<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: wlc placement in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4705941#M247271</link>
    <description>&lt;P&gt;As Marce explained answer is "it depends". I would start my day with reading the CVD's&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/solutions/design-zone/networking-design-guides/campus-wired-wireless.html" target="_blank"&gt;https://www.cisco.com/c/en/us/solutions/design-zone/networking-design-guides/campus-wired-wireless.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If that gives me a high-level idea, then I will start reading the WLC configuration guides and design guides. For me there are multiple reasons which can impact the WLC placement in the network.&lt;/P&gt;
&lt;P&gt;1. If I have AP's reaching out from the public networks (OEAP)&lt;/P&gt;
&lt;P&gt;2. If I have APs distributed across multiple WAN sites connected over MPLS/SD-WAN/VPN etc.&lt;/P&gt;
&lt;P&gt;3. If the role of the WLC is Anchor controller&lt;/P&gt;
&lt;P&gt;then I would definitely consider placing them in a DMZ which has upstream firewall/IPS/IDS/DDOS protection.&lt;/P&gt;
&lt;P&gt;Sometimes AP mode such as Local/Flex also impacts the WLC placement. If my APs are inside LAN segment, then I will definitely place it where it can be centrally accessible (Core Switch possibly) and make sure that is redundantly connected.&lt;/P&gt;
&lt;P&gt;Now since you have routed access network, using Flex connect might become a challenge as you might have to work with multiple flex profiles and additional configuration to support the routed access network. I would suggest you go with local mode for AP's as in this case traffic is tunneled to the WLC along with Management traffic. So, from the configuration side you can reduce the complexity.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Oct 2022 19:47:44 GMT</pubDate>
    <dc:creator>Arshad Safrulla</dc:creator>
    <dc:date>2022-10-19T19:47:44Z</dc:date>
    <item>
      <title>wlc placement</title>
      <link>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4705520#M247254</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have two questions&amp;nbsp; ,&lt;/P&gt;&lt;P&gt;1)usually where should I place the wlc&amp;nbsp; , behind firewall or core&lt;/P&gt;&lt;P&gt;2)I have routed access layer , So&amp;nbsp; the connectivity to wlc will be layer 2 or layer 3&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 08:57:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4705520#M247254</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2022-10-19T08:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: wlc placement</title>
      <link>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4705544#M247256</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- There's no unique answer and &lt;EM&gt;'behind core&lt;/EM&gt;' is somewhat undefined, it depends where the wireless clients are , usually on the Intr&lt;STRONG&gt;a&lt;/STRONG&gt;net which close proximity to core , to start with.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 09:48:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4705544#M247256</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-10-19T09:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: wlc placement</title>
      <link>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4705627#M247259</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Sorry it was not behind , I mean&amp;nbsp; wlc connected to the core .&lt;/P&gt;&lt;P&gt;Now the second question is,&lt;/P&gt;&lt;P&gt;Currently i am following the traditional layer2 architecture between distribution and&amp;nbsp;&amp;nbsp; access &amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the SSID EMPLOYEES -10.0.2.0/24&lt;/P&gt;&lt;P&gt;So I have a vlan 10 for&amp;nbsp; employees in all edge switches and &amp;nbsp; on distrubtion side gateway configured&amp;nbsp;&lt;/P&gt;&lt;P&gt;And in the wlc added vlan 10 and one inteface&amp;nbsp; with the ip 10.0.2.10/24&lt;/P&gt;&lt;P&gt;If I am moving from l2 to l3 , how the configuration would be&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Add vlan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 13:32:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4705627#M247259</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2022-10-19T13:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: wlc placement</title>
      <link>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4705941#M247271</link>
      <description>&lt;P&gt;As Marce explained answer is "it depends". I would start my day with reading the CVD's&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/solutions/design-zone/networking-design-guides/campus-wired-wireless.html" target="_blank"&gt;https://www.cisco.com/c/en/us/solutions/design-zone/networking-design-guides/campus-wired-wireless.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If that gives me a high-level idea, then I will start reading the WLC configuration guides and design guides. For me there are multiple reasons which can impact the WLC placement in the network.&lt;/P&gt;
&lt;P&gt;1. If I have AP's reaching out from the public networks (OEAP)&lt;/P&gt;
&lt;P&gt;2. If I have APs distributed across multiple WAN sites connected over MPLS/SD-WAN/VPN etc.&lt;/P&gt;
&lt;P&gt;3. If the role of the WLC is Anchor controller&lt;/P&gt;
&lt;P&gt;then I would definitely consider placing them in a DMZ which has upstream firewall/IPS/IDS/DDOS protection.&lt;/P&gt;
&lt;P&gt;Sometimes AP mode such as Local/Flex also impacts the WLC placement. If my APs are inside LAN segment, then I will definitely place it where it can be centrally accessible (Core Switch possibly) and make sure that is redundantly connected.&lt;/P&gt;
&lt;P&gt;Now since you have routed access network, using Flex connect might become a challenge as you might have to work with multiple flex profiles and additional configuration to support the routed access network. I would suggest you go with local mode for AP's as in this case traffic is tunneled to the WLC along with Management traffic. So, from the configuration side you can reduce the complexity.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 19:47:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4705941#M247271</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-10-19T19:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: wlc placement</title>
      <link>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4706511#M247308</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hi,&lt;/P&gt;&lt;P&gt;This is your post in the below thread&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/wireless/issues-with-wireless-in-routed-access-layer-design/td-p/4437641" target="_blank"&gt;https://community.cisco.com/t5/wireless/issues-with-wireless-in-routed-access-layer-design/td-p/4437641&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If the AP’s are in local mode AP will build a capwap tunnel to the controller, so any wireless clients connected will egressing directly from the controller as the client data traffic will be encapsulated with capwap between AP and WLC. In the routed access world this is the preferred method for me as this will reduce complexity. Remember you need L3 reachability between AP management VLAN and WLC AP Manager interface.&lt;/P&gt;&lt;P&gt;If i have ssid test 10.0.2.0/24 (vlan 2 )&lt;/P&gt;&lt;P&gt;Are you saying to create vlan 2 on the access switch and on core 2 ,&lt;BR /&gt;and a vlan interface on the controller 10.0.2.10/24&lt;/P&gt;&lt;P&gt;then there will be stp election ?&lt;/P&gt;&lt;P&gt;Please clarify&lt;/P&gt;&lt;P&gt;Then you will create dynamic interface per VLAN in your controller (tag VLAN per said as reqd.) and then corresponding VLAN’s in the upstream switches as well.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 12:18:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4706511#M247308</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2022-10-20T12:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: wlc placement</title>
      <link>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4706531#M247310</link>
      <description>&lt;P&gt;Hi Bluesea,&lt;/P&gt;
&lt;P&gt;WLC will not participate in STP. In case you are going with local mode AP's as you said you will create the SVI for VLAN2 in Core Switch and then allow it on the trunk connecting to the WLC.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"Then you will create dynamic interface per VLAN in your controller (tag VLAN per said as reqd.) and then corresponding VLAN’s in the upstream switches as well."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Above statement is valid only if Flex AP's then you need to worry about VLAN to SSID mapping and Flex profiles etc. this method is not recommended for routed access networks.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 12:39:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4706531#M247310</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-10-20T12:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: wlc placement</title>
      <link>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4706540#M247311</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/465548"&gt;@Arshad Safrulla&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In that case do I need to create the same vlan on the access layer also , or access layer&amp;nbsp; do we need only ap management vlan&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 12:55:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4706540#M247311</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2022-10-20T12:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: wlc placement</title>
      <link>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4706553#M247313</link>
      <description>If you are going with Local mode then only AP management VLAN is needed in needed in all access switches.&lt;BR /&gt;</description>
      <pubDate>Thu, 20 Oct 2022 13:20:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4706553#M247313</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-10-20T13:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: wlc placement</title>
      <link>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4710119#M247522</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/465548"&gt;@Arshad Safrulla&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What if&amp;nbsp; we create the vlan&amp;nbsp; assoicated with the SSID&amp;nbsp; on the access side&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 05:49:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4710119#M247522</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2022-10-26T05:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: wlc placement</title>
      <link>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4710399#M247523</link>
      <description>&lt;P&gt;Then you need to have APs in Flex mode, and you need to create the required Flex profiles. It will be like 1 Flex profile per access switch/stack.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 07:46:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-placement/m-p/4710399#M247523</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-10-26T07:46:34Z</dc:date>
    </item>
  </channel>
</rss>

