07-21-2014 02:21 PM - edited 07-05-2021 01:15 AM
I have one a Root Bridge. Its Software/Hardware is up.
The Non-Root Bridge never show Software/Hardware is up.
If I switch the Non-Root Bridge to AP they come up.
When the Non-Root Bridge boots the log says it is unable to associate.
Why won't the interface come up - or is there a way to find WHY it won't associate? Some log?
07-21-2014 02:46 PM
One more question:
With this, how do the Install Root-Bridge and Install Non-Root-Bridge settings work? After I set them what do I do?
Thanks,
07-21-2014 03:39 PM
few suggestion here
1. Remove all security settings & see whether those are associated in Open Auth
2. swap the roles (ie, current RB configure as NRB & current NRB as RB & see whether radio comes up)
HTH
Rasika
**** Pls rate all useful responses ****
07-23-2014 09:21 AM
I agree with Ras. Unwrap the complexity first. Also post the config of both please.
07-23-2014 09:39 AM
07-23-2014 09:42 AM
Remove "optional"
infrastructure-ssid optional
Remove
dot11 ssid autoinstall authentication open guest-mode infrastructure-ssid !
Lets clean that up first
07-24-2014 07:18 AM
07-24-2014 08:34 AM
I assume these are setup on a desk next to each other and they have antennas attached .. ?
07-24-2014 08:42 AM
Repost your latest config on both sides after the changes you did ..
07-24-2014 08:59 AM
Right George. I removed any config I did and put one in Bridge Install Mode and the other in Root Bridge install mode.
For the first time they are associating.
Now I would like to secure them, encrypt the traffic and get them out of install mode. Can you show me?
Attached are both show runs and logs from both.
07-24-2014 09:05 AM
Im concerned because it shows it was dropping in the logs. I think your issue was the infrastructure SSID command. Thats required, not optional.
Do you have plans on doing VLANs across this thing or just a simple layer 2 to pass traffic ?
07-24-2014 09:07 AM
BTW - Install mode puts the radio signal strength in the CLI / LOG .. This is why you see all those readings ..
07-24-2014 09:08 AM
What security did you have in mind ? EAP, PSK ?
07-24-2014 09:10 AM
WPA is what I am thinking. But whatever you think best. WPA with shared key.
07-24-2014 09:16 AM
WPA2 PSK .. is a simple and secure way ..
You need to config 2 spots ..
1) Under dot11 ssid you need to enter the below.. Add your key ..
dot11 ssid (your ssid)
authentication open
authentication key-management wpa version 2
infrastructure-ssid
wpa-psk ascii XXXXXXXXX
2) drop into the radio you are using and put " encryption mode ciphers aes-ccm ". This tells the radio to use AES-CCM (WPA2 AES). If you are doing vlans then you need to do each vlan here. If not, then just drop this in under dot11radioX.
Do this to both sides.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide