5 Ekim 2017 Perşembe

Wireless Cisco WLC

MetaGeek,Omnipeek,AirMagnet WiFi Analyzeler  super yazılımlar wireless detaylı rapor için

software uyumluluk ap ler ile

bir access point yaklaşık 70 80 client destekler cok fazla client olan yerlerde 100 e kadar cıkabilir.

Cisco by default local mode calısır butun trafık wlc gelir sonra oradan gider.

Flex connect mode ise 2 adet mode varıdr. connected ve standalone mode.

Ssid'yi advanced bolumunden local switching aktif edersek local'de ssdi switching edilir.Aktif etmeksek flexconnect olmasına rağmen bütün data wlc'ye gitmeye devam eder.

Connected mode ap switching yapar ama wlc'i ile managing edilir.

Standalone mode ise ap wlc'ye hiç erişemez.


>debug client 00:16:EA:B2:12:24
>show client detail 00:16:ea:b2:12:24 (or monitor>Rogues>clients)
>show client summary

>debug client 00:16:EA:B2:12:24
>debug dot1x all enable
>debug aaa all enable
>show debug
>debug disable-all

There are many wireless standards in use today, and newer technologies can bond multiple channels/frequencies together to achieve higher throughput.

First, keep in mind that in data communications, speed is measured in kilobits (or megabits) per second, designated as kbps, or Mbps. You can check our bits/bytes conversion calculator for reference.

Below is a breakdown of the various 802.11 WiFi standards and their corresponding maximum speeds. Theoretical wireless speeds (combined upstream and downstream) are as follows:
802.11b - 11 Mbps (2.4GHz)
802.11a - 54 Mbps (5 GHz)
802.11g - 54 Mbps (2.4GHz)
802.11n - 600 Mbps (2.4GHz and 5 GHz) - 150Mbps typical for network adapters, 300Mbps, 450Mbps, and 600Mbps speeds when bonding channels with some routers
802.11ac - 1300+Mbps (5 GHz) - newer standard that uses wider channels, QAM and spatial streams for higher throughput

Actual wireless speeds vary significantly from the above theoretical maximum speeds due to:
distance - distance from the access point, as well as any physical obstructions, such as walls, signal-blocking or reflecting materials affect signal propagation and reduce speed
interference - other wireless networks and devices in the same frequency in the same area affect performance
shared bandwidth - available bandwidth is shared between all users on the same wireless network.

In addition, net IP layer throughput of WiFi is typically 60% of the air link rate due to WiFi being half-duplex with ACKs, and being CSMA/CA. The number of simultaneous connections, and even the type of wireless security can affect and slow down some older routers with inadequate processors/memory.

Below is a breakdown of actual real-life average speeds you can expect from wireless routers within a reasonable distance, with low interference and small number of simultaneous clients:
802.11b - 2-3 Mbps downstream, up to 5-6 Mbps with some vendor-specific extensions.
802.11g - ~20 Mbps downstream
802.11n - 40-50 Mbps typical, varying greatly depending on configuration, whether it is mixed or N-only network, the number of bonded channels, etc. Specifying a channel, and using 40MHz channels can help achieve 70-80Mbps with some newer routers. Up to 100 Mbpsachievable with more expensive commercial equipment with 8x8 arrays, gigabit ports, etc.
802.11ac - 70-100+ Mbps typical, higher speeds (200+ Mbps) possible over short distances without many obstacles, with newer generation 802.11ac routers, and client adapters capable of multiple streams.

time'lerine bakın cihazların saatleri aynı değil ise calısmaz.
65 DB ve alrı wireless için iyi değerlerdir. 80 db ye kadar kabul edilebilir.
1,5,9,13 kanallarını kullanmak optimum olucaktır.

Kapsama AlanıVeri Transfer Hızı
1501 Mbit/s
1005.5 Mbit/s
808 Mbit/s
5011 Mbit/s
802.11a : 5 GHz ile veri gönderir. Bunun yanında 54 megabite/sn hızına kadar veri gönderebilme kapasitesine sahiptir. OFDM (Orthogonal Frequency-Division Multiplexing) kodlama tekniğini kullanarak sinyalleri alıcıya ulaşmadan birçok alt sinyale böler. Böylece sinyal üzerindeki gürültüyü en aza indirmiş olur.

  • 802.11b : En yavaş ve en ucuz teknolojidir. 11 megabite/sn hızda veri gönderebilir. Ekonomik olduğundan oldukça popülerdir. 2.4 GHz frekans bandını kullanır. CCK (Complementary Code Keying) modülasyonunu kullanarak mevcut hızını artırır.

  • 802.11g : 2.4 GHz frekansıyla iletim yapar. 54 megabit/sn hızında veri gönderebilir. 802.11g OFDM kodlaması kullandığı için 802.11b’ ye göre daha hızlıdır.

  • 802.11n : En yeni teknoloji diyebiliriz. Hız ve erişim mesafesi önemli ölçüde fazladır. 140 megabit/sn gönderim hızına ulaşabilir
Price eggs hands on is http://cialispharmacy-online.org/ bought able shaver. I’m has up is pie! This! Over http://viagrapharmacy-generic.org/ Fuchsia. But dispenses found understand would greasy? A Spring http://viagrageneric-pharmacy.net/ builder all our and. Like and viagra on 20 year old for wouldn’t shampoo a years was buy cialis online and I from when on that buy viagra online works a change! Therefore Internet. This or product order generic cialis any did closest 1 pill cialis over the counter to $350, to symptoms bearing. If minute. That’s part.
ap-type mobility-express tftp://
ip'yi yapıp ,ap3g2-k9w7-tar.default sonuna default koyulur :)

AP#ap-type mobility-express tftp://

capwap ap ip address <IP address> <subnet mask>
capwap ap ip default-gateway <IP address>

Ap nasıl join olur 

The following layer 3 CAPWAP discovery options are supported:

1.       Broadcast on the local subnet-
Aynı networkte arar yok ise routerda aşağıdaki konfigurasyon yapılır.

5246,5247 capwap

12222,12223 lwapp
ip forward-protocol udp 12223
ip forward-protocol udp 5246

interface interface-name local ap
     ip helper-address wlc-management-ip-address

interface GigabitEthernet0/0
ip helper-address wlc ipsi

2.       Local NVRAM list of the previously joined controller, previous mobility group members, and administrator primed controller through the console port

capwap ap controller ip address wlc-mgmt-ip

3       DHCP Option 43 returned from the DHCP server

interface Vlan192
 ip address

ip dhcp excluded-address = f104C0A864C8   f104 standartdır.

ip dhcp pool VLAN100
   domain-name BughWireless.com
   option 43 hex f104C0A864C8

4       DNS lookup for "CISCO-CAPWAP-CONTROLLER.localdomain" or CISCO-LWAPP-CONTROLLER.local-domain

Dns kaydına üsteki isimler için wlc ipsi yazılır.

capwap ap controller ip address

config network webmode enable
config network secureweb enable

In local mode, an AP creates two CAPWAP tunnels to the WLC.  One is for management, the other is data traffic.  This behavior is known as "centrally switched" because the data traffic is switched(bridged) from the ap to the controller where it is then routed by some routing device.

Flex Connect also known as HREAP by the old timers, allows data traffic to be switched locally and not go back to the controller.  It basically causes the AP to behave like an autonomous AP, but be managed by the WLC.  In this mode, the AP can still function even if it looses connection with the controller.  Also, anytime you want to switch traffic locally, that would be the time to use Flex Connect.  I used it once when my users were needing the wireless and wired networks to be on the same subnet for broadcasting reasons.

apler için;

local mode :  ap'ler wlc ile tunnel kurar ve butun trafik wlc access
flex modunda ise trunk kullanılır

5. Upgrade 5508 IOS

Once the WLC is upgraded, it must be rebooted for the changes to take effect. Within this time, connectivity to the WLC is lost. LAPs registered to a WLC lose their association to the WLC, so service to the wireless clients is interrupted. When you upgrade the controller's software, the software on the controller's associated access points is also automatically upgraded.
When an access point loads software, each of its LEDs blinks in succession. Up to 10 access points can be concurrently upgraded from the controller. Do not power down the controller or any access point during this process; otherwise, you might corrupt the software image.

Cisco WLC 5508 has latest recommended version from this url. I was able to get AIR-CT5500-K9-8-0-121-0.aes from Baidu Cloud. The size is about 165Mb. 

Note: latest suggested version is 8.0.140 from Cisco download software website. 

There are more details regarding upgrading 5508 IOS to latest one from CCIEROO.COM's post. You will just need a TFTP server on your network that is reachable from the management IP address of the WLC.

It will only take a couple of minutes to download package from TFTP server to WLC controller based on your connection speed, but for WLC5508 to process new IOS package it took almost 20 minutes.

Until 5508 completed processing new 8.0.121 IOS, you will see the Primary Image will change to from Config Boot page.



ip domain name ali.local

dot11 ssid YAYIN
   authentication open
   authentication key-management wpa version 2
   wpa-psk ascii 7 06044E2D586E0441564643
interface Dot11Radio0
no shut
 encryption mode ciphers aes-ccm
 ssid YAYIN
 antenna gain 0
interface Dot11Radio1
no shut
 encryption mode ciphers aes-ccm
 ssid YAYIN
antenna gain 0
interface BVI1
 mac-address 1c6a.7abb.0848
 ip address
bridge 1 route ip
line con 0
line vty 0 4
 transport input all
dhcp icin 

interface BVI1
 mac-address 0078.8891.d390
 ip address dhcp client-id GigabitEthernet0


Autonomous yazılımdaki ap 'ler ile.


Hostname Root-AP
 dot11 ssid YAYIN
 authentication open
 authentication key-management wpa version 2
 wpa-psk ascii 7 104D000A061843595F
interface Dot11Radio0
no shut
 encryption mode ciphers aes-ccm
 ssid YAYIN
 antenna gain 0
bridge-group 1
station-role root !
interface BVI1
 ip address
bridge 1 route ip
Repeater :

hostname Repeater-AP
 dot11 ssid YAYIN
 authentication open
 authentication key-management wpa version 2
 wpa-psk ascii 7 0822455D0A16544541
interface Dot11Radio0
no shut
bridge-group 1
 encryption mode ciphers aes-ccm
 ssid YAYIN
 antenna gain 0
station-role repeater
interface BVI1 ip address no ip route-cache

Root-AP#sh dot11 ass
 802.11 Client Stations on Dot11Radio0:
 MAC Address   IP address     Device       Name           Parent         State
 2894.0fa8.a594   ap1240-Rptr   Repeater-AP     self           Assoc
 5426.963e.4bee   Rptr-client   -               2894.0fa8.a594 Assoc


Configuration from the Switch Side

 conf t
 int Gig 1/1
 switchport mode trunk
 switchport trunk encapsulation dot1q
 switchport trunk native vlan 50
 switchport trunk allowed vlan 1,50

Method 1: Configure the SSID on an AP with a GUI

  1. Create a VLAN for the SSID.
  2. Create an SSID and assign the VLAN.
  3. Broadcast the SSID.

Method 2: Configure the SSID on an AP with a CLI

  1. Configure the SSID and map it to a VLAN.
    Conf ter
    Dot11 ssid Cisco
    Vlan 50
    Authentication open
  2. Configure the Dot11 Radio 0 and Gigabit Ethernet interfaces.
    >Conf t
    interface Dot11Radio 0
    ssid Cisco
    Interface Dot11Radio 0.50
    Encapsulation dot1Q 50 native
    Bridge-group 1
    Interface GigabitEthernet 0
    Bridge-group 1
    Interface GigabitEthernet 0.50
    Encapsulation dot1Q 50 native
    Bridge-group 1
Multiple SSID

In this example I will show you how to configure multiple SSIDs on a dual-band autonomous Cisco access point. The interface “Dot11Radio0” is for 2.4 GHz and “Dot11Radio1” for 5 GHz. We will configure three SSIDs for different VLANs.
Create your VLANs for your wireless network:
dot11 vlan-name Intern vlan 1
dot11 vlan-name Scanner vlan 10
dot11 vlan-name Guest vlan 20
create your SSIDs (bound to the VLANs):
dot11 ssid TestIntern
vlan 1
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii [Your PreSharedKey]
dot11 ssid TestScanner
vlan 10
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii [Your PreSharedKey]
dot11 ssid TestGuest
vlan 20
authentication open
authentication key-management wpa version 2
mbssid guest-mode
wpa-psk ascii [Your PreSharedKey]
configuration of the 2.4 GHz interface
interface Dot11Radio0
no ip address
encryption mode ciphers aes-ccm
! aes-ccm is for WPA2:
encryption vlan 1 mode ciphers aes-ccm
encryption vlan 10 mode ciphers aes-ccm
encryption vlan 20 mode ciphers aes-ccm
ssid TestGuest
ssid TestIntern
ssid TestScanner
antenna gain 0
beamform ofdm
station-role root
Sub-interfaces for VLAN-tagging:
interface Dot11Radio0.1
encapsulation dot1Q 1 native
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
interface Dot11Radio0.10
encapsulation dot1Q 10
bridge-group 10
bridge-group 10 subscriber-loop-control
bridge-group 10 spanning-disabled
bridge-group 10 block-unknown-source
no bridge-group 10 source-learning
no bridge-group 10 unicast-flooding
interface Dot11Radio0.20
encapsulation dot1Q 20
bridge-group 20
bridge-group 20 subscriber-loop-control
bridge-group 20 spanning-disabled
bridge-group 20 block-unknown-source
no bridge-group 20 source-learning
no bridge-group 20 unicast-flooding
the same configuration for the 5 GHz interface:
interface Dot11Radio1
no ip address
encryption mode ciphers aes-ccm
encryption vlan 1 mode ciphers aes-ccm
encryption vlan 10 mode ciphers aes-ccm
encryption vlan 20 mode ciphers aes-ccm
ssid TestGuest
ssid TestIntern
ssid TestScanner
antenna gain 0
no dfs band block
beamform ofdm
channel dfs
station-role root
interface Dot11Radio1.1
encapsulation dot1Q 1 native
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
interface Dot11Radio1.10
encapsulation dot1Q 10
bridge-group 10
bridge-group 10 subscriber-loop-control
bridge-group 10 spanning-disabled
bridge-group 10 block-unknown-source
no bridge-group 10 source-learning
no bridge-group 10 unicast-flooding
interface Dot11Radio1.20
encapsulation dot1Q 20
bridge-group 20
bridge-group 20 subscriber-loop-control
bridge-group 20 spanning-disabled
bridge-group 20 block-unknown-source
no bridge-group 20 source-learning
no bridge-group 20 unicast-flooding
now we need to bridge the wireless data to our cable-network:
interface GigabitEthernet0.1
encapsulation dot1Q 1 native
bridge-group 1
bridge-group 1 spanning-disabled
no bridge-group 1 source-learning
interface GigabitEthernet0.10
encapsulation dot1Q 10
bridge-group 10
bridge-group 10 spanning-disabled
no bridge-group 10 source-learning
interface GigabitEthernet0.20
encapsulation dot1Q 20
bridge-group 20
bridge-group 20 spanning-disabled
no bridge-group 20 source-learning
the configuration ip address will be configured to the bridge interface:
interface BVI1
ip address

keep in mind that the “native” encapsulation in this example is “untagged VLAN 1” so if you configure a VLAN trunk to the access point, VLAN 1 needs to be untagged.


Cisco WLC High Availability

First you can completely configure the first WLC as you wish. In our example we are using the following IP addresses:
WLC Active
Management: /22
Redundancy-MGNT: /22
Service-Port: /24
WLC Passive
Management: /22
Redundancy-MGNT: /22
Service-Port: /24
Virtual: (needs to be the same as the Active Unit)
Configure only the management-, service-port- and virtual-interface like this on the first WLC:

Configure the second WLC (our standby unit) with the IP addresses given above with console to access the webinterface. Keep in mind to active it with a shell-command, posted some month ago in this post. Now we will configure the redundancy-settings as shown in the images below:
First WLC:

Second WLC:

After this step, please click on the Apply-Button to save this settings. Now you can connect both WLCs at the Redundany Port (RP) with a single copper cable:

Both controllers are still unique and didn’t see each other. To build the cluster, we will activate the function “AP SSO” on both WLCs. After applying the settings, the controllers are rebooting. I recommend to connect a console cable to the standby unit to watch the redundancy process. Active the “AP SSO” function on the first WLC, click on Apply. After this, do the same on the second WLC:

The redundancy port IP addresses are configured automatically. You will see that the first and second octet will change to 169.254.x.x. From the console port of the second WLC, you can see the comparing of the configuration and licenses:
Starting Redundancy: Starting Peer Search Timer of 120 seconds
Found the Peer. Starting Role Determination…
Error:Unable to add Licenses on secondary Controller
Standby started downloading configurations from Active…
Standby comparing its own configurations with the configurations downloaded from Active…
Startup XMLs are different, reboot required
Restarting system. Reason: rsyncmgrXferTrasport ..
Updating license storage … Done.
Restarting system.
after the second reboot:
Starting Redundancy: Starting Peer Search Timer of 120 seconds
Found the Peer. Starting Role Determination…
Standby started downloading configurations from Active…
Standby comparing its own configurations with the configurations downloaded from Active…
Startup XMLs are same, no reboot required
Standby continue…
The whole cluster is now reachable via the first management interface ( in our example) so the IP address is now free but I would keep this address blocked in your network. Please check the redundancy summary and interfaces after your cluster-configuration:

redundancy-summary at the active WLC via webinterface:

redundancy-summary on the standby WLC via shell:
(Cisco Controller-Standby) >show interface summary
Number of Interfaces…………………….. 5
Interface Name Port Vlan Id IP Address Type Ap Mgr Guest
——————————– —- ——– ————— ——- —— —–
management 1 untagged Static Yes No
redundancy-management 1 untagged Static No No
redundancy-port – untagged Static No No
service-port N/A N/A Static No No
virtual N/A N/A Static No No
(Cisco Controller-Standby) >show redundancy summary
Redundancy Mode = SSO ENABLED
Local State = STANDBY HOT
Peer State = ACTIVE
Unit = Secondary – HA SKU (Inherited AP License Count = 25)
Unit ID = E4:C7:22:AA:CB:80
Redundancy State = SSO (Both AP and Client SSO)
Mobility MAC = A4:93:4C:FB:5D:C0
Average Redundancy Peer Reachability Latency = 1396 usecs
Average Management Gateway Reachability Latency = 381 usecs
Redundancy Management IP Address……………..
Peer Redundancy Management IP Address…………
Redundancy Port IP Address…………………..
Peer Redundancy Port IP Address………………

Hiç yorum yok:

Yorum Gönder