<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication, Wireless and VLans in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/authentication-wireless-and-vlans/m-p/358238#M140694</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK .... we are one step on and I'm probably answering my own questions as I go along ... but worth noting for others maybe.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I now have mandatory wep WORKING &lt;YIPEE&gt; on both vlans. I think I realise my mistake in that I was trying to make wep mandatory for the whole AP and that caused only my first, alphabetically, ssid to be available.&lt;/YIPEE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK - now it's time to lock the beast down a little more. Still open to sugegstions on how one ought to do this better - situation is a standalone AP providing access to a single site which has a need to seperate traffic out and a traditional wired lan is impossible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Feb 2005 09:21:09 GMT</pubDate>
    <dc:creator>dyckhscr</dc:creator>
    <dc:date>2005-02-03T09:21:09Z</dc:date>
    <item>
      <title>Authentication, Wireless and VLans</title>
      <link>https://community.cisco.com/t5/wireless/authentication-wireless-and-vlans/m-p/358232#M140688</link>
      <description>&lt;P&gt;OK, I am stuck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have an Ap1210 that I need to have at least 2 secured vlans running on. I have configured the ssid's and associated them with individual vlans. Also have the bridge-groups defined and the associated sub-interfaces on the Radio and FastEth ports. Oh, and currently authentication is open and guest-mode is disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far so good - if I then configure up a client to access these I have no problem. However, as soon as I try to apply authentication to the individual ssid's or vlans my connection is terminated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I use .......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; encryption key 1 size 128bit 7 xxx transmit-key&lt;/P&gt;&lt;P&gt; encryption mode wep mandatory&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then only the alphabetically first ssid gets access. I have nothing fancy like backend Radius or TACACS servers, but need to lock down the ssid's or vlans in some manner - not so much from each other (the vlans do that nicely enough), but from outside sources.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would really appreciate anybody's help on this - specifically examples of how this has been done would be great. FWIW I have already digested the "Configuring Authentication Types" document but it hasn't helped me.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 17:24:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authentication-wireless-and-vlans/m-p/358232#M140688</guid>
      <dc:creator>dyckhscr</dc:creator>
      <dc:date>2021-07-04T17:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication, Wireless and VLans</title>
      <link>https://community.cisco.com/t5/wireless/authentication-wireless-and-vlans/m-p/358233#M140689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried adding the VLAN ID to your encryption statements?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i.e.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;encryption vlan &lt;VLAN_ID&gt; key 1 size 128bit 7 xxx transmit-key &lt;/VLAN_ID&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its an optional keyword, so i would assume if you didn't add it, and you are trying to use a WEP key on your client to associate to your AP then it will fail as the AP doesn't know which SSID your WEP key is bound to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is correct, then currently you should still be able to associate to the AP if your remove the WEP key from your client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;PD&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Feb 2005 16:33:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authentication-wireless-and-vlans/m-p/358233#M140689</guid>
      <dc:creator>paddyxdoyle</dc:creator>
      <dc:date>2005-02-01T16:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication, Wireless and VLans</title>
      <link>https://community.cisco.com/t5/wireless/authentication-wireless-and-vlans/m-p/358234#M140690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did do that - however from the client end it makes no difference, I still have open access so long as I have the ssid name. I don't even need to enter the key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's my config for the relevant section .... shortened to 40 bits whilst testing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Dot11Radio0&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;no ip route-cache&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;encryption vlan 5 key 1 size 40bit 7 xxx transmit-key&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;encryption vlan 4 key 1 size 40bit 7 xxx transmit-key&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ssid Name1&lt;/P&gt;&lt;P&gt;vlan 5&lt;/P&gt;&lt;P&gt;authentication open&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ssid Name2&lt;/P&gt;&lt;P&gt;vlan 4&lt;/P&gt;&lt;P&gt;authentication open&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the moment I have no WEP enabled just so that I know that isn't confusing the matter. However, as a slight aside, can I have multiple WEP keys and associate them to different ssid's?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is showing up my severe lack of knowledge wth wireless kit but I have asked for training so be gentle with me .....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Feb 2005 11:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authentication-wireless-and-vlans/m-p/358234#M140690</guid>
      <dc:creator>dyckhscr</dc:creator>
      <dc:date>2005-02-02T11:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication, Wireless and VLans</title>
      <link>https://community.cisco.com/t5/wireless/authentication-wireless-and-vlans/m-p/358235#M140691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do I understand you correctly that even if you force the client to look for a "preferred" AP and (manually configured) SSID, that the client will not associate?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;..... and that the same client will associate with the first SSID?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could it actually be that the client is associating, but not getting a DHCP address (or not able to get traffic through the second (not working) VLAN?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version of IOS are you running? What version of client software? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2005 01:03:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authentication-wireless-and-vlans/m-p/358235#M140691</guid>
      <dc:creator>scottmac</dc:creator>
      <dc:date>2005-02-03T01:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication, Wireless and VLans</title>
      <link>https://community.cisco.com/t5/wireless/authentication-wireless-and-vlans/m-p/358236#M140692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt;Do I understand you correctly that even if you &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct - however I am past that now and apols for not having clarified that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic flows on both vlans upto the point where I apply authentication - at this point it goes astray.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I am doing is trying to get one vlan working and then I'll move onto the other - however I can't seem to do that. Putting WEP on and making it mandatory is ok, but beyond that it is either me making a basic mistake (likely as I have little experience here) or something else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IOS is 12.2(13)JA4 and Client is running XP sp2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2005 08:30:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authentication-wireless-and-vlans/m-p/358236#M140692</guid>
      <dc:creator>dyckhscr</dc:creator>
      <dc:date>2005-02-03T08:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication, Wireless and VLans</title>
      <link>https://community.cisco.com/t5/wireless/authentication-wireless-and-vlans/m-p/358237#M140693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Scrap the part about making wep mandatory - even that doesn't seem to be working now ... grrrr. Have applied the encryption vlan x key 1 etc on one vlan but traffic still flows even though I haven't changed the client configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I may be looking at this all wrong but ..... what I want to do is the following.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apply a single mandatory WEP key to the whole AP. To do this I am using .... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int d0&lt;/P&gt;&lt;P&gt;encryption key 1 size x xxx transmit-key&lt;/P&gt;&lt;P&gt;encryption mode wep mandatory&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I want to have authentication on my vlans that is different from the AP WEP and each vlan and using the following ....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;encryption vlan 2 key 1 size x xxx transmit-key&lt;/P&gt;&lt;P&gt;encryption vlan 3 key 1 size x xxx transmit-key&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this not possible? The end result I want is to protect one vlan from the other and from casual snooping from the outside.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2005 08:52:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authentication-wireless-and-vlans/m-p/358237#M140693</guid>
      <dc:creator>dyckhscr</dc:creator>
      <dc:date>2005-02-03T08:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication, Wireless and VLans</title>
      <link>https://community.cisco.com/t5/wireless/authentication-wireless-and-vlans/m-p/358238#M140694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK .... we are one step on and I'm probably answering my own questions as I go along ... but worth noting for others maybe.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I now have mandatory wep WORKING &lt;YIPEE&gt; on both vlans. I think I realise my mistake in that I was trying to make wep mandatory for the whole AP and that caused only my first, alphabetically, ssid to be available.&lt;/YIPEE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK - now it's time to lock the beast down a little more. Still open to sugegstions on how one ought to do this better - situation is a standalone AP providing access to a single site which has a need to seperate traffic out and a traditional wired lan is impossible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2005 09:21:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authentication-wireless-and-vlans/m-p/358238#M140694</guid>
      <dc:creator>dyckhscr</dc:creator>
      <dc:date>2005-02-03T09:21:09Z</dc:date>
    </item>
  </channel>
</rss>

