01-04-2012 01:26 PM - edited 07-03-2021 09:19 PM
Hello,
I am tasked with configuring a 2504 wireless controller. Is it possible to assign an SSID to an interface that has dynamic ap management enabled?
Scenario:
Location1:
1) 10.0.0.0/24
2)192.168.0.0/24 DMZ
Location 2:
1) 10.0.5.0
Both locations are routable using network 1 at each location. However, I need to configure several access points and send them to location 2. These access points will communicate with the controller at location 1 on network 1. Two SSIDs will need to be on network 1 at location 1. The other SSID will be on Network 2 at location 1. This network is not routable.
Thank You for your help.
Solved! Go to Solution.
01-05-2012 06:59 PM
Kennin,
FYI.... I just actually did an install with a 2504 today. The setup was an internal network and a guest network in the dmz. I configured the management with dynamic ap managemet 10.8.0.0/24. I then configued another interface for the internal network on a differen subnet 10.32.0.0/24. The guest network was also on a differnt subnet and I configured the interface on a 192.168.0.0/24.
Management: 10.8.0.0 Port 1 primary Port 2 backup - Dynamic ap manager enabled
Internal: 10.32.0.0 Port 1 primary Port 2 backup - Dynamic ap manager disabled
Guest: 192.168.0.0 Port 3 primary no backup port - Dynamic ap manager disabled
01-04-2012 01:30 PM
Is there a reason you have dynamic ap management enabled? If you have the 2504 at location 1, those ap should be in local mode. The AP's at location 2 should be configured for h-reap. This allows you to say, this SSID will map to this vlan at location 2. If you enable h-reap local switching on the wlan ssid, this give you the otion of mapping ssid to vlans or else it will tunnel back tothe wlc. Make sense?
Here is a link for h-reap
http://www.cisco.com/en/US/products/ps10315/products_tech_note09186a0080736123.shtml
http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a00807cc3b8.shtml
01-04-2012 01:34 PM
I am new to cisco wireless controllers. Without dynamic AP management enabled how can the access points communicate with the controller?
01-04-2012 01:39 PM
They connect through the management interface.
01-04-2012 01:40 PM
Once I disable dynamic ap management on the management interface, All access points stop communicating with the controller.
01-04-2012 01:44 PM
Okay... I thought you were configuring multiple ap manager interfaces. If you want to use the management interface as the ap manager, you enable that there. Then you can use the other ports for your other vlans.
Look at senerio 1 and senerio 2.
http://www.cisco.com/en/US/products/ps11630/products_tech_note09186a0080b8450c.shtml
01-04-2012 01:55 PM
So this is how you want this to be setup:
Scenario:
Location1:
1) 10.0.0.0/24
2)192.168.0.0/24 DMZ
Location 2:
1) 10.0.5.0
Both locations are routable using network 1 at each location. However, I need to configure several access points and send them to location 2. These access points will communicate with the controller at location 1 on network 1. Two SSIDs will need to be on network 1 at location 1. The other SSID will be on Network 2 at location 1. This network is not routable.
Since location 1 is a flat network with only one subnet (internal) and one in the DMZ, you will configure WLC management/ap-manger port 1 on the 10.0.0.0/24 subnet. You can then map your SSID#1 to the management interface. Create a new dynaminc interface on the WLC and assign it an ip in the 192.168.0.0/24 subnet and place that on port 2. Connect port 2 to the DMZ. Now since you want everything to tunnel back to the WLC from location 2, you would leave the ap's in local mode. Devices in location 2 associating on SSID #1 will obtain an ip address in location 1 and tunnel back to the WLC and traffic will egress out of port 1. Devices that associate in location 1 or location 2 to SSID#2 (Guest) will tunnel back to the WLC in location 1 and traffic will egress out of port 2.
Since you want to tunnel traffic back to the WLC from location 2, you need to make sure your link has enough bandwidth or else the ap's will be bouncing.
If you setup the AP's in location 2 in h-reap mode, then you can place devices that associate to SSID #1 on the 10.0.50.0 subnet. Devices that associate to SSID #2 at location 2 will tunnel back to the WLC and egress out of port 2.
01-04-2012 01:56 PM
Ok, this is my issue. I am unable to configure two interfaces on the same subnet. I get a message stating ip confilct with another interface.
01-04-2012 01:58 PM
Correct... each interface must be on a different subnet.
01-04-2012 02:00 PM
The documentation has multiple interfaces on the same subnet and vlan tag.
01-04-2012 02:01 PM
Cisco 2500 Series Wireless Controller also support multiple AP-managers (for AP Load Balancing) where multiple AP-managers can be configured in addition to an AP-manager which is bounded with a management interface. In this case, it is recommended to have all AP-managers in the same subnet as a management interface.
>show interface summary Interface Name Port Vlan Id IP Address Type Ap Mgr Guest --------------------- ---- -------- -------------- ------- ------ ----- apmgr2 2 10 10.10.10.12 Dynamic Yes No apmgr3 3 10 10.10.10.13 Dynamic Yes No apmgr4 4 10 10.10.10.14 Dynamic Yes No management 1 10 10.10.10.10 Static Yes No virtual N/A N/A 1.1.1.1 Static No No >
In the above output, the management interface and AP-manager are bounded together to port 1. Three more AP-managers are created on other physical ports (2, 3, and 4) in the same subnet as management interfaces.
01-04-2012 02:05 PM
How many ap's do you have? If you don't have a lot, there is no need to have multiple. You can if you want though.
01-04-2012 02:01 PM
Correct.... but then you have to enable ap-manager on each interface.
01-04-2012 02:04 PM
Dynamic AP Manament? Or some other setting.
01-04-2012 02:06 PM
Dynamic AP Management.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide