<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco 5505 and single access point. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-5505-and-single-access-point/m-p/2369851#M310149</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The AP has 1 physical port so obviously this will be trunked and so will the port on the ASA. I do have the secuirty plus license. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see in the config below. the actual physical IP address of the inside network is 192.168.70.254 ( port 7 facing the AP vlan 1 ) i can provide DHCP range to an interface. how do i guest the guest network to work on the ASA? and set an IP range to this network? hope this make sense?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt; switchport trunk allowed vlan 1,10&lt;/P&gt;&lt;P&gt; switchport trunk native vlan 1&lt;/P&gt;&lt;P&gt; switchport mode trunk&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.70.254 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address *****&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 29 Oct 2013 11:40:02 GMT</pubDate>
    <dc:creator>James Hoggard</dc:creator>
    <dc:date>2013-10-29T11:40:02Z</dc:date>
    <item>
      <title>Cisco 5505 and single access point.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5505-and-single-access-point/m-p/2369849#M310144</link>
      <description>&lt;P&gt;I have a Cisco 5505 and have an access point plugged into the POE port 7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 SSID'S on the access point &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 1 - production on the 192.168.70.0 /24&lt;/P&gt;&lt;P&gt;vlan 10 - guest&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.0.0 /24 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not have a&amp;nbsp; seperate DHCP sever so the ASA will have to act as the DHCP server for both vlans.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need the guest network just to have access to the internet nothing else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can this be done?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also have the option of using IPSEC to a site which has a windows DHCP server if this helps?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:57:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5505-and-single-access-point/m-p/2369849#M310144</guid>
      <dc:creator>James Hoggard</dc:creator>
      <dc:date>2019-03-12T02:57:16Z</dc:date>
    </item>
    <item>
      <title>Cisco 5505 and single access point.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5505-and-single-access-point/m-p/2369850#M310146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess you would have to configure a Trunk between the standalone AP and the ASA5505. And to support Trunking your ASA5505 would have to have Security Plus license if I dont remember wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you could Trunk the 2 Vlans from AP to the ASA and configure separate DHCP pool for them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sadly I never even touch Wireless networks/devices in my work (other people for that) so I dont what your different options there are. I just imagine that if your ASA5505 is running Base License and you cannot trunk and IF your AP had 2 physical ports then you could do around the Trunking limitation of your ASA by configuring Access Mode ports for each Vlan on the ASA and connecting 2 separate ports from the AP to those ASA ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Allowing only Internet access for the other WLAN should be possible with simple access rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The DHCP through L2L VPN might be an option but its surely more complicated to set up.&amp;nbsp; If you had a Cisco router at the local site you could even use it as DHCP server. I am not sure if APs have this possibility? As I said I dont know the first thing about configuring Wireless networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 10:52:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5505-and-single-access-point/m-p/2369850#M310146</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-29T10:52:54Z</dc:date>
    </item>
    <item>
      <title>Cisco 5505 and single access point.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5505-and-single-access-point/m-p/2369851#M310149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The AP has 1 physical port so obviously this will be trunked and so will the port on the ASA. I do have the secuirty plus license. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see in the config below. the actual physical IP address of the inside network is 192.168.70.254 ( port 7 facing the AP vlan 1 ) i can provide DHCP range to an interface. how do i guest the guest network to work on the ASA? and set an IP range to this network? hope this make sense?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt; switchport trunk allowed vlan 1,10&lt;/P&gt;&lt;P&gt; switchport trunk native vlan 1&lt;/P&gt;&lt;P&gt; switchport mode trunk&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.70.254 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address *****&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 11:40:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5505-and-single-access-point/m-p/2369851#M310149</guid>
      <dc:creator>James Hoggard</dc:creator>
      <dc:date>2013-10-29T11:40:02Z</dc:date>
    </item>
    <item>
      <title>Cisco 5505 and single access point.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5505-and-single-access-point/m-p/2369852#M310151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well you would have to add an interface for the &lt;STRONG&gt;Vlan10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface Vlan10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nameif guest&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; security-level 10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; ip address 172.16.0.x 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;dhcpd address 172.16.0.a-172.16.0.b guest&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;dhcpd dns &lt;DNS1&gt; &lt;DNS2&gt; guest&lt;/DNS2&gt;&lt;/DNS1&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;dhcpd enable guest&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And you would naturally need some additional configurations like interface ACL and NAT configuration depending on your needs and current configurations&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 11:54:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5505-and-single-access-point/m-p/2369852#M310151</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-29T11:54:46Z</dc:date>
    </item>
    <item>
      <title>Cisco 5505 and single access point.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5505-and-single-access-point/m-p/2369853#M310153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorted this. thanks for you help anyway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 12:03:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5505-and-single-access-point/m-p/2369853#M310153</guid>
      <dc:creator>James Hoggard</dc:creator>
      <dc:date>2013-10-29T12:03:58Z</dc:date>
    </item>
    <item>
      <title>Cisco 5505 and single access point.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-5505-and-single-access-point/m-p/2369854#M310156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good to hear. Was there a problem with some configuration or were you missing some of the above configurations for example?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If any reply answered your question please do remember to mark the reply as the correct answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 12:06:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-5505-and-single-access-point/m-p/2369854#M310156</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-29T12:06:07Z</dc:date>
    </item>
  </channel>
</rss>

