Jump to content

Recommended Posts

Posted (edited)

I haven't tried to do this for a long, long time... but I seem to remember being able to put the IP address of the WLC into a browser and pull up the Config web page for it.

 

Just tried to do it and check an SSID had the correct Wi-Fi password set... and it is refusing to connect. Thought it might be a Chrome thing as Edge does the same... Trying HTTP and HTTPS gives slightly different warnings...

 

Initially just refusing:

 

This site can’t be reached XX.X.XXX.XXX refused to connect.

Try:

 

Checking the connection

Checking the proxy and the firewall

ERR_CONNECTION_REFUSED

 

Then various warnings about:

 

This site can’t provide a secure connection XX.X.XXX.XXX uses an unsupported protocol.

ERR_SSL_VERSION_OR_CIPHER_MISMATCH

Unsupported protocol

The client and server don't support a common SSL protocol version or cipher suite.

 

I can Telnet in through Putty, but I don't know enough Cisco Cli to do anything useful!

 

EDIT: Got there in the end, good old IE just lets me click through all the warnings, but I can normally do this with Chrome as well... this time it is just refusing point blank!

 

I wonder with the demise of IE and the fact that Chrome/Edge are dropping certain ciphers means the CISCO switches of a certain age are going to be more difficult to manage?

 

EDIT 2: Just went and stood next to the visitor who was trying to get on to the 'guest' Wi-Fi and watched them type it in... it worked first time... Nothing wrong with the password...? What a surprise! Guess I just need to be standing near things to get them to work... It's a tough job, but someone has to do it... :cool:

Edited by Koldov
Posted

Can you upgrade the WLC controller firmware? Or is it stuck at v7?

 

Basically it's so old browsers have disabled the insecure versions of TLS it uses.

 

Also note there's an option to block connections from WiFi clients.

  • Thanks 1
Posted
Can you upgrade the WLC controller firmware? Or is it stuck at v7?

 

The firmware is currently: Software Version 7.4.150.0 (would new firmware require a licensed vendor/support account to download?).

 

Basically it's so old browsers have disabled the insecure versions of TLS it uses.

 

Yes, I thought that might be the case - won't be getting rid of IE11 on my PC yet, just in case anything else like this pops up!

 

Also note there's an option to block connections from WiFi clients.

 

Management Via Wireless

 

Enable Controller Management to be accessible from Wireless Clients

 

Is ticked, but I'm on a wired PC anyway.

Posted

Require is a strong word.

 

Handily they put an md5 hash on the public page

 

Check how the upgrade from 7 to 8 works in detail though, they changed a lot

  • Thanks 1
  • 4 weeks later...
Posted

Historically you could request a newer firmware (even if you were out of support) from Cisco TAC if you could identify a security vulnerability* in the version you're currently running and a newer version** that fixes the issue.

 

I haven't had to do that in years though, so policy may have changed.

 

*as in, provide the link to the Cisco bulletin.

** link to the newer version.

  • Thanks 1
Posted
Historically you could request a newer firmware (even if you were out of support) from Cisco TAC if you could identify a security vulnerability* in the version you're currently running and a newer version** that fixes the issue.

 

I haven't had to do that in years though, so policy may have changed.

 

*as in, provide the link to the Cisco bulletin.

** link to the newer version.

 

Yes I did this about a year ago for some ASA 5505 firewalls I had. It did not take me up to the latest version of the software though :(

Posted
Yes I did this about a year ago for some ASA 5505 firewalls I had. It did not take me up to the latest version of the software though :(

 

There is an element of "rinse, lather, repeat" to the method. Depends who you get on TAC and whether their interest is to avoid future tickets or stick strictly to the policy.

  • Thanks 1
Posted

Appreciate the sentiment, but apart from feeling like I'd need a wooden leg, eye patch and a hook (Arrrrrrrrrrrrr)....

 

Think I'm going to pass.... not only am I not comfortable with the possibility of breaking the whole network, I'm not at the stage of desperation where I could justify downloading (and install on my network) anything from a site that looks like this!

 

5508.jpg

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...