01-19-2023 10:55 AM
Hi Community,
We want to design a workaround when APs in a plant continues working when the WLC and VLAN CAPWAP goes Down.
Now, the AP switchport is in mode access and AP works in mode local.
We need to keep one SSID associated to one VLAN UP when the WLC goes down.
Could we put the AP on Flexconnect with central switching? This will have the clients keep connected to SSID?
There are others Solutions ?
Thanks for all
01-19-2023 10:47 PM
- Yes , you can do that and or FlexConnect is designed for that purpose ,
M.
01-29-2023 06:57 AM
> Could we put the AP on Flexconnect with central switching?
No - central switching only works when the AP is connected to the WLC. You could keep your primary SSID configured that way and maybe have a backup SSID which is configured for flex local switching which will remain working when the AP loses connection to the WLC. Obviously you need the local switching VLAN configured on the local switches where the AP is plugged in with appropriate DHCP, routing etc to support those clients. And the switch port obviously needs to be configured as a trunk port with the current access vlan configured as the switchport native vlan.
01-29-2023 07:19 AM
Hi
Central switch rely on the WLC. In a scenario where you lost the WLC, central switching can not help you. You need Local switching. For Local switching and AP interface in trunk with switch can get you some flexibility. However, when the controller went down, the SSID will continue to serve only already connected clients, new clients will not be able to joing as the WLC will not be there to handle authentication request.
https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/flexconnect.html
01-29-2023 12:35 PM
> new clients will not be able to joing as the WLC will not be there to handle authentication request.
That's not entirely true @Flavio Miranda - as per the link you provided local auth SSID can continue to work without WLC. That would most often be WPA2-PSK but can also be 802.1x if there is a radius server local to the APs which can provide the authentication. It's also possible to use 802.1x central auth by default in connected mode with fallback to local radius in standalone mode. The local radius is configured in the flex profile.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide