SlideShare a Scribd company logo
1 of 30
Download to read offline
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 1 #airheadsconf#airheadsconf
Mobility Access Switches
& Wired/Wireless Integration
Madani Adjali
June 4th & 5th
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 2 #airheadsconf
Platform Overview
Software Defined Networking
Role Based User Access
ClearPass Downloadable Roles
Aruba AP Interworking
Agenda
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 3 #airheadsconf#airheadsconf3
Product Overview
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 4 #airheadsconf
•  Security to wired access
-  Flexible role-based access
-  Policy moves from wireless to wired
•  Operational simplicity
-  Low-touch installation and configuration**
-  Dynamic configuration of policies
-  Integration with Aruba Instant
•  Simplify the network
-  Eliminate VLANs in the closet
-  Extend logical configurations
•  802.11ac Ready
-  Scaled to support high-density
deployments
-  PoE+ on every switch port
Introducing the Aruba
Mobility Access Switch Family
**Roadmap – Activate Integration
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 5 #airheadsconf
Mobility Access Switch Capabilities
A.  Ethernet Switch
•  Layer 2/3 forwarding
•  Role-based policy
enforcement
B.  Integration with ClearPass
•  Role-based policy
•  Downloadable Role/ACL
C.  Wired Access Point
•  Tunneled Node
•  Role-based policy
enforcement at Mobility
Controller
•  Single policy for WLAN
and wired
A. L2/L3
Forwarding
C. Wired AP
Mobility Access
Switch
Access Point
LAN Core
Mobility
Controller
AirWave
Management
Platform
ClearPass Policy
Manager
B. Role/ACL
Download
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 6 #airheadsconf
S3500 Mobility Access Switch
•  Designed for Wired Access
–  24/48 Port Models
–  Wire-rate and non-blocking performance
–  Role-based access with user visibility
–  Per port PoE/PoE+
•  ArubaStack
–  Stack up to 8 devices
–  Up to 384x GbE and 16x 10GbE
–  Single management IP address
–  Single configuration file
•  Flexible Forwarding Options
–  Traditional L2/L3 Switching
–  Tunnel traffic to Mobility Controller
•  Modular Components
–  Field replaceable AC power supplies
•  Optional redundant power supply
–  Field replaceable fan tray
–  Optional 4-port uplink module
•  1000BASE/10GBASE-x SFP/SFP+
Note: PoE budget assumes power-supplies are load-sharing.
SKU Ports PoE Budget
S3500-24F 24x1000BASE-X Not Applicable
S3500-24T 24x10/100/1000BASE-T Not Applicable
S3500-24P 24x10/100/1000BASE-T 660W
S3500-48T 48x10/100/1000BASE-T Not Applicable
S3500-48P 48x10/100/1000BASE-T 660W
S3500-48PF 48x10/100/1000BASE-T 1440W
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 7 #airheadsconf
S3500: Front and Rear Views
•  Modular Components
–  Power Supplies
–  Fan Tray
–  Uplink Module
•  Rackmount Options
-  2 Post Rack (front & mid-mount)
-  4 Post Rack
-  Wall Mount
•  Dimensions & Airflow
-  1RU
-  1.75˝ (H) x 17.5˝ (W) x 17.5˝ (D)
-  Front/Side to Rear Airflow
•  Management
-  Console (RJ45 Serial)
-  Out-of-band Ethernet
-  USB Storage
-  LCD Display
•  Limited Lifetime Warranty
Optional
Uplink Module
S3500-48P Front View
Fixed 10/100/1000BASE-T Ports
S3500 Rear View
Console
USB Field-Replaceable
Fan Tray
Hot-Swappable Power Supplies
Ethernet
Out-of-Band
S3500-24F Front View
24x1000BASE-X SFP Ports
LCD
LCD
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 8 #airheadsconf
S2500 Mobility Access Switch
SKU Ports PoE Budget
S2500-24T 24x 10/100/1000BASE-T Not Applicable
S2500-24P 24x 10/100/1000BASE-T 400W
S2500-48T 48x 10/100/1000BASE-T Not Applicable
S2500-48P 48x 10/100/1000BASE-T 400W
•  Designed for Wired Access
–  24/48-port 10/100/1000BASE-T
–  Wire-rate and non-blocking performance
–  Role-based access with user visibility
–  Per port PoE/PoE+
•  ArubaStack
–  Stack up to 8 devices
–  Up to 384x GbE and 16x 10GbE
–  Single management IP address
–  Single configuration file
–  Stackable with S3500
•  Flexible Forwarding Options
–  Traditional L2/L3 Switching
–  Tunneled traffic to Mobility Controller
•  Integrated Components
–  Built in fans for quiet operation
–  Fixed 4-port uplinks
•  1000BASE/10GBASE-x SFP/SFP+
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 9 #airheadsconf
S2500: Front and Rear Views
S2500 Front View
S2500 Rear View
Fixed 10/100/1000BASE-T Ports Fixed 4xGE/10G Uplinks
LCD
Display
USB Integrated
Power Supply
Fixed Fans
•  Fixed Components
–  Built-in Uplinks
–  Integrated Power
•  PoE Budget
-  400W
-  PoE Priority Available
•  Rackmount Options
-  2 Post Rack (Front)
-  Wall & 2-Post Mid Mount
•  Dimensions & Airflow
-  1RU
-  1.75˝ (H) x 17.5˝ (W) x 12˝ (D)
-  Side to side airflow
•  Management
-  Console (RJ45 & mUSB Serial)
-  Out-of-band Ethernet
-  USB Storage
-  LCD Display
•  Limited Lifetime Warranty
Ethernet
Out-of-Band
Console
Mini-USB
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 10 #airheadsconf
S1500 Mobility Access Switch
SKU Ports PoE Budget
S1500-24P 24x 10/100/1000BASE-T 400W
S1500-48P 48x 10/100/1000BASE-T 400W
•  Designed for Wired Access
–  24/48-port 10/100/1000BASE-T
–  Wire-rate and non-blocking
performance
–  Role-based access with user
visibility
–  Per port PoE/PoE+
•  Flexible Forwarding Options
–  Traditional L2/L3 Switching
–  Tunneled traffic to Mobility
Controller
•  Integrated Components
–  Built in fans for quiet operation
–  Fixed 4-port uplinks
•  1000BASE-x SFP
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 11 #airheadsconf
S1500: Front and Rear Views
S1500-48P Front View
S1500-24/48P Rear View
Console
USB Integrated Power Supply
Fixed
4x 1000BASE-X
(SFP) Ports
48x 10/100/1000 (RJ45) Ports
Mode LEDs and
Selector
•  Fixed Components
–  4x 1000BASE-x Uplinks (SFP)
–  Integrated Power
•  PoE Budget
-  400W
-  PoE Priority Available
•  Features & Scaling
–  Reduced Scaling vs. S2500
–  Same Feature Set vs. S2500
•  Rackmount Options
-  2 Post Rack (Front)
-  Wall & 2-Post Mid Mount
•  Dimensions & Airflow
-  1RU
-  1.75˝ (H) x 17.5˝ (W) x 12˝ (D)
-  Side to side airflow
•  Management
-  Console (RJ45)
-  USB Storage
•  Limited Lifetime Warranty
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 12 #airheadsconf
Features & Capabilities Overview
•  ArubaStack
•  Multiple Spanning Tree (MSTP) & Rapid PVST+
•  Link Aggregation Group
•  Hot Standby Link
•  GVRP*
•  Voice VLAN
-  LLDP-MED & CDP Fingerprinting
•  Quality of Service (Granular QoS)
•  Ethernet OAM 802.3ah*
Platform / Layer 2 Features
Authentication & Security
•  Role Based User Access
•  User Derived Roles
-  MAC, DHCP Signature*
•  AAA Authentication
-  802.1X, MAC, Captive Portal*
•  External Authentication Servers
-  Radius, Tacacs+ & LDAP
•  Radius Fail-Open*
•  Tunneled Node to Mobility Controller
Routing / Layer 3
•  Routed VLAN Interface (RVI)
•  Static Routing
•  OSPFv2
-  MD5 Authentication
-  Route Filtering*
•  Multicast
-  PIM-SM
-  IGMP Snooping/MLDv1
•  Network Address Translation*
•  Instant/Campus AP PoE Prioritization
•  Instant Rogue AP Enforcement
•  Instant VLAN Sharing
•  Airgroup
•  ClearPass Policy Manager (CPPM)
-  Downloadable Roles
•  ClearPass Guest (CPG)
•  Site to Site IPSEC VPN
Aruba Portfolio Integration*
*New in AOS 7.2/7.2.1
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 13 #airheadsconf#airheadsconf13
Software Defined Networking
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 14 #airheadsconf
Software Defined Unified Access
Personalized	
  Experience	
  	
  
User	
  
Simplify	
  Network	
  Ops	
  
IT	
  
VPN	
  
Access	
  Policy	
   Mobility	
  State	
   Performance	
  
Management	
   LocaCon	
   Content	
   Network	
  Apps	
  AnalyCcs	
  
Onboard	
  New	
  Apps,	
  
BYOD	
  &	
  Guests	
  
Flow	
  Awareness,	
  
App	
  Services	
  
Monitor	
  Wi-­‐Fi,	
  Wired	
  
&	
  WAN	
  	
  
Controller	
   AirWave	
  ClearPass	
  
SDN	
  Control	
  Plane	
  	
  
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 15 #airheadsconf
Airgroup Today
Airwave Management
Platform (Optional)
ClearPass Policy
Manager (Optional)
Mobility Controller
Core/Distribution
Registered to:
User X
Role Faculty
Guest
Registered to:
User C
Role Student
Guest
Registered to:
User C
Role StudentRegistered to:
User Y
Role Faculty
Registered to:
User B
Role Student
Registered to:
User X
Role Faculty
Campus-PSK VLAN: 100-104
Campus-802.1x VLAN: 200-204
VLAN 400
VLAN 500
Guest VLAN: 999
Guest
Registered to:
User A
Role Student
Multicast DNS traffic is forwarded via
GRE to Mobility Controller to provide
AirPlay/AirPrint services between
VLANs and between Wired/Wireless.
Registered to:
User B
Role Student
*New in AOS 7.2
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 16 #airheadsconf
Flow Steering Tomorrow
OF
OF
OF
OF
OF
OF
OF
OF
OF
OF
OF
OF
•  Virtual cut-through
paths per user/app
•  Unified access on
multi-vendor network
•  Stitching flows
across roles
OF
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 17 #airheadsconf#airheadsconf17
Role Based User Access
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 18 #airheadsconf
Our AAA View of the World
Manufacturers
Via MAC OUI
Operating Systems
Via DHCP
Fingerprinting
Mobility Access Switches see…
And our security enforcement model uses…
MAC
Addresses
Usernames/
Passwords
IP Phones
Via Device-Type
Fingerprinting
User-roles
…provisioned locally or dynamically
which simplifies AAA deployments
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 19 #airheadsconf
What is a User-Role?
A user-role is a container that consists of:
•  VLAN ID
•  Stateless ACLs
•  QoS Profile
•  Policer Profile
•  Captive Portal Settings
•  VoIP Profile
…A user-role can be referenced locally or passed
down via a Radius Vendor Specific Attribute
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 20 #airheadsconf
How do I implement User-Roles?
User Derivation Rules
•  Manufacturers by Vendor OUI
–  Instead of pre-populating a user database or a static MAC bypass list with
MAC addresses from the same vendor, create a UDR to match on the
Vendor’s OUI (first 6 digits or 24 bits) and assign a VLAN or user-role.
•  Operating Systems by DHCP Fingerprinting
–  Operating systems and some classes of devices utilize unique DHCP
messages (e.g. the options they request, the order of the options). A UDR
can be created to match on that unique fingerprint or signature and assign
a VLAN or user-role.
•  IP Phone by Device-Type Fingerprinting
–  IP Phones and AAA don’t always get along. Device-Type fingerprinting
allows you to match on an IP Phone’s LLDP/CDP “phone” capability
announcement so you can create a UDR to assign a VLAN or user-role.
No External Radius Required!
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 21 #airheadsconf
How do I implement User-Roles?
Traditional AAA Services
•  802.1x
–  For clients with 802.1x compatible supplicants, 802.1x provides
secure access using usernames/passwords and/or certificates.
Authenticated users can be assigned a default user-role or a
specific user-role.
•  MAC Authentication
–  For network assets that do not support 802.1x, MAC authentication
can be used to allow access to the network. Authenticated users
can be assigned a default user-role or a specific user-role.
•  Captive Portal
–  For guest clients, a web page can be provided so that they can
login and gain access. Guest users can then be assigned a
specific user-role limiting their network access.
Supported with Internal and External Auth Servers!
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 22 #airheadsconf
Begin Demo 1
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 23 #airheadsconf#airheadsconf23
Aruba CPPM & MAS
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 24 #airheadsconf
ClearPass Policy Manager Integration
802.11n AP ClearPass
Mobility
Controller
1. User provides their
credentials and other
context to Authenticate
Context
•  User: Joe Smith
•  Role: Guest
•  Device: Apple iPad
•  Date: M-F, 8am-5pm
•  Access: Internet
Mobility Access
Switch
2. ClearPass Policy
Manager returns Role
& Policy for User/
Device
3. Role & Policy pushed
to the Mobility Controller
for Role & Policy
Enforcement**
3. Role & Policy pushed
to the Mobility Access
Switch for Role & Policy
Enforcement*
Policy Enforcement Policy Definition
**Roadmap *New in AOS 7.2
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 25 #airheadsconf
Begin Demo 2
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 26 #airheadsconf#airheadsconf26
Aruba IAP & MAS
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 27 #airheadsconf
Aruba AP Interworking
PoE Prioritization (IAP/CAP)
Hi! You’re important so I’m
going to set your PoE
priority to high!
Hi! I’m an Instant
AP!
Rogue AP Enforcement (IAP)
I’ll shut it down! I’ll block its
traffic if I find it on trunk or
shutdown the access port
ALERT! I’ve found
a Rogue AP!
VLAN Sharing (IAP)
Alright, I’ll automatically
add them to our trunk port.
Thanks!
I’ve created 3
VLANs!
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 28 #airheadsconf
Begin Demo 3
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 29 #airheadsconf#airheadsconf
Thank You
CONFIDENTIAL
© Copyright 2013. Aruba Networks, Inc.
All rights reserved 30 #airheadsconf#airheadsconf30

More Related Content

What's hot

8 software defined networking and traffic engineering partha narasimhan_ash c...
8 software defined networking and traffic engineering partha narasimhan_ash c...8 software defined networking and traffic engineering partha narasimhan_ash c...
8 software defined networking and traffic engineering partha narasimhan_ash c...Aruba, a Hewlett Packard Enterprise company
 

What's hot (20)

2012 ah vegas remote networking fundamentals
2012 ah vegas   remote networking fundamentals2012 ah vegas   remote networking fundamentals
2012 ah vegas remote networking fundamentals
 
2012 ah vegas mobile device fundamentals
2012 ah vegas   mobile device fundamentals2012 ah vegas   mobile device fundamentals
2012 ah vegas mobile device fundamentals
 
Remote Wireless LANs
Remote Wireless LANsRemote Wireless LANs
Remote Wireless LANs
 
8 software defined networking and traffic engineering partha narasimhan_ash c...
8 software defined networking and traffic engineering partha narasimhan_ash c...8 software defined networking and traffic engineering partha narasimhan_ash c...
8 software defined networking and traffic engineering partha narasimhan_ash c...
 
Outdoor network engineering jeffrey weaver
Outdoor network engineering jeffrey weaverOutdoor network engineering jeffrey weaver
Outdoor network engineering jeffrey weaver
 
2012 ah apj wi fi design for voice & video
2012 ah apj   wi fi design for voice & video2012 ah apj   wi fi design for voice & video
2012 ah apj wi fi design for voice & video
 
2012 ah apj keynote - technology update
2012 ah apj   keynote - technology update2012 ah apj   keynote - technology update
2012 ah apj keynote - technology update
 
Mobility switch security architecture scott calzia madani adjali
Mobility switch security architecture scott calzia madani adjaliMobility switch security architecture scott calzia madani adjali
Mobility switch security architecture scott calzia madani adjali
 
Industry breakout focus on education open_dns_andy logan
Industry breakout focus on education open_dns_andy loganIndustry breakout focus on education open_dns_andy logan
Industry breakout focus on education open_dns_andy logan
 
2012 ah emea advanced mobility design
2012 ah emea   advanced mobility design2012 ah emea   advanced mobility design
2012 ah emea advanced mobility design
 
