Need Help Configuring Wireless Interface on Cisco 1811 Router

Unanswered Question
Sep 9th, 2010

Hi all,

I'm a programmer by trade, and have been given the task of configuring my company's new cisco router.  I've never done any of this stuff before, but have managed to stumble my way though the CLI to setup the basics. However, I haven't been able to figure out the wireless part as I'm having trouble finding enough information to describe how to setup/configure a Dot11Radio interface on a Cisco router.

My environment is as follows:
- We have 2 companies (both owned by same owner) residing in the same building.
- We have 2 DSL lines coming in (one for each company) each with their own modem. Both modems will be connected to the Cisco 1811 router via Fa0 and Fa1 ethernet ports.
- Inside the router I have 3 vlans setup:
  VLAN 10 for Company A [10.10.10.0]
  VLAN 20 for Company B [10.10.20.0]
  VLAN 30 for Guests    [10.10.30.0]


I have 2 Dot11Radio interfaces on the router.  What I would like to do is attach Dot11Radio-0 to VLAN 10, giving Company A wireless access to their network.  Then I would like to setup Dot11Radio-1 as the sole access point for VLAN 30, so that guests can *only* get access to the internet via a wireless connection.

I've gone through the steps found on Cisco's website shown here http://www.cisco.com/en/US/docs/ios/wlan/configuration/guide/wi_cfg_vlans_ps6441_TSD_Products_Configuration_Guide_Chapter.html#wp1059830  but it doesn't seem to be properly configuring the wireless interface as I can't get any wireless connection.  This is probably due to the fact that I'm getting a little hung up as I go through the steps.

I seem to be good on steps 1-6, but I have questions after that.  On step 7 am I to use the exact same SSID i created in step 3? Is this how the radio interface is linked to the vlan - by using the same SSID?  Also, once I enter the SSID in step 7, the line prompt does not change to "Router(config-if-ssid)#" like the example shows, instead it remains as Router(config-if)#.

Then I'm really getting hung up on the steps 10 and 11. Do I have to use sub interfaces when I only have 2 networks that I need wireless access, one for each Dot11Radio interface? If I can get around using subinterfaces how do I set it up? - as the example only shows how to use subinterfaces.

Please explain [with enough info for a newbie to understand] what I need to do to set this up.  Thanks in advance for your help.

Below is my current config from the router:

!
version 12.4
no service config
no service timestamps debug datetime msec
no service timestamps log datetime msec
no service password-encryption
!
hostname xxxxx
!
boot-start-marker
boot-end-marker
!
logging buffered 51200 warnings
!
no aaa new-model
clock timezone PCTime -5
!
!
no ip dhcp use vrf connected
ip dhcp excluded-address 10.10.10.1 10.10.10.150
ip dhcp excluded-address 10.10.10.200 10.10.10.255
ip dhcp excluded-address 10.10.20.1 10.10.20.150
ip dhcp excluded-address 10.10.20.200 10.10.20.255
!
ip dhcp pool 10.10.10.0/24
network 10.10.10.0 255.255.255.0
default-router 10.10.10.1
dns-server xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx
!
ip dhcp pool 10.10.20.0/24
network 10.10.20.0 255.255.255.0
default-router 10.10.20.1
dns-server xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx
!
ip dhcp pool 10.10.30.0/24
network 10.10.30.0 255.255.255.0
default-router 10.10.30.1
dns-server xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx
!
!
ip cef
ip domain name xxxxxx.com
ip name-server xxx.xxx.xxx.xxx
ip name-server xxx.xxx.xxx.xxx
no ipv6 cef
!
multilink bundle-name authenticated
!
!
username xxxxx privilege 15 password xxxxx
archive
log config
  hidekeys
!
!
!
!
interface FastEthernet0
description $Company A Gateway$
ip address xxx.xxx.xxx.xxx 255.255.255.0
ip access-group 101 in
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
interface FastEthernet1
description $Company B Gateway$
ip address xxx.xxx.xxx.xxx 255.255.255.0
ip access-group 101 in
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
interface FastEthernet2
switchport access vlan 10
!
interface FastEthernet3
switchport access vlan 10
!
interface FastEthernet4
switchport access vlan 10
!
interface FastEthernet5
switchport access vlan 10
!
interface FastEthernet6
switchport access vlan 10
!
interface FastEthernet7
switchport access vlan 10
!
interface FastEthernet8
switchport access vlan 10
!
interface FastEthernet9
switchport access vlan 20
!
interface Dot11Radio0
no ip address
no ip route-cache
shutdown
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root
no cdp enable
!
interface Dot11Radio1
no ip address
no ip route-cache
shutdown
speed basic-6.0 9.0 basic-12.0 18.0 basic-24.0 36.0 48.0 54.0
station-role root
no cdp enable
!
interface Vlan1
no ip address
no ip nat inside
shutdown
!
interface Vlan10
description $Company A Network Block$
ip address 10.10.10.1 255.255.255.0
ip access-group 110 in
ip nat inside
ip virtual-reassembly
!
interface Vlan20
description $Company B Network Block$
ip address 10.10.20.1 255.255.255.0
ip access-group 120 in
ip nat inside
ip virtual-reassembly
!
interface Vlan30
description $Guest Network Block$
ip address 10.10.30.1 255.255.255.0
ip access-group 130 in
ip nat inside
ip virtual-reassembly
!
interface Async1
no ip address
encapsulation slip
no ip route-cache
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 xxx.xxx.xxx.xxx
!
!
no ip http server
no ip http secure-server
ip nat inside source list 1 interface FastEthernet0 overload
ip nat inside source list 2 interface FastEthernet1 overload
!
!
access-list 1 permit 10.10.10.0 0.0.0.255
access-list 2 permit 10.10.20.0 0.0.0.255
access-list 2 permit 10.10.30.0 0.0.0.255
access-list 101 permit tcp any any established
access-list 110 permit ip host 10.10.10.5 host 10.10.20.5
access-list 110 permit ip host 10.10.10.5 host 10.10.20.6
access-list 110 permit ip host 10.10.10.6 host 10.10.20.5
access-list 110 permit ip host 10.10.10.6 host 10.10.20.6
access-list 110 deny   ip 10.10.10.0 0.0.0.255 10.10.20.0 0.0.0.255
access-list 110 deny   ip 10.10.10.0 0.0.0.255 10.10.30.0 0.0.0.255
access-list 110 permit ip any any
access-list 120 permit ip host 10.10.20.5 host 10.10.10.5
access-list 120 permit ip host 10.10.20.5 host 10.10.10.6
access-list 120 permit ip host 10.10.20.6 host 10.10.10.5
access-list 120 permit ip host 10.10.20.6 host 10.10.10.6
access-list 120 deny   ip 10.10.20.0 0.0.0.255 10.10.10.0 0.0.0.255
access-list 120 deny   ip 10.10.20.0 0.0.0.255 10.10.30.0.0.0.0.255
access-list 120 permit ip any any
access-list 130 deny   ip 10.10.30.0 0.0.0.255 10.10.10.0 0.0.0.255
access-list 130 deny   ip 10.10.30.0 0.0.0.255 10.10.20.0 0.0.0.255
access-list 130 permit ip any any
!
!
control-plane
!
!
banner login ^
---------------------------------------------------------
Only authorized Company A Employee's may access this device.
If you are NOT an authorized user, disconnect now!!!
---------------------------------------------------------
^
!
!
line con 0
login local
line 1
modem InOut
stopbits 1
speed 115200
flowcontrol hardware
line aux 0
line vty 0 4
password xxxxxx
login
!
no process cpu extended
no process cpu autoprofile hog
end

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.

Actions

This Discussion