Operational Best Practices

System Health Widget Operational Best Practices describes the details for the operational best practices that the System Health widget provides.

Table 1. System Health Widget Operational Best Practices
TypeFieldDescription
OperationalCertificate AuthenticationPre-installed Extreme certificates allow validation between ExtremeCloud IQ Controller and an AP. APs that do not support signed certificates, can provide self-signed certificates. In this case, you must disable Enforce Manufacturing Certificate on ExtremeCloud IQ Controller for the AP. AP Authentication failure messages are logged in the ExtremeCloud IQ Controller Events Log.
OperationalMesh AP operating on DFS channel.Due to DFS procedures and mandatory ‘Stay off Channel‘ periods, APs operating on DFS channels in a Mesh topology can result in service outages.
OperationalAP recommended version imageAPs are not running the recommended version image. Run the supported AP firmware version. Running other firmware revisions can lead to unexpected results. See Upgrade AP Images.
OperationalAP with Dual 5 GHz and power provided is AFAP510 and AP410 support Dual 5 GHz radios and AF (low power) is provided. Therefore, Radio 2 will be shut down. Configure the AP radio for 2.4 GHz or 5 GHz, or provide AT (high power).
OperationalBackup secure tunnelSecure tunnel is supported on ExtremeWireless Wi-Fi 6 APs. To improve resilience and reduce the outage interval associated with a failover event in a high-availability pair, access points establish session tunnels to both peers in a high-availability pair.
OperationalNTPProper time stamp synchronization is facilitated through Network Time Protocol (NTP). If the NTP server is not reachable, verify the NTP server settings. See Network Time.
OperationalService interface is not operational. Check connectivity for proper service.System functions reference specific interfaces for connectivity. For proper operation, corresponding system interfaces must be enabled and operational.
OperationalBackup tunnel established to ExtremeCloud IQ ControllerTo improve resilience and reduce the outage interval associated with a failover event in a high- availability setup. Access points establish session tunnels to both peers in a high-availability pair.
OperationalAP acknowledgment messageAPs send an acknowledgment message for each configuration update. A missing configuration acknowledgment message from an AP can indicate a connectivity issue.
OperationalCommunication between AP and controller over port 13910 is blocked by the firewallFor proper communication between the AP and the controller, ensure that Port 13910 is open in the firewall.
Note: When the AP is more than one hop away, setting the default route via the Management port can also block communication between an AP and the controller.
OperationalAP connection to primary controllerIn the event of an unexpected release of APs, check your network connectivity between APs and the controllers for possible interruptions.
OperationalAdoption rules did not successfully assign APs to siteConsider the following when configuring adoption rules for AP site assignment:
  • The selected AP Profile must match the AP hardware type.
  • The regulatory domain of the AP must match the Country setting for the site.

For more information, see Adding or Editing Adoption Rules.

OperationalHigh-Availability ConfigurationHigh-Availability connectivity status. Verify your high-availability configuration. See Availability.
OperationalHigh-Availability SynchronizationHigh-Availability connectivity status with synchronization message.
OperationalAssigned Entitlements StatusThe system must be licensed to operate. A best practice is to start the license renewal process at least 90 days before the license expiration date to avoid interruption of functionality.
The following are the available status warnings:
  • Yellow status warning — Some assigned entitlements expire in less than 90 days.
  • Red status warning — Some assigned entitlements expire in less than 30 days.

To view the list of entitlements, go to Administration > License > Entitlements.

For more information, refer to Product Subscription License.

OperationalExtremeCloud IQ Controller is not onboarded to ExtremeCloud IQ.Onboard ExtremeCloud IQ Controller into ExtremeCloud IQ to take advantage of Cloud Visibility. After ExtremeCloud IQ Controller is onboarded into the cloud, all access points that are discovered by that controller are visible in ExtremeCloud IQ. Cloud connectivity is displayed on the License Details page. For information about how to onboard ExtremeCloud IQ Controller to ExtremeCloud IQ, refer to the ExtremeCloud IQ Controller Deployment Guide.
OperationalClient Address Protection. Clients denied.Indicates that a client has attempted to access the network though an IP address that is configured on the Protected IP Address List. Select the icon to display the protected IP address and the MAC address of the offending client. For more information, see Site Allow List/Deny List.
OperationalAPs Below Normal PowerA list of all APs running below Normal power.
  • Success: All APs are fully powered
  • Warning: APs are running with less than full power. A list of APs with power below Normal.