<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DMZ Anchor Controller in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/dmz-anchor-controller/m-p/939113#M27633</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From Chapter 10 of the Enterprise Mobility 4.1 Design Guide - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/netsol/ns656/networking_solutions_design_guidance09186a00808d9330.html" target="_blank"&gt;http://www.cisco.com/en/US/netsol/ns656/networking_solutions_design_guidance09186a00808d9330.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following verifications and troubleshooting tasks assume the following: â&amp;#128;¢The solution is using the web authentication functionality resident in the anchor controller(s). â&amp;#128;¢User credentials are created and stored locally on the anchor controller(s).&lt;/P&gt;&lt;P&gt;Before attempting to troubleshoot the various symptoms below, at the very least you should be able to ping from the campus (foreign) controller to the anchor controller(s). If not, verify routing.&lt;/P&gt;&lt;P&gt;Next, you should be able to perform the following advanced pings. These can only be performed via the serial console interfaces of the controllers: â&amp;#128;¢mping neighbor WLC ip&lt;/P&gt;&lt;P&gt;This pings the neighbor controller through the LWAPP control channel. â&amp;#128;¢eping neighbor WLC ip&lt;/P&gt;&lt;P&gt;This pings the neighbor controller through the LWAPP data channel.&lt;/P&gt;&lt;P&gt;If a standard ICMP ping goes through, but mpings do not, ensure that the default mobility group name of each WLC is the same, and ensure that the IP, MAC, and mobility group name of each WLC is entered in the mobility members list of every WLC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If pings and mpings are successful, but epings are not, check the network to make sure that IP protocol 97 (Ethernet-over-IP) is not being blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please make sure that the mobility group names are on each other's controller. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Feb 2008 05:23:00 GMT</pubDate>
    <dc:creator>john.preves</dc:creator>
    <dc:date>2008-02-27T05:23:00Z</dc:date>
    <item>
      <title>DMZ Anchor Controller</title>
      <link>https://community.cisco.com/t5/wireless/dmz-anchor-controller/m-p/939111#M27631</link>
      <description>&lt;P&gt;I'm having trouble setting up an Anchor Controller on my DMZ.  I have setup everything up and tested it out on my inside network and the Anchor Controller comes up with no problem.  When I put the Anchor Controller on the DMZ the data path is up but the control path is down. I can do EPING's but MPINGS fail everytime.    The DMZ is secured by a checkpoint firewall. I've made sure ports UDP 16666, 16667 and TCP 97 are open on the firewall.  It looks like the traffic is going out to the Anchor controller on the DMZ but not coming back in to establish the tunnel.   I've contacted Checkpoint but there support is not the best and I'm wondering if anyone has suppport for a checkpointfirewall.  Thanks in advance&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 22:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dmz-anchor-controller/m-p/939111#M27631</guid>
      <dc:creator>sbeauton</dc:creator>
      <dc:date>2021-07-03T22:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Anchor Controller</title>
      <link>https://community.cisco.com/t5/wireless/dmz-anchor-controller/m-p/939112#M27632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you NATing inside controller management ip address?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Feb 2008 21:13:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dmz-anchor-controller/m-p/939112#M27632</guid>
      <dc:creator>sungy</dc:creator>
      <dc:date>2008-02-26T21:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Anchor Controller</title>
      <link>https://community.cisco.com/t5/wireless/dmz-anchor-controller/m-p/939113#M27633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From Chapter 10 of the Enterprise Mobility 4.1 Design Guide - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/netsol/ns656/networking_solutions_design_guidance09186a00808d9330.html" target="_blank"&gt;http://www.cisco.com/en/US/netsol/ns656/networking_solutions_design_guidance09186a00808d9330.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following verifications and troubleshooting tasks assume the following: â&amp;#128;¢The solution is using the web authentication functionality resident in the anchor controller(s). â&amp;#128;¢User credentials are created and stored locally on the anchor controller(s).&lt;/P&gt;&lt;P&gt;Before attempting to troubleshoot the various symptoms below, at the very least you should be able to ping from the campus (foreign) controller to the anchor controller(s). If not, verify routing.&lt;/P&gt;&lt;P&gt;Next, you should be able to perform the following advanced pings. These can only be performed via the serial console interfaces of the controllers: â&amp;#128;¢mping neighbor WLC ip&lt;/P&gt;&lt;P&gt;This pings the neighbor controller through the LWAPP control channel. â&amp;#128;¢eping neighbor WLC ip&lt;/P&gt;&lt;P&gt;This pings the neighbor controller through the LWAPP data channel.&lt;/P&gt;&lt;P&gt;If a standard ICMP ping goes through, but mpings do not, ensure that the default mobility group name of each WLC is the same, and ensure that the IP, MAC, and mobility group name of each WLC is entered in the mobility members list of every WLC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If pings and mpings are successful, but epings are not, check the network to make sure that IP protocol 97 (Ethernet-over-IP) is not being blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please make sure that the mobility group names are on each other's controller. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2008 05:23:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dmz-anchor-controller/m-p/939113#M27633</guid>
      <dc:creator>john.preves</dc:creator>
      <dc:date>2008-02-27T05:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Anchor Controller</title>
      <link>https://community.cisco.com/t5/wireless/dmz-anchor-controller/m-p/939114#M27634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am wondering if you ever got this resolved.  I am running into the exact same problem you described here.  I've got the local Checkpoint admins looking into it, but if you happen to have the fix for this, I'd be much appreciative!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2008 22:18:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dmz-anchor-controller/m-p/939114#M27634</guid>
      <dc:creator>jeff_groesbeck</dc:creator>
      <dc:date>2008-12-09T22:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Anchor Controller</title>
      <link>https://community.cisco.com/t5/wireless/dmz-anchor-controller/m-p/939115#M27635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes we got this working.  The problem was a NAT statement on the CheckPoint Firewall.   Make sure you have nat statments for the outside Anchor Controller and also NATS for the inside networks.   Hopefully you'll be able to get this issue fixed.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2008 23:46:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dmz-anchor-controller/m-p/939115#M27635</guid>
      <dc:creator>sbeauton</dc:creator>
      <dc:date>2008-12-09T23:46:28Z</dc:date>
    </item>
  </channel>
</rss>

