Learn how to configure advanced features that enhance access point performance, mobility, security, and traffic handling.
Configure transmission rate with high throughput
To configure high throughput transmission rate for WGB in moving deployments, perform this task. You can manually limit the transmission rate using the high throughput modulation and coding scheme (MCS).
Procedure
| 1. | Use the config dot11radio interface 802.11ax disable command to disable the 802.11ax standard on the specified dot11radio interface. Example:
|
|
| 2. | Use the config dot11radio interface 802.11ac disable disable command to disable the 802.11ax standard on the selected dot11radio interface. Example:
|
|
| 3. | Use the config dot11radio interface speed ht-mcs m4 m5 command to configure the desired HT MCS rate for the specified dot11radio interface. This action helps achieve the required transmission rates. Example:
|
|
| 4. | Use the debug wgb dot11 rate command to check the WGB Tx MCS rate.
|
Configure legacy rate for WGB
You can also configure legacy rates for WGB if required.
Procedure
Use the config dot11radio interface speed legacy-ratelegacy-rate command to cofigure the specific legacy rate on the dot11radio interface.
|
802.11v features
The 802.11v is a wireless network management standard that:
-
enables network-assisted roaming to optimize client connectivity,
-
helps balance client load by providing guidance to client devices, and
-
improves wireless performance through enhanced management frames and procedures.
802.11v is part of the IEEE 802.11 family of Wi-Fi standards. It includes features such as network-assisted roaming, which allows network infrastructure (such as wireless controllers) to direct clients to better access points (APs), reducing congestion and improving overall network efficiency.
Roaming and management enhancements
The following sections detail how 802.11v supports roaming and client management:
-
Enhancement of roaming with 802.11v support: When 802.11v support is enabled on a Workgroup Bridge (WGB), it enhances roaming by enabling the WGB to proactively select optimal APs based on updated neighborhood information. The WGB can actively initiate roaming to suitable APs from dynamically updated lists, and periodic checks ensure that the WGB maintains the most accurate AP neighbor data.
-
Basic service set transition request frame: The Basic Service Set (BSS) Transition Request frame includes channel information of neighboring APs. Limiting scanning to these specified channels significantly reduces roaming latency in environments that use multiple channels.
-
Disassociate the client on the AP using WLC: The Wireless LAN Controller (WLC) can disassociate a client based on factors such as AP load, Received Signal Strength Indicator (RSSI), and data rate. The WLC can notify 802.11v-enabled clients of an impending disassociation through the BSS transition management request frame. If the client fails to re-associate with another AP within a configurable time, the disassociation is enforced.
Administrators can enable the disassociation-imminent configuration on the WLC, which activates the optional field within the BSS transition management request frame. For detailed information of 802.11v configuration on the WLC, see Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide .
Enable or disable 802.11v support
Enable 802.11v support on the WGB to optimize roaming performance by restricting channel scanning to those learned from the neighbor list.
Procedure
Enable or disable 802.11v support on WGB.
|
Configure BSS transition query interval
Perform this task to configure the time interval at which the WGB sends BSS transition query messages to the parent AP. This ensures optimal network performance by managing the frequency of transition queries.
Procedure
Use configure wgb neighborlist-update-interval interval command to configure the time interval that WGB sends BSS transition query message to the parent AP.
|
Verify neighbor list
Ensure the neighbor list received from the associated AP is accurate and up to date.
Procedure
Use show wgb dot11v bss-transition neighbour command to display the neighbor list received from the associated AP.
|
Verify the channel list
Verify the channel list to ensure the device is correctly identifying channels from the dot11v neighbor, auxiliary radio scan, and residual channel scan. This step is crucial for troubleshooting connectivity or performance issues related to wireless networks.
Procedure
Use show wgb dot11v bss-transition channel command to check channel list from dot11v neighbor, aux radio scanned, and residual channel scanned.
|
Clear neighbor list
Perform this task to clear the neighbor list for error condition recovery. This ensures optimal device performance by resolving potential connectivity issues related to neighbors.
Procedure
Use clear wgb dot11v bss-transition neighbor command to clear neighbor list to provide error condition recovery.
|
Auxiliary scanning
Configure aux-scan mode as either scanning-only or handoff mode on WGB radio 2 (5 GHz) to improve roaming performance.
Scan-only mode
The scanning-only mode is a wireless access point operational mode that:
-
enables radio operation exclusively for scanning,
-
continuously monitors the wireless environment to collect data on network performance, interference, and rogue devices, and
-
allows configuration of scanning parameters such as channel lists and scanning intervals.
When slot 2 radio is configured in scanning-only mode, slot 1 (5G) radio is always selected as the uplink. Slot 2 (5G) radio continues to scan the configured SSID based on the channel list. By default, the channel list contains all supported 5G channels (based on reg domain). You can configure the scanning list manually, or the device can learn it from 802.11v.
When roaming is triggered, the algorithm looks for candidates in the scanning table and skips the scanning phase if the table is not empty. The WGB then associates to the selected candidate AP.
Configure scan-only mode
Enable the device to operate in scan-only mode, facilitating network monitoring and assessment without transmitting data.
Procedure
Use the configure dot11Radio 2 mode scan only command to configure scanning only mode.
|
Configure scanning table timer
Adjust the scanning table timer to optimize the candidate AP selection process and prevent roaming failures caused by outdated RSSI values.
Before you begin
The scanning table maintains a list of candidate APs detected by the device. By default, entries in this table expire after 1200 milliseconds. Modifying the expiration timer may help improve roaming efficiency by allowing more time for RSSI updates.
Procedure
Use the configure wgb scan timeout interval command to adjust the timer. By default, candidate AP entries in scanning table are automatically removed in 1200 ms.
|
Manually add or remove channels from the channel list
Perform this task to manually add or remove channels from the channel list to optimize wireless network performance or for specific configuration requirements.
Procedure
Add or remove channels from the channel list using one of the options.
|
Verify scanning table
Perform this task to confirm the current AP scanning details and identify the best AP for optimal connectivity.
Procedure
Use show wgb scan command to verify the scanning table.
|
Auxiliary Scanning handoff mode
An Auxiliary Scanning handoff mode is a wireless radio configuration that
-
allows both radios (radio 1 and radio 2) to serve as uplink connections,
-
supports dynamic switching of roles and traffic between radios after each roaming event, and
-
enables efficient roaming by using a scanning radio to associate with the best available access point.
The Auxiliary Scanning list can be manually configured or learned automatically using the 802.11v standard. This handoff mode improves roaming performance by quickly associating with the best available access point.
Radio roles
The radio 2 shares the same MAC address with the radio 1 and supports scanning, association, and data serving. Both radios can operate in either a serving or scanning role. After each roaming event, the roles and traffic automatically switch between radio 1 and radio 2.
Roaming of AP
When roaming is triggered, the system algorithm checks the scanning database for the best AP to establish a connection. WGB always uses the radio in the scanning role to complete the roaming association with the new AP. This configuration reduces roaming interruptions to between 20 and 50 milliseconds.
This table shows an example of aux-scan handoff radio mode configuration on IW9165E:
| Slot 0 (2.4 G) |
Slot 1 (5G) |
Slot 2 (5G only) |
Slot 3 (scanning radio) |
|---|---|---|---|
| N/A |
WGB |
Scan handoff |
N/A |
This table shows how long roaming interruptions last for different methods when using three different modes:
| Roaming interruption time |
Normal channel setting |
Auxiliary Scanning only |
Auxiliary Scanning Handoff |
|---|---|---|---|
| Scanning |
(40+20)*3=180 ms |
0-40 ms |
0 ms |
| Association |
30-80 ms |
30-80 ms |
20-50 ms |
| Total |
~210 ms |
70-120 ms |
20-50 ms |
Guidelines and restrictions for Auxiliary Scanning
-
The
different-parentthreshold applies to bothscan-onlyandhandoffmodes.-
In
scan-onlymode, roaming decisions are strictly based on selecting a different candidate BSSID. This supports combinations such as dual 2.4 GHz and dual 5 GHz. -
In
handoffmode, the WGB can either roam to a different BSSID or switch radios while remaining on the same parent BSSID.
-
-
The
same-parentthreshold is only relevant when the WGB is operating inhandoffmode.
Configure radio 2 in Aux-Scan handoff mode
Perform this task to configure the WGB slot 2 radio in auxiliary-scan handoff mode, ensuring seamless connectivity and optimized network performance.
Before you begin
Auxiliary-scan handoff mode allows the radio to scan for available access points without interrupting active connections. This feature is particularly useful for improving handoff reliability in environments with multiple access points.
Procedure
| 1. | Use the configure dot11Radio radio-num mode scan handoff command to configure the WGB slot 2 radio to aux-scan mode:
|
|
| 2. | (Optional) Use the show running-config command to view the radio configuration.
|
Configure RSSI delta threshold for candidate BSSID
This section explains how the WGB evaluates candidate APs during auxiliary scans. By adjusting the RSSI delta threshold, you can control how much stronger a new signal must be before it triggers a roam or radio switch. This adjustment helps prevent unnecessary transitions when signal strengths are similar.
Procedure
| 1. | Use the configure wgb mobile aux-scan delta-rssi different-parentthreshold command to configure the RSSI-delta threshold (in dB) when the candidate BSSID is different from the current BSSID.
Default threshold value is 6 dB. |
|
| 2. | Use the configure wgb mobile aux-scan delta-rssi same-parentthreshold command to configure the RSSI-delta threshold (in dB) when the candidate remains on the same parent BSSID.
Default threshold value is 100 dB. |
Verify WGB scan
Perform this task to confirm the current role of each radio and analyze the auxiliary scanning results, including the best AP selection and performance metrics.
WGB scan provides detailed information about the auxiliary scanning process for each radio. This data helps to determine the best AP based on signal strength (RSSI), channel, and scan time.
Procedure
Use the show wgb scan command to view the current role of each radio and the results of aux scanning.
|
Optimized roaming with dual-radio WGBs
Dual-radio WGBs are wireless workgroup bridges that
-
use two radios to enhance roaming efficiency,
-
minimize service disruption by skipping the active scanning phase with an existing scanning table, and
-
initiate roaming when beacon frames are missed or packet retry thresholds are reached.
From the Cisco IOS-XE 17.15.1 release, devices with dual-radio configurations have improved roaming efficiency. This reduces service downtime.
Trigger factors for roaming
Trigger factors for roaming include:
-
Low RSSI: Measures the power level that a wireless device, such as an AP, receives from a signal. Use RSSI values to determine the quality of the wireless connection to troubleshoot and optimize wireless networks.
-
Beacon miss-count: Indicates the number of consecutive beacon frames that a client device has missed from an AP in a wireless network.
-
Maximum packet retries: Specifies the maximum number of times a data packet can be retransmitted if the client device does not send an acknowledgement.
Configuration options for dual-radio
Here are the possible configurations for the IW9165E AP in a dual-radio setup:
| Dual-radio |
AP |
|---|---|
| 5 GHz radio 1 + radio 2 (scanning only mode) |
IW9165E |
| 5 GHz radio 1 + radio 2 (aux-scan handoff mode) |
Layer 2 NAT
One-to-one (1:1) Layer 2 NAT allows you to assign a unique public IP address to an existing private IP address (end device). This enables the end device to communicate with a public network.
Layer 2 NAT maintains two translation tables:
-
private-to-public subnet translations
-
public-to-private subnet translations
In industrial deployments, such as Human Machine Interfaces (HMIs) or robots, the same firmware is often programmed on every machine. This results in duplicate IP addresses across multiple devices. Layer 2 NAT resolves this issue by enabling devices with duplicate private IP addresses to communicate with public networks.
Configure Layer 2 NAT
The Layer 2 NAT (Network Address Translation) configuration commands are used to control IP address translation for wired clients within a VLAN at Layer 2.
These commands allow administrators to:
-
Enable or disable Layer 2 NAT globally on the device.
-
Define a default VLAN where NAT rules are applied.
-
Translate individual host addresses from private to public, or from public to private.
-
Translate entire subnets from private-to-public or public-to-private.
This configuration ensures seamless communication between private networks and external/public networks by dynamically or statically mapping IP addresses, while maintaining VLAN-based traffic segregation.
Procedure
| 1. | Use the configure l2nat { enable | disable} command to enable or disable Layer 2 NAT.
|
|
| 2. | Use the configure l2nat default-vlan vlan_id command to define the VLAN where all NAT rules are applied.
|
|
| 3. | Use the configure l2nat { add | delete} inside from host original_ip_addr to translated_ip_addr command to translate a private IP address of a wired client to a public IP address.
|
|
| 4. | Use the configure l2nat { add | delete} outside from host original_ip_addr to translated_ip_addr command to translate a public IP address to a private IP address.
|
|
| 5. | Use the configure l2nat { add | delete} inside from network original_nw_prefix to translated_nw_prefix subnet_mask command to translate a private subnet to a public subnet.
|
|
| 6. | Use the configure l2nat { add | delete} outside from network original_nw_prefix to translated_nw_prefix subnet_mask command to translate a public subnet to a private subnet.
|
Verify Layer 2 NAT Configuration
Use the following commands to verify Layer 2 NAT configuration, check translation statistics, and clear rules or counters for troubleshooting.
-
show l2nat entry: Displays the Layer 2 NAT running entries.
-
show l2nat config: Displays the Layer 2 NAT configuration details.
-
show l2nat stats: Displays the Layer 2 NAT packet translation statistics.
-
show l2nat rules: Displays the Layer 2 NAT rules from the configuration.
-
clear l2nat statistics: Clears packet translation statistics.
-
clear l2nat rule: Clears Layer 2 NAT rules.
-
clear l2nat config: Clears Layer 2 NAT configuration.
-
debug l2nat: Enables debugging of packet translation process.
-
debug l2nat all: Prints out the NAT entry match result when a packet arrives.
This command may create overwhelming log print in console. Console may lose response because of this command, especially when Syslog service is enabled with a broadcast address.
-
undebug l2nat: Disables debugging of packet translation process.
Configuration Example of Host IP Address Translation
In this scenario, the end client (172.16.1.36) connected to WGB needs to communicate with the server (192.168.150.56) connected to the gateway. Layer 2 NAT provides an address for the end client on the outside network (192.168.150.36) and an address for the server on the inside network (172.16.1.56).
Layer 2 NAT configuration example
This example displays Layer 2 NAT configuration details. In the output, I2O means 'inside to outside' and O2I means 'outside to inside.
Device# show l2nat config
L2NAT Configuration are:
===================================
Status: enabled
Default Vlan: 0
The Number of L2nat Rules: 4
Dir Inside Outside Vlan
O2I 172.16.1.56 192.168.150.56 0
I2O 172.16.1.36 192.168.150.36 0
I2O 172.16.1.255 192.168.150.255 0
I2O 172.16.1.1 192.168.150.1 0
Layer 2 NAT rules example
This example displays the Layer 2 NAT rules.
Device# show l2nat rule
Dir Inside Outside Vlan
O2I 172.16.1.56 192.168.150.56 0
I2O 172.16.1.36 192.168.150.36 0
I2O 172.16.1.255 192.168.150.255 0
I2O 172.16.1.1 192.168.150.1 0
Layer 2 NAT entries example
This example displays the current Layer 2 NAT entries.
Device# show l2nat entry
Direction Original Substitute Age Reversed
inside-to-outside 172.16.1.36@0 192.168.150. 36@0 -1 false
inside-to-outside 172.16.1.56@0 192.168.150. 56@0 -1 true
inside-to-outside 172.16.1.1@0 192.168.150. 1@0 -1 false
inside-to-outside 172.16.1.255@0 192.168.150. 255@0 -1 false
outside-to-inside 192.168.150.36@0 172.16.1.36@0 -1 true
outside-to-inside 192.168.150.56@0 172.16.1.56@0 -1 false
outside-to-inside 192.168.150.1@0 172.16.1.1@0 -1 true
outside-to-inside 192.168.150.255@0 172.16.1.255@0 -1 true
WGB wired clients example
This example displays the WGB wired clients over the bridge.
Before Layer 2 NAT is enabled:
Device# show wgb bridge
***Client ip table entries***
mac vap port vlan_id seen_ip confirm_ago fast_brg
B8:AE:ED:7E:46:EB 0 wired0 0 172.16.1.36 0.360000 true
24:16:1B:F8:05:0F 0 wbridge1 0 0.0.0.0 3420.560000 true
After Layer 2 NAT is enabled:
Device# show wgb bridge
***Client ip table entries***
mac vap port vlan_id seen_ip confirm_ago fast_brg
B8:AE:ED:7E:46:EB 0 wired0 0 192.168.150.36 0.440000 true
24:16:1B:F8:05:0F 0 wbridge1 0 0.0.0.0 3502.220000 true
If the wired client in NAT experiences E2E traffic issues, you can restart the client registration process by using the clear wgb client single command:
Layer 2 NAT packet translation statistics example
This example displays the Layer 2 NAT packet translation statistics.
Device# show l2nat stats
Direction Original Substitute ARP IP ICMP UDP TCP
inside-to-outside 172.16.1.1@2660 192.168.150.1@2660 1 4 4 0 0
inside-to-outside 172.16.1.36@2660 192.168.150.36@2660 3 129 32 90 1
inside-to-outside 172.16.1.56@2660 192.168.150.56@2660 2 114 28 85 1
inside-to-outside 172.16.1.255@2660 192.168.150.255@2660 0 0 0 0 0
outside-to-inside 192.168.150.1@2660 172.16.1.1@2660 1 4 4 0 0
outside-to-inside 192.168.150.36@2660 172.16.1.36@2660 3 39 38 0 1
outside-to-inside 192.168.150.56@2660 172.16.1.56@2660 2 35 34 0 1
outside-to-inside 192.168.150.255@2660 172.16.1.255@2660 0 0 0 0 0
To reset the statistics, you can use the clear l2nat stats command.
Configuration Example of Network Address Translation
In this scenario, Layer 2 NAT translates inside addresses in the 172.16.1.0/24 subnet to addresses in the 192.168.150.0/24 subnet, replacing only the network prefix during translation. The host bits remain the same.
The command used for this scenario is here:
Device# configure l2nat add inside from network 172.16.1.0 to 192.168.150.0 255.255.255.0
Native VLAN on Ethernet Ports
In a typical Workgroup Bridge (WGB) deployment, a single wired client connects directly to the WGB Ethernet port. Consequently, the wired client traffic must reside on the same VLAN as the WGB management VLAN. If you require the wired client traffic to be on a different VLAN than the WGB management VLAN, configure the native VLAN on the Ethernet port.
Configuring native VLAN ID per Ethernet port is not supported. Both Ethernet ports share the same native VLAN configuration.
When WGB broadcast tagging is enabled and a single wired passive client connects directly to the WGB Ethernet port, an issue may arise where the infrastructure downstream (DS) side client fails to ping the WGB behind the passive client. To resolve this, configure the following commands:
configure wgb ethport native-vlan enableand configure wgb ethport native-vlan id X, where X is the same VLAN as the WGB management VLAN.
To verify your configuration, use the show wgb ethport config or show running-config command.
Configure Native VLAN on Ethernet Ports
The native VLAN configuration commands are used to manage how untagged traffic is handled on the Workgroup Bridge (WGB) Ethernet port.
These commands allow administrators to:
-
Enable or disable native VLAN configuration on the WGB Ethernet port.
-
Specify the native VLAN ID to ensure that untagged traffic is correctly assigned to the intended VLAN.
Procedure
| 1. | Use the config wgb ethport ethport native-vlan { enable | disable } command to enable or disable native VLAN configuration.
|
|
| 2. | Use the config wgb ethport ethport native-vlan vlan_id command to specify the native VLAN ID.
|
|
| 3. | (Optional) Use the show wgb ethport config or show running-config command to verify your configuration.
|
Low latency profile
Low latency profiles are configurations that optimize IEEE 802.11 networks to meet the low latency and Quality of Service requirements essential for IoT applications.
-
Enhanced Distributed Channel Access (EDCA): Prioritizes wireless channel access for latency-sensitive traffic to ensure consistent performance.
-
Aggregated MAC Protocol Data Unit (AMPDU): Combines multiple data frames into a single transmission to reduce overhead and improve efficiency.
-
Packet Retry: Ensures successful data delivery by retransmitting aggregated or individual packets based on network conditions.
IoT Application Support
These features collectively support the deployment of IoT devices and applications that demand low latency and high Quality of Service in wireless environments.
Enable or disable an optimized-video EDCA profile
Configure an optimized low-latency profile for video use cases to improve video performance by reducing delays and enhancing the quality of service.
This task focuses on enabling or disabling the optimized-video EDCA profile on a specific radio interface of WGB. The optimized-video profile ensures better handling of video traffic by prioritizing it in the network.
Procedure
| 1. | Enable or disable the optimized-video EDCA profile on a specific radio interface of WGB using one of the options.
|
|||||||
| 2. | (Optional) Use the show controllers dot11Radio radio_slot_id command to verify the configuration:
|
Enable or disable optimized-automation EDCA profile
Enable the optimized low-latency profile for automation use cases to improve performance and efficiency in wireless network environments.
Procedure
| 1. | Enable or disable the optimized-video EDCA profile on a specific radio interface of WGB using one of the options.
|
|||||||
| 2. | (Optional) Use the show controllers dot11Radio radio_slot_id command to verify the configuration:
|
Configure customized-wmm EDCA profile
Customize the Wi-Fi Multimedia (WMM) profile to optimize traffic queues and improve QoS for specific types of network traffic.
WMM enhances the performance of Wi-Fi networks by prioritizing traffic based on the type of data being transmitted. Configuring a customized WMM EDCA (Enhanced Distributed Channel Access) profile allows you to fine-tune the performance parameters for voice, video, background, and best-effort traffic.
Procedure
| 1. | Use the configure dot11Radio radio_slot_id profile customized-wmm enable command to enable the customized WMM profile.
|
|
| 2. | Use the configure dot11Radio {0| 1|2}wmm {be| vi| vo| bk}{cwmin cwmin_num |cwmax cwmax_num | aifs aifs_num |txoplimit txoplimit_num} command to configure customized WMM profile parameters.
Parameter descriptions:
|
|
| 3. | (Optional) Disable the customized WMM profile. Use the configure dot11Radio radio_slot_id profile customized-wmm disable command to disable the customized WMM profile.
|
Configure EDCA parameters using Controller GUI
Configure Enhanced Distributed Channel Access (EDCA) parameters to optimize wireless channel access for voice, video, and other QoS traffic.
Procedure
| 1. | Navigate to . This page allows you to configure global parameters for 6 GHz, 5 GHz, and 2.4 GHz radios.
|
|
| 2. | In the EDCA Parameters section, choose an EDCA profile from the EDCA Profile drop-down list.
EDCA parameters provide preferential wireless channel access for voice, video, and other QoS traffic. |
|
| 3. | Click Apply. |
Configure EDCA parameters using Controller CLI
To optimize wireless network performance for IoT low-latency applications by adjusting Enhanced Distributed Channel Access (EDCA) parameters.
Perform these steps on the command-line interface (CLI) of a Cisco Wireless Controller.
Procedure
| 1. | Use the configure terminal command to enter the global configuration mode.
|
|
| 2. | Use the ap dot11 {5ghz | 24ghz | 6ghz } shutdown command to disable the radio network.
|
|
| 3. | Use the ap dot11 {5ghz | 24ghz | 6ghz } edca-parameters iot-low-latency command to enable the iot-low-latency EDCA profile for the 5 GHz, 2.4 GHz, or 6 GHz network.
|
|
| 4. | Use the no ap dot11 {5ghz | 24ghz | 6ghz } shutdown command to enable the radio network.
|
|
| 5. | Use the end command to return to privileged EXEC mode.
|
|
| 6. | (Optional) Use the show ap dot11 {5ghz | 24ghz | 6ghz } network command to view the current configuration.
|
A-MPDU
Aggregation is the process of grouping multiple packet data frames into a single larger frame for transmission, rather than sending them individually. This method enhances efficiency and reduces overhead in wireless communications. Two common aggregation methods are Aggregated MAC Protocol Data Unit (A-MPDU) and Aggregated MAC Service Data Unit (A-MSDU). A-MPDU parameters specifically define the size of the aggregated packet and the necessary spacing between aggregated packets, allowing the receiving WLAN station to properly decode the data.
Configure A-MPDU
Before you begin
Configure A-MPDU parameters to optimize the aggregation and transmission of packet data frames, ensuring efficient decoding by WLAN stations.
Procedure
| 1. | Use the ap dot11 {5ghz | 24ghz | 6ghz } rf-profile profile-name command to configure profile-based A-MPDU parameters.
|
|
| 2. | Use the dot11n a-mpdu tx block-ack window-size window-size command to configure transmission block-acknowledgment (block-ack) window size.
|
|
| 3. | Use the exit command to return to global configuration mode.
|
|
| 4. | Use the ap dot11 {5ghz | 24ghz | 6ghz } dot11n a-mpdu tx block-ack window-size window-size command to configure transmission block-acknowledgment window size globally.
|
|
| 5. | Use the wireless tag rf rf-tag-name command to create an RF tag.
|
|
| 6. | Use the 5ghz-rf-policy rf-profile-name command to bind RF tags to RF profiles and to apply them to specific radios.
|
|
| 7. | Use the end command to return to privileged EXEC mode.
|
|
| 8. | (Optional) Use the show controllers dot11Radio radio_slot_id command to show the configured A-MPDU length value.
|
SNMP features
The Simple Network Management Protocol (SNMP) on WGB is a functional element that
-
facilitates monitoring and management of the WGB device through the SNMP protocol,
-
includes roles for information exchange (manager, agent, MIB), and
-
supports network health assessment and parameter configuration.
The SNMP framework on WGB includes:
-
SNMP Manager: Controls and monitors the activities of network devices using SNMP, typically implemented as a network management system (NMS).
-
SNMP Agent: The software component within the managed device that maintains and reports device data.
-
SNMP MIB: A collection of managed objects (variables) which can be queried or set by the SNMP manager.
SNMP process
This illustration shows the SNMP process. When an SNMP manager requests data, the agent receives the request and relays it to the subagent, which responds. The agent then sends an SNMP response packet to the manager.
SNMP versions
Cisco IOS software supports the following versions of SNMP:
-
SNMPv2c—The community-string-based administrative framework for SNMPv2. SNMPv2c is an update of the protocol operations and data types of SNMPv2p (SNMPv2 classic), and uses the community-based security model of SNMPv1.
-
SNMPv3—Version 3 of SNMP. SNMPv3 uses the following security features to provide secure access to devices:
-
Message integrity—Ensuring that a packet has not been tampered with in transit.
-
Authentication—Determining that the message is from a valid source.
-
Encryption—Scrambling the contents of a packet to prevent it from being learned by an unauthorized source.
-
Supported SNMP MIB files
The Management Information Base (MIB) is a database containing objects that can be managed on a device. These managed objects, also called variables, can be set or read to provide information about network devices and interfaces. The objects are organized in a hierarchical structure and are grouped in collections identified by object identifiers. Access to MIBs is provided through network management protocols such as SNMP.
The MIB module provides network management information on IEEE 802.11 wireless device association management and data packet forwarding configuration and statistics.
An Object Identifier (OID) uniquely identifies a MIB object on a managed network device. The OID shows the object's location in the MIB hierarchy and provides a way to access the MIB object in a network of managed devices.
Supported OIDs
The list of objects that are supported by the SNMP Management and Information Base (MIB):
-
CISCO-DOT11-ASSOCIATION-MIB OIDs are given here.
| OID Object Name |
OID |
OID Type |
OID Description |
|---|---|---|---|
| cDot11ParentAddress |
1.3.6.1.4.1.9.9.273.1.1.1 |
String |
Provides the MAC address of the parent access point. |
| cDot11ActiveWirelessClients |
1.3.6.1.4.1.9.9.273.1.1.2.1.1 |
Gauge |
The device on this interface is currently associating with the number of wireless clients. |
| cDot11ActiveBridges |
1.3.6.1.4.1.9.9.273.1.1.2.1.2 |
Gauge |
The device on this interface is currently associating with the number of bridges. |
| cDot11ActiveRepeaters |
1.3.6.1.4.1.9.9.273.1.1.2.1.3 |
Gauge |
The device on the interface is currently associating with the number of repeaters. |
| cDot11AssStatsAssociated |
1.3.6.1.4.1.9.9.273.1.1.3.1.1 |
Counter |
When device restarts, the object counts the number of stations associated with the device on the interface. |
| cDot11AssStatsAuthenticated |
1.3.6.1.4.1.9.9.273.1.1.3.1.2 |
Counter |
When the device restarted, it currently counts the number of stations authenticated with the device on the interface. |
| cDot11AssStatsRoamedIn |
1.3.6.1.4.1.9.9.273.1.1.3.1.3 |
Counter |
When the device restarted, the object counts the number of stations roamed from another device to the device on the interface. |
| cDot11AssStatsRoamedAway |
1.3.6.1.4.1.9.9.273.1.1.3.1.4 |
Counter |
This object counts the number of stations roamed away from the device on the interface since device re-started. |
| cDot11AssStatsDeauthenticated |
1.3.6.1.4.1.9.9.273.1.1.3.1.5 |
Counter |
This object counts the number of stations deauthenticated with this device on the interface since device re-started |
| cDot11AssStatsDisassociated |
1.3.6.1.4.1.9.9.273.1.1.3.1.6 |
Counter |
This object counts the number of stations disassociated with this device on the interface since device re-started |
| cd11IfCipherMicFailClientAddress |
1.3.6.1.4.1.9.9.273.1.1.4.1.1 |
String |
This is MAC address of the client attached to the radio interface that caused the most recent MIC failure |
| cd11IfCipherTkipLocalMicFailures |
1.3.6.1.4.1.9.9.273.1.1.4.1.2 |
Counter |
When the device restarted, the object counts the number of MIC failures encountered on the radio interface. |
| cd11IfCipherTkipRemotMicFailures |
1.3.6.1.4.1.9.9.273.1.1.4.1.3 |
Counter |
When the device restarted, the object counts the number of MIC failures reported by clients on the radio interface. |
| cd11IfCipherTkipCounterMeasInvok |
1.3.6.1.4.1.9.9.273.1.1.4.1.4 |
Counter |
When the device restarted, the object counts the number of TKIP Counter Measures invoked on the interface. |
| cd11IfCipherCcmpReplaysDiscarded |
1.3.6.1.4.1.9.9.273.1.1.4.1.5 |
Counter |
When the device restarted, the object counts the number of received unicast fragments discarded by replay mechanism on the interface. |
| cd11IfCipherTkipReplaysDetected |
1.3.6.1.4.1.9.9.273.1.1.4.1.6 |
When the device restarted, the object counts the number of TKIP replay errors detected on this interface. |
|
| cDot11ClientRoleClassType |
1.3.6.1.4.1.9.9.273.1.2.1.1.3 |
Counter |
The role classification of the client |
| cDot11ClientDevType |
1.3.6.1.4.1.9.9.273.1.2.1.1.4 |
EnumVal |
The device type of the client. |
| cDot11ClientRadioType |
1.3.6.1.4.1.9.9.273.1.2.1.1.5 |
EnumVal |
The radio classification of the client. |
| cDot11ClientWepEnabled |
1.3.6.1.4.1.9.9.273.1.2.1.1.6 |
EnumVal |
Whether WEP key mechanism is used for transmitting frames of data for the client |
| cDot11ClientWepKeyMixEnabled |
1.3.6.1.4.1.9.9.273.1.2.1.1.7 |
EnumVal |
Whether this client is using WEP key mixing |
| cDot11ClientMicEnabled |
1.3.6.1.4.1.9.9.273.1.2.1.1.8 |
EnumVal |
Whether the MIC is enabled for the client |
| cDot11ClientPowerSaveMode |
1.3.6.1.4.1.9.9.273.1.2.1.1.9 |
EnumVal |
The power management mode of the client. |
| cDot11ClientAid |
1.3.6.1.4.1.9.9.273.1.2.1.1.10 |
Gauge |
This is the association identification number of clients or multicast addresses associating with the device. |
| cDot11ClientDataRateSet |
1.3.6.1.4.1.9.9.273.1.2.1.1.11 |
String |
Is a set of data rates at which this client can transmit and receive data |
| cDot11ClientSoftwareVersion |
1.3.6.1.4.1.9.9.273.1.2.1.1.12 |
String |
Cisco IOS software version |
| cDot11ClientName |
1.3.6.1.4.1.9.9.273.1.2.1.1.13 |
String |
Cisco IOS device hostname |
| cDot11ClientAssociationState |
1.3.6.1.4.1.9.9.273.1.2.1.1.14 |
EnumVal |
The object indicates the state of the authentication and association process |
| cDot11ClientVlanId |
1.3.6.1.4.1.9.9.273.1.2.1.1.17 |
Gauge |
The VLAN which the wireless client is assigned to when it is successfully associated to the wireless station. |
| cDot11ClientSubIfIndex |
1.3.6.1.4.1.9.9.273.1.2.1.1.18 |
Integer |
This is the ifIndex of the sub-interface which this wireless client is assigned to when it is successfully associated to the wireless station. |
| cDot11ClientAuthenAlgorithm |
1.3.6.1.4.1.9.9.273.1.2.1.1.19 |
EnumVal |
The IEEE 802.1x authentication methods performed between the wireless station and this client during association |
| cDot11ClientDot1xAuthenAlgorithm |
1.3.6.1.4.1.9.9.273.1.2.1.1.21 |
Octet String |
The IEEE 802.1x authentication methods performed between the wireless client and the authentication server. |
| cDot11ClientUpTime |
1.3.6.1.4.1.9.9.273.1.3.1.1.2 |
Gauge |
The time in seconds that this client has been associated with this device |
| cDot11ClientSignalStrength |
1.3.6.1.4.1.9.9.273.1.3.1.1.3 |
Integer |
The device-dependent measure the signal strength of the most recently received packet from the client. |
| cDot11ClientSigQuality |
1.3.6.1.4.1.9.9.273.1.3.1.1.4 |
Gauge |
The device-dependent measure the signal quality of the most recently received packet from the client. |
| cDot11ClientPacketsReceived |
1.3.6.1.4.1.9.9.273.1.3.1.1.6 |
Counter |
The number of packets received from this client. |
| cDot11ClientBytesReceived |
1.3.6.1.4.1.9.9.273.1.3.1.1.7 |
Counter |
The number of bytes received from the client. |
| cDot11ClientPacketsSent |
1.3.6.1.4.1.9.9.273.1.3.1.1.8 |
Counter |
The number of packets sent to the client. |
| cDot11ClientBytesSent |
1.3.6.1.4.1.9.9.273.1.3.1.1.9 |
Counter |
The number of bytes sent to the client. |
| cDot11ClientMsduRetries |
1.3.6.1.4.1.9.9.273.1.3.1.1.11 |
Counter |
The counter increases when it successfully transmits an MSDU after one or more retransmissions. |
| cDot11ClientMsduFails |
1.3.6.1.4.1.9.9.273.1.3.1.1.12 |
Counter |
The counter increments when the client fails to transmit an MSDU successfully because the number of transmit attempts exceeds a certain limit. |
Configure SNMP parameters
This procedure describes how to configure Simple Network Management Protocol (SNMP) on the WGB. You can enable SNMPv2c or SNMPv3 depending on your network requirements. The steps include setting community strings or usernames, defining authentication and encryption methods, and enabling SNMP functionality on the device.
-
Configure all SNMP parameters before enabling the SNMP feature using the CLI command: configure snmp enabled.
-
All SNMP configurations will be automatically removed when the SNMP feature is disabled.
Procedure
| 1. | Use the configure snmp v2c community-id length length command to enter the SNMP v2c community ID (SNMP v2c only).
|
|
| 2. | Use the configure snmp version {v2c | v3 } command to specify the SNMP protocol version.
|
|
| 3. | Use the configure snmp auth-method {md5 | sha } command to specify the SNMP v3 authentication protocol (SNMP v3 only).
|
|
| 4. | Use the configure snmp v3 username length length command to enter the SNMP v3 username (SNMP v3 only).
|
|
| 5. | Use the configure snmp v3 password length length command to enter the SNMP v3 user password (SNMP v3 only).
The valid range for length is 8 to 64 characters. |
|
| 6. | Use the configure snmp encryption {des | aes | none } command to specify the SNMP v3 encryption protocol (SNMP v3 only).
Encryption values are des or aes . Use none if a v3 encryption protocol is not needed. |
|
| 7. | Use the configure snmp secret length length command to enter the SNMP v3 encryption passphrase (SNMP v3 only).
The valid range for length is 8 to 64 characters. |
|
| 8. | Use the configure snmp enabled command to enable SNMP functionality on the WGB.
To configure SNMP v2c, repeat Step 1, Step 2 and Step 8. To configure SNMP v3, repeat Step 2 through Step 8. |
|
| 9. | (Optional) Use the configure snmp disabled command to disable SNMP configuration.
|
SNMP configuration examples
Configuring SNMP v2c:
Device#configure snmp v2 community-id 25
Device#configure snmp version v2c
Device#configure snmp enabled
Configuring SNMP v3 (security level AuthPriv):
Device#configure snmp auth-method md5
Device#configure snmp v3 username length 32
Device#configure snmp v3 password length 25
Device#configure snmp secret length 12
Device#configure snmp encryption aes
Device#configure snmp version v3
Device#configure snmp enabled
Configuring SNMP v3 (security level AuthNoPriv):
Device#configure snmp auth-method md5
Device#configure snmp v3 username length 32
Device#configure snmp v3 password length 32
Device#configure snmp encryption none
Device#configure snmp version v3
Device#configure snmp enabled
Verifying SNMP
Use the show snmp command to verify the SNMP configuration.
SNMP version v3
Device# show snmp
SNMP: enabled
Version: v3
Community ID: test
Username: username
Password: password
Authentication method: SHA
Encryption: AES
Encryption Passphrase: passphrase
Engine ID: 0x8000000903c0f87fe5f314
SNMP version v2c
Device# show snmp
SNMP: enabled
Version: v2c
Community ID: test
Username: username
Password: password
Authentication method: SHA
Encryption: AES
Encryption Passphrase: passphrase
Engine ID: 0x8000000903c0f87fe5f314
QoS ACL classification and marking
Quality of Service (QoS) ACL classification and marking identify network traffic using access control list (ACL) rules and assign a traffic class or priority value.
-
Classification uses ACLs to match traffic flows based on parameters such as source or destination IP address, protocol type, port numbers, or other header fields.
-
Marking occurs after classification, where packets are tagged with specific QoS values, such as DSCP, IP precedence, or CoS, to indicate their priority level.
Starting with Cisco Unified Industrial Wireless Software Release 17.14.1, you can classify packets from two wired ports and assign them to different access control driver queues. In addition to TCP and UDP, the WGB supports ethertype-based and DSCP-based classification to meet jitter and latency requirements.
Rule-based traffic classifications
A rule-based traffic classification is a network management technique that:
-
uses custom rules to classify incoming Ethernet packets by criteria such as 802.1p, DSCP, and protocol type,
-
assigns classified packets to priority queues on the wireless side for QoS enforcement, and
-
ensures critical services receive higher priority, reducing latency and optimizing network performance.
Rule configuration criteria
You can configure mapping rules using the following parameters:
-
Ethernet type (for example, Profinet)
-
Transport layer port numbers or port ranges
-
DSCP values
-
Source and destination IP addresses
-
Protocol types
Packet classification and assignment
As incoming packets arrive at the Ethernet port, WGB applies the defined rules to:
-
Identify critical services or traffic flows
-
Classify packets based on predefined criteria
-
Assign packets to the appropriate access control queues on the wireless network
Benefits of rule-based mapping
By using customized rule-based classification and mapping, you can:
-
Enforce QoS policies effectively
-
Prioritize critical applications and services
-
Reduce latency for time-sensitive traffic
-
Improve overall network performance and user experience
QoS and ACL traffic classification methods
Traffic classification is the process of distinguishing one type of network traffic from another by examining packet fields. It is enabled only when QoS is active. During classification, the device performs a lookup and assigns a QoS label to the packet. The QoS label defines the QoS actions to be applied and identifies the output queue for forwarding.
-
Classification relies on fields across packet layers
-
Packets are grouped into service classes based on Ethertype, DSCP, or TCP/UDP ports, and consistently treated within those classes.
-
The data plane records rule hits for analysis, while the control plane configures data forwarding.
Layer 2 classification fields
Layer 2 Ethernet frames use the Ethertype field (2 bytes) to carry classification information. This field normally indicates the type of data encapsulated in the frames.
Layer 3 classification fields
Layer 3 IP packets carry classification information in the Type of Service (ToS) field (8 bits). It has:
-
IP precedence values that range from 0–7, and
-
DSCP values that range from 0–63.
Layer 4 classification fields
Layer 4 TCP segments or UDP datagrams use the source or destination port fields for classification. These port numbers allow devices to classify traffic based on applications or services.
Traffic assignment to service classes
The system assigns traffic to a specific service class based on Ethertype, DSCP, or UDP/TCP port (or port range). Packets within a service class are treated consistently. WGBs classify packets from wired ports and map them to different driver queues according to user configuration.
Data plane role in classification
Data plane statistics provide counters showing how many times each rule is matched by traffic. These counters help administrators analyze rule effectiveness and optimize performance.
Control plane role in classification
The control plane is responsible for managing and configuring how data is forwarded through the network.
The following flowchart illustrates how packets from a WGB Ethernet port are classified and mapped to QoS rules based on existing profiles, Ethertype, port identifiers, and DSCP values.
Legacy QoS mapping behavior
Summary
Access points assign traffic priority by retrieving VLAN-based TCI values, applying a fixed priority of 6 for Profinet, and using DSCP-to-dot1p mapping for IP and IPv6 traffic.
Workflow
Access points determine traffic priority based on ethertype using the following rules:
- Retrieve TCI Priority: Access points retrieve the Tag Control Information (TCI) priority from the VLAN element for the specified ethertype 0x8100.
- Assign TCI Priority for Profinet: For ethertype 0x8892 (profinet), access points assign the TCI priority as 6.
- Set DSCP Priority for IP and IPv6: For ethertype 0x0800 (IP) and 0x86DD (IPv6), access points set the DSCP priority according to the default dscp2dot1p mapping table.
How Access Points assign QoS priorities
Summary
Access points assign QoS priorities based on protocol type and configured rules, with defaults applied for non-IP traffic or when no rules are set.
Workflow
Here's how the process of enabling QoS on access points works:
- The access point determines the priority for an ethertype QoS mapping of 0x8892 (profinet) based on the configuration setting.
- For ethertypes 0x0800 (IP) and 0x86DD (IPv6), the access point assigns priority according to mapping rules that consider either the port or DSCP:
- The access point checks the UDP/TCP port (or port range) rule.
- The access point checks the DSCP rule.
- The access point assigns a user priority value of 0 to packets that are not IPv4/IPv6.
- If no rule configuration is present, the QoS profile defaults to the legacy mapping behavior.
If 802.1p priority exists, it overrides any customised rule.
Configure QoS Mapping Profile
This procedure allows you to define the different classification rules for configuring WGB QoS mapping.
Procedure
| 1. | Use the config wgb qos-mapping profile-name enable command to enable the specified QoS mapping profile.
|
|
| 2. | Use the config wgb qos-mapping profile-name add ethtype hex hex-number priority priority command to add a mapping rule based on Ethernet type.
You can delete the rules based on ethernet type using the config wgb qos-mapping profile-name delete ethtype hex hex-number
|
|
| 3. | Use the config wgb qos-mapping profile-name add [srcport number | dstport number | range start-number ending-number ] priority priority command to add a mapping rule based on port ID or range.
You can delete rules based on port-id/range using the config wgb qos-mapping profile-name delete [srcport number | range start-number ending-number [dstport number | range start-number ending-number ]]
|
|
| 4. | Use the config wgb qos-mapping profile-name add dscp number priority priority command to add a mapping rule based on DSCP value.
You can delete a mapping rule based on DSCP value using the
config wgb qos-mapping profile-name delete dscp number priority priority command.
|
|
| 5. | Use the config wgb qos-mapping profile-name disable command to disable the specified QoS mapping profile.
When disabled, the profile is cleared from the datapath but retained in the WGB configuration file. If the profile does not exist, a warning is issued and no new profile is created. |
|
| 6. | (Optional) Use the config wgb qos-mapping profile-name delete command to delete the specified QoS mapping profile.
When deleted, the profile is removed from both the datapath and the WGB configuration. |
Verify Quality of Service Map
To verify the QoS mapping configuration on the Control Plane, run the show wgb qos-mapping .
Device# show wgb qos-mapping
Number of QoS Mapping Profiles: 2
====================================
Profile name : qos1
Profile status : active
Number of Rules: 8
Rules:
L4 srcport : 31000-31100, dstport : 6666-7777, priority : 7
L4 srcport : 23000, dstport : N/A, priority : 3
L4 srcport : N/A, dstport : 20000-20100, priority : 5
L4 srcport : N/A, dstport : 2222, priority : 2
L4 srcport : 12300-12500, dstport : N/A, priority : 6
IPv4/IPv6 dscp: 43, priority : 1
Ethernet type : 0x8892, priority : 0
L4 srcport : 8888, dstport : 9999, priority : 4
Profile name : qos2
Profile status : inactive
Number of Rules: 8
Rules:
L4 srcport : 31000-31100, dstport : 6666-7777, priority : 2
L4 srcport : 23000, dstport : N/A, priority : 6
L4 srcport : N/A, dstport : 20000-20100, priority : 4
L4 srcport : N/A, dstport : 2222, priority : 7
L4 srcport : 12300-12500, dstport : N/A, priority : 3
IPv4/IPv6 dscp: 43, priority : 0
Ethernet type : 0x8892, priority : 1
L4 srcport : 8888, dstport : 9999, priority : 5
To verify the WGB QoS mapping configuration on the Data Plane, run the show datapath qos-mapping rule .
Device# show datapath qos-mapping rule
Status: active
QoS Mapping entries
======= dscp mapping =======
Default dscp2dot1p Table Value:
[0]->0 [1]->0 [2]->0 [3]->0 [4]->0 [5]->0 [6]->0 [7]->0
[8]->1 [9]->1 [10]->1 [11]->1 [12]->1 [13]->1 [14]->1 [15]->1
[16]->2 [17]->2 [18]->2 [19]->2 [20]->2 [21]->2 [22]->2 [23]->2
[24]->3 [25]->3 [26]->3 [27]->3 [28]->3 [29]->3 [30]->3 [31]->3
[32]->4 [33]->4 [34]->4 [35]->4 [36]->4 [37]->4 [38]->4 [39]->4
[40]->5 [41]->5 [42]->5 [43]->5 [44]->5 [45]->5 [46]->5 [47]->5
[48]->6 [49]->6 [50]->6 [51]->6 [52]->6 [53]->6 [54]->6 [55]->6
[56]->7 [57]->7 [58]->7 [59]->7 [60]->7 [61]->7 [62]->7 [63]->7
active dscp2dot1p Table Value:
[0]->0 [1]->0 [2]->0 [3]->0 [4]->0 [5]->0 [6]->0 [7]->0
[8]->1 [9]->1 [10]->1 [11]->1 [12]->1 [13]->1 [14]->1 [15]->1
[16]->7 [17]->2 [18]->2 [19]->2 [20]->2 [21]->2 [22]->2 [23]->2
[24]->3 [25]->3 [26]->3 [27]->3 [28]->3 [29]->3 [30]->3 [31]->3
[32]->4 [33]->4 [34]->4 [35]->4 [36]->4 [37]->4 [38]->4 [39]->4
[40]->5 [41]->5 [42]->5 [43]->5 [44]->5 [45]->5 [46]->5 [47]->5
[48]->6 [49]->6 [50]->6 [51]->6 [52]->6 [53]->6 [54]->6 [55]->6
[56]->7 [57]->7 [58]->7 [59]->7 [60]->7 [61]->7 [62]->7 [63]->7
To verify the WGB QoS mapping statistics on Data Plane, run the show datapath qos-mapping statistics command.
Device# show datapath qos-mapping statistics
======= pkt stats per dscp-mapping rule =======
dscp up pkt_cnt
16 7 0
To clear the WGB QoS mapping statistics on Data Plane, run the clear datapath qos-mapping statistics command.
The command clears packet count statistics per rule on data-plane.
Packet Capture: TCP dump utilities
TCP dump utilities are network packet analyzers that perform the following functions:
-
Capture packets transmitted over network interfaces.
-
Display and save packet data for monitoring and troubleshooting.
-
Enable in-depth analysis of wired network traffic on WGBs.
The TCP Dump on WGB chapter provides information on how to enable TCP dump through the WGB wired interface on the Catalyst IW9167EH .
Packet Capture Modes and Capabilities
The WGB packet capture utility supports the following modes and behaviors:
-
Default: Displays captured packets with header in real time on the WGB terminal.
-
Verbose: Parses and prints real-time packets on the WGB terminal, displaying headers and data in hexadecimal format.
-
Capture: Captures packets to file storage instead of printing them in real time.
The TCP dump utility does not support the simultaneous capture of packets to storage and printing them on the WGB terminal.
In default or verbose mode, the WGB terminal can print a maximum of 1000 packet entries.
Every round of Packet Capture (PCAP) clears the existing PCAP file. Before any new PCAP session, transfer the current PCAP file to an external server to prevent it from being overwritten. PCAP stops automatically when the PCAP file reaches a size of 100 MB.
The utility supports various protocol filters for debugging, including:
-
Transmission Control Protocol, Internet Control Message Protocol (ICMP) and ICMPv6
-
Profinet with IP proto 0x8892
-
Address Resolution Protocol (ARP)
-
Internet Group Management Protocol (IGMP)
-
User Datagram Protocol
-
Dynamic Host Configuration Protocol (DHCP) with port 67 or port 68 and DHCPv6 with port 546 or port 547
-
Common Industrial Protocol (CIP) with TCP port 44818
-
Domain Name System (DNS) with port 53
-
Simple Network Management Protocol with port 161 or port 162
Filter expressions for a PCAP comprise at least one primitive, which consists of qualifiers followed by an identifier. The three kinds of qualifiers are:
-
Type: Specifies the type of the identifier (port, host, network, or range of ports).
-
Dir: Specifies the transfer direction of the packets.
-
Proto: Limits the capture to a specific protocol.
When constructing filter expressions, use logical operators AND, OR, and NOT, and use parentheses to group expressions to ensure correct interpretation.
Enable wired packet captures
This procedure enables packet capture (PCAP) on a WGB to monitor wired traffic. It allows you to capture packets by protocol (IP, TCP, UDP), apply verbose output for detailed analysis, save packet data to PCAP files, and use custom filters (including VLAN) to analyze specific traffic across native and non-native VLANs.
Procedure
| 1. | Enable PCAP using one of the options given here:
|
|||||||||
| 2. | To upload the packets to an external server, use the command given here: Use the copy pcap file-name.pcap0 {tftp| sftp}://server-ip [directory][file-name] command to upload the packets to an external server.
|
Disable wired packet captures
Procedure
| 1. | Use the no debug traffic wired [0-3]{ip| tcp| udp}[verbose| capture] command to disable PCAP with the default filter.
|
|
| 2. | Use the no debug traffic wired [0-3 ]filter expression [verbose| capture] command to disable PCAP with the custom filter.
|
Verify wired packet capture
-
To verify the debug status, use the show debug command.
Device#show debug traffic: wired tcp debugging is enabled -
To view the captured internal wired packets stored in the file, use the show pcap command.
After capturing packets to the file, use the show pcap command to view them.
Device#show pcap reading from file /pcap/APXXXX.XXXX.XXXX_capture.pcap0, link-type EN10MB (Ethernet) 1 00:00:00.000000 IP 0.0.0.0 > 224.0.0.1: igmp query v2 2 09:41:48.903670 IP 209.165.200.189 > 209.165.200.1: ICMP echo request, id 29920, seq 1, length 64 3 09:41:48.908927 IP 209.165.200.1 > 209.165.200.189: ICMP echo reply, id 29920, seq 1, length 64 4 09:41:49.904914 IP 209.165.200.102 > 209.165.200.1: ICMP echo request, id 29920, seq 2, length 64 5 09:41:49.909009 IP 209.165.200.1 > 209.165.200.102: ICMP echo reply, id 29920, seq 2, length 64 -
To filter and view the basic content of captured packets sequentially, run the show pcap [filter expression] command.
Device#show pcap filter "src 209.165.200.189” reading from file /pcap/APXXXX.XXXX.XXXX_capture.pcap0, link-type EN10MB (Ethernet) 1 09:41:48.903670 IP 209.165.200.189 > 209.165.200.1: ICMP echo request, id 29920, seq 1, length 64 2 09:41:48.908927 IP 209.165.200.1 > 209.165.200.189: ICMP echo reply, id 29920, seq 1, length 64 -
To filter and view the detailed content of a specific packet, run the show pcap [filter expression][detail no] command.
Device#show pcap filter "src 209.165.200.189" detail 2 2024-04-25 09:41:49.904914 000000 18 59 f5 96 af 74 00 50 56 85 8a 0a 08 00 45 00 000010 00 54 14 6c 40 00 40 01 b7 9d 64 16 53 72 64 16 000020 53 01 08 00 70 81 74 e0 00 02 d4 3e 2b 66 00 00 000030 00 00 50 24 04 00 00 00 00 00 10 11 12 13 14 15 000040 16 17 18 19 1a 1b 1c 1d 1e 1f 20 21 22 23 24 25 000050 26 27 28 29 2a 2b 2c 2d 2e 2f 30 31 32 33 34 35 000060 36 37
Port address translation
Port Address Translation (PAT), also known as Network Address and Port Translation (NAPT), is a network address translation method that:
-
translates multiple internal wired client private IP addresses and port numbers
-
to unique public IP addresses and port numbers
-
before sending packets to the external network.
A private IP address is used only within an internal network. A public IP address is globally unique and used on the Internet. NAPT mapping uses both the IP address and the port number. This allows packets from multiple internal hosts to map to the same external IP address with different port numbers.
From Release 17.16.1, PAT is supported on the IW9165E Workgroup Bridge (WGB) Access Points (APs) of each AGV.
From Release 26.1.1, you can use port numbers from 1 to 1024 on both TCP and UDP protocols, though these should be used with caution as they belong to the reserved category of ports; the valid port range is 1 to 65535.
NAPT operational details and limitations
NAPT supports TCP and UDP for communication between devices on the internal and external networks.
The following list outlines the limitations for WGB:
-
NAT is not supported for incoming packets with an 802.1Q VLAN tag behind the device.
-
Multicast traffic is not supported for NAT inside wired clients.
-
FTP traffic is supported in active mode; in passive mode, it is supported only when the FTP server is located within the NAT inside.
-
The TFTP protocol is supported only when the TFTP server resides inside the NAT.
-
Application Layer Gateway (ALG) is not supported.
The following list outlines the limitations for uWGB:
-
Access Control Lists (ACLs) are not supported.
-
The NAPT supports only one private LAN as the NAPT inside network.
Profinet clients on the AGV must be configured with a unique IP address that belongs to the global subnet.
This image illustrates the concept of Network Address Port Translation (NAPT), demonstrating how a Wireless Gateway Bridge (WGB) translates incoming packets from an external network to an internal host by mapping external IP addresses and ports to internal ones.
NAPT rules and mapping tables
A NAPT rule and mapping table is a network translation mechanism that:
-
defines how a Workgroup Bridge (WGB) translates internal private addresses and ports to an external, routable address and port,
-
maintains a table that maps internal device traffic to corresponding global IP/port pairs, and
-
supports both TCP and UDP protocols for address and port translation.
The configuration supports a maximum of 256 IP NAT rules on WGB.
NAPT mapping table
The mapping table is created and managed based on the traffic and NAPT rules.
NAPT uses entries containing the source IP address, source port number, protocol type, destination IP address, and destination port number (TCP or UDP). These entries enable the system to translate addresses, filter packets, and index the NAPT mapping table.
The maximum number of mapping entries in NAPT translation table is 4096.
This table shows an example of a NAPT mapping.
| Protocol |
Internal Local IP Address and Port |
WGB Global IP Address |
External Global IP Address and Port |
|---|---|---|---|
| TCP |
192.168.0.10: 80 |
172.16.100.11 |
172.16.100.11: 61080 |
Upstream and downstream data flows
Upstream and downstream data flows are types of network traffic flows that:
-
use Network Address and Port Translation (NAPT) to translate source or destination addresses,
-
allow secure transfer of data between internal and external networks, and
-
maintain privacy and integrity of IP addresses.
Downstream data flow using NAPT
Downstream data flow refers to the flow of data from the external network to the AGV's internal network. The gateway (WGB or uWGB) manages communication between the external and internal networks..
When packets arrive with an external IP address and port number, the mapping table is checked to identify the corresponding internal destination.
The packets are then translated and forwarded to the internal network based on the destination IP address and port number.
The diagram illustrates how address and port translation manages both upstream (internal-to-external) and downstream (external-to-internal) traffic flows between private LAN clients and external networks.
Upstream data flow using SNAT
Upstream data flow refers to the transfer of packets from internal networks to external networks. The gateway enables communication between the two networks.
All outgoing packets from the internal network are translated to the external network using Source Network Address Translation (SNAT).
For upstream traffic, SNAT replaces the source IP address and port numbers with the gateway’s IP address, ensuring that internal IP addresses are not exposed to the external network.
Configure NAPT on WGB
This procedure describes how to configure Source Network Address Translation (SNAT) for upstream data flow and Network Address and Port Translation (NAPT) for downstream data flow.
Complete Steps 1 to 3 to configure upstream data flow using SNAT.
Complete Steps 4 and 5 to configure downstream data flow using NAPT.
Procedure
| 1. | Use the configure ip nat enable command to enable NAPT.
Use the configure ip nat disable command to disable the NAPT. |
|
| 2. | Use the configure ip nat address add ip inside- ip-address netmask netmask command to configure inside IPv4 address and netmask.
|
|
| 3. | (Optional) Use the configure ip nat inside port range min-port-number max-port-number command to configure SNAT port range for upstream data flow.
The valid range for the port is 1 to 65535. This range must not overlap with the SNAT port range. By default, the minimum port value is 30000 and the maximum is 59999. The minimum configurable value for both ranges is 1. |
|
| 4. | Use the configure ip nat outside port range min-port-number max-port-number command to configure NAPT port range for downstream data flow.
The valid range for the port is 1 to 65535.
|
|
| 5. | Use the configure ip nat rule add inside ip inside-ip-address port inside-port-number outside port outside-port-number protocol { tcp| udp} command to configure the NAPT mapping rule for downstream data flow.
inside-ip-address is the internal wired client network IP address. inside-port-number is the internal wired client network TCP or UDP port number. Outside port number must be within the configured NAPT range. The valid range for the port is 1 to 65535. This range must not overlap with the NAPT port range. |
|
| 6. | (Optional) Use the show ip nat configuration command to view the current NAPT configuration.
|
|
| 7. | (Optional) Use the show ip nat tranlations command to view the current NAPT translation entries from the NAPT rule table.
In the output, 'forward' refers to the log details of data packets processed by the WGB, including the source, destination, and translation information. 'Reverse' refers to the log details of return traffic, ensuring that responses from the destination reach the original source by reversing the traffic direction. It ensures the response from the destination correctly reaches back to the source by reversing the direction of the original traffic. |
Manage uWGB in NAPT deployment
Follow this procedure to manage uWGB in a NAPT deployment.
Before you begin
Ensure that all uWGB wired clients are in the private LAN.
Procedure
| 1. | Use the configure dot11Radio 1 mode uwgb mac_address ssid-profile test_ssid command to configure radio mode to uWGB.
You can choose any unique MAC address, or use the optional method given below to calculate a unique MAC address.
To calculate the unique MAC address, add the offset value 0x12 to the base MAC address. To find the base MAC address, use the show controllers dot11Radio interface command, as shown in Step 2. Use the formula: base MAC address + offset = unique MAC address.
|
|
| 2. | (Optional) Use the show controllers dot11Radio 1 command to find the base MAC address.
|
|
| 3. | (Optional) Use the show wgb dot11 associations command to verify the uWGB is in the WGB state.
|
|
| 4. | Configure NAPT to enable end-to-end traffic flow for uWGB wired clients. |
Configure NAPT on uWGB
This procedure describes how to configure Source Network Address Translation (SNAT) for upstream data flow and Network Address and Port Translation (NAPT) for downstream data flow.
Follow Step 1 through Step 4 to configure support for upstream data flow using SNAT.
Follow Step 5 and Step 6 to to configure support for downstream data flow using NAPT.
Procedure
| 1. | Use the configure ip nat enable command to enable NAPT.
|
|
| 2. | (Optional) Use the configure ip nat inside port range min-port-number max-port-number command to configure SNAT port range for upstream data flow.
The valid range for the port is 1 to 65535. This range must not overlap with the SNAT port range. By default, the minimum port value is 30000 and the maximum is 59999. The minimum configurable value for both ranges is 1.
|
|
| 3. | Use the configure ip nat address add ip inside- ip-address netmask netmask command to configure the gateway IPv4 address for the internal wired client on the uWGB.
|
|
| 4. | Use the configure interface nat-outside address ipv4 static static-ip-address static-netmask gateway-ip-address command to configure external IPv4 address on the uWGB.
static-ip-address is the uWGB own public address gateway-ip-address is the uWGB external IP address. The outside port number is automatically generated for upstream data flow. The configuration supports the internal-to-external traffic flow. |
|
| 5. | Use the configure ip nat outside port range min-port-number max-port-number command to configure NAPT port range on the uWGB to receive traffic from the external network to the internal network.
The valid range for the port is 1 to 65535. This range must not overlap with the NAPT port range. The default minimum port value is 61000 and the maximum is 65535. The minimum configurable value for both ranges is 1. |
|
| 6. | Use the configure ip nat rule add inside ip inside-ip-address port inside-port-number outside port outside-port-number protocol { tcp| udp} command to configure the NAPT mapping rule for downstream data flow.
inside-ip-address is the internal wired client network IP address. inside-port-number is the internal wired client network TCP or UDP port number. Outside port number must be within the configured NAPT range. |
|
| 7. | (Optional) Use the show ip nat configuration command to view the current NAPT configuration.
|
|
| 8. | (Optional) Use the show ip nat tranlations command to view the current NAPT translation entries from the NAPT rule table.
In the output, 'forward' refers to the log details of data packets processed by the uWGB, including the source, destination, and translation information. 'Reverse' refers to the log details of return traffic, ensuring that responses from the destination reach the original source by reversing the traffic direction. It ensures the response from the destination correctly reaches back to the source by reversing the direction of the original traffic. |
Delete NAPT mapping rule
This procedure describes how to delete NAPT configuration entries. You can remove a specific NAPT mapping rule by specifying the inside and outside parameters. You can also delete a rule by its rule ID or clear all NAPT rules from the configuration. Choose the method based on whether you want to remove a specific rule or reset the entire NAPT configuration.
Procedure
Delete NAPT mapping rule using one of the options given here:
|
Delete NAPT IP address
This procedure explains how to delete the configured NAT IP addresses. You can remove the gateway IPv4 address assigned to the internal wired client. Alternatively, you can delete the external IPv4 address configured on the NAT outside interface.
To remove all the NAPT configuration, you should also delete the IP address and interface.
Procedure
Delete the NAPT IP address using one of the options given here:
|