Industry breakout government military forum_jon green_stuart schulte
Industry breakout government military forum_jon green_stuart schulteIndustry breakout government military forum_jon green_stuart schulte
Industry breakout government military forum_jon green_stuart schulte
 
2012 ah vegas deploying byod
2012 ah vegas   deploying byod2012 ah vegas   deploying byod
2012 ah vegas deploying byod
 
Aruba webinar dorm wi fi design v4
Aruba webinar   dorm wi fi design v4Aruba webinar   dorm wi fi design v4
Aruba webinar dorm wi fi design v4
 
2012 ah apj rf troubleshooting
2012 ah apj   rf troubleshooting2012 ah apj   rf troubleshooting
2012 ah apj rf troubleshooting
 
Airheads scottsdale 2010 maximizing 11n performance
Airheads scottsdale 2010   maximizing 11n performanceAirheads scottsdale 2010   maximizing 11n performance
Airheads scottsdale 2010 maximizing 11n performance
 
Rf troubleshooting advanced kelly griffin_peter lane
Rf troubleshooting advanced kelly griffin_peter laneRf troubleshooting advanced kelly griffin_peter lane
Rf troubleshooting advanced kelly griffin_peter lane
 
4 healthcare forum deploying vocera on aruba wlan_kevin huey
4 healthcare forum deploying vocera on aruba wlan_kevin huey4 healthcare forum deploying vocera on aruba wlan_kevin huey
4 healthcare forum deploying vocera on aruba wlan_kevin huey
 
Airheads barcelona 2010 securing wireless la ns
Airheads barcelona 2010   securing wireless la nsAirheads barcelona 2010   securing wireless la ns
Airheads barcelona 2010 securing wireless la ns
 
5 steps to a faster, smarter wlan
5 steps to a faster, smarter wlan5 steps to a faster, smarter wlan
5 steps to a faster, smarter wlan
 
2 top10 tips from aruba tac rizwan shaikh
2 top10 tips from aruba tac rizwan shaikh2 top10 tips from aruba tac rizwan shaikh
2 top10 tips from aruba tac rizwan shaikh
 

Viewers also liked

Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...Aruba, a Hewlett Packard Enterprise company
 
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...Aruba, a Hewlett Packard Enterprise company
 

Viewers also liked (20)

Aruba instant the easy button for wireless gokul rajagopalan
Aruba instant the easy button for wireless gokul rajagopalanAruba instant the easy button for wireless gokul rajagopalan
Aruba instant the easy button for wireless gokul rajagopalan
 
2012 ah vegas guest access fundamentals
2012 ah vegas   guest access fundamentals2012 ah vegas   guest access fundamentals
2012 ah vegas guest access fundamentals
 
Do d directives regarding wireless lan
Do d directives regarding wireless lanDo d directives regarding wireless lan
Do d directives regarding wireless lan
 
Aruba networks webinar_wi-fi_without_interruption_sep20_2012
Aruba networks webinar_wi-fi_without_interruption_sep20_2012Aruba networks webinar_wi-fi_without_interruption_sep20_2012
Aruba networks webinar_wi-fi_without_interruption_sep20_2012
 
Gigabit wifi 802.11 ac in depth_peter thornycroft
Gigabit wifi 802.11 ac in depth_peter thornycroftGigabit wifi 802.11 ac in depth_peter thornycroft
Gigabit wifi 802.11 ac in depth_peter thornycroft
 
2012 ah vegas unified access fundamentals
2012 ah vegas   unified access fundamentals2012 ah vegas   unified access fundamentals
2012 ah vegas unified access fundamentals
 
Security intermediate practical cryptography_certs_and 802.1_x_rich langston...
Security intermediate  practical cryptography_certs_and 802.1_x_rich langston...Security intermediate  practical cryptography_certs_and 802.1_x_rich langston...
Security intermediate practical cryptography_certs_and 802.1_x_rich langston...
 
Hello instant 0612_1a
Hello instant 0612_1aHello instant 0612_1a
Hello instant 0612_1a
 
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
Case study migrating 1800 a ps to 7240 mobility controllers_douglas burke_ste...
 
Mac authentication amigopod radius
Mac authentication amigopod radiusMac authentication amigopod radius
Mac authentication amigopod radius
 
Creating an 802 1 xv3
Creating an 802 1 xv3Creating an 802 1 xv3
Creating an 802 1 xv3
 
2012 ah apj guest access fundamentals
2012 ah apj   guest access fundamentals2012 ah apj   guest access fundamentals
2012 ah apj guest access fundamentals
 
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
 
Airheads vail 2011 pci 2.0 compliance
Airheads vail 2011   pci 2.0 complianceAirheads vail 2011   pci 2.0 compliance
Airheads vail 2011 pci 2.0 compliance
 
2012 ah vegas top10 tips from aruba tac
2012 ah vegas   top10 tips from aruba tac2012 ah vegas   top10 tips from aruba tac
2012 ah vegas top10 tips from aruba tac
 
Guest wlan via gu iv3
Guest wlan via gu iv3Guest wlan via gu iv3
Guest wlan via gu iv3
 
Creating an 802 1 xv3
Creating an 802 1 xv3Creating an 802 1 xv3
Creating an 802 1 xv3
 
Air waveupdate sujathamandava
Air waveupdate sujathamandavaAir waveupdate sujathamandava
Air waveupdate sujathamandava
 
Airheads vail 2011 amigopod overview
Airheads vail 2011   amigopod overviewAirheads vail 2011   amigopod overview
Airheads vail 2011 amigopod overview
 
Advanced rf troubleshooting_peter lane
Advanced rf troubleshooting_peter laneAdvanced rf troubleshooting_peter lane
Advanced rf troubleshooting_peter lane
 

