2 SSID and VLAN on each access point

I'm new to Setup IOS APs and wireless, in particular, a couple of 1142Ns in autonomous mode and are looking for answers and examples. These APs will be connected to the POE on an ASA 5505 firewall ports. I also set up the 5505.

The requirements are that each AP have a SSID 'internal' and 'external' and each AP will have two VLANS.

The APs should allow roaming between them.

Internal SSID will allow full access to the company's internal network and the Internet and will use WPA2. It will use the corporate dhcp server and the dhcp server to use IOS to distribute addresses.

The external SSID will not have access to the Internet and use WEP. The ASA 5505 provide dhcp on these clients.

The two ports PoE on the ASA 5505 will be shared resources for inside and dmz VLAN.

If anyone has examples of any of these conditions, observations or similar config they are willing to share, please post them.

In particular, I would like to see an example of homelessness config Setup VLAN, SSID config and Setup WPA2 and WEP.

Thanks in advance.

The link below will help you get the configuration based on the AP wireless...

http://www.Cisco.com/en/us/Tech/tk722/tk809/technologies_configuration_example09186a008055c39a.shtml

Here is the link for PSK WPA-2 as well

https://www.Cisco.com/en/us/Tech/tk722/tk809/technologies_configuration_example09186a008054339e.shtml#pers

The above can help you...

Concerning

Surendra

=====

Please do not forget to note positions that answered your question or was useful

Tags: Cisco Wireless

Similar Questions

  • Remove the secondary controller and tertiary high availability for each access point

    I want to remove secondary and tertiary sector controller of high availability for each access point. I have more than 900 APs associated with a Version of the WLC 8510 8.0.121.0 software. What is the best/better way to remove secondary and tertiary controller?
    Or I can create a model first. We use version 2.2

    Hello

    Easiest way:

    Yes you can do this by using the first Cisco Infrastructure, you can create a Setup AP Lightweight model to specify the name of the PDC and the IP address and specify an empty value (choose the first empty option in the drop-down list) and 0.0.0.0 for the secondary and tertiary sector controllers.  Then you can apply this model to the AP, and she must remove (virgins all) values for these fields.

    Long way:

    Yes there is no clean way to remove it from the CLI. you need to manually remove each on the AP.

    Concerning

    Remember messages useful rates

  • AC1900-Nighthawk WiFi Range Extender can be wired in and used as an access point?

    I want to replace my WN802T which is connected to the network.

    Found the manual and it can be used as an access point.

  • Use HREAP SSID and vLAN

    Hello

    I have currently a small deployment wireless using LWAPP 1141 against WISN controllers. The controller is configured with a SSID against a dynamic interface.

    For the mobility of the user, the company wants to use one SSID for the movement of personnel between offices

    New Office Online to use 3502 configured as of HREAP and local CAPWAPs to next mode switching.

    My understanding is that the CAPWAPs require a virtual interface on the controller to CAPWAP > traffic controller. Requires a dynamic interface for users of the site of HREAP setting on the controller? If this is not the case, how an SSID on the controller are mapped to the vLAN on the remote site?

    Thank you

    David,

    No problem, so review your comments below really all what you need to do is the following.

    Once the SSID is set to H-HARVEST of local switching, and the AP is set in Mode H-REAP follow these steps:

    -Under AP Configuration click the H-REAP tab and activate the socket supported VLAN

    -The value VLAN native 797 and click on apply

    -Under AP Configuration click the H-REAP tab click on mappings of VLAN

    -Enter the respective VLAN for the SSID is shown if they are different from

    -On the remote switch port Configuration of AP as a port Trunk just like you did with the WLC port (797 of VLANs allowed native and 301.)

    The Group REAP H is more important if your use 802. 1 x or authentication EAP type where a radius server is used. You can create a Group H-HARVEST to implement if you want even if you do not use this authentication method.  In regards to the WLC knows it remote. I don't think he cares.

    You can see examples of my 3 screen shots attached.

    I hope this helps... Please evaluate the useful messages.

    Thank you

    Kayle

  • From a few access points SSID

    Hi all

    I'll create a new WLAN id/identifier SSID in Cisco 4402 wireless controller and as soon as I did that create the ssid will be pushed to all access points, but I want to broadcast the SSID that at a few access points, is anyway we achieve this in the controller itself or WCS. Please let me know

    Thank you

    Hello

    Yes, you can shape this traffic. His call to Cisco AP groups. You can simply consult the configuration for confi efforts guide. What is the code, you are on, if you are on 4.2 you can Overide WLAN.

    I hope this helps...

  • RV180W add the access point with itinerant support

    I have a client with a RV180w the latest firmware running.  We currently use the router as a router and provide wireless access.  We want to add a wireless coverage and I'm interested in our options.  We have a network unifying ethernet that we could use to give the new connectivity LAN AP.  Can buy us another RV180W and use it in AP mode and roaming wireless connectivity.  The customer wants a guest and business WLAN so we'll use the VLAN of the router.  How we set up the new AP?  Should we use WDS?   If we use WDS, can we still use WPA2?  Thank you for your help.

    Hello, Mr. Carl,.

    Yes is possible to use WDS and WPA2 at the same time.

    The master of accreditation will be setup as a RADIUS server to authenticate the other access points, while clients use the WPA2-PSK, which occupies the same on each access point.

    Let me share with you the information found on WDS and the configuration of basic, found on the guide me section.

    WDS configuration:

    http://sbkb.Cisco.com/CiscoSB/UKP.aspx?VW=1&docid=ea8660ccb0cf4ae99cebfafd4303cdc1_WDS_Configuration_on_RV180W.XML&PID=4&FCID=&fpid=&slnid=13

    RV180W configuration:

    http://sbkb.Cisco.com/CiscoSB/UKP.aspx?VW=1&docid=dd5990ef4ad947ae89da5c3e0b8bd985_Wireless_Configuration_on_RV180W.XML&PID=4&FCID=&fpid=&slnid=4

    If this answer is satisfactory to you, please mark it as response.

    Diego Rodriguez

    Cisco network engineer

    Thank you

  • Cisco SG500 and VLAN

    OK so here is what I try to accomplish with 3 switch Cisco SG500-52. I created 4 VLANS on a SG500 I call my central office switch and it is set in routing mode. My VLAN is thus 400 (Infrastructure ESXI hosts, firewall, etc.), 401 (VoIP), 402 (users) and 403 (wireless). I have configured interfaces and the delivery without problem for me through my subnets and the communities of remote access through 3 offices.

    Where I'm not sure is on the SG500 I set as a L2 switch and my ESXi host are connected (I have 10 ports on one VLAN remote iSCSI traffic) is that I have to create VLAN 400 and mark those ports not marked? So should I use 1-2 ports and set them as ports and tag to my main switch 400?

    In the affirmative on the main switch I create junction ports and mark for the VLAN on the switch that could access the L2 switch? Is this also the case for the other SG500 I have who are all devices for 402 VLAN?

    I'm overloading it?

    Thanks in advance for any help.

    Hi Sdonnelly2,

    For vlan 402 and 400 on the uplink to your sg500 (L2) would be 400U and 402 T.

    Other interfaces for VoIP phones on vlan 401 would be configured to 401 T. This is if your phones expect traffic labeled, otherwise they would be configured to 401U.

    For Vlan 402 other interfaces would still be 402U. PC only contacted untagged traffic

    For 403 Vlan wireless uplink access point must be configured (400U, 401, 402, 403T)

    It is perhaps more information than expected, but I hope that I have answered other questions you had.

  • How to force the client to connect to the specific access point?

    I have a client that connects to an Access Point to the upper floor.  The connection is "Very low" and pings are restless.  Is there a way to force the client to connect to the point of access on its own soil in the hallway.

    Access Points using 1131AG; WLC2106

    PSK + WPA2

    Thank you

    There is not a way to force the client to use a specific side access point controller of things.  According to the specifications, the client decides when and where to associate.  You can try to disable some of the rates below data or lower power tx of the AP to reduce the coverage of each access point cell.  By doing this, the client cannot see the other as favourable AP.

  • Change the SSID and WEP key after changing the AP

    The Setup is a Linksys BEFSR41 router and a Linksys WAP54G access point.

    Initial Setup used by default no WEP and SSID.

    No problem connecting to my XPS1330.

    Now, I would change the SSID (to distinguish my home network from other networks) and

    Adding a WEP KEY.

    VISTA will allow me to change the current, marked network to home or should I delete this one and start again?

    Thank you

    Bill


  • Satellite M70: I can't connect to the WLan access point

    I have several wireless laptops, all work fine - except my M70.
    I use Intel Proset, and he sees the access point, but says "unable to connect" when I try.
    The signal is high (2 meters distance).

    I tried with WEP, WPA and without security. I am absolutely convinced that I entered the right keys.
    The access point is a Belkin Pre - N-, but I tried with a point of access 3Com, with the same problem - my Ipaq, my other PC, and all guests can connect,- but not my Toshiba!
    The wireless card is the standard Intel, with the latest driver from October 2006 intalled.

    Getting desperate...

