---
language: "en"
---
# Cisco Spaces Runbooks & Knowledge Articles

## Deployment Documentation

*

  ### [Cisco Spaces Runbooks (Cisco Validated)](https://runbooks.ciscospaces.io/docs/cisco-spaces-runbooks-cisco-validated.md)

  Note that the icon will open up the navigation pane. The contents within are deployment guides to successfully realize outcomes with Cisco Spaces. The root run...
*

  ### [Cisco Spaces Day 2 Runbooks](https://runbooks.ciscospaces.io/docs/cisco-spaces-day-2-runbooks.md)

  The Cisco Spaces Day 2 Runbooks are operational guides designed to support ongoing management, optimization, and governance of a Cisco Spaces deployment after ...
*

  ### [Knowledge Articles](https://runbooks.ciscospaces.io/docs/knowledge-articles.md)

  Knowledge articles are small snippets of information or concentrations on a single topic, that are key to deployment success. These are useful for customers wh...
*

  ### [Partner Ecosystem Guides](https://runbooks.ciscospaces.io/docs/partner-ecosystem-guides.md)

  These documents provide comprehensive guidance on understanding and navigating the Cisco Spaces Partner Ecosystem. They are designed to help partners, develope...
*

  ### [Site Changelog](https://runbooks.ciscospaces.io/docs/site-changelog.md)

  2026 Changelog - 2026.07 Changelog - 2026.06 Changelog - 2026.05 Changelog - 2026.04 Changelog - 2026.03 Changelog - 2026.02 Changelog - 2026.01 2025 Changelog...

---
language: "en"
---
# Catalyst AP Capability Matrix

## Catalyst AP Capability Matrix

The Catalyst AP Capability Matrix table is focused on Access Points with integrated omni-directional antenna. Access Points with external and directional antenna have **NOT** been validated

|      **AP Model**       |                                                                                                                                                                                                                                          **IOT Radio feature support**                                                                                                                                                                                                                                          ||||                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            **Use Cases**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |||||||
|      **AP Model**       |
|-------------------------|--------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|
| **IOT Gateway Support** | **BLE Rx Only** **(scanning)** | **BLE Tx Only** **(beaconing)**                                                                                                                           | **Dual Mode** **(scanning + beaconing )**                                                                                                                 | **Asset Tracking** **(BLE based)**                                                                                                                        | **Asset Tracking** **(Wi-Fi based)**                                                                                                                      | **Asset Tracking** **(Native UWB based)**                                                                                                                 | **Indoor Navigation** **(BLE Tx)** | **Space Utilization - (Building \& Floor )** **(Wi-Fi based)**                                                                                            | **Staff Duress** **(BLE based)**                                                                                                                          | **Environmental Monitoring** **(3rd party BLE sensors)**                                                                                                  |
| **9178I/9176I**         | **Advanced**                   | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | 🗓️                                | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| **9176D1**              | **Advanced**                   | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                  | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                                                                                                                                         |
| **9179F**               | **Advanced**                   | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                  | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                                                                                                                                         |
| **9172**                | **Advanced**                   | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                  | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| **9166D1**              | **Advanced**                   | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![info](https://runbooks.ciscospaces.io/__attachments/a_9f797684df3ea7be221229a992659b49a4d20e52b5ca0beb98e6846f0a2a416b/atlassian-info?cb=feab5cd71111204d6b52545f3027dd0c)             | ![info](https://runbooks.ciscospaces.io/__attachments/a_9f797684df3ea7be221229a992659b49a4d20e52b5ca0beb98e6846f0a2a416b/atlassian-info?cb=feab5cd71111204d6b52545f3027dd0c)             | ❌                                  | ![info](https://runbooks.ciscospaces.io/__attachments/a_9f797684df3ea7be221229a992659b49a4d20e52b5ca0beb98e6846f0a2a416b/atlassian-info?cb=feab5cd71111204d6b52545f3027dd0c)             | ![info](https://runbooks.ciscospaces.io/__attachments/a_9f797684df3ea7be221229a992659b49a4d20e52b5ca0beb98e6846f0a2a416b/atlassian-info?cb=feab5cd71111204d6b52545f3027dd0c)             | ![info](https://runbooks.ciscospaces.io/__attachments/a_9f797684df3ea7be221229a992659b49a4d20e52b5ca0beb98e6846f0a2a416b/atlassian-info?cb=feab5cd71111204d6b52545f3027dd0c)             | ![info](https://runbooks.ciscospaces.io/__attachments/a_9f797684df3ea7be221229a992659b49a4d20e52b5ca0beb98e6846f0a2a416b/atlassian-info?cb=feab5cd71111204d6b52545f3027dd0c)             |
| **9166**                | **Advanced**                   | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                  | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| **9164**                | **Advanced**                   | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                  | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| **9162**                | **Advanced**                   | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                  | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| **9136**                | **Advanced**                   | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                  | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| **9130**                | **Advanced**                   | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                  | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| **9124**                | **Advanced**                   | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![info](https://runbooks.ciscospaces.io/__attachments/a_9f797684df3ea7be221229a992659b49a4d20e52b5ca0beb98e6846f0a2a416b/atlassian-info?cb=feab5cd71111204d6b52545f3027dd0c)             | ![info](https://runbooks.ciscospaces.io/__attachments/a_9f797684df3ea7be221229a992659b49a4d20e52b5ca0beb98e6846f0a2a416b/atlassian-info?cb=feab5cd71111204d6b52545f3027dd0c)             | ❌                                  | ![info](https://runbooks.ciscospaces.io/__attachments/a_9f797684df3ea7be221229a992659b49a4d20e52b5ca0beb98e6846f0a2a416b/atlassian-info?cb=feab5cd71111204d6b52545f3027dd0c)             | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![info](https://runbooks.ciscospaces.io/__attachments/a_9f797684df3ea7be221229a992659b49a4d20e52b5ca0beb98e6846f0a2a416b/atlassian-info?cb=feab5cd71111204d6b52545f3027dd0c)             | ![info](https://runbooks.ciscospaces.io/__attachments/a_9f797684df3ea7be221229a992659b49a4d20e52b5ca0beb98e6846f0a2a416b/atlassian-info?cb=feab5cd71111204d6b52545f3027dd0c)             |
| **9120**                | **Advanced**                   | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                  | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| **9117**                | **Advanced**                   | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                                                                                                                                         | ⚠️                                                                                                                                                        | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                  | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                                                                                                                                         | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| **9115**                | **Advanced**                   | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                                                                                                                                         | ⚠️                                                                                                                                                        | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                  | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                                                                                                                                         | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| **9105**                | **Advanced**                   | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                  | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| **4800**                | **Base**                       | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                                                                                                                                         | ⚠️                                                                                                                                                        | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                  | ⚠️                                                                                                                                                        | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                                                                                                                                         | ⚠️                                                                                                                                                        |
| **1815w**               | **Base**                       | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                  | ❌                                                                                                                                                         | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                                                                                                                                         | ❌                                                                                                                                                         |
| **1815m**               | **Base**                       | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                  | ❌                                                                                                                                                         | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                                                                                                                                         | ❌                                                                                                                                                         |
| **1815i**               | **Base**                       | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                  | ❌                                                                                                                                                         | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                                                                                                                                         | ❌                                                                                                                                                         |
| **1840**                | **Base**                       | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                  | ❌                                                                                                                                                         | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                                                                                                                                         | ❌                                                                                                                                                         |

|                                                                                                                                               **Legend**                                                                                                                                               ||
|-----------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------|
| ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | Supported                                                                                                                                   |
| ❌                                                                                                                                                         | Not supported                                                                                                                               |
| ![info](https://runbooks.ciscospaces.io/__attachments/a_9f797684df3ea7be221229a992659b49a4d20e52b5ca0beb98e6846f0a2a416b/atlassian-info?cb=feab5cd71111204d6b52545f3027dd0c)             | Technically Supported but**Not validated.**Recommend customers to validate the use-case in their environment before deploying in production |
| ⚠️                                                                                                                                                        | Technically Supported but **Not Recommended**. Known performance limitation due to older generation chipset                                 |
| 🗓️                                                                                                                                                       | Roadmap item. To be released at a future date.                                                                                              |

---
language: "en"
---
# Changelog - 2025.03

## 2025.03

### 🛠️ Runbooks

* [**Cisco Spaces Smart Rooms Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-rooms-runbook-cisco-validated)

  ➤ Documentation was added explaining how Cisco Spaces uses Webex devices as occupancy sensors to control building HVAC systems and the benefits of this integration, including energy savings and optimized wellbeing. Clarified prerequisites for using this feature now include having a BACnet BMS, room-level HVAC controls, an active Cisco Spaces license with rich maps, and Webex Control Hub integration.

*** ** * ** ***

* [**Cisco Spaces OpenRoaming Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated)

  ➤ Updated documentation clarifies the required minimum Meraki firmware version for Wi-Fi onboarding is now R31.1.6 and specifies the necessary user permissions for setup in OpenRoaming, DNA Spaces, Meraki Dashboard/WLC, and Connector. The process for enabling OpenRoaming with the Cisco Spaces Support team is also outlined.

*** ** * ** ***

* [**Cisco Spaces Indoor Navigation Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-indoor-navigation-runbook-cisco-valid)

  ➤ Clarified administrator permissions required for Space Experience and IOT Services setup. Added information about the minimal impact of Bluetooth Low Energy (BLE) on Wi-Fi usage in indoor navigation and provided a link to the Cisco DNA Spaces privacy data sheet.

*** ** * ** ***

* [**Cisco Spaces Smart Workspaces Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida)

  ➤ Clarified setup steps now specify required read/write permissions for Spaces, Webex Control Hub, and/or Meraki Dashboard. Troubleshooting information was added for Webex devices in Digital Signage mode not appearing in Space Experience and for configuring "Where am I" characters on floor views, along with expanded details about Meraki camera requirements and Space Explorer kiosk configuration.

*** ** * ** ***

* [**Cisco Spaces OS Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated)

  ➤ Spaces OS installation now requires admin read/write access for Cisco Spaces, Catalyst Center, WLC, Meraki Dashboard, and Webex Control Hub, as applicable. Updated guidance on CAD file best practices and troubleshooting for Digital Map creation has been added, including details on re-uploading files, handling location hierarchy changes, and campus wayfinding considerations.

*** ** * ** ***

* [**Cisco Spaces Asset Tracking Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-asset-tracking-runbook-cisco-validate)

  ➤ Meraki deployments now use the AP's BLE radio directly, simplifying deployment but limiting functionality to base gateway features like Eddystone and iBeacon formats. Additionally, the documentation now clarifies that read/write permissions in Spaces for IOT Services and IOT Explorer are required for certain configurations.

*** ** * ** ***

* [**Cisco Spaces Occupancy Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-runbook-cisco-validated)

  ➤ Documentation was added for Space Utilization, a new app that helps optimize space usage and plan for hybrid work. Detailed information on PIR sensors for occupancy detection, including setup, best practices, and troubleshooting, was also added.

---
language: "en"
---
# Changelog - 2025.04

## 2025.04

### 🛠️ Runbooks

* [**Cisco Spaces Smart Rooms Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-rooms-runbook-cisco-validated)

  ➤ This update adds information on configuring BMS Edge Service, including required network connectivity details and monitoring procedures for Cisco Smart Room Gateway and BMS communication. It also clarifies how the BMS and Cisco Spaces monitor each other's connection status and handle connection loss.

*** ** * ** ***

* [**Cisco Spaces OpenRoaming Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated)

  ➤ Clarified that this documentation should only be used after completing the Spaces OS Runbook, which covers all prerequisites for OpenRoaming. The caveats, tips, and FAQ sections were removed.

*** ** * ** ***

* [**Cisco Spaces Indoor Navigation Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-indoor-navigation-runbook-cisco-valid)

  ➤ The Spaces OS Runbook is now required reading before using this document. Caveats and tips were removed.

*** ** * ** ***

* [**Cisco Spaces Smart Workspaces Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida)

  ➤ Updated documentation clarifies how to set up digital signage, now referred to as "Space Explorer - Kiosk app," with detailed instructions for Webex and non-Webex devices. It also includes information about the Cisco Spaces IoT Device Marketplace and using Meraki cameras for people counting and other metrics.

*** ** * ** ***

* [**Cisco Spaces OS Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated)

  ➤ Added instructions for setting up Webex Control Hub integrations with Cisco Spaces, including pre-requisites and step-by-step configuration details for Locations, Workspace Metrics, Workspace Configurations, and the integration itself. This update clarifies how to properly structure Locations and Floors in Control Hub for optimal Cisco Spaces functionality and provides best practices for a smoother setup experience.

*** ** * ** ***

* [**Cisco Spaces Asset Tracking Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-asset-tracking-runbook-cisco-validate)

  ➤ The Spaces OS Runbook is now required reading before using this document. Caveats, tips, and the FAQ section have been removed.

*** ** * ** ***

* [**Cisco Spaces Occupancy Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-runbook-cisco-validated)

  ➤ Added prerequisites and overview information for using Cisco Spaces. Clarified details about device compatibility, adding room occupancy capacity, and removing sensors within Space Manager, while removing outdated FAQ and some redundant phrasing.

*** ** * ** ***

### 📚 Knowledge Articles

* [**Digital Map Pro and CAD/DWG/PDF Best Practices**](https://runbooks.ciscospaces.io/docs/digital-map-pro-and-cad-dwg-pdf-best-practices)

  ➤ CAD files uploaded for AI processing should now exclude employee names if you wish to keep them private within the Digital Map Editor and other applications. Previously, there was no guidance on including or omitting employee names in these files.

*** ** * ** ***

* [**Cisco Spaces Device Compatibility Matrices**](https://runbooks.ciscospaces.io/docs/cisco-spaces-device-compatibility-matrices)

  ➤ Clarified device compatibility information, specifying that only Meraki-branded devices work with Meraki and non-branded devices work with Catalyst. Added details on Cisco Collaboration device compatibility for various features, including sensor functionality in MTR mode and requirements for people counting and environmental data.

*** ** * ** ***

* [**OpenRoaming: Cisco Spaces SDK Integration**](https://runbooks.ciscospaces.io/docs/openroaming-cisco-spaces-sdk-integration)

  ➤ Minor formatting or metadata update.

*** ** * ** ***

* [**OpenRoaming: Carrier Offload with a Partner App (Generic Auto-Attach)**](https://runbooks.ciscospaces.io/docs/openroaming-carrier-offload-with-a-partner-app-gen)

  ➤ Minor formatting or metadata update.

*** ** * ** ***

* [**OpenRoaming: Carrier Offload with a Partner App (AT\&T Auto-Attach)**](https://runbooks.ciscospaces.io/docs/openroaming-carrier-offload-with-a-partner-app-att)

  ➤ Minor formatting or metadata update.

---
language: "en"
---
# Changelog - 2025.05

## 2025.05

### 🛠️ Runbooks

* [**Cisco Spaces Smart Rooms Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-rooms-runbook-cisco-validated)

  ➤ Minor formatting or metadata update.

*** ** * ** ***

* [**Cisco Spaces OpenRoaming Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated)

  ➤ This runbook now clarifies the OpenRoaming onboarding process for Meraki networks, emphasizing that all Meraki-related configurations (including SSIDs, VLANs, and RADIUS authentication) must be completed *before* configuring OpenRoaming in Cisco Spaces. It also provides updated links to relevant documentation and knowledge articles for setup and troubleshooting, including information about activating carrier offloading partners.

*** ** * ** ***

* [**Cisco Spaces Indoor Navigation Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-indoor-navigation-runbook-cisco-valid)

  ➤ Documentation was updated to include several new Catalyst WLC managed AP models (9172I, 9176I, 9176D, and 9178I), with a note about the CW9176D's non-omnidirectional BLE radio and potential impact on accuracy. Information was also added regarding Wi-Fi 7 model support for Indoor Navigation (currently in validation) and clarified prerequisites for Campus Wayfinding, including location hierarchy grouping and geo-alignment considerations.

*** ** * ** ***

* [**Cisco Spaces Smart Workspaces Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida)

  ➤ Updated setup instructions for non-Webex devices and digital kiosk configuration were moved to a new location in the Cisco Spaces Smart Workspaces Runbook. Troubleshooting steps for unresponsive displays during kiosk setup were also clarified and simplified.

*** ** * ** ***

* [**Cisco Spaces OS Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated)

  ➤ Added a reference to a Knowledge Article for detailed best practices and removed a previous link to a guide with similar information, as well as a reference to OpenStreetMap.

*** ** * ** ***

* [**Cisco Spaces Asset Tracking Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-asset-tracking-runbook-cisco-validate)

  ➤ Minor formatting or metadata update.

*** ** * ** ***

* [**Cisco Spaces Occupancy Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-runbook-cisco-validated)

  ➤ No content was added or removed.

*** ** * ** ***

### 📚 Knowledge Articles

* [**Digital Map Pro and CAD/DWG/PDF Best Practices**](https://runbooks.ciscospaces.io/docs/digital-map-pro-and-cad-dwg-pdf-best-practices)

  ➤ Documentation was added to describe the new Space Explorer Kiosk App quick access types and special styling available for specific space types within Cisco Spaces Digital Maps. Note that the application may be updated prior to documentation and the product UI should be considered the source of truth.

*** ** * ** ***

* [**Cisco Spaces Device Compatibility Matrices**](https://runbooks.ciscospaces.io/docs/cisco-spaces-device-compatibility-matrices)

  ➤ Clarified device compatibility for Workspaces by indicating devices that are still in testing and not yet generally available. A table of kiosk display compatibility for Workspaces was also added.

*** ** * ** ***

* [**OpenRoaming: Cisco Spaces SDK Integration**](https://runbooks.ciscospaces.io/docs/openroaming-cisco-spaces-sdk-integration)

  ➤ Clarified that this article follows the Cisco Spaces OpenRoaming Runbook. Instructions for enabling push notifications on iOS and Android were reworded for conciseness.

*** ** * ** ***

* [**OpenRoaming: Carrier Offload with a Partner App (Generic Auto-Attach)**](https://runbooks.ciscospaces.io/docs/openroaming-carrier-offload-with-a-partner-app-gen)

  ➤ Instructions for enabling and configuring the OpenRoaming app were updated to reference the Cisco Spaces OpenRoaming Runbook. A link to a video guided demo was removed.

*** ** * ** ***

* [**OpenRoaming: Carrier Offload with a Partner App (AT\&T Auto-Attach)**](https://runbooks.ciscospaces.io/docs/openroaming-carrier-offload-with-a-partner-app-att)

  ➤ Instructions for enabling and configuring the OpenRoaming app were updated to reference the Cisco Spaces OpenRoaming Runbook, replacing a video demonstration.

*** ** * ** ***

* [**Guide to Network Map Geo-Placement and Best Practices**](https://runbooks.ciscospaces.io/docs/guide-to-network-map-geoplacementand-best-practice)

  ➤ Minor formatting or metadata update.

*** ** * ** ***

* [**Split Licensing**](https://runbooks.ciscospaces.io/docs/split-licensing)

  ➤ Minor formatting or metadata update.

---
language: "en"
---
# Changelog - 2025.06

## 2025.06

### 🛠️ Runbooks

* [**Cisco Spaces OpenRoaming Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated)

  ➤ Meraki network configuration for SSIDs and VLANs must now be done entirely within the Meraki dashboard. This update clarifies that *all* SSID configuration, not just OpenRoaming-related settings, needs to be handled in the dashboard.

*** ** * ** ***

* [**Cisco Spaces Indoor Navigation Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-indoor-navigation-runbook-cisco-valid)

  ➤ Documentation for several Catalyst WLC managed AP models (9105, 9115, and 9120) has been removed, and no new AP models have been added.

*** ** * ** ***

* [**Cisco Spaces Smart Workspaces Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida)

  ➤ Information on factory resetting and setup in PWA mode was initially added and then removed from this update, resulting in no net change for readers.

*** ** * ** ***

* [**Cisco Spaces OS Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated)

  ➤ Connector scaling information and best practices were added, including example use cases and recommended configurations for location services, IoT services, or a combination of both. Guidance for high availability deployments was also added with links to regional resources.

*** ** * ** ***

* [**Cisco Spaces Asset Tracking Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-asset-tracking-runbook-cisco-validate)

  ➤ Added instructions for deploying asset tracking without Catalyst Center, including using CAD files for AP auto-location and leveraging Excel for location hierarchy creation. New information was also added regarding using the 9170 Series for asset tracking and clarifying the appropriate applications/APIs for accessing location data.

*** ** * ** ***

* [**Cisco Spaces Occupancy Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-runbook-cisco-validated)

  ➤ Documentation was added regarding device compatibility, configurations, and meeting zones in Webex Control Hub or on devices. Information about minimum versions and connector guidance was removed.

*** ** * ** ***

### 📚 Knowledge Articles

* [**Cisco Spaces Device Compatibility Matrices**](https://runbooks.ciscospaces.io/docs/cisco-spaces-device-compatibility-matrices)

  ➤ Added support information for several Cisco Board and Desk devices, including whether they are fully functional and support MTR. Clarified the support status by replacing the "Tested + Validated/Unsupported" categories with more specific functional descriptions.

*** ** * ** ***

* [**Split Licensing**](https://runbooks.ciscospaces.io/docs/split-licensing)

  ➤ Updated licensing information explains how to use split licensing features, now pointing to the Cisco Spaces Configuration Guide instead of a separate knowledge article.

---
language: "en"
---
# Changelog - 2025.07

## 2025.07

### 🛠️ Runbooks

* [**Cisco Spaces OpenRoaming Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated)

  ➤ Minor formatting or metadata update.

*** ** * ** ***

* [**Cisco Spaces Indoor Navigation Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-indoor-navigation-runbook-cisco-valid)

  ➤ The list of supported Catalyst WLC managed access points was updated to include models 9115, 9120. While some models were seemingly removed and re-added, the net effect is the addition of these two new models to the supported list.

*** ** * ** ***

* [**Cisco Spaces Smart Workspaces Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida)

  ➤ Troubleshooting steps were added for Cisco Collaboration devices configured in Digital Signage mode that don't appear in Cisco Spaces. Guidance was also added for configuring the "Where am I?" character on a floor view.

*** ** * ** ***

* [**Cisco Spaces Asset Tracking Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-asset-tracking-runbook-cisco-validate)

  ➤ Documentation was updated to include supported operational modes (Rx, Tx, and Dual) for Advanced APs, specifically recommending them for Spaces Outcomes. Clarification was also added regarding the non-recommendation of specific Aironet and Catalyst APs (9115, 9117, 1815, 1840, and 4800) for IoT services.

*** ** * ** ***

* [**Cisco Spaces Occupancy Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-runbook-cisco-validated)

  ➤ Clarified setup and configuration details for Portal Beam devices, including installation steps and troubleshooting tips. Expanded information on occupancy reporting, including sensor placement for Thingsee PRESENCE and explanations of data fields like "Peak People Count".

---
language: "en"
---
# Changelog - 2025.08

## 2025.08

### 🛠️ Runbooks

* [**Space Explorer Web App**](https://runbooks.ciscospaces.io/docs/space-explorer-web-app)

  ➤ New article.

*** ** * ** ***

* [**Cisco Spaces Captive Portal Runbook**](https://runbooks.ciscospaces.io/docs/cisco-spaces-captive-portal-runbook)

  ➤ Documentation was added for Captive Portal firewall ports and routing, including specific IP addresses and URLs for walled garden configurations. Clarifications were also made to the captive portal setup steps, including where to find radius server details and how to apply walled garden settings.

*** ** * ** ***

* [**Cisco Spaces OpenRoaming Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated)

  ➤ OpenRoaming now requires specific firewall rules to allow inbound traffic for essential functionality, including RADIUS, RADSEC, and HTTPS for certificate signing. A table detailing the required source/destination IPs, ports, and protocols for these rules has been added.

*** ** * ** ***

* [**Cisco Spaces Indoor Navigation Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-indoor-navigation-runbook-cisco-valid)

  ➤ Updated software version requirements for Catalyst 9800 WLCs now specify using either version 17.12.4 or 17.15.1, removing previous support for version 17.9.6 and clarifying that other versions are not officially supported.

*** ** * ** ***

* [**Cisco Spaces Smart Workspaces Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida)

  ➤ Documentation was updated to provide details on Cisco Spaces Calendar Integrations and clarify the process of assigning Meraki Things sensors to meeting rooms within Space Manager. Expanded information and visuals were also added for visualizing outcomes with Meraki Things sensors, including how sensor data is aggregated and displayed.

*** ** * ** ***

* [**Cisco Spaces OS Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated)

  ➤ Updated VM requirements for the Production configuration were added, along with guidance on maintaining metadata consistency when uploading revised CAD files to Cisco Spaces. Clarification was also provided on how Webex Workspaces and IoT Sensors are handled during CAD file re-uploads.

*** ** * ** ***

* [**Cisco Spaces Asset Tracking Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-asset-tracking-runbook-cisco-validate)

  ➤ Updated terminology and information were added for Wi-Fi 6, Wi-Fi 6E, and the new Wi-Fi 7 standard, including details about the 9170 Series with UWB capabilities. Inconsistent naming conventions for Wi-Fi 6 and Wi-Fi 6E were also corrected.

*** ** * ** ***

* [**Cisco Spaces Occupancy Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-runbook-cisco-validated)

  ➤ Support for IOS-XE versions earlier than 17.9.6, along with specific versions within 17.9 and later, has been removed due to critical BLE bug fixes present only in the supported versions. The documentation now clarifies that only IOS-XE 17.12.4+ and 17.15.1+ are supported for BLE functionality.

*** ** * ** ***

### 📚 Knowledge Articles

* [**Cisco Spaces Calendar Integrations (Webex Hybrid Calendar/O365/Gcal)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-calendar-integrations-webex-hybrid-ca)

  ➤ MTR devices now support Hybrid Calendar. No other content was removed or modified.

*** ** * ** ***

* [**Digital Map Pro and CAD/DWG/PDF Best Practices**](https://runbooks.ciscospaces.io/docs/digital-map-pro-and-cad-dwg-pdf-best-practices)

  ➤ A preview of the new Wayfinding Custom POI and Path Editor in the Cisco Spaces Dashboard was added, allowing admins greater control over wayfinding in the Space Explorer Kiosk and Spaces Premier for Wireless apps. Documentation was also updated to clarify the process and scenarios for re-uploading CAD files for Digital Maps, including handling missing objects, changing locations, and adding/modifying floors.

*** ** * ** ***

### 🤝 Partner Ecosystem Guides

* [**Cisco Spaces Partner Ecosystem Overview**](https://runbooks.ciscospaces.io/docs/cisco-spaces-partner-ecosystem-overview)

  ➤ New article.

---
language: "en"
---
# Changelog - 2025.09

## 2025.09

### 🛠️ Runbooks

* [**Cisco Spaces Captive Portal Runbook**](https://runbooks.ciscospaces.io/docs/cisco-spaces-captive-portal-runbook)

  ➤ The documentation now mandates that Wireless Access Points (WAPs) are assigned to floor maps in Catalyst Centre to ensure they appear in the Cisco Spaces Location Hierarchy, a prerequisite for Captive Portal redirection. It also updates the Captive Portal SSID creation process within Cisco Spaces and provides a new, specific method to retrieve the Splash Page URL from the "View Config Guide," replacing previous explicit instructions for configuring URL filters and ACLs on the Catalyst 9800.

*** ** * ** ***

* [**Cisco Spaces OS Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated)

  ➤ The documentation now provides specific guidelines for optimal AP placement, including perimeter coverage, density, maximum AP-AP distance, and signal strength requirements, to enhance Cisco Spaces outcomes. These guidelines help users ensure effective AP deployment for location-based services.

*** ** * ** ***

* [**Space Explorer Web App**](https://runbooks.ciscospaces.io/docs/space-explorer-web-app)

  ➤ The Space Explorer Web App now supports Smart Desking (hot desking) with expanded SSO login options, including Webex, Microsoft, and Google, and makes admin consent for user login optional for a smoother experience. Desk booking functionality requires a Spaces Premier for Wireless license and integrates with RoomOS or PhoneOS devices configured for hot desking.

*** ** * ** ***

### 📚 Knowledge Articles

* [**Catalyst AP Capability Matrix**](https://runbooks.ciscospaces.io/docs/catalyst-ap-capability-matrix) 🆕

  ➤ This Catalyst AP Capability Matrix table provides a reference for Access Point features, primarily focusing on models with integrated omni-directional antennas. It also details IOT Radio feature support (scanning + beaconing) and Space Utilization for APs with external and directional antennas.

*** ** * ** ***

* [**Upgrading Smart Workspaces Kiosk/Signage Version**](https://runbooks.ciscospaces.io/docs/upgrading-smart-workspaces-kiosk-signage-version)

  ➤ The documentation now specifies that Kiosk v2.0 upgrades are supported in both US (.io) and Singapore (.sg) environments, with .eu support planned for Fall 2025. Additionally, it introduces Kiosk v2.1, detailing its upgrade path from v2.0 and providing links to its feature overview and release notes.

---
language: "en"
---
# Changelog - 2025.10

## October 2025

### 🛠️ Runbooks

* [**Cisco Spaces Asset Tracking Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-asset-tracking-runbook-cisco-validate)

  ➤ Minor formatting or whitespace changes.

* [**Cisco Spaces Captive Portal Runbook**](https://runbooks.ciscospaces.io/docs/cisco-spaces-captive-portal-runbook)

  ➤ Updates captive portal configuration including RADIUS integration and guest access workflows. Provides step-by-step instructions for customizing splash pages and branding. Covers authentication options including social login, SMS verification, and sponsored access. Includes troubleshooting guidance for common connectivity issues.

* [**Cisco Spaces Occupancy Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-runbook-cisco-validated)

  ➤ Enhances occupancy monitoring setup with improved sensor configuration and threshold tuning. Includes guidance on defining occupancy zones and capacity limits. Covers real-time dashboard configuration and alerting setup. Provides best practices for accurate counting in various room types and layouts.

* [**Cisco Spaces OS Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated)

  ➤ Refines Cisco Spaces deployment procedures and administrative configuration steps. Covers network integration requirements and firewall configuration. Includes user provisioning, role-based access control, and SSO setup. Provides guidance on dashboard customization and analytics configuration.

* [**Cisco Spaces Smart Workspaces Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida)

  ➤ Updates Microsoft Teams Rooms integration and workspace booking configuration. Covers desk and room reservation system setup with calendar synchronization. Includes guidance on configuring occupancy-based release policies. Provides instructions for deploying wayfinding and space utilization analytics.

* [**Space Explorer Web App**](https://runbooks.ciscospaces.io/docs/space-explorer-web-app)

  ➤ Improves Space Explorer navigation and location analytics visualization features. Covers map navigation, floor plan viewing, and real-time device location tracking. Includes guidance on using search and filtering capabilities. Provides tips for analyzing space utilization trends and generating reports.

*** ** * ** ***

### 📚 Knowledge Articles

* [**Catalyst AP Capability Matrix**](https://runbooks.ciscospaces.io/docs/catalyst-ap-capability-matrix)

  ➤ Minor formatting or whitespace changes.

* [**Cisco Spaces Device Compatibility Matrices**](https://runbooks.ciscospaces.io/docs/cisco-spaces-device-compatibility-matrices)

  ➤ Updates supported device models and firmware version requirements. Lists all compatible access points, sensors, and cameras with feature availability. Includes minimum software version requirements for each capability. Provides guidance on upgrade paths and compatibility considerations.

* [**Counting People from Meraki Video (MV) Cameras**](https://runbooks.ciscospaces.io/docs/counting-people-from-meraki-video-mv-cameras) 🆕

  ➤ Instructions for setting up camera-based people counting with Meraki MV, including placement guidelines and analytics configuration. Covers counting line definition, zone configuration, and dashboard setup. Includes optimal mounting heights, angles, and lighting considerations. Provides accuracy optimization techniques and troubleshooting for common scenarios.

* [**Counting People from Wi-Fi**](https://runbooks.ciscospaces.io/docs/counting-people-from-wifi)

  ➤ Enhances Wi-Fi based people counting accuracy settings and detection zone configuration. Covers RSSI threshold tuning and dwell time settings. Includes guidance on reducing false positives and handling edge cases. Provides best practices for entrance/exit counting and directional detection.

* [**Unified Location Hierarchy Best Practices**](https://runbooks.ciscospaces.io/docs/unified-location-hierarchy-best-practices)

  ➤ Refines location hierarchy structure and floor plan mapping best practices. Covers building, floor, and zone organization strategies. Includes guidance on importing and calibrating floor plans. Provides recommendations for naming conventions and metadata tagging.

*** ** * ** ***

### 🤝 Partner Ecosystem Guides

* [**Cisco Spaces Partner Ecosystem Overview**](https://runbooks.ciscospaces.io/docs/cisco-spaces-partner-ecosystem-overview)

  ➤ Minor update to offers, range content.

---
language: "en"
---
# Changelog - 2025.11

## November 2025

### 🛠️ Runbooks

* [**Cisco Spaces Indoor Navigation Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-indoor-navigation-runbook-cisco-valid)

  ➤ Minor formatting or whitespace changes.

*** ** * ** ***

### 📚 Knowledge Articles

* [**Cisco Spaces Calendar Integrations (Webex Hybrid Calendar/O365/Gcal)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-calendar-integrations-webex-hybrid-ca)

  ➤ Updated documentation with improved clarity and accuracy. Includes refined procedures and updated configuration guidance. Covers recent feature changes and enhancements. Provides additional examples and troubleshooting information.

* [**Cisco Spaces Design \& Deployment Module FAQ**](https://runbooks.ciscospaces.io/docs/cisco-spaces-design-deployment-module-faq) 🆕

  ➤ New documentation providing detailed guidance and configuration instructions. Covers key concepts, procedures, and best practices for successful implementation. Includes examples and validation steps. Provides troubleshooting information for common issues.

* [**Upgrading Smart Workspaces Kiosk/Signage Version**](https://runbooks.ciscospaces.io/docs/upgrading-smart-workspaces-kiosk-signage-version)

  ➤ Updated documentation with improved clarity and accuracy. Includes refined procedures and updated configuration guidance. Covers recent feature changes and enhancements. Provides additional examples and troubleshooting information.

---
language: "en"
---
# Changelog - 2025.12

## December 2025

### 🛠️ Runbooks

* [**Cisco Spaces OpenRoaming Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated)

  ➤ Updates deployment procedures and configuration best practices. Includes step-by-step instructions for common setup scenarios. Covers troubleshooting guidance and known issue workarounds. Provides reference information for advanced configuration options.

*** ** * ** ***

### 📚 Knowledge Articles

* [**Cisco Spaces Device Compatibility Matrices**](https://runbooks.ciscospaces.io/docs/cisco-spaces-device-compatibility-matrices)

  ➤ Updates supported device models and firmware version requirements. Lists all compatible access points, sensors, and cameras with feature availability. Includes minimum software version requirements for each capability. Provides guidance on upgrade paths and compatibility considerations.

* [**Digital Map Pro and CAD/DWG/PDF Best Practices**](https://runbooks.ciscospaces.io/docs/digital-map-pro-and-cad-dwg-pdf-best-practices)

  ➤ Refines recommended approaches and implementation guidance. Covers proven strategies from successful deployments. Includes common pitfalls to avoid and optimization tips. Provides checklists and validation procedures.

---
language: "en"
---
# Changelog - 2026.01

## January 2026

### 🛠️ Runbooks

* [**Cisco Spaces Occupancy Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-runbook-cisco-validated)

  ➤ Enhances occupancy monitoring setup with improved sensor configuration and threshold tuning. Includes guidance on defining occupancy zones and capacity limits. Covers real-time dashboard configuration and alerting setup. Provides best practices for accurate counting in various room types and layouts.

*** ** * ** ***

* [**Cisco Spaces Smart Workspaces Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida)

  ➤ Updates Microsoft Teams Rooms integration and workspace booking configuration. Covers desk and room reservation system setup with calendar synchronization. Includes guidance on configuring occupancy-based release policies. Provides instructions for deploying wayfinding and space utilization analytics.

*** ** * ** ***

### 📚 Knowledge Articles

* [**Digital Map Pro and CAD/DWG/PDF Best Practices**](https://runbooks.ciscospaces.io/docs/digital-map-pro-and-cad-dwg-pdf-best-practices)

  ➤ Refines recommended approaches and implementation guidance. Covers proven strategies from successful deployments. Includes common pitfalls to avoid and optimization tips. Provides checklists and validation procedures.

*** ** * ** ***

* [**Guide to Network Map Geo-Placement and Best Practices**](https://runbooks.ciscospaces.io/docs/guide-to-network-map-geoplacementand-best-practice)

  ➤ Refines recommended approaches and implementation guidance. Covers proven strategies from successful deployments. Includes common pitfalls to avoid and optimization tips. Provides checklists and validation procedures.

*** ** * ** ***

* [**Upgrading Smart Workspaces Kiosk/Signage Version**](https://runbooks.ciscospaces.io/docs/upgrading-smart-workspaces-kiosk-signage-version)

  ➤ Updates documentation with improved clarity and accuracy. Includes refined procedures and updated configuration guidance. Covers recent feature changes and enhancements. Provides additional examples and troubleshooting information.

---
language: "en"
---
# Changelog - 2026.02

## February 2026

### 🛠️ Runbooks

* [**Cisco Spaces Occupancy Day 2 Guide**](https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-day-2-guide)

  ➤ Enhances step-by-step instructions and configuration examples. Covers prerequisites and planning considerations. Includes validation steps and expected outcomes. Provides troubleshooting tips for common issues.

* [**Cisco Spaces Occupancy Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-runbook-cisco-validated)

  ➤ Minor update to managed content.

* [**Cisco Spaces OS Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated)

  ➤ Refines Cisco Spaces deployment procedures and administrative configuration steps. Covers network integration requirements and firewall configuration. Includes user provisioning, role-based access control, and SSO setup. Provides guidance on dashboard customization and analytics configuration.

* [**Cisco Spaces Smart Workspaces Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida)

  ➤ Updates Microsoft Teams Rooms integration and workspace booking configuration. Covers desk and room reservation system setup with calendar synchronization. Includes guidance on configuring occupancy-based release policies. Provides instructions for deploying wayfinding and space utilization analytics.

* [**Space Explorer Web App**](https://runbooks.ciscospaces.io/docs/space-explorer-web-app)

  ➤ Improves Space Explorer navigation and location analytics visualization features. Covers map navigation, floor plan viewing, and real-time device location tracking. Includes guidance on using search and filtering capabilities. Provides tips for analyzing space utilization trends and generating reports.

*** ** * ** ***

### 📚 Knowledge Articles

* [**Cisco Spaces Calendar Integrations (Webex Hybrid Calendar/O365/Gcal)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-calendar-integrations-webex-hybrid-ca)

  ➤ Updates documentation with improved clarity and accuracy. Includes refined procedures and updated configuration guidance. Covers recent feature changes and enhancements. Provides additional examples and troubleshooting information.

*** ** * ** ***

### 🤝 Partner Ecosystem Guides

* [**Infant Protection with Securitas Healthcare and Cisco Spaces**](https://runbooks.ciscospaces.io/docs/infant-protection-with-securitas-healthcare-and-ci)

  ➤ Updates documentation with improved clarity and accuracy. Includes refined procedures and updated configuration guidance. Covers recent feature changes and enhancements. Provides additional examples and troubleshooting information.

* [**Staff Duress with Kontakt.io and Cisco Spaces**](https://runbooks.ciscospaces.io/docs/staff-duress-with-kontaktio-and-cisco-spaces) 🆕

  ➤ New documentation providing detailed guidance and configuration instructions. Covers key concepts, procedures, and best practices for successful implementation. Includes examples and validation steps. Provides troubleshooting information for common issues.

---
language: "en"
---
# Changelog - 2026.03

## March 2026

### 🛠️ Runbooks

* [**Cisco Spaces Occupancy Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-runbook-cisco-validated)

  ➤ Enhances occupancy monitoring setup with improved sensor configuration and threshold tuning. Includes guidance on defining occupancy zones and capacity limits. Covers real-time dashboard configuration and alerting setup. Provides best practices for accurate counting in various room types and layouts.

* [**Cisco Spaces OS Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated)

  ➤ Refines Cisco Spaces deployment procedures and administrative configuration steps. Covers network integration requirements and firewall configuration. Includes user provisioning, role-based access control, and SSO setup. Provides guidance on dashboard customization and analytics configuration.

* [**Cisco Spaces Smart Workspaces Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida)

  ➤ Updates Microsoft Teams Rooms integration and workspace booking configuration. Covers desk and room reservation system setup with calendar synchronization. Includes guidance on configuring occupancy-based release policies. Provides instructions for deploying wayfinding and space utilization analytics.

* [**Space Explorer Web App**](https://runbooks.ciscospaces.io/docs/space-explorer-web-app)

  ➤ Improves Space Explorer navigation and location analytics visualization features. Covers map navigation, floor plan viewing, and real-time device location tracking. Includes guidance on using search and filtering capabilities. Provides tips for analyzing space utilization trends and generating reports.

*** ** * ** ***

### 📚 Knowledge Articles

* [**Catalyst AP Capability Matrix**](https://runbooks.ciscospaces.io/docs/catalyst-ap-capability-matrix)

  ➤ Updates Catalyst access point feature support and capability requirements. Details which location services features are available on each AP model. Includes antenna and deployment mode considerations. Covers firmware requirements and feature enablement procedures.

* [**Cisco Spaces Design \& Deployment Module FAQ**](https://runbooks.ciscospaces.io/docs/cisco-spaces-design-deployment-module-faq)

  ➤ Updates documentation with improved clarity and accuracy. Includes refined procedures and updated configuration guidance. Covers recent feature changes and enhancements. Provides additional examples and troubleshooting information.

* [**Export your Existing Catalyst Center Floor maps into an Ekahau RF Predictive Project**](https://runbooks.ciscospaces.io/docs/export-your-existing-catalyst-center-floor-maps-in) 🆕

  ➤ New documentation providing detailed guidance and configuration instructions. Covers key concepts, procedures, and best practices for successful implementation. Includes examples and validation steps. Provides troubleshooting information for common issues.

* [**IOT Services Deployment, Monitoring, and Troubleshooting Guide**](https://runbooks.ciscospaces.io/docs/iot-services-deployment-monitoring-and-troubleshoo) 🆕

  ➤ Detailed instructions and configuration examples for successful implementation. Covers prerequisites, step-by-step procedures, and validation steps. Includes screenshots and examples for clarity. Provides troubleshooting tips and answers to frequently asked questions.

*** ** * ** ***

### 🤝 Partner Ecosystem Guides

* [**Infant Protection with Securitas Healthcare and Cisco Spaces**](https://runbooks.ciscospaces.io/docs/infant-protection-with-securitas-healthcare-and-ci)

  ➤ Updates documentation with improved clarity and accuracy. Includes refined procedures and updated configuration guidance. Covers recent feature changes and enhancements. Provides additional examples and troubleshooting information.

* [**Staff Duress with Kontakt.io and Cisco Spaces**](https://runbooks.ciscospaces.io/docs/staff-duress-with-kontaktio-and-cisco-spaces)

  ➤ Updates documentation with improved clarity and accuracy. Includes refined procedures and updated configuration guidance. Covers recent feature changes and enhancements. Provides additional examples and troubleshooting information.

---
language: "en"
---
# Changelog - 2026.04

## April 2026

### 🛠️ Runbooks

* [**Cisco Spaces OS Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated)

  ➤ The "Cisco Spaces OS Runbook (Cisco Validated)" page was updated to include Nutanix as a supported platform for Spaces Connector and add a link to the "Connector Configuration" page for more details. New "Device Occupancy Configurations" with recommended values were added, along with a note about optional per-room overrides being replaced by "Device Configurations in Control Hub." The "Health Check" section was removed, and a new FAQ entry was added explaining how to confirm if netconf is enabled on a WLC.
* [**Cisco Spaces Smart Workspaces Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida)

  ➤ The "Kiosk List of API Endpoints for Firewall Settings" section was updated to clarify that all listed domains use port 443 and to explicitly label "Required" and "Optional" endpoints. The "temporary: \*.amazonaws.com" endpoint now includes a note about "Smart Rooms \& Custom Logo." Additionally, a new URL for clearing device storage was added for the US and rest of world region.
* [**Space Explorer Web App**](https://runbooks.ciscospaces.io/docs/space-explorer-web-app)

  ➤ The "Spaces Infrastructure" section was updated to specify support for the ".io" data center region, with ".eu" and ".sg" regions marked as "ROADMAP." The "Making Meeting Rooms from Digital Maps Bookable" section was added, detailing prerequisites and steps to enable Room Booking via "Location \& Room Overrides" and "Room overrides" in the Cisco Spaces dashboard. Additionally, the "Assigning 3rd Party IoT Sensors to Bookable ("Hot") Desks" feature is now explicitly marked as a "ROADMAP" feature.

*** ** * ** ***

### 📚 Knowledge Articles

* [**Counting People from Meraki Video (MV) Cameras**](https://runbooks.ciscospaces.io/docs/counting-people-from-meraki-video-mv-cameras)

  ➤ Added a link to the "MV33/93 (Gen 3) - Placement \& Configuration Guide" under the "Must Read" section.
* [**Digital Map Pro and CAD/DWG/PDF Best Practices**](https://runbooks.ciscospaces.io/docs/digital-map-pro-and-cad-dwg-pdf-best-practices)

  ➤ Added information about using "Hatch Patterns" in CAD files to block out or show specific areas of a map, which will be given 100% wall height and will not process metadata. Also added a new FAQ section, "How can I hide rooms or areas of the map?", detailing methods including changing Space Type or using Hatch Patterns.
* [**IOT Services Deployment, Monitoring, and Troubleshooting Guide**](https://runbooks.ciscospaces.io/docs/iot-services-deployment-monitoring-and-troubleshoo)

  ➤ Minor formatting or whitespace changes only.

*** ** * ** ***

### 🤝 Partner Ecosystem Guides

* [**Partner Runbook with Cisco Spaces**](https://runbooks.ciscospaces.io/docs/partner-runbook-with-cisco-spaces) 🆕

  ➤ New Partner Runbook for Cisco Spaces provides comprehensive guidance on infrastructure setup, including Cisco Hardware and Software Components, Cisco Spaces Prerequisites, and Catalyst Center/Prime Infrastructure configuration. It details installation and configuration steps, integration validation, troubleshooting, and support, with sections on Reference Architectures and how components interact. The runbook also includes an FAQ and a feedback mechanism for continuous improvement.
* [**Staff Duress with Kontakt.io and Cisco Spaces**](https://runbooks.ciscospaces.io/docs/staff-duress-with-kontaktio-and-cisco-spaces)

  ➤ The "Staff Duress with Kontakt.io and Cisco Spaces" page was updated to include more detailed information about Cisco Spaces Connector 3.x, Kio Cloud Partner App activation, and Kontakt.io device procurement. A new "INFRASTRUCTURE SETUP" section was added, detailing AP density, BLE design considerations, AP compatibility validation, and network design validation for accurate location tracking. The "Kontakt.io Prerequisites" section was also updated to reflect these changes.

---
language: "en"
---
# Changelog - 2026.05

## May 2026

### 🛠️ Runbooks

* [**Cisco Spaces Indoor Navigation Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-indoor-navigation-runbook-cisco-valid)

  ➤ The "Configuring the BLE Radios" section was updated to clarify that configuring BLE services can be done in bulk by the Cisco support team, rather than the "deployment team," and that the subsequent sections are for reference only.

* [**Cisco Spaces Occupancy Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-runbook-cisco-validated)

  ➤ The "Cisco Spaces Occupancy Runbook (Cisco Validated)" page was updated with a revised procedure for setting up and installing a Portal Beam using the Kio Setup Manager. The updated instructions include new details on device compatibility and connectivity, a more detailed installation workflow for both first-time and additional Portal Beams in a room, and a modified process for verifying thermal camera images and configuring Exclusion Zones.

* [**Space Explorer Web App**](https://runbooks.ciscospaces.io/docs/space-explorer-web-app)

  ➤ The "Space Explorer Web App" documentation now includes a tip for naming Kiosks, details on how Kiosk configuration impacts the app's default map view and Wayfinding, and clarifies that "Step 2: Widgets" and "Step 4: 'Where am I?'" have no impact. Additionally, the "Making Meeting Rooms from Digital Maps Bookable" section has been significantly expanded with a "Room Booking Feature Description," "Booking Options," and "Booking Workflows," while also updating pre-requisites and notes on unsupported room types.

*** ** * ** ***

### 📚 Knowledge Articles

* [**Counting People from Meraki Video (MV) Cameras**](https://runbooks.ciscospaces.io/docs/counting-people-from-meraki-video-mv-cameras)

  ➤ The "MV33/93 (Gen 3) - Placement \& Configuration Guide" link was removed from the "Must Read" section.

* [**IoT Device Guidance for MT EoS**](https://runbooks.ciscospaces.io/docs/iot-device-guidance-for-mt-eos) 🆕

  ➤ New guidance is available for Cisco Meraki customers using MT Sensors, which have reached End of Sale. This guide helps customers migrate to alternate 3rd party sensors available on the Cisco Spaces IoT Device Marketplace, providing a configuration guide and a list of comparable sensors for various use cases, including automation and duress.

* [**Multiple Authentication Methods on a Single Captive Portal**](https://runbooks.ciscospaces.io/docs/multiple-authentication-methods-on-a-single-captiv) 🆕

  ➤ Introduces **Captive Portal Multi-Auth** , allowing administrators to configure multiple authentication methods (e.g., Access Code, Social Sign-In, SMS with link verification) within a single captive portal to serve diverse visitor populations. Additionally, the **Data Capture workflow** has been enhanced to support **configurable custom form fields** for collecting specific visitor information. This update simplifies guest access management and improves data collection customization.

* [**Trusted Device Management in Captive Portal**](https://runbooks.ciscospaces.io/docs/trusted-device-management-in-captive-portal) 🆕

  ➤ New documentation for **Trusted Device Management in Captive Portal** details how administrators can allow specific devices to bypass captive portal authentication. It covers the benefits of using **Trusted Devices** , such as simplifying device onboarding and supporting non-browser devices, and outlines the procedures for creating a **Trusted Device Template** and adding **Trusted Devices** by their MAC addresses in Cisco Spaces.

* [**Upgrading Smart Workspaces Kiosk/Signage Version**](https://runbooks.ciscospaces.io/docs/upgrading-smart-workspaces-kiosk-signage-version)

  ➤ The Kiosk v2.1 Release Notes were updated with new features including Multi-Floor Pathfinder, a Rooms/Desks/All Spaces widget, and new Search filters. The Space Explorer Web App now supports Wayfinding App (Clip) cross-launch, Share functionality, and Room Booking. Space Manager updates include moving Room Occupancy Reports to the Space Utilization app and a new Tags field for desks. Space Experience introduces a new Floor View with floor selection options and new Settings for global Wayfinding QR code expiry, branding, and Kiosk \& Web App Location \& Room Overrides.

---
language: "en"
---
# Changelog - 2026.06

## June 2026

### 🛠️ Runbooks

* [**Cisco Spaces Captive Portal Runbook**](https://runbooks.ciscospaces.io/docs/cisco-spaces-captive-portal-runbook)

  ➤ Minor formatting or whitespace changes only.

* [**Cisco Spaces Indoor Navigation Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-indoor-navigation-runbook-cisco-valid)

  ➤ In the **Wireless Infrastructure** section under **Prerequisites** , the specific list of compatible Catalyst WLC managed AP models (such as 9115, 9120, 9130, and others) and the required Catalyst 9800 WLC software versions (17.12.4 or 17.15.1) have been removed. They are replaced with a reference directing users to the **AP Compatibility Matrix** guide for compatible models.

* [**Cisco Spaces Occupancy Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-runbook-cisco-validated)

  ➤ Removed "desk" from the list of real-time metrics, and clarified that desk-based outcomes are not currently available within Cisco Spaces, though desk sensor data can be accessed via the Firehose API. Additionally, moved the "Meta API (Firehose API)" real-time room occupancy feature from the unsupported functionality list to the supported historical/real-time outcomes section.

* [**Cisco Spaces OpenRoaming Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated)

  ➤ Updated the Meraki OpenRoaming prerequisites to specify required AP firmware versions (R31.1.6+ for Wi-Fi 7/6E/6 and R30.7.2+ for Wi-Fi 5/Wave 2) and added a fallback instruction to use a Cisco Spaces Connector if these requirements are not met. Added outbound firewall rules for Meraki-based deployments over port 2083 and clarified SSID naming requirements, noting that Meraki deployments must use a new, unique SSID while Catalyst and AireOS deployments can match existing SSIDs. Removed outdated instructions regarding Meraki backend feature flags, pre-configuring SSIDs in the Meraki dashboard, and manually enabling Hotspot Connectors for Meraki.

* [**Cisco Spaces OS Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated)

  ➤ Updated the "Cisco Spaces OS Runbook (Cisco Validated)" to clarify that the "AMI" installation option refers to "AWS AMI", updated the Connector Scaling production use cases to "Location only", and added a "hard limit" note to the 3,000 AP count for GRPC connections. Additionally, added port "8184 TCP (TDL)" to the IoT Services requirements, updated the cloud controller note to specify "customers with public/private cloud environments", and revised several UI navigation steps (such as changing "Get Started" to "Add New" and "Save" to "Create").

*** ** * ** ***

### 📚 Knowledge Articles

* [**Cisco Spaces Calendar Integrations (Webex Hybrid Calendar/O365/Gcal)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-calendar-integrations-webex-hybrid-ca)

  ➤ Minor formatting or whitespace changes only.

* [**Counting People from Wi-Fi**](https://runbooks.ciscospaces.io/docs/counting-people-from-wifi)

  ➤ Added a note clarifying that Connector hashing is only available for Catalyst deployments, and reorganized the "Deduplication Mechanisms Flow Chart" section to appear earlier on the page. Also introduced new subheadings for "Hashing Disabled (most common)", "Hashing Enabled", "Counting Unique User IDs", "Counting Proxy Devices On SSID", and "Counting Proxy Devices with REGEX" to improve section organization.

* [**Digital Map Pro and CAD/DWG/PDF Best Practices**](https://runbooks.ciscospaces.io/docs/digital-map-pro-and-cad-dwg-pdf-best-practices)

  ➤ Minor formatting or whitespace changes only.

* [**IoT Device Guidance for MT EoS**](https://runbooks.ciscospaces.io/docs/iot-device-guidance-for-mt-eos)

  ➤ Updated the Cisco Spaces IoT Device Marketplace URL and significantly expanded the "Comparable Sensor List" section. The updated list now includes specific descriptions for Meraki MT sensors (MT10, MT11, MT12, MT14, MT15, MT20, MT30, and MT40) and introduces several new third-party alternative sensors from manufacturers such as Ela Innovation, Minew, Kontakt.io, Smart Sensor Devices, Securitas Healthcare, Moko Smart, and Centrak.

---
language: "en"
---
# Changelog - 2026.07

## July 2026

### 🛠️ Runbooks

* [**Cisco Spaces Captive Portal Runbook**](https://runbooks.ciscospaces.io/docs/cisco-spaces-captive-portal-runbook)

  ➤ Minor formatting or whitespace changes only.

* [**Cisco Spaces Occupancy Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-runbook-cisco-validated)

  ➤ Updated the "Room Presence Using PIR Sensors" section to clarify supported room types, streamline the Thingsee PIR sensor ordering process via the Device Marketplace, and expand the list of supported and unsupported functionalities for room occupancy data across Cisco Spaces apps (including Space Utilization, Space Manager, IoT Explorer, and Spaces Firehose API).

* [**Cisco Spaces OpenRoaming Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated)

  ➤ Updated the runbook to replace references to the "Carrier Offload with a Partner App (AT\&T Auto-Attach)" knowledge article with references to the new "Appendix: Carrier Offload Providers" section, which includes guidance on configuring Carrier Offload and adding custom carriers. Removed support and setup instructions for the deprecated Cisco Spaces Connector version 2.x, updating the requirements to specify Connector version 3.x. Additionally, cleaned up paragraph formatting and list structures in the Overview and Network Components sections.

* [**Cisco Spaces OS Day 2 Guide**](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-day-2-guide)

  ➤ Updated the section headers throughout the guide---including "Introduction," "Scope," "Operational Outcomes," "Monitoring Model," "Routine Operations," "Maintenance Tasks," "Troubleshooting Workflow," "Common Troubleshooting Scenarios," "Validation After Recovery," "Documentation and Change Control," and "FAQs"---to use uppercase formatting. Additionally, made minor spacing adjustments to the text under the "Scope" section.

* [**Cisco Spaces Smart Workspaces Runbook (Cisco Validated)**](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida)

  ➤ Updated a troubleshooting URL link in the document, changing the anchor reference from a specific Cisco Collaboration device configuration issue to the broader "#Caveats-\&-Tips" section.

*** ** * ** ***

### 📚 Knowledge Articles

* [**IOT Services Deployment, Monitoring, and Troubleshooting Guide**](https://runbooks.ciscospaces.io/docs/iot-services-deployment-monitoring-and-troubleshoo)

  ➤ Updated the MAC filtering configuration process so that customers can now configure MAC filtering directly by navigating to **IoT Services \> Settings**, rather than needing to open a Support Case with the Cisco Spaces support / backend teams. References to requiring Cisco team assistance to set and apply these filters have been removed.

* [**OpenRoaming: Carrier Offload with a Partner App (T-Mobile Auto-Attach)**](https://runbooks.ciscospaces.io/docs/openroaming-carrier-offload-with-a-partner-app-tmo) 🆕

  ➤ Introduces the T-Mobile Auto-Attach Partner App in Cisco Spaces, which enables businesses to offer Carrier Offload services to T-Mobile mobile network customers by automating agreements and facilitating SLA/network health telemetry via the Spaces Meta API. The documentation outlines the prerequisites, including configuring the Cisco Spaces OpenRoaming Runbook, and provides step-by-step instructions to setup and activate the T-Mobile Auto-Attach application. These procedures guide users through submitting the Contact Request Form, obtaining a Tenant/Account Name, and selecting specific locations to begin offloading carrier traffic.

*** ** * ** ***

### 🤝 Partner Ecosystem Guides

* [**Infant Protection with Securitas Healthcare and Cisco Spaces**](https://runbooks.ciscospaces.io/docs/infant-protection-with-securitas-healthcare-and-ci)

  ➤ Minor formatting or whitespace changes only.

* [**Remote Patient Monitoring with Corsano and Cisco Sensor Connect**](https://runbooks.ciscospaces.io/docs/remote-patient-monitoring-with-corsano-and-cisco-s) 🆕

  ➤ Provides implementation guidance for deploying a Remote Patient Monitoring (RPM) solution that integrates Corsano Health wearable medical devices with Cisco wireless infrastructure and Cisco Spaces Sensor Connect. Outlines the reference architecture, deployment workflow, infrastructure requirements, configuration procedures, and validation steps for continuous physiological monitoring and BLE telemetry collection. Details how Cisco Catalyst Access Points act as BLE gateways to forward patient telemetry to the Corsano platform, enabling clinical monitoring, patient onboarding, and historical trend tracking.

---
language: "en"
---
# Cisco Spaces Asset Tracking Runbook (Cisco Validated)

## OVERVIEW

*This Cisco Validated runbook is designed only as a follow on from the* ***Spaces OS Runbook*** *. It provides a comprehensive guide on asset tracking using Cisco Spaces. It includes an overview of asset tracking, recommended prerequisites, wireless infrastructure setup for both Catalyst and Meraki systems, AP density and placement guidelines, Spaces infrastructure requirements, implementation steps for Catalyst and Meraki, and the configuration of IoT services. Additionally, it covers the requirements for asset tags and detailed instructions for setting up the Spaces Connector and integrating with WLC.*

Lack of real-time Asset tracking solutions can add critical bottleneck to the supply chain operations and in the healthcare industry, cause life-threatening delays.

Spaces native apps can track all devices connected to the network in real time and with a host of partner apps \& BLE devices, which can monitor and manage all critical or high value assets in the campuses

* Track all devices connected to the network

* Access to industry-leading applications with the App marketplace

* Easy deployment of third-party apps \& devices with additional gateways

* Scale \& manage IoT devices \& partner apps

Use Cases:

* Healthcare: Manage medical equipment in real-time and improve operational efficiency

* Retail \& Hospitality: Track high value assets and equipment within the campuses

* Workspaces: Locate all devices connected to the network on a map interface for real-time tracking

* Manufacturing: Track the location of high value assets

### SUPPORT \& ONBOARDING INFO

Please follow the link below to find out about the different ways to get support for Cisco Spaces.

[++Support Info Link++](https://activate.dnaspaces.io/hubfs/Assets/CiscoSpaces-SupportUpdate.pdf?__hstc=105720540.52aaa4a978f36be89855b002cb35bfc4.1729705805310.1729705805310.1729705805310.1&__hssc=105720540.1.1729705805310&__hsfp=3667649010)

*** ** * ** ***

## PREREQUISITES

This runbook should **only be used as a follow on from the** [**Spaces OS Runbook**](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated). If that runbook has not been completed, go back and validate the deployment against that first.

### Catalyst

Within Catalyst AP environment, we are aiming for 2 key requirements; BLE support, and IOX Container support on the AP. APs providing both of these requirements will allow the use of Advanced IOT Gateway support. Those only providing BLE, will show as Base. APs not included on the following list, are not supported APs for Asset Tracking use cases, but may be supported for other use cases, such as occupancy.

**Supported AP's Operational Modes**  

|            **AP Model**             | **BLE** | **IOT Gateway Support** |                                                                  **Rx Only (scanning)**                                                                   |                                                                  **Tx Only (beaconing)**                                                                  |                                                                   **Dual Mode (Rx+Tx)**                                                                   |
|-------------------------------------|---------|-------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|
|                                     |         |                         | Recommended for Spaces Outcomes                                                                                                                                                                                                                                                                                                                                                                                                                                                 |||
| 9170 Series (9176/9178 UWB capable) | Yes     | Advanced                | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| 9166 (inc. D1)                      | Yes     | Advanced                | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| 9164                                | Yes     | Advanced                | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| 9162                                | Yes     | Advanced                | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| 9136                                | Yes     | Advanced                | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| 9130                                | Yes     | Advanced                | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| 9120                                | Yes     | Advanced                | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| 9117                                | Yes     | Advanced                | ❌                                                                                                                                                         | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                                                                                                                                         |
| 9115                                | Yes     | Advanced                | ❌                                                                                                                                                         | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ❌                                                                                                                                                         |
| 9105                                | Yes     | Advanced                | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) | ![check mark](https://runbooks.ciscospaces.io/__attachments/a_771cde6d7c0442bb4be72fa0f87aa219b694d3e186fc9c8fbe96db65e015df3d/atlassian-check_mark?cb=a10212e1c1021c5194f7535b6843f955) |
| 4800                                | Yes     | Base                    | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                                                                                                                                         |
| 1815w                               | Yes     | Base                    | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                                                                                                                                         |
| 1815m                               | Yes     | Base                    | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                                                                                                                                         |
| 1815i                               | Yes     | Base                    | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                                                                                                                                         |
| 1840                                | Yes     | Base                    | ❌                                                                                                                                                         | ❌                                                                                                                                                         | ❌                                                                                                                                                         |

**Special considerations for the Aironet \& Catalyst AP's**

Cisco 9115 and 9117 as well as 1815, 1840, and 4800 AP's are not recommended for IoT services.

#### **Advanced Gateway - Recommended**

The Cisco Spaces Advanced IOT Gateway allows us to gather extra data from IOX compatible devices found from the Spaces IOT Device Marketplace.

This is particularly relevant for asset tracking, as we can capture battery life of tags through this extra data, meaning tags don't just drop off the network, and we can manage replacing tags when needed.

The advanced gateway leverages both the IOT radio, and the IOX container capability, and as a result, a smaller subset of AP's are supported.

To manage the IOX container functionality, these AP's are required to be managed by a 9800 WLC, all are supported. Suggested for code versions is 17.9.x (latest). There have been significant improvements in IOT Services on 9800 since 17.9.5, so lowest recommended is 17.9.6 - See 9800 Known IOX Issues for more details.

#### **Base Gateway**

Base gateway functionality purely collects RSSI from tags, meaning we only need access to the BLE radio on the AP, not IOX. As a result, the list is more extensive, but the use cases are limited.

For particular note within asset tracking, we will not be able to receive the battery level of IOT tags, whether they are from the IOT Marketplace or not. This will serve difficult in maintenance of the solution, as tags may simply drop off without warning.

Even for the base gateway, 9800 is still utilised, and 17.9.6 is still the minimum recommended code version.

Base gateway functionality is not recommended where advanced gateways can be used, it often serves a inferior solution, and provides less expandability for future use cases.

*** ** * ** ***

### Meraki

For Meraki deployments, we have no such feature as the IOX container, meaning we simply leverage the BLE radio on the AP directly. This means the use case is easier to deploy, but comes with some limitations.

We can only leverage Eddystone or iBeacon formats, and cannot collect any 'extra data; that we can with the advanced gateway. In summary, on Meraki deployments we can deliver base gateway functionality only - See Base Gateway.

Due to the fact we only leverage the BLE radio for Meraki deployments, the pre-requisites are less stringent.

In summary, we support any Meraki AP Wave 2 and onwards, on firmware version 29 and above (latest is suggested).  

| **Technology** |                            **Supported APs**                             |
|----------------|--------------------------------------------------------------------------|
| Wave 2         | MR33, MR42, MR42E, MR52, MR53, MR53E, MR74, MR84                         |
| Wi-Fi 6        | MR28, MR36, MR36H, MR44, MR45, MR46, MR46E, MR55, MR56, MR76, MR78, MR86 |
| Wi-Fi 6E       | MR57, CW9162I, CW9164I, CW9166I, CW9163E                                 |
| Wi-Fi 7        | 9170 Series (9176/9178 UWB capable)                                      |

*** ** * ** ***

### AP Density

General guidance for designing for location services has not changed over the years, and we still follow 4 main guidelines  
![AP Density.png](https://runbooks.ciscospaces.io/__attachments/a_fc65ddfae50bf128c5f3f922107d5ebdb295773e46f78e15b6d791683a0d0de6/AP%20Density.png?cb=b2f3681d58a20ef50d31168bb52455ca)

4 guidelines for designing for location services:

* AP's should be around the perimeter (aiming to surround any client with AP's on all sides)

* Clients should be heard by 3 or more AP's, at -75dBm or better

* AP's should be spaces 12-21 meters (39-67 ft) apart

* AP's should be deployed at 6 meters (20 ft) or less

*** ** * ** ***

### AP Placement Check

With AP Auto Location access points on a Digital Map can be automatically located in Cisco Spaces. By improving device location accuracy and reducing troubleshooting efforts caused by incorrect AP placement, AP Auto Location helps streamline deployments, reduce complexity, save time, and minimize costs associated with verifying and placing APs on maps.  

|                     Product                     |                                                                                  Platform                                                                                   |                     Releases                     |
|-------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------|
| Cisco Catalyst 9100 Family of Access Points     | * Cisco Catalyst 9130 Series Access Points * Cisco Catalyst 9136 Series Access Points * Cisco Catalyst 9164 Series Access Points * Cisco Catalyst 9166 Series Access Points | Minimum required version is Cisco IOS XE 17.12.1 |
| Cisco Catalyst 9800 Series Wireless Controllers | Cisco Catalyst 9800 Series Wireless Controllers                                                                                                                             | Cisco IOS XE 17.12.x                             |
| Cisco Spaces                                    | Cisco Spaces: Connector 3                                                                                                                                                   | Location Service 3.1.0.94 or later               |

* Cisco Catalyst 9800 Series Wireless Controllers must be connected to the Cisco Spaces: Connector and both must be available in the Cisco Spaces cloud account.

* Digital maps must be available for the floors to place the AP. Use the Locations \& Maps feature to add digital maps. For more information, see [++Setting up Locations and Maps++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m-locations-and-maps1.html).

* Site tags are mandatory for the floors. Use the Cisco Catalyst 9800 Series Wireless Controllers GUI to create site tags. The APs that are being placed in Cisco Spaces must be associated with the site tags. For more information about configuring site tags, see "[Configuring a Site Tag](https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/m-sniffer-cg.html#task_dkt_2vn_kz)" in the Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide.

Generating ranging data for default site tags is not supported in Cisco Spaces.

AP Auto Locate is also being implemented for both Meraki Dashboard, and Catalyst Center. This would allow automatic placement of APs in respective management platforms, and then ingestion of AP placement into Spaces.

[AP Auto Locate - Meraki](https://documentation.meraki.com/MR/Deployment_Guides/AP_Auto_Locate)

AP Auto Locate - Catalyst Center (Currently not available).  
For an in-depth guide for AP Auto Locate please refer to the [Configuration Guide](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m-device-placement.html).

*** ** * ** ***

### Asset Tags

Choosing asset tags is a core part of implementing a good asset tracking solution.

There are a number of core fundamentals to consider when choosing physical tags for a solution:

* Price

* Compatibility

* Form factor

* Battery life

* Extra features (e.g. temperature or button press)

The [Spaces IOT Device Marketplace](https://dnaspaces.io/devicemarketplace/home) is a page dedicated to providing this information, and connecting buyers to sales teams from the respective tag supplier.

The marketplace also offers a list of tags that have been validated to work with the advanced gateway setup, meaning we will be able to gather battery life (as well as the option of other data), along side delivering location.

The platform is also capable of supporting any iBeacon or Eddystone tag, delivering just base location functionality, and no other data.

These tags may be more appropriate for a base gateway solution.

*** ** * ** ***

## IMPLEMENTATION

To complete these steps, an admin will require read/write permissions within Spaces for IOT Services and IOT Explorer

Given the above prerequisites have been met, its now time to implement our asset tracking use cases.

For each stack (Catalyst or Meraki), we will cover whats needed to add these stacks to Spaces, how to enable IOT services, then how to deliver outcomes.

This implementation section is particularly focused towards our use case of asset tracking, but many steps are matched for other use cases, so it may be necessary to skip, or just verify some steps.

### Configuring IOT Services

Now all infrastructure and hierarchy is setup, IOT Services can be enabled. This will push configuration to our controller, as well as push the IOX container to the AP, enabling BLE and creating a telemetry stream for the data.

1. Navigate to **About IoT Services** page on the left-hand side of the **Menu** \>**IoT Services**.

2. On Day 0 of the IoT Services Activation an Amber Banner will be at the top that signals the deployment hasn't started yet.

3. Once all the prerequisites are met, click **Activate** button on the Amber Banner. Alternatively, click on **Activate IoT Services** to begin.

4. Select **Wireless** and click on **Next**.

5. After the Prerequisite Check Screen it progresses to Activation Screen that shows how many Connectors and Controllers are up.

6. Post Activation Summary Screen, there are two ways to deploy IoT services.

7. Here, click either **Activate** to enable IOT Services everywhere, or click **Click here for customization** to only enable IOT Services on selected connectors, controllers or AP's.

Following this process, will enable all compatible AP's to be advanced gateways (as dictated above), and all other AP's will be enabled as base gateways.  
![configure IOT Services.png](https://runbooks.ciscospaces.io/__attachments/a_f92bcffc29bbe02acae6edeb66e06d695fa657f05a92d62e0f86907c0d4b9c7e/configure%20IOT%20Services.png?cb=fa12d58c1bf090a4f0d6ac68e3c74eb9)

*** ** * ** ***

### Claim and Configuring Asset Tags

We now have everything ready to start tracking our asset tags, but first, we should claim the beacons and push any configuration.

First, lets claim our beacons.

[***Click here for a video guided demo***](https://player.vimeo.com/video/867820770#:~:text=%22%20href%3D%22-,https%3A//player.vimeo.com/video/867820770,-%22%3E)

1. Under **IOT Services** \>**Device Management** , click the blue button in the middle of the screen labelled **Onboard Devices**.

2. Select **Floor Beacons**.

3. Fill out the order ID. This is usually sent by the tag manufacturer by email at point of ordering, and/or will be included in the packaging of the tags themselves. Then hit **Add to Inventory.**

Now we can go ahead and push out any config changes needed to our claimed beacons.

[***Click here for video guided demo***](https://player.vimeo.com/video/867822206#:~:text=%22%20href%3D%22-,https%3A//player.vimeo.com/video/867822206,-%22%3E)

1. Configure claimed beacons by navigating to **IoT Services** \> **Device Management** \> **Devices** \> **Claimed Beacons.**

2. Click the **Configure Beacons** link which will open the beacon configuration portal.

3. Identify the beacon via its Unique ID in the Device Inventory as well as printed on the physical device.

4. Make any configurations changes as needed, and when ready to apply the changes, click the **SAVE CHANGES** button. Test this out by enabling telemetry on a beacon via the beacon configuration page, then verify this operation was a success by clicking on an individual beacon in the Device Inventory and selecting **Telemetry**.

5. Verify in **Device Management** \> **Devices** \> **Claimed Beacons** that the changes have been applied by selecting the beacon and viewing its request history and viewing its updated settings, such as UUID, Major, Minor, Transmission Power, Transmission Frequency, as well as telemetry and location data.

### Spaces Apps

Spaces delivers a number of use cases (known as apps) within the platform. These cover a great range of use cases, but here we will deep dive on the implementation and usability of the apps particularly focused on delivering asset tracking outcomes. For more information on other Cisco Spaces outcomes, please see the [outcome store.](https://spaces.cisco.com/store/)

#### IoT Explorer - Preferred

IoT Explorer is an application designed to cater to specific use case needs. Deploy and create use cases effortlessly, including asset tracking, temperature monitoring, and presence detection, all in one centralized dashboard.

Centralize/Consolidate asset tracking process and obtain live insights into the location and usage of assets globally. Tailor notifications according to personalized guidelines and receive prompt alerts for significant shifts in asset behaviour and whereabouts.

**Value Delivered:** Increase operational efficiency to save time \& cost, gain insights from historic trends to enhance decision-making, and deliver real-time visibility to stakeholders.

**Useful to:** Operations, Facilities, IT, Security

Lets create our first asset tracking use case within IoT Explorer.

[***Click here for a video guided demo***](https://player.vimeo.com/video/792106034?h=e5ccde4727&badge=0&autopause=0&player_id=0&app_id=58479#:~:text=%22%20href%3D%22-,https%3A//player.vimeo.com/video/792106034,-%22%3E)

1. Head into **IoT Explorer \> Asset Tracking** , then select **Get Started**.

2. Enter a **Use Case Name** and also a **Description** for the use case.

3. Now under **Configure \> Manage Assets \> Import Assets** , we can select our assets to import. This can either be done by setting up existing device filters, or through a CSV bulk import. If the beacons are already claimed, use the **Existing Device Filter Criteria.**

4. Assets should now be visible to locate within the **Locator** tab, and also in a list view within the **Assets** tab. In both of these tabs, clicking a given asset can provide more info, history, battery life etc. Searching for given assets here makes it easier to narrow down specific assets.

5. We can now generate rules for these assets within **Rules \> Add Rule.**

   1. Configure a **Rule Name** at the top of the screen.

   2. Start by adding in a **Rule** element from the right hand pane. Note: Only one rule element can be configured per rule.

   3. Next drag in and configure some **Condition** elements. These conditions can be combined to generate more or less complex ruling setups.

   4. Now, add in **Actions** to determine what happens when the rule is triggered and matches the set conditions. Note: The action 'Log the event' is set by default and cannot be removed. It is recommended to configure these logs by clicking the action and adding context.

   5. Finally, hit **Save \& Publish** to put the new rule into practice.

6. Now that a rule is in place, take a look in the **Events** tab, and see if any of the rules have been triggered. Events can also be exported here for compliance use cases.

*** ** * ** ***

## Caveats and Tips

**Steps to Deploy Asset Tracking Without Catalyst Center**

1. CAD or vector PDF files, 9800 with the right version to for AP auto locate.

<!-- -->

2. Convert the CAD into map. For creation of the location hierarchy, use the Excel based location hierarchy creation method.

<!-- -->

3. You now have your floors created (using excel method) and AI maps.

<!-- -->

4. Run AP auto locate. Edit / modify the placement of APs as needed.

<!-- -->

5. Turn on IOT Services to turn on BLE (needs Spaces Connector).

<!-- -->

6. Use Detect and Locate app for IT outcomes, IOT Explorer app for other OT outcomes. And finally use the API if you want to send X/Y data to either your own app or a partner app.

*** ** * ** ***

## REFERENCE

### Connector IP Requirements

|        Region        |      Primary IP Address      |      Disaster Recovery      |
|----------------------|------------------------------|-----------------------------|
| Global Setup (IO)    | 52.20.144.155 34.231.154.95  | 54.176.92.81 54.183.58.225  |
| EU Setup (EU)        | 63.33.127.190 63.33.175.64   | 3.122.15.26 3.122.15.7      |
| Singapore Setup (SG) | 13.228.159.49 54.179.105.241 | 13.214.251.223 54.255.57.46 |

### 9800 Known IOX Issues

| **Bug ID** |                                           **Title**                                           |              **Fixed in release**              |                                                                                                           **Comments**                                                                                                           |
|------------|-----------------------------------------------------------------------------------------------|------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| CSCwj93064 | 17.15.1 - IOX App Installation failing on 9178 SI WiFi 7 AP, 4800 TI                          | 17.9.5ES08, 17.9.6, 17.12.4, 17.15.1           | Sometimes IOX Application install would fail                                                                                                                                                                                     |
| CSCwk18357 | After IOX app uninstall on 9130 SI stopped functioning in Dual mode                           | 17.9.5ES08, 17.9.6, 17.12.4, 17.15.1           | Affecting APs in Dual Mode                                                                                                                                                                                                       |
| CSCwk21493 | On Capwap AP restart BLE interface state on WLC is changed to Closed state                    | 17.9.5ES08, 17.9.6, 17.12.4, 17.15.1           | Affects the observation and the status only, not functional impact                                                                                                                                                               |
| CSCwj92716 | Native mode and IOx app both use iot uart interface leading to continuous iot chip resets     | 17.9.5ES06, 17.9.6, 17.12.4, 17.15.1           | Whenever the AP (re)boots or activates the Cisco Spaces IoT-Services IOX App, there is a possibility that the AP will not fully convert to "Advanced"/IOX Mode, preventing the IOX App from being able to control the BLE Radio. |
| CSCwj19805 | AP 9130AX BLE 2.7.22 Advertising 0dBm TxPower and chip sync issue during firmware upgrade     | 17.9.5ES03, 17.9.6, 17.12.4, 17.15.1           | Affects only TI based APs in Transmit or Dual mode, for wayfinding type use cases                                                                                                                                                |
| CSCwj98884 | iox status down after capwapd crash and grpc is not established when certificate is malformed | 17.9.5ES06, 17.9.6, 17.12.4, 17.15.1           | Affects BLE channel if there is a CAPWAP crash. Requires a re-start of IOT services, pushing of the certificate again                                                                                                            |
| CSCwi57873 | TI AP - BLE Resets , connect/disconnect times out sometimes                                   | 17.9.5ES06, 17.9.6, 17.12.4, 17.15.1           | Affects TI based APs due to older SDK not responding                                                                                                                                                                             |
| CSCwi64652 | AX APs do not reset BLE interface after 100 attempts                                          | 17.9.5ES01, 17.9.6, 17.12.4, 17.15.1           | Affects TI based APs which get stuck after 100 resets                                                                                                                                                                            |
| CSCwk00429 | IOX App starts after reboot but never reached RUNNING state                                   | 17.9.6, 17.12.4, 17.15.1                       | Sometimes seen that the IOX app does not fully deploy until it is reinstalled                                                                                                                                                    |
| CSCwk00501 | Cisco Spaces IOT Services Exhausts IOX App Storage due to Constant Resets                     | Fixed in IOX app version 1.6.33+               | corner case, affects if AP is already in a bad state                                                                                                                                                                             |
| CSCwk00645 | Cisco Spaces Connector drops gRPC connection request after \~2500 APs established             | Fixed in IOT Wireless docker version 3.1.3.17+ | Any APs attempting to establish gRPC to the Spaces Connector after \~2500 have already done so will fail to establish gRPC against the connector                                                                                 |
| CSCwk99004 | Default Channel Pipeline data channel disconnection                                           | Fixed in IOT Wireless docker version 3.1.3.44+ | Connector can experience data channel disconnects. The default channel pipeline on iot-services and location can encounter an exception, which causes service interruption.                                                      |
| No bug ID  | Multiple other fixes, improvements, metrics, logging etc                                      | Fixed in IOT Wireless docker version 3.1.3.44+ | No bug IDs, but multiple fixes and improvements have been made in the IOT Docker                                                                                                                                                 |

### Cisco Spaces Connector Ports Used

![Screenshot 2025-03-11 at 7.11.04 PM.png](https://runbooks.ciscospaces.io/__attachments/a_f65fc723eea18273af36047391b169bdf927706d75b33206db4a0d7a79f28b64/Screenshot%202025-03-11%20at%207.11.04%E2%80%AFPM.png?cb=76fbc58f4662bf070e1d2fdb9d908793)

---
language: "en"
---
# Cisco Spaces Calendar Integrations (Webex Hybrid Calendar/O365/Gcal)

## General Background

### Introduction - Outcomes \& Use Cases

Regardless of the chosen architecture (Webex Hybrid Calendar or Spaces direct integration to O365 or Gcal), a calendar integration with Cisco Spaces can be leveraged for showing booking status and upcoming meetings on Space Explorer Kiosk app.  
Note: in the EFT stage, this serves as an override of the calendar on collaboration device occupancy enabled rooms and as a calendar for 3^rd^ Party IoT occupancy sensor rooms (a separate EFT)

It can also be used to compare against people count occupancy data for reporting on ghost bookings and booking trends. These important metrics can help inform real estate and workplace experience teams of any booking culture issues that might be arising in the workplace. End users (employees) can find meeting rooms more efficiently by avoiding rooms that have an upcoming booking that might overlap with the duration of the meeting they need to schedule at that moment (from Space Explorer Kiosk app). In the future, Cisco Spaces will offer more interfaces and new options to interact with the calendar. For example, booking anonymously from the Space Explorer Kiosk app and creating meeting invites from the mobile/desktop web app tied to the logged in user's calendar.

### **Known Gaps** \| Roadmap

* Calendar-only rooms (no occupancy sensors) on Kiosk app

* Calendar-only rooms (no occupancy sensors) in Space Manager \> Overview

* Booking (anonymously - "as the resource") from Kiosk app

* Booking (on user calendar) from Space Explorer Web App

### Basic Architecture

#### **Webex Hybrid Calendar**

O365/Gcal ↔ Webex Control Hub ↔ Cisco Spaces  
MTR devices support Hybrid Calendar, but require additional configuration in Control Hub.

#### **O365 or Gcal Direct Integration**

O365 ↔ Cisco Spaces

Gcal ↔ Cisco Spaces  
Note: if a room is connected to both a Webex Control Hub Workspace and linked to an O365/Gcal calendar resource, the ++O365/Gcal events take precedence over Webex Hybrid Calendar++.

#### Pros \& Cons

|------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------|
|                                    | **Pros**                                                                                                                                                                                                                                                                                                                                                                                                    | **Cons**                                                                                                     |
| **Webex Hybrid Calendar**          | * Automatic room name matching allows for faster/easier calendar linking automatically through the existing Webex Control Hub integration. * Leveraging Webex video endpoints in rooms unlocks the ability to send a "Hold" message to the in-room device screen, which is unique to Webex rooms, since a "Hold" is not an official calendar feature.                                                       | * It is not always obvious if there is a configured and active Hybrid Calendar without checking Control Hub. |
| **O365 / Gcal Direct Integration** | * Fewer "hops" between systems, and while a less complex architecture, it may have a negligible impact on latency of receiving updates into Cisco Spaces. * If a Webex Workspace does not exist (e.g. a calendar-only room or a room with a 3^rd^ party occupancy sensor - ++roadmap++), Cisco Spaces can still receive calendar events. * Works as an override if Webex Hybrid Calendar is not configured. | * Slower, more manual setup when linking individual calendars per room.                                      |

*** ** * ** ***

## Webex Hybrid Calendar Technical Overview

### Background

Calendar Service with Webex Hybrid Calendar support enables Cisco Spaces customers to seamlessly integrate their workspace's calendar with Cisco Spaces. This integration will be achieved by utilizing [RoomOS xAPIs](https://roomos.cisco.com/xapi) to receive calendar data, which will be utilized in Cisco Spaces applications (e.g. Space Explorer Kiosk \& Web App, Space Manager, Space Utilization). This will help the customer to better manage and utilize their workspaces using Cisco Spaces.

If Webex Hybrid Calendar is configured in Control Hub per Workspace, then the calendar events will automatically sync to Cisco Spaces backend for applications to consume. **This is the recommended method of setting up a calendar integration with Cisco Spaces.** As covered in the Pros \& Cons table, there are some cases where the Cisco Spaces direct integration to O365 or Gcal is appropriate. The main reason to use Hybrid Calendar is automatically keeping Cisco collaboration devices and calendars in-sync through the Control Hub configuration. There is less chance of mismatching calendar resources and meeting rooms in Space Manager later in the product lifecycle management.

### General Workflow

1. Configure Webex Workspaces in Control Hub with Hybrid Calendar

2. Upload maps to create Meeting Rooms

3. Integrate Control Hub with Cisco Spaces matching up Locations \& Floors in the Spaces Location Hierarchy correctly

4. Connect Webex Workspaces with Meeting Rooms in Space Manager

5. Each Meeting Room's calendar resource and its events automatically sync through xEvents to Spaces

### Number of Events \| Hours of Events Synced

Currently (as of November 2025), RoomOS devices only synchronize the current day + 8 hours of calendar events. Therefore, Cisco Spaces is not aware of any events further out on the calendar.

### Webex Hybrid Calendar Timing

When a booking is initiated, it can take up to 60 seconds (configurable up to 5 minutes for Exchange) for the cloud to generate a Meeting ID, if a booking is accepted by the source calendar. During this time, a device only provides a Booking ID (i.e. "id"), which is generated as part of a booking request. This is reflected in a BookingRequest xEvent. However, if a booking is not confirmed by the source calendar within 60 seconds (configurable for Exchange), it will timeout and remove the booking.

### Cisco Spaces Integration Update Available -- Review \& Approve

Always check for the latest permissions request, review, and approve for the best experience and new features.  
**NEW** (as of September 2025) - new permissions to access xEvent xAPIs from device for improved speed and reliability when syncing calendar events from devices to Spaces backend via webhooks.  
![Control Hub - Workspaces - Integrations - Cisco Spaces - Review Update](https://runbooks.ciscospaces.io/__attachments/a_5e2c35788292eafa67c8d8f19750dd5c99723ebae8344adad3e0553e6cdae433/image-20250603-214101.png?cb=6a5420b8ce7f3aa6944d88d9466277a2)
Control Hub \> Workspaces \> Integrations \> Cisco Spaces \> Review Update  
![Control Hub - Workspaces - Integrations - Cisco Spaces - Review and Approve](https://runbooks.ciscospaces.io/__attachments/a_8f369104add1de5d50792b4a78fbed405a8a7197f1250a67f1483d31de363e00/image-20250603-214201.png?cb=c6e64d5baf00daa51fa87d7853940649)
Control Hub \> Workspaces \> Integrations \> Cisco Spaces \> Review and Approve

*** ** * ** ***

## Microsoft O365 Calendar Technical Overview

### Background

Calendar Service with Microsoft Azure multi-tenant support enables Cisco Spaces customers to seamlessly integrate their workspace's calendar with Cisco Spaces. This integration will be achieved by utilizing Microsoft Graph APIs to receive calendar data, which will be utilized in Cisco Spaces applications (e.g. Space Explorer Kiosk \& Web App, Space Manager, Space Utilization). This will help the customer to better manage and utilize their workspaces using Cisco Spaces.

### Hidden from Global Address List (GAL)

**Note:** Rooms that are marked "Hidden from GAL" can't be retrieved through this endpoint.

Source: <https://learn.microsoft.com/en-us/exchange/recipients-in-exchange-online/manage-user-mailboxes/manage-user-mailboxes#general>

### General Workflow

For detailed step-by-step instructions, see: <https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m-calendar-integrations.html>

1. Go to **Cisco Spaces** \> **Integrations** \> **O365**

2. The user will be asked to sign-in as a Cisco Spaces Tenant admin and must accept the permissions, requested in the OAuth flow to successfully provision the application in their Tenant (see [Application Permissions](https://runbooks.ciscospaces.io/docs/cisco-spaces-calendar-integrations-webex-hybrid-calendar-o365-gcal#Application-Permissions) \& [Authorized Admin User](https://runbooks.ciscospaces.io/docs/cisco-spaces-calendar-integrations-webex-hybrid-calendar-o365-gcal#Authorized-Admin-User) below)

3. Cisco Spaces Calendar Service will acquire Tenant token for Microsoft Graph API to read places to detect new calendar resources periodically (every 24 hours) and calendar events via real-time webhooks (new, rescheduled, and canceled meetings).

### Data Flow Diagram

![Cisco Spaces O365 Calendar Integration Data Flow](https://runbooks.ciscospaces.io/__attachments/a_a0f25749d7fba6efef967b21f5d179edabc5d27291bbf33d1dd7753919de8a80/image-20250603-214304.png?cb=bda9463f6906a53ee3d452ab6b79db54)
Cisco Spaces O365 Calendar Integration Data Flow

### Application Permissions

Calendar Service will require the permissions below from the customer's Microsoft Azure tenant account to read calendar resources using Microsoft Graph APIs.

1. **Place.Read.All**

   * This will help Calendar Service to read meeting room resources from the customer's MS Azure tenant account.

2. **Calendars.Read**

   * This will help Calendar Service to read meetings/events for the meeting room resources.

### Authorized Admin User

A user with admin access to the Microsoft Entra admin center can grant the permissions above for the Cisco Spaces Calendar Service integration request. A user with the correct admin permissions needs to login to the Spaces dashboard to start the integration and login through the OAuth permission granting flow. If the customer revokes the consent for the permissions at any time, Calendar Service will remove the stored graph token to read resources using Microsoft Graph APIs and disable the functionality until the next successful integration.

    https://login.microsoftonline.com/common/adminconsent?client_id=92a88413-3496-4587-a83a-fde51780ee68&redirect_uri=https://calendar.dnaspaces.io/calendar-service/v1/multitenant/ms365/user/onBoarding&state={{state}}

**{{state}}** is populated at the time of the admin initiating the admin consent flow in **Cisco Spaces** \> **Integrations** \> **O365** page.  
![Microsoft Entra - Cisco Spaces O365 Calendar Integration - Properties](https://runbooks.ciscospaces.io/__attachments/a_e61d6dcddd1991bf9b9d71f271a3380db17bb23159e6e5919cc5dc7f97a4528e/image-20250603-214349.png?cb=c1e28c9037dfaf5108629d5710f5d54f)
Microsoft Entra - Cisco Spaces O365 Calendar Integration - Properties

*** ** * ** ***

## Google Calendar (Gcal) Technical Overview

### Background

Calendar Service with Google Workspace multi-tenant support enables Cisco Spaces customers to seamlessly integrate their workspace's calendar with Cisco Spaces. This integration will be achieved by utilizing Google Workspace APIs to receive calendar data, which will be utilized in Cisco Spaces applications (e.g. Space Explorer Kiosk \& Web App, Space Manager, Space Utilization). This will help the customer to better manage and utilize their workspaces using Cisco Spaces.

### General Workflow

For detailed step-by-step instructions, see: <https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m-calendar-integrations.html>

1. Cisco Spaces Calendar Service is registered as a Multi-tenant application in Google Workspace marketplace.

2. User will be asked to sign-in as a Cisco Spaces Tenant admin and must accept the permissions, requested in the OAuth flow to successfully provision the application in their Account (***Application Permissions)***

3. Cisco Spaces Calendar Service will acquire Google Calendar API token to read calendar resources periodically (every 24 hours, list of events for the upcoming day) and receive via webhooks (real-time new, rescheduled, and canceled meetings).

### Data Flow Diagram

![Cisco Spaces Google Calendar Integration Data Flow](https://runbooks.ciscospaces.io/__attachments/a_0777158ef0d73f50e77057bcd115f326f850ee387a7e27f8138de6a1d2ed0867/image-20250603-214436.png?cb=2d961244a9f874fe3de213ec7bdc551d)
Cisco Spaces Google Calendar Integration Data Flow

### Application Permissions

Calendar Service will require the permissions below from the customer's Google Workspace account admin to read calendar resources using Google Calendar APIs.

1. See and download any calendar you can access using your Google Calendar

   * This app wants permission to

     See your personal calendar and any other calendars you can access

     See events on your personal calendar and on other calendars you can access

     Download a copy of your personal calendar and any other calendars you can access

     See the email addresses of the contacts or groups you share calendars with

     Your calendar and other calendars you can access may contain info, like daily schedules, personal contacts, and private appointments.

2. View calendar resources on your domain

   * View details (e.g., name, type, etc.) of calendar resources on your domain

3. View customer related information

   * View details (e.g., contact email, organization title etc) of customer

Review Permissions: <https://myaccount.google.com/connections>  
![Cisco Spaces Google Calendar Permissions](https://runbooks.ciscospaces.io/__attachments/a_7814b7a36067d958d63137ceee20f872af45f68cd8707258158d401f65f74faf/image-20250603-214524.png?cb=1388ac88f769724a6f10f1f0c2dadb19)
Cisco Spaces Google Calendar Permissions

### Authorized Admin User

A user with admin access to the Google Workspace account can grant the permissions above the Cisco Spaces Calendar Service integration request. If the customer revokes the consent for the permissions at any time, Calendar Service will remove the store authorization token to read resources from Google Workspace calendar APIs and diable the functionality until the next successful integration.

*** ** * ** ***

## Workflow Overview \& Screenshots

![Cisco Spaces Calendar Integration Workflow Overview](https://runbooks.ciscospaces.io/__attachments/a_c0662365a088d7160ecd6c2399950f5093e9936314b9be7e56f7b6ecba0b3610/image-20250603-214609.png?cb=48e3321e20b7474f5240ff047b3577ae)
Cisco Spaces Calendar Integration Workflow Overview

*** ** * ** ***

### Integrations Page

![Cisco Spaces - Integrations](https://runbooks.ciscospaces.io/__attachments/a_9c686cdbd382df0b8b3be4ccddbb3d843c6e7596a5f1b88a66e887ff3fb36555/image-20250603-214649.png?cb=c93038b619b738cf5c20af5a6a1367e5)
Cisco Spaces \> Integrations

*** ** * ** ***

### Google Calendar (Gcal)

![Cisco Spaces - Integrations - Google Calendar](https://runbooks.ciscospaces.io/__attachments/a_4774c87b2f700e9c2ba098960dd9bb6b6e2072ec4a9972b28857ae1ee234687c/image-20250603-214719.png?cb=1b4c6aead9be7fe086334e1796be38f1)
Cisco Spaces \> Integrations \> Google Calendar  
![Cisco Spaces - Integrations - Google Calendar - Admin User OAuth Login](https://runbooks.ciscospaces.io/__attachments/a_442d96e785848f796eb85b5de3de37200e279c2abce3bc54a697e073610d0669/image-20250603-214800.png?cb=b51668842efb20b244fbb61ce8e7be8c)
Cisco Spaces \> Integrations \> Google Calendar \> Admin User OAuth Login  
![Cisco Spaces - Integrations - Google Calendar - Permissions](https://runbooks.ciscospaces.io/__attachments/a_33b67b6694911dc110e5f3684773a9fd4e7315f7535e27767212ca60d554b1d2/image-20250603-214902.png?cb=1497beb9681bfb14dd8d73c72ac6cb4a)
Cisco Spaces \> Integrations \> Google Calendar \> Permissions

*** ** * ** ***

### Microsoft O365 Calendar

![Cisco Spaces - Integrations - Office 365](https://runbooks.ciscospaces.io/__attachments/a_34d1d2b1aa361e50f68fc8e8f8b54ba5202872207185d29e3c738140ac20e5f7/image-20250603-214944.png?cb=ee23ad9187b7b5bc34656c3865a3b6c3)
Cisco Spaces \> Integrations \> Office 365  
![Cisco Spaces - Integrations - Office 365 - Microsoft Admin Login](https://runbooks.ciscospaces.io/__attachments/a_ee763d7e4709cf94e17122b479ce348f114d7c7d6858e1f708a54f450643f00a/image-20250603-215027.png?cb=2cead574e722c02b74fb0c2be92d8451)
Cisco Spaces \> Integrations \> Office 365 \> Microsoft Admin Login  
![Cisco Spaces - Integrations - Office 365 - Permissions](https://runbooks.ciscospaces.io/__attachments/a_6250c4f2418a438f7fabe7fdf3260d87a48bb0195bebef66f9c2884135207a75/image-20250603-215105.png?cb=831cfefeada779ec7e0caa796bb6bb6e)
Cisco Spaces \> Integrations \> Office 365 \> Permissions

*** ** * ** ***

### Space Manager \> Manage Rooms (Link Calendar)

![Cisco Spaces - Space Manager - Space Management - Room - Link Calendar](https://runbooks.ciscospaces.io/__attachments/a_9790cabb4317ce960c8e9c762fbc80cb5a60ca5fcbc64913bebb0b6bccfd6cf6/image-20250603-215142.png?cb=b3806e4bcdf1f50cc99a734da752ec90)
Cisco Spaces \> Space Manager \> Space Management \> Room \> Link Calendar

*** ** * ** ***

## RESOURCES

* <https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m-calendar-integrations.html>

* <https://learn.microsoft.com/en-us/graph/api/place-list>

* <https://learn.microsoft.com/en-us/exchange/recipients-in-exchange-online/manage-user-mailboxes/manage-user-mailboxes#general>

* <https://myaccount.google.com/connections>

* [Overview of Hybrid Calendar](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cloudCollaboration/spark/hybridservices/calendarservice/cmgt_b_deploy-spark-hybrid-calendar-service/cmgt_b_deploy-spark-hybrid-calendar-service_preface_01.pdf)

* <https://help.webex.com/en-us/article/niqovwv/Hybrid-Calendar-Service-with-Microsoft-365-integration-reference>

* <https://help.webex.com/en-us/article/mwka5l/Hybrid-Calendar-Service-with-Microsoft-Exchange-integration-reference>

* <https://help.webex.com/en-us/article/m2az0i/Hybrid-Calendar-Service-with-Google-Calendar-integration-reference>

* <https://help.webex.com/en-us/article/9sjyh2/Hybrid-Calendar-release-notes>

* <https://roomos.cisco.com/xapi>

---
language: "en"
---
# Cisco Spaces Captive Portal Runbook

**CISCO VALIDATED**

## OVERVIEW

With the standard expectation of users to always be connected to the internet no matter where they are, it is paramount that users can be connected securely and seamlessly.

This Cisco validated runbook will look at Captive Portals to onboard customers.

A captive portal is the first touchpoint with your business for customers on Wi-Fi. It provides an opportunity to engage with customers who connect to Wi-Fi, offer relevant information, drive monetization, and potentially acquire customer information. Captive portals enable businesses to choose from multiple authentication mechanisms and deliver targeted experiences based on business rules. They can recognize repeat visitors and deliver customized offers, enhancing customer engagement and loyalty.

*** ** * ** ***

## SUPPORT AND ONBOARDING

Please follow the link below to find out about the different ways to get support for Cisco Spaces.

[++Support Info Link++](https://activate.dnaspaces.io/hubfs/Assets/CiscoSpaces-SupportUpdate.pdf?__hstc=105720540.52aaa4a978f36be89855b002cb35bfc4.1729705805310.1729705805310.1729705805310.1&__hssc=105720540.1.1729705805310&__hsfp=3667649010)

*** ** * ** ***

## PREREQUISITES

*This Cisco validated runbook is designed only as a follow on from the* ***Spaces OS Runbook*** *. If you have not completed that runbook yet, please go back and ensure that the deployment has been validated against that before continuing here.*

### General Prerequisites

Captive Portal requires the following prerequisites met:

* An active Cisco Spaces account.

* A Cisco wireless network. Both controller-based (Cisco AireOS or Cisco Catalyst wireless controller) and cloud-based (Cisco Meraki) networks are supported.

* Add the wireless network to your Cisco Spaces account.

  * For controller-based architecture, the Cisco Spaces Connector must be used.

  * For Cisco Meraki networks, add the Cisco Meraki account to your Cisco Spaces account.

* Wireless Access Points (WAPs) must be in the Cisco Spaces Location Hierarchy. If importing from Catalyst Centre, ensure that WAPs are assigned to floor maps in Catalyst Centre (not just to sites). This is a pre-requisitve to have the WAPs present in Cisco Spaces Location Hierarchy. Without WAPs being present in the Location Hierarchy, clients will not get redirected to the Captive Portal.

#### Captive Portal Firewall Port List and Routing

![image-20250822-110045.png](https://runbooks.ciscospaces.io/__attachments/a_b13a7a1e2188485bc39daf4d12ce38059642b139e00f43d0c0eb1e4c0ea88dee/image-20250822-110045.png?cb=7bf4b79003c346b1cae12fabd270bafc)

*** ** * ** ***

## IMPLEMENTATION

At a hight level, the Cisco Spaces' Captive Portal architecture is as follows:

![image-20250825-051518.png](https://runbooks.ciscospaces.io/__attachments/a_2fb3532789539c95166c7f7de5800da6a0cb28adff0d371d27bf19a19ae72da9/image-20250825-051518.png?cb=45b721327759595631e7913945ac2e3a)

The process of setting up a Captive Portal requires two important tasks of i) Wireless Infrastructure Configuration and subsequently, ii) Captive Portal Configuration.

The Wireless Infrastructure Configuration ensures the underlying network is ready to host a Captive Portal setup. Once the Wireless Infrastructure configuration has been completed, the Captive Portal Configuration steps can commence on Cisco Spaces dashboard.

### Wireless Infrastructure Configuration

Setting up Wireless Infrastructure for Captive Portal requires the following steps:

1. Configure webauths parameters

2. Configure ACLs

3. Configure AAA servers

4. Configure SSID

Please refer to the relevant Wireless Infrastructure instructions based on the controller in your network.

#### Meraki Wireless Infrastructure Configuration

Click the arrow to expand content related to Meraki Wireless Infrastructure Configuration.
Meraki Wireless Infrastructure Configuration  

[Click here for a video guided demo](https://www.youtube.com/watch?v=ASQIGrvgBB0)

#### Step 1: Edit / Create SSID in Meraki

This step is needed if a new SSID needs to be created for a Captive Portal, so that it can be imported into Cisco Spaces.

1. In the Meraki Dashboard, Navigate to the **Wireless** \> **Access Control**

![image-20250311-021058.png](https://runbooks.ciscospaces.io/__attachments/a_8b808ba1bf848ac395d933555a2badd00a45214394188119e9915f0a315375d3/image-20250311-021058.png?cb=f30b059f4ceac2d138debec4df8e63fd)

2. Create or edit the SSID that is needed for Captive Portal access.

![Screenshot 2025-03-11 at 1.12.45 pm.png](https://runbooks.ciscospaces.io/__attachments/a_d43af377b83960cb6f69a44a9cfca8aed7051da0e9821706d69d76b6e4a53bb7/Screenshot%202025-03-11%20at%201.12.45%E2%80%AFpm.png?cb=8735d825671592f4245ef3362ee3382d)

3. In the Security area, choose **Mac-based access control (no encryption)**.

![image-20250311-022632.png](https://runbooks.ciscospaces.io/__attachments/a_b64760e7469631de8edb3c23429ca063d41ed53c67f25a46bc26c75ab4e930b9/image-20250311-022632.png?cb=18f4b4ed9f5520bf5556a04c76fe945b)

4. In the Splash page area, choose **Click-through** .

![Screenshot 2025-03-11 at 1.27.15 pm.png](https://runbooks.ciscospaces.io/__attachments/a_2f6ca18fe2dc45c9a65382ca586b4d9a5f58396b00d6cebdda74eccaca279baf/Screenshot%202025-03-11%20at%201.27.15%E2%80%AFpm.png?cb=3a5d2cd2db087f82cbd8576fb0dd9e4c)

#### Step 2: Import the SSID in Cisco Spaces

1. In Cisco Spaces dashboard, navigate to **Captive Portals** application:

![image-20250306-022921.png](https://runbooks.ciscospaces.io/__attachments/a_0d8b4a06bbc60c16f8e06f0c2eb187c0eabcd22c282df0b426998c089c469871/image-20250306-022921.png?cb=cb61ce7a85d417e398528c26b2621717)

2. Then: **SSID** -\> **Import / Configure SSID** -\> **Meraki**

   Choose the organization.

![image-20250306-033248.png](https://runbooks.ciscospaces.io/__attachments/a_2209bb293e7a6f5866566e180a7fe2f1284336379b1cf7d8df5e0ed8dcfcb45e/image-20250306-033248.png?cb=fd8baef1efd073b9cd56fb1324d072bc)

![image-20250306-034203.png](https://runbooks.ciscospaces.io/__attachments/a_f421ee9a57362f0c726f8dd9523e0da1d118c0e4828881f8d0b380022db412d4/image-20250306-034203.png?cb=52dcd1895ae2aef545fb1ac98da3898b)  
![image-20250306-033400.png](https://runbooks.ciscospaces.io/__attachments/a_f33f32af95c2db8e5a8f414f14ba91d15f1a61d22f8456a36e3f2a5135f8fb13/image-20250306-033400.png?cb=e0d157bb22ee89a16ad57af9c0b72796)  
If the sync is not complete yet, you will not see the SSID. In which case, wait until sync is complete and try again to see the SSID. It may take up to 2hrs for the sync to complete.

3. If the synch is completed and SSIDs are visible, choose the SSID and click **Import**.

4. Once imported, click **Configure Manually** and choose the appropriate Wireless Infrastructure for relevant instructions. In this case, it will be Cisco Meraki.

5. Click the **Configure SSID** tab and note important information regarding Wall garden and the Custom Splash Page URL. These details will need to be configured on the Meraki dashboard in later steps.

   **Walled Garden**

   These two IP addresses will be used as inputs in a later step: 34.235.248.212/32 \& 52.55.235.39/32  
   ![Screenshot 2025-03-12 at 3.13.37 pm.png](https://runbooks.ciscospaces.io/__attachments/a_48c2bea32a197c0d3bb159f594b903ed663e8098f18fc75105fa7a258257dda7/Screenshot%202025-03-12%20at%203.13.37%E2%80%AFpm.png?cb=3025edc2663a241ca6627d307bbf08c7)

   **Splash Page URL**  
   ![image-20250312-041112.png](https://runbooks.ciscospaces.io/__attachments/a_246fb02abb4d28afeffd38fc18d53c87ad1365b574d631960c03cb561df0ac99/image-20250312-041112.png?cb=65f78afa01ded9c80a7e42f4e5d2c3c6)

6. Click the **Configure Radius Server**tab and note details of the Radius authentication and accounting servers for configuration in the following steps.

**Radius Authentication**  

|    **Host**    |  34.197.146.105 34.228.1.95  |
|----------------|------------------------------|
| **Port**       | 1812                         |
| **Secret Key** | \*\*\*\*\*\*\*\*\*\*\*\*\*\* |

**Radius Accounting**  

|    **Host**    |  34.197.146.105 34.228.1.95  |
|----------------|------------------------------|
| **Port**       | 1813                         |
| **Secret Key** | \*\*\*\*\*\*\*\*\*\*\*\*\*\* |

#### Step 3: Configuration in Meraki

1. In the Meraki dashboard, navigate to **Wireless** \> **Access Control** Radius servers area, click **Add server,** and in the fields that appear configure the radius server details for authentication. Add the following servers separately:

![Screenshot 2025-03-11 at 4.29.48 pm.png](https://runbooks.ciscospaces.io/__attachments/a_24f042584c58e36df13670965f770091cef9b6dbdfd92bf834f22fbf1fdeb8fc/Screenshot%202025-03-11%20at%204.29.48%E2%80%AFpm.png?cb=e371cb33b4d3831b790635ada3558884)

2. In the **Radius accounting servers** area, click **Add server** , and in the fields that appear configure the radius server details for accounting. Add the following servers separately:

![Screenshot 2025-03-11 at 4.26.28 pm.png](https://runbooks.ciscospaces.io/__attachments/a_880e779b138128c517462bcf1ed62d7b271c43a3eaf2164e4e5bad5fd2c98ce7/Screenshot%202025-03-11%20at%204.26.28%E2%80%AFpm.png?cb=92dc243f3e31eabb330e6e0134eb2501)

3. From the "Radius attribute specifying group policy name" drop-down list, choose **Filter-Id**.

![Screenshot 2025-03-11 at 4.19.49 pm.png](https://runbooks.ciscospaces.io/__attachments/a_3531a621a92cde011946878da6fea07a9e579cccd7bff95fab747e4e8b138994/Screenshot%202025-03-11%20at%204.19.49%E2%80%AFpm.png?cb=855a38e477c2d50f768daedfa7c52f7a)

4. Scroll back up to the **Advanced splash settings** (directly above Radius configuration) and click it. Enter the Walled garden details there using the two IP addresses noted in an earlier step: 34.235.248.212/32 \& 52.55.235.39/32

![Screenshot 2025-03-11 at 4.54.03 pm.png](https://runbooks.ciscospaces.io/__attachments/a_651f0367c6835dc0dc8dcfdfc4a1970be871b627ef1d81b71c1d637ca9543ccb/Screenshot%202025-03-11%20at%204.54.03%E2%80%AFpm.png?cb=5d89d8dee4e87ffa2f005cdbd1735c1d)

5. Save the changes

6. Navigate to **Wireless** \> **Configuration** \> **Splash Page.**Choose the correct SSID for configuring.

7. In the **Custom Splash URL** area, choose "Or provide a URL where users will be redirected" and paste the Splash page URL copied earlier from Cisco Spaces.

![image-20250312-044052.png](https://runbooks.ciscospaces.io/__attachments/a_17fd43db4f21b5117223fd8b2f6a96a0d1b292a14b9883abb315297b2a74e395/image-20250312-044052.png?cb=95b296830527fad4d527f9b569a58568)

8. Save the changes.

#### Step 4: Configuration in Meraki

1. In the Cisco Meraki dashboard, click **Network-wide** \> **Group Policies**

![Screenshot 2025-03-11 at 4.33.01 pm.png](https://runbooks.ciscospaces.io/__attachments/a_07a6e400b74de10b21938181ca7c33df8acb0f5a40d4d4c72d3f1a7b50c75dc8/Screenshot%202025-03-11%20at%204.33.01%E2%80%AFpm.png?cb=2738d190f50c69931796de83fa35075a)

2. Click **Add a Group**

3. In the New Group window that appears, enter a name for the group. Note this name exactly, since it will be needed in Cisco Spaces rules when provisioning seamless authentication.

You have to configure this name as the policy name in the Cisco Spaces dashboard. If you are specifying the group name as "CaptiveBypass", this policy name will act as the default policy name for all the Captive Portal rules. That is, if you are not specifying a policy name for a Captive Portal rule for which the "Seamlessly Internet Provision" is opted, the policy name "CaptiveBypass" will be applied for that rule.

4. From the Bandwidth drop-down list, choose the required option, and specify the Internet bandwidth to be provisioned for the customers.

5. From the Splash drop-down list, choose **Bypass**.

![Screenshot 2025-03-11 at 4.39.32 pm.png](https://runbooks.ciscospaces.io/__attachments/a_a0ff818119885823885cf21000437f3f6099b9adc5300416f21f03853b098562/Screenshot%202025-03-11%20at%204.39.32%E2%80%AFpm.png?cb=9d572f67b0d75ad672108a09cc4234bc)

6. Save Changes

#### Catalyst Wireless Infrastructure Configuration

Click the arrow to expand content related to Catalyst Wireless Infrastructure Configuration.
Catalyst Wireless Infrastructure Configuration  

For detailed instructions on setting on Cisco Spaces Captive Portal with Catalyst 9800 WLC, please refer to the configuration guide [here](https://www.cisco.com/c/en/us/support/docs/wireless/dna-spaces/215423-dna-spaces-captive-portal-with-9800-cont.html#anc9).  
Please note, Catalyst 9800 Wireless Controller must have a trusted certificate installed tied to the virtual int ip/dns entry. If this is not set, clients will get an untrusted server error.

[Learn more](https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213917-generate-csr-for-third-party-certificate.html#anc5)

If further assistance is needed with the trusted certificate, please raised a TAC case with the Cisco Wireless team.

[Click here for a video guided demo](https://www.youtube.com/watch?v=b4BsPk-JZvY)

#### Create the Captive Portal SSID on Cisco Spaces

1. In Cisco Spaces dashboard, navigate to **Captive Portals** application:

![image-20250306-022921.png](https://runbooks.ciscospaces.io/__attachments/a_0d8b4a06bbc60c16f8e06f0c2eb187c0eabcd22c282df0b426998c089c469871/image-20250306-022921.png?cb=cb61ce7a85d417e398528c26b2621717)

2. Then: **SSID** -\> **Import / Configure SSID** -\> **AireOS Controller / Catalyst 9800 Wireless Controller**

   Choose the organization.

![image-20250306-033248.png](https://runbooks.ciscospaces.io/__attachments/a_2209bb293e7a6f5866566e180a7fe2f1284336379b1cf7d8df5e0ed8dcfcb45e/image-20250306-033248.png?cb=fd8baef1efd073b9cd56fb1324d072bc)

![image-20250306-034203.png](https://runbooks.ciscospaces.io/__attachments/a_f421ee9a57362f0c726f8dd9523e0da1d118c0e4828881f8d0b380022db412d4/image-20250306-034203.png?cb=52dcd1895ae2aef545fb1ac98da3898b)

![image-20250902-124036.png](https://runbooks.ciscospaces.io/__attachments/a_b5f557ed36f8c359179f9dd76b10eb337e214a09fcc2d35d751e89bdd8006eff/image-20250902-124036.png?cb=84fcbf67850fae8f341a35821031853d)

3. Create the SSID that you will use for the Captive Portal and click **Add** at the bottom.

![image-20250902-124626.png](https://runbooks.ciscospaces.io/__attachments/a_366ca9def622de03830dce40b8ae5daebb62ea2e36c5a39d290d450a38bb3126/image-20250902-124626.png?cb=fac6bec07c306b781b3c0715c7449e36)

4. Click **View Config Guide** to access key information needed for next steps.

![image-20250902-124534.png](https://runbooks.ciscospaces.io/__attachments/a_ce38bf1e0f26eda70e64b1d4f47c805e8891503da5e3be62c423e741fe262f66/image-20250902-124534.png?cb=9ae3b59d9429ac152b29c11612c4afc3)

#### Get Splash Page URL details

The Splash Page URL details are needed to redirect login to the Splash page. The URL is required to configure WebAuth paramaters in a later step.

1. After clicking **View Config Guide** (from the previous step), navigate to **Catalyst 9800 Wireless Controllers** -\> **Configure SSID** → **Creating the Access Control List**.

2. Under the section **Creating the Access Control List** , scroll down to Step 2g. and the Cisco Spaces splash URL for your tenant will be there. It will appear as:

   **https://splash.dnaspaces.io/\*\*/\*\*\*\*\*\*\***

If you are using the EMEA portal, the splash page URL will appear as **https://splash.dnaspaces.eu/\*\*/\*\*\*\*\*** or **https://splash.ciscospaces.sg/\*\*/\*\*\*\*** for APAC portal

3. Make a note of this URL to set in the WebAuth parameter later.

#### Create the Access Control List (if required)

By default, the 9800 creates hardcoded pre-auth ACLs when you setup a web-auth WLAN. These hardcoded ACLs allow DHCP, DNS, and traffic to the external web auth server. All the rest is redirected like any http traffic.

However, if you need to allow specific non-HTTP traffic type through, you can configure a pre-auth ACL. You would then need to imitate the content of the existing hardcoded pre-auth ACL and augment it to your needs. Please refer to the [ACL configuration guide](https://www.cisco.com/c/en/us/support/docs/wireless/dna-spaces/215423-dna-spaces-captive-portal-with-9800-cont.html#toc-hId-261502382).

#### Create the URL Filters List

Pre-authentication ACL is used in web authentication to allow certain types of traffic before the authentication is complete. This allows the clients limited access to particular network resources before authentication.

1. Log into Catalyst 9800 Wireless Controller.

2. Create the ACL by adding URL filters.

   a. Choose **Configuration** \> **Security** \> **URL Filters** .

   b. In the **URL Filters** window, click **Add** .

   c. In the **List Name** field, enter the list name.

   d. Keep **Type** as **PRE-AUTH**

   e. Change the status of **Action** to **Permit** .

   f. In the URLs field, enter the URL **splash.dnaspaces.io** (or **splash.dnaspaces.eu** if you are using the EMEA portal; or **splash.ciscospaces.sg** or for APAC portal)

   g. In ++addition++ to the splash domain configured in step f., add the following domains if you want to enable social authentication for the Captive Portal:

   \*.fbcdn.net

   \*.licdn.com

   \*.licdn.net

   \*.twimg.com

   \*.gstatic.com

   \*.twitter.com

   \*.akamaihd.net

   \*.facebook.com

   \*.facebook.net

   \*.linkedin.com

   ssl.gstatic.com

   \*.googleapis.com

   static.licdn.com

   \*.accounts.google.com

   \*.connect.facebook.net

   oauth.googleusercontent.com

   h. Click **Update \& Apply to Device**

![Screenshot 2025-09-23 at 7.35.14 pm.png](https://runbooks.ciscospaces.io/__attachments/a_729a028cdad98277e3c245fbc214445a8a8165b229e848dc586261771c8badae/Screenshot%202025-09-23%20at%207.35.14%E2%80%AFpm.png?cb=d584c8343ebdb4766ad88ba7dc41bf4c)

#### Captive Portal - when to use a RADIUS server?

The SSID can be configured to use a RADIUS Server or without it. There are some differences in configuration depending on whether RADIUS is used or not. Both scenarios will be covered in the following sections.

If the Session Duration, Bandwidth Limit, or Seamlessly Provision Internet is configured in the Actions section of the Cisco Spaces Captive Portal Rule configuration, the SSID needs to be configured with a RADIUS Server, otherwise, there is no need to use the RADIUS Server. All kinds of portals on Spaces are supported on both configurations.

Before getting into specific RADIUS / non-RADIUS configurations, ensure base settings like virtual IPs and trustpoint certificate are correct in the Global Web Auth Parameter.

##### Configure Global Web Auth Parameter

Configure the Global Web Auth Parameter to ensure the default base settings are correct.

1. Navigate to **Configuration** \> **Security** \> **Web Auth** , Click the 'global' parameter name to edit settings.

   ![Screenshot 2025-09-21 at 11.28.46 pm.png](https://runbooks.ciscospaces.io/__attachments/a_bda6ea010a2302d50da9c8cc5cfa09a8e10199d33dacd4afd967f5b33534b38d/Screenshot%202025-09-21%20at%2011.28.46%E2%80%AFpm.png?cb=429a1792dc209bfab11c170f5c584c5f)
2. Ensure both IPv4 and IPv6 are present with the default addresses.

**Important** : Ensure that both Virtual IPv4 and IPv6 addresses are configured in the global web auth parameter map. If the Virtual IPv6 is not configured, the clients are sometimes redirected to the internal portal instead of the configured Spaces portal. This is why a Virtual IP must always be configured.

IPv4: 192.0.2.1 can be configured as Virtual IPv4

IPv6: FE80:0:0:0:903A::11E4 can be configured as the Virtual IPv6.

There are little to no reasons to use other IPs than those.  
![Screenshot 2025-09-21 at 11.07.20 pm.png](https://runbooks.ciscospaces.io/__attachments/a_7805f523083dbc36053268f43235567d7b957bea7b46f42b8762245038ef0a4d/Screenshot%202025-09-21%20at%2011.07.20%E2%80%AFpm.png?cb=70f57087c7bc14a485a0255b052452d3)

3. Catalyst 9800 Wireless Controller must have a signed trusted certificate installed tied to the virtual int ip/dns entry. If this is not set, clients will get an untrusted server error. For information about certificates on Catalyst 9800, refer to <https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213917-generate-csr-for-third-party-certificate.html#anc5>

**Note** : In some cases, a trusted and signed certificate provider does not accept private IP address - such as the default 192.0.2.1. For such cases, please refer to the workaround in the FAQ section: [What if my certificate authority won't issue a certificate for the Catalyst 9800's virtual IP?](https://runbooks.ciscospaces.io/docs/cisco-spaces-captive-portal-runbook#CiscoSpacesCaptivePortalRunbook-Whatifmycertificateauthoritywon%E2%80%99tissueacertificatefortheCatalyst9800%E2%80%99svirtualIP(192.0.2.1)?)

4. Check the **Disable Success Window** and **Disable Logout Window** checkboxes (otherwise the Captive Portal will redirect to the local WLC version)

5. Click **Update \& Apply to Device** to save changes.

#### Configuring Captive Portal without RADIUS Server

##### Create the Web Auth Parameter (without RADIUS Server on Cisco Spaces)

A parameter map for web-based authentication sets parameters that can be applied to subscriber sessions during authentication. If you do not create a parameter map, the policy uses default parameters.

To create the Web Auth Parameter Map , perform the following steps:

1. Navigate to **Configuration** \> **Security** \> **Web Auth** , Click +**Add** to create a new parameter map. In the window that pops-up configure the parameter map name, and select **Consent** as the type and check the **Disable Success Window** and **Disable Logout Window** checkboxes (otherwise the Captive Portal will redirect to the local WLC version).

![Screenshot 2025-09-19 at 5.15.18 pm.png](https://runbooks.ciscospaces.io/__attachments/a_983b807d016c6b565eca942e0112f8630889c43178c26a1a45d8a20cfc7fc770/Screenshot%202025-09-19%20at%205.15.18%E2%80%AFpm.png?cb=46397736746c5e4a35194d31b676ff12)

2. Still in the Web Auth Parameter settings, navigate to the **Advanced** tab, and enter the Redirect for log-in URL, Append for AP MAC Address, Append for Client MAC Address, Append for WLAN SSID and portal IPv4 Address as follows and then click **Update** \& **Apply to Device**.

![Screenshot 2025-09-19 at 5.09.08 pm.png](https://runbooks.ciscospaces.io/__attachments/a_e0708067f8b8a4447b2b10e4f2e29d38374032d14f0e9b76b6361135e1400162/Screenshot%202025-09-19%20at%205.09.08%E2%80%AFpm.png?cb=709331957e0e30d9e734678e9eae98c6)

a. Redirect URL for Log-in = \<Specific URL for the customer tenant goes here\> (refer to **Get Splash Page URL details** section)

b. Redirect Append for AP MAC Address = **ap_mac**

c. Redirect Append for Client MAC Address = **client_mac**

d. Redirect Append for WLAN SSID = **wlan**

e. Portal IPV4 Address = **34.235.248.212** (++please perform an nslookup to the appropriate domain++ - e.g. **splash.dnaspaces.io** and use ++one++ of the values. Alternatively, refer to table below)  
Please consult the table below to work out the correct Portal IPV4 Address to use in Step 2e based on your Cisco Spaces tenant domain. Use only one IP address entry for Step 2e.  

|                  |                                              **Tenant Domain**                                              ||
|------------------|------------------------------------------------------|-------------------------------------------------------|
| **Global (.io)** | **splash.dnaspaces.io** 34.235.248.212 52.55.235.39  | **splash.ciscospaces.io** 3.33.232.255 15.197.234.109 |
| **EMEA (.eu)**   | **splash.dnaspaces.eu** 54.77.207.183 34.252.175.120 | **splash.ciscospaces.eu** 35.71.129.209 52.223.8.107  |
| **APAC (.sg)**   | N/A                                                  | **splash.ciscospaces.sg** 13.250.197.154              |

f. Click **Update \& Apply**

##### Configure Policy Profile on the 9800 Controller

Policy profile contains policy to be associated with the WLAN. It specifies the settings for client VLAN, URL filters, session and idle timeout settings and so on.

1. Navigate to **Configuration \> Tags \& Profiles \> Policy** and use the default policy, or create a new Policy Profile. Alternatively, clone the default-policy-profile to customise settings by clicking the checkbox on the left-hand side and then clicking **Clone**.

2. In the **Access** **Policies** tab, configure the **client** **VLAN** and add the **URL** **Filters** (created previously in **Create the URL Filters List**).

![Screenshot 2025-09-18 at 11.43.14 pm.png](https://runbooks.ciscospaces.io/__attachments/a_972aee3c0aa5f17eef56552f68561fad23a224c6a2f89a9fe14bd3d98e5b4a7c/Screenshot%202025-09-18%20at%2011.43.14%E2%80%AFpm.png?cb=c039e67360d8a0177644923cfb08f077)

##### Create the SSID on the 9800 Controller

1. Choose **Configuration** \> **Tags and Profiles** \> **WLAN**s.

2. Click **Add**.

3. On the **General** tab, in the **Profile Name** field, enter the profile name.

4. In the **SSID** field, enter the Captive Portal SSID name (ensuring that it matches exactly the Captive Portal SSID created in Cisco Spaces).

   ![Screenshot 2025-09-18 at 11.00.11 pm.png](https://runbooks.ciscospaces.io/__attachments/a_552dbe262a77c713d56eccead78d4bc2123062321b329ceb16c12f1679107aa5/Screenshot%202025-09-18%20at%2011.00.11%E2%80%AFpm.png?cb=c7745115ca89fdcecab88ed2f7ce128b)

**Important:** The SSID entered in this step much match exactly the SSID created in 'Create the Captive Portal SSID' step. ++The SSID in the Controller and Cisco Spaces must match exactly++ (case-sensitive).

5. Set the status as **Enabled**.

6. Click the **Security** tab, and then click the Layer2 tab.

7. From the **Layer 2 Security Mode** drop-down list, choose **None**.

8. Ensure **MAC Filtering**is unchecked

9. Uncheck **OWE Transition Mode**

   ![Screenshot 2025-09-18 at 11.05.40 pm.png](https://runbooks.ciscospaces.io/__attachments/a_b87e76de07a3dbc8f9a4b0e0a9b10a2cff5806b4b3dc5b4695737ac87a656545/Screenshot%202025-09-18%20at%2011.05.40%E2%80%AFpm.png?cb=aa69b5fa6926ea4b0ab47b3868d82fab)

10. Click the **Layer3** tab.

11. Check the **Web Policy** check box.

12. From the **WebAuth Parameter** Map drop-down list, choose the **Web Auth Parameter Map** created previously (in section Create the Web Auth Parameter (without RADIUS Server on Cisco Spaces)).

    ![Screenshot 2025-09-18 at 11.24.36 pm.png](/__attachments/a_7ae0bf2c2b41f9597e1818354e9f69cecc9dc6abdb934aff962013c3885862b8/Screenshot%202025-09-18%20at%2011.24.36%E2%80%AFpm.png?cb=6e5b597728a06888cca4481bcb26486d)

13. Click on the **Add to Policy Tags** tab

14. Link the Policy Tag with the Policy Profile

    ![Screenshot 2025-09-22 at 11.35.40 pm.png](/__attachments/a_309d50edf04ecbc9d3fc66f6bc9c55eccab6a12ba6a444e41c898cf1ab3c1eaf/Screenshot%202025-09-22%20at%2011.35.40%E2%80%AFpm.png?cb=34b97add3c563e6495571547a8fbcea3)

15. Click **Save** \& **Apply** **to Device**.

##### Apply Policy Tag to the AP

The Policy Tag configured in the previous step should be applied to the AP to broadcast the SSID.

1. Navigate to **Configuration \> Wireless \> Access Points**

2. Select the **AP** in question and add the **Policy** **Tag**

**Important:** This causes the AP to restart its CAPWAP tunnel and join back to the 9800 controller  
![Screenshot 2025-09-19 at 12.10.57 am.png](https://runbooks.ciscospaces.io/__attachments/a_b9884cb36ba5a4c81d06f64389398b7e63051631cc3377451f38d0f5c9cba830/Screenshot%202025-09-19%20at%2012.10.57%E2%80%AFam.png?cb=2f634a2794ab86234d9bbe72a773170f)

#### Configuring Captive Portal with RADIUS Server

##### Create the Web Auth Parameter Map (with RADIUS Server on Cisco Spaces)

A parameter map for web-based authentication sets parameters that can be applied to subscriber sessions during authentication. If you do not create a parameter map, the policy uses default parameters.

To create the Web Auth Parameter Map, perform the following steps:

1. Navigate to **Configuration** \> **Security** \> **Web Auth** , Click +**Add** to create a new parameter map. In the window that pops-up configure the parameter map name, and select **Webauth** as the type and check the **Disable Success Window** and **Disable Logout Window** checkboxes (otherwise the Captive Portal will redirect to the local WLC version).

   ![Screenshot 2025-09-19 at 5.52.17 pm.png](https://runbooks.ciscospaces.io/__attachments/a_8b412a9269be042c657e67507c42274d78ab5a82230fbf24d1b7b53d2cc276ed/Screenshot%202025-09-19%20at%205.52.17%E2%80%AFpm.png?cb=a8c39197bf3e9d0b3f7d9b40cf054ebb)

2. Still in the Web Auth Parameter, navigate to the **Advanced** tab, and enter the Redirect for log-in URL, Append for AP MAC Address, Append for Client MAC Address, Append for WLAN SSID and portal IPv4 Address as follows and then click **Update** \& **Apply to Device** .

![Screenshot 2025-09-19 at 5.09.08 pm.png](https://runbooks.ciscospaces.io/__attachments/a_e0708067f8b8a4447b2b10e4f2e29d38374032d14f0e9b76b6361135e1400162/Screenshot%202025-09-19%20at%205.09.08%E2%80%AFpm.png?cb=709331957e0e30d9e734678e9eae98c6)

a. Redirect for Log-in = \<Specific URL for the customer tenant goes here\> (refer to **Get Splash Page URL details** section)

b. Redirect Append for AP MAC Address = ap_mac

c. Redirect Append for Client MAC Address = client_mac

d. Redirect Append for WLAN SSID = wlan

e. Portal IPV4 Address = 34.235.248.212 (++please perform an nslookup to the appropriate domain++ - e.g. **splash.dnaspaces.io** and use ++one++ of the values. Alternatively, refer to table below)  
Please consult the table below to work out the correct Portal IPV4 Address to use in Step 2e based on your Cisco Spaces tenant domain. Use only one IP address entry for Step 2e.  

|                  |                                              **Tenant Domain**                                              ||
|------------------|------------------------------------------------------|-------------------------------------------------------|
| **Global (.io)** | **splash.dnaspaces.io** 34.235.248.212 52.55.235.39  | **splash.ciscospaces.io** 3.33.232.255 15.197.234.109 |
| **EMEA (.eu)**   | **splash.dnaspaces.eu** 54.77.207.183 34.252.175.120 | **splash.ciscospaces.eu** 35.71.129.209 52.223.8.107  |
| **APAC (.sg)**   | N/A                                                  | **splash.ciscospaces.sg** 13.250.197.154              |

f. Click **Update \& Apply**

**Configure Radius Server**

To provide an additional layer of security for your portal, the Cisco Spaces supports radius-authentication for the internet provisioning on the captive portals.

As part of the Radius AAA configuration, Radius Authentication and Authorization servers will be set up.  
Radius Accounting servers are not required for Captive Portals and should not be configured

1. Log into Catalyst 9800 Wireless Controller. Cisco Spaces acts as the RADIUS server for user authentication and it can respond to two IP addresses.

2. Configure the RADIUS server.

We highly recommend to use RADIUS authentication for captive portals. The following features work only if you configure RADIUS authentication.

a. Seamless Internet Provisioning.

b. Extended session duration.

c. Deny Internet.

3. Choose **Configuration** \> **Security** \> **AAA**.

4. In the Authentication Authorization and Accounting window, click the **Servers/Groups** tab.

5. Choose **Radius** \> **Servers** , and click **Add**.

6. In the **Name** field, enter a name for the radius server.

7. In the **IPv4 / IPv6 Server Address** field, enter the radius server address.

   **Radius Servers**

   Only Cisco Spaces RADIUS servers can be configured. The servers are listed below.

|    **Host**    |                                                        34.197.146.105 34.228.1.95                                                        |
|----------------|------------------------------------------------------------------------------------------------------------------------------------------|
| **Port**       | 1812                                                                                                                                     |
| **Secret Key** | \*\*\*\*\*\*\*\*\*\*\*\*\*\* \[A customer specific key has to be sourced from the Cisco Spaces dashboard Captive Portal app. See below\] |

To view the RADIUS server Secret Key, click the **Captive Portal** app in Cisco Spaces dashboard. Click **SSIDs** , and then click the **Configure Manually** link for the Cisco Catalyst SSID. In the window that appears, click the **Configure Radius Server** tab and the Key field password will be there. **Tip**: Search for "Key field" in the window.  
![Screenshot 2025-09-19 at 10.10.31 pm.png](https://runbooks.ciscospaces.io/__attachments/a_0d3c9cefcc5f2b8089704fae052bdadbc99908084047c69aad3126eb6b79b78c/Screenshot%202025-09-19%20at%2010.10.31%E2%80%AFpm.png?cb=0b8897cea689a304034df6b858155bfd)

8. In the **Key** field, enter the key: \*\*\*\*\*\*\*\*\*\*\*\*\* and confirm it in the **Confirm Key** field.

9. In the **Auth Port** field, enter **1812**.

10. In the **Acct Port** field, enter **1813**.

11. Click **Save** \& **Apply to Device** . The server added will be available in **Servers** list.

12. Repeat step 5. if a second Radius server is desired, otherwise proceed to creating a Server Group in the next step.

    ![Screenshot 2025-09-21 at 10.45.48 pm.png](/__attachments/a_af846e38a9c33e54aeceabe47a5890861d7ae894f604faae387e957faa8c3865/Screenshot%202025-09-21%20at%2010.45.48%E2%80%AFpm.png?cb=4bc0a110c6987b689395605e480b16d6)

13. Choose **Radius** \> **Server Groups** , and click **Add**.

14. In the **Name** field, enter a name.

15. From the **MAC-Delimiter** drop-down list, choose **hyphen**.

16. From the **MAC-Filtering** drop-down list, choose **mac**.

17. Move the radius server previously created from "**Available Servers** " to "**Assigned Servers**" using the arrow button.

18. Click **Save** \& **Apply to Device** .

    ![Screenshot 2025-09-19 at 10.32.38 pm.png](/__attachments/a_ab05cee2c70bc1b527fef2fa77913423769e180ea8973fdf65503321902781f7/Screenshot%202025-09-19%20at%2010.32.38%E2%80%AFpm.png?cb=910c9d18ed950181df7791b7e15a8199)

19. In the **Authentication Authorization and Accounting** window, click the **AAA Method List** tab.

20. Click **Authentication** , and click **Add** and specify the following details:

    1. In the **Method List Name** field, enter the method list name.

    2. From the **Type** drop-down list, choose **Login**

    3. From the **Group** Type drop-down list, choose **Group**.

    4. Move the server group created earlier from **Available Server Groups** to **Assigned Servers Groups** , and click **Save** \& **Apply to Device** .

       ![Screenshot 2025-09-19 at 10.36.58 pm.png](/__attachments/a_09a27c007969a2432df3298f4fc2f7ee4187f946a5d5f3005ef5fdf92930fe70/Screenshot%202025-09-19%20at%2010.36.58%E2%80%AFpm.png?cb=e5cd3abe3f2bb992350d73773bdac249)

21. On the AAA Method List tab, click **Authorization** , and click **Add**, and specify the following details:

    1. In the **Method List Name** field, enter the method list name.

    2. From the **Type** drop-down list, choose **Network**.

    3. From the **Group Type** drop-down list, choose **group**.

    4. Move the server group previously created (point 12. to point 17.) from **Available Servers** to **Assigned Servers** using the arrow button, and click **Save** \& **Apply to Device** .

       ![Screenshot 2025-09-19 at 10.37.46 pm.png](/__attachments/a_3220b6a963d2b855efd2bc42180f3e52e1a1d6851fc86133a58663a7af146fc7/Screenshot%202025-09-19%20at%2010.37.46%E2%80%AFpm.png?cb=18e42a831938507ca03dc476069a5970)

As mentioned previously, Radius Accounting servers are not required for Captive Portals and should not be configured.

##### Configure Policy Profile on the 9800 Controller

Policy profile contains policy to be associated with the WLAN. It specifies the settings for client VLAN, URL filters, session and idle timeout settings and so on.

1. Navigate to **Configuration \> Tags \& Profiles \> Policy** and create a new Policy Profile or use the default Policy Profile.

   ![Screenshot 2025-09-19 at 11.23.06 pm.png](https://runbooks.ciscospaces.io/__attachments/a_c05b608b30c52cb854d398f80aeaf298dcc94c96ec39d88fcb19977b06ef82a7/Screenshot%202025-09-19%20at%2011.23.06%E2%80%AFpm.png?cb=af95b798069bfc7841dcf68e47062ce7)

2. In the **Access Policies** tab, configure the client VLAN and add the URL filter.

   ![Screenshot 2025-09-19 at 11.23.23 pm.png](https://runbooks.ciscospaces.io/__attachments/a_e0aff5baf9b98e7cde02aae92d3979a5da9fd9e1e986c3dd928dde4c804653a3/Screenshot%202025-09-19%20at%2011.23.23%E2%80%AFpm.png?cb=7e2cf7ed50ff867363ee8df314db6b1a)

3. In the **Advanced tab** , in the **AAA Policy** area, check the **Allow AAA Override** check box

4. Click **Update** \& **Apply to Device** .

   ![Screenshot 2025-09-19 at 11.24.08 pm.png](https://runbooks.ciscospaces.io/__attachments/a_feed34058e54c0195a16d0534614bd7c389f3df8300ba3afcda17ce41f26bf45/Screenshot%202025-09-19%20at%2011.24.08%E2%80%AFpm.png?cb=b5e1b281be76e3801bff5de63e39268d)

##### Create the SSID

1. Choose **Configuration** \> **Tags and Profiles** \> **WLAN**s.

2. Click **Add**.

3. On the **General** tab, in the **Profile Name** field, enter the profile name.

4. In the **SSID** field, enter the Captive Portal SSID name (ensuring that it matches exactly the Captive Portal SSID created in Cisco Spaces).

   ![Screenshot 2025-09-19 at 5.45.06 pm.png](https://runbooks.ciscospaces.io/__attachments/a_92984f2a962783994c7c249c4601cdd09b387c5f7785a23a0c829fb5e6e351a6/Screenshot%202025-09-19%20at%205.45.06%E2%80%AFpm.png?cb=0703f120b9000ca774e64981bd8d1f9f)

**Important:** The SSID entered in this step much match exactly the SSID created in 'Create the Captive Portal SSID' step. ++The SSID in the Controller and Cisco Spaces must match exactly++ (case-sensitive).

5. Set the status as **Enabled**.

6. Click the **Security** tab, and then click the **Layer2** tab.

7. From the **Layer 2 Security Mode** drop-down list, choose **None**.

8. Enable **MAC Filtering** , uncheck **OWE Transition Mode** and add the **Authorization List**

   ![Screenshot 2025-09-19 at 10.56.52 pm.png](https://runbooks.ciscospaces.io/__attachments/a_92e5c05e6f4cc88c9d6c21dd25e6df84edcecdf44d1575b1754f0d700ca846c2/Screenshot%202025-09-19%20at%2010.56.52%E2%80%AFpm.png?cb=3a30047fe39b36725e493cb18c8b8015)

9. Click the **Layer3** tab.

10. Check the **Web Policy** check box.

11. From the **WebAuth Parameter** **Map** drop-down list, choose the **Web Auth Parameter Map** created previously.

12. From the **Authentication List** drop-down list, choose the Authentication Server created previously.

13. Check the **On Mac Filter Failure** check box.

14. If Pre-authentication ACLs were needed and created previously, you can select them here.

![Screenshot 2025-09-19 at 11.01.56 pm.png](https://runbooks.ciscospaces.io/__attachments/a_8687172050383eb591ff3e60e016383e8040807da24fbca66f64d0fab0ee1a6a/Screenshot%202025-09-19%20at%2011.01.56%E2%80%AFpm.png?cb=93260c72bbd18547cc35bba3cfa124c4)

15. Click on the **Add to Policy Tags** tab

16. Link the Policy Tag with the Policy Profile

    ![Screenshot 2025-09-19 at 11.46.51 pm.png](/__attachments/a_99a145f2b5af2c1d9d1631cc06e1d4d1102fdde4a7649f809fe8eafb35ac2bd2/Screenshot%202025-09-19%20at%2011.46.51%E2%80%AFpm.png?cb=7a71e4b7c53d7a2859f74085a5eea15a)

17. Click **Save** \& **Apply** **to Device**.

##### Apply Policy Tag to AP to Broadcast SSID

1. Navigate to **Configuration \> Wireless \> Access Points**

2. Select the AP in question

3. Add the **Policy Tag**.

4. Click Update \& Apply to Device

**Important:** This causes the AP to restart its CAPWAP tunnel and join back to the 9800 controller.  
![Screenshot 2025-09-19 at 11.56.00 pm.png](https://runbooks.ciscospaces.io/__attachments/a_a3b82656a424eae4b608a8959c0ed7d9c65a9d79045e539a3c26b71063daba58/Screenshot%202025-09-19%20at%2011.56.00%E2%80%AFpm.png?cb=ff9ec5b80b29545bbae5100cba35b3d7)

*** ** * ** ***

### Captive Portal Configuration (No Authentication)

Once the Wireless Infrastructure has been setup. Configuring the Captivate Portal requires the following tasks:

1. Create or Import Portal

2. Set authentication and data capture settings

3. Configure rules and triggers

For a video guided demo, please see the links below:

[++***How to Setup Instant Portals***++](https://www.youtube.com/watch?v=r3QH0G1qcFU)

[++***How to Configure Captive Portal Rules***++](https://www.youtube.com/watch?v=9cg9NtEYGeM)

#### Create a Portal

1. In Cisco Spaces, navigate to **Captive Portal App** -\> **Portal**

![Screenshot 2025-03-17 at 3.45.33 pm.png](https://runbooks.ciscospaces.io/__attachments/a_7202760e47d6e91b2d8439fff6d58d575075d9e3fc2e7e7147a562e60e45df74/Screenshot%202025-03-17%20at%203.45.33%E2%80%AFpm.png?cb=50bfddcc33841cdef420fb4b804b04e8)

2. Either create a new portal or use one of the templates like Covid-19 specific templates. If using a templates, select a template and duplicate it for editing.

![Screenshot 2025-03-17 at 3.45.43 pm.png](https://runbooks.ciscospaces.io/__attachments/a_0b0d5cfcfdda1966029a62b2b75e1daedbd3dab35b0817075b189cee9f600c0d/Screenshot%202025-03-17%20at%203.45.43%E2%80%AFpm.png?cb=109642827ca340b3e2077276e99dd09b)  
![Screenshot 2025-03-17 at 3.45.58 pm.png](https://runbooks.ciscospaces.io/__attachments/a_8779459d941af0ba12baedfda2708eaaf514559b8a73d4d67607b8c41df0ff37/Screenshot%202025-03-17%20at%203.45.58%E2%80%AFpm.png?cb=36aa455f4dbfceea1302f78f88613a58)

3. Enter a name for the portal and select the locations where this portal will be used. Select **Next**

![Screenshot 2025-03-17 at 3.58.39 pm.png](https://runbooks.ciscospaces.io/__attachments/a_31c54144b2ba43527c887fab1e7fe9362414bd63ac8d5e0c4c0aace78a6a2fe6/Screenshot%202025-03-17%20at%203.58.39%E2%80%AFpm.png?cb=023fd3718ff468dec331b6160c8781b3)

4. Select the authentication type as per need. For no specific authentications need, select **No Authentication** as an example.

For other Captive Portal Authentication methods, please refer to our Knowledge Article: \[Coming Soon\]

![Screenshot 2025-03-17 at 3.59.18 pm.png](https://runbooks.ciscospaces.io/__attachments/a_7466b752e4fa8a15ccaee69b8c94ef313b7f413b7a611ab331278af2d14dff2f/Screenshot%202025-03-17%20at%203.59.18%E2%80%AFpm.png?cb=fd7d4edf4e15651276bd0828cc536cfb)

5. Choose if Data Capture and User Agreements need to be displayed on the portal. Remain unselected if not needed.

6. Choose if users need to specifically agree to opt-in the network. Put the opt-in message, choose the default behaviour.

![Screenshot 2025-03-17 at 4.24.58 pm.png](https://runbooks.ciscospaces.io/__attachments/a_d4a45db8ae310ffac05ace95eda4dc8907ab6a67d85e1620ba5b992b0fcb6a49/Screenshot%202025-03-17%20at%204.24.58%E2%80%AFpm.png?cb=ba67af58f4c157441a019f998e261469)

7. If you want to show a specific Data Capture form that users must complete, enable Data Capture.

8. Multiple Fields are available to be chosen, and fields can be made mandatory to be completed by visitors.

![Screenshot 2025-03-17 at 4.27.35 pm.png](https://runbooks.ciscospaces.io/__attachments/a_c473cc4a7046b9f3f64b0de96cf96255da041e17b4329221470876d1c1d6dc10/Screenshot%202025-03-17%20at%204.27.35%E2%80%AFpm.png?cb=f7fd40e93b7053676bafebc9aeb9b15b)  
![Screenshot 2025-03-17 at 4.28.16 pm.png](https://runbooks.ciscospaces.io/__attachments/a_9dd1596ea43cf860e2b2b2995c6f51c31a9e01eda06502598e4d54291c94f913/Screenshot%202025-03-17%20at%204.28.16%E2%80%AFpm.png?cb=2f391bc807db34465f2406af82ef0df9)

9. After all needed fields are chosen, click **Next**.

10. Select and configure the Terms and Conditions as necessary. Choose whether to Enable Terms and Conditions, Enable Privacy Policy or Age Gating.

![Screenshot 2025-03-17 at 4.32.32 pm.png](https://runbooks.ciscospaces.io/__attachments/a_a8830cec5e2e7f74acbbc642900f2791a84a328c91c136d569cfffd48403282b/Screenshot%202025-03-17%20at%204.32.32%E2%80%AFpm.png?cb=852333f204a689d61e3e62fe1940d613)

11. Select Save and Configure Portal when done.

#### Edit the Captive Portal Settings

1. Click the newly created portal to start editing it.

![Screenshot 2025-03-19 at 4.07.26 pm.png](https://runbooks.ciscospaces.io/__attachments/a_24888d9fc28511ded56a257e2127ad65defb0e8da85f47c63ed4c1a3041a677d/Screenshot%202025-03-19%20at%204.07.26%E2%80%AFpm.png?cb=630c3dc87e445881286f2da984b6db35)

2. In the Portal Editor window, edit as well as reorder all the modules on the side panel by dragging and dropping them in the desired sequence.

![image-20250318-051423.png](https://runbooks.ciscospaces.io/__attachments/a_caf46b01830f8aeb120538bfb2f77ab55f728b9cf26b0e437e6bc4157a181d32/image-20250318-051423.png?cb=57842ef9244b1a8b27ce7a0dbcac8b10)

3. Type in any required welcome message. You can preview the look and feel of the Captive Portal page on the right-side Portal Preview panel that renders draft-changes live.

![Screenshot 2025-03-17 at 4.34.13 pm.png](https://runbooks.ciscospaces.io/__attachments/a_e3dca425bf0937eab691b4dd5e85d73ad2e1a1f2aab2b1bf2f04f204da15a49e/Screenshot%202025-03-17%20at%204.34.13%E2%80%AFpm.png?cb=d0c49ab73af8d3d970ad9b504dcaf139)

![Screenshot 2025-03-17 at 4.35.11 pm.png](https://runbooks.ciscospaces.io/__attachments/a_dc9f6545353ba620221d8029f9a9fb7fabf82f63f2eadf011cbdf6e9107a812e/Screenshot%202025-03-17%20at%204.35.11%E2%80%AFpm.png?cb=28231bd80cc9fe98f9871b8b0073a002)

4. Smart variables can also be added in the messages using $\<key\>.

| **Smart Variable** |        **Description**         |
|--------------------|--------------------------------|
| $location          | Location Name as per Hierarchy |
| $Address           | Address of the location        |
| $State             | State of the location          |
| $Zipcode           | Zip Code of the location       |
| $Country           | County of the location         |
| $City              | City of the location           |

5. These variables in this Portal Editor section pertains to the properties of the ++location where the client is connecting++ - i.e. which buildings, floor etc.

6. The Landing page upon success can be edited by clicking **Get Internet**

![Screenshot 2025-03-18 at 4.17.33 pm.png](https://runbooks.ciscospaces.io/__attachments/a_425b7ea69ba93a3c69a460648c6400174ba35c68b4db42a2e011a113976e47c8/Screenshot%202025-03-18%20at%204.17.33%E2%80%AFpm.png?cb=43d223e82eb21b7e743b95505915a60f)

7. New modules can be added directly with additional content.

![Screenshot 2025-03-18 at 4.18.00 pm.png](https://runbooks.ciscospaces.io/__attachments/a_f9c302c5f6dfc55b18442cefb53b6cb99c4a1c8af4005ca3ab00f677cbe76e96/Screenshot%202025-03-18%20at%204.18.00%E2%80%AFpm.png?cb=3bad458e0e13b7b593d6f4aebacd73c3)

8. Any previous configurations can be edited by clicking the pencil icon on top of the Portal Editor page.

![Screenshot 2025-03-18 at 4.18.27 pm.png](https://runbooks.ciscospaces.io/__attachments/a_172cb894a53673ed3369b4617b3db7b54cf5ad99f8e3805fdd07322c65a2e158/Screenshot%202025-03-18%20at%204.18.27%E2%80%AFpm.png?cb=e8fc0343f9e1ecf44b871d818c3fbf38)

#### Create Portal Rules

1. Navigate to Cisco Spaces and then, **Captive Portal App** -\> **Captive Portal Rules**

![.png](https://runbooks.ciscospaces.io/__attachments/a_04932bd3c7c3838318dca14d9ff97fe91f1b707ce35866a5dca932cc05f57a88/%20.png?cb=7ab68821d76e9cd61ad878e7c1eac662)

2. Create a new rule to make a specific rule to be triggered as needed by click **Create New Rule**.

3. Enter a name for the rule. Select which SSID is this rule going to triggered against. The SSID should have already been imported / configured from earlier steps.

![Screenshot 2025-03-18 at 4.44.32 pm.png](https://runbooks.ciscospaces.io/__attachments/a_560b8d9f1db38808cdcc6c18a6cb7ea026d1ee9efc252b5d795e8eb36f255ddf/Screenshot%202025-03-18%20at%204.44.32%E2%80%AFpm.png?cb=603255bea22a3ca2ebe1fdbc2d85bf61)

4. Add a location against which this rule should be be triggered. At least one location level needs to be selected.

![Screenshot 2025-03-19 at 2.38.21 pm.png](https://runbooks.ciscospaces.io/__attachments/a_e21d6aef5fb3fcb6ee6364ee94be60ebbf80a6c4c60f4b8156bd3f7db42f7696/Screenshot%202025-03-19%20at%202.38.21%E2%80%AFpm.png?cb=19f93ed480216a991784be2eba08e56c)

5. Location needs to be chosen from existing location hierarchy and can be chosen all the way from entire campus levels all the way down to a single zone on a floor.

![Screenshot 2025-03-19 at 1.02.03 pm.png](https://runbooks.ciscospaces.io/__attachments/a_0fe3e71b0d881d28880f1a87efeb145988ed3367d7ed8ad14512823bfa64683a/Screenshot%202025-03-19%20at%201.02.03%E2%80%AFpm.png?cb=a0127b7e5bc238ca9f67cb37b4a4b6ad)

6. Any mix of locations can be selected inc. AireOS, Catalyst or Meraki networks. Click **Done** once the networks are selected.

The rule will be triggered only if a client is connecting on an AP that exists in the selected location.

7. In the Locations Section, if the location hierarchy has metadata tags in use, the rule can also be triggered against very specific locations. Example Use Case: Exclude "yet to open" sites and include "recently opened" sites for a new portal campaign.

![Screenshot 2025-03-19 at 2.59.40 pm.png](https://runbooks.ciscospaces.io/__attachments/a_f3760d0d49410c49bdcb25f91dc37b0e9cf482c592cfad925f0e5cb62f71070a/Screenshot%202025-03-19%20at%202.59.40%E2%80%AFpm.png?cb=e7795faaf96371aa37fe9a7522e3fc56)

8. In the Identify section, multiple selections are available to be tweaked. Cisco Spaces saves mac-address used by clients to achieve these filters. The table below details the options:

|     **Identify Filter**     |                                                                                                        **Function**                                                                                                        |
|-----------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Filter by Onboarding Status | Allows to chose a particular action or portal for visitors who have already completed captive portal authentications previously or not.                                                                                    |
| Filter by Opt-In Status     | Allows to chose a particular action or portal for visitors who have specifically chosen to opt-in.                                                                                                                         |
| Filter by Tags              | Captive Portals application and Location Personas application can tag visitors with specific tags based on their on-location behavior. This tags can be used to trigger a specific action or portal for specific visitors. |
| Filter by Previous Visits   | Allows to chose a particular action or portal based on whether a client has come into a specific location at least a specific number or between a number of times in particular days or day ranges                         |

![image-20250319-040803.png](https://runbooks.ciscospaces.io/__attachments/a_56dc1e68768a6f545b1a35920fc8f44a28058de67f885cc01897649b344afd73/image-20250319-040803.png?cb=66581c8233d341380822f84102da1f26)

9. In the Actions Section -- multiple selections are available. The table below details the options:

|          **Actions**          |                                                                                                        **Function**                                                                                                        |
|-------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Show Captive Portal           | A specific portal that is created can be chosen to be shown. Different rules can be created to show different types of portals                                                                                             |
| Seamlessly Provision Internet | This option can be used to avoid showing the portal and directly onboard visitors' devices. *For Seamless Provisioning in Meraki*-- choose the exact group policy name which was provided in Meraki configuration earlier. |
| Deny Internet                 | This option can be used to reject the device association.                                                                                                                                                                  |

10. Furthermore, a tag can be created to be assigned to visitors that match all the rules and get successfully onboarded to the network.

![image-20250319-043123.png](https://runbooks.ciscospaces.io/__attachments/a_976214077df60853af3ad99c73547a81e77be735b602fc34f17c3003376228da/image-20250319-043123.png?cb=0048f9e79ef2cff3fa7f6b550dbc9afa)

11. External APIs can be triggered when a new client is onboarded for the very first time. For triggering an API every time a client is successfully onboarded, 'Enable for repeat visitors' can be selected.

![image-20250319-043606.png](https://runbooks.ciscospaces.io/__attachments/a_5a90f69a24c43027372dbea3c213cb6a229a8e5aabaa02360dcc9dabe9479877/image-20250319-043606.png?cb=155edea9c0f89769f1bc1b611b4f17ef)  
These variables in this API section pertains to the properties of ++the visitor that is connecting++. (Example: visitor name, gender etc.)  
Many variables like email, name, address etc. are only available if they were captured for the same visitor using the Data Capture form in the portal.

The following Smart Variables are available in Captive Portals API:  

| **Variable Details**  | **Smart Variables**  |
|-----------------------|----------------------|
| Location Name         | $locationName        |
| Email                 | $email               |
| Address               | $Address             |
| Mac-address           | $macaddress          |
| Mobile                | $mobile              |
| State                 | $State               |
| Encrypted Mac-address | $encryptedMacaddress |
| Gender                | $gender              |
| Zip Code              | $Zipcode             |
| Device subscriber ID  | $deviceSubscruberId  |
| Opt in Status         | $optinstatus         |
| Country               | $Country             |
| First Name            | $firstName           |
| URL                   | $URL                 |
| City                  | $City                |
| Last Name             | $lastName            |
| Type                  | $Type                |

12. View the overall created rule in the summary section on the right-side of the dashboard.

![image-20250319-045058.png](https://runbooks.ciscospaces.io/__attachments/a_c15de0ded7578321c8148004edaeacf27dbf233e0e51e8e85ea113f2a40fb6dc/image-20250319-045058.png?cb=164432b368696f8e6e140f9874429960)

13. If satisfied with the rule, click **Save \& Publish** .

![image-20250319-045127.png](https://runbooks.ciscospaces.io/__attachments/a_91fbf8b9e66ff7687db7f9d2e4d8dfbea1d5d7dac0fbc6c7879cd4dcd7100030/image-20250319-045127.png?cb=55ea8400072e407bc44c43e7935ffd47)

14. Once the rule is pushed, the Captive Portal will show up as being Live in the Portal window.

![Screenshot 2025-03-19 at 4.03.17 pm.png](https://runbooks.ciscospaces.io/__attachments/a_76f019e9312fad1600708988d76cb7b55e932e83addb4ddcd78ca02802574f6d/Screenshot%202025-03-19%20at%204.03.17%E2%80%AFpm.png?cb=6d2f4c772784c4391db91f6116813779)

*** ** * ** ***

## FAQ

### What does the complete data flow look like from guest end-device to having Captive Portal provision Internet?

**Meraki Data Flow (with Radius)**  
![MERAKI FLOW WITH RADIUS AUTHENTICATION - SIGN-ON.png](https://runbooks.ciscospaces.io/__attachments/a_f865202e0c41194d023976491a8e09107a76c85d85d025c753af44605ea889de/MERAKI%20FLOW%20WITH%20RADIUS%20AUTHENTICATION%20-%20SIGN-ON.png?cb=e8ac1d34c9739b36a32e5bf42acc999f)

**Meraki Data Flow (without Radius)**  
![Meraki_data_flow.png](https://runbooks.ciscospaces.io/__attachments/a_b8e8e824455147bb3d3aae472374683fa32b370b75fd29f50f6e5fd6cc172d93/Meraki_data_flow.png?cb=917b3c6f88bca2401cb623d724c5d47e)

**Catalyst Data Flow (with Radius)**

![Flow With Radius.png](https://runbooks.ciscospaces.io/__attachments/a_e8fbce9578bfc5517336e022ba42080eac0b24befae0cbdd4148a5b900e153fc/Flow%20With%20Radius.png?cb=a6c7cb61ab363d036ba3f068d76ef404)

**Catalyst Data Flow (without Radius)**

![Flow without Radius.png](https://runbooks.ciscospaces.io/__attachments/a_2dceba794177a9194baa7b2b683456552f8d9ae12a999b847d9274dd9a32112a/Flow%20without%20Radius.png?cb=dd8930ed315b67d93598c618f98fe583)

**What if my certificate authority won't issue a certificate for the Catalyst 9800's virtual IP (192.0.2.1)?**

When configuring a Captive Portal on a Catalyst 9800 Wireless Controller, it's essential to install a trusted SSL/TLS certificate that matches the controller's virtual interface IP address or DNS name. Without a trusted certificate, users will encounter browser security warnings when redirected to the captive portal.

The virtual IP address used by the Catalyst 9800 is typically 192.0.2.1, which is a reserved, non-routable address used internally by the controller.

However, many public Certificate Authorities (CAs) will not issue certificates that include private or reserved IP addresses (such as 192.0.2.1) in the Subject Alternative Name (SAN) field, as this violates industry standards and CA policies.

**Workaround:**

To resolve this, use a domain name instead of the IP address in the certificate's SAN field.

**Example 1:**

* WLC virtual IP: `192.0.2.1`

* Chosen domain: `wlc-portal.company.com`

* Internal DNS record:

  `wlc-portal.company.com → 192.0.2.1`

* Certificate SAN: `DNS:wlc-portal.company.com` (no IP addresses)

**Example 2:**

* WLC virtual IP: `192.0.2.1`

* Chosen domain: `guestwifi.melbournebranch.local`

* Internal DNS record:

  `guestwifi.melbournebranch.local → 192.0.2.1`

* Certificate SAN: `guestwifi.melbournebranch.local` (no IP addresses)

  Follow these steps:

1. **Choose a Domain Name:** Select a unique domain name (e.g., `wlc-portal.example.com`) to represent the WLC's virtual interface.

2. **Configure the WLC:** In the Catalyst 9800 configuration, set the virtual interface's DNS name to the chosen domain name.

   1. Log in to the Catalyst 9800 WLC web GUI

   2. Navigate to **Configuration \> Security \> Web Auth**

   3. Click the "global" Web Auth to begin configuration

   4. Locate **Virtual IPv4 Hostname**

   5. Enter your chosen domain name (e.g., `wlc-portal.example.com`)

   6. **Click Update \& Apply to Device**

      ![Screenshot 2025-09-23 at 1.33.26 pm.png](/__attachments/a_64646eb2506b16740127c675d1e895c8f371510513e22fc48515b3d549bcd5a0/Screenshot%202025-09-23%20at%201.33.26%E2%80%AFpm.png?cb=207c3eb1b8982cb4418ca3f7067612b2)

Alternatively, via CLI:  

|                                                             **CLI Config**                                                             |
|----------------------------------------------------------------------------------------------------------------------------------------|
| config parameter-map type webauth global virtual-ip dns-name [wlc-portal.example.com](http://wlc-portal.example.com/) end write memory |

3. **Update Internal DNS:** On your internal (on-premises) DNS server, create a DNS record that resolves the domain name to the virtual IP address (`192.0.2.1`).

4. **Obtain the Certificate:** Request a certificate from a public CA with the chosen domain name in the SAN field---do not include the private IP address.

5. **Install the Certificate:** Upload and apply the certificate to the Catalyst 9800 controller.

This approach ensures clients see a trusted certificate when accessing the captive portal, while avoiding issues with CAs rejecting certificates that reference private IPs.  
* This workaround relies on all client devices using your internal DNS when connecting to the wireless network.

* If devices use external DNS (e.g., 8.8.8.8), they may not be able to resolve the domain, potentially causing captive portal issues.

* Always ensure the domain name used is not publicly resolvable to avoid conflicts or security concerns.

* After changing the virtual IP DNS name, you may need to clear client browser DNS caches or disconnect/reconnect Wi-Fi clients for changes to take effect.

---
language: "en"
---
# Cisco Spaces Day 2 Runbooks

The Cisco Spaces Day 2 Runbooks are operational guides designed to support ongoing management, optimization, and governance of a Cisco Spaces deployment after initial implementation (Day 1). While Day 1 focuses on deployment and configuration, the Day 2 Runbooks provide structured guidance for sustaining and scaling the solution in a production environment.

These documents outline the processes, roles, and best practices required to maintain platform health, ensure data integrity, manage integrations, support end users, and continuously improve outcomes. It includes operational workflows, monitoring and alerting recommendations, change management considerations, performance validation checkpoints, and escalation paths. The runbook also defines ownership models across IT, facilities, security, and business stakeholders to ensure accountability and alignment.

Designed as a practical, repeatable reference, the Day 2 Runbook enables teams to:

* Maintain system performance and reliability

* Operationalize reporting and insights

* Govern data access and compliance requirements

* Manage upgrades, feature enhancements, and integrations

* Troubleshoot issues efficiently

* Drive continuous value realization

Ultimately, the Cisco Spaces Day 2 Runbooks serve as the authoritative guide for steady-state operations, ensuring the platform remains aligned with business objectives and delivers sustained value over time.

---
language: "en"
---
# Cisco Spaces Design & Deployment Module FAQ

## Introduction

This document addresses known or potential questions from the three typical personas that will be interacting with the Cisco Spaces DDM. Two key personas are:

1. Customer IT team (CIO, VP of Networking, IT Manager etc.)

2. Cisco Channel Partners / MSPs

But before going into those specific personas, this document covers some basic questions which are considered independent of the persona type.

*** ** * ** ***

## Non Persona Specific Questions

### What is the DDM and what is included?

The Cisco Spaces DDM is a companion tool for validation of network design + deployment guidance for smart spaces use cases. The DDM ensures your network, and your buildings are optimized and ready to support smart spaces outcomes such as precise location and asset tracking, indoor navigation, occupancy analytics and more. DDM deployment guidance enables you to activate smart spaces use cases in your buildings.

#### Key Components of DDM

##### Network Design Validation for Smart Spaces Outcomes

The Cisco Spaces DDM network validator validates that the planned or existing network design provided by the customer will lead to the successful deployment of Smart Spaces outcomes such as precise location and asset tracking, indoor navigation, occupancy analytics and more. Key activities in this are to validate the design for location best practices, validate AP density and AP placement for smart spaces outcomes. The output of this is a report validating the customer's design and may include recommendations for changes in the placement of APs potentially including additional APs to be added as well as adjustments to the placement of planned/existing APs.

*** ** * ** ***

### What are the key benefits of the DDM?

Customers that purchase the Design \& Deployment Module (DDM) along with their hardware purchase can make use of the following benefits such as:

#### Modernize Your Infrastructure

* Infrastructure upgrades are complex. Cisco Spaces DDM helps modernize your infrastructure and simplifies and assures deployment of key business use cases. That means less guesswork, faster rollouts, and confidence that your solutions are secure, scalable, and future-ready.

* Let Cisco handle the complexity --- so IT teams can be strategic enablers and drive business impact.

#### Densify and Future-Proof

* Build a high-density, high-performance network that meets today's demands and scales for tomorrow's smart spaces outcomes.

* Cisco Spaces DDM helps you validate, optimize your access point density as well as strategic placement and prepares your infrastructure for advanced use cases like real-time location services, Occupancy Analytics, Seamless Onboarding with OpenRoaming, IoT services, Indoor navigation and more.

* Cisco Spaces DDM also reduces the time to deploy business critical outcomes while also reducing future troubleshooting and support tickets by ensuring the network is validated and deployed for smart spaces outcomes.

#### Create a Platform Effect

* Transform your infrastructure into a sensor for smart spaces.

* By aligning your Cisco networking and collaboration devices, you gain more than just *connectivity* --- you activate a platform effect where every device works together, seamlessly, to drive better outcomes across your business

* Deliver smart spaces use cases at a lower cost of ownership than various point solutions

*** ** * ** ***

### How to buy DDM?

#### There are two main DDM licenses that can be purchased

##### SPACES-DDM

* For Medium-density HW smart spaces use cases such as Wi-Fi and BLE based RTLS, OpenRoaming, and Occupancy Analytics (use cases typically found in the Spaces Advantage license)

* SPACES-DDM is priced per device

##### SPACES-DDM-PRM

* For High- density smart spaces use cases such as Indoor Navigation and high precision Asset Tracking (use cases typically found in the Spaces Premier license)

* SPACES-DDM-PRM is priced per 10K sq.ft (this means for a 150K sq.ft building, you would need 15 of these licenses)

Both licenses have a 3-year minimum term. DDM can be purchased a la carte (recommended to be purchased with Cisco hardware but can be bought with software too).

*** ** * ** ***

### What are the DDM inputs, what is the optimal customer journey?

#### Pre-sales

##### **Sales/customer/partner/CX**

* **Smart Spaces Studio** -- Use the Smart Spaces Studio to get an accurate pre-sales estimate (+/- 5-10%) of the hardware and software packages needed for Smart Spaces outcomes selected in the studio. Cisco highly recommends using the Smart Spaces Studio prior to procuring Wi-Fi 7 APs, licenses and/or bundles.

<https://spaces.cisco.com/smart-spaces-studio/>

#### Pre-deployment

##### **Customer/partner/CX**

* Continue to use your existing defined processes for AP design (predictive/ap on stick/combo) in Ekahau/Hamina focused on meeting the customer Wi-Fi capacity/performance requirements as well as designing for RTLS. Use the per AP density output from the Smart Spaces Studio as a guideline for your AP design. Use the documented Cisco design guidelines for location outcomes such as AP based BLE indoor navigation and AP based UWB precise location (coming soon). Coming soon you will also be able to automatically apply Cisco specific smart spaces design profiles in Ekahau and Hamina which will allow those tools to consider smart spaces outcomes in their design requirements for placement of planned APs (coming soon).

#### **DDM Validation**

* **Cisco Spaces DDM**-- The DDM validates that the planned or existing network design provided by the customer/partner will lead to the successful deployment of Smart Spaces outcomes such as precise location and asset tracking, indoor navigation, and more.

DDM Network Validation must be done before the APs are deployed

##### Inputs to Validation

* Recommended: Provide Ekahau/Hamina planned/existing AP designs to Cisco (if possible share Ekahau/Hamina projects to Cisco)

* Alternatively: Provide CAD maps for all floors to Cisco (or vector pdf) along with AP placement reference designs

DDM does not create an AP design from scratch

##### Outputs from Validation

* Smart Spaces validated report -- DDM will provide a Smart Spaces validated AP report with recommendations to meet all intended outcomes (RTLS, indoor navigation etc.)

##### **Deployment**

* **Customer/partner/CX**-- Install the APs and network components as designed and validated in the previous stages. Note any installation challenges that may necessitate re-positioning APs, and which could alter the validated smart spaces outcomes.

##### **Post-deployment**

* **Customer/partner/CX** -- Continue to use your existing defined processes for post-deployment AP design validation via active/passive site surveys in Ekahau/Hamina focused on meeting the customer Wi-Fi capacity/performance requirements as well as RTLS requirements. Physical site walkthroughs may also help validate installed AP positions against the planned AP designs and DDM validation performed in previous stages.

*** ** * ** ***

### What are the key areas the DDM validation is focused on?

1. Digitize provided Ekahau/Hamina projects and/or CAD maps in Smart Spaces Network Validator

2. Validate network for key smart spaces use cases:

   1. Indoor Navigation

   2. Occupancy Analytics

   3. Asset Location

   4. Various RTLS outcomes (may include high precision location with UWB)

3. Validate buildings to optimize smart spaces outcomes by evaluating:

   1. AP Density

   2. Building characteristics which may impact outcomes

   3. AP to AP distance \& position

   4. Location design best practices

4. Smart Spaces validated AP position recommendations to meet all intended smart spaces outcomes (RTLS, indoor navigation etc.)

*** ** * ** ***

### What is the argument for DDM?

DDM delivers value through multiple stages from pre-deployment validation to post-deployment OS activation and use cases deployment. It's important at the HW purchase and design stage to ensure the right hardware is purchased, the right design considerations are taken into account and the infrastructure components are correctly planned.

*** ** * ** ***

### DDM has been purchased but where to start now?

Start off by going to <https://spaces.cisco.com/ddm/> and enter the information to get started.

*** ** * ** ***

## Persona -- End customer IT Teams (Ex: CIOs, Wireless IT leaders etc.)

### Why do I need DDM?

The Cisco Spaces DDM will work with you and your customer through the network and design validation -- making sure the right hardware is used at the right density and strategic positions, Spaces OS activation, and Use Cases deployment to ensure the customer's network, and buildings are optimized and ready to support smart spaces outcomes such as precise location and asset tracking, indoor navigation, occupancy analytics and more. These are the outcomes customer IT teams are being asked to deliver leveraging their Cisco infrastructure, and it's critical for customers for those use cases to be successful. The DDM is meant to augment and work with existing customer design processes and partner engagements.

### I always buy hardware in bulk with +15% extra at 1000 Sq Feet per AP. What is the value of the DDM during the hardware buying cycle?

While the purchase of bulk quantity of APs with extra APs is very insightful, the purchase is only the beginning of the customer's journey to fulfil the use case. For these outcomes to be real, the purchased infrastructure needs to be installed in correct locations and deployed correctly to scale and perform optimally.

The Cisco Spaces DDM helps customers validate that these outcomes are achieved in a scalable way.

### Why should I buy DDM at the time of hardware purchase, when most value is realized only at the time of deployment?

Cisco Spaces DDM delivers value through multiple stages from pre-deployment network validation to post-deployment OS activation and use cases deployment. Additionally, Cisco Spaces DDM is intended to validate the coexistence of different radio technologies to enable/unlock smart spaces RTLS use cases.

### What is included in DDM, why am I paying for network validation, OS activation and use case deployment right now?

Cisco Spaces DDM delivers value through multiple stages from pre-deployment network validation to post-deployment OS activation and use cases deployment. It's important at the HW purchase and design stage to ensure the right hardware is purchased, the right design considerations are taken into account and the infrastructure components are correctly planned. Typically, the highest costs come during hardware installation (cabling, labor, building planning, certifications, power, rack and cooling considerations and more). Ensuring the network is validated to support the intended Smart Spaces outcomes is key to successful outcomes and significantly reducing the potential of needing to redo hardware installation down the road.

### What are the DDM inputs, what is the optimal customer journey?

#### Pre-sales

* **Sales/customer/partner/CX -** Smart Spaces Studio -- Use the Smart Spaces Studio to get an accurate pre-sales estimate (+/- 5-10%) of the hardware and software packages needed for Smart Spaces outcomes selected in the studio. Cisco highly recommends using the Smart Spaces Studio prior to procuring Wi-Fi 7 APs, licenses and/or bundles.

<https://spaces.cisco.com/smart-spaces-studio/>

#### Pre-deployment

* **Customer/partner/CX**-- Continue to use your existing defined processes for AP design (predictive/ap on stick/combo) in Ekahau/Hamina focused on meeting the customer Wi-Fi capacity/performance requirements as well as designing for RTLS. Use the per AP density output from the Smart Spaces Studio as a guideline for your AP design. Use the documented Cisco design guidelines for location outcomes such as AP based BLE indoor navigation and AP based UWB precise location (coming soon). Coming soon you will also be able to automatically apply Cisco specific smart spaces design profiles in Ekahau and Hamina which will allow those tools to consider smart spaces outcomes in their design requirements for placement of planned APs (coming soon).

#### DDM Validation

* **Cisco Spaces DDM**-- The DDM validates that the planned or existing network design provided by the customer/partner will lead to the successful deployment of Smart Spaces outcomes such as precise location and asset tracking, indoor navigation, and more.

DDM Network Validation must be done before the APs are deployed

##### **Inputs to Validation**

* Recommended: Provide Ekahau/Hamina planned/existing AP designs to Cisco (if possible share Ekahau/Hamina projects to Cisco)

* Alternatively: Provide CAD maps for all floors to Cisco (or vector pdf) along with AP placement reference designs

DDM does not create an AP design from scratch

##### **Outputs from Validation**

* Smart Spaces validated report -- DDM will provide a Smart Spaces validated AP report with recommendations to meet all intended outcomes (RTLS, indoor navigation etc.)

**Deployment -- customer/partner/CX**-- Install the APs and network components as designed and validated in the previous stages. Note any installation challenges that may necessitate re-positioning APs, and which could alter the validated smart spaces outcomes.

**Post-deployment -- customer/partner/CX** -- Continue to use your existing defined processes for post-deployment AP design validation via active/passive site surveys in Ekahau/Hamina focused on meeting the customer Wi-Fi capacity/performance requirements as well as RTLS requirements. Physical site walkthroughs may also help validate installed AP positions against the planned AP designs and DDM validation performed in previous stages.

*** ** * ** ***

### What are the key areas the DDM validation is focused on?

1. Digitize provided Ekahau/Hamina projects and/or CAD maps in Smart Spaces Network Validator

2. Validate network for key smart spaces use cases:

   1. Indoor Navigation

   2. Occupancy Analytics

   3. Asset Location

Various RTLS outcomes (may include high precision location with UWB)

3. Validate buildings to optimize smart spaces outcomes by evaluating:

   1. AP Density

   2. Building characteristics which may impact outcomes

   3. AP to AP distance \& position

   4. Location design best practices

4. Smart Spaces validated AP position recommendations to meet all intended smart spaces outcomes (RTLS, indoor navigation etc.)

*** ** * ** ***

### I am not planning to buy Spaces today and not interested in what it offers, why should I get DDM?

DDM delivers value through multiple stages from pre-deployment validation to post-deployment OS activation and use cases deployment. It's important at the HW purchase and design stage to ensure the right hardware is purchased, the right design considerations are taken into account and the infrastructure components are correctly planned to be able to deliver smart spaces outcomes in the future.

*** ** * ** ***

### I am already engaged with an IT partner/MSP do I still need to buy the DDM and what do I get?

The DDM is meant to augment and work with existing customer design processes and partner engagements. Cisco Spaces DDM will work with you through validation, Smart Spaces OS activation, and Use Cases deployment to ensure your network, and your buildings are optimized and ready to support smart spaces outcomes such as precise location and asset tracking, indoor navigation, occupancy analytics and more.

*** ** * ** ***

### I am very confident about the Ekahau / Hamina AP placement designs that I have created, using my own license, employee skills and knowledge or via partner following Cisco best practices. Are you suggesting the output from these tools is poor, or are you suggesting that the outcomes I want will not work based on my Ekahau / Hamina design?

As Wi-Fi networks become denser and with new outcomes comes added complexity. Existing customer and partner pre-deployment planning/design and post-deployment Wi-Fi validation/tuning will continue to be critical components of the overall journey. The Cisco Spaces DDM is meant to augment and work with existing customer/partner processes. Cisco Spaces DDM will work with you through validation, Smart Spaces OS activation, and Use Cases deployment to ensure your network, and your buildings are optimized and ready to support smart spaces outcomes such as precise location and asset tracking, indoor navigation, occupancy analytics and more.

*** ** * ** ***

### I am already very confident that my current AP layout works for my use cases ad solutions. I'm just swapping another vendor with Cisco APs -- like for like. What is the value I will get from buying DDM?

Even if you are replacing APs like for like, it is not inherently a given that existing or future outcomes would continue to work. Cisco Spaces DDM guides you across network design validation and Cisco specific deployment criteria which is more than just 'telling me where to place the APs'. Many smart spaces outcomes that are specifically delivered by Cisco, for example, Indoor Navigation via Cisco Spaces also carry learnings from deployments done by Cisco. Cisco Spaces DDM will work with you through validation, Smart Spaces OS activation, and Use Cases deployment to ensure your network, and your buildings are optimized and ready to support smart spaces outcomes such as precise location and asset tracking, indoor navigation, occupancy analytics and more. It may still be possible that as part of DDM network validation, we may find that your existing deployments work well and you wouldn't need any changes, but that's step one of what DDM will validate for you.

*** ** * ** ***

### I have multiple partners who I engage at various stages of my deployments. I have a partner to do my procurement decisions, another to help me deploy the software and lastly, a MSP for management of the infrastructure. Can DDM help me solve for this mess?

The DDM is meant to augment and work with existing partner engagements. Cisco Spaces DDM will work with you through validation, Smart Spaces OS activation, and Use Cases deployment to ensure your network, and your buildings are optimized and ready to support smart spaces outcomes such as precise location and asset tracking, indoor navigation, occupancy analytics and more.

*** ** * ** ***

### Does DDM validation replace my normal AP planning/design process?

No, the Cisco Spaces DDM is meant to augment your existing AP planning/design process. As Wi-Fi networks become denser and with new outcomes comes added complexity. Existing customer and partner pre-deployment planning/design and post-deployment Wi-Fi validation/tuning will continue to be critical components of the overall journey. Cisco Spaces DDM will work with you through validation, Smart Spaces OS activation, and Use Cases deployment to ensure your network, and your buildings are optimized and ready to support smart spaces outcomes such as precise location and asset tracking, indoor navigation, occupancy analytics and more.

*** ** * ** ***

### Could we use BLE beacons if my AP deployment is not dense enough for indoor navigation, e.g. 2,000 sq.ft/AP?

Technically yes however the DDM will focus on what it takes to deploy BLE based indoor navigation using only APs without needing to use BLE beacons. In circumstances where it's not possible to augment or use APs DDM can consider where BLE beacons are needed to deliver indoor navigation.

*** ** * ** ***

### What smart spaces benefits come from a DDM validated medium density AP deployment and similarly what smart spaces benefits do I get with a DDM validated high density AP deployment? Why does density matter?

DDM Validated Medium Density AP Deployment (approx. 1,500 -- 2000 sq.ft per AP):

* Increased Wi-Fi connectivity capacity over older less dense connectivity designs

* Good Wi-Fi and BLE location accuracy (typically 5-7 meters)

* Connected Wi-Fi device occupancy for buildings and floors

* Good BLE based asset tracking

DDM Validated High Density AP Deployment (approx. 1,000 sq.ft per AP or below):

* All Medium Density items mentioned above

* Increased Wi-Fi capacity with smaller cells and enhanced performance at short range with 4k QAM

* Indoor Navigation using only APs without overlay networks

* High Precision Asset Tracking using Ultra-wideband (UWB ≤1 meter in optimized environments)

*** ** * ** ***

### If we have already purchased the DDM where can we do to get started?

Go to <https://spaces.cisco.com/ddm/> and enter your information to get started.

*** ** * ** ***

## Persona -- Partners/MSP

### What is it that we are not doing that DDM Is doing?

The DDM is meant to augment your existing AP planning/design process. As Wi-Fi networks become denser and with new outcomes comes added complexity. Existing customer and partner pre-deployment planning/design and post-deployment Wi-Fi validation/tuning will continue to be critical components of the overall journey. The DDM is meant to augment and work with existing customer/partner processes. Cisco Spaces DDM will work with you through validation, Smart Spaces OS activation, and Use Cases deployment to ensure your network, and your buildings are optimized and ready to support smart spaces outcomes such as precise location and asset tracking, indoor navigation, occupancy analytics and more.

*** ** * ** ***

### Can I use the DDM license within my offering to the customer?

DDM is not currently offered as a partner specific SKU, but if the customer has bought DDM, a partner can access the DDM working with their customers and Cisco through the DDM network design validation, Spaces OS activation, and Smart Spaces use case deployment.

*** ** * ** ***

### Is DDM a replacement/competition for my offerings that I offer?

The DDM is meant to augment your existing AP planning/design process. As Wi-Fi networks become denser and with new outcomes comes added complexity. Existing customer and partner pre-deployment planning/design and post-deployment Wi-Fi validation/tuning will continue to be critical components of the overall journey. The DDM is meant to augment and work with existing customer/partner processes. Cisco Spaces DDM will work with you through validation, Smart Spaces OS activation, and Use Cases deployment to ensure your network, and your buildings are optimized and ready to support smart spaces outcomes such as precise location and asset tracking, indoor navigation, occupancy analytics and more.

*** ** * ** ***

### Is there a way to get a pre-sales estimate of the hardware and software I need for different Smart Spaces outcomes?

Ans: Yes, the Smart Spaces Studio will provide an accurate pre-sales estimate of the hardware and software needed for different Smart Spaces outcomes.

<https://spaces.cisco.com/smart-spaces-studio/>

*** ** * ** ***

### What are the customer/partner provided inputs that are needed for the DDM validation?

* Recommended: Provide Ekahau/Hamina planned/existing AP designs to Cisco (if possible share Ekahau/Hamina projects to Cisco)

* Alternatively: Provide CAD maps for all floors to Cisco (or vector pdf) along with AP placement reference designs

DDM does not create an AP design from scratch

*** ** * ** ***

### Does the customer/partner need to provide a planned/installed AP design for the Cisco Spaces DDM validation ?

Yes, the customer/partner need to provide a planned/installed AP design as input to the Cisco Spaces DDM. The validation will not create an AP design from scratch, the DDM validates existing planned/installed AP designs for smart spaces location outcomes such as indoor navigation, asset tracking, occupancy analytics and more.

*** ** * ** ***

### Does the Cisco Spaces DDM validation perform detailed Wi-Fi RF planning/analysis?

No, the DDM validation validates existing planned/installed AP designs for smart spaces location outcomes such as indoor navigation, asset tracking, occupancy analytics and more. In most cases, the AP density and position requirements for location outcomes provide adequate Wi-Fi coverage but customers/partners should review any DDM validation recommendations against their Wi-Fi capacity/performance needs.

*** ** * ** ***

### What are the key areas the DDM validation is focused on?

1. Digitize provided Ekahau/Hamina projects and/or CAD maps in Smart Spaces Network Validator

2. Validate network for key smart spaces use cases:

* Indoor Navigation

* Occupancy Analytics

* Asset Location

* Various RTLS outcomes (may include high precision location with UWB)

3. Validate buildings to optimize smart spaces outcomes by evaluating:

* AP Density

* Building characteristics which may impact outcomes

* AP to AP distance \& position

* Location design best practices

4. Smart Spaces validated AP position recommendations to meet all intended smart spaces outcomes (RTLS, indoor navigation etc.)

*** ** * ** ***

### Does DDM validation replace my normal AP planning/design process?

No, the DDM is meant to augment your existing AP planning/design process. As Wi-Fi networks become denser and with new outcomes comes added complexity. Existing customer and partner pre-deployment planning/design and post-deployment Wi-Fi validation/tuning will continue to be critical components of the overall journey. The DDM is meant to augment and work with existing customer/partner processes. Cisco Spaces DDM will work with you through validation, Smart Spaces OS activation, and Use Cases deployment to ensure your network, and your buildings are optimized and ready to support smart spaces outcomes such as precise location and asset tracking, indoor navigation, occupancy analytics and more.

*** ** * ** ***

### Could we use BLE beacons if my AP deployment is not dense enough for indoor navigation, e.g 2,000 sq.ft/AP?

Technically yes however the DDM will focus on what it takes to deploy BLE based indoor navigation using only APs without needing to use BLE beacons. In circumstances where it's not possible to augment or use APs DDM can consider where BLE beacons are needed to deliver indoor navigation.

*** ** * ** ***

### How does DDM determine optimal AP relocation or additional AP recommendations?

Cisco Spaces DDM Smart Spaces Network Validator is used to:

1. Digitize provided Ekahau/Hamina projects and/or CAD maps in Smart Spaces Network Validator

2. Validate network for key smart spaces use cases:

* Indoor Navigation

* Occupancy Analytics

* Asset Location

* Various RTLS outcomes (may include high precision location with UWB)

3. Validate buildings to optimize smart spaces outcomes by evaluating:

* AP Density

* Building characteristics which may impact outcomes

* AP to AP distance \& position

* Location design best practices

4. Smart Spaces validated AP position recommendations to meet all intended smart spaces outcomes (RTLS, indoor navigation etc.)

*** ** * ** ***

### If my customer has already purchased the DDM where can they go to get started?

Have the customer go to <https://spaces.cisco.com/ddm/> and enter their information to get started.

---
language: "en"
---
# Cisco Spaces Device Compatibility Matrices

This knowledge article is the source of truth for devices that have verified compatibility with Cisco Spaces. This document will be updated to remain current and relevant to existing and emerging outcomes for Cisco Spaces.

Devices specifically marked as Meraki are only compatible with the Meraki platform. Devices not explicitly branded Meraki are only compatible with Catalyst environments.  
Cisco Spaces supports both Cisco collaboration (Webex) RoomOS and Microsoft Teams Room (MTR) operating systems. In both modes, Cisco Webex Collaboration devices support people count, presence, and environmental sensor telemetry.

Notable differences for MTR device functionality (vs. RoomOS - these are included in RoomOS):

* Kiosk mode

* Home screen Web Widgets (a pre-requisite for Smart Rooms in order to display the BMS / HVAC status to end users to reassure them the air is being optimized for their well-being)

## Device Compatibility for Workspaces

|-----------------------|----------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------|-------------------------------------------------------------------------------|
| **Category**          | **Use Case**                                       | **Device Recommendation**                                                                                                                                                                                                                                                                                                             | **Third Party Partner/Vendor**                                                      | **Spaces App Support**                                                        |
| Room Occupancy        | Room Occupancy -- People Count (BLE)               | Portal Beam                                                                                                                                                                                                                                                                                                                           | Kontakt.io                                                                          | Space Manager, Space Utilization, Kiosk, Space Explorer Web App               |
| Room Occupancy        | Room Occupancy (Webex) *(see special notes below)* | Cisco Board Series Cisco Room Series Cisco Desk Series *Standalone Navigators are not supported*                                                                                                                                                                                                                                      |                                                                                     | Space Manager, Space Utilization, Kiosk, Space Explorer Web App               |
| Room Occupancy        | Webex Room Occupancy will be changing from [xStatus RoomAnalytics PeopleCount Current](https://roomos.cisco.com/xapi/Status.RoomAnalytics.PeopleCount.Current/) to [xStatus RoomAnalytics RoomInUse](https://roomos.cisco.com/xapi/Status.RoomAnalytics.RoomInUse/) to cover more scenarios that indicate binary occupancy (Available vs. Occupied). Inputs to RoomInUse status are configurable in [Webex Control Hub](https://admin.webex.com/).                                                                                                            ||||
| Room Occupancy        | Room Occupancy -- Presence (BLE)                   | Thingsee Presence                                                                                                                                                                                                                                                                                                                     | Haltian                                                                             | Space Manager, Space Utilization, IoT Explorer, Kiosk, Space Explorer Web App |
| Desk Occupancy        | Desk Occupancy (BLE) \*                            | Portal Beam (**Roadmap**) Thingsee Presence (**Roadmap**)                                                                                                                                                                                                                                                                             | Kontkat.io Haltian                                                                  | Space Explorer Web App                                                        |
| Desk Occupancy        | Desk Occupancy (Webex)\*                           | Cisco Desk Series Cisco Desk Phone 9800 Series (not 9811) Cisco Desk Phone 8875 Cisco Navigator w/ Cisco Spaces PWA                                                                                                                                                                                                                   |                                                                                     | Space Explorer Web App                                                        |
| Environmental Metrics | Temperature / Humidity                             | [*MT10, MT14, MT15 (* ***EOL*** *)*](https://www.cisco.com/c/en/us/products/collateral/security/physical-security/meraki-sensors/meraki-mt-sensors-eol.html) T15h Temperature \& Humidity Tag (Wi-Fi only) Portal Beam Cisco Board, Room, and Desk Series Blue PUCK T EN12830 temperature sensor Blue PUCK T-PROBE temperature sensor | Securitas Healthcare [Kontakt.io](http://kontakt.io/) Ela Innovation Ela Innovation | Env. Analytics, Kiosk, Space Manager                                          |
| Environmental Metrics | TVOC                                               | [*MT14 and MT15*](https://www.cisco.com/c/en/us/products/collateral/security/physical-security/meraki-sensors/meraki-mt-sensors-eol.html)*(EOL)*                                                                                                                                                                                      |                                                                                     | Env. Analytics, Kiosk, Space Manager                                          |
| Environmental Metrics | CO2                                                | [*Meraki Things: MT15*](https://www.cisco.com/c/en/us/products/collateral/security/physical-security/meraki-sensors/meraki-mt-sensors-eol.html)*(EOL)* Hibou Air Quality CO~2~                                                                                                                                                        | Smart Sensor Devices AB                                                             | Env. Analytics, Kiosk, Space Manager                                          |
| Environmental Metrics | IAQ                                                | [*Meraki Things: MT14, MT15*](https://www.cisco.com/c/en/us/products/collateral/security/physical-security/meraki-sensors/meraki-mt-sensors-eol.html) Cisco Navigator (Table) Cisco Board, Room, and Desk Series                                                                                                                      |                                                                                     | Env. Analytics, Kiosk, Space Manager                                          |
| Environmental Metrics | Ambient Noise                                      | Cisco Board, Room, and Desk Series (w/ Cisco Microphones only)                                                                                                                                                                                                                                                                        |                                                                                     | Env. Analytics, Kiosk, Space Manager                                          |
| Asset Tracking        | Asset Tracking (BLE)                               | Asset Tag 2 Asset Tag 2 mini T22                                                                                                                                                                                                                                                                                                      | Kontkat.io Kontakt.io Securitas Healthcare                                          | Asset Tracker, Detect and Locate, IoT Explorer                                |

Devices marked with \* are not yet released as Generally Available for the specified use case.  
**Note:** special notes on device compatibility for use-cases:

1. For Cisco Collaboration devices, use of 3rd party microphones are **not** supported for the ultrasound based presence sensing

2. ST60 and Precision 60 cameras that do "SpeakerTrack" do **not** support "people count out of call" or "head detection"

3. Room Kit Plus, Room Kit Pro, and Codec Pro **require** Quad Cam to support "people count out of call" or "head detection". Codec Pro not currently supported.

4. Cisco Collaboration Navigator **must** be placed inside the meeting room to generate room specific environmental telemetry data

5. Desk devices **must** be configured in a Workspace in Control Hub as a "Desk" space type to be used for desk booking. If supported, they can be configured with "hot desking" under the Workspace \> Scheduling settings.

<https://help.webex.com/en-us/article/nc6od6r/Utilization-and-environmental-metrics-for-workspaces>

## Kiosk Display Compatibility for Workspaces

|     **Device**     | **Tested + Validated** |                                       Notes                                       |
|--------------------|------------------------|-----------------------------------------------------------------------------------|
| Cisco Board Pro G2 | ✅                      | RoomOS fully functional MTR Digital Signage supported, MTR Kiosk is not supported |
| Cisco Board Pro    | ✅                      | RoomOS fully functional MTR Digital Signage supported, MTR Kiosk is not supported |
| Cisco Board        | ❌                      |                                                                                   |
| Cisco Desk Pro     | ✅                      | RoomOS fully functional MTR Digital Signage supported, MTR Kiosk is not supported |
| Cisco Desk         | ❌                      |                                                                                   |
| Cisco Desk Mini    | ❌                      |                                                                                   |
| Cisco Navigator    | ❌                      |                                                                                   |

*** ** * ** ***

## Device Compatibility for Healthcare

|----------------------|----------------------------------|-----------------------------------------------------------------------------|-----------------------------------------------------------|
| **Category**         | **Use Case**                     | **Device Recommendation**                                                   | **Spaces App Support**                                    |
| Asset Tracking       | Asset tracking (BLE)             | Kontakt Asset Tag 2 Asset tag 2 mini Securitas T22                          | Asset Tracker, Detect and Locate, IoT Explorer, Securitas |
| Asset Tracking       | Asset tracking (UWB) - dongle    | TR100 (geoplan with dongle) TR200 (geoplan with dongle)                     | IoT Explorer, Detect and Locate, Geoplan                  |
| Infant Protection    | Infant monitoring                | Securitas Hugs (Wi-Fi)                                                      | Securitas                                                 |
| Duress/ Panic Button | Staff Badge / Staff Duress (BLE) | Kontakt Staff Badge Asset Tag 2 Polestar BLE tag Centrak Multi mode BLE tag | Kontakt, Centrak, Polestar                                |
| Duress/ Panic Button | Staff duress (UWB) - dongle      | ID300 (geoplan with dongle) ID200 (geoplan with dongle)                     | Geoplan                                                   |

*** ** * ** ***

## REFERENCES

1. <https://help.webex.com/en-us/article/nc6od6r/Utilization-and-environmental-metrics-for-workspaces>

---
language: "en"
---
# Cisco Spaces Firewall Traffic Matrix for Spaces OS and Outcome Services

## Overview

Use this knowledge article as the single firewall reference for Cisco Spaces OS and outcome services. It identifies and validates the firewall rules required between customer-managed clients, Cisco Spaces infrastructure, wireless infrastructure, and outcome-specific services.

Apply only the rule groups for the components and outcomes in your deployment. Cisco Spaces cloud addresses can change, so use FQDN-based destination objects when your firewall supports them. If your security policy requires static IP objects, compare the addresses in this article with the current Cisco documentation and the values displayed in your Cisco Spaces tenant before implementing a change.

## Prerequisites

Before you begin:

1. Identify your Cisco Spaces tenant region:

   * IO: `dnaspaces.io` and `ciscospaces.io`

   * EU: `dnaspaces.eu` and `ciscospaces.eu`

   * SG: `ciscospaces.sg`

2. Inventory the components in scope:

   * Cisco Spaces Connector

   * Cisco AireOS or Catalyst 9800 wireless controllers

   * Catalyst access points with IoT Services

   * Catalyst Center

   * Meraki Dashboard integration

   * Kiosk or Space Explorer clients

   * Captive Portal

   * OpenRoaming

   * Smart Rooms gateway and building management system

   * Sensor Connect Wireless IoT Orchestrator and registered external applications

3. Confirm that DNS, NTP, proxy, and TLS inspection policies are available for the relevant source networks.

4. Record the Cisco Spaces tenant, region, source subnets, and firewall change identifier.

5. For Captive Portal, open **Cisco Spaces \> Captive Portal \> SSIDs** , select the SSID, and use **Configure Manually** or **View Config Guide** to obtain the tenant-specific splash URL, RADIUS server addresses, and shared secret.

> Do not copy RADIUS server addresses or secrets from another tenant. Use the values generated for the SSID in your own Cisco Spaces tenant.

## How to read the traffic matrix

Each rule separates the source and destination ports. Unless a row explicitly states otherwise, **Source port** is `Any (ephemeral)`: the initiating client selects a temporary source port, while the firewall rule matches the listed service **Destination port**. Stateful firewalls should permit the associated return traffic. Do not configure the destination service port as a fixed source port.

## Select the required rule groups

|               Deployment component or outcome                |         Required rule groups          |
|--------------------------------------------------------------|---------------------------------------|
| Spaces Connector with AireOS or Catalyst 9800                | A, B                                  |
| IoT Services on Catalyst wireless                            | A, B, C                               |
| Meraki wireless integration, including Scanning API and MQTT | E                                     |
| Catalyst Center integration                                  | D                                     |
| Meraki Dashboard API synchronization only                    | E1                                    |
| Smart Workspaces kiosk or signage                            | F                                     |
| Space Explorer browser or PWA                                | G                                     |
| Captive Portal                                               | H                                     |
| OpenRoaming with Connector                                   | A, B, I                               |
| OpenRoaming with Meraki                                      | I                                     |
| Smart Rooms gateway                                          | J                                     |
| Sensor Connect for IoT Services                              | K                                     |
| Asset Tracking, Occupancy, or Indoor Navigation              | A, B, and C when IoT Services is used |

*** ** * ** ***

A. Allow the Cisco Spaces Connector to reach Cisco Spaces cloud  

## A. Allow the Cisco Spaces Connector to reach Cisco Spaces cloud

Allow each Connector to initiate the following traffic to the endpoint for the tenant region.  

|        Region        |         Source         |      Destination FQDN      |      Published IP addresses       | Protocol |   Source port   | Destination port |                 Use                  |
|----------------------|------------------------|----------------------------|-----------------------------------|----------|-----------------|------------------|--------------------------------------|
| IO current           | Cisco Spaces Connector | `connector.ciscospaces.io` | `75.2.50.127`, `99.83.199.229`    | TCP/TLS  | Any (ephemeral) | 443              | Cloud control and data               |
| IO existing          | Cisco Spaces Connector | `connector.dnaspaces.io`   | `52.20.144.155`, `34.231.154.95`  | TCP/TLS  | Any (ephemeral) | 443              | Cloud control and data               |
| IO disaster recovery | Cisco Spaces Connector | Regional recovery service  | `54.176.92.81`, `54.183.58.225`   | TCP/TLS  | Any (ephemeral) | 443              | Disaster-recovery cloud connectivity |
| EU                   | Cisco Spaces Connector | `connector.dnaspaces.eu`   | `63.33.127.190`, `63.33.175.64`   | TCP/TLS  | Any (ephemeral) | 443              | Cloud control and data               |
| EU disaster recovery | Cisco Spaces Connector | Regional recovery service  | `3.122.15.26`, `3.122.15.7`       | TCP/TLS  | Any (ephemeral) | 443              | Disaster-recovery cloud connectivity |
| SG                   | Cisco Spaces Connector | `connector.ciscospaces.sg` | `13.228.159.49`, `54.179.105.241` | TCP/TLS  | Any (ephemeral) | 443              | Cloud control and data               |
| SG disaster recovery | Cisco Spaces Connector | Regional recovery service  | `13.214.251.223`, `54.255.57.46`  | TCP/TLS  | Any (ephemeral) | 443              | Disaster-recovery cloud connectivity |

For IO tenants using static address objects, include the current and existing published addresses during the Cisco Spaces domain transition. Prefer the regional FQDN when possible.

Expected result: The Connector dashboard shows healthy control and data channels to Cisco Spaces cloud.
B. Allow Connector and wireless controller communication  

## B. Allow Connector and wireless controller communication

Where the Connector and wireless infrastructure are separated by a firewall, permit the applicable traffic between their assigned addresses.  

|         Source          |      Destination       | Protocol |   Source port   | Destination port |                    Use                     |
|-------------------------|------------------------|----------|-----------------|------------------|--------------------------------------------|
| Wireless controller     | Cisco Spaces Connector | TCP      | Any (ephemeral) | 16113            | NMSP location telemetry                    |
| Cisco Spaces Connector  | Catalyst 9800          | TCP      | Any (ephemeral) | 830              | NETCONF                                    |
| Cisco Spaces Connector  | Wireless controller    | TCP      | Any (ephemeral) | 22               | SSH management used by Connector workflows |
| Wireless infrastructure | Cisco Spaces Connector | UDP      | Any (ephemeral) | 2003, optional   | FastLocate                                 |

If the firewall policy requires a single initiating direction and the local implementation does not make it clear, validate the direction against the current Connector open-port diagram before applying the rule. Do not expose these management ports to the public internet.

Expected result: The controller is active in Cisco Spaces and Connector connectivity tests succeed.
C. Allow IoT Services communication  

## C. Allow IoT Services communication

Apply these rules only when Cisco Spaces IoT Services are enabled on Catalyst wireless infrastructure.  

|         Source         |      Destination       | Protocol |   Source port   | Destination port |                     Use                     |
|------------------------|------------------------|----------|-----------------|------------------|---------------------------------------------|
| Catalyst 9800          | Cisco Spaces Connector | TCP      | Any (ephemeral) | 8004             | Telemetry Data Logger stream                |
| Catalyst 9800          | Cisco Spaces Connector | TCP      | Any (ephemeral) | 8184             | Telemetry Data Logger stream                |
| Cisco Spaces Connector | Access points          | TCP      | Any (ephemeral) | 8443             | IOx application installation and management |
| Access points          | Cisco Spaces Connector | TCP      | Any (ephemeral) | 8000             | gRPC and REST communication                 |

Expected result: **IoT Services \> About \> View Detailed Status** shows successful deployment, and the selected access points show an enabled gateway and an up IOx channel.

For Meraki wireless telemetry, use rule group E. It separates the Meraki Dashboard API, Scanning API, and TLS-protected MQTT flows.
D. Allow Catalyst Center activation and certificate checks  

## D. Allow Catalyst Center activation and certificate checks

Allow Catalyst Center to initiate the following traffic:  

|     Source      |           Destination           | Protocol |   Source port   | Destination port |             Use              |
|-----------------|---------------------------------|----------|-----------------|------------------|------------------------------|
| Catalyst Center | `dnaspaces.io`                  | TCP/TLS  | Any (ephemeral) | 443              | IO tenant activation         |
| Catalyst Center | `dnaspaces.eu`                  | TCP/TLS  | Any (ephemeral) | 443              | EU tenant activation         |
| Catalyst Center | `ciscospaces.sg`                | TCP/TLS  | Any (ephemeral) | 443              | SG tenant activation         |
| Catalyst Center | `validation.identrust.com`      | TCP      | Any (ephemeral) | 80               | Certificate revocation check |
| Catalyst Center | `commercial.ocsp.identrust.com` | TCP      | Any (ephemeral) | 80               | Certificate revocation check |

Expected result: In Catalyst Center, **System \> Settings \> CMX Servers/Cisco Spaces** shows the Cisco Spaces integration as activated.
E. Allow the seamless Meraki integration  

## E. Allow the seamless Meraki integration

The native Meraki integration can exchange organization and network information, maps, devices, SSIDs, Scanning API subscriptions, MQTT broker configuration, and Wi-Fi or BLE location information. Apply the flows used by your deployment.

### E1. Dashboard API synchronization

Allow Cisco Spaces to initiate the following API connection:  

|             Source             |     Destination      | Protocol |   Source port   | Destination port |                                              Use                                               |
|--------------------------------|----------------------|----------|-----------------|------------------|------------------------------------------------------------------------------------------------|
| Cisco Spaces regional services | Meraki Dashboard API | TCP/TLS  | Any (ephemeral) | 443              | Organization, network, device, map, SSID, Scanning API, and MQTT configuration synchronization |

When **Organization \> Settings \> Login IP ranges** restricts Dashboard API access by source address, add the applicable regional Cisco Spaces source addresses to the API policy:  

| Region |         Cisco Spaces source IP addresses         |
|--------|--------------------------------------------------|
| IO     | `34.192.26.106`, `52.206.67.43`, `3.208.52.128`  |
| EU     | `52.208.15.59`, `54.220.148.167`, `54.220.45.63` |
| SG     | `3.1.251.174`, `13.215.110.252`                  |

Review all existing integrations before enabling or tightening an IP restriction so that other authorized API clients are not blocked.

### E2. Scanning API location data

Allow Meraki cloud to deliver Scanning API location observations to the tenant-generated Cisco Spaces Post URL:  

|    Source    |                     Destination                     | Protocol |   Source port   | Destination port |                                  Use                                   |
|--------------|-----------------------------------------------------|----------|-----------------|------------------|------------------------------------------------------------------------|
| Meraki cloud | Tenant-generated Cisco Spaces Scanning API Post URL | TCP/TLS  | Any (ephemeral) | 443              | HTTPS validation and JSON POST delivery of Wi-Fi and BLE location data |

Use the Post URL and secret generated for the organization in Cisco Spaces. Do not substitute a URL from another tenant or region.

### E3. Wireless MQTT

Allow the Meraki wireless networks that send data to Cisco Spaces to establish a TLS MQTT session:  

|         Source          |                                     Destination                                     |    Protocol    |   Source port   | Destination port |                Use                |
|-------------------------|-------------------------------------------------------------------------------------|----------------|-----------------|------------------|-----------------------------------|
| Meraki wireless network | Cisco Spaces account- and region-specific MQTT broker configured by the integration | TCP/TLS (MQTT) | Any (ephemeral) | 8883             | Encrypted wireless MQTT telemetry |

> *To support this configuration and ensure the seamless flow of MQTT traffic, please make sure that the TLS port 8883 is open between Meraki and Spaces for all the networks sending data to Spaces.*

Expected result: The Meraki organization and selected networks synchronize with Cisco Spaces, the Scanning API Post URL validates and receives observations, and MQTT clients establish TLS sessions on destination port 8883.
F. Allow Smart Workspaces kiosk and signage clients  

## F. Allow Smart Workspaces kiosk and signage clients

Allow outbound TCP 443 from kiosk and signage client networks. Where wildcard destinations are permitted, the regional wildcards are recommended:

* IO: `*.ciscospaces.io`, `*.dnaspaces.io`

* EU: `*.ciscospaces.eu`, `*.dnaspaces.eu`

* SG: `*.ciscospaces.sg`

If explicit FQDN objects are required, use the applicable regional list. Every row uses TCP/TLS, source port `Any (ephemeral)`, and destination port `443`.  

|         Source          |       Service       |                     IO destination                     |                     EU destination                     |          SG destination           | Protocol |   Source port   | Destination port |
|-------------------------|---------------------|--------------------------------------------------------|--------------------------------------------------------|-----------------------------------|----------|-----------------|------------------|
| Kiosk or signage client | Kiosk               | `kiosk.ciscospaces.io`                                 | `kiosk.ciscospaces.eu`                                 | `kiosk.ciscospaces.sg`            | TCP/TLS  | Any (ephemeral) | 443              |
| Kiosk or signage client | Signage             | `signage.dnaspaces.io`                                 | `signage.dnaspaces.eu`                                 | `signage.ciscospaces.sg`          | TCP/TLS  | Any (ephemeral) | 443              |
| Kiosk or signage client | Workspaces          | `workspaces.dnaspaces.io`, `workspaces.ciscospaces.io` | `workspaces.dnaspaces.eu`, `workspaces.ciscospaces.eu` | `workspaces.ciscospaces.sg`       | TCP/TLS  | Any (ephemeral) | 443              |
| Kiosk or signage client | Webex API WebSocket | `webex-api-server.dnaspaces.io`                        | `webex-api-server.dnaspaces.eu`                        | `webex-api-server.ciscospaces.sg` | TCP/TLS  | Any (ephemeral) | 443              |
| Kiosk or signage client | Workspace WebSocket | `swsjetstreams.dnaspaces.io`                           | `swsjetstreams.dnaspaces.eu`                           | `sgswsjetstreams.ciscospaces.sg`  | TCP/TLS  | Any (ephemeral) | 443              |
| Kiosk or signage client | RMS                 | `rms.dnaspaces.io`, `rms.ciscospaces.io`               | `rms.dnaspaces.eu`, `rms.ciscospaces.eu`               | `rms.ciscospaces.sg`              | TCP/TLS  | Any (ephemeral) | 443              |
| Kiosk or signage client | Maps                | `maps.ciscospaces.io`                                  | `maps.ciscospaces.eu`                                  | `maps.ciscospaces.sg`             | TCP/TLS  | Any (ephemeral) | 443              |

Also allow the following third-party traffic:  

|         Source          |      Destination       | Protocol |   Source port   | Destination port |     Use     |
|-------------------------|------------------------|----------|-----------------|------------------|-------------|
| Kiosk or signage client | `api.mapbox.com`       | TCP/TLS  | Any (ephemeral) | 443              | Map content |
| Kiosk or signage client | `events.mapbox.com`    | TCP/TLS  | Any (ephemeral) | 443              | Map events  |
| Kiosk or signage client | `fonts.googleapis.com` | TCP/TLS  | Any (ephemeral) | 443              | Web fonts   |

`*.amazonaws.com` is currently identified as temporary for Smart Rooms and custom logos. Use it only when the selected feature requires it and narrow the rule when a more specific published destination becomes available. `*.pendo.com` is optional and non-blocking.

Expected result: The kiosk or signage application loads its maps and live state without missing content or WebSocket errors.
G. Allow Space Explorer browser and PWA clients  

## G. Allow Space Explorer browser and PWA clients

Allow the following traffic from the end-user or managed-device network:  

|                Source                |            Destination            | Protocol |   Source port   | Destination port |              Use               |
|--------------------------------------|-----------------------------------|----------|-----------------|------------------|--------------------------------|
| Space Explorer browser or PWA client | `ciscospaces.app`                 | TCP/TLS  | Any (ephemeral) | 443              | Space Explorer application     |
| Space Explorer browser or PWA client | `maps.ciscospaces.io`             | TCP/TLS  | Any (ephemeral) | 443              | Cisco Spaces maps              |
| Space Explorer browser or PWA client | `sws-jetstreams.dnaspaces.io`     | TCP/TLS  | Any (ephemeral) | 443              | Live application data          |
| Space Explorer browser or PWA client | `workspaces-preprod.dnaspaces.io` | TCP/TLS  | Any (ephemeral) | 443              | Temporary published dependency |
| Space Explorer browser or PWA client | `api.mapbox.com`                  | TCP/TLS  | Any (ephemeral) | 443              | Map content                    |
| Space Explorer browser or PWA client | `events.mapbox.com`               | TCP/TLS  | Any (ephemeral) | 443              | Map events                     |
| Space Explorer browser or PWA client | `fonts.googleapis.com`            | TCP/TLS  | Any (ephemeral) | 443              | Web fonts                      |

The current Space Explorer publication identifies IO as supported and marks some EU and SG endpoints as roadmap. Confirm regional availability before using this rule group outside IO. Also allow the identity-provider destinations selected for Webex, Microsoft, or Google sign-in.

Expected result: Users can sign in, load the building map, and complete the licensed room or desk workflow.
H. Allow Captive Portal splash and RADIUS traffic  

## H. Allow Captive Portal splash and RADIUS traffic

### H1. Allow splash traffic

Allow TCP 443 from the client or controller path that presents the portal to the tenant-specific splash URL shown in the Cisco Spaces dashboard. For firewalls or controller ACLs that also require static addresses, use the addresses for the tenant domain:  

|   Region    |              Source              | Splash destination FQDN |      Published IP addresses       | Protocol |   Source port   | Destination port |          Use          |
|-------------|----------------------------------|-------------------------|-----------------------------------|----------|-----------------|------------------|-----------------------|
| IO existing | Client or controller portal path | `splash.dnaspaces.io`   | `34.235.248.212`, `52.55.235.39`  | TCP/TLS  | Any (ephemeral) | 443              | Captive Portal splash |
| IO current  | Client or controller portal path | `splash.ciscospaces.io` | `3.33.232.255`, `15.197.234.109`  | TCP/TLS  | Any (ephemeral) | 443              | Captive Portal splash |
| EU existing | Client or controller portal path | `splash.dnaspaces.eu`   | `54.77.207.183`, `34.252.175.120` | TCP/TLS  | Any (ephemeral) | 443              | Captive Portal splash |
| EU current  | Client or controller portal path | `splash.ciscospaces.eu` | `35.71.129.209`, `52.223.8.107`   | TCP/TLS  | Any (ephemeral) | 443              | Captive Portal splash |
| SG          | Client or controller portal path | `splash.ciscospaces.sg` | `13.250.197.154`                  | TCP/TLS  | Any (ephemeral) | 443              | Captive Portal splash |

Add only the domains required by the authentication methods configured for the portal. For example, a portal that offers a social sign-in option also needs the current domains published by that identity provider.

### H2. Allow RADIUS traffic when authentication is enabled

|                Source                 |                 Destination                 | Protocol |   Source port   | Destination port  |                       Use                       |
|---------------------------------------|---------------------------------------------|----------|-----------------|-------------------|-------------------------------------------------|
| Wireless controller or Meraki network | Tenant-specific Cisco Spaces RADIUS servers | UDP      | Any (ephemeral) | 1812              | Authentication                                  |
| Wireless controller or Meraki network | Tenant-specific Cisco Spaces RADIUS servers | UDP      | Any (ephemeral) | 1813, conditional | Accounting when required by the selected design |

Use both tenant-specific server addresses displayed in the dashboard. RADIUS accounting is not required for the base Catalyst 9800 captive portal flow; enable it only when the selected feature requires it.

Expected result: A test client is redirected to the tenant splash page, completes the configured authentication, and receives the intended network access.
I. Allow OpenRoaming traffic  

## I. Allow OpenRoaming traffic

Apply the Spaces OS base rules plus the rules for the selected architecture.

### Connector-based OpenRoaming

|              Source              | Destination |  Protocol   |   Source port   | Destination port |                                 Use                                 |
|----------------------------------|-------------|-------------|-----------------|------------------|---------------------------------------------------------------------|
| Cisco AireOS wireless controller | Connector   | UDP and TCP | Any (ephemeral) | 1812 and 1813    | OpenRoaming RADIUS messages                                         |
| Connector                        | ANY         | TCP         | Any (ephemeral) | 2083             | RADSEC - OpenRoaming Identity Providers                             |
| Connector                        | ANY         | TCP/TLS     | Any (ephemeral) | 443              | Certificate signing and membership - OpenRoaming Membership service |

### Meraki-based OpenRoaming

Allow Meraki access points to initiate the following traffic:  

| Region |        Source        |   Destination    | Protocol |   Source port   | Destination port |  Use   |
|--------|----------------------|------------------|----------|-----------------|------------------|--------|
| IO     | Meraki access points | `184.73.46.220`  | TCP      | Any (ephemeral) | 2083             | RADSEC |
| EU     | Meraki access points | `63.33.180.45`   | TCP      | Any (ephemeral) | 2083             | RADSEC |
| SG     | Meraki access points | `54.169.186.118` | TCP      | Any (ephemeral) | 2083             | RADSEC |

Expected result: A supported OpenRoaming client authenticates and connects without a captive portal prompt.
J. Allow Smart Rooms gateway traffic  

## J. Allow Smart Rooms gateway traffic

### WAN

Allow the Smart Rooms gateway to initiate the following traffic:  

|       Source        |                                                Destination                                                 | Protocol |   Source port   | Destination port |                 Use                  |
|---------------------|------------------------------------------------------------------------------------------------------------|----------|-----------------|------------------|--------------------------------------|
| Smart Rooms gateway | `nodev3.iotium.io`, `checkip.amazonaws.com`, `*.google.com`, `docker.com`, `*.docker.io`, `44.202.124.117` | TCP/TLS  | Any (ephemeral) | 443              | Published Smart Rooms cloud services |
| Smart Rooms gateway | Published Smart Rooms tunnel service                                                                       | TCP      | Any (ephemeral) | 7422             | Secure cloud tunnel                  |

### Building management system

Between the Smart Rooms gateway LAN interface and the building management system, allow the following traffic, or use the customer-specific BACnet destination port when it differs:  

|              Source               |            Destination            | Protocol |   Source port   |            Destination port            |                Use                 |
|-----------------------------------|-----------------------------------|----------|-----------------|----------------------------------------|------------------------------------|
| Smart Rooms gateway LAN interface | Building management system        | UDP      | Any (ephemeral) | 47808 or customer-specific BACnet port | BACnet                             |
| Building management system        | Smart Rooms gateway LAN interface | UDP      | Any (ephemeral) | 47808 or customer-specific BACnet port | BACnet return or initiated traffic |

Expected result: The gateway establishes its secure cloud tunnel and the gateway and building management system report a healthy connection.
K. Allow Sensor Connect for IoT Services traffic  

## K. Allow Sensor Connect for IoT Services traffic

Apply this rule group when the Cisco Sensor Connect Wireless IoT Orchestrator application is deployed on a supported Cisco Catalyst 9800 Wireless Controller.

The Wireless IoT Orchestrator uses a unique application IP address. When access points cannot reach that address directly, such as when the controller is behind a firewall or located in a remote data center, configure the Sensor Connect NAT IP on the controller and use that reachable address as the firewall destination.

### Access points to Wireless IoT Orchestrator

|       Source        |                    Destination                    | Protocol |   Source port   | Destination port |                           Use                            |
|---------------------|---------------------------------------------------|----------|-----------------|------------------|----------------------------------------------------------|
| Cisco access points | Wireless IoT Orchestrator IP or configured NAT IP | TCP      | Any (ephemeral) | 50221            | Initial HTTP connection to the Wireless IoT Orchestrator |
| Cisco access points | Wireless IoT Orchestrator IP or configured NAT IP | TCP      | Any (ephemeral) | 43626            | Establish and maintain the application connection        |

### External applications to Wireless IoT Orchestrator

Apply only the interfaces used by the registered application.  

|             Source              |         Destination          | Protocol |   Source port   | Destination port |                Use                 |
|---------------------------------|------------------------------|----------|-----------------|------------------|------------------------------------|
| Registered external application | Wireless IoT Orchestrator IP | TCP/TLS  | Any (ephemeral) | 8081             | HTTPS REST API interface           |
| Registered external application | Wireless IoT Orchestrator IP | TCP      | Any (ephemeral) | 41883            | MQTT publisher listening interface |

Restrict these rules to the access point and registered application source ranges. Do not expose the Wireless IoT Orchestrator interfaces directly to the public internet. The REST interface uses authentication and HTTPS. Ensure clients trust the configured server certificate, and install an organization-approved certificate when required by security policy.

Expected result:

* **Configuration \> Services \> IoT Services** shows the IoT Orchestrator application in the **Running** state.

* The IoT Orchestrator reports that its connection to the controller was established successfully.

* **Inventory \> Access Points** lists the expected access points as connected.

* Registered external applications can use the required REST or MQTT interface.

## Validate the deployment

Complete the checks for every applied rule group:

1. From the actual source segment, confirm that each required FQDN resolves.

2. Confirm that the permitted TCP or UDP session reaches the intended destination without an unexpected proxy, TLS inspection, or NAT policy failure.

3. Review firewall logs for denied sessions from the Connector, controller, access points, Meraki cloud or wireless networks, client devices, Catalyst Center, Smart Rooms gateway, Wireless IoT Orchestrator, or registered external applications. Confirm that the session uses an ephemeral source port and the destination port listed in the applicable rule.

4. Confirm the corresponding platform status:

   * Connector control and data channels are healthy.

   * Controllers are active.

   * IoT Services deployment is successful.

   * Catalyst Center integration is activated.

   * Meraki Dashboard synchronization completes, the Scanning API receiver validates and receives observations, and wireless MQTT sessions establish over TLS 8883.

   * Kiosk, signage, or Space Explorer loads all content.

   * Captive Portal redirect and optional RADIUS authentication succeed.

   * OpenRoaming authentication succeeds.

   * Smart Rooms cloud and BACnet connections are healthy.

   * Sensor Connect shows the IoT Orchestrator running, the expected access points connected, and the required external application interface reachable.

5. Record the test result and the date on which the FQDN and IP list was verified.

## Troubleshooting

### FQDN resolves but the application remains offline

* Confirm the rule permits the resolved IPv4 or IPv6 address actually selected by the client.

* Check whether the firewall supports dynamic FQDN objects and refreshes DNS answers.

* Review proxy authentication and TLS inspection policies. WebSocket services must remain usable for kiosk and Space Explorer live data.

### Connector cloud channels are down

* Confirm outbound TCP 443 to the correct regional Connector FQDN.

* For IO static policies, confirm that both current and existing migration addresses are present.

* Check DNS, NTP, default route, proxy, and firewall logs from the Connector subnet.

### Controller or IoT Services remains inactive

* Confirm that rules B and C are applied between the correct Connector, controller, and access point addresses.

* Confirm that TCP 830 is used only for Catalyst controllers.

* Confirm that optional UDP 2003 is required before enabling FastLocate.

* In Cisco Spaces, review the detailed IoT Services deployment status and retry only after the denied path is corrected.

### Captive Portal does not redirect or authenticate

* Reopen **Configure Manually** or **View Config Guide** and compare the deployed splash FQDN, IPs, RADIUS server addresses, ports, and shared secret with the tenant-generated values.

* Confirm DNS and DHCP are available to unauthenticated clients.

* Confirm the pre-authentication or walled-garden policy permits the splash destination and the identity providers configured for the portal.

* Do not add UDP 1813 unless accounting is required by the selected workflow.

### Meraki integration is incomplete

* Confirm the regional Cisco Spaces source addresses are in the Dashboard API allowlist.

* Confirm the restriction applies to API access without unintentionally excluding administrators or other authorized integrations.

* For Scanning API, confirm that Meraki cloud can reach the tenant-generated Cisco Spaces Post URL over TCP/TLS destination port 443 and that the configured secret matches.

* For wireless MQTT, confirm that every participating Meraki network can reach the account- and region-specific broker over TCP/TLS destination port 8883.

* Confirm the firewall is not incorrectly requiring 443 or 8883 as a fixed source port; the initiating client uses an ephemeral source port.

### Sensor Connect access points or applications cannot connect

* Confirm that the IoT Orchestrator application is in the **Running** state before testing connectivity.

* If the access points cannot route directly to the IoT Orchestrator application IP, confirm that the controller has the correct Sensor Connect NAT IP and that rules target that address.

* For access point connectivity, confirm TCP 50221 and TCP 43626 from the access point source ranges.

* For registered external applications, confirm TCP 8081 for REST and TCP 41883 for MQTT as applicable.

* In **Inventory \> Access Points**, compare the expected controller access points with the access points reported as connected.

* If the REST connection reaches TCP 8081 but authentication fails, verify the registered application's API key or certificate and the configured server/client certificate trust model.

## Supplementary information

* [Cisco Spaces Configuration Guide](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide.html)

* [Seamless Meraki Integration with Cisco Spaces](https://documentation.meraki.com/Wireless/Operate_and_Maintain/How_Tos/Features_and_Integrations/Seamless_Meraki_Integration_with_Cisco_Spaces)

* [Meraki Scanning API](https://developer.cisco.com/meraki/scanning-api/overview/)

* [Cisco Spaces: Connector 3 Configuration Guide](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/connector/config/b_connector_30.html)

* [Cisco Spaces OS Runbook](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated)

* [Cisco Spaces Smart Workspaces Runbook](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-validated)

* [Space Explorer Web App](https://runbooks.ciscospaces.io/docs/space-explorer-web-app)

* [Cisco Spaces Captive Portal Runbook](https://runbooks.ciscospaces.io/docs/cisco-spaces-captive-portal-runbook)

* [Cisco Spaces OpenRoaming Runbook](https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated)

* [Cisco Spaces Smart Rooms Runbook](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-rooms-runbook-cisco-validated)

* [Cisco Sensor Connect for IoT Services Quick Start Guide](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-orchestrator/qsg/sensor-connect-iot-qsg.html)

---
language: "en"
---
# Cisco Spaces Indoor Navigation Runbook (Cisco Validated)

## OVERVIEW

*This Cisco Validated overview document will provide a comprehensive overview of the process for deploying Cisco Spaces Indoor Wayfinding, a solution designed to enhance indoor navigation and user experience. The guide is structured to assist network administrators and IT professionals in effectively setting up and managing the indoor wayfinding system.*

The introduction to Cisco Spaces Indoor Wayfinding briefly explains the purpose and benefits of implementing indoor wayfinding solutions within your organization.

In the system requirements section, it details the necessary versions and configurations of Cisco Spaces OS required for optimal performance. It also covers the essential hardware components and network specifications needed to support indoor wayfinding.

The configuration and deployment section includes steps for site preparation, such as mapping and planning the navigation paths. It provides instructions on setting up Cisco Spaces and integrating with existing network infrastructure. Additionally, it offers a detailed walkthrough of deploying the indoor wayfinding system, ensuring all components work seamlessly together.

Finally, the guide presents best practices that provide recommendations for maintaining system efficiency, including regular updates, monitoring, and user feedback mechanisms. It also includes tips for optimizing navigation accuracy and enhancing user engagement.

This guide aims to facilitate a smooth and successful deployment of Cisco Spaces Indoor Wayfinding, ensuring users enjoy a reliable and intuitive navigation experience.

### SUPPORT AND ONBOARDING

Please follow the link below to find out about the different ways to get support for Cisco Spaces.

[++Support Info Link++](https://activate.dnaspaces.io/hubfs/Assets/CiscoSpaces-SupportUpdate.pdf?__hstc=105720540.52aaa4a978f36be89855b002cb35bfc4.1729705805310.1729705805310.1729705805310.1&__hssc=105720540.1.1729705805310&__hsfp=3667649010)

*** ** * ** ***

## PREREQUISITES

This runbook should **only be used as a follow on from the** [**Spaces OS Runbook**](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated). Please refer to that document before progressing here.

In addition to the Spaces OS installation, below are the more specific requirements for Indoor Navigation.  
Please note that Meraki managed wireless infrastructure is not currently supported but will have supportability at a later date.

### Prerequisites Checklist

|-----------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Area**                    | **Prerequisites**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **Wireless Infrastructure** | Please refer to the [AP Compatibility Matrix](https://runbooks.ciscospaces.io/docs/catalyst-ap-capability-matrix) guide for compatible models                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| **AP Deployment Density**   | 1 AP per 1000 sq.ft                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **AP Deployment Density**   | 1 AP per \> 1,000 \<= 1,800 sq.ft. deployed with battery beacons                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **AP Deployment Density**   | APs are within 8-15m of each other                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **AP Placement**            | APs accurately placed on network maps Catalyst: * [++AP Auto Locate++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m-device-placement.html) (preferred) * Note: WLC version 17.12.2+ (required) * AP placement on Catalyst Center (**site survey to confirm AP location -- required**) * [++GPS Markers for network map and wayfinding map geo-alignment++](https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/catalyst-center/2-3-7/user_guide/b_cisco_catalyst_center_user_guide_237/m_work-with-wireless-2d-and-3d-maps.html#Cisco_Task_in_List_GUI.dita_cb69eac4-798d-4741-861c-3e88f3ea2a32) |
| **Spaces Infrastructure**   | Cisco Spaces Connector 3.2 Virtual Machine (VM) with **internet access to Spaces Cloud endpoints** ([++firewall allow list++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/connector/2-x/config/b_connector/m_open-ports.html) and [++proxy requirements++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/connector/2-x/config/b_connector/m_proxy.html))                                                                                                                                                                                                                                                                                                                             |
| **Spaces Infrastructure**   | Enable IoT Services - [++Advanced BLE Gateway enabled++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-services-wireless/b_iot_services/m_overview.html) BLE Mode: **BLE Transmit Mode (iBeacon) enabled** (minimum requirement) Dual Scan and Transmit Mode (recommended for Indoor Wayfinding + additional Cisco Spaces BLE Gateway functionality)                                                                                                                                                                                                                                                                                                                                       |
| **Spaces Infrastructure**   | Provide accurate CAD .dwg files for each floor in the EFT location ([++**Best Practices**++](https://runbooks.ciscospaces.io/docs/digital-map-pro-and-cad-dwg-pdf-best-practices) - including walls, furniture, room labels/IDs, and other recognizable points of interest)                                                                                                                                                                                                                                                                                                                                                                                                                            |
| **Spaces Infrastructure**   | Deploy Cisco Spaces digital signage application on a Cisco Webex Board Pro / Pro 2 **in the building lobby or central location to access wayfinding QR codes** ([++firewall allow list requirements++](https://spaces.cisco.com/setupguide/app-space-experience/#prerequisites)).                                                                                                                                                                                                                                                                                                                                                                                                                      |

The CW9176D has a BLE radio that is not omnidirectional, and as such, accuracy with this model may not be guaranteed.  
Wi-Fi 7 models support Indoor Navigation and validation of the use case is currently active.

*** ** * ** ***

### AP Density Assessment

To find a rough estimate of the AP density for a given floor, the total number of AP's on a given floor can be divided by the total square feet for that floor. From here it may provide an early indication if additional battery powered beacons need to supplement any gaps in the deployment that would lead to a suboptimal wayfinding experience.

There are a couple ways to assess the square footage of a floor. Here are two methods to get estimates.

#### Cisco Spaces AI Map Generator

The [Cisco Spaces AI Map Generator](https://mapsdemo.ciscospaces.io/) is a website that will allow you to experience a quick, lightweight version of the Digital Maps that can be generated within the Spaces dashboard. It is as easy as uploading your .DWG file and then it will begin to process the floor plan. The output will provide you the square footage of the floor.  
![Screenshot 2025-02-18 at 3.05.32 PM.png](https://runbooks.ciscospaces.io/__attachments/a_849b16687fea7cca816875231ee139596fcb3695a4ee0f28b8d2b0b8c48f7e40/Screenshot%202025-02-18%20at%203.05.32%E2%80%AFPM.png?cb=9300e062655dd919c73ee1b9c2e02c18)

#### Google Maps

Google Maps is another alternative to estimate the square footage. Here are the steps for the floor size estimation.

[smartspaces-Find-my-building-size.pdf](https://runbooks.ciscospaces.io/__attachments/a_b909a23e4b960613e96de7769b8d0c522c9bf7c3ed17e95813c8602ede0e21e5/smartspaces-Find-my-building-size.pdf.md)

1. Go to [maps.google.com](http://maps.google.com/) and search for your location

2. Click **Layers** to see satellite imagery

3. Zoom in on your site using the plus sign

4. Right click on the map and select **Measure distance**

5. Click on the map to draw a polygon around the area you want to measure

6. Close the shape

7. Google Maps will automatically show the area measurement within the polygon

![Screenshot 2025-02-18 at 5.25.46 PM.png](https://runbooks.ciscospaces.io/__attachments/a_7b40d9cdcbc55c5f7deb86ea54a9a020777118c3e2e671429dbb373dc1fedad8/Screenshot%202025-02-18%20at%205.25.46%E2%80%AFPM.png?cb=e6c13214256cba8afb1dda9a090be6b6)

*** ** * ** ***

### AP Placement Check

AP's needs to be accurately placed on network maps​.

* WLC managed AP's :​

  * [++AP Auto Locate++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m-device-placement.html) (preferred)​

    * Note: WLC version 17.12.2+ (required)​

  * AP placement on Catalyst Center (**site survey to confirm AP location -- required**)​

    * [++GPS Markers for network map and wayfinding map geo-alignment++](https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/catalyst-center/2-3-7/user_guide/b_cisco_catalyst_center_user_guide_237/m_work-with-wireless-2d-and-3d-maps.html#Cisco_Task_in_List_GUI.dita_cb69eac4-798d-4741-861c-3e88f3ea2a32)

#### AP Auto Locate

* AP Auto locate can provide most accurate information about AP placement​

* Detailed information and instructions can be found in this configuration guide :[++AP Auto Locate++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m-device-placement.html) ​

![Screenshot 2025-01-31 at 6.48.47 PM.png](https://runbooks.ciscospaces.io/__attachments/a_19cc131c56c47d1aaf222e6846a778254b80c64cb6fd9158aa948605fc2affe7/Screenshot%202025-01-31%20at%206.48.47%E2%80%AFPM.png?cb=ce2ef99211068ec3c60fd33f6acbd44d)  

![Screenshot 2025-01-31 at 6.48.58 PM.png](https://runbooks.ciscospaces.io/__attachments/a_8fb12892dc22b3fc1b1e1b7b98f9940e5cb5542694289fe57b6dfd68adc6034e/Screenshot%202025-01-31%20at%206.48.58%E2%80%AFPM.png?cb=42a4239a36a7c5cda53e801fe3bf5295)

#### AP Placement on Catalyst Center​

A 4 or more (minimum of 3) GPS Markers are required, and each should be placed at least 20 meters apart from each other. ​This is to ensure proper scaling and orientation of Catalyst Center network maps when aligning with Digital Maps​ on Cisco Spaces.

More details on placing GPS markers can be found in [the Spaces OS runbook](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated).

*** ** * ** ***

### BLE Beacon Guidance

|--------------------|-----------------------------------------------------------------------------------|---------------------------------------------|
| **Beacon Density** | **Typical Guidance​**                                                             | **Additional Battery BLE Beacon Needed**    |
| High density       | 1 AP beacon / 700 -- 1500 sq ft (65 - 140 sq m)​ ***Avg 1 per 1000 sq ft*** **​** | Minimum or few beacons needed to cover gaps |
| Medium density     | 1 AP beacon / 1500 -- 3000 sq ft (140 - 278 sq m)​​ **Avg 1 per 1800 sq ft** ​    | Needs additional beacons                    |

*** ** * ** ***

### Digital Map Processing

Digital maps are a necessary component for the wayfinding experience. It starts with a Digital Kiosk where the users will review the 3D visualized map of a floor space. Once they locate the destination on the Digital Map then they can select to option to get directions where a QR code will be presented. This is why it is necessary to have Digital Maps within the Cisco Spaces dashboard.

[The Spaces OS runbook](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated) goes through setup and best practices for preparing the CAD files for processing the Digital Maps. If Digital Maps have not been created yet please refer to the Spaces OS runbook.

*** ** * ** ***

### Digital Kiosk Readiness

Digital kiosk readiness is provided in great detail in [the Spaces Smart Workspaces runbook](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida). Please review that runbook for device compatibility and URLs that need to be reach for communication between the kiosk device and the Spaces cloud.  
Ethernet based connectivity is recommended for kiosk device network connectivity. Otherwise, if using WiFi be sure to avoid using a network with a captive portal.

*** ** * ** ***

## IMPLEMENTATION

To complete these steps, an admin will require read/write permissions within Spaces for Space Experience and IOT Services.

Deploying the Cisco Spaces Indoor Navigation solution involves several key steps. Starting with setting up the WebEx Collaboration Boards to serve as the initial touchpoints for the navigation experience. Next, configure the BLE radios to transmit the beacons necessary for accurate positioning calculations. Afterward, review the planned routes to ensure they offer optimal paths throughout the building. Finally, conduct a thorough verification of the entire navigation experience.

Below is a RACI diagram of the tasks detailed in subsequent subsections. This will provide a quick reference as to who is responsible for which tasks while Indoor Navigation is under Limited Availability.  

|                                                         Task                                                         | Customer (C) | Deployment Team (DT) |
|----------------------------------------------------------------------------------------------------------------------|--------------|----------------------|
| 1. Pre-req readiness validation (IOT service , SW version , ap density and placement criteria, CAD file and maps)etc | R/A          | I                    |
| 2. Configure the BLE radios                                                                                          | I            | R/A                  |
| 3. Path drawing review                                                                                               | I            | R/A                  |
| 4. Enable feature flags for kiosk                                                                                    | I            | R/A                  |
| 5. Configure the digital kiosk                                                                                       | R/A          | C                    |
| 6. Onsite validation                                                                                                 | I            | R/A                  |

### Legend:

* **R (Responsible)** -- The role that does the work to complete the task.

* **A (Accountable)** -- The role ultimately answerable for the task's completion.

* **C (Consulted)** -- The role providing input or expertise.

* **I (Informed)** -- The role kept up to date on progress.

### Configuring Digital Kiosk

Configuring the digital kiosk is detailed in [the Spaces Smart Workspaces runbook](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida). Please refer to this documentation for configuration details.  
While Indoor Wayfinding is in Limited Availability the Spaces deployment team will need to enable a feature flag to enable pathfinding for the kiosks.

*** ** * ** ***

### Configuring the BLE Radios

For this section related to configuring the BLE radios, bulk configuration of the BLE radio settings \& UUID assignments is possible and can be managed by the Spaces Indoor Wayfinding deployment team while Indoor Wayfinding is in Limited Availability.  
The sections below on configuring BLE services are for reference only. Please contact support as the configuration can be done in bulk by the Cisco support team.

#### How to Configure BLE Services in Cisco Spaces

With accurate placement of AP's on the network map and geo-alignment with the fully geo-referenced Cisco Spaces Digital Maps Pro, the Cisco Spaces iOS App Clip can render a map + AI drawn paths + calculate its own location on-device​.  

|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| ![Screenshot 2025-02-02 at 6.33.57 PM.png](https://runbooks.ciscospaces.io/__attachments/a_0df0764b5f4dbc10af8be9780de32c51b6163bfa32c5654fbbaa266642c2a211/Screenshot%202025-02-02%20at%206.33.57%E2%80%AFPM.png?cb=595a76df84c2bc16a9e16857d0124a34) | ![Screenshot 2025-02-02 at 6.34.10 PM.png](https://runbooks.ciscospaces.io/__attachments/a_71bf307bb110015e3d80557be2583a4da871083972a86b92b51cac14f2002c28/Screenshot%202025-02-02%20at%206.34.10%E2%80%AFPM.png?cb=390925d1482cc9ed355a4400137856f3) |

Indoor wayfinding uses BLE on AP's (or additional battery beacons), and those BLE beacons need to be transmitting the signal, which can be captured by Mobile application to calculate its own position on the map​.

The steps for configuring the BLE radios is as follows:

1. Enable IoT Services

   1. This is part of the Spaces OS runbook and is a prerequisite for the Indoor Navigation outcome. Please visit the Spaces OS runbook if this has yet to be done.

2. Enable BLE mode (through the Spaces dashboard menu **IoT Services**). There are two options for this below:

   1. Need to BLE Transmit Mode (iBeacon) enabled ​(minimum requirement). ​Detailed steps are here: ​[Configuring AP as a Beacon in Transmit mode](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-services-wireless/b_iot_services/m_ap-as-a-beacon.html#Cisco_Task.dita_7e94eaf3-8c8d-4372-9153-074bd333562f:~:text=6.%20Configuration%20Status-,Configure%20AP%20as%20a%20Beacon%20in%20Transmit%20Mode,-You%20can%20configure)

      ![Screenshot 2025-02-02 at 6.52.02 PM.png](/__attachments/a_28b2e5022835e975eea6523f9ceb6b9a0e98005dc227899d5a2c196745d8f8d7/Screenshot%202025-02-02%20at%206.52.02%E2%80%AFPM.png?cb=48dcd64e4c1a4b4e763d2f19ca058eef)

   2. ​Dual Scan and Transmit Mode ​(recommended for Indoor Wayfinding + ​additional Cisco Spaces BLE Gateway functionality)​. Detailed steps are here: [​Configuring AP as a Beacon in Dual mode](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-services-wireless/b_iot_services/m_ap-as-a-beacon.html#Cisco_Task.dita_7e94eaf3-8c8d-4372-9153-074bd333562f:~:text=12.%20Configuration%20Status-,Configure%20AP%20as%20a%20Beacon%20in%20Dual%20Mode,-You%20can%20configure)

      ![Screenshot 2025-02-02 at 6.52.27 PM.png](/__attachments/a_af6667f1832d37f5d4aa1aac0fe0647ece039ec6c3de38ea8f0f9159516e0517/Screenshot%202025-02-02%20at%206.52.27%E2%80%AFPM.png?cb=eb74b8dd045bc6ee726968580f3f2292)

#### BLE Formatting Schema

A naming convention for the BLE beacons is to be used. The format for the UUID, major, and minor values that leverage the Spaces tenant ID, a building enumeration, the floor number, and a beacon enumeration. See below for the schema.

![Screenshot 2025-11-17 at 4.43.03 PM.png](https://runbooks.ciscospaces.io/__attachments/a_5282a9232438c35b59e98642bc20991c771cc5502c58aac309360a1da1288e52/Screenshot%202025-11-17%20at%204.43.03%E2%80%AFPM.png?cb=0c3a2b707d7e0a45f29961baac1d616d)

#### Recommended BLE Configuration

* **Power**: 0dBm​

  * Controls the beacon signal range. -12dBm gives an approximate range of​ 20 meters and +4 dBm an approximate range of 70 meters.​

* **Adv. Tx power**: -70

  * Expected RSSI at a distance of 1 meter from the beacon. Usually between -60​ to -70 to indicate immediate proximity at 1 meter.

* **Adv. Interval**: 330

  * ​Time between consecutive beacon broadcasts. Usually between 100 to 750ms

*** ** * ** ***

### Path Drawing Review

A path drawing review will be be performed with the specified point of contact from the Cisco Spaces team. Verification of the path drawing to various rooms on the floor are taking the appropriate route is performed in this review. If any edits are needed, due to consideration needed for glass walls, furniture, or areas to be avoided, for any of the routes they can be made at this time.  
![Screenshot 2025-02-05 at 4.41.01 PM.png](https://runbooks.ciscospaces.io/__attachments/a_503b8bdd95c051b402fca1d5ba84d974575eafc409963d3437c0c149eac373ef/Screenshot%202025-02-05%20at%204.41.01%E2%80%AFPM.png?cb=b0bad7beed51968d83af8b6c2d54a952)
*Path drawing screenshot*

### Transitions Review

**Tip:** when naming Transitions (e.g. Elevators, Stairs), try using unique names for each instance. For example, "1N" for "1st Floor North" and "2N" for "2nd Floor North" so that it is easy to match up Transitions from floor to floor. In elevators, where each elevator shaft may link to different sets of floors, using a number or letter to differentiate them will make it easier to verify the floors that should be linked. For example, "1-1", "1-2", "1-3" for "1st Floor elevators banks 1, 2, and 3", where "1-1" links to floors 1-10, "1-2" links to floors 1 and 11-20, and "1-3" links to floors 1 and 21-30. In order to wayfind from the 29th Floor to the 2nd Floor by elevator, take elevator "1-3" to the 1st Floor, then elevator "1-1" to the 2nd Floor.  
![Space Experience - Wayfinding - Path and Transitions - Stairs example connecting all floors](https://runbooks.ciscospaces.io/__attachments/a_01174130f179e732553d0f34dab09abc0700c96aaf094394f392ddda97a93c33/Screenshot%202025-10-17%20at%2014.37.08.png?cb=b3bcb8387a37291ad53086657e182eb9)
Space Experience \> Wayfinding \> Path \& Transitions - Stairs example connecting all floors  
![Space Experience - Wayfinding - Path and Transitions - Stairs example excluding some floors](https://runbooks.ciscospaces.io/__attachments/a_2159d09c782ad503c74b2688bb1813148adbdf4479540ebad073b0ed992d57dc/Screenshot%202025-10-17%20at%2014.37.23.png?cb=9ef7009fd1e363adc600d9301d686d0b)
Space Experience \> Wayfinding \> Path \& Transitions - Stairs example excluding some floors  
![Space Experience - Wayfinding - Path and Transitions - Elevators example connecting all floors](https://runbooks.ciscospaces.io/__attachments/a_36ce40f0d494418d197edd43f478a9eea3949a496ffff9da4f4fc0ab3a32468e/Screenshot%202025-10-17%20at%2014.42.40.png?cb=a031295863dde880438084f37b813592)
Space Experience \> Wayfinding \> Path \& Transitions - Elevators example connecting all floors

*** ** * ** ***

### Verify the Wayfinding Experience

#### On-Site Beacon Validation and Accuracy Testing

After all of the prerequisites and setup has been completed the last part is the walk test and accuracy testing. If deployment assistance has already been prearranged then an engineer from the Cisco Spaces team will be scheduled to come onsite to perform these activities.

##### Walk Test

The walk test is done to cover several items related to the BLE beacons in the environment:

1. Verify beacons received accurately

2. Verify adequate beacon coverage

The walk test uses specific beacon recording software that is downloaded to a mobile device. A predetermined route is provided with a start and end indicators for the specified floor.  
![Screenshot 2025-02-07 at 11.59.50 AM.png](https://runbooks.ciscospaces.io/__attachments/a_dfdf025f83259706d25fe76b7b340a3e3b9cb5f7c7c4f1188b391c4e3dcb1afc/Screenshot%202025-02-07%20at%2011.59.50%E2%80%AFAM.png?cb=a5d27bf2019cc10814e77cd07a4eb534)
*Walk test path example*

After the walk test is concluded the file will be uploaded to the cloud for review. The Cisco Spaces team will review the results within approximately one week and provide a report. The report may be accompanied with any recommendations for gaps found in the coverage, unless the deployment involves an onsite engineer from Cisco Spaces. In which case, such items will be assessed at that time.  
![Screenshot 2025-02-07 at 11.58.58 AM.png](https://runbooks.ciscospaces.io/__attachments/a_93a3fd588085c16868fb49e34ae31fd078abe2a68c3f0dc936331ff0501def28/Screenshot%202025-02-07%20at%2011.58.58%E2%80%AFAM.png?cb=a9541eb3cb9be8e8b1f85f7183becf19)
*Example walk test report*

##### Accuracy Testing

If a Cisco Spaces engineer is dispatched onsite accuracy testing will be performed by testing various routes on the floor to ensure proper accuracy of the blue dot on the mobile device. If any gaps or issues are found then recommendations will be provided and/or made to ensure a positive wayfinding experience.

#### How to Experience Indoor Navigation

Indoor navigation is experienced on a mobile device to give someone turn-by-turn directions within a building. Currently there is a disparity in the mobile experience between iPhone and Android due to limitations with accessing parts of the hardware. An Android application is currently in development to allow for parity in the wayfinding experience. Illustrations between the current experience of the two platforms are contained below.  
Currently the only language supported in the App Clip is english.

|                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |                                                                                                              **iPhone**                                                                                                               |                                                                                                                          **Android (web)**                                                                                                                           |                                                                                                                         **Android (app)**                                                                                                                         |
|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1. While at the kiosk, select a meeting room on the floor. Select the **Get Directions** button.                                                                                                                                                                                                                                                                                                                                                                                                                  | ![Cisco Spaces Space Explorer Kiosk showing Room Details popup](https://runbooks.ciscospaces.io/__attachments/a_b1fb32c2876bc8fabbe7470496f7681a84152580c443604005a91560a93a0837/IMG_4957.jpg?cb=93423eeb407075cf27dd78a05b92c264)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
| 2. A QR code will appear in place of the Room Details.                                                                                                                                                                                                                                                                                                                                                                                                                                                            | ![Space Explorer Kiosk showing Get Direction QR code](https://runbooks.ciscospaces.io/__attachments/a_467abcd544a1d89ad6883b367fe0eff30e3e430f1b64f8d5d7a364e86ad18760/Screenshot%202025-10-17%20at%2012.37.17.png?cb=f5dc24fceeed14189b9621565b14e9bd)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |||
| 3. Open a QR reader or camera app to scan the QR code, then select the URL "chip" presented in yellow.                                                                                                                                                                                                                                                                                                                                                                                                            | ![iOS Camera app scanning a QR code](https://runbooks.ciscospaces.io/__attachments/a_07ba62ce7e4880ef95b49980997b68f1c0134f7041c8033a96acd8f4a8041461/IMG_2680.PNG)                                                                                                  | ![Android Camera app scanning a QR code](https://runbooks.ciscospaces.io/__attachments/a_d2871c389acea7933f04ae0e8775427f33140d5645639b4a1b8819c036a5d3bb/Screenshot_20251017_114102_Camera.JPG?cb=99d8e500f090e1455485d82f2688e27c)                                                                                                                                                                                                                                                                                                                                   ||
| 4. For iPhone, an App Clip dialog will appear from the bottom of the screen. Select **Open** to proceed.                                                                                                                                                                                                                                                                                                                                                                                                          | ![iOS Camera app prompting to Open the Cisco Spaces Indoor Wayfinding App Clip](https://runbooks.ciscospaces.io/__attachments/a_0318a43b3f5a01dd964017ce50333a5cf83874e4a51d65881eccc9e7f9a3342f/IMG_4959.PNG?cb=7d1190d3ea955c94d944b72f19dd74a5)                   | **N/A**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 ||
| 5. If not done previously, the iOS phone will ask for Cisco Spaces to use the phone's location. Select **Allow While Using Until Tomorrow** (preferable) or **Allow Once** to proceed with turn-by-turn navigation.                                                                                                                                                                                                                                                                                               | ![Cisco Spaces Indoor Wayfinding App Clip prompting to use location](https://runbooks.ciscospaces.io/__attachments/a_5b1ff5fd293bf583422692661944293efb5cf97e735006e5a6a1bc1e584d221e/IMG_4960.PNG?cb=fc74a99e027ea86c342ac5fa2fe5d640)                              | **N/A**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 ||
| 6. The destination will be shown on the 3D AI Digital Map. Select **Take me there** to begin the journey. **Note:** the Android web page will show a banner at the top of the browser that will lead to Google Play Store to download the Android app. **Note:** if previously downloaded, the Android app will open automatically to the scanned destination to begin navigation.                                                                                                                                | ![Cisco Spaces Indoor Wayfinding App Clip showing destination and Take me there button](https://runbooks.ciscospaces.io/__attachments/a_e7fea9acd21ba8e65d715c2b22b40ad52f7631c201aee8dcaa49d7197ccb63f2/IMG_2683.PNG?cb=d892cc0a850176fb02c7a3557b264ef3)           | ![Cisco Spaces Indoor Wayfinding web app showing destination and Take me there button](https://runbooks.ciscospaces.io/__attachments/a_28b3135c8991d98ff2625bb502278d1b8e5c95641eed5613f18fe336eb547f7a/Screenshot_20251017_114418_Chrome.JPG?cb=2405a29ba94a09ae6f5cad6cb1f36cdc)                  | ![Cisco Spaces Indoor Wayfinding App showing destination and Take me there button](https://runbooks.ciscospaces.io/__attachments/a_cd0d3649a59159e6e06be32205a7e87bcd5033fbe73bf0a8ec8e969521fe5d7b/Screenshot_20251017_114717_Cisco%20Spaces.JPG?cb=66df6630f2439277ce2b4ac35de421ca)           |
| 7. On Android (web), search for and choose a **Starting point** . Then, select **Show Directions** to view an animated path between them. **Note:** on iOS, at any time, search for and choose a new destination, but the **Starting point** is always the phone's live location. **Note:** on Android, clicking the blue **Open** button on the banner opens Cisco Spaces app listing in the Google Play Store. Click **Install** to download and install the Cisco Spaces app, then **Open** to launch the app. | **N/A**                                                                                                                                                                                                                               | ![Cisco Spaces Indoor Wayfinding web app showing a field to select a Starting point](https://runbooks.ciscospaces.io/__attachments/a_bbdaf03aa7326809d78c3c284cdd92a6929741b6fc0b0bd415db38db724e6f90/Screenshot_20251017_124859_Chrome.JPG?cb=0f09f5f1be975c1c1949a3cad100638a)                    | ![Cisco Spaces app listing in Android Google Play Store](https://runbooks.ciscospaces.io/__attachments/a_c21439e34349d7567652ba383a6503fd9edac0cf7cea11b077503b152286e6c2/Screenshot_20251017_114535_Google%20Play%20Store.JPG?cb=3f0e8e3c4868095c024d2155b1d0670c)                              |
| 8. If not done previously, the Android phone will ask for Cisco Spaces to use the phone's location. Select **Allow only while using the app** (preferable) or **Ask every time** to proceed with turn-by-turn navigation. **Note:** where applicable, **Precise Location** is preferred for outdoor GPS navigation and Transitions between buildings.                                                                                                                                                             | **N/A**                                                                                                                                                                                                                               | **N/A**                                                                                                                                                                                                                                                              | ![Cisco Spaces Indoor Wayfinding App prompting to use location](https://runbooks.ciscospaces.io/__attachments/a_25a9aea3e6595f2968417a087f2e6ffdc5e837121a1c4820ab0aa56f102fac5c/Screenshot_20251017_114737_Cisco%20Spaces.JPG?cb=668afa9f73abf3cb96947c7ac2616011)                              |
| 9. The navigation will begin and provide instructions on each step of the journey. A path (shortest route) will be drawn on the map from the phone's live location to the destination. On Android, the shortest route between the **Starting point** and **Destination** will appear as an animated line.                                                                                                                                                                                                         | ![Cisco Spaces Indoor Wayfinding App Clip showing live location and shortest path to destination](https://runbooks.ciscospaces.io/__attachments/a_1be3acd2c2197bc81eaf6f75a48a6ba9651f3c066bd774e852be6c56298a4739/IMG_2684.PNG?cb=4d34cf935d1e8902eaa8eeea07859595) | ![Cisco Spaces Indoor Wayfinding web app showing a static route between Starting point and Destination](https://runbooks.ciscospaces.io/__attachments/a_ac0c9871faf6d043509ce9e8e182472e33ac7f151c654bea78453ff383e1a70f/Screenshot_20251017_114510_Chrome.JPG?cb=adf34f5dc65ad40f017be61c2dcdd3aa) | ![Cisco Spaces Indoor Wayfinding App showing live location and shortest path to destination](https://runbooks.ciscospaces.io/__attachments/a_15ece3d7a7885e9341023a5c46060769dbc0dd56bea44c7a87aa0619466b1beb/Screenshot_20251017_114835_Cisco%20Spaces.JPG?cb=a0e89aa62fb4224dc393bd0473073a07) |
| 10. On arrival the iOS App Clip and Android app will show a message that the journey has concluded.                                                                                                                                                                                                                                                                                                                                                                                                               |                                                                                                                                                                                                                                       | **N/A**                                                                                                                                                                                                                                                              |                                                                                                                                                                                                                                                                   |

*** ** * ** ***

## FAQ

1. **Does enabling indoor navigation have any impact on WiFi usage?​​**

   1. Enabling BLE has minimal interference with Wi-Fi

   2. BLE advertisement is transmitted on 3 channels -- 1MHz wide whereas Wi-Fi has a 22 MHz channel bandwidth in 2.4GHz frequency range

   3. If any single advertising channel for BLE is blocked, the other channels are likely to be free since they're separated by quite a few MHz of bandwidth

   4. BLE channels are strategically placed to avoid interference from WiFi channels Ch1, 6, and 11​

   5. The Tx power for indoor navigation is between -9dBm to 0dBm for BLE whereas WiFi transmits at \~20dBm

   6. Low Tx powers of BLE results in insignificant intereference with Wi-Fi. On the other hand, BLE avoids interference by hopping between multiple channels placed between Wi-Fi channels​

2. **What PII data is collected when a user engages with the Cisco Spaces Indoor Navigation experience?​**

   1. [++https://trustportal.cisco.com/c/dam/r/ctp/docs/privacydatasheet/DNA/cisco-dna-spaces-privacy-data-sheet.pdf++](https://trustportal.cisco.com/c/dam/r/ctp/docs/privacydatasheet/DNA/cisco-dna-spaces-privacy-data-sheet.pdf)

3. **What do I need to keep in mind for Campus Wayfinding (i.e. indoor-outdoor and inter-building navigation)?**

   There are several factors that affect Campus Wayfinding and decrease time to process CAD files:
   1. Locations in the Location Hierarchy **MUST** be grouped under the same common level above the Building level.

   2. A group of Buildings (i.e. Campus) **MUST** fit within a 100km² area (roughly 10km x 10km). To be safe, the distance between the 2 furthest buildings must be no more than 8km.

   3. Geo-alignment on the world map is essential. Elements included in the CAD files (e.g. bridgeways, paths, etc.) can help align Buildings to ensure smooth transitions between Buildings in a Campus.​

*** ** * ** ***

## REFERENCE

![Screenshot 2025-03-11 at 6.13.17 PM.png](https://runbooks.ciscospaces.io/__attachments/a_ea49c9f15e34937a70aadab7b1bed6f7af3355a791887935cdb71e8b3ea2dba6/Screenshot%202025-03-11%20at%206.13.17%E2%80%AFPM.png?cb=2a5cc36bd094c04622ca30b2f62640e7)
Data flow to enable indoor navigation

![Screenshot 2025-03-11 at 6.17.29 PM.png](https://runbooks.ciscospaces.io/__attachments/a_8cd76047075535e3a7bfe24697296b9bb8e7bb0336123a2483ec6cf5ed9215d6/Screenshot%202025-03-11%20at%206.17.29%E2%80%AFPM.png?cb=3adaa208ac99aaf673f4b097511c73da)
Data ports needed for indoor navigation

---
language: "en"
---
# Cisco Spaces Occupancy Day 2 Guide

## OVERVIEW

The *Cisco Spaces Occupancy Day 2 Guide* provides Day 2 operational guidance for Occupancy outcomes in Cisco Spaces. It is intended for customers, partners, and Cisco teams who are responsible for ongoing operations, monitoring, and optimization of occupancy data after an initial deployment is complete.

Cisco Spaces Occupancy capabilities enable organizations to understand how spaces are actually used, from campus and building levels down to floors, zones, and rooms. These insights support outcomes such as space optimization, capacity planning, safety and compliance, and improved workplace experiences. While achieving these outcomes begins with a successful deployment, their long-term value depends on effective Day 2 operations.

### Purpose of This Guide

The purpose of this guide is to:

* Describe **ongoing operational tasks** required to maintain accurate and reliable occupancy data

* Define **monitoring, reporting, and troubleshooting practices** for occupancy outcomes

* Provide guidance on how to **interpret and act on occupancy insights** over time

* Support continuous improvement and alignment with business and facilities objectives

This guide focuses on **operational excellence after go-live**, rather than initial setup.

#### Intended Audience

This guide is intended for:

* IT operations teams managing Cisco Spaces

* Facilities and workplace experience teams consuming occupancy insights

* Partners supporting managed services or ongoing operations

* Cisco internal teams supporting customer success and adoption

The guidance assumes familiarity with Cisco Spaces concepts, location hierarchy, and deployed occupancy technologies.

#### Scope

The *Cisco Spaces Occupancy Day 2 Guide* applies to occupancy outcomes delivered through Cisco Spaces applications such as:

* Space Utilization

* Right Now

* Space Manager

* Related occupancy and location analytics capabilities

Technology-specific deployment details (e.g., sensor placement, onboarding steps) are intentionally minimized and referenced back to the deployment runbook where appropriate.

### Relationship to the Occupancy Deployment Runbook

This document is **not a replacement for the Cisco Spaces Occupancy Deployment Runbook**.

* The [**Deployment Runbook**](https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-runbook-cisco-validated) focuses on **Day 0 / Day 1 activities**, including:

  * Architecture and technology selection

  * Prerequisites and onboarding requirements

  * Initial configuration of Cisco Spaces and supporting technologies

  * Validation of occupancy data at deployment time

* This **Day 2 Occupancy Operations Guide** focuses on:

  * Ongoing health and accuracy of occupancy data

  * Monitoring and dashboards

  * Reporting and analytics usage

  * Troubleshooting common operational issues

  * Long-term optimization and outcome realization

Readers should ensure that occupancy has been **successfully deployed and validated** according to the [deployment runbook](https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-runbook-cisco-validated) before relying on this guide for operations.

*** ** * ** ***

## OPERATIONAL PRIORITIES \& KPI'S

Once Cisco Spaces Occupancy has been successfully deployed, Day 2 operations shift focus from enablement to **sustained value delivery** . The primary objective of ongoing operations is to ensure that occupancy data remains **accurate, reliable, and actionable**, and that it continues to support business and workplace outcomes over time.

Cisco Spaces includes a **Monitor** page in the dashboard that displays system and app health details such as connected locations, anomalies, and app latency or uptime status. These operational signals help validate the KPIs listed above and should be used as part of routine checks. Refer to Section 3 for specifics on accessing and interpreting these monitoring screens within Cisco Spaces.

This section defines the **core operational priorities** for occupancy and the **KPIs** that teams should monitor to validate success.

### Day 2 Operational Priorities

Day 2 operations for occupancy in Cisco Spaces typically align to the following priorities:

#### Data Accuracy and Trust

Occupancy insights are only valuable if stakeholders trust the data. Operational teams must ensure:

* Occupancy counts reflect real-world usage patterns

* Location hierarchy, maps, and metadata remain accurate

* Data collection is consistent across time and locations

Maintaining trust in the data is foundational for adoption by facilities, real estate, and business teams.

#### Availability and Continuity

Occupancy data should be continuously available to support:

* Real-time monitoring (e.g., Right Now)

* Historical analysis (e.g., Space Utilization)

* Scheduled reports and dashboards

Day 2 operations must identify and address gaps caused by device outages, connectivity issues, or configuration drift.

#### Outcome Alignment

Operational teams should continuously validate that occupancy insights are aligned with intended outcomes, such as:

* Space optimization and consolidation

* Capacity planning and growth forecasting

* Safety, density monitoring, and compliance

* Improved employee and visitor experiences

This often requires collaboration between IT, facilities, real estate, and workplace stakeholders.

#### Operational Efficiency

Day 2 operations should minimize manual effort by:

* Standardizing monitoring and reporting

* Leveraging alerts and dashboards

* Establishing repeatable processes for troubleshooting and maintenance

### Key Performance Indicators (KPIs)

The following KPIs help measure the health and effectiveness of occupancy operations in Cisco Spaces. Not all KPIs will apply to every deployment; teams should select those that best align to their use cases.

#### Occupancy Data Health KPIs

These KPIs indicate whether occupancy data is being collected and processed correctly:

* Percentage of locations reporting occupancy data

* Frequency of missing or stale occupancy data

* Consistency of occupancy counts over time

* Sensor or device reporting status (where applicable)

#### Application Availability KPIs

These KPIs measure the operational availability of Cisco Spaces occupancy applications:

* Availability of Space Utilization dashboards

* Availability of Right Now real-time occupancy views

* Successful generation of scheduled reports

#### Accuracy and Validation Indicators

While absolute accuracy can vary by technology, operational teams should track indicators such as:

* Expected vs. observed occupancy trends (e.g., weekdays vs. weekends)

* Sudden or sustained anomalies at room, floor, or building levels

* Correlation between occupancy data and known events or schedules

These indicators help identify when deeper investigation or recalibration may be required.

#### Usage and Adoption KPIs

These KPIs help assess whether occupancy outcomes are being consumed and acted upon:

* Number of active users accessing occupancy dashboards

* Frequency of report exports or views

* Stakeholder feedback from facilities and real estate teams

Adoption is a key signal that occupancy data is delivering value.

### Operational Ownership

Clear ownership is critical for effective Day 2 operations. Organizations should define:

* Who monitors occupancy data health

* Who responds to alerts or anomalies

* Who owns reporting and stakeholder communication

* How issues are escalated and resolved

Defining ownership upfront helps ensure occupancy outcomes remain reliable and aligned with business needs.

*** ** * ** ***

## MONITORING \& DASHBOARDS

Effective Day 2 operations for occupancy outcomes in Cisco Spaces rely on **continuous monitoring and visibility** across the entire system. Monitoring ensures that occupancy data remains reliable, applications remain available, and insights continue to reflect real-world space usage.

Cisco Spaces supports monitoring through **multiple complementary mechanisms**, including:

* Built-in dashboards and monitoring views within the Cisco Spaces user interface

* Programmatic access to telemetry and events via the Cisco Spaces Firehose API

Together, these mechanisms enable both **operational awareness** and **integration with external monitoring, analytics, or automation systems**.

### Monitoring Objectives

The primary objectives of monitoring occupancy in Cisco Spaces are to:

* Validate that **occupancy data is being collected and processed consistently**

* Detect issues that could impact **data accuracy, timeliness, or availability**

* Provide confidence in **real-time and historical occupancy insights**

* Enable proactive response to anomalies before they affect downstream systems or stakeholders

Monitoring should be treated as a **continuous operational discipline**, regardless of whether insights are consumed directly in Cisco Spaces or externally.

### Layers of Monitoring

Occupancy monitoring in Cisco Spaces spans multiple layers, each contributing to overall system health and outcome reliability.

#### Platform and Service Health

At the highest level, operational teams must ensure that the Cisco Spaces platform and enabled services are functioning as expected. This includes:

* Overall platform and service availability

* Health of occupancy-related applications

* Processing latency that could affect dashboards, reports, or data streams

These signals confirm that the platform is capable of delivering occupancy insights.

#### Data Flow and Continuity

Monitoring should confirm that occupancy data:

* Is continuously generated by source technologies

* Flows reliably through the Cisco Spaces platform

* Is delivered without significant gaps or delays

This applies equally to data viewed in the Cisco Spaces UI and data consumed through APIs such as the Firehose.

#### Location and Hierarchy Coverage

Occupancy monitoring should account for **coverage across the full location hierarchy**, including:

* Campuses, buildings, and floors

* Zones and rooms where applicable

Operational teams should be able to identify:

* Locations that are not reporting occupancy data

* Changes in reporting behavior at specific hierarchy levels

These gaps may surface visually in dashboards or programmatically through missing or inconsistent data streams.

#### Consumption and Delivery Monitoring

Occupancy outcomes are often consumed through multiple channels:

* Cisco Spaces dashboards and reports

* External systems consuming data via the Firehose API

Monitoring should validate that:

* Dashboards and reports remain accessible and current

* Firehose streams are active and delivering expected events

* Downstream systems continue to receive and process occupancy data

This ensures continuity of outcomes across the entire ecosystem.

### Dashboards and Streams as Operational Tools

Both dashboards and data streams play a central role in Day 2 operations:

* **Dashboards** provide consolidated, human-readable views of system health, trends, and anomalies.

* **Firehose API streams** provide near real-time telemetry that can be used for:

  * External monitoring and alerting

  * Custom analytics and visualization

  * Integration with ITSM, facilities, or data platforms

Operational teams may use one or both mechanisms depending on organizational needs, but the **monitoring goals remain the same**.

### From Monitoring to Action

Monitoring is only valuable if it leads to action. Day 2 occupancy operations should establish:

* Thresholds or conditions that trigger investigation

* Defined responses to common monitoring signals

* Escalation paths when issues affect business outcomes or downstream systems

Triggers may originate from:

* Visual indicators in Cisco Spaces dashboards

* Missing, delayed, or anomalous data observed via the Firehose API

* Alerts generated by external systems consuming occupancy data

These scenarios are explored in later sections.

### Relationship to Cisco Spaces Monitoring Capabilities

Cisco Spaces provides built-in monitoring views within the platform as well as programmatic access to occupancy data and events via the Firehose API. Together, these capabilities support a holistic monitoring strategy for Day 2 occupancy operations.

Subsequent sections will provide more detailed guidance on:

* Routine configuration checks

* Alerting and thresholds

* Troubleshooting common occupancy issues

* Operational best practices for sustained outcomes

*** ** * ** ***

## ROUTINE CONFIGURATION CHECKS

Day 2 occupancy outcomes depend on the **ongoing correctness of configuration**, not just the initial deployment. Over time, changes to spaces, devices, organizational structures, or business requirements can introduce configuration drift that impacts occupancy data quality and reliability.

Routine configuration checks help ensure that Cisco Spaces continues to reflect the **current physical and organizational reality** of the environment.

### Purpose of Routine Checks

The goals of routine configuration checks are to:

* Maintain accuracy and trust in occupancy data

* Detect configuration drift before it impacts reporting or decision-making

* Ensure alignment between physical spaces and digital representations

* Support consistent monitoring and troubleshooting

These checks should be performed on a **regular cadence** and as part of any significant change to the environment.

### Location Hierarchy Validation

The Cisco Spaces location hierarchy (campus, building, floor, zone, room) provides the structural foundation for all occupancy insights. Day 2 operations should periodically verify that:

* Locations are correctly defined and organized

* Hierarchy relationships accurately reflect real-world layouts

* New or modified spaces are properly represented

* Deprecated or unused locations are cleaned up

Inaccuracies at this layer can propagate through dashboards, reports, and APIs, resulting in misleading occupancy outcomes.

### Maps and Spatial Metadata

Digital maps and spatial metadata play a critical role in occupancy visualization and analytics. Routine checks should confirm that:

* Floor maps are current and aligned with physical layouts

* Zones and rooms are correctly drawn and labeled

* Spatial boundaries match intended use cases (e.g., open areas vs. enclosed rooms)

Changes such as renovations, space reconfiguration, or repurposing should trigger map and metadata reviews.

### Device and Data Source Association

Occupancy outcomes rely on correct association between data sources and locations. Operational teams should verify that:

* Devices or sensors remain assigned to the correct locations

* New devices are properly onboarded and mapped

* Decommissioned or relocated devices are updated or removed

* Data sources align with expected occupancy use cases

Incorrect associations can lead to over-counting, under-counting, or missing occupancy data.

### Application Configuration Consistency

Cisco Spaces applications that deliver occupancy outcomes may include configurable parameters such as:

* Reporting intervals and aggregation levels

* Thresholds for alerts or notifications

* Visibility and access controls

Routine checks should ensure that application settings:

* Remain consistent with operational goals

* Reflect current stakeholder requirements

* Have not been unintentionally altered over time

### Change Management Considerations

Routine configuration checks should be closely aligned with change management processes. Any of the following events should prompt additional validation:

* Physical space changes or renovations

* Organizational or tenant changes

* Device replacements or technology upgrades

* Updates to reporting or monitoring requirements

Documenting configuration changes and their impact on occupancy outcomes helps maintain long-term stability and operational clarity.

### Cadence and Ownership

Organizations should define:

* How often routine configuration checks are performed

* Which teams are responsible for specific checks

* How findings are documented and addressed

Common cadences include monthly reviews and post-change validations, but frequency should align with the pace of change in the environment.

*** ** * ** ***

## REPORTS \& ANALYTICS

Reports and analytics are the primary mechanisms by which occupancy data is **translated into insight and action** . In Day 2 operations, the focus shifts from simply viewing occupancy data to **using it consistently and confidently** to support planning, optimization, and decision-making.

This section describes how reporting and analytics should be approached operationally, independent of any specific visualization or export method.

### Purpose of Occupancy Reporting

The purpose of occupancy reporting in Cisco Spaces is to:

* Provide **evidence-based visibility** into how spaces are used

* Support **trend analysis** over time as well as point-in-time views

* Enable informed decisions related to space planning, consolidation, and investment

* Establish a common, trusted data source for multiple stakeholders

Effective reporting helps ensure that occupancy outcomes extend beyond IT and are embedded into business and facilities processes.

### Types of Occupancy Insights

Day 2 operations typically support multiple categories of occupancy insights.

#### Historical Utilization Trends

Historical reporting helps answer questions such as:

* Which buildings or floors are underutilized or overutilized?

* How usage patterns change by day of week or time of day

* How occupancy evolves over months or quarters

These insights are commonly used for space optimization and long-term planning.

#### Comparative Analysis

Comparative analytics enable teams to:

* Compare usage across locations or regions

* Identify inconsistencies in space utilization

* Benchmark performance before and after changes (e.g., return-to-office initiatives)

This type of analysis supports continuous improvement efforts.

#### Exception and Outlier Identification

Reports can also be used to identify:

* Unexpected spikes or drops in occupancy

* Locations that consistently deviate from expected patterns

* Anomalies that warrant deeper investigation

These insights often feed into alerting and troubleshooting workflows.

### Reporting Cadence and Rhythm

Day 2 occupancy reporting is most effective when it follows a **defined cadence**, rather than being ad hoc.

Common reporting rhythms include:

* **Weekly summaries** for operational awareness

* **Monthly reports** for facilities and workplace teams

* **Quarterly reviews** aligned to real estate and planning cycles

Establishing a consistent rhythm helps normalize occupancy data as part of routine decision-making.

### Stakeholder Consumption

Occupancy analytics are typically consumed by multiple stakeholders, including:

* IT and operations teams monitoring system health

* Facilities teams managing space usage

* Real estate and workplace strategy teams planning future needs

* Business leaders evaluating workplace effectiveness

Day 2 operations should ensure that:

* Reports are aligned to stakeholder needs

* Metrics are clearly defined and consistently interpreted

* Occupancy data is presented in a way that supports decision-making, not just observation

### Delivery Models for Reports and Analytics

Occupancy insights may be delivered through multiple mechanisms, such as:

* Native dashboards and reports within Cisco Spaces

* Scheduled exports for offline analysis

* Integration with external analytics or business intelligence platforms via APIs

Regardless of delivery model, operational teams should ensure that:

* Reports are generated reliably and on schedule

* Data sources remain consistent over time

* Changes to reporting logic are communicated to stakeholders

### Operational Considerations

As part of Day 2 operations, teams should periodically validate that:

* Reports continue to reflect current location structures and use cases

* Metrics remain relevant as business needs evolve

* Stakeholders understand how to interpret occupancy data correctly

Reporting should evolve over time, but changes should be intentional and well-governed to preserve trust in the data.

*** ** * ** ***

## ALERTING \& THRESHOLDS

Alerting enables operational teams to move from passive monitoring to **proactive management** of occupancy outcomes. In Day 2 operations, alerts help surface conditions that require attention, investigation, or action before they impact decision-making or downstream systems.

This section defines how alerting and thresholds should be approached conceptually for occupancy in Cisco Spaces, independent of any specific implementation method.

### Purpose of Alerting in Day 2 Operations

The purpose of alerting is to:

* Highlight conditions that deviate from expected behavior

* Reduce reliance on manual dashboard reviews

* Enable timely response to issues affecting data quality or availability

* Protect the integrity of occupancy insights used by stakeholders

Effective alerting focuses on **exceptions**, not normal operational behavior.

### Types of Alerting Scenarios

Alerting for occupancy outcomes typically falls into several categories.

#### Data Availability and Continuity

Alerts may be triggered when:

* Occupancy data stops reporting for one or more locations

* Data becomes stale or delayed beyond acceptable thresholds

* Coverage gaps appear in the location hierarchy

These alerts help ensure continuity of reporting and analytics.

#### Data Quality and Anomalies

Alerts can also surface unexpected behavior, such as:

* Sudden spikes or drops in occupancy

* Occupancy patterns that contradict historical trends

* Inconsistent reporting between related locations (e.g., floor vs. room)

These signals often require investigation rather than immediate remediation.

#### Application and Delivery Issues

Alerts may indicate:

* Unavailability of occupancy dashboards or reports

* Failures in scheduled report generation

* Disruptions in data delivery to external systems

These alerts help protect downstream consumers of occupancy data.

#### Business and Operational Thresholds

In some cases, alerts are tied directly to business conditions, such as:

* Density thresholds being exceeded

* Sustained underutilization or overutilization

* Conditions relevant to safety, compliance, or experience objectives

These alerts may be consumed by non-IT stakeholders.Defining Meaningful Thresholds

### Defining Meaningful Thresholds

Thresholds should be defined carefully to avoid alert fatigue. Effective thresholds:

* Are based on historical baselines and expected patterns

* Vary by location type or hierarchy level

* Distinguish between transient anomalies and sustained conditions

Thresholds may evolve over time as occupancy patterns change.

### Alert Sources and Mechanisms

Alerts related to occupancy may originate from multiple sources, including:

* Visual indicators or notifications within Cisco Spaces

* Programmatic signals derived from Firehose API data

* External systems that consume occupancy data and apply their own logic

Regardless of source, alerts should be:

* Actionable

* Clearly understood by the receiving team

* Mapped to defined response processes

### Response and Escalation

Alerting must be paired with clear response expectations. Day 2 operations should define:

* Who receives specific types of alerts

* What initial actions are expected

* When and how issues are escalated

Not all alerts require immediate action, but all alerts should have a **defined owner**.

### Review and Tuning

Alerting strategies should be reviewed periodically to ensure they remain effective. Reviews should consider:

* False positives and alert fatigue

* Missed conditions that should have triggered alerts

* Changes in occupancy patterns or business requirements

Alerting is not static; it should mature alongside the occupancy deployment.

### Example Alerting Implementations

The following examples illustrate common ways organizations implement alerting for occupancy outcomes. These are examples, not requirements.

#### Example 1: Alerts Within Cisco Spaces

**Where**

* Cisco Spaces dashboard and monitoring views

**What**

* Visual indicators of anomalies

* Status of locations, apps, and data health

* Immediate operational awareness

**Best For**

* Human-in-the-loop operations

* Daily or weekly operational reviews

* First-line detection

These alerts typically require manual review rather than automated notification.

#### Example 2: Alerts via Firehose API and External Monitoring

**Where**

* Third-party monitoring or analytics platforms

  (e.g., Splunk, Elastic, Datadog, custom BI)

**What**

* Missing or delayed occupancy events

* Sustained threshold violations

* Data volume or pattern anomalies

**Best For**

* Automated alerting

* Integration with ITSM workflows

* Large or distributed deployments

In this model, thresholds are defined *outside* Cisco Spaces, using Firehose data as the signal source.

#### Example 3: Hybrid Alerting Models

**Where**

* Cisco Spaces for visibility

* External systems for alerting and escalation

**What**

* Cisco Spaces confirms the issue visually

* External systems generate alerts and tickets

**Best For**

* Enterprises with established NOC or SOC processes

### Connector Health and Performance Monitoring

Connector health is a critical component of alerting for occupancy outcomes, particularly when data is consumed by external systems. Even when Cisco Spaces is operating normally, connector degradation can prevent occupancy insights from reaching downstream consumers.

#### **Common Connector Health Signals**

* Connector availability (up/down)

* Message or event delivery rate

* Processing latency

* Resource utilization (CPU, memory)

* Errors and service issues

#### **Alerting Use Cases**

* Connector becomes unavailable

* Message rate drops below expected baseline

* Sustained resource saturation

* Services impacted on the connector or errors present

These alerts are typically implemented in:

* The Cisco Spaces connector monitoring interface (where available)

* External monitoring platforms observing connector behavior

* Container or platform-level monitoring tools

Connector health alerts should be treated as **delivery-impacting events**, even if occupancy data generation appears healthy within Cisco Spaces.

*** ** * ** ***

## TROUBLESHOOTING

Despite well-designed monitoring and alerting, Day 2 operations will occasionally encounter issues that affect occupancy outcomes. Troubleshooting focuses on **identifying root causes**, validating assumptions, and applying corrective actions to restore confidence in occupancy data.

This section outlines common troubleshooting scenarios and the types of actions typically taken to resolve them.

### Troubleshooting Approach

Effective troubleshooting of occupancy outcomes follows a consistent approach:

1. **Identify the symptom** (what appears wrong)

2. **Scope the impact** (which locations, apps, or consumers are affected)

3. **Validate data flow and configuration**

4. **Apply targeted corrective actions**

5. **Monitor for resolution and stability**

This approach applies regardless of whether issues are detected via dashboards, alerts, or external systems consuming occupancy data.

### Common Symptoms and Investigation Areas

#### Missing or Stale Occupancy Data

##### **Symptoms**

* Locations show no occupancy data

* Reports contain gaps or missing periods

* Firehose streams stop delivering expected events

##### **Investigation Areas**

* Platform and application health

* Data source connectivity

* Location hierarchy and associations

* Recent configuration or environmental changes

#### Unexpected Occupancy Spikes or Drops

##### **Symptoms**

* Sudden increases or decreases in occupancy

* Patterns that do not align with historical baselines

* Inconsistent counts across related locations

##### **Investigation Areas**

* Changes in user behavior or schedules

* Temporary events or anomalies

* Data source behavior and aggregation

* Filtering or inclusion logic

#### Inflated or Skewed Occupancy Counts

##### **Symptoms**

* Occupancy consistently higher than expected

* Guest or non-business traffic influencing metrics

* Discrepancies between Wi-Fi-based and sensor-based data

##### **Investigation Areas**

* Scope of data sources contributing to occupancy

* Inclusion or exclusion criteria (e.g., SSIDs or device types)

* Alignment between occupancy use case and data sources

##### **Corrective Actions**

* Refine occupancy data scope to align with business-relevant traffic

* Adjust inclusion or exclusion criteria for data sources

* Validate changes through trend comparison and monitoring

This is a common scenario where **SSID filtering** or equivalent scoping mechanisms may be applied to improve data relevance.

#### Inconsistent Room or Zone-Level Occupancy

##### **Symptoms**

* Rooms appear occupied when they are not

* Adjacent spaces show conflicting occupancy patterns

* Room-level insights do not match expectations

##### **Investigation Areas**

* Map accuracy and spatial boundaries

* Device or sensor placement and association

* Aggregation logic between rooms, zones, and floors

#### Downstream Consumption Issues

##### **Symptoms**

* External systems report missing or delayed occupancy data

* Discrepancies between Cisco Spaces dashboards and external analytics

* Alerting failures in integrated systems

##### **Investigation Areas**

* Firehose API stream status

* Event volume and filtering logic

* Downstream processing or ingestion pipelines

##### **Corrective Actions**

* Validate Firehose stream configuration and continuity

* Refine filters to ensure relevant events are delivered

* Align expectations between Cisco Spaces data and downstream consumers

### Validation After Remediation

After corrective actions are applied, operational teams should:

* Monitor affected locations for stability over time

* Compare post-change trends to historical baselines

* Confirm resolution with impacted stakeholders

* Document findings and corrective actions

This helps prevent recurrence and improves future troubleshooting efficiency.

### When to Escalate

Issues should be escalated when:

* Symptoms persist after reasonable corrective actions

* Multiple locations or outcomes are impacted

* Issues affect safety, compliance, or business-critical decisions

* Root cause is unclear or systemic

Clear escalation paths help minimize impact and recovery time.

### Example Troubleshooting Entry Points

#### Example 1: Investigating in Cisco Spaces

**Go Here When**

* Dashboards look wrong

* Locations show missing data

* Occupancy patterns look suspicious

**Where**

* Cisco Spaces monitoring views

* Location-level dashboards

* App-level health indicators

**What You're Looking For**

* Gaps in reporting

* Location-specific anomalies

* App availability issues

#### Example 2: Investigating via Firehose Data

**Go Here When**

* External systems report issues

* Dashboards and downstream systems disagree

* You need event-level visibility

**Where**

* Firehose event streams

* External log or analytics tools

**What You're Looking For**

* Missing or delayed events

* Unexpected event volumes

* Filtering or ingestion errors

#### Example 3: Investigating Environmental or Configuration Changes

**Go Here When**

* Issues start after a known change

* Only specific locations are affected

**Where**

* Change records

* Location hierarchy and map configurations

* Device associations

### Connector-Related Troubleshooting Scenarios

#### Symptoms

* Occupancy dashboards appear normal, but external systems receive no data

* Delayed or sporadic occupancy events downstream

* Inconsistent data delivery across connectors

#### Investigation Areas

* Connector availability status

* Message throughput compared to baseline

* CPU and memory utilization

* Errors or backpressure indicators

* Recent configuration or scaling changes

#### Corrective Actions

* Restart or scale connector resources (where applicable)

* Adjust throughput or batching parameters

* Investigate downstream ingestion bottlenecks

* Coordinate with platform or infrastructure teams if resource constraints persist

Connector health issues should be resolved **before** deeper data-level troubleshooting is attempted.

Occupancy outcomes depend on multiple operational layers: data generation, platform processing, connector delivery, and downstream consumption. Issues at any layer can impact outcomes and should be monitored and troubleshot accordingly.

*** ** * ** ***

## MAINTENANCE \& DEVICE MANAGEMENT

Long-term success with occupancy outcomes in Cisco Spaces depends on **intentional maintenance and lifecycle management**. While monitoring and troubleshooting address immediate issues, maintenance activities help prevent degradation over time and ensure that occupancy insights continue to reflect real-world conditions.

This section outlines the key maintenance considerations for sustaining occupancy outcomes throughout the lifecycle of the deployment.

### Maintenance Objectives

The objectives of Day 2 maintenance activities are to:

* Preserve accuracy and consistency of occupancy data

* Ensure continued reliability of data sources and delivery mechanisms

* Align occupancy insights with evolving business and physical environments

* Minimize operational risk through proactive management

Maintenance should be planned and repeatable, rather than ad hoc.

### Device and Sensor Lifecycle Considerations

Occupancy outcomes may depend on a variety of devices, sensors, or data sources. Day 2 operations should account for:

* Device health and operational status

* Battery life and replacement cycles (where applicable)

* Firmware or software updates

* Replacement or decommissioning of aging hardware

Changes at the device level should trigger validation of occupancy data to confirm continued accuracy.

### Connector and Integration Lifecycle

For deployments that integrate with external systems, connectors play a critical role in delivering occupancy data. Lifecycle considerations include:

* Connector version upgrades

* Scaling or performance adjustments

* Compatibility with downstream systems

* Monitoring resource utilization over time

Connector updates or changes should be coordinated and validated to avoid disruptions in data delivery.

### Platform and Application Updates

Cisco Spaces platform and application updates may introduce:

* New capabilities

* Performance improvements

* Behavioral changes affecting data or reporting

Operational teams should:

* Stay informed about platform updates

* Validate occupancy outcomes after significant changes

* Communicate changes that may affect stakeholders or integrations

### Environmental and Organizational Changes

Occupancy deployments are influenced by changes beyond technology, including:

* Office renovations or space reconfiguration

* Changes in workplace policies or schedules

* Organizational growth, consolidation, or relocation

Day 2 operations should include processes to:

* Revalidate location hierarchies and maps

* Adjust reporting and analytics assumptions

* Revisit thresholds and alerting logic

### Periodic Validation and Review

In addition to continuous monitoring, organizations should perform periodic reviews to:

* Reconfirm alignment between physical spaces and digital representations

* Validate that occupancy insights remain meaningful and trusted

* Identify opportunities for optimization or improvement

These reviews often align with quarterly or semi-annual planning cycles.

### Documentation and Knowledge Management

Sustaining occupancy outcomes over time requires clear documentation, including:

* Configuration decisions and assumptions

* Known limitations or caveats

* Historical issues and resolutions

Maintaining this institutional knowledge helps reduce risk during personnel or organizational changes.

*** ** * ** ***

## PRIVACY \& COMPLIANCE CONSIDERATIONS

Occupancy outcomes provide valuable insights into how spaces are used, but they must be managed in a way that **respects privacy, complies with regulations, and maintains stakeholder trust** . Day 2 operations play a key role in ensuring that occupancy data continues to be **protected, properly scoped, and used appropriately** throughout the lifecycle of the deployment.

The Cisco Spaces privacy model supports these objectives by defining how data is collected, processed, and protected in compliance with industry standards and customer governance requirements.

### Privacy Objectives

The primary privacy objectives for occupancy operations are to:

* Ensure occupancy data is used for **aggregate and business-level insights**, not individual tracking

* Maintain transparency with stakeholders regarding what data is collected and why

* Align data handling practices with organizational policies and legal or regulatory requirements

* Preserve trust as occupancy insights are shared with broader audiences or external systems

Privacy considerations are ongoing and should be revisited periodically, not just at deployment time.

### Cisco Spaces Privacy Model

Cisco Spaces follows a privacy model that distinguishes between the **data controller** (the customer) and the **data processor** (Cisco). Under this model:

* **Customers determine what data is collected and how it is used** --- Cisco processes the data on the customer's behalf.

* Cisco processes only **non-sensitive personal data** (e.g., network identifiers such as MAC addresses), and *does not collect highly sensitive personal data*, such as race, health data, or biometric data.

* Cisco does not intentionally collect personal data from minors.

Occupancy outcomes are typically delivered as **aggregated, non-PII insights**, not as individual tracking or identification. This supports both privacy compliance and broad adoption by business stakeholders.

### Data Access and Governance

Occupancy data access should be governed according to organizational roles and responsibilities, including:

* **Who can view occupancy dashboards and reports**

* **Who can export or consume data via APIs**

* **How access aligns to job functions and least-privilege principles**

Governance practices should ensure that data is only accessible to appropriate audiences and that sensitive access paths (e.g., API tokens) are managed securely.

### Data Usage and Limitations

Occupancy data in Cisco Spaces may be used for:

* Trend analysis and occupancy reporting

* Space utilization and planning

* Safety and density compliance

* Integration with other operational systems

However:

* The **purpose of data collection is defined by the customer**, per their governance and agreements with Cisco.

* Data retention and usage policies must be established based on **organizational needs and applicable laws**, not simply on technical defaults.

Operational teams should document usage policies and ensure stakeholders understand how occupancy data may and may not be used.

### Integration with External Systems

When occupancy data is sent to external systems via connectors or APIs (e.g., Firehose streams), additional privacy considerations arise:

* Downstream systems may combine occupancy data with other datasets, potentially increasing data sensitivity

* External systems must enforce their own privacy and access controls

* API consumers must adhere to customer governance and data protection policies

Day 2 operations should govern not only the data within Cisco Spaces, but **how it is consumed and protected downstream**.

### Retention and Lifecycle Management

Data retention for occupancy insights should align with:

* **Business analysis needs** (e.g., trend comparisons over months or years)

* **Regulatory requirements** (e.g., GDPR, industry-specific mandates)

* **Organizational data governance policies**

Operational teams should be able to articulate:

* How long occupancy data is retained in Cisco Spaces

* How long it persists in external analytics platforms

* What processes exist for **archiving or deletion** when appropriate

### Compliance, Logging, and Audit Readiness

Cisco Spaces adheres to recognized security and privacy best practices, including:

* Adoption of Cisco Secure Development Lifecycle (CSDL) processes

* Compliance with industry frameworks such as ISO 27001 and GDPR

* Use of logging, auditing, and privileged access controls to protect data and support incident response processes

Operational teams should be prepared to:

* Explain how occupancy data is collected and processed

* Demonstrate controls around access and usage

* Provide evidence of privacy governance during audits

### Communication and Transparency

Maintaining trust requires ongoing communication with stakeholders about:

* What data is collected and why

* How occupancy data is used to support business outcomes

* How privacy and compliance are enforced operationally

Clear messaging helps internal users and external visitors understand the boundary between **aggregate occupancy insights** and **individual tracking**, supporting both privacy and adoption.

*** ** * ** ***

## CONTINUOUS IMPROVEMENT \& FEEDBACK

Occupancy outcomes are not static. As organizations, workplaces, and usage patterns evolve, Day 2 operations must continuously adapt to ensure that occupancy insights remain **relevant, trusted, and actionable**.

This section describes how organizations can apply continuous improvement practices to maximize the long-term value of Cisco Spaces occupancy capabilities.

### Purpose of Continuous Improvement

The purpose of continuous improvement in Day 2 occupancy operations is to:

* Ensure occupancy insights continue to support business and workplace objectives

* Refine operational practices based on real-world usage

* Adapt to changes in space design, organizational behavior, and technology

* Strengthen trust and adoption across stakeholders

Continuous improvement ensures that occupancy outcomes mature over time rather than stagnate.

### Feedback Loops

Effective improvement depends on structured feedback loops between:

* IT and operations teams managing Cisco Spaces

* Facilities and real estate teams using occupancy insights

* Business stakeholders making planning or investment decisions

Feedback may include:

* Questions about data accuracy or interpretation

* Requests for new reports or views

* Observed mismatches between expected and actual space usage

* Lessons learned from operational issues or incidents

Capturing and acting on this feedback is a key Day 2 responsibility.

### Periodic Outcome Reviews

Organizations should establish periodic reviews focused on **outcomes**, not just system health. These reviews may include:

* Validation of key occupancy KPIs

* Assessment of whether insights are driving decisions

* Identification of underused or overused spaces

* Review of alerting effectiveness and noise levels

Reviews are often aligned with monthly, quarterly, or planning cycles.

### Refinement of Monitoring, Alerting, and Reporting

As occupancy patterns change, operational mechanisms should evolve accordingly:

* Monitoring views may be adjusted to highlight new priorities

* Alert thresholds may need recalibration

* Reports and analytics may be refined to better serve stakeholders

Refinement should be deliberate and documented to preserve consistency and trust.

### Incorporating Change and Innovation

Continuous improvement also includes evaluating:

* New Cisco Spaces capabilities

* New data sources or occupancy technologies

* Changes in workplace strategy (e.g., hybrid work models)

* Integration opportunities with other systems

Day 2 operations should provide a structured way to test, validate, and adopt changes without disrupting existing outcomes.Measuring Success Over Time

### Measuring Success Over Time

Success should be measured not only by system stability, but by:

* Adoption and sustained use of occupancy insights

* Stakeholder confidence in data-driven decisions

* Reduced reactive troubleshooting through proactive operations

* Improved alignment between physical space and business needs

These signals indicate that occupancy outcomes are delivering lasting value.

### Closing the Loop

Continuous improvement closes the Day 2 lifecycle by feeding lessons learned back into:

* Operational practices

* Documentation and runbooks

* Deployment assumptions for future rollouts

* Organizational decision-making

This creates a virtuous cycle where each iteration improves both **operations and outcomes**.

*** ** * ** ***

## APPENDIX

### Appendix A --- Day 2 Occupancy Operations Reference Matrix

This reference matrix provides a **quick lookup** for common Day 2 operational scenarios related to occupancy outcomes in Cisco Spaces. It helps operators quickly determine **where to investigate** , **which monitoring mechanism to use** , and **which section of this guide provides context**.

This appendix is intended as a **practical companion** to the conceptual guidance in Sections 1--7.

#### Monitoring, Alerting, and Troubleshooting Matrix

|                   **Scenario / Symptom**                    |   **Primary Area to Check**    |        **Monitoring Mechanism**        |          **What You're Validating**          | **Related Section** |
|-------------------------------------------------------------|--------------------------------|----------------------------------------|----------------------------------------------|---------------------|
| Occupancy dashboards show no data                           | Platform \& app health         | Cisco Spaces monitoring views          | Platform availability, app status            | Sections 3, 7       |
| Some locations missing occupancy                            | Location hierarchy \& coverage | Cisco Spaces dashboards                | Location reporting gaps                      | Sections 3, 4, 7    |
| Occupancy data appears stale or delayed                     | Data flow continuity           | Cisco Spaces + Firehose API            | Event freshness, processing delays           | Sections 3, 6, 7    |
| Sudden spike or drop in occupancy                           | Data quality \& trends         | Dashboards, reports, Firehose          | Pattern deviation from baseline              | Sections 5, 6, 7    |
| Occupancy higher than expected                              | Data scope \& filtering        | Dashboards, Firehose                   | Source inclusion (e.g., SSIDs, device types) | Sections 6, 7       |
| Guest or non-business traffic skewing data                  | Data relevance                 | Firehose API, reports                  | Traffic scope vs use case                    | Section 7           |
| Dashboards look correct but downstream systems show no data | Data delivery                  | Connector monitoring                   | Connector availability, message flow         | Sections 6, 7       |
| Intermittent data delivery to external systems              | Connector performance          | Connector monitoring                   | Message rate, retries, latency               | Sections 6, 7       |
| Firehose consumers see inconsistent events                  | Stream integrity               | Firehose API                           | Event volume, filtering logic                | Sections 3, 7       |
| Alerts triggered too frequently                             | Alert tuning                   | Alerting system (internal or external) | Threshold calibration                        | Section 6           |
| Expected alerts not triggering                              | Alert coverage                 | Firehose / monitoring tools            | Missing conditions or signals                | Section 6           |
| Room-level occupancy inconsistent                           | Spatial configuration          | Maps, device associations              | Map accuracy, device placement               | Sections 4, 7       |
| Issues start after physical changes                         | Change impact                  | Configuration \& hierarchy             | Drift after renovations or moves             | Sections 4, 7       |
| CPU or memory alerts on connectors                          | Connector health               | Connector monitoring tools             | Resource saturation                          | Sections 6, 7       |
| Reduced message rate from connectors                        | Delivery throughput            | Connector metrics                      | Backpressure or scaling limits               | Sections 6, 7       |

#### Monitoring Mechanisms at a Glance

|                **Mechanism**                |       **Primary Purpose**        |             **Typical Use**             |
|---------------------------------------------|----------------------------------|-----------------------------------------|
| Cisco Spaces dashboards \& monitoring views | Human-facing visibility          | Day-to-day operational awareness        |
| Occupancy reports \& analytics              | Trend analysis                   | Planning and optimization               |
| Firehose API                                | Programmatic data access         | External analytics and alerting         |
| Connector monitoring                        | Delivery reliability             | Availability and performance validation |
| External monitoring platforms               | Automated alerting \& escalation | Enterprise operations workflows         |

#### Operational Guidance

* Always validate **connector health** before assuming data generation issues.

* Use **historical trends** to contextualize anomalies before acting.

* Treat alerting as **signal-based**, not volume-based.

* Document corrective actions to improve future troubleshooting efficiency.

*** ** * ** ***

### Appendix B --- Day 2 Occupancy Operations Checklist

This checklist provides a **practical, repeatable reference** for teams responsible for ongoing occupancy operations in Cisco Spaces. It is intended to complement the guidance in Sections 1--10 and can be used as part of routine operations, audits, or handoffs.

#### Baseline Validation (Post--Go-Live or Major Change)

☐ Occupancy deployment validated using the deployment runbook

☐ Location hierarchy reflects current physical environment

☐ Floor maps, zones, and rooms are accurate and current

☐ Devices, sensors, and data sources are correctly associated

☐ Initial occupancy trends align with expectations

#### Monitoring Readiness

☐ Cisco Spaces monitoring views reviewed and understood

☐ Key dashboards available and accessible to operators

☐ Firehose API streams active (if used)

☐ External monitoring systems receiving data as expected

☐ Connector health and performance visible (availability, rate, resources)

#### KPI and Reporting Validation

☐ Operational KPIs defined and documented

☐ Reports aligned to stakeholder needs

☐ Reporting cadence established (weekly, monthly, quarterly)

☐ Historical trends reviewed for baseline understanding

☐ Stakeholders trained on report interpretation

#### Alerting and Thresholds

☐ Alerting responsibilities clearly defined

☐ Alert sources identified (Cisco Spaces, Firehose, connectors, external tools)

☐ Thresholds based on historical baselines

☐ Alert noise reviewed and tuned

☐ Escalation paths documented

#### Troubleshooting Preparedness

☐ Common symptoms and investigation paths documented

☐ Access to Cisco Spaces monitoring views verified

☐ Firehose data accessible for investigation (if applicable)

☐ Connector metrics available for diagnosis

☐ Troubleshooting outcomes documented for reuse

#### Configuration Integrity

☐ Routine configuration check cadence established

☐ Location hierarchy periodically reviewed

☐ Map and spatial metadata validated after changes

☐ Application settings reviewed for consistency

☐ Change management processes aligned to occupancy impacts

#### Maintenance and Lifecycle Management

☐ Device and sensor lifecycle tracked

☐ Firmware and software update process defined

☐ Connector versions and performance reviewed

☐ Platform updates reviewed for occupancy impact

☐ Periodic validation reviews scheduled

#### Privacy and Compliance

☐ Data access aligned to role-based governance

☐ Downstream data usage reviewed and approved

☐ Retention policies documented and enforced

☐ Privacy considerations communicated to stakeholders

☐ Audit and compliance readiness maintained

#### Continuous Improvement

☐ Feedback mechanisms in place with stakeholders

☐ Periodic outcome reviews conducted

☐ Monitoring, alerting, and reporting refined over time

☐ Lessons learned documented

☐ Opportunities for optimization identified and tracked

#### Ownership and Accountability

☐ Day 2 ownership clearly defined

☐ Backup ownership documented

☐ Operational documentation kept current

☐ Onboarding process for new operators established

*** ** * ** ***

### Appendix C --- Reference Links

This appendix provides authoritative reference material that complements the Day 2 Occupancy Operations Guide. These resources offer deeper technical, architectural, and governance details without duplicating content in this document.

#### Cisco Spaces Deployment and Operations

* **Cisco Spaces Occupancy Deployment Runbook (Cisco Validated)**

  Provides Day 0 / Day 1 guidance for designing, deploying, and validating occupancy outcomes.

  <https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-runbook-cisco-validated>

* **Cisco Spaces Configuration Guide --- Monitoring and Support**

  Describes platform monitoring, application health, and operational visibility within Cisco Spaces.

  <https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m_monitoring_and_support.html>

#### APIs, Integrations, and Data Access

* **Cisco Spaces Firehose API Documentation**

  Reference for programmatic access to occupancy and location events, including integration and downstream analytics use cases.

  <https://developer.cisco.com/docs/cisco-spaces-firehose/api/>

* **Cisco Spaces Developer Documentation**

  Broader API and integration reference for Cisco Spaces.

  <https://developer.cisco.com/docs/cisco-spaces/>

#### Privacy, Security, and Governance

* **Cisco Spaces Privacy White Paper**

  Describes Cisco's privacy model, data handling practices, and compliance posture for Cisco Spaces.

  <https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/dna-spaces/white-paper-c11-742079.html>

* **Cisco Trust Center**

  Central reference for Cisco security, privacy, and compliance information.

  <https://www.cisco.com/site/us/en/about/trust-center.html>

#### Cisco Validated and Solution References

* **Cisco Spaces Overview and Solution Resources**

  <https://www.cisco.com/go/spaces>

* **Cisco Validated Designs (CVDs)**

  <https://www.cisco.com/c/en/us/solutions/design-zone.html>

---
language: "en"
---
# Cisco Spaces Occupancy Runbook (Cisco Validated)

## OVERVIEW

This Occupancy runbook is meant to be the source of truth for all outcomes involving occupancy, regardless of technology. Rather than have multiple guides that are separated out by wireless, collab, or any other technologies, this guide is focused on customer outcomes.

The runbook begins with methods and means to get support for the features ranging from proof of value, free trial customers, paid customers, as well as onboarding activities.

Section 2 contains general requirements that are a set of standards that should be deployed in most situations. Items such as the Location Hierarchy and maps should be consistent not only for occupancy outcomes but for all outcomes.

Occupancy has varying levels of definition. Some customers are looking for just campus, building, or even floor level. Others may want room level outcomes. Some may want all levels. Section 3 is organized to get the specific requirements needed for any level of outcome the use case calls for.

Finalizing the runbook are two sections. First one contains caveats and tips which is meant to organize information throughout the runbook and beyond to provide recommendations and pitfalls to avoid. The last section contains the FAQ which will have commonly asked questions with answers provided.

### Support \& Onboarding Info

Please follow the link below to find out about the different ways to get support for Cisco Spaces.

[++Support Info Link++](https://activate.dnaspaces.io/hubfs/Assets/CiscoSpaces-SupportUpdate.pdf?__hstc=105720540.52aaa4a978f36be89855b002cb35bfc4.1729705805310.1729705805310.1729705805310.1&__hssc=105720540.1.1729705805310&__hsfp=3667649010)

*** ** * ** ***

## PREREQUISITES

### Spaces OS

*This Cisco Validated runbook is designed only as a follow on from the* [***Spaces OS Runbook***](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated)*.* It is the base installation for Cisco Spaces and is a prerequisite for this outcome. Please refer to the Spaces OS runbook for guidance on fulfilling this requirement.

*** ** * ** ***

## OCCUPANCY APPS \& OVERVIEW

### Overview

Cisco Spaces occupancy outcomes can provide real-time and accurate occupancy data. These outcomes utilize advanced technologies such as sensors, beacons, or Wi-Fi and provides accurate and reliable data.

Occupancy outcomes can be acquired at various levels of the location hierarchy. The hierarchy in Cisco Spaces is as follows:

* Organization

* Campus

* Building

* Floor

* Zone

* Room

* Desk

Details of these differences, requirements, and applications will be provided in the subsequent sections.

*** ** * ** ***

### App/Technology Dependency Matrix

|              |                                                                                                **Right Now**                                                                                                |                                                                                           **Location Analytics**                                                                                            |                                                                                            **Behavior Metrics**                                                                                             |                                                                                                                                                                                                    **Space Manager**                                                                                                                                                                                                    |                                                                                            **Space Utilization**                                                                                            |                                                                                                                                                                                                  **Detect \& Locate**                                                                                                                                                                                                   |
|  **Campus**  | ![3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png](https://runbooks.ciscospaces.io/__attachments/a_b2d176fb50012aec26e9f35a0d806ab4aab0960e1d55a292cf1214b1419e0df0/3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png?cb=fee818474221f17b23479ab834674d6c) | ![3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png](https://runbooks.ciscospaces.io/__attachments/a_b2d176fb50012aec26e9f35a0d806ab4aab0960e1d55a292cf1214b1419e0df0/3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png?cb=fee818474221f17b23479ab834674d6c) | ![3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png](https://runbooks.ciscospaces.io/__attachments/a_b2d176fb50012aec26e9f35a0d806ab4aab0960e1d55a292cf1214b1419e0df0/3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png?cb=fee818474221f17b23479ab834674d6c) |                                                                                                                                                                                                                                                                                                                                                                                                                         | ![3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png](https://runbooks.ciscospaces.io/__attachments/a_b2d176fb50012aec26e9f35a0d806ab4aab0960e1d55a292cf1214b1419e0df0/3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png?cb=fee818474221f17b23479ab834674d6c) |                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **Building** | ![3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png](https://runbooks.ciscospaces.io/__attachments/a_b2d176fb50012aec26e9f35a0d806ab4aab0960e1d55a292cf1214b1419e0df0/3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png?cb=fee818474221f17b23479ab834674d6c) | ![3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png](https://runbooks.ciscospaces.io/__attachments/a_b2d176fb50012aec26e9f35a0d806ab4aab0960e1d55a292cf1214b1419e0df0/3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png?cb=fee818474221f17b23479ab834674d6c) | ![3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png](https://runbooks.ciscospaces.io/__attachments/a_b2d176fb50012aec26e9f35a0d806ab4aab0960e1d55a292cf1214b1419e0df0/3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png?cb=fee818474221f17b23479ab834674d6c) |                                                                                                                                                                                                                                                                                                                                                                                                                         | ![3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png](https://runbooks.ciscospaces.io/__attachments/a_b2d176fb50012aec26e9f35a0d806ab4aab0960e1d55a292cf1214b1419e0df0/3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png?cb=fee818474221f17b23479ab834674d6c) |                                                                                                                                                                                                                                                                                                                                                                                                                         |
|  **Floor**   | ![3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png](https://runbooks.ciscospaces.io/__attachments/a_b2d176fb50012aec26e9f35a0d806ab4aab0960e1d55a292cf1214b1419e0df0/3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png?cb=fee818474221f17b23479ab834674d6c) | ![3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png](https://runbooks.ciscospaces.io/__attachments/a_b2d176fb50012aec26e9f35a0d806ab4aab0960e1d55a292cf1214b1419e0df0/3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png?cb=fee818474221f17b23479ab834674d6c) | ![3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png](https://runbooks.ciscospaces.io/__attachments/a_b2d176fb50012aec26e9f35a0d806ab4aab0960e1d55a292cf1214b1419e0df0/3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png?cb=fee818474221f17b23479ab834674d6c) |                                                                                                       ![3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png](https://runbooks.ciscospaces.io/__attachments/a_b2d176fb50012aec26e9f35a0d806ab4aab0960e1d55a292cf1214b1419e0df0/3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png?cb=fee818474221f17b23479ab834674d6c)                                                                                                       | ![3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png](https://runbooks.ciscospaces.io/__attachments/a_b2d176fb50012aec26e9f35a0d806ab4aab0960e1d55a292cf1214b1419e0df0/3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png?cb=fee818474221f17b23479ab834674d6c) | ![3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png](https://runbooks.ciscospaces.io/__attachments/a_b2d176fb50012aec26e9f35a0d806ab4aab0960e1d55a292cf1214b1419e0df0/3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png?cb=fee818474221f17b23479ab834674d6c) ![d3bd546a-09e0-49b3-81bd-b32108237588.png](https://runbooks.ciscospaces.io/__attachments/a_7f4d1e78c5b99f8e76d305b27e89b70e30418effda115a327236da4e1ba15a83/d3bd546a-09e0-49b3-81bd-b32108237588.png?cb=ca53fc516747d256f0ceca33876924fd) |
|   **Zone**   | ![3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png](https://runbooks.ciscospaces.io/__attachments/a_b2d176fb50012aec26e9f35a0d806ab4aab0960e1d55a292cf1214b1419e0df0/3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png?cb=fee818474221f17b23479ab834674d6c) | ![3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png](https://runbooks.ciscospaces.io/__attachments/a_b2d176fb50012aec26e9f35a0d806ab4aab0960e1d55a292cf1214b1419e0df0/3c289eb8-822b-487e-9b7e-3c7dc2fee86b.png?cb=fee818474221f17b23479ab834674d6c) |                                                                                                                                                                                                             |                                                                                                                                                                                                                                                                                                                                                                                                                         |                                                                                                                                                                                                             |                                                                                                                                                                                                                                                                                                                                                                                                                         |
|   **Room**   |                                                                                                                                                                                                             |                                                                                                                                                                                                             |                                                                                                                                                                                                             | ![57811a5e-fa5d-4571-bdd6-52de97c63266.png](https://runbooks.ciscospaces.io/__attachments/a_df7e1c0d73f6a8daaa9c7a9bd5a12db72a7ba9bb7d728de853c169a6c8d59085/57811a5e-fa5d-4571-bdd6-52de97c63266.png?cb=79950cd512f736d63dbf88f5d22c4017) ![d3bd546a-09e0-49b3-81bd-b32108237588.png](https://runbooks.ciscospaces.io/__attachments/a_7f4d1e78c5b99f8e76d305b27e89b70e30418effda115a327236da4e1ba15a83/d3bd546a-09e0-49b3-81bd-b32108237588.png?cb=ca53fc516747d256f0ceca33876924fd) | ![57811a5e-fa5d-4571-bdd6-52de97c63266.png](https://runbooks.ciscospaces.io/__attachments/a_df7e1c0d73f6a8daaa9c7a9bd5a12db72a7ba9bb7d728de853c169a6c8d59085/57811a5e-fa5d-4571-bdd6-52de97c63266.png?cb=79950cd512f736d63dbf88f5d22c4017) |                                                                                                                                                                                                                                                                                                                                                                                                                         |
|   **Desk**   |                                                                                                   **N/A**                                                                                                   |                                                                                                   **N/A**                                                                                                   |                                                                                                   **N/A**                                                                                                   |                                                                                                                                                                                                         **N/A**                                                                                                                                                                                                         |                                                                                                   **N/A**                                                                                                   |                                                                                                                                                                                                         **N/A**                                                                                                                                                                                                         |
|--------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

*** ** * ** ***

### Spaces Applications

#### Space Utilization

Empowering real estate and facilities teams with occupancy analytics across buildings, floors, and rooms. This app helps optimize space usage, reduce real estate costs, and plan for hybrid workplace demands.​​  
For more detailed information and/or configuration options please refer to our Configuration Guide for the [Space Utilization](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/space-utilization/b-space-utilizn-app.html) app.

##### Use Cases \& Value

* Wireless-Based Occupancy Trends (for Campuses, Buildings, Floors, and Zones)

  * Capture real-time occupancy data to build up historical utilization data across your portfolio, campuses, buildings, and floors.​

    * **Value Delivered :** Historical building occupancy for real estate and workplace decision making​.

    * **Useful For :** Facilities, Real Estate, and Workplace teams​​

* Room-level Utilization Trends

  * Combine Webex device, IoT Sensor telemetry, and calendar event data for room occupancy metrics, ghost booking rates, and more.

    * **Value Delivered :** Room booking and peak people count data combined for workplace decision making.

    * **Useful For :** Facilities, Real Estate, and Workplace teams​

Space Utilization does **not** support any vertical other than workspaces.

Exception 1: Administrative buildings non-workspace environments like retail, healthcare, or education.

Exception 2: Rooms which are vertical agnostic.

#### Right Now

Right Now provides a real time count of the number of people within a physical space \& how it compares with the historical average.  
For more detailed information and/or configuration options please refer to our Configuration Guide for the [Right Now](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m_rightnow.html) app.

##### **Use Cases \& Value**

* Active count of visitors​

  * Count of devices/people who were spotted in the location during the last 10 minutes​

* Total count of visitors

  * Count of visitors that were present during the past X hours (X being the threshold defined across individual verticals). For example this could be 3 hours for Retail and 8 Hours for Workspaces

* Density Trigger

  * It also allows users to set limits beyond which a trigger is activated. A feature that is becoming increasingly important in the post Covid world

* Associated device count

  * Right Now app currently counts only associated devices. Associated Devices: No. of devices associating with network.

* Protocol Compliance​​​​

  * Real time warning when the number of people at a location/sub-location exceed a previously defined threshold. Threshold could be absolute (number of people) or density (number of people per sq.ft.) ​

#### Behavior Metrics

The Behavior Metrics App enables vertical specific insights into the behavior of people within a physical space. Eg, Time spent by a shopper at a store, Time spent by employees at the workplace, frequency of visits of students to the library​.  
For more detailed information and/or configuration options please refer to our Configuration Guide for the [Behavior Metrics](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m_business-insights.html) app.

##### **Use Cases Value**

* Get vertical specific behavior insights​

  * Get insights into employee, student, customer or patient behavior, entry/exit times, time spent, visit frequency etc​

* Benchmark performance of business locations​

  * Compare and benchmark the performance of locations historically, against other locations within the org or with the category, industry which they operate​

* Understand people distribution density​​​

  * Understand trends in occupancy over different time periods and optimize space utilization based on the data​

* Correlate behavior data with other data sources​

  * Run correlations with other data sources such as revenue, POS data, CRM, weather, academic performance (universities), HR outcomes (workspaces), HVAC to optimize processes. Integrate presence data with HVAC data to save energy costs

#### Location Analytics

The Location Analytics app enables to create various reports related to the no. of visitors and visits. Create custom widgets by filtering data based on location, date range or SSIDs.  
For more detailed information and/or configuration options please refer to our Configuration Guide for the [Location Analytics](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m-location-analytics-app.html) app.

##### **Use Cases Value**

* Create custom reports for specific business needs​

  * Dive deeper into the data to get a granular understanding of peoples behavior. Get insights for specific locations or time periods.​

    * **Value Delivered**: Improved decision making​

    * **Useful to**: Operations, HR, Marketing teams

* Compare peoples behavior across locations​

  * Measure behavior of employees, customers, guests or students across different offices, campuses floors​

    * **Value Delivered**: Improved decision making​

    * **Useful to**: IT teams, Operations, HR​

* View visitor count and visit patterns

  * Measure customer loyalty, student or employee engagement by understanding patterns of behavior new vs repeat visitors. Target these segments with specific actions.​

    * **Value Delivered**: Improved retention loyalty​

    * **Useful to**: HR and Admin teams, Sales Marketing.​

* Understand average dwell time​

  * Measure the impact of dwell time by correlating it with sales and revenue, employee attrition or student performance data. Make informed decisions based on this data.​

    * **Value Delivered**: Increased sales, Improved student or employee productivity​

    * **Useful to**: HR, Campus Faculty, Sales Marketing​

#### Space Manager

For more detailed information and/or configuration options please refer to our Configuration Guide for the [Space Manager](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/smart-workspaces/b-smart-workspaces-cg/space-manager.html) app.

##### Use Cases Value​​

Experience a comprehensive overview of the workplace within a single, real-time view of floor occupancy (and with 24-hour playback). In a captivating 3D virtual environment, visualize and discover how people and things come together in indoor spaces. Identify gaps in coverage, manage new and existing IoT devices, link Wireless Access Points and Webex devices to workspaces, and much more. ​

* Workplace Occupancy and Utilization​​​​

  * View real-time Floor and Room utilization​

  * 24-hour playback of occupancy heat map data​

  * Overlay WiFi occupancy Heat Maps on Rich Maps​

  * Real-time metrics (building, floor, room)​

    * **Value Delivered**: space optimization, facilities services and real estate management​

    * **Useful to**: Facilities, Real Estate and IT

* Room Occupancy Reports​​

  * Configure, view, and download Room Occupancy Reports for a floor or building.

  * Export standardized room occupancy data based on Cisco Space Digital Maps Pro to a CSV file for further analysis

  * Set date and time ranges to analyze specific or recurring reports

  * Filter room occupancy data by day of week, hour of day, room capacity, and optionally exclude empty rows with no people detected

  * The output CSV provides aggregated peak people count every 15, 30, or 60 minutes per room

  * Import into Excel, PowerBI, Tableau, or an analytics tool of choice to create custom graphs

    * **Value Delivered**: Build custom dashboards to visualize and analyze occupancy data by importing the CSV export into PowerBl, Tableau, etc., which allows users to make informed real estate and workplace decisions.

    * **Useful to**: Facilities, Real Estate and IT​

* Environmental Monitoring​

  * Real-time metrics (indoor air quality, TVOCs, CO2, temperature, humidity, ambient noise, and more)​

    * **Value Delivered**: Provides insights into comfort, safety, and sustainability metrics in the workplace​

    * **Useful to**: Facilities, Real Estate and IT​

* Manage Devices​

  * Associate Webex, Meraki and 3rd party IoT devices to Rich Map​​

  * Manage sensors Add, Edit or Remove devices on the Workspace Management page​​

  * Manage workspace metadata (e.g.: name, type, capacity)​

    * **Value Delivered**: Assign devices to workspaces and check their status with real-time information.​

    * **Useful to**: Facilities, Real Estate and IT​

* Visualize/Find Devices​

  * See device locations on the floorplan​​

  * Identify gaps in device coverage​​

  * Distinguish device types and data sources on Rich Maps​

    * **Value Delivered**: Visualization of data sources

    * **Useful to**: Facilities, Real Estate and IT​

*** ** * ** ***

### Hierarchy for Occupancy Overview

#### Campus Overview

Campus level occupancy details provides a very high level of observations based on how campuses are defined in the hierarchy. This could be based on geographic locations where buildings may be clustered in areas. It could also be based on separation of business entities with an organization.

Campus level occupancy data can be acquired using WiFi technology. Subsections under the Campus level in the Location Hierarchy will provide more granular occupancy outcomes.

#### Building Overview

Generally, buildings will be some individual structure that contains one or more floors in the hierarchy. This level of occupancy data is aggregated from all floors contained to a single building to illustrate the outcomes associated with it.

Building level occupancy data can be acquired using WiFi technology. Subsections under the Building level in the Location Hierarchy will provide more granular occupancy outcomes.

#### Floor Overview

Floor occupancy provides granular insights into how specific floors within a building are utilized, allowing for a more detailed level visibility than building occupancy. While building occupancy gives an overall view of how many people are present across the entire structure, floor occupancy focuses on individual floors, highlighting variations in usage between different areas. This enables more precise space optimization, resource allocation, and safety measures. It also allows businesses to understand patterns at a finer scale, such as which floors experience higher traffic, compared to the broader insights offered by building-wide data.

#### Zone Overview

Zone occupancy offers even more granular insights by focusing on specific areas or sections within a floor, providing a detailed understanding of how different zones are used. While floor occupancy looks at overall activity across an entire floor, zone occupancy pinpoints usage within designated areas like workspaces or corridors. This allows for targeted optimization of resources. Zone-level data helps identify high-traffic or underutilized spaces, enabling precise decisions on space planning and ensuring safety compliance in more confined areas compared to the broader analysis provided by floor or building occupancy.

##### Configuring Zones (Zone level occupancy only)

Please refer to our [Configuration Guide](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m-location-hierarchy.html#create-zones-for-floor-location) for detailed steps for creating Zones.

*** ** * ** ***

### Wired 802.11x Occupancy

Wired 802.1X occupancy extends Cisco Spaces occupancy outcomes to employees who connect through authenticated wired access ports. When wired and Wi-Fi identities use a consistent format, Cisco Spaces can correlate presence across both connection types and avoid counting the same person twice during a network transition.

Use this section to qualify a Catalyst wired deployment, onboard the switch through the Cisco Spaces Connector, enable wired counting, and validate combined wired and wireless occupancy.

#### Supported deployment

Use wired occupancy when all of the following conditions are met:

* The location has a significant number of employees who connect through wired docking stations.

* Cisco Catalyst 9300 or 9400 Series switches provide the wired access layer.

* IEEE 802.1X authentication is enabled globally and on every access port that should contribute to occupancy.

* Wired and wireless authentication return user identities in the same format.

* At least one Wi-Fi network at the test location is already onboarded to Cisco Spaces.

* A customer network administrator is available to configure the switch and support validation.

Desktop-only connections, Meraki switches, other Catalyst switch families, and authentication methods other than 802.1X are outside the supported scope of this workflow.
> **Important:** Begin with one switch and one floor. Expand the deployment only after the wired-only, Wi-Fi-only, and transition scenarios pass validation.

*** ** * ** ***

#### Prerequisites

Complete the [++Cisco Spaces OS Runbook++](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated) before beginning this procedure. The following foundation must already be available:

* A Cisco Spaces Connector is deployed and displays an **Active** status.

* The Connector can reach the management address of the target switch.

* TCP 830 is permitted for NETCONF and TCP 8014 is permitted for telemetry between the required components.

* The target building and floor exist in the Cisco Spaces Location Hierarchy.

* The building time zone is configured correctly.

* The wireless LAN controller and test access point are onboarded, mapped to the correct floor, and available for transition testing.

* An 802.1X-enabled test SSID and an 802.1X-enabled wired access port are available.

* The test user returns the same identity format on wired and wireless authentication.

Before implementation, record the test location, target switch, access port, test device, corporate SSID, expected user identity, and expected occupancy result.

*** ** * ** ***

#### Implementation

**1. Verify Connector readiness**

1. In Cisco Spaces, navigate to **Setup** \> **Wired Networks**.

2. Confirm that the Connector assigned to the target location displays an **Active** status.

3. Confirm that the Connector can reach the switch management IP.

4. Confirm that the required NETCONF and telemetry ports are permitted between the Connector and the switch.

Do not continue until the Connector is healthy and network reachability has been verified.

**2. Prepare the switch**

The customer network administrator completes this configuration on the target switch.

1. Enable `netconf-yang`.

2. Configure credentials with privilege level 15 by using the approved local or AAA method.

3. Allow SSH access from the Cisco Spaces Connector.

4. Enable 802.1X globally.

5. Enable 802.1X on every target wired access port.

> **Important:** A device connected through an access port without 802.1X does not contribute to wired occupancy.

**3. Install the IoT Wired Service**

1. In Cisco Spaces, navigate to **Setup** \> **Wired Networks** \> **View Connectors**.

2. Select the Connector assigned to the test location.

3. Add the **IoT Wired Service**.

4. Allow approximately 15 minutes for the service to download and start.

5. Confirm that the service container displays a **Running** status.

6. Confirm that the telemetry subscription is active.

**4a. Add the switch to Cisco Spaces**

1. From the same Connector, select the option to add a switch.

2. Enter the switch name and management IP.

3. Enter the NETCONF username and password.

4. Save the configuration.

5. Confirm that the switch displays an **Active** status and is manageable in Cisco Spaces.

**4b. Import multiple switches from a spreadsheet**

Use bulk import when multiple switches must be onboarded together, the deployment spans multiple floors or buildings, standardized credentials or configuration are available, or speed and consistency are important. Bulk import changes only the switch onboarding method; the Connector, switch preparation, and 802.1X requirements remain the same.

1. In Cisco Spaces, navigate to **Setup \> Wired Networks**.

2. In the **Add Switch** step, select **Add Switches**.

3. Select the Connector that will manage the switches.

4. Select **Import switches from spreadsheet**.

5. Download the spreadsheet template.

6. Add one row for each switch and complete the following fields:

* switchName

* IP Address

* Username

* Password

To map a switch to a specific floor during import, also complete Location Path (Optional). Otherwise, leave this field blank and map the switch after onboarding.

7. Upload the completed spreadsheet.

8. Review the configuration preview and validation results.

9. Correct any invalid entries in the spreadsheet and upload it again.

10. When all required entries are valid, proceed with the upload.

11. Confirm that each imported switch displays an **Active** status and is manageable in Cisco Spaces.

**5. Map the wired and wireless infrastructure**

1. Map the switch to the correct building and floor in the Location Hierarchy.

2. Confirm that the wireless LAN controller and test access point resolve to the same test floor.

3. Confirm that the building time zone is correct.

For detailed Location Hierarchy guidance, refer to the [++Cisco Spaces configuration guide++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m_hierarchy-location.html).

**6. Enable wired devices in Live Occupancy**

1. Open **Live Occupancy**.

2. Open **Settings**.

3. Enable **Include Wired Devices**.

4. Select the test location and confirm that the setting is applied.

Authenticated wired users can now contribute to occupancy for the mapped location.

*** ** * ** ***

#### Validation

Validate identity correlation and occupancy behavior before expanding the deployment.

**Confirm the wired connection**

1. Connect the test device to the 802.1X-enabled access port.

2. On the switch, run `show mac address-table` and confirm that the test device appears on the expected port.

3. Run `show dot1x interface <port>` and confirm that the device completed 802.1X authentication.

4. In Cisco Spaces, confirm that the device appears in **Setup \>\> Wired Network \>\> View Switches**.

5. In **Location Hierarchy**, confirm that the switch is found at the expected location (building or floor it was placed in).

**Validate combined wired and Wi-Fi occupancy**

Run each applicable scenario and record the actual result:  

|               Scenario               |                                          Expected result                                           |
|--------------------------------------|----------------------------------------------------------------------------------------------------|
| Wi-Fi only                           | The authenticated user is present once at the expected location.                                   |
| Wired only                           | The authenticated user is present once at the expected location.                                   |
| Wi-Fi to wired                       | The user remains present during the transition and the person count does not increase.             |
| Wired to Wi-Fi                       | The user remains present during the transition and the person count does not increase.             |
| Simultaneous Wi-Fi and wired         | The same user is counted once.                                                                     |
| Laptop on wired plus mobile on Wi-Fi | The result follows the configured identity and de-duplication policy without inflating occupancy.  |
| VPN enabled                          | VPN connectivity does not add another person to the occupancy result.                              |
| Corporate SSID to guest SSID         | The user leaves the authenticated occupancy population as expected for the configured SSID policy. |

Validation is successful when the person count remains stable, presence does not flap during connection changes, and the same authenticated identity is not counted twice.

After live validation passes, allow sufficient data to accumulate and confirm that wired and wireless activity appears at the intended campus, building, or floor level in **Space Utilization**.

*** ** * ** ***

#### Troubleshooting

**A wired user does not appear in occupancy**

1. Confirm that 802.1X is enabled globally on the switch.

2. Confirm that 802.1X is enabled on the specific access port.

3. Confirm successful authentication with `show dot1x interface <port>`.

4. Confirm that the device appears in `show mac address-table` on the expected port.

5. Confirm that the **IoT Wired Service** is installed and displays **Running**.

6. Confirm that the telemetry subscription is active.

7. Confirm that the switch displays **Active** in Cisco Spaces.

8. Confirm that the switch is mapped to the correct floor.

9. Confirm that **Include Wired Devices** is enabled in **Live Occupancy**.

**The count changes when a user moves between wired and Wi-Fi**

1. Compare the authenticated user identity returned by the wired and wireless networks.

2. Confirm that both networks return the identity in the same format.

3. Confirm that the switch, wireless LAN controller, and access point are mapped to the same physical location.

4. Repeat the transition test with one device and one user before testing multiple devices.

**Occupancy appears on the wrong day or location**

1. Confirm that the switch is mapped to the intended building and floor.

2. Confirm that the building time zone is correct.

3. Confirm that the wireless infrastructure used for validation is mapped to the same floor.

**The switch remains inactive**

1. Confirm management-IP reachability from the Connector.

2. Confirm SSH and NETCONF access from the Connector.

3. Confirm the NETCONF credentials and privilege level.

4. Confirm that `netconf-yang` is enabled.

5. Confirm that required firewall rules permit the Connector and switch to communicate.

*** ** * ** ***

### Room (Collaboration Occupancy)

#### Overview

Room-level occupancy outcomes in Cisco Spaces involve using sensors and collaboration devices, such as Webex, to monitor and visualize live meeting room occupancy. This includes detecting room presence and people count. Additionally, other data types can be acquired, such as environmental conditions like air quality, temperature, and humidity. The data collected related to room occupancy helps optimize room usage and enhance employee productivity.

#### Prerequisites

For a list of supported compatible devices please refer to our [Device Supportability Matrix](https://runbooks.ciscospaces.io/docs/cisco-spaces-device-compatibility-matrices).

##### *Verify hierarchy from Control Hub + Metadata*

* Webex Control Hub integration accurately organized into Locations \> Floors \> Workspaces \> Devices (see section 2 on Location Hierarchy for more details)

###### Metadata

|-------------------------------------------|----------------------------------------------------|-------------------------------------------------------------------------|
| **Platform level setting**                |                                                    |                                                                         |
| 1: Pro Maps Upload                        | Mandatory for room metric and for heat map feature | Dashboard level setting: **Setup** **Locations Maps** **Digital Maps**  |
| 2: Associating occupancy sensors to rooms | Mandatory for room metrics                         | **Space Manager** **Space Management**                                  |
| 3: Defining default device for each room  | Mandatory if rooms have 1 sensor                   | **Space Manager** **Space Management** click on an individual workplace |

##### *Digital Maps: Room Naming + Collab Device Placement*

As mentioned in ++*Section 2*++ ++for creating Digital Maps++ verify that the follow steps have been completed:

1. When CAD files are finished processing (see section on Digital Map and CAD File Upload), edit room names/labels in the Digital Map Editor (under *Setup Locations Maps Digital Maps Review*)​

2. In *Space Manager Space Management*, assigning Webex devices to Rich Map workspaces​

3. Using the Space Experience app to deploy digital kiosk app to a Webex Board or other kiosk display using a browser-based kiosk app

**Optional onboarding task**: Generate a kiosk app Token URL (not recommended, but sometimes necessary for digital kiosk displays that do not have the proper browser local storage)​

#### Optimizing People Count in Meeting Rooms

Since room-level occupancy relies on the camera sensors in the board, desk, and room devices, sometimes background people may be picked up within the camera frame even if they are not in the room. This may be due to glass walls and windows that may provide complete viewing of the spaces outside of the meeting room. To mitigate occupancy inaccuracies due to this, meeting zones may be configured to define the part of the room where people count will be applied to.  
Detailed information about modifying [device compatibility and configurations](https://help.webex.com/en-us/article/nc6od6r/Utilization-and-environmental-metrics-for-workspaces) and [meeting zones](https://help.webex.com/en-us/article/owp8b5/Set-up-a-meeting-zone-on-Board,-Desk,-and-Room-devices) on devices or in Webex Control Hub.

*** ** * ** ***

### Room (Portal Beam Occupancy)

#### Overview

Cisco Spaces' solution partner, [Kontakt.io](http://kontakt.io/)s device Portal Beam is a multi sensor BLE device that provides information about room occupancy (people count) and environmental data like temperature and humidity that is leveraged into Cisco Spaces outcome applications by leveraging the IOT Sensor Connect architecture (aka Indoor IOT Services). Portal Beams leverage the existing Cisco wireless access point infrastructure and Cisco Spaces plugin framework to provide additional visibility into occupancy within workspaces without needing any additional gateways or significant additional investments. With Cisco Spaces + Portal Beam joint solution, specific outcomes within Cisco Spaces can be met with a plug and play architecture that can be setup within minutes of physically installing the beam devices.  
![image-20241116-210044.png](https://runbooks.ciscospaces.io/__attachments/a_85b8ffb37f5aabe8374141e24af443b5c95ff7bb905de1f0e6ee5026daa252a0/image-20241116-210044.png?cb=61cc173125fdf38e1805608bb95c43e6)

*** ** * ** ***

#### Prerequisites

##### **Infrastructure Requirements:**

###### For Catalyst based customers:

* *Cisco Catalyst 9800 WLC* : with IOS-XE Versions of 17.12.4 or above (In 17.12 train) or 17.15.1 or above (in 17.15 train). While BLE is technically supported in older and other releases, due to key BLE related bug fixes that are present in the above specific version, only these specific versions are going to be supported.

* *AP Models* : C9120 or above, with the latest Spaces BLE Gateway installed (aka BLE IOX App) While BLE is technically supported in some other AP models and may work without the IOX App installed, due to performance requirements, the mentioned combination is going to be supported.

* *Spaces Connector* : Spaces Connector version 3.1 or above, with the latest released docker versions. Spaces Connector version 2.3 is no longer supported. Refer to the Spaces OS runbook for the correct guidance for the sizing of the connector.

###### For Meraki based customers:

This combination has not undergone validation. We recommend engaging with the Spaces product management teams to explore this use case further.

* Cisco Application Requirements:

  * Maps : Cisco Spaces Digital Map (aka CAD based Rich Map) is required. Refer to the best practices for the Rich Map for making sure the map is meeting basic requirements such as names, layers, etc.

  * APs : Access Points need to be placed on the network map either using Catalyst Center, Prime Infrastructure or using Cisco Spaces Any Locate feature. Either way, the APs need to be correctly positioned on the floor plan.

  * Licensing : Cisco Spaces Act or Unlimited License is required.

  * (Optional) Cisco Webex Pro Boards : One of the outcome applications consuming the room telemetry data will be the Kiosk experience. If needing to deploy the kiosk using Portal Beam data, Cisco Webex Pro boards will also be needed. Refer to the right runbook for those details.

##### **Kontakt Requirements:**

* Access to physical Portal Beam devices

* Depending on how the devices were purchased, correct Kontakt licensing or support SKUs. If purchased with Cisco Solutions Plus, then appropriate SKUs should be added already. Please work with the sales teams to make sure correct licensing is in place.

*** ** * ** ***

#### Supported and Unsupported Functionality

##### **Supported Functionality:**

In the currently available Cisco Spaces + Portal Beam architecture, the following functionality and outcomes are supported:

++*For Environmental Sensor Data (Temperature and Relative Humidity):*++  

|             App or Feature              |  Frequency of Data   |               Data                |
|-----------------------------------------|----------------------|-----------------------------------|
| Space Manager App *Room occupancy view* | Real time            | Temperature and Relative Humidity |
| IOT Services                            | Real time            | Temperature and Relative Humidity |
| Environmental Analytics                 | Real time historical | Temperature and Relative Humidity |
| Meta API (Firehose API)                 | Real time            | Temperature and Relative Humidity |

++*For People Count (Room Occupancy) Data:*++  

|                App or Feature                 | Frequency of Data |                                 Outcome                                  |
|-----------------------------------------------|-------------------|--------------------------------------------------------------------------|
| Kiosk                                         | Real time         | People count on rich map                                                 |
| Space Manager App *Room occupancy view*       | Real time         | Binary room occupancy (i.e., occupied or unoccupied)                     |
| Space Manager App *Room occupancy report*     | Historical        | (IN BETA) People count and binary room occupancy as an exportable report |
| Space Utilization App *Room Occupancy Charts* |                   |                                                                          |

++*Supported Verticals*++ ++:++Workspaces.

While other verticals may have similar use case and room types etc. where the solution may work just as well, Cisco has validated this solution only in workspaces verticals and is the only vertical type supported for now.

++*Supported Space Types*++ ++:++ Meeting Rooms, Conference Rooms, Small Audio Privacy Rooms.

* Room occupancy:

  * Single Beam in a room 10 people per Beam for rooms = 10 people

  * Multiple Beams in a room 8 people per Beam for rooms 10 people *(\*not available today, roadmap feature)*

While other room types may have similar use case where the solution may work just as well, Cisco has validated this solution only with meeting room or small closed rooms and are the only room types where this solution is supported. Large conference rooms or rooms requiring multiple portal beams in a single room are currently not supported.  
![Screenshot 2024-11-16 at 1.38.49 PM.png](https://runbooks.ciscospaces.io/__attachments/a_d1fef717f19c094153a759e14327f34a582baacfcf222b7f7b12ac561f781620/Screenshot%202024-11-16%20at%201.38.49%E2%80%AFPM.png?cb=1b8fa6b4436b84cbb44c88dfc2b621ce)
Room occupancy in kiosk

![image-20241116-213919.png](https://runbooks.ciscospaces.io/__attachments/a_1aaa70a0f686196703689a3c8be0b4be2a7505c9c8d736bb27f6c857565668c9/image-20241116-213919.png?cb=92f789222588f0aed501c1a669b26b4d)
Room occupancy in Space Manager

##### **Unsupported Functionality:**

The following functionalities and outcomes are currently not supported by the Cisco Spaces + Portal Beam solution. While there is potential for these features to be introduced in the future, there is no official confirmation or guarantee at this time, and they are currently unavailable to customers.

If needed, please work directly with Cisco Spaces product team to discuss further.

++*For People Count (Room Occupancy) Data:*++  

|-------------------------|-------------------|---------------------------------|
| App or Feature          | Frequency of Data | Outcome                         |
| Meta API (Firehose API) | Real time         | People Count and Room occupancy |
| Smart Rooms             | Real time         | HVAC control based on occupancy |
| Smart Desks             | Real time         | Desk Occupancy and monitoring   |

In addition, while the Portal Beam device may support other functionality, the current joint solution is limited and does not support:

* Desk Occupancy from Portal Beam in Spaces

* IR based location in Spaces

* Room Occupancy with multiple Portal Beams in a single room in Spaces

* Integration with Portal Lights as a 3rd party gateway (Not a supported architecture)

#### Reference Architecture

![Screenshot 2024-11-16 at 1.44.07 PM.png](https://runbooks.ciscospaces.io/__attachments/a_7daee284e60dc22b3dfda1456d5efbde46490cdcf798b7fb0a511e04a782ac05/Screenshot%202024-11-16%20at%201.44.07%E2%80%AFPM.png?cb=cfab5ac2b156e301e584b940ced7e5ae)

#### Deployment Workflow

This is the workflow for deploying Cisco Spaces + Portal Beam joint solution.

**In Cisco Spaces:**

**Step 1 - Claim Kontakt Order ID in Spaces IOT Services**

This can be done before or after the devices have been delivered. Generally, the order ID comes with the devices and the devices can be claimed even before they are powered on.

1. Log into the Spaces account

2. From the left-menu, go to **IoT Services** **Device Management**.

3. Select **Onboard Devices** **Floor Beacons** **Next**.

4. Enter the [http://Kontakt.io](http://kontakt.io/) **Order ID** (it's case sensitive) and select **Add to Inventory**.

5. To verify the devices were successfully claimed, from Device Management, go the **Devices** tab, **Floor Beacons** **Claimed Devices** verify the claimed devices are listed.

   Portal Beam devices are identified as **Floor Beacons**.

![16561183342236](https://runbooks.ciscospaces.io/__attachments/a_50bad752f52b0c3ee95f9345c0535a166379c845f96495e5d86034063e0ee010/16561183342236?cb=f449f306ba9441280cebe6e58e5965f6)

**Step 2 - Activate Kontakt Portal Beam Plugin**

This step enables the plugin within the Spaces dashboard, allowing data from [Kontakt.io](http://kontakt.io/) to be received back into Spaces.

1. Log in to the Spaces account you want to enable the [Kontakt.io](http://kontakt.io/) Plugin.

2. Go to **Setup \> Plugins**

   ![image-20260319-145856.png](https://runbooks.ciscospaces.io/__attachments/a_e7c6cb623fe7bd5b3a1bb29d94e4713d2de6f3efd4ac5efbbb6ac4530f27863f/image-20260319-145856.png?cb=51e71fd7a6ca8ab860883b6ef05e4862)
3. Find the [**Kontakt.io**](http://kontakt.io/)**Plugin for PortalBeam** and select**Activate.**

4. **Select the latest production version** of the plugin available, then click**Next.**

5. **Select the location(s)** to activate the plugin, then click **Next**.

6. Click **Accept Permissions**.

7. Review the summary page and click **Activate**.

**Step 3 - Activate Kontakt Device Management Plugin**

This step allows the use Kontkat's Kio Setup Manager mobile app to complete the setup of the Portal Beams. The plugin only applies to Portal Beams claimed within Cisco Spaces.

**Get Cisco Spaces Device Management Server API Key**

1. Log in to the Spaces account where the Portal Beams have been claimed.

2. Go to **IoT Services** **Device Management**.

![DM-API-Key-step1.png](https://runbooks.ciscospaces.io/__attachments/a_096cae3c209e805e91920f2d697e889ead24d80004290c6c686d127ae056310e/16561243669148?cb=38b2ffeae64c127967111afa04c1d667)

3. From the top menu, select **Devices** select the **Mac Address** of a device from the **Beacon Configuration section** , select **Advance Configuration** select **Confirm**.

![DM-API-Key-step2-advanced-confg.png](https://runbooks.ciscospaces.io/__attachments/a_1c0b65f261ed3d4ba106bb89c0d8b895ee36b18421e0e3ca37f2fb257e4dc02b/16561203493660?cb=2908bd48755cb535383d20cf49306b1e)

4. From the **Server API Key section** , select **Copy to clipboard**. This API Key is required in the next step.

![DM-API-Key-step4-get-api-key.png](https://runbooks.ciscospaces.io/__attachments/a_3faaf43f22d90b37295484fab36b50536f36291f0df2223f737db56fa6853c71/16561197387292?cb=13fd8579ee44e7647f0b718713b747a0)

**Activate Kontakt Device Management plugin**

1. From a web browser, go to the below URL specific to the Cisco Spaces account region. If not already signed in to Cisco Spaces, there will be a prompt to sign in.

   **United States region:** <https://plugin-app.cloud.us.kontakt.io/device-management/>

   **Europe region:** <https://plugin-app.cloud.uk.kontakt.io/device-management/>
2. From the **Add Devices** menu, select **Device Federation**.

3. Paste the **Cisco Spaces Device Manager Server Key** into the below field.

![Cisco Spaces with Kontakt.io Device Federation setup](https://runbooks.ciscospaces.io/__attachments/a_fec1f8c8ab7f840a364b17e2c8c48126836e1b737cb99287d9f14a6207d5b531/16561212846620?cb=9b6521260e080a759cfc0cfed1a690c3)

4. To confirm the plugin activation, from the **Inventory** menu, select **Infrastructure** verify the Portal Beams are listed.

5. Be sure to bookmark the region's Device Management Plugin URL.

   Once the Portal Beams are mounted and setup, they can be viewed and managed in the settings from this plugin and can view the last thermal image captured and shared from the Kio Setup Manager mobile app.

*For Steps 4 and 5 - Cisco highly recommends using Kontakts official installer service to make sure devices are correctly installed and configured. Cisco will not be responsible for any incorrect data that may be generated due to that. Please work with a Kontakt representative to get additional details. Nonetheless, if customers still want to move forward on their own, these are the steps.*

**Step 4 - Mount Portal Beam**

Before beginning, review the Portal Beam [placement and coverage area guidelines](https://support.kontakt.io/hc/en-gb/articles/6800468551196#UUID-5f5bf05c-4519-782f-cfe4-74c11912c5a7) and [ceiling mount instructions](https://support.kontakt.io/hc/en-gb/articles/12525698772508#UUID-4ae33dc7-f4df-8239-33c5-2ac65c21afeb).

1. Write down the **Portal Beam's Unique ID and MAC address** printed on its underside. This is needed during the next step.

2. Turn on the Portal Beam from its underside, move its battery switch to the **ON** position.

3. Mount the Portal Beam to the ceiling.

**Step 5 - Setup and Verify Portal Beam Settings and Coverage**

Using Kontakt's Kio Setup Manager mobile app, capture the Portal Beam's real-time thermal image. This image is a heatmap of the objects detected within its field of view allowing verification of the people detected and set Exclusion Zones.

Exclusion Zones are user-defined areas within the Portal Beam's field of view that are ignored by the [http://Kontakt.io](http://kontakt.io/) Occupancy Engine. These zones can include non-human, stationary objects with high background temperatures, such as TVs, light fixtures, windows, or other electrical equipment. Additionally, a zone can be a specific area within a large room where occupancy detection is not required.

1. Download the **Kio Setup Manager** mobile app. If the app is already obtained, be sure to check for updates.

   To download the app, go to the [App Store](https://apps.apple.com/at/app/kontakt-io-administration-app/id1067320511) or [Google Play](https://play.google.com/store/apps/details?id=io.kontakt.app&hl=en_US&gl=US). Search for **Kio Setup Manager** .
   * Device compatibility: iPhone or iPad: iOS version 17 or later \| Android phone or tablet: version 8 or later

   * Device connectivity: Bluetooth enabled and an internet connection over Wi-Fi or cellular data

2. **Turn on** the Portal Beam. On the underside of the Portal Beam, move the **battery switch** to the **ON position.**

3. From your mobile device, open the **Kio Setup Manager** \> from the **Sign in Method,** tap **Cisco Spaces Account.**

   ![Screenshot 2026-05-11 at 9.21.42 PM.png](https://runbooks.ciscospaces.io/__attachments/a_48c085593838cb952da0d5d2601a2f06cd4c598276234c3cd5e1485d7b567f0d/Screenshot%202026-05-11%20at%209.21.42%E2%80%AFPM.png?cb=2a5702f41a704bfc4a79ccb3cd5297f4)
4. You're directed to Cisco Spaces sign in. Enter your**Cisco Spaces credentials** \> select the **account**.

5. From the bottom menu, tap **Devices**.

6. From the list of **Nearby Devices** , locate the Portal Beam by its **MAC address** or **Unique ID.**

7. Tap the **Portal Beam** to view its management menu options.

   (Optional) To verify the Portal Beam selected, tap Show Details \> tap Flash LED. From its front-side, a colored LED flashes briefly.
8. From the menu, tap **Install Device.** From **Choose location** \> tap the campus, building, floor, and room where the Portal Beam will be installed.

9. Tap **Next** and prepare to mount the Portal Beam.

   1. If it is the **first Portal Beam installed** in the room: provide the **installation height** \> tap **Next** and mount the beam.

      Once mounted, continue to the next step.

      ![Screenshot 2026-05-11 at 9.26.29 PM.png](/__attachments/a_39ad89b9b45320b25f5d68e5a18d77c76fe6b92865df1d520ca12b6c11658558/Screenshot%202026-05-11%20at%209.26.29%E2%80%AFPM.png?cb=9609a50d01accf5d0a30fa2c9f226c3c)
   2. it is an **additional Portal Beam being installed in the same location** the app automatically detects the existing beam assigned to the room \> tap **Next**.

      Prepare to mount the second Portal Beam at the same height as the existing beam and at the distance required between the two beams provided in the below screen --- 102. 72 in (8.9 ft, 2.7 m).  
      ![Screenshot 2026-05-11 at 9.30.19 PM.png](/__attachments/a_ccd35a4e7391d9aefdbb77ee7a5c3ed12882b97a36d44a0a909d56e22a349727/Screenshot%202026-05-11%20at%209.30.19%E2%80%AFPM.png?cb=d935f743158d1520239851258f5228bd)

      Tap **Next** . From the Mounting orientation illustration displayed, mount the second Portal Beam as detailed in the screen \> once mounted, tap **Next**.
10. From the top section of the captured image, tap the **cloud icon.**

    The thermal image is uploaded to the Portal Beam's Occupancy settings within the Device Management Plugin.
11. From the captured image, verify if any hot objects were detected.

    If there are any non-human, stationary hot objects detected or areas you want to exclude from occupancy detection, you can configure these as **Exclusion Zones (tap Add Exclusion Zone).** After configuring the Exclusion Zones, tap **Next** .

    It's recommended to set windows within the room as exclusion zones, especially when there is direct sunlight into the room.

    **Exclusion Zone examples:**

    The following Portal Beam thermal images show how Exclusion Zones can be set to exclude objects or areas from occupancy detection. Each exclusion zone is outlined in red.

    Hot objects: wall-mounted TV and window excluded from occupancy detection.

|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Captured thermal image ![Portal Beam thermal images hot objects detected](https://runbooks.ciscospaces.io/__attachments/a_ab8d791b0f7798766afc47eed641e07c2764a1126d8c59a3de2e7f6d12bd6f04/16561137984540?cb=872f18f1d2aee8890286072d0c24f924) | TV and window set to exclusion zones ![Portal Beam hot objects exclusion zones](https://runbooks.ciscospaces.io/__attachments/a_2648177cdf4dc7abac92a12089258e6499a36989f97fd295470253dbbdd5628e/16561138066332?cb=6b39f9f2f5d34f6fd7c9f564ea5b513f) |

Large room: two specific areas excluded from occupancy detection.  

|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Captured thermal image ![Portal Beam thermal image no objects detected](https://runbooks.ciscospaces.io/__attachments/a_fe4967b6fb3b2930edc6e63412deee166c8d81cd83ba66f791c964c48a763dd5/16561170488092?cb=9534fa42caad493f280078d0f490f95e) | Two areas set to exclusion zones ![Portal Beam two areas as exclusion zones](https://runbooks.ciscospaces.io/__attachments/a_2a073be60575a22fbb82991c17b39aa4390b03292726a49cec711db579b39cb6/16561153820444?cb=4adb795bfb4be03b10b800be1bb981a7) |

13. View the device note that will be saved in its profile --- you can add additional information \> tap Next.

14. Once complete, the app displays **Installation Success!** --- this is your confirmation the install is complete.

**Step 6 - Associate Portal Beam to the workspace (Room) in Space Manager Application**

This step results visually experiencing the Portal Beam's real-time room occupancy and environmental data from Spaces Digital Maps

1. From the **Cisco Spaces Home** page, navigate to the **Space Manager** app.

2. Go to**Manage Rooms** locate and select the **room** name (left most table column) where the Portal Beam is installed.

3. From the **Room Details** page, go to the **IoT sensors** section, select **Add Devices**.

4. From the **Service Type** , select **BLE**.

5. From the list, select the **Portal Beam** , select **Next** to associate the beam to the workspace.

**Step 7 - Add room occupancy capacity**

This step results in employee experience apps displaying this added metadata and occupancy data having a denominator for utilization percentage calculations.

1. From the **Cisco Spaces Home** page, navigate to the **Space Manager** app.

2. Go to **Manage Rooms** locate and select the **room** name (left most table column) from the list view.

3. On the **Room Details** page, locate and edit the **Capacity** field.

![Space Manager - Manage Rooms - Room Details - Capacity](https://runbooks.ciscospaces.io/__attachments/a_df0c1c1afc962bbfa6db80fe402cb9fb2aa8a5c09ba5c17e8a1712adae7136c4/Screenshot%202026-01-26%20at%2021.32.40.heic?cb=bb84bdabc76f0e35586e3f91681acffc)
Space Manager - Manage Rooms - Room Details

**Step 8 - Validate Portal Beam outcomes on Digital Maps**

As the final deployment step, we recommend validating the Portal Beam outcomes from the Digital Maps. Complete this at the room location where the Portal Beam is mounted and will require two people.

From the **Cisco Spaces home** page, navigate to the **Space Manager** app. Navigate to the correct floor and select the Room Occupancy option. All the rooms can be seen with the associated sensors and their real time  

|                                                                                                                                                                                                                                                            Validation steps (complete at the Portal Beam's room-level location)                                                                                                                                                                                                                                                            |                               Expected outcome                                |
|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------|
| 1. From **Digital Maps** , begin with the **room empty** ; ensure that occupancy for the room is **0**. 2. Have **one person enter the room** wait for up to **two minutes** for the **occupancy to change 1**. 3. Wait **15 seconds** , then have the **second person enter the room** wait for up of **two minutes** for the **occupancy to change to 2**. 4. Wait **15 seconds** have **both people exit the room** wait for up to **two minutes** for the **occupancy to change to 0**. 5. Validate the room environmental readings are accurate (e.g. temperature reading is not 0C). | Room occupancy counts are accurate. Sensor/temperature readings are accurate. |

**Step 8 - Enable Digital Kiosk Outcome**

Once the devices are correctly added and validated, customers can use the device data to feed into the Kiosk application. Refer to the Kiosk section within the relevant guides to understand the steps needed.

#### Data Flow and Data Security

![Screenshot 2024-11-16 at 2.37.15 PM.png](https://runbooks.ciscospaces.io/__attachments/a_b3214c4c5dc9091977b8d14ef6e7275450ab7c6a2dfb06f5174fb09e492ab5f4/Screenshot%202024-11-16%20at%202.37.15%E2%80%AFPM.png?cb=26f2fd394d522bac63068e6889b5611b)

Data Flow Diagram  
![Screenshot 2024-11-16 at 2.37.47 PM.png](https://runbooks.ciscospaces.io/__attachments/a_0b1135d24ca47c86849d8a551f8f7897fa55606080d088e8eb63a237bce82198/Screenshot%202024-11-16%20at%202.37.47%E2%80%AFPM.png?cb=29e345094f2e49cf3cdf0aa12d07bd12)
No image or PII data is ever leaving the device or sent to the cloud

#### Best Practices

For Cisco Spaces + Portal Beam solution, Cisco recommends the following best practices.

* Make sure all infrastructure release versions and AP deployment modes are used. For example, if older IOS-XE code or a connector with a lower than recommended resources are used, customers may run into known and unpredictable BLE behavior. It will directly impact any BLE based outcomes

* Follow all Cisco recommended best practices for location grade deployment, including but not limited to APs installed at the periphery of the floors, no more than 50 feet of inter AP distance, devices heard at least -75dbm or better by at least 3 APs.

* Make sure IoT Services and location (Detect and Locate) is working for the account and location properly as it is a inherently used by the plugin framework.

* Make sure devices are either installed by Kontakt official installers, or in conjuction with Kontakt support and guidance and follows all Kontkat best practices published.

* Understand and explain to customers the unsupported and supported functionality to set right expectations.

![image-20241116-224608.png](https://runbooks.ciscospaces.io/__attachments/a_bceac6253f052b3fdbfb3062affb073415c14d2caeee3d1f0ff4a13b8dd2eeb5/image-20241116-224608.png?cb=7bf1d8acddcc4cf7ddfd565731817cd8)
Example - Portal Beam in middle of the room centered around the seating area

![image-20241116-224647.png](https://runbooks.ciscospaces.io/__attachments/a_eacbc081a0225681b38c079b34ddaedfbac6b8558972ec7e268e5c5190c6712c/image-20241116-224647.png?cb=545cabaed35faaf3ac73a157625cf3c7)
Example - Portal Beam in middle of the room centered around the seating area

For Cisco Spaces + Portal Beam solution, Cisco recommends the following best practices.

* Make sure all infrastructure release versions and AP deployment modes are used. For example, if older IOS-XE code or a connector with a lower than recommended resources are used, customers may run into known and unpredictable BLE behavior. It will directly impact any BLE based outcomes

* Follow all Cisco recommended best practices for location grade deployment, including but not limited to APs installed at the periphery of the floors, no more than 50 feet of inter AP distance, devices heard at least -75dbm or better by at least 3 APs.

* Make sure IoT Services and location (Detect and Locate) is working for the account and location properly as it is a inherently used by the plugin framework.

* Make sure devices are either installed by Kontakt official installers, or in conjuction with Kontakt support and guidance and follows all Kontkat best practices published.

* Understand and explain to customers the unsupported and supported functionality to set right expectations.

![image-20241116-224608.png](https://runbooks.ciscospaces.io/__attachments/a_bceac6253f052b3fdbfb3062affb073415c14d2caeee3d1f0ff4a13b8dd2eeb5/image-20241116-224608.png?cb=7bf1d8acddcc4cf7ddfd565731817cd8)
Example - Portal Beam in middle of the room centered around the seating area

![image-20241116-224647.png](https://runbooks.ciscospaces.io/__attachments/a_eacbc081a0225681b38c079b34ddaedfbac6b8558972ec7e268e5c5190c6712c/image-20241116-224647.png?cb=545cabaed35faaf3ac73a157625cf3c7)
Example - Portal Beam in middle of the room centered around the seating area

#### Troubleshoot Portal Beam Room Occupancy

If issues are seen with the occupancy counts, or need to verify a Portal Beams people detection capability, use the Kio Setup Manager mobile app, downloaded from either App Store or Play Store. If these actions do not resolve the issue, please open a support ticket.

* **Capture real time thermal image to verify people detection.**

  * Repeat Step 5 from the workflow to make sure the functionality is working correctly.

* **Configure or update the exclusion zones.**

  * Repeat Step 5 from the workflow to make sure the functionality is working correctly.

* **View the last image shared from Cisco Spaces**

  * Go to links mentioned in Step 3 from the workflow and validate the image is seen correctly for the appropriate Portal Beam.

* **Update device firmware**

  * Use either Kio Setup Manager mobile app or Cisco Spaces to upgrade the firmware on the Portal Beam, if available. If using the mobile app, a blue up arrow icon ![image-20241116-225449.png](https://runbooks.ciscospaces.io/__attachments/a_7307081d5100aa77846ec3bde89705f3274172bbe2a539a090ca2d2f6d9b8035/acccec6c-d328-4c5a-9624-5d682dd9e55f?cb=4090ca04cb641fa23ad9a53c16af273b) displayed next to a Portal Beam indicates that a firmware update is available. Be sure to allow enough time for any firmware update to be completed.

##### **Validate IOT Services**

Refer to Cisco Spaces documentation or leverage Cisco TAC support to make sure IOT Services is working correctly.

#### Portal Beam Checklist Form

The form here is to ensure proper readiness for the occupancy outcome using portal beams prior to deployment.

* [++https://spaces.cisco.com/checklist-portal-beams/++](https://spaces.cisco.com/checklist-portal-beams/)

*** ** * ** ***

### Room Presence Using PIR Sensors

#### **Overview**

Passive Infrared (PIR) sensors are used to detect motion by sensing infrared energy emitted by people within the sensor's field of view. In Cisco Spaces, PIR sensors are used for room-level presence detection for spaces such as

*
  * **Small meeting rooms**

  * **Focus rooms**

  * **Phone rooms**

  * **Huddle spaces**

PIR sensors provide a binary occupancy outcome:

*
  * **Occupied**

  * **Unoccupied**

PIR sensors are currently supported for room-level presence outcomes only.

#### Supported Sensors

The following sensor is supported for Cisco Spaces PIR presence outcomes:

* **Thingsee PIR Sensor (** [Spec-sheet for Thingsee PIR](https://haltian.com/products/occupancy-sensor/#download-occupancy)**)**

![image-20250311-181600.png](https://runbooks.ciscospaces.io/__attachments/a_ce77e7c20a36b0b3407e412d614d39d21e1524f76ae62de09f551387f04edfb8/image-20250311-181600.png?cb=b3cfa42ef0f23f6a0a5ab02dcc359a5b)
Thingsee PIR sensor with Dome

#### Prerequisites

|--------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Area**           | **Pre-requisites**                                                                                                                                                                                                                                                                                                                                                                              |
| **Wireless infra** | * Catalyst WLC managed APs 9120, 9130, 9136, 9162, 9164, 9166, 9171, 9172, 9174, 9176, 9178                                                                                                                                                                                                                                                                                                     |
| **Wireless infra** | * Catalyst 9800 WLC running 17.12.4 (latest stable)                                                                                                                                                                                                                                                                                                                                             |
| **Spaces infra**   | Cisco Spaces Connector 3.1 Virtual Machine (VM) with **internet access to Spaces Cloud endpoints** ([++firewall allow list++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/connector/2-x/config/b_connector/m_open-ports.html) and [++proxy requirements++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/connector/2-x/config/b_connector/m_proxy.html))                      |
| **Spaces infra**   | Enable IoT Services - [++Advanced BLE Gateway enabled++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-services-wireless/b_iot_services/m_overview.html) ​ BLE Mode: **BLE Scan Mode (iBeacon) enabled** (minimum requirement) Dual mode is fine but only Transmit Mode is not supported                                                                                            |
| **Spaces infra**   | Provide accurate CAD .dwg files for each floor in the EFT location ([++**Best Practices**++](https://cisco-my.sharepoint.com/personal/deayoung_cisco_com/Documents/Meraki_GSuiteMigration/CAD%20File%20Best%20Practices/Cisco%20Spaces%20Digital%20Maps%20CAD%20File%20Best%20Practices.pptx?web%3D1) - including walls, furniture, room labels/IDs, and other recognizable points of interest) |
| **PIR Sensor**     | PIR Order should be in Place                                                                                                                                                                                                                                                                                                                                                                    |

#### How to Order PIR Sensor

1. Log into [Cisco Spaces](https://ciscospaces.io/) , Select to **Device Marketplace** and click on **Explore All Devices** .

   ![Screenshot 2026-07-10 at 5.21.33 PM.png](https://runbooks.ciscospaces.io/__attachments/a_d99b92e8bb349ff35a7c433f25f9c98986983f1365186c9d0599e1914d17fa44/Screenshot%202026-07-10%20at%205.21.33%E2%80%AFPM.png?cb=862ff51017772db5679f2771f7945bcf)

2. Search for Thingsee Presence and select the listing. On the right panel, click on Contact Sales button.

![Screenshot 2026-07-10 at 5.23.58 PM.png](https://runbooks.ciscospaces.io/__attachments/a_dc371c3eae5b2c2e54581d380233a2da66dc922b21e1f64ed2c6f2b959273cd7/Screenshot%202026-07-10%20at%205.23.58%E2%80%AFPM.png?cb=089cdc6d3653818f383f05db89dfeee3)

3. Fill the Contact Vendor form and submit it.

   ![Screenshot 2026-07-10 at 5.33.06 PM.png](https://runbooks.ciscospaces.io/__attachments/a_940d0cd28622b0496d8c0503b2f9b8557d776e1f6bf194cdb8ffcb7bd9b2c135/Screenshot%202026-07-10%20at%205.33.06%E2%80%AFPM.png?cb=8954bb59235b157e6b7a75cead94da9e)

![:warning:](https://runbooks.ciscospaces.io/__attachments/a_f1835336a35bbcd963e042c7109c79d927f866308c397a108ec509da2761721f/atlassian-warning?cb=14432459925d605e05cae2605cdfe666)  
confirm with the vendor that the sensors include Cisco-specific firmware. A minimum order quantity of 50 sensors is required when ordering through Device Marketplace.

4. A confirmation window will appear at the top.

![Screenshot 2026-07-10 at 5.36.40 PM.png](https://runbooks.ciscospaces.io/__attachments/a_ca453c5c4b45b85d0181384d6dd5b209c99db08932ee1d1ba3c4eb7c6ad7a786/Screenshot%202026-07-10%20at%205.36.40%E2%80%AFPM.png?cb=48122e2c0d20e1b91c4b4d85b22b38ef)

5. The Haltian team will follow up with you to create the purchase order and coordinate shipment of the devices. Please keep an eye out for emails from Haltian.

![image-20250109-190009.png](https://runbooks.ciscospaces.io/__attachments/a_bbd55424c7b16af822bbbe59812917d0afe19dce25aaf276ef118814a7b15921/image-20250109-190009.png?cb=dbe1fed63a3962aaf88f74d017b048e8)

6. The customer will receive an invoice from the Haltian team.

7. Haltian will provide an order ID for the purchased devices. Use the order ID to claim the devices under **IoT Services** in Cisco Spaces.

   Example order ID format: `HLTN-H****`

#### Supported and Unsupported Functionality

##### **Supported Functionality**

In the currently available Cisco Spaces + PIR architecture, the following functionality and outcomes are supported:

++*For Room Occupancy Data:*++  

|                  App / Feature                  | Frequency of Data |                                           Data                                            |
|-------------------------------------------------|-------------------|-------------------------------------------------------------------------------------------|
| Digital Signage / Kiosk                         | Real time         | Binary room occupancy, such as occupied or unoccupied                                     |
| Space Utilization App                           | Real time         | Binary room occupancy displayed as a historical graph                                     |
| Space Utilization App --- Room Occupancy Report | Historical        | Binary room occupancy available as an exportable report                                   |
| Space Manager App --- Room Occupancy View       | Real time         | Binary room occupancy, such as occupied or unoccupied                                     |
| IoT Explorer --- Sensor View                    | Real time         | Binary room occupancy, such as occupied or unoccupied                                     |
| IoT Explorer --- Occupancy History              | Historical        | Binary room occupancy displayed as a historical graph with 1-day, 7-day, and 30-day views |
| Spaces Firehose API                             | Real time         | Binary occupancy value                                                                    |

**Unsupported Functionality:**

The following functionalities and outcomes are currently not supported by the Cisco Spaces + PIR solution. While there is potential for these features to be introduced in the future, there is no official confirmation or guarantee at this time, and they are currently unavailable to customers.

If needed, please work directly with Cisco Spaces product team to discuss further.

++*For Room Occupancy Data:*++  

|-----------------------|-------------------|----------------------------------------------------------------|
| App or Feature        | Frequency of Data | Outcome                                                        |
| Space Utilization App | Historical        | Room Occupancy in the dashboard (i.e., occupied or unoccupied) |
| Smart Rooms           | Real time         | HVAC control based on occupancy                                |
| Smart Desks           | Real time         | Desk Occupancy and monitoring                                  |

#### Reference Architecture

![image-20241202-221240.png](https://runbooks.ciscospaces.io/__attachments/a_04a80d84ba07f78ce866589d903de1e3909de70a9ce32ed890ecd9ee3e5176c2/image-20241202-221240.png?cb=efcd6d86b23a149663d5c1e3b80611ef)

#### Deployment Workflow (PIR sensor setup and activation)

##### Claiming PIR sensor using Order ID

1. Login into Cisco Spaces Dashboard

2. Navigate to IOT Services and Inventory**.**

<!-- -->

3. ![Screenshot 2026-07-10 at 6.05.12 PM.png](https://runbooks.ciscospaces.io/__attachments/a_c7b574cddb786cb3c3a385874732b89cf4dae9581fb7750c3d923b02eadae438/Screenshot%202026-07-10%20at%206.05.12%E2%80%AFPM.png?cb=95646a72cea7a87b98e687543fbbd992)

   Select **Claim Devices** and select **BLE Tags and Sensors** and click Next.

![Screenshot 2026-07-10 at 6.06.24 PM.png](https://runbooks.ciscospaces.io/__attachments/a_b5ad182ea2450e5d91b8ade20e05283eb04427cbd502db51c80153a59645845c/Screenshot%202026-07-10%20at%206.06.24%E2%80%AFPM.png?cb=8f3c5ec26bb0fb4446bea8ea2b084daa)  
![Screenshot 2026-07-10 at 6.13.15 PM.png](https://runbooks.ciscospaces.io/__attachments/a_1ef40a82ec16104729c843fe6f478a6df6e1b2a0aee0a2ac76dd04fdc556641a/Screenshot%202026-07-10%20at%206.13.15%E2%80%AFPM.png?cb=1f1d6b2abbf619606752ea8411b7f7af)

4. Use the Order ID provided by vendor and click **Claim**

![Screenshot 2026-07-10 at 6.16.36 PM.png](https://runbooks.ciscospaces.io/__attachments/a_911725b8479c0c1f43d9783ef4f6b31ee1b2294da835bc094ba03b2b74c1962b/Screenshot%202026-07-10%20at%206.16.36%E2%80%AFPM.png?cb=11a0e31210f5b771772f709ba1a5c797)

5. A confirmation message will indicate that the devices have been successfully claimed. The devices will get added under **Claimed Devices** . Make sure the all the sensors are showing under the Claimed Devices and verify the Last Heard time (usually shows few seconds ago for active beacons)

   ![Screenshot 2026-07-10 at 6.32.40 PM.png](https://runbooks.ciscospaces.io/__attachments/a_f7a57607c57e3814928dfa64b2863ad07de02b180293a0d4b546b4941714ee71/Screenshot%202026-07-10%20at%206.32.40%E2%80%AFPM.png?cb=0926491c0e533378c6d229a77837ea06)

**Best Practices :** Label the PIR sensors in order to manage or track them easily as shown below as soon as you claim the devices.

#### Placement of the PIR sensor​

![:warning:](https://runbooks.ciscospaces.io/__attachments/a_f1835336a35bbcd963e042c7109c79d927f866308c397a108ec509da2761721f/atlassian-warning?cb=14432459925d605e05cae2605cdfe666)  
PIR Sensors are only recommended for Small meeting pods or small meeting rooms with capacity of 2-3 people.

##### **Workplace occupancy detection**

Thingsee PRESENCE can be installed under a table to detect the usage of a working space. Sensor sensitivity should be decreased to avoid unwanted detections outside the working space.  
![image-20250311-223509.png](https://runbooks.ciscospaces.io/__attachments/a_7598cc522a745c69854e8c89e39fdc76fbc162849d7fcc46b0a5eae36659fc14/image-20250311-223509.png?cb=f921f8497aea9cc605002b8590340695)

##### **Using Workplace Occupancy Dome**

The detection beam can easily be adjusted with a separate, easy to install, Workplace Occupancy Dome. The detection beam is more accurate when the hole on top of the sensor is facing front.  
![image-20250311-223629.png](https://runbooks.ciscospaces.io/__attachments/a_752e5278163233019b91ed140d9b325ea4cecda07cc130f2b59e6767ee91489f/image-20250311-223629.png?cb=f1abd1b684b78c2bb7877bb872eec008)

##### **Installing the sensor under in a small meeting room or pods**

Install Thingsee PRESENCE at a location from where the it could cover the maximum area to transmit the infrared signals. Best Practice is to place the sensor at the 2/3 height of the wall or side of a meeting rooms wall which could cover the maximum area to transmit the infrared signals.

Below are few examples of the Placing the PIR sensors but not limited to.  
![image-20250311-193209.png](https://runbooks.ciscospaces.io/__attachments/a_a889dea782a24ad5ea7d204503e75a9a2d8170e545012ba32a04740b6814b2df/image-20250311-193209.png?cb=0c7d82f95edb7c05a09a996c0930bc6a)
Meeting Pod  
![image-20250109-001758.png](https://runbooks.ciscospaces.io/__attachments/a_79cde772b3f89bd4a5e9fc6d0fe01d1fed95deda4e817472d53aff84e8cf622b/image-20250109-001758.png)
Small Meeting room  
![image-20250108-234417.png](https://runbooks.ciscospaces.io/__attachments/a_9229f8a349990dfa6cddb49e0d480c9d8554c8613d7d6dbf6171507d4c8c8c4b/image-20250108-234417.png)
Small Meeting room

##### **Installing the sensor under a table**

Install Thingsee PRESENCE under the table as middle as possible. If there are any objects, such as table legs, under the table, place the sensor on the user side of the object. Make sure there is a 50 mm gap between Thingsee PRESENCE and the object so that it can be easily maintained.

Below are few examples of the Placing the PIR sensors but not limited to.  
![image-20250311-223701.png](https://runbooks.ciscospaces.io/__attachments/a_bdd4fee184809a98b7a1379ca46d56be4e841c396231d81fe687857fb0b4bdb7/image-20250311-223701.png?cb=a4e14000cc8d2cd906eb3213a66ab5ca)

![image-20250108-235003.png](https://runbooks.ciscospaces.io/__attachments/a_121cdca708c6495dd7cb86ce60382b8f46ffbd0e95fac13201aa8cc139283358/image-20250108-235003.png?cb=676e8504428c964ac3e67e0913bd4517)

![image-20250109-005014.png](https://runbooks.ciscospaces.io/__attachments/a_ac2c5ba01d16382ffb6692616def7512c9c9e57c2ba9572a366d5993cdf30e36/image-20250109-005014.png?cb=f81da9f847a5cbda6cfbc4808a56cf2d)

##### **Haltian Guided installation of the Thingsee Presence Sensor**

Things to avoid in installation (Best Practices)

<https://youtu.be/35B_peJpTUs>

##### **Changing the batteries**

If you change the batteries, Haltian recommends using Varta Industrial Pro 1.5 V AAA LR06 alkaline batteries.

Open the sensor to change the batteries or reboot the device by replacing the batteries.  
![image-20250311-223745.png](https://runbooks.ciscospaces.io/__attachments/a_970842922c64051a909de8ad06fe2c1a2d24b56b3ce670e85d0fd80f421896ea/image-20250311-223745.png?cb=8faa94f72566c6bb1c1407f7544d3f85)

#### Integrating Space manager

##### Adding a Sensor to a Room

1. Once the Sensor is been claimed, can be associated under Space manager for a Room occupancy use case.

2. Make sure the Digital space where you are associating the PIR Sensor is a Meeting room as shown below under the Digital Map and publish the map again.

![image-20241204-025748.png](https://runbooks.ciscospaces.io/__attachments/a_d2c9ba4574f8c37058689460f8e4580fa1d168c2350cba0cb157e0fb15c9eac2/image-20241204-025748.png?cb=ec66b7ac54b6e76128ed200fb81094d8)

3. **Navigate to Space Manager** **Space Management** and select the Location and floor/zone where the Meeting room located and you want to associate the PIR to.

4. Click on the Meeting room space and should open a pop window on the right side after that as below.

![image-20241204-030916.png](https://runbooks.ciscospaces.io/__attachments/a_35013b7077aea6a259775c75f6390ae5ec5131d3801458987720121e2f363cdc/image-20241204-030916.png?cb=f4da144c192b4f7367617f8308ad45f7)

5. Click on **Add Devices** under the IOT Sensorsassociate the Sensors mac/BLE mac or uniq ID(device ID) to a Meeting room

![image-20241204-031311.png](https://runbooks.ciscospaces.io/__attachments/a_9da31bd9074a8777e97e301d3ceb621d95e47ba1e5f0805ad6ec7a906188151e/image-20241204-031311.png?cb=6cf29a8626b360947f8fc9500c0dfc4c)

6. Once added it should reflect under the IOT Sensors.

![image-20241204-031443.png](https://runbooks.ciscospaces.io/__attachments/a_e51ddb3255809bfdaae9e57bd03dd27af2cf22afa71d46b36405763a4a1a02b0/image-20241204-031443.png?cb=cff2e62f39c0192ac6670d35385709fa)

**Necessary Step (Short term) :**

For room occupancy report to reflect these PIR room info - we need to set occupancy setting for each of this room.

Select edit option for occupancy and save the setting (it will be default People count).  
![RoomOccupancy-setting-20241204-163649.gif](https://runbooks.ciscospaces.io/__attachments/a_b18d793854726abeb4700384ab45ed5a6b1b32b8957253d44b6cfe3baeb9a559/RoomOccupancy-setting-20241204-163649.gif?cb=6173ec92e38442b3e40e1b5d7886caf7)  
Space Manager only knows Portal Beams for 3rd Party IoT Sensors for now. Space Manager v2 will account for binary PIR sensors showing correctly there.

7. **Navigate to Space Manager** **Overview** and PIR reflect immediately there under the Room Occupancy view for the specific Meeting Room

![image-20241204-031730.png](https://runbooks.ciscospaces.io/__attachments/a_ce4b744b33409327cef6ffec4bf3eb4db64b93326f28af01825e863d98ba4a3a/image-20241204-031730.png?cb=74bc72490c7f4791fc47a7c1f5a50643)

8. Meeting Room should immediately reflect Available status under the Room Occupancy View.

![image-20241204-032111.png](https://runbooks.ciscospaces.io/__attachments/a_b12b0b98a5ba51ab1d9304361165ddb7ddb8c94fc6749005a9ed2064787676fc/image-20241204-032111.png?cb=bedda26987e572c8df075033479d53da)  
Occupancy is detected within 30 sec , There is 5 min(300 seconds) guard timer to detect if its not occupied.

##### Removing a Sensor from a Room

There are two ways to remove sensors once placed in a room within **Space Manager**.

1. In the Space Details screen (as seen in step 6 above) you can click on **Disassociate** to remove one single sensor from a room.

![Screenshot 2025-04-28 at 4.58.44 PM.png](https://runbooks.ciscospaces.io/__attachments/a_2d4a222689da095c19b83ba51f4c2dbfabb32be367ab886836356d1b7f2b016c/Screenshot%202025-04-28%20at%204.58.44%E2%80%AFPM.png?cb=e7499ab02091f595571667058b69d0f4)

2. To remove all sensors at one time the ellipsis can be selected next to **Add Devices** and then select **Remove All Device**.

![Screenshot 2025-04-28 at 5.02.31 PM.png](https://runbooks.ciscospaces.io/__attachments/a_71f641e3391d96144eb3a1b286d7092af21c64fc4b6e18395a6d22fd378e44ce/Screenshot%202025-04-28%20at%205.02.31%E2%80%AFPM.png?cb=bd9c131646f4e15b92907dab422718e3)

#### Digital Kiosk Experience

Digital Signage should also reflect the Occupancy Room occupancy status immediately.  
![image-20241204-034822.png](https://runbooks.ciscospaces.io/__attachments/a_0c1684ae9ccf1025650fc4c38191fc0a55ef9d8444de838be15e28249eacd506/image-20241204-034822.png?cb=79cab152b616542665c622aa033c36b6)

#### Room Occupancy Reports

You can Generate Occupancy reports Under Space Manager Room Occupancy report for Buildings, Floors and rooms.

1. Click on Create a Report and select Buildings, Floors or Rooms.

![image-20241204-035923.png](https://runbooks.ciscospaces.io/__attachments/a_ccc7b9b0055135b03da1b176d160e43e7296c530daf46ae7438a195cf796ab5a/image-20241204-035923.png?cb=3d3b5e86432a058f922acad23d9e2ef3)

2. Select a specific Location which will be shown from the Location Hierarchy and Click Next.

![image-20241204-040037.png](https://runbooks.ciscospaces.io/__attachments/a_a33fd7e357745c98ad07c2518b3c7c1ad73cbdec407d6a0f86d5252af00d4389/image-20241204-040037.png?cb=99bbd29434421ecbdce470b572d9907c)

3. Select the Date range or can also Customize it as shown below.

![image-20241204-040206.png](https://runbooks.ciscospaces.io/__attachments/a_ce247d5a020419622861cde0a3f3ac0a194e6bfb2c0905cc763490d26d98bfa0/image-20241204-040206.png?cb=fafffaa4d6489a6dfec4f96b5ef1c363)

4. You can be as specific as for Days, hours and capacity of rooms and click on create report.

![image-20241204-040236.png](https://runbooks.ciscospaces.io/__attachments/a_83f1eb758eef4054027867ffd3656b21acb90d3813fcae63ef8190ec5fc1743b/image-20241204-040236.png?cb=af6fbfc15db93196a787f17be11ae626)

5. Report layout would like this and can also be exported in .CSV formate to further review and share.

![image-20241204-034927.png](https://runbooks.ciscospaces.io/__attachments/a_eaa73e9262f9bd3a1f7221122ff16aab980a90e7dfc89154f82baef4645439d1/image-20241204-034927.png?cb=343914f3ddcfa1462a170ea8c9557c65)

#### Observations and troubleshooting

* **Missing location for claimed sensors in IOT services.** This blocked sensor to be seen and associated in space manager to any room and not usable for occupancy use case through space manager.

![image-20250109-230004.png](https://runbooks.ciscospaces.io/__attachments/a_d3a8df4578d7fa729e1d12d48b2fbefa5a587e62f9288c073afaaf8cfa906250/image-20250109-230004.png?cb=2d81a9f6870e05928e7364980c036a5b)

**Workaround :** Delete the the sensor from IOT services multiple times if needed (until it updates the location under the IOT services)

You need to select the Mac Addresses which are not updating last known location. Under the actions use Delete Beacons to delete that.  
![image-20250109-230733.png](https://runbooks.ciscospaces.io/__attachments/a_1eb1e3d737cfc5c0ab2f95c4537c35dd624303745f2a244a0ea6074d8bf08dde/image-20250109-230733.png?cb=ca5a8f0271f7bb61e70f461d36c9f662)

**Seeing dual Profile types IBeacon and Kontakt under the IOT Services**  
![image-20250109-225547.png](https://runbooks.ciscospaces.io/__attachments/a_67a665adcbbc10ceff50938c80afde8f52516e6358f316b6da92d60ce0ce5390/image-20250109-225547.png?cb=1cb99186926fb3ca211d0c633cae207e)

* **Room occupancy report runs in 4 hour intervals** . (Recent update : Resolved but please reach out to Spaces support if the issue reappears )

  **Workaround :** if customer runs report which included current day - then report includes last 4 hours but it shows incorrect data for those last 4 hours (as FALSE) as data is still not processed. We should either avoid prodding last 4 hours or have different status/value for those hours to avoid confusion or have this 4 hour consideration shown as info to customer.

![image-20250116-050618.png](https://runbooks.ciscospaces.io/__attachments/a_49a87f32e4f7979633c4ca2914f73f020a2ed4d810fc9cc76a7503f8b66ba19a/image-20250116-050618.png?cb=88d1e53749a407c6cb54350c24527722)

* **Room Occupancy Report Interval :** Room occupancy report calculation for 15 min slot does not sync with WebEx calculation. Currently presence in 8 to 8:15 window reflect into 8:00 slot rather than 8:15 like Webex report. ( Expected )

* The Space will be identified as **Occupied within 30 seconds** (Once the person enters the area if the PIR sensor coverage in both Desk and Room scenarios) and once the person leaves the coverage of the PIR sensor it will still reflect as **Available after 5 minutes interval (5 minutes/300 seconds guard timer)**.The Guard timer should also reflect on Occupancy report as Presence True.

* **Peak People Count Column :** Room Occupancy report should have N/A entry to Peak People Count , currently it reflect 0 (tentatively expected)

* **Space Manager**: after adding the IOT device with a meeting room the state is seen as NOT AVAILABLE even Sensor has been associated successfully and showing status on overview and room occupancy

![image-20250109-225051.png](https://runbooks.ciscospaces.io/__attachments/a_52bf4435cbf099a3c807dee49d127394b5c8b3e4b17dcff69e1d5729b1b94d1e/image-20250109-225051.png?cb=1fb3c5d6f2375e4caaf851a87074ca06)

* **Occupancy selection under space manager for PIR sensor** : to set PIR as default occupancy device (needed for room occupancy report) while associating PIR sensor to the room , Currently UI only show portal beam option only. It is expected that Space Manager v2 should fix the issue.

![image-20250109-232519.png](https://runbooks.ciscospaces.io/__attachments/a_ad4a250434d76ec2fe8c26087063f5930e2a704490842589373ff339b5689506/image-20250109-232519.png?cb=e221f08eae8e204ad342a77d998b3e7c)  
Increase in Power level will impact the battery life of the PIR sensors.

*** ** * ** ***

### Desk

#### Overview

Currently there are no GA outcomes for Desk Occupancy

*** ** * ** ***

## REFERENCES

* <https://help.webex.com/en-us/article/nc6od6r/Utilization-and-environmental-metrics-for-workspaces>

*** ** * ** ***

## CAVEATS TIPS

### Location Hierarchy

#### Merging Locations

![Screenshot 2024-10-30 at 2.01.23 PM.png](https://runbooks.ciscospaces.io/__attachments/a_09458b1fe9e7b4c486aa6f2c2ad14f7c2c4482bd4d4d0f1e618be4c0d6698864/Screenshot%202024-10-30%20at%202.01.23%E2%80%AFPM.png?cb=0f69cd278e010821dd521472dc49fbf9)
Location Hierarchy merging elements together

* Combining multiple hierarchies (e.g. Webex Control Hub and wireless network) adds complexity​

* The merge function de-duplicates locations so that multiple platforms can be combined into a simplified, unified hierarchy​

* For a Meraki Org / Network, always plan to merge the Org level above all the Network levels, and the network maps as floors.​

* Keep in mind that Catalyst Center may have more groups/levels than the Spaces Excel template supports (3), so it may be best to merge Catalyst Center and skip the Excel template.​

* **Please reach out to the Cisco Spaces team for more complicated merges.**

*** ** * ** ***

### Cisco Collaboration Integration

#### Collaboration Devices + Control Hub

* Webex Devices send telemetry (e.g. people count, temperature, humidity, etc.) on changes to sensor values​

* Control Hub metadata syncs every \~2 hours (e.g. room capacity, moving location / floor)

*** ** * ** ***

### Occupancy Architecture

#### How does the end-to-end solution work for occupancy?

![Screenshot 2024-11-04 at 11.48.41 AM.png](https://runbooks.ciscospaces.io/__attachments/a_bc7e1c5666a6889952a61c6f389beb10ce284b6a6c8ed9751f631d0cac4531f1/Screenshot%202024-11-04%20at%2011.48.41%E2%80%AFAM.png?cb=460a8adcb2f89e33f82cd22c0e2b486f)

#### Occupancy Outcome Data

| Building Floor Occupancy |      Room Occupancy      |
|--------------------------|--------------------------|
| Signage                                            ||
| Streaming API Firehose                             ||
| Batch/CSV Exports        | Room Occupancy Downloads |
| Right Now                |                          |
| Behavior Metrics         |                          |

---
language: "en"
---
# Cisco Spaces OpenRoaming Runbook (Cisco Validated)

## OVERVIEW

*This Cisco validated runbook is designed only as a follow on from the* [++***Spaces OS Runbook***++](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated)*. If you have not completed that runbook yet, please go back and ensure that the deployment has been validated against that before continuing here.*

With the standard expectation of users to always be connected to the internet no matter where they are, it is paramount that users can be connected securely and seamlessly. Wi-Fi onboarding allows users a frictionless onboarding experience and a seamless handover when roaming between cellular and Wi-Fi.

OpenRoaming enables secure, seamless, and automatic network connectivity by eliminating tedious Wi-Fi guest onboarding processes and the risk of connecting to rogue SSIDs. This is especially helpful for a mobile device user trying to access the internet because OpenRoaming removes the need to choose between multiple SSIDs, or enter insecure, shared credentials on poorly designed captive portals.

This runbook will look at OpenRoaming to onboard customers. For information about integrating with Carrier Offload with Partner Apps (such as AT\&T Auto-Attach), please refer to [Appendix: Carrier Offload Providers](https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated#Carrier-Offload-Providers)

### SUPPORT AND ONBOARDING

Please follow the link below to find out about the different ways to get support for Cisco Spaces.

[++Support Info Link++](https://activate.dnaspaces.io/hubfs/Assets/CiscoSpaces-SupportUpdate.pdf?__hstc=105720540.52aaa4a978f36be89855b002cb35bfc4.1729705805310.1729705805310.1729705805310.1&__hssc=105720540.1.1729705805310&__hsfp=3667649010)

*** ** * ** ***

## PREREQUISITES

This runbook should **only be used as a follow on from the** [++**Spaces OS Runbook**++](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated). All the prerequisite steps are covered in the Spaces OS runbook and should be completed before progressing here.

Namely, OpenRoaming requires the following prerequisites met:

* An active Cisco Spaces account.

* A Cisco wireless network. Both controller-based (Cisco AireOS or Cisco Catalyst wireless controller) and cloud-based (Cisco Meraki) networks are supported.

* Add the wireless network to your Cisco Spaces account.

  * For controller-based architecture, the Cisco Spaces Connector must be used.

  * For Cisco Meraki networks, add the Cisco Meraki account to your Cisco Spaces account.

### OpenRoaming Prerequisites

#### Network Components

|------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **C9800 WLC\*** ^**1**^            | -16.12.1 or above * Cisco Spaces Connector                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| **AireOS WLC\***                   | * Only AireOS 8.10.x supported * Other releases: AireOS 8.9, 8.8, 8.7 and below are EoL/EoS and will not be supported for OpenRoaming. * Cisco Spaces Connector                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **Meraki**                         | -Wi-Fi 7, Wi-Fi 6E, Wi-Fi 6 APs: R31.1.6 and above -Wi-Fi 5, Wave 2 APs: R30.7.2 and above -Admin access required for Meraki Account to activate SSID for OpenRoaming -At least one **unconfigured SSID** on Meraki Dashboard in "Disabled state" If you do not meet one or more of the above prerequisites, you can manually activate OpenRoaming on your Meraki network by installing a Cisco Spaces Connector. In this scenario, please raise a [++support case++](https://activate.dnaspaces.io/hubfs/Assets/CiscoSpaces-SupportUpdate.pdf?__hstc=105720540.52aaa4a978f36be89855b002cb35bfc4.1729705805310.1729705805310.1729705805310.1&__hssc=105720540.1.1729705805310&__hsfp=3667649010) for deployment support and describe your scenario. |
| **Cisco Spaces Connector** ^**2**^ | Connector version 3.x                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| **CMX Tethering**                  | Not Supported                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **AP Support**                     | All 9100 Series Access Points Catalyst Wave 1 and Wave 2 Access Points All MR Wi-Fi 5 wave 2 (that can be upgraded to at least MR 31.1.6), Wi-Fi 6 and Wi-Fi 6E APs                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |

^**1**^ Embedded Wireless Controller (EWC) on Catalyst 9100 and the Embedded Wireless on Catalyst 9000 switches are NOT supported.

^**2**^ Cannot be configured with HTTP/HTTPS proxy enabled.

* See WLC release notes for supported APs per release

#### OpenRoaming Client Matrix

|-------------------------------|----------------------------------------------------------------------------------------------------------------------|
| **Device Support**            | -Samsung Devices: Android 10 or higher -Google Pixel: Android 11 or higher -Apple devices running iOS 13.3 or higher |
| **OS Support**                | -Apple devices running iOS 13.3 or higher -Android phones running Android 9 or higher                                |
| **Cisco Spaces SDK**          | -iOS 13.3 or higher -XCode version 12 or higher -Android 9 or higher                                                 |
| **Service Providers (today)** | -T-Mobile -AT\&T -Comcast                                                                                            |

SSID broadcasting must be enabled for OpenRoaming to function

#### OpenRoaming Firewall Rules

In addition to ports opened to allow basic functionality, OpenRoaming will require a security policy configured on the network firewall to allow inbound traffic. By default, all inbound traffic is disallowed.

Connector based deployments  
![image-20250822-105544.png](https://runbooks.ciscospaces.io/__attachments/a_52de5695ab03256eee5ab01d5a9a1ca359ceb83367fe43fb6172dfd9b21b058b/image-20250822-105544.png?cb=9a6631f79ab9a438b473a0623f51e265)

Refer to the table below for all the required Firewall Rules for Open Roaming:  

|            **Source IP Address**            | **Destination IP Address** | **Direction**  | **Transport** | **Source Port** | **Destination Port** |                    **Protocol**                     |                                            **Further Information**                                             |
|---------------------------------------------|----------------------------|----------------|---------------|-----------------|----------------------|-----------------------------------------------------|----------------------------------------------------------------------------------------------------------------|
| Cisco AireOS Wireless Controller IP address | Connector                  | Unidirectional | UDP and TCP   | Any             | 1812, 1813           | Remote Authentication Dial-In User Service (RADIUS) | Communication between Connector and Cisco AireOS Wireless Controller for OpenRoaming client's RADIUS messages. |
| Connector                                   | Any                        | Unidirectional | TCP           | Any             | 2083                 | RADIUS over TLS (RADSEC)                            | Communication between Connector and OpenRoaming Identity Providers                                             |
| Connector                                   | Any                        | Unidirectional | TCP           | Any             | 443                  |                                                     | HTTPS for CSR signing - OpenRoaming Membership                                                                 |

Meraki based deployments  
Meraki APs must have outbound connectivity to the following IPs over port 2083:

* [++184.73.46.220++](https://184.73.46.220/) (For IO customers)

* [++63.33.180.45++](https://63.33.180.45/) (For EU customers)

* [++54.169.186.118++](https://54.169.186.118/) (For SG customers)

*** ** * ** ***

## IMPLEMENTATION

To complete these steps, an admin will require read/write permissions within Spaces for OpenRoaming and DNA Spaces, as well as read/write access to Meraki Dashboard and/or WLC, and read access to connector for verification.

With the prerequisites covered, implementing OpenRoaming requires four main steps:

1. Create an OpenRoaming Profile

2. Enable Hotspot Connector

3. Configure Network Controller

4. Configure the OpenRoaming SSID

Each of the main steps will be discussed.

*** ** * ** ***

### Create an OpenRoaming Profile

An OpenRoaming profile contains information about the network SSID and specifies which user identities are allowed to access the guest network. You can also configure carrier offload in the OpenRoaming profile.

To create an OpenRoaming profile, the following substeps need to be performed:

Substep 1: Set Access Policy

Substep 2: Configure an SSID

Substep 3 (Optional): Configure Carrier Offload

Substep 4: Review and Confirm Settings

[++***Click here for a video guided demo***++](https://player.vimeo.com/video/583751846)

#### Set Access Policy

Set your policy on who can access your OpenRoaming network.

1. Go to **OpenRoaming app** within Cisco Spaces Dashboard.​

   ![Screenshot 2026-06-04 at 09.44.36.png](https://runbooks.ciscospaces.io/__attachments/a_9f2ca15d79b56bd45b46ce7ae07ae9cef80bc8ed02fee28d17e6bb2313e5efa6/Screenshot%202026-06-04%20at%2009.44.36.png?cb=e1b1a14dbbcc7f57f7809efc38afb7bb)
   Access the OpenRoaming App

Or alternatively, through the side-menu by clicking the **Dashboard** drag-down.  
![Screenshot 2026-06-04 at 09.45.41.png](https://runbooks.ciscospaces.io/__attachments/a_7eef0f051b837c39b69365ae06068a23190ef06c8bb519c04327423661e226bb/Screenshot%202026-06-04%20at%2009.45.41.png?cb=421261185adef80fb8a214229a3fc4c1)

2. Click on **Setup** .​ If this is the first time that you are setting up OpenRoaming, when you click **Setup** , a **Terms and Conditions** dialog box is displayed. Click **I Agree** to proceed.

3. In the **OpenRoaming Profiles** section, click **Create OpenRoaming Profile**.

The **Create an OpenRoaming Profile** configuration wizard is displayed.

4. Click **Proceed**.

5. Under **Access Policy**, specify who can access your OpenRoaming network. Select the types of identities that can access the OpenRoaming network as well as if real identities are required.

The options available are:

i) **Accept all authenticated users**: This is the default option.

ii) **Accept only users who provide their identity**: An example of an accepted identity is a real identity, such as an email ID.

iii) **Accept users with specified identity types** : Choose the desired identity types from the list that is displayed. Enable the **Require real identity** knob if you want users to enter their real identities. The identity types chosen here is displayed adjacent to their real or anonymous identity settings, in a table next to this list.  
![Screenshot 2026-06-04 at 09.47.05.png](https://runbooks.ciscospaces.io/__attachments/a_96e304d3bf650bd37859ff05b8284517c1810fe9b48df39f691338668926fde4/Screenshot%202026-06-04%20at%2009.47.05.png?cb=e7b7a4f990331480dd7f6569e50c5bbd)
Set Access Policy

iv) **Accept only your users**: If you choose this option, you will need to be added as an identity provider.

6. Under **Preferred Credentials**, choose the desired option from those listed below by clicking the corresponding radio button. This option will set your policy on who can access your OpenRoaming network:

i) **I do not have preferred credentials**  
If you have selected **Accept only your users** in the **Access Policy** section, this option will be disabled.

ii) **I have preferred credentials, which I want to use** : If you choose this option, you must select a domain from the list of domains that are displayed or click **Add a Custom Domain** .

![Screenshot 2026-06-04 at 09.49.09.png](https://runbooks.ciscospaces.io/__attachments/a_f29888c80e0b19acfeca934a77ca91f6251cf0f111091b0d1060edc9337d40af/Screenshot%202026-06-04%20at%2009.49.09.png?cb=67b3794a54807105b2f99640c25a115f)
Set Preferred Credentials

7. Click **Continue**.

The **SSID Details** window is displayed.

#### Configure an SSID

Enter the SSID details for this OpenRoaming Profile - this is a secure SSID different from your guest SSID.  
If Carrier Offload will be configured as part of the Open Roaming setup, please refer to step 3 below: Configure Carrier Offload.

1. In the **SSID Details** section, enter the SSID name in the corresponding field. This is the SSID that will be broadcast for OpenRoaming.

For Catalyst and AireOS deployments, if the name that you enter is an existing SSID, ensure that the SSID name is an exact match of what is in the network.  
For Meraki deployments, a new unique SSID name must be used. You must have a unused SSID available.

2. (Optional) In the **Advanced** section, you can choose among the following options by clicking the corresponding radio button:

i) **Default Status** : Choose between **Enable** or **Disable** by clicking the corresponding radio button. The default option is **Enable**.

ii) **Fast Transition (802.11r)** : Choose between **Adaptive** , **Enable** or **Disable** by clicking the corresponding radio button. The default option is **Adaptive**.  
802.11r is to significantly reduce the length of time that connectivity is interrupted between a mobile device and Wi-Fi infrastructure.

When 'Enable' is selected, the controller allows all clients to use Fast Transition, even if they don't support it.

The 'Adaptive' option enables Fast Transition only for clients that support it. The controller will dynamically determine which clients are Fast Transition capable and allow them to use Fast Transition. Clients that do not support Fast Transition will fall back to regular reauthentication processes.

The **Create an OpenRoaming Profile** configuration wizard is displayed.

3. Click **Next**.

The **Carrier Offload** window is displayed.

Follow the steps below to configure Carrier Offload. For more information on integrating specific Carrier Offload Providers, refer to [Appendix: Carrier Offload Providers](https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated#Carrier-Offload-Providers)
Configure Carrier Offload (Optional)  

#### Configure Carrier Offload (Optional)

You can leverage your Wi-Fi network to provide voice and data services to mobile carrier subscribers on your Wi-Fi network. ++This configuration is optional++.  
Ensure that the Settlement Provider is already configured previously. See below.

Before you configure carrier offload, ensure that the following prerequisites are in place:

* You must have an existing relationship with a mobile carrier or service provider.

* You must have configured the settlement provider with the mobile carrier or service provider.

* You must configure a carrier or add a custom carrier. [Refer to Appendix: Carrier Offload Providers](https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated#Carrier-Offload-Providers).

1. Use the **Allow Carrier Offload** knob to enable the **Carrier Offload** settings.

A table listing the various carriers, along with their corresponding details such as the **Offloading Partner** , **Static Routing** , **Realms** , and **MNC/MCC** settings, is displayed.

2. Based on your existing relationships with various carriers, you can either select from the carriers that are available in the table or click **Add Custom Carrier** to add carriers of your choice.

If you have not configured a carrier, or if you click **Add Custom Carrier** , you must visit the**Cisco Spaces Partner App Center** to first activate the offloading partner. Contact your carrier offloading partner for specific information that has to be entered in the custom fields. As an example, refer to the [Appendix: Carrier Offload Providers](https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated#Carrier-Offload-Providers).

If AT\&T is selected as the carrier for Carrier Offload, the dashboard will alert that you must activate this option explicitly through the AT\&T Auto-Attach Partner app. This alert has been added since AT\&T has mandated that all customers must activate their partner app before they began accepting AT\&T users at the venue.  
![Screenshot 2025-02-26 at 6.00.35 pm.png](https://runbooks.ciscospaces.io/__attachments/a_77e4393c2943ca161923ff74600f55de43e2ee1740da4b722efb9d4776d5017d/Screenshot%202025-02-26%20at%206.00.35%E2%80%AFpm.png?cb=c6e26b453d317734cd401bfc34c94865)  
![Screenshot 2025-02-26 at 5.56.23 pm.png](https://runbooks.ciscospaces.io/__attachments/a_399c0f65ec09ecc88f334491552174eb6d6cf1782e2e7ea284d920321973877a/Screenshot%202025-02-26%20at%205.56.23%E2%80%AFpm.png?cb=80ed1048d2006146284bdf709528b1dc)

Refer to [Appendix: Carrier Offload Providers](https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated#Carrier-Offload-Providers) for more information about activation.

3. Click **Next**.

The **Review Your Configuration** window is displayed.

#### Review and Confirm Settings

Review and confirm the OpenRoaming profile configuration.

After you have configured the access policy, SSID, and the optional carrier offload, you can review your OpenRoaming profile configuration and modify it if required before saving these settings.

1. In the **Review Your Configuration** window, verify the settings and do one of the following:

By default, the OpenRoaming profile name is the same as the SSID name. You can choose to retain the OpenRoaming profile name as the SSID name or modify the profile name.

i) If you are satisfied with the configuration, proceed with the next step by clicking **Done**.

ii) If you have to make changes, click the **Edit** link next to the section whose configuration has to be modified and make changes. Continue to click **Next** until you arrive at the **Review Your Configuration** window. On successful modification of the OpenRoaming Profile configuration, proceed with the next step by clicking **Done**.

2. Click **Done** to complete the creation of the OpenRoaming profile.

A success message appears briefly, and a confirmation window is displayed.

![Screenshot 2026-06-04 at 09.52.10.png](https://runbooks.ciscospaces.io/__attachments/a_a1e48a4ef817c7add16e740f2780e10e5ce2900111db8f206d8fb751f7cedf30/Screenshot%202026-06-04%20at%2009.52.10.png?cb=12b7ee55470ef2f1ca6c7184ac3eeaef)
Review your Configuration  
![Screenshot 2026-06-04 at 09.53.05.png](https://runbooks.ciscospaces.io/__attachments/a_f883c781bd853c784ccb16d1658483b6c109b2c3c9fa07ca020b70d5f7656c95/Screenshot%202026-06-04%20at%2009.53.05.png?cb=413916009783894d9d31d8d1de179670)
Confirm Profile Created

*** ** * ** ***

### Enable Hotspot Connector

**A Hotspot Connector is not usually needed for Meraki**. This functionality is handled via APIs to Meraki cloud.

Meraki implementations should validated their API integration is active only.
Enable a Hotspot on the Cisco Spaces Connector (Cisco AireOS or Cisco Catalyst Network)  

#### Enable a Hotspot on the Cisco Spaces Connector (Cisco AireOS or Cisco Catalyst Network)

This step will allow you to enable a Hotspot on the Cisco Spaces Connector for Cisco AireOS or Cisco Catalyst Network. This is needed to add OpenRoaming functionality.

When you add a hotspot on the Cisco Spaces Connector, it leads to the installation of a new docker. You can enable a hotspot on the Cisco Spaces Connector either during the initial configuration of the connector or later using the procedure outlined here.  
A Cisco Spaces Connector should already have been configured by following the prerequisite [++Spaces OS runbook++](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated). In which case, you can see it listed in the **Hotspot-enabled Connectors** section on the **OpenRoaming Setup** window.

#### Enable Hotspot on Cisco Spaces Connector 3.x

1. In section 2, if you do not already have a connector that is hotpot enabled, you will see the following. If you already have enabled your connector for hotspot, you can move onto Configure Network. Ensure the connector you want to use has hotspot enabled.

   ![Screenshot 2026-06-04 at 10.18.29.png](https://runbooks.ciscospaces.io/__attachments/a_23f3107cc3403157bfcd33359256975bba60efe805da8f1ae6ce306cff385f4e/Screenshot%202026-06-04%20at%2010.18.29.png?cb=45cfb78a5a426613052e8a66348481b3)
   Hospot not enabled on connector
2. In the Cisco Spaces dashboard left navigation pane, click **Setup** and choose **Wireless Networks**.

3. In the **Connect your wireless network** window that is displayed, go to the **Step 2** area and click **View Connectors** .

   ![Untitled copy.jpg](https://runbooks.ciscospaces.io/__attachments/a_a152078c1af3193b5ce9e671e374ccb757f03fedd0786b2712c5da168e09ce86/Untitled%20copy.jpg?cb=88ede95f94349a1a18419e5a316a56d1)
   View Connectors
4. Click the name of the connector you want to enable, then in the window that is displayed, click **Add Services** .

   ![Untitled 3.jpg](https://runbooks.ciscospaces.io/__attachments/a_1e4007fc9332a4fe7a15926f9b2f2f8353b362fc049653d9613a1ca64fbbf7e8/Untitled%203.jpg?cb=fc8a0a3635d0d6c2d73bee3f0bcf05f2)
   Add Service
5. In the **Add Service** window that is displayed, choose **hotspot** and click **Add**.

In **Services** , **Service Manager** is added by default.

In the **Connector Details** window, you can see that the number of services enabled has increased.  
![image-20250122-061727.png](https://runbooks.ciscospaces.io/__attachments/a_460a7dd10ffc6b5433c41dd4526c0c19e75cfef529c942254b5f4bc161c3912f/image-20250122-061727.png?cb=ffd2ba8f77e5260be9cab8e50712767e)
Hotspot Service

![image-20250122-061807.png](https://runbooks.ciscospaces.io/__attachments/a_c7a396fd4d97872b69a6b0b933484143ea9bdb1f3b38d72ed9c6af1c5974d653/image-20250122-061807.png?cb=667672b3dcf1d09e45342238bc993edf)
Hotspot Service details

Validate Meraki API integration  

#### Validate Meraki API Integration

In this section we should ensure the Meraki API integration is valid and active before proceeding to configure network.

1. Under **2.Hotspot-enabled Connectors** , open the **Meraki API** tab.

2. Ensure you see a green tick as validation the API connection is active.

   ![Screenshot 2026-06-04 at 11.01.59.png](https://runbooks.ciscospaces.io/__attachments/a_2332d020e4655b190a68b8298ca5805d6934d579c8a50fd723c37c70720b8b18/Screenshot%202026-06-04%20at%2011.01.59.png?cb=9af4f0ead802b18ba02d51ad844057bf)
   Meraki API Active

3. If you see a **Set Up** button, that means the Meraki Integration is not active. You should follow the Set Up link, and configure your Meraki Integration before proceeding. See <https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated#Meraki-Wireless> for more details.

It is reccomended to use the Meraki Integration over the Meraki API method  
![Screenshot 2026-06-04 at 11.04.16.png](https://runbooks.ciscospaces.io/__attachments/a_6ca66e3cb84309a7065f3b9f7bf6eb09d7edb6f011081240a4cbcf852b50d643/Screenshot%202026-06-04%20at%2011.04.16.png?cb=8c9cd585dec1371b1122b49383ca38fb)
Meraki API Inactive

*** ** * ** ***

### Configure Network

Depending on your wireless network, follow the corresponding procedure to associate an OpenRoaming profile with the controller and configure the network:
Configure Cisco AireOS or Cisco Catalyst Network  

#### Configure Cisco AireOS or Cisco Catalyst Network

Before you configure the Cisco AireOS or Cisco Catalyst wireless network, you must configure the SSID and AAA policy.

1. In the OpenRoaming app, click **Set Up OpenRoaming** or choose ![hamburger.jpg](https://runbooks.ciscospaces.io/__attachments/a_b35760e3c3dc82cb2e9df388168a342509b390e2ede6f8ffa6e44c0169479cfb/hamburger.jpg?cb=06b3cb45fd23d2c41de354cd9ba96bd7) \> **Setup**.

The OpenRoaming Setup page is displayed.  
If you have completed the OpenRoaming Profile configuration, click **Continue OR Setup** in the configuration wizard to proceed.

In the Network configuration section, under the AireOS/Catalyst controllers tab, a list of all the Cisco AireOS and Cisco Catalyst series controllers appears with details such as the Controller status and associated Connectors.

2. Under **3. Network configuration** \> **Cisco Wireless** , in the **Action** column, click the **3 dots** , click ![gear.jpg](https://runbooks.ciscospaces.io/__attachments/a_3d151a930acf221a320844fc811ae73fd8801903745d9ba07137389ea978515c/gear.jpg?cb=dd9f2d138e7d3a833b7632106e0a2ee5) **Configure Controller** corresponding to the controller you want to configure.

   The **Configure Controller** window is displayed.
3. Choose the required **OpenRoaming Profile** for this controller, then click **Continue**.

   ![image-20260604-103149.png](https://runbooks.ciscospaces.io/__attachments/a_6235dc06413e1abb6dde64bf2a6b61929674ecef4f1ef3e2280c9edf2cfd4fdf/image-20260604-103149.png?cb=d368f1827f314820180ef6f5dd6b3554)
   Choose OpenRoaming Profile
4. Choose the controller type between **AireOS** and **Catalyst 9800** .

   ![Screenshot 2026-06-04 at 10.27.40.png](https://runbooks.ciscospaces.io/__attachments/a_8844e35bac04cb1814c3fcf39f3471910041e4bc1b966367dce7d248dbe37c9e/Screenshot%202026-06-04%20at%2010.27.40.png?cb=6a429d8d211a633bbdab5f557854b8c6)
   Select required controller
5. In the **Connector IP Address** field, enter the IP Address of the connector if not automatically filled.

6. The WLAN Name will be automatically filled as per the SSID Name configured in the chosen OpenRoaming Profile. To edit this, you must edit the OpenRoaming Profile.

7. Click **Show Configuration**.

8. Select the either **Catalyst: (17.2.1/17.3.1)** (for IOS XE versions 17.2.1 or later) or **Catalyst: (16.12.1/17.1.1)** (for IOS XE versions earlier than 17.2.1)​

9. The generated CLI configuration is for the Hotspot OpenRoaming ANQP server. **Copy the configuration** .

It is always important to review generated configuration, and make sure you are comfortable and understand the configuration.  
The generated configuration assumes the default Wireless Policy Profile and Policy Tag will be used. In deployments with the defaults being used, the entire configuration can be used.

Otherwise, if using a different Wireless Policy Profile and Policy Tag, copy only the OpenRoaming HotSpot ANQP server settings as highlighted below.  
![Screenshot 2026-06-04 at 10.28.27.png](https://runbooks.ciscospaces.io/__attachments/a_237d1042d715239160c1a662af3ac3304a4c9e9e1b7b1838bdfa7152b97df386/Screenshot%202026-06-04%20at%2010.28.27.png?cb=f110e3b3e863643a680f688bd5fdb89c)
Copy generated config

10. Paste the selected OpenRoaming profile configuration in the Cisco AireOS or Catalyst controller CLI.

![image-20241215-130244.png](https://runbooks.ciscospaces.io/__attachments/a_94466386e2c5ff2e2146e5b99e6f61a07e47968c80c7abb7c600e8d85d707119/image-20241215-130244.png?cb=90677fe3ed72edbeb952910a17409b3e)

11. Click **Close**.

    The **OpenRoaming Setup** window is displayed.

To configure the ANQP server manually on the 9800 Controller or to use non-default Wireless Policy profile and Policy Tag, refer to this video: <https://www.youtube.com/watch?v=XsD6e6F6u4k>

Configure Cisco Meraki Network  

#### Configure Cisco Meraki Network

Configuration of Cisco Meraki networks that use templates is not supported.

1. In the OpenRoaming window, click **Set Up OpenRoaming** or choose ![hamburger.jpg](https://runbooks.ciscospaces.io/__attachments/a_b35760e3c3dc82cb2e9df388168a342509b390e2ede6f8ffa6e44c0169479cfb/hamburger.jpg?cb=06b3cb45fd23d2c41de354cd9ba96bd7) \> **Setup**.

The OpenRoaming Setup page is displayed.

2. In the **3. Network configuration** section, click the **Meraki Networks** tab.

3. Click **Configure meraki network(s) for openroaming profile** .

   ![image-20260604-105006.png](https://runbooks.ciscospaces.io/__attachments/a_c5cdebba9653bdc45b6914c728b7882124094ab9edeefe35e63e6778bc4704c7/image-20260604-105006.png?cb=6fec58f9c7d7f4c76b57506eb8d81855)
   Configure meraki network(s) for openroaming profile

The **Configure OpenRoaming for Meraki**window is displayed.  
For information on configuring a Cisco Meraki network, go to the [++*Cisco Spaces Configuration Guide*++](https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Mobility/DNA-Spaces/cisco-dna-spaces-config/dnaspaces-configuration-guide/m_meraki-config.html).

4. Choose an **Organization** from the drop-down list.

5. Choose the **Cisco Meraki networks** for which you want to enable OpenRoaming. This step is not service affecting for the existing SSID(s).

   ![image-20260604-105655.png](https://runbooks.ciscospaces.io/__attachments/a_ea077718a3148470a91d14d40efad3c95631d384125b52189c88604c0a2c3459/image-20260604-105655.png?cb=7bb66c11d0302b956de87e7603d8a72f)
   Select Meraki Networks

You can select multiple networks from the list.

7. Click **Next**.

8. From the drop-down list, select the **OpenRoaming profile** that needs to be applied on the Cisco Meraki network.

   ![image-20250116-130622.png](https://runbooks.ciscospaces.io/__attachments/a_ef562cdfb09d05c0e1dae78dc84c2f98e3aca472f18293b9d82f1032c6b0ffe9/image-20250116-130622.png?cb=8f560ee221a58563b3e79800c1aeee8f)
9. Click **Configure**.

The Configure button will configure the chosen Meraki Networks, with a new SSID, as created in the OpenRoaming Profile.

10. To validate this, go to [https://meraki.cisco.com](https://meraki.cisco.com/)

11. Log in to the application using the login credentials of your Cisco Meraki account.

12. Click the required **Cisco Meraki Organization**, and choose the required network.

13. Choose **Wireless \> Configure \> SSID** and verify, the SSID you created in the OpenRoaming Profile, was created successfully and is enabled.

    ![image-20241216-123613.png](/__attachments/a_cee9b41be9f2d3fd1298ca9783903865e0f4288238392869295eb60864734565/image-20241216-123613.png?cb=2eec3926810bcf2bdbf2f913d7f0789c)  
    ![image-20260602-133228.png](/__attachments/a_29878170c0694799b092bdae569f11a799db3405f4e083d189ec87a5ebf65bed/image-20260602-133228.png?cb=242b9a8d025c3f28d9be265ea526fd81)
14. Choose **edit settings** and ensure the following details are configured

    1. SSID: Enabled

    2. Security: Enterprise with my RADIUS server

    3. Encryption: WPA2 or WPA3

    4. Splash Page: None (direct access)

    5. Radius Servers are configured

Some clients might refuse to connect to SSIDs using OpenRoaming when configured with weak encryption methods (e.g., WPA1 or 'WPA1 and WPA2'). Please ensure the SSIDs are configured with strong encryption, such as 'WPA2 Only' or 'WPA3', under **Wireless** \> **Configure** \> **Access Control** , in the '*WPA encryption*' section.

17. Optionally configure **VLAN tagging** in the **Client IP and VLAN** settings if required on your network

![image-20250514-085943.png](https://runbooks.ciscospaces.io/__attachments/a_1d6f290c6b9d5818e817ef50b9ea275573718a36b285533731582449bbfc37a4/image-20250514-085943.png?cb=de5386ffced2cb2ccf33a6419502deef)

9. Navigate to **Wireless \> Hotspot 2.0** to ensure Hotspot 2.0 is enabled.

![image-20250219-023815.png](https://runbooks.ciscospaces.io/__attachments/a_14955c4ad6fea8be71ba7f33ca353bcf12470f276da618e7b00aa70ec0ffc334/image-20250219-023815.png?cb=bfe1f2327b9c3b3183eb1d3851432642)

10. This completes the Meraki Dashboard OpenRoaming configuration. Continue with OpenRoaming configuration on Cisco Spaces: <https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated#CiscoSpacesOpenRoamingRunbook(CiscoValidated)-CreateanOpenRoamingProfile>

*** ** * ** ***

#### Check Activation

Check the OpenRoaming activation status on Cisco Spaces dashboard:  
![image-20241216-125605.png](https://runbooks.ciscospaces.io/__attachments/a_19e1ecd39793379706ecc7a65f79c9ccdcdf92770ac78149c8a012e642de8213/image-20241216-125605.png?cb=fc7f1aaf394d5beee81e62a51b3f28b4)

If using Meraki, you can check client connection by navigating to **Network-wide \> Clients**. Check the device is connected.  
![image-20250218-041240.png](https://runbooks.ciscospaces.io/__attachments/a_f5b6b084dd8e5ed4346849cbb1542d7199f1f129619a25ee0a5b89655b40358c/image-20250218-041240.png?cb=35d35264fe4a2e02f596e41590cdce75)

You can also validate the API calls were made from Space to Meraki to complete the activation in **Organization \> Monitor \> Change Log**  
![image-20260602-135013.png](https://runbooks.ciscospaces.io/__attachments/a_3e68c3591150cf279a545da99056f6b96355182858f8a596a274d38fb282bff4/image-20260602-135013.png?cb=ea4073f2aaf2228fce3a0fd593bc0a90)

#### Test Your OpenRoaming Network

You can test your OpenRoaming network configuration through the following methods:

* **Cloud/Social:** To use this method, download the OpenRoaming mobile app from the iOS App Store or Google Play Store to your mobile device.

* **Device Manufacturer**: Use this method to test your OpenRoaming network natively on a Samsung or Google mobile device.

* **Other Methods**: In addition to the above two methods, you can also test your OpenRoaming network using the following two options:

  * **Carrier Offload**: If you have set up a Carrier Offload solution, a mobile phone from the supported carrier will automatically get attached to your OpenRoaming network.

  * **Cisco Spaces SDK**: If you have integrated your brand's mobile app with Cisco Spaces SDK, a mobile phone with your mobile app will automatically get attached to your OpenRoaming network.

  For more information about Cisco Spaces SDK, see Knowledge Article: <https://runbooks.ciscospaces.io/docs/openroaming-cisco-spaces-sdk-integration> \& Developer Docs: <https://developer.cisco.com/docs/dna-spaces-sdk/> . Log in using your Cisco credentials, if prompted.

#### View OpenRoaming Reports

To view your OpenRoaming reports, click \> Home.

The following reports are available in the OpenRoaming dashboard:

* **Unique Devices**

* **Devices by IDP**

* **Devices by Manufacturer**

* **Data Usage**

* **Average Visit Duration**

* **Data Consumed per User**

* **Connections per Day**

* **Connections per Hour**

*** ** * ** ***

## APPENDIX

### Carrier Offload Providers

OpenRoaming enables seamless, secure, and automatic Wi-Fi connectivity by linking access providers (such as venues and enterprises) with trusted identity providers (such as carriers and cloud services). Carrier Offload further simplifies guest Wi-Fi onboarding, increases Wi-Fi attach rates, and supports traffic offload from cellular to Wi-Fi networks, while providing actionable insights through Cisco Spaces to improve customer engagement and business outcomes.

This section offers the process to follow to integrate various Carrier Offload Providers.

**AT\&T**
Carrier Offload with AT\&T Auto-Attach  
The AT\&T Auto-Attach Partner App in Cisco Spaces allows businesses to offer Carrier Offload services to AT\&T mobile network customers. By leveraging Cisco Spaces' existing relationship with one of the world's largest cellular providers, businesses can seamlessly connect AT\&T devices onto their wireless network -- providing seamless \& easy to use connectivity, replacing/supplementing DAS systems \& eliminating dead zones.​​

The two primary functions of the AT\&T Partner App are:

1. It automates the "handshake" between the access network (customer) and AT\&T to setup the agreement to offload AT\&T users.

2. It facilitates automation of SLA/network health related telemetry to AT\&T via Spaces Meta API to provide a view of the quality of experience of their users on the access network

   Once the Open Roaming app is enabled and the steps to configure are completed, follow the next steps to deploy AT\&T Auto-Attach application for carrier offload.​

#### Step 1: Setup AT\&T Auto-Attach Application

1. In Cisco Spaces, navigate to the **Partner Apps** tab on top. Then click **Show all Partner Apps**

   ![Screenshot 2026-07-15 at 9.19.34 pm.png](https://runbooks.ciscospaces.io/__attachments/a_0aae56585445c22b0b0bf44f025865327ef1fa5a9dd351d8d089ca0fff892748/Screenshot%202026-07-15%20at%209.19.34%E2%80%AFpm.png?cb=f9a65c0092f3ef879aef21ff17d6f145)

2. Select **AT\&T Auto-Attach** and then click **Activate** on the screen loaded.

![Screenshot 2026-07-15 at 9.26.33 pm.png](https://runbooks.ciscospaces.io/__attachments/a_8e5e487a445cdc8927248a92524aa0da303bad2d65df47039be7c87afd24c25d/Screenshot%202026-07-15%20at%209.26.33%E2%80%AFpm.png?cb=901d94fc8703b57a58b3bb64b7089349)

3. A pop-up window is displayed, asking you to accept the Terms \& Conditions. This is followed by a prompt that allows you to choose an option to either use an existing account or create a new one. Select the 2nd option to **create a new account** and Click on **Sign Up** .​

   ![Screenshot 2026-07-15 at 9.29.56 pm.png](https://runbooks.ciscospaces.io/__attachments/a_8c8b5b82669ecd807a8fc7e4abaef6f18d645e919797d07b22917e5de77e1dc1/Screenshot%202026-07-15%20at%209.29.56%E2%80%AFpm.png?cb=f0df04ff339b71736d21d044497ed994)

4. A **Contact Request Form** is displayed. Fill the form and Click **Submit**.

![image-20250219-020420.png](https://runbooks.ciscospaces.io/__attachments/a_73dc4409402e3d731961db2251e687de8aae470801babb020d95ef82d2e6170e/image-20250219-020420.png?cb=e2ae77c2bddd1d8b934ce1786c4bbe7b)

5. Once the form is filled, AT\&T will contact you via **email** and setup a meeting​ to discuss location, location information and to sign their agreement. Essentially, AT\&T wants to ensure that their customers will have a good experience when being offloaded to your wireless network.

![image-20250219-021019.png](https://runbooks.ciscospaces.io/__attachments/a_400bc4b2f6bd55ea41b6407362b4d81917516944963c25777bc6308af4757748/image-20250219-021019.png?cb=d21a7e16bbf5815653be3e04d0fc96aa)

6. After this meeting, AT\&T will provide you with a **token** which will be used for activating the application in the next steps.​

![image-20250219-021129.png](https://runbooks.ciscospaces.io/__attachments/a_fcb913c9c1c85c0830df9fa66affb97bfde02d6b0e1697561de3c2d5ee6f1c6c/image-20250219-021129.png?cb=3936f7a624da183e7c1d1df4b4369d2e)

#### Step 2: Activate AT\&T Auto-Attach Application

1. Once the account is created, log in to your **Cisco Spaces account​**

2. Navigate to the **Partner Apps** tab on top. Then click **Show all Partner Apps**

3. Select **AT\&T Auto-Attach** ​ and click **Activate** on the next screen.

4. A pop-up window is displayed, choose **option 1** stating you have an existing account and Click **Continue​**

   ![Screenshot 2026-07-15 at 9.32.00 pm.png](https://runbooks.ciscospaces.io/__attachments/a_087f876409ab0d91193590f97d69041122fab6644f70b3bbfc32df3447186c91/Screenshot%202026-07-15%20at%209.32.00%E2%80%AFpm.png?cb=4827ddc80bdfba81faecaae509407561)

5. Click on **Grant Permissions​**

   ![Screenshot 2026-07-15 at 9.32.09 pm.png](https://runbooks.ciscospaces.io/__attachments/a_4ce5d7f60447b73cf94acfbaa1bac08cdf384d8263de6f30fa855f9d6e275b29/Screenshot%202026-07-15%20at%209.32.09%E2%80%AFpm.png?cb=9a812f5b5ef220b9e65a8f68a016e997)

6. Next, we need to choose locations for which we want to enable AT\&T Auto-Attach carrier offload. You can either check the box Enable for all locations or select specific locations from your location hierarchy and Click **Next**.​

![Screenshot 2026-07-15 at 9.32.56 pm.png](https://runbooks.ciscospaces.io/__attachments/a_325a408fb727a20d42e61eef5068553659951cb40302e412d05bf40bb1ef66cc/Screenshot%202026-07-15%20at%209.32.56%E2%80%AFpm.png?cb=b5818de3db7ba81fc4c7e4b5e1950985)

7. This opens the AT\&T Auto-Attach **portal** . Enter the email under which the account is registered and click **Continue** .​

![image-20250219-022559.png](https://runbooks.ciscospaces.io/__attachments/a_52b6946b8332d25cef01c11ca19bf7aa5e71137be29f2387b6174f56cd3a77a9/image-20250219-022559.png?cb=4ae6931b753ae2bbda462a82fccedc34)

8. Enter the **token** sent by AT\&T and **Sign in**

![image-20250219-022639.png](https://runbooks.ciscospaces.io/__attachments/a_da7a4c5324ab50b03384ecbceaa6ab6a0853b696e81146370a6fcda8aabb02a3/image-20250219-022639.png?cb=4149a3cff9d2c9915e1416c674dc4266)

​

9. An email is sent from AT\&T to confirm that the AT\&T Auto-Attach application is live and you are offloading carrier traffic to your network.​

**T-Mobile**
Carrier Offload with T-Mobile Auto-Attach  
The T-Mobile Auto-Attach Partner App in Cisco Spaces allows businesses to offer Carrier Offload services to T-Mobile mobile network customers. By leveraging Cisco Spaces' existing relationship with one of the world's largest cellular providers, businesses can seamlessly connect T-Mobile devices onto their wireless network -- providing seamless \& easy to use connectivity, replacing/supplementing DAS systems \& eliminating dead zones.​​

The two primary functions of the T-Mobile Partner App are:

1. It automates the "handshake" between the access network (customer) and T-Mobile to setup the agreement to offload T-Mobile users.

2. It facilitates automation of SLA/network health related telemetry to T-Mobile via Spaces Meta API to provide a view of the quality of experience of their users on the access network

Once the Open Roaming app is enabled and the steps to configure are completed, follow the next steps to deploy T-Mobile Auto-Attach application for carrier offload.​

#### Step 1: Setup T-Mobile Auto-Attach Application

1. In Cisco Spaces, navigate to the **Partner Apps** tab on top. Then click **Show all Partner Apps**

   ![Screenshot 2026-07-15 at 9.19.34 pm.png](https://runbooks.ciscospaces.io/__attachments/a_0aae56585445c22b0b0bf44f025865327ef1fa5a9dd351d8d089ca0fff892748/Screenshot%202026-07-15%20at%209.19.34%E2%80%AFpm.png?cb=f9a65c0092f3ef879aef21ff17d6f145)

2. Select **T-Mobile Offload** and then click **Activate** on the screen loaded.

![Screenshot 2026-07-15 at 9.59.51 pm.png](https://runbooks.ciscospaces.io/__attachments/a_64a72f7481d218e698b4347ea0641dc8dbdfb9700c6c8b6a5b78df102f990143/Screenshot%202026-07-15%20at%209.59.51%E2%80%AFpm.png?cb=7f26097e4884ad78d0964a72061634e0)

3. A pop-up window is displayed, asking you to accept the Terms \& Conditions. This is followed by a prompt that allows you to choose an option to either use an existing account or create a new one. Select the 2nd option to **create a new account** and Click on **Sign Up**.​

![Screenshot 2026-07-15 at 10.01.49 pm.png](https://runbooks.ciscospaces.io/__attachments/a_0f8f12b1cad8faac2eb30a1a48dda9d1044eadc2a890079aab373716aea58c54/Screenshot%202026-07-15%20at%2010.01.49%E2%80%AFpm.png?cb=96916ece452d292e4354df3d63de1ff3)

4. A **Contact Request Form** is displayed. Fill the form and Click **Submit**.

![image-20260710-064019.png](https://runbooks.ciscospaces.io/__attachments/a_1be3fe00b67b11b4dd208fb54e30d01ff35fa93c2e05c73b1af67d1ba74db665/image-20260710-064019.png)

![image-20260710-064455.png](https://runbooks.ciscospaces.io/__attachments/a_2743b141bc5215ca3c68e7786b245f7660f4edc0c98031cc3e8a0f6fe6edf5d6/image-20260710-064455.png)

5. Once the form is filled, T-Mobile will contact you via **email** and setup a meeting​ to discuss location, location information and to sign their agreement. Essentially, T-Mobile wants to ensure that their customers will have a good experience when being offloaded to your wireless network.

![image-20260710-064538.png](https://runbooks.ciscospaces.io/__attachments/a_f837415c05f4595eddc8367408f3d51d0bb7499d2c3426e265bf204e0a4d79e2/image-20260710-064538.png?cb=653bc14a18bc44c862b613045ab1d94e)

6. After this meeting, T-Mobile will provide you with a **token** which will be used for activating the application in the next steps.​

#### Step 2: Activate T-Mobile Auto-Attach Application

1. Once the account is created, log in to your **Cisco Spaces account​**

2. Navigate to the **Partner Apps** tab on top. Then click **Show all Partner Apps​**

3. Select **T-Mobile Auto-Attach** ​ and click **Activate** on the next screen.

4. A pop-up window is displayed, choose **option 1** stating you have an existing account and Click **Continue​**

![Screenshot 2026-07-15 at 10.02.13 pm.png](https://runbooks.ciscospaces.io/__attachments/a_ede66278c32f4e1029476ed1c1c409130f3fb4ed7f8a1fe1ae51b0dd600738d9/Screenshot%202026-07-15%20at%2010.02.13%E2%80%AFpm.png?cb=4f6342bf77043aa5ab6d980a2dc3c30e)

5. Click on **Grant Permissions​**

![Screenshot 2026-07-15 at 10.02.34 pm.png](https://runbooks.ciscospaces.io/__attachments/a_e2cd2b8bdd39263e339368dcc7d4ca3fbdd58bd508b2304db1109c8c95fe4db1/Screenshot%202026-07-15%20at%2010.02.34%E2%80%AFpm.png?cb=534c6ea57ccb457575d0803b0e7c58aa)

6. Next, we need to choose locations for which we want to enable T-Mobile Auto-Attach carrier offload. You can either check the box Enable for all locations or select specific locations from your location hierarchy and Click **Next** .​

   ![image-20260710-065103.png](https://runbooks.ciscospaces.io/__attachments/a_bcba398ba38d0ed4fdcbba785dace35c1404937a77b0c7fbaab7af200ca360e5/image-20260710-065103.png?cb=230b5356b63f7d5461263645b08d786c)

7. This opens the T-Mobile Auto-Attach **portal** . Enter the email and password shared when the approval for the location is complete and click **Login** .​

![image-20260710-065133.png](https://runbooks.ciscospaces.io/__attachments/a_d5495ef92b8356942b8d9d3341f33ee310e073917a6bb15df868ea8c1c196fdb/image-20260710-065133.png?cb=77cbb18b91c159fea24260b802fe2298)  
![image-20260710-065453.png](https://runbooks.ciscospaces.io/__attachments/a_ffc73c2b25ca8d2104125daa18ad3c771c5731054b857d19ff86950a5ff409cb/image-20260710-065453.png?cb=2ce9b087aceb245fd4244f2929c4b1a3)  
![image-20260714-130850.png](https://runbooks.ciscospaces.io/__attachments/a_2b31cedfc729074067aa5b74c390591d2ab67421c43d84b96ad6cf56daba3e2a/image-20260714-130850.png?cb=b9c2e8f094400a23451ae956b4de259a)

Enter your Tenant/Account Name and proceed to activation

​

8. T-Mobile Auto-Attach application will be live and you are offloading carrier traffic to your network.​

*** ** * ** ***

## REFERENCE

For more information about OpenRoaming in a Cisco Spaces setup, see the following documents:

* [++*Cisco Spaces OpenRoaming Setup Guide*++](https://dnaspaces.cisco.com/setupguide/app-open-roaming/)

* [++*Cisco Spaces Connector Configuration Guide*++](https://www.cisco.com/c/en/us/td/docs/wireless/cisco-dna-spaces/connector/config/b_connector/m_dnaspacesconnector.html)

* [++*Cisco Spaces Configuration Guide*++](https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Mobility/DNA-Spaces/cisco-dna-spaces-config/dnaspaces-configuration-guide.html)

For all Cisco Spaces documentation, see:

<https://www.cisco.com/c/en/us/support/wireless/dna-spaces/series.html>

---
language: "en"
---
# Cisco Spaces OS Day 2 Guide

## INTRODUCTION

This guide helps Cisco Spaces administrators keep a Cisco Spaces OS deployment healthy after the initial setup is complete. Use it for routine monitoring, maintenance, troubleshooting, and support escalation across the Cisco Spaces platform foundation.

The guide assumes that Cisco Spaces OS has already been deployed using the Cisco Spaces OS runbook and that the required wireless, map, connector, integration, and API components are in production.

*** ** * ** ***

## SCOPE

Use this guide to operate and troubleshoot:

* Cisco Spaces tenant and admin access

* Cisco Spaces Connector instances

* Connector control and data channels

* Catalyst wireless controller and Catalyst Center integrations

* Meraki network and map integrations

* Webex device integration

* Location hierarchy and digital maps

* Location, IoT, and local Firehose services on the connector

* API keys and downstream integrations

* Support case preparation and escalation

This guide does not replace the deployment runbook. For initial onboarding, feature enablement, or design prerequisites, use the [Cisco Spaces OS runbook](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated).

*** ** * ** ***

## OPERATIONAL OUTCOMES

A healthy Cisco Spaces OS environment should provide these ongoing outcomes:

* Cisco Spaces administrators can sign in and manage the tenant.

* Each production connector is online and shows healthy control and data-channel status.

* Wireless controllers and networks continue sending the expected telemetry.

* Catalyst Center, Meraki, and Webex integrations remain synchronized.

* Location hierarchy, floors, AP placement, and maps stay current after site changes.

* IoT Services, Location Services, and Local Firehose operate as expected where enabled.

* API keys and downstream integrations are valid, owned, rotated, and monitored.

* Operational teams can detect, triage, and escalate service-impacting issues quickly.

*** ** * ** ***

## MONITORING MODEL

Use the built-in Cisco Spaces dashboards as the primary monitoring surface, and supplement them with connector-local monitoring when the deployment needs external alerting.  

|             Area              |                     Primary check                      |              Cadence              |                             Healthy signal                             |                                    Action when unhealthy                                     |
|-------------------------------|--------------------------------------------------------|-----------------------------------|------------------------------------------------------------------------|----------------------------------------------------------------------------------------------|
| Tenant access                 | Admin sign-in and role access                          | Weekly and after identity changes | Authorized admins can sign in and reach required menus                 | Validate SSO, roles, user state, and recent identity-provider changes                        |
| Connector availability        | Connector list and connector detail page               | Daily                             | Connector is online; control and data channels are connected           | Follow connector-down triage and collect diagnostics                                         |
| Connector resource health     | Connector dashboard or monitoring API                  | Daily; more often for large sites | CPU, memory, disk, and data rates are within the site baseline         | Check capacity, recent data-rate changes, service status, and host resources                 |
| Wireless controller telemetry | Wireless network, controller, and connector status     | Daily                             | Expected controllers are active and sending data                       | Validate controller reachability, configuration, certificates, and recent controller changes |
| Location hierarchy            | Location hierarchy and floor views                     | Weekly and after site changes     | Sites, buildings, floors, and AP placement match the production estate | Reconcile hierarchy, maps, and source-of-truth updates                                       |
| Digital maps                  | Map import and floor-map review                        | Monthly and after floor changes   | Current maps are present and AP markers are correctly placed           | Reprocess or update maps and verify AP placement                                             |
| Catalyst Center integration   | Integration status and sync recency                    | Weekly                            | Sync completes and managed sites/devices appear as expected            | Check credentials, reachability, permissions, and source-system changes                      |
| Meraki integration            | Integration status, network tags, and map/floor data   | Weekly                            | Tagged networks, maps, floors, APs, and telemetry are present          | Review tags, API access, map metadata, and Meraki org/network state                          |
| Webex integration             | Webex connector status and room/device data            | Weekly                            | Expected org, workspaces, devices, and room data are available         | Validate authorization, room inventory, and device assignment                                |
| IoT Services                  | IoT Services dashboard and detailed status             | Daily where used                  | WLCs, AP gateways, BLE gateways, and enabled services are healthy      | Follow IoT Services triage and check affected controller/AP groups                           |
| Local Firehose                | Local Firehose service metrics and downstream receiver | Daily where used                  | Events are delivered at expected rate with no sustained backlog        | Validate API key, receiver reachability, service status, and event rate                      |
| APIs and consumers            | API key inventory and downstream checks                | Monthly; after key changes        | Active keys are owned, documented, and used only by expected consumers | Rotate or disable unknown keys and validate consumer configuration                           |

*** ** * ** ***

## CONNECTOR HEALTH MONITORING API

For deployments that use external monitoring, configure the monitoring platform to poll the connector-local monitoring endpoint:

    GET https://<connector-fqdn-or-ip>/api/connector/v1/monitoringdata
    Authorization: Bearer <connector-api-key>

Generate the API key from the connector user interface and store it in the monitoring platform as a secret. Do not embed the key in scripts, tickets, or shared documentation.

Monitor at least these signals:  

|         Signal         |                               Why it matters                                |                         Suggested alert behavior                          |
|------------------------|-----------------------------------------------------------------------------|---------------------------------------------------------------------------|
| Connector reachability | Confirms the monitoring platform can reach the connector                    | Alert when polling fails for two or more consecutive intervals            |
| CPU usage              | Sustained high CPU can indicate undersized resources or unusual data volume | Alert when usage remains above the site baseline for 15 minutes           |
| Memory usage           | Sustained high memory can affect connector services                         | Alert when usage remains above the site baseline for 15 minutes           |
| Disk usage             | Full disks can affect logs, diagnostics, and service operation              | Alert before the disk reaches the local operational limit                 |
| Controller count       | Confirms expected controllers remain connected                              | Alert when active controller count drops below the site baseline          |
| Location update rate   | Confirms expected telemetry volume                                          | Alert on sustained zero rate or large deviation from normal site behavior |
| Data rate              | Helps detect unexpected loss or spikes in telemetry                         | Alert on sustained zero rate or unusual spikes after change windows       |
| gRPC connectivity      | Confirms cloud communication paths                                          | Alert when cloud communication is disconnected or unstable                |

Start with conservative thresholds based on the site's normal weekday and weekend patterns. After two to four weeks, tune thresholds so alerts identify real degradation without creating noise.

*** ** * ** ***

## ROUTINE OPERATIONS

### Daily Checks

1. Open Cisco Spaces and confirm the tenant loads normally.

2. Review connector status for each production connector.

3. Confirm control-channel and data-channel status are healthy.

4. Check the connector dashboard for CPU, memory, disk, and service health.

5. Review wireless controller status and verify the expected controllers are active.

6. For deployments using IoT Services, review the IoT Services dashboard and detailed status pages.

7. For deployments using Local Firehose, confirm events are flowing to the downstream receiver.

8. Check recent alert tickets or monitoring alerts and compare them with any planned change windows.

### Weekly Checks

1. Review Catalyst Center, Meraki, and Webex integration status.

2. Confirm recently added or changed sites, buildings, floors, APs, and maps are reflected in Cisco Spaces.

3. Review API key ownership and confirm new keys were created through the approved change process.

4. Check connector service metrics for unusual data-rate, location-rate, or resource trends.

5. Verify that alert recipients and operational ownership are still current.

### Monthly Checks

1. Review connector software and service versions against the supported deployment standard.

2. Validate connector host capacity against current controller, AP, client, IoT, and Firehose volume.

3. Review stale admins, stale API keys, and unused integrations.

4. Confirm maps and AP placement remain aligned to facilities changes.

5. Confirm support contacts and escalation paths are current.

6. Review recurring incidents and convert repeated manual fixes into monitoring, automation, or change-control improvements.

### After-Change Checks

Run these checks after wireless controller upgrades, Catalyst Center changes, Meraki changes, Webex authorization changes, SSO changes, map imports, connector upgrades, firewall changes, or API key rotations.

1. Confirm Cisco Spaces sign-in and role access.

2. Confirm connector online status and control/data-channel health.

3. Confirm expected controllers, APs, floors, and maps remain visible.

4. Confirm integration sync has completed.

5. Confirm IoT Services, Location Services, Local Firehose, and API consumers are still receiving expected data.

6. Record the validation result in the change record.

*** ** * ** ***

## MAINTENANCE TASKS

### Connector Maintenance

1. Maintain an inventory of each connector, including hostname, IP address, site ownership, monitored controllers, services enabled, and operational owner.

2. Review connector health before and after upgrades or host maintenance.

3. Keep connector access limited to approved administrators.

4. Rotate connector-local API keys through the approved change process.

5. Download diagnostics before disruptive troubleshooting when a connector is degraded and support escalation may be needed.

6. Keep connector resource sizing aligned to the production telemetry volume.

### Integration Maintenance

1. Document the owner, purpose, credential type, and renewal process for each integration.

2. Review integration health after source-system changes.

3. Remove unused integrations and disable unused API keys.

4. Keep integration credentials and API keys out of shared tickets and runbooks.

5. Validate downstream consumers after any key rotation, receiver change, or firewall change.

### Location and Map Maintenance

1. Treat location hierarchy and digital maps as operational data that must be maintained after site changes.

2. Reconcile new, renamed, moved, or retired sites and floors with the source of truth.

3. Verify AP placement after floor-plan changes, AP replacements, or map reimports.

4. Reprocess or update maps when the production floor layout changes.

5. Validate user-facing outcomes that depend on maps and AP placement after the update is complete.

### Alert and Incident Maintenance

1. Maintain baseline telemetry rates for each major site or connector.

2. Review alert thresholds after large AP, controller, or service changes.

3. Keep the incident runbook owner and escalation list current.

4. Link repeated incidents to corrective actions rather than treating them as isolated events.

*** ** * ** ***

## TROUBLESHOOTING WORKFLOW

Use this workflow before jumping into component-specific troubleshooting:

1. Identify the affected outcome. Examples: missing location data, connector offline, maps stale, IoT service degraded, Local Firehose not delivering events, or API consumer not receiving data.

2. Identify the scope. Determine whether the issue affects one floor, one building, one site, one connector, one controller, one integration, or the whole tenant.

3. Check recent changes. Review controller, firewall, DNS, SSO, connector, integration, map, and API-key changes.

4. Check Cisco Spaces dashboards. Confirm the affected component status and any related alerts.

5. Check connector health. Validate control/data channels, service status, resource usage, and logs.

6. Validate the upstream source. Confirm controllers, Catalyst Center, Meraki, or Webex are healthy and reachable.

7. Validate the downstream consumer. Confirm the application, receiver, or monitoring tool can authenticate and receive data.

8. Capture evidence. Record timestamps, affected scope, screenshots, logs, monitoring output, and recent changes.

9. Escalate with diagnostics if the issue persists or has business impact.

*** ** * ** ***

## COMMON TROUBLESHOOTING SCENARIOS

### Connector Is Offline or Degraded

Symptoms:

* Connector status shows offline, disconnected, or degraded.

* Control channel or data channel is not connected.

* External monitoring cannot poll the connector monitoring endpoint.

* Multiple dependent services stop receiving data.

Checks:

1. Confirm the connector VM or host is powered on and reachable.

2. Confirm DNS, default gateway, proxy, firewall, and certificate inspection changes.

3. In Cisco Spaces, open the connector detail view and review control-channel and data-channel status.

4. In the connector UI, review service status, CPU, memory, disk, and logs.

5. Confirm the connector can reach the Cisco Spaces cloud endpoints required by the deployment.

6. Confirm upstream controllers are still reachable from the connector.

7. Download diagnostics if the issue is not immediately resolved.

Resolution:

1. Restore network reachability or host resources.

2. Restart only the affected connector service when instructed by product documentation or support.

3. If the connector remains degraded, open a support case with diagnostics and recent change details.

### Connector Resource Usage Is High

Symptoms:

* CPU, memory, or disk usage is persistently above baseline.

* Location update rate or data rate is much higher than normal.

* Connector services become slow or unstable.

Checks:

1. Compare the current controller, AP, client, IoT, and Firehose volume with the sizing assumptions used at deployment.

2. Check whether a recent site, controller, AP, or service expansion changed the connector workload.

3. Review connector service metrics for the service driving the increase.

4. Review disk usage and diagnostic/log retention.

Resolution:

1. Reduce unexpected traffic sources if the spike is caused by a misconfiguration.

2. Increase connector resources or redistribute workload if production volume has grown.

3. Tune external alert thresholds after the new normal is confirmed.

### Wireless Controller Telemetry Is Missing

Symptoms:

* A controller is absent, inactive, or degraded.

* A site or floor stops receiving location updates.

* APs tied to a controller do not appear as expected.

Checks:

1. Confirm the controller is online and healthy in the wireless management system.

2. Confirm the connector can reach the controller.

3. Confirm required controller settings, credentials, certificates, and telemetry protocols remain configured.

4. Check for controller upgrades, certificate changes, firewall changes, or management IP changes.

5. Compare affected sites/floors with the controllers that serve them.

Resolution:

1. Restore controller reachability and credentials.

2. Revalidate connector-to-controller connectivity.

3. Confirm telemetry resumes and the affected location hierarchy updates.

### Catalyst Center Sync Is Stale or Incomplete

Symptoms:

* Expected sites, floors, devices, or maps from Catalyst Center do not appear in Cisco Spaces.

* Integration sync fails or does not reflect recent source changes.

Checks:

1. Confirm Catalyst Center is reachable and healthy.

2. Confirm integration credentials and permissions are valid.

3. Review whether the source hierarchy, devices, or maps changed recently.

4. Check whether the expected site or device is in a supported scope for the integration.

Resolution:

1. Correct credentials, reachability, or permissions.

2. Re-run or wait for the next supported sync cycle.

3. Validate the location hierarchy, floors, maps, and AP placement after sync completes.

### Meraki Data or Maps Are Missing

Symptoms:

* Expected Meraki networks, maps, floors, or APs do not appear.

* Map or AP metadata is stale.

* Meraki telemetry is absent for a site.

Checks:

1. Confirm the Meraki integration is authorized and healthy.

2. Confirm the expected organization and networks are in scope.

3. Confirm required network tags and map metadata are still present.

4. Confirm APs are online in Meraki and assigned to the expected network and floor.

Resolution:

1. Correct integration authorization, network scope, or tags.

2. Correct source map or AP metadata.

3. Validate the affected floors in Cisco Spaces after sync.

### Webex Device or Workspace Data Is Missing

Symptoms:

* Expected Webex devices, rooms, or workspaces are missing.

* Room occupancy or environmental data is not available where expected.

Checks:

1. Confirm the Webex integration is authorized.

2. Confirm affected devices are assigned to the expected workspaces.

3. Confirm the devices are online and reporting in Webex.

4. Confirm the Cisco Spaces location hierarchy maps the devices to the expected site, building, or floor.

Resolution:

1. Correct Webex authorization or device assignment.

2. Revalidate the integration.

3. Confirm the affected data appears in the expected Cisco Spaces outcome.

### Digital Maps Are Stale or Incorrect

Symptoms:

* Floor maps do not match the physical layout.

* AP markers are missing, duplicated, or misplaced.

* Location outcomes are inaccurate after floor changes.

Checks:

1. Confirm whether a facilities or wireless change occurred.

2. Review the floor map and AP marker placement.

3. Confirm the correct floor is associated with the site and building.

4. Confirm AP names and identifiers match the wireless source of truth.

Resolution:

1. Update or reimport the map.

2. Correct AP placement and floor association.

3. Validate location-dependent outcomes after the map update.

### IoT Services Are Degraded

Symptoms:

* IoT Services dashboard shows degraded status.

* AP gateway, BLE gateway, or service activation status is unhealthy.

* IoT devices are not discovered or updated as expected.

Checks:

1. Review the IoT Services detailed status pages.

2. Identify whether the issue affects one WLC, one AP group, one floor, or all IoT Services.

3. Confirm the affected WLCs and APs are online.

4. Confirm connector service status and resource usage.

5. Check whether AP or controller upgrades, policy changes, or network changes occurred.

Resolution:

1. Restore WLC/AP health and connector reachability.

2. Correct gateway or service activation issues.

3. Validate device discovery or updates after recovery.

### Local Firehose Events Are Not Delivered

Symptoms:

* Downstream receiver does not receive expected events.

* Local Firehose service metrics show no events or abnormal rates.

* The receiver reports authentication or connectivity errors.

Checks:

1. Confirm Local Firehose is enabled and healthy on the connector.

2. Confirm the downstream receiver is reachable from the connector.

3. Confirm the Local Firehose API key is valid and used by the expected consumer.

4. Review Local Firehose service metrics for event rate, failures, or sustained gaps.

5. Check firewall, DNS, certificate, and receiver changes.

Resolution:

1. Restore receiver reachability or authentication.

2. Rotate the API key if it is expired, exposed, or no longer trusted.

3. Validate event delivery with a known test window.

### API Consumer Fails After Key Rotation

Symptoms:

* A downstream application returns authorization errors.

* Data flow stops immediately after a key change.

Checks:

1. Confirm which API key was rotated and which consumers were expected to update.

2. Confirm the consumer is using the new key and the correct endpoint.

3. Confirm the old key was disabled only after consumers moved to the new key.

4. Check consumer logs for authentication, rate-limit, or endpoint errors.

Resolution:

1. Update the consumer secret and redeploy or restart the consumer as required.

2. Validate data flow.

3. Disable the old key after all consumers are confirmed healthy.

### Cisco Spaces Support Case Is Needed

Open a case when:

* A production connector remains offline or degraded after local triage.

* A Cisco Spaces outcome has sustained business impact.

* The issue appears to be a Cisco Spaces cloud, connector, or product defect.

* Support-directed service restart, log review, or recovery action is required.

Collect:

* Tenant name and account details

* Affected site, building, floor, connector, controller, APs, integration, and outcome

* Start time, time zone, and whether the issue is ongoing

* Business impact and urgency

* Recent changes

* Screenshots of status pages

* Connector diagnostics and logs

* External monitoring output, if available

* Steps already taken

Use the Cisco Spaces support entry point in the dashboard or [Cisco.com](http://cisco.com/) support workflow. Set the severity based on business impact and Cisco support severity guidance.

*** ** * ** ***

## VALIDATION AFTER RECOVERY

After resolving an incident, validate the full data path:

1. Confirm the affected component status is healthy in Cisco Spaces.

2. Confirm connector resource usage returned to baseline.

3. Confirm upstream controllers, networks, APs, maps, or integrations are healthy.

4. Confirm downstream applications or APIs receive expected data.

5. Confirm the affected business outcome has recovered.

6. Update the incident record with root cause, recovery steps, and preventive actions.

*** ** * ** ***

## DOCUMENTATION AND CHANGE CONTROL

Maintain these records for each Cisco Spaces OS environment:

* Tenant and subscription ownership

* Admin owners and backup owners

* Connector inventory and service ownership

* Controller, Catalyst Center, Meraki, and Webex integration ownership

* Location hierarchy and map source of truth

* API key inventory, owner, consumer, and rotation date

* Monitoring thresholds and alert recipients

* Support contacts and escalation process

* Known limitations, accepted risks, and recurring corrective actions

*** ** * ** ***

## FAQ'S

### How often should connector health be checked?

Check connector status daily in Cisco Spaces. Use external monitoring for production environments where connector or data-path degradation must create an operational alert.

### What is the best first signal for connector health?

Start with connector online status, control-channel status, data-channel status, and connector resource health. If external monitoring is available, add the connector monitoring API.

### Should every site use the same monitoring thresholds?

No. Establish a local baseline for each major site or connector. Large sites, sites with IoT Services, and sites using Local Firehose may have different normal data-rate and resource patterns.

### What should be checked after a wireless controller upgrade?

Confirm controller health, connector reachability, control/data-channel status, location update rate, affected floor data, and any services that depend on controller telemetry.

### What should be checked after a map update?

Confirm the correct floor map appears, AP markers are placed correctly, the location hierarchy is accurate, and dependent outcomes still show expected data.

### What should be done before rotating an API key?

Identify all consumers, stage the new key, update consumers during a change window, validate data flow, and then disable the old key.

*** ** * ** ***

## SUPPLEMENTARY INFORMATION

* [Cisco Spaces OS Runbook](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated)

* [Cisco Spaces Day 2 Runbooks](https://runbooks.ciscospaces.io/docs/cisco-spaces-day-2-runbooks)

* [Cisco Spaces Connector Troubleshooting](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/connector/config/b_connector_30/m-troubleshooting1.html)

* [IoT Services Deployment, Monitoring, and Troubleshooting](https://runbooks.ciscospaces.io/docs/iot-services-deployment-monitoring-and-troubleshoo#DAY-N---TROUBLESHOOTING-AND-MONITORING)

* [Cisco Spaces Support Update](https://activate.dnaspaces.io/hubfs/Assets/CiscoSpaces-SupportUpdate.pdf)

* [Cisco Spaces Developer Documentation](https://developer.cisco.com/docs/dna-spaces/)

---
language: "en"
---
# Cisco Spaces OS Runbook (Cisco Validated)

## OVERVIEW

This Cisco Validated overview document will aid in configuring Spaces OS, ensuring a robust infrastructure that underpins a Cisco Spaces deployment.

Cisco Spaces OS serves as the foundational layer for deploying and managing intelligent location-based services within an organization. As the essential base installation, Spaces OS integrates a suite of critical components designed to streamline operations and enhance data utilization.

By onboarding data through platforms like Catalyst Center, Wireless LAN Controller (WLC), and Meraki, Spaces OS ensures seamless connectivity and comprehensive data capture. It facilitates the configuration of a unified location hierarchy and merges data from diverse sources to provide a cohesive spatial understanding. Additionally, Spaces OS supports the creation of detailed Digital Maps, offering a visual representation of spaces for better navigation and planning. With the capability to enable IoT streaming services, Spaces OS empowers organizations to leverage real-time data insights for improved decision-making and operational efficiency.  
![image-20260612-103404.png](https://runbooks.ciscospaces.io/__attachments/a_b1726fc90a98b3acc229e59d77be4d1221a268201713cd8e63346cd0f9fe547b/image-20260612-103404.png?cb=370b51067f072a473fd13b79967ae813)

### SUPPORT \& ONBOARDING INFO

Please follow the link below to find out about the different ways to get support for Cisco Spaces: [Support Info Link](https://activate.dnaspaces.io/hubfs/Assets/CiscoSpaces-SupportUpdate.pdf?__hstc=105720540.52aaa4a978f36be89855b002cb35bfc4.1729705805310.1729705805310.1729705805310.1&__hssc=105720540.1.1729705805310&__hsfp=3667649010)​

*** ** * ** ***

## SPACES OS INSTALLATION

To complete Spaces OS installation, an admin will require read/write for Cisco Spaces, as well as Catalyst Center, WLC, Meraki Dashboard and Webex Control Hub, or as many as applicable within the environment.

### Onboarding Cisco Devices for Intaking Telemetry \& Data

![image-20260612-105844.png](https://runbooks.ciscospaces.io/__attachments/a_b4970a1be87eaaaf33a43653f7c9726d626da780a943ffbe52910e944994791d/image-20260612-105844.png?cb=967a8d74735bedd422edc1b219ff22cf)

#### Overview

Onboarding data relates to the methods for connecting the telemetry data from the infrastructure to the Spaces dashboard.

Steps below should be completed for as many infrastructure stacks as available - the more data we feed into Spaces, the more valuable the outcomes can become.
Catalyst Wireless  

#### Catalyst Wireless

##### *Spaces Connector*

In order to connect the wireless network with Cisco Spaces, Cisco Spaces Connector should be installed on a virtual machine. The Spaces Connector supports VMware ESXi 6.5 or above versions, as well as [++AWS AMI++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/connector/2-x/config/b_connector/m_ami.html), [++Nutanix++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/connector/config/b_connector_30/m_connector-vm-on-nutanix-environment.html), and [++HyperV++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/connector/config/b_connector_30/m_hyper-v3.html).

For more Connector VM options and details please review the [++Connector Configuration++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/connector/config/b_connector_30/m_initialsetup_30.html) page.

The connector supports the Production configuration with the VM requirement as follows:  
**It is highly recommended that 8 vCPU be used when possible. Using fewer resources is possible but may restrict the ability to run certain services.**

**Connector Configurations**  

|                | **Production** |
|----------------|----------------|
| vCPU           | 8              |
| Memory (GB)    | 16             |
| Hard Disk (GB) | 120            |

**Connector Scaling**  

|                                               |                                |   **Production**   |
|-----------------------------------------------|--------------------------------|--------------------|
| **Location only**                             | **AP Count**                   | 15,000             |
| **Location only**                             | **Client Count**               | 150,000            |
| **Location only**                             | **Message Rate**(NMSP msg/sec) | 38,000             |
| **IoT Services** **(Recommended Adv 1 \& 2)** | **GRPC connection** (AP count) | 3,000 (hard limit) |
| **IoT Services** **(Recommended Adv 1 \& 2)** | **Client Count**               | 30,000             |
| **IoT Services** **(Recommended Adv 1 \& 2)** | **Message rate**(BLE msg/sec)  | 170,000            |

For connector scaling please refer to the use cases in the table.

* Standard configuration provides scaling information for location only per the capacity details provided

* Running IoT services in addition to location services Cisco Spaces recommends the Production configuration, per the capacity details provided

++**Connector Scaling and Sizing Best Practices**++

* Start with **Production** and scale down as needed

* Don't let CPU and memory go above 75%

* Adding new services will add additional load

* Keep an eye on the message rate - add mac prefix filtering as a best practice (can be done via a [++support case++](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated#CiscoSpacesOSRunbook(CiscoValidated)-SUPPORT&ONBOARDINGINFO))

Tested VMware Environments

* VMware ESXi: 6.5.0 Update 2 (Build 13004031), 6.7.0 Update 2 (Build 13006603)

* VMware vSphere Client Version 6.7.0

* VMware vCenter Server Appliance 6.7.0

The Cisco Spaces Connector should be able to reach out to the Cisco Spaces endpoints for establishing data connectivity with Cisco Spaces.
For Global Setup (IO)  
The Cisco Spaces Connector must be able to reach out to [++https://connector.dnaspaces.io/++](https://connector.dnaspaces.io/)

Primary IP Adresses: 52.20.144.155, 34.231.154.95

Disaster Recovery IP Addresses: 54.176.92.81, 54.183.58.225
For EU Setup (EU)  
The Cisco Spaces Connector must be able to reach out to [++https://connector.dnaspaces.eu/++](https://connector.dnaspaces.eu/)

Primary IP Adresses: 63.33.127.190, 63.33.175.64

Disaster Recovery IP Addresses: 3.122.15.26, 3.122.15.7
For Singapore Setup (SG)  
The Cisco Spaces Connector must be able to reach out to [++https://connector.ciscospaces.sg/++](https://connector.ciscospaces.sg/)

Primary IP Adresses: 13.228.159.49, 54.179.105.241

Disaster Recovery IP Addresses: 13.214.251.223, 54.255.57.46

The Cisco Spaces Connector must be able to communicate to the WLC on ports:

Normal Operations

* 16113 TCP (NMSP)

* 830 TCP (NETCONF) -- only for Catalyst Controllers

* 22 TCP (SSH)

* (optional) 2003 UDP (FastLocate)

IOT Services

* 8004 TCP (TDL)

* 8184 TCP (TDL)

For IOT Services, Spaces Connector and APs must be able to communicate on the following ports:

* 8443 TCP (IOX App Install)

* 8000 TCP (gRPC and REST API calls)

**The above is of particular note to customers with public/private cloud environments**  
![Screenshot 2025-03-11 at 7.11.04 PM.png](https://runbooks.ciscospaces.io/__attachments/a_9a85baacf5b56b7528c8a1fe894eb0ff4e19e789457adb86729a2f7b74ac97fb/Screenshot%202025-03-11%20at%207.11.04%E2%80%AFPM.png?cb=76fbc58f4662bf070e1d2fdb9d908793)  
**For an in-depth guide into the connector please refer to our** [++**Configuration Guide**++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/connector/config/b_connector_30/m_ova_30.html)**.**

The first steps in setting up the Connector are as follows.  
It is always recommended, if not required for some outcomes, to use the latest version of the Connector available.

[++***Click here for a video guided demo***++](https://youtu.be/JQVplmA_97U)

1. Download the Cisco Spaces Connector OVA from here: [++Cisco Spaces OVA++](https://software.cisco.com/download/home/286323456/type/286322783/)

2. Deploy the downloaded Cisco Spaces OVA file on a virtual machine.

3. Once the OVA is deployed, log into the VMware console using the default username and password provided in the console, username: root Password:root

4. Enter the network settings.

5. Optional: Enter NTP settings.

6. Set the password for *spacesadmin* user.

7. When prompted, reboot the device and open the WebUI using the address provided.

8. Log into the Cisco Spaces dashboard, click on **Setup** on the Menu.

9. Select **Wireless Networks**.

10. Click on **Add New** button .

11. Select **Cisco AireOS/Catalyst**.

12. Select **via Spaces Connector** , then select **Continue Setup** button.

13. Under step 2 **Configure Spaces Connector** , click on **Create Connector**.

14. In the **Connector Name** field, enter a name for the connector and click on **Create**.

15. On step 2 **Configure Spaces Connector** , click on **View Connectors**.

16. A list of Connectors that have been created will be seen. Select the desired Connector.

17. Click on **Generate Token**.

18. Copy the token that appears on the following screen of the Cisco Spaces dashboard.

19. Launch the Cisco Spaces Connector using the HTTP address provided at the OVA deployment, https://\< IP-address \>/. In the Cisco Spaces Connector window that opens up, enter the username and password that was configured earlier.

20. On **Configure connector** place the token, and click **save**.

It may be needed to wait a few minutes for Cisco Spaces connector to start as images may take some time to download. The wait time is dependent on the speed of the connection

The Connector setup is now complete.

This is how the Connector Dashboard and Cisco Spaces Dashboard will look like once the connector is active.  
The connector can be deployed in a [++High Availability configuration++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/connector/config/b_connector_30/m-vip-paired.html). See the linked guide for instructions and restrictions.

**Connector Dashboard**  
![Connector 1.png](https://runbooks.ciscospaces.io/__attachments/a_efa613071f9b5fc0f9abbba1afa4f14ef93cdf7a2322c9f35f2d091d64f51702/Connector%201.png?cb=109e070321577cafca9758e62620d9d0)  
![Connector 2.png](https://runbooks.ciscospaces.io/__attachments/a_4458f5871468d00238df08b83da1d5fe7f1ef4f67c3f32295bb7a7df2d9aee81/Connector%202.png?cb=14edb16ace9b3b7aac2d87d4f9782815)

*Control Channel: Health of connection between Cisco Spaces Connector and Cisco Spaces Cloud.*

*Data Channel: Health of connection between Cisco Spaces Connector and Cisco Spaces Cloud.*

**Cisco Spaces Dashboard**  
![image-20260624-092404.png](https://runbooks.ciscospaces.io/__attachments/a_8fa331e4c94d65130b0b4353a34b4031a759d922ac14f885d36d6095f30d5d58/image-20260624-092404.png?cb=cecb84f6970e7e01087d945624c6bb0b)  
If a more in-depth guide is needed for granular configurations please refer to our [++Configuration Guide++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/connector/config/b_connector_30/m_overview_30.html).

##### *WLC*

Recommended firmware versions are 17.12.4+ and 17.15.x

Now the Spaces connector is configured, WLC can be added to Spaces.

1. On the Customized Setup page step 3, click on **Add Controllers**

2. Select the Connector that was just created from the drop-down

3. Add the IP address of the Controller

4. Add the name of the Controller

5. Select Controller Type

6. Add details based on the controller type.

   For AireOS WLC -- Select Controller SNMP version depending on the controller's SNMP version. Read/Write permissions are needed for V2C and V3

   * For V2C SNMP, provide SNMP Community.

   * For V3 SNMP, provide username, password, select authentication Protocol and enter Privacy password.

   * Enabling the WSA tickbox is used for WIPS purposes in Spaces.

   For Catalyst WLC / Catalyst 9800 -- Add the following credentials
   * Enter Netconf Username and Password.

   * Enter Enable password of the controller.

   * Verify the interface: NMSP will only be sent from the interface configured as the "wireless management interface". Interfaces used as a service-port (e.g., gig0/0 for an appliance) cannot send NMSP traffic.

7. Click on the **Test Connectivity** button.

8. Click **Save \& Add Next Controller** if needing to add another controller. If not, click **Save \& Close**.

This is how the Spaces dashboard should look once the controller and connector are active.  
![WLC Integration.png](https://runbooks.ciscospaces.io/__attachments/a_9ceeb9fe1c1a5ae1181fa93fe0e8df04e06b833152edd090c9be419c86ae792b/WLC%20Integration.png?cb=1766a6befd4697326851fa4523c609f6)  
For an in-depth guide into integrating wireless please refer to our [++Configuration Guide++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m_wlc-config.html).

##### *Catalyst Center*

Integrating Catalyst Center with Cisco Spaces is the easiest way to setup Spaces for any Catalyst based deployment.

Prerequisites follow:

* Catalyst Center, Release 2.1.2.3 or higher.

* Catalyst Center must be able to connect to [++https://dnaspaces.io:443++](https://dnaspaces.io/) for the initial activation. It may **also** require access to other regions depending on the Cisco Spaces account region.

  See below for more details:

  * [++https://dnaspaces.io:443++](https://dnaspaces.io/) (IO deployments)

  * [++https://dnaspaces.io:443++](https://dnaspaces.io/) and [++https://dnaspaces.eu:443++](https://dnaspaces.eu/) (EU deployments)

  * [++https://dnaspaces.io:443++](https://dnaspaces.io/) and [++https://dnaspaces.sg:443++](https://dnaspaces.eu/) (SG deployments)

* Floor plans with accurately placed APs inluding heights and angles accordingly. See <https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/catalyst-center/2-3-7/user_guide/b_cisco_catalyst_center_user_guide_237/m_work-with-wireless-2d-and-3d-maps.html> for more details.

GPS markers are crucial to Spaces use cases.

It is reccomended to leverage the Network Map Calibration tool within Spaces rather than Catalyst Center for placing GPS markers.

If placing GPS markers on Catalyst Center, ensuring high accuracy is crucial for a number of use cases.

1. Log in to Cisco Spaces, and navigate to **Integrations.**

2. **Under Integrations** \>**Cisco** \>**Catalyst Center** select Connect. The Catalyst Center integration will show.

3. When the window appears, click **Add Instance.**

4. In the dialogue box, input a new instance nameand then click **Generate**.

5. Log in to Catalyst Center, and navigate to **System** \>**Settings** \>** External Services** \>**CMX Servers/Cisco Spaces**.

6. Next to Cisco Spaces, click **Activate** , then paste the token into the dialogue box and click **Connect** .

   This should now show a success notification, and the status should show as Activated.

   ![image-20241115-110744.png](https://runbooks.ciscospaces.io/__attachments/a_1bfe21ba2567db0991407ade9e0ea685e519c477a4ea3684e6a3babf7751415d/image-20241115-110744.png?cb=a9bda2b5a4a5bb92d9058c78b8913cfb)

7. Now navigate to **Design** \>**Network Settings**, and select a location that should be pulled through to Cisco Spaces. Suggestion is to configure at a global level if possible.

8. Click the **Wireless**tab, then in the Cisco Spaces/CMX Server area, choose the service that was configured. This will now trigger a dynamic sync over to location hierarchy within Cisco Spaces.

![image-20241115-111210.png](https://runbooks.ciscospaces.io/__attachments/a_f9dad658ed2749e4b87aeb2b1eb36ab4011f253c1c79a9f20f46e3d4d3f8d3d8/image-20241115-111210.png?cb=e8df228e9464f031710e228975473e19)

Confirmation of this can be found in Cisco Spaces, under **Setup** \>**Locations \& Maps** \>**Recent Activity**  
![image-20260623-092206.png](https://runbooks.ciscospaces.io/__attachments/a_3b871aba43ff2aab596f15551e7fe578eac4e95e05f048d86ace02ba2f27ce6f/image-20260623-092206.png?cb=7493eeb596c8dbd7b76d6c47420ab0e4)

For an in-depth guide into the integrating with Catalyst Center please refer to our [++Configuration Guide++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m_dnac.html).
Meraki Wireless  

#### Meraki Wireless

This integration enables to seamlessly connect the Meraki Account to Cisco Spaces via the Meraki Dashboard -- in just a few clicks.

There will be an option to select to integrate into an existing Spaces account if you have one,or to create a new one.

**Meraki Wireless Prerequisites**

* Meraki Organization admins with read/write access (SAML admins are not supported)

* One building per network

* Floor maps placed accurately against real world both in scale and location

For optimal performance and being able to use all Cisco Spaces capabilities, it is preferred that the Meraki setup have maps with APs placed on them. However, if there are no maps with APs placed on them, Cisco Spaces core analytics features and seamless onboarding features will work.

* APs placed accurately on floor maps. Follow these articles to place APs accurately

  * [++https://documentation.meraki.com/Platform_Management/Dashboard_Administration/Operate_and_Maintain/Monitoring_and_Reporting/Placing_Devices_on_the_Map_in_Dashboard++](https://documentation.meraki.com/Platform_Management/Dashboard_Administration/Operate_and_Maintain/Monitoring_and_Reporting/Placing_Devices_on_the_Map_in_Dashboard)

  * [++https://documentation.meraki.com/Wireless/Design_and_Configure/Deployment_Guides/AP_Auto_Locate++](https://documentation.meraki.com/Wireless/Design_and_Configure/Deployment_Guides/AP_Auto_Locate)

* Meraki account must be in commercial domain ([++http://meraki.com++](http://meraki.com/)). Meraki accounts with the following domains are **not** **supported**:

  * Canada = [++meraki.ca++](http://meraki.ca/)

  * China = [++meraki.cn++](http://meraki.cn/)

  * India = [++meraki.in++](http://meraki.in/)

  * FedRamp = [++api.gov-meraki.com++](http://api.gov-meraki.com/)

* APs must be able to reach the following endpoints on port 1883

  * [++mqtt.dnaspaces.io++](http://mqtt.dnaspaces.io/) (For IO deployments)

  * [++mqtt.dnaspaces.eu++](http://mqtt.dnaspaces.eu/) (For EU deployments)

  * [++mqtt.dnaspaces.sg++](http://mqtt.dnaspaces.sg/) (For SG deployments)

Below are some references to help complete prerequisites:

* [++Meraki location deployment guide++](https://documentation.meraki.com/MR/Monitoring_and_Reporting/Location_Deployment_Guidelines)

* [++Adding floor plans in Meraki++](https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Using_a_Floor_Plan_or_Custom_Map_in_Dashboard)

* [++AP Auto Location guide++](https://documentation.meraki.com/MR/Deployment_Guides/AP_Auto_Locate)

* [++Meraki Integration FAQs++](https://documentation.meraki.com/MR/Cisco_Spaces_Integration/Seamless_Meraki_Integration_with_Cisco_Spaces)

To configure the Meraki Spaces Integration

1. Log in to the Meraki dashboard, Navigate to **Organization \> Integrations**

2. Go to Under the **Browse** tab, Click **"Connect"** on the **"Cisco Spaces"** tile

3. Under the Browse tab, Click **Connect** on the Cisco Spaces tile.

   ![Screenshot 2024-12-06 at 10.06.53 AM.png](https://runbooks.ciscospaces.io/__attachments/a_d3168293b1049539848a13872c87bf511dbccc3a827528aa02871c56c5926cf2/Screenshot%202024-12-06%20at%2010.06.53%E2%80%AFAM.png?cb=fdcda5e7df267d5135b90c4e15277b0a)

Option 1: Creating a New Spaces Account  
1. To create a new Cisco Spaces account, choose the option **Create a new Cisco Spaces Account** and click **Continue**.

Administrators can remove specific networks from syncing to Spaces by using Network Tags in the Meraki dashboard. By default all Meraki networks will sync to Spaces. However the Administrator can apply 'CiscoSpaces' as the tag name added to a Meraki network and only networks with 'CiscoSpaces' as the tag name will sync to Spaces.

[++Creating Network tags in Meraki++](https://documentation.meraki.com/General_Administration/Organizations_and_Networks/Organization_Menu/Manage_Tags#Creating_Network_tags)

2. Enter the Spaces Account Name and click on **Add Integration**. The Spaces Account Name is pre-filled with the Meraki Organization name and can be customized.

3. A new Cisco Spaces account with a unique tenant ID is created. This triggers an invitation email is sent from Cisco Spaces to the Org Admin email address that did the integration as well as anyone designated as a Meraki Organization Admin for the organization. This will also trigger all networks under that Meraki Organization to be synced with Spaces.

After the integration is complete it may take up to 24 hours for applications in Cisco Spaces to start populating analytics data

4. To access the newly created Cisco Spaces account, it is required to accept this invite and setup a password.

The Cisco Spaces welcome email is sent to the Meraki Org admin who triggered the Meraki Integration process. The email is valid for 5 days. The invitation email can be resent by navigating to Use this integration on the integration details page in the Meraki dashboard and clicking on Resend Invite.

5. Launch the Cisco Spaces dashboard from the integration's details page, review admins and manage networks.

Cisco Spaces Analytics applications will start working after the Meraki Org is fully sync'd with the Spaces account, this could take up to 24 hours for everything to fully sync after the integration is completed.
Option 2: Connecting to an Existing Spaces Account  
1. If a Cisco Spaces account already exists, link it to the Meraki Organization. Choose the option that states **Connect to existing Cisco Spaces Account** and click on **Continue**.

Administrators can remove specific networks from syncing to Spaces by using Network Tags in the Meraki dashboard. By default all Meraki networks will sync to Spaces. However the Administrator can apply 'CiscoSpaces' as the tag name added to a Meraki network and only networks with 'CiscoSpaces' as the tag name will sync to Spaces.

Creating Network tags in Meraki: [++https://documentation.meraki.com/General_Administration/Organizations_and_Networks/Organization_Menu/Manage_Tags#Creating_Network_tags++](https://documentation.meraki.com/General_Administration/Organizations_and_Networks/Organization_Menu/Manage_Tags#Creating_Network_tags)

2. Click on **Login**. The browser will be redirected to Cisco Spaces login page.

3. Enter credentials and click **Continue**.

4. Type or Choose the respective Cisco Spaces Account to connect to the Meraki Organization from the options listed.

5. Click **Select**.

6. Once selected to the Spaces account permission will be asked to connect the Cisco Spaces account to the Meraki Organization.

   Check the box next to **Import Meraki Administrators as Spaces Administrators** and click **Confirm**.
7. The Spaces Account selected is now linked to the Meraki Organization. This will trigger anyone designated as a Meraki Org Admin for the organization, to be added to the Spaces account as Spaces admin. This will also cause all networks under that Meraki Organization to be synced.

After the integration is complete it may take up to 24 hours for applications in Cisco Spaces to start populating analytics data.

8. Launch the Cisco Spaces dashboard from the integration's details page, review admins and manage networks.

Cisco Spaces Analytics applications will start working after the Meraki Org is fully sync'd with the Spaces account, this could take up to 24 hours for everything to fully sync after the integration is completed.
Removing the integration (when needed)  

##### *Removing the integration (when needed)*

1. To remove the integration, in Meraki dashboard, Navigate to **Organization** \>**Integrations** under the My integrations tab and select the Cisco Spaces integration.

2. From the integration details page select **Remove** in the top right corner.

3. Select **Confirm** to remove the integration.

Optional:To remove any Meraki networks from the Cisco Spaces account navigate to Location Hierarchy in the Cisco Spaces account, click the 3 dots to the right of the hierarchy and select **Delete Location**.

Once the integration is completed, navigate to Spaces\>Setup\>Wireless Networks. Under **Connect via Meraki Integration**, 1) Connect your Meraki, you should see a green icon next to your organization. Example:  
![image-20260611-160942.png](https://runbooks.ciscospaces.io/__attachments/a_d6fba2f2953b4b9cf1f408130087c0acdbec797f78257c6eb1ef3c214ce70ee7/image-20260611-160942.png?cb=f754047eb96986f45ffd30e9fa9f42a7)

Under 3) Import Meraki Networks into Location Hierarchy, verify that all of the networks (or the ones you've tagged with "CiscoSpaces") have been successfully imported.
Webex Control Hub  

#### Webex Control Hub

Integrating Webex Control Hub with Cisco Spaces allows for granular detail on room occupancy, alongside other use case such as environmental metrics.

The following is a summary of the implementation of work needed to integrate Cisco Spaces and Webex Control Hub. The rest of this section will dive into detail on each of these steps. For more information, continue through this section

##### **Prerequisites**

* Devices should be in workspaces

* Workspaces should be on floors, with locations configured with correct building names and addresses

* One building per location(The above is covered in the Location and Maps section below)

* Devices should be configured with the following details:

  * People Count Out of Call​ → **ON**

  * People Presence Detector​ → **ON**

  * Ambient Noise Estimation \> Interval​ → **10**

  * Ambient Noise Estimation \> Mode​ → **ON**

* Workspace \> Settings should be as follows:

  * Allow Control Hub to capture workspace metrics from device sensors → **Checked**

  * Enable sensor data configurations on all supported devices → **Checked**

* All Workspaces should have capacity set correctly

* All Workspaces should have space type set correctly

Below is a guide covering how to ensure your environment is configured as per best practises, and to align with the prerequisites
Intro to Locations in Webex Control Hub  
Setting up the structure of Control Hub Locations and Floors is an essential part of the Cisco Spaces integration. A improper structure can add weeks to deployments, result in a degraded end user experience across various outcomes (e.g. Kiosk, Wayfinding, etc.), and cause major downtime to setup properly.

Locations in Control Hub are important for many reasons, including setting up Webex Calling, but the way they are setup and structured can impact other use cases. For example, placing all devices across a campus of multiple buildings into a single Location may result in a Floor list with multiples of Floor 1, Floor 2, etc. For use cases such as Kiosk and Wayfinding, buildings are distinct entities that must be split into separate Locations with their own unique/non-duplicate Floor numbering in order to draw paths and route end users mirroring the physical world. Splitting an existing multi-building Location in Control Hub may result in Webex Calling disruptions and/or added time for setup.

Meanwhile, there are advantages in Cisco Spaces when Control Hub Locations and Floors are setup properly. For example, when a device is organized under a Location \> Floor \> Workspace, connecting that device to a room becomes easier. Space Manager \> Manage Rooms (Space Management) uses a combination of that organization and fuzzy string matching between the Meeting Room name (from the CAD file) and the Webex Workspace name to auto-connect them and use the device for room occupancy outcomes. This automation can save many hours or days of work.  
![Control Hub - Locations List](https://runbooks.ciscospaces.io/__attachments/a_db0bf45ff192b8e0cfce5cff9f89ee65589c13c616f951f1b47925850b9a06cc/Screenshot%202025-04-11%20at%2015.38.41.png?cb=c2af6221ad37150aabce77e704bc5365)
Control Hub \> Locations List  
![Control Hub - Locations - Overview](https://runbooks.ciscospaces.io/__attachments/a_6dfe065ba60fe0024d0e723db5bc07a5b4209ee88b4d816b7696cbf50424c215/Screenshot%202025-04-11%20at%2015.40.37.png?cb=c330245f5990dffd39f0d97c01ec174d)
Control Hub \> Locations \> Overview  
![Control Hub - Locations - Floors](https://runbooks.ciscospaces.io/__attachments/a_92817c14350b4cd7ee395d05d745fa6b43bad8193d21332d28b1fd7c363c188a/Screenshot%202025-04-11%20at%2015.39.48.png?cb=2e9cd248bd79d0ff00d9d3cf37ad6dca)
Control Hub \> Locations \> Floors

Configuring Locations and Floors  
***Creating Locations and Floors***  
A Location in Webex Control Hub corresponds to a Building in Cisco Spaces.

If you haven't created any Location in Webex Control Hub , please follow this guide to bulk create your Locations (aka Buildings): [https://help.webex.com/en-us/article/ajh6iy/Locations-in-Control-Hub?dtid=osscdc000283\&linkclickid=srch#Add-or-edit-multiple-locations](https://help.webex.com/en-us/article/ajh6iy/Locations-in-Control-Hub?dtid=osscdc000283&linkclickid=srch#Add-or-edit-multiple-locations)

Floors cannot be created in bulk. Please follow the <https://help.webex.com/en-us/article/ajh6iy/Locations-in-Control-Hub#Manage-locations> guide to add floors to each Location.

***Bulk assigning workspaces to floors***

1. Select **Workspaces** (from left nav menu) then enter the **Workspaces**tab across the top.

2. Select all workspaces for a given floor, then click **edit** .A new window will appear.

3. Under **Location \> Location, set the location** to the required building.

4. A new element called floor will appear. **Select the required floor**.

5. Once configuration is finished, click **Next**.

6. Review the configuration, then click **Apply**.

7. Ensure configuration took effect with no errors, the click **Close**.

Workspace Configurations  
***Enabling required global workspace settings***

1. Go to **Workspaces** \> **Settings**.

2. Check **Allow Control Hub to capture workspace metrics from device sensors**

3. Check **Enable sensor data configurations on all supported devices**

![Control Hub - Workspaces - Settings](https://runbooks.ciscospaces.io/__attachments/a_54ebe4d384fb3f08782ae5a8d188eef8004f14074e1c0f445ca7ff9e27f5f17f/Screenshot%202024-11-13%20at%2012.52.35.png?cb=6cd54ff1e76abd560298704a53a2ed58)
Control Hub - Workspaces - Settings

***Bulk assigning capacity to workspaces***

1. Select **Workspaces** (from left nav menu) then enter the **Workspaces**tab across the top.

2. Select all workspaces with the same capacity, then click **edit** .A new window will appear.

3. Under **Workspace Settings \> Capacity** ,**set the value for capacity**.

4. Once configuration is finished, click **Next**.

5. Review the configuration, then click **Apply**.

6. Ensure configuration took effect with no errors, the click **Close**.

![Webex Control Hub - Workspaces Bulk Edit Configurations](https://runbooks.ciscospaces.io/__attachments/a_2ea506b7ef8067bdc254e14456a826623584b065e3f553ae45f7889971468061/Screenshot%202024-11-13%20at%2012.55.41.png?cb=467af09090c2d7c2b00a52e26751ee30)
Webex Control Hub - Workspaces Bulk Edit Configurations

***Bulk assigning space types to workspaces***

1. Select **Workspaces** (from left nav menu) then enter the **Workspaces**tab across the top.

2. Select all workspaces for a given type (E.G. Meeting rooms), then click **edit** .A new window will appear.

3. Under **Workspace Settings \>** **Type** ,**set the type** as required.

4. Once configuration is finished, click **Next**.

5. Review the configuration, then click **Apply**.

6. Ensure configuration took effect with no errors, the click **Close**.

Device Configurations  
***Bulk enabling required device settings***

1. Head to **Devices**(in the left nav) and select all required devices.

2. Click **Edit** and a new right hand panel will open. Select **All configurations**

   ![02_06_04.jpg](https://runbooks.ciscospaces.io/__attachments/a_8667767ba194e52bfe6c2ac8c91be5fb63e5103b630a4f9fffc35c17735d66a5/02_06_04.jpg?cb=40457802c85a618aba2f58c535cfc3e1)
3. On the new page that appears, apply the following configuration:

   1. People Count Out of Call​ → **ON**

   2. People Presence Detector​ → **ON**

   3. Ambient Noise Estimation \> Interval​ → **10**

   4. Ambient Noise Estimation \> Mode​ → **ON**

4. Once complete, click **Next**

5. Verify changes and click **Apply**

   ![Screenshot 2026-06-05 at 14.10.06.png](https://runbooks.ciscospaces.io/__attachments/a_41f1f98a042e03f85afd94e39fb2b133715089e8ec99e1cad25a2781470ee3ae/Screenshot%202026-06-05%20at%2014.10.06.png?cb=0c05d346e33abbe163d2cae990f1ce91)
6. Verify that all changes have been applied and there are no errors, then click **Close**.

##### Integration*​*

This integration will allow telemetry from selected workspaces to be sent directly from Control Hub to the Cisco Spaces account. This will power room occupancy, booking status, in-room environmental metrics, etc.

![Cisco Spaces - Setup - Webex](https://runbooks.ciscospaces.io/__attachments/a_8f9def940f03f4f9d9c638619bb1a229d1d541145faeb8300d1b943383eb3004/Screenshot%202024-11-07%20at%209.01.51%E2%80%AFAM.png?cb=fcfeae3ffbfb8398db491f7019be2818)
Cisco Spaces - Setup \> Webex

1. Log in to Cisco Webex Control Hub and navigate to **Workspaces** \> **Integrations**.

2. Find the Cisco Spaces app tile and click **Details**.

3. Scroll down to review the permissions required (i.e. xAPIs).

4. Check the box to accept the **Terms and Conditions**.

5. Scroll to the bottom right corner of the page and click **Activate**.

6. Click **Copy to clipboard**.

7. Navigate to **Setup** \>**Webex** in the Spaces dashboard.

8. In the **Connect your Webex** window, click **Connect**.

9. In the Enter or copy-paste the Webex Token field, enter the Cisco Webex token, and click **Connect**.

10. This will result in a sync between Webex Control Hub and Cisco Spaces.

The Cisco Webex synchronization status will display as Active for all active users in a specific tenant (account) if at least one user successfully connected their Cisco Spaces account with the Cisco Webex account while importing the Cisco Webex networks into Location Hierarchy.  
![Webex Control Hub Integration - Sync Status visible to all admins](https://runbooks.ciscospaces.io/__attachments/a_3111755b259e019692128406b9520ac78c8fa201e93dc89400f0ce85e447802f/Screenshot%202025-04-11%20at%2014.57.17.png?cb=18e9c7a804788b62e34604686374222e)
Webex Control Hub Integration - Sync Status visible to all admins  
![Webex Control Hub Integration - Sync Status visible to the admin who pasted the Access Token into Setup - Webex](https://runbooks.ciscospaces.io/__attachments/a_796c450d8bf89da690ad4c186a50d4f906b9fd66612312c8dbca70e1d924d756/Screenshot%202025-04-11%20at%2014.58.43.png?cb=e47b016ea07259fbee1f6c9a349de22d)
Webex Control Hub Integration - Sync Status visible to the admin who pasted the Access Token into Setup \> Webex

*** ** * ** ***

### Configuring the Location Hierarchy

![image-20260612-105932.png](https://runbooks.ciscospaces.io/__attachments/a_cb29ca29074fc39640b43fc9413da33e3abcc74c521e468aff8b0560d063339c/image-20260612-105932.png?cb=5234378de5e4c6ac5f34088e439ec22c)

The Location Hierarchy allows businesses to organize their buildings into a recognizable and consistent structure. Cisco infrastructure and sensor telemetry will then be combined, normalized, and standardized into a structure regardless of separate hierarchies across other platforms (e.g. Catalyst Center, Prime, Meraki Dashboard, Webex Control Hub). The hierarchy can be organized based on specific brands, regions, campuses and other taxonomies that are relevant to the business.

By translating the IT network view into a business view, it can be automatically presented with a cleaner business relevant insights report. Any changes to the network topology are automatically reflected here thereby making it easy to manage.  
**Important:** How the Location Hierarchy is structured is as much cosmetic as it is functional with wide-ranging effects in applications and outcomes. Proceed with caution before Creating and/or Merging the Location Hierarchy. Making corrections later can result in lost data and service disruptions to end users. Consult with the Cisco Spaces team if there any doubts or would like to consult on the best practices given your specific environment details.

**Recommended Route**

We recommend following geographical hierarchy as follows:

* Continent or bigger (e.g. Europe, EMEA, APAC)

* Country

* Region (e.g. state, county, city)

* Campus (only if multiple buildings on a single site)

* Building

* Floor

The above is the end goal. The below is the priority of sources in order to achieve this goal.

In order:

* Catalyst Center and/or Excel template

* Meraki Dashboard

* Webex Control Hub

Recommendation is to fix any issues with hierarchy in Catalyst Center where possible, rather than using the excel to fix the missing elements.  
Excel is the most flexible method, but requires the most manual configuration. You should use it to add ++missing++ hierarchy elements, but not to build the entire hierarchy from scratch.

#### Managing and Merging the Location Hierarchy

Spaces should have by now ingested hierarchies from all integrated platforms: Catalyst Center, Meraki Dashboard, and Webex Control Hub.  
Note: you will see Catalyst Center, Prime, and Meraki Dashboard Locations + Floors (and network maps) appear in the Cisco Spaces Location Hierarchy automatically. While data may start to populate in some applications from the time of integration and initial setup (e.g. Connector), **there are required steps to Create and/or Merge the network hierarchies into the official Location Hierarchy** . Follow these steps to make the Location Hierarchy Creates and/or Merges permanent, and to upload CAD files to create **Digital Maps** for other outcomes and use cases.

This section is designed to merge those hierarchies into a single, business focused hierarchy, to use across the Spaces platform.

1. If there is an existing location Hierarchy it can be viewed under **Setup** \>**Locations \& Maps**.

2. Click on **Review**.

3. Click on the **\>**sign to expand and review the locations.

4. Click on the drop-down under **Action**.

5. Choose 'merge with' to merge same location hierarchies that would have been previously created.

6. Choose the location that needs to be merged from the dropdown under Existing Locations.

   This configuration is hierarchal, meaning configuring this at a campus level, will also configure the same at all buildings and floors below. This can be changed manually on a per location basis as needed.
7. Click **Next** and Select **Agree and continue** once reviewed.

8. Review changes and click **Merge**.

For an in-depth guide into the Location Hierarchy please refer to our and [++Setup Guide++](https://spaces.cisco.com/setupguide/configure-location-hierarchy/) and [++Knowledge Article++](https://runbooks.ciscospaces.io/docs/unified-location-hierarchy-best-practices).

#### Configuring Metadata

##### *Location Hierarchy Metadata*

Meta data is needed for computing accuracy of occupancy at the platform level. See the table below for elements that need configuration.

1. Login into Cisco Spaces and go to **Location Hierarchy**.

2. Navigate the hierarchy and select a location.

3. Select the **Location Info** tab

4. Click the blue **Edit** button next to Location Data.

5. Configure elements as needed, then click **Update**.

6. Click **Save**.

7. Continue to configure location data as needed. It is recommended to configure location data for every element within the location hierarchy.

Metadata configuration is hierarchal, meaning config applied at a campus level, will reflect down into respective buildings and floors. This is most relevant for config such as brand, or timezone, and less relevant for config such as area, which will change throughout the hierarchy.  

|------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Location Hierarchy Metadata**                |                                                                                                                                                                                                                                         |
| Timezone (Mandatory)                           | Has to be defined at the network level. Computation defaults to GMT if time zone is not set. Impacts 'time of day' and daily counts among other metrics.                                                                                |
| Occupancy Limit (Max Capacity) (Mandatory)     | Critical for computing % utilization Normalizing occupancy data for better cross location comparison Seating capacity= no. of seats/workstations assigned for a particular floor/building Has to be defined at network and floor level. |
| Area in Square Feet / Square Meter (Suggested) | Used to compute density. Normalizes occupancy data for better cross location comparison                                                                                                                                                 |

##### *Live Occupancy Metadata*

Filtering is another element that is required for accurate occupancy data. As people typically carry multiple devices with them that connect to the network it is essential that there is a method to understand how to get an accurate count for each person, rather than each device. Look below at the table for such methods.  
For more insight on what to configure here, and how people counting works, see <https://runbooks.ciscospaces.io/docs/counting-people-from-wi-fi>

1. Log into Cisco Spaces and navigate to **Live Occupancy** \> **Settings**.

2. Select the blue pencil next to excluded SSIDs from Live Occupancy analytics.

3. Select all SSIDs that employees do not connect to. Use the guidance below to help determine which SSIDs to select.

4. Click **Save**.

|----------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Live Occupancy Settings**                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Excluded SSIDs from Live Occupancy analytics (Mandatory) | Exclude all SSIDs which employees (or students for universities) do not connect to. Recommend excluding Guest SSID's for two reasons: 1. Guests contribution to occupancy is insignificant in most cases <!-- --> 2. Guest SSIDs are used by employees to associate their second devices. Guest SSIDs typically do not have dot1x authentication and this results in duplicate counting of people                                                                                                                                                                |
| Categorize Visitors (Suggested)                          | Categorizing visitors allows configuring which SSIDs are used for what purpose. SSIDs can be configured as: * Auto - Spaces will try to automatically assign visitor category based on the data it sees. * Employee - Used to show employee data * Guest - Used to show guest data * Custom - Can be used to categorize to a deeper level, such a contractor SSID. These visitor categorizations are used within the Live Occupancy and Visitor Trends apps, and configuring them can give deeper understanding into the type of visitors within an environment. |

*** ** * ** ***

### Digital Map Creation \& CAD File Upload

![image-20260612-110019.png](https://runbooks.ciscospaces.io/__attachments/a_ad326dddf0e3d43b74a1185c7a5e8e247a3457586697f55a9f0ed5e79f950119/image-20260612-110019.png?cb=3422c3fda61920de4fbea216bd36df9c)

![Screenshot 2024-10-08 at 9.52.22 AM.png](https://runbooks.ciscospaces.io/__attachments/a_34873f8ec1a12d34260323890545789a2e153373c1f858ab6c93e4d252ad2cad/Screenshot%202024-10-08%20at%209.52.22%E2%80%AFAM.png?cb=3d535c3a6e3112054989b60ed962ca4c)

#### Upload, process, and publish Digital Maps

Once the Location Hierarchy is created, merged, and unified across multiple sources, the next step is to upload CAD files (.dwg) or Vector PDFs to generate a Cisco Spaces Digital Map.  
After uploading it can take up to 1 week for processing workspaces / office floorplans. Very large buildings and other maps (e.g. venues, retail, healthcare, education, manufacturing, etc.) can take longer, such as 3-4 weeks.

**Prerequisites**

1. License: Cisco Spaces Advantage, Premier or Premier with Collab \& Wireless

2. One CAD or Vector PDF file per floor

3. Separate layers:

   1. Architectural layer

   2. Funiture layer

   3. Space names/IDs/Labels

For Digital Maps best practices, please read our knowledge article: <https://runbooks.ciscospaces.io/docs/digital-map-pro-and-cad-dwg-pdf-best-practices#Wayfinding-Custom-POI-and-Path-Editor---Early-Preview-(August-2025)>

**STEP 1:** Under **Setup \> Locations \& Maps**

Click on the **Digital Maps**  tab. Either search or choose your desired building and Click **Set address** if no address is added, or **Confirm address** if the address is present but unconfirmed.  
![Screenshot 2026-02-27 at 4.08.11 PM.png](https://runbooks.ciscospaces.io/__attachments/a_ce71f72106fff9c671b76311e97a2606e0dbc9e2b4892103bc030cc49d731f15/Screenshot%202026-02-27%20at%204.08.11%E2%80%AFPM.png?cb=7134e7edd92b26260205c1daa0213cee)  
![Screenshot 2026-02-27 at 4.15.59 PM.png](https://runbooks.ciscospaces.io/__attachments/a_fe69880d4b6f1ebc5e92a63e6911b214973b18d90d7cdd9573547da2fbb6ad85/Screenshot%202026-02-27%20at%204.15.59%E2%80%AFPM.png?cb=6943fa54e558e2db5f7a96ad611233e9)

**STEP 2: Set address / Confirm Address:**

Provide and confirm the correct building street address using Google address autocomplete.  
Click in the street address field and select the correct address from the dropdown for the best results  
**Verify** if the location pin is at the right location, if not, you can drag and drop the pin on the center or the focus area of the building. This will be the default center or focus area in other Spaces apps. Click on **"Update"** . Locations with an incorrect street address (++must++ match the physical building outline) will be rejected.  
![Screenshot 2026-02-27 at 4.21.16 PM.png](https://runbooks.ciscospaces.io/__attachments/a_58311e6c3d502a1ec5dfb53e262f351a95c3d45dbdb77164f5b5373d4c10cae2/Screenshot%202026-02-27%20at%204.21.16%E2%80%AFPM.png?cb=fc0e1243f0a04981e895a42f4cf89de4)  
![Screenshot 2026-02-27 at 4.31.10 PM.png](https://runbooks.ciscospaces.io/__attachments/a_08669f8f53cfc62ecee25fb2bcc63dac472ca580cd6d6cb7cea4688810ad993b/Screenshot%202026-02-27%20at%204.31.10%E2%80%AFPM.png?cb=1c802c6990de7fd5f2ff7144ad4021f7)

**STEP 3:** Create floors by Clicking on **"Add/update floors"**.  
Floors created or merged from Catalyst Center, Prime, Meraki, or Webex Control Hub may already be populated on this page.  
![Screenshot 2026-02-27 at 5.02.49 PM.png](https://runbooks.ciscospaces.io/__attachments/a_948e73d273c4c676e5dedbfed0910782479e29911ac099975bbcff184962b33d/Screenshot%202026-02-27%20at%205.02.49%E2%80%AFPM.png?cb=87e545f57414053dd48db7f9cbe11888)

**STEP 4:** Click on **Add new floor** to add new floors  
![Screenshot 2026-02-27 at 5.07.40 PM.png](https://runbooks.ciscospaces.io/__attachments/a_b01137964ce92c4e921d1f929ef60e4eded6ca4fb172c4d402b436dda53943c6/Screenshot%202026-02-27%20at%205.07.40%E2%80%AFPM.png?cb=033c3a1d701387c8db20e057b1ed0cb3)

**STEP 5:** Add missing metadata to the floors. Enter floor details and level number. Ensure that all floors are accurately listed with their corresponding level numbers and short names, as these cannot be modified until the map has been processed and published; however, once the map is processed and published, the metadata can be modified.  
"Level Number" cannot be duplicated within a building. Floors **must** either be combined or split up at the source (e.g. Webex Control Hub, Catalyst Center, Meraki Dashboard).​ This metadata has a significant impact on apps such as Wayfinding, Kiosk (Signage), etc.

**Verify** floor and Click **"Save"**  
![Screenshot 2026-02-27 at 5.08.06 PM.png](https://runbooks.ciscospaces.io/__attachments/a_d94b2ec50dce0529023816de0ce592e0bf1e22cf6615fccb698da81868e5ce43/Screenshot%202026-02-27%20at%205.08.06%E2%80%AFPM.png?cb=a45d9bce495c73ace900178fbdfae8bb)  
When naming floors, choose a naming convention that is familiar to your end users. Repetitive information, such a building name, may not be necessary in the Floor Name and/or Short Name if the building name already appears in the UI (e.g. Kiosk, Space Explorer Web App, Wayfinding App Clip/App). There is a 5 alphanumeric character limit in the Short Name, and Level Numbers **must** be numerical whole numbers. A good rule of thumb for Short Name is to replicate what you may see in an elevator floor button panel, or a placard in a stairwell indicating the current floor.

**STEP 6:** Click **Add Digital Maps** for the desired floor or multiple floors at the building level to upload your CAD or Vector PDF files.
Add Digital Maps - multiple floors at the building level  

#### Add Digital Maps - multiple floors at the building level

Click **Choose file** to upload the CAD file, then click submit.

You can add new floors and edit existing floor details.  
Editing is allowed **only** for floors that are **not** currently processing, and or if finished processing **must** be published first before editing.  
![Screenshot 2026-03-04 at 10.44.17 AM-20260304-051638.png](https://runbooks.ciscospaces.io/__attachments/a_90d2c64dd97f50001b4cec223ff9a038eb243962341c4e634d663c862924d002/Screenshot%202026-03-04%20at%2010.44.17%E2%80%AFAM-20260304-051638.png?cb=091e8fcdcd45c8066a8ee3108113f83a) Add Digital Maps - single floor  

#### Add Digital Maps - single floor

![Screenshot 2026-02-27 at 7.55.25 PM-20260227-142935.png](https://runbooks.ciscospaces.io/__attachments/a_aa546b244f54c80a7a242c26e6539cb6a916765577d28b0a9bd89f11e9579169/Screenshot%202026-02-27%20at%207.55.25%E2%80%AFPM-20260227-142935.png?cb=d8f3c489d01c9c1ab5c17ef8e6205e8c)

**STEP 7:**Upload the CAD/Vectorized pdf file.

Click or drag file here to upload.

Edit the floor details if incorrect and add supplementary information for processing the CAD file.  
Hidden and "frozen" layers will not be processed. Missing objects will need to be un-hidden or un-frozen, and re-uploaded to be processed correctly. Cross Reference (XREF) files are not supported. If your CAD files include XREF, first merge them into a single DWG, then upload.  
![Screenshot 2026-02-27 at 7.55.42 PM-20260227-143134.png](https://runbooks.ciscospaces.io/__attachments/a_afc2c4792d7005a13e39177c9cc0a87a88bed5dfdd71eda06a6e015844baa22d/Screenshot%202026-02-27%20at%207.55.42%E2%80%AFPM-20260227-143134.png?cb=2fe24861b1bbd04d0dca5519c92718c9)

Select the file from your device and click the **Submit** button.  
An additional dropdown and input fields will appear if the selected file is already submitted for another building in this account. You must select the **Reason for force submission** and provide **Supplementary information for processing the CAD file**before the submission.  
![Screenshot 2026-02-27 at 8.10.43 PM.png](https://runbooks.ciscospaces.io/__attachments/a_bcbf7ccf4a83dddaa08b190be0bb31f45a4dac4ce41fdb9ccf87dc90904c968b/Screenshot%202026-02-27%20at%208.10.43%E2%80%AFPM.png?cb=1e3b1ec2993ca04990381f357ced80a4)  
![Screenshot 2026-02-27 at 8.18.55 PM-20260227-144947.png](https://runbooks.ciscospaces.io/__attachments/a_f1c01e0e03f40fa42f2cebfaa17efecac87f6bd061331ce53ff8a9f6d162c8ee/Screenshot%202026-02-27%20at%208.18.55%E2%80%AFPM-20260227-144947.png?cb=ffb25745a4cb259fcf6958982cf0201c)

Your CAD file submitted for Digital Maps processing, an **AI-generated preview** will be available in approximately 15 minutes. You will receive an email notifying that the AI Preview is available to review.  
This is a great opportunity to review the content of the CAD file, but missing elements or incorrect space names may be incorrect. The Cisco Spaces Mapping Team will review and provide a final corrected version that will be editable (see STEP 8 below). In most cases, metadata or structural elements the AI did not capture correctly can be corrected in the QA phase of processing. If the Cisco Spaces Mapping Team determines that there is important missing information, the CAD files will be rejected with a reason and notes for corrective actions.  
![Screenshot 2026-02-27 at 5.51.15 PM-20260227-122121.png](https://runbooks.ciscospaces.io/__attachments/a_4930bafda2a2dc5b4734cf4b7587cb293e2f2292b6768e7e2da9a7a7bbd49e3d/Screenshot%202026-02-27%20at%205.51.15%E2%80%AFPM-20260227-122121.png?cb=620d66792cb6d7ce45c138bd15df69b7)

**STEP 8:** The map status is now **Processing** . The list view will display the status as **Processing.**  
![Screenshot 2026-02-27 at 5.51.37 PM-20260227-145502.png](https://runbooks.ciscospaces.io/__attachments/a_53b242b1f6741224d0173f802da4d3a6b958e905096cd82100a5fd00e03dc0ec/Screenshot%202026-02-27%20at%205.51.37%E2%80%AFPM-20260227-145502.png?cb=b57edb06f1271cc4546a045286f8d56c)

**STEP 9:** When the AI-generated preview appears, click **View** to display the AI preview  
![Screenshot 2026-02-27 at 8.28.46 PM-20260227-145922.png](https://runbooks.ciscospaces.io/__attachments/a_856901f0cf2efc1146a72804cfe6facd4379af62c84aa1d71542146cc2d5de36/Screenshot%202026-02-27%20at%208.28.46%E2%80%AFPM-20260227-145922.png?cb=1ef36af46379e9ddfe8af3900ef188b3)

Sample preview of your map.  
You cannot edit this map until your Digital Map is ready for review.  
![Screenshot 2026-02-27 at 8.31.39 PM-20260227-150144.png](https://runbooks.ciscospaces.io/__attachments/a_ecbf6994b07bcfa950eeed67150b52cc7267da331964ed6b575ab14ce412624e/Screenshot%202026-02-27%20at%208.31.39%E2%80%AFPM-20260227-150144.png?cb=bae99b3dd60bebbffc7aa87d419ed633)

**STEP 10:** Once processed, **Processing Status** will change to **'Review pending'** . Click **"Review building"** or**"Review floor"** to view the processed Digital Maps.  
![Screenshot 2026-03-02 at 10.09.17 AM-20260302-044825.png](https://runbooks.ciscospaces.io/__attachments/a_51280d48a10c0fd1d7dd41907df8d62a52f07a294d755e44074f26f8cfda0c84/Screenshot%202026-03-02%20at%2010.09.17%E2%80%AFAM-20260302-044825.png?cb=b1ce6ad08b382dd847e5ea80b50561ff)

**STEP 11:** **Review building** - Review all floors at once.

**Add/Edit** Room Labels. Once everything looks good, select **"Publish".**  
![Screenshot 2026-03-02 at 10.38.13 AM-20260302-050900.png](https://runbooks.ciscospaces.io/__attachments/a_2ecf0c05beb630b2a3e97f605897004c21deaf15ab025914dbd485a12a959467/Screenshot%202026-03-02%20at%2010.38.13%E2%80%AFAM-20260302-050900.png?cb=329cd2956593963651049272015328af)

**Review floor**: Review one floor at a time.  
![Screenshot 2026-03-02 at 10.44.26 AM-20260302-051451.png](https://runbooks.ciscospaces.io/__attachments/a_f36eb3d5fb35986042f300962679308a6b53be712992d4989ed7393c0de82ea7/Screenshot%202026-03-02%20at%2010.44.26%E2%80%AFAM-20260302-051451.png?cb=f8703cff4300a8ec7b1e762cf92ed03e)

**STEP 12:** The Digital Map is now **published** successfully  
![Screenshot 2026-03-02 at 11.21.57 AM-20260302-055202.png](https://runbooks.ciscospaces.io/__attachments/a_75067e33519f9a7d13ca6fcd98cb1edcb6e8d28429e85c1e4142963c9d72e4af/Screenshot%202026-03-02%20at%2011.21.57%E2%80%AFAM-20260302-055202.png?cb=554610a4be48a50ea7b0fddc9d7fa7a4)

**STEP 13:** You can set the default map view for the published maps.

Click on **"Set default view"**against the building.  
![Screenshot 2026-03-02 at 11.22.56 AM-20260302-055824.png](https://runbooks.ciscospaces.io/__attachments/a_e78ea742473293f57747d068ba830057594b2f3ae04da719c72eea706595b832/Screenshot%202026-03-02%20at%2011.22.56%E2%80%AFAM-20260302-055824.png?cb=aafd1f0f6e97fd51da5ab02d5aeb6892)

**STEP 14:** Adjust the map's center, pitch, bearing, and zoom, then save to set the default view. Use the "**Apply to all floors**" option to apply these settings across all floors if desired.  
Changes on each floor save together when you click **Save**. Updates apply only after editing all floors and saving once.  
![Screenshot 2026-03-02 at 11.30.04 AM-20260302-060829.png](https://runbooks.ciscospaces.io/__attachments/a_b349d79cae3c17afdebf4384df4762ecf40a64a62a5ccea6e9a2552000cb369d/Screenshot%202026-03-02%20at%2011.30.04%E2%80%AFAM-20260302-060829.png?cb=76cbb6ba4385e6a285319b2f1f5e9b58)

**STEP 15:** Click **"Network map calibration"**for the selected floor.

##### **Network map calibration**

We recommend calibrating your network map to ensure it is aligned correctly with the Digital Map \& GPS Markers are placed, enabling precise calculation of client device positions. Learn more: <https://runbooks.ciscospaces.io/docs/guide-to-network-map-geo-placement-and-best-practi>  
![Screenshot 2026-03-02 at 9.04.28 PM-20260302-153611.png](https://runbooks.ciscospaces.io/__attachments/a_e7e57f3cbad67e0db12f29b0e4e0ba19d5c8e8f6f49c619ab26276ff3dc99831/Screenshot%202026-03-02%20at%209.04.28%E2%80%AFPM-20260302-153611.png?cb=fee840bc67b16a34ff2165f13b479302)

**STEP 16:** Roughly align the network and Digital Map layers to match to map orientation (does not need to be precise in this step), then click the **"Next"**button.  
![Screenshot 2026-03-04 at 10.06.14 AM-20260304-050357.png](https://runbooks.ciscospaces.io/__attachments/a_65b7ca01a5ebe93da7af2d375a5aeff11e4498e5c0052c7b13e4a11a98ee8e19/Screenshot%202026-03-04%20at%2010.06.14%E2%80%AFAM-20260304-050357.png?cb=404bcc71e6b9ddb2c234ec3d6527d0e0)

**STEP 17:** Click **"Add markers"** to place markers correlating specific points between maps, which must be exact. Then click the **"Save"** button to save alignments and markers.

Place at-least 3 markers at the specific points like building corners/room/starting furniture corners etc.  
![Screenshot 2026-03-04 at 2.08.27 PM-20260304-084208.png](https://runbooks.ciscospaces.io/__attachments/a_8bd57fbf400d21dc45439a321cce1ae7ba23084feeae3ac178cf19c0d9ce5a94/Screenshot%202026-03-04%20at%202.08.27%E2%80%AFPM-20260304-084208.png?cb=0573cf7c7e4bc98fcd38fa4ffedaca60)

#### Delete, discard or cancel Digital Maps

Delete Digital Map  

##### Delete Digital Map

**STEP 1** : Click on **Delete map** to remove all map versions under the building, including unpublished and published ones. This action may affect linked configurations such as Kiosks, Wayfinding, Occupancy tracking and devices on the map.  
**Warning:** **DO NOT delete Digital Maps in order to process an updated floor file.** Under **Setup** \> **Locations \& Maps** \> **Digital Maps** \> "3 dots" menu on the location/floor list item, you can **Add Digital Map** to replace the existing Digital Map. The workflow is the same as initially uploading, but after processing, previous Digital Map content will be preserved if there were no structural or name/ID changes to the individual spaces/POIs. This ensure data and device assignment continuity between uploads, while only processing the differences between the CAD file versions uploaded. **Deleting the Digital Map erases all database records and cannot be reversed.**  
![Screenshot 2026-03-02 at 10.48.34 AM-20260302-051903.png](https://runbooks.ciscospaces.io/__attachments/a_338284f95c036ca76361ad24d3db6144a80f7107c166248c44c4c9dcca602504/Screenshot%202026-03-02%20at%2010.48.34%E2%80%AFAM-20260302-051903.png?cb=d220efa4af8e6152c6c898cc4b12487c)

**STEP 2**: Enter all required inputs, including the reason for deletion and additional comments, to confirm the action. Deletion is irreversible.  
![Screenshot 2026-03-02 at 9.53.15 AM-20260302-052238.png](https://runbooks.ciscospaces.io/__attachments/a_b217890d6bbfab6ae971bb142c4b8ad53221a1cc72def6a495991e01b4761ef0/Screenshot%202026-03-02%20at%209.53.15%E2%80%AFAM-20260302-052238.png?cb=f46258be5bbb398de7a76d5b5d732526)

**STEP 3**: After deleting all the maps, you can upload a CAD file or Vector PDF to create a new Digital Map if needed.
Discard Digital Map  

##### Discard Digital Map

If something appears incorrect, discard individual floor maps that have been processed but not published, then start over.  
Discarding is ideal for fully processed Digital Maps that are obviously incorrect floors or missing elements that you believe are caused by a bad CAD file.

**STEP 1** : Click **"Discard map"** next to the floor whose processed maps you want to discard.  
![Screenshot 2026-03-02 at 10.56.43 AM-20260302-052937.png](https://runbooks.ciscospaces.io/__attachments/a_d478974c719b1c24adf799d378b1d9e2b4207f3548f7ad52a93cdc6e6ac3736f/Screenshot%202026-03-02%20at%2010.56.43%E2%80%AFAM-20260302-052937.png?cb=d5d7fbc58d8134ba2e0be107ad1622ba)

**STEP 2**: Enter all required inputs, including the discard reason and additional comments, to confirm. Discarding is irreversible.  
![Screenshot 2026-03-02 at 11.00.56 AM-20260302-053235.png](https://runbooks.ciscospaces.io/__attachments/a_87294e1151485beb1ebe0a0f7d28ef39e0de6a85ffd49fe9be291ab16c6e8923/Screenshot%202026-03-02%20at%2011.00.56%E2%80%AFAM-20260302-053235.png?cb=84b1706c96a3be2115e39df6c7f3bbe0)

**STEP 3**: After discarding all the maps, you can upload a CAD file or Vector PDF to create a new Digital Map if needed.
Cancel Digital Map  

##### Cancel Digital Map

You can cancel the maps which are in progress / under processing or AI generated preview maps.  
Canceling is ideal for AI Preview that are obviously incorrect floors or missing elements that you believe are caused by a bad CAD file. It is possible the AI output can be corrected by the Cisco Spaces Mapping Team, but if not, they will add a note when rejecting during QA.

**STEP 1** : Click "**Cancel**" to stop processing the Digital Maps.  
![Screenshot 2026-03-02 at 11.05.31 AM-20260302-054140.png](https://runbooks.ciscospaces.io/__attachments/a_f258c90f850cc46cde60f6ad45a96f5a4533d9363824507d696408357ef6f49c/Screenshot%202026-03-02%20at%2011.05.31%E2%80%AFAM-20260302-054140.png?cb=caeb269ec48f6d610aae529c76b7d935)

**STEP 2**: Enter all required inputs, including the reason for cancelling and additional comments, to confirm. Cancelling is irreversible.  
![Screenshot 2026-03-02 at 11.06.01 AM-20260302-054257.png](https://runbooks.ciscospaces.io/__attachments/a_a65d201629ae43d4dd9741b6e66e25c436c59cd6044c9ad30c6ba64af2b0040b/Screenshot%202026-03-02%20at%2011.06.01%E2%80%AFAM-20260302-054257.png?cb=ee788148646c0dd1188107af8f0e263f)

**STEP 3**: After cancelling all the maps, you can upload a CAD file or Vector PDF to create a new Digital Map if needed.

*** ** * ** ***

### Enabling IoT Services

![image-20260612-110123.png](https://runbooks.ciscospaces.io/__attachments/a_b038afa15079827a14c084458ab31e65e29569c233ee6270f1fed99992f06a56/image-20260612-110123.png?cb=f2da4aa37b77a106278fbcc3e1054bb9)

Now all infrastructure and hierarchy is set up and Digital Maps created, IOT Services can be enabled. IOT Services gives Cisco Spaces the functionality to scan and transmit using the BLE radio.
Catalyst Deployments  

#### Catalyst Deployment

In this section, we will enable IOT Services for Catalyst based deployments. To do this, we will enabled IOT Services on Spaces Connector, then WLC, then required APs.
IOT Services Wizard flow (prefered)  
1. Navigate to **IoT Services** \> **About** and click the **Activate** button. The About IoT Services window will open.

![image-20260622-104831.png](https://runbooks.ciscospaces.io/__attachments/a_c07665c55011b7d44a7c1e42dbcf857c62b634e888b27bfb2cf08b4d3407d6a3/image-20260622-104831.png?cb=4d38731ba76624303c6cad0a286c097b)

2. Ensure that **Wireless** is selected and click **Next**.

3. The prerequisites will be checked automatically. If any of the prerequisites are not met, resolve this before continuing. Once complete, the IoT Services Activation page will open.

![image-20260622-105315.png](https://runbooks.ciscospaces.io/__attachments/a_3ec45c9ec858b53dee95a56c4076f505d1843f469d37e40033bb6a4cd0298995/image-20260622-105315.png?cb=e28f886e7188bda2fd050effc459ade3)

4. By default all compatible connectors, controllers and APs will be enabled for IoT Services. To proceed with this, click **Activate.**

   1. To customize which connectors and/or APs to deploy IoT Services to, click **Click here for customization**.

   2. **Select the connector(s)** where IoT Services will be deployed to and click **Activate**.

      ![image-20260622-110455.png](/__attachments/a_8533e4f1f0d03b94c5193711956aedc251528aaf8b5f04bb9040c9bc36eac2b3/image-20260622-110455.png?cb=ff2ce620a85f1bec36b79fe5b3aeb40a)
   3. Wait for the connector(s) to be activated, then select **Activate Wireless.**

      ![image-20260622-111349.png](/__attachments/a_90f916227da3185e83c10b36fc3104b9476c6702c7cae2fea2ddbdf49b6ab20f/image-20260622-111349.png?cb=e2a9f21f7e1fe073fd04b5247528bdb4)
   4. Select all APs required to deploy **IoT Services** , then select **Next** and then **Activate** .

      ![image-20260622-112750.png](/__attachments/a_ca1657f989a0a5b22405033a22b25197216a63cb725a785b11ac2bd46405cfd1/image-20260622-112750.png?cb=21ee1f40c017c2262ffa3379d2a5da93)
5. Activation is now underway. Use the menu under **IoT Services** \> **About** \> **View Detailed Status** to monitor the status of IoT Services.

Use this Deployment Status page to help monitor IoT Services status on a regular basis.  
![image-20260622-113539.png](https://runbooks.ciscospaces.io/__attachments/a_947139cf241d9242c45b789b1e672367a77aa1cad5119903bc42d3b2cf810912/image-20260622-113539.png?cb=d5b69d31ae4b36440b2f5e0c1a32967a)

The activation process will be completed when all of the In-Progress deployments, are shown as Success.

Investigate any failed deployments and reactivate the IoT Services.
IOT Services Manual Enablement  

##### Spaces Connector

First, we must enable the IOT Services functionality on the connector. This creates a new container on the connector, pushed through Spaces dashboard.  
Installing the IoT Wireless container will automatically enable IoT Services for all associated WLCs. This includes pushing configuration to WLCs

1. Log into Cisco Spaces and head to **Setup \> Wireless Networks**.

2. In the **Connect via Spaces Connector** section, click on **View Connectors**, and open the connector you want to deploy IOT Services to.

3. Click on **+ Add Services** , select **IoT Wireless** , then click **Save**.

This will begin the install of the IoT Wireless container onto the chosen connector. This will take 5 minutes or more, and will go through the stages of; Queued → In Progress → Complete.  
![Untitled 3.jpg](https://runbooks.ciscospaces.io/__attachments/a_57d759310e5cb7d541dcafddcd3b4976d6643e1b0ea397a662cd23df609db7a7/Untitled%203.jpg?cb=fc8a0a3635d0d6c2d73bee3f0bcf05f2)
Add Service

##### WLC

As mentioned above, enabling IOT Services on Spaces Connector will automatically try to configure IOT Services on the WLC as well. This section will validate this has been completed, and work through common issues seen.

1. Under **Setup \> Wireless Networks \> View Connector** , open the required **connector** , and click the **cog icon** under the actions menu.

   ![image-20260604-144616.png](https://runbooks.ciscospaces.io/__attachments/a_e7faa7247dc1f144181d9a3fbed2059a00ae704b8e154870f4a3666a6ece18a2/image-20260604-144616.png?cb=1bb375f58111f500343379fe4b335fbc)
2. You will then be shown a list of associated WLCs for this connector, as well as the status of IOT Services configuration for each. We are looking for all WLCs to say **SUCCESS**.

##### APs

We have now enabled IOT Services on the required WLC and Connector. In this step we will enable IOT Services on the required Access Points.  
Deploying IOT Services to Access Points, should not impact client serving ability of the AP, but there have been occurrences that this has happened. Reccomendation is to deploy during times of low traffic, or outage windows.

1. **IOT Services \> Manage**, and navigate to the building you wish to deploy IOT Services to.

2. Use the checkboxes, to select required APs to deploy IOT Services to.

3. Select from the top bar **Action \> Manage IOx App \> Install IOx App**.

   ![image-20260604-152146.png](https://runbooks.ciscospaces.io/__attachments/a_d2eff4e789a10436606823ca33e26569ca0b438765dd955e9f533446f8b061b6/image-20260604-152146.png?cb=1acad3b88a0ebd6d82cc6c008493e9e4)
4. The **Bulk IoX App Management** panel will then appear. Click **Install** , then **Confirm**. This will then proceed to install IOT Services for each of the selected APs.

5. You can confirm this, by clicking on an **AP MAC** , then opening **Request History** and viewing the progress.

   ![image-20260604-152433.png](https://runbooks.ciscospaces.io/__attachments/a_e37046f67855fadc5d6008d9796875bcebf0573a86fce49b041aaa8b99adde35/image-20260604-152433.png?cb=f1021dfc33ae933849eef99cd5a2d4ce)
6. You can confirm the install was successfull, when Gateway Status is enabled, and IOX Channel Status is Up for all required APs.

   If this is not the case, see the section below on troubleshooting IOX Install

   ![image-20260604-152835.png](https://runbooks.ciscospaces.io/__attachments/a_5c795eeb93ad3be7954ec9f6b45cb8da5b87be90f8aa9b0eba22fa2ab88c62c8/image-20260604-152835.png?cb=a8f0303680d0965bf287d6964c0a8a87)
   IOX Install Success
7. Repeat the above steps for all buildings required.

##### Troubleshooting

Troubleshooting enabling IOT Services on WLC  
In the scenario they do not say SUCCESS, they will instead have an error code. You can click the WLC name to find out more information on what succeeded and what failed.

The following is also relevant if you see a WLC showing as DEGRADED, which in most cases implies IOT Services is not enabled on WLC, but is on Connector.  
![image-20260619-115547.png](https://runbooks.ciscospaces.io/__attachments/a_d01d3657d7cc4c4993b3a08a6f560e9b004961d396c91c4c58d01a1f2f8daa3c/image-20260619-115547.png?cb=85d81bab7a5d04125730295f17cf54fc)

Below is the full list of operations in order when enabling IOT Services on a WLC.

1. **Enable SCP Server**

2. **Get Trustpoint**

3. **Clean CA Certificate File**

4. **Clean CA Certificate Key Pair**

5. **Clean CA Certificate**

6. **Setup CA Certificate**

7. **Finish CA Certificate**

8. **Setup Streaming Token**

9. **Get Profile**

10. **AP Profile - Enable App Hosting**

11. **AP Profile - Enable AP Sensor**

12. **AP Profile - Enable GRPC Stream**

13. **Update Stream setup complete**

Most common scenarios for errors

* Netconf credentials are incorrect or user does not have correct privelage levels

* Required ports are not opened either between WLC and connector, or APs and connector

* In cases where IOX app fails to install, likely dont have enough storage. Reload AP or log into AP to delete flash.

After identifying and resolving any issues, you can use the 3 dots in the Action column to Enable Stream again, re-enabling IOT Services for that selected WLC.  
![image-20260604-145659.png](https://runbooks.ciscospaces.io/__attachments/a_958d933f6de105a7d1ccfec6e8c47a9d8068d7fef2c4654249876e2ba277ec6d/image-20260604-145659.png?cb=0390c6c37ec5b9a0708e72c5977f0052) Troubleshooting steps enabling IOT Services on AP  
Most common scenarios for errors

* Don't have correct netconf credentials or correct privelage levels

* Required ports are not opened either between WLC and connector, or APs and connector. See the Spaces OS Diagram in the Appendix for more info.

* In cases where IOX app fails to install, the AP likely don't have enough storage. Reload AP or log into AP to delete flash.

Meraki Deployments  
Support for Bluetooth Low Energy (BLE) devices are available on the Cisco Meraki network, in addition to the existing support on the Cisco Catalyst Wireless network.

This enhancement allows the Cisco Spaces platform to seamlessly integrate with BLE devices using Cisco Meraki. With this enhancement, Cisco Meraki BLE devices can now be accessed in various Cisco Spaces applications, including Firehose IoT Telemetry events, IoT Explorer, Signage, and Live Occupancy.

For this feature to work, you must perform specific configurations on the Cisco Meraki network to enable the data transmission to Cisco Spaces. Data flow is limited to read only, meaning Spaces can simply read the configuration and stream data from Meraki. Use cases such are limited to Scan based only, and configuration of BLE devices is not supported.  
Meraki use of IOT is only supported using the Spaces Meraki OAuth integration, and not via the API key mechanism

1. Login to the Meraki Dashboard and navigate to **Network-Wide** \> **Configure** \> **General.** Under **Location and scanning** verify that the following values are selected

   1. Analytics: **Analytics enabled**

   2. Scanning API: **Scanning API enabled**

   3. For Post URL, verify that there are two entries (one for Bluetooth, one for WiFi)

![image-20260622-132633.png](https://runbooks.ciscospaces.io/__attachments/a_5f59eb818a2b5d27f724b7af1f5f322eb19044048f635f3e3c7166566c52ac17/image-20260622-132633.png?cb=27cbd53cd02684d232ba46d4cd32a617)

If you need to configure any of these Post URLs manually, follow these steps:
Manual Configuration of Scanning API Post URLs  
1. Login to Cisco Spaces and navigate to **Setup** \> **Wireless Networks** \>**Connect via Meraki Integration** \> **2) Configure Meraki Integration** \>**Post URL** and click **Copy** next to the URL

2. Return to the Meraki Dashboard and click **Add a Post URL.**A new line will be created. Paste the value into the Post URL field.

3. Replace the \<URLValidator\> part of the URL with the Validator value shown in the field above.

![image-20260622-133605.png](https://runbooks.ciscospaces.io/__attachments/a_e17af7110f17e8ec03268cf2bee1d55f28c76c74e6c9960c62780cc35fb6296b/image-20260622-133605.png?cb=a0eafb7e69ab8c1df544f6f04c56ef89)

4. Copy the Secret from Spaces \> **Setup** \> **Wireless Networks** \>**Connect via Meraki Integration** \> **2) Configure Meraki Integration** \> **Secret Key** and paste it into the **Secret** field next to the Post URL.

5. Select **V3** for API version

6. Radio Type **WiFi** or **Bluetooth.**You should have one line for each.

7. Click **Validate**. A new yellow banner will appear to confirm the validation:

![image-20260622-140031.png](https://runbooks.ciscospaces.io/__attachments/a_fccf9d9be31b284b10c39aba9d482dace1f59fdcb3a4d4ef46e310f142715bdc/image-20260622-140031.png?cb=a7cb06fc59c4c9e05055edebc000b742)

8. Click **Save** to save changes on the page.

2. Navigate to **Wireless** \> **Configure** \> **IoT Radio Settings** \>**Bluetooth.** Set **Scanning** to **On**.

3. Repeat the process for all networks integrated with Spaces.

Meraki Dashboard APIs can be leveraged as a scalable mechanism for enabling IOT Radios. More information can be found [++here++](https://developer.cisco.com/meraki/api-v1/update-network-wireless-bluetooth-settings/).

4. Navigate to Cisco Spaces \> **?** (at the top of the page) \> **Support** \> **Configuration \& Deployment Support** and click **Open a Case.**Cisco Support Case Manager will open in a new browser tab.

   1. Copy and paste the following message template into your support case:

      1. Title: Support for MQTT broker configuration

      2. Description:

         Hi,

         We require support with the configuration of the MQTT broker. Scanning API configurations have been completed.

         Please provide the details required for the MQTT broker for the following networks: \<list networks\>

         Thank you.

   2. Cisco Support Team will provide you the details for the MQTT broker, including the broker password.

5. Navigate to **Wireless** \> **Configure** \> **IoT Radio Settings** \> **MQTT** and enable **MQTT telemetry streaming**.

6. Configure the **MQTT Broker** with the details provided by the Support Team.

7. Navigate all the way down on this page and enable **Bluetooth telemetry** and **Wi-Fi telemetry**. Ensure all Additional Message fields are checked.

8. Login to Spaces and navigate to Detect \& Locate. Select a location with a Meraki infrastructure and check that the number of BLE tags is non zero.

![image-20260623-091409.png](https://runbooks.ciscospaces.io/__attachments/a_631a86115ad1a4ef34172da098857d1f4e16312ff80f995d02c3dcaf5cff8a76/image-20260623-091409.png?cb=df3127a6ce0636ac3889e2ea117456aa)

##### IoT Services Device Filter

After enabling IoT Services, its generally suggested to enable a device filter. This helps reduce the noise of IoT devices in the dashboard, as well as reduce the load and increase the scalability on the Connector.

To enable IoT Services Device Filter

1. Head to **IoT Services \> Settings** .

   ![image-20260618-184839.png](https://runbooks.ciscospaces.io/__attachments/a_a32d32ab43f55f23cf5f79e50dcf19a8906fe32de57d6a6fb1dac181fe44114b/image-20260618-184839.png?cb=2efd9ccc640acdf9b433bfc72e41ade2)
2. Ensure the following is configured:

   1. **Allow Public MACs → True**

   2. **Allow Random Static MACs → True**

   3. **Allow Random Private MACs → False**

Configure MAC filter  
1. Under the Device Filtering section, and click the **+ Add** button next to **Allow MAC Prefix Configuration**.

2. You will then be asked to enter a **New MAC Prefix**. Use the known MACs of IOT devices you want to use within Spaces. These can be found on devices, configuring the claim code within Spaces, or by finding the devices in Detect and Locate (using the manufacturer field to help).

*** ** * ** ***

## DELIVERING OUTCOMES

Now Cisco Spaces OS is complete, which sets up Spaces in the most successful way for now delivering outcomes. Most outcomes should now simply be enabled in a few clicks, and be compatible to run side by side with each other using the same infrastructure. Each outcome will have its own pre-requisites and steps on how to implement them. Use the following Outcomes Runbooks on steps to deliver.  
![image-20260612-103404.png](https://runbooks.ciscospaces.io/__attachments/a_b1726fc90a98b3acc229e59d77be4d1221a268201713cd8e63346cd0f9fe547b/image-20260612-103404.png?cb=370b51067f072a473fd13b79967ae813)

### [++Smart Workspaces++](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida)

Cisco Spaces Smart Workspaces transforms traditional work environments into dynamic, data-driven ecosystems that enhance productivity and collaboration. By leveraging advanced location-based services, Smart Workspaces enables organizations to optimize space utilization, streamline operations, and create a more engaging workplace experience.

### [++Asset Tracking++](https://runbooks.ciscospaces.io/docs/cisco-spaces-asset-tracking-runbook-cisco-validated)

Lack of real-time Asset tracking solutions can add critical bottleneck to your supply chain operations and in the healthcare industry, cause life-threatening delays.

With Spaces native apps you can track all devices connected to your network in real time and with a host of partner apps \& BLE devices, you can monitor and manage all critical or high value assets in your campuses.

### [++Occupancy++](https://runbooks.ciscospaces.io/docs/cisco-spaces-occupancy-runbook-cisco-validated)

Cisco Spaces provides a comprehensive platform for leveraging location-based services to enhance operational efficiency and decision-making.

The "Occupancy" outcome within Cisco Spaces is designed to monitor and analyze the utilization of physical spaces, allowing organizations to optimize their environments effectively. By integrating real-time data from connected devices and sensors, users can gain valuable insights into space usage patterns, identify trends, and ensure compliance with occupancy regulations.

This documentation will be a guide through the setup process, enabling an organization to harness the full potential of Cisco Spaces for occupancy management and drive informed decisions for space planning and resource allocation.

### [++Captive Portal++](https://runbooks.ciscospaces.io/docs/cisco-spaces-captive-portal-runbook)

A captive portal is the first touchpoint with your business for customers on Wi-Fi. It provides an opportunity to engage with customers who connect to Wi-Fi, offer relevant information, drive monetization, and potentially acquire customer information. Captive portals enable businesses to choose from multiple authentication mechanisms and deliver targeted experiences based on business rules. They can recognize repeat visitors and deliver customized offers, enhancing customer engagement and loyalty.

### [++OpenRoaming++](https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated)

OpenRoaming enables secure, seamless, and automatic network connectivity by eliminating tedious Wi-Fi guest onboarding processes and the risk of connecting to rogue SSIDs. This is especially helpful for a mobile device user trying to access the internet because OpenRoaming removes the need to choose between multiple SSIDs, or enter insecure, shared credentials on poorly designed captive portals.

### [++Indoor Navigation++](https://runbooks.ciscospaces.io/docs/cisco-spaces-indoor-navigation-runbook-cisco-valid)

Indoor Navigation enabled indoor and campus based wayfinding leveraging Cisco Access Points to deliver accurate positioning and routing. Indoor Navigation helps guests and staff effectively find locations within a building, saving time and effort needed.

### [++Smart Rooms++](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-rooms-runbook-cisco-validated)

Cisco Smart Rooms seamlessly integrate your existing Cisco Webex devices with your Building Management System (BMS) to provide demand control ventilation, optimize the experience, wellbeing, and productivity of your existing spaces when in use, and reduce energy use when spaces are not in use.

### [++Space Explorer Web App++](https://runbooks.ciscospaces.io/docs/space-explorer-web-app)

The Space Explorer Web App allows flexible access with SSO login (via Webex, Microsoft, and Google Login - more details below) to authenticate end users. The Web App is complementary to the Space Explorer Kiosk app meant to be displayed on a lobby display. In addition to room occupancy and calendar status, the Space Explorer Web App adds Smart Desking functionality to Cisco Spaces workplace experience applications. It is a flexible workspace solution that allows employees to reserve dynamically allocated desks ("Hot Desks") instead of having assigned seating. It is a key part of hybrid work models and is commonly managed through IoT, AI, and cloud-based platforms.

*** ** * ** ***

## CAVEATS \& TIPS

### Placing GPS Markers

As mentioned above, the preferred route for GPS configuration is to use the Network Maps Calibration tool

GPS Markers are utilised in Cisco Spaces, any time converting between x,y and lat,lon locations.  
For detailed best practice, refer to this [++Knowledge Article++](https://runbooks.ciscospaces.io/docs/guide-to-network-map-geo-placement-and-best-practi).

This function is used by the following apps today, but is likely to expand. Its recommended to implement GPS markers in all deployments of Spaces, even if these features are not used today.

* Space Manager

* Wayfinding

* Smart Workspaces

* App Center delivered use cases

Recommendation is to place 3 markers per floor. Use [++OpenStreetMap++](http://www.openstreetmap.org/) to gather the appropriate lat,lon details. Use prominent features (such as corners of the building) to accurately place markers.

**Failing to follow the above will result in a poor experience.**

1. Log into Catalyst Center, and navigate to **Design** \> **Network Hierarchy**, on the left pane select a floor.

2. From the map toolbar, click the **GPS Markers** toggle.

3. From the map left pane, click the **GPS Markers** icon**.**

4. Use the drawing tool to place the GPS marker:

   1. Click on the map to place the GPS marker.

   2. In the **Place Markers** pop-up window, enter the name, latitude, longitude, x and y coordinates in the appropriate fields.

   3. Click **Add GPS Marker**.

5. Repeat these steps until there are three GPS markers on the floor map in a polygon-shape.

6. Click **Save** from the map toolbar.

The GPS marker is an attribute of the building and can be applied to all the floors of the building.

### Wireless Network Design Tips

#### Overview

The density of a wireless deployment will be a major factor in the accuracy of occupancy depending on the specific outcome needed. Occupancy using Wi-Fi may not require a dense coverage for campus and building occupancy details as it relies on devices connecting to the Wi-Fi network. Moving into an outcome where Floor and Zone level accuracy is required, a denser network deployment is highly recommended.

#### AP Density Assessment

APs needs to be accurately placed on network maps​ to ensure the best outcomes.

* WLC managed Aps :​

  * [++AP Auto Locate++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m-device-placement.html) (preferred)​

    * Note: WLC version 17.12.2+ (required)​

  * AP placement on Catalyst Center (**site survey to confirm AP location -- required**)​

    * [++GPS Markers for network map and wayfinding map geo-alignment++](https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/catalyst-center/2-3-7/user_guide/b_cisco_catalyst_center_user_guide_237/m_work-with-wireless-2d-and-3d-maps.html#Cisco_Task_in_List_GUI.dita_cb69eac4-798d-4741-861c-3e88f3ea2a32) ​

* [++Cloud managed Aps :++](https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Using_a_Floor_Plan_or_Custom_Map_in_Dashboard#Why_Geoalignment_Matters)​

  * [++Geo-alignment of Meraki Dashboard network map++](https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Using_a_Floor_Plan_or_Custom_Map_in_Dashboard#Why_Geoalignment_Matters)​

  * [++Manual placement of Meraki APs on Meraki Dashboard network map++](https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Placing_Devices_on_the_Map_in_Dashboard)​

**AP Auto Locate**

* AP Auto locate can provide most accurate information about AP placement​

* Here are more details : [++AP Auto Locate++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m-device-placement.html) ​

For best practice guidance for implementing AP Auto Locate please review [++this guide here++](https://www.cisco.com/c/en/us/support/docs/wireless/spaces/225868-understand-best-practices-ap-auto.html).

**Catalyst Center**

4 or more (minimum of 3) GPS Markers are required, and each should be placed at least 20 meters apart from each other. This is to ensure proper scaling and orientation of Catalyst Center network maps when aligning with Digital Maps on Cisco Spaces.

More details here : [++GPS Markers for network map and wayfinding map geo-alignment++](https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/catalyst-center/2-3-7/user_guide/b_cisco_catalyst_center_user_guide_237/m_work-with-wireless-2d-and-3d-maps.html#Cisco_Task_in_List_GUI.dita_cb69eac4-798d-4741-861c-3e88f3ea2a32)

**Meraki Cloud Managed**

Please refer to the following : ​

* [++Geo-alignment of Meraki Dashboard network map++](https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Using_a_Floor_Plan_or_Custom_Map_in_Dashboard#Why_Geoalignment_Matters)​

* [++Manual placement of Meraki APs on Meraki Dashboard network map++](https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Placing_Devices_on_the_Map_in_Dashboard)

* Additionally, the following video will help illustrate the alignment process: <https://app.vidcast.io/share/f1faa92d-66e3-4da1-be78-0b6ec79e9123> ​

#### AP Placement

The density of AP deployment in terms of "1 AP per X sq ft" can be found by using:

(***Number of APs on floor) / (Total Sq ft of the floor)***

**Number of APs on floor**

This information is available from the Spaces Dashboard ​

Navigate to **Location Hierarchy** , then to the desired building and select the desired floor. On the main page select the **Network Devices** tab. You will see the number of APs next the **Access Points**section.  
![image-20260612-131836.png](https://runbooks.ciscospaces.io/__attachments/a_bebfcb6c23620b940ef3e004f0c262bfc814168ec8e88cf0b1bf5867b41178be/image-20260612-131836.png?cb=bd62c4648070d96a638ec72f991a2ce2)

**Total Sq ft of the floor**​

* This information can be retrieved from the dashboard Location Hierarchy section as long as the manual input has been updated accurately ​

![image-20260612-132706.png](https://runbooks.ciscospaces.io/__attachments/a_341c72d5be638c3f483415f0bcfc234db7f3407a20ad7623251a63acdda9124f/image-20260612-132706.png?cb=e126aea5718d66dbe5c74999306b4a2f)

* Otherwise, estimate the floor using Google Maps by providing exact building address and using measure distance feature as shown below

  * This assumes that the floor plan matches the footprint of the building

  * The example below draws along the rooftop of the building as it matches the floor plans within the building

  * Once the points are all connected around the perimeter, Google maps will provide a square footage calculation in the window and the bottom center of the screen

![Screenshot 2024-10-11 at 9.45.52 AM.png](https://runbooks.ciscospaces.io/__attachments/a_7772d9f4dd8fb223c86c6014bec10bdf6f6e3a719dc98926aa8b0faaa995093a/Screenshot%202024-10-11%20at%209.45.52%E2%80%AFAM.png?cb=caae49d8465a3fa448eeae63cd2e4e06)

*** ** * ** ***

### Kiosk List of API Endpoints for Firewall Settings

|                                                                                                                                                                                          **IO Region**                                                                                                                                                                                          |                                                                                                                                                                                          **EU Region**                                                                                                                                                                                          |                                                                                                                                                                                                 **SG Region**                                                                                                                                                                                                 |
|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| [https://kiosk.dnaspaces.io](https://kiosk.dnaspaces.io/) wss://webex-api-server.dnaspaces.io [https://rms.dnaspaces.io](https://rms.dnaspaces.io/) [https://api.mapbox.com](https://api.mapbox.com/) [https://events.mapbox.com](https://events.mapbox.com/) [https://workspaces.dnaspaces.io](https://workspaces.dnaspaces.io/) [https://fonts.googleapis.com](https://fonts.googleapis.com/) | [https://kiosk.dnaspaces.eu](https://kiosk.dnaspaces.eu/) wss://webex-api-server.dnaspaces.eu [https://rms.dnaspaces.eu](https://rms.dnaspaces.eu/) [https://api.mapbox.com](https://api.mapbox.com/) [https://events.mapbox.com](https://events.mapbox.com/) [https://workspaces.dnaspaces.eu](https://workspaces.dnaspaces.eu/) [https://fonts.googleapis.com](https://fonts.googleapis.com/) | [https://kiosk.ciscospaces.sg](https://kiosk.ciscospaces.sg/) wss://webex-api-server.ciscospaces.sg [https://rms.ciscospaces.sg](https://rms.ciscospaces.sg/) [https://api.mapbox.com](https://api.mapbox.com/) [https://events.mapbox.com](https://events.mapbox.com/) [https://workspaces.ciscospaces.sg](https://workspaces.ciscospaces.sg/) [https://fonts.googleapis.com](https://fonts.googleapis.com/) |

*** ** * ** ***

### Meraki Firewall Issues

Depending on security policies of the Meraki environment the following IP addresses may need to be added to be permitted for communication with Cisco Spaces:

These settings are found under Organization \> Settings \> Login IP ranges \> Allow dashboard API Access to these IP Ranges.  
![image-20241121-151631.png](https://runbooks.ciscospaces.io/__attachments/a_f54b365cdff6a10baae4094ad952f7fcf5874341187aa62b99a0fee09b439f2e/image-20241121-151631.png?cb=c0aae97e73e7b53a49910ae426310db2)

Caution: Selecting "Allow Dashboard and Dashboard API Access to these IP Ranges" could restrict access to the Meraki Dashboard. Ensure that "Dashboard API access" is selected.

Exercise due diligence before enabling any new security restriction. Important API applications could unwittingly be locked out (e.g. those provided by ecosystem partners or service providers) from the organization if their IP ranges are not included before enabling this feature.

|    **US**     |     **EU**     |     **SG**     |
|---------------|----------------|----------------|
| 34.192.26.106 | 52.208.15.59   | 3.1.251.174    |
| 52.206.67.43  | 54.220.148.167 | 13.215.110.252 |
| 3.208.52.128  | 54.220.45.63   |                |

*** ** * ** ***

## FAQ

**Acronyms used**

API - Application Programming Interface

BLE - Bluetooth Low Energy

CAD - Computer-Aided Design

DNS - Domain Name System

GPS - Global Positioning System

IoT - Internet of Things

NETCONF - Network Configuration Protocol

NMSP - Network Mobility Services Protocol

SNMP - Simple Network Management Protocol

SSID - Service Set Identifier

vCPU - Virtual Central Processing Unit

VM - Virtual Machine

WLC - Wireless LAN Controller

XREF - Cross Reference

**What is Cisco Spaces OS and what are its key features?**

Cisco Spaces OS is the fundamental software platform for managing and deploying location-based services within the organisation. It acts as the base installation and seamlessly integrates a suite of critical components designed to streamline operations and enhance data utilisation.

Key features include:

* Onboarding data from various sources like Catalyst Center, Wireless LAN Controllers (WLC), and Meraki for a holistic view.

* Unified location hierarchy configuration for organised network views and access point deployment management.

* Digital Map creation using uploaded CAD files for visual representation of spaces, enhancing navigation, and planning.

* Enabling IoT streaming services, allowing organisations to leverage real-time data insights for better decision-making.

**How do I onboard Cisco devices and intake telemetry data into Spaces OS?**

Spaces OS supports onboarding data from various Cisco platforms, including Catalyst Wireless, Catalyst Center, and Meraki. Each platform has a specific process for integration.

For Catalyst Wireless:

The Cisco Spaces Connector needs to be installed on a virtual machine, allowing communication with the WLCs. Detailed instructions on configuring the connector, adding WLCs, and establishing connectivity can be found in the Cisco Spaces OS Runbook.

For Catalyst Center:

Ensure Catalyst Center is at Release 2.1.2.3 or higher and accurately placed GPS markers. The integration process involves creating a token in Cisco Spaces, activating CMX Servers/Cisco Spaces in Catalyst Center, and configuring service selection under the Wireless tab in Network Settings.

For Meraki Wireless:

A Meraki account can be connected to Cisco Spaces via the Meraki dashboard. Options are to choose to integrate into an existing Spaces account or create a new one. Detailed steps for both options are available in the Cisco Spaces OS Runbook.

**What is Location Hierarchy in Cisco Spaces OS, and how do I configure it?**

Location Hierarchy enables the ability to organize the network view within Cisco Spaces based on the physical business locations and access point deployments. This hierarchy can be structured based on brands, regions, campuses, and other relevant taxonomies.

To configure:

1. Access the Location Hierarchy feature under Setup \> Locations \& Maps.

2. Review existing hierarchies ingested from integrated platforms like Catalyst Center, Meraki, and Webex Control Hub.

3. Merge similar location hierarchies using the 'merge with' option.

4. Configure metadata like Time Zone, Capacity, and Area for accurate occupancy computation.

**Why are GPS Markers important in Cisco Spaces OS, and how do I place them?**

GPS Markers play a crucial role in converting between x,y and lat,lon locations within Cisco Spaces, ensuring accurate location-based services. They are vital for apps like Space Manager, Wayfinding, and Smart Workspaces.

To place GPS Markers:

1. In Catalyst Center, navigate to Design \> Network Hierarchy and select a floor.

2. Enable the GPS Markers toggle from the map toolbar.

3. Use the drawing tool to place markers on the map, providing a name, latitude, longitude, and x, y coordinates for each.

4. Place at least three markers per floor, using prominent features like building corners for accuracy.

**How do I create Digital Maps in Cisco Spaces OS?**

Digital Maps in Cisco Spaces provide visual representations of the spaces, enhancing navigation and planning.

To create a Digital Map:

1. Go to **Setup** \> **Locations \& Maps** and click the **Digital Maps** tab.

2. Select the desired building and click "Add Digital Map."

3. Confirm the building's street address for accurate location pin placement.

4. Add floors by clicking "Add new floor" and providing necessary metadata like level numbers and short names.

5. Upload CAD files or Vector PDFs for each floor, ensuring one file per floor.

6. Review and confirm the uploaded files, then submit for processing.

7. Once processed, review the unpublished Digital Map and add/edit room labels.

8. Publish the building to make the Digital Map available in Cisco Spaces.

**What are some best practices for uploading CAD files for Digital Maps?**

Please refer to the [++US National CAD Standard++](https://www.nationalcadstandard.org/ncs6/content.php) for guidance on layer details.

There are 3 main elements for a great CAD file (.dwg) or Vector PDF with layers:

1. Architectural layers (e.g. walls, doors, stairs, windows, etc.)

2. Furniture layer

3. Space names / IDs / labels

Additional best practices:

* Spaces (Space Type) marked clearly or detail provided. For example, a space with a collaboration endpoint will need a room or desk to assign it to.

* Have clearly defined or marked POIs like stairs, bathrooms, elevators etc.

* Room Names:

  * Should be intuitive for end-users

  * Should be made as short as possible whilst keeping readibility (i.e. don't include building/floor/zone names, room size, room type, etc.)

  * Ideally the room names in the CAD file match the workspace name in Webex Control Hub. Without this, manual mapping of room name to Webex Control Hub workspace must be done.

  * Sometimes, a CAD or Vector PDF file can have multiple such identifiers for the same room. In this case, please leave a comment in the upload workflow with which identifier should be used as a name for the spaces.

* Provide clear layer names in CAD. For example: "A-Furn" (furniture), "Doors" (for doors), "Windows" (for windows), etc.

* Keep elements in separate layers. Example: walls, doors, labels in their own layers.

* Cross Reference (XREF) layers will not be processed. "Bind" them into a single .dwg when exporting from AutoCAD or another program.

**How do I export a complex CAD (.dwg) file from AutoCAD with multiple layers that I do not want to include for the Digital Map?**

If the CAD (.dwg) file has as a "Layout" tab with the exact layers and objects needed:

1. Right-click on the tab (bottom of the application window on macOS)

2. Choose the "Export Layout to Model..." option

The resulting CAD (.dwg) file will only contain the layers and objects visible in that Layout.  
![AutoCAD - Export Layout to Model...](https://runbooks.ciscospaces.io/__attachments/a_69aa45743dce9b69eca0cc4af8b53a8892de0934d22597dd2061979419dd38e5/AutoCAD%20-%20Export%20Layout%20to%20Model....png?cb=7e8fc15b643b678789616c9e163df0a3)
AutoCAD - Export Layout to Model...

**What kind of changes can I expect when re-uploading CAD files to modify existing Digital Maps?**

There are a few scenarios where intentionally or unintentionally re-upload CAD files may be necessary:

1. After uploading CAD files for the first time (before finished processing), canceling is perfectly acceptable. Canceling the processing will make it possible to choose different files (if chosen mistakenly or realizing some changes were needed in the file contents) or add/remove files from processing. Otherwise, waiting for the first round of processing (per building) is necessary before adding or removing any floors.

2. After map processing has completed and there are missing objects in the Digital Map (among other reasons - see below), re-upload the exact same file as before and a new reason, comments, and attachments modal appears inline. The reason dropdown categories are:

   1. Missing objects (e.g. walls, furniture)

   2. Missing spaces (e.g. floor space is invisible where a room or other space type should be)

   3. Missing space names/labels (e.g. wrong layer or metadata used for room names)

   4. Changed street address or GPS center-point of building

   5. Multiple reasons or Other (comment below)

Provide additional comments to help our mapping team review the AI processed maps and provide a faster/better update. Optionally include an image with annotations for a holistic picture of the corrections needed.  
![Re-upload CAD files.png](https://runbooks.ciscospaces.io/__attachments/a_e4cd1804361664f02ab57f4f919e1fcd2a911a673d40ad53a8b34e731c30e6cb/Re-upload%20CAD%20files.png?cb=a80b80c51d73a79a1516969ba935471a)
Re-upload CAD files  
![Re-upload CAD files - reasons dropdown](https://runbooks.ciscospaces.io/__attachments/a_9ab34b2234ae343f8ab146f9efed49be02f92b96706064063144e7e82b1bb00b/Re-upload%20CAD%20files%20-%20reasons%20dropdown.png?cb=1dc05cf691eeb319729bf692d65535a5)
Re-upload CAD files - reasons dropdown

3. Similar to scenario 2 above, the Location Hierarchy has changed and the exact same files are used to create the same Digital Map in a new Location. Use the appropriate reason dropdown option: "Changed street address or GPS center-point of building". This also applies to re-uploading when the Cisco Spaces mapping team has declined/rejected a CAD file because the building could not be found on the world map. Please provide additional details in the comments field to help the mapping team accurately align the Digital Map on the world map for accuracy in outcomes.

Note: a building can only exist in one place in the world and cannot be duplicated across multiple Locations in the Location Hierarchy or in multiple Cisco Spaces Tenants. Only the most recent upload will work correctly for outcomes such as Pathfinder on Space Explorer Kiosk and Indoor Navigation App Clip for turn-by-turn blue-dot wayfinding indoors.

4. After CAD files are finished processing and Published, it is safe to upload additional floor files or modify existing with new file versions. Follow the same workflow as before, but either create new floors (w/ metadata) or check the boxes for floors to update specifically to change the files.

Note: re-uploading unchanged floors is not necessary. When re-uploading, only check the boxes for the floors that need to be updated.

5. Currently, it is not possible to delete individual floor Digital Maps. Please open a TAC case to request help removing unwanted files until this feature is available in the dashboard.

6. Currently, it is not possible to process individual floors in parallel in the same Building. Either cancel a map processing job and re-upload or wait for the current process to complete and Publish. Then, proceed with the next upload. Multiple parallel floor uploads in the same Building will be possible in a future update.

**Will Webex Workspaces remain connected to the Meeting Rooms after re-uploading CAD files to modify Digital Maps?**

There is not currently a way to edit a Digital Map directly with new walls, rooms, or furniture after a CAD file has been processed. To make physical layout changes, upload a modified CAD file to the Cisco Spaces Digital Map platform, and it will attempt to carry forward metadata (e.g. Webex Workspace connection, Meeting Room name manual edits). Generally, metadata associations stay intact in the database as long as the internal identifiers have not changed. Typically, a furniture layout will not create new identifiers, but physically moving walls or changing a room name in the CAD file will create new entities on the backend and erase previous manual edits in the Digital Map Editor (e.g. room name). IoT Sensor associations should carry forward as well.

The Digital Map Editor (under **Setup** \> **Locations \& Maps** \> **Digital Maps**) provides an interface to make lightweight, metadata changes to previously processed CAD files. For example: space names, space IDs, and space types. While it is quite easy to manually make these edits, the source CAD files do not receive those edits.  
**It is important to always keep your source CAD files up to date** so that when they are re-uploaded for processing at any point in the future to update the physical layout, space metadata (e.g. name, ID, type) remains intact and is not reverted. If this metadata remains identical to the previous version uploaded and processed, manual edits will carry forward. Any diff in a new file version will overwrite manual edits that conflict.

If new or moved rooms' names are close matches to their respective Webex Workspaces, auto-connecting in Space Manager \> Manage Rooms should reduce manual work to associate all collaboration devices with rooms post-processing CAD files.  
**Note:** Webex Workspaces must be assigned to a Location and a Floor in Control Hub to benefit from auto-connect based on name matching. IoT Sensors will need to be re-added if physical spaces or name have changed significantly, as they do not benefit from auto-connection by name.

**What do I need to keep in mind for Campus Wayfinding (i.e. indoor-outdoor and inter-building navigation)?**

There are several factors that affect Campus Wayfinding and decrease time to process CAD files:

1. Campus wayfinding is performed within a single campus element in the hierarchy. Therefore navigation between buildings must be within the same campus. The campus element is defined as the immediate parent of any building.

2. A group of Buildings (i.e. Campus) **MUST** fit within a 100km² area (roughly 10km x 10km). To be safe, the distance between the 2 furthest buildings must be no more than 8km.

3. Geo-alignment on the world map is essential. Elements included in the CAD files (e.g. bridgeways, paths, etc.) can help align Buildings to ensure smooth transitions between Buildings in a Campus.

**How do I enable IoT Services in Cisco Spaces OS?**

IoT Services extend the capabilities of Cisco Spaces by enabling BLE on compatible access points and creating a telemetry stream for data.

To enable:

1. Navigate to **IoT Services** on the left-hand side menu.

2. Ensure all prerequisites are met and click the "Activate" button.

3. Select "Wireless" and proceed to the next step.

4. The Activation Screen shows the number of active connectors and controllers.

5. It can be chosen to activate IoT services everywhere or customize the deployment by selecting specific connectors, controllers, or APs.

**What firewall settings are required for Cisco Spaces Kiosk to function correctly?**

To ensure Cisco Spaces Kiosk functions properly, firewall settings might need to be adjusted to allow communication with specific API endpoints. The required endpoints vary based on the Spaces region (IO, EU, or SG).

Refer to the "Kiosk List of API Endpoints for Firewall Settings" section in the Cisco Spaces OS Runbook for the complete list of endpoints for each region. Make sure the firewall permits traffic to these endpoints to prevent connectivity issues with the Kiosk application.

**If I complete AP Auto Locate in Spaces will the AP placement sync into Catalyst Center?**

No this is not functionality that is available today. AP Auto Locate is planned to migrate to both Catalyst Center and Meraki, so placement is done in those platforms and passed into Spaces.

**How can I confirm if netconf is enabled on my WLC?**

You can SSH from connector to WLC over the netconf port number (default 830).

    ssh -p 830 -s <username_configured_in_Spaces>@<controller_IP> netconf

If the user connects, this proves that connector can establish netconf to WLC using the give user.

*** ** * ** ***

## APPENDIX

### Spaces OS Diagram

![Screenshot 2025-03-11 at 7.11.04 PM.png](https://runbooks.ciscospaces.io/__attachments/a_9a85baacf5b56b7528c8a1fe894eb0ff4e19e789457adb86729a2f7b74ac97fb/Screenshot%202025-03-11%20at%207.11.04%E2%80%AFPM.png?cb=76fbc58f4662bf070e1d2fdb9d908793)

### Spaces OS Checklist

* [ ] Prerequisites
* [ ] Verify all necessary firewall rules are in place for Spaces connectivity
* [ ] Retrieve metadata for locations (need max occupancy for floors and building, total area sq ft/mt, and time zone)
* [ ] CAD drawings acquired
* [ ] Smart Account linked
* [ ] Catalyst managed specific environments
* [ ] Configuration and Activation of Spaces Connector(s)
* [ ] Wireless controller(s) added
* [ ] Catalyst Center or Meraki integration
* [ ] Webex Control Hub Integration
* [ ] Network Hierarchy Merges
* [ ] Metadata entered into hierarchy
* [ ] Digital Map(s) published
* [ ] Network map(s) and Digital map(s) aligned
* [ ] Devices (e.g. Webex) mapped to rooms
* [ ] AP placements on map(s) \[one of the following\]
* [ ] AP AutoLocate (auto or manually placed)
* [ ] Placed in Catalyst Center or Meraki Dashboard
* [ ] IoT Services Activated
* [ ] Live Occupancy SSID Filters set

---
language: "en"
---
# Cisco Spaces Partner Ecosystem Overview

## OVERVIEW

The Cisco Spaces Partner Ecosystem connects application and device partners with Cisco's cloud-based location platform to deliver real-world business outcomes through location intelligence. This runbook provides a streamlined guide for partners to understand the ecosystem, explore integration options, navigate onboarding, and successfully publish and manage their solutions within Cisco Spaces.

*** ** * ** ***

## INTRODUCTION TO PARTNER ECOSYSTEM

Cisco Spaces is a unified cloud platform built on a layered architecture that transforms physical environments into smart spaces by integrating devices, sensors, and applications. At its foundation are Cisco's wireless infrastructure, sensors, and third-party IoT devices that provide real-time telemetry and environmental data. This data is processed and contextualized through Cisco Spaces location and occupancy services, enriched with AI-powered maps and spatial metadata.

Partners play an important role at the top and bottom layers of this stack - building and integrating applications that extend the value of Cisco Spaces into enterprise use cases and devices that gather and transmit information. Through SDKs, APIs, and the Partner App Center, application and device partners can deliver tailored outcomes for customers across industries. The ecosystem offers the tools and infrastructure needed for partners to innovate, integrate, and scale solutions on a platform designed for smart, connected environments.  
![image-20250811-194801.png](https://runbooks.ciscospaces.io/__attachments/a_321ab5d592cb2075a564013e9e743403c35d588d0dbbf0b597f1ea55cde80445/image-20250811-194801.png?cb=8d64fb541924d3307183b345edb5b5e0)

*** ** * ** ***

## COMPONENTS OF THE ECOSYSTEM

This section introduces the core components that collectively support partners in building, managing, and delivering innovative solutions through Cisco Spaces.

### Cisco Spaces

[Cisco Spaces](https://spaces.cisco.com/) is a cloud platform that transforms your buildings into smart spaces. By leveraging Cisco networking and collaboration devices as sensors, Cisco Spaces reimagines how employees, customers and visitors experience your spaces, boosts operational efficiency, optimizes energy and maximizes efficiency of space - all at a significantly low Total Cost of Ownership (TCO).

Cisco Spaces is deployed across 14 billion square feet globally across healthcare, workplaces/ offices, financial services, retail, education, hospitality, stadiums and venues, airports, and warehousing facilities. Spaces is consistently recognized for its excellence by customers - it has been named a Customer Choice platform for Indoor Location Services in 2020, 2021, 2022, and 2023 and is Top Rated on TrustRadius for Location Intelligence. With a 172% ROI and payback in just six months, it's a powerful, scalable solution that grows with your needs ([Forrester Total Economic Impact Report](https://spaces.cisco.com/forrester-tei-report/)).

[Take a product tour](https://spaces.cisco.com/spaces-product-tour/) to explore the platform and applications.  
![image-20250805-235857.png](https://runbooks.ciscospaces.io/__attachments/a_42f0d4c05de9f466eb4683d6e35e073bd254153e69f029abded1d5ab8d0b4cd1/image-20250805-235857.png?cb=d352c11d2c94abbce4c2f759fb657290)

### Partner Dashboard

The Partner Dashboard serves as the central hub for Cisco Spaces partners, offering a unified interface to create, manage, and monitor applications. Partners can submit new applications, track the status of their submissions, update app details such as descriptions and screenshots, and access tools to test application functionality and integration with Cisco Spaces data. This streamlined platform simplifies the application lifecycle, enabling partners to efficiently maintain and deliver high-quality integrations within the Cisco Spaces ecosystem.

Read more on [how to use the Partner Dashboard.](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/partner-dashboard/basic/b-dnas-pd/m-dnas-partners-supporting-apis.html?bookSearch=true#id_133183)  
![image-20250805-235730.png](https://runbooks.ciscospaces.io/__attachments/a_f08eff8508a1ac63395e825a7d36ea64bb39c4dd4aa132dbc8932671d050497b/image-20250805-235730.png?cb=4ed56e6162a71ee53cf2ff6d28b26c1f)

### Partner App Center

The Partner App Center is the integration marketplace within Cisco Spaces, where validated partner applications are published and made accessible to customers. It enables streamlined discovery, activation, and deployment of partner solutions directly within the Cisco Spaces environment. All applications undergo a validation process to ensure technical compatibility and security. Once validated, they are made available to a broad customer base, with deployment initiated through a seamless activation workflow.

This platform not only enhances solution visibility for partners but also ensures that customers can deploy interoperable, scalable, and secure integrations within their environments. Partner applications play a critical role in enabling industry-specific business outcomes. By leveraging real-time location data, environmental telemetry, and contextual insights from Cisco Spaces, these applications deliver targeted use cases tailored to sector-specific needs. The App Center gives customers confidence in selecting solutions aligned with their operational goals and industry requirements. For example, in smart workplaces, partners offer applications for occupancy analytics, space booking, and air quality monitoring---enabling space optimization, sustainability, and improved employee experience. In healthcare, partner solutions support asset tracking for critical equipment, staff duress systems, and patient flow analytics, helping to improve operational efficiency, safety, and care delivery.  
![image-20250805-234823.png](https://runbooks.ciscospaces.io/__attachments/a_f49d3a6cf9393d2210c6e512cdc10de260341672386c96d2ccf80b5ad36e907c/image-20250805-234823.png?cb=8be9d998f234c5d3f3730e95c4293c58)

### Cisco Spaces IoT Devices Marketplace (IDM)

The IoT Devices Marketplace features devices that are compatible with Cisco Spaces. Customers can filter devices based on industry type, use cases, technologies, price range, and other criteria. Technical specifications for each device are clearly detailed, along with a list of compatible partner applications. Additionally, customers can request more information or ask for a quotation directly through the marketplace, after which the vendor team will reach out with further details.  
![Screenshot 2025-08-05 at 11.40.52 AM (2).png](https://runbooks.ciscospaces.io/__attachments/a_b787ce19917d392fadf525e41d0cd1a3e45cbd0ebeb3194c31b9333a639d8a41/Screenshot%202025-08-05%20at%2011.40.52%E2%80%AFAM%20(2).png?cb=f7a22e47193fd52e8022fbc1280b6fb7)

*** ** * ** ***

## CISCO SPACES OUTCOMES AND USE CASES

Cisco Spaces enables outcome-driven solutions across various industries by leveraging real-time location data, IoT integrations, and intelligent analytics. Below are key outcomes and use cases.  

|             **Outcome**              |                                           **Use Cases**                                            |        **Industries**        |
|--------------------------------------|----------------------------------------------------------------------------------------------------|------------------------------|
| **Workplace Efficiency**             | Occupancy Analytics, Space Availability, Hot Desking, Indoor Navigation, Sustainable Meeting Rooms | Workspaces                   |
| **Patient Safety \& Experience**     | Infant Protection, Staff Duress, Patient Safety, Patient Engagement                                | Healthcare                   |
| **Seamless and Secure Connectivity** | Seamless Wi-Fi Onboarding                                                                          | Healthcare, Retail \& Venues |
| **Customer Engagement \& Loyalty**   | Personalized Engagements, Customer Acquisition \& Loyalty                                          | Retail \& Venues             |
| **Behavioral Insights**              | Visitor Behavior Analytics, Visitor Segmentation                                                   | Retail \& Venues             |
| **Asset Visibility**                 | Asset Tracking                                                                                     | Logistics \& Warehouses      |
| **Operational Safety**               | Employee Safety                                                                                    | Logistics \& Warehouses      |

*** ** * ** ***

## CISCO SPACES PARTNERSHIP PROGRAMS

### **Cisco Spaces Application Partners**

Application Partners encompass independent software vendors (ISVs), developers, and organizations that design and develop applications utilizing the Cisco Spaces platform, its APIs, and associated data. These applications enhance the overall value proposition for Cisco Spaces customers by enabling advanced capabilities such as advanced analytics, digital engagement, environmental monitoring, and other innovative solutions. All partner applications are featured and distributed through the Cisco Spaces Partner App Center.

**Key Features \& Benefits**

* Access to Cisco Spaces APIs, SDKs, and developer tools

* Capability to develop outcome-driven solutions leveraging Cisco Spaces data

* Application listing within the Cisco Spaces Partner App Center that is discoverable by Cisco Spaces customers

* Increased visibility to Cisco Spaces' extensive global customer network

#### How to become a Partner

To request a Cisco Spaces partner account, visit [Cisco Spaces Partner Dashboard](https://partners.dnaspaces.io/partner) and click Partner with us. Choose the appropriate partnership type - Application or Solution Partner and submit the form. Once your request is submitted, the Cisco Spaces Product Team will review the information provided. They may reach out to gather additional details, assess your solution, and explore potential collaboration opportunities.

##### Evaluation Criteria

* Assessment of the partner solution's capabilities, features, and overall value proposition.

* Assessment of target use cases and their relevance to Cisco Spaces customers across various industries and verticals.

* Review of how effectively the solution integrates with Cisco Spaces infrastructure, including APIs, SDKs, and data services.

* Existing customer base leveraging Cisco Spaces within the partner solution.

* Review of a working demo to assess functionality, usability, and overall user experience.

* Solution's ability to scale with increasing customer demands and platform growth.

##### Approval and Access

Upon approval, the Cisco Spaces team will provision accounts to access

1. [Cisco Spaces](https://dnaspaces.io/)

2. [Cisco Spaces Partner Dashboard](https://partners.dnaspaces.io/partner)

Activate your Cisco Spaces account using the invitation email sent. This activation is required to access the partner dashboard. Once the Cisco Spaces account is activated, users can sign in to the Partner Dashboard.

#### Cisco Spaces Integration Methods/Features

Cisco Spaces provides APIs and SDKs to accelerate innovation and deliver meaningful business outcomes.

##### **Cisco Spaces Firehose Streaming API**

The Cisco Spaces Partner Firehose API provides a continuous, real-time stream of location and presence data, enabling developers to build dynamic and responsive applications. It delivers live updates on device movements, proximity events, and zone-based entry/exit triggers, along with current location data and associated device profiles such as MAC addresses and device types. The API supports a broad range of event types, making it ideal for applications that require contextual awareness and location intelligence. Built for scale, it ensures high-throughput and reliable data delivery, even in large enterprise environments. All events are transmitted in JSON format, making them easy to parse and integrate across various programming languages and platforms.

[Learn more about Cisco Spaces Firehose Streaming API documentation](https://developer.cisco.com/docs/cisco-spaces-firehose/api/)

##### **Cisco Spaces Onboarding SDK**

The Cisco Spaces SDK enables iOS and Android apps to securely connect users to Wi-Fi using OpenRoaming, without user interaction. It leverages identity federation for seamless access, user analytics, and device-level engagement through native notification frameworks.​ The Cisco Spaces SDK further allows partners to add more information about the users, and engage with them, directly on their device, through the iOS and Android notification framework.

[Learn more about Cisco Spaces Onboarding SDK](https://developer.cisco.com/docs/cisco-spaces-sdk/introduction/)

##### **Cisco Spaces AI Maps SDK**

The Cisco Spaces AI Maps SDK is a JavaScript SDK that allows developers to embed and interact with 3D Digital Map Pro within a web page. The map can be initialized with custom parameters such as latitude, longitude, bearing, pitch, and zoom to create a tailored view. The SDK provides methods and events for rich interactivity, including the ability to update 3D room overlays with preset color states---green for Available, amber for Booked, red for Occupied, and blue for On Hold---making it ideal for kiosk and digital signage use cases. Additionally, developers can place custom images at specific coordinates (latitude and longitude), enabling scenarios such as real-time asset tracking.

Contact the Cisco Spaces team to get more details on how to integrate using the AI Maps SDK (beta)

##### **Cisco Spaces Wayfinding SDK**

The Cisco Spaces Wayfinding SDK offers native libraries for iOS and Android platforms, enabling real-time blue-dot indoor navigation within mobile applications. By integrating this SDK, developers can provide end users with an intuitive wayfinding experience---guiding them from their current location to a specified destination on the map using precise indoor positioning.

To enable the blue-dot functionality, a proper wayfinding beacon setup and management within Cisco Spaces is required. It's important to note that this SDK is focused on full app integration and does not include support for the App Clip experience available in other Cisco Spaces offerings.

For integration details and support, please contact the Cisco Spaces team.

##### Cisco Sensor Connect Infrastructure API

Cisco Sensor Connect is an IoT integration framework designed to facilitate seamless onboarding, management, and data ingestion from Bluetooth Low Energy (BLE) and other sensor devices into the Cisco Spaces platform. It leverages the IoT Orchestrator, deployed on Cisco Catalyst 9800 Wireless Controllers running Cisco IOS-XE 17.15.1 or later, to provide robust device connectivity and real-time telemetry streaming. This solution is ideal for organizations requiring highly secure, isolated networks while still benefiting from Cisco Spaces intelligent location services and IoT analytics. It enables secure, local ingestion and processing of data from a variety of sensors such as environmental monitors, occupancy detectors, and asset trackers.

[Learn more about Sensor Connect for IoT Services](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-orchestrator/config-guide/b-spaces-connect-iot-config-guide.html)

*** ** * ** ***

### **Cisco Spaces Device Partners**

Cisco Spaces collaborates with IoT device vendors and manufacturers through its Device Partner program, allowing them to list and promote their hardware solutions on the Cisco Spaces Device Marketplace. All listed devices are validated for compatibility, security, and seamless integration with the Cisco Spaces platform, ensuring reliable deployment within customer environments.

Once the device is listed, Customers can request for quote directly with from the Vendor by submitting a form on the IoT marketplace. The vendor can then establish direct communication with the customers to fulfill the orders. Customers can onboard devices seamlessly into Spaces by proving the order id.

#### **How to become a Partner**

This section lists the steps to apply to be a device partner and how to get your device listed on the IoT devices Marketplace.

* Submit Your Application

  Visit [Cisco Spaces Device Partners](https://spaces.cisco.com/device-partners/) and complete the Device Vendor Partner application form. Before technical collaboration begins, the partner team must sign a Non-Disclosure Agreement (NDA) with Cisco to protect confidential information shared during the integration process.

* Collaborate with the Cisco Spaces Team

  Once submitted, the Cisco Spaces team will initiate contact to review your application. During this phase, you will collaborate with Cisco to share your device's technical specifications, intended use cases, and deployment scenarios.

* Cisco Spaces Compatibility

  Devices must either integrate with the Cisco Spaces SDK or undergo validation to ensure compatibility. The Cisco Spaces team will assist with assessing integration requirements and supporting any necessary development or configuration efforts.

* Testing and Data Validation

  The Cisco Spaces team will work with your technical team to test the device's data integration and confirm that data flow reliably into the Cisco Spaces platform.

* Marketplace Listing

  Upon successful validation, the device will be listed on the Cisco Spaces IoT Device Marketplace. This listing will include device specifications, supported use cases, and the option for customers to submit a request for quote (RFQ) directly to your organization.

##### Evaluation Criteria

* The device should support clearly defined use cases relevant to Cisco Spaces customers (e.g., occupancy analytics, asset tracking, environment monitoring).

* The device must be capable of integrating with Cisco Spaces infrastructure, either through direct API/SDK integration or approved interoperability workflows.

* Vendors are responsible for engaging directly with customers who submit Requests for Quote (RFQs) through the marketplace. This includes timely communication, order fulfillment, and post-sales support where applicable.

*** ** * ** ***

## SUPPORT \& ESCALATION PATHS

This section outlines how partners and customers can seek help, report issues, and engage with the appropriate teams depending on the nature of the request or problem. Proper routing of support queries ensures faster resolution and better overall experience for both customers and partners.

### Support for Partners

Cisco Spaces offers a range of documentation and guides to help partners effectively integrate, configure, and deploy their solutions. These resources are designed to support partners across different stages of the integration lifecycle - from onboarding to advanced use case implementation.

Partners integrated into Cisco Spaces can use the following support:

* [Partner Dashboard: Application Creation \& Management](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/partner-dashboard/basic/b-dnas-pd.html)

  * This document provides detailed instructions for partners on how to create, configure, and manage applications within the **Cisco Spaces Partner Dashboard**. It covers the full application setup process---including registration, API access (such as the Firehose Streaming API), authentication, and testing---enabling partners to build, validate, and prepare their apps for publication in the Cisco Spaces Partner App Center.

* [Runbooks](https://runbooks.ciscospaces.io/docs/cisco-spaces-runbooks-cisco-validated)

  * Cisco Spaces offers a collection of validated runbooks that provide step-by-step guidance for deploying a wide range of outcomes using Cisco Spaces. These runbooks are designed for both customers and partners and cover foundational setup as well as advanced, use case-specific configurations. Each runbook includes technical prerequisites, configuration steps, network setup, and recommendations to ensure successful implementation. These resources serve as essential references for accelerating deployments and realizing business outcomes across various industries.

* [Configuration Guides](https://www.cisco.com/c/en/us/support/wireless/dna-spaces/series.html)

  * Configuration guides provide detailed instructions for setting up the Cisco Spaces platform and its applications. The guides cover both core platform configurations and solution-specific setups such as asset tracking, IoT services, environmental monitoring, and more. Each guide includes prerequisites, system integration steps, and best practices to ensure seamless and secure deployment across enterprise environments.

* [Setup Guides](https://spaces.cisco.com/setupguide/welcome-setupguide/)

  * Setup guides are quick-start, intuitive and user-friendly resources that provide step-by-step instructions, visual walkthroughs, and video tutorials that walk users through setting up Cisco Spaces.

* Cisco Spaces Partner Support

  * For integration questions, app validation status, marketplace listing issues, and SDK/API guidance, partners can contact the Cisco Spaces partner team at [ciscospacespartnerteam@cisco.com](mailto:ciscospacespartnerteam@cisco.com).

* TAC Cases (via Customer)

  * Partners can not raise TAC cases directly. However, if a customer is impacted and a TAC case is opened, Cisco TAC will work with the partner (if necessary) to resolve integration-level issues.

### Support for Customers

Customers leveraging Cisco Spaces and associated partner applications can seek help through the following channels:

* Cisco TAC (Technical Assistance Center):

  Customers should open a TAC case for issues related to:

  * Cisco Spaces platform functionality (data, APIs, dashboard issues)

  * Network integration issues (Wi-Fi/AP-related)

  * Device onboarding problems

  * Any outages or major disruptions

  To open a TAC case, go to <https://www.cisco.com/go/tac>
* Partner Application Support:

  If a customer encounters issues specific to a partner application (e.g., login issues, app behavior anomalies, data discrepancies), they should reach out directly to the partner's support contact listed in the App Center. Cisco Spaces does not provide L1/L2 support for third-party app logic or configurations.

* Escalation to Cisco Spaces Team:

  If the issue involves platform compatibility with a partner application or a deployment blocker that cannot be resolved via TAC or partner support, customers may escalate to the Cisco Spaces team via their Cisco account team.

#### Support Grid

|                **Issue Type**                |          **Primary Contact**           |
|----------------------------------------------|----------------------------------------|
| Platform bugs or outages                     | Cisco TAC                              |
| Partner app-specific functionality issue     | Partner's support contact (App Center) |
| App validation status or listing support     | Cisco Spaces Partner Team              |
| API/SDK technical questions                  | DevNet                                 |
| IoT device onboarding or marketplace listing | Cisco Spaces Partner Team              |

---
language: "en"
---
# Cisco Spaces Runbooks (Cisco Validated)

Note that the ![image-20250512-171355.png](https://runbooks.ciscospaces.io/__attachments/a_127e2857adac5250277710752c2f571b5a0fc5e1d92cc444225ba97f7feaf673/image-20250512-171355.png?cb=a6a4da2969a5cba3bc0cd35c4251651c) icon will open up the navigation pane.

The contents within are deployment guides to successfully realize outcomes with Cisco Spaces.

The root runbook is the Spaces OS, which is foundational for all outcomes. This is the primary prerequisite for everything else.

All other runbooks are designed for specific outcomes. These deployment guides are layered on top of the Spaces OS.  
![image-20260624-093510.png](https://runbooks.ciscospaces.io/__attachments/a_cf500ebf3cae00b08000f8ffc9dd09a24dd33a1f668b45a72958ee0daf3f0cc4/image-20260624-093510.png?cb=8f56abc684a47e7d1d15eaf742e01a24)

---
language: "en"
---
# Cisco Spaces Smart Rooms Runbook (Cisco Validated)

## OVERVIEW

**What Are Cisco Smart Rooms?**

Cisco Smart Rooms seamlessly integrate your existing Cisco Webex devices with your Building Management System (BMS) to provide demand control ventilation, optimize the experience, wellbeing, and productivity of your existing spaces when in use, and reduce energy use when spaces are not in use.

Some Cisco devices, such as the Webex Room Kit and some partner devices within the Cisco Spaces Marketplace, can detect occupancy within a given space. That occupancy data is first sent to the Cisco Spaces Cloud. It's then sent to the Cisco Spaces Building Gateway which connects to your BMS network as a virtual BACnet device. The Cisco Spaces Building Gateway is the only new hardware needed if you already have the Webex Room Kit installed. Your BMS can then adjust temperature and air flow settings based on the occupancy of the space.  
![image-20250221-005105.png](https://runbooks.ciscospaces.io/__attachments/a_bf5c19419d7fa7a6d537417588317dc3aecf51e943eec26b573f6740e1f0f00e/image-20250221-005105.png?cb=454f788e1dbc4d4bb7bf7d6a8502f239)

### SUPPORT AND ONBOARDING

Please follow the link below to find out about the different ways to get support for Cisco Spaces.

[++Support Info Link++](https://activate.dnaspaces.io/hubfs/Assets/CiscoSpaces-SupportUpdate.pdf?__hstc=105720540.52aaa4a978f36be89855b002cb35bfc4.1729705805310.1729705805310.1729705805310.1&__hssc=105720540.1.1729705805310&__hsfp=3667649010)

*** ** * ** ***

## PREREQUISITES

This runbook should **only be used as a follow on from the** [**Spaces OS Runbook**](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated). Please refer to that document before progressing here.

In addition to the Spaces OS installation, below are the more specific requirements for Smart Rooms.

### Prerequisites Checklist

![image-20250225-212247.png](https://runbooks.ciscospaces.io/__attachments/a_b7d379c949f83456d4e57f7be7d4d253e2695f278f0ed7b053a42a2bb2a2954e/image-20250225-212247.png?cb=116af360328c81dfcf458a34c5f7c9f0)

### **BMS Pre-deployment Checklist**

*Prior to site survey, a pre-deployment requirements sheet should be sent to the customer, this lists all the assets and information we will require for a successful deployment. As follows: ·*

* **Your building has a Niagra-based BMS or any using the BACnet communication protocol**

  For example. Johnson Controls, ALC, Optergy, Distech Controls, Honeywell, etc.

* **Your building has room-level HVAC controls**

### **Webex Metrics**

This section will illustrate how to configure the metrics in Control Hub.

1. Log into Webex Control Hub, and navigate to the **Devices**tab.

2. Select devices to apply the config to, then select **All configurations**.

3.

![Screenshot 2024-11-07 at 9.27.04 AM.png](https://runbooks.ciscospaces.io/__attachments/a_bd24a74f9240341063a9b1e6a0346eb19012ad7476355d4b3a56ccd288efd555/Screenshot%202024-11-07%20at%209.27.04%E2%80%AFAM.png?cb=a2eda8619a6c3af69349e94ff31a9564)
<https://help.webex.com/en-us/article/nc6od6r/Historical-Data-for-Webex-Rooms-Workspaces>

![Screenshot 2024-11-07 at 9.25.17 AM.png](https://runbooks.ciscospaces.io/__attachments/a_dcba622b4da968e6a32aad1bd612a17a1c22eadc70697434adc63756b2e44e4a/Screenshot%202024-11-07%20at%209.25.17%E2%80%AFAM.png?cb=e2a4f17117868fd4a23888dce851bb4d)
*People Count Out Of Call* - <https://help.webex.com/en-us/article/nc6od6r/Historical-Data-for-Webex-Rooms-Workspaces>

![Screenshot 2024-11-07 at 9.43.32 AM.png](https://runbooks.ciscospaces.io/__attachments/a_1cab62cf8056cf50ed38a728fb3275746fbdd42a4a869cd68087dfb75d3319a0/Screenshot%202024-11-07%20at%209.43.32%E2%80%AFAM.png?cb=b2308d7d0470e0b9c0291f7a83a77265)
*People Presence Detector​ -* <https://help.webex.com/en-us/article/nc6od6r/Historical-Data-for-Webex-Rooms-Workspaces>

![Screenshot 2024-11-07 at 9.47.46 AM.png](https://runbooks.ciscospaces.io/__attachments/a_dbada1c422cee177dae4a223d532ae5f66520b70858f45c9c4b483b6dc2793b3/Screenshot%202024-11-07%20at%209.47.46%E2%80%AFAM.png?cb=01dba372f8adfc5ee1ea911bd875ec71)
*Ambient Noise Estimation* - <https://help.webex.com/en-us/article/nc6od6r/Historical-Data-for-Webex-Rooms-Workspaces>

### Calendar Integrations

O365 and Google Calendar options are in Webex Control Hub under:​ Workspaces (page) \> click on a Workspace \> Scheduling (tab) \> Calendar (option)​

[Deployment guide for Hybrid Calendar](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cloudCollaboration/spark/hybridservices/calendarservice/cmgt_b_deploy-spark-hybrid-calendar-service/cmgt_b_deploy-spark-hybrid-calendar-service_preface_01.pdf)  
![image-20250204-032331.png](https://runbooks.ciscospaces.io/__attachments/a_8a91e01c787fee4f9d999153b58f3dde1f85bc5ad97a0f21414d8a08405ab54b/image-20250204-032331.png?cb=f8999681770709ffb5f2b5b87e78dd0b)

**As of March 2024, the Spaces team is enhancing the Webex Hybrid Calendar integration by migrating from a polling method (every 10 minutes using REST APIs) to webhooks for real-time calendar event updates.**

![image-20250204-032547.png](https://runbooks.ciscospaces.io/__attachments/a_31910e33d74d42a9f43344f3dfbaf7363783159e0e4011502ee58129c0c2accf/image-20250204-032547.png?cb=8b4ffdc589fa7c71fe1f5b248636f179)

![image-20250204-032634.png](https://runbooks.ciscospaces.io/__attachments/a_a85900787bfce2c0939e08a7552a84809b843d798bc278270ab505486d76f5e0/image-20250204-032634.png?cb=0fd3946cd5d502928bc530078a5e28eb)

![image-20250204-032728.png](https://runbooks.ciscospaces.io/__attachments/a_050b21f49ba386179bd2753f7f63704091efdd9bf14cb31ea9d62cea7b8580d3/image-20250204-032728.png?cb=063a1d1588e1e830e7c6b23fb0cf670c)  
![image-20250204-032757.png](https://runbooks.ciscospaces.io/__attachments/a_06af1947d48732c93ae2d4ea75dd08d0a31e01b269c5af4eed7a3329881d4644/image-20250204-032757.png?cb=3b08dc8d06c1e1788c506c2a6c4e1929)

*** ** * ** ***

## IMPLEMENTATION

To complete these steps, an admin will require read/write permissions within Spaces for Space Experience, as well as read/write access to Webex Control Hub.

***The Smart Rooms deployment team will work with building engineer of the organization to get the answers to the questions below for the gateway onboarding.***  

|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Q: How will we communicate with the BMS? There are two options: 1. We can read points from your BMS and write points directly back to your BMS (a read/write relationship) -or- 2. We can read points from your BMS and write points to a pseudo BACnet device which your BMS reads and then actions on, according to your logic (a read/read relationship) |
| Q: If option 1) (read/write) what priority should we write at?                                                                                                                                                                                                                                                                                              |
| Q: In order to prevent conflicts, what IP address and BACnet ID can be assigned to the Spaces Smart Room Gateway                                                                                                                                                                                                                                            |
| Q: Is there a VLAN?                                                                                                                                                                                                                                                                                                                                         |
| Q: Do you use a BBMD?                                                                                                                                                                                                                                                                                                                                       |
| Q: What BMS do you use?                                                                                                                                                                                                                                                                                                                                     |
| Q: How old is your BMS?                                                                                                                                                                                                                                                                                                                                     |
| Q: Can you expose all BACnet equipment or do you need to limit exposure with a JACE or similar Niagra 4 device? Limiting devices may be required if the building has multiple tenants, for example.                                                                                                                                                         |
| Q: Do you have a JACE or other Niagra 4 device in place currently?                                                                                                                                                                                                                                                                                          |
| Q: What network is your BMS on? (Landlord's/base building, Cisco, or something else?)                                                                                                                                                                                                                                                                       |
| Q: Who supports/ manages the BMS? Please provide a Point of Contact name, and contact information                                                                                                                                                                                                                                                           |
| Q: What mechanisms are in place for room by room HVAC? (VAVs, fan coils, chilled beam, etc...)                                                                                                                                                                                                                                                              |
| Q: Can your BACnet instance support a polling frequency of once per minute/device? If not, what polling frequency can your instance support?                                                                                                                                                                                                                |
| Q: Do you have any issues with the existing BMS, for example: latency, controllers offline or frequently unreachable, etc...?                                                                                                                                                                                                                               |

### Site Survey and Preparation​

#### **Site Survey**

As part of the EFT and initial onboarding process, it is best to perform a site survey to validate the space can support Smart Rooms technology. Preferably this would be done remotely with the on-site building engineer. During the site survey all the rooms should be visited to confirm they have dedicated ventilation, they are closed spaces (no half walls), and that they have dedicated ducts (no underfloor shared plenum). Additionally during the site survey the cabinet for the Spaces Building Gateway should be identified and validate if the necessary connections and power are available.

##### Walkthrough of the rooms

* Photos

* Validate conditions against plans

* Identify location of sensors and equipment

* Identify issues that would impact effectiveness of product (e.g room has no ceiling)

##### Check the location and readiness of server cabinet

* WAN and LAN connection

* Power

##### Meet with building engineer

* Review Sequence of Operations (SOO) and integration plan

* Validate deployment process and plan

* Request the BMS controls as-built submittals

*** ** * ** ***

### **Add Building to Smart Rooms**

#### Roles and Responsibilities

* Cisco Spaces Admin to complete this step

* WPR Engineering lead or Workplace IT team

* Cisco Space Admin to invite Building Engineer

#### Configuration steps

1. In the Cisco Spaces dashboard, navigate to Space Experience

![image-20250221-220114.png](https://runbooks.ciscospaces.io/__attachments/a_cd5a3ac544f93bc184920802d737f273841def6e9bc22c647eeced09d40a5d27/image-20250221-220114.png?cb=c34fccfdb6bcb60acf364543623a42af)

2. To add a building - Select Smart Rooms\> +Add

![image-20250221-220152.png](https://runbooks.ciscospaces.io/__attachments/a_67a44d9fc56f6616859b1ff68536258892a42c04adb58d19ed046a0852c62007/image-20250221-220152.png?cb=42d05ad9810c9e1a698eaf21ef423971)

3. Select the building from the drop down list

![image-20250221-220217.png](https://runbooks.ciscospaces.io/__attachments/a_8d890e0df69fd8b7fa18de6f13f9d2c8ba3d20b14df5b4f99ffa320a9dcb6704/image-20250221-220217.png?cb=67b35c9be5e061013fecb2890d4344cd)

4. Select ship gateway

5. Invite Building Engineer -- Questions around this access and control of who can invite

![image-20250221-221022.png](https://runbooks.ciscospaces.io/__attachments/a_136d40610d2da76f0d90d3d9aecbb8d0dc16ba3c50ab396258bb17dc34a5d565/image-20250221-221022.png?cb=f7f875d80432b48eaf5415eb0c5f6409)

*** ** * ** ***

### Building Gateway Registration

#### Claim and Register Building Gateway

1. Building Engineer accepts invite and logs into Building Gateway Manager -- Building Gateway Manager has no other access to Cisco Spaces applications

![image-20250221-221222.png](https://runbooks.ciscospaces.io/__attachments/a_d3cc8c1f96643c3e818a7ffb832a3755b916a45c4b43ea293a3cb1c1543291b6/image-20250221-221222.png?cb=fa90e3896da7d91fa743fd3a3cbdf798)

2. Select +Add Gateway

![image-20250221-221318.png](https://runbooks.ciscospaces.io/__attachments/a_f909c8b6567d4851ca1950ba2e74e26d417accde006fea3188e9b4f003d77e1b/image-20250221-221318.png?cb=86c326c7eeb19bb3bb6ae6ecf664b455)

3. Choose the building you want to add gateway to from list

![image-20250221-221340.png](https://runbooks.ciscospaces.io/__attachments/a_6227def835bb40f7e4ca909aeff9ec3900c90fcc7d6657a85145ea0abb10ce87/image-20250221-221340.png?cb=f7274856377d3d38459514074b8e216b)

4. Enter Serial number and select Claim

5. Confirm the new Building name and gateway serial number populated in the list of enabled sites

![image-20250221-221410.png](https://runbooks.ciscospaces.io/__attachments/a_3314e7a15c47c90bd1a7697b620733d456deed63403d2bb591e0b7568aaf2d59/image-20250221-221410.png?cb=136566c4821fb8b6ab2b9dc82c59f962)

*** ** * ** ***

### Building Gateway Installation​

#### **Overview**

The Cisco Smart Rooms gateway connects to the building or OT network to communicate directly with the building management system (BMS) and endpoint controllers (e.g VAVs and thermostats). The gateway receives occupancy and IAQ sensor telemetry data from the cloud, processes that data at the edge along with data coming from the BMS, and sets BACNet setpoints or makes available read-only BACNet points to the BMS network for control (see BACNet Integration below for more detail)

The Cisco Spaces Building Gateway is a cloud-based platform that securely connects on-premises building management systems (BMS) to the Cisco Spaces cloud to enable Cisco Spaces Smart Rooms solution.

For deployments there are two recommended reference architectures:

**Single Tenant:** If you are in a single-tenanted building or have your own dedicated BMS and building network, you can connect the gateway directly to the building network for integration.

![image-20250225-212552.png](https://runbooks.ciscospaces.io/__attachments/a_2d9f02d8880b81ad3e2349882fc2ef159d2b5c8015442ac66158fc6d260dd2ae/image-20250225-212552.png?cb=36b2a0d79b57a8984e1e78579ca52dd7)

**Multi Tenant:**If you are in a multi-tenanted building and your BMS and building network are shared by multiple tenants, your landlord or the operator of the building network will likely want to put in a JACE controller as middleware. This JACE controller will limit access to the network, allowing read and write to only the data points associated with your space and restrict access to data points that would impact the operations of other tenants' spaces.  
![image-20250225-212607.png](https://runbooks.ciscospaces.io/__attachments/a_d1608a2a07e8bb2d06474b86d8a9fc259d74201acb91fd742db1804be29a9e40/image-20250225-212607.png?cb=ebb13974597dea41639cb0d09bc29a06)

If the deployment is in a multi-tenant building or the building owner does not want to allow access to all BACnet devices in the site, a JACE or similar Niagra 4 controller needs to be installed by the customer. This must be done with their system integrator. Share the list of BACNet points above with the system integrator to ensure they are exposed. The JACE device is a pre-requisite for future steps.

#### **Network Configuration \& Security**

The Smart Rooms gateway requires 1) a connection to the internet (WAN) with TCP port 443 and port 7422 outbound available and 2) an IP connection to the building network (LAN) with the appropriate BACNet port (typically 47808 by may vary depending on customer) open for both inbound and outbound.

Connections on WAN and LAN can be via static IP or DHCP. Authentication to the WAN and to the LAN can be configured via 802.1x authentication for additional security.

**Requirements for the Gateway Installation :**

1. Power

   1. The Cisco Spaces Building Gateway needs a regular 110 or 220-volt outlet to power it.

2. Enterprise Authentication configuration

   1. MAC authentication Bypass (MAB) will be required for Building gateway WAN, LAN and service MACs in order for the Building gateway to connect to the cloud and BMS server on the LAN network. The following MAC addresses will be provided by the Spaces administrator for MAB authentication:

      1. WAN interface MAC:

      2. LAN interface MAC:

      3. BMS Edge Service MAC:

      4. Troubleshooting services MAC:

      5. 802.1x coming soon.

3. Wired connectivity

   1. The WAN interface needs to be connected to the switch port that has outbound 443 internet access and the above domains listed as allowed domains for connectivity.

   2. LAN interface (port B) needs to be connected to the same switch where BMS server is connected and it needs to be on the same VLAN as BMS server to ensure BACnet UDP communication is established between the Building gateway and BMS server.

4. WAN connectivity

   1. TCP port 443 outbound and port 7422 outbound must be open and available on the WAN network. The Spaces Building gateway needs to establish an outbound TCP 443 connection to the following URLs and IPs for management plane connectivity

      1. [Nodev3.iotium.io](http://nodev3.iotium.io/): This is our cloud end-point for Secure Edge connection.

      2. [Checkip.amazonaws.com](http://checkip.amazonaws.com/): For DNS validation of nodev3.iotium.io and geolocation of iNode public IP.

      3. \*.google.com: For NTP.

      4. \*http://docker.com and \*.docker.io: Required for Building Gateway Edge Applications, including internal services, and troubleshooting tools.

      5. 44.202.124.117: our virtual building gateway headend in AWS cloud where the secure tunnel is established for all OAM communication. (Post EFT phase there will be virtual gateways in different regions, each of which will have a unique IP address, for now all regions will use the North American IP)

|    Region     |   IP address   |
|---------------|----------------|
| North America | 44.202.124.117 |

For static WAN configuration, please have the following information ready:

1. DHCP or Static

2. If Static - WAN IP Address

3. Default Gateway

4. Network CIDR (Subnet Mask)

5. Optional Configurations

6. Proxy

7. FQDN

8. Port

9. DNS Servers (optional, if not provided will use Google default name servers)

10. Server 1:

11. Server 2:

12. Server 3:

13. NTP Servers (optional, if not provided will use Google default time servers)

14. Server 1:

15. Server 2:

16. Server 3:

17. Server 4:

18. LAN connectivity

The LAN interface needs to be connected on the same switch where the BMS server is connected and authenticated via MAB. The Cisco Space Building Gateway needs a reserved IP address in DHCP.

For multi-tenant installation: If there is a JACE box that has tenant BACnet points mapped as a tenant BMS gateway then connect the network port of the JACE to the LAN interface of the building gateway (LAN B) and configure the static IP using the building gateway cloud console.

For LAN configuration, please have the following information ready:

1. DHCP or Static

2. Network CIDR (IP and Mask Length)

3. Spaces Building Gateway IP address

4. Optional

5. VLAN enabled

6. VLAN ID

7. BMS Edge service configuration

In order to configure the BMS Edge Service you will need the following:

1. IP address and BACnet instance number from the BMS contactor

2. The BACnet UDP port number (if different than default port 47808)

3. The device ID for the building gateway as configured in the BMS for points binding

4. Provide the BMS Edge service IP address to the BMS contractor to on-board the building gateway as a BACet Device

5. Configure for BBMD if needed

6. Spaces cloud connector for edge service configuration

7. TCP port 443 Outbound must be open and available on the WAN network. The Spaces cloud connector needs to establish an outbound TCP connection with the spaces microsite.

8. TCP port 7422 outbound must be open and available on the WAN network. The Spaces cloud connector needs to establish an outbound TCP connection with the spaces cloud.

*** ** * ** ***

### BACnet Onboarding​

![image-20250225-221850.png](https://runbooks.ciscospaces.io/__attachments/a_dc299180bbd6ff22ceb5c0ff7ffe63e05a3a49af993eea2c1be5702b856942af/image-20250225-221850.png?cb=b7c71068bc074264b37c16ad247ae0fd)

#### **BACnet Integration/Onboarding**

Cisco Smart Rooms control heating and cooling by adjusting setpoints on HVAC devices via BACnet. There are two approaches to BACnet integration: either a read-write or read-read.

Read-write:

The Cisco Smart Rooms system can read temperature and flow BACNet points from the BMS, and combine that data with information from Cisco Spaces regarding occupancy and room schedules, and make direct changes (write) to the HVAC systems by writing heating and cooling setpoints directly to the BMS. The priority is configurable.

Read-read:

The Cisco Smart Rooms system can make occupancy and scheduling data available by writing to a pseudo BACnet device which your BMS reads and actions on based on your own rules and logic. The customer's system integrator will need to perform additional programing in this case.

For integration the customer needs to make BACnet data points available to the Cisco Spaces building gateway.

Typical Available BACnet Points (for VAVs)  

|-----------------------------|--------------------|------------------|-------------------|--------------------|
| **Point**                   | **Equipment Type** | **Abbreviation** | **Typical Value** | **Writable Point** |
| Schedule                    | VAV                | SCHED            | 0 or 1            | X                  |
| Space Temp                  | VAV                | ST               | Varies            |                    |
| Occupied Cooling Setpoint   | VAV                | OCSP             | 73°F              | X                  |
| Unoccupied Cooling Setpoint | VAV                | UNOCSP           | 85°F              | X                  |
| Occupied Heating Setpoint   | VAV                | OHSP             | 71°F              | X                  |
| Unoccupied Heating Setpoint | VAV                | UNOHSP           | 55°F              | X                  |
| Max Air Flow Setpoint       | VAV                | MAXFSP           | Varies            | X                  |
| Min Air Flow Setpoint       | VAV                | MINFSP           | Varies            | X                  |
| Space CO2                   | VAV                | CO2              | Varies            |                    |
| Air Flow                    | VAV                | FLOW             | Varies            |                    |
| Damper Position             | VAV                | DMPR             | Varies            |                    |
| Demand Shed Control         | VAV                | SHED             | Varies            |                    |
| VFD Fan Speed               | AHU                | VFDSPD           | Varies            |                    |

#### **BACnet Device Discovery**

* BACNet Device Discovery is the process of finding all of the devices on a BACnet network, and then the objects which are available on each device. The basic BACnet protocol for discovery is the Who-Is service; this uses broadcast traffic to request devices within a range of IDs to respond with an I-Am message.

  ​

* While BACnet HPL allows sending Who-is messages directly, running a scan is faster and easier. A BACnet scan looks for all devices and creates a list of the results and generally takes just a few minutes.

*** ** * ** ***

### VAV mapping​

#### **Configuration steps**

##### **Map Equipment**

1. Find the building you want to map equipment to click on the ellipses button and select "Map Equipment"

![image-20250221-223345.png](https://runbooks.ciscospaces.io/__attachments/a_fe13351e81a8bac53200daa18ee4f001d1043c15a24d5afd2335bd8b3451e028/image-20250221-223345.png?cb=6583bb9ba7e467ff9da563be9584737c)

2. On the Rooms and Zones list you will see what rooms have or do not have equipment mapped to them.

![image-20250221-223403.png](https://runbooks.ciscospaces.io/__attachments/a_0845fc0c3ad166d6b38f623be4ae813cc22fa8db05a7fb0843e7a648adcb0b4e/image-20250221-223403.png?cb=4d2ca242a214898d52e8666d23f799dd)

3. Select Download Template to start mapping

![image-20250221-223425.png](https://runbooks.ciscospaces.io/__attachments/a_7e1f6501ab71a9673674d49d3b065cb5b52c142f9061fc3df01461016b2192ee/image-20250221-223425.png?cb=906aecd2dbf2262a6df33a248ea004da)

4. Open the Excel file template that was downloaded

![image-20250221-223456.png](https://runbooks.ciscospaces.io/__attachments/a_2b7e80ea2c8d6988a3b2838ffe447015c27c2e42beb6c7c27e0853d82cb2275b/image-20250221-223456.png?cb=e0e2bc55049d80d3f22923343800ca16)

5. Match the correct equipment (VAV's, FCU's) to the corresponding room

6. The Room list populated from the Webex Workspaces synced from Control Hub. The equipment list is populated by the gateway via BACnet discovery on exposed/programmed points completed by the BMS controls vendor

7. Save the template and upload in the same location as downloaded

8. Confirm you see the corresponding devices associated with the correct Rooms and Zones that they were mapped to

![image-20250221-223516.png](https://runbooks.ciscospaces.io/__attachments/a_f650336da4e2c52a7a92ab52e973aba0374d95888f08ba38c1679ff57cbf4d58/image-20250221-223516.png?cb=5389311a0477fbb21ccfd1daa12d7f76)

*** ** * ** ***

### Verify and Benchmarking

* **Testing \& Validation** - depends on the number of VAVs mapped, from minutes to days. Testing the initial connection to see if the BMS is reading each change takes only a few seconds per VAV, always performed sequentially, testing if the VAV is mapped to the correct room takes up to several minutes per test to ensure the atmosphere in the room changes as expected, always performed sequentially.)`​`

  ​

* **Benchmarking** - at least 1 week; 2-3 weeks recommended. . (This is the process of capturing data BEFORE we begin optimizing so we can provide an accurate optimization report.)

*** ** * ** ***

### ​Activation on Webex endpoint

#### **Enable Smart Rooms**

##### Roles and Responsibilities

* WPR Engineering Lead to enable

* WPR IT involvement

* Onsite FM team provided access to disable if issue arises

##### Activate Smart Rooms and Widget

1. In Space Experience navigate to Smart Rooms\> Buildings

![image-20250221-223553.png](https://runbooks.ciscospaces.io/__attachments/a_fcdf35dc323a8424770175cd45de5dbf25523b6f4498264b27ae796742e6e875/image-20250221-223553.png?cb=43aa3ea6620b0f38fcc8bcb065d120b3)

2. Select the Building you want to enable Smart Rooms in and choose Configure Smart Rooms

![image-20250221-223607.png](https://runbooks.ciscospaces.io/__attachments/a_b6267557cd24b5ee1855c0635cf27df99c2397dc76a6dce1681ec28d16ec1d6b/image-20250221-223607.png?cb=9362c4575935f5250a6f5bf7f0a3530b)

3. Toggle on the rooms to be enabled

![image-20250221-223623.png](https://runbooks.ciscospaces.io/__attachments/a_05f3ab509c5ae863193f4e6b7871d0bf2a1af9559fc1b1f57c517407b10e248e/image-20250221-223623.png?cb=c107672547ad9017fd15f05e8239122c)

1. Activate -- Enables the gateway to perform the setback logic, making the workspace a Smart Room

2. Widget -- Enables the Webex web widget on the screen of the device, giving occupants visibility into what state the Smart Room is in

4. Select a room to see the widget and status of the Smart Room

![image-20250221-223640.png](https://runbooks.ciscospaces.io/__attachments/a_22d6de54cfdf7e0c69bdc0b8a2ca7a29117743c30697906df1a378612df69f92/image-20250221-223640.png?cb=edc716a609fb6810ab8b38918f755c1e)

*** ** * ** ***

## Monitoring

### **Cisco Smart Room Gateway Comms Monitoring**

The constant monitoring of connection between the Smart Rooms gateway and BMS is critical when commands are received from the Cisco gateway to the BMS. If connection is lost from the Spaces Gateway, the BMS must revert to default programming. To accomplish this, a heartbeat connection point will be discovered from the Spaces gateway and trended on the BMS to monitor. This is accomplished by the following:

#### **BMS Monitoring**

* Cisco gateway will deliver a binary point to be discovered by the BMS. This point will oscillate and be used to disable Cisco gateway commands if the connection is lost (the point stops oscillating \& goes stale). In this event, the BMS will revert to base unit sequencing until connection is reestablished.

* Cisco cloud will change the value of this point every 60 seconds, It will toggle from ON to OFF. The BMS will need to be programmed to monitor this point and if it does not see a change of value over a 5 minute (adjustable) period, the Cisco gateway connection status will be off and remain off until communications are reestablished.

* When the Cisco gateway connection status point goes inactive, a BMS alarm will be activated notifying the building operators/Cisco Spaces/BMS operators.

* Below is an example of how the logic may look:

![AD_4nXdQSsfZNSK9Php4Q20PETIIjyw90wjPTm_rTUfX0VUxdnKiNDii-T2ePf5GE6CB4KWDeeWg5VtzdOdFM33q1m7vJV7pAXMY3S0H6adnW29_d1vYM29spjHwzukSVv8zBnNPcQsBOg?key=KpvWH-P_hmEWO_u2cH1rlDKy](https://runbooks.ciscospaces.io/__attachments/a_6592635e131d3eb5f29b87c214ca7c753aa8043db2d1b6ff3d4ca5b23861c82a/AD_4nXdQSsfZNSK9Php4Q20PETIIjyw90wjPTm_rTUfX0VUxdnKiNDii-T2ePf5GE6CB4KWDeeWg5VtzdOdFM33q1m7vJV7pAXMY3S0H6adnW29_d1vYM29spjHwzukSVv8zBnNPcQsBOg%3Fkey=KpvWH-P_hmEWO_u2cH1rlDKy?cb=f187e42a42c8701f27baeb618912974a)

#### **Cisco Spaces Monitoring**

* The BMS will be programmed to change the value of their binary point every 60 seconds, It will toggle from on to off. Cisco gateway will monitor this point and if it does not see a change of value over a 5 minute (adj) period Cisco gateway will null out all commands until communications are reestablished for a minimum of 5 minutes (adj). Cisco gateway will notify users of the lost connection.

*** ** * ** ***

## REFERENCES

### ++**How it works**++

We use your existing Webex collaboration devices, such as the Webex Room bar, as an occupancy sensor by utilizing the person detecting ability native to the Webex cameras.

That occupancy data is pulled down from the Cisco Spaces Cloud to the Cisco Spaces OT gateway which connects to your BMS network as a BACnet device. The OT gateway is the only new hardware needed if you already have Webex collaboration devices installed.

When the BMS is operational, and a space is unoccupied, we set back the heating or cooling point for that space to cut down unnecessary heating or cooling. When the space becomes occupied or is about to be occupied (if integrated with your meeting calendar) the set-back is released and the BMS returns the space to an optimal temperature. We continue to monitor temperate while the space is occupied to ensure optimal conditions are maintained.

#### ++**Pre-Requisites:**++

* Your building has a BMS using the BACnet communication protocol (such as Johnson Controls - Metasys, Siemens - Desigo, Honeywell - Niagara (Tridium) \& WEBs, Schneider Electric - EcoStruxure, Trane - Tracer SC, Distech, Optergy, or many others)

* Your building has room-level HVAC controls

* You are an existing Cisco Spaces Customer with an ACT license; Rich maps operational, with a WebEx control hub integration

#### ++**Key Benefits:**++

1**. Energy Savings:** Eliminates unnecessary heating and cooling during idle periods, lowering utility costs.

2. **Optimized Wellbeing**: Spaces are comfortable upon arrival and maintained at optimal levels throughout meetings, enhancing tenant experience and productivity.

3. **Sustainability** An average-size meeting room can save 100lbs of carbon per year, equivalent to 2 fully grown trees.

4. **Data-Driven Insights**: Gain insights into room utilization patterns and energy trends through detailed analytics.

All data to and from the cloud is sent through an encrypted tunnel. BACNet data is sent unencrypted.

* Data From Cisco Spaces Cloud

* Room Schedule

* Room Occupancy

* Person Booking the room

#### Objectives

1. **Setback**- To setback the conference rooms occupied setpoints when the rooms are not being used to reduce wasted energy from HVAC equipment.

2. **Precondition**- Precondition conference rooms prior to usage to provide occupants a comfortable room upon occupancy.

##### SOO Notes

For the VAV Setback and Preconditioning sequence changes only the OCSP \& OHSP points will be written to. It's important to note that the heating setpoint should never be greater than the cooling setpoint and should always be at a minimum of 1°F less than the cooling setpoint.

The Schedule point is an important point that is used to indicate that the Air Handler that serves the VAV box is on or off. If the Schedule point is reading zero it indicates that air is not available for the VAV box resulting in no available cooling.

##### Setback SOO

When the room is not scheduled the VAV occupied setpoints will be adjusted to reduce the cooling or heating demand of the room. The room will still be conditioned just at different setpoints when not scheduled. The sequence will perform as follows:

When:

* Cisco Room Schedule = OFF and the VAV SCHED = 1

  * Write OCSP default value +4°F at priority 10 (Example default OCSP =73°F new value = 77°F)

  * Write OHSP default value -4°F at priority 10 (Example default OHSP =71°F new value = 67°F)

* Cisco Room Schedule = ON and the VAV SCHED = 1

  * Write OCSP current value null at priority 10 (This change VAV box to operate at default)

  * Write OHSP current value null at priority 10 (This change VAV box to operate at default)

* Cisco Room Schedule = ON and the VAV SCHED = 0

  * Write OCSP current value null at priority 10 (This change VAV box to operate at default)

  * Write OHSP current value null at priority 10 (This change VAV box to operate at default)

  * Note with the VAV schedule off air might not be available to the room which is out of Views control.

* Cisco Room Schedule = OFF and the VAV SCHED = 0

  * Write OCSP default value +4°F at priority 10 (Example default OCSP =73°F new value = 77°F)

  * Write OHSP default value -4°F at priority 10 (Example default OHSP =71°F new value = 67°F)

  * This will typically be seen at the end of the day and will keep the box in setback when the building starts the next morning unless there is a Cisco Room Scheduled for first thing in the morning.

  * Note with the VAV schedule off air might not be available to the room which is out of Views control.

##### Precondition SOO

Prior to a Cisco Room Scheduled event Preconditioning is used to have the room at default occupied setpoints at the start of a meeting. It's important to understand how long it takes a room to recover from a setback state to an occupied state. For example its important to know the average time for the space temperature to decrease or increase by 1°F. For example if it takes 5 minutes for a space to drop 1°F and we are transitioning from a space temperature of 76°F to a setpoint of 73°F the room should be taken out of Setback 15 minutes prior to the Cisco Rooms scheduled event start time. The same logic will be used for heat recovery. For this sequence we will call these points as follows.

Cool Recovery Time (CRT) = Average minutes it takes to lower the temperature 1°F

Heat Recovery Time (HRT) = Average minutes it takes to raise the temperature 1°F The Preconditioning SOO shall be as follows:

When Preconditioning Cooling

* Cisco Room Schedule has an event starting in 30 minutes and the space temperature is above the default cooling setpoint the precondition start time is calculated as follows:

* Precondition Cooling Start Time = Room Schedule Time - ((ST - default OCSP)\*CRT)

* Example: ST = 75°F, default OCSP = 73°F, and CRT = 5 minutes for meeting starting at 11:00am the Precondition Cooling Start Time = 10:50am.

* At Precondition Cooling Start Time write the following:

* Write OCSP current value null at priority 10 (This change VAV box to operate at default)

* Write OHSP current value null at priority 10 (This change VAV box to operate at default)

When Preconditioning Heating

* Cisco Room Schedule has an event starting in 30 minutes and the space temperature is below the default heating setpoint the precondition start time is calculated as follows:

* Precondition Heating Start Time = Room Schedule Time - ((ST - default OHSP)\*HRT)

* Example: ST = 67°F, default OHSP = 71°F, and CRT = 5 minutes for meeting starting at 11:00am the Precondition Heating Start Time = 10:40am.

* At Precondition Cooling Start Time write the following:

* Write OCSP current value null at priority 10 (This change VAV box to operate at default)

* Write OHSP current value null at priority 10 (This change VAV box to operate at default)

* Note: If the room is only served by cooling only VAV boxes preconditioning heating is not available and should not be used for the space.

### Monitoring and Exception Handling

The system is designed for resiliency. All control programming runs on the edge device, and not in the cloud. If requested the system can be deployed in High-availability configuration if the customer opts for the premium package.

The gateway, WAN and LAN connectivity, and individual Webex devices are all monitored as part of the managed service. Cisco's support teams will proactively address any issues, if they cannot be resolved by the support team or necessary changes will impact the customers systems, the customer will be notified of the issue and steps to be taken for resolution. If disruption in connectivity will significantly impact performance of the system the team may disable the Smart Rooms functionality until it is resolved, allowing the building's default programming to fully assume control.

If there is a failure in connectivity or the gateway, the following behaviors ensure a safe degradation of functionality:

#### **Webex Devices Lose Connectivity**

If Webex cameras or devices in the room lose connectivity, there will be no occupancy data coming from the room. In this event the gateway will release any programming and set all setpoints back to the default building programming. Once connectivity resumes the application will resume proactive conditioning.

#### **Loss of Internet Connectivity**

If there is no connection to the internet the local gateway will not receive occupancy data or calendar data for setbacks and preconditioning. In this event the gateway will release any programming and set all setpoints back to the default building programming. Once connectivity resumes the application will resume proactive conditioning.

#### **Hardware Failure**

If there is a hardware failure the support team will be immediately alerted and can alert the customer to take action. The latest setpoint changes will remain in place. Once the hardware comes back online it will resume adjusting setpoints. If the device remains offline, depending on the BMS the setpoints will eventually be overridden by the existing programming of the BMS.

### BMS Communication Monitoring

The constant monitoring of connection between the Smart Rooms gateway and BMS is critical when commands are received from the Cisco gateway to the BMS. If connection is lost from the Spaces Gateway, the BMS must revert to default programming. To accomplish this, a heartbeat connection point will be discovered from the Spaces gateway and trended on the BMS to monitor.

This is accomplished by the following:

* Cisco gateway will deliver a binary point to be discovered by the BMS. This point will oscillate and be used to disable Cisco gateway commands if the connection is lost (the point stops oscillating \& goes stale). In this event, the BMS will revert to base unit sequencing until connection is reestablished.

* Cisco cloud will change the value of this point every 60 seconds, It will toggle from ON to OFF. The BMS will need to be programmed to monitor this point and if it does not see a change of value over a 5 minute (adjustable) period, the Cisco gateway connection status will be off and remain off until communications are reestablished.

* When the Cisco gateway connection status point goes inactive, a BMS alarm will be activated notifying the building operators/Cisco Spaces/BMS operators.

---
language: "en"
---
# Cisco Spaces Smart Workspaces Runbook (Cisco Validated)

## OVERVIEW

*This Cisco Validated runbook will be a guide through the setup and configuration of Smart Workspaces, ensuring that the benefits of a connected and intelligent workplace can fully be realized.*

Cisco Spaces Smart Workspaces transforms traditional work environments into dynamic, data-driven ecosystems that enhance productivity and collaboration. By leveraging advanced location-based services, Smart Workspaces enables organizations to optimize space utilization, streamline operations, and create a more engaging workplace experience.

This solution provides real-time insights into workspace occupancy, usage patterns, and environmental conditions, empowering businesses to make informed decisions on space planning and resource allocation. With features like interactive digital maps, customizable alerts, and seamless integration with IoT devices, Smart Workspaces offers a holistic approach to managing modern work environments.

### SUPPORT \& ONBOARDING INFO

Please follow the link below to find out about the different ways to get support for Cisco Spaces.

* [++Support Info Link++](https://activate.dnaspaces.io/hubfs/Assets/CiscoSpaces-SupportUpdate.pdf?__hstc=105720540.52aaa4a978f36be89855b002cb35bfc4.1729705805310.1729705805310.1729705805310.1&__hssc=105720540.1.1729705805310&__hsfp=3667649010)

*** ** * ** ***

## PREREQUISITES

### Spaces OS

*This Cisco validated runbook is designed only as a follow on from the* [***Spaces OS Runbook***](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated)*.*The Cisco Spaces OS is the base installation for Cisco Spaces and is a prerequisite for this outcome. Please refer to the Spaces OS runbook for guidance on fulfilling this requirement.

*** ** * ** ***

### Device Support Matrix

Devices that are supported on Cisco Spaces ranges in use cases from different levels of occupancy to asset tracking to environmental metrics and more. Please review are list of currently supported devices along with their intended use cases on our [Knowledge Article on device compatibility](https://runbooks.ciscospaces.io/docs/cisco-spaces-device-compatibility-matrices).

*** ** * ** ***

### IDM (IOT Device Marketplace) Support Matrix

The Cisco Spaces IoT Device Marketplace is a platform where you can discover, research, and purchase IoT devices. IoT Device Marketplace is a part of the Cisco Spaces full-stack partner ecosystem. Each device is preconfigured to give the customer an out-of-the-box experience with sensors, tags, wearables, and more.

To learn more about the sensors available and supported on Cisco Spaces please visit the IoT Device Marketplace.

<https://dnaspaces.io/devicemarketplace/home>

*** ** * ** ***

### Calendar Support Matrix

Please refer to our Knowledge Article [Cisco Spaces Calendar Integrations (Webex Hybrid Calendar/O365/Gcal)](https://runbooks.ciscospaces.io/docs/cisco-spaces-calendar-integrations-webex-hybrid-calendar-o365-gcal) for supportability details.

*** ** * ** ***

## IMPLEMENTATION AND OUTCOMES

To complete these steps, an admin will require read/write permissions within Spaces for Space Manager and Space Experience, as well as read/write access to Webex Control Hub and/or Meraki Dashboard.

### Space Explorer - Kiosk app

#### Space Explorer - Kiosk app requirements

The Cisco Spaces digital kiosk app is a web app that can be remotely configured using a Cisco Board Pro or Desk Pro, and potentially 3rd party touchscreen or static TV displays. However, certain conditions must be met in order to function properly, and unless otherwise stated 3rd party displays are not certified or guaranteed to work by Cisco.  
**Chromium-based browser engines** are highly recommended.

**WebGL**

WebGL is a JavaScript API that allows users to create interactive 2D and 3D graphics in a web browser without the need for plugins. In order to run reliably, it must run on a device with a GPU.  
An all-in-one display, computer browser, or kiosk container app's browser engine **MUST** support WebGL. Check support here: [https://get.webgl.org​](#)

**Local Storage**

Most modern browsers have the Local Storage capability. However, whether the browser or kiosk container app's browser engine supports Local Storage persistence across reboots, operating system upgrades, etc. should be verified and tested on a case-by-case basis.  
*Browser Session Storage is required to deploy kiosk, and clearing the Session Storage clears the kiosk configuration, which requires re-claiming the device in the Non-Webex Devices section of the Space Experience app.*

**Example:** Chrome Browser policy that deletes session storage on reboot

Not that a Chrome browser would be used specifically to deploy the kiosk app, but to highlight that Local Storage can be erased automatically depending on various settings. It is best to use a dedicated kiosk program with policies in the embedded browser engine that support persistence of Local Storage.

<https://support.google.com/chrome/a/answer/2657289>

* chrome://policy

![Example - Chrome Browser policy that deletes session storage on reboot](https://runbooks.ciscospaces.io/__attachments/a_3e204ee44b01fc7ada3f2bb92c7eecb76d63b67217e491aa0b01909c6d1ab5b9/02_58_27.jpg?cb=4849a6d1e0ef6dd7504a67656bd6b6cb)
Example: Chrome Browser policy that deletes session storage on reboot

#### Kiosk Device Compatibility

**Recommended**-- Best Performance

* [++Cisco Board Pro++](https://www.cisco.com/c/en/us/support/collaboration-endpoints/spark-board/series.html) (55", 75")

* [++Cisco Desk Pro++](https://www.cisco.com/c/en/us/support/collaboration-endpoints/webex-desk-pro/model.html)

**Compatible** - not recommended due to being EOS

* [++Webex Board 55S++](https://www.cisco.com/c/en/us/support/collaboration-endpoints/spark-board/series.html) - EoS

* [++Webex Board 70S++](https://www.cisco.com/c/en/us/support/collaboration-endpoints/spark-board/series.html) - EoS

* [++Webex Board 85S++](https://www.cisco.com/c/en/us/support/collaboration-endpoints/spark-board/series.html) -- EoS

**Other Options**

* [++Cisco collaboration devices certification program++](https://help.webex.com/en-us/article/7sw4gab/Cisco-collaboration-devices-certification-program)

* [++Samsung Smart Kiosk Interactive Displays++](https://www.samsung.com/us/business/)

* [++Elo Touch Interactive Displays++](https://www.elotouch.com/touchscreen-signage.html)

Some kiosk displays may require a **host device** such as a Room Kit Mini, mini PC, or another computer with a built-in browser or kiosk app to load the Cisco Spaces kiosk web app.

#### Matrix of Deployment Options

|              |     **Webex Control Hub Integration w/ Webex Board**     |                **Non-Webex Device Method + Kiosk Mode w/ Webex Board**                |            **Webex Control Hub Integration + Kiosk Mode w/ Webex Board**            |                       **Webex Control Hub Integration w/ 3rd Party Kiosk Device**                       |                                  **Non-Webex Device Method w/ 3rd Party Kiosk**                                  |
|--------------|----------------------------------------------------------|---------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------|
| Availability | Available (Recommended)                                  | Available                                                                             | Roadmap                                                                             | Roadmap                                                                                                 | Available                                                                                                        |
| Benefits     | * End-to-end monitored by Cisco * Remotely deployable    | * Users cannot exit Kiosk app                                                         | * End-to-end monitored by Cisco * Remotely deployable * Users cannot exit kiosk app | * End-to-end monitored by Cisco * Remotely deployable * Users cannot exit kiosk app * Lower cost option | * Users cannot exit kiosk app (depends on kiosk) * Lower cost option                                             |
| Caveats      | * Users can exit kiosk app * Unused Webex Board features | * Requires person on-site * Limited logs and monitoring * Unused Webex Board features | * Unused Webex Board features                                                       |                                                                                                         | * Requires person on-site (depends on kiosk) * Limited logs and monitoring * Not certified / guaranteed by Cisco |

**Note:** Microsoft Teams Room (MTR) devices...

* DO support Digital Signage Mode ([xConfiguration Standby Signage Mode](https://roomos.cisco.com/xapi/Configuration.Standby.Signage.Mode/))

* Do NOT support Kiosk Mode ([xConfiguration UserInterface Kiosk Mode](https://roomos.cisco.com/xapi/Configuration.UserInterface.Kiosk.Mode/))

* Do NOT support WebApp ([xCommand UserInterface Extensions WebApp Save](https://roomos.cisco.com/xapi/Command.UserInterface.Extensions.WebApp.Save/))

#### Kiosk List of API Endpoints for Firewall Settings

Below are the endpoints used to deliver Cisco Spaces Kiosk app. Signage endpoints should be able to reach every one of these endpoints on an outbound request.

**Ports:** 443 for all domains / endpoints listed below  

|                                                                                                                                                                                                                       **IO Region**                                                                                                                                                                                                                        |                                                                                                                                                                                                                       **EU Region**                                                                                                                                                                                                                        |                                                                                                                                                                                                  **SG Region**                                                                                                                                                                                                  |
|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Highly recommended** to add these wildcards: `*.ciscospaces.io` `*.dnaspaces.io`                                                                                                                                                                                                                                                                                                                                                                         | **Highly recommended** to add these wildcards: `*.ciscospaces.eu` `*.dnaspaces.eu`                                                                                                                                                                                                                                                                                                                                                                         | **Highly recommended** to add these wildcards: `*.ciscospaces.sg` `--`                                                                                                                                                                                                                                                                                                                                          |
| **Required**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
| `https://kiosk.ciscospaces.io` `https://signage.dnaspaces.io` `https://workspaces.dnaspaces.io` `https://workspaces.ciscospaces.io` `wss://webex-api-server.dnaspaces.io` `--` `wss://swsjetstreams.dnaspaces.io` `--` `https://rms.dnaspaces.io` `https://rms.ciscospaces.io` `https://maps.ciscospaces.io` `https://api.mapbox.com` `https://events.mapbox.com` `https://fonts.googleapis.com` temporary: `*.amazonaws.com` (Smart Rooms \& Custom Logo) | `https://kiosk.ciscospaces.eu` `https://signage.dnaspaces.eu` `https://workspaces.dnaspaces.eu` `https://workspaces.ciscospaces.eu` `wss://webex-api-server.dnaspaces.eu` `--` `wss://swsjetstreams.dnaspaces.eu` `--` `https://rms.dnaspaces.eu` `https://rms.ciscospaces.eu` `https://maps.ciscospaces.eu` `https://api.mapbox.com` `https://events.mapbox.com` `https://fonts.googleapis.com` temporary: `*.amazonaws.com` (Smart Rooms \& Custom Logo) | `https://kiosk.ciscospaces.sg` `https://signage.ciscospaces.sg` `--` `https://workspaces.ciscospaces.sg` `--` `wss://webex-api-server.ciscospaces.sg` `--` `wss://sgswsjetstreams.ciscospaces.sg` `--` `https://rms.ciscospaces.sg` `https://maps.ciscospaces.sg` `https://api.mapbox.com` `https://events.mapbox.com` `https://fonts.googleapis.com` temporary: `*.amazonaws.com` (Smart Rooms \& Custom Logo) |
| **Optional**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
| non-blocking: `*.pendo.com`                                                                                                                                                                                                                                                                                                                                                                                                                                | non-blocking: `*.pendo.com`                                                                                                                                                                                                                                                                                                                                                                                                                                | non-blocking: `*.pendo.com`                                                                                                                                                                                                                                                                                                                                                                                     |

#### Digital Signage Setup \& Configuration

##### Webex Control Hub Setup

###### Device Modes

1. **Digital Signage mode**: A webpage takes over the entire display when in Halfwake state, but all device functionalities remain accessible by swiping up from the bottom edge of the display.

2. **Home screen Web App**: Ad hoc access to one or more kiosks from the home screen app list on the device.

3. **Kiosk mode (Recommended for lobby displays)**: Lock the display to a specific webpage URL and block all other functionality on the device.

*** ** * ** ***

###### Webex Control Hub: Device All Configurations Settings

Enable **WebGL** , **WebEngine**, and optimize Standby, Halfwake, and other Cisco Board configurations:

* \[xConfiguration WebEngine Features WebGL\](<https://roomos.cisco.com/xapi/Configuration.WebEngine.Features.WebGL/> ) ⇒ `On` (default: `Off`)

* \[xConfiguration WebEngine Mode\](<https://roomos.cisco.com/xapi/Configuration.WebEngine.Mode/> ) ⇒ `On` (default: `Off`)

* \[xConfiguration Standby Control\](<https://roomos.cisco.com/xapi/Configuration.Standby.Control/> ) ⇒ `Off` (default: `On`)

* \[xConfiguration Standby Delay\](<https://roomos.cisco.com/xapi/Configuration.Standby.Delay/> ) ⇒ `480` (default: `10`)

* \[xConfiguration Standby Level DeepSleep Mode\](<https://roomos.cisco.com/xapi/Configuration.Standby.Level.DeepSleep.Mode/> ) ⇒ `Off` (default: `Off`, optionally: `OutsideOfficeHours`)

* \[xConfiguration Standby WakeupOnMotionDetection\](<https://roomos.cisco.com/xapi/Configuration.Standby.WakeupOnMotionDetection/> ) ⇒ `On` (default: `On`)

* \[xConfiguration Time OfficeHours Enabled\](<https://roomos.cisco.com/xapi/Configuration.Time.OfficeHours.Enabled/> ) ⇒ `True` (default: `True`)

* \[xConfiguration Time OfficeHours WorkDay Start\](<https://roomos.cisco.com/xapi/Configuration.Time.OfficeHours.WorkDay.Start/> ) ⇒ when the board should exit standby or deepsleep (default: `07:00`)

* \[xConfiguration Time OfficeHours WorkDay End\](<https://roomos.cisco.com/xapi/Configuration.Time.OfficeHours.WorkDay.End/> ) ⇒ when the board should enter standby or deepsleep (default: `19:00`)

* \[xConfiguration Time OfficeHours WorkWeek Monday\](<https://roomos.cisco.com/xapi/Configuration.Time.OfficeHours.WorkWeek.Monday/> ) ⇒ days of the week office hours should be applied (default: `True`, separate xAPIs for Monday through Sunday)

* \[xConfiguration Time OfficeHours OutsideOfficeHours Standby Delay\](<https://roomos.cisco.com/xapi/Configuration.Time.OfficeHours.OutsideOfficeHours.Standby.Delay/> ) ⇒ `5` (default: `5`)

* \[xConfiguration Time OfficeHours OutsideOfficeHours Standby AutoWakeup\](<https://roomos.cisco.com/xapi/Configuration.Time.OfficeHours.OutsideOfficeHours.Standby.AutoWakeup/> ) ⇒ `Enabled` (default: `Disabled`)

Kiosk Mode:

* \[xConfiguration UserInterface Kiosk Mode\](<https://roomos.cisco.com/xapi/Configuration.UserInterface.Kiosk.Mode/> ) ⇒ `On` (default: `Off`)

* \[xConfiguration UserInterface Kiosk URL\](<https://roomos.cisco.com/xapi/Configuration.UserInterface.Kiosk.URL/> ) ⇒ paste Non-Webex Devices kiosk URL in Space Experience app to generate a 4-digit code, this method will be replaced by automated xAPIs configuration (default: `blank`)

Digital Signage Mode:

* \[xConfiguration Standby Signage Mode\](<https://roomos.cisco.com/xapi/Configuration.Standby.Signage.Mode/> ) ⇒ `On` (default: `Off`)

* \[xConfiguration Standby Signage Url\](<https://roomos.cisco.com/xapi/Configuration.Standby.Signage.Url/> ) ⇒ automatically configured via xAPIs (default: `blank`)

* \[xConfiguration Standby Signage InteractionMode\](<https://roomos.cisco.com/xapi/Configuration.Standby.Signage.InteractionMode/> ) ⇒ `Interactive` (default: `NonInteractive`)

*** ** * ** ***

###### Webex Control Hub: Configure Webex Device in Digital Signage Mode

###### **Cisco Spaces Integration Method**

1. Click on Devices (left menu)

2. Search for the device in the list view

3. Click it to open the device details view

4. Click on **Configurations** \> **Digital** **Signage** (right side section)

5. Toggle **Digital Signage** and **Interactivity**

6. Choose "Cisco Spaces" radio button

7. Click Save

Devices placed into this mode will be detected in the Space Experience app automatically as long as the device is organized in **Webex Control Hub under a Location \> Floor** and ++merged++ into the **Cisco Spaces Location Hierarchy under Setup \> Locations \& Maps**.  
![Screenshot 2026-05-21 at 9.29.43 AM.png](https://runbooks.ciscospaces.io/__attachments/a_09504e5545f4c484b8dfda8279b45b577f5d8eece60019be1dd8e45c5c2ff082/Screenshot%202026-05-21%20at%209.29.43%E2%80%AFAM.png?cb=9b90281ee5d56fdf06e052801f340316)
Digital signage setting  
![Screenshot 2026-05-21 at 9.31.37 AM.png](https://runbooks.ciscospaces.io/__attachments/a_c0e7e4975fea29af2dc20f4b950d3ba5961f2e0472dad02c36ee08656476789f/Screenshot%202026-05-21%20at%209.31.37%E2%80%AFAM.png?cb=7842bf2c85a15f58d0b691ddc23cc013)
Digital signage configuration

If the Cisco Spaces kiosk app is stuck on a "Loading..." screen in kiosk mode on a collaboration device, clearing the device's cache from Webex Control Hub should cause it to sync and load correctly.

[https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-validated#Caveats-\&-Tips](https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-validated#Caveats-&-Tips)

*** ** * ** ***

###### **URL Method**

URLs with "?token=..." are not supported. The kiosk app MUST be deployed using the **Non-Webex Devices** methods in the Space Experience app.

1. Click on Devices (left menu)

2. Search for the device in the list view

3. Click it to open the device details view

4. Click on **Configurations** \> **Digital Signage** (right side section)

5. Toggle **Digital Signage** and **Interactivity**

6. Choose "URL" radio button

7. Click Save

![Screenshot 2024-10-09 at 9.43.01 AM.png](https://runbooks.ciscospaces.io/__attachments/a_48b70ab7cbdb1da820acf5ab2c4795fa0c4f292abcf5ba6e4baf81bdaf481ebd/Screenshot%202024-10-09%20at%209.43.01%E2%80%AFAM.png?cb=eb585715fa9a16a140f35e2726f3c531)  
Note: use with caution. Clearing the browser cache for the URL Method disconnects the device from any configured settings. The browser Local Storage is cleared and requires Kiosk setup again.

If the Cisco Spaces kiosk app is stuck on a "Loading..." screen in kiosk mode on a collaboration device, clearing the device's cache from Webex Control Hub should cause it to sync and load correctly.

<https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida#CiscoSpacesSmartWorkspacesRunbook(CiscoValidated)-1.TroubleshootingCiscoCollaborationdeviceconfiguredinDigitalSignagemodeinWebexControlHub,butnotappearinginSpaceExperience%3EDevices%3EWebexDeviceslistviewforconfiguration>

*** ** * ** ***

###### Web App

URLs with "?token=..." are not supported. The kiosk app **MUST** be deployed using the **Non-Webex Devices** methods in the Space Experience app.

1. Web App configuration steps

![Screenshot 2024-11-15 at 11.06.12 PM.png](https://runbooks.ciscospaces.io/__attachments/a_0cec2858efec7f112baab5144f404c9f9aeb03391e2ed7849b287ab6bbc54cad/Screenshot%202024-11-15%20at%2011.06.12%E2%80%AFPM.png?cb=238543afca0ce5ba28e80b98904b8041)

*** ** * ** ***

###### Kiosk mode **(Recommended for lobby displays)**

URLs with "?token=..." are not supported. The kiosk app **MUST** be deployed using the **Non-Webex Devices** methods in the Space Experience app.

1. In Space Experience app, click **Non-Webex Devices** (tab)

2. Click **Add Signage** (blue button) in the top right corner

3. Expand the Location Hierarchy until you find a Location and ++importantly the specific Floor++ the Kiosk device is on physically

4. Click the **radio button** on the right side of the Floor

5. Click **Next** (blue button) in the bottom right

6. Click **Can't see the activation code?**

7. **Copy** the URL (looks like: https://signage.dnaspaces.io/t/...) This URL is unique to your Account/Tenant. Save it for setting up more Kiosks later.

8. Leave the Spaces dashboard at this stage and go to Webex Control Hub (https://admin.webex.com)

9. In Control Hub, go to **Devices** (left nav)

10. Scroll to or search for the Kiosk device (e.g. Board Pro) and click on the device row

11. On the right side, under the **Configurations** header, click on **All configurations**

12. Scroll to or search for **Kiosk** under **UserInterface** \> **Kiosk**

13. **Paste** the URL from Step 7 above into the **Configuration value** field under **UserInterface** \> **Kiosk** \> **URL**

14. Choose **On** from the **Configuration value** dropdown under **UserInterface** \> **Kiosk** \> **Mode**

15. Click **Next** (bottom right)

16. Click **Apply** (bottom right)

17. Click **Close** (bottom right)

18. The kiosk device display will show a 4-digit code (single-use)

19. Go back to the Space dashboard tab in your browser with Space Experience app open showing the fields for **Activation Code** and **Name your signage**

20. Type the 4-digit code from Step 18 into the **Activation Code** field

21. Type a unique name for this kiosk in the **Name your signage** field (see: <https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida#CiscoSpacesSmartWorkspacesRunbook(CiscoValidated)-SetupNon-WebexDevice%E2%80%8B>in a later section for best practices)

22. Click **Save** (blue button, bottom right)

23. Click **Close**

24. Under the **Non-Webex Devices** (tab), find the kiosk on the list view

25. On the row of the kiosk, click **Configure** under the **Actions** column

26. Go through the kiosk configuration workflow under <https://runbooks.ciscospaces.io/docs/cisco-spaces-smart-workspaces-runbook-cisco-valida#CiscoSpacesSmartWorkspacesRunbook(CiscoValidated)-SpaceExperience:ConfigureDigitalKioskSteps>

![Copy-Paste signage URL into Webex Control Hub - All Configurations - Kiosk Mode and URL](https://runbooks.ciscospaces.io/__attachments/a_83ad193631dac3783af8e9684557e824c6934650ad69b67e1d8e2035b6d5bd2b/Screenshot%202025-04-03%20at%2016.22.45.png?cb=5ac6644b2fe59862219d7cd955a13514)
Copy+Paste signage URL into Webex Control Hub \> All Configurations \> Kiosk Mode and URL

#### Cisco Spaces: Space Experience app

##### Webex Devices

* Setup Webex Device

![Screenshot 2024-10-09 at 9.15.11 AM.png](https://runbooks.ciscospaces.io/__attachments/a_b7cdfeb15c8dd0815d7033ceb851b3fd4c5fd59b953e8a54fbaf0b69362eee47/Screenshot%202024-10-09%20at%209.15.11%E2%80%AFAM.png?cb=3776973ecf2937587e81b77509e61768)

![Screenshot 2024-10-09 at 9.15.35 AM.png](https://runbooks.ciscospaces.io/__attachments/a_0c567f443c67bb78a4b9cdb452a962249981bc668a67a83c44c399f0b454f9d4/Screenshot%202024-10-09%20at%209.15.35%E2%80%AFAM.png?cb=5b057d08cd7e2a0cd77320b99cde35dd)

*** ** * ** ***

##### Setup Non-Webex Device​

* Simple and secure Digital Kiosk deployment​

**Non-Webex Device Method Naming Convention​**

When setting up multiple displays, especially many per floor of the same building, we recommend establishing a kiosk naming convention in the Space Experience app that makes identifying devices easier.​

Using the **Non-Webex Devices** deployment method does not share device metadata with the Spaces platform, so we recommend including some kind of device identifier (e.g. serial number, partial MAC) in the name of the kiosk in the Space Experience app.​

**Avoid Duplicate Kiosk Names**  
![Screenshot 2024-10-09 at 9.40.59 AM.png](https://runbooks.ciscospaces.io/__attachments/a_fd2daa662b6096c5e2fab24b9c09cac2823f5869f60d196295e86d5bf38c1f27/Screenshot%202024-10-09%20at%209.40.59%E2%80%AFAM.png?cb=fe0a0e5a752d733e7e5efb24cf0a51c7)

1. Steps to configure **Non-Webex Devices** kiosk

![Screenshot 2024-10-09 at 9.38.43 AM.png](https://runbooks.ciscospaces.io/__attachments/a_a3051496a1d92c33e5279998d44f7212a348e8c9ace480c5dcb1984e27406178/Screenshot%202024-10-09%20at%209.38.43%E2%80%AFAM.png?cb=f686be8fdf7caeca33d945e3dfdb7ada)

*** ** * ** ***

##### Space Experience: Configure Digital Kiosk Steps

**Step 1: Kiosk type \& view**

* Signage type

  * Interactive - Ideal for touch displays

  * Non Interactive - Perfect for static, information displays​

* View

  * Building - Presents an overview of the entire building

  * Floor - Shows a single floor's 3D Rich Map (cannot select other floors)

* Override Lat Long

  * The default map center point is taken from Setup \> Locations \& Maps \> Locations by clicking on the "3 dots" menu for the location and editing the Location Metadata. The pin location on the Google Map view is the center point used by default in kiosks, but it can be overridden using these fields.

  * Get latitude and longitude values from Google Maps (as an example) by right-clicking on Google Maps on the building.

![Space Experience - Signage type and view](https://runbooks.ciscospaces.io/__attachments/a_a26bb12d5d4ea3b32f24208a9904ff73949f89b16f62b1d023f247b8c8f2dbac/Screenshot%202024-11-14%20at%2014.56.33.png?cb=885553c81492cabf2ec6df92756fe92e)
Space Experience - Kiosk type \& view

**Step 2: Configure Widgets**

Configure which widgets to show on each signage:

* Occupancy

* Indoor Air Quality

* CO2 Level

* Temperature

  * Fahrenheit

  * Celsius

* Humidity

* Point of Interest (POI)

![Space Experience - Configure Widgets](https://runbooks.ciscospaces.io/__attachments/a_3c324202ab2c41795f90b9653439a82a68a701419a61ade42eebccf964383002/Screenshot%202024-11-14%20at%2015.02.06.png?cb=12a222aa5786140a0910f2e5ef8a735c)
Space Experience - Configure Widgets

**Step 3: Set the default map view**

Use the controls below or on the right side to change the default perspective of the Rich Map. The signage display will appear exactly as shown during configuration. Alternatively, drag the Rich Map to the right to position it on the screen.

Pitch - vertical angle of the map view

Bearing - horizontal rotation of the map view

Zoom - level of zoom in the map view  
Note: only whole numbers are supported for Pitch, Bearing, and Zoom.  
![Space Experience - Set the default map view](https://runbooks.ciscospaces.io/__attachments/a_5a35f1bf6d522b73e39a9b38d750c1b6c9f88069e4e75f441523bb734ea0f7e4/Screenshot%202024-11-14%20at%2015.07.53.png?cb=bad1c04698f03e7f25d7a6d61b759a9f)
Space Experience - Set the default map view

**Step 4: Configure "Where am I?" 3D character**

* Place and rotate 3D caricature (named: "Spot) with a Digital Kiosk display on the floor map for giving context to the person interacting with the kiosk.​

***Note:*** *a floor must be chosen in the "Add Signage" step (before* ***Configure*** *) to place a "Where am I?" character.​*  
![Space Experience - Configure Where am I 3D character](https://runbooks.ciscospaces.io/__attachments/a_873cf25eb80c725bf88ede9e0d330f6bd0a778fa637ebde158d87a22f3fb9b26/Screenshot%202024-11-14%20at%2015.27.22.png?cb=85cdc58f93da52a60358f3b5ca7f9cb9)
Space Experience - Configure "Where am I?" 3D character

**Step 5: Review and** **Publish**  
Note: the preview will show the previously published version of the kiosk app. It will not update with new configurations until after clicking Publish.  
![Space Experience - Review and Publish](https://runbooks.ciscospaces.io/__attachments/a_c1b18a76a5472dc8c13600fd0570fe94ce4983773524c1c714ba024c3c9dc3de/Screenshot%202024-11-14%20at%2014.52.02.png?cb=bc37e58358bb3ff0f4f28cb719586097)
Space Experience - Review and Publish  
![Space Experience - Published](https://runbooks.ciscospaces.io/__attachments/a_20d1844ce56e5bb4b3f18ac679c2047e13ee07e065d584b0fec6613c645c331f/Screenshot%202024-11-14%20at%2014.52.50.png?cb=cffdb45a9d761fb5a59091c765371f4b)
Space Experience - Published

*** ** * ** ***

### Visualizing Outcomes with Meraki Things (MT) Sensors

#### Overview of Outcomes

**Note:** Publishing MT data to Cisco Spaces Digital Kiosk and dashboard apps requires that the Meraki integration has already been performed as outlined in the Spaces OS runbook.

Pre-requisites:

1. Upload floorplans and [properly geo-reference them](https://runbooks.ciscospaces.io/docs/guide-to-network-map-geo-placement-and-best-practi)

2. [MT placed on floorplans](https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Placing_Devices_on_the_Map_in_Dashboard#Drag_and_Drop_the_Icon_Manually)

<https://app.vidcast.io/share/09711009-fd50-4bd7-8403-6aa758f98f03>

#### Meraki Things (MT) Sensor Meeting Room Assignment

In **Space Manager** \> **Manage Rooms**:

1. click on a Meeting Room's name in the list

2. go to IoT Sensors → **(+) Add Devices**

3. search for and select device(s)

4. click **Add Device**

#### Environmental Analytics Outcome

![Environmental Analytics - Overview](https://runbooks.ciscospaces.io/__attachments/a_0bfc0e9c3a33a817cb5355d892b48f4c0608c92951c6e0c5d99ed6f849023746/Screenshot%202025-08-12%20at%2016.46.14.png?cb=b6ef03f99bcd2550ab37d444cc0f5b29)
Environmental Analytics - Overview

At a high level, get an overview of the performance of your portfolio or specific buildings to figure out where to drill into problem areas.  
![Environmental Analytics - Air Quality - CO2 - Floor View](https://runbooks.ciscospaces.io/__attachments/a_f1c0d3d7d5846658d5bd558fc4a5f90347cc6e235849a16a357d416ddb19a834/Screenshot%202025-08-12%20at%2016.48.33.png?cb=7b4d3ad3699ad851c8aeeef6365d75c5)
Environmental Analytics - Air Quality - CO₂ - Floor View

Once drilling into specific buildings and floors, visualize daily and monthly aggregated sensor data. View cumulative time across all sensors spent outside of their ideal ranges. Compare floors and drill into specific time ranges, especially for peaks to see which specific sensors or meeting rooms were contributing to out of range sensor violations.  
**Note:** MT placed on the network floorplan in Meraki Dashboard and in the Cisco Spaces Location Hierarchy will show up as individual sensors when drilling into specific time slots in the graphs. MT assigned to Meeting Rooms in Space Manager are aggregated along with all other sensors of the same environmental metrics type assigned to that Meeting Room, but can be viewed individually, too.

#### Kiosk Outcome: Building, Floor, \& Room Sensor Metrics

![Screenshot 2024-11-15 at 8.58.53 AM.png](https://runbooks.ciscospaces.io/__attachments/a_a36c268aef15ece346e4e448bcf04a720fd0b896fa925df44d060e1b0fe23341/Screenshot%202024-11-15%20at%208.58.53%E2%80%AFAM.png?cb=705d233825a161a344bd9396a1ebef3b)

* **Building** - temperature, humidity, and air quality aggregated metrics

* **Floor** - temperature, humidity, and air quality aggregated metrics

* **Room** - temperature, humidity, air quality, and ambient noise metrics​

*** ** * ** ***

### Configuring Spaces for IoT Services

* **Integration**: BLE, wireless, \& wired IoT Devices

* **Outcome**: building\^, floor\^, room\*\*, \& desk\*\* sensor metrics

* **Building** -- aggregate - temperature, humidity, air quality, and CO~2~

* **Floor** -- aggregate - temperature, humidity, air quality, and CO~2~

* **Room** -- aggregate -- temperature, humidity, air quality, CO~2~, and ambient noise

* **Roadmap**\*\*: presence, people count, and calendar resource integration

* **Desk**\*\*

\^ Currently requires additional work and will add time to deployment

\*\* Roadmap

#### **IoT Devices Pre-Requisites**

##### *Catalyst 9136/9166 on-device sensors (e.g. temperature, humidity, IAQ)*

<https://www.youtube.com/watch?v=SgEFyjczY3U>

###### ++IoT Device Marketplace sensors++

<https://dnaspaces.io/devicemarketplace/home>

###### ++AP Configuration Setup++

Catalyst 91XX Access Points w/ simultaneous BLE beacon and gateway capabilities

###### IoT Services

<https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-services-wireless/b_iot_services/m_overview.html>

###### Claiming Sensors

<https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m-sensors.html>

*** ** * ** ***

### Configuring the Cisco Room Navigator

[Room Navigator Set up](https://help.webex.com/en-us/article/55ypt4/Set-up-Room-Navigator-as-a-room-booking-device)

* Factory Reset and setup in PWA mode

![Screenshot 2024-11-15 at 3.37.05 PM.png](https://runbooks.ciscospaces.io/__attachments/a_2524059e1dcf5dfcbc377b4a954c37b829555d513cddc5dd22d8e0eef1d6e194/Screenshot%202024-11-15%20at%203.37.05%E2%80%AFPM.png?cb=434e4478fc96b88a471fc8c733ce2b4b)

![Screenshot 2024-11-15 at 3.39.51 PM.png](https://runbooks.ciscospaces.io/__attachments/a_cdae3e1fcb5c1bc9ab483271b350b5bb1d28d2280f2653a885450854a8a859a8/Screenshot%202024-11-15%20at%203.39.51%E2%80%AFPM.png?cb=a776d920f63a01cac9c6df751895e2b2)  
**Note:** the wall Navigator **must** be paired with an in-room video equipment in order to display the Cisco Spaces Navigator Meeting Room PWA. A Standalone Navigator will display the Kiosk application, which does not run properly on a Navigator due to limited resources for web rendering.  
![Screenshot 2024-11-15 at 3.40.03 PM.png](https://runbooks.ciscospaces.io/__attachments/a_5b9263af7d9005d63933074a60d43dd2911ff56de7c3c885d4fe38620018c8b1/Screenshot%202024-11-15%20at%203.40.03%E2%80%AFPM.png?cb=fd3e3d56847fd8c5915ab14b5395e248)

Configuring the Cisco Spaces Navigator Meeting Room PWA (persistent web app) on an outside the room Wall Navigator is **optional**, but currently the only supported method to turn the Navigator status LED bar blue to indicate the "Hold" status and color when clicking the 3-minute "Hold" button on a configured room on the Space Explorer Kiosk or Web App. However, not all native RoomOS or Microsoft Teams Room (MTR) features are available on the Cisco Spaces Wall Navigator PWA (persistent web app). For example, you cannot book a room and check-in/auto-release is not available from Webex Control Hub configuration settings. Available, Booked, and Occupies statuses are reflected on the Cisco Spaces PWA. A Standalone Navigator with or without Cisco Spaces PWA running cannot be configured to update occupancy status based on 3rd Party Occupancy IoT sensors from the Cisco Spaces platform, but may be possible in a future update.

*** ** * ** ***

### Visualizing Room Telemetry Data with Space Manager

![Screenshot 2024-11-15 at 4.15.40 PM.png](https://runbooks.ciscospaces.io/__attachments/a_bc7bcd236052a9ab6c414c8f203ce569e217407a7835e8d428fc9eea4bcd1a8f/Screenshot%202024-11-15%20at%204.15.40%E2%80%AFPM.png?cb=83c1b309c1bf9627750d64a3b4298621)

![Screenshot 2024-11-15 at 4.15.51 PM.png](https://runbooks.ciscospaces.io/__attachments/a_2d5a21e09be7dfc64f2cfdae6c438a01f337f90e0912852c962106fd07c2ea6c/Screenshot%202024-11-15%20at%204.15.51%E2%80%AFPM.png?cb=99817c4f380a4afff7c65663e2cb0efe)

![Screenshot 2024-11-15 at 4.16.01 PM.png](https://runbooks.ciscospaces.io/__attachments/a_6e0e032d75c9da6e4f167366784f5a6e02475650e16e8849d52c8dc9087c909d/Screenshot%202024-11-15%20at%204.16.01%E2%80%AFPM.png?cb=cc5e19d11402fa47f84652b47aa32972)

![Screenshot 2024-11-15 at 4.16.13 PM.png](https://runbooks.ciscospaces.io/__attachments/a_f09938266cfbf8c696b4e890dceeece042aa8e9de9d73909f937d4138cbd4963/Screenshot%202024-11-15%20at%204.16.13%E2%80%AFPM.png?cb=8ac084751c82cbc8ac4549c14f09a835)

#### Devices

![Screenshot 2024-11-15 at 8.23.53 PM.png](https://runbooks.ciscospaces.io/__attachments/a_ac2b90edc960ee936c10c35f21cf0c69d92187f6bfe6b16a0aaaca001468c516/Screenshot%202024-11-15%20at%208.23.53%E2%80%AFPM.png?cb=17c80b13ae90b6442dc9574ae727a0cf)

![Screenshot 2024-11-15 at 8.24.05 PM.png](https://runbooks.ciscospaces.io/__attachments/a_d7c73cca099e4472acf217db6864709f9839f4e331ac562400f929b44f17fb2d/Screenshot%202024-11-15%20at%208.24.05%E2%80%AFPM.png?cb=50c335755d39b957fcd90b0c45f0067e)

*** ** * ** ***

### Configuring Meeting Room Settings in Space Manager

![Screenshot 2024-11-15 at 8.45.09 PM.png](https://runbooks.ciscospaces.io/__attachments/a_de639a204c4d2c23058032df1f48b2540b24ebcc295f43941dcbb6b93e406e2a/Screenshot%202024-11-15%20at%208.45.09%E2%80%AFPM.png?cb=04741f67514f24757ba74feb8f7970b7)

![Screenshot 2024-11-15 at 8.50.09 PM.png](https://runbooks.ciscospaces.io/__attachments/a_5aa81ba63f534d0f59a58e939fa92852ba8753c536ae8838e71371cecb8cf43f/Screenshot%202024-11-15%20at%208.50.09%E2%80%AFPM.png?cb=f616944ed5f8c8550070a94a8f70d6f5)

![Screenshot 2024-11-15 at 8.50.22 PM.png](https://runbooks.ciscospaces.io/__attachments/a_c1b9eebd6c592433e7077c0bdd908dbbf4bc9666a2734b63ec785c317a0730aa/Screenshot%202024-11-15%20at%208.50.22%E2%80%AFPM.png?cb=8f13a791c96d433630cc1238930b67a7)

![Screenshot 2024-11-15 at 8.50.32 PM.png](https://runbooks.ciscospaces.io/__attachments/a_bffe29b8a1f278e9fcfa49759cdb5bfc294c6ee6af40cc677c8264c24d19a071/Screenshot%202024-11-15%20at%208.50.32%E2%80%AFPM.png?cb=2428a839167e749d5330c95c141a4b0b)

*** ** * ** ***

## REFERENCES

* <https://help.webex.com/en-us/article/nc6od6r/Utilization-and-environmental-metrics-for-workspaces>

*** ** * ** ***

## Caveats \& Tips

### 1. Troubleshooting Cisco Collaboration device configured in **Digital Signage** mode in **Webex Control Hub** , but not appearing in **Space Experience** \> **Devices** \> **Webex Devices** list view for configuration

#### In some cases, the display may appear stuck, frozen, or otherwise unresponsive/non-responsive on this application screen, and the device is not appearing in Spaces to Configure.

![Cisco Spaces Kiosk App waiting to be configured](https://runbooks.ciscospaces.io/__attachments/a_a1f7c2f1c7a8864f5f358354753828deaacf106751d57003509ed781f50fee60/Screenshot%202025-03-14%20at%2012.28.37.png?cb=71fc40898fa0f8100da056e03adc3e32)
Cisco Spaces Kiosk App waiting to be configured  
![Cisco Spaces - Space Experience - Devices - Webex Devices](https://runbooks.ciscospaces.io/__attachments/a_7f803ad83b3aaa6797046c6c324aa2bee69773f5d72ca98c1a3be68da4b50201/Screenshot%202025-03-14%20at%2013.06.19.png?cb=8aa9af8d5163237e7d242e6ed9086e1d)
Cisco Spaces - Space Experience \> Devices \> Webex Devices

##### First, check to make sure the Webex Device is assigned to the exact Location+Floor in Control Hub that is merged into the Cisco Space Location Hierarchy, and that the device appears under the list of Webex Devices.

![Cisco Spaces - Location Hierarchy - Network Devices - Webex Devices](https://runbooks.ciscospaces.io/__attachments/a_5f270016f74f2288cd2368f124e4339518e83bb283fdf03698742a11e2529da7/Screenshot%202025-03-14%20at%2013.16.39.png?cb=022d8b985c54e9039a446f75a733c8ab)
Cisco Spaces \> Location Hierarchy \> Network Devices \> Webex Devices

###### Second, confirm that the radio button configuration is correct in Control Hub (**Devices** \> **Digital Signage** ), and that **WebGL** is enabled in **All Configurations** .

![Devices - Digital Signage - Cisco Spaces](https://runbooks.ciscospaces.io/__attachments/a_0c668ee25365063cd7a5f9b0c3d5248d349b6c8da849f3c4771d3318d7315745/Screenshot%202025-03-14%20at%2013.11.31.png?cb=6bb535f30848465bdb7fd31be1748226)
Devices \> Digital Signage \> Cisco Spaces

###### Third, try clearing the device cache via the **WebEngine** \> **DeleteStorage** \> **Type** \> **Signage** , following these steps:

(a) \[on the device page\] open the Actions menu (top right)

(b) select "Run xCommand"

(c) search for "WebEngine"

(d) select "DeleteStorage"

(e) click on "DeleteStorage" in the page

(f) choose "Signage" from the Type dropdown

(g) click "Execute"

(h) try disabling Digital Signage mode and then re-enabling  
![Webex Control Hub - Run xCommand - WebEngine - DeleteStorage - Type - Signage - Execute](https://runbooks.ciscospaces.io/__attachments/a_1b1210bd84f71463f3ed3bd7c83adeaacf4b0bd41b3736df09d7a232508b43be/Screenshot%202025-03-14%20at%2008.29.36.png?cb=472fe93cf3f0f9827c75a8f822babff6)
Webex Control Hub - Run xCommand \> WebEngine \> DeleteStorage \> Type \> Signage \> Execute

###### Finally, the device should appear on the list in **Space Experience** \> **Devices** \> **Webex Devices**

![Cisco Spaces - Space Experience - Devices - Webex Devices list view](https://runbooks.ciscospaces.io/__attachments/a_8458078b9c7bf6e7ab37350a9ba2980bc26c818f656f225964ee82e06380d78e/Screenshot%202025-03-14%20at%2012.30.57.png?cb=513468f76e27946f404c4821397a4a9d)
Cisco Spaces - Space Experience \> Devices \> Webex Devices list view

###### Additionally, if the troubleshooting workflow above does not work, you may need to clear the local storage and cache using the following URL (different per region) to fully reset the web application config.

These are mainly relevant to resetting the browser for a "Token URL"

(a) US and rest of world: `https://signage.dnaspaces.io/cleardevicestorage/clear.html?clear=true`

(b) EU: `https://signage.dnaspaces.eu/cleardevicestorage/clear.html?clear=true`

(c) SG: `https://signage.ciscospaces.sg/cleardevicestorage/clear.html?clear=true`  
![Clear Browser Storage screenshot](https://runbooks.ciscospaces.io/__attachments/a_8e419cb6694f09fda2da7c4cdba1b17f283b67dfdde3748ccaaf39648da67de4/Screenshot%202025-11-25%20at%2014.25.48.png?cb=26006f6288309f361fc4c1d9764e6208)

##### 2. If you are not able to configure a "Where am I?" character (i.e. "Spot" - the Cisco Spaces mascot) on a floor view.

Check whether the **Webex Device** (using the native Cisco Spaces Digital Signage mode in Control Hub) or **Non-Webex Device** (using the URL method) is correctly assigned to a specific floor in the Location Hierarchy. The floor assignment MUST be on the exact same floor that you want to position the "Where am I?" character.

Webex Device method, assign the device to a Location+Floor in Webex Control Hub, make sure it is merged correctly into the Cisco Spaces Location Hierarchy, and appears under **Location Hierarchy** \> **Network Devices** \> **Webex Devices**

Non-Webex Device/URL method, in the very first step after clicking **Add Signage**, click through the Location Hierarchy to choose a floor, NOT a location.  
![Screenshot 2025-03-14 at 13.36.56.png](https://runbooks.ciscospaces.io/__attachments/a_c8dc738401bcaea87bb699968411d5e49d16d3fe5e4a8a1c5f405701f9f0f5e2/Screenshot%202025-03-14%20at%2013.36.56.png?cb=1a21e83701e30d923a28ddf2b75e17b3)

*** ** * ** ***

## FAQ

### **How does the Space Explorer \> Signages setup workflow affect the Space Explorer - Kiosk app Building view?**

Building View scenarios in the table below (not exhaustive)  

|                                                                                                                                                                                                                                                                                                                                    **Scenario / Description**                                                                                                                                                                                                                                                                                                                                    |                                                                                                                                                                                  **Space Experience Configuration**                                                                                                                                                                                   |                                                                                                                                                                   **Space Explorer - Kiosk UI**                                                                                                                                                                   |
|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Step 2: Configure Widgets All widgets enabled The building and floor occupancy widgets are on a scale from 0-100% (if over 100% utilization the vertical bar chart will expand, but floors will be capped at 100%). Building and floor occupancy are identical to "Live Occupancy" dashboard app and are derived from wireless client counts relative to building and floor max capacity values in the Location Hierarchy metadata. Temperature, humidity, Indoor Air Quality (IAQ), CO₂, and Ambient Noise are aggregated at the building level and average across all devices providing each metric. The Point of Interest (POI) option refers to the Quick Access POI menu on the floor view. | ![Space Experience - Signages - Step 2 - Configure Widgets - All widgets enabled](https://runbooks.ciscospaces.io/__attachments/a_9635f4351564e4982452fc0a7ae812f3de380970f78c85abed780f69ccde3762/Screenshot%202025-03-25%20at%2014.10.44.png?cb=3474fc532480c19ac750979b0d757be7) Space Experience - Signages - Step 2 - Configure Widgets - All widgets enabled                                                                   | ![Space Explorer - Kiosk - Building View - All widgets enabled](https://runbooks.ciscospaces.io/__attachments/a_78ce559b480c1b1bbfda62b1d63fcc0369266fe2564784c5933c9395ad03efe6/Screenshot%202025-03-24%20at%2008.47.04.png?cb=bde14183b049251059a16f88e2f03113) Space Explorer - Kiosk - Building View - All widgets enabled                                                                   |
| Step 2: Configure Widgets Occupancy widget disabled Occupancy widget disabled will hide the vertical building occupancy graph and the individual floor percentages (note: the screenshot here does not correctly reflect hidden floor occupancy widgets).                                                                                                                                                                                                                                                                                                                                                                                                                                        | ![Space Experience - Signages - Step 2 - Configure Widgets - Occupancy widget disabled](https://runbooks.ciscospaces.io/__attachments/a_7970266f4835b398be8b8fa705e712c23277c907fb6ced010d162ab1409b48e2/Screenshot%202025-03-24%20at%2009.05.53.png?cb=56d3e1181452dee14b8797d3f9f2961d) Space Experience - Signages - Step 2 - Configure Widgets - Occupancy widget disabled                                                       | ![Space Explorer - Kiosk - Building View - Occupancy widget disabled](https://runbooks.ciscospaces.io/__attachments/a_e0d270fa6679057f1052ef031f55d8e5c243c1c795a658c178a7d2efb7239659/Screenshot%202025-03-24%20at%2009.00.05.png?cb=1a70b0f9b255d9343d58334d1c67ec07) Space Explorer - Kiosk - Building View - Occupancy widget disabled                                                       |
| Step 2: Configure Widgets Occupancy and air quality widgets disabled                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | ![Space Experience - Signages - Step 2 - Configure Widgets - Occupancy and air quality widgets disabled](https://runbooks.ciscospaces.io/__attachments/a_6e3c61e6a18590e5ee53e658bfa9225f756bd29c7e4f49f22c5f067aad342910/Screenshot%202025-03-24%20at%2009.06.02.png?cb=907f375e540550c16bc31f0c8fa73614) Space Experience - Signages - Step 2 - Configure Widgets - Occupancy and air quality widgets disabled                     | ![Space Explorer - Kiosk - Building View - Occupancy and air quality widgets disabled](https://runbooks.ciscospaces.io/__attachments/a_518ff9ac0ff326e7f8254715711043c5d1b4e48e8829bb28840dced7a2271af6/Screenshot%202025-03-24%20at%2009.02.48.png?cb=0e02d8281f45a401aeee165d39b70ab0) Space Explorer - Kiosk - Building View - Occupancy and air quality widgets disabled                     |
| Step 2: Configure Widgets Occupancy, air quality, and comfort widgets disabled                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | ![Space Experience - Signages - Step 2 - Configure Widgets - Occupancy, air quality, and comfort widgets disabled](https://runbooks.ciscospaces.io/__attachments/a_1604188dc1923d1d1b85483f0352c70785c0f53ba059646855476bc667e8fd73/Screenshot%202025-03-24%20at%2009.06.11.png?cb=7ca0ed48902a3ad7b84aa09a675a836e) Space Experience - Signages - Step 2 - Configure Widgets - Occupancy, air quality, and comfort widgets disabled | ![Space Explorer - Kiosk - Building View - Occupancy, air quality, and comfort widgets disabled](https://runbooks.ciscospaces.io/__attachments/a_5b26fedf407ab32b2253b0ca671ed1a324194f63d9ff290cbb2edb94101fd5cc/Screenshot%202025-03-24%20at%2009.04.04.png?cb=aa55f213fee16d728aaf9779e2fa1914) Space Explorer - Kiosk - Building View - Occupancy, air quality, and comfort widgets disabled |

#### **How does the Space Explorer \> Signages setup workflow affect the Space Explorer - Kiosk app Floor view?**

Floor View scenarios in the table below (not exhaustive)  

|                                                                                                                                                                                                                                                                                              **Scenario / Description**                                                                                                                                                                                                                                                                                               |                                                                                                                                                       **Space Experience Configuration**                                                                                                                                                        |                                                                                                                                                                **Space Explorer - Kiosk UI**                                                                                                                                                                |
|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Step 2: Configure Widgets All widgets enabled The floor occupancy widgets are on a scale from 0-100% (if over 100% utilization the floors will be capped at 100%). Floor occupancy are identical to "Live Occupancy" dashboard app and are derived from wireless client counts relative to floor max capacity values in the Location Hierarchy metadata. Temperature, humidity, Indoor Air Quality (IAQ), CO₂, and Ambient Noise are aggregated at the building level and average across all devices providing each metric. The Point of Interest (POI) option refers to the Quick Access POI menu on the floor view. | ![Space Experience - Signages - Step 2 - Configure Widgets - All widgets enabled](https://runbooks.ciscospaces.io/__attachments/a_9635f4351564e4982452fc0a7ae812f3de380970f78c85abed780f69ccde3762/Screenshot%202025-03-25%20at%2014.10.44.png?cb=3474fc532480c19ac750979b0d757be7) Space Experience - Signages - Step 2 - Configure Widgets - All widgets enabled             | ![Space Explorer - Kiosk - Floor View - All widgets enabled](https://runbooks.ciscospaces.io/__attachments/a_6b6c80aaa659cf9154d753f5dc344a375d025c9e7e618a80478d2b13429c99ab/Screenshot%202025-03-24%20at%2008.48.29.png?cb=eef6ea35a701c4f2f85765231527eddd) Space Explorer - Kiosk - Floor View - All widgets enabled                                                                   |
| Step 2: Configure Widgets Occupancy widget disabled                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | ![Space Experience - Signages - Step 2 - Configure Widgets - Occupancy widget disabled](https://runbooks.ciscospaces.io/__attachments/a_7970266f4835b398be8b8fa705e712c23277c907fb6ced010d162ab1409b48e2/Screenshot%202025-03-24%20at%2009.05.53.png?cb=56d3e1181452dee14b8797d3f9f2961d) Space Experience - Signages - Step 2 - Configure Widgets - Occupancy widget disabled | ![Space Explorer - Kiosk - Floor View - Occupancy widget disabled](https://runbooks.ciscospaces.io/__attachments/a_53281a9d806e2733bb943d1f30bd1637e1e79fe4f9e606fbf4556e29e7b34916/Screenshot%202025-03-24%20at%2009.00.19.png?cb=98cf8c54e0c3a82ee66ad2876b9e0070) Space Explorer - Kiosk - Floor View - Occupancy widget disabled                                                       |
| Step 2: Configure Widgets Occupancy and air quality widgets disabled                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | ![Space Experience - Signages - Step 2 - Configure Widgets - Occupancy and air quality widgets disabled](https://runbooks.ciscospaces.io/__attachments/a_6e3c61e6a18590e5ee53e658bfa9225f756bd29c7e4f49f22c5f067aad342910/Screenshot%202025-03-24%20at%2009.06.02.png?cb=907f375e540550c16bc31f0c8fa73614)                                                                     | ![Space Explorer - Kiosk - Floor View - Occupancy and air quality widgets disabled](https://runbooks.ciscospaces.io/__attachments/a_9277737ecaf22e7f5a5d3a18d7197ad271cbeb764422909477ad433a4ab4994b/Screenshot%202025-03-24%20at%2009.02.59.png?cb=c44a3c4bf68bb61c543095adc98526d5) Space Explorer - Kiosk - Floor View - Occupancy and air quality widgets disabled                     |
| Step 2: Configure Widgets Occupancy, air quality, and comfort widgets disabled                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | ![Space Experience - Signages - Step 2 - Configure Widgets - Occupancy, air quality, and comfort widgets disabled](https://runbooks.ciscospaces.io/__attachments/a_1604188dc1923d1d1b85483f0352c70785c0f53ba059646855476bc667e8fd73/Screenshot%202025-03-24%20at%2009.06.11.png?cb=7ca0ed48902a3ad7b84aa09a675a836e)                                                           | ![Space Explorer - Kiosk - Floor View - Occupancy, air quality, and comfort widgets disabled](https://runbooks.ciscospaces.io/__attachments/a_6dcc44835103954bfe17ee5e4a448d37ad61c501fd47b93310dd11587b4fdbda/Screenshot%202025-03-24%20at%2009.04.17.png?cb=741989de1d3e4dd0521e2b65fe8a0281) Space Explorer - Kiosk - Floor View - Occupancy, air quality, and comfort widgets disabled |
| Step 2: Configure Widgets All widgets disabled                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | ![Space Experience - Signages - Step 2 - Configure Widgets - All widgets disabled](https://runbooks.ciscospaces.io/__attachments/a_88689b83028d579ca1ff530aeb2455a548bd43d03b668262765080e8858c2d68/Screenshot%202025-03-24%20at%2009.06.20.png?cb=918f4568b2aa91a79561dc5843f65c3d)                                                                                           | ![Space Explorer - Kiosk - Floor View - All widgets disabled](https://runbooks.ciscospaces.io/__attachments/a_ccef23a30ea8a6e596847e1b4c78eea670f7df77cd82e73d7539f79b838ef89a/Screenshot%202025-03-24%20at%2009.05.27.png?cb=1f9c0b8bcae03bb79b77404601cda04e) Space Explorer - Kiosk - Floor View - All widgets disabled                                                                 |

##### **How does the Space Explorer \> Signages setup workflow affect the Space Explorer - Kiosk app Room Details popup?**

Room Details popup scenarios in the table below (not exhaustive)  

|                                                                                           **Scenario / Description**                                                                                            |                                                                                                                                                 **Space Experience Configuration**                                                                                                                                                  |                                                                                                                                                                        **Space Explorer - Kiosk UI**                                                                                                                                                                        |
|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Step 2: Configure Widgets All widgets enabled Disabling Occupancy widgets does not affect individual meeting room occupancy status. The room status setting can be managed in Space Manager in a future update. | ![Space Experience - Signages - Step 2 - Configure Widgets - All widgets enabled](https://runbooks.ciscospaces.io/__attachments/a_9635f4351564e4982452fc0a7ae812f3de380970f78c85abed780f69ccde3762/Screenshot%202025-03-25%20at%2014.10.44.png?cb=3474fc532480c19ac750979b0d757be7) Space Experience - Signages - Step 2 - Configure Widgets - All widgets enabled | ![Space Explorer - Kiosk - Room Details popup - All widgets enabled](https://runbooks.ciscospaces.io/__attachments/a_ce3c12ad8aa7139703c9807f7e0095336e0e3d6bb899d1bcf6255e4d97cfae47/Screenshot%202025-03-25%20at%2014.42.28.png?cb=ed56a01611f7656b7ad5b03667103c67) Space Explorer - Kiosk - Room Details popup - All widgets enabled                                                                   |
| Step 2: Configure Widgets Occupancy and air quality widgets disabled                                                                                                                                            | ![Space Experience - Signages - Step 2 - Configure Widgets - Occupancy and air quality widgets disabled](https://runbooks.ciscospaces.io/__attachments/a_6e3c61e6a18590e5ee53e658bfa9225f756bd29c7e4f49f22c5f067aad342910/Screenshot%202025-03-24%20at%2009.06.02.png?cb=907f375e540550c16bc31f0c8fa73614)                                                         | ![Space Explorer - Kiosk - Room Details popup - Occupancy and air quality widgets disabled](https://runbooks.ciscospaces.io/__attachments/a_f2e138405cc6e2ca2aac1b7a46582890486a7c9ab4817ce998b83c3312c1844c/Screenshot%202025-03-24%20at%2009.03.13.png?cb=31e3d618c07d35d410343f9d54ef4059) Space Explorer - Kiosk - Room Details popup - Occupancy and air quality widgets disabled                     |
| Step 2: Configure Widgets Occupancy, air quality, and comfort widgets disabled                                                                                                                                  | ![Space Experience - Signages - Step 2 - Configure Widgets - Occupancy, air quality, and comfort widgets disabled](https://runbooks.ciscospaces.io/__attachments/a_1604188dc1923d1d1b85483f0352c70785c0f53ba059646855476bc667e8fd73/Screenshot%202025-03-24%20at%2009.06.11.png?cb=7ca0ed48902a3ad7b84aa09a675a836e)                                               | ![Space Explorer - Kiosk - Room Details popup - Occupancy, air quality, and comfort widgets disabled](https://runbooks.ciscospaces.io/__attachments/a_ff576244793f1ff33bbe9934a6db0d3846962dbdc42ae3fc8a72491943408179/Screenshot%202025-03-24%20at%2009.04.29.png?cb=5c2efb0cc4f66c8362a9b8dc8e5e9664) Space Explorer - Kiosk - Room Details popup - Occupancy, air quality, and comfort widgets disabled |

---
language: "en"
---
# Counting People from Meraki Video (MV) Cameras

Currently there are limited use cases supported in Cisco Spaces for Meraki Video (MV) cameras. This article will walk through that limited beta functionality until fully validated and supported.

## Pre-Requisites \& Setup

[Documentation](https://documentation.meraki.com/MV)

**Must Read:**

* [MV Presence Analytics](https://documentation.meraki.com/MV/Video_Analytics/MV_Presence_Analytics)

Cisco Spaces relies on the line crossing analytics feature (camera tripwires).

Gen3 cameras **highly recommended**.  
**Tip:** Please ensure proper camera placement (angle, height, orientation) and pay attention to occlusion sources such as doors that open through tripwires or do not provide adequate visibility of people ***before*** and ***after*** crossing the tripwire line. Additional guidance provided in the **Must Read** documentation above.  
**Note:** Meraki Dashboard only supports one MQTT Broker at a time. Cisco Spaces relies on the MQTT integration for camera line crossing analytics, so any other MQTT integrations will be disabled while sending telemetry to Cisco Spaces.

## Location Hierarchy

When an MV camera is added to a Meraki Org \> Network \> Floor Plan, this syncs to Cisco Spaces Dashboard in a Group \> Location \> Floor structure when merged into the Location Hierarchy. Cameras can be included at the Network or Floor Plan (i.e. placed on the network floor plan) level on the Meraki Dashboard in order to contribute to people counting in Cisco Spaces.  

| **Meraki Dashboard** |  **Cisco Spaces**   |
|----------------------|---------------------|
| Org                  | Group / Campus      |
| Network              | Location / Building |
| Floor Plan           | Floor               |

### Other Levels of the Location Hierarchy

Cisco Spaces does not support other levels of the Location Hierarchy at this time. For example, counting people at the floor, zone/area, room level, and desk level are not supported use cases.

## Counting People

Cisco Spaces aggregates all camera tripwire crossing (entry/exit) across the entire building.  
**Note:** Cisco Spaces aggregates ALL camera tripwires across a single Meraki Network (i.e. any cameras at the Network or Floor Plan levels). If tripwires are setup in the same Network that are not intended for Location/Building level people counting in Cisco Spaces, then they will get aggregated along with the in-scope cameras.

### Simple People Counting

In a simple scenario, a building might have all entry/exit points on a single floor. For example, on the ground floor, there may be a front lobby, fire exits, service entrance(s), etc. In this scenario, all cameras would be placed on the Network's ground floor Floor Plan in Meraki Dashboard. Each camera would most likely have a single tripwire.  
![First Floor Only - Entrances and Exits](https://runbooks.ciscospaces.io/__attachments/a_aac445739d63b98ce76a5467fc273f06fe696c5f121d4a373fb8ccb71d92d250/Ground%20Floor%20Entries%20and%20Exits.png?cb=72dfd02f27953e1189910443b52a8125)
First Floor Only - Entrances and Exits

In the example Ground Floor floorplan above, notice how all entrances and exits are on the outer walls of the building.

### Complex People Counting

#### Building Tenant with Landlord Owned Lobby

In a tenant scenario, it may not be possible to place MV cameras in a common area owned and operated by the landlord of the building. Every external facing entrance **must** be covered with camera tripwires. These entrances may be each elevator bank on every floor occupied by the tenant, or the stairwell entrances on every floor (even if they provide only one-way access - e.g. exit-only).  
![Second Floor of Landlord Owned Lobby Building.png](https://runbooks.ciscospaces.io/__attachments/a_ea76918f9c4efd8960c3a5d6f6834139bd714c7b2e0b7e5765519d46aa213d2b/Second%20Floor%20of%20Landlord%20Owned%20Lobby%20Building.png?cb=d0abd408d9505e6b33649da4e86bf66e)
Second Floor of Landlord Owned Lobby Building  
![Third Floor of Landlord Owned Lobby Building.png](https://runbooks.ciscospaces.io/__attachments/a_735d33cfc5e224a66911a4a3737fd61137197af150c4e9ccbbffba47107e7f1e/Third%20Floor%20of%20Landlord%20Owned%20Lobby%20Building.png?cb=30e52fb44acea058d9242637d4023a83)
Third Floor of Landlord Owned Lobby Building

In the example Second and Third Floor floorplans above, notice how entrances and exists are only covered on interior spaces such as elevator bank outer doors and stairwells. In this example, stairs are emergency exits only and would eventually exit outside the building at the lowest floor, but people can come and go via the elevators to the lobby and other floors.

#### Parking Garage

Sometimes, not always, a parking garage may have a separate entrance to a building (e.g. basement, connected via skybridge to a particular floor, etc.) that allows access to an elevator shaft or stairwell with direct access to all floors in the building. These elevator and stair entrances need their own camera tripwires drawn. In this complex scenario, if a garage entrance (or something similar) cannot be covered with a camera, then every interior entrance on **all** floors **must** be covered with cameras, much like the Building Tenant with Landlord Owned Lobby example above.

---
language: "en"
---
# Counting People from Wi-Fi

Deduplication is the essential process that Spaces uses to calculate people presence within a space, by counting Wi‑Fi devices. Since most individuals carry multiple Wi‑Fi‑enabled devices---such as smartphones, tablets, or laptops---the raw device count will not be representative of the number of people within a Space. The ratio between people and devices is an ever changing metric, which is why Spaces leverages a couple of key mechanisms to make people counting as accurate as possible.

## **Choosing the Right Deduplication Mechanism**

Within Spaces today, we have 3 key mechanisms for deduplicating. Usability of these features will depend on a few factors, such as the type of certs or usernames onboarded, use of SSIDs, and whether hashing has been enabled on the Spaces Connector. The appropriate mechanism depends on the combination of these factors.

### Deduplication Mechanisms Flow Chart

This flow chart references the same data as below, but allows you to follow a flow chart format to decide which mechanism is right and available for your deployment.  
![Flowcharts (1).png](https://runbooks.ciscospaces.io/__attachments/a_8fd5cdea615260fdc9b0d83583f30498688cc3791a990fe656cab805f078c8ae/Flowcharts%20(1).png?cb=4ecf8267020a410a5e5fbed40034c7a8)

To understand each of the elements in this flow chart, continue to read on for the deduplication factors.

### **Deduplication Factors**

This section will cover all of the factors that impact which mechanism of deduplication we can use, or whether deduplication is possible.

#### **Username makeup**

This is whether there is a user tied to the 802.1X username, or not. For example, a username of 'jdoe@cisco.com', is attribute to a user. This is generally known as a user certificate and is commonly associated with PEAP/MSCHAPv2 username/password logins. This is relevant to deduplication, as Spaces can simply count the number of users we see. In this document, this will be known as '***Person in Username***'.

If we have a device tied to the username field, this makes it slightly more complex to count users. This is most common with 802.1X setups that use host certs, which means authenticating the device to the network rather than the user on that device. In this document, this will be known as '***Device in Username*** *'.*

Finally, if we don't have usernames in Spaces at all, we have an even more challenging environment for people counting. This is most common on networks that have captive portals, PSK authentication, or no authentication at all. In this instance, we are relying on simply knowing the MAC of a device, rather than any extra information about it. In this document, this will be known as '***No Username***'.

#### **SSID Makeup**

When counting devices as a proxy for users, the makeup of SSIDs is very important. With this instance in deduplication, we have to find a way to identify (most commonly) laptops, and count them as a proxy for users, as there will be a near perfect mapping between number of laptops, and number of users. A very easy way to do this, is to have all laptops on a single SSID, such as a cert based SSID, and everything else being on guest or BYOD. In this document, this will be known as '***Single User SSID***'.

If there is no clear SSID to count laptops on, a REGEX filter must be implemented to identify laptops on the SSID. This means, we need a clear way to identify what a laptop cert looks like, such as a prefix or suffix that is on every laptop cert. In this document, this will be known as '***No Single User SSID***'.

#### **Connector Hashing**

Connector hashing is only available for Catalyst deployments

Due to some of the filtering we have to do to identify laptops in the cases above, some methods of deduplication are not supported when hashing is enabled. The most simple way to check if hashing is enabled, is to select a client within Detect and Locate, and see if you can see the username, MAC, or IP of the client. If you cannot, and instead it says 'hashed', that location has hashing enabled. Throughout this document, it is called out whether mechanisms are compatible with hashing or not.

### Deduplication Mechanism Compatibility Matrix

This section is designed to help decide which mechanism of deduplication is right for your deployment.
Hashing Disabled (most common)  
**Hashing Disabled**  

|                        |      **Single User SSID**      |      **No Single User SSID**      |
|------------------------|--------------------------------|-----------------------------------|
| **Person in Username** | Count Unique User IDs          | Count Unique User IDs             |
| **Device in Username** | Counting Proxy Devices On SSID | Counting Proxy Devices with REGEX |
| **No Username**        | Counting Proxy Devices On SSID | Deduplication is not possible     |

Counting Proxy Devices with REGEX, is only possible if there is a clear format difference in the device identifier, between laptops and other devices.
Hashing Enabled  
**Hashing Enabled**  

|             ***Hashing On***              |      **Single User SSID**      |    **No Single User SSID**    |
|-------------------------------------------|--------------------------------|-------------------------------|
| **Person in username (E.G. User Cert)**   | Count Unique User IDs          | Count Unique User IDs         |
| **Device in username (E.G. Device Cert)** | Counting Proxy Devices On SSID | Deduplication is not possible |
| **No Username**                           | Counting Proxy Devices On SSID | Deduplication is not possible |

*** ** * ** ***

## **Understanding and Configuring Deduplication Mechanisms**

This section is designed to help fully understand how your **chosen** deduplication mechansim works, and how to configure. If you have not yet decided on your mechanism, reference the above section - *Choosing the Right Deduplication Mechanism.*
Counting Unique User IDs  

### **Counting Unique User IDs**

This is the most common method, relying on consistent usernames (e.g. certificates or directory-based identities). It deduplicates users based on their unique identity, across multiple devices.

Effective Username Example:

* Device 1: [jdoe@company.com](mailto:jdoe@company.com)

* Device 2: [jdoe@company.com](mailto:jdoe@company.com)

  *→ Counted as 1 user*

Ineffective Username Examples:

* Device 1: [jdoe@company.com](mailto:jdoe@company.com), Device 2: [jd@company.com](mailto:jd@company.com)

* Device 1: [jdoe@company.com](mailto:jdoe@company.com), Device 2: [HOST-1235@company.com](mailto:HOST-1235@company.com)

  *→ Both examples counted as 2 users due to inconsistency*

*Example Table (Raw Usernames):*  

|  **MAC Address**  | **IP Address** | **Username** |
|-------------------|----------------|--------------|
| 3C:52:82:A1:6B:7D | 10.10.10.12    | jdoe         |
| 00:1A:2B:3C:4D:5E | 10.10.14.90    | jdoe         |
| B8:27:EB:3F:96:2C | 10.10.12.88    | asmith       |

→ Unique users counted: 2

*Example Table (Hashed Usernames):*  

|  **MAC Address**  | **IP Address** | **Hashed Username** |
|-------------------|----------------|---------------------|
| 3C:52:82:A1:6B:7D | 10.10.10.12    | 7b8e81ce82          |
| 00:1A:2B:3C:4D:5E | 10.10.14.90    | 7b8e81ce82          |
| B8:27:EB:3F:96:2C | 10.10.12.88    | 49c3e6ac65          |

→ Unique users counted: 2, even though identities are not visible due to hashing, unique count is still the same.

**Configuration**  
![image-20250908-100025.png](https://runbooks.ciscospaces.io/__attachments/a_b7a5fdf25f7b5063d3c9ca3a6c5ebaeaed327b9dbf80fa8dd402e420cf2b6868/image-20250908-100025.png?cb=a00dce4dbddea8a93d46edac0491cea4)

1. Log into Cisco Spaces and navigate to **Right Now** \> **Settings**.

2. Select the blue pencil next to excluded SSIDs from Right Now analytics.

3. Select all SSIDs that employees do not connect to.

4. Click **Save**.

Counting Proxy Devices On SSID  

### **Counting Proxy Devices On SSID**

In environments where every user is assigned a unique device (e.g., a company-issued laptop), counting devices can serve as a good approximation of user occupancy. We can call these devices proxy devices, as they act as a proxy for users.

* Count only devices connecting to a specific SSID (e.g., corporate laptops on CorpNet)

* Filtering is handled via Spaces UI (Right Now \> Settings)

* Supports hashing

*Example Table*

*Corporate SSID Devices:*  

|  **MAC Address**  | **IP Address** | **Username**  |
|-------------------|----------------|---------------|
| 3C:52:82:A1:6B:7D | 10.10.10.12    | LAPTOP-jdoe   |
| B8:27:EB:3F:96:2C | 10.10.12.88    | LAPTOP-asmith |

*Guest/BYOD Devices (excluded):*  

|  **MAC Address**  | **IP Address** | **Username** |
|-------------------|----------------|--------------|
| 5A:1C:8E:2F:71:AA | 10.10.5.14     | iphone-jane  |
| 30:E1:7A:55:B3:19 | 10.10.6.250    | guest-laptop |

→ Only corporate SSID devices are counted → 2 users

**Configuration**  
![image-20250908-100025.png](https://runbooks.ciscospaces.io/__attachments/a_b7a5fdf25f7b5063d3c9ca3a6c5ebaeaed327b9dbf80fa8dd402e420cf2b6868/image-20250908-100025.png?cb=a00dce4dbddea8a93d46edac0491cea4)

1. Log into Cisco Spaces and navigate to **Right Now** \> **Settings**.

2. Select the blue pencil next to excluded SSIDs from Right Now analytics.

3. Select all SSIDs that employees do not connect to.

4. Click **Save**.

Counting Proxy Devices with REGEX  

### **Counting Proxy Devices with REGEX**

* Devices are identified using a REGEX pattern (e.g. \^LAPTOP-\[a-z0-9\]+$)

* Requires un-hashed data

* Implemented via backend configuration in Spaces

*Example Table:*  

|  **MAC Address**  | **IP Address** |  **Username**   |
|-------------------|----------------|-----------------|
| 3C:52:82:A1:6B:7D | 10.10.10.12    | LAPTOP-jdoe     |
| D8:6F:4C:32:9E:01 | 10.10.3.102    | emma-tablet     |
| A4:5E:60:3E:7F:99 | 10.10.13.12    | LAPTOP-denadams |

→ Using REGEX, 2 users are counted (devices starting with "LAPTOP-")  
This method **does not** support hashing due to the need to evaluate readable usernames.

**Configuration**  
![image-20250908-100025.png](https://runbooks.ciscospaces.io/__attachments/a_b7a5fdf25f7b5063d3c9ca3a6c5ebaeaed327b9dbf80fa8dd402e420cf2b6868/image-20250908-100025.png?cb=a00dce4dbddea8a93d46edac0491cea4)

1. Log into Cisco Spaces and navigate to **Right Now** \> **Settings**.

2. Select the blue pencil next to excluded SSIDs from Right Now analytics.

3. Select all SSIDs that employees do not connect to.

4. Click **Save**.

After configuring Right Now Settings, you must follow the next steps. This is process differs from other setups.

Now right now is complete, please raise a support case with the filter you would like to apply, to count devices as outlined above. Details should include:

*Filter needed to apply (ideally in REGEX, but natural language is also great, such as "anything ending in @cisco.com)*

*Include or Exclude filter - do you want to include anything with that matches your filter or exclude.*

Filter must have a minimum of 3 characters to provide enough accuracy. A filter such as "anything starting with an underscore will result in poor results.

*Filters can be coupled up with others, with AND or OR operators. For example "Anyone with with USER/ and ends in @cisco.com OR any user that ends in @meraki.net"*

*** ** * ** ***

## FAQ

**How accurate is people counting with Cisco Spaces?**

Accuracy is entirely dependent on how rigorous your filtering and cert setup is. There is possibilities to get near 100% accuracy, but there will always be edge cases of users who dont carry a device, or who log into device centric SSIDs like guests.

**Which apps will changing people count settings impact?**

The settings configured in Right Now, will impact the following apps:

* Right Now

* Behaviour Metrics

* Space Utilization

**Does changing people count settings effect data from collaboration or IOT devices?**

No, people counting settings configured in Right Now will only impact data coming from Wi-Fi

**My users don't use .1x and I have no way to identify users any other way, how do I get accurate people counting?**

Unfortunately, there will be no way for us to recognize individual users without this. Instead, you should consider other mechanisms, such as cameras or tripwire sensors, to count users.

---
language: "en"
---
# Digital Map Pro and CAD/DWG/PDF Best Practices

## OVERVIEW

![Screenshot 2025-04-11 at 18.31.07.png](https://runbooks.ciscospaces.io/__attachments/a_67c3ad82ae852daaafb471028a0899a80ec2c635465a40d8e926be7a187b6337/Screenshot%202025-04-11%20at%2018.31.07.png?cb=fe489e0ba48ea288a13affdeb88e5f5e)
What makes a good CAD file for Smart Workspaces?

### CAD File Overview

There are **3 main elements** for a great CAD file (.dwg) or Vector PDF:

1. **Architectural layers** (e.g. walls, doors, stairs, windows, etc.)

2. **Furniture layer**

3. **Space names / IDs / labels**

### CAD File Best Practices

* Spaces (Space Type) marked clearly, or detail provided. For example, a space with a collaboration endpoint will need a room or desk to assign it to.

* Have **clearly defined or marked POIs** like stairs, bathrooms, elevators etc.

* Provide **room names** in the CAD file or give the right identifiers that you would like the rooms to be labeled. Sometimes, a CAD or Vector PDF file can have multiple such identifiers for the same room. In this case, please leave a comment in the upload workflow with which identifier should be used as a name for the spaces.

* Provide clear **layer names** in CAD. For example: "A-Furn" (furniture), "Doors" (for doors), "Windows" (for windows), etc.

* Keep elements in **separate layers**. Example: walls, doors, labels in their own layers.

* **Cross Reference (XREF) layers will not be processed.** You must "Bind" them into a single .dwg when exporting from AutoCAD or another program.

* Add/remove **Hatch Patterns** from rooms to block out / show specific areas of the map. Hatched areas will be given 100% wall height in the 3D styling and metadata in the area will not be processed.

*** ** * ** ***

## SPACE TYPES

### Overview

There are concepts to understand when setting up and configuring Cisco Spaces AI Digital Maps that have implications throughout the platform. To establish a consistent ontology/terminology, please refer to the terms below:

* **Space Type** - finite, structured list of categories of spaces/rooms/bounded areas, for grouping many of these into consistent types. Different locales/regions/companies have different terms for each of these, but the concept for each space type should be somewhat universal when accounting for synonyms. End users do not usually think in terms of Space Types, except through the lens of any UI. Search in this field should surface results based on a synonym list per type. Great for filtering and grouping.

* **Space Name** - additional context, typically unique and how end users usually perceive the various spaces. Great for end user search, labels, etc. A Space Name can be identical to a Space ID, for example, a desk ID.

* **Space ID** - typically permanent identifiers. Great for machine-to-machine matching. Not usually useful to end users or admins in many cases.

User Interfaces:

1. **Digital Map Editor** - under **Setup** \> **Locations \& Maps** \> **Digital Maps** \> **View/edit maps**, admins edit space types, names, and IDs

2. **Space Manager** app - admins manage and connect sensors to specific Space Types (e.g. Meeting Rooms can connect to Webex Workspaces and IoT Sensors, Workstations can only connect Webex Workspaces, and other Space Types cannot currently be managed and are only certain Space Types are visible on maps - learn more: [Other Space Types](https://runbooks.ciscospaces.io/docs/digital-map-pro-and-cad-dwg-pdf-best-practices#DigitalMapProandCAD/DWG/PDFBestPractices-OtherSpaceTypes))

3. **Space Explorer Kiosk \& Web App** - end users search or visually scan for various Space Types based on icons, labels, or tapping on most spaces (each UI can be slightly different). The UI can utilize filters, search fields, icons, etc. to differentiate Spaces Types and allow end users to interact with them.

Importantly, each of the choices in UIs #1-3 determines what is shown in #3. This is fairly rigid by design to maintain consistency (while flexibility is possible over time and depending on the verticals and personas of end users). Any result is usually attainable by utilizing the existing rules. Generally, a calendar bookable, short term use, and shared space would be Space Type = Meeting Room. Similarly, a bookable personal use space for extended times would be Space Type = Workstation.

#### Meeting Rooms

Meeting Rooms are an essential space types for assigning Webex Workspaces and IoT Sensors in order to associate telemetry such as People Count, Presence, Temperature, Humidity, Carbon Dioxide (CO₂), Indoor Air Quality (IAQ), TVOC, PM2.5, Ambient Noise, etc. Meeting Rooms can also have a calendar assigned.

Meeting Rooms play a key role in end user and admin dashboard applications such as Space Explorer Kiosk \& Web App, Indoor Navigation / Wayfinding, Space Manager, Space Utilization, Environmental Analytics, etc.

For managing Meeting Rooms, use **Space Manager** \> **Manage Rooms**

#### CAD File Best Practices for Meeting Rooms

1. Outlines are not necessary, but helpful, for Meeting Room types in the CAD file produce easily identifiable spaces.

![CAD (.dwg) space outlines](https://runbooks.ciscospaces.io/__attachments/a_72ab365edc5b566cd943515d6ba1075198bf1670c6b4944d845ed074d54b78e3/Screenshot%202025-04-14%20at%2011.19.18.png?cb=876e54ee481f099f966aa02909a3b49a)
CAD (.dwg) space outlines

2. Meeting Room Names and/or IDs **must** be included in the CAD file layers.

![CAD (.dwg) Meeting Rooms without Name or ID](https://runbooks.ciscospaces.io/__attachments/a_44dd160e382ee7f4417c5e6b999835e378d3557e6f416072aa52280822659815/Screenshot%202025-04-14%20at%2011.19.56.png?cb=9fb84766be5c1076eb968411e6223eeb)
CAD (.dwg) Meeting Rooms without Name or ID

3. Meeting Room furniture is **highly recommended**.

![CAD (.dwg) Meeting Room without furniture](https://runbooks.ciscospaces.io/__attachments/a_dd03a23aaa311a175998123fe503be939c5d99b0728ad01f44bdd2aa755b1ee8/Screenshot%202025-04-14%20at%2011.20.17.png?cb=c3bc7152e4ce78fc2f8c4c2b8ddecacb)
CAD (.dwg) Meeting Room without furniture

### Workstations / Desks

Workstations expand on the special space types with assignable Webex Workspaces and IoT Sensors. A limited amount of telemetry (e.g. login status, Presence) is available for Workstations as compared to Meeting Rooms. A calendar cannot be assigned to a Workstation, but certain applications such as Space Explorer Kiosk \& Web App do have a proprietary Cisco Spaces calendar automatically available as part of the Smart Desking solution.

For managing Workstations, use **Space Manager** \> **Manage Desks**

#### CAD File Best Practices for Workstations

1. Outlines for Workstation types in the CAD file produce easily identifiable spaces.

![CAD (.dwg) space outlines](https://runbooks.ciscospaces.io/__attachments/a_c5ec10267682ce57ef35ea5389f3a39e0ea8ba28aac6a67640961d6ba8223255/Screenshot%202025-04-11%20at%2018.01.50.png?cb=33dad4a484a46e28dd7f33febf1a5312)
CAD (.dwg) space outlines

2. Workstation/Desk IDs (or names) **must** be included in the CAD file layers.

![CAD (.dwg) Workstation ID or name](https://runbooks.ciscospaces.io/__attachments/a_3df9a8e3c55a0fd2f66abfaa0bd9dec983a7d0c5c783b0dc20d4ba8cf3bf1a7a/Screenshot%202025-04-11%20at%2018.08.11.png?cb=d83662e4eb4bac3e17e0acb4b74e78fc)
CAD (.dwg) Workstation ID or name

3. Workstation furniture is **highly recommended**.  
![CAD (.dwg) Workstation furniture](https://runbooks.ciscospaces.io/__attachments/a_533691750fa5a42c69bf30a07c0bd5c4b11534fb0240d5643c09652ef23c58ff/Screenshot%202025-04-11%20at%2018.02.20.png?cb=444a6029973d17c46212bcaebf6e737a)
CAD (.dwg) Workstation furniture

4. **No outlines and IDs/names will result in no editable workstations** in the Digital Map Editor. They cannot be turned into bookable desks.

![CAD (.dwg) without outlines, IDs, or names](https://runbooks.ciscospaces.io/__attachments/a_2d4182949af0ddbf73c5df163866d2e5edc8422b9617318d5e220d9cc89158ff/Screenshot%202025-04-11%20at%2018.03.23.png?cb=a54e2e9308fbf55d35ac280aeead5f67)
CAD (.dwg) without outlines, IDs, or names

5. **Do NOT include employee names in the CAD file if you do not want them to be processed by the AI and visible in the Digital Map Editor and other applications.**

![CAD File - Employee Names Visible](https://runbooks.ciscospaces.io/__attachments/a_416ce6e49eed02ad9ccb1bb32cae19146246b7a068387c1cc7c3427e58403ebe/Screenshot%202025-04-16%20at%2008.45.28.png?cb=cdef8c9e8d0ac332dd94b1db9ed75dc4)
CAD File - Employee Names Visible  
![Digital Map Editor - Employee Names Visible](https://runbooks.ciscospaces.io/__attachments/a_be031a7d76ebd3878007de75c39a3fb85f10c3a7c357d9b03d6cf8e71e16d276/clipboard-20260629-145003.png?cb=c629f92de1a2f0d0aa0b02b619d7ea5b)
Digital Map Editor - Employee Names Visible

### Other Space Types

Other spaces types besides the main two (Meeting Rooms \& Workstations) have limited functionality throughout Cisco Spaces solutions.

Examples of other space type support:

* Space Explorer Kiosk App - other space types may have an icon marker and they are searchable

* Space Explorer Web App - other spaces types may have an icon marker

* Space Explorer Indoor Navigation iOS App Clip - other space types are searchable and can be navigated to

Examples of other space types **not** being supported:

* Space Manager - cannot manage other space types and assign sensors or devices

* Space Utilization - cannot measure occupancy of other space types

* Environmental Analytics - cannot assign sensors or devices to other space types to measure environmental data (note: sensors attached to the floor are included, but they will not be aggregated at the room level, only the individual sensor)

* Space Explorer Kiosk App - cannot visualize sensor data in other spaces types

* Space Explorer Web App - cannot book, search, visualize occupancy data, or click on other space types

#### Space Explorer Kiosk App -- Quick Access Types

Cisco Spaces Digital Maps space types and styling may change with application updates. Refer back here for updates, but applications may be updated before this document. Always refer to the product UI over this document.  
![Space Explorer Kiosk App - Quick Access Types - On This Floor Legend](https://runbooks.ciscospaces.io/__attachments/a_bfc50b5ddae2959ecb1049bc19a5bdc0abaed3c23f1574cfa1b5da4a65b93cd5/Screenshot%202025-05-21%20at%2008.03.36.png?cb=95b6b85c49c4d1c9b0d89935e3cc60a0)
Space Explorer Kiosk App v2.0 and earlier -- Quick Access Types (On This Floor Legend)

Supported types in the **Digital Map Editor** , under **Setup** \> **Locations \& Maps** \> **Digital Maps** \> **View/Edit**, which will appear in the Space Explorer Kiosk App as a quickly accessible / highlightable type and with special icons.

Space types **cannot** be switched between header sections (e.g. Office Space, Others). One exception: "Unknown" can be changed to any space type, but once saved cannot be changed between header sections.

##### Office Space

|                                                                                        **Space Type**                                                                                         | **Quick Access Type** | **Special Styling (e.g. icon)** | **Searchable Space Name** |
|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------|---------------------------------|---------------------------|
| Workstation ![warning](https://runbooks.ciscospaces.io/__attachments/a_f1835336a35bbcd963e042c7109c79d927f866308c397a108ec509da2761721f/atlassian-warning?cb=14432459925d605e05cae2605cdfe666) \[important type for desks\]  | ❌                     | ✅ \[icon only\]                 | ❌                         |
| Meeting Room ![warning](https://runbooks.ciscospaces.io/__attachments/a_f1835336a35bbcd963e042c7109c79d927f866308c397a108ec509da2761721f/atlassian-warning?cb=14432459925d605e05cae2605cdfe666) \[important type for rooms\] | ❌                     | ✅ \[name tooltip\]              | ✅                         |
| Reception                                                                                                                                                                                     | ❌                     | ❌                               | ❌                         |
| Support Space                                                                                                                                                                                 | ❌                     | ❌                               | ❌                         |
| Cafeteria                                                                                                                                                                                     | ✅                     | ✅ \[icon only\]                 | ✅                         |
| Gym                                                                                                                                                                                           | ❌                     | ❌                               | ❌                         |
| Child Care Area                                                                                                                                                                               | ✅                     | ✅ \[icon only\]                 | ✅                         |
| Emergency Assembly Point                                                                                                                                                                      | ❌                     | ❌                               | ❌                         |
| Entertainment                                                                                                                                                                                 | ❌                     | ❌                               | ❌                         |
| Help Desk                                                                                                                                                                                     | ✅                     | ✅ \[icon only\]                 | ✅                         |
| Laboratory                                                                                                                                                                                    | ❌                     | ❌                               | ❌                         |
| Medical                                                                                                                                                                                       | ❌                     | ❌                               | ❌                         |
| Showers                                                                                                                                                                                       | ❌                     | ❌                               | ❌                         |
| Storage                                                                                                                                                                                       | ❌                     | ❌                               | ❌                         |
| Restroom                                                                                                                                                                                      | ✅                     | ✅ \[icon only\]                 | ✅                         |

##### Healthcare - Rooms

|       **Space Type**        | **Quick Access Type** | **Special Styling (e.g. icon)** | **Searchable Space Name** |
|-----------------------------|-----------------------|---------------------------------|---------------------------|
| Blood Draw                  |                       |                                 |                           |
| Decontamination Unit        |                       |                                 |                           |
| Dispensary                  |                       |                                 |                           |
| Environmental Services Unit |                       |                                 |                           |
| Examination Room            |                       |                                 |                           |
| Imaging Unit                |                       |                                 |                           |
| Laboratory                  |                       |                                 |                           |
| Neurology                   |                       |                                 |                           |
| Nurse Station               |                       |                                 |                           |
| On Call Room                |                       |                                 |                           |
| Patient Room                |                       |                                 |                           |
| Pharmacy                    |                       |                                 |                           |
| Preparation Room            |                       |                                 |                           |
| Trauma Kit                  |                       |                                 |                           |
| Treatment Room              |                       |                                 |                           |
| Triage                      |                       |                                 |                           |
| Vacancy                     |                       |                                 |                           |

##### Others

|                                                                                         **Space Type**                                                                                          | **Quick Access Type** | **Special Styling (e.g. icon)** | **Searchable Name** |
|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------|---------------------------------|---------------------|
| Circulation                                                                                                                                                                                     | ❌                     | ❌                               | ❌                   |
| Elevator ![warning](https://runbooks.ciscospaces.io/__attachments/a_f1835336a35bbcd963e042c7109c79d927f866308c397a108ec509da2761721f/atlassian-warning?cb=14432459925d605e05cae2605cdfe666) \[important type for wayfinding\]  | ✅                     | ✅ \[icon only\]                 | ✅                   |
| Stairs ![warning](https://runbooks.ciscospaces.io/__attachments/a_f1835336a35bbcd963e042c7109c79d927f866308c397a108ec509da2761721f/atlassian-warning?cb=14432459925d605e05cae2605cdfe666) \[important type for wayfinding\]    | ✅                     | ✅ \[icon only\]                 | ✅                   |
| Escalator ![warning](https://runbooks.ciscospaces.io/__attachments/a_f1835336a35bbcd963e042c7109c79d927f866308c397a108ec509da2761721f/atlassian-warning?cb=14432459925d605e05cae2605cdfe666) \[important type for wayfinding\] | ❌                     | ❌                               | ❌                   |

##### Unknown

When the type was not recognized or could not be categorized by the Digital Map Artificial Intelligence (AI), then it will be marked as "unknown" and appear invisible, as in no styling is applied and other types or the world map underneath that space will show through.

## Digital Map Editor Screenshots

![Digital Map Editor - hover state over POIs](https://runbooks.ciscospaces.io/__attachments/a_634faf476b782389b6cf2e7e6960a0ce40edcb6209f3d4aa6f04340400a66663/clipboard-20260629-144539.png?cb=9af67cf3c3327afe5a79337126ceb42f)
Digital Map Editor - hover state over POIs  
![Digital Map Editor - Modify Map Popover](https://runbooks.ciscospaces.io/__attachments/a_8168ce30ecfd6aea498eabf3862c6c4e8afd9863ee8a278ef5aaa3bc177d4941/clipboard-20260629-144934.png?cb=583189440d0938fc0dac17d6f3c802c2)
Digital Map Editor - Modify Map Popover  
![Digital Map Editor - Office Space Types](https://runbooks.ciscospaces.io/__attachments/a_db75974a33fde32f4f18d13cd2d808f73ac9e08b6c4378409946eaeaa5f89f72/clipboard-20260629-144941.png?cb=73bb1b2dc495aac3028bf057c3ac45ca)
Digital Map Editor - Office Space Types  
![Digital Map Editor - Healthcare - Rooms](https://runbooks.ciscospaces.io/__attachments/a_4d52ffdaa275fb90ad94e3fde1187841f1eef005c2ee27f4b815ae836c031855/clipboard-20260629-144948.png?cb=d9c6a13656fb090c5c779415ae9506b7)
Digital Map Editor - Healthcare - Rooms Types  
![Digital Map Editor - Others Types](https://runbooks.ciscospaces.io/__attachments/a_7bd2d326653f7aebbf88fe5902560cd6fe855babc1adcc383a6bc60548d8d9eb/clipboard-20260629-144956.png?cb=7f8e47c7c12547a243d06e1020754de0)
Digital Map Editor - Others Types

![Digital Map Editor - Unknown Type](https://runbooks.ciscospaces.io/__attachments/a_670028f7ab5afb3ec61a686d4b48469cb4ea377b918b5d295141357dffb67091/Screenshot%202025-05-21%20at%2008.19.21.png?cb=e9c539727489afa4e9e7c80b4e63c221)
Digital Map Editor - Unknown Type

## Wayfinding Custom POI and Path Editor - Early Preview (August 2025)

The **Space Experience** app on the Cisco Spaces Dashboard is for admins to deliver and manage workplace experience outcomes through Cisco Spaces. Admins will have more control over delivering **Pathfinding** on the **Space Explorer Kiosk** app (e.g. lobby TV or touch display) and with the *Spaces Premier for Wireless* licensing blue-dot, turn-by-turn **Wayfinding** via iOS App Clip and Android Google Play app.

Learn more about deploying Indoor Navigation here: <https://runbooks.ciscospaces.io/docs/cisco-spaces-indoor-navigation-runbook-cisco-valid>

This preview explains the high level concepts and common use cases for adding and editing Custom POIs and Paths in the upcoming **Space Experience** \> **Wayfinding** section of the Cisco Spaces Dashboard.  
**Note:** The design and Custom POI options may change before production release.
<https://app.vidcast.io/share/9212137b-d72c-4cfe-b588-a82d715e05b3>

*** ** * ** ***

## CAVEATS \& TIPS

1. **How do I export a complex CAD (.dwg) file from AutoCAD with multiple layers that I do not want to include for the Digital Map Pro?**

If the CAD (.dwg) file has as a "Layout" tab with the exact layers and objects needed:

**a.** Right-click on the tab (bottom of the application window on macOS)

**b.** Choose the "Export Layout to Model..." option

The resulting CAD (.dwg) file will only contain the layers and objects visible in that Layout.  
![AutoCAD - Export Layout to Model...](https://runbooks.ciscospaces.io/__attachments/a_cb63681eba2dad6abd5ba6dbbfc1d7b9442c20d6a225934dcbb94042dadd4a40/AutoCAD%20-%20Export%20Layout%20to%20Model....png?cb=7e8fc15b643b678789616c9e163df0a3)
AutoCAD - Export Layout to Model...

2. **What is the difference in outcome between individual desk IDs and a label for a group of desks?**

By labeling desks individually, each desk will be editable under Setup \> Locations \& Maps \> Digital Maps \> View/Edit (Digital Map Editor). Surrounding a group of dekss  

|                                                                                                                 **CAD File**                                                                                                                  |                                                                                                                     **Digital Map Pro**                                                                                                                     |
|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| ![Screenshot 2025-04-15 at 16.49.07.png](https://runbooks.ciscospaces.io/__attachments/a_daa2b72b021ced306e9fff836ebc4e84433c20a081f31757c15abc90a00b24a5/Screenshot%202025-04-15%20at%2016.49.07.png?cb=467841691583d9dab7d48a9863dc3b97) CAD File - Group of Desks Labeled | ![Digital Map Pro - Group of Desks Editable](https://runbooks.ciscospaces.io/__attachments/a_221189b1fae45e9607114b292153a4d3d83c0d5e4858d8edbce7afe8428cfc74/Screenshot%202025-04-15%20at%2016.44.38.png?cb=4f9bae48780e219a5abe4d7b7cfe46ef) Digital Map Pro - Group of Desks Editable   |
| ![CAD File - Individual Desks Labeled](https://runbooks.ciscospaces.io/__attachments/a_9f2ca012f041da4b6df5dab6edd0cd394ec15eb3ff7ba664a96a4f7ff12b0720/Screenshot%202025-04-15%20at%2016.29.48.png?cb=e0e6bc22f0f5b39eabb3bf3e19e33d4f) CAD File - Individual Desks Labeled | ![Digital Map Pro - Individual Desk Editable](https://runbooks.ciscospaces.io/__attachments/a_b0bd964984af27055e132b0474943debae654679fb5a6021de6dcc1e944dc496/Screenshot%202025-04-15%20at%2016.38.26.png?cb=15631bd0da853d48cbcc44ff8f394003) Digital Map Pro - Individual Desk Editable |

3. **What kind of changes can I expect when re-uploading CAD files to modify existing Digital Maps?**

There are a few scenarios where intentionally or unintentionally re-upload CAD files may be necessary:

**a.** After uploading CAD files for the first time (before finished processing), canceling is perfectly acceptable. Canceling the processing will make it possible to choose different files (if chosen mistakenly or realizing some changes were needed in the file contents) or add/remove files from processing. Otherwise, waiting for the first round of processing (per building) is necessary before adding or removing any floors.

**b.** After map processing has completed and there are missing objects in the Digital Map Pro (among other reasons - see below), re-upload the exact same file as before and a new reason, comments, and attachments modal appears inline. The reason dropdown categories are:

**i.** Missing objects (e.g. walls, furniture)

**ii.** Missing spaces (e.g. floor space is invisible where a room or other space type should be)

**iii.** Missing space names/labels (e.g. wrong layer or metadata used for room names)

**iv.** Changed street address or GPS center-point of building

**v.** Multiple reasons or Other (comment below)

Provide additional comments to help our mapping team review the AI processed maps and provide a faster/better update. Optionally include an image with annotations for a holistic picture of the corrections needed.  
![Re-upload CAD files.png](https://runbooks.ciscospaces.io/__attachments/a_3a0ed3654ed9e06a337e792e53cf86e6a4798c93416f781227f200f0e98baa54/Re-upload%20CAD%20files.png?cb=a80b80c51d73a79a1516969ba935471a)  
![Re-upload CAD files - reasons dropdown](https://runbooks.ciscospaces.io/__attachments/a_9d39bcb02b4969761fae180efaf65cb8ac9d93a7e46cb5bfb7d507e1a1cf552e/Re-upload%20CAD%20files%20-%20reasons%20dropdown.png?cb=1dc05cf691eeb319729bf692d65535a5)

**c.** Similar to scenario 2 above, the Location Hierarchy has changed and the exact same files are used to create the same Digital Map Pro in a new Location. Use the appropriate reason dropdown option: "Changed street address or GPS center-point of building". This also applies to re-uploading when the Cisco Spaces mapping team has declined/rejected a CAD file because the building could not be found on the world map. Please provide additional details in the comments field to help the mapping team accurately align the Digital Map Pro on the world map for accuracy in outcomes.  
**Note:** a building can only exist in one place in the world and cannot be duplicated across multiple Locations in the Location Hierarchy or in multiple Cisco Spaces Tenants. Only the most recent upload will work correctly for outcomes such as Pathfinder on Space Explorer Kiosk and Indoor Navigation App Clip for turn-by-turn blue-dot wayfinding indoors.

**d.** After CAD files are finished processing and Published, it is safe to upload additional floor files or modify existing with new file versions. Follow the same workflow as before, but either create new floors (w/ metadata) or check the boxes for floors to update specifically to change the files.  
**Note:** re-uploading unchanged floors is not necessary. When re-uploading, only check the boxes for the floors that need to be updated.

4. **Will Webex Workspaces remain connected to the Meeting Rooms after re-uploading CAD files to modify Digital Maps?**

There is not currently a way to edit a Digital Map directly with new walls, rooms, or furniture after a CAD file has been processed. To make physical layout changes, upload a modified CAD file to the Cisco Spaces AI Digital Map platform, and it will attempt to carry forward metadata (e.g. Webex Workspace connection, Meeting Room name manual edits). Generally, metadata associations stay intact in the database as long as the internal identifiers have not changed. Typically, a furniture layout will not create new identifiers, but physically moving walls or changing a room name in the CAD file will create new entities on the backend and erase previous manual edits in the Digital Map Editor (e.g. room name). IoT Sensor associations should carry forward as well.

The Digital Map Editor (under **Setup** \> **Locations \& Maps** \> **Digital Maps**) provides an interface to make lightweight, metadata changes to previously processed CAD files. For example: space names, space IDs, and space types. While it is quite easy to manually make these edits, the source CAD files do not receive those edits.  
**It is important to always keep your source CAD files up to date** so that when they are re-uploaded for processing at any point in the future to update the physical layout, space metadata (e.g. name, ID, type) remains intact and is not reverted. If this metadata remains identical to the previous version uploaded and processed, manual edits will carry forward. Any diff in a new file version will overwrite manual edits that conflict.

If new or moved rooms' names are close matches to their respective Webex Workspaces, auto-connecting in Space Manager \> Manage Rooms should reduce manual work to associate all collaboration devices with rooms post-processing CAD files.  
**Note:** Webex Workspaces must be assigned to a Location and a Floor in Control Hub to benefit from auto-connect based on name matching. IoT Sensors will need to be re-added if physical spaces or name have changed significantly, as they do not benefit from auto-connection by name.

5. **What do I need to keep in mind for Campus Wayfinding (i.e. indoor-outdoor and inter-building navigation)?**

There are several factors that affect Campus Wayfinding and decrease time to process CAD files:

**a.** Locations in the Location Hierarchy **MUST** be grouped under the same common level above the Building level.

**b.** A group of Buildings (i.e. Campus) **MUST** fit within a 100km² area (roughly 10km x 10km). To be safe, the distance between the 2 furthest buildings must be no more than 8km.

**c.** Geo-alignment on the world map is essential. Elements included in the CAD files (e.g. bridgeways, paths, etc.) can help align Buildings to ensure smooth transitions between Buildings in a Campus.

6. **How can I set the default map view (pitch, bearing, zoom, latitude/longitude)?**

<https://app.vidcast.io/share/24c8b89d-9dea-4b2a-a856-65a44cfb4813>

7. **How can I hide rooms or areas of the map?**

   There are a few methods to hide elements from the map:

   1. The simplest way to hide a meeting room label and the room from search results is to change the Space Type to a type without a label/icon and not searchable (in the [table above](https://runbooks.ciscospaces.io/docs/digital-map-pro-and-cad-dwg-pdf-best-practices#DigitalMapProandCAD/DWG/PDFBestPractices-OfficeSpace)).

   2. Recommended: if you would like to hide / block out / fill in the space boundaries entirely by replacing with a wall object with 100% height, add a **Hatch Pattern** in the source CAD file that fills in the area to be hidden.

   3. During CAD file upload workflow, include notes and annotated images to explain which rooms to hide / block out / fill in.

![Example CAD file Hatch Pattern](https://runbooks.ciscospaces.io/__attachments/a_04b232005de6dcd0b3e47ba59950ad93fa3ebd425f199779ae54d58eabe64e10/Screenshot%202026-04-01%20at%2009.09.32.png?cb=834c07791d42d081b099a96691a9b86d)
Example CAD file Hatch Pattern  
![Example Digital Map with Hatch Pattern hiding - blocking out - filling in wall with 100 percent height](https://runbooks.ciscospaces.io/__attachments/a_01a9dbaeeb4d4ecdc0b86c564f99ce09c92d4978c61cc51fdfe77376c29035b4/Screenshot%202026-04-01%20at%2009.11.44.png?cb=8017dd7c8bd4589f2da671a0d71eea05)
Example Digital Map with Hatch Pattern hiding / blocking out / filling in wall with 100% height

*** ** * ** ***

## RESOURCES

* <https://app.vidcast.io/share/8fb202a5-e26d-480f-962c-ea77748bf033>

* <https://spaces.cisco.com/setupguide/configure-location-hierarchy/>

* <https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m-locations-and-maps.html>

* Sample CAD File: [SJC10 demo CADs for a lab setup.zip](https://runbooks.ciscospaces.io/__attachments/a_f17e8f92e22328190071314e6899a1fd897fac59d2ac2a0f73149ed868b6dac7/SJC10%2520demo%2520CADs%2520for%2520a%2520lab%2520setup.zip.md?cb=b7ce89f7c882a59e32c65b207635606f)

---
language: "en"
---
# Export your Existing Catalyst Center Floor maps into an Ekahau RF Predictive Project

*An easy and effective way to get an RF Predictive Design in just a few seconds*

## OVERVIEW

The goal of this exercise is to demonstrate the steps on how easy and quickly partners and customers can export their Catalyst Center hierarchy, building(s) and existing access points (APs) into an Ekahau RF predictive file. The Ekahau(.esx) file generated by your Catalyst Center is intended to be used by the Cisco Spaces team for DDM validation purposes. Leveraging this approach, customers and partners can save significant amount of time and effort instead of creating RF predictive designs from scratch.

Before getting into the steps-by-step criteria, we want to highlight a few points on why this is important going forward. Additionally, we have a [**DDM FAQ**](https://runbooks.ciscospaces.io/docs/cisco-spaces-design-deployment-module-faq) that will clarify any questions you may have regarding the Spaces DDM Validation process:

### **Why are we doing this?**

· We know that creating RF predictive survey projects from scratch can be time consuming so Cisco in partnership with Ekahau have created a quick and straight forward approach to export your current hierarchy, building(s), floorplan(s) and AP placements with its key characteristics into an esx format.

### **What is the purpose on getting an Ekahau file with your floorplans \& AP Placements?**

· As part of the DDM validation process conducted by the Spaces BE team, getting an RF predictive design will allow us to have a baseline reference to assess, validate and provide you with a detailed course of action to ensure your workspace is capable to support high precision outcomes, e.g indoor navigation/wayfinding, asset tracking, occupancy by zone level and much more.

### **Customer/Partner have gone through an RF validation survey onsite already. Can I provide those files to start the DDM validation process?**

· DDM validation is focused on assessing and validating BLE and UWB propagation characteristics along with our Cisco validated guidelines to ensure your workspace is ready to accurately unlock high precision Spaces outcomes. As up to date, the only way to start designing and validating for BLE and UWB is via an RF predictive design. An RF validation survey will provide Wi-Fi data along with the L1 spectrum sweeps collected from the physical space.

### **Are there any benefits in providing RF predictive designs for DDM validation?**

· Absolutely. Besides saving significant amount of time and effort on creating RF validation projects from scratch, it will give the Spaces BE team a realistic view of the AP density and physical position of each single AP/Antenna which are key for the analysis. Aside of that, it will help on expediting the analysis and validation time that the Spaces BE team require to come back with final recommendations and next steps.

*** ** * ** ***

## SUPPORT AND ONBOARDING

Please follow the link below to find out about the different ways to get support for Cisco Spaces.

[++Support Info Link++](https://activate.dnaspaces.io/hubfs/Assets/CiscoSpaces-SupportUpdate.pdf?__hstc=105720540.52aaa4a978f36be89855b002cb35bfc4.1729705805310.1729705805310.1729705805310.1&__hssc=105720540.1.1729705805310&__hsfp=3667649010)

*** ** * ** ***

## PREREQUISITES

Customer should have Cisco Catalyst Center (formerly Cisco DNA Center) deployed with a hierarchy define, building(s), accurate floorplans and access points (APs) properly placed on the maps.

* Floorplans should reflect accurate AP placement, ceiling height and AP model(s). As an example:

* Cisco Catalyst CW9178 Series APs at 12ft ceiling height

* Cisco Catalyst C9130AXE Series with AIR-ANT2513-P4M-N antennas at 25ft height with the right Azimuth and Elevation angles.

Recommended versions:

* Cisco Catalyst Center (physical or virtual appliance): 2.3.7.9 and higher

* Ekahau AI Pro: 11.8.8.1 and higher

**Note:** Catalyst Center version 2.3.7.x and Ekahau AI Pro 11.8.x already include/support the latest Cisco Wi-Fi 7 portfolio introduced recently e.g CW9171, CW9172i, CW9174i/e, CW9176, CW9178 and CW9179F. For further details, please refer to the Cisco Catalyst Center [**Compatibility Matrix**](https://www.cisco.com/c/dam/en/us/td/docs/Website/enterprise/catalyst_center_compatibility_matrix/index.html)and the Ekahau AI [**release notes**](https://sw.ekahau.com/download/pro/Release%20Notes.html) and [**change log of APs and antennas**](https://sw.ekahau.com/download/pro/accessPointAndAntenna/Antennas%20And%20APs%20Release%20Notes.html)

*** ** * ** ***

## HOW TO EXPORT

### Export your Catalyst Center Hierarchy into an Ekahau file

1. Log into your Catalyst Center and navigate to your upper left pane:

* ***Design\>Network Hierarchy***and select the location(s)/building and specific floors that need to be exported as an Ekahau file.

* In this example, all of the floors under the *"Tribuna Alta"*building are the ones that need to be exported, the rest of the building/floors are not required currently.

2. Next to my building *"Tribuna Alta"* hover your mouse to the three dots on the right- hand side and select *"Export Floor Maps":*

![Picture 1.png](https://runbooks.ciscospaces.io/__attachments/a_98fc77ff0f50e40e4e1bae75ea358ad75a53e40377355e6c0337f77d7c095cb5/Picture%201.png?cb=fb78e38308a76ed9aa3e87a533ca2c55)

* As you are selecting the whole building, the export will implicitly include all the floors within that building/location. In this case, the exported file will have three different floors, as highlighted in the image above.

**Note:** If your intended goal is to include the whole area with its respective buildings and floors, you can instead select your area/parent location and export all of them. That will include everything under that parent location. For further details related to the hierarchy, areas and buildings, please check the following [**reference**](https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/catalyst-center/2-3-7/user_guide/b_cisco_catalyst_center_user_guide_237/m_design-the-network-hierarchy.html)

3. Make sure to name your file with an intuitive identifier that refers to the location and explicitly select "Ekahau Project" export format:

* That will generate and download an .esx file to your desktop.

* The esx project generated by Catalyst Center will be used by the Cisco Spaces BE team to initially review and validate whether your environment has the right AP density and strategic AP placement to unlock high precision outcomes.

![Picture 2.png](https://runbooks.ciscospaces.io/__attachments/a_c56a1e349e0097383c5134f076512783354838ca9bd4cc9401faebb6afb92264/Picture%202.png?cb=699c9ee6bcb916cb16cf6369c1316bb2)

The Cisco Spaces team have created an easy way for you to share your Ekahau files. Once the project is uploaded and submitted, our Spaces BE team will get a notification about this project.

### Does Cisco have a way to share Ekahau files besides e-mail?

The Cisco Spaces team has created an intuitive way for customers and partners that have purchased DDM to upload and share the projects with the Cisco team.

1. Navigate to the [Cisco Spaces DDM site](https://spaces.cisco.com/ddm/)

2. Fill the information requested and Deal ID whenever possible. You should comply with the "terms and conditions" highlighted and click next.

![Picture13.png](https://runbooks.ciscospaces.io/__attachments/a_43a2c13e27e50d61ba5f8b8700d811456abdb60517d496141c6bffe0c7c58d48/Picture13.png?cb=22abd72fec862b1d7c88f6cfa73ad5c2)
Cisco Spaces DDM Website

2. Proceed to upload your Ekahau (.esx) file(s) and submit.

**Note:** You can upload multiple projects in one shot. Typically, RF Predictive designs are more compact in terms of file size (MB) vs other forms of RF surveys that tend to exceed \~100MBs  
![Picture14.png](https://runbooks.ciscospaces.io/__attachments/a_617fe306eff7b5791030f45a900e8f384f5b930e66640bba75c42929dd780dcf/Picture14.png?cb=099c40094c21c8372bc091dbe6d62f58)

3. Once the Ekahau project is submitted, you will get a notification email stating that the project was successfully received by Cisco. In parallel, the Cisco team will have your information/projects already in the queue to proceed with the DDM analysis and validation.

4. Here is an example of the project that was received by the Cisco Spaces BE team. It has all the prerequisites needed to formally start with the Spaces DDM validation exercise:

![Picture15.png](https://runbooks.ciscospaces.io/__attachments/a_5d620b41028da3602c721bbe5217d31eda712ad6a363bb98d9005dcb3dae53a8/Picture15.png?cb=1aae4dc55d6d3f3a960911f06d149f52)

Besides having the floor plans with accurate AP placements, heights, AP model/antennas and type of materials bundled into a .esx file, the example above is already an Ekahau RF predictive design that will be used as part of the DDM validation process. The final goal is to assess, design and validate AP density and strategic placement needed to future-proof your workspace to support high precision outcomes e.g Indoor navigation/wayfinding, asset tracking, occupancy, etc.

---
language: "en"
---
# Guide to Network Map Geo-Placement and Best Practices

## Background

Accurate network map geo-coordinates ensure anything on the network (including the network APs themselves) or tracked by the network (e.g. asset tags) are properly assigned latitude and longitude with respect to a world map. Errors in network map placement, scaling, and alignment can result in margins of error measured in feet up to miles depending on the severity of incorrect geo-coordinates. Ultimately, this can result in poor performance in indoor wayfinding, asset tracking, WiFi client trilateration, etc. For example, heat maps of building occupants can appear outside buildings boundaries. To ensure the best outcomes, placement of network maps and APs relative to those maps is essential.

There are multiple ways to solve network map placement issues and new methods in the product development pipeline. This document will be updated to account for these methods over time, but it was last updated in December 2025.

The preferred approach is to use the **Cisco Spaces** \> **Network Map Calibration - RECOMMENDED** method.

*** ** * ** ***

## Network Map Margins

Making sure WiFi clients, for example, are confined to a building's boundaries starts with a good quality network map file. Network maps with extra spacing or margin around the edges of buildings can create some extra space for client trilateration to deviate outside the boundaries of the building. A quick fix might involve opening the network map file in an image editor and trimming the extra space using a cropping tool. For example, on a Mac, you can open an image file in Preview, opening up Tools, then Rectangular Selection. By pressing ⌘ + A on the keyboard, you can select the entire image, then drag the four sides of the selection boundary to the outermost edges of the building outline. Pressing ⌘ + C, then ⌘ + N will create a new image file that you can save.  
![Screenshot 2025-02-21 at 9.15.37 AM.png](https://runbooks.ciscospaces.io/__attachments/a_ee685809552cfa2619fb5cfe2e71cd7aa7be59925540423d673a0869ef8d1dd9/Screenshot%202025-02-21%20at%209.15.37%E2%80%AFAM.png?cb=87d54a32976b54077120b70bcdabdab4)
*Figure 1 -- The unnecessary margin area in the example image file (.png) is denoted by the two red boxes. The area between the red lines is unnecessary and can result in inaccuracies in indoor location data.*  
![Screenshot 2025-02-21 at 9.18.15 AM.png](https://runbooks.ciscospaces.io/__attachments/a_9c08fc66e5fd8a405d6b988b9d1624f20c9fba3064312ed3de4583e2c77664f7/Screenshot%202025-02-21%20at%209.18.15%E2%80%AFAM.png?cb=9da139a7481710589c442764539e541a)
*Figure 2 -- An example of a network map after removing the unnecessary margin area from the image file (.png).*

*** ** * ** ***

## Cisco Spaces

### AP Auto Placement

[++Set Up Access Point Auto Location++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m-device-placement.html)

At least 4 "anchor" APs are required per floor for AP Auto Placement.

### **Network Map Calibration - RECOMMENDED**

Flat floorplan image files that have been synced from Meraki Dashboard, Catalyst Center, and Prime can optionally be "calibrated" (i.e. aligned) with Digital Maps manually in Cisco Spaces Dashboard under **Setup** \> **Locations \& Maps** \> **Digital Maps** \> **View/edit maps** \> **Network Map Calibration**.

The process involves going into each floor and in step one, moving, rotating, and scaling a transparent Digital Map on top of an image of the Network Map file. In this step, the goal is to approximately align the two maps, but precisely lining them up is not necessary in this step.

In step two, you must place at least 3 markers and precisely position them (ideally in corners that are easy to visually match up) in both the Network Map and Digital Map that correlate with the exact same position.

The more precise and more markers (depending on building geometry, such as square, round, or irregular polygons), the more accurate alignment will be, which will determine client location accuracy for outcomes like historical floor heat maps in Space Utilization app. However, accuracy is also determined by other major factors such as signal interference and obstructions, access point (AP) density and placement, and AP radio type (e.g. WiFi, BLE, UWB).
<https://app.vidcast.io/share/5338b5db-c41c-4dac-9ad8-11edc87f07d3>

*** ** * ** ***

## Catalyst Center -- Overlay Objects

### Catalyst Center -- Set Scale

[++Work with Wireless 2D and 3D Floor Maps: 2D Map Toolbar \> More \> Set Scale++](https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/catalyst-center/2-3-7/user_guide/b_cisco_catalyst_center_user_guide_237/m_work-with-wireless-2d-and-3d-maps.html#Cisco_Reference.dita_48f78f45-54e6-4461-8614-9cf8adecae6b__d168419e8622)

A correct scale measurement ensures the distance between GPS Markers and scale of the network map image align. Incorrect scale may result in "Red Pins" (see below under the Pin Colors section).

**Set Scale**: Change the map scale by providing a known measurement on the map:

1. Click the map to specify the starting point of the measurement.

2. Click the map again to specify the ending point of the measurement.

3. In the **New line length (ft)** field, enter the length of the measurement.

4. Click **OK**.

The floor map dimensions are recalculated based on the new measurement.  
![Screenshot 2025-02-21 at 9.18.37 AM.png](https://runbooks.ciscospaces.io/__attachments/a_bd2ec2e037e79884b426e60fd17f2a866081156fa706797c6765940663d5fc5d/Screenshot%202025-02-21%20at%209.18.37%E2%80%AFAM.png?cb=2bbb55be03b759976686529694b99a80)
*Figure 3 - Using a network map image with a to-scale distance reference makes it easier to perform the "Set Scale" action in Catalyst Center*

### Catalyst Center -- GPS Markers

[++Work with Wireless 2D and 3D Floor Maps: Add, Edit, and Remove GPS Markers++](https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/catalyst-center/2-3-7/user_guide/b_cisco_catalyst_center_user_guide_237/m_work-with-wireless-2d-and-3d-maps.html#ariaid-title36)

A minimum of 3 (ideally 4 or more depending on floor size) GPS Markers are required and each should be placed at least 20 meters apart from each other. This is to ensure proper scaling and orientation of Catalyst Center network maps when aligning with Digital Maps on Cisco Spaces, such as in Space Manager \> Overview \> Floor Occupancy heat maps.

#### How to Obtain Latitude, Longitude for GPS Markers

Basic -- Go to [++https://www.openstreetmap.org++](https://www.openstreetmap.org/), search for the street address, zoom in to the corners of the building, right click, and click the latitude, longitude at the top of the pop-up. Repeat for each corner of the building, while adding GPS Markers in Catalyst Center.  
![Screenshot 2025-02-21 at 9.18.57 AM.png](https://runbooks.ciscospaces.io/__attachments/a_3c4075e124247f7355bab8cff6d605f0057e86873151c3f3d0d44ba9c013a443/Screenshot%202025-02-21%20at%209.18.57%E2%80%AFAM.png?cb=208b7839a37fad7da5955f3daee472c3)

Advanced -- If you want more precise GPS Markers to more perfectly align the Catalyst Center network map with the Digital Maps Pro, you can open a Cisco Spaces Support case in the Cisco Spaces Dashboard and request GPS Marker latitude, longitude values with a screenshot of where to place them on the network map.  
![Screenshot 2025-02-21 at 9.19.27 AM.png](https://runbooks.ciscospaces.io/__attachments/a_8f7f54c6c7c01aa04c2bde84e5851c5b66566e4cc1f6d7040208eb1d1938688e/Screenshot%202025-02-21%20at%209.19.27%E2%80%AFAM.png?cb=93ef6811ee11a518476a02e846c12bec)
*Figure 4 - An example side-by-side screenshot of the Digital Map Pro (with latitude, longitude values) and the network map*

Roadmap -- Cisco Spaces will be geo-referencing network maps at the time of uploading CAD files in order to automatically and perfectly align both maps for a seamless and scalable experience.

#### Pin Colors

++Green Pins++ -- Cisco Spaces map service [++applies logic++](https://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/infrastructure/3-7/user/guide/bk_CiscoPrimeInfrastructure_3_7_0_User_Guide/bk_CiscoPrimeInfrastructure_3_7_0_User_Guide_chapter_01001.html#task_1098614) to the GPS Marker positions relative to each other across floors to ensure consistency and has determined they are relatively correct, but they can still be off technically.

++Red Pins++ -- Cisco Spaces map service's logic has determined that the GPS Markers are mostly likely incorrect and will lead to inaccurate client location data relative to a world map and geo-coordinates. Therefore, clients heat map data will not show in Space Manager \> Overview and other Cisco Spaces apps that require geo-alignment. Please correct the GPS Markers to be more consistent between floors.  
![Screenshot 2025-02-21 at 9.19.46 AM.png](https://runbooks.ciscospaces.io/__attachments/a_bdea4a987c7eb8ebcf9a6f55faac829b0a236b0a2274c9713715648173e3da94/Screenshot%202025-02-21%20at%209.19.46%E2%80%AFAM.png?cb=f8a64aed3d02266ec8d6c18c6f3a9d5b)
*Figure 5 -- An example of a network map with GPS Markers correctly placed in Catalyst Center and showing as green pins in Detect \& Locate app.*

*** ** * ** ***

### Catalyst Center -- Coverage Areas

[++2D Floor Map Devices and Overlay Objects++](https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/catalyst-center/2-3-7/user_guide/b_cisco_catalyst_center_user_guide_237/m_work-with-wireless-2d-and-3d-maps.html#ariaid-title11)

[++Add, Edit, and Remove Coverage Areas++](https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/catalyst-center/2-3-7/user_guide/b_cisco_catalyst_center_user_guide_237/m_work-with-wireless-2d-and-3d-maps.html#add_coverage_area)

If a Coverage Area appears rotated or out of alignment with the network map, then client location will be skewed relative to the Cisco Spaces Digital Map even if GPS Markers are accurate.  
![Screenshot 2025-02-21 at 9.20.02 AM.png](https://runbooks.ciscospaces.io/__attachments/a_22b3624e141e1cee3d3eab33342dc8735e2fa6a77f5932e2af29e1b13a8b9d1d/Screenshot%202025-02-21%20at%209.20.02%E2%80%AFAM.png?cb=cfb4e8d72f73097de49c6a36eb95cfe2)
*Figure 6 -- Example of network map and Coverage Area misalignment as observed in Detect \& Locate app.*  
![Screenshot 2025-02-21 at 9.20.13 AM.png](https://runbooks.ciscospaces.io/__attachments/a_4f1f9f4ba841b03b9263e68468f59402eb4a356e7ce8b6f6c36e1c692a4af635/Screenshot%202025-02-21%20at%209.20.13%E2%80%AFAM.png?cb=e6857e2dabc77c3103389d81e8cbaefd)
*Figure 7 -- Example of a heat map in Space Manager \> Overview \> Floor Occupancy based on the network map and Coverage Area misalignment in the previous figure (Figure 4).*

*** ** * ** ***

## Meraki Dashboard -- Network Floor Plans

### Meraki Documentation

* [++Using a Floor Plan or Custom Map in Dashboard++](https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Using_a_Floor_Plan_or_Custom_Map_in_Dashboard)

* [++Floor Plan Geoalignment: Why Geoalignment Matters++](https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Using_a_Floor_Plan_or_Custom_Map_in_Dashboard#section_7)

* [++Placing Devices on the Map in Dashboard++](https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Placing_Devices_on_the_Map_in_Dashboard)

![Screenshot 2025-02-21 at 9.20.22 AM.png](https://runbooks.ciscospaces.io/__attachments/a_66ff7b09bfee5994ee8f984e094bf9cd84343376774bfe39b2d421a08e7f59fc/Screenshot%202025-02-21%20at%209.20.22%E2%80%AFAM.png?cb=e38a80f1f270408f92d31a312f437f11)
*Figure 8 -- Example of the Meraki Dashboard network map in its default placement over the building without properly placing, scaling, and aligning the image to the building outline. Here it is visible on the satellite ma view, but it is recommended to use the regular building outline map view for precise alignment with the base of the building instead of the roof due to birds eye 3D perspective.*  
![Screenshot 2025-02-21 at 9.20.32 AM.png](https://runbooks.ciscospaces.io/__attachments/a_cc92fdd3349ff9c155dca972f0b434324c74c5b3cad278ba145bf16851f8f9fc/Screenshot%202025-02-21%20at%209.20.32%E2%80%AFAM.png?cb=349916b51ca20c4e1017be7b53089706)
*Figure 9 -- Example of an incorrectly placed, scaled, and aligned network map on the Meraki Dashboard and how the resulting heat map data in the Cisco Spaces Space Manager app appears incorrectly at the city block placement, larger than the actual building, and misaligned with the edges of the building.*

*** ** * ** ***

### Network Map Placement, Scaling, and Alignment

The most common occurrence among Meraki Dashboard network map deployments is proper placement, scaling, and alignment of the network map image file on the Meraki Dashboard. To upload a network map image file, click on a network, then hover over "Network-wide", and click on "Map \& floor plans". If the network floor plans have already been added, then click on "Edit" on each of the floors on the right side of the map view one-by-one to correct their placement, scaling, and alignment. Add a new floor plan by clicking on "Add a new floor plan" on the top of the map view.
<https://app.vidcast.io/share/f1faa92d-66e3-4da1-be78-0b6ec79e9123>

![Screenshot 2025-02-21 at 9.20.47 AM.png](https://runbooks.ciscospaces.io/__attachments/a_a91e2b687bb4a88e35a913792456078aab86ec6a69658c073538470cf56a0857/Screenshot%202025-02-21%20at%209.20.47%E2%80%AFAM.png?cb=8dfbdec91bdb78a2ae75329e5d8b5c42)
*Figure 10 -- Menu item for Network-wide \> Map \& floor plans*

![Screenshot 2025-02-21 at 9.20.54 AM.png](https://runbooks.ciscospaces.io/__attachments/a_789d586ff358ed61c6369e3e1ea13d088a7bf5ccae4d55a32531a077a79dd5b4/Screenshot%202025-02-21%20at%209.20.54%E2%80%AFAM.png?cb=1e0f45daa19085a367769edb4ad54f68)
*Figure 11 -- Add new floor plan. Add floor name and street address, and upload floor plan image file.*

![Screenshot 2025-02-21 at 9.21.04 AM.png](https://runbooks.ciscospaces.io/__attachments/a_0fba96f2a1ced4dd140181e26a43ef20737c5b04ef724ff84bb6db2dc237bf04/Screenshot%202025-02-21%20at%209.21.04%E2%80%AFAM.png?cb=5073f7ce7370e1e9ef2049ffd07770a9)
*Figure 12 -- Zoomed out view of the building outline map view. Showing default placement of the floor plan image file rotated 90º from the actual building outline, scaled up to multiple city blocks, and not aligned with the building outline underneath.*

![Screenshot 2025-02-21 at 9.21.14 AM.png](https://runbooks.ciscospaces.io/__attachments/a_a89ace35de876dede9e99b9bdffb2568ad2912ef11b9aee0c708b84741c6f4f8/Screenshot%202025-02-21%20at%209.21.14%E2%80%AFAM.png?cb=0d29127b0c28d1ad3833bc9621fea416)
*Figure 13 -- Zoomed out view after move the floor plan image, scaling, and aligning the building outline underneath.*

![Screenshot 2025-02-21 at 9.21.23 AM.png](https://runbooks.ciscospaces.io/__attachments/a_a55a3bea71a8a855c08eedb839af6b9d9c367ce03ee4d8caab69f221ba571f71/Screenshot%202025-02-21%20at%209.21.23%E2%80%AFAM.png?cb=ee31de6b2d50b6da085cf911eef57a09)
*Figure 14 -- Adjust opacity to make it easier to align the network floor plan with the world map underneath.*

![Screenshot 2025-02-21 at 9.21.28 AM.png](https://runbooks.ciscospaces.io/__attachments/a_50ca77d4f619b547e91822102a77b3f5b60e193a3c332a9cf862faaca1f582c6/Screenshot%202025-02-21%20at%209.21.28%E2%80%AFAM.png?cb=225a6f61c1b9e7c3b02140072c8d2b95)
*Figure 15 -- When editing an existing floor plan image, Location shows the geo-coordinates of the image placement instead of the original street address in a previous Figure / screenshot. Placement, scaling, and alignment steps are identical to a new floor plan upload.*

---
language: "en"
---
# How Data is Interpreted and Calculated for Apps in Spaces

## Overview

Cisco Spaces processes data in different ways based on context. This article will demonstrate how data is interpreted and calculated for different apps within Cisco Spaces.

*** ** * ** ***

## Spaces Applications

### Right Now

The Right Now app allows for real time count of the number of people within your locations. It provides a real time count of the number of people within a physical space \& how that compares with the historical average.

* Visitors are defined as counts of unique (Wi-Fi associated) user-ids that are present at a target location during the past 10 mins. This means that when mac addresses share the same user-ids they are counted as one visitor (deduplicated).

* Also, there are configuration filters in the app to allow/remove certain SSIDs in the counts

* The average value for the last 51 weeks is shown as historical data for each chart in the report.

![image-20250602-060905.png](https://runbooks.ciscospaces.io/__attachments/a_c7a5ce33b6f7bf8cedcc81c90c3a4458979671c0c343111da2cec411f4d44dcf/image-20250602-060905.png?cb=44ed73d582be97f859cbf2e5cc9e9aaa)

* Historical minute-wise counts from Right Now can be exported through the Data Export feature (Setup\>Data Export\> Create new export\> choose 'Right Now' option.

![Screenshot 2025-06-02 at 2.38.09 pm.png](https://runbooks.ciscospaces.io/__attachments/a_5d80d7c93153832922085f28c3a5c9f3f4ae4bea859fe9c543d58ceb57543610/Screenshot%202025-06-02%20at%202.38.09%E2%80%AFpm.png?cb=6688e5efa87024de84f4c6ccde4e564f)

*** ** * ** ***

### Behaviour Metrics

Behaviour Metrics provides data around people behaviour within locations - e.g. Buildings, floors, zones etc.

* Primarily metrics include Visit Duration (dwell time) and Visit Frequency (how often a person visits a location)

* Behaviour metrics has vertical specific versions for Retail, Workspace and Education customers and a Generic version for others.

* Retail focuses on measuring behaviour of guests and this involves excluding employee devices from the computation. The employee devices are segregated through an ML based algorithm.

* Workspace and Education metrics involve using SSID filters to separate employees/students from guests. Employee/Student metrics are derived by using dot1x authentication to dedupe those with multiple devices.

* Visit classification (to a location) also varies across verticals. It requires an 'idle time' of three hours before a visit is terminated in the case of retail and 10 hours for Workspace and Education.

![Screenshot 2025-06-04 at 4.46.15 pm.png](https://runbooks.ciscospaces.io/__attachments/a_ac37fb1bd91b01d19dd9efebda1542b4866bbd19dd0da2ecc1b496592b13726d/Screenshot%202025-06-04%20at%204.46.15%E2%80%AFpm.png?cb=0b440509ae19724a336691416eacaaa8)

*** ** * ** ***

### Space Utilization

Space Utilization allows occupancy insights of buildings and floors. It allows organizations to optimize space, cut costs and streamline operations. It counts people within specific locations (orgs, buildings, floors, zones and rooms).

* It uses wifi to compute occupancy/utilization of buildings and floors, and sensors (Cisco video endpoints, Portal Beam, Thingsee and Moko) for rooms

* People counting also de-duplicates people with multiple devices. The utilization counts are based on unique (Wifi associated) user-ids. This means that when mac addresses share the same user-ids they are counted as one visitor (deduplicated).

* The SSIDs excluded in the Right Now App configuration are applied here as well.

* The utilization percent are based off of the configured max building/floor capacity in the location hierarchy.

* Data is broken down at a daily level.

![Screenshot 2025-06-02 at 3.13.14 pm.png](https://runbooks.ciscospaces.io/__attachments/a_6b3edbf4ec0b6e9f1dc8548af7e6c58d545a3ed92ff6e1ff0e8482c0722aeecd/Screenshot%202025-06-02%20at%203.13.14%E2%80%AFpm.png?cb=6fea9fb737287887fb495627a2532237)

*** ** * ** ***

### Location Analytics

Location Analytics is an app that counts associated devices. It enables you to create various reports related to the no. of 'visitors and visits' to your locations. You can create custom widgets by filtering data based on location, date range or SSIDs and get a granular view of location behaviors.

* Visitors are defined as counts of mac addresses regardless if they share the same user-ids. No deduplication is applied.

* Devices connected less than 5 mins or greater than 12 hours are excluded.

* Data can be broken down by SSID, Building, Floor and Zone and time ranges are customizable and is available across the life of the Spaces tenant.

![Screenshot 2025-06-02 at 3.11.20 pm.png](https://runbooks.ciscospaces.io/__attachments/a_11ebe68cc06919f758b40cf919930d22a2f44c8ec2ae49b7e9d164b1b63d1ff2/Screenshot%202025-06-02%20at%203.11.20%E2%80%AFpm.png?cb=92c898c7a48cf36850982c68131c00f6)

*** ** * ** ***

### Detect and Locate

Detect and Locate is an application that allows users to determine the location of devices as detected by their Access Points. It allows you to track and locate any device connected to your network. The most common type of devices are Wi-Fi clients, but the application can also detect the location of 'Wi-Fi RFID tags', 'rogue APs' and 'rogue clients'.

* Clients are defined as counts of mac addresses regardless if they share the same user-ids. No deduplication is applied.

* Only non-randomized probing counts of clients are displayed (in red). For all intents and purposes, the probing data does not represent approximate count of people in the space due to aggressiveness of randomization.

* Historical data playback is up to 30 days.

![Screenshot 2025-06-02 at 3.10.42 pm.png](https://runbooks.ciscospaces.io/__attachments/a_229f73853cfb1743773811f999f4b0ede7051c8093f408dfc74a2a5112ab0098/Screenshot%202025-06-02%20at%203.10.42%E2%80%AFpm.png?cb=8a450400007678fc4a6d6d298ce8638f)

*** ** * ** ***

## Reference

* <https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m_business-insights.html>

---
language: "en"
---
# Infant Protection with Securitas Healthcare and Cisco Spaces

## **OVERVIEW**

This document provides a comprehensive guide to deploying the Infant Protection Solution integrated with Securitas Healthcare. This integrated solution enhances infant safety through real-time location tracking, tamper detection, and automated alerts managed via the hospital's security and clinical workflows.

The Infant Protection Solution ensures advanced and scalable security coverage for infants within a specific department or across the hospital campus. Each infant wears a Hugs tag attached to the ankle and automatically enrolls into the system. Once enrolled, infants are continuously monitored across all areas with Cisco wireless coverage. This use case extends to NICU infants and pediatric patients in open-crib stages.

In the system requirements section, this document outlines the supported Cisco Spaces and Securitas Healthcare versions, recommended configurations, and hardware requirements for optimal performance. It also provides network specifications and best practices to ensure successful deployment.

This document focuses on the implementation utilizing Wi-Fi-based Hugs tags for infant monitoring. While the underlying Cisco Spaces platform and Securitas Healthcare infrastructure can process both Wi-Fi and Bluetooth Low Energy (BLE) telemetry, all specific configuration steps, guidance, and examples within this document are tailored solely for the Hugs Wi-Fi tag implementation.

The solution has achieved ATO (Authority to Operate) certification, ensuring its compliance with stringent security and operational standards.

## **TARGET AUDIENCE**

This runbook is designed for

* Hospital IT Administrators responsible for infrastructure deployment and integration

* Clinical Engineering Teams managing medical device integration and support

* Security Operations Personnel monitoring alerts and coordinating incident response

* Partners deploying healthcare solutions for hospital customers

* Facility Managers overseeing campus-wide safety initiatives

## **HOW IT WORKS**

The Infant Monitoring solution leverages Wi-Fi based Real-Time Location Systems (RTLS) technology for comprehensive infant safety management. It combines Cisco Spaces Infrastructure with Securitas Healthcare Infrastructure to track and protect infants in real time.

### **Hugs Tags and Band**

The Hugs tag contains a small Wi-Fi transmitter that responds to tamper detection through the band, that is enabled as soon as the tag is applied to the infant. Once applied, the tag emits a signal and is automatically enrolled into the system. From this time forward, the system constantly monitors the tag. If the tag is not seen by the system for a certain period of time, an alert is generated in the system.

#### **Exit Protection**

Exits, including elevators, are monitored using Exit Controllers. If an infant tag nears an active exit and the door is open, an alarm triggers. Exit Controllers can activate door locks to prevent egress, while authorized staff can bypass via keypad or access control integration.

##### **LF Interference Alert**

If the tag's ability to detect LF signals near exits is compromised, the system generates an LF interference alert to proactively notify staff. The solution also includes LF interference avoidance capabilities that actively prevent interference issues before they impact system performance.

##### **Tamper Detection**

The Hugs tag includes a tamper sensor that immediately triggers an alarm if the ankle band is cut or detached. Because Hugs tags are Wi-Fi-enabled, tamper alarms work anywhere with Cisco wireless coverage.

##### **Continual Supervision**

Each tag transmits telemetry at regular intervals. The system monitors missing tag messages and triggers an alarm if communication ceases (configurable, typically within one minute). Continuous Wi-Fi coverage ensures infants are protected during transport or testing.

##### **Out-of-Unit Alert**

If an infant is detected outside the Obstetrics or NICU unit without a logged staff transport, an "Out-of-Unit" alert triggers, ensuring visibility beyond exit boundaries.

## **SOLUTION COMPONENTS**

**Cisco Hardware Components**  

|          **Device**          |                **Function**                 |                                                                        **Recommended Versions**                                                                        |             **Quantity Guidance**             |                              **Notes**                               |
|------------------------------|---------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------|----------------------------------------------------------------------|
| Cisco Catalyst Access Points | Scans for Wi-Fi signals from Hugs Tags      | Wi-Fi 6/6E/7                                                                                                                                                           | 1 AP per 2500 sq ft for high-density coverage | Any Indoor APs supported by Catalyst WLC image                       |
| Cisco Aironet WLC            | Scans for Wi-Fi signals from Hugs Tags      | 8.10.x or latest version <https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html>                     | Per campus architecture                       | Legacy support only, not recommended for new deployments             |
| Cisco Catalyst WLC           | Manages Catalyst AP's, aggregates telemetry | IOS-XE 17.15 or above <https://www.cisco.com/c/en/us/support/ios-nx-os-software/ios-xe-17/products-release-notes-list.html> Minimum compatible version 17.9.6 or above | Per campus architecture                       | Required for modern Wi-Fi 6/6E deployments All 2.4 GHz radios active |

**Cisco Software Components**  

|            **Application**            |                                                                     **Function**                                                                     |                                                            **Version**                                                            |                                                                                                                                                                                                                                         **Notes**                                                                                                                                                                                                                                          |
|---------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Cisco Spaces Connector                | Gathers data from controller and AP and sends data to Spaces Cloud                                                                                   | [Download the latest version](https://software.cisco.com/download/home/286323456/type/286322783/release/Connector%203-Jun%202025) | Active/Active HA supported; minimum 8 vCPU, 16GB RAM, 500GB storage. If HA requirements necessitate a VIP pair configuration (Virtual IP Address), it's important to note that converting an existing Active/Active Securitas setup to a VIP pair requires a Securitas maintenance window. To avoid this interruption, it is typically easiest and recommended to set up a VIP pair with Securitas initially if the customer's HA requirements dictate this configuration from the outset. |
| Cisco Spaces Dashboard                | Cloud-based portal for Cisco Spaces services and applications                                                                                        |                                                                                                                                   | * Global: [https://ciscospaces.io](https://ciscospaces.io/) * EU : <https://ciscospaces.eu/> * SG : <https://ciscospaces.sg/>                                                                                                                                                                                                                                                                                                                                                              |
| Securitas Healthcare RTLS Partner App | Consumes Cisco Spaces location and event data to enable infant monitoring, staff safety, and RTLS workflows within the Securitas Healthcare solution | Latest version on App Center                                                                                                      | Activate via Cisco Spaces Dashboard → Partner Apps                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Local Firehose Service                | Streams real-time raw location and event data from Cisco Spaces to on-prem applications                                                              | Latest                                                                                                                            | Added via Cisco Spaces Dashboard                                                                                                                                                                                                                                                                                                                                                                                                                                                           |

**Securitas Healthcare Device Components**  

|                 **Device**                  |                                                                                                         **Image**                                                                                                         |                                                   **Function**                                                   |   **Version**    |                 **Quantity Guidance**                 |                                   **Notes**                                   |
|---------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------|------------------|-------------------------------------------------------|-------------------------------------------------------------------------------|
| Hugs Wi-Fi Tag                              | ![Screenshot 2025-12-04 at 10.21.28 AM.png](https://runbooks.ciscospaces.io/__attachments/a_95b1b062b8b248d8cd947f0102da56b7e6a161d3ac20efd451e3b179a9e56e3f/Screenshot%202025-12-04%20at%2010.21.28%E2%80%AFAM.png?cb=38296d719316246fd7b545ab5fc40659) | Wi-Fi--enabled infant tag that transmits location and alarm events to the Hugs system                            | 902.39 and above | 1 per infant                                          | Wi-Fi transmitter that responds to tamper detection through the Hugs Tag Band |
| Hugs Tag Band                               | ![Screenshot 2025-12-04 at 10.21.50 AM.png](https://runbooks.ciscospaces.io/__attachments/a_11c6ba311c0534e356277a7ea1f00846fc5de8ca24bb742e9d8a24771ea1b800/Screenshot%202025-12-04%20at%2010.21.50%E2%80%AFAM.png?cb=89174764601605cd4910a29b7d39a18e) | Infant ankle band that provides secure attachment, tamper detection, and LF exit sensing when used with exciters |                  | 1 per infant                                          | Infant ankle tag with tamper detection and LF exit sensing                    |
| Hugs Tag Charger                            | ![Screenshot 2025-12-04 at 10.24.50 AM.png](https://runbooks.ciscospaces.io/__attachments/a_e7672fe4d79630cee28aac8e44120ca3c134e047949a48f3cd1e5c4c7ddd5229/Screenshot%202025-12-04%20at%2010.24.50%E2%80%AFAM.png?cb=8bb80badb63f17575d8293db13849042) | Charging station for Hugs Wi-Fi Tags                                                                             | 1.3 and above    | 1 charger supports charging of 24 tags simultaneously | Fully charged tags can work 8-10 days                                         |
| EX5500 Controllers and Non-Secured Exciters | ![Screenshot 2025-12-04 at 10.20.29 AM.png](https://runbooks.ciscospaces.io/__attachments/a_f802139168598844ad48bb9a9dd13dd9295775a94a052a2b93fad3e2f173b454/Screenshot%202025-12-04%20at%2010.20.29%E2%80%AFAM.png?cb=5617421b08a4fdd8432fc134fd1c726b) | LF exit monitoring hardware that detects tagged infants at monitored exits                                       | 430.04 and above | 1 per monitored exit/elevator bank                    | Doorway RF controller for exit protection                                     |

**Securitas Healthcare Infrastructure Components**  

|           **Component**           |                                               **Function**                                                |                                                                                             **Version**                                                                                              |                                                                      **Hardware Requirements**                                                                       |                             **Notes**                             |
|-----------------------------------|-----------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------|
| AeroScout Location Engine Server  | Processes Wi-Fi tag telemetry and calculates real-time location, events, and alarms                       | 5.7 or higher(5.8.30 latest) [Download the latest version](https://knowledgebase.securitashealthcare.com/Hospital_Solutions/Software_Downloads/AeroScout_Location_Engine/Location_Engine_for_Cisco)  | Provided as ova file, Ubuntu OS included, RAM -- per memory allocation table, 200GB storage                                                                          | Provides real-time location updates to the MobileView Application |
| AeroScout Location Engine Manager | Provides centralized configuration, monitoring, and administration of one or more Location Engine Servers | 5.7 or higher (5.8.30 latest) [Download the latest version](https://knowledgebase.securitashealthcare.com/Hospital_Solutions/Software_Downloads/AeroScout_Location_Engine/Location_Engine_for_Cisco) | Windows 10/11 Enterprise 64 bit Windows Server 2016/2019/2022/2025 Standard Intel Core i3+, 6GB RAM, 50GB storage                                                    | Management interface for Engine Server                            |
| MobileView Application            | Displays location, alarms, workflows, and reports for infant protection, staff safety, and asset tracking | 5.7 or higher [Download the latest version](https://knowledgebase.securitashealthcare.com/Hospital_Solutions/Software_Downloads/MobileView)                                                          | Windows Server 2016/2019/2022/2025 (Data Center and Standard Edition) MS SQL Server: 2016, 2017, 2019, 2022 (Standard and Enterprise) RAM -- per the deployment type | Web application for monitoring and alerts                         |

*** ** * ** ***

## **PREREQUISITES**

### **Cisco Spaces Prerequisites**

1. Cisco Spaces License

   1. Minimum required license for this solution is Spaces Advantage (ACT)

   2. To identify existing licenses - <https://spaces.cisco.com/find-my-license/>

   3. Explore Packages - <https://spaces.cisco.com/packages/#compare>

2. Spaces OS configured and validated per <https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated>

3. Cisco Catalyst Center or Prime Infrastructure configured with accurate floor maps.

4. Local Firehose service added and enabled

5. Outbound HTTPS (443) connectivity to Cisco Spaces Cloud.

### **Securitas Healthcare Prerequisites**

The links referenced in the section below point to Securitas Healthcare documentation and may require access credentials. Please request access to the Securitas Healthcare Knowledge Base here:

<https://knowledgebase.securitashealthcare.com/>

If you have an existing Securitas Infrastructure, it is recommended to verify with the Securitas support team that its current version is compatible with Cisco Spaces, as any necessary updates may require time and should be factored into project timelines and planning.

1. Review [Securitas Healthcare Product Versions Compatibility Matrix Reference Guide](https://knowledgebase.securitashealthcare.com/Hospital_Solutions/AeroScout_Location_Engine/Others_-_AEROSCOUT_LOCATION_ENGINE_(ALE)/Securitas_Healthcare_Product_Versions_Compatibility_Matrix_Reference_Guide) for system compatibility and supported versions for AeroScout Location Engine (ALE) and MobileView.

2. Verify Network connectivity between AeroScout Location Engine, Spaces Connector, and Spaces.

*** ** * ** ***

## **REFERENCE ARCHITECTURE**

![Screenshot 2026-01-28 at 5.51.00 PM.png](https://runbooks.ciscospaces.io/__attachments/a_bb8eb71e402f62cab3aa3893ac8c648b1855e920f71162e05a57859ebfe255b8/Screenshot%202026-01-28%20at%205.51.00%E2%80%AFPM.png?cb=7c84a17b68fb75d1abd1dfeba3d8228c)

*** ** * ** ***

## **HOW COMPONENTS INTERACT**

The integration between Cisco Spaces and Securitas Healthcare for RTLS, including Infant Protection, is orchestrated through data flow between various on-premises and cloud components. This flow ensures real-time location tracking and management, with considerations for High Availability to maintain continuous operation.

1. Once the Hugs tags are activated, Securitas Healthcare HUGS Tags (Wi-Fi) attached to infants or patients transmit periodic 802.11 compliant (2.4GHz) beacon messages.

2. Data Collection by Cisco Infrastructure

   1. Cisco Catalyst Access Points (APs), specifically their 2.4 GHz radios, detect these tag signals and collect the Wi-Fi and Tag MAC Address and raw RSSI information.

   2. The APs forward this raw MAC/RSSI information to the Wireless LAN Controller (WLC) (AireOS or Catalyst 9800) over CAPWAP.

   3. Cisco FRA Implications - Cisco's FRA feature optimizes general Wi-Fi networks by dynamically reassigning AP 2.4 GHz radios (e.g., to 5 GHz or monitor mode) to reduce interference. However, this directly conflicts with mission-critical RTLS applications like infant monitoring, which rely on consistent and dedicated 2.4 GHz listening by multiple APs to accurately track Wi-Fi RFID tags. To ensure high-fidelity location tracking for infant protection, it is essential to disable FRA on APs serving the RTLS use case. This guarantees their 2.4 GHz radios remain in client-serving mode, providing the consistent tag message capture necessary for accurate RTLS.

      For more details on FRA:

      1. [++Flexible Radio Assignment (FRA) and Redundant Radios++](https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-3/b_RRM_White_Paper/fra.html)

      2. [++RTLS Guidance for Cisco FRA and Cisco DNA Spaces with Stanley Healthcare++](https://knowledgebase.securitashealthcare.com/Hospital_Solutions/AeroScout_Location_Engine/Wireless_LAN_Vendors/Cisco/RTLS_Guidance_for_Cisco_FRA_and_Cisco_DNA_Spaces_with_Stanley_Healthcare)

3. Data Processing by Cisco Spaces Connector (with HA)

   1. The WLC sends this information to the Cisco Spaces Connector VM (on-premises) over NMSP. If FastLocate/Hyperlocation is enabled, RSSI information can also be sent over FASTPath.

   2. The Cisco Spaces Connector VM performs two key actions

      1. It sends Wi-Fi client and Tag MAC / RSSI information to the Cisco Spaces Cloud over HTTPS.

      2. It also sends Wi-Fi Client RSSI (Associated), Wi-Fi Client MAC address (Associated) to the AeroScout Engine Server via a gRPC Local Firehose stream.

   3. High Availability (HA) for Cisco Spaces Connector: For resilience, it is recommended to deploy two Cisco Spaces Connector virtual machines as a VIP pair. While Active/Active HA is supported, deploying a VIP pair is strongly recommended for Securitas Healthcare deployments, particularly where BLE tag tracking may be required in the future. Migrating from Active/Active to a VIP pair at a later stage requires a Securitas maintenance window; deploying a VIP pair initially avoids future service disruption.

4. Location Calculation

   1. The AeroScout Engine Server (on-premise) receives both the location information and map data from the Cisco Spaces Cloud.

   2. It processes this combined information to calculate the precise X/Y location for all Hugs Wi-Fi tags.

5. Management and Application Layer

   1. The AeroScout Engine Manager (on-premises) is responsible for the centralized administration and configuration of the AeroScout Engine Server, including importing site maps from Spaces and managing the integration.

   2. The MobileView Application (on-premises) receives real-time location updates and positions for tags from the AeroScout Engine Server. This application provide the end-user interface for Infant Protection, allowing staff to monitor tag locations on maps, set up alerts, and manage workflows.

This integrated data flow, enhanced with High Availability for critical components like the Cisco Spaces Connector, ensures that the location of infants can be accurately tracked and monitored in real-time with minimal disruption, enabling robust Infant Protection functionalities within the healthcare environment.

*** ** * ** ***

## **INSTALLATION AND CONFIGURATION STEPS**

### **Cisco Spaces Configuration Steps**

1. Confirm that the Cisco Spaces license is active

   1. Login to your Spaces account and navigate to My Account section.

   2. Navigate to License Information section to verify status.

      ![Screenshot 2026-01-28 at 5.00.50 PM.png](/__attachments/a_d5c5f926ec57a97372e0790b348312f5ea0d257ecaa850d62143ab9a06514548/Screenshot%202026-01-28%20at%205.00.50%E2%80%AFPM.png?cb=c9f4f327d3e2d9342629bc37db9d521c)

2. Follow the [++OS Runbook++](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated) to install Spaces Connector on VM and add Catalyst WLC

   1. Confirm that the Cisco Spaces Connector and Catalyst Controller are active.

![Screenshot 2026-01-27 at 11.19.19 AM.png](https://runbooks.ciscospaces.io/__attachments/a_4788e57032ee572ef66e1670b56ecf5698a3a2a63d0af322843a96d0cb119da0/Screenshot%202026-01-27%20at%2011.19.19%E2%80%AFAM.png?cb=6ac899f3ea04af00ffa26dd15e089a76)

3. Cisco Catalyst Center or Prime Infrastructure Floor Maps Configuration

   1. Log in to Cisco Catalyst Center or Prime Infrastructure web interface.

   2. Navigate to Design \> Network Hierarchy (Catalyst Center) or Maps \> Site Maps (Prime Infrastructure) and select your building.

   3. Add or edit floors with accurate details including floor name, floor number, floor type, and floor height (typically 10-12 feet).

   4. Upload floor map files using CAD (.dwg, .dxf preferred) or image formats (.png, .jpg, .pdf)

   5. Set map scale and dimensions by entering actual building length and width, or use the span-and-measure tool to click two known points and enter the actual distance - this is critical for location accuracy.

   6. Define RF attenuation by marking walls, obstacles, and materials (thick walls, regular walls, glass, doors) to improve location accuracy.

   7. Place Access Points on the map at their exact physical mounting locations and assign to correct floors.

   8. Add GPS markers (minimum 3-4 markers, at least 20 meters apart) for proper geo-alignment.

   9. Verify synchronization by logging into Cisco Spaces and navigating to Setup \> Locations \& Maps to confirm all floors, maps, and APs appear correctly.

   Reference Documentation
   * [Network Map Geo-Placement Best Practices](https://runbooks.ciscospaces.io/docs/guide-to-network-map-geo-placement-and-best-practi)

   * <https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m-locations-and-maps.html#locations-and-maps>

4. Add [++Local Firehose++](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/connector/config/b_connector_30/m-local-firehose.html) service within the connector.

   1. Navigate to Setup -\> Wireless Networks and click on View connectors.

   2. Select the connector and under Instances, click on Add Services.

      ![Screenshot 2026-01-27 at 11.22.47 AM.png](/__attachments/a_7382b948acdd8ac3ed1c6382fc99859ab90245d06ab28f83a4f4b49608260abe/Screenshot%202026-01-27%20at%2011.22.47%E2%80%AFAM.png?cb=dffbf473697651550e4a2a6ad5eb6d99)

   3. Select local-firehose and click on Save.

      ![Screenshot 2026-01-27 at 11.23.38 AM.png](/__attachments/a_baeb76178414939f9e15a547bdcbe7ba47c6819a4cb83e272d1b5fba14546769/Screenshot%202026-01-27%20at%2011.23.38%E2%80%AFAM.png?cb=690c10fe340b4afafbdbe96d30272072)

5. Activate Securitas Healthcare RTLS Partner App

   1. Navigate to the Partner Apps tab within the Spaces Dashboard

      ![Screenshot 2026-01-27 at 11.25.10 AM.png](/__attachments/a_d81fcef31a5766526e1752e7f3f50b7c6bcd386ce28ae87467ab038ba5335564/Screenshot%202026-01-27%20at%2011.25.10%E2%80%AFAM.png?cb=ed45d2c04054c6bac025c97b4abe5253)

   2. Click on Apps by Healthcare and Search for Securitas and click on the app tile. The app details should show up in a window to the right.

      ![Screenshot 2026-01-27 at 11.49.18 AM.png](/__attachments/a_e83fb21294405fb0701bededb69c0418bc21b1529cfccb3a91857802ccaa9072/Screenshot%202026-01-27%20at%2011.49.18%E2%80%AFAM.png?cb=a5ca8e60dccd3a681576f29caf1f20e6)

   3. Click on Activate to start the activation process.

      ![Screenshot 2026-01-27 at 11.50.46 AM.png](/__attachments/a_cd437de8ee093511f0a6a020a91fb04dc994570fbf0bf142eccf97a95fdf2242/Screenshot%202026-01-27%20at%2011.50.46%E2%80%AFAM.png?cb=7a0ca7276981992cdab92fa191cb841d)

   4. Review the permissions needed to activate the app and click on Grant Permission.

      ![Screenshot 2026-01-27 at 11.51.00 AM.png](/__attachments/a_b6e56f5300c2f77383c9ffa3509311147750b8a1070f963d106c39a83f00c5ad/Screenshot%202026-01-27%20at%2011.51.00%E2%80%AFAM.png?cb=929d98e72ace2c78c97775b9ac8b43e9)
   5. Select all the locations and click on Next

      ![Screenshot 2026-01-27 at 11.51.20 AM.png](/__attachments/a_0b449b4bbc15e8e39e259a6b0ab70c0c695b07facb2609224301de8758c25b90/Screenshot%202026-01-27%20at%2011.51.20%E2%80%AFAM.png?cb=0e7b207352b1edda3c403b618f96290b)
   6. Select all BLE devices and click on Select \& Activate.

      ![Screenshot 2026-01-27 at 11.51.31 AM.png](/__attachments/a_142dcfb9bd7fb26491245f5859ab5ed1946d80e8e383fb750ca822d740fff5ba/Screenshot%202026-01-27%20at%2011.51.31%E2%80%AFAM.png?cb=48b9dbcccf28c6d52731540f3709d7bb)
   7. Generate the activation key and copy it into a location for retrieval. The App is now activated within your Spaces Instance.

      ![Screenshot 2026-01-27 at 11.51.59 AM.png](/__attachments/a_10ca08fac5c862944023c32c939852254d3249dc0e1419a77876f831c278ab2c/Screenshot%202026-01-27%20at%2011.51.59%E2%80%AFAM.png?cb=b57a0cd20ed44b9acac2ad0f39239aa2)
   8. Navigate to Partner Apps tab on the dashboard and under Your Activated Apps section, verify if Securitas Healthcare RTLS app is visible.

      ![Screenshot 2026-01-27 at 11.52.13 AM.png](/__attachments/a_e00377b7b3612434083d16bf064d309f88d12c7773168754f5d448af075a818a/Screenshot%202026-01-27%20at%2011.52.13%E2%80%AFAM.png?cb=dde6b6d04d48ec91ce6eb302a1aec9b4)

### **Securitas Healthcare Installation Steps**

1. Deploy and Configure AeroScout Location Engine which consists of Engine Server (AES) and Engine Manager (AEM)

   For detailed deployment steps, refer to the [AeroScout Location Engine 5.8.x Deployment and User Guide](https://knowledgebase.securitashealthcare.com/Hospital_Solutions/AeroScout_Location_Engine/Product_Documentation/Location_Engine_5.8.x_Deployment_and_User_Guide)

   1. Login to the AeroScout Location Engine

   2. Navigate to Configuration-\> Server parameters -\> System Parameters

![Screenshot 2026-02-05 at 6.48.03 PM.png](https://runbooks.ciscospaces.io/__attachments/a_e1d010e7c77d2a4b6bb9d064c8b315df7bfab9d1abdee81caac1d7df6f7fea4a/Screenshot%202026-02-05%20at%206.48.03%E2%80%AFPM.png?cb=e45de3c73e14d066e605863f5970fe90)

c. On the System Parameters window, select the Cisco tab  
![Screenshot 2026-02-05 at 6.50.36 PM.png](https://runbooks.ciscospaces.io/__attachments/a_274d0cd996ab0edd8f9fe85d7e885a4dc4a58f1f950be564beb5eb49dee18335/Screenshot%202026-02-05%20at%206.50.36%E2%80%AFPM.png?cb=74bb1ca9b8580acea55b17ae95b2cdc2)

d. Under Cisco Parameters section, select Cisco Spaces and Click on Load token  
![Screenshot 2026-02-05 at 6.53.17 PM.png](https://runbooks.ciscospaces.io/__attachments/a_3df2a4b1d4e993c0f98446128aa638bbadc81053094a3deb81462d3cb9b13ce4/Screenshot%202026-02-05%20at%206.53.17%E2%80%AFPM.png?cb=debf6c19f899baa95dd673a0643b4830)

e. In the Load Token dialog, enter in an Instance Name. The Instance Name should be a name that describes the Activation. For example, 'River Campus' or 'University of xxx'. The Instance Name is added to the Activation information in Cisco Spaces after the Token Activation process.  
![Screenshot 2026-02-05 at 7.04.32 PM.png](https://runbooks.ciscospaces.io/__attachments/a_355297e1a77ef210b5de1852c1d08dafd645b59d91ad38c885333f5ccd64a55b/Screenshot%202026-02-05%20at%207.04.32%E2%80%AFPM.png?cb=e428afed6aabd67e7a4857594f6d97f5)

f. Paste the activation token copied from the Securitas Healthcare RTLS app activation process and click on Activate.  
![Screenshot 2026-01-28 at 4.18.50 PM.png](https://runbooks.ciscospaces.io/__attachments/a_098792402d329798af8215e9c01fc8f85e92d68a2a6612e557325fe56f4b7ee5/Screenshot%202026-01-28%20at%204.18.50%E2%80%AFPM.png?cb=c760699f3a2b920a7b4b7f0b8070e226)

g. View the Connection Information by clicking on the down arrow  
![Screenshot 2026-02-05 at 6.58.11 PM.png](https://runbooks.ciscospaces.io/__attachments/a_e95df968e9d293b3d7f3b23717ee924a60e1372f6ee06dce5e6224e5307ad1d8/Screenshot%202026-02-05%20at%206.58.11%E2%80%AFPM.png?cb=1a4907b152a2403be3423960fbea0f03)

h. Enter the Host Name / IP Address of the Primary Connector.

Note:

For HA, enter the Host Name / IP Address of the Second Connector, which cannot be the same as the Primary Connector.

For HA VIP Paired (recommended), enter the Virtual IP address in Primary Connector.  
![Screenshot 2026-02-05 at 7.07.29 PM.png](https://runbooks.ciscospaces.io/__attachments/a_5aed3d9796e891152fcd29e68d47619b378a7fa69efc3ef739e4e85f98193c6b/Screenshot%202026-02-05%20at%207.07.29%E2%80%AFPM.png?cb=5d4f883bd3bdd350128c1043b05d75b1)

i. Click on Test Connection to verify if the systems can connect. If a Secondary Connector is defined, its connection will also be tested.

![Screenshot 2026-02-05 at 7.08.46 PM.png](https://runbooks.ciscospaces.io/__attachments/a_1ac3886fa4485080342cf0cb79e4286ccb3b591b9751c4b7b6c042d3f2199de7/Screenshot%202026-02-05%20at%207.08.46%E2%80%AFPM.png?cb=e9aec0e24f72450e60d3e50f3e0d4cbf)

j. Click on Close. Click OK to save and close the System Parameters.

h. The Info tab will show the current status of the ALE communication between the Connector and Cisco Spaces.  
![Screenshot 2026-02-05 at 7.11.03 PM.png](https://runbooks.ciscospaces.io/__attachments/a_67338dfea6dfca29e61353e6467a64524b68fccc487fba0a60054c24369c520d/Screenshot%202026-02-05%20at%207.11.03%E2%80%AFPM.png?cb=575da2b97ca547858f03bf9513a50c4c)

k. Sync the network design by right-clicking on Site and selecting Sync Network Design From \> Cisco  
![Screenshot 2026-02-05 at 7.11.16 PM.png](https://runbooks.ciscospaces.io/__attachments/a_e3fa1c539e03fdc97f94789abbfd1050350796802fd2ab0ffcd740c97d445134/Screenshot%202026-02-05%20at%207.11.16%E2%80%AFPM.png?cb=816ac20ed8eacd1462e3ba4b43ca6caf)

2. Deploy and Configure MobileView Application

   For detailed deployment steps, refer to the [MobileView 5.8.x Install and Upgrade Guide](https://knowledgebase.securitashealthcare.com/?title=Hospital_Solutions/MobileView/Product_Documentation/MobileView_5.8.x_Install_%26_Upgrade_Guide)

3. Connect AeroScout to MobileView

   For detailed deployment steps, refer to the [AeroScout Location Engine 5.8.x Deployment and User Guide](https://knowledgebase.securitashealthcare.com/Hospital_Solutions/AeroScout_Location_Engine/Product_Documentation/Location_Engine_5.8.x_Deployment_and_User_Guide)

   1. To connect multiple MobileView clients to a single Engine Server, MobileView clients are connected by associating them to campuses. Campus association is only allowed for Admin users.

   2. Under the General Tab, check Allow Multiple MobileView sites association with Engine Campuses

   3. This will enable the Campus -- MobileView Association Option under Configuration.

   4. ![Screenshot 2026-01-28 at 4.19.46 PM.png](https://runbooks.ciscospaces.io/__attachments/a_032e6b2bb985282ff7f0cebed44791ccae82387371419271c1af7f054e1e63b3/Screenshot%202026-01-28%20at%204.19.46%E2%80%AFPM.png?cb=03593049f7ccc64c131d778b01e00bd5)
   5. MobileView Servers are added automatically after setting a gateway connection to the Location Engine Server

   6. Associate each MobileView Server (by IP address) with relevant campuses

   7. Each campus will send tag location reports only to its associated MobileView clients.

   8. Confirm MobileView Servers show as online (offline servers display as 'Offline'). Secured MobileView environments are indicated with a lock icon

      ![Screenshot 2026-02-05 at 9.17.52 PM.png](/__attachments/a_72fc17d76c1e0ebdf48f30dfac35012cace980429ad63d728c00be461a82cf8c/Screenshot%202026-02-05%20at%209.17.52%E2%80%AFPM.png?cb=7fdbabf1554b34cf120ab7fb0c2a1157)

4. [++Install Hugs on Mobileview Application++](https://knowledgebase.securitashealthcare.com/?title=Hospital_Solutions/MobileView/Product_Documentation/MobileView_5.8.x_Install_%26_Upgrade_Guide)

   1. The MobileView unified installer includes the MobileView platform and all applications. Hugs can be installed during the installation or after. Select People Applications and click Next.

      ![Screenshot 2026-01-28 at 4.20.07 PM.png](/__attachments/a_ae297ad5e8f8d43b86eb3003a91f5648afc70ed0a54a2004ca84e6ab9036be60/Screenshot%202026-01-28%20at%204.20.07%E2%80%AFPM.png?cb=28c7d9d42f1f1885ab16fcae88335e7e)
   2. Select the size option relevant to the expected site size. For further information refer to the [++MobileView Hardware Sizing Calculator++](https://knowledgebase.securitashealthcare.com/Hospital_Solutions/MobileView/Product_Documentation/MobileView_Hardware_Sizing_Calculator). Click Next. The Environment Verification Results window opens showing the verification results. Click Next.

   3. The Database Connection window opens. Connect to the SQL Server VM.

      ![Screenshot 2026-01-28 at 4.20.19 PM.png](/__attachments/a_4e2eea6fdc249c1a1ec4a55cc9e93830bc7a766b5beca941098003fd689523a6/Screenshot%202026-01-28%20at%204.20.19%E2%80%AFPM.png?cb=15dc595dcac8b33362fec5f892263c96)
   4. Configure the Application Server, Password Security and Gateway Connection parameters and complete the installation.

   5. Open your Web browser and connect to MobileView's URL. For example: ++http://\[MV_SERVER_IP\]/asset-manager-web/++

   6. Enter your User Name and Password and login to the application.

      ![Screenshot 2026-01-28 at 4.21.20 PM.png](https://runbooks.ciscospaces.io/__attachments/a_f74aff7dcdd3724b88fb74eefd17bc6e9645171c9ca0bb47ada2017f9e2703fc/Screenshot%202026-01-28%20at%204.21.20%E2%80%AFPM.png?cb=3beb115e31d0bdd12032c90ba7cb12f8)  
      ![Screenshot 2026-01-28 at 4.21.30 PM.png](/__attachments/a_f86a7eb3b635614b24543f120a08e541a6e9646cc7d2d90499575740067dc3ae/Screenshot%202026-01-28%20at%204.21.30%E2%80%AFPM.png?cb=811cc3eefa7eb44692a9cfbfd8b759a7)
   7. [++Hugs user guide++](https://knowledgebase.securitashealthcare.com/Hospital_Solutions/Hugs_Infant_Protection/Hugs_Infant_Protection/Product_Documentation/User_Guides/Hugs_5.8.x_User_Guide) provides instructions on how to use all aspects and features of Hugs on MobileView application software.

   8. Setup Instant Notifier (Alerts) in the MobileView application. The [++user guide++](https://knowledgebase.securitashealthcare.com/Hospital_Solutions/Hugs_Infant_Protection/Hugs_Infant_Protection/Product_Documentation/User_Guides/Hugs_5.8.x_User_Guide) for detailed steps on how to setup alerts.

*** ** * ** ***

## **INTEGRATION VALIDATION CHECKLIST**

* [ ] Validate that required ports (HTTPS 443, gRPC, and NMSP) are open between WLC, Connector, and AeroScout Engine.
* [ ] Confirm Securitas Healthcare RTLS Partner App has been activated in the Cisco Spaces Dashboard  
* [ ] Navigate to Partner Apps tab on the dashboard and under Your Activated Apps section, verify if Securitas Healthcare RTLS app is visible.  
![Screenshot 2025-12-09 at 6.32.11 PM.png](https://runbooks.ciscospaces.io/__attachments/a_cfed025d834abcce1e77f661bfd48b369e24f7fceae15a8af96a2d4f9a2497d5/Screenshot%202025-12-09%20at%206.32.11%E2%80%AFPM.png?cb=63b2369707db097fe165cf4eaf240399)

* [ ] Verify Local Firehose stream is active in Spaces Connector UI.  
  * [ ] Navigate to Setup -\> Wireless Networks and click on View connectors.
* [ ] Select the connector and under Instances, verify the last heard date and time on the Local Firehose.  
![Screenshot 2025-11-17 at 3.47.34 PM.png](https://runbooks.ciscospaces.io/__attachments/a_095b54cb9611705c2a7f284d2795e35457f1657cb0e0b4a2bc9e002e90d7fb9e/Screenshot%202025-11-17%20at%203.47.34%E2%80%AFPM.png?cb=ca2c5d11e1790daa865785aae237748e)  
* [ ] Verify that location hierarchy is consistent across Cisco Spaces, Location Engine, and MobileView.
* [ ] Verify all Hugs tags visible in Cisco Spaces *Detect \& Locate*  
  * [ ] Navigate to Detect and Locate on the Dashboard
  * [ ] Select the building and floor where the devices are placed
  * [ ] The TAG section should display the number of tags on the floor
* [ ] Click on the tag that shows up on the Map to see the information of the tag  
![Screenshot 2026-02-02 at 12.29.20 PM.png](https://runbooks.ciscospaces.io/__attachments/a_5c545fba94cc02919c7df8953e7ee6707f1572385eddac051937bbee33d57c15/Screenshot%202026-02-02%20at%2012.29.20%E2%80%AFPM.png?cb=254f8ad80da12e002cd7b30791269bdd)

* [ ] Verify all Tags are visible in Securitas Healthcare MobileView Application.  
  * [ ] On the Hugs homepage, review the "Available," "In Use Now," "Charging," "Available - Need Charging," and "Expired" counts. Click to see lists.
  * [ ] Confirm admitted infants and their tag IDs are visible. Look for "expired tag" icons.
* [ ] Click on the links under the Hugs Tags section to get more information on the tags. The In-use tags will give you more details on the Infant, the tag device details and location history.  
![Screenshot 2025-12-08 at 2.48.33 PM.png](https://runbooks.ciscospaces.io/__attachments/a_631629f27c4ede7144782f74512720ec5ce3abf48a60a53229548868a0dec039/Screenshot%202025-12-08%20at%202.48.33%E2%80%AFPM.png?cb=82e47398dd441b19f916fbb1ceaff4a8)  
![Screenshot 2025-12-08 at 2.54.48 PM.png](https://runbooks.ciscospaces.io/__attachments/a_8ae296728e234a4564c7f26d3503993b5ef86ed20a5dfb7dff12cf128032bae8/Screenshot%202025-12-08%20at%202.54.48%E2%80%AFPM.png?cb=8e43f8a449c792ad36d247f7ea431e9d)  
* [ ] To get a comprehensive list of all tags and their status, generate a Protected Tags Status Report. Click on the Reports Icons on the top, navigate to Instant Reports \> Protected Tags Status, select the options and hit generate. This report generates a list of infants and shows their tag battery level and their current location.  
![Screenshot 2025-12-08 at 3.03.34 PM.png](https://runbooks.ciscospaces.io/__attachments/a_1945da66eece1fc6e040e04c30eede8719856fe6cef55f39236e1451c2e89bda/Screenshot%202025-12-08%20at%203.03.34%E2%80%AFPM.png?cb=7fb12bacd42c84fe0b58274c0e082f06)  
* [ ] Verify that alerts (Tamper, Exit, Out-of-Unit) are setup and trigger correctly in MobileView.

*** ** * ** ***

## **CAVEATS AND TIPS**

### **Wi-Fi Coverage Dependency**

Tag visibility and alert reliability depend on sufficient 2.4 GHz Wi-Fi coverage throughout the monitored area. Conduct coverage validation before enabling alerts.

#### **Firewall Rules**

Outbound connectivity from the Cisco Spaces Connector (ports 443 and NMSP) is mandatory for data flow to the Spaces Cloud and AeroScout Engine.

#### **Map Consistency**

Floor maps and naming conventions must be consistent across Cisco Spaces, AeroScout Engine, and MobileView to ensure correct geolocation mapping.

#### **Clock Synchronization**

All systems (WLC, Connector, Engine, and MobileView servers) should use the same NTP source to maintain log accuracy and event correlation.

#### **High Availability**

It is recommended to deploy two Cisco Spaces Connector virtual machines as a VIP pair. While Active/Active HA is supported, deploying a VIP pair is strongly recommended for Securitas Healthcare deployments, particularly where BLE tag tracking may be required in the future. Migrating from Active/Active to a VIP pair at a later stage requires a Securitas maintenance window; deploying a VIP pair initially avoids future service disruption.

#### **MobileView Data Retention**

Event and audit log retention policies should align with hospital compliance requirements (HIPAA or local equivalents).

#### **RF Interference**

Avoid installing Exit Controllers or APs near strong LF emitters or metallic surfaces that can distort field strength detection.

*** ** * ** ***

## **TROUBLESHOOTING GUIDE**

This section provides a practical guide to diagnosing and resolving common issues that may arise during the deployment, configuration, or ongoing operation of the Cisco Spaces + Securitas Healthcare Infant Monitoring solution. It covers a range of potential problems, from connectivity and data flow to application performance and alert functionality. Before escalating an issue, it is highly recommended to review these troubleshooting steps and ensure all prerequisites and basic system health checks have been performed.

### **Hugs Tags are not visible in Cisco Spaces or MobileView Application**

This often occurs due to the tag being out of Wi-Fi range, not powered on, not properly enrolled in the Securitas Healthcare system, or a break in the data flow path from the Access Points through the WLC and Cisco Spaces Connector to the AeroScout Engine.

* Confirm the tag is powered on and actively within a known good Wi-Fi coverage area.

* Verify the tag's enrollment and activation status directly within the Securitas Healthcare system.

* Review Cisco Spaces Detect \& Locate for the tag's visibility.

* Confirm that the Cisco Spaces Connector is actively receiving data from the WLC and successfully forwarding it to the AeroScout Engine Server.

### **Real-time location updates are delayed or inconsistent**

This usually points to network latency, congestion, or resource limitations on one of the processing components (WLC, Cisco Spaces Connector, AeroScout Engine). High CPU/memory utilization on these servers can lead to processing backlogs and delayed updates.

* Observe if location updates are consistently slow or if tags occasionally exhibit jumping behavior on the map.

* Investigate network latency and packet loss between all critical components, including Access Points, WLC, Cisco Spaces Connector, and the AeroScout Engine.

* Review the resource utilization (CPU, RAM) on both the Cisco Spaces Connector and AeroScout Engine Server VMs. Consider allocating additional resources if they are consistently operating at high capacity to improve processing speed.

*** ** * ** ***

## **SUPPORT AND MONITORING**

### **Joint Support Model**

The Cisco Spaces Partner Ecosystem operates under a shared responsibility support model, ensuring issues are routed quickly to the team best positioned to resolve them.  

|---------------------------------------------------------------------|-------------------------------------------------------|
| **Responsibility Area**                                             | **Primary Owner**                                     |
| Cisco Spaces Platform, APIs, Network Integration                    | Cisco Spaces Partner Team                             |
| AeroScout / MobileView                                              | Securitas Healthcare Team                             |
| Joint Use Case Runbook Creation \& Maintenance                      | Cisco Spaces Partner Team + Securitas Healthcare Team |
| Cisco Space Partner App Validation, Listing, Marketplace Onboarding | Cisco Spaces Partner Team                             |

### **Support Workflow**

The workflow for identifying, triaging, and resolving issues follows a structured path designed to ensure accountability, consistency, and efficiency across Cisco Spaces and Partner teams.

#### **Issue Identification (Customer Initiated)**

An issue is detected in a Cisco Spaces--integrated deployment, such as:

* Location or telemetry data not visible in Cisco Spaces

* AeroScout/MobileView devices not appearing or updating

* Deployment, onboarding, or integration errors

* Unexpected application behavior or UI issues

The reporting party should capture:

* Time and date of occurrence

* Error messages or screenshots

* Affected sites, devices, or users

* Recent changes (network, configuration, upgrades)

* Business or clinical impact

#### **Triage (Primary Determination of Ownership)**

During triage, the issue is evaluated to determine its point of origin within the Cisco Spaces platform, partner application, or integration layer.

Using the responsibility tables defined above:

* Ownership is identified

* The appropriate Cisco Spaces or partner support teams are notified

This Runbook serves as the primary troubleshooting reference during this phase, helping to:

* Match observed symptoms to known issues and common failure scenarios

* Validate configuration and data flow expectations

* Determine whether the issue can be resolved through documented steps or requires deeper technical investigation and escalation

This structured triage process ensures issues are routed correctly, reduces duplication of effort, and accelerates resolution.

#### **Primary Support Routing**

For issues suspected to originate within Cisco Spaces:

* Open a Cisco TAC case

* Cisco TAC manages the case end-to-end and coordinates internally with the Cisco Spaces Partner Team as needed

##### Steps to Open a Cisco TAC Case

1. Log in to **Cisco Support** : <https://www.cisco.com/support>

2. Select **Open a Case**

3. Choose the relevant **Cisco Spaces product or service**

4. Provide:

   * Detailed problem description

   * Logs, screenshots, and timestamps

   * Customer site and Spaces instance details

   * Confirmation that runbook troubleshooting steps were completed

5. Submit the case and record the TAC case number for tracking

#### Securitas Healthcare Support

For issues related to AeroScout or MobileView applications, tags, or clinical workflows, Securitas Healthcare is the first point of contact.

Technical Support -- Securitas Healthcare

* Toll Free: +1-866-730-1620

* Direct: +1-866-731-8328

* Website: <https://www.securitashealthcare.com/infant-protection-lp>

The Securitas Healthcare support team will:

* Triage application-level issues

* Request logs or diagnostics as needed

* Engage Cisco Spaces Partner Team if integration-level assistance is required

#### **Resolution and Closure**

Once the issue is resolved:

* The owning team validates the fix with the reporting party

* Root cause analysis, corrective actions, and preventive guidance are documented

* Any new learnings, configuration updates, or escalation paths are incorporated into the runbook

This creates a continuous feedback loop, improving future deployments and reducing mean time to resolution.

*** ** * ** ***

## **FREQUENTLY ASKED QUESTIONS (FAQ)**

### **Can I use Cisco Meraki Access Points for this solution?**

This solution requires Cisco Catalyst (or Aironet legacy) Access Points managed by a Catalyst WLC. Meraki APs are not supported for this specific HUGS integration.

### **How much bandwidth is consumed between the on-premises environment and Cisco Spaces Cloud?**

Average bandwidth consumption is approximately 1 Kbps per Access Point, sustained. Actual usage may vary slightly based on AP count, telemetry frequency, and enabled services.

### **Does the system continue to function if connectivity to the cloud is lost?**

Yes. Tag telemetry ingestion and real-time location processing for critical use cases continue locally. However, management operations---such as map updates, configuration changes, and cloud-based analytics---are suspended until connectivity is restored. During this time, associated devices will not appear in the MobileView application.

*** ** * ** ***

## **REFERENCES**

* [++Cisco Spaces OS Runbook++](https://runbooks.ciscospaces.io/docs/cisco-spaces-runbooks-cisco-validated)

* <https://spaces.cisco.com/smart-space-builder/>

* [++Securitas Healthcare Knowledge Base++](https://knowledgebase.securitashealthcare.com/)

* [++Flexible Radio Assignment (FRA) and Redundant Radios++](https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-3/b_RRM_White_Paper/fra.html)

* [++RTLS Guidance for Cisco FRA and Cisco DNA Spaces with Stanley Healthcare++](https://knowledgebase.securitashealthcare.com/Hospital_Solutions/AeroScout_Location_Engine/Wireless_LAN_Vendors/Cisco/RTLS_Guidance_for_Cisco_FRA_and_Cisco_DNA_Spaces_with_Stanley_Healthcare)

* [Network Map Geo-Placement Best Practices](https://runbooks.ciscospaces.io/docs/guide-to-network-map-geo-placement-and-best-practi)

* <https://www.cisco.com/c/en/us/td/docs/wireless/spaces/config-guide/ciscospaces-configuration-guide/m-locations-and-maps.html#locations-and-maps>

* <https://www.cisco.com/c/en/us/td/docs/wireless/spaces/connector/config/b_connector_30/m-local-firehose.html>

*** ** * ** ***

## **FEEDBACK AND CONTINUOUS IMPROVEMENT**

This runbook is a living document that evolves based on real-world deployments and customer feedback. Your input helps us improve accuracy, clarity, and completeness of the runbook.

**Submit Feedback:** [Runbook Feedback Form](https://form.asana.com/?k=FV-k6EGfjuDd3qN7RxaZcA&d=5557457880942)

**Email:** [ciscospacespartnerteam@cisco.com](mailto:ciscospacespartnerteam@cisco.com)

For technical support issues, please follow the Support and Escalation Process outlined in this document.

---
language: "en"
---
# IoT Device Guidance for MT EoS

Cisco has announced EOS for Meraki MT Sensors. To help Cisco Meraki customers that use MT devices for delivering sensors-based use cases migrate easily, customers can use this guide to explore alternate 3rd party sensors available on the Cisco Spaces IoT Device Marketplace.

There is currently no direct alternative sensor from Cisco, nor a successor planned. We encourage customers to explore Cisco Spaces and third-party alternative sensors outside of Cisco.

Cisco Spaces supports a validated ecosystem of third-party sensors which can be found at <https://ciscospaces.io/devicemarketplace/home>  
![image-20260604-202836.png](https://runbooks.ciscospaces.io/__attachments/a_0f4e174f570562d249fcb340b8b27881849b358362db3d409b0ddd5343c3f58d/image-20260604-202836.png?cb=0f2b39c93b14132b6ff77a668a6804b5)

## Comparable Sensor List

|           **Meraki MT Sensor**            |                                                                                                                                    **Spaces IDM Sensor**                                                                                                                                    |
|-------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| MT10 - Temperature and humidity sensor    | Minew -- S1 Ela Innovation -- Blue PUCK T EN12830 Kontakt.io - Temperature Pro \& Lite                                                                                                                                                                                                      |
| MT11 - Indoor temperature probe sensor    | Minew - S1 with External Probe Ela Innovation - Blue PUCK T-PROBE Kontakt.io - Temperature Pro with Probe​                                                                                                                                                                                  |
| MT12 - Indoor water leak detection sensor | Coming Soon                                                                                                                                                                                                                                                                                 |
| MT14 - Indoor air quality sensor          | Smart Sensor Devices - Hibou Air Quality Sensor​                                                                                                                                                                                                                                            |
| MT15 - Indoor air quality and CO2 sensor  | Smart Sensor Devices - Hibou Air Quality Sensor​                                                                                                                                                                                                                                            |
| MT20 - Indoor open/close sensor           | Coming Soon                                                                                                                                                                                                                                                                                 |
| MT30 - Smart automation button            | For Automation use cases:​ * Kontakt.io - Asset Tag 2 and Asset Tag 2 Mini​ * Securitas Healthcare - T22 Tags​ * Moko Smart - H3 Card Beacon​ For Duress use cases:​ * Securitas Healthcare - T23 Tag​ * Centrak - Multi mode BLE Tag​ * Kontakt.io - Smart Badge 3 and Smart Badge 3 Mini​ |
| MT40 - Smart power controller             |                                                                                                                                                                                                                                                                                             |

---
language: "en"
---
# IOT Services Deployment, Monitoring, and Troubleshooting Guide

## OVERVIEW

Cisco Spaces is the next generation outcomes cloud from Cisco, which builds on top of years of industry leading indoor location solutions and adds in multiple new components to deliver an end-to-end solution to solve business use cases through a cloud and subscription-based delivery model. It is designed to help organizations understand how people and things move and interact within their physical spaces, enabling them to make data-driven decisions to improve customer experiences, operational efficiencies, and business outcomes. It provides a single point of entry for all location technology and intelligence through a single dashboard interface. Cisco Spaces delivers the industry's most scalable location-based services platform, while being compatible across existing Cisco Aironet^®^ wireless LAN Controllers, Cisco Catalyst^®^ 9800 series wireless LAN Controllers, select Cisco Catalyst^®^ 9000 series of switches, Cisco Meraki^®^ infrastructure (including MV Cameras), as well as select Cisco Collaboration endpoints and support for a wide range of deployment options. In addition, Cisco Spaces can consume and control the IoT radios on select Wireless Access Points to deliver new IoT use cases and enable true Smart Spaces Solutions.

In addition to consuming data from the network infrastructure, Cisco Spaces processes, filters and cleanses the data, provides toolkits to act on this data and makes this data accessible to partners - Independent Software vendors, enterprise software as well as solution partners for delivering business outcomes. There is also an entire ecosystem of third party IoT devices (known as Cisco Spaces IoT Device Marketplace) which can be controlled by IoT gateways which are installed on Wireless Access Points and Catalyst switches via the Cisco Spaces dashboard. Cisco Spaces also enables customers to send data to multiple software partners which are available in the Cisco Spaces Partner App Center to integrate the Cisco solution with a different third-party solution which can be focused on verticals like Healthcare, Manufacturing, Retail, Higher Education or could deliver dedicated use cases like High Value Asset Tracking, Patient and Staff Safety, Employee Experience and Customer Management, Space Utilization, Environmental Monitoring and Compliance etc.

*** ** * ** ***

## SUPPORT AND ONBOARDING

Please follow the link below to find out about the different ways to get support for Cisco Spaces.

[++Support Info Link++](https://activate.dnaspaces.io/hubfs/Assets/CiscoSpaces-SupportUpdate.pdf?__hstc=105720540.52aaa4a978f36be89855b002cb35bfc4.1729705805310.1729705805310.1729705805310.1&__hssc=105720540.1.1729705805310&__hsfp=3667649010)

*** ** * ** ***

## CISCO SPACES IOT SERVICES FOR BLE

Cisco Spaces IoT Services is a component of the Cisco Spaces platform that focuses on integrating and managing Internet of Things (IoT) devices to provide enhanced insights and automation capabilities within physical spaces. The IoT Services component allows organizations to connect various BLE/IoT sensors and devices to the Cisco Spaces cloud, enabling them to collect, analyze, and act on data from these devices.

Key aspects of Cisco Spaces IoT Services include:

1. Device Management: Simplifies the onboarding, configuration, and management of IoT devices. This includes provisioning new devices, monitoring their status, and managing firmware updates.

2. Integration with Cisco Infrastructure with a multi-vendor multi technology gateway: Leverages existing Cisco wireless and networking infrastructure to support IoT device connectivity by deploying multi-vendor gateways on the APs and switches. This integration reduces the need for additional hardware, dedicated point solutions and gateways, reduces costs and TCO, and simplifies deployment.

3. Data Collection and Analytics: Collects data from connected IoT devices, such as environmental sensors (temperature, humidity, air quality), occupancy sensors, and asset trackers. The platform then analyzes this data to provide actionable insights.

4. Event and Rule Engine: Allows users to create custom rules and events based on data from IoT devices. For example, users can set up alerts for temperature thresholds, motion detection, or equipment usage patterns, triggering automated actions or notifications.

5. End to End Monitoring and Support: Cisco Spaces monitors for any anomalies and failures across the infrastructure, the cloud and APIs to generate proactive alerts and warnings as well as provide an end to end dedicate support channel for resolving any issues seen or reported.

6. APIs and SDKs: Provides APIs and software development kits (SDKs) for developers to build custom applications and integrations. This enables organizations to tailor the platform to their specific needs and integrate with other enterprise systems as well as third party ecosystem ISVs.

7. Use Cases: Supports a wide range of use cases across various industries, such as:

   * Smart Spaces: Optimizing energy usage, enhancing security, and improving occupant comfort.

   * Healthcare: Monitoring environmental conditions, tracking assets and medical equipment, prevent loss and ensuring patient/staff safety.

   * Retail: Managing inventory, optimizing store layouts, and enhancing customer experiences.

   * Manufacturing: Monitoring equipment location, ensuring worker safety, and improving operational efficiency.

Cisco Spaces IoT Services provides a comprehensive solution for leveraging IoT technologies to gain deeper insights into physical spaces, automate processes, and improve overall efficiency and effectiveness in various operational contexts.

### How to use this guide

In this guide, we will be focusing specifically on IOT services -- how to deploy, monitor and troubleshoot the network to be able to consistently deliver these outcomes. This guide is tailored for an IT audience with a foundational understanding of network infrastructure, typically someone with administrative access to Spaces dashboard, the wireless and other network equipment in the enterprise, who oversees monitoring, maintaining and troubleshooting the network to make sure the business outcomes are not impacted.

This guide will be broken into three main sections:

1. Day 0 -- This section will cover things that the IT teams should understand ahead of time to deliver a successful deployment. It would cover topics such as reference architectures, best practices for Access Point (AP) deployment, recommended minimum software releases, supported AP models and Wireless LAN controller (WLC) deployment modes etc.

2. Day 1 -- This section will focus on some best practices that should be followed during the setup and will cover some different examples of use cases. It is meant to provide a good understanding of what ideal scenarios may look like for long term deployment success.

3. Day N -- This section will cover monitoring and troubleshooting that should be done by IT teams for avoiding any issues, but what troubleshooting to do if there are issues seen.

Throughout this guide, we will include Cisco recommendations, best practices, notes, and cautions where relevant. Happy reading!

*** ** * ** ***

## DAY 0 - BLE DEPLOYMENT PREREQUISITES AND BEST PRACTICES

### Understanding BLE as an IOT technology

Bluetooth Low Energy (BLE) is a pivotal IoT technology designed for short-range, low-power wireless communication, making it ideal for connecting a multitude of smart devices. BLE's energy-efficient design allows for prolonged battery life in IoT devices such as sensors, beacons, and wearables, facilitating seamless data exchange and real-time monitoring. Its capability to operate in the 2.4 GHz ISM band enhances its utility in creating interconnected ecosystems for smart buildings, healthcare, industrial automation, and retail environments and more. Cisco's WiFi6 and newer Access Points all support BLE and allow customers to leverage that existing infrastructure

A key difference between BLE and traditional Bluetooth is the power consumption. In Bluetooth, the primary device connects to the secondary and maintains the connection, which while is lot more energy greedy than BLE, allows for use cases such as VoIP. BLE on the other hand is generally advertisement based but also allows for some connections to be established for exchanging small amounts of data. In BLE, the primary detects the secondaries broadcast, and (if interested) connects, retrieves data, and closes the connection (few milliseconds, energy efficient, exchange small amounts of data)  

|       **Feature**       |       **BLE**        |
|-------------------------|----------------------|
| Max range (theoretical) | \< 100 m             |
| Data rate               | 1 Mbps 2 Mbps (BLE5) |
| Throughput              | 0.27 Mbps            |
| Time to send data       | 6 ms                 |
| Power consumption       | 0.01 to 0.5 W        |

A typical question that comes up when IT teams are asked to turn on BLE based use cases is whether it would interfere or cause issues with existing 2.4GHz Wi-Fi network. The fact is BLE is built to be Wi-Fi friendly. As mentioned before, for the most common use cases, such as location tracking, telemetry reading etc. only BLE advertising is sufficient. BLE advertisements only happen on non-Wi-Fi Channels 37, 38 and 39 which do not interfere with Wi-Fi channels 1, 6 and 11 which are typically used for 2.4GHz in the enterprise.  
![image-20260319-181345.png](https://runbooks.ciscospaces.io/__attachments/a_9ac104f09f4c8403c4a0a46ce7efb33e792df328a507eab33ab896ec9d7fa0f9/image-20260319-181345.png?cb=461332231fa0e0560e65ef36a67652a8)
Channels colored in orange are used for BLE advertisements

When BLE connection is indeed made (for example: to read specific BLE telemetry or connect to Meraki Things device or to upgrade the firmware of a BLE device etc.), Wi-Fi can be impacted, but adaptive frequency hopping reduces interference.

*Cisco Recommendation*

The abundance of devices on 2.4GHz is something that should be considered and Cisco's recommendation is to move any critical Wi-Fi SSIDs to use 5GHz or 6GHz band wherever possible.

### Cisco Spaces IOT Services Architecture

![Screenshot 2026-03-19 at 11.19.19 AM.png](https://runbooks.ciscospaces.io/__attachments/a_120f2d3c6a15cac4577451386dcba8223061071671371e79e3ed12eefc373b0d/Screenshot%202026-03-19%20at%2011.19.19%E2%80%AFAM.png?cb=15fec92d15e2f1ada29872b1429ce9f2)

*Note*

As of the writing of this guide, the direct MQTT for BLE data from Meraki MR APs to Cisco Spaces cloud is still under Quality Assurance but is expected to be available shortly. Hence, it has been added in this guide.

Cisco Spaces IOT Services supports both Catalyst and Meraki based deployments, which few key differences in the features and outcomes delivered. We will review those next, but first, let's quickly understand some key components of the IOT Services architecture.

* Cisco Spaces Connector - Cisco Spaces Connector is a software component (available only as a VM -- deployable on VMWare ESXi, Microsoft Hyper-V and as an AMI on AWS) that facilitates the integration of Cisco Spaces with a customer's on-premises infrastructure. It acts as a bridge between the Cisco Spaces cloud platform and the customer's local network, allowing for seamless data exchange and enabling the various location-based services and analytics that Cisco Spaces offers.

* Catalyst Access Points -- Act as bi-directional multi-vendor BLE gateways allowing not only for scanning and/or transmitting BLE signals, but also the ability to configure and manage BLE devices that have been previously claimed in Cisco Spaces.

  * Scan and forward BLE advertisements and payload directly from AP to connector (GRPC)

  * Receive configuration and management commands from Spaces via connector (GRPC)

  * Initiate downstream BLE connection with BLE tags and push configuration and firmware (i.e., configuration and management of BLE tags from IOT Device Marketplace)

* Catalyst 9800 WLC - The Catalyst 9800 controller is the single point for configuring and managing a wireless network and access points. The Catalyst 9800 controller configures and manages APs using the CAPWAP protocol. The Catalyst 9800 controller receives BLE configuration from Cisco Spaces over NETCONF and passes the configuration to AP over CAPWAP. The feedback path from the AP to the wireless controller is through CAPWAP, and from the Catalyst 9800 controller to Cisco Spaces through Telemetry data logger (TDL) telemetry streaming. The gRPC configuration from Cisco Spaces also goes through Catalyst 9800 controller and from there to the corresponding AP. The configuration sets up the gRPC channel between the AP and Cisco Spaces.

* Meraki Access Points -- Act as uni-directional BLE gateway. They can scan and/or transmit BLE signals (configured via Meraki dashboard) but Cisco Spaces cannot currently use Meraki APs to push configuration down to 3^rd^ party BLE devices, even if they are claimed in Cisco Spaces.

  * Scan and forward BLE advertisements and payload directly from APs via MQTT -- arrives to Spaces in near real time

* Meraki Dashboard -- The Meraki dashboard is the configuration pane of glass for all APs. While raw BLE data can be sent directly from Meraki APs to Cisco Spaces, processing of BLE data from those APs is done in Meraki cloud.

  * Forwards calculated BLE location from dashboard via Scanning API -- which can be delayed, normally in the range of 3-5 minutes, but there is no specific limit to how long can be that delay.

* Spaces Cloud -- Provides all the functionality in the cloud. With respect to IOT Services, the Spaces cloud delivers several functionalities, such as:

  * Receives raw BLE messages from Meraki and Catalyst

  * Leverages Network maps from DNAC / PI. Or customer can use CAD files + Spaces AP Auto Locate as a replacement for network maps and create Cisco Digital maps.

  * Merges location hierarchy from multiple sources like DNAC / PI / Webex / Meraki into a common model for use across all native and partner apps

  * Calculates the x/y for tags using Cloud Location Engine for Catalyst and receive calculated location for Meraki

  * Onboard, group, manage, configure and view BLE devices using IOT Services framework

  * Control and manage infrastructure

* 3^rd^ party Apps -- To carry IOT data in Cisco Spaces IOT Services solution, Cisco offers two options for approved 3^rd^ party partner applications:

  * Cloud Firehose API (Preferred) -- Carries all data end to end with full scale and visibility. Examples of data available -- maps, location hierarchy, BLE, Wi-Fi, UWB, location X/Y, identity and more.

  * Local Firehose API (for select partners) -- carries subset (minimal) data.

*Take Caution*

Specific Firewall Ports need to be opened to make sure the data can flow correctly. Please validate and confirm the following ports are opened correctly on Catalyst environment. The following ports need to be opened to allow for the basic functionality of Cisco Spaces. In addition to basic functionality, additional ports need to be opened for IoT Services  
![Screenshot 2026-03-19 at 11.28.24 AM.png](https://runbooks.ciscospaces.io/__attachments/a_5a73f7ed05e3fb45c11c3fdf704d9616ab5eca4e80192091fc8b4e3e7f06008b/Screenshot%202026-03-19%20at%2011.28.24%E2%80%AFAM.png?cb=da8d32aaf6ebd1b5680db723c37857ce)

**Table of Ports Needed**  

|                 Normal Operations                  |            IOT Services            |
|----------------------------------------------------|------------------------------------|
| 16113 TCP (NMSP)                                   | 8004 TCP (TDL)                     |
| 830 TCP (NETCONF) -- only for Catalyst Controllers | 8443 TCP (IOX App Install)         |
| 22 TCP (SSH)                                       | 8000 TCP (gRPC and REST API calls) |
| (optional) 2003 UDP (FastLocate)                   |                                    |

### Hardware / Software Compatibility Matrix

Cisco Spaces IOT Services works best with specific versions of software. Below lists the different releases and AP models that are tested and supported for IOT Services. Anything not listed should be considered untested and officially unsupported. Please reach out to your Cisco Spaces specialists or Cisco account teams if there are any questions and we can assist with specific guidance.

|-------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Catalyst 9800 Hardware        | 9800-CL, 9800-L, 9800-40, 9800-80                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Catalyst 9800 Software        | While IOT Services has been supported since IOS-XE 17.3.1, Cisco has added new features and identified/resolved multiple critical known defects related to BLE. Hence, for any production deployment, customers need to deploy minimum 17.9.6 or 17.12.4 once available. Until those releases are available, recommendation is to use either 17.9.5 or 17.12.3. Other releases can lead to customers hitting the same defects leading to poor experience.                                                                                                                                                           |
| Catalyst 9800 Deployment Mode | · Not supported on Cisco Embedded Wireless Controller on Cisco Catalyst Access Points (Cisco EWC-AP) · Not supported on Catalyst 9800 Controller running on Catalyst Switches in SD-Access mode (ECA). This limitation is looking to be addressed in the future.                                                                                                                                                                                                                                                                                                                                                    |
| Spaces Connector              | Spaces Connector 3 (May 2024) While IOT Services was supported on Connector 2.3, that version has now been deprecated so all customers need to migrate to connector 3.x                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Catalyst AP Models            | Internal Antenna Models: The following APs are supported: 9105, 9115, 9117, 9120, 9130, 9136, 9162, 9164, 9166. However, for better BLE performance, customers are highly encouraged to leverage the following AP models for mission critical use cases due to better BLE radio performance - Catalyst 9120, 9130, 9136, 916x External Antenna Models: Only ANT-9101, 9102, 9103 and 9104 antennas have a dedicated IOT element in the antenna allowing for BLE signals to properly be transmitted and received at the IOT radio for Catalyst APs. All other antenna types haven't been validated and may not work. |
| Prime Infrastructure          | 3.8 MR1 and later                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Catalyst Center               | Release 2.1.1 and later                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Meraki                        | Release r30 and later                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |

### Things to keep in mind pre-deployment

* For IOT services to function normally, Spaces requires APs to be placed correctly on Maps and having those Maps added. This not only required for accurate location calculation but is also important for further systems in the data pipeline that require location of BLE devices. Customers can either:

  * Leverage CAD based Spaces Digital Maps with Any Locate to automatically place APs on the floor map, or

  * Catalyst Center or Cisco Prime Infrastructure based maps

* Always use the latest Spaces connector versions. All the services in Spaces Connector 3 run as individual docker containers and can be upgraded inline without major downtime. Best practice is to start with the latest versions available at deployment and check once a month for any new upgrades and plan for upgrade when possible. This is applicable to all connector services, including IOT Wireless, Local Firehose etc.

* Always use the latest IOX application for the Access Points. The IOX application can be upgraded from Spaces dashboard directly. Best practice is to start with the latest versions available at deployment and check once a month for any new upgrades.

* While any BLE tag from any vendor can be supported in Spaces, that statement comes with a large caveat. Technically, any BLE device that is heard by the APs will be heard in Spaces, however, we have seen many instances of customers running into issues such as poor or highly inaccurate locations due to device misbehaviors. For example, a BLE device may not be sending an iBeacon frame out correctly, or it is sending the packet at extremely low power so not enough APs can hear it, or that it is using some custom firmware that Cisco has no idea about etc. As many random BLE tags can behave very differently, and as Cisco has no control of device behavior, it is not possible for Cisco to provide any location accuracy guarantees.

* For location and device level support, Cisco Spaces fully supports devices that are part of the [Cisco Spaces IOT Device Marketplace](https://dnaspaces.io/devicemarketplace/home) for applications. If you or someone on your behalf is placing an order directly with the IDM device vendor, remember to make sure the vendor is made aware to provide devices compatible with Cisco Spaces and running the Cisco BLE SDK on the device.

  * If you decide to choose to use a device from a different vendor or a device that is not running Cisco BLE SDK, then we suggest you first validate the location accuracy with those tags in a smaller setup with limited devices in few different locations first. Only if the location accuracy and tag behavior is acceptable to your use case should you go forward with in for any production use cases. Cisco Spaces can only provide best-effort location calculation for such devices which can range anywhere from good location accuracy to extremely poor accuracy.

* Remember to keep all the devices in NTP sync correctly otherwise it can lead to errors.

* For HA on Spaces Connector 3.x, you must configure the connectors in a Virtual IP (VIP) Pair. The two connectors need to be on the same Layer 2 subnet for VIP based HA to work.

* If the Cisco Spaces: Connector is an Amazon Elastic Compute Cloud (EC2) Instance from Amazon Machine Images (AMI), ensure that the wireless controller and connector are in the same virtual private cloud (VPC). Ensure that the wireless controller has a private IP address so that the security group of connectors does not block the traffic, allowing enabled IOT streams to function. Permit all the TCP traffic at the Virtual private clouds (VPC) level so that the Telemetry Data Logger (TDL) is established without any issues.

* Netconf must be enabled on the Catalyst 9800 WLC, and the credential provided to Spaces must have full privilege to run Netconf commands on the WLC. Remember to add these commands to the WLC running config before adding WLC to Spaces.

    aaa new-model
    aaa authentication login default local
    aaa authorization exec default local

* For Meraki based network, remember that the scanning API can provide location updates that can be delayed. Cisco Spaces is leveraging that same API for location information, so if there are mission critical / time sensitive use cases that need the location calculation with quick update rate, understand that there may be limitations in what is realistically achievable. For Catalyst networks, Cisco Spaces calculates the location from raw data in real time.

* For Meraki based networks, having a lot of MT devices can impact the BLE performance of MR Access Points as MT devices require BLE connection to be established and during that time, the BLE radio is sharing resources.

* In general, for any deployment, if there is a lot of congestion on 2.4GHz band -- either due to existing Wi-Fi deployment or other sources of interference, BLE performance will be impacted. It is recommended to move critical Wi-Fi to non-2.4GHz band. In general, BLE tags are generally going to advertise frequently so APs will catch some of the messages. So for the most part, the use case may not be heavily impacted, but customers should understand the RF behavior in their space and set expectations accordingly.

* Plan for correct scale and deployment size of Spaces Connector. See details next.

### Cisco Spaces Connector Scale and Size Guidance

While the Spaces Connector 3 VM is highly scalable and created for high performance, it is important to size the VM correctly for the scale and use cases selected. We offer three ready-made variations of the resource combinations for the connector: Standard (2vCPU, 4 GB RAM), Advanced1 (4vCPU, 8GB RAM) and Advanced2 (8vCPU, 16GB RAM). However, at the end of the day, it is still just a VM so customers can always simply add more resources if needed very easily. That is generally not going to be needed but is an option depending on the load on the VM. Note that for HA, both the active and standby connectors need to have the same exact resource specification.

For customers looking to understand how to best size their connectors, there are few things to understand:

* Ideally, you will be fine until the overall CPU / Memory doesn't go above 75%. Anything more than that and you will start to run into issues like BLE messages getting dropped, excessive lag and delays, failure to push configurations etc. and need to scale up. We will cover how to monitor for these metrics in the Day N section of the guide.

* All services contribute to the load on the connector. So, depending on the number of services turned on, the load will grow for the same network. For example, if you have only IOT Wireless service with 500 APs running BLE, a connector may be running at 50% CPU, but if you turn on Local Firehose, the connector may jump to 70%. Adding Hotspot or IOT Wired may make it go to 95%, even though the number of APs is still 500.

* The connector load is also dependent on the number of BLE messages (scans) that are being processed. For the same example above, a customer with 500 APs in say, a hospital with limited BLE devices may hear 15K BLE messages per second across all APs. But if it's an airport or a venue with lots of devices continuously moving in and out with rotating mac addresses, the connector may be processing 30K messages per second.

* Remember, number of APs, number of BLE messages, services turned on -- all contribute to the load on the connector and need to be considered when sizing the connector.

If the only services in use are Service Manage and IOT Wireless, then a typical guidance that customers can use as a reference to choose the appropriate size to go with. Remember that this is only a guidance, and every deployment is different and other services can have an impact.

**Advanced2 Connector**

* vCPU: 8

* Memory: 16GB

* Disk Space: 120GB

*Cisco Recommendation*

Cisco recommends starting with at least Advanced1 spec and then monitor for key CPU, memory and message rate metrics available from Spaces dashboard and deciding to scale up to scale down. Always make your decision based on actual usage of the connector resources and re-evaluate this whenever making changes such as adding more load or services.

#### Additional considerations

Other than the load of the network, customers should also consider the uplink connectivity as well as the bandwidth available to the connectors to make sure BLE deployments can be successful.

For connectivity, Cisco expects customers to have a stable internet connection between connectors and the cloud. If the link is unstable or intermittent, then customers should also additionally monitor for connection drops (*Setup \> Wireless Networks \> View Connector \> Click on Connector Name \> Metrics \> Service Manager \> Control Channel Status* ) and run connectivity test from Connector as explained [here](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/connector/config/b_connector_30/m-troubleshooting.html). If the connection is dropping more than once every 15 minutes, then it is not a stable uplink and can result in various issues such as failure to push configuration, mismatched configurations, delays etc. Customers are recommended to move the connector to a more stable uplink in that case.

For bandwidth, Cisco expects customers to have an uplink of at least 100Mbps for best performance. If the bandwidth available is low, customers should additionally monitor the packet drop rate from the connector as well as the connection drops. Depending on the number of BLE messages being processed and sent to the cloud, a low bandwidth link will result in the link choking and delays or messages dropped.

### Best Practices for AP Deployment and Tag config for Location

The same AP deployment best practices that have always held true for RTLS continue to apply. Propagation of BLE signals is like 2.4GHz Wi-Fi signals.

* Have at least one AP per 2500 sq feet (230 sq m). Make sure APs have BLE radio turned on and is either in scan mode or dual mode to hear BLE beacons.

* Have APs on the edges of the floors and then covering inside.

* Create a convex hull area around the area with BLE devices.

* Create inclusion and exclusion zones in the maps imported in Spaces.

* Place APs on maps accurately and if antenna orientations are available, they should be accurate on the source (PI or Catalyst Center)

* A minimum of 3 or more APs should hear BLE devices with an RSSI of -75dbm or higher

* For BLE tags, prerequisites for location accuracy are:

  * Use iBeacon profile whenever possible

  * Best accuracy is achieved when devices are using Cisco BLE SDK (part of Cisco Spaces IoT Device Marketplace) and those devices are claimed in Cisco Spaces

  * Run accuracy test in Spaces to understand the expected accuracy ahead of time for any tag before deploying it across a large use case

* A BLE tag with a typical transmit power of -12dBm has a typical max range of 65 ft (20 m). That also will vary with the physical characteristics of the deployment location. Hence, it's highly recommended to have at least a few APs within 50 ft of the tag for best coverage. If the tag is not heard properly, IDM devices are able to be configured using IOT Services and Catalyst APs. Customers should bump up the configured transmit power of those tags and consider updating the transmit frequency to improve the BLE performance of the tag (downside being increased battery consumption).

![image-20260319-211130.png](https://runbooks.ciscospaces.io/__attachments/a_a0205ab40d299680fa73e4dcf1aa0db0f2a5ce9707e3a1b3602275b663d089ff/image-20260319-211130.png?cb=fa09fdc37d9eb14fdb64ff892768330b)

*** ** * ** ***

## DAY 1 - SETUP VALIDATION, BEST PRACTICES FOR EXAMPLE USE CASES

Welcome to Day 1. You have decided to go ahead and start using Cisco Spaces IOT Services. You've reviewed the prerequisites, things to keep in mind and have setup the wireless infrastructure for delivering successful BLE based outcomes. This section will go over some of the best practices and things to keep in mind during the setup process, understand what to look for a successful validation, as well as provide some additional guidance for specific types of use cases.  
*Note*

This guide will not cover the actual steps to turn on IOT Services. For configuration steps, please refer to the configuration guides [here](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-services-wireless/b_iot_services.html) and [here](https://www.cisco.com/c/en/us/support/wireless/dna-spaces/products-installation-and-configuration-guides-list.html).  
*Note*

The validation steps here are expected to be used for after the configuration is completed to make sure things are working as expected. Customers are expected to be able to use these as a reference to do troubleshooting, but they should not need to run these if the prerequisites are met before and IOT services is setup correctly as per the configuration guides.

### Validation of end-to-end connection

#### Validation of Connector

1. Validate that the connector status is up, all the services such as IOT Wireless, Local Firehose etc. are up and running the latest available versions. If HA is configured, then validate the HA / VIP status.

![Screenshot 2026-03-19 at 2.49.44 PM.png](https://runbooks.ciscospaces.io/__attachments/a_0c07baecb626d6f8ef406921c302c89deb3ff7e8d88300d513132142331ece75/Screenshot%202026-03-19%20at%202.49.44%E2%80%AFPM.png?cb=f7534b8bf42135a4fbc588baf12a447e)

2. Validate proxy (if used) and NTP and DNS details on the connector UI. Often times, customers don't realize is that data transfer would run into failures with NTP, DNS and proxy issues. While Spaces connector fully supports proxies, it's important to understand that configurations of proxies need to be done correctly otherwise it leads to data failures.

3. Validate the IOT Wireless service health from the connector UI. Make sure the heartbeat is recent, confirm the Active GRPC counts and confirm the incoming and outgoing messages are updating.

![image-20260319-215604.png](https://runbooks.ciscospaces.io/__attachments/a_dfd8b8fc93debeab793eaad3be2cd9a60333a3c6edd4964ae42b32dfe20ddeee/image-20260319-215604.png?cb=55b756a65dc3b711eb4704cd99ba82c6)

4. Open the details of the IOT Wireless Service and confirm there are no auth failures or error counts continuously increasing. On the same UI page, you would also be able to confirm all the WLCs that have BLE / IOT Streams turned on, their status, last heard time, APs and per-AP BLE counters.

#### Validation of AP

1. Validate that the IOX app (if used), floor beacon channel (gRPC), AP beacon channel (TDL) are all up for all APs. Floor beacon channel should be last heard within the last few seconds, AP beacon channel should be last heard within 2 hours and IOX app channel should be heard within last few seconds.

![Screenshot 2026-03-19 at 3.01.07 PM.png](https://runbooks.ciscospaces.io/__attachments/a_7b0ea75768b8153511252a5756fd7ca8042073417b221ddd701ac7d706372570/Screenshot%202026-03-19%20at%203.01.07%E2%80%AFPM.png?cb=3fc0afa91e8d184c477b2496ca5277f8)

If Step 1 is showing all correct, then the additional commands below aren't needed. But, for additional reference for IT teams, we are listing CLI commands that can be used for additional validation and troubleshooting.

2. Verify connection between the AP and the connector is valid. State should be Ready and URL should be the connector on port 8000.

![image-20260319-220243.png](https://runbooks.ciscospaces.io/__attachments/a_628643a8bfe517a82777e8a9916c2380a75cb49c39901be352eb34130f7629e0/image-20260319-220243.png?cb=beb53d6d4f5116c7fb221799a8f08fe1)

3. Verify streaming token is valid for the GRPC tunnel. Token should be Valid and Last Success should be recent than the failure.

![image-20260319-220306.png](https://runbooks.ciscospaces.io/__attachments/a_153abd0249098853516685fd2dd5f43d28e2db77292fcd0ecce52986763711b3/image-20260319-220306.png?cb=26d2f7febb458949902b4faa1f1143b2)  
![image-20260319-220322.png](https://runbooks.ciscospaces.io/__attachments/a_c15bf7f8118e6a22d505f87d0e1a42c4ce9abe449dbc8fe90aba73348eb78009/image-20260319-220322.png?cb=3e0f156ba50b18ce39a2d4351889c4fa)

4. If there are errors, GRPC server logs can be used to understand potential issues.

![image-20260319-221543.png](https://runbooks.ciscospaces.io/__attachments/a_8157b65c6b0c096f944933699c2df20e390b9d5f21b600ebb24f69c151744394/image-20260319-221543.png?cb=89462c51d324cf010f9fdc9c5468b892)

5. If AP is running IOX App (i.e. in Advanced Gateway mode, recommended), then the following commands can help understand if BLE is functioning correctly on the AP itself. There are commands and logs for BLE scan records to validate if the AP is scanning for BLE devices, metrics to monitor health.

![image-20260319-221614.png](https://runbooks.ciscospaces.io/__attachments/a_77272ba9afd51a93a2a07f28a93a8fbf92ac265a248e856e12f487a4571273be/image-20260319-221614.png?cb=248bc9972e4aefccc1ee45987b4955fc)  
![image-20260319-221629.png](https://runbooks.ciscospaces.io/__attachments/a_f79fee7965ca36dcdb99c7be401406c6e3582c5ea438b7496158e14fccce6078/image-20260319-221629.png?cb=ab2e8e030c30924ca68c5628d30377f8)  
![image-20260319-221651.png](https://runbooks.ciscospaces.io/__attachments/a_e040c09b0d8a3cd6edf863896e7de3696ab50292979e6276d4bf7ae876c88ba8/image-20260319-221651.png?cb=763fed5e1a0b6deb69ebe1a686d294c0)

6. If AP is not running IOX App, then there are some different commands to help understand if BLE is functioning correctly on the AP itself -- both for scanning and transmit, depending on the BLE configuration done on Spaces.

![image-20260319-222453.png](https://runbooks.ciscospaces.io/__attachments/a_9cce18b00503f28c0fed16de34d4f092fadaa62a73c5f30562da8aa58e3fdee9/image-20260319-222453.png?cb=021393af3c69b94deb2cbc7dcd8d8c12)  
![image-20260319-222507.png](https://runbooks.ciscospaces.io/__attachments/a_5e44b3b707f88aff6fc19df5098d5415f006b5a6c9e6e245abfb6d90d9d52ca8/image-20260319-222507.png?cb=ea4fc665da55c008aef5112cb07ec6c0)  
![image-20260319-222553.png](https://runbooks.ciscospaces.io/__attachments/a_c652c2f509b430bd48d817514b12c7fcfea731cb221870317d50f524e52d16ea/image-20260319-222553.png?cb=32031d32d2648289f9e261858d41eec2)

#### Validation of WLC

1. Validate TDL subscription is correctly configured, and all the subscriptions are valid. For Spaces, IDs 122-131 need to be present and Valid.

![image-20260319-222620.png](https://runbooks.ciscospaces.io/__attachments/a_fef824fdc095dfd788a175ce380d0868d5f6afa2b60d780bdc6f1c66c76b489a/image-20260319-222620.png?cb=f0df4489c61fac527de85d2028697699)

2. Validate if the actual telemetry ID is working correctly.

![image-20260319-223328.png](https://runbooks.ciscospaces.io/__attachments/a_2c1837ed1c6b693a847b8db33c2f65a33fb2ccaa058e73cafad080cd22587d3e/image-20260319-223328.png?cb=5a0af76c934dd8ab8e256add8051e5d7)  
*Note*

It's important for customers to understand different telemetry streams are used for sending different data to the cloud. For example, one subscription may be sending AP name or BLE status, another can be used to send temperature/humidity from AP sensors from Catalyst 9136, 9166 APs etc. So, it's important that all the subscriptions that Spaces uses (122-131) are up and valid.

Sometimes, the WLC can have issues such as firewall problems, or too many subscriptions limit reached on 9800 etc. which will lead to issues. Hence, it's critical to validate that all the subscriptions are working correctly.

3. Validate AP statuses and GRPC statuses.

![image-20260319-223437.png](https://runbooks.ciscospaces.io/__attachments/a_5cd959de32626ab44d2d301f7bdc734eaba4ffebe7af5ed52e8da17b9b80175f/image-20260319-223437.png?cb=07f1f1b218e597f3786b28e9b6c93d70)  
![image-20260319-223448.png](https://runbooks.ciscospaces.io/__attachments/a_02dcb73d044df4bdd0148a79d739e503e0ebe6cb06ae68618fc996a04f9d2dc3/image-20260319-223448.png?cb=8a6476ef92d5b3712292b6e1c073b5e7)  
![image-20260319-223457.png](https://runbooks.ciscospaces.io/__attachments/a_863080d1b66f6fa7d7dc0ac8827f23758a4aea1b5c3ea41695c1a681c2616006/image-20260319-223457.png?cb=1d25003bb647ba303ac5f1e1f79e7525)  
![image-20260319-223603.png](https://runbooks.ciscospaces.io/__attachments/a_f07667f054babe9e17f244511a70189ca58a7ea4d66d1e311ee8254508544c0f/image-20260319-223603.png?cb=0c74f018b6089ee20cd864590e4d9536)

### Grouping and Filtering

With Cisco Spaces, customers can filter BLE devices in multiple ways, including the ability to filter in the cloud, say for subsequent upstream or partner applications or even at the connector (version 3) or at the latest BLE IOX application running on the AP.

Most customers should be fine with the default filtering that can be done at the cloud, and we'll cover that next. But for advanced users, we will also provide the ability to understand how additional layer of filtering can be achieved.

#### Cisco Spaces Cloud based filtering:

You can create groups and assign devices to them. You can focus attention on certain devices, and view only these devices by filtering them by the group.

The advantages of manual groups are as follows:

* Policies are applied to groups.

* Firehose APIs can filter devices by these groups.

* In the Cisco Spaces: IoT Service dashboard, you can filter devices by groups.

![pic001.jpg](https://runbooks.ciscospaces.io/__attachments/a_5e0db2e3c091e1d7407ca58745c863100dc64c7e4a2d3eabe1d79bcf2e4cc23f/pic001.jpg?cb=2ea57cd9fddc7419073a0861094380c2)

While Cisco Spaces: IoT Service scans all devices, you may not want to view certain devices on the dashboard. You can now filter out devices from the Cisco Spaces: IoT Service dashboard using types of MAC addresses. Filtering is currently at the cloud level and not at AP-level. Once filtered, these devices do not appear in the following locations;

* Cisco Spaces: Detect and Locate

* Cisco Spaces: IoT Service

* Output of Firehose API calls

You can filter out devices based on the following MAC address types.

* Enable Public MAC: Allows global, fixed MAC addresses that are registered with the IEEE Registration Authority, which does not change during the device's lifetime.

* Enable Random Static MAC: Allows random static MAC address, which is a random number generated every time that the device boots up or a value that stays the same for the device's lifetime. However, it does not change within one power cycle of the device.

* Enable Random Private MAC: Allows random private MAC addresses of two types:

  * Resolvable: These are generated from an identity resolving key (IRK) and a random number. They can be changed often (even during the lifetime of a connection) and prevents an unknown scanning device from identifying and tracking the device. Only scanning devices that possess the IRK distributed by the beaconing device (exchanged using a private resolvable address) can resolve that address, allowing the scanning device to identify the beaconing device.​

  * Unresolvable: A random number that can change anytime.

![pic002.jpg](https://runbooks.ciscospaces.io/__attachments/a_e5cda9f91c47046e51290adcd8277828824eb74b19b785b47b6d7c591e7369a9/pic002.jpg?cb=736bdd58e6825266cb6c489ea91fc207)  
*Best Practice*

If tracked assets/sensors are tags and not apple / android devices, verify random private mac filtering is turned on in IoT Services.  
*Note*

If the system load continues to be high (CPU, Memory, Outgoing message rate) then customers can work with Cisco Spaces support team to implement additional filtering based on device OUI. That way, only the chosen devices with specific OUI or BLE MAC prefixes are processed and sent to Spaces and all other device data is dropped. This reduces the system load significantly. However, it also means that no other BLE devices will be seen by Spaces. So customers should consider this only if necessary. It may be easier to just scale the connector up first and see if the load is manageable.

#### Connector and IOX Application BLE Scan Filtering:

The connector BLE scan filter will allow BLE scan payloads to be filtered at the Cisco Spaces Connector (version 3) on the customer's premises before the information is transmitted to the cloud. Based on the applied filters, this will ensure that the BLE scan data does not leave the customer's location. The filtering parameter is done based on MAC address (prefix or full MAC address). The MAC prefix filter allows a list of MAC address substrings to be applied to the start of the MAC address. It only allows the BLE payloads with a MAC address matching one of the MAC prefixes to be forwarded to Cisco Spaces.  
![02_40_07.jpg](https://runbooks.ciscospaces.io/__attachments/a_218d7728f3d3ea3e1f578dd19f95b59a81cd4e119f749609186d912218c9cb12/02_40_07.jpg?cb=fbfc67ef1d8fd9a70e1acfbda135d05f)
*BLE MAC filtering*

To configure MAC filtering, navigate to **IoT Services \> Settings**. Note, that the filtering is only able to be done at the entire tenant level. So any filters applied will be pushed to all the connectors and onto the IOX application for APs.

Once the filter is set customers can view that information on the Cisco Spaces connector UI. The current MAC prefix filter settings can also be verified locally on the Cisco Spaces Connector user interface. To view the settings, login to the web interface of the Cisco Spaces Connector. The main dashboard will have boxes for each of the running services. Click on the launch icon in the upper right corner for iot-services.

![pic003.png](https://runbooks.ciscospaces.io/__attachments/a_9c484dac1d03ee4963f415a880fb83a14af1febd2c78cd349e36e806da0510b7/pic003.png?cb=eff1291fd3a93fc19e4e4886e3fd5668)

The page will provide more details about the service, including the MAC Prefix Filter. Also, the current metrics for how many events are being dropped as a result of using the filter.  
![pic004.png](https://runbooks.ciscospaces.io/__attachments/a_9debc50b650481829bdb806dcfa161760042c1727dcb0cdd460d3a95057e3ba5/pic004.png?cb=2a209987ff1a31cb05498b245d1e3f7f)

Logging for the filtering will also be available on the connector. A new file named filter.log will be added to the IoT Services logging directory. The log file will contain the MAC prefix filter settings when loaded or changed at any time while IoT Services runs. The log file can troubleshoot the MAC prefix filter at any time. A new counter metric, incoming-grpc-dropped-filter-rate, tracks the number of packets dropped on the Cisco Spaces Connector due to the MAC prefix filter. The metric will not appear on the Cisco Spaces dashboard for the IoT Services but will be available only in the metric log files, which can be remotely uploaded for troubleshooting.

### Device Monitoring

From the IoT Service \> **Device Monitoring** page, you can monitor all the IoT devices and gateways, and get a one-shot categorized view of devices according to their battery life and last heard time.

In the **Total gateways** part of this section, you can see an overview of all gateways that are being monitored. You can also see the number of reachable gateways (base and advanced) counted under the green dot, and the number of unreachable gateways counted under the red dot.

In the **Total BLE Devices** part of this section, you can see an overview of all BLE devices that are being monitored. You can also see the number of reachable devices (base and advanced) counted under the green dot, and the number of unreachable devices counted under the red dot.  
![pic005.jpg](https://runbooks.ciscospaces.io/__attachments/a_6a69cb9416fdf48f2ed74abdd8c99a5746f34c7090322f7db5db841b2f1d8907/pic005.jpg?cb=ee0f56c780bdcf845440480cd1783d43)

In the Battery life section, you get an overview of only those BLE devices (beacons) that can sense their own battery life. The devices are categorized according to their current battery life as Critical, Low, Medium or High.  
![pic006.jpg](https://runbooks.ciscospaces.io/__attachments/a_a0c8280c33f37a517d303c2e49f9820b15ba95e9817ef524d3ce38df2ba99734/pic006.jpg?cb=de10b41da900bbdd5cff51bad2a3010e)

In the section for Last Heard, you get an overview of all BLE devices (beacons). The devices are categorized according to the last time they were heard. Generally, you want to make sure the devices that you care about the most as being heard. In the Day 3 section, we will also talk about how you can set up specific alerts for devices not being heard.  
![Picture1.jpg](https://runbooks.ciscospaces.io/__attachments/a_63fdb9d28b1ed6de8c5f535415f999c5d9fc4b49384b71dd4437e86f7abd8d1c/Picture1.jpg?cb=e627dca622afb6577576b7a60f088eef)

### Best Practices for Asset Tracking Use Case

*Best Practice*

* For Catalyst based deployments, use the minimum recommended IOS-XE release. For any production deployment, customers need to use minimum 17.9.6 or 17.12.4 once available. Until those releases are available, recommendation is to use either 17.9.5 or 17.12.3.

* Deploy APs in recommended fashion as explained before in the guide. Make sure APs are correctly placed on the maps, with exclusion/inclusion zones marked correctly, AP models, height, antennas etc. selected correctly.

* Run accuracy tests ahead of time to understand the expected accuracy. If there are issues with the tests, it could be due to APs not in the right location, not turned on for BLE scanning, devices not being heard at high enough RSSI, device misbehavior. Re-check to make sure any deployment issues are resolved. If the issue is still seen, open a Cisco Spaces support case.

* Make sure devices are using iBeacon and are claimed in Spaces. If devices are unclaimed, or from a random device manufacturer that is not part of the IDM, such a tag can be used for asset tracking, but you won't have any visibility in device health to guarantee outcomes. Any BLE or firmware vulnerability will either become a massive security risk or you will need to deploy additional gateways or mobile app to update tag one by one in person. Also, due to any potential device misbehavior beyond Cisco's control, Spaces will not be able to guarantee location accuracy. Customers should consider this when choosing the device to use.

#### Asset Tracking with Cisco Spaces IOT Explorer

The Cisco Spaces: IoT Explorer app enables you to monitor and optimize the performance of your assets, sensors, alerting system, and workflows. While the application covers three different use cases (asset tracking, temperature monitoring, presence detection), Asset tracking is the primary use case for this application within Cisco Spaces.

You can create rules/alerts, view data logs, view the real time location and status of the device or sensor. The end application can be leveraged both via the Spaces Dashboard (meant for IT / Spaces admins) as well as a web application, which is available as a beta/limited feature as of the time of the writing of this guide.

Asset Tracking use case allows you to add asset tags to help manage and monitor the location of important objects and search for assets on a map and see their location in real time with automatic location updates. You can also add new asset tags with scalable and streamlined on-board processes and create rules to quickly notify team members when an item leaves a specific zone. The Cisco Spaces: IoT Explorer application retains asset location history for at least one year.  
![image-20260330-232310.png](https://runbooks.ciscospaces.io/__attachments/a_942e03ac43e06ff60573d600dbfdc2f66a60ded98d6b76d4be30e00afcd5b80d/image-20260330-232310.png?cb=eaea540136ecc217cfa76fce60e5db31)

The following is the data flow of how asset tracking use case is delivered on IOT Explorer when the underlying infrastructure is Catalyst.  
![image-20260330-232346.png](https://runbooks.ciscospaces.io/__attachments/a_1dc032ab1905d613957901a05e1bfadbf7fcd1408b84cfb97c99a92c28218f1d/image-20260330-232346.png?cb=e97143b50522a1fc34b15b1b523f2c47)

The following is the data flow of how asset tracking use case is delivered on IOT Explorer when the underlying infrastructure is Meraki. Note that at the time of writing this guide, the direct BLE path from MR AP to Spaces via MQTT and decoding of the telemetry is in Spaces QA testing, expected to be made generally available shortly.  
![image-20260330-232400.png](https://runbooks.ciscospaces.io/__attachments/a_05e26cfbfeb95f87cd6bdfdb7328c54dfa35bdd5588564cacbd0d6266886d6c9/image-20260330-232400.png?cb=b72c4670def045c34e5320e6c5711c2f)

### Best Practices for Staff Duress Use Case

*Best Practice*

Best practices for BLE based Staff Duress solution are same as asset tracking. Please refer to the same.

The following is an example of Staff Duress solution delivered via a Spaces partner using Firehose API to receive telemetry information (such as button press) and the location of BLE badge from Spaces to deliver the end-to-end Staff Duress solution.  
![image-20260330-232412.png](https://runbooks.ciscospaces.io/__attachments/a_638890c523b2c8c2bffd67b829d2c08b77aab56ecc0d9f953fc92ddc9b30d8cc/image-20260330-232412.png?cb=1b5efd50ff8941d8e22e0726a9fec468)

### Design Practices for Cisco Spaces Wayfinding Use Case

Cisco Spaces recently launched native Indoor Wayfinding solution allowing customers to Improve productivity by finding your way to collaboration spaces quickly and make navigating the workplace effortless. It helps customers extend their experience to your mobile phone for wayfinding on the go by leveraging app clips where no custom mobile app needed and no app downloads needed (for iOS devices). It also allows employees, guests and other users to get turn by turn directions to relevant spaces and points of interest.  

| ![image-20260330-232436.png](https://runbooks.ciscospaces.io/__attachments/a_8a139f363fc604a747aea7c4af5f4a53ea799111f346a6a3fe6f8439d02cf192/image-20260330-232436.png?cb=666fba5b8f7caf8f6b5765a7af42dfd7) | ![image-20260330-232443.png](https://runbooks.ciscospaces.io/__attachments/a_98be74cc7d949dcfb3a4ba168bb60ae383bbd2f7beb2beb021f09cb69650863f/image-20260330-232443.png?cb=9f771d8f43e3cf0f3e1a191a7c3d2857) |
|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

Wayfinding use case requires a lot of planning so here are some guidelines and best practices to help understand what is takes to implement the solution.  

|-------------------------------------|--------------------------------------|---------------------------------------------------------------------|------------------------|
| **Beacon density / ceiling height** | **Example environment**              | **Typical guidance**                                                | **Estimated Accuracy** |
| High density / low ceiling          | Workspaces, Open Offices             | 1 beacon / 300 -- 700 sq ft (28 - 65 sq m) *Avg 1 per 500 sq ft*    | \< 3m                  |
| Medium density / high ceiling       | Warehouses, Hospitals, Retail stores | 1 beacon / 700 -- 1500 sq ft (65 - 140 sq m) *Avg 1 per 1200 sq ft* | 3 -5 m                 |
| Low density / high ceiling          | Airports, Parking Garages            | 1 beacon / 1500 -- 3000 sq ft (140 - 278 sq m)                      | 5 -6 m                 |

Design Principals for Wayfinding:

* Whenever beacons (Cisco APs or supplemental) are placed, Homogeneity of signal is the most important factor

* Beacons at intersections of hallways, helps with changing directions

* Line of sight to user device, don't plan for beacons tucked around corners

* Evenly distribute beacons, add dedicated linear beacons for long hallways

* Beacons at point of level change (top / bottom of stairs, elevator etc.), helps with correct level assignment and automated level change turn by turn wayfinding

* Install on ceilings as low as possible, maximum height 10m. Anything more will degrade performance. Balance with potential theft if can be easily reached by humans moving around.

* Rule of thumb: Rooms with capacity of 4+ get their own beacons

* Remember all locations are different. Leverage Cisco's support to get the best beacon placement layout for the location

*** ** * ** ***

## DAY N - TROUBLESHOOTING AND MONITORING

This section of the guide will focus on talking about what are the common scenarios for IT teams to handle, including monitoring and troubleshooting any Cisco Spaces IOT Services BLE issues.

### Monitoring on the Connector

Customers should always keep an eye on the health of their connectors are they are the primary means of sending the data to the cloud and the success of any business outcomes depend on the connectors staying healthy. While Spaces provides multiple ways to view the key performance indicators via the dashboard and the connector UI (covered in the section on connector validation earlier), realistically, customers can not be expected to always be looking at those screens. Being aware of what to look at in the dashboards and UI is important to understand what's going on and spot checks, but being able to consistently monitor it using APIs is something we recommend.

The KPIs that should be monitored and recommended values are:

* System CPU -- recommended to be \< 70%

* System Memory -- recommended to be \< 70%

* IOT wireless service CPU and Memory -- recommended to be \< 70%

* GRPC connection count -- which shows how many APs have GRPC up and active

* GRPC message and input / output rate -- provides a baseline of the data flow. Large variation like drops can point to an issue

While these metrics are available from the connector UI, this section will focus on how to use connector APIs to monitor these directly.

Prerequisites for using REST APIs:

APIs are receiving data directly from the connector docker. So:

1. Services should be up. For this guide, at a minimum, service manager and IOT Wireless services need to be deployed.

2. The connector needs to be added to a Spaces Account

The following steps can be used to generate the API keys and then use REST to get the monitoring data

1. Login into the Connector 3 UI and go to Manage API Keys. Generate a new Key.

![image-20260330-232515.png](https://runbooks.ciscospaces.io/__attachments/a_48c07a473919f15d1fbfdf977024cae662b4979b49fe0c83bb7a52781089760c/image-20260330-232515.png?cb=3992f6d6fe86de78b22b85c12e3cac0e)

2. You can use this API key to simply run a HTTPS request to the connector to get a one time output of the monitoring information. Two example ways to run this that we cover in this guide are using terminal and Postman. Customers can easily use common scripting methods such as Python requests module to run this and automate data collection and alerting.

**Example 1:** Terminal curl command

You can run this command on terminal.
Bash

    curl -k 'https://<ip of connector>/api/connector/v1/monitoringdata' --header 'Authorization: Bearer <API Key>'

![image-20260330-232528.png](https://runbooks.ciscospaces.io/__attachments/a_dd94a2624734694f3236ee3e8c0243c4547072b65aa5e8c386dfd0c2e67373fa/image-20260330-232528.png?cb=9923cff929bd03454b210ef622282b74)

**Example 2:** Postman

You can use the same API key under *Security -\> Bearer Token* and run the same API URL in Postman
HTML

    https://<ip of connector>/api/connector/v1/monitoringdata

![image-20260330-232541.png](https://runbooks.ciscospaces.io/__attachments/a_1c77bf03f760b5df465a4e92f6dc86c4c4d94650177b8ce00deeac6b2cec826d/image-20260330-232541.png?cb=f16236159a153c82ad2c6a5a91286092)  
*Cisco Recommendation*

Cisco recommends that customers use these APIs to monitor key indicators to make sure the system is working optimally, such as not under heavy load or not unexpected drops in the GRPC counts or rates. If such a scenario happens, customers are encouraged to leverage this guide to make sure the configuration is done correctly and can review some common troubleshooting scenario examples. But if that doesn't help recover the system to a normal working state, customers should open a Cisco support ticket.

### Monitoring on the Cloud

In addition to the connector, customers should leverage the Spaces dashboard to keep an eye on the deployment.

Monitoring Devices -- This was already covered in the earlier section

Monitoring for Updates -

Customers are encouraged to always upgrade to the latest software versions for the connector and services when available. Cisco continuously rolls out newer features and bug fixes in the different services such as IOX application and connector services.  
![image-20260330-232559.png](https://runbooks.ciscospaces.io/__attachments/a_2fcf0572e2507e694249b2cbe1acaf703aa21e9d8b245f5ba978dee2b8856fe2/image-20260330-232559.png?cb=74a0d752e1f7ecccfc85fbd7dfd869be)

It's recommended to upgrade these services. For any issues seen with any service, the controller will be marked as degraded, and customers can look at the details by clicking on that link.

A controller can be marked degraded if:

* A Service is deployed but not correctly activated

* Errors with the service

Additional monitoring for services status can be checked by clicking on Instances Tab and Metrics Tab.  
![image-20260330-232611.png](https://runbooks.ciscospaces.io/__attachments/a_af869545578dfa2dd467f3a8b8f28be555ebdf4ce0ec356504ee67a09fe5f7c3/image-20260330-232611.png?cb=b2c9dd6da767c0c6ff7bc18d7bb64926)  
![image-20260330-232626.png](https://runbooks.ciscospaces.io/__attachments/a_3b5d3277c54ecd8e8bd7beb09dfe00a9e45655960ea524257a9592ca8adfa2af/image-20260330-232626.png?cb=c1b10af8817337af8802b5aa1d00e951)

Customers can also use the Rules in IOT Explorer Application to create rules for critical BLE devices that are used for mission critical use cases for making sure timely alerts are received for triggers such as:

· Device Not Heard -- can be useful for making sure BLE is working as expected, to prevent loss, as well as to provide a level of confidence for any business-critical outcome.

· Device Entered or Exit -- useful for location-based alerts

Steps to configure such rules are covered in the IOT Explorer configuration guide available [here](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-explorer/config/b-iot-explorer-cg.html).

### Troubleshooting scenario examples

#### Poor location accuracy

Ensuring accurate location reporting in the Cisco Spaces platform requires a systematic approach to troubleshooting. Here are the key points to check:

1. Understand RSSI and RF Characteristics

   1. RSSI (Received Signal Strength Indicator) is critical for determining location accuracy.

   2. Different physical locations can have varying RF characteristics, impacting RSSI readings.

   3. Conduct location accuracy tests from the Cisco Spaces dashboard across multiple locations to establish a baseline. This will help in understanding the expected accuracy and identifying any deviations.

2. Verify AP Placement on Maps

   1. Accurate placement of Access Points (APs) on the map is essential.

   2. Ensure all APs that are present and reporting RSSI are correctly placed on the map.

   3. Use the Detect and Locate configuration page to identify and rectify any missing APs on the map.

3. Enable and Verify BLE Scanning

   1. Ensure that Bluetooth Low Energy (BLE) scanning is enabled for all APs.

   2. Confirm that BLE data is being received from these APs.

   3. Check GRPC and TDL settings, and review AP scanning logs if necessary to troubleshoot BLE data issues.

4. Sensor Characteristics and Device Recommendations

   1. Different sensors have varying power and behavior characteristics.

   2. Cisco recommends using devices from the IOT device marketplace, which have been tested for compatibility.

   3. If using a different tag type, be aware that Cisco cannot guarantee location accuracy. Test the tags in a small deployment before scaling up to a larger deployment.

5. Enable iBeacon Profile

   1. Ensure the iBeacon profile is enabled to facilitate accurate location tracking.

6. Ensure Sufficient AP Coverage

   1. At least three or more APs should hear the device at -75 dBm or better.

   2. Use AP scanning logs to verify the RSSI levels received at different APs.

7. Check Connector Health

   1. Monitor the health of connectors, specifically checking CPU usage, memory usage, and packet drops.

   2. Address any performance issues to maintain optimal operation and location accuracy.

#### IOX app install failures

IOX application install can fail on the Access Points for a couple of commonly found reasons. Try the following things to resolve it.

1. Check AP storage

   1. Sometimes the AP storage space is already too full -- maybe due to existing cores or log files that take up excessive storage. Unfortunately, in that case, the IOX application install will not be successful. To remediate it, you can try a couple of options.

   2. Manually delete all the core files by logging into the AP (SSH / Console) or using a script to do it in bulk.

   3. Add a core dump TFTP server to the wireless configuration. When you do that, subsequent cores that may get generated are uploaded to the server and then deleted from the AP. But it will only take effect after the setting is applied, previous cores will still be needed to be deleted.

   4. If you aren't sure which APs have enough storage or not, it may be best to just run a simple script and delete any existing cores from the APs before trying to do the IOX application install, or BLE gateway deployment.

2. Firewall rules

   1. The most common reason for IOX application installs failure is not opening the right firewall ports. Please double check the firewall rules and confirm the ports are correctly opened as explained in the configuration guides.

#### When to change the power of BLE device

In the Cisco Spaces platform, you have the capability to configure and manage BLE devices that are claimed into an account, including the ability to adjust their transmit power levels. Adjusting the transmit power level can be crucial in various scenarios to ensure optimal performance and location accuracy. Here are key points to consider when deciding to change the transmit power level of BLE devices:

1. When to Consider Changing Transmit Power Level

   1. Signal Reliability: If the BLE device's signal is not reliably being heard by APs, resulting in frequent data drops, it may be necessary to increase the transmit power level.

   2. Distance Between APs: If APs are too far apart to provide accurate location data, increasing the device's power level might help before considering adding more APs.

   3. Dense AP Deployment: In cases where there is a very dense deployment of APs, reducing the power level of the BLE devices can help minimize overall noise levels and limit the range so that the signal is only heard by a select few APs.

2. Factors Affecting BLE Signal Range

   1. The expected range of a BLE device depends primarily on its transmission power setting.

   2. Environmental factors such as interference, multipath, or absorption can also impact BLE signal range.

3. Transmit Power Level Guidelines

   1. A general rule of thumb is that if a BLE device is transmitting at a power level of -12 dBm, its range is approximately 65 feet (20 meters).

   2. To ensure reliability, maintain at least a 20% buffer from the maximum range. For example, if the transmit power level of -12 dBm provides a range of 65 feet, aim to place APs within a maximum distance of 50 feet.

   3. If you need more APs to hear the signal or if the APs are farther away, consider increasing the device's transmit power level.

4. Configuration for Cisco IDM Devices

   1. Cisco IDM devices are configured to transmit at a power level of -12 dBm by default.

   2. Customers can adjust this setting based on their specific deployment needs.

| TX Power setting | Transmission power (dBm) | Approximate range |
|------------------|--------------------------|-------------------|
| 0                | -30 dBm                  | 6.5 ft (2 m)      |
| 1                | -20 dBm                  | 13 ft (4 m)       |
| 2                | -16 dBm                  | 32 ft (10 m)      |
| 3 (default)      | -12 dBm                  | 65 ft (20 m)      |
| 4                | -8 dBm                   | 98 ft (30 m)      |
| 5                | -4 dBm                   | 131 ft (40 m)     |
| 6                | 0 dBm                    | 196 ft (60 m)     |
| 7                | 4 dBm                    | 229 ft (70 m)     |

#### Netconf failures

You may see some failures in configuration of BLE related settings, which can be due to Netconf failures. Netconf is used between the connector and the WLC to push configuration to the WLC and in turn the APs. If there is any failure in that (example: configuration, credential, bug etc.) then it will lead to potential failures on Cisco Spaces end. Check to make sure Netconf is working as expected.

1. Check the logs

   1. You may first want to get and review the connector server.log file to see if you see any Netconf errors.

2. Check configuration

   1. Make sure Netconf is enabled

   2. WLC requires a few aaa Netconf commands provided earlier in the guide. Make sure those are still present on the WLC configuration

   3. Make sure you have not enabled Netconf operation in candidate store mode as Spaces does not support that. If you have, you'd want to disable it by running the following command on the WLC.

    no netconf-yang feature candidate-datastore

3. Check authorization

   1. Make sure that the credential provided to Spaces is authorized to run Netconf commands on the WLC. You may want to use local credential to add WLC to Spaces.

#### Service upgrade failures

As mentioned multiple times in this guide, it's highly recommended to make sure you are running the latest service and system versions. Best practice is to check at regular intervals (Example: once a month) for new system and service package versions.  
![image-20260330-232654.png](https://runbooks.ciscospaces.io/__attachments/a_6c67b4b05879d057504b91b72e1f303ad26f1bf3951664a2b5c8889549040fe3/image-20260330-232654.png?cb=e3b3597607884fbac759a543eb1ae338)  
![image-20260330-232706.png](https://runbooks.ciscospaces.io/__attachments/a_81dbb1c86ac0dab69e992becf2ebe7291859acbe1099afaa4e1b8fed963ff7cb/image-20260330-232706.png?cb=6696c5e2fc5e91d7a040a322a2e37f9c)

However, if you run into any failure or issue with a service upgrade, here are the steps you should try.

1. Check the connectivity.

   1. Having intranet or internet issues can lead to failures with service package downloads and installs.

   2. If you have setup VIP HA on the connector, then they need to be on the same subnet and there should be no connectivity issues between the connector pair and each connector's internet reachability.

2. Try to refresh instance of the connector.

![Picture1.png](https://runbooks.ciscospaces.io/__attachments/a_5bb168475e48b6cccae46a10c4d3c8c1c6ad4230ce42f1f1ea960fbb32fb8591/Picture1.png?cb=4cc061faff3212618bd9fe124119336b)

#### TDL Subscription failure

If you see issues with AP beacon channel (ideally last updated time for that should be within 2 hours) as seen in IOT Services, then that can point to some TDL subscription issues. You should try some common steps to troubleshoot those.

1. Make sure enough TDL subscriptions are available.

   1. Catalyst 9800 WLC have limited number of subscriptions that it can support, depending on the WLC hardware type.

   2. Run the WLC command show telemetry ietf subscription all and details to make sure Spaces related subscriptions are present and valid and connected as explained before in this guide.

2. Delete or remove subscriptions of other services if needed

   1. If you are running too many services, for example: you have added Catalyst Center, Cisco Prime Infrastructure etc. together will Spaces connector, then it's possible you have run out of the limit of subscriptions that the WLC can support.

   2. Please remove the other subscriptions and retry.

In this section, we have tried to cover some of the common scenarios that you may see in your IOT Services deployment, but it's not an exhaustive list either in terms of the issues or the steps that may need to be taken. While the steps should be able to help you troubleshoot and fix, or at least provide you insight into what may be happening, you may still need further help. As explained before, if you've tried to run the troubleshooting and still are facing issues, it is recommended to open a Cisco support case for requesting the next level of assistance.

*** ** * ** ***

## CONCLUSION

In deploying and maintaining Cisco Spaces IoT Services, attention to detail in troubleshooting and debugging is essential for optimal performance and accurate location tracking. By understanding the complexities of RSSI and RF characteristics, ensuring precise AP placement, enabling and verifying BLE scanning, and considering the unique characteristics of different sensors, you can address common issues that affect location accuracy. Additionally, careful management of BLE device transmit power levels, maintaining sufficient AP coverage, and monitoring connector health are crucial steps to ensure the reliability and efficiency of your IoT deployment.

Following this guide, you can systematically troubleshoot and debug your Cisco Spaces IoT services, resulting in a robust and accurate location tracking system. Always remember to test configurations in smaller deployments before scaling up, and leverage the tools and settings provided by Cisco Spaces to fine-tune your setup. With diligent monitoring and timely adjustments, you can achieve the high level of accuracy and performance needed for your IoT applications.

*** ** * ** ***

## REFERENCES

* [Connector Configuration Guide](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/connector/config/b_connector_30.html)

* [Spaces Setup Guide](https://spaces.cisco.com/setupguide)

* [IOT Services Configuration Guide](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-services-wireless/b_iot_services.html)

* [Spaces DevNet](https://developer.cisco.com/cisco-spaces/)

* [Firehose API Guide](https://www.cisco.com/c/dam/en/us/td/docs/wireless/cisco-dna-spaces/partner-app/partner-firehose-api/Cisco_DNA_Spaces_API_Guide.pdf)

* [Firehose API Partner Documentation](https://partners.dnaspaces.io/docs/v1/basic/index.html#!c-dnas-partners-overview.html)

* [All Cisco Spaces Support Documentation](https://www.cisco.com/c/en/us/support/wireless/dna-spaces/series.html#~tab-documents)

---
language: "en"
---
# Knowledge Articles

Knowledge articles are small snippets of information or concentrations on a single topic, that are key to deployment success.

These are useful for customers who know the basics, but need a short document to highlight usability of one key, or complex feature.

These can also be useful for post deployment references.  
Note that the ![image-20250512-171355.png](https://runbooks.ciscospaces.io/__attachments/a_d78e42a5ea5088c01b4dd9b23856ae9737c41128894ccb4e3de36354121d8ab2/image-20250512-171355.png?cb=a6a4da2969a5cba3bc0cd35c4251651c) icon on the left side of the screen will open up the navigation pane.

---
language: "en"
---
# Multiple Authentication Methods on a Single Captive Portal

## OVERVIEW

The Captive Portal Multi-Auth feature is introduced to address the diverse authentication needs of guest Wi-Fi environments that serve mixed visitor populations. This enhancement allows administrators to configure multiple authentication methods within a single captive portal, providing greater flexibility and convenience for end users. By enabling a primary authentication method alongside alternate options such as Access Code, Social Sign-In, SMS with link verification, or SMS with password verification, organizations can tailor the onboarding experience to different visitor types---such as VIPs, contractors, or casual guests---within the same portal.

Additionally, the Data Capture workflow has been enhanced to support configurable custom form fields, allowing businesses to collect specific visitor information beyond standard onboarding data. This update improves the customization and effectiveness of visitor data collection to meet unique business requirements.

Overall, Captive Portal Multi-Auth simplifies guest access management by consolidating multiple authentication paths into one portal, enhancing user experience while maintaining secure and controlled internet access.

*** ** * ** ***

## FUNCTIONALITY

### **Captive Portal Multi-Auth**

Captive Portal now supports configuring alternate authentication methods in addition to a primary authentication method. In the portal creation wizard, the Authentication step includes **Primary Authentication** and **Alternate authentication**tabs. Admins can configure supported alternate methods such as Access Code, Social Sign-In, SMS with link verification, or SMS with password verification.

#### Custom fields in Data Capture

The Data Capture step now supports configurable custom form field tailored to specific business requirements.

#### What problem does it solve?

Many guest Wi-Fi environments serve mixed visitor populations. A retail store may want most visitors to sign in with email or SMS, but also give VIPs, contractors, or event staff an access code. A hotel may prefer SMS verification for guests but offer social sign-in for casual visitors.

Organizations frequently need to collect business-specific visitor data that extends beyond standard onboarding information. Existing captive portal workflows offered predefined field structures, limiting customization for data capture.

#### What does the feature do?

Captive Portal Multi-Auth adds a two-part authentication configuration model:

1. **Primary Authentication**

   This allows the admin to select the default authentication method that will be presented to end users when the Captive portal is rendered for them.

![image-20260525-090209.png](https://runbooks.ciscospaces.io/__attachments/a_3667f7064b1fdb165472240dd1c255963446b416a5e6b83740768459d05e7abc/image-20260525-090209.png?cb=bcd6a24f47cfcd6b1680e2e188820a8e)

**Alternate Authentication**

If Primary Authentication is set to anything other than **No Authentication** , admins can add alternate methods. All authentication methods available in Spaces including Access Code, Social Sign-In, SMS with link verification, and SMS with password verification are available as alternate options. Social Sign-In can include Facebook, Twitter, and LinkedIn.

![image-20260525-090330.png](https://runbooks.ciscospaces.io/__attachments/a_1089e6360eb496e57bf81c34c4000d961c60014ff87f6297e52f5decae846c44/image-20260525-090330.png?cb=089471f48f3a49b6ad40961ae3edc628)

![image-20260525-090438.png](https://runbooks.ciscospaces.io/__attachments/a_7f29bff2d361a63d93e2c0b5fff9cc9486756f16d241dc17ddfc9403fff012a6/image-20260525-090438.png?cb=d323614f60d0878737e33141fa0000b6)

This update does **not** introduce new authentication methods.

The Data Capture workflow now supports configurable custom form fields. Admins can add custom fields while enabling Data Capture . Custom fields can be configured with field labels, placeholders, mandatory validation, and selectable options depending on the field type.  
![image-20260525-090514.png](https://runbooks.ciscospaces.io/__attachments/a_471ea409a847e5b0590ea7e203fcaae558cb78a70652bbe8aa416f72b7c65fba/image-20260525-090514.png?cb=b0f79feff895acd874f360bc1a6ba76e)  
![image-20260525-090532.png](https://runbooks.ciscospaces.io/__attachments/a_0a6b9d056f077473199e5971961cf8624a74ced03c7844a3d7864d6a3568cb1d/image-20260525-090532.png?cb=914ffb60d61dd18aa2cd8135860adb43)

#### Dashboard changes: before and after

The newer version of the workflow will be replacing the previous version of the workflow.  

|          **Area**           |                                                    **Before Launch**                                                     |                                                            **After Launch**                                                            |
|-----------------------------|--------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------|
| Authentication setup        | Portal creation uses an **Authentication Type** drop-down where the admin chooses the authentication type for the portal | Portal creation shows an **Authentication** step with **Primary Authentication** and **Alternate authentications** tabs.               |
| No Authentication behaviour | No Authentication is one of the available authentication types.                                                          | If **No Authentication** is selected as the primary method, user will not be able to add any alternative authentication method         |
| Social Sign-In              | Social Sign-In can be configured with supported social networks such as Facebook, Twitter, and LinkedIn.                 | Social Sign-In remains available, and the alternate-auth flow allows Facebook, Twitter, and LinkedIn options.                          |
| Additional Data Capture     | After selecting authentication details, admins move to Data Capture and add fields with **+Add Field Element**.          | Data Capture remains a separate step after authentication, with **Enable Data Capture** and **+Add Form Field** in the updated wizard. |
| Custom fields               | Limited predefined form fields                                                                                           | Support for Plain Text, Dropdown, Check Box, Radio Button, and Date Picker custom fields                                               |
| Data Capture                | Basic form field support                                                                                                 | Expanded configurable Data Capture with custom fields                                                                                  |

#### End-user experience of connecting to a Captive Portal

Visitors continue to connect to the SSID and land on the captive portal. The difference is that the portal can now support more than one authentication path. A visitor can complete the method that applies to them, such as SMS, access code, or social sign-in, and then proceed with the existing internet provisioning flow. The underlying captive portal behavior remains consistent: after the required authentication steps are completed, Cisco Spaces provisions internet access

If Custom Data Capture fields are enabled, visitors may also be prompted to complete organization-defined custom fields before internet provisioning occurs

#### Compatibility of Existing portals

Existing portals will continue to work with no change in behavior. Portals created prior to the launch date will not support multiple authentication. These legacy portals may be copied or imported but clones of exiting portals would not support multiple authentication methods.

*** ** * ** ***

## FAQs

**Q: Does Multi-Auth add new authentication types?**

No. It allows admins to combine existing captive portal authentication options in a single portal.

**Q: Can I use both SMS with link verification and SMS with password verification as alternates?**

No. Only one SMS option can be selected at a time.

**Q: Can I use alternate authentication when the primary method is No Authentication?**

The alternate authentication window is disabled when Primary Authentication is set to No Authentication.

**Q: Can I view or modify multi-auth portals in the previous version of the dashboard?**

Portals create with Multi-Auth Capability are only supported in the latest version of the dashboard. They will not be viewable or editable in the previous versions of the dashboard.

**Q: Can I make custom fields mandatory?**

Yes. Custom fields support mandatory validation using the "Make this field mandatory" option.

---
language: "en"
---
# OpenRoaming: Cisco Spaces SDK Integration

## OVERVIEW

*This Knowledge Article is designed only as a follow on from the* [***Cisco Spaces OpenRoaming Runbook***](https://runbooks.ciscospaces.io/docs/cisco-spaces-os-runbook-cisco-validated)*. If you have not completed that runbook yet, please go back and ensure that the deployment has been validated against that before continuing here.*

The **Cisco Spaces Software Development Kit** (SDK) leverages OpenRoaming technology to attach users, seamlessly and securely, to Wi-Fi networks, without the need for user interaction. It allows an iOS or Android application developer to configure iOS and Android devices with an identity of choice that can be verified with the back-end system. This paves the way to allows businesses to generate information and engage with customers, directly on their devices, through contextual push notifications within an iOS and Android notification framework.​

The outcomes SDK Integration provides businesses include:

* Differentiated experience for loyalty/enterprise app users​​​

* Drive contextual engagement and marketing campaigns​​

* Drive up app downloads and at-location app usage​​

* Address privacy MAC challenges​​​

## PREREQUISITES

Enable and configure OpenRoaming App as per the [Cisco Spaces OpenRoaming Runbook](https://runbooks.ciscospaces.io/docs/cisco-spaces-openroaming-runbook-cisco-validated).

Once the Open Roaming app is enabled and the steps to configure are completed, follow the next steps to configure Cisco SDK Integration.​

## IMPLEMENTATION

To successfully register a new app, the following procedure must be completed:

* Register App

* Configure Profile

* Push Notification

* Authentication

The steps below demonstrate how to setup and activate Cisco Spaces SDK.

1. Log in to [Cisco Spaces](https://dnaspaces.io/login).

2. Navigate to **Configure \> Cisco Spaces SDK**

![image-20250219-035752.png](https://runbooks.ciscospaces.io/__attachments/a_df4309479fc92439791328ed59d5c4c52bb07e08cada83d57a773309784a8b1c/image-20250219-035752.png?cb=df8290047211d7324a07e3da3194b054)

3. Click **Register App**.

4. To choose the platform for the new app, check either the iOS or Android check box or both.

   If you select both platforms, the subsequent windows display parameters for both platforms.
5. In the Register App section, enter the following:

   * **App Name:** Enter the name of the application.

   * **Bundle Identifier:** Enter the Bundle ID or bundle identifier string that identifies your app on the iOS platform.

Every iOS application requires a bundle ID to work and must be unique if the developer intends to publish it on the App Store. The bundle ID is in the format domain.your-company.app-name.

*

  * **Package Name:**Enter the unique package name to identify an Android app.

The package name of an app is in the format domain.your-company.app-name. However, you can choose to enter any name.  
![image-20250219-040743.png](https://runbooks.ciscospaces.io/__attachments/a_99e210a2f215bea9c8212579df4abe9cd0cb6016dd24a6ba71bf62ddcd9befc4/image-20250219-040743.png?cb=ad3d65ac53295bd06413d8b9cb891160)

6. Click **Next**.

7. In the **Configure Profile** section, enter the following:

   * **Displayed Operator Name:** Enter a valid identifier. This name is displayed as the Wi-Fi SSID name on the user's android or iOS device.

   * **Domain:** Enter a unique domain name for the profile.

     * The domain name is available in the OpenRoaming app. For more information see, [Configure Network Controller](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/openroaming/b-spaces-or-cg/m-config-or.html#Cisco_Concept.dita_6e8a7653-a61a-413f-8379-fb2d00db5631).

     * You should add this domain name in the controller configuration.

     * If you have more than one app, then each app must have a unique domain name.

   * **Roaming Consortium OIs:** From the **Roaming Consortium OIs** drop-down list, check the check box next to the array of Roaming Consortium Organization (RCO) identifiers. This is optional.

![image-20250219-042944.png](https://runbooks.ciscospaces.io/__attachments/a_ba66609bfccb257bf7bcc81e7db91caf6fd5dc355c4d12d764531911233b66c0/image-20250219-042944.png?cb=4a743a8d2de6fbd7b827a98f4e8bf0ee)

8. To enable push notifications for iOS, check the **Enable Push Notification for iOS** check box.

   1. Enter the iOS App ID.

   2. Click Upload to browse and upload the APNS P12 and Certificate.

   3. Enter the APNS certificate password.

9. To enable push notifications for Android, check the **Enable Push Notification for Android** check box.

   1. Enter the Android App ID.

   2. Enter the API key.

      ![image-20250219-043108.png](/__attachments/a_eddb7816d8ce438a736ce2091a5f16e04b13c6c5e1c457fa7275356c9740ae6c/image-20250219-043108.png?cb=668105ad5bb003c13123606e91d50cb8)

10. Click **Next**.

11. To support Apple sign-in as the user identity for the new mobile app, check **Enable Apple Sign In** in the **Authentication** section.

    1. In the **Enter Client ID** field, enter the apple account sign-in client ID.

    2. In the **Enter Secret Key** field, enter the secret key for Apple account.

12. To support Google sign-in as the user identity for the new mobile app, check **Enable Google Sign In** in the **Authentication** section.

    1. In the **Enter Client ID** field, enter the google account sign-in client ID.

    2. In the **Enter Secret Key** field, enter the secret key for Google account.

13. Click **Register App** to complete the app registration. The registered apps are displayed.

    ![https://www.cisco.com/c/dam/en/us/td/i/400001-500000/480001-490000/481001-482000/481107.jpg](https://www.cisco.com/c/dam/en/us/td/i/400001-500000/480001-490000/481001-482000/481107.jpg)

    You can click:
    * **View Configurations:** To view the application configuration details.

    * **Delete** icon: To delete the registered application.

14. (Optional) Click **Edit** to update push notifications for iOS and Android platforms.

15. (Optional) Click **Update** .

---
language: "en"
---
# Partner Ecosystem Guides

These documents provide comprehensive guidance on understanding and navigating the Cisco Spaces Partner Ecosystem.

They are designed to help partners, developers, and integrators effectively engage with Cisco Spaces, build solutions, and bring them to market through validated pathways.  
Note that the ![image-20250825-213211.png](https://runbooks.ciscospaces.io/__attachments/a_369a3d0f13c64b2b8b58ac9e3cd46d61d1521a0d7814cdcc178812ba7fd7a66c/image-20250825-213211.png?cb=84bc33d2fdc06a13a750b3ce670b8e10) icon on the left side of the screen will open up the navigation pane.

---
language: "en"
---
# Remote Patient Monitoring with Corsano and Cisco Sensor Connect

## **OVERVIEW**

Healthcare organizations are increasingly adopting Remote Patient Monitoring (RPM) solutions to improve patient outcomes, reduce clinician workload, and enable proactive models of care. Traditional intermittent vital sign measurements provide periodic snapshots of a patient's condition and may delay the identification of physiological deterioration. Continuous monitoring using wearable medical devices enables clinicians to detect changes in patient condition earlier, allowing timely intervention and improving the quality and efficiency of care. This approach supports multiple stages of the patient journey, including pre-operative assessment, inpatient monitoring, post-operative recovery, and hospital-at-home or post-discharge care. Continuous monitoring has the potential to reduce avoidable escalations, improve patient throughput, optimize staff workflows, and enhance patient safety through earlier detection of clinical deterioration.

This runbook provides Cisco partners and customers with implementation guidance for deploying a RPM solution using Corsano Health wearable medical devices integrated with Cisco. This solution combines Cisco's wireless infrastructure and Corsano's continuous patient monitoring platform to deliver real-time physiological monitoring with location-aware clinical intelligence.

This runbook outlines the reference architecture, deployment workflow, infrastructure requirements, configuration procedures, validation steps, operational considerations, and support model required to successfully deploy and operate the Cisco Spaces Remote Patient Monitoring solution. By combining continuous physiological monitoring with indoor location intelligence, healthcare organizations can enhance patient safety, improve clinical workflows, and establish a scalable foundation for future Medical IoT use cases across the care continuum.

*** ** * ** ***

## **TARGET AUDIENCE**

This runbook is intended for stakeholders involved in the design, deployment, and operation of Remote Patient Monitoring solutions within healthcare environments, including:

* **Hospital IT Administrators** responsible for network infrastructure and system integration

* **Clinical Engineering Teams** managing device integration, validation, and ongoing operational support

* **Cisco Partners and System Integrators** deploying and configuring healthcare solutions for customer environments

* **Facility and Operations Managers** overseeing campus-wide safety initiatives and ensuring alignment with organizational policies

*** ** * ** ***

## **HOW IT WORKS**

The Remote Patient Monitoring (RPM) solution combines Cisco wireless infrastructure, Cisco Spaces Sensor Connect, and the Corsano continuous patient monitoring platform to enable real-time physiological monitoring of patients throughout their care journey. The solution continuously captures patient vital signs using wearable medical devices and securely delivers this data to clinicians through the Corsano platform.

Cisco Catalyst wireless infrastructure serves as the underlying IoT transport layer for the solution. By leveraging Bluetooth Low Energy (BLE) capabilities built into Cisco Catalyst access points, hospitals can deploy continuous patient monitoring without installing a dedicated BLE gateway infrastructure. This allows healthcare organizations to extend the value of their existing wireless investment while supporting additional Medical IoT use cases on the same infrastructure.

### Patient Onboarding

Patients are onboarded using the Corsano HCP application. During the onboarding process, the patient profile is created, the wearable bracelet is assigned and paired, Wearing Optimization is completed, and blood pressure cuff calibration is performed when applicable. Once onboarding is complete, the patient begins continuous monitoring.

#### Continuous Patient Monitoring

Once activated, the Corsano wearable periodically broadcasts patient telemetry using Bluetooth Low Energy (BLE). Cisco Catalyst Access Points receive these BLE advertisements and forward the telemetry through Cisco Sensor Connect to the Corsano platform for continuous monitoring. Healthcare professionals can monitor patient information through the Corsano Portal and Corsano HCP application, which provide access to patient details, physiological measurements, historical trends, and clinical response information. The platform also supports NEWS2 scoring and blood pressure measurements when configured as part of the clinical workflow.BLE Telemetry Collection

Cisco Catalyst Access Points equipped with integrated Bluetooth® Low Energy (BLE) radios continuously scan for BLE advertisements transmitted by Corsano wearable devices. Acting as distributed BLE gateways, the access points collect device telemetry and forward it through the Cisco wireless infrastructure to Cisco Sensor Connect. This architecture eliminates the need for dedicated BLE gateway hardware, allowing healthcare organizations to leverage their existing Cisco wireless infrastructure for continuous patient monitoring.

#### Telemetry Processing and Clinical Monitoring

Cisco Sensor Connect serves as the telemetry transport layer between the Cisco wireless infrastructure and the Corsano platform. BLE telemetry collected by the Cisco wireless infrastructure is securely streamed to the Corsano On-Premises Gateway using MQTT. The gateway subscribes to the telemetry stream, validates and processes the incoming data, and securely forwards relevant patient information to the Corsano Health Cloud over HTTPS. Healthcare professionals can then access continuous patient monitoring, physiological measurements, historical trends, and clinical information through the Corsano Portal and Corsano HCP application.

#### Clinical Monitoring and Decision Support

The Corsano platform continuously evaluates incoming patient telemetry against configured clinical monitoring parameters. Healthcare professionals can review patient status, historical trends, NEWS2 scores, and clinical response information through the Corsano Portal or HCP mobile application. This enables clinicians to monitor patient condition continuously and prioritize care based on patient status.

#### Patient Off-boarding

At the completion of monitoring or upon patient discharge, the wearable bracelet can be unassigned from the patient profile using the Corsano HCP application. This removes the association between the patient and the wearable, allowing the device to be prepared for reuse in subsequent patient onboarding workflows.

#### Scalable Medical IoT Platform

Cisco Sensor Connect architecture provides a scalable Medical IoT foundation capable of supporting large numbers of wearable medical devices across healthcare facilities. Because the solution leverages the existing Cisco wireless infrastructure as the BLE transport layer, hospitals can expand continuous patient monitoring deployments without introducing parallel gateway networks or additional BLE infrastructure.

This architecture not only enables Remote Patient Monitoring but also establishes a foundation for future healthcare IoT services, allowing organizations to extend the same infrastructure to additional use cases such as asset tracking, environmental monitoring, workflow optimization, and patient flow analytics.

*** ** * ** ***

## **SOLUTION COMPONENTS**

This section identifies the hardware, software, and application components required to deploy the Remote Patient Monitoring solution. Cisco provides the wireless infrastructure, BLE transport, and Sensor Connect services, while Corsano provides the wearable medical devices, patient monitoring platform, and clinical applications.

### **Cisco Components**

|               **Device**                |                                                                                                         **Function**                                                                                                         |                                                                               **Recommended Versions**                                                                               |
|-----------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Cisco Catalyst 9800 Wireless Controller | Hosts the Cisco Sensor Connect (IoT Orchestrator) application and manages BLE telemetry from Cisco access points.                                                                                                            | Cisco IOS XE 17.15.5 or 17.18+ <https://www.cisco.com/c/en/us/support/ios-nx-os-software/ios-xe-17/products-release-notes-list.html> Virtual WLC is not supported for this use case. |
| Cisco Catalyst Access Points            | Operate as BLE gateways that scan Corsano bracelet advertisements and forward telemetry to Sensor Connect.                                                                                                                   | [Supported Access Points](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-orchestrator/release-notes/1-1/cisco-spaces-connect-for-iot-services-release-notes.html)         |
| Cisco Sensor Connect (IoT Orchestrator) | Runs as a containerized application within the Catalyst 9800 WLC using Cisco IOx. Receives BLE telemetry from Catalyst APs, manages device communication, and securely streams telemetry to the Corsano on-premises gateway. | 1.2.1 or later [Download the latest version](https://software.cisco.com/download/home/286323456/type)                                                                                |

#### **Corsano Components**

|                                                                                                                    **Device**                                                                                                                     |                                                                                                                                                               **Function**                                                                                                                                                               |
|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Corsano Wearable Bracelet ![Screenshot 2026-04-14 at 2.50.37 PM.png](https://runbooks.ciscospaces.io/__attachments/a_aedf4d4a40ca7bc3784756f9dab9a5c8cf08d4c87b7118d47305a195f1e1b56d/Screenshot%202026-04-14%20at%202.50.37%E2%80%AFPM.png?cb=cc186b704e9b40f8a2726213e78a3375) | FDA-cleared wearable medical device that continuously measures patient physiological parameters and broadcasts telemetry using Bluetooth Low Energy (BLE). Supports continuous monitoring of physiological measurements such as heart rate, respiratory rate, SpO₂, skin temperature, activity, and other supported clinical parameters. |
| Corsano On-Premises Gateway                                                                                                                                                                                                                       | Receives BLE telemetry from Cisco Sensor Connect using MQTT, processes and validates incoming physiological data, and securely forwards clinically relevant information to the Corsano Health Cloud.                                                                                                                                     |
| Corsano Health Cloud                                                                                                                                                                                                                              | Cloud platform that stores patient telemetry, performs clinical analytics, and provides access to patient dashboards, alerts, and reporting.                                                                                                                                                                                             |
| Corsano Portal                                                                                                                                                                                                                                    | Web-based clinical dashboard used by healthcare providers to monitor patient vital signs, historical trends, alarms, and patient compliance.                                                                                                                                                                                             |
| Corsano HCP Mobile App                                                                                                                                                                                                                            | Mobile application used by healthcare professionals for patient onboarding, bracelet assignment, patient monitoring, and clinical notifications. Supports patient registration, bracelet pairing, firmware updates, wearing optimization, blood pressure cuff calibration, and patient offboarding.                                      |

*** ** * ** ***

## **PREREQUISITES**

### **Cisco Prerequisites**

Before deploying the Remote Patient Monitoring solution, ensure that the Cisco wireless infrastructure meets all prerequisites. Refer to the guide for the latest supported hardware, software, and deployment requirements: [Cisco Spaces Connect for IoT Services -- Prerequisites](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-orchestrator/config-guide/b-spaces-connect-iot-config-guide/m-prerequisites.html)

One of the following eligible licenses is required:

* Cisco Wireless Advantage

* Cisco Spaces Smart Operation

* Cisco Spaces ACT

* Cisco Spaces Unlimited

Cisco Sensor Connect supports a maximum number of concurrent BLE device connections per access point for operations that require an active BLE connection (such as device configuration or firmware updates). This limit varies by AP model and should be reviewed during solution planning to ensure operational activities such as firmware updates can be performed efficiently at scale.

### **Corsano Prerequisites**

**Corsano Health Platform**

*
  * A valid Corsano Health tenant must be provisioned before deployment.

  * Contact Corsano Support to provision the environment and provide administrator access.

**Corsano On-Premises Gateway**

*
  * The Corsano On-Premises Gateway must be installed within the customer network.

  * During installation, Corsano Support will register the gateway using:

    * Gateway IP address

    * Gateway Serial Number

    * Cisco Sensor Connect application token

**Corsano Wearable Devices**

*
  * Corsano wearable monitoring bracelets must be available for deployment.

  * Devices should be fully charged before patient onboarding.

  * Verify firmware compatibility prior to deployment.

**Corsano HCP Portal**

*
  * Healthcare professionals (HCPs) requiring access must first register through the Corsano Portal.

  * Hospital administrators must approve and assign HCP users to the appropriate department before monitoring activities can begin.

**Corsano HCP Mobile Application**

*
  * Install the Corsano HCP mobile application on supported mobile devices used for patient onboarding.

  * The application is used to:

    * Register patients

    * Pair wearable devices

    * Perform Wearing Optimization

    * Pair blood pressure cuffs (if applicable)

    * Offboard patients upon discharge

**Patient Onboarding Materials**

*
  * Ensure patient wristbands, Corsano wearable devices, and onboarding QR codes or identifiers are available before beginning patient enrollment.

  * If blood pressure monitoring is required, compatible BP cuffs should be paired prior to completing patient onboarding.

**Clinical Workflow Preparation**

*
  * Define patient monitoring workflows, department assignments, and clinical escalation procedures prior to deployment.

  * Verify that healthcare professionals have received training on patient onboarding, wearable placement, and portal usage before the solution is placed into production.

*** ** * ** ***

## **INFRASTRUCTURE PLANNING AND DESIGN**

Proper infrastructure planning is critical to delivering reliable Remote Patient Monitoring outcomes. Cisco Sensor Connect leverages the existing Cisco wireless infrastructure to collect Bluetooth® Low Energy (BLE) telemetry from Corsano wearable devices, eliminating the need for dedicated BLE gateway hardware.

Unlike traditional Wi-Fi deployments that prioritize client connectivity, Remote Patient Monitoring deployments should be designed to ensure continuous BLE telemetry collection across the monitored care environment. Infrastructure should therefore be designed to support reliable telemetry collection and clinical monitoring outcomes rather than wireless connectivity alone.

The recommended deployment workflow for the solution is:

1. Plan the Cisco wireless infrastructure.

2. Deploy the Cisco Catalyst Access Points.

3. Install and configure the Catalyst 9800 Wireless LAN Controller.

4. Deploy Cisco Sensor Connect (IoT Orchestrator).

5. Validate BLE telemetry collection and network connectivity.

6. Deploy the Corsano platform.

7. Begin patient onboarding.

Following this sequence ensures the Cisco infrastructure is fully operational before the clinical applications and wearable devices are introduced.

### **AP Planning and BLE Design Considerations**

Cisco Catalyst Access Points function as distributed BLE gateways for Corsano wearable devices. The number and placement of access points should be determined during the design phase based on the physical characteristics of the healthcare environment and the expected monitoring scale.

When planning the deployment, consider:

* Building construction and materials (for example reinforced concrete, lead-lined rooms, or thick walls)

* Patient room size and floor layout

* Ceiling height

* Expected number of concurrently monitored wearable devices

AP density should be validated through a wireless site survey and pilot deployment before production rollout, as healthcare environments vary by layout, construction, and monitoring requirements.

Cisco recommends the following design best practices:

* Design the wireless infrastructure for BLE telemetry collection and location outcomes rather than Wi-Fi client coverage alone.

* Ensure access points are distributed throughout patient care areas, including room perimeters and corridors, to provide continuous BLE coverage.

* Each wearable device should be detected by at least three access points with an RSSI of --75 dBm or stronger to support reliable X/Y location calculations.

* Where practical, maintain an AP-to-device proximity of approximately 50 ft (15--20 m). Additional AP density may be required depending on wall construction, room geometry, and building materials.

* Position access points accurately on digital floor maps, including antenna orientation where available, to improve operational visibility and simplify troubleshooting.

* Validate BLE coverage and telemetry performance before onboarding patients into production.

Cisco Sensor Connect supports a finite number of concurrent active BLE device connections per access point. These limits vary by Catalyst AP model and should be considered when planning large-scale deployments or scheduling firmware updates.

[Refer to the Cisco Sensor Connect documentation for the latest guidance on the maximum number of concurrent BLE device connections supported per access point.](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-orchestrator/release-notes/1-1/cisco-spaces-connect-for-iot-services-release-notes.html)

#### **Catalyst 9800 WLC Planning**

Deploy and size the Cisco Catalyst 9800 Wireless LAN Controller based on the expected number of access points, wireless clients, and Remote Patient Monitoring scale. For production healthcare deployments, Cisco recommends deploying Catalyst 9800 controllers as an HA Stateful Switchover (HA SSO) pair to provide controller redundancy and maintain uninterrupted wireless services during controller failures.

Select the appropriate Catalyst 9800 platform based on the supported AP and client scale for the deployment.

[Refer to the Cisco Catalyst 9800 Wireless Controller datasheets and deployment guides for the latest platform sizing, scalability limits, and High Availability best practices.](https://www.cisco.com/site/us/en/products/networking/wireless/wireless-lan-controllers/resources.html)

#### **Map and Location Readiness (Optional but recommended)**

Accurate floor maps and infrastructure topology remain important for operational visibility and future location-aware healthcare workflows.

Organizations should configure Cisco Catalyst Center (or supported mapping sources) with:

* Accurate building hierarchy

* Floor maps

* Correct access point placement

Maintaining accurate infrastructure information simplifies troubleshooting, infrastructure monitoring, and future expansion into additional use cases.

*** ** * ** ***

## **REFERENCE ARCHITECTURE**

![Screenshot 2026-07-08 at 2.50.40 PM.png](https://runbooks.ciscospaces.io/__attachments/a_961ca3e857f7bd540a22de3512f7004c0f6e24a3bf0ab35dabca2f6c21e3dedd/Screenshot%202026-07-08%20at%202.50.40%E2%80%AFPM.png?cb=c7fd92ac514cd56a21f625430a549327)

*** ** * ** ***

## **HOW COMPONENTS INTERACT**

The Remote Patient Monitoring solution is orchestrated through structured telemetry exchange between Corsano wearable medical devices, Cisco Catalyst wireless infrastructure, Cisco Sensor Connect, and the Corsano Health platform. This architecture enables continuous collection of physiological telemetry, secure transport of patient data, and real-time monitoring through the Corsano Portal and HCP mobile application.

Once a Corsano wearable device is assigned to a patient and activated, it begins broadcasting periodic Bluetooth Low Energy (BLE) advertisements containing physiological telemetry and device information. Depending on the monitoring configuration, transmitted telemetry may include heart rate, respiratory rate, blood oxygen saturation (SpO₂), skin temperature, activity, motion, battery status, and other supported physiological parameters.

### **BLE Telemetry Collection by Cisco Infrastructure**

Cisco Catalyst Access Points equipped with integrated BLE radios continuously scan for BLE advertisements transmitted by nearby Corsano wearable devices. The access points capture the device MAC address, timestamp, RSSI, and BLE telemetry payload before forwarding the information to the Cisco Catalyst 9800 Wireless LAN Controller over CAPWAP.

Cisco Catalyst Access Points function as distributed BLE gateways, allowing the existing wireless infrastructure to collect patient telemetry without requiring dedicated BLE gateway hardware.

#### **Telemetry Processing by Cisco Sensor Connect**

The Catalyst 9800 Wireless LAN Controller hosts the Cisco Sensor Connect (IoT Orchestrator) application, which serves as the telemetry transport layer for the solution. The wireless controller forwards BLE telemetry to Sensor Connect using gRPC. Sensor Connect aggregates BLE telemetry received from multiple access points and securely streams the collected data to the Corsano On-Premises Gateway using MQTT.

This architecture allows Cisco Sensor Connect to act as the secure integration point between the Cisco wireless infrastructure and the Corsano platform while maintaining scalable communication with large numbers of wearable medical devices.

#### **Telemetry Processing by Corsano**

The Corsano On-Premises Application subscribes to the MQTT telemetry stream generated by Cisco Sensor Connect.

Upon receiving telemetry, the gateway:

* Processes and validates incoming physiological measurements

* Filters irrelevant or duplicate telemetry

* Associates telemetry with registered Corsano wearable devices

* Packages clinically relevant information for cloud transmission

Only validated patient telemetry is securely forwarded to the Corsano Health Cloud over HTTPS, reducing unnecessary network traffic while ensuring reliable delivery of clinical information.

#### **Clinical Processing within Corsano Health Cloud**

The Corsano Health Cloud receives physiological telemetry from the on-premises gateway and performs centralized patient monitoring and clinical analysis.

The platform:

* Associates wearable devices with patient records

* Stores historical physiological measurements

* Continuously analyzes incoming vital signs

* Evaluates configurable clinical thresholds and NEWS2 scoring

* Generates alerts for abnormal physiological conditions

* Maintains patient history, dashboards, and reporting

Healthcare professionals access this information through the Corsano Portal or Corsano HCP mobile application, allowing clinicians to monitor patients in near real time from any authorized location.

#### **Clinical Applications and Healthcare Workflows**

The Corsano Portal serves as the primary clinical interface for monitoring patients and reviewing physiological data. Healthcare professionals can view current patient status, historical trends, NEWS2 scores, and clinical response information while managing patient onboarding and monitoring workflows.

The Corsano HCP mobile application extends these capabilities by enabling clinicians to onboard new patients, pair wearable devices, perform wearing optimization, monitor patient status, and access patient information while remaining mobile throughout the healthcare facility.

#### **Operational Responsibility Model**

The solution architecture maintains clear ownership boundaries across the Cisco infrastructure and Corsano clinical platform.

Cisco Infrastructure is responsible for:

* Cisco Catalyst wireless infrastructure

* Cisco Sensor Connect

* BLE telemetry collection and Secure telemetry transport

* Infrastructure monitoring and connectivity

Corsano Platform is responsible for:

* Wearable medical devices

* Patient onboarding and device association

* Physiological telemetry processing

* Clinical analytics and NEWS2 scoring

* Patient dashboards and reporting

* Clinical alerts and healthcare workflows

This separation enables independent lifecycle management of the infrastructure and clinical application layers while providing a scalable and secure architecture for continuous patient monitoring.

*** ** * ** ***

## **INSTALLATION AND CONFIGURATION STEPS**

### **Cisco Infrastructure Deployment**

#### **Deploy Cisco Catalyst Access Points**

Deploy Cisco Catalyst Access Points according to the **AP Planning and Deployment** recommendations described in the **Infrastructure Setup** section. Ensure that the deployed access points are supported for Cisco Sensor Connect and meet the minimum hardware and software requirements documented in the Cisco Sensor Connect Prerequisites Guide.

Once deployed, verify that all access points are operational, joined to the Catalyst 9800 Wireless LAN Controller, and providing the intended BLE coverage before proceeding with the remainder of the installation.

#### **Install and Configure the Catalyst 9800 Wireless LAN Controller**

Deploy and configure a supported Cisco Catalyst 9800 Wireless LAN Controller following Cisco best practices. The controller is responsible for managing the Cisco Catalyst Access Points and hosting the Cisco Sensor Connect application.

Complete the controller installation, upgrade to a supported Cisco IOS XE release, and verify that all access points have successfully joined the controller.

[Refer to the Cisco Catalyst 9800 Wireless LAN Controller Configuration Guide for detailed installation and configuration procedures.](https://www.cisco.com/c/en/us/support/wireless/catalyst-9800-series-wireless-controllers/series.html#Configuration)  
![Screenshot 2026-07-08 at 4.35.09 PM.png](https://runbooks.ciscospaces.io/__attachments/a_416077e954fbfd879f40027558b92d10188458ff8b005664e9c05b01b6631491/Screenshot%202026-07-08%20at%204.35.09%E2%80%AFPM.png?cb=f925b25ed781fa83cbcec36762c5923c)

#### **Install Cisco Sensor Connect (IoT Orchestrator)**

Cisco Sensor Connect (IoT Orchestrator) provides the BLE telemetry transport layer between the Cisco wireless infrastructure and the Corsano Remote Patient Monitoring platform. It runs as a Cisco IOx application on the Catalyst 9800 Wireless LAN Controller and is responsible for receiving BLE telemetry from Cisco Catalyst Access Points and securely streaming it to the Corsano On-Prem App.

Complete the deployment of Cisco Sensor Connect by following the [Cisco Sensor Connect Quick Start Guide.](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-orchestrator/qsg/sensor-connect-iot-qsg.html)  
![Screenshot 2026-07-08 at 4.29.16 PM.png](https://runbooks.ciscospaces.io/__attachments/a_a9b43ff428bf79967f8ffa00f4fe5310f26f5c1845f4f062094537211da4507f/Screenshot%202026-07-08%20at%204.29.16%E2%80%AFPM.png?cb=1ee352a505ae235894fa6c1dc4afa708)

#### **Create Token for Corsano App**

To connect to the Corsano devices using the Sensor Connect App, generate keys for onboarding, control, and data receiver Apps.

[Refer to this section for detailed steps](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-orchestrator/qsg/sensor-connect-iot-qsg.html#RegisteringPartnerApplicationtoInteractwiththeIoTOrchestratorApplication)  
![image-20260708-234853.png](https://runbooks.ciscospaces.io/__attachments/a_c1d0c489efeec43511b7223d9828762b25d15db6310ad143b15238592ff998ab/image-20260708-234853.png?cb=c358b804b20670fe12af9797b82c9d9e)

### **Corsano Platform Deployment**

#### **Install the Corsano On-Prem App**

Once Cisco infrastructure validation is complete, **contact Corsano Support.**

Corsano Support will:

* Install the Gateway software

* Register the Gateway

* Configure MQTT connectivity

* Register the Sensor Connect application token

* Validate communication with the Corsano Health Cloud

Refer to the Cisco Infrastructure Getting Started Guide for the complete installation workflow.

#### Configure the Corsano Platform

Deploy the Corsano platform by completing the following:

* Configure the hospital environment

* Create departments

* Configure administrator accounts

* Register Healthcare Professional (HCP) users

* Validate communication between the Gateway and Corsano Health Cloud

Detailed deployment procedures are available in the Corsano Installation Guide and associated Corsano deployment documentation.

#### Install the Corsano HCP Application

Install the Corsano HCP application on supported mobile devices used by healthcare professionals.

The application is used to:

* Register healthcare professionals

* Onboard patients

* Pair wearable devices

* Perform Wearing Optimization

* Monitor patient telemetry

* Offboard patients

Refer to the HCP Onboarding Guide for complete installation and onboarding procedures.

#### Onboard Patients

After the Cisco infrastructure and Corsano platform have been successfully deployed, healthcare professionals can begin onboarding patients.

Patient onboarding includes:

* Patient registration

* Bracelet assignment

* Device pairing

* Firmware update (if required)

* Wearing Optimization

* Blood pressure cuff calibration (if applicable)

* Verification of physiological telemetry

Following successful onboarding, patient data becomes available through the Corsano Portal and HCP application for continuous monitoring.

#### **Infrastructure Readiness Checklist**

* [ ] Cisco Catalyst wireless infrastructure is fully operational
* [ ] Cisco Sensor Connect is installed and running
* [ ] Supported Catalyst access points are deployed throughout monitored areas
* [ ] Required Cisco Spaces licenses have been activated
* [ ] Required firewall ports are open
* [ ] Network connectivity between Cisco infrastructure and Corsano App has been confirmed
* [ ] Sensor Connect application token has been generated for Corsano integration

*** ** * ** ***

## **INTEGRATION VALIDATION CHECKLIST**

The following validation steps should be completed before placing the Remote Patient Monitoring solution into production. This checklist verifies that the Cisco infrastructure, Cisco Sensor Connect, Corsano platform, and patient monitoring workflows are operating correctly.

### **1. Verify Cisco Infrastructure Status**

Confirm that the Cisco wireless infrastructure is operational and meets the minimum software requirements. Verify that the Catalyst 9800 Wireless LAN Controller, Cisco Catalyst Access Points, and Cisco Sensor Connect are healthy and communicating correctly.  
![image-20260708-232635.png](https://runbooks.ciscospaces.io/__attachments/a_7d266a238c8b50d013299bb740181f511c1f407eecc91659a4f82548e843f322/image-20260708-232635.png?cb=ed4ab4189f3332e7bb55bd65e6f3073b)  
![image-20260708-232313.png](https://runbooks.ciscospaces.io/__attachments/a_b9c0bba42c83222f905e211ffa1c6dccd5b5d4d8afb5f0bf2fe94bd067eb0380/image-20260708-232313.png?cb=41e14ab4d8dd7b587b09b34f2a4a022e)

#### **2. Validate Sensor Connect Health**

Confirm that Cisco Sensor Connect is running successfully on the Catalyst 9800 Wireless LAN Controller. Verify that BLE telemetry is being received from the access points and that communication with the has been successfully established.

#### **3. Validate BLE Telemetry Collection**

Using a test Corsano wearable, verify that BLE advertisements are detected by the Cisco wireless infrastructure. Confirm that Sensor Connect receives telemetry from the wearable and that no communication errors are reported.

#### **4. Verify Gateway Connectivity**

Confirm that the Corsano On-Premises Gateway is successfully connected to Cisco Sensor Connect using MQTT and is forwarding telemetry to the Corsano Health Cloud over HTTPS.

#### **5. Validate Corsano Platform Connectivity**

Log in to the Corsano Portal and verify that the gateway is online and communicating with the Corsano Health Cloud. Confirm that Healthcare Professional (HCP) users can successfully access the portal and assigned departments.

#### **6. Perform Patient Onboarding Validation**

Using the Corsano HCP application, onboard a test patient by registering the patient, pairing a wearable device, and completing the Wearing Optimization workflow. Verify that the wearable is successfully assigned to the patient profile.

#### **7. Validate Physiological Telemetry**

Confirm that physiological measurements from the wearable device are visible within the Corsano Portal. Verify that supported vital signs update continuously and that patient information is displayed correctly.

#### **8. Validate Clinical Monitoring and Alerts**

Where clinical thresholds or NEWS2 scoring are configured, simulate a test scenario and verify that the Corsano platform correctly evaluates patient telemetry and generates the expected clinical alerts or notifications.

#### **9. Validate Mobile Application Workflow**

Confirm that healthcare professionals can access the Corsano HCP mobile application, monitor patient status, and view patient telemetry using the assigned department and user credentials.

#### **10. Perform End-to-End Workflow Validation**

Complete a full operational workflow using a test patient, beginning with patient onboarding and ending with continuous physiological monitoring. Verify that telemetry is collected by Cisco infrastructure, processed by Sensor Connect, delivered to the Corsano platform, and displayed correctly in both the Corsano Portal and HCP mobile application. Successful completion of this validation confirms that the Remote Patient Monitoring solution is ready for production deployment.

*** ** * ** ***

## **REFERENCES**

### Cisco Documentation

* [Cisco Sensor Connect for IoT Services -- Quick Start Guide](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-orchestrator/qsg/sensor-connect-iot-qsg.html)

* [Cisco Sensor Connect for IoT Services -- Configuration Guide](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-orchestrator/config-guide/b-spaces-connect-iot-config-guide/m-overview-of-cisco-spaces-connect-for-iot-services.html)

* [Cisco Sensor Connect for IoT Services -- Prerequisites](https://www.cisco.com/c/en/us/td/docs/wireless/spaces/iot-orchestrator/config-guide/b-spaces-connect-iot-config-guide/m-prerequisites.html)

* [Cisco Catalyst 9800 Series Wireless Controller Data Sheets](https://www.cisco.com/c/en/us/products/wireless/catalyst-9800-series-wireless-controllers/datasheet-listing.html?utm_source=chatgpt.com)

#### Corsano Documentation

* [Corsano Continuous Remote Patient Monitoring](https://corsano.com/solutions/remote-patient-monitoring/)

* [Corsano Knowledge Base](https://corsano.com/knowledge-base/)

* [Corsano Support Portal](https://corsano.com/contact-us/)

*** ** * ** ***

## **FEEDBACK AND CONTINUOUS IMPROVEMENT**

This runbook is a living document that evolves based on real-world deployments and customer feedback. Your input helps us improve accuracy, clarity, and completeness of the runbook.

**Submit Feedback:** [Runbook Feedback Form](https://form.asana.com/?k=FV-k6EGfjuDd3qN7RxaZcA&d=5557457880942)

**Email:** [ciscospacespartnerteam@cisco.com](mailto:ciscospacespartnerteam@cisco.com)

For technical support issues, please follow the Support and Escalation Process outlined in this document.

[Next Page](https://runbooks.ciscospaces.io/llms-full.txt/1)
