SlideShare a Scribd company logo
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved 1
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved 2
TOP 10 TIPS FROM ARUBA TAC
Ken Peredia
Aruba Networks
March 2012
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved 33
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
Objectives: Help our customers understand
some of the recent issues around the Region
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved 44
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
Foreword
5 5
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
Before you open a ticket…
•  Check online resources such as
–  Airheads Social (community.arubanetworks.com)
–  Aruba Knowledge Base (support.arubanetworks.com)
–  Aruba validated reference designs (VRDs)
–  Software Release Notes
•  Enable PhoneHome on all controllers
–  phonehome enable
–  phonehome auto-report
–  phonehome smtp <mail server ip address> <email address>
6 6
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
Before you open a ticket…
7 7
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
Before you open a ticket…
8 8
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
Before you open a ticket…
•  Check online resources such as
–  Airheads Social (community.arubanetworks.com)
–  Aruba Knowledge Base (support.arubanetworks.com)
–  Aruba validated reference designs (VRDs)
–  Software Release Notes
•  Pre-empt the support info requests
–  Be ready to supply “tar logs tech-support”
–  Best to attach it to the ticket, or, send it once ticket is
assigned to engineer
•  Don’t attach to original support request email if it is larger than
5MB
–  Console output for RMAs (or a reason why there is none)
9 9
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
Before you open a ticket…
•  Delays to case resolution
–  Lack of controller logs or logs taken too long after the issue
•  Controller can only store fixed amount of logs, the higher the
logging verbosity, the shorter that time is
–  Logs from other points, such as IAS/NPS or client
–  “did it work before” or “new config” ?
•  Try to simplify the issue
–  Does the simple case work ?
–  Remove any tweaks and optimizations that might be clouding
the issue, or, put up a default virtual AP for testing (if
possible)
•  Sometimes config is over optimized/tweaked
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved 1010
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
The Countdown
11 11
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#10 - Upgrading to 6.1.x
•  Double upgrades are required for most older
ArubaOS versions
–  Latest s/w in most older streams “knows” how to upgrade to
release 6.1.x
–  Due to changes in the flash layout on the controller to
accommodate larger ArubaOS image
–  This is further complicated for RAPs (to be covered next)
•  Please read the release notes “Upgrade
Procedures” section !
–  3.3.x (or 3.4.x) à latest 3.4.4.x à 6.1
–  5.0.x à latest 5.0.4.x à 6.1
–  6.0.x à latest 6.0.1.x or 6.0.2.x à 6.1
12 12
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#10 - Upgrading to 6.1.x
•  Aruba 3200
–  The 3200 is getting low on free memory due to ever
expanding feature set of ArubaOS.
–  Aruba has released an “XM” (extra memory) version of the
3200 also a field kit (3200-MEM-UG) where you can upgrade
the memory yourself
•  No you can’t use your own memory from local PC shop !
–  A long running or heavily utilized 3200 controller may need to
be rebooted to ensure there is enough free memory for the
upgrade
–  Non upgraded 3200 will not be supported for ArubaOS 6.2
13 13
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#9 - Upgrading RAPs to 6.1.x
•  The problem
–  ArubaOS has a check to ensure that an image that is
downloaded during self upgrade is not of unexpected size
–  Prior to 6.x, that maximum was 4MB
–  ArubaOS 5.0.3.x and higher knows that 6.x is > 4MB and has
a new maximum size check
•  Two common issues for RAP2/RAP5
–  RAP is running 6.1.x due to correct upgrade sequence but
has old provisioning image (pre 5.0.3.x)
•  if it is reset to default it will not be able to re-connect/re-upgrade
as it reverts to the provisioning image
–  “Brand new out of the box” RAP won’t connect to controller
•  It is running older provisioning image.
14 14
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#9 - Upgrading RAPs to 6.1.x
•  Provisioning image versus running image
–  RAP5 or RAP2 has 2 s/w images on it
1.  the provisioning image that runs the rapconsole
2.  the production image that is downloaded after first connect to
controller
–  The provisioning image can be upgraded via CLI in all
releases except 6.x
•  CLI command removed in 6.1.x
•  CLI command exists in 6.0.x but fails (6.x cannot be saved)
–  provisioning image is never automatically upgraded.
•  Old in-service RAPs may still have 5.0.0.x or 3.3.2 RN code in it.
15 15
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#9 – Upgrading RAPs to 6.1.x
•  History of RAP factory images
•  3.3.2.18-RN (2009~2010)
•  5.0.0.2 (2010~2011)
•  5.0.4.0 (15 Oct 2011 ~ present)
•  What is on my RAP ?
–  “show ap image version”
–  also visible on RAP console
16 16
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#9 - Upgrading RAPs to 6.1.x
•  6.1 Upgrade challenge
–  The ArubaOS 6.x image is too big to be a provisioning image
–  RAP just hangs after it is provisioned from RAP console
–  Must upgrade provisioning image to 5.0.4.x before trying to
upgrade to 6.1.x
1.  Ensure RAP is UP (show ap active)
2.  From CLI “apflash ap-name someRAP backup-partition”
–  apflash command will cause RAP to reboot
17 17
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#9 - Upgrading RAPs to 6.1.x
•  A final comment about RAP upgrades
–  During 3.x code timeframe, the ap-role did not allow svc-ftp,
but it was added as a default in 5.x/6.x
–  Despite the fact a RAP communicates with IPSEC, there are
generic protocols running inside the tunnel, ftp being one of
them
•  FTP is used to upgrade the s/w on the RAP
•  By default RAP will try FTP a number of times before reverting to
tftp, overall this can take 15 minutes or so to time out, delaying
the upgrade.
–  Before upgrading a RAP network, please ensure that svc-ftp
is permitted in one of the ACLs within the ap-role
•  “show rights ap-role” and look for entry allowing “user” to
“controller” for svc-ftp
18 18
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#9 - Upgrading RAPs to 6.1.x
(c620) #show rights ap-role
access-list List
----------------
Position Name Location
-------- ---- --------
1 control
2 ap-acl
control
-------
Priority Source Destination Service Action TimeRange Log Expired Queue TOS 8021P Blacklist Mirror
-------- ------ ----------- ------- ------ --------- --- ------- ----- --- ----- --------- ------ ------- ------------- ------
1 user any udp 68 deny Low 4
2 any any svc-icmp permit Low 4
3 any any svc-dns permit Low 4
4 any any svc-papi permit Low 4
ap-acl
------
Priority Source Destination Service Action TimeRange Log Expired Queue TOS 8021P Blacklist Mirror
-------- ------ ----------- ------- ------ --------- --- ------- ----- --- ----- --------- ------ ------- ------------- ------
1 any any svc-gre permit Low 4
2 any any svc-syslog permit Low 4
3 any user svc-snmp permit Low 4
4 user any svc-http permit Low 4
5 user any svc-http-accl permit Low 4
6 user any svc-ntp permit Low 4
7 user controller svc-ftp permit Low 4
(c620) #
19 19
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#8 – Mesh networks
•  RF RF RF RF !!
–  Most issues with mesh all come back to RF !
•  Common issues
–  Insufficient RSSI to achieve the desired rate
•  Use the outdoor planner to predict
–  High gain antenna misalignment
•  Not always good enough to just “aim by eye”
–  Vertical height mismatch on omni antennas
•  Most important over short distance and high gain omnis
–  Hidden nodes
•  All mesh points must hear each other, not just the portal
•  Can mitigate with RTS threshold (to an extent)
20 20
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#8 – Mesh networks
•  Outdoor planner helps predict performance
–  Great for understanding the effect of antenna choice and
height of antenna
–  Planner knows the regulatory constraints (max EIRP etc.)
-75dBm predicted
coverage
21 21
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#7 – OCSP
•  Online Certificate Status Protocol (OCSP)
–  Is an IETF standard used for obtaining the revocation status
of an X.509 digital certificate. It is described in RFC 2560 and
is on the Internet standards track. It was created as an
alternative to certificate revocation lists (CRL), specifically
addressing certain problems associated with using CRLs in a
public key infrastructure (PKI). Messages communicated via
OCSP are encoded in ASN.1 and are usually communicated
over HTTP. The "request/response" nature of these
messages leads to OCSP servers being termed OCSP
responders.
22 22
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#7 – OCSP
•  You could be running into an issue where web
browsers attempt to contact an OCSP server, to
see if the captive portal certificate is valid and
has not been revoked.
–  The following browsers (or OS) enables OCSP validation by
default:
•  Firefox 3 (on all platforms) enables OCSP checking by default.
•  Safari and Google Chrome in Mac OS X follow system-wide
setting in Keychain Access. It was disabled by default prior to
Mac OS X Lion (10.7). As of 10.7 (Lion), the default setting is
'Best Attempt'. That means the browser will attempt to perform
OCSP validation (or CRL validation) if the information is available
in the cert.
23 23
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#7 – OCSP
•  Since it is not efficient to disable OCSP checking
on all your clients, you can open up traffic to the
OCSP server in your logon role
–  For AOS 6.0 and below:
•  netdestination OCSP
•  host <ip addresses from the DNS name in the OSCP portion of the certificate>
•  !
•  ip access-list session Permit_OCSP
•  user alias OCSP svc-http permit
•  user alias OCSP svc-https permit
•  !
•  user-role guest-logon
•  captive-portal "guest-cp_prof"
•  session-acl logon-control
•  session-acl Permit_OCSP
•  session-acl captiveportal
•  !
24 24
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#7 – OCSP
–  Using AOS 6.1 and later, the whitelist feature can accomplish
the same thing using DNS names. The following example
assumes that the OCSP URL embedded in the certificate is
http://ocsp.usertrust.com:
•  Netdestination ocsp.usertrust.com
•  Name ocsp.usertrust.com
•  !
•  aaa authentication captive-portal default
•  white-list ocsp.usertrust.com
25 25
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#6 – Broadcast/Multicast Mitigation
•  Currently, the following knobs mitigate flood
traffic in customer networks:
–  Global Knob
•  firewall broadcast-filter arp
•  This knob would enable broadcast ARP conversion on all vlans and
convert all the broadcast ARP req to unicast ARP requests for the
target wireless clients (that are part of the station table/user table).
–  Virtual AP profile knobs
•  broadcast-filter arp
• This knob would convert the mcast ARP request to unicast ARP
request (on that VAP) if the target IP/mac is part of user table and
station table. And datapath would send the unicast ARP request to
the target station.
•  broadcast-filter all
• This would drop everything else except DHCP today on that VAP.
And for the dhcp frames destined to clients, datapath would
convert the dhcp broadcast offers/acks to unicast dhcp frames.
26 26
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#6 – Broadcast/Multicast Mitigation
–  Vlan knobs
•  bcmc-optimization
•  This would drop all the bcast/mcast frames on the vlan with
exceptions for ARP, DHCP, VRRP. This would mean datapath
dropping all other broadcasts/multicast frames on wired interfaces on
the vlan also.
•  ip local-proxy-arp
•  This will enable the local proxyARP functionality on the vlan.
•  Controller datapath would proxyARP with target’s mac when we
receive an ARP request on an L2 vlan if the targetip is a known user
thru route cache/user table.
•  On an L3 vlan, datapath would respond with controller mac instead.
•  suppress-arp
•  In addition to enforcing proxyARP functionality, datapath would drop
grat ARPs on WiFi tunnels and all ARP flooding on un-trusted
interfaces.
27 27
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#5 – Voice
•  TIPs for deploying Voice over Wi-Fi
–  Follow the manufacturer’s deployment guide
–  Review the “Optimizing Aruba WLANs for Roaming Devices”
VRD to see if your voice device has best practice config.
–  Clip the lower data rates.
–  Make sure voip-aware-scan is enabled
–  In 11n deployments make sure the WMM/DSCP markings
match the wired QoS settings
•  Also make sure “single-chain-legacy” is enabled in the rf ht radio
profile
–  If the voice device supports 5GHz be mindful of what
channels it supports. Some phones do not support channel
165 for example.
–  Enable local-probe-req-thresh 25 as a start
–  Do not have more than 2 steps of tx-power diff between APs.
28 28
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#3 - Client Connectivity/Perf Issues
•  A common support topic!
•  Frequent causes
–  RF issues
–  Client driver issues (versions, power save, roaming quirks)
–  Config on controller (ARM, A-MSDU, rates etc.)
–  Important L3 hosts stuck in user table
–  Controller datapath under stress (covered in #4)
29 29
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#4 – Controller under stress
•  Controller can be impacted by network floods or
loops resulting in high CPU on datapath
–  Datapath is where packets are mostly handled
–  Symptoms may be high latency for all clients, slow response
of webUI on controller, ping loss to controller interfaces.
•  High CPU can also come from unexpected
process behavior
–  Httpd running high due to high bit HTTPS certs
–  WMS too busy doing IDS type work
•  If you suspect a high CPU condition, collect the
following data and contact support for
assistance
30 30
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#4 – Controller under stress
•  Multiple places to check
–  show cpuload current
–  show datapath bwm
–  show datapath bridge counters
–  show datapath crypto
–  show datapath frame
–  show datapath maintenance
–  show datapath message-queue
–  show datapath utilization
–  show memory
–  show netstat
–  show processes sort-by cpu
31 31
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#3 - Client Connectivity/Perf Issues
•  RF Issues
–  Make use of spectrum analyzer function, or, check the radio
stats (covered in the RF presentation)
–  Causes may be 802.11 or non 802.11 related
–  Some s/w options exist, including s/w retry, interference
immunity
–  Sometimes 2.4GHz just cannot cope
•  Public events and stadiums are a good example
32 32
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#3 - Client Connectivity/Perf Issues
•  Client driver issues
–  Many clients have their own strange behaviors
•  Vendor algorithms for roaming are often secret, some clients are
notoriously sticky
•  Same for selection of 11gn vs. 11an for dual band clients
•  Can try a dedicated test SSID profile for a problem client on a
single AP
–  Where possible, always try to update drivers
•  Try to work out “everyone affected or just that client”
33 33
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#3 - Client Connectivity/Perf Issues
•  Client driver issues
–  Driver settings can influence connectivity
•  Power save and battery/AC status can impact “ping tests”
•  To much “roaming aggressiveness” can cause thrashing
–  Be careful of dual band clients that don’t support the same
channel set as the APs
•  Many client chipsets don’t support UNII-2/UNII-2e channels
•  Some Wi-Fi cards are regionalized and may not support your
regulatory domain
•  Band-steering may be trying to steer you to a channel the client
doesn’t support (i.e. Galaxy Tab doesn’t use UNII-3)
34 34
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#3 - Client Connectivity/Perf Issues
•  Config on controller
–  In noisy 2.4GHz environment, default ARM settings may be
too aggressive for noise/error threshold channel changes
•  Review ARM history “show ap arm history ap-name <ap>”
•  Increase 2.4GHz ARM profile “noise-wait-time” and/or “error-wait-
time” to be more tolerant of noisy/congested 2.4GHz
–  Aggressive config tuning for 2.4GHz (especially for voice)
can often cause reduced coverage
•  Often results in low speed rates removed from SSID profiles
•  wlan ssid-profile <profile> local-probe-req-thresh
•  Need to find a balance of the right snr
35 35
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#3 - Client Connectivity/Perf Issues
•  Config on controller
–  Apple 10.6.x iMAC devices with 3x3 Atheros chipsets sold in
2011 had A-MSDU enabled by default, Aruba had it disabled
until recently due to a bug.
•  “firewall amsdu”
•  Apple disabled AMSDU by default on 10.7.x
–  Older non-802.11n devices may have interoperability issues
with 802.11n APs
•  Commonly seen with handheld/industrial devices
•  Often enabling single chain legacy can help
•  Transmits legacy non 11n frames on single radio chain
•  “rf ht-radio-profile <profile> single-chain-legacy”
36 36
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#3 - Client Connectivity/Perf Issues
•  Important L3 host stuck in user table
–  If a packet with a source IP of (for example) the default
gateway arrives via an IP, the controller will create a user
entry for it.
–  This can cause intermittent connectivity issues due to firewall
policy or session limit exceeded
–  Often triggered by Windows bridging between wired and
wireless. Could also be caused by a host with static IP.
–  Use validuser ACL to prevent users being created for
important IP addresses.
ip access-list session validuser
any any svc-sec-papi permit
network 169.254.0.0 255.255.0.0 any any deny
alias protected_hosts any any deny
any any any permit
ipv6 any any any permit
!
netdestination protected_hosts
host 192.168.1.253
host 192.168.1.254
network 10.0.0.0 255.255.255.0
37 37
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#3 - Client Connectivity/Perf Issues
•  Authentication issues
–  Incorrect time settings on clients can cause certificate
validation issues, often silently
–  For windows clients, use MSFT tracing “netsh ras set
tracing * enabled” to debug issues on Windows side
–  Use ArubaOS command “show auth-tracebuf” for all auth
issues
•  This is a magical command !
•  Observe how this output looks for successful/regular auth
•  Compare it when problems arise (can often spot certificate issues
with this command)
38 38
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#3 - Client Connectivity/Perf Issues
Nov 3 11:08:02 station-up * 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - - wpa2 aes
Nov 3 11:08:02 station-data-ready * 00:21:6a:8b:0a:dc 00:00:00:00:00:00 180 -
Nov 3 11:08:02 m-auth resp * 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - - authenticated
Nov 3 11:08:02 wpa2-key1 <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - 117
Nov 3 11:08:02 eap-start -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - -
Nov 3 11:08:02 eap-id-req <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 2 5
Nov 3 11:08:02 eap-id-resp -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 2 44 host/pc1.lab.com
Nov 3 11:08:02 rad-req -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 11 259
Nov 3 11:08:02 rad-resp <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 11 129
Nov 3 11:08:02 eap-req <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 144 6
Nov 3 11:08:02 eap-resp -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 144 180
Nov 3 11:08:02 rad-req -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 12 478
Nov 3 11:08:02 rad-resp <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 12 1141
Nov 3 11:08:02 eap-req <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 145 1012
Nov 3 11:08:02 eap-resp -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 145 6
Nov 3 11:08:02 rad-req -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 13 304
Nov 3 11:08:02 rad-resp <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 13 1137
Nov 3 11:08:02 eap-req <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 146 1008
Nov 3 11:08:02 eap-resp -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 146 6
Nov 3 11:08:02 rad-req -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 14 304
Nov 3 11:08:02 rad-resp <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 14 1137
Nov 3 11:08:02 eap-req <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 147 1008
Nov 3 11:08:02 eap-resp -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 147 6
Nov 3 11:08:02 rad-req -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/rradpolicy1 15 304
Nov 3 11:08:02 rad-req -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 19 1436
Nov 3 11:08:02 rad-resp <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 19 188
Nov 3 11:08:02 eap-req <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 152 65
Nov 3 11:08:02 eap-resp -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 152 6
Nov 3 11:08:02 rad-req -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/ise-policy1 20 304
Nov 3 11:08:02 rad-accept <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/ise-policy1 20 276
Nov 3 11:08:02 eap-success <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 152 4
Nov 3 11:08:02 station-data-ready * 00:21:6a:8b:0a:dc 00:00:00:00:00:00 180 -
Nov 3 11:08:02 m-auth resp * 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - - authenticated
Nov 3 11:08:02 wpa2-key1 <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - 117
Nov 3 11:08:02 wpa2-key2 -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - 119
Nov 3 11:08:02 wpa2-key3 <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - 151
Nov 3 11:08:02 wpa2-key4 -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - 95
VLAN
username
server
Radius ID
EAP ID
length
result
39 39
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#3 - Client Connectivity/Perf Issues
•  Recently seen authentication issues
–  Cannot connect dot1x wireless on XP via RDP
•  Refer http://technet.microsoft.com/en-us/network/dd727529.aspx#EWKAC
•  Use VNC instead, resolved vista/NPS2008
–  IAS can “discard” messages, which triggers the ArubaOS
“server out of service” as no response is seen
•  Hotfix exists for unknown domain, for other cases always send
reject not “discard”
–  XP SP3 clients have PEAP auth issues with NPS 2008
•  http://support.microsoft.com/kb/969111
40 40
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#2 – Common misconfiguration
•  Spanning Tree
–  Beware changes to STP type between ArubaOS versions
•  3.x à 3.4.x RSTP became default
•  6.x à PVST+ added (not used by default)
–  If controller connectivity is impacted after an upgrade, it may
be STP related.
–  Test thoroughly any STP interop between controller and your
switches.
•  Example: our RSTP does not always play nice with MSTP which
is the default on many switches.
•  Controller DHCP scalability
–  Internal DHCP server is not recommended to be used for
more than 2 x /24 scopes
41 41
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#2 – Common misconfiguration
•  Too fast periodic DB sync
–  Master to redundant master periodic DB sync requires the
controller to dump various databases and transfer them
across.
–  While the databases are being dumped, client processing is
not occurring.
–  In most cases, periodic DB sync should not be required more
than once per 24 hours.
•  Misconfigured multi-association on Virtual AP
–  Also known as “fast-roaming”
–  Multi-association should not be configured. Having it enabled
can cause the APs to hit max-client count very quickly.
–  Planned to be removed in rel 6.2
42 42
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#2 – Common misconfiguration
•  Captive portal web max clients too low
–  If you are using the controller captive portal for many users,
you must adjust the default setting for “Maximum supported
concurrent clients” to be higher, i.e.
•  “web-server web-max-clients 300”
–  Default value is 25 to protect HTTPd from abuse
43 43
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#2 – Common misconfiguration
•  Insufficient power for 2nd enet port on AP 13x
–  Not a controller misconfiguration per-se
–  AP13x hardware must have 802.3at power to run both
ethernet ports
–  If only presented with 802.3af power,
can still run 3x3 but only with enet0
•  After bootup, s/w will disable enet1
–  Ensure to always connect enet0 if just
using a single cable to avoid any issues
with AP power management
44 44
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#1 - Best practice tweaks
•  Layer 2 broadcast filtering
–  Virtual AP broadcast filter “arp”
–  Virtual AP broadcast filter “all”
–  Use these on tunnel mode VAPs to reduce the amount of
broadcast and multicast traffic that may leak from the layer2
network onto the air
•  i.e. filters out CDP, STP BDPUs etc. from leaking to WLAN
•  Make sure that the VAP is not required to support multicast
traffic, often voice networks will use multicast for call hold music
etc
45 45
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#1 - Best practice tweaks
•  RF optimizations
–  band-steering
•  Multiple modes available – “force”, “prefer”, “balance”
–  s/w retry (new in 6.1.2.6+)
•  A different retry mechanism for 11n clients
•  Shows benefit with i-devices, especially in presence of
interference
•  “wlan ht-ssid-profile <profile> sw-retry”
–  High density 5GHz should use 20MHz channels not 40MHz
•  Also watch out for this with outdoor mesh – most countries only
have 2 non overlapped 40MHz outdoor channels
46 46
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#1 - Best practice tweaks
•  Rate optimizations
–  SSID profile “mcast-rate-opt”
•  Send broadcast and multicast frames at the rate of the worst
client, up to 24Mbps. Improves WLAN air time utilization
–  SSID profile “eapol-rate-opt” (new in 6.1.2.7+)
•  Use lowest tx rates for EAPOL frames to improve roaming
reliability for dot1x enabled devices
•  Auth optimizations
–  Decrease default EAPOL ID request period from 30 to 3
seconds, for faster state recovery
•  aaa authentication dot1x <profile> timer idrequest_period 3
–  Enable “validate-pmkid” in dot1x profile to prevent any state
mismatches with half baked OKC clients
47 47
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
#1 - Best practice tweaks
•  Load balancing optimizations
–  Always use a wlan traffic mgmt profile when doing high
density testing
•  “fair-access” is the best practice configuration for all client types
•  “preferred-access” if non-11n clients do not have an application
performance requirement
–  SSID local probe response threshold
•  “wlan ssid-profile <profile> local-probe-req-thresh X” is a useful
way to stop APs from responding to probes from distant clients.
•  Use “show ap debug client-table ap-name <ap>” to determine
signal from nearby clients
•  Typical values of X might be in the range 20~30,
48 48
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
In conclusion
•  support@arubanetworks.com
–  One email address for all products
•  Timezone/shift-work nature of support front line
–  You can always request your ticket to be moved to another
time-zone
–  Avoid unicasting emails/attachments to support staff
•  Using reply to all will get more eyes on your issue
•  Always call support for urgent issues
•  Please exercise caution when making changes
–  Always keep off-box backups
–  When tweaking, incrementally add changes
•  ArubaOS has a number of ways to contain changes
49 49
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
Takeaways
TAC Quick Reference Guide
–  https://support.arubanetworks.com/DOCUMENTATION/tabid/77/DMXModule/512/
Command/Core_Download/Default.aspx?EntryId=1371
Validated Reference Designs (VRD)
–  http://www.arubanetworks.com/technology/reference-design-guides/
Airheads Social
–  http://community.arubanetworks.com/
Aruba Knowledge Base
–  https://kb.arubanetworks.com/
Raise a ticket for any product, RMA, anything !
–  support@arubanetworks.com
Requests for Enhancements (RFE)
–  Please discuss with your SE/Sales team
Outdoor planner tool
–  https://outdoorplanner.arubanetworks.com/
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved 5050
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved
Questions?
CONFIDENTIAL
© Copyright 2012. Aruba Networks, Inc.
All rights reserved 5151
Coming Up:
Tech Playground 12pm – 1:30pm

More Related Content

What's hot

Cisco switch setup with cppm v1.2
Cisco switch setup with cppm v1.2Cisco switch setup with cppm v1.2
Cisco switch setup with cppm v1.2
Aruba, a Hewlett Packard Enterprise company
 
2012 ah vegas wlan design fundamentals
2012 ah vegas   wlan design fundamentals2012 ah vegas   wlan design fundamentals
2012 ah vegas wlan design fundamentals
Aruba, a Hewlett Packard Enterprise company
 
Airheads scottsdale 2010 maximizing 11n performance
Airheads scottsdale 2010   maximizing 11n performanceAirheads scottsdale 2010   maximizing 11n performance
Airheads scottsdale 2010 maximizing 11n performance
Aruba, a Hewlett Packard Enterprise company
 
Advanced rf troubleshooting_peter lane
Advanced rf troubleshooting_peter laneAdvanced rf troubleshooting_peter lane
Advanced rf troubleshooting_peter lane
Aruba, a Hewlett Packard Enterprise company
 
RAP Networks Validated Reference Design
RAP Networks Validated Reference DesignRAP Networks Validated Reference Design
RAP Networks Validated Reference Design
Aruba, a Hewlett Packard Enterprise company
 
Optimizing wlan operations peter lane
Optimizing wlan operations peter laneOptimizing wlan operations peter lane
Optimizing wlan operations peter lane
Aruba, a Hewlett Packard Enterprise company
 
Acmp study guide_d[1]
Acmp study guide_d[1]Acmp study guide_d[1]
Aruba networks webinar_wi-fi_without_interruption_sep20_2012
Aruba networks webinar_wi-fi_without_interruption_sep20_2012Aruba networks webinar_wi-fi_without_interruption_sep20_2012
Aruba networks webinar_wi-fi_without_interruption_sep20_2012
Aruba, a Hewlett Packard Enterprise company
 
2012 ah vegas rf troubleshooting
2012 ah vegas   rf troubleshooting2012 ah vegas   rf troubleshooting
2012 ah vegas rf troubleshooting
Aruba, a Hewlett Packard Enterprise company
 
2012 ah vegas deploying byod
2012 ah vegas   deploying byod2012 ah vegas   deploying byod
2012 ah vegas deploying byod
Aruba, a Hewlett Packard Enterprise company
 
Airheads scottsdale 2010 broadcast quality video over 11n
Airheads scottsdale 2010   broadcast quality video over 11nAirheads scottsdale 2010   broadcast quality video over 11n
Airheads scottsdale 2010 broadcast quality video over 11n
Aruba, a Hewlett Packard Enterprise company
 
2012 ah vegas wlan design for high density
2012 ah vegas   wlan design for high density2012 ah vegas   wlan design for high density
2012 ah vegas wlan design for high density
Aruba, a Hewlett Packard Enterprise company
 
Security advanced rich langston_jon green
Security advanced rich langston_jon greenSecurity advanced rich langston_jon green
Security advanced rich langston_jon green
Aruba, a Hewlett Packard Enterprise company
 
Airheads dallas 2011 rap troubleshooting
Airheads dallas 2011   rap troubleshootingAirheads dallas 2011   rap troubleshooting
Airheads dallas 2011 rap troubleshooting
Aruba, a Hewlett Packard Enterprise company
 
2012 ah vegas mobile device fundamentals
2012 ah vegas   mobile device fundamentals2012 ah vegas   mobile device fundamentals
2012 ah vegas mobile device fundamentals
Aruba, a Hewlett Packard Enterprise company
 
2 top10 tips from aruba tac rizwan shaikh
2 top10 tips from aruba tac rizwan shaikh2 top10 tips from aruba tac rizwan shaikh
2 top10 tips from aruba tac rizwan shaikh
Aruba, a Hewlett Packard Enterprise company
 
5 steps to a faster, smarter wlan
5 steps to a faster, smarter wlan5 steps to a faster, smarter wlan
5 steps to a faster, smarter wlan
Aruba, a Hewlett Packard Enterprise company
 
Airheads barcelona 2010 rf design for retail warehousing manufacturing
Airheads barcelona 2010   rf design for retail warehousing manufacturingAirheads barcelona 2010   rf design for retail warehousing manufacturing
Airheads barcelona 2010 rf design for retail warehousing manufacturing
Aruba, a Hewlett Packard Enterprise company
 
Next generation remote networks aruba instant gokul rajagopalan
Next generation remote networks aruba instant gokul rajagopalanNext generation remote networks aruba instant gokul rajagopalan
Next generation remote networks aruba instant gokul rajagopalan
Aruba, a Hewlett Packard Enterprise company
 
Designing for the all wireless office ash chowdappa-kelly griffin
Designing for the all wireless office ash chowdappa-kelly griffinDesigning for the all wireless office ash chowdappa-kelly griffin
Designing for the all wireless office ash chowdappa-kelly griffin
Aruba, a Hewlett Packard Enterprise company
 

What's hot (20)

Cisco switch setup with cppm v1.2
Cisco switch setup with cppm v1.2Cisco switch setup with cppm v1.2
Cisco switch setup with cppm v1.2
 
2012 ah vegas wlan design fundamentals
2012 ah vegas   wlan design fundamentals2012 ah vegas   wlan design fundamentals
2012 ah vegas wlan design fundamentals
 
Airheads scottsdale 2010 maximizing 11n performance
Airheads scottsdale 2010   maximizing 11n performanceAirheads scottsdale 2010   maximizing 11n performance
Airheads scottsdale 2010 maximizing 11n performance
 
Advanced rf troubleshooting_peter lane
Advanced rf troubleshooting_peter laneAdvanced rf troubleshooting_peter lane
Advanced rf troubleshooting_peter lane
 
RAP Networks Validated Reference Design
RAP Networks Validated Reference DesignRAP Networks Validated Reference Design
RAP Networks Validated Reference Design
 
Optimizing wlan operations peter lane
Optimizing wlan operations peter laneOptimizing wlan operations peter lane
Optimizing wlan operations peter lane
 
Acmp study guide_d[1]
Acmp study guide_d[1]Acmp study guide_d[1]
Acmp study guide_d[1]
 
Aruba networks webinar_wi-fi_without_interruption_sep20_2012
Aruba networks webinar_wi-fi_without_interruption_sep20_2012Aruba networks webinar_wi-fi_without_interruption_sep20_2012
Aruba networks webinar_wi-fi_without_interruption_sep20_2012
 
2012 ah vegas rf troubleshooting
2012 ah vegas   rf troubleshooting2012 ah vegas   rf troubleshooting
2012 ah vegas rf troubleshooting
 
2012 ah vegas deploying byod
2012 ah vegas   deploying byod2012 ah vegas   deploying byod
2012 ah vegas deploying byod
 
Airheads scottsdale 2010 broadcast quality video over 11n
Airheads scottsdale 2010   broadcast quality video over 11nAirheads scottsdale 2010   broadcast quality video over 11n
Airheads scottsdale 2010 broadcast quality video over 11n
 
2012 ah vegas wlan design for high density
2012 ah vegas   wlan design for high density2012 ah vegas   wlan design for high density
2012 ah vegas wlan design for high density
 
Security advanced rich langston_jon green
Security advanced rich langston_jon greenSecurity advanced rich langston_jon green
Security advanced rich langston_jon green
 
Airheads dallas 2011 rap troubleshooting
Airheads dallas 2011   rap troubleshootingAirheads dallas 2011   rap troubleshooting
Airheads dallas 2011 rap troubleshooting
 
2012 ah vegas mobile device fundamentals
2012 ah vegas   mobile device fundamentals2012 ah vegas   mobile device fundamentals
2012 ah vegas mobile device fundamentals
 
2 top10 tips from aruba tac rizwan shaikh
2 top10 tips from aruba tac rizwan shaikh2 top10 tips from aruba tac rizwan shaikh
2 top10 tips from aruba tac rizwan shaikh
 
5 steps to a faster, smarter wlan
5 steps to a faster, smarter wlan5 steps to a faster, smarter wlan
5 steps to a faster, smarter wlan
 
Airheads barcelona 2010 rf design for retail warehousing manufacturing
Airheads barcelona 2010   rf design for retail warehousing manufacturingAirheads barcelona 2010   rf design for retail warehousing manufacturing
Airheads barcelona 2010 rf design for retail warehousing manufacturing
 
Next generation remote networks aruba instant gokul rajagopalan
Next generation remote networks aruba instant gokul rajagopalanNext generation remote networks aruba instant gokul rajagopalan
Next generation remote networks aruba instant gokul rajagopalan
 
Designing for the all wireless office ash chowdappa-kelly griffin
Designing for the all wireless office ash chowdappa-kelly griffinDesigning for the all wireless office ash chowdappa-kelly griffin
Designing for the all wireless office ash chowdappa-kelly griffin
 

Viewers also liked

Top 10 tips_aruba_tac_madison lee
Top 10 tips_aruba_tac_madison leeTop 10 tips_aruba_tac_madison lee
Top 10 tips_aruba_tac_madison lee
Aruba, a Hewlett Packard Enterprise company
 
Aruba instant the easy button for wireless gokul rajagopalan
Aruba instant the easy button for wireless gokul rajagopalanAruba instant the easy button for wireless gokul rajagopalan
Aruba instant the easy button for wireless gokul rajagopalan
Aruba, a Hewlett Packard Enterprise company
 
Creating an 802 1 xv3
Creating an 802 1 xv3Creating an 802 1 xv3
Do d directives regarding wireless lan
Do d directives regarding wireless lanDo d directives regarding wireless lan
Do d directives regarding wireless lan
Aruba, a Hewlett Packard Enterprise company
 
Aruba webinar dorm wi fi design v4
Aruba webinar   dorm wi fi design v4Aruba webinar   dorm wi fi design v4
Aruba webinar dorm wi fi design v4
Aruba, a Hewlett Packard Enterprise company
 
2012 ah vegas guest access fundamentals
2012 ah vegas   guest access fundamentals2012 ah vegas   guest access fundamentals
2012 ah vegas guest access fundamentals
Aruba, a Hewlett Packard Enterprise company
 
Airheads vail 2011 pci 2.0 compliance
Airheads vail 2011   pci 2.0 complianceAirheads vail 2011   pci 2.0 compliance
Airheads vail 2011 pci 2.0 compliance
Aruba, a Hewlett Packard Enterprise company
 
2012 ah vegas unified access fundamentals
2012 ah vegas   unified access fundamentals2012 ah vegas   unified access fundamentals
2012 ah vegas unified access fundamentals
Aruba, a Hewlett Packard Enterprise company
 
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
Aruba, a Hewlett Packard Enterprise company
 
2012 ah emea advanced mobility design
2012 ah emea   advanced mobility design2012 ah emea   advanced mobility design
2012 ah emea advanced mobility design
Aruba, a Hewlett Packard Enterprise company
 
Security intermediate practical cryptography_certs_and 802.1_x_rich langston...
Security intermediate  practical cryptography_certs_and 802.1_x_rich langston...Security intermediate  practical cryptography_certs_and 802.1_x_rich langston...
Security intermediate practical cryptography_certs_and 802.1_x_rich langston...
Aruba, a Hewlett Packard Enterprise company
 
8 software defined networking and traffic engineering partha narasimhan_ash c...
8 software defined networking and traffic engineering partha narasimhan_ash c...8 software defined networking and traffic engineering partha narasimhan_ash c...
8 software defined networking and traffic engineering partha narasimhan_ash c...
Aruba, a Hewlett Packard Enterprise company
 
2012 ah apj guest access fundamentals
2012 ah apj   guest access fundamentals2012 ah apj   guest access fundamentals
2012 ah apj guest access fundamentals
Aruba, a Hewlett Packard Enterprise company
 
Spectralink airheads 2013
Spectralink airheads 2013Spectralink airheads 2013
Guest wlan via gu iv3
Guest wlan via gu iv3Guest wlan via gu iv3
Hello instant 0612_1a
Hello instant 0612_1aHello instant 0612_1a
Mac authentication amigopod radius
Mac authentication amigopod radiusMac authentication amigopod radius
Mac authentication amigopod radius
Aruba, a Hewlett Packard Enterprise company
 
Gigabit wifi 802.11 ac in depth_peter thornycroft
Gigabit wifi 802.11 ac in depth_peter thornycroftGigabit wifi 802.11 ac in depth_peter thornycroft
Gigabit wifi 802.11 ac in depth_peter thornycroft
Aruba, a Hewlett Packard Enterprise company
 
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
Aruba, a Hewlett Packard Enterprise company
 
Mac address authentication
Mac address authenticationMac address authentication

Viewers also liked (20)

Top 10 tips_aruba_tac_madison lee
Top 10 tips_aruba_tac_madison leeTop 10 tips_aruba_tac_madison lee
Top 10 tips_aruba_tac_madison lee
 
Aruba instant the easy button for wireless gokul rajagopalan
Aruba instant the easy button for wireless gokul rajagopalanAruba instant the easy button for wireless gokul rajagopalan
Aruba instant the easy button for wireless gokul rajagopalan
 
Creating an 802 1 xv3
Creating an 802 1 xv3Creating an 802 1 xv3
Creating an 802 1 xv3
 
Do d directives regarding wireless lan
Do d directives regarding wireless lanDo d directives regarding wireless lan
Do d directives regarding wireless lan
 
Aruba webinar dorm wi fi design v4
Aruba webinar   dorm wi fi design v4Aruba webinar   dorm wi fi design v4
Aruba webinar dorm wi fi design v4
 
2012 ah vegas guest access fundamentals
2012 ah vegas   guest access fundamentals2012 ah vegas   guest access fundamentals
2012 ah vegas guest access fundamentals
 
Airheads vail 2011 pci 2.0 compliance
Airheads vail 2011   pci 2.0 complianceAirheads vail 2011   pci 2.0 compliance
Airheads vail 2011 pci 2.0 compliance
 
2012 ah vegas unified access fundamentals
2012 ah vegas   unified access fundamentals2012 ah vegas   unified access fundamentals
2012 ah vegas unified access fundamentals
 
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
 
2012 ah emea advanced mobility design
2012 ah emea   advanced mobility design2012 ah emea   advanced mobility design
2012 ah emea advanced mobility design
 
Security intermediate practical cryptography_certs_and 802.1_x_rich langston...
Security intermediate  practical cryptography_certs_and 802.1_x_rich langston...Security intermediate  practical cryptography_certs_and 802.1_x_rich langston...
Security intermediate practical cryptography_certs_and 802.1_x_rich langston...
 
8 software defined networking and traffic engineering partha narasimhan_ash c...
8 software defined networking and traffic engineering partha narasimhan_ash c...8 software defined networking and traffic engineering partha narasimhan_ash c...
8 software defined networking and traffic engineering partha narasimhan_ash c...
 
2012 ah apj guest access fundamentals
2012 ah apj   guest access fundamentals2012 ah apj   guest access fundamentals
2012 ah apj guest access fundamentals
 
Spectralink airheads 2013
Spectralink airheads 2013Spectralink airheads 2013
Spectralink airheads 2013
 
Guest wlan via gu iv3
Guest wlan via gu iv3Guest wlan via gu iv3
Guest wlan via gu iv3
 
Hello instant 0612_1a
Hello instant 0612_1aHello instant 0612_1a
Hello instant 0612_1a
 
Mac authentication amigopod radius
Mac authentication amigopod radiusMac authentication amigopod radius
Mac authentication amigopod radius
 
Gigabit wifi 802.11 ac in depth_peter thornycroft
Gigabit wifi 802.11 ac in depth_peter thornycroftGigabit wifi 802.11 ac in depth_peter thornycroft
Gigabit wifi 802.11 ac in depth_peter thornycroft
 
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
 
Mac address authentication
Mac address authenticationMac address authentication
Mac address authentication
 

Similar to 2012 ah vegas top10 tips from aruba tac

LAB - Component Based Development
LAB - Component Based DevelopmentLAB - Component Based Development
LAB - Component Based Development
Perforce
 
CON5898 What Servlet 4.0 Means To You
CON5898 What Servlet 4.0 Means To YouCON5898 What Servlet 4.0 Means To You
CON5898 What Servlet 4.0 Means To You
Edward Burns
 
6° Sessione Oracle - CRUI: Oracle Database Appliance: Il potere dell’ingegner...
6° Sessione Oracle - CRUI: Oracle Database Appliance:Il potere dell’ingegner...6° Sessione Oracle - CRUI: Oracle Database Appliance:Il potere dell’ingegner...
6° Sessione Oracle - CRUI: Oracle Database Appliance: Il potere dell’ingegner...
Jürgen Ambrosi
 
Ceph Community Talk on High-Performance Solid Sate Ceph
Ceph Community Talk on High-Performance Solid Sate Ceph Ceph Community Talk on High-Performance Solid Sate Ceph
Ceph Community Talk on High-Performance Solid Sate Ceph
Ceph Community
 
Optimize DR and Cloning with Logical Hostnames in Oracle E-Business Suite (OA...
Optimize DR and Cloning with Logical Hostnames in Oracle E-Business Suite (OA...Optimize DR and Cloning with Logical Hostnames in Oracle E-Business Suite (OA...
Optimize DR and Cloning with Logical Hostnames in Oracle E-Business Suite (OA...
Andrejs Prokopjevs
 
Inter connect2016 yps-2749_02232016_aspresented
Inter connect2016 yps-2749_02232016_aspresentedInter connect2016 yps-2749_02232016_aspresented
Inter connect2016 yps-2749_02232016_aspresented
Bruce Semple
 
3 Ways to Connect to the Oracle Cloud
3 Ways to Connect to the Oracle Cloud3 Ways to Connect to the Oracle Cloud
3 Ways to Connect to the Oracle Cloud
Simon Haslam
 
Meetup Oracle Database: 3 Analizar, Aconsejar, Automatizar… las nuevas funcio...
Meetup Oracle Database: 3 Analizar, Aconsejar, Automatizar… las nuevas funcio...Meetup Oracle Database: 3 Analizar, Aconsejar, Automatizar… las nuevas funcio...
Meetup Oracle Database: 3 Analizar, Aconsejar, Automatizar… las nuevas funcio...
avanttic Consultoría Tecnológica
 
Symantec Public Meetup
Symantec Public MeetupSymantec Public Meetup
Symantec Public Meetup
Rudrajit Tapadar
 
Performance: Observe and Tune
Performance: Observe and TunePerformance: Observe and Tune
Performance: Observe and Tune
Paul V. Novarese
 
Oracle Fleet Patching and Provisioning Deep Dive Webcast Slides
Oracle Fleet Patching and Provisioning Deep Dive Webcast SlidesOracle Fleet Patching and Provisioning Deep Dive Webcast Slides
Oracle Fleet Patching and Provisioning Deep Dive Webcast Slides
Ludovico Caldara
 
BigData Clusters Redefined
BigData Clusters RedefinedBigData Clusters Redefined
BigData Clusters Redefined
DataWorks Summit
 
Ebs performance tuning session feb 13 2013---Presented by Oracle
Ebs performance tuning session  feb 13 2013---Presented by OracleEbs performance tuning session  feb 13 2013---Presented by Oracle
Ebs performance tuning session feb 13 2013---Presented by Oracle
Akash Pramanik
 
Nové vlastnosti Oracle Database Appliance
Nové vlastnosti Oracle Database ApplianceNové vlastnosti Oracle Database Appliance
Nové vlastnosti Oracle Database Appliance
MarketingArrowECS_CZ
 
Cognos Performance Tuning Tips & Tricks
Cognos Performance Tuning Tips & TricksCognos Performance Tuning Tips & Tricks
Cognos Performance Tuning Tips & Tricks
Senturus
 
Approaching hyperconvergedopenstack
Approaching hyperconvergedopenstackApproaching hyperconvergedopenstack
Approaching hyperconvergedopenstack
Ikuo Kumagai
 
SQLintersection keynote a tale of two teams
SQLintersection keynote a tale of two teamsSQLintersection keynote a tale of two teams
SQLintersection keynote a tale of two teams
Sumeet Bansal
 
Database as a Service, Collaborate 2016
Database as a Service, Collaborate 2016Database as a Service, Collaborate 2016
Database as a Service, Collaborate 2016
Kellyn Pot'Vin-Gorman
 
Oracle Enterprise Manager 12c - OEM12c Presentation
Oracle Enterprise Manager 12c - OEM12c PresentationOracle Enterprise Manager 12c - OEM12c Presentation
Oracle Enterprise Manager 12c - OEM12c Presentation
Francisco Alvarez
 
Solaris 11 Consolidation Tools
Solaris 11 Consolidation ToolsSolaris 11 Consolidation Tools
Solaris 11 Consolidation Tools
Roman Ivanov
 

Similar to 2012 ah vegas top10 tips from aruba tac (20)

LAB - Component Based Development
LAB - Component Based DevelopmentLAB - Component Based Development
LAB - Component Based Development
 
CON5898 What Servlet 4.0 Means To You
CON5898 What Servlet 4.0 Means To YouCON5898 What Servlet 4.0 Means To You
CON5898 What Servlet 4.0 Means To You
 
6° Sessione Oracle - CRUI: Oracle Database Appliance: Il potere dell’ingegner...
6° Sessione Oracle - CRUI: Oracle Database Appliance:Il potere dell’ingegner...6° Sessione Oracle - CRUI: Oracle Database Appliance:Il potere dell’ingegner...
6° Sessione Oracle - CRUI: Oracle Database Appliance: Il potere dell’ingegner...
 
Ceph Community Talk on High-Performance Solid Sate Ceph
Ceph Community Talk on High-Performance Solid Sate Ceph Ceph Community Talk on High-Performance Solid Sate Ceph
Ceph Community Talk on High-Performance Solid Sate Ceph
 
Optimize DR and Cloning with Logical Hostnames in Oracle E-Business Suite (OA...
Optimize DR and Cloning with Logical Hostnames in Oracle E-Business Suite (OA...Optimize DR and Cloning with Logical Hostnames in Oracle E-Business Suite (OA...
Optimize DR and Cloning with Logical Hostnames in Oracle E-Business Suite (OA...
 
Inter connect2016 yps-2749_02232016_aspresented
Inter connect2016 yps-2749_02232016_aspresentedInter connect2016 yps-2749_02232016_aspresented
Inter connect2016 yps-2749_02232016_aspresented
 
3 Ways to Connect to the Oracle Cloud
3 Ways to Connect to the Oracle Cloud3 Ways to Connect to the Oracle Cloud
3 Ways to Connect to the Oracle Cloud
 
Meetup Oracle Database: 3 Analizar, Aconsejar, Automatizar… las nuevas funcio...
Meetup Oracle Database: 3 Analizar, Aconsejar, Automatizar… las nuevas funcio...Meetup Oracle Database: 3 Analizar, Aconsejar, Automatizar… las nuevas funcio...
Meetup Oracle Database: 3 Analizar, Aconsejar, Automatizar… las nuevas funcio...
 
Symantec Public Meetup
Symantec Public MeetupSymantec Public Meetup
Symantec Public Meetup
 
Performance: Observe and Tune
Performance: Observe and TunePerformance: Observe and Tune
Performance: Observe and Tune
 
Oracle Fleet Patching and Provisioning Deep Dive Webcast Slides
Oracle Fleet Patching and Provisioning Deep Dive Webcast SlidesOracle Fleet Patching and Provisioning Deep Dive Webcast Slides
Oracle Fleet Patching and Provisioning Deep Dive Webcast Slides
 
BigData Clusters Redefined
BigData Clusters RedefinedBigData Clusters Redefined
BigData Clusters Redefined
 
Ebs performance tuning session feb 13 2013---Presented by Oracle
Ebs performance tuning session  feb 13 2013---Presented by OracleEbs performance tuning session  feb 13 2013---Presented by Oracle
Ebs performance tuning session feb 13 2013---Presented by Oracle
 
Nové vlastnosti Oracle Database Appliance
Nové vlastnosti Oracle Database ApplianceNové vlastnosti Oracle Database Appliance
Nové vlastnosti Oracle Database Appliance
 
Cognos Performance Tuning Tips & Tricks
Cognos Performance Tuning Tips & TricksCognos Performance Tuning Tips & Tricks
Cognos Performance Tuning Tips & Tricks
 
Approaching hyperconvergedopenstack
Approaching hyperconvergedopenstackApproaching hyperconvergedopenstack
Approaching hyperconvergedopenstack
 
SQLintersection keynote a tale of two teams
SQLintersection keynote a tale of two teamsSQLintersection keynote a tale of two teams
SQLintersection keynote a tale of two teams
 
Database as a Service, Collaborate 2016
Database as a Service, Collaborate 2016Database as a Service, Collaborate 2016
Database as a Service, Collaborate 2016
 
Oracle Enterprise Manager 12c - OEM12c Presentation
Oracle Enterprise Manager 12c - OEM12c PresentationOracle Enterprise Manager 12c - OEM12c Presentation
Oracle Enterprise Manager 12c - OEM12c Presentation
 
Solaris 11 Consolidation Tools
Solaris 11 Consolidation ToolsSolaris 11 Consolidation Tools
Solaris 11 Consolidation Tools
 

More from Aruba, a Hewlett Packard Enterprise company

Airheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba CentralAirheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
Aruba, a Hewlett Packard Enterprise company
 
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard AgentsAirheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
Aruba, a Hewlett Packard Enterprise company
 
Airheads Tech Talks: Advanced Clustering in AOS 8.x
Airheads Tech Talks: Advanced Clustering in AOS 8.xAirheads Tech Talks: Advanced Clustering in AOS 8.x
Airheads Tech Talks: Advanced Clustering in AOS 8.x
Aruba, a Hewlett Packard Enterprise company
 
EMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Advance Aruba CentralEMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Advance Aruba Central
Aruba, a Hewlett Packard Enterprise company
 
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.xEMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
Aruba, a Hewlett Packard Enterprise company
 
EMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS SwitchEMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS Switch
Aruba, a Hewlett Packard Enterprise company
 
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS SwitchEMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
Aruba, a Hewlett Packard Enterprise company
 
Introduction to AirWave 10
Introduction to AirWave 10Introduction to AirWave 10
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS SwitchEMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
Aruba, a Hewlett Packard Enterprise company
 
EMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- Aruba Central with Instant APEMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- Aruba Central with Instant AP
Aruba, a Hewlett Packard Enterprise company
 
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.xEMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
Aruba, a Hewlett Packard Enterprise company
 
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
EMEA Airheads-  Getting Started with the ClearPass REST API – CPPMEMEA Airheads-  Getting Started with the ClearPass REST API – CPPM
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
Aruba, a Hewlett Packard Enterprise company
 
EMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP DeploymentEMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP Deployment
Aruba, a Hewlett Packard Enterprise company
 
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.xEMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
Aruba, a Hewlett Packard Enterprise company
 
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)
Aruba, a Hewlett Packard Enterprise company
 
EMEA Airheads - What does AirMatch do differently?v2
 EMEA Airheads - What does AirMatch do differently?v2 EMEA Airheads - What does AirMatch do differently?v2
EMEA Airheads - What does AirMatch do differently?v2
Aruba, a Hewlett Packard Enterprise company
 
Airheads Meetups: 8400 Presentation
Airheads Meetups: 8400 PresentationAirheads Meetups: 8400 Presentation
Airheads Meetups: 8400 Presentation
Aruba, a Hewlett Packard Enterprise company
 
Airheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau PresentationAirheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau Presentation
Aruba, a Hewlett Packard Enterprise company
 
Airheads Meetups- High density WLAN
Airheads Meetups- High density WLANAirheads Meetups- High density WLAN
Airheads Meetups- High density WLAN
Aruba, a Hewlett Packard Enterprise company
 
Airheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes ArubaAirheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes Aruba
Aruba, a Hewlett Packard Enterprise company
 

More from Aruba, a Hewlett Packard Enterprise company (20)

Airheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba CentralAirheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
 
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard AgentsAirheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
 
Airheads Tech Talks: Advanced Clustering in AOS 8.x
Airheads Tech Talks: Advanced Clustering in AOS 8.xAirheads Tech Talks: Advanced Clustering in AOS 8.x
Airheads Tech Talks: Advanced Clustering in AOS 8.x
 
EMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Advance Aruba CentralEMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Advance Aruba Central
 
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.xEMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
 
EMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS SwitchEMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS Switch
 
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS SwitchEMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
 
Introduction to AirWave 10
Introduction to AirWave 10Introduction to AirWave 10
Introduction to AirWave 10
 
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS SwitchEMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
 
EMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- Aruba Central with Instant APEMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- Aruba Central with Instant AP
 
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.xEMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
 
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
EMEA Airheads-  Getting Started with the ClearPass REST API – CPPMEMEA Airheads-  Getting Started with the ClearPass REST API – CPPM
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
 
EMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP DeploymentEMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP Deployment
 
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.xEMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
 
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)
 
EMEA Airheads - What does AirMatch do differently?v2
 EMEA Airheads - What does AirMatch do differently?v2 EMEA Airheads - What does AirMatch do differently?v2
EMEA Airheads - What does AirMatch do differently?v2
 
Airheads Meetups: 8400 Presentation
Airheads Meetups: 8400 PresentationAirheads Meetups: 8400 Presentation
Airheads Meetups: 8400 Presentation
 
Airheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau PresentationAirheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau Presentation
 
Airheads Meetups- High density WLAN
Airheads Meetups- High density WLANAirheads Meetups- High density WLAN
Airheads Meetups- High density WLAN
 
Airheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes ArubaAirheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes Aruba
 

Recently uploaded

一比一原版(毕业证书)马来西亚双威大学毕业证如何办理
一比一原版(毕业证书)马来西亚双威大学毕业证如何办理一比一原版(毕业证书)马来西亚双威大学毕业证如何办理
一比一原版(毕业证书)马来西亚双威大学毕业证如何办理
ucowe
 
Southwest Airlines Low Fare Calendar: The Ultimate Guide
Southwest Airlines Low Fare Calendar: The Ultimate GuideSouthwest Airlines Low Fare Calendar: The Ultimate Guide
Southwest Airlines Low Fare Calendar: The Ultimate Guide
i2aanshul
 
ghmc zones and circle and why they are needed
ghmc zones and circle and why they are neededghmc zones and circle and why they are needed
ghmc zones and circle and why they are needed
narinav14
 
Bahrain Visa For Indians, Complete Process
Bahrain Visa For Indians, Complete ProcessBahrain Visa For Indians, Complete Process
Bahrain Visa For Indians, Complete Process
toolzbuycomaccess
 
Frontier Airlines at Boston Logan International Airport (BOS) Comprehensive G...
Frontier Airlines at Boston Logan International Airport (BOS) Comprehensive G...Frontier Airlines at Boston Logan International Airport (BOS) Comprehensive G...
Frontier Airlines at Boston Logan International Airport (BOS) Comprehensive G...
AirportCityTerminals Terminals
 
What Budget-Friendly Attractions Does San Antonio Offer For Families
What Budget-Friendly Attractions Does San Antonio Offer For FamiliesWhat Budget-Friendly Attractions Does San Antonio Offer For Families
What Budget-Friendly Attractions Does San Antonio Offer For Families
Walking Tours of San Antonio
 
Best leisure recommended travel tips of 2024
Best leisure recommended travel tips of 2024Best leisure recommended travel tips of 2024
Best leisure recommended travel tips of 2024
kdadfarin363
 
一比一原版(UST毕业证)圣托马斯大学毕业证如何办理
一比一原版(UST毕业证)圣托马斯大学毕业证如何办理一比一原版(UST毕业证)圣托马斯大学毕业证如何办理
一比一原版(UST毕业证)圣托马斯大学毕业证如何办理
yfuwd
 
What Is The United Airlines Change Name Policy?
What Is The United Airlines Change Name Policy?What Is The United Airlines Change Name Policy?
What Is The United Airlines Change Name Policy?
flyingrules001namech
 
What Should You Expect On Austin's History Tour
What Should You Expect On Austin's History TourWhat Should You Expect On Austin's History Tour
What Should You Expect On Austin's History Tour
Walking Tours of Austin
 
American Airlines Name Change Policy Highlights.pptx
American Airlines Name Change Policy Highlights.pptxAmerican Airlines Name Change Policy Highlights.pptx
American Airlines Name Change Policy Highlights.pptx
edqour001namechange
 
Inca Trail to Machu Picchu An Unforgettable Adventure
Inca Trail to Machu Picchu An Unforgettable AdventureInca Trail to Machu Picchu An Unforgettable Adventure
Inca Trail to Machu Picchu An Unforgettable Adventure
Xtreme Tourbulencia
 
Colombia Historical Tour - savvytravelers
Colombia Historical Tour - savvytravelersColombia Historical Tour - savvytravelers
Colombia Historical Tour - savvytravelers
Savvy Travelers
 
定制(cardiff学位证书)英国卡迪夫大学毕业证本科学历原版一模一样
定制(cardiff学位证书)英国卡迪夫大学毕业证本科学历原版一模一样定制(cardiff学位证书)英国卡迪夫大学毕业证本科学历原版一模一样
定制(cardiff学位证书)英国卡迪夫大学毕业证本科学历原版一模一样
eovoam
 
09 Days Tour To Skardu(By Road): Skardu Ambassador Tours
09 Days Tour To Skardu(By Road): Skardu Ambassador Tours09 Days Tour To Skardu(By Road): Skardu Ambassador Tours
09 Days Tour To Skardu(By Road): Skardu Ambassador Tours
Skardu Ambassador Tours
 
How Safe Is Manta Ray Night Snorkeling In Kona
How Safe Is Manta Ray Night Snorkeling In KonaHow Safe Is Manta Ray Night Snorkeling In Kona
How Safe Is Manta Ray Night Snorkeling In Kona
Kona Ocean Adventures
 
Slovenia Visa for Indians | How to apply
Slovenia Visa for Indians | How to applySlovenia Visa for Indians | How to apply
Slovenia Visa for Indians | How to apply
Triple I Business
 

Recently uploaded (17)

一比一原版(毕业证书)马来西亚双威大学毕业证如何办理
一比一原版(毕业证书)马来西亚双威大学毕业证如何办理一比一原版(毕业证书)马来西亚双威大学毕业证如何办理
一比一原版(毕业证书)马来西亚双威大学毕业证如何办理
 
Southwest Airlines Low Fare Calendar: The Ultimate Guide
Southwest Airlines Low Fare Calendar: The Ultimate GuideSouthwest Airlines Low Fare Calendar: The Ultimate Guide
Southwest Airlines Low Fare Calendar: The Ultimate Guide
 
ghmc zones and circle and why they are needed
ghmc zones and circle and why they are neededghmc zones and circle and why they are needed
ghmc zones and circle and why they are needed
 
Bahrain Visa For Indians, Complete Process
Bahrain Visa For Indians, Complete ProcessBahrain Visa For Indians, Complete Process
Bahrain Visa For Indians, Complete Process
 
Frontier Airlines at Boston Logan International Airport (BOS) Comprehensive G...
Frontier Airlines at Boston Logan International Airport (BOS) Comprehensive G...Frontier Airlines at Boston Logan International Airport (BOS) Comprehensive G...
Frontier Airlines at Boston Logan International Airport (BOS) Comprehensive G...
 
What Budget-Friendly Attractions Does San Antonio Offer For Families
What Budget-Friendly Attractions Does San Antonio Offer For FamiliesWhat Budget-Friendly Attractions Does San Antonio Offer For Families
What Budget-Friendly Attractions Does San Antonio Offer For Families
 
Best leisure recommended travel tips of 2024
Best leisure recommended travel tips of 2024Best leisure recommended travel tips of 2024
Best leisure recommended travel tips of 2024
 
一比一原版(UST毕业证)圣托马斯大学毕业证如何办理
一比一原版(UST毕业证)圣托马斯大学毕业证如何办理一比一原版(UST毕业证)圣托马斯大学毕业证如何办理
一比一原版(UST毕业证)圣托马斯大学毕业证如何办理
 
What Is The United Airlines Change Name Policy?
What Is The United Airlines Change Name Policy?What Is The United Airlines Change Name Policy?
What Is The United Airlines Change Name Policy?
 
What Should You Expect On Austin's History Tour
What Should You Expect On Austin's History TourWhat Should You Expect On Austin's History Tour
What Should You Expect On Austin's History Tour
 
American Airlines Name Change Policy Highlights.pptx
American Airlines Name Change Policy Highlights.pptxAmerican Airlines Name Change Policy Highlights.pptx
American Airlines Name Change Policy Highlights.pptx
 
Inca Trail to Machu Picchu An Unforgettable Adventure
Inca Trail to Machu Picchu An Unforgettable AdventureInca Trail to Machu Picchu An Unforgettable Adventure
Inca Trail to Machu Picchu An Unforgettable Adventure
 
Colombia Historical Tour - savvytravelers
Colombia Historical Tour - savvytravelersColombia Historical Tour - savvytravelers
Colombia Historical Tour - savvytravelers
 
定制(cardiff学位证书)英国卡迪夫大学毕业证本科学历原版一模一样
定制(cardiff学位证书)英国卡迪夫大学毕业证本科学历原版一模一样定制(cardiff学位证书)英国卡迪夫大学毕业证本科学历原版一模一样
定制(cardiff学位证书)英国卡迪夫大学毕业证本科学历原版一模一样
 
09 Days Tour To Skardu(By Road): Skardu Ambassador Tours
09 Days Tour To Skardu(By Road): Skardu Ambassador Tours09 Days Tour To Skardu(By Road): Skardu Ambassador Tours
09 Days Tour To Skardu(By Road): Skardu Ambassador Tours
 
How Safe Is Manta Ray Night Snorkeling In Kona
How Safe Is Manta Ray Night Snorkeling In KonaHow Safe Is Manta Ray Night Snorkeling In Kona
How Safe Is Manta Ray Night Snorkeling In Kona
 
Slovenia Visa for Indians | How to apply
Slovenia Visa for Indians | How to applySlovenia Visa for Indians | How to apply
Slovenia Visa for Indians | How to apply
 

2012 ah vegas top10 tips from aruba tac

  • 1. CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved 1
  • 2. CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved 2 TOP 10 TIPS FROM ARUBA TAC Ken Peredia Aruba Networks March 2012
  • 3. CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved 33 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved Objectives: Help our customers understand some of the recent issues around the Region
  • 4. CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved 44 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved Foreword
  • 5. 5 5 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved Before you open a ticket… •  Check online resources such as –  Airheads Social (community.arubanetworks.com) –  Aruba Knowledge Base (support.arubanetworks.com) –  Aruba validated reference designs (VRDs) –  Software Release Notes •  Enable PhoneHome on all controllers –  phonehome enable –  phonehome auto-report –  phonehome smtp <mail server ip address> <email address>
  • 6. 6 6 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved Before you open a ticket…
  • 7. 7 7 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved Before you open a ticket…
  • 8. 8 8 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved Before you open a ticket… •  Check online resources such as –  Airheads Social (community.arubanetworks.com) –  Aruba Knowledge Base (support.arubanetworks.com) –  Aruba validated reference designs (VRDs) –  Software Release Notes •  Pre-empt the support info requests –  Be ready to supply “tar logs tech-support” –  Best to attach it to the ticket, or, send it once ticket is assigned to engineer •  Don’t attach to original support request email if it is larger than 5MB –  Console output for RMAs (or a reason why there is none)
  • 9. 9 9 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved Before you open a ticket… •  Delays to case resolution –  Lack of controller logs or logs taken too long after the issue •  Controller can only store fixed amount of logs, the higher the logging verbosity, the shorter that time is –  Logs from other points, such as IAS/NPS or client –  “did it work before” or “new config” ? •  Try to simplify the issue –  Does the simple case work ? –  Remove any tweaks and optimizations that might be clouding the issue, or, put up a default virtual AP for testing (if possible) •  Sometimes config is over optimized/tweaked
  • 10. CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved 1010 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved The Countdown
  • 11. 11 11 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #10 - Upgrading to 6.1.x •  Double upgrades are required for most older ArubaOS versions –  Latest s/w in most older streams “knows” how to upgrade to release 6.1.x –  Due to changes in the flash layout on the controller to accommodate larger ArubaOS image –  This is further complicated for RAPs (to be covered next) •  Please read the release notes “Upgrade Procedures” section ! –  3.3.x (or 3.4.x) à latest 3.4.4.x à 6.1 –  5.0.x à latest 5.0.4.x à 6.1 –  6.0.x à latest 6.0.1.x or 6.0.2.x à 6.1
  • 12. 12 12 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #10 - Upgrading to 6.1.x •  Aruba 3200 –  The 3200 is getting low on free memory due to ever expanding feature set of ArubaOS. –  Aruba has released an “XM” (extra memory) version of the 3200 also a field kit (3200-MEM-UG) where you can upgrade the memory yourself •  No you can’t use your own memory from local PC shop ! –  A long running or heavily utilized 3200 controller may need to be rebooted to ensure there is enough free memory for the upgrade –  Non upgraded 3200 will not be supported for ArubaOS 6.2
  • 13. 13 13 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #9 - Upgrading RAPs to 6.1.x •  The problem –  ArubaOS has a check to ensure that an image that is downloaded during self upgrade is not of unexpected size –  Prior to 6.x, that maximum was 4MB –  ArubaOS 5.0.3.x and higher knows that 6.x is > 4MB and has a new maximum size check •  Two common issues for RAP2/RAP5 –  RAP is running 6.1.x due to correct upgrade sequence but has old provisioning image (pre 5.0.3.x) •  if it is reset to default it will not be able to re-connect/re-upgrade as it reverts to the provisioning image –  “Brand new out of the box” RAP won’t connect to controller •  It is running older provisioning image.
  • 14. 14 14 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #9 - Upgrading RAPs to 6.1.x •  Provisioning image versus running image –  RAP5 or RAP2 has 2 s/w images on it 1.  the provisioning image that runs the rapconsole 2.  the production image that is downloaded after first connect to controller –  The provisioning image can be upgraded via CLI in all releases except 6.x •  CLI command removed in 6.1.x •  CLI command exists in 6.0.x but fails (6.x cannot be saved) –  provisioning image is never automatically upgraded. •  Old in-service RAPs may still have 5.0.0.x or 3.3.2 RN code in it.
  • 15. 15 15 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #9 – Upgrading RAPs to 6.1.x •  History of RAP factory images •  3.3.2.18-RN (2009~2010) •  5.0.0.2 (2010~2011) •  5.0.4.0 (15 Oct 2011 ~ present) •  What is on my RAP ? –  “show ap image version” –  also visible on RAP console
  • 16. 16 16 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #9 - Upgrading RAPs to 6.1.x •  6.1 Upgrade challenge –  The ArubaOS 6.x image is too big to be a provisioning image –  RAP just hangs after it is provisioned from RAP console –  Must upgrade provisioning image to 5.0.4.x before trying to upgrade to 6.1.x 1.  Ensure RAP is UP (show ap active) 2.  From CLI “apflash ap-name someRAP backup-partition” –  apflash command will cause RAP to reboot
  • 17. 17 17 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #9 - Upgrading RAPs to 6.1.x •  A final comment about RAP upgrades –  During 3.x code timeframe, the ap-role did not allow svc-ftp, but it was added as a default in 5.x/6.x –  Despite the fact a RAP communicates with IPSEC, there are generic protocols running inside the tunnel, ftp being one of them •  FTP is used to upgrade the s/w on the RAP •  By default RAP will try FTP a number of times before reverting to tftp, overall this can take 15 minutes or so to time out, delaying the upgrade. –  Before upgrading a RAP network, please ensure that svc-ftp is permitted in one of the ACLs within the ap-role •  “show rights ap-role” and look for entry allowing “user” to “controller” for svc-ftp
  • 18. 18 18 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #9 - Upgrading RAPs to 6.1.x (c620) #show rights ap-role access-list List ---------------- Position Name Location -------- ---- -------- 1 control 2 ap-acl control ------- Priority Source Destination Service Action TimeRange Log Expired Queue TOS 8021P Blacklist Mirror -------- ------ ----------- ------- ------ --------- --- ------- ----- --- ----- --------- ------ ------- ------------- ------ 1 user any udp 68 deny Low 4 2 any any svc-icmp permit Low 4 3 any any svc-dns permit Low 4 4 any any svc-papi permit Low 4 ap-acl ------ Priority Source Destination Service Action TimeRange Log Expired Queue TOS 8021P Blacklist Mirror -------- ------ ----------- ------- ------ --------- --- ------- ----- --- ----- --------- ------ ------- ------------- ------ 1 any any svc-gre permit Low 4 2 any any svc-syslog permit Low 4 3 any user svc-snmp permit Low 4 4 user any svc-http permit Low 4 5 user any svc-http-accl permit Low 4 6 user any svc-ntp permit Low 4 7 user controller svc-ftp permit Low 4 (c620) #
  • 19. 19 19 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #8 – Mesh networks •  RF RF RF RF !! –  Most issues with mesh all come back to RF ! •  Common issues –  Insufficient RSSI to achieve the desired rate •  Use the outdoor planner to predict –  High gain antenna misalignment •  Not always good enough to just “aim by eye” –  Vertical height mismatch on omni antennas •  Most important over short distance and high gain omnis –  Hidden nodes •  All mesh points must hear each other, not just the portal •  Can mitigate with RTS threshold (to an extent)
  • 20. 20 20 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #8 – Mesh networks •  Outdoor planner helps predict performance –  Great for understanding the effect of antenna choice and height of antenna –  Planner knows the regulatory constraints (max EIRP etc.) -75dBm predicted coverage
  • 21. 21 21 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #7 – OCSP •  Online Certificate Status Protocol (OCSP) –  Is an IETF standard used for obtaining the revocation status of an X.509 digital certificate. It is described in RFC 2560 and is on the Internet standards track. It was created as an alternative to certificate revocation lists (CRL), specifically addressing certain problems associated with using CRLs in a public key infrastructure (PKI). Messages communicated via OCSP are encoded in ASN.1 and are usually communicated over HTTP. The "request/response" nature of these messages leads to OCSP servers being termed OCSP responders.
  • 22. 22 22 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #7 – OCSP •  You could be running into an issue where web browsers attempt to contact an OCSP server, to see if the captive portal certificate is valid and has not been revoked. –  The following browsers (or OS) enables OCSP validation by default: •  Firefox 3 (on all platforms) enables OCSP checking by default. •  Safari and Google Chrome in Mac OS X follow system-wide setting in Keychain Access. It was disabled by default prior to Mac OS X Lion (10.7). As of 10.7 (Lion), the default setting is 'Best Attempt'. That means the browser will attempt to perform OCSP validation (or CRL validation) if the information is available in the cert.
  • 23. 23 23 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #7 – OCSP •  Since it is not efficient to disable OCSP checking on all your clients, you can open up traffic to the OCSP server in your logon role –  For AOS 6.0 and below: •  netdestination OCSP •  host <ip addresses from the DNS name in the OSCP portion of the certificate> •  ! •  ip access-list session Permit_OCSP •  user alias OCSP svc-http permit •  user alias OCSP svc-https permit •  ! •  user-role guest-logon •  captive-portal "guest-cp_prof" •  session-acl logon-control •  session-acl Permit_OCSP •  session-acl captiveportal •  !
  • 24. 24 24 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #7 – OCSP –  Using AOS 6.1 and later, the whitelist feature can accomplish the same thing using DNS names. The following example assumes that the OCSP URL embedded in the certificate is http://ocsp.usertrust.com: •  Netdestination ocsp.usertrust.com •  Name ocsp.usertrust.com •  ! •  aaa authentication captive-portal default •  white-list ocsp.usertrust.com
  • 25. 25 25 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #6 – Broadcast/Multicast Mitigation •  Currently, the following knobs mitigate flood traffic in customer networks: –  Global Knob •  firewall broadcast-filter arp •  This knob would enable broadcast ARP conversion on all vlans and convert all the broadcast ARP req to unicast ARP requests for the target wireless clients (that are part of the station table/user table). –  Virtual AP profile knobs •  broadcast-filter arp • This knob would convert the mcast ARP request to unicast ARP request (on that VAP) if the target IP/mac is part of user table and station table. And datapath would send the unicast ARP request to the target station. •  broadcast-filter all • This would drop everything else except DHCP today on that VAP. And for the dhcp frames destined to clients, datapath would convert the dhcp broadcast offers/acks to unicast dhcp frames.
  • 26. 26 26 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #6 – Broadcast/Multicast Mitigation –  Vlan knobs •  bcmc-optimization •  This would drop all the bcast/mcast frames on the vlan with exceptions for ARP, DHCP, VRRP. This would mean datapath dropping all other broadcasts/multicast frames on wired interfaces on the vlan also. •  ip local-proxy-arp •  This will enable the local proxyARP functionality on the vlan. •  Controller datapath would proxyARP with target’s mac when we receive an ARP request on an L2 vlan if the targetip is a known user thru route cache/user table. •  On an L3 vlan, datapath would respond with controller mac instead. •  suppress-arp •  In addition to enforcing proxyARP functionality, datapath would drop grat ARPs on WiFi tunnels and all ARP flooding on un-trusted interfaces.
  • 27. 27 27 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #5 – Voice •  TIPs for deploying Voice over Wi-Fi –  Follow the manufacturer’s deployment guide –  Review the “Optimizing Aruba WLANs for Roaming Devices” VRD to see if your voice device has best practice config. –  Clip the lower data rates. –  Make sure voip-aware-scan is enabled –  In 11n deployments make sure the WMM/DSCP markings match the wired QoS settings •  Also make sure “single-chain-legacy” is enabled in the rf ht radio profile –  If the voice device supports 5GHz be mindful of what channels it supports. Some phones do not support channel 165 for example. –  Enable local-probe-req-thresh 25 as a start –  Do not have more than 2 steps of tx-power diff between APs.
  • 28. 28 28 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #3 - Client Connectivity/Perf Issues •  A common support topic! •  Frequent causes –  RF issues –  Client driver issues (versions, power save, roaming quirks) –  Config on controller (ARM, A-MSDU, rates etc.) –  Important L3 hosts stuck in user table –  Controller datapath under stress (covered in #4)
  • 29. 29 29 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #4 – Controller under stress •  Controller can be impacted by network floods or loops resulting in high CPU on datapath –  Datapath is where packets are mostly handled –  Symptoms may be high latency for all clients, slow response of webUI on controller, ping loss to controller interfaces. •  High CPU can also come from unexpected process behavior –  Httpd running high due to high bit HTTPS certs –  WMS too busy doing IDS type work •  If you suspect a high CPU condition, collect the following data and contact support for assistance
  • 30. 30 30 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #4 – Controller under stress •  Multiple places to check –  show cpuload current –  show datapath bwm –  show datapath bridge counters –  show datapath crypto –  show datapath frame –  show datapath maintenance –  show datapath message-queue –  show datapath utilization –  show memory –  show netstat –  show processes sort-by cpu
  • 31. 31 31 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #3 - Client Connectivity/Perf Issues •  RF Issues –  Make use of spectrum analyzer function, or, check the radio stats (covered in the RF presentation) –  Causes may be 802.11 or non 802.11 related –  Some s/w options exist, including s/w retry, interference immunity –  Sometimes 2.4GHz just cannot cope •  Public events and stadiums are a good example
  • 32. 32 32 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #3 - Client Connectivity/Perf Issues •  Client driver issues –  Many clients have their own strange behaviors •  Vendor algorithms for roaming are often secret, some clients are notoriously sticky •  Same for selection of 11gn vs. 11an for dual band clients •  Can try a dedicated test SSID profile for a problem client on a single AP –  Where possible, always try to update drivers •  Try to work out “everyone affected or just that client”
  • 33. 33 33 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #3 - Client Connectivity/Perf Issues •  Client driver issues –  Driver settings can influence connectivity •  Power save and battery/AC status can impact “ping tests” •  To much “roaming aggressiveness” can cause thrashing –  Be careful of dual band clients that don’t support the same channel set as the APs •  Many client chipsets don’t support UNII-2/UNII-2e channels •  Some Wi-Fi cards are regionalized and may not support your regulatory domain •  Band-steering may be trying to steer you to a channel the client doesn’t support (i.e. Galaxy Tab doesn’t use UNII-3)
  • 34. 34 34 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #3 - Client Connectivity/Perf Issues •  Config on controller –  In noisy 2.4GHz environment, default ARM settings may be too aggressive for noise/error threshold channel changes •  Review ARM history “show ap arm history ap-name <ap>” •  Increase 2.4GHz ARM profile “noise-wait-time” and/or “error-wait- time” to be more tolerant of noisy/congested 2.4GHz –  Aggressive config tuning for 2.4GHz (especially for voice) can often cause reduced coverage •  Often results in low speed rates removed from SSID profiles •  wlan ssid-profile <profile> local-probe-req-thresh •  Need to find a balance of the right snr
  • 35. 35 35 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #3 - Client Connectivity/Perf Issues •  Config on controller –  Apple 10.6.x iMAC devices with 3x3 Atheros chipsets sold in 2011 had A-MSDU enabled by default, Aruba had it disabled until recently due to a bug. •  “firewall amsdu” •  Apple disabled AMSDU by default on 10.7.x –  Older non-802.11n devices may have interoperability issues with 802.11n APs •  Commonly seen with handheld/industrial devices •  Often enabling single chain legacy can help •  Transmits legacy non 11n frames on single radio chain •  “rf ht-radio-profile <profile> single-chain-legacy”
  • 36. 36 36 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #3 - Client Connectivity/Perf Issues •  Important L3 host stuck in user table –  If a packet with a source IP of (for example) the default gateway arrives via an IP, the controller will create a user entry for it. –  This can cause intermittent connectivity issues due to firewall policy or session limit exceeded –  Often triggered by Windows bridging between wired and wireless. Could also be caused by a host with static IP. –  Use validuser ACL to prevent users being created for important IP addresses. ip access-list session validuser any any svc-sec-papi permit network 169.254.0.0 255.255.0.0 any any deny alias protected_hosts any any deny any any any permit ipv6 any any any permit ! netdestination protected_hosts host 192.168.1.253 host 192.168.1.254 network 10.0.0.0 255.255.255.0
  • 37. 37 37 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #3 - Client Connectivity/Perf Issues •  Authentication issues –  Incorrect time settings on clients can cause certificate validation issues, often silently –  For windows clients, use MSFT tracing “netsh ras set tracing * enabled” to debug issues on Windows side –  Use ArubaOS command “show auth-tracebuf” for all auth issues •  This is a magical command ! •  Observe how this output looks for successful/regular auth •  Compare it when problems arise (can often spot certificate issues with this command)
  • 38. 38 38 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #3 - Client Connectivity/Perf Issues Nov 3 11:08:02 station-up * 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - - wpa2 aes Nov 3 11:08:02 station-data-ready * 00:21:6a:8b:0a:dc 00:00:00:00:00:00 180 - Nov 3 11:08:02 m-auth resp * 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - - authenticated Nov 3 11:08:02 wpa2-key1 <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - 117 Nov 3 11:08:02 eap-start -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - - Nov 3 11:08:02 eap-id-req <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 2 5 Nov 3 11:08:02 eap-id-resp -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 2 44 host/pc1.lab.com Nov 3 11:08:02 rad-req -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 11 259 Nov 3 11:08:02 rad-resp <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 11 129 Nov 3 11:08:02 eap-req <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 144 6 Nov 3 11:08:02 eap-resp -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 144 180 Nov 3 11:08:02 rad-req -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 12 478 Nov 3 11:08:02 rad-resp <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 12 1141 Nov 3 11:08:02 eap-req <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 145 1012 Nov 3 11:08:02 eap-resp -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 145 6 Nov 3 11:08:02 rad-req -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 13 304 Nov 3 11:08:02 rad-resp <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 13 1137 Nov 3 11:08:02 eap-req <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 146 1008 Nov 3 11:08:02 eap-resp -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 146 6 Nov 3 11:08:02 rad-req -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 14 304 Nov 3 11:08:02 rad-resp <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 14 1137 Nov 3 11:08:02 eap-req <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 147 1008 Nov 3 11:08:02 eap-resp -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 147 6 Nov 3 11:08:02 rad-req -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/rradpolicy1 15 304 Nov 3 11:08:02 rad-req -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 19 1436 Nov 3 11:08:02 rad-resp <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/radpolicy1 19 188 Nov 3 11:08:02 eap-req <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 152 65 Nov 3 11:08:02 eap-resp -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 152 6 Nov 3 11:08:02 rad-req -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/ise-policy1 20 304 Nov 3 11:08:02 rad-accept <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30/ise-policy1 20 276 Nov 3 11:08:02 eap-success <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 152 4 Nov 3 11:08:02 station-data-ready * 00:21:6a:8b:0a:dc 00:00:00:00:00:00 180 - Nov 3 11:08:02 m-auth resp * 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - - authenticated Nov 3 11:08:02 wpa2-key1 <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - 117 Nov 3 11:08:02 wpa2-key2 -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - 119 Nov 3 11:08:02 wpa2-key3 <- 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - 151 Nov 3 11:08:02 wpa2-key4 -> 00:21:6a:8b:0a:dc 00:1a:1e:66:f7:30 - 95 VLAN username server Radius ID EAP ID length result
  • 39. 39 39 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #3 - Client Connectivity/Perf Issues •  Recently seen authentication issues –  Cannot connect dot1x wireless on XP via RDP •  Refer http://technet.microsoft.com/en-us/network/dd727529.aspx#EWKAC •  Use VNC instead, resolved vista/NPS2008 –  IAS can “discard” messages, which triggers the ArubaOS “server out of service” as no response is seen •  Hotfix exists for unknown domain, for other cases always send reject not “discard” –  XP SP3 clients have PEAP auth issues with NPS 2008 •  http://support.microsoft.com/kb/969111
  • 40. 40 40 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #2 – Common misconfiguration •  Spanning Tree –  Beware changes to STP type between ArubaOS versions •  3.x à 3.4.x RSTP became default •  6.x à PVST+ added (not used by default) –  If controller connectivity is impacted after an upgrade, it may be STP related. –  Test thoroughly any STP interop between controller and your switches. •  Example: our RSTP does not always play nice with MSTP which is the default on many switches. •  Controller DHCP scalability –  Internal DHCP server is not recommended to be used for more than 2 x /24 scopes
  • 41. 41 41 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #2 – Common misconfiguration •  Too fast periodic DB sync –  Master to redundant master periodic DB sync requires the controller to dump various databases and transfer them across. –  While the databases are being dumped, client processing is not occurring. –  In most cases, periodic DB sync should not be required more than once per 24 hours. •  Misconfigured multi-association on Virtual AP –  Also known as “fast-roaming” –  Multi-association should not be configured. Having it enabled can cause the APs to hit max-client count very quickly. –  Planned to be removed in rel 6.2
  • 42. 42 42 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #2 – Common misconfiguration •  Captive portal web max clients too low –  If you are using the controller captive portal for many users, you must adjust the default setting for “Maximum supported concurrent clients” to be higher, i.e. •  “web-server web-max-clients 300” –  Default value is 25 to protect HTTPd from abuse
  • 43. 43 43 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #2 – Common misconfiguration •  Insufficient power for 2nd enet port on AP 13x –  Not a controller misconfiguration per-se –  AP13x hardware must have 802.3at power to run both ethernet ports –  If only presented with 802.3af power, can still run 3x3 but only with enet0 •  After bootup, s/w will disable enet1 –  Ensure to always connect enet0 if just using a single cable to avoid any issues with AP power management
  • 44. 44 44 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #1 - Best practice tweaks •  Layer 2 broadcast filtering –  Virtual AP broadcast filter “arp” –  Virtual AP broadcast filter “all” –  Use these on tunnel mode VAPs to reduce the amount of broadcast and multicast traffic that may leak from the layer2 network onto the air •  i.e. filters out CDP, STP BDPUs etc. from leaking to WLAN •  Make sure that the VAP is not required to support multicast traffic, often voice networks will use multicast for call hold music etc
  • 45. 45 45 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #1 - Best practice tweaks •  RF optimizations –  band-steering •  Multiple modes available – “force”, “prefer”, “balance” –  s/w retry (new in 6.1.2.6+) •  A different retry mechanism for 11n clients •  Shows benefit with i-devices, especially in presence of interference •  “wlan ht-ssid-profile <profile> sw-retry” –  High density 5GHz should use 20MHz channels not 40MHz •  Also watch out for this with outdoor mesh – most countries only have 2 non overlapped 40MHz outdoor channels
  • 46. 46 46 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #1 - Best practice tweaks •  Rate optimizations –  SSID profile “mcast-rate-opt” •  Send broadcast and multicast frames at the rate of the worst client, up to 24Mbps. Improves WLAN air time utilization –  SSID profile “eapol-rate-opt” (new in 6.1.2.7+) •  Use lowest tx rates for EAPOL frames to improve roaming reliability for dot1x enabled devices •  Auth optimizations –  Decrease default EAPOL ID request period from 30 to 3 seconds, for faster state recovery •  aaa authentication dot1x <profile> timer idrequest_period 3 –  Enable “validate-pmkid” in dot1x profile to prevent any state mismatches with half baked OKC clients
  • 47. 47 47 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved #1 - Best practice tweaks •  Load balancing optimizations –  Always use a wlan traffic mgmt profile when doing high density testing •  “fair-access” is the best practice configuration for all client types •  “preferred-access” if non-11n clients do not have an application performance requirement –  SSID local probe response threshold •  “wlan ssid-profile <profile> local-probe-req-thresh X” is a useful way to stop APs from responding to probes from distant clients. •  Use “show ap debug client-table ap-name <ap>” to determine signal from nearby clients •  Typical values of X might be in the range 20~30,
  • 48. 48 48 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved In conclusion •  support@arubanetworks.com –  One email address for all products •  Timezone/shift-work nature of support front line –  You can always request your ticket to be moved to another time-zone –  Avoid unicasting emails/attachments to support staff •  Using reply to all will get more eyes on your issue •  Always call support for urgent issues •  Please exercise caution when making changes –  Always keep off-box backups –  When tweaking, incrementally add changes •  ArubaOS has a number of ways to contain changes
  • 49. 49 49 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved Takeaways TAC Quick Reference Guide –  https://support.arubanetworks.com/DOCUMENTATION/tabid/77/DMXModule/512/ Command/Core_Download/Default.aspx?EntryId=1371 Validated Reference Designs (VRD) –  http://www.arubanetworks.com/technology/reference-design-guides/ Airheads Social –  http://community.arubanetworks.com/ Aruba Knowledge Base –  https://kb.arubanetworks.com/ Raise a ticket for any product, RMA, anything ! –  support@arubanetworks.com Requests for Enhancements (RFE) –  Please discuss with your SE/Sales team Outdoor planner tool –  https://outdoorplanner.arubanetworks.com/
  • 50. CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved 5050 CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved Questions?
  • 51. CONFIDENTIAL © Copyright 2012. Aruba Networks, Inc. All rights reserved 5151 Coming Up: Tech Playground 12pm – 1:30pm