03-16-2015 12:10 PM - edited 07-05-2021 02:43 AM
We just purchased 2 controllers 5508 and many CAP3702. I'm searching the option where the AP can communicate directly each other instead using controller port but still be managed by the controller for coolest feature like clean-air....
I follow the formation IUWNE last week and the teacher said " the AP will switch client data traffic locally and perform client authentication locally when their connection to the controller is lost" . That's the option "flex connect" http://www.cisco.com/c/en/us/td/docs/wireless/controller/8-0/configuration-guide/b_cg80/b_cg80_chapter_010001000.html#ID17
thanks for your help.
03-17-2015 04:33 PM
In the "default" deployment method (where the AP's are in "local" mode) all of the client traffic is being tunneld back to the WLC within the data CAPWAP tunnel. Besides this data CAPWAP tunnel there is always a management tunnel which is being used for central authentication, radio resource management and more.
When you put the AP's in "FlexConnect" mode only the management tunnel is active and the client data will be locally switched right after the access-point inteface. Therefor you need configure an trunk interface / tag all the client VLAN's to the AP. Not so long ago you needed to make this settings on every access-point locally which was a very painful thing to do. Nowadays you can use FlexConnect profiles for this, which also allows you to configure local authentication in the case the WLC can't be reached.
Using FlexConnect does have some drawbacks you need to consider (like the moving of MAC address when a user roams, the question how you are going to protect the guest traffic, QoS policies, specific features which are not available and bugs). On the other side is Cisco very active in making more "local" features available for FlexConnect. An example of this is AVC which should be available for FlexConnect in the upcoming 8.1 release (expect for the 2504 WLC) .
I do use FlexConnect a lot because of the local breakout of user traffic, but the main reason is the virtual WLC which we deploy a lot lately (in all kind of environments / use-cases). With this WLC you don't have a choice and you must run FlexConnect.
05-28-2015 10:37 PM
I follow the formation IUWNE last week and the teacher said " the AP will switch client data traffic locally and perform client authentication locally when their connection to the controller is lost"
That's the option "flex connect"
Hi,
That is correct that feature is called flex connect, how to can configure the flex-connect refer the below link
https://supportforums.cisco.com/document/98646/wireless-lan-flexconnect-configuration-example
06-01-2015 10:05 AM
Yes possible in Flex mode [old name reap, hreap] . check the following guide.
https://supportforums.cisco.com/document/98646/wireless-lan-flexconnect-configuration-example#sthash.RPpia90Y.dpuf
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide