cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1587
Views
5
Helpful
4
Replies

CAPWAP 2802 AP and Disables 2nd ethernet interface

davidfield
Level 3
Level 3

Hello All,

 

I have an issue where we had a 3rd party contractor mount and connect a large number of 2802 AP's around a building and patch in 2 cables to each AP so that both ports are connected.  Its not a problem as we only patched in a single cable at the riser switches..... However, we have had instances where individuals have been working in the risers and patching in equipment and have been accidentally patching in the 2nd port on the AP's and creating spanning tree loops and take the site down.  We do not have exclusive management of the Risers as the local IT team have an access requirement and the easiest solution would be to disable the 2nd ethernet port at the AP but I cannot see where to do this on the 3504 Controller.  Can anyone advise how I can disable the 2nd port at the AP?

 

Thanks in advance

David

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

as i re-call only 1 port was used, depending on the config you used.

 

check below disabling:  section - Converting Cisco Wave 2 AP AUX Port to LAN Port (CLI)

 

https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-8/config-guide/b_cg88/ap_power_and_lan_connections.html#power-over-ethernet

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

What Im seeing is by default the 2nd port is active and is a layer 2 switch port of the native vlan for the trunk to the AP.

Miguel10
Level 1
Level 1

Hi, There is a feature request for this, but Cisco doesn't seem to be interested in Fixing it for now.

Bug Search Tool (cisco.com)

Since the Wave2 AP's are announced EOL I do not think Cisco will give much importance to this request, therefor your only available option is to physically secure the switch, so no one can connect cables without any pre-approvals, or disconnect the cable from AP side physically. If I am in your situation, I would ask my labelling team to label the ports clearly and print the PAS and paste it in the IDF rack door (only if the room is properly secured) and I will also look in to educating the local IT team in whatever the way possible. 

I would also suggest to look in to any STP enhancements (loop guard, BPDU guard etc.) which can prevent this, since I haven't been on this situation and no Wave2 AP in my lab to test, I cannot comment which will work.

Rich R
VIP
VIP

In fact @Miguel10 that bug is showing status Terminated which confirms they have already decided not to implement the feature.

Review Cisco Networking for a $25 gift card