Tuesday, April 3, 2018

Deploying Wireless with Routed Access LAN Design.

Has there ever been a SRND, CVD or reference to specifically deploying Wireless LANs with Routed Access LAN design?

I'm looking for a resource to explain how to deploy a Wireless Network with the following characteristics:

  1. Cannot be a centralized deployment (i.e. CAPWAP tunnelled to WLC), due to my network having routine loss of connectivity to the DC (it's a maritime environment).
  2. Would need to support Cisco FlexConnect as per the above reasons to ensure clients can associate in a WAN down scenario, with local switching and a local RADIUS auth server available when ISE cube is unreachable.
  3. Two SSIDs - Corp and Guest
  4. VRF-aware - supporting path isolation at L2 and L3 for compliance purposes.

Roaming is one of the major issues that I want to overcome - support for BSS Fast Transition (and other MAC layer functions) is lost because that part of the Cisco Split-MAC architecture is handled by the Cisco 5520 WLC and not the APs. However, I don't want to extend a VLAN across the entire LAN to support L2 Roaming between APs that are connected to switch stacks in different racks. L3 Roaming via the WLC is not feasible because of the poor connectivity to the DC, which would time out anyway. Converged Access, on paper, looked like the kind of thing I could have used but it's EoL and was buggy anyway.

It's also undesirable to have traffic tromboning back and forth across a bandwidth-limited WAN link, so the Corp and Guest Networks need to be able to securely reach local resources, whilst allowing for path isolation/segmentation with VLANs and VRF-Lite. Without moving a ISE Policy Node onto every single vessel (financially not feasible), I have to rely on a backup auth server to provide some enterprise authentication fucntions, but I'd like the onboard RADIUS server to be the backup auth server for client authentication onboard - when WAN connectivity is available, use the ISE Policy Nodes in the DC.

I feel like I've got pretty close to a conceptually valid network design that fits my rather obscure use case, but I cannot find a single resource that adequately covers implementing Wireless in a Routed Access LAN, as a reference point.

I've even considered running a vWLC onboard an ISR4K, but it would be an expensive option with relatively limited features when compared to a pair of 5520 WLCs in HA.

Any tips or advice would be much appreciated.



No comments:

Post a Comment