background image

 

 

 

 

 

 

 

AC6605 Access Controller 
V200R001C00 

Dual-Link Backup White Paper

 

 

 

Issue 

01 

Date 

2012-05-30 

 

HUAWEI TECHNOLOGIES CO., LTD. 

 

Summary of Contents for AC6605

Page 1: ...AC6605 Access Controller V200R001C00 Dual Link Backup White Paper Issue 01 Date 2012 05 30 HUAWEI TECHNOLOGIES CO LTD ...

Page 2: ...e customer All or part of the products services and features described in this document may not be within the purchase scope or the usage scope Unless otherwise specified in the contract all statements information and recommendations in this document are provided AS IS without warranties guarantees or representations of any kind either express or implied The information in this document is subject...

Page 3: ...ded Audience This document is intended for Data configuration engineers Commissioning engineers Network monitoring engineers System maintenance engineers Symbol Conventions The symbols that may be found in this document are defined as follows Symbol Description Alerts you to a high risk hazard that could if not avoided result in serious injury or death Alerts you to a medium or low risk hazard tha...

Page 4: ...e 01 2012 05 30 Huawei Proprietary and Confidential Copyright Huawei Technologies Co Ltd iii Change History Changes between document issues are cumulative The latest document issue contains all the changes made in earlier issues Issue 01 2012 05 30 This is the first formal issue ...

Page 5: ...1 3 Principles 2 1 3 1 Dual Link Backup Mechanism 2 1 3 2 AP Login Process 3 1 3 3 STA Login Process 6 1 3 4 Active Standby Switchover and Revertive Switchover 6 1 3 5 Loop Prevention in VLANs 7 1 3 6 Dual Link Backup in Layer 2 Networking and Configuration Notes 10 1 3 7 Dual Link Backup in Layer 3 Networking and Configuration Notes 18 1 4 Applications 29 1 4 1 Direct Forwarding in Layer 3 Chain ...

Page 6: ... is implemented by deploying a standby AC at the same layer as the active AC The standby AC has the same configuration as the active AC When the active AC fails the backup AC starts to manage services quickly Purpose An AC usually controls thousands of APs and tens of thousands of STAs therefore the AC must be highly reliable Configuring dual link backup can ensure stable service operating on a WL...

Page 7: ...both ACs The status of an AP is displayed as normal on the active AC and displayed as standby on the standby AC When both the active and standby ACs are working properly only the active AC manages services of APs and delivers configurations to the APs An AP sends Echo packets to monitor the status of the links connected to the ACs When the active AC is unavailable because of an AC fault or network...

Page 8: ... still online and do not need to be reauthenticated after the switchover is complete The AP status on the standby AC changes from standby to normal after the AP detects a failure on the primary link When traffic is switched back from the standby AC to the active AC services are not affected because both the primary link and backup link are working properly Users are still online and do not need to...

Page 9: ... agent is deployed between the ACs and APs and the primary and secondary DHCP servers are configured on the active and standby ACs The DHCP relay agent sends a DHCP Discovery packet to the active AC in active standby mode or to both the ACs in load balancing mode 3 If the DHCP relay agent works in active standby mode the active AC receives the DHCP Discovery packet and replies with a DHCP Offer pa...

Page 10: ...to the AP When the AP works STAs can go online and use network services Setting Up the Second Tunnel with the Other AC 1 The AP determines to set up a CAPWAP tunnel with the other AC only when the Discover Response packet sent by the first AC contains the dual link backup flag The AP starts to set up the second tunnel after the first AC has delivered configurations to the AP This avoids repeated c...

Page 11: ... and extends its IP address lease during an active standby switchover This low probability is acceptable Additionally the ACs cannot function as gateways for STAs If an AC functions as the gateway for STAs the gateway IP address changes after a switchover However STAs cannot change the gateway IP address causing service interruption Data Forwarding Data of STAs is forwarded in either of the follow...

Page 12: ...nage APs The APs obtain IP addresses and service configurations from the ACs The BRAS allocates IP addresses to STAs and works as the gateway for STAs Data packets from STAs are forwarded to the active AC through a CAPWAP tunnel and forwarded to the BRAS by the AC at Layer 2 The BRAS forwards the data packets to the upstream network at Layer 3 In this networking the ACs must be configured with the...

Page 13: ...port isolation on the ACs or aggregation switches MSTP is recommended Figure 1 4 Loop in management VLANs of aggregation and access switches AC2 AC1 Aggregation switch Aggregation switch Service VLANs of STAs also need to be configured on the two aggregation switches and ACs causing loops Similarly enabling MSTP or configuring port isolation can prevent loops in these VLANs Because there are many ...

Page 14: ...es Co Ltd 9 isolation on the ACs or aggregation switches When using MSTP to prevent loops ensure that the blocked port is one of ports between the ACs and upstream aggregation switches the four ports marked red in Figure 1 5 Figure 1 5 Loop formed whenAP management VLAN is the same as a VLAN of switches or STAs AC2 AC1 Aggregation switch Aggregation switch ...

Page 15: ...nagement VLAN VLAN 3931 service VLAN Access switch Access switch Aggregation switch As shown in Figure 1 6 the ACs are deployed between an aggregation switch and two access switches on a Layer 2 network Data packets from STAs are forwarded in direct mode AC1 is the active AC and AC2 is the standby AC The configuration notes in this networking are as follows Configure the same AC ID and carrier ID ...

Page 16: ...ip pool ap standby excluded ip address 19 19 19 1 AC6605_AC2 ip pool ap standby excluded ip address 19 19 19 3 19 19 19 150 AC6605_AC2 ip pool ap standby option 43 sub option 3 ascii HuaweiAC 19 19 19 1 19 19 19 2 This configuration is optical in Layer 2 networking but is recommended You can also manually assign IP addresses for APs in a batch If this method is used you do not need to specify the ...

Page 17: ...le protect ac 19 19 19 2 priority 0 AC6605_AC2 wlan AC6605_AC2 wlan view wlan ac protect enable protect ac 19 19 19 1 priority 7 In the preceding commands protect ac specifies the IP address of the standby AC Set this parameter to the other AC s IP address on each AC The active AC must have a higher priority than the standby AC The value 0 indicates the highest priority and the value 7 indicates t...

Page 18: ...s switches Data packets from STAs are forwarded through tunnels AC1 is the active AC and AC2 is the standby AC The configuration notes in this networking are as follows Configure the same AC ID and carrier ID for AC1 and AC2 Otherwise after the active AC fails services cannot be switched to the standby AC because BSSIDs of the two ACs are different Run the following commands AC6605_AC1 wlan ac glo...

Page 19: ...d ip address 19 19 19 3 19 19 19 150 AC6605_AC2 ip pool ap standby option 43 sub option 3 ascii HuaweiAC 19 19 19 1 19 19 19 2 This configuration is optical in Layer 2 networking but is recommended You can also manually assign IP addresses for APs in a batch If this method is used you do not need to specify the IP address range in the address pools but you still need to configure an IP address poo...

Page 20: ...9 19 19 1 priority 7 In the preceding commands protect ac specifies the IP address of the standby AC Set this parameter to the other AC s IP address on each AC The active AC must have a higher priority than the standby AC The value 0 indicates the highest priority and the value 7 indicates the lowest priority A smaller value indicates a higher priority Run the display wlan ac protect command to ch...

Page 21: ...AN 3010 management VLAN VLAN 3931 service VLAN Access switch Access switch As shown in Figure 1 8 the ACs are only connected to an aggregation switch on a Layer 2 network Data packets from STAs are forwarded in direct mode AC1 is the active AC and AC2 is the standby AC The configuration notes in this networking are as follows The configuration notes are the same as those in Layer 2 chain networkin...

Page 22: ...N 3931 Access switch Access switch VLAN 3010 management VLAN VLAN 3931 service VLAN As shown in Figure 1 9 the ACs are only connected to an aggregation switch Data packets from STAs are forwarded through tunnels AC1 is the active AC and AC2 is the standby AC The configuration notes in this networking are as follows The configuration notes are the same as those in Layer 2 chain networking tunnel fo...

Page 23: ...IP 80 0 0 X IP 80 0 0 X VLAN 3010 management VLAN VLAN 3931 service VLAN Access switch Access switch Aggregation switch As shown in Figure 1 10 the ACs are deployed between two aggregation switches on a Layer 3 network Data packets from STAs are forwarded in direct mode AC1 is the active AC and AC2 is the standby AC The configuration notes in this networking are as follows Configure the same AC ID...

Page 24: ...ress pools configured for APs on AC1 and AC2 do not overlap each other Configure an IP address pool for APs on AC1 AC6605_AC1 ip pool ap active AC6605_AC1 ip pool ap active gateway list 80 0 0 8 AC6605_AC1 ip pool ap active network 80 0 0 0 mask 255 255 255 0 AC6605_AC1 ip pool ap active excluded ip address 80 0 0 1 80 0 0 7 AC6605_AC1 ip pool ap active excluded ip address 80 0 0 9 80 0 0 19 AC660...

Page 25: ... 0 AC6605_AC2 wlan AC6605_AC2 wlan view wlan ac protect enable protect ac 30 30 30 1 priority 7 In the preceding commands protect ac specifies the IP address of the standby AC Set this parameter to the other AC s IP address on each AC The active AC must have a higher priority than the standby AC The value 0 indicates the highest priority and the value 7 indicates the lowest priority A smaller valu...

Page 26: ...wo aggregation switches on a Layer 3 network Data packets from STAs are forwarded through tunnels AC1 is the active AC and AC2 is the standby AC The configuration notes in this networking are as follows Configure the same AC ID and carrier ID for AC1 and AC2 Otherwise after the active AC fails services cannot be switched to the standby AC because BSSIDs of the two ACs are different Run the followi...

Page 27: ...licts ensure that the IP address pools configured for APs on AC1 and AC2 do not overlap each other Configure an IP address pool for APs on AC1 AC6605_AC1 ip pool ap active AC6605_AC1 ip pool ap active gateway list 80 0 0 8 AC6605_AC1 ip pool ap active network 80 0 0 0 mask 255 255 255 0 AC6605_AC1 ip pool ap active excluded ip address 80 0 0 1 80 0 0 7 AC6605_AC1 ip pool ap active excluded ip addr...

Page 28: ... 0 AC6605_AC2 wlan AC6605_AC2 wlan view wlan ac protect enable protect ac 30 30 30 1 priority 7 In the preceding commands protect ac specifies the IP address of the standby AC Set this parameter to the other AC s IP address on each AC The active AC must have a higher priority than the standby AC The value 0 indicates the highest priority and the value 7 indicates the lowest priority A smaller valu...

Page 29: ...ets from STAs are forwarded in direct mode AC1 is the active AC and AC2 is the standby AC The configuration notes in this networking are as follows Configure the same AC ID and carrier ID for AC1 and AC2 Otherwise after the active AC fails services cannot be switched to the standby AC because BSSIDs of the two ACs are different Run the following commands AC6605_AC1 wlan ac global ac id 999 carrier...

Page 30: ...55 255 0 AC6605_AC1 ip pool ap active excluded ip address 80 0 0 1 80 0 0 7 AC6605_AC1 ip pool ap active excluded ip address 80 0 0 9 80 0 0 19 AC6605_AC1 ip pool ap active excluded ip address 80 0 0 101 80 0 0 254 AC6605_AC1 ip pool ap active option 43 sub option 3 ascii HuaweiAC 30 30 30 1 30 30 30 2 This configuration is mandatory in Layer 3 networking Configure an IP address pool for APs on AC...

Page 31: ...fies the IP address of the standby AC Set this parameter to the other AC s IP address on each AC The active AC must have a higher priority than the standby AC The value 0 indicates the highest priority and the value 7 indicates the lowest priority A smaller value indicates a higher priority Run the display wlan ac protect command to check the AC priorities AC6605_AC1 display wlan ac protect Protec...

Page 32: ...onfiguration notes in this networking are as follows Configure the same AC ID and carrier ID for AC1 and AC2 Otherwise after the active AC fails services cannot be switched to the standby AC because BSSIDs of the two ACs are different Run the following commands AC6605_AC1 wlan ac global ac id 999 carrier id ctc AC6605_AC2 wlan ac global ac id 999 carrier id ctc The ACs must deliver the same VAP to...

Page 33: ...ure an IP address pool for APs on AC1 AC6605_AC1 ip pool ap active AC6605_AC1 ip pool ap active gateway list 80 0 0 8 AC6605_AC1 ip pool ap active network 80 0 0 0 mask 255 255 255 0 AC6605_AC1 ip pool ap active excluded ip address 80 0 0 1 80 0 0 7 AC6605_AC1 ip pool ap active excluded ip address 80 0 0 9 80 0 0 19 AC6605_AC1 ip pool ap active excluded ip address 80 0 0 101 80 0 0 254 AC6605_AC1 ...

Page 34: ...ain Networking As shown in Figure 1 14 two ACs are deployed in a Layer 3 chain networking and work in dual link backup mode to improve network reliability and ensure stable wireless services Data packets from STAs are directly forwarded This networking mode simplifies the network architecture and applies to large scale WLANs where APs are deployed in a centralized manner An AC manages APs in multi...

Page 35: ...he IP address of VLANIF40 to communicate with APs VLAN 3010 is the management VLAN of APs Enable DHCP relay and specify IP addresses of the two ACs as the DHCP server addresses for the DHCP relay agent Set the default VLAN of GigabitEthernet 0 0 1 and GigabitEthernet 0 0 2 to VLAN 3010 and configure the two interfaces to allow VLAN40 VLAN 3010 and VLAN 3931 Set the default VLAN of GigabitEthernet ...

Page 36: ...ct interface interface XGigabitEthernet0 0 1 port link type trunk port trunk allow pass vlan 40 3010 3931 ip route static 40 40 40 0 255 255 255 0 30 30 30 5 wlan wlan ac source interface Vlanif3010 wlan ac protect enable protect ac 30 30 30 2 return Wired side configuration file of AC1 sysname lsw_AC1 vlan batch 40 3010 3931 interface GigabitEthernet0 0 1 port link type trunk port trunk pvid vlan...

Page 37: ...atic 40 40 40 0 255 255 255 0 30 30 30 5 wlan wlan ac source interface Vlanif3010 wlan ac protect enable protect ac 30 30 30 1 priority 7 return Wired side configuration file of AC2 sysname lsw_AC2 vlan batch 40 3010 3931 interface GigabitEthernet0 0 1 port link type trunk port trunk pvid vlan 3010 port trunk allow pass vlan 40 3010 3931 interface XGigabitEthernet0 0 27 port link type trunk port t...

Page 38: ...ame network segment This networking does not require high AC performance AC1 is the active AC and AC2 is the standby AC It is recommended that you manually add offline APs to the ACs Perform the same service configurations including user authentication configuration on the two ACs Before enabling dual link backup complete the tunnel configuration and commit the configuration on AC1 and AC2 If you ...

Page 39: ... is the service VLAN of APs Set the default VLAN of GigabitEthernet 0 0 1 GigabitEthernet 0 0 2 GigabitEthernet 0 0 3 GigabitEthernet 0 0 4 and GigabitEthernet 0 0 5 to VLAN 3010 Configure interfaces GigabitEthernet 0 0 1 through GigabitEthernet 0 0 4 to allow VLAN 3010 and configure GigabitEthernet 0 0 5 to allow VLAN 3010 and VLAN 3931 Figure 1 15 Dual link backup in Layer 3 branched networking ...

Page 40: ...select interface interface XGigabitEthernet0 0 1 port link type trunk port trunk allow pass vlan 3010 3931 wlan wlan ac source interface Vlanif3010 wlan ac protect enable protect ac 19 19 19 2 service set name set1 id 1 forward mode tunnel service vlan 3931 return Wired side configuration file of AC1 sysname lsw_AC1 vlan batch 3010 3931 interface GigabitEthernet0 0 1 port link type trunk port trun...

Page 41: ...e interface Vlanif3010 wlan ac protect enable protect ac 19 19 19 1 priority 7 service set name set1 id 1 forward mode tunnel service vlan 3931 return Wired side configuration file of AC2 sysname lsw_AC1 vlan batch 3010 3931 interface GigabitEthernet0 0 1 port link type trunk port trunk pvid vlan 3010 port trunk allow pass vlan 3010 interface XGigabitEthernet0 0 27 port link type trunk port trunk ...

Page 42: ...port trunk pvid vlan 3010 port trunk allow pass vlan 3010 interface GigabitEthernet0 0 4 description connect to AP port link type trunk port trunk pvid vlan 3010 port trunk allow pass vlan 3010 interface GigabitEthernet0 0 5 description connect to BRAS port link type trunk port trunk pvid vlan 3931 port trunk allow pass vlan 3010 3931 return The preceding configuration files show the basic configu...

Reviews: