09-15-2012 05:35 PM - edited 07-03-2021 10:40 PM
I can't use Officeextend because i'm using vWLC.
vWLC is sitting at DMZ, CAPWAP Data + Control Port allowed in FW.
vWLC is configured with NATted public ip address
3500 AP at other side of internet is associated to vWLC
Flexconnect with Local Switching is doing fine.
I'm having problem with Central Switching, wireless client can see the SSID (open auth) but can't connect.
No logs seen vWLC GUI Monitor > Clients
So I'm thinking if this is possible?
Dave
09-15-2012 05:37 PM
Just to add, latency is 23ms (min) and 90ms (max) from AP to vWLC
09-15-2012 05:40 PM
Well never tried it with the vWLC, but I have tested APs connecting in local mode, FlexConnect and OfficeExtend with no issues using local or centrally switched. What does the client show in the monitor tab? Are they in the run state and in the correct vlan?
Sent from Cisco Technical Support iPhone App
09-15-2012 05:59 PM
No client. Not even attempt.
09-15-2012 06:17 PM
Have you tried it locally with an ap joined with the vWLC instead of over the Internet.
Sent from Cisco Technical Support iPhone App
09-15-2012 06:19 PM
within my local network via Flexconnect mode, yes and its woking properly.
09-15-2012 06:33 PM
Try to issues this command, but your APs does join just an issue with your clients. Have you tested with more than one FlexConnect ap or just one.
config network ap-discovery nat-ip-only disable
Sent from Cisco Technical Support iPhone App
09-15-2012 08:15 PM
Already tried that command.. Enabling and disabling.. Still doesn't work.
I have 3500/3600 AP over the net.
Sent from Cisco Technical Support iPhone App
09-15-2012 07:15 PM
Are you anchoring the SSID to another vWLC or a WLC? You mentioned that the vWLC is in the dmz, so the question is, where is the vlan the centrally switched SSID is mapped to, is it in the dmz.
Sent from Cisco Technical Support iPhone App
09-15-2012 08:26 PM
I have two vWLC, 1 is foreign and the other one is anchor.
But this specific SSID is not anchored.
SSID settings is mapped to VLAN 120 which reside at my core switch. I can ping the gateway of the VLAN120 from my anchor vWLC.
I have another 1131 AP terminated locally (within my network) and joined to this anchor vWLC.
Wireless client can connect to this SSID without any problem (whether Centrally or Locally Switched)
Sent from Cisco Technical Support iPhone App
09-15-2012 08:47 PM
I'm just trying to understand your setup. The only difference from local located APs and over the internet is the up the ap joins. so the FlexConnect ap joins a vWLC in the dmz and the SSID that is centrally switched is allowed through the firewall to the inside network. This ssid is not anchored to the other foreign wlc. So on the vWLC in the dmz you can't see any client info from that SSID. I would do a debug mac address of the client. Can you make sure that there is nothing specified in the mobility anchor of the SSID and also if your using ap groups verify the setting there.
Sent from Cisco Technical Support iPhone App
09-16-2012 05:03 PM
vWLC does not support anchor controller. Its in the release notes as unsupported.
http://www.cisco.com/en/US/docs/wireless/controller/release/notes/crn73.html#wp973325
09-17-2012 02:18 AM
Hi Scott, you understand my setup correctly. By the way, is there a change if you can try this with your LAB?
Still I can't make it work. I'm just curious if this will work in your LAB.
vWLC (inside) <-> ASA outside <-> internet <-> any home based internet router <-> AP (could be 1131, 3500, 3600.. etc)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide