04-15-2025 04:41 PM
Hi guys!
I'm back carrying weird issue with my WLC and AP! Today morning, I saw some weird logs on my core switch.
A lot of MAC address flapping log written there especially between AP and WLC. All my AP is joined WLC, most AP are 3700, 3800 or 9120. WLC model is 9800. and All AP are running as flex mode, so client MAC address are usually appeared from the access port connecting to AP not WLC. but some clients MAC address are appearing from the port connecting to WLC, even though all AP are running as flex. Is that normal situation? I still can see some client MAC address from the WLC port as below.(VLAN 11 is for client wireless).
Mac Address Table
-------------------------------------------
Vlan Mac Address Type Ports
---- ----------- -------- -----
1 f01d.2d38.xxxx DYNAMIC Po25
1 f01d.2d38.xxxx DYNAMIC Po25
1 f01d.2d38.xxxx DYNAMIC Po25
11 027f.cada.xxxx DYNAMIC Po25
11 4201.42e9.xxxx DYNAMIC Po25
11 78b8.d649.xxxx DYNAMIC Po25
11 f01d.2d38.xxxx DYNAMIC Po25
04-15-2025 05:34 PM
Couple of things -
1. Even though your APs are in flex mode, are you doing local switching for all the SSIDs or there are some WLAN with central switching as well?
2. any specific reason of having the client vlan in wlc side despite of doing flex? I am assuming you might be having an SSID with Central switching enabled.
Also can you try to find a common ground among all these clients whose mac addresses are appearing in the WLC? Like same SSID, site or anything?
04-15-2025 05:53 PM
Not sure what you meant, I have 2 vlans for wireless (vlan11, 15), and WLC also have these vlans because they are used for WLAN. do I not need vlan 11,15 in WLC? if all AP are running in flex?
I just want to know why some client MAC addresses intermittently appear and hide from WLC port... even though AP are running in flex.
04-16-2025 05:55 AM - edited 04-16-2025 05:57 AM
I think you have missed @Saikat Nandy 's point @yum3372
The AP mode is not what determines how the traffic is switched, it is the WLAN configuration.
So for local switching although the AP must be in Flexconnect Mode the client traffic only gets 100% locally switched by the AP if the WLAN is also configured for local switching, local authentication and local DHCP. So the key question (again) - how are the WLANs configured?
> do I not need vlan 11,15 in WLC?
The VLANs only need to be configured on the WLC if the WLANs are central switching. So back to the previous question - how are the WLANs configured?
If all your WLANs are configured for local switching then you do not need the VLANs configured on the WLC at all.
If you want to reference the VLANs by name then they need to be configured in the Flex profile to define the VLAN name for the AP.
If you are happy to reference the VLANs by VLAN ID (VLAN number) then they do not even need to be specified in the Flex profile - simply configure the VLAN number on the policy profile.
There's another post on the community recently (if I find the link I'll add it) where somebody found that if you use the same VLAN on central and local switched WLANs then the behaviour you observed happens - probably a bug in the code so avoid using the same VLANs for centrally and locally switched WLANs. So if you have configured the VLANs on the WLC when they are not needed that's probably causing what you're seeing.
04-16-2025 06:49 AM - edited 04-16-2025 06:51 AM
To clarify this, it's not the WLAN itself you need to look at, it's the policy tag and the policy profile.
The policy profile is where, in the General tab (GUI), you leave "Central Switching" turned off (if local switching at the AP/switch is the intent), and in the Access Policies tab (GUI), you specify which VLAN the client should get locally switched to.
The policy tag is where you assign which WLANs to broadcast and using which policy profile.
So, ensure that these are set up correctly, and that all neighboring APs have the same policy tag applied.
04-18-2025 12:40 AM
I just checked my WLC and it has the vlans for WLAN(11,15)... Damm! Could it be the root cause of the problem? right?
And I just found out how to set up the flex profile on WLC as below. Do you think I need to change the set up for the SSID and everything to use AP in flex mode correctly?
04-18-2025 04:45 AM
> I just checked my WLC and it has the vlans for WLAN(11,15)... Damm! Could it be the root cause of the problem? right?
Yes
> And I just found out how to set up the flex profile on WLC as below. Do you think I need to change the set up for the SSID and everything to use AP in flex mode correctly?
Yes. Obviously we don't know what the present setup looks like but you should follow the guides to set up Flexconnect Local Switching, Local Authentication and Local DHCP correctly if you don't want the VLANs to be configured on the WLC.
04-15-2025 07:08 PM
Are there multiple SSIDs that do flex vs central switching, different VLANs? If so, are clients configured to connect to multiple SSIDs automatically?
04-15-2025 07:11 PM
No. only 2 vlans (11,15) are in my network for wireless. and their SSID are configured for flex only.
04-16-2025 01:23 AM
Can I have a 'show tech wireless' from the controller please.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide