So close, I've replace the VLAN 200 with VLAN ID 555 and VLAN 25 on the foreign controller with 555 and now getting the following error on the foreign controller:
Aug 10 21:50:31.360: %MM_LOG-4-EXPORT_ANCHOR_DENY: Chassis 1 R0/0: mobilityd: Export anchor required, but received export anchor deny for: WLAN Profile: gstpro-1, Client MAC: 00:0c:29:0d:c6:1a, Error: Received export anchor deny - profile mismatch.
Aug 10 21:50:27.965: %CLIENT_ORCH_GUEST_LAN_LOG-7-CLIENT_RECEIVED: Chassis 1 R0/0: wncd: Wired Guest Client MAC: 000c.290d.c61a join request received on vlan 555 - interface GigabitEthernet3
On the Anchor controller I am getting the following logs:
Aug 10 21:50:31.356: %MMIF_LOG-4-ANCHOR_RESP_PROFILE_MISMATCH: Chassis 1 R0/0: wncd: Export anchor required but config is incorrect, sending export anchor deny mismatch for: Wlan-Profile: gstpro-1, Policy Profile: testpro-1, client mac: 00:0c:29:0d:c6:1a
Aug 10 21:50:31.344: %CLIENT_ORCH_LOG-4-ANCHOR_INVALID_MBSSID: Chassis 1 R0/0: wncd: Export anchor required but config is incorrect (e.g.: wlan should be up, wlan profile name and policy profile name should match) for: Wlan-Profile: gstpro-1, Policy Profile: testpro-1, client MAC: 000c.290d.c61a
Aug 10 21:50:31.343: %CLIENT_ORCH_LOG-4-ANCHOR_INVALID_WLAN_ID: Chassis 1 R0/0: wncd: Export anchor required but unable to get wlan id for: Wlan-Profile: gstpro-1, Policy Profile: testpro-1, client MAC: 000c.290d.c61a
There is a few mistakes in the article, and some of the fine detail doesn't marry up hence causing issues.
I think the profiles need to match, then this is this requirement which contradicts it?
Every guest LAN has a unique name and this name cannot be shared with RLAN or WLAN.
Take a look at the commands from the article below:
wireless profile policy testpro-1
mobility anchor 192.168.201.111 priority 1
guest-lan profile-name gstpro-1 1 wired-vlan 25
no security web-auth
wireless guest LAN map gstmap-1
guest-lan gstpro-1 policy testpro-1
wireless profile policy testpro-2
guest-lan profile-name testpro-2 1
client association limit
no security web-auth
You see the second one (anchor controller) has a guest-lan name that matches the wireless profile policy name "testpro-2", whereas the other controller its called "gstpro-1".
Is this correct?