Koldov Posted June 23, 2022 Posted June 23, 2022 (edited) I haven't tried to do this for a long, long time... but I seem to remember being able to put the IP address of the WLC into a browser and pull up the Config web page for it. Just tried to do it and check an SSID had the correct Wi-Fi password set... and it is refusing to connect. Thought it might be a Chrome thing as Edge does the same... Trying HTTP and HTTPS gives slightly different warnings... Initially just refusing: This site can’t be reached XX.X.XXX.XXX refused to connect. Try: Checking the connection Checking the proxy and the firewall ERR_CONNECTION_REFUSED Then various warnings about: This site can’t provide a secure connection XX.X.XXX.XXX uses an unsupported protocol. ERR_SSL_VERSION_OR_CIPHER_MISMATCH Unsupported protocol The client and server don't support a common SSL protocol version or cipher suite. I can Telnet in through Putty, but I don't know enough Cisco Cli to do anything useful! EDIT: Got there in the end, good old IE just lets me click through all the warnings, but I can normally do this with Chrome as well... this time it is just refusing point blank! I wonder with the demise of IE and the fact that Chrome/Edge are dropping certain ciphers means the CISCO switches of a certain age are going to be more difficult to manage? EDIT 2: Just went and stood next to the visitor who was trying to get on to the 'guest' Wi-Fi and watched them type it in... it worked first time... Nothing wrong with the password...? What a surprise! Guess I just need to be standing near things to get them to work... It's a tough job, but someone has to do it... Edited June 23, 2022 by Koldov
mavhc Posted June 23, 2022 Posted June 23, 2022 Can you upgrade the WLC controller firmware? Or is it stuck at v7? Basically it's so old browsers have disabled the insecure versions of TLS it uses. Also note there's an option to block connections from WiFi clients. 1
Koldov Posted June 23, 2022 Author Posted June 23, 2022 Can you upgrade the WLC controller firmware? Or is it stuck at v7? The firmware is currently: Software Version 7.4.150.0 (would new firmware require a licensed vendor/support account to download?). Basically it's so old browsers have disabled the insecure versions of TLS it uses. Yes, I thought that might be the case - won't be getting rid of IE11 on my PC yet, just in case anything else like this pops up! Also note there's an option to block connections from WiFi clients. Management Via Wireless Enable Controller Management to be accessible from Wireless Clients Is ticked, but I'm on a wired PC anyway.
mavhc Posted June 23, 2022 Posted June 23, 2022 Require is a strong word. Handily they put an md5 hash on the public page Check how the upgrade from 7 to 8 works in detail though, they changed a lot 1
nyamani Posted July 19, 2022 Posted July 19, 2022 @Koldov I have same issue of yours, did your issue solved using instruction of @mavhc. if solved just let me know to ask the one managing our WLC to apply it. Thanks.
Koldov Posted July 19, 2022 Author Posted July 19, 2022 I have not upgraded the firmware on the switches, I am keeping IE11 on my work laptop to connect.
pete Posted July 19, 2022 Posted July 19, 2022 Historically you could request a newer firmware (even if you were out of support) from Cisco TAC if you could identify a security vulnerability* in the version you're currently running and a newer version** that fixes the issue. I haven't had to do that in years though, so policy may have changed. *as in, provide the link to the Cisco bulletin. ** link to the newer version. 1
Davit2005 Posted July 19, 2022 Posted July 19, 2022 Historically you could request a newer firmware (even if you were out of support) from Cisco TAC if you could identify a security vulnerability* in the version you're currently running and a newer version** that fixes the issue. I haven't had to do that in years though, so policy may have changed. *as in, provide the link to the Cisco bulletin. ** link to the newer version. Yes I did this about a year ago for some ASA 5505 firewalls I had. It did not take me up to the latest version of the software though
pete Posted July 19, 2022 Posted July 19, 2022 Yes I did this about a year ago for some ASA 5505 firewalls I had. It did not take me up to the latest version of the software though There is an element of "rinse, lather, repeat" to the method. Depends who you get on TAC and whether their interest is to avoid future tickets or stick strictly to the policy. 1
Koldov Posted July 20, 2022 Author Posted July 20, 2022 Appreciate the sentiment, but apart from feeling like I'd need a wooden leg, eye patch and a hook (Arrrrrrrrrrrrr).... Think I'm going to pass.... not only am I not comfortable with the possibility of breaking the whole network, I'm not at the stage of desperation where I could justify downloading (and install on my network) anything from a site that looks like this!
mavhc Posted July 20, 2022 Posted July 20, 2022 That's why you check the md5 hash, then you know it's not been altered 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now