<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CAPWAP Though NAT (AP Side and Controller Side) in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/capwap-though-nat-ap-side-and-controller-side/m-p/3905831#M170640</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I’m working on a design at the moment where the customer runs a Zero Trust model, The customer has multiple sites with no WAN. All traffic is Internet based towards there cloud provider where they run SAML aware proxies to permit access to their applications. They are cloud heavy and have no on-prem services.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Meraki works well for them to provide untrusted WiFi access, however we have a situation where I need to run Aireos /IOSXE on one of the sites due to the high density and feature requirements.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Is it possible for the AP to be behind NAT (option 43 on the router pointing towards a Public IP) and in the cloud environment NAT the Public IP to the MGMT interface of the controller, controller configured for FLEX (9800 Controller).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’ve tested this and can see in the DTLS packet the controller is returning its real address and hence the AP doesn’t register as it doesn’t have routing access to the RFC1918 address the controller is on.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 17:49:53 GMT</pubDate>
    <dc:creator>rgreville666</dc:creator>
    <dc:date>2021-07-05T17:49:53Z</dc:date>
    <item>
      <title>CAPWAP Though NAT (AP Side and Controller Side)</title>
      <link>https://community.cisco.com/t5/wireless/capwap-though-nat-ap-side-and-controller-side/m-p/3905831#M170640</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I’m working on a design at the moment where the customer runs a Zero Trust model, The customer has multiple sites with no WAN. All traffic is Internet based towards there cloud provider where they run SAML aware proxies to permit access to their applications. They are cloud heavy and have no on-prem services.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Meraki works well for them to provide untrusted WiFi access, however we have a situation where I need to run Aireos /IOSXE on one of the sites due to the high density and feature requirements.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Is it possible for the AP to be behind NAT (option 43 on the router pointing towards a Public IP) and in the cloud environment NAT the Public IP to the MGMT interface of the controller, controller configured for FLEX (9800 Controller).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’ve tested this and can see in the DTLS packet the controller is returning its real address and hence the AP doesn’t register as it doesn’t have routing access to the RFC1918 address the controller is on.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 17:49:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/capwap-though-nat-ap-side-and-controller-side/m-p/3905831#M170640</guid>
      <dc:creator>rgreville666</dc:creator>
      <dc:date>2021-07-05T17:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: CAPWAP Though NAT (AP Side and Controller Side)</title>
      <link>https://community.cisco.com/t5/wireless/capwap-though-nat-ap-side-and-controller-side/m-p/3905884#M170641</link>
      <description>Not sure if this is possible. Is the AP for OEAP configured? That is in the AP configuration under FlexConnect and named "Enable OfficeExtend AP" (at least on the 8.5.x code for the 5520). &lt;BR /&gt;Have you configured the public facing IP address on the AP under High Availability (plus the WLC name as configured under Controller -General - Name). &lt;BR /&gt;If that doesn't work, you probably need a VPN between the sites, but I think it should work. &lt;BR /&gt;&lt;BR /&gt;Also check this: &lt;A href="https://community.cisco.com/t5/other-wireless-mobility-subjects/wlc-nat-feature-problem-for-oeap/td-p/2632340" target="_blank"&gt;https://community.cisco.com/t5/other-wireless-mobility-subjects/wlc-nat-feature-problem-for-oeap/td-p/2632340&lt;/A&gt;</description>
      <pubDate>Fri, 09 Aug 2019 09:35:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/capwap-though-nat-ap-side-and-controller-side/m-p/3905884#M170641</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-08-09T09:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: CAPWAP Though NAT (AP Side and Controller Side)</title>
      <link>https://community.cisco.com/t5/wireless/capwap-though-nat-ap-side-and-controller-side/m-p/3905899#M170642</link>
      <description>&lt;P&gt;Hi, Thanks for the reply. This is on a 9800 IOSXE controller.. I think this is what im looking for.. "&lt;SPAN&gt;config network ap-discovery nat-ip-only&lt;/SPAN&gt;&lt;STRONG&gt;"&lt;/STRONG&gt; I can't seem to find that on the new controller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 09:57:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/capwap-though-nat-ap-side-and-controller-side/m-p/3905899#M170642</guid>
      <dc:creator>rgreville666</dc:creator>
      <dc:date>2019-08-09T09:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: CAPWAP Though NAT (AP Side and Controller Side)</title>
      <link>https://community.cisco.com/t5/wireless/capwap-though-nat-ap-side-and-controller-side/m-p/3905908#M170643</link>
      <description>In that case, I suggest to open a TAC, the 9800 platform is still very new and doesn't yet have all features of the AireOS controllers.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 09 Aug 2019 10:38:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/capwap-though-nat-ap-side-and-controller-side/m-p/3905908#M170643</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-08-09T10:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: CAPWAP Though NAT (AP Side and Controller Side)</title>
      <link>https://community.cisco.com/t5/wireless/capwap-though-nat-ap-side-and-controller-side/m-p/3905989#M170644</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/release-notes/rn-16-10-9800.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/release-notes/rn-16-10-9800.html&lt;/A&gt;&lt;/P&gt;&lt;DIV class="container grid"&gt;&lt;DIV class="row blowout wide-narrow-v2 visitedlinks"&gt;&lt;DIV class="col wide-v2"&gt;&lt;DIV&gt;&lt;H2&gt;Guidelines and Restrictions&lt;/H2&gt;&lt;DIV class="body conbody"&gt;&lt;H3&gt;Software&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class="p"&gt;AP connection over network address translation (NAT) and port address translation (PAT) is not supported.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class="p"&gt;Mobility NAT is not supported.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 09 Aug 2019 13:25:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/capwap-though-nat-ap-side-and-controller-side/m-p/3905989#M170644</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2019-08-09T13:25:01Z</dc:date>
    </item>
  </channel>
</rss>

