A real-life situation
A company has one WLC at headquarters and twenty small branches. When branch APs run in local mode, a laptop printing to a printer two metres away sends every page across the WAN to headquarters and back. When the WAN link fails, the branch loses Wi-Fi completely. FlexConnect mode fixes both.
Local mode: everything goes to the WLC
Local mode is the default. The AP builds two CAPWAP tunnels to the WLC: one for control, one for data. Every client frame is encapsulated and sent to the WLC, which puts it into the client's VLAN there. The AP itself needs only one VLAN, for its own address, so its switch port is an access port. (Between serving clients, a local-mode AP briefly scans other channels for rogues and RF data.)
This is ideal on a campus, where the WLC is close: one place to apply policy, and clients keep their IP address when they roam between any APs.
FlexConnect: switch traffic at the branch
- 1. Locally switched WLAN: The AP puts the laptop's frames in VLAN 10 on its trunk; they reach the printer server without crossing the WAN.
- 2. Control (and centrally switched WLANs): Control traffic always goes to the WLC. Traffic for centrally switched WLANs is tunnelled there too.
A FlexConnect AP still joins the WLC with CAPWAP for control, but for WLANs set to local switching it bridges client traffic straight onto its switch port, in the VLAN mapped to that WLAN. Because client VLANs now leave the AP itself, its switch port is a trunk, with the native VLAN set to the AP's own management VLAN.
| FlexConnect state | Locally switched WLANs | Centrally switched WLANs |
|---|---|---|
| Connected (WLC reachable) | Work; authentication handled by the WLC | Work, tunnelled to the WLC |
| Standalone (WAN down) | Existing clients keep working; new clients can join with PSK, or 802.1X if local authentication is set up | Stop |
Switch port configuration
! Local-mode AP: one VLAN, for the AP's own address
interface GigabitEthernet1/0/10
switchport mode access
switchport access vlan 30
spanning-tree portfastClient traffic is inside CAPWAP, so the switch only sees the AP's VLAN.
! FlexConnect AP: AP VLAN untagged, client VLANs tagged
interface GigabitEthernet1/0/10
switchport mode trunk
switchport trunk native vlan 30
switchport trunk allowed vlan 10,20,30
spanning-tree portfast trunkThe AP sends its own traffic untagged (native VLAN 30) and tags locally switched client traffic with the VLAN mapped to each WLAN.
On an AireOS WLC: Wireless › All APs › AP-BR1 › General › AP Mode = FlexConnect, then on the WLAN Advanced › FlexConnect Local Switching, and the VLAN mapping on the AP's FlexConnect tab. On a Catalyst 9800 the same choices live in the flex profile and the policy profile (central switching disabled).
(Cisco Controller) >show ap config general AP-BR1 Cisco AP Name.................................... AP-BR1 ... AP Mode ......................................... FlexConnect ...
The other modes, and when to use them
| Mode | Serves clients? | Use it when |
|---|---|---|
| Monitor | No | You want full-time scanning on all channels for rogue APs, attacks (wIPS) and location tracking |
| Sniffer | No | You need a packet capture of one channel, sent to a PC running Wireshark |
| Rogue detector | No (radios off) | You want to find rogue APs plugged into the wired network; the AP watches ARP on a trunk |
| SE-Connect | No | You suspect non-Wi-Fi interference and need a remote spectrum analyser |
| Bridge / Mesh | Yes (optional) | APs must link to each other over the air (see topologies) |
| Flex+Bridge | Yes | A mesh at a branch that should also switch traffic locally |
Why it works this way
Central switching gives one point of control but makes every frame travel to the controller. That is cheap on a campus LAN and expensive over a WAN. FlexConnect splits the job: the WLC still manages the AP, but the data takes the shortest path, and the branch doesn't depend on the WAN for local traffic.
Common mistakes
- Leaving a FlexConnect AP on an access port: locally switched clients have no VLAN to land in.
- Setting the trunk's native VLAN to a client VLAN instead of the AP's VLAN, so the AP can't reach the WLC.
- Putting a monitor-mode AP where coverage is needed: it serves no clients.
💡 Exam tip: local mode = access port, everything to the WLC; FlexConnect = trunk port, local switching at the branch, survives a WAN outage.
Key takeaways
- Local mode tunnels all client traffic to the WLC; the AP sits on an access port.
- FlexConnect switches chosen WLANs locally; the AP sits on a trunk with its own VLAN native.
- In standalone mode, locally switched WLANs keep working while centrally switched ones stop.
- Monitor, sniffer, rogue detector and SE-Connect modes don't serve clients.
Check yourself
The WAN link to headquarters fails. Which branch WLANs keep working?
How should the switch port for a FlexConnect AP with two locally switched WLANs be configured?
You need a Wireshark capture of 802.11 frames on channel 36. Which mode?