Uplink Monitoring and Load Balancing
ArubaOS 8.5.0.0 and later versions do not support the uplink load balancing feature.
Wi-Fi Uplink
Starting from ArubaOS 8.5.0.0, Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink is introduced to provide connectivity of AP to an external wireless network. The 3G Third Generation of Wireless Mobile Telecommunications Technology. See W-CDMA./4G Fourth Generation of Wireless Mobile Telecommunications Technology. See LTE. cellular uplink and the Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink can be used to extend the connectivity to places where a wired uplink cannot be configured.
Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink allows an AP running ArubaOS to connect to an external wireless network or a managed device by using a third-party AP, such as a Mi-Fi device or a smart phone running a hotspot Hotspot refers to a WLAN node that provides Internet connection and virtual private network (VPN) access from a given location. A business traveler, for example, with a laptop equipped for Wi-Fi can look up a local hotspot, contact it, and get connected through its network to reach the Internet.. This requires the Aruba AP running ArubaOS to work as a standard Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. client. When the standard Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. client is used as an uplink, the AP requires MAC Media Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network. Address Translation (MAT) to bridge the traffic between wireless or wired users of the AP and the uplink network. Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink can also be used to connect the AP to another Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. service, such as a hospital wireless network.
It is recommended to use Aruba mesh between one uplink Aruba AP and another Aruba AP. Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink is used only when mesh is not suitable.
The ArubaOS AP must be provisioned with the necessary Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink client parameters. After the AP reboots, it works as a standard client with the provisioned client parameters and connects with a Mi-Fi device or another AP to reach the managed device. The provisioned AP acts as both client and AP when it receives configurations from the managed device, which allows other wireless and wired clients to connect to the Aruba AP.
- Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink is applicable to 802.11ax AP platforms and 802.11ac 802.11ac is a wireless networking standard in the 802.11 family that provides high-throughput WLANs on the 5 GHz band. wave2 AP platforms except 340 Series access points.
- Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink is not supported on 802.11ac 802.11ac is a wireless networking standard in the 802.11 family that provides high-throughput WLANs on the 5 GHz band. wave1 AP platforms, including AP-204, AP-205, 210 Series, 220 Series, and 270 Series access points.
- Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink is not supported on AP-555 in tri-radio mode.
|
|
The following sections describe how to configure a Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. Uplink profile and provision an AP with Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink:
Configuring a Wi-Fi Uplink Profile
The following configuration conditions apply to Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink:
- If the Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink is used on 2.4 GHz Gigahertz. or 5 GHz Gigahertz. band Band refers to a specified range of frequencies of electromagnetic radiation., mesh or cellular uplink is disabled. The two links are mutually exclusive.
- To bind or unbind the Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink on 2.4 GHz Gigahertz. or 5 GHz Gigahertz. band Band refers to a specified range of frequencies of electromagnetic radiation., reboot the AP.
- An AP provisioned with Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink client parameters can failover to wired uplink and vice-versa, depending on the priority specified for Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink and wired uplink. However, preemption is not allowed in this release.
The following procedure describes how to configure an AP with Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink profile:
- In the node hierarchy, navigate to the tab.
- Expand the accordion.
- Select .
- Select the Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink profile that you want to edit or click and enter a name into the dialog box to create a new profile.
You can create upto 16 Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink profiles with different priorities in an ap-group or ap-name.
- Configure the Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink profile settings described in Table 1.
When both WPA Wi-Fi Protected Access. WPA is an interoperable wireless security specification subset of the IEEE 802.11 standard. This standard provides authentication capabilities and uses TKIP for data encryption. Hexkey and WPA Wi-Fi Protected Access. WPA is an interoperable wireless security specification subset of the IEEE 802.11 standard. This standard provides authentication capabilities and uses TKIP for data encryption. Passphrase fields are configured, WPA Wi-Fi Protected Access. WPA is an interoperable wireless security specification subset of the IEEE 802.11 standard. This standard provides authentication capabilities and uses TKIP for data encryption. Hexkey takes precedence.
The following CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. commands configure an AP with a Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink profile:
(host)[mynode](config)# ap wifi-uplink-profile test-uplink
(host)[mynode](WiFi uplink profile "test-uplink")# essid uplink-new
(host)[mynode](WiFi uplink profile "test-uplink")# wpa-passphrase ********
(host)[mynode](WiFi uplink profile "test-uplink")# opmode personal
(host)[mynode](WiFi uplink profile "test-uplink")# exit
Provisioning an AP with Wi-Fi Uplink
The following procedure describes how to provision an Aruba AP with the Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink:
- In a node hierarchy, navigate to .
- In the Campus APs tab, select the new AP from the list, then click .
- In the AP provisioning section, click the drop-down list and select the AP group to which the Aruba AP should be assigned.
- In , select if you want to provide the AP with its managed device IP address, or select to manually define the managed device IP for that AP. If you select the option, you are prompted to enter the managed device's DNS Domain Name System. A DNS server functions as a phone book for the intranet and Internet users. It converts human-readable computer host names into IP addresses and IP addresses into host names. It stores several records for a domain name such as an address 'A' record, name server (NS), and mail exchanger (MX) records. The Address 'A' record is the most important record that is stored in a DNS server, because it provides the required IP address for a network peripheral or element. name or IP address.
- In , select if you have configured a DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. server to provide the AP with
the AP IP address, or select to manually define the AP IP address.
If you select the option, you are prompted to enter the following
information for the selected AP:
- IPv4 address, netmask Netmask is a 32-bit mask used for segregating IP address into subnets. Netmask defines the class and range of IP addresses., internet gateway Gateway is a network node that allows traffic to flow in and out of the network. used by the AP, and DNS Domain Name System. A DNS server functions as a phone book for the intranet and Internet users. It converts human-readable computer host names into IP addresses and IP addresses into host names. It stores several records for a domain name such as an address 'A' record, name server (NS), and mail exchanger (MX) records. The Address 'A' record is the most important record that is stored in a DNS server, because it provides the required IP address for a network peripheral or element. server.
- IPv6 address, netmask Netmask is a 32-bit mask used for segregating IP address into subnets. Netmask defines the class and range of IP addresses., internet gateway Gateway is a network node that allows traffic to flow in and out of the network. used by the AP, and DNS Domain Name System. A DNS server functions as a phone book for the intranet and Internet users. It converts human-readable computer host names into IP addresses and IP addresses into host names. It stores several records for a domain name such as an address 'A' record, name server (NS), and mail exchanger (MX) records. The Address 'A' record is the most important record that is stored in a DNS server, because it provides the required IP address for a network peripheral or element. server.
- Select the check box to enable Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink on the AP.
When Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink is enabled, at least one Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink profile must be added to the AP group.
- Click .
- Click .
- In the window, select the check box and click to re-provision the AP.
|
|
You must re-provision the AP to enable Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink profile on the AP. Re-provisioning the AP causes it to automatically reboot. The following animation displays how to provision an Aruba AP with Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. Uplink when you manually define the managed device IP for the AP in the WebUI:
|
The following CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. commands configure the Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink profile in the AP group:
(host)[mynode](config)# ap-group wfu-test
Warning: WiFi uplink profile will not take effect until an AP is reprovisioned
(host)[mynode](AP group "wfu-test")# wifi-uplink-profile test-uplink priority 1
The following CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. commands provision the AP with Wi-Fi Wi-Fi is a technology that allows electronic devices to connect to a WLAN network, mainly using the 2.4 GHz and 5 GHz radio bands. Wi-Fi can apply to products that use any 802.11 standard. uplink profile:
(host)[mynode](config)# provision-ap
(host)[mynode](config-submode)# read-bootinfo ip-addr 192.168.244.2
(host)[mynode](config-submode)# link-priority-wifi 10
(host)[mynode](config-submode)# ap-group wfu-test
(host)[mynode](config-submode)# wifi-uplink
(host)[mynode](config-submode)# reprovision ip-addr 192.168.244.2
Uplink Load Balancing
WAN Wide Area Network. WAN is a telecommunications network or computer network that extends over a large geographical distance. traffic can be balanced across two or more active uplinks from a managed device to a VPN Virtual Private Network. VPN enables secure access to a corporate network when located remotely. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network, while benefiting from the functionality, security, and management policies of the private network. This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two. concentrator. The uplink load balancing feature supports both active and standby uplinks, so the traffic load is balanced across two wired uplinks, while the backup cellular uplink remains idle.
When a managed device has multiple active uplinks, uplink load balancing can modify the IKE Internet Key Exchange. IKE is a key management protocol used with IPsec protocol to establish a secure communication channel. IKE provides additional feature, flexibility, and ease of configuration for IPsec standard. parameters for the managed device to create multiple managed device/VPN Virtual Private Network. VPN enables secure access to a corporate network when located remotely. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network, while benefiting from the functionality, security, and management policies of the private network. This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two. concentrator IPsec Internet Protocol security. IPsec is a protocol suite for secure IP communications that authenticates and encrypts each IP packet in a communication session. tunnels, one on each uplink. Once multiple uplinks and IPsec Internet Protocol security. IPsec is a protocol suite for secure IP communications that authenticates and encrypts each IP packet in a communication session. tunnels are up, Layer-3 traffic can be load-balanced across these uplinks using specially created internal routing ACLs Access Control List. ACL is a common way of restricting certain types of traffic on a physical port. and nexthop lists.
Load Balancing ACLs
When uplink load balancing is enabled, any Layer-3 traffic session that is not associated to a manually defined routing ACL Access Control List. ACL is a common way of restricting certain types of traffic on a physical port. will be managed by two specially created, internal ACLs Access Control List. ACL is a common way of restricting certain types of traffic on a physical port. placed at the bottom of the routing ACL Access Control List. ACL is a common way of restricting certain types of traffic on a physical port. table; the editable ACL Access Control List. ACL is a common way of restricting certain types of traffic on a physical port. , followed by the non-editable ACL Access Control List. ACL is a common way of restricting certain types of traffic on a physical port. .
Load Balancing Nexthop Lists
The uplink load balancing feature uses three special internally created nexthop lists:
is used for load-balancing internet-bound traffic, and for managing encrypted traffic headed to the corporate headquarters. These nexthop lists include information about one nexthop gateway Gateway is a network node that allows traffic to flow in and out of the network. and one managed device / VPN Virtual Private Network. VPN enables secure access to a corporate network when located remotely. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network, while benefiting from the functionality, security, and management policies of the private network. This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two. concentrator IPsec Internet Protocol security. IPsec is a protocol suite for secure IP communications that authenticates and encrypts each IP packet in a communication session. tunnel for each uplink, which are added to these lists so all nexthops are considered active and are available for routing.
The third nexthop list created by this feature is , which is created by the load balancing feature, and used by uplinks in active-standby mode to send control plane traffic from the managed device to the VPN Virtual Private Network. VPN enables secure access to a corporate network when located remotely. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network, while benefiting from the functionality, security, and management policies of the private network. This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two. concentrator.
Configuring the Uplink Manager
The following procedure describes how to disable or enable the uplink manager, and manage priorities for the wired and cellular connections. The uplink managed is enabled by default on managed device uplinks.
- In the node hierarchy, navigate to the tab
- Expand the accordion.
- Select the check-box to enable WAN Wide Area Network. WAN is a telecommunications network or computer network that extends over a large geographical distance. compression .
- Select one of the following options from drop-down list.
- : Hash-based load balancing uses information from the packets being sent (for example, the source IP address, destination IP address, protocol and port numbers to determine how to load balance that traffic).
- : Traffic is equally distributed to all the active uplinks.
- : Traffic is balanced between the uplinks based upon the number of sessions managed by each link, so that the load for each active uplink stays within 5% of the other active uplinks.
- Click in the table and enter the following values to define a uplink VLAN Virtual Local Area Network. In computer networking, a single Layer 2 network may be partitioned to create multiple distinct broadcast domains, which are mutually isolated so that packets can only pass between them through one or more routers; such a domain is referred to as a Virtual Local Area Network, Virtual LAN, or VLAN. for an uplink interface on the managed device.
- : Name of the uplink.
- : Type of the uplink. The options are MPLS Multiprotocol Label Switching. The MPLS protocol speeds up and shapes network traffic flows. , INET, LTE Long Term Evolution. LTE is a 4G wireless communication standard that provides high-speed wireless communication for mobile phones and data terminals. See 4G. and Metro-Ethernet Ethernet is a network protocol for data transmission over LAN.
- : VLAN Virtual Local Area Network. In computer networking, a single Layer 2 network may be partitioned to create multiple distinct broadcast domains, which are mutually isolated so that packets can only pass between them through one or more routers; such a domain is referred to as a Virtual Local Area Network, Virtual LAN, or VLAN. ID number
- Select this check-box to disable or re-enable the VLAN Virtual Local Area Network. In computer networking, a single Layer 2 network may be partitioned to create multiple distinct broadcast domains, which are mutually isolated so that packets can only pass between them through one or more routers; such a domain is referred to as a Virtual Local Area Network, Virtual LAN, or VLAN..
- : Select this check-box to use this uplink only as a backup link.
- : If the uplink is using load balancing in mode, this value defines the weight given to the uplink in an active/active uplink scenario. An uplink with a higher weight will be assigned more session traffic than an uplink with a lower weight. The supported range of values is 1-100.
- Click Submit.
- Click .
- In the window, select the check box and click .
The following examples configure an uplink load-balancing solution using the Mobility Master command-line interface.
If a managed device terminates a secure tunnel on a VPN Virtual Private Network. VPN enables secure access to a corporate network when located remotely. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network, while benefiting from the functionality, security, and management policies of the private network. This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two. concentrator, you can issue the command on the VPN Virtual Private Network. VPN enables secure access to a corporate network when located remotely. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network, while benefiting from the functionality, security, and management policies of the private network. This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two. concentrator configuration to enable load balancing on secure uplinks between the VPN Virtual Private Network. VPN enables secure access to a corporate network when located remotely. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network, while benefiting from the functionality, security, and management policies of the private network. This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two. concentrator and a managed device.
The following CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. example enables uplinks between a managed device with the MAC Media Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network. address 01:00:5E:00:00:FF and a VPN Virtual Private Network. VPN enables secure access to a corporate network when located remotely. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network, while benefiting from the functionality, security, and management policies of the private network. This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two. concentrator, this automatically enables load balancing:
(host)[node](config) #vpn-peer peer-mac 01:00:5E:00:00:FF cert-auth factory-cert
.If the peer device is an x86 smanaged device. However, then configure the MAC Media Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network. address of the management interface of the However, if the peer device is a hardware platform, you must provide the MAC Media Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network. address of the VLAN Virtual Local Area Network. In computer networking, a single Layer 2 network may be partitioned to create multiple distinct broadcast domains, which are mutually isolated so that packets can only pass between them through one or more routers; such a domain is referred to as a Virtual Local Area Network, Virtual LAN, or VLAN. interface of the managed device
Step 2: Configure Wired and Cellular Uplinks
The following CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. commands configure the wired and cellular uplinks in the uplink manager:
(host) [node] (config) #uplink cellular uplink-id
(host) [node] (config) #uplink wired vlan
The uplink manager and load-balancing settings are enabled automatically when you configure the cellular or wired uplinks.
The following CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. commands configure additional uplink load-balancing settings.
(host) [node] (config) #uplink load-balance ?
mode Configure load-balancing mode
threshold-limits Set threshold limits for load balancing