cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
935
Views
10
Helpful
4
Replies

1 SSID to connect to a specific VLAN based on where the AP is located.

WhyFi
Level 1
Level 1

Hello,

 

I just wanted to know if this is possible or not.

 

Current situation:

We have a building with multiple floors.

Each floor has his own VLAN.

And all floors have multiple Cisco APs that connect to our Cisco WLC.

The APs broadcast an SSID and when you connect, you are on the VLAN for the Wifi.

So we have a VLAN for each floor + a Wifi VLAN that is the same on all floors.

 

What we want:

For the Wifi I would also like to create a VLAN per floor.

That way I don't have to create a /23 or /22 network specifically for the Wifi.

And we also know on which floor the user is located based on the IP.

But I don't want to create a different SSID for each floor.

 

My question:

Is it possible to use 1 SSID and assign the users to different VLANs based on which AP they use to connect to?

 

I have looked into interface groups, but that just seems to use round-robin to assign an IP. Unless I'm not seeing something?

 

 

 

1 Accepted Solution

Accepted Solutions

In wired world, what you are trying to do make sense. (different vlan for each floor). In wireless world it dose not make sense. Even you want to assign different vlan for each floor for wireless, you can't achieve it.

 

In wireless, once you assign an IP client will keep that IP, even if you roam to another floor (this is to facilitate seamless roaming & not to disturb ongoing client sessions). Therefore client will get IP from where they first associate to your network (most of time floor 1 of a given building). Once that happen & client move to floor 2 , 3 (as long as WiFi coverage is there on his roaming path), still he gets floor 1 assigned IP.

 

Therefore, in wireless world it make sense to have larger subnets (some time across multiple buildings, if they are nearby & client can roam from one building to another without dropping their wireless session)

 

HTH

Rasika

*** Pls rate all useful responses ***

View solution in original post

4 Replies 4

Deepak Kumar
VIP Alumni
VIP Alumni

Hi,

 

The first option is to configure AP in the different group.  this will make possible to have different subnets using the same SSID is to configure access points into different AP Groups which are linked to different subnets, that is doing it on a per-AP basis rather than per user basis. There is some limitation as 50 on 2500 series WLC.

https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-5/configuration-guide/b_cg75/b_cg75_chapter_01011011.html

 

 

Second way:  if there is a dynamic VLAN assignment on the authentication server. You associate the SSID to the management interface and the trunk 10 (All floor WIFI VLANs) dynamic interfaces to the WLC. The authentication server passes the interface name back to the WLC which maps clients to different VLANs on the wired network.

https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-vlan/71683-dynamicvlan-config.html

 

Regards,

Deepak Kumar

 

 

 

Regards,
Deepak Kumar,
Don't forget to vote and accept the solution if this comment will help you!

In wired world, what you are trying to do make sense. (different vlan for each floor). In wireless world it dose not make sense. Even you want to assign different vlan for each floor for wireless, you can't achieve it.

 

In wireless, once you assign an IP client will keep that IP, even if you roam to another floor (this is to facilitate seamless roaming & not to disturb ongoing client sessions). Therefore client will get IP from where they first associate to your network (most of time floor 1 of a given building). Once that happen & client move to floor 2 , 3 (as long as WiFi coverage is there on his roaming path), still he gets floor 1 assigned IP.

 

Therefore, in wireless world it make sense to have larger subnets (some time across multiple buildings, if they are nearby & client can roam from one building to another without dropping their wireless session)

 

HTH

Rasika

*** Pls rate all useful responses ***

Thanks for the replies! Very informative.

I'm going to take the easy way of creating a larger subnet for the Wifi.

The hassle of dynamic vlan assignment look interesting, but not worth it.

 

the option not presented yet is to switch the AP from local mode to flexconnect mode.

in flexconnect mode the AP does not tunnel ALL data to the controller, where the controller puts in on a vlan

but can direct the AP to drop the packets on a local vlan (local to the switch it is connected to.

 

but I don't say this solves all your problems!

because the client moving from one floor to another may NOT decide to switch to an AP on the new floor.

Review Cisco Networking for a $25 gift card