cancel
Showing results for 
Search instead for 
Did you mean: 

MeshConnex | Smart-RF | AP460e | NX5500 | Weak singal on 5GHX MCX mapped Radio | Non-Root to Non-Root optimal path not forming.

MeshConnex | Smart-RF | AP460e | NX5500 | Weak singal on 5GHX MCX mapped Radio | Non-Root to Non-Root optimal path not forming.

s88791459
New Contributor

I am trying to configure AP460e to form mesh using MESHCONNEX. I have created the following root profile. I want the APs to be set initially as root and only on uplink failure state, become non root and connect to nearby root.

All AP460e-s are connected to the central NX5500 controller via Backhaul.
Some APs are connected in linear chain, for eg AP-1 to AP-2 to AP-3 to AP-4. AP-4 is connected to NX5500 via Backhaul.
Distance between AP to AP is around 400-1200Mtrs.

I was observing weak signal from 2.4Ghz radio. I had changed the SMART-RF sensitivity to High and set custom DATA-RATES in APs. Which seems to have fixed the weak signal Issue from 2.4Ghz.

Now, I am facing issue with 5Ghz radio. Not getting good coverage.

4 8Dbi dual mode antennas are installed to 5GHz radio antenna ports. And two Single Band 8Dbi antenna are installed on the 2Ghz radio antenna port.

Can you please suggest what I can add or modify to increase the signal on 5Ghz radios? What Can I do to get the following:
1. Fast Roaming of Vehicles moving inside the Covered Zone.
2. Proper Meshing. Root AP should become non root in case backhaul fails and connects to nearby APs.

Here is the entire config from the NX5500:

login as: admin
admin@10.40.8.4's password:
NX5500>ena
NX5500#ping 10.40.8.92
PING 10.40.8.92 (10.40.8.92) 100(128) bytes of data.
108 bytes from 10.40.8.92: icmp_seq=1 ttl=64 time=71.5 ms
108 bytes from 10.40.8.92: icmp_seq=2 ttl=64 time=113 ms
108 bytes from 10.40.8.92: icmp_seq=3 ttl=64 time=9.18 ms
^C
--- 10.40.8.92 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2002ms
rtt min/avg/max/mdev = 9.184/64.911/113.981/43.042 ms
NX5500#show wire mesh tre
In progress .....................
1:MCX [21 MPs(17 roots, 4 bound)]
|-AP-85
| |-AP-89
| |-AP-72
| |-AP-66
| |-AP-92
|-AP-84
|-AP-77
|-AP-88
|-AP-63
|-AP-75
|-AP-64
|-AP-71
|-AP-60
|-AP-86
|-AP-61
|-AP-81
|-AP-68
|-AP-76
|-AP-95
|-AP-70
|-AP-79

Total number of meshes displayed: 1
NX5500#
NX5500#show run
!
! Configuration of NX5500 version 7.7.1.1-005R
!
!
version 2.7
!
!
client-identity-group default
load default-fingerprints
!
ip access-list BROADCAST-MULTICAST-CONTROL
permit icmp any any rule-precedence 9
permit tcp any any rule-precedence 10 rule-description "permit all TCP traffic"
permit udp any eq 67 any eq dhcpc rule-precedence 11 rule-description "permit DHCP replies"
deny udp any range 137 138 any range 137 138 rule-precedence 20 rule-description "deny windows netbios"
deny ip any 224.0.0.0/4 rule-precedence 21 rule-description "deny IP multicast"
deny ip any host 255.255.255.255 rule-precedence 22 rule-description "deny IP local broadcast"
permit ip any any rule-precedence 100 rule-description "permit all IP traffic"
!
mac access-list PERMIT-ARP-AND-IPv4
permit any any type ip rule-precedence 10 rule-description "permit all IPv4 traffic"
permit any any type arp rule-precedence 20 rule-description "permit all ARP traffic"
!
ip snmp-access-list default
permit any
!
firewall-policy default
no ip dos smurf
no ip dos twinge
no ip dos invalid-protocol
no ip dos router-advt
no ip dos router-solicit
no ip dos option-route
no ip dos ascend
no ip dos chargen
no ip dos fraggle
no ip dos snork
no ip dos ftp-bounce
no ip dos tcp-intercept
no ip dos broadcast-multicast-icmp
no ip dos land
no ip dos tcp-xmas-scan
no ip dos tcp-null-scan
no ip dos winnuke
no ip dos tcp-fin-scan
no ip dos udp-short-hdr
no ip dos tcp-post-syn
no ip dos tcphdrfrag
no ip dos ip-ttl-zero
no ip dos ipspoof
no ip dos tcp-bad-sequence
no ip dos tcp-sequence-past-window
no ip-mac conflict
no ip-mac routing conflict
dhcp-offer-convert
no stateful-packet-inspection-l2
alg sip
alg facetime
alg sccp
logging icmp-packet-drop all
logging malformed-packet-drop all
logging verbose
ip tcp adjust-mss 1400
!
!
mint-policy global-default
!
meshpoint-qos-policy default
accelerated-multicast autodetect classification best-effort
!
wlan-qos-policy default
qos trust dscp
qos trust wmm
!
radio-qos-policy default
admission-control best-effort
admission-control best-effort max-clients 256
admission-control best-effort max-roamed-clients 256
admission-control best-effort reserved-for-roam-percent 150
admission-control background
admission-control background max-clients 256
admission-control background max-roamed-clients 256
admission-control background reserved-for-roam-percent 150
accelerated-multicast max-streams 45
smart-aggregation
!
wlan RED_EYE
ssid RED_EYE
vlan 1
bridging-mode local
encryption-type none
authentication-type none
wireless-client inactivity-timeout 60
wing-extensions move-command
wing-extensions smart-scan
wing-extensions wmm-load-information
client-load-balancing
wireless-client count-per-radio 50
ip arp trust
no ip arp header-mismatch-validation
use ip-access-list in BROADCAST-MULTICAST-CONTROL
use ip-access-list out BROADCAST-MULTICAST-CONTROL
no ipv6 nd header-mismatch-validation
use mac-access-list in PERMIT-ARP-AND-IPv4
use mac-access-list out PERMIT-ARP-AND-IPv4
service monitor adoption vlan 1
!
wlan RED_EYE1
ssid RED_EYE1
vlan 1
bridging-mode local
encryption-type ccmp
authentication-type none
wireless-client inactivity-timeout 60
wpa-wpa2 psk 0 re@123
wing-extensions move-command
wing-extensions smart-scan
wing-extensions wmm-load-information
client-load-balancing
wireless-client count-per-radio 50
ip arp trust
no ip arp header-mismatch-validation
use ip-access-list in BROADCAST-MULTICAST-CONTROL
use ip-access-list out BROADCAST-MULTICAST-CONTROL
no ipv6 nd header-mismatch-validation
use mac-access-list in PERMIT-ARP-AND-IPv4
use mac-access-list out PERMIT-ARP-AND-IPv4
http-analyze
service monitor adoption vlan 1
!
meshpoint MCX
meshid 1
beacon-format mesh-point
control-vlan 1
allowed-vlans 1
neighbor inactivity-timeout 60
security-mode psk
wpa2 psk 0 eR24bvdeRR
wpa2 eap peap-mschapv2 user admin password 0 eR24bvdeRR trustpoint eR24bvdeRR
wpa2 eap tls trustpoint eR24bvdeRR
wpa2 eap identity eR24bvdeRR
root
!
smart-rf-policy default
group-by floor
sensitivity high
assignable-power 5GHz max 20
assignable-power 5GHz min 14
assignable-power 2.4GHz max 20
channel-list 5GHz 36,48,60,100,112,124,136
channel-list 2.4GHz 2,6,12
channel-width 5GHz auto
channel-width 2.4GHz auto
smart-ocs-monitoring frequency 5GHz 3
smart-ocs-monitoring frequency 2.4GHz 3
smart-ocs-monitoring sample-count 5GHz 3
smart-ocs-monitoring sample-count 2.4GHz 3
smart-ocs-monitoring extended-scan-frequency 5GHz 0
smart-ocs-monitoring extended-scan-frequency 2.4GHz 0
interference-recovery client-threshold 255
interference-recovery channel-switch-delta 5GHz 5
interference-recovery channel-switch-delta 2.4GHz 5
no select-shutdown
smart-sensor
smart-sensor algorithm cell-size sparse
smart-sensor auto-trigger
smart-sensor band smart-band-24GHz
no smart-sensor tri-radio-only
neighbor-recovery power-threshold 5GHz -65
neighbor-recovery power-threshold 2.4GHz -65
select-shutdown cci-high-threshold -82
select-shutdown cci-low-threshold -95
select-shutdown frequency-limiter 5
select-shutdown frequency 30
coverage-hole-recovery interval 5GHz 15
coverage-hole-recovery interval 2.4GHz 15
coverage-hole-recovery coverage-interval 5GHz 5
coverage-hole-recovery coverage-interval 2.4GHz 5
interference-recovery channel-hold-time 180
neighbor-recovery dynamic-sampling
!
wips-policy default
event client-anomaly identical-src-and-dest-addr filter-ageout 0
event excessive eap-flood threshold-client 15 threshold-radio 40 filter-ageout 0
event client-anomaly dos-broadcast-deauth filter-ageout 0
event client-anomaly fuzzing-invalid-mgmt-frames filter-ageout 0
event client-anomaly non-conforming-data filter-ageout 0
event ap-anomaly transmitting-device-using-invalid-mac
event client-anomaly crackable-wep-iv-key-used filter-ageout 0
event ap-anomaly wireless-bridge
event excessive auth-server-failures threshold-client 5 threshold-radio 20 filter-ageout 0
event client-anomaly fuzzing-invalid-seq-num filter-ageout 0
event ap-anomaly airjack
event ap-anomaly null-probe-response
event client-anomaly fuzzing-all-zero-macs filter-ageout 0
event excessive frames-from-unassoc-station threshold-client 2 threshold-radio 0 filter-ageout 0
event ap-anomaly asleap
event excessive eap-nak-flood threshold-client 10 threshold-radio 20 filter-ageout 0
event ap-anomaly ad-hoc-violation
event ap-anomaly unencrypted-wired-leakage
event excessive dos-eapol-start-storm threshold-client 10 threshold-radio 20 filter-ageout 0
event client-anomaly tkip-mic-counter-measures filter-ageout 0
event client-anomaly invalid-8021x-frames filter-ageout 0
event client-anomaly wellenreiter filter-ageout 0
event client-anomaly non-changing-wep-iv filter-ageout 0
event excessive dos-assoc-or-auth-flood threshold-client 25 threshold-radio 45 filter-ageout 0
event client-anomaly fuzzing-invalid-frame-type filter-ageout 0
event ap-anomaly ap-ssid-broadcast-in-beacon
event excessive dos-unicast-deauth-or-disassoc threshold-client 25 threshold-radio 45 filter-ageout 0
event excessive aggressive-scanning threshold-client 30 threshold-radio 200 filter-ageout 0
event excessive 80211-replay-check-failure threshold-client 10 threshold-radio 25 filter-ageout 0
event client-anomaly netstumbler-generic filter-ageout 0
event excessive decryption-failures threshold-client 25 threshold-radio 75 filter-ageout 0
event ap-anomaly impersonation-attack
!
sensor-policy "Sensor Policy"
rssi-interval-duration 10
scan-mode Default-Scan
!
!
management-policy default
no telnet
no http server
no nova
https server
rest-server
ssh
user admin password 1 930de6f12e368f122c1091860e9af34b663972ebcee1ca5e40e062499d4f365c role superuser access all
snmp-server community 0 private rw
snmp-server community 0 public ro
snmp-server user snmptrap v3 encrypted des auth md5 0 admin123
snmp-server user snmpmanager v3 encrypted des auth md5 0 admin123
!
ex3500-management-policy default
snmp-server community public ro
snmp-server community private rw
snmp-server notify-filter 1 remote 127.0.0.1
snmp-server view defaultview 1 included
!
ex3500-qos-class-map-policy default
!
ex3500-qos-policy-map default
!
profile nx5500 default-nx5500
no autoinstall configuration
no autoinstall firmware
no device-upgrade auto
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto load-management
crypto remote-vpn-client
interface ge1
interface ge2
interface ge3
interface ge4
interface ge5
interface ge6
interface pppoe1
use firewall-policy default
service pm sys-restart
router ospf
router bgp
adoption-mode controller
!
profile rfs4000 default-rfs4000
autoinstall configuration
autoinstall firmware
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto remote-vpn-client
interface radio1
interface radio2
interface up1
interface ge1
interface ge2
interface ge3
interface ge4
interface ge5
interface wwan1
interface pppoe1
use firewall-policy default
use client-identity-group default
logging on
service pm sys-restart
router ospf
router bgp
adoption-mode controller
!
profile ap460 AP-Leaf
no autoinstall configuration
no autoinstall firmware
antenna-id external group-1 ml-2452-pna7-01r
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto load-management
crypto remote-vpn-client
interface radio1
wlan RED_EYE bss 1 primary
interface radio2
data-rates an
placement outdoor
meshpoint MCX bss 1
interface radio3
interface bluetooth1
shutdown
mode le-sensor
interface ge1
interface ge2
interface vlan1
ip address dhcp
ip dhcp client request options all
interface pppoe1
use firewall-policy default
misconfiguration-recovery-time 300
service pm sys-restart
router ospf
adoption-mode controller
!
profile ap460 AP-Root
spanning-tree mst enable
spanning-tree mst 1 priority 32768
spanning-tree mst instance 1 vlan 1
spanning-tree errdisable recovery cause bpduguard
no autoinstall configuration
no autoinstall firmware
antenna-id external group-1 ml-2452-pna7-01r
load-balancing balance-ap-loads
load-balancing balance-channel-loads 5ghz
load-balancing balance-channel-loads 2.4ghz
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto load-management
crypto remote-vpn-client
interface radio1
smart-rf preferred-channel-width 20MHz
data-rates bgn
placement outdoor
wlan RED_EYE bss 1 primary
wlan RED_EYE1 bss 2 primary
aggregation ampdu none
aggregation ampdu max-aggr-size tx 65535
antenna-mode 2x2
no dynamic-chain-selection
antenna-diversity
no 11axTWT
interface radio2
placement outdoor
meshpoint MCX bss 1
aggregation ampdu none
aggregation ampdu max-aggr-size tx 65535
antenna-mode 4x4
no dynamic-chain-selection
antenna-diversity
no 11axSupport
no 11axTWT
interface radio3
shutdown
interface bluetooth1
shutdown
mode le-sensor
interface ge1
interface ge2
interface vlan1
ip address dhcp
ip dhcp client request options all
interface pppoe1
use firewall-policy default
ntp server 10.40.9.250
misconfiguration-recovery-time 300
service pm sys-restart
router ospf
meshpoint-device MCX
root
preferred interface 5GHz
monitor critical-resource action no-root
monitor primary-port-link action no-root
path-method uniform
hysteresis min-threshold -98
exclude wired-peer mint-level-1
acs priority-meshpoint 5GHz MCX
adoption-mode controller
!
profile ap460 default-ap460
no autoinstall configuration
no autoinstall firmware
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto load-management
crypto remote-vpn-client
interface radio1
placement outdoor
interface radio2
interface radio3
interface bluetooth1
shutdown
mode le-sensor
interface ge1
interface ge2
interface pppoe1
use firewall-policy default
service pm sys-restart
router ospf
adoption-mode controller
!
profile ap82xx default-ap82xx
autoinstall configuration
autoinstall firmware
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto remote-vpn-client
interface radio1
interface radio2
interface radio3
interface ge1
interface ge2
interface vlan1
ip address dhcp
ip address zeroconf secondary
ip dhcp client request options all
interface wwan1
interface pppoe1
use firewall-policy default
use client-identity-group default
service pm sys-restart
router ospf
adoption-mode controller
!
profile ap81xx default-ap81xx
autoinstall configuration
autoinstall firmware
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto remote-vpn-client
interface radio1
interface radio2
interface radio3
interface bluetooth1
shutdown
mode bt-sensor
interface ge1
interface ge2
interface vlan1
ip address dhcp
ip address zeroconf secondary
ip dhcp client request options all
interface wwan1
interface pppoe1
use firewall-policy default
use client-identity-group default
service pm sys-restart
router ospf
adoption-mode controller
!
profile ap7522 default-ap7522
autoinstall configuration
autoinstall firmware
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto load-management
crypto remote-vpn-client
interface radio1
transmit-beamforming
interface radio2
interface ge1
interface vlan1
ip address dhcp
ip address zeroconf secondary
ip dhcp client request options all
interface pppoe1
use firewall-policy default
use client-identity-group default
service pm sys-restart
router ospf
adoption-mode controller
!
profile ap7532 default-ap7532
autoinstall configuration
autoinstall firmware
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto load-management
crypto remote-vpn-client
interface radio1
interface radio2
interface ge1
interface vlan1
ip address dhcp
ip address zeroconf secondary
ip dhcp client request options all
interface pppoe1
use firewall-policy default
use client-identity-group default
service pm sys-restart
router ospf
adoption-mode controller
!
profile ap7562 default-ap7562
autoinstall configuration
autoinstall firmware
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto load-management
crypto remote-vpn-client
interface radio1
placement outdoor
interface radio2
placement outdoor
interface ge1
interface ge2
interface vlan1
ip address dhcp
ip address zeroconf secondary
ip dhcp client request options all
interface pppoe1
use firewall-policy default
use client-identity-group default
service pm sys-restart
router ospf
adoption-mode controller
!
profile ap7502 default-ap7502
autoinstall configuration
autoinstall firmware
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto load-management
crypto remote-vpn-client
interface radio1
interface radio2
interface ge1
interface fe1
interface fe2
interface fe3
no power
interface vlan1
ip address dhcp
ip address zeroconf secondary
ip dhcp client request options all
interface pppoe1
use firewall-policy default
use client-identity-group default
service pm sys-restart
adoption-mode controller
!
profile ap71xx default-ap71xx
autoinstall configuration
autoinstall firmware
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto remote-vpn-client
interface radio1
interface radio2
interface radio3
interface ge1
interface ge2
interface vlan1
ip address dhcp
ip address zeroconf secondary
ip dhcp client request options all
interface wwan1
interface pppoe1
use firewall-policy default
use client-identity-group default
service pm sys-restart
adoption-mode controller
!
profile ap6532 default-ap6532
autoinstall configuration
autoinstall firmware
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto load-management
crypto remote-vpn-client
interface radio1
interface radio2
interface ge1
interface vlan1
ip address dhcp
ip address zeroconf secondary
ip dhcp client request options all
interface pppoe1
use firewall-policy default
use client-identity-group default
service pm sys-restart
adoption-mode controller
!
profile ap650 default-ap650
autoinstall configuration
autoinstall firmware
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto load-management
crypto remote-vpn-client
interface radio1
interface radio2
interface ge1
interface vlan1
ip address dhcp
ip address zeroconf secondary
ip dhcp client request options all
interface pppoe1
use firewall-policy default
use client-identity-group default
service pm sys-restart
adoption-mode controller
!
profile ap6521 default-ap6521
autoinstall configuration
autoinstall firmware
interface radio1
interface ge1
interface vlan1
ip address dhcp
ip address zeroconf secondary
ip dhcp client request options all
interface pppoe1
use firewall-policy default
use client-identity-group default
service pm sys-restart
adoption-mode controller
!
profile ap621 default-ap621
autoinstall configuration
autoinstall firmware
interface radio1
interface ge1
interface vlan1
ip address dhcp
ip address zeroconf secondary
ip dhcp client request options all
use firewall-policy default
use client-identity-group default
service pm sys-restart
adoption-mode controller
!
profile ap6511 default-ap6511
autoinstall configuration
autoinstall firmware
interface radio1
interface up1
interface fe1
interface fe2
interface fe3
interface fe4
interface vlan1
ip address dhcp
ip address zeroconf secondary
ip dhcp client request options all
interface pppoe1
use firewall-policy default
use client-identity-group default
service pm sys-restart
adoption-mode controller
!
profile ap6562 default-ap6562
autoinstall configuration
autoinstall firmware
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto load-management
crypto remote-vpn-client
interface radio1
placement outdoor
interface radio2
placement outdoor
interface ge1
interface vlan1
ip address dhcp
ip address zeroconf secondary
ip dhcp client request options all
interface pppoe1
use firewall-policy default
use client-identity-group default
service pm sys-restart
adoption-mode controller
!
profile ap6522 default-ap6522
autoinstall configuration
autoinstall firmware
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto load-management
crypto remote-vpn-client
interface radio1
interface radio2
interface ge1
interface vlan1
ip address dhcp
ip address zeroconf secondary
ip dhcp client request options all
interface pppoe1
use firewall-policy default
use client-identity-group default
service pm sys-restart
adoption-mode controller
!
profile ap622 default-ap622
autoinstall configuration
autoinstall firmware
crypto ikev1 policy ikev1-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ikev2 policy ikev2-default
isakmp-proposal default encryption aes-256 group 2 hash sha
crypto ipsec transform-set default esp-aes-256 esp-sha-hmac
crypto ikev1 remote-vpn
crypto ikev2 remote-vpn
crypto auto-ipsec-secure
crypto load-management
crypto remote-vpn-client
interface radio1
interface radio2
interface ge1
interface vlan1
ip address dhcp
ip address zeroconf secondary
ip dhcp client request options all
use firewall-policy default
use client-identity-group default
service pm sys-restart
adoption-mode controller
!
rf-domain default
location default
timezone Asia/Calcutta
country-code in
use smart-rf-policy default
use wips-policy default
ad-wips-wireless-mitigation disable
ad-wips-wired-mitigation disable
channel-list dynamic
control-vlan 1
!
nx5500 40-83-DE-86-B8-10
use profile default-nx5500
use rf-domain default
hostname NX5500
license AAP a57751d7d63358dda9b90ee98fa73153de709ae016452d395a453bdbc64639041d66ff70cedfecf7
license ADSEC DEFAULT-ADV-SEC-LICENSE
timezone Asia/Calcutta
mint mlcp vlan
mint mlcp ip
no mint mlcp ipv6
spanning-tree mst enable
spanning-tree mst 1 priority 32768
spanning-tree mst instance 1 vlan 1
spanning-tree errdisable recovery cause bpduguard
interface vlan1
ip address 10.40.8.4/23
use firewall-policy default
ntp server 10.40.9.250
ip dns-server-forward
logging on
logging console debugging
logging buffered debugging
logging syslog debugging
logging host 10.40.9.250
controller hello-interval 15 adjacency-hold-time 61
!
ap460 48-9B-D5-FD-7D-22
use profile AP-Root
use rf-domain default
hostname AP-85
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.85/23
controller host 10.40.8.4
no controller vlan
meshpoint-device MCX
root
!
ap460 48-9B-D5-FD-7D-34
use profile AP-Root
use rf-domain default
hostname AP-84
mint mlcp vlan
mint mlcp ip
ip default-gateway 10.40.8.1
interface radio1
power smart
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
antenna-mode 4x4
interface radio2
placement outdoor
interface radio3
shutdown
placement outdoor
interface vlan1
ip address 10.40.8.84/23
ip address zeroconf secondary
no ip dhcp client request options all
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-7E-B4
use profile AP-Root
use rf-domain default
hostname AP-77
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.77/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-7E-EC
use profile AP-Root
use rf-domain default
hostname AP-90
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.90/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-7F-3E
use profile AP-Root
use rf-domain default
hostname AP-89
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.89/23
meshpoint-device MCX
no root
!
ap460 48-9B-D5-FD-7F-4A
use profile AP-Root
use rf-domain default
hostname AP-88
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.88/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-7F-DA
use profile AP-Root
use rf-domain default
hostname AP-63
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.63/23
controller host 10.40.8.4
!
ap460 48-9B-D5-FD-7F-EC
use profile AP-Root
use rf-domain default
hostname AP-90
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.90/23
controller host 10.40.8.4
meshpoint-device MCX
no root
!
ap460 48-9B-D5-FD-80-1C
use profile AP-Root
use rf-domain default
hostname AP-75
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.75/23
controller host 10.40.8.4
!
ap460 48-9B-D5-FD-80-22
use profile AP-Root
use rf-domain default
hostname AP-CONTROL-ROOM
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
antenna-mode 2x2
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.9.249/23
controller host 10.40.8.4
!
ap460 48-9B-D5-FD-80-34
use profile AP-Root
use rf-domain default
hostname AP-64
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.64/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-80-3A
use profile AP-Root
use rf-domain default
hostname AP-71
ip default-gateway 10.40.8.1
antenna-id external group-2 ml-2452-hpag4a6-01
antenna-id external group-3 ml-2452-hpag4a6-01
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
channel smart
no smart-rf preferred-channel-width
power smart
data-rates custom basic-54 basic-48 basic-24 basic-12 mcs-4s
rate-selection standard
placement outdoor
antenna-mode 4x4
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.71/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-80-58
use profile AP-Root
use rf-domain default
hostname AP-60
no channel-list dynamic
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
rf-mode sensor
placement outdoor
interface vlan1
ip address 10.40.8.60/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-80-D0
use profile AP-Root
use rf-domain default
hostname AP-93
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.93/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-80-D6
use profile AP-Root
use rf-domain default
hostname AP-86
