cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6686
Views
5
Helpful
7
Replies

Set up a firewall between wireless controller and APs

wfqk
Level 7
Level 7

Hi, I would like to setup a Palo Alto firewall between cisco WLC and APs to control some traffic. Anyone can share some idea for this? or send link in order to know what I need to pay attention to? Thank you very much.

7 Replies 7

Francesco Molino
VIP Alumni
VIP Alumni

Hi

 

Here 1 link out of plenty on Cisco websites to show what ports are used and so that will need to be open between APs and WLC:

https://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/113344-cuwn-ppm.html

 


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

At the minimum APs need UDP 5246-5247 (CAPWAP control and CAPWAP data) to the WLC.

UDP 5248 for multicast depending on your design and configuration.

That's assuming the AP DHCP etc is provided local to the AP and will not need to pass through the firewall.

------------------------------
Please click Helpful if this post helped you and Accept as Solution (drop down menu at top right of this reply) if this answered your query.
------------------------------
TAC recommended codes for AireOS WLC's   and   TAC recommended codes for 9800 WLC's
Best Practices for AireOS WLC's,   Best Practices for 9800 WLC's   and   Cisco Wireless compatibility matrix
Check your 9800 WLC config with Wireless Config Analyzer using "show tech wireless" output or "config paging disable" then "show run-config" output on AireOS and use Wireless Debug Analyzer to analyze your WLC client debugs
Field Notice: FN63942 APs and WLCs Fail to Create CAPWAP Connections Due to Certificate Expiration
Field Notice: FN72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Required
Field Notice: FN72524 IOS APs stuck in downloading state after 4 Dec 2022 due to Certificate Expired
- Fixed in 8.10.196.0, latest 9800 releases, 8.5.182.12 (8.5.182.13 for 3504) and 8.5.182.109 (IRCM, 8.5.182.111 for 3504)
Field Notice: FN70479 AP Fails to Join or Joins with 1 Radio due to Country Mismatch, RMA needed
Field Notice: FN74383 APs Running 17.12.4/5/6/6a May Run Out of Flash Space Preventing Upgrades
How to avoid boot loop due to corrupted image on Wave 2 and Catalyst 11ax Access Points (CSCvx32806)
Field Notice: FN74035 - Wave2 APs DFS May Not Detect Radar After Channel Availability Check Time
Leo's list of bugs affecting 2800/3800/4800/1560 APs
Default AP console baud rate from 17.12.x is 115200 - introduced by CSCwe88390

Thank you very much for your reply. The below is a diagram. Can I do this way?

 

WLC ------------FW(Palo Alto) -------switch------AP  ............ PC/user
                                                                      |
                                                                 DHCP

Yes

------------------------------
Please click Helpful if this post helped you and Accept as Solution (drop down menu at top right of this reply) if this answered your query.
------------------------------
TAC recommended codes for AireOS WLC's   and   TAC recommended codes for 9800 WLC's
Best Practices for AireOS WLC's,   Best Practices for 9800 WLC's   and   Cisco Wireless compatibility matrix
Check your 9800 WLC config with Wireless Config Analyzer using "show tech wireless" output or "config paging disable" then "show run-config" output on AireOS and use Wireless Debug Analyzer to analyze your WLC client debugs
Field Notice: FN63942 APs and WLCs Fail to Create CAPWAP Connections Due to Certificate Expiration
Field Notice: FN72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Required
Field Notice: FN72524 IOS APs stuck in downloading state after 4 Dec 2022 due to Certificate Expired
- Fixed in 8.10.196.0, latest 9800 releases, 8.5.182.12 (8.5.182.13 for 3504) and 8.5.182.109 (IRCM, 8.5.182.111 for 3504)
Field Notice: FN70479 AP Fails to Join or Joins with 1 Radio due to Country Mismatch, RMA needed
Field Notice: FN74383 APs Running 17.12.4/5/6/6a May Run Out of Flash Space Preventing Upgrades
How to avoid boot loop due to corrupted image on Wave 2 and Catalyst 11ax Access Points (CSCvx32806)
Field Notice: FN74035 - Wave2 APs DFS May Not Detect Radar After Channel Availability Check Time
Leo's list of bugs affecting 2800/3800/4800/1560 APs
Default AP console baud rate from 17.12.x is 115200 - introduced by CSCwe88390

If we setup vlan10 as management interface and vlan20 for client traffic going through firewall like the below. and DHCP is connected to vlan20 at firewall outside. The reason is we can make it easier to setup relation between WLC and AP. How do you think about it? 

 

 

WLC(vlan10) --------------------(vlan10)AP . . . . . . . PC
   |                                                                 |
vlan20-------------FW----------------vlan20

                                                                      |

                                                                   DHCP

I think you need to test your theory out to be honest. You had two different designs and your last one seems like you will put a PA between vlan 20. What are you trying to achieve here and during your testing, you need to make sure that there is no stability issue and or client experience issues. Just seems like you will introduce more headaches down the road and for folks whom have to troubleshoot.
-Scott
*** Please rate helpful posts ***

I'll go one step further than @Scott Fella and say no you can't do what you show in your second design.

You seem to not understand what the options are with local and central switching of the client traffic with a WLC.

If the client traffic is centrally switched then your AP has no connection to vlan 20.  The client traffic is tunnelled to the WLC over CAPWAP and exits the WLC on vlan 20.  Yes you could then switch that back to the client side via firewall if you wanted to but that would be independent of the AP.  There wouldn't be much point in having a firewall at all in this case.

If you use flexconnect with local switching then the traffic is switched directly onto vlan 20 by the AP so why would you want to send it to the WLC, and over a firewall, and then obviously the WLC doesn't need any connection to vlan 20.  Although maybe you'd want a firewall between your client vlan 20 and the internet but then vlan 20 will go to your internet router not the WLC.

 

So you need to decide on the most appropriate design, understanding the difference between AP in local mode or flexconnect mode and the difference between central switching and local switching.  Then you can decide if you want to put a firewall in the path.  Go read the basics of how WLC and CAPWAP APs work.  Then when you've understood that, work out which design works best for your circumstances and then decide whether a firewall is appropriate and where it should be situated.  Don't put a firewall in just for the sake of it when it doesn't add any value and could reduce the reliability of your solution (like Scott said headaches down the road).

------------------------------
Please click Helpful if this post helped you and Accept as Solution (drop down menu at top right of this reply) if this answered your query.
------------------------------
TAC recommended codes for AireOS WLC's   and   TAC recommended codes for 9800 WLC's
Best Practices for AireOS WLC's,   Best Practices for 9800 WLC's   and   Cisco Wireless compatibility matrix
Check your 9800 WLC config with Wireless Config Analyzer using "show tech wireless" output or "config paging disable" then "show run-config" output on AireOS and use Wireless Debug Analyzer to analyze your WLC client debugs
Field Notice: FN63942 APs and WLCs Fail to Create CAPWAP Connections Due to Certificate Expiration
Field Notice: FN72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Required
Field Notice: FN72524 IOS APs stuck in downloading state after 4 Dec 2022 due to Certificate Expired
- Fixed in 8.10.196.0, latest 9800 releases, 8.5.182.12 (8.5.182.13 for 3504) and 8.5.182.109 (IRCM, 8.5.182.111 for 3504)
Field Notice: FN70479 AP Fails to Join or Joins with 1 Radio due to Country Mismatch, RMA needed
Field Notice: FN74383 APs Running 17.12.4/5/6/6a May Run Out of Flash Space Preventing Upgrades
How to avoid boot loop due to corrupted image on Wave 2 and Catalyst 11ax Access Points (CSCvx32806)
Field Notice: FN74035 - Wave2 APs DFS May Not Detect Radar After Channel Availability Check Time
Leo's list of bugs affecting 2800/3800/4800/1560 APs
Default AP console baud rate from 17.12.x is 115200 - introduced by CSCwe88390
Review Cisco Networking for a $25 gift card