Networking-Blog

My WordPress Blog

Cisco Event Manager

Event Manager : This ensures when LAN interface is down, HSRP will fail-over to
secondary router, this script will force ATM0 interface down in order to have the
BGP VRF routes removed from routing table on the PE routers and will fail-over to
the secondary router which has a route map tag 2 configured on PE router with route’s
to 
AV-PAIR public ip address.

!

event manager applet LANDown
event track 20 state down
action 1.0 syslog msg “Vlan 1 interface is down; shutting down ATM0”
action 2.0 cli command “enable“
action 3.0 cli command “config t“
action 4.0 cli command “interface atm0“
action 5.0 cli command “shut“
action 6.0 cli command “end“

!
!

event manager applet LANUp
event track 20 state up
action 1.0 syslog msg “Vlan 1 interface is up; bring up ATM0”
action 2.0 cli command “enable“
action 3.0 cli command “config t“
action 4.0 cli command “interface atm0“
action 5.0 cli command “no shut“
action 6.0 cli command “end“

CISCO WIRELESS RADIUS EAP AUTHENTICATION

aaa new-model
!
aaa group server radius wifieap
server 10.201.1.10 auth-port 1812 acct-port 1813
!
dot11 ssid GHG-Client-EAP
vlan 1
authentication open eap wifiaaa
authentication network-eap wifieap
authentication key-management wpa
guest-mode
!
!
interface Dot11Radio0
no ip address
!
encryption vlan 1 mode ciphers aes-ccm tkip
!
ssid GHG-Client-EAP
!
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root
world-mode dot11d country GB outdoor
!
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no cdp enable
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
!
interface Vlan1
no ip address
bridge-group 1
bridge-group 1 spanning-disabled
!
!
interface BVI1
ip address 192.168.#.# 255.255.255.#
!
ip radius source-interface BVI1
!
radius-server host 10.201.1.10 auth-port 1812 acct-port 1813 key 7 00573E03150327080A131B5A5F
radius-server host 10.202.1.10 auth-port 1812 acct-port 1813 key 7 00573E03150327080A131B5A5F
radius-server host 10.200.0.10 auth-port 1812 acct-port 1813 key 7 00573E03150327080A131B5A5F
radius-server timeout 3


For Radius EAP Authentication :

aaa new-model
!
aaa group server radius wifieap
server 10.201.1.10 auth-port 1812 acct-port 1813
!
dot11 ssid GHG-Client-EAP
vlan 1
authentication open eap wifiaaa
authentication network-eap wifieap
authentication key-management wpa
guest-mode
!
ip radius source-interface BVI1
!
radius-server host 10.201.1.10 auth-port 1812 acct-port 1813 key 7 00573E03150327080A131B5A5F
radius-server host 10.202.1.10 auth-port 1812 acct-port 1813 key 7 00573E03150327080A131B5A5F
radius-server host 10.200.0.10 auth-port 1812 acct-port 1813 key 7 00573E03150327080A131B5A5F
radius-server timeout 3

Cisco 887G ADSL + 3G Backup

VPN IP SLA – In order to keep vpn up and active.

IP SLA MONITOR STATIC FLOATING ROUTE SOURCE LAN :

ip sla 1
icmp-echo 10.20.0.1 source-interface vlan 1
threshold 2
timeout 1000
frequency 5
!
!
ip sla schedule 1 life forever start-time now
!
!
ip sla 10
icmp-echo 80.74.16.173 source-interface Dialer0
threshold 2
timeout 1000
frequency 5
!
ip sla schedule 10 life forever start-time now
ip sla responder
!
track 10 interface ATM0 line-protocol
delay down 15 up 15
!
!
ip route 0.0.0.0 0.0.0.0 Dialer0 name PRIMARY track 10
ip route 0.0.0.0 0.0.0.0 Cellular0 name 3G_BACKUP
!

Rest of the Configuration :

ADSL :

service internal
!
interface ATM0
no ip address
atm vc-per-vp 64
atm bandwidth dynamic
atm ilmi-keepalive 30 retry 5
pvc 0/38
encapsulation aal5mux ppp dialer
dialer pool-member 1
!
dsl sync interval 3
dsl sync mode itu
dsl operating-mode itu-dmt
dsl power-cutback 1
dsl noise-margin 3
dsl max-tone-bits 10
dsl bitswap both
!
interface Dialer0
ip address negotiated
ip verify unicast reverse-path
ip access-group INTERNET in
ip nat outside
encapsulation ppp
dialer pool 1
dialer-group 1
ppp authentication chap callin
ppp chap hostname test@securewan.co.uk
ppp chap password 0 password
ppp ipcp dns request
crypto map mapping
!

3G Interface

chat-script mobile “” “ATDT*98*1#” TIMEOUT 60 CONNECT

interface Cellular0
ip address negotiated
ip nat outside
encapsulation ppp
dialer in-band
dialer idle-timeout 0
dialer string mobile
dialer-group 1
ppp chap hostname web
ppp chap password 7 10590C1B
ppp ipcp dns request
crypto map mapping
!
!
interface Vlan1
description Corporate VLAN
ip address 10.20.4.100 255.255.255.0
ip access-group LAN in
ip tcp adjust-mss 1400
!

DNS Name-Server :

ip name-server 80.74.16.30
ip name-server 80.74.16.31
ip name-server 8.8.8.8
ip dns server
!
ip nat inside source route-map NAT_WW interface Dialer0 overload
ip nat inside source route-map NAT_3G interface Cellular0 overload
!
ip access-list extended NAT_ACL_WW
deny ip 10.20.4.0 0.0.0.255 10.20.0.0 0.0.255.255
permit ip 10.20.4.0 0.0.0.255 any
deny ip any any
!
ip access-list extended NAT_ACL_3G
deny ip 10.20.4.0 0.0.0.255 10.20.0.0 0.0.255.255
permit ip 10.20.4.0 0.0.0.255 any
deny ip any any
!
route-map NAT_WW permit 10
match ip address NAT_ACL_WW
!
route-map NAT_3G permit 20
match ip address NAT_ACL_3G

 

VPN :ADSL_3G

crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2

!
crypto isakmp key cvsrtmvpn96 address 85.234.65.57crypto isakmp identity hostname
crypto isakmp keepalive 15 10

!
crypto ipsec transform-set secure esp-3des esp-md5-hmac
!
!
crypto map mapping_3g 1 ipsec-isakmp
set peer 85.234.65.57
set security-association lifetime seconds 86400
set security-association idle-time 86400
set transform-set secure
match address VPN
!
ip access-list extended VPN
permit ip 10.20.4.0 0.0.0.255 any
!

ACCESS-LIST RULE :
ip access-list extended INTERNET
remark WAVEWORKS
permit ip 80.74.16.8 0.0.0.7 any
permit ip host 80.74.17.9 any
remark IPSEC_VPN
permit esp host 85.234.65.57 any
permit udp host 85.234.65.57 any eq isakmp
permit icmp host 85.234.65.57 any
remark ICMP
permit icmp any any administratively-prohibited
permit icmp any any echo-reply
permit icmp any any packet-too-big
permit icmp any any time-exceeded
permit icmp any any traceroute
permit icmp any any unreachable
remark NTP
permit udp host 80.74.16.30 any eq ntp
permit udp host 80.74.16.31 any eq ntp
remark DNS
permit udp any eq domain any
remark DENY_ALL
deny ip any any log
!
ip access-list extended LAN
remark DENY_BROADCASTS
deny ip any host 10.20.4.0
deny ip any host 10.20.4.255
deny ip host 0.0.0.0 any
remark PERMIT_ALL
permit ip 10.20.4.0 0.0.0.255 any
remark DENY_ALL
deny ip any any log
!
ip access-list standard TELNET_SSH
permit 80.74.17.9
permit 80.74.16.8 0.0.0.7
permit 10.20.4.0 0.0.0.255
!
line vty 0 4
access-class TELNET_SSH in
!
dialer-list 1 protocol ip permit
!
line 3
exec-timeout 0 0
script dialer mobile

 

LINUX VMG VPN PROFILE :

conn cvs161_3g
left=85.234.65.57
leftsubnet=0.0.0.0/0
right=0.0.0.0
rightid=@cvs161.waves.uk.net
rightsubnet=10.20.253.40/29
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
ikelifetime=24h
keylife=24h
keyingtries=3
pfs=no
rekey=yes
auto=start
dpdaction=restart
dpddelay=15
dpdtimeout=30

ipsec.secrets :

