cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2234
Views
0
Helpful
1
Replies

FlexConnect local authentication & local switching options.

sardarjion
Level 1
Level 1

I have home lab setup where I am trying the FlexConnect mode. I am testing this with one AP first so setup is:

  • RVS 4000 router connected to internet.
  • WLC 2504 v8.5.182 connected to RVS4000 LAN port 1
  • AP 2702 connected to LAN Port 2 of RVS4000

I am trying to establish two things:

  1. Local authentication - WLANs have PSK authentication enabled and I want the clients should authenticate at AP level and not route it to WLC
  2. Only Control messages flow from AP to WLC and back and no actual data because ports are connected to RVS 4000 for routing.

For Authentication I see two options:

sardarjion_0-1675963116950.png

If I select this option in WLAN settings, then I cannot select "Local Client Profiling" option. I want to have that option because it helps monitor all the clients connected. 

Second option is enabled below but seems local authentication is not working. The test I perform is turn off the WIFI from phone and then turn off the WLC and then turn on the wifi on phone again. It tries to connect to the wifi network but keeps asking me for password and even after putting the password it says incorrect password.  

 

sardarjion_2-1675963429540.png

The other setting, I am trying is to make sure all the data traffic doesn't go to WLC and directly to router as AP is connected to router. I am trying to enable this option but it doesn't work.

sardarjion_3-1675963676037.png

 

 

 

 

1 Reply 1

Rich R
VIP
VIP

Flex local auth will only work if you have it enabled - that box must be ticked.
Profiling is done by WLC so you can't have both.
Flex local switching definitely works.  Have you defined the VLAN, configured the AP port as trunk and defined the flex WLAN - VLAN mapping?

If you think flex local auth is not working then capture AP console logs.  When disconnected from WLC it should go to standalone mode and handle the auth locally.  See what the logs are saying.

Review Cisco Networking for a $25 gift card