<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MSN 760 and AP point 422 in M and MSM Series</title>
    <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612660#M2973</link>
    <description>We need two SSID vlan - 11, vlan -12. Vlan 11 for Internet access; Vlan 12 for Internal server file access.&lt;BR /&gt;&lt;BR /&gt;vlan 11 - 10.73.186.0/24&lt;BR /&gt;vlan 12 - 10.73.187.0/24&lt;BR /&gt;vlan 80 - 10.73.188.0/24 [ only for management purpose ].&lt;BR /&gt;&lt;BR /&gt;WLC management ip address - 10.73.188.5,&lt;BR /&gt;&lt;BR /&gt;Create two LAN ports on WLC: &lt;BR /&gt;vlan 11; 10.73.186.5&lt;BR /&gt;vlan 12; 10.73.187.5&lt;BR /&gt;&lt;BR /&gt;Create two VSC vlan-11 &amp;amp; vlan-12 with default setting [uncheck "wireless security filter"] then bind the VSC with default accesss point. Now my SSID is advertise, I am able to get DHCP IP from WLC.&lt;BR /&gt;&lt;BR /&gt;NOw my issuse I am able to reach upto wireless controller, but I am not able to ping default gateway. From Wireless controller I am able to ping my switch.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Please suggest &lt;BR /&gt;to troubleshoot, since it is veru urgent, expecting immediate help, if it possible could you please take online session on Saturday.</description>
    <pubDate>Thu, 08 Apr 2010 06:28:14 GMT</pubDate>
    <dc:creator>ProCurve-Super</dc:creator>
    <dc:date>2010-04-08T06:28:14Z</dc:date>
    <item>
      <title>MSN 760 and AP point 422</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612654#M2967</link>
      <description>In MSM 760 Lan port should be tagged port or untagged port also the access point should be in tagged mode or untagged mode, we have 3 VLAN to be broadcast in WLAN.&lt;BR /&gt;&lt;BR /&gt;Myself facing the following issuse in MSM760, in wireless conection from laptop I am able to reach untill wireless controller, but I am not able to ping default gateway of switch.&lt;BR /&gt;&lt;BR /&gt;From wireless controller I am able to ping switch default gateway.&lt;BR /&gt;&lt;BR /&gt;Any suggestion for routing realted issuse in MSM760</description>
      <pubDate>Tue, 06 Apr 2010 12:38:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612654#M2967</guid>
      <dc:creator>ProCurve-Super</dc:creator>
      <dc:date>2010-04-06T12:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: MSN 760 and AP point 422</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612655#M2968</link>
      <description>For the vlans, the default vlan where the controller lan port and the AP are connected should be untagged, for other vlans they should be tagged but depends on the impelemtaion you are using, are they access controlled.&lt;BR /&gt;&lt;BR /&gt;And for th eother issue on the VSC uncheck "wireless security filter" option then save and sync the AP it should work normaly and you will be able to access the network with no issues (i think)</description>
      <pubDate>Tue, 06 Apr 2010 13:48:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612655#M2968</guid>
      <dc:creator>Shadow13</dc:creator>
      <dc:date>2010-04-06T13:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: MSN 760 and AP point 422</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612656#M2969</link>
      <description>For your AP to MSM controller communication you have a choice. Either you can go VLAN all the way or you can have a mix of VLAN and untagged traffic for the management part. It is really up to you and how you want to architect your network. Personally when I do VLANs, I usually want to have ALL my network segmented with VLANs and I don't use untagged traffic in that case. But that's a matter of personal preference.&lt;BR /&gt;&lt;BR /&gt;Something that you must know is that when using the AP in Plug and Play/automatic mode (this is the default AP behavior and it means without explicitely provisioning the AP to seek the MSM controller), the AP will choose any path available to seek the MSM controller. Meaning that there is an automatic discovery procedure that will first seek the MSM controller untagged then move to the VLANs discovered in the network. What this means is that if the AP can find an untagged path to the MSM controller it will most likely use it, but if the untagged path is not available, the AP will try the VLANs, and it may use ANY of your configured VLANs to reach the MSM controller. All this is automatic and you cannot really predict which path the AP will take (in plug and play/automatic mode, it does not matter which path is taken for as long as the AP can communicate with the MSM controller).&lt;BR /&gt;&lt;BR /&gt;If you want to control in a more deterministic way how the AP will discover the controller (untagged or on a particular VLAN), you should use the provisioning pages of the AP to specify the connectivity that you want the AP to use to seek the MSM controller (untagged/tagged, etc).&lt;BR /&gt;&lt;BR /&gt;Now, for your second question, Shadow13 is right, one thing to check is the wireless security filters, but again, we would need to know more about your VSC configuration to cast a definitive answer. Meaning are you access controlled, or not? And based on the answer, are you authenticated or not, etc...</description>
