cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
738
Views
0
Helpful
5
Replies

Wireless Client Connectivity

Jim Kerr
Level 1
Level 1

We have approximately 20 companies that use a shared LAN and authenticate using wired 802.1x and are completely separated for security using Vlan’s / VRF’s.

This has worked very well. However, I now want to arrange for the clients for each company to use our wireless network (though not to use Guest Wi-Fi).

We currently use Cisco WLC 5520, Cisco ISE and Windows AD. In addition, we use Flex Connect at the site for local wireless breakout at the switch.

I’d like for our users at each company to authenticate using wireless 802.1x using our existing Cisco ISE & AD. The user is then required to be dynamically placed into their individual vlan for their company.

However, I know there are limitations with regards the number of SSID’s that can and should be used (I think the maximum number of SSID’s is 16 and that really, we shouldn’t go for more than 4).

Rather than having to create multiple SSID’s Ideally, I would want to deploy just 1 SSID for them all to use but then based on the users AD credentials (authenticated via AD and ISE) then I’d like to dynamically place the user in a Vlan dedicated for their company (similar to what we currently do with wired dot1x).

Does anyone know if this is possible and any idea how this can be done ?

5 Replies 5

patoberli
VIP Alumni
VIP Alumni
Short answer, yes this should be possible, if you offer the correct VLAN at every location. So if userA from companyA visits company, is he now able with a wire to get online in the correct network?
If yes, then it should also be possible to offer the same VLAN from Wireless.
The WLC (depends on the model) allows more SSID, but no more than 8 (I think) per access point simultaneously. You can assign the needed SSID per AP-Group, which you probably already have, for the Flexconnect configuration.

In any case, this should be possible.

thank you for your response.

So all 20 companies share the 1 same building, the same floors and can be sat next to each other.

Each company can currently access the wired network and are dynamically placed in their own vlan via wired dot1x.

I know that for a WLAN it is mapped to a wired Vlan. However I'd like to advertise just 1 SSID (WLAN) and dynamically map it to different vlan's depending on the partner following AD authentication.

I'm very conscious that if I have to use a large number of SSID's (ie 1 for each partner) then this will cause issues with interference and channel congestion.

 

Do you have any examples or can share a link of how it can be done ?

As you are using a centralized wireless solution, this is fairly easy.

First thing to check, are your accesspoints connected with a trunk and a native vlan, or an access port (which is the same vlan as the ssid currently offers).

If it's by a trunk, then you can probably even use the same ISE policy for the wireless network.



You require an SSID with 802.1X as Authentication Key Management and the ISE as Radius servers. Only challenge is the Flex configuration. If I'm not mistaken, you have to configure each possible local client VLAN inside the Flex group (VLAN mapping), so that if an AP places a client into such a VLAN, the AP recognized it. I've never done a Flex installation, so I'm no specialist with this.



I think you need this manual: https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-2/configuration/guide/cg/cg_flexconnect.html#11549






This link should provide what you are looking for, check under Solution – AAA Override of VLAN Name step 1-12:
https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-1/Flex-7500/Flex_7500_DG.html#pgfId-131938


<<< Please help the community by marking useful posts helpful, or accept as a solution if it resolved your issue >>>

Haydn Andrews
VIP Alumni
VIP Alumni

One option would be for a single 802.1x SSID where ISE does the splitting of the users to map to the correct VLAN, based on the user

https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-4/configuration/guides/consolidated/b_cg74_CONSOLIDATED/b_cg74_CONSOLIDATED_chapter_010010000.html

Consideration you need to take into account is that you really need the same VLAN mappings at all sites, otherwise you will have issues.

Also At any given point, an AP has a maximum of 16 VLANs. This might be an issue, but if you don't require every VLAN per building this might work. This is regardless of the number of SSIDs.

 

Other option would be looking at changing the architecture of the wireless to local mode and dropping off out the back of the WLC which would mean you could have more than 16 interfaces mapped.

*****Help out other by using the rating system and marking answered questions as "Answered"*****
*** Please rate helpful posts ***
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: