Professional Documents
Culture Documents
WAN Intranet
• Single site network • Distributed network • Simplified Campus/Branch • Data center hosted
• Low IT footprints • Highly scalable • Consistent Wired/Wireless controller
• SP hotspots • Best in class for distributed • Common OS • Distributed enterprises
networks Aironet Access Points
• Virtual controller function 11ac Wave2 : 3800/2800/1800
• Controllers • Controllers
• Controllers
11ac: 3700/2700/1700
on AP • New 8540 Controller • Integrated • New 8540 Controller
11n: 3600/ 2600/ 1600/ 700i/700w
• 11ac: 1800/2800/3800 • New 5520 Controller 3650/3850/Sup 8E • New 5520 Controller
• or other Cisco Wireless • or other Cisco Wireless
Controllers Controllers
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Wi-Fi Connectivity Speed Timeline
Gigabit Wi-Fi As Primary Access
4
Spatial 4SS Desktops
Stream
s
3SS Desktops / Laptops
5260** 3
Spatial
Streams 2SS Laptops / Tablets
3500** 3500** 2
Spatial 1SS Tablets / Smartphones
Stream
2340**
1730**
1300* = Connect Rates (Mbps)
1
Spatial
600* Stream
870* SS = Spatial Streams
450
Multi-Gigabit
Uplinks
*Assuming 80 MHz channel is available
2 Gigabit
Ethernet
Uplinks
54
Ethernet
65 and suitable
Gigabit
Uplink
24 **Assuming 160 MHz channel is
2 11
802.11ac 802.11ac Dual available and suitable
802.11 802.11b 802.11a/g 802.11n 5GHz
Wave 1 Wave 2
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
New
Next-Generation Wave 2 802.11ac Access Points
Advantages
• Layer-3 roaming within the branch
• Cookie cutter configuration for every branch site
Remote Site C
Remote Site A
Remote Site B
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Branch Office Deployment Central Site
FlexConnect (HREAP)
Centralized
• Hybrid architecture Traffic
Centralized
Traffic
• Single management and control point
• Data Traffic Switching
• Centralized traffic
(split MAC) or
• Local traffic (local MAC)
WAN
• Standalone Mode will preserve local traffic
only
• Traffic Switching is configured per AP
and per WLAN (SSID)
Remote Office
Local
Traffic
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
FlexConnect Glossary
Connected Mode When FlexConnect AP can reach Controller, it gets help from controller to complete client
authentication.
Standalone Mode When FlexConnect AP cannot reach Controller, it goes into standalone state and does client
authentication by itself.
Local Switching Data traffic switched onto local VLANs for an SSID
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Configure FlexConnect Mode
Step 1: Configure Access Point Mode
• Enable FlexConnect mode per AP
• Supported APs:
AP-1040, AP-1130, AP-1140, AP-1240, AP-
1250, AP-1260, AP-1520, AP-1530, AP-
1550, AP-1570, AP-1600, AP-1700, AP-
1800, AP-2600, AP-2700, AP-2800, AP-
3500, AP-3600, AP-3700, AP-3800
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Configure FlexConnect Local Switching
Step 2: Enable Local Switching per WLAN
Only WLAN with “FlexConnect Local Switching” enabled will allow local
switching on the FlexConnect AP
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Configure FlexConnect VLAN Mapping
Step 3: FlexConnect Specific Configuration – VLAN Support
• FlexConnect AP can be connected on an access port or connected to a 802.1Q
trunk port (using the native VLAN)
• VLAN mapping can be performed per AP configuration on WLC and/or by AP
groups using Cisco Prime Infrastructure templates
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Configure FlexConnect VLAN Mapping
Step 4: FlexConnect Specific Configuration – Native Vlan
• When connecting with Native VLAN on AP, L2 switchport must also match with
corresponding Native VLAN configuration
• Each corresponding SSID that is allowed to be locally switch should be allowed
on the corresponding switchport.
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Configure FlexConnect SSID-VLAN Mapping
Step 5: Per AP SSID to VLAN Mapping
• Mapping of SSID to 802.1Q VLAN is done per FlexConnect AP
• Or use Cisco Prime Infrastructure (NCS) via configuration templates
1 2
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Configure FlexConnect VLAN Mapping
Using Cisco Prime Infrastructure
• Prime Infrastructure provides simplified configuration to all FlexConnect APs
with one Lightweight AP Template
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Evaluate FlexConnect Architectural
Requirements
FlexConnect Design Considerations For Your
Reference
Deployment WAN Bandwidth WAN RTT Max APs per Max Clients per
Type (Min) Latency (Max) Branch Branch
It is highly recommended that the minimum bandwidth restriction remains 24 Kbps per AP with the round trip
latency no greater than 300 ms for data deployments and 100 ms for data + voice deployments.
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
FlexConnect Design Considerations
Feature Limitations in Standalone mode and Local Switching
• MAC/Web Auth in Standalone Mode
• IPv6 Mobility
• SXP TrustSec
• Service Discovery Gateway
• Native Profiling and Policy Classification
• See full list in « FlexConnect Feature Matrix »
• http://www.cisco.com/en/US/products/ps6366/products_tech_note09186a0080b3690b.s
html
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
IPv6 Support
✔
✔
✔
✔
✔
✔
✔
✔
✔
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Economies of Scale For Lean Branches
Flex 7500 Wireless Controller
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Optimized for High Scale Deployments
Cisco 8540 Series Controller Functionality
Access Points 6,000
Key Differentiation Clients 64,000
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
For Your
FlexConnect Feature Introduction Reference
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Why do we need FlexConnect & AP
Groups?
Understanding AP Groups
Overview AP Group 1 Central Site
Flex 7500
• AP Groups is a logical concept of
grouping AP’s which deliver similar Wi-Fi
services; these services can be:
• By physical location, and/or
• By functional services
(data, voice, guest, etc..)
• Same AP groups need to be defined in all Remote Site A WAN Remote Site B
7510/8510
Scaling CT-5508 WiSM-2 CT-2504
/8540
# WLAN
512 512 512 16
(SSID)
# VLAN AP Group 2
4095 512 512 16
(Interfaces)
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
AP Groups
Configuration: Create a New Group
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
AP Groups Usage @ Internet
VLAN-2
• AP groups give the ability to statically
map Wi-Fi service (WLAN) to VLAN
based on physical location VLAN-3
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Understanding FlexConnect Groups
Central Site
Flex 7500
Overview Cluster
7510/
Scaling 8510/ CT-5508 WiSM2 CT-2504
8540
FlexConnect
2000 100 100 30
Groups
AP per Group 100 25 25 25 FlexConnect Group 1 FlexConnect Group 2
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
FlexConnect Groups and CCKM/OKC Keys
Overview Central Site CCKM Keys
RADIUS Server
• If a FlexConnect AP boots up
in standalone mode, it will not get the OKC/CCKM
keys from the WLC
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
FlexConnect Groups Creation
Step 1: Add a New FlexConnect Group
1
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
For Your
Reference
FlexConnect Groups Template on PI
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
For Your
Reference
FlexConnect Groups Template on PI
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
Designing a Resilient Wireless
Branch Network
FlexConnect Backup Scenario
Central Site
WAN Failure
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
FlexConnect Backup Scenario
Central Site
WLC Failure scenario with N+1 HA
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
FlexConnect Backup Scenario
WLC failure scenario with SSO Central Site
Standby
Active
• HA considerations:
• No impact for locally switched SSIDs
• Disconnection of centrally switched SSIDs WAN
clients with AP SSO
• No/minimal impact for centrally switched client
with Client SSO (7.5 and above)
• FlexConnect AP will NOT transition to Application
Standalone because SSO kicks in Server
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
FlexConnect Group : Backup Scenario
Central Site
Local Backup RADIUS
Central
• Normal authentication is done centrally RADIUS
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Local Authentication
Central Site
• By default FlexConnect AP
authenticates clients through central WAN
controller Local
RADIUS
Remote Site
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Local Authentication
Configuration
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
FlexConnect Group: Backup Scenario
Central Site
Local Backup Authentication
Central
• Normal authentication is done centrally RADIUS
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Designing Secure & BYOD Enabled
Branch Network
FlexConnect Peer-to-peer Blocking
Starting
Local Switching Peer-to-peer Blocking from 7.2
Central Site
Overview
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Local Switching Peer-to-peer Blocking
Configuration
* Central Switching WLAN will support “Forward - UpStream” and will send the packet to the next upstream
node connected to WLC
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
FlexConnect AAA VLAN & QoS
Override
Starting
from 7.2
FlexConnect AAA VLAN Override
Description RADIUS Central Site
FlexConnect Group
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
For Your
FlexConnect AAA VLAN Override Reference
Configuration
IETF 65
IETF 64
IETF 81
WAN
ISE
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
VLAN Based Central Switching Central
VLAN 3
Go to Default
VLAN ID
Overview Central
RADIUS
VLAN 7
• While doing AAA VLAN Override with VLAN 3 does not
local switching : VLAN 7 Exist on this
WLC
• If VLAN ID does not exist at the AP,
the traffic is central switched to the WAN
central VLAN ID
Remote Site
• If the central VLAN ID does not exist,
the traffic is centrally switched to the
default VLAN ID of the WLAN
VLAN 7 VLAN 7
does not
VLAN 3 Exist on
does not this AP
Exist on
this AP
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Starting
from 7.5
FlexConnect AAA QoS Override
Description
Vendor ID/Vendor Type Attribute
Dynamically assign QoS levels and/or
bandwidth contracts for local switching, [14179\002] Aire-QoS-Level
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
AAA Override Deployment Scenario
Problem Statement
Central Site
VLAN 20
WAN
Application
Server
Function VLAN ID
Engineering 11
Marketing 21
Function VLAN ID Sales 31
Engineering 10 Application
Server
Marketing 20
Sales 30 VLAN 20
Remote Site A Remote Site B does not
exist
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Starting
VLAN Name Mapping at FlexConnect Group from 8.1
Remote Site B
Remote Site A
VLAN ID
VLAN ID
11
10 21
20 31
30
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Starting
from 8.1
VLAN Name AAA Override - Solution
Central Site
Aire-Interface-Name or
IETF Tunnel-Private-Group-ID
VLAN NAME=
Marketing
WAN
Application
Server
Remote Site Remote Site VLAN Name VLAN ID
VLAN 20 Engineering 11
Marketing 21
VLAN Name VLAN ID Sales 31
Engineering 10
Marketing 20
Sales 30
Remote Site A VLAN 21 Remote Site B
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
FlexConnect ACL VLAN Mapping &
Per-Client ACL
Starting
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
FlexConnect Access Lists
Configuration – Create FlexConnect ACL
• FlexConnect ACL rule creation is similar to rule creation for Local Mode AP
1
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
FlexConnect ACL – VLAN Mapping
Configuration – FlexConnect ACL per AP 2
• FlexConnect ACL can be applied per AP
using VLAN Mappings configuration
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
FlexConnect ACL – VLAN Mapping
Configuration –FlexConnect ACL per FlexConnect Group
• FlexConnect ACL can be applied per FlexConnect Groups per VLAN in the ACL
Mapping tab.
1 2
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
FlexConnect Split Tunneling
(Using FlexConnect Split ACL)
Starting
Overview
• Split tunneling allow some traffic to be locally switched although the WLAN is defined as centrally
switched
• Split tunneling is using a NAT/PAT feature with ACL to perform the local switching
• Split tunneling is using the AP IP@ for the NAT/PAT feature
NAT/PAT WAN
ACL
Central Server
Local Traffic
Local Printer
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
FlexConnect ACL – Split Tunneling
Configuration
• Create a centrally switched WLAN
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
FlexConnect ACL – Split Tunneling
Configuration – Per Access Point
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
FlexConnect ACL – Split Tunneling
Configuration – Per FlexConnect Group
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Deploying BYOD with FlexConnect
Local Switching
(Using FlexConnect WebPolicies
ACL)
Bring Your Own Device(s) : The New Normal
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
BYOD Device On-Boarding in FlexConnect Starting
from 7.4
Example: Apple iOS Device Provisioning
Device Provisioning
Wizard
2
Client
Reconnects
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
FlexConnect Web Policy ACL
Configure Web Policy ACL per FlexConnect AP
• ACL Mapping can be configured per FlexConnect AP
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
FlexConnect Web Policy ACL
Configure Web Policy ACL per FlexConnect Group
• Use ACL Mapping tab in FlexConnect Group configuration
• WebPolicies ACL are not the same as VLAN ACL or WebAuthentication ACL.
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
Cisco Wireless Central DHCP Processing
Configuration
• To support DHCP Profiling Probe with FlexConnect, DHCP request must be
sent to WLC. This is done by the « Central DHCP Processing » configuration.
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
Deploying BYOD with FlexConnect Wireless
Summary – 802.1x/EAP Authentication ISE
DHCP Server
FlexConnect AP
CAPWAP WLC
Web Server
WAN
WiFi Association
802.1x/EAP Response
Inside CAPWAP
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
Deploying BYOD with FlexConnect Wireless
Summary – DHCP Request ISE
DHCP Server
FlexConnect AP
CAPWAP WLC
Web Server
WAN
DHCP Request
Inside CAPWAP
Device is
RADIUS-Accounting an iPad
• host-name=MyiPad
• dhcp-class-identifier=APPLE
DHCP Lease
Inside CAPWAP
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
Deploying BYOD with FlexConnect Wireless
Summary – URL-Redirect ISE
DHCP Server
FlexConnect AP
CAPWAP WLC
Web Server
WAN
URL-Redirect
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Deploying BYOD with FlexConnect Wireless
Summary – Registration & Provisioning ISE
DHCP Server
FlexConnect AP
CAPWAP WLC
Web Server
WAN
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Deploying BYOD with FlexConnect Wireless
Summary – Device Access ISE
DHCP Server
FlexConnect AP
CAPWAP WLC
Web Server
WAN
DHCP Request/Response
Inside CAPWAP
Web Traffic
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
Summary of FlexConnect ACLs
-
80
BRKEWN-2016 80
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public
Service-Ready Branch
FlexConnect VideoStream
Video Multicast Delivery Challenges
Technical Challenges 802.11
Data Rates
• Multicast packets (UDP) are sent as
1
broadcast packets over the air per 802.11
standard 2
5.5
• Broadcast packets do not use error
correction: “fire and forget” 6
9
• Broadcast packets are sent at data rate B/G 11
Video Impact
mandatory to all clients connected to the
WLAN 12
• Choppy, Unreliable Video
18
1 Mb for B/G (400K actual) • Video Stream does not utilize 802.11n/ac
24
6 Mb for A (2.7 Mb actual) High Throughput data rates
36
48
• Heavy utilization of channel due to high
rate of very slow packets
54
M0 • Video delivery is not reliable causing poor
Quality of Experience
N M1
...
Video M14
Server Default 802.11B/G M15
mandatory data rates
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
Starting
from 8.0
Video Multicast Delivery Solution
802.11
Technical Solution Data Rates Video Impact
1
N M1
...
Video M14
Server M15
Default 802.11B/G
mandatory data rates
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
FlexConnect VideoStream Configuration
Enable VideoStream - Global
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
FlexConnect VideoStream Configuration
Add Stream Configuration
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
FlexConnect VideoStream Configuration
Enable VideoStream - WLAN
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
FlexConnect VideoStream Monitoring
Controller
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 88
FlexConnect Bridge Mode Support
Starting
FlexConnect on Mesh APs from 8.0
Centralized
Traffic
Failover Considerations
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
For Your
AP Modes Feature Comparison Reference
Feature\AP Mode Local Mode Bridge Mode Flexconnect Mode Flex+Bridge Mode
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
FlexConnect Bridge Mode Configuration
Wireless Access Points AP_NAME General
AP will reboot
upon change
Same options
as an AP in Flex
Mode
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 93
FlexConnect Application Visibility
and Control
How AVC solution works
AireOS 8.1 App Visibility & AireOS 8.1
User Experience Report
App BW Transaction …
Time
WebEx 3 Mb 150 ms …
Citrix 10 Mb 500 ms …
Static
Netflow
AP
NBAR on AP
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 95
AVC on FlexConnect APs
Katana
Gen2 AP
WAN
Gen2 AP
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 96
AVC for FlexConnect APs
AP Functionality
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
AVC Configuration on Local Switching WLAN
WLAN AVC
Configuration
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 98
AVC Configuration per FlexConnect Group
• FlexConnect Group specific AVC configuration takes precedence over WLAN AVC config
• No AP Specific AVC configuration.
• WLAN AVC configuration will be pushed to Flex APs where WLAN is broadcast
Enable/disable, Profile,
Monitor per WLAN
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
FlexConnect AVC Profiles
Can be associated under WLAN and/or FlexConnect Group
FlexConnect AVC
profiles
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 100
FlexConnect AVC Applications
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 101
Monitoring AVC Statistics per FlexConnect Group
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 102
Operating the Wireless Branch
Branch Office Provisioning
Network Plug-N-Play – Simple, Secure, Scalable
Today’s Process Business
Network Challenges
Direct Costs
Central Staging Facility
Ships • Shipping after Configuring device
Pre Provision
1• Travel
equipment costs for IT installer
Projects/Sites
• Install OS
• Install Config
• Prime device Network Admin
Network Complexity
Reseller/Partner Admin
• Config errors
• Different products / processes
2 Install & Power-on 3 Monitor device
devices installation
Security
• 3rd party not secure
Installer
Installer
Network Admin
Time/Productivity
Site-1 Site-2 Site-3
• Manual process
Site(s)
• Shipping , Storage, Travel
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 105
Network PnP Discovery Options
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 106
Use Case : Branch Deployment for On-Prem PnP Server
APIC-EM
/PnP PnP Server/Site Updates
Step 1 Server
New devices PID Serial # Hostname WLC IP address
contact PnP
Pre Provision Site in APIC EM Server to get
AIR-CAP3702I-A-K9 RFD0PP2T025 AP-Store1-1 192.168.15.1
• Serial Number based match rule provisioned ISR-2951 FOX23zxcb ISR-bakcup 192.168.15.2
• MAC Addressed based match C3850 FOC123dfg Dist1 192.168.16.3
• Config
C3560C FOC443asd ACC-sw1 192.168.16.4
• Installer User ID
C3560C FOC443asa ACC-sw2 192.168.16.5
Challenges:
• Provisioning of branch offices quickly and easily
Solution:
WLC IP (Prim/Sec/Ter)
• Pre-Provision the AP details from a central Service (PnP)
Installer AP Name
AP Mode (Flex/Local)
AP Group Name
Flex Group Name – Coming 8.3 BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 107
Branch Office Upgrade over WAN
Upgrading a FlexConnect Deployment
Concerns
• Sites using FlexConnect AP are usually sites with low WAN bandwidth
• Each site may have small number of AP, but an enterprise may have a lot of
branches
• Upgrading ~6000 AP through a low bandwidth WAN is a challenge :
• Time needed to download all the AP firmware
• Exhaust of the WAN link
• Risk of failures during the download
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 109
Starting
from 7.2
FlexConnect Smart AP Image Upgrade
Firmware Image
Overview
Old
New
New
Cisco Prime Old
New Primary Secondary
• Smart AP Image Upgrade use a « master »
AP in each FlexConnect Group to download Wireless LAN
the code. Central Site Controller
Master AP
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 111
FlexConnect Smart AP Image Upgrade
Configuration
Master AP Selection is
Optional
• “FlexConnect AP Upgrade” checkbox has to be enabled for each FlexConnect Group.
• By default, Master AP for each FlexConnect Group is selected using Lower-MAC algorithm.
• One Master select per AP type.
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 112
FlexConnect
() Smart AP Image Upgrade
Configuration contd.
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 113
Bringing All Together – FlexConnect
Best Practices
FlexConnect Best Practices
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 115
Summary
• Cisco Unified Wireless Network based on Controllers deliver Wireless Branch Solution
• FlexConnect is the feature designed to solve remote connectivity and WAN constraints
• Several Failover Scenario are targeted to offer Survivability of Small Remote Sites
References:
• Wireless LAN Controller Scale Comparison
Guidehttp://www.cisco.com/en/US/products/hw/wireless/products_category_buyers_guide.html#controllers
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 116
Complete Your Online Session Evaluation
• Give us your feedback to be
entered into a Daily Survey
Drawing. A daily winner will
receive a $750 Amazon gift card.
• Complete your session surveys
through the Cisco Live mobile
app or from the Session Catalog
on CiscoLive.com/us.
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 117
Continue Your Education
• Demos in the Cisco campus
• Walk-in Self-Paced Labs
• Lunch & Learn
• Meet the Engineer 1:1 meetings
• Related sessions
BRKEWN-2016 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 118
Thank you