The purpose of this tech note is to enable correct and successful converged access deployment for Branch deployment.
It is very crucial to have a right design foundation before you deploy converged access
5760 WLC running in centralized mode is NOT converged access.
Incorporate all best practices config below to ensure there are no surprises in terms of functional issues
Decide on the correct code version depending on the feature set the customer requires. Software versions 3.3.5, 3.6.2aE and 3.7.1 (upcoming) are the codes to consider depending of the feature set requirements. Also, these versions may change when future maintenance releases come out.
Below is a overview of branch wireless deployment models
Comparison between traditional branch wireless deployment and Converged Access architecture
Building the right architectural foundation
Note: as you see above it is important to break away from the traditional method of deployment (one wireless vlan across the entire deployment). Recommended option is to have different client vlans per MA/MC (3850 and 3650). For roaming across switches, the default sticky anchoring feature automatically creates anchor / foreign pairs which aids in seamless roaming where client retains if ip address across roams. Even in case where sticky anchoring is disabled, there will be layer 3 roaming established which achieves seamless roams. Latency will not be a concern here as we are talking about branch deployment here where we would typically have 2-3 3650/3850 converged access switches.
Typical Branch network deployment (Small and Large branch networks)
Above figure shows both small and large branch networks
Typically for a branch deployment the average number of APs range from 50-150 APs and client count ranges from 1000-2000 clients
Depending on the size of the deployment, build basic blocks and expand as needed.
As shown on the figure on the left, you can use 2-4 MA (3650/3850) and a single MC (3650/3850, single sub domain) per building. A single Switch Peer group (SPG) is sufficient per MC
If the size if large than above point, you can just replicate the above design into 2 such sets or more (figure on the right)
Typically at the branch sites each building has non-contiguous RF hence there is no need to build mobility peering between MCs. Mobility peering is only needed in cases where there is contiguous RF between buildings where seamless roaming is required.
Typically for such a deployment you DO NOT need a standalone controller (5760) for AP and client management
It is still recommended to use a GUEST Anchor controller like a AireOS 5508 WLC across WAN (at a central location) for guest users (central webauth using ISE)
Best Practice Configuration
Note: the below configs are tried and tested on multiple deployments and it simply justWORKS. You can simply tweak the configs per customer topology and quickly bring up the network. If for some reason there is a glitch, please leave a comment and we will fine tune the recommendations.
Create necessary VLANs (management, clients and guest)
DHCP Snooping and ARP inspection: Enable DHCP snooping and ARP inspection on the guest VLAN. Configure L2 trunk connected to the network as trusted for ARP inspection and DHCP snooping
Security: Convert relevant authentication commands on the access switches to their Class-Based Policy Language (CPL) equivalents.
Note: this command permanently converts the legacy configuration on the switch to identity-based networking services. On entering this command, a message is displayed asking for your permission to continue. Please permit the conversion.
Wireless Management Interface Config
Mobility Config (Guest Anchor Controller)
Mobility Config (Branch switch)
Enable Fast SSID change
wireless client fast-said-change
Note: You add build advanced features set on top of these configs as per deployment needs.
Use of Cisco Prime Infrastructure workflow (use of templates to deploy multiple branch network within a few minutes) - Branch deployment Automation
Cisco PI 2.2.1 (and above running) Wireless Tech Pack 1.0.0 introduces templates for converged access (Small and Large network templates) which enables deploying converged access network with just a few clicks across multiple locations (if needed) at the same time.
This is what Cisco book says about PAC phases:.....Phase 0: The PAC is generated or provisioned and installed on the client Phase 1: After they authenticate each other, they will negotiate a TLS tunnel....What will be installed on the client in phase...
I have checked the telnet / ssh function in the global settings. And global configuration is selected in the AP's advanced configuration page. Now I can ssh to all APs successfully , but I cannot telnet to all APs. The network between ...
So I have been given one of these after a store upgrade that I've been working on, Im quite IT literate and I can console into devices but without guidance this is where my knowledge stops, I want to use this AP for home use, when I plug it in, I get a co...
I have new 1830 with Mobility Express ver 8.10.121 installed CABLINGPC > POE Adapter (no switch) > AP1830all using straight ethernet cablePC Ethernet IP: 192.168.1.101AP IP: 192.168.1.201 PROBLEMS:1. After configuration, no SSID appe...