ā07-21-2013 01:39 AM - edited ā07-04-2021 12:28 AM
Dear All,
I am not understanding why we need this thing when we install the certificates on the wlc. We already have WLC name that is resolved on the DNS. Why cant we use that one instead ...? Anyways they might have designed it like that or any reason behind..?
When we say virtual IP should be non-routable, how do we give common name that is resolvable by DNS..? My DNS VIP is 192.2.X.X series..?
Pls clarify my doubt....
KVS
Solved! Go to Solution.
ā07-21-2013 08:24 AM
I understand your confusion. We've all been there on this one scratching our head. I hope after this post you better understand.
First, the cert you loaded sounds like it's the cert for the WLC management. So you don't get that annoying pop up when you access the WLC. Correct?
If so, this has nothing to do with the virtual address and GUEST certificate. The virtual address on the controller is used for a number of things, mobility and guest redirect are a few. In your case, since you are saying virtual address and certificate you must be referencing a guest cert. Again, different from your wlc management cert. The guest cert stops the annoying pop up, accept this cert for your guest users before they get the guest page. Again different cert ..
if you dont have a guest wireless network or you dont care if the guest gets the pop up no cert is needed. If you are doing a guest network and you DONT want the guest to get he annoying pop up you need to do the cert.
On my blog I outlined how to create the cert
The reason why the cert has to match the virual address is because of the redirect. Here is how it works. A client connects to your guest network. He goes to yahoo.com. The wlc allows the request to go out to DNS and get resolved. The DNS responds with the IP address and the WLC hijacks this request and puts the virtual address in its place. The clients browser automatically tries to open the virtual address (bang) pop up. Unless you have the cert installed.
Make sense?
__________________________________________________________________________________________
"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
__________________________________________________________________________________________
ā"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."
ā07-21-2013 05:12 AM
Prasan,
Am not sure what your confusion is? The DNS resolution has nothing to do with the ip address being routable or not.
Sent from Cisco Technical Support iPhone App
ā07-21-2013 05:56 AM
OK... Please tell me why we need DNS entry for Virtual IP, when we install certificate?
ā07-21-2013 08:24 AM
I understand your confusion. We've all been there on this one scratching our head. I hope after this post you better understand.
First, the cert you loaded sounds like it's the cert for the WLC management. So you don't get that annoying pop up when you access the WLC. Correct?
If so, this has nothing to do with the virtual address and GUEST certificate. The virtual address on the controller is used for a number of things, mobility and guest redirect are a few. In your case, since you are saying virtual address and certificate you must be referencing a guest cert. Again, different from your wlc management cert. The guest cert stops the annoying pop up, accept this cert for your guest users before they get the guest page. Again different cert ..
if you dont have a guest wireless network or you dont care if the guest gets the pop up no cert is needed. If you are doing a guest network and you DONT want the guest to get he annoying pop up you need to do the cert.
On my blog I outlined how to create the cert
The reason why the cert has to match the virual address is because of the redirect. Here is how it works. A client connects to your guest network. He goes to yahoo.com. The wlc allows the request to go out to DNS and get resolved. The DNS responds with the IP address and the WLC hijacks this request and puts the virtual address in its place. The clients browser automatically tries to open the virtual address (bang) pop up. Unless you have the cert installed.
Make sense?
__________________________________________________________________________________________
"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
__________________________________________________________________________________________
ā"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."
ā07-21-2013 11:48 AM
Hello George,
Yes, Its a very wonderful explanation and sad point is i could give only +5, i wish to give more ... Really many thanks for your time.
We are doing this stuff in our project and your answer gave me more understanding on it....
KVS
ā07-21-2013 07:22 PM
Thanks for supporting the rating system .. Stop back if you have any more questions ..
Sent from Cisco Technical Support iPhone App
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide