Question

Locked

871W - Unable to get wireless to work

By gachua ·
Hello,

I am pretty new to Cisco IOS so please bare with me.

I used the DHCP Configuration Spreadsheet and the below pasted config is basically exactly like it with only a few modifications.

I can see the GuestWLAN on my wireless configuration tool and try to connect but, don't get an ip address.

I've tried to remove security all together but, still the same thing.

I'm sure there is something small I am doing wrong that is staring me right in the face. I just can't see it

Any help would be appreciated.

IOS version on the router: c870-advsecurityk9-mz.124-4.XC5.bin
****
Config:

swordfish#sh runn
Building configuration...

Current configuration : 5509 bytes
!
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname swordfish
!
boot-start-marker
boot-end-marker
!
enable secret 5 $1$asdfa3w4afsdfJHd0bbi0
enable password 7 13387503ASDF97592539
!
aaa new-model
!
!
aaa authentication login default local
aaa authorization exec default local
!
aaa session-id common
!
resource policy
!
ip cef
no ip dhcp use vrf connected
ip dhcp excluded-address 192.168.1.1 192.168.1.10
ip dhcp excluded-address 192.168.2.1 192.168.2.10
!
ip dhcp pool Internal-net
import all
network 192.168.1.0 255.255.255.0
default-router 192.168.1.111
domain-name test.com
lease 4
!
ip dhcp pool VLAN20
import all
network 192.168.2.0 255.255.255.0
default-router 192.168.2.222
domain-name test.com
lease 4
!
!
ip inspect name MYFW tcp
ip inspect name MYFW udp
no ip domain lookup
ip domain name chuaenterprises.com
!
!
crypto pki trustpoint TP-self-signed-642930702
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-642930702
revocation-check none
rsakeypair TP-self-signed-642930702
!
!
crypto pki certificate chain TP-self-signed-642930702
certificate self-signed 01
30820253 308201BC A0030201 02020101 300D0609 2A864886 F70D0101 04050030
30312E30 2C060355 04031325 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 36343239 33303730 32301E17 0D303730 31303930 34343634
335A170D 32303031 30313030 30303030 5A303031 2E302C06 03550403 1325494F
532D5365 6C662D53 69676E65 642D4365 72746966 69636174 652D3634 32393330
37303230 819F300D 06092A86 4886F70D 01010105 000381 00308189 02818100
AFB366B8 93807E0C FAAFB69A D1CB21E5 93E65C06 5B01FC6E 9797384D 1916FDE5
9FEACB B3F14009 3E89560F 85EFFE73 F67CBE9B FD80F1F0 8B25AB96 B8D8B415
D2EF2CDF 3601536B 29F439C8 33FDA55F 74C0BF37 66D25299 57E393C5 C7F11A50
C123E017 9243912B 2F17ED3D A64B05DF 72E9097A D45DBF4B FA63E243 179067B9
02030100 01A37D30 7B300F06 03551D13 0101FF04 05300301 01FF3028 0603551D
11042130 1F821D73 776F7264 66697368 2E636875 61656E74 65727072 69736573
2E636F6D 301F0603 551D2304 18301680 146B6D4C 9A76F17A 33727776 93E5D517
A83478EC 77301D06 03551D0E 04160414 6B6D4C9A 76F17A33 72777693 E5D517A8
3478EC77 300D0609 2A864886 F70D0101 04050003 81810003 69E40EB7 42753FC1
46AE0062 77FF936C 2F2A01E5 8A250844 D2138431 FAB90B36 B663D360 D54777F8
6FBDA127 9BF99A36 488C3871 B984E268 14C66A99 8F9E7235 BB44109D 05804F5C
BEEBF189 A9BC4310 E173D536 D0C2C242 D6A58A62 46C0D523 398442F6 C15BFCC8
1BC2550E 6D2C76DF 00AA191D EE3549AB 11A55414 AFA16D
quit
username swordfish privilege 15 password 7 151ASDT32662G783679
!
!
!
bridge irb
!
!
interface FastEthernet0
spanning-tree portfast
!
interface FastEthernet1
spanning-tree portfast
!
interface FastEthernet2
spanning-tree portfast
!
interface FastEthernet3
spanning-tree portfast
!
interface FastEthernet4
ip address dhcp
ip access-group Internet-inbound-ACL in
ip inspect MYFW out
ip nat outside
ip virtual-reassembly
ip tcp adjust-mss 1460
duplex auto
speed auto
no cdp enable
!
interface Dot11Radio0
no ip address
!
encryption vlan 1 mode ciphers tkip
!
encryption vlan 20 mode ciphers tkip
!
ssid GuestWLAN
vlan 20
authentication open
authentication key-management wpa
guest-mode
wpa-psk ascii 7 00451D12420F06091D
!
ssid InternalWLAN
authentication open
authentication key-management wpa
wpa-psk ascii 7 14561C1F4A50272436
!
ssid Swordfish
vlan 1
!
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
channel 2412
station-role root
no dot11 extension aironet
no cdp enable
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no snmp trap link-status
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
!
interface Dot11Radio0.20
description Guest wireless LAN - routed WLAN
encapsulation dot1Q 20
ip address 192.168.2.222 255.255.255.0
ip access-group Guest-ACL in
ip inspect MYFW out
ip nat inside
ip virtual-reassembly
no snmp trap link-status
!
interface Vlan1
description Internal Network
no ip address
ip nat inside
ip virtual-reassembly
bridge-group 1
bridge-group 1 spanning-disabled
!
interface BVI1
description Bridge to Internal Network
ip address 192.168.1.111 255.255.255.0
ip access-group BVI_LIST in
ip nat inside
ip virtual-reassembly
!
ip route 0.0.0.0 0.0.0.0 dhcp
!
ip http server
ip http secure-server
ip nat inside source list 1 interface FastEthernet4 overload
!
ip access-list extended BVI_LIST
deny icmp any any
permit tcp any any eq telnet
permit ip any any
ip access-list extended Guest-ACL
deny ip any 192.168.1.0 0.0.0.255
permit ip any any
ip access-list extended Internet-inbound-ACL
permit udp any eq bootps any eq bootpc
permit icmp any any echo
permit icmp any any echo-reply
permit icmp any any traceroute
permit gre any any
permit esp any any
!
access-list 1 permit 192.168.1.0 0.0.0.255
access-list 1 permit 192.168.2.0 0.0.0.255
!
!
!
control-plane
!
bridge 1 route ip
!
line con 0
password 7 06003G3G545A0B54
logging synchronous
no modem enable
line aux 0
line vty 0 4
password 7 0ASWD743327811551D70
!
scheduler max-task-time 5000
!
webvpn context Default_context
ssl authenticate verify all
!
no inservice
!
end
****
Thanks

This conversation is currently closed to new comments.

5 total posts (Page 1 of 1)  
| Thread display: Collapse - | Expand +

All Answers

Collapse -

Which template did you use?

by georgeou In reply to 871W - Unable to get wire ...

The newer one for the regular IOS?
http://articles.techrepublic.com.com/5100-1035-6112367.html

The older one for Advanced IP (more expensive) IOS?
http://articles.techrepublic.com.com/5100-1035_11-6102399.html
Note that this one has been updated so please redownload the template and try it again.

Collapse -

Thanks

by gachua In reply to Which template did you us ...

I figured out that I had two problems. I was using the wrong template for my IOS and I also needed a Wireless Card firmware upgrade. All is working now... On to tackling setting up a VPN Server.

A bit of a learning curve but, I'm loving my 871w. Found it at a business closing auction and picked it up for $175 !!!

Collapse -

ip virtual-reassembly is the pblm

by mscp39 In reply to 871W - Unable to get wire ...

put no ip virtual-reassembly on interface.
That will help u out.

Collapse -

2nd Bridge Group

by neilslink In reply to 871W - Unable to get wire ...

You need to create a 2nd bridge group:

interface Dot11Radio0.20
no ip address
bridge-group 2
bridge-group 2 subscriber-loop-control
bridge-group 2 spanning-disabled
bridge-group 2 block-unknown-source
no bridge-group 2 source-learning
no bridge-group 2 unicast-flooding
no shut


bridge 2 protocol ieee

bridge 2 route ip

interface vlan 20
bridge-group 2
bridge-group spanning-disabled
no shut

interface bvi 2
ip address 192.168.2.222 255.255.255.0
no shut

Back to Networks Forum
5 total posts (Page 1 of 1)  

Related Discussions

Related Forums