12-05-2011 07:45 AM - edited 07-03-2021 09:10 PM
hi there,
I have a WLC 5508. The service port is on the main "office" VLAN - i.e. the same subnet as all the servers etc.
We currently use sub-interfaces for all of the different vlans.
I'm trying to create a new wireless network for the "office" VLAN but whenever I go to create another interface it won't let me set one on the "office" subnet "conflicts with another interface".
Does anyone know a way around this? Am more than happy to provide more info.
I will include some screenshots.
-Al
Solved! Go to Solution.
12-05-2011 09:09 AM
You can by enable management via dynamic interface.
config network mgmt-via-dynamic-interface
Sent from my iPhone
12-05-2011 07:55 AM
The service port is out of band management and you cant have routing between the service port and the management interface.
Sent from my iPhone
12-05-2011 08:50 AM
Thanks Scott. So I guess I need to move the service port onto another subnet. Seems obvious now I think about it!
12-05-2011 09:04 AM
Well usually you don't connect the service port on the network. If you do, it should connect to a non routable subnet. Basically you would use it if you lost connection the the wlc and you want to be able to GUI or telnet/ssh to the
Q. How do we access the WLC when the network is down?
A. When the network is down, the WLC can be accessed by the service port. This port is assigned an IP address in an entirely different subnet from other ports of the WLC and so is called out-of-band management. For more information, refer the Configuring Ports and Interfaces section of the Cisco Wireless LAN Controller Configuration Guide, Release 7.0.116.0.
Sent from my iPhone
12-05-2011 09:06 AM
Thanks again. Do you know if you can configure the WLC to allow management from interfaces other than "management" and the "service port"?
12-05-2011 09:09 AM
You can by enable management via dynamic interface.
config network mgmt-via-dynamic-interface
Sent from my iPhone
12-05-2011 09:12 AM
thanks again.
12-05-2011 09:26 AM
Some folks will still IP the service port and put it on the network just incase they lose mangament of the WLC. but as Scott mentioned you will want to make sure you limit its routing to the managment interface, other wise you will see issues.
12-05-2011 10:10 AM
Sorry I might have been unclear earlier.
What I wanted to know was whether you can logon to the management web console from interfaces other than "management" and "service port"?
12-05-2011 10:16 AM
You can if you enable management via dynamic interface. Basically this allows you to https to the ip of your dynamic interface if you have one. Other than that, it's the management an service port only.
Sent from Cisco Technical Support iPhone App
12-05-2011 10:25 AM
thanks again Scott.
12-05-2011 10:33 AM
No problem.
Sent from my iPhone
12-05-2011 04:47 PM
You want to be careful, if you have a guest network on the inside. You might not want users hitting that inside interface.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide