<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic No the switching type isn't in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706149#M56708</link>
    <description>&lt;P&gt;No the switching type isn't dynamic based on bandwidth or WAN status etc.You have to state whether you want that SSID to switch locally or centrally if the APs are in FlexConnect mode. This can be done from the GUI under&amp;nbsp;&lt;STRONG&gt;WLAN -&amp;gt; Select your SSID -&amp;gt; Advanced Tab -&amp;gt; select/de-select FlexConnect Local Switching&lt;/STRONG&gt;. (This might be H-REAP local switching for your code)&lt;/P&gt;&lt;P&gt;So for one SSID I&amp;nbsp;may have APs in Local Mode with all traffic tunnelled back to the WLAN Controller but then I could also have some remote offices with the same SSID off the same WLAN Controller which are in FlexConnect (H-REAP)&amp;nbsp;mode with local switching enabled. This allows for the flexibility of local authentication if you have servers on site and can also make it easier to manage firewall rules if traversing the WAN. That's purely a design/requirement thing though.&lt;/P&gt;&lt;P&gt;I think code 7.0.252 can perform the local switching feature but bare in mind many new features aren't available on the older codes and your 4400 can't support anything higher than 7.0.x If you are using guest anchor between your 2504/4400 there may be issues if they are running different versions of code.&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Ric&lt;/P&gt;</description>
    <pubDate>Tue, 04 Aug 2015 02:03:28 GMT</pubDate>
    <dc:creator>Ric Beeching</dc:creator>
    <dc:date>2015-08-04T02:03:28Z</dc:date>
    <item>
      <title>FexConnect AP local auth and roaming when WAN is down?</title>
      <link>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706146#M56705</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a remote site with 2 AP's in FlexConnect mode. Vlan switching is enabled.&lt;/P&gt;&lt;P&gt;The&amp;nbsp;auth method is WPA2-PSK.&lt;/P&gt;&lt;P&gt;What will happen if the WAN link goes down? Will a new client be able to&amp;nbsp;authenticate and associate?&lt;/P&gt;&lt;P&gt;Will the client be able to roam seamlessly?&lt;/P&gt;&lt;P&gt;Do I need to configure anything else than local vlan switching?&lt;/P&gt;&lt;P&gt;When and for what do I need to create users in the local database of the flex ap?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 10:40:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706146#M56705</guid>
      <dc:creator>istvan.kelemen1</dc:creator>
      <dc:date>2021-07-05T10:40:36Z</dc:date>
    </item>
    <item>
      <title> Hi Istvan,Please see the</title>
      <link>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706147#M56706</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Istvan,&lt;/P&gt;&lt;P&gt;Please see the feature tables below from the document&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/112042-technote-wlc-00.html&lt;/P&gt;&lt;H3 style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; line-height: normal;"&gt;Security - Client&lt;/H3&gt;&lt;P style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;Security support on FlexConnect varies with different modes and states. This table summarizes the security features that are supported:&lt;/P&gt;&lt;TABLE class="sptable" style="border: 1px solid rgb(153, 153, 153); color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TH style="padding: 5px; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(153, 153, 153); vertical-align: bottom; background-color: rgb(245, 245, 245);"&gt;&amp;nbsp;&lt;/TH&gt;&lt;TH style="padding: 5px; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(153, 153, 153); vertical-align: bottom; background-color: rgb(245, 245, 245);"&gt;WAN Up (Central Switching)&lt;/TH&gt;&lt;TH style="padding: 5px; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(153, 153, 153); vertical-align: bottom; background-color: rgb(245, 245, 245);"&gt;WAN Up (Local Switching)&lt;/TH&gt;&lt;TH style="padding: 5px; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(153, 153, 153); vertical-align: bottom; background-color: rgb(245, 245, 245);"&gt;WAN Up (Local Switching, Local Authorization)&lt;/TH&gt;&lt;TH style="padding: 5px; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(153, 153, 153); vertical-align: bottom; background-color: rgb(245, 245, 245);"&gt;WAN Down (Standalone)&lt;/TH&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Open/Static WEP&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;WPA-PSK&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;802.1x (WPA/WPA2)&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;MAC filter Authentication&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;No&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;No&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;CCKM Fast Roaming&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Yes, for connected clients. No, for new clients.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H3 style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; line-height: normal;"&gt;Mobility / Roaming Scenarios&lt;/H3&gt;&lt;TABLE class="sptable" style="border: 1px solid rgb(153, 153, 153); color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TH colspan="1" rowspan="2" style="padding: 5px; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(153, 153, 153); vertical-align: bottom; background-color: rgb(245, 245, 245);"&gt;&lt;STRONG&gt;WLAN Configuration&lt;/STRONG&gt;&lt;/TH&gt;&lt;TH colspan="3" rowspan="1" style="padding: 5px; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(153, 153, 153); vertical-align: bottom; background-color: rgb(245, 245, 245);"&gt;&lt;STRONG&gt;Local Switching&lt;/STRONG&gt;&lt;/TH&gt;&lt;TH colspan="3" rowspan="1" style="padding: 5px; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(153, 153, 153); vertical-align: bottom; background-color: rgb(245, 245, 245);"&gt;&lt;STRONG&gt;Central Switching&lt;/STRONG&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TH colspan="1" rowspan="1" style="padding: 5px; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(153, 153, 153); vertical-align: bottom; background-color: rgb(245, 245, 245);"&gt;&lt;STRONG&gt;CCKM&lt;/STRONG&gt;&lt;/TH&gt;&lt;TH colspan="1" rowspan="1" style="padding: 5px; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(153, 153, 153); vertical-align: bottom; background-color: rgb(245, 245, 245);"&gt;&lt;STRONG&gt;PMK (OKC)&lt;/STRONG&gt;&lt;/TH&gt;&lt;TH colspan="1" rowspan="1" style="padding: 5px; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(153, 153, 153); vertical-align: bottom; background-color: rgb(245, 245, 245);"&gt;&lt;STRONG&gt;Others&lt;/STRONG&gt;&lt;/TH&gt;&lt;TH colspan="1" rowspan="1" style="padding: 5px; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(153, 153, 153); vertical-align: bottom; background-color: rgb(245, 245, 245);"&gt;&lt;STRONG&gt;CCKM&lt;/STRONG&gt;&lt;/TH&gt;&lt;TH colspan="1" rowspan="1" style="padding: 5px; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(153, 153, 153); vertical-align: bottom; background-color: rgb(245, 245, 245);"&gt;&lt;STRONG&gt;PMK (OKC)&lt;/STRONG&gt;&lt;/TH&gt;&lt;TH colspan="1" rowspan="1" style="padding: 5px; border-width: 1px 1px 2px; border-style: solid; border-color: rgb(153, 153, 153); vertical-align: bottom; background-color: rgb(245, 245, 245);"&gt;&lt;STRONG&gt;Others&lt;/STRONG&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Mobility Between Same Flex Group&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Fast Roam&lt;SUP&gt;(1)&lt;/SUP&gt;&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Fast Roam&lt;SUP&gt;(1)&lt;/SUP&gt;&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Full Auth&lt;SUP&gt;(1)&lt;/SUP&gt;&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Fast Roam&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Fast Roam&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Full Auth&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Mobility Between Different Flex Group&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Full Auth&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Full Auth&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Full Auth&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Full Auth&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Full Auth&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Full Auth&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Inter Controller Mobility&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;N/A&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;N/A&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;N/A&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Full Auth&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Fast Roam&lt;/TD&gt;&lt;TD style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;Full Auth&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD colspan="7" style="padding: 5px; border: 1px solid rgb(153, 153, 153);"&gt;&lt;P&gt;&lt;SUP&gt;(1)&lt;/SUP&gt;&amp;nbsp;Provided WLAN is mapped to the same VLAN (same subnet).&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What version of code are you running on your WLC?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ric&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2015 01:42:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706147#M56706</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2015-08-03T01:42:44Z</dc:date>
    </item>
    <item>
      <title>wlc 2504 - 7.4.130wlc4404 - 7</title>
      <link>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706148#M56707</link>
      <description>&lt;P&gt;wlc 2504 - 7.4.130&lt;/P&gt;&lt;P&gt;wlc4404 - 7.0.252&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: arial, helvetica, sans-serif; font-size: 12px; font-weight: bold; line-height: normal; text-align: center; background-color: rgb(245, 245, 245);"&gt;WAN Up (Local Switching &amp;nbsp;-&amp;nbsp;&lt;/SPAN&gt;when does it come to the play? when the bandwidth is not enough?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2015 19:58:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706148#M56707</guid>
      <dc:creator>istvan.kelemen1</dc:creator>
      <dc:date>2015-08-03T19:58:56Z</dc:date>
    </item>
    <item>
      <title>No the switching type isn't</title>
      <link>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706149#M56708</link>
      <description>&lt;P&gt;No the switching type isn't dynamic based on bandwidth or WAN status etc.You have to state whether you want that SSID to switch locally or centrally if the APs are in FlexConnect mode. This can be done from the GUI under&amp;nbsp;&lt;STRONG&gt;WLAN -&amp;gt; Select your SSID -&amp;gt; Advanced Tab -&amp;gt; select/de-select FlexConnect Local Switching&lt;/STRONG&gt;. (This might be H-REAP local switching for your code)&lt;/P&gt;&lt;P&gt;So for one SSID I&amp;nbsp;may have APs in Local Mode with all traffic tunnelled back to the WLAN Controller but then I could also have some remote offices with the same SSID off the same WLAN Controller which are in FlexConnect (H-REAP)&amp;nbsp;mode with local switching enabled. This allows for the flexibility of local authentication if you have servers on site and can also make it easier to manage firewall rules if traversing the WAN. That's purely a design/requirement thing though.&lt;/P&gt;&lt;P&gt;I think code 7.0.252 can perform the local switching feature but bare in mind many new features aren't available on the older codes and your 4400 can't support anything higher than 7.0.x If you are using guest anchor between your 2504/4400 there may be issues if they are running different versions of code.&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Ric&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2015 02:03:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706149#M56708</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2015-08-04T02:03:28Z</dc:date>
    </item>
    <item>
      <title>Ah I think I understand now</title>
      <link>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706150#M56709</link>
      <description>&lt;P&gt;Ah I think I&amp;nbsp;understand now!&lt;/P&gt;&lt;P&gt;So when the AP is in Flex mode, I&amp;nbsp;can choose between local or central witching when the WAN is up. So when the WAN goes down, the AP will locally switch traffic even if I set central switch?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2015 21:18:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706150#M56709</guid>
      <dc:creator>istvan.kelemen1</dc:creator>
      <dc:date>2015-08-04T21:18:32Z</dc:date>
    </item>
    <item>
      <title>Almost."So when the AP is in</title>
      <link>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706151#M56710</link>
      <description>&lt;P&gt;Almost.&lt;/P&gt;&lt;P&gt;"&lt;SPAN style="font-size: 14.3999996185303px;"&gt;So when the AP is in Flex mode, I&amp;nbsp;can choose between local or central witching when the WAN is up" - &lt;STRONG&gt;Correct&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN style="font-size: 14.3999996185303px;"&gt;So&amp;nbsp;when the WAN goes down, the AP will locally switch traffic even if I set central switch?" - &lt;STRONG&gt;Incorrect&lt;/STRONG&gt;. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;If you want the APs to still service traffic when the WAN goes down then they have to be in H-REAP/FlexConnect mode and the SSID (WLAN) needs to have local switching enabled.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2015 01:58:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706151#M56710</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2015-08-05T01:58:07Z</dc:date>
    </item>
    <item>
      <title>Yes, I meant this under the</title>
      <link>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706152#M56711</link>
      <description>&lt;P&gt;Yes, I meant this under the second one. Thanks!&lt;/P&gt;&lt;P&gt;Few more questions... When the AP is in Flex mode, does it trunk when it is switching the traffic centrally? What should the native vlan be?&lt;/P&gt;&lt;P&gt;Or when it is in Flex mode, and the WAN is up,&amp;nbsp;it switches the traffic centrally so, it sends the traffic out with&amp;nbsp;a vlan tag matching with the appropriate&amp;nbsp;ssid upto the WLC or via CAPWAP tunnel over the&amp;nbsp;native vlan?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2015 18:06:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706152#M56711</guid>
      <dc:creator>istvan.kelemen1</dc:creator>
      <dc:date>2015-08-05T18:06:18Z</dc:date>
    </item>
    <item>
      <title>In Flex mode with central</title>
      <link>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706153#M56712</link>
      <description>&lt;P&gt;In Flex mode with central switching all the data traffic will be tunnelled back to the controller via the CAPWAP tunnel so that will be whatever you are tagging your trunk's native vlan as for the Access Point.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;"or via CAPWAP tunnel over the&amp;nbsp;native vlan?" - Yep!&lt;/SPAN&gt;&amp;nbsp;So in your scenario (Flex with Central switch), all the data and control traffic will flow inside a tunnel that is initially tagged with whatever vlan you have as the native vlan on your trunk port connected to the access point. This may change as it flows through the network but that doesn't matter. The traffic will arrive at your WLAN controller and from there it will egress to the rest of the network based off the interface you have told it to go out of under the WLAN (SSID)&amp;nbsp;setting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2015 11:43:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706153#M56712</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2015-08-06T11:43:13Z</dc:date>
    </item>
    <item>
      <title>Ah thx!What will happen if</title>
      <link>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706154#M56713</link>
      <description>&lt;P&gt;Ah thx!&lt;/P&gt;&lt;P&gt;What will happen if the WAN&amp;nbsp;or the WLC&amp;nbsp;goes down?&lt;/P&gt;&lt;P&gt;Will the AP become a layer 2 switch, and change it's uplink to trunk and forwards all the traffic upwards to the layer 3 switch? Or it will only switch traffic between the clients connected to the same SSID and where the local swithing is enabled, or also between SSID-s and vlans via&amp;nbsp;the L3 switch?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2015 15:43:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/2706154#M56713</guid>
      <dc:creator>istvan.kelemen1</dc:creator>
      <dc:date>2015-08-06T15:43:44Z</dc:date>
    </item>
    <item>
      <title>Re:  Hi Istvan,</title>
      <link>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/3865740#M56714</link>
      <description>&lt;P&gt;I have some confusion as per below document it says if I set local auth/local switch then 802.1x is not supported&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/Enterprise-Mobility-8-5-Design-Guide/Enterprise_Mobility_8-5_Deployment_Guide/ch7_HREA.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/Enterprise-Mobility-8-5-Design-Guide/Enterprise_Mobility_8-5_Deployment_Guide/ch7_HREA.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H3&gt;Authentication-local/switch-local&lt;/H3&gt;&lt;P class="pB1_Body1"&gt;This state represents a WLAN that uses open, static WEP, shared, or WPA2 PSK security methods. User traffic is switched locally. These are the only security methods supported locally if a FlexConnect goes into standalone mode. The WLAN continues to beacon and respond to probes (&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/Enterprise-Mobility-8-5-Design-Guide/Enterprise_Mobility_8-5_Deployment_Guide/ch7_HREA.html#42265" target="_blank" rel="noopener"&gt;Figure 7-5&lt;/A&gt;). Existing users remain connected and new user associations are accepted. If the AP is in connected mode, authentication information for these security types is forwarded to the WLC.&lt;/P&gt;&lt;P class="pB1_Body1"&gt;But as per above post it seems 802.1x is supported in local auth/ local switching mode.&lt;/P&gt;&lt;P class="pB1_Body1"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 12:47:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fexconnect-ap-local-auth-and-roaming-when-wan-is-down/m-p/3865740#M56714</guid>
      <dc:creator>buro_1986</dc:creator>
      <dc:date>2019-05-31T12:47:15Z</dc:date>
    </item>
  </channel>
</rss>

