Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

PDF

Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

VLAN group support for DHCP and static IP clients

Want to summarize with AI?

Log in

Outlines VLAN group support for assigning DHCP and static IP clients to VLANs, configuring MAC and IP bindings, enforcing network access policies, and details prerequisites and feature history for IPv4 client management.


A VLAN group feature is a network function that

  • assigns clients to VLANs based on DHCP or static IP information

  • restricts internet access for static IP clients whose addresses do not match the VLAN’s IP list, and

  • applies only to IPv4 clients with automatic enablement unless explicitly disabled by configuration.

  • The VLAN Group to support DHCP and Static IP clients feature manages network access for DHCP and static IP clients.

  • Ensure that the ipv4 dhcp required command is not configured on the wireless policy profile. If this command is present, the feature is disabled, and the client remains in the IP learn state. Ensure that the ip mac-binding command is configured on the wireless policy profile. This command associates VLAN information with the MAC address and IP address assigned to the client, whether assigned statically or through DHCP.

Feature history

This table provides release and related information about the feature explained in this section.

This feature is also available in all the releases subsequent to the one in which they are introduced in, unless noted otherwise.

Table 1. Feature history for VLAN group support for DHCP and static IP clients

Feature Name

Release Information

Feature Description

VLAN group support for DHCP and static IP clients

Cisco IOS XE 17.9.1

From this release VLAN group support for DHCP and static IP clients enhances network segmentation by allowing controllers to assign both DHCP and IPv4 static IP clients to VLANs using computed logic.


Prerequisites and restrictions of VLAN Group support for DHCP and static IP clients

Prerequisites of VLAN Group support for DHCP and static IP clients

  • Ensure that a switch VLAN interface (SVI) is configured with the IP address.

  • Ensure that IP MAC-binding is configured on the target Policy Profile(s).

Restrictions of VLAN Group support for DHCP and static IP clients

  • FlexConnect local switching and FlexConnect local authentication are not supported. Only local mode, FlexConnect central switching, and FlexConnect central authentication are supported.

  • IPv6 is not supported.

  • The peer controller cannot have a VLAN group in the policy profile, because a VLAN group with static IP mobility is not supported. To support VLAN group with an anchor peer controller, static-ip-mobility must be configured and DHCP required must be disabled.


Supported features

This table provides details about supported features for VLAN group support for DHCP and static IP clients.

  • Configure SVI with an IP address in the same subnet as the client’s IP address.

  • Clients are excluded if there is no matching SVI.

Feature Support
Guest Anchor Yes
Mobility Yes
RLAN Yes
SVI

Yes

Ensure that you configure SVI with an IP address in the same subnet as that of the client's IP address.

IRCM support: Guest AireOS as anchor and Cisco Catalyst 9800 controller as foreign Yes
IRCM support : Guest AireOS as foreign and Cisco Catalyst 9800 controller as anchor

Yes

The client is excluded if there is no match for the SVI.