SlideShare ist ein Scribd-Unternehmen logo
1 von 38
ARUBA REMOTE ACCESS POINT (RAP)
TROUBLESHOOTING
Technical Climb Webinar
10:00 GMT | 11:00 CET | 13:00 GST
October 17th, 2017
Presenter: Pravin Kumar
Pravin.kumar2@hpe.com
2
Welcome to the Technical Climb Webinar
Listen to this webinar using the computer
audio broadcasting or dial in by phone.
The dial in number can be found in the audio
panel, click additional numbers to view local
dial in numbers.
If you experience any difficulties accessing
the webinar contact us
using the questions panel.
3
Housekeeping
This webinar will be recorded
All lines will be muted during the
webinar
How can you ask questions?
Use the question panel on your screen
The recorded presentation will be posted on Arubapedia for
Partners (https://arubapedia.arubanetworks.com/afp/)
RAP SUPPORT IN 8.X
5
Agenda
• Introduction
• RAP support in clustering
• Terminology
• Configuration
• Troubleshooting and Logs
• Debugging commands
• Limitations
6
Introduction
Without Cluster:
• RAP should terminate on VRRP-IP or needs to configure lms & bkp-lms for redundancy
• Client will deauth when AP fail over to other controller
• Client traffic is interrupted during failover
• RAP needs to download entire config on every rebootstrap/failover
With Cluster (8.x):
• Classic cluster controller supports redundancy for both Aps and clients
• Dormant(standby) entry will be created for wireless users on standby controller
• RAP will establish tunnel with all cluster members with same inner-ip for easy of management.
• Cluster is limited to max 4 nodes in case of RAP
RAP SUPPORT IN CLUSTERING
8
Terminology
A-AAC
Active AP anchor controller, role given to AP where it is terminated.
Config will be download from A-AAC controller.
S-AAC
Standby AP anchor controller, role given to AP where standby tunnel
is established on controller.
When active goes down Standby controller becomes active
9
Terminology Contd..
UAC
User Anchor Controller, a role given to a controller from individual User
perspective. UAC handles all the wireless client traffic, including
association/disassociation notification, authentication, and all the unicast
traffic between controller and the client.
The purpose of UAC is to fix the controller so that when wireless client roams
between APs, the controller remains the same within the cluster.
S-UAC
Standby Controller from the User perspective
User fails over to this controllers on Active UAC down
10
Clustering overview
Clustering for Mission Critical Networks
1
Seamless Campus Roaming
Clients stay anchored to a single MD when
roaming across controllers
3
Client Load Balancing
Users automatically load balanced across
cluster members
2
Hitless Client Failover
User traffic uninterrupted upon cluster
member failure
Mobility
Master/Standby
MCMC MC
11
Clustering
Highlights
1 Available ONLY with Mobility
Master
2 Only among Managed Devices
(not MM)
3 No License needed
MC MC
Mobility
Master/Standby
Headquarter
MC
12
Clustering
Highlights
1 Available ONLY with Mobility
Master
2 Only among Managed Devices
(not MM)
3 No License needed
MC MC
Mobility
Master/Standby
Headquarter
4 CAP, RAP and Mesh AP support MC
13
Clustering
Highlights
5 72xx, 70xx and VMC supported
721
0
7240
7220
7205703
0
70
24
70
10
70
05
70
08
VMC-
50 VMC-
250 VMC-
1k
14
70
24
Clustering
Highlights
5 72xx, 70xx and VMC supported
All Managed Devices need to run
the
same software version
6 721
0
7240
7220
7205703
0
70
10
70
05
70
08
8.0.
0
8.0.
1
8.0.
1
8.0.
1
8.0.
1
8.0.
1
8.0.
1
8.0.
1
8.0.
1
8.0.
1
8.0.
1
8.0.
1
8.0.
1
VMC-
50 VMC-
250 VMC-
1k
15
Clustering
Cluster Capacity
1 Up to 12 nodes in a cluster
when using 72xx devices
7240
7205
7220
7205
7220
7205
7210
7205
7240
7205
7240
7205
16
Clustering
Cluster Capacity
1 Up to 12 nodes in a cluster
when using 72xx devices
2 Up to 4 nodes in a cluster
when using 70xx devices
7010
7005
7030
7024
17
Clustering
Cluster Capacity
1 Up to 12 nodes in a cluster
when using 72xx devices
VMC-
50 VMC-
250 VMC-
1k
2 Up to 4 nodes in a cluster
when using 70xx devices
3 Up to 4 nodes in a cluster
when using VMC devices
VMC-
1k
18
Clustering
Key Considerations
1 Clustering and HA-AP Fast
Failover mutually exclusive
2 Cluster members need to run
the same firmware version
3 Size of Cluster terminating
RAPs limited to 4
4 Mix of 72xx and 70xx devices
in a cluster not recommended
19
Clustering
AP Anchor Controller (AAC)
AAC S-AAC
Mobility
Master/Standby
1
AP sets up Active Tunnels with
its LMS
(AAC)
2 S-AAC is dynamically assigned
from other cluster members
3 AP sets up Standby Tunnels with
S-AAC
Active Tunnel
Standby Tunnel
20
Clustering
AAC Failover
AAC S-AAC
Mobility
Master/Standby
1 AAC fails and Failure detected
by S-AAC
2 AP tears tunnel and S-AAC
instructs AP to fail over
Active Tunnel
Standby Tunnel
AAC
21
Clustering
AAC Failover
AAC S-AAC
Mobility
Master/Standby
1 AAC fails and Failure detected
by S-AAC
2 AP tears tunnel and S-AAC
instructs AP to fail over
3 AP builds Active tunnels with
new AAC
Active Tunnel
Standby Tunnel
AAC AAC
4 New S-AAC is assigned by Cluster
Leader
S-AAC
22
CLI Configuration
• Create rap pool on MM/mynode node
• lc-rap-pool cluster-rap-pool <StartAddress> <EndAddress>
Configure cluster profile at node
(Aruba) [cluster2] (config) #lc-cluster group-profile 72xx
(Aruba) [cluster2] (Classic Controller Cluster Profile "72xx")#controller 10.29.163.2
(Aruba) [cluster2] (Classic Controller Cluster Profile "72xx")# controller 10.29.163.3
(Aruba) [cluster2] (Classic Controller Cluster Profile "72xx")# #redundancy
(Aruba) [cluster2] (Classic Controller Cluster Profile "72xx")# #write memory
• Enable cluster membership on all nodes
(Aruba) [cluster2] (config) #change-config-node /md/cluster2/00:1a:1e:01:2f:58
(Aruba) [00:1a:1e:01:2f:58] (config) #lc-cluster group-membership 72xx
(Aruba) [00:1a:1e:01:2f:58] (config) #write memory
23
UI Configuration
24
UI Configuration Contd..
25
Config verification
(ArubaMM2)#show lc-cluster group-membership
(ArubaMM3)#show lc-cluster group-membership
26
Config verification
(ArubaMM2) #show ap database
(ArubaMM3) #show ap database
27
Config verification
(ArubaMM2) #show whitelist-db rap
(ArubaMM3) #show whitelist-db rap
28
Troubleshooting commands
(ArubaMM2) #show crypto isakmp sa
(ArubaMM3) #show crypto isakmp sa
29
Troubleshooting commands
To check cluster IP entries, execute below command and it will work only on MM.
(Aruba) [mynode] (config) #show crypto isakmp clusterIP
30
Troubleshooting commands
(ArubaMM2) #show user-table
(ArubaMM3) #show user-table standby
31
Troubleshooting commands
(ArubaMM2) #show datapath station
(ArubaMM3) #show datapath station
32
Troubleshooting commands
(ArubaMM2) #show gsm debug channel user
(ArubaMM3) #show gsm debug channel user
33
Troubleshooting commands
(ArubaMM2) # show aaa cluster essid-all users
(ArubaMM2) #show aaa cluster essid-all bucketmap
34
Troubleshooting commands
(ArubaMM3) # show aaa cluster essid-all users
(ArubaMM3) #show aaa cluster essid-all bucketmap
35
Logging and Debugging commands
logging security level debugging
logging security level debugging process crypto
show ap remote debug bucketmap datapath ap-name <ap_name>
show ap remote debug bucketmap sapd ap-name <ap_name>
show ap remote debug bucketmap stm ap-name <ap_name>
show cluster-tech-support <filename>
CLI to show Active/standby Users:
show aaa cluster essid-all users <<< shows the active users for all the available essids
show aaa cluster essid-all users standby <<< shows the dormant users for all the available essids
show aaa cluster essid <essid> users <<< shows all the active users for a given essid
show aaa cluster essid <essid> users standby <<< shows all the dormant users for a given essid
36
Limitations
Cluster is not supported for PSK-RAPs
RAP whitelistdb entry should be configured only on MM-M.
Cluster is not supported for external whitelilstdb
Cluster supports only for Cert-based RAPs
37
Questions ?
THANK YOU!

Weitere ähnliche Inhalte

Was ist angesagt?

EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...
EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...
EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...Aruba, a Hewlett Packard Enterprise company
 

Was ist angesagt? (20)

EMEA Airheads- ArubaOS - Rogue AP troubleshooting
EMEA Airheads- ArubaOS - Rogue AP troubleshootingEMEA Airheads- ArubaOS - Rogue AP troubleshooting
EMEA Airheads- ArubaOS - Rogue AP troubleshooting
 
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba CentralAirheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
 
Airheads Meetups- High density WLAN
Airheads Meetups- High density WLANAirheads Meetups- High density WLAN
Airheads Meetups- High density WLAN
 
Useful cli commands v1
Useful cli commands v1Useful cli commands v1
Useful cli commands v1
 
Aruba 802.11n Networks Validated Reference Design
Aruba 802.11n Networks Validated Reference DesignAruba 802.11n Networks Validated Reference Design
Aruba 802.11n Networks Validated Reference Design
 
Aruba Remote Access Point (RAP) Networks Validated Reference Design
Aruba Remote Access Point (RAP) Networks Validated Reference DesignAruba Remote Access Point (RAP) Networks Validated Reference Design
Aruba Remote Access Point (RAP) Networks Validated Reference Design
 
EMEA Airheads - What does AirMatch do differently?v2
 EMEA Airheads - What does AirMatch do differently?v2 EMEA Airheads - What does AirMatch do differently?v2
EMEA Airheads - What does AirMatch do differently?v2
 
Adapting to evolving user, security, and business needs with aruba clear pass
Adapting to evolving user, security, and business needs with aruba clear passAdapting to evolving user, security, and business needs with aruba clear pass
Adapting to evolving user, security, and business needs with aruba clear pass
 
RAP Networks Validated Reference Design
RAP Networks Validated Reference DesignRAP Networks Validated Reference Design
RAP Networks Validated Reference Design
 
EMEA Airheads How licensing works in Aruba OS 8.x
EMEA Airheads  How licensing works in Aruba OS 8.xEMEA Airheads  How licensing works in Aruba OS 8.x
EMEA Airheads How licensing works in Aruba OS 8.x
 
EMEA Airheads- ArubaOS - Cluster Manager
EMEA Airheads- ArubaOS - Cluster ManagerEMEA Airheads- ArubaOS - Cluster Manager
EMEA Airheads- ArubaOS - Cluster Manager
 
Advanced rf troubleshooting_peter lane
Advanced rf troubleshooting_peter laneAdvanced rf troubleshooting_peter lane
Advanced rf troubleshooting_peter lane
 
EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...
EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...
EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...
 
ArubaOS DHCP Fingerprinting
ArubaOS DHCP FingerprintingArubaOS DHCP Fingerprinting
ArubaOS DHCP Fingerprinting
 
EMEA Airheads- Instant AP- Instant AP Best Practice Configuration
EMEA Airheads- Instant AP- Instant AP Best Practice ConfigurationEMEA Airheads- Instant AP- Instant AP Best Practice Configuration
EMEA Airheads- Instant AP- Instant AP Best Practice Configuration
 
Guest Access with ArubaOS
Guest Access with ArubaOSGuest Access with ArubaOS
Guest Access with ArubaOS
 
EMEA Airheads- ArubaOS - High availability with AP Fast Failover
EMEA Airheads- ArubaOS - High availability with AP Fast FailoverEMEA Airheads- ArubaOS - High availability with AP Fast Failover
EMEA Airheads- ArubaOS - High availability with AP Fast Failover
 
Enabling AirPrint & AirPlay on Your Network
Enabling AirPrint & AirPlay on Your NetworkEnabling AirPrint & AirPlay on Your Network
Enabling AirPrint & AirPlay on Your Network
 
Breakout - Airheads Macau 2013 - Top 10 Tips from Aruba TAC
Breakout - Airheads Macau 2013 - Top 10 Tips from Aruba TAC Breakout - Airheads Macau 2013 - Top 10 Tips from Aruba TAC
Breakout - Airheads Macau 2013 - Top 10 Tips from Aruba TAC
 
Advanced ClearPass Workshop
Advanced ClearPass WorkshopAdvanced ClearPass Workshop
Advanced ClearPass Workshop
 

Ähnlich wie EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting

A10_CompactTrainingv5.pdf (1).pdf
A10_CompactTrainingv5.pdf (1).pdfA10_CompactTrainingv5.pdf (1).pdf
A10_CompactTrainingv5.pdf (1).pdfneoalt
 
Base Designs Lab Setup for Validated Reference Design
Base Designs Lab Setup for Validated Reference DesignBase Designs Lab Setup for Validated Reference Design
Base Designs Lab Setup for Validated Reference DesignContent Rules, Inc.
 
Cisco data center support
Cisco data center supportCisco data center support
Cisco data center supportKrunal Shah
 
EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...
EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...
EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...Aruba, a Hewlett Packard Enterprise company
 
Mobile Experience Management and Network Services Health Check with Aruba Air...
Mobile Experience Management and Network Services Health Check with Aruba Air...Mobile Experience Management and Network Services Health Check with Aruba Air...
Mobile Experience Management and Network Services Health Check with Aruba Air...Aruba, a Hewlett Packard Enterprise company
 
CCIE Real LAB LAB 1.1 CCIEREALLABWORKBOOK.COM
CCIE Real LAB LAB 1.1  CCIEREALLABWORKBOOK.COMCCIE Real LAB LAB 1.1  CCIEREALLABWORKBOOK.COM
CCIE Real LAB LAB 1.1 CCIEREALLABWORKBOOK.COMcciereallabworkbooks
 
Important cisco-chow-commands
Important cisco-chow-commandsImportant cisco-chow-commands
Important cisco-chow-commandsssusere31b5c
 
©LWTAOB© 2013 Cisco andLab – O.docx
©LWTAOB© 2013 Cisco andLab – O.docx©LWTAOB© 2013 Cisco andLab – O.docx
©LWTAOB© 2013 Cisco andLab – O.docxLynellBull52
 
CCIE Real LAB LAB 1.1 CCIEREALLABWORKBOOK.COM
CCIE Real LAB LAB 1.1  CCIEREALLABWORKBOOK.COMCCIE Real LAB LAB 1.1  CCIEREALLABWORKBOOK.COM
CCIE Real LAB LAB 1.1 CCIEREALLABWORKBOOK.COMcciereallabworkbooks
 
Ccna 3 chapter 2 v4.0 answers 2011
Ccna 3 chapter 2 v4.0 answers 2011Ccna 3 chapter 2 v4.0 answers 2011
Ccna 3 chapter 2 v4.0 answers 2011Dân Chơi
 
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...Aruba, a Hewlett Packard Enterprise company
 
Power path viewer_technical_presentation
Power path viewer_technical_presentationPower path viewer_technical_presentation
Power path viewer_technical_presentationxKinAnx
 

Ähnlich wie EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting (20)

Wireless LAN Design Fundamentals in the Campus
Wireless LAN Design Fundamentals in the CampusWireless LAN Design Fundamentals in the Campus
Wireless LAN Design Fundamentals in the Campus
 
Aruba OS 6.3 Command Line Interface Reference Guide
Aruba OS 6.3 Command Line Interface Reference GuideAruba OS 6.3 Command Line Interface Reference Guide
Aruba OS 6.3 Command Line Interface Reference Guide
 
A10_CompactTrainingv5.pdf (1).pdf
A10_CompactTrainingv5.pdf (1).pdfA10_CompactTrainingv5.pdf (1).pdf
A10_CompactTrainingv5.pdf (1).pdf
 
Base Designs Lab Setup for Validated Reference Design
Base Designs Lab Setup for Validated Reference DesignBase Designs Lab Setup for Validated Reference Design
Base Designs Lab Setup for Validated Reference Design
 
EMEA Airheads - Multi zone ap and centralized image upgrade
EMEA Airheads - Multi zone ap and centralized image upgradeEMEA Airheads - Multi zone ap and centralized image upgrade
EMEA Airheads - Multi zone ap and centralized image upgrade
 
Cisco data center support
Cisco data center supportCisco data center support
Cisco data center support
 
EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...
EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...
EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...
 
Mobile Experience Management and Network Services Health Check with Aruba Air...
Mobile Experience Management and Network Services Health Check with Aruba Air...Mobile Experience Management and Network Services Health Check with Aruba Air...
Mobile Experience Management and Network Services Health Check with Aruba Air...
 
Iuwne10 S06 L03
Iuwne10 S06 L03Iuwne10 S06 L03
Iuwne10 S06 L03
 
CCIE Real LAB LAB 1.1 CCIEREALLABWORKBOOK.COM
CCIE Real LAB LAB 1.1  CCIEREALLABWORKBOOK.COMCCIE Real LAB LAB 1.1  CCIEREALLABWORKBOOK.COM
CCIE Real LAB LAB 1.1 CCIEREALLABWORKBOOK.COM
 
Important cisco-chow-commands
Important cisco-chow-commandsImportant cisco-chow-commands
Important cisco-chow-commands
 
Ap7181 cli guide
Ap7181 cli guideAp7181 cli guide
Ap7181 cli guide
 
©LWTAOB© 2013 Cisco andLab – O.docx
©LWTAOB© 2013 Cisco andLab – O.docx©LWTAOB© 2013 Cisco andLab – O.docx
©LWTAOB© 2013 Cisco andLab – O.docx
 
Design Fundamentals for Remote and Branch Access Networks
Design Fundamentals for Remote and Branch Access NetworksDesign Fundamentals for Remote and Branch Access Networks
Design Fundamentals for Remote and Branch Access Networks
 
CCIE Real LAB LAB 1.1 CCIEREALLABWORKBOOK.COM
CCIE Real LAB LAB 1.1  CCIEREALLABWORKBOOK.COMCCIE Real LAB LAB 1.1  CCIEREALLABWORKBOOK.COM
CCIE Real LAB LAB 1.1 CCIEREALLABWORKBOOK.COM
 
Take a Walk on the Wired Side
Take a Walk on the Wired SideTake a Walk on the Wired Side
Take a Walk on the Wired Side
 
Ccna 3 chapter 2 v4.0 answers 2011
Ccna 3 chapter 2 v4.0 answers 2011Ccna 3 chapter 2 v4.0 answers 2011
Ccna 3 chapter 2 v4.0 answers 2011
 
CCNA 2
CCNA 2 CCNA 2
CCNA 2
 
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
 
Power path viewer_technical_presentation
Power path viewer_technical_presentationPower path viewer_technical_presentation
Power path viewer_technical_presentation
 

Mehr von Aruba, a Hewlett Packard Enterprise company

Mehr von Aruba, a Hewlett Packard Enterprise company (18)

Airheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard AgentsAirheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
 
EMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Advance Aruba CentralEMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Advance Aruba Central
 
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.xEMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
 
EMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS SwitchEMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS Switch
 
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS SwitchEMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
 
Introduction to AirWave 10
Introduction to AirWave 10Introduction to AirWave 10
Introduction to AirWave 10
 
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS SwitchEMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
 
EMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- Aruba Central with Instant APEMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- Aruba Central with Instant AP
 
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.xEMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
 
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
EMEA Airheads-  Getting Started with the ClearPass REST API – CPPMEMEA Airheads-  Getting Started with the ClearPass REST API – CPPM
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
 
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)
 
Airheads Meetups: 8400 Presentation
Airheads Meetups: 8400 PresentationAirheads Meetups: 8400 Presentation
Airheads Meetups: 8400 Presentation
 
Airheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau PresentationAirheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau Presentation
 
Airheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes ArubaAirheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes Aruba
 
EMEA Airheads - Configuring different APIs in Aruba 8.x
EMEA Airheads - Configuring different APIs  in Aruba 8.x EMEA Airheads - Configuring different APIs  in Aruba 8.x
EMEA Airheads - Configuring different APIs in Aruba 8.x
 
Bringing up Aruba Mobility Master, Managed Device & Access Point
Bringing up Aruba Mobility Master, Managed Device & Access PointBringing up Aruba Mobility Master, Managed Device & Access Point
Bringing up Aruba Mobility Master, Managed Device & Access Point
 
EMEA Airheads- Aruba 8.x Architecture overview & UI Navigation
EMEA Airheads- Aruba 8.x Architecture overview & UI NavigationEMEA Airheads- Aruba 8.x Architecture overview & UI Navigation
EMEA Airheads- Aruba 8.x Architecture overview & UI Navigation
 
EMEA Airheads- ClearPass extensions and how they can help
EMEA Airheads-  ClearPass extensions and how they can helpEMEA Airheads-  ClearPass extensions and how they can help
EMEA Airheads- ClearPass extensions and how they can help
 

Kürzlich hochgeladen

EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024Results
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?Igalia
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slidevu2urc
 

Kürzlich hochgeladen (20)

EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 

EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting

  • 1. ARUBA REMOTE ACCESS POINT (RAP) TROUBLESHOOTING Technical Climb Webinar 10:00 GMT | 11:00 CET | 13:00 GST October 17th, 2017 Presenter: Pravin Kumar Pravin.kumar2@hpe.com
  • 2. 2 Welcome to the Technical Climb Webinar Listen to this webinar using the computer audio broadcasting or dial in by phone. The dial in number can be found in the audio panel, click additional numbers to view local dial in numbers. If you experience any difficulties accessing the webinar contact us using the questions panel.
  • 3. 3 Housekeeping This webinar will be recorded All lines will be muted during the webinar How can you ask questions? Use the question panel on your screen The recorded presentation will be posted on Arubapedia for Partners (https://arubapedia.arubanetworks.com/afp/)
  • 5. 5 Agenda • Introduction • RAP support in clustering • Terminology • Configuration • Troubleshooting and Logs • Debugging commands • Limitations
  • 6. 6 Introduction Without Cluster: • RAP should terminate on VRRP-IP or needs to configure lms & bkp-lms for redundancy • Client will deauth when AP fail over to other controller • Client traffic is interrupted during failover • RAP needs to download entire config on every rebootstrap/failover With Cluster (8.x): • Classic cluster controller supports redundancy for both Aps and clients • Dormant(standby) entry will be created for wireless users on standby controller • RAP will establish tunnel with all cluster members with same inner-ip for easy of management. • Cluster is limited to max 4 nodes in case of RAP
  • 7. RAP SUPPORT IN CLUSTERING
  • 8. 8 Terminology A-AAC Active AP anchor controller, role given to AP where it is terminated. Config will be download from A-AAC controller. S-AAC Standby AP anchor controller, role given to AP where standby tunnel is established on controller. When active goes down Standby controller becomes active
  • 9. 9 Terminology Contd.. UAC User Anchor Controller, a role given to a controller from individual User perspective. UAC handles all the wireless client traffic, including association/disassociation notification, authentication, and all the unicast traffic between controller and the client. The purpose of UAC is to fix the controller so that when wireless client roams between APs, the controller remains the same within the cluster. S-UAC Standby Controller from the User perspective User fails over to this controllers on Active UAC down
  • 10. 10 Clustering overview Clustering for Mission Critical Networks 1 Seamless Campus Roaming Clients stay anchored to a single MD when roaming across controllers 3 Client Load Balancing Users automatically load balanced across cluster members 2 Hitless Client Failover User traffic uninterrupted upon cluster member failure Mobility Master/Standby MCMC MC
  • 11. 11 Clustering Highlights 1 Available ONLY with Mobility Master 2 Only among Managed Devices (not MM) 3 No License needed MC MC Mobility Master/Standby Headquarter MC
  • 12. 12 Clustering Highlights 1 Available ONLY with Mobility Master 2 Only among Managed Devices (not MM) 3 No License needed MC MC Mobility Master/Standby Headquarter 4 CAP, RAP and Mesh AP support MC
  • 13. 13 Clustering Highlights 5 72xx, 70xx and VMC supported 721 0 7240 7220 7205703 0 70 24 70 10 70 05 70 08 VMC- 50 VMC- 250 VMC- 1k
  • 14. 14 70 24 Clustering Highlights 5 72xx, 70xx and VMC supported All Managed Devices need to run the same software version 6 721 0 7240 7220 7205703 0 70 10 70 05 70 08 8.0. 0 8.0. 1 8.0. 1 8.0. 1 8.0. 1 8.0. 1 8.0. 1 8.0. 1 8.0. 1 8.0. 1 8.0. 1 8.0. 1 8.0. 1 VMC- 50 VMC- 250 VMC- 1k
  • 15. 15 Clustering Cluster Capacity 1 Up to 12 nodes in a cluster when using 72xx devices 7240 7205 7220 7205 7220 7205 7210 7205 7240 7205 7240 7205
  • 16. 16 Clustering Cluster Capacity 1 Up to 12 nodes in a cluster when using 72xx devices 2 Up to 4 nodes in a cluster when using 70xx devices 7010 7005 7030 7024
  • 17. 17 Clustering Cluster Capacity 1 Up to 12 nodes in a cluster when using 72xx devices VMC- 50 VMC- 250 VMC- 1k 2 Up to 4 nodes in a cluster when using 70xx devices 3 Up to 4 nodes in a cluster when using VMC devices VMC- 1k
  • 18. 18 Clustering Key Considerations 1 Clustering and HA-AP Fast Failover mutually exclusive 2 Cluster members need to run the same firmware version 3 Size of Cluster terminating RAPs limited to 4 4 Mix of 72xx and 70xx devices in a cluster not recommended
  • 19. 19 Clustering AP Anchor Controller (AAC) AAC S-AAC Mobility Master/Standby 1 AP sets up Active Tunnels with its LMS (AAC) 2 S-AAC is dynamically assigned from other cluster members 3 AP sets up Standby Tunnels with S-AAC Active Tunnel Standby Tunnel
  • 20. 20 Clustering AAC Failover AAC S-AAC Mobility Master/Standby 1 AAC fails and Failure detected by S-AAC 2 AP tears tunnel and S-AAC instructs AP to fail over Active Tunnel Standby Tunnel AAC
  • 21. 21 Clustering AAC Failover AAC S-AAC Mobility Master/Standby 1 AAC fails and Failure detected by S-AAC 2 AP tears tunnel and S-AAC instructs AP to fail over 3 AP builds Active tunnels with new AAC Active Tunnel Standby Tunnel AAC AAC 4 New S-AAC is assigned by Cluster Leader S-AAC
  • 22. 22 CLI Configuration • Create rap pool on MM/mynode node • lc-rap-pool cluster-rap-pool <StartAddress> <EndAddress> Configure cluster profile at node (Aruba) [cluster2] (config) #lc-cluster group-profile 72xx (Aruba) [cluster2] (Classic Controller Cluster Profile "72xx")#controller 10.29.163.2 (Aruba) [cluster2] (Classic Controller Cluster Profile "72xx")# controller 10.29.163.3 (Aruba) [cluster2] (Classic Controller Cluster Profile "72xx")# #redundancy (Aruba) [cluster2] (Classic Controller Cluster Profile "72xx")# #write memory • Enable cluster membership on all nodes (Aruba) [cluster2] (config) #change-config-node /md/cluster2/00:1a:1e:01:2f:58 (Aruba) [00:1a:1e:01:2f:58] (config) #lc-cluster group-membership 72xx (Aruba) [00:1a:1e:01:2f:58] (config) #write memory
  • 25. 25 Config verification (ArubaMM2)#show lc-cluster group-membership (ArubaMM3)#show lc-cluster group-membership
  • 26. 26 Config verification (ArubaMM2) #show ap database (ArubaMM3) #show ap database
  • 27. 27 Config verification (ArubaMM2) #show whitelist-db rap (ArubaMM3) #show whitelist-db rap
  • 28. 28 Troubleshooting commands (ArubaMM2) #show crypto isakmp sa (ArubaMM3) #show crypto isakmp sa
  • 29. 29 Troubleshooting commands To check cluster IP entries, execute below command and it will work only on MM. (Aruba) [mynode] (config) #show crypto isakmp clusterIP
  • 30. 30 Troubleshooting commands (ArubaMM2) #show user-table (ArubaMM3) #show user-table standby
  • 31. 31 Troubleshooting commands (ArubaMM2) #show datapath station (ArubaMM3) #show datapath station
  • 32. 32 Troubleshooting commands (ArubaMM2) #show gsm debug channel user (ArubaMM3) #show gsm debug channel user
  • 33. 33 Troubleshooting commands (ArubaMM2) # show aaa cluster essid-all users (ArubaMM2) #show aaa cluster essid-all bucketmap
  • 34. 34 Troubleshooting commands (ArubaMM3) # show aaa cluster essid-all users (ArubaMM3) #show aaa cluster essid-all bucketmap
  • 35. 35 Logging and Debugging commands logging security level debugging logging security level debugging process crypto show ap remote debug bucketmap datapath ap-name <ap_name> show ap remote debug bucketmap sapd ap-name <ap_name> show ap remote debug bucketmap stm ap-name <ap_name> show cluster-tech-support <filename> CLI to show Active/standby Users: show aaa cluster essid-all users <<< shows the active users for all the available essids show aaa cluster essid-all users standby <<< shows the dormant users for all the available essids show aaa cluster essid <essid> users <<< shows all the active users for a given essid show aaa cluster essid <essid> users standby <<< shows all the dormant users for a given essid
  • 36. 36 Limitations Cluster is not supported for PSK-RAPs RAP whitelistdb entry should be configured only on MM-M. Cluster is not supported for external whitelilstdb Cluster supports only for Cert-based RAPs

