<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security on 1130ag in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/security-on-1130ag/m-p/1006290#M143840</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got this working in a test lab a long time ago with a AP1131AG, below is part of the config, I hope is relevant:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot11 ssid &amp;lt;&lt;GUEST ssid="" name=""&gt;&amp;gt;&lt;/GUEST&gt;&lt;/P&gt;&lt;P&gt;   vlan 5&lt;/P&gt;&lt;P&gt;   mbssid guest-mode&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot11 ssid &amp;lt;&lt;INTERNAL ssid="" name=""&gt;&amp;gt;&lt;/INTERNAL&gt;&lt;/P&gt;&lt;P&gt;   vlan 10&lt;/P&gt;&lt;P&gt;   mbssid guest-mode&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dot11Radio0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; ssid &amp;lt;&lt;GUEST ssid="" name=""&gt;&amp;gt;&lt;/GUEST&gt;&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; ssid &amp;lt;&lt;INTERNAL ssid="" name=""&gt;&amp;gt;&lt;/INTERNAL&gt;&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; mbssid&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dot11Radio0.5&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 5 native&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; bridge-group 5&lt;/P&gt;&lt;P&gt; bridge-group 5 subscriber-loop-control&lt;/P&gt;&lt;P&gt; bridge-group 5 block-unknown-source&lt;/P&gt;&lt;P&gt; no bridge-group 5 source-learning&lt;/P&gt;&lt;P&gt; no bridge-group 5 unicast-flooding&lt;/P&gt;&lt;P&gt; bridge-group 5 spanning-disabled&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dot11Radio0.10&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 10&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; bridge-group 10&lt;/P&gt;&lt;P&gt; bridge-group 10 subscriber-loop-control&lt;/P&gt;&lt;P&gt; bridge-group 10 block-unknown-source&lt;/P&gt;&lt;P&gt; no bridge-group 10 source-learning&lt;/P&gt;&lt;P&gt; no bridge-group 10 unicast-flooding&lt;/P&gt;&lt;P&gt; bridge-group 10 spanning-disabled&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Apr 2008 09:08:32 GMT</pubDate>
    <dc:creator>andrew.prince</dc:creator>
    <dc:date>2008-04-22T09:08:32Z</dc:date>
    <item>
      <title>Security on 1130ag</title>
      <link>https://community.cisco.com/t5/wireless/security-on-1130ag/m-p/1006289#M143839</link>
      <description>&lt;P&gt;I'm new to Cisco AP's.  I'm trying to setup security per VLAN on a new 1130ag.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I finally got the Guest VLAN configured for Open Authentication (I'll lock down VLAN access after I get AP setup, it's not live yet).  Where is the option to broadcast SSID for this Guest access?  I have to manually enter in the network...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But more importantly, I'm trying to setup an INT VLAN on the AP with security enabled.  Looking through the SSID Management section, here is what I have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;INT should be the SSID name, and I'm wanting to broadcast this, but like the Guest VLAN, it's not showing up.  &lt;/P&gt;&lt;P&gt;VLAN1&lt;/P&gt;&lt;P&gt;radio ag&lt;/P&gt;&lt;P&gt;Open Auth no addition&lt;/P&gt;&lt;P&gt;Key Mngmnt Mandatory &lt;/P&gt;&lt;P&gt;enable WPA WPAv2&lt;/P&gt;&lt;P&gt;WPA pre-shared key: cisco ASCII&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are the options I've enabled in hopes of requiring a client to type "cisco" to connect, and have WPA2 for encryption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I doing something wrong?   I manually enter the INT for the wireless network and get "Connection timed out", but am able to connect to the Open 'Guest' network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And again, I see the "Broadcast SSID" in the Quick Security Setup option, but not in the SSID Management section.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for reading.  And thanks for any advice/tips.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Be well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 22:45:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/security-on-1130ag/m-p/1006289#M143839</guid>
      <dc:creator>Armegeden</dc:creator>
      <dc:date>2021-07-03T22:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Security on 1130ag</title>
      <link>https://community.cisco.com/t5/wireless/security-on-1130ag/m-p/1006290#M143840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got this working in a test lab a long time ago with a AP1131AG, below is part of the config, I hope is relevant:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot11 ssid &amp;lt;&lt;GUEST ssid="" name=""&gt;&amp;gt;&lt;/GUEST&gt;&lt;/P&gt;&lt;P&gt;   vlan 5&lt;/P&gt;&lt;P&gt;   mbssid guest-mode&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot11 ssid &amp;lt;&lt;INTERNAL ssid="" name=""&gt;&amp;gt;&lt;/INTERNAL&gt;&lt;/P&gt;&lt;P&gt;   vlan 10&lt;/P&gt;&lt;P&gt;   mbssid guest-mode&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dot11Radio0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; ssid &amp;lt;&lt;GUEST ssid="" name=""&gt;&amp;gt;&lt;/GUEST&gt;&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; ssid &amp;lt;&lt;INTERNAL ssid="" name=""&gt;&amp;gt;&lt;/INTERNAL&gt;&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; mbssid&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dot11Radio0.5&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 5 native&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; bridge-group 5&lt;/P&gt;&lt;P&gt; bridge-group 5 subscriber-loop-control&lt;/P&gt;&lt;P&gt; bridge-group 5 block-unknown-source&lt;/P&gt;&lt;P&gt; no bridge-group 5 source-learning&lt;/P&gt;&lt;P&gt; no bridge-group 5 unicast-flooding&lt;/P&gt;&lt;P&gt; bridge-group 5 spanning-disabled&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dot11Radio0.10&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 10&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; bridge-group 10&lt;/P&gt;&lt;P&gt; bridge-group 10 subscriber-loop-control&lt;/P&gt;&lt;P&gt; bridge-group 10 block-unknown-source&lt;/P&gt;&lt;P&gt; no bridge-group 10 source-learning&lt;/P&gt;&lt;P&gt; no bridge-group 10 unicast-flooding&lt;/P&gt;&lt;P&gt; bridge-group 10 spanning-disabled&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2008 09:08:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/security-on-1130ag/m-p/1006290#M143840</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-04-22T09:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: Security on 1130ag</title>
      <link>https://community.cisco.com/t5/wireless/security-on-1130ag/m-p/1006291#M143841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello and thanks for the reply.  I'm doing side-by-side comparison with my config and I'm not seeing much difference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a clip of mine:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot11 vlan-name GUEST vlan 3&lt;/P&gt;&lt;P&gt;dot11 vlan-name SCHOOL vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot11 ssid GUEST&lt;/P&gt;&lt;P&gt;   vlan 3&lt;/P&gt;&lt;P&gt;   authentication open&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot11 ssid INT&lt;/P&gt;&lt;P&gt;   vlan 1&lt;/P&gt;&lt;P&gt;   authentication open&lt;/P&gt;&lt;P&gt;   authentication key-management wpa version 2&lt;/P&gt;&lt;P&gt;   wpa-psk ascii 7 05giberish123&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot11 ssid SCHOOL&lt;/P&gt;&lt;P&gt;   vlan 2&lt;/P&gt;&lt;P&gt;   authentication open&lt;/P&gt;&lt;P&gt;   authentication key-management wpa version 2&lt;/P&gt;&lt;P&gt;   wpa-psk ascii 7 12giberish123&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dot11Radio0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; encryption vlan 1 mode ciphers tkip&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; encryption vlan 2 mode ciphers aes-ccm tkip&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; ssid GUEST&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; ssid INT&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; ssid SCHOOL&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; station-role root&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dot11Radio0.1&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 1 native&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; bridge-group 1&lt;/P&gt;&lt;P&gt; bridge-group 1 subscriber-loop-control&lt;/P&gt;&lt;P&gt; bridge-group 1 block-unknown-source&lt;/P&gt;&lt;P&gt; no bridge-group 1 source-learning&lt;/P&gt;&lt;P&gt; no bridge-group 1 unicast-flooding&lt;/P&gt;&lt;P&gt; bridge-group 1 spanning-disabled&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dot11Radio0.2&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 2&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; bridge-group 2&lt;/P&gt;&lt;P&gt; bridge-group 2 subscriber-loop-control&lt;/P&gt;&lt;P&gt; bridge-group 2 block-unknown-source&lt;/P&gt;&lt;P&gt; no bridge-group 2 source-learning&lt;/P&gt;&lt;P&gt; no bridge-group 2 unicast-flooding&lt;/P&gt;&lt;P&gt; bridge-group 2 spanning-disabled&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dot11Radio0.3&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 3&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; bridge-group 3&lt;/P&gt;&lt;P&gt; bridge-group 3 subscriber-loop-control&lt;/P&gt;&lt;P&gt; bridge-group 3 block-unknown-source&lt;/P&gt;&lt;P&gt; no bridge-group 3 source-learning&lt;/P&gt;&lt;P&gt; no bridge-group 3 unicast-flooding&lt;/P&gt;&lt;P&gt; bridge-group 3 spanning-disabled&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pardon if this is too much info, not really sure which is vital.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this look correct for setting up WPA2?  How about having the SSID's non-hidden?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Apr 2008 21:22:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/security-on-1130ag/m-p/1006291#M143841</guid>
      <dc:creator>Armegeden</dc:creator>
      <dc:date>2008-04-30T21:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: Security on 1130ag</title>
      <link>https://community.cisco.com/t5/wireless/security-on-1130ag/m-p/1006292#M143842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A side-by-side comparison would have shown that you have missed:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"mbssid guest-mode" in each of the dot11 ssid configurations i.e:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dot11 ssid GUEST&lt;/P&gt;&lt;P&gt;mbssid guest-mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"mbssid" is required under the dot11radio0 interface to actually indicate more than one ssid should be sent in the beacon i.e:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Dot11Radio0&lt;/P&gt;&lt;P&gt;mbssid&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Add the above and test, let me know of your results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The WPA2 config looks ok.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 May 2008 06:49:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/security-on-1130ag/m-p/1006292#M143842</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-05-01T06:49:45Z</dc:date>
    </item>
  </channel>
</rss>

