Soru

Zorluk: Çok zorAP and WLC Management Access Connections

A network engineer is deploying a centralized Cisco Wireless LAN Controller (WLC) connected to an upstream Cisco Catalyst switch port configured as an 802.1Q trunk. The WLC Management Interface is assigned the IP address 192.168.10.10/24192.168.10.10/24 with VLAN ID 10. The upstream switch trunk interface has a native VLAN configured as VLAN 10. Cisco Lightweight Access Points (APs) operating in Local mode are connected to remote access switchports in VLAN 20 (192.168.20.0/24192.168.20.0/24) and successfully acquire DHCP IP addresses. However, the APs fail to establish CAPWAP tunnels with the WLC management interface. Diagnostic captures confirm that the WLC sends tagged 802.1Q frames for VLAN 10, but the switch drops them because VLAN 10 is configured as the native VLAN on the trunk interface. Which configuration change will resolve this CAPWAP management connectivity issue?

  1. Change the native VLAN on the switch trunk port to an unused VLAN (e.g., VLAN 999) or set the WLC Management Interface VLAN ID to 0 (untagged).Cevap
  2. B
    Reconfigure the access switch ports connected to the Local mode APs as 802.1Q trunk ports with native VLAN 10.
  3. C
    Enable Spanning Tree PortFast on the upstream switch trunk port connected to the WLC.
  4. D
    Convert the AP operational mode from Local mode to FlexConnect mode to allow CAPWAP control traffic to bypass the WLC Management Interface.

Cevap

Change the native VLAN on the switch trunk port to an unused VLAN (such as VLAN 999) or configure the WLC Management Interface VLAN ID to 0 (untagged).
When a Cisco Wireless LAN Controller management interface is explicitly configured with a VLAN identifier like VLAN 10, it appends an 802.1Q tag to all egress traffic. If the connected switch trunk port has native VLAN 10 configured, the switch expects untagged traffic for VLAN 10 and drops incoming tagged frames for that native VLAN. Changing the switch trunk native VLAN to an unused VLAN ID ensures VLAN 10 frames are tagged and accepted, or changing the WLC VLAN ID to 0 instructs the controller to transmit untagged frames, resolving the CAPWAP connectivity failure.

Adım Adım Çözüm

1
Analyze the encapsulation behavior of Cisco WLC management interfaces on 802.1Q trunks.
When a WLC management interface is assigned a specific VLAN ID (e.g., VLAN 10), the WLC tags all outgoing frame headers with an 802.1Q VLAN 10 tag.
The WLC expects explicit 802.1Q tagging when a non-zero VLAN ID is configured.
2
Evaluate the upstream switch trunk port native VLAN configuration conflict.
The upstream switch trunk port has VLAN 10 configured as its native VLAN. Standard switch behavior expects untagged frames for the native VLAN and drops tagged frames arriving for the configured native VLAN ID.
Matching tagged frames to the native VLAN ID creates an 802.1Q native VLAN tagging mismatch.
3
Determine the corrective configuration change.
Changing the switch trunk native VLAN to an unused VLAN ID (e.g., VLAN 999) allows VLAN 10 traffic to remain tagged end-to-end, or setting WLC Management VLAN ID to 0 forces the WLC to transmit untagged frames that match native VLAN 10.
Aligning frame encapsulation between the WLC and switch restores bi-directional Layer 3 CAPWAP reachability.

Anahtar Kavram

802.1Q Native VLAN Matching for WLC Management Interfaces
Bu soruyu puanla