SlideShare a Scribd company logo
1 of 36
Remote and Branch Networking Fundamentals
June 9-14, 2014
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
2 #AirheadsConf
Agenda
• Challenges of Deploying Remote networks
• Aruba Solution
• Aruba Instant
• Aruba Instant for Private WAN based Deployments
• Aruba Instant-VPN
• Management and Zero-Touch Deployment
Challenges of Deploying Remote
Networks
4
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Who should care?
Branch office / Remote
teleworker
Retail
Healthcare
5
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Challenges
Aruba Solution
7
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Aruba Solution
Home Office On The RoadBranch
Datacenter
AirWave Aruba Mobility Controller ClearPass Access Management
Instant-VPN
Mobility Switch
Instant Cluster
Virtual Intranet
Access (VIA) Client
Internet / WAN
Instant Cluster
Management and Zero-Touch
Deployment
9
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Internet
Airwave and Aruba Central
Campus Network
Aruba Central Aruba AirWave
Data Center
• Advanced guest services
• Mobile device onboarding
• Unified wired/wireless
policy
Airwave
ClearPas
s
Mobility
Switch
10
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Aruba Activate: Zero-touch
Deployment
Aruba Instant
12
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Aruba Instant
• Redundancy for
internal failure
• Redundancy for
external failure
• Organic growth
• Mobility-ready
• RF optimization
• Master AP
selection
• Over-the-air
provisioning
• WiFi oriented
configuration
Simple to
deploy
Self-
optimizing
Self-
healing
Scalable
13
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Aruba Instant Architecture
• Distributed data-plane
– Wireless encryption / decryption, firewall
• Distributed control-plane
– Authentication, DHCP, ARM, WIPS
• Centralized (local) management-plane
– Configuration, firmware management, GUI, SNMP
14
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Automatic RF Management
Infrastructure control
• Automatic RF
optimization for
coverage & capacity
• Real-time spectrum
analysis and
interference avoidance
• Load / Application
awareness
• Self-healing
Channel 11
Channel 6
Channel 1
Client Control
• Moves clients towards
less congested
frequency band
• Distributes clients
across available
spectrum*
• Bandwidth controls
15
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Security tailored for Mobility
Context Aware
On-boarding
Role-based access
Policy Enforcement
• Aruba RFProtect + AirWave RAPIDS
• RF Scanning, Rogue AP detection / containment, Valid-station protection
• Encryption
• Over-the-air AES encryption, IPSec VPN to datacenter (where applicable)
• Role-based Access
• Per-user, per-device access
• Policy Enforcement Firewall
• Segregation of business traffic from guest traffic.
• Blacklisting for session violation
• Centralized Monitoring and Alerting
16
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
• No need for separate SSID for QoS.
• Session based DSCP tagging &
prioritization
• Multicast-to-unicast conversion for
video
• Media-classification for encrypted
voice –Apple Facetime
• AirGroup* to manage Apple AirPlay,
AirPrint, etc
Mobility Services: Real-time
Applications
Clear
Pass
IAP
IAP IAP
17
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Mobility Services: Guest Access
• Securely Manage Visitor Access
– Streamlined workflow; No IT
• Sponsored-based, Visitor Self-Registration, Pre-registration,
Anonymous Guest Access
• 3rd Party Integrations
• APIs for integration with existing applications / CRM tools
– Assignable roles, expiration times, user names, passwords
• Highest Customization
– Skin technology, software plugins, APIs
– Targeted advertising and content delivery
Private WAN based Deployments
19
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Private-WAN based Deployments
20
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Private-WAN based Deployments
21
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Auto-GRE for Guest
Branch office
Datacenter
AirWave ClearPass
Instant Cluster
VRRP Link
Master Standby
Guest Anchor
Master Active
Servers
MPLS
Employee Traffic
Guest Traffic
Aruba Instant-VPN
23
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Datacenter
AirWave/Aruba
Central Aruba Mobility Controller
ClearPass solution
Internet / WAN
VRRP Link
Master Standby
DMZ
Master Active
Home Office
Instant
Home office Solution
Home Office
Instant
24
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Branch Office Solution
Branch office
Datacenter
AirWave/Aruba
Central Aruba Mobility Controller
ClearPass solution
Instant Cluster
Internet / WAN
VRRP Link
Master Standby
DMZ
Master Active
Branch office
Instant Cluster
25
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
DHCP - How does Distributed L3
work ?
Network 10.0.0.0/8
VLANs 10 to 99
Data Center
Remote Branch
Internet /
WAN
Active
VPN
Tunnel
Client A
Browsing to
Intranet
Browsing to
Youtube
Route on IAP –
For 10.0.0.0/8 network, next
hop is VPN terminating
controller’s IP address
Master IAP Memeber IAP
Client B
Browsing to
Intranet
Browsing to
Youtube
VLAN 250
IAP-VC is the
DHCP Server
DHCP
Request
VC SRC NATs traffic using IAPs local IPVC routes the traffic to the
tunnel
Intranet
26
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
DHCP - How does Centralized
L2 work ?
Network 10.0.0.0/8
VLANs 10 to 99
Data Center
Remote Branch
Internet /
WAN
Active
VPN
Tunnel
Client A
Browsing to
Intranet
Browsing to
Youtube
Route on IAP –
For 10.0.0.0/8 network, next
hop is VPN terminating
controller’s IP address
Master IAP Member IAP
Client B
Browsing to
Intranet
Browsing to
Youtube
VLAN 50
DHCP
Request
VC SRC NATs traffic using IAPs local IPVC bridges traffic in the
tunnel
VLAN 50
DHCP Server and
Default Gateway
Intranet
27
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
DHCP - How does Local Subnet
work ?
Intranet
Network 10.0.0.0/8
VLANs 10 to 99
Data Center
Remote Branch
Internet /
WAN
Active
VPN
Tunnel
Client A
Browsing to
Intranet
Browsing to
Youtube
Route on IAP –
For 10.0.0.0/8 network, next
hop is VPN terminating
controller’s IP address
Master IAP Slave IAP
Client B
Browsing to
Intranet
Browsing to
Youtube
VLAN 200
IAP-VC is the
DHCP Server
DHCP
Request
VC SRC NATs traffic using IAPs local IPVC SRC NATs traffic using
inner IP
28
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Recommendations
IAP-VPN Modes Usage Recommendations
Distributed L3 Recommended for all deployments.
Local
Recommended for Guest networks with centralized captive portal
servers.
Centralized L2
Recommended only if Multicast to branch is a requirement. If
Multicast to branch networks is not required, use L3 modes.
Aruba Instant-VPN Design Options
31
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Single AP deployments
32
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Single AP deployments
33
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Multi-AP deployments
34
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Multi-AP deployments
35
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
Thank You
#AirheadsConf
41
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
42
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
Thank You
#AirheadsConf

More Related Content

What's hot

6 understanding aruba rf issues
6 understanding aruba rf issues6 understanding aruba rf issues
6 understanding aruba rf issuesVenudhanraj
 

What's hot (20)

Network Management with Aruba Airwave #AirheadsConf Italy
Network Management with Aruba Airwave #AirheadsConf ItalyNetwork Management with Aruba Airwave #AirheadsConf Italy
Network Management with Aruba Airwave #AirheadsConf Italy
 
Shanghai Breakout: Advanced Airwave Workshop
Shanghai Breakout: Advanced Airwave WorkshopShanghai Breakout: Advanced Airwave Workshop
Shanghai Breakout: Advanced Airwave Workshop
 
Airheads Macau 2013 - WLAN Management & Troubleshooting with AirWave
Airheads Macau 2013 - WLAN Management & Troubleshooting with AirWaveAirheads Macau 2013 - WLAN Management & Troubleshooting with AirWave
Airheads Macau 2013 - WLAN Management & Troubleshooting with AirWave
 
Getting the most out of the Aruba Policy Enforcement Firewall
Getting the most out of the Aruba Policy Enforcement FirewallGetting the most out of the Aruba Policy Enforcement Firewall
Getting the most out of the Aruba Policy Enforcement Firewall
 
Defining Advanced AAA Policies for Access Networks
Defining Advanced AAA Policies for Access NetworksDefining Advanced AAA Policies for Access Networks
Defining Advanced AAA Policies for Access Networks
 
Best Practices on Migrating to 802.11ac Wi-Fi #AirheadsConf Italy
Best Practices on Migrating to 802.11ac Wi-Fi #AirheadsConf ItalyBest Practices on Migrating to 802.11ac Wi-Fi #AirheadsConf Italy
Best Practices on Migrating to 802.11ac Wi-Fi #AirheadsConf Italy
 
Packets never lie: An in-depth overview of 802.11 frames
Packets never lie: An in-depth overview of 802.11 framesPackets never lie: An in-depth overview of 802.11 frames
Packets never lie: An in-depth overview of 802.11 frames
 
Amigopod and ArubaOS Integration
Amigopod and ArubaOS IntegrationAmigopod and ArubaOS Integration
Amigopod and ArubaOS Integration
 
EMEA Airheads – Aruba controller features used to optimize performance
EMEA Airheads – Aruba controller features used to optimize performanceEMEA Airheads – Aruba controller features used to optimize performance
EMEA Airheads – Aruba controller features used to optimize performance
 
RAP Networks Validated Reference Design
RAP Networks Validated Reference DesignRAP Networks Validated Reference Design
RAP Networks Validated Reference Design
 
Shanghai Breakout: Advanced RF Design and Troubleshooting
Shanghai Breakout: Advanced RF Design and Troubleshooting Shanghai Breakout: Advanced RF Design and Troubleshooting
Shanghai Breakout: Advanced RF Design and Troubleshooting
 
Aruba Campus Wireless Networks
Aruba Campus Wireless NetworksAruba Campus Wireless Networks
Aruba Campus Wireless Networks
 
Enabling the Virtual Enterprise
Enabling the Virtual EnterpriseEnabling the Virtual Enterprise
Enabling the Virtual Enterprise
 
6 understanding aruba rf issues
6 understanding aruba rf issues6 understanding aruba rf issues
6 understanding aruba rf issues
 
Deploying Microsoft Lync over Wi-Fi #AirheadsConf Italy
Deploying Microsoft Lync over Wi-Fi #AirheadsConf ItalyDeploying Microsoft Lync over Wi-Fi #AirheadsConf Italy
Deploying Microsoft Lync over Wi-Fi #AirheadsConf Italy
 
3 air wave practical workshop_mike bruno_matt sidhu
3 air wave practical workshop_mike bruno_matt sidhu3 air wave practical workshop_mike bruno_matt sidhu
3 air wave practical workshop_mike bruno_matt sidhu
 
Base Designs Lab Setup for Validated Reference Design
Base Designs Lab Setup for Validated Reference DesignBase Designs Lab Setup for Validated Reference Design
Base Designs Lab Setup for Validated Reference Design
 
Unified access with Aruba Mobility Access Switches – Live Demo
Unified access with Aruba Mobility Access Switches – Live DemoUnified access with Aruba Mobility Access Switches – Live Demo
Unified access with Aruba Mobility Access Switches – Live Demo
 
Breaking the Status Quo
Breaking the Status QuoBreaking the Status Quo
Breaking the Status Quo
 
Enabling AirPrint & AirPlay on Your Network
Enabling AirPrint & AirPlay on Your NetworkEnabling AirPrint & AirPlay on Your Network
Enabling AirPrint & AirPlay on Your Network
 

Viewers also liked

Viewers also liked (20)

Shanghai Breakout: 802.11ac Wi-Fi Fundamentals
Shanghai Breakout: 802.11ac Wi-Fi FundamentalsShanghai Breakout: 802.11ac Wi-Fi Fundamentals
Shanghai Breakout: 802.11ac Wi-Fi Fundamentals
 
Advanced Aruba Mobility Access Switch Workshop #AirheadsConf Italy
Advanced Aruba Mobility Access Switch Workshop #AirheadsConf ItalyAdvanced Aruba Mobility Access Switch Workshop #AirheadsConf Italy
Advanced Aruba Mobility Access Switch Workshop #AirheadsConf Italy
 
Aruba Atmosphere / Airheads 2014 Keerti Melkote Keynote
Aruba Atmosphere / Airheads 2014 Keerti Melkote KeynoteAruba Atmosphere / Airheads 2014 Keerti Melkote Keynote
Aruba Atmosphere / Airheads 2014 Keerti Melkote Keynote
 
Aruba Instant Workshop #AirheadsConf Italy
Aruba Instant Workshop #AirheadsConf ItalyAruba Instant Workshop #AirheadsConf Italy
Aruba Instant Workshop #AirheadsConf Italy
 
E Rate Modernization Overview
E Rate Modernization Overview E Rate Modernization Overview
E Rate Modernization Overview
 
Breakout - Airheads Macau 2013 - WLAN Management & Troubleshooting with AirWave
Breakout - Airheads Macau 2013 - WLAN Management & Troubleshooting with AirWaveBreakout - Airheads Macau 2013 - WLAN Management & Troubleshooting with AirWave
Breakout - Airheads Macau 2013 - WLAN Management & Troubleshooting with AirWave
 
