cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Who Me Too'd this topic

Flexconnect VLAN Based Central Switching

john.gregory
Level 1
Level 1

Hi,

 

I am new to Wireless networks and a I have some clarifications.

 

I have a scenario wherein my client needs to upgrade to a new WLC 5520. They have a two sets of 5508 WLC. One pair is configured for HQ office and another pair is for Remote Sites. HQ APs are pointed to HQ WLC and Remote APs to REMOTE WLC.

 

HQ is setup as LOCAL MODE (central switched)

REMOTE is setup as FLEXCONNECT (local switched)

 

HQ and REMOTE WLC have the same SSID for the sake of this post let just say the SSID is "WLAN_NAC". WLAN users are authenticated through a NAC appliance and NAC will dictate based on policy which vlan they will belong. This WLAN "WLAN_NAC" is associated to the WLC management interface.

 

However, based on their current setup they have few dynamic vlan interfaces configured but it's not associated to any WLAN. Does this mean the WLC is not using this interfaces?

 

I am studying on what would be the best approach for migration. Below are my queries and clarifications.

 

1. Is it possible to maintain the same "WLAN_NAC" SSID

2. Enable AAA Override, Flexconnect Local Switching and VLAN Based Central Switching on "WLAN_NAC"

 

Traffic Flow:

a. HQ user will connect to  WLAN_NAC ssid after it passed the NAC posture check, NAC will assign the user to vlan 231 and will be centrally switch.

b. Remote user will connect to WLAN_NAC ssid after it passed the NAC posture check, NAC will assign the user to vlan 250 and will be local switch.

 

3. Create a flexconnect group for Remote Sites and configure AAA VLAN ACL Mapping. Map the vlan 250 for local switching.

 

4. Create a flexconnect group for HQ, but no AAA VLAN ACL Mapping configuration. If HQ user connects to WLAN_NAC ssid, and NAC assign the user to vlan 250 for example, will it be centrally switched? What IP address will the user gets? is it from VLAN 250 subnet or WLC MGMT Subnet? I read an article that states that, "if vlan is not configured it will use a default vlan" what is the default vlan?

 

Thanks in advanced for the time and support.

 

 

Who Me Too'd this topic