CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 1 #airheadsconf#airheadsconf
Aruba Instant – The for Wireless
Controllerless Wi-Fi for SME and DE
Presented by:
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 2 #airheadsconf
What makes for “Easy” wireless?
What is Aruba Instant?
Agenda
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 3 #airheadsconf
What is “Easy” WiFi?
•  No central point
of failure
•  High-Availability
•  Organic growth
•  Mobility-ready
•  No central bottleneck
•  RF optimization
•  Master AP
selection
•  Over-the-air
provisioning
•  WiFi oriented
configuration
Simple to
deploy
Self-
organizing
Self-
healing
Scalable
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 4 #airheadsconf#airheadsconf4
What comprises Instant
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 5 #airheadsconf
The Physical APs
Product	
   IAP	
   Descrip0on	
  
IAP-­‐92/93	
  
802.11abgn,	
  2x2	
  MIMO,	
  single	
  radio,	
  dual	
  band,	
  1	
  Ethernet	
  port,	
  reset	
  
buBon,	
  IAP-­‐92:	
  external	
  antennas,	
  IAP-­‐93:	
  internal	
  antennas	
  
IAP-­‐104/105	
  
802.11abgn,	
  2x2	
  MIMO,	
  dual	
  radio,	
  1	
  Ethernet	
  port,	
  reset	
  buBon,	
  
IAP-­‐104:	
  external	
  antennas,	
  IAP-­‐105:	
  internal	
  antennas	
  
IAP-­‐134/135	
  
802.11abgn,	
  3x3	
  MIMO,	
  dual	
  radio,	
  2	
  Ethernet	
  ports,	
  reset	
  buBon,	
  
IAP-­‐134:	
  external	
  antennas,	
  IAP-­‐135:	
  internal	
  antennas	
  
IAP-­‐175P/175AC	
  
802.11abgn,	
  2x2	
  MIMO,	
  dual	
  radio,	
  	
  antenna	
  connectors,	
  1	
  Ethernet	
  port,	
  
no	
  reset	
  buBon,	
  IAP-­‐175P:	
  POE,	
  IAP	
  -­‐175AC:	
  AC	
  powered	
  (with	
  PSE),	
  	
  
RAP-­‐3WN/P	
  
802.11bgn,	
  2x2	
  MIMO,	
  single	
  radio,	
  	
  integrated	
  antennas,	
  3	
  Ethernet	
  
ports,	
  USB,	
  reset	
  buBon,	
  RAP-­‐3WN:	
  AP-­‐AC-­‐UN	
  power,	
  RAP-­‐3WNP:	
  AP-­‐
AC-­‐48V36,	
  PSE	
  on	
  Ethernet	
  2	
  
RAP-­‐108/109	
  
802.11bgn,	
  2x2	
  MIMO,	
  dual	
  radio,	
  	
  2	
  Ethernet	
  ports	
  (1x	
  
10/100/1000BaseT,	
  1x	
  10/100BaseT),	
  USB,	
  RAP-­‐108:	
  external	
  antennas,	
  
RAP-­‐109:	
  internal	
  antennas	
  
RAP-­‐155/155P	
  
802.11abgn,	
  2.4GHz	
  radio	
  2x2:2,	
  5GHz	
  radio:	
  3x3:3	
  dual	
  radio,	
  
5	
  Ethernet	
  ports	
  5x	
  10/100/1000BaseT,	
  USB,	
  RAP-­‐155P:	
  54Vdc	
  supply,	
  
POE	
  PSE	
  support	
  on	
  two	
  LAN	
  ports	
  
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 6 #airheadsconf
•  De-centralized self-organizing system
•  Setup
–  Automatic master election
–  OTA provisioning
–  UI Localization
–  Virtual Controller Network IP
•  Functionality
–  On-board auto-RF, IP management, AAA, security
•  Resiliency
–  Failover
The Virtual Controller
Demo
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 7 #airheadsconf#airheadsconf7
Architectural Highlights
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 8 #airheadsconf
•  Distributed data-plane
–  Wireless encryption / decryption, firewall
•  Distributed control-plane
–  Authentication, DHCP, ARM, WIPS, Client state sync-up
•  Centralized (local) management-plane
–  Configuration, firmware management, GUI
Performance & Scalability
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 9 #airheadsconf
•  Adaptive Radio Management
–  Automatic channel & power assignment
–  Band-steering
–  Airtime Fairness and bandwidth contracts
–  Spectrum Load Balancing
•  Spectrum Analysis
–  Hybrid or dedicated mode spectrum analysis
•  Air Monitor
–  Rogue detection and containment
•  Wireless mesh
–  Automatic mesh connectivity and repair
Wireless Innovation
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 10 #airheadsconf
•  Layer 2 mobility
–  Direct peer to peer AP communication for transferring Client State
•  Layer 3 mobility
–  Optimized GRE tunnel-ing from connected network to home network
Mobility
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 11 #airheadsconf
•  Firewall
–  Per-user firewall
–  Policy-based forwarding and blacklisting
–  Bandwidth contracts
–  OS fingerprinting
•  Wireless Intrusion Detection
–  Background scanning of all wireless channels
–  Intrusion detection – dedicated or hybrid mode
–  Containment – tarpiting
–  Switch integration to block rogues
•  Guest SSID
–  Automatic VLAN separation without uplink VLAN support
Security
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 12 #airheadsconf
•  Dynamic Radius Proxy
–  Single NAS Client configuration in RADIUS server
•  Methods
–  In-built MAC-auth
–  In-built RADIUS
–  In-built captive portal
–  External AAA integration
–  802.11U (EAP-SIM)
•  Combinations
–  Fail-through
–  BYOD
AAA
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 13 #airheadsconf
•  Options
–  Ethernet
–  Cellular (3G and LTE)
–  Mesh
–  WiFi
–  PPPoE
•  Failover
–  Dual-ethernet,
–  Ethernet – Cellular
Uplink options
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 14 #airheadsconf
•  RF resiliency
•  Virtual controller redundancy
•  Uplink redundancy
•  External RADIUS redundancy & load-balancing
•  AirWave redundancy
•  VPN redundancy
Resiliency
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 15 #airheadsconf
•  Voice-type SSID
•  Application-Level Gateways
•  Media classification
•  Dynamic Multicast Optimization
•  AirGroup
Voice, Video & Convergence
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 16 #airheadsconf
•  Authentication
–  Inbuilt Captive Portal
–  Custom redirect
•  Content Filtering
–  OpenDNS
Guest Access
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 17 #airheadsconf
•  Firmware
–  InstantUI (Local)
–  Aruba Central
–  AirWave
•  Configuration
–  InstantUI
–  Aruba Central / AirWave
–  CLI
•  Troubleshooting
–  InstantUI
–  Remote – SNMP / Syslog / AirWave / Aruba Central
Management
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 18 #airheadsconf#airheadsconf
Thank You

Instant overview gokul_rajagopalan

  • 1.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 1 #airheadsconf#airheadsconf Aruba Instant – The for Wireless Controllerless Wi-Fi for SME and DE Presented by:
  • 2.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 2 #airheadsconf What makes for “Easy” wireless? What is Aruba Instant? Agenda
  • 3.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 3 #airheadsconf What is “Easy” WiFi? •  No central point of failure •  High-Availability •  Organic growth •  Mobility-ready •  No central bottleneck •  RF optimization •  Master AP selection •  Over-the-air provisioning •  WiFi oriented configuration Simple to deploy Self- organizing Self- healing Scalable
  • 4.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 4 #airheadsconf#airheadsconf4 What comprises Instant
  • 5.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 5 #airheadsconf The Physical APs Product   IAP   Descrip0on   IAP-­‐92/93   802.11abgn,  2x2  MIMO,  single  radio,  dual  band,  1  Ethernet  port,  reset   buBon,  IAP-­‐92:  external  antennas,  IAP-­‐93:  internal  antennas   IAP-­‐104/105   802.11abgn,  2x2  MIMO,  dual  radio,  1  Ethernet  port,  reset  buBon,   IAP-­‐104:  external  antennas,  IAP-­‐105:  internal  antennas   IAP-­‐134/135   802.11abgn,  3x3  MIMO,  dual  radio,  2  Ethernet  ports,  reset  buBon,   IAP-­‐134:  external  antennas,  IAP-­‐135:  internal  antennas   IAP-­‐175P/175AC   802.11abgn,  2x2  MIMO,  dual  radio,    antenna  connectors,  1  Ethernet  port,   no  reset  buBon,  IAP-­‐175P:  POE,  IAP  -­‐175AC:  AC  powered  (with  PSE),     RAP-­‐3WN/P   802.11bgn,  2x2  MIMO,  single  radio,    integrated  antennas,  3  Ethernet   ports,  USB,  reset  buBon,  RAP-­‐3WN:  AP-­‐AC-­‐UN  power,  RAP-­‐3WNP:  AP-­‐ AC-­‐48V36,  PSE  on  Ethernet  2   RAP-­‐108/109   802.11bgn,  2x2  MIMO,  dual  radio,    2  Ethernet  ports  (1x   10/100/1000BaseT,  1x  10/100BaseT),  USB,  RAP-­‐108:  external  antennas,   RAP-­‐109:  internal  antennas   RAP-­‐155/155P   802.11abgn,  2.4GHz  radio  2x2:2,  5GHz  radio:  3x3:3  dual  radio,   5  Ethernet  ports  5x  10/100/1000BaseT,  USB,  RAP-­‐155P:  54Vdc  supply,   POE  PSE  support  on  two  LAN  ports  
  • 6.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 6 #airheadsconf •  De-centralized self-organizing system •  Setup –  Automatic master election –  OTA provisioning –  UI Localization –  Virtual Controller Network IP •  Functionality –  On-board auto-RF, IP management, AAA, security •  Resiliency –  Failover The Virtual Controller Demo
  • 7.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 7 #airheadsconf#airheadsconf7 Architectural Highlights
  • 8.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 8 #airheadsconf •  Distributed data-plane –  Wireless encryption / decryption, firewall •  Distributed control-plane –  Authentication, DHCP, ARM, WIPS, Client state sync-up •  Centralized (local) management-plane –  Configuration, firmware management, GUI Performance & Scalability
  • 9.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 9 #airheadsconf •  Adaptive Radio Management –  Automatic channel & power assignment –  Band-steering –  Airtime Fairness and bandwidth contracts –  Spectrum Load Balancing •  Spectrum Analysis –  Hybrid or dedicated mode spectrum analysis •  Air Monitor –  Rogue detection and containment •  Wireless mesh –  Automatic mesh connectivity and repair Wireless Innovation
  • 10.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 10 #airheadsconf •  Layer 2 mobility –  Direct peer to peer AP communication for transferring Client State •  Layer 3 mobility –  Optimized GRE tunnel-ing from connected network to home network Mobility
  • 11.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 11 #airheadsconf •  Firewall –  Per-user firewall –  Policy-based forwarding and blacklisting –  Bandwidth contracts –  OS fingerprinting •  Wireless Intrusion Detection –  Background scanning of all wireless channels –  Intrusion detection – dedicated or hybrid mode –  Containment – tarpiting –  Switch integration to block rogues •  Guest SSID –  Automatic VLAN separation without uplink VLAN support Security
  • 12.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 12 #airheadsconf •  Dynamic Radius Proxy –  Single NAS Client configuration in RADIUS server •  Methods –  In-built MAC-auth –  In-built RADIUS –  In-built captive portal –  External AAA integration –  802.11U (EAP-SIM) •  Combinations –  Fail-through –  BYOD AAA
  • 13.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 13 #airheadsconf •  Options –  Ethernet –  Cellular (3G and LTE) –  Mesh –  WiFi –  PPPoE •  Failover –  Dual-ethernet, –  Ethernet – Cellular Uplink options
  • 14.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 14 #airheadsconf •  RF resiliency •  Virtual controller redundancy •  Uplink redundancy •  External RADIUS redundancy & load-balancing •  AirWave redundancy •  VPN redundancy Resiliency
  • 15.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 15 #airheadsconf •  Voice-type SSID •  Application-Level Gateways •  Media classification •  Dynamic Multicast Optimization •  AirGroup Voice, Video & Convergence
  • 16.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 16 #airheadsconf •  Authentication –  Inbuilt Captive Portal –  Custom redirect •  Content Filtering –  OpenDNS Guest Access
  • 17.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 17 #airheadsconf •  Firmware –  InstantUI (Local) –  Aruba Central –  AirWave •  Configuration –  InstantUI –  Aruba Central / AirWave –  CLI •  Troubleshooting –  InstantUI –  Remote – SNMP / Syslog / AirWave / Aruba Central Management
  • 18.
    CONFIDENTIAL © Copyright 2013.Aruba Networks, Inc. All rights reserved 18 #airheadsconf#airheadsconf Thank You