04-27-2012 12:33 AM - edited 11-18-2020 02:58 AM
FlexConnect is a wireless solution for branch office and remote office deployments. Prior to WLC Release 7.2, FlexConnect was referred as Hybrid REAP (HREAP). Now it is called FlexConnect.
FlexConnect feature enables customers to configure and control Access Points through a wide area network (WAN) link without deploying a controller in each branch office. The FlexConnect access points can switch client data traffic and perform client authentication locally when their connection to the controller is lost. When they are connected to the controller, they can also send traffic back to the controller. In the connected mode, the FlexConnect access point can also perform local authentication.
FlexConnect is supported on the Cisco Aironet 1130AG, 1140, 1240, 1250, 1260, AP801, AP802, AP3550, and Cisco Aironet 600 Series OfficeExtend Access Points on the Cisco WiSM, Cisco 5500, 4400, 2100, 2500, and Flex 7500 Series Controllers, the Catalyst 3750G Integrated Wireless LAN Controller Switch; the Controller Network Module for Integrated Services Routers.
FlexConnect (previously known as Hybrid Remote Edge Access Point or H-REAP) is a wireless solution for branch office and remote office deployments. It enables customers to configure and control access points in a branch or remote office from the corporate office through a wide area network (WAN) link without deploying a controller in each office. The FlexConnect access points can switch client data traffic locally and perform client authentication locally when their connection to the controller is lost. When they are connected to the controller, they can also send traffic back to the controller. In the connected mode, the FlexConnect access point can also perform local authentication.
Figure shows a typical FlexConnect deployment.
text box.
ID text box
Choose MONITOR > Clients or MONITOR > Summary to verify whether the clients are getting associated to the Flexconnect AP.
Cisco Wireless LAN Controller Configuration Guide - Configuring FlexConnect
Cisco WLC Configuration Guide, Release 7.5 - Configuring FlexConnect
Hi,
can i have a locally switched VLAN gateway to a local internet connection in a branch?
Hi Joseph
Yes, that's what I used the feature for.
Any way to set the AP flexconnect parameters for all the AP's, or do you have to hit each one individually?
Great document, I do have a question about this part:
Select the VLAN Support check box and enter the number of the native VLAN on the remote network (such as 100) in the Native VLAN ID text box.
This Native VLAN that I define here on the 5508 WLC at the corporate site this would be the native VLAN of the remote site not the Corporate site correct?
FlexConnect group what is that for exactly?
Also 5508 supports 100 AP groups and 25 AP's per group so that equates to 2500 AP's however max AP support on 5508 is 500 AP's. Can someone confirm what is the exact number?
Hi there,
Configuration it seems not so complicated, I am goint to implement it next wednesday on the remote office, on the central office they have a virtual WLC with the latest release 7.6.100. reading this document, I get a little doubts,
1.- If the AP is on remote office, How can I tell to the AP that look for virtual WLC that is on central office to get registered? if the AP look for VWLC locally (making broadcast that no pass over the WAN link).
2.- How the virutal WLC will know that the native vlan specified (for the AP) on this configuration example is across the WAN link?
3.- What considerations we neet to take making reference to routing (on switch core of the remote office, radius servers and certificates)
4.- We need to create interfaces on the virtual WLC?...
Thanks a lot for yor inputs. I will apreciate so much.
Hi guys, I have an issue on flexconnect with remote site. we are extending our ssid's to remote offices.
the int used while making the ssid flexconnect was management int which is in vlan 116. in the remote office we need to make vlan mappings for guest. in the remote site our native vlan is 1 and after completing the vlan mapping for guest and ssid network for employees with native vlan 1,the users are unable to obtain ip address from the dhcp server thru wireless.
the local lan vlan is in vlan 1 and the ap's also have management address fro the same vlan.
Thanks
Hi guys, I have an issue on flexconnect with remote site. we are extending our ssid's to remote offices.
the int used while making the ssid flexconnect was management int which is in vlan 116. in the remote office we need to make vlan mappings for guest. in the remote site our native vlan is 1 and after completing the vlan mapping for guest and ssid network for employees with native vlan 1,the users are unable to obtain ip address from the dhcp server thru wireless.
the local lan vlan is in vlan 1 and the ap's also have management address fro the same vlan.
Thanks
Dear,
Thank you for the same. I just want to know whether we can do guest authentication(time based access) for the users on AP at remote site and after authetication internet access should go via local gateway?
Please share any guide.
Thank You,
Abhisar
it is not working on my case. when i do a show client detail it still gets VLAN36 instead of VLAN 100
Session Timeout.................................. 1800
Client CCX version............................... 4
Client E2E version............................... 1
QoS Level........................................ Silver
Avg data Rate.................................... 0
Burst data Rate.................................. 0
Avg Real time data Rate.......................... 0
Burst Real Time data Rate........................ 0
802.1P Priority Tag.............................. disabled
CTS Security Group Tag........................... Not Applicable
KTS CAC Capability............................... No
WMM Support...................................... Enabled
APSD ACs....................................... BK(T/D) BE(T/D) VI(T/D) VO(T/D)
Power Save....................................... ON
Current Rate..................................... m7
Supported Rates.................................. 1.0,2.0,5.5,11.0,6.0,9.0,
............................................. 12.0,18.0,24.0,36.0,48.0,
............................................. 54.0
Mobility State................................... Local
Mobility Move Count.............................. 0
Security Policy Completed........................ Yes
Policy Manager State............................. RUN
Policy Manager Rule Created...................... Yes
--More-- or (q)uit
Audit Session ID................................. 0a0501040000000455a56de3
AAA Role Type.................................... none
Local Policy Applied............................. none
IPv4 ACL Name.................................... none
FlexConnect ACL Applied Status................... Unavailable
IPv4 ACL Applied Status.......................... Unavailable
IPv6 ACL Name.................................... none
IPv6 ACL Applied Status.......................... Unavailable
Layer2 ACL Name.................................. none
Layer2 ACL Applied Status........................ Unavailable
Client Type...................................... SimpleIP
mDNS Status...................................... Disabled
mDNS Profile Name................................ none
No. of mDNS Services Advertised.................. 0
Policy Type...................................... N/A
Encryption Cipher................................ None
Protected Management Frame ...................... No
Management Frame Protection...................... No
EAP Type......................................... Unknown
FlexConnect Data Switching....................... Local
FlexConnect Dhcp Status.......................... Local
FlexConnect Vlan Based Central Switching......... No
FlexConnect Authentication....................... Central
--More-- or (q)uit
FlexConnect Central Association.................. No
Quarantine VLAN.................................. 0
Access VLAN...................................... 36
Local Bridging VLAN.............................. 36
I hope this isn't a stupid question. But can someone decode this sentence in step 8:
The controller can be configured for FlexConnect in both centrally switched and locally switched WLANs.
Isn't FlexConnect = Locally Switch? Or is that just saying FlexConnect APs can have centrally Switched WLANs?
Thanks,
Nick
Hi,
You can select local or central switching per ssid.
See link:
https://supportforums.cisco.com/discussion/12317706/understanding-flexconnect-local-vs-central-switching-and-wlc-failover-scenario
Hope it helps
Hi ,
is it possible from prime or solar-wind to validate all SSID's VLan mapping from Prime ?
I have couple of Flext connect enabled access points which are configured with 6/7 SSID's each SSID has different Vlan.
so for verification, is it possible to compare VLAN mapping for all Ap with a specific Access point.
can we use flexconnect local switching by don't enable vlan support at APS ?
Just asking another FlexConnect question since we are on the topic:
I have 5 sites with their own WLC 5508 controller. I will like to use FlexConnect to downgrade to only one WLC that provides for LAPs in all 5 locations. The question is, what happens to the communications between the AP's and the WLC? WIll they all go through the MPLS backbone? I am concerned that these chatty communications between the WLC and the AP's will bogg down the MPLS network.
But how should be configured port on the switch to which the controller is connected?????
For example, we install WLC 3504 in main DC, but all APs is located in remote offices. If i understood correctly, port on the switch to which WLC 3504 is connected in this case must be configured like "access" port, for one vlan only - management vlan for wifi in DC?
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: