Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

PDF

Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

Configure a wireless profile policy (GUI)

Want to summarize with AI?

Log in

Provides comprehensive configuration procedures for wireless profile policies, flex profiles, AP profiles, user management, password encryption, and RF profiles through GUI and CLI interfaces.


Define and apply a wireless profile policy to manage network behavior and access for wireless clients.

Use this task to create or modify a policy profile, ensuring wireless network policies suit your organization's needs.

Procedure

1.

Choose Configuration > Tags & Profiles > Policy.

2.

On the Policy Profile page, click Add.

3.

In the Add Policy Profile window, in General tab, enter a name and description for the policy profile. The name can be ASCII characters from 32 to 126, without leading and trailing spaces. Do not use spaces as it causes system instability.

4.

To enable the policy profile, set Status as Enabled.

5.

Use the slider to enable or disable Passive Client and Encrypted Traffic Analytics.

6.

In the CTS Policy section, choose the appropriate status for the following:

  • Inline Tagging—a transport mechanism using which a controller or access point understands the source SGT.

  • SGACL Enforcement

7.

Specify a default SGT. The valid range is from 2 to 65519.

8.

In the WLAN Switching Policy section, choose the following, as required:

  • Central Switching: Tunnels both the wireless user traffic and all control traffic via CAPWAP to the centralized controller where the user traffic is mapped to a dynamic interface/VLAN on the controller. This is the normal CAPWAP mode of operation.

  • Central Authentication: Tunnels client data to the controller, as the controller handles client authentication.

  • Central DHCP: The DHCP packets received from AP are centrally switched to the controller and then forwarded to the corresponding VLAN based on the AP and the SSID.

  • Central Association Enable: When central association is enabled, all switching is done on the controller.

  • Flex NAT/PAT: Enables Network Address Translation(NAT) and Port Address Translation (PAT) mode.

9.

Click Save & Apply to Device.

The wireless profile policy is successfully created and applied. Devices use the updated policy settings for wireless client management.


Configure a wireless policy profile (CLI)

Define and apply a wireless policy profile on your device using command-line interface commands.

Use this task to configure wireless profile policies on Cisco wireless controllers. Policy profiles specify settings such as VLAN mapping, idle timeouts, and accounting lists for wireless networks.

Note

When a client moves from an old controller to a new controller (managed by Cisco Prime Infrastructure), the old IP address of the client is retained, if the IP address is learned by ARP or data gleaning. To avoid this scenario, ensure that you enable ipv4 dhcp required command in the policy profile. Otherwise, the IP address gets refreshed only after a period of 24 hours.

Follow the procedure given to configure a wireless profile policy:

Before you begin

  • Ensure you have administrator privileges to access and configure the device.

  • Have the required VLAN ID, idle timeout value, and accounting list details available, if applicable.

Follow these steps to configure a wireless profile policy:

Procedure

1.

Enter global configuration mode.

Example:

Device# configure terminal
2.

Configure the WLAN policy profile and enters wireless policy configuration mode.

Example:

Device(config)# wireless profile policy rr-xyz-policy-1
3.

(Optional) Configure the duration of idle timeout in seconds.

Example:

Device(config-wireless-policy)# idle-timeout 1000
4.

Configure the VLAN name or VLAN ID.

Example:

Device(config-wireless-policy)# vlan 24
5.

Set the accounting list for IEEE 802.1x.

Example:

Device(config-wireless-policy)# accounting-list user1-list
6.

Save the configuration, exit configuration mode, and return to privileged EXEC mode.

Example:

Device(config-wireless-policy)# no shutdown
7.

(Optional) View detailed information about a policy profile, using the show wireless profile policy detailed policy-profile-name command.

Example:

Device# show wireless profile policy summary
The wireless policy profile is configured and enabled on the device. All specified settings are applied to the selected policy.

What to do next

  • Associate the policy profile with a WLAN as needed.

  • Review and validate the applied settings by connecting a client device and confirming expected behavior.


Configure a flex profile (GUI)

Create or modify a flex profile to customize wireless network behavior for specific sites or device groups.

Use flex profiles within your network management system to define site-specific configurations such as VLANs, SSIDs, or access policies.

Before you begin

Identify the devices or sites to apply the flex profile.

Procedure

1.

Choose Configuration > Tags & Profiles > Flex.

2.

Click Add.

3.

Enter the Name of the flex profile. Use ASCII characters from 32 to 126. Do not include leading and trailing spaces.

4.

In the Description field, enter a description for the flex profile.

5.

Click Apply to Device.

The flex profile is created or updated and available for assignment to devices or sites.

What to do next

Assign the flex profile to the relevant site, device, or group as needed.


Configure a flex profile

Create or modify a flex profile to customize wireless network behavior for specific sites or device groups.

Use flex profiles within your network management system to define site-specific configurations such as VLANs, SSIDs, or access policies.

Before you begin

Identify the devices or sites to apply the flex profile.

Procedure

1.

Enter global configuration mode.

Example:

Device# configure terminal
2.

Configure a flex profile and enter flex profile configuration mode.

Example:

Device(config)# wireless profile flex rr-xyz-flex-profile
3.

(Optional) Enable default parameters for the flex profile.

Example:

Device(config-wireless-flex-profile)# description xyz-default-flex-profile
4.

(Optional) Enable ARP caching.

Example:

Device(config-wireless-flex-profile)# arp-caching
5.

Save the configuration, exit configuration mode, and return to privileged EXEC mode.

Example:

Device(config-wireless-flex-profile)# end
6.

(Optional) View detailed parameters about the flex profile, use the show wireless profile flex detailed flex-profile-name command.

Example:

Device# show wireless profile flex summary  

The flex profile is created or updated and available for assignment to devices or sites.

What to do next

Assign the flex profile to the relevant site, device, or group as needed.


Configure an AP profile (GUI)

Configure and customize AP join profiles for your wireless deployment.

Use this task to define, modify, or apply AP profile parameters such as country code, LED state, timers, VLAN tagging, security settings, management options, and advanced features, using the device’s graphical interface.

Before you begin

  • Review the default AP join profile to update parameters for your environment (For example, Control and Provisioning of Wireless Access Points (CAPWAP), IPv4 or IPv6, UDP Lite, High Availability, retransmit configuration parameters, global AP failover, Hyperlocation configuration parameters, Telnet or SSH, 11u parameters, and so on.)

  • Obtain required information, such as network-specific settings, controller addresses, credentials, and profile names.

Procedure

1.

Choose Configuration > Tags & Profiles > AP Join.

2.

On the AP Join Profile window, click Add.

The Add AP Join Profile window is displayed.

Note

DHCP fallback is enabled by default. If an AP is assigned a static IP address and unable to reach the controller, the AP falls back to the DHCP. To prevent an AP from switching the static IP to DHCP, you must disable the DHCP fallback configuration in an AP join profile.

3.

In the General tab, enter a name and description for the AP join profile. The name can be ASCII characters from 32 to 126, without leading and trailing spaces.

4.

Check the LED State check box to set the LED state of all APs connected to the device to blink, making them easier to locate. The LED state is enabled by default.

5.

In the Client tab and Statistics Timer section, enter the time in seconds that the AP sends its 802.11 statistics to the controller.

6.

In the TCP MSS Configuration section, check the Adjust MSS Enable check box to enter value for Adjust MSS. You can enter or update the maximum segment size (MSS) for transient packets that traverse a router. TCP MSS adjustment enables the configuration of the maximum segment size (MSS) for transient packets that traverse a router, specifically TCP segments with the SYN bit set.

In a CAPWAP environment, a lightweight AP discovers a device by using CAPWAP discovery mechanisms, and then sends a CAPWAP join request to the device. The device sends a CAPWAP join response to the AP that allows the AP to join the device.

When the AP joins the device, the device manages its configuration, firmware, control transactions, and data transactions.

7.

In the CAPWAP tab, you can configure these options:

  • High Availability

    You can configure primary and secondary backup controllers for all APs (which are used if primary, secondary, or tertiary controllers are not responsive) in this order: primary, secondary, tertiary , primary backup, and secondary backup.In addition, you can configure various timers, including heartbeat timers and discovery request timers. To reduce the controller failure detection time, you can configure the fast heartbeat interval (between the controller and the AP) with a smaller timeout value. When the fast heartbeat timer expires (at every heartbeat interval), the AP determines if any data packets have been received from the controller within the last interval. If no packets have been received, the AP sends a fast echo request to the controller.

  1. In the High Availability tab, enter the time (in seconds) in the Fast Heartbeat Timeout field to configure the heartbeat timer for all APs. Specifying a small heartbeat interval reduces the amount of time it takes to detect device failure.

    Note

    Configure Fast Heartbeat Timeout to assist AP in sending primary discovery request periodically to the configured backup controllers along with the primary, secondary, and tertiary-base controllers.

  2. In the Heartbeat Timeout field, enter the time in seconds to configure the heartbeat timer for all APs. Specifying a small heartbeat interval reduces the amount of time it takes to detect device failure.

  3. In the Discovery Timeout field, enter a value between one and 10 seconds (inclusive) to configure the AP discovery request timer.

  4. In the Primary Discovery Timeout field, enter a value between 30 and 3000 seconds (inclusive) to configure the AP primary discovery request timer.

  5. In the Primed Join Timeout field, enter a value between 120 and 43200 seconds (inclusive) to configure the AP primed join timeout.

  6. In the Retransmit Timers Count field, enter the number of times that you want the AP to retransmit the request to the device and vice versa. Valid range is between three and eight.

  7. In the Retransmit TimersInterval field, enter the time duration between retransmission of requests. Valid range is between two and five.

  8. Check the Enable Fallback check box to enable fallback.

  9. Enter the Primary Controller name and IP address.

  10. Enter the Secondary Controller name and IP address.

  11. Click Save & Apply to Device.

    Note
    The primary and secondary settings in the AP join profile are not used for AP fallback. This means that the AP will not actively probe for those controllers (which are a part of the AP join profile), when it has joined one of them.

    This setting is used only when the AP loses its connection with the controller, and then prioritizes which other controller it should join. These controllers have a priority of four and five, following APs in the High Availability tab of the AP page.

    The APs that are added as the primary, secondary, and tertiary APs in the High Availability tab of the AP configuration page, are actively probed and are used for the AP fallback option.

  • Advanced

  1. In the Advanced tab, check the Enable VLAN Tagging check box to enable VLAN tagging.

  2. Check the Enable Data Encryption check box to enable Datagram Transport Layer Security (DTLS) data encryption.

  3. Check the Enable Jumbo MTU to enable large maximum transmission unit (MTU). The MTU is the largest physical packet size, measured in bytes, that a network can transmit. Any messages larger than the MTU are divided into smaller packets before transmission. Jumbo frames exceed the standard Ethernet frame size, which is 1518 bytes (including Layer 2 (L2) header and FCS). Because vendors may have different frame size definitions, jumbo frames are not standardized by IEEE.

  4. Use the Link Latency drop-down list to select the link latency. Link latency monitors the round-trip time of the CAPWAP heartbeat packets (echo request and response) from the AP to the controller and back.

  5. From the Preferred Mode drop-down list, choose the mode.

  6. Click Save & Apply to Device.

8.

In the AP tab, you can configure these options:

  • General

  1. In the General tab, check the Switch Flag check box to enable switches.

  2. Check the Power Injector State check box if power injector is being used. Use power injectors to provide flexible powering options for APs, such as local power, multiport switches with inline power, or multiport power patch panels.

    Power Injector Selection parameter enables you to protect your switch port from an accidental overload if the power injector is inadvertently bypassed.

  3. From the Power Injector Type drop-down list, choose power injector type from these options:

    • Installed—This option examines and remembers the MAC address of the currently connected switch port and assumes that a power injector is connected. Choose this option if your network contains older Cisco 6-Watt switches and you want to avoid possible overloads by forcing a double-check of any relocated APs.

      If you want to configure the switch MAC address, enter the MAC address in theInjector Switch MAC Address text box. If you want the AP to find the switch MAC address, leave theInjector Switch MAC Address text box blank.

      Note

      Each time an AP is relocated, the MAC address of the new switch port fails to match the remembered MAC address, and the AP remains in low-power mode. You must then physically verify the existence of a power injector and reselect this option to cause the new MAC address to be remembered.

    • Override—This option allows the AP to operate in high-power mode without first verifying a matching MAC address. You can use this option if your network does not contain any older Cisco 6-W switches that could be overloaded if connected directly to a 12-W AP. The advantage of this option is that if you relocate the AP, it continues to operate in high-power mode without any further configuration. The disadvantage of this option is that if the AP is connected directly to a 6-W switch, an overload occurs.

  4. In theInjector Switch MAC field, enter the MAC address of the switch either in xx:xx:xx:xx:xx:xx, xx-xx-xx-xx-xx-xx, or xxxx.xxxx.xxxx format.

  5. From the EAP Type drop-down list, choose the EAP type as EAP-FAST , EAP-TLS , or EAP-PEAP.

  6. From the AP Authorization Type drop-down list, choose the type as either CAPWAP DTLS + or CAPWAP DTLS.

  7. In the Client Statistics ReportingInterval section, enter the interval for 5 GHz and 2.4 GHz radios in seconds.

  8. Check the Enable check box to enable extended module.

  9. From the Profile Name drop-down list, choose a profile name for mesh.

  10. Click Save & Apply to Device.

  • Hyperlocation: Cisco Hyperlocation is a location solution that allows to track the location of wireless clients with the accuracy of one meter. Selecting this option disables all other fields in the screen, except NTP Server.

  1. In the Hyperlocation tab, check the Enable Hyperlocation check box.

  2. Enter the Detection Threshold value to filter out packets with low RSSI. The valid range is –100 dBm to –50 dBm.

  3. Enter the Trigger Threshold value to set the number of scan cycles before sending a BAR to clients. The valid range is zero to 99.

  4. Enter the Reset Threshold value to reset value in scan cycles after trigger. The valid range is zero to 99.

  5. Enter the NTP Server IP address.

  6. Click Save & Apply to Device.

  • BLE: If your APs are Bluetooth Low Energy (BLE) enabled, they can transmit beacon messages that are packets of data or attributes transmitted over a low energy link. These BLE beacons are frequently used for health monitoring, proximity detection, asset tracking, and in-store navigation. For each AP, you can customize BLE Beacon settings configured globally for all APs.

  1. In the BLE tab, enter a value in the BeaconInterval field to indicate how often you want your APs to send out beacon advertisements to nearby devices. The range is from one to 10, with a default value of one.

  2. In the Advertised Attenuation Level field, enter the attenuation level. The range is from 40 to 100, with a default of 59.

  3. Click Save & Apply to Device.

  • Packet Capture: Packet Capture feature allows to capture the packets on the AP for the wireless client troubleshooting. The packet capture operation is performed on the AP by the radio drivers on the current channel on which it is operational, based on the specified packet capture filter.

  1. In the Packet Capture tab, choose an AP Packet Capture Profile from the drop-down list.

  2. You can also create a new profile by clicking the + sign.

  3. Enter a name and description for the AP packet capture profile.

  4. Enter the Buffer Size.

  5. Enter the Duration.

  6. Enter the Truncate Length information.

  7. In the Server IP field, enter the IP address of the TFTP server.

  8. In the File Path field, enter the directory path.

  9. Enter the username and password details.

  10. From the Password Type drop-down list, choose the type.

  11. In the Packet Classifiers section, use the option to select or enter the packets to be captured.

  12. Click Save.

  13. Click Save & Apply to Device.

9.

In the Management tab, you can configure these options:

  • Device

  1. In the Device tab, enter the IPv4/IPv6 Address of the TFTP server, TFTP Downgrade section.

  2. In the Image File Name field, enter the name of the software image file.

  3. From the Facility Value drop-down list, choose the appropriate facility.

  4. Enter the IPv4 or IPv6 address of the host.

  5. Choose the appropriate Log Trap Value.

  6. Enable Telnet, SSH or both configurations, if required.

  7. Enable core dump, if required.

  8. Click Save & Apply to Device.

  • User

  1. In the User tab, enter username and password details.

  2. Choose the appropriate password type.

  3. In the Secret field, enter a custom secret code.

  4. Choose the appropriate secret type.

  5. Choose the appropriate encryption type.

  6. Click Save & Apply to Device.

  • Credentials

  1. In the Credentials tab, enter local username and password details.

  2. Choose the appropriate local password type.

  3. Enter 802.1x username and password details.

  4. Choose the appropriate 802.1x password type.

  5. Enter the time in seconds after which the session should expire.

  6. Enable local credentials, 802.1x credentials, or both as required.

  7. Click Save & Apply to Device.

  • CDPInterface

  1. In the CDPInterface tab, enable the CDP state, if required.

  2. Click Save & Apply to Device.

10.

In the Rogue AP tab, check the Rogue Detection check box to enable rogue detection.

11.

In the Rogue Detection Minimum RSSI field, enter the RSSI value.

This field specifies the minimum RSSI value for which a Rogue AP should be reported. All Rogue APs with RSSI lower than what is configured will not be reported to controller.

12.

In the Rogue Detection TransientInterval field, enter the transient interval value.

This field indicates how long the Rogue AP should be seen before reporting the controller.

13.

In the Rogue Detection ReportInterval field, enter the report interval value.

This field indicates the frequency (in seconds) of Rogue reports sent from AP to controller.

14.

Check the Rogue Containment Automatic Rate Selection check box to enable rogue containment automatic rate selection.

The AP selects the best rate for the target Rogue, based on its RSSI.

15.

Check the Auto Containment on FlexConnect Standalone check box to enable the feature.

The AP continues containment if it moves to FlexConnect standalone mode.

16.

Click Save & Apply to Device.

The AP join profile is created or updated. Devices assigned to this profile use its configuration for network operation and management.

What to do next

  • Verify that APs have successfully joined and received the new settings by reviewing AP status.

  • Adjust profile settings as necessary for site-specific needs or to resolve configuration issues.


Configure an AP profile (GUI)

Configure and customize AP join profiles for your wireless deployment.

Use this task to define, modify, or apply AP profile parameters such as country code, LED state, timers, VLAN tagging, security settings, management options, and advanced features, using the device’s graphical interface.

Before you begin

  • Review the default AP join profile to update parameters for your environment (For example, Control and Provisioning of Wireless Access Points (CAPWAP), IPv4 or IPv6, UDP Lite, High Availability, retransmit configuration parameters, global AP failover, Hyperlocation configuration parameters, Telnet or SSH, 11u parameters, and so on.)

  • Obtain required information, such as network-specific settings, controller addresses, credentials, and profile names.

Procedure

1.

Choose Configuration > Tags & Profiles > AP Join.

2.

On the AP Join Profile window, click Add .

The Add AP Join Profile window is displayed.

Note

DHCP fallback is enabled by default. If an AP is assigned a static IP address and unable to reach the controller, the AP falls back to the DHCP. To prevent an AP from switching the static IP to DHCP, you must disable the DHCP fallback configuration in an AP join profile.

3.

In the General tab, enter a name and description for the AP join profile.

4.

From the Country Code drop-down list, select the relevant country.

5.

Check the LED State check box to set the LED state of all APs connected to the device to blink, making them easier to locate.

6.

In the Client tab and Statistics Timer section, enter the time in seconds that the AP sends its 802.11 statistics to the controller.

7.

In the TCP MSS Configuration section, check the Adjust MSS Enable check box to enter value for Adjust MSS. You can enter or update the maximum segment size (MSS) for transient packets that traverse a router. TCP MSS adjustment enables the configuration of the maximum segment size (MSS) for transient packets that traverse a router, specifically TCP segments with the SYN bit set.

In a CAPWAP environment, a lightweight AP discovers a device by using CAPWAP discovery mechanisms, and then sends a CAPWAP join request to the device. The device sends a CAPWAP join response to the AP that allows the AP to join the device.

When the AP joins the device, the device manages its configuration, firmware, control transactions, and data transactions.

8.

In the CAPWAP tab, you can configure these options:

  • High Availability

    You can configure primary and secondary backup controllers for all APs (which are used if primary, secondary, or tertiary controllers are not responsive) in this order: primary, secondary, tertiary , primary backup, and secondary backup. In addition, you can configure various timers, including heartbeat timers and discovery request timers. To reduce the controller failure detection time, you can configure the fast heartbeat interval (between the controller and the AP) with a smaller timeout value. When the fast heartbeat timer expires (at every heartbeat interval), the AP determines if any data packets have been received from the controller within the last interval. If no packets have been received, the AP sends a fast echo request to the controller.

  1. In the High Availability tab, enter the time in seconds in the Fast Heartbeat Timeout field to configure the heartbeat timer for all APs. Specifying a small heartbeat interval reduces the amount of time it takes to detect device failure.

    Note

    Configure Fast Heartbeat Timeout to assist AP in sending primary discovery request periodically to the configured backup controllers along with the primary, secondary, and tertiary-base controllers.

  2. In the Heartbeat Timeout field, enter the time in seconds to configure the heartbeat timer for all APs. Specifying a small heartbeat interval reduces the amount of time it takes to detect device failure.

  3. In the Discovery Timeout field, enter a value between one and 10 seconds (inclusive) to configure the AP discovery request timer.

  4. In the Primary Discovery Timeout field, enter a value between 30 and 3000 seconds (inclusive) to configure the AP primary discovery request timer.

  5. In the Primed Join Timeout field, enter a value between 120 and 43200 seconds (inclusive) to configure the AP primed join timeout.

  6. In the Retransmit Timers Count field, enter the number of times that you want the AP to retransmit the request to the device and vice versa. Valid range is between three and eight.

  7. In the Retransmit Timers Interval field, enter the time duration between retransmission of requests. Valid range is between two and five.

  8. Check the Enable Fallback check box to enable fallback.

  9. Enter the Primary Controller name and IP address.

  10. Enter the Secondary Controller name and IP address.

  11. Click Save & Apply to Device.

    Note
    The primary and secondary settings in the AP join profile are not used for AP fallback. This means that the AP will not actively probe for those controllers (which are a part of the AP join profile), when it has joined one of them.

    This setting is used only when the AP loses its connection with the controller, and then prioritizes which other controller it should join. These controllers have a priority of four and five, following APs in the High Availability tab of the AP page.

    APs added as the primary, secondary, and tertiary APs in the High Availability tab of the AP configuration page are actively probed and used for the AP fallback option.

  • Advanced

  1. In the Advanced tab, check the Enable VLAN Tagging check box to enable VLAN tagging.

  2. Check the Enable Data Encryption check box to enable Datagram Transport Layer Security (DTLS) data encryption.

  3. Check the Enable Jumbo MTU to enable large maximum transmission unit (MTU). The MTU is the largest physical packet size, measured in bytes, that a network can transmit. Any messages larger than the MTU are divided into smaller packets before transmission. Jumbo frames exceed the standard Ethernet frame size, which is 1518 bytes (including Layer 2 (L2) header and FCS). Because vendors may have different frame size definitions, jumbo frames are not standardized by IEEE.

  4. Use the Link Latency drop-down list to select the link latency. Link latency monitors the round-trip time of the CAPWAP heartbeat packets (echo request and response) from the AP to the controller and back.

  5. From the Preferred Mode drop-down list, choose the mode.

  6. Click Save & Apply to Device.

9.

In the AP tab, you can configure various options:

  • General

  1. In the General tab, check the Switch Flag check box to enable switches.

  2. Check the Power Injector State check box if power injector is being used. Use power injectors to provide flexible powering options for APs, such as local power, multiport switches with inline power, or multiport power patch panels.

  3. From the Power Injector Type drop-down list, choose power injector type from the following options:

    • Installed: If you want the AP to examine and remember the MAC address of the currently connected switch port. (This selection assumes that a power injector is connected.)

    • Override: To enable the AP to operate in high-power mode without first verifying a matching MAC address.

  4. In the Injector Switch MAC field, enter the MAC address of the switch.

  5. From the EAP Type drop-down list, choose the EAP type as EAP-FAST , EAP-TLS , or EAP-PEAP .

  6. From the AP Authorization Type drop-down list, choose the type as either CAPWAP DTLS + or CAPWAP DTLS .

  7. In the Client Statistics Reporting Interval section, enter the interval for 5 GHz and 2.4 GHz radios in seconds.

  8. Check the Enable check box to enable extended module.

  9. From the Profile Name drop-down list, choose a profile name for mesh .

  10. Click Save & Apply to Device .

  • Hyperlocation: Cisco Hyperlocation is a location solution that allows to track the location of wireless clients with the accuracy of one meter. Selecting this option disables all other fields in the screen except for NTP Server.

  1. In the Hyperlocation tab, check the Enable Hyperlocation check box.

  2. Enter the Detection Threshold value to filter out packets with low RSSI. The valid range is –100 dBm to –50 dBm.

  3. Enter the Trigger Threshold value to set the number of scan cycles before sending a BAR to clients. The valid range is 0 to 99.

  4. Enter the Reset Threshold value to reset value in scan cycles after trigger. The valid range is 0 to 99.

  5. Enter the NTP Server IP address.

  6. Click Save & Apply to Device .

  • BLE: If your APs are Bluetooth Low Energy (BLE) enabled, they can transmit beacon messages that are packets of data or attributes transmitted over a low-energy link. These BLE beacons are used for health monitoring, proximity detection, asset tracking, and in-store navigation. You can customize BLE beacon settings for each AP, even if they are configured globally.

  1. In the BLE tab, enter a value in the Beacon Interval field to indicate how often you want your APs to send out beacon advertisements to nearby devices. The range is from one to 10, with a default value of one.

  2. In the Advertised Attenuation Level field, enter the attenuation level. The range is from 40 to 100, with a default of 59.

  3. Click Save & Apply to Device.

10.

In the Management tab, you can configure the following:

  • Device

  1. In the Device tab, enter the IPv4/IPv6 Address of the TFTP server, TFTP Downgrade section.

  2. In the Image File Name field, enter the name of the software image file.

  3. From the Facility Value drop-down list, choose the appropriate facility.

  4. Enter the IPv4 or IPv6 address of the host.

  5. Choose the appropriate Log Trap Value.

  6. Enable Telnet, SSH or both configurations, if required.

  7. Enable core dump, if required.

  8. Click Save & Apply to Device.

  • User

  1. In the User tab, enter username and password details.

  2. Choose the appropriate password type.

  3. In the Secret field, enter a custom secret code.

  4. Choose the appropriate secret type.

  5. Choose the appropriate encryption type.

  6. Click Save & Apply to Device.

  • Credentials

  1. In the Credentials tab, enter local username and password details.

  2. Choose the appropriate local password type.

  3. Enter 802.1x username and password details.

  4. Choose the appropriate 802.1x password type.

  5. Enter the time in seconds after which the session should expire.

  6. Enable local credentials, 802.1x credentials, or both as required.

  7. Click Save & Apply to Device.

  • CDP Interface

  1. In the CDP Interface tab, enable the CDP state, if required.

  2. Click Save & Apply to Device.

11.

In the Rogue AP tab, check the Rogue Detection check box to enable rogue detection.

12.

In the Rogue Detection Minimum RSSI field, enter the RSSI value.

This field specifies the minimum RSSI value for which a Rogue AP should be reported. All Rogue APs with RSSI lower than what is configured will not be reported to controller.

13.

In the Rogue Detection Transient Interval field, enter the transient interval value.

This field indicates how long the Rogue AP should be seen before reporting the controller.

14.

In the Rogue Detection Report Interval field, enter the report interval value.

This field indicates the frequency (in seconds) of Rogue reports sent from AP to controller.

15.

Check the Rogue Containment Automatic Rate Selection check box to enable rogue containment automatic rate selection.

The AP selects the best rate for the target Rogue, based on its RSSI.

16.

Check the Auto Containment on FlexConnect Standalone check box to enable the feature.

The AP continues containment if it moves to FlexConnect standalone mode.

17.

Click Save & Apply to Device.

The AP join profile is created or updated. Devices assigned to this profile use its configuration for network operation and management.

What to do next

  • Verify that APs have successfully joined and received the new settings by reviewing AP status.

  • Adjust profile settings as necessary for site-specific needs or to resolve configuration issues.


Configure an AP profile (CLI)

Set up and customize an AP profile using CLI commands to apply network-wide AP configurations.

Use this procedure when you need to define or modify an AP profile for your wireless controller, typically to standardize AP settings or apply feature-specific options.

Before you begin

Identify the name and required settings for your AP profile.

Procedure

1.

Enter global configuration mode.

Example:

Device# configure terminal
2.

Configure an AP profile and enter AP profile configuration mode.

Example:

Device(config)# ap profile xyz-ap-profile 
Note
  • In an AP profile, the EAP-FAST is the default EAP type.

  • When you delete a named profile, the APs associated with that profile does not revert to the default profile.

3.

Add a description for the AP profile.

Example:

Device(config-ap-profile)# description "xyz ap profile"
4.

Configure DHCP fallback.

Example:

Device(config-ap-profile)# ip dhcp fallback
Note

DHCP fallback is enabled by default. If an AP is assigned a static IP address and cannot reach the controller, the AP falls back to the DHCP. To prevent an AP from switching from a static IP to DHCP, disable the DHCP fallback configuration in an AP join profile.

5.

Enable CDP for all Cisco APs.

Example:

Device(config-ap-profile)# cdp
6.

Save the configuration, exit configuration mode, and return to privileged EXEC mode.

Example:

Device(config-ap-profile)# end
7.

(Optional) Display detailed information about an AP join profile.

Example:

Device# show ap profile name xyz-ap-profile detailed  

The AP profile is created or updated with specified settings, and changes are active on the controller.

What to do next

Assign APs to the new profile as required, and verify AP behavior matches the intended configuration.


Configure user for AP management (CLI)

Set up a management user account to centrally control APs through CLI.

Procedure

1.

Enter global configuration mode.

Example:

Device# configure terminal
2.

Configure an AP profile, and then enter AP profile configuration mode.

Example:

Device(config)# ap profile default-ap-profile 
3.

Specify the AP management username and password for managing all of the APs configured to the controller.

Example:

Device(config-ap-profile)# mgmtuser username myusername password 0 12345678
  • 0: Specifies an UNENCRYPTED password.

  • 8: Specifies an AES encrypted password.

Note

While configuring a username, ensure that you do not use special characters. Using special characters may cause a configuration error.

4.

Return to privileged EXEC mode.

Example:

Device(configure-ap-profile)# end

The AP management user is configured for all APs that are managed by the controller.


Set a private configuration key for password encryption

Configure a private configuration key to enable password encryption on the device.

Use this task to set or change a private key used for encrypting passwords. You must do this before you enable AES password encryption.

Procedure

1.

Enter global configuration mode.

Example:

Device# configure terminal
2.

Set the password encryption keyword.

Example:

Device(config)# key config-key password-encrypt 12345678
                    

Here, config-key refers to any key value with at least eight characters.

Note

The config-key value must not begin with these special characters:

  • !

  • #

  • ;

3.

Enable the encrypted pre-shared key.

Example:

Device(config)# password encryption aes
4.

Return to privileged EXEC mode. Alternatively, you can also press Ctrl-Z to exit global configuration mode.

Example:

Device(config)# end

You have now enabled password encryption using your specified private configuration key.

What to do next

You can now enable AES password encryption, if needed.

Configure an RF profile (GUI)

Create and enable an RF profile to optimize radio frequency settings for your wireless network.

Use this task to define an RF profile that sets parameters for radio bands and device operation. This ensures consistent performance across your wireless deployment.

Before you begin

Use the same RF profile name when configuring the wireless RF tag. If the RF tag contains an RF profile that does not exist, the radios do not operate.

Procedure

1.

Choose Configuration > Tags & Profiles > RF.

2.

On the RF Profile window, click Add.

3.

In the General tab, enter a name for the RF profile. The name can be ASCII characters from 32 to 126, without leading and trailing spaces.

4.

Choose the appropriate Radio Band.

5.

To enable the profile, set the status as Enable.

6.

Enter a Description for the RF profile.

7.

Click Save & Apply to Device.

The new RF profile is created, enabled, and applied to the device.

What to do next

  • Verify that the RF profile settings are visible and active on your device.

  • Assign the profile to RF tags or APs, if required, to complete your configuration.


Configure an RF profile (CLI)

Create and enable an RF profile to optimize radio frequency settings for your wireless network.

Use this task to define an RF profile that sets parameters for radio bands and device operation. This ensures consistent performance across your wireless deployment.

Before you begin

Use the same RF profile name when configuring the wireless RF tag. If the RF tag contains an RF profile that does not exist, the radios do not operate.

Procedure

1.

Enter global configuration mode.

Example:

Device# configure terminal
2.

Configure an RF profile, and enter RF profile configuration mode.

Example:

Device(config)# ap dot11 24ghz rf-profile rfprof24_1
Note
Use the 24ghz command to configure the 802.11b parameters. Use the 5ghz command to configure the 802.11a parameters. Use the 6ghz command to configure the 802.11 6-GHz parameters.
3.

(Optional) Enable default parameters for the RF profile.

Example:

Device(config-rf-profile)# default
4.

Enable the RF profile on the device.

Example:

Device(config-rf-profile)# no shutdown
5.

Exit configuration mode and return to privileged EXEC mode.

Example:

Device(config-rf-profile)# end
6.

(Optional) Display a summary of available RF profiles.

Example:

Device# show ap rf-profile summary
7.

(Optional) Display detailed information about a particular RF profile.

Example:

Device# show ap rf-profile name rfprof24_1 detail

You have created and enabled a new RF profile, and applied it to the device.

What to do next

  • Verify that the RF profile settings are visible and active on your device.

  • Assign the profile to RF tags or APs as required to complete your configuration.