%any 85.234.65.57 : PSK “cvsrtmvpn96”

All Traffic will be forced to be sent down the tunnel including
INTERNET BREAK-OUT terminating at the Linux VM :

Linux VPN Profile

leftsubnet=0.0.0.0/0
right=0.0.0.0

Cisco Router VPN ACL set to :

ip access-list extended VPN
permit ip 10.20.4.0 0.0.0.255 any

This will cause all traffic to be pushed down the tunnel, even internet bound traffic.

 

Changes made to Linux terminating firewall

This will locally break-out sourced traffic to the internet :
iptables -t nat -I POSTROUTING 83 -o eth1 -s 10.20.4.0/24 -j MASQUERADE
!
route add –host 85.234.66.161 gw 85.234.65.57
!

This will provide HQ connectivity and block intersite connectivity as well
as allow
internet access :

iptables -I FORWARD 46 -s 10.20.78.0/26 -d 10.20.0.0/24 -j ACCEPT
iptables -I FORWARD 47 -s 10.20.0.0/24 -d 10.20.78.0/26 -j ACCEPT
iptables -I FORWARD 48 -s 10.20.78.0/26 -d 10.20.0.0/16 -j DROP
iptables -I FORWARD 49 -s 10.20.0.0/16 -d 10.20.78.0/26 -j DROP
iptables -I FORWARD 50 -s 10.20.78.0/26 -j ACCEPT
iptables -I FORWARD 51 -d 10.20.78.0/26 -j ACCEPT

 

This is to allow HQ site to be able to establish connectivity over to remote site via
ipsec vpn tunnel

iptables -t nat -N 3g_access

sudo iptables -t nat -I POSTROUTING 85 -s 10.20.0.0/24 -j 3g_access
!
sudo iptables -t nat -I 3g_access 5 -d 10.20.78.0/26 -p icmp –icmp-type echo-request -j ACCEPT
sudo iptables -t nat -I 3g_access 6 -d 10.20.78.0/26 -j ACCEPT

CISCO 887VA-W WIRELESS + Integrated Access-Point – SINGLE SSID

Cisco Router Configuration :

interface Wlan-GigabitEthernet0
description Internal switch interface connecting to the embedded AP
switchport mode trunk
no ip address
!
interface wlan-ap0
description Embedded Service module interface to manage the embedded AP
ip unnumbered Vlan1
no ip redirects
no ip unreachables
!
!

interface Vlan1
description DODDS-WIFI
ip address 10.10.66.200 255.255.255.0
ip access-group CLIENT_LAN in
ip nat inside
ip inspect myfw in
ip virtual-reassembly in
ip tcp adjust-mss 1400

!
!

Create VLAN 1 ACCESS-LISTS


VLAN 1 :

ip access-list extended CLIENT_LAN
remark DHCP
permit udp any eq bootpc any eq bootps
remark SPOOFED
deny ip any host 10.10.66.255
deny ip any host 10.10.66.0
deny ip host 0.0.0.0 any
remark PERMIT_ALL
permit ip 10.10.66.0 0.0.0.255 any
remark DENY_ALL
deny ip any any log

!
!

Create DHCP Scope :

ip dhcp pool CLIENT
import all
network 10.10.66.0 255.255.255.0
default-router 10.10.66.200
dns-server 10.10.1.11 10.10.1.2 10.10.66.200
lease 0 12
update arp
!
!

Default Config in place :

bridge 1 protocol ieee
bridge 1 route ip

!
!

Cisco ACCESS-POINT Configuration :


CREATE SSID’s for VLAN :

dot11 ssid DODDS-GUEST
vlan 1

authentication open
authentication key-management wpa
mbssid guest-mode
wpa-psk ascii 7 00564302545F0F1528341F1B1D4855

!
!

Wireless Radio Interface Configuration :

interface Dot11Radio0
no ip address
no ip route-cache
!
!
encryption vlan 1 mode ciphers tkip
!
ssid DODDS-GUEST
!
!
antenna gain 0
speed basic-12.0 basic-18.0 basic-24.0 basic-36.0 basic-48.0 basic-54.0 m0. m1. m2. m3. m4. m5. m6. m7. m8. m9. m10. m11. m12. m13. m14. m15.
channel 2412
station-role root
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled

!
!

INTERVLAN Routing Interface :

interface GigabitEthernet0
description the embedded AP GigabitEthernet 0 is an internal interface connecting AP with the host router
no ip address
no ip route-cache
!
interface GigabitEthernet0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
no bridge-group 1 source-learning
bridge-group 1 spanning-disabled

!
!

CREATE 1 Bridge Interfaces :

interface BVI1
description CLIENTLAN
ip address 10.10.66.201 255.255.255.0
no ip route-cache

!
!

Default bridge group is 1

bridge 1 protocol ieee
bridge 1 route ip

Create a Default Route over to Cisco Router VLAN 1 :

ip default-gateway 10.10.66.200

 

Complete Router Configs :

Router
AP 

CISCO 887VA-W Integrated Access-Point – DUAL SSID’s

CISCO 887VA-W WIRELESS + INTERGATED ACCESS-POINT

Cisco Router Configuration :

interface Wlan-GigabitEthernet0
description Internal switch interface connecting to the embedded AP
switchport mode trunk
no ip address

!
interface wlan-ap0
description Embedded Service module interface to manage the embedded AP
ip unnumbered Vlan1
no ip redirects
no ip unreachables
!
!

Create 2 VLANS :

interface Vlan1
description DODDS-WIFI
ip address 10.10.66.200 255.255.255.0
ip access-group CLIENT_LAN in
ip nat inside
ip inspect myfw in
ip virtual-reassembly in
ip tcp adjust-mss 1400
!
interface Vlan2
description DODDS-GUEST
ip address 192.168.66.200 255.255.255.0
ip access-group GUEST_LAN in
ip nat inside
ip inspect myfw in
ip virtual-reassembly in
ip tcp adjust-mss 1400

To ensure VLAN 2 is created, we suggest you configure one of the router’s FastEthernet interfaces
so that it is assigned to VLAN 2. This will force the router to create VLAN 2 in its VLAN database:

int fastethernet0/0
switchport access vlan 2 

!
!

 

Create 2 VLAN ACCESS-LISTS

VLAN 1 :

 

ip access-list extended CLIENT_LAN
remark DHCP
permit udp any eq bootpc any eq bootps
remark SPOOFED
deny ip any host 10.10.66.255
deny ip any host 10.10.66.0
deny ip host 0.0.0.0 any
remark PERMIT_ALL
permit ip 10.10.66.0 0.0.0.255 any
remark DENY_ALL
deny ip any any log
!

VLAN2 :

ip access-list extended GUEST_LAN 
remark DHCP
permit udp any eq bootpc any eq bootps
remark SPOOFED
deny ip any host 192.168.66.255
deny ip any host 192.168.66.0
deny ip host 0.0.0.0 any
remark DENY_GUESTLAN_TO_LAN
deny ip 192.168.66.0 0.0.0.255 10.10.66.0 0.0.0.255
remark PERMIT_GUESTLAN
permit ip 192.168.66.0 0.0.0.255 any
remark DENY_ALL
deny ip any any log

!
!

Create 2 DHCP Scopes for both Networks :

ip dhcp pool CLIENT
import all
network 10.10.66.0 255.255.255.0
default-router 10.10.66.200
dns-server 10.10.1.11 10.10.1.2 10.10.66.200
lease 0 12
update arp

ip dhcp pool GUEST
import all
network 192.168.66.0 255.255.255.0
default-router 192.168.66.200
dns-server 192.168.66.200
lease 0 12
update arp

!
!

Default Config in place :

bridge 1 protocol ieee
bridge 1 route ip

!
!

Cisco ACCESS-POINT Configuration :


CREATE 2 SSID’s for the 2 VLAN’s

dot11 ssid DODDS-WIFI
vlan 1
authentication open
mbssid guest-mode

!

dot11 ssid DODDS-GUEST
vlan 2
authentication open
authentication key-management wpa
mbssid guest-mode
wpa-psk ascii 7 00564302545F0F1528341F1B1D4855

!
!

Wireless Radio Interface Configuration :

interface Dot11Radio0
no ip address
no ip route-cache
!
encryption vlan 1 key 1 size 128bit 7 B4FC3CB4C9F77341AC86BD5936B9 transmit-key
encryption vlan 1 mode wep mandatory
!
encryption vlan 2 mode ciphers tkip
!
ssid DODDS-GUEST
!
ssid DODDS-WIFI
!
antenna gain 0
speed basic-12.0 basic-18.0 basic-24.0 basic-36.0 basic-48.0 basic-54.0 m0. m1. m2. m3. m4. m5. m6. m7. m8. m9. m10. m11. m12. m13. m14. m15.
channel 2412
station-role root
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled
!
interface Dot11Radio0.2
encapsulation dot1Q 2
no ip route-cache
no cdp enable
bridge-group 2
bridge-group 2 subscriber-loop-control
bridge-group 2 block-unknown-source
no bridge-group 2 source-learning
no bridge-group 2 unicast-flooding
bridge-group 2 spanning-disabled

!
!

INTERVLAN Routing Interface :

interface GigabitEthernet0
description the embedded AP GigabitEthernet 0 is an internal interface connecting
AP with the host router
no ip address
no ip route-cache
!
interface GigabitEthernet0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
no bridge-group 1 source-learning
bridge-group 1 spanning-disabled

!
interface GigabitEthernet0.2
encapsulation dot1Q 2
no ip route-cache
bridge-group 2
no bridge-group 2 source-learning
bridge-group 2 spanning-disabled

!
!

CREATE 2 Bridge Interfaces :


interface BVI1
description CLIENTLAN
ip address 10.10.66.201 255.255.255.0
no ip route-cache
!
interface BVI2
description GUESTLAN
ip address 192.168.66.201 255.255.255.0
ip helper-address 10.10.66.200
no ip route-cache

!
!

Default bridge group is 1, Create bridge 2 for Bridge interface BV2 &
interface GigabitEthernet0.2

bridge 1 protocol ieee
bridge 1 route ip
bridge 2 protocol ieee

Create a Default Route over to Cisco Router VLAN 1 :

ip default-gateway 10.10.66.200

 

Complete Router Configs :

Router
AP 

CISCO 1131AP VLAN 8 NATIVE – DEFAULT-GATEWAY

version 12.3
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname AP
!
enable secret 5 $1$cOge$9zbTng9zmzz0L8KShmMwU/
!
ip subnet-zero
!
!
no aaa new-model
!
dot11 ssid JAZ_DMZ
vlan 8
authentication open
authentication key-management wpa
guest-mode
wpa-psk ascii 7 143D48051A57284F0918
!
power inline negotiation prestandard source
!
!
username Cisco password 7 02250D480809
!
bridge irb
!
!
interface Dot11Radio0
no ip address
no ip route-cache
!
encryption vlan 8 mode ciphers tkip
!
encryption mode ciphers tkip
!
ssid JAZ_DMZ
!
speed basic-11.0 24.0 36.0 48.0 54.0
channel 2462
station-role root access-point
world-mode dot11d country GB outdoor
!
interface Dot11Radio0.8
encapsulation dot1Q 8 native
no ip route-cache
no cdp enable
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled
!
interface Dot11Radio1
no ip address
no ip route-cache
shutdown
speed basic-6.0 9.0 basic-12.0 18.0 basic-24.0 36.0 48.0 54.0
station-role root
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled
!
interface FastEthernet0
no ip address
no ip route-cache
speed 100
full-duplex
bridge-group 1
no bridge-group 1 source-learning
!
interface BVI1
ip address 192.168.8.2 255.255.255.248
no ip route-cache
!
ip default-gateway 192.168.8.1
ip http server
no ip http secure-server
ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
!
!
control-plane
!
bridge 1 route ip
!
!
!
line con 0
line vty 0 4
login local
!
end

 

Notes :

Layer 2 switch is configured for vlan 8 and Layer 3 router is also configured for
DOT1Q vlan 8 and all Nating is in place on the Layer 3 router that does the
inter- Vlan routing.

CISCO WIRELESS CONFIGURATION

CISCO WIRELESS

Authenication WPA + Single SSID.

dot11 ssid DFWireless
vlan 1
authentication open
authentication key-management wpa
guest-mode
wpa-psk ascii 7 06001C225B4B0B485C4341
!
!
interface Dot11Radio0
no ip address
!
encryption mode ciphers tkip
encryption vlan 1 mode ciphers tkip
!
ssid DFWireless
!
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root
world-mode dot11d country GB outdoor
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
!
!
interface Vlan1
no ip address
bridge-group 1
bridge-group 1 spanning-disabled
!
!
interface BVI1
description LAN
ip address 10.10.#.254 255.255.255.0
ip inspect myfw in
ip nat inside
ip virtual-reassembly
!
!
bridge 1 protocol ieee
bridge 1 route ip

#######################################

Authentication WEP  + Single SSID.

dot11 ssid DFWireless
vlan 1
authentication open
guest-mode
!
interface Dot11Radio0
no ip address
!
encryption vlan 1 key 1 size 128bit 7 3D5B79CA337DD1C379430BA081F3 transmit-key
encryption vlan 1 mode wep mandatory
!
ssid DFWireless
!
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root access-point
world-mode dot11d country GB outdoor

#######################################

Multiple mbssid Authentication open + WPA

dot11 ssid DFWireless
vlan 2
authentication open
authentication key-management wpa
mbssid guest-mode
wpa-psk ascii 7 00564302545F0F1528341F1B1D4855
!
dot11 ssid DFWireless-GUEST
vlan 1
authentication open
mbssid guest-mode
!
interface Dot11Radio0
no ip address
!
encryption vlan 1 key 1 size 128bit 7 B4FC3CB4C9F77341AC86BD5936B9 transmit-key
encryption vlan 1 mode wep mandatory
!
encryption vlan 2 mode ciphers tkip
!
ssid DFWireless
!
ssid DFWireless-GUEST
!
mbssid
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root access-point
world-mode dot11d country GB outdoor
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
!
interface Dot11Radio0.2
encapsulation dot1Q 2 native
bridge-group 2
bridge-group 2 subscriber-loop-control
bridge-group 2 spanning-disabled
bridge-group 2 block-unknown-source
no bridge-group 2 source-learning
no bridge-group 2 unicast-flooding
!
interface Vlan1
no ip address
bridge-group 1
bridge-group 1 spanning-disabled
!
interface Vlan2
no ip address
bridge-group 2
bridge-group 2 spanning-disabled
!
interface BVI1
description DFWireless
ip address 10.10.1.254 255.255.255.0
!
interface BVI2
description DFWireless-GUEST
ip address 10.10.2.254 255.255.255.0
!
bridge 1 protocol ieee
bridge 1 route ip
!
bridge 2 protocol ieee
bridge 2 route ip

#######################################

CISCO 881W <<Integrated Wireless AP>>

dot11 mbssid
!
dot11 ssid DFWireless
vlan 1
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 15115F01137E272F7B21
!
interface Dot11Radio0
no ip address
no ip route-cache
!
encryption vlan 1 mode ciphers aes-ccm tkip
!
broadcast-key vlan 1 change 30
!
!
ssid DFWireless
!
antenna gain 0
speed basic-12.0 basic-18.0 basic-24.0 basic-36.0 basic-48.0 basic-54.0 m0. m1. m2. m3. m4. m5. m6. m7. m8. m9. m10. m11. m12. m13. m14. m15.
station-role root access-point
world-mode dot11d country GB outdoor
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled
!
interface GigabitEthernet0
description the embedded AP GigabitEthernet 0 is an internal interface connecting AP with the host router
no ip address
no ip route-cache
!
interface GigabitEthernet0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
no bridge-group 1 source-learning
bridge-group 1 spanning-disabled
!
interface BVI1
ip address 192.168.126.204 255.255.255.0
!
bridge 1 protocol ieee
bridge 1 route ip

Cisco 881 + XRIO UBM

881 Router Config :

interface FastEthernet4
ip address (PUBLIC_LAN_IP_ADDRESS)
!
!
interface Vlan1
Description LAN
ip address 192.168.1.1 255.255.255.0
!
bridge 1 protocol ieee
bridge 1 route ip

 

