05-09-2023 02:08 AM
Hello All,
I have a customer who has many branches with 2 o 3 APs in each branch. They also already have ISE. They have specific requirements:
1- Local DHCP services in each branch (not centralized).
2- They need to locally switch/bridge the traffic inside the branch and not tunnel it centrally to the main site/DC/Controller.
3- They need to apply ISE Posture health check on clients using AnyConnect client.
With FlexConnect mode of APs (default is connected mode - i.e. in normal situation connection is up to centralized 9800 Controller).
Is this doable? if yes, what are the limitations? any issues with DHCP & VLAN assignment?
Thanks
05-09-2023 03:25 AM
1) and 2) are kind of standard features of 9800 when APs are configured in Flexconnect mode
3) Is in essence not related to wireless but Anyconnect , (but) have the ISE posturing policy enforced on the VPN server where the Anyconnect client connects to.
M.
05-10-2023 12:45 AM
So, i saw in the WLC configuration guide the following constrain:
• FlexConnect APs do not forward the DHCP packets after Change of Authorization (CoA) and change of VLANs using 802.1x encryption. You must disconnect the client from the WLAN and reconnect the client to enable the client to get an IP address in the second VLAN.
I assume that the scenario will apply in my case here, since in the posture process the user connects initially to a VLAN (unhealthy) then connects to another VLAN when posture is ok.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide