anyone have actual documentation for this?  Everything i&apos;ve googled so far is proving rather unhelpful.&lt;br /&gt;&lt;br /&gt;As i understand it, in the "Download Web Auth Certificate to Controller" section i have a number of fields.  Server Name and IP need to correlate to the settings of my virtual interface.&lt;br /&gt;&lt;br /&gt;but then we get into "Server File Name" and "Password:".  is server file name the name i want to give the cert when it&apos;s on the server?  What is this password field?</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4e07a/0" level="1." new="yes">      <Author authinfo="Customer Support Engineer, Cisco" ccie="yes">lavramov</Author><Timestamp>Nov 5, 2009, 10:29am PST</Timestamp><Msgbody>Do you want to downlad a cert from WLC to WCS?&lt;br /&gt;Or push a cert from WCS to WLC?&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/docs/wireless/wcs/6.0/configuration/guide/6_0tasks.html#wpmkr1077669&apos;)"&gt;http://www.cisco.com/en/US/docs/wireless/wcs/6.0/configuration/guide/6_0tasks.html#wpmkr1077669&lt;/A&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4e07a/1" level="1.1" new="yes"><Author authinfo=" CITY OF EVANSTON">thanmad</Author><Timestamp>Nov 5, 2009, 1:22pm PST</Timestamp><Msgbody>I&apos;m not a cert expert by any means, i&apos;m just trying to make the rediculous cert error i get in web-passthru to disappear.&lt;br /&gt;&lt;br /&gt;I was able to get the CA to the controller (via wcs) but i can&apos;t seem to get the server cert installed.  we&apos;re using a wildcard cert (*.domain.com) so i&apos;m a little unsure if that is causing problems or not.&lt;br /&gt;&lt;br /&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4e07a/2" level="1.1.1" new="yes">      <Author authinfo="Customer Support Engineer, Cisco" ccie="yes">lavramov</Author><Timestamp>Nov 6, 2009, 4:28pm PST</Timestamp><Msgbody>Ok got it. If your cert is for FQDN, then your WCS hostname should be FQDN too. Remember that the license for WCS is bundled to your hostname and if lets say you change your wcs hostname from wcs to wcs.domain.com then you need to change your WCS license.&lt;br /&gt;&lt;br /&gt;Having said that, here is how to install a CSR on your WCS server:&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/products/ps6305/products_configuration_example09186a00808a94ca.shtml&apos;)"&gt;http://www.cisco.com/en/US/products/ps6305/products_configuration_example09186a00808a94ca.shtml&lt;/A&gt;</Msgbody><Attachment/></Message></Reply></Reply></Reply></Replies></Conversation><Conversation id=".2cd4e309" messages="1" subscribed="no" title="Web authentication for guests on Controller"><Message attachment="no" canreply="yes" id=".2cd4e309" level="">      <Author authinfo="network Analyst, SPECTRA ENERGY">Barryhoy</Author><Timestamp>Nov 6, 2009, 10:28am PST</Timestamp><Msgbody>I seem to be having issues with my guest network on a intermittent basis.  The guests get on the network and get a correct ip address with no problem every time.  the only thing is when they open their browser and try to go to google or any other web page, they are not being redirected to the login authentication page. We are just using the default web page.  I am not sure if it is a DNS issue or some kind of certificate issue.  It will just seem to start working again.  Does anyone have any ideas.  I have read the doccumentation on troubleshooting the web authentication.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4e309/0" level="1." new="yes">      <Author authinfo="network Analyst, SPECTRA ENERGY">Barryhoy</Author><Timestamp>Nov 6, 2009, 3:51pm PST</Timestamp><Msgbody>I may have found the problem.  I have changed the DNS addresses and am waiting to hear if it has resolved the issue. </Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4d321" messages="2" subscribed="no" title="guest wlan design questions"><Message attachment="no" canreply="yes" id=".2cd4d321" level=""><Author authinfo=" GARDEN VALLEY SCHOOL DIVISION">dan.letkeman</Author><Timestamp>Oct 28, 2009, 6:16pm PST</Timestamp><Msgbody>I need to setup a guest wlan on a single 5508 controller.  Currently all of my ap&apos;s are in h-reap mode and all in remote buildings connected via a high speed wireless wan.&lt;br /&gt;&lt;br /&gt;The guest network could consist of 500 users in the near future, so i&apos;m wondering what is the best way to configure the guest wlan so I don&apos;t have one big broadcast domain across my entire network?</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4d321/0" level="1." new="yes">            <Author authinfo=" PARALLEL TECHNOLOGIES, INC.">klein425@hotmail.com</Author><Timestamp>Nov 6, 2009, 12:12pm PST</Timestamp><Msgbody>The best way would be to use AP Groups which sets an SSID on a specific access point to belong to specified VLAN.&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/partner/products/ps10315/products_installation_and_configuration_guides_list.html&apos;)"&gt;http://www.cisco.com/en/US/partner/products/ps10315/products_installation_and_configuration_guides_list.html&lt;/A&gt; (see page 6-47 for exact configuration instructions).&lt;br /&gt;&lt;br /&gt;I&apos;m assuming that you want guest traffic tunneled back to the controller.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd4d321/1" level="1.1" new="yes"><Author authinfo=" GARDEN VALLEY SCHOOL DIVISION">dan.letkeman</Author><Timestamp>Nov 6, 2009, 2:32pm PST</Timestamp><Msgbody>Ok.  I already have my ap&apos;s in ap groups (per building) and I have different vlans in each building with the same ssid company wide.  I&apos;m doing this via h-reap.&lt;br /&gt;&lt;br /&gt;My question is how do I accomplish the same thing with the guest wlan, but without h-reap.  Or do i use h-reap and just setup acl&apos;s to block the traffic?  But then does web authentication work the same?&lt;br /&gt;&lt;br /&gt;The confusion for me comes in at the controller level with the guest-wlan interface I created having to be attached to a vlan.  Is this not needed to do web authentication?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thanks,&lt;br /&gt;Dan.</Msgbody><Attachment/></Message></Reply></Reply></Replies></Conversation><Conversation id=".1ddcc520" messages="26" subscribed="no" title="Custom WebAuth"><Message attachment="no" canreply="yes" id=".1ddcc520" level="">            <Author authinfo=" State of NJ -Judiciary">wowsersusa</Author><Timestamp>Nov 14, 2006, 12:00pm PST</Timestamp><Msgbody>I am basically trying to take the e-mail pass-through page and manipulate the simple html code say Signature instead of Email Address.  However Every time I copy the code and open up the login.html that I upload with the custom webauth page I no longer have a submit button and even when I hit enter it no longer redirects me anywhere. Basically the need for this is to have the users name in the system to log them.  We are just trying to figure out if there is a way for a guest to self register themselves by reading a license agreement and then signing at the bottom.  Thanks in advance for any help that could be provided</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/0" level="1." new="yes">      <Author authinfo="TECHNICIAN, DIVEX SOLUTIONS">wdrootz</Author><Timestamp>Nov 20, 2006, 11:49am PST</Timestamp><Msgbody>Try these links:&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/univercd/cc/td/doc/product/wireless/control/c44/ccfig40/c40users.htm#wp1048609&apos;)"&gt;http://www.cisco.com/univercd/cc/td/doc/product/wireless/control/c44/ccfig40/c40users.htm#wp1048609&lt;/A&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/products/ps6366/products_configuration_guide_chapter09186a008076cf0c.html&apos;)"&gt;http://www.cisco.com/en/US/products/ps6366/products_configuration_guide_chapter09186a008076cf0c.html&lt;/A&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/1" level="1.1" new="yes">      <Author authinfo="Network Engineer, Georgetown County Government">blawrimore1</Author><Timestamp>Nov 21, 2006, 8:14am PST</Timestamp><Msgbody>im having the same issue, and ive looked up and down cisco&apos;s site for some help.  the most ive come up with is a general guide on what fields to code, like "make sure you capture the redirect url".&lt;br /&gt;&lt;br /&gt;ive copied the source code of the internal auth page, modified it, tar&apos;d it, and uploaded successfully.  the javascript does not work, there is no submit button, and none of the basic cisco banners are there.  i assume its because of the directory structure, which is not documented.&lt;br /&gt;&lt;br /&gt;i do see in figure 9-14 (here: &lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/univercd/cc/td/doc/product/wireless/control/c44/ccfig40/c40users.htm#wp1053578&apos;)"&gt;http://www.cisco.com/univercd/cc/td/doc/product/wireless/control/c44/ccfig40/c40users.htm#wp1053578&lt;/A&gt; ) that there is a submit button and a terms button.  i would be ecstatic if i could find out how that terms button works.&lt;br /&gt;&lt;br /&gt;all i need is a "ive read the terms and agree to them" page, along with the terms for them to read.  modifying the internal page does not allow for carraige returns so this is not acceptable for my use.&lt;br /&gt;&lt;br /&gt;please help with this issue, ive seen it posted a few times and no answers that i can find.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/2" level="1.1.1" new="yes"><Author authinfo=" x-tra automation pte ltd">alvin1976</Author><Timestamp>Feb 7, 2007, 12:26am PST</Timestamp><Msgbody>Hello,&lt;br /&gt;When i followed the instruction given by cisco literature on creating a customized webauth page, it doesn&apos;t work. The downloaded sample has a "no-action" javascript which basically does nothing. In order for the submit button to work, you need to configure the WLC to work with the internal webauth page, associate to the WLAN with webauth and open IE browser to be prompted with the actual login page. There you need to save the webpage and you&apos;ll get the REAL sample with workable login javascript. make sure you have the file "loginscript.js" in the "web Authentication_files" directory. Do your modification and tar the entire package. Don&apos;t forget to rename the html to login.html. Make sure you "APPLY" the customized page in security&gt;web login&gt; I&apos;m still having some problem with this method, but I&apos;ll post this in another thread.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/3" level="1.1.1.1" new="yes">            <Author authinfo=" State of NJ -Judiciary">wowsersusa</Author><Timestamp>Feb 7, 2007, 5:06am PST</Timestamp><Msgbody>Well Thank you for your post but I figured this out lte november.  