Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

PDF

Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

AP mode of options

Want to summarize with AI?

Log in

Explains supported AP operating modes and workflows, covering Cloud ID, Day 0 onboarding, prioritized migration methods, fast offline migration steps, local status and offline migration details, and strategies to prevent false migration.


An AP mode option is a provisioning choice that

  • allows the AP to operate in either Meraki Cloud mode or Catalyst controller mode

  • can be set during the initial deployment or after deployment

  • and enables the AP to join the appropriate management system.


Cloud IDs

A Cloud ID is an identifier that

  • represents the Meraki Serial Number for a device

  • appears on the device’s physical label, packaging, QR code, and related materials, and

  • is essential for the Meraki device claim workflow in networks using devices such as the Cisco Wireless 917x series AP.

Additional reference information

The Cloud ID enables the streamlined claiming and management of Meraki devices within cloud-managed workflows. From the Cisco Wireless 917x series AP onward, this identifier provides a consistent reference for inventory and setup operations.

  • A network administrator uses the Cloud ID printed on the access point’s label to claim the device in the Meraki dashboard.

  • The QR code containing the Cloud ID simplifies device onboarding for IT staff.

A device serial number used in traditional on-premises workflows is not considered a Cloud ID unless it participates in the Meraki cloud claim process.


Onboarding process for Wi-Fi 7 APs

This section describes how to connect Cisco Catalyst 917x Wi-Fi 7 APs (CW917x) to the Meraki Dashboard and the Cisco Catalyst 9800 Wireless LAN Controller.

Summary

This process involves connecting the APs to the Meraki Dashboard and migrating them to the Cisco Catalyst 9800 Wireless LAN Controller.

The key components involved in the process are

  • Cisco Catalyst 917x Wi-Fi 7 APs (CW917x): The APs must be powered on and claimed on the Meraki dashboard.

  • Meraki Dashboard: Cloud-based management platform for onboarding APs.

  • Cisco Catalyst 9800 Wireless LAN Controller: Final migration destination for managing APs.

Workflow

These stages describe connecting the APs to the Meraki Dashboard and migrating to the Cisco Catalyst 9800 Wireless LAN Controller.

  1. Stage 1: Connect to Meraki Dashboard
    • Power on APs.
    • Claim APs using order number, Cloud ID, or MAC address. You can see the claimed APs on the Meraki dashboard as they start up.
    Note

    Ensure there are no DHCP, DNS, or PnP configurations that can lead the CW917x AP to the controller.

  2. Stage 2: Migrate the APs to the Cisco Catalyst 9800 Wireless LAN Controller
    • Option 1: Cloud-assisted migration If internet is available and the Meraki Dashboard account is configured, allow APs to join the dashboard and then migrate to the controller.
    • Option 2: Offline or fast offline migration If no internet is available:
      • Offline migration uses DHCP or DNS without changes to the existing network.
      • Fast offline migration uses new DHCP or DNS settings and skips cloud verification.
    • If fast offline migration is not used, the AP will
      • search for the Meraki cloud for eight minutes, and
      • after eight minutes, check DHCP or DNS for the controller and migrate via CAPWAP discovery.

Result

APs successfully transition from initial setup in the Meraki Dashboard to established operational management under the controller, ready for enhanced performance and control.


Priority order for AP migration methods

To ensure efficient and reliable AP migration, use the following methods in priority order. Select the highest-priority method available for your deployment.

The migration methods are prioritized in this order

  • Fast Offline Migration

    • DHCPv4

    • DNSv4

    • DHCPv6

    • DNSv6

  • Local Status Page

    • You can manually migrate the APs through the Local Status window of the AP when Fast Offline Migration options are not available.

  • Offline Migration

    • DHCPv4

    • DHCPv6

    • DNSv4

    • DNSv6

    • Broadcast or Multicast Discovery


Fast offline migration

This task guides you through the process of executing a fast offline migration using DHCPv4, DHCPv6, DNSv4, and DNSv6 configurations to ensure network stability and performance.

This procedure is essential for network environments requiring quick migration of APs to a new controller mode, leveraging DHCP and DNS configurations.

Procedure

1.

DHCPv4: The fast offline migration for DHCPv4 is Option 43.

The syntax for the option 43 string is F3 <size> <IP array> Mode=<1|2>, where Mode 1 is Meraki and Mode 2 is Catalyst.

  1. To change the existing option 43 string f104.ac10.0118 to f305.ac10.0118.02, do the following:

    • Change type from f1 to f3,

    • Change length from 04 to 05,

    • Add the sub-option 01 for Meraki or 02 for Catalyst.

  2. For controller discovery using DHCPv4, enter the following IOS/IOS XE configuration example:

    ip dhcp pool vlan192
                                        network 192.168.200.0 255.255.255.0
                                        default-router 192.168.200.1
                                        option 43 hex hex f305.ac10.0118.02
                                    
  3. In the Windows server configuration, choose DHCP > IPv4 > Scope Options.

  4. From the list of option names, select 043 Vendor Specific Info and click Configure Options.

    The Scope Options window is displayed.
  5. Choose the General tab and check the 043 Vendor Specific Info checkbox from the Available Options.

  6. Click OK.

Note

Ensure that at least one IP from the IP array is reachable through Internet Control Message Protocol (ICMP) or CAPWAP. The AP tries to contact the controller through pings. If the controller responds, the AP migrates to the controller management mode, otherwise the AP tries a CAPWAP discovery.

2.

DHCPv6: The fast offline migration for DHCPv6 involves configuring Option 52 and Option 17.

Note

Configure Option 17, where the Enterprise ID is 29671, Subcode is 1, Mode is either 1 (Meraki), or 2 (Catalyst vendor-specific 29671). Option 52 (standard) is IPv6 array.

  1. In the Windows server configuration, choose DHCP > IPv6 > Scope Options.

  2. From the list of option names, select 00052 capwap ac-address and click Configure Options.

    The Scope Options window is displayed.
  3. Choose the General tab and select the 00052 capwap ac-address checkbox from the Available Options.

  4. Click OK.

  5. To configure Option 17, choose DHCP > right-click IPv6, and select Define Vendor Classes.

    The DHCP Vendor Classes window is displayed.
  6. In the DHCP Vendor Classes window, create a new class.

  7. In the New Class window, enter the Display Name, enter the Vendor ID as 29671, and enter the ASCII value as Cisco Wireless AP CW9178I, for the CW9178I platform.

    Note

    For CW9176I and CW9176D1, use the following ASCII strings, respectively, Cisco Wireless AP CW9176I and Cisco Wireless AP CW9176D1.

  8. Click OK.

  9. Choose DHCP > right-click IPv6, and select Set Predefined Options.

    The Predefined Options and Values for v6 window is displayed.
  10. In the Predefined Options and Values for v6 window, click Option Type.

    The Option Type window is displayed.
  11. In the Option Type window, in the Code field, enter 1 and then click OK.

  12. Click OK.

  13. Choose DHCP > IPv6 > Scope Options > Configure Options.

    The Scope Options window is displayed.
  14. In the Scope Options window, click the Advanced tab.

  15. From the Vendor class list, select the vendor class.

  16. From the Available Options, check the 00001 fast-conversion checkbox.

  17. In the Data entry section, in the Byte field, enter 0X2.

  18. Click OK.

    Note

    Ensure at least one IP from the IP array is reachable via Internet Control Message Protocol (ICMP) or CAPWAP. The AP tries to reach the controller through pings. If the controller responds, the AP migrates to the controller management mode, otherwise the AP tries a CAPWAP discovery.

    The 00001 fast-conversion option is added to the list of Scope Options.
3.

DNSv4 and DNSv6: Fast offline migration using the migration string.

  1. Add a DNS record cisco-automigrate.<domain> in the DNS server.

    The AP checks for the cisco-automigrate.<domain> DNS entry.

    If the IP pings from DNS are successful, then the APs migrate immediately to the controller mode. If the pings fail, the AP tries the CAPWAP discovery method.

    Note

    For this method to work correctly, the DHCP server must return the domain-name option (option 15) to the AP.

Successfully configuring fast offline migration ensures that APs migrate quickly to the new controller mode, maintaining network stability and performance.


Local status page


Offline migration

The AP uses the traditional discovery mechanisms of DHCP, DNS and broadcast or multicast, if it is not able to reach the Meraki Cloud, perform a Fast Offline Migration, or migrate using the Local Status page.


Prevent false or accidental migration

The purpose of this task is to guide users on preventing accidental or unauthorized migration of APs to a controller, ensuring network stability and security.

To prevent accidental or false migration, perform these steps:

Procedure

1.

Ensure that at least one IP in the IP address array returned by the DHCP option or the IP address of the resolved DNS entry is CAPWAP reachable. This CAPWAP response must include the controller version image for the CW917x AP to validate it and join the controller.

2.

Enter cisco-do-not-automigrate when setting the DNS entry to resolve the controller's IP address. When it is resolved, the AP does not migrate to the controller mode.

3.

You can configure commands to prevent the controller from responding to Day 0 CAPWAP discovery requests by CW917x APs. You can fine tune its configuration based on its own deployment specification. Configuration is done in the AP Join Profile.

To prevent accidental or false migration, you must perform these configurations.

Device(config)# ap profile onboarding-prof
Device(config-ap-profile)# no capwap-discovery onboarding
Device(config-ap-profile)# exit
                    

To respond to the CAPWAP discovery, use the following configuration:

Device(config)# ap profile onboarding-prof
Device(config-ap-profile)# capwap-discovery ?
onboarding  Configure CAPWAP onboarding related parameters
private     Include private IP in CAPWAP Discovery Response
public      Include public IP in CAPWAP Discovery Response

Device(config-ap-profile)# capwap-discovery onboarding ?
all      Configure automatic CAPWAP onboarding from Meraki based on both
unicast and broadcast discovery request
unicast  Configure automatic CAPWAP onboarding from Meraki based on unicast
discovery request only 
                    

By default the controller accepts only unicast requests for onboarding.

Note

If the CW917x APs have to be in the same subnet as the controller and use Broadcast (IPv4), or Multicast (IPv6) for discovery, then CAPWAP discovery onboarding should be set to all . Otherwise, the controller does not respond to Broadcast or Multicast discovery requests.

Completion of this task ensures that the APs are properly configured and do not unintentionally migrate to controller mode, preventing unauthorized network changes and maintaining system integrity.