Professional Documents
Culture Documents
Branch Office
Wireless LAN Design
#CLUS
Cisco Webex Teams
Questions?
Use Cisco Webex Teams (formerly Cisco Spark)
to chat with the speaker after the session
How
1 Find this session in the Cisco Live Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Agenda
Wireless LAN Controller and Access Point Portfolio
Branch Deployment Options
Evaluate FlexConnect Requirements and identify need for AP Groups &
FlexConnect AP Groups
Design a Resilient, Secure, and BYOD enabled Branch Network
Design a Service-Ready Branch
Provision and Operate Wireless Branch over WAN
Deploying Branch Offices using Cisco Mobility Express
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Intent Based Infrastructure - Wireless LAN
Controller Portfolio
Multiple Deployment options & SD-Access Wireless Ready
SD-Access Wireless Ready
Branch Deployment Campus Deployment
Cisco 8540
6000 APs
Cisco 5520 64,000 clients,
1500 APs 40 Gbps
20,000 Clients, 20
Cisco 3504 Gbps
150 APs
3000 Clients,
Mobility Express 4 Gbps
Cisco vWLC**
100 Aps 3000 APs
2000 Clients 32000 Clients
Flexconnect mode
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
The industry’s most comprehensive and
innovative access point portfolio
The best infrastructure leads to the best outcomes
Good - Enterprise class Better Best in class
Ideal for small to medium-sized deployments Mission critical High density
NEW
1 Future availability 2 Available for high-powered only 3 Available for wall plate and teleworker only 4 Available for teleworker only
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Designed to be DNA Ready
Industry’s Most Comprehensive Outdoor AP
Portfolio
1540 1560 1570
New*
802.11ac Wave 2
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Unified Wireless Deployment Options
BRANCH BRANCH CAMPUS
Mobility Express Flex Connect Centralized
WAN INTRANET
• Single/Multi site networks
• Low IT footprints
DNA Center
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Designing Branch offices
using Local Wireless
LAN Controller
Branch Office with Local WLAN Controller
Central Site
Backup WLC
CAPWAP
• Cookie cutter configuration for every branch site
WAN • Layer-3 roaming with controller in each branch
• Full local control, no dependency on WAN
` ` ` ` ` `
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Designing Branch offices
using FlexConnect
Branch Office Deployment
Central Site
FlexConnect Centralized
Traffic Centralized
• Hybrid architecture Traffic
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Configuring
FlexConnect Local
Switching
Steps to configure FlexConnect Local Switching
STEP 01
STEP 02
Enable WLAN for Local
• Enable FlexConnect Local Switching on WLAN
Switching
STEP 03
Create WLAN to • Configure Native VLAN on FlexConnect AP
VLAN mapping • Configure WLAN-VLAN Mapping
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Configure FlexConnect mode on Access Point
STEP 01
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Configure FlexConnect Local Switching on WLAN
STEP 02
Enable WLAN for Local Switching
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Configure Native VLAN on FlexConnect AP
STEP 03a
Configure Native VLAN on FlexConnect AP
When connecting with Native VLAN on AP, L2 switch port must
also match with corresponding Native VLAN configuration on the
AP
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Configure WLAN to VLAN Mapping
STEP 03b
Configure WLAN-VLAN mapping
Mapping of WLAN to VLAN can be done per FlexConnect AP or
FlexConnect Group. Also VLAN must be configured on switch port
1 2
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Configure FlexConnect VLAN Mapping
Using Cisco Prime Infrastructure
• Prime Infrastructure provides simplified configuration to all FlexConnect APs with one
Lightweight AP Template
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Evaluate FlexConnect
Architectural
Requirements
For Your
Flex Connect Design Considerations Reference
It is highly recommended that the minimum bandwidth restriction remains 24 Kbps per AP with the round trip
C and 100 ms for Data + Voice deployments.
latency no greater than 300 ms for data deployments
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
For Your
Flex Connect Design Considerations Reference
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
IPv6 Support
✔
✔
✔
✔
✔
✔
✔
✔
✔
Significant support for IPv6 with Central Switching
IPv6 RA Guard and IPv6 Bridging fully supported with Local Switching
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Why do we need AP
and FlexConnect
Groups?
Understanding AP Groups
AP Group 2
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
AP Groups
Configuration: Create a New Group
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
AP Groups Use Case - SSID AP Group 1
@ Internet
Guest-Access
Central Site
Per Location SSID
Corporate-Voice
location
Users see the same Corporate-Data
Wi-Fi service on all sites. WAN
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Understanding FlexConnect Groups
Central Site
WLC5520
Overview
FlexConnect AVC
Smart Image Upgrade
FlexConnect
2000 1500 100
Groups
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect Groups and CCKM/OKC Keys
RADIUS Server
If a FlexConnect AP boots up
in standalone mode, it will not get the
OKC/CCKM keys from the WLC
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect Groups Creation
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect Groups Template on PI For Your
Reference
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect Groups Template on PI For Your
Reference
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Designing a Resilient
Wireless Branch
Network
FlexConnect Resiliency - WAN Failure
Central Site
WAN Failure
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect Resiliency – N+1 HA Scenario
Central Site
WLC Failure scenario with N+1 HA
Secondary Primary
WLC WLC
FlexConnect APs will go to Standalone mode
No impact for locally switched SSIDs
Disconnection of centrally switched SSIDs
clients
WAN
CCKM roaming allowed in FlexConnect group
Remote Site
FlexConnect AP will then search
for backup WLC; when backup WLC is found,
FlexConnect AP will resync with WLC and Application
Server
resume client sessions with central traffic
Client sessions with Local Traffic are not
impacted during resync with Backup WLC
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect Resiliency – SSO HA Scenario
Active
True Box to box High Availability i.e. 1:1. Sub-
second failover to StandBy WLC
Configuration(AP database, Client Run state etc.)
information on Active is synched to Standby WLC
FlexConnect AP will NOT transition to Standalone WAN
because SSO kicks in
AP will continue to be in Connected mode with the
Standby (now Active) WLC Application
Server
Centrally Switched SSID will never go down
Remote Office
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect – AAA Survivability
Local Backup RADIUS
Central
Normal authentication is done centrally RADIUS
FlexConnect Group
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect - Local Authentication
Central Site
FlexConnect Group
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect - Local Authentication
Configuration
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect Group: Local EAP Authentication
Local Backup Authentication Central Site
Central
Normal authentication is done centrally RADIUS
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Designing Secure &
BYOD Enabled Branch
Network
FlexConnect Peer-to-
peer Blocking
Local Switching Peer-to-peer Blocking Starting
from 7.2
Central Site
Overview
Application
For P2P blocking inter-AP use ACL Server
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Local Switching Peer-to-peer Blocking
Configuration
* Central Switching WLAN will support “Forward - UpStream” and will send the packet to the next upstream
node connected to WLC
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect AAA VLAN
& QoS Override
FlexConnect AAA VLAN Override Starting
from 7.2
FlexConnect Group
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect AAA VLAN Override For Your
Reference
Configuration IETF 65
IETF 64
IETF 81
WAN
ISE
Create Sub-Interface on
FlexConnect AP
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
VLAN Based Central Switching Central
Go to Default
VLAN ID
VLAN 3
Overview Central
RADIUS
VLAN 7
• While doing AAA VLAN Override with VLAN 3 does not
local switching: VLAN 7 Exist on this
WLC
• If VLAN ID does not exist at the AP, the
traffic is central switched to the central WAN
VLAN ID
• If the central VLAN ID does not exist, the Remote Site
VLAN 7
does not
VLAN 3 Exist on
does not this AP
Exist on
this AP
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect AAA QoS Override Starting
from 7.5
Description
[14179\0010] Aire-Real-Time-Bandwidth-
Burst-Contract
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
AAA Override Deployment Scenario - VLAN Name
Problem Statement – Map clients to specific vlans based on their function
Central Site
VLAN 20
WAN
Application
Server
Function VLAN ID
Engineering 11
Marketing 21
Function VLAN ID Sales 31
Engineering 10 Application
Server
Marketing 20
Sales 30
VLAN 20
Remote Site A Remote Site B does not
exist
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
VLAN Name Mapping at FlexConnect Group Starting
from 8.1
Remote Site B
Remote Site A
VLAN ID
VLAN ID
11
10 21
20 31
30
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
VLAN Name AAA Override - Solution Starting
from 8.1
Central Site
Aire-Interface-Name or
IETF Tunnel-Private-Group-ID
VLAN NAME=
Marketing
WAN
Application
Server
Remote Site Remote Site VLAN Name VLAN ID
VLAN 20 Engineering 11
Marketing 21
VLAN Name VLAN ID Sales 31
Engineering 10
Marketing 20
Sales 30
Remote Site A VLAN 21 Remote Site B
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect ACL VLAN
Mapping
FlexConnect ACL – VLAN Mapping
Overview Central Site
• FlexConnect ACL rule creation is similar to rule creation for Local Mode AP
3
2
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect ACL – VLAN Mapping
Configuration – FlexConnect ACL per AP
2
• FlexConnect ACL can be applied per AP using
VLAN Mappings configuration
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect ACL – VLAN Mapping
Configuration – FlexConnect ACL per FlexConnect Group
• FlexConnect ACL can be applied per FlexConnect Groups per VLAN in the ACL Mapping tab.
1 2
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect Split
Tunneling
(Using FlexConnect
Split ACL)
FlexConnect ACL – Split Tunneling Starting
from 7.3
Overview
Split tunneling allow some traffic to be locally switched although the WLAN is defined
as centrally switched
Split tunneling is using a NAT/PAT feature with ACL to perform the local switching
NAT/PAT WAN
ACL
Central Server
Local Traffic
Local Printer
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect ACL – Split Tunneling
Configuration
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect ACL – Split Tunneling
Configuration – Per Access Point
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect ACL – Split Tunneling
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Deploying BYOD with
FlexConnect Local
Switching
(Using FlexConnect
WebPolicies ACL)
Bring Your Own Device(s) : The New Normal
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
BYOD - Device On-boarding in FlexConnect
Example: Apple iOS Device Provisioning
2
Device Provisioning
Wizard Client
Reconnects
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect Access Lists fo BYOD
Create FlexConnect ACL
3
2
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect Web Policy ACL
Configure Web Policy ACL per FlexConnect AP
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect Web Policy ACL
Configure Web Policy ACL per FlexConnect Group
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Wireless Central DHCP Processing
Configuration
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Deploying BYOD with FlexConnect Wireless ISE
802.1x/EAP Authentication
DHCP Server
FlexConnect AP
CAPWAP WLC
Web Server
WAN
WiFi Association
Unknown Device,
Redirect to registration
802.1x/EAP Request Radius Access-Request
Inside CAPWAP
Radius Access-Response
• Access-Type: Access-Accept
• URL-Redirect-ACL=FlexACLWebPolicy,
URL + ACL Redirect • URL-Redirect=http://……)
Inside CAPWAP
802.1x/EAP Response
Inside CAPWAP
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Deploying BYOD with FlexConnect Wireless ISE
DHCP Request
DHCP Server
FlexConnect AP
CAPWAP WLC
Web Server
WAN
DHCP Request
Inside CAPWAP
Device is
RADIUS-Accounting
an iPad
• host-name=MyiPad
• dhcp-class-identifier=APPLE
DHCP Lease
Inside CAPWAP
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Deploying BYOD with FlexConnect Wireless ISE
URL-Redirect
DHCP Server
FlexConnect AP
CAPWAP WLC
Web Server
WAN
URL-Redirect
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Deploying BYOD with FlexConnect Wireless ISE
Registration & Provisioning
DHCP Server
FlexConnect AP
CAPWAP WLC
Web Server
WAN
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Deploying BYOD with FlexConnect Wireless ISE
Summary – Device Access
DHCP Server
FlexConnect AP
CAPWAP WLC
Web Server
WAN
DHCP Request/Response
Inside CAPWAP
Web Traffic
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Summary of FlexConnect ACLs
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Wireless TrustSec
Support
Starting
5 Employee
6 Voice A B
7 Partner
Local NO NO YES
Topology, location independent
Flex YES YES YES
Policy (SGT) stays with endpoint.
Simplifies ACL management traffic Mesh NO NO YES (Indoor only)
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Service-Ready Branch
Application Visibility and Control
Video Stream
FlexConnect Application
Visibility and Control
How AVC solution works on wireless?
AireOS 8.1 App Visibility & AireOS 8.1
User Experience Report
App BW Transaction …
Time
WebEx 3 Mb 150 ms …
Citrix 10 Mb 500 ms …
Static
Netflow
AP
NBAR on AP
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
AVC on FlexConnect APs
Katana
Gen2 AP, NBAR Engine 23, PP 14
WAN
Gen2 AP
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
AVC for FlexConnect APs
AP Functionality
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
AVC Configuration on Local Switching WLAN
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
AVC Configuration per FlexConnect Group
• FlexConnect Group specific AVC configuration takes precedence over WLAN AVC config
• WLAN AVC configuration will be pushed to Flex APs where WLAN is broadcast
Enable/disable, Profile,
Monitor per WLAN
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect AVC Profiles
Can be associated under WLAN and/or
FlexConnect Group
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect AVC Applications
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Monitoring AVC Statistics per FlexConnect Group
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect
VideoStream
Video Multicast Delivery Challenges
Technical Challenges 802.11
• Multicast packets (UDP) are sent as
Data Rates
broadcast packets over the air per 802.11 1
standard 2
802.11
Technical Solution Data Rates Video Impact
1
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect VideoStream Configuration
Add Stream Configuration
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect VideoStream Configuration
Enable VideoStream - WLAN
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect VideoStream Monitoring
Controller
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect Bridge
Mode Support
FlexConnect on Mesh APs Starting
from 8.0
Centralized
Traffic
FlexConnect on Mesh APs
Failover Considerations
AP SSO is supported for the RAP only. N+1
Recommended WAN
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
AP Modes Feature Comparison
For Your
Reference
Feature\AP Mode Local Mode Bridge Mode Flexconnect Mode Flex+Bridge Mode
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect Bridge Mode Configuration
Wireless Access Points AP_NAME General
AP will reboot
upon change
Same options
as an AP in Flex
Mode
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Operating the Wireless
Branch
Branch Office Provisioning
Branch Office Upgrade over WAN
Branch Office
Provisioning
Network Plug-N-Play – Simple, Secure, Scalable
Today’s Process NetworkChallenges
Business
Central Staging Facility Direct Costs
1• Shipping after Configuring device
Ships Pre Provision
equipment Projects/Sites
• Install OS • Travel costs for IT installer
• Install Config
• Prime device Network Admin
Network
Reseller/Partner Admin Complexity
• Config errors
2
• Different products
Install & Power-on 3
/ processes
Monitor device
devices installation
Security
Installer • 3rd party not secure
Installer
Network Admin
DNS Lookup
02
pnpserver.localdomain ---- e.g.172.19.45.222 (PnP Server)
DNS
Server
CAPWAP
03
CAPWAP based WLC discovery for AP
CAPWAP
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Branch Provisioning with PnP Server
PID Serial # Hostname WLC IP a ddress A P Mode Flex Group name
PnP Server
Places AP in appropriate flexgroup
Apply relevant flex configs to AP
Day 0
Network Admin
Network Admin pre Remote Installer on branch
Day 1
provisions branch • Mount and cable devices
APs in PnP server. • Power-on
WLC IP (Prim/Sec/Ter)
AP Name
AP Mode (Flex) * Resources required for PnP:
AP Group Name Installer 64 Gb RAM, 500 Gb Storage
Flex Group Name Scale: 10,000 devices
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Branch Office Upgrade
over WAN
Upgrading a FlexConnect Deployment
Concerns
Sites using FlexConnect AP are usually sites with low WAN bandwidth
Each site may have small number of AP, but an enterprise may have a lot of branches
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect Smart AP Image Upgrade Starting
from 7.2
Firmware Image
Master AP
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect Smart AP Image Upgrade
Firmware Image
Master AP Selection is
Optional
• “FlexConnect AP Upgrade” checkbox has to be enabled for each FlexConnect Group.
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
FlexConnect Smart AP Image Upgrade
Configuration contd.
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Bringing All Together –
FlexConnect Best
Practices
FlexConnect Best Practices
Enable FlexConnect Groups
Enable FlexConnect Groups
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Summary
• Cisco Unified Wireless Network based on Controllers deliver Wireless Branch Solution
• FlexConnect is the feature designed to solve remote connectivity and WAN constraints
• Several Failover Scenario are targeted to offer Survivability of Small Remote Sites
References:
• Wireless LAN Controller Scale Comparison Guide - http://www.cisco.com/c/en/us/products/wireless/wireless-
lan-controller/product-comparison.html
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Wireless Branch
Deployment
Cisco Mobility Express
Cisco Mobility Express: Simple by Design
Controller Function embedded into the access point
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Mobility Express WLAN Deployment
Branch solution for small, medium or distributed enterprise with multiple management options
Controller Based in
Mobility Express Mobility Express Mobility Express in Branch campus
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Positioning Cisco Mobility Express
Small/Midsize
K-12 Education Hospitality Retail offices
Use innovative learning Connect to customers Accept mobile Provide robust Wifi to
tools and bring a large- through loyalty payments and offer employees along with
school experience to applications and offer your services to guest access. Same
smaller sites revenue-generating customers everywhere experience as bigger
services office
DNA ready for Small to Medium size, Single or Multi site deployments
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Mobility Express Interoperability
AireOS 8.7 ISE 2.2 or higher DNA Center 1.2 EFT CMX Presence &
DNA Center 1.2.x GA Analytics CMX
Location
CMX Engage
DNA Ready for Small to Medium Size, Single or Multi site Deployments
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Branch Offices with Cisco Mobility Express
Overview Network Plug and Play DNAC ISE
Central Site
WAN
Advantages
Cookie cutter configuration for Site A Site B Site C
every site
Independent or centralized
manageability of each site
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Deploying Cisco Mobility Express
Depending on the deployment, Mobility Express capable Access Points can be connected to an
access port or a trunk port on the switch. Management traffic is always untagged.
VLAN 10
VLAN 20
v20 v30 v40 VLAN 30
VLAN 10 VLAN 40
01 OTAP Over-the-Air-Provisioning
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Over-the-Air Provisioning Devices
Provision Monitor
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Setup Wizard – Over the Air Provisioning
CREATE WIRELESS
CREATE ADMIN ACCOUNT SET UP YOUR CONTROLLER CONFIRM SETTINGS
NETWORK
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Deploying using APIC-EM/Network Plug and Play
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Network Plug and Play – Private Cloud
ip dhcp pool pnp_device_pool
network 192.168.1.0 255.255.255.0
default-router 192.168.1.1 Master AP
option 43 ascii running PnP
"5A1N;B2;K4;I192.168.1.123;J80" Agent
LAN/WAN
LAN
PnP Server uses
PnP Server
self signed SSL
certificate
DHCP Request
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Network Plug and Play – Public Cloud
ip dhcp pool pnp_device_pool
network 192.168.1.0 255.255.255.0
default-router 192.168.1.1 Master AP
dns-server 171.70.168.183 8.8.8.8 running PnP Cisco Cloud
domain-name cisco.com Agent Redirect Server
DMZ
Internet PnP Server uses
PnP Server self signed SSL
certificate
DHCP Request
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Available with 8.7
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Mobility Express
Features
Evolution of Cisco Mobility Express
DEC, 2017
AireOS 8.6
JUL, 2017
AireOS 8.5
MAR, 2017
AireOS 8.4
FEB, 2016
AireOS 8.3 MR1
AUG, 2016
AireOS 8.3
AP Groups
RF Profiles
Conversion Support in UI 802.1x on Access Points
DEC, 2015 Support for Fastlane in UI AP Global Credentials
AireOS 8.2 Scale -100 APs/2000 TACACS+ and RADIUS Support Preferred Master
clients ACL Enhancements Save Configuration Notification
Day 0 using PnP Configuring External Antennas TLS Secure Tunnel
Site Survey Application Control CALEA
Support on 1562 AP Support for Apple Features Passpoint
SEP, 2015 Guest WLAN Enhancements Centralized NAT
AireOS 8.1 MAC Filtering
Support on 2800 & 3800 Lobby Ambassador
MR2 Expert View
Internal DHCP server support
Software Update – cisco.com
CMX Cloud Support
SNMPv3 Support
Serviceability improvements
Setup Wizard via CLI
Software Update – HTTP
NTP Pool support
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Evolution of Cisco Mobility Express
JUL, 2018
AireOS 8.8
APR, 2018
AireOS 8.7
mDNS support
Videostream support(MC2UC)
Optimal AP Join for heterogeneous network
FQDN support SFTP
DNA Centre support - WSA agent & enable DNA-C connectivity Schedule WLAN
Ability to update s/w during Day 0 using Network PnP Cisco RFID Tag support
Support for SFTP software download transfer mode DNS Based ACL Rules(post auth ACL)
Support for Optimal AP Join EoGRE support
Support for Bi-directional rate limit per client, BSSID and WLAN Option 43 support for ME
Ability to limit clients per WLAN, per radio
Support for RLANs
Support for Passive Clients
802.1x supplicant support on AP with EAP-TLS and EAP-PEAP
Walled Garden, Radius NAC
· DNS-based ACLs (Pre-auth ACL, IPv4 only)
· Central Web Authentication
· BYOD support
Ability to import EAP DEV certificate and OID file
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Site Survey
Cisco Mobility Express supports internal
DHCP server and operates without a pingable
gateway. This enables Site Surveyor to take
the Access Point powered by a Battery Pack
and a client device to perform an active
survey
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
WLAN Support
Supports maximum of 16 WLANs
WLAN Options:
Open
WPA2 Personal
WPA2 Enterprise (External RADIUS, AP)
Central Web Authentication (Release 8.7)
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Available with 8.6
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Available with 8.7
Optimal AP Join
Use Cases Feature Supported AP Models
• Customer is adding an AP to • Enables a CAPWAP or • Supported on 2800, 3800,
the existing ME network but Mobility Express AP to and 1560 on 8.7
the AP being added has a download the ME code from
different code version than Master AP • All other Wave 2 APs in
ME-WLC. For the new AP to 8.8 via Efficient Join
join ME-WLC, software has • This feature eliminates the
to be updated on the AP dependency on an external • Not supported on 11ac
server(SFTP, TFTP or Wave 1 APs
cisco.com) for providing the
code at the time of AP Join
for 3800, 2800 and 1560
Series APs
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Available with 8.7
If 3800, 2800 and 1560 AP is being added and ME-WLC AP model is one of
these APs, an external server does not have to configured to provide the code
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Available with 8.7
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Available with 8.7
Bi-Directional Rate
Bidirectional Rate Limiting
Limiting – Standard
WebUI View
configuration
Configuration available on the WLAN Traffic Shaping tab
Standard view has a slider to configure BDRL and Expert view allows BDRL
configuration for real-time(UDP) traffic
Client Limiting
Use Cases Feature Device Configuration
• Client Limiting on WLAN is • Client Limiting enables ability • Enter between 1 and 2000
useful in cases where you to limit the number of clients or select pre-selected
want to restrict the number on a wireless network. values
of clients on a WLAN. It • To limit clients per Radio
also ensures that the • Client Limiting is supported on an AP, enter 1 to 200
WLAN bandwidth is used on the following:
efficiently in the network • Per WLAN
• Per Radio / AP
• Client Limiting on AP Radio
is useful in cases where NOTE: By default, Mobility
you want to uniformly Express supports 2000 clients
distribute client load across and 200 clients per AP Radio
the AP radios for optimal
use of RF bandwidth
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Available with 8.7
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Available with 8.7
AAA Override
Use Cases Feature Device Configuration
• Clients connecting to a WLAN • AAA Override feature on a WLAN • AAA Override must be enabled
get their VLAN assignment from enables you to apply VLAN on the WLAN
AAA. For example, at a school, tagging, Quality of Service (QoS),
both Students & Teachers and Access Control Lists (ACLs) • For AAA Override of VLAN,
connect to the School-WiFi but to individual clients based on the VLAN which gets returned from
Teachers get assigned VLAN returned RADIUS attributes from AAA must exist on the
10 and Students get assigned the AAA server FlexConnect APs
VLAN 20
• For AAA Override of VLAN
• For single or multi-site Name, VLAN Name to VLAN ID
deployment with different VLAN mapping must exists on the
schemes, one can use AAA to FlexConnect APs
return a VLAN NAME instead of
VLAN ID to onboard clients on
the desired VLAN specific to
the site
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Available with 8.7
AAA returnedWebUI
AAA Override VLAN configuration
Name Override
1. AAA Override must be enabled on 2. For AAA returned VLAN Name,
the WLAN from the Advanced Tab VLAN Name to VLAN ID mapping
as shown below must exist on WLAN
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Application Visibility and Control
Cisco Mobility Express can identify signatures of 1000+ applications. It runs NBAR
Engine 2 and Protocol Pack 14
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Application Control
Action Drop – Shown from the Network Summary Page
Steps
1. On the Network Summary page,
view the APPLICATIONS widget
in a tabular format
2. Click on the desired application to
add the rule. The Add AVC Rule
window will pop up
3. Select Drop from the Action drop
down list
4. Select the WLAN to apply this
AVC Rule
5. Click on the Apply button
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Configuring RF Parameters
Navigate to Advanced > RF
Optimization
The following RF Parameters are
available on UI
Client Density
Traffic Type
2.4 / 5.0 GHz band
Flexible Radio Assignment
Event Driven RRM
CleanAir Detection
5.0 GHz Channel Width
2.4 and 5.0 GHz Data Rates
DCA Channels
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Available with 8.6
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Available with 8.6
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Available with 8.6
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Available with 8.6
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Mobility Express
HA - Master Election
Mobility Express – High Availability
Failure of Access Point running the controller function
Upon controller failure, another Access Point will be elected to run the controller. Uses
VRRP.
HA considerations
No impact for connected clients on locally switched SSIDs
Roaming allowed within FlexConnect group for already connected clients
What about new clients? - Static keys are locally stored in FlexConnect AP: new
clients can join if authentication is PSK
Lost features
RRM, CleanAir
Web authentication
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Master Election Overview
Master Election is a mechanism to elect a new Cisco Mobility Express CAPABLE
Access Point to run the controller function incase of a failure
To have redundancy, you must have TWO or more Mobility Express Capable Access
Points in your network
VRRP is used to detect the failure of Master AP which initiates the election of a new
Master. Failover typically takes 60-90s.
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Available with 8.7
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Electing a new Master Access Point
Master election process is based on a set of priorities. When an active Master Access Point fails, the
election process gets initiated and it elects a new AP to be master based on user defined priority or
automatic election
1. User Defined
a. User Defined Master - User can select an Access Point to be the Master Access Point. If such a selection is
made, no new Master will be elected in case of a failure of the active Master. After five minutes, if the current
Master is still not active, it will be assumed dead and Master Election will begin to elect a new Master.
b. User Defined Next Preferred Master – Admin can configure the Next Preferred Master from UI or CLI. When
this is configured and the active Master AP fails, the one configured as the Next Preferred Master will be
elected as a Master.
2. Automatic Election
a. Most Capable Access Point - If the first two priorities are not configured, Master AP election algorithm will
select the new Master based on the capability of the Access Point. For example, 3800 is the most capable
followed by 2800, 1850, 1830 and finally the 1815 Series. All 1815 Series Access Points have the same
capability.
b. Least Client Load – If here are multiple Access Points with the same capability i.e. multiple 3800 Access
points, the one with least client load is elected as the Master Access Point.
c. Lowest MAC Address – If all of the Access Points are the same and have the same client load, then Access
Point with the lowest MAC will be elected as a Master.
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Mobility Express
Failure of Access Point running the controller function
• Election of a new controller using VRRP
• Heartbeat exchanged every 10s with Master AP
• After 3 missed heartbeats, master election is initiated and all Mobility Express
capable APs participate in Master Election
• APs fall into standalone mode while Master Election in-progress and within next
30s, a new Master is elected
• Standalone Access Points join the new elected master and go to connected mode
• Election Priorities
• Most capable Access Points. 3800 > 2800 > 1800.
• Access Client with least client load
• In case of tie, election based on lowest MAC Address
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Master Election Process AIR-AP1852I-B-K9
P
AIR-AP2802I-B-K9 AIR-AP1852I-B-K9
MASTER AP
AIR-AP2702I-B-K9
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Master Election Process AIR-AP1852I-B-K9
P
AIR-AP2802I-B-K9 AIR-AP1852I-B-K9
MASTER AP
AIR-AP2702I-B-K9
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Mobility Express - Summary
Branch Solution for Appliance-less WLC-Based Networks for up to 100 APs
Ease of AVC & CMX RF Excellence & Guest & Security DNA Center &
Deployment with Apple Innovations Multi-site
Resiliency & Scale Deployment
• Manage up to 100 • Understand what is • Flexible Radio • Multiple guest • Day0 PnP with config
AP’s, 2000 clients running on your Assignment & Dual onboarding options & image download
without additional network 5GHz for best Wi-fi with built-in lobby • DNA Automation &
licensing costs • Bidirectional rate limit experience ambassador Assurance EFT
• Best practices on by per • Best in class RF with • Rogue detection & available with
default & built-in WLAN/SSID/Client HDX – ClientLink, classification DNAC1.2
redundancy for • CMX Location & CleanAir & Spectrum • ISE/Radius, Walled • DNA Automation &
resilient operations Presence Analytics Intelligence Garden support and Assurance GA in
• Localized with • CMX Engage/Cloud • Apple Fast Lane with BYOD integration DNAC 1.3
Chinese, Japanse & integration for optimized Wi-fi • 802.1x support on AP • Intelligent Capture
Korean personalized and connectivity & with EAP-TLS and EFT in DNAC 1.3 &
• Management relevant guest prioritize business EAP-PEAP AireOS 8.8
simplicity with mobile experience applications
app & WebUI
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Enterprise Wireless Book
http://cs.co/wirelessbook
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Cisco Wireless LAN Documentation
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Click - https://www.youtube.com/user/CiscoWLAN/
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Complete your online session evaluation
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Continue
your Demos in
the Cisco
Walk-in
self-paced
Meet the
engineer
Related
sessions
education campus labs 1:1
meetings
#CLUS BRKEWN-2016 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Thank you
#CLUS
#CLUS