BRKNMS 2847 PDF
BRKNMS 2847 PDF
BRKNMS 2847 PDF
Cisco Public
Wireless Troubleshooting with Cisco
Prime Infrastructure
Ian Procyk - Consulting Systems Engineer
Paul Lysander - Technical Marketing Engineer
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public
Agenda
• Introduction
• Understanding Prime and its role in troubleshooting
• Authentication issues
• Weak Signals
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Introduction
Working issues over the years with the UBC wireless team
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Introduction
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Introduction
Understanding Where Prime Fits In The Network
Cisco Identity
Services Engine Cisco Prime
(ISE)
Infrastructure
API
Cisco
Cisco Wireless LAN NMSP over SSL Mobility Services
Controller (WLC) Engine (MSE)
Access
Points
Active Wireless
RFID Tag Client
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Introduction
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Introduction
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Introduction
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Introduction
• Prior
to 3.1 background task polling was a serial
process subject to thread locks. If something was
misbehaving in your environment, it was possible for
Prime to become delayed or wedged in a
background task. The result depending on the fault,
could be very stale data…
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Introduction
• Client
traps are disable by default
on WLCs
• Ata minimum it would be
beneficial to turn on client traps
for association, dissociation and
deauthentication
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Introduction
enhanced-802.11-associate
Enable Sending Dot11 Enhanced Association Trap for Clients
enhanced-802.11-deauthenticate
Enable Sending Dot11 Enhanced Deauthentication Trap for Clients
enhanced-802.11-stats Enable
Sending Enhanced Stats Trap for Clients
enhanced-authentication Enable
Sending Enhanced Authentication Success Trap for Clients
*enhanced client traps will have an impact on your WLC control plane
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Introduction
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Introduction
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Commonly Used
Components of Prime
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Components of Prime
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Components of Prime
• client count
• associated vs. authenticated
• Syslog summary
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Components of Prime
Dashlet Customization
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Components of Prime
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Components of Prime
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Components of Prime
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Components of Prime
Useful metrics
added as
columns:
SSID
Traffic
RSSI
SNR
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Components of Prime
• Client sessions
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Components of Prime
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Components of Prime
• Coverage gaps
• Client balance
• Channel / TX Power
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Components of Prime
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Looking @ The Infrastructure
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
HOW HEALTHY IS MY WI-FI?
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Infrastructure Health
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Infrastructure Health
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
Infrastructure Health
AP Performance
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Infrastructure Health
AP Performance
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Infrastructure Health
AP Performance
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
Infrastructure Health
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Infrastructure Health
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Infrastructure Health
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Infrastructure Health
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Infrastructure Health
RRM Dashboard
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Infrastructure Health
RRM Dashboard
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Infrastructure Health
Band Select
effectiveness
5GHz adoption
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Infrastructure Health
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Infrastructure Health
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Infrastructure Health
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Infrastructure Health
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Troubleshooting Common
Complaints
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Client Troubleshooting
• Check Prime, search for user – where are they? What is their connection
status? Link status? Do I have a down AP in that area?
• You see that they have multiple devices – WLC http profiling allows you to see
the type of other devices
• You can confirm via the heatmaps and currently connected clients list that
there are other users on the same AP the boss is having trouble with…
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Client Troubleshooting
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Client Troubleshooting
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Client Troubleshooting
Checking to see if there are any other events taking place on the AP recently
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Client Troubleshooting
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Client Troubleshooting
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Client Troubleshooting
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
“The Network Is Down…”
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Client Troubleshooting
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Client Troubleshooting
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Client Troubleshooting
Device is
dual band
capable, but
why is it on
2.4GHz?
What’s the
RSSI?
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Client Troubleshooting
Looking at the
Apple TV over
a few week
window.
Its RSSI/SNR
look to be mostly
in the normal
range.
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
Client Troubleshooting
The Apple TV
box is currently
Connected to
Channel #1
Signal is strong
But there is
Interference
from a piconet
network with
high duty cycle…
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
Client Troubleshooting
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
Client Troubleshooting
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
BRKNMS-2847
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
Client Troubleshooting
• What is the channel mix? Do the scanners support DFS, CH# 165?
• Depending on floor plan RRM might have turned AP power levels down too far
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Client Troubleshooting
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Client Troubleshooting
Notice the
level of
Signal
propagation
between
racks…
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Client Troubleshooting
In this area
there is high
isolation
between
AP’s
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
Client Troubleshooting
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Client Troubleshooting
On site performance
validation with 7925
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Additional Tools
For your consideration
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
InterMapper Core Network Analysis
• Graph and chart any
variable you can…
• Controller CPU
• ICMP response time
• Interface utilization
• DHCP scope utilization
• AP count per WLC
• FW drop counters
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
InterMapper – DHCP Scope Utilization
• Large number of guest
or transient / mobile
users?
