The purpose of this tech note is to enable correct and successful converged access deployment for Branch deployment.
It is very crucial to have a right design foundation before you deploy converged access
5760 WLC running in centralized mode is NOT converged access.
Incorporate all best practices config below to ensure there are no surprises in terms of functional issues
Decide on the correct code version depending on the feature set the customer requires. Software versions 3.3.5, 3.6.2aE and 3.7.1 (upcoming) are the codes to consider depending of the feature set requirements. Also, these versions may change when future maintenance releases come out.
Below is a overview of branch wireless deployment models
Comparison between traditional branch wireless deployment and Converged Access architecture
Building the right architectural foundation
Note: as you see above it is important to break away from the traditional method of deployment (one wireless vlan across the entire deployment). Recommended option is to have different client vlans per MA/MC (3850 and 3650). For roaming across switches, the default sticky anchoring feature automatically creates anchor / foreign pairs which aids in seamless roaming where client retains if ip address across roams. Even in case where sticky anchoring is disabled, there will be layer 3 roaming established which achieves seamless roams. Latency will not be a concern here as we are talking about branch deployment here where we would typically have 2-3 3650/3850 converged access switches.
Typical Branch network deployment (Small and Large branch networks)
Above figure shows both small and large branch networks
Typically for a branch deployment the average number of APs range from 50-150 APs and client count ranges from 1000-2000 clients
Depending on the size of the deployment, build basic blocks and expand as needed.
As shown on the figure on the left, you can use 2-4 MA (3650/3850) and a single MC (3650/3850, single sub domain) per building. A single Switch Peer group (SPG) is sufficient per MC
If the size if large than above point, you can just replicate the above design into 2 such sets or more (figure on the right)
Typically at the branch sites each building has non-contiguous RF hence there is no need to build mobility peering between MCs. Mobility peering is only needed in cases where there is contiguous RF between buildings where seamless roaming is required.
Typically for such a deployment you DO NOT need a standalone controller (5760) for AP and client management
It is still recommended to use a GUEST Anchor controller like a AireOS 5508 WLC across WAN (at a central location) for guest users (central webauth using ISE)
Best Practice Configuration
Note: the below configs are tried and tested on multiple deployments and it simply justWORKS. You can simply tweak the configs per customer topology and quickly bring up the network. If for some reason there is a glitch, please leave a comment and we will fine tune the recommendations.
Create necessary VLANs (management, clients and guest)
DHCP Snooping and ARP inspection: Enable DHCP snooping and ARP inspection on the guest VLAN. Configure L2 trunk connected to the network as trusted for ARP inspection and DHCP snooping
Security: Convert relevant authentication commands on the access switches to their Class-Based Policy Language (CPL) equivalents.
Note: this command permanently converts the legacy configuration on the switch to identity-based networking services. On entering this command, a message is displayed asking for your permission to continue. Please permit the conversion.
Wireless Management Interface Config
Mobility Config (Guest Anchor Controller)
Mobility Config (Branch switch)
Enable Fast SSID change
wireless client fast-said-change
Note: You add build advanced features set on top of these configs as per deployment needs.
Use of Cisco Prime Infrastructure workflow (use of templates to deploy multiple branch network within a few minutes) - Branch deployment Automation
Cisco PI 2.2.1 (and above running) Wireless Tech Pack 1.0.0 introduces templates for converged access (Small and Large network templates) which enables deploying converged access network with just a few clicks across multiple locations (if needed) at the same time.
HI The AP3802i used to join the wlc, but now it cannot join. Both ap and wlc can ping each other. Below show logging. Anyone can help to take a look at it? Thank you AP11#show loggingSystem logging:Mar 1 19:02:25 kernel: [*03/01/2021 19:02...
Hi, I'm learning for CCNA exam on real hardware so i just started playing with WLC. I have encountered general problem which doesn't let me go forward. Maybe problem is actually i have this what i have so i have to work on this what i have But to the poin...
Hello, Based on the formula below, dBm 19.979 should be 99.51mW, but a window box in Ekahau shows it is 25mW. Please see the screenshot below. Are there any one who can tell what the issue is? Thank you P(mW) = 1mW ⋅ 10^(P(dBm)/...
Hello,I want to know if it is possible to provide power to a Mesh AP with a power injector like AIR-PWRINJ6, without connecting this to a switch port !Because it is easier to use a Power injector than a Power adaptator is case there is no power outlet nea...
Hello,One of the devices (android phone) on the corporate WLAN is unable to connect.No issues with apple device on the same WLAN and same AP.Message on the phone: time limit reachedDebug message on wlc at the time of connection:debug di*osapiBsnTimer...