WESM xl Management and Configuration Guide WS.02.XX and greater
9-10
Fast Layer 2 Roaming and Layer 3 Mobility
Overview
In summary, follow these guidelines:
■ The Wireless Edge Services xl Module automatically enables fast Layer 2
roaming between RPs on the same module. (Layer 3 roaming is not a
concern for roaming on a single module.)
■ Except when using Web-Auth, modules automatically handle seamless
(but not necessarily fast) Layer 2 roaming between RPs on different
modules.
■ Fast roaming between modules at Layer 2 requires extra configuration
and is possible in a WLAN that requires WPA/WPA2 with 802.1X. See
“Configuring Fast Layer 2 Roaming for WPA/WPA2 with 802.1X” on
page 9-11.
■ When a WLAN enforces Web-Auth, attempt whenever possible to have all
RPs adopted by the same Wireless Edge Services xl Module. (See “Layer
2 Roaming on a Web-Auth WLAN Between Different Wireless Edge Ser-
vices xl Modules” on page 9-4 for more information on your options.)
■ You must configure a Layer 3 mobility domain for Layer 3 roaming.
Layer 3 roaming is seamless, but not fast. See “Configuring Layer 3 Mobil-
ity” on page 9-14.
In some networks, you must enable Layer 2 roaming between some Wireless
Edge Services xl Modules and Layer 3 roaming between others. Keep these
rules in mind as you plan relationships between Layer 3 mobility domains and
redundancy groups:
■ A Layer 3 mobility domain can include multiple redundancy groups or no
redundancy groups at all.
You can divide a Layer 3 mobility domain into multiple redundancy
groups, or you can place all modules in the domain in the same group.
Although modules in the same redundancy group often map a WLAN to
the same static VLAN, as long as you place the modules in the same Layer 3
mobility domain, this is not a requirement. Roaming behavior is not
typically affected by how you group modules into redundancy groups.
■ Best practices dictate that two Wireless Edge Services xl Modules in the
same redundancy group either be in the same Layer 3 mobility domain or
in no mobility domain at all (for a network that does not require Layer 3
roaming).
WPA/WPA2 with
802.1X
seamless fast • PMK caching
•pre-
authentication
not seamless seamless modules in the
same Layer 3
mobility domain
WLAN Security
Option
Layer 2 Roam
Without Special
Configuration
Best
Layer 2
Roam
Requirements for
Best Layer 2
Roam
Layer 3 Roam
Without Special
Configuration
Best
Layer 3
Roam
Requirements for
Best Layer 3
Roam