WAP Device Best Practice

Hello everyone,
After a whole lot of testing (months), I have finally figured out the best configuration for WAP (321,551,561,371) devices that by default have problems with Apple devices disconnecting or having problems with Airplay and so on. Down below a couple of changes you should make to your configuration, which will hopefully also fix this for you, for once and for all :)
- Disable bonjour (Administration) - (This is still failing (when enabled) since IOS8, please fix this Cisco! -- More info on the Bonjour issue: https://supportforums.cisco.com/discussion/12221896/mdnsresponder-error-over-and-over)
- Disable Bandwidth utilization (Wireless)
- Set a static channel for both 2.4 and 5ghz
  - For 2.4Ghz I recommend 1,6 or 11 (lower). For 5Ghz I recommend 36, 44 or 48.
- Use WPA2-AES only (Networks, WPA Versions)
- Use 20 or 20/40Mhz for 2.4ghz and 80Mhz (WAP 371) (or 40Mhz for WAP561) for 5ghz mode
- Frame burst enabled for 5ghz only
- Beacon Interval: 100 (default) DTIM Period: 1 (for 2.4 and 5ghz)
- Legacy rate sets (2.4 ghz), basic: 1,2,5.5,11, Supported: enable all.
Update (Nov, 24 2014):
I have been testing for a few months now to optimize and make WiFi products (like Apple, NEST, Android phones) stay connected to the WAP access points, and what I've found out is that when you disable Broadcast Key refresh rate completely (to 0) they seem to stay connected even better :)
- Wireless > Networks: Click Show details then EDIT and set Broadcast Key Refresh Rate to 0.
Update (Nov, 29 2014):
You may also use the same SSID for both 2.4 and 5ghz so the WAP can auto assign the right band for each client.
Update (Apr, 2015):
You may use either 20 or 20/40 for 2.4Ghz, both should work fine if you are not in a 'crowded' area.
If there are lots of other Wifi networks on 2.4Ghz around you, pls use 20Mhz only!
Note: All other settings like disabling/enabling VLAN or QOS have no effect on disconnect problems, so you can leave those enabled (if you used them).
Enjoy ;)

I followed the on screen wizard of the access point to set up the cluster mode, after that I applied the settings you suggested..
I have POE ethernet running to each unit - each unit is assigned a static IP.
The only reason we have choosen the CISCO WAP371s was that the fact after a very extensive trail and error with a variety of access points - cisco worked best with our IPTV provider, least amount of hick ups.. but we are noticing nodes on the network that are wifi - falling off like our WEMO nodes, also the strange cap of download speeds. 
We do have a back up Dlink Access point DIR 868L - that operates fine with no speed cap or loss.. 
I am hoping for to figure out how to do an auto reboot every 3 days.
screen cap attached for set up

Similar Messages

  • WAP 321 best practice

    Hi
    I've got 4 AP placed in the corners of the house.
    I would like to provide the best possibilities of roaming users which will be moved in the building.
    What kind of parameters I can change to set sensivity of reconnection user to another AP ?
    Many times I saw that device works with AP with weak signal when available is another with much stronger signal.
    Is any way to change moment when device will be reconnected ?
    Is this process related to OS of the device ?
    Generaly to avoid interference AP in neighborhood should work on different channels 1 6 11.
    To configure WDS all AP should work on the same channel. Why ?
    Is WAP 321 is salt water resist ?
    Could it be install on boat ?
    Of course inside of cabin but I can imagine that salty fog or steam available around can be dangerus.
    Please advice if I can use this model or should chose differrent ?
    Best regards
    Darek

    Hello Dariusz,
    What kind of parameters I can change to set sensivity of reconnection user to another AP ?
    Generally, the clients control which AP they want to connect at any given point of time. If you are using Windows operating system, you can set the roaming mode to aggressive where the wireless interface on the device will constantly monitor the signal strength from different Access Points in the viscinity (on the same SSID) and when it finds an AP with better signal than the current one it is attached to, it will switch the association to the new AP.
    http://www.intel.com/support/wireless/wlan/sb/cs-015906.htm
    Many times I saw that device works with AP with weak signal when available is another with much stronger signal.
    Is any way to change moment when device will be reconnected ?
    Answer is included in the link below:
    http://www.intel.com/support/wireless/wlan/sb/cs-015906.htm
    Is this process related to OS of the device ?
    This is typically controlled by the Client Operating System/wireless card driver.
    Generaly to avoid interference AP in neighborhood should work on different channels 1 6 11.
    To configure WDS all AP should work on the same channel. Why ?
    Essentially, WDS is sort of bridging/repeating across multiple Access Points without the need for a wired infrastructure to connect the access points. Since the WAP321 has a single radio interface, it cannot switch between different channels on the fly when communicating with another AP and with the clients. In order for the AP to bridge/repeat data from a neighboring access point, it has to be on the same channel as the neighboring access point and for association purposes, all other radio parameters should remain the same.
    http://en.wikipedia.org/wiki/Wireless_distribution_system
    If you have a wired infrastructure connecting these access points, then you can use Single Point Setup to connect these access points in a clusture and manage the channel assignment.
    http://sbkb.cisco.com/CiscoSB/ukp.aspx?vw=1&docid=268839bea50742079bdf0ae12a245002_Single_Point_Setup_Wireless_Neighborhood_on_WAP551_and_WAP56.xml
    Hope this helps.
    Regards,
    Nagaraja

  • Responsive projects autosizing for multiple devices -- best practices?

    While it's a nice idea to have the three different breakpoints on width that allow you to make some major layout changes, I'm having trouble making this work well across multiple devices.  With the high resolutions of current mobile devices, this model just doesn't seem to work well.  For example, the iPad 2 in landscape mode select the desktop layout, which isn't bad, but in portrait mode gets the tablet layout, which by default is set up to be landscape.  I changed the heights for both breakpoints to better fit the iPad, but then the iPhone in landscape gets the tablet layout, requiring a lot of scrolling.
    Given the wide range of resolutions on mobile devices, it's not at all clear how this a simplistic mechanism like this could ever work.  For one thing, it sure seems like you need to provide for both portrait and landscape layouts on tablets and phones, with Captivate using both width and height to select the best one.  Also, is there any way to tell it to fill the screen without scrolling? How about automatically leaving the area clear where there's a status bar (or telling it to hide the status bar)?
    I could just create a separate version of the project for each device, but then lose much of the value of creating a Responsive Project in the first place.  Have those of you with more experience found good ways to deal with these variables, or is the best option to just create separate versions of the project?

    While it's a nice idea to have the three different breakpoints on width that allow you to make some major layout changes, I'm having trouble making this work well across multiple devices.  With the high resolutions of current mobile devices, this model just doesn't seem to work well.  For example, the iPad 2 in landscape mode select the desktop layout, which isn't bad, but in portrait mode gets the tablet layout, which by default is set up to be landscape.  I changed the heights for both breakpoints to better fit the iPad, but then the iPhone in landscape gets the tablet layout, requiring a lot of scrolling.
    Given the wide range of resolutions on mobile devices, it's not at all clear how this a simplistic mechanism like this could ever work.  For one thing, it sure seems like you need to provide for both portrait and landscape layouts on tablets and phones, with Captivate using both width and height to select the best one.  Also, is there any way to tell it to fill the screen without scrolling? How about automatically leaving the area clear where there's a status bar (or telling it to hide the status bar)?
    I could just create a separate version of the project for each device, but then lose much of the value of creating a Responsive Project in the first place.  Have those of you with more experience found good ways to deal with these variables, or is the best option to just create separate versions of the project?

  • We are evaluating the use of iPod touch devices to record best practice videos on our manufacturing floor and to post to an internal Moodle web site. How can you upload a video from the iPod touch to a site other than YouTube?

    We are evaluating the use of iPod touch devices to record best practice videos on our manufacturing floor and to post to an internal Moodle web site. How can you upload a video from the iPod touch to a site other than YouTube? The Moodle upload interface is expecting a file selection dialog box like windows or OSX. I do not want to have to go through an intermediary step of messing with a pc.
    Thanks!

    It should be around 7 and a half gigs. In iTunes, across the bottom there should be a bar that show how much storage is being used and by what. (music, movies, apps, etc.) To make music take up less room, you can check the box to make it convert the music to 128kbps AAC. This lowers the quality, but with most earbuds and speakers, you can't even tell the difference.
    The iPod touch has parental controls built in. You'll find them in Settings. I think they only work for enabling/disabling Safari, Mail, YouTube, and App Store. Here's an app that does more: http://www.mobicip.com/online_safety/ipod_touch

  • Best Practice - WAP connecting switchport configuration.

    Is there a best practice for deploying the WAP's in a WAP/WLC infrastructure?  Should the connecting switchport be an Access port or a Trunk port?  I've seen this implemented in both fashions and wasn't sure if one was a better choice than the order.  What is the difference?
    My other question is regarding applying additional switchport configurations.  Is there anything wrong with applying either spanning-tree portfast, spanning-tree bpdguard, or switchport port-security. 

    Hi Ken,
    Access port all the time, everywhere, UNLESS the AP is configured for HREAP/FLEX then trunk. Or if you deploy a AP in monitor mode then TRUNK.
    QOS -- if its access port trust dscp. If you truck trust cos.
    No you are fine. Portfast is highly recommended.
    "Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin
    ‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."

  • Best practice for limiting network management to few devices

    Hello ,
    I have set up a very basic security implementation that is no way realistic, but I just want to experiment and learn...
    In my 1801 router that answers DHCP requests on separate wired and wireless vlans, I have bound static IP addresses to the MAC addresses of my laptop wireless and wired interfaces.
    Then I set up an ACL to permit inbound traffic from these IPs only for the vty lines.
    Obviously this is easily defeated by statically assigning these same IPs to any device on the network, so I was thinking about a better way to limit management of the router to a few devices.
    What is the best practice in professional environments?
    Thanks.

    Obviously this is easily defeated by statically assigning these same IPs to any device on the network, so I was thinking about a better way to limit management of the router to a few devices.
    TACACs or RADIUS with robust password policy and regular interval to change the passwords (30 to 45 days).
    Read this and go to the "Composing hard-to-guess passwords" section.

  • Best practices for attaching iSCSI devices

    Hello all,
    My environment: Nexus 5010 with 2148T FEX switches in the racks.
    Can (or should) I use the 2148T as the switch between clustered servers and the iSCSI SAN?  The SAN is a Dell MD3000i connected to Dell R710 servers, Win Ent 2008 R2 Server.
    Plans are to use two vlans so I have dual data paths to the SAN.  Being new to the Nexus, I'm not sure what the best practice/configuration is for that.
    Any suggestions on reading materials or best practice configurations would be appreciated!
    Thanks...
    Ted

    We recently implemented Nexus 7010s, 5020s, and 2248s in our data center. Now we would like to harden them from a security persective; are there any Best Practices available for hardening Nexus devices?
    Hi Carl,
    I dont think a specifc hardening document has been realsed but yes you can refer the generic ios based hardening and try with NX-OS which are all supported or not.
    http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080120f48.shtml
    Hope to Help !!
    Ganesh.H
    Remeber to rate the helpful post

  • Best practices for additonal storage devices in a clustered container

    I am wondering what is considered as best practices related to adding more storage devices. I have a Solaris Cluster 3.2, a failover resource group with a SZBT resource and a HASP resource for the zone root path. Now i have to add more storage devices (for Oracle to the zone). The additional storage devices are in the same metaset as the zone root. I see the following options:
    -> Add it to the zone (simple not managed by HASP)
    -> Add it to the existing HASP for the RG and lofs mount it in the Zone (managed by HASP, but needs lofs mount)
    Are there other options, and what is considered best practices?
    Fritz

    Hi Fritz,
    no matter which option you take it should resoult in lofs mounts.
    I in person would not mix the concepts, you started with HASP, so I would continue with HASP.
    To achieve this you have to take three steps:
    1 add the file systems to the HASP resource,
    2. create the mountpoints in the local zone
    3 add the file system to the Mounts variable in the SCZBT's parameter file.
    If you do not want to reboot the zones, you can mount the loopback files manually, but the safest option ( you will not mess up with typos in th mount pints and realize it later) would be to disable and reenable th sczbt resource.
    Cheers
    Detlef

  • Flash Alternative Content ~ Best Practice ~ Safari on iOS Devices ~ iPad iPhone iPod Touch

    Hi Folks,
    Is there a documented best practice for providing alternate content for Flash in Safari on iOS devices?
    I am getting white space where my Flash animation would normally appear, and management is displeased. I need to display alternative content in this space. I'm hopeful that Adobe has published a best practice for how to accomplish this.
    tyvm
    Keith

    Not sure about Adobe official stance but they have started using swfobject Flash detection to place Flash <objects> on the Web page. The problem I see with the Adobe implementation is that about the only alternate content they recommend is "Click here to download the latest version of Flash player".
    That is about the lamest alternate content you could possibly imagine! Just because you recommend that your viewers download the new version.... doesn't mean they will... so they still go without REAL alternate content.
    A MUCH BETTER use of swfobject is to actually provide alternate content! For your review::
    If you think that Flash is somehow bad for SEO, it's time to dispell that MYTH!
    If fact, in some circumstances I'll use Flash INSTEAD of just HTML because then I'll have better SEO than with just HTML alone.
    http://www.worldbarefootcenter.com/
    The link to World Barefoot Center in the above post is just one example. View the source code and you see a couple paragraphs of text along with regular HTML links.... but what displays is the Flash version of the image and Flash links.
    The client provided the artwork for the page... and that's what they wanted to use a .jpg image. Well yes, that could be done in HTML but it would be virtually invisible to Google. So Instead I converted the image into a Flash .swf and used swfobject to display the Flash. swfobject allows you to create alternate content inside the <div> which also holds the Flash .swf, then when the page is loaded it detects if the browser has the Flash pluggin. If it does, it displays just the Flash content, if not, it displays the alternate content. Since almost everyone has the Flash pluggin, for most people the Flash version of the <div> will display.
    The alternate content for that <div> can be any regular HTML text, images, media player, links, etc., anything that you would use if you were not using the Flash. Now the best part is that the alternate content can be "over the top" as far as optimizing for SEO, since it will not be seen by most viewers.
    Here's another example of SEO with Flash.. again, the page is just a single image provided by the client:
    http://www.ksowetsuits.com/
    View the source code. The alt content is paragraph after paragraph of information about the site, including lists and links. If it was just the HTML, it might be kind of a boring Home page. But for SEO I can go "over the top" in promoting the site, since most viewers will never see that part... but it's all indexed by search engines. The end result is BETTER SEO using Flash than just HTML.
    On another Web site, a Flash video is displayed, the alt content is the complete text narration of the video. Now how many people would take the time to read that if they could just watch the video instead?? again, better SEO with Flash than without. In fact in one case we had first page search result from that video narration within 4 hours of posting the page.
    On still another site with a Flash video, the alt content is another video, but a .mov version, which will, in effect play Flash video on the iPhone (not possible you say??). Well since the iPhone does not have Flash pluggin, it simply displays the .mov version of the video, while everyione else sees the Flash version.
    So anyway, if Flash is a part of your Web development, you should look into using swfobject and alternate content.
    http://code.google.com/p/swfobject/
    Best wishes,
    Eye for Video
    www.cidigitalmedia.com
    So it is and has been for a number of years now, very easy to provide alternate content for non Flash devices... and that includes text, images, and video.
    Best wishes,
    Adninjastrator

  • ACS best practices for device config

    Can anybody tell me what the best practice is in regards to device setup in ACS?
    Specifically, is it better to specify each device individually or is it ok to allow whole subnets access to access, therefore allowing all devices in those subnets access to ACS for AAA.

    Find My iPad is not a fully reliable way to secure data on a corporate iPad. The service is too easy to defeat and block you from wiping the data. You can, however, make settings that will make it much more difficult for someone to get data from your company iPads and iPhones even if they can defeat the Find My iPad connection. I'd suggest you read these Apple documents:
    http://www.apple.com/ipad/business/docs/iOS_Security.pdf
    http://www.apple.com/ipad/business/docs/iOS_MDM.pdf
    They'll give you an overview of how to secure your devices.
    Regards.

  • Best practices for hardening Nexus devices

    We recently implemented Nexus 7010s, 5020s, and 2248s in our data center. Now we would like to harden them from a security persective; are there any Best Practices available for hardening Nexus devices?

    We recently implemented Nexus 7010s, 5020s, and 2248s in our data center. Now we would like to harden them from a security persective; are there any Best Practices available for hardening Nexus devices?
    Hi Carl,
    I dont think a specifc hardening document has been realsed but yes you can refer the generic ios based hardening and try with NX-OS which are all supported or not.
    http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080120f48.shtml
    Hope to Help !!
    Ganesh.H
    Remeber to rate the helpful post

  • IOS Update Best Practices for Business Devices

    We're trying to figure out some best practices for doing iOS software updates to business devices.  Our devices are scattered across 24 hospitals and parts of two states. Going forward there might be hundreds of iOS devices at each facility.  Apple has tools for doing this in a smaller setting with a limited network, but to my knowledge, nothing (yet) for a larger implementation.  I know configurator can be used to do iOS updates.  I found this online:
    https://www.youtube.com/watch?v=6QPbZG3e-Uc
    I'm thinking the approach to take for the time being would be to have a mobile sync station setup with configurator for use at each facility.  The station would be moved throughout the facility to perform updates to the various devices.  Thought I'd see if anyone has tried this approach, or has any other ideas for dealing with device software updates.  Thanks in advance. 

    Hi Bonesaw1962,
    We've had our staff and students run iOS updates OTA via Settings -> Software Update. In the past, we put a DNS block on Apple's update servers to prevent users from updating iOS (like last fall when iOS 7 was first released). By blocking mesu.apple com, the iPads weren't able to check for or install any iOS software updates. We waited until iOS 7.0.3 was released before we removed the block to mesu.apple.com at which point we told users if they wanted to update to iOS 7 they could do so OTA. We used our MDM to run reports periodically to see how many people updated to iOS 7 and how many stayed on iOS 6. As time went on, just about everyone updated on their own.
    If you go this route (depending on the number of devices you have), you may want to take a look at Caching Server 2 to help with the network load https://www.apple.com/osx/server/features/#caching-server . From Apple's website, "When a user on your network downloads new software from Apple, a copy is automatically stored on your server. So the next time other users on your network update or download that same software, they actually access it from inside the network."
    I wish there was a way for MDMs to manage iOS updates, but unfortunately Apple hasn't made this feature available to MDM providers. I've given this feedback to our Apple SE, but haven't heard if it is being considered or not. Keeping fingers crossed.
    Hope this helps. Let us know what you decide on and keep us posted on the progress. Good luck!!
    ~Joe

  • Best Practices for ASA 5500 Device Monitoring

    I have looked high and low and am unable to find anything on this topic. I am hoping that somebody here may be able to share some insight into what are considered the best practices for monitoring ASA's--specifically the 5510 with Sec+ License.
    My current monitoring application keeps reporting issues with outbound interface buffers being too high, but there are not any performance issues and I believe the thresholds are just set absurdly low.
    Thank you in advance for any assistance.

    Hi James,
    You probably won't be able to find any all-encompassing documentation for these types of best practices that cover all scenarios. The better method would be to define exactly what items you'd like to monitor and we can provide some guidance on how to best get that working for you.
    -Mike

  • IOS Template - Best Practices

    Hello,
    Does anyone have a standard template that they apply to all ios switches/routers/waps? I'm looking for some best practices for ios configs. For example, which services do you disable on all devices, what snmp settings, etc..
    Thanks!

    Hi,
    See the below link :
    http://www.cymru.com/Documents/secure-ios-template.html
    Regards,
    Mehrdad

  • Best practice on sqlite for games?

    Hi Everyone, I'm new to building games/apps, so I apologize if this question is redundant...
    I am developing a couple games for Android/iOS, and was initially using a regular (un-encrypted) sqlite database. I need to populate the database with a lot of info for the games, such as levels, store items, etc. Originally, I was creating the database with SQL Manager (Firefox) and then when I install a game on a device, it would copy that pre-populated database to the device. However, if someone was able to access that app's database, they could feasibly add unlimited coins to their account, unlock every level, etc.
    So I have a few questions:
    First, can someone access that data in an APK/IPA app once downloaded from the app store, or is the method I've been using above secure and good practice?
    Second, is the best solution to go with an encrypted database? I know Adobe Air has the built-in support for that, and I have the perfect article on how to create it (Ten tips for building better Adobe AIR applications | Adobe Developer Connection) but I would like the expert community opinion on this.
    Now, if the answer is to go with encrypted, that's great - but, in doing so, is it possible to still use the copy function at the beginning or do I need to include all of the script to create the database tables and then populate them with everything? That will be quite a bit of script to handle the initial setup, and if the user was to abandon the app halfway through that population, it might mess things up.
    Any thoughts / best practice / recommendations are very appreciated. Thank you!

    I'll just post my own reply to this.
    What I ended up doing, was creating the script that self-creates the database and then populates the tables (as unencrypted... the encryption portion is commented out until store publishing). It's a tremendous amount of code, completely repetitive with the exception of the values I'm entering, but you can't do an insert loop or multi-line insert statement in AIR's SQLite so the best move is to create everything line by line.
    This creates the database, and since it's not encrypted, it can be tested using Firefox's SQLite manager or some other database program. Once you're ready for deployment to the app stores, you simply modify the above set to use encryption instead of the unencrypted method used for testing.
    So far this has worked best for me. If anyone needs some example code, let me know and I can post it.

Maybe you are looking for

  • Sub-contracting External Processing PP-PI

    hI, I am trying to create sub-contracting order through SAP PP-PI. I have a FG - X, with components X1 & X2. I have 3operations and 3 phases in the Recipe for X. The 2nd phase is having the control key for external processing, because of which i had

  • My new macbook pro has a dull, yellow tinted screen.

    I purchased a (new, with warranty) standard macbook pro 13" on eBay to downsize from my 15" 2010 model, and the screen is notably duller and has a yellow overcast to it. I have tried to calibrate the screen which helps a little bit but it still gets

  • [ANN] Oracle JDeveloper 10g is now available for download.

    It's probably worth a mention in this forum too ;-) In case you haven't notice we have just released Oracle JDeveloper 10g production with a many new features that makes it the ideal Java tools for Oracle Application Server users. Check it out at: ht

  • Webdynpro model context mapping issue

    Hi, I have created a faceless Web Dynpro model component (DC1) and an UI Component (DC2). DC1 is an used component in DC2. After mapping the model node from the interface controller of DC1 to DC2 it says "Referenced model class is missing". I asume,

  • SAP help for Logistics Customizing Cockpit

    Hi Friends Greetings... I want to read complete scenario for BW extraction, I want to know LIS, and LO concept, Central Delta Managemen, Set up tables, why we need MCstructures if we have LIS structures etc., I'm trying to search in "help.sap.com" bu