<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS-Problem WLC guest-WLAN in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/dns-problem-wlc-guest-wlan/m-p/2285481#M43116</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, does it make sense to change the virtual IP to 2.2.2.2, 3.3.3.3 or whatever instead of 1.1.1.1?&lt;/P&gt;&lt;P&gt;How do I know which IP is not given out by the IANA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Sep 2013 13:57:40 GMT</pubDate>
    <dc:creator>Mike Farnschlaeder</dc:creator>
    <dc:date>2013-09-20T13:57:40Z</dc:date>
    <item>
      <title>DNS-Problem WLC guest-WLAN</title>
      <link>https://community.cisco.com/t5/wireless/dns-problem-wlc-guest-wlan/m-p/2285479#M43114</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the following problem with Cisco 2504 WLAN Controller.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A customer of mine bought a certificate (GlobalSign) for the guest-wlan. This certificate was successfully&lt;BR /&gt;implemented by me.&lt;BR /&gt;But now I´m having&amp;nbsp; problems with the DNS lookup (1.1.1.1 / wlan.mycustomer.de), because they don´t have any DNS-Server in their&lt;BR /&gt;WLAN-network. This network it completely physically seperated from their other networks. The WLAN-clients are going straight&lt;BR /&gt;to the router and internet respectively. &lt;/P&gt;&lt;P&gt;So I am not able to do a port forwarding of DNS via firewall into their main network.&lt;BR /&gt;The router is a AVM Fritzbox and unfortunately it is not possible to make any DNS host entries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what can I do? Any ideas?&lt;/P&gt;&lt;P&gt;They will not install any DNS-Server in this WLAN network!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Somebody told me that it is possible to make an A-record for the 1.1.1.1 at the provider´s side where the domain is located. But to be honest, I don´t know how this should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help!&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 07:53:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dns-problem-wlc-guest-wlan/m-p/2285479#M43114</guid>
      <dc:creator>Mike Farnschlaeder</dc:creator>
      <dc:date>2021-07-04T07:53:49Z</dc:date>
    </item>
    <item>
      <title>DNS-Problem WLC guest-WLAN</title>
      <link>https://community.cisco.com/t5/wireless/dns-problem-wlc-guest-wlan/m-p/2285480#M43115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can request your provider to put in the A-record for you, and as it is linked to your customers domain, it should be fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only thing I caution against is that IANA gave out the 1.x/8 subnet to a company.&amp;nbsp; So it is possible they could look out there and request that all records using their IP range be removed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH, &lt;BR /&gt;Steve &lt;BR /&gt; &lt;BR /&gt;------------------------------------------------------------------------------------------------ &lt;BR /&gt;Please remember to rate useful posts, and mark questions as answered&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Sep 2013 13:35:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dns-problem-wlc-guest-wlan/m-p/2285480#M43115</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2013-09-20T13:35:51Z</dc:date>
    </item>
    <item>
      <title>DNS-Problem WLC guest-WLAN</title>
      <link>https://community.cisco.com/t5/wireless/dns-problem-wlc-guest-wlan/m-p/2285481#M43116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, does it make sense to change the virtual IP to 2.2.2.2, 3.3.3.3 or whatever instead of 1.1.1.1?&lt;/P&gt;&lt;P&gt;How do I know which IP is not given out by the IANA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Sep 2013 13:57:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dns-problem-wlc-guest-wlan/m-p/2285481#M43116</guid>
      <dc:creator>Mike Farnschlaeder</dc:creator>
      <dc:date>2013-09-20T13:57:40Z</dc:date>
    </item>
    <item>
      <title>DNS-Problem WLC guest-WLAN</title>
      <link>https://community.cisco.com/t5/wireless/dns-problem-wlc-guest-wlan/m-p/2285482#M43117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can go and check the IANA website to see what addresses are not assigned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I would just use 192.0.2.x/24 as this is reserved for documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH, &lt;BR /&gt;Steve &lt;BR /&gt; &lt;BR /&gt;------------------------------------------------------------------------------------------------ &lt;BR /&gt;Please remember to rate useful posts, and mark questions as answered&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Sep 2013 14:04:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dns-problem-wlc-guest-wlan/m-p/2285482#M43117</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2013-09-20T14:04:34Z</dc:date>
    </item>
    <item>
      <title>DNS-Problem WLC guest-WLAN</title>
      <link>https://community.cisco.com/t5/wireless/dns-problem-wlc-guest-wlan/m-p/2285483#M43118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the guest traffic is going straight out to the Internet, then you need to be able to resolve the FQDN of the certificate to the VIP of the WLC.&amp;nbsp; If they don't have an external DNS server and you have to actually have the company who manages their external domain, make an entry for their FQDN of the certificate to be used.&amp;nbsp; The VIP now has to be tied to one of their public address.&amp;nbsp; This works, because I have had to do this many times because of either, no company owned external DNS server, they don't want to open a port on the FW to allow DNS internally and or the service provider will not add a bogus IP address in an a-record.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt; &lt;BR /&gt;Scott &lt;BR /&gt; &lt;BR /&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Sep 2013 13:30:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dns-problem-wlc-guest-wlan/m-p/2285483#M43118</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-09-22T13:30:07Z</dc:date>
    </item>
  </channel>
</rss>

