- Auto Anchor SSID between Wireless LAN Controllers acting as MC
- Enabling Central Web Authentication on ISE
- Configuring Auto Anchor and Mobility Groups on Wireless Services
- Configuring Wireless Multicast on Wireless LAN Controllers
- Converged Access Consolidated Quick Reference Templates for Wireless LAN
- Converged Access Controller AP Join Issue Troubleshoot with Traces
- Converged Access Controllers MAC Address Entry for Network Mobility Service Protocol
- Configuration Example: Converged Access Management through Prime Infrastructure with SNMP v2 and v3
- Converged Access Path Maximum Transmission Unit Discovery
- Third-Party Certificate Installation on Converged Access Wireless LAN Controllers
- Configuration Example: Converged Access for WLC EAP-FAST with Internal RADIUS Server
- Converged Access and WLC Local EAP Authentication Configuration Example
- Configuration Example: Custom Web Authentication with Local Authentication
- Dynamic VLAN Assignment with Converged Access and ACS 5.2 Configuration Example
- Configuration Example: External RADIUS Server EAP Authentication
- External Web Authentication on Converged Access
- Installing Wireless Services
- Local Web Authentication with External RADIUS Authentication
- Local Web Authentication on Converged Access
- PEAP Authentication with Microsoft NPS Configuration
- QoS on Converged Access Controllers and Lightweight Access Points
- Configuration Example: TACACS Administrator Access to Converged Access Wireless LAN Controllers
- Configuration Example: Unified Access WLC Guest Anchor with Converged Access
- VideoStream Troubleshooting
- Custom Web Authentication Locally Hosted on WLC or an External Server
- Wireless Converged Access Chromecast Configuration Example
- Web Passthrough Configuration Example
- Configuration Examples: WPA2-PSK and Open Authentication
- Supported Platforms and Releases
- Configuring Mobility Groups on Cisco Catalyst 3850 Series Switch
- Configuring Foreign SSID
- Configuring Auto Mobility Groups on Cisco 5500 Series Wireless Controller GUI
- Configuring Anchor SSID on Cisco 5500 Series GUI
- Testing Client Connectivity on Wireless Services
- Configuring Auto Anchor SSID on Cisco Catalyst 3850 Series Switch
- Configuring Foreign SSID on Cisco 5500 Series Wireless Controller
- Verifying Auto Anchor and Mobility Groups Configuration
Configuring Auto Anchor and Mobility Groups on Wireless Services
This document describes the procedure to configure an auto anchor between Cisco 5500 Series Wireless Controller and Cisco Catalyst 3850 Series Switches. It also includes the procedure to configure mobility groups on Cisco Catalyst 3850 Series Switches and the procedure to configure a Pre Shared Key (PSK) Service Set Identifier (SSID).
This article considers Cisco Catalyst 3850 Series Switch as both foreign and anchor Wireless LAN Controller (WLC).
- Supported Platforms and Releases
- Configuring Mobility Groups on Cisco Catalyst 3850 Series Switch
- Configuring Foreign SSID
- Configuring Auto Mobility Groups on Cisco 5500 Series Wireless Controller GUI
- Configuring Anchor SSID on Cisco 5500 Series GUI
- Testing Client Connectivity on Wireless Services
- Configuring Auto Anchor SSID on Cisco Catalyst 3850 Series Switch
- Configuring Foreign SSID on Cisco 5500 Series Wireless Controller
- Verifying Auto Anchor and Mobility Groups Configuration
Supported Platforms and Releases
Configuring Mobility Groups on Cisco Catalyst 3850 Series Switch
To configure the Cisco Catalyst 3850 Series Switch for mobility groups, the Cisco Catalyst 3850 Series Switch needs to be in the Mobility Controller (MC) mode.
Device# configure terminal
Device(config)# wireless mobility controller
To configure the mobility groups on Cisco Catalyst 3850 Series Switch, reset the switch and then configure the mobility groups on the Cisco Catalyst 3850 Series Switch. The following table displays the details that are used to create a sample mobility group for Cisco Catalyst 3850 Series Switch and Cisco 5500 Series Wireless Controller:
| Model | IP address | MAC Address | Group Name |
| 5508 | 192.0.2.1 | 00:24:97:69:63:c0 | mcast_mob |
| 3850 | 192.0.2.2 | 20:37:06:cf:5f:f9 | Converged Access |
Configuring Foreign SSID
To create a PSK SSID, the SSID is configured as a foreign SSID and the clients are pushed to Cisco 5500 Series Wireless Controller.
wlan anchor-profile 1 anchor-ssid no security wpa akm dot1x security wpa wpa1 ciphers tkip security wpa akm psk set-key ascii 0 Testlab1
-
To enable the Service Set Identifier (SSID) to push the clients to the Cisco anchor 5500 WLC, use the following commands:
mobility anchor 192.0.2.1 no shutdown
Configuring Auto Mobility Groups on Cisco 5500 Series Wireless Controller GUI
To form a mobility group between Cisco Catalyst 3850 Series Switches and Cisco 5500 Series Wireless Controller, perform the following steps:
-
To enable New Mobility, navigate to Controller > Mobility Management > Mobility Configuration.
-
Confirm that Cisco 5500 Series Wireless Controller's Management IP address is listed in the Mobility Controller's public IP address. The WLC is configured to support the new mobility architecture.

Note
You can also enable the Mobility Oracle. However, this is optional.
-
Add the Cisco Catalyst 3850 Series Switches in the mobility group. The mobility group is configured. However, approximately a minute is taken for the control path to form as compared to the flat mobility group architecture.

Note
The procedure is similar to configuring any other WLC.
Configuring Anchor SSID on Cisco 5500 Series GUI
To configure an anchor SSID on Cisco 5500 Series GUI, perform the following tasks:
Testing Client Connectivity on Wireless Services
To test the connectivity between the client and Cisco Catalyst 3850 Series Switches and Cisco 5500 Series Wireless Controller, perform the following:
-
To verify that the client connects to Cisco Catalyst 3850 Series Switch, use the following command:
Device# show wireless client summary show wireless client mac-address <MAC ADDR> detail
The following output displays the connectivity status of the client on Cisco Catalyst 3850 Series Switch: Wireless LAN Id : 1 Wireless LAN Name: anchor-profile Policy Manager State : RUN
-
To confirm that the client successfully connects to Cisco 5500 Series Wireless Controller, use the following commands:
Device# show client summary show client detail <mac addr> or use the GUI
Configuring Auto Anchor SSID on Cisco Catalyst 3850 Series Switch
-
To remove the previous mobility command from the SSID, use the following commands: wlan anchor-profile 1 anchor-ssid no mobility anchor 192.0.2.1
-
To define Cisco Catalyst 3850 Series Switch as the anchor of the SSID, use the following command: mobility anchor 192.0.2.2
-
To configure SSID to map a client to a particular client VLAN, use the following command: Client vlan 21
Configuring Foreign SSID on Cisco 5500 Series Wireless Controller
To configure the Cisco 5500 Series Wireless Controller so that the clients are navigated to Cisco Catalyst 3850 Series Switch, change the mobility anchor settings so that the mobility anchor sends the clients to Cisco Catalyst 3850 Series switch.
Verifying Auto Anchor and Mobility Groups Configuration
The new mobility architecture uses three User Datagram Protocol (UDP) ports to transfer information between WLCs in the mobility group. The three UPDs must be open in both directions for communication to work. The three UDPs to transfer information between WLCs in the mobility group are the following:
|
UDP Port |
Function |
|
16666 |
Mobility Control Path |
|
16667 |
Mobility Data Path |
|
16668 |
Mobility Oracle Path |
To display the status of the mobility group, use the following command:
Device# show wireless mobility summary
The following output displays the summary of the mobility controller:
Mobility Role : Mobility Controller Mobility Protocol Port : 16666 Mobility Group Name : CONVERGEDACCESS Mobility Oracle IP Address : 0.0.0.0 DTLS Mode : Enabled Mobility Domain ID for 802.11r : 0x8ff4 Mobility Keepalive Interval : 10 Mobility Keepalive Count : 3 Mobility Control Message DSCP Value : 0 Mobility Domain Member Count : 2 Link Status is Control Link Status: Data Link Status The following displays the controllers that are configured in the mobility domain: IP Public IP Group Name Multicast IP Link Status ------------------------------------------------------------------------------- 198.51.100.1 - CONVERGED ACCESS 0.0.0.0 UP : UP 203.0.113.1 192.0.2.254 mcast_mob UP : UP
Verifying Client Connectivity Status
To verify the status of client connectivity, use the following commands:
Device# show wireless mobility controller client summary
Device# show wireless client summary
Verifying Mobility Group Status between Wireless Services
The mobility group between Cisco 5500 Series Wireless Controller and Cisco Catalyst 3850 Series Switch is enabled when the following is displayed on the terminal:
Device# *Apr 17 05:47:59.230: %IOSXE-6-PLATFORM: 1 process wcm: *capwapPingSocketTask: %MM-6-MEMBER_UP: Data path to mobility member 198.51.100.1 is UP. 3850# *Apr 17 05:48:29.228: %IOSXE-6-PLATFORM: 1 process wcm: *mcListen: %MM-6-MEMBER_UP: Control path to mobility member 203.0.113.1 is UP.
Feedback