cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
362
Views
3
Helpful
9
Replies

MAC address flapping between AP and WLC(9800)?

yum3372
Level 1
Level 1

Hi guys!

I'm back carrying weird issue with my WLC and AP! Today morning, I saw some weird logs on my core switch.

A lot of MAC address flapping log written there especially between AP and WLC. All my AP is joined WLC, most AP are 3700, 3800 or 9120. WLC model is 9800. and All AP are running as flex mode, so client MAC address are usually appeared from the access port connecting to AP not WLC. but some clients MAC address are appearing from the port connecting to WLC, even though all AP are running as flex. Is that normal situation? I still can see some client MAC address from the WLC port as below.(VLAN 11 is for client wireless).

 

Mac Address Table
-------------------------------------------

Vlan Mac Address Type Ports
---- ----------- -------- -----
1 f01d.2d38.xxxx DYNAMIC Po25
1 f01d.2d38.xxxx DYNAMIC Po25
1 f01d.2d38.xxxx DYNAMIC Po25
11 027f.cada.xxxx DYNAMIC Po25
11 4201.42e9.xxxx DYNAMIC Po25
11 78b8.d649.xxxx DYNAMIC Po25
11 f01d.2d38.xxxx DYNAMIC Po25

9 Replies 9

Saikat Nandy
Cisco Employee
Cisco Employee

Couple of things - 

1. Even though your APs are in flex mode, are you doing local switching for all the SSIDs or there are some WLAN with central switching as well?
2. any specific reason of having the client vlan in wlc side despite of doing flex? I am assuming you might be having an SSID with Central switching enabled.

Also can you try to find a common ground among all these clients whose mac addresses are appearing in the WLC? Like same SSID, site or anything?

Not sure what you meant, I have 2 vlans for wireless (vlan11, 15), and WLC also have these vlans because they are used for WLAN. do I not need vlan 11,15 in WLC? if all AP are running in flex? 

I just want to know why some client MAC addresses intermittently appear and hide from WLC port... even though AP are running in flex.

I think you have missed @Saikat Nandy 's point @yum3372 
The AP mode is not what determines how the traffic is switched, it is the WLAN configuration.
So for local switching although the AP must be in Flexconnect Mode the client traffic only gets 100% locally switched by the AP if the WLAN is also configured for local switching, local authentication and local DHCP.  So the key question (again) - how are the WLANs configured?

do I not need vlan 11,15 in WLC? 
The VLANs only need to be configured on the WLC if the WLANs are central switching.  So back to the previous question - how are the WLANs configured?
If all your WLANs are configured for local switching then you do not need the VLANs configured on the WLC at all.
If you want to reference the VLANs by name then they need to be configured in the Flex profile to define the VLAN name for the AP.
If you are happy to reference the VLANs by VLAN ID (VLAN number) then they do not even need to be specified in the Flex profile - simply configure the VLAN number on the policy profile.

There's another post on the community recently (if I find the link I'll add it) where somebody found that if you use the same VLAN on central and local switched WLANs then the behaviour you observed happens - probably a bug in the code so avoid using the same VLANs for centrally and locally switched WLANs.  So if you have configured the VLANs on the WLC when they are not needed that's probably causing what you're seeing.

To clarify this, it's not the WLAN itself you need to look at, it's the policy tag and the policy profile.

The policy profile is where, in the General tab (GUI), you leave "Central Switching" turned off (if local switching at the AP/switch is the intent), and in the Access Policies tab (GUI), you specify which VLAN the client should get locally switched to.

The policy tag is where you assign which WLANs to broadcast and using which policy profile.

So, ensure that these are set up correctly, and that all neighboring APs have the same policy tag applied.

I just checked my WLC and it has the vlans for WLAN(11,15)... Damm! Could it be the root cause of the problem? right?

And I just found out how to set up the flex profile on WLC as below. Do you think I need to change the set up for the SSID and everything to use AP in flex mode correctly?

Catalyst 9800 Wireless Controller의 FlexConnect 이해 - Cisco

> I just checked my WLC and it has the vlans for WLAN(11,15)... Damm! Could it be the root cause of the problem? right?
Yes

> And I just found out how to set up the flex profile on WLC as below. Do you think I need to change the set up for the SSID and everything to use AP in flex mode correctly?
Yes.  Obviously we don't know what the present setup looks like but you should follow the guides to set up Flexconnect Local Switching, Local Authentication and Local DHCP correctly if you don't want the VLANs to be configured on the WLC.

eglinsky2012
Spotlight
Spotlight

Are there multiple SSIDs that do flex vs central switching, different VLANs? If so, are clients configured to connect to multiple SSIDs automatically?

No. only 2 vlans (11,15) are in my network for wireless. and their SSID are configured for flex only. 

Can I have a 'show tech wireless' from the controller please.

Review Cisco Networking for a $25 gift card