<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What devices are you in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632352#M41225</link>
    <description>&lt;P&gt;What devices are you deploying in the OEAP mode?&amp;nbsp; 602's or normal enterprise class units?&lt;/P&gt;&lt;P&gt;What is your discovery mechanism?&amp;nbsp; A DNS call?&lt;/P&gt;&lt;P&gt;602's don't do a DNS lookup..&lt;/P&gt;</description>
    <pubDate>Tue, 03 Feb 2015 20:44:32 GMT</pubDate>
    <dc:creator>David Ritter</dc:creator>
    <dc:date>2015-02-03T20:44:32Z</dc:date>
    <item>
      <title>WLC NAT Feature problem for OEAP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632340#M41213</link>
      <description>&lt;P style="font-size: 14.5454540252686px;"&gt;Dear all,&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;The problem that i have when i enable NAT on my MGMT interface, the APs on the "inside" does not find the WLC.&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;If uncheck the NAT the APs will connect right away.&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;When I enable the NAT, the APs stay connected but some them and from time to time they leave the WLC and join the backup WLC&amp;nbsp;and back to main and and...&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;I also use the feature&amp;nbsp;&lt;SPAN style="font-weight:bold"&gt;config network ap-discovery nat-ip-only&lt;/SPAN&gt; &lt;STRONG&gt;disable&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;&lt;STRONG&gt;&lt;EM&gt;Code 7.6.130.0&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;I know it is better to use a separate WLC for OEAP, but the option is there and I would like to use it because we have not much OEAPs.&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;should I prevent the internal APs to be able to reach the external IP? I allowed only CAPWA to the NAT IP, is there anything we should change..?&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;best regards,&lt;BR /&gt;Sebastian&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 09:23:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632340#M41213</guid>
      <dc:creator>Sebastian Helmer</dc:creator>
      <dc:date>2021-07-05T09:23:02Z</dc:date>
    </item>
    <item>
      <title>When you enable NAT, I</title>
      <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632341#M41214</link>
      <description>&lt;P&gt;When you enable NAT, I believe you also need to add the APs MAC address in the ap authorization. APs inside will eventually drop when enabling that feature without adding all the MAC address.&lt;/P&gt;&lt;P&gt;Edit: Come to think about it, you just need to issue the command you posted:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px; -webkit-text-size-adjust: 100%; font-weight: bold;"&gt;config network ap-discovery nat-ip-only&lt;/SPAN&gt;&lt;SPAN style="font-size: 14px; -webkit-text-size-adjust: 100%;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="font-size: 14px; -webkit-text-size-adjust: 100%;"&gt;disable&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;-Scott&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2015 13:43:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632341#M41214</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2015-01-30T13:43:02Z</dc:date>
    </item>
    <item>
      <title>Scott,I added only the</title>
      <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632342#M41215</link>
      <description>&lt;P&gt;Scott,&lt;/P&gt;&lt;P&gt;I added only the "Problem" makers to see if that helps, and it seem so...great..I have th e Problems since almost years and worked with a lot of Workarounds...where is that documented?&lt;/P&gt;&lt;P&gt;I will now checkout some CLI command to make that easier, because we are having hundred of APs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks so far I will update with a "correct Answer" after a while and i see that it works for me..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Sebastian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2015 13:43:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632342#M41215</guid>
      <dc:creator>Sebastian Helmer</dc:creator>
      <dc:date>2015-01-30T13:43:03Z</dc:date>
    </item>
    <item>
      <title>The idea to add the mac's</title>
      <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632343#M41216</link>
      <description>&lt;P&gt;The idea to add the mac's doesn't help.. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It was just a lucky hit in the moment I checked the WLC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the command is used, but without success....at the Moment I have just two APs..we will see if the count grows...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2015 14:03:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632343#M41216</guid>
      <dc:creator>Sebastian Helmer</dc:creator>
      <dc:date>2015-01-30T14:03:49Z</dc:date>
    </item>
    <item>
      <title>Sebastian,when using</title>
      <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632344#M41217</link>
      <description>&lt;P&gt;Sebastian,&lt;/P&gt;&lt;P&gt;when using anninternal wlc for OEAP, one thing you want is to sort of prevent unknown APs from registering as an OEAP. The only way to do that is with MAC address being added to the WLC. This way you can remove any given ap that you might decide to remove. &amp;nbsp;Another option is to get a 2504 just for OEAP's as long as your not hitting over 75 AP's. &amp;nbsp;Cisco has a bundle in which if you purchase two 1702, 2702, or 3702, you get a free 2504-25. &amp;nbsp;You can use any of these also for OEAP, but no wired connection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Scott&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2015 15:08:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632344#M41217</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2015-01-30T15:08:15Z</dc:date>
    </item>
    <item>
      <title>Scott,I know best practise</title>
      <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632345#M41218</link>
      <description>&lt;P&gt;Scott,&lt;/P&gt;&lt;P&gt;I know best practise would be a dedicated WLC, but my colleauges and global technical teamlead&amp;nbsp;asked me why because it seems to work and to be honest the option is there and if there is a way I would like to use it as well. Maybe just to safe the working and maintenance and management for the additional WLC..But if there is no solution, sure I will go the best practise way...but right now it makes fun to go deeper in that ;)..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyhow, I discussed the situation with our firewall guy's and we didn't find a reason because everything seems to be okay like we see in the tcpdumps, but we are still in discussions..&lt;/P&gt;&lt;P&gt;I did some debugs on the AP,&amp;nbsp;because I think on the WLC with about 200 APs it could make trouble. I see no problem..if you like I can post it..BUT when I configure the public NAT IP als primary WLC for the AP it works...without problems..(since about 20min) otherwise with the interanl WLC IP as primary configured the AP will struggle every 5min as we see today...&lt;/P&gt;&lt;P&gt;Is there any idea with those new information? For me it sound like a Protocoll "problem" It was with some codes we used in the past the same..&lt;/P&gt;&lt;P&gt;Sebastian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 19:06:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632345#M41218</guid>
      <dc:creator>Sebastian Helmer</dc:creator>
      <dc:date>2015-02-03T19:06:28Z</dc:date>
    </item>
    <item>
      <title>The WLC that you have nat </title>
      <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632346#M41219</link>
      <description>&lt;P&gt;The WLC that you have nat&amp;nbsp; enabled, is that an anchor wlc or a foreign wlc?&lt;/P&gt;&lt;P&gt;-Scott&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 19:25:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632346#M41219</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2015-02-03T19:25:06Z</dc:date>
    </item>
    <item>
      <title>It's an anchor for a few</title>
      <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632347#M41220</link>
      <description>&lt;P&gt;It's an anchor for a few foreign!&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 19:30:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632347#M41220</guid>
      <dc:creator>Sebastian Helmer</dc:creator>
      <dc:date>2015-02-03T19:30:29Z</dc:date>
    </item>
    <item>
      <title>Okay, so nat ip address on</title>
      <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632348#M41221</link>
      <description>&lt;P&gt;Okay, so nat ip address on the management should only be configured on that anchor.&amp;nbsp; You have local mode ap's on that anchor?&lt;/P&gt;&lt;P&gt;-Scott&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 19:35:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632348#M41221</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2015-02-03T19:35:04Z</dc:date>
    </item>
    <item>
      <title>U mean as primary WLC for the</title>
      <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632349#M41222</link>
      <description>&lt;P&gt;U mean as primary WLC for the APs? Is there any explanation why?&lt;/P&gt;&lt;P&gt;we use successfully except one voice wlan location flexconnect everywhere.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 19:42:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632349#M41222</guid>
      <dc:creator>Sebastian Helmer</dc:creator>
      <dc:date>2015-02-03T19:42:01Z</dc:date>
    </item>
    <item>
      <title>The problem that the internal</title>
      <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632350#M41223</link>
      <description>&lt;P&gt;The problem that the internal AP has in linking with the WLC on the Internal management IP is that shortly in the dialog the WLC will tell the AP to reply on the NAT (External) ip.&amp;nbsp; How many internal devices can ping the external doorway?&amp;nbsp; Current code can allow the WLC to report both the internal and external IP's.&amp;nbsp; that's the mode you need.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem with one WLC providing both internal and external support is that RLANS require 1mbps support.&amp;nbsp; lacking that and rlans will fail to authenticate.&amp;nbsp; That means that all the ssids are&amp;nbsp;transmitting beacons at 1mbps.&amp;nbsp; at least that was the way it was in the beginning and I have not gone back and tested my current code (7.6.120).&amp;nbsp; I have way too many rlans to loose.&amp;nbsp; Almost all of my OEAPS' are supporting rlans for a voip phone and a workstation.&lt;/P&gt;&lt;P&gt;Another, OEAP ssids don't support MFP&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 20:13:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632350#M41223</guid>
      <dc:creator>David Ritter</dc:creator>
      <dc:date>2015-02-03T20:13:04Z</dc:date>
    </item>
    <item>
      <title>David, thanks to to let me</title>
      <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632351#M41224</link>
      <description>&lt;P&gt;David,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks to to let me know that&amp;nbsp;&lt;/P&gt;&lt;P&gt;As u can see above my WLC is responding with the internal and the external. That should be no issue. I used the necessary cli command.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My APs wasn't able to ping the external till yesterday, we thought that could be &amp;nbsp;the&amp;nbsp;problem so we enabled that but it didn't helped.&lt;/P&gt;&lt;P&gt;But now when I configure the external ip on the ap it joins successfully the WLC.&lt;/P&gt;&lt;P&gt;If that is they way I need to go because I have also a mobility setup in place for the anchor setup I use, I'm fine with that. But it would be nice to have&amp;nbsp;details why I have to use the external ip and it is not working with the internal management ip.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sebastian&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 20:31:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632351#M41224</guid>
      <dc:creator>Sebastian Helmer</dc:creator>
      <dc:date>2015-02-03T20:31:13Z</dc:date>
    </item>
    <item>
      <title>What devices are you</title>
      <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632352#M41225</link>
      <description>&lt;P&gt;What devices are you deploying in the OEAP mode?&amp;nbsp; 602's or normal enterprise class units?&lt;/P&gt;&lt;P&gt;What is your discovery mechanism?&amp;nbsp; A DNS call?&lt;/P&gt;&lt;P&gt;602's don't do a DNS lookup..&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 20:44:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632352#M41225</guid>
      <dc:creator>David Ritter</dc:creator>
      <dc:date>2015-02-03T20:44:32Z</dc:date>
    </item>
    <item>
      <title>602 and they are workin fine.</title>
      <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632353#M41226</link>
      <description>&lt;P&gt;602 and they are workin fine. Manually configured as u can see in the config guide. Why is that important for my case? My problem are the internal APs&amp;nbsp;&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 21:04:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632353#M41226</guid>
      <dc:creator>Sebastian Helmer</dc:creator>
      <dc:date>2015-02-03T21:04:34Z</dc:date>
    </item>
    <item>
      <title>don't know yet..  I don't</title>
      <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632354#M41227</link>
      <description>&lt;P&gt;don't know yet..&amp;nbsp; I don't hook anything to the OEAP wlc that I'm not going to config as such.&lt;/P&gt;&lt;P&gt;I going to spin up a 3602 and send it over to the OEAP box and watch what happens..&lt;/P&gt;&lt;P&gt;All but 2 of my oe's are 602's and the wlc is not discoverable to an out-of-box unit..&amp;nbsp; they all log to the production system first and I will move it an observe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 21:26:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632354#M41227</guid>
      <dc:creator>David Ritter</dc:creator>
      <dc:date>2015-02-03T21:26:45Z</dc:date>
    </item>
    <item>
      <title>I don't know what to tell you</title>
      <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632355#M41228</link>
      <description>&lt;P&gt;I don't know what to tell you..&amp;nbsp; My 3062 landed on the productions system and I redirected it to the OE system and the out-of-box apgroup.&amp;nbsp; It took about 10 mins for it to roll over and decide to stay.&amp;nbsp; I bet it tries the outside ip a few times then gives up and stays on the inside.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 22:13:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632355#M41228</guid>
      <dc:creator>David Ritter</dc:creator>
      <dc:date>2015-02-03T22:13:07Z</dc:date>
    </item>
    <item>
      <title>Ok, today we decided to block</title>
      <link>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632356#M41229</link>
      <description>&lt;P&gt;Ok, today we decided to block the ability for internal APs to join the public ip. I will see if that helps. I keep u in the loop.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2015 20:24:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-nat-feature-problem-for-oeap/m-p/2632356#M41229</guid>
      <dc:creator>Sebastian Helmer</dc:creator>
      <dc:date>2015-02-04T20:24:46Z</dc:date>
    </item>
  </channel>
</rss>

