<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Office Extend AP NAT Problem in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/office-extend-ap-nat-problem/m-p/1855662#M181317</link>
    <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a wireless LAN Controller 5508 that is connected to a dmz on a ASA 5520 that will provide wireless services to home users. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have primed the access point(s) with the external IP of the controller. I see the requests come in through our permiter router and hit the ASA. When I debug the controller it sees the request and replies, however the port it sees is 5257, I thought this should be UDP 5246 and 5247. See debug on the WLC below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:44:57.422: ec:c8:82:c3:71:60 Discovery Request from 91.102.62.46:5257&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:44:57.422: ec:c8:82:c3:71:60 Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 25, joined Aps =0&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:44:57.423: ec:c8:82:c3:71:60 Discovery Response sent to 91.102.62.46:5257&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:44:57.423: ec:c8:82:c3:71:60 Discovery Response sent to 91.102.62.46:5257&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:45:07.424: ec:c8:82:c3:71:60 Discovery Request from 91.102.62.46:5257&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:45:07.424: ec:c8:82:c3:71:60 Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 25, joined Aps =0&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:45:07.424: ec:c8:82:c3:71:60 Discovery Response sent to 91.102.62.46:5257&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:45:07.424: ec:c8:82:c3:71:60 Discovery Response sent to 91.102.62.46:5257&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:45:17.425: ec:c8:82:c3:71:60 Discovery Request from 91.102.62.46:5257&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did see there was a known bug with the WLC and the NAT and have siince upgraded to version 7.0.220.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have run the packet trace on the FW from the outside -&amp;gt; dmz and from dmz to outside and the packet goes through. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts on what might be up would be useful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sun, 04 Jul 2021 04:26:27 GMT</pubDate>
    <dc:creator>greg.murray</dc:creator>
    <dc:date>2021-07-04T04:26:27Z</dc:date>
    <item>
      <title>Office Extend AP NAT Problem</title>
      <link>https://community.cisco.com/t5/wireless/office-extend-ap-nat-problem/m-p/1855662#M181317</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a wireless LAN Controller 5508 that is connected to a dmz on a ASA 5520 that will provide wireless services to home users. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have primed the access point(s) with the external IP of the controller. I see the requests come in through our permiter router and hit the ASA. When I debug the controller it sees the request and replies, however the port it sees is 5257, I thought this should be UDP 5246 and 5247. See debug on the WLC below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:44:57.422: ec:c8:82:c3:71:60 Discovery Request from 91.102.62.46:5257&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:44:57.422: ec:c8:82:c3:71:60 Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 25, joined Aps =0&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:44:57.423: ec:c8:82:c3:71:60 Discovery Response sent to 91.102.62.46:5257&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:44:57.423: ec:c8:82:c3:71:60 Discovery Response sent to 91.102.62.46:5257&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:45:07.424: ec:c8:82:c3:71:60 Discovery Request from 91.102.62.46:5257&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:45:07.424: ec:c8:82:c3:71:60 Join Priority Processing status = 0, Incoming Ap's Priority 1, MaxLrads = 25, joined Aps =0&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:45:07.424: ec:c8:82:c3:71:60 Discovery Response sent to 91.102.62.46:5257&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:45:07.424: ec:c8:82:c3:71:60 Discovery Response sent to 91.102.62.46:5257&lt;/P&gt;&lt;P&gt;*spamApTask7: Jan 24 13:45:17.425: ec:c8:82:c3:71:60 Discovery Request from 91.102.62.46:5257&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did see there was a known bug with the WLC and the NAT and have siince upgraded to version 7.0.220.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have run the packet trace on the FW from the outside -&amp;gt; dmz and from dmz to outside and the packet goes through. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts on what might be up would be useful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 04:26:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/office-extend-ap-nat-problem/m-p/1855662#M181317</guid>
