Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

PDF

Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

Out-of-band AP image download

Want to summarize with AI?

Log in

Explains the out-of-band access point image download process, including key concepts and implementation details for managing AP firmware updates independently of the primary network connection.


Out-of-band AP image download is an enhanced upgrade method that

  • moves AP image downloads out of the CAPWAP control path using an enhanced webserver (nginx) on the controller

  • improves upgrade speed and flexibility compared to traditional in-band methods, and

  • falls back to CAPWAP method automatically if the out-of-band download fails.

Out-of-band download advantages

In WLAN deployments, APs traditionally gather their software image and configuration from the controller (in-band) during the join, predownload, and upgrade phases over the CAPWAP control path. This mechanism has limitations in the context of CAPWAP window size, processing of CAPWAP packets, and parallel image downloads. With image upgrade being a significant activity in the lifecycle of APs, upgrades become a time-consuming activity when the deployment size increases, especially for remote deployments, because the image always comes from the controller, irrespective of the deployment types.

To make upgrades faster and more flexible, the AP image upgrade method is enhanced in Cisco IOS XE Dublin 17.11.1 release. An enhanced webserver (nginx) running on the controller helps the AP image downloads to be available out of the CAPWAP path (out of band).

Key considerations for out-of-band AP image download:

  • HTTPS configuration done at the global level applies to all the APs joining the controller.

  • When AP image download over an Out-of-Band method fails, the download falls back to the CAPWAP method, as a result of which the APs will not be stranded.

  • AP image download over HTTPS may fail if the HTTPS server Trustpoint has a chain of CA certificates.

  • Before you downgrade from Cisco IOS XE Dublin 17.11.1 to an earlier version, ensure that the Out-of-Band AP Image Download feature is disabled, as it is not supported in previous releases.


Feature history for out-of-band AP image download

This table provides release and related information for the feature explained in this module.

This feature is available in all the releases subsequent to the one in which it is introduced in, unless noted otherwise.

Table 1. Feature history for out-of-band AP image download

Feature

Release

Feature Information

Out-of-Band AP Image Download

Cisco IOS XE Dublin 17.11.1

The AP image upgrade method is enhanced to make the upgrades faster and more flexible.


Restrictions for Out-of-Band AP image download

This feature is not supported on the following platforms:

  • Cisco Embedded Wireless Controller on Catalyst Access Points

  • Cisco Embedded Wireless Controller on Catalyst Switches

  • Cisco Wave 1 Access Points


Download AP image from controller using HTTPS (CLI)

Configure APs to download images from the controller over HTTPS for efficient out-of-band image updates.
APs can download images efficiently from the controller using HTTPS when the AP supports out-of-band download methods. This feature reduces upgrade time and network overhead compared to traditional CAPWAP-based image transfers.

Before you begin

  • HTTPS configuration must be enabled.

  • The nginx server must be running on the controller. Use the show platform software yang-management process command to check whether the nginx server is running.

  • The custom-configured port must be reachable between the controller and the corresponding AP.

Procedure

1.

Enter global configuration mode.

Example:

Device# configure terminal
2.

Configure the corresponding AP to download the image over HTTPS from the controller.

Example:

Device(config)# ap upgrade method https

This command configures the AP to use out-of-band AP image download method if the AP supports it.

You can check whether the AP supports efficient download method using the show AP config general command.

Use the no form of this command to disable out-of-band AP image download method.

3.

Configure a custom port for image download from the nginx server running on the controller.

Example:

Device(config)# ap file-transfer https port port-number

Example:

Device(config)# ap file-transfer https port 8445

For HTTPS port, the valid values range from 0 to 65535, with a default of 8443. You cannot use port 443 for AP file transfers because it is the default port used for other HTTPS requests. Also, avoid configuring standard and well-known ports because the configuration may fail.

By default, the Efficient AP image download feature uses port 8443 for HTTPS. If the same port is configured for HTTPS access for controller GUI, then GUI access will not work. In such instances, use a port number other than 8443 for controller GUI Access or configure a different port for AP file transfer over HTTPS instead of 8443.

The port 8443 is customizable. A sample config is given below:

Source= wireless controller
Destination= Access Point
Protocol=HTTPS
Destination Port=8443
Source Port=any
Description= "Out of Band AP Image Download"
4.

Return to privileged EXEC mode.

Example:

Device(config)# end
The AP is now configured to download images from the controller using HTTPS over the specified port, enabling efficient out-of-band image updates.

Download AP Image from Controller Using HTTPS (GUI)

Enable efficient AP image upgrade by configuring HTTPS method for out-of-band file transfer from the controller to access points.

The HTTPS method provides an efficient out-of-band file transfer mechanism for AP image upgrades. This configuration allows access points to download images directly from the controller using HTTPS protocol on a designated port.

Procedure

1.

Choose Configuration > Wireless > Wireless Global.

2.

In the AP Image Upgrade section, enable the HTTPS Method to allow image download on APs from the controller, over HTTPS.

Note

The AP should support out-of-band image download. You can verify this in the Configuration > Wireless > Access Points window. Select the AP, and in the Edit AP > Advanced tab, view the details of the support in the AP Image Management section.

3.

Enter the HTTPS Port to designate AP file transfers on that port.

Valid values range from 0 to 65535, with the default being 8443. Note that you cannot use port 443 for AP file transfers because that is the default port for other HTTPS requests.

By default, the Efficient AP image download feature uses port 8443 for HTTPS. If the same port is configured for HTTPS access for controller GUI, then GUI access will not work. In such instances, use a port number other than 8443 for controller GUI Access or configure a different port for AP file transfer over HTTPS instead of 8443.

4.

Click Apply to Device to save the configuration.

The HTTPS method for AP image download is now enabled and configured. Access points that support out-of-band image download can now efficiently download images from the controller using the specified HTTPS port.


Verify image upgrade

Verify out of band image download capabilities, status, and methods used by access points for image upgrades.

To check whether an AP supports efficient download method, use this command:

Device# show ap config general

Cisco AP Name : AP002C.C862.E880
=================================================

Cisco AP Identifier : 002c.c88b.0300
Country Code : Multiple Countries : IN,US
Regulatory Domain Allowed by Country : 802.11bg:-A 802.11a:-ABDN
AP Country Code : US - United States
AP Regulatory Domain
802.11bg : -A
AP Upgrade Out-Of-Band Capability : Enabled
AP statistics : Disabled

To view the AP image download statistics, use this command.

Use the show AP image command to see the detailed output.

Device# show ap image summary

Total number of APs  : 1
Number of APs 
        Initiated                  : 0
        Downloading                : 0
        Predownloading             : 0
        Completed downloading      : 0
        Completed predownloading   : 0
        Not Supported              : 0
        Failed to Predownload      : 0
        Predownload in progress    : No

To view the method used to download the AP image, use this command:

Device# show wireless stats ap image-download

AP image download info for last attempt
AP Name  Count ImageSize StartTime         EndTime            Diff(secs) Predownload Aborted  Method 
-----------------------------------------------------------------------------------------------------
mysore1  1     40509440  08/23/21 22:17:59 08/23/21 22:19:06  67         No          No       CAPWAP 


To view the method used to download the AP image, use this command:

Device# show ap upgrade method 

AP upgrade method HTTPS : Disabled

To view the port used for the AP image transfer, use this command:

Device# show ap file-transfer https summary 
 

       Configured port                 : 8443
       Operational port                : 8443

!If different ports are shown under 'Configured port' and 'Operations port' 
!that means custom port configuration has failed and is continuing with the previous port. 
!The failure reason could be the input port, which is a well-known port and already in use.

To view the whether an AP supports image download over HTTPS, use this command:

Device# show ap name AP2800 config general | sec Upgrade

AP Upgrade Out-Of-Band Capability               : Enabled 

To view the detailed output an AP's pre-image, use this command:

Device# show ap image

Total number of APs  : 2
Number of APs 
        Initiated                  : 0
        Downloading                : 0
        Predownloading             : 0
        Completed downloading      : 2
        Completed predownloading   : 0
        Not Supported              : 0
        Failed to Predownload      : 0
        Predownload in progress    : No
AP Name    Primary Image Backup Image Predownload Status Predownload Version Next Retry Time Retry Count Method
--------------------------------------------------------------------------------------------------------------------
AP_3800_1  17.11.0.69    17.11.0.71   None               0.0.0.0             N/A             0           HTTPS
AP2800     17.11.0.69    17.11.0.71   None               0.0.0.0             N/A             0           HTTPS

!The 'method' column indicates the download method used by the AP.