<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wireless 877W in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wireless-877w/m-p/564592#M87136</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The common configuration for this type of scenario is to bridge the VLAN1 and Dot11radio interfaces together in order to place both wired and wireless clients on the same VLAN/network.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the customer's requirement is to allow both static WEP128 and PEAP clients to co-exist on a single SSID, then that's not going to work.  PEAP uses dynamic encryption keys, so when EAP is configured on the SSID, the encryption keys are dynamic. You'd have to create a separate SSID on a separate VLAN to support static WEP in addition to PEAP on the same router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try reconfiguring (based upon your attached configs) as follows to support PEAP on VLAN 1 (use CONSOLE port, not telnet when configuring):&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;bridge irb&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;int do 0&lt;/P&gt;&lt;P&gt;no encryption key 1&lt;/P&gt;&lt;P&gt;no encryption mode wep mandatory&lt;/P&gt;&lt;P&gt;encryption vlan 1 mode wep mandatory&lt;/P&gt;&lt;P&gt;no bridge-group 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;int do 0.1&lt;/P&gt;&lt;P&gt;bridge-group 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;int vlan 1&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;bridge-group 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;int bvi 1&lt;/P&gt;&lt;P&gt;ip address 172.16.0.97 255.255.255.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip radius source-interface bvi 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;bridge 1 route ip&lt;/P&gt;&lt;P&gt;bridge 1 protocol ieee&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;*******************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 'radius source-interface bvi 1' forces the router to use 172.0.16.97 as the source of all RADIUS packets; therefore, you want to make sure the ACS Server has this router configured as an AAA Client with ip address 172.0.16.97.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try this out, if it works, then do a 'wr mem' on the router to save the config to nvram.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 10 Feb 2007 01:57:29 GMT</pubDate>
    <dc:creator>Benjamin Solero</dc:creator>
    <dc:date>2007-02-10T01:57:29Z</dc:date>
    <item>
      <title>Wireless 877W</title>
      <link>https://community.cisco.com/t5/wireless/wireless-877w/m-p/564589#M87133</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I posted a question a week or so ago about setting up an 877W with wireless and VPN back to headend site.  The requirement is for the remote site (5 + users) to VPN to main site but have wireless locally with authentication via PEAP into headend site were ACS into AD is configured. I have installed the Router, but at the minute only with VPN access.  I was not able to get the wireless working!  I'm having issues with the BVI/Radio/Vlan interfaces.  The remote site is to only have one subnet with some wireless and some not.  My subnet is 172.16.0.96/28.  Do i only need one Ip address on the router, as i can't assign the Vlan and BVI interface in the same subnet?  Should my Default Gateway be the BVI Interface?  I have also configured WEP 128 (Customer asked for) but Windows displays this an 'Open Network' and only one laptop can see it? And this can't connect.  i tried to forget the PEAP and just get wireless working locally for some security but with no luck &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have posted the config, can somebody help me and tell me what i have done wrong?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help is appreciated!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 19:48:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-877w/m-p/564589#M87133</guid>
      <dc:creator>andrew100</dc:creator>
      <dc:date>2021-07-04T19:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless 877W</title>
      <link>https://community.cisco.com/t5/wireless/wireless-877w/m-p/564590#M87134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Two subnets one for each interface.If only one laptop can see it,try  changing the channel numbers.PEAP is supported only in win Xp.Laptops not running win XP cant connect.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2006 13:20:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-877w/m-p/564590#M87134</guid>
      <dc:creator>mchin345</dc:creator>
      <dc:date>2006-08-11T13:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless 877W</title>
      <link>https://community.cisco.com/t5/wireless/wireless-877w/m-p/564591#M87135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm struggling with excatly the same problem. Got a few access points on our LAN using PEAP fine but can't seem to get it working on a 877w. Can get the VPN connection back to our concentrator working. Has anyone got any ideas.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Feb 2007 13:43:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-877w/m-p/564591#M87135</guid>
      <dc:creator>pbroa1iss</dc:creator>
      <dc:date>2007-02-09T13:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless 877W</title>
      <link>https://community.cisco.com/t5/wireless/wireless-877w/m-p/564592#M87136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The common configuration for this type of scenario is to bridge the VLAN1 and Dot11radio interfaces together in order to place both wired and wireless clients on the same VLAN/network.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the customer's requirement is to allow both static WEP128 and PEAP clients to co-exist on a single SSID, then that's not going to work.  PEAP uses dynamic encryption keys, so when EAP is configured on the SSID, the encryption keys are dynamic. You'd have to create a separate SSID on a separate VLAN to support static WEP in addition to PEAP on the same router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try reconfiguring (based upon your attached configs) as follows to support PEAP on VLAN 1 (use CONSOLE port, not telnet when configuring):&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;bridge irb&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;int do 0&lt;/P&gt;&lt;P&gt;no encryption key 1&lt;/P&gt;&lt;P&gt;no encryption mode wep mandatory&lt;/P&gt;&lt;P&gt;encryption vlan 1 mode wep mandatory&lt;/P&gt;&lt;P&gt;no bridge-group 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;int do 0.1&lt;/P&gt;&lt;P&gt;bridge-group 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;int vlan 1&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;bridge-group 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;int bvi 1&lt;/P&gt;&lt;P&gt;ip address 172.16.0.97 255.255.255.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip radius source-interface bvi 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;bridge 1 route ip&lt;/P&gt;&lt;P&gt;bridge 1 protocol ieee&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;*******************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 'radius source-interface bvi 1' forces the router to use 172.0.16.97 as the source of all RADIUS packets; therefore, you want to make sure the ACS Server has this router configured as an AAA Client with ip address 172.0.16.97.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try this out, if it works, then do a 'wr mem' on the router to save the config to nvram.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Feb 2007 01:57:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-877w/m-p/564592#M87136</guid>
      <dc:creator>Benjamin Solero</dc:creator>
      <dc:date>2007-02-10T01:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless 877W</title>
      <link>https://community.cisco.com/t5/wireless/wireless-877w/m-p/564593#M87137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;That?s a great help, but I'm still having problems getting peap working. I have checked our firewall and the ACS server and am not getting any failed attempts but I am getting failed attempts when I remove the AAA account so I know it's hitting the ACS server. According to the debugging on the router It looks to be a problem with the shared key, but I have checked and doubled checked that. I have attached both the router config and the debugging. Can anyone shed any light? Thanks is advance,&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Feb 2007 11:54:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-877w/m-p/564593#M87137</guid>
      <dc:creator>pbroa1iss</dc:creator>
      <dc:date>2007-02-13T11:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless 877W</title>
      <link>https://community.cisco.com/t5/wireless/wireless-877w/m-p/564594#M87138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Phil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using NDG's on your AAA server?  Your Pre-shared key is that of the NDG?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Feb 2007 12:22:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-877w/m-p/564594#M87138</guid>
      <dc:creator>andrew100</dc:creator>
      <dc:date>2007-02-13T12:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: Wireless 877W</title>
      <link>https://community.cisco.com/t5/wireless/wireless-877w/m-p/564595#M87139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it sits in the NDG authenticating using RADIUS (cisco aironet)&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Feb 2007 13:09:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-877w/m-p/564595#M87139</guid>
      <dc:creator>pbroa1iss</dc:creator>
      <dc:date>2007-02-13T13:09:49Z</dc:date>
    </item>
  </channel>
</rss>

