<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Delsenyj, can you please take in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/need-help-with-multi-vlan-ssid-config-on-aironet-1852i-with/m-p/3026702#M35903</link>
    <description>&lt;P&gt;Delsenyj, can you please take a look at this &lt;A href="http://video.cisco.com/detail/videos/wireless/video/5452665274001/configuring-multiple-ssids-for-multiple-vlans" target="_blank" title="Cisco Mobility Express: Configuring Multiple SSIDs for Multiple VLANs"&gt;Cisco video&lt;/A&gt; that discusses this specific issue? Also, you can find the 8.3 Mobility Express Guide &lt;A href="http://www.cisco.com/c/en/us/td/docs/wireless/access_point/mob_exp/83/user_guide/b_ME_User_Guide_83.html" target="_blank" title="Cisco Mobility Express Guide, 8.3"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jul 2017 03:33:50 GMT</pubDate>
    <dc:creator>rbinu</dc:creator>
    <dc:date>2017-07-12T03:33:50Z</dc:date>
    <item>
      <title>Need help with multi vlan/ssid config on Aironet 1852i with Mobility Express</title>
      <link>https://community.cisco.com/t5/wireless/need-help-with-multi-vlan-ssid-config-on-aironet-1852i-with/m-p/3026698#M35899</link>
      <description>&lt;P&gt;I have an Aironet 1852i, with Mobility Express pre-installed (and confirmed to be in ME mode), and I am trying to configure it with 2 wlans for our internal domain networks (both using Windows RADIUS, and both on seperate vlans with seperate external DHCP servers), and another for personal devices and guests. &amp;nbsp;The problem I am having, is coming up with a working solution for the personal devices/guest network. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The 1852i that I have, is the only WLC on our network. &amp;nbsp;It has a static management IP, and the DHCP server for the management network (vlan 8), is on a Cisco ISR 4331 (our primary router), which the 1852i is also directly connected to. &amp;nbsp;The switchport that the 1852i connects to, on the ISR, is configured as a trunk port, with vlan 8 native (management vlan), and allowed vlans 5, 6, 8, and 11.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Wlan 1 is configured for vlan 5, with wpa2 enterprise (using external RADIUS).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Wlan 2 is configured for vlan 11, with wpa2 enterprise (using external RADIUS).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Vlan 5 has a Windows Server 2012 providing DHCP for vlan 5&lt;/P&gt;
&lt;P&gt;Vlan 11 has a Windows Server 2012 providing DHCP for vlan 11, and RADIUS for both wlan 1 &amp;amp; 2.&lt;/P&gt;
&lt;P&gt;(both servers are part of the same domain)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Wlan 1 and 2 work perfectly fine. &amp;nbsp;Our Windows domain clients can connect to their relevant wlan, using their credentials, they get authenticated, and receive a correctly assigned DHCP address for the network they are connected to.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The third wlan (Wlan 3), which is for guests &amp;amp; personal devices. &amp;nbsp;Vlan 6 is assigned to this network, and the DHCP server for this network is also on our ISR 4331. &amp;nbsp;To avoid any captive portal issues with our iphone users, I was hoping that I could set wlan 3 up as a standard wlan for vlan 6, using wpa2 enterprise, but using the internal RADIUS server on the AP. &amp;nbsp;That way any employees or guests that want to use it, have to request access, which could be provided using the Mobility Express gui. &amp;nbsp;However, when configured like this, no client/user can authenticate on wlan 3 with any credentials from wlan users entered in Mobility Express. (wlan 1 &amp;amp; 2 still work find though)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My first question is if that is even possible? (using external RADIUS for some wlan's and internal RADIUS for others, using the same WLC)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So as a fall back, I've tried just configuring wlan 3 as a standard wlan, but now using wpa2 personal (again with vlan 6). &amp;nbsp;With this setup, users can authenticate, using the shared wpa2 personal passphrase, but end up receiving a DHCP assigned ip address from vlan 8 (the management vlan), and not vlan 6. Seperate DHCP pools, using seperate subnets, have been configured on the ISR router, and under each vlan interface (on the ISR) the helper address for that vlan, has been applied.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So I am not sure what I may be missing, but it almost seems as though the WLC is not passing the Vlan info with its DHCP requests for clients on Wlan 3 (assigned to vlan 6)?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any help or advice would be greatly appreciated!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 13:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/need-help-with-multi-vlan-ssid-config-on-aironet-1852i-with/m-p/3026698#M35899</guid>
      <dc:creator>delsenyj</dc:creator>
      <dc:date>2021-07-05T13:24:20Z</dc:date>
    </item>
    <item>
      <title>If i'm right, the mobility</title>
      <link>https://community.cisco.com/t5/wireless/need-help-with-multi-vlan-ssid-config-on-aironet-1852i-with/m-p/3026699#M35900</link>
      <description>&lt;P&gt;If i'm right, the mobility express option is functionally equal to a "virtual wireless controller" running on the AP itself?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;if the controller and the isr can reach eachother&amp;nbsp;on vlan6, then the controller must only forward dhcp requests on layer-2 to the vlan, where the isr&amp;nbsp;can respond to &amp;nbsp;the request.&lt;BR /&gt;in dhcp-proxy mode, the controller forwards the request using the management interface as source, giving the result you describe.&lt;/P&gt;
&lt;P&gt;comparing to a wireless controller configuration&lt;BR /&gt;the controller needs to have&lt;BR /&gt;- an interface in the correct vlan (6) configured&lt;BR /&gt;- an ip-address in the subnet used on this vlan&amp;nbsp;(not really used)&lt;BR /&gt;- a dhcp server configured in this subnet (the isr)&lt;BR /&gt;- dchp proxy mode disabled (!)&lt;/P&gt;
&lt;P&gt;hope this helps?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2017 11:17:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/need-help-with-multi-vlan-ssid-config-on-aironet-1852i-with/m-p/3026699#M35900</guid>
      <dc:creator>pieterh</dc:creator>
      <dc:date>2017-01-20T11:17:52Z</dc:date>
    </item>
    <item>
      <title>It looks like you are correct</title>
      <link>https://community.cisco.com/t5/wireless/need-help-with-multi-vlan-ssid-config-on-aironet-1852i-with/m-p/3026700#M35901</link>
      <description>&lt;P&gt;It looks like you are correct, pieterh.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Right after submitting my initial post (and reading it back to myself again), I stumbled across the Cisco Wireless Controller Configuration Guide v.8.3 (NOT the Mobility Express Configuration Guide v.8.3!!). &amp;nbsp;Going through that, I realized that Mobility Express is built off that platform, as a lot of the same features are there, just not accessible via the Mobility Express gui.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As such, I did end up creating dynamic interfaces on the WLC, for each vlan, each assigned with an IP address within the respective vlan. &amp;nbsp;Each dynamic interface (vlan interface, or sub-interface) was set to use the management interface as the physical port. &amp;nbsp;Then, within each wlan, I configured them to use their respective dynamic interface (vlan interface, on the WLC) that I just created (rather then the management interface, which is default).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The DHCP proxy mode was already off (from my previous attempts), and the DHCP server for vlan 6 remained as I had it configured, on the ISR.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;That did the trick for the IP address assignment issue that I was seeing! &amp;nbsp;Clients can now receive DHCP assigned IP addresses for any wlan that they are connecting to.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The next thing was the RADIUS issue....I found (in the wireless controller configuration guide), that it is indeed possible to use internal AND/OR external RADIUS, per wlan. &amp;nbsp;As default, when a wlan is configured to use RADIUS, the WLC will first try any external RADIUS server(s). &amp;nbsp;Since the list of external RADIUS servers (listed on the WLC) is a global list, the same list is used for any wlan configured with RADIUS. &amp;nbsp;After trying the external RADIUS servers, then it will try the internal RADIUS server. &amp;nbsp;Unless the timeout settings are changed, and if a mixed (internal and external) RADIUS server environment is being used, any wlans configured to use the internal RADIUS server will have clients authentications fail due to timeout, while waiting for the WLC to try each external RADIUS server first.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;That is default.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;There is a couple of settings that I found to work around that....one changes the authentication server priority, per wlan....which did not work for me.&lt;/P&gt;
&lt;P&gt;The other, and what did work, was to disable the wlan's radius authentication server setting, using:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;config wlan radius_server auth disable &amp;lt;WLAN &amp;gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;It's a misleading command, because what it actually does is configures the wlan to not use any external RADIUS server for authentication checks, but does not restrict authenticating with internal RADIUS.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Now I just need to work on the whole captive portal thing, with regards to apple devices (iphones) and the captive portal DNS redirects, using vlans (vlan 6 in my case) that do not have access to the company DNS servers.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;back to reading the config guide!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 16:00:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/need-help-with-multi-vlan-ssid-config-on-aironet-1852i-with/m-p/3026700#M35901</guid>
      <dc:creator>delsenyj</dc:creator>
      <dc:date>2017-02-10T16:00:53Z</dc:date>
    </item>
    <item>
      <title>Hi Delseny, </title>
      <link>https://community.cisco.com/t5/wireless/need-help-with-multi-vlan-ssid-config-on-aironet-1852i-with/m-p/3026701#M35902</link>
      <description>&lt;P&gt;Hi Delseny,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i encountered same issue here.. same configuration/setup you said. Could you share to us the steps/config on how to configure&amp;nbsp;WLAN to use the specific created dynamic interface ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See below scenario&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dynamic int-guest vlan 1 then use by WLAN ssid guest&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dynamic int-employee vlan 20 then use by WLAN ssid employee&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;management vlan is under vlan 10.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;CLI command will do since in mobility express 8.3.xx firmware&amp;nbsp;has no available option/configuration.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 14:10:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/need-help-with-multi-vlan-ssid-config-on-aironet-1852i-with/m-p/3026701#M35902</guid>
      <dc:creator>Rommel Papa</dc:creator>
      <dc:date>2017-03-23T14:10:47Z</dc:date>
    </item>
    <item>
      <title>Delsenyj, can you please take</title>
      <link>https://community.cisco.com/t5/wireless/need-help-with-multi-vlan-ssid-config-on-aironet-1852i-with/m-p/3026702#M35903</link>
      <description>&lt;P&gt;Delsenyj, can you please take a look at this &lt;A href="http://video.cisco.com/detail/videos/wireless/video/5452665274001/configuring-multiple-ssids-for-multiple-vlans" target="_blank" title="Cisco Mobility Express: Configuring Multiple SSIDs for Multiple VLANs"&gt;Cisco video&lt;/A&gt; that discusses this specific issue? Also, you can find the 8.3 Mobility Express Guide &lt;A href="http://www.cisco.com/c/en/us/td/docs/wireless/access_point/mob_exp/83/user_guide/b_ME_User_Guide_83.html" target="_blank" title="Cisco Mobility Express Guide, 8.3"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2017 03:33:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/need-help-with-multi-vlan-ssid-config-on-aironet-1852i-with/m-p/3026702#M35903</guid>
      <dc:creator>rbinu</dc:creator>
      <dc:date>2017-07-12T03:33:50Z</dc:date>
    </item>
  </channel>
</rss>

