cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3759
Views
0
Helpful
12
Replies

1130AG AP Issue

I have serveral 1130AG AP that when they are configured to use LWAPP all of my Motorola Handheld scanners connect to the SSIDs fine.

When I have some that are on Autonomous then the scanners will not connect at all.

I have upgraded a test 1130AG to the lates IOS and that does not help.

Any suggestions.

12 Replies 12

Scott Fella
Hall of Fame
Hall of Fame

Not enough information to help you here... You need to post your configuration for the autonomous AP and tell us what SSID the devices are using to connect.

Thanks,

Scott

Help out other by using the rating system and marking answered questions as "Answered"

-Scott
*** Please rate helpful posts ***

This is my config, neither SSID will connect via the scanners, but my phone will connect to either.

!

version 12.4

no service pad

service timestamps debug datetime msec

service timestamps log datetime msec

service password-encryption

!

hostname TESTWAP

!

enable secret 5 $1$7Sa0$E/ht0mNM7EYOo9ORkeCc2/

!

no aaa new-model

!

!

dot11 syslog

!

dot11 ssid GUESTTEST

   vlan 8

   authentication open

   guest-mode

!

dot11 ssid PRIVATE

   vlan 1

   authentication open

!

!

!

!

!

bridge irb

!

!

interface Dot11Radio0

no ip address

no ip route-cache

!

encryption key 1 size 128bit 7 A586DEC9AA12D1772BF8CF617842

encryption key 2 size 128bit 7 4586DEC9AA12D1772BF8CF617842 transmit-key

encryption key 3 size 128bit 7 93CEC7D386E2F7EB4AAC8D3D58E7

encryption key 4 size 128bit 7 990EC692BCBABCEA6A2ACBA5586E

!

ssid GUESTTEST

!

ssid PRIVATE

!

station-role root

rts threshold 2312

!

interface Dot11Radio0.1

encapsulation dot1Q 1 native

no ip route-cache

bridge-group 1

bridge-group 1 subscriber-loop-control

bridge-group 1 block-unknown-source

no bridge-group 1 source-learning

no bridge-group 1 unicast-flooding

bridge-group 1 spanning-disabled

!

interface Dot11Radio0.8

encapsulation dot1Q 8

no ip route-cache

bridge-group 8

bridge-group 8 subscriber-loop-control

bridge-group 8 block-unknown-source

no bridge-group 8 source-learning

no bridge-group 8 unicast-flooding

bridge-group 8 spanning-disabled

!

interface Dot11Radio1

no ip address

no ip route-cache

!

ssid GUESTTEST

!

ssid PRIVATE

!

dfs band 3 block

channel dfs

station-role root

!

interface Dot11Radio1.1

encapsulation dot1Q 1 native

no ip route-cache

bridge-group 1

bridge-group 1 subscriber-loop-control

bridge-group 1 block-unknown-source

no bridge-group 1 source-learning

no bridge-group 1 unicast-flooding

bridge-group 1 spanning-disabled

!

interface Dot11Radio1.8

encapsulation dot1Q 8

no ip route-cache

bridge-group 8

bridge-group 8 subscriber-loop-control

bridge-group 8 block-unknown-source

no bridge-group 8 source-learning

no bridge-group 8 unicast-flooding

bridge-group 8 spanning-disabled

!

interface FastEthernet0

no ip address

no ip route-cache

duplex auto

speed auto

!

interface FastEthernet0.1

encapsulation dot1Q 1 native

no ip route-cache

bridge-group 1

no bridge-group 1 source-learning

bridge-group 1 spanning-disabled

!

interface FastEthernet0.8

encapsulation dot1Q 8

no ip route-cache

bridge-group 8

no bridge-group 8 source-learning

bridge-group 8 spanning-disabled

!

interface BVI1

ip address 192.168.100.36 255.255.255.0

no ip route-cache

!

ip default-gateway 192.168.100.254

ip http server

no ip http secure-server

ip http help-path

http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag

bridge 1 route ip

!

!

!

line con 0

line vty 0 4

login local

line vty 5 15

login

!

end

so if you are using wep

you have to add the following commands under dot11radio configuration mode

encryption vlan 1 mode wep mandatory

encryption vlan 8 mode wep mandatory

encryption vlan 1 key .....

encryption vlan 8 key ..............

if you don't want to use wep , then there is no need to have:

encryption key 1 size 128bit 7 A586DEC9AA12D1772BF8CF617842

encryption key 2 size 128bit 7 4586DEC9AA12D1772BF8CF617842 transmit-key

encryption key 3 size 128bit 7 93CEC7D386E2F7EB4AAC8D3D58E7

encryption key 4 size 128bit 7 990EC692BCBABCEA6A2ACBA5586E

-----------------------------------------------------------------------

please make sure to rate correct answers

Not using WEP. Still no luck.

What are you using? What is setup on the WLC that works? On the WLC post the show WLAN

This way we can see how the SSID is configured since you mentioned that the devices connect fine to those APs.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

This is the WLAN config on the WLC that I need to use.


WLAN Identifier.................................. 4
Profile Name..................................... WIFIGUEST
Network Name (SSID).............................. PRIVATE
Status........................................... Enabled
MAC Filtering.................................... Disabled
Broadcast SSID................................... Enabled
AAA Policy Override.............................. Disabled
Network Admission Control
  Client Profiling Status ....................... Disabled
  Radius-NAC State............................... Disabled
  SNMP-NAC State................................. Disabled
  Quarantine VLAN................................ 0
Maximum number of Associated Clients............. 0
Maximum number of Clients per AP Radio........... 200
Number of Active Clients......................... 38
Exclusionlist Timeout............................ 60 seconds
Session Timeout.................................. 1800 seconds
CHD per WLAN..................................... Enabled
Webauth DHCP exclusion........................... Disabled
Interface........................................ wifi

--More-- or (q)uit
Multicast Interface.............................. Not Configured
WLAN IPv4 ACL.................................... unconfigured
WLAN IPv6 ACL.................................... unconfigured
DHCP Server...................................... Default
DHCP Address Assignment Required................. Disabled
Static IP client tunneling....................... Disabled
Quality of Service............................... Silver
Scan Defer Priority.............................. 4,5,6
Scan Defer Time.................................. 100 milliseconds
WMM.............................................. Allowed
WMM UAPSD Compliant Client Support............... Disabled
Media Stream Multicast-direct.................... Disabled
CCX - AironetIe Support.......................... Enabled
CCX - Gratuitous ProbeResponse (GPR)............. Disabled
CCX - Diagnostics Channel Capability............. Disabled
Dot11-Phone Mode (7920).......................... Disabled
Wired Protocol................................... None
Passive Client Feature........................... Disabled
Peer-to-Peer Blocking Action..................... Disabled
Radio Policy..................................... All
DTIM period for 802.11a radio.................... 1
DTIM period for 802.11b radio.................... 1
Radius Servers

--More-- or (q)uit
   Authentication................................ Global Servers
   Accounting.................................... Global Servers
      Interim Update............................. Disabled
   Dynamic Interface............................. Disabled
Local EAP Authentication......................... Disabled
Security

   802.11 Authentication:........................ Open System
   FT Support.................................... Disabled
   Static WEP Keys............................... Disabled
   802.1X........................................ Disabled
   Wi-Fi Protected Access (WPA/WPA2)............. Disabled
   Wi-Fi Direct policy configured................ Disabled
   EAP-Passthrough............................... Disabled
   CKIP ......................................... Disabled
   Web Based Authentication...................... Disabled
   Web-Passthrough............................... Disabled
   Conditional Web Redirect...................... Disabled
   Splash-Page Web Redirect...................... Disabled
   Auto Anchor................................... Disabled
   FlexConnect Local Switching................... Disabled
   FlexConnect Local Authentication.............. Disabled
   FlexConnect Learn IP Address.................. Enabled

--More-- or (q)uit
   Client MFP.................................... Optional but inactive (WPA2 not configured)
   Tkip MIC Countermeasure Hold-down Timer....... 60
Call Snooping.................................... Disabled
Roamed Call Re-Anchor Policy..................... Disabled
SIP CAC Fail Send-486-Busy Policy................ Enabled
SIP CAC Fail Send Dis-Association Policy......... Disabled
KTS based CAC Policy............................. Disabled
Band Select...................................... Disabled
Load Balancing................................... Disabled
Multicast Buffer................................. Disabled

Mobility Anchor List
WLAN ID     IP Address            Status
-------     ---------------       ------

802.11u........................................ Disabled
  Access Network type............................ Not configured
  Network Authentication type.................... Not configured
  Internet service............................... Disabled
  HESSID......................................... 00:00:00:00:00:00

Hotspot 2.0.................................... Disabled

from the WLAN config, that is an open WLAN.  If that is the case then:

conf t

int dot0

no encryption key 1 size 128bit 7 A586DEC9AA12D1772BF8CF617842

no encryption key 2 size 128bit 7 4586DEC9AA12D1772BF8CF617842 transmit-key

no encryption key 3 size 128bit 7 93CEC7D386E2F7EB4AAC8D3D58E7

no encryption key 4 size 128bit 7 990EC692BCBABCEA6A2ACBA5586E

end

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

Scott Fella
Hall of Fame
Hall of Fame

Add guest-mode on the PRIVATE SSID. That is how it's configured on the WLC.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

I have set the No command for the encryption and set the PRIVATE ssid to guest-mode with no luck. My scanners see the access point radio mac address, but will not connect.

that should work, teh WLAN from the WLC isn't running any encryption.  with removing those commands should do the same on the aIOS as well.

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

I reset the AP to factory default and setup:

one SSID  - no go.

one SSID with 1 VLAN - no go

This is frustrating.

Try with OPEN authentication and broadcasting SSID.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card