      <pubDate>Wed, 07 Apr 2010 12:02:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612656#M2969</guid>
      <dc:creator>Fred!</dc:creator>
      <dc:date>2010-04-07T12:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: MSN 760 and AP point 422</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612657#M2970</link>
      <description>Access point are able to get associated with wireless controller.&lt;BR /&gt;&lt;BR /&gt;Wireless NIC card are able to get DHCP IP address from Acess point, but not able to ping switch gateway, I have un check wireless security filter, but I am not able to ping the switch gateway, screen shoot attached for MSM760, please give me suggestion for further troubleshoot.</description>
      <pubDate>Wed, 07 Apr 2010 13:14:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612657#M2970</guid>
      <dc:creator>ProCurve-Super</dc:creator>
      <dc:date>2010-04-07T13:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: MSN 760 and AP point 422</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612658#M2971</link>
      <description>the internet vlan (11) you should make it in the internet port not the lan port, please change that and make sure to define it as egress vlan on the VSC. if this is your requirement to use the internet port.&lt;BR /&gt;&lt;BR /&gt;Is this what you want ?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Can you tell us what scenario exaclty are you planning to implement ?</description>
      <pubDate>Wed, 07 Apr 2010 13:32:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612658#M2971</guid>
      <dc:creator>Shadow13</dc:creator>
      <dc:date>2010-04-07T13:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: MSN 760 and AP point 422</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612659#M2972</link>
      <description>From your screen captures, I can see that you are 1) Access Controlled 2) That you want to use HTML authentication&lt;BR /&gt;&lt;BR /&gt;I second Shadow13 for the fact that the way you created VLAN 11 on the same subnet as the Internet port and assigned it to the LAN port is wrong.&lt;BR /&gt;&lt;BR /&gt;The MSM controller is primarily a router, this is why there is a signification between the LAN and the Internet port. Traffic gets routed between the 2 ports. If you create an interface on the LAN port that has the same subnet as the Internet port, the MSM controller will not be able to properly route the traffic. This is most likely why you can't reach the 10.73.186.x segment gateway.</description>
      <pubDate>Wed, 07 Apr 2010 14:05:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612659#M2972</guid>
      <dc:creator>Fred!</dc:creator>
      <dc:date>2010-04-07T14:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: MSN 760 and AP point 422</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612660#M2973</link>
      <description>We need two SSID vlan - 11, vlan -12. Vlan 11 for Internet access; Vlan 12 for Internal server file access.&lt;BR /&gt;&lt;BR /&gt;vlan 11 - 10.73.186.0/24&lt;BR /&gt;vlan 12 - 10.73.187.0/24&lt;BR /&gt;vlan 80 - 10.73.188.0/24 [ only for management purpose ].&lt;BR /&gt;&lt;BR /&gt;WLC management ip address - 10.73.188.5,&lt;BR /&gt;&lt;BR /&gt;Create two LAN ports on WLC: &lt;BR /&gt;vlan 11; 10.73.186.5&lt;BR /&gt;vlan 12; 10.73.187.5&lt;BR /&gt;&lt;BR /&gt;Create two VSC vlan-11 &amp;amp; vlan-12 with default setting [uncheck "wireless security filter"] then bind the VSC with default accesss point. Now my SSID is advertise, I am able to get DHCP IP from WLC.&lt;BR /&gt;&lt;BR /&gt;NOw my issuse I am able to reach upto wireless controller, but I am not able to ping default gateway. From Wireless controller I am able to ping my switch.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Please suggest &lt;BR /&gt;to troubleshoot, since it is veru urgent, expecting immediate help, if it possible could you please take online session on Saturday.</description>
      <pubDate>Thu, 08 Apr 2010 06:28:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612660#M2973</guid>
      <dc:creator>ProCurve-Super</dc:creator>
      <dc:date>2010-04-08T06:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: MSN 760 and AP point 422</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612661#M2974</link>
      <description>Now, it is a bit clearer, but I believe we will need some more details:&lt;BR /&gt;&lt;BR /&gt;1) Can you provide a screen capture of the DHCP server page (I'm assuming you are using the MSM controller's DHCP server for your guests, is that right?)&lt;BR /&gt;&lt;BR /&gt;2) Again you need to consider that anything you put on the LAN port MUST NOT be on the same subnet as the Internet port. So I believe there is a fundamental flaw in how you want this to work. I think the VLAN 11 on the LAN port must be on a private subnet and the Internet port will do the NATing&lt;BR /&gt;&lt;BR /&gt;3) Where is your gateway located? I'm assuming it is on the Internet port side of the controller, right? And please provide the IP address of the gateway.&lt;BR /&gt;&lt;BR /&gt;4) Is the other SSID (the one mapped to VLAN 12) access controlled or not? &lt;BR /&gt;&lt;BR /&gt;With all this information I can try to picture and scan what the setup should look like</description>
      <pubDate>Thu, 08 Apr 2010 12:05:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612661#M2974</guid>
      <dc:creator>Fred!</dc:creator>
      <dc:date>2010-04-08T12:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: MSN 760 and AP point 422</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612662#M2975</link>
      <description>Also to add to Fred, from where do the clients for the 2 VSCs get the IP addresses ?&lt;BR /&gt;&lt;BR /&gt;When you say the clients get IP addresses, from which subnet exactly ?&lt;BR /&gt;&lt;BR /&gt;Where is the internet port connected ? &lt;BR /&gt;&lt;BR /&gt;Do you want to use the internet port for the internet VSC ?&lt;BR /&gt;&lt;BR /&gt;For the internal server VSC, do you want it to be access controller or this is Employees VSC and the core will control it ?&lt;BR /&gt;&lt;BR /&gt;For now either way i think you need to use egress vlans on both VSCs regardless of where the VLAN is created (LAN OR INTERNET PORT, but lets see what exactly you want to confirm how to configure the VLANs and to which port should be assigned.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 09 Apr 2010 00:26:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612662#M2975</guid>
      <dc:creator>Shadow13</dc:creator>
      <dc:date>2010-04-09T00:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: MSN 760 and AP point 422</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612663#M2976</link>
      <description>I am using only LAN ports [ using physical port number -2 on WLC, I am able to see the LAN port in GUI as green ] and create &lt;BR /&gt;VLAN under Network page for VLAN-11 &amp;amp; 12. &lt;BR /&gt; &lt;BR /&gt;VLAN 11; Static IP Address - 10.73.186.10 /24&lt;BR /&gt;and vlan 12; static ip address - 10.73.187.10/24&lt;BR /&gt;&lt;BR /&gt;DHCP for management VALN in under Network 10.73.188.0 /24, address alocation page&lt;BR /&gt;VLAN11 &amp;amp; VALN 12 DHCP configured in bottom of the VSC page, in laptop I am able to get vlan11 IP DHCP scope &amp;amp; VLAN12 DHCP scope &lt;BR /&gt;from SSID VALN11 &amp;amp; VLAN 12.&lt;BR /&gt;&lt;BR /&gt;In Default group VSC biniding I have enable particular VALN 11 &amp;amp; 12. &lt;BR /&gt;&lt;BR /&gt;All the access point and and WLC are connected in 2910 48 ports switch, default gateway in the 2910 switch as follows  VLAN 80 - 10.73.188.1, VALN 11 - 10.73.186.1&lt;BR /&gt;VALN 12 - 10.73.187.1&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Note - I am not using Internet port, it is down now.&lt;BR /&gt;</description>
      <pubDate>Fri, 09 Apr 2010 06:00:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612663#M2976</guid>
      <dc:creator>ProCurve-Super</dc:creator>
      <dc:date>2010-04-09T06:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: MSN 760 and AP point 422</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612664#M2977</link>
      <description>OK. Now it becomes clearer. So if you want to use a single port with all you want to do, I would reverse the controller ports. Meaning only using the Internet port of the product and not the LAN port.&lt;BR /&gt;&lt;BR /&gt;The idea here is that you would first delete the VLANs from your LAN port. Then create 3 VLANs on the Internet port, 80 (on subnet 188.x) for management, 11 (subnet 186.x) and 12 (subnet 187.x). For VLAN 11 and 12 make sure you have no nating when you create it.&lt;BR /&gt;&lt;BR /&gt;Then what you have to do is make sure that the APs can be discovered on the Internet port (in the discovery page there is a checkbox for that)&lt;BR /&gt;&lt;BR /&gt;You also have to configure both your VSCs to always force the data traffic through the data tunnel.&lt;BR /&gt;&lt;BR /&gt;And finally you assign VLAN 11 and VLAN 12 (that you have previously created) as egress of your respective VSCs in the authenticated drop down.&lt;BR /&gt;&lt;BR /&gt;That's pretty much the only way I see this working. The guest traffic will be tunneled and isolated through the network, they will get their IP within the scopes that you have defined in the VSC and once authenticated they would go on their respective VLANs. Using the LAN port to come in and come out is not a good option when using a single port scenario like you are using. The product does many things on the LAN port that I won't detail here, but because of the access control functionality, a lot of things are going on with the port.</description>
      <pubDate>Fri, 09 Apr 2010 13:10:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612664#M2977</guid>
      <dc:creator>Fred!</dc:creator>
      <dc:date>2010-04-09T13:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: MSN 760 and AP point 422</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612665#M2978</link>
      <description>aha Fred, but now the LAN port will not be used on anything right ?&lt;BR /&gt;&lt;BR /&gt;so when he switches everything to the internet port the traffic will be the same as using the LAN port the management traffic and the vlans traffic will be handled by the internet port, ?&lt;BR /&gt;&lt;BR /&gt;And now he needs to untagged the internet port in the management vlan and tag it on the other vlans, and remove the tagging and untagging from the LAN port right ?</description>
      <pubDate>Fri, 09 Apr 2010 13:15:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612665#M2978</guid>
      <dc:creator>Shadow13</dc:creator>
      <dc:date>2010-04-09T13:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: MSN 760 and AP point 422</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612666#M2979</link>
      <description>One more thing, can he use the lan port for ingress on the management vlan (untagged), then create the other 2 vlans on the internet port and use it for egress (tagged for the other 2 vlans only), will it be better ?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 09 Apr 2010 13:22:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612666#M2979</guid>
      <dc:creator>Shadow13</dc:creator>
      <dc:date>2010-04-09T13:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: MSN 760 and AP point 422</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612667#M2980</link>
      <description>Oh and ProCurve-Super I forgot to mention that you need to go inside the DHCP server configuration page and make sure that you check the box so that the IPs can be delivered within the tunnel.&lt;BR /&gt;&lt;BR /&gt;Shadow13: Yes, he pretty much needs to replicate what he had already configured in terms of connectivity to the Internet port instead.&lt;BR /&gt;&lt;BR /&gt;The LAN port will not be connected. But because of the product behavior with regard to access control, there are services such as DHCP and access control that is sitting on that side. Again as I said the product is basically a router and it routes from one interface (the LAN) to another (the Internet). With the help of the tunnel we can 'fake' this behavior because the tunnel is coming straight inside the services (DHCP/access control) and from there it will be routed based on the egress VLAN of the VSCs.</description>
      <pubDate>Fri, 09 Apr 2010 13:23:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612667#M2980</guid>
      <dc:creator>Fred!</dc:creator>
      <dc:date>2010-04-09T13:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: MSN 760 and AP point 422</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612668#M2981</link>
      <description>Shadow13: Our last replies crossed. My previous reply was responding to you first comment. To answer your question, in his case he would have just one port connected (which will be the Internet port), he won't use the LAN for anything, no management. The management would come from the internet side. If he wants to use both port, he would have to connect both ports and we can revisit the way the scenario works in that case. But my understanding is that he wants a single port to be connected.</description>
      <pubDate>Fri, 09 Apr 2010 13:26:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612668#M2981</guid>
      <dc:creator>Fred!</dc:creator>
      <dc:date>2010-04-09T13:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: MSN 760 and AP point 422</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612669#M2982</link>
      <description>Lol&lt;BR /&gt;Fred: so if he needs to use 2 port what i mentioned will work normally is that right ? the traffic will ingress the LAN port through the management vlan and match the VSC, clients will get ip addresses form the right scopes and then egress the traffic through the internet port for the mapping on the VSCs to each vlan, right ?&lt;BR /&gt;&lt;BR /&gt;BTW is this you real name coz i have a doubt :D</description>
      <pubDate>Fri, 09 Apr 2010 13:29:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612669#M2982</guid>
      <dc:creator>Shadow13</dc:creator>
      <dc:date>2010-04-09T13:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: MSN 760 and AP point 422</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612670#M2983</link>
      <description>OK. I get it now :) Hum, I would say yes, it should work, but personally I do prefer to segment the traffic for clarity. So either in the 2 port case I would assign different VLANs on the LAN port or I would enable the tunnel.. otherwise you kind of mix up management with your client data traffic. But that's a personnal choice.&lt;BR /&gt;&lt;BR /&gt;And yes, it is my real name, unlike some I don't use complicated names that hide my identity ;-)</description>
      <pubDate>Fri, 09 Apr 2010 16:05:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/msn-760-and-ap-point-422/m-p/4612670#M2983</guid>
      <dc:creator>Fred!</dc:creator>
      <dc:date>2010-04-09T16:05:43Z</dc:date>
    </item>
  </channel>
</rss>

