<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Overlapping subnets in different wireless VLANs in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4497125#M235194</link>
    <description>&lt;P&gt;Not sure what you mean by "low". The impression I have is that when dealing with all the stuff to prevent intrusive action by unauthorized clients or duplicated address the controller flattens the VLANs but I don't know why. It would be that simple. Just imagine the same (DHCP snooping etc etc) in a switch, would you consider it normal? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Nov 2021 12:42:26 GMT</pubDate>
    <dc:creator>Alex Mac</dc:creator>
    <dc:date>2021-11-03T12:42:26Z</dc:date>
    <item>
      <title>Overlapping subnets in different wireless VLANs (same SSID)</title>
      <link>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4494072#M234988</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's the first time that I'm facing this challenge but I may run into a scenario where different dynamically assigned VLANs might host the same subnet, like 10.10.34.0/24. The VLANs are extended to different VRFs so there won't be any conflict in terms of routing.&lt;/P&gt;&lt;P&gt;As far as I know I always thought of wireless VLANs as simple L2 domains but I'm told that for mobility WLCs take into account L3 information and two VLANs managed by the same WLCs and with the same L3 IP addressing used within may run into problems. Like all he VLANs were flattened at WLC level and two client with the same IP address but in different VLANs could be seen as one by the WLC.&lt;BR /&gt;&lt;BR /&gt;Does anyone have experience on this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could anyone help in shedding some light on this please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 21:28:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4494072#M234988</guid>
      <dc:creator>Alex Mac</dc:creator>
      <dc:date>2021-11-11T21:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping subnets in different wireless VLANs</title>
      <link>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4494079#M234989</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Note sure if this can work referencing :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-vlan/68100-wlan-controllers-vlans.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-vlan/68100-wlan-controllers-vlans.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;gt;...&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;STRONG&gt;Dynamic Interfaces on WLCs&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;gt;...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;gt;...&amp;nbsp;&lt;SPAN&gt;If the port is untagged, all dynamic interfaces must be on a&lt;STRONG&gt; different IP subnet&lt;/STRONG&gt; from any other interface configured on the port.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Oct 2021 09:25:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4494079#M234989</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2021-10-28T09:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping subnets in different wireless VLANs</title>
      <link>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4494090#M234991</link>
      <description>&lt;P&gt;Hi Alex,&lt;/P&gt;&lt;P&gt;I assume that you are running 9800 platform and Flex AP's. If the same IP is seen twice by WLC it will report as IP Theft and client will excluded as per the configured timeout. Please refer to the below enhancement request.&lt;/P&gt;&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvr98802?rfs=iqvred" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvr98802?rfs=iqvred&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you can find in the above link, this enhancement is added starting from 17.3.3 and higher. Make sure you have the correct IOS-XE code running in your WLC. Config guide as below&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-4/config-guide/b_wl_17_4_cg/m_vewlc_flex_connect.html#concept_hvw_sjw_clb" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-4/config-guide/b_wl_17_4_cg/m_vewlc_flex_connect.html#concept_hvw_sjw_clb&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Oct 2021 09:41:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4494090#M234991</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2021-10-28T09:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping subnets in different wireless VLANs</title>
      <link>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4496599#M235136</link>
      <description>&lt;P&gt;But that's only for flex local switching.&amp;nbsp; I think it will still be a problem for anything centrally switched?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 15:04:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4496599#M235136</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2021-11-02T15:04:55Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping subnets in different wireless VLANs</title>
      <link>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4496826#M235160</link>
      <description>&lt;P&gt;I think the scenario which you are referring will be very low. I have very rarely come across networks where they use overlapping IP addresses even if it's in different VRF's. I think if AP's are in local mode we need to look at the design as a whole. Only solution I see is converting the AP's to Flex.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 21:30:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4496826#M235160</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2021-11-02T21:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping subnets in different wireless VLANs</title>
      <link>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4497125#M235194</link>
      <description>&lt;P&gt;Not sure what you mean by "low". The impression I have is that when dealing with all the stuff to prevent intrusive action by unauthorized clients or duplicated address the controller flattens the VLANs but I don't know why. It would be that simple. Just imagine the same (DHCP snooping etc etc) in a switch, would you consider it normal? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 12:42:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4497125#M235194</guid>
      <dc:creator>Alex Mac</dc:creator>
      <dc:date>2021-11-03T12:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping subnets in different wireless VLANs</title>
      <link>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4497781#M235244</link>
      <description>&lt;P&gt;Hi Alex,&lt;/P&gt;&lt;P&gt;You can't even configure dynamic interfaces with overlapping IP subnets in AireOS (Dynamic interface is compulsory in AireOS world), but in 9800 platforms you really don't need L3 SVI's unless there is mdns gateway or dhcp relay. So technically you can get away wth configuring the L2 VLAN which offers same subnet under 2 SSID's in 9800. The real problem happens when there are 2 clients with the same IP address. WLC will mark the client to be excluded for IP Theft.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If AP's are in local mode there is a workaround (only in 9800 no L3 SVI's), but not recommended. You can divide the DHCP IP scopes&lt;/P&gt;&lt;P&gt;VLAN 10 - VRF DATA - 10.0.0.0/24 - SSID EMPLOYEE - DHCP SCOPE 10.0.0.1-10.0.0.128&lt;/P&gt;&lt;P&gt;VLAN 20 - VRF PERSONAL - 10.0.0.0/24 - SSID EMPLOYEE2 - DHCP SCOPE 10.0.0.129-10.0.0.254&lt;/P&gt;&lt;P&gt;By manipulating the DHCP scopes you are avoiding duplicate IP issue. But you have to compensate on the available IP addresses.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 10:45:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4497781#M235244</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2021-11-04T10:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping subnets in different wireless VLANs (same SSID)</title>
      <link>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4501733#M235483</link>
      <description>&lt;P&gt;Hi Arshad,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;unfortunately we are speaking of the same SSID and VLANs assigned dynamically by the RADIUS, that would be the scenario.&lt;BR /&gt;&lt;BR /&gt;Alex&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 21:31:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4501733#M235483</guid>
      <dc:creator>Alex Mac</dc:creator>
      <dc:date>2021-11-11T21:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping subnets in different wireless VLANs (same SSID)</title>
      <link>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4501748#M235485</link>
      <description>&lt;P&gt;Still the same theory applies, you cannot have 2 clients with same IP. You can try to manipulate your DHCP scope to stop assignment of same IP to 2 clients.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 22:07:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/overlapping-subnets-in-different-wireless-vlans-same-ssid/m-p/4501748#M235485</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2021-11-11T22:07:00Z</dc:date>
    </item>
  </channel>
</rss>

