接口 :web
virtual interface : (
二三层漫游)
用于支持移动性管理需求 (客户端漫游时的网关)
DHCP中继
嵌入式三层安全
guest web认证 (web认证重定向地址)
×××终结
客户端在不一样控制器和客户端之间通讯
在一个网络里其余设备不一样配置和virtual interface相同的地址 不能被映射到任何物理口 不能存在与路由表中全部控制器在一个移动组里virtual interface必须配置相同的IP
Enter the following parameters:
• Any fictitious, unassigned, and unused gateway IP address
• DNS gateway hostname
To ensure connectivity and web authentication, the DNS server should always point to the virtual interface.
If a DNS hostname is configured for the virtual interface, then the same DNS host name must be configured
on the DNS server(s) used by the client.
config interface address dynamic-interface/management/service-port/virtual x.x.x.x
config interface hostname virtual
show interface detailed virtual
Service-Port Interface
默认网关不能设置为service接口IP
控制器上能够定义远端网络到达服务接口的路由
用于控制器的带外网管
一般预留一个VLAN和子网供WLC和LWAPP使用,可将管理子网中的IP分配给管理接口和AP管理接口
外部管理数据流(web,telnet,ssh,aaa)和LWAPP都到达此地址
因为LAP分布于不一样的位置,LAP的数据流视为外部数据流
config route add
network-ip-addr ip-netmask gateway
可经过config route add x.x.x.x x.x.x.x来定义远程工做站到控制器的路由
show interface detailed service-port
Interface Name................................... service-port
MAC Address...................................... 00:0c:29:16:0c:f0
IP Address....................................... 172.16.1.254
IP Netmask....................................... 255.255.255.0
DHCP Protocol.................................... Disabled
AP Manager....................................... No
Guest Interface.................................. No
动态接口 : (
桥接无线客户端的接口)
即vlan 接口,被用户建立用作客户端的vlan,也称用户口
一台控制器最多支持512个动态接口 客户端关联到无线接口的DHCP中继
二层管理口 , 三层AP管理口
全部的动态口必须在不一样的VLAN或IP子网中
Wireless Controllers |
Maximum VLANs |
Cisco Virtual Wireless Controller |
512 |
Cisco Wireless Controller Module for ISR G2 |
16 |
Cisco 2500 Series Wireless Controllers |
16 |
Cisco 5500 Series Wireless Controller |
512 |
Cisco Catalyst 6500 Series Wireless Services
Module2 (WiSM2) 512
Cisco Flex 7500 Series Cloud Controller 4,096
Cisco 8500 Series Controller 4,096
If you are using DHCP proxy and/or a RADIUS source interface, ensure that the dynamic interface has
a valid routable address. Duplicate or overlapping addresses across controller interfaces are not supported.
We recommend using tagged VLANs for dynamic interfaces
AP-manager interface :
控制器和AP之间的3层通讯
WLC在此接口上侦听LAP试图发现控制器时发送的子网广播 新版本复用了manage interface
用作AP到控制器之间的CAPWAP/LWAPP隧道间的关联和通讯