Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

PDF

Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

Wireless guest access

Want to summarize with AI?

Log in

Explains the Wireless Guest Access feature that provides internet access to guests in a secure and accountable manner.


Wireless guest access is a network security feature that

  • provides internet access to guests in a secure and accountable manner

  • uses the enterprise's existing wireless and wired infrastructure to the maximum extent, and

  • reduces the cost and complexity of building a physical overlay network.

Wireless guest access architecture and components

The Wireless Guest Access solution comprises of two controllers - a Guest Foreign and a Guest Anchor. An administrator can limit bandwidth and shape the guest traffic to avoid impacting the performance of the internal network.

Note
  • When a client joins through a capwap tunnel from an AP, the RADIUS NAS-Port-Type is set as "wireless 802.11". Here, Point of Attachment (PoA) and Point of Presence (PoP) is the same.

  • When a client joins through a mobility tunnel, the RADIUS NAS-Port-Type is set as "virtual". Here, PoA is the Foreign controller and PoP is the Anchor controller as the client is anchored. For information on the standard types, see the following link:

    https://www.iana.org/assignments/radius-types/radius-types.xhtml#radius-types-13

Wireless Guest Access feature comprises these functions:

  • Guest Anchor controller is the point of presence for a client.

  • Guest Anchor Controller provides internal security by forwarding the traffic from a guest client to a Cisco Wireless Controller in the demilitarized zone (DMZ) network through the anchor controller.

  • Guest Foreign controller is the point of attachment of the client.

  • Guest Foreign Controller is a dedicated guest WLAN or SSID and is implemented throughout the campus wireless network wherever guest access is required. A WLAN with mobility anchor (guest controller) configured on it identifies the guest WLAN.

  • Guest traffic segregation implements Layer 2 or Layer 3 techniques across the campus network to restrict the locations where guests are allowed.

  • Guest user-level QoS is used for rate limiting and shaping, although it is widely implemented to restrict the bandwidth usage for a guest user.

  • Access control involves using embedded access control functionality within the campus network, or implementing an external platform to control guest access to the Internet from the enterprise network.

  • Authentication and authorization of guests that are based on variables, including date, duration, and bandwidth.

  • An audit mechanism to track who is currently using, or has used, the network.

  • A wider coverage is provided by including areas such as lobbies and other common areas that are otherwise not wired for network connectivity.

  • The need for designated guest access areas or rooms is removed.

Note
To use IRCM with AireOS in your network, contact Cisco TAC for assistance.

This table shows controller support for guest access functions.

Table 1. Supported controllers

Controller Name

Supported as Guest Anchor

Supported as Guest Foreign

Cisco Catalyst 9800-40 Wireless Controller

Yes

Yes

Cisco Catalyst 9800-80 Wireless Controller

Yes

Yes

Cisco Catalyst 9800-CL Wireless Controller

Yes

Yes

Cisco Catalyst 9800-L Wireless Controller

Yes

Yes

Cisco Catalyst 9800 Embedded Wireless Controller for Switch

No

No

Cisco Catalyst 9800 Embedded Wireless Controller on Cisco Catalyst 9100 Series APs

No

No

This is a list of features supported by Cisco Guest Access:

  • Sleeping Clients

  • FQDN

  • AVC (AP upstream and downstream)

  • Native Profiling

  • Open Authentication

  • OpenDNS

  • Supported Security Methods:

    • MAB Central Web Authentication (CWA)

    • Local Web Authentication (LWA)

    • LWA on MAB Failure

    • 802.1x + CWA

    • 802.1x

    • PSK

    • 802.1x + LWA

    • PSK + CWA

    • PSK + LWA

    • iPSK + CWA

    • MAB Failure + PSK

    • MAB Failure + OWE

    • MAB Failure + SAE

  • SSID QoS Upstream and Downstream (Foreign)

  • AP/ Client SSO

  • Static IP Roaming

  • Client IPv6

  • Roaming across controllers

  • RADIUS Accounting

    Note
    In a guest access scenario, accounting is always performed at the foreign controller for all authentication methods.
  • QoS: Client-Level Rate Limiting

  • Guest Anchor Load Balancing

  • Workgroup Bridges (WGB)

Note
To enable the controller to support multiple VLANs from a WGB, use wgb vlan command.

Foreign map

A foreign map is a guest access feature that

  • supports guest access using Policy Profile and WLAN Profile configuration models in the controller

  • is achieved with policy profile and WLAN profile config model, and

  • configures two different WLAN profiles on two Guest Foreigns where seamless roaming is not allowed between them.

Foreign map configuration

Foreign Map support in Cisco Catalyst 9800 Series Wireless Controller is achieved with the policy profile and WLAN profile configuration model.

Foreign map commands

  • Guest Foreign commands:

    • Foreign1: wlanProf1 PolicyProf1

    • Foreign2: wlanProf2 PolicyProf2

  • Guest Anchor commands:

    • wlanProf1, wlanProf2

    • PolicyProf1: Vlan100 - subnet1

    • PolicyProf2: Vlan200 - subnet2

Foreign map roaming

Configure two different WLAN profiles on the two Guest Foreigns and seamless roaming is not allowed between them. This is expected configuration. However, seamless roaming is allowed if the same WLAN profile is configured on two Guest Foreigns, but it prevents Foreign Map feature from working.


Wireless Guest Access: Use Cases

The wireless guest access feature can be used to meet different requirements. Some of the possibilities are shared here.

Scenario One: Providing Secured Network Access During Company Merger

This feature can be configured to provide employees of company A who are visiting company B to access company A resources on company B network securely.

Scenario Two: Shared Services over Existing Setup

Using this feature, you can provide multiple services using multiple vendors piggy backing on the existing network. A company can provide services on an SSID which is anchored on the existing controller. This is while the existing service continues to serve over the same controller and network.


Guidelines for wireless guest access

Match the security profiles under WLAN on both Guest Foreign, and Guest Anchor.

  • Match the policy profile attributes such as NAC and AAA Override on both Guest Foreign, and Guest Anchor controllers.

  • On Export Anchor, the WLAN profile name and Policy profile name is chosen when a client joins at runtime and the same should match with the Guest Foreign controller.


Recommendation: troubleshooting IPv6

When a guest export client cannot get a routable IPv6 address through SLAAC or cannot pass traffic when the IPv6 address is learned through DHCPv6, you can use these workarounds:

  • On IPv6 Routers: You can work around the RA multicast to unicast conversion by modifying behavior on the IPv6 gateway. Depending on the product, this may be the default behavior or may require configuration.

  • On Cisco IPv6 Routers: Configure unicast RA depending on your platform.

  • On non-Cisco IPv6 Routers: If non-Cisco network devices do not support configuration command to enable solicited unicast RA then a work around does not exist.

For Cisco IPv6 Routers:

  • Cisco Nexus platform: Has solicited unicast RA enabled by default to help with wireless deployment.

  • Cisco IOS-XE platform: Use the following configuration command to turn on unicast RA to help with wireless deployment:

    ipv6 nd ra solicited unicast


Load balancing among multiple guest controllers

Load balancing among multiple guest controllers is a network configuration feature that

  • distributes large guest client volumes across up to 72 controllers for a single export foreign guest WLAN configuration

  • supports priority-based anchor configuration with primary anchors (priority 1,3) and backup anchors for failure scenarios, and

  • automatically handles failover by disconnecting clients from failed primary anchors and redirecting them to secondary anchors.

Configuration and failover behavior

To configure mobility guest controllers, use mobility anchor ip address .

You can specify primary anchors with priority (1,3) and choose another anchor as backup in case of failure.

In a multi-anchor scenario, when the primary anchor goes down, the clients get disconnected from the primary anchor and joins the secondary anchor.

When the highest priority anchor goes down before the keep-alive timeout completes, the export anchor request for new clients fails, and Foreign selects the next highest priority Anchor in the list to export the clients.


Configure mobility tunnel for guest access (GUI)

Enable secure guest network access by establishing a mobility tunnel that allows traffic to traverse between network segments while maintaining security policies.

Use this procedure when setting up guest network access that requires mobility tunneling to route guest traffic through designated mobility anchors in your wireless infrastructure.

Procedure

1.

Choose Configure > Tags and Profiles > WLANs.

2.

In the Wireless Networks area, click the relevant WLAN or RLAN and click Mobility Anchor.

3.

In the Wireless Network Details section, choose a device from the Switch IP Address drop-down list.

4.

Click Apply.

The mobility tunnel for guest access is configured and the selected switch is designated as the mobility anchor for the wireless network.


Configure mobility tunnel for guest access (CLI)

Configure a mobility tunnel to enable guest access across mobility groups.
Follow the procedure given below to configure a mobility tunnel. This allows guest clients to roam between access points in different mobility groups while maintaining their network session.

Procedure

1.

Configure a mobility group.

Example:

Device(config)# wireless mobility group name group-name

Example:

Device(config)# wireless mobility group name mtunnelgrp
2.

Configure a mobility MAC address.

Example:

Device(config)# wireless mobility mac-address mac-address

Example:

Device(config)# wireless mobility mac-address 0d:4c:da:3a:f2:21
3.

Configure a mobility peer.

Example:

Device(config)# wireless mobility group member mac-address mac-address ip ip-address group group-name

Example:

Device(config)# wireless mobility group member mac-address df:07:a1:a7:a8:55 ip 206.223.123.2 group mtgrp
The mobility tunnel is now configured, allowing guest clients to seamlessly roam between controllers in the mobility group.

Configure guest access policy (GUI)

Configure guest access policies to manage how guest users connect to and use your wireless network.

Guest access policies define the network access parameters and security settings for temporary users who need network connectivity without full user credentials.

Procedure

1.

Choose Configuration > Tags & Profiles > Policy.

2.

Click Add.

3.

In the General tab, enter the Name and enable the Central Switching toggle button.

4.

In the Access Policies tab, under the VLAN settings, choose the vlans from the VLAN/VLAN Group drop-down list.

5.

In the Mobility tab, under the Mobility Anchors settings, check the Export Anchor check box.

6.

In the Advanced tab, under the WLAN Timeout settings, enter the Idle Timeout (sec).

7.

Click Apply to Device.

The guest access policy is configured and applied to the device, allowing guest users to access the network according to the defined parameters.


Configure guest access policy (CLI)

Create and configure a guest access profile policy to enable guest networking on wireless clients.

Follow the procedure given below to create and configure the guest access profile policy. Alternately, you may use the existing default policy profile after configuring the mobility anchor to that policy.

You can only configure anchors which are peers. Ensure that the IP address that is used is a mobility peer and is included in the mobility group. The system shows an invalid anchor IP address error message when any other IP address is used.

To delete the mobility group, ensure that the mobility peer which is also a mobility anchor is removed from the policy profile.

Note
  • No payload is sent to Guest Foreign to display the VLAN.

  • To avoid a client exclusion from occurring due to VLAN, Cisco Catalyst 9800 Series Controllers need to define VLAN along with the associated name being pushed from ISE.

Procedure

1.

Enter global configuration mode.

Example:

Device# configure terminal
2.

Configure the policy profile and enter wireless profile configuration mode.

Example:

Device(config)# wireless profile policy wlan-policy-profile

Example:

Device(config)# wireless profile policy guest-test-policy
Note
  • You can use the default-policy-profile to configure the profile policy.

3.

Shut down the policy if it exists before configuring the anchor.

Example:

Device(config-wireless-policy)# shutdown
4.

(Optional) Enable central switching.

Example:

Device(config-wireless-policy)# central switching
5.

Configure Guest Foreign or Guest Anchor.

  • Configure Guest Foreign with anchor IP address
  • Configure Guest Anchor

Example:

For Guest Foreign:

Device(config-wireless-policy)# mobility anchor anchor-ip-address

For Guest Anchor:

Device(config-wireless-policy)# mobility anchor

Example:

For Guest Foreign:

Device(config-wireless-policy)# mobility anchor 19.0.2.1

For Guest Anchor:

Device(config-wireless-policy)# mobility anchor
6.

(Optional) Configure duration of idle timeout, in seconds.

Example:

Device (config-wireless-policy)# idle-timeout timeout

Example:

Device (config-wireless-policy)# idle-timeout 1000
7.

Configure VLAN name or VLAN ID.

Example:

Device(config-wireless-policy)# vlan vlan-id

Example:

Device(config-wireless-policy)# vlan 2
Note
VLAN is optional for a Guest Foreign controller.
8.

Enable policy profile.

Example:

Device(config-wireless-policy)# no shutdown
9.

Exit the configuration mode and return to privileged EXEC mode.

Example:

Device(config-wireless-policy)# end
10.

(Optional) Display the configured profiles.

Example:

Device# show wireless profile policy summary
11.

(Optional) Display detailed information of a policy profile.

Example:

Device# show wireless profile policy detailed policy-profile-name

Example:

Device# show wireless profile policy detailed guest-test-policy
The guest access policy is configured and enabled, allowing guest clients to connect using the specified mobility anchor and VLAN settings.

View guest access debug information (CLI)

View guest access debug information using commands.

  • To display client level detailed information about mobility state and the anchor IP address, use this command:

    show wireless client mac-add mac-address detail

  • To display the client mobility statistics, use this command:

    show wireless client mac-address mac-address mobility statistics

  • To display client level roam history for an active client in sub-domain, use this command:

    show wireless client mac-address mac-address mobility history

  • To display detailed parameters of a given profile policy, use this command:

    show wireless profile policy detailed policy-name

  • To display the global level summary for all mobility messages, use this command:

    show wireless mobility summary

  • To display the statistics for the Mobility manager, use this command:

    show wireless stats mobility


Verify wireless guest access enablement

To check if wireless guest access is enabled, run this command.

Device# show platform hardware chassis  active  qfp feature sw client vlan all

-------------------------------------------------------------
Vlan : 666
Learning Enabled : true
DHCPSN Enabled : true
Non IP Multicast Enabled : false
Broadcast Enabled : false
Wireless Passive Client Enabled : false
Guest-Lan Enabled : true 
MTU : 65535
Input UIDB : 65503
Output UIDB : 65497
Flood List : 0XB8658A0