cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
716
Views
0
Helpful
7
Replies

Configuring physical WLC ports for egress of Guest traffic.

s.vosper
Level 1
Level 1

Hi All

Could some body please tell me if its possible or indeed advisable to configure physical ports on a WLC for egresstion of specific VLANs,

For example could one confiure a seperate port to connect to the DMZ for guest VLAN traffic only. I'm sure the best way is to use guest anchoring with secure tunneling, but is this alternative way even possible. If so could someone please point me to the documentation.

Many thanks

Simon

2 Accepted Solutions

Accepted Solutions

Scott Fella
Hall of Fame
Hall of Fame

You can, but what you need to understand is that your can either LAG or not use LAG.  If you want to break out the ports on the WLC to specify a primary and or a secondary port, you can, but LAG will need to be disabled.

Thanks,

Scott

Help out other by using the rating system and marking answered questions as "Answered"

-Scott
*** Please rate helpful posts ***

View solution in original post

There isn't a doc out there explaining this, since LAG is the prefered method.  Its basically simple... in your interface or dynamic interface, you specify what port is your primary and secondary.

Thanks,

Scott

Help out other by using the rating system and marking answered questions as "Answered"

-Scott
*** Please rate helpful posts ***

View solution in original post

7 Replies 7

Scott Fella
Hall of Fame
Hall of Fame

You can, but what you need to understand is that your can either LAG or not use LAG.  If you want to break out the ports on the WLC to specify a primary and or a secondary port, you can, but LAG will need to be disabled.

Thanks,

Scott

Help out other by using the rating system and marking answered questions as "Answered"

-Scott
*** Please rate helpful posts ***

Scott Fella
Hall of Fame
Hall of Fame

So for example...

If you had a 5508.... you can have two ports configured as a primary and secondary port for an interface. 

Port1

     Primary for management

     Secondary for internal vlans

Port 2

     Secondary for management

     Primary for internal vlans

Port 3

     Primary for guest

Port 4

     Secondary for guest

You don't have to use a backup port if you don't want.

Thanks,

Scott

Help out other by using the rating system and marking answered questions as "Answered"

-Scott
*** Please rate helpful posts ***

Thanks for the reply Scott

Could you point me to some docs on how this is done please?

Cheers

Simon

There isn't a doc out there explaining this, since LAG is the prefered method.  Its basically simple... in your interface or dynamic interface, you specify what port is your primary and secondary.

Thanks,

Scott

Help out other by using the rating system and marking answered questions as "Answered"

-Scott
*** Please rate helpful posts ***

I want to add .. If you choose to break out ports. Remeber to TAG all the vlans. Dont dotn native. We had issues with leaking between ports when there was more then 1 native.

__________________________________________________________________________________________
"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
__________________________________________________________________________________________
‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."

"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
___________________________________________________________

The important thing is to only allow the vlans for that port on the trunk..... that usually will solve that issue of seeing the wrong traffic on a different vlan.  Learned from experience:)

Thanks,

Scott

Help out other by using the rating system and marking answered questions as "Answered"

-Scott
*** Please rate helpful posts ***

s.vosper
Level 1
Level 1

THanks guys. I very much appreciate both of your input.

Regards

Simon

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card