SlideShare a Scribd company logo
1 of 69
#ATM15 |
ARUBA WLANS 101 AND DESIGN
FUNDAMENTALS
Tim Cappalli
March 2015
@ArubaNetworks
2 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• Sr. Mobility Solutions Architect
Wireless Practice Lead
• Boston, MA
• Airheads Community: cappalli
• Favorite product? ClearPass
About Me
@ArubaNetworks
@tcappy0707
about.me/timcappalli
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved3#ATM15 |
Agenda
• Mobility controller architecture
• Aruba Instant architecture
• RAP-NG / IAP-VPN
• Management platforms
– Aruba Central
– AirWave
• Discussion & Questions
@ArubaNetworks
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved4#ATM15 |
Deployment types
• Mobility Controller: Master-local
• Mobility Controller: All masters
• Instant
• Instant: RAP-NG
• Hybrid! (all of the above, mix and match)
@ArubaNetworks
5#ATM15 |
Mobility Controller
Architecture
@ArubaNetworks
6 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Mobility Controller Family
@ArubaNetworks
256 APs
4,096 IPSec
512 APs
16,384 IPSec
1,024 APs
24,576 IPSec
2,048 APs
32,768 IPSec
7200 SERIES
7 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Mobility Controller Family
@ArubaNetworks
CLOUD SERVICES CONTROLLERS
16 APs
Can be powered via PoE
64 APs
32 APs
10 PoE+
8 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Mobility Controller Family
@ArubaNetworks
CLOUD SERVICES CONTROLLERS
32 APs, 24 PoE+, 2x10G
9 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Campus physical topology
@ArubaNetworks
Master
backup
Master
active
Local ControllerLocal Controller
Datacenter Datacenter
EDGEEDGEEDGE
10 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Campus logical topology
@ArubaNetworks
Master
standby
Master
active
Local ControllerLocal Controller
IPSEC
GRE
PRIMARY
GRE
STANDBY
11 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
L2 Deployment
@ArubaNetworks
Core/Distribution Switch
Controller
Tagged link
MGMT 30 10.200.30.1
CORP CLIENTS 31 10.200.31.1
BYOD CLIENTS 32 10.200.32.1
GUEST 33 10.200.33.1
30 10.200.30.5
31
32
33 10.200.33.5
BYOD Client
DNS / DHCP
IP 10.200.33.51
GW 10.200.33.1
12 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
L3 Deployment
@ArubaNetworks
WAN/Core/Distribution Router
TRANSIT 254 10.200.254.2/30
LOOPBACK lo 10.200.30.1
CORP CLIENTS 31 10.200.31.1
BYOD CLIENTS 32 10.200.32.1
GUEST 33 10.200.33.1
BYOD Client
DNS / DHCP
Controller
IP 10.200.33.51
GW 10.200.33.1
Transit link
10.200.254.1/30
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved13#ATM15 |
Master controller responsibilities
• Policy configuration
• Wireless security (WIPS / RFProtect)
• AP white lists (CAPs w/ CPsec and RAPs)
• Initial AP configuration
• Authentication and roles
@ArubaNetworks
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved14#ATM15 |
Local controller responsibilities
• AP and session termination
– Terminates AP tunnels
– User traffic processed and forwarded
• RFProtect enforcement and blacklisting
• ARM
• Mobility
• QoS
@ArubaNetworks
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved15#ATM15 |
Controller scaling
• Controller scaling table (VRD)
• The important numbers
– AP capacity
– User/device capacity << important!
– Tunnel capacity
• WMS scaling for master controller
– Master controller may need to be larger than the locals depending
on the environment
@ArubaNetworks
CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved16#ATM15 |
Controller scaling
• Platform
– 7000 series (7005/7010/7024/7030) should only be used as local
controllers*
– 7200 series should be master for multiple 7000 locals
• Failover capacity
@ArubaNetworks
17 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• Tunnel
• Bridge
• Decrypt-tunnel
• Configured per virtual-ap and per ethernet interface
• Choose based on network topology and
requirements
Campus Forwarding Modes
@ArubaNetworks
18 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• All traffic is tunneled back to controller
• User VLANs live in controller
• Wired network is a high-speed overlay network
• User traffic passes through stateful firewall and deep
packet inspection engine (*on 7 series controllers)
Tunnel
@ArubaNetworks
19 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• User traffic bridged out to local network
• User VLANs live in edge network
• Authentication traffic tunneled to controller
• Control plane security (cpsec) required
• Captive portal authentication is not supported
Bridge
@ArubaNetworks
20 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• User VLANs live in controller
• AP decrypts traffic and strips 802.11 headers
• AP adds 802.3 headers and frame is encapsulated in
GRE tunnel to controller
• Controller applies firewall policies to traffic
• Solves double-encryption issues when using a VPN
• Control plane security (cpsec) required
Decrypt-tunnel (d-tunnel)
@ArubaNetworks
2121#ATM15 |
Campus Redundancy
@ArubaNetworks
22 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Master-Local Redundancy
@ArubaNetworks
Standby
Master Local 1
Local 2
Local 1
Local 2
Local
Master
Master
Master
Local
Local n
Local n
Master
Fully Redundant
Redundant Aggregation
Hot Standby
No Redundancy
23 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
HA: AP Fast Failover
@ArubaNetworks
GRE
STANDBYGRE
ACTIVE
AOS 6.3+
24 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
HA: AP Fast Failover
@ArubaNetworks
GRE
ACTIVE
AOS 6.3+
25 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
AP FF: Controller Roles
• DUAL: Primary for some APs, standby for others
• ACTIVE: Controller does not terminate standby
tunnels for other controllers
• STANDBY: Controller only terminates standby
tunnels
@ArubaNetworks
26 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
AP FF: N+1 Oversubscription
@ArubaNetworks
Controller Platform Ratio Max GRE tunnels
7000-series
(70-05/10/24/30)
1:1 --
7210 4:1 16K
7220 4:1 32K
7240 4:1 64K
M3 & 3600 2:1 16K
AOS 6.4+
27 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
VRRP Failover (L2)
@ArubaNetworks
LMS-IP: 172.16.100.5
172.16.100.2
VRRP MASTER
172.16.100.5
VIRTUAL IP
172.16.100.3
VRRP BACKUP
GRE TUNNEL
SRC-IP <AP>
DST-IP: 172.16.100.5
28 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
VRRP Failover (L2)
@ArubaNetworks
LMS-IP: 172.16.100.5
172.16.100.5
VIRTUAL IP
172.16.100.3
VRRP MASTER
GRE TUNNEL
SRC-IP <AP>
DST-IP: 172.16.100.5
AP RE-BOOTSTRAPS
29 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Backup-LMS (L3)
@ArubaNetworks
LMS-IP: 172.16.100.2
BACKUP LMS-IP: 10.50.20.2
172.16.100.2 10.50.20.2
GRE TUNNEL
SRC-IP <AP>
DST-IP: 172.16.100.2
30 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Backup-LMS (L3)
@ArubaNetworks
LMS-IP: 172.16.100.2
BACKUP LMS-IP: 10.50.20.2
172.16.100.2 10.50.20.2
GRE TUNNEL
SRC-IP <AP>
DST-IP: 10.50.20.2
AP REBOOTS
31 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Remote AP (RAP)
@ArubaNetworks
32 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Remote AP (RAP)
• Purpose-built RAPs and campus APs
• Certificate-based provisioning
• Secure wired and wireless remote access
• RAPs are Instant out of the box
• Aruba Activate
@ArubaNetworks
33 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Remote AP
@ArubaNetworks
INTERNET
34 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
IPSEC TUNNEL
Remote AP - Logical
@ArubaNetworks
INTERNET
rap.arubanetworks.com
MAC-ETH0 24:DE:C6:CB:4A:F0 SERIAL BZ0030536
PROVISIONING TYPE IAP TO RAP
AP GROUP Boston-RAP
CONTROLLER rap.arubanetworks.com
ACTIVATE
35 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• Tunnel
• Bridge
• Decrypt-tunnel
• Split-tunnel
RAP Forwarding Modes
@ArubaNetworks
36 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• Tunnels certain traffic back to controller via IPSec
tunnel (defined in user roles)
• Allows non-corporate traffic to be bridged out locally
saving bandwidth.
• RAP handles encryption, decryption and firewall
enforcement locally
Split-tunnel
@ArubaNetworks
37 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Limitations
• Roaming
• ARM features
• Requires controller licenses
• Limited visibility
@ArubaNetworks
38#ATM15 |
Aruba Instant Architecture
@ArubaNetworks
39 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• AP model begins with the letter I
– IAP-225, IAP-215, IAP-205, etc
• Instant APs can be converted to controller-based APs
• No feature licensing with local management
• Manage locally, via AirWave, or Aruba Central (cloud)
• Dynamic provisioning via Aruba Activate (free)
Aruba Instant Overview
@ArubaNetworks
40 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
• Cooperate locally at L2
• Multiple uplink options (Ethernet, 4G/LTE, WiFi)
• ARM, ClientMatch, AppRF, AirGroup, L3 Mobility
• IAP-VPN/RAP-NG for distributed environments
Aruba Instant Overview - Technical
@ArubaNetworks
41 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Instant topology
@ArubaNetworks
INTERNET
VC
42 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Instant traffic flow
• Traffic destined for tunnels goes through VC
• NAT’d traffic (guest) goes through VC
• Regular user traffic firewalled, processed and
switched out at AP
@ArubaNetworks
43 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Instant traffic flow
@ArubaNetworks
INTERNET
VC
[10] 20,30 [10] 20,30
VC IP: 172.16.10.5
AP IP: 172.16.10.10 AP IP: 172.16.10.11
Client IP: 172.16.20.10www.google.com
44 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Instant traffic flow – Guest/NAT
@ArubaNetworks
INTERNET
VC
[10] 20,30 [10] 20,30
VC IP: 172.16.10.5
AP IP: 172.16.10.10 AP IP: 172.16.10.11
Client IP: 172.31.98.42
Internal IAP Guest Network
“Magic VLAN” 3333
172.31.98.x
Src-NAT’d with VC address www.google.com
45#ATM15 |
RAP-NG / IAP-VPN
@ArubaNetworks
46 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
RAP-NG / IAP-VPN Topology
@ArubaNetworks
Master
active
Master
backup
Master
active
Master
backup
Site 1
VC
Site 2
VC
Site 3
VC
INTERNET
Datacenter 1 Datacenter 2
47 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Benefits
• Local RF coordination
• Roaming
• Isolated broadcast domains for each cluster
• Authentication survivability
• MAS integration
@ArubaNetworks
48 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
DHCP modes
• Local
• Centralized L2
• Distributed L2
• Centralized L3
• Distributed L3
@ArubaNetworks
49 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
DHCP modes
@ArubaNetworks
DHCP MODE SUBNET DHCP CLIENT GW CORP TRAFFIC LCL/INTERNET
Local Local Master AP Master AP
Src-NAT
IPSec tunnel
Src-NAT
Master AP IP
Centralized L2 CORP Datacenter Datacenter
Tagged & switched to
datacenter via tunnel
Src-NAT
Master AP IP
Distributed L2 CORP Master AP Datacenter
Tagged & switched to
datacenter via tunnel
Src-NAT
Master AP IP
Centralized L3 CORP Datacenter Master AP
Routed to datacenter
inside IPSec tunnel
Src-NAT
Master AP IP
Distributed L3 CORP Master AP Master AP
Routed to datacenter
inside IPSec tunnel
Src-NAT
Master AP IP
50 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
RAP-NG/IAP-VPN licensing
• For basic VPN connectivity (single role), a
single PEFNG license is required
• To use different roles for individual IAP
clusters, the PEFV license is required for each
controller
@ArubaNetworks
5151#ATM15 |
Aruba Activate
@ArubaNetworks
52 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Aruba Activate
@ArubaNetworks
53 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Aruba Activate
@ArubaNetworks
54#ATM15 |
MANAGEMENT
@ArubaNetworks
5555#ATM15 |
Aruba Central
@ArubaNetworks
56 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Aruba Central Overview
• Cloud management for Instant and MAS
• ZTP with Aruba Activate
• Firmware management
• Reporting
• Responsive UI (adaptive to any display)*
• AppRF management and visibility*
• Cloud captive portal w/ social*
@ArubaNetworks
* Central 2.0 – Coming Soon
57 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Aruba Central
@ArubaNetworks
58 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Aruba Central
@ArubaNetworks
59 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Aruba Central
@ArubaNetworks
60 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Aruba Central
@ArubaNetworks
6161#ATM15 |
AirWave
@ArubaNetworks
62 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
AirWave Overview
• On-premise solution (VM or physical)
• Management, monitoring and reporting of Aruba
controllers, Instant clusters, and MAS
• Multi-vendor
• In a hybrid controller-Instant environment,
AirWave recommended
• Single pane of glass
@ArubaNetworks
63 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Single pane of glass
@ArubaNetworks
64 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Instant GUI config
@ArubaNetworks
65#ATM15 |
Discussion & Questions
@ArubaNetworks
66 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
arubanetworks.com/vrd
@ArubaNetworks
67 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Other resources
@ArubaNetworks
In-depth Wireless Architecture
cwnp.com
THANK YOU
68#ATM15 | @ArubaNetworks
69#ATM15 | @ArubaNetworks

More Related Content

What's hot

EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...
EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...
EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...Aruba, a Hewlett Packard Enterprise company
 
Customer Presentation - Aruba Wi-Fi Overview (1).PPTX
Customer Presentation - Aruba Wi-Fi Overview (1).PPTXCustomer Presentation - Aruba Wi-Fi Overview (1).PPTX
Customer Presentation - Aruba Wi-Fi Overview (1).PPTXssuser5824cf
 

What's hot (20)

EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...
EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...
EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...
 
Real-world 802.1X Deployment Challenges
Real-world 802.1X Deployment ChallengesReal-world 802.1X Deployment Challenges
Real-world 802.1X Deployment Challenges
 
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.xEMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
 
Adapting to evolving user, security, and business needs with aruba clear pass
Adapting to evolving user, security, and business needs with aruba clear passAdapting to evolving user, security, and business needs with aruba clear pass
Adapting to evolving user, security, and business needs with aruba clear pass
 
Wireless LAN Design Fundamentals in the Campus
Wireless LAN Design Fundamentals in the CampusWireless LAN Design Fundamentals in the Campus
Wireless LAN Design Fundamentals in the Campus
 
Roaming behavior and Client Troubleshooting
Roaming behavior and Client TroubleshootingRoaming behavior and Client Troubleshooting
Roaming behavior and Client Troubleshooting
 
EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
EMEA Airheads - Aruba Remote Access Point (RAP) TroubleshootingEMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
 
Guest Access with ArubaOS
Guest Access with ArubaOSGuest Access with ArubaOS
Guest Access with ArubaOS
 
Aruba ClearPass Guest 6.3 User Guide
Aruba ClearPass Guest 6.3 User GuideAruba ClearPass Guest 6.3 User Guide
Aruba ClearPass Guest 6.3 User Guide
 
Useful cli commands v1
Useful cli commands v1Useful cli commands v1
Useful cli commands v1
 
EMEA Airheads- ArubaOS - Understanding Control-Plane-Security
EMEA Airheads-  ArubaOS - Understanding Control-Plane-SecurityEMEA Airheads-  ArubaOS - Understanding Control-Plane-Security
EMEA Airheads- ArubaOS - Understanding Control-Plane-Security
 
Aruba Remote Access Point (RAP) Networks Validated Reference Design
Aruba Remote Access Point (RAP) Networks Validated Reference DesignAruba Remote Access Point (RAP) Networks Validated Reference Design
Aruba Remote Access Point (RAP) Networks Validated Reference Design
 
ClearPass Overview
ClearPass OverviewClearPass Overview
ClearPass Overview
 
Aruba 802.11ac networks: Validated Reference Designs
Aruba 802.11ac networks: Validated Reference DesignsAruba 802.11ac networks: Validated Reference Designs
Aruba 802.11ac networks: Validated Reference Designs
 
ClearPass Policy Model - An Introduction
ClearPass Policy Model - An IntroductionClearPass Policy Model - An Introduction
ClearPass Policy Model - An Introduction
 
Virtual Intranet Access (VIA)
Virtual Intranet Access (VIA)Virtual Intranet Access (VIA)
Virtual Intranet Access (VIA)
 
Customer Presentation - Aruba Wi-Fi Overview (1).PPTX
Customer Presentation - Aruba Wi-Fi Overview (1).PPTXCustomer Presentation - Aruba Wi-Fi Overview (1).PPTX
Customer Presentation - Aruba Wi-Fi Overview (1).PPTX
 
ClearPass design scenarios that solve the toughest security policy requirements
ClearPass design scenarios that solve the toughest security policy requirementsClearPass design scenarios that solve the toughest security policy requirements
ClearPass design scenarios that solve the toughest security policy requirements
 
