10-17-2017 06:59 AM - edited 03-08-2019 12:23 PM
This is a complete newby question but currently we have a virtual WLC located at our main offices controlling 30 APs here as well as controlling APs at two other offsite locations across an MPLS site to site. currently running no vlans but we would like to add our guest network (separate carrier) to the WLC to be broadcast. VLan 50 setup on the main layer 3 switch and WLC right now. this is currently not working as we still get a 10.x.x.x IP from the new guest SSID. what things should we start checking or is this setup even possible currently with only using one WLC for multiple locations?
10-17-2017 07:21 AM
10-17-2017 09:46 AM
10-17-2017 03:15 PM
10-18-2017 07:03 AM
10-18-2017 07:46 AM
Ok thanks.
You don't need the vlan 50 (guest) layer 3 interface on the WLC.
It has to be configured on the switch if you want a local switching SSID.
Here a word doc with few screenshots
10-23-2017 05:16 AM
Those changes made the difference, i can now connect to the guest network and pull a valid IP from our guest network. the only issue I am having now and it may be a small oversight is once i get an IP I cannot get out to the internet. I can see the gateway and log in to the router etc.. but cannot get past it. I am wondering if i have a loop somplace at this point. I attached the output of the two ports
port 42 is the direct connection to our guest network gateway
Port 41 is the port connected to the test AP
C1L3#show running-config in gi1/0/42
Building configuration...
Current configuration : 62 bytes
!
interface GigabitEthernet1/0/42
switchport mode trunk
end
C1L3#show running-config in gi1/0/41
Building configuration...
Current configuration : 39 bytes
!
interface GigabitEthernet1/0/41
end
C1L3#show vlan
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Gi1/0/1, Gi1/0/2, Gi1/0/3, Gi1/0/4, Gi1/0/5, Gi1/0/6, Gi1/0/7, Gi1/0/8, Gi1/0/9, Gi1/0/10, Gi1/0/11, Gi1/0/12, Gi1/0/13, Gi1/0/14, Gi1/0/15, Gi1/0/16, Gi1/0/17, Gi1/0/18, Gi1/0/19, Gi1/0/20
Gi1/0/21, Gi1/0/22, Gi1/0/23, Gi1/0/24, Gi1/0/25, Gi1/0/26, Gi1/0/27, Gi1/0/28, Gi1/0/29, Gi1/0/30, Gi1/0/31, Gi1/0/32, Gi1/0/33, Gi1/0/34, Gi1/0/35, Gi1/0/36, Gi1/0/37, Gi1/0/38, Gi1/0/39
Gi1/0/40, Gi1/0/41, Gi1/0/43, Gi1/0/44, Gi1/0/45, Gi1/0/46, Gi1/0/47, Gi1/0/48, Gi1/0/49, Gi1/0/50, Gi1/0/51, Gi1/0/52
50 guest active
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1 enet 100001 1500 - - - - - 0 0
50 enet 100050 1500 - - - - - 0 0
1002 fddi 101002 1500 - - - - - 0 0
1003 tr 101003 1500 - - - - - 0 0
1004 fdnet 101004 1500 - - - ieee - 0 0
1005 trnet 101005 1500 - - - ibm - 0 0
Remote SPAN VLANs
------------------------------------------------------------------------------
Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
10-23-2017 05:21 AM
10-24-2017 05:45 AM
10-24-2017 02:10 AM
Hello
"get an IP I cannot get out to the internet"
Disable ip routing on the switch as the router is performing the L3 for your guest vlan
res
Paul
10-24-2017 05:44 AM
10-24-2017 10:11 AM
10-24-2017 10:45 AM
10-24-2017 10:57 AM - edited 10-24-2017 10:58 AM
From the client, can you do a traceroute and see the path, at least up to your firewall.
You tried pinging google dns from client as well?
Are there any ACLs for that SSID? or on the switch SVI?
10-24-2017 10:59 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide