WLC understands that WGB is client but still identifies as WGB
WGBs are clients to the WLAN
The WLAN requires Aironet IE enabled for a WGB to associate
WGBs can support most types of WLAN layer 2 security
MAC filtering only impacts the WGB and not the wired clients
wired clients inherit the policy assigned to their WGB
• Idle timeout is not supported for both WGB and wired clients.
• Session timeout is not applicable for wired clients.
• Web authentication is not supported.
• WGB supports only up to 20 clients.
• If you want to use a chain of certificates, copy all the CA certificates to a file and install it under a trust
point on the WGB, else server certificate validation may fail.
• Wired clients connected to the WGB are not authenticated forsecurity. Instead, the WGB is authenticated
against the access point to which it associates. Therefore, we recommend that you physically secure the
wired side of the WGB.
• Wired clients connected to a WGB inherit the WGB's QoS and AAA override attributes.
• To enable the WGB to communicate with the root AP, create a WLAN and make sure that Aironet IE
is enabled under the Advanced settings.
IP Addressing
Addressing is done on the BVI1 interface (similar to an SVI)
you could run into static or dynamic addressing request
same basic config as a switch in this regard
we can dynamically or statically set the default gateway/route
one exception to this all is with ipv6 dynamic addressing/gateway
it works fine over the wired port
it seems to disregardsRAs on its radio interface when joined as WGB
oddly enough, it passes RAs through to its wired clients just fine
WGB can associate to any Local or mesh mode AP
WGBs can associate to Flexconnect APs on 3700 series lightweight APs
Basic process for WGB PSK association Config
Configure the SSID Globally
Define the SSID name
identifies the L2 Security type (open, PSK, 802.1x)
Calls out WPA version whe needed
Defines the WPA PSK when needed
Assign to a VLAN when enabled
References EAP profile and 802.1x Credentials
Configure the Radio
Pick which radio will be used for the WGB association
Define the encryption used for the SSID if applicable
Call out the SSID
Set the radio to a role of workgroup-bridge
Enable the radio (shut down by default)
Configure terminal
AP(config)# dot11 ssid [NAME]
AP(config)# authentication open
AP(config)# authentication key-management wpa version 2
AP(config)# wpa-psk ascii [PASSWORD]
AP(config)# interface d1 (dot11radio1 for 5ghz)
AP(config-if)# encryption mode ciphers aes-ccm
AP(config-if)# ssid [NAME]
AP(config-if)# no shutdown
AP(config-if)#exit
Verify:
AP# show dot11 associations
AP# show dot11 associations all
AP# show dot11 bssid (show currently active SSIDs)
WGBs don’t roam by default
Use the mobile station commands to enable roaming behavior
Scan - pick a subset of channels to scan through
Period - frequency of scanning with optional RSSI threshold value
Minimum-rate - minimum data rate before WGB disassociates from AP
Ignore neighbor-list - ignores CCX reports from other APs to form a limited channel scan list
Typically only used when the “scan” option is configured
Improve roaming
Configure terminal
AP(config)# interface d1 (dot11radio1 for 5ghz)
AP(config-if)#mobile station scan ? (Pick channels you need to scan) 36 40 44 48 149 153 157 161 165
AP(config-if)#mobile station scan 36 40 44 48 149 153 157 161 165
AP(config-if)#mobile station period 20 threshold 70
AP(config-if)#mobile station minimum-rate 24.0
AP(config-if)#mobile station ignore neighbor-list
WGB Timeouts
assoc-response - Association Response time-out value
auth-response - Authentication Response time-out value
channel-scan - Channel-scan time-out value
client-add - Client-add time-out value
eap-timeout - EAP Timeout value
iapp-refresh - IAPP Refresh time-out value
Configure terminal
AP(config)#workgroup-bridge timeouts ?
AP(config)#workgroup-bridge timeouts assoc-response 800
AP(config)#workgroup-bridge timeouts channel-scan slow
AP(config)#workgroup-bridge timeouts client-add 800
AP(config)#workgroup-bridge timeouts eap-timeout 2
AP(config)#workgroup-bridge timeouts iapp-refresh 800
Other Configs
Preferred parent
Can pick up to 4 (high priority) parent MAC addresses
Timeout value controls the timer and possibility of associating elsewhere
Packet retries
How many times to attempt sending best effort packets before giving up
Optional "drop-packet" config to prevent disassociation when this happens
Verify:
AP# show dot11 associations
Configure terminal
AP(config)#interface d1
AP(config-if)#parent 1 [MAC Address]
AP(config-if)#parent timeout 10 (WGB will wait 10 seconds until join a new AP)