<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Local breakout help in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4602477#M241395</link>
    <description>&lt;P&gt;If your SSID is already in flexconnect mode, then the solution is pretty easy. Is basically routing task.&amp;nbsp; Corp traffic you sent do MPLS and internet traffic you send local.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;From a Security perspective, we could add a firewall on the topology&amp;nbsp; but from connectivity perspective, no required.&lt;/P&gt;</description>
    <pubDate>Fri, 29 Apr 2022 14:45:57 GMT</pubDate>
    <dc:creator>Flavio Miranda</dc:creator>
    <dc:date>2022-04-29T14:45:57Z</dc:date>
    <item>
      <title>Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4602476#M241394</link>
      <description>&lt;P&gt;So maybe I am over thinking this or perhaps its not possible. I am trying to have clients maintain internal network connectivity by means of their VLAN and access internet for any http/https traffic. Similar to split tunneling or split traffic like we do with VPN. One would think I can connect an outside internet line to the WLC and perhaps configure an SVI and allow access to VLAN xxx out to the internet?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a network that is fairly simplistic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The wireless clients are on VLANxxx. They get internal DHCP, and authenticate to RADIUS. We are trying to create a local breakout to the internet for their internet traffic so it does not hit our MPLS line and use precious resource. I know the WLC has Layer capabilities so I wonder if I can somehow setup a direct local breakout from this, or should I do inter VLAN routing, or is there an easier path?&amp;nbsp; Internet ISP can be routable if needed, abut I have an internal IP from its own switch at: 10.x.x.x&lt;/P&gt;&lt;P&gt;Here is a simple diagram:&lt;/P&gt;&lt;P&gt;    Outside internet to connect to WLC (10.x.x.x)&lt;/P&gt;&lt;P&gt;           ^&lt;/P&gt;&lt;P&gt;Client&amp;gt; AP (flex) &amp;gt; WLC (Has SSID and VLAN SVI)/Switch &amp;gt; Core&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 19:41:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4602476#M241394</guid>
      <dc:creator>frederick.mercado</dc:creator>
      <dc:date>2023-10-19T19:41:48Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4602477#M241395</link>
      <description>&lt;P&gt;If your SSID is already in flexconnect mode, then the solution is pretty easy. Is basically routing task.&amp;nbsp; Corp traffic you sent do MPLS and internet traffic you send local.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;From a Security perspective, we could add a firewall on the topology&amp;nbsp; but from connectivity perspective, no required.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2022 14:45:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4602477#M241395</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2022-04-29T14:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4602508#M241397</link>
      <description>&lt;P&gt;Our APs are in flexconnect but are local to the facility. The wireless clients are on the VLANxxxx from cores and our APs are on VLANxx for management. The outside internet is also provided here. What would be a configuration to try? There is no route to outside internet.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 19:42:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4602508#M241397</guid>
      <dc:creator>frederick.mercado</dc:creator>
      <dc:date>2023-10-19T19:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4602530#M241398</link>
      <description>&lt;P&gt;&amp;nbsp;The important thing is the WLAN.. Is the option "FlexConnect Local Switching " checked&amp;nbsp; on the WLC? If not, then the traffic is sent to the WLC and then the scenario is different.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2022 15:47:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4602530#M241398</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2022-04-29T15:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4602531#M241399</link>
      <description>&lt;P&gt;Removed&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 19:42:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4602531#M241399</guid>
      <dc:creator>frederick.mercado</dc:creator>
      <dc:date>2023-10-19T19:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4602846#M241429</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/215928-flexconnect-oeap-with-split-tunneling-co.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/215928-flexconnect-oeap-with-split-tunneling-co.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know this feature but I am not sure it can apply in WLC9800&lt;/P&gt;</description>
      <pubDate>Sat, 30 Apr 2022 15:00:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4602846#M241429</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-30T15:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4606153#M241660</link>
      <description>&lt;P&gt;Office-extend is a different feature - designed for homeworkers and probably not appropriate for this scenario.&amp;nbsp; Also that guide is for AireOS.&lt;/P&gt;
