Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

WLC and ap vlan communication

Hi,

I have a need to vlan tag traffic between my wlc and aps. I see where you can set this under controller -> interfaces -> management and ap-manager interfaces and vlan identifier. My question is...once this is done, how does the ap know to tag its traffic bound for the wlc? Is there a command I need to run on the ap? Or is there something I can do in the wlc software?

thanks,

6 REPLIES

Re: WLC and ap vlan communication

I would use a separate vlan identifier for the APs from my client SSID/WLANs. For the WLANs add a dynamic interface for each in the subnet it exists. Make sure to tag the appropriate vlan tag here. You can do the same thing for the APs on the mgt and AP mgr interfaces. Make sure all ports on the switches are trunked for appropriate vlans. oOnce this is done the APs get their configuration from the controller. You only must insure that they can discover the controller. You can achieve this through the use of option 43, DNS discovery, or priming the APs.

Community Member

Re: WLC and ap vlan communication

Thanks,

That's what I gathered from cisco's site when they said that lwapp ap's dont understand vlan tagging. So I just set them up in another subnet and used dns to find the CISCO-LWAPP-CONTROLLER. I have two wlans, one is a guest wlan that uses the cisco controller to authenticate. That one is working great with the new ap's. The other..however uses a microsoft ias server for auth. and that doesn't seem to be working with the new ap's in the other subnet. It does work fine with the other ap's though. Is there something I overlooked?

Community Member

Re: WLC and ap vlan communication

I do not know IAS but in Cisco ACS you need to add the network device and setup the secret key, this has been done?

Back to your original question: you do have your WCS, WLC and access points all on different VLAN's? Your clients should be on their own VLANS

Community Member

Re: WLC and ap vlan communication

are you using laps in reap mode or hreap? To my understanding you cant do multiple vlans with reap laps.

Community Member

Re: WLC and ap vlan communication

Actually it does work...just seems to connect slower on the different subnet.

thanks,

Community Member

Re: WLC and ap vlan communication

You should be connecting your APs to access ports, not trunks; so VLAN tagging is irrelevant (even if you were to tag it the switch would overwrite). The VLANs where clients are terminated are all defined on the WLCs (which is the client data ingress/egress point).

I'd double-check your RADIUS and IAS configuration, you should have only a single client for each WLC defined in your RADIUS server, and need only one RADIUS server defined on any given WLC (although once you have it working you should setup a secondary for redundancy). Remember, it's not the APs that are performing authentication, it's the WLCs.

Erik

372
Views
0
Helpful
6
Replies
CreatePlease to create content