<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 5508 controller Office extended setup in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/5508-controller-office-extended-setup/m-p/4189760#M223623</link>
    <description>Nat is only available on the management interface configuration.  As long as there are no internal AP’s connected you do not have to issue this command. &lt;BR /&gt;&lt;BR /&gt;config network ap-discovery nat-ip-only disable&lt;BR /&gt;&lt;BR /&gt;As far as SSO, you are changing the management IP address to a public ip so that you need to consider. I would think you would need to break HA. &lt;BR /&gt;Why not break sso and use the other controller for OEAP. There is no real benefit for SSO for guest anchor. &lt;BR /&gt;</description>
    <pubDate>Fri, 27 Nov 2020 15:26:28 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2020-11-27T15:26:28Z</dc:date>
    <item>
      <title>5508 controller Office extended setup</title>
      <link>https://community.cisco.com/t5/wireless/5508-controller-office-extended-setup/m-p/4189625#M223604</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;we are doing office extended setup on cisco 5508 controller with 8.5.135 airos and 2702i access point&lt;/P&gt;&lt;P&gt;controller is behind firewall&lt;/P&gt;&lt;P&gt;our 5508 controller is not dedicated for the OEAP setup our controller working as gust anchor controller also it is in HA,&lt;/P&gt;&lt;P&gt;destination Nat is present on the firewall,&lt;/P&gt;&lt;P&gt;On firewall we have the port 5246 and 5247 open for real ip to join the controller,&lt;/P&gt;&lt;P&gt;currently NAT ip is not&amp;nbsp; configured in mgmt. interface of 5508 controller, option is grid out in mgmt. interface of 5508 controller as it is in HA&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Query&lt;/P&gt;&lt;P&gt;1. Is it mandatory to have the NAT on the 5508 management interface only ? or we can do NAT on other part of network(on firewall facing towards DMZ-internet).&lt;/P&gt;&lt;P&gt;Because we did the&amp;nbsp; destination NAT on the firewall side for the management ip of our controller&lt;/P&gt;&lt;P&gt;Request of the 2702i coming to the controller using real ip , discovery response also going from wlc to destination real ip, next exchange is lost somewhere&lt;/P&gt;&lt;P&gt;2. our wlc has 8.5.135 license we don't require special DTLS license as it already has DATA+Wplus in existing airos right?&lt;/P&gt;&lt;P&gt;3. if we configure the NAT directly on the MGMT interface we need to break HA, enable NAT, again build HA, and we have the guest mobility tunnel to private ip to all other sites , does it will be problem for this tunnels.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;Shrikant&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 19:50:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/5508-controller-office-extended-setup/m-p/4189625#M223604</guid>
      <dc:creator>ShrikantGAIKWAD69594</dc:creator>
      <dc:date>2021-07-05T19:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: 5508 controller Office extended setup</title>
      <link>https://community.cisco.com/t5/wireless/5508-controller-office-extended-setup/m-p/4189760#M223623</link>
      <description>Nat is only available on the management interface configuration.  As long as there are no internal AP’s connected you do not have to issue this command. &lt;BR /&gt;&lt;BR /&gt;config network ap-discovery nat-ip-only disable&lt;BR /&gt;&lt;BR /&gt;As far as SSO, you are changing the management IP address to a public ip so that you need to consider. I would think you would need to break HA. &lt;BR /&gt;Why not break sso and use the other controller for OEAP. There is no real benefit for SSO for guest anchor. &lt;BR /&gt;</description>
      <pubDate>Fri, 27 Nov 2020 15:26:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/5508-controller-office-extended-setup/m-p/4189760#M223623</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2020-11-27T15:26:28Z</dc:date>
    </item>
  </channel>
</rss>

