This document discusses branch network solutions from Aruba Networks. It begins with an overview of branch solutions and the disruptions and cost savings they enable. It then covers centralized WLAN solutions with cloud services controllers and features of Aruba's branch operating system. The document also discusses decentralized WLAN with Aruba Instant, intelligent WAN services, and integration with Palo Alto Networks. It concludes by providing guidance on choosing the right branch solution based on factors like network size, branch type, and existing campus architecture.
2. 2#ATM16
Agenda
– Branch Solutions Overview
– Branch Disruptions, Cost Savings
– Centralized WLAN in Branch
– Cloud Services Controllers Positioning
– Branch AOS Features & New Opportunities
– Branch WAN Services
– Decentralized WLAN in Branch
– Aruba Instant with VPN
– Choosing the right solution for your business
@ArubaNetworks |
5. 5#ATM16
Disruptive Changes for Branch IT
@ArubaNetworks |
ETHERNET/3G/4G
LEGACY WAN
CONNECTIVITY
CLOUD APPS
LOCAL APP SERVERS
E3
By 2016, 30% of the advanced
attacks will enter organizations via
branch networks.
Public cloud IaaS will grow to over
$34B worldwide by 2018.
CLOUD SECURITY
ARCHITECTURES
DEDICATED SECURITY APPLIANCES
6. 6#ATM16
New Requirements for the Branch Network
@ArubaNetworks |
Unified role-based policies
and network rightsizing
WIRELESS + WIRED
Threat management and secure
guest access
SECURITY
WAN optimization, WAN health
monitoring, and availability during
failures
WAN INTELLIGENCE
Visibility and quality of services
for business critical applications
CLOUD PERFORMANCE
7. 7#ATM16
Cost Savings By Rightsizing The Branch
@ArubaNetworks |
Eliminate the need for separate WAN service
router, firewall...
One platform for wireless and wired clients
with common policy enforcement
Unified wireless architecture across campus
and branch
Deliver the all-wireless branch office with
unified communications
12. 12#ATM16
Cost Savings By Rightsizing The Branch
@ArubaNetworks |
Zero-touch provisioning
WAN optimization
WAN survivability
WAN health checks
Secured ports wired access
Policy-based WAN routing
Context based firewall
(user, app, device, location, content,
reputation)
13. 13#ATM16
Branch AOS Features & New opportunities
@ArubaNetworks |
Software and Cloud Services driving to Rightsized Branch IT
• Branch device and services consolidation
• Cloud security services. By 2016, 30% of advanced threats will enter
via branches (Source – Gartner Branch Office Security)
• Cloud and guest services drive the need for hybrid WAN architectures
Branch Infrastructure Refresh
Trends / Opportunities
ARUBA 7005 ARUBA 7010
ARUBA 7024
15. 15#ATM16
Intelligent WAN / PBR
– Policy based routing to multiple WAN links
(MPLS, Internet, 3G/4G) for cost savings
and improved WAN usage, performance
– WAN health check monitors loss and
latency on WAN links, Redundancy with
multiple next hops on WAN health or
performance issues
– Selective traffic routing to Active-Active
HQ/DC (DC1, DC2 etc.) IKE IPSEC tunnels
(Cellular is Standby)
– Routing inside tunnels, L3 GRE over
IPSEC – Corporate (IPSEC) Vs. Guest (L3
GRE)
@ArubaNetworks |
Public Cloud
HQ / DC
7240 7240
MAS
Internet`
Aruba 7000 CSC
CSC
16. 16#ATM16
WAN Optimization (Compression)
– WAN compression (hardware enabled)
between CSC (70xx) and 72xx Campus
Controllers
– 15-25% average payload compression
expected on traffic between branch and
HQ/DC
– The Master to Branch Cloud Services
Controller traffic over IPSEC will be
compressed and decompressed, Encrypted
traffic has NO compression
@ArubaNetworks |
HQ / DC
7240 7240
MAS
Aruba 7000 CSC CSC
17. 17#ATM16
Intelligent WAN / Bandwidth Contracts
– Application or App Category bandwidth
contracts on WAN Uplinks
– Limit App or App category bandwidth on
non-critical applications (E.g. Social Media,
Entertainment etc.)
– AppRF / DPI and Advanced QoS to
prioritize app/app categories on WAN
uplinks
@ArubaNetworks |
Public Cloud
HQ / DC
7240 7240
MAS
Internet`
Aruba 7000 CSC
CSC
Business Low
Business Critical
18. 18#ATM16
Aruba / Palo Alto Integration
Data Center
Aruba CSC w/ PA
Global Protect
PA
Gateway /
Portal
Branch (US)
Aruba CSC w/
PA Global Protect
• Aruba CSC gets cloud
provisioned via Activate and
downloads configurations
(including PA) via ZTP
• Aruba CSC Initiates a HTTPS
connection to PA portal and
downloads list of PA FW’s and
FW priorities.
Branch (Shanghai)
1
1
Aruba CSC w/ PA
Global Protect
2
Aruba CSC w/
PA Global Protect
2
2
• Branch offices establish secure
IPSEC tunnels to all PA
Gateways
• Branch routing policies (PBR)
selectively routes traffic to the
highest priority Gateway
Private Cloud
On Firewall failure or de-
commission, traffic will get re-
routed to FW with the next
highest priority
3
PA
Gateway
Aruba 72xx MC
Internet, SAAS or selective
traffic can get inspected via PA
Cloud SAAS
Advanced security threats
(ATP/APT, Zero Day, DLP etc.)
to distributed enterprise
enabled via Wild Fire
integration
4
SAAS
Pre-Provisioning:-
- Install PA certificates at 72xx (MC)
- Configure PA portal IP under PAN options in the MC under
Configuration -> Branch -> Smart Config -> WAN
21. 21#ATM16
HOW IT WORKS
• First AP configured through built-in UI use Activate for zero-touch
provisioning
–READY…
• It becomes the “master” & performs firewall and controller functions
–SET…
• New APs in the same VLAN automatically connect to the “master” &
download config
–GO!!
• New APs in different locations can also use Activate or import configuration from
the first AP
• Data center connectivity can be established with VPN tunnel between the master
AP and Aruba controllers as needed
–EXPAND!!
Instant APs
NO ONSITE IT NEEDED
NETWORK SURVIVABILITY
22. 22#ATM16
WI-FI THAT CAN EVOLVE WITH BUSINESS
Internet
Mobility
Controller
AD / RADIUS
Enterprise HQ
Instant UI
Instant
Aruba Central Aruba Airwave
MULTIPLE MANAGEMENT OPTIONS - MULTIPLE DEPLOYMENT OPTIONS
26. 26#ATM16
Decision Criteria for Wireless in a Branch
Branch Network
Size and complexity of
the branch
Type of branch:
Greenfield or
Brownfield
Backhaul and Wired
Infrastructure Choices
Services
Requirements
Existing campus
Network in place?
27. 27#ATM16
Benefits of a Centralized WLAN in Branches
Branch in a Box
– Intelligent WAN - PBR, Bandwidth Contracts
– WAN Optimization – acceleration, caching
– Secure WAN – URL filtering, web reputation,
PEF
– Integrated wired ports for a greenfield branch
with wireless services
– Architectural parity with Campus Network
– Earlier Access to Advanced services – Lync
SDN, Full Palo Alto Firewall Integration, etc
28. 28#ATM16
Benefits of a de-centralized WLAN in a Branch
Add WLAN and VPN to wired inftrastructure
– Cost-effective, especially for smaller
branches or when wired/backhaul
infrastructure is already in place or well-
planned
– Less redundant hardware required for local
WLAN survivability
– Easier to understand and set-up (No master-
local architecture required in data center)
– Great value in the form of AppRF,
ClientMatch, Cloud guest, Basic Palo Alto
Firewall Integration
29. 29#ATM16
Guidance for a Branch
– Consider Service Requirements
– Centralized architecture for branch in a box services
– Decentralized architecture for wireless and VPN services
– Consider Type of branch (Greenfield, Brownfield)
– For greenfield branches lead with centralized architecture
– Consider Existing Campus Wireless Architecture
– Customers might prefer architectural uniformity, especially if master-local architecture is already present in the data center
– Consider Local WLAN Survivability and Simplicity
– Customers that primarily use local branch services with occasional data center access may prefer the simplicity
and local survivability of a de-centralized solution
30. 30#ATM16
Join Aruba’s Titans of Tomorrow
force in the fight against network
mayhem. Find out what your
IT superpower is.
Share your results with friends
and receive a free superpower
t-shirt.
www.arubatitans.com
This is a sample Picture with Content slide ideal for including a picture with a brief descriptive statement.
To Replace the Picture on this Sample Slide (this applies to all slides in this template that contain replaceable pictures)
Select the sample picture and press Delete. Click the icon inside the shape to open the Insert Picture dialog box. Navigate to the location where the picture is stored, select desired picture and click on the Insert button to fit the image proportionally within the shape.
Note: Do not right-click the image to change the picture inside the picture placeholder. This will change the frame size of the picture placeholder. Instead, follow the steps outlined above.
Tip: use the Crop tool to reposition a picture within a placeholder. From the Picture Tools Format tab on the ribbon, click the Crop button. Click and drag the picture within the placeholder to reposition. To scale the picture within the placeholder (while Crop is active), grab a round corner handle and drag to resize. Hold Shift key to constrain picture aspect ratio when resizing.
This is a sample Picture with Content slide ideal for including a picture with a brief descriptive statement.
To Replace the Picture on this Sample Slide (this applies to all slides in this template that contain replaceable pictures)
Select the sample picture and press Delete. Click the icon inside the shape to open the Insert Picture dialog box. Navigate to the location where the picture is stored, select desired picture and click on the Insert button to fit the image proportionally within the shape.
Note: Do not right-click the image to change the picture inside the picture placeholder. This will change the frame size of the picture placeholder. Instead, follow the steps outlined above.
Tip: use the Crop tool to reposition a picture within a placeholder. From the Picture Tools Format tab on the ribbon, click the Crop button. Click and drag the picture within the placeholder to reposition. To scale the picture within the placeholder (while Crop is active), grab a round corner handle and drag to resize. Hold Shift key to constrain picture aspect ratio when resizing.
This is a sample Picture with Content slide ideal for including a picture with a brief descriptive statement.
To Replace the Picture on this Sample Slide (this applies to all slides in this template that contain replaceable pictures)
Select the sample picture and press Delete. Click the icon inside the shape to open the Insert Picture dialog box. Navigate to the location where the picture is stored, select desired picture and click on the Insert button to fit the image proportionally within the shape.
Note: Do not right-click the image to change the picture inside the picture placeholder. This will change the frame size of the picture placeholder. Instead, follow the steps outlined above.
Tip: use the Crop tool to reposition a picture within a placeholder. From the Picture Tools Format tab on the ribbon, click the Crop button. Click and drag the picture within the placeholder to reposition. To scale the picture within the placeholder (while Crop is active), grab a round corner handle and drag to resize. Hold Shift key to constrain picture aspect ratio when resizing.
Pre-Provisioning:-
Install PA certificates at 72xx (MC)
Configure PA portal IP under PAN options in the MC under Configuration -> Branch -> Smart Config -> WAN
Unification of wired and wireless policies – some of these branch office appliances will need wired Ethernet ports for plugging in devices like cameras, phones, printers etc. Similar policies for wired and wireless devices need to be applied in this environment. This enables unification of security policies and further helps with management and troubleshooting of the branch network as a whole
Intelligent and dynamic WAN optimization – techniques like compression and acceleration further ensures that the scarce WAN resources are utilized effectively.
Survivability – the branch needs the capability to support multiple uplinks from ISPs and implement policy based routing to use the WAN resources efficiently
Advanced Security – large distributed organizations need an array of techniques to combat blended attacks, wherein managing multiple, separate security tools can be overwhelming, inefficient and expensive. Advanced tools that enable Unified Threat Management (UTM) is beneficial for these branches. Content-based classification, behavioral analysis and reputation based system further enables the visibility and control that is needed to track usage and further control branch traffic. Centralized encryption ensures that all user traffic is encrypted that ensures comprehensive end-to-end security.
Multiple Uplink Options – in the case of a WAN failure the branch network should be able to offer alternative uplink options (3G, 4G) so that the network is highly available
Architectural parity with a campus network – For a customer who is used to a controller based architecture at the campus, having a smaller form factor appliances with built-in WLAN controller functionality at the branch will maintain architectural and operational consistency
Greenfield branch with basic wireless services – A brand new branch with just basic wireless services might want to take a look at the appliance based unified wired and wireless solution to have an integrated network
The size, scale and the scope of any branch office is typically lesser than what one would see in a campus. In a branch office environment scalability of services and mobility becomes less important. It is more important to have a solution that is plug & play, highly redundant, resilient to WAN outages, that can be deployed easily/Zero touch and managed centrally and so on. The controller less architecture with all the innovation that vendors have put in becomes an ideal choice for large distributed enterprises over a controller-based architecture.
Reliable Wireless Access – to offer wireless access to connect the endpoint devices.
Authentication and security – to provide secure network access to the endpoints and keep the network secure against rogues and other attacks
Quality of Service (QoS) - for multimedia applications: the branch network needs to support enterprise class QoS to support applications like voice, video, UCC etc.
Plug-and-play services: the branch network needs to support newer generation services like an Apple TV, Chromecast etc. so that users can build an all wireless office environment
Cloud based zero touch provisioning – Given the number of branch offices that an enterprise might have, the more plug and play the solution is, easier is the solution to roll out in a large scale
Secure Corporate connectivity – depending on the traffic type the branch office solution needs to be able to route traffic back to HQ securely so that the users at the branch can get their work done
Centralized management – it is critical that an administrator is able to install, manage and troubleshoot these distributed branch networks from one central location
When, what is it. Condense.
Legacy WAN (E1, T1 etc. ) -> Ethernet
Local app server -> cloud apps
Dedicated security appliances - > cloud security architectures
MPLS, dedicated P2P circuit -> Hybrid WAN with low cost 4G/DSL handoff
Complex networks -> L2 handoff
Software and Cloud Services driving to Rightsized Branch IT
Box consolidation. Moving to business wan away from T1/ei. Best of breeed cloud integrated with palo alto.
We need zero touch provisioning, central management, business WAN
Contest Overview
- Aruba is running a marketing campaign where we ask “What is your IT superpower?”
- Go to arubatitans.com to take a quick quiz to discover your superpower.
- Share your results with friends and encourage others to play the game
- Once you share, go to the Social and Community Hub, Gracia Commons, 3rd fl to pick up your free superpower shirt.
FAQ
1. What do I have to do to get a shirt?
Share your IT superpower results with friends and encourage them to play the game. Then come to the Social & Community Hub, 3rd Floor Gracia Commons to pick up your shirt. We just need your name and badge for verification.
2. Where do I get my shirt?
Come to the #ATM16 Social & Community hub located at Gracia Commons on the 3rd Floor
3. Do I have to be at the event to get the shirt?
Yes. You have to be at #ATM16 to get a shirt.
4. Can I get my colleague a shirt? He/she is in a session right now.
Unfortunately not. We encourage your colleague to participate so that they can win a shirt for themselves.
5. Can I bring a shirt home for my colleague?
Unfortunately not. You have to be at #ATM16 to get a shirt.
6. You don’t have a shirt in my size, can you ship the right size to me later?
Unfortunately not. Please select the best size from our inventory on site.