02-12-2023 05:58 AM
Good day all,
My name is Allan. I want some help configuring WLC-9800-CL HA. The controllers are already up, and I can access them on the ESXi server. The main issue is how to add three departments so that they can access Wi-Fi using different SSIDs. I have three departments listed below.
HR > 10.10.x.x/24 - VLAN 3
Finance >172.16.x.x/24 - VLAN 4
Admin > 172.16.x.x/24 - VLAN 2
Here is my thinking, I will create three WLANs in the controller with their respective SSIDs. In the controller, again configure three SVIs 10.10.x.254, 172.16.x.254, and 172.16.x.254.
After that, I will create static or default routes for each subnet, pointing to the gateway. Then Configure Gi2 of the controllers as a trunk and allow the three VLANs.
Then on the Core Switch, where I have the SVIs for these Subnets, I will add DHCP option 43 for each subnet.
Kindly advise if this is correct; if not, please point me in the right direction.
I really appreciate any help you can provide.
Allan
Solved! Go to Solution.
02-12-2023 06:32 AM
You are in the right direction - Make sure Switch SVI as Gateway when you configure your DHCP for users' IP addresses.
configuring SSID PolicyTAG / SITE TAG / RF TAG - if you did not come across this before?
02-13-2023 07:18 AM
Good day, Rich,
Thank you so much for the info provided. I have taken note of your advice!
Thank you!
02-13-2023 01:54 PM
@Allan001 do you happen to have a radius server like Cisco ISE or something else? You might be able to just create your vlans, but then have one SSID and then depending on the OU the user belongs to, you can define the vlan. This is assuming you are using 802.1x.
02-12-2023 06:32 AM
You are in the right direction - Make sure Switch SVI as Gateway when you configure your DHCP for users' IP addresses.
configuring SSID PolicyTAG / SITE TAG / RF TAG - if you did not come across this before?
02-12-2023 06:52 AM
Hi Balaji,
Thank you so much for getting back to me so quickly. I will go through the URL provided; you are a lifesaver. If I am stuck somewhere, I will respond to this thread again.
Thank you!
Allan001
02-12-2023 09:41 AM
No worries, thanks for sharing your feedback. you should be good...
make sure if you doing anchoring/mobility , MAC Address should be same for HA Active and standby (if not when it failover mobility will not work)
02-12-2023 09:16 AM
- Also note that before production use , during and or later you can always have a checkup of the WLC-9800-CL HA configuration with the CLI command : show tech wireless , (on the current master) have the output analyzed by https://cway.cisco.com/
M.
02-12-2023 09:56 AM
Hi, Marce 1000,
Thank you very much. I will test with the command " show tech wireless".
Much appreciated.
Allan001
02-13-2023 09:29 AM
02-13-2023 05:40 AM
Just one comment to add:
> In the controller, again configure three SVIs 10.10.x.254, 172.16.x.254, and 172.16.x.254.
As per 9800 best practices guide (link in my signature below) it is not recommended to configure SVI on 9800 except where specifically required for specific features which only work with SVI on WLC. You should simply be bridging the WLAN traffic to the VLAN with the SVIs on your switch.
02-13-2023 07:18 AM
Good day, Rich,
Thank you so much for the info provided. I have taken note of your advice!
Thank you!
02-13-2023 01:54 PM
@Allan001 do you happen to have a radius server like Cisco ISE or something else? You might be able to just create your vlans, but then have one SSID and then depending on the OU the user belongs to, you can define the vlan. This is assuming you are using 802.1x.
02-13-2023 11:57 PM
Hi Scott,
Thank you so much for the technical advice. Unfortunately, we do not have ISE. We are using a different FW. So many solutions from the community team. Thank you!
Regards,
Allan001
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide