04-03-2013 10:44 AM - edited 07-03-2021 11:49 PM
Hello,
We have currently a WLC 5508 using 8 ports bundled into an etherchannel.
We would like to remove one physical from this etherchannel and use it for providing an access to Internet only,
Is it possible to create an virtual interface on the WLC that points only on this port?
If yes what could be the best option ? (we would like to have a physical separation for the Internet traffic only and encrypt the capwapp up to the WLC).
Thanks for your advices,
Regards
Solved! Go to Solution.
04-03-2013 10:49 AM
The best way is to have an anchor WLC. This way you can tunnel traffic to a guest anchor WLC located in the DMZ.
http://www.cisco.com/en/US/docs/wireless/technology/guest_access/technical/reference/4.1/GAccess_41.html
Sent from Cisco Technical Support iPhone App
04-03-2013 11:10 AM
When you break LAG then each port is its own, meaning that you would tie say your data vlan to port 1. The Swicth port going to port 1 could be a truck and the data vlan is configured on this switch port and tagging. You could then add port 2 as a back up shoud port 1 go down.
As far as load balance traffic. You would turn off etherchannel on the switch side, so no.
Normally if you have 3 WLANs you can tie 1 to each WLC port, 1 - data, 2 - voice, 3 - medical.
__________________________________________________________________________________________
"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
__________________________________________________________________________________________
"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."
04-03-2013 10:48 AM
Im afraid not. Once you LAG all the ports become (1). Only want is to break LAG and go PORTS.
__________________________________________________________________________________________
"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
__________________________________________________________________________________________
"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."
04-03-2013 10:48 AM
It is not possible. It's either all in a LAG or now at all.
Sent from Cisco Technical Support iPhone App
04-03-2013 10:49 AM
The best way is to have an anchor WLC. This way you can tunnel traffic to a guest anchor WLC located in the DMZ.
http://www.cisco.com/en/US/docs/wireless/technology/guest_access/technical/reference/4.1/GAccess_41.html
Sent from Cisco Technical Support iPhone App
04-03-2013 10:52 AM
Thanks for your answers,
That means we would lose the whole LAG even if we break one interface?
And if we agree to do that we can achieve this ? But load-balancing won't be effective on the 7 other ports correct?
Otherwise what would be suggested to ensure a good separation for such purpose ?(using a minimum devices in between)
04-03-2013 11:10 AM
When you break LAG then each port is its own, meaning that you would tie say your data vlan to port 1. The Swicth port going to port 1 could be a truck and the data vlan is configured on this switch port and tagging. You could then add port 2 as a back up shoud port 1 go down.
As far as load balance traffic. You would turn off etherchannel on the switch side, so no.
Normally if you have 3 WLANs you can tie 1 to each WLC port, 1 - data, 2 - voice, 3 - medical.
__________________________________________________________________________________________
"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
__________________________________________________________________________________________
"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."
04-03-2013 11:12 AM
Ok but we can have port 1 into a trunk and pass several VLANs into it ?
04-03-2013 11:22 AM
Yes of course. You could tie all your WLANs to port 1 if you like. Make sure you truck the switch port and dont signify a vlan ID on the port in the WLC.
__________________________________________________________________________________________
"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
__________________________________________________________________________________________
"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."
04-03-2013 11:42 AM
If this answers your questions, please kindly mark the question as answered. Thanks
__________________________________________________________________________________________
"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
__________________________________________________________________________________________
"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."
04-03-2013 02:31 PM
+5 George for the correct answer:)
Sent from Cisco Technical Support iPhone App
04-03-2013 11:38 PM
Thank you all for your support in that matter,
I have now a better view on what's technically possible,
Kind regards
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide