Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.x

PDF

Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.x

Controller-directed URWB traffic

Want to summarize with AI?

Log in

Introduces controller-directed URWB traffic, enabling communication across broadcast domains and infrastructure subnets, centralizing traffic forwarding, preserving seamless mobility, and maintaining vehicle location and VLAN context for Layer 3 mobility.


This feature enables communication between different broadcast domains and infrastructure subnets.

It allows URWB vehicles and their wired clients to communicate across multiple infrastructure subnets and reduces broadcast domains while preserving seamless mobility.

In controller-directed mode, the controller maintains awareness of vehicle location, client association, and VLAN context as vehicles move. This enables Layer 3 mobility across infrastructure segments while keeping forwarding decisions centralized.


URWB clients

A URWB client is a controller-managed client type that represents either:

  • a vehicle AP participating in the URWB network, or

  • a wired endpoint connected behind a vehicle AP.

On the controller, URWB clients are tracked similarly to wireless clients for mobility, policy, and forwarding purposes. This allows the controller to apply consistent VLAN, policy, and roaming behavior as the vehicle moves between segments.

URWB clients

  • Vehicle AP: A mobile AP mounted on a vehicle and joined to the URWB network.

  • Wired URWB client: A camera, sensor, or other Ethernet-connected device behind the vehicle AP.


URWB traffic egress point

To enable the Controller-directed URWB Traffic feature, the URWB profile must be configured with the appropriate traffic egress point. When the traffic egress point is set to controller, it automatically generates the "cisco-urwb-client "WLAN and the corresponding "cisco-urwb-client" policy profile.

The policy tag must then be configured correctly to map the "cisco-urwb-client" WLAN to the "cisco-urwb-client" policy profile. This mapping is required for URWB client mobility, policy handling, and traffic forwarding to work as expected.


URWB client WLANs

A URWB client WLAN (cisco-urwb-client) is a system-generated controller construct used to manage URWB clients. The system creates this WLAN automatically when a user changes the traffic egress point in a URWB profile to controller.

It supports controller-based mobility and policy handling for URWB clients and binds URWB clients to the required policy and forwarding context.

In addition to the WLAN, the system also creates a policy profile named "cisco-urwb-client" automatically. Use this policy profile to create the required mapping between the policy profile and the WLAN.


URWB mobility across subnets

URWB mobility across subnets allows a vehicle AP and the wired devices behind it to remain reachable while moving between infrastructure segments.

Mobility cases:

  • Intra-segment handoff: Roaming within the same subnet, with traffic continuing through the same segment.

  • Inter-segment handoff: Roaming across different subnets, requiring controller-directed traffic handling and forwarding updates.

When inter-segment handoff occurs, the controller updates the forwarding path based on the vehicle AP’s new location while preserving client connectivity.


Limitations of Controller-directed URWB traffic

This feature has the following limitations in release 26.2.1:

  • Only a single controller is supported.

  • Only local mode is supported, FlexConnect is not supported.

  • Controller high availability for controllers are not supported.

  • IPv6 for the management network is not supported.

  • IGMP snooping must be disabled on VLANs used by mobile APs and URWB wired clients. You can use the no ip igmp snooping vlan vlan command for this.

  • Wireless relay is not supported.


How URWB client mobility works

URWB client mobility allows vehicle APs and their downstream wired clients to maintain connectivity while moving between network segments.

The key components involved in the process are:

  • Vehicle AP: The mobile AP that moves between infrastructure subnets.

  • Coordinator AP: The AP that aggregates URWB traffic within a local segment.

  • Wireless LAN Controller: The device that tracks client location and updates forwarding behavior.

The process involves the following stages:

  1. The vehicle AP connects through a coordinator AP and is identified by the controller as a URWB client.

  2. The controller tracks the vehicle AP location, client state, and VLAN context.

  3. When the vehicle AP roams to a new segment, the controller updates the forwarding path.

  4. Traffic for the vehicle AP and wired clients continues without manual reconfiguration.

Result:Clients remain connected and reachable as vehicles move across subnets.


Create VLAN for vehicle AP and wired client (GUI)

Creating dedicated VLANs ensures that traffic from vehicle-based wired clients (such as VLAN 110) and mobile AP management traffic (such as VLAN 111) are correctly identified, segmented, and forwarded by the controller.

Procedure

  1. Choose Configuration > Layer2 > VLAN.

  2. Click the VLAN tab and click the Add button.

    The Create VLAN page is displayed.
  3. Select the Create a single VLAN option and enter these parameters:

    1. VLAN ID: Create separate VLAN IDs for vehicle AP and wired clients. For example, enter 111 as the VLAN ID for vehicle AP and 110 for the wired client.
    2. Name: Enter appropriate names for the VLAN. Ensure that the length of the VLAN name is less than 20 characters.
      Note

      Disable VTPv1 and VTPv2 or switch to VTPv3 before configuring a VLAN name longer than 32 characters.

  4. Click Apply to Device.

The VLANs are created on the controller, segmenting traffic for vehicle APs and wired clients and enabling proper routing and mobility support.


Create VLAN for vehicle AP and wired client

Establish the necessary network segments on the controller to support URWB client data and mobile AP management traffic.

When implementing controller-directed URWB traffic, the controller must be aware of the specific subnets used by mobile devices. Creating dedicated VLANs ensures that traffic from vehicle-based wired clients (such as VLAN 110) and mobile AP management traffic (such as VLAN 111) are correctly identified, segmented, and forwarded by the controller.

Procedure

  1. Use the configure terminal command to enter configuration mode.

    Example:

    Device# configure terminal 
  2. Use the vlan vlan-id command to create VLAN for the vehicle AP.

    Example:

    Device(config)# vlan 111 
  3. Use the vlan vlan-id command to create VLAN for wired clients behind the vehicle AP.

    Example:

    Device(config)# vlan 110 
  4. Use the end command to return to the privileged EXEC mode.

    Example:

    Device(config)# end 

Create URWB profile for mobility role base and client (GUI)

Set up URWB network profiles to ensure centralized traffic management and assign correct mobility roles for mobile clients.

Use this task when you want to establish the controller as the central traffic egress point for mobile clients by defining appropriate URWB profiles and mobility roles.

Procedure

  1. Choose Configuration > Tags & Profiles > URWB Network Profile.

  2. In the General tab, enable the URWB Status and enter the URWB Network Profile Name.

  3. Click the Mobility tab, and complete these steps:

    1. From the Mobility Role drop-down list, select either Base, Base Relay, or Client.
      Note

      When you select Base or Base Relay as the mobility role, the Wired Ports tab is displayed. When you select Client as the mobility role, the Wired Clients tab is displayed.

    2. From the Traffic Egress Point drop-down list select one of these egress points:
      1. Coordinator: Specifies coordinator as the URWB traffic egress point.

      2. WLC: Specifies wireless LAN controller as the URWB traffic egress point.

    3. In the Fast Drop Count field, configure the fast wireless disconnect feature by entering the drop count. The range is 0 to 65535. The default value is 0.
  4. In the Advanced section, under the Mobility Backhaul Check area, complete these steps:

    1. From the Coordinator Down drop-down list, select either Disabled, Handoff-Inhibition, or Relay-Switch, to configure hand-off when the coordinator is unreachable.

    2. From the Ethernet Down drop-down list, select either Disabled, Handoff-Inhibition, or Relay-Switch, to configure hand-off when all the Ethernet ports are disconnected.

  5. In the Mobility Scan section, configure the scan parameters:

    1. Isolation: Scanning takes place when the device is disconnected from the infrastructure. The maximum waiting time before the scanning is triggered is 0 to 65535 ms. The default value is 0.

    2. Periodic: Scanning takes place periodically. The value range is 0 to 65535 seconds. The default value is 0.

    3. RSSI Threshold: Scanning takes place when the RSSI value falls below threshold. The value range is 0 to 96. The default value is 0.

  6. Click Apply to Device.

The URWB network profiles are configured, and the controller functions as the central traffic egress point. Mobility roles for mobile clients are defined, ensuring proper traffic routing and client management.


Configure wired ports (GUI)

Configure which physical Ethernet interface on the URWB device operates as the Secondary LAN Port. This provides an additional wired connection for the network profile.

When you select Base or Base Relay as the mobility role, the Wired Ports tab is displayed. Under Ethernet settings, the secondary port can be disabled or assigned to LAN 1, LAN 2, LAN 3, or LAN 4. Changes may require configuration activation or a reload of the associated AP(s).

Procedure

  1. Choose Configuration > Tags & Profiles > URWB Network Profile.

  2. Select the required URWB profile from the displayed list.

  3. Click the Wired Ports tab

  4. In the Ethernet Settings section, complete these steps:

    1. From the Secondary LAN Port drop-down list, select a secondary LAN port to enable LAN port PoE.
    2. Check the LAN Port PoE check box to enable the LAN port PoE.
      Note

      The Secondary LAN Port and LAN Port PoE configuration has no effect on unsupported APs. This feature is currently supported on Cisco Catalyst 9124AX series APs.

  5. Click Apply to Device to save the configuration.

The selected LAN interface is configured as the secondary LAN port and applied to the device, potentially requiring configuration activation or an AP reload.


Configure wired clients (GUI)

Enable and manage connectivity, authentication, and NAT configuration for wired devices connected to URWB access points.

Procedure

  1. Choose Configuration > Tags & Profiles > URWB Network Profile.

  2. Select the required URWB profile from the displayed list.

  3. Click the Wired Ports tab

  4. In the Ethernet Settings section, complete these steps:

    1. From the Secondary LAN Port drop-down list, select a secondary LAN port to enable LAN port PoE.
    2. Check the LAN Port PoE check box to enable the LAN port PoE. The Secondary LAN Port and LAN Port PoE configuration has no effect on unsupported APs.
  5. In the Local Authentication section, select the RADIUS server group used to authenticate wired clients. The blue shortcut icon opens the RADIUS configuration area if a group must be created or reviewed.

    The selected RADIUS servers must be reachable from the network and already contain the appropriate client credentials or policies.

  6. In the NAT section, check the Enable NAT check box to enable the NAT feature.

  7. In NAT Address, enter the IPv4 address of the AP facing the on-board local network and then enter the subnet mask associated with that address.

  8. Enter the Outside Port Range. The NAT outside port range is from 1 to 65535 unless both are 0.

  9. In the NAT Rules section, click Add and complete these steps to add new rules:

    1. Select the required protocol, normally TCP or UDP.
    2. Enter the outside port on which the NAT address receives the connection. The range for NAT rule outside port is from 1 to 65535.
    3. Enter the IPv4 address of the wired device as the inside IPv4 address.
    4. Enter the inside port on that wired device.
  10. Click Save. The newly added rule is displayed in a table.

Wired devices are configured and connected, authenticated (if required), and NAT rules are applied. The configuration is saved and displayed in the profile.

Create URWB profile for mobility role base and client

Configure URWB network profiles so that the controller is the traffic egress point for both the base role and the client role.

This configuration is required to shift traffic handling from the local coordinator to the controller, enabling centralized traffic management for mobile subnets. Both the mobility role base and client need to configure the egress point to controller.

Before you begin

  • In controller-directed deployments, both profiles must use the traffic egress point `WLC`.

  • The base profile must use mobility role `Base` and the client profile must use mobility role `Client`

Procedure

  1. Use the configure terminal command to enter global configuration mode.

    Example:

    Device# configure terminal 
  2. Use the wireless profile urwb profile command to create or edit the base URWB profile.

    Example:

    Device(config)# wireless profile urwb mb-base-urwb-profile
  3. Use the mobility traffic-egress wlc command to set the controller as the traffic egress point.

    Example:

    Device(config-wireless-urwb-profile)# mobility traffic-egress wlc 
    
  4. Use the exit command to return to the global configuration mode.

    Example:

    Device(config-wireless-urwb-profile)# exit 
  5. Use the wireless profile urwb profile command to create or edit the client URWB profile.

    Example:

    Device(config)# wireless profile urwb mb-client-urwb-profile 
  6. Use the mobility traffic-egress wlc command to set the controller as the traffic egress point for the client.

    Example:

    Device(config-wireless-urwb-profile)# mobility traffic-egress wlc
  7. Use the mobility role client command to set the mobility role for the client profile.

    Example:

    Device(config-wireless-urwb-profile)# mobility role client
  8. Use the end command to return to the privileged EXEC mode.

    Example:

    Device(config-wireless-urwb-profile)# end 
  9. (Optional) Use the show wireless profile urwb detailed profile command to verify the configuration and operating status.

    Example:

    Device# show wireless profile urwb detailed mb-base-urwb-profile
    
    Profile Name                        : mb-base-urwb-profile
    Description                         : 
    Status                              : Disabled
    Multicast                           : Disabled
    RADIUS server group name            : 
    
    Mobility
      Role                              : Base
      Traffic Egress Point              : WLC
      Warm up time                      : 30000
      Timeout for candidate             : 800
      High threshold value              : 6
      Low threshold value               : 3
      Low/High threshold value          : 35
      Advertise signal redundancy       : 1
      Backhaul check ethernet           : Disabled
      Backhaul check Coordinator        : Disabled
      Scanning
        Periodic (s)                    : Disabled
        Isolation (ms)                  : Disabled
        RSSI threshold                  : Disabled
      Fast Drop Count                   : 0
    
    MPLS      
      High Availability                 : Disabled
      High Availability Timeout         : 100
      Unicast flood                     : Disabled
      Unicast flood limitation          : Disabled
      Allow ethernet 1                  : Disabled
      Ethernet Filter Method            : Not Configured
      Ethernet Types List               : Not Configured
    
    MPO
      Status                            : Disabled
      Maximum links                     : 2
      Minimum RSSI to establish         : 20
      CoS                               : 6
      Telemetry status                  : Disabled
    
    Secondary Ethernet
      Port state                      : Disabled
      PoE out                         : Disabled
    
    Reliability
      Gratuitous ARP Status             : Disabled
      QOS Mapping for Priority 0        : 0
      QOS Mapping for Priority 1        : 1
      QOS Mapping for Priority 2        : 2
      QOS Mapping for Priority 3        : 3
      QOS Mapping for Priority 4        : 4
      QOS Mapping for Priority 5        : 5
      QOS Mapping for Priority 6        : 6
      QOS Mapping for Priority 7        : 7
    
    NAT
      Status                            : Disabled

Create policy tag profile (GUI)

Associate the automatically generated URWB WLAN and policy profile with a policy tag.

Procedure

  1. Choose Configuration > Tags & Profiles > Tags.

    The Policy Tag page is displayed.
  2. Click Add.

    The Add Policy Tag page is displayed.

  3. Enter the policy tag name and the description.

  4. In the WLAN-POLICY Maps section, click Add.

    The Map WLAN and Policy section is displayed.

  5. From the WLAN Profile and Policy Profile drop-down lists, map the WLAN and policy profile names, and click the tick-mark button.

  6. Click Apply to Device.

The policy tag profile is successfully created and associated with the default URWB WLAN and policy profile, enabling efficient management of coordinator APs.


Create policy tag profile

Associate the automatically generated URWB WLAN and policy profile with a policy tag.

After enabling the controller-directed URWB feature, the system generates a default WLAN and policy profile (cisco_urwb_client). You cannot modify these parameters. These must be mapped to a policy tag so they can be assigned to the coordinator APs.

Procedure

  1. Use the configure terminal command to enter global configuration mode.

    Example:

    Device# configure terminal 
  2. Use the wireless tag policy policy-tag command to create or edit the policy tag.

    Example:

    Device(config)# wireless tag policy urwb-base-policy-tag
    

    When the feature is enabled in the URWB profile, the system automatically creates a policy profile (cisco_urwb_client ) and a WLAN profile (cisco_urwb_client ).

  3. Use the wlan wlan-profile policy policy-profile command to map the system-created URWB WLAN and policy profile to the policy tag.

    Example:

    Device(config-policy-tag)# wlan cisco-urwb-client policy cisco-urwb-client
  4. Use the end command to return to privileged EXEC mode.

    Example:

    Device(config-policy-tag)# end 

Bind policy tag to coordinator APs (GUI)

Assign the configured URWB policy tag to the coordinator APs to activate the URWB feature on those devices

After creating the policy tag containing the required URWB WLAN and policy profile, you must bind it to the specific coordinator APs to ensure they apply the correct configuration settings.

Procedure

  1. Choose Configuration > Wireless > Access Points.

  2. Click an AP from the list of displayed APs.

    The Edit AP page is displayed.
  3. Click the General tab.

