cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1764
Views
0
Helpful
4
Replies

Broadcast traffic on Local Mode AP

sisentner
Level 1
Level 1

Hi All,

Thanks in advance for any responses.  I understand that broadcast traffic is not passed by the WLC(by default) but in our situation we have centralized WLC's.  We keep the WLC's in data centers and have hundreds of sites that have AP's in local mode, hence CAPWAP all traffic to the WLC's via our fiber network.  All sites have their own(sometimes several) L3 networks with a router at reach site.  Here is the foggy part for me.  Is all of the, wireless client, broadcast traffic blocked only at the WLC or will the local router block that CAPWAP'd broadcast traffic.  I am hoping that I can use a /21 to serve all clients on one WLAN for ease but obviously don't want to flood our wan with unneeded broadcast traffic.  We do use Flex in some case's but it doesn't apply to the situation I am curious about.

thanks in advance

1 Accepted Solution

Accepted Solutions

ammahend
VIP
VIP

you are right, you can read the link below on how WLC handles Broadcast and Multicast traffic and for most part it should not be an issue.

https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Mobility/emob73dg/emob73/ch2_Arch.html#pgfId-1058225

 

To use /21 which is a sizable subnet for a usergroup tell me a little bit more about your wireless security, how are you onboarding users, how many types of wireless devices you plan to have on this WLAN, what kind of L2 L3 security you plan to use for each device type, authorization level for these devices etc to start with.

 

Segmentation is a key aspect of security.

 

Thank you

Ambuj

-hope this helps-

View solution in original post

4 Replies 4

ammahend
VIP
VIP

you are right, you can read the link below on how WLC handles Broadcast and Multicast traffic and for most part it should not be an issue.

https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Mobility/emob73dg/emob73/ch2_Arch.html#pgfId-1058225

 

To use /21 which is a sizable subnet for a usergroup tell me a little bit more about your wireless security, how are you onboarding users, how many types of wireless devices you plan to have on this WLAN, what kind of L2 L3 security you plan to use for each device type, authorization level for these devices etc to start with.

 

Segmentation is a key aspect of security.

 

Thank you

Ambuj

-hope this helps-

I left out the situation as it can be hard to describe that is why I posed the question pertaining to a large segment with the use of Local mode AP's CAPWAPing traffic back to the WLC. Using EAP-TLS on one WLAN and PEAP on the other. ISE is used for the EAP-TLS WLAN, an NPS server used for the PEAP WLAN. Certs/settings are pushed via an AD group to the devices for both WLAN's(different AD domain's). Both WLAN's are WPA2-Enterprise/AES. Our scenario is WLC's(HA pairs) that are in 2 separate data centre's. Each WLC having different WLAN's client segments. WLC's/AP's are in a separate management VRF(for security) and can talk to each other. The request to me is to make a WLAN residing on WLC-A, available on WLC-B and vice versa. I am not interested in using mobility groups or foreign/anchor controllers so I am going to mirror image the WLAN on each WLC(hopefully that makes sense). For nothing more than ease, I was going to use a /21. I could use a /22 but I want to allow for growth or an unexpected large amount of clients for short times. I only require support, at this time for approx 1000 clients/wlan. I also preferred not to use interface groups to minimize overhead for any firewall rules that need to be enforced etc. Thanks for the link I did not get a chance to read it yet but I am hoping it will answer my "broadcast" traffic question. As for your questions, I am not sure if I answered all of them or not.
Thank you

Shaun

That link explains how it works nicely. Thank you

Shaun

you are welcome, to you security description above, I have sent you a private message.

 

Thank you

-hope this helps-
Review Cisco Networking for a $25 gift card