CiscoFlexAP Sunum 2016
CiscoFlexAP Sunum 2016
LAN Design
Rajat Tayal ([email protected])
Technical Marketing Engineer
BRKEWN-2016
THANK YOU!!
Cisco Spark
Questions?
Use Cisco Spark to chat with the
speaker after the session
How
1. Find this session in the Cisco Live Mobile App
2. Click “Join the Discussion”
3. Install Spark or go directly to the space
4. Enter messages/questions in the space
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Agenda
• Wireless Controller and Acess Point Portfolio
• Branch Deployment Options
• Evaluate FlexConnect Requirements and identify need for FlexConnect & AP Groups
• Design a Resilient, Secure, and BYOD enabled Branch Network
• Service-Ready Branch
• Provision and Operate Wireless Branch over WAN
• Deploying Small and medium sites using Cisco Mobility Express
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Platforms &
Wireless Controller Portfolio Large Enterprise, Branch
Virtualization
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Cisco Aironet 802.11ac Wave 2 Access Point Portfolio
Industry’s most comprehensive and innovative
Enterprise Class Mission Critical Best in Class
DNA Ready | RF Excellence | CMX | Centralized, FlexConnect or Mobility Express
Dual 5 GHz | Flexible Radio | HDX
Future Proof
3800
2800
1830 1850 • 4x4:3SS 160 MHz
1815 • 4x4:3SS 160 MHz • 5 Gbps Performance
Indoor / High-powered Indoor • 4x4:3SS 80 MHz • 5 Gbps Performance • 2.4 and 5GHz or
Wall Plate / Teleworker • 3x3:2SS 80 MHz Dual 5GHz
• 1.7 Gbps Performance • 2.4 and 5GHz or
• 2x2:2SS 80 MHz • 867 Mbps Performance Dual 5GHz • 2 GE Ports Uplink or
• Internal or External
• 867 Mbps Performance • Tx Beam Forming Antenna • 2 GE Ports Uplink 1 GE + 1 mGig (5G)
• Tx Beam Forming • 1 GE Port Uplink • Tx Beam Forming • CleanAir and ClientLink • CleanAir and ClientLink
• Integrated BLE Gateway1 • USB 2.0 • 2 GE Ports Uplink • Internal or External • StadiumVision
• Max Transmit Power (dBm) • USB 2.0 Antenna • Internal or External
per local regulations2 • Smart Antenna Antenna
• 3 GE Local Ports, including Connector • Smart Antenna Connector
1 PoE out3 • USB 2.0 • USB 2.0
• Local ports 802.1x ready3 • Investment Proof
• Centralized, FlexConnect and Mobility Express
• USB 2.04
1Future availability 2 Available for High-powered only 3 Available for wall-plate and teleworker only 4 Available for teleworker only
Modularity
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Aironet 802.11ac Outdoor Access Point Portfolio
Industry’s most comprehensive and innovative portfolio
DNA Ready | RF Excellence | CMX
New
New
1570
1560 • 802.11ac Wave 1
• 4x4:3 80 MHz; 1.3 Gbps
• 802.11ac Wave 2, MU-MIMO • External antenna model (EAC)
• 3x3:3, 80MHz, 1.3Gbps (I) • Cable Modem model (IC/EC)
1540 • 2x2:2, 80MHz, 867Mbps (E/D) • SFP
• 802.11ac Wave 2, MU-MIMO • Internal or External antenna model (I/E) • GPS
• 2x2:2, 80MHz, 867 Mbps • Internal directional antenna model (D) • PoE Out 802.3at (Ext Ant. only)
• Ultra low profile • SFP • Flexible Antenna Ports
• Internal antenna model (I) • Flexible Antenna Ports • CleanAir and ClientLink
• Internal directional antenna model (D) • CleanAir and ClientLink • Modularity (Ext Ant. only)
• PoE (802.3af) power • Centralized, FlexConnect, Mesh and • Centralized, FlexConnect and Mesh
• Centralized, FlexConnect, Mesh* and Mobility Express Cable Modem Version Only (IC/EC)
Mobility Express • DOCSIS 3.0, 24x8
802.11ac Wave 2 • Internal or External antenna
WAN Intranet
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Wireless Branch Deployment
FlexConnect Deployment
Branch Office with Local WLAN Controller
Options Backup Central
Controller
Central Site
Small or Mid-size Branch WLCs
CT-3504, CAPWAP
Integrated controller modules in
ISR/ISR-G2 WAN
vWLC vWLC
WLC-35xx WLCM for
ISR/ISR-G2
Advantages
• Layer-3 roaming within the branch
• Cookie cutter configuration for
every branch site
Remote Site C
Remote Site A
Remote Site B
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Branch Office Deployment
Central Site
FlexConnect
Centralized
• Hybrid architecture Traffic Centralized
