wifi_channels.xlsx wlc_cli_commands.xlsx

* BSSID ( Basic Service Set Identifier ): MAC physical address of the AP or wireless router that is used to connect to the WiFi

WIFI TROUBLESHOOTING

  1. Maximum power - wifi > radio settings
  2. Channel width: 20/40MHz
    1. More width means more noise (i'm listening to wider channel) but better throughput
    2. Less width means more stable but 54mb max
  3. 2.4GHz 5GHz - wifi > conf > access ctrl
  4. Enabling Band Steering: Configure > Access control > Wireless options
  5. Exclude DFS channels (see explanation below) External Link
    1. DFS 'events' are radar interference events (from weather radar frequencies)
  6. Check the following tools while the event happens or starting likely sources of interference like microwave ovens:

Channel_Utilization_Live_Tool - 4g: usually 4,6,11,14 (22MHz width) 4g-chann – 5G: ch 36-64

WIFI TYPES:

GI: Guard Interval . intended to avoid signal loss from multipath effect. Short GI (~400ns)

MCS Type 802.11 Mode Description
Legacy 802.11a/b/g No MCS index. Uses fixed data rates (e.g., 6, 9, 12, 18, 24, 36, 48, 54 Mbps).
HT-MCS 802.11n (HT) High Throughput (HT). Supports MCS 0 to 31 (depending on spatial streams).
VHT-MCS 802.11ac (VHT) Very High Throughput (VHT). Supports MCS 0 to 9 (per spatial stream).
HE-MCS 802.11ax (HE) High Efficiency (HE). Supports MCS 0 to 11 (per spatial stream).
Parameter Description
MCS Type HT-MCS (802.11n), VHT-MCS (802.11ac), HE-MCS (802.11ax).
Channel Width 20 MHz, 40 MHz, 80 MHz, 160 MHz.
Spatial Streams Number of spatial streams (NSS): 1 to 8 (depending on the standard).
Guard Interval Short GI (400 ns) or Long GI (800 ns).

dB and dBm


PROBE AND BEACON FRAMES

DFS EVENTS:

WMM (WIFI Multimedia, wireless QoS) LINK

  1. 802.1P. Works by tweaking the Interframe Space (IFS) and Random Backoff Timer

Event-Driven RRM. EDRRM allows an access point in distress to bypass normal RRM intervals and immediately change channels.


CLIENT WIFI ANALYSIS

iwlist wlp2s0 scan

Then to infer the mode we are : Link1


REST-API: Use postman.
To ADD a static route:

curl -L -H 'X-Cisco-Meraki-API-Key: <my Key>' -H 'Content-Type: application/json' -X POST --data-binary '{"name":"test-route2","subnet":"99.99.98.0/24","gatewayIp":"10.5.0.99", "enabled": false}' 'https://dashboard.meraki.com/api/v0/networks/L_644577696667403593/staticRoutes'

To DELETE a static route:

curl -L -H 'X-Cisco-Meraki-API-Key: <my Key>' -X DELETE -H 'Content-Type: application/json' 'https://dashboard.meraki.com/api/v0/network/L_644577696667403593/staticRoutes/51a49428-b4f3-46d2-9b8b-3d5e719fbd59'

SNMP
For one network

Network-wide > General > SNMP

For the whole organization:

Organization > Settings > SNMP

BLUETOOTH:

Featured snippet from the web Bluetooth utilizes frequency-hopping spread spectrum technology to avoid interference problems. The ISM 2.4 GHz band is 2400 to 2483.5 MHz, and Bluetooth uses 79 radio frequency channels in this band, starting at 2402 MHz and continuing every 1 MHz

MAIN CISCO WIFI LINE

AIREOS

IOS-XE WLC


MERAKI SECTION
CONFIGURE WIFI (quick and dirty):

  1. Claim AP device in inventory with its SN ('claim' link)
  2. Wireless > Configure > SSIDs . Set new SSID
  3. Wireless > Configure > Access Control . For the SSID.

CLIENT VPN TROUBLESHOOTING:

TROUBLESHOOTING

  1. Packet capture: note that we can capture in all the devices not just in the security appliance. In the packet capture page there's a transparent dropdown menu right to the 'Packet capture' heading
  2. To search for power cycles, check its consequences, for instance, an AP reboot will be seen in the port it is connected to flapping.
  3. To schedule upgrades, check this Link.
  4. HA a MX cluster might look GREEN and right but be careful, if, for whatever reason, vrrp is not working fine both of them will show as ACTIVE in the console and the vpn tunnel will flap no stop. Recommended albeit not documented is not to connect them back to back but via a lan firewall.

TOPOLOGY INFO:

Switch > Monitor-Switches > (Select a switch) > Topology

To see where the LAN interfaces are connection to (besides Topology option):

Network > Monitor > packet capture # not really what is connected to, just what is being learnt

Connect to the local console:

Sec. appl > Addressing & VLANs > MX IP

LICENSING ADDING DEVICE

  1. Claim the device with the serial number (or with the order number in the shipping email)
    1. licence email has subject “Your Meraki order has shipped -” sender: ship-notification@meraki.com
  2. Add the license. Note that license doesn't need to be bound to the device

PROCEDURE TO BUILD A RACK OF MS SWITCHES
MX NAT warm-spare deployment VRRP heartbeats are sent across the LAN interfaces=on each VLAN every second. If no VRRP keepalives are heard by the secondary MX=on any VLAN after three seconds, the dead timer will expire triggering a failover event. https://www.willette.works/mx-warm-spare/

PROCEDURE TO BUILD A RACK OF MS SWITCHES

  1. Shut down all the switches
  2. Connect 1 uplink from the MX to a dumb switch and each of the other 5 ports in the dumb switch to each of the MS meraki switches.
  3. Wait for the MS to cope up fully online (connected to meraki cloud white light)
  4. Shut down all the MS
  5. Configure the stack in the dashboard.
  6. Connect the stack cable (typical daisy chain)
  7. Do not remove the dumb switch based uplinks and Power on the all MS switches (keep the dumb switch with the uplink to the MX and the 5 patches to each of the MS)
  8. Once the MS download the configuration from Meraki cloud, all switches except one (master) will block their uplink ports.
  9. At this point, we can remove the dump switch and leave connected as an uplink the port that was not blocked (MS to MX)

PROCEDURE TO REPLACE SWITCH MEMBER

  1. Connect dumb switch between internet and stack. Check everything online.
  2. Power off new member
  3. Claim new-member in GUI
  4. Add new-member Network. Not to the stack yet.
  5. Power on and connect new-switch to another port of the dumb swicth, so it has internet access.
  6. Wait until new-switch is detected, updated and upgraded. Final state will be solid white light.
  7. Power off new-switch
  8. Clone configuration from old switch to new switch
    1. Switch > switch stacks > select stack > clone and replace m.
    2. Power off old-switch, new switch still off.
    3. If you have static dhcp assigment, change it now.
    4. Once done, we swap stack switch cables from old to new

if one of the switches not coming up in ther stack:
- disconnect the stack cables. - power it off - remove it from the stack logically - connect it to internet (separatelly)

PROCEDURE TO REPLACE STANDALONE SWITCH

  1. Claim switch
  2. Add it to the network
  3. Select new swicth
  4. Choose clone and select as source the old switch
  5. Select everything.
  6. Replace physically the switch

LOG ANALYSIS

MERAKI MX UPLINK OPTIONS:

LINKS OF INTEREST

Authentication

uses a Remote Authentication Dial-In User Service (RADIUS) server to authenticate devices, while WPA Personal uses a single password for all devices.