Dhiresh Yadav is a wireless expert and working for the Cisco's High Touch Technical Support (HTTS) team, a team that provides reactive technical support to majority of Cisco’s premium customers. In this document Dhiresh has explained configuration steps required for a Web-auth SSID to allow a VPN user without needing a full web-auth authentication and still not get disconnected after every few minutes.
How to configure the Wireless LAN Controller for basic operation and Web-auth.
Cisco 5500 Series WLC that runs firmware Version 126.96.36.199.
Note: The Configuration and web-auth explanation provided below is applicable to all WLC models and any CUWN image equal to or above 188.8.131.52.
In a Customer network setup ,there are sometimes requirements to allow VPN by connecting to a Web-auth enabled wlan without authentication and hence finish web-authentication.VPN traffic is allowed by a Pre-auth ACl and hence VPN users can connect to the web-auth SSID without requiring authentication.This SSID might be in use by another set of users also who go through normal and full authentication to get the Internet access.The problem for these VPN users is that they pick the ip address but never finish complete authentication while connecting to VPN , So instead of session timeout , Web-auth timeout kicks in and the client is deauthenticated.
The value of this timer is 5 Minutes and has a fixed value till 7.6 WLC image.So it will make the wireless network nearly unusable for these kind of users because of this low web-auth session timeout value. The capability to change this value is added in 8.0. So if the client is not hitting the Idle timeout , it can access VPN via Pre-auth ACL allowed traffic and need not to go through Web-authentication or face disconnection for a longer period of time.
Configure the WLC
Complete the following configuration in order to configure the WLC for this setup:
Two C9800s work as HA. Please see the below picture. In one of the two wlc, number 15 light is off and is red on the second wlc. Number 15 is "Alam LED" based on the description. Do you think its normal? why it happen? Thank you
Someone sent me this link to look at, but it is no longer available. Anyone know where I can find more info? Cisco wireless 3D analyzer: A game changer in simplifying WiFi planning, monitoring, and troubleshooting https://blogs.cisco.com/networ...
I am currently trying to figure our how to create an uptime report on Prime, i have created reports for ASA, switches, and routers that show their true uptime (via the Last Boot Time data field), but cant seem to find anything similar for WLC's or AP's.&n...
Hello Cisco Community, I have two pairs of Cisco 8510 Controllers with software version: 184.108.40.206. These Controllers generate more than 50.000 of the following log messages per hour: [SA]apf_utils.c:219 Could not check supported rates...
So i had a tough time defining the AP settings cisco air-cap1702i-e-k9 d, I managed to set 2.4Ghz and 5Ghz wireless networks the only issue that speed is extremely low , I have on my direct wifi connection 200MB while in Cisco net bare...