03-08-2013 07:07 AM - edited 07-03-2021 11:41 PM
I have serveral 1130AG AP that when they are configured to use LWAPP all of my Motorola Handheld scanners connect to the SSIDs fine.
When I have some that are on Autonomous then the scanners will not connect at all.
I have upgraded a test 1130AG to the lates IOS and that does not help.
Any suggestions.
03-08-2013 07:15 AM
Not enough information to help you here... You need to post your configuration for the autonomous AP and tell us what SSID the devices are using to connect.
Thanks,
Scott
Help out other by using the rating system and marking answered questions as "Answered"
03-08-2013 07:26 AM
This is my config, neither SSID will connect via the scanners, but my phone will connect to either.
!
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname TESTWAP
!
enable secret 5 $1$7Sa0$E/ht0mNM7EYOo9ORkeCc2/
!
no aaa new-model
!
!
dot11 syslog
!
dot11 ssid GUESTTEST
vlan 8
authentication open
guest-mode
!
dot11 ssid PRIVATE
vlan 1
authentication open
!
!
!
!
!
bridge irb
!
!
interface Dot11Radio0
no ip address
no ip route-cache
!
encryption key 1 size 128bit 7 A586DEC9AA12D1772BF8CF617842
encryption key 2 size 128bit 7 4586DEC9AA12D1772BF8CF617842 transmit-key
encryption key 3 size 128bit 7 93CEC7D386E2F7EB4AAC8D3D58E7
encryption key 4 size 128bit 7 990EC692BCBABCEA6A2ACBA5586E
!
ssid GUESTTEST
!
ssid PRIVATE
!
station-role root
rts threshold 2312
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled
!
interface Dot11Radio0.8
encapsulation dot1Q 8
no ip route-cache
bridge-group 8
bridge-group 8 subscriber-loop-control
bridge-group 8 block-unknown-source
no bridge-group 8 source-learning
no bridge-group 8 unicast-flooding
bridge-group 8 spanning-disabled
!
interface Dot11Radio1
no ip address
no ip route-cache
!
ssid GUESTTEST
!
ssid PRIVATE
!
dfs band 3 block
channel dfs
station-role root
!
interface Dot11Radio1.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled
!
interface Dot11Radio1.8
encapsulation dot1Q 8
no ip route-cache
bridge-group 8
bridge-group 8 subscriber-loop-control
bridge-group 8 block-unknown-source
no bridge-group 8 source-learning
no bridge-group 8 unicast-flooding
bridge-group 8 spanning-disabled
!
interface FastEthernet0
no ip address
no ip route-cache
duplex auto
speed auto
!
interface FastEthernet0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
no bridge-group 1 source-learning
bridge-group 1 spanning-disabled
!
interface FastEthernet0.8
encapsulation dot1Q 8
no ip route-cache
bridge-group 8
no bridge-group 8 source-learning
bridge-group 8 spanning-disabled
!
interface BVI1
ip address 192.168.100.36 255.255.255.0
no ip route-cache
!
ip default-gateway 192.168.100.254
ip http server
no ip http secure-server
ip http help-path
http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
bridge 1 route ip
!
!
!
line con 0
line vty 0 4
login local
line vty 5 15
login
!
end
03-08-2013 07:37 AM
so if you are using wep
you have to add the following commands under dot11radio configuration mode
encryption vlan 1 mode wep mandatory
encryption vlan 8 mode wep mandatory
encryption vlan 1 key .....
encryption vlan 8 key ..............
if you don't want to use wep , then there is no need to have:
encryption key 1 size 128bit 7 A586DEC9AA12D1772BF8CF617842
encryption key 2 size 128bit 7 4586DEC9AA12D1772BF8CF617842 transmit-key
encryption key 3 size 128bit 7 93CEC7D386E2F7EB4AAC8D3D58E7
encryption key 4 size 128bit 7 990EC692BCBABCEA6A2ACBA5586E
-----------------------------------------------------------------------
please make sure to rate correct answers
03-08-2013 07:55 AM
Not using WEP. Still no luck.
03-08-2013 08:04 AM
What are you using? What is setup on the WLC that works? On the WLC post the show WLAN
This way we can see how the SSID is configured since you mentioned that the devices connect fine to those APs.
Sent from Cisco Technical Support iPhone App
03-08-2013 08:11 AM
This is the WLAN config on the WLC that I need to use.
WLAN Identifier.................................. 4
Profile Name..................................... WIFIGUEST
Network Name (SSID).............................. PRIVATE
Status........................................... Enabled
MAC Filtering.................................... Disabled
Broadcast SSID................................... Enabled
AAA Policy Override.............................. Disabled
Network Admission Control
Client Profiling Status ....................... Disabled
Radius-NAC State............................... Disabled
SNMP-NAC State................................. Disabled
Quarantine VLAN................................ 0
Maximum number of Associated Clients............. 0
Maximum number of Clients per AP Radio........... 200
Number of Active Clients......................... 38
Exclusionlist Timeout............................ 60 seconds
Session Timeout.................................. 1800 seconds
CHD per WLAN..................................... Enabled
Webauth DHCP exclusion........................... Disabled
Interface........................................ wifi
--More-- or (q)uit
Multicast Interface.............................. Not Configured
WLAN IPv4 ACL.................................... unconfigured
WLAN IPv6 ACL.................................... unconfigured
DHCP Server...................................... Default
DHCP Address Assignment Required................. Disabled
Static IP client tunneling....................... Disabled
Quality of Service............................... Silver
Scan Defer Priority.............................. 4,5,6
Scan Defer Time.................................. 100 milliseconds
WMM.............................................. Allowed
WMM UAPSD Compliant Client Support............... Disabled
Media Stream Multicast-direct.................... Disabled
CCX - AironetIe Support.......................... Enabled
CCX - Gratuitous ProbeResponse (GPR)............. Disabled
CCX - Diagnostics Channel Capability............. Disabled
Dot11-Phone Mode (7920).......................... Disabled
Wired Protocol................................... None
Passive Client Feature........................... Disabled
Peer-to-Peer Blocking Action..................... Disabled
Radio Policy..................................... All
DTIM period for 802.11a radio.................... 1
DTIM period for 802.11b radio.................... 1
Radius Servers
--More-- or (q)uit
Authentication................................ Global Servers
Accounting.................................... Global Servers
Interim Update............................. Disabled
Dynamic Interface............................. Disabled
Local EAP Authentication......................... Disabled
Security
802.11 Authentication:........................ Open System
FT Support.................................... Disabled
Static WEP Keys............................... Disabled
802.1X........................................ Disabled
Wi-Fi Protected Access (WPA/WPA2)............. Disabled
Wi-Fi Direct policy configured................ Disabled
EAP-Passthrough............................... Disabled
CKIP ......................................... Disabled
Web Based Authentication...................... Disabled
Web-Passthrough............................... Disabled
Conditional Web Redirect...................... Disabled
Splash-Page Web Redirect...................... Disabled
Auto Anchor................................... Disabled
FlexConnect Local Switching................... Disabled
FlexConnect Local Authentication.............. Disabled
FlexConnect Learn IP Address.................. Enabled
--More-- or (q)uit
Client MFP.................................... Optional but inactive (WPA2 not configured)
Tkip MIC Countermeasure Hold-down Timer....... 60
Call Snooping.................................... Disabled
Roamed Call Re-Anchor Policy..................... Disabled
SIP CAC Fail Send-486-Busy Policy................ Enabled
SIP CAC Fail Send Dis-Association Policy......... Disabled
KTS based CAC Policy............................. Disabled
Band Select...................................... Disabled
Load Balancing................................... Disabled
Multicast Buffer................................. Disabled
Mobility Anchor List
WLAN ID IP Address Status
------- --------------- ------
802.11u........................................ Disabled
Access Network type............................ Not configured
Network Authentication type.................... Not configured
Internet service............................... Disabled
HESSID......................................... 00:00:00:00:00:00
Hotspot 2.0.................................... Disabled
03-08-2013 08:22 AM
from the WLAN config, that is an open WLAN. If that is the case then:
conf t
int dot0
no encryption key 1 size 128bit 7 A586DEC9AA12D1772BF8CF617842
no encryption key 2 size 128bit 7 4586DEC9AA12D1772BF8CF617842 transmit-key
no encryption key 3 size 128bit 7 93CEC7D386E2F7EB4AAC8D3D58E7
no encryption key 4 size 128bit 7 990EC692BCBABCEA6A2ACBA5586E
end
HTH,
Steve
------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered
03-08-2013 08:17 AM
Add guest-mode on the PRIVATE SSID. That is how it's configured on the WLC.
Sent from Cisco Technical Support iPhone App
03-08-2013 08:30 AM
I have set the No command for the encryption and set the PRIVATE ssid to guest-mode with no luck. My scanners see the access point radio mac address, but will not connect.
03-08-2013 08:40 AM
that should work, teh WLAN from the WLC isn't running any encryption. with removing those commands should do the same on the aIOS as well.
HTH,
Steve
------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered
03-08-2013 08:58 AM
I reset the AP to factory default and setup:
one SSID - no go.
one SSID with 1 VLAN - no go
This is frustrating.
03-08-2013 05:39 PM
Try with OPEN authentication and broadcasting SSID.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide