09-21-2012 06:01 AM - edited 07-03-2021 10:42 PM
hi All,
I have a head quarters with two WLC5508 anchored to another 5508 on the DMZ. Now we want to roll out wireless guest to the branches with local switching of guest wireless traffic. The guest ssid used at head quarters is anchored to the guest controller and using webauthentication.
Question 1: Can i use the same guest SSID for branch also in this case ?
Question 2 : If i only enable "HREAP local switching" feature on the guest SSID, will the other HQ SSID's still be broadcast in the HREAP branch AP's ?
I am assuming the guest ssid at branch will take IP address from local IP subnet since its local switched, webauthentication will happen on the HQ guest controller ? and once webauth completes, guest SSID traffic will be locally switched . Is this correct ?
regards
Joe
09-21-2012 07:40 AM
Question 1: Can i use the same guest SSID for branch also in this case ?
Yes you can use the same Guest SSID
Question 2 : If i only enable "HREAP local switching" feature on the guest SSID, will the other HQ SSID's still be broadcast in the HREAP branch AP's ?
Yes they will. Unless you use ap groups and define what APs will broadcast what wlan's, the default group will have all SSIDs from WLAN id 1-16
I am assuming the guest ssid at branch will take IP address from local IP subnet since its local switched, webauthentication will happen on the HQ guest controller ? and once webauth completes, guest SSID traffic will be locally switched . Is this correct ?
You don't need to use local switching unless you want to have guest traffic go out to the remote site. If Internet routes out to HQ, then centrally switch the guest SSID. That is what I do unless they have a dedicated guest Internet at each location.
Sent from Cisco Technical Support iPhone App
09-21-2012 07:45 AM
Hi Scott,
Thanks for the info. Yes, webauthentication for the guest ssid happens on the HQ dmz guest controller for hQ guests and same is intended to be used for branch guest access as well. Yes we need to use local swtiching cos we have local adsl connections in branches and dont want to take the data traffic to the HQ.
What will the traffic flow like in this case ?
1. client sends DHCP request and gets IP on locally defined VLAN on the HREAP AP
during this, the controller get to know of the client association via the CAPWAP control message from HREAP AP
2. Client opens browser and enter website address (google.com) and gets the controller webauth login page
is this step happening in the capwap tunnel or outside it ? the TCP communication between client and WLC
3. Client enters username and password for webauth
but the wlc virtual IP is not routed anywhere, so how will the username and password reach the wlc ? (through the capwap tunnel ? )
4. controller checks the username/password eiither locally defined or can be on a nac guest server or ISE ?
if the username/password reaches the controller, it should be able to verify the credentials wtih an external entity like NGS oR ISE ?
regards
Joe
09-21-2012 08:44 PM
1. client sends DHCP request and gets IP on locally defined VLAN on the HREAP AP
during this, the controller get to know of the client association via the CAPWAP control message from HREAP AP
Yes, but the WLC will not get any client data since the traffic isn't going back to the WLC.
2. Client opens browser and enter website address (google.com) and gets the controller webauth login page
is this step happening in the capwap tunnel or outside it ? the TCP communication between client and WLC
This happens all inside the mobility tunnel back to the anchor wlc.
3. Client enters username and password for webauth
but the wlc virtual IP is not routed anywhere, so how will the username and password reach the wlc ? (through the capwap tunnel ? )
The WLC uses it VIP, client doesn't care. If you have a 3rd party certificate, you need to make sure the FQDN is resolvable with the VIP address or you will get a certificate error.
4. controller checks the username/password eiither locally defined or can be on a nac guest server or ISE ?
if the username/password reaches the controller, it should be able to verify the credentials wtih an external entity like NGS oR ISE ?
Well what is hosting the webauth... the WLC or NGS or ISE.... only one can do this and that is what you have to decide.
Thanks,
Scott
Help out other by using the rating system and marking answered questions as "Answered"
10-08-2012 01:14 PM
hi Scot,
i tested it out and it doesnt work like that. The client will only get IP from the HQ DMZ subnet to which that SSID anchored, even though the AP is flexconnect AP and local VLAN configured for the SSID subnet. I think this is expected behaviour ?
regards
Joe
10-14-2012 11:27 PM
dhcp req is always bridged locally for locally switched wlan, Did you configure local switching on both anchor & foreign.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide