cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
267
Views
2
Helpful
2
Replies

Cisco 9800-80 Local Device Authentication Capacity

DATHOZ
Level 1
Level 1

We have a few pairs of 9800-80 and approx 13k APs. We would like to start using the AAA local Device Authentication for AP join, but since we use redundancy between the HA pairs we need to identify the capacity and the load that this new service would add to the WLCs. I could not find documentation on this topic. Does anyone have any knowledge/data on this topic?

Thanks,

-Dave

2 Replies 2

marce1000
VIP
VIP

 

 - There won't be a performance penalty for this , follow up with commands like :

     show platform resources
     show processes cpu platform sorted | ex 0%      0%      0%
     show platform hardware chassis active qfp datapath utilization | i load
     show processes memory platform sorted
     show processes memory platform accounting

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Rich R
VIP
VIP

As @marce1000 says the performance impact is negligible.

The AP is only authenticated at join time so if you have 6000 APs (which is the most you can support on a single WLC) trying to authenticate all at once (eg after WLC reload) then some might take a little longer but it's still a relatively trivial number of radius requests.  It's not something I would worry about.  We use it and have never seen it cause any problems.  The load of the CAPWAP state engine for the APs is going to be proportionally much higher than the AP AAA.

Review Cisco Networking for a $25 gift card