• Importantto keep an
eye out for DHCP
scope exhaustion
• Ensurethat DHCP
pools have roughly
equal balance
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
InterMapper – RADIUS Request Rate
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
InterMapper – RADIUS Auth vs. Reject
• Keeping an eye on
RADIUS server
reject/accept rate
can provide insight
into new
supplicant issues
• Spot a accidental
misconfiguration
or problem with
directory store or
auth policy
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Elastic Search + Logstash + Kibana
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Elastic Search + Logstash + Kibana
• Graphical
representation of
authentication and
accounting logs
• Filter
per anything:
username
MAC addr
WLC
SSID
RADIUS instance
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
Hand Held Wi-Fi Analyzers
• An example would be Fluke’s Air Check
• Yes, it’s another device to carry
• Yes, it’s expensive
• It’s
the fastest way to listen to CCX advertisements from Cisco APs, showing
you client load status and other important information a lot of other tools miss
out. Great for validating antenna and coax connections are working as
expected.
• It’s a calibrated device
• Use external directional antenna for faster direction finding
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
Wi-Fi Signal Checks – OSX
OSX: Wi-Fi Signal app – Sits in your menu bar
<-Wi-Fi Signal
option+click->
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Wi-Fi Signal Checks – OSX
• OSX: Wi-Fi Explorer App
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
Wi-Fi Signal Checks – PC
• PC with Intel Pro/Wireless chip: Intel’s advanced statistics tool that’s bundled
with pro/wireless drivers. PS: Always get latest software & driver package
directly from Intel’s website)
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
Wi-Fi Signal Checks – PC
• Another tool to consider is Metageek’s inSSIDer.
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Wi-Fi Signal Checks – Android
• Wi-Fi Analyzer
• As always your device and
its antenna, and the
position of your hand
will impact signal strength
readings.
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
Wi-Fi Packet Capture
• Sometimes you need to run over the air packet captures to sniff out problems and or provide
data to TAC. When you find yourself in this situation you have two choices…
Option 1:
Convert a deployed AP into Sniffer mode. This will put the AP into RX only mode, with it sending
what it hears back to the WLC and then over to Omnipeek using Omnipeek’s Cisco remote
adapter. This is not a cheap solution, and requires that you buy Omnipeek. Unless you install a
dedicated sniffer AP you also have a compromise in coverage while the existing AP is in sniffer
mode.
However, it is the best way to capture and record the RF domain for days/weeks on end. Very
useful if you have a significant long term problem. Also one of the best ways to capture roaming
in a multi-channel environment (several sniffers running at once)
https://supportforums.cisco.com/document/75236/collecting-wireless-sniffer-trace-using-cisco-lightweight-ap-sniffer-mode
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Wi-Fi Packet Capture
Option 2:
You go into the field with a portable packet capture alternative.
For 802.11ac you might be best served with MacBook running its wireless NIC in sniffer mode
(available via wireless diagnostics).
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
Wi-Fi Packet Capture
If you are using a PC, then I typically resort to AirPcap with Wireshark. As of July 2015 there
doesn’t appear to be an 802.11ac compliant AirPcap card out yet.
Note that Microsoft’s Network Monitor software gives hit/miss access to your Wireless NIC. You
may have limited success trying to do a wireless packet capture using this software and your
internal laptop NIC.
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 88
Spectrum Analysis
• If you suspect interference then the only way to look for it is to use a spectrum analyzer
• Cisco APs with clean air have a high resolution spectrum analyzer built in and can be used for
free with Cisco’s Spectrum Expert remote software (shown to the right). If you want a more
modern user interface Metageek’s Channalyzer software (shown below) can receive spectrum
analyzer data streams from Cisco APs.
• A more portable USB based spectrum analysis
option is the WiSpy DBX, also by Metageek
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
Offline Channel Analysis
• Tools
like Omnipeek and Wireshark are incredibly
powerful analysis tools
• However, visualization of a over-the-air packet
capture is really cool with Metageek’s Eye PA
software
• Withthis software its very easy to identify top
talkers, or stations with very slow data rates that are
monopolizing a cell
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
Poor Mans Faraday Cage…
• Looking for a way to test a client
in isolation in a busy RF area?
• Wantto test roaming without
moving?
• Solution:
A broken (non functional)
microwave…
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
ANY QUESTIONS?
BRKNMS-2847 © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
Complete Your Online Session Evaluation
• Give us your feedback to be
entered into a Daily Survey
Drawing. A daily winner will
receive a $750 Amazon gift card.
• Complete your session surveys
through the Cisco Live mobile
app or from the Session Catalog
on CiscoLive.com/us.
Presentation ID © 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 93
Thank you
Presentation ID
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public
9
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public