⚠️ WLC menus below follow Cisco AireOS controllers (like the 3504 and 5520) used in CCNA study material. Exact names vary by release. The switch commands are Cisco IOS / IOS XE. Nothing here was run in a lab.
A real-life situation
A new WLC1 arrives for the lab office. AP1 is already on SW1 port Gi1/0/10 in VLAN 30. Staff laptops must land in VLAN 10 (10.10.10.0/24) and guests in VLAN 20 (10.10.20.0/24). Your job: cable WLC1 to SW1, give it its addresses, and create the Staff and Guest WLANs.
- 1. AP1 joins WLC1. AP1 (10.10.30.21) builds CAPWAP tunnels to WLC1's management interface, 10.10.99.10.
- 2. A laptop joins WLAN Staff. Its frames reach WLC1 inside the CAPWAP data tunnel.
- 3. WLC1 maps WLAN Staff to VLAN 10. The Staff WLAN uses the dynamic interface 'staff' (VLAN 10). WLC1 sends the frame on the trunk tagged 10; SW1 routes it.
- 4. Authentication goes to RADIUS. For 802.1X WLANs, WLC1 talks to the RADIUS server at 10.10.99.50 from its management address.
What a WLC is made of: ports and interfaces
A WLC has ports (physical connectors) and interfaces (logical addresses in a VLAN, a bit like SVIs). This split is the part most people mix up.
Physical ports
| Port | Purpose |
|---|---|
| Distribution system (DS) ports | The normal data ports. They connect to the switch, usually as 802.1Q trunks, and carry CAPWAP, client traffic and management. |
| Service port | Out-of-band management (OOB). An access port, no VLAN tags. Still works if the DS ports have a problem. |
| Redundancy port | Connects to a second WLC for high availability (HA SSO). |
| Console port | Serial CLI access, for first setup and recovery. |
Logical interfaces
| Interface | Purpose | This lab |
|---|---|---|
| Management | In-band management (GUI, SSH), RADIUS, and the end point of CAPWAP tunnels from APs. | 10.10.99.10, VLAN 99 |
| Dynamic | One per client VLAN. A WLAN mapped to it puts its clients in that VLAN. You create as many as you need. | staff 10.10.10.5 VLAN 10, guest 10.10.20.5 VLAN 20 |
| Virtual | A fake, non-routed address shared by all WLCs in a mobility group: DHCP relay, web-auth redirects, mobility. | 192.0.2.1 |
| Service port | The address of the service port, in a separate management subnet. | optional |
| Redundancy management | Used with HA to reach the standby WLC. | not used |
Why it is built this way
The WLC is the meeting point between radio and wire. A WLAN is just a name and a set of rules. It needs to be "anchored" to a VLAN so clients get a normal address from the normal DHCP server and use the normal gateway (SW1). The dynamic interface is that anchor. This lets you put staff and guests on different VLANs and filter them with different ACLs, exactly like wired users.
LAG exists for the same reason as EtherChannel: one cable is a single point of failure and a bottleneck. With LAG, all DS ports act as one link, and every interface uses the LAG.
How to configure it, step by step
Step 1: the switch side (Cisco IOS)
AireOS LAG is static: it doesn't speak LACP or PAgP. So SW1 must use mode on. The trunk must carry the management VLAN and every client VLAN.
vlan 10
name STAFF
vlan 20
name GUEST
vlan 99
name MGMT
!
interface range GigabitEthernet1/0/1 - 2
description WLC1 DS ports 1-2
switchport mode trunk
switchport trunk allowed vlan 10,20,99
channel-group 1 mode on
!
interface Port-channel1
description WLC1 LAG
switchport mode trunk
switchport trunk allowed vlan 10,20,99
!
port-channel load-balance src-dst-ipOn SW1. 'mode on' because the WLC's LAG does not negotiate. SW1 already has SVIs 10.10.10.1, 10.10.20.1 and 10.10.99.1 as gateways.
Step 2: first boot and the management interface
A new AireOS WLC starts a setup wizard on the console (newer releases also offer a web wizard). It asks for the system name, an admin user and password, the service port address, the management interface (IP, mask, gateway, VLAN), the virtual interface address, the mobility group, a first WLAN, the country code, and NTP. For the lab:
| Wizard field | Value |
|---|---|
| System name | WLC1 |
| Management interface IP / mask | 10.10.99.10 / 255.255.255.0 |
| Default router | 10.10.99.1 |
| Management VLAN | 99 (tagged; 0 would mean untagged) |
| Virtual gateway IP | 192.0.2.1 |
| Country | Your country (sets the legal channels and power) |
Step 3: turn on LAG
In the GUI: CONTROLLER › General › LAG Mode on next reboot: Enabled, click Apply, save, and reboot. After the reboot all DS ports are one LAG, and each interface shows LAG as its port. There is only one LAG per WLC.
Step 4: create the dynamic interfaces
CONTROLLER › Interfaces › New. Enter the name and VLAN, click Apply, then fill in the details page:
| Field | staff | guest |
|---|---|---|
| Interface Name | staff | guest |
| VLAN Id | 10 | 20 |
| IP Address / Netmask | 10.10.10.5 / 255.255.255.0 | 10.10.20.5 / 255.255.255.0 |
| Gateway | 10.10.10.1 | 10.10.20.1 |
| Primary DHCP Server | 10.10.99.1 (SW1) | 10.10.99.1 (SW1) |
The WLC relays client DHCP requests to that server, much like ip helper-address on a router.
Step 5: create the WLAN
WLANs › Create New › Go. Choose Type WLAN, enter a Profile Name and an SSID, pick an ID, and click Apply. The edit page has four tabs:
| Tab | Key settings | Staff WLAN |
|---|---|---|
| General | Status (Enabled), Radio Policy (which bands), Interface/Interface Group, Broadcast SSID | Enabled, all bands, interface staff |
| Security | Layer 2 (WPA2/WPA3, PSK or 802.1X), Layer 3 (web authentication), AAA Servers | WPA2 + WPA3, 802.1X, RADIUS 10.10.99.50 (next lesson) |
| QoS | Platinum (voice), Gold (video), Silver (best effort, the default), Bronze (background) | Silver |
| Advanced | Allow AAA Override, session timeout, client exclusion, DHCP Addr. Assignment Required, FlexConnect Local Switching | Defaults |
A new WLAN is disabled until you tick Status: Enabled. Repeat for Guest with interface guest. Then Save Configuration (top right), or the WLC loses the changes on reboot.
The same can be done on the AireOS CLI. For example, the WLAN steps look like this:
config wlan create 1 Staff Staff
config wlan interface 1 staff
config wlan enable 1
save configAireOS CLI (prompt '(Cisco Controller) >'). Creates WLAN ID 1 with profile and SSID Staff, maps it to the staff interface, enables it and saves.
On a Catalyst 9800 (IOS XE) controller the same idea is split into profiles: a WLAN profile (SSID and security), a policy profile (VLAN and QoS), joined in a policy tag that is applied to APs. The CCNA mainly uses the AireOS screens.
Step 6: secure management access
| Setting | Where (AireOS GUI) | Recommended |
|---|---|---|
| HTTP / HTTPS GUI | MANAGEMENT › HTTP-HTTPS | HTTPS on, HTTP off |
| Telnet / SSH CLI | MANAGEMENT › Telnet-SSH | SSH on, Telnet off |
| Management from wireless clients | MANAGEMENT › Mgmt Via Wireless | Off (the default) |
| Admin logins against RADIUS/TACACS+ | SECURITY › AAA › TACACS+ or RADIUS, then SECURITY › Priority Order › Management User | Central AAA with local fallback |
| Limit who can reach the WLC itself | SECURITY › Access Control Lists › CPU Access Control Lists | Allow only admin subnets |
These follow the same logic as Passwords, local users and SSH on a router: encrypted access only, and central accounts.
How to verify it
SW1#show etherchannel summary Flags: D - down P - bundled in port-channel I - stand-alone s - suspended R - Layer3 S - Layer2 U - in use ... Group Port-channel Protocol Ports ------+-------------+-----------+----------------------------------------------- 1 Po1(SU) - Gi1/0/1(P) Gi1/0/2(P)
(Cisco Controller) >show interface summary Number of Interfaces.......................... 4 Interface Name Port Vlan Id IP Address Type Ap Mgr Guest -------------------------------- ---- -------- --------------- ------- ------ ----- guest LAG 20 10.10.20.5 Dynamic No No management LAG 99 10.10.99.10 Static Yes No staff LAG 10 10.10.10.5 Dynamic No No virtual N/A N/A 192.0.2.1 Static No No
(Cisco Controller) >show wlan summary Number of WLANs.................................. 2 WLAN ID WLAN Profile Name / SSID Status Interface Name ------- -------------------------------- -------- -------------------- 1 Staff / Staff Enabled staff 2 Guest / Guest Enabled guest
What goes wrong and how to troubleshoot it
| Symptom | Likely cause | Fix |
|---|---|---|
| WLC unreachable after enabling LAG | Switch uses LACP (active) or PAgP; the WLC doesn't negotiate | Use channel-group 1 mode on |
| SSID not visible | WLAN status disabled, or Broadcast SSID off | General tab: Status Enabled |
| Clients connect but get no IP address | Client VLAN not allowed on the trunk, wrong VLAN ID on the dynamic interface, or no DHCP server set | show interfaces trunk on SW1; check the interface page |
| Clients get an address in the wrong subnet | WLAN mapped to the wrong interface | WLAN General tab › Interface |
| Management VLAN works only untagged | VLAN set to 99 on the WLC but native VLAN 99 on the switch (or the reverse) | Make both sides agree: tagged on both or untagged on both |
| Changes gone after a reboot | Configuration not saved | Save Configuration / save config |
Common mistakes
- Confusing ports and interfaces. Ports are physical; interfaces are logical, VLAN-based addresses.
- Using LACP active on the switch toward an AireOS WLC. LAG is static only.
- Forgetting to allow client VLANs on the trunk to the WLC.
- Giving the virtual interface a real, routed address that is used elsewhere.
- Leaving HTTP and Telnet enabled for management.
💡 Exam tip: know the WLC port types (DS, service, redundancy, console) and the interface types (management, dynamic, virtual, service port, redundancy management). Expect a question that LAG uses mode on (no LACP/PAgP) and bundles all DS ports. Be ready to recognise the WLAN tabs (General, Security, QoS, Advanced) and the QoS levels Platinum, Gold, Silver, Bronze.
Key takeaways
- Ports are physical; interfaces are logical addresses in VLANs.
- The management interface handles GUI/SSH, RADIUS and CAPWAP from APs.
- A WLAN is mapped to a dynamic interface, which decides the client VLAN.
- LAG bundles all DS ports; the switch uses
channel-group … mode on. - Create a WLAN in WLANs › Create New, enable it, and save the configuration.
Check yourself
Which WLC object decides which VLAN the clients of a WLAN are placed in?
SW1's ports to an AireOS WLC are configured with 'channel-group 1 mode active'. LAG is enabled on the WLC. What happens?
Which interface do APs build their CAPWAP tunnels to on an AireOS WLC?
A new WLAN has been created and mapped to an interface, but no client can see the SSID. What is the first thing to check?
Which port gives out-of-band management access to the WLC?