You are correct in saying about the javascript.js file.  My problem was I edited it using VI and for some reason it put some non-standard ascii characters in my Javascript.  I just downloaded the page again and it works.  The only other problem I had was inside the controller I had to make sure under WLAN passthrough had e-mail checked in order for me to send login information to an accounting server.&lt;br /&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/4" level="1.1.1.1.1" new="yes">            <Author authinfo=" Coleman Technologies">jennifer.huber</Author><Timestamp>Feb 7, 2007, 11:46am PST</Timestamp><Msgbody>Can you assist me with redirecting via editing the javascript.js file?  I have the js file, but don&apos;t know where to put the url.  I&apos;m using SourceEditor (it&apos;s free)  Thanks much!</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/5" level="1.1.1.1.1.1" new="yes">            <Author authinfo=" State of NJ -Judiciary">wowsersusa</Author><Timestamp>Feb 7, 2007, 12:17pm PST</Timestamp><Msgbody>Hello Ms. Jennifer,&lt;br /&gt;&lt;br /&gt;What exactly are you trying to do?  What we did for our company is create a custom webpage with a EULA designed by lawyers with a signature block at the bottom instead of E-mail.  Then under the WLAN Layer 3 Security I selected WebPolicy then I selected passthrough and E-mail input.   Essentially I cheated and made the Input E-mail ay Signature.  I will be glad to help in any way I can.  </Msgbody><Attachment/></Message></Reply></Reply><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/6" level="1.1.1.1.2" new="yes">            <Author authinfo=" Coleman Technologies">jennifer.huber</Author><Timestamp>Feb 7, 2007, 12:18pm PST</Timestamp><Msgbody>I have edited the basic web splash screen, and want the accept/submit button to redirect guest users to a different website.  I believe when I upload a custom web auth page, I need to have a complete html file, and cannot use the redirect field that is only present on the controller when I am using the internal (default) web auth page.  I do not know how to redirect based on a javascript file.  I don&apos;t know where to specify the url, or how the js file parses the url.  Thanks for your help!</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/7" level="1.1.1.1.2.1" new="yes">            <Author authinfo=" State of NJ -Judiciary">wowsersusa</Author><Timestamp>Feb 8, 2007, 6:19am PST</Timestamp><Msgbody>Actually it is on your splash screen html file where you need to put the redirect.&lt;br /&gt;Look for Form method part of your html code and this is what I had to enter for it to redirect the url to another website.  Do not edit the javascript file it will screw things up. I learned that lesson. Let me know if this helps.&lt;br /&gt;&lt;br /&gt;&lt;FORM method="post" ACTION="/login.html"&gt;&lt;br /&gt;&lt;INPUT TYPE="hidden" NAME="redirect_url" SIZE="255" MAXLENGTH="255" VALUE="www.google.com"&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/8" level="1.1.1.1.2.1.1" new="yes">            <Author authinfo=" Coleman Technologies">jennifer.huber</Author><Timestamp>Feb 8, 2007, 6:44am PST</Timestamp><Msgbody>The FORM section of the html I pulled down looked like this:&lt;br /&gt;&lt;br /&gt;&lt;FORM action=/login.html method=post&gt;&lt;INPUT type=hidden maxLength=15 size=16 &lt;br /&gt;value=0 name=buttonClicked&gt; &lt;INPUT type=hidden maxLength=15 size=16 value=0 &lt;br /&gt;name=err_flag&gt; &lt;INPUT type=hidden maxLength=31 size=32 name=err_msg&gt; &lt;INPUT &lt;br /&gt;type=hidden maxLength=15 size=16 value=0 name=info_flag&gt; &lt;INPUT type=hidden &lt;br /&gt;maxLength=31 size=32 name=info_msg&gt; &lt;INPUT type=hidden maxLength=255 size=255 &lt;br /&gt;name=redirect_url&gt;&lt;br /&gt;&lt;br /&gt;I edited this section to get the redirect to work:&lt;br /&gt;&lt;br /&gt;&lt;FORM action="&lt;A HREF="javascript:newWin(&apos;http://www.google.com&apos;)"&gt;http://www.google.com&lt;/A&gt;" method=post&gt;&lt;br /&gt;&lt;br /&gt;Thanks so much for heading me in the right direction!&lt;br /&gt;&lt;br /&gt;I also realized that I had accidentally made the login.html a login.htm and the webauth bundle would not extract properly.  I kept getting the error:&lt;br /&gt;&lt;br /&gt;Error extracting webauth files.&lt;br /&gt;&lt;br /&gt;Once I renamed the login.htm to .html the upload worked.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/9" level="1.1.1.1.2.1.1.1" new="yes">            <Author authinfo=" Coleman Technologies">jennifer.huber</Author><Timestamp>Feb 8, 2007, 8:20am PST</Timestamp><Msgbody>Actually - my post wasn&apos;t correct - the redirect worked from the controller preview, but not as a redirected user.&lt;br /&gt;&lt;br /&gt;The section I edited to make it work was this:&lt;br /&gt;&lt;br /&gt;&lt;INPUT type=hidden maxLength=255 size=255 &lt;br /&gt;name=redirect_url value="&lt;A HREF="javascript:newWin(&apos;http://www.google.com&apos;)"&gt;http://www.google.com&lt;/A&gt;"&gt;&lt;br /&gt;&lt;br /&gt;Wanted to clarify for any other people having issues.  Controller code version is:4.0.206.0, and it is a WLC 4402-50.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/10" level="1.1.1.1.2.1.1.1.1" new="yes">            <Author authinfo=" Atlantic Health">mmatulevich</Author><Timestamp>Feb 27, 2007, 8:53am PST</Timestamp><Msgbody>This is a good thread, as I have been having problems with web passthrough for guests since day 1 of upgrading to 4.0.179.11.  I feel as though I am very close, a guest user now will see our custom passthrough page, click a button stating they have read the above usage information, and get to the "connection successfull" page.&lt;br /&gt;&lt;br /&gt;From here, nothing happens: there is no redirect.  You can manually change your url and use the internet as you should.  If you click your home page button you end up back at the passthrough page, where if you click the button again it just loops the same page.  Here is the popular part of my html:  If anyone has any suggestions, I greatly appreciate it.  TAC has responded that they will not assist with custom made pages.  If anyone wants to email me directly, I am at &lt;A HREF="mailto:mikematulevich@yahoo.com"&gt;mikematulevich@yahoo.com&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;&lt;FORM method="post" ACTION="/login.html"&gt;&lt;br /&gt;&lt;INPUT TYPE="hidden" NAME="buttonClicked" SIZE="16" MAXLENGTH="15" VALUE="0"&gt;&lt;br /&gt;&lt;INPUT TYPE="hidden" NAME="err_flag" SIZE="16" MAXLENGTH="15" VALUE="0"&gt;&lt;br /&gt;&lt;INPUT TYPE="hidden" NAME="err_msg" SIZE="32" MAXLENGTH="31" VALUE=""&gt;&lt;br /&gt;&lt;INPUT TYPE="hidden" NAME="info_flag" SIZE="16" MAXLENGTH="15" VALUE="0"&gt;&lt;br /&gt;&lt;INPUT TYPE="hidden" NAME="info_msg" SIZE="32" MAXLENGTH="31" VALUE=""&gt;&lt;br /&gt;&lt;INPUT TYPE="hidden" NAME="redirect_url" SIZE="255" MAXLENGTH="255" VALUE=""&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/11" level="1.1.1.1.2.1.1.1.1.1" new="yes">            <Author authinfo=" State of NJ -Judiciary">wowsersusa</Author><Timestamp>Feb 27, 2007, 11:35am PST</Timestamp><Msgbody>Mike  what you have to edit or add is up above the FORM method area.  I remember having to add in some of my own code which I posted pretty much a whole block and you should be able to figure out where it goes.&lt;br /&gt;&lt;br /&gt;      &lt;br /&gt;&lt;/STYLE&gt;&lt;br /&gt;&lt;script language="javascript" src="./loginscript.js"&gt;&lt;/script&gt;&lt;br /&gt;&lt;script&gt;&lt;br /&gt;    var url = "";&lt;br /&gt;    if(url != ""){&lt;br /&gt;        var link = document.location.href;&lt;br /&gt;        var searchString = "?redirect=";&lt;br /&gt;        var equalIndex = link.indexOf(searchString);&lt;br /&gt;        var redirectUrl = "www.google.com";&lt;br /&gt;        if(equalIndex &gt; 0) {&lt;br /&gt;                equalIndex += searchString.length;&lt;br /&gt;                redirectUrl += link.substring(equalIndex);&lt;br /&gt;                //attach the redirect url only if the ext web auth url doesn&apos;t contain it&lt;br /&gt;                searchString = "&amp;redirect=";&lt;br /&gt;                equalIndex = url.indexOf(searchString);&lt;br /&gt;                if(equalIndex &lt; 0){&lt;br /&gt;                    url+= "&amp;redirect=";&lt;br /&gt;                    url+=redirectUrl;&lt;br /&gt;                }&lt;br /&gt;        }&lt;br /&gt;        window.location.href = url;&lt;br /&gt;    }&lt;br /&gt;&lt;br /&gt;function getErrorMsgIfAny(){&lt;br /&gt; if(document.forms[0].err_flag.value == 1){&lt;br /&gt;    document.writeln(&apos; \\&lt;br /&gt;     &lt;tr align="center"&gt; &lt;td colspan="2" style="color:#CC0000"&gt;Login Error.&lt;/td&gt;\\&lt;br /&gt;     &lt;/tr&gt;&lt;tr align="center"&gt; &lt;td width="350" class="message" colspan="2"&gt; Please try again.&lt;/td&gt;&lt;/tr&gt;\\&lt;br /&gt;    &lt;tr&gt; &lt;td class="caption" colspan="2"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&apos;);&lt;br /&gt; }else{&lt;br /&gt;   document.writeln(&apos; &apos;);&lt;br /&gt; }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;function noenter() {&lt;br /&gt;  return !(window.event &amp;&amp; window.event.keyCode == 13); }&lt;br /&gt;&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;/head&gt;&lt;br /&gt;&lt;body bgcolor="#ffffff" text="#000000" leftmargin="0" topmargin="0" marginwidth="0" marginheight="0"&gt;&lt;br /&gt;&lt;FORM method="post" ACTION="/login.html"&gt;&lt;br /&gt;&lt;INPUT TYPE="hidden" NAME="buttonClicked" SIZE="16" MAXLENGTH="15" VALUE="0"&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/12" level="1.1.1.1.2.1.1.1.1.1.1" new="yes">            <Author authinfo=" Atlantic Health">mmatulevich</Author><Timestamp>Feb 27, 2007, 1:40pm PST</Timestamp><Msgbody>Thanks wow, good stuff.  You didn&apos;t do any modifications to your javascript file I hope?&lt;br /&gt;&lt;br /&gt;I think the only real difference in the html I somehow missed was the&lt;br /&gt;&lt;br /&gt;var redirectUrl = "www.google.com"&lt;br /&gt;&lt;br /&gt;I thought for some reason if all these values were set to "", then it would redirect the user&apos;s specific home page.  I will give this a shot.  That being said, for the line a little lower on your html:&lt;br /&gt;&lt;br /&gt;&lt;INPUT TYPE="hidden" NAME="redirect_url" SIZE="255" MAXLENGTH="255" VALUE=""&gt;&lt;br /&gt;&lt;br /&gt;Did you have to specify the VALUE="www.google.com" in that portion, or did you leave it ""&lt;br /&gt;&lt;br /&gt;Thanks in advance!</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/13" level="1.1.1.1.2.1.1.1.1.1.1.1" new="yes">            <Author authinfo=" State of NJ -Judiciary">wowsersusa</Author><Timestamp>Feb 28, 2007, 4:34am PST</Timestamp><Msgbody>FYI for anyone. DO NOT Modify the java script I had many problems when I did.  </Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/14" level="1.1.1.1.2.1.1.1.1.1.1.1.1" new="yes">            <Author authinfo=" Atlantic Health">mmatulevich</Author><Timestamp>Feb 28, 2007, 6:06am PST</Timestamp><Msgbody>Well I gave a few more bundles a try, modifying the html only by adding a redirect url in different areas.  Upon clicking the button as a guest user, you still just end up at a "Connection Successfull" screen with the url of "1.1.1.1/login.html" - and it just sits there.  &lt;br /&gt;&lt;br /&gt;I noticed in your html you have some session information after ACTION="/login.html"&lt;br /&gt;&lt;br /&gt;I never see that so I am wondering if this is where my problem is?&lt;br /&gt;&lt;br /&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/15" level="1.1.1.1.2.1.1.1.1.1.1.1.1.1" new="yes">            <Author authinfo=" Atlantic Health">mmatulevich</Author><Timestamp>Feb 28, 2007, 11:51am PST</Timestamp><Msgbody>Ah nevermind that, thats something that is getting pasted by the cisco website when I send a forum reply.  So, this is where I am - even I have editied these two fields in the html from "":&lt;br /&gt;&lt;br /&gt;var redirectUrl = "&lt;A HREF="javascript:newWin(&apos;http://www.google.com/&apos;)"&gt;http://www.google.com/&lt;/A&gt;";&lt;br /&gt;&lt;br /&gt;&lt;INPUT TYPE="hidden" NAME="redirect_url" SIZE="255" MAXLENGTH="255" VALUE="&lt;A HREF="javascript:newWin(&apos;http://www.google.com/&apos;)"&gt;http://www.google.com/&lt;/A&gt;"&gt;&lt;br /&gt;&lt;br /&gt;As a guest, the passthrough page displays properly.  I noticed the full url at this point was:&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;https://1.1.1.1/fs/customwebauth/login.html?switch_url=https://1.1.1.1/login.html&amp;ap_mac=xx:xx:xx:xx:xx:xx&amp;wlan=xxxxxx&amp;redirect=my_browser_homepage&apos;)"&gt;https://1.1.1.1/fs/customwebauth/login.html?switch_url=https://1.1.1.1/login.html&amp;ap_mac=xx:xx:xx:xx:xx:xx&amp;wlan=xxxxxx&amp;redirect=my_browser_homepage&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;Checking the source at that point showed the original values of "" instead of the defined &lt;A HREF="javascript:newWin(&apos;http://www.google.com.&apos;)"&gt;www.google.com.&lt;/A&gt;  When I click the button to proceed, I get the Connection Successfull page with the url:&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;https://1.1.1.1/login.html&apos;)"&gt;https://1.1.1.1/login.html&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;Checking that page&apos;s source also does not show &lt;A HREF="javascript:newWin(&apos;http://www.google.com&apos;)"&gt;www.google.com&lt;/A&gt; as a value, but rather:&lt;br /&gt;&lt;br /&gt;&lt;FORM method="post" ACTION="/login_success.html"&gt;&lt;br /&gt;&lt;INPUT TYPE="hidden" NAME="redirect_url" SIZE="255" MAXLENGTH="255" VALUE=""&gt;&lt;br /&gt;&lt;/FORM&gt;&lt;br /&gt;&lt;br /&gt;So I do not know why but something is overwriting the bundle changes I make.  I did verify the .tar and apply/save config to the controller prior to testing.  Any thoughts?&lt;br /&gt;&lt;br /&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/16" level="1.1.1.1.2.1.1.1.1.1.1.1.1.1.1" new="yes">            <Author authinfo=" Systems Connect, Inc.">sethc@systemsconnect.com</Author><Timestamp>Feb 28, 2007, 5:06pm PST</Timestamp><Msgbody>(Don&apos;t yell at me) but I just changed the logo and text of the sample web auth page with Frontpage and it worked fine.&lt;br /&gt;&lt;br /&gt;My questions is this.. I&apos;m planning on having web auth against ACS for the internal wireless network, but for a guest network, I&apos;d like to do passthrough.   Is there any way to have separate custom pages to do this?    &lt;br /&gt;&lt;br /&gt;If it&apos;s not possible I may just try and restrict SSID&apos;s via ACS and make a guest account, although at first try the NAR for restricting SSID&apos;s didn&apos;t work</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/17" level="1.1.1.1.2.1.1.1.1.1.1.1.1.1.1.1" new="yes">            <Author authinfo=" Atlantic Health">mmatulevich</Author><Timestamp>Mar 1, 2007, 11:46am PST</Timestamp><Msgbody>Progress is a good thing, I think.  I left all the values as they were at default for redirection in the html source. ("")  Uploaded the bundle and applied it.  CLI&apos;ed into the controller and entered &apos;config custom-web redirectUrl &lt;A HREF="javascript:newWin(&apos;http://www.google.com.&apos;&apos;)"&gt;www.google.com.&apos;&lt;/A&gt;  &lt;br /&gt;&lt;br /&gt;I had thought that field only applied when using the default (Internal) web login page.  saved the configuration, logged in as guest and after clicking the button, passed through and redirected to google!&lt;br /&gt;&lt;br /&gt;The only problem left, which is potentially a forseeable one for guests, is that we will most likely redirect to our company homepage.  A guest will probably then hit their browser homepage button, which sends them back to the passthrough page with a statuscode=1 at the end of the url, leaving them in a loop if they refresh.&lt;br /&gt;&lt;br /&gt;If they open another browser session, there is no problem and they go to their usual homepage and are fine.  If anyone has any input on that or something to try let me know! almost there!</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/18" level="1.1.1.1.2.1.1.1.1.1.1.1.1.1.1.1.1" new="yes">            <Author authinfo=" Systems Connect, Inc.">sethc@systemsconnect.com</Author><Timestamp>Mar 1, 2007, 12:50pm PST</Timestamp><Msgbody>I did observe the same thing as you today as I&apos;m doing a new WCS/WISM/Wireless deployment.. you beat me to posting it! Even though you choose custom web auth, you still do have to use the config custom-web redirectURL command on the controller itself.&lt;br /&gt;&lt;br /&gt;I actually noticed the same thing as you w/ the guest page but didn&apos;t try to open a new browser session..  that&apos;s the only thing I have to get around as well!</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/19" level="1.1.1.1.2.1.1.1.1.1.1.1.1.1.1.1.1.1" new="yes">            <Author authinfo=" Atlantic Health">mmatulevich</Author><Timestamp>Mar 5, 2007, 12:55pm PST</Timestamp><Msgbody>I was able to get the homepage button to send you to your browser&apos;s original homepage after using the passthrough page.  I was missing a line in my html that prevented cache.  I guess without this line the browser session was holding the passthrough page as the homepage.  The line was:&lt;br /&gt;&lt;br /&gt;&lt;meta http-equiv="Pragma" content="no-cache"&gt;&lt;br /&gt;&lt;br /&gt;So now redirection works as well as the user&apos;s homepage button after passthrough!  Many thanks to the forum as this was my absolute only means to information.  &lt;br /&gt;&lt;br /&gt;I am still continuing to work on the page to get it to function like the internal passthrough, meaning it would redirect you to your own browser homepage.  I will keep an eye on this thread to help out anyone if I can, and post my own progress.&lt;br /&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/20" level="1.1.1.1.2.1.1.1.1.1.1.1.1.1.1.1.1.1.1" new="yes">            <Author authinfo=" Systems Connect, Inc.">sethc@systemsconnect.com</Author><Timestamp>Mar 15, 2007, 8:28am PST</Timestamp><Msgbody>My HTML page already had that line.&lt;br /&gt;&lt;br /&gt;The problem I am running in to now is that when using custom web auth page, the web-passthrough page gets changed as well, and it&apos;s different.&lt;br /&gt;&lt;br /&gt;TAC had me downgrade controller software to 4.0.179.11.&lt;br /&gt;&lt;br /&gt;If you use the default internal web auth pages, you&apos;ll see that you get served a different page when you use a WLAN with web-auth versus one with web-passthrough + email input. &lt;br /&gt;&lt;br /&gt;I&apos;ll let everyone know what I found out with my case..</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/21" level="1.1.1.1.2.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1" new="yes">            <Author authinfo=" Atlantic Health">mmatulevich</Author><Timestamp>Mar 15, 2007, 9:15am PST</Timestamp><Msgbody>Definately, there are more scripts added that reference the javascript file when you do more than passthrough.  After all the testing I did just to get passthrough working, your custom html working depends highly on where you place the scripts.  I&apos;m sure you will figure it out as long as you include the new ones in your page - good luck</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/22" level="1.1.1.1.2.1.1.1.1.1.1.1.1.1.1.1.1.1.1.2" new="yes"><Author authinfo=" ">kjetil.carlsen@gmail.com</Author><Timestamp>Mar 17, 2008, 3:53am PST</Timestamp><Msgbody>I&apos;m using the "custom web auth page", and everything works fine exept when i get rederected back to the webpage if wrong password/username/allready loggen inn etc.&lt;br /&gt;&lt;br /&gt;If running the "default web auth page" im returned with this url:&lt;br /&gt;&lt;br /&gt;https://xxxxxxx/login.html?switch_url=http://xxxxxx/login.html&amp;ap_mac=xx:xx:xx:a8:27:e0&amp;wlan=xxxx-guest&amp;redirect=www.google.com&amp;statusCode=5&lt;br /&gt;&lt;br /&gt;If I switch too the "custom web auth page" I’m missing the parameter "statusCode=" - and therefore gets no alerted errormessage..&lt;br /&gt;Anyone know why?&lt;br /&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/23" level="1.1.1.1.2.1.1.1.1.1.1.1.1.1.1.1.1.1.1.2.1" new="yes">            <Author authinfo=" IBM CHINA/HONG KONG LIMITED">ibm.alexl</Author><Timestamp>Feb 9, 2009, 2:23am PST</Timestamp><Msgbody>For the redirect page, is it also works on https page? I have customer who want to redirect to a SSL page (intranet) when users connect to the wireless network. &lt;br /&gt;&lt;br /&gt;Could it done by modifying the custom login page redirect_url hidden html field??&lt;br /&gt;&lt;br /&gt;Thanks.</Msgbody><Attachment/></Message></Reply></Reply></Reply><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/24" level="1.1.1.1.2.1.1.1.1.1.1.1.1.1.1.1.1.1.2" new="yes">            <Author authinfo=" CHICKASAW TELECOM, INC.">robert_braver</Author><Timestamp>Nov 6, 2009, 12:02pm PST</Timestamp><Msgbody>Has anyone figured out getting redirect to the user&apos;s desired page working on a custom web auth configuration?&lt;br /&gt;&lt;br /&gt;TIA for any pointers.