  4. In the General section, enter the AP name and specify location at which the AP is present.

  5. In the Tags section, select the appropriate Policy, Site, and RF tags that you created in the Configuration > Tags & Profiles > Tags page.

  6. Click Update & Apply to Device.

The selected coordinator APs now apply the URWB policy tag and activate their WLAN and policy configurations.


Bind the policy tag to coordinator APs

Assign the URWB policy tag to the coordinator APs so they apply the required URWB WLAN and policy configuration.

After creating the policy tag containing the required URWB WLAN and policy profile, you must bind it to the specific coordinator APs to ensure they apply the correct configuration settings.

Procedure

  1. Use the configure terminal command to enter configuration mode.

    Example:

    Device# configure terminal 
  2. Use the ap ap-mac command to enter AP configuration mode for the target coordinator AP.

    Example:

    Device(config)# ap 0011.2233.4455
  3. Use the policy-tag urwb-policy-tag command to apply the policy tag to the AP.

    Example:

    Device(config-ap-tag)# policy-tag urwb-base-policy-tag
     
    
  4. Use the end command to return to privileged EXEC mode.

    Example:

    Device(config-ap-tag)# end 

Configure VLAN tagging for vehicle AP (GUI)

Enable and assign a VLAN tag to a vehicle access point (AP) so that it can support separate network segments for improved traffic management.

Use this task when you need to assign VLAN tags to vehicle access points to support network segmentation, which can be necessary for isolating traffic types.

Procedure

  1. Choose Configuration > Wireless > Access Points.

  2. Click an AP from the list of displayed APs.

    The Edit AP page is displayed.
  3. Click the Advanced tab.

  4. In the VLAN Tag section, check the VLAN Tag check box to enable the VLAN tag.

    Note

    When changing the VLAN tag, there is a momentary loss of association of the AP with the controller.

    The VLAN Tag ID is displayed.
  5. In the VLAN Tag ID field, enter the VLAN tag ID. The range is from 1 to 4094.

  6. Click Update & Apply to Device.

The vehicle AP is updated with the new VLAN tag.


Configure VLAN tagging for the vehicle AP

Enable VLAN tagging on the vehicle AP so it joins the correct infrastructure VLAN for mobility and traffic handling.

In controller-directed URWB traffic scenarios, vehicle APs operate on different subnets and VLANs than infrastructure coordinators. You must enable VLAN tagging for these APs to maintain correct network segmentation and roaming capabilities.

The configured tag VLAN must not be the same as the wireless management VLAN configured on the controller.

Procedure

Use the ap name ap_name vlan-tag vlan-number command to assign the specific VLAN tag to the vehicle AP.

Example:

Device# ap name Vehicle-AP-01 vlan-tag 111

View the client type information

Use these commands to verify that the controller has correctly identified and programmed the URWB client.

Procedure

  1. Use the show wireless client mac-address mac detail command to confirm that the device is correctly identified as a URWB client. You can view the general client details, including the client type and authentication state.

    Example:

    Device# show wireless client mac-address 5x13.d5f6.264a detail | sec Type
    
    Client MAC Type             : Universally Administered Address
    Client Type                 : URWB Client
    Mobility Roam Type          : None
    Policy Type                 : N/A
    EAP Type                    : Not Applicable
    
  2. Use the show platform hardware chassis active qfp feature wireless wlclient cpp-client mac mac details command to verify the data path tunnel type and confirm that the client is correctly processed by the hardware.

    Example:

    Device# show platform hardware chassis active qfp feature wireless wlclient cpp-client mac 5x13.d5f6.264a details | sec Type
    
      POA Tunnel Type     : DATA
      Client Type         : URWB Client
      P2P Type            : BLOCKING DISABLE
  3. Use the show platform software wireless-client chassis active f0 mac-address mac command to view the global WLAN ID, SSID, and mobility state for a specific URWB client.

    Example:

    Device# show platform software wireless-client chassis active f0 mac-address 5x13.d5f6.264a
    
    ID                           : 0xa0000003
    MAC address                  : 5x13.x5x6.264a
    Type                         : URWB Client
    Global WLAN ID               : 5
    SSID                         : cisco_urwb_client
    Client index                 : 0
    Mobility state               : Local
    Authentication state         : Run