
Document ID: 112042
Updated: Dec 18, 2013
Contributed by Nicolas Darchis, Cisco TAC Engineer.
Contents
Introduction
This document describes the feature matrix for the FlexConnect feature on the Wireless LAN Controller (WLC). This feature matrix applies to Cisco Unified Wireless Network (CUWN) Releases 7.5 and earlier.
Prerequisites
Requirements
Cisco recommends that you have knowledge of these topics:
- Control and Provisioning of Wireless Access Points (CAPWAP) protocol
- Configuration of lightweight Access Points (APs) and Cisco WLCs
Components Used
The information in this document is based on CUWN Releases 7.0.98.0 and later.
Background Information
FlexConnect
FlexConnect is a wireless solution for branch office and remote office deployments. It enables you to configure and control APs in a branch or remote office from the corporate office through a WAN link without the deployment of a controller in each office. The FlexConnect APs can switch client data traffic locally and perform client authentication locally. When they are connected to the controller, they can also send traffic back to the controller. FlexConnect is only supported on these components:
- 1130AG, 1140, 1240AG, 1250, AP801, 1600, 2600, 3500I, 3500E, 3600, 1040, 1520, 1550, and 1260 APs
- Cisco Flex 8500 and 7500, Cisco 5500, 4400, and 2500 Series Controllers
- Catalyst 3750G Integrated WLC Switch
- Cisco WiSM and WiSM2
- Controller Network Module for Integrated Services Routers
FlexConnect local authentication is useful where you cannot maintain a remote office setup with a minimum bandwidth of 128 kb/s and a round-trip latency of no greater than 100 ms. The maximum tolerated latency for FlexConnect is 300 ms, regardless of the features that are used.
FlexConnect Feature Matrix
This section outlines the legacy and new features in FlexConnect Releases 7.0.116.0 and later.
Security - Client
Security support on the FlexConnect varies with different modes and states. This table summarizes the security features that are supported:
WAN Up (Central Switching) | WAN Up (Local Switching) | WAN Up (Local Switching, Local Authorization) | WAN Down (Standalone) | |
---|---|---|---|---|
Open/Static WEP | Yes | Yes | Yes | Yes |
WPA-PSK | Yes | Yes | Yes | Yes |
802.1x (WPA/WPA2) | Yes | Yes | Yes | Yes |
MAC filter Authentication | Yes | Yes | No | No |
CCKM Fast Roaming | Yes | Yes | Yes | Yes, for connected clients. No, for new clients. |
Security - Infrastructure
WAN Up (Central Switching) | WAN Up (Local Switching) | WAN Down (Standalone) | |
---|---|---|---|
Data DTLS Encryption | Yes | N/A | N/A |
Local EAP (7.0 to 7.4) | Yes (LEAP/EAP-FAST) | Yes (LEAP/EAP-FAST) | Yes (LEAP/EAP-FAST) |
LocaL EAP (7.5 and above) | Yes (LEAP/EAP-FAST/PEAP/EAP-TLS) | Yes (LEAP/EAP-FAST/PEAP/EAP-TLS) | Yes (LEAP/EAP-FAST/PEAP/EAP-TLS) |
Backup Radius | Yes (7.0.116) | Yes (7.0.116) | Yes |
Security
Security support on the FlexConnect varies with different modes and states. This table summarizes the legacy and new security features supported with WLC Versions 7.0.116.0 and later:
WAN Up (Central Switching) | WAN Up (Local Switching) | WAN Up (Local Switching, Local Authorization) | WAN Down (Standalone) | |
---|---|---|---|---|
Wireless Intrusion Prevention (WIPS) | Yes | Yes | Yes | No |
Rogue, Intrusion Detection (IDS) | Yes | Yes | Yes | No |
Management Frame Protection (MFP) (Client, Infrastructure) | Yes | Yes | Yes | No |
802.11w "MFP" | Yes (7.5) | Yes (7.5) | Yes (7.5) | Yes (7.5) |
802.11r Fast Transition | Yes | Yes | Yes | No |
Self-Signed Certificate (SSC) | Yes | Yes | Yes | No |
Rogue Location Discovery Protocol (RLDP) | Might work depending on hops, WAN speed | Might work depending on hops, WAN speed | Might work depending on hops, WAN speed | No |
Opportunistic Key Caching (OKC) Fast Roam | Yes | Yes | Yes | No(1) |
FlexConnect Local Auth | N/A | Yes | Yes | Yes |
AAA Override | Yes | Yes | Yes | Yes |
static ACL | Yes | Yes(2) No | Yes(2) No | Yes(2) No |
per-user radius ACL | Yes (7.5) | Yes (7.5) | Yes (7.5) | No |
L2 ACL | Yes (7.5) | Yes (7.5) | Yes (7.5) | Yes (7.5) |
P2P Blocking | Yes | Yes | Yes | Yes |
Bring Your Own Device (BYOD) | Yes | Yes (7.2.110.0) | No | No |
PCI Compliance for Neighbor Pkts | Yes | Yes | Yes | No |
Russia DTLS Support | Yes | N/A | No | No |
wIPS Enhanced Local Mode (ELM) | Yes | Yes | Yes | No |
Limit Clients per WLAN | Yes | Yes(3) | Yes | No |
Limit Clients per Radio | Yes | Yes | Yes | Yes |
Client Exclusion Policy | Yes | Yes(3) | Yes | No |
Radius NAC | Yes | Yes | No | No |
TrustSec SXP | No | No | No | No |
(1) Yes for clients that have association at Connected mode. |
Voice & Video
This table lists the legacy and new Voice & Video services supported with WLC Versions 7.0.116.0 and later with FlexConnect:
WAN Up (Central Switching) 100 ms RTT | WAN Up (Local Switching) 100 ms RTT | WAN Down (Standalone) | |
---|---|---|---|
Voice | Yes with RTT 100 ms | Yes with RTT 100 ms | Yes with RTT 100 ms |
Yes with RTT 900 ms (with CCKM and OKC) | Yes with RTT 900 ms (with CCKM and OKC) | ||
QoS Markings(1) | Yes | Yes | Yes |
QoS Per-User Bandwidth Contract | Yes (7.4) | Yes (7.5) | No |
UAPSD | Yes | Yes | Yes |
Voice Diagnostics | Yes | Yes | No |
Voice Metrics | Yes | Yes | No |
TSPEC /Call Admission Control (CAC) | Yes - non CCX | Yes - non CCX | No |
Yes - CCX(2) | Yes - CCX(2) | ||
(1) Includes both DSCP/dot1p markings. |
Services
This table lists the legacy and new services supported with WLC Version 7.0.116.0 with FlexConnect:
WAN Up (Central Switching) | WAN Up (Local Switching) | WAN Up (Local Switching, Local Authorization ) | Wan Down (Standalone) | |
---|---|---|---|---|
Internal Webauth | Yes | Yes | No | No |
External Webauth | Yes (7.2.110.0) | Yes (7.2.110.0) | No | No |
CleanAir (SI on 3500) | Yes | Yes | Yes | No |
Multicast-Unicast (Videostream) | Yes (except on 7500, 8500 and vWLC) | N/A | N/A | N/A |
Location | Yes with BW/Scale limitation | Yes with BW /Scale limitation | Yes with BW /Scale limitation | N/A |
Radio Ressource Management | Yes | Yes | Yes | No |
NG RRM ? RF Static Grouping | Yes(1) | Yes(1) | Yes | No |
SE Connect (Cleanair Update) | Yes | Yes | Yes | No(2) |
S60 Enhancement | Yes | Yes | Yes | No |
Profiling | Yes | Yes | Yes | No |
(1) Any RRM-specific requirements apply (at least 4 APs for TPC). |
Infrastructure
WAN Up (Central Switching) | WAN Up (Local Switching) | WAN Down (Standalone) | |
---|---|---|---|
Passive Clients | No | No | No |
Syslog | Yes | Yes | Yes |
CDP | Yes | Yes | Yes |
Client Link | Yes | Yes | No |
Load Balancing | Yes (7.4) | Yes (7.5) | Yes (7.5) |
Band Select | Yes | Yes | No |
AP Image PreDownload | Yes | Yes | No |
FlexConnect Smart AP Image Upgrade | Yes | Yes | Yes(1) |
AP Regularity Domain Updates (Chile) | Yes | Yes | Yes |
VLAN Pooling/Mcast Optim. | Yes | N/A | N/A |
Mesh ? 24 backhaul | N/A | N/A | N/A |
Cisco WGB Support (2) | Yes | Yes (7.3) | No |
3rd party WGB Support | Yes | Yes | Yes |
Web Auth Proxy | Yes | Yes | No |
FlexConnect AP Group Increase | Yes | Yes | Yes |
Client fault tolerance | N/A | Yes | N/A |
DHCP Option 60 | Yes | Yes | Yes |
DFS/802.11h | Yes | Yes | Yes |
AP Group VLANs | Yes | N/A | N/A |
(1) Provided if the Master AP is already upgraded and Slave APs are updated with their Master AP. |
Mobility / Roaming Scenarios
WLAN Configuration | Local Switching | Central Switching | ||||
CCKM | PMK (OKC) | Others | CCKM | PMK (OKC) | Others | |
Mobility Between Same Flex Group | Fast Roam(1) | Fast Roam(1) | Full Auth(1) | Fast Roam | Fast Roam | Full Auth |
Mobility Between Different Flex Group | Full Auth(1) | Fast Roam(1) | Full Auth(1) | Full Auth | Fast Roam | Full Auth |
Inter Controller Mobility | N/A | N/A | N/A | Full Auth | Fast Roam | Full Auth |
(1) Provided WLAN is mapped to the same VLAN (same subnet). |
Open a Support Case (Requires a Cisco Service Contract.)
Related Cisco Support Community Discussions
The Cisco Support Community is a forum for you to ask and answer questions, share suggestions, and collaborate with your peers.
Refer to Cisco Technical Tips Conventions for information on conventions used in this document.