Академический Документы
Профессиональный Документы
Культура Документы
Sarath Gorthi
Technical Marketing Engineer, EN
BRKEWB-2016
Agenda
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Cisco Webex Teams
Questions?
Use Cisco Webex Teams to chat
with the speaker after the session
How
1 Find this session in the Cisco Events Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Wireless Controller
and Access Point
Portfolio
Catalyst 9800 Wireless Controller
Deploy at any scale
Catalyst 9800-80
6000 APs, 64K clients
80 Gbps
Catalyst 9800-40
2000 Aps, 32K Clients,
40 Gbps
Catalyst 9800-CL
1000, 3000 or 6000 APs
10K, 32K or 64K Clients
Catalyst 9800-L
250 APs, 5K Clients,
5 Gbps
Catalyst 9800
Embedded Wireless**
200 APs, 4K Clients
Catalyst 9800
Embedded Wireless* Catalyst 9800-CL
100 APs, 2K Clients 1000 APs, 10K Clients *Supports Local Switching only
**SD-Access only
^Catalyst 9800 for Public cloud FlexConnect only
Up to 100 APs Up to 250 APs Up to 1000 APs Up to 3000 APs Up to 6000 APs
Ideal for small to medium-sized deployments Mission critical and scale deployment
Powered by Powered by
Cisco RF ASIC Cisco RF ASIC
Cisco DNA Assurance with iCAP Bluetooth 5 USB Integrated or external antenna SKUs
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Branch Design Options
Branch Design Considerations
Central Traffic
WAN Bandwidth
Resiliency Security
Central IT
Lean IT
Cloud Policies Video Streaming
NAT Guest
Services Radius Branches Guest Portals
BYOD
SP Managed
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Branch Wireless Design Options
Dedicated Local Embedded Local Remote
Controller Controller Controller
Local Controller Embedded Controller Options Flex Connect
BRANCH BRANCH
WLC
` WAN
• Single/Multi site networks
• Low IT footprints
` `
Cisco DNA
Center
Policy Automation Assurance Security ISE CMX
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Branch Office with dedicated WLAN Controller
Central Site
Backup WLC
CAPWAP
WAN
• Layer-3 roaming with controller in each branch
• Full local control, no dependency on WAN
` ` ` ` ` `
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Branch Office with Embedded WLAN Controller
Catalyst 9800 for Catalyst Switch Catalyst 9800 for Catalyst Access Point
• Branches can have Local embedded Controllers
Scale to 200 APs and 4,000 Clients Scale to 100 APs and 2000 Clients • No Separate Appliance
SDA Fabric FlexConnect Local Switching
Supported on Catalyst 9300, 9400 Support on Catalyst 9100 Series
and 9500 Series switches access points
B C
E
• Embedded controller on Cat9k switch is SDA
Fabric only
• Embedded controller on AP is local switching
only
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Branch Office with Flex Connect (Remote Controller)
Central Site
Data Center
WLC
• Highly Scalable
• Central management
• Supports optional central switching
` ` ` ` ` `
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Designing and Deployment
using FlexConnect
Introducing FlexConnect Central Site
Radius
Controller
Cluster
• Ease of Management via Controller
Central
• CAPWAP management and data plane are split: Switching
• Central Switching (SSID data traffic sent to WLC) WAN
• Local Switching (SSID data traffic sent to local VLAN)
Local
Switching
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
FlexConnect Glossary
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Configuring
FlexConnect Local
Switching?
Cisco 9800 Catalyst 9800 Config Model
Access Points
Policy Tag RF
RF Tag
WLAN
Profile
Profile
2.4 GHz
RF
Policy
Profile
Profile
5 GHz
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Steps to configure FlexConnect Local Switching
STEP 01
STEP 02
Enable WLAN for Local
• Configure FlexConnect Local Switching on WLAN
Switching
by turning off central switching on policy profile
STEP 03
Create WLAN to • Configure Native VLAN on FlexConnect AP
VLAN mapping • Configure WLAN-VLAN Mapping
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Configure FlexConnect mode on Access Point
STEP 01
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Configure FlexConnect Local Switching on WLAN
STEP 02
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Configure Native VLAN on AP
STEP 03a
Configure Native VLAN on FlexConnect AP Site and attach to the AP
When connecting with Native VLAN on AP, L2 switch port must also
match with corresponding Native VLAN configuration on the AP
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Configure WLAN to VLAN Mapping
STEP 03b
Configure WLAN-VLAN mapping
Mapping of WLAN to VLAN can be done as part of the Policy profile .
The same need to be configured on switch port
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Demo Time
Site Tag ( Flex Connect)
Understanding Site tag (Flex Connect)
Central Site
WLC
Overview
Each flexconnect site is a group and share the
following in this group
CCKM/OKC fast roaming keys
Local/backup RADIUS servers IP/keys WAN
Local EAP authentication Remote Site Remote Site
AAA-Override for Local Switching
Smart Image Upgrade
FlexConnect AVC
WLC WLC WLC
Scaling
9800-80 9800-40 9800-L
FlexConnect
6000 2000 250
Profiles
FlexConnect Site 1 FlexConnect Site 2
AP per Flex
100 100 100
Group
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
FlexConnect Groups and CCKM/OKC Keys
RADIUS Server
If a FlexConnect AP boots up
in standalone mode, it will not get the
OKC/CCKM keys from the WLC
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Designing a
Resilient Wireless
Branch Network
F@#$?%! Router!!!
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
FlexConnect Resiliency - WAN Failure
Central Site
WAN Failure
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
FlexConnect Resiliency – N+1 HA Scenario
Central Site
WLC Failure scenario with N+1 HA
Secondary Primary
WLC WLC
FlexConnect APs will go to Standalone mode
No impact for locally switched SSIDs
Disconnection of centrally switched SSIDs
clients
WAN
CCKM roaming allowed in FlexConnect group
Remote Site
FlexConnect AP will then search
for backup WLC; when backup WLC is found,
Application
FlexConnect AP will resync with WLC and Server
resume client sessions with central traffic
Client sessions with Local Traffic are not
impacted during resync with Backup WLC
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
FlexConnect Resiliency – SSO HA Scenario
Active
True Box to box High Availability i.e. 1:1. Sub-
second failover to StandBy WLC
Configuration(AP database, Client Run state etc.)
information on Active is synched to Standby WLC
FlexConnect AP will NOT transition to Standalone WAN
because SSO kicks in
AP will continue to be in Connected mode with the
Standby (now Active) WLC Application
Server
Centrally Switched SSID will never go down
Remote Office
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
FlexConnect – AAA Survivability
Local Backup RADIUS
Central Site
Local Backup RADIUS
Central
Normal authentication is done centrally RADIUS
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
FlexConnect - Local Authentication
Central Site
FlexConnect Group
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
FlexConnect - Local Authentication
Configuration
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Segmentation & Security
in Branch Network
Segmentation
FlexConnect AAA VLAN
FlexConnect AAA VLAN Override
Description RADIUS Central Site
FlexConnect Group
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
FlexConnect AAA VLAN Override
Configuration IETF 65
IETF 64
IETF 81
WAN
ISE
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
VLAN Based Central Switching Central
Go to Default
VLAN ID
VLAN 3
Overview Central
RADIUS
VLAN 7
• While doing AAA VLAN Override with VLAN 3 does not
local switching: VLAN 7 Exist on this
WLC
• If VLAN ID does not exist at the AP, the
traffic is central switched to the central WAN
VLAN ID
Remote Site
• If the central VLAN ID does not exist, the
traffic is centrally switched to the default
VLAN ID of the WLAN / Policy Profile
VLAN 7
does not
VLAN 3 Exist on
does not this AP
Exist on
this AP
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
VLAN Based Central Switching
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
AAA Override Deployment Scenario
Problem Statement – Map clients to specific vlans based on their function
Central Site
VLAN 20
WAN
Application
Server
Function VLAN ID
Engineering 11
Marketing 21
Function VLAN ID Sales 31
Engineering 10 Application
Server
Marketing 20
Sales 30
VLAN 20 does
Remote Site A Remote Site B not exist
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
VLAN Name Mapping at FlexConnect Group /Profile
Flex Group A Central Site Flex Group B
VLAN Name VLAN
VLAN Name VLAN ID VLAN Name VLAN
ID ID
Engineering 10
Engineering 10 Engineering 11
Marketing 20
VLAN Name VLAN
Marketing 20 Marketing 21
Sales ID
30
Sales 30 Sales 31
Engineering 11
. .
. Marketing 21
WAN .
HR 160 Sales 31 HR 161
Remote Site B
Remote Site A
VLAN ID
VLAN ID
11
10 21
20 31
30
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
VLAN Name AAA Override - Solution
Central Site
Aire-Interface-Name or
IETF Tunnel-Private-Group-ID
VLAN NAME=
Marketing
WAN
Application
Server
Remote Site Remote Site VLAN Name VLAN ID
VLAN 20 Engineering 11
Marketing 21
VLAN Name VLAN ID Sales 31
Engineering 10
Marketing 20
Sales 30
Remote Site A VLAN 21 Remote Site B
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Identity PSK
Challenges for Enterprises: Advanced security encryption across all
devices
Simple Operations
Increased demand for Identity security High Scale
IoT devices without 802.1x
Cost Effective
Keys Solution Asks:
Private PSK with RADIUS integration; Per client AAA override (VLAN / ACL, QoS etc)
Cisco Advantage:
Highly scalable identity PSK solution designed for a large multi controller network
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public
Identity PSK
✓ PSK WLAN
✓ AAA Override
IOT Devices
xxyyzz
Access Point Wireless LAN Controller ISE
Sensors
No+=PSK
Cisco-AVPair attributes
"psk-mode=ascii”
Cisco-AVPair += "psk=aabbcc"
"psk=xxyyzz"
WAN
ACL can be applied on WLAN (configured on Policy
Remote Site
Profile)
ACL can be applied on a VLAN (configured in flex Application
Server
connect profile)
FlexConnect ACL support AAA-returned Client ACL
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
ACL – Policy Profile Mapping
• Configuration – Map it to the Policy Profile
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
ACL – VLAN Mapping
• Configuration – Map it to the Flex Connect Profile on
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Policy ACL
• For a AAA Overide ACL to work on an AP in Flex Connect , the ACL should present on AP
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
FlexConnect Split
Tunneling
(Using FlexConnect
Split ACL)
FlexConnect ACL – Split Tunneling
Overview
Split tunneling allow some traffic to be locally switched although the WLAN is defined
as centrally switched
Split tunneling is using a NAT/PAT feature with ACL to perform the local switching
NAT/PAT WAN
ACL
Central Server
Local Traffic
Local Printer
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
FlexConnect ACL – Split Tunneling
Configuration
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Operating the Wireless Branch
over WAN
Flex Connect Design Considerations
It is highly recommended that the minimum bandwidth restriction remains 24 Kbps per AP with the round trip
C and 100 ms for Data + Voice deployments.
latency no greater than 300 ms for data deployments
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
WLC behind NAT
WLC IP
NAT IP
• WLC only supports 1-1 NAT ISE/AAA
Data Center
management interface AD
Branch network
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
Branch Office Upgrade
over WAN
Upgrading a FlexConnect Deployment
Concerns
Sites using FlexConnect AP are usually sites with low WAN bandwidth
Each site may have small number of AP, but an enterprise may have a lot of branches
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
Efficient AP join (enabled by default) in flex
connect profile
• Enables an CAPWAP to download the code from another AP in the network as • Supported on all 802.11ax and
long as it is of the same AP family. 802.11ac Wave 2 APs (indoor
and outdoor)
• For example, If you add a 9120AX and a 9115AX is present, code will be
• AP families sharing the same image:
downloaded from the 9115AX
• ap3g3: Aironet® 4800, 3800, 2800,
• This feature minimizes the data sent on WAN at the time of AP join or AP Image 1560 Series
Pre-download • ap1g5: Aironet 1815i,
1815w,1815m,1540, 1840 Series
• WLC elects a master AP in each FlexConnect Group for each Model /Type
• ap1g4: Aironet 1852, 1832
• ap1g7: Catalyst 9115AX,
9120AX Series
• ap1g6: Catalyst 9117AX Series
• ap1g6a: Catalyst 9130AX Series
Not supported on Wave 1 APs
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Efficient AP join 16.12
.1
16.12
.2
WAN
M M
16.12
.2 16.12
16.12
16.12 16.12 .2
16.12 .2
.1 .1
.1
Catalyst Aironet Aironet
9115AX 1852i 1815i
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
FlexConnect Efficient AP Image Upgrade
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
FlexConnect Best
Practices
FlexConnect Best Practices
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Wireless Branch
Deployment
Embedded
Wireless Controller
EWC on Cisco Catalyst access points
Ready for enterprise deployments
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
EWC ready for enterprise branch deployments
Resilient
<10 seconds
Redundancy with active and standby Active to standby switchover SMU (patching) support
controllers running simultaneously in a few seconds for both controller and
on two access points access point
Intelligent, with
IT simplicity Simplified WebUI for monitoring,
provisioning, and day-N operations
Cisco DNA Center
Plug and Play (PnP),
Open standards-based
programmability with
Automation, and Assurance NETCONF and YANG
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
EWC on Cisco Catalyst 9100 access points
Ideal for single or multisite small to medium- Mission critical Best in class
sized enterprise deployments Best suited for high-density enterprise branch deployments
Powered by Powered by
Cisco RF ASIC Cisco RF ASIC
Software feature parity Supports up to 100 APs, Supports Wave 2 APs as Cisco DNA Assurance
across APs 2000 clients client serving with ICAP
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
What about 802.11ac Wave 2 access points?
Supports client serving mode
Indoor
Outdoor
1540 1560
All 802.11ac Wave 2 access points can connect to the embedded wireless controller
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Embedded Wireless Controller on Catalyst AP
vs. Mobility Express
Support Wave 2 APs (x800 Series) as subordinate Scale: 50-100 Access Points
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
EWC on Catalyst 9100 access points
Interoperability matrix
Cisco IOS XE ISE 2.3 Cisco DNA Center Cisco DNA Spaces
16.12.2 1.3.2
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Deploying the Cisco Embedded Wireless
Controller
Deploying the Cisco Embedded
Wireless Controller
• EWC-capable access points can be connected to an access port or a trunk port on the switch, depending on the
deployment method
• Management traffic is always untagged
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
How to provision?
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Day-0 provisioning – What’s new?
• Single “CiscoAirprovision-<ABCD>”
PSK SSID
• mywifi.cisco.com URL for accessing
EWC-AP WebUI
• Mobile app provisioning
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
Over-The-Air Provisioning (OTAP)
Get your wireless network up and running in less than 10 minutes
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Day-0 EWC-AP selection
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
Deploy using OTAP
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
Redundancy and
high availability
EWC: Resiliency
• Active and standby controllers running simultaneously • Controller SMU support for hot and cold patching
on two Cisco Catalyst 9100 EWC-capable
• AP service pack support for resolving issues on
access points
access points
• No new master election. Faster switchover (less than
10 seconds) with standby controller • AP device pack updates enable new AP models
to be backward compatible with customer-
• After failover, another access point in the network will installed code versions
be elected to become a standby, providing
redundancy until the last available EWC-AP in
the network
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 95
EWC on Catalyst access points: Resiliency
• Failure of active
controller triggers a
Always-on network switchover to
• APs continue to switch standby
data traffic
• Standby controller is
Always-on clients active in less than 10
How it
• Users and endpoints seconds, and
continue to stay connected
works another EWC-AP is
elected as a standby,
Always-on services CAPWAP-AP Active Standby
Active providing
• Less than 10 seconds EWC-AP Standby
EWC-AP redundancy
downtime of services
• APs fail over to the
new controller
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 96
EWC: Active-standby redundancy
• When subordinated EWC-capable 9100 APs join, the active EWC-AP selects a standby AP based on an
algorithm, and active-standby redundancy is formed
• In the event of a failure of the active AP, the standby EWC-AP becomes active and is elected as a
controller automatically
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
EWC: Standby election
• The active EWC-AP will wait until external APs join to begin standby election
• The active EWC-AP will assign a priority to all joined APs. An AP with the highest priority will be selected as the
standby. Priority is calculated based on following parameters:
• Explicit user configuration; choose a particular EWC-AP as the preferred controller (highest priority)
• AP model (for example, give the 9130AX models the highest priority)
• AP join time
• When an active EWC-AP fails, the standby becomes active. The election process is then initiated to elect the
next standby. It elects the access point with the highest priority as the standby AP
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 98
EWC: Preferred controller and make controller
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
EWC: Active-Standby on EWC-AP
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 100
EWC: Seamless software update infrastructure
Active
• Installs controller-
Seamless SW updates specific updates
• Update (patch) EWC without (patches) without
client downtime client downtime to
fix issues seamlessly
AP service pack • Enables service
• Update specific AP updates for specific
models with AP How it
access point models
service pack works without impacting
AP device pack other models
• Introduce new AP models in AP model • New APs can join
your network without any the controller with an
downtime and without AP device pack
impacting other APs Standby without impacting
other APs
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 101
Software updates
Software upgrade options
17.1
http:// SFTP
TFTP
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 103
Mapping of AP images to AP models
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 104
Site Survey mode
Site Survey
Cisco EWC on Catalyst APs is next-generation autonomous and supports Site Survey in Cisco IOS
XE Release 16.12.2. The following access points with the EWC image support the Site
Survey capability:
• Cisco Catalyst 9120AX Series (C9120AX-x)
• Cisco Catalyst 9117AX Series (C9117AX-x) 192.168.0.1/24
• Cisco Catalyst 9115AX Series (C9115AX-x)
• Cisco Catalyst 9130AX Series (C91130AX-x)
192.168.0.X/24 Surveyor
Cisco EWC supports an internal DHCP server and operates without a pingable gateway. This
enables the user to take the access point powered by a battery pack and a client device to
perform an active survey
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 106
Converting AP
from CAPWAP to
EWC-AP
and vice versa
Conversion: CAPWAP AP to EWC-AP
• Download the EWC-AP software .zip • Execute the conversion command from
from Cisco.com. This zip file has the the access point’s CLI.
access point and WLC images. Unzip the
file and put it on the TFTP server.
Note: Conversion requires two files to be downloaded on the AP: an AP image and a WLC image from the unzipped folder.
The ap1g6 is for the 9117AX Series, ap1g6a is for the 9130AX Series, and ap1g7 is for the 9115AX and 9120AX Series. The WLC image
file (C9800-AP-iosxe.wlc.bin) is the same for all Cisco Catalyst 9100 APs.
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 108
Converting a CAPWAP AP to EWC
CAPWAP AP
8.10/16.11
TFTP
DHCP request
1
Master AP
16.12.2
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 109
Converting an EWC-AP to a CAPWAP AP
There are typically two reasons why one would want to convert an access point
running the EWC image to CAPWAP
• You want to keep the access point in an EWC deployment but do not want the access point to
participate in the master election process upon a failover of the master AP
• You want to migrate one or more access points with EWC to an appliance or
vWLC-based deployment
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 110
EWC-AP to CAPWAP AP using the CLI
AP#ap-type capwap
1
CAPWAP AP
Master AP 16.12
16.12.2
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 111
EWC to CAPWAP AP using WebUI
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 112
Migrating AireOS Mobility Express to EWC on an
AP
Translate
Export Import
configuration
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 113
Bringing it all together
Embedded Controller Flex Connect
Local Controller
Options
WLC
WA
` • Single/Multi site N
networks
• Low IT footprints
` `
FlexConnect
Single/Multi-site networks Controller running in Data Center
Local WLAN Controller Low IT footprints Distributed Network , Highly Scalable
Controller running on AP or Switch
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 114
Cisco Enterprise Wireless Book
http://cs.co/wirelessbook
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 115
TUE WED THU FRI
MOB
Lab on Catalyst
Wireless 9800 Celebration 18:30
Portfolio &
Controllers
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 117
Continue your education
Demos in the
Walk-In Labs
Cisco Showcase
BRKEWN-2016 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 118
Thank you