The situation
The network from the WLC configuration lesson is cabled but unconfigured. Staff laptops must land in VLAN 10 and authenticate with their usernames through RADIUS. Visitors use a shared password and must land in VLAN 20. AP1 sits in the AP VLAN, 30, and WLC1 is managed in VLAN 99.
- 1. AP1 joins WLC1: From VLAN 30 (10.10.30.21) to the management interface 10.10.99.10.
- 2. Clients: Client traffic is tunnelled to WLC1, which puts Staff in VLAN 10 and Guest in VLAN 20 on its trunk.
Task 1: plan it
Show the plan
| Item | Value |
|---|---|
| SW1 ↔ WLC1 | Po1, two ports, channel-group 1 mode on, trunk VLANs 10, 20, 99 |
| SW1 ↔ AP1 | Gi1/0/10, access VLAN 30 (local-mode AP) |
| AP discovery | DHCP option 43 in the VLAN 30 pool, pointing to 10.10.99.10 |
| Management interface | 10.10.99.10/24, VLAN 99, gateway 10.10.99.1 |
| Dynamic interfaces | staff 10.10.10.5 VLAN 10 · guest 10.10.20.5 VLAN 20 |
| WLAN 1 Staff | WPA2/WPA3 Enterprise (802.1X), RADIUS 10.10.99.50, interface staff |
| WLAN 2 Guest | WPA2 Personal (PSK), interface guest |
Task 2: the switch side
Show the configuration
interface range GigabitEthernet1/0/1 - 2
switchport mode trunk
switchport trunk allowed vlan 10,20,99
channel-group 1 mode on
interface Port-channel1
switchport mode trunk
switchport trunk allowed vlan 10,20,99
!
interface GigabitEthernet1/0/10
switchport mode access
switchport access vlan 30
spanning-tree portfast
!
ip dhcp pool AP-VLAN30
network 10.10.30.0 255.255.255.0
default-router 10.10.30.1
option 43 hex f1040a0a630aLAG to the WLC must be mode on: AireOS LAG doesn't negotiate LACP or PAgP. 0a0a630a is 10.10.99.10 in hex.
Task 3: the WLC
In the GUI: CONTROLLER › Interfaces › New, then WLANs › Create New.
Show the settings
| Page | Staff | Guest |
|---|---|---|
| Interface name / VLAN | staff / 10 | guest / 20 |
| Interface IP / gateway | 10.10.10.5 / 10.10.10.1 | 10.10.20.5 / 10.10.20.1 |
| DHCP server | 10.10.99.1 | 10.10.99.1 |
| WLAN: SSID, status | Staff, Enabled | Guest, Enabled |
| General › Interface | staff | guest |
| Security › Layer 2 | WPA2 + WPA3, AKM 802.1X | WPA2, AKM PSK, passphrase |
| Security › AAA Servers | RADIUS 10.10.99.50 | None |
The RADIUS server also needs WLC1 (10.10.99.10) added as a client with the same shared secret, or every Staff login fails.
Task 4: verify
(Cisco Controller) >show wlan summary Number of WLANs.................................. 2 WLAN ID WLAN Profile Name / SSID Status Interface Name ------- -------------------------------- -------- -------------------- 1 Staff / Staff Enabled staff 2 Guest / Guest Enabled guest
(Cisco Controller) >show ap summary Number of APs.................................... 1 AP Name Slots AP Model Ethernet MAC Location Country IP Address Clients --------- ----- -------------------- ----------------- --------- ------- ------------- ------- AP1 2 AIR-AP2802I-B-K9 a4:b2:3c:11:22:01 Floor 1 US 10.10.30.21 2
(Cisco Controller) >show client summary Number of Clients................................ 2 MAC Address AP Name Slot Status WLAN Auth Protocol Port Wired Role ----------------- ---------------- ---- ----------- ---- ---- ----------------- ---- ----- ----- 3c:22:fb:1a:2b:3c AP1 1 Associated 1 Yes 802.11ax(5 GHz) 13 No Local 3c:22:fb:4d:5e:6f AP1 0 Associated 2 Yes 802.11n(2.4 GHz) 13 No Local
Find the fault
Fault 1
AP1 gets 10.10.30.21 from DHCP, but never appears in show ap summary. The pool contains option 43 hex f1040a0a6314.
Show diagnosis
0a0a6314 is 10.10.99.20, not .10: option 43 points AP1 at the wrong controller. Fix: option 43 hex f1040a0a630a, then let the AP renew.
Fault 2
Staff laptops connect but get 10.10.20.x addresses.
Show diagnosis
WLAN 1 is mapped to the guest interface. show wlan summary would show it. Fix: General › Interface = staff.
Fault 3
Guests associate and authenticate, but never get an IP address. Staff work.
Show diagnosis
VLAN 20 isn't allowed on Po1 (or on its member ports), so the WLC's DHCP requests for guests never reach SW1. Fix: switchport trunk allowed vlan add 20 on Po1 and its members.
Fault 4
SW1#show etherchannel summary | begin Group Group Port-channel Protocol Ports ------+-------------+-----------+----------------------------------------------- 1 Po1(SD) LACP Gi1/0/1(I) Gi1/0/2(I)
Show diagnosis
SW1 uses channel-group 1 mode active (LACP). The WLC doesn't speak LACP, so no bundle forms. Fix: channel-group 1 mode on.
Fault 5
Every Staff login fails; Guest works. The RADIUS server's log shows requests from 10.10.99.10 rejected for an unknown client.
Show diagnosis
WLC1 isn't defined as a RADIUS client on the server (or the shared secrets differ). Fix: add 10.10.99.10 with the same secret as configured on the WLC.
Check yourself
Which WLC setting decides which VLAN a WLAN's clients are placed in?
How must the switch side of an AireOS WLC LAG be configured?
AP1 is in VLAN 30 and WLC1 in VLAN 99. How does AP1 find WLC1 in this lab?