The Cisco Document Team has posted an article. This document describes the FlexConnect feature and its general configuration on Catalyst 9800 Wireless Controllers. Know of something that needs documenting? Share a new document ...
The Cisco Document Team has posted an article. This document describes the FlexConnect feature and its general configuration on Catalyst 9800 Wireless Controllers. Know of something that needs documenting? Share a new document ...
The Cisco Document Team has posted an article. This document describes the common issues with clients connecting to a WLAN with Local Web Authentication (LWA). Know of something that needs documenting? Share a new document requ...
The Cisco Document Team has posted an article. This document describes how to decode a certificate with well-known online tools & their interpretation to create a certificate chain in the 9800 WLC. Know of something that needs ...
Sometimes we are just asked for assistance to configure a secure WLAN doing authentication against a “server” (most of the time trying to simulate what they already have on wired, normally for authentication of the domain users), but having no idea t...
The Cisco Document Team has posted an article. This document describes the syslog message 'Unregistered 9800-CL can only be used in lab' and how to resolve it. Know of something that needs documenting? Share a new document requ...
OverviewConfigurationCreate a CSV File With a List of All the APs Joined to the 9800Verifying theCSV File Will Work with the EEM AppletsBreakdown of the Enabling and Disabling EEM AppletsMonitoring the Applet Overview On the Cisco Catalyst 9800 Seri...
The Cisco Document Team has posted an article. This document describes in detail the Access Point Image download process for non-homogeneous EWC networks with TFTP and SFTP Servers. Know of something that needs documenting? Sha...
The Cisco Document Team has posted an article. This document describes how to detect and locate a rogue access point or a rogue client with the use of the 9800 wireless controller. Know of something that needs documenting? Shar...
The Cisco Document Team has posted an article. This document describes how to configure 9800 Wireless Lan Controllers (WLC) with a mobility tunnel over Network Address Translation (NAT). Know of something that needs documenting...
The Cisco Document Team has posted an article. This document describes the ISSU upgrade pre-checklist and how to troubleshoot potential issues on the Cisco Catalyst 9800 Series Wireless Controller. Know of something that needs ...
The Cisco Document Team has posted an article. This document describes the different outcomes when you enable/disable fast roam methods on the wireless clients. Know of something that needs documenting? Share a new document req...
The Cisco Document Team has posted an article. This document describes the different types of certificates and trustpoints that can be used on the 9800 WLC. Know of something that needs documenting? Share a new document request...
Access Point ROMMON Recovery AP: prompt Recovery Here is the step by step procedure for 1140 series AP.. Its the same for almost 90% or all the Aironet product series Image usedc1140-k9w7-tar.124-21a.JY.tar Assumin...
The Cisco Document Team has posted an article. This document describes the flow for the end client undergoes when connecting to a CWA WLAN. Know of something that needs documenting? Share a new document request to doc-ic-feedba...
The Cisco Document Team has posted an article. This document describes in detail the AP Join Process with the Cisco Catalyst 9800 WLC. Know of something that needs documenting? Share a new document request to doc-ic-feedback@ci...
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:
Implementing DHCP Option 43 and Option 60 in external MS-DHCP Server using Vendor Class Identifier.
Challenge - How to find Cisco device Vendor Class Identifier
Procedure
Step 1
Implement DHCP Server in Windows Server (Ver. any)
Step 2
Install Wireshark Network Protocol Analyzer (Packet tracer) in the Windows Server machine where the DHCP server is running.
After installation select “Ethernet” connection and start packet capturing.
Step 3
Connect Cisco device (AP/ LWAP/ Switch/ Router). Configure to devices ethernet interfaces “ip address” should be obtained from DHCP server therefore ethernet interface should be configured as “ip address dhcp”
The connected device starts sending broad casting message packets with its MAC address to lease IP address from DHCP server.
Wireshark packet tracer already started and capture ethernet packets, it will show the connected MAC address send broadcast message to DHCP server. DHCP server captured the broadcast message and replied to the device.
If you select the first line of broadcast message of the device in Wireshark packet analyzer, you can easily identify Vendor Class Identifier in left side bottom part of the window.
Wiershark AP3702 packet capturing
Implementing DHCP option 43 and 60
The generic vendor class identification option is 43. Each vendor has been given a unique vendor identification number in decimal. “241” is used for Cisco Management controller. When it converts to hexadecimal “F1 or f1”.
Conversion decimal to hexadecimal:
241 ÷ 16 = 15 R 1 —> (0.0625 x 16) = 1 = 1
15 ÷ 16 = 0 R 15 —> (0.9375 x 16) = 15 = f
When it writes to hexadecimal writes to bottom to top as a “f 1”
Internal DHCP pool configuration
Internal DHCP pool in Cisco router or switch can use as follows:
ip dhcp pool VLAN20
network 172.168.10.0 255.255.255.0
default-router 172.168.10.1
dns-server 83.68.72.2
option 43 hex f104aca80a02 <= 04-indicates one controller/aca80a02-“controller ip:172.168.10.2 in hexadecimal”
option 60 ascii “Cisco AP c3700”
External MS_Windows Server DHCP configuration.
Windows Server DHCP
Step 1
Open DHCP Server in Windows Server (Ver. any)
Expand the DHCP network scope under IPv4
Select on IPv4 and right click the mouse and chose “Define Vendor Classes”.
Define Vendor Class
Press “Add” button in DHCP Vendor Classes dialog box.
Click “Add” button in Predefined Options and Values dialog box.
Type Name as “WLC-4402” Wireless controller device, select Data type as “IP Address” and mark Array check box, Type Code as 241 (Management Controller) and Type the Description as Management Controller IP address allocation. Press “OK” button. This is an alternative method for DHCP option 43 in DHCP server and in internal DHCP pool in Cisco router or switch.
Then you will be back to the “Predefined Options and Values” dialog box. Press “Edit Array” button. “IP Address Array Editor” dialog box appears and can type number of controllers IP address if more than one WLC controller exist on your network in IP address space. Press “OK” button.
Select “Scope Options” under created network scope and right click on it, then click “Configure Options”.
AIR-CAP3702 console port connected to PC/Laptop USB port and using Cisco CLI analyzer or Putty can read IP status of both devices. (IPs in examples are not real. Above example IP address and below message IP addresses are two different VLANs IP addresses. Don't try to match IP's equality.)