07-16-2025 12:19 AM
Hi all,
I’m working with a Cisco 9115AXI AP in FlexConnect mode and need to deploy two SSIDs:
Guest (central switching, tunneled via CAPWAP to the controller)
Corporate (local switching)
Is this supported on a single AP?
What I’ve configured:
AP is in FlexConnect mode (Disable Enable local site in the Site Tag)
Two WLAN profiles: • Guest: “Central Switching” enabled • Corporate: “Local Switching” enabled with the VLAN 8 (corporate) mapped to Corporate SSID.
The switch port is trunking with allowed VLANs 10 (Guest) and 8 (Corporate). The native is the MGMT VLAN (1).
Does this work?
Thx
07-16-2025 12:45 AM
hello @assimkoonk. Yes, ur setup is supported. In FlexConnect mode, a single Cisco 9115AXI AP can broadcast multiple SSIDs with different switching modes. Having a Guest SSID using central switching (tunneled via CAPWAP to the controller) and a Corporate SSID using local switching (mapped to VLAN
Ur switch port config looks correct, trunking VLANs 8 and 10, with native VLAN 1 for management. Just make sureur FlexConnect VLAN mappings are properly set and that DHCP is reachable: Guest clients should get IPs from the central DHCP (via the controller), and Corporate clients from a local scope on VLAN 8. If the CAPWAP tunnel is stable and your VLANs are properly routed and allowed, this should work fine. AND IF U CAN SHARE WITH ME MORE CONFIGS MAN, WE CAN DIVE DEEPER ...
Here are some helpful references:
hope it helps G
-Enes
07-16-2025 12:49 AM
and i forgot this lol: for the 9115AX: https://www.cisco.com/c/en/us/td/docs/wireless/access_point/9115ax/quick/guide/ap9115ax-getstart.html
07-16-2025 02:05 AM
Yes AP support two SSID one local and other central authc.
But
Guest ssid make it local switching- central authc (CWA)
Corporate ssid make it central switching- central authc
Traffic of guest handle by AP is more better that handle by wlc
MHM
07-16-2025 05:38 AM
@assimkoonk
1. Yes you can mix and match centrally and locally switched WLANs on a Flexconnect AP.
2. You say: "The switch port is trunking with allowed VLANs 10 (Guest) and 8 (Corporate). The native is the MGMT VLAN (1)."
But if Guest is centrally switched then it will go to WLC over CAPWAP on VLAN 1 so you should not configure VLAN 10 on the AP switch port - it will be switched onto VLAN 10 on the WLC.
3. @MHM Cisco World says you should locally switch your Guest WLAN but that really depends on your network design and requirements. If the site is remote and the internet access for guest is at the WLC then centrally switched is the correct way to go. If you wanted to do local guest internet breakout at the site then locally switched might be appropriate.
07-16-2025 03:08 PM
Wlc usually in DC' and corporate user usually need to access server in DC' thar why I prefer it central switching
Guest is only try access internet which no need to tunnel it traffic to wlc in DC' instead we can routing it directly by AP in branch to access internet.
This my opinion' as you mention it up to him.
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide