ā03-15-2023 01:34 PM
Good day, all,
I require assistance with four questions.
1) Is creating a functional wireless solution using C9800-CL with a single subnet range feasible? The subnet is configured as VLAN 4, which connects the entire organization. There is no management network; the only subnet being used is /23.
2) Can a functional wireless solution be established utilizing C9800-CL with two subnets? One of the subnets is designated for user VLAN. The other VLAN is 22 and not in use.
3) Is it necessary for the AP license to be registered with the controller before the APs can join the C9800-CL controller, or will the APs join the controller first, and then the controller can be licensed?
4) Lastly, is it possible to establish high availability (HA) with either of the first two questions?
I would like to know how I should proceed with these scenarios.
I really appreciate any help you can provide.
Allan001
ā03-15-2023 02:34 PM
I think we all need to better understand what you have to work with and for you to also try to understand the various types of deployments.
ā03-15-2023 03:49 PM
Hi Scott Fella,
Thank you for getting back to me so quickly.
1) To clarify, we are deploying on-premises, and it is a flat network.
2) The High Availability (HA) I am referring to is SSO.
3) Tomorrow, I will verify the model of the Access Points that the customer has purchased. They are new and have been recommended by Cisco to be supported on C9800-CL.
4) The controller code version is 17.6
Allan001
ā03-15-2023 04:47 PM
ā03-15-2023 11:51 PM
Hi Scott Fella,
Thank you for sharing the info.
Please share a brief implementation of the two scenarios with configure examples if possible. Thank you.
Here is how I think I should configure it. Please correct me wherever you see that I am wrong.
a) The first solution with one subnet - if I configure the user VLAN 4 as the wireless management. Thus, users and the wireless management will be using the same subnet. Will this work, and would HA work as well with the same subnet? Or, in this scenario, we would have to advise the customer that HA will not be possible with the current IP plan - we would need additional separate IP ranges. Only after that, we can we then implement HA.
The configuration would be like this:
1) Configure VLAN 4 in the controller.
2) Configure SVI using VLAN 4 in the controller.
3) Configure Gi2 as a trunk and allow the single VLAN4 on that trunk.
4) On the switch where APs are terminated. Configure the ports with APS as access ports and add them to VLAN 4.
Done.
b) 2nd solution with two subnets:
1) Configure the unused VLAN 22 as the wireless management
2) Configure IP Add from VLAN 22 on Gi1 or configure Gi1 as a trunk port and configure SVI in the controller and pass it via Gi1
3) Configure Gi2 as a trunk
4) Configure user VLAN 4 SVI in the controller and pass it via Gi2.
5) On the switch, configure ports facing APs as access ports and add to VLAN4
6) Lastly, will HA work using the wireless management VLAN 22 subnet? Or do we have to add more subnets for HA to work efficiently?
Done.
Kindly advise - if the above implementations are correct or wrong.
I didn't know flex works better than local, so I will go with flex once I have a working solution.
Allan001
ā03-16-2023 12:31 AM
ā03-16-2023 02:02 AM
Hi Scott Fella,
Yes, VLANs can be created but at a later stage due to customer budget. For now, they just want a solution that works with the current setup. Improvements will be done at a later stage.
Thank you,
Allan001
ā03-16-2023 06:20 AM
Yes you could probably make it all work on a single flat network but that really isn't recommended. Don't rush into this and deploy something sub-optimal. It's always more difficult to change things later than deploy them correctly from the start. Go through the best practice guide below carefully then read and watch the many examples and videos on 9800 config which you can find when you search and then plan and design it to suit the needs of the network. Also note the links below for TAC recommended code versions. 17.6 is not a bad choice (17.6.5 is the latest) but it's approaching end of sale https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-xe-17/ios-xe-17-6-x-eol.html so 17.9 (currently 17.9.2, 17.9.3 should be out anytime soon in the next week or two) is the next extended support release which will give much longer lifetime.
ā03-16-2023 07:00 AM
Hi Rich R,
Thank you for your suggestion. I will take your advice and review the URL links for best practices.
Once again, thank you,
Allan001
ā03-16-2023 07:23 AM
So from what I hear is that you will deploy this on a flat network and then later... hopefully the customer can add vlans and setup the wireless to also use those vlans. You need to be specific, because going from a flat network to having many vlans is not an easy thing for a customer to do.
Anyways, with FlexConnect, the port the ap is connected to will be a trunk port with the native vlan being the Ap management. So the initial native vlan will be whatever vlan they are using for their flat network. Implementing a trunk makes it easy later when the wired side has vlans. configured, then you just add the vlans to the trunk that you need and exclude the vlans that are not used for wireless. The controller will just be on the vlan that you have now. You can move that later to a "management" vlan, but that also takes some planning. Since you have a flat network, the ap's and the controller will be on the same subnet, thus the ap's will use a layer 2 broadcast to discover the controller.
It is pretty simple after you do this a few times, but make sure you read the documentation on FlexConnect and the documentation on the installation of the 9800-CL so you don't run into any issues when deploying this on the customer hypervisor.
You will need to be able to explain your implementation and how the implementation can get migrated when vlans get configured.
ā03-16-2023 09:10 AM
Hi Scott Fella,
Thank you so much; I really appreciate your input; it's fantastic! I will definitely read about FlexConnect.
Thank you, once more!
Allan001
ā03-16-2023 09:14 AM - edited ā03-16-2023 09:14 AM
Just make sure you follow the steps for the 9800-CL install. Many skip through some of them and they find out that ap's will not join the controller. So make this a priority and you will be successful. Hope that helps!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide