cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2297
Views
5
Helpful
3
Replies

Cisco phone roaming over flexconnect AP ?

Philanthropist
Level 1
Level 1

Hi, 

would appreciate if anyone can explain following question.

 

Network Component;

Wireless controller : 8510

Client = Cisco phone 7925

AP Mode : FlexConnect (local switching)

Authentication/encryption : WPA2/PSK (AES)

Site AP count = 66

Flex connect mode : Connected

 

My question is whenever client move from one AP to another in above scenario, need full or partial authentication and weather CCKM/OCK or CCKM/PSK help in quick roaming ?

 

 

1 Accepted Solution

Accepted Solutions

Hello @Philanthropist 

 This is actually a trick question. I´d say that you need full authentication and i will explain why.

 Cisco IP phone 7925, according to documentation here states that this device is CCX4 capable. To support WPA2/AES with CCKM key cache, this documentation  here states that the device needs to be CCX5.

 

 The advantage of using  CCKM/OCK or CCKM/WPA2 would be prevent you from perform full authentication when roaming, thus, speeding up the process. This is great for sensitivity data. However, as mentioned above, you may not be able to benefit from this feature.

 If you were using RADIUS then the scenario would be different. On this case you could benefit from CCKM/OKC being enough for that only have an Flexconnect AP group.

 Hope that help.

 

 

-If I helped you somehow, please, rate it as useful.-

 

View solution in original post

3 Replies 3

Hello @Philanthropist 

 This is actually a trick question. I´d say that you need full authentication and i will explain why.

 Cisco IP phone 7925, according to documentation here states that this device is CCX4 capable. To support WPA2/AES with CCKM key cache, this documentation  here states that the device needs to be CCX5.

 

 The advantage of using  CCKM/OCK or CCKM/WPA2 would be prevent you from perform full authentication when roaming, thus, speeding up the process. This is great for sensitivity data. However, as mentioned above, you may not be able to benefit from this feature.

 If you were using RADIUS then the scenario would be different. On this case you could benefit from CCKM/OKC being enough for that only have an Flexconnect AP group.

 Hope that help.

 

 

-If I helped you somehow, please, rate it as useful.-

 

thanks @Flavio Miranda for explanation and indeed very useful information but it arose couple of more questions

1. correct me if i am wrong, Cisco Compatible extension (CCX) certification is for non cisco device to check their compatibility to work with Cisco system whereas in my case its complete cisco solution ?

2. Going lil deeper into my network problem, is Radio Resource Management (RRM) frames are part of CAPWAP control (udp 5246) or CAPWAP data (udp 5247) packet ?

 

once again thank, 

1. correct me if i am wrong, Cisco Compatible extension (CCX) certification is for non cisco device to check their compatibility to work with Cisco system whereas in my case its complete cisco solution ?

 Dont think so. Otherwise, they shouldn´t mention CCX in a Cisco Doc for your phone model.

 

2. Going lil deeper into my network problem, is Radio Resource Management (RRM) frames are part of CAPWAP control (udp 5246) or CAPWAP data (udp 5247) packet ?

Not sure if I got it but let  me try to explain what I understand. 

RRM is an Umbrella algorithm responsible for control the whole Wireless network. Under which we have specialized algorithm like TPC, DCA,etc.

CAPWAP is the protocol used on the communication between AP and WLC. So, yes, CAPWAP carriers all the information gathered by AP and transport it to WLC and vice-versa which is result of RRM action.

Although CAPWAP is somehow Management frame as well, we have also management frame exchanged between AP and client which is part of 802.11 management frames (beacons, probes,CTS/RTS, Authen, etc)

Hope I got your point but if I not, you can keep going with the conversation. Keep in mind that I dont have a monopoly on the truth, I am just curious and love Wireless stuff. If you or anyone else have a different interpretation, please, let me know.

 

-If I helped you somehow, please, rate it as useful.-

Review Cisco Networking for a $25 gift card