01-21-2022 09:25 AM
While reviewing our organizations WLC.s for best practice I notices that some of our sites have the guest SSID mapped to the management interface. Per the 8.5 config guide - Do not map a guest WLAN to the management interface. If the EoIP tunnel breaks, the client could obtain an IP and be placed on the management subnet. We are using guest anchor for these sites and they terminate on a different interface not management on the anchor WLC.
In this scenario are we still at risk to the above issue mentioned in the 8.5 config guide?
Thanks in advance
01-21-2022 09:44 AM
I just ran across this, anyone have thoughts on this for resolution to my question above:
The default interface used by the foreign WLC for the guest WLAN is the management interface. If the EoIP tunnel cannot be established with the anchor, the foreign controller will disassociate any wireless clients that were previously associated with the unreachable anchor and then assign new clients and reassociate clients to the interface configured under the guest WLAN of the foreign itself. Therefore, it is recommended to link the guest WLAN on the foreign to a non-routable network, or alternatively configure the DHCP server of the management interface with an unreachable IP address. If the anchor becomes unreachable, this prevents the guest clients to gain access to the management network.
01-21-2022 12:25 PM
In the past when configuring guest anchor, I have always created a bogus interface like vlan666 or whatever and that doesn't reside in the trunk at all. This way if the tunnel breaks, the traffic is placed on the vlan. In my example, vlan666.
01-24-2022 09:05 AM
On top of @Scott Fella's great advise, some generic design guidelines I use
Finally what ever the WLAN mode don't use management interface.
If you need more tips
https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2018/pdf/BRKEWN-2014.pdf
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide