Networking-Blog

My WordPress Blog

CISCO 1131AP VLAN 8 NATIVE – DEFAULT-GATEWAY

version 12.3
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname AP
!
enable secret 5 $1$cOge$9zbTng9zmzz0L8KShmMwU/
!
ip subnet-zero
!
!
no aaa new-model
!
dot11 ssid JAZ_DMZ
vlan 8
authentication open
authentication key-management wpa
guest-mode
wpa-psk ascii 7 143D48051A57284F0918
!
power inline negotiation prestandard source
!
!
username Cisco password 7 02250D480809
!
bridge irb
!
!
interface Dot11Radio0
no ip address
no ip route-cache
!
encryption vlan 8 mode ciphers tkip
!
encryption mode ciphers tkip
!
ssid JAZ_DMZ
!
speed basic-11.0 24.0 36.0 48.0 54.0
channel 2462
station-role root access-point
world-mode dot11d country GB outdoor
!
interface Dot11Radio0.8
encapsulation dot1Q 8 native
no ip route-cache
no cdp enable
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled
!
interface Dot11Radio1
no ip address
no ip route-cache
shutdown
speed basic-6.0 9.0 basic-12.0 18.0 basic-24.0 36.0 48.0 54.0
station-role root
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled
!
interface FastEthernet0
no ip address
no ip route-cache
speed 100
full-duplex
bridge-group 1
no bridge-group 1 source-learning
!
interface BVI1
ip address 192.168.8.2 255.255.255.248
no ip route-cache
!
ip default-gateway 192.168.8.1
ip http server
no ip http secure-server
ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
!
!
control-plane
!
bridge 1 route ip
!
!
!
line con 0
line vty 0 4
login local
!
end

 

Notes :

Layer 2 switch is configured for vlan 8 and Layer 3 router is also configured for
DOT1Q vlan 8 and all Nating is in place on the Layer 3 router that does the
inter- Vlan routing.

CISCO WIRELESS CONFIGURATION

CISCO WIRELESS

Authenication WPA + Single SSID.

dot11 ssid DFWireless
vlan 1
authentication open
authentication key-management wpa
guest-mode
wpa-psk ascii 7 06001C225B4B0B485C4341
!
!
interface Dot11Radio0
no ip address
!
encryption mode ciphers tkip
encryption vlan 1 mode ciphers tkip
!
ssid DFWireless
!
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root
world-mode dot11d country GB outdoor
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
!
!
interface Vlan1
no ip address
bridge-group 1
bridge-group 1 spanning-disabled
!
!
interface BVI1
description LAN
ip address 10.10.#.254 255.255.255.0
ip inspect myfw in
ip nat inside
ip virtual-reassembly
!
!
bridge 1 protocol ieee
bridge 1 route ip

#######################################

Authentication WEP  + Single SSID.

dot11 ssid DFWireless
vlan 1
authentication open
guest-mode
!
interface Dot11Radio0
no ip address
!
encryption vlan 1 key 1 size 128bit 7 3D5B79CA337DD1C379430BA081F3 transmit-key
encryption vlan 1 mode wep mandatory
!
ssid DFWireless
!
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root access-point
world-mode dot11d country GB outdoor

#######################################

Multiple mbssid Authentication open + WPA

dot11 ssid DFWireless
vlan 2
authentication open
authentication key-management wpa
mbssid guest-mode
wpa-psk ascii 7 00564302545F0F1528341F1B1D4855
!
dot11 ssid DFWireless-GUEST
vlan 1
authentication open
mbssid guest-mode
!
interface Dot11Radio0
no ip address
!
encryption vlan 1 key 1 size 128bit 7 B4FC3CB4C9F77341AC86BD5936B9 transmit-key
encryption vlan 1 mode wep mandatory
!
encryption vlan 2 mode ciphers tkip
!
ssid DFWireless
!
ssid DFWireless-GUEST
!
mbssid
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root access-point
world-mode dot11d country GB outdoor
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
!
interface Dot11Radio0.2
encapsulation dot1Q 2 native
bridge-group 2
bridge-group 2 subscriber-loop-control
bridge-group 2 spanning-disabled
bridge-group 2 block-unknown-source
no bridge-group 2 source-learning
no bridge-group 2 unicast-flooding
!
interface Vlan1
no ip address
bridge-group 1
bridge-group 1 spanning-disabled
!
interface Vlan2
no ip address
bridge-group 2
bridge-group 2 spanning-disabled
!
interface BVI1
description DFWireless
ip address 10.10.1.254 255.255.255.0
!
interface BVI2
description DFWireless-GUEST
ip address 10.10.2.254 255.255.255.0
!
bridge 1 protocol ieee
bridge 1 route ip
!
bridge 2 protocol ieee
bridge 2 route ip

#######################################

CISCO 881W <<Integrated Wireless AP>>

dot11 mbssid
!
dot11 ssid DFWireless
vlan 1
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii 7 15115F01137E272F7B21
!
interface Dot11Radio0
no ip address
no ip route-cache
!
encryption vlan 1 mode ciphers aes-ccm tkip
!
broadcast-key vlan 1 change 30
!
!
ssid DFWireless
!
antenna gain 0
speed basic-12.0 basic-18.0 basic-24.0 basic-36.0 basic-48.0 basic-54.0 m0. m1. m2. m3. m4. m5. m6. m7. m8. m9. m10. m11. m12. m13. m14. m15.
station-role root access-point
world-mode dot11d country GB outdoor
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled
!
interface GigabitEthernet0
description the embedded AP GigabitEthernet 0 is an internal interface connecting AP with the host router
no ip address
no ip route-cache
!
interface GigabitEthernet0.1
encapsulation dot1Q 1 native
no ip route-cache
bridge-group 1
no bridge-group 1 source-learning
bridge-group 1 spanning-disabled
!
interface BVI1
ip address 192.168.126.204 255.255.255.0
!
bridge 1 protocol ieee
bridge 1 route ip

Cisco 877w Wireless 2 Vlans

dot11 ssid COMMS-GUEST
vlan 2
authentication open
authentication key-management wpa
guest-mode
mbssid guest-mode
wpa-psk ascii 7 00564302545F0F1528341F1B1D4855
!
dot11 ssid COMMS-WIFI
vlan 1
authentication open
mbssid guest-mode
!
bridge irb
!
encryption vlan 1 key 1 size 128bit 7 B4FC3CB4C9F77341AC86BD5936B9 transmit-key
encryption vlan 1 mode wep mandatory
!
encryption vlan 2 mode ciphers tkip
!
ssid COMMS-GUEST
!
ssid COMMS-WIFI
!
mbssid
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0
station-role root
world-mode dot11d country GB outdoor
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
!
interface Dot11Radio0.2
encapsulation dot1Q 2
no cdp enable
bridge-group 2
bridge-group 2 subscriber-loop-control
bridge-group 2 spanning-disabled
bridge-group 2 block-unknown-source
no bridge-group 2 source-learning
no bridge-group 2 unicast-flooding
!
interface Vlan1
no ip address
bridge-group 1
bridge-group 1 spanning-disabled
!
interface Vlan2
no ip address
bridge-group 2
bridge-group 2 spanning-disabled
!
interface BVI1
description LAN
ip address 1.1.1.1 255.255.255.0
ip inspect myfw in
ip nat inside
ip virtual-reassembly
!
interface BVI2
description GUESTLAN
ip address 2.2.2.2 255.255.255.0
ip inspect myfw in
ip nat inside
ip virtual-reassembly
!
bridge 1 protocol ieee
bridge 1 route ip
bridge 2 protocol ieee
bridge 2 route ip

Cisco Wireless 877w Signal Tweak

Commstest(config)#int dot11Radio0
!
world-mode dot11d country GB outdoor
station-role root access-point
channel 2462
power local cck max
power local ofdm max

!

speed throughput ofdm     –  OFDM Weak Signal Detection ON
speed range
speed 54.0
!
channel least-congested   – Dynamically channel set for least-congested chanel.

config t
interface dot11radio0
channel 2462

This set the channel to 11

I was able to verfiy this using the show controllers command
I found this table with the channels and their respective frequencies

Channel 1 : 2412 Mhz 11g
Channel 2 : 2417 Mhz 11g
Channel 3 : 2422 Mhz 11g
Channel 4 : 2427 Mhz 11g
Channel 5 : 2432 Mhz 11g
Channel 6 : 2437* Mhz 11g
Channel 7 : 2442 Mhz 11g
Channel 8 : 2447 Mhz 11g
Channel 9 : 2452 Mhz 11g
Channel 10 : 2457 Mhz 11g
Channel 11 : 2462 Mhz 11g
!
!
show controllers dot11Radio 0

Configuring the RTS Threshold

Request to Send (RTS) indicates the size of a frame that requires an RTS control message sent before it.
You must keep a few considerations in mind when you set this parameter.

RTS packets are sent more often because of smaller values. In addition, more bandwidth is consumed,
therefore reducing the amount of throughput on the network. However, the more RTS packets sent, the
quicker the system can recover from interference or collisions, which occurs in large, busy networks.

RTS is also helpful when two clients cannot hear each other (for instance, they are on opposite sides of a cell),
although they can hear the AP.

The RTS Threshold setting is between 0 and 2339 bytes. The default value is 2312.

The RTS Max. Retries setting dictates the number of times the AP issues an RTS before it quits.
This setting is a value between 1 and 128. The default value is 32.

Configuring Data Retries

When packets are sent, they can be lost. As such, the AP resends the packets to ensure the packets are
received by the client. You can tell the AP how often to resend packets by configuring the maximum amount
of data retries.

packet retries 128

Cisco 877w WPA Key Wireless Configuration

dot11 ssid CommsWireless
authentication open
authentication key-management wpa
guest-mode
wpa-psk ascii 0 12345678910
!
interface Dot11Radio0
no ip address
!
encryption mode ciphers tkip
!
ssid CommsWireless
!
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root
world-mode dot11d country GB outdoor
!
interface Dot11Radio0.1
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
!
interface Vlan1
no ip address
bridge-group 1
bridge-group 1 spanning-disabled
!
!
interface BVI1
description $ES_LAN$
ip address 192.168.1.1 255.255.255.0
ip nat inside
ip virtual-reassembly
!
!
bridge 1 protocol ieee
bridge 1 route ip

!