cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1503
Views
5
Helpful
9
Replies

Flexconnect Local Switching

Ermir Morina
Level 1
Level 1

Greetings Community,

 

Is there any way for traffic to failover to local network after the connection to WLC fails.

Right now I have Central Authentication with Local Switching and when i shut down the connection from WLC to AP the hosts that are already authenticated continue working just fine, but I cannot authenticate new users.

 

Looking forward to your replies!

 

Kind regards,

Ermir.

9 Replies 9

Arshad Safrulla
VIP Alumni
VIP Alumni

You can do local authentication, local switching. In this case irrespective the AP is connected mode or standalone mode flex AP will take care of authentication and switching.

please keep in mind the information made available to the controller will be limited in this case even when the AP is in connected mode.

depending on the platform (aireos or catalyst) config will change, you may refer to the config guides. If the correct platform info provided we may be able to guide you.

Hello @Arshad Safrulla

I was wondering if you can do mac filtering on access points (local switching), because our current setup is a central auth (Local WLC database Mac Filtering + PSK) and local switching? (We have WLC3504 with Air1815i APs on remote sites)

Arshad Safrulla
VIP Alumni
VIP Alumni

With AireOS for sure you can do PSK, but if you need MAC filtering you need to have a local radius server and use wpa2-enterprise. 

I haven't done any local auth local switch deployments yet with 9800, so I can't be certain whether the above theory applies to 9800.

Yes, but will that allow me to use that authentication method as a failover method if my authentication towards my Central WLC fails?

Arshad Safrulla
VIP Alumni
VIP Alumni

yes, Normal authentication is done centrally, On occasion when WLC is not reachable, AP authenticates new clients with locally defined ISE server under FC group.

So what you are saying is I have to configure the flexconnect group and enable Local Auth on the FC group and add my ISE server, and that will allow me on cases when Central Auth (WLC Mac Filtering) isn't reachable it will switch to the ISE Server?

Also there will still be another problem because my ISE Server and the WLC are on the same central site and are reached through the same routes and connections, so once the WLC is down (I mean on cases when I won't probably have VPN connection to my Central Site) ISE will be down too and I will also lose that failover authentication too.

 


@Ermir Morina wrote:

So what you are saying is I have to configure the flexconnect group and enable Local Auth on the FC group and add my ISE server, and that will allow me on cases when Central Auth (WLC Mac Filtering) isn't reachable it will switch to the ISE Server?


Yes, you need to add each AP as a network device and configure the required Radius policies

 


Also there will still be another problem because my ISE Server and the WLC are on the same central site and are reached through the same routes and connections, so once the WLC is down (I mean on cases when I won't probably have VPN connection to my Central Site) ISE will be down too and I will also lose that failover authentication too.


Yes in that case this will not work, you may have to deploy a PSN node in the branch.

Wouldn't enabling local authentication on access points ruin the functionality of central authentication? 

And also does creating local users on APs and also enabling local authentication allow this setup to work and to function as a authentication failover method ( after my connection to the WLC is shut ) without any problem? 

 

Thanks a lot for the discussion and your prompt replies, I am so grateful.

 

Idea of this is that as long as the ISE is reachable from the remote site wireless users will authenticate centrally.  if you have a PSN in the remote site itself, then clients will authenticate against it even when the WAN is down.

ok I just verified this on my LAB. When you have local ap local auth enabled and radius servers configured under FC group AP will directly speak to the ISE for AAA services. (AP is the NAD not WLC) irrespective AP is connected or standalone.

When the AP lcoal auth is not ticked WLC is authenticating the client against ISE when WLC is reachable to the client (connected) and when the WLC is not reachable (standalone) AP is authenticating the client to the local ISE.

So to answer your first question, this is a design decision where you have to consider all the pros and cons and do the design accordingly. As for your second question, yes creating local users will help you to have a failover mechanism. But if you are worried about security, recommendation would be to have a local PSN at the site.

Review Cisco Networking products for a $25 gift card