Hinweis der Redaktion

  1. Current Aruba’s Move Architecture and what is the current challenge in this. Network Access: Layer 1 Access(AP’s) - Innovation from .11b to .11ac – Wireless or RF optimization – Client Match - Hardware changes Aggregation: (Local controllers or Mobility Controllers) All the client tunnel to the controller – AppRF – WCC - Wireless CP/DP – Not good for resilient – Upgrade and not good for failover – Load sharing is not possible Network Services: (Master Controllers or Master Mobility controller) Central mgmt – WMS + N+1 redundancy – No support for SDN(Software Defined Networking) or Open flow controllers– No Global view/visibility like topology, all AP’s. Airgroup - Need more scale and push for more intelligence or more memory.
  2. The AOS 8 Clustering feature was designed primarily for mission critical networks. Its goal is to provide full redundancy to APs and Wifi clients alike in case of a malfunction of one or more of its cluster members. Here are the benefits that could be immediately obtained from deploying on campus Aruba Mobility controllers as Managed Devices in a cluster configuration: Seamless Campus Roaming: The fact that clients remain anchored to a single controller (cluster member) throughout their roaming on campus, no matter which access point they connect to, makes their roaming experience seamless since their L2/L3 information and sessions remain on the same controller. Hitless Client Failover: Thanks to the full redundancy within the cluster, in the event of a cluster member failure, its connected clients are failed over to a redundant cluster member without disruption to their wireless connectivity, nor to their existing high value sessions. Client Load Balancing: The clients are automatically load balanced within the cluster. When clients are moved among cluster members, the move is done in a hitless manner.
  3. Here are highlights of the Clustering feature: 1. The Clustering feature is only available in deployments with the Mobility Master, as opposed to standalone controller deployments. 2. Cluster members can only be Mobility Controllers. In other words, we cannot at this time have Mobility Masters in a cluster. 3. There is no license required to turn on the Clustering feature.
  4. Here are highlights of the Clustering feature: 1. The Clustering feature is only available in deployments with the Mobility Master, as opposed to standalone controller deployments. 2. Cluster members can only be Mobility Controllers. In other words, we cannot at this time have Mobility Masters in a cluster. 3. There is no license required to turn on the Clustering feature. 4. Cluster members can terminate Campus APs (CAP), Remote APs (RAP) and Mesh APs.
  5. The following Mobility Controllers are supported: &2xx, 70xx and Virtual Mobility Controllers (VMC)
  6. The following Mobility Controllers are supported: &2xx, 70xx and Virtual Mobility Controllers (VMC) All Managed Devices are required to run the same ArubaOS version (8.0 and higher)
  7. Cluster capacity per platform: Up to 12 Mobility Controllers when using 72xx
  8. Cluster capacity per platform: Up to 12 Mobility Controllers when using 72xx Up to 4 Mobility Controllers when using 70xx
  9. Cluster capacity per platform: Up to 12 Mobility Controllers when using 72xx Up to 4 Mobility Controllers when using 70xx Up to 4 VMs when using the Virtual Mobility Controller (VMC)
  10. It is important to keep in mind several key considerations: The Clustering feature and the HA AP Fast Failover feature are mutually exclusive. Cluster members are required to run the same ArubaOS version. When the cluster is terminating Remote APs (RAPs), the size of the cluster is reduced to 4. A mix of hardware (7xxx) and x86 Mobility Controllers in the same cluster is NOT supported A mix of 72xx and 70xx Mobility Controllers in the same cluster is not recommended, not to mention the fact that the number of cluster members is reduced to 4.
  11. The AP Anchor Controller (AAC) is a role given to a cluster member Mobility Controller from an AP perspective. The AAC is actually the AP LMS controller. In other words, an AP that belongs to a given ap-group will get assigned its AAC through the lms-ip option in the ap system profile. The AAC is responsible for the handling of all the management functions of an AP and its radios. Here are examples of the AAC tasks: AP image upgrade CPSEC tunnel setup Config download to the AP With redundancy enabled, Cluster Manager dynamically assigns another cluster member as a Standby AAC (S-AAC) to the AP. The AP in turn builds standby tunnel(s) to the S-AAC
  12. In the event of an AAC failure: The S-AAC detects the failure within a very short time thanks to the inter-controller heartbeats The S-AAC instructs the AP to failover immediately
  13. In the event of an AAC failure: The S-AAC detects the failure within a very short time thanks to the inter-controller heartbeats The S-AAC instructs the AP to failover immediately The AP tears down its tunnel with the AAC, and changes the status of its tunnel with the S-AAC from standby to active The S-AAC becomes the new AAC for that AP, and the Cluster Leader promptly assigns a new S-AAC among the remaining cluster members