    Hello

    If you get a signal strong, so I guess that the laptop is already connected to the access point. Or am I wrong?
    On my laptop, the computer WLan small icon appears only if I connected to the Wlan and then I can see the State of the signal.

    However, you suggested to use the Intel Proset utility to configure the WiFi network but on the clean Windows configuration. Have you tested it?

    This question seems very strange to me.
    Sometimes it of not possible to connect the WiFi network because of poor compatibility between the router and wireless network card.
    My router supports Wlan AB mode and my second card for computer laptop support BG.
    That's why I m not able to connect to the Wlan. Maybe it s also your case.

    On my router, I can also put the MAC address filtering. You should check this option on your router.
    But generally it is not easy to say why it happens. You know you should check every single option and if it s not possible so I guess that it s a compatibility issue.

  • Impossible to access wifi with other access points

    WNDR4500v3 with firmware V1.0.0. I32

    I bought this router on dec 25 2015 to replace a dead linksys router.
    The router feeds a switch of 16 points from one of the 4 ports.
    I have a win 7 pc connected to one of the other routers 3 ports.
    Then a VoIP connected to port 3 of the router.
    I have 2 other wireless access points connected to the port 16.
    We feed a remote building through a wired connection to the firset access point
    The other access point is also fed by a wired connection.
    The old linksys router had him for 4 years.

    As I said I bought this router as a replacement... but since its worthless and the two wireless access point do not have internet connection.
    So either I get it work or will return it for a refund within 24 hours.

    Figured that out it was Network Manager and windows share the unknown connection of marking.

    In advanved sharing setting I have to change to use for user accounts and passwords to connect to other computers

    Then all the problems went away.

    No more giving up connection and with no internet connection.

  • Set up home network of multi access point

    Recently, I cut the string so to speak with directv and is passed to a streaming cable through view PlayStation. However this left me with a little slower network I want to. I have a 3-storey house in a crowded area and my cable modem is on the lower floor.

    Currently, I have a linksys ea3500 connected to a modem cable in the basement. I have a family room on floor 2, where I connected PlayStation. On the third floor, I have a Roku in the bedroom for live tv broadcast and also a Home Office.

    I can work around 70mbps down when connected via Ethernet to the ea3500 on the ground floor, but a signal wirelessly on the second floor is about 25mbps down and falls to 15 or so away on the third floor.

    I ordered a new router (wrt 1900ACS) and also a netgear powerline 1200 kit. My plan is to connect the line adaptor to the ea3500 and place another line on two ground adapter. To which I would link the wrt 1900 and run as an access point for the existing network. I would also link the PlayStation to the wrt1900 through cat 5 to improve the reliability of the connection.

    My hope is that this will greatly increase my speed of download available in the House. We are connected fairy and at any time have probably 10 to 15 devices (tablets, phones, laptops, TVs, desktop, nest, etc.)

    Given my current gear (and the warning that I won't have to run wires through the wall or through the vents) is the configuration I describe the best way to increase the signal strength and bandwidth bandwidth/speed? Does it matter if I use the new wrt 1900acs as a slave to the ea3500, since it will be connected via the power line to the ea3500 lan port? Should I just unplug the ea3500 and only use the 1900acs on the Middle floor and connect the power supply line direct adapter to the cable modem?

    Any idea to my plan or recommended changes to my plan would be appreciated!

    It's good then let the EA3500 and add the WRT1900ACS in via PowerLine Bridge Mode.

  • Ordered the wrong access point!

    I thought that I had ordered a 1130ag but looks like I ordered a 1131ag LWWAP.

    Please could someone tell me what the difference between a 1130 and 1131. I understand I can load the IOS on the light AP software using a tftp server, but I do not know which exit to load on this subject. 12.3JX, 12.3JA, 12.3JEA, 12.3JEB! can anyone help please? either by the way, I am in the United Kingdom, do not know if this affects image to install. Thank you.

    Hi Paul,.

    This happens all the time, so it shouldn't be a problem :) I'm guessing that you have received this AP - AIR - LAP1131AG - x - K9 LWAPP. When you really wanted this AP - AIR-AP1131G-x-K9 Cisco IOS software. Look at the comparison;

    http://www.Cisco.com/en/us/products/ps6087/products_data_sheet0900aecd801b901c.html

    That being said, you should be good to go with 12.3 (11) JA1.

    To access Cisco Aironet to Cisco IOS version 12.3 Points (11) JA1

    http://www.Cisco.com/en/us/docs/wireless/access_point/iOS/release/notes/b11jar1n.html

    Cisco IOS version 12.3 (11) JA1 supports 32 MB independent platforms. 16 MB platforms and platforms supported by Cisco IOS version 12.3 (8) JA and earlier versions (350, 1100, 1130, 1200 and 1230 access points and access point/bridge 1300 series) are supported by Cisco IOS version 12.3 (8) JEA1.

    Do not install a "JX" (it is a software image support to upgrade and recovery Cisco Lightweight Access Point Protocol (LWAPP));

    These release notes describe features, improvements, and caveats for Cisco IOS release 12.3 (11) JX1.

    Note: This version must be loaded on points of access to the plant or by using the lightweight stand-alone mode upgrade tool. Your access point may become unusable if you install this software without using the upgrade tool.

    http://www.Cisco.com/en/us/docs/wireless/access_point/iOS/release/notes/b311jx1.html

    Returning to standalone Access Point

    http://www.Cisco.com/en/us/products/HW/wireless/ps430/prod_technical_reference09186a00804fc3dc.html#wp161272

    You can convert an access point of the mode light return to autonomous mode by loading a Cisco IOS version that supports stand-alone mode (Cisco IOS release 12.3 (7) JA or earlier version). If the access point is associated with a controller, you can use the controller to load the version of Cisco IOS. If the access point is not associated with a controller, you can load the version of Cisco IOS using TFTP.

    By using a TFTP server to revert to a previous version

    Follow these steps to return mode LWAPP stand-alone mode by loading a version of Cisco IOS using a TFTP server:

    --------------------------------------------------------------------------------

    Step 1 the IP address of the computer on which the server software runs TFTP should range from 10.0.0.2 to 10.0.0.30.

    Step 2 make sure the PC contains the file access point (for example, c1200-k9w7 - tar.122 - 15.JA.tar for a 1200 Series access point) in the TFTP server folder and the TFTP server is activated.

    Step 3 Rename the access point image file in the folder of the TFTP server c1200-k9w7 - tar.default for a series of 1200 point, c1130-k9w7 - tar.default of access for a series of 1130 access point and c1240-k9w7 - tar.default for a series of 1240 access point.

    Step 4 connect the PC to the access point using an Ethernet category 5 cable (CAT5).

    Step 5 disconnect the power to the access point.

    Step 6 push the MODE button and hold the button while you reconnect power to the access point.

    Step 7 hold the MODE button until the status of the LED turns red (approximately 20 to 30 seconds), then release.

    Step 8 wait until restarting access point, as indicated by the LEDs become green followed the status LED flashes green.

    Step 9 after the access point reboots, reconfigure using the GUI or the CLI.

    This doc.

    http://www.Cisco.com/en/us/products/HW/wireless/ps430/prod_technical_reference09186a00804fc3dc.html#wp161272

    I hope this helps!

    Rob

  • RV110W access point / bridge mode?

    Hi guys,.

    I have a few questions on RV110W.

    I would like to install wifi on my local network access, I have gateway with wan, web filtering etc. etc.. I just want a good wifi access point.

    So why I want to equip with a RV110W and not a normal access point? It's just my boss want mandatory limitation of the internet access of planning by hours, days ~ ~ and guest access. Another detail, my local network have not all dhcp.

    So, in the first place. Can I plug my lan rj45 on switch of RV110W port for internet by my current gateway?

    If I set the limitation of the internet, has done this job of feature on switch port wireless access?

    If I put the dhcp on RV110W (for example 192.X.X.5 to 192.X.X.10) and I identify the ip address on my other gateway for internet access (filtering fortigate), can I put the dhcp on RV110W only on wifi or it will assign ip on other devices on my LAN?

    Thank you very much!

    Hi Ash, you can connect the RV110W by a switch port to another router.

    Dhcp RV110W is not customizable to the point where you can specific to your other router IP of the gateway.

    If active RV110W dhcp would provide DHCP what accept DHCP.

    You may want to look into WAP121 or WAP321.

    -Tom
    Please mark replied messages useful

  • Unique to the multiple SSID and possible access point single channel?

    Hello world.

    I have a silly question.

    Let say, we have three VLAN, vlan1, 2, 3 and they are mapped to the following wireless LANs:

    VLAN 1 ssid1

    VLAN 2 ssid2

    Vlan3 ssid 3

    AP - trunk - dagprogramm network.

    Our access point has mobile devices in three local wireless networks, IE ssid1ssid2 and ssid3

    Since the mode AP use half duplex, mobile devices need acknowledgement positive to ap they can send data, so once channel let channel 3 (assuming that 802. 11b is used) can be shared by all the devices in three local wireless networks.

    My understanding is correct?

    Thanks and a great weekend.

    An access point = an associated action related channel and each ssid and the customer that one channel and the AP is essentially as a hub

    concerning

    Joe

Maybe you are looking for