Best Practices to Deploy High-Availability in Wireless LAN Architectures

Size: px
Start display at page:

Download "Best Practices to Deploy High-Availability in Wireless LAN Architectures"

Transcription

1

2 Best Practices to Deploy High-Availability in Wireless LAN Architectures Kara Muessig Technical Solutions Architect CCIE (Wireless) #29572

3 Planned downtime Failover Redundancy Survivability Clustering/Pooling Performance High Availability End-to-end access Cost $$$$ Productivity Session Objectives Learn the Design Recommendations, Configuration Best Practices, Deployment tips, to have your wireless network..always on, ALWAYS Present, ALWAYS AVAILABLE 3

4 Special Thanks! This presentation is a culmination of best practices and tips from a wide range of Cisco technologists. 4

5 Agenda For Your Reference Radio Frequency (RF) High Availability (HA) Site Survey, RRM, CleanAir Deterministic (N+1) Failover AP Pre-image Download Centralized (N+N) HA Architecture AP SSO, Client SSO Distributed (Converged Access) HA Architecture FlexConnect and WAN Survivability Management and Mobility Services HA Prime Infrastructure Mobility Services Engine One Policy, One Management, One Network Unified Access Wireless Autonomous FlexConnect Centralized Converged Access U n p a r a l l e l e d D e p l o y m e n t F l e x i b i l i t y 5

6 Radio Frequency High Availability RF HA is the ability to have redundancy in the physical layer. Creating a stable RF environment Dealing with coverage holes if an AP goes down How to mitigate an interference source Creating a pervasive, predictable RF environment 6

7 Guidelines for surveying for RF HA Rule of Thumb Want most radios at power level 3 Site Survey tools: Use Active Survey Examples: AirMagnet, Ekahau, Veriwave WaveDeploy Clients and Controller Get to know the area: Consider three dimensional radio propagation in multi-story buildings Be aware of perimeter and corner areas Survey for lowest common client type and technology supported b/g, a, n Smartphones usually have lower power radio # Antennas 2.4 GHz 5 GHz Antenna Gain (dbi) 2.4 GHz 5 GHz Total Tx Pwr (dbm) 2.4 GHz 5 GHz 2 2 MacBook Pro ipad 3 iphone 4S iphone 5 Samsung S (20) 26 (23) ave-peak ave-peak Cisco and/or its affiliates. n/a All rights reserved n/a ave-peak ave-peak

8 Managing the spectrum: RRM, RF Profiles, CleanAir RRM (Radio Resource Management) Manage Spectrum Efficiency to provide the optimal throughput under changing conditions Provides a system wide RF view of the network To dynamically balance the infrastructure and mitigate changes Monitor and maintain coverage for all clients RF Profiles Allow for selectively tuning RRM functions within groups of AP s sharing a common coverage zone RF Profiles are created for either the 2.4 GHz radio or 5GHz radio Allow administrative control over: o Min/Max TPC values, TPCv1 Threshold, TPCv2 Threshold, Data Rates CleanAir Spectrum intelligence solution designed to proactively manage the challenges of a shared wireless spectrum Who, what, when, where, and how with interference Enables the network to act upon this information 8

9 Client Link: Reduced Coverage Holes ClientLink Disabled ClientLink Enabled Lower Data Rates Source: Miercom; AirMagnet/Fluke Iperf Survey Higher Data Rates 9

10 Deterministic / N+1 Failover

11 Controllers and physical connection All controllers including 5760, 5508, 2504, 8510, 7500 WiSM2 and older models can participate in deterministic failover Utilizing VSS pairs allows the 5508 controllers to have link redundancy WLC 5760 introduces multiple LAG groups that allow for link redundancy if you don t have VSS pairs FlexLink (preferred method) with active / standby Load balancing per VLAN between links Cisco 5508 Catalyst VSS Pair This the primary link Switch communicates with 5760 on this link 1 port or 2 port LAG 5760 Layer 2 Adjacent only This the standby link 1 port or 2 port LAG 5760 link is on standby, no communication here Infrastructure sees 5760 here 11

12 **Ethernet in IP Tunnel Mobility Group For Your Reference Mobility Group allows controllers to peer with each other to support Seamless and Fast roaming across controller boundaries (CCKM / r key domain) Support for up to 24 controllers, 24,000 APs per mobility group Seamless Roaming (not Fast) is supported across mobility groups with in the mobility group domain up to 72 controllers With Inter Release Controller Mobility (IRCM) roaming is supported between , and 7.0, 7.2, 7.3, 7.4 codes **With and 7.5 codes new mobility changes the tunnel type with in the controller to CAPWAP tunnels instead of EoIP tunnels Controller-A MAC: AA:AA:AA:AA:AA:01 Mobility Group Name: MyMobilityGroup Mobility Group Neighbors: Controller-B, AA:AA:AA:AA:AA:02 Controller-C, AA:AA:AA:AA:AA:03 Controller-B MAC: AA:AA:AA:AA:AA:02 Mobility Group Name: MyMobilityGroup Mobility Group Neighbors: Controller-A, AA:AA:AA:AA:AA:01 Controller-C, AA:AA:AA:AA:AA:03 Controller-C MAC: AA:AA:AA:AA:AA:03 Mobility Group Name: MyMobilityGroup Mobility Group Neighbors: Controller-A, AA:AA:AA:AA:AA:01 Controller-B, AA:AA:AA:AA:AA:02 12

13 Controller Redundancy - Deterministic mode WLAN-Controller-A WLAN-Controller-B WLAN-Controller-C Primary: WLAN-Controller-A Secondary: WLAN-Controller-B Tertiary: WLAN-Controller-C Primary: WLAN-Controller-B Secondary: WLAN-Controller-C Tertiary: WLAN-Controller-A Primary: WLAN-Controller-C Secondary: WLAN-Controller-A Tertiary: WLAN-Controller-B Administrator statically assigns APs a primary, secondary, and/or tertiary controller Assigned from controller interface (per AP) or Prime Infrastructure (template-based) You need to specify Name and IP if WLCs are not in the same Mobility Group AP uses heartbeats to validate current WLC connectivity When AP looses 5 heartbeats it starts join process to first backup WLC candidate Candidate Backup WLC is the first alive WLC in this order : primary, secondary, tertiary, global primary, global secondary. Failover is faster than Dynamic mode because AP goes back to discovery state just to make sure the backup WLC is UP and then immediately starts the JOIN process 14

14 Deterministic: Backup Controllers Backup controllers configured for all APs under Wireless > High Availability tab Used if there are no primary/secondary/tertiary WLCs configured on the AP The backup controllers are added to the primary discovery request message recipient list of the AP. 15

15 AP Failover Priority Assign priorities to APs: Critical, High, Medium, Low Critical priority APs get precedence over all other APs when joining a controller In a failover situation, a higher priority AP will be allowed in ahead of all other APs AP Priority: Critical Critical AP fails over AP Priority: Medium Medium priority AP dropped Controller If controller is full, existing lower priority APs will be dropped to accommodate higher priority APs 16

16 Reducing Failover Time: Fast Heartbeat, Primary Discovery Request Fast Heartbeat When the fast heartbeat timer expires, the AP sends 3 fast echo requests to the WLC for 3 times (instead of 1 sec heartbeats) If no response, primary is considered dead and the AP selects an available controller from its backup controller list in the order of primary, secondary, tertiary, primary backup controller, and secondary backup controller. Fast Heartbeat only supported for Local and Flex mode AP Primary Discovery Request Timer The access point maintains a list of backup controllers and periodically sends primary discovery requests to each entry on the list. Configure a primary discovery request timer to specify the amount of time that a controller has to respond to the discovery request If controller doesn t respond in allocated amount of time then AP moves it off the list of available backup controllers. 17

17 Deterministic: N+1 Design Redundant WLC can be in a geographically separate location Redundant WLC need not be part of the same mobility group Configure high availability parameters to detect failure and faster failover Use AP priority in case of over subscription of redundant WLC HA SKU available in 7.4: No need to purchase licenses on backup WLC When backup takes over 90-days counter is started NOC or Data Center WLC-BKP WLAN-Controller-1 WLAN-Controller-2 WLAN-Controller-n Needs to be configured normally as you would do with the secondary controller (no auto sync). This is NOT AP SSO Nothing different than normal N+1 operations. APs Configured With: Primary: WLAN- Controller-1 Secondary: WLC-BKP APs Configured With: Primary: WLAN- Controller-2 Secondary: WçC-BKP APs Configured With: Primary: WLAN- Controller-n Secondary: WLC-BKP 18

18 AP Pre-image Download

19 AP Joins without Download AP Pre-image Download CAPWAP-L3 AP Pre-download image AP Pre-image download allows AP to download code while it is operational CAPWAP APs can download and keep more than one image of 4-5MB each Pre-image download operation 1. Upgrade the image on the controller 2. Don t reboot the controller 3. Issue AP Pre-image download command 4. Once all AP images are downloaded 5. Reboot the controller 6. AP reloads and joins the controller without downtime of downloading the image Cisco WLAN Controller Access Points 20

20 Configure AP pre-download image For Your Reference Perform primary image predownload on the AP Wireless > AP > Global Configuration AP now starts pre-downloading AP now swaps image after reboot of the controller 21

21 Summary HA before 7.3 and SSO Primary/Secondary/Tertiary WLC need to be defined on each AP Each WLC configured separately and have their own unique IP Address Primary and Secondary Backup are configured Globally Fast Heartbeat can be used to speed up failover With Failover detection AP goes in Discovery State and CAPWAP State Machine is restarted Downtime between Failover may go up to 1.5 minutes depending upon number of APs Each WLC is managed and monitored separately by NCS/Prime Infrastructure 22

22 Centralized (N+N) HA Architecture

23 Supported Code and Controllers For every active primary controller there is a standby redundant controller. WLC 5508 Supported Controllers: 5508, WiSM2, 7500, 8510 AP Stateful Switch Over (SSO) 7.3 WLC HA Sku 7.4 (for N+1) Client Stateful Switch Over (SSO) 7.5 WLC Flex 7500 WiSM 2 WLC

24 AP Stateful Switch Over (AP SSO)

25 High Availability AP SSO Model is 1:1 (Active : Hot-Standby) Supported on 5500 / 7500 / 8500 and WiSM-2 Same hardware and software version Two new interfaces Redundancy Port Redundancy Management Interface Same management IP on Active and Standby Static & dynamic system configurations synced to standby. AP information synced to the standby. Synced when AP Joins or it s configuration changes. AP CAPWAP re-join is avoided on switchover. Detection time : msec for box failover, 3-4 seconds for management gateway failover Back-to-back Connectivity on the Redundancy Port between the two WLCs Clients are de-authenticated on failover; forced to re-associate Effective service downtime = Detection time + Switch Over Time (Network recovery/convergence) + Client re-association time 26

26 AP SSO - States Active WLC AP Keep-Alive Redundancy Information failure/notify Role and Negotiation Config Peer Sync Redundancy Link Established (Over dedicated Redundancy Port) Standby WLC Client Associate AP Join Switch AP session intact. Does not re-establish capwap Effective downtime for client is Detection time + Switchover time + Client Association time Client reassociates 27

27 AP SSO Configuration (Only valid for 7.3 / 7.4)

28 AP SSO Gui Config For Your Reference By default HA is disabled. Configure Redundant Management and Peer Redundant Management IP first before enabling AP SSO 31

29 AP SSO GUI Config cont. For Your Reference Configure AP SSO selecting Enable from drop down: Optional configuration To Reset Peer WLC click on Commands -> Redundancy -> Reset Peer 32

30 AP SSO Show commands For Your Reference To check the Redundancy Status and Switchover History show redundancy status Total 10 history counts are maintained for switchover. 33

31 AP SSO Important things to Note Once SSO is enabled, Standby WLC cannot be accessed via the GUI on service port. It can be accessed via console connection, SSH/Telnet on service port, and SSH on the redundant management interface Physical connection between Redundant Port and Infrastructure Network should be done first before HA configuration Webauth certificates have to be installed on BOTH controllers prior to setting up HA OEAP600 not supported Clear configuration on Active WLC will also initiate clear config on Standby WLC. Internal DHCP is not supported when HA configuration is enabled. L2 MGID is synched but L3 MGID database is cleared with SSO Location and Rogue information is not synched. When HA is disabled on Active it will be pushed to Standby and after reboot all the ports will come up on Active and will be disabled on Standby. 34

32 AP SSO - Licensing For Your Reference HA Pair with HA SKU HA SKU is a new SKU with Zero AP Count License The device with HA SKU becomes standby first time it pairs up AP-count license info will be pushed from Active to Standby In the event of Active failure HA SKU will let APs join with AP-count obtained and will start 90-day count-down. After 90-days, it starts nagging messages.won t disconnect connected APs HA Pair with both the WLC having Valid AP Count License Active / Standby WLC decided based on configuration. AP-count license info will be pushed from Active to Standby In the event of Active Failure, the new Active will operate with the license count of the previous Active and will start 90-day count-down. Starting in AirOS 7.4. Valid for all controller types. 35

33 Client Stateful Switch Over (Client SSO)

34 Client SSO - Overview Client s information is synced to the Standby Client information is synced when client moves to RUN state. Client re-association is avoided on switch over Fully authenticated clients(run state) are synced to the peer. The intermediate client state events are not synced Transient clients are dis-associated after switch over. Effective service downtime = Detection time + Switch Over Time (Network recovery/convergence) 37

35 Client SSO - States Keep-Alive Redundancy AP and failure/notify Role Client Negotiation info Peer Sync Active WLC Client Associate Redundancy Link Established (Over dedicated Redundancy Port) Standby WLC AP Join Switch AP session intact. Does not re-establish capwap Effective downtime for client is Detection time + Switchover time Client session intact. Does not re-associate 38

36 Client SSO Configuration & Topology

37 Client SSO GUI config For Your Reference 40

38 CLI Configuration Commands For Your Reference configure interface address management <ip-address> <subnet-mask> <gateway> configure interface address redundancy-management <ip-address> peerredundancy-management <ip-address> configure redundancy unit [primary secondary] configure redundancy mode [sso disable] configure redundancy timer keep-alive-timer <interval> (default 100 milli-sec) configure redundancy timer peer-search-timer <timeout> (default 120 sec) 41

39 Troubleshooting commands For Your Reference Show redundancy summary shows state and role of each controller Show AP uptime Show AP summary Show client summary Show client detail shows connected time of client Show pmk-cache all FSR for each client present on active/standby controllers 42

40 Supported (N+N) HA Topologies - AirOS Two 5508, 7500* or 8500* connected via back-to-back RP port in the same data center 2. Two 5508, 7500* or 8500* connected via RP port over L2 VLAN/fiber in the same or different data center** 3. Two 5508, 7500* or 8500* connected to a VSS pair 1. Two WiSM-2 on the same chassis 2. Two WiSM-2 on different chassis with redundancy VLAN extended over L2 network** 3. Two WiSM-2 on different chassis in VSS mode * WLC types supported in 7.5 code ** Support for topology started in

41 WLC 5508/7500/8500 Back-to-back RP Connectivity Configuration on Primary WLC: configure interface address management configure interface address redundancy-management peer-redundancy-management configure redundancy unit primary configure redundancy mode sso Configuration on Hot Standby WLC: configure interface address management configure interface address redundancy-management peer-redundancy-management configure redundancy unit secondary configure redundancy mode sso Management GW is monitored with 12 pings ( ~15 sec) 44

42 WLC 5508/7500/8500 RP Connectivity via Switches Configuration on Primary WLC: configure interface address management configure interface address redundancy-management peer-redundancy-management configure redundancy unit primary configure redundancy mode sso Configuration on Hot Standby WLC: configure interface address management configure interface address redundancy-management peer-redundancy-management configure redundancy unit secondary configure redundancy mode sso. RTT Latency : 80 ms or less default ; Bandwidth: 60 Mbps or more ; MTU:

43 WiSM-2 connectivity over L2 Redundancy VLAN Configuration on Cat6k wism service-vlan 192 ( service port VLAN ) wism redundancy-vlan 169 ( redundancy port VLAN ) wism module 6 controller 1 allowed-vlan (data VLAN ). RTT Latency : 80 ms or less default ; Bandwidth: 60 Mbps or more ; MTU:

44 WLC Connected to VSS Pair VSS with 5508 and split LAG VSS with 5508 and non-split LAG WiSM2 with VSS Cisco Catalyst VSS Pair Catalyst VSS Pair L3 Core L2/L3 Distribution Cisco 5508 Standby Cisco 5508 Cisco 5508 Standby Cisco 5508 Access 47

45 Hybrid - SSO with Deterministic HA SSO can be deployed with Secondary and Tertiary Controllers Both Active and Standby combined in SSO setup are configured as primary. On failure of both Active and Standby WLC in SSO setup, APs will fall back to secondary and further to configured tertiary controller. 48

46 Client SSO Important points ONLY Clients in RUN state are maintained during failover Transient list is deleted Clients in transitions like roaming, dot1x key regeneration, webauth logout, etc. are disassociated Posture and NAC OOB are not supported, since client is not in RUN state Some clients, and some information about clients are not sync between Active and Standby CCX Based apps - need to be re-started post Switch-over Client Statistics are not synced PMIPv6, NBAR, SIP static CAC tree are not synced, need to be re-learned after SSO WGB and clients associated to it are not synced OEAP(600) clients are not synced Passive clients are not synced After failover previous Active controller will reboot (if it didn t crash) and try to find redundancy pair ISSU is not supported New mobility is NOT supported 49

47 SSO Behavior and Recommendations RTT latency on Redundancy Link : 80 milliseconds or less. 80% of keepalive timer. Preferred MTU on Redundancy Link : 1500 or above. Bandwidth on Redundancy Link : 60 Mbps or more / 7500 / 8500 : RP Connectivity between Active and Standby Via Switches ( 7.5 ) Back-to-back ( 7.3, 7.4, 7.5 ) WiSM-2 : single 6500 chassis OR different chassis using VSS setup/extending redundancy VLAN. Recommended to have Redundancy Link and RMI Connectivity between WLCs on different switches or on different L2 networks Keepalive/Peer Discovery timers should be left with default timer values for better performance Default box failover detection time is 3 *100 = = 360 +jitter (12 msec)= ~400 msec 50

48 Distributed (Converged Access) HA Architecture

49 Distributed Architecture- Converged Access Today wireless data plane is centralized, wireless traffic overlaid on top wired GLBP A distributed wireless and wired data plane brings: Scalability, End to end traffic visibility, Common policy, Rich media optimization SSO VSS WIRELESS WIRED ISSU First Hop Redundancy Etherchanneled uplinks High Availability all traditional wired HA now a part of wireless HA Stackwise HSRP Redundant Supervisors VRRP StackPower NSF 52

50 Converged Access Deployment Overview Mobility Domain MO ISE PI Mobility Group MC MC Sub-Domain #1 Sub-Domain #2 SPG SPG MA MA MA MA MA MA 53

51 High Availability on the 3850 HA on the 3850 HA is available on a per stack basis (up to 4 members at FCS), not between stacks Stack MC or utilized AirOS MC s to prevent single point of failure There is no HA setup for master-active and master-standby. They are elected automatically by the stack. However, user can set priority level to the members and this is used in the active/standby election. Currently, this can be done from CLI. SSO is not available on 5760, but you can configure deterministic failover with HA sku. 54

52 Catalyst 3850 HA Shift from 3750X Catalyst 3750-X StackWise-Plus - Hybrid control-plane processing - N:1 stateless control-plane redundancy - Distributed L2/L3 Forwarding Redundancy - Stateless L3 protocol Redundancy Catalyst 3850 StackWise Centralized control-plane processing Stateful redundancy (SSO) - Distributed L2/L3 Forwarding Redundancy - IOS HA Framework alignment for L3 protocol 55

53 Catalyst 3850 Fault Tolerance in Stack A A S MA/MC Active MC goes down in stack Standby MC must now become Active Guest Anchor MC MA ISE Active MC goes down in stack No impact to non-roamed clients on other MA switches Local clients on the stack need to re-authenticate and re-dhcp Roamed clients need to re-auth and re-dhcp PI Mobility Group SPG MC MA MA MA SPG MC MA MA MA PoP (Local Client re-auths, re-dhcps) (Roamed Client re-auths, re-dhcps, (No impact to existing becomes local) clients on MAs) clients on MAs) (No impact to existing 56

54 Catalyst 3850 Fault Tolerance across Stacks If the whole Catalyst 3850-based stack, operating as an MC, completely goes down Roaming within a Switch Peer Group still works seamlessly Roaming between Switch Peer Groups does not work (re-dhcp) PMKs (via PKC) will not be distributed if the MC is down so no Fast Roaming for new clients until the MC is restored When the MC is down, RRM, Guest Access, (guest tunneling) and other MC-based functions do not operate within the affected Switch Peer Group other Switch Peer Groups are unaffected. Mobility Group SPG MC MA Stack Blowe totally d up down real good MA No PMK, no Fast roam) MA (Client roams Seamlessly) SPG Guest Anchor MC MC MA MA MA PoP MA ISE (Client re-auths, re-dhcps, becomes local) 57 PI

55 MC Failure Sub-Domain and Anchor Connections Roamed and Local users, High Availability Considerations Tunnel to Guest Anchor MC MC Totally Down Now, the MC fails let s examine the effects When the MC for a given SubDomain goes down, all of the tunnels serviced by that MC go down this includes all MA-MC tunnels (purple tunnels as shown on this diagram), as well as any MC-Guest Anchor tunnel (if present grey tunnel as shown on this diagram) SPG SPG MA Non-roamed user (No impact to existing clients on MAs) MA MA MA MA (Roamed Client re-auths, re-dhcps, becomes local) 2013 Cisco and/or its affiliates. All rights reserved. Roamed user MA Note that all of the tunnel connections between switches within the SPGs themselves stay up as these are pre-formed at SPG creation, and once up, do not depend on the MC to stay up 58

56 Hybrid - MC Redundancy with AireOS SSO Active MC goes down in 1:1 HA Standby HA MC 5508, WiSM-2, 8510 becomes Active Active MC MC Down HA MC Roamed and Local users, High Availability Considerations Tunnel to Guest Anchor Local users on their MAs have no impact following a HA MC failover event Former Standby MC Now Active Intra-SPG roamed users also have no impact following the MC HA failover APs stay up and running SPG SPG MA MA MA MA MA MA All previously-roamed clients (inter-spg) will result in a hard roam after MC failover (re-auth, re-dhcp, change of client IP address, known as becoming local ) Any new intra-spg or inter-spg roaming happening after MC HA failover from local MA clients will be handled normally (No impact (Inter-SPG to existing roamed Client intra-spg Non-roamed user: Roamed user (between SPGs): re-auths, (No impact to existing roamed re-dhcps, local clients on MAs) clients on becomes local) 2013 Cisco and/or its affiliates. All rights reserved. MAs) 59

57 FlexConnect and WAN Survivability

58 FlexConnect overview Management and data plane are split Data Plane can be: Centralized (split MAC architecture) Local (local MAC architecture) Centralized Traffic Central Site Cluster of WLC Centralized Traffic Two modes of operation: Connected (when WLC is reachable) Standalone (when WLC is not reachable) Traffic Switching is configured per AP and per WLAN (SSID) From 7.3 split tunneling is supported on a WLAN basis FlexConnect Group: Defines the Key caching domain for Fast Roaming, allows backup Radius scenarios WAN Local Traffic Remote Office 61

59 FlexConnect Survivability WAN Failure (or single central WLC failure) HA considerations: No impact for connected clients on locally switched SSIDs Disconnection for centrally switched SSIDs clients Static authentication keys are locally stored in FlexConnect AP New clients can join if authentication is based on static keys Fast roaming allowed within FlexConnect group for already connected clients Lost features RRM, CleanAir, WIDS, Location, other AP modes Web authentication, NAC Remote Site Central Site WAN Application Server 62

60 FlexConnect Group: Local Backup RADIUS Backup Scenario Normal authentication is done centrally On WAN failure, AP authenticates new clients with locally defined RADIUS server Existing connected clients stay connected Clients can roam with CCKM fast roaming, or Reauthentication Central RADIUS Local Backup RADIUS Remote Site Central Site WAN FlexConnect Group 1 CCKM Fast Roaming 63

61 Local Authentication By default FlexConnect AP authenticates clients through central controller Local Authentication allow use of local RADIUS server directly from the FlexConnect AP Central RADIUS Central Site WAN Local RADIUS Remote Site FlexConnect Group 1 New in

62 FlexConnect Group: Local Backup Authentication Backup Scenario Normal authentication is done centrally On WAN failure, AP authenticates new clients with its local database Each FlexConnect AP has a copy of the local user DB Existing authenticated clients stay connected Clients can roam with: CCKM fast roaming, or Local re-authentication Supported Security Types Release Version LEAP 6.0 EAP-FAST 6.0 PEAP 7.5 EAP-TLS 7.5 Central RADIUS Remote Site CCKM Fast Roaming Central Site WAN FlexConnect Group 1 65

63 FlexConnect Survivability WLC failure with Deterministic N+1 HA considerations: No impact for locally switched SSIDs Disconnection of centrally switched SSIDs clients Secondary Central Site Primary FlexConnect AP transitions to Standalone and then to Connected when joins the Secondary WAN When in Standalone mode, Fast roaming is allowed within the FlexConnect Group Upon resync with Secondary, client sessions for local traffic are not impacted (provided that the configuration on the WLCs are identical) Remote Office Application Server 66

64 FlexConnect WLC failure scenario with SSO HA considerations: No impact for locally switched SSIDs Disconnection of centrally switched SSIDs clients Standby Central Site Active FlexConnect AP will NOT transition to Standalone because SSO kicks in AP will go straight to Connected mode with the Standby WLC With client SSO local and centralized traffic is not impacted. Remote Office WAN Application Server 67

65 Management and Mobility Services HA

66 Prime Infrastructure (CPI) High Availability CPI runs in an active / standby (1:1) mode Secondary PI not accessible Requires same HW and SW - Physical-physical and virtual-virtual supported Can be geographically separated, however need a reliable, high speed, unimpeded network in-between No database loss when failover occurs Failover can be Automatic or Manual. Failback is always manual If the standby PI doesn t receive 3 heartbeats (timeout 2 seconds) then either the standby PI will become active or will be sent to network admin. Active Standby 69

67 PI HA - Config For Your Reference The first step is to install and configure the Secondary PI. When configuring the Primary PI for HA, the Secondary PI needs to be installed and reachable by the Primary PI The following parameters must be configured on the primary PI: name/ip address of secondary PI address of network administrator for system notification manual or automatic failover option Secondary PI must always be a new installation and this option must be selected during PI install process, i.e. standalone or primary PI cannot be converted to secondary PI. Standalone PI can be converted to HA Primary. 70

68 PI HA Config Verification For Your Reference Verify that the configuration is complete on the HA Status tab. After initial deployment of PI, the entire configuration of primary PI is replicated to the host of the secondary PI This process can be time consuming and take up to a half hour to run After database is replicated on the delta of changes will be pushed over to the secondary PI 71

69 Mobility Service Engine HA

70 Mobility Service Engine (MSE) - HA Every active primary MSE is backed up by another inactive instance. The secondary MSE becomes active only after the failover procedure is initiated. The failover procedure can be manual or automatic. A heartbeat is maintained between the primary and secondary MSE When the primary MSE fails and the secondary takes over, the virtual address of the primary MSE is switched transparently. No HA license or a second set of client/ WIPS license required HA for all services supported; Failover times < 1 min HA supports Network Connected and Direct Connected. Directly connected with a cable can help reduce latencies in heartbeat response times, data replication and failure detection times. Supports automatic & manual failover / failback Physical to physical & virtual to virtual HA supported WLC1 Primary MSE Virtual IP: Eth0: WLC2 Directly or network connected Secondary MSE Eth0: PI 3 rd Party 73

71 MSE HA - Config For Your Reference Additional config required under HA HA mode in Start up script Define secondary name & ip address 74

72 MSE HA Verification For Your Reference Status shows active under the HA Configuration Sync is complete 75

73 High Availability - Summary Radio Frequency (RF) High Availability (HA) Site Survey, RRM, CleanAir Cisco Prime Infrastructure Deterministic (N+1) Failover AP Pre-image Download Centralized (N+N) HA Architecture AP SSO, Client SSO Distributed (Converged Access) HA Architecture FlexConnect and WAN Survivability Management and Mobility Services HA Prime Infrastructure Mobility Services Engine MSE Aironet Access Point Campus Network Wireless LAN Controllers 76

74 Related Session and Links BRKEWN Understanding RF Fundamentals and the Radio Design of Wireless Networks Fred Niehaus BRKEWN Branch Office Wireless LAN Design Karan Sheth BRKEWN Converged Access Mobility Design & Architecture (2013 Orlando) - Sujit Ghosh HA Deployment guide 0bd3504.shtml#upgrade WOS HA Demo Aparajita Sood 77

75 Complete Your Online Session Evaluation Give us your feedback and you could win fabulous prizes. Winners announced daily. Receive 20 Cisco Daily Challenge points for each session evaluation you complete. Complete your session evaluation online now through either the mobile app or internet kiosk stations. Maximize your Cisco Live experience with your free Cisco Live 365 account. Download session PDFs, view sessions on-demand and participate in live activities throughout the year. Click the Enter Cisco Live 365 button in your Cisco Live portal to log in. 78

76

Best Practices to Deploy High-Availability in Wireless LAN Architectures

Best Practices to Deploy High-Availability in Wireless LAN Architectures Best Practices to Deploy High-Availability in Wireless LAN Architectures Brian Levin ENG, Technical Marketing Engineer The New Normal High Density How many devices have you got today? High Quality No coverage

More information

Best practices to deploy high-availability in Wireless LAN Architectures

Best practices to deploy high-availability in Wireless LAN Architectures Best practices to deploy high-availability in Wireless LAN Architectures Simone Arena Wireless Networking Group, TME Abstract The proliferation of Wi-Fi enabled devices creates a significant challenge

More information

High Availability (AP SSO) Deployment Guide

High Availability (AP SSO) Deployment Guide High Availability (AP SSO) Deployment Guide Document ID: 113681 Contents Introduction Prerequisites Requirements Components Used Conventions Topology New HA Overview HA Connectivity Using Redundant Port

More information

Architecting Network for Branch Offices with Cisco Unified Wireless

Architecting Network for Branch Offices with Cisco Unified Wireless Architecting Network for Branch Offices with Cisco Unified Wireless Karan Sheth - Sr. Technical Marketing Engineer Objective Design & Deploy Branch Network That Increases Business Resiliency 2 Agenda Learn

More information

Architecting Network for Branch Offices with Cisco Unified Wireless Karan Sheth Sr. Technical Marketing Engineer

Architecting Network for Branch Offices with Cisco Unified Wireless Karan Sheth Sr. Technical Marketing Engineer Architecting Network for Branch Offices with Cisco Unified Wireless Karan Sheth Sr. Technical Marketing Engineer BRKEWN-2016 Abstract This session focuses on the architecture concepts of the branch office

More information

CCIE Wireless v3 Lab Video Series 1 Table of Contents

CCIE Wireless v3 Lab Video Series 1 Table of Contents CCIE Wireless v3 Lab Video Series 1 Table of Contents Section 1: Network Infrastructure Layer 2 Technologies VLANs VTP Layer 2 Interfaces DTP Spanning Tree- Root Election Spanning Tree- Path Control Spanning

More information

CCIE Wireless v3 Workbook Volume 1

CCIE Wireless v3 Workbook Volume 1 CCIE Wireless v3 Workbook Volume 1 Table of Contents Diagrams and Tables 7 Topology Diagram 7 Table 1- VLANs and IP Subnets 8 Table 2- Device Management IPs 9 Table 3- Device Credentials 10 Table 4- Term

More information

Configuring OfficeExtend Access Points

Configuring OfficeExtend Access Points Information About OfficeExtend Access Points, page 1 OEAP 600 Series Access Points, page 2 OEAP in Local Mode, page 3 Supported WLAN Settings for 600 Series OfficeExtend Access Point, page 3 WLAN Security

More information

Deploying Cisco Wireless Enterprise Networks

Deploying Cisco Wireless Enterprise Networks 300-365 Deploying Cisco Wireless Enterprise Networks NWExam.com SUCCESS GUIDE TO CISCO CERTIFICATION Exam Summary Syllabus Questions Table of Contents Introduction to 300-365 Exam on Deploying Cisco Wireless

More information

Configuring Hybrid REAP

Configuring Hybrid REAP 13 CHAPTER This chapter describes hybrid REAP and explains how to configure this feature on controllers and access points. It contains the following sections: Information About Hybrid REAP, page 13-1,

More information

Configure Devices Using Converged Access Deployment Templates for Campus and Branch Networks

Configure Devices Using Converged Access Deployment Templates for Campus and Branch Networks Configure Devices Using Converged Access Deployment Templates for Campus and Branch Networks What Are Converged Access Workflows?, on page 1 Supported Cisco IOS-XE Platforms, on page 3 Prerequisites for

More information

CCIE Wireless v3.1 Workbook Volume 1

CCIE Wireless v3.1 Workbook Volume 1 CCIE Wireless v3.1 Workbook Volume 1 Table of Contents Diagrams and Tables 7 Topology Diagram 7 Table 1- VLANs and IP Subnets 8 Table 2- Device Management IPs 9 Table 3- Device Credentials 10 Table 4-

More information

exam. Number: Passing Score: 800 Time Limit: 120 min CISCO Deploying Cisco Wireless Enterprise Networks. Version 1.

exam. Number: Passing Score: 800 Time Limit: 120 min CISCO Deploying Cisco Wireless Enterprise Networks. Version 1. 300-365.exam Number: 300-365 Passing Score: 800 Time Limit: 120 min CISCO 300-365 Deploying Cisco Wireless Enterprise Networks Version 1.0 Exam A QUESTION 1 The customer has deployed C7960 phones with

More information

Configuring FlexConnect Groups

Configuring FlexConnect Groups Information About FlexConnect Groups, page 1, page 5 Configuring VLAN-ACL Mapping on FlexConnect Groups, page 10 Configuring WLAN-VLAN Mappings on FlexConnect Groups, page 11 Information About FlexConnect

More information

Configuring Auto-Anchor Mobility

Configuring Auto-Anchor Mobility Information About Auto-Anchor Mobility, page 1 Guest Anchor Priority, page 5 Information About Auto-Anchor Mobility You can use auto-anchor mobility (also called guest tunneling) to improve load balancing

More information

Wireless LAN Controller (WLC) Mobility Groups FAQ

Wireless LAN Controller (WLC) Mobility Groups FAQ Wireless LAN Controller (WLC) Mobility Groups FAQ Document ID: 107188 Contents Introduction What is a Mobility Group? What are the prerequisites for a Mobility Group? How do I configure a Mobility Group

More information

Cisco Troubleshooting Cisco Wireless Enterprise Networks WITSHOOT v1.1

Cisco Troubleshooting Cisco Wireless Enterprise Networks WITSHOOT v1.1 Course Overview Provides students information to troubleshoot Cisco wireless networks. The course provides guidelines for troubleshooting Wi-Fi architectures of Cisco wireless components. Who Should Attend

More information

Converged Access: Wireless AP and RF

Converged Access: Wireless AP and RF This chapter describes the best recommendation or practices of Radio Resource Management (RRM), beam forming, Fast SSID, and Cisco CleanAir features. The examples provided in this chapter are sufficient

More information

Cisco 8500 Series Wireless Controller Deployment Guide

Cisco 8500 Series Wireless Controller Deployment Guide Cisco 8500 Series Wireless Controller Deployment Guide Document ID: 113695 Contents Introduction Prerequisites Requirements Components Used Conventions Product Overview Product Specifications Features

More information

P ART 3. Configuring the Infrastructure

P ART 3. Configuring the Infrastructure P ART 3 Configuring the Infrastructure CHAPTER 8 Summary of Configuring the Infrastructure Revised: August 7, 2013 This part of the CVD section discusses the different infrastructure components that are

More information

Configuring Client Roaming

Configuring Client Roaming Finding Feature Information, page 1 Restrictions for, page 1 Information About Client Roaming, page 2 How to Configure Layer 2 or Layer 3 Roaming, page 4 Monitoring Client Roaming Parameters, page 10 Monitoring

More information

Configuring FlexConnect Groups

Configuring FlexConnect Groups Information About FlexConnect Groups, page 1, page 3 Configuring VLAN-ACL Mapping on FlexConnect Groups, page 8 Information About FlexConnect Groups To organize and manage your FlexConnect access points,

More information

Cisco Deploying Basic Wireless LANs

Cisco Deploying Basic Wireless LANs Cisco Deploying Basic Wireless LANs WDBWL v1.2; 3 days, Instructor-led Course Description This 3-day instructor-led, hands-on course is designed to give you a firm understanding of the Cisco Unified Wireless

More information

Configuring Client Roaming

Configuring Client Roaming Finding Feature Information, page 1 Restrictions for, page 1 Information About Client Roaming, page 2 How to Configure Layer 2 or Layer 3 Roaming, page 4 Monitoring Client Roaming Parameters, page 11 Monitoring

More information

Cisco Unified Wireless Network Software Release 7.4

Cisco Unified Wireless Network Software Release 7.4 Product Bulletin Cisco Unified Wireless Network Software Release 7.4 PB722724 Overview Cisco Unified Wireless Network (CUWN) Software Release 7.4 brings advancements to the wireless market with innovative

More information

Borderless Networks. Tom Schepers, Director Systems Engineering

Borderless Networks. Tom Schepers, Director Systems Engineering Borderless Networks Tom Schepers, Director Systems Engineering Agenda Introducing Enterprise Network Architecture Unified Access Cloud Intelligent Network & Unified Services Enterprise Networks in Action

More information

Configuring High Availability (HA)

Configuring High Availability (HA) 4 CHAPTER This chapter covers the following topics: Adding High Availability Cisco NAC Appliance To Your Network, page 4-1 Installing a Clean Access Manager High Availability Pair, page 4-3 Installing

More information

Architecting Network for Branch Offices with Cisco Unified Wireless

Architecting Network for Branch Offices with Cisco Unified Wireless Architecting Network for Branch Offices with Cisco Unified Wireless Aparajita Sood Technical Marketing Engineer Objective Design & Deploy Branch Network That Increases Business Resiliency 3 Agenda Learn

More information

Real4Test. Real IT Certification Exam Study materials/braindumps

Real4Test.   Real IT Certification Exam Study materials/braindumps Real4Test http://www.real4test.com Real IT Certification Exam Study materials/braindumps Exam : 400-351 Title : CCIE Wireless Vendor : Cisco Version : DEMO Get Latest & Valid 400-351 Exam's Question and

More information

Configuring WDS, Fast Secure Roaming, Radio Management, and Wireless Intrusion Detection Services

Configuring WDS, Fast Secure Roaming, Radio Management, and Wireless Intrusion Detection Services CHAPTER 11 Configuring WDS, Fast Secure Roaming, Radio Management, and Wireless Intrusion Detection Services This chapter describes how to configure your access point/bridges for wireless domain services

More information

Test Results Summary for Cisco Unified Wireless LAN Test 7.5 for Japan (Release )

Test Results Summary for Cisco Unified Wireless LAN Test 7.5 for Japan (Release ) Test Results Summary for Cisco Unified Wireless LAN Test 7.5 for Japan (Release 7.5.102.0) First Published: May 14, 2013 Last Modified: July 10, 2013 Americas Headquarters Cisco Systems, Inc. 170 West

More information

FlexConnect. Information About FlexConnect

FlexConnect. Information About FlexConnect Information About, on page 1 Restrictions on, on page 6 Configuring, on page 8 Information About (previously known as Hybrid Remote Edge Access Point or H-REAP) is a wireless solution for branch office

More information

Test Results Summary for Cisco Wireless LAN Controller AireOS 8.2MR1 for Japan (Release Version AireOS )

Test Results Summary for Cisco Wireless LAN Controller AireOS 8.2MR1 for Japan (Release Version AireOS ) Test Results Summary for Cisco Wireless LAN Controller AireOS 8.2MR1 for Japan (Release Version AireOS First Published: March 04, 2016 Last Modified: March 07, 2016 Americas Headquarters Cisco Systems,

More information

PassCollection. IT certification exam collections provider, High pass rate

PassCollection.   IT certification exam collections provider, High pass rate PassCollection http://www.passcollection.com IT certification exam collections provider, High pass rate Exam : 300-365 Title : Deploying Cisco Wireless Enterprise Networks Vendor : Cisco Version : DEMO

More information

Configuring RF Profiles

Configuring RF Profiles Prerequisites for, page 1 Restrictions for, page 1 Information About RF Profiles, page 2 Configuring an RF Profile (GUI), page 5 Configuring an RF Profile (CLI), page 6 Applying an RF Profile to AP Groups

More information

Per-WLAN Wireless Settings

Per-WLAN Wireless Settings DTIM Period, page 1 Off-Channel Scanning Deferral, page 3 Cisco Client Extensions, page 10 Client Profiling, page 12 Client Count per WLAN, page 15 DTIM Period Information About DTIM Period In the 802.11

More information

Configuring Backup Controllers

Configuring Backup Controllers Information About, page 1 Restrictions for, page 2 (GUI), page 2 (CLI), page 3 Information About A single controller at a centralized location can act as a backup for access points when they lose connectivity

More information

FortiNAC. Cisco Airespace Wireless Controller Integration. Version: 8.x. Date: 8/28/2018. Rev: B

FortiNAC. Cisco Airespace Wireless Controller Integration. Version: 8.x. Date: 8/28/2018. Rev: B FortiNAC Cisco Airespace Wireless Controller Integration Version: 8.x Date: 8/28/2018 Rev: B FORTINET DOCUMENT LIBRARY http://docs.fortinet.com FORTINET VIDEO GUIDE http://video.fortinet.com FORTINET KNOWLEDGE

More information

Mobility Groups. Information About Mobility

Mobility Groups. Information About Mobility Information About Mobility, page 1 Information About, page 5 Prerequisites for Configuring, page 10 Configuring (GUI), page 12 Configuring (CLI), page 13 Information About Mobility Mobility, or roaming,

More information

Using Access Point Communication Protocols

Using Access Point Communication Protocols Information About Access Point Communication Protocols, page 1 Restrictions for Access Point Communication Protocols, page 2 Configuring Data Encryption, page 2 Viewing CAPWAP Maximum Transmission Unit

More information

Universal Wireless Controller Configuration for Cisco Identity Services Engine. Secure Access How-To Guide Series

Universal Wireless Controller Configuration for Cisco Identity Services Engine. Secure Access How-To Guide Series Universal Wireless Controller Configuration for Cisco Identity Services Engine Secure Access How-To Guide Series Author: Hosuk Won Date: November 2015 Table of Contents Introduction... 3 What Is Cisco

More information

High Density & High Availability in Wireless Deployment

High Density & High Availability in Wireless Deployment Fast Innovation requires Fast IT High Density & High Availability in Wireless Deployment MinSe Kim, Sr. Technical Marketing Engineer, Cisco Systems 1 Agenda WiFi Operation Today WLAN RF Design Fundamental

More information

Test Results Summary for Cisco Unified Wireless LAN Test 7.4 for Japan (Release )

Test Results Summary for Cisco Unified Wireless LAN Test 7.4 for Japan (Release ) Test Results Summary for Cisco Unified Wireless LAN Test 7.4 for Japan (Release 7.4.100.0) First Published: January 25, 2013 Last Modified: March 25, 2013 Americas Headquarters Cisco Systems, Inc. 170

More information

Software-Defined Access Wireless

Software-Defined Access Wireless Introduction to, page 1 Configuring SD-Access Wireless (CLI), page 7 Enabling SD-Access Wireless (GUI), page 8 Configuring SD-Access Wireless VNID (GUI), page 9 Configuring SD-Access Wireless WLAN (GUI),

More information

Configuring Auto-Anchor Mobility

Configuring Auto-Anchor Mobility Information About Auto-Anchor Mobility, page 1 Information About Auto-Anchor Mobility You can use auto-anchor mobility (also called guest tunneling) to improve load balancing and security for roaming clients

More information

Ensure that you meet these requirements before you attempt this configuration:

Ensure that you meet these requirements before you attempt this configuration: Contents Introduction Prerequisites Requirements Components Used Conventions Network Diagram Configure Configure Mobility Groups for the WLCs Assign Primary, Secondary, and Tertiary Controllers for the

More information

CertKiller q

CertKiller q CertKiller.500-451.28q Number: 500-451 Passing Score: 800 Time Limit: 120 min File Version: 5.3 500-451 Cisco Unified Access Systems Engineer Exam I just passed today with 89%. My sole focus was the VCE.

More information

DWS-4000 Series DWL-3600AP DWL-6600AP

DWS-4000 Series DWL-3600AP DWL-6600AP Unified Wired & Wireless Access System Configuration Guide Product Model: Release 1.0 DWS-4000 Series DWL-8600AP DWL-6600AP DWL-3600AP Page 1 Table of Contents 1. Scenario 1 - Basic L2 Edge Setup: 1 Unified

More information

Configuring Layer2 Security

Configuring Layer2 Security Prerequisites for Layer 2 Security, page 1 Configuring Static WEP Keys (CLI), page 2 Configuring Dynamic 802.1X Keys and Authorization (CLI), page 2 Configuring 802.11r BSS Fast Transition, page 3 Configuring

More information

Managing Software. Upgrading the Controller Software. Considerations for Upgrading Controller Software

Managing Software. Upgrading the Controller Software. Considerations for Upgrading Controller Software Upgrading the Controller Software, on page 1 Considerations for Upgrading Controller Software, on page 1 Upgrading Controller Software (GUI), on page 2 Upgrading Controller Software (CLI), on page 5 Predownloading

More information

Performing Administrative Tasks

Performing Administrative Tasks CHAPTER 15 The Administration enables you to schedule tasks, administer accounts, and configure local and external authentication and authorization. Also, set logging options, configure mail servers, and

More information

Design and Deployment of Enterprise WLANs

Design and Deployment of Enterprise WLANs Design and Deployment of Enterprise WLANs 2 Agenda Controller-Based Architecture Overview Mobility in the Cisco Unified WLAN Architecture Architecture Building Blocks Deploying the Cisco Unified Wireless

More information

Client Data Tunneling

Client Data Tunneling Ethernet over GRE Tunnels, on page 1 Proxy Mobile IPv6, on page 9 Ethernet over GRE Tunnels Ethernet over GRE (EoGRE) is a new aggregation solution for aggregating Wi-Fi traffic from hotspots. This solution

More information

Multicast VLAN, page 1 Passive Clients, page 2 Dynamic Anchoring for Clients with Static IP Addresses, page 5

Multicast VLAN, page 1 Passive Clients, page 2 Dynamic Anchoring for Clients with Static IP Addresses, page 5 Multicast VLAN, page 1 Passive Clients, page 2 Dynamic Anchoring for Clients with Static IP Addresses, page 5 Multicast VLAN Information About Multicast Optimization Prior to the 7.0.116.0 release, multicast

More information

Deployment Guide for Cisco Guest Access Using the Cisco Wireless LAN Controller, Release 4.1

Deployment Guide for Cisco Guest Access Using the Cisco Wireless LAN Controller, Release 4.1 Deployment Guide for Cisco Guest Access Using the Cisco Wireless LAN Controller, Release 4.1 Last revised: February 1, 2008 Contents Overview section on page 1 Configuring Guest Access on the Cisco Wireless

More information

Cisco Mobility Express Solution

Cisco Mobility Express Solution FAQ Cisco Mobility Express Solution 2017 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 8 Contents General Information... 3 Access Point Compatibility

More information

Configuring Link Aggregation

Configuring Link Aggregation Information About Link Aggregation, page 1 Restrictions for Link Aggregation, page 2 (GUI), page 4 (CLI), page 4 Verifying Link Aggregation Settings (CLI), page 5 Configuring Neighbor Devices to Support

More information

Configuring Client Profiling

Configuring Client Profiling Prerequisites for, page 1 Restrictions for, page 2 Information About Client Profiling, page 2, page 3 Configuring Custom HTTP Port for Profiling, page 4 Prerequisites for By default, client profiling will

More information

Cisco NCS Overview. The Cisco Unified Network Solution CHAPTER

Cisco NCS Overview. The Cisco Unified Network Solution CHAPTER CHAPTER 1 This chapter describes the Cisco Unified Network Solution and the Cisco Prime Network Control System (NCS). It contains the following sections: The Cisco Unified Network Solution, page 1-1 About

More information

Cisco Unified Wireless Technology and Architecture

Cisco Unified Wireless Technology and Architecture CHAPTER 2 Cisco Unified Wireless Technology and Architecture The purpose of this chapter is to discuss the key design and operational considerations in an enterprise Cisco Unified Wireless Deployment.

More information

Wireless LAN Controller (WLC) Design and Features FAQ

Wireless LAN Controller (WLC) Design and Features FAQ Wireless LAN Controller (WLC) Design and Features FAQ Document ID: 118833 Contents Introduction Design FAQ Features FAQ Related Information Introduction This document provides information on the most frequently

More information

Configuring Repeater and Standby Access Points and Workgroup Bridge Mode

Configuring Repeater and Standby Access Points and Workgroup Bridge Mode CHAPTER 19 Configuring Repeater and Standby Access Points and Workgroup Bridge Mode This chapter describes how to configure your access point as a repeater, as a hot standby unit, or as a workgroup bridge.

More information

Introduction to Technology

Introduction to Technology Introduction to 802.11 Technology Suebpong Nitichai Email: sniticha@cisco.com 1 IEEE 802.11 Family Technology Overview IEEE 802.11 Standard define : A Physical layer Radio Frequencies, Data Modulation,

More information

Ports and Interfaces. Ports. Information About Ports. Ports, page 1 Link Aggregation, page 5 Interfaces, page 10

Ports and Interfaces. Ports. Information About Ports. Ports, page 1 Link Aggregation, page 5 Interfaces, page 10 Ports, page 1 Link Aggregation, page 5 Interfaces, page 10 Ports Information About Ports A port is a physical entity that is used for connections on the Cisco WLC platform. Cisco WLCs have two types of

More information

Software-Defined Access Wireless

Software-Defined Access Wireless Introduction to, page 1 Configuring SD-Access Wireless (CLI), page 7 Enabling SD-Access Wireless (GUI), page 8 Configuring SD-Access Wireless VNID (GUI), page 9 Configuring SD-Access Wireless WLAN (GUI),

More information

SD-Access Wireless: why would you care?

SD-Access Wireless: why would you care? SD-Access Wireless: why would you care? CUWN Architecture - Centralized Overview Policy Definition Enforcement Point for Wi-Fi clients Client keeps same IP address while roaming WLC Single point of Ingress

More information

Politecnico di Torino Network architecture and management. Outline 11/01/2016. Marcello Maggiora, Antonio Lantieri, Marco Ricca

Politecnico di Torino Network architecture and management. Outline 11/01/2016. Marcello Maggiora, Antonio Lantieri, Marco Ricca Politecnico di Torino Network architecture and management Marcello Maggiora, Antonio Lantieri, Marco Ricca Outline Politecnico di Torino network: Overview Building blocks: Edge, Core, Distribution, Access

More information

Test Results Summary for Cisco Wireless LAN Controller AireOS 8.3, IOS XE for Japan (Release Version AireOS /IOS XE 16.2.

Test Results Summary for Cisco Wireless LAN Controller AireOS 8.3, IOS XE for Japan (Release Version AireOS /IOS XE 16.2. Test Results Summary for Cisco Wireless LAN Controller AireOS 8.3, IOS XE 16.2.1 for Japan (Release Version AireOS 8.3.102.0/IOS XE 16.2.1) First Published: 2016-03-04 Last Modified: 2016-09-28 Americas

More information

Vendor: Cisco. Exam Code: Exam Name: Implementing Advanced Cisco Unified Wireless Security (IAUWS) v2.0. Version: Demo

Vendor: Cisco. Exam Code: Exam Name: Implementing Advanced Cisco Unified Wireless Security (IAUWS) v2.0. Version: Demo Vendor: Cisco Exam Code: 642-737 Exam Name: Implementing Advanced Cisco Unified Wireless Security (IAUWS) v2.0 Version: Demo QUESTION 1 Which statement describes the major difference between PEAP and EAP-FAST

More information

Cisco Wireless LAN Controller Configuration Guide

Cisco Wireless LAN Controller Configuration Guide Cisco Wireless LAN Controller Configuration Guide Software Release 7.0.116.0 April 2011 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com

More information

Mesh Deployment Modes

Mesh Deployment Modes This chapter describes the mesh deployment modes and contains the following sections: Wireless Mesh Network, page 1 Wireless Backhaul, page 1 Point-to-Multipoint Wireless Bridging, page 2 Point-to-Point

More information

Template information can be overridden on individual devices.

Template information can be overridden on individual devices. CHAPTER 12 This chapter describes the Controller Template Launch Pad. It is a hub for all controller templates. Templates provide a way to set parameters that you can then apply to multiple devices without

More information

NXC Series. Handbook. NXC Controllers NXC 2500/ Default Login Details. Firmware Version 5.00 Edition 19, 5/

NXC Series. Handbook. NXC Controllers NXC 2500/ Default Login Details. Firmware Version 5.00 Edition 19, 5/ NXC Series NXC 2500/ 5500 NXC Controllers Firmware Version 5.00 Edition 19, 5/2017 Handbook Default Login Details LAN Port IP Address https://192.168.1.1 User Name admin Password 1234 Copyright 2017 ZyXEL

More information

Converged Access Mobility Design & Architecture

Converged Access Mobility Design & Architecture Converged Access Mobility Design & Architecture Sujit Ghosh Sr. Mgr. Technical Marketing Enterprise Networking Group Converged Access Architecture Overview Diving into the One Network BRKCRS-2022 Session

More information

Cisco Exam Implementing Advanced Cisco Unified Wireless Security v2.0 Version: 9.0 [ Total Questions: 206 ]

Cisco Exam Implementing Advanced Cisco Unified Wireless Security v2.0 Version: 9.0 [ Total Questions: 206 ] s@lm@n Cisco Exam 642-737 Implementing Advanced Cisco Unified Wireless Security v2.0 Version: 9.0 [ Total Questions: 206 ] Cisco 642-737 : Practice Test Question No : 1 RADIUS is set up with multiple servers

More information

Configuring WDS, Fast Secure Roaming, Radio Management, and Wireless Intrusion Detection Services

Configuring WDS, Fast Secure Roaming, Radio Management, and Wireless Intrusion Detection Services 12 CHAPTER Configuring WDS, Fast Secure Roaming, Radio Management, and Wireless Intrusion Detection Services This chapter describes how to configure your access points for wireless domain services (WDS),

More information

Q&As. Implementing Cisco Unified Wireless Voice Networks (IUWVN) v2.0. Pass Cisco Exam with 100% Guarantee

Q&As. Implementing Cisco Unified Wireless Voice Networks (IUWVN) v2.0. Pass Cisco Exam with 100% Guarantee 642-742 Q&As Implementing Cisco Unified Wireless Voice Networks (IUWVN) v2.0 Pass Cisco 642-742 Exam with 100% Guarantee Free Download Real Questions & Answers PDF and VCE file from: 100% Passing Guarantee

More information

Wireless Domain Services FAQ

Wireless Domain Services FAQ Wireless Domain Services FAQ Document ID: 65346 Contents Introduction What is WDS? How do I configure my AP as a WDS? On what platforms does Cisco Structured Wireless Aware Network (SWAN) WDS run? How

More information

Managing Rogue Devices

Managing Rogue Devices Information About Rogue Devices, page 1 Configuring Rogue Detection (GUI), page 5 Configuring Rogue Detection (CLI), page 8 Information About Rogue Devices Rogue access points can disrupt wireless LAN

More information

Template information can be overridden on individual devices.

Template information can be overridden on individual devices. CHAPTER 12 This chapter describes the Controller Template Launch Pad. It is a hub for all controller templates. Templates provide a way to set parameters that you can then apply to multiple devices without

More information

DEPLOYING BASIC CISCO WIRELESS LANS (WDBWL)

DEPLOYING BASIC CISCO WIRELESS LANS (WDBWL) [Type a quote from the document or the summary of an interesting point. You can position the text box anywhere in the document. Use the Drawing Tools tab to change the formatting of the pull quote text

More information

Cisco TrustSec How-To Guide: Universal Configuration for the Cisco Wireless LAN Controller

Cisco TrustSec How-To Guide: Universal Configuration for the Cisco Wireless LAN Controller Cisco TrustSec How-To Guide: Universal Configuration for the Cisco Wireless LAN Controller For Comments, please email: howtoguides@external.cisco.com Current Document Version: 3.0 August 27, 2012 Table

More information

Campus LAN and Wireless LAN Design Summary

Campus LAN and Wireless LAN Design Summary CISCO VALIDATED DESIGN Campus LAN and Wireless LAN Design Summary October 2015 REFERENCE NETWORK ARCHITECTURE Contents Campus Design Introduction... 1 Campus LAN and Wireless LAN Design Guidance... 2 High-Density

More information

Multicast/Broadcast Setup

Multicast/Broadcast Setup Configuring Multicast Mode, page 1 Mediastream, page 9 Configuring Multicast Domain Name System, page 14 Configuring Multicast Mode Information About Multicast/Broadcast Mode If your network supports packet

More information

Configuring Port Channels

Configuring Port Channels CHAPTER 5 This chapter describes how to configure port channels and to apply and configure the Link Aggregation Control Protocol (LACP) for more efficient use of port channels in Cisco DCNM. For more information

More information

A connected workforce is a more productive workforce

A connected workforce is a more productive workforce A connected workforce is a more productive workforce D-Link wireless networking solutions enable business networks of all sizes to create highly mobile, highly productive work environments at a low total

More information

Editing WLAN SSID or Profile Name for WLANs (CLI), page 6

Editing WLAN SSID or Profile Name for WLANs (CLI), page 6 Prerequisites for WLANs, page 1 Restrictions for WLANs, page 2 Information About WLANs, page 3 Creating and Removing WLANs (GUI), page 3 Enabling and Disabling WLANs (GUI), page 4 Editing WLAN SSID or

More information

Securing Cisco Wireless Enterprise Networks ( )

Securing Cisco Wireless Enterprise Networks ( ) Securing Cisco Wireless Enterprise Networks (300-375) Exam Description: The 300-375 Securing Wireless Enterprise Networks (WISECURE) exam is a 90minute, 60-70 question assessment that is associated with

More information

Configure Controller and AP Settings

Configure Controller and AP Settings Configure SNMP Credentials for Rogue AP Tracing, on page 1 Configure Protocols for CLI Sessions, on page 2 Enable Unified AP Ping Reachability Settings on the Prime Infrastructure, on page 2 Refresh Controllers

More information

Securing Wireless LAN Controllers (WLCs)

Securing Wireless LAN Controllers (WLCs) Securing Wireless LAN Controllers (WLCs) Document ID: 109669 Contents Introduction Prerequisites Requirements Components Used Conventions Traffic Handling in WLCs Controlling Traffic Controlling Management

More information

Campus network: Looking at the big picture

Campus network: Looking at the big picture Outline Politecnico di Torino architecture and management Marcello Maggiora, Antonio Lantieri, Marco Ricca Building blocks Core, Distribution, Access, Edge network architecture Core network Distribution

More information

Configuring a WLAN for Static WEP

Configuring a WLAN for Static WEP Restrictions for Configuring Static WEP, page 1 Information About WLAN for Static WEP, page 1 Configuring WPA1+WPA2, page 3 Restrictions for Configuring Static WEP The OEAP 600 series does not support

More information

Software-Defined Access Wireless

Software-Defined Access Wireless Introduction to, page 1 Configuring SD-Access Wireless (CLI), page 7 Introduction to The Enterprise Fabric provides end-to-end enterprise-wide segmentation, flexible subnet addressing, and controller-based

More information

Vendor: HP. Exam Code: HP2-Z32. Exam Name: Implementing HP MSM Wireless Networks. Version: Demo

Vendor: HP. Exam Code: HP2-Z32. Exam Name: Implementing HP MSM Wireless Networks. Version: Demo Vendor: HP Exam Code: HP2-Z32 Exam Name: Implementing HP MSM Wireless Networks Version: Demo QUESTION 1 A network administrator deploys several HP MSM APs and an HP MSM Controller. The APs discover the

More information

Cisco Catalyst 9800 Wireless Controller Series Web UI Deployment Guide

Cisco Catalyst 9800 Wireless Controller Series Web UI Deployment Guide Cisco Catalyst 9800 Wireless Controller Series Web UI Deployment Guide Introduction 2 Feature Overview 2 Elements of the configuration model Tags and Profiles 2 Association of tags to APs 5 Day 0 Express

More information

DHCP. DHCP Proxy. Information About Configuring DHCP Proxy. Restrictions on Using DHCP Proxy

DHCP. DHCP Proxy. Information About Configuring DHCP Proxy. Restrictions on Using DHCP Proxy Proxy, page 1 Link Select and VPN Select, page 4 Option 82, page 7 Internal Server, page 10 for WLANs, page 13 Proxy Information About Configuring Proxy When proxy is enabled on the controller, the controller

More information

IP network that supports DHCP or manual assignment of IP address, gateway, and subnet mask

IP network that supports DHCP or manual assignment of IP address, gateway, and subnet mask Network Requirements, page 1 Wireless LAN, page 2 Wi-Fi Network Components, page 3 802.11 Standards for WLAN Communications, page 6 Security for Communications in WLANs, page 9 WLANs and Roaming, page

More information

WLAN Timeouts. Timeouts. Timeout for Disabled Clients. Session Timeout. Information About Configuring a Timeout for Disabled Clients

WLAN Timeouts. Timeouts. Timeout for Disabled Clients. Session Timeout. Information About Configuring a Timeout for Disabled Clients Timeouts, page 1 Address Resolution Protocol Timeout, page 3 Authentication for Sleeping Clients, page 4 Timeouts Timeout for Disabled Clients Information About Configuring a Timeout for Disabled Clients

More information

Configure n on the WLC

Configure n on the WLC Configure 802.11n on the WLC Document ID: 108184 Contents Introduction Prerequisites Requirements Components Used Related Products Conventions 802.11n An Overview How Does 802.11n Provide Greater Throughput

More information

3. What could you use if you wanted to reduce unnecessary broadcast, multicast, and flooded unicast packets?

3. What could you use if you wanted to reduce unnecessary broadcast, multicast, and flooded unicast packets? Nguyen The Nhat - Take Exam Exam questions Time remaining: 00: 00: 51 1. Which command will give the user TECH privileged-mode access after authentication with the server? username name privilege level

More information