<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Local Webauth across multiple controller types in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/local-webauth-across-multiple-controller-types/m-p/5264288#M281186</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/321232"&gt;@dselfridge&lt;/a&gt;&amp;nbsp; &amp;nbsp;: I suppose that should work ; (&lt;SPAN&gt;&lt;EM&gt;&lt;U&gt;But am I correct in thinking if a client registers on say the 5508 Portal then roams across to a 9800 homed AP, they should stay connected&lt;/U&gt;? &lt;U&gt;Assuming of course that the mobility tunnels are up&lt;/U&gt;.&lt;/EM&gt;)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;- If not you can &lt;STRONG&gt;debug&lt;/STRONG&gt; the client on the 9800 'when it arrives' using :&amp;nbsp;&lt;A href="https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity" target="_blank"&gt;https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; You can have client debugs (so called RadioActive Traces) ; analyzed with&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-debug-analyzer/" target="_blank"&gt;Wireless Debug Analyzer&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Commands from&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#toc-hId-866973845" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#toc-hId-866973845&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; can also be useful&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;- Checkout the &lt;STRONG&gt;configuration&lt;/STRONG&gt; on both controllers to (w.r.t. mobility and other stuff)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; For the 9800 use the CLI command&lt;FONT color="#008000"&gt;&lt;STRONG&gt; show tech wireless&lt;/STRONG&gt;&lt;/FONT&gt; and feed the output into&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank"&gt;Wireless Config Analyzer&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; - For the 5508 use&amp;nbsp;&lt;A href="https://community.cisco.com/t5/networking-knowledge-base/show-the-complete-configuration-without-breaks-pauses-on-cisco/ta-p/3115114#toc-hId-1039672820" target="_blank"&gt;WirelessAnalyzer input (procedure) for AireOs controllers&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;and feed the output from that into&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank"&gt;Wireless Config Analyzer&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; M.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Feb 2025 15:07:16 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2025-02-24T15:07:16Z</dc:date>
    <item>
      <title>Local Webauth across multiple controller types</title>
      <link>https://community.cisco.com/t5/wireless/local-webauth-across-multiple-controller-types/m-p/5264217#M281181</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;
&lt;P&gt;My Customer is in the middle of migrating multiple sites from AireOS (5508) to IOS (9800) WLCs.&lt;/P&gt;
&lt;P&gt;Most sites work fine and guest users are serviced by the LobbyAdmin feature and local web-auth on the 9800 controller.&lt;/P&gt;
&lt;P&gt;Some APs are yet to be replaced, so until that happens, they need to stay on the 5508, which of course has it's own LWA Portal. The issue is that a minority of sites have a mix of APs, old &amp;amp; new, so i have a 'salt &amp;amp; pepper' environment. Therefore, if a user is on say an older 3502 AP, they will hit the 5508 portal. If they then roam to say a 9120 AP they then are on the 9800 controller, will the session stay up? Like wise if they start on 9800 AP and roam to a 5508 AP. Also, there are 2 Lobby Admin Portals to maintain, which is confusing.&lt;/P&gt;
&lt;P&gt;I have mobility tunnels setup between the controllers (IRCM Code). No Anchors are in the mix, because internet breakout is local to each site. The controllers are in data centers and the APs are in Flexconnect mode with local switching.&lt;/P&gt;
&lt;P&gt;What I want to achieve is that if a guest user connects to the guest SSID and no matter if they are on an old or newer AP, they consistently hit the Lobby on the 9800. is this even possible? It's only temporary, to give time for the customer to replace all the older APs.&lt;/P&gt;
&lt;P&gt;Obviously, i would prefer they use CWA with ISE - but for various reasons, that's not a runner at this time.&lt;/P&gt;
&lt;P&gt;TIA&lt;/P&gt;
&lt;P&gt;Dan&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 11:57:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-webauth-across-multiple-controller-types/m-p/5264217#M281181</guid>
      <dc:creator>dselfridge</dc:creator>
      <dc:date>2025-02-24T11:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: Local Webauth across multiple controller types</title>
      <link>https://community.cisco.com/t5/wireless/local-webauth-across-multiple-controller-types/m-p/5264219#M281182</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - That's impossible to achieve because each controller (type) has it's own authenticating rules behind the Lobby , &lt;FONT color="#008000"&gt;&lt;EM&gt;best is to finish the AP migration&lt;U&gt; as soon as possible ,&lt;/U&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 12:08:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-webauth-across-multiple-controller-types/m-p/5264219#M281182</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-02-24T12:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: Local Webauth across multiple controller types</title>
      <link>https://community.cisco.com/t5/wireless/local-webauth-across-multiple-controller-types/m-p/5264231#M281183</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/321232"&gt;@dselfridge&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Long shot here but what is you setup the 5508 with external web portal and point&amp;nbsp; to 9800 ?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 12:57:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-webauth-across-multiple-controller-types/m-p/5264231#M281183</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2025-02-24T12:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: Local Webauth across multiple controller types</title>
      <link>https://community.cisco.com/t5/wireless/local-webauth-across-multiple-controller-types/m-p/5264232#M281184</link>
      <description>&lt;P&gt;Thank you for replying so quickly&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But am I correct in thinking if a client registers on say the 5508 Portal then roams across to a 9800 homed AP, they should stay connected? Assuming of course that the mobility tunnels are up.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 12:58:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-webauth-across-multiple-controller-types/m-p/5264232#M281184</guid>
      <dc:creator>dselfridge</dc:creator>
      <dc:date>2025-02-24T12:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: Local Webauth across multiple controller types</title>
      <link>https://community.cisco.com/t5/wireless/local-webauth-across-multiple-controller-types/m-p/5264288#M281186</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/321232"&gt;@dselfridge&lt;/a&gt;&amp;nbsp; &amp;nbsp;: I suppose that should work ; (&lt;SPAN&gt;&lt;EM&gt;&lt;U&gt;But am I correct in thinking if a client registers on say the 5508 Portal then roams across to a 9800 homed AP, they should stay connected&lt;/U&gt;? &lt;U&gt;Assuming of course that the mobility tunnels are up&lt;/U&gt;.&lt;/EM&gt;)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;- If not you can &lt;STRONG&gt;debug&lt;/STRONG&gt; the client on the 9800 'when it arrives' using :&amp;nbsp;&lt;A href="https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity" target="_blank"&gt;https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; You can have client debugs (so called RadioActive Traces) ; analyzed with&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-debug-analyzer/" target="_blank"&gt;Wireless Debug Analyzer&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Commands from&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#toc-hId-866973845" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#toc-hId-866973845&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; can also be useful&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;- Checkout the &lt;STRONG&gt;configuration&lt;/STRONG&gt; on both controllers to (w.r.t. mobility and other stuff)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; For the 9800 use the CLI command&lt;FONT color="#008000"&gt;&lt;STRONG&gt; show tech wireless&lt;/STRONG&gt;&lt;/FONT&gt; and feed the output into&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank"&gt;Wireless Config Analyzer&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; - For the 5508 use&amp;nbsp;&lt;A href="https://community.cisco.com/t5/networking-knowledge-base/show-the-complete-configuration-without-breaks-pauses-on-cisco/ta-p/3115114#toc-hId-1039672820" target="_blank"&gt;WirelessAnalyzer input (procedure) for AireOs controllers&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;and feed the output from that into&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank"&gt;Wireless Config Analyzer&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; M.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 15:07:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-webauth-across-multiple-controller-types/m-p/5264288#M281186</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-02-24T15:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: Local Webauth across multiple controller types</title>
      <link>https://community.cisco.com/t5/wireless/local-webauth-across-multiple-controller-types/m-p/5264300#M281188</link>
      <description>&lt;P&gt;That mix and match just isn't a preferred way to migrate, not just for guest, but you have a lot of inter controller roaming that has to happen. I would of waited to migrate one whole site, take that 5508 and use that for an anchor at the next site, so that you can push guest to that anchor until you have migrated that one site, which then you can disable the anchoring on the 9800 and that becomes the controller with LWA. I think you just have to play around with what you have available and like what&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;mentioned, give that a try also.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 15:37:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-webauth-across-multiple-controller-types/m-p/5264300#M281188</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2025-02-24T15:37:45Z</dc:date>
    </item>
  </channel>
</rss>

