cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4811
Views
5
Helpful
4
Replies

CAPWAP Though NAT (AP Side and Controller Side)

rgreville666
Level 2
Level 2

Hi,

I’m working on a design at the moment where the customer runs a Zero Trust model, The customer has multiple sites with no WAN. All traffic is Internet based towards there cloud provider where they run SAML aware proxies to permit access to their applications. They are cloud heavy and have no on-prem services.


Meraki works well for them to provide untrusted WiFi access, however we have a situation where I need to run Aireos /IOSXE on one of the sites due to the high density and feature requirements.


Is it possible for the AP to be behind NAT (option 43 on the router pointing towards a Public IP) and in the cloud environment NAT the Public IP to the MGMT interface of the controller, controller configured for FLEX (9800 Controller).

 

I’ve tested this and can see in the DTLS packet the controller is returning its real address and hence the AP doesn’t register as it doesn’t have routing access to the RFC1918 address the controller is on.


Thanks

4 Replies 4

patoberli
VIP Alumni
VIP Alumni
Not sure if this is possible. Is the AP for OEAP configured? That is in the AP configuration under FlexConnect and named "Enable OfficeExtend AP" (at least on the 8.5.x code for the 5520).
Have you configured the public facing IP address on the AP under High Availability (plus the WLC name as configured under Controller -General - Name).
If that doesn't work, you probably need a VPN between the sites, but I think it should work.

Also check this: https://community.cisco.com/t5/other-wireless-mobility-subjects/wlc-nat-feature-problem-for-oeap/td-p/2632340

Hi, Thanks for the reply. This is on a 9800 IOSXE controller.. I think this is what im looking for.. "config network ap-discovery nat-ip-only" I can't seem to find that on the new controller.

 

Thanks

 

 

 

In that case, I suggest to open a TAC, the 9800 platform is still very new and doesn't yet have all features of the AireOS controllers.


https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/release-notes/rn-16-10-9800.html

------------------------------
Please click Helpful if this post helped you and Accept as Solution (drop down menu at top right of this reply) if this answered your query.
------------------------------
TAC recommended codes for AireOS WLC's   and   TAC recommended codes for 9800 WLC's
Best Practices for AireOS WLC's,   Best Practices for 9800 WLC's   and   Cisco Wireless compatibility matrix
Check your 9800 WLC config with Wireless Config Analyzer using "show tech wireless" output or "config paging disable" then "show run-config" output on AireOS and use Wireless Debug Analyzer to analyze your WLC client debugs
Field Notice: FN63942 APs and WLCs Fail to Create CAPWAP Connections Due to Certificate Expiration
Field Notice: FN72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Required
Field Notice: FN72524 IOS APs stuck in downloading state after 4 Dec 2022 due to Certificate Expired
- Fixed in 8.10.196.0, latest 9800 releases, 8.5.182.12 (8.5.182.13 for 3504) and 8.5.182.109 (IRCM, 8.5.182.111 for 3504)
Field Notice: FN70479 AP Fails to Join or Joins with 1 Radio due to Country Mismatch, RMA needed
Field Notice: FN74383 APs Running 17.12.4/5/6/6a May Run Out of Flash Space Preventing Upgrades
How to avoid boot loop due to corrupted image on Wave 2 and Catalyst 11ax Access Points (CSCvx32806)
Field Notice: FN74035 - Wave2 APs DFS May Not Detect Radar After Channel Availability Check Time
Leo's list of bugs affecting 2800/3800/4800/1560 APs
Default AP console baud rate from 17.12.x is 115200 - introduced by CSCwe88390
Review Cisco Networking for a $25 gift card