This session will discuss WAN, branch and remote networking, including zero touch deployment, network security, simple and fast convergence for large scale IPSec deployments, seamless integration with cloud-based services, ADVPN, and others.
8. 8#ATM16
Modes supported by the controllers - Branch
@ArubaNetworks |
7005
Master11
7240/7220/7210
Local12
Branch13
Only 70xx series support BRANCH mode
18. 18#ATM16
Zero Touch Provisioning – DHCP Options
@ArubaNetworks |
Brand Office
7005 Mobility
Controller
BRANCH OFFICE / TELECOMMUTER
Internet Services
INTERNET
DHCP
DHCP Req with Option 60 set
to ArubaMC
19. 19#ATM16
Zero Touch Provisioning – DHCP Options
@ArubaNetworks |
Brand Office
7005 Mobility
Controller
BRANCH OFFICE / TELECOMMUTER
Internet Services
INTERNET
DHCP
DHCP Req with Option 60 set
to ArubaMC
20. 20#ATM16
Zero Touch Provisioning – DHCP Options
@ArubaNetworks |
Brand Office
7005 Mobility
Controller
BRANCH OFFICE / TELECOMMUTER
Internet Services
INTERNET
DHCP
DHCP Req with Option 60 set
to ArubaMC
DHCP Resp with Option 43 set
to Master controller IP and
country code of operation for
branch controller
21. 21#ATM16
Zero Touch Provisioning – DHCP Options
@ArubaNetworks |
Brand Office
7005 Mobility
Controller
BRANCH OFFICE / TELECOMMUTER
Internet Services
INTERNET
DHCP
DHCP Req with Option 60 set
to ArubaMC
DHCP Resp with Option 43 set
to Master controller IP and
country code of operation for
branch contoller
22. 22#ATM16
Zero Touch Provisioning – Activate
@ArubaNetworks |
Brand Office
7005 Mobility
Controller
BRANCH OFFICE / TELECOMMUTER
Aruba Activate
INTERNET
DHCP/DNS
DHCP Req with Option 60 set
to ArubaMC
DHCP Resp has no Option 43
Resolve
device.arubanetworks.com
23. 23#ATM16
Zero Touch Provisioning – Activate
@ArubaNetworks |
Brand Office
7005 Mobility
Controller
BRANCH OFFICE / TELECOMMUTER
Aruba Activate
INTERNET
DHCP/DNS
DHCP Req with Option 60 set
to ArubaMC
DHCP Resp has no Option 43
Resolve
device.arubanetworks.com
24. 24#ATM16
Zero Touch Provisioning – Activate
@ArubaNetworks |
Brand Office
7005 Mobility
Controller
BRANCH OFFICE / TELECOMMUTER
Aruba Activate
INTERNET
DHCP/DNS
DHCP Req with Option 60 set
to ArubaMC
DHCP Resp has no Option 43
Resolve
device.arubanetworks.com
Communicate with Activate on
port 443 (HTTPS)
25. 25#ATM16
Semi – Auto (mini-setup)
@ArubaNetworks |
Brand Office
7005 Mobility
Controller
BRANCH OFFICE / TELECOMMUTER
Internet Services
INTERNET
DHCP
DHCP Req with Option 60 set
to ArubaMC
DHCP Resp without Option 43
Device not found in activate
26. 26#ATM16
Semi – Auto (mini-setup)
@ArubaNetworks |
Brand Office
7005 Mobility
Controller
BRANCH OFFICE / TELECOMMUTER
Internet Services
INTERNET
DHCP
DHCP Req with Option 60 set
to ArubaMC
DHCP Resp without Option 43
Device not found in activateEnter Option (partial string is acceptable): mini-setup
Enter Branch Master switch IP address or FQDN: 10.69.129.100
Auto-provisioning is in progress. Choose one of the following options to override or debug...
'enable-debug' : Enable auto-provisioning debug logs
'disable-debug' : Disable auto-provisioning debug logs
'mini-setup' : Stop auto-provisioning and start mini setup dialog for branch role
'full-setup' : Stop auto-provisioning and start full setup dialog for any role
Enter Country Code: US
27. 27#ATM16
Manual (full-setup)
@ArubaNetworks |
Enter Option (partial string is acceptable): full-setup
Auto-provisioning is in progress. Choose one of the following options to override or debug...
'enable-debug' : Enable auto-provisioning debug logs
'disable-debug' : Disable auto-provisioning debug logs
'mini-setup' : Stop auto-provisioning and start mini setup dialog for branch role
'full-setup' : Stop auto-provisioning and start full setup dialog for any role
Are you sure that you want to stop auto-provisioning and start full setup dialog? (yes/no): yes
Enter System name [Aruba7005]: branch01-7005
Enter Switch Role (master|local|standalone|branch) [master]: branch
Enter Branch Master switch IP address or FQDN [172.16.0.254]: 10.69.129.100
Enter Branch wired uplink port [GE 0/0/0]: GE 0/0/3
Enter Branch wired-vlan Type (pppoe|dhcp|static) [static]: dhcp
This controller is restricted to Country code US for United States, please confirm?: yes
Enter Time Zone [PST-8:0]:
Enter Time in UTC [00:24:38]:
Enter Date (MM/DD/YYYY) [5/5/2015]:
28. 28#ATM16
HTTPS (mac address, serial number, SKU)
IAP - Activate Provisioning
@ArubaNetworks |
Internet
Master IAP/VC Activate
HTTPS (Provisioning settings)
DNS
Resolve device.arubanetworks.com
HTTPS
29. 29#ATM16
IAP – DHCP Provisioning
@ArubaNetworks |
Internet
Master IAP/VC ActivateDHCP
DHCP request with option 60
HTTPS
DHCP response with option 43
31. 31#ATM16
How does branch get its configuration?
@ArubaNetworks |
– 6.4.3 Introduces Smart Config Menu
– GUI based configuration ONLY
7240/7220/7210
Branch Config Group Whitelist
00:0b:86:b8:c2:98
00:0b:86:bd:33:44
00:0b:86:b8:ff:cd
MAC Address of Remote
Branch Controllers 70xx
32. 32#ATM16
How to configure the Whitelist?
@ArubaNetworks |
7240/7220/7210
Aruba Activate
Automatic via Activate
33. 33#ATM16
How to configure the Whitelist?
@ArubaNetworks |
7240/7220/7210
Aruba Activate
Automatic via Activate
34. 34#ATM16
How to configure the Whitelist?
@ArubaNetworks |
7240/7220/7210
Aruba Activate
Automatic via Activate Manual via User Input
7240/7220/7210
35. 35#ATM16
How to configure the Whitelist?
@ArubaNetworks |
7240/7220/7210
Aruba Activate
Automatic via Activate Manual via User Input
7240/7220/7210
48. 48#ATM16
What happens if we push a bad configuration?
@ArubaNetworks |
7005
Master pushes wrong VLAN11
7240/7220/7210
Causes Connectivity Loss12
49. 49#ATM16
What happens if we push a bad configuration?
@ArubaNetworks |
7005
Master pushes wrong VLAN11
7240/7220/7210
Causes Connectivity Loss12
BoC Factory Defaults13
Master pushes config14
No push after 10 failures15
50. 50#ATM16
Summary - ZTP
@ArubaNetworks |
New mode called “Branch” introduced (only supported on 70xx)11
70xx ships with last port on 4094 with DHCP Client enabled12
ZTP requires DHCP (Option 43) or Activate configured13
Smart Config Menu on 72xx introduced to manage branch configs14
Ability to push VLANs, IP, DHCP server etc config from Smart Menu15
Ability to recover from bad config or upgrade push16
56. 56#ATM16
Enable Redundancy and Centralized Licensing
@ArubaNetworks |
Headquarter
s
INTERNET
Aruba Activate
Aruba 5400R
Corp NetworkVIP – 10.69.129.100
Centralized Licensing
57. 57#ATM16
AP Groups and CSC Smart Configuration
@ArubaNetworks |
Headquarter
s
INTERNET
Aruba Activate
Aruba 5400R
Corp Network
Create AP Groups (WLANs)11
Create Smart Config Group12
Configure VLAN’s, IP’s, DHCP etc.13
58. 58#ATM16
Sync Whitelist from Activate
@ArubaNetworks |
Headquarter
s
INTERNET
Aruba Activate
Aruba 5400R
Corp Network
68. 68#ATM16
Centralized Layer 3 – Packet Flow
Internet
Firewall Load Balancer Controller
IPSec tunnel UDP 4500
802.1x RADIUS
DHCP
DHCP request
DHCP request unicast to DHCP server by IAP using
VLAN IP
DHCP response by DHCP server to IAP’s VLAN IP
DHCP response
Client
Corporate traffic
VC is the gateway
69. 69#ATM16
Distributed Layer 3 – Packet Flow
Internet
Client Member IAP Master IAP/VC Controller
Internet Traffic Src NATed with VC’s Local IP
Corp. Traffic forwarded through IPSec tunnel
DHCP Discover
ARP reply
Internet Traffic
Corp. Traffic
DHCP Offer
DHCP Request
DHCP Ack
Gateway ARP
IPSec tunnel UDP port 4500
VC is the GW.
BID allocation process
70. 70#ATM16
Centralized Layer 2 – Packet Flow
Internet
Client Member IAP Master IAP/VC Controller
Internet Traffic Src NATed with VC’s Local IP
Corp. Traffic forwarded through IPSec tunnel via GRE
DHCP Discover
ARP reply
Internet Traffic
Corp. Traffic
DHCP Offer
DHCP Request
DHCP Ack
Gateway ARP
IPSec tunnel UDP port 4500
Forwarded by VC to Controller via GRE
Forwarded by VC to Controller via GRE
Forwarded by VC to Controller via GRE
GW is in the DC, if WAN is down VC will proxy ARP for GW.
71. 71#ATM16
Join Aruba’s Titans of Tomorrow
force in the fight against network
mayhem. Find out what your
IT superpower is.
Share your results with friends
and receive a free superpower
t-shirt.
www.arubatitans.com
Contest Overview
- Aruba is running a marketing campaign where we ask “What is your IT superpower?”
- Go to arubatitans.com to take a quick quiz to discover your superpower.
- Share your results with friends and encourage others to play the game
- Once you share, go to the Social and Community Hub, Gracia Commons, 3rd fl to pick up your free superpower shirt.
FAQ
1. What do I have to do to get a shirt?
Share your IT superpower results with friends and encourage them to play the game. Then come to the Social & Community Hub, 3rd Floor Gracia Commons to pick up your shirt. We just need your name and badge for verification.
2. Where do I get my shirt?
Come to the #ATM16 Social & Community hub located at Gracia Commons on the 3rd Floor
3. Do I have to be at the event to get the shirt?
Yes. You have to be at #ATM16 to get a shirt.
4. Can I get my colleague a shirt? He/she is in a session right now.
Unfortunately not. We encourage your colleague to participate so that they can win a shirt for themselves.
5. Can I bring a shirt home for my colleague?
Unfortunately not. You have to be at #ATM16 to get a shirt.
6. You don’t have a shirt in my size, can you ship the right size to me later?
Unfortunately not. Please select the best size from our inventory on site.