Traffic
• Single management and control point
• Data Traffic Switching
• Centralized traffic
(split MAC) or
• Local traffic (local MAC)
WAN
• Traffic Switching is configured per AP
and per WLAN (SSID)
• Standalone Mode will preserve local traffic
Remote Office
Local
Traffic
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect Glossary
01 Connected Mode
When FlexConnect AP can reach Controller, it gets help
from controller to complete client authentication
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Configuring FlexConnect Local
Switching
Step 1: Configure FlexConnect Mode on AP
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Step 2: Configure FlexConnect Local Switching on
WLAN
Only WLAN with “FlexConnect Local Switching” enabled will allow local
switching on the FlexConnect AP
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Step 3: Configure Native VLAN on FlexConnect AP
When connecting with Native VLAN on AP, L2 switchport must also match with corresponding Native
VLAN configuration
VLAN mapping can be performed per AP, per FlexConnect Group on WLC or using Cisco Prime
Infrastructure templates
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Step 4: Configure FlexConnect WLAN-VLAN
Mapping
Mapping of WLAN to VLAN can be done per FlexConnect AP or FlexConnect Group
Or use Cisco Prime Infrastructure via configuration templates
Each corresponding WLAN that is allowed to be locally switch should be allowed on the
corresponding switchport
1 2
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Configure FlexConnect VLAN Mapping
Using Cisco Prime Infrastructure
Prime Infrastructure provides simplified configuration to all FlexConnect APs
with one Lightweight AP Template
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Evaluate FlexConnect Architectural
Requirements
For Your
Reference
FlexConnect Design Considerations
WAN Limitations Apply
Deployment WAN Bandwidth WAN RTT Max APs per Max Clients per
Type (Min) Latency (Max) Branch Branch
It is highly recommended that the minimum bandwidth restriction remains 24 Kbps per AP with the round trip
latency no greater than 300 ms for data deployments and 100 ms for data + voice deployments.
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
FlexConnect Design Considerations
Feature Limitations in Standalone mode and Local Switching
• MAC/Web Auth in Standalone Mode
• IPv6 Mobility
• Service Discovery Gateway
• Native Profiling and Policy Classification
• FlexConnect Feature Matrix
• http://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/112042-technote-wlc-00.html
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
IPv6 Support
✔
✔
✔
✔
✔
✔
✔
✔
✔
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
For Your
FlexConnect Feature Introduction Reference
FlexConnect Features Release Version
AAA-VLAN Override, ALCs & P2P Blocking 7.2
Smart AP Image Upgrade 7.2
External Web-Auth & Mobile Device On-boarding 7.2
Flex 7500 Scale Update 7.3
VLAN Based Central Switching 7.3
Split-tunneling 7.3
Work Group Bridge (WGB) Support 7.3
Bi-Directional Rate Limiting 7.4
ISE BYOD Registration & Provisioning 7.4
AAA-ACL & AAA-QoS Override 7.5
EAP-TLS & PEAP Support for Local Authentication 7.5
Ethernet Fallback 7.6
VideoStream for Local Switching 8.0
Faster time to deploy 8.0
FlexConnext on Mesh APs 8.0
AVC for FlexConnect 8.1
VLAN Name override for FlexConnect 8.1
FlexConnect Mode for AP from PnP 8.2
FlexConnect Group for AP from PnP and Default FlexConnect Group 8.3
TrustSec SXP/SGT 8.4
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Optimized for High Scale Deployments
Functionality
Cisco 8540 Series Controller
Access Points 6,000
Key Differentiation Clients 64,000
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Why do we need FlexConnect & AP
Groups?
Understanding AP Groups
Overview AP Group 1 Central Site
WLC5520
• AP Groups is a logical concept of
grouping AP’s which deliver similar Wi-Fi
services; these services can be:
• By physical location, and/or
• By functional services
(data, voice, guest, etc..)
