Routelearn.net
Course menu

Course 7: Wireless for CCNALesson 2.2 (3 of 4 in this course)48 of 91 in the CCNA series

WLC configuration

Ports and interfaces on a Wireless LAN Controller, creating a WLAN, and connecting APs, step by step through the GUI.

Intermediate · 12 min read

WLC (Wireless LAN Controller) is a device that centrally configures and manages lightweight access points. Through its physical ports and logical interfaces it maps each WLAN (SSID) to a wired VLAN, and it pushes WLAN, security and radio settings to the APs that join it over CAPWAP.

In simple terms: Instead of setting up each access point by hand, you configure the Wi-Fi once on the controller and it hands the settings to all of its APs.

⚠️ WLC menus below follow Cisco AireOS controllers (like the 3504 and 5520) used in CCNA study material. Exact names vary by release. The switch commands are Cisco IOS / IOS XE. Nothing here was run in a lab.

A real-life situation

A new WLC1 arrives for the lab office. AP1 is already on SW1 port Gi1/0/10 in VLAN 30. Staff laptops must land in VLAN 10 (10.10.10.0/24) and guests in VLAN 20 (10.10.20.0/24). Your job: cable WLC1 to SW1, give it its addresses, and create the Staff and Guest WLANs.

SSID StaffGi1/0/10VLAN 30Gi1/0/1-2Po1 trunkGi1/0/20VLAN 99LaptopStaff · 10.10.10.50AP110.10.30.21SW1gateway .1 for each VLANWLC1mgmt 10.10.99.10RADIUS10.10.99.50
  1. 1. AP1 joins WLC1. AP1 (10.10.30.21) builds CAPWAP tunnels to WLC1's management interface, 10.10.99.10.
  2. 2. A laptop joins WLAN Staff. Its frames reach WLC1 inside the CAPWAP data tunnel.
  3. 3. WLC1 maps WLAN Staff to VLAN 10. The Staff WLAN uses the dynamic interface 'staff' (VLAN 10). WLC1 sends the frame on the trunk tagged 10; SW1 routes it.
  4. 4. Authentication goes to RADIUS. For 802.1X WLANs, WLC1 talks to the RADIUS server at 10.10.99.50 from its management address.

What a WLC is made of: ports and interfaces

A WLC has ports (physical connectors) and interfaces (logical addresses in a VLAN, a bit like SVIs). This split is the part most people mix up.

Physical ports

PortPurpose
Distribution system (DS) portsThe normal data ports. They connect to the switch, usually as 802.1Q trunks, and carry CAPWAP, client traffic and management.
Service portOut-of-band management (OOB). An access port, no VLAN tags. Still works if the DS ports have a problem.
Redundancy portConnects to a second WLC for high availability (HA SSO).
Console portSerial CLI access, for first setup and recovery.

Logical interfaces

InterfacePurposeThis lab
ManagementIn-band management (GUI, SSH), RADIUS, and the end point of CAPWAP tunnels from APs.10.10.99.10, VLAN 99
DynamicOne per client VLAN. A WLAN mapped to it puts its clients in that VLAN. You create as many as you need.staff 10.10.10.5 VLAN 10, guest 10.10.20.5 VLAN 20
VirtualA fake, non-routed address shared by all WLCs in a mobility group: DHCP relay, web-auth redirects, mobility.192.0.2.1
Service portThe address of the service port, in a separate management subnet.optional
Redundancy managementUsed with HA to reach the standby WLC.not used
WLAN Staff
SSID Staff, ID 1
Interface staff
10.10.10.5/24
VLAN 10
802.1Q tag
LAG
DS ports 1-2 → SW1 Po1
How a client ends up in a VLAN: WLAN → interface → VLAN → port.

Why it is built this way

The WLC is the meeting point between radio and wire. A WLAN is just a name and a set of rules. It needs to be "anchored" to a VLAN so clients get a normal address from the normal DHCP server and use the normal gateway (SW1). The dynamic interface is that anchor. This lets you put staff and guests on different VLANs and filter them with different ACLs, exactly like wired users.

LAG exists for the same reason as EtherChannel: one cable is a single point of failure and a bottleneck. With LAG, all DS ports act as one link, and every interface uses the LAG.

How to configure it, step by step

Step 1: the switch side (Cisco IOS)

AireOS LAG is static: it doesn't speak LACP or PAgP. So SW1 must use mode on. The trunk must carry the management VLAN and every client VLAN.

vlan 10 name STAFF vlan 20 name GUEST vlan 99 name MGMT ! interface range GigabitEthernet1/0/1 - 2 description WLC1 DS ports 1-2 switchport mode trunk switchport trunk allowed vlan 10,20,99 channel-group 1 mode on ! interface Port-channel1 description WLC1 LAG switchport mode trunk switchport trunk allowed vlan 10,20,99 ! port-channel load-balance src-dst-ip

On SW1. 'mode on' because the WLC's LAG does not negotiate. SW1 already has SVIs 10.10.10.1, 10.10.20.1 and 10.10.99.1 as gateways.

Step 2: first boot and the management interface

A new AireOS WLC starts a setup wizard on the console (newer releases also offer a web wizard). It asks for the system name, an admin user and password, the service port address, the management interface (IP, mask, gateway, VLAN), the virtual interface address, the mobility group, a first WLAN, the country code, and NTP. For the lab:

Wizard fieldValue
System nameWLC1
Management interface IP / mask10.10.99.10 / 255.255.255.0
Default router10.10.99.1
Management VLAN99 (tagged; 0 would mean untagged)
Virtual gateway IP192.0.2.1
CountryYour country (sets the legal channels and power)

Step 3: turn on LAG

In the GUI: CONTROLLER › General › LAG Mode on next reboot: Enabled, click Apply, save, and reboot. After the reboot all DS ports are one LAG, and each interface shows LAG as its port. There is only one LAG per WLC.

Step 4: create the dynamic interfaces

CONTROLLER › Interfaces › New. Enter the name and VLAN, click Apply, then fill in the details page:

Fieldstaffguest
Interface Namestaffguest
VLAN Id1020
IP Address / Netmask10.10.10.5 / 255.255.255.010.10.20.5 / 255.255.255.0
Gateway10.10.10.110.10.20.1
Primary DHCP Server10.10.99.1 (SW1)10.10.99.1 (SW1)

The WLC relays client DHCP requests to that server, much like ip helper-address on a router.

Step 5: create the WLAN

WLANs › Create New › Go. Choose Type WLAN, enter a Profile Name and an SSID, pick an ID, and click Apply. The edit page has four tabs:

TabKey settingsStaff WLAN
GeneralStatus (Enabled), Radio Policy (which bands), Interface/Interface Group, Broadcast SSIDEnabled, all bands, interface staff
SecurityLayer 2 (WPA2/WPA3, PSK or 802.1X), Layer 3 (web authentication), AAA ServersWPA2 + WPA3, 802.1X, RADIUS 10.10.99.50 (next lesson)
QoSPlatinum (voice), Gold (video), Silver (best effort, the default), Bronze (background)Silver
AdvancedAllow AAA Override, session timeout, client exclusion, DHCP Addr. Assignment Required, FlexConnect Local SwitchingDefaults

A new WLAN is disabled until you tick Status: Enabled. Repeat for Guest with interface guest. Then Save Configuration (top right), or the WLC loses the changes on reboot.

The same can be done on the AireOS CLI. For example, the WLAN steps look like this:

config wlan create 1 Staff Staff config wlan interface 1 staff config wlan enable 1 save config

AireOS CLI (prompt '(Cisco Controller) >'). Creates WLAN ID 1 with profile and SSID Staff, maps it to the staff interface, enables it and saves.

On a Catalyst 9800 (IOS XE) controller the same idea is split into profiles: a WLAN profile (SSID and security), a policy profile (VLAN and QoS), joined in a policy tag that is applied to APs. The CCNA mainly uses the AireOS screens.

Step 6: secure management access

SettingWhere (AireOS GUI)Recommended
HTTP / HTTPS GUIMANAGEMENT › HTTP-HTTPSHTTPS on, HTTP off
Telnet / SSH CLIMANAGEMENT › Telnet-SSHSSH on, Telnet off
Management from wireless clientsMANAGEMENT › Mgmt Via WirelessOff (the default)
Admin logins against RADIUS/TACACS+SECURITY › AAA › TACACS+ or RADIUS, then SECURITY › Priority Order › Management UserCentral AAA with local fallback
Limit who can reach the WLC itselfSECURITY › Access Control Lists › CPU Access Control ListsAllow only admin subnets

These follow the same logic as Passwords, local users and SSH on a router: encrypted access only, and central accounts.

How to verify it

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show etherchannel summary
Flags:  D - down        P - bundled in port-channel
        I - stand-alone s - suspended
        R - Layer3      S - Layer2
        U - in use
...
Group  Port-channel  Protocol    Ports
------+-------------+-----------+-----------------------------------------------
1      Po1(SU)          -        Gi1/0/1(P)  Gi1/0/2(P)
On SW1: Po1 is up with both ports bundled. Protocol - means no negotiation (mode on), which is right for a WLC LAG.
Example output · based on Cisco documentation; exact format varies by platform and software version
(Cisco Controller) >show interface summary
Number of Interfaces.......................... 4

Interface Name                   Port Vlan Id  IP Address      Type    Ap Mgr Guest
-------------------------------- ---- -------- --------------- ------- ------ -----
guest                            LAG  20       10.10.20.5      Dynamic No     No
management                       LAG  99       10.10.99.10     Static  Yes    No
staff                            LAG  10       10.10.10.5      Dynamic No     No
virtual                          N/A  N/A      192.0.2.1       Static  No     No
Each interface uses LAG as its port. The management interface is also the AP manager (APs build CAPWAP to it). Dynamic interfaces are in their client VLANs.
Example output · based on Cisco documentation; exact format varies by platform and software version
(Cisco Controller) >show wlan summary
Number of WLANs.................................. 2

WLAN ID  WLAN Profile Name / SSID          Status    Interface Name
-------  --------------------------------  --------  --------------------
1        Staff / Staff                     Enabled   staff
2        Guest / Guest                     Enabled   guest
Both WLANs are enabled and mapped to the right interfaces. In the GUI, the WLANs page shows the same list.

What goes wrong and how to troubleshoot it

SymptomLikely causeFix
WLC unreachable after enabling LAGSwitch uses LACP (active) or PAgP; the WLC doesn't negotiateUse channel-group 1 mode on
SSID not visibleWLAN status disabled, or Broadcast SSID offGeneral tab: Status Enabled
Clients connect but get no IP addressClient VLAN not allowed on the trunk, wrong VLAN ID on the dynamic interface, or no DHCP server setshow interfaces trunk on SW1; check the interface page
Clients get an address in the wrong subnetWLAN mapped to the wrong interfaceWLAN General tab › Interface
Management VLAN works only untaggedVLAN set to 99 on the WLC but native VLAN 99 on the switch (or the reverse)Make both sides agree: tagged on both or untagged on both
Changes gone after a rebootConfiguration not savedSave Configuration / save config

Common mistakes

  • Confusing ports and interfaces. Ports are physical; interfaces are logical, VLAN-based addresses.
  • Using LACP active on the switch toward an AireOS WLC. LAG is static only.
  • Forgetting to allow client VLANs on the trunk to the WLC.
  • Giving the virtual interface a real, routed address that is used elsewhere.
  • Leaving HTTP and Telnet enabled for management.

💡 Exam tip: know the WLC port types (DS, service, redundancy, console) and the interface types (management, dynamic, virtual, service port, redundancy management). Expect a question that LAG uses mode on (no LACP/PAgP) and bundles all DS ports. Be ready to recognise the WLAN tabs (General, Security, QoS, Advanced) and the QoS levels Platinum, Gold, Silver, Bronze.

Key takeaways

  • Ports are physical; interfaces are logical addresses in VLANs.
  • The management interface handles GUI/SSH, RADIUS and CAPWAP from APs.
  • A WLAN is mapped to a dynamic interface, which decides the client VLAN.
  • LAG bundles all DS ports; the switch uses channel-group … mode on.
  • Create a WLAN in WLANs › Create New, enable it, and save the configuration.

Check yourself

Predict · scenario 1

Which WLC object decides which VLAN the clients of a WLAN are placed in?

Predict · scenario 2

SW1's ports to an AireOS WLC are configured with 'channel-group 1 mode active'. LAG is enabled on the WLC. What happens?

Predict · scenario 3

Which interface do APs build their CAPWAP tunnels to on an AireOS WLC?

Predict · scenario 4

A new WLAN has been created and mapped to an interface, but no client can see the SSID. What is the first thing to check?

Predict · scenario 5

Which port gives out-of-band management access to the WLC?

FAQ

Does LAG on a Cisco AireOS WLC use LACP?
No. AireOS LAG does not negotiate with LACP or PAgP, so the switch side must use channel-group mode on. All distribution system ports join one LAG, and enabling or disabling LAG needs a controller reboot.
What is a dynamic interface on a WLC?
A Layer 3 interface on the WLC in a client VLAN. You map a WLAN to it, and that decides which VLAN the wireless clients of that WLAN are placed in. It works like an SVI for client traffic.
What is the virtual interface used for?
It is a non-routed address that every WLC in a mobility group shares, used for DHCP relay to clients, web authentication redirects and mobility. Cisco recommends an address that is not used in your network, such as 192.0.2.1.