<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Corporate Wireless using HREAP and Centralised Controllers in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/corporate-wireless-using-hreap-and-centralised-controllers/m-p/1940671#M149071</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Although I haven't done this personally, my best reccomendation would be to specify a quarantine vlan on the interface on the controller and maybe have it be the same at all sites and see if that will flow thru in H-REAP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Mar 2012 14:26:21 GMT</pubDate>
    <dc:creator>Kayle Miller</dc:creator>
    <dc:date>2012-03-22T14:26:21Z</dc:date>
    <item>
      <title>Corporate Wireless using HREAP and Centralised Controllers</title>
      <link>https://community.cisco.com/t5/wireless/corporate-wireless-using-hreap-and-centralised-controllers/m-p/1940670#M149070</link>
      <description>&lt;P&gt;I have a bit of a conundrum at the moment.&amp;nbsp; I will be the first to admit I am no expert when it comes to the finer points of HREAP, but thought I would throw this out there in case someone else has already come across this approach and maybe even has a few tips?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Background:-&amp;nbsp; We run centralised wireless controllers across two datacentres.&amp;nbsp; We have a WCS with MSE and a bunch of AIR-CAP3502I-N-K9 AP's within our Campus, spread across multiple floors and buildings.&amp;nbsp; We already have a working Guest access solution using NGS with HREAP to our Campus and our remoite sites, leveraging an anchor controller in a DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently looking at corporate wireless access in the following way:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AP's in HREAP local switching mode, native vlan is defined for it's particular location/floor (possibly running groups of AP's in specific HREAP groups) - RADIUS 802.1x through to a Symantec SNAC LAN Enforcer; for posture assessment which will then proxy requests on to IAS and active-directory, should remediation be required the SNAC places the client in a remediation VLAN which is terminated in the datacentre and houses a remediation server to carry out any remedation tasks.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see how a permitted machine may work in this topology, but - if remediation is required and the SNAC puts the client into a remediation vlan, I cannot see how this will work in a centralised model, whilst at the same time using HREAP local switching? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The majority of enterprises I am aware of tend to use localised controllers to each site, negating the requirement to use HREAP, but for the purposes of our design, I have to work with our centralised model.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone got corporate wireless working using HREAP into centralised controllers out there?&amp;nbsp; If so, how did you get around the conundrum of remediating clients whose machines needed to be updated?&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Permitted machines will be controlled using certificates from our active-directory/PKI infrastructure both for the machine and the user, to ensure only allowed people and machines can connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should we be using HREAP local switching at all?&amp;nbsp; Or should we follow the guest approach and tunnel all corporate clients back to the datacentre too?&amp;nbsp; Looking for some pointers or ideas here.&amp;nbsp; Many thanks in advance.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 04:42:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/corporate-wireless-using-hreap-and-centralised-controllers/m-p/1940670#M149070</guid>
      <dc:creator>ddavies016</dc:creator>
      <dc:date>2021-07-04T04:42:08Z</dc:date>
    </item>
    <item>
      <title>Corporate Wireless using HREAP and Centralised Controllers</title>
      <link>https://community.cisco.com/t5/wireless/corporate-wireless-using-hreap-and-centralised-controllers/m-p/1940671#M149071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Although I haven't done this personally, my best reccomendation would be to specify a quarantine vlan on the interface on the controller and maybe have it be the same at all sites and see if that will flow thru in H-REAP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2012 14:26:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/corporate-wireless-using-hreap-and-centralised-controllers/m-p/1940671#M149071</guid>
      <dc:creator>Kayle Miller</dc:creator>
      <dc:date>2012-03-22T14:26:21Z</dc:date>
    </item>
  </channel>
</rss>