&lt;P&gt;Some things still not clear from your descriptions:&lt;/P&gt;
&lt;P&gt;- Is your WLC on the same site as the APs or is the WLC at a different site? (I'm getting the impression the WLC is at a separate central site)&lt;/P&gt;
&lt;P&gt;- You want to break out the internet traffic at the local site?&lt;/P&gt;
&lt;P&gt;- Your "simple diagram" doesn't show what's between the AP and the WLC - so what is there?&amp;nbsp; Or are you saying your AP is physically connected directly to the WLC?&lt;/P&gt;
&lt;P&gt;Might be easier to put your diagram on a drawing showing all the relevant connectivity.&amp;nbsp; It's very difficult to answer your question without knowing all those details.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For general Flexconnect overview:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213945-understand-flexconnect-on-9800-wireless.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213945-understand-flexconnect-on-9800-wireless.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;There is a feature called&amp;nbsp;Split Tunneling for FlexConnect that you might be able to use although it's really intended for accessing specific local services eg. printer.&amp;nbsp; But you might be able to use it to break out everything except the traffic going to specific core services.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-3/config-guide/b_wl_17_3_cg/m_vewlc_flex_connect.html#ID138" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-3/config-guide/b_wl_17_3_cg/m_vewlc_flex_connect.html#ID138&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Actually looking at their example I think they're doing exactly what you want to - sending a specific IP for central switching and everything else local.&lt;/P&gt;</description>
      <pubDate>Sat, 07 May 2022 11:39:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4606153#M241660</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-05-07T11:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4607046#M241698</link>
      <description>&lt;P&gt;We tried setting up a VRF on our 9300 switches with network advantage only to realize they are not VRF NAT aware, the 16.12.4 ios at least does not support the vrf statement for ip nat inside. So back to the WLC:&lt;/P&gt;&lt;P&gt;Our WLC and APs are all local to one site. Wireless management on VLAN xx (along with controller IP) and APs. Clients getting IP off VLAN xx, and mobile clients we have setup for VLAN xxx (10.74.x.x). We are trying to give mobile clients direct internet connectivity without the use of another router or FW. Then ACL it off. We saw that the WLC had&amp;nbsp; routing capabilities with NAT, so we figured we will try.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We simply want to give clients access to the internet without going through our local MPLS.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 19:44:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4607046#M241698</guid>
      <dc:creator>frederick.mercado</dc:creator>
      <dc:date>2023-10-19T19:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4607092#M241703</link>
      <description>&lt;P&gt;9800 is not supposed to be used as a router, with or without VRF.&lt;/P&gt;
&lt;P&gt;Many router commands functions may still be there and some may even work but wireless BU have been removing them from the WLC IOS-XE so even if they work today they might not work in the next release.&amp;nbsp; If you use them then you do so at your own risk.&lt;/P&gt;
&lt;P&gt;Why not do the NAT in global VRF on 9300L? (if it even supports that?) The 9300L range is basic and really only intended as a simple switch so no surprise it doesn't support advanced routing features.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 22:39:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4607092#M241703</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-05-09T22:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4607100#M241704</link>
      <description>&lt;P&gt;Makes sense for the WLC. It just makes things easier. The 9300 does not support Nat over VRF, or intra-VRF NAT...yet that is. The statement is missing from when to designate the "ip nat inside....overload". Every direction we turn is a wall.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 19:44:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4607100#M241704</guid>
      <dc:creator>frederick.mercado</dc:creator>
      <dc:date>2023-10-19T19:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4607516#M241744</link>
      <description>&lt;P&gt;This is basically Layer 3 routing, I recommend you connect your Internet router to L3 switch directly. I would manipulate routing in order to achieve this, if using static routes I would add more specific routes towards MPLS where the subnets are defined and default route towards Internet in your L3 switch.&lt;/P&gt;
&lt;P&gt;For MPLS&lt;/P&gt;
&lt;P&gt;ip route 10.0.0.0 255.0.0.0 &amp;lt;MPLS Router IP&amp;gt;&lt;/P&gt;
&lt;P&gt;ip route X.X.X.X X.X.X.X &amp;lt;MPLS Router IP&amp;gt;&lt;/P&gt;
&lt;P&gt;For Internet&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ip route 0.0.0.0 0.0.0.0 &amp;lt;Internet Router IP&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 14:20:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4607516#M241744</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-05-10T14:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4607617#M241758</link>
      <description>&lt;P&gt;&lt;BR /&gt;But I noticed that when doing a traceroute to 8.8.8.8 the route it takes is through is the VLAN of the client or the L3 GW, and out to the MPLS router&lt;BR /&gt;IS there anyway to curb this?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 19:45:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4607617#M241758</guid>
      <dc:creator>frederick.mercado</dc:creator>
      <dc:date>2023-10-19T19:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4607648#M241759</link>
      <description>You can consider adding a policy route in Core Switch where you define the interesting traffic and and set the next hop to be the Internet router&lt;BR /&gt;</description>
      <pubDate>Tue, 10 May 2022 17:35:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4607648#M241759</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-05-10T17:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4607731#M241767</link>
      <description>Could you provide an example to help given my current configuration?&lt;BR /&gt;</description>
      <pubDate>Tue, 10 May 2022 20:15:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4607731#M241767</guid>
      <dc:creator>frederick.mercado</dc:creator>
      <dc:date>2022-05-10T20:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4607814#M241768</link>
      <description>&lt;P&gt;It's called policy based routing.&amp;nbsp; Standard routing is based on the packet's destination address.&amp;nbsp; Policy based routing allows you to base the routing decision on source and/or destination address and other characteristics independent of the routing table.&amp;nbsp; In this case you would send everything originating from the mobile client subnet source range to the next hop IP of your internet router.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/iproute_pi/configuration/xe-17/iri-xe-17-book/m_iri-pbr.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/iproute_pi/configuration/xe-17/iri-xe-17-book/m_iri-pbr.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 22:28:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4607814#M241768</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-05-10T22:28:17Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4608495#M241829</link>
      <description>&lt;P&gt;Indeed, I attempted this by doing a route-map as well, it seemed the traffic was not phased by this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I have a VLAN xxx (10.74.x.x) on the core with the mobile traffic, and I wanted it to reach the ISP or interface with 207.x.x.x (no switchport or L3 int) with a route map what would be a good example?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 19:46:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4608495#M241829</guid>
      <dc:creator>frederick.mercado</dc:creator>
      <dc:date>2023-10-19T19:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4608579#M241841</link>
      <description>&lt;P&gt;&lt;BR /&gt;ip access-list extended Guest_ACL&lt;BR /&gt;permit ip 10.74.126.0 0.0.0.255 any &lt;BR /&gt;!&lt;BR /&gt;route-map Guest_PBR permit 10&lt;BR /&gt;match ip address Guest_ACL&lt;BR /&gt;set ip next-hop 207.91.252.28&lt;BR /&gt;!&lt;BR /&gt;interface vlan 126&lt;BR /&gt;ip policy route-map Guest_PBR&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need this in both switches. This switches must know how to reach&amp;nbsp;&lt;SPAN&gt;207.91.252.28&amp;nbsp;(route must be present in both the switches, otherwise still be routed over MPLS as I assume there is a default route recieved over MPLS)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 19:45:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4608579#M241841</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-05-11T19:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4609302#M241898</link>
      <description>&lt;P&gt;I have added this exact configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 19:47:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4609302#M241898</guid>
      <dc:creator>frederick.mercado</dc:creator>
      <dc:date>2023-10-19T19:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4609318#M241899</link>
      <description>&lt;P&gt;Removed&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 19:47:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4609318#M241899</guid>
      <dc:creator>frederick.mercado</dc:creator>
      <dc:date>2023-10-19T19:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: Local breakout help</title>
      <link>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4609342#M241900</link>
      <description>207.91.252.28 is configured in GigabitEthernet1/0/44 ( in ur switch), so it will not work as this ip is defined as the next hop. You need to define the next hop (set ip next-hop 207.91.252.25)&lt;BR /&gt;</description>
      <pubDate>Thu, 12 May 2022 20:20:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-breakout-help/m-p/4609342#M241900</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-05-12T20:20:54Z</dc:date>
    </item>
  </channel>
</rss>