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.86/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-81-06
use profile AP-Root
use rf-domain default
hostname AP-61
ip default-gateway 10.40.8.1
no load-balancing balance-ap-loads
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
antenna-mode 2x2
interface radio2
placement outdoor
interface radio3
placement outdoor
wlan RED_EYE bss 1 primary
interface vlan1
ip address 10.40.8.61/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-81-66
use profile AP-Root
use rf-domain default
hostname AP-65
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.65/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-81-CC
use profile AP-Root
use rf-domain default
hostname AP-83
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.83/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-81-D2
use profile AP-Root
use rf-domain default
hostname AP-74
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.74/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-81-D8
use profile AP-Root
use rf-domain default
hostname AP-81
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.81/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-82-3E
use profile AP-Root
use rf-domain default
hostname AP-72
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.72/23
no ipv6 address autoconfig
controller host 10.40.8.4
no controller vlan
meshpoint-device MCX
no root
!
ap460 48-9B-D5-FD-82-8C
use profile AP-Root
use rf-domain default
hostname AP-68
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.68/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-82-98
use profile AP-Root
use rf-domain default
hostname AP-69
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.69/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-82-CE
use profile AP-Root
use rf-domain default
hostname AP-80
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.80/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-83-16
use profile AP-Root
use rf-domain default
hostname AP-76
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.76/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-83-22
use profile AP-Root
use rf-domain default
hostname AP-95
ip default-gateway 10.40.8.1
no load-balancing balance-ap-loads
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.95/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-83-3A
use profile AP-Root
use rf-domain default
hostname AP-70
ip default-gateway 10.40.8.1
load-balancing balance-ap-loads
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
antenna-mode 2x2
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.70/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-83-40
use profile AP-Root
use rf-domain default
hostname AP-66
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.66/23
controller host 10.40.8.4
no controller vlan
meshpoint-device MCX
no root
!
ap460 48-9B-D5-FD-83-BE
use profile AP-Root
use rf-domain default
hostname AP-78
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.78/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-83-D6
use profile AP-Root
use rf-domain default
hostname AP-92
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.92/23
controller host 10.40.8.4
no controller vlan
meshpoint-device MCX
no root
!
ap460 48-9B-D5-FD-84-24
use profile AP-Root
use rf-domain default
hostname AP-67
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.67/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-D5-FD-84-30
use profile AP-Root
use rf-domain default
hostname AP-79
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.79/23
controller host 10.40.8.4
no controller vlan
!
ap460 48-9B-FD-7F-82-3E
use profile AP-Root
use rf-domain default
hostname AP-96
ip default-gateway 10.40.8.1
interface radio1
data-rates custom basic-12 basic-24 36 48 54 basic-mcs-1s mcs-2s
placement outdoor
interface radio2
placement outdoor
interface radio3
placement outdoor
interface vlan1
ip address 10.40.8.96/23
controller host 10.40.8.4
no controller vlan
!
!
end
NX5500#

2 REPLIES 2

s88791459
New Contributor
I had raised a GTAC case, but it was not much of an help. It is a new deployment with AP460es and Extreme GTAC does not support new deployments. Previously the site was using AP7562s and RFS4000.

Can you please go through the posted configuration and give me some pointers. What should I change?

Christoph_S
Valued Contributor II
Hello Soham,

You may want to open a GTAC ticket on this one for in-depth troubleshooting. 

BR

------------------------------
Christoph S.
------------------------------
Christoph S.
GTM-P2G8KFN