<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Roaming behaviour - local vs flexconnect in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/roaming-behaviour-local-vs-flexconnect/m-p/2988081#M95686</link>
    <description>&lt;P&gt;Hi all. I have a site that is misbehaving and I would like to run my findings past the knowledgeable people of this forum. Here is the scenario:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Two 4400 WLCs in mobility group TEST&lt;/LI&gt;
&lt;LI&gt;~ 100 APs all running in local mode&lt;/LI&gt;
&lt;LI&gt;One WLAN Profile&lt;/LI&gt;
&lt;LI&gt;15 different location&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Each location has assigned a different VLAN, IP subnet and ap group which links these together with the APs that are located on that site. So for example:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Site A -&amp;nbsp; VLAN 100, subnet 192.168.1.0/24, AP_Group_A&lt;/LI&gt;
&lt;LI&gt;Site B -&amp;nbsp; VLAN 200, subnet 192.168.2.0/24, AP_Group_B&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;And so on. As mentioned, all these VLANs are centrally switched and there is only one WLAN profile which has a different VLAN depending on the AP Group.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;So when a user moves between these locations, it creates a layer 3 roaming event. That's all fine but where I have a problem is what happens with the MAC address of the client. It appears that as traffic from a L3 roaming client passes through the WLC, the source MAC is rewritten as the MAC address of the WLC on the anchor WLC. This becomes a problem because there is a captive portal running on a separate device, which needs to see the real client MAC address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Instead, what happens is this:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Client A connects to the wireless at Site A and gets IP address 192.168.1.10&lt;/LI&gt;
&lt;LI&gt;Client A moves to location B and the WLC detects a L3 mobility event.&lt;/LI&gt;
&lt;LI&gt;Traffic from client A now exits through VLAN 200 on the foreign controller but is returned via VLAN 100 on the anchor controller.&lt;/LI&gt;
&lt;LI&gt;The captive portal device sees traffic coming in from VLAN 200 with a source IP from VLAN 100. Additionally, the source MAC address is the wired interface of the anchor controller.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;As a result, when a number of clients do this, all their traffic appears to be from the same source MAC.&lt;/P&gt;
&lt;P&gt;I'm not sure the fact that there are multiple controllers actually matters here, as I believe it is roaming between subnets that is causing the problem, rather than roaming between controllers.&lt;/P&gt;
&lt;P&gt;So my next question is, how would this scenario be different if I used HREAP/Flexconnect instead? What I believe should happen is this:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Client A moves from one AP in Site A to another AP in Site A - this is a layer 2 roaming event and is performed seamlessly.&lt;/LI&gt;
&lt;LI&gt;Client A moves from Site A to Site B - layer 3 roaming not supported in Flexconnect mode so the client has to obtain another DHCP address and no NAT'ing is performed.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope all that makes sense. Based on the information above, would you say that my assumptions are correct?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Another idea I had is to disable layer 3 roaming and only allow layer 2 roaming. But I can't find any information on how to do this, or even if it is possible.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Many thanks!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Paul&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 13:07:04 GMT</pubDate>
    <dc:creator>Paul Harris</dc:creator>
    <dc:date>2021-07-05T13:07:04Z</dc:date>
    <item>
      <title>Roaming behaviour - local vs flexconnect</title>
      <link>https://community.cisco.com/t5/wireless/roaming-behaviour-local-vs-flexconnect/m-p/2988081#M95686</link>
      <description>&lt;P&gt;Hi all. I have a site that is misbehaving and I would like to run my findings past the knowledgeable people of this forum. Here is the scenario:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Two 4400 WLCs in mobility group TEST&lt;/LI&gt;
&lt;LI&gt;~ 100 APs all running in local mode&lt;/LI&gt;
&lt;LI&gt;One WLAN Profile&lt;/LI&gt;
&lt;LI&gt;15 different location&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Each location has assigned a different VLAN, IP subnet and ap group which links these together with the APs that are located on that site. So for example:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Site A -&amp;nbsp; VLAN 100, subnet 192.168.1.0/24, AP_Group_A&lt;/LI&gt;
&lt;LI&gt;Site B -&amp;nbsp; VLAN 200, subnet 192.168.2.0/24, AP_Group_B&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;And so on. As mentioned, all these VLANs are centrally switched and there is only one WLAN profile which has a different VLAN depending on the AP Group.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;So when a user moves between these locations, it creates a layer 3 roaming event. That's all fine but where I have a problem is what happens with the MAC address of the client. It appears that as traffic from a L3 roaming client passes through the WLC, the source MAC is rewritten as the MAC address of the WLC on the anchor WLC. This becomes a problem because there is a captive portal running on a separate device, which needs to see the real client MAC address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Instead, what happens is this:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Client A connects to the wireless at Site A and gets IP address 192.168.1.10&lt;/LI&gt;
&lt;LI&gt;Client A moves to location B and the WLC detects a L3 mobility event.&lt;/LI&gt;
&lt;LI&gt;Traffic from client A now exits through VLAN 200 on the foreign controller but is returned via VLAN 100 on the anchor controller.&lt;/LI&gt;
&lt;LI&gt;The captive portal device sees traffic coming in from VLAN 200 with a source IP from VLAN 100. Additionally, the source MAC address is the wired interface of the anchor controller.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;As a result, when a number of clients do this, all their traffic appears to be from the same source MAC.&lt;/P&gt;
&lt;P&gt;I'm not sure the fact that there are multiple controllers actually matters here, as I believe it is roaming between subnets that is causing the problem, rather than roaming between controllers.&lt;/P&gt;
&lt;P&gt;So my next question is, how would this scenario be different if I used HREAP/Flexconnect instead? What I believe should happen is this:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Client A moves from one AP in Site A to another AP in Site A - this is a layer 2 roaming event and is performed seamlessly.&lt;/LI&gt;
&lt;LI&gt;Client A moves from Site A to Site B - layer 3 roaming not supported in Flexconnect mode so the client has to obtain another DHCP address and no NAT'ing is performed.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope all that makes sense. Based on the information above, would you say that my assumptions are correct?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Another idea I had is to disable layer 3 roaming and only allow layer 2 roaming. But I can't find any information on how to do this, or even if it is possible.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Many thanks!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Paul&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 13:07:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/roaming-behaviour-local-vs-flexconnect/m-p/2988081#M95686</guid>
      <dc:creator>Paul Harris</dc:creator>
      <dc:date>2021-07-05T13:07:04Z</dc:date>
    </item>
  </channel>
</rss>