      <dc:creator>greg.murray</dc:creator>
      <dc:date>2021-07-04T04:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Office Extend AP NAT Problem</title>
      <link>https://community.cisco.com/t5/wireless/office-extend-ap-nat-problem/m-p/1855663#M181318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you post the NAT config from the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2012 14:04:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/office-extend-ap-nat-problem/m-p/1855663#M181318</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2012-01-24T14:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: Office Extend AP NAT Problem</title>
      <link>https://community.cisco.com/t5/wireless/office-extend-ap-nat-problem/m-p/1855664#M181319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was just testing this yesterday andgot it to work.... The ap will use udp 5246 &amp;amp; 5247 and when I was tesing,&amp;nbsp; I didn't use an ASA, but had to do nat translation on m y router (test lab).&amp;nbsp; The port will not be 5246 or 5247 since the other router will nat using a different port.&amp;nbsp; Here is my log:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;udp 72.57.26.241:5246&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.221.27:5246&amp;nbsp;&amp;nbsp; 71.238.159.119:5266&amp;nbsp;&amp;nbsp; 71.238.159.119:5266&lt;/P&gt;&lt;P&gt;udp 72.57.26.241:5246&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.221.27:5246&amp;nbsp;&amp;nbsp; ---&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---&lt;/P&gt;&lt;P&gt;udp 72.57.26.241:5247&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.221.27:5247&amp;nbsp;&amp;nbsp; 71.238.159.119:5266&amp;nbsp;&amp;nbsp; 71.238.159.119:5266&lt;/P&gt;&lt;P&gt;udp 72.57.26.241:5247&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.221.27:5247&amp;nbsp;&amp;nbsp; ---&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Jan 24 02:41:08.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 72.57.26.241 peer_port: 5246&lt;/P&gt;&lt;P&gt;*Jan 24 02:41:08.001: %CAPWAP-5-CHANGED: CAPWAP changed state to&lt;/P&gt;&lt;P&gt;wmmAC status is FALSE&lt;/P&gt;&lt;P&gt;*Jan 24 02:41:09.491: %CAPWAP-5-DTLSREQSUCC: DTLS connection created sucessfully peer_ip: 72.57.26.241 peer_port: 5246&lt;/P&gt;&lt;P&gt;*Jan 24 02:41:09.492: %CAPWAP-5-SENDJOIN: sending Join Request to 72.57.26.241&lt;/P&gt;&lt;P&gt;*Jan 24 02:41:09.492: %CAPWAP-5-CHANGED: CAPWAP changed state to JOIN&lt;/P&gt;&lt;P&gt;*Jan 24 02:41:09.697: %CAPWAP-5-CHANGED: CAPWAP changed state to CFG&lt;/P&gt;&lt;P&gt;*Jan 24 02:41:10.123: %CAPWAP-5-CHANGED: CAPWAP changed state to UP&lt;/P&gt;&lt;P&gt;*Jan 24 02:41:10.343: %CAPWAP-5-JOINEDCONTROLLER: AP has joined controller WLC-2504&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2012 14:05:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/office-extend-ap-nat-problem/m-p/1855664#M181319</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-01-24T14:05:27Z</dc:date>
    </item>
    <item>
      <title>Office Extend AP NAT Problem</title>
      <link>https://community.cisco.com/t5/wireless/office-extend-ap-nat-problem/m-p/1855665#M181320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Outside Rtr&lt;/P&gt;&lt;P&gt;===========&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0.1&lt;/P&gt;&lt;P&gt; description ### Link to Internet ###&lt;/P&gt;&lt;P&gt; ip address 94.136.227.xx 255.255.255.248 - external ip&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip access-group OUTSIDE_IN in&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; description ### Link to Firewalls ###&lt;/P&gt;&lt;P&gt; ip address 172.16.100.254 255.255.255.0&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip nat inside source static 172.16.10.1 94.136.227.xx - controller NAT &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended OUTSIDE_IN&lt;/P&gt;&lt;P&gt; permit udp any host 94.136.227.xx eq 5246&lt;/P&gt;&lt;P&gt; permit udp any host 94.136.227.xx eq 5247&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA&lt;/P&gt;&lt;P&gt;===&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (wireless-dmz) 1 interface&lt;/P&gt;&lt;P&gt;nat (wireless-dmz) 1 172.16.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;static (wireless-dmz,OUTSIDE) 172.16.10.1 172.16.10.1 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-group wireless-dmz_access_in in interface wireless-dmz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2012 15:13:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/office-extend-ap-nat-problem/m-p/1855665#M181320</guid>
      <dc:creator>greg.murray</dc:creator>
      <dc:date>2012-01-24T15:13:09Z</dc:date>
    </item>
  </channel>
</rss>

