WLC ports & WLAN deployment planning
Management of Cisco APs is usually done by connecting to the WLC in a web browser (HTTP/HTTPS). For initial boot monitoring or quick, basic changes, you can also use a direct serial console connection. Once an AP is online and has a management IP address, you can use Telnet or (preferably) SSH to access the Command Line Interface (CLI) over the wired network.
WLC physical and logical ports
WLCs include several port types that support network connectivity and management.
Physical ports
- Serial (Console) Port: Used for initial setup and troubleshooting.
- Ethernet Service Port: Provides out-of-band management access via SSH or the GUI (web browser).
- Redundancy Port: A dedicated physical interface used for High Availability (HA) setups (like SSO). It synchronizes bulk/incremental data, negotiates roles, and carries keep-alive messages between Active and Standby controllers.
- Ethernet (Data) Ports: The primary ports for most traffic, including control and data CAPWAP tunnels to APs, plus in-band management traffic. On AireOS controllers, these are called distribution system ports (referring to the wired network).
- Trunking and LAG: WLC Ethernet ports must carry traffic for many VLANs, so they should be configured for 802.1Q trunking. For resiliency and load balancing (and additional bandwidth), you can bundle multiple Ethernet ports into a Link Aggregation Group (LAG), similar to an EtherChannel on a switch. The connected switchports must also be configured as an EtherChannel.
Image 256
Image Title - Image of WLC and its physical ports
Logical ports (interfaces)
- Dynamic Interfaces: Used to map wired VLANs to wireless LANs. AireOS controllers require an IP address, subnet mask, default gateway, and DHCP server configuration for each dynamic interface (per VLAN). IOS-XE controllers, on the other hand, treat these as Layer 2, meaning the controller doesn’t need an IP address for each VLAN.
- Wireless Management Interface (WMI): Handles in-band management traffic, including RADIUS authentication, SSH, GUI administration (via the web browser: HTTP), SNMP monitoring, syslog messages, NTP synchronization, and inter-controller communication. It also terminates CAPWAP tunnels from APs. It requires an IP address, subnet mask, and default gateway. On IOS-XE controllers, the WMI is often a Switched Virtual Interface (SVI).
- Virtual Interface: Used for specific client-facing operations, such as relaying DHCP requests to a DHCP server or supporting client mobility. Clients perceive the controller’s virtual interface address as the DHCP server. This address is never used for controller-to-network device communication and should be configured with a non-routable, unpingable IP address (e.g., 1.1.1.1), or a non-routable private IP address used strictly for the Virtual Interface. For seamless client roaming, all controllers in the same mobility group should use an identical virtual interface address.
Accessing the WLC GUI
To configure a WLC, you typically use its web-based Graphical User Interface (GUI). Open a browser and navigate to the WLC’s management IP address using HTTP or HTTPS.
This assumes the controller has already been given an initial configuration (including a management IP address). For HTTPS access, the controller must also have a valid SSL certificate available for the connection.
Both the GUI and CLI require user authentication. Authentication can be handled by:
- A local user database on the controller
- External Authentication, Authorization and Accounting (AAA) servers such as TACACS+ or RADIUS
After you log in to an IOS-XE controller, you’ll land on a dashboard. To make configuration changes, select Configuration from the left-side menu. On AireOS controllers, click the Advanced link in the upper-right corner to access configuration options.
Image 257
Image Title - Image of WLC logon screen
The GUI layout differs between platforms:
- IOS-XE controllers show a vertical list of configuration categories on the left.
- AireOS controllers use tabs across the top, with function lists on the left.
Even though the navigation looks different, both platforms provide access to the same core wireless configuration settings.
Planning your WLAN deployment
Before you create WLANs, plan the design. WLANs (like VLANs) can separate users and traffic, but there are practical limits.
- WLAN Limits: Cisco controllers support a maximum of 512 WLANs, but only 16 can be actively used on a single AP. For best practice purposes, however, 5 or fewer WLANs is ideal for efficiency.
- Airtime Consumption: Each WLAN requires APs to broadcast beacon management frames at regular intervals (typically 10 times per second) to advertise its existence. More WLANs mean more beacons, consuming valuable airtime, especially at lower mandatory data rates. Excessive beacons can starve the channel, impacting client data transmission. A general rule of thumb is to limit WLANs to five or fewer, with three being ideal.
Key parameters to plan for each WLAN include:
- The Service Set Identifier (SSID) string.
- The controller interface and corresponding VLAN number.
- The type of wireless security required.
Wireless security protocols: WPA, WPA2, and WPA3
Understanding wireless security protocols is important for CCNA 200-301 v1.1 exam preparation and for real deployments. Wi‑Fi security has evolved over time to address weaknesses and improve protection.
Encryption in wireless networks
Wireless signals travel through free space, so anyone within range can potentially capture frames. Encryption is what prevents those captured frames from being readable.
- Purpose: Encryption scrambles data sent over the wireless medium so it’s unreadable without the correct decryption key. This protects confidentiality and helps protect integrity.
- Client-AP Communication: Clients and APs must agree on security settings (including encryption) when the client associates to a BSS.
- WLC and Security Management: In centralized wireless designs, the WLC is a key point of control. It can authenticate clients using a central service, enforce security policies (for example, requiring clients to obtain an IP address from a trusted DHCP server before granting access), and provide centralized monitoring for intrusion detection/prevention, QoS, and bandwidth policing.
- Data and Control Traffic Encryption: Encryption depends on the deployment mode. For example, in Cisco FlexConnect mode, by default only control traffic (AP-to-WLC management communication) is encrypted, while user data is locally switched and not encrypted by the CAPWAP tunnel. For solutions like OfficeExtend (teleworker deployments), both control and data traffic are encrypted with Datagram Transport Layer Security (DTLS) to protect traffic across untrusted networks. This is a good reminder to always confirm where encryption is applied in a given design.
WPA (Wi-Fi Protected Access)
WPA was introduced as an interim replacement for the fundamentally flawed WEP (Wired Equivalent Privacy). WPA uses TKIP (Temporal Key Integrity Protocol) and adds per-packet key mixing plus a message integrity check to detect tampering.
WPA was a major improvement over WEP, but it has since been deprecated due to vulnerabilities. Avoid WPA unless you must support legacy devices.
WPA2 (Wi-Fi Protected Access 2)
WPA2 became the long-standing industry standard and a requirement for Wi‑Fi certification. It uses AES (Advanced Encryption Standard) with CCMP (Counter Mode with Cipher Block Chaining Message Authentication Code Protocol) for strong encryption.
WPA2 supports two authentication modes:
WPA2 is still widely deployed, although WPA3 adds newer protections.
WPA3 (Wi-Fi Protected Access 3)
WPA3 is the latest generation of Wi‑Fi security and adds several improvements:
- SAE (Simultaneous Authentication of Equals): Replaces PSK with a more secure handshake resistant to offline dictionary attacks.
- Forward secrecy: Protects previously captured traffic even if the passphrase is later compromised.
- Enhanced encryption: 192-bit security suite for high-security networks.
- Protection against brute-force attacks: Makes password guessing much more difficult.
WPA3-Personal improves security while keeping configuration relatively simple. WPA3-Enterprise adds features aimed at larger organizations. Many controllers support transitional modes (WPA2+WPA3) to support mixed client environments during migration.