A real-life situation
A hospital has two WLCs, one per wing, each putting clients in its own subnet. A nurse walks from one wing to the other on a Wi-Fi phone call. If the phone simply joined the second wing as a new client, it would need a new IP address, and the call would drop. Roaming is the set of mechanisms that stops that happening.
Who decides to roam
The client decides, using its own rules: usually when the current AP's signal or signal-to-noise ratio falls below a threshold, or too many frames need retries. It then scans for other APs with the same SSID and reassociates to the best one. The network can only help: with good cell overlap (about 15–20% at −67 dBm for voice), and with hints from 802.11k and 802.11v.
Intra-controller roaming
Both APs are joined to the same WLC. The WLC already holds the client's entry, keys and VLAN, so it just updates which AP the client is behind. The client keeps its IP address; this is the simplest and fastest case.
Inter-controller roaming
The new AP belongs to a different WLC. The two WLCs must be in the same mobility group, so they trust each other and exchange client information over mobility tunnels.
- Layer 2 roam: both WLCs have the client's VLAN (the same subnet). The old WLC hands the client entry to the new one, which now owns the client completely. The IP address still works.
- Layer 3 roam: the new WLC puts that WLAN in a different subnet. The client keeps its old address, so its traffic must still enter the network at the old WLC. The original WLC becomes the anchor, the new one the foreign WLC, and the client's traffic travels between them in a mobility tunnel.
- 1. Before the roam: The laptop joined through AP1. WLC1 put it in VLAN 10 with address 10.10.10.50.
- 2. After the roam: AP2 belongs to WLC2, which uses VLAN 110 for this WLAN. WLC2 (foreign) tunnels the laptop's traffic to WLC1 (anchor), so 10.10.10.50 keeps working.
Fast roaming: 802.11r, k and v
With WPA2/WPA3-Enterprise, a full 802.1X authentication through RADIUS at every roam can take hundreds of milliseconds. Several amendments shorten or guide roaming:
| Method | What it does |
|---|---|
| PMK caching / OKC | Reuses the key from an earlier 802.1X authentication, so the client only repeats the four-way handshake |
| 802.11r (Fast BSS Transition, FT) | Derives keys for the next AP in advance and folds the key exchange into the authentication and reassociation frames; the roam takes a few frames |
| 802.11k (radio resource measurement) | The AP gives the client a neighbour report: a short list of nearby APs and channels, so it scans less |
| 802.11v (BSS transition management) | The network can suggest the client move to a better AP, for example when the current one is overloaded |
Why it works this way
An IP address belongs to a subnet, and a subnet lives in one place in the network. Rather than renumber the client, the controllers move or tunnel its traffic so the address stays valid. And because the client only sees radio signals, not the network design, the decision to roam stays with the client, guided by hints.
Common mistakes
- Thinking the AP or WLC moves the client. The client chooses; 802.11v can only suggest.
- Expecting inter-controller roaming without a mobility group configured on both WLCs.
- Turning on 802.11r for every client: some older devices fail to join an FT-only WLAN. Adaptive or mixed modes exist for that reason.
Key takeaways
- Roaming keeps the client's IP address while it changes AP; the client decides when.
- Intra-controller roams just update the WLC; Layer 2 inter-controller roams move the client entry.
- Layer 3 roams keep the client anchored at its original WLC, tunnelled from the foreign WLC.
- PMK caching and 802.11r speed up roams; 802.11k and v help clients choose an AP.
Check yourself
Which device decides when a client roams to another AP?
A client roams to an AP on another WLC that maps the WLAN to a different subnet. What keeps its IP address working?
Which amendment lets a client prepare keys for the next AP so it doesn't need a full 802.1X authentication?