Client on Flex mode can't reach WLC if using same subnet WLC9800.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-17-2025 12:29 AM
Hi,
I am encountering an issue with the AP in Flex mode. When configured to use VLAN 300, it successfully obtains an IP address and operates normally. However, it cannot ping the WLC on VLAN 300 or access the GUI. Conversely, when the client is switched to VLAN 301, everything functions as expected WLC is C9800-L-C-K9 running 17.12.3. Could anyone please advise?
- Labels:
-
Catalyst Wireless Controllers
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-17-2025 12:36 AM
Check if vlan allow in trunk of AP to SW
MHM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-17-2025 12:53 AM
- Have a checkup of the C9800-L-C-K9 configuration using the CLI command show tech wireless
(not a simple show tech) and feed the output from that into Wireless Config Analyzer
M.
-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-17-2025 03:30 AM - edited 01-17-2025 03:35 AM
First, in order for a wireless client to access the WLC GUI, you need to permit.
Configuration > Wireless: Wireless Global > Management Via Wireless: Enable
or CLI
#wireless mgmt-via-wireless
Related to the Vlan300, sounds like you have connectivity issue and it is difficult to say where the problem is as we dont know the topology. If can be firewall, it can be Access List, it can be routing and it can be vlan missing in trunk/port-channel
You need to identify where is the layer3 for vlan 300 and from there, you can try to ping the WLC using vlan 300 as source. Ping will probably fail.
You can use traceroute to see where the traffic stops. You can compare the config from vlan300 with vlan301 on your switches to identify what is different.
WLC does not have routing, so, probably the problem is not on the WLC.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-19-2025 03:22 PM
From the SVI can you ping the WLC? If not then the issue is most likely a firewall/ACL between the SVI and the WLC. Or routing to the WLC
Need topology to understand better, whats different on the wired side between VLAN 300 and 301
*** Please rate helpful posts ***
