cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2634
Views
0
Helpful
6
Replies

How To Configuration Ip Helper in Cisco Aironet 1040

azmimml123
Level 1
Level 1

First I give info to my enviroment network.

eviroment network.JPG

Server PT Server0 = this is DHCP server

Switch0 = main switch with 6 vlan.

vlan 110 - Reserve

vlan 111 -  Equipment network

vlan 112 - Server

Vlan 113 - printer

Vlan 114 - Main-Staff

Vlan 115 - Guest

Vlan 116 - Editorial

Switch1 = Editorial with 6 vlan.

vlan 110 - Reserve

vlan 111 -  Equipment network

vlan 112 - Server

Vlan 113 - printer

Vlan 114 - Main-Staff

Vlan 115 - Guest

Vlan 116 - Editorial

Cisco Switch = Bookcafe switch with 6 vlan.

vlan 110 - Reserve

vlan 111 -  Equipment network

vlan 112 - Server

Vlan 113 - printer

Vlan 114 - Main-Staff

Vlan 115 - Guest

Vlan 116 - Editorial

AP Cisco AiroNet 1040 in Cisco Switch

This configuration In AP

Current configuration : 4818 bytes

!

version 12.4

no service pad

service timestamps debug datetime msec

service timestamps log datetime msec

service password-encryption

!

hostname PTSBookCafe-AP-2F

!

logging rate-limit console 9

enable secret 5 $1$m9Wp$g7GhXuKDHpXKiIv2gAyug1

!

no aaa new-model

clock timezone GMT 8

!

!

dot11 syslog

!

dot11 ssid PTS-Bookcafe

   vlan 116

   authentication open

   mbssid guest-mode

!

dot11 ssid PTS-Bookcafe-Guest

   vlan 115

   authentication open

   mbssid guest-mode

!

dot11 ssid PTS-Bookcafe-Staff

   vlan 114

   authentication open

   mbssid guest-mode

!

!

!

username Cisco password 7 112A1016141D

username pts privilege 15 password 7 010315564B1F15

username packetsys privilege 15 password 7 105E1A4B150301

!

!

bridge irb

!

!

interface Dot11Radio0

no ip address

no ip route-cache

!

encryption vlan 115 key 1 size 40bit 7 958FE32074A1 transmit-key

encryption vlan 115 mode wep mandatory

!

encryption vlan 114 key 1 size 40bit 7 FAB0830B1E1D transmit-key

encryption vlan 114 mode wep mandatory

!

encryption vlan 116 key 1 size 40bit 7 7DE78BE46993 transmit-key

encryption vlan 116 mode wep mandatory

!

ssid PTS-Bookcafe

!

ssid PTS-Bookcafe-Guest

!

ssid PTS-Bookcafe-Staff

!

antenna gain 0

mbssid

station-role root

bridge-group 1

bridge-group 1 subscriber-loop-control

bridge-group 1 block-unknown-source

no bridge-group 1 source-learning

no bridge-group 1 unicast-flooding

bridge-group 1 spanning-disabled

!

interface Dot11Radio0.114

encapsulation dot1Q 114

no ip route-cache

bridge-group 114

bridge-group 114 subscriber-loop-control

bridge-group 114 block-unknown-source

no bridge-group 114 source-learning

no bridge-group 114 unicast-flooding

bridge-group 114 spanning-disabled

!

interface Dot11Radio0.115

encapsulation dot1Q 115

no ip route-cache

bridge-group 115

bridge-group 115 subscriber-loop-control

bridge-group 115 block-unknown-source

no bridge-group 115 source-learning

no bridge-group 115 unicast-flooding

bridge-group 115 spanning-disabled

!

interface Dot11Radio0.116

encapsulation dot1Q 116

no ip route-cache

bridge-group 116

bridge-group 116 subscriber-loop-control

bridge-group 116 block-unknown-source

no bridge-group 116 source-learning

no bridge-group 116 unicast-flooding

bridge-group 116 spanning-disabled

!

interface Dot11Radio1

no ip address

no ip route-cache

shutdown

!

encryption vlan 115 key 1 size 40bit 7 4BE69C052F60 transmit-key

encryption vlan 115 mode wep mandatory

!

encryption vlan 114 key 1 size 40bit 7 3EC6360FB109 transmit-key

encryption vlan 114 mode wep mandatory

!

encryption vlan 116 key 1 size 40bit 7 72A8F72E7675 transmit-key

encryption vlan 116 mode wep mandatory

antenna gain 0

station-role root

bridge-group 1

bridge-group 1 subscriber-loop-control

bridge-group 1 block-unknown-source

no bridge-group 1 source-learning

no bridge-group 1 unicast-flooding

bridge-group 1 spanning-disabled

!

interface Dot11Radio1.114

encapsulation dot1Q 114

ip helper-address 192.168.0.4

no ip route-cache

bridge-group 114

bridge-group 114 subscriber-loop-control

bridge-group 114 block-unknown-source

no bridge-group 114 source-learning

no bridge-group 114 unicast-flooding

bridge-group 114 spanning-disabled

!

interface Dot11Radio1.115

encapsulation dot1Q 115

ip helper-address 192.168.0.4

no ip route-cache

bridge-group 115

bridge-group 115 subscriber-loop-control

bridge-group 115 block-unknown-source

no bridge-group 115 source-learning

no bridge-group 115 unicast-flooding

bridge-group 115 spanning-disabled

!

interface Dot11Radio1.116

encapsulation dot1Q 116

no ip route-cache

bridge-group 116

bridge-group 116 subscriber-loop-control

bridge-group 116 block-unknown-source

no bridge-group 116 source-learning

no bridge-group 116 unicast-flooding

bridge-group 116 spanning-disabled

!

interface GigabitEthernet0

no ip address

no ip route-cache

duplex auto

speed auto

no keepalive

bridge-group 1

no bridge-group 1 source-learning

bridge-group 1 spanning-disabled

!

interface GigabitEthernet0.114

encapsulation dot1Q 114

no ip route-cache

bridge-group 114

no bridge-group 114 source-learning

bridge-group 114 spanning-disabled

!

interface GigabitEthernet0.115

encapsulation dot1Q 115

no ip route-cache

bridge-group 115

no bridge-group 115 source-learning

bridge-group 115 spanning-disabled

!

interface GigabitEthernet0.116

encapsulation dot1Q 116

no ip route-cache

bridge-group 116

no bridge-group 116 source-learning

bridge-group 116 spanning-disabled

!

interface BVI1

ip address 192.168.11.80 255.255.255.0

no ip route-cache

!

ip default-gateway 192.168.11.254

ip http server

no ip http secure-server

ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag

bridge 1 route ip

!

!

!

line con 0

line vty 0 4

login local

!

end

In configuration...

Will i connect to Guest (VLAN115) DHCP working. but Will i connect to VLAN 114 and VLAN 116 DHCP not working. So how to doit..?

6 Replies 6

kcnajaf
Level 7
Level 7

HI Azmi,

Ip helpder need to be configured on the L3 interface and not on the AP. Hope you would have defined L3 interface for all the VLANs and you will have to configure the ip helper address in there. A typical config would be as below.

int vlan115

ip address x.x.x.x

ip helper-address 192.168.0.4

!

int vlan114

ip address x.x.x.x

ip helper-address 192.168.0.4

!

int vlan116

ip address x.x.x.x

ip helper-address 192.168.0.4

Also you need to ensure that switch port to which AP is connected is configured as trunk and you have allowed all the desired vlans on the trunk.

Hope that helps.

Regards

Najaf

Please rate when applicable or helpful !!!

Thanks Najaf KC.

before that. DHCP working on Aironet 1040. after restart no working.

On Vlan 115 working, but Vlan 114 and 116 dhcp not working. I suspec device not save in configuration.

Hi,

Are the wired clients able to get the DHCP ip address from VLAN 114 and VLAN 116? You can check this by configuring one of the switch port (on the same switch where the AP is connected) to these vlans and connecting a PC to this.

Could you please share the switch port configuration where the AP is connected?

Hope that helps.

Regards

Najaf

Please rate when applicable or helpful !!!

Hii this client use AP. but IN AP I configure virtual Port

Dot11Radio1.114 (for VLAN 114)

Dot11Radio1.115 (for VLAN 115)

Dot11Radio1.116 (for VLAN 116)

AP conect to PORT in switch Catalyst 2960-C Series.

This Switchport configuration

Using 2414 out of 65536 bytes

!

version 12.2

no service pad

service timestamps debug datetime msec

service timestamps log datetime msec

service password-encryption

!

hostname PTSBookCafe-SW-2F

!

boot-start-marker

boot-end-marker

!

enable secret 5 XXXXXXXXXXXXXXXXXXXXX

!

username pts privilege 15 password 7 XXXXXXXXXXXXX

username packetsys privilege 15 password 7 XXXXXXXXXXXXX

!

!

no aaa new-model

clock timezone GMT 8

system mtu routing 1500

!

!

ip domain-name pts.com.my

!

!

crypto pki trustpoint TP-self-signed-4189828096

enrollment selfsigned

subject-name cn=IOS-Self-Signed-Certificate-4189828096

revocation-check none

rsakeypair TP-self-signed-4189828096

!

!

crypto pki certificate chain TP-self-signed-4189828096

certificate self-signed 01 nvram:IOS-Self-Sig#3636.cer

spanning-tree mode pvst

spanning-tree extend system-id

!

!

!

!

vlan internal allocation policy ascending

!

ip ssh version 2

!

!

interface FastEthernet0/1

description ***Connected to AP***

switchport trunk native vlan 111

switchport mode trunk

!

interface FastEthernet0/2

description ***Connected to AP***

switchport trunk native vlan 111

switchport mode trunk

!

interface FastEthernet0/3

description ***Connected to CCTV***

switchport access vlan 112

switchport mode access

!

interface FastEthernet0/4

description ***Connected to CCTV***

switchport access vlan 112

switchport mode access

!

interface FastEthernet0/5

description ***Connected to Printer***

switchport access vlan 113

switchport mode access

!

interface FastEthernet0/6

description ***Connected to Printer***

switchport access vlan 113

switchport mode access

!

interface FastEthernet0/7

description ***Connected to Server***

switchport access vlan 112

switchport mode access

!

interface FastEthernet0/8

description ***Connected to Server***

switchport access vlan 112

switchport mode access

!

interface GigabitEthernet0/1

description ***Trunk to Main Building***

switchport mode trunk

media-type sfp

!

interface GigabitEthernet0/2

!

interface Vlan1

no ip address

shutdown

!

interface Vlan111

description ***Network Management***

ip address 192.168.11.247 255.255.255.0

!

ip default-gateway 192.168.11.254

ip http server

ip http secure-server

ip sla enable reaction-alerts

!

line con 0

exec-timeout 5 0

login local

line vty 0 4

exec-timeout 5 0

login local

transport input telnet

line vty 5 15

exec-timeout 5 0

login local

transport input ssh

!

end

Hi Azmi,

It looks like you are using native vlan 111 under the switch port and you dont have native vlan defined on the AP. Try modifing AP config as below

interface Dot11Radio0.111

encapsulation dot1Q 111 native

no ip route-cache

bridge-group 1


interface GigabitEthernet0.111

encapsulation dot1Q 111 native

no ip route-cache

bridge-group 1

Hope that helps

Regards

Najaf

Please rate when applicable or helpful !!!

AP connect to Interface Fa0/2. not Fa0/1