Aruba Wlans and Advanced Design Fundamentals: #Atm15Anz - @arubaanz

Download as pdf or txt
Download as pdf or txt
You are on page 1of 65

ARUBA WLANS AND ADVANCED

DESIGN FUNDAMENTALS

#ATM15ANZ | @ArubaANZ
Agenda

•  Mobility controller architecture


•  Aruba Instant architecture
•  IAP-VPN
•  Management platforms
–  Aruba Central
–  AirWave
•  Discussion & Questions

#ATM15ANZ | @ArubaANZ 2 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Deployment types

•  Mobility Controller: Master-local


•  Mobility Controller: All masters
•  Instant
•  Instant: IAP-VPN
•  Hybrid! (all of the above, mix and match)

#ATM15ANZ | @ArubaANZ 3 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Mobility Controller Architecture
Mobility Controller Family
7200 SERIES

256 APs
4,096 IPSec
Transition Content
512 APs
16,384 IPSec

1,024 APs
24,576 IPSec

2,048 APs
32,768 IPSec

#ATM15ANZ | @ ArubaANZ 5 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Mobility Controller Family
CLOUD SERVICES CONTROLLERS

16 APs

Transition Content
Can be powered via PoE

64 APs

32 APs
10 PoE+

#ATM15ANZ | @ ArubaANZ 6 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Mobility Controller Family
CLOUD SERVICES CONTROLLERS

32 APs, 24 PoE+, 2x10G Transition Content

#ATM15ANZ | @ ArubaANZ 7 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Campus physical topology
Datacenter Datacenter

Master Master
active backup

Local Controller Local Controller

EDGE EDGE EDGE

#ATM15ANZ | @ ArubaANZ 8 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Campus logical topology

Master Master
active standby

IPSEC

Local Controller Local Controller

GRE
STANDBY
GRE
PRIMARY

#ATM15ANZ | @ ArubaANZ 9 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
L2 Deployment
MGMT 30 10.200.30.1 ER
IP HELP DNS / DHCP

CORP CLIENTS 31 10.200.31.1


Core/Distribution Switch
BYOD CLIENTS 32 10.200.32.1
GUEST 33 10.200.33.1
Tagged link

30 10.200.30.5
31
Controller
32
33 10.200.33.5

BYOD Client

IP 10.200.32.51
GW 10.200.32.1

#ATM15ANZ | @ ArubaANZ 10 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
L3 Deployment
DNS / DHCP

WAN/Core/Distribution Router

10.200.254.1/30

Transit link
TRANSIT 254 10.200.254.2/30
LOOPBACK lo 10.200.30.1
Controller
CORP CLIENTS 31 10.200.31.1
BYOD CLIENTS 32 10.200.32.1
GUEST 33 10.200.33.1

BYOD Client

IP 10.200.32.51
GW 10.200.32.1

#ATM15ANZ | @ ArubaANZ 11 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Master controller responsibilities

•  Policy configuration
•  Wireless security (WIPS / RFProtect)
•  AP white lists (CAPs w/ CPsec and RAPs)
•  Initial AP configuration
•  Authentication and roles

#ATM15ANZ | @ArubaANZ 12 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Local controller responsibilities

•  AP and session termination


–  Terminates AP tunnels
–  User traffic processed and forwarded
•  RFProtect enforcement and blacklisting
•  ARM
•  Mobility
•  QoS

#ATM15ANZ | @ArubaANZ 13 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Controller scaling

•  Controller scaling table (VRD)


•  The important numbers
–  AP capacity
–  User/device capacity << important!
–  Tunnel capacity
•  WMS scaling for master controller
–  Master controller may need to be larger than the locals depending
on the environment

#ATM15ANZ | @ArubaANZ 14 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Controller scaling

•  Platform
–  7000 series (7005/7010/7024/7030) should only be used as local
controllers*
–  7200 series should be master for multiple 7000 locals
•  Failover capacity

#ATM15ANZ | @ArubaANZ 15 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Campus Forwarding Modes

•  Tunnel
•  Decrypt-tunnel
•  Bridge

•  Configured per virtual-ap


•  Choose based on network topology and requirements

#ATM15ANZ | @ArubaANZ 16 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Tunnel
Tunnel-Mode
Mobility
Controller
•  All traffic is tunneled back to controller
•  User VLANs live in controller
•  Wired network is a high-speed overlay
network
GRE Tunnel:
Encrypted •  User traffic passes through stateful
firewall and deep packet inspection
engine (*on 7 series controllers)

Access
Point

#ATM15ANZ | @ArubaANZ 17 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Decrypt-tunnel (d-tunnel)
Decrypt-Tunnel-Mode
Mobility
Controller
•  User VLANs live in controller
•  AP decrypts traffic and strips 802.11
headers
•  AP adds 802.3 headers and frame is
GRE Tunnel:
Unencrypted
encapsulated in GRE tunnel to
controller
•  Controller applies firewall policies to
traffic
Access
Point

#ATM15ANZ | @ArubaANZ 18 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Bridge
Bridge Mode
Access
Switch
•  User traffic bridged out to local network
•  User VLANs live in edge network
•  Authentication traffic tunneled to
controller
•  Control plane security (cpsec) required
•  Captive portal authentication is not
supported
Access
Point

#ATM15ANZ | @ArubaANZ 19 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Campus Redundancy
Master-Local Redundancy
Master Standby
Master Local 1 Local n

Local 2
Fully
Redundant
Master
Local 1 Local n

Local 2
Redundant Aggregation

Master

Local

Hot Standby
Master
Local

No Redundancy
#ATM15ANZ | @ ArubaANZ 21 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
VRRP Failover (L2)

172.16.100.5
VIRTUAL IP

172.16.100.2 172.16.100.3
VRRP MASTER VRRP BACKUP

GRE TUNNEL
SRC-IP <AP>
DST-IP: 172.16.100.5

LMS-IP: 172.16.100.5

#ATM15ANZ | @ ArubaANZ 22 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
VRRP Failover (L2)

172.16.100.5
VIRTUAL IP

172.16.100.3
VRRP MASTER

GRE TUNNEL
SRC-IP <AP>
DST-IP: 172.16.100.5

LMS-IP: 172.16.100.5

AP RE-BOOTSTRAPS

#ATM15ANZ | @ ArubaANZ 23 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Backup-LMS (L3)

172.16.100.2 10.50.20.2

GRE TUNNEL
SRC-IP <AP>
DST-IP: 172.16.100.2

LMS-IP: 172.16.100.2
BACKUP LMS-IP: 10.50.20.2

#ATM15ANZ | @ ArubaANZ 24 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Backup-LMS (L3)

172.16.100.2 10.50.20.2

GRE TUNNEL
SRC-IP <AP>
DST-IP: 10.50.20.2

LMS-IP: 172.16.100.2
BACKUP LMS-IP: 10.50.20.2

AP REBOOTS

#ATM15ANZ | @ ArubaANZ 25 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
HA: AP Fast Failover

GRE
GRE STANDBY
ACTIVE

AOS 6.3+
#ATM15ANZ | @ ArubaANZ 26 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
HA: AP Fast Failover

GRE
ACTIVE

AOS 6.3+
#ATM15ANZ | @ ArubaANZ 27 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
AP FF: Controller Roles

•  DUAL: Primary for some APs, standby for others

Transition
•  ACTIVE: Controller does notContent
terminate standby
tunnels for other controllers

•  STANDBY: Controller only terminates standby


tunnels

#ATM15ANZ | @ ArubaANZ 28 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
AP FF: N+1 Oversubscription

Controller Platform Ratio Max GRE tunnels


7000-series
(70-05/10/24/30) Transition
1:1
Content --

7210 4:1 16K


7220 4:1 32K
7240 4:1 64K
M3 & 3600 2:1 16K

AOS 6.4+
#ATM15ANZ | @ ArubaANZ 29 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Licensing

•  Per-AP
–  AP
–  Policy Enforcement Firewall (PEF)
–  RFProtect

•  Per-Controller
–  Policy Enforcement Firewall VPN (PEFV)
•  For traffic entering through a VPN tunnel
•  Required for VIA

#ATM15ANZ | @ArubaANZ 30 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Remote AP (RAP)

#ATM15ANZ | @ ArubaANZ 31 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Remote AP (RAP)

•  Purpose-built RAPs and campus APs


•  Certificate-based provisioning
Transition
•  Secure wired and wirelessContent
remote access
•  RAPs are Instant out of the box
•  Aruba Activate

#ATM15ANZ | @ ArubaANZ 32 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Remote AP

INTERNET

#ATM15ANZ | @ ArubaANZ 33 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Remote AP - Logical
MAC-ETH0 24:DE:C6:CB:4A:F0 SERIAL BZ0030536
ACTIVATE PROVISIONING TYPE IAP TO RAP

Boston-RAP
536
AP GROUP
030
| BZ0
A:F0
CONTROLLER rap.arubanetworks.com
B:4
:D E :C6:C
24

IPSEC TUNNEL INTERNET

rap.arubanetworks.com

#ATM15ANZ | @ ArubaANZ 34 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
RAP Forwarding Modes

•  Tunnel
•  Bridge
•  Decrypt-tunnel
•  Split-tunnel

#ATM15ANZ | @ArubaANZ 35 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Split-tunnel

•  Tunnels certain traffic back to controller via IPSec


tunnel (defined in user roles)
•  Allows non-corporate traffic to be bridged out locally
saving bandwidth.
•  RAP handles encryption, decryption and firewall
enforcement locally

#ATM15ANZ | @ArubaANZ 36 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Limitations

•  Roaming
•  ARM features
Transition
•  Requires controller Content
licenses
•  Limited visibility

#ATM15ANZ | @ ArubaANZ 37 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Aruba Instant Architecture
Aruba Instant Overview

•  AP model begins with the letter I


–  IAP-225, IAP-215, IAP-205, etc
•  Instant APs can be converted to controller-based
APs
•  No feature licensing with local management
•  Manage locally, via AirWave, or Aruba Central
(cloud)
•  Dynamic provisioning via Aruba Activate (free)

#ATM15ANZ | @ArubaANZ 39 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Aruba Instant Overview - Technical

•  Cooperate locally at L2
•  Multiple uplink options (Ethernet, 4G/LTE, WiFi)
•  ARM, ClientMatch, AppRF, AirGroup, L3 Mobility
•  IAP-VPN for distributed environments

#ATM15ANZ | @ArubaANZ 40 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Instant topology

INTERNET

VC

#ATM15ANZ | @ ArubaANZ 41 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Instant traffic flow

•  Traffic destined for tunnels goes through VC


•  NAT’d traffic (guest) goes through VC
Transition
•  Regular user traffic Content
firewalled, processed and
switched out at AP

#ATM15ANZ | @ ArubaANZ 42 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Instant traffic flow

INTERNET

VC IP: 172.16.10.5
AP IP: 172.16.10.10 AP IP: 172.16.10.11
[10] 20,30 [10] 20,30
VC

www.google.com Client IP: 172.16.20.10

#ATM15ANZ | @ ArubaANZ 43 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Instant traffic flow – Guest/NAT

INTERNET

VC IP: 172.16.10.5
AP IP: 172.16.10.10 AP IP: 172.16.10.11
[10] 20,30 [10] 20,30
VC

Internal IAP Guest Network


“Magic VLAN” 3333
172.31.98.x
Src-NAT’d with VC address www.google.com Client IP: 172.31.98.42

#ATM15ANZ | @ ArubaANZ 44 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
IAP-VPN
IAP-VPN Topology
Datacenter 1 Datacenter 2

Master Master Master Master


active backup active backup

INTERNET

Site 1 Site 2 Site 3

VC

VC VC

#ATM15ANZ | @ ArubaANZ 46 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Benefits

•  Local RF coordination
•  Roaming
Transition
•  Isolated broadcast Content
domains for each cluster
•  Authentication survivability

#ATM15ANZ | @ ArubaANZ 47 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
DHCP modes

•  Local
•  Centralized L2
•  Distributed L2
•  Centralized L3
•  Distributed L3

#ATM15ANZ | @ ArubaANZ 48 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
DHCP modes

DHCP MODE SUBNET DHCP CLIENT GW CORP TRAFFIC LCL/INTERNET


Src-NAT Src-NAT
Local Local Master AP Master AP
IPSec tunnel Master AP IP

Centralized L2 CORP
Transition
Datacenter
Content
Datacenter
Tagged & switched to Src-NAT
datacenter via tunnel Master AP IP
Tagged & switched to Src-NAT
Distributed L2 CORP Master AP Datacenter
datacenter via tunnel Master AP IP
Routed to datacenter Src-NAT
Centralized L3 CORP Datacenter Master AP
inside IPSec tunnel Master AP IP
Routed to datacenter Src-NAT
Distributed L3 CORP Master AP Master AP
inside IPSec tunnel Master AP IP

#ATM15ANZ | @ ArubaANZ 49 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
IAP-VPN licensing

•  For basic VPN connectivity (single role), a


single PEFNG license is required
•  To use different roles for individual
Transition Content IAP
clusters, the PEFV license is required for each
controller

#ATM15ANZ | @ ArubaANZ 50 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Aruba Activate
Aruba Activate

Transition Content

#ATM15ANZ | @ ArubaANZ 52 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Aruba Activate

Transition Content

#ATM15ANZ | @ ArubaANZ 53 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
MANAGEMENT
Aruba Central
Aruba Central Overview

•  Cloud management for Instant and MAS


•  ZTP with Aruba Activate
Transition
•  Firmware management Content
•  Reporting
•  Responsive UI (adaptive to any display)
•  AppRF management and visibility
•  Cloud captive portal w/ social

#ATM15ANZ | @ ArubaANZ 56 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Aruba Central

#ATM15ANZ | @ ArubaANZ 57 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Aruba Central

#ATM15ANZ | @ ArubaANZ 58 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Aruba Central

#ATM15ANZ | @ ArubaANZ 59 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Aruba Central

#ATM15ANZ | @ ArubaANZ 60 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
AirWave
AirWave Overview

•  On-premise solution (VM or physical)


•  Management, monitoring and reporting of Aruba
controllers, Instant clusters,
Transition and MAS
Content
•  Multi-vendor
•  In a hybrid controller-Instant environment,
AirWave recommended
•  Single pane of glass

#ATM15ANZ | @ ArubaANZ 62 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Single pane of glass

Transition Content

#ATM15ANZ | @ ArubaANZ 63 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Instant GUI config

Transition Content

#ATM15ANZ | @ ArubaANZ 64 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Discussion & Questions

You might also like