<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WLC 5520 Flexconnect AP with EoGRE in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-5520-flexconnect-ap-with-eogre/m-p/5128968#M272576</link>
    <description>&lt;P&gt;on a 5520 WLC v8.10.183&lt;/P&gt;
&lt;P&gt;We have been able to get a Flexconnect AP to build a EoGRE tunnel and put clients on it.&lt;BR /&gt;We have also been able to get a Flexconnect AP to drop client onto a Local VLAN as well.&lt;/P&gt;
&lt;P&gt;We would like to configure one WLAN on the Flexconnect AP and place the client on the EoGRE tunnel or Local VLAN dynamically based on the return values from AAA/ISE.&lt;/P&gt;
&lt;P&gt;When we set the WLAN Profile &amp;gt; Tunnel Profile to our EoGRE profile, all clients are placed on the EoGRE tunnel&lt;BR /&gt;even though we return just the VLAN from the AAA server.&lt;/P&gt;
&lt;P&gt;When we set the WLAN Profile &amp;gt; Tunnel Profile to none, all clients are placed on the local AP vlan&lt;BR /&gt;even though we send these Cisco AV-Pairs from AAA/ISE&lt;/P&gt;
&lt;P&gt;gw-domain-name=abc123&lt;BR /&gt;mn-service=ipv4&lt;BR /&gt;cisco-mpc-protocol-interface=eogre&lt;BR /&gt;Primary-Tgw-IP=1.1.1.1&lt;BR /&gt;Secondary-Tgw-IP=2.2.2.2&lt;/P&gt;
&lt;P&gt;In the EoGRE tunneling guide under Flexconnect it states the following:&lt;/P&gt;
&lt;UL class="ul"&gt;
&lt;LI id="topic_58DDEFC8585F48EB93171526630E9FDB__li_34422787A5D248F3B2784E28058D68D7" class="li"&gt;
&lt;P class="p"&gt;802.1x authenticated “simple” and “tunneled” EoGRE clients are supported on the same WLAN.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="topic_58DDEFC8585F48EB93171526630E9FDB__li_8473E05A685E441BB65BE5DC0ED26C1A" class="li"&gt;
&lt;P class="p"&gt;Based on authentication, clients are separated into local or tunneled mode.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Is what I am trying to deploy possible?&amp;nbsp; &amp;nbsp;Is there any guide to what AV-Pairs should be returned from ISE to make it happen?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jun 2024 12:00:50 GMT</pubDate>
    <dc:creator>brian.holmes</dc:creator>
    <dc:date>2024-06-12T12:00:50Z</dc:date>
    <item>
      <title>WLC 5520 Flexconnect AP with EoGRE</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5520-flexconnect-ap-with-eogre/m-p/5128968#M272576</link>
      <description>&lt;P&gt;on a 5520 WLC v8.10.183&lt;/P&gt;
&lt;P&gt;We have been able to get a Flexconnect AP to build a EoGRE tunnel and put clients on it.&lt;BR /&gt;We have also been able to get a Flexconnect AP to drop client onto a Local VLAN as well.&lt;/P&gt;
&lt;P&gt;We would like to configure one WLAN on the Flexconnect AP and place the client on the EoGRE tunnel or Local VLAN dynamically based on the return values from AAA/ISE.&lt;/P&gt;
&lt;P&gt;When we set the WLAN Profile &amp;gt; Tunnel Profile to our EoGRE profile, all clients are placed on the EoGRE tunnel&lt;BR /&gt;even though we return just the VLAN from the AAA server.&lt;/P&gt;
&lt;P&gt;When we set the WLAN Profile &amp;gt; Tunnel Profile to none, all clients are placed on the local AP vlan&lt;BR /&gt;even though we send these Cisco AV-Pairs from AAA/ISE&lt;/P&gt;
&lt;P&gt;gw-domain-name=abc123&lt;BR /&gt;mn-service=ipv4&lt;BR /&gt;cisco-mpc-protocol-interface=eogre&lt;BR /&gt;Primary-Tgw-IP=1.1.1.1&lt;BR /&gt;Secondary-Tgw-IP=2.2.2.2&lt;/P&gt;
&lt;P&gt;In the EoGRE tunneling guide under Flexconnect it states the following:&lt;/P&gt;
&lt;UL class="ul"&gt;
&lt;LI id="topic_58DDEFC8585F48EB93171526630E9FDB__li_34422787A5D248F3B2784E28058D68D7" class="li"&gt;
&lt;P class="p"&gt;802.1x authenticated “simple” and “tunneled” EoGRE clients are supported on the same WLAN.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="topic_58DDEFC8585F48EB93171526630E9FDB__li_8473E05A685E441BB65BE5DC0ED26C1A" class="li"&gt;
&lt;P class="p"&gt;Based on authentication, clients are separated into local or tunneled mode.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Is what I am trying to deploy possible?&amp;nbsp; &amp;nbsp;Is there any guide to what AV-Pairs should be returned from ISE to make it happen?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2024 12:00:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5520-flexconnect-ap-with-eogre/m-p/5128968#M272576</guid>
      <dc:creator>brian.holmes</dc:creator>
      <dc:date>2024-06-12T12:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5520 Flexconnect AP with EoGRE</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5520-flexconnect-ap-with-eogre/m-p/5132303#M272744</link>
      <description>&lt;P&gt;Never tried to do this myself so don't know the answer but from trying to find the right AV-pairs for other previous issues I can confirm the documentation is poor to non-existent. Unless you have a known working setup you can do a packet capture on, it's just trial and error!&lt;BR /&gt;TAC usually have no idea (unless you get very lucky and get an engineer who has personal experience with this). We've had trouble even getting 1st line TAC to understand the question (took weeks and numerous emails), never mind know the answer (don't know)!&lt;/P&gt;
&lt;P&gt;I'd say your best bet is to contact your account team SE (or whatever they call them these days) and they may be able to find somebody in wireless BU who could answer your question.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 00:29:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5520-flexconnect-ap-with-eogre/m-p/5132303#M272744</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-06-17T00:29:59Z</dc:date>
    </item>
  </channel>
</rss>

