cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2139
Views
0
Helpful
6
Replies

Multiple Vlans in a single SSID in Flexconnect Mode

SiJian Bao
Level 1
Level 1

My WLAN is going to be configured as the flexconnect mode witch runs multiple vlans using ISE, in that situation, can my WLC be linked to an access-port instead of a trunk port?

2 Accepted Solutions

Accepted Solutions

Stephen Rodriguez
Cisco Employee
Cisco Employee

No it would still need to go to a trunk port as you are going to have multiple
Vlans

Steve

Sent from Cisco Technical Support iPhone App

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

View solution in original post

Scott Fella
Hall of Fame
Hall of Fame

Just to add... Your saying that if all your AP's are in FlexConnect local switching and nothing gets tunneled back to the WLC, you could have the WLC connected to an access port but the vlan ID for the management interface would need to be set to zero (0). Like Steve mentioned, if your planning to add dynamic interfaces on the WLC for client traffic, then the WLC should be connected to a trunk port. It's best to just connect the WLC to a trunk port anyways and tag the management vlan.

Now it's a different story if your AP's are in FlexConnect locally switched, then the AP has to also be on a trunk port. So if you have WLAN's that are locally switched and more than one vlan, in which clients will be placed on, the switchport has to be a trunk port.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

View solution in original post

6 Replies 6

Stephen Rodriguez
Cisco Employee
Cisco Employee

No it would still need to go to a trunk port as you are going to have multiple
Vlans

Steve

Sent from Cisco Technical Support iPhone App

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

Scott Fella
Hall of Fame
Hall of Fame

Just to add... Your saying that if all your AP's are in FlexConnect local switching and nothing gets tunneled back to the WLC, you could have the WLC connected to an access port but the vlan ID for the management interface would need to be set to zero (0). Like Steve mentioned, if your planning to add dynamic interfaces on the WLC for client traffic, then the WLC should be connected to a trunk port. It's best to just connect the WLC to a trunk port anyways and tag the management vlan.

Now it's a different story if your AP's are in FlexConnect locally switched, then the AP has to also be on a trunk port. So if you have WLAN's that are locally switched and more than one vlan, in which clients will be placed on, the switchport has to be a trunk port.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

In fact my environment is like this:

We have a headquarter and 3 branches, each site has several APs and the WLC is at the headquarter. Each branch has different VLAN for one same SSID which is the wireless access for the employees and we decide to use the flex connect local switch mode. Two extra WLANs are configured for guest and VIP which have diferent VLANs. And we use the ISE for the AAA server to control the access.

Then for my environment. It's nothing about the dynamic VLAN, right? Can I just connect all my APs to a trunk port and my WLC to access port? Thanks a lot and happy Dragon Boat Festival which is a big festival in my country!

Scott Fella
Hall of Fame
Hall of Fame

The WLC should be connected to a trunk port that allows the management vlan and any other vlans you create. If your doing LAG also, you definetly need trunk ports to create an etherchannel.

Local mode AP's connect to an access port and FlexConnect AP's connect to a trunk port also only allowing vlans for the ap manager and wireless traffic.

Happy Dragon Boat Festival!

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

Thanks Scott, I connect my WLC and APs to trunk port and they work fine now with ISE

Glad you got it working.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***
Review Cisco Networking for a $25 gift card