04-09-2012 06:59 AM - edited 07-03-2021 09:58 PM
Hello,
I need to replace a 4402 with a 2504 controller and put a 2504 controller in the DMZ for guest access. This would be the setup:
The 4402 would be replaced at a remote site (not hreap) and support a couple of wlans, one of those would not be local and would be anchored back to the 2504 in the DMZ for the guest services. All of my 5508's also would be hitting the 2504-DMZ to anchor the guest service as well. Is this still feesable in the 2504 series? I ask because I saw somewhere (albiet I cant find it again) that said you could not do anchors on the 2504 series?
Thanks,
Raun
Solved! Go to Solution.
02-06-2013 09:03 AM
Looks like the answer about 2500 series being used as a guest anchor has changed:
A. Yes, starting Cisco Unified Wireless Network Software Release 7.4, the Cisco 2500 Series Wireless LAN Controller can terminate (up to 15 EoIP tunnels) guest traffic outside the firewall. The Cisco 2000 Series Wireless LAN Controller can only originate guest tunnels.
Reference: http://tiny.cc/d8ejcw
04-09-2012 07:42 PM
Talked to my SE, for everyone else, a 2504 can not be an anchor controller, but can connect to anchor for things such as guest access.
04-09-2012 11:42 PM
That is true. 2504 can not be an anchor. it can only be a foreign WLC that configured (for some SSIDs) with some other anchor.
Q. Can the Cisco 2100/2500 Series Wireless LAN Controller be used as a guest anchor controller in the unsecured network area?
A. No. The Cisco 2100/2500 Series Wireless LAN Controller cannot terminate guest traffic outside the firewall. The Cisco 2000 Series Wireless LAN Controller can only originate guest tunnels.
Reference: http://tiny.cc/d8ejcw
02-06-2013 09:03 AM
Looks like the answer about 2500 series being used as a guest anchor has changed:
A. Yes, starting Cisco Unified Wireless Network Software Release 7.4, the Cisco 2500 Series Wireless LAN Controller can terminate (up to 15 EoIP tunnels) guest traffic outside the firewall. The Cisco 2000 Series Wireless LAN Controller can only originate guest tunnels.
Reference: http://tiny.cc/d8ejcw
02-06-2013 10:13 AM
Yup, I had read this on 7.4. Unfortunately, you can't do wired guest anchor to the 2504 though. Somewhat limiting, in my opinion. Cisco trying to get you to buy that 5508 to throw in your dmz. Thanks for the reply!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide