SlideShare une entreprise Scribd logo
1  sur  42
Télécharger pour lire hors ligne
Remote and Branch Networking Fundamentals
June 9-14, 2014
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
2 #AirheadsConf
Agenda
•  Challenges of Deploying Remote networks
•  Aruba Solution
•  Aruba Instant
•  Aruba Instant for Private WAN based Deployments
•  Aruba Instant-VPN
•  Management and Zero-Touch Deployment
Challenges of Deploying Remote
Networks
4
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Who should care?
Branch office / Remote
teleworker
Retail
Healthcare
5
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Challenges
Aruba Solution
7
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Aruba Solution
Home Office On The RoadBranch
Datacenter
AirWave Aruba Mobility Controller ClearPass Access Management
Instant-VPN
Mobility Switch
Instant Cluster
Virtual Intranet
Access (VIA) Client
Internet / WAN
Instant Cluster
Management and Zero-Touch
Deployment
9
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Internet
Airwave and Aruba Central
Campus Network
Aruba Central Aruba AirWave
Data Center
•  Advanced	
  guest	
  services	
  
•  Mobile	
  device	
  onboarding	
  	
  
•  Unified	
  wired/wireless	
  
policy	
  	
  
Airwave
ClearPass
Mobility
Switch
10
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Aruba Activate: Zero-touch
Deployment
Aruba Instant
12
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Aruba Instant
•  Redundancy for
internal failure
•  Redundancy for
external failure
•  Organic growth
•  Mobility-ready
•  RF optimization
•  Master AP
selection
•  Over-the-air
provisioning
•  WiFi oriented
configuration
Simple to
deploy
Self-
optimizing
Self-
healing
Scalable
13
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Aruba Instant Architecture
•  Distributed data-plane
–  Wireless encryption / decryption, firewall
•  Distributed control-plane
–  Authentication, DHCP, ARM, WIPS
•  Centralized (local) management-plane
–  Configuration, firmware management, GUI, SNMP
14
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Automatic RF Management
Infrastructure control
•  Automatic RF
optimization for
coverage & capacity
•  Real-time spectrum
analysis and
interference avoidance
•  Load / Application
awareness
•  Self-healing
Channel 11
Channel 6
Channel 1
Client Control
•  Moves clients towards
less congested
frequency band
•  Distributes clients across
available spectrum*
•  Bandwidth controls
15
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Security tailored for Mobility
Context Aware
On-boarding
Role-based access
Policy Enforcement
•  Aruba RFProtect + AirWave RAPIDS
•  RF Scanning, Rogue AP detection / containment, Valid-station protection
•  Encryption
•  Over-the-air AES encryption, IPSec VPN to datacenter (where applicable)
•  Role-based Access
•  Per-user, per-device access
•  Policy Enforcement Firewall
•  Segregation of business traffic from guest traffic.
•  Blacklisting for session violation
•  Centralized Monitoring and Alerting
16
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
•  No need for separate SSID for QoS.
•  Session based DSCP tagging &
prioritization
•  Multicast-to-unicast conversion for
video
•  Media-classification for encrypted
voice –Apple Facetime
•  AirGroup* to manage Apple AirPlay,
AirPrint, etc
Mobility Services: Real-time
Applications
Clear
Pass
IAP
IAP IAP
17
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Mobility Services: Guest Access
•  Securely Manage Visitor Access
–  Streamlined workflow; No IT
•  Sponsored-based, Visitor Self-Registration, Pre-registration,
Anonymous Guest Access
•  3rd Party Integrations
•  APIs for integration with existing applications / CRM tools
–  Assignable roles, expiration times, user names, passwords
•  Highest Customization
–  Skin technology, software plugins, APIs
–  Targeted advertising and content delivery
Private WAN based Deployments
19
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Private-WAN based Deployments
20
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Private-WAN based Deployments
21
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Auto-GRE for Guest
Branch office
Datacenter
AirWave ClearPass
Instant Cluster
VRRP Link
Master Standby
Guest Anchor
Master Active
Servers
MPLS
Employee Traffic
Guest Traffic
Aruba Instant-VPN
23
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Datacenter
AirWave/Aruba
Central Aruba Mobility Controller
ClearPass solution
Internet / WAN
VRRP Link
Master Standby
DMZ
Master Active
Home Office
Instant
Home office Solution
Home Office
Instant
24
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Branch Office Solution
Branch office
Datacenter
AirWave/Aruba
Central Aruba Mobility Controller
ClearPass solution
Instant Cluster
Internet / WAN
VRRP Link
Master Standby
DMZ
Master Active
Branch office
Instant Cluster
25
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
DHCP - How does Distributed L3
work ?
Network 10.0.0.0/8
VLANs 10 to 99
Data Center
Remote Branch
Internet /
WAN
Active
VPN
Tunnel
Client A
Browsing to
Intranet
Browsing to
Youtube
Route on IAP –
For 10.0.0.0/8 network, next
hop is VPN terminating
controller’s IP address
Master IAP Memeber IAP
Client B
Browsing to
Intranet
Browsing to
Youtube
VLAN 250
IAP-VC is the
DHCP Server
DHCP
Request
VC SRC NATs traffic using IAPs local IPVC routes the traffic to the
tunnel
Intranet
26
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
DHCP - How does Centralized L2
work ?
Network 10.0.0.0/8
VLANs 10 to 99
Data Center
Remote Branch
Internet /
WAN
Active
VPN
Tunnel
Client A
Browsing to
Intranet
Browsing to
Youtube
Route on IAP –
For 10.0.0.0/8 network, next
hop is VPN terminating
controller’s IP address
Master IAP Member IAP
Client B
Browsing to
Intranet
Browsing to
Youtube
VLAN 50
DHCP
Request
VC SRC NATs traffic using IAPs local IPVC bridges traffic in the
tunnel
VLAN 50
DHCP Server and
Default Gateway
Intranet
27
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
DHCP - How does Local Subnet
work ?
Intranet
Network 10.0.0.0/8
VLANs 10 to 99
Data Center
Remote Branch
Internet /
WAN
Active
VPN
Tunnel
Client A
Browsing to
Intranet
Browsing to
Youtube
Route on IAP –
For 10.0.0.0/8 network, next
hop is VPN terminating
controller’s IP address
Master IAP Slave IAP
Client B
Browsing to
Intranet
Browsing to
Youtube
VLAN 200
IAP-VC is the
DHCP Server
DHCP
Request
VC SRC NATs traffic using IAPs local IPVC SRC NATs traffic using
inner IP
28
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Recommendations
IAP-VPN Modes	
   Usage Recommendations
	
  
Distributed L3	
   Recommended for all deployments. 	
  
Local 	
  
Recommended for Guest networks with centralized captive portal
servers. 	
  
Centralized L2 	
  
Recommended only if Multicast to branch is a requirement. If
Multicast to branch networks is not required, use L3 modes.	
  
29
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Branch ID Algorithm
Aruba Instant-VPN Design Options
31
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Single AP deployments
32
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Single AP deployments
33
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Multi-AP deployments
34
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Multi-AP deployments
35
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
Thank You
#AirheadsConf
36
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Distributed-L2
37
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Central-L2
38
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Central-L3
39
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Dist-L3
40
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Local Mode
41
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
DOWNLOAD: Airheads Mobile
JOIN: community.arubanetworks.com
FOLLOW: @arubanetworks
DISCUSS: #AirheadsConf
ATMOSPHERE 2014
AIRHEADS@
42
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
Thank You
#AirheadsConf

Contenu connexe

Tendances

The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...Aruba, a Hewlett Packard Enterprise company
 
Integrating Unified Communications and Collaboration on an Aruba Access Network
Integrating Unified Communications and Collaboration on an Aruba Access NetworkIntegrating Unified Communications and Collaboration on an Aruba Access Network
Integrating Unified Communications and Collaboration on an Aruba Access NetworkAruba, a Hewlett Packard Enterprise company
 
Aruba presentation solutions overview - v1
Aruba presentation   solutions overview - v1Aruba presentation   solutions overview - v1
Aruba presentation solutions overview - v1Hasan Zuberi
 

Tendances (20)

Aruba Campus Wireless Networks
Aruba Campus Wireless NetworksAruba Campus Wireless Networks
Aruba Campus Wireless Networks
 
Network Management with Aruba Airwave #AirheadsConf Italy
Network Management with Aruba Airwave #AirheadsConf ItalyNetwork Management with Aruba Airwave #AirheadsConf Italy
Network Management with Aruba Airwave #AirheadsConf Italy
 
Remote & Branch Networking Fundamentals #AirheadsConf Italy
Remote & Branch Networking Fundamentals #AirheadsConf ItalyRemote & Branch Networking Fundamentals #AirheadsConf Italy
Remote & Branch Networking Fundamentals #AirheadsConf Italy
 
New Branch IT Opportunities: Enhanced Performance & Reduced Costs
New Branch IT Opportunities: Enhanced Performance & Reduced CostsNew Branch IT Opportunities: Enhanced Performance & Reduced Costs
New Branch IT Opportunities: Enhanced Performance & Reduced Costs
 
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
 
Unified access with Aruba Mobility Access Switches – Live Demo
Unified access with Aruba Mobility Access Switches – Live DemoUnified access with Aruba Mobility Access Switches – Live Demo
Unified access with Aruba Mobility Access Switches – Live Demo
 
EMEA Airheads – Aruba controller features used to optimize performance
EMEA Airheads – Aruba controller features used to optimize performanceEMEA Airheads – Aruba controller features used to optimize performance
EMEA Airheads – Aruba controller features used to optimize performance
 
Integrating Unified Communications and Collaboration on an Aruba Access Network
Integrating Unified Communications and Collaboration on an Aruba Access NetworkIntegrating Unified Communications and Collaboration on an Aruba Access Network
Integrating Unified Communications and Collaboration on an Aruba Access Network
 
Advanced RF Design & Troubleshooting #AirheadsConf Italy
Advanced RF Design & Troubleshooting #AirheadsConf ItalyAdvanced RF Design & Troubleshooting #AirheadsConf Italy
Advanced RF Design & Troubleshooting #AirheadsConf Italy
 
Best Practices on Migrating to 802.11ac Wi-Fi #AirheadsConf Italy
Best Practices on Migrating to 802.11ac Wi-Fi #AirheadsConf ItalyBest Practices on Migrating to 802.11ac Wi-Fi #AirheadsConf Italy
Best Practices on Migrating to 802.11ac Wi-Fi #AirheadsConf Italy
 
WLAN Architecture - Considerations
WLAN Architecture - ConsiderationsWLAN Architecture - Considerations
WLAN Architecture - Considerations
 
Network Management with Aruba AirWave
Network Management with Aruba AirWaveNetwork Management with Aruba AirWave
Network Management with Aruba AirWave
 
Shanghai Breakout: Location Analytics – Key Considerations and Use Cases
Shanghai Breakout: Location Analytics – Key Considerations and Use CasesShanghai Breakout: Location Analytics – Key Considerations and Use Cases
Shanghai Breakout: Location Analytics – Key Considerations and Use Cases
 
3 air wave practical workshop_mike bruno_matt sidhu
3 air wave practical workshop_mike bruno_matt sidhu3 air wave practical workshop_mike bruno_matt sidhu
3 air wave practical workshop_mike bruno_matt sidhu
 
EMEA Airheads- ArubaOS - Rogue AP troubleshooting
EMEA Airheads- ArubaOS - Rogue AP troubleshootingEMEA Airheads- ArubaOS - Rogue AP troubleshooting
EMEA Airheads- ArubaOS - Rogue AP troubleshooting
 
Wi-Fi Behavior of Popular Mobile Devices #AirheadsConf Italy
Wi-Fi Behavior of Popular Mobile Devices #AirheadsConf ItalyWi-Fi Behavior of Popular Mobile Devices #AirheadsConf Italy
Wi-Fi Behavior of Popular Mobile Devices #AirheadsConf Italy
 
Deploying Microsoft Lync over Wi-Fi #AirheadsConf Italy
Deploying Microsoft Lync over Wi-Fi #AirheadsConf ItalyDeploying Microsoft Lync over Wi-Fi #AirheadsConf Italy
Deploying Microsoft Lync over Wi-Fi #AirheadsConf Italy
 
Shanghai Breakout: Advanced Airwave Workshop
Shanghai Breakout: Advanced Airwave WorkshopShanghai Breakout: Advanced Airwave Workshop
Shanghai Breakout: Advanced Airwave Workshop
 
Aruba presentation solutions overview - v1
Aruba presentation   solutions overview - v1Aruba presentation   solutions overview - v1
Aruba presentation solutions overview - v1
 
Real-world 802.1X Deployment Challenges
Real-world 802.1X Deployment ChallengesReal-world 802.1X Deployment Challenges
Real-world 802.1X Deployment Challenges
 

En vedette (6)

Aruba WLANs 101 and design fundamentals
Aruba WLANs 101 and design fundamentalsAruba WLANs 101 and design fundamentals
Aruba WLANs 101 and design fundamentals
 
Aruba AP 270 Series Installation Guide
Aruba AP 270 Series Installation GuideAruba AP 270 Series Installation Guide
Aruba AP 270 Series Installation Guide
 
Aruba Beacons Validated Reference Guide
Aruba Beacons Validated Reference GuideAruba Beacons Validated Reference Guide
Aruba Beacons Validated Reference Guide
 
Campus Redundancy Models
Campus Redundancy ModelsCampus Redundancy Models
Campus Redundancy Models
 
Aruba Remote Access Point (RAP) Networks Validated Reference Design
Aruba Remote Access Point (RAP) Networks Validated Reference DesignAruba Remote Access Point (RAP) Networks Validated Reference Design
Aruba Remote Access Point (RAP) Networks Validated Reference Design
 
Aruba ClearPass Exchange Deep Dive
Aruba ClearPass Exchange Deep DiveAruba ClearPass Exchange Deep Dive
Aruba ClearPass Exchange Deep Dive
 

Similaire à Remote Branch Networking Fundamentals

Sydney UC - February 2015
Sydney UC - February 2015Sydney UC - February 2015
Sydney UC - February 2015justimorris
 
8 software defined networking and traffic engineering partha narasimhan_ash c...
8 software defined networking and traffic engineering partha narasimhan_ash c...8 software defined networking and traffic engineering partha narasimhan_ash c...
8 software defined networking and traffic engineering partha narasimhan_ash c...Aruba, a Hewlett Packard Enterprise company
 
Transforming Networks into a NFV-Centric Environment
Transforming Networks into a NFV-Centric EnvironmentTransforming Networks into a NFV-Centric Environment
Transforming Networks into a NFV-Centric EnvironmentADVA
 
Networking 101 part 2 for ai
Networking 101 part 2 for aiNetworking 101 part 2 for ai
Networking 101 part 2 for aiursus006
 

Similaire à Remote Branch Networking Fundamentals (20)

Remote Wireless LANs
Remote Wireless LANsRemote Wireless LANs
Remote Wireless LANs
 
Next generation remote networks aruba instant gokul rajagopalan
Next generation remote networks aruba instant gokul rajagopalanNext generation remote networks aruba instant gokul rajagopalan
Next generation remote networks aruba instant gokul rajagopalan
 
WLAN Design for Location, Voice & Video
WLAN Design for Location, Voice & VideoWLAN Design for Location, Voice & Video
WLAN Design for Location, Voice & Video
 
2012 ah vegas remote networking fundamentals
2012 ah vegas   remote networking fundamentals2012 ah vegas   remote networking fundamentals
2012 ah vegas remote networking fundamentals
 
Advanced Aruba ClearPass Workshop
Advanced Aruba ClearPass WorkshopAdvanced Aruba ClearPass Workshop
Advanced Aruba ClearPass Workshop
 
Instant overview gokul_rajagopalan
Instant overview gokul_rajagopalanInstant overview gokul_rajagopalan
Instant overview gokul_rajagopalan
 
1 voice and video over wi fi-balajee krishnamurthy
1 voice and video over wi fi-balajee krishnamurthy1 voice and video over wi fi-balajee krishnamurthy
1 voice and video over wi fi-balajee krishnamurthy
 
Aruba Instant Workshop #AirheadsConf Italy
Aruba Instant Workshop #AirheadsConf ItalyAruba Instant Workshop #AirheadsConf Italy
Aruba Instant Workshop #AirheadsConf Italy
 
Advanced Aruba Airwave Workshop #AirheadsConf Italy
Advanced Aruba Airwave Workshop #AirheadsConf ItalyAdvanced Aruba Airwave Workshop #AirheadsConf Italy
Advanced Aruba Airwave Workshop #AirheadsConf Italy
 
Enabling AirPrint & AirPlay on Your Network
Enabling AirPrint & AirPlay on Your NetworkEnabling AirPrint & AirPlay on Your Network
Enabling AirPrint & AirPlay on Your Network
 
Shanghai Breakout: Access Management with Aruba ClearPass
Shanghai Breakout: Access Management with Aruba ClearPassShanghai Breakout: Access Management with Aruba ClearPass
Shanghai Breakout: Access Management with Aruba ClearPass
 
Sydney UC - February 2015
Sydney UC - February 2015Sydney UC - February 2015
Sydney UC - February 2015
 
8 software defined networking and traffic engineering partha narasimhan_ash c...
8 software defined networking and traffic engineering partha narasimhan_ash c...8 software defined networking and traffic engineering partha narasimhan_ash c...
8 software defined networking and traffic engineering partha narasimhan_ash c...
 
Shanghai Breakout: Advanced RF Design and Troubleshooting
Shanghai Breakout: Advanced RF Design and Troubleshooting Shanghai Breakout: Advanced RF Design and Troubleshooting
Shanghai Breakout: Advanced RF Design and Troubleshooting
 
Transforming Networks into a NFV-Centric Environment
Transforming Networks into a NFV-Centric EnvironmentTransforming Networks into a NFV-Centric Environment
Transforming Networks into a NFV-Centric Environment
 
Advanced Access Management with Aruba ClearPass #AirheadsConf Italy
Advanced Access Management with Aruba ClearPass #AirheadsConf ItalyAdvanced Access Management with Aruba ClearPass #AirheadsConf Italy
Advanced Access Management with Aruba ClearPass #AirheadsConf Italy
 
Access Management with Aruba ClearPass #AirheadsConf Italy
Access Management with Aruba ClearPass #AirheadsConf ItalyAccess Management with Aruba ClearPass #AirheadsConf Italy
Access Management with Aruba ClearPass #AirheadsConf Italy
 
Security advanced rich langston_jon green
Security advanced rich langston_jon greenSecurity advanced rich langston_jon green
Security advanced rich langston_jon green
 
Networking 101 part 2 for ai
Networking 101 part 2 for aiNetworking 101 part 2 for ai
Networking 101 part 2 for ai
 
Defining Advanced AAA Policies for Access Networks
Defining Advanced AAA Policies for Access NetworksDefining Advanced AAA Policies for Access Networks
Defining Advanced AAA Policies for Access Networks
 

Plus de Marcello Marchesini

Akamai State of Internet - Q1 2014 - Infographic
Akamai State of Internet - Q1 2014 - InfographicAkamai State of Internet - Q1 2014 - Infographic
Akamai State of Internet - Q1 2014 - InfographicMarcello Marchesini
 
Infographic: The Power of Enterprise PaaS
Infographic: The Power of Enterprise PaaSInfographic: The Power of Enterprise PaaS
Infographic: The Power of Enterprise PaaSMarcello Marchesini
 
SAMSUNG Wireless Enterprise - Voice Optimization [White paper]
SAMSUNG Wireless Enterprise - Voice Optimization [White paper]SAMSUNG Wireless Enterprise - Voice Optimization [White paper]
SAMSUNG Wireless Enterprise - Voice Optimization [White paper]Marcello Marchesini
 
Ponemon report : 'Critical Infrastructure: Security Preparedness and Maturity -
Ponemon report : 'Critical Infrastructure: Security Preparedness and Maturity -Ponemon report : 'Critical Infrastructure: Security Preparedness and Maturity -
Ponemon report : 'Critical Infrastructure: Security Preparedness and Maturity -Marcello Marchesini
 
Samsung Wireless Enterprise LAN - June 2014
Samsung Wireless Enterprise LAN  - June 2014Samsung Wireless Enterprise LAN  - June 2014
Samsung Wireless Enterprise LAN - June 2014Marcello Marchesini
 
ARUBA 2014 : 802.11ac Wi-Fi fundamentals v2
ARUBA 2014 : 802.11ac Wi-Fi fundamentals v2ARUBA 2014 : 802.11ac Wi-Fi fundamentals v2
ARUBA 2014 : 802.11ac Wi-Fi fundamentals v2Marcello Marchesini
 
Aruba utilities on mobile devices v30
Aruba utilities on mobile devices v30Aruba utilities on mobile devices v30
Aruba utilities on mobile devices v30Marcello Marchesini
 
PALO ALTO -NETWORKS Application Usage & Threat Report 2014
PALO ALTO -NETWORKS  Application Usage & Threat Report 2014PALO ALTO -NETWORKS  Application Usage & Threat Report 2014
PALO ALTO -NETWORKS Application Usage & Threat Report 2014Marcello Marchesini
 

Plus de Marcello Marchesini (9)

Akamai State of Internet - Q1 2014 - Infographic
Akamai State of Internet - Q1 2014 - InfographicAkamai State of Internet - Q1 2014 - Infographic
Akamai State of Internet - Q1 2014 - Infographic
 
Infographic: The Power of Enterprise PaaS
Infographic: The Power of Enterprise PaaSInfographic: The Power of Enterprise PaaS
Infographic: The Power of Enterprise PaaS
 
SAMSUNG Wireless Enterprise - Voice Optimization [White paper]
SAMSUNG Wireless Enterprise - Voice Optimization [White paper]SAMSUNG Wireless Enterprise - Voice Optimization [White paper]
SAMSUNG Wireless Enterprise - Voice Optimization [White paper]
 
Dns protection
Dns protectionDns protection
Dns protection
 
Ponemon report : 'Critical Infrastructure: Security Preparedness and Maturity -
Ponemon report : 'Critical Infrastructure: Security Preparedness and Maturity -Ponemon report : 'Critical Infrastructure: Security Preparedness and Maturity -
Ponemon report : 'Critical Infrastructure: Security Preparedness and Maturity -
 
Samsung Wireless Enterprise LAN - June 2014
Samsung Wireless Enterprise LAN  - June 2014Samsung Wireless Enterprise LAN  - June 2014
Samsung Wireless Enterprise LAN - June 2014
 
ARUBA 2014 : 802.11ac Wi-Fi fundamentals v2
ARUBA 2014 : 802.11ac Wi-Fi fundamentals v2ARUBA 2014 : 802.11ac Wi-Fi fundamentals v2
ARUBA 2014 : 802.11ac Wi-Fi fundamentals v2
 
Aruba utilities on mobile devices v30
Aruba utilities on mobile devices v30Aruba utilities on mobile devices v30
Aruba utilities on mobile devices v30
 
PALO ALTO -NETWORKS Application Usage & Threat Report 2014
PALO ALTO -NETWORKS  Application Usage & Threat Report 2014PALO ALTO -NETWORKS  Application Usage & Threat Report 2014
PALO ALTO -NETWORKS Application Usage & Threat Report 2014
 

Dernier

Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxLoriGlavin3
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESmohitsingh558521
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsPixlogix Infotech
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxLoriGlavin3
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxLoriGlavin3
 

Dernier (20)

Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and Cons
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
 

Remote Branch Networking Fundamentals

  • 1. Remote and Branch Networking Fundamentals June 9-14, 2014
  • 2. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved 2 #AirheadsConf Agenda •  Challenges of Deploying Remote networks •  Aruba Solution •  Aruba Instant •  Aruba Instant for Private WAN based Deployments •  Aruba Instant-VPN •  Management and Zero-Touch Deployment
  • 3. Challenges of Deploying Remote Networks
  • 4. 4 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Who should care? Branch office / Remote teleworker Retail Healthcare
  • 5. 5 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Challenges
  • 7. 7 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Aruba Solution Home Office On The RoadBranch Datacenter AirWave Aruba Mobility Controller ClearPass Access Management Instant-VPN Mobility Switch Instant Cluster Virtual Intranet Access (VIA) Client Internet / WAN Instant Cluster
  • 9. 9 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Internet Airwave and Aruba Central Campus Network Aruba Central Aruba AirWave Data Center •  Advanced  guest  services   •  Mobile  device  onboarding     •  Unified  wired/wireless   policy     Airwave ClearPass Mobility Switch
  • 10. 10 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Aruba Activate: Zero-touch Deployment
  • 12. 12 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Aruba Instant •  Redundancy for internal failure •  Redundancy for external failure •  Organic growth •  Mobility-ready •  RF optimization •  Master AP selection •  Over-the-air provisioning •  WiFi oriented configuration Simple to deploy Self- optimizing Self- healing Scalable
  • 13. 13 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Aruba Instant Architecture •  Distributed data-plane –  Wireless encryption / decryption, firewall •  Distributed control-plane –  Authentication, DHCP, ARM, WIPS •  Centralized (local) management-plane –  Configuration, firmware management, GUI, SNMP
  • 14. 14 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Automatic RF Management Infrastructure control •  Automatic RF optimization for coverage & capacity •  Real-time spectrum analysis and interference avoidance •  Load / Application awareness •  Self-healing Channel 11 Channel 6 Channel 1 Client Control •  Moves clients towards less congested frequency band •  Distributes clients across available spectrum* •  Bandwidth controls
  • 15. 15 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Security tailored for Mobility Context Aware On-boarding Role-based access Policy Enforcement •  Aruba RFProtect + AirWave RAPIDS •  RF Scanning, Rogue AP detection / containment, Valid-station protection •  Encryption •  Over-the-air AES encryption, IPSec VPN to datacenter (where applicable) •  Role-based Access •  Per-user, per-device access •  Policy Enforcement Firewall •  Segregation of business traffic from guest traffic. •  Blacklisting for session violation •  Centralized Monitoring and Alerting
  • 16. 16 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf •  No need for separate SSID for QoS. •  Session based DSCP tagging & prioritization •  Multicast-to-unicast conversion for video •  Media-classification for encrypted voice –Apple Facetime •  AirGroup* to manage Apple AirPlay, AirPrint, etc Mobility Services: Real-time Applications Clear Pass IAP IAP IAP
  • 17. 17 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Mobility Services: Guest Access •  Securely Manage Visitor Access –  Streamlined workflow; No IT •  Sponsored-based, Visitor Self-Registration, Pre-registration, Anonymous Guest Access •  3rd Party Integrations •  APIs for integration with existing applications / CRM tools –  Assignable roles, expiration times, user names, passwords •  Highest Customization –  Skin technology, software plugins, APIs –  Targeted advertising and content delivery
  • 18. Private WAN based Deployments
  • 19. 19 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Private-WAN based Deployments
  • 20. 20 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Private-WAN based Deployments
  • 21. 21 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Auto-GRE for Guest Branch office Datacenter AirWave ClearPass Instant Cluster VRRP Link Master Standby Guest Anchor Master Active Servers MPLS Employee Traffic Guest Traffic
  • 23. 23 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Datacenter AirWave/Aruba Central Aruba Mobility Controller ClearPass solution Internet / WAN VRRP Link Master Standby DMZ Master Active Home Office Instant Home office Solution Home Office Instant
  • 24. 24 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Branch Office Solution Branch office Datacenter AirWave/Aruba Central Aruba Mobility Controller ClearPass solution Instant Cluster Internet / WAN VRRP Link Master Standby DMZ Master Active Branch office Instant Cluster
  • 25. 25 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf DHCP - How does Distributed L3 work ? Network 10.0.0.0/8 VLANs 10 to 99 Data Center Remote Branch Internet / WAN Active VPN Tunnel Client A Browsing to Intranet Browsing to Youtube Route on IAP – For 10.0.0.0/8 network, next hop is VPN terminating controller’s IP address Master IAP Memeber IAP Client B Browsing to Intranet Browsing to Youtube VLAN 250 IAP-VC is the DHCP Server DHCP Request VC SRC NATs traffic using IAPs local IPVC routes the traffic to the tunnel Intranet
  • 26. 26 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf DHCP - How does Centralized L2 work ? Network 10.0.0.0/8 VLANs 10 to 99 Data Center Remote Branch Internet / WAN Active VPN Tunnel Client A Browsing to Intranet Browsing to Youtube Route on IAP – For 10.0.0.0/8 network, next hop is VPN terminating controller’s IP address Master IAP Member IAP Client B Browsing to Intranet Browsing to Youtube VLAN 50 DHCP Request VC SRC NATs traffic using IAPs local IPVC bridges traffic in the tunnel VLAN 50 DHCP Server and Default Gateway Intranet
  • 27. 27 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf DHCP - How does Local Subnet work ? Intranet Network 10.0.0.0/8 VLANs 10 to 99 Data Center Remote Branch Internet / WAN Active VPN Tunnel Client A Browsing to Intranet Browsing to Youtube Route on IAP – For 10.0.0.0/8 network, next hop is VPN terminating controller’s IP address Master IAP Slave IAP Client B Browsing to Intranet Browsing to Youtube VLAN 200 IAP-VC is the DHCP Server DHCP Request VC SRC NATs traffic using IAPs local IPVC SRC NATs traffic using inner IP
  • 28. 28 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Recommendations IAP-VPN Modes   Usage Recommendations   Distributed L3   Recommended for all deployments.   Local   Recommended for Guest networks with centralized captive portal servers.   Centralized L2   Recommended only if Multicast to branch is a requirement. If Multicast to branch networks is not required, use L3 modes.  
  • 29. 29 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Branch ID Algorithm
  • 31. 31 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Single AP deployments
  • 32. 32 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Single AP deployments
  • 33. 33 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Multi-AP deployments
  • 34. 34 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Multi-AP deployments
  • 35. 35 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Thank You #AirheadsConf
  • 36. 36 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Distributed-L2
  • 37. 37 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Central-L2
  • 38. 38 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Central-L3
  • 39. 39 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Dist-L3
  • 40. 40 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Local Mode
  • 41. 41 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf DOWNLOAD: Airheads Mobile JOIN: community.arubanetworks.com FOLLOW: @arubanetworks DISCUSS: #AirheadsConf ATMOSPHERE 2014 AIRHEADS@
  • 42. 42 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Thank You #AirheadsConf