<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall blocking lightweight access points? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-blocking-lightweight-access-points/m-p/1237906#M860168</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I appreciate any assistance as sometimes we tend to overthink the obvious. We opened the firewall for IP from 10.0.0.0 /8 to each Ap's ip that should cover those 2 ports.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 05 May 2009 14:26:16 GMT</pubDate>
    <dc:creator>vancamt76</dc:creator>
    <dc:date>2009-05-05T14:26:16Z</dc:date>
    <item>
      <title>Firewall blocking lightweight access points?</title>
      <link>https://community.cisco.com/t5/network-security/firewall-blocking-lightweight-access-points/m-p/1237904#M860162</link>
      <description>&lt;P&gt;I have 3 access points that I recently converted to LWAPP. After the conversion, all 3 AP's are now MIA - no sign of them in WCS or on any of our controllers. I can trace them back to the switch that they are directly connected to and they do pull a DHCP address. I found this on the firewall: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May 04 2009 16:39:58: %ASA-7-710005: UDP request discarded from &amp;lt;AP's ip&amp;gt;/26586 to inside:255.255.255.255/12223 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am wondering if there is something on the firewall that is blocking the requests from the AP's to join the controller. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:27:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-blocking-lightweight-access-points/m-p/1237904#M860162</guid>
      <dc:creator>vancamt76</dc:creator>
      <dc:date>2019-03-11T15:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall blocking lightweight access points?</title>
      <link>https://community.cisco.com/t5/network-security/firewall-blocking-lightweight-access-points/m-p/1237905#M860164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;When you turn on a LWAAP AP, he start descovering a DHCP server to get a an IP Address,and TFTP server to get his configuration. the LWAAP tunnel use some UDP port, and I think that you should allow them in your firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A. Follow these guidelines when you use CAPWAP:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your firewall is currently configured to allow traffic only from access points that use LWAPP, you must change the rules of the firewall to allow traffic from access points that use CAPWAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure that the CAPWAP UDP ports 5246 and 5247 (similar to the LWAPP UDP ports 12222 and 12223) are enabled and are not blocked by an intermediate device that could prevent an access point from joining the controller.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If access control lists (ACLs) are in the control path between the controller and its access points, you need to open new protocol ports to prevent access points from being stranded.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;more info: &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6366/products_qanda_item09186a008064a991.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6366/products_qanda_item09186a008064a991.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it's useful,&lt;/P&gt;&lt;P&gt;from a Future CCSP&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:j.reda7@gmail.com"&gt;j.reda7@gmail.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Reda&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 May 2009 08:56:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-blocking-lightweight-access-points/m-p/1237905#M860164</guid>
      <dc:creator>rjaaouan</dc:creator>
      <dc:date>2009-05-05T08:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall blocking lightweight access points?</title>
      <link>https://community.cisco.com/t5/network-security/firewall-blocking-lightweight-access-points/m-p/1237906#M860168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I appreciate any assistance as sometimes we tend to overthink the obvious. We opened the firewall for IP from 10.0.0.0 /8 to each Ap's ip that should cover those 2 ports.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 May 2009 14:26:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-blocking-lightweight-access-points/m-p/1237906#M860168</guid>
      <dc:creator>vancamt76</dc:creator>
      <dc:date>2009-05-05T14:26:16Z</dc:date>
    </item>
  </channel>
</rss>

