Catalyst 9800 WLC: WLAN, Policy Profile and Policy Tag - 夜莺博客

Catalyst 9800 WLC: WLAN, Policy Profile and Policy Tag

The Catalyst 9800 does not use the flat "WLAN + interface" model that older AireOS controllers used. Instead every SSID is assembled from three independent objects: a WLAN profile (the SSID, security and radio policy), a policy profile (VLAN, ACL, QoS, timeouts) and a policy tag that binds the WLAN profile to the policy profile. Engineers who migrate from 5508 or 8540 controllers usually build the profiles correctly and then wonder why clients land in the wrong VLAN -- the missing piece is almost always the tag. This guide walks through the whole chain from CLI, then lists the verification commands to prove the mapping is live.

How the Catalyst 9800 configuration model fits together

Three tag types exist: policy tags (WLAN profile to policy profile, up to 16 pairs), site tags (flex profile plus AP join profile) and RF tags (RF profile). A wireless client's VLAN, ACL and QoS behaviour comes from the policy profile, never from the WLAN profile itself. See WPA3-Enterprise 802.1X Wireless RADIUS Configuration for the authentication side of the same SSID.

Step 1 - Create the WLAN profile

Device# configure terminal
Device(config)# wlan corp-wlan 1 corp-wlan
Device(config-wlan)# ssid CORP-WIFI
Device(config-wlan)# security wpa wpa2
Device(config-wlan)# security wpa akm dot1x
Device(config-wlan)# radio policy dot11 5ghz
Device(config-wlan)# no shutdown
Device(config-wlan)# exit

Set the WLAN ID (here 1) explicitly. A WLAN profile alone carries no VLAN or switching policy, so it is safe to create before the policy profile exists.

Step 2 - Create the policy profile

Device(config)# wireless profile policy corp-policy
Device(config-wireless-policy)# vlan 120
Device(config-wireless-policy)# idle-timeout 1800
Device(config-wireless-policy)# no shutdown
Device(config-wireless-policy)# exit

Add ipv4 dhcp required in the policy profile when clients roam between controllers, otherwise a stale client IP can be retained after the move. Layer 3 security, session timeout and AVC profiles all live here as well.

Step 3 - Map both profiles with a policy tag

Device(config)# wireless tag policy corp-tag
Device(config-policy-tag)# wlan corp-wlan policy corp-policy
Device(config-policy-tag)# exit

The tag is what the AP actually consumes. Until the tag exists and is applied to the AP (through a site tag or per-AP configuration), the SSID will broadcast but clients receive no usable policy.

Verification and common faults

  • show wireless wlan summary - confirms the WLAN profile, its ID and enabled state.
  • show wireless profile policy summary - confirms the VLAN and status of each policy profile.
  • show ap tag summary - shows which policy, site and RF tag each AP is using.
  • show wireless client summary then show wireless client mac-address xxxx.xxxx.xxxx detail - shows the negotiated policy profile and VLAN for a live client.

Three failures account for most tickets: the policy tag was created but never applied to the AP; the VLAN in the policy profile does not exist as an SVI on the controller, so central switching silently drops DHCP; or the WLAN was left in shutdown state while testing. If the AP never joins at all, start from Cisco Aironet Won’t Connect to Wireless LAN Controller before touching the WLAN. Once the SSID carries voice or video, apply consistent markings at the AP and uplink - the principles in wireless QoS trust DSCP apply unchanged to wireless.

原文链接:https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-17/config-guide/b_wl_17_17_cg/m_wlan_9800.html