Home | Site Map | Cisco How ToNet How To | Wireless |Search | Forums | Services | Donations | Careers | About Us | Contact Us|

Solved: Wireless client can't receives IP from DHCP

Cisco Router, Firewall, VPN, SDM, ASA and Switch

Solved: Wireless client can't receives IP from DHCP

Postby chicagotech » Fri Apr 20, 2007 4:37 pm

Fixed it. Check this link: Station 000e.350b.f15b Authentication failed
http://www.chicagotech.net/netforums/vi ... .php?t=683

We have 10 Cisco 1200 wireless APs. The VLAN 1 use Windows certificate as authentication and VLAN 100 for the public. They work fine. We just bought two 1310 wireless bridges for outdoor use. We contact Cisco support for setup these two bridges as below:

Building Switch + Cat 5 + Root Bridge ---------- Non-Root Bridge + Switch + cat 5 + PC or wireless in remote site.

The wired PC in the remote works fine. However, the wireless PC doesn’t work either of public or domain network. It receives the strong signal but the IP or 0.0.0.0 or 169.254.x.x. Any suggestion?

Here is configuration on non-root bridge.

version 12.3
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname Outdoor_1300_1
!
!
ip subnet-zero
!
!
aaa new-model
!
!
aaa group server radius rad_eap
server 10.0.0.12 auth-port 1645 acct-port 1646
server 10.0.20.54 auth-port 1812 acct-port 1813
!
aaa group server radius rad_mac
!
aaa group server radius rad_acct
!
aaa group server radius rad_admin
!
aaa group server tacacs+ tac_admin
!
aaa group server radius rad_pmip
!
aaa group server radius dummy
!
aaa group server radius rad_eap1
server 10.0.20.54 auth-port 1812 acct-port 1813
!
aaa authentication login eap_methods group rad_eap
aaa authentication login mac_methods local
aaa authentication login eap_methods1 group rad_eap1
aaa authorization exec default local
aaa accounting network acct_methods start-stop group rad_acct
aaa session-id common
!
dot11 ssid 06Wireless
vlan 1
authentication open eap eap_methods1
authentication network-eap eap_methods1
authentication key-management wpa
authentication client username Cisco password 7 062506324F41
guest-mode
infrastructure-ssid
!
dot11 ssid Chicago
vlan 300
authentication open
!
dot11 ssid Student
vlan 200
authentication open
authentication key-management wpa
wpa-psk ascii 7 xxx
!
dot11 ssid Teacher
vlan 100
authentication open
authentication key-management wpa
wpa-psk ascii 7 xxx
!
dot11 network-map
!
!

!
bridge irb
!
!
interface Dot11Radio0
no ip address
no ip route-cache
!
encryption vlan 100 mode ciphers tkip
!
encryption vlan 200 mode ciphers tkip
!
encryption vlan 1 mode ciphers tkip
!
ssid 06Wireless
!
ssid Chicago
!
ssid Student
!
ssid Teacher
!
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role non-root bridge wireless-clients
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
!
interface Dot11Radio0.100
encapsulation dot1Q 100
no ip route-cache
bridge-group 100
bridge-group 100 spanning-disabled
!
interface Dot11Radio0.200
encapsulation dot1Q 200
no ip route-cache
bridge-group 200
bridge-group 200 spanning-disabled
!
interface Dot11Radio0.300
encapsulation dot1Q 300
no ip route-cache
bridge-group 255
bridge-group 255 spanning-disabled
!
interface FastEthernet0
no ip address
no ip route-cache
hold-queue 80 in
!
interface FastEthernet0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
!
interface FastEthernet0.100
encapsulation dot1Q 100
no ip route-cache
bridge-group 100
bridge-group 100 spanning-disabled
!
interface FastEthernet0.200
encapsulation dot1Q 200
no ip route-cache
bridge-group 200
bridge-group 200 spanning-disabled
!
interface FastEthernet0.300
encapsulation dot1Q 300
no ip route-cache
bridge-group 255
bridge-group 255 spanning-disabled
!
interface BVI1
ip address 10.0.20.53 255.255.0.0
no ip route-cache
!
ip default-gateway 10.0.0.2
ip http server
no ip http secure-server
ip http help-path http://www.cisco.com/warp/public/779/sm ... g/help/eag
ip radius source-interface BVI1
!
radius-server attribute 32 include-in-access-req format %h
radius-server host 10.0.0.12 auth-port 1645 acct-port 1646 key 7 121A5502001F
radius-server host 10.0.20.54 auth-port 1812 acct-port 1813 key 7 13261E010803
radius-server vsa send accounting
!
control-plane
!
bridge 1 route ip
!
!
!
line con 0
line vty 0 4
!
end
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
chicagotech
Site Admin
 
Posts: 6356
Joined: Mon Nov 27, 2006 1:24 pm
Location: Chicago USA

Return to Cisco

Your Ad Here

Who is online

Users browsing this forum: No registered users and 3 guests