cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1071
Views
0
Helpful
9
Replies

Local breakout

frederick.mercado
Spotlight
Spotlight

Hi, fairly new to advanced networking. 

 

We have a two 9300 core L3 switches, and a new WLC 9800. We have a MOBILE SSID that we have apple devices connect to, but we do not want them clogging up our MPLS and instead go to a local internet breakout. 

 

Any ideas?

 

9 Replies 9

I may misunderstood the requirement but you can use flexconnect SSID dor Apple device. This way, Apple device´s traffic will be droped on the local network and then you device if you will route it to the internet or only local netwok. 

Our devices are already connected via flex and SSID. We just need to get them out to a local breakout (internet). While still maintaining internal VLAN communication.

That´s depends how your internet gateway works.

 

 If you L3 switch send traffic to a firewall, you need to create a route on L3 switch sending to firewall using as source the network  10.74.126.x and destination the firewall. On the firewall you need to permit the network  10.74.126.x and create a NAT. 

 The same thing for a router.  

In this case site required different subnet for that site, and make a PBR or NAT rule going out to HQ or Know subnet use you MPLS, unknow send them to Internet, is this what you looking to do ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Yes. Currently our setup is as follows:

 

Hello,

 

I am not really clear on what 'MPLS and instead go to a local internet breakout' means in your case. Can you post the configuration of (I assume it has to be the core switch(es) the device(s) that are directly connected to the 'local Internet breakout) ? A topology drawing would even be better.

 

Either way, if the clients you want to route out locally are all in Vlan 126, policy based routing might work.

Haydn Andrews
VIP Alumni
VIP Alumni

So if the WLC is not local to the APs and you want to use a local internet break out you would need to use flexconnect for the SSID

*****Help out other by using the rating system and marking answered questions as "Answered"*****
*** Please rate helpful posts ***

We are trying to just configure a way for a local breakout. We considered PBR for http/https protocol, but it seems that maybe creating a internet VLAN and allowing inter VLAN routing may be best? Unless there is a way to route internet traffic, essentially split tunneling or splitting traffic on the WLC itself?

JPavonM
VIP
VIP

If your WLC is local to the site, you can configure differnt VLANs per physical port on the C9800 side and map MOBILE SSID to that VLAN so you can split traffic into a different Internet router. Or you can configure VRF's to enhance security.

If your deployment is with remote Flexconnect APs and central C9800, then follow this guide.

Review Cisco Networking for a $25 gift card