07-30-2024 09:44 PM
Dear Experts..
Quite a new here.
So I'm looking for a possible deisgn and solution for having two sets of 9800L WLC on both DC and DR site as they serve primary from DC unit and if that one fails, DR unit as secondary fallback for all APs.
I got deployed one SSO pair (two 9800L WLCs) at DC and running smooth. But when we do DC-DR exercises drill, DC site will be shutdown and all APs from all sites (except DC site APs) need to registered to another WLC at DR site.
So, the local vendor told me one SSO at DC and one SSO at DR or one SSO at DC and one standalone WLC at DR will not work the way I want it. Said I have to break my SSO pair at DC and move one unit to DR site as N+1 design.
Is that really true ?!
Is there any better options or design that I can go. I just don't want to break the current deisgn (SSO pair at DC site).
Please help me out.
Thank you all in advanced.
Solved! Go to Solution.
07-31-2024 01:26 AM
>...So, basically SSO at DC and another SSO at DR nor SSO at DC and standalone WLC at DR is not recommended or supported.
There is no problem having 2 SSO's at each site , the DR-SSO playing an N+1 role.
M.
07-30-2024 11:10 PM
If the Layer 2 extended and the latency in limit you can extend the WLC to other site :
SSO Pre-requisites
But the question you mentioned DR So if the whole site failure, then there is no connectivity between DR right ?
You can also break HA and deploy N+1 same above guide give you direction.
Correct SSO HA (should be same place 2 Units) - if you looking DR kind then N+1 is the best options (there are some Limitation you can find in the document).
07-31-2024 12:06 AM
Dear @balaji.bandi ..
Thank you so much for the answer.
The DC and DR sites are connected by Layer3 only. During DC-DR drill exercises whole DC site will be shutodwn and no need to think about APs in DC site. But in other scenario, let's say WLC at DC site fails.. all APs at DC and remotes sites shall connect and registere to WLC at DR site. (This is what we want..)
So, basically SSO at DC and another SSO at DR nor SSO at DC and standalone WLC at DR is not recommended or supported. Then I should go with the option to break current SSO pair at DC site and go with N+1 (standalone unit at DC and standalone unit at DR site) as a best option ?!
Thanks again.
07-31-2024 12:53 AM
Oh.. Sorry I also found this one in the SSO pair guide.
07-31-2024 01:26 AM
>...So, basically SSO at DC and another SSO at DR nor SSO at DC and standalone WLC at DR is not recommended or supported.
There is no problem having 2 SSO's at each site , the DR-SSO playing an N+1 role.
M.
07-31-2024 02:07 AM
07-31-2024 04:04 AM
>....Thank you so much for the answer.
- No problem ; note that when configuring or making configuration changes to 9800 controllers it is always
very useful to validate the (new) configuration with the CLI command show tech wireless and feed the output from
that into Wireless Config Analyzer
(Use the full command as mentioned in green , it does not work with show tech)
M.
07-31-2024 04:59 AM
yes correct your understanding here.
So make a wise decsion to deploying modes.
08-12-2024 08:07 AM
Agreed with Marce - no problem at all with keeping your SSO pair at DC and have either SSO pair or single WLC at your DR site as N+1 backup to the DC. That's exactly what we do to achieve 99.999% availability. We have SSO pair in DC1 and SSO pair in DC2 which are N+1 backup for each other. We put half the APs on each DC so in case of a DC failure only half the APs would have to fail across to the other DC. That also means under normal operation each SSO pair only runs up to 50% capacity which also avoids the problems with 9800 WLCs not performing well under full load as per https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html#designforlargescaledeployments and mentioned on various other posts here.
Remember that you need to keep the N+1 WLC configs in sync manually.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide