10-24-2022 11:33 AM
Hello cisco community,
I am new to Anchor Mobility feature. we have 2 9800 controllers in anchor mobility 1 is used as foreign and other in DMZ zone used as Anchor. Now explain me the Scenarios implemented for Redundancy, Is this possible to implement SSO on these 2 Devices if yes how can I achieve that?
Regards :"
Khushbakhat
10-24-2022 12:40 PM
Not sure I got it correctly, you looking to deploy HA, or do you already have HA and deploy Anchoring?
check some document can help you :
10-24-2022 10:49 PM
Basically I want to confirm that both HA and anchor mobility work together if I have only 2 devices 1 is act as foreign and 1 is act as anchor.
10-24-2022 12:54 PM
Hello Khushbakhat,
I would think that you want to do HA-SSO which basically makes the two controllers work as one logical device. If that's your goal, you must meet the following prerequisites:
Maximum RP link latency = 80 ms RTT, minimum bandwidth = 60 Mbps and minimum MTU = 1500
Both controllers must be of same PID. In case of 9800-CL, ensure the host environment (ESXi or KVM or ENCS) is the same for both instances.
Both controllers must run the same version of software.
Both controllers must run in the same Installation Mode (Either Bundle or Install). We recommend Install mode for WLC.
Both controllers must have redundant IPs in the same subnet. IP addresses used for redundancy must be unroutable without a gateway present in the subnet.
Both controllers must have a unique wireless management interface.
Wireless management interface of both devices must belong to the same VLAN/subnet.
if all of the above can be done. You just need to follow the HA-SSO configuration guide for the WLC, which can be found at the link below:
If you are looking for having two logical boxes and load balancing the APs between them, you will need to configure the AP's controller list and assign the primary and backup controllers. The link below shows the steps to accomplish this task:
10-24-2022 10:47 PM
Thanks,
My concern is that with HA-SSO my 2 devices become 1 logical device than my scenario of anchor mobility is working or not. Logically 1 device but physically 2 devices act as foreign and anchor devices ?
10-25-2022 05:01 AM
Hi @khushbakhat ,
If you deploy 1 WLC as Anchor and the other as Foreign you will not get redundancy. I would suggest that you create HA-SSO with the WLCs. In order to send the Guest traffic to DMZ you have the below options.
Options when AP in Local Mode
Options when APs in Flex mode
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide