Converged Wired and Wireless Access
Provisioning a Small Branch WLAN
95
Best Practice User Guide for the Catalyst 3850 and Catalyst 3650 Switch Series
Configure QoS Service Policies for an Open WLAN
Step 3
Configure service policies for ingress and egress traffic for an open WLAN.
All ingress traffic is classified the same as wired traffic, but egress traffic is allocated only 30% of the
available bandwidth.
When configuring QoS for an open WLAN, a low priority WLAN should be created for guest usage. The
end users on an open WLAN are restricted and should not impact business-critical traffic on secure
enterprise WLANs.
All WLANs share the port_child_policy egress policy. The policy is configured by default and is not
explicitly configured on a WLAN.
DHCP Snooping
Step 4
DHCP snooping configuration is required on the controller for proper client join functionality.
DHCP snooping needs to be enabled on each client VLAN including the override VLAN if override
is applied on the WLAN.
Enable bootp-broadcast command. It is needed for clients that send the DHCP messages with broadcast
addresses and broadcast bit is set in the DHCP message.
On the interface:
Note
If upstream is via a port channel, the trust Config should be on the port channel interface as well.
Note
DHCP snooping should be configured on the Guest Anchor controller for guest access similar to the
Config above.
To allow ingress and egress traffic on the network, the -required option in the WLAN settings forces
clients to perform an address request and renew operation each time an association is made with the
WLAN. This option allows strict control of used IP addresses.
wlan-Guest-Client-Input-Policy
ip dhcp snooping wireless bootp-broadcast enable
interface TenGigabitEthernet1/0/1
Содержание Catalyst 3850
Страница 2: ......
Страница 4: ......
Страница 10: ...Contents vi Cisco Catalyst 3850 Series and Cisco Catalyst 3650 Series Switches Best Practices Guide ...