cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
465
Views
0
Helpful
0
Replies

Clients not connecting with AP 1600 after configuration

jesnowakb
Level 1
Level 1

Hi there!!

 

I'm configuring a new Aironet 1600. I have to configure two SSIDs: Emplyees (vlan 40) and guests (vlan 45). Authentication for Employees is 802.1x against a RADIUS server and Guest is just WAP2. I'm trying to test the AP with the guest SSID (because I dont have the RADIUS server in my network), but the clients wont connect to the guest SSID. This is my first configuration and I used the web interface, not sure what I'm missing. Can you help?

 

dot11 ssid ECSA
   vlan 40
   band-select
   authentication open eap eap_methods
   authentication network-eap eap_methods
   mbssid guest-mode
   mobility network-id 1
!
dot11 ssid ECSA_GUEST
   vlan 45
   band-select
   authentication open
   authentication key-management wpa version 2
   guest-mode
   mbssid guest-mode
   mobility network-id 2
   wpa-psk ascii 7 106B050D1737065B0611393F74

 

interface Dot11Radio0
 no ip address
 !
 encryption vlan 45 mode ciphers aes-ccm
 !
 encryption vlan 40 mode wep optional
 !
 ssid ECSA
 !
 ssid ECSA_GUEST
 !
 antenna gain 0
 stbc
 beamform ofdm
 mbssid
 station-role root
 bridge-group 1
 bridge-group 1 subscriber-loop-control
 bridge-group 1 spanning-disabled
 bridge-group 1 block-unknown-source
 no bridge-group 1 source-learning
 no bridge-group 1 unicast-flooding
!
interface Dot11Radio0.40
 encapsulation dot1Q 40
 bridge-group 40
 bridge-group 40 subscriber-loop-control
 bridge-group 40 spanning-disabled
 bridge-group 40 block-unknown-source
 no bridge-group 40 source-learning
 no bridge-group 40 unicast-flooding

 

interface Dot11Radio0.45
 encapsulation dot1Q 45
 bridge-group 45
 bridge-group 45 subscriber-loop-control
 bridge-group 45 spanning-disabled
 bridge-group 45 block-unknown-source
 no bridge-group 45 source-learning
 no bridge-group 45 unicast-flooding
!
interface Dot11Radio1
 no ip address
 !
 encryption vlan 45 mode ciphers aes-ccm tkip
 !
 encryption vlan 40 mode wep optional
 !
 ssid ECSA
 !
 ssid ECSA_GUEST
 !
 antenna gain 0
 peakdetect
 dfs band 3 block
 stbc
 beamform ofdm
 mbssid
 channel dfs
 station-role root
 bridge-group 1
 bridge-group 1 subscriber-loop-control
 bridge-group 1 spanning-disabled
 bridge-group 1 block-unknown-source
 no bridge-group 1 source-learning
 no bridge-group 1 unicast-flooding
!
interface Dot11Radio1.40
 encapsulation dot1Q 40
 bridge-group 40
 bridge-group 40 subscriber-loop-control
 bridge-group 40 spanning-disabled
 bridge-group 40 block-unknown-source
 no bridge-group 40 source-learning
 no bridge-group 40 unicast-flooding
!

 

interface Dot11Radio1.45
 encapsulation dot1Q 45
 bridge-group 45
 bridge-group 45 subscriber-loop-control
 bridge-group 45 spanning-disabled
 bridge-group 45 block-unknown-source
 no bridge-group 45 source-learning
 no bridge-group 45 unicast-flooding
!
interface GigabitEthernet0
 no ip address
 duplex auto
 speed auto
 bridge-group 1
 bridge-group 1 spanning-disabled
 no bridge-group 1 source-learning
!
interface GigabitEthernet0.40
 encapsulation dot1Q 40
 bridge-group 40
 bridge-group 40 spanning-disabled
 no bridge-group 40 source-learning
!
interface GigabitEthernet0.45
 encapsulation dot1Q 45
 bridge-group 45
 bridge-group 45 spanning-disabled
 no bridge-group 45 source-learning
!
interface BVI1
 mac-address f07f.0654.1e8b
 ip address dhcp

!

radius server 172.16.15.10
 address ipv4 172.16.15.10 auth-port 1645 acct-port 1646
 key 7 032178382658780D1658

 

THANKS!

 

0 Replies 0