?
Solved

Reconfig of Cisco AP to no vlans

Posted on 2008-06-26
5
Medium Priority
?
715 Views
Last Modified: 2013-11-12
Hi Experts,

I initially set up my cisco wireless ap on a network where I have several vlans, the config works great.  I have been asked to ship one of my ap to another site where they do not have vlans and I wanted to make sure my config would work once shipped.  I am including the important part of this config change.  I understand the ip address and pretty normal stuff will change and I have that under control its this part of the config I want to make sure is ok.  

This is my initial config:

dot11 ssid <ssid>
   vlan 90
   authentication open eap eap_methods
   authentication key-management wpa
!

interface Dot11Radio0
 no ip address
 no ip route-cache
 !
 encryption vlan 90 mode ciphers tkip
 !
 encryption vlan 75 mode ciphers aes-ccm tkip
 !
 ssid <ssid>
 !
 speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
 station-role root
 bridge-group 1
 bridge-group 1 block-unknown-source
 no bridge-group 1 source-learning
 no bridge-group 1 unicast-flooding
 bridge-group 1 spanning-disabled
!
interface Dot11Radio0.75
 encapsulation dot1Q 75
 no ip route-cache
!
interface Dot11Radio0.90
 encapsulation dot1Q 90
 no ip route-cache
 bridge-group 90
 bridge-group 90 subscriber-loop-control
 bridge-group 90 block-unknown-source
 no bridge-group 90 source-learning
 no bridge-group 90 unicast-flooding
 bridge-group 90 spanning-disabled
!
interface FastEthernet0
 no ip address
 no ip route-cache
 duplex auto
 speed auto
!
interface FastEthernet0.1
 encapsulation dot1Q 1
 no ip route-cache
!
interface FastEthernet0.40
 encapsulation dot1Q 40 native
 no ip route-cache
 bridge-group 1
 no bridge-group 1 source-learning
 bridge-group 1 spanning-disabled
!
interface FastEthernet0.90
 encapsulation dot1Q 90
 no ip route-cache
 bridge-group 90
 no bridge-group 90 source-learning
 bridge-group 90 spanning-disabled


This is my reconfigured AP with no vlans:

dot11 ssid <ssid>
   vlan 1
   authentication open eap eap_methods
   authentication key-management wpa
!

interface Dot11Radio0
 no ip address
 no ip route-cache
 !
 encryption vlan 1 mode ciphers tkip
 !
 ssid <ssid>
 !
 speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
 station-role root
 bridge-group 1
 bridge-group 1 block-unknown-source
 no bridge-group 1 source-learning
  no bridge-group 1 unicast-flooding
 bridge-group 1 spanning-disabled
!
interface Dot11Radio0.1
 no ip route-cache
!
interface FastEthernet0
 no ip address
 no ip route-cache
 duplex auto
 speed auto
!
interface FastEthernet0.1
 encapsulation dot1Q 1 native
 no ip route-cache
 bridge-group 1
 no bridge-group 1 source-learning
 bridge-group 1 spanning-disabled

Also, since I am not using vlans, can this be put on a normal switchport and not a trunk port?

Thanks,

R
0
Comment
Question by:rhltechie28
  • 3
  • 2
5 Comments
 
LVL 10

Expert Comment

by:Sorenson
ID: 21875081
Get rid of the subintefaces (.1).. That will still assume you have vlan 1 configured on a switch, and that the AP is connected to a dot1q trunk port.

change it to look like:
==snip===
!
interface Dot11Radio0
 no ip address
 no ip route-cache
 !
 no shut
 !
 ssid xxxxxxx
 !
 station-role root
 bridge-group 1
 bridge-group 1 subscriber-loop-control
 bridge-group 1 block-unknown-source
 no bridge-group 1 source-learning
 no bridge-group 1 unicast-flooding
 bridge-group 1 spanning-disabled
!
!
interface FastEthernet0
 no ip address
 no ip route-cache
 no shut
 bridge-group 1
 no bridge-group 1 source-learning
 bridge-group 1 spanning-disabled
 hold-queue 160 in
!
!
interface BVI1
 ip address x.x.x.x  x.x.x.x
 no ip route-cache
 no shut
!
==snip===

then you will be able to hang it from a regular switch port (non trunked).

0
 

Author Comment

by:rhltechie28
ID: 21875108
Ah, gotcha.  So the config I sent along would work if I have an ip address on vlan 1 of my switch correct?  I believe I do.  I apologize when I said no vlans, that was obviously the wrong wording.
0
 
LVL 10

Accepted Solution

by:
Sorenson earned 1000 total points
ID: 21875304
sure.  if the switch port was a dot1q trunk, and the switch had vlan 1 defined (by default it is there).  it would have been good.  
if you were putting it in a switch that didn't do trunking, or have vlans (for example an unmanged switch), then you would need to remove the sub interfaces.
0
 

Author Comment

by:rhltechie28
ID: 21875375
Thank you for your help.
0
 
LVL 10

Expert Comment

by:Sorenson
ID: 21875394
np -
0

Featured Post

The new generation of project management tools

With monday.com’s project management tool, you can see what everyone on your team is working in a single glance. Its intuitive dashboards are customizable, so you can create systems that work for you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

During and after that shift to cloud, one area that still poses a struggle for many organizations is what to do with their department file shares.
Unable to change the program that handles the scan event from a network attached Canon/Brother printer/scanner. This means you'll always have to choose which program handles this action, e.g. ControlCenter4 (in the case of a Brother).
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…

600 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question