<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I agree with Steve ..  FLEX in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wireless-for-mobile-devices-utilizing-local-internet/m-p/2627982#M110568</link>
    <description>&lt;P&gt;I agree with Steve ..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FLEX CONNECT&lt;/P&gt;&lt;P&gt;-use flex connect groups for keying&amp;nbsp;&lt;/P&gt;&lt;P&gt;- if you use 802.1X you will need consider how the users will auth. That traffic will likely have to come across the wan&amp;nbsp;&lt;/P&gt;&lt;P&gt;- you can drive the guest traggic back over the wan to a DMZ if you wanted.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 07 Feb 2015 17:42:17 GMT</pubDate>
    <dc:creator>George Stefanick</dc:creator>
    <dc:date>2015-02-07T17:42:17Z</dc:date>
    <item>
      <title>Wireless for Mobile Devices utilizing local Internet</title>
      <link>https://community.cisco.com/t5/wireless/wireless-for-mobile-devices-utilizing-local-internet/m-p/2627980#M110566</link>
      <description>&lt;P&gt;We have a couple 5508 controllers (one in US and one in EMEA) and AIR-CAP2602I-E-K9 AP's. &amp;nbsp;Our 50 branch offices (US, EMEA, and APAC) have 3750's but we are in the process of replacing these with 3850's. &amp;nbsp;We want to provide a wireless network strictly for mobile devices (iphones/ipads) for employees when they are in the office. &amp;nbsp;All of the 50 branch offices will have local internet so we want Internet traffic to traverse through the local ISP and not across the WAN. &amp;nbsp;Additionally we need this to be a secure environment so only employees can use this wireless network. &amp;nbsp;We do have a separate "Guest" network that is used by clients/guests. &amp;nbsp;What is the best option to deploy this? &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 09:27:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-for-mobile-devices-utilizing-local-internet/m-p/2627980#M110566</guid>
      <dc:creator>CHRIS KALETH</dc:creator>
      <dc:date>2021-07-05T09:27:56Z</dc:date>
    </item>
    <item>
      <title>You would need to deploy in</title>
      <link>https://community.cisco.com/t5/wireless/wireless-for-mobile-devices-utilizing-local-internet/m-p/2627981#M110567</link>
      <description>&lt;P&gt;You would need to deploy in FlexConnect mode so that the traffic stays local and follows the local routing policy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Sat, 07 Feb 2015 16:02:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-for-mobile-devices-utilizing-local-internet/m-p/2627981#M110567</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2015-02-07T16:02:10Z</dc:date>
    </item>
    <item>
      <title>I agree with Steve ..  FLEX</title>
      <link>https://community.cisco.com/t5/wireless/wireless-for-mobile-devices-utilizing-local-internet/m-p/2627982#M110568</link>
      <description>&lt;P&gt;I agree with Steve ..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FLEX CONNECT&lt;/P&gt;&lt;P&gt;-use flex connect groups for keying&amp;nbsp;&lt;/P&gt;&lt;P&gt;- if you use 802.1X you will need consider how the users will auth. That traffic will likely have to come across the wan&amp;nbsp;&lt;/P&gt;&lt;P&gt;- you can drive the guest traggic back over the wan to a DMZ if you wanted.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Feb 2015 17:42:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-for-mobile-devices-utilizing-local-internet/m-p/2627982#M110568</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2015-02-07T17:42:17Z</dc:date>
    </item>
    <item>
      <title>Thanks. Can we enforce our</title>
      <link>https://community.cisco.com/t5/wireless/wireless-for-mobile-devices-utilizing-local-internet/m-p/2627983#M110569</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we enforce our employees to authenticate against AD from their mobile device or push out a cert (we use MobileIron for our MDM)? &amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we prevent our employee laptops from connecting to the "Mobile" SSID?&lt;/P&gt;&lt;P&gt;Should we consider the 3850's as the local controller?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Feb 2015 18:04:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-for-mobile-devices-utilizing-local-internet/m-p/2627983#M110569</guid>
      <dc:creator>CHRIS KALETH</dc:creator>
      <dc:date>2015-02-07T18:04:30Z</dc:date>
    </item>
    <item>
      <title>Sounds like you are using 802</title>
      <link>https://community.cisco.com/t5/wireless/wireless-for-mobile-devices-utilizing-local-internet/m-p/2627984#M110570</link>
      <description>&lt;P&gt;Sounds like you are using 802.1X. Keep in mind while in flex mode the mobile traffic is dumped locally. However authentication would need to come back to the WLC then be processed by the radius and checked against AD.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes you can use a cert for authentication another name for this is EAP TLS. If you have a mdm in place it would be no different if the user was in the corp office.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Preventing a corp device from accessing a guest SSID can be tricky. Some folks will deploy a supplicant &amp;nbsp;like anyconnect on laptops that &amp;nbsp;prevents the&amp;nbsp;device to connect to the mobile ssid. You may want to check your mdm. It may be able to prevent this as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3850 as a local control. I wouldn't unless you have the time to work through the bugs and lack of features .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Feb 2015 18:18:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-for-mobile-devices-utilizing-local-internet/m-p/2627984#M110570</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2015-02-07T18:18:30Z</dc:date>
    </item>
    <item>
      <title>You would define policies if</title>
      <link>https://community.cisco.com/t5/wireless/wireless-for-mobile-devices-utilizing-local-internet/m-p/2627985#M110571</link>
      <description>&lt;P&gt;You would define policies if using 802.1x authentication. You can then distinguish between mobile device if using certs and domain machines. You can push out a GPO to your domain machines preventing them from joining the mobile SSID or any other SSID you have that you want to prevent.&amp;nbsp;&lt;/P&gt;&lt;P&gt;FlexConnect would still be a better choice unless you want to manage each site using a 3850 as an MC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Scott&lt;/P&gt;</description>
      <pubDate>Sat, 07 Feb 2015 18:21:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wireless-for-mobile-devices-utilizing-local-internet/m-p/2627985#M110571</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2015-02-07T18:21:28Z</dc:date>
    </item>
  </channel>
</rss>

