Interface Group in WLC

Hi to who will see my case
I have WLC configured by 3 Interfaces groups , 5 interfaces for each group (each group used by one SSID) .
SSID-EMPLOYEE
     EMPLOYEE-GROUP
          -EMPLOYEE-INTEFCAE-1 DHCP is MS server 2003 (Scope 10.21.4.0/22)
          -EMPLOYEE-INTEFCAE-2 DHCP is MS server 2003 (Scope 10.21.8.0/22)
          -EMPLOYEE-INTEFCAE-3 DHCP is MS server 2003 (Scope 10.21.12.0/22)
          -EMPLOYEE-INTEFCAE-4 DHCP is MS server 2003 (Scope 10.21.16.0/22)
          -EMPLOYEE-INTEFCAE-5 DHCP is MS server 2003 (Scope 10.21.20.0/22)
and the same for SSID-STUDENT and SSID-VOICE.
My labtob sometimes connects with the EMPLOYEE-INTEFCAE-1 and sometime with the second interface  and so, How can I force it to connect with one interface all the time or how can I prevent the WLC to use the second interface as long as the first  interface is not full.
because I need to reserve an IP address in the DHCP server from the first scope for my labtob, once I connect to the network I will get the same reserverd Address , but in my case I reserved the IP but the controller forced my labtob to connect  the second interface and new scope.
Regards
Mahmoud

The interface group treats hosts in a similar fashion to round-robin.
1st host:group member 1
2nd host:group member 2
3rd...
4th...
until the last group member is reached and then it goes back to one.
Not sure if there is a way to force a host to a particular group member, unless of course you use a dedicated wlan bound to the particular subnet. This would not utilize the interface grouping though.
Perhaps  a NAC solution could add some control over which network the laptop lands in....

Similar Messages

  • ISE and WLC dynamic interface group assignment ?

    I have a somewhat large deployment coming up with several WLC dynamic interfaces assigned to an interface group, replicated across for multiple sites.  I understand that ISE can return the VLAN ID to the WLC to place the client in, but if I'm using interface groups, this seems to negate the usefulness of the interface group to load clients across multiple VLANs.  Not only that, but with the number of dynamic interfaces (VLAN ID's), multiplied by the number of sites, would seem to be overwhelming on the ISE side policy configuration.
    Is it possible for ISE to return an Interface name/group to the WLC instead of just a VLAN ID ?
    TIA

    I understand that WLC 7.2 code can now accept the interface group name as a AAA override, which is great, but it doesn't specify the AAA source (ISE vs. ACS).
    This is the example I'm questioning: (they use the VLAN ID only, instead of an interface name)
    http://www.cisco.com/en/US/products/ps10315/products_tech_note09186a0080bba10d.shtml#topic17
    Edit:
    Found the correct Attribute Under "Adv. Attribute Settings" in the Airspace Authorization Profiles (Airespace:Airespace-Interface-Name).

  • WLC Deleting Interface: Interface group is being used by AP Group

    When trying to delete an interface from an interface group, I am getting the error Interface group is being used by AP Group. Is there a way I can delete the interface?

    Or you can select another interface freeing the one up you want to delete and then delete it .. key here is that the WLC wont delete a interface that is tied to a WLAN ..
    "Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
    ‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."

  • 5508 WLC Interface Groups

    We have not configured or used interface groups in our wireless deployments, and I am just curious if there are any issues or caveats experienced with using these?  We have a few instances where we have setup a /23 network for a specific wlan.  I  undertsand this increases broadcasts.  Would interface groups be preferred over using a /23 or even maybe a /22 to accomodate addressing?

    By default, the WLC will not forward broadcast.  There are pro's an con's to interface groups... if your doing multicast, that can be an issue unless you specify an multicast vlan.  I have used interface groups because customer standardize on /24, so I would combine a bunch of /24's to create an interface group.  I have customers with /23 and /23 and others with no issues... but I look at it as on the wired side.  You okay with /23 and or /22 on the wired side?
    Thanks,
    Scott
    *****Help out other by using the rating system and marking answered questions as "Answered"*****

  • Question on Interface Groups and Mobility

    Hi everyone.
    I have a small question.
    I have two 5508 controllers with 6 Access Points (3 on each controller).  The network layout has one AP on one controller, one on the other, 45 degrees and about 100ft apart from each other.
    In this layout the clients roam from one AP to the other, one controller to the other, but there are certain times where the client loses connectivity to the network (layer 3). I don't see any disconnect or roaming messages in the controller logs, but the laptop shows a "!" sign in its wireless connection (win 7).
    It can take from a few seconds to several minutes for it to get an ip address and connectivity again.
    Now, for my setup:
    I have 3 interfaces with different VLANs, and an interface group that binds those 3 interfaces together. The interfaces are called the same on both controllers, and the interface group as well.
    The wlan number is the same, as the SSID configuration.
    The question is:
    When the client roams to the other controller, does it retain the same interface/VLAN configuration?  I have found documentation stating that when the user roams and the WLC has the same subnet, it goes with no issues, but it doesn't mention interface groups.  Could it be that in some handovers the client falls in a different VLAN even when it is in the same interface group?
    Thanks in advance for your help.

    Are these two WLC in same mobility group ? If that is the case clients should not change the IP when they roam from one WLC to another. Even in interface group configuration it should work like this.
    Here is sample config I did to test this out (I haven't use interface group, but as per my understanding It should not make any difference).
    http://mrncciew.com/2013/03/17/l3-inter-controller-roaming/
    HTH
    Rasika

  • Dynamic interface group assignment

    Wir testen aktuell das dynamische vlan assignment mit dem wlc (version 7.3.101) und dem microsoft nps server. das überschreiben der vlan id anhand einer zutreffenden netzwerkrichlinie funktioniert einwandfrei. nun stellt sich die frage, ob das überschreiben auch möglich ist, wenn auf dem wlc für eine ap-group eine interface gruppe anstelle eines einzelnen vlans definiert ist. hat jemand erfahrungen damit gemacht? konkret sieht der aufbau wie folgend aus:
    vlan 100-110 sind in als interface group01 zusammengefasst.
    unter ap groups ist eine ssid mit dieser interface gruppe01 konfiguriert.
    unter wlan ist eine ssid mit: radius server overwrite interface und: allow aaa override konfiguriert.
    auf dem nps gibt es eine zutreffende netzwerkrichtlinie mit radius attribute:
    framed-protocol = ppp
    service-type = Framed
    Tunnel-Medium-Type 802
    Tunnel-Pvt-Group-Id = gruppe01 (Name der Interface Gruppe, analog VLAN)
    Tunnel-Type = VLAN
    --> Wenn wir eine einfache VLAN ID angeben funktioniert es, mit dem Namen der Interface Gruppe funktioniert es nicht.
    Hat jemand erfahrung, ob das zuweisen einer interface gruppe per radius attribut möglich ist?

    Thank you for your answer.
    if i define a single vlan id, everything works fine. but we try to make this work with an interface group instead of a single vlan... i am not shure if this is possible or not.. i just read the following release notes:
    AAA Override Support for Interface Groups
    This release supports AAA override for interface groups.
    This feature extends the current access point group and AAA override architecture where access point groups and AAA override can be configured to override the interface group WLAN that the interface is mapped to. This is done with multiple interfaces using interface groups.
    so if i change the single vlan id from tunnel-private-group-id attribute to the interface group it doesnt work anymore...

  • FlexConnect & Interface Groups

    I have a WLC 5508 running 7.4.121.0 where several sites  have APs in FlexConnect mode.
    For those sites I also have interface groups (this is just an example, i have more than one group)
    Site 1 - Group 1 - vlan 110 (faculty) and vlan 112 (students)
    Site 2 - Group 2 - vlan 210 (faculty) and vlan 212 (students)
    Under WLAN -> Advanced -> AP Groups
    I select Site 1 Group Name and add a new WLAN SSID to Interface/Interface Group mapping.
    When I go to Wireless and select a FlexConnect AP from Site 1 and then go to the FlexConnect Tab -> VLAN Mappins the VLAN ID is wrong (neither 110 or 112). I can of course manually change it to 110 but then any clients on vlan 112 on that SSID can't connect to the network. 
    Is there a way to specific a VLAN ID when using Interface group and Flexconnect?

    Do you have configured local switching and use AAA overide to asign the VLAN for faculty and students? Else can you give some more information about the configuration.
    With local switching and VLAN AAA overide you need to create sub-interfaces on the AP's. You can do this in the Flexconnect group (one per site). Then go tho VLAN-ACL mapping and add the VLAN's you need on this site .

  • Change Interface to Interface Group for WLAN

    Hi Guys,
    We have 2 WISMs here and one WLAN connected to interface "Int1" and they are working fine. For now, we want to expand the IP addresses of this SSID, so we created several VLANs as well as some interfaces in WLC and created a interface group to contain all the interfaces (includes to original "Int1"). When we tried to change the interface to the interface group under that SSID, we found that the clients lost the connection. We even tried to put only the "Int1" in the interface group. Is there any way to expand the IP addresses without network outage? Thanks!

    Check the following link for proper interface grouping.
    http://mrncciew.com/2013/02/27/configuring-dynamic-interfaces-on-wlc/
    NOte:re-create and re-test the Int group with few Interface in the group and then add more.

  • Problem in QPM 4 with interface group async

    hi.i have a question.i have deployed my wan routers QoS without any software and now i have to deploy same one with QPM 4 and there is a problem.i want to assign a service policy to interface group async with qpm but it doesnt detect int group async and it detects all my async interfaces separately interface async 1/0 - 1/29. my QPM is patched with latest patches but when i fetch my running config from a router it detects that policy not under the interface group async but under each interface async X separately. how can i deploy a policy map under the interface group async not under separated async interfaces?? please help

    The service policy that you have applied to the multilink gets into
    affect only when the multilink is congested.
    Follow the URL for the configuration of the QOS :
    http://www.cisco.com/en/US/docs/ios/12_4/qos/configuration/guide/qslfisrl.html

  • WISM Interface Grouping with different subnets

    WISM v7.0 VLAN Select.
    Anyone can confirm if the VLANs subnet to be configured under interface group MUST be having the same subnet.
    Eg. VLAN1 - mask 255.255.255.248
          VLAN2 - mask 255.255.255.120
    Would these two VLANs be able to work together in interface grouping?
    Thanks in advance.
    Cheers,
    Wong

    The subnet mask doesn't matter, but the smaller subnet will ge marked dirty first since it is a smaller subner.
    Sent from Cisco Technical Support iPad App

  • Deleting Interface: Interface group is being used by AP Group

    When trying to delete an interface from the Interface Groups, I am getting an error "Interface group is being used by AP Group." Is there a way I can go in to delete the interface?

    Hi toupheng.her, thank you for using our forum, my name is Johnnatan I am part of the Small business Support community. In this case you need to disable all protocols or vlans where you are using the group that you want to delete, probably a vlan is using your group and that´s why you can´t delete it, then you will be able to delete it. You can also search ACL, VPN, NAT, etc... I hope you find this answer useful,
    *Please mark the question as Answered or rate it so other users can benefit from it"
    Greetings,
    Johnnatan Rodriguez Miranda.
    Cisco Network Support Engineer.

  • Interface Groups

    Force a device to a specific VLAN when using interface groups. A handful of devices need a static IP
    Sent from Cisco Technical Support iPad App

    You can force a device only if your using 802.1x and you are setup to use AAA Override. If its PSK, you can't force them on a specifics VLAN. You might be better off creating a new WLAN and have that only point to a specific interface.
    Sent from Cisco Technical Support iPhone App

  • Flexconnect - local-switching - Interface Groups - multiple subnets/vlans

    So I'm trying to setup an "interface-group-like" configuration on some Flexconnect APs with local switching enabled in order to support multiple subnets/VLANs linked to a single SSID.
    Does anyone know if this is possible or have any suggestions?
    I've tried:
    AP Groups - One SSID which would require central switching for it to be of use (I think).
    AP Groups - Creating an additional SSID and then placing the APs in a group per site. This works but is going to be difficult to manage if I have 400+ sites running this sort of setup.
    For reference, my end goal is to have multiple (400+) branch sites with the same WLAN mapped to 3 or 4 different VLANs in order to split the subnets up into smaller chunks (/23s or /24s). These VLANs are all switched locally and are uniform in numbering across all the sites from a layer 2 perspective.
    Thanks,
    Ric

    Interface groups is not an available feature on FlexConnect. FlexConnect doesn't support layer 3 roaming if devices roam from one FlexConnect ap to another and the wlan to vlan mappings are different. This is a limitation to FlexConnect along with a few others listed in the FlexConnect deployment guide.
    -Scott

  • Max # of dynamic interfaces on 4404 WLC

    Can anyone tell me if there is a limit to how many dynamic interfaces I can create on a 4404 WLC?
    I know that I can only have 16 SSIDs, so I have set up one SSID for my private network and am using AAA Override and configured my radius server to assign the different VLANs for each group. I have to create a dynamic interface for each individual VLAN and I just want to know if there is any kind of hard limit for the number of dynamic interfaces I can have so I don't run into a potential problem down the road.
    TIA,
    Deanna

    I was able to verify that you only can create up to 513 dymanic interfaces. This of course does not include your management, ap-manager or VIP.
    Hope this answers your question... it did for me... now I know!

  • RF Grouping problem WLC 5508

    Hi,
    We have a problem regarding RF Grouping between two WLC 5508.
    The two controllers have the same RF Group name,RF Grouping is enabled,they belong to the same mobility group,their management IP
    address is on the same subnet, they ping each other but they don't elect a Group Leader. Each one
    elects itself as the Group Leader.
    We have tried to place 2 APs,each belonging to different controller, close one to the other but nothing changed.
    Any help would be much appreciated.

    Hi Nicolas,
    Because we have an almost live network, we wouldn't like to go public with our configurations. Is there any other way we can send them to you?
    Thanks in advance,
    Theofilos

Maybe you are looking for

  • Apple ID 3rd Gen - sync new purchases

    I have the new 3rd generation Apple TV.  The movies that I owned before I bought it now show up under Moves > Purchased, but any movies I bought since then aren't showing up.  I can stream them from my computer if I keep my computer on, but I can't f

  • Data Execution Prevention problem on Windows with Safari

    Hi. I'm running Safari 5.1.2 on Windows Vista Business. Whenever I try to print a web page (any page) Windows reports a Data Execution Prevention and closes Safari. I can always print the same web page from IE. How do I fix?

  • Select List of Dates

    I want to select all dates between two dates and display the values within a column. e.g.: Date Range: January 1, 2003 - March 3rd, 2003 Result: Dates January 1, 2003 January 2, 2003 January 3, 2003 January 4, 2003 January 5, 2003 January 6, 2003 I d

  • AR Transaction/payment schedule maintance

    Hi all My client would like to update the due date on completed transactions in Oracle AR (11.5.8). As known, this can be done manually in the 'Transaction Summary -> Installments' screen in AR, but my client would like this task to be automated. My

  • Getting an iMac fixed in Mexico

    This is an interesting tale about Apple. I live in Mexico, Mazatlan to be exact. I have an iMac that I bought in February 2008 just before I moved here. It is broken and there appears there is no way to get it fixed in Mexico. I have tried for a mont