Base Designs Lab Setup for Validated Reference Design
Base Designs Lab Setup for Validated Reference DesignBase Designs Lab Setup for Validated Reference Design
Base Designs Lab Setup for Validated Reference Design
 
Advanced rf troubleshooting_peter lane
Advanced rf troubleshooting_peter laneAdvanced rf troubleshooting_peter lane
Advanced rf troubleshooting_peter lane
 

Viewers also liked (9)

The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
 
RF characteristics and radio fundamentals
RF characteristics and radio fundamentalsRF characteristics and radio fundamentals
RF characteristics and radio fundamentals
 
The Top Eight Best Practices for Deploying XenApp and XenDesktop 7.6
The Top Eight Best Practices for Deploying XenApp and XenDesktop 7.6The Top Eight Best Practices for Deploying XenApp and XenDesktop 7.6
The Top Eight Best Practices for Deploying XenApp and XenDesktop 7.6
 
Network Management with Aruba AirWave
Network Management with Aruba AirWaveNetwork Management with Aruba AirWave
Network Management with Aruba AirWave
 
Getting the most out of the Aruba Policy Enforcement Firewall
Getting the most out of the Aruba Policy Enforcement FirewallGetting the most out of the Aruba Policy Enforcement Firewall
Getting the most out of the Aruba Policy Enforcement Firewall
 
Fast-track your career by going from wireless to mobility engineer
Fast-track your career by going from wireless to mobility engineerFast-track your career by going from wireless to mobility engineer
Fast-track your career by going from wireless to mobility engineer
 
Wi-Fi Security Fundamentals
Wi-Fi Security FundamentalsWi-Fi Security Fundamentals
Wi-Fi Security Fundamentals
 
A-to-Z design guide for the all-wireless workplace
A-to-Z design guide for the all-wireless workplaceA-to-Z design guide for the all-wireless workplace
A-to-Z design guide for the all-wireless workplace
 
Packets never lie: An in-depth overview of 802.11 frames
Packets never lie: An in-depth overview of 802.11 framesPackets never lie: An in-depth overview of 802.11 frames
Packets never lie: An in-depth overview of 802.11 frames
 

Similar to Aruba WLANs 101 and design fundamentals

Extend mobility to remote branch networks with Aruba's new cloud services con...
Extend mobility to remote branch networks with Aruba's new cloud services con...Extend mobility to remote branch networks with Aruba's new cloud services con...
Extend mobility to remote branch networks with Aruba's new cloud services con...Aruba, a Hewlett Packard Enterprise company
 
Transforming Networks into a NFV-Centric Environment
Transforming Networks into a NFV-Centric EnvironmentTransforming Networks into a NFV-Centric Environment
Transforming Networks into a NFV-Centric EnvironmentADVA
 
Deploying mobile unified communications and collaboration (UCC) with Microsof...
Deploying mobile unified communications and collaboration (UCC) with Microsof...Deploying mobile unified communications and collaboration (UCC) with Microsof...
Deploying mobile unified communications and collaboration (UCC) with Microsof...Aruba, a Hewlett Packard Enterprise company
 
FieldServer Overview 2015.r1
FieldServer Overview 2015.r1FieldServer Overview 2015.r1
FieldServer Overview 2015.r1Eric W Dunn
 
Integrating Unified Communications and Collaboration on an Aruba Access Network
Integrating Unified Communications and Collaboration on an Aruba Access NetworkIntegrating Unified Communications and Collaboration on an Aruba Access Network
Integrating Unified Communications and Collaboration on an Aruba Access NetworkAruba, a Hewlett Packard Enterprise company
 
ARUBA - Remote Branch-networking-fundamentals-2014
ARUBA - Remote Branch-networking-fundamentals-2014ARUBA - Remote Branch-networking-fundamentals-2014
ARUBA - Remote Branch-networking-fundamentals-2014Marcello Marchesini
 
IXIA VISIBILITY ARCHITECTURE Eliminating Blind spots
IXIA VISIBILITY ARCHITECTURE Eliminating Blind spotsIXIA VISIBILITY ARCHITECTURE Eliminating Blind spots
IXIA VISIBILITY ARCHITECTURE Eliminating Blind spotsCisco Russia
 
Oracle Cloud Networking And Security Exposed
Oracle Cloud Networking And Security Exposed Oracle Cloud Networking And Security Exposed
Oracle Cloud Networking And Security Exposed Riccardo Romani
 
Breakout - Airheads Macau 2013 - Microsoft Lync, Unified Communications, Clou...
Breakout - Airheads Macau 2013 - Microsoft Lync, Unified Communications, Clou...Breakout - Airheads Macau 2013 - Microsoft Lync, Unified Communications, Clou...
Breakout - Airheads Macau 2013 - Microsoft Lync, Unified Communications, Clou...Aruba, a Hewlett Packard Enterprise company
 

Similar to Aruba WLANs 101 and design fundamentals (20)

Unified access with Aruba Mobility Access Switches – Live Demo
Unified access with Aruba Mobility Access Switches – Live DemoUnified access with Aruba Mobility Access Switches – Live Demo
Unified access with Aruba Mobility Access Switches – Live Demo
 
Extend mobility to remote branch networks with Aruba's new cloud services con...
Extend mobility to remote branch networks with Aruba's new cloud services con...Extend mobility to remote branch networks with Aruba's new cloud services con...
Extend mobility to remote branch networks with Aruba's new cloud services con...
 
Access Management with Aruba ClearPass
Access Management with Aruba ClearPassAccess Management with Aruba ClearPass
Access Management with Aruba ClearPass
 
2012 ah vegas remote networking fundamentals
2012 ah vegas   remote networking fundamentals2012 ah vegas   remote networking fundamentals
2012 ah vegas remote networking fundamentals
 
FieldServer for Integrators Overview
FieldServer for Integrators OverviewFieldServer for Integrators Overview
FieldServer for Integrators Overview
 
Mobility switch security architecture scott calzia madani adjali
Mobility switch security architecture scott calzia madani adjaliMobility switch security architecture scott calzia madani adjali
Mobility switch security architecture scott calzia madani adjali
 
Transforming Networks into a NFV-Centric Environment
Transforming Networks into a NFV-Centric EnvironmentTransforming Networks into a NFV-Centric Environment
Transforming Networks into a NFV-Centric Environment
 
Deploying mobile unified communications and collaboration (UCC) with Microsof...
Deploying mobile unified communications and collaboration (UCC) with Microsof...Deploying mobile unified communications and collaboration (UCC) with Microsof...
Deploying mobile unified communications and collaboration (UCC) with Microsof...
 
FieldServer Overview 2015.r1
FieldServer Overview 2015.r1FieldServer Overview 2015.r1
FieldServer Overview 2015.r1
 
Integrating Unified Communications and Collaboration on an Aruba Access Network
Integrating Unified Communications and Collaboration on an Aruba Access NetworkIntegrating Unified Communications and Collaboration on an Aruba Access Network
Integrating Unified Communications and Collaboration on an Aruba Access Network
 
ARUBA - Remote Branch-networking-fundamentals-2014
ARUBA - Remote Branch-networking-fundamentals-2014ARUBA - Remote Branch-networking-fundamentals-2014
ARUBA - Remote Branch-networking-fundamentals-2014
 
Remote Wireless LANs
Remote Wireless LANsRemote Wireless LANs
Remote Wireless LANs
 
IXIA VISIBILITY ARCHITECTURE Eliminating Blind spots
IXIA VISIBILITY ARCHITECTURE Eliminating Blind spotsIXIA VISIBILITY ARCHITECTURE Eliminating Blind spots
IXIA VISIBILITY ARCHITECTURE Eliminating Blind spots
 
FieldServer for OEM Overview
FieldServer for OEM OverviewFieldServer for OEM Overview
FieldServer for OEM Overview
 
Next generation remote networks aruba instant gokul rajagopalan
Next generation remote networks aruba instant gokul rajagopalanNext generation remote networks aruba instant gokul rajagopalan
Next generation remote networks aruba instant gokul rajagopalan
 
Remote & Branch Networking Fundamentals #AirheadsConf Italy
Remote & Branch Networking Fundamentals #AirheadsConf ItalyRemote & Branch Networking Fundamentals #AirheadsConf Italy
Remote & Branch Networking Fundamentals #AirheadsConf Italy
 
Oracle Cloud Networking And Security Exposed
Oracle Cloud Networking And Security Exposed Oracle Cloud Networking And Security Exposed
Oracle Cloud Networking And Security Exposed
 
Outdoor network engineering jeffrey weaver
Outdoor network engineering jeffrey weaverOutdoor network engineering jeffrey weaver
Outdoor network engineering jeffrey weaver
 
Breakout - Airheads Macau 2013 - Microsoft Lync, Unified Communications, Clou...
Breakout - Airheads Macau 2013 - Microsoft Lync, Unified Communications, Clou...Breakout - Airheads Macau 2013 - Microsoft Lync, Unified Communications, Clou...
Breakout - Airheads Macau 2013 - Microsoft Lync, Unified Communications, Clou...
 
Airheads Macau 2013 - WLAN Management & Troubleshooting with AirWave
Airheads Macau 2013 - WLAN Management & Troubleshooting with AirWaveAirheads Macau 2013 - WLAN Management & Troubleshooting with AirWave
Airheads Macau 2013 - WLAN Management & Troubleshooting with AirWave
 

More from Aruba, a Hewlett Packard Enterprise company

More from Aruba, a Hewlett Packard Enterprise company (20)

Airheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba CentralAirheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
 
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard AgentsAirheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
 
EMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Advance Aruba CentralEMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Advance Aruba Central
 
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.xEMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
 
EMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS SwitchEMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS Switch
 
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS SwitchEMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
 
Introduction to AirWave 10
Introduction to AirWave 10Introduction to AirWave 10
Introduction to AirWave 10
 
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS SwitchEMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
 
EMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- Aruba Central with Instant APEMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- Aruba Central with Instant AP
 
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.xEMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
 
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
EMEA Airheads-  Getting Started with the ClearPass REST API – CPPMEMEA Airheads-  Getting Started with the ClearPass REST API – CPPM
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
 
EMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP DeploymentEMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP Deployment
 
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)
 
EMEA Airheads - What does AirMatch do differently?v2
 EMEA Airheads - What does AirMatch do differently?v2 EMEA Airheads - What does AirMatch do differently?v2
EMEA Airheads - What does AirMatch do differently?v2
 
Airheads Meetups: 8400 Presentation
Airheads Meetups: 8400 PresentationAirheads Meetups: 8400 Presentation
Airheads Meetups: 8400 Presentation
 
Airheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau PresentationAirheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau Presentation
 
Airheads Meetups- High density WLAN
Airheads Meetups- High density WLANAirheads Meetups- High density WLAN
Airheads Meetups- High density WLAN
 
Airheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes ArubaAirheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes Aruba
 
EMEA Airheads - Configuring different APIs in Aruba 8.x
EMEA Airheads - Configuring different APIs  in Aruba 8.x EMEA Airheads - Configuring different APIs  in Aruba 8.x
EMEA Airheads - Configuring different APIs in Aruba 8.x
 
EMEA Airheads - Multi zone ap and centralized image upgrade
EMEA Airheads - Multi zone ap and centralized image upgradeEMEA Airheads - Multi zone ap and centralized image upgrade
EMEA Airheads - Multi zone ap and centralized image upgrade
 

Recently uploaded

EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxKatpro Technologies
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slidevu2urc
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024Results
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 

Recently uploaded (20)

EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 

Aruba WLANs 101 and design fundamentals

  • 1. #ATM15 | ARUBA WLANS 101 AND DESIGN FUNDAMENTALS Tim Cappalli March 2015 @ArubaNetworks
  • 2. 2 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • Sr. Mobility Solutions Architect Wireless Practice Lead • Boston, MA • Airheads Community: cappalli • Favorite product? ClearPass About Me @ArubaNetworks @tcappy0707 about.me/timcappalli
  • 3. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved3#ATM15 | Agenda • Mobility controller architecture • Aruba Instant architecture • RAP-NG / IAP-VPN • Management platforms – Aruba Central – AirWave • Discussion & Questions @ArubaNetworks
  • 4. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved4#ATM15 | Deployment types • Mobility Controller: Master-local • Mobility Controller: All masters • Instant • Instant: RAP-NG • Hybrid! (all of the above, mix and match) @ArubaNetworks
  • 6. 6 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Mobility Controller Family @ArubaNetworks 256 APs 4,096 IPSec 512 APs 16,384 IPSec 1,024 APs 24,576 IPSec 2,048 APs 32,768 IPSec 7200 SERIES
  • 7. 7 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Mobility Controller Family @ArubaNetworks CLOUD SERVICES CONTROLLERS 16 APs Can be powered via PoE 64 APs 32 APs 10 PoE+
  • 8. 8 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Mobility Controller Family @ArubaNetworks CLOUD SERVICES CONTROLLERS 32 APs, 24 PoE+, 2x10G
  • 9. 9 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Campus physical topology @ArubaNetworks Master backup Master active Local ControllerLocal Controller Datacenter Datacenter EDGEEDGEEDGE
  • 10. 10 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Campus logical topology @ArubaNetworks Master standby Master active Local ControllerLocal Controller IPSEC GRE PRIMARY GRE STANDBY
  • 11. 11 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | L2 Deployment @ArubaNetworks Core/Distribution Switch Controller Tagged link MGMT 30 10.200.30.1 CORP CLIENTS 31 10.200.31.1 BYOD CLIENTS 32 10.200.32.1 GUEST 33 10.200.33.1 30 10.200.30.5 31 32 33 10.200.33.5 BYOD Client DNS / DHCP IP 10.200.33.51 GW 10.200.33.1
  • 12. 12 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | L3 Deployment @ArubaNetworks WAN/Core/Distribution Router TRANSIT 254 10.200.254.2/30 LOOPBACK lo 10.200.30.1 CORP CLIENTS 31 10.200.31.1 BYOD CLIENTS 32 10.200.32.1 GUEST 33 10.200.33.1 BYOD Client DNS / DHCP Controller IP 10.200.33.51 GW 10.200.33.1 Transit link 10.200.254.1/30
  • 13. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved13#ATM15 | Master controller responsibilities • Policy configuration • Wireless security (WIPS / RFProtect) • AP white lists (CAPs w/ CPsec and RAPs) • Initial AP configuration • Authentication and roles @ArubaNetworks
  • 14. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved14#ATM15 | Local controller responsibilities • AP and session termination – Terminates AP tunnels – User traffic processed and forwarded • RFProtect enforcement and blacklisting • ARM • Mobility • QoS @ArubaNetworks
  • 15. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved15#ATM15 | Controller scaling • Controller scaling table (VRD) • The important numbers – AP capacity – User/device capacity << important! – Tunnel capacity • WMS scaling for master controller – Master controller may need to be larger than the locals depending on the environment @ArubaNetworks
  • 16. CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved16#ATM15 | Controller scaling • Platform – 7000 series (7005/7010/7024/7030) should only be used as local controllers* – 7200 series should be master for multiple 7000 locals • Failover capacity @ArubaNetworks
  • 17. 17 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • Tunnel • Bridge • Decrypt-tunnel • Configured per virtual-ap and per ethernet interface • Choose based on network topology and requirements Campus Forwarding Modes @ArubaNetworks
  • 18. 18 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • All traffic is tunneled back to controller • User VLANs live in controller • Wired network is a high-speed overlay network • User traffic passes through stateful firewall and deep packet inspection engine (*on 7 series controllers) Tunnel @ArubaNetworks
  • 19. 19 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • User traffic bridged out to local network • User VLANs live in edge network • Authentication traffic tunneled to controller • Control plane security (cpsec) required • Captive portal authentication is not supported Bridge @ArubaNetworks
  • 20. 20 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • User VLANs live in controller • AP decrypts traffic and strips 802.11 headers • AP adds 802.3 headers and frame is encapsulated in GRE tunnel to controller • Controller applies firewall policies to traffic • Solves double-encryption issues when using a VPN • Control plane security (cpsec) required Decrypt-tunnel (d-tunnel) @ArubaNetworks
  • 22. 22 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Master-Local Redundancy @ArubaNetworks Standby Master Local 1 Local 2 Local 1 Local 2 Local Master Master Master Local Local n Local n Master Fully Redundant Redundant Aggregation Hot Standby No Redundancy
  • 23. 23 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | HA: AP Fast Failover @ArubaNetworks GRE STANDBYGRE ACTIVE AOS 6.3+
  • 24. 24 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | HA: AP Fast Failover @ArubaNetworks GRE ACTIVE AOS 6.3+
  • 25. 25 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content AP FF: Controller Roles • DUAL: Primary for some APs, standby for others • ACTIVE: Controller does not terminate standby tunnels for other controllers • STANDBY: Controller only terminates standby tunnels @ArubaNetworks
  • 26. 26 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content AP FF: N+1 Oversubscription @ArubaNetworks Controller Platform Ratio Max GRE tunnels 7000-series (70-05/10/24/30) 1:1 -- 7210 4:1 16K 7220 4:1 32K 7240 4:1 64K M3 & 3600 2:1 16K AOS 6.4+
  • 27. 27 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | VRRP Failover (L2) @ArubaNetworks LMS-IP: 172.16.100.5 172.16.100.2 VRRP MASTER 172.16.100.5 VIRTUAL IP 172.16.100.3 VRRP BACKUP GRE TUNNEL SRC-IP <AP> DST-IP: 172.16.100.5
  • 28. 28 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | VRRP Failover (L2) @ArubaNetworks LMS-IP: 172.16.100.5 172.16.100.5 VIRTUAL IP 172.16.100.3 VRRP MASTER GRE TUNNEL SRC-IP <AP> DST-IP: 172.16.100.5 AP RE-BOOTSTRAPS
  • 29. 29 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Backup-LMS (L3) @ArubaNetworks LMS-IP: 172.16.100.2 BACKUP LMS-IP: 10.50.20.2 172.16.100.2 10.50.20.2 GRE TUNNEL SRC-IP <AP> DST-IP: 172.16.100.2
  • 30. 30 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Backup-LMS (L3) @ArubaNetworks LMS-IP: 172.16.100.2 BACKUP LMS-IP: 10.50.20.2 172.16.100.2 10.50.20.2 GRE TUNNEL SRC-IP <AP> DST-IP: 10.50.20.2 AP REBOOTS
  • 31. 31 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Remote AP (RAP) @ArubaNetworks
  • 32. 32 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Remote AP (RAP) • Purpose-built RAPs and campus APs • Certificate-based provisioning • Secure wired and wireless remote access • RAPs are Instant out of the box • Aruba Activate @ArubaNetworks
  • 33. 33 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Remote AP @ArubaNetworks INTERNET
  • 34. 34 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | IPSEC TUNNEL Remote AP - Logical @ArubaNetworks INTERNET rap.arubanetworks.com MAC-ETH0 24:DE:C6:CB:4A:F0 SERIAL BZ0030536 PROVISIONING TYPE IAP TO RAP AP GROUP Boston-RAP CONTROLLER rap.arubanetworks.com ACTIVATE
  • 35. 35 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • Tunnel • Bridge • Decrypt-tunnel • Split-tunnel RAP Forwarding Modes @ArubaNetworks
  • 36. 36 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • Tunnels certain traffic back to controller via IPSec tunnel (defined in user roles) • Allows non-corporate traffic to be bridged out locally saving bandwidth. • RAP handles encryption, decryption and firewall enforcement locally Split-tunnel @ArubaNetworks
  • 37. 37 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Limitations • Roaming • ARM features • Requires controller licenses • Limited visibility @ArubaNetworks
  • 38. 38#ATM15 | Aruba Instant Architecture @ArubaNetworks
  • 39. 39 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • AP model begins with the letter I – IAP-225, IAP-215, IAP-205, etc • Instant APs can be converted to controller-based APs • No feature licensing with local management • Manage locally, via AirWave, or Aruba Central (cloud) • Dynamic provisioning via Aruba Activate (free) Aruba Instant Overview @ArubaNetworks
  • 40. 40 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | • Cooperate locally at L2 • Multiple uplink options (Ethernet, 4G/LTE, WiFi) • ARM, ClientMatch, AppRF, AirGroup, L3 Mobility • IAP-VPN/RAP-NG for distributed environments Aruba Instant Overview - Technical @ArubaNetworks
  • 41. 41 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Instant topology @ArubaNetworks INTERNET VC
  • 42. 42 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Instant traffic flow • Traffic destined for tunnels goes through VC • NAT’d traffic (guest) goes through VC • Regular user traffic firewalled, processed and switched out at AP @ArubaNetworks
  • 43. 43 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Instant traffic flow @ArubaNetworks INTERNET VC [10] 20,30 [10] 20,30 VC IP: 172.16.10.5 AP IP: 172.16.10.10 AP IP: 172.16.10.11 Client IP: 172.16.20.10www.google.com
  • 44. 44 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Instant traffic flow – Guest/NAT @ArubaNetworks INTERNET VC [10] 20,30 [10] 20,30 VC IP: 172.16.10.5 AP IP: 172.16.10.10 AP IP: 172.16.10.11 Client IP: 172.31.98.42 Internal IAP Guest Network “Magic VLAN” 3333 172.31.98.x Src-NAT’d with VC address www.google.com
  • 45. 45#ATM15 | RAP-NG / IAP-VPN @ArubaNetworks
  • 46. 46 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | RAP-NG / IAP-VPN Topology @ArubaNetworks Master active Master backup Master active Master backup Site 1 VC Site 2 VC Site 3 VC INTERNET Datacenter 1 Datacenter 2
  • 47. 47 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Benefits • Local RF coordination • Roaming • Isolated broadcast domains for each cluster • Authentication survivability • MAS integration @ArubaNetworks
  • 48. 48 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | DHCP modes • Local • Centralized L2 • Distributed L2 • Centralized L3 • Distributed L3 @ArubaNetworks
  • 49. 49 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content DHCP modes @ArubaNetworks DHCP MODE SUBNET DHCP CLIENT GW CORP TRAFFIC LCL/INTERNET Local Local Master AP Master AP Src-NAT IPSec tunnel Src-NAT Master AP IP Centralized L2 CORP Datacenter Datacenter Tagged & switched to datacenter via tunnel Src-NAT Master AP IP Distributed L2 CORP Master AP Datacenter Tagged & switched to datacenter via tunnel Src-NAT Master AP IP Centralized L3 CORP Datacenter Master AP Routed to datacenter inside IPSec tunnel Src-NAT Master AP IP Distributed L3 CORP Master AP Master AP Routed to datacenter inside IPSec tunnel Src-NAT Master AP IP
  • 50. 50 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content RAP-NG/IAP-VPN licensing • For basic VPN connectivity (single role), a single PEFNG license is required • To use different roles for individual IAP clusters, the PEFV license is required for each controller @ArubaNetworks
  • 52. 52 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Aruba Activate @ArubaNetworks
  • 53. 53 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Aruba Activate @ArubaNetworks
  • 56. 56 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Aruba Central Overview • Cloud management for Instant and MAS • ZTP with Aruba Activate • Firmware management • Reporting • Responsive UI (adaptive to any display)* • AppRF management and visibility* • Cloud captive portal w/ social* @ArubaNetworks * Central 2.0 – Coming Soon
  • 57. 57 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Aruba Central @ArubaNetworks
  • 58. 58 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Aruba Central @ArubaNetworks
  • 59. 59 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Aruba Central @ArubaNetworks
  • 60. 60 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Aruba Central @ArubaNetworks
  • 62. 62 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content AirWave Overview • On-premise solution (VM or physical) • Management, monitoring and reporting of Aruba controllers, Instant clusters, and MAS • Multi-vendor • In a hybrid controller-Instant environment, AirWave recommended • Single pane of glass @ArubaNetworks
  • 63. 63 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Single pane of glass @ArubaNetworks
  • 64. 64 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Instant GUI config @ArubaNetworks
  • 65. 65#ATM15 | Discussion & Questions @ArubaNetworks
  • 66. 66 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content arubanetworks.com/vrd @ArubaNetworks
  • 67. 67 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Other resources @ArubaNetworks In-depth Wireless Architecture cwnp.com
  • 68. THANK YOU 68#ATM15 | @ArubaNetworks

Editor's Notes

  1. Although Aruba makes it easy to choose the best WLAN architecture to fit your IT and business needs, it's vital to sort through some critical pre-deployment issues before you get started. Join us to review the latest product and architectural options from Aruba as well as validated WLAN design best practices. This session includes in-depth coverage of Aruba Instant and Aruba Mobility Controllers.
  2. Make networks mobility-defined instead of fixed
  3. Make networks mobility-defined instead of fixed
  4. Make networks mobility-defined instead of fixed
  5. Make networks mobility-defined instead of fixed
  6. Make networks mobility-defined instead of fixed
  7. Make networks mobility-defined instead of fixed
  8. Make networks mobility-defined instead of fixed
  9. Make networks mobility-defined instead of fixed
  10. Make networks mobility-defined instead of fixed
  11. Make networks mobility-defined instead of fixed
  12. Make networks mobility-defined instead of fixed
  13. Make networks mobility-defined instead of fixed
  14. Make networks mobility-defined instead of fixed
  15. Make networks mobility-defined instead of fixed
  16. Make networks mobility-defined instead of fixed
  17. Make networks mobility-defined instead of fixed
  18. Make networks mobility-defined instead of fixed
  19. Make networks mobility-defined instead of fixed
  20. Make networks mobility-defined instead of fixed
  21. Make networks mobility-defined instead of fixed
  22. Make networks mobility-defined instead of fixed
  23. Make networks mobility-defined instead of fixed
  24. Make networks mobility-defined instead of fixed
  25. Make networks mobility-defined instead of fixed
  26. Make networks mobility-defined instead of fixed
  27. Make networks mobility-defined instead of fixed
  28. Make networks mobility-defined instead of fixed
  29. Make networks mobility-defined instead of fixed
  30. Make networks mobility-defined instead of fixed
  31. Make networks mobility-defined instead of fixed
  32. Make networks mobility-defined instead of fixed
  33. Make networks mobility-defined instead of fixed
  34. Make networks mobility-defined instead of fixed
  35. Make networks mobility-defined instead of fixed
  36. Make networks mobility-defined instead of fixed
  37. Make networks mobility-defined instead of fixed
  38. Make networks mobility-defined instead of fixed
  39. Make networks mobility-defined instead of fixed
  40. Make networks mobility-defined instead of fixed
  41. Make networks mobility-defined instead of fixed
  42. Make networks mobility-defined instead of fixed
  43. Make networks mobility-defined instead of fixed
  44. Make networks mobility-defined instead of fixed
  45. Make networks mobility-defined instead of fixed
  46. Fast failover between two datacenters
  47. Make networks mobility-defined instead of fixed
  48. Make networks mobility-defined instead of fixed
  49. Make networks mobility-defined instead of fixed
  50. Make networks mobility-defined instead of fixed
  51. Make networks mobility-defined instead of fixed
  52. Make networks mobility-defined instead of fixed
  53. Make networks mobility-defined instead of fixed
  54. Make networks mobility-defined instead of fixed
  55. Make networks mobility-defined instead of fixed
  56. Make networks mobility-defined instead of fixed
  57. Make networks mobility-defined instead of fixed
  58. Make networks mobility-defined instead of fixed
  59. Make networks mobility-defined instead of fixed
  60. Make networks mobility-defined instead of fixed
  61. Make networks mobility-defined instead of fixed
  62. Make networks mobility-defined instead of fixed
  63. Make networks mobility-defined instead of fixed
  64. Make networks mobility-defined instead of fixed
  65. Make networks mobility-defined instead of fixed
  66. Make networks mobility-defined instead of fixed
  67. Make networks mobility-defined instead of fixed
  68. Make networks mobility-defined instead of fixed