<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 9800 HA SSO and Certificate Setup/Failover in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/9800-ha-sso-and-certificate-setup-failover/m-p/5221062#M277502</link>
    <description>&lt;P class="p"&gt;&lt;SPAN&gt;The Redundancy Management Interface (RMI) is used as a secondary link between the active and standby Cisco Catalyst 9800 Series Wireless Controllers. This interface is the same as the wireless management interface, and the IP address on this interface is configured in the same subnet as the Wireless Management&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph"&gt;IP&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p"&gt;Two HA interfaces (RMI and RP) must be configured on the same subnet, and the subnet cannot be shared with any other interfaces on the device.&lt;/P&gt;
&lt;P class="p"&gt;Ref:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/m_vewlc_high_availability.html#restrictions-high-avail" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/m_vewlc_high_availability.html#restrictions-high-avail&lt;/A&gt;&lt;/P&gt;
&lt;P class="p"&gt;Jagan Chowdam&lt;/P&gt;</description>
    <pubDate>Wed, 06 Nov 2024 17:06:19 GMT</pubDate>
    <dc:creator>jagan.chowdam</dc:creator>
    <dc:date>2024-11-06T17:06:19Z</dc:date>
    <item>
      <title>9800 HA SSO and Certificate Setup/Failover</title>
      <link>https://community.cisco.com/t5/wireless/9800-ha-sso-and-certificate-setup-failover/m-p/5221043#M277497</link>
      <description>&lt;P&gt;Good Day,&lt;BR /&gt;&lt;BR /&gt;I have 2 questions related to the SSL certificate for a pair of 9800-40's set up in an HA SSO pair.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Using the Guide: "&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/220277-configure-high-availability-sso-on-catal.html" target="_blank" rel="noopener"&gt;Configure High Availability SSO on Catalyst 9800 | Quick Start Guide - Cisco&lt;/A&gt;" and setting up the IP's. saying that basically you set up both WLC with IP's. and each get a RMI IP.&amp;nbsp;&lt;BR /&gt;Does the RMI IP have to be in the same vlan/subnet as the main WLC IP? I assume it makes more sense to put them together since all 3 addresses are routable.&amp;nbsp;&lt;BR /&gt;Also, with AAA i have to make sure to call out the WLC WMI WLC and both RMI IP's&lt;BR /&gt;&lt;BR /&gt;Secondly, Having set up HA SSO and using a CA signed certificate. I assume i still use the primary WLC WMI IP to manage the device, so that IP should resolve to the DNS name. but should i also have Both RMI IP's resolve to the DNS name as well.&amp;nbsp;&lt;BR /&gt;wlc01 - WMI 10.1.1.10&lt;BR /&gt;WLC01 - RMI 10.1.1.11&lt;BR /&gt;WLC02 - RMI 10.1.1.20&lt;BR /&gt;&lt;BR /&gt;I think i read that "&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213917-generate-csr-for-third-party-certificate.html" target="_blank" rel="noopener"&gt;Generate and Download CSR Certificates on Catalyst 9800 WLCs - Cisco&lt;/A&gt;" the certificae should copy over to the secondary, but i also see where some people still upload it to the secondary wlc which you would access with the wlc02 RMI ip address.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Lastly, during a failover, does the primary ip switch between the devices. AKA, 10.1.1.10 will access the Primary/Active WLC. But if you needed to mess or look at a certain device, you use that devices RMI ip address.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you for your time and please let me know if i need to further explain anything.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 16:00:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-ha-sso-and-certificate-setup-failover/m-p/5221043#M277497</guid>
      <dc:creator>tcebak</dc:creator>
      <dc:date>2024-11-06T16:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 HA SSO and Certificate Setup/Failover</title>
      <link>https://community.cisco.com/t5/wireless/9800-ha-sso-and-certificate-setup-failover/m-p/5221048#M277499</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- A few items , you do not need to copy the certificate to the secondary ; the primary IP remains transparent available during a failover ;&amp;nbsp; RMI's must not be in the same subnet as the main WLC IP ; they don't need DNS names&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Foremost : when configuring the&amp;nbsp; 9800 controller ; always validate such issues ; with by using &lt;STRONG&gt;WirelessAnalyzer&lt;/STRONG&gt;&amp;nbsp;:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; this is done with the CLI command &lt;FONT color="#008000"&gt;&lt;STRONG&gt;show tech &lt;U&gt;wireless&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt; ; (not a simple &lt;FONT color="#FF0000"&gt;&lt;EM&gt;show tech&lt;/EM&gt;&lt;/FONT&gt;) and feed the output from that into&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank"&gt;Wireless Config Analyzer&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;You will (&lt;STRONG&gt;also&lt;/STRONG&gt;) get immediate feedback on configuration errors related to these items ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 16:12:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-ha-sso-and-certificate-setup-failover/m-p/5221048#M277499</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-11-06T16:12:03Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 HA SSO and Certificate Setup/Failover</title>
      <link>https://community.cisco.com/t5/wireless/9800-ha-sso-and-certificate-setup-failover/m-p/5221056#M277501</link>
      <description>&lt;P&gt;Thank you about the comment about RMI's being in a different subnet! i think i overlooked that in the example when i was looking through a few different documents.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;"&lt;SPAN&gt;when RMI + RP is used, both Standby and Active controllers have a redundancy management interface (RMI) to which are assigned IP addresses, namely used to ensure gateway reachability." Just making sure that those IP's need to be in a valid subnet that can route across the network? or can you put in basically and non-valid subnet that doesn't exist on the network?&lt;BR /&gt;&lt;BR /&gt;Thanks again!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 16:47:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-ha-sso-and-certificate-setup-failover/m-p/5221056#M277501</guid>
      <dc:creator>tcebak</dc:creator>
      <dc:date>2024-11-06T16:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 HA SSO and Certificate Setup/Failover</title>
      <link>https://community.cisco.com/t5/wireless/9800-ha-sso-and-certificate-setup-failover/m-p/5221062#M277502</link>
      <description>&lt;P class="p"&gt;&lt;SPAN&gt;The Redundancy Management Interface (RMI) is used as a secondary link between the active and standby Cisco Catalyst 9800 Series Wireless Controllers. This interface is the same as the wireless management interface, and the IP address on this interface is configured in the same subnet as the Wireless Management&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph"&gt;IP&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p"&gt;Two HA interfaces (RMI and RP) must be configured on the same subnet, and the subnet cannot be shared with any other interfaces on the device.&lt;/P&gt;
&lt;P class="p"&gt;Ref:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/m_vewlc_high_availability.html#restrictions-high-avail" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/m_vewlc_high_availability.html#restrictions-high-avail&lt;/A&gt;&lt;/P&gt;
&lt;P class="p"&gt;Jagan Chowdam&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 17:06:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-ha-sso-and-certificate-setup-failover/m-p/5221062#M277502</guid>
      <dc:creator>jagan.chowdam</dc:creator>
      <dc:date>2024-11-06T17:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 HA SSO and Certificate Setup/Failover</title>
      <link>https://community.cisco.com/t5/wireless/9800-ha-sso-and-certificate-setup-failover/m-p/5221087#M277503</link>
      <description>&lt;P&gt;Ok, thank you. i think i keep getting the different connections mixed up in my head, but this is making sense and i'm following now. Thanks! just going to configure it to double check. thanks again!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 18:29:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-ha-sso-and-certificate-setup-failover/m-p/5221087#M277503</guid>
      <dc:creator>tcebak</dc:creator>
      <dc:date>2024-11-06T18:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 HA SSO and Certificate Setup/Failover</title>
      <link>https://community.cisco.com/t5/wireless/9800-ha-sso-and-certificate-setup-failover/m-p/5221090#M277504</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/555767"&gt;@tcebak&lt;/a&gt;&amp;nbsp; &amp;nbsp;Ok , remember to execute the &lt;STRONG&gt;WirelessAnalyzer&lt;/STRONG&gt; procedure as described afterwards ; it is kind of &lt;U&gt;&lt;STRONG&gt;mandatory&lt;/STRONG&gt;&lt;/U&gt; &lt;EM&gt;before production use!&lt;BR /&gt;&lt;/EM&gt;&amp;nbsp;You may also find this presentation useful :&amp;nbsp;&lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/global-event/docs/2024/pdf/BRKEWN-2094.pdf" target="_blank"&gt;https://www.ciscolive.com/c/dam/r/ciscolive/global-event/docs/2024/pdf/BRKEWN-2094.pdf&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;although that only&amp;nbsp; mentions the basics (SSID's , WLAN's,,,,) ; it's not focused on the HA stuff&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 18:37:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-ha-sso-and-certificate-setup-failover/m-p/5221090#M277504</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-11-06T18:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 HA SSO and Certificate Setup/Failover</title>
      <link>https://community.cisco.com/t5/wireless/9800-ha-sso-and-certificate-setup-failover/m-p/5221095#M277507</link>
      <description>&lt;P&gt;Thank you, that document does help explain the ssid/wlans/etc and pictures/examples make it easier to understand. Luckily i was able to fumble my way through with setting up my single lab 9800 which is still just getting used to the new layout and policies. of course the lab is simple and our PROD switch over will have a lot more, but any documentation always helps and i'll check out the WirelessAnalyzer.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 18:49:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-ha-sso-and-certificate-setup-failover/m-p/5221095#M277507</guid>
      <dc:creator>tcebak</dc:creator>
      <dc:date>2024-11-06T18:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: 9800 HA SSO and Certificate Setup/Failover</title>
      <link>https://community.cisco.com/t5/wireless/9800-ha-sso-and-certificate-setup-failover/m-p/5221098#M277508</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Yeah , you can already use WirelessAnalyzer on the lab-9800 to , get a look and feel with it ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 18:55:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-ha-sso-and-certificate-setup-failover/m-p/5221098#M277508</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-11-06T18:55:25Z</dc:date>
    </item>
  </channel>
</rss>

