I have a vWLC and some 3702i's, all running the latest code. This is a small, simplified lab/branch-office type deployment with only a couple of AP's. On the LAN, there is DHCP provided by a Windows host. Everything works fine in FlexConnect mode with local switching. However, if I switch an AP over to Flex+Bridge mode, making no other changes but that, the clients can initially connect and communicate with LAN hosts, but after about 3-5 minutes, they'll drop off and not be able to ping anything except the controller. However, the interface still indicates that it has a valid IP. If I renew the DHCP lease though, it immediately starts working again, for another 3-5 minutes. If I switch the AP back to FlexConnect mode, everything goes back to working correctly. I thought the purpose of Flex+Bridge was that everything would work exactly the same as FlexConnect, but with the ability to connect mesh AP's as well. Has anyone encountered this behavior before, and/or have any idea what I might be missing? Thanks in advance!
... View more
New to FTD...
On other firewalls I've worked on, you could set up a "virtual" IP on the firewall itself that it could then NAT to hosts behind the firewall. I know where to set up the NAT rules using FMC, but where do we set the additional IP (or VIP-equivalent) on the specific interface? BTW, this is a Firepower 4100 running FTD, not an ASA...
... View more