Correct configuration of the Cisco Access Point 1242AG

Hi all

Here's the situation:

Recently, we decided to create a small network of WLAN in our company. We choose the Cisco AIR-AP1242AG-E-K9 with 2x2.4GHz 2.2dbi rotating dipole antenna.

For better management, a new VLAN routable (ID:20) added to our router IP 192.168.55.1 and SNET 255.255.255.0

Then, I made the following configurations in the autonomous AP through WEB Console:

  • Static IP:192.20.10.35, SNET:255.255.254.0, GWY:192.20.10.200
  • Vlan1 (native) and VLAN20 (Radio0 - 802.11 g) added in Services.
  • I put the encryption against zero for VLAN1 Mode and cipher AES-CCMP for VLAN20
  • In Server Manager, I've defined a new 192.20.10.35 RADIUS server (AP-IP) and a secret shared and left the default ports for authentication and accounting (1645 and 1646). Also, in the default server priorities section I put focused 1 time for authentication EAP and the IP (Radius Server) 192.20.10.35 Access Point MAC.
  • During the General local RADIUS server configuration, I add as a server for access to the network current (AAA client) the same IP address and the shared secret as the ones I use during the configuration of the RADIUS server above. In authentication protocols enable I left checked only the JUMP and the Mac. In addition, in the users individual section 2 new users created with passwords.
  • In the SSID Manager a new hidden SSID created for interface Radio0 - 802.11 g, associated with VLAN20 and in the Client authentication settings section, I left as accepted authentication open with MAC and EAP authentication method. Also, I left the option to use by default for EAP and MAC authentication servers in Server priorities Section and finally I choose mandatory for key management in the section Client authenticated and active the option enable WPA key management.

I can ping VLAN20 IPs from any PC which is a member of the VLAN native both AP

As wireless clients, I use 2 Motorola MC5574 with Windows Mobile 6.1 professional. Both of them have a WLAN Jedi adapter that is configured with the following:

IPs:192.168.55.10 and 192.168.55.11

SNET:255.255.255.0

GWY:192.168.55.1

In addition, a unique profile has been created on all of them to use for the authentication of the association AP. Each profile has been configured for WPA2-Enterprise with AES and LEAP and identification information predefined user (those defined in the PA for individual users)

The problem:

Association of clients with AP is always successful but, authentication fails, and I can't ping the AP IP, IP VLAN20, nor the other customers.

What I'm missing here? I'm sure it's quite simple somenthing but although I tried several different configurations (even WPA - PSK, WPA2-PSK with TKIP) I always find myself without an appropriate solution to unable to ping.

Thanks in advance for any help

Hello

Can you please paste the show run out of AP?

Kind regards

Madhuri

Tags: Cisco Wireless

Similar Questions

  • Droid Turbo could not connect the Cisco access point

    Greetings.

    Since the upgrade to a droid turbo, I was unable to connect to the network without wire of my work. I work in the it Department, but my experience with Cisco technologies and wireless is limited, so I tried to understand why. My previous bike x worked fine. We have a network of all the access points managed by a controller Cisco 4402 running version 7.0.98 of the BONES. I was able to connect to another wireless network that I could meet outside of work, and I am able to connect to the network of my work if I connect it is unsecured guest SSID. Only connections to our 4 secure networks fail. The controller reports that my phone cannot all simply to authenticate. The controller is configured for WPA2 / AES using a key 284 on the particular network, that I am trying to connect. I entered this key manually both via copy and paste. As far as my phone goes, I only tried to withdraw and time networks like tent to start it in safe mode without success. I read on various forums android that maybe it's a problem related to Kit Kat and this kind of problem has appeared on other handsets from other manufacturers, but nothing definite.

    Any suggestions would be much appreciated.

    -Josh

    Let me direct you to two other discussions here on the Droid Turbo forum and the other from Cisco which may help.

    Unable to connect to company wifi

    https://forums.Motorola.com/posts/af633eb3e4

    DROID WiFi Turbo questions

    https://forums.Motorola.com/posts/06a2f3c5ca

    Connectivity issues with Cisco and Moto X (Gen 2) allowed RMC controllers (probably related)

    https://supportforums.Cisco.com/discussion/12331486/connectivity-issues-Cisco-controllers-and-PMF-enabled-Moto-x-Gen-2

    I hope this helps!

  • "No access to the network" problem in Windows 7 and error message "your computer seems to be correctly configured but the device or resource (DNS SERVER) is not responding."

    Hello, I have a desktop PC and a laptop (DELL Inspiron N-4050).
    I have problem with my internet connection cable which is working fine on my PC, but does not not on my laptop giving an error "no access to the network.

    When I troubleshoot it says "your computer seems to be correctly configured but the device or resource (DNS SERVER) is not responding."
    I said to many technicians of microsoft online response, but they could not solve my problem and said this is my DNS problem and advised me to contact my Internet service provider. Guess it's because of my internet so why it works on my PC not on laptop?

    Yesterday, my ethernet cable pulled out my cell phone and I couldn't connect to the internet more. But on my desktop PC, it works perfectly fine. (I do not use wifi, if this information is also required) I have studied several threads with similar situations, and I have tried different methods to solve the problem to no avail. I did a system restore, but I'm having no luck. Also, I did not of the latest changes with my anti virus software and my LAN card drivers look to date.

    When I remove my cable from the laptop and again connect my cable then it works but only after the PC sat for awhile.
    1.I did flush DNS by typing "ipconfig/flushdns" in the command prompt.
    2. my IP address, DNS, subnet mask etc are set to automatic.
    3.I also added physical address taken from command line giving "ipconfig/all". for the properties of the network driver settings.
    4.I ' installed the drivers to date of 2014 on my laptop.
    5.I did a lot of searching the web, but they do not solve my problem.

    Please help me to solve it.
    I appreciate your help.
    Thank you.

    Hello Hall,

    Please keep us updated on the status of the issue.

    I suggest you to follow the steps in this Microsoft article troubleshooting and check if it helps:

    Error message "your computer seems to be configured correctly, but the device or resource (DNS server) is not responding" in Windows 7

    http://support.Microsoft.com/kb/2779064/en-us

    Hope the helps of information.

    Please reply with the results, in order to help you solve the problem.

    Thank you

  • 4402 wireless controller and the 1130AG access points

    I have a bunch of 1130AG (35) and 1231 points of access. I just bought a controller 4402 so I could handle these much easier access points. I currently have the offline access points, so I could control. With the wireless in the mix controller, that I have to fix these to light mode or can I leave them offline.

    We know not the operating instructions so I can leave them in stand-alone mode. Most of them is in the rafters in our warehuse, and I didn't have to pull of these if I have to. If I can use them offline, how can I do that?

    Thanks much for any info!

    Dave

    Hi Dave,.

    A WLC manages autonomous APs.
    So if you want to centralize the management of your APs through the WLC, you will need to convert it to light and enter them on the WLC.

    To convert the lightweight access points, you can choose between several options:

    1. thanks to a specific upgrade tool that you could install on a PC:
    http://www.Cisco.com/en/us/partner/docs/wireless/access_point/conversion/LWAPP/upgrade/guide/lwapnote.html

    2. [the most evolutionary] by WCS, with a model of migration that could apply to several APs:
    http://www.Cisco.com/en/us/docs/wireless/WCS/7.0/Configuration/Guide/7_0apcfg.html#wp1054876

    3. [not in any book] by the following steps:
    3 (a) download the CEC lwapp recovery image and store it on a TFTP server.
    3 (b) Telnet to the stand-alone PA and issuing the following command:
    Archive Download-sw / overwrite/reload tftp: / // [lwapp recovery image file path]

    As a general recommendation, before to convert the lightweight access points, you can be sure that the wired infrastructure behind is ready to direct them to the WLC for recording.
    It's suggestions explained in the link on the above option #1.

    Hope this helps,

    Fede

    --
    If this helps you or answers to your question if it you please mark it as 'responded' or write it down, if other users can easily find it.

  • Ordered the wrong access point!

    I thought that I had ordered a 1130ag but looks like I ordered a 1131ag LWWAP.

    Please could someone tell me what the difference between a 1130 and 1131. I understand I can load the IOS on the light AP software using a tftp server, but I do not know which exit to load on this subject. 12.3JX, 12.3JA, 12.3JEA, 12.3JEB! can anyone help please? either by the way, I am in the United Kingdom, do not know if this affects image to install. Thank you.

    Hi Paul,.

    This happens all the time, so it shouldn't be a problem :) I'm guessing that you have received this AP - AIR - LAP1131AG - x - K9 LWAPP. When you really wanted this AP - AIR-AP1131G-x-K9 Cisco IOS software. Look at the comparison;

    http://www.Cisco.com/en/us/products/ps6087/products_data_sheet0900aecd801b901c.html

    That being said, you should be good to go with 12.3 (11) JA1.

    To access Cisco Aironet to Cisco IOS version 12.3 Points (11) JA1

    http://www.Cisco.com/en/us/docs/wireless/access_point/iOS/release/notes/b11jar1n.html

    Cisco IOS version 12.3 (11) JA1 supports 32 MB independent platforms. 16 MB platforms and platforms supported by Cisco IOS version 12.3 (8) JA and earlier versions (350, 1100, 1130, 1200 and 1230 access points and access point/bridge 1300 series) are supported by Cisco IOS version 12.3 (8) JEA1.

    Do not install a "JX" (it is a software image support to upgrade and recovery Cisco Lightweight Access Point Protocol (LWAPP));

    These release notes describe features, improvements, and caveats for Cisco IOS release 12.3 (11) JX1.

    Note: This version must be loaded on points of access to the plant or by using the lightweight stand-alone mode upgrade tool. Your access point may become unusable if you install this software without using the upgrade tool.

    http://www.Cisco.com/en/us/docs/wireless/access_point/iOS/release/notes/b311jx1.html

    Returning to standalone Access Point

    http://www.Cisco.com/en/us/products/HW/wireless/ps430/prod_technical_reference09186a00804fc3dc.html#wp161272

    You can convert an access point of the mode light return to autonomous mode by loading a Cisco IOS version that supports stand-alone mode (Cisco IOS release 12.3 (7) JA or earlier version). If the access point is associated with a controller, you can use the controller to load the version of Cisco IOS. If the access point is not associated with a controller, you can load the version of Cisco IOS using TFTP.

    By using a TFTP server to revert to a previous version

    Follow these steps to return mode LWAPP stand-alone mode by loading a version of Cisco IOS using a TFTP server:

    --------------------------------------------------------------------------------

    Step 1 the IP address of the computer on which the server software runs TFTP should range from 10.0.0.2 to 10.0.0.30.

    Step 2 make sure the PC contains the file access point (for example, c1200-k9w7 - tar.122 - 15.JA.tar for a 1200 Series access point) in the TFTP server folder and the TFTP server is activated.

    Step 3 Rename the access point image file in the folder of the TFTP server c1200-k9w7 - tar.default for a series of 1200 point, c1130-k9w7 - tar.default of access for a series of 1130 access point and c1240-k9w7 - tar.default for a series of 1240 access point.

    Step 4 connect the PC to the access point using an Ethernet category 5 cable (CAT5).

    Step 5 disconnect the power to the access point.

    Step 6 push the MODE button and hold the button while you reconnect power to the access point.

    Step 7 hold the MODE button until the status of the LED turns red (approximately 20 to 30 seconds), then release.

    Step 8 wait until restarting access point, as indicated by the LEDs become green followed the status LED flashes green.

    Step 9 after the access point reboots, reconfigure using the GUI or the CLI.

    This doc.

    http://www.Cisco.com/en/us/products/HW/wireless/ps430/prod_technical_reference09186a00804fc3dc.html#wp161272

    I hope this helps!

    Rob

  • Windows 7 wireless emphasizes the connection to the wrong access point

    I use a model of wireless USB Netgear WN111 with Windows 7 64-bit adapter, connect to a D-Link wireless access point.

    Every time I have connect or wake the computer from sleep, he insists on connecting to the wrong access point - it connects to an unsecured Linksys device somewhere within the range.  I then manually connect to the correct access point - my D-Link.

    I went into the network sharing Center > manage the wireless networks and removed the network Linksys of rogue, but it always comes back.

    Any ideas or advice?

    Hello

    I don't know why he keeps picking up the 'rogue' network after that you deleted. My Windows 7 does not behave like that, and my research can reveal a way that I could do. Maybe someone else can tell you why he does. However, as a solution, you can try the following in manage wireless networks...

    1. do not remove the network of thugs, move it to the bottom of the list all the way down.

    2. open the rogue network properties and uncheck the box "connect automatically when this network is in range.

    3. open the properties of your network and check the box "connect automatically when this network is in range.

    4. you can even try to untick "connect to a more preferred network if available" both networks.

    Please mark this as useful or response if applicable.

    Tricky

  • Windows 7 PCs are not connected to the closest access point

    Windows 7 PCs are not connected to the nearest access point.  Any ideas?

    For example:

    We have AP 1 and 2 of the AP for exaple.  They have the same SSID.  AP 2 is further with a bad signal.  AP 1 is closest with an excellent signal.  Why my laptop does not connect to the AP 1?

    You MUST use the same SSID.  I think that you misread my post.

    And Yes, a channel problem is that what I have proposed.  You can try to configure access points using the 3 discrete channels (1, 6 and 11) to minimize any overlapping units to the same channel coverage.
    At least this is the traditional way, we do it, although the automatic selection increases common and 11n 40 Mhz channels (if defined in this way) are also in.

  • How can I reset or fix my router wireless or (lost the ability to connect wirelessly to the internet) access point

    Wireless hub works, other computers are connected

    On a laptop, I lost the ability to connect wirelessly to the internet (message: limited connectivity)

    Recommended by the system solution: reset or repair your access point or wireless router

    How can I do?

    I think that what you aim for is "power cycle".

    To do this, simply unplug the router/access point power adapter. Wait a minute. Then reconnect it.

    Hope this helps

    Post back if necessary

    ___________________

    If this post can help solve your problem, please click the 'Mark as answer' or 'Useful' at the top of this message. Marking a post as answer, or relatively useful, you help others find the answer more quickly.

  • WET11 V2 cannot be connected to the AP (access point) via WiFi

    I am facing following problem.

    Someone at - he advice me please how to solve these problems.

    Purpose:

    1. I want to use internet on TV Sony Bravia. (Bravia has no WiFI. "I have only LAN).

    Environment:

    1 access point (Router) - WiFi > WET11 V2 - LAN > TV (Sony Bravia).

    2. IP address 192.168.1.5 = WET11 (automatically not static)

    BOF WET11 V2 assigned IP address access point.
    I checked the access point access point IP attributed to WET11.

    3 TV IP address is automatically.

    But the IP address is unaffected for television.

    4 WET11 firmware version = V2.05 (Sep 16, 2003)

    Problem:

    1. IP address cannot be assigned for television.

    2 WET11 is not the answer for the command 'ping 192.168.1.5' WiFi access point.

    3. I did ping command when the LAN TV cable has been replaced by the wireless access point LAN cable.

    BR

    Mutt

    It is not advisable to use a 802. 11B wireless bridge on a device such as your streaming media TV. Connection will be very slow and is probably the reason why you have a hard time to connect to your wireless router that's more compatible with it. I suggest using a Wireless N bridge or a multimedia wireless on your TV adapter so that you can fully appreciate the media streaming.

  • Tecra 9100 - unable to connect to the WLan access point

    Hello

    I have a Tecra T9100 with miniPCI WLan. I reinstalled XP Pro and all the drivers (downloaded from the Toshiba site) and I've always had a problem with Wifi:

    I can see all access point (in the windows control panel), but when I click on connect, I received a message that the access point is no more...
    He didn't ask me for the security settings?

    does anyone have an idea?

    Much thanks

    Leclere

    Hello

    To my knowledge the Tecra 9100 was equipped with the wireless LAN standard: 802. 11B mini card PCI ORiNOCO.

    You need to check if the WiFi signal is strong enough for a transmission correctly
    I think that the signal of WLan access points is not strong enough because of the distance.

  • Satellite M70: I can't connect to the WLan access point

    I have several wireless laptops, all work fine - except my M70.
    I use Intel Proset, and he sees the access point, but says "unable to connect" when I try.
    The signal is high (2 meters distance).

    I tried with WEP, WPA and without security. I am absolutely convinced that I entered the right keys.
    The access point is a Belkin Pre - N-, but I tried with a point of access 3Com, with the same problem - my Ipaq, my other PC, and all guests can connect,- but not my Toshiba!
    The wireless card is the standard Intel, with the latest driver from October 2006 intalled.

    Getting desperate...

    Hello

    If you get a signal strong, so I guess that the laptop is already connected to the access point. Or am I wrong?
    On my laptop, the computer WLan small icon appears only if I connected to the Wlan and then I can see the State of the signal.

    However, you suggested to use the Intel Proset utility to configure the WiFi network but on the clean Windows configuration. Have you tested it?

    This question seems very strange to me.
    Sometimes it of not possible to connect the WiFi network because of poor compatibility between the router and wireless network card.
    My router supports Wlan AB mode and my second card for computer laptop support BG.
    That's why I m not able to connect to the Wlan. Maybe it s also your case.

    On my router, I can also put the MAC address filtering. You should check this option on your router.
    But generally it is not easy to say why it happens. You know you should check every single option and if it s not possible so I guess that it s a compatibility issue.

  • LEAP and EAP-FAST in the same access point

    Hello...

    We have an infrastructure based on 1142 APs.  Now, they have set up an SSID with JUMP as an authentication mechanism.

    The infrastructure is not a wireless LAN controller, access points are configured as standalone APs with SSID configured in each of them.

    The mechanism to authenticate the windows with JUMP positions was a little tricky.  We need now to migrate all stations to EAP-FAST, but without loss of JUMP environment during the migration.   You have to configure the APs to serve the two authentication mechanism: LEAP and EAP-FAST.

    Is it possible to have it?

    What should we do about it?

    Thanks in advance...

    For autonomous APs. If you are using:

    Authentication open EAP protocol

    Network EAP-

    It accepts virtually all EAP types, not depends on the radius server to have all active... for example EAP methods, if you are using ACS may the PEAP LEAP EAP-FAST, EAP - TLS at the sametime...

    So no matter what, the customer's server and the RADIUS wireless must match the EAP type configured... any type of EAP, the AP should support it...

  • connect the PC to the dedicated access point

    Hello

    Is in the WLAN network as two configured SSID, one for a printers and another for a PC. It is possible to ping the printer form LAN but not PC WLAN. It is not the ACL set. Is no chance of routing between WLAN on WLC? The firewall is a layer 3 device in the network.

    The controller is 2112 with 7.0.98 version of the software and all APs are in local mode. The network is flat with 16 bit mask.

    The second problem is that on the Wi - Fi network that precedes some AP (1231) are converted to standalone AP mode LAP.
    The network has been added to an another TOWER 1242 with external antenna.
    A PC with WI - Fi wants to connect to the new TOWER even has a bad signal.
    1231 model has only one external antenna and is closer than 1242.
    How do to impose this PC is always connect to 1231, is possible to configure on WLC?

    Kamil

    Hi Kelly,

    1) check on the 'blocking of the peer to peer' option on the configuration of your SSID. You want to disable.

    (2) the customer himself decides where it wants to connect. If she's stupid drivers that make it to connect to an access point not 'best' you can not do much.

    Only things you can do:

    -updated client drivers

    -enable or disable the load balancing across WLC. There is no best setting. Basically load balancing prevents clients to connect to APs that are already occupied. So, if it is currently enabled, maybe your AP 1230 is occupied?

    Nicolas

    ===

    Please note the answers that will help you

  • Configuration of the Cisco ACS 5.3 AnyConnect VPN and management of a Cisco ASA 5500.

    We have configured a Cisco ASA 5505 as a VPN endpoint for one of our user groups.  It works, but it works too well.

    We have a group called XXX we need to have access to the Cisco AnyConnect Client.  We have selected this group of our Active Directory and added to our ACS configuration.  We've also added a group called YYY that will manage the ASA. However, this group has no need to access the VPN.

    We added XXX movies for the elements of the policy of access to the network-> authorization profiles.  We also have a profile of YYY.

    She continues to knock on our default Service rule that says allow all.

    We have also created a default network access rule. for this.

    I am at a loss.  I'm sure I missed a checkbox or something.

    Any help would be really appreciated.

    Dwane

    We use Protocol Management GANYMEDE ASA and Ray for VPN access?

    For administration, you must change the device by default admin access strategy and create a permission policy. Even by the way, you can change the network access by default for vpn access and create a respective policy for that too.

    On the SAA, you must configure Ganymede and Ray both as a server group.

    For the administration, you can set Ganymede as an external authentication under orders aaa Server

    AAA-server protocol Ganymede GANYMEDE +.

    Console HTTP authentication AAA GANYMEDE

    Console Telnet AAA authentication RADIUS LOCAL

    authentication AAA ssh console LOCAL GANYMEDE

    Console to enable AAA authentication RADIUS LOCAL

    For VPN, you must set the authentication radius under the tunnel-group.

    I hope this helps.

    Kind regards

    Jousset

    The rate of useful messages-

  • After running Thinkvantage System Update, unable to connect the wireless access point

    I've recently performed Thinkvantage System update for updating various programs/drivers on my T61p.  I've updated the V5.12 access connections.  In addition to this I was required to update driver V1.52 power management and functionality of the shortcut key for

    V2.10.0002 (two of them were the most recent available).

    After these updates, I can connect is no longer to any access point wireless that worked before this update.  I have tried to reinstall earlier versions of Access Connections, but still couldn't connect to wireless access points.

    ANY help would be appreciated.

    OK, problem solved.  I found that when I ran last weekend system update downloaded and installed an incorrect driver for my wireless hardware.  I installed the correct driver and now the connection to a wireless access point works.

    Certainly, I don't understand how/why not update system would be to download and install an incorrect driver.  VERY FRUSTRANT and TEDIOUS!

Maybe you are looking for

  • FB Messenger notifications

    OK, my notifications for this show on my lockscreen app I like only they but last night I put them do not disturb in the app, but then I decided to turn to not not disturb off the coast and my notifications stopped then appear on my lock screen, how

  • Bluetooth settings lost on the Satellite L850D - 12 p

    I seem to have 'lost' my Bluetooth settings, including the icon at the bottom of the screen.I tried to download a driver, but I'm not sure I have the right pair. I downloaded the driver Package version Realtek Bluetooth filter 12.28.2013.0912 81.5 MB

  • Adapter Wifi G580 is missing

    Hi, I had model g580 name 20150.and uses the operating system windows 7 ultimate 32 bit.when I tried to connect the wifi it showing me a wifi card is missing after I downloaded wifi adpter lenevo site but still it is show result wireless adpater is m

  • My hp C309g printer range fails to align. just changed the ink cartridges. Works on Windows 7.

    has a great. My son worked hard a yuear there to get this printer working... He changed the cartridges of ink a couble of day and now it is not printing.  We tried to realign the heads but it come as "Failed" to align on the screen... Please any sugg

  • Controlling the speed of display photo on Windows Movie Maker

    I did a film of images attached to the audio. I am trying to find a way to control the speed in which images are displayed to go along with the audio. It's for a final project for College. Help, please.