How to point AP to specific WLC when have multiple

Hello EE,

We have a few sites with APs and a corporate controller.  We have one other site with a controller as well given the number of APs at that location.

My question in putting APs in at other sites, how do you determine if they will come to the corporate controller or this secondary site?
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

They will need to join with one WLC (depending on what type of configuration you have setup), so when you place new APs, they will generally communicate with one or the other WLC. The WLC will need to provision the AP and issue a certificate and that AP will communicate strictly to that WLC.
operationsITAuthor Commented:
Thank you, I understand that they need to be joined, but I had the scenario where I was looking in one controller and didn't see the APs trying to connect then checked the AP log and saw it was going to the other.  I am curious what determines that and how I would get it to go to the other?
Are these WLCs configured with HA?
What were the top attacks of Q1 2018?

The Threat Lab team analyzes data from WatchGuard’s Firebox Feed, internal and partner threat intelligence, and a research honeynet, to provide insightful analysis about the top threats on the Internet. Check out our Q1 2018 report for smart, practical security advice today!

Only at the AP level on the HA tab
Craig BeckCommented:
You usually determine which WLC an AP will join in one of 3 ways...

1] DHCP Option 43
2] DNS
3] Configure the Master Controller option on one WLC in the mobility group.

If you drop all the APs onto the same VLAN as the WLC's management interface you don't need to do [1] or [2] - the APs will send a L2 broadcast for a WLC if [1] and [2] fail so the WLC will respond.  Setting the Master Controller option on one WLC (if you have more than one in the same mobility group) will force APs to join that WLC if they haven't previously joined a WLC.

If you have a dedicated AP VLAN and separate the APs from the WLC via Layer3 you need to do [1] or [2].  The DHCP method is generally preferred as you can specify one or more WLC IP addresses and guarantee which one will be contacted first (as per the order you enter the IP addresses in the option).

So, if you go with a single VLAN for your WLC and APs you just tick the Master Controller box in the Controller -> Advanced section.  If you have separate VLANs for APs and the WLC, go with DHCP and configure option 43 to point the APs to the WLC you want them to join.

You don't necessarily need to issue certs to APs.  Most Cisco APs come with a MIC certificate (manufacturer installed) so the WLC will trust those certs.  If you start messing with recovery images, etc, you may need to add certs, or if you specifically want to authenticate APs at the switchport via 802.1x.  In your case though you'll not need any of that by the sound of it.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
operationsITAuthor Commented:
great Craigbeck I will check
operationsITAuthor Commented:
Great thanks!
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Wireless Hardware

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.