Professional Documents
Culture Documents
Objective
Cisco Public
Agenda
Learn Cisco Unified Wireless LAN Principles (Reminder)
Understand Wireless Branch Deployment Options
Evaluate FlexConnect Architectural Requirements
Identify the need for FlexConnect & AP Groups
Design a Resilient Branch Network
Design Secure & BYOD enabled Branch Network
How to operate Wireless Branch efficiently over WAN
FlexConnect Resiliency DEMO
BRKEWN-2026
Cisco Public
Autonomous
FlexConnect
Centralized
Converged
Access
U n p a r a l l e l e d D e p l o ym e n t F l e x i b i l i t y
BRKEWN-2026
Cisco Public
Cisco Prime
Infrastructure
Wireless LAN
Controllers
Campus
Network
Aironet Access
Point
Cisco Public
Overview
Branches can also have local
remote controllers
Small or Mid-size Branch
WLCs
CT-2504,
Integrated controller modules in
ISR/ISR-G2
Converged Access Cat-3850
Central Site
CAPWAP
WAN
WLC-25xx
WLCM for
ISR/ISR-G2
Cat-3850
Remote Site C
Remote Site A
Remote Site B
BRKEWN-2026
Cisco Public
Note: If you have ISR/ISR G2 at branch site then it is recommended to use the
IOS Firewall at edge for unified access policies.
BRKEWN-2026
Cisco Public
10
Central Site
Centralized
Traffic
Cluster of
WLC
Centralized
Traffic
WAN
Local
Traffic
Remote Office
BRKEWN-2026
Cisco Public
11
FlexConnect Glossary
Connected Mode When FlexConnect can reach Controller (connected
state), it gets help from controller to complete client authentication.
Standalone mode When controller is not reachable by FlexConnect, it goes
into standalone state and does client authentication by itself.
Local Switching Data traffic switched onto local VLANs for an SSID
Central Switching Data traffic tunneled back to WLC for an SSID
BRKEWN-2026
Cisco Public
12
BRKEWN-2026
Cisco Public
13
BRKEWN-2026
Cisco Public
14
For Your
Reference
Deployment
Type
WAN
Bandwidth
(Min)
WAN RTT
Latency (Max)
Data
64 kbps
300 ms
25
Data
640 kbps
300 ms
50
1000
Data
1.44 Mbps
1 sec
50
1000
Data+Voice
128 kbps
100 ms
25
Data+Voice
1.44 Mbps
100 ms
50
1000
Monitor
64 kbps
2 sec
N/A
Monitor
640 kbps
2 sec
50
N/A
BRKEWN-2026
Cisco Public
20
http://www.cisco.com/en/US/products/ps6366/products_tech_note09186a0080b3690b.shtml
BRKEWN-2026
Cisco Public
21
Key Differentiation
WAN Tolerance
High Latency Networks
Access Points
300-6,000
Clients
64,000
Branches
2000
100
Deployment Model
FlexConnect
Form Factor
1 RU
IO Interface
2 x 10GE
Upgrade Licenses
BRKEWN-2026
WAN Survivability
Security
802.1x based port authentication
Voice support
Voice CAC
OKC/CCKM
Cisco Public
22
7.0.116.0
7.4
Total APs
2000
6000
Total Clients
20,000
64,000
500
2000
No
Yes
~250 Mb
~1 Gb
No
Yes
No
Yes
BRKEWN-2026
Cisco Public
23
For Your
Reference
Release Version
7.2
7.2
7.2
7.3
7.3
Split-tunneling
7.3
7.3
7.4
7.4
7.5
7.5
BRKEWN-2026
Cisco Public
24
Understanding AP Groups
Overview
AP Group 1
Central Site
Flex 7500
WAN
Flex 7500
CT-5508
WiSM-2
CT-2504
# AP Groups
6000
500
1000
50
# WLAN
(SSID)
512
512
512
16
# VLAN
(Interfaces)
4095
512
512
16
BRKEWN-2026
Remote Site B
Remote Site A
AP Group 2
Cisco Public
AP Group 3
26
AP Groups Usage
@ Internet
Manufacturing Site
Central Site
Corporate-Voice
Corporate-Data
Central Site
Corporate-Voice, Corporate-Data,
Guest-Access
AP Group 1
WAN/MAN
Manufacturing Site
Store
Corporate-Voice,
Corporate-Data, Scanners
AP Group 3
Store
Corporate-Data,
Guest-Access
Scanners
AP Group 2
Corporate-Data
Guest-Access
BRKEWN-2026
Cisco Public
28
AP Groups Usage
Per AP Group SSID to VLAN Mapping
AP groups give the ability to
statically map Wi-Fi service
(WLAN) to VLAN based on
physical location
Users see the same
Wi-Fi service on all sites.
Admin can monitor and filter
based on different IP@ each
site
Can also be used to have
smaller Wi-Fi subnets
For example per floor subnets
in a building.
AP Group 1
Head Office
VLAN-1
Central Site
VLAN-2
VLAN-3
WAN/MAN
Corporate-Data
AP Group 3
Store
AP Group 2
Manufacturing Site
Corporate-Data
Corporate-Data
BRKEWN-2026
Cisco Public
29
Central Site
Flex 7500
Cluster
WAN
Remote Site
Remote Site
Scaling information
Scaling
Flex
7500
CT-5508
WiSM2
CT-2504
FlexConnect
Groups
2000
100
100
30
AP per Group
100
25
25
25
BRKEWN-2026
FlexConnect Group 2
FlexConnect Group 1
Cisco Public
31
Central Site
RADIUS Server
WAN
FlexConnect
Group 1
FlexConnect Group 2
FlexConnect Group 1
BRKEWN-2026
CCKM Keys
Cisco Public
32
WAN
Remote Site
Application
Server
BRKEWN-2026
Cisco Public
35
BRKEWN-2026
Central Site
WAN
Remote Site
Application
Server
Cisco Public
36
Central RADIUS
WAN
Local Backup
RADIUS
Remote Site
FlexConnect Group 1
Cisco Public
37
Local Authentication
By default FlexConnect AP
authenticates clients through central
controller
Local Authentication allow use of local
RADIUS server directly from the
FlexConnect AP
Central Site
Central RADIUS
WAN
Local
RADIUS
Remote Site
FlexConnect Group 1
New in 7.0.116
BRKEWN-2026
Cisco Public
39
Central Site
Central RADIUS
WAN
Remote Site
Release Version
6.0
6.0
7.5
7.5
2014 Cisco and/or its affiliates. All rights reserved.
Cisco Public
41
Starting
from 7.2
Description
Central Site
WAN
Remote Site
Application
Server
BRKEWN-2026
Cisco Public
45
Starting
from 7.2
RADIUS
VLAN 3
QoS
VLAN =7 Silver
QoS = Platinum
WAN
Application
Server
Remote Site
FlexConnect Group 1
BRKEWN-2026
Cisco Public
48
For Your
Reference
WAN
ISE
BRKEWN-2026
Cisco Public
49
Central
VLAN 3
BRKEWN-2026
Central RADIUS
Go to Default
VLAN ID
VLAN 7
does not
Exist on
this WLC
VLAN 3
VLAN 7
WAN
Remote Site
VLAN 3
does not
Exist on
this AP
VLAN 7 VLAN 7
does not
Exist on
this AP
Cisco Public
50
Starting
from 7.5
AAA override
QoS Profile of AAA override
Local WLAN configuration
QoS Profile of local WLAN configuration
Attribute
[14179\002]
Aire-QoS-Level
[14179\004]
Aire-802.1P-Tag
[14179\007]
Aire-Data-Bandwidth-AverageContract
[14179\008]
Aire-Real-Time-BandwidthAverage-Contract
[14179\009]
Aire-Data-Bandwidth-BurstContract
[14179\0010]
Aire-Real-Time-BandwidthBurst-Contract
Cisco Public
51
Starting
from 7.2
Overview
Central Site
WAN
Remote Site
Scale
512 FlexConnect ACL per WLC
Application
Server
Cisco Public
53
Starting
from 7.3
Overview
Split tunneling allow some traffic to be locally switched although the WLAN is
defined as centrally switched
Split tunneling is using a NAT/PAT feature with ACL to perform the local
switching
Split tunneling is using the AP IP@ for the NAT/PAT feature
FlexConnect AP
CAPWAP
WLC
Central Traffic
WAN
NAT/PAT
ACL
Central Server
Local Traffic
Local Printer
BRKEWN-2026
Cisco Public
58
Starting
from
7.2.110
Central Site
WebServer
WAN
Internet
Remote Site
VLAN
503
VLAN 7 - Employee
Guest
FlexConnect Group 1
BRKEWN-2026
Cisco Public
63
Starting
from 7.4
WLC
Initial
Connection
Using PEAP
ISE
CA-Server
Device
Provisioning
Wizard
Client
Reconnects
Future
Connections
Using EAP-TLS
WLC
BRKEWN-2026
ISE
Cisco Public
CA-Server
70
ISE
DHCP Server
FlexConnect AP
CAPWAP
WLC
Web Server
WAN
WiFi Association
802.1x/EAP Request
Inside CAPWAP
Radius Access-Request
Radius Access-Response
Unknown Device,
Redirect to registration
Access-Type: Access-Accept
URL-Redirect-ACL=FlexACLWebPolicy,
URL-Redirect=http://)
Inside CAPWAP
802.1x/EAP Response
Inside CAPWAP
BRKEWN-2026
Cisco Public
75
ISE
DHCP Server
FlexConnect AP
CAPWAP
WLC
Web Server
WAN
DHCP Request
Inside CAPWAP
DHCP Lease
RADIUS-Accounting
host-name=MyiPad
dhcp-class-identifier=APPLE
Device is an
Apple iPad
Inside CAPWAP
BRKEWN-2026
Cisco Public
76
CAPWAP
WLC
Web Server
WAN
HTTP Request
Redirected to WLC by AP
HTTP
Request
Inside CAPWAP
URL-Redirect
BRKEWN-2026
Cisco Public
77
ISE
DHCP Server
FlexConnect AP
CAPWAP
WLC
Web Server
WAN
Device is Registrered
Trigger Change-of-Auth
RADIUS Change-of-Authorization
EAP Authentication
BRKEWN-2026
Cisco Public
78
ISE
DHCP Server
FlexConnect AP
CAPWAP
WLC
Web Server
WAN
802.1x/EAP Request/Response
Inside CAPWAP
Radius Access-Request
Radius Access-Response
Device is Registrered
And Provisioned
Allow Access
DHCP Request/Response
Inside CAPWAP
Web Traffic
BRKEWN-2026
Cisco Public
79
Starting
from 7.2
Concerns
Sites using FlexConnect AP are usually sites with low WAN bandwidth
Each site may have small number of AP, but an enterprise may have a
lot of branches
Upgrading ~6000 AP through a low bandwidth WAN is a challenge :
BRKEWN-2026
Cisco Public
81
Starting
from 7.2
Firmware Image
New
Old
Primary
New
Wireless Control
System
Old
New
Secondary
Central Site
Wireless LAN
Controller
WAN
Remote Site-N
Remote Site-1
Cisco Public
82
Firmware Image
4.
5.
6.
7.
Secondary
New
Old
Primary
Central Site
New
Old
Secondary
Wireless LAN
Controller
WAN
AP Firmware Image
Old
Primary
Remote Site-N
New
Secondary
Master AP
BRKEWN-2026
Cisco Public
83
C
A
P
W
A
P
Switch
AP 3600
SSID: FlexDemo
IP: 10.10.10.10
Cisco Public
IP: 10.10.10.20
87
Summary
Summary
Cisco Unified Wireless Network based on Controllers deliver Wireless Branch
Solution
FlexConnect is the feature designed to solve remote connectivity and WAN
constraints
Several Failover Scenario are targeted to offer Survivability of Small Remote
Sites
Wireless LAN Controller Scale Comparison Guide:
http://www.cisco.com/en/US/products/hw/wireless/products_category_buyers_
guide.html#controllers
FlexConnect Branch Controller Deployment Guide:
http://www.cisco.com/en/US/products/ps11635/products_tech_note09186a0080b7f141.shtml
BRKEWN-2026
Cisco Public
89
Deploying Ciscos
FlexConnect in Branches
Increases Business Resiliency
Call to Action
Visit the World of Solutions: Cisco Campus
Walk-in Labs
Technical Solutions Clinics
Meet the Engineer
Recommended Reading: For reading material and further resources for this
session, please visit www.pearson-books.com/CLMilan2014
BRKEWN-2026
Cisco Public
91
BRKEWN-2026
Cisco Public
92