Aruba Wlans and Advanced Design Fundamentals: #Atm15Anz - @arubaanz
Aruba Wlans and Advanced Design Fundamentals: #Atm15Anz - @arubaanz
Aruba Wlans and Advanced Design Fundamentals: #Atm15Anz - @arubaanz
DESIGN FUNDAMENTALS
#ATM15ANZ | @ArubaANZ
Agenda
#ATM15ANZ | @ArubaANZ 2 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Deployment types
#ATM15ANZ | @ArubaANZ 3 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Mobility Controller Architecture
Mobility Controller Family
7200 SERIES
256 APs
4,096 IPSec
Transition Content
512 APs
16,384 IPSec
1,024 APs
24,576 IPSec
2,048 APs
32,768 IPSec
#ATM15ANZ | @ ArubaANZ 5 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Mobility Controller Family
CLOUD SERVICES CONTROLLERS
16 APs
Transition Content
Can be powered via PoE
64 APs
32 APs
10 PoE+
#ATM15ANZ | @ ArubaANZ 6 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Mobility Controller Family
CLOUD SERVICES CONTROLLERS
#ATM15ANZ | @ ArubaANZ 7 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Campus physical topology
Datacenter Datacenter
Master Master
active backup
#ATM15ANZ | @ ArubaANZ 8 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Campus logical topology
Master Master
active standby
IPSEC
GRE
STANDBY
GRE
PRIMARY
#ATM15ANZ | @ ArubaANZ 9 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
L2 Deployment
MGMT 30 10.200.30.1 ER
IP HELP DNS / DHCP
30 10.200.30.5
31
Controller
32
33 10.200.33.5
BYOD Client
IP 10.200.32.51
GW 10.200.32.1
#ATM15ANZ | @ ArubaANZ 10 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
L3 Deployment
DNS / DHCP
WAN/Core/Distribution Router
10.200.254.1/30
Transit link
TRANSIT 254 10.200.254.2/30
LOOPBACK lo 10.200.30.1
Controller
CORP CLIENTS 31 10.200.31.1
BYOD CLIENTS 32 10.200.32.1
GUEST 33 10.200.33.1
BYOD Client
IP 10.200.32.51
GW 10.200.32.1
#ATM15ANZ | @ ArubaANZ 11 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Master controller responsibilities
• Policy configuration
• Wireless security (WIPS / RFProtect)
• AP white lists (CAPs w/ CPsec and RAPs)
• Initial AP configuration
• Authentication and roles
#ATM15ANZ | @ArubaANZ 12 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Local controller responsibilities
#ATM15ANZ | @ArubaANZ 13 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Controller scaling
#ATM15ANZ | @ArubaANZ 14 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Controller scaling
• Platform
– 7000 series (7005/7010/7024/7030) should only be used as local
controllers*
– 7200 series should be master for multiple 7000 locals
• Failover capacity
#ATM15ANZ | @ArubaANZ 15 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Campus Forwarding Modes
• Tunnel
• Decrypt-tunnel
• Bridge
#ATM15ANZ | @ArubaANZ 16 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Tunnel
Tunnel-Mode
Mobility
Controller
• All traffic is tunneled back to controller
• User VLANs live in controller
• Wired network is a high-speed overlay
network
GRE Tunnel:
Encrypted • User traffic passes through stateful
firewall and deep packet inspection
engine (*on 7 series controllers)
Access
Point
#ATM15ANZ | @ArubaANZ 17 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Decrypt-tunnel (d-tunnel)
Decrypt-Tunnel-Mode
Mobility
Controller
• User VLANs live in controller
• AP decrypts traffic and strips 802.11
headers
• AP adds 802.3 headers and frame is
GRE Tunnel:
Unencrypted
encapsulated in GRE tunnel to
controller
• Controller applies firewall policies to
traffic
Access
Point
#ATM15ANZ | @ArubaANZ 18 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Bridge
Bridge Mode
Access
Switch
• User traffic bridged out to local network
• User VLANs live in edge network
• Authentication traffic tunneled to
controller
• Control plane security (cpsec) required
• Captive portal authentication is not
supported
Access
Point
#ATM15ANZ | @ArubaANZ 19 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Campus Redundancy
Master-Local Redundancy
Master Standby
Master Local 1 Local n
Local 2
Fully
Redundant
Master
Local 1 Local n
Local 2
Redundant Aggregation
Master
Local
Hot Standby
Master
Local
No Redundancy
#ATM15ANZ | @ ArubaANZ 21 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
VRRP Failover (L2)
172.16.100.5
VIRTUAL IP
172.16.100.2 172.16.100.3
VRRP MASTER VRRP BACKUP
GRE TUNNEL
SRC-IP <AP>
DST-IP: 172.16.100.5
LMS-IP: 172.16.100.5
#ATM15ANZ | @ ArubaANZ 22 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
VRRP Failover (L2)
172.16.100.5
VIRTUAL IP
172.16.100.3
VRRP MASTER
GRE TUNNEL
SRC-IP <AP>
DST-IP: 172.16.100.5
LMS-IP: 172.16.100.5
AP RE-BOOTSTRAPS
#ATM15ANZ | @ ArubaANZ 23 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Backup-LMS (L3)
172.16.100.2 10.50.20.2
GRE TUNNEL
SRC-IP <AP>
DST-IP: 172.16.100.2
LMS-IP: 172.16.100.2
BACKUP LMS-IP: 10.50.20.2
#ATM15ANZ | @ ArubaANZ 24 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Backup-LMS (L3)
172.16.100.2 10.50.20.2
GRE TUNNEL
SRC-IP <AP>
DST-IP: 10.50.20.2
LMS-IP: 172.16.100.2
BACKUP LMS-IP: 10.50.20.2
AP REBOOTS
#ATM15ANZ | @ ArubaANZ 25 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
HA: AP Fast Failover
GRE
GRE STANDBY
ACTIVE
AOS 6.3+
#ATM15ANZ | @ ArubaANZ 26 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
HA: AP Fast Failover
GRE
ACTIVE
AOS 6.3+
#ATM15ANZ | @ ArubaANZ 27 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
AP FF: Controller Roles
Transition
• ACTIVE: Controller does notContent
terminate standby
tunnels for other controllers
#ATM15ANZ | @ ArubaANZ 28 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
AP FF: N+1 Oversubscription
AOS 6.4+
#ATM15ANZ | @ ArubaANZ 29 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Licensing
• Per-AP
– AP
– Policy Enforcement Firewall (PEF)
– RFProtect
• Per-Controller
– Policy Enforcement Firewall VPN (PEFV)
• For traffic entering through a VPN tunnel
• Required for VIA
#ATM15ANZ | @ArubaANZ 30 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Remote AP (RAP)
#ATM15ANZ | @ ArubaANZ 31 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Remote AP (RAP)
#ATM15ANZ | @ ArubaANZ 32 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Remote AP
INTERNET
#ATM15ANZ | @ ArubaANZ 33 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Remote AP - Logical
MAC-ETH0 24:DE:C6:CB:4A:F0 SERIAL BZ0030536
ACTIVATE PROVISIONING TYPE IAP TO RAP
Boston-RAP
536
AP GROUP
030
| BZ0
A:F0
CONTROLLER rap.arubanetworks.com
B:4
:D E :C6:C
24
rap.arubanetworks.com
#ATM15ANZ | @ ArubaANZ 34 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
RAP Forwarding Modes
• Tunnel
• Bridge
• Decrypt-tunnel
• Split-tunnel
#ATM15ANZ | @ArubaANZ 35 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Split-tunnel
#ATM15ANZ | @ArubaANZ 36 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Limitations
• Roaming
• ARM features
Transition
• Requires controller Content
licenses
• Limited visibility
#ATM15ANZ | @ ArubaANZ 37 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Aruba Instant Architecture
Aruba Instant Overview
#ATM15ANZ | @ArubaANZ 39 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Aruba Instant Overview - Technical
• Cooperate locally at L2
• Multiple uplink options (Ethernet, 4G/LTE, WiFi)
• ARM, ClientMatch, AppRF, AirGroup, L3 Mobility
• IAP-VPN for distributed environments
#ATM15ANZ | @ArubaANZ 40 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Instant topology
INTERNET
VC
#ATM15ANZ | @ ArubaANZ 41 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Instant traffic flow
#ATM15ANZ | @ ArubaANZ 42 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Instant traffic flow
INTERNET
VC IP: 172.16.10.5
AP IP: 172.16.10.10 AP IP: 172.16.10.11
[10] 20,30 [10] 20,30
VC
#ATM15ANZ | @ ArubaANZ 43 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Instant traffic flow – Guest/NAT
INTERNET
VC IP: 172.16.10.5
AP IP: 172.16.10.10 AP IP: 172.16.10.11
[10] 20,30 [10] 20,30
VC
#ATM15ANZ | @ ArubaANZ 44 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
IAP-VPN
IAP-VPN Topology
Datacenter 1 Datacenter 2
INTERNET
VC
VC VC
#ATM15ANZ | @ ArubaANZ 46 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Benefits
• Local RF coordination
• Roaming
Transition
• Isolated broadcast Content
domains for each cluster
• Authentication survivability
#ATM15ANZ | @ ArubaANZ 47 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
DHCP modes
• Local
• Centralized L2
• Distributed L2
• Centralized L3
• Distributed L3
#ATM15ANZ | @ ArubaANZ 48 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
DHCP modes
Centralized L2 CORP
Transition
Datacenter
Content
Datacenter
Tagged & switched to Src-NAT
datacenter via tunnel Master AP IP
Tagged & switched to Src-NAT
Distributed L2 CORP Master AP Datacenter
datacenter via tunnel Master AP IP
Routed to datacenter Src-NAT
Centralized L3 CORP Datacenter Master AP
inside IPSec tunnel Master AP IP
Routed to datacenter Src-NAT
Distributed L3 CORP Master AP Master AP
inside IPSec tunnel Master AP IP
#ATM15ANZ | @ ArubaANZ 49 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
IAP-VPN licensing
#ATM15ANZ | @ ArubaANZ 50 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Aruba Activate
Aruba Activate
Transition Content
#ATM15ANZ | @ ArubaANZ 52 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Aruba Activate
Transition Content
#ATM15ANZ | @ ArubaANZ 53 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
MANAGEMENT
Aruba Central
Aruba Central Overview
#ATM15ANZ | @ ArubaANZ 56 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Aruba Central
#ATM15ANZ | @ ArubaANZ 57 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Aruba Central
#ATM15ANZ | @ ArubaANZ 58 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Aruba Central
#ATM15ANZ | @ ArubaANZ 59 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Aruba Central
#ATM15ANZ | @ ArubaANZ 60 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
AirWave
AirWave Overview
#ATM15ANZ | @ ArubaANZ 62 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Single pane of glass
Transition Content
#ATM15ANZ | @ ArubaANZ 63 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Instant GUI config
Transition Content
#ATM15ANZ | @ ArubaANZ 64 CONFIDENTIAL © Copyright 2015. Aruba, a Hewlett Packard Enterprise company. All rights reserved.
Discussion & Questions