- Cisco Mobility Express Overview
- Deploying Cisco Mobility Express
- Configuring Cisco Mobility Express controller
- Using internal DHCP server on Cisco Mobility Express
- TLS Support on Mobility Express
- Configuring Cisco Mobility Express for Site Survey
- Creating Wireless Networks
- Managing Services with Cisco Mobility Express
- Managing the Cisco Mobility Express Deployment
- Master AP Failover and Electing a new Master
- Managing Access Points
- Adding Access Points to Cisco Mobility Express Network
- Configuring Access Point as 802.1x Supplicant
- Configuring RF Profiles
- Configuring Management Access
- Managing Admin Accounts
- Managing TACACS+ and RADIUS Servers
- Managing TIME on Cisco Mobility Express
- Updating Cisco Mobility Express Software
- CALEA Support
Managing the Cisco
	 Mobility Express Deployment
- Managing Access Points
- Adding Access Points to Cisco Mobility Express Network
- Configuring Access Point as 802.1x Supplicant
- Configuring RF Profiles
- Configuring Management Access
- Managing Admin Accounts
- Managing TACACS+ and RADIUS Servers
- Managing TIME on Cisco Mobility Express
- Updating Cisco Mobility Express Software
- CALEA Support
Managing Access Points
Starting Release 8.4, Cisco Mobility Express supports up to 100 Access Points. To view the list or modify parameters on an Access Points, follow the procedure below:
Adding Access Points to Cisco Mobility Express Network
When adding Access Points to Cisco Mobility Express network, the following have to be considered:
Software Version on the Access Point–If the software version of the access point, which is being added, is different than what is on the Master AP, a software download of the code running on the Master Access Point has to happen on the Access Point being added. For the new Access Point to download the code that is running on the Master Access Point, one of the following has to be configured:
-  
			 TFTP server details and the Access Point images path information has to be configured on the Software Update page. 
-  
			 If the Master AP has 8.3.102.0 or later code, one can configure the Cisco.com login credentials on the Software Update page and the code on the new Access Point will be automatically downloaded from cisco.com when an Access Point joins. 
|  Note | For Software download to take place directly from Cisco.com, the Master AP should be the one with the SMARTNet Contract. | 
| Step 1 | Download the Access Point image zip file from cisco.com on a TFTP server. The bundle version must be the same as the one running on the Master AP. Unzip the file to extract the individual Access Point images. | ||
| Step 2 | Navigate to 
			 Management 
			 > 
			 Software
				Update. Select 
			 TFTP for 
			 Transfer
				Mode and configure the TFTP Parameters. (OR) | ||
| Step 3 | Navigate to Management > Software Update. Select Cisco.com as the Transfer Mode and configure parameters related to the Cisco.com user account. | ||
| Step 4 | Connect the AP
			 to the network. When the AP boots up, it obtains an IP address from the DHCP
			 server. If the AP version matches the one on Master AP, it joins. However, if
			 the version on the AP being added is different than then one on the Master AP,
			 it starts to download the image from either the configured TFTP server or
			 cisco.com. After the image download is complete, the AP will reboot and join
			 the Master AP. 
 
 | 
Configuring Access Point as 802.1x Supplicant
Starting AireOS Release 8.6, one can configure Access Points running Cisco Mobility Express as a 802.1x supplicant.
Mobility Express APs can act as the 802.1x supplicant and is authenticated by the switch against the ISE that uses EAP-FAST. Once the port is configured for 802.1x authentication, the switch does not allow any traffic other than 802.1x traffic to pass through the port until the device connected to the port authenticates successfully. An AP can be authenticated either before it joins a WLC or after it has joined a WLC, in which case you configure 802.1x on the switch after the Access Point joins the WLC.
Configuring RF Profiles
Starting AireOS Release 8.6, Cisco Mobility Express will support six pre-built RF Profiles as well as creation of RF Profiles.
RF Profiles allows you to tune groups of APs that share a common coverage zone together and selectively change how RRM will operates the APs within that coverage zone. For example, a university might deploy a high density of APs in an area where a high number of users will congregate or meet. This situation requires that you manipulate both data rates and power to address the cell density while managing the co-channel interference. In adjacent areas, normal coverage is provided and such manipulation would result in a loss of coverage. Using RF profiles and AP groups allows you to optimize the RF settings for AP groups that operate in different environments or coverage zones. RF profiles are created for the 802.11 radios. RF profiles are applied to all APs that belong to an AP group, where all APs in that group will have the same profile settings. The RF profile gives you the control over the data rates and power (TPC) values. One can either associate a build in RF Profile with AP Groups or create a new RF Profile and then associate that with the AP Group.
Configuring RF Profiles
To configure RF Profiles, enable Expert View on Cisco Mobility Express. Expert View is available on the top banner of the Cisco Mobility Express WebUI as shown below and enabled various configurable parameters which are not available in Standard view.

		  
| Step 1 | Navigate to Advanced > RF Profiles | 
| Step 2 | Click on the Add new RF Profile button. | 
| Step 3 | Under the 
				General
				tab, configure the following: 
 
 | 
| Step 4 | Under the
				802.11 tab, configure the following: 
 | 
| Step 5 | Under the RRM
				tab, configure the following: 
 | 
| Step 6 | Under the
				Client Distribution tab, configure the following: 
 | 
Configuring Access Point Groups
To configure AP Groups, enable Expert View on Cisco Mobility Express. Expert View is available on the top banner of the Cisco Mobility Express WebUI as shown below and enabled various configurable parameters which are not available in Standard view.

		  
| Step 1 | Navigate to Wireless Settings > Access Point Groups. | 
| Step 2 | Click on the Add new group button. | 
| Step 3 | Under the 
				General
				tab, configure the following: 
 | 
| Step 4 | Under the WLANs tab, click on the Add WLAN button to add the WLAN to the AP Group | 
| Step 5 | Under the Access Points tab, select the Access Points which must be added to the AP Group | 
| Step 6 | Under the RF Profiles tab, select the RF Profile for 2.4 and 5.0 GHz band. The RF Profile will be applied to this AP Group. | 
| Step 7 | Click Apply. | 
Configuring Access Point Groups
Starting AireOS Release 8.6, Cisco Mobility Express will support upto 100 AP Groups depending on model of the AP running the Wireless controller function.
AP Group is a logical grouping of Access Points in the wireless network. AP Groups enable location based services i.e. if you want to broadcast an SSID on a set of Access Points and a another SSID on different set of Access Points, you can do so by creating AP Groups and adding the Access Points accordingly.
|  Note | Maximum of 50 AP Groups are supported on Mobility Express and a maximum of 100 APs can be added to a single AP Group. | 
Configuring Management Access
The Management Access Interface on the Mobility Express controller is the default interface for in-band management of the controller and connectivity to enterprise services. It is also used for communications between the controller and access points.
There are four types of Management Access supported on the Mobility Express controller.
- HTTP Access–To enable HTTP access mode, which allows you to access the controller GUI using http://<ip-address> through a web browser, choose Enabled from the HTTP Access drop-down list. Otherwise, choose Disabled. The default value is Disabled. HTTP access mode is not a secure connection.
- HTTPS Access–To enable HTTPS access mode, which allows you to access the controller GUI using http://ip-address through a web browser, choose Enabled from the HTTPS Access drop-down list. Otherwise, choose Disabled. The default value is Enabled. HTTPS access mode is a secure connection.
- Telnet Access–To enable Telnet access mode, which allows remote access to the controller's CLI using your laptop's command prompt, choose Enabled from the Telnet Access drop-down list. Otherwise, choose Disabled. The default value is Disabled. The Telnet access mode is not a secure connection.
- SSHv2 Access–To enable Secure Shell Version 2 (SSHv2) access mode, which is a more secure version of Telnet that uses data encryption and a secure channel for data transfer, choose Enabled from the SSHv2 Access drop-down list. Otherwise, choose Disabled. The default value is Enabled. The SSHv2 access mode is a secure connection.
To enable or disable the different types of management access to the controller, follow the procedure below:
| Step 1 | Navigate to Management > Access. | ||
| Step 2 | For the various Access Types,
			 select either 
			 Enabled or 
			 Disabled. 
 | ||
| Step 3 | Click Apply to submit changes. | 
Managing Admin Accounts
Cisco Mobility Express Cisco Mobility Express supports creation of admin accounts to prevent unauthorized users from reconfiguring the controller and viewing configuration. It supports the following three access levels for Admin user accounts:
- Read/Write–Accounts with read and write privilege have full provisioning and monitoring capability
- Read only–Accounts with Read only privilege only have monitoring capability and can browse all screens
- Lobby Ambassador–A Lobby Ambassador can create and manage guest user accounts on the Cisco Mobility Express. The lobby ambassador has limited configuration privileges and can access only the web pages used to manage the guest accounts.
|  Note | The local user database is limited to a maximum of 2048 entries, which is also the default value. This database is shared by local management users (including lobby ambassadors), local network users (including guest users), MAC filter entries, exclusion list entries. Together they cannot exceed the maximum value. | 
To create admin users, follow the procedure below:
| Step 1 | Navigate to Management > Admin Accounts and click on the Add New User button. | 
| Step 2 | Enter the
			 following to configure the admin user account. 
 | 
| Step 3 | Click tick icon. | 
Managing TACACS+ and RADIUS Servers
Starting Release 8.5, Cisco Mobility Express will support up to Six RADIUS and Three TACACS Servers. To configure RADIUS and TACACS+ Servers, enable Expert View on Cisco Mobility Express. Expert View is available on the top banner of the Cisco Mobility Express WebUI as shown below and enabled various configurable parameters which are not available in Standard view.
 
		  
			 
		
Adding TACACS+ Servers
Adding RADIUS Servers
Configuring AP SSH Credentials
On Cisco Mobility Express, AP SSH credentials are configured as controller credentials by default. To change the AP SSH credentials on all the APs, follow the procedure below.
Managing Admin User Priority
Prior to Release 8.5, admin accounts on Cisco Mobility Express were created locally on the controller. In Release 8.5 TACACS+ and RADIUS servers can also be used for authentication admin users.
When multiple databases are configured, it is important to configure the admin account user priority. To configure the priority, follow the Procedure below.
| Step 1 | Enable 
				Expert
				  View on Cisco Mobility Express. 
				Expert
				  View is available on the top banner of the Cisco Mobility Express WebUI as
				shown below and enables various configurable parameters which are not available
				in Standard view. 
  
 | ||
| Step 2 | Navigate to 
				Management 
				> Admin
				  Accounts and click on the 
				Management
				  User Priority Order. 
 
 | ||
| Step 3 | To change the priority, between TACACS+ and RADIUS, click on either and move UP or DOWN. Please note Local Admin Accounts cannot be moved to Priority 3. It can only be either 1 or 2. | 
Managing TIME on Cisco Mobility Express
The system date and time on the Cisco Mobility Express controller is typically configured when running the initial Wireless Express setup wizard.
Configuring NTP Server
Up to three Network Time Protocol (NTP) servers can be configured to sync date and time if one was not configured during the Wireless Express setup. Time Zone can be configured to offset the clock.
To configure Time Zone and NTP servers, follow the procedure below:
| Step 1 | Navigate to Management > Time. | ||
| Step 2 | Choose the desired Time Zone . | ||
| Step 3 | Enter the NTP Polling Interval. The polling interval ranges from 3600 to 604800 seconds. | ||
| Step 4 | To add an NTP
				server, click 
				Add NTP
				  Server button and configure the following: 
 
 
 
 | 
Updating Cisco Mobility Express Software
Cisco Mobility Express controller software update can be performed using the controller's web interface. Software update ensures that both the controller software and all the Access Points associated are updated.
An AP joining the controller compares its software version with the Master AP version and incase of mismatch, the new AP requests for a software update. For software update, one must configure the Transfer Mode and corresponding details on the Software Update page.
|  Note | Master AP does not have AP images. It facilitates the transfer of new software from the configured Transfer Mode to the Access Points requesting for Software Update. | 
Software download on the Access Points is automatically sequenced to ensure that not more than 5 APs are downloading the software simultaneously and the queue refreshes till all the Access Points requiring upgrade have downloaded the new image.
Starting Release 8.3.100.0, Cisco Mobility Express supports the following Transfer Mode for Software Update:
Cisco.com–Cisco.com transfer mode is introduced in 8.3.100.0. In this software update method, the software image can be directly streamed from cisco.com to the individual Access Points. Internet access required for this transfer mode and EULA and SMARTNet contract requirements have to be met for this transfer mode.
HTTP–HTTP transfer mode is supported if the Mobility Express Network has the same model of Access Points. Use HTTP as the transfer mode for Software Update using the AP file from a local machine.
|  Note | If there is a mix of Access Points in the Mobility Express network, Software Update via cisco.com or TFTP Transfer Method should be used. | 
TFTP–TFTP transfer mode can be used to perform Software Update on a Mobility Express Network. Master AP facilitates transfer of image from the TFTP server to the individual Access Points. The AP images are stored and served from the TFTP server upon request.
|  Note | There is no service interruption during pre-image download. After pre-image download is complete on all APs, a Manual or scheduled reboot of Mobility Express network can be triggered. | 
- Software Update using cisco.com Transfer Mode
- Software Update using HTTP Transfer Mode
- Software Update using TFTP Transfer Mode
- Managing Advanced RF Parameters
Software Update using cisco.com Transfer Mode
Software Update via Cisco.com works for all Access Points supported in a Cisco Mobility Express Deployment. Below requirements must be met to initiate a Software Update from cisco.com.
- Internet access is required for software download from cisco.com to APs. However, no proxy is required.
- A valid cisco.com (CCO) account with username & password required.
- EULA acceptance on a per user basis. Only Master AP (not all APs in the network) must have SMARTNet contract else Software Update will not start.
|  Note | Software Update from cisco.com is supported via GUI only. | 
In order to perform Software Update using cisco.com Transfer Mode, follow the procedure below:
| Step 1 | To perform Software Update via Cisco.com, navigate to Management > Software Update and configure the following: | ||
| Step 2 | Click Apply. | ||
| Step 3 | Click Update to initiate software update wizard. | ||
| Step 4 | In the Software Update Wizard, select the Recommended Software Release or Latest Software Release. Click Next. | ||
| Step 5 | Select 
			 Update Now to initiate software update immediately or 
			 Schedule the Update for Later. 
 
 | ||
| Step 6 | Click on the Auto Restart checkbox if automatic restart of all access points in the network is desired after the software update is finished. Click Next. | ||
| Step 7 | Click 
			 Confirm to start the software update. To monitor the download progress on individual Access Points, expand the Predownload image status. | 
Software Update using HTTP Transfer Mode
If you have the same model of Access Points in the Mobility Express deployment, HTTP Transfer mode can be used to perform Software Update. For HTTP Transfer mode, one can simply upload the Access Point upgrade image from the local machine. To perform Software Update using HTTP Transfer Mode, follow the procedure below:
| Step 1 | Download the AP Image bundle from cisco.com to the local machine. The table below points to Release 8.5.103.0 images. | ||||||||||||||||||||||
| Step 2 | 
 
 | ||||||||||||||||||||||
| Step 3 | Unzip the AP
			 Image bundle to extract individual AP Images. Mapping of Access Points to their
			 corresponding images is shown below: 
 
 | ||||||||||||||||||||||
| Step 4 | To perform
			 Software Update via 
			 HTTP
			 Transfer Mode, navigate to 
			 Management >
				Software Update and configure the following: 
 
 | ||||||||||||||||||||||
| Step 5 | Click Apply. | ||||||||||||||||||||||
| Step 6 | Click on Updateto initiate software update. | 
Software Update using TFTP Transfer Mode
Software Update via TFTP Transfer Mode works for all Access Points supported in a Cisco Mobility Express Deployment. You would need a TFTP server which can communicate with the Master Access Point to use this upgrade method. This update method is supported from controller WebUI as well as CLI.
Upgrading from WebUI
To perform Software Update using TFTP Transfer mode from WebUI, follow the procedure below:
| Step 1 | Download the AP Image bundle from cisco.com to the TFTP server. | ||
| Step 2 | Unzip the AP Image bundle to extract individual AP Images. | ||
| Step 3 | To perform
				Software Update via 
				TFTP
				Transfer Mode, navigate to 
				Management
				  > Software Update and configure the following: 
 
 
 
 | ||
| Step 4 | Click Apply. | ||
| Step 5 | Click 
				Update Now
				to initiate software update. 
 
 | 
Upgrading from CLI
| Step 1 | Login to AP running Mobility Express controller via SSH or Telnet(if it is enabled). | ||
| Step 2 | Specify the
				datatype. (Cisco Controller) >transfer download datatype ap-image 
 | ||
| Step 3 | Specify the
				transfer mode. (Cisco Controller) >transfer download ap-images mode tftp 
 | ||
| Step 4 | Specify the
				IP address of the TFTP server. (Cisco Controller) >transfer download ap-images serverIp <IP addr> 
 | ||
| Step 5 | Specify the
				path of the AP images on the TFTP server. (Cisco Controller) >transfer download ap-images imagePath <path to AP images> 
 
 
 | ||
| Step 6 | Start
				pre-downloading of the image on the APs. (Cisco Controller) >transfer download start Mode........................................... TFTP Data Type...................................... ap-image TFTP Server IP................................. 10.1.1.77 TFTP Packet Timeout............................ 10 TFTP Max Retries............................... 10 TFTP Path...................................... ap_bundle_8.1.112.30/ This may take some time. Are you sure you want to start? (y/N) y TFTP Code transfer starting. Triggered APs to pre-download the image. Reboot the controller once AP Image pre-download is complete 
 | ||
| Step 7 | Check the
				pre-download status by executing the CLI below. (Cisco Controller) >show ap image all
Total number of APs............... 3
Number of APs
       Initiated.........................1
       Predownloading....................2
       Completed predownloading..........0
       Not Supported.....................0
       Failed/BackedOff to Predownload...0
                   Primary    Backup  Predownload Predownload Next Retry  Retry Failure
AP Name	             Image     Image 	   Status      Version    Time      Count Reason
––––––––––––––   ––––––––––  –––––––--  ––––––––    –––––––––   –––––––   ––––  –––––
AP6412.256e.0e78 8.1.112.21	 8.1.112.21 Predownloading   ––	        NA	   NA	 
APAOEC.F96C.D640 8.1.112.21	 8.1.112.21 Predownloading   ––	        NA   	NA	
3600-gemini	  8.1.112.21	 8.1.112.21 Predownloading   ––	           NA    
 | ||
| Step 8 | Wait for the
				pre-image download to complete on the Access Points. (Cisco Controller) >show ap image all
Total number of APs............... 3
Number of APs
       Initiated.........................1
       Predownloading....................2
       Completed predownloading..........0
       Not Supported.....................0
       Failed/BackedOff to Predownload...0
                    Primary    Backup  Predownload Predownload Next Retry Retry Failure
AP Name	             Image     Image 	   Status      Version    Time      Count Reason
 ––––––––––––––   ––––––––––  –––––––--  ––––––––    –––––––––   –––––––   ––––  –––––
AP6412.256e.0e78 8.1.112.21	 8.1.112.21 Complete     ––	         NA	          NA	 
APAOEC.F96C.D640 8.1.112.21	 8.1.112.21 Complete     ––	         NA           NA	
3600-gemini	  8.1.112.21	 8.1.112.21 Complete	  ––	              NA           
 | ||
| Step 9 | After the
				pre-download is complete, issue a reset system as shown below. (Cisco Controller) >reset system The system has unsaved changes. Would you like to save them now? (y/N) y Configuration Saved! System will now restart! 
 | 
Managing Advanced RF Parameters
Cisco Mobility supports a number RF Parameters which can be configured the administrator to optimize their network deployment. To manage advanced RF Parameters, follow the procedure below:
| Step 1 | Enable 
			 Expert View on Cisco Mobility Express. 
			 Expert View is available on the top banner of the Cisco
			 Mobility Express WebUI as shown below and enabled various configurable
			 parameters which are not available in Standard view.  
 | ||
| Step 2 | Under 
			 Advanced RF Parameters, the following parameters are
			 available: 
 
 
 
 | ||
| Step 3 | Click Apply. | 
CALEA Support
Support for The Communications Assistance for Law Enforcement Act (CALEA) is available in Cisco Mobility Express starting Release 8.5. To configure CALEA Server, follow the procedure below:
| Step 1 | Enable 
			 Expert View
			 on Cisco Mobility Express. 
			 Expert View
			 is available on the top banner of the Cisco Mobility Express WebUI as shown
			 below. 
  
 | 
| Step 2 | Navigate to 
			 Advanced 
			 >
				Controller Tools. Click on the 
			 CALEA Tab
			 and configure the following: 
 
 | 
| Step 3 | Click Apply. | 
 Feedback
Feedback