Similar to Mobility access switches_madani adjali

Avaya Networking Solution Overview
Avaya Networking Solution OverviewAvaya Networking Solution Overview
Avaya Networking Solution OverviewMotty Ben Atia
 
Next Generation Optical Networking: Software-Defined Optical Networking
Next Generation Optical Networking: Software-Defined Optical NetworkingNext Generation Optical Networking: Software-Defined Optical Networking
Next Generation Optical Networking: Software-Defined Optical NetworkingADVA
 
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Cisco Russia
 
PLNOG 13: Krzysztof Konkowski: Cisco Access Architectures: GPON, Ethernet, Ac...
PLNOG 13: Krzysztof Konkowski: Cisco Access Architectures: GPON, Ethernet, Ac...PLNOG 13: Krzysztof Konkowski: Cisco Access Architectures: GPON, Ethernet, Ac...
PLNOG 13: Krzysztof Konkowski: Cisco Access Architectures: GPON, Ethernet, Ac...PROIDEA
 
Design and Deployment of Enterprise WLANs
Design and Deployment of Enterprise WLANsDesign and Deployment of Enterprise WLANs
Design and Deployment of Enterprise WLANsFab Fusaro
 
Software Defined Optical Networks - Mayur Channegowda
Software Defined Optical Networks - Mayur ChannegowdaSoftware Defined Optical Networks - Mayur Channegowda
Software Defined Optical Networks - Mayur ChannegowdaCPqD
 
Software Defined Optical Networks - Mayur Channegowda
Software Defined Optical Networks - Mayur ChannegowdaSoftware Defined Optical Networks - Mayur Channegowda
Software Defined Optical Networks - Mayur ChannegowdaCPqD
 
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Cisco Russia
 

Similar to Mobility access switches_madani adjali (20)

Shanghai Breakout: Aruba Mobility Access Switch Workshop
Shanghai Breakout: Aruba Mobility Access Switch Workshop Shanghai Breakout: Aruba Mobility Access Switch Workshop
Shanghai Breakout: Aruba Mobility Access Switch Workshop
 
Extending Role Based Policies to Wired Access
Extending Role Based Policies to Wired AccessExtending Role Based Policies to Wired Access
Extending Role Based Policies to Wired Access
 
Breakout - Airheads Macau 2013 - Unified Access: Deploying Mobility Access S...
Breakout - Airheads Macau 2013 - Unified Access: Deploying  Mobility Access S...Breakout - Airheads Macau 2013 - Unified Access: Deploying  Mobility Access S...
Breakout - Airheads Macau 2013 - Unified Access: Deploying Mobility Access S...
 
Advanced Aruba Mobility Access Switch Workshop
Advanced Aruba Mobility Access Switch WorkshopAdvanced Aruba Mobility Access Switch Workshop
Advanced Aruba Mobility Access Switch Workshop
 
Migrating to the 7200 controller george anderson marcus christensen
Migrating to the 7200 controller george anderson marcus christensenMigrating to the 7200 controller george anderson marcus christensen
Migrating to the 7200 controller george anderson marcus christensen
 
Unified access with Aruba Mobility Access Switches – Live Demo
Unified access with Aruba Mobility Access Switches – Live DemoUnified access with Aruba Mobility Access Switches – Live Demo
Unified access with Aruba Mobility Access Switches – Live Demo
 
Overview of Major Aruba Switching Features incl. Smart Rate for Multi-Gig Ports
Overview of Major Aruba Switching Features incl. Smart Rate for Multi-Gig PortsOverview of Major Aruba Switching Features incl. Smart Rate for Multi-Gig Ports
Overview of Major Aruba Switching Features incl. Smart Rate for Multi-Gig Ports
 
Instant overview gokul_rajagopalan
Instant overview gokul_rajagopalanInstant overview gokul_rajagopalan
Instant overview gokul_rajagopalan
 
Avaya Networking Solution Overview
Avaya Networking Solution OverviewAvaya Networking Solution Overview
Avaya Networking Solution Overview
 
Next Generation Optical Networking: Software-Defined Optical Networking
Next Generation Optical Networking: Software-Defined Optical NetworkingNext Generation Optical Networking: Software-Defined Optical Networking
Next Generation Optical Networking: Software-Defined Optical Networking
 
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
 
PLNOG 13: Krzysztof Konkowski: Cisco Access Architectures: GPON, Ethernet, Ac...
PLNOG 13: Krzysztof Konkowski: Cisco Access Architectures: GPON, Ethernet, Ac...PLNOG 13: Krzysztof Konkowski: Cisco Access Architectures: GPON, Ethernet, Ac...
PLNOG 13: Krzysztof Konkowski: Cisco Access Architectures: GPON, Ethernet, Ac...
 
Решения Mobile Backhaul и Mobile Backhaul Security
Решения Mobile Backhaul и Mobile Backhaul SecurityРешения Mobile Backhaul и Mobile Backhaul Security
Решения Mobile Backhaul и Mobile Backhaul Security
 
1 voice and video over wi fi-balajee krishnamurthy
1 voice and video over wi fi-balajee krishnamurthy1 voice and video over wi fi-balajee krishnamurthy
1 voice and video over wi fi-balajee krishnamurthy
 
Design and Deployment of Enterprise WLANs
Design and Deployment of Enterprise WLANsDesign and Deployment of Enterprise WLANs
Design and Deployment of Enterprise WLANs
 
Next generation remote networks aruba instant gokul rajagopalan
Next generation remote networks aruba instant gokul rajagopalanNext generation remote networks aruba instant gokul rajagopalan
Next generation remote networks aruba instant gokul rajagopalan
 
SGS-5240-48T4X Stackable Managed Switch
SGS-5240-48T4X Stackable Managed SwitchSGS-5240-48T4X Stackable Managed Switch
SGS-5240-48T4X Stackable Managed Switch
 
Software Defined Optical Networks - Mayur Channegowda
Software Defined Optical Networks - Mayur ChannegowdaSoftware Defined Optical Networks - Mayur Channegowda
Software Defined Optical Networks - Mayur Channegowda
 
Software Defined Optical Networks - Mayur Channegowda
Software Defined Optical Networks - Mayur ChannegowdaSoftware Defined Optical Networks - Mayur Channegowda
Software Defined Optical Networks - Mayur Channegowda
 
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
 

More from Aruba, a Hewlett Packard Enterprise company

More from Aruba, a Hewlett Packard Enterprise company (20)

Airheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba CentralAirheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
 
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard AgentsAirheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
 
Airheads Tech Talks: Advanced Clustering in AOS 8.x
Airheads Tech Talks: Advanced Clustering in AOS 8.xAirheads Tech Talks: Advanced Clustering in AOS 8.x
Airheads Tech Talks: Advanced Clustering in AOS 8.x
 
EMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Advance Aruba CentralEMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Advance Aruba Central
 
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.xEMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
 
EMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS SwitchEMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS Switch
 
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS SwitchEMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
 
Introduction to AirWave 10
Introduction to AirWave 10Introduction to AirWave 10
Introduction to AirWave 10
 
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS SwitchEMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
 
EMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- Aruba Central with Instant APEMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- Aruba Central with Instant AP
 
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.xEMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
 
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
EMEA Airheads-  Getting Started with the ClearPass REST API – CPPMEMEA Airheads-  Getting Started with the ClearPass REST API – CPPM
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
 
EMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP DeploymentEMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP Deployment
 
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.xEMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
 
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)
 
EMEA Airheads - What does AirMatch do differently?v2
 EMEA Airheads - What does AirMatch do differently?v2 EMEA Airheads - What does AirMatch do differently?v2
EMEA Airheads - What does AirMatch do differently?v2
 
Airheads Meetups: 8400 Presentation
Airheads Meetups: 8400 PresentationAirheads Meetups: 8400 Presentation
Airheads Meetups: 8400 Presentation
 
Airheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau PresentationAirheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau Presentation
 
Airheads Meetups- High density WLAN
Airheads Meetups- High density WLANAirheads Meetups- High density WLAN
Airheads Meetups- High density WLAN
 
Airheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes ArubaAirheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes Aruba
 

Recently uploaded

The Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfThe Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfSeasiaInfotech2
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Vector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesVector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesZilliz
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
Training state-of-the-art general text embedding
Training state-of-the-art general text embeddingTraining state-of-the-art general text embedding
Training state-of-the-art general text embeddingZilliz
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr LapshynFwdays
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Manik S Magar
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 

Recently uploaded (20)

The Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdfThe Future of Software Development - Devin AI Innovative Approach.pdf
The Future of Software Development - Devin AI Innovative Approach.pdf
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Vector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector DatabasesVector Databases 101 - An introduction to the world of Vector Databases
Vector Databases 101 - An introduction to the world of Vector Databases
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Training state-of-the-art general text embedding
Training state-of-the-art general text embeddingTraining state-of-the-art general text embedding
Training state-of-the-art general text embedding
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 

Mobility access switches_madani adjali

  • 1. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 1 #airheadsconf#airheadsconf Mobility Access Switches & Wired/Wireless Integration Madani Adjali June 4th & 5th
  • 2. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 2 #airheadsconf Platform Overview Software Defined Networking Role Based User Access ClearPass Downloadable Roles Aruba AP Interworking Agenda
  • 3. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 3 #airheadsconf#airheadsconf3 Product Overview
  • 4. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 4 #airheadsconf •  Security to wired access -  Flexible role-based access -  Policy moves from wireless to wired •  Operational simplicity -  Low-touch installation and configuration** -  Dynamic configuration of policies -  Integration with Aruba Instant •  Simplify the network -  Eliminate VLANs in the closet -  Extend logical configurations •  802.11ac Ready -  Scaled to support high-density deployments -  PoE+ on every switch port Introducing the Aruba Mobility Access Switch Family **Roadmap – Activate Integration
  • 5. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 5 #airheadsconf Mobility Access Switch Capabilities A.  Ethernet Switch •  Layer 2/3 forwarding •  Role-based policy enforcement B.  Integration with ClearPass •  Role-based policy •  Downloadable Role/ACL C.  Wired Access Point •  Tunneled Node •  Role-based policy enforcement at Mobility Controller •  Single policy for WLAN and wired A. L2/L3 Forwarding C. Wired AP Mobility Access Switch Access Point LAN Core Mobility Controller AirWave Management Platform ClearPass Policy Manager B. Role/ACL Download
  • 6. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 6 #airheadsconf S3500 Mobility Access Switch •  Designed for Wired Access –  24/48 Port Models –  Wire-rate and non-blocking performance –  Role-based access with user visibility –  Per port PoE/PoE+ •  ArubaStack –  Stack up to 8 devices –  Up to 384x GbE and 16x 10GbE –  Single management IP address –  Single configuration file •  Flexible Forwarding Options –  Traditional L2/L3 Switching –  Tunnel traffic to Mobility Controller •  Modular Components –  Field replaceable AC power supplies •  Optional redundant power supply –  Field replaceable fan tray –  Optional 4-port uplink module •  1000BASE/10GBASE-x SFP/SFP+ Note: PoE budget assumes power-supplies are load-sharing. SKU Ports PoE Budget S3500-24F 24x1000BASE-X Not Applicable S3500-24T 24x10/100/1000BASE-T Not Applicable S3500-24P 24x10/100/1000BASE-T 660W S3500-48T 48x10/100/1000BASE-T Not Applicable S3500-48P 48x10/100/1000BASE-T 660W S3500-48PF 48x10/100/1000BASE-T 1440W
  • 7. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 7 #airheadsconf S3500: Front and Rear Views •  Modular Components –  Power Supplies –  Fan Tray –  Uplink Module •  Rackmount Options -  2 Post Rack (front & mid-mount) -  4 Post Rack -  Wall Mount •  Dimensions & Airflow -  1RU -  1.75˝ (H) x 17.5˝ (W) x 17.5˝ (D) -  Front/Side to Rear Airflow •  Management -  Console (RJ45 Serial) -  Out-of-band Ethernet -  USB Storage -  LCD Display •  Limited Lifetime Warranty Optional Uplink Module S3500-48P Front View Fixed 10/100/1000BASE-T Ports S3500 Rear View Console USB Field-Replaceable Fan Tray Hot-Swappable Power Supplies Ethernet Out-of-Band S3500-24F Front View 24x1000BASE-X SFP Ports LCD LCD
  • 8. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 8 #airheadsconf S2500 Mobility Access Switch SKU Ports PoE Budget S2500-24T 24x 10/100/1000BASE-T Not Applicable S2500-24P 24x 10/100/1000BASE-T 400W S2500-48T 48x 10/100/1000BASE-T Not Applicable S2500-48P 48x 10/100/1000BASE-T 400W •  Designed for Wired Access –  24/48-port 10/100/1000BASE-T –  Wire-rate and non-blocking performance –  Role-based access with user visibility –  Per port PoE/PoE+ •  ArubaStack –  Stack up to 8 devices –  Up to 384x GbE and 16x 10GbE –  Single management IP address –  Single configuration file –  Stackable with S3500 •  Flexible Forwarding Options –  Traditional L2/L3 Switching –  Tunneled traffic to Mobility Controller •  Integrated Components –  Built in fans for quiet operation –  Fixed 4-port uplinks •  1000BASE/10GBASE-x SFP/SFP+
  • 9. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 9 #airheadsconf S2500: Front and Rear Views S2500 Front View S2500 Rear View Fixed 10/100/1000BASE-T Ports Fixed 4xGE/10G Uplinks LCD Display USB Integrated Power Supply Fixed Fans •  Fixed Components –  Built-in Uplinks –  Integrated Power •  PoE Budget -  400W -  PoE Priority Available •  Rackmount Options -  2 Post Rack (Front) -  Wall & 2-Post Mid Mount •  Dimensions & Airflow -  1RU -  1.75˝ (H) x 17.5˝ (W) x 12˝ (D) -  Side to side airflow •  Management -  Console (RJ45 & mUSB Serial) -  Out-of-band Ethernet -  USB Storage -  LCD Display •  Limited Lifetime Warranty Ethernet Out-of-Band Console Mini-USB
  • 10. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 10 #airheadsconf S1500 Mobility Access Switch SKU Ports PoE Budget S1500-24P 24x 10/100/1000BASE-T 400W S1500-48P 48x 10/100/1000BASE-T 400W •  Designed for Wired Access –  24/48-port 10/100/1000BASE-T –  Wire-rate and non-blocking performance –  Role-based access with user visibility –  Per port PoE/PoE+ •  Flexible Forwarding Options –  Traditional L2/L3 Switching –  Tunneled traffic to Mobility Controller •  Integrated Components –  Built in fans for quiet operation –  Fixed 4-port uplinks •  1000BASE-x SFP
  • 11. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 11 #airheadsconf S1500: Front and Rear Views S1500-48P Front View S1500-24/48P Rear View Console USB Integrated Power Supply Fixed 4x 1000BASE-X (SFP) Ports 48x 10/100/1000 (RJ45) Ports Mode LEDs and Selector •  Fixed Components –  4x 1000BASE-x Uplinks (SFP) –  Integrated Power •  PoE Budget -  400W -  PoE Priority Available •  Features & Scaling –  Reduced Scaling vs. S2500 –  Same Feature Set vs. S2500 •  Rackmount Options -  2 Post Rack (Front) -  Wall & 2-Post Mid Mount •  Dimensions & Airflow -  1RU -  1.75˝ (H) x 17.5˝ (W) x 12˝ (D) -  Side to side airflow •  Management -  Console (RJ45) -  USB Storage •  Limited Lifetime Warranty
  • 12. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 12 #airheadsconf Features & Capabilities Overview •  ArubaStack •  Multiple Spanning Tree (MSTP) & Rapid PVST+ •  Link Aggregation Group •  Hot Standby Link •  GVRP* •  Voice VLAN -  LLDP-MED & CDP Fingerprinting •  Quality of Service (Granular QoS) •  Ethernet OAM 802.3ah* Platform / Layer 2 Features Authentication & Security •  Role Based User Access •  User Derived Roles -  MAC, DHCP Signature* •  AAA Authentication -  802.1X, MAC, Captive Portal* •  External Authentication Servers -  Radius, Tacacs+ & LDAP •  Radius Fail-Open* •  Tunneled Node to Mobility Controller Routing / Layer 3 •  Routed VLAN Interface (RVI) •  Static Routing •  OSPFv2 -  MD5 Authentication -  Route Filtering* •  Multicast -  PIM-SM -  IGMP Snooping/MLDv1 •  Network Address Translation* •  Instant/Campus AP PoE Prioritization •  Instant Rogue AP Enforcement •  Instant VLAN Sharing •  Airgroup •  ClearPass Policy Manager (CPPM) -  Downloadable Roles •  ClearPass Guest (CPG) •  Site to Site IPSEC VPN Aruba Portfolio Integration* *New in AOS 7.2/7.2.1
  • 13. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 13 #airheadsconf#airheadsconf13 Software Defined Networking
  • 14. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 14 #airheadsconf Software Defined Unified Access Personalized  Experience     User   Simplify  Network  Ops   IT   VPN   Access  Policy   Mobility  State   Performance   Management   LocaCon   Content   Network  Apps  AnalyCcs   Onboard  New  Apps,   BYOD  &  Guests   Flow  Awareness,   App  Services   Monitor  Wi-­‐Fi,  Wired   &  WAN     Controller   AirWave  ClearPass   SDN  Control  Plane    
  • 15. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 15 #airheadsconf Airgroup Today Airwave Management Platform (Optional) ClearPass Policy Manager (Optional) Mobility Controller Core/Distribution Registered to: User X Role Faculty Guest Registered to: User C Role Student Guest Registered to: User C Role StudentRegistered to: User Y Role Faculty Registered to: User B Role Student Registered to: User X Role Faculty Campus-PSK VLAN: 100-104 Campus-802.1x VLAN: 200-204 VLAN 400 VLAN 500 Guest VLAN: 999 Guest Registered to: User A Role Student Multicast DNS traffic is forwarded via GRE to Mobility Controller to provide AirPlay/AirPrint services between VLANs and between Wired/Wireless. Registered to: User B Role Student *New in AOS 7.2
  • 16. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 16 #airheadsconf Flow Steering Tomorrow OF OF OF OF OF OF OF OF OF OF OF OF •  Virtual cut-through paths per user/app •  Unified access on multi-vendor network •  Stitching flows across roles OF
  • 17. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 17 #airheadsconf#airheadsconf17 Role Based User Access
  • 18. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 18 #airheadsconf Our AAA View of the World Manufacturers Via MAC OUI Operating Systems Via DHCP Fingerprinting Mobility Access Switches see… And our security enforcement model uses… MAC Addresses Usernames/ Passwords IP Phones Via Device-Type Fingerprinting User-roles …provisioned locally or dynamically which simplifies AAA deployments
  • 19. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 19 #airheadsconf What is a User-Role? A user-role is a container that consists of: •  VLAN ID •  Stateless ACLs •  QoS Profile •  Policer Profile •  Captive Portal Settings •  VoIP Profile …A user-role can be referenced locally or passed down via a Radius Vendor Specific Attribute
  • 20. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 20 #airheadsconf How do I implement User-Roles? User Derivation Rules •  Manufacturers by Vendor OUI –  Instead of pre-populating a user database or a static MAC bypass list with MAC addresses from the same vendor, create a UDR to match on the Vendor’s OUI (first 6 digits or 24 bits) and assign a VLAN or user-role. •  Operating Systems by DHCP Fingerprinting –  Operating systems and some classes of devices utilize unique DHCP messages (e.g. the options they request, the order of the options). A UDR can be created to match on that unique fingerprint or signature and assign a VLAN or user-role. •  IP Phone by Device-Type Fingerprinting –  IP Phones and AAA don’t always get along. Device-Type fingerprinting allows you to match on an IP Phone’s LLDP/CDP “phone” capability announcement so you can create a UDR to assign a VLAN or user-role. No External Radius Required!
  • 21. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 21 #airheadsconf How do I implement User-Roles? Traditional AAA Services •  802.1x –  For clients with 802.1x compatible supplicants, 802.1x provides secure access using usernames/passwords and/or certificates. Authenticated users can be assigned a default user-role or a specific user-role. •  MAC Authentication –  For network assets that do not support 802.1x, MAC authentication can be used to allow access to the network. Authenticated users can be assigned a default user-role or a specific user-role. •  Captive Portal –  For guest clients, a web page can be provided so that they can login and gain access. Guest users can then be assigned a specific user-role limiting their network access. Supported with Internal and External Auth Servers!
  • 22. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 22 #airheadsconf Begin Demo 1
  • 23. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 23 #airheadsconf#airheadsconf23 Aruba CPPM & MAS
  • 24. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 24 #airheadsconf ClearPass Policy Manager Integration 802.11n AP ClearPass Mobility Controller 1. User provides their credentials and other context to Authenticate Context •  User: Joe Smith •  Role: Guest •  Device: Apple iPad •  Date: M-F, 8am-5pm •  Access: Internet Mobility Access Switch 2. ClearPass Policy Manager returns Role & Policy for User/ Device 3. Role & Policy pushed to the Mobility Controller for Role & Policy Enforcement** 3. Role & Policy pushed to the Mobility Access Switch for Role & Policy Enforcement* Policy Enforcement Policy Definition **Roadmap *New in AOS 7.2
  • 25. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 25 #airheadsconf Begin Demo 2
  • 26. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 26 #airheadsconf#airheadsconf26 Aruba IAP & MAS
  • 27. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 27 #airheadsconf Aruba AP Interworking PoE Prioritization (IAP/CAP) Hi! You’re important so I’m going to set your PoE priority to high! Hi! I’m an Instant AP! Rogue AP Enforcement (IAP) I’ll shut it down! I’ll block its traffic if I find it on trunk or shutdown the access port ALERT! I’ve found a Rogue AP! VLAN Sharing (IAP) Alright, I’ll automatically add them to our trunk port. Thanks! I’ve created 3 VLANs!
  • 28. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 28 #airheadsconf Begin Demo 3
  • 29. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 29 #airheadsconf#airheadsconf Thank You
  • 30. CONFIDENTIAL © Copyright 2013. Aruba Networks, Inc. All rights reserved 30 #airheadsconf#airheadsconf30