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
AP Groups
Configuration: Create a New Group
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
AP Groups Use Case @ Internet
VLAN-2
• AP groups give the ability to statically
map Wi-Fi service (WLAN) to VLAN
based on physical location VLAN-3
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Understanding FlexConnect Groups
Central Site
WLC5520
Overview
FlexConnect
2000 1500 100
Groups
AP per Group 100 100 100 FlexConnect Group 1 FlexConnect Group 2
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
FlexConnect Groups and CCKM/OKC Keys
Overview Central Site CCKM Keys
RADIUS Server
• If a FlexConnect AP boots up
in standalone mode, it will not get the
OKC/CCKM keys from the WLC
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
FlexConnect Groups Creation
Step 1: Add a New FlexConnect Group
1
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
For Your
Reference
FlexConnect Groups Template on PI
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
For Your
Reference
FlexConnect Groups Template on PI
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
Designing a Resilient Wireless
Branch Network
FlexConnect Backup Scenario
Central Site
WAN Failure
FlexConnect APs will go to Standalone mode
No impact for locally switched SSIDs
Disconnection of centrally switched SSIDs
clients
WAN
Static authentication keys are locally stored in
FlexConnect AP
Remote Site
Lost Features
RRM, WIDS, location, other AP modes Application
Web authentication, NAC Server
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
FlexConnect Backup Scenario
Central Site
WLC Failure scenario with N+1 HA
Secondary Primary
WLC WLC
FlexConnect APs will go to Standalone mode
No impact for locally switched SSIDs
Disconnection of centrally switched SSIDs
clients WAN
CCKM roaming allowed in FlexConnect group
FlexConnect AP will then search Remote Site
for backup WLC; when backup WLC is found,
FlexConnect AP will resync with WLC and Application
resume client sessions with central traffic Server
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
FlexConnect Backup Scenario
Active
Remote Office
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
FlexConnect Group : Backup Scenario
Central Site
Local Backup RADIUS
Central
Normal authentication is done centrally RADIUS
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Local Authentication
Central Site
FlexConnect Group
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Local Authentication
Configuration
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
FlexConnect Group: Backup Scenario
Central Site
Local Backup Authentication
Central
Normal authentication is done centrally RADIUS
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Designing Secure & BYOD Enabled
Branch Network
FlexConnect Peer-to-peer
Blocking
Starting
Local Switching Peer-to-peer Blocking from 7.2
Central Site
Overview
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Local Switching Peer-to-peer Blocking
Configuration
* Central Switching WLAN will support “Forward - UpStream” and will send the packet to the next upstream
node connected to WLC
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
FlexConnect AAA VLAN & QoS
Override
Starting
from 7.2
FlexConnect AAA VLAN Override
Description RADIUS Central Site
FlexConnect Group
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
For Your
FlexConnect AAA VLAN Override Reference
Configuration IETF 65
IETF 64
IETF 81
WAN
ISE
Create Sub-Interface on
FlexConnect AP
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
VLAN Based Central Switching Central
VLAN 3
Go to Default
VLAN ID
Overview Central
RADIUS
VLAN 7
• While doing AAA VLAN Override with VLAN 3 does not
local switching: VLAN 7 Exist on this
WLC
• If VLAN ID does not exist at the AP,
the traffic is central switched to the WAN
central VLAN ID
Remote Site
• If the central VLAN ID does not exist,
the traffic is centrally switched to the
default VLAN ID of the WLAN
VLAN 7
does not
VLAN 3 Exist on
does not this AP
Exist on
this AP
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Starting
from 7.5
FlexConnect AAA QoS Override
Description
Dynamically assign QoS levels and/or bandwidth Vendor ID/Vendor Type Attribute
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
AAA Override Deployment Scenario
Problem Statement – Map clients to specific vlans based on their function
Central Site
VLAN 20
WAN
Application
Server
Function VLAN ID
Engineering 11
Marketing 21
Function VLAN ID Sales 31
Engineering 10 Application
Server
Marketing 20
Sales 30 VLAN 20
Remote Site A Remote Site B does not
exist
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Starting
VLAN Name Mapping at FlexConnect Group from 8.1
Remote Site B
Remote Site A
VLAN ID
VLAN ID
11
10 21
20 31
30
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Starting
from 8.1
VLAN Name AAA Override - Solution
Central Site
Aire-Interface-Name or
IETF Tunnel-Private-Group-ID
VLAN NAME=
Marketing
WAN
Application
Server
Remote Site Remote Site VLAN Name VLAN ID
VLAN 20 Engineering 11
Marketing 21
VLAN Name VLAN ID Sales 31
Engineering 10
Marketing 20
Sales 30
Remote Site A VLAN 21 Remote Site B
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
FlexConnect ACL VLAN Mapping
& Per-Client ACL
Starting
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
FlexConnect Access Lists
Configuration – Create FlexConnect ACL
• FlexConnect ACL rule creation is similar to rule creation for Local Mode AP
1
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
FlexConnect ACL – VLAN Mapping
Configuration – FlexConnect ACL per AP
2
• FlexConnect ACL can be applied per AP
using VLAN Mappings configuration
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
FlexConnect ACL – VLAN Mapping
Configuration –FlexConnect ACL per FlexConnect Group
• FlexConnect ACL can be applied per FlexConnect Groups per VLAN in the ACL
Mapping tab.
1 2
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
FlexConnect Split Tunneling
(Using FlexConnect Split ACL)
Starting
Overview
Split tunneling allow some traffic to be locally switched although the WLAN is defined as
centrally switched
Split tunneling is using a NAT/PAT feature with ACL to perform the local switching
Split tunneling is using the AP IP @ for the NAT/PAT feature
NAT/PAT WAN
ACL
Central Server
Local Traffic
Local Printer
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
FlexConnect ACL – Split Tunneling
Configuration
• Create a centrally switched WLAN
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
FlexConnect ACL – Split Tunneling
Configuration – Per Access Point
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
FlexConnect ACL – Split Tunneling
Configuration – Per FlexConnect Group
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Deploying BYOD with
FlexConnect Local Switching
(Using FlexConnect
WebPolicies ACL)
Bring Your Own Device(s) : The New Normal
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
BYOD - Device On-boarding in FlexConnect
Example: Apple iOS Device Provisioning
2
Device Provisioning
Wizard Client
Reconnects
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
FlexConnect Web Policy ACL
Configure Web Policy ACL per FlexConnect AP
• ACL Mapping can be configured per FlexConnect AP
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
FlexConnect Web Policy ACL
Configure Web Policy ACL per FlexConnect Group
• Use ACL Mapping tab in FlexConnect Group configuration
• WebPolicies ACL are not the same as VLAN ACL or WebAuthentication ACL.
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
Cisco Wireless Central DHCP Processing
Configuration
• To support DHCP Profiling Probe with FlexConnect, DHCP request must be
sent to WLC. This is done by the « Central DHCP Processing » configuration.
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
Deploying BYOD with FlexConnect Wireless
Summary – 802.1x/EAP Authentication ISE
DHCP Server
FlexConnect AP
CAPWAP WLC
Web Server
WAN
WiFi Association
Unknown Device,
Redirect to registration
802.1x/EAP Request Radius Access-Request
Inside CAPWAP
Radius Access-Response
• Access-Type: Access-Accept
• URL-Redirect-ACL=FlexACLWebPolicy,
URL + ACL Redirect • URL-Redirect=http://……)
Inside CAPWAP
802.1x/EAP Response
Inside CAPWAP
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
Deploying BYOD with FlexConnect Wireless
Summary – DHCP Request ISE
DHCP Server
FlexConnect AP
CAPWAP WLC
Web Server
WAN
DHCP Request
Inside CAPWAP
Device is
RADIUS-Accounting
an iPad
• host-name=MyiPad
• dhcp-class-identifier=APPLE
DHCP Lease
Inside CAPWAP
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
Deploying BYOD with FlexConnect Wireless
Summary – URL-Redirect ISE
DHCP Server
FlexConnect AP
CAPWAP WLC
Web Server
WAN
URL-Redirect
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Deploying BYOD with FlexConnect Wireless
Summary – Registration & Provisioning ISE
DHCP Server
FlexConnect AP
CAPWAP WLC
Web Server
WAN
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Deploying BYOD with FlexConnect Wireless
Summary – Device Access ISE
DHCP Server
FlexConnect AP
CAPWAP WLC
Web Server
WAN
DHCP Request/Response
Inside CAPWAP
Web Traffic
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
Summary of FlexConnect ACLs
-
80
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
Wireless TrustSec Support
Starting
Wireless TrustSec Support from 8.4
5 Employee
6 Voice A B
7 Partner
Local NO NO YES
Topology, location independent
Flex YES YES YES
Policy (SGT) stays with endpoint.
Simplifies ACL management traffic Mesh NO NO YES (Indoor only)
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
Service-Ready Branch
FlexConnect VideoStream
Video Multicast Delivery Challenges
Technical Challenges 802.11
• Multicast packets (UDP) are sent as
Data Rates
broadcast packets over the air per 802.11 1
standard 2
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
FlexConnect VideoStream Configuration
Add Stream Configuration
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 88
FlexConnect VideoStream Configuration
Enable VideoStream - WLAN
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
FlexConnect VideoStream Monitoring
Controller
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
FlexConnect Bridge Mode
Support
Starting
from 8.0
FlexConnect on Mesh APs
Centralized
Traffic
Failover Considerations
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 93
For Your
AP Modes Feature Comparison Reference
Feature\AP Mode Local Mode Bridge Mode Flexconnect Mode Flex+Bridge Mode
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 94
FlexConnect Bridge Mode Configuration
Wireless Access Points AP_NAME General
AP will reboot
upon change
Same options
as an AP in Flex
Mode
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 95
FlexConnect Application Visibility
and Control
How AVC solution works on wireless?
AireOS 8.1 App Visibility & AireOS 8.1
User Experience Report
App BW Transaction …
Time
WebEx 3 Mb 150 ms …
Citrix 10 Mb 500 ms …
Static
Netflow
AP
NBAR on AP
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
AVC on FlexConnect APs
Katana
Gen2 AP, NBAR Engine 23, PP 14
WAN
Gen2 AP
Flow ID App Name Packets Deployment Type WAN Bandwidth ( Min) WAN RTT Max Aps per Max Clients per
1 WebEx 1000 Latency(Max) Branch Branch
2 Msft-Lync 2300 Data + Flex AVC 75 Kbps 300 msec 5 25
3 Skype 660
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 98
AVC for FlexConnect APs
AP Functionality
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
AVC Configuration on Local Switching WLAN
WLAN AVC
Configuration
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 100
AVC Configuration per FlexConnect Group
• FlexConnect Group specific AVC configuration takes precedence over WLAN AVC config
• No AP Specific AVC configuration.
• WLAN AVC configuration will be pushed to Flex APs where WLAN is broadcast
Enable/disable, Profile,
Monitor per WLAN
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 101
FlexConnect AVC Profiles
Can be associated under WLAN and/or FlexConnect Group
FlexConnect AVC
profiles
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 102
FlexConnect AVC Applications
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 103
Monitoring AVC Statistics per FlexConnect Group
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 104
Operating the Wireless Branch
Branch Office Provisioning
Network Plug-N-Play – Simple, Secure, Scalable
Today’s Process Business
Network Challenges
Direct Costs
Central Staging Facility
Ships • Shipping after Configuring device
Pre Provision
1• Travel
equipment costs for IT installer
Projects/Sites
• Install OS
• Install Config
• Prime device Network Admin
Network Complexity
Reseller/Partner Admin
• Config errors
• Different products / processes
2 Install & Power-on 3 Monitor device
devices installation
Security
• 3rd party not secure
Installer
Installer
Network Admin
Time/Productivity
Site-1 Site-2 Site-3
• Manual process
Site(s)
• Shipping , Storage, Travel
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 107
Network Plug & Play Discovery options
DHCP Option 43
01
PnP String: 5A1D;B2;K4;I172.19.45.222;J80
DHCP
Server
DNS Lookup
02
pnpserver.localdomain ---- e.g.172.19.45.222 (PnP Server)
DNS
Server
CAPWAP
03
CAPWAP based WLC discovery for AP
CAPWAP
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 108
Branch Provisioning with PnP Server
PID Serial # Hostname WLC IP address AP Mode Flex Group
name
PnP Server
Day 0
• Places AP in appropriate
flexgroup/default
• Apply relevant flex configs to
AP
Network Admin
Network Admin pre
Day 1
provisions branch APs in Remote Installer on branch
PnP server. • Mount and cable devices
WLC IP (Prim/Sec/Ter) • Power-on
AP Name
AP Mode (Flex) * Resources required for PnP:
AP Group Name Installer 64 Gb RAM, 500 Gb Storage
Flex Group Name Scale: 10,000 devices
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 109
Branch Office Upgrade over WAN
Upgrading a FlexConnect Deployment
Concerns
Sites using FlexConnect AP are usually sites with low WAN bandwidth
Each site may have small number of AP, but an enterprise may have a lot of
branches
Upgrading ~6000 AP through a low bandwidth WAN is a challenge :
Time needed to download all the AP firmware
Exhaust of the WAN link
Risk of failures during the download
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 111
Starting
from 7.2
FlexConnect Smart AP Image Upgrade
Firmware Image
Master AP
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 113
FlexConnect Smart AP Image Upgrade
Configuration
Master AP Selection is
Optional
• “FlexConnect AP Upgrade” checkbox has to be enabled for each FlexConnect Group.
• By default, Master AP for each FlexConnect Group is selected using Lower-MAC algorithm.
• One Master select per AP type.
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 114
FlexConnect
() Smart AP Image Upgrade
Configuration contd.
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 115
Bringing All Together – FlexConnect
Best Practices
FlexConnect Best Practices
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 117
Summary
• Cisco Unified Wireless Network based on Controllers deliver Wireless Branch Solution
• FlexConnect is the feature designed to solve remote connectivity and WAN constraints
• Several Failover Scenario are targeted to offer Survivability of Small Remote Sites
References:
• Wireless LAN Controller Scale Comparison Guide - http://www.cisco.com/c/en/us/products/wireless/wireless-lan-
controller/product-comparison.html
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 118
Wireless Branch Deployment
Cisco Mobility Express
What Cisco Mobility Express does?
Runs Wireless LAN Controller
01 function on an access point
Activates best-practice
settings by default and 04 Easily manages and
supports presence-based 03 troubleshoots your network
using advanced software-
analytics
based functions
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 120
Where can you use it?
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 121
Which APs can run Cisco Mobility Express?
50 1000 50 1000 100 2000
AIR-AP1815I-x-K9 AIR-AP1852-x-K9 AIR-AP3800-x-K9
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 122
Small/Medium Site with Cisco Mobility Express
Overview Network Plug and Play Prime Infrastructure ISE
Central Site
WAN
Advantages
Cookie cutter configuration for Site A Site B Site C
every site
Independent or centralized
manageability of each site
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Deploying Cisco Mobility Express
Depending on the deployment, Mobility Express capable Access Points can be connected to an access
port or a trunk port on the switch. Management traffic is always untagged.
VLAN 10
VLAN 20
v20 v30 v40 VLAN 30
VLAN 10 VLAN 40
01 OTAP Over-the-Air-Provisioning
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 125
Over the Air Provisioning
Cisco Wireless App
Provision Monitor
Laptop
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 126
Setup Wizard
CREATE WIRELESS
CREATE ADMIN ACCOUNT SET UP YOUR CONTROLLER CONFIRM SETTINGS
NETWORK
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 127
Deploying using APIC-EM/Network Plug and Play
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 128
Network Plug and Play – Private Cloud
ip dhcp pool pnp_device_pool
network 192.168.1.0 255.255.255.0 Master AP
default-router 192.168.1.1 running PnP
option 43 ascii Agent
"5A1N;B2;K4;I192.168.1.123;J80"
LAN/WAN
LAN
PnP Server uses
PnP Server
self signed SSL
certificate
DHCP Request
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 129
Network Plug and Play – Public Cloud
ip dhcp pool pnp_device_pool
network 192.168.1.0 255.255.255.0
default-router 192.168.1.1 Master AP
dns-server 171.70.168.183 8.8.8.8 running PnP Cisco Cloud
domain-name cisco.com Agent Redirect Server
DMZ
Internet PnP Server uses
PnP Server self signed SSL
certificate
DHCP Request
DHCP server Device creates pre-defined cloud redirect server
responds with device name (devicehelper.cisco.com) and resolves for IP
IP, domain name and address
DNS server Device establishes HTTP request with device serial number (UDI)
communication with
Cloud Redirect Server Cloud redirect server
receives UDI and sends
APIC-EM IP address
PnP Agent initiates HTTP communication with HTTP PnP work request with device serial number (UDI)
the APIC-EM server and sends the device UDI
PnP Agent installs local trustpoint PnP Server receives UDI and
for the server SSL certificate sends server SSL certificate over
HTTPS PnP work request with device serial number (UDI) HTTP
PnP Agent initiates HTTPS communication
with the server and sends the device UDI
Master AP reboots and will PnP Server receives UDI and
run the controller sends ME controller configuration
configuration after it comes over HTTPS
back up BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 130
Cisco Mobility Express
Features
Evolution of Cisco Mobility Express JUL 2017
MAR 2017 8.5
8.4
FEB, 2016
8.3 MR1
AUG, 2016
8.3
Mobility
Express
Introduced
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 132
WLAN Support
Supports maximum of 16 WLANs.
WLAN Options:
• Open
• WPA2 Personal
• WPA2 Enterprise (External RADIUS, AP)
NOTE : AP indicates Master AP and the authentication is done by the Controller.
For Internal and External Splash Page, a number of Access Types are supported. They are as follows:
• Local User Account
• Web Consent
• Email Address
• RADIUS
• WPA2 Personal
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 133
Application Visibility and Control
Cisco Mobility Express can identify signatures of 1000+ applications. It runs
NBAR Engine 2 and Protocol Pack 14
As part of control action, applications can be:
• Drop
• Rate Limit
• Mark
For Mark, one can select DSCP as Platinum, Gold, Silver, Bronze or Custom. If custom
is selected, one has to specific he DSCP value. For Rate Limit, one can specify the
Average Rate and Burst Rate for the application.
Simplified workflow to create AVC profile and apply it to WLAN
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 134
CMX with Cisco Mobility Express
Cisco Mobility Express works
with both CMX On-Premise
deployment as well as CMX in
the Cloud
For CMX Cloud, one can open
an account a 60 Day trial
account at
https://cmxcisco.com/.
Use Presence for Analytics
and Connect for onboarding
Guests.
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 135
Site Survey
Cisco Mobility Express supports internal
DHCP server and operates without a
pingable gateway. This enables Site
Surveyor to take the Access Point powered
by a Battery Pack and a client device to
perform an active survey.
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 136
Configuring CMX connector on Mobility Express
Steps
1. Navigate to Advanced > CMX
2. Enable the CMX Status
3. Enter the CMX Server URL
4. Enter the CMX Server Token
5. Click on the Apply button
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 137
Cisco Mobility Express
Software Update
Software Update Methods
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 139
Cisco Mobility Express
Resiliency (Master Election)
Master Election Overview
Master Election is a mechanism to elect a new Cisco Mobility Express CAPABLE
Access Point to run the controller function incase of a failure
CAPABLE means AP Image type is MOBILITY EXPRESS IMAGE and AP
Configuration is MOBILITY EXPRESS CAPABLE
To have redundancy, you must have two or more Mobility Express capable Access
Points in your network
VRRP is used to detect the failure of Master AP which initiates the election of a new
Master. Failover typically takes 60-90s.
Master Election is based on priorities
1. User Defined Master
2. Next Preferred Master
3. Most Capable Access Point
4. Least Client Load
5. Lowest MAC Address
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 141
Electing a new Master Access Point
Master election process is based on a set of priorities. When an active Master Access Point fails, the
election process gets initiated and it elects the Access Point with the highest priority as the Master AP.
1. User Defined Master - User can select an Access Point to be the Master Access Point. If such a
selection is made, no new Master will be elected in case of a failure of the active Master. After five
minutes, if the current Master is still not active, it will be assumed dead and Master Election will begin
to elect a new Master.
2. Next Preferred Master – Admin can configure the Next Preferred Master from CLI. When this is
configured and the active Master AP fails, the one configured as the Next Preferred Master will be
elected as a Master.
3. Most Capable Access Point - If the first two priorities are not configured, Master AP election algorithm
will select the new Master based on the capability of the Access Point. For example, 3800 is the most
capable followed by 2800, 1850, 1830 and finally the 1815 Series. All 1815 Series Access Points have
the same capability.
4. Least Client Load – If here are multiple Access Points with the same capability i.e. multiple 3800
Access points, the one with least client load is elected as the Master Access Point.
5. Lowest MAC Address – If all of the Access Points are the same and have the same client load, then
Access Point with the lowest MAC will be elected as a Master.
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 142
Summary
• Cisco Mobility Express is virtual Wireless LAN Controller embedded on 11ac Wave 2 Access Points. No
need for a separate controller h/w
• Ideal for small to medium sites – supports up to 100 Access Points, 2000 Clients
• Simplicity is the motto – Quick and Easy to setup, Simple Controller WebUI even for advanced features,
Best Practices are enabled out of the box, Redundancy with Master Election, Manageability via PI.
