11-12-2019 01:16 PM - edited 07-05-2021 11:18 AM
Hello,
I have a Cisco 3702i AP at home connected to my Ubiquiti switch as a trunk. If I log onto the AP it can ping all my VLAN gateways so I'm please that works. I can see the SSIDs, but when I try and connect I don't get prompted for the password, what have I done wrong? I wanted both SSIDs on the same VLAN, but I don't think this is possible. So I've tried to set them to VLAN 140 and 141.
Can you see anything wrong?
hostname Cisco-AP2 ! ! logging rate-limit console 9 ! no aaa new-model no ip source-route no ip cef ip domain name home.andy-white.co.uk ! ! ! ! dot11 pause-time 100 dot11 syslog ! dot11 ssid MyNet-2.4Ghza vlan 141 authentication open authentication key-management wpa version 2 guest-mode wpa-psk ascii 7 xxx ! dot11 ssid MyNet-5Ghza vlan 140 authentication open authentication key-management wpa version 2 guest-mode wpa-psk ascii 7 xxx ! ! dot11 ids mfp detector ! power inline negotiation prestandard source no ipv6 cef ! bridge irb ! ! ! interface Dot11Radio0 no ip address ! encryption vlan 141 mode ciphers aes-ccm ! ssid MyNet-2.4Ghza ! antenna gain 0 stbc mbssid speed basic-1.0 2.0 5.5 11.0 6.0 9.0 12.0 18.0 24.0 36.0 48.0 54.0 m0. m1. m2. m3. m4. m5. m6. m7. m8. m9. m10. m11. m12. m13. m14. m15. m16. m17. m18. m19. m20. m21. m22. m23. station-role root ! interface Dot11Radio0.141 encapsulation dot1Q 141 bridge-group 141 bridge-group 141 subscriber-loop-control bridge-group 141 spanning-disabled bridge-group 141 block-unknown-source no bridge-group 141 source-learning no bridge-group 141 unicast-flooding ! interface Dot11Radio0.254 encapsulation dot1Q 254 native bridge-group 1 bridge-group 1 subscriber-loop-control bridge-group 1 spanning-disabled bridge-group 1 block-unknown-source no bridge-group 1 source-learning no bridge-group 1 unicast-flooding ! interface Dot11Radio1 no ip address ! encryption vlan 141 mode ciphers aes-ccm ! ssid MyNet-5Ghza ! antenna gain 0 peakdetect no dfs band block stbc mbssid channel width 40-below channel dfs station-role root ! interface Dot11Radio1.140 encapsulation dot1Q 140 bridge-group 140 bridge-group 140 subscriber-loop-control bridge-group 140 spanning-disabled bridge-group 140 block-unknown-source no bridge-group 140 source-learning no bridge-group 140 unicast-flooding ! interface Dot11Radio1.254 encapsulation dot1Q 254 native bridge-group 1 bridge-group 1 subscriber-loop-control bridge-group 1 spanning-disabled bridge-group 1 block-unknown-source no bridge-group 1 source-learning no bridge-group 1 unicast-flooding ! interface GigabitEthernet0 no ip address duplex auto speed auto bridge-group 1 bridge-group 1 spanning-disabled no bridge-group 1 source-learning ! interface BVI1 mac-address 80e0.1dc6.508c ip address 192.168.254.8 255.255.255.0 ipv6 address dhcp ipv6 address autoconfig ipv6 enable ! ip default-gateway 192.168.254.1 ip forward-protocol nd ip http server ip http secure-server ! access-list 111 permit tcp any any neq telnet bridge 1 route ip
Thanks
11-12-2019 09:34 PM
Hi Andrew,
Try this config & see
interface GigabitEthernet0.140
encapsulation dot1Q 140
bridge-group 140
!
interface GigabitEthernet0.141
encapsulation dot1Q 141
bridge-group 141
!
interface GigabitEthernet0.254
encapsulation dot1Q 254 native
bridge-group 1
!
HTH
Rasika
*** Pls rate all useful responses ***
11-13-2019 04:11 AM
11-13-2019 08:53 AM
11-13-2019 12:05 PM
I mean add those sub-interfaces to Gigabit Ethernet (simply add those config lines to your configuration, not to replace your existing configs)
HTH
Rasika
11-13-2019 01:10 PM
Interesting, I get a password prompt now it logs on, I get a 169.x.x.x so I need to sort my DHCP which is enable on that VLAN.
I don't see he other SSID broadcasting anymore now though (MyNet-5Ghza).
11-13-2019 03:53 PM
11-13-2019 10:28 PM
11-17-2019 03:28 AM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: