SlideShare a Scribd company logo
1 of 75
#ATM15 |
The Aruba Tech Support Top 10 Tips
Tarun George & Gowri Amujuri
March 2015
@ArubaNetworks
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved2#ATM15 |
WLAN Design, Configuration and Troubleshooting
Tips by TAC
@ArubaNetworks
3 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• Segmental Troubleshooting
• AP Stability and System profile Optimization
• Optimize load on processes
• Datapath Debugging
• Deployment Tips
Aruba OS
@ArubaNetworks
4 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
#1
Segmental Troubleshooting
@ArubaNetworks
5 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Segmental Troubleshooting
Segmental Troubleshooting gains.
# Faster root cause analysis.
# One time Data Collection
# Bring focus on the smallest segment in the network within our control.
@ArubaNetworks
6 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Segmental Troubleshooting
Where do we start if
we are unsure of the
exact cause of the
current issue being
faced?
@ArubaNetworks
7 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Segmental Troubleshooting
User
show tech-support user mac <Mac Address>
tar logs user mac <User Mac > tech-support
User Debugging
Logging Level debugging user-debug <Mac
Address>
@ArubaNetworks
8 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Segmental Troubleshooting
AP
show ap tech-support ap-name <Name of AP>
show ap debug counters
show ap bss-table ap-name
show ap debug system-status ap-name
@ArubaNetworks
9 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Segmental Troubleshooting
Controller
show tech-support
tar log tech-support
Outside world
Debugging for Specific process/Sub-cat.. (Explained)
Pcap
show interface gigabitethernet <slot/module/port>
Network Diagram
Note: Show tech-support <filename> Store output in file.
@ArubaNetworks
10 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Segmental Troubleshooting.. Processes
show process monitor statistics
Process Monitor Statistics
Name State Restarts Allowed Restarts Timeout Value Timeout Chances Time Started
/mswitch/bin/dbstart PROCESS_RUNNING 8 0 240 3 Sat Feb 28 21:31:55 2015
/mswitch/bin/packet_filter PROCESS_RUNNING - 0 240 3 Sat Feb 28 21:31:56 2015
Mdns , httpd_wrap , Authmgr ,STM , WMS , cfgm , dhcp
@ArubaNetworks
11 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
#2
AP Stability and System Profile Optimization
@ArubaNetworks
12 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
AP Stability and System Profile Optimization
AP System Status.
Campus and Remote APs have similar challenges to stay connected to the
controller.
Health Check of the AP is vital, since it can trigger
client and controller anomalies.
Show AP debug system-status ap-name <Name of AP>
@ArubaNetworks
13 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
AP Stability and System Profile Optimization
• Reboot Information
DHCP/Controller/Keep Alive miss
• Rebootstrap Information
Date Time Reason (Latest 10)
LMS Change/Heartbeat Miss
• HA Failover Information
Date Time Reason (Latest 10)
@ArubaNetworks
14 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
AP Stability and System Profile Optimization
• Recent Control Messages from AP to Controller
Date Time Message Description
Sun Mar 1 12:29:49 2015(164 secs ago): SENT REQ
type=KEEPALIVE len=45 peer=10.163.196.72 seq_num=4567
num_attempts=1 rtt=0 secs
• Rebootstrap LMS
• Crash Information
@ArubaNetworks
15 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
AP Stability and System Profile Optimization
• CPU and Memory Usage
Timestamp CPU Util(%) Memory Util(%)
2015-03-01 12:32:27 2 24
• Peak CPU Util in the last one hour
Timestamp CPU Util(%) Memory Util(%)
2015-03-01 12:19:25 3 24
@ArubaNetworks
16 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
AP Stability and System Profile Optimization
Heartbeat Stats of Serving Controller
Heartbeats Sent Sent Seqnum Heartbeats Received Rcvd Seqnum MTUs sent Misc sent Measurement Duration
2690183 25824 2667575 25824 22607 0 since last rebootstrap
2690193 n/a 2667575 n/a 22607 0 total since bootup
Interface counters
Interface Rx_pkts Rx_errors Rx drops Tx_pkts Tx_errors Tx_drops Resets
wifi0 3209433 16822381 2230363 236918 61 0 0
wifi1 4096977 2070224 4095468 2242763 58 0 11
@ArubaNetworks
17 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
AP Stability and System Profile Optimization
MTU Discovery
Probes Responses Last Sent Last Rcvd
45214 22607 2712890 2712890
Switch MTU, 1500
Ethernet bonding
SlaveId Name Link State #LinkFails Ethernet Duplex/Speed Settings
Autoneg Speed (Mbps) Duplex Iface
0 eth0 UP ACTIVE 0 on 1000 Full eth0
eth1 DOWN STANDBY 0 on 10 Half eth1
@ArubaNetworks
18 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
AP Stability and System Profile Optimization
Controller Information
Item Value
Primary LMS 10.163.196.72
Backup LMS 10.163.196.71
AP to Active Controller Message Information
Item Value
AP state REGISTERED
Power Status
Operational State : Unknown
Current HW State POE-AT: No restrictions
@ArubaNetworks
19 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
AP Stability and System Profile Optimization
MTU Discovery
Probes Responses Last Sent Last Rcvd
45214 22607 2712890 2712890
Switch MTU, 1500
Ethernet bonding
SlaveId Name Link State #LinkFails Ethernet Duplex/Speed Settings
Autoneg Speed (Mbps) Duplex Iface
0 eth0 UP ACTIVE 0 on 1000 Full eth0
eth1 DOWN STANDBY 0 on 10 Half eth1
@ArubaNetworks
20 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
AP Stability Optimizations
@ArubaNetworks
21 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
AP Stability Optimizations
Heartbeat DSCP: Assign a DSCP value to AP heartbeats to prioritize heartbeats traveling over low-speed links. The
supported range is 0-63, and the default value is 0.
Bootstrap threshold: Number of consecutive missed heartbeats on a GRE tunnel (heartbeats are sent once per second on each
tunnel) before an AP rebootstraps. On the controller, the GRE tunnel timeout is 1.5 x bootstrap-threshold; the tunnel is torn
down after this number of seconds of inactivity on the tunnel.
SAP MTU: Maximum Transmission Unit, in bytes, on the wired link for the AP.
Spanning Tree: Select this checkbox to enable the Spanning Tree protocol.
@ArubaNetworks
22 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
# 3
Optimize load on processes
@ArubaNetworks
23 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
HTTPD
Stress on the webserver can be because of number of sessions in the initial role for
guest access. This is either because of large certificate (Key Length 2048 or 4096) that
are used by the server or a large number of devices (phones/Tablets with APPs) that
generate HTTP/HTTPS sessions and get re-directed to the web-server.
show web-server profile
Web Server Configuration
Parameter Value
SSL/TLS Protocol Config tlsv1
Captive Portal Certificate GUEST-AUTH
User session timeout <30-3600> (seconds) 3600
Maximum supported concurrent clients <25-320> 75
Enable WebUI access on HTTPS port (443) true
Enable bypass captive portal landing page false
@ArubaNetworks
24 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
HTTPD
show web-server statistics
Web Server Statistics:
Current Request Rate: 1 Req/Sec
Current Traffic Rate: 1 KB/Sec
Busy Connection Slots: 7
Available Connection Slots: 68
Total Requests Since Up Time: 284
Total Traffic Since Up Time: 1122 KB Avg.
Request Rate Since Up Time: 1 Req/Sec Avg.
Traffic Rate Since Up Time: 6144 Bytes/Sec
Server Scoreboard: _____________KKKKKK_W_____________
Scoreboard Key: _ - Waiting for Connection, s -
Starting up R - Reading Request, W - Sending
Reply K - Keepalive, D - DNS Lookup C -
Closing connection, L - Logging G - Gracefully
finishing, I - Idle cleanup of worker . - Open slot
with no current process
@ArubaNetworks
25 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
STM and WMS
STM
Station Management is responsible for all AP information and Station information. This process can be over
run if there is,
# Aggressive polling from Airwave/SNMP servers for Wlan tables.
# Network wide AP reboot and bootstraps
# AP debug scripts run from the controller.
WMS
IDS/IPS events and frequent AP bootstraps could lead to WMS being busy. WMS is actively looking for RF
information of WiFi devices(Rogue/Valid/Interfering).
@ArubaNetworks
26 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Mitigation
Use AMON
WMS Offload to Airwave.
Reduce SNMP polling or increase the polling period
Disable WMS functionality if you do not require IDS/IPS functionality.
@ArubaNetworks
27 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
# 4
Datapath Debugging
@ArubaNetworks
28 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Datapath Monitoring
Show datapath utilization
show datapath utilization
Datapath Network Processor Utilization
| Cpu utilization during past |
Cpu | 1 Sec 4 Secs 64 Secs |
10 | 99% | 99% | 99% |
11 | 0% | 0% | 0% |
12 | 0% | 0% | 0% |
13 | 0% | 0% | 0% |
14 | 0% | 0% | 0% |
15 | 0% | 0% | 0% |
16 | 0% | 0% | 0% |
show datapath frame 10
|SUM/| | | |
|CPU | Addr | Description Value |
+----+------+-----------------------------------------------------+
| 10 | [00] | Allocated Frames 1040|
| 10 | [01] | Max Allocated Frames 2208 |
| 10 | [03] | Unknown Unicast 147074970|
| 10 | [34] | Flood Frames 1506164167|
+----+------+-----------------------------------------------------+
| 10 | [00] | Rx Frames 635394472|
| 10 | [01] | Rx Bytes 1864525959|
| 10 | [02] | Tx Frames 1240985989|
+----+------+-----------------------------------------------------+
@ArubaNetworks
29 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Datapath Bandwidth Management
show datapath bwm
Datapath Bandwidth Management Table Entries
Type Id Bits/sec Policed Bytes Bytes Flags CPU Status
---- ---- --------- ---------- ------- ----------- ------- ------- ------
0 1 20000000 0 78125 0/0 9 ALLOCATED
0 2 4000000 0 15625 0/0 9 ALLOCATED
0 3 160000000 0 624890 0/0 9 ALLOCATED
0 4 4000000 0 15625 0/0 9 ALLOCATED
0 5 2000128 0 7813 0/0 9 ALLOCATED
0 6 2000128 0 7813 0/0 9 ALLOCATED
0 7 2000128 0 7813 0/0 9 ALLOCATED
Firewall:
Rate limit CP untrusted ucast traffic Enabled 20 Mbps
Rate limit CP untrusted mcast traffic Enabled 4 Mbps
Rate limit CP trusted ucast traffic Enabled 160 Mbps
Rate limit CP trusted mcast traffic Enabled 4 Mbps
Rate limit CP route traffic Enabled 2 Mbps
Rate limit CP session mirror traffic Enabled 2 Mbps
Rate limit CP auth process traffic Enabled 2 Mbps
@ArubaNetworks
30 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
CP and DP Packet Capture
• Wifi -Client
packet-capture datapath wifi-client aa:aa:aa:aa:aa:aa all
• VIA client/RAP
packet-capture datapath ipsec <peer-ip>
• Generic traffic to controller
packet-capture controlpath tcp/udp 4343
@ArubaNetworks
31 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
# 5
@ArubaNetworks
Deployment Tips
Missing optimizations
32 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Deployment Tips
Honey Comb Pattern
Wireless
Local Probe Threshold = 25
Transmit Power of AP 5Ghz Min Tx – 12 Max Tx – 15
2.4 Ghz Min Tx – 6 Max Tx – 9
Avoid Asymmetric RF
The difference between minimum and maximum Tx power on
the same radio should not be more than 6dbm
DMO Enable
Basic and Beacon rate
802.11a 5Ghz – 24
802.11g 2.4Ghz – 12
80 Mhz Channel bonding - DFS Channels
@ArubaNetworks
33 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Deployment Tips.. Contd
GRE Stripping IP - VRRP for LMS and Stripping IP
Jumbo Frames - Enabled
802.3at
Airgroup
Dot1x
OKC
Validate PMK ID
802.11r/k/v
EAPOL Rate Optimization
@ArubaNetworks
34 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Deployment Tips… ASE
https://ase.arubanetworks.com/
@ArubaNetworks
35 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Deployment Tips..
ASE for troubleshooting
@ArubaNetworks
36#ATM15 |
Network Services
AirWave
ClearPass
@ArubaNetworks
37 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
# 6
ClearPass Platform: System Cleanup Options
@ArubaNetworks
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved38#ATM15 |
ClearPass Platform: System Cleanup Options
• Free disk space threshold is a config in Cluster Wide Service Parameter. Default 30%
• A system cron job runs every hour and checks the disk utilization. If the free space falls below the
configured threshold, an alert is logged into the system. NOW in addition, the following aggressive
cron cleans up anything more than 1 day old in version 6.5 of CPPM
• Log database records
• Core files
• System load monitor files
• Application and system log files
• Auto and manual backup files
• Stored reports
• Expired guest accounts
• Audit records
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved39#ATM15 |
ClearPass Platform: System Cleanup Options
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved40#ATM15 |
ClearPass Platform: System Cleanup Options
We also introduced some new CLI commands
– Check on disk-space and memory usage - “show sysinfo”…
– system cleanup [# of days to retain] **This is an on-demand task
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved41#ATM15 |
ClearPass Platform: System Cleanup Options
• Same command function also exist in the GUI
– Remember this is an on-demand task
42 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
# 7
@ArubaNetworks
ClearPass Platform : Graphite
43 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• Graphite is a new reporting tool to compliment Insight in CPPM from 6.3 version.
• Graphite runs on every node irrespective of standalone or cluster and statistics can be viewed
from any node.
• Performance monitoring Display is disabled by default and should be enabled manually and set
access permission levels accordingly.
• To access Graphite data, use the URL https://<CPPM IP Address>/graphite
ClearPass Platform : Graphite
44 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• Make sure Performance monitoring is enabled from GUI
ClearPass Platform : Graphite
45 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• Setting up access to Graphite from CPPM UI
ClearPass Platform : Graphite
46 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• We can allow or deny any networks to access Graphite for a node or cluster.
• Make sure stats collection is set true True under Service parameters.
ClearPass Platform : Graphite
47 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
ClearPass Platform : Graphite
48 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
ClearPass Platform : Graphite
49 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
# 8
ClearPass : Upgrade Utility Tool
@ArubaNetworks
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved50#ATM15 |
ClearPass : Upgrade Utility Tool
• The Cluster Upgrade Tool is a simple user interface that automates the upgrade procedure
for a ClearPass cluster.
• When the upgrade is initiated, no manual actions are required until all selected nodes have
been upgraded.
• The Upgrade Tool is not available while the publisher is rebooted and migrating the
Configuration Database.
• The Upgrade Tool will not detect nodes that were upgraded manually without the tool.
• If a configured standby publisher node was manually upgraded without the tool, the Upgrade
Tool will not restore the state of the standby publisher configuration.
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved51#ATM15 |
ClearPass : Upgrade Utility Tool
• The Cluster Upgrade Tool is released as a patch update. It can be downloaded and installed
either through Policy Manager’s Software Updates portal, or from the Aruba Support portal.
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved52#ATM15 |
ClearPass : Upgrade Utility Tool
• Log in to Policy Manager on the publisher node and go to Administration > Agents and Software
>Updates > Software Updates.
• When the installation is complete, the Admin service will be restarted. You do not need to reboot.
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved53#ATM15 |
ClearPass : Upgrade Utility Tool
• Before you begin the upgrade, the upgrade image must be present on the publisher node of the
cluster.
• Download the upgrade image to the publisher under Software updates
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved54#ATM15 |
ClearPass : Upgrade Utility Tool
• To monitor the progress of the other nodes in the cluster, wait until the database migration is
complete and then log in to the tool again.
• Change the url to https://CPPM IP Address/upgrade
• We should see all the subscribers status that are in sync.
• The list of subscribers will be present and subscriber upgrades will go in parallel.
• ‘Start Upgrade’ to start the upgrade on the servers.
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved55#ATM15 |
ClearPass : Upgrade Utility Tool
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved56#ATM15 |
ClearPass : Upgrade Utility Tool
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved57#ATM15 |
ClearPass : Upgrade Utility Tool
• Check the logs for each node by ‘View Logs’ next to each node and we can see the progress of
patches and upgrades from publisher.
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved58#ATM15 |
ClearPass : Upgrade Utility tool
59 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
# 9
@ArubaNetworks
AirWave – VisualRF Performance Tips
60 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• Sometimes we see VisualRF takes long time to show up new AP’s to deploy on the floor plans.
• We can manually force VisualRF to poll the AP’s to get new AP or existing AP’s updated details.
• NO need to restart VisualRF to show up new AP’s.
• Change the url in AMP to https://<Airwave IP Address>/visualrf/poll_aps_now.xml
AirWave – VisualRF Performance Tips
61 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• In 8.x moved to HTML5 for VisualRF UI for faster UI interaction with backend.
• Whilst we are improving the features on the new UI, there are some features which were present
in flash and not in HTML5.
• In VisualRF > Setup page, we can switch between HTML5 and flash so that we can take
advantage of options present in both version
• Switching between HTML5 and Flash version is easy with below URL without refreshing
VisualRF.
• Change the URL to
https://Airwave IP Address/site?campus_id=6c56c239-bfba-4d19-aeca-8ec5af68b725
from
https://Airwave IP Address/vrf?campus_id=6c56c239-bfba-4d19-aeca-8ec5af68b725
AirWave – VisualRF Performance Tips
62 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
AirWave – VisualRF Performance tips
63 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
AirWave – VisualRF Performance Tips
64 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• We can change ‘vrf’ to ‘site’ on any page for VisualRF URL’s to switch to flash mode from HTML5
mode.
At times we see Heat maps not showing/updating properly in VisualRF
• We can resize the floor plan to same size so that the grid calculation happens and heat maps will
be re-drawn.
• No need to restart VisualRF for heat maps to update.
AirWave – VisualRF Performance Tips
65 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• Unlock the floor plan and go to properties and ‘Measure’
Airwave – VisualRF Performance Tips
66 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• Select the distance, click ‘OK’ and ‘Save’ without changing the distance, this will trigger floor plan
to recalculate the heatmpas.
Airwave – VisualRF Performance Tips
67 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
# 10
Airwave – Tips for Data Retention Settings
@ArubaNetworks
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved68#ATM15 |
Airwave – Tips for Data Retention Settings
• Data in AirWave is primarily stored in 2 formats:
• Postgres - an open source, relational SQL database. Usually, when you see data in tables, that
data is stored in Postgres.
• RRD Files - used for storing data that's displayed in time-sequence graphs (i.e, client count over
the last year, bandwidth used over the last month). There can be many thousands of RRD files
on a single AirWave server. One benefit of RRD is that its files have a fixed size. As data is
inserted to an RRD file (like by an AirWave monitoring process), it does not grow. A downside of
this is that the file starts using storage space as soon as it is created.
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved69#ATM15 |
Airwave – Tips for Data Retention Settings
• We can set data retention settings under AMP Setup > General page under the section ‘Historical
Data Retention’.
• Client Association and VPN Session History. This setting has a bearing on how much history we
can show in the association history on the client historical table and how much data can be
included in the user session data.
• Its recommend to keep high because the data is useful
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved70#ATM15 |
Airwave – Tips for Data Retention settings
• Inactive Client and VPN User Data. This setting determines how long we keep the information on
every client that has ever connected to the network.
• This impacts how long we keep RRD files. Keeping it low can save disk space.
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved71#ATM15 |
Airwave – Tips for Data Retention settings
• Client data retention Interval : This influences how much historical data you can see for each
client in the graphs, for example the signal quality, usage graphs on the client detail/diagnostic
page.
• It's very important to keep this low, like in the 14-31 days range.
• This is especially important in public wi-fi deployments that will have lots of unique users.
• This setting controls what size RRD files are created to store per-user historical signal, usage,
goodput, health and other metrics.
• Keeping it low doesn't impact device, group and folder-level monitoring, and it doesn't have any
negative impact on reports. It only impacts the graphs on the client Detail and Diagnostic pages.
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved72#ATM15 |
Airwave – Tips for Data Retention settings
• By default Rogues are kept forever which will impact the overall
system performance and for RAPIDS page load.
• It also impacts VisualRF for Rogue calculation if it has thousands
of Rogue devices.
• This is especially important in public wi-fi deployments that have
open SSID and lot of nearby devices are detected as Rogues
• Setting the value to low as 14 days will greatly help.
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved73#ATM15 |
Airwave – Tips for Data Retention settings
• Airwave by default has 20+ Reports which runs daily.
• Keep Reports that are needed for the environment and delete/disable the default reports.
• Report retention setting can be costly in high dense environments especially for disk space.
• This increase the nightly backup file size, nightly maintenance time and report generation time.
• Exporting the reports via .csv or .pdf or emailing them is a good option.
• Keeping the retention value will have the pickled client tables not to grow huge in size and makes
report generation faster.
74 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Questions
@ArubaNetworks
THANK YOU
75#ATM15 | @ArubaNetworks

More Related Content

What's hot

Customer Presentation - Aruba Wi-Fi Overview (1).PPTX
Customer Presentation - Aruba Wi-Fi Overview (1).PPTXCustomer Presentation - Aruba Wi-Fi Overview (1).PPTX
Customer Presentation - Aruba Wi-Fi Overview (1).PPTXssuser5824cf
 
6 understanding aruba rf issues
6 understanding aruba rf issues6 understanding aruba rf issues
6 understanding aruba rf issuesVenudhanraj
 

What's hot (20)

Optimizing Aruba WLANs for Roaming Devices
Optimizing Aruba WLANs for Roaming DevicesOptimizing Aruba WLANs for Roaming Devices
Optimizing Aruba WLANs for Roaming Devices
 
Managing and Optimizing RF Spectrum for Aruba WLANs
Managing and Optimizing RF Spectrum for Aruba WLANsManaging and Optimizing RF Spectrum for Aruba WLANs
Managing and Optimizing RF Spectrum for Aruba WLANs
 
Roaming behavior and Client Troubleshooting
Roaming behavior and Client TroubleshootingRoaming behavior and Client Troubleshooting
Roaming behavior and Client Troubleshooting
 
Useful cli commands v1
Useful cli commands v1Useful cli commands v1
Useful cli commands v1
 
EMEA Airheads - What does AirMatch do differently?v2
 EMEA Airheads - What does AirMatch do differently?v2 EMEA Airheads - What does AirMatch do differently?v2
EMEA Airheads - What does AirMatch do differently?v2
 
EMEA Airheads- ArubaOS - Cluster Manager
EMEA Airheads- ArubaOS - Cluster ManagerEMEA Airheads- ArubaOS - Cluster Manager
EMEA Airheads- ArubaOS - Cluster Manager
 
Access Management with Aruba ClearPass
Access Management with Aruba ClearPassAccess Management with Aruba ClearPass
Access Management with Aruba ClearPass
 
EMEA Airheads- Instant AP- Instant AP Best Practice Configuration
EMEA Airheads- Instant AP- Instant AP Best Practice ConfigurationEMEA Airheads- Instant AP- Instant AP Best Practice Configuration
EMEA Airheads- Instant AP- Instant AP Best Practice Configuration
 
EMEA Airheads- ArubaOS - Understanding Control-Plane-Security
EMEA Airheads-  ArubaOS - Understanding Control-Plane-SecurityEMEA Airheads-  ArubaOS - Understanding Control-Plane-Security
EMEA Airheads- ArubaOS - Understanding Control-Plane-Security
 
EMEA Airheads- Troubleshooting 802.1x issues
EMEA Airheads- Troubleshooting 802.1x issuesEMEA Airheads- Troubleshooting 802.1x issues
EMEA Airheads- Troubleshooting 802.1x issues
 
Base Designs Lab Setup for Validated Reference Design
Base Designs Lab Setup for Validated Reference DesignBase Designs Lab Setup for Validated Reference Design
Base Designs Lab Setup for Validated Reference Design
 
EMEA Airheads- Aruba Instant AP- VPN Troubleshooting
EMEA Airheads- Aruba Instant AP-  VPN TroubleshootingEMEA Airheads- Aruba Instant AP-  VPN Troubleshooting
EMEA Airheads- Aruba Instant AP- VPN Troubleshooting
 
Breakout - Airheads Macau 2013 - Top 10 Tips from Aruba TAC
Breakout - Airheads Macau 2013 - Top 10 Tips from Aruba TAC Breakout - Airheads Macau 2013 - Top 10 Tips from Aruba TAC
Breakout - Airheads Macau 2013 - Top 10 Tips from Aruba TAC
 
EMEA Airheads- ArubaOS - Rogue AP troubleshooting
EMEA Airheads- ArubaOS - Rogue AP troubleshootingEMEA Airheads- ArubaOS - Rogue AP troubleshooting
EMEA Airheads- ArubaOS - Rogue AP troubleshooting
 
Adapting to evolving user, security, and business needs with aruba clear pass
Adapting to evolving user, security, and business needs with aruba clear passAdapting to evolving user, security, and business needs with aruba clear pass
Adapting to evolving user, security, and business needs with aruba clear pass
 
Customer Presentation - Aruba Wi-Fi Overview (1).PPTX
Customer Presentation - Aruba Wi-Fi Overview (1).PPTXCustomer Presentation - Aruba Wi-Fi Overview (1).PPTX
Customer Presentation - Aruba Wi-Fi Overview (1).PPTX
 
Bringing up Aruba Mobility Master, Managed Device & Access Point
Bringing up Aruba Mobility Master, Managed Device & Access PointBringing up Aruba Mobility Master, Managed Device & Access Point
Bringing up Aruba Mobility Master, Managed Device & Access Point
 
6 understanding aruba rf issues
6 understanding aruba rf issues6 understanding aruba rf issues
6 understanding aruba rf issues
 
Campus Redundancy Models
Campus Redundancy ModelsCampus Redundancy Models
Campus Redundancy Models
 
EMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP DeploymentEMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP Deployment
 

Viewers also liked

The Top Eight Best Practices for Deploying XenApp and XenDesktop 7.6
The Top Eight Best Practices for Deploying XenApp and XenDesktop 7.6The Top Eight Best Practices for Deploying XenApp and XenDesktop 7.6
The Top Eight Best Practices for Deploying XenApp and XenDesktop 7.6eG Innovations
 
Aos & cppm integration & testing document for eap tls & eap peap
Aos & cppm integration & testing document for eap tls & eap peapAos & cppm integration & testing document for eap tls & eap peap
Aos & cppm integration & testing document for eap tls & eap peapJulia Ostrowski
 

Viewers also liked (15)

Aruba WLANs 101 and design fundamentals
Aruba WLANs 101 and design fundamentalsAruba WLANs 101 and design fundamentals
Aruba WLANs 101 and design fundamentals
 
RF characteristics and radio fundamentals
RF characteristics and radio fundamentalsRF characteristics and radio fundamentals
RF characteristics and radio fundamentals
 
The Top Eight Best Practices for Deploying XenApp and XenDesktop 7.6
The Top Eight Best Practices for Deploying XenApp and XenDesktop 7.6The Top Eight Best Practices for Deploying XenApp and XenDesktop 7.6
The Top Eight Best Practices for Deploying XenApp and XenDesktop 7.6
 
Network Management with Aruba AirWave
Network Management with Aruba AirWaveNetwork Management with Aruba AirWave
Network Management with Aruba AirWave
 
Wi-Fi Security Fundamentals
Wi-Fi Security FundamentalsWi-Fi Security Fundamentals
Wi-Fi Security Fundamentals
 
Getting the most out of the Aruba Policy Enforcement Firewall
Getting the most out of the Aruba Policy Enforcement FirewallGetting the most out of the Aruba Policy Enforcement Firewall
Getting the most out of the Aruba Policy Enforcement Firewall
 
A-to-Z design guide for the all-wireless workplace
A-to-Z design guide for the all-wireless workplaceA-to-Z design guide for the all-wireless workplace
A-to-Z design guide for the all-wireless workplace
 
Cisco switch setup with cppm v1.2
Cisco switch setup with cppm v1.2Cisco switch setup with cppm v1.2
Cisco switch setup with cppm v1.2
 
EMEA Airheads ClearPass guest with MAC- caching using Time Source
EMEA Airheads ClearPass guest with MAC- caching using Time SourceEMEA Airheads ClearPass guest with MAC- caching using Time Source
EMEA Airheads ClearPass guest with MAC- caching using Time Source
 
Fast-track your career by going from wireless to mobility engineer
Fast-track your career by going from wireless to mobility engineerFast-track your career by going from wireless to mobility engineer
Fast-track your career by going from wireless to mobility engineer
 
Aruba clearpass ebook_chpt1_final
Aruba clearpass ebook_chpt1_finalAruba clearpass ebook_chpt1_final
Aruba clearpass ebook_chpt1_final
 
Top 10 tips_aruba_tac_madison lee
Top 10 tips_aruba_tac_madison leeTop 10 tips_aruba_tac_madison lee
Top 10 tips_aruba_tac_madison lee
 
Aos & cppm integration & testing document for eap tls & eap peap
Aos & cppm integration & testing document for eap tls & eap peapAos & cppm integration & testing document for eap tls & eap peap
Aos & cppm integration & testing document for eap tls & eap peap
 
Aruba wireless and clear pass 6 integration guide v1.3
Aruba wireless and clear pass 6 integration guide v1.3Aruba wireless and clear pass 6 integration guide v1.3
Aruba wireless and clear pass 6 integration guide v1.3
 
Packets never lie: An in-depth overview of 802.11 frames
Packets never lie: An in-depth overview of 802.11 framesPackets never lie: An in-depth overview of 802.11 frames
Packets never lie: An in-depth overview of 802.11 frames
 

Similar to The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting tips

Mobile Experience Management and Network Services Health Check with Aruba Air...
Mobile Experience Management and Network Services Health Check with Aruba Air...Mobile Experience Management and Network Services Health Check with Aruba Air...
Mobile Experience Management and Network Services Health Check with Aruba Air...Aruba, a Hewlett Packard Enterprise company
 
Nfd18 anuta-networks
Nfd18 anuta-networksNfd18 anuta-networks
Nfd18 anuta-networksKiran Sirupa
 
Extend mobility to remote branch networks with Aruba's new cloud services con...
Extend mobility to remote branch networks with Aruba's new cloud services con...Extend mobility to remote branch networks with Aruba's new cloud services con...
Extend mobility to remote branch networks with Aruba's new cloud services con...Aruba, a Hewlett Packard Enterprise company
 
CA Unified Infrastructure Management Network Performance Management Capabili...
 CA Unified Infrastructure Management Network Performance Management Capabili... CA Unified Infrastructure Management Network Performance Management Capabili...
CA Unified Infrastructure Management Network Performance Management Capabili...CA Technologies
 
Quick QUIC Technical Update (2017)
Quick QUIC Technical Update (2017)Quick QUIC Technical Update (2017)
Quick QUIC Technical Update (2017)Taisuke Yamada
 
Approaching hyperconvergedopenstack
Approaching hyperconvergedopenstackApproaching hyperconvergedopenstack
Approaching hyperconvergedopenstackIkuo Kumagai
 
Real World Problem Solving Using Application Performance Management 10
Real World Problem Solving Using Application Performance Management 10Real World Problem Solving Using Application Performance Management 10
Real World Problem Solving Using Application Performance Management 10CA Technologies
 
[Advantech] ADAM-3600 training kit and Taglink
[Advantech]  ADAM-3600 training kit and Taglink[Advantech]  ADAM-3600 training kit and Taglink
[Advantech] ADAM-3600 training kit and TaglinkMing-Hung Hseih
 
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERS
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERSROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERS
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERSDeepak Shankar
 
Reconsider TCPdump for Modern Troubleshooting
Reconsider TCPdump for Modern TroubleshootingReconsider TCPdump for Modern Troubleshooting
Reconsider TCPdump for Modern TroubleshootingAvi Networks
 
BRKRST-3068 Troubleshooting Catalyst 2K and 3K.pdf
BRKRST-3068  Troubleshooting Catalyst 2K and 3K.pdfBRKRST-3068  Troubleshooting Catalyst 2K and 3K.pdf
BRKRST-3068 Troubleshooting Catalyst 2K and 3K.pdfssusercbaa33
 
Scalable Enterprise Ready Neutron Networking with Nuage Networks
Scalable Enterprise Ready Neutron Networking with Nuage NetworksScalable Enterprise Ready Neutron Networking with Nuage Networks
Scalable Enterprise Ready Neutron Networking with Nuage NetworksScott Sneddon
 
VMAX : répondez aux niveaux de services applicatifs les plus élevés
VMAX : répondez aux niveaux de services applicatifs les plus élevésVMAX : répondez aux niveaux de services applicatifs les plus élevés
VMAX : répondez aux niveaux de services applicatifs les plus élevésRSD
 

Similar to The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting tips (20)

Mobile Experience Management and Network Services Health Check with Aruba Air...
Mobile Experience Management and Network Services Health Check with Aruba Air...Mobile Experience Management and Network Services Health Check with Aruba Air...
Mobile Experience Management and Network Services Health Check with Aruba Air...
 
ClearPass design scenarios that solve the toughest security policy requirements
ClearPass design scenarios that solve the toughest security policy requirementsClearPass design scenarios that solve the toughest security policy requirements
ClearPass design scenarios that solve the toughest security policy requirements
 
Nfd18 anuta-networks
Nfd18 anuta-networksNfd18 anuta-networks
Nfd18 anuta-networks
 
Extend mobility to remote branch networks with Aruba's new cloud services con...
Extend mobility to remote branch networks with Aruba's new cloud services con...Extend mobility to remote branch networks with Aruba's new cloud services con...
Extend mobility to remote branch networks with Aruba's new cloud services con...
 
CA Unified Infrastructure Management Network Performance Management Capabili...
 CA Unified Infrastructure Management Network Performance Management Capabili... CA Unified Infrastructure Management Network Performance Management Capabili...
CA Unified Infrastructure Management Network Performance Management Capabili...
 
Unified access with Aruba Mobility Access Switches – Live Demo
Unified access with Aruba Mobility Access Switches – Live DemoUnified access with Aruba Mobility Access Switches – Live Demo
Unified access with Aruba Mobility Access Switches – Live Demo
 
Quick QUIC Technical Update (2017)
Quick QUIC Technical Update (2017)Quick QUIC Technical Update (2017)
Quick QUIC Technical Update (2017)
 
Performance vision Version 2.15 news
Performance vision Version 2.15 newsPerformance vision Version 2.15 news
Performance vision Version 2.15 news
 
Design Fundamentals for Remote and Branch Access Networks
Design Fundamentals for Remote and Branch Access NetworksDesign Fundamentals for Remote and Branch Access Networks
Design Fundamentals for Remote and Branch Access Networks
 
Approaching hyperconvergedopenstack
Approaching hyperconvergedopenstackApproaching hyperconvergedopenstack
Approaching hyperconvergedopenstack
 
Real World Problem Solving Using Application Performance Management 10
Real World Problem Solving Using Application Performance Management 10Real World Problem Solving Using Application Performance Management 10
Real World Problem Solving Using Application Performance Management 10
 
Time Synchronisation
Time SynchronisationTime Synchronisation
Time Synchronisation
 
[Advantech] ADAM-3600 training kit and Taglink
[Advantech]  ADAM-3600 training kit and Taglink[Advantech]  ADAM-3600 training kit and Taglink
[Advantech] ADAM-3600 training kit and Taglink
 
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERS
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERSROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERS
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERS
 
Reconsider TCPdump for Modern Troubleshooting
Reconsider TCPdump for Modern TroubleshootingReconsider TCPdump for Modern Troubleshooting
Reconsider TCPdump for Modern Troubleshooting
 
BRKRST-3068 Troubleshooting Catalyst 2K and 3K.pdf
BRKRST-3068  Troubleshooting Catalyst 2K and 3K.pdfBRKRST-3068  Troubleshooting Catalyst 2K and 3K.pdf
BRKRST-3068 Troubleshooting Catalyst 2K and 3K.pdf
 
Puertos utilizados sap
Puertos utilizados sapPuertos utilizados sap
Puertos utilizados sap
 
Scalable Enterprise Ready Neutron Networking with Nuage Networks
Scalable Enterprise Ready Neutron Networking with Nuage NetworksScalable Enterprise Ready Neutron Networking with Nuage Networks
Scalable Enterprise Ready Neutron Networking with Nuage Networks
 
Thread SEP2 Talk
Thread SEP2 TalkThread SEP2 Talk
Thread SEP2 Talk
 
VMAX : répondez aux niveaux de services applicatifs les plus élevés
VMAX : répondez aux niveaux de services applicatifs les plus élevésVMAX : répondez aux niveaux de services applicatifs les plus élevés
VMAX : répondez aux niveaux de services applicatifs les plus élevés
 

More from Aruba, a Hewlett Packard Enterprise company

EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...
EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...
EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...Aruba, a Hewlett Packard Enterprise company
 

More from Aruba, a Hewlett Packard Enterprise company (20)

Airheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard AgentsAirheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
 
EMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Advance Aruba CentralEMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Advance Aruba Central
 
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.xEMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
 
EMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS SwitchEMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS Switch
 
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS SwitchEMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
 
Introduction to AirWave 10
Introduction to AirWave 10Introduction to AirWave 10
Introduction to AirWave 10
 
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS SwitchEMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
 
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.xEMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
 
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
EMEA Airheads-  Getting Started with the ClearPass REST API – CPPMEMEA Airheads-  Getting Started with the ClearPass REST API – CPPM
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
 
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)
 
Airheads Meetups: 8400 Presentation
Airheads Meetups: 8400 PresentationAirheads Meetups: 8400 Presentation
Airheads Meetups: 8400 Presentation
 
Airheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau PresentationAirheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau Presentation
 
Airheads Meetups- High density WLAN
Airheads Meetups- High density WLANAirheads Meetups- High density WLAN
Airheads Meetups- High density WLAN
 
Airheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes ArubaAirheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes Aruba
 
EMEA Airheads - Configuring different APIs in Aruba 8.x
EMEA Airheads - Configuring different APIs  in Aruba 8.x EMEA Airheads - Configuring different APIs  in Aruba 8.x
EMEA Airheads - Configuring different APIs in Aruba 8.x
 
EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
EMEA Airheads - Aruba Remote Access Point (RAP) TroubleshootingEMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
 
EMEA Airheads - Multi zone ap and centralized image upgrade
EMEA Airheads - Multi zone ap and centralized image upgradeEMEA Airheads - Multi zone ap and centralized image upgrade
EMEA Airheads - Multi zone ap and centralized image upgrade
 
EMEA Airheads- Aruba 8.x Architecture overview & UI Navigation
EMEA Airheads- Aruba 8.x Architecture overview & UI NavigationEMEA Airheads- Aruba 8.x Architecture overview & UI Navigation
EMEA Airheads- Aruba 8.x Architecture overview & UI Navigation
 
EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...
EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...
EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...
 
EMEA Airheads- ClearPass extensions and how they can help
EMEA Airheads-  ClearPass extensions and how they can helpEMEA Airheads-  ClearPass extensions and how they can help
EMEA Airheads- ClearPass extensions and how they can help
 

Recently uploaded

So einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfSo einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfpanagenda
 
Data governance with Unity Catalog Presentation
Data governance with Unity Catalog PresentationData governance with Unity Catalog Presentation
Data governance with Unity Catalog PresentationKnoldus Inc.
 
2024 April Patch Tuesday
2024 April Patch Tuesday2024 April Patch Tuesday
2024 April Patch TuesdayIvanti
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesThousandEyes
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentPim van der Noll
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersNicole Novielli
 
Time Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsTime Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsNathaniel Shimoni
 
Generative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfGenerative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfIngrid Airi González
 
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Alkin Tezuysal
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxLoriGlavin3
 
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...AliaaTarek5
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersRaghuram Pandurangan
 
Testing tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesTesting tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesKari Kakkonen
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Hiroshi SHIBATA
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxLoriGlavin3
 

Recently uploaded (20)

So einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfSo einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdf
 
Data governance with Unity Catalog Presentation
Data governance with Unity Catalog PresentationData governance with Unity Catalog Presentation
Data governance with Unity Catalog Presentation
 
2024 April Patch Tuesday
2024 April Patch Tuesday2024 April Patch Tuesday
2024 April Patch Tuesday
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software Developers
 
Time Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsTime Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directions
 
Generative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdfGenerative Artificial Intelligence: How generative AI works.pdf
Generative Artificial Intelligence: How generative AI works.pdf
 
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
 
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
(How to Program) Paul Deitel, Harvey Deitel-Java How to Program, Early Object...
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information Developers
 
Testing tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesTesting tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examples
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
 

The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting tips

  • 1. #ATM15 | The Aruba Tech Support Top 10 Tips Tarun George & Gowri Amujuri March 2015 @ArubaNetworks
  • 2. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved2#ATM15 | WLAN Design, Configuration and Troubleshooting Tips by TAC @ArubaNetworks
  • 3. 3 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • Segmental Troubleshooting • AP Stability and System profile Optimization • Optimize load on processes • Datapath Debugging • Deployment Tips Aruba OS @ArubaNetworks
  • 4. 4 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content #1 Segmental Troubleshooting @ArubaNetworks
  • 5. 5 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Segmental Troubleshooting Segmental Troubleshooting gains. # Faster root cause analysis. # One time Data Collection # Bring focus on the smallest segment in the network within our control. @ArubaNetworks
  • 6. 6 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Segmental Troubleshooting Where do we start if we are unsure of the exact cause of the current issue being faced? @ArubaNetworks
  • 7. 7 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Segmental Troubleshooting User show tech-support user mac <Mac Address> tar logs user mac <User Mac > tech-support User Debugging Logging Level debugging user-debug <Mac Address> @ArubaNetworks
  • 8. 8 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Segmental Troubleshooting AP show ap tech-support ap-name <Name of AP> show ap debug counters show ap bss-table ap-name show ap debug system-status ap-name @ArubaNetworks
  • 9. 9 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Segmental Troubleshooting Controller show tech-support tar log tech-support Outside world Debugging for Specific process/Sub-cat.. (Explained) Pcap show interface gigabitethernet <slot/module/port> Network Diagram Note: Show tech-support <filename> Store output in file. @ArubaNetworks
  • 10. 10 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Segmental Troubleshooting.. Processes show process monitor statistics Process Monitor Statistics Name State Restarts Allowed Restarts Timeout Value Timeout Chances Time Started /mswitch/bin/dbstart PROCESS_RUNNING 8 0 240 3 Sat Feb 28 21:31:55 2015 /mswitch/bin/packet_filter PROCESS_RUNNING - 0 240 3 Sat Feb 28 21:31:56 2015 Mdns , httpd_wrap , Authmgr ,STM , WMS , cfgm , dhcp @ArubaNetworks
  • 11. 11 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | #2 AP Stability and System Profile Optimization @ArubaNetworks
  • 12. 12 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | AP Stability and System Profile Optimization AP System Status. Campus and Remote APs have similar challenges to stay connected to the controller. Health Check of the AP is vital, since it can trigger client and controller anomalies. Show AP debug system-status ap-name <Name of AP> @ArubaNetworks
  • 13. 13 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | AP Stability and System Profile Optimization • Reboot Information DHCP/Controller/Keep Alive miss • Rebootstrap Information Date Time Reason (Latest 10) LMS Change/Heartbeat Miss • HA Failover Information Date Time Reason (Latest 10) @ArubaNetworks
  • 14. 14 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | AP Stability and System Profile Optimization • Recent Control Messages from AP to Controller Date Time Message Description Sun Mar 1 12:29:49 2015(164 secs ago): SENT REQ type=KEEPALIVE len=45 peer=10.163.196.72 seq_num=4567 num_attempts=1 rtt=0 secs • Rebootstrap LMS • Crash Information @ArubaNetworks
  • 15. 15 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | AP Stability and System Profile Optimization • CPU and Memory Usage Timestamp CPU Util(%) Memory Util(%) 2015-03-01 12:32:27 2 24 • Peak CPU Util in the last one hour Timestamp CPU Util(%) Memory Util(%) 2015-03-01 12:19:25 3 24 @ArubaNetworks
  • 16. 16 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | AP Stability and System Profile Optimization Heartbeat Stats of Serving Controller Heartbeats Sent Sent Seqnum Heartbeats Received Rcvd Seqnum MTUs sent Misc sent Measurement Duration 2690183 25824 2667575 25824 22607 0 since last rebootstrap 2690193 n/a 2667575 n/a 22607 0 total since bootup Interface counters Interface Rx_pkts Rx_errors Rx drops Tx_pkts Tx_errors Tx_drops Resets wifi0 3209433 16822381 2230363 236918 61 0 0 wifi1 4096977 2070224 4095468 2242763 58 0 11 @ArubaNetworks
  • 17. 17 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | AP Stability and System Profile Optimization MTU Discovery Probes Responses Last Sent Last Rcvd 45214 22607 2712890 2712890 Switch MTU, 1500 Ethernet bonding SlaveId Name Link State #LinkFails Ethernet Duplex/Speed Settings Autoneg Speed (Mbps) Duplex Iface 0 eth0 UP ACTIVE 0 on 1000 Full eth0 eth1 DOWN STANDBY 0 on 10 Half eth1 @ArubaNetworks
  • 18. 18 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | AP Stability and System Profile Optimization Controller Information Item Value Primary LMS 10.163.196.72 Backup LMS 10.163.196.71 AP to Active Controller Message Information Item Value AP state REGISTERED Power Status Operational State : Unknown Current HW State POE-AT: No restrictions @ArubaNetworks
  • 19. 19 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | AP Stability and System Profile Optimization MTU Discovery Probes Responses Last Sent Last Rcvd 45214 22607 2712890 2712890 Switch MTU, 1500 Ethernet bonding SlaveId Name Link State #LinkFails Ethernet Duplex/Speed Settings Autoneg Speed (Mbps) Duplex Iface 0 eth0 UP ACTIVE 0 on 1000 Full eth0 eth1 DOWN STANDBY 0 on 10 Half eth1 @ArubaNetworks
  • 20. 20 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | AP Stability Optimizations @ArubaNetworks
  • 21. 21 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | AP Stability Optimizations Heartbeat DSCP: Assign a DSCP value to AP heartbeats to prioritize heartbeats traveling over low-speed links. The supported range is 0-63, and the default value is 0. Bootstrap threshold: Number of consecutive missed heartbeats on a GRE tunnel (heartbeats are sent once per second on each tunnel) before an AP rebootstraps. On the controller, the GRE tunnel timeout is 1.5 x bootstrap-threshold; the tunnel is torn down after this number of seconds of inactivity on the tunnel. SAP MTU: Maximum Transmission Unit, in bytes, on the wired link for the AP. Spanning Tree: Select this checkbox to enable the Spanning Tree protocol. @ArubaNetworks
  • 22. 22 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | # 3 Optimize load on processes @ArubaNetworks
  • 23. 23 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | HTTPD Stress on the webserver can be because of number of sessions in the initial role for guest access. This is either because of large certificate (Key Length 2048 or 4096) that are used by the server or a large number of devices (phones/Tablets with APPs) that generate HTTP/HTTPS sessions and get re-directed to the web-server. show web-server profile Web Server Configuration Parameter Value SSL/TLS Protocol Config tlsv1 Captive Portal Certificate GUEST-AUTH User session timeout <30-3600> (seconds) 3600 Maximum supported concurrent clients <25-320> 75 Enable WebUI access on HTTPS port (443) true Enable bypass captive portal landing page false @ArubaNetworks
  • 24. 24 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | HTTPD show web-server statistics Web Server Statistics: Current Request Rate: 1 Req/Sec Current Traffic Rate: 1 KB/Sec Busy Connection Slots: 7 Available Connection Slots: 68 Total Requests Since Up Time: 284 Total Traffic Since Up Time: 1122 KB Avg. Request Rate Since Up Time: 1 Req/Sec Avg. Traffic Rate Since Up Time: 6144 Bytes/Sec Server Scoreboard: _____________KKKKKK_W_____________ Scoreboard Key: _ - Waiting for Connection, s - Starting up R - Reading Request, W - Sending Reply K - Keepalive, D - DNS Lookup C - Closing connection, L - Logging G - Gracefully finishing, I - Idle cleanup of worker . - Open slot with no current process @ArubaNetworks
  • 25. 25 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | STM and WMS STM Station Management is responsible for all AP information and Station information. This process can be over run if there is, # Aggressive polling from Airwave/SNMP servers for Wlan tables. # Network wide AP reboot and bootstraps # AP debug scripts run from the controller. WMS IDS/IPS events and frequent AP bootstraps could lead to WMS being busy. WMS is actively looking for RF information of WiFi devices(Rogue/Valid/Interfering). @ArubaNetworks
  • 26. 26 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Mitigation Use AMON WMS Offload to Airwave. Reduce SNMP polling or increase the polling period Disable WMS functionality if you do not require IDS/IPS functionality. @ArubaNetworks
  • 27. 27 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | # 4 Datapath Debugging @ArubaNetworks
  • 28. 28 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Datapath Monitoring Show datapath utilization show datapath utilization Datapath Network Processor Utilization | Cpu utilization during past | Cpu | 1 Sec 4 Secs 64 Secs | 10 | 99% | 99% | 99% | 11 | 0% | 0% | 0% | 12 | 0% | 0% | 0% | 13 | 0% | 0% | 0% | 14 | 0% | 0% | 0% | 15 | 0% | 0% | 0% | 16 | 0% | 0% | 0% | show datapath frame 10 |SUM/| | | | |CPU | Addr | Description Value | +----+------+-----------------------------------------------------+ | 10 | [00] | Allocated Frames 1040| | 10 | [01] | Max Allocated Frames 2208 | | 10 | [03] | Unknown Unicast 147074970| | 10 | [34] | Flood Frames 1506164167| +----+------+-----------------------------------------------------+ | 10 | [00] | Rx Frames 635394472| | 10 | [01] | Rx Bytes 1864525959| | 10 | [02] | Tx Frames 1240985989| +----+------+-----------------------------------------------------+ @ArubaNetworks
  • 29. 29 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Datapath Bandwidth Management show datapath bwm Datapath Bandwidth Management Table Entries Type Id Bits/sec Policed Bytes Bytes Flags CPU Status ---- ---- --------- ---------- ------- ----------- ------- ------- ------ 0 1 20000000 0 78125 0/0 9 ALLOCATED 0 2 4000000 0 15625 0/0 9 ALLOCATED 0 3 160000000 0 624890 0/0 9 ALLOCATED 0 4 4000000 0 15625 0/0 9 ALLOCATED 0 5 2000128 0 7813 0/0 9 ALLOCATED 0 6 2000128 0 7813 0/0 9 ALLOCATED 0 7 2000128 0 7813 0/0 9 ALLOCATED Firewall: Rate limit CP untrusted ucast traffic Enabled 20 Mbps Rate limit CP untrusted mcast traffic Enabled 4 Mbps Rate limit CP trusted ucast traffic Enabled 160 Mbps Rate limit CP trusted mcast traffic Enabled 4 Mbps Rate limit CP route traffic Enabled 2 Mbps Rate limit CP session mirror traffic Enabled 2 Mbps Rate limit CP auth process traffic Enabled 2 Mbps @ArubaNetworks
  • 30. 30 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | CP and DP Packet Capture • Wifi -Client packet-capture datapath wifi-client aa:aa:aa:aa:aa:aa all • VIA client/RAP packet-capture datapath ipsec <peer-ip> • Generic traffic to controller packet-capture controlpath tcp/udp 4343 @ArubaNetworks
  • 31. 31 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | # 5 @ArubaNetworks Deployment Tips Missing optimizations
  • 32. 32 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Deployment Tips Honey Comb Pattern Wireless Local Probe Threshold = 25 Transmit Power of AP 5Ghz Min Tx – 12 Max Tx – 15 2.4 Ghz Min Tx – 6 Max Tx – 9 Avoid Asymmetric RF The difference between minimum and maximum Tx power on the same radio should not be more than 6dbm DMO Enable Basic and Beacon rate 802.11a 5Ghz – 24 802.11g 2.4Ghz – 12 80 Mhz Channel bonding - DFS Channels @ArubaNetworks
  • 33. 33 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Deployment Tips.. Contd GRE Stripping IP - VRRP for LMS and Stripping IP Jumbo Frames - Enabled 802.3at Airgroup Dot1x OKC Validate PMK ID 802.11r/k/v EAPOL Rate Optimization @ArubaNetworks
  • 34. 34 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Deployment Tips… ASE https://ase.arubanetworks.com/ @ArubaNetworks
  • 35. 35 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Deployment Tips.. ASE for troubleshooting @ArubaNetworks
  • 37. 37 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content # 6 ClearPass Platform: System Cleanup Options @ArubaNetworks
  • 38. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved38#ATM15 | ClearPass Platform: System Cleanup Options • Free disk space threshold is a config in Cluster Wide Service Parameter. Default 30% • A system cron job runs every hour and checks the disk utilization. If the free space falls below the configured threshold, an alert is logged into the system. NOW in addition, the following aggressive cron cleans up anything more than 1 day old in version 6.5 of CPPM • Log database records • Core files • System load monitor files • Application and system log files • Auto and manual backup files • Stored reports • Expired guest accounts • Audit records
  • 39. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved39#ATM15 | ClearPass Platform: System Cleanup Options
  • 40. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved40#ATM15 | ClearPass Platform: System Cleanup Options We also introduced some new CLI commands – Check on disk-space and memory usage - “show sysinfo”… – system cleanup [# of days to retain] **This is an on-demand task
  • 41. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved41#ATM15 | ClearPass Platform: System Cleanup Options • Same command function also exist in the GUI – Remember this is an on-demand task
  • 42. 42 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | # 7 @ArubaNetworks ClearPass Platform : Graphite
  • 43. 43 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • Graphite is a new reporting tool to compliment Insight in CPPM from 6.3 version. • Graphite runs on every node irrespective of standalone or cluster and statistics can be viewed from any node. • Performance monitoring Display is disabled by default and should be enabled manually and set access permission levels accordingly. • To access Graphite data, use the URL https://<CPPM IP Address>/graphite ClearPass Platform : Graphite
  • 44. 44 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • Make sure Performance monitoring is enabled from GUI ClearPass Platform : Graphite
  • 45. 45 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • Setting up access to Graphite from CPPM UI ClearPass Platform : Graphite
  • 46. 46 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • We can allow or deny any networks to access Graphite for a node or cluster. • Make sure stats collection is set true True under Service parameters. ClearPass Platform : Graphite
  • 47. 47 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | ClearPass Platform : Graphite
  • 48. 48 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | ClearPass Platform : Graphite
  • 49. 49 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content # 8 ClearPass : Upgrade Utility Tool @ArubaNetworks
  • 50. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved50#ATM15 | ClearPass : Upgrade Utility Tool • The Cluster Upgrade Tool is a simple user interface that automates the upgrade procedure for a ClearPass cluster. • When the upgrade is initiated, no manual actions are required until all selected nodes have been upgraded. • The Upgrade Tool is not available while the publisher is rebooted and migrating the Configuration Database. • The Upgrade Tool will not detect nodes that were upgraded manually without the tool. • If a configured standby publisher node was manually upgraded without the tool, the Upgrade Tool will not restore the state of the standby publisher configuration.
  • 51. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved51#ATM15 | ClearPass : Upgrade Utility Tool • The Cluster Upgrade Tool is released as a patch update. It can be downloaded and installed either through Policy Manager’s Software Updates portal, or from the Aruba Support portal.
  • 52. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved52#ATM15 | ClearPass : Upgrade Utility Tool • Log in to Policy Manager on the publisher node and go to Administration > Agents and Software >Updates > Software Updates. • When the installation is complete, the Admin service will be restarted. You do not need to reboot.
  • 53. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved53#ATM15 | ClearPass : Upgrade Utility Tool • Before you begin the upgrade, the upgrade image must be present on the publisher node of the cluster. • Download the upgrade image to the publisher under Software updates
  • 54. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved54#ATM15 | ClearPass : Upgrade Utility Tool • To monitor the progress of the other nodes in the cluster, wait until the database migration is complete and then log in to the tool again. • Change the url to https://CPPM IP Address/upgrade • We should see all the subscribers status that are in sync. • The list of subscribers will be present and subscriber upgrades will go in parallel. • ‘Start Upgrade’ to start the upgrade on the servers.
  • 55. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved55#ATM15 | ClearPass : Upgrade Utility Tool
  • 56. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved56#ATM15 | ClearPass : Upgrade Utility Tool
  • 57. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved57#ATM15 | ClearPass : Upgrade Utility Tool • Check the logs for each node by ‘View Logs’ next to each node and we can see the progress of patches and upgrades from publisher.
  • 58. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved58#ATM15 | ClearPass : Upgrade Utility tool
  • 59. 59 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | # 9 @ArubaNetworks AirWave – VisualRF Performance Tips
  • 60. 60 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • Sometimes we see VisualRF takes long time to show up new AP’s to deploy on the floor plans. • We can manually force VisualRF to poll the AP’s to get new AP or existing AP’s updated details. • NO need to restart VisualRF to show up new AP’s. • Change the url in AMP to https://<Airwave IP Address>/visualrf/poll_aps_now.xml AirWave – VisualRF Performance Tips
  • 61. 61 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • In 8.x moved to HTML5 for VisualRF UI for faster UI interaction with backend. • Whilst we are improving the features on the new UI, there are some features which were present in flash and not in HTML5. • In VisualRF > Setup page, we can switch between HTML5 and flash so that we can take advantage of options present in both version • Switching between HTML5 and Flash version is easy with below URL without refreshing VisualRF. • Change the URL to https://Airwave IP Address/site?campus_id=6c56c239-bfba-4d19-aeca-8ec5af68b725 from https://Airwave IP Address/vrf?campus_id=6c56c239-bfba-4d19-aeca-8ec5af68b725 AirWave – VisualRF Performance Tips
  • 62. 62 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | AirWave – VisualRF Performance tips
  • 63. 63 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | AirWave – VisualRF Performance Tips
  • 64. 64 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • We can change ‘vrf’ to ‘site’ on any page for VisualRF URL’s to switch to flash mode from HTML5 mode. At times we see Heat maps not showing/updating properly in VisualRF • We can resize the floor plan to same size so that the grid calculation happens and heat maps will be re-drawn. • No need to restart VisualRF for heat maps to update. AirWave – VisualRF Performance Tips
  • 65. 65 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • Unlock the floor plan and go to properties and ‘Measure’ Airwave – VisualRF Performance Tips
  • 66. 66 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • Select the distance, click ‘OK’ and ‘Save’ without changing the distance, this will trigger floor plan to recalculate the heatmpas. Airwave – VisualRF Performance Tips
  • 67. 67 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content # 10 Airwave – Tips for Data Retention Settings @ArubaNetworks
  • 68. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved68#ATM15 | Airwave – Tips for Data Retention Settings • Data in AirWave is primarily stored in 2 formats: • Postgres - an open source, relational SQL database. Usually, when you see data in tables, that data is stored in Postgres. • RRD Files - used for storing data that's displayed in time-sequence graphs (i.e, client count over the last year, bandwidth used over the last month). There can be many thousands of RRD files on a single AirWave server. One benefit of RRD is that its files have a fixed size. As data is inserted to an RRD file (like by an AirWave monitoring process), it does not grow. A downside of this is that the file starts using storage space as soon as it is created.
  • 69. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved69#ATM15 | Airwave – Tips for Data Retention Settings • We can set data retention settings under AMP Setup > General page under the section ‘Historical Data Retention’. • Client Association and VPN Session History. This setting has a bearing on how much history we can show in the association history on the client historical table and how much data can be included in the user session data. • Its recommend to keep high because the data is useful
  • 70. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved70#ATM15 | Airwave – Tips for Data Retention settings • Inactive Client and VPN User Data. This setting determines how long we keep the information on every client that has ever connected to the network. • This impacts how long we keep RRD files. Keeping it low can save disk space.
  • 71. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved71#ATM15 | Airwave – Tips for Data Retention settings • Client data retention Interval : This influences how much historical data you can see for each client in the graphs, for example the signal quality, usage graphs on the client detail/diagnostic page. • It's very important to keep this low, like in the 14-31 days range. • This is especially important in public wi-fi deployments that will have lots of unique users. • This setting controls what size RRD files are created to store per-user historical signal, usage, goodput, health and other metrics. • Keeping it low doesn't impact device, group and folder-level monitoring, and it doesn't have any negative impact on reports. It only impacts the graphs on the client Detail and Diagnostic pages.
  • 72. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved72#ATM15 | Airwave – Tips for Data Retention settings • By default Rogues are kept forever which will impact the overall system performance and for RAPIDS page load. • It also impacts VisualRF for Rogue calculation if it has thousands of Rogue devices. • This is especially important in public wi-fi deployments that have open SSID and lot of nearby devices are detected as Rogues • Setting the value to low as 14 days will greatly help.
  • 73. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved73#ATM15 | Airwave – Tips for Data Retention settings • Airwave by default has 20+ Reports which runs daily. • Keep Reports that are needed for the environment and delete/disable the default reports. • Report retention setting can be costly in high dense environments especially for disk space. • This increase the nightly backup file size, nightly maintenance time and report generation time. • Exporting the reports via .csv or .pdf or emailing them is a good option. • Keeping the retention value will have the pickled client tables not to grow huge in size and makes report generation faster.
  • 74. 74 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Questions @ArubaNetworks
  • 75. THANK YOU 75#ATM15 | @ArubaNetworks

Editor's Notes

  1. Make networks mobility-defined instead of fixed
  2. Make networks mobility-defined instead of fixed
  3. Make networks mobility-defined instead of fixed
  4. Make networks mobility-defined instead of fixed
  5. Make networks mobility-defined instead of fixed
  6. Make networks mobility-defined instead of fixed
  7. Make networks mobility-defined instead of fixed
  8. Make networks mobility-defined instead of fixed
  9. Make networks mobility-defined instead of fixed
  10. Make networks mobility-defined instead of fixed
  11. Make networks mobility-defined instead of fixed
  12. Make networks mobility-defined instead of fixed
  13. Make networks mobility-defined instead of fixed
  14. Make networks mobility-defined instead of fixed
  15. Make networks mobility-defined instead of fixed
  16. Make networks mobility-defined instead of fixed
  17. Make networks mobility-defined instead of fixed
  18. Make networks mobility-defined instead of fixed
  19. Make networks mobility-defined instead of fixed
  20. Make networks mobility-defined instead of fixed
  21. Make networks mobility-defined instead of fixed
  22. Make networks mobility-defined instead of fixed
  23. Make networks mobility-defined instead of fixed
  24. Make networks mobility-defined instead of fixed
  25. Make networks mobility-defined instead of fixed
  26. Make networks mobility-defined instead of fixed
  27. Make networks mobility-defined instead of fixed
  28. Make networks mobility-defined instead of fixed
  29. Make networks mobility-defined instead of fixed
  30. Make networks mobility-defined instead of fixed
  31. Make networks mobility-defined instead of fixed
  32. Make networks mobility-defined instead of fixed
  33. Make networks mobility-defined instead of fixed
  34. Make networks mobility-defined instead of fixed
  35. Make networks mobility-defined instead of fixed
  36. Make networks mobility-defined instead of fixed
  37. Make networks mobility-defined instead of fixed
  38. Make networks mobility-defined instead of fixed
  39. Make networks mobility-defined instead of fixed
  40. Make networks mobility-defined instead of fixed
  41. Make networks mobility-defined instead of fixed