<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Office Extend Mode in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767279#M181745</link>
    <description>&lt;P&gt;I have got a 3502 setup anf functioing in Office Extend mode. I have found one issue though. I have to set the checkbox on the my Management Interface to Enable NAT Address and put the external address in the box. Once this occurs no internal APs can join the controller.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any ideas on setting this up with a single controller behind a router and not having to set the NAT Address for the Management interface? Should I setup a second interface on the controller to be for external management?&lt;/P&gt;</description>
    <pubDate>Sun, 04 Jul 2021 03:57:44 GMT</pubDate>
    <dc:creator>nshoe18</dc:creator>
    <dc:date>2021-07-04T03:57:44Z</dc:date>
    <item>
      <title>Office Extend Mode</title>
      <link>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767279#M181745</link>
      <description>&lt;P&gt;I have got a 3502 setup anf functioing in Office Extend mode. I have found one issue though. I have to set the checkbox on the my Management Interface to Enable NAT Address and put the external address in the box. Once this occurs no internal APs can join the controller.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any ideas on setting this up with a single controller behind a router and not having to set the NAT Address for the Management interface? Should I setup a second interface on the controller to be for external management?&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 03:57:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767279#M181745</guid>
      <dc:creator>nshoe18</dc:creator>
      <dc:date>2021-07-04T03:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: Office Extend Mode</title>
      <link>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767280#M181746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;there was a defect raised against this, and I thought it was fixed in later 6.0 and 7.0 codes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a workaround to this as well.  Basically you need the FW rules to allow the internal ap to hairpin back into the network to reach the NAT address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2011 13:21:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767280#M181746</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2011-10-20T13:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: Office Extend Mode</title>
      <link>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767281#M181747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you say the FW, are you talking about the remote side or the corporate side?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2011 13:27:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767281#M181747</guid>
      <dc:creator>nshoe18</dc:creator>
      <dc:date>2011-10-20T13:27:43Z</dc:date>
    </item>
    <item>
      <title>Office Extend Mode</title>
      <link>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767282#M181748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;where the controller is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Please remember to rate helpful posts or to mark the question as answered so that it can be found later.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2011 13:55:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767282#M181748</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2011-10-20T13:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: Office Extend Mode</title>
      <link>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767283#M181749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I just saw what you mean. I have the NAT statement in there but no Access-List for the UDP ports needed. That is what you are referencing correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2011 14:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767283#M181749</guid>
      <dc:creator>nshoe18</dc:creator>
      <dc:date>2011-10-20T14:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: Office Extend Mode</title>
      <link>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767284#M181750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I wanted to chime in with a quick comment. If you give your WLC an outside address you can avoid the NAT all together. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2011 15:12:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767284#M181750</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2011-10-20T15:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Office Extend Mode</title>
      <link>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767285#M181751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Then how would my internal APs connect?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2011 15:18:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767285#M181751</guid>
      <dc:creator>nshoe18</dc:creator>
      <dc:date>2011-10-20T15:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: Office Extend Mode</title>
      <link>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767286#M181752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the inside (dpending on your FW rules) you should be able to hit the DMZ becuase you are more TRUSTED. You can of course lock it down to ports from inside to DMZ and only allow the APs traffic and client traffic to pass. But most people from the inside allow traffic to the DMZ. And then restrict from the DMZ back in ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/1/2/65211-WLC.GUEST.PORTS.gif" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2011 15:26:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767286#M181752</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2011-10-20T15:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Office Extend Mode</title>
      <link>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767287#M181753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since we are small, I only have a single controller and no true DMZ per se. I have setup an ACL just haven't tested it yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2011 15:40:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767287#M181753</guid>
      <dc:creator>nshoe18</dc:creator>
      <dc:date>2011-10-20T15:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: Office Extend Mode</title>
      <link>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767288#M181754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, well no worries. As Steve pointed out there is/was a NAT issue on earlier code. I think it was fixed in M1. but again, if you give the WLC an outside address and protect it with ACLs from the outside and allow your internal folks to hit it from the inside you should be ok. But again, I dont know how your network is designed or your specific design requirements. Please take these as suggestions as they may apply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps Steve can add to this as well...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2011 15:46:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/office-extend-mode/m-p/1767288#M181754</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2011-10-20T15:46:30Z</dc:date>
    </item>
  </channel>
</rss>

