WLC management port is another trunk that vlan native

Hello

I installed my first WLC 5508 with this topology:

WLC connected trought distribution SFP 1 GB port to the port of switch configured as a Trunk port cut 3 Wireless VLAN:

-Management WLC, wireless and wireless voice data Vlan (Vlan native is WLAN Management).

-J' created 2 dynamic interface on WLC on my VLAN Wireless:

10.7.1.0/24: default management Virtual Interface installing WLC +.

10.7.6.0/24: Virtual Interface of voice and

10.7.2.0/24: Wireless Data Interface virtual trought GUI.

DHCP configured on each dynamic interface is the interface vlan L3 subent for SWITCH main technical IP DHCP Pool equal VLAN.

WLC management interface IP address is: 10.7.1.10/24

I create 2 WLAN SSID name with given ID 1, and ID2 voice.

I create and AP group named APGRP1 that contains the AP recorded about WLC and using the two WLAN SSID.

The two AP are connected to the switch acess port configured as native management WLC VLAN access port.

I have to create 3 IP DHCP pool on main switch with the related L3 Interfaces for Inter VLAN routing.

Problem: when I try to connect from mobile data SSID I get IP address of management WLC VLAN a VLAN data no.

the same case of Wireless IP Phone configured with voice SSID.

What I can likely that allows two devices to get the address IP of the correct VLAN?

Thnks

Hi Adil,

T1 > coelio AP on the switch must be configured on a mode of access to the port or trunk mode?

YEARS - the LWAPP / CAPWAP APs connected to the switchport should be an access port not trunk.

Q2 > if the first case, the configuration of the port, on the same VLAN as WLC management VLAN support Vlans other WLANS (voice and data)?

YEARS - Yes it supports, since traffic that involes the WLAN will be inside the tunnel of logic LWAPP/CAPWAP.

Q3 > I will check the interface between WLAN and dynamic Interfaces map and I'll tell you.

YEARS - I will wait for your answer!

Let me know if that answers your question...

Concerning
Surendra
====
Please do not forget to note positions that answered your question and mark as answer or was useful

Tags: Cisco Wireless

Similar Questions

  • PowerConnect 5448, how all the trunk of physical ports and allow all the VLAN tags to pass transparently

    I would like to achieve such a goal, do all acts of switch ports 5448 as 'trunk', that is, just as an entry-level switch. Yes, I want all the tags VLAN through seamlessly.

    Let me explain more clearly. If

    • With MAC1 PC1 is connected to switch port 1 (port 1) in short, PC2 with MAC2 is connected to port 2.
    • PC1 sends a packet with vlanid = 30 ethernet VLAN tag,.

    I want the ethernet packet must be SENT to port 2 without modification, i.e. 2 PC will receive the package with exactly the same byte packets that PC1 sends.

    Currently, I want to configure all ports from the switch to act like this, but how to do this? Can someone tell me the more concise CLI commands to achieve? Alternatively, it is possible via the web interface?

    I must again complain the poor manual, which talks about this concept and this notion over and over again (both of ambiguous statements that the author of manual does not), BUT doesn't explain them not at the level of the content of the packages, so I'm totally at a loss.

    I tried the web interface. Simply together port 1 and 2 for access mode or general mode does not work.

    Please help me. Thank you in advance.

    Thank you, Josh, you begin to point me in the right direction.

    Now, I know just affecting a Trunk port, or general mode is NOT sufficient.  I have to give what kind of package VLAN (i.e. what VLAN ID) are allowed to pass through.

    To do this assignment, I have to take 2 steps. say first of all, the database "vlan" to recognize a VLAN ID in the world, then say that some specific port is allowed to pass through with this VLAN ID specific packages.

    Thus, in order to pass packets VLAN with VLAN ID 18-25 no modified (marked packets in packages marked on) g7 to the g8 to port port, I have to do:

    Console # config
    Console (config) # vlan database
    Console(config-VLAN) # vlan 18-25
    Console(config-VLAN) # exit

    Console (config) # interface ethernet g7
    Console # switchport general mode
    Console # switchport General allowed vlan add the tag of 18-25

    and again for the g8. And if I want to 48 ports to act like that, I have to write this kind of order 48 times right? All the shortcuts?

    Some useful links for me: http://hasanmansur.com/2012/10/14/powerconnect-switchport-modes/

  • Question of VLAN native of UCS

    All,

    I have a problem that I can not just wrap my mind autour.  We have UCS setup in a lab with 2 interconnections connected to 2 nexus switches 5510.  The nexus switches are passed to the network via a Switch 4900 m.  All circuits are configured and tested as functional. All routing is configured and confirmed.  I have a problem in UCS, which is confusing to me.  In the lab, I kept the VLAN native to the vlan1.  I have the Setup VLAN 2-10 on all switches test and interconnections.  I created a service profile that contains 1 network card and placed it in the VLAN 7.  I installed Windows 2008 on a blade using this service profile.  In the operating system I statically IP'ed the NIC for the schema used in VLAN 7.  The OS, I cannot ping another device located in the vlan 7.  Also, I can't ping a host on a different VLAN.  If I place a check on the VLAN 1 as the vlan native I still cannot ping anything.  If I place the audit for vlan native to vlan 7 I can ping hosts in the same vlan, as well as outside of the vlan.  So why should I place vlan 7 as the vlan native when all my boxes are set up in the vlan 1 is the vlan native?

    Thanks for any help,

    Ken

    Ken,

    When you allow some VLANs on your Service vNIC profile you will need to set the VLAN native. This is because the way you have configured currently you are only "allowing VLAN 15', but you're not marking it.   It will work fine for ESX or Linux which allows to assign the dot1q tag to the host.  With Windows unless you have specific drivers doing the marking for you, you will need to do it at the level of the vNIC in UCS.

    Two ways to see this in action.  When you create a service profile in the 'Basic' - not 'Expert' method, you will need to choose a single VLAN for your interfaces.  This will treat interfaces about like an "access Port".  Conversely, when you use the "Expert mode you select the vNIC as a trunk, in which you" will allow to "all VLAN you acceding them as to, like this is the method you did.»

    For a Windows operating system, set the VLAN natively for the VLAN you want to access and you'll be gentle.  Unchecking this option button that "VLAN native" is allowing traffic to cross out of UCS on the VLAN native VLAN 1, your network - it is therefore MAC appears on other fabric under VLAN1

    Kind regards

    Robert

  • Dynamic management of the mobile AP management interface to another dynamic interface (WLC 2504)

    Situation/configuration is the following:

    -2504 WLC (8.1.131) with a total of 22 AP is connected.

    -Several WLAN active each with its own interface (dynamic)

    -L' (static) management interface is the option "Activate the dynamic management of AP" enabled.

    -The four physical interfaces of the WLC remain TROLLING configured.

    What is the problem:

    In the current configuration, the management interface is in the same vlan as the AP we now want to move the management interface to a different VLAN, but keep the AP in the vlan current. The idea is to move the management interface to its new vlan and disable "enable dynamic management of AP". Then, create a new interface (dynamic) in the same vlan as of AP and select 'turn on the dynamic management of AP' on this interface. Configure it as it is no problem but is does not work. The AP will record is no longer with the WLC.

    Is there something I may be missing why this does not work?

    Richard.

    Yes, that's the gist of it.

    I recommend always making a capture packets if only just for educational purposes and to see how this works in action. I found it interesting when I did in the lab here.

  • Catch 22 - Port Trunk Configurations: how to combine identifiers VLAN native with DHCP (but allows traffic of VM)

    Catch 22 - Port Network Configurations: how to combine identifiers VLAN native with DHCP (but allow the virtual computer)

    I came across a Catch 22.  Maybe someone can restore the directly here.  I found a "witch hunt" for sure.

    It comes with the Ports of junction on the side of the switch of the ESX host network.

    Context:

    Ok. The Setup is a HP Blade C7000 enclosure.  I try to configure ports for switching to the blades.  ESX 3.5 U4 will be installed the BL460cs.  Installation is preferred method: revive unattended.  No problem with the syntax of Kick-Start,

    I am here, it's the side network.

    The problem:

    I find a major complication in that the switch ports must be configured for both traffic Service Console and VMkernel, more Virtual Machine since only two NICs by blade. Not best practices, but we have only two switches Cisco 3020 inside.  The two uplink physical NIC is paired in the same vSwitch.  (No iSCSI does fortunately).

    So the Catch 22 question is as follows:

    If the id VLAN native set up on the switch port, DHCP works of course and the VMware boot loader is able to grasp a binary / packets on the network (FTP Site) and install OK.  But after no installation, no communication with SC unless I set the VLAN id of the SC to '0 '.  The value "4" 0 does not communication, but "40" is the VLAN native.

    If id configuring VLAN native retired from the Switch port, DHCP will not work and host does not have IP address during the VMware boot process.  This is as expected as traffic without label is not assigned an eligible

    VLAN, so no comms.

    The Port of the Switch configuration:

    interface GigabitEthernet0/16

    SERVERNAME description

    switchport trunk encapsulation dot1q

    switchport trunk vlan native 40

    switchport trunk allowed vlan 40-254

    switchport mode trunk

    switchport nonegotiate

    Speed 1000

    No cdp enable

    spanning tree portfast trunk

    end

    Summary

    OK, let's summarize where things are and if possible please attach responses to their digital identity.

    (1) is there a way to delete the VLAN tagging altogether side ESX host? Not only the id '0 '. The problem is with clearly with the VLAN native defined as "40".  If "40" IDs specified on the Group of ports for the Service Console, no joy, no comms. If the id of '0' value, capable of ping gateway and communicate on the network.

    (2) what is the problem with the definition of VLAN native as "40" when the config for the switch port is set as VLAN native "40"?  Or if it was a problem?  Both parameters clearly do not work together.

    (3) a switch receiving a unmarked frame it will assign to the VLAN Trunk native. Ok. Trunking bases and why I need a VLAN specified on the port for DHCP native work.  But it seems that since the id VLAN is set manually even as VLAN native, closed communications and no traffic as possible.

    (4) executives made tag 802. 1 q VLAN native?  I think that it is not and this could well be the problem. Since the id VLAN "40" is not labeled, but try to score the side host vSwitch port group.

    Please let me know your thoughts, community and how in general, we are approaching 2 NIC ESX configurations.

    When trunking multiple VLANs, you either have a default VLAN is nothing is tagged, or you don't.  That's what the vlan native to you, it defines which VLAN would be used if no tag is visible on the packets traversing the network.  For servers, if you are marking, then everything has to tag, if you're not marking at the server level, then the port must be either an access port or a VLAN native or default must be set.  I also don't keep your service console the same network as your vm.  Keep this isolated for the security of the network.  If you isolate this VLAN, you can separate and use a single IP address for installation and one for post construction.

    Or, you can provide an IP address during the build.

    -KjB

    VMware vExpert

  • When I try to scan with my CanoScan N640P ex scanner I receive a message indicating the Port to the printer that is used by another device. How can I work around this problem?

    When I try to scan with my CanoScan N640P ex scanner I receive a message indicating the Port to the printer that is used by another device.  How can I work around this problem?

    Hi ejp70,

    1. did you of recent changes on the computer?

    2. to when was the last time the scanner was working fine?

    3. you have any other printer\scanner connected to the computer?

    If you have any other printer\scanner connected to the computer, disconnect them and check if it works.

    I suggest that you uninstall and reinstall the scanner to the computer, also make sure that you install the latest drivers for scanner on Canon website.

  • If vlan native between Trunk ports not configured so what happens?

    I have a network where two ports of junction are allowed vlan 9 but not native VLANs configured. will be affect performance?

    by default the vlan1 is configure the vlan native to assign a vlan on the interface different native

    switchport trunk vlan native xxx

    HTH

    Richard

  • WLC service port

    Hi, someone has tried to use the service port WLC as a management port vlan and routed as well.

    Thnak you

    You have to, and you should also make sure there is no communication between the managememnt / interface ap - manager and the service port. If there is, you will have problems and that's why I never connect the service on the network port. If your direction is down... most likely your wlc is down also.

  • change of access port blocking another port

    Hello

    This is my first post here. I recently branch for a laboratory at home switch a sg300-10. I enabled couche3 routing on it and have encountered a strange problem. The switch is the default gw on this network, and in front of the switch, it is a cable modem)

    IP route 0.0.0.0 0.0.0.0 192.168.0.7).

    This is my config:

    config-file-header

    switch5ed948

    v1.2.7.76 / R750_NIK_1_2_584_002

    CLI v1.0

    SSD of encrypted file indicator

    @

    SSD-control-start

    config of SSD

    control of password file unrestricted SSD

    no control of the integrity of the file ssd

    SSD-control-end cb0a3fdb1f3a1af4e4430033719968c0

    !

    database of VLAN

    VLAN 10

    output

    Add a voice vlan Yes-table 0001e3 Siemens_AG_phone___

    Add a voice vlan Yes-table 00036 b Cisco_phone___

    Add a voice vlan Yes-table 00096e Avaya___

    Add a voice vlan Yes-table 000fe2 H3C_Aolynk___

    Add a voice vlan Yes-table 0060 b 9 Philips_and_NEC_AG_phone

    Add a voice vlan Yes-table 00d01e Pingtel_phone___

    VLAN voice Yes-table add Polycom/Veritel_phone___ 00e075

    Add a voice vlan Yes-table 00e0bb 3Com_phone___

    IP address of 192.168.0.120 dhcp relay

    activate a dhcp IP Relay

    Info IP dhcp option

    No Hello activation

    hostname switch5ed948

    No complexity of passwords allow

    ID password cisco

    Server SNMP Server

    clock timezone "" 1

    summer time clock web recurring EU

    unicast SNTP client enable

    unicast SNTP client survey

    192.168.0.120 SNTP server

    The telnet server IP

    !

    interface vlan 1

    no ip address dhcp

    activate a dhcp IP Relay

    !

    interface vlan 10

    name of LOM

    IP address 192.168.10.254 255.255.255.0

    activate a dhcp IP Relay

    !

    interface gigabitethernet7

    switchport mode access

    !

    interface gigabitethernet8

    switchport mode access

    switchport access vlan 10

    !

    IP route 0.0.0.0 0.0.0.0 192.168.0.7

    Pretty simple. About gi7 gi8 I want to configure 2 interfaces (lights out management) of LOM 2 devices in vlan 10.

    When I enable the vlan 10 on gi7, I lose network connectivity to devices behind IG5 which is a trunk port vlan 1. Very strange

    So, I just want to use 2 ports such as access on a non-standard VLAN ports. These ports should not be ports trunk/general, simple access to the ports.

    What I'm doing wrong here?

    TIA,

    Natxo

    Natxo, that's how it takes work.

    interface vlan 1

    IP 192.168.0.254 255.255.255.0

    interface vlan 10

    IP address 192.168.10.254 255.255.255.0

    --------------------------

    Host A is located in a port which is a member of the vlan 1. A NIC host configuration should be--

    IP 192.168.0.x

    Mask 255.255.255.0

    Gateway 192.168.0.254

    Host B is located in a port which is a member of the vlan 10. B NIC host configuration should be--

    192.168.10.x intellectual property

    Mask 255.255.255.0

    Gateway 192.168.10.254

    ----------------------------

    Now, if the host A and B are both capable to respond to ICMP, while there should be no problem to ping any direction. Also, make sure that if either of these computers have access to turn off wireless.

    -Tom
    Please mark replied messages useful

  • Traffic on the management ports load

    Can someone tell me what traffic is running on the management port?  I install vsphere 5.1 with 3 hosts, vmotion and san iscsi drive. I intend to separate management traffic on a closed network of 1 GB in which the management ports will connect to a 1 GB switch which will have a port connected to the global network.  Use VMotion cela this port strongly with its activities?

    The cluster will be slightly loaded with only 8 to 10 vm across all 3 four hosts of Quad Core processor.

    I intend to connect with NICs 10Gb iscsi san and dedicated switch.

    If I had to, I could use a 10G switch to the management network.

    The individual virtual machine will be nic interfaces 1 Gb individual key of the network if necessary.

    If you could tell me the documents that would also be appreceiated.

    any thoughts would be appreciated.

    Thank you

    Ken

    "Best Practice" is said to have a network card dedicated to the management, and a dedicated for vmotion. Ideally different subnets / VLAN.

    In smaller environments, but I often will create this:

    vSwitch0 with 2 network cards (if everything goes well on the cards separated/asics) and with the management and vmotion vmkernel port. It works very well, thank you very much despite sometimes described as not "best practices." Well - I think that the concern is that in situations of heavy vmotion (especially when storage vmotion is concerned) traffic management could be hampered/flooded. I just never saw him in the real world, although in environments with more than 4-5 guests I always put in place in accordance with the "best practices" just because...

    vswitch 1 with 2 maps, 2 vmkernel ports (each with its own ip address) for iSCSI

    vswitch 2 with 2 (or more) network cards and however many ports of VM / VLANS are necessary.

    (just to be clear, the 'best practice' would vswitch 0 with 2 network cards and 2 vmkernel ports that configured in the management and the other as vmotion.) Each nic will be dedicated to a vmkernel, but available failover for others...)

  • Port is too long that the process that runs on there

    Platforms: 11.2.0.3 on AIX/Linux/Solaris

    This is a question about how software Oracle maintains sessions client connected after that the listener is stopped with elegance


    Scenario of
    =========
    You have a DB and its listener running on the DB server. The listener runs on port 3278.
    From your laptop, you start a sqlplus session to through the listener. After the session must be connected to the laptop. The process of listening to the DB server is reduced. But sql * more session connected to the laptop can still issue queries and get the results.sqlplus session is still connected to the DB via port 3728, even if the listener is down. ESTABLISHED for that port displays the following output of netstat on the Server DB (10.80.0.213)
    $ netstat -an | grep 3728
    10.80.0.213.3728   192.168.0.101.59001  17520    881 49640      0 ESTABLISHED
    A TCP/IP Port exists only when the process that runs / plays on it is. Right? Thus, after the listener is brought back is there another process that maintains this port so that the client session is served with what he needs the DB?

    As far as I KNOW, none of the two processes can share a port. Unless there is a mechanism in the listener that calls the port to another process, when it is worn down.

    Hello
    I think that explains very well at a level detailed - the way he manages the ports has changed slightly in the new versions of oracle - lsof does not look like it can in older versions.

    http://packetpushers.NET/SQLNET-a-k-a-Oracle-TNS-and-firewalls/

    See you soon,.
    Harry

  • How do the 4000th Equallogic Installer management ports

    Hello

    We released Equallogic 4000E with two controllers. I would like to connect the management ports on our "management VLANs" society.

    But I don't know if I need two different IP addresses for the two management ports?

    Or I just organize just one IP address for one of the ports management and EQL will take care of the rest? I understand that a single controller is active at a time.

    Appreciate any clarification on this if you have storage EQL.

    Thank you

    But what I don't understand is the number of IP addresses do I organize for the "management interface."

    1 single IP on your network.

    The standby controller will have all the IP when it become active (and the other become Eve).

    André

  • ESXi 3.5 - Management Port now a Vmkernel Port

    I built my first box of ESXi 3.5.  Wow I love the installation.  Had a working server complete in less than 15 min from start at once, as it was in the CR 2.5.  After installation, I noticed when I went to add a new vswitch so that at the end of the wizzard I wasn't able to create a port vmkernel on the same subnet as an another port of vmotion vmkernel.  I watched one noticed that vswif (vswitch0) did not have a console port.  The management port has been merged/rolls in a way vmkernel.  I checked a TI has the ability to make a port of vmotion.

    My question is... Is this OK or best practice or not a good idea to use the vswitch hosting the management port to get the vmotion traffic using ESXi?

    Pete

    Hello

    Transferred to ESXi forum.

    My question is... Is this OK or best practice or not a good idea to use the vswitch hosting the management port to get the vmotion traffic using ESXi?

    I would treat the management port just like you would treat any network management, keep it separate. However, most people combine VMotion and management on the same vSwitch.  In general from a security perspective, the management is separated from VMotion. VMotion is a clear text Protocol, so access to it should be restricted to JUST ESX hosts.

    If it was me, I create an another vmkernel for VMotion on a different subnet, and give it it's own Teddy.

    Best regards

    Edward L. Haletky

    VMware communities user moderator

    ====

    Author of the book "VMWare ESX Server in the enterprise: planning and securing virtualization servers, Copyright 2008 Pearson Education.»

    Blue gears and SearchVMware Pro Articles: http://www.astroarch.com/wiki/index.php/Blog_Roll

    Security Virtualization top of page links: http://www.astroarch.com/wiki/index.php/Top_Virtualization_Security_Links

  • Firefox does not start because he says that it's another instance that runs in the background, but I checked and it is not a!

    Firefox does not start because he says that it's another instance that runs in the background, but I checked and it is not a! I have Linux Fedora 15 and I'm not the root. I spoke to the Manager and he said I should delete a file in the folder where firefox is installed and which can solve the problem. Can you help me?

    Thanks, Marius
    

    Upgrade your browser Firefox 8 and check

  • How do I remove, rename, or move files or folders in another program, that I can't find?

    Im running Windows 7 Ultimate edition. What should I do to solve this problem: too often, when I try to delete, rename or move a file/s or folder/s so on my desktop, documents, library, or anywhere with a typical, it should create a custom folder, I get an error message telling me that I can not remove this file or folder because it is open in another program. It drives me crazy because I don't know what the heck, or when the devil this folder doesn't exist anywhere else on my laptop. I tried to look for programs and files to determine if there are duplicate areas where the file can share with another path, but nothing. I also looked at the properties of the file/folder, but it does show me nothing relevant, even if I uncheck the read-only box. I am the only user/administrator of my laptop. I created a profile of the privileged administrator I use only, nothing else. I run a home network with 5 computers and treat various problems in the past, but this problem started recently, after I upgraded my network of Windstream modem 4220 + linksys wrt600n to Windstream wireless all-in-one router. The new router was a piece of * so I've not unhooked it and reiinstalled my original Windstream modem 4220 + linksys wrt600n devices. I had a few problems, but everything is now back to how it was. I can only think that this may have something to do with the share on the network? Correct me if I'm wrong (please), but there seems to be too many titles listed under users? It's whats listed under users: administrator, Classic .NET AppPool, default, default AppPool, (my username) and Public. In any case, please help % @#! I think I may be fubar had my network configuration after uninstallation and reinstallation of the windstream (local phone/internet provider) facilities and added a printer wireless capability (which does not). and may have caused the problem that I can't delete, rename or move files or folders in another program, that I can't find? If yes or else, HELP!

    When you have the problem that happens, open the Task Manager.
    Then, you can view the processes that are open and see if the program or file is open by another process. If so, then select end task.
    Then return to Windows Explorer and see if you can remove the file now.

    You may also be able to delete the file in Mode without failure.
    To access Safe Mode:
    (a) restart your computer and start pressing F8 on your keyboard. On a computer that is configured to start to multiple operating systems, you can press the F8 key when the Boot Menu appears.
    (b) select an option when the Windows Advanced Options menu appears, and press ENTER.
    (c) when the boot menu appears again, and the words "Safe Mode" appear in blue at the bottom, select the installation that you want to start, and then press ENTER.

    If you run a Web server, you can see the AppPool under users.

    An application pool is a group of one or more URLS served by a worker process or a set of worker processes. Application pools define limits for the applications they contain, which means that all the applications that are running outside of a given application pool does not affect applications in the application pool.

    Hope this has helped answer your questions.

    Thank you!

Maybe you are looking for