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".1ddcc520/25" level="1.1.1.1.2.1.1.1.1.1.1.1.1.1.1.1.1.1.2.1" new="yes">            <Author authinfo=" CHICKASAW TELECOM, INC.">robert_braver</Author><Timestamp>Nov 6, 2009, 1:17pm PST</Timestamp><Msgbody>Working: redirect to user&apos;s desired URL&lt;br /&gt;&lt;br /&gt;Not long after I posted asking about redirecting to the user&apos;s desired page, I found a workaround.&lt;br /&gt;&lt;br /&gt;I had been using the built-in default web auth files as a template and customized.&lt;br /&gt;&lt;br /&gt;There are webauth bundle examples on CCO that someone mentioned, so I searched and found them.  In those examples, they don&apos;t use a loginscript.js - they just put whatever functions they need in the html page.&lt;br /&gt;&lt;br /&gt;At any rate, there is a newer submitAction function in the example I looked at.  I replaced the previous version and all works as expected.</Msgbody><Attachment/></Message></Reply></Reply></Reply></Reply></Reply></Reply></Reply></Reply></Reply></Reply></Reply></Reply></Reply></Reply></Reply></Reply></Reply></Reply></Reply></Reply></Replies></Conversation><Conversation id=".2cd4c68d" messages="1" subscribed="no" title="Authentication throu controler 4402 from remote branch office"><Message attachment="no" canreply="yes" id=".2cd4c68d" level="">            <Author authinfo=" Zonemedia Management Ltd">james.taiwo</Author><Timestamp>Oct 22, 2009, 2:24am PST</Timestamp><Msgbody>Hi&lt;br /&gt;&lt;br /&gt;We have head office with 4402 controller and few 1130AG series access points. Clients PCs access to wifi network after authentication throu http site (service is woking on 4402 controler). &lt;br /&gt;In other branch (connected to head office throu WAN-VPN) we have one 1130AG AP and we would like to use the same www authentication for clients. Is is possible ? How is the best way to do this ? Can we do this using differents LAN ip addressing for branch AP and clients ?&lt;br /&gt;&lt;br /&gt;thanks in advance&lt;br /&gt;James</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4c68d/0" level="1." new="yes">            <Author authinfo=" PARALLEL TECHNOLOGIES, INC.">klein425@hotmail.com</Author><Timestamp>Nov 6, 2009, 12:27pm PST</Timestamp><Msgbody>The ideal solution would be to use the 4402 web-auth page and then route Internet traffic locally, instead of through the VPN.  Unfortunatly I&apos;m not aware of such a solution.&lt;br /&gt;&lt;br /&gt;If you don&apos;t have the remote 1130 AP set to HREAP mode all traffic will be tunneled back to the WLC and clients will be forced to use the web-auth on the 4402.&lt;br /&gt;&lt;br /&gt;If you are using HREAP, traffic would get routed locally and not forced to the 4402 page.&lt;br /&gt;&lt;br /&gt;Depending on the remote users&apos; traffic patterns and how secure you want authentication/encryption, it might be okay just to tunnel the traffic back.  This is also dependant on a good WAN.  If it goes down, no wireless access at remote side.</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4dcf4" messages="1" subscribed="no" title="Internal DHCP/Guest/NAT Question...?!?"><Message attachment="no" canreply="yes" id=".2cd4dcf4" level="">            <Author authinfo=" GENERAL DYNAMICS INFORMATION TECHNOLOGY, INC.">kenneth.hall</Author><Timestamp>Nov 3, 2009, 5:34pm PST</Timestamp><Msgbody>WLC 2125 (running 5.2.193.0) - Trying to determine if it is possible to have a Guest SSID hand out an address from the internal DHCP server and have that NAT&apos;d out a physically separate interface that just goes to a local ISP? Or is the only way to connect the separate port to a router/DHCP server for that network and let the external router do the NAT&apos;ing?!?&lt;br /&gt;&lt;br /&gt;-k</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4dcf4/0" level="1." new="yes">      <Author authinfo="Wireless Practice Manager, INTERNETWORK ENGINEERING">dennischolmes</Author><Timestamp>Nov 6, 2009, 9:50am PST</Timestamp><Msgbody>External routing from a router, ASA, PIX, or other layer 3 device only. The controller has no ability to NAT.</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4d45a" messages="1" subscribed="no" title="Problems with 802.1x and Atheros cards"><Message attachment="no" canreply="yes" id=".2cd4d45a" level="">            <Author authinfo=" UNIVERSITY OF VT">lynne.meeks</Author><Timestamp>Oct 29, 2009, 7:30am PST</Timestamp><Msgbody> We have just discovered a problem with 802.1x authentication and Atheros cards.&lt;br /&gt;We have seen this on both MAC OS X 10.6.0 systems and an XP System&lt;br /&gt;&lt;br /&gt;This appears to be a DHCP problem in that clients don&apos;t get an IP address unless they reboot- which usually fixes it. Sometimes the controller will think the client is connected with a valid IP but the client doesn&apos;t actually get the address (never sends an ACK to the offer)&lt;br /&gt;&lt;br /&gt;Then it will work until they try to reconnect again after a suspend or roaming to a new AP&lt;br /&gt;&lt;br /&gt;Anybody seen this? It&apos;s making our network look bad since we have a lot of MACs with Atheros cards...