WLC acting as a router??

Hi there,
We have one doubt about a question a customer has made us. Is it possible to create 2 WLAN, associate them to corresponding VLAN, but only trunking the management VLAN to the switches?
This scenario is for the WLC like been a router, because the WLC knows two VLAN with their ip addressing scheme in one side, and in the other side it's connected to the DMZ with an untagged VLAN, different from the other two.
I think it's not possible to deploy an scenario like this, but I'm not 100% sure, even with another manufacturer, but this is not the case.
Any help would be appreciated.

The WLC doesn't not act as a router and only bridges traffic.  What you can do is define port 1 of the WLC as primary for the management interface and for the guest interface define port 2 as the primary.  Now you can define the management as port 1 as the primary and port 2 as the backup and use port 3 as the primary for guest and port 4 as the backup for guest.  Then on the trunk port on the switch, only allow the management vlan on port 1 and 2 and guest vlan for port 3 and 4 on the switch.  You will still need a router for the guest vlan as the WLC will not do any NAT translations.
Thanks,
Scott
Help out other by using the rating system and marking answered questions as "Answered"

Similar Messages

  • Will apple tv act like a router?

    Will the apple tv (2nd gen) act like a router if I connect my smart tv to it via the ethernet cable?
    I know this is a long shot but seeing as how the apple tv is connect via the wireless it would save me running a network cable or network adapter to the tv which isn't wireless.
    Applekwacker

    The ATV is not a router and cannot act as one.

  • WLC Guest Access Internet Routing

    Not sure if this the right forum, but i'm wondering if anyone can explain this.
    I have a trunk from the wlc to my router with one switch in between. 
    wlc---trunk----3560---trunk---2821
    The interface on the wlc and the 2821 both have an ip address and can ping each other.  When a wireless client connects to the guest network they cannot access the internet unless the 3560 switch has an ip address set on the vlan that is trunked from the wlc to the router
    wlc(vlan 825 - 10.7.200.2)----trunk-----3560(vlan 825 - 10.7.200.3)-----trunk-----2821(vlan825 - 10.7.200.1)
    The gateway for the clients is 10.7.200.1 which is the router.  If i take the ip address off of the vlan interface on the 3560 the trunk is still there, but the clients on the guest network cannot get through.  The gateway on the interface on the wlc is also set to 10.7.200.1
    Any ideas why I need that ip address on the 3560?
    Dan.

    Hi Dan,
    you may send the switch "show tech" and the WLC "show run-config" taken with the problematic config for a quick look.
    Regards,
    Federico

  • Performance of layer 3 switches when they are acting like a router

    Hi everybody
    I want to know what are the performance differences of layer 3 switches when they are acting just like a router with lots of route entries in their routing table in compare to when they are acting in layer 2?
    The layer 3 switch in our case is “WS-C3750X-24T-S”
    I guess there is a difference between these two situations:
    when the switch is acting in layer 3 and just routes packet between different VLAN (in routing table we just have entries for connected interfaces and nothing else)
    when the switch is acting in layer 3 and also has to do routing based on static routes or routes learned via a routing table
    I think in situation 1 the switch performance is just like when it is acting in layer 2 but I don’t know about situation 2. Does anyone know about this?
    Thanks a lot

    Hello.
    Actually there is no difference unless you reach a capacity limit of routing table and other TCAM entries.
    Also you need to note that some IOSs do not support full (but stub only) EIGRP functionality.
    PS: see details regarding routing capacity.

  • "Having a cluster node act as a router is not supported by Sun Cluster"

    Hello,
    can someone please explain me the rationale behind the above statement?
    I need to enable ip_forwarding in the kernel and would like to understand what "not supported"
    means exactly (i.e. what the involved risks are).
    I have a 2 node Solaris 9 / SC 3.1 cluster runnning with ip_forwarding = 1 since more than 2 years
    wirhout a problem, at least that I am aware of :-)
    Thanks in advance,
    Rick

    Correct, I only use failover addresses (Logical Hostnames), glad to know it is safe to have routing in this case!!
    I think you should mention that in the docs, and maybe in scinstall (which, right now, just touches /etc/notrouter
    and says "please DO NOT enable routing" :-))
    Thanks for the explanation, I really appreciated it.
    Best,
    Rick

  • Accessing a USB drive attached to ISP gateway which is behind an Airport Express acting as a router

    I have a Fritzbox 7362 SL provided to me by my (German) ISP, my German is not very good, so I am struggling with the documentation for the device.
    A useful feature is its ability to accept USB drives or thumbdrives which is marketed as a 'NAS' drive. So far I am able to access the attached thumb drive through the browser interface, but I am having trouble figuring out how to transfer files on to the thumb drive without removing it from the gateway and plugging it in to my MBP - the WiFi on the gateway is switched off and an Airport Express is the only wireless router in operation at the moment.
    The thumb drive shows in Finder, but clicking on it brings up the PC icon which normally shows for non Macs on the same network, then it tries to connect, but the only message that comes back is 'connection failed'. Clicking on the 'Connect As' button brings up the 'Guest' or 'Registered User' options, neither of which work. What Name / Password do I need to connect? The server is called 'fritz-nas' At present my name as it appears on my Mac user account shows up in the Name field.

    All that I can provide is what has worked for me for years.
    The Time Capsule is setup as the router for the network, connected to a simple Zoom 5431J cable modem.
    Static Internet IP connection from the cable provider is 12.34.567.89
    By default, the Time Capsule is at 10.0.1.1 on the local network
    Port Mapping setup for the Time Capsule is......
    Public UDP Port 8884
    Public TCP Ports 8884
    Private IP 10.0.1.1
    Private UDP 548
    Private TCP 548
    The hard drive on the Time Capsule is accessed from a remote location at afp://12.34.567.89:8884
    The AirPort Extreme is connected by Ethernet to the Time Capsule and is it setup to operate in Bridge Mode
    The AirPort Extreme always receives a reserved local IP address of 10.0.1.2 from the Time Capsule
    The Port Mapping setup (on the Time Capsule) looks like this for the AirPort Extreme.......
    Public UDP Port 8888
    Public TCP Port 8888
    Private IP  10.0.1.2
    Private UDP 548
    Private TCP 548
    The USB hard drive connected to the AirPort Extreme is accessed from a remote location at afp://12.34.567.89:8888
    If you are still having difficulty, I would delete all of Port Mapping settings on the Time Capsule and Update the Time Capsule. Then, go back and setup the Port Mapping for the Time Capsule, check that to make sure that it is working, then setup the Port Mapping settings on the Time Capsule for the AirPort Extreme.

  • Can i conect a extreme via the rj45 and still extend my wireless  to another main extreme acting as the router?

    Can I connect a extreme using the rj45 and still extend my wireless to another time capsule working as the router?

    Yes, that should be possible. I am assuming that you have the first AirPort connected to the Internet modem or another router by Ethernet and you want to extend it with another AirPort.

  • IMac acting as wireless router??

    I just upgraded to an iMac intel 20" and was going to buy an airport express. I then started playing around on it and saw that there was a way to share the internet on my iMac. Is this any different from an airport express? Should I not do that?
    Thanks

    Your iMac supports sharing its Internet connection wirelessly, but some functions of the base station aren't available, such as AirTunes, and the computer would need to be on and awake all the time.
    (29200)

  • How to set MBair to acting like ad-hoc wifi router ...

    Hi all X'
    I wanna to participate a ipodtouch4 to the cable internet at the MBair.
    The internet at the MBair is with a cable but with NO ROUTER.
    HOW CAN I MAKE THE MBAIR TO ACT AS A 'ROUTER'?
    DHCP seems not the way it is.

    Comcast certainly can and does put the SMC modem into bridging mode for customers.
     From an older thread....
       "The request to put the router in bridge mode takes Comcast about 3 seconds to do. The correct number to call to have it done is 800-363-2416 and ask anyone who answers to do this."

  • Routing of WLC 2504

    I am using WLC 2504 with AP1242 to access LAN through wi-fi and below are the details/configuration i am using.
    1. Using a belkin router with LAN IP 192.16.17.50 and DHCP 192.168.6.1
    2. Connected WLC 2504 with belkin router [192.168.6.254] and enabled DHCP [192.168.6.200-250] on WLC 2504 for Access points.
    3. All these devices [Belkin router, WLC 2504 and APs ] are connected on 8 port unmanaged switch.
    wi-fi connectivity is working fine and we are able to access 192.16.17.X series from wi-fi [192.168.6.X] but can not access 192.16.17.X from wi-fi 192.168.6.X so is there any way to access wi-fi IP series 192.168.6.X from LAN 192.16.17.X.
    Please share the information if anybody has the information.
    Thanks
    Ashish

    If you have different subnets defined on the 2504, then you need a managed switch that allows the port to be trunked.  The WLC 2504 does not route and that is why.  The WLC only bridges the traffic in which your switch has to pass the vlan tag and your router has to route the vlans.  I don't think your home router can route multiple inside networks and your un managed switch for sure will not pass vlan tag.

  • How do I set up an Airport Extreme as a router?

    I need to make sure my Airport Extreme is set up as a router and NOT a bridge. I cannot find anything about this on Apple's manuals, the forums nor the interwebs in general. Has someone done this before?
    Currently I have the Airport Extreme working as a WiFi seemelessly. I have two devices connected to the Airport Extreme via ethernet ports but only one is communicating. The other (a solar microconverter) is not communicating with the router. Cables work, I have unplugged and replugged everything, YES, everthing! Both devices have little green lights lit up next to the port they are plugged into.
    Can anyone out there just tell me how I can either make sure it is set up as a router or how to change the Airport Extreme to work as a router.
    I'm pretty desperate at this point.
    TIA

    In AirPort Utility 5.6:
    In AirPort Utility 6 click on your device.
    The device shouldn't be in bridge mode if you want it to act as a router.

  • TC set up when not connected to internet/using as a router

    Hi,
    I bought a TC and can't seem to get it to back up at a reasonable speed with an ethernet cable attached to my MBP. I have 180GB to back up, I've been getting 1GB in 3 hours, which is ridiculous, so something must be wrong. My suspicion is it's doing it wirelessly.
    It's not set up as a router because I'm staying with friends and I can't seem to see in the instructions how to set it up to transfer the data by cable. Can anyone suggest how to move forward, I'm just feeling frustrated with it, and I can't have it tied to a desk for 540 days to do a first back up.
    Anyone's assistance would be really appreciated - with the sparks out the back when I first plugged it in - I'm wondering whether I should just send it back... this has not been plug and play so far, but appreciate it not being connected to the net/acting as a router might be complicating things a bit.
    Thanks
    Ben

    Hello benho. Welcome to the Apple Discussions!
    with the sparks out the back when I first plugged it in - I'm wondering whether I should just send it back
    You did power all your networking equipment off before making any connections ... right?
    You can configure the Time Capsule (TC) as either a stand-alone router or to join an existing wireless network in order to perform backups.
    If your Mac has AirPort at the top of the network connections list, it will attempt to connect wirelessly first, and then, move down the list to the next networking option. If you want to "force" your computer to try Ethernet first, just move this option to the top of the list.

  • VPN Server with two router local network

    I just got a Mac Mini Server 2011 to set up as a home server. One of the main features I want to use is a VPN so I can access my files on my local network when I'm away from home. I live in Japan and I have a Japanese optical connection to the internet that runs through two boxes before I can use it in any form: some sort of modem, and a "gateway" which I literally just found out is also acting as a router and serving DHCP addresses. In addition, I have a 2TB Time Capsule that, until just recently, I had been using in the "Share a Public IP" mode because I didn't realize the gateway was also issuing DHCP addresses. I cannot simply plug my TC into the modem in place of the gateway - both are required to access the internet.
    Until today I had both routers using DHCP on the local networks they each created. Under that environment, I had finally configured Lion Server to file share (easy), manage network accounts (moderate), and serve Profile Manager (difficult). But despite my best efforts at mapping the ports on the Time Capsule, I just couldn't get the ports open using tools like canyouseeme.org, so the VPN was a no-go. That's when I realized the gateway could be a router too, so with some creative google searches, and extensive use of google translate, I was able to figure out how to open ports on the gateway. It does it pretty differently from the Time Capsule and other routers I've seen. It asks you define the host on the LAN (what i assume to be the target IP), the protocol (TCP vs. UDP), and then a range of ports for it to open. I plugged in the IP of the Time Capsule, opened all the UDP ports (since it was an option to just open all, and I figured 1) the TC would still protect my network and 2) it would just be a test), but I still couldn't see the ports as being open.
    So then I got desperate, and I switched the TC back to Bridge Mode, reconfigured the Server and my MBP (my client Mac) to the new IP addresses being served by the Japanese gateway, and tried again. I think I reconfigured the DNS settings in Server Admin properly to account for the change in IP, and then updated the services in Server.app, but now I can't even get to my server homepage (the apple placeholder page) using either its IP or its .private domain, and to make matters worse, I STILL can't seem to get the ports open (yes, I changed the port mapping to send it directly to the server IP as the target after the change).
    To add insult to injury, the wired ethernet connection I had been running from my TC to the MM Server is now reporting a cable unplugged (it's not), even when I plug it directly into the gateway, though I am able to connect wirelessly.
    Does anyone have any idea what's going on? Why can't I get these ports open? (By the way, I called my ISP and they said they aren't blocking any of the ones I'd want to use for VPN.)
    What is the *better* set up - using the TC as a second LAN, serving its own DHCP addresses, or using it in Bridge mode?
    Why did these changes sever my wired connection?
    I was getting even more problems (like loss of internet connectivity on all devices) using the TC in bridge mode, so I decided to go back to the dual network setup.

    Hello Eric,
    As I mentioned above.
    For external Internet access, I would create a Generation
    1 VM
    and use 2 Legacy Network Adapters for
    the Interfaces . Connect it to the External and Internal network, and then install VM Linux IPFire (How
    to install) and
    configure IPFire with RED and GREEN interface.
    You don't need router or any firewall.
    I have the same set-up that you are trying to do in your lab and it's working great.
    All my VMs / computers on the LAN have their gateway the Linux VM.
    Hope this help.
    Regards,
    Charbel Nemnom
    MCSA, MCSE, MCS, MCITP
    Blog: www.charbelnemnom.com
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • How can i use a second router to replace verizon fios router?

    Okay so just as the title says how do i use a second router? I got a cisco valet router... I don't know how to use it because the verizon router/modem is wierd i know how to use a router if i only had a modem but fios gives router/modem so how can i use my 2nd router? The current verizon fios router/modem is b/g mode and i wanna change to b/g/n so i can get a better speed from my internet... SO how can i use my 2nd router? I tried this http://www.dslreports.com/faq/verizonfios/3.0_Networking#12506 but i don't get it can someone guide me better or make a video explaination on how to use a 2nd router? I have it connected with see as in pic i connect from my router Internet port to wan port and the ethernet lan port to the ethernet lan port on verizon fios and no work please help...

    OK, so with this, we have a few options. You appear to have a MoCa connection to the ONT, hence the coaxial cable being present.
    1: The ActionTec can be bridged to the Valet router. This will not require any additional cabling, however it will require a small amount of work to have working. You will also require the ActionTec still in the mix, even though it will not be acting as a router anymore with this configuration.
    Visit http://www.dslreports.com/faq/16077 and look at Option 4. There is a thread linked that will allow you to set up the ActionTec as just a MoCa bridge, and will pass the Public IP to your router. You will, in order for this to work once the ActionTec is bridged, need to connect the cable from your Valet router's Internet port, to the ActionTec's LAN port and nothing else goes to the ActionTec. From this point, your Valet should run as your primary and everything should connect through your Valet. If you are adding another router, a Netgear N300, you should perform the LAN to LAN setup, which we will talk about once you've got the Valet working correctly. LAN to LAN configs require a custom setup, so do not set up the Netgear for now.
    2: This is my preferred method, which would be to run an Ethernet cable to the ONT. Option 6 in the FAQ. This will require spaking to Verizon to have them move your ONT to Ethernet, but once they do this, you can disconnect the Coaxial Cable from your ActionTec router, and plug in your CAT5/CAT6 cable from the ONT to the ActionTec's Internet/WAN port. Use the ActionTec to ensure everything is working after the switchover, and once off the phone, log into the ActionTec, perform a DHCP Release, and then prompty power off the ActionTec. Once this is done, plug the CAT6 cable into your Valet router's Internet port. You should from this point, be able to connect to the Cisco, and if the DHCP Lease was broken successfully, the Cisco should begin serving up your Internet connection. If it does not, leave the Cisco powered off for a few hours to break the DHCP lease, and then power it up. If the Valet does not work, still, give the Valet a factory reset and set up this router again, with the Ethernet cable from the ONT connected to it.
    I would just take a good luck at the FAQ linked above again, and see what would work the best. Easiest thing to do is to get the ONT moved to Ethernet, which allows you to eliminate the ActionTec unless you need it in the future for TV service, and also allows you to use any router with ease.
    Once the Valet is up and running and holds your Public IP address from Verizon (use http://whatismyip.com/ to determine this) , and also serves up IPs to devices on your network, post back and we can help you set up the Netgear. If you have any issues while setting this up, fall back to the ActionTec. It's factory reset will work without configuration needed, regardless of you being on Coax or Ethernet.
    ========
    The first to bring me 1Gbps Fiber for $30/m wins!

  • Routing with a multihomed Mac

    Hi,
    I have a Mac running Leopard 10.5.4 with two network cards in it, and I'm trying to get it to act as a router.
    The setup is very simple:
    A ---- M ---- B
    M is the Mac with two nics.
    The nic (en0) on computer M connected to computer A has an IP of 10.0.0.1/24.
    Computer A has an IP of 10.0.0.2 and a gateway of 10.0.0.1
    The nic (en1) on computer M connected to computer B has an IP of 192.168.0.1/24.
    Computer B's IP is 192.168.0.2 with a gateway of 192.168.0.1
    Both computer A and B can ping computer M on the appropriate interface, but I cannot get computers A and B to ping each other. It sounds to me like computer M simply isn't forwarding the packets across its interfaces.
    The routing table on computer M shows entries for both subnets on the appropriate en0/en1 interface.
    There are no firewall rules at all on any of the machines (so nothing is blocking the ping).
    Is there something I need to do to tell Leopard to forward traffic across its two network cards?
    For the record: there is no NAT going here at all, and this has nothing to do with internet connection sharing. This is an isolated little network with only three machines; no net connection, no NAT, no nothing. All I want is for machine M to do some routing for me
    Can anyone help?
    Thanks in advance.
    Hamster.

    It sounds to me like computer M simply isn't forwarding the packets across its interfaces
    That's correct. By default the OS doesn't forward packets, only accepts packets destined for itself.
    Is there something I need to do to tell Leopard to forward traffic across its two network cards?
    Yes. Enable IP forwarding:
    sysctl -w net.inet.ip.forwarding=1
    Note this will be transient (i.e. lost at next reboot). To make it persistent add the 'net.inet.ip.forwarding=1' to /etc/sysctl.conf

Maybe you are looking for

  • Error in PL/SQL block..

    Hi Im facing an error in the following code.. Cant trace it out. /* Formatted on 2009/10/21 22:09 (Formatter Plus v4.8.8) */ DECLARE    latest_task_id    NUMBER;    task_name_em7      VARCHAR2 (50);    select_flag_em7    NUMBER        := 1;    ds_cou

  • Issue Receipt for Down Payment

    I have a requirement to issue a receipt after receiving cash for a downpayment. The current process is to issue a down payment request F-37 - when cash is received it is posted using F-29 the system automatically books the output tax payable. I need

  • Os 9 classic install loops

    I bought an Ebay imac g4 "lampshade" running OS 10.4.11 minus OS 9. Attempting installation from an OS 9 CD two icons appear in the dock: "Classic Startup", and "Install Language Kits". They hop for a while until this message appears: "Classic cannot

  • Testing ABAP Web dynpro: Error  code 403 and for the reason Forbidden

    Hi,   We have NW04s Installed and trying to execute a SAP supplied ABAP web dynpro application DEMO_SIMPLE_MAIN. Please see the following error and let us know which service it's talking about? I am familiar with SICF. However in AS7.0( New name for

  • Run external files

    Hi guys.how can i run external files.Like cls.exe. thanx in advance