Course menu

Course 7: Wireless for CCNALesson 2.4 (5 of 5 in this course)60 of 122 in the CCNA series

Lab: build a WLAN with a WLC

Connect a WLC with LAG, join an AP with DHCP option 43, create Staff and Guest WLANs on the right VLANs, and fix five faults.

Intermediate · 25 min read

What you will learn

After this lesson, you can connect a WLC and an AP to the switched network, create two WLANs mapped to the right VLANs, verify joins and clients, and find the faults that stop each step.

  • LAG
  • Option 43
  • WLANs and interfaces
  • Troubleshooting

A WLC (Wireless LAN Controller) centrally manages lightweight access points. APs join it over CAPWAP; it maps each WLAN (SSID) to a dynamic interface in a client VLAN and applies the WLAN's security, such as 802.1X with RADIUS or a pre-shared key.

In simple terms: The controller is the brain and the access points are the radios. You configure the wireless networks once on the controller, and every AP that joins it broadcasts them.

The situation

The network from the WLC configuration lesson is cabled but unconfigured. Staff laptops must land in VLAN 10 and authenticate with their usernames through RADIUS. Visitors use a shared password and must land in VLAN 20. AP1 sits in the AP VLAN, 30, and WLC1 is managed in VLAN 99.

SSID StaffGi1/0/10VLAN 30Gi1/0/1-2Po1 trunkGi1/0/20VLAN 99LaptopStaff · 10.10.10.50AP110.10.30.21SW1gateway .1 for each VLANWLC1mgmt 10.10.99.10RADIUS10.10.99.50
  1. 1. AP1 joins WLC1: From VLAN 30 (10.10.30.21) to the management interface 10.10.99.10.
  2. 2. Clients: Client traffic is tunnelled to WLC1, which puts Staff in VLAN 10 and Guest in VLAN 20 on its trunk.

Task 1: plan it

Show the plan
ItemValue
SW1 ↔ WLC1Po1, two ports, channel-group 1 mode on, trunk VLANs 10, 20, 99
SW1 ↔ AP1Gi1/0/10, access VLAN 30 (local-mode AP)
AP discoveryDHCP option 43 in the VLAN 30 pool, pointing to 10.10.99.10
Management interface10.10.99.10/24, VLAN 99, gateway 10.10.99.1
Dynamic interfacesstaff 10.10.10.5 VLAN 10 · guest 10.10.20.5 VLAN 20
WLAN 1 StaffWPA2/WPA3 Enterprise (802.1X), RADIUS 10.10.99.50, interface staff
WLAN 2 GuestWPA2 Personal (PSK), interface guest

Task 2: the switch side

Show the configuration
interface range GigabitEthernet1/0/1 - 2 switchport mode trunk switchport trunk allowed vlan 10,20,99 channel-group 1 mode on interface Port-channel1 switchport mode trunk switchport trunk allowed vlan 10,20,99 ! interface GigabitEthernet1/0/10 switchport mode access switchport access vlan 30 spanning-tree portfast ! ip dhcp pool AP-VLAN30 network 10.10.30.0 255.255.255.0 default-router 10.10.30.1 option 43 hex f1040a0a630a

LAG to the WLC must be mode on: AireOS LAG doesn't negotiate LACP or PAgP. 0a0a630a is 10.10.99.10 in hex.

Task 3: the WLC

In the GUI: CONTROLLER › Interfaces › New, then WLANs › Create New.

Show the settings
PageStaffGuest
Interface name / VLANstaff / 10guest / 20
Interface IP / gateway10.10.10.5 / 10.10.10.110.10.20.5 / 10.10.20.1
DHCP server10.10.99.110.10.99.1
WLAN: SSID, statusStaff, EnabledGuest, Enabled
General › Interfacestaffguest
Security › Layer 2WPA2 + WPA3, AKM 802.1XWPA2, AKM PSK, passphrase
Security › AAA ServersRADIUS 10.10.99.50None

The RADIUS server also needs WLC1 (10.10.99.10) added as a client with the same shared secret, or every Staff login fails.

Task 4: verify

Example output · based on Cisco documentation; exact format varies by platform and software version
(Cisco Controller) >show wlan summary
Number of WLANs.................................. 2

WLAN ID  WLAN Profile Name / SSID          Status    Interface Name
-------  --------------------------------  --------  --------------------
1        Staff / Staff                     Enabled   staff
2        Guest / Guest                     Enabled   guest
Example output · based on Cisco documentation; exact format varies by platform and software version
(Cisco Controller) >show ap summary
Number of APs.................................... 1

AP Name    Slots  AP Model              Ethernet MAC       Location   Country  IP Address     Clients
---------  -----  --------------------  -----------------  ---------  -------  -------------  -------
AP1        2      AIR-AP2802I-B-K9      a4:b2:3c:11:22:01  Floor 1    US       10.10.30.21    2
AP1 has joined from its VLAN 30 address. (Example output; columns trimmed.)
Example output · based on Cisco documentation; exact format varies by platform and software version
(Cisco Controller) >show client summary
Number of Clients................................ 2

MAC Address       AP Name          Slot Status      WLAN Auth Protocol          Port Wired Role
----------------- ---------------- ---- ----------- ---- ---- ----------------- ---- ----- -----
3c:22:fb:1a:2b:3c AP1              1    Associated  1    Yes  802.11ax(5 GHz)   13   No    Local
3c:22:fb:4d:5e:6f AP1              0    Associated  2    Yes  802.11n(2.4 GHz)  13   No    Local
One client on each WLAN, both authenticated.

Find the fault

Fault 1

AP1 gets 10.10.30.21 from DHCP, but never appears in show ap summary. The pool contains option 43 hex f1040a0a6314.

Show diagnosis

0a0a6314 is 10.10.99.20, not .10: option 43 points AP1 at the wrong controller. Fix: option 43 hex f1040a0a630a, then let the AP renew.

Fault 2

Staff laptops connect but get 10.10.20.x addresses.

Show diagnosis

WLAN 1 is mapped to the guest interface. show wlan summary would show it. Fix: General › Interface = staff.

Fault 3

Guests associate and authenticate, but never get an IP address. Staff work.

Show diagnosis

VLAN 20 isn't allowed on Po1 (or on its member ports), so the WLC's DHCP requests for guests never reach SW1. Fix: switchport trunk allowed vlan add 20 on Po1 and its members.

Fault 4

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show etherchannel summary | begin Group
Group  Port-channel  Protocol    Ports
------+-------------+-----------+-----------------------------------------------
1      Po1(SD)         LACP      Gi1/0/1(I)  Gi1/0/2(I)
Show diagnosis

SW1 uses channel-group 1 mode active (LACP). The WLC doesn't speak LACP, so no bundle forms. Fix: channel-group 1 mode on.

Fault 5

Every Staff login fails; Guest works. The RADIUS server's log shows requests from 10.10.99.10 rejected for an unknown client.

Show diagnosis

WLC1 isn't defined as a RADIUS client on the server (or the shared secrets differ). Fix: add 10.10.99.10 with the same secret as configured on the WLC.

Check yourself

Predict · scenario 1

Which WLC setting decides which VLAN a WLAN's clients are placed in?

Predict · scenario 2

How must the switch side of an AireOS WLC LAG be configured?

Predict · scenario 3

AP1 is in VLAN 30 and WLC1 in VLAN 99. How does AP1 find WLC1 in this lab?