References:
• Cisco Mobility Express- http://www.cisco.com/c/en/us/solutions/enterprise-networks/mobility-express/index.html
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 143
Cisco Wireless LAN Documentation
INSTALLATION GUIDES RADIO CONFIGURATION CLIENT ADDRESSING POLICY ENGINE
• 5520 WLC • 802.11r BSS Fast Transition • Bi-Directional Rate Limiting • AVC
• 8540 WLC • Adaptive wIPS • Flex AP-EoGRE Tunnel Gtwy • Bonjour
• AP1570 • ATF Ph 1 & 2 • IPv6 • Chromecast
• AP1810 OE • CleanAir • Jabber • Device Classification
• AP1810W Wall Plate • CMX FastLocate • Jabber and UCM • Domain Filtering
• AP1850 • High Density • Microsoft Lync • mDNS Gateway w/Chromecast
• AP2700/3700 • Rogue Management • Passpoint Configuration • Wireless Device Profiling & Policy Classification
• AP2800/3800 • RRM RF Grouping Algorithm • Real-Time Traffic Over WLAN BEST PRACTICES
• AP702W • RRM White Paper • VideoStream • Apple Devices
• APIC-EM Wireless AP PnP • Vocera IP Phone in WLAN • Enterprise Mobility Design Guide
ENCRYPTION
• Flex7500 WLC • VoWLAN Troubleshooting • High Availability (SSO)
• BYOD for FlexConnect
• Mesh APs • HyperLocation
• BYOD with ISE
• Mobility Express • iPhone 6 Roaming
• Security Integration
• Smart Licensing • N+1 High Availability
• Univ. AP Regulatory Domain • WLAN Express
• Virtual WLC • WLC Configuration Best Practices
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 144
Click - https://www.youtube.com/user/CiscoWLAN/
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
VoD Links
Faster Innovation
• Fastlane App Demo https://www.youtube.com/watch?v=N1QMUcv3aRQ
• Cisco CMX Solution https://www.youtube.com/watch?v=KQRb8vfU0qM
Cost & • Cisco Aironet AP-3800 RF Excellence • Wireless LAN Controller Dashboard Review
https://www.youtube.com/watch?v=dBpGsTKeyNM&t=64s https://www.youtube.com/watch?v=af09TBaafRI&feature=youtu.be
Complexity
• Digital Network Architecture with Wave2 with 802.11ac • Cisco Wireless Mobile App https://www.youtube.com/watch?v=HyvZ4mbVAWs
https://www.youtube.com/watch?v=ySjN13hPhXY&t=2s
• WLC Advanced UI Client Troubleshooting
• Cisco Aironet Series – Flexible Radio Assignment https://www.youtube.com/watch?v=dZVxI6jOx_Q
https://www.youtube.com/watch?v=K_-BykT_YIM
• ISE Simplified Wireless Setup
https://www.youtube.com/watch?v=A3F2DrFu7Lo&feature=youtu.be
• TechWiseTV: Apple and Cisco: Fast-Tracking the Mobile Enterprise
https://www.youtube.com/watch?v=bh8rEvrzm7Y&feature=youtu.be
Lower • Cisco Wireless TrustSec Demo
https://www.youtube.com/watch?v=A3F2DrFu7Lo&feature=youtu.be
• Prioritised Business Apps
https://www.youtube.com/watch?v=z0EOKNxL964&feature=youtu.be
Risk
• Cisco Wireless Netflow Lancope Integration Demo
https://www.youtube.com/watch?v=TuWYkrt94CQ
• Apple and Cisco: Three Solutions Coming Together
https://www.youtube.com/watch?v=7MgsDkf55wQ&feature=youtu.be
• OpenDNS Integration with WLC
https://www.youtube.com/watch?v=cMdX8sBBYG4
• WiFi Optimised Feature
https://www.youtube.com/watch?v=xgPfxAolJoQ&feature=youtu.be
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 146
Complete Your Online
Session Evaluation
• Give us your feedback to be
entered into a Daily Survey
Drawing. A daily winner will
receive a $750 gift card.
• Complete your session surveys
through the Cisco Live mobile
app or on www.CiscoLive.com/us.
© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public
Continue Your Education
• Demos in the Cisco campus
• Walk-in Self-Paced Labs
• Lunch & Learn
• Meet the Engineer 1:1 meetings
• Related sessions
BRKEWN-2016 © 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 148
Thank you