7.3 Automated RF and Client Optimization: AirMatch and ClientMatch

Key Takeaways

  • AirMatch runs in Central on a 24-hour cycle, computing a channel, channel-width, and EIRP plan for each radio that is deployed once per cycle at a scheduled time with low network utilization.

  • Unlike legacy Adaptive Radio Management (ARM) which made isolated, reactive real-time decisions resulting in channel flapping, AirMatch leverages centralized historical RF telemetry to prevent disruptive mid-day changes.

  • In AOS 10, ClientMatch is orchestrated by Central (in AOS 8 it ran on the Mobility Conductor); it band-steers, sticky-steers, load-balances, and MU-MIMO-steers clients.

  • ClientMatch moves clients with 802.11v BSS Transition Management messages or deauth moves; a client that ignores five or more 802.11v moves receives a deauth move instead.

  • Clients that resist steering go on an unsteerable list for 48 hours after three failed deauth moves, or for 24 hours after ignoring more than five consecutive 802.11v moves.

Last updated: October 2026

Automated RF and Client Optimization: AirMatch and ClientMatch

Quick Summary: High-performance enterprise wireless demands constant adaptation to changing physical environments, variable client densities, and dynamic RF interference. Aruba addresses these challenges through two specialized, complementary optimization systems: AirMatch and ClientMatch. AirMatch operates in Central to calculate holistic, campus-wide channel, bandwidth, and transmit power plans on a 24-hour cycle. ClientMatch, also orchestrated by Central in AOS 10, continuously evaluates client signal metrics to steer devices from congested bands to cleaner spectrum (Band Steering) and resolve sub-optimal connections (Sticky Client Steering).


The Enterprise RF Challenge: Infrastructure vs Client Dynamics

Enterprise Wi-Fi performance is governed by two distinct operational domains that require completely different management methodologies:

  1. Infrastructure RF Optimization (The Radio Environment): Access points must select operating channels, channel bandwidths (20, 40, 80, or 160 MHz), and Effective Isotropic Radiated Power (EIRP) levels that maximize coverage while minimizing co-channel interference (CCI). Because RF signals penetrate walls and floors unpredictably, changes made to one radio directly impact neighboring radios.
  2. Client Roaming Behavior (The Endpoint Environment): Under the IEEE 802.11 standard, the client device—not the access point—determines when to roam and which AP to associate with. Many mobile clients exhibit "sticky client" behavior, clinging to a distant AP with deteriorating signal quality rather than roaming to an adjacent AP located directly overhead. Furthermore, dual-band and tri-band clients frequently associate with congested 2.4 GHz channels despite supporting cleaner 5 GHz and 6 GHz spectrum.

To optimize both domains without conflict, Aruba separates infrastructure RF tuning into AirMatch and real-time client mobility into ClientMatch.


AirMatch: Cloud-Native Global RF Optimization

The Evolution Beyond Legacy ARM

In legacy WLAN systems (including early ArubaOS releases), RF management was handled by Adaptive Radio Management (ARM). ARM operated as a decentralized, reactive algorithm running on individual APs or local controllers. If an AP detected transient RF noise (such as a microwave oven or rogue hotspot), ARM reacted immediately by changing channels:

  • This localized reaction often pushed co-channel interference onto adjacent APs, triggering a cascading "domino effect" of channel switches across the floor.
  • Mid-day channel changes forced client disassociations and disrupted active voice and video calls.
  • ARM made decisions based strictly on localized, short-term data without understanding the global RF topography of the entire building.

The AirMatch Machine Learning Architecture

AirMatch replaces reactive local algorithms with a centralized, predictive machine-learning engine hosted in Aruba Central:

+-------------------------------------------------------------------------+
|                        Aruba Central: AirMatch ML                       |
+-------------------------------------------------------------------------+
       ^                                                           |
       | 1. Continuous RF Telemetry (24 hrs)                       | 3. Coordinated Push
       |    - Path loss matrix across all APs                      |    (Scheduled, low use)
       |    - Co-channel interference & noise                      |    - Optimal Channels
       |    - Non-Wi-Fi interferers & radar events                 |    - Channel Widths
       |    - Historical client traffic density                    |    - EIRP Power Levels
       |                                                           v
+-------------------------------------------------------------------------+
|                       Campus Access Point Network                       |
|    [AP-1] <-------- L2 Neighbor Probing --------> [AP-2] <----> [AP-3]  |
+-------------------------------------------------------------------------+
  1. 24-Hour Telemetry Gathering: Throughout the business day, every AP continuously monitors its RF environment without interrupting client access. APs send periodic RF measurement reports to Central, detailing neighbor path-loss matrices, channel utilization percentages, background noise levels, and non-Wi-Fi interferers.
  2. Cloud ML Computation: Central aggregates data from all radios across the campus to build a comprehensive, multi-dimensional RF graph of the facility. The machine-learning model simulates thousands of channel and power permutations to compute the mathematically optimal RF distribution plan.
  3. Scheduled Deployment: AirMatch deploys the new plan once per cycle at the scheduled time. HPE's best practice is to schedule it for the period of lowest network utilization, so channel changes have minimal user impact.
  4. Improvement threshold: A new plan is deployed only if it improves the radio-conflict metric by at least the configured threshold. The default Balanced coverage-tuning setting uses an 8% improvement threshold (the range is 0% aggressive to 16% conservative).

Dynamic Capabilities of AirMatch

  • Automated Dynamic Channel Width Sizing: In high-density auditoriums or conference halls with substantial co-channel contention, AirMatch automatically shrinks channel widths from 80 MHz to 40 MHz or 20 MHz. This generates more non-overlapping channels, eliminating co-channel interference and maximizing aggregate network capacity. Conversely, in sparse environments with minimal neighbors, AirMatch expands channels to 80 MHz for maximum single-client throughput.
  • EIRP Power Balancing: AirMatch dynamically balances transmit power levels between APs to maintain consistent cell-edge overlap (targeting -65 dBm cell boundaries). This eliminates "coverage holes" while preventing APs from transmitting at power levels so high that asymmetric client devices (like smartphones) can hear the AP but lack the transmit power to reply.
  • Event-Driven Changes: Between scheduled plans, AirMatch still reacts to dynamic events such as poor channel quality, radar (DFS) detections, and high-noise events. These reactive changes continue even if the APs lose contact with Central.

ClientMatch: Real-Time Intelligent Client Optimization

While AirMatch plans the infrastructure once per cycle, ClientMatch works continuously on individual clients. In AOS 10, the main difference from AOS 8 is that ClientMatch is orchestrated by Central instead of a Mobility Conductor (AOS 10 TechDocs, "ClientMatch"). For each client it keeps a list of the radios that can hear the client and at what signal level, then applies its rule sets.

+-------------------------------------------------------------+
|                      ClientMatch Engine                     |
+-------------------------------------------------------------+
                               |
       +-----------------------+-----------------------+
       |                                               |
+-------------------+                         +-------------------+
|   Band Steering   |                         |  Sticky Steering  |
| (2.4 GHz -> 5/6G) |                         | (Low SNR -> High) |
+-------------------+                         +-------------------+
       |                                               |
       +-----------------------+-----------------------+
                               |
                               v
          +-----------------------------------------+
          |       Execution Protocol Decision       |
          +-----------------------------------------+
                 /                           \
                /                             \
   [Client Supports 802.11v/k]     [Client ignores 802.11v 5+ ]
              /                                     \
             v                                       v
+-------------------------+             +-------------------------+
| Send 802.11v BSS        |             | Deauth move if 802.11v  |
| Transition Request Frame|             | is ignored 5+ times     |
+-------------------------+             +-------------------------+

1. Band Steering

  • The Problem: The 2.4 GHz band provides only three non-overlapping channels and suffers from widespread interference from Bluetooth, microwaves, and legacy devices. However, many dual-band and tri-band client devices default to associating with 2.4 GHz because its lower frequency signals appear stronger in passive beacon scans.
  • The Solution: When a client known to be 5 GHz- or 6 GHz-capable tries to authenticate on 2.4 GHz, ClientMatch does not let it connect there, pushing it to a better band. In AOS 10 it moves 2.4 GHz clients whose signal is worse than -45 dBm only to a 5 or 6 GHz radio that hears them better than -65 dBm.

2. Sticky Client Steering

  • The Problem: As a user walks through a campus building with a laptop, the laptop maintains its connection to the original AP down the hall even when the signal drops to -78 dBm (high packet error rate, low data rate), ignoring a fresh AP right above the user.
  • The Solution: Because ClientMatch knows which radios hear the client and how well, it can identify a much better candidate AP and tell the client to move there.

3. Load Balancing Steering

  • In crowded environments like university auditoriums or cafeteria spaces, dozens of clients may crowd onto the first AP near the entryway while adjacent APs in the room sit idle. ClientMatch balances client counts per radio. Load-balancing moves use only 802.11v, never deauth moves.

4. MU-MIMO Steering

  • ClientMatch groups MU-MIMO-capable clients on the same radios so the AP can actually use MU-MIMO.

ClientMatch Steering Protocols and Unsteerable Client Management

To execute steering decisions without causing connection drops or user-visible latency spikes, ClientMatch uses standards-based protocols:

Standards-Based Steering: IEEE 802.11v and 802.11k

  1. 802.11k (Radio Resource Measurement): The AP transmits Neighbor Reports to the client. This report contains a curated list of neighboring APs, their operating channels, and signal metrics. When the client needs to roam, it queries only the listed candidate channels rather than scanning all 50+ channels across the spectrum, cutting roaming delay to milliseconds.
  2. 802.11v (BSS Transition Management): This is ClientMatch's primary steering mechanism. When ClientMatch decides to steer a client, the current AP transmits an 802.11v BSS Transition Management Request frame to the device. This frame specifies recommended target BSSIDs (candidate APs) and the reason for the steer. Modern operating systems (iOS, Android, Windows, macOS) evaluate the request and execute a clean, seamless handoff to the recommended AP.

Deauth Moves

A deauth move sends a deauthentication frame to the client and then allows it to associate only to the desired radio for a period of time. ClientMatch uses deauth moves when 802.11v is not effective: if a client ignores or rejects 802.11v requests five or more times, ClientMatch switches to a deauth move.

Unsteerable Client Management

Some clients refuse to cooperate:

  • After three unsuccessful deauth steer attempts, the client goes on the unsteerable list for 48 hours.
  • After ignoring more than five consecutive 802.11v moves, it goes on the list for 24 hours.
  • Known problem devices can be added to the unsteerable list permanently through the REST API. While a client is on the list, ClientMatch leaves it on its chosen AP, which keeps legacy hardware stable.

Systematic Comparison: AirMatch vs ClientMatch

Operational DimensionAirMatchClientMatch
Primary ObjectiveOptimize AP radio infrastructure (channels, power, widths)Optimize client association, band distribution, and roaming
Execution Frequency24-hour cycle, deployed at the scheduled timeContinuous evaluation of client conditions
Operational LocationCentral serviceOrchestrated by Central in AOS 10 (Mobility Conductor in AOS 8)
Controlled ParametersChannel numbers, Channel widths (20-160 MHz), EIRP (dBm)Client BSSID association, Band allocation (2.4/5/6 GHz)
Key Inputs / Telemetry24-hr neighbor path-loss matrix, noise floor, radar eventsReal-time client RSSI/SNR, retry rates, 802.11k/v capabilities
Reactive TriggersRadar, high noise, and channel-quality eventsSticky, band, load-balance, and MU-MIMO conditions
Exception HandlingConfiguration constraints and coverage-tuning thresholdUnsteerable list (24 or 48 hours)

Common Exam Traps

  • AirMatch vs. ClientMatch Roles: Confusing which system manages what. AirMatch tunes AP radios (infrastructure RF: channels, EIRP power, channel widths). ClientMatch tunes client connections (endpoints: band steering, sticky client steering, 802.11v roaming).
  • The Mid-Day Channel Flap Assumption: Believing that AirMatch constantly switches AP channels throughout the business day like legacy ARM. AirMatch deploys one coordinated plan per 24-hour cycle at the scheduled time, and between plans it reacts only to events such as radar, high noise, and poor channel quality.
  • Who Controls Roaming: Forgetting that in IEEE 802.11 standards, the client makes the ultimate roaming decision. ClientMatch recommends target APs via 802.11v BSS Transition frames, but well-behaved clients evaluate the guidance before initiating the handoff.
Loading diagram...
AirMatch Cloud RF Optimization vs ClientMatch Real-Time Steering Lifecycle
Test Your Knowledge

How does Aruba AirMatch improve upon the operational behavior of legacy Adaptive Radio Management (ARM) in campus wireless deployments?

A

AirMatch builds a coordinated channel, power, and width plan from 24 hours of data and deploys it at a set time

B

AirMatch forces all access points to transmit at maximum legal EIRP at all times, removing the need for channel planning

C

AirMatch hands every RF decision to individual client smartphones by using 802.11k neighbor reports

D

AirMatch changes AP channels every five minutes during peak hours in response to local real-time retries

Test Your Knowledge

A hospital nurse pushing a wireless workstation-on-wheels walks down a long corridor. The workstation's wireless adapter remains associated with an AP down the hallway with an RSSI of -77 dBm, even though an AP on the ceiling directly above reports an RSSI of -58 dBm. Which mechanism and protocol will Aruba ClientMatch primarily use to steer this sticky workstation to the closer AP?

A

ClientMatch sends an AirSlice reservation to the distant AP to boost its antenna gain by 15 dBi

B

ClientMatch sends an 802.11v BSS Transition Management request suggesting the closer AP's BSSID

C

ClientMatch sends an 802.1Q tagged frame telling the access switch to shut down the distant AP's PoE port

D

ClientMatch sets the client's DHCP lease time to zero, forcing it to release its IP address and reconnect

Test Your Knowledge

During a wireless deployment in a manufacturing warehouse, network engineers observe that several legacy handheld barcode scanners repeatedly ignore 802.11v BSS Transition requests and keep returning to the same AP after deauth moves. How does Aruba ClientMatch handle these non-compliant devices to maintain operational stability?

A

ClientMatch raises the transmit power of all surrounding APs to 30 dBm to overwhelm the scanners' receivers

B

ClientMatch moves the AP radios from 5 GHz to 6 GHz so that the scanners are forced onto Wi-Fi 6E spectrum

C

ClientMatch permanently bans the scanners' MAC addresses from associating with any AP in the enterprise

D

ClientMatch marks them unsteerable after repeated failed attempts and stops steering them for a period

Sections you finish are checked off in the contents.