CCIE or Null!

My journey to CCIE!

Cisco WLC redundancy with mobility groups.

with 4 comments

While LWAPs and Wireless Controllers can streamline and standardize WLAN deployments, it also tends to provide a not so nifty single point of failure. If you only have one WLC in your network and you lose all connectivity to that WLC, whether it be a mis-configuration or a general failure all your LWAP’s will go down until they can join the controller again (or find another controller to join).

The configuration for this is actually fairly simple (especially if you only have 2 WLC’s). First off you want to issue the sh mobility summary to go over the current mobility settings, all these settings are important but probably the most important one is the Default Mobility Domain this is the current name of the mobility group and both controllers will need to be in the same mobility group. (Important: Mobility group names are case-sensitive). If you wish you can change the mobility domain name by issuing the follow command config mobility group name group_name command.

Now once you’ve decided on a mobility group name and both controllers are in the same mobility group, you need to add each respective controller’s MAC address and IP Address as a member of the mobility group on all participating controllers. This done with the following command config mobility group member add mac_address ip_address. Mobility group members can be removed by changing the add keyword with the word delete. Now, each model of Cisco WLC’s can support a max number of 24 mobility group members. So their is a limit, albeit a fairly large limit but it does exist.

Also keep in mind, all this can be done via the GUI interface under Controller -> Mobility Management and of course in the GUI everything is pretty self-explanatory in labelled fields for you to configure easier. (Just more time-consuming)

Once this is all said and done you want to issue the sh mobility summary again to verify the configuration and verify the status of each mobility group member is up.

A few facts to keep in the back of your mind are mobility group messages communicate over UDP port 16666, you will want to create rules or an ACL allowing that kind of traffic between the controllers (If you have any type of firewalls between them). You can issue the following commands to very connectivity ping, eping, mping. Obviously the ping command is just there to verify layer 1 connectivity, eping will verify the EoIP tunnel between the controller has formed. The EoIP (Ethernet of IP) tunnel is where all these mobility messages are exchanged through, and mping will test communication over UDP 16666. resources

WLC Configuration Guide Release 7.0, Chapter 14 Configuring Mobility Groups

WLC Mobility Groups FAQ


Note: I would have loved to include my own screen shots, but I do not have 2 WLC’s out of production to work with.

Written by Stephen J. Occhiogrosso

February 16, 2011 at 5:16 PM

4 Responses

Subscribe to comments with RSS.

  1. Do you know if it is possible to have some LAP’s in a mobility group and leave some statically assigned to a particular WLC?


    August 10, 2011 at 8:06 PM

  2. If you have multiple WLC’s in the same mobility group, you can manually set the primary, secondary, and tertiary controllers on the individual LWAP with the LWAP settings itself.


    August 11, 2011 at 5:54 AM

  3. Does the mobility group copies the local guest users between the two WLC? If it doesn’t, is there a way to replicate local guest user without using WCS? Many thanks.


    November 26, 2012 at 4:55 AM

  4. Hello.
    I have a doubt of this. We have two WLCs ( Primary & Secondary) in same mobility group and the APs of locations are spread between both WLCs.
    (eg: I have 10 APs in my office. 5 APs are in WLC1 & other 5 APs are in WLC2)

    In that case, does the WLCs talk to each other when deciding the best channel for APs? In one location ! have 3 APs and all 3 APs are in channel 11. (no issue for users). But since 3 APs are in two WLCs, my management need me to confirm that the AP “separation” among WLC is still ensuring that the “best channel algorithm” is working fine.

    Please advice me on this.


    May 1, 2014 at 11:01 PM

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

This site uses Akismet to reduce spam. Learn how your comment data is processed.

%d bloggers like this: