Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.x

Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.x

IPv6 Layer 3 access

Want to summarize with AI?

Log in

Explains how IPv6 layer 3 access enables controller-based wireless client subnet termination and advanced IPv6 services on the Cisco Catalyst 9800 Series Wireless Controller.


IPv6 Layer 3 access is a controller-based wireless client forwarding capability that

  • terminates wireless client IPv6 subnets on switched virtual interfaces (SVIs) on the Cisco Catalyst 9800 Series Wireless Controller

  • advertises wireless client routes to the upstream network through OSPFv3, and

  • provides VRF-aware IPv6 services such as DHCPv6 relay, IPv6 multicast routing, and NAT64.

In a Layer 2 wireless architecture, an upstream switch or router terminates the wireless client subnets. With IPv6 Layer 3 access, the controller terminates the client subnets and participates in routing. This design can improve scalability, resiliency, and operational efficiency for IPv6-first and dual-stack networks.

IPv6 Layer 3 access supports the coexistence of Layer 2 and Layer 3 WLANs. You can enable Layer 3 access on the wireless policy profiles that require controller-based subnet termination and leave it disabled on other policy profiles.

The controller supports flow based equal-cost multipath (ECMP) forwarding over four equal-cost paths by default. ECMP distributes flows across multiple best paths that have the same routing metric.


Feature history for IPv6 Layer 3 Access

  • This table provides release and related information for the feature explained in this module.

  • This feature is also available in all the releases subsequent to the one in which they are introduced in, unless noted otherwise.

Table 1. Feature history for IPv6 Layer 3 Access

Feature Name

Release Information

Feature Description

IPv6 Layer 3 Access

Cisco IOS XE 26.2.1

IPv6 Layer 3 Access is a controller-based wireless client forwarding capability that terminates IPv6 client subnets on switched virtual interfaces and advertises client routes to the upstream network through OSPFv3. It provides VRF-aware IPv6 services and improves scalability, resiliency, and operational efficiency for IPv6-first and dual-stack networks.


DHCPv6 relay agents

A DHCPv6 relay agent is a network function on the wireless controller that

  • encapsulates wireless client DHCPv6 messages into relay-forward messages

  • sends the relay-forward messages to a DHCPv6 server through unicast communication, and

  • decapsulates the client messages from relay-reply messages and forwards them to wireless clients.

You can configure DHCPv6 server settings on a wireless policy profile or an SVI. You can configure the DHCPv6 VPN option at the wireless policy profile, SVI, or global configuration level.

The configuration scope determines which clients the VPN option applies to. A wireless policy profile configuration applies only to clients associated with that policy profile. An SVI configuration applies to clients on the corresponding VLAN. A global configuration applies to all applicable DHCPv6 clients on the controller.

If the VPN option is configured at more than one scope, the controller applies the most specific configuration. A wireless policy profile configuration takes precedence over an SVI configuration, and an SVI configuration takes precedence over the global configuration.

The controller supports primary and secondary DHCPv6 server addresses at configuration scopes that allow multiple relay destinations. A wireless policy profile supports one DHCPv6 server address.

Supported DHCPv6 relay options

  • Interface-ID: The Interface-ID option is enabled by default. No configuration is required.

  • Virtual Subnet Selection (VSS): Carries the VRF name of the client interface. This option uses Cisco enterprise ID nine, and suboption three carries the VRF name. The DHCPv6 server can use this information to apply policy for the originating VRF.

The client interface VRF is carried in the VSS option. The server VRF determines how the controller routes relay packets to the DHCPv6 server.

Lightweight DHCPv6 relay agents

A lightweight DHCPv6 relay agent (LDRA) is a Layer 2 relay function that inserts relay-agent information while the controller bridges client traffic. LDRA is the functional equivalent of the DHCPv4 Layer 2 relay agent.

When you enable the VPN option on a wireless policy profile without configuring a DHCPv6 server, the controller applies LDRA processing. The controller automatically adds the mandatory Interface-ID option and adds the VSS option only when you configure it.


How IPv6 Layer 3 client forwarding works

These stages describe how IPv6 Layer 3 forwarding works.

Summary

The key components involved in the process are:

  • Wireless client: Connects to a WLAN that uses a wireless policy profile.

  • Access point: Connects the wireless client to the controller.

  • Cisco Catalyst 9800 Series Wireless Controller: Terminates the client SVI and forwards client traffic at Layer 3.

  • Upstream routers: Exchange routes with the controller through OSPFv3 and forward traffic through the enterprise network.

Workflow

The process involves these stages:

  1. The wireless client joins a WLAN whose wireless policy profile has Layer 3 access enabled.
  2. The controller terminates the client subnet on the corresponding SVI.
  3. OSPFv3 advertises the client subnet to the upstream routers.
  4. The controller and the upstream routers select the best routing path. When multiple paths have equal metrics, ECMP distributes flows across the equal-cost paths.
  5. The controller forwards client traffic through the selected path.

Result

The controller provides routed IPv6 connectivity for wireless clients and advertises the client subnets to the upstream network.


How DHCPv6 relay agents work

These stages describe how DHCPv6 relay agents work.

Summary

The key components involved in the process are:

  • Wireless client: Sends DHCPv6 messages to obtain IPv6 configuration.

    Cisco Catalyst 9800 Series Wireless Controller: Relays and processes DHCPv6 messages.

  • DHCPv6 server: Allocates IPv6 configuration and returns DHCPv6 replies.

Workflow

The process involves these stages:

  1. The wireless client sends a multicast DHCPv6 message.

  2. The controller selects the effective relay configuration according to the policy profile, SVI, and global precedence.
  3. The controller encapsulates the client message in a relay-forward message and adds the required relay options.
  4. The controller converts the client multicast exchange into unicast communication with the DHCPv6 server and uses the server VRF to route the relay packet.
  5. The DHCPv6 server returns a relay-reply message.
  6. The controller decapsulates the relay-reply message and forwards the server-originated reply to the wireless client.

Result

The wireless client receives IPv6 configuration from an external DHCPv6 server through the controller.


Guidelines for IPv6 Layer 3 forwarding

Ensure that the IPv6 Layer 3 forwarding deployment meets these guidelines:

  • Enable Layer 3 access on each wireless policy profile that uses controller-based client subnet termination. Layer 3 access is disabled by default.

  • Use Local mode or FlexConnect central switching with central DHCP.

  • Use OSPFv3 for dynamic routing and static routes for IPv6 reachability to infrastructure devices.

  • Configure an external DHCPv6 server for full DHCPv6 relay operation.

  • Apply DHCPv6 relay configuration at the intended scope. A wireless policy profile configuration overrides an SVI configuration, and an SVI configuration overrides the global configuration.

  • Use the client interface VRF in the VSS option when the DHCPv6 server requires the originating VRF context.

  • Use the server VRF to provide destination routing for relay packets to the DHCPv6 server.


Restrictions for IPv6 Layer 3 forwarding

These restrictions apply to IPv6 Layer 3 forwarding:

  • FlexConnect local switching, MEWLC, and ECA deployments are not supported.

  • BGP is not supported for this feature.

  • The internal DHCPv6 server is not supported.

  • Inter-controller mobility is not supported for Layer 3 access clients.

  • A client cannot roam between Layer 2 and Layer 3 WLANs that use different VLANs, interfaces, or VRFs. The controller rejects the roam.

  • Mobility anchor and static IP mobility configurations are not supported on a wireless policy profile that has Layer 3 access enabled.


Use cases for IPv6 Layer 3 forwarding

IPv6 Layer 3 forwarding supports these use cases:

  • IPv6-first wireless access: Provides routed client connectivity in an IPv6-first enterprise network.

  • Dual-stack wireless access: Uses a single OSPFv3 process for IPv4 and IPv6 address families.

  • VRF-aware segmentation: Maintains separate routing contexts for client networks and supports VRF-aware DHCPv6 relay.

  • Layer 2 and Layer 3 WLAN coexistence: Allows selected WLANs to use controller-based Layer 3 termination while other WLANs continue to use Layer 2 termination.

  • Resilient upstream connectivity: Uses OSPFv3 and flow-based ECMP to advertise client subnets and forward traffic across equal-cost paths.

  • IPv6 multicast services: Supports PIM sparse mode, PIM source-specific multicast, and MLDv2 for wireless clients.

  • IPv6-to-IPv4 communication: Supports NAT64 so that IPv6-only wireless clients can access IPv4-only resources.


Enable Layer 3 access on a wireless policy profile

Enable the controller to terminate and route client traffic for a wireless policy profile.

Layer 3 access is disabled by default. Enable it only on wireless policy profiles that require controller-based client subnet termination.

Before you begin

  • Configure the client VLAN and SVI.

  • Ensure that the deployment uses Local mode or FlexConnect central switching with central DHCP.

Follow these steps to enable Layer 3 access on a wireless policy profile:

Procedure

  1. Enter wireless policy profile configuration mode and enable Layer 3 access.

    Example:

    wireless profile policy policy-profile-name  l3-access

    Use the no form of this command to disable Layer 3 access.

  2. Verify the Layer 3 access state for the policy profile.

    Example:

    show wireless profile policy detailed policy-profile-name  | include L3
    The command displays the L3 access as enabled.
  3. Verify the Layer 3 access state for a connected wireless client.

    Example:

    show wireless client mac-address client-mac-address  detail | include L3
    The command displays the L3 access as enabled for a client.

Layer 3 access is enabled for clients that use the wireless policy profile.


Configure DHCPv6 relay or LDRA

Configure the controller to relay DHCPv6 messages or insert DHCPv6 relay-agent information for wireless clients.

You can configure DHCPv6 relay on a wireless policy profile or an SVI. You can enable the DHCPv6 VPN option at the wireless policy profile, SVI, or global configuration level. Select the configuration scope according to the clients to which the VPN option must apply:

  • Wireless policy profile: Applies only to clients associated with the wireless policy profile.

  • SVI: Applies to clients on the corresponding VLAN.

  • Global configuration: Applies to all applicable DHCPv6 clients on the controller.

If the VPN option is configured at more than one scope, the controller applies the configuration in this order of precedence:

  • Wireless policy profile

  • SVI

  • Global configuration

Use LDRA when the controller bridges client traffic and no DHCPv6 server is configured on the wireless policy profile.

Before you begin

  • Obtain the IPv6 address of the external DHCPv6 server. You can configure one DHCPv6 server address on a wireless policy profile.

  • Configure the VRF that provides reachability to the DHCPv6 server.

  • Ensure that routes to the external DHCPv6 server are available.

  • Select the configuration scope required by the deployment.

Follow these steps to configure DHCPv6 relay or LDRA:

Procedure

  1. Select one of the following configurations according to the required scope and forwarding behavior.

    Full DHCPv6 relay on a wireless policy profile.

    1. Configure the DHCPv6 server address and server VRF. Enable the VPN option when the DHCPv6 server requires the client VRF context.

      Example:

      wireless profile policy policy-profile-name 
          ipv6 dhcp server dhcpv6-server-address  vrf server-vrf-name 
          ipv6 dhcp relay option vpn

      You can configure only one DHCPv6 server address on a wireless policy profile.

    LDRA on a wireless policy profile.

    1. Do not configure a DHCPv6 server on a wireless policy profile that uses LDRA. Enable the VPN option to apply LDRA processing.

      Example:

      wireless profile policy policy-profile-name 
          ipv6 dhcp relay option vpn

      The controller automatically inserts the mandatory Interface-ID option. It adds the VSS option only when the VPN option is configured.

    DHCPv6 relay on an SVI.

    1. Configure the relay destination. Include the server VRF, link address, source address, or source interface when required by the deployment.

      Example:

      interface Vlan vlan-id 
          ipv6 dhcp relay destination dhcpv6-server-address  link-address link-address  | source-address source-address 
          ipv6 dhcp relay destination vrf server-vrf-name dhcpv6-server-address  link-address link-address  | source-address source-address 
          ipv6 dhcp relay source-interface source-interface 
          ipv6 dhcp relay option vpn

      Use only the relay destination form and optional parameters required by the deployment.

    Global DHCPv6 relay VPN option.

    1. Enable the VPN option globally when it must apply to all applicable DHCPv6 clients on the controller.

      A wireless policy profile or SVI configuration takes precedence over the global configuration.

      Example:

      ipv6 dhcp-relay option vpn
  2. Connect a wireless client and confirm that it receives IPv6 configuration from the external DHCPv6 server.

The controller applies the selected DHCPv6 relay or LDRA behavior at the configured scope.


Configure OSPFv3 for IPv6 Layer 3 access

Enable IPv6 routing on wireless client VLANs by configuring OSPFv3 to advertise subnets and learn upstream routes.

OSPFv3 supports both IPv4 and IPv6 address families, including VRF-specific deployments.

Before you begin

  • Configure the client VLAN, SVI, IPv6 address, and VRF.

  • Confirm the OSPFv3 process ID and area for the deployment.

Follow these steps to configure OSPFv3 for IPv6 Layer 3 access:

Procedure

  1. Configure the OSPFv3 process and IPv6 unicast address family. Configure a VRF-specific address family when required.

    Configure BFD and nonstop routing (NSR) only when required by the network design.

  2. Associate the client SVI with the OSPFv3 process and area for IPv6.

    Example:

    interface Vlan vlan-id 
    vrf forwarding vrf-name 
    ipv6 address ipv6-prefix prefix-length 
    ipv6 enable
    ospfv3 process-id  ipv6 area area-id 
    
  3. For a dual-stack deployment, configure the IPv4 address family and associate the SVI with the OSPFv3 process for IPv4.

  4. Verify the OSPFv3 neighbors and learned IPv6 routes.

The controller exchanges IPv6 routes with its OSPFv3 neighbors and advertises the configured client subnets.


Configure IPv6 multicast routing for wireless clients

Enable Layer 3 wireless clients to receive IPv6 multicast traffic through proper routing and group management.

IPv6 multicast routing for wireless clients allows efficient group-based communication, supporting advanced protocols such as PIM and MLD.

Before you begin

  • Configure the client VRF and IPv6 SVI.

  • Identify the rendezvous point and wireless IPv6 multicast group for the deployment.

Follow these steps to configure IPv6 multicast routing for wireless clients:

Procedure

  1. Enable IPv6 unicast routing, multicast routing for the client VRF, and MLD snooping.

    Example:

    ipv6 unicast-routing
    ipv6 multicast-routing vrf vrf-name 
    ipv6 mld snooping
    ipv6 mld vrf vrf-name  state-limit state-limit 
  2. Configure the IPv6 PIM rendezvous point for the client VRF.

    Example:

    ipv6 pim vrf vrf-name  rp-address rp-ipv6-address 
  3. Enable wireless multicast and configure the AP CAPWAP IPv6 multicast group.

    Example:

    wireless multicast
    wireless multicast ipv6 ipv6-multicast-group 
  4. Verify the wireless multicast configuration and IPv6 group membership.

The controller forwards supported IPv6 multicast traffic for Layer 3 wireless clients.