02-09-2014 08:30 PM - edited 07-05-2021 12:08 AM
Hi, need help with my current situation. We had a Cisco wlan controller 2100, we've connected this device in one of our global partner's Radius server in another country/territory. We're able to connect to the radius server for auth and users can go online but one thing pops up before they get connected, please see screenshot below:
Once this wireless user has been connected right after clicking on the "connect" button, this message won't appear anymore the next time he/she connects to the wifi the next day. This message will reappear if you remove the wireless profile under "Manage Wireless Network"
Regards,
Jeff
Solved! Go to Solution.
02-09-2014 08:44 PM
This is because you are validating the server certificate in the wireless profile. If you uncheck this, then you will not be presented with that error. If you have an internal CA, then you should be trusting that cert and the domain computers should trust that certificate.
Sent from Cisco Technical Support iPhone App
02-09-2014 08:49 PM
This link talks about validation of server certificate.
https://supportforums.cisco.com/docs/DOC-17512#Wireless_Authentication_properties
Here is a screen shot of where you can validate server cert.
Sent from Cisco Technical Support iPhone App
02-09-2014 08:44 PM
This is because you are validating the server certificate in the wireless profile. If you uncheck this, then you will not be presented with that error. If you have an internal CA, then you should be trusting that cert and the domain computers should trust that certificate.
Sent from Cisco Technical Support iPhone App
02-09-2014 08:49 PM
This link talks about validation of server certificate.
https://supportforums.cisco.com/docs/DOC-17512#Wireless_Authentication_properties
Here is a screen shot of where you can validate server cert.
Sent from Cisco Technical Support iPhone App
02-09-2014 10:25 PM
Ok, I understand now the situation. I could set this via gpo for them(wireless users) to use this SSID with the settings set by the GPO problem is, we're just using Windows Server 2003 SP2 which I dont see the option for wpa2-ent. It just has the options for wep, wpa, and wpa-psk under IEEE 802.1x tab. Checked Windows Server 2008 R2 SP1 and it does have options for WPA2-Ent.
Thanks
Jeff
02-10-2014 12:22 AM
It did work after disabling "Validate Server Certificate" checkbox. The next action is to look if there's a hotfix/update for our old Windows Server 2003 SP2 OS fo the wlan security options.
Thanks for all replies and have a great day ahead!
Jeff
02-10-2014 03:10 AM
Yeah server 2003 doesn't have that option. You might be able to push out an XML wireless profile though that has it. I have done this in the past where you create a windows profile one for Windows XP and another for Windows 7 and you export them. Then you can run a script when users login to execute an import. This works well also if your using WEP or preshared keys since GPO will not push out the keys:)
http://www.informit.com/articles/article.aspx?p=1597099
Sent from Cisco Technical Support iPhone App
02-10-2014 09:33 PM
I see, will try this workaround and see how it works. BTW, an off topic question, is there a way to limit the range of specific access points or limit the number of users?
For the range, i.e 5meters only for example and 5 users? something like that, is this possible?
regards,
02-10-2014 10:09 PM
1) Maximum clients allowed per controller(per WLAN) can be controlled
The maximum number of clients per WLAN feature is supported only for access points that are in connected mode.
AND this feature is not supported when you use FlexConnect local authentication.
2) At the AP level, Load balancing is an option. Client Window Size per AP is configurable.
But please note that most clients don't honor the rejection.
So we have mechanism to only reject a client X # of times(Max Denial Count) , then we can eventualy let them associate.
3) The range of the AP cannot be controlled in terms of distance. However you can drive this via Transmit power.
Tx power level 1 corresponds to 17dBm and it goes down upto 8 that corresponds to -4dBm
You may need a site survey mechanism to choose the power level (on a per AP basis) based on your requirement.
Please make sure that you have enough coverage overlap for the clients to seamlessly roam.
Refer : http://www.cisco.com/en/US/tech/tk722/tk809/technologies_tech_note09186a00800e90fe.shtml
02-10-2014 10:24 PM
Appreciate that quick response I'll try to explore this and will let you know for any results.
Thanks and enjoy the rest of the day!
Jeff
02-10-2014 10:49 PM
I tried to check the controller and under security>ACL, I dont see any options for "FlexConnect" Does this mean the controller is set as "Connected" mode?
02-10-2014 10:59 PM
If the AP is in FlexConnect mode, then the AP is said to be in connected mode when its CAPWAP control plane link to the WLC is up and operational. This means that the WAN link between the LAP and WLC is not down.
*****Help out other by using the rating system and marking answered questions as "Answered"*****
02-11-2014 05:01 AM
It probably because of the code you have on the 2100. The newer model WLC's and code allows for this to be changed on a per WLAN or per radio.
Sent from Cisco Technical Support iPhone App
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide