Introduces Remote LANs (RLANs), outlining their limitations, and provides instructions for enabling or disabling RLANs, creating and configuring RLAN and policy profiles through GUI and CLI, attaching policy tags, configuring fast switching, and verifying RLAN configuration.
A remote LAN is a network security feature that
-
enables authentication of wired clients using the wireless controller
-
switches client traffic between central and local switching modes, and
-
treats wired client traffic as wireless client traffic for unified management.
Feature history
| Feature name |
Release information |
Feature description |
|---|---|---|
| Remote LANs |
Cisco IOS XE 16.9.1 |
Remote LAN (RLAN) is a network security feature that allows authentication of wired clients using a wireless controller. It treats wired client traffic as wireless client traffic for unified management. The RLAN in an AP sends authentication requests for wired clients, similar to the process for centrally authenticated wireless clients. |
| Fast switching support for RLAN |
Cisco IOS XE 17.15.2 |
Fast switching support for RLAN is a network optimization mechanism that reduces latency and improves throughput by enabling VLAN-tagged data packets to be switched directly between WAN and LAN ports using the AP's internal switch processor. This feature is supported on Cisco Catalyst 9105AXW APs starting with release 17.15.2. |
The RLAN in an AP sends authentication requests for wired clients. Authentication of a wired client in an RLAN is similar to the process for a centrally authenticated wireless client.
For information about APs that support this feature, see https://www.cisco.com/c/en/us/td/docs/wireless/access_point/feature-matrix/ap-feature-matrix.html
Ethernet (AUX) port
By default, the second Ethernet port in Cisco Aironet 1850, 2800, and 3800 Series APs functions as a link aggregation (LAG) port. When LAG is disabled, you can use this port as an RLAN port.
These APs models use LAG port as an RLAN port:
-
1852E
-
1852I
-
2802E
-
2802I
-
3802E
-
3802I
-
3802P
-
4802
Role of Controller
-
The controller acts as an authenticator, receiving Extensible Authentication Protocol (EAP) over LAN (EAPOL) messages from the wired client sent through an AP.
-
The controller communicates with the configured Authentication, Authorization, and Accounting (AAA) server.
-
The controller configures the LAN ports for an AP and pushes the configuration to the corresponding AP.
Fast switching support for RLAN
A fast switching feature is a network optimization mechanism that
-
enables VLAN-tagged data packets to be switched directly between WAN and LAN ports using the access point's internal switch processor
-
bypasses CPU processing to reduce latency and improve throughput, and
-
supports efficient data handling for latency-sensitive applications such as gaming and video streaming.
On Cisco Catalyst 9105AXW APs from version 17.15.2, hardware fast switching for RLAN client traffic is supported. To configure this feature, enable fast switching on the controller and assign the appropriate VLAN IDs to LAN ports. This optimizes network performance and ensures seamless connectivity.
Starting with release 17.15.2, hardware fast switching for RLAN client traffic is supported on Cisco Catalyst 9105AXW APs. This feature enhances performance by reducing latency and improving throughput. The AP can switch VLAN-tagged data packets directly between WAN and LAN ports using its internal switch processor, which bypasses CPU processing. Fast switching is ideal for latency-sensitive applications such as gaming and video streaming and enables efficient data handling. To configure this feature, enable fast switching on the controller and assign the appropriate VLAN IDs to LAN ports. This optimizes network performance and ensures seamless connectivity.