&lt;br /&gt;&lt;br /&gt;thanks,&lt;br /&gt;&lt;br /&gt;Lynne</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4d45a/0" level="1." new="yes">      <Author authinfo="Wireless Practice Manager, INTERNETWORK ENGINEERING">dennischolmes</Author><Timestamp>Nov 6, 2009, 6:44am PST</Timestamp><Msgbody>Try disabling dhcp by proxy. That tends to slow down the dhcp process significantly and disabling it allows you to track dhcp requests and lease times easier. In the WLC gui go to controller, advanced, dhcp, and then take the check mark out of the box. This will stop the dhcp relay mechanism where all dhcp requests appear to the dhcp server to come from the virtual interface of the controller.</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4df6b" messages="1" subscribed="no" title="WiSM Image Upgrade problem "><Message attachment="no" canreply="yes" id=".2cd4df6b" level="">      <Author authinfo="Network Specialist, UNITED COMPUTER &amp; MA">jain.nitin</Author><Timestamp>Nov 5, 2009, 12:16am PST</Timestamp><Msgbody>Hi All, we are facing problem in upgrading wism image from 3.2.78 to 3.2.195. When Ever I try to upgrade image of controllers i get an error message failed to store in flash.. I tried to upload boot loader file as well which is of 4MB, but I am getting same message..I am using TFTD32 software. I also noticed that controllers have two images in its memory, primary &amp; backup. I want to delete the backup one so that memory can be free..if its a memory problem...can any body help me on this..I want to resolve this issue asap.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4df6b/0" level="1." new="yes">            <Author authinfo=" EDS (AUSTRALIA) PTY LIMITED">leolaohoo</Author><Timestamp>Nov 5, 2009, 10:07pm PST</Timestamp><Msgbody>Wow.  That&apos;s pretty old firmware.  Why don&apos;t you upgrade to 4.2.207.0 instead?&lt;br /&gt;&lt;br /&gt;Don&apos;t bother deleting the 2nd boot flash because this will save your skin when the 1st boot flash fails.</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4df0c" messages="1" subscribed="no" title="WCS oui/vendor unknown"><Message attachment="no" canreply="yes" id=".2cd4df0c" level=""><Author authinfo=" GARDEN VALLEY SCHOOL DIVISION">dan.letkeman</Author><Timestamp>Nov 4, 2009, 4:16pm PST</Timestamp><Msgbody>Hello,&lt;br /&gt;&lt;br /&gt;When I&apos;m running reports in wcs we have a lot of our new machines show as unknown in the vendor list.  Is there a way to make manual entries for certain oui&apos;s?  Or even better, a way to update the list?&lt;br /&gt;&lt;br /&gt;Thanks,&lt;br /&gt;Dan.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4df0c/0" level="1." new="yes">      <Author authinfo="Customer Support Engineer, Cisco" ccie="yes">lavramov</Author><Timestamp>Nov 5, 2009, 10:09am PST</Timestamp><Msgbody>This is not supported as of now. It&apos;s a good thing to be requested as a Personnal Enhancement Request via your sales / account team.</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4dbec" messages="0" subscribed="no" title="Question on best practice for NAT/PAT and client access to firewall IP  "><Message attachment="no" canreply="yes" id=".2cd4dbec" level="">            <Author authinfo=" ">news2010a</Author><Timestamp>Nov 3, 2009, 11:26am PST</Timestamp><Msgbody>Imagine that I have this scenario:&lt;br /&gt;&lt;br /&gt;Client(IP=192.168.1.1/24)--[CiscoL2 switch]--Router--CiscoL2Switch----F5 Firewall IP=10.10.10.1/24 (only one NIC, there is not outbound and inbound NIC configuration on this F5 firewall)&lt;br /&gt;&lt;br /&gt;One of my users is complaining about the following:&lt;br /&gt;When clients receive traffic from the F5 firewall (apparently the firewall is doing PAT not NAT, the client see IP address 10.10.10.1. &lt;br /&gt;&lt;br /&gt;Do you see this is a problem? Should I make another IP address range available and do NAT properly so that clients will not see the firewall IP address? I don&apos;t see this situation is a problem but please let me know if I am wrong.&lt;br /&gt;</Msgbody> <Attachment/></Message></Conversation><Conversation id=".2cd4db97" messages="1" subscribed="no" title="Confirmation on public, private key concept"><Message attachment="no" canreply="yes" id=".2cd4db97" level="">            <Author authinfo=" ">news2010a</Author><Timestamp>Nov 3, 2009, 9:10am PST</Timestamp><Msgbody>This is not a Cisco product related, but in case someone can confirm I&apos;d appreciate it:&lt;br /&gt;&lt;br /&gt;Imagine from a web server (let&apos;s say the Microsoft IIS web server thing) you generate a "certificate request" and submit that to the CA (Certificate Authority, Verisign for example).&lt;br /&gt;&lt;br /&gt;Then Verisign process your request and send you the certificate via e-mail and then you install that certificate on the web server Microsoft IIS web server.&lt;br /&gt;&lt;br /&gt;Question:&lt;br /&gt;The certificate that Verisign sent over e-mail is (or contain) the public key, correct?&lt;br /&gt;&lt;br /&gt;How about the private key? Was that private key generated when such "certificate request" was processed at the very first step in the Microsoft web server, correct?&lt;br /&gt;</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4db97/0" level="1." new="yes">            <Author authinfo=" CISCO SYSTEMS">dancampb</Author><Timestamp>Nov 3, 2009, 10:25am PST</Timestamp><Msgbody>You are correct with your thoughts of public and private keys.  </Msgbody><Attachment/></Message></Reply></Replies></Conversation></Topic></Forum></Community></ActiveMessages>')

