Wireless 3014
Wireless 3014
Deploy High-
Availability in Wireless
LAN Architectures
How
1. Find this session in the Cisco Live Mobile App
2. Click “Join the Discussion”
3. Install Spark or go directly to the space
4. Enter messages/questions in the space
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
The new Normal
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Session Objective
admin
The goal of this session is to show you how to design and deploy a Highly
Available wireless network to reduce the network downtime
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Agenda
• High Availability (HA), the theory of operations:
• What to do at the Radio Frequency layer?
• Controller HA for different Deployment Modes:
• Centralised, FlexConnect, Mobility Express, Prime and MSE high availability
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
DNA ready Wireless Controller Portfolio
Large Enterprise
Mid-size Enterprise
Indoor / High-powered
Indoor Wall Plate / 3x3:2SS 80MHz 4x4:3SS 80Mhz 4x4:3SS 160 MHz 4x4:3SS 160 MHz
Teleworker 5 Gbps Performance
867 Mbps Performance 1.7 Gbps Performance 5 Gbps Performance
2x2:2SS 80 MHz Tx Beam Forming Internal or External Antenna 2.4 and 5GHz or 2.4 and 5GHz or
Dual 5GHz Dual 5GHz
867 Mbps Performance 1 GE Port Uplink Tx Beam Forming
2 GE Ports Uplink 2 GE Ports Uplink or
Tx Beam Forming USB 2.0 2 GE Ports Uplink
1 GE + 1 mGig (5G)
Integrated BLE Gateway1 USB 2.0 CleanAir and ClientLink
CleanAir and ClientLink
Max Transmit Power (dBm) Internal or External Antenna
StadiumVision
per local regulations2 Smart Antenna Connector
Internal or External Antenna
3 GE Local Ports, including USB 2.0
1 PoE out3 Smart Antenna Connector
Local ports 802.1x ready3 USB 2.0
USB 2.04 Investment Proof Modularity
New*
80 MHz channel
But it
comes with
a price
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Radio Frequency (RF) High Availability
• Site Survey, site survey….and site survey
• Use “Active” survey
• Coverage vs. Capacity
• Consider Client type (ex. Smartphone vs. Laptop)
My
Myantenna
power isgain
halfisof4
my times
brother
smaller
MacBook
I trythen
and to connect
move totoanother
5GHz
and stay ifconnected
BSSID until
it is REALLY
the signal better
is REALLY bad
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Radio Frequency (RF) High Availability
• Site Survey, site survey….and site survey
• Use “Active” survey
• Coverage vs. Capacity
• Consider Client type (ex. Smartphone vs. Laptop)
• Tools
• What you use is less important than how you use it
• Use the same tool to compare results
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
RF High Availability: Cisco RRM
• What are Radio Resource Manager (RRM)’s objectives?
• Provide a system wide RF view of the network at the Controller (only Cisco!!)
• Dynamically balance the network and mitigate changes
• Manage Spectrum Efficiency so as to provide the optimal throughput under changing conditions
• What’s RRM
• DCA—Dynamic Channel Assignment
• TPC—Transmit Power Control
• CHDM—Coverage Hole Detection and Mitigation
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
RF High Availability: Cisco RRM
RRM DCA in action
A rogue AP is detected on
channel 11
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
RF High Availability: Cisco RRM
RRM CHDM in action
RRM will determine the optimal
Power plan based on AP layout
If an AP fails…
If an AP fails…
• CleanAir
• Hardware based Solution
• Best Practice: always turn it on supported APs (all 802.11ac APs are CleanAir capable)
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Maximise the Spectrum
Avoiding Excessive Management Traffic
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Maximise the Spectrum
PHY Rate Tuning: Why PHY Rates Matter
• How fast can we talk?
18Mbps • Signal (RSSI) and Noise are
Client near AP: key factors
24Mbps
Higher PHY Rate
• As client moves further
36Mbps
More Efficient 48Mbps
(high signal-to-noise ratio) 54Mbps
from AP or as noise
worsens, client rate-
shifts downward
Client far from AP:
Lower PHY Rate • Lower rate, more airtime
Less Efficient consumed
(lower signal-to-noise ratio)
• 802.11ac Wave 2
example ~15’
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Maximise the Spectrum
PHY Rate Tuning: How-To Basics
18Mbps
24Mbps
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
RRM’s new Flexible Radio Assignment (FRA)
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Flexible Radio Assignment (FRA) – Client Service Mode
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
FRA – Assignment Priority
1 • Coverage
Pervasive dense –and
too2.4GHz Mark Redundant
5GHz coverage
5GHz 2.4GHz
Serving Serving • Default operating Role
5GHz Wireless
3 Serving Security Wireless monitoring of 2.4 and 5 GHz
Monitor
5GHz Wireless
4 Serving Sensor One radio dedicated as a Sensor
(not automatically configured)
TECCRS-2001 32
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
Wireless Controller HA
Wireless Controller Deployment modes
NEW NEW
Campus LAN
Fabric WAN
Centralised Control Plane Centralised Control Plane Centralised Control Plane Distributed Control Plane
Centralised Data Plane Distributed Data Plane Distributed Data Plane Distributed Data Plane
Target
Campus Campus Branch Branch
Positioning
Purchase
Decision
Wireless Only Wired and Wireless Wireless only Wireless only
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Centralised Mode HA Requirements Benefits
Minimum release: 7.5
Active Client State is synched
3504, 5500, 8500 series
AP state is synched
Client SSO L2 connection between boxes
No Application downtime
Same HW and software
HA-SKU available
1:1 box redundancy
Network Uptime
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
N+1 Redundancy • Administrator statically assigns APs a primary,
WLAN-Controller-A WLAN-Controller-B WLAN-Controller-C
secondary, and/or tertiary controller
• Assigned from controller interface (per AP) or Prime
Infrastructure (template-based)
• You need to specify Name and IP if WLCs are not in the
same Mobility Group
IP Network • Pros:
• Predictability: easier operational management
• Support for L3 network between WLCs
Access Point • Flexible redundancy design options:1:1, N:1, N:N:1
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
N+1 Redundancy
Global backup Controllers
• Backup controllers configured for all APs under Wireless > High Availability
• Used if there are no primary/secondary/tertiary WLCs configured on the AP
• The backup controllers are added to the primary discovery response message to the AP
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
N+1 Redundancy
AP Failover mechanism < 30-45 sec (*)
• When configured with Primary and backup
Controllers:
• AP uses CAPWAP heartbeats to validate current
WLC connectivity
AP Boots UP WLC failure
• Upon loosing a CAPWAP heartbeat to the Primary, detected
AP sends 5 consecutives heartbeats every 3 second Reset
(default) Discovery
• Configurable to minimum of 3 keepalive every 2 sec
• If no reply, AP starts the join process to the first
backup WLC candidate: Image Data
• Backup is the first alive WLC in this order: primary, DTLS
secondary, tertiary, global primary, global secondary. Setup
Run
• With N+1 Failover, AP goes back to discovery state
just to make sure the backup WLC is UP and then
immediately starts the JOIN process
Join Config
• With N+1, AP periodically checks for Primary to come
back online and falls back to it (AP fallback can be
disabled)
(*) With Fast Heartbeat and minimum values for keepalive
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
N+1 Redundancy
AP Fast Heartbeat < 30-45 sec (*)
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
N+1 Redundancy
AP Primary Discovery Request Timer
• The access point periodically sends primary discovery requests to the Primary
WLC to know when it is back online. Default is 120 sec.
• If AP Fallback is enabled (default), the AP automatically joins back the Primary
controller
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
N+1 Redundancy
Critical AP fails over
AP Failover Priority
• Assign priorities to APs: Critical, High, AP Priority: Critical Overloaded
Controller
Medium, Low
Medium priority
• Critical priority APs get precedence over AP dropped
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
N+1 Redundancy < 30-45 sec (*) Geo separated DC
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Wireless Controller HA
Centralised Mode – Stateful Switch
Over (SSO)
< 1 sec
Stateful Switchover (SSO)
Active Controller
• True Box to Box High Availability i.e. 1:1 RP 1
• One WLC in Active state and second WLC in Hot Standby state
• Secondary continuously monitors the health of Active WLC via dedicated link L2 network
Hot Stand-by Controller
https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-1/HA_SSO_DG/High_Availability_DG.html
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Stateful Switchover (SSO)
Pairing the boxes
• HA Pairing is possible only between the same type of Active Controller
hardware and software versions
• 3500/5500/8500 have dedicated Redundancy Ports
RP 1
• Direct connection supported in 7.3 and 7.4
L2 network (7.5)
Hot Stand-by Controller
• L2 connection supported in 7.5 and above
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Stateful Switchover (SSO)
Failover sequence
ACTIVE STANDBY
ACTIVE
1. Redundancy role negotiation and config sync
2. APs associates with Active controller
Si Si
3. Client associates with Active through AP GARP
4. Active failure: notify peer / or missing keep alive
5. Standby WLC sends out GARP
6. Standby becomes Active:
AP DB and Client DB (7.5) is already synced with standby controller Si
Si
Si
Si
AP CAPWAP tunnel session intact
Client session intact, client does not re-associate*
Campus
Access
video: https://www.youtube.com/watch?v=If5F7eZkC3w
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
WLC3504 Series Wireless LAN Controller
Industry’s first Wireless LAN Controller with Multigigabit Ethernet
Throughput 4Gbps
Compact (1 RU) | mGig ready | Dedicated RP/SP ports | HA SSO | Side by Side rack mount
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Stateful Switch Over (SSO)
Redundancy Management Interface
• Redundancy Management Interface (RMI)
• To check gateway reachability sending ICMP packets every 1 sec
• Peer reachability once the Active does not respond to Keepalive on the Redundant Port
• Notification to standby in event of box failure or manual reset
• Communication with Syslog, NTP, TFTP server for uploading configurations
• Must be in same subnet as Management Interface. From 8.0 the Management VLAN needs to be tagged
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Stateful Switchover (SSO)
Redundancy Port
• Redundancy Port (RP):
• Active/Standby role negotiation
• Configuration synch from Active to Standby (bulk and incremental configuration)
• Peer reachability sending UDP keep alive messages every 100 msec
• Notification to standby in event of box failure
• Time synch with peer, if NTP not available
• Auto generated IP Address where last 2 octets are picked from the last 2 octets of RMI
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Stateful Switchover (SSO) For Your
Reference
Configuration
• Management interfaces on both WLCs
must be on the same subnet
• Mandatory Configuration for HA setup:
• Redundant Management IP Address
• Peer Redundant Management IP Address
• Redundancy Mode set to SSO enable (7.3
and 7.4 would show AP SSO)
• Primary/Secondary Configuration – Required
if peer WLC’s UDI is not HA SKU
• The Primary HA must have valid AP licenses
• Unit can be secondary if it has at least 50 AP
Optional Configuration:
(5508) permanent licenses (no restrictions for • Service Port Peer IP
other WLCs) • Mobility MAC Address
• Keep Alive and Peer Search Timer
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Wireless Controller HA
FlexConnect Mode
FlexConnect quick recap.... Central Site
WLCs
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
FlexConnect HA
Limitations Benefits
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
FlexConnect
Central Site
WAN Failure (or single central WLC failure)
• HA considerations:
• Disconnection for centrally switched SSIDs clients
• No impact for connected clients on locally switched
SSIDs
WAN
• Fast roaming allowed within FlexConnect group for
already connected clients
Remote Site
• What about new clients?
• Static keys are locally stored in FlexConnect AP: new
Application
clients can join if authentication is PSK Server
• Lost features
• RRM, CleanAir, WIDS, Location, other AP modes
• Web authentication, NAC
Centrally switched traffic
Locally switched traffic BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
FlexConnect Central Site
WLC failure with Deterministic N+1 HA Secondary Primary
• HA considerations:
• Disconnection for centrally switched SSIDs clients
• No impact for connected clients on locally switched
SSIDs
Remote
Office
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
FlexConnect AAA Survivability
Central Site
FlexConnect Local Auth Central
RADIUS
• By default FlexConnect AP authenticates clients
through central controller when in Connected
mode
• This feature allows AP to act as an Authenticator
even in Connected mode WAN
Local
• AAA servers are defined at the FlexGroup level RADIUS
Remote
• Useful HA scenarios: Office
• Independent branch: AAA is local at the branch, no
AAA traffic goes through WAN
• WLC goes down but WAN is up. Local users are
authenticated from AP to Central site AAA
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
FlexConnect AAA Survivability
AAA Server on AP Central Site
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
FlexConnect For Your
Reference
AAA server on AP - Configuration
• Check “Enable AP Local Auth” under the FlexConnect Group “General” tab
• Under the “Local Authentication” tab:
• Define EAP parameters (LEAP, EAP-FAST, PEAP, EAP-TLS )
• Define users (max 100) and passwords
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
Wireless Controller HA
Mobility Express
Mobility Express
Failure of Access Point running the controller function
• Controller and APs in the same L2 broadcast domain. Based on FlexConnect
architecture. Support central authentication and local switching for clients
• HA considerations:
• No impact for connected clients on locally switched SSIDs
• Fast roaming allowed within FlexConnect group for already connected clients
• What about new clients?
• Static keys are locally stored in FlexConnect AP: new clients can join if authentication is
PSK
• Lost features
• RRM, CleanAir
• Web authentication
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Mobility Express
Failure of Access Point running the controller function
• Election of a new controller using VRRP
• Heartbeat exchanged every 10s with Master AP
• After 3 missed heartbeats, master election is initiated and all Mobility Express capable
APs participate in Master Election
• APs fall into standalone mode while Master Election in-progress and within next 30s, a
new Master is elected
• Standalone Access Points join the new elected master and go to connected mode
• Election Priorities
• Most capable Access Points. 3800 > 2800 > 1800.
• Access Client with least client load
• In case of tie, election based on lowest MAC Address
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
Master Election Process AIR-AP1852I-B-K9
AIR-AP2802I-B-K9 AIR-AP1852I-B-K9
MASTER
AP
AIR-AP2702I-B-K9
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
Management and Mobility Services HA
Prime and MSE HA
Prime and MSE HA
Requirements Benefits
Active / Standby (1:1) mode No database loss upon failover
Same software & hardware Failover Automatic or Manual
Prime HA Minimum failover time is 15 s Failback is always manual
PI 2.2 supports Virtual IP (VIP) No AP licenses on Secondary
HA SKU from PI 2.0 and later Supported across WAN
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
CMX HA Overview
• CMX 10.3 is the first release supporting HA with CMX
• Only 2 Box HA is supported with one active and one passive server.
• Prerequisites:
• Both the machines need to be of the same size (same size VM or same physical
machine)
• The CMX software version on both of them should be the same.
• They must be on the same subnet.
• System uses a heartbeat and (optionally a Virtual IP) check pointing between
two systems, active and standby.
• Failover time about 7 mins
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Enable HA from CMX Web Interface
• In CMX navigate to the System tab and click the Settings icon. This will display a modal dialog with a
variety of settings in CMX. Select the High Availability option to display the options required to enable
High Availability.
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
CMX HA Upgrade
• CMX can NOT be upgraded to a new software release while high availability is
enabled. With a high availability setup do the following:
1. Disable High Availability.
2. CMX can now be upgraded on secondary and primary servers now. The
recommendation is to upgrade the secondary first. Once a successful upgrade has
completed the primary can be upgraded. Both servers can be upgraded in parallel if
desired.
• Upgrade Secondary Server
• Upgrade Primary Server
3. Enable High Availability
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
HA Design and Deployment Practices
HA Design and Deployment Practices
Connecting an AP to the wired network
Recommendations:
• Create redundancy throughout the access layer by
homing APs to different switches
• If the AP is in Local mode, configure the port as
access with SPT PortFast, BPDU guard, etc.
• If the AP is in Flex mode and Local Switching,
configure the port as trunk and allow only the
VLANs you need
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
HA Design and Deployment Practices
Connecting a Controller to the wired network: options
• Same as Option 1
WLC
• Spread ports across VSS members
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
Connecting a Controller to the wired network
Single AireOS Controllers (3500/5500/8500) Distribution
Layer Switch/Stack
Option 1: to single Modular Switch or StackWise
Identical configuration on WLC and switch side (EC mode, trunk mode,
allowed VLANs, native VLAN, etc.)
EC mode: only mode “ON” supported; no LACP, PAgP
EC load-balancing: no restriction for 3500/5500/8500
• Recommended to include L3 and L4 port for better hash results Trunk
EC load-balancing for WISM2: Port-channel
• Need to set the EC load balancing method on the switch to “src-dest-IP”. Use CLI
“port-channel load-balance src_dest_ip”
Note: no STP supported on AireOS Controllers. Do not disable it on switch
side. Use “switchport portfast trunk”
AireOS based WLC
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
Connecting a Controller to the wired network
Single AireOS Controllers (3500/5500/8500) Distribution
Layer Switch/Stack
Option 1: to single Modular Switch or StackWise
Identical configuration on WLC and switch side (EC mode, trunk mode,
port-channel load-balance src-dst-mixed-ip-port
allowed VLANs, native
! VLAN, etc.)
EC mode: only mode “ON” supported;
interface no LACP, PAgP
GigabitEthernet1/0/1
EC load-balancing: no restriction
description for 5508/2500/7500/8500
to_WLC-1
• Recommended to include L3trunk
switchport and L4 port for better
encapsulation hash results
dot1q Trunk
• On the switch use: “port-channel
switchport trunk load-balance
allowed vlan src-dst-mixed-ip-port”
10,11,20,30,40 Port-channel
EC load-balancing for WISM2:mode
switchport trunk
• Need to set the EC load balancing
channel-group method
1 mode on on the switch to “src-dest-IP”. Use CLI
“port-channel load-balance src_dest_ip”
switchport portfast trunk
• For Catalyst 6500 with PFC3 use “port-channel load-balance src-dst-ip exclude
vlan” (command supported in 12.2(33)SXH6 and 12.2(33)SXI3 and above)
Note: no STP supported on AireOS Controllers. Do not disable it on switch AireOS based WLC
side. Use “switchport portfast trunk”
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Connecting a Controller to the wired network
Catalyst VSS Pair
Option 2: to a VSS pair
Recommended
Network Design
WLC
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
Design & Deployment Practice
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
HA Design and Deployment Practices Recommended
Network
Connecting AireOS HA Pair to the wired network Design
Same configuration
on both Po1 and Po2 Catalyst VSS Pair
Option 2: to VSS pair
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 88
HA Design and Deployment Practices
Connecting AireOS HA Pair to the wired network Distribution
Layer Switches
AireOS AireOS
Active WLC Standby WLC
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
HA Design and Deployment Practices
Campus
HA Design and Deployment Practices
Campus
• What is the acceptable downtime for your business applications?
• Are 30 sec to few minutes ok? Go with N+1 to have more deployment flexibility
• No downtime? Go with AireOS Stateful Switchover
• SSO: what is the downtime to upgrade a HA pair and how to minimise it?
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
HA Design and Deployment Practices
Upgrading an SSO Pair - standard procedure
Active
8.0 Standby 1. Download the new code on Active
7.6 7.6 2. Code transferred to Standby:
Do NOT reboot at this time!
Campus/WAN
CAPWAP tunnel
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 93
HA Design and Deployment Practices
Upgrading an SSO Pair - Standard procedure
Active
8.0 Standby
8.0 1. Download the new code on Active
7.6 7.6 2. Code transferred to Standby
3. Pre-download software on APs
4. Swap the images on APs
5. Reboot the HA pair
Campus/WAN • APs will reboot and join when Active is UP
Active
8.5 Standby backup 1. Download the new code on Active
8.3 8.3 8.5 2. Code transferred to Standby
Do NOT reboot at this time!
3. Pre-download software on AP Group
Campus/WAN
CAPWAP tunnel
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 95
HA Deployment Best Practices
Upgrading an SSO Pair – Efficient procedure using N+1
Active
8.5
8.2 8.5 Standby backup 1. Download the new code on Active
8.3 8.3 8.5 2. Code transferred to Standby
Do NOT reboot at this time!
3. Pre-download software on AP Group and
swap the image
Campus/WAN
CAPWAP tunnel
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 96
HA Deployment Best Practices
Upgrading an SSO Pair – Efficient procedure using N+1
Active
8.5
8.2 8.5 Standby backup 1. Download the new code on Active
8.3 8.3 8.5 2. Code transferred to Standby
Do NOT reboot at this time!
3. Pre-download software on AP Group and
swap the image
Campus/WAN 4. Configure APs to join the backup controller
• This can be automated using Prime
CAPWAP tunnel
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
HA Deployment Best Practices
Upgrading an SSO Pair – Efficient procedure
When all the APs are moved to backup:
Active
8.5 8.5 Standby backup 7. Reboot the HA pair
Workflow
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 100
Scheduled AP Upgrade with Prime 3.3
Cisco Prime 3.3
Primary N+1
WLC WLC
Trigger Rolling Upgrade Already upgraded N+1 Version: X+1
Version :X+1
Version: X controller
8.3
eg. 8.5 eg. 8.5
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 101
Rolling AP Upgrade
(Upgrade Secondary (N+1) WLC
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 102
Rolling AP Upgrade
Upgrade Groups
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 103
Rolling AP Upgrade
Upgrade Groups
• Create a new group
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 104
Rolling AP Upgrade
Point AP’s to the Secondary (N+1) WLC 8.3.111.0
Run Now/Schedule
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 105
Rolling AP Upgrade
Once you Submit …
A Job is created
Take the 1st group of AP’s, point them to the Secondary WLC and reboot the AP’s and wait till then come
up
Take the next group of AP’s, point them to the Secondary WLC and reboot the AP’s and so on ..
After all the AP's are registered to the Secondary WLC, reboot the Primary WLC which comes back with
the new image
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 106
Rolling AP Upgrade
Moving the AP’s back to the Primary
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 107
Rolling AP Upgrade
Job Status
• Provides step-by-
step WLC status
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 108
HA Design and Deployment Practice
Branch
HA Design and Deployment Practices
Branch Redundancy: Centralised Controller & Flex (local switching)
HA considerations:
Data Centre • if WAN fails, Flex APs allow a level of redundancy:
Campus Services
• Local Data path stays UP
• Control plane features go down: RRM, CleanAir,
5500 / 8500/ 7510 WebAuth, etc.
ISE • WLC SSO at central site provides Control plane
survivability
Si
WAN
PI
Si
Design considerations:
• WAN requirements:
• General: 24kbps per AP, 300 ms RTT (Data)
Remote • More info here: http://tiny.cc/FlexDG
location
• APs are in Flex Mode = less features and functionalities
compare to Local Mode. Key features missing:
• No L3 roaming, No Bonjour Gateway
• Flex Groups have AP count limit
• 100 APs for 3504/5520/8540
FlexConnect APs • Switchport as Trunk if SSID/VLAN separation needed
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 110
HA Design and Deployment Practices
Branch Redundancy: Local Controller, Flex local switching & Central backup Controller
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 111
Key Takeaways
Key Takeaways
• High Availability for Wireless is a multi level approach, starting from Level 1 (RF)
• You have different solutions to chose based on the downtime that is acceptable
for your business application
• Cisco Controller SSO eliminates the network downtime upon a controller failure
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 113
VoD Links
Faster Innovation
• Cisco CMX Solution https://www.youtube.com/watch?v=KQRb8vfU0qM • Fastlane App Demo https://www.youtube.com/watch?v=N1QMUcv3aRQ
• Cisco Dual 5GHz Wi-Fi https://www.youtube.com/watch?v=mbpjiETvDXc • Cisco Aironet Plug and Play Cloud Redirection
Reduce https://www.youtube.com/watch?v=W7fBZ6xfSxw
• Cisco Aironet Series – Flexible Radio Assignment • WLC Advanced UI Client Troubleshooting
https://www.youtube.com/watch?v=K_-BykT_YIM https://www.youtube.com/watch?v=dZVxI6jOx_Q
BRKEWN-3014 © 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public 114
Q&A
Complete Your Online
Session Evaluation
• Give us your feedback and
receive a Cisco Live 2018 Cap
by completing the overall event
evaluation and 5 session
evaluations.
• All evaluations can be completed
via the Cisco Live Mobile App.
Don’t forget: Cisco Live sessions will be
available for viewing on demand after the
event at www.CiscoLive.com/Global.
© 2018 Cisco and/or its affiliates. All rights reserved. Cisco Public
Thank you