<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic general problem: WLAN to VLAN forwarding in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/general-problem-wlan-to-vlan-forwarding/m-p/1679025#M99305</link>
    <description>&lt;P&gt;Hello together,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try to find a general solution to the following problem:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco WLAN environment, &amp;gt;50 intelligent APs, &amp;gt;300 WLAN User, multiple SSIDs. Behind every SSID is a different VLAN. DHCP enabled on the clients. The users standard of knowledge does not provide the means to configure their WLAN Client. Users are in an active directory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;The objective:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The user must be able to connect to their VLAN without knowing the key of the corresponding SSID.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The momentary solution is an correspondingly hard konfigured WLAN Adapter with RJ45 connector which provides access to the requested SSID / VLAN.&lt;/P&gt;&lt;P&gt;To clarify: WLAN Adapter A -&amp;gt; Access to SSID A / VLAN A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WLAN Adapter B -&amp;gt; Access to SSID B / VLAN B&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now there are users with i.e. iPads without an RJ45 port, who should &lt;STRONG style="text-decoration: underline; "&gt;also&lt;/STRONG&gt; be able to connect to their VLANs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How can I do this?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought I could get a running 802.1X network based on a WLC 4402 and controlled APs, but if I enable 802.1X the old hard konfigured WLAN Adapters stop functioning because they do not support that standard. The withdrawal from service of the WLAN Adapters is not an option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone has suggestions, I would greatly appreciate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Sun, 04 Jul 2021 03:23:00 GMT</pubDate>
    <dc:creator>ahanstein</dc:creator>
    <dc:date>2021-07-04T03:23:00Z</dc:date>
    <item>
      <title>general problem: WLAN to VLAN forwarding</title>
      <link>https://community.cisco.com/t5/wireless/general-problem-wlan-to-vlan-forwarding/m-p/1679025#M99305</link>
      <description>&lt;P&gt;Hello together,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try to find a general solution to the following problem:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco WLAN environment, &amp;gt;50 intelligent APs, &amp;gt;300 WLAN User, multiple SSIDs. Behind every SSID is a different VLAN. DHCP enabled on the clients. The users standard of knowledge does not provide the means to configure their WLAN Client. Users are in an active directory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;The objective:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The user must be able to connect to their VLAN without knowing the key of the corresponding SSID.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The momentary solution is an correspondingly hard konfigured WLAN Adapter with RJ45 connector which provides access to the requested SSID / VLAN.&lt;/P&gt;&lt;P&gt;To clarify: WLAN Adapter A -&amp;gt; Access to SSID A / VLAN A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WLAN Adapter B -&amp;gt; Access to SSID B / VLAN B&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now there are users with i.e. iPads without an RJ45 port, who should &lt;STRONG style="text-decoration: underline; "&gt;also&lt;/STRONG&gt; be able to connect to their VLANs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How can I do this?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought I could get a running 802.1X network based on a WLC 4402 and controlled APs, but if I enable 802.1X the old hard konfigured WLAN Adapters stop functioning because they do not support that standard. The withdrawal from service of the WLAN Adapters is not an option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone has suggestions, I would greatly appreciate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 03:23:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/general-problem-wlan-to-vlan-forwarding/m-p/1679025#M99305</guid>
      <dc:creator>ahanstein</dc:creator>
      <dc:date>2021-07-04T03:23:00Z</dc:date>
    </item>
    <item>
      <title>general problem: WLAN to VLAN forwarding</title>
      <link>https://community.cisco.com/t5/wireless/general-problem-wlan-to-vlan-forwarding/m-p/1679026#M99306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andre,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the best solution to your problem would be to allow VLAN assignment via RADIUS. This way you can group users in AD and then create a policy on the RADIUS server to instruct the AP/WLC to assign a specific VLAN for that user. If you have devices that your organization does not control then it would be my recomendation to create a guest only SSID using web auth that provides Internet access only. To move forward with this solution I would recomend using either EAP-TLS or PEAP and group policy to automate the SSID configuration and certificate enrollment if needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jul 2011 16:44:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/general-problem-wlan-to-vlan-forwarding/m-p/1679026#M99306</guid>
      <dc:creator>b.garczynski</dc:creator>
      <dc:date>2011-07-01T16:44:23Z</dc:date>
    </item>
    <item>
      <title>general problem: WLAN to VLAN forwarding</title>
      <link>https://community.cisco.com/t5/wireless/general-problem-wlan-to-vlan-forwarding/m-p/1679027#M99307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree, since you are mentioning that your users are configured in AD, 802.1x with dynamic VLAN assignment is the best choice in your situation. This will also work for your ipads.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe you can give us some details what wlan NICs you are using and what exactly did not work when you tried .1x?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jul 2011 17:06:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/general-problem-wlan-to-vlan-forwarding/m-p/1679027#M99307</guid>
      <dc:creator>stefan.angerer</dc:creator>
      <dc:date>2011-07-01T17:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: general problem: WLAN to VLAN forwarding</title>
      <link>https://community.cisco.com/t5/wireless/general-problem-wlan-to-vlan-forwarding/m-p/1679028#M99308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;At first: thanks for the responses:&lt;/P&gt;&lt;P&gt;@b.garczynski&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/people/b.garczynski"&gt;What you described was my first intention, but if I understand it right Radius is only possible with 802.1X. But that´s unfortunately not supported by the WLAN adapters.&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@stefan.angerer&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;My "corpus delicti" is the Siemens Gigaset WLAN Repeater 108&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://gigaset.com/at/de/product/GIGASETWLANREPEATER108.html?tab=data"&gt;http://gigaset.com/at/de/product/GIGASETWLANREPEATER108.html?tab=data&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This Adapter does not support 802.1X and just crashes if it is assigned to an WLAN where the .1x standard is running. If it´s disabled, it`s doing its job.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@all&lt;/P&gt;&lt;P&gt;Furthermore the VLAN Association must be safe and flexible, so an Authentification via MAC or similar is also not an option.&lt;/P&gt;&lt;P&gt;Customers can be quite demanding...&lt;SPAN __jive_emoticon_name="angry" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/angry.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jul 2011 14:34:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/general-problem-wlan-to-vlan-forwarding/m-p/1679028#M99308</guid>
      <dc:creator>ahanstein</dc:creator>
      <dc:date>2011-07-04T14:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: general problem: WLAN to VLAN forwarding</title>
      <link>https://community.cisco.com/t5/wireless/general-problem-wlan-to-vlan-forwarding/m-p/1679029#M99309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;maybe you could try to use a dedicated 802.1x supplicant?&lt;/P&gt;&lt;P&gt;(e.g. Cisco Anyconnect 3.0 which is free)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jul 2011 10:28:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/general-problem-wlan-to-vlan-forwarding/m-p/1679029#M99309</guid>
      <dc:creator>stefan.angerer</dc:creator>
      <dc:date>2011-07-05T10:28:04Z</dc:date>
    </item>
    <item>
      <title>general problem: WLAN to VLAN forwarding</title>
      <link>https://community.cisco.com/t5/wireless/general-problem-wlan-to-vlan-forwarding/m-p/1679030#M99310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How about configure the WLAN adapters to associate to specific SSID in question by using PSK?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jul 2011 10:32:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/general-problem-wlan-to-vlan-forwarding/m-p/1679030#M99310</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2011-07-05T10:32:47Z</dc:date>
    </item>
    <item>
      <title>general problem: WLAN to VLAN forwarding</title>
      <link>https://community.cisco.com/t5/wireless/general-problem-wlan-to-vlan-forwarding/m-p/1679031#M99311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can't do dynamic VLAN with PSK.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jul 2011 10:34:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/general-problem-wlan-to-vlan-forwarding/m-p/1679031#M99311</guid>
      <dc:creator>stefan.angerer</dc:creator>
      <dc:date>2011-07-05T10:34:09Z</dc:date>
    </item>
    <item>
      <title>general problem: WLAN to VLAN forwarding</title>
      <link>https://community.cisco.com/t5/wireless/general-problem-wlan-to-vlan-forwarding/m-p/1679032#M99312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right, if we want to do dynamic VLAN assignment the only option is via RADIUS which then requires some type of EAP method for authentication. So from what I gather from the thread is that we cannot do 802.1x for authentication. This leaves us only with the option of an SSID per VLAN and a PSK for authentication. That said we can use configuration options such as HREAP and AP Groups to help keep the SSID configuration to a minimum across the network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jul 2011 16:16:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/general-problem-wlan-to-vlan-forwarding/m-p/1679032#M99312</guid>
      <dc:creator>b.garczynski</dc:creator>
      <dc:date>2011-07-05T16:16:22Z</dc:date>
    </item>
  </channel>
</rss>

