08-07-2025 09:06 AM
Background:
WLC 9800 cluster is directly connected to ACI leaf switches. All data traffic is coming to WLC (CAPWAP). Wireless user network is quite large.
Query:
Can we configure wireless user vlan gateways at ACI bridge domain. So that all wireless users will be learned as endpoints in ACI. After coming to ACI, traffic will be pointing to firewalls via L3outs.
I think above option is technically possible, but is it recommended to have the user network gateways configured in ACI? Other option is having the ACI as L2 and gateways configured in firewall.
08-08-2025 12:08 AM
as Long as configuration and BUM traffic going in right flow i do not see any issue here.
check some reference :
https://www.youtube.com/watch?v=lLxG8hd2QQ8
Can we configure wireless user vlan gateways at ACI bridge domain. So that all wireless users will be learned as endpoints in ACI
not sure what is the use case here ? you looking to ACI to get insight information for the end point locator ?
WLC does already all telemetry, why do we need ACI need to know about end point.
the Endpoint Locator is meant for DC Host and end point connected to DC switches, since its VM Moving between DC or Leaf switches to track.
08-08-2025 11:31 AM
Thanks BB for the information. I have watched the above video and it seems they also did the same configuration. But in the beginning of the video, it is mentioned that this is not intended to be considered as a Cisco Validate Design. I checked the Cisco Validated Designs but could not find any documents related to this. Do you know any Cisco Validated Designs for ACI and WLC related.
Similar to the video mentioned earlier, we have a stretched ACI fabric that connects two data centers in different locations to the same ACI fabric. This setup allows us to use a firewall cluster located in another location for geo-redundancy in case one firewall cluster fails. That is why I want to configure the gateways in ACI.
My main concern is whether it is recommended to configure the gateways for SSIDs in ACI. Since ACI is designed for data center networking, if we configure the gateways in ACI, user traffic will also be routed through the ACI fabric
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide