Hi-
Our environment consists of (2) master tier controllers, (2) local controllers, and (2) guest (DMZ) controllers which serve as anchor points for GRE. The (2) local controllers each have L2 GREs out to each guest controller. The Guest Vlan resides on each local controller, however it is not trunked between them. Clients hit the Guest ssid and are redirected through the GRE.
The problem:
The issue is with Guests (who connect via a simple Captive Portal page) are complaining of having to reauthenticate very often. I've set the user-idle timeout setting to 10 min. While investigating this, I realized that they were often switching between the (2) local controllers. I've enabled Vlan mobility, however, we still appear to have the problem. Does the guest Vlan have to be trunked between both locals for this to work? Both locals are trunking our internal Vlans via our Cisco infrastructure; The Guest Vlan is not for obvious reasons. If this is required, could I simply connect the (2) locals via directly connected interfaces? Are there any commands I can run to validate Vlan Mobility?
Thanks in advance for your help.
-Luis