I have a WLC 5520 and I am looking to only allow Mac and Windows workstations access to the company wifi. I have configured a local policy and selected the types of devices I want to allow to connect. However, I am still able to connect devices that are not in the list I created (android, iphone, etc).
... View more
I currently have my APs terminated into 3850 Catalyst switches which run as Mobility Controllers. We purchased a 5520 WLC and I wanted to know if there is a way to move the APs over one by one to point to the new 5520 WLC. I ssh'd into the APs and set the primary-base controller to the 5520 and the secondary to the 3850 but that didn't seem to make a difference. Every time the AP reloads, it joins the 3850 controller. I know the controller works because I was able to point a separate AP to the 5520 that is terminated into a 3850 that is NOT running as a Mobility Controller. I set the primary controller to the IP of the 5520 and it joined with no issue.
... View more
Just an update. I did some ICMP debugging and found that the pings are being redirected to a bogus gateway IP and that is most likely causing the ping fails. We did some research and found this bug and this is exactly what we are experiencing. The gateway address showing up in the debug messages happens to be one digit off. So instead of it forwarding packets to something like 10.1.1.1, it's forwarding to 10.0.1.1. It's like it's nulling out the 2nd octet.
https://quickview.cloudapps.cisco.com/quickview/bug/CSCus28969
... View more
Hi,
Uptime is currently 240 days
I ran the sh command and found this:
class-map copp-system-class-icmp-echo (match-any) match protocol icmp_echo police cir 64 kbps , bc 3600000 bytes conformed 150309163572 bytes; action: transmit violated 4840309833 bytes;
... View more
I have 2 Nexus 5Ks that drop ping packets when pinging between them at 70-90% drop rate.
The ping drop rate also occurs for the following:
- Between access layer switches and 5Ks
- Between end user devices/servers and 5K
- Between PC and HSRP gateway address on 5K
No drops occur for following:
- From switch to switch passing through Nexus
- From PC to server passing though Nexus
- From PC to device on same network of HSRP gateway address
I am aware of the policing issue on the 5Ks but I don't think that is the case here. This just started happening recently and we've had the 5Ks for over 2 years now.
Any t-shooting or debug command ideas?
... View more
Rasika,
What is the purpose of creating a separate vlan just for the APs? And would they still function if they are on the Management Vlan?
... View more
Rasika,
If I went with a WLC like a 5760 or a 5520, can the WLC hang off of one of my core switches? Or does the WLC have to terminate into all of the 3850s? I was thinking I could just convert the 3850s into MAs and the MAs would detect the WLC on the network. Let me know if this is a viable option.
... View more
Thanks for the reply. I was leaning towards a similar setup as yours with having a 5760 act as the MC and just convert all of the 3850s to MAs. Seems to make the most sense.
... View more
Is it possible to have a 3850 running as an MC act as a WLC for an entire campus? I have multiple 3850 stacks throughout our campus with 3700 APs connected to them. Each stack runs as a Mobility Controller. I would like to centralize the wireless management if possible by having one MC be the WLC and have the other 3850s act as mobility agents.
... View more
I currently have 3 3850 stacks each on separate floor. Each one is running as a mobility controller with 4-6 APs connected to each controller. I'm looking for a way to centralize everything. Meaning, take a 3850 and turn it into the main mobility controller to administer the entire WLAN without having to have a separate controller for each set of APs.
... View more