UBM :

configure
edit mobile-port Mobile1
apn 3gnet
exit
edit mobile-port Mobile2
apn 3gnet
exit
commit
y

add healthcheck-profile 3G
recovery-time 10000
retry-attempts 10
timeout 10000
exit

add link mobile1
type mobile
port Mobile1
username web
password web
healthcheck-address 8.8.8.8
download 1000
upload 1000
healthcheck-profile 3G
exit

add link mobile2
type mobile
port Mobile2
username web
password web
healthcheck-address 8.8.8.8
download 1000
upload 1000
healthcheck-profile 3G

add lan-interface lan1
port Port1
address <<LAN_IP_ADDRESS>><<NOTATION>> ( Cisco 881 Point-to-Point-FA4)
exit
commit
y

edit system parameters
system-name <<SITE_NAME>>
tcp-mss-clamp-mode manual

tcp-mss-clamp-value 1400
timeserver-primary 80.74.16.30
timeserver-secondary 80.74.16.31
exit

remove access-rule AllowSSH
remove access-rule AllowHTTPS
remove access-rule AllowSNMP
commit
y

edit user admin
password globalwave
exit
commit
y

config save

add address-alias SSH
type source
address 85.234.86.74/32
exit

add access-rule SSH
source SSH
exit

add tunnel site_name-3g1
type tcp
endpoint-remote 80.74.16.189
endpoint-local mobile1Endpoint
virtual-remote <<IP_ADDRESS>>
virtual-local <<IP_ADDRESS>>
download 1000
upload 1000
exit

add tunnel site_name-3g2
type tcp
endpoint-remote 80.74.16.189
endpoint-local mobile2Endpoint
virtual-remote <<IP_ADDRESS>>
virtual-local <<IP_ADDRESS>>
download 1000
upload 1000
exit
commit
y

add team team1-3g
algorithm distribute
add member tunnel site_name-3g1
exit
add member tunnel site_name-3g2
exit
exit

add policy policy1
source lan1Subnet
destination any
team team1-3g
exit

commit
y

config save

 

VBOND :

 

add tunnel site_name-3g1
type tcp
endpoint-remote 0.0.0.0
endpoint-local coreEndpoint
virtual-remote <<IP_ADDRESS>>
virtual-local <<IP_ADDRESS>>
download 1000
upload 1000
exit

add tunnel site_name-3g2
type tcp
endpoint-remote 0.0.0.0
endpoint-local coreEndpoint
virtual-remote <<IP_ADDRESS>>
virtual-local <<IP_ADDRESS>>
download 1000
upload 1000
exit
commit
y

add team site_name-3g
algorithm distribute
add member tunnel site_name-3g1
exit
add member tunnel site_name-3g2
exit
exit
commit
y

add address-alias site_name-lan
type destination
address <<LAN_IP_ADDRESS>><<NOTATION>>
exit
commit
y

add policy site_namepol
destination site_name-lan
team site_name-3g
exit

commit
y

config save

Cisco 881w – Access-Point + XRIO UBM

881 Router Config :

interface FastEthernet4
ip address (PUBLIC_LAN_IP_ADDRESS)
!
interface wlan-ap0
description Service module interface to manage the embedded AP
ip unnumbered Vlan1
no ip redirects
no ip unreachables
arp timeout 0
!
interface Wlan-GigabitEthernet0
description Internal switch interface connecting to the embedded AP
!
interface Vlan1
Description LAN
ip address 192.168.1.1 255.255.255.0
!
bridge 1 protocol ieee
bridge 1 route ip

 

881w Integrated AP : Access-Point :

dot11 mbssid
dot11 syslog
!
dot11 ssid CommsWireless
vlan 1
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 050A130C351D1E074A560547
!
interface Dot11Radio0
no ip address
no ip route-cache
!
encryption vlan 1 mode ciphers tkip
!
encryption mode ciphers tkip
!
broadcast-key vlan 1 change 30
!
!
ssid CommsWireless
!
antenna gain 0
speed  basic-12.0 basic-18.0 basic-24.0 basic-36.0 basic-48.0 basic-54.0 m0. m1. m2. m3. m4. m5. m6.
m7. m8. m9. m10. m11. m12. m13. m14. m15.
station-role root
!

Note :

Under interface Dot11Radio0 

These can be removed :

encryption vlan 1 mode ciphers tkip
encryption mode ciphers tkip

Replaced with :

encryption vlan 1 mode ciphers aes-ccm tkip

 

interface Dot11Radio0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled
!
interface GigabitEthernet0
description the embedded AP GigabitEthernet 0 is an internal interface connecting AP with the host router
no ip address
!
interface GigabitEthernet0.1
encapsulation dot1Q 1 native
bridge-group 1
no bridge-group 1 source-learning
bridge-group 1 spanning-disabled
!
interface BVI1
description LAN
ip address 192.168.1.2 255.255.255.0
!
ip default-gateway 192.168.1.1
!
bridge 1 protocol ieee
bridge 1 route ip

 

UBM :

configure
edit mobile-port Mobile1
apn 3gnet
exit
edit mobile-port Mobile2
apn 3gnet
exit
commit
y

add healthcheck-profile 3G
recovery-time 10000
retry-attempts 10
timeout 10000
exit

add link mobile1
type mobile
port Mobile1
username web
password web
healthcheck-address 8.8.8.8
download 1000
upload 1000
healthcheck-profile 3G
exit

add link mobile2
type mobile
port Mobile2
username web
password web
healthcheck-address 8.8.8.8
download 1000
upload 1000
healthcheck-profile 3G

add lan-interface lan1
port Port1
address <<LAN_IP_ADDRESS>><<NOTATION>>( Cisco 881 Point-to-Point-FA4)
exit
commit
y

edit system parameters
system-name <<SITE_NAME>>
tcp-mss-clamp-mode manual
tcp-mss-clamp-value 1400
timeserver-primary 80.74.16.30
timeserver-secondary 80.74.16.31
exit

remove access-rule AllowSSH
remove access-rule AllowHTTPS
remove access-rule AllowSNMP
commit
y

edit user admin
password globalwave
exit
commit
y

config save

add address-alias SSH
type source
address 85.234.86.74/32
exit

add access-rule SSH
source SSH
exit

add tunnel site_name-3g1
type tcp
endpoint-remote 80.74.16.189
endpoint-local mobile1Endpoint
virtual-remote <<IP_ADDRESS>>
virtual-local <<IP_ADDRESS>>
download 1000
upload 1000
exit

add tunnel site_name-3g2
type tcp
endpoint-remote 80.74.16.189
endpoint-local mobile2Endpoint
virtual-remote <<IP_ADDRESS>>
virtual-local <<IP_ADDRESS>>
download 1000
upload 1000
exit
commit
y 

add team team1-3g
algorithm distribute
add member tunnel site_name-3g1
exit
add member tunnel site_name-3g2
exit
exit

add policy policy1
source lan1Subnet
destination any
team team1-3g
exit

commit
y

config save

 

VBOND :

 

add tunnel site_name-3g1
type tcp
endpoint-remote 0.0.0.0
endpoint-local coreEndpoint
virtual-remote <<IP_ADDRESS>>
virtual-local <<IP_ADDRESS>>
download 1000
upload 1000
exit

add tunnel site_name-3g2
type tcp
endpoint-remote 0.0.0.0
endpoint-local coreEndpoint
virtual-remote <<IP_ADDRESS>>
virtual-local <<IP_ADDRESS>>
download 1000
upload 1000
exit
commit
y

add team site_name-3g
algorithm distribute
add member tunnel site_name-3g1
exit
add member tunnel site_name-3g2
exit
exit
commit
y

add address-alias site_name-lan
type destination
address <<LAN_IP_ADDRESS>><<NOTATION>>
exit
commit
y

add policy site_namepol
destination site_name-lan
team site_name-3g
exit

commit
y

config save

CISCO – WFQ – Weighted Fair Queuing

A configured working solution :

From here you will need to make a route-map and set ip precedence or TOS values :

!

ip access-list extended qos_outbound
permit tcp 192.168.10.64 0.0.0.31 any eq 443
permit tcp 192.168.10.64 0.0.0.31 any eq 3389
!
!
route-map qos_outbound
match ip address qos_outbound
set ip tos 8
!
!
interfave vlan 1
fair-queue
hold-queue 4096 out
!
interface Bvi1
ip policy route-map qos_outbound