04-01-2025 11:09 PM
Hi All,
We're about to upgrade our WiFi network architecture. Currently we have a Foreign/Anchor setup for direct internet access. Is this the current Cisco recommended architecture? A colleague has suggest a new architecture removing the Anchor and running a GRE tunnel from the Foreign controller to the external firewall. Is this a recommended design in an Enterprise network?
Any URLs you know of regarding WiFi architecture would be greatly appreciated.
Thanks in advance for taking the time to reply
04-02-2025 06:45 AM
I wouldn't say there are recommendations except for "how you want to delivery the guest traffic withouth touching any other part of your network." Guest anchors work fine and are pretty easy to deploy if you have the budget for them. GRE, VRF, etc. being able to tunnel guest traffic from a site to another location for internet egress is another option. At time, if the site has a local egress, you don't need either and can just send traffic out the foreign controller to a vlan that is dedicated to that local internet egress. You design it the best way that you can afford and your team can support.
04-02-2025 07:32 AM - edited 04-02-2025 07:41 AM
This is the official Cisco Design Guide:
https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/cisco-campus-lan-wlan-design-guide.html#Guestwireless
It suggests the anchor design or local direct internet access - as Scott has also suggested - so it's really down to your own requirements/preferences. Sometimes it just comes down to company policy about how guest traffic is handled where insistence on anchor design seems to be much less prevalent these days as the security folks have started to trust/accept that VLANs really do keep traffic effectively separated.
ps: If you decide you want to go for an EoGRE solution (or just want to understand it) then refer to:
https://www.cisco.com/c/dam/en/us/td/docs/wireless/controller/9800/17-2/deployment-guide/c9800-eogre-deployment-guide-rel-17-2.pdf
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/m_wl_eogre.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide