01-22-2024 10:47 AM
We have a few pairs of 9800-80 and approx 13k APs. We would like to start using the AAA local Device Authentication for AP join, but since we use redundancy between the HA pairs we need to identify the capacity and the load that this new service would add to the WLCs. I could not find documentation on this topic. Does anyone have any knowledge/data on this topic?
Thanks,
-Dave
01-23-2024 12:19 AM
- There won't be a performance penalty for this , follow up with commands like :
show platform resources
show processes cpu platform sorted | ex 0% 0% 0%
show platform hardware chassis active qfp datapath utilization | i load
show processes memory platform sorted
show processes memory platform accounting
M.
01-23-2024 08:21 AM - edited 01-23-2024 02:16 PM
As @marce1000 says the performance impact is negligible.
The AP is only authenticated at join time so if you have 6000 APs (which is the most you can support on a single WLC) trying to authenticate all at once (eg after WLC reload) then some might take a little longer but it's still a relatively trivial number of radius requests. It's not something I would worry about. We use it and have never seen it cause any problems. The load of the CAPWAP state engine for the APs is going to be proportionally much higher than the AP AAA.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide