What's New in Cisco IOS XE Dublin 17.12.2
From this release, Layer 2 VRF is also supported with WGB, RADSEC, and TRUSTSEC capabilities. However, RLAN is not supported with VRF. For more information, see Remote LANs.
05-25-2025 06:54 AM
Hi all;
When configuring interfaces and their roles in C9800, how can I force the WLC to do not use SP for only OOB purpose and WMI for wireless user traffic servicing? In other words, how WLC forces to not use its SP for AAA negotiation with RADIUS server?
Thanks
Solved! Go to Solution.
05-26-2025 02:36 AM
Thanks for your reply;
Although your mentioned link help me understand the topic more, but I found a better explanation as follows:
The WMI is the mandatory Layer 3 interface (physical interface or an SVI) on the Catalyst 9800 (there is only one WMI on the controller). It is used for all communications between the controller and APs. Also, it is used for all CAPWAP or inter-controller mobility messaging and tunneling traffic. WMI is also the default interface for in-band management and connectivity to enterprise services, such as, AAA, SYSLOG, SNMP, etc. You can use the WMI IP address to remotely connect to the device using SSH, Telnet, or access the controller’s GUI using HTTP or HTTPS.
05-25-2025 07:40 AM
- Such questions require a 'valid WHY' = ?
M.
05-25-2025 09:45 AM
Just to add to what @marce1000 mentioned, it's important to review the intended use and capabilities of the Service Port. Understanding of Cisco's recommended implementation practices is essential to design and have a supportable network infrastructure. I know folks always ask "why", maybe because other vendors implement their's in a different way, but again, you still need to follow what the vendor recommends. Can things change, sure... will it, who knows.
05-26-2025 02:36 AM
Thanks for your reply;
Although your mentioned link help me understand the topic more, but I found a better explanation as follows:
The WMI is the mandatory Layer 3 interface (physical interface or an SVI) on the Catalyst 9800 (there is only one WMI on the controller). It is used for all communications between the controller and APs. Also, it is used for all CAPWAP or inter-controller mobility messaging and tunneling traffic. WMI is also the default interface for in-band management and connectivity to enterprise services, such as, AAA, SYSLOG, SNMP, etc. You can use the WMI IP address to remotely connect to the device using SSH, Telnet, or access the controller’s GUI using HTTP or HTTPS.
05-26-2025 04:46 AM
I'm still not clear exactly what you were trying to ask @rezaalikhani with multiple double negatives in your questions but the important point is that the SP is in a separate VRF and early versions of 9800 had very limited VRF support so initially it was really just SSH which could be supported on SP. Since then successive versions have increased support for other features on SP in VRF - these are mentioned in the release notes for the relevant versions. Note that telemetry features only work through WMI, not SP.
From this release, Layer 2 VRF is also supported with WGB, RADSEC, and TRUSTSEC capabilities. However, RLAN is not supported with VRF. For more information, see Remote LANs.
VRF Support |
From this release, Virtual Routing and Forwarding (VRF) is supported. For more information, see VRF Support. |
> how WLC forces to not use its SP for AAA negotiation with RADIUS server?
In your AAA configuration you can specify both source interface and VRF for the server.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide