cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1864
Views
0
Helpful
7
Replies

guest internet local breakout

ahmad.syed
Level 1
Level 1

Hi Team,

We are discussing to deploy guest internet locally at site rather than using Anchor controller present in DC using internet link at DC.

 

 

Can you please help with steps , how we can achieve

 

1 Accepted Solution

Accepted Solutions
7 Replies 7

Sandeep Choudhary
VIP Alumni
VIP Alumni

In that case you have to use flex connect Central authentication and local switching.

 

https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/81680-hreap-modes.html

https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/81680-hreap-modes.html

 

Regards

Dont forget to arte helpful posts

With having foreign controller only , can we get Guest portal services from ISE. My question is , we want to have guest network locally with flexconnect design . But wanted that guest user should get access through ISE with guest portal .

 

Can we achieved? If yes how ?

Just search for “Cisco FlexConnect ISE CWA” and you will find information on how to configure what you want. If you have the 9800’s, then just add that into the above search to get configuration examples.

https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html
-Scott
*** Please rate helpful posts ***

Hello @Scott Fella ,

Thanks for response. We have 5520 WLC . Can we achieve this in 5520 as we want both corporate and Guest SSID to be served by same AP in flexconnect.

 

 

 

Hi Ahmad,

We have similar requirement, When you able to achieve this? If yes, can please advise how? Did you have to install additional Anchor controller locally and tunneled with Foreign controller over WAN Link?

Regards,

Puru

 

 

JPavonM
VIP
VIP

That design with localy forwarded clients (not anchored) is same for both C9800 and AireOS WLCs using Flexconnect and you can have a mix of Corporates and Guests in different SSIDs been forwarded to different VLANs.

The routing decition to use a central Internet circuit to forward traffic would be accomplished using a IPSEC or GRE tunnel between the remote site and DC (using routers or FWs) or by using VRFs.

Thank you

Appreciate your Response. I was looking for anchored solution.

Regards,

Puru

 

 

 

 

Review Cisco Networking for a $25 gift card