MSM7xx Controllers Configuration Guide v6.4.0
Configuration considerations for VoIP traffic
If your wireless network supports VoIP traffic, consider the following:
• If voice traffic is detected on a radio (i.e., the traffic is marked with a QoS setting of AC_VO),
background scanning is disabled on the radio. Not all VoIP traffic is properly QoS-tagged.
Scanning will not be disabled for this traffic.
• Setting a high dwell time (under Neighborhood scanning on the Radio page), may cause
packet loss in VoIP traffic. The potential delay for a VoIP frame is equal to the dwell time. The
maximum recommended delay for VoIP traffic is 100 ms (unidirectional).
• For best results, configure a low scan rate by reducing scan ratio and dwell time under
Neighborhood scanning on the Radio page. For example, setting scan rate to 0.1% and dwell
time to 10 ms results in one scan-slot every 30 seconds.
• Setting the Traffic shaping feature (on the Radio configuration page) to Airtime fairness can
help. Airtime fairness gives every client device an equal share of air time. VoIP devices need
little air time, so when competing with other devices, the VoIP device will be at the head of
the line. Without Airtime fairness, air time allocation is more on a first-come, first-served basis.
Teaming considerations
IDS is supported on controller teams. However, in the case of multiple teams, manual classification
may be required to avoid situations where the authorized AP on one team is detected as a rogue
AP by another team.
Starting IDS
This procedure assumes the controller has a Premium Mobility Controller license installed.
1. Select Controller >> Security > IDS.
2. Enable the checkbox and click Save. Once enabled, the IDS icon in the Summary box will
turn green.
3. To detect rogue APs, IDS needs connectivity to all VLANs in use by the network. By default,
APs monitor the network on which the management tunnel with the controller is established,
they also monitor any VLANs that are mapped to the APs on the Controlled APs >>
Configuration > VLANs page. If you want to other VLANs (for example, VLANs that are used
200 Intrusion detection system (IDS)