Shanghai Breakout: Access Management with Aruba ClearPass
Shanghai Breakout: Access Management with Aruba ClearPassShanghai Breakout: Access Management with Aruba ClearPass
Shanghai Breakout: Access Management with Aruba ClearPass
 
Aruba Networks at WFD6
Aruba Networks at WFD6 Aruba Networks at WFD6
Aruba Networks at WFD6
 
Meridian APPs and ALE at WFD6
Meridian APPs and ALE at WFD6Meridian APPs and ALE at WFD6
Meridian APPs and ALE at WFD6
 
Customer Keynote - Microsoft Lync
Customer Keynote - Microsoft LyncCustomer Keynote - Microsoft Lync
Customer Keynote - Microsoft Lync
 
Aruba Technical Webinar: Unplugging the Last Cord
Aruba Technical Webinar:  Unplugging the Last CordAruba Technical Webinar:  Unplugging the Last Cord
Aruba Technical Webinar: Unplugging the Last Cord
 
Breakout - Airheads Macau 2013 - Cloud WiFi
Breakout - Airheads Macau 2013 - Cloud WiFiBreakout - Airheads Macau 2013 - Cloud WiFi
Breakout - Airheads Macau 2013 - Cloud WiFi
 
Make Your Own Meridian Mobile App Workshop #AirheadsConf Italy
Make Your Own Meridian Mobile App Workshop #AirheadsConf ItalyMake Your Own Meridian Mobile App Workshop #AirheadsConf Italy
Make Your Own Meridian Mobile App Workshop #AirheadsConf Italy
 
Breakout - Airheads Macau 2013 - ClearPass Access Management Basics
Breakout - Airheads Macau 2013 - ClearPass Access Management Basics Breakout - Airheads Macau 2013 - ClearPass Access Management Basics
Breakout - Airheads Macau 2013 - ClearPass Access Management Basics
 
IDC Aruba Webinar - 3 Feb 15
IDC Aruba Webinar - 3 Feb 15IDC Aruba Webinar - 3 Feb 15
IDC Aruba Webinar - 3 Feb 15
 
Make Your Own Meridian Mobile App Workshop #AirheadsConf Italy
Make Your Own Meridian Mobile App Workshop #AirheadsConf ItalyMake Your Own Meridian Mobile App Workshop #AirheadsConf Italy
Make Your Own Meridian Mobile App Workshop #AirheadsConf Italy
 
WLAN Design for Location, Voice & Video
WLAN Design for Location, Voice & VideoWLAN Design for Location, Voice & Video
WLAN Design for Location, Voice & Video
 
Adaptive Trust Security
Adaptive Trust SecurityAdaptive Trust Security
Adaptive Trust Security
 
Wi-Fi Behavior of Popular Mobile Devices #AirheadsConf Italy
Wi-Fi Behavior of Popular Mobile Devices #AirheadsConf ItalyWi-Fi Behavior of Popular Mobile Devices #AirheadsConf Italy
Wi-Fi Behavior of Popular Mobile Devices #AirheadsConf Italy
 
E-Rate 2.0 Overview
E-Rate 2.0 Overview E-Rate 2.0 Overview
E-Rate 2.0 Overview
 

Similar to Remote & Branch Networking Fundamentals #AirheadsConf Italy

Sydney UC - February 2015
Sydney UC - February 2015Sydney UC - February 2015
Sydney UC - February 2015justimorris
 
Iwan advantage-v2-140330172853-phpapp01
Iwan advantage-v2-140330172853-phpapp01Iwan advantage-v2-140330172853-phpapp01
Iwan advantage-v2-140330172853-phpapp01Boris Rojas
 
Deploying mobile unified communications and collaboration (UCC) with Microsof...
Deploying mobile unified communications and collaboration (UCC) with Microsof...Deploying mobile unified communications and collaboration (UCC) with Microsof...
Deploying mobile unified communications and collaboration (UCC) with Microsof...Aruba, a Hewlett Packard Enterprise company
 
Transforming Networks into a NFV-Centric Environment
Transforming Networks into a NFV-Centric EnvironmentTransforming Networks into a NFV-Centric Environment
Transforming Networks into a NFV-Centric EnvironmentADVA
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayCisco Canada
 
End-to-Eend security with Palo Alto Networks (Onur Kasap, Palo Alto Networks)
End-to-Eend security with Palo Alto Networks (Onur Kasap, Palo Alto Networks)End-to-Eend security with Palo Alto Networks (Onur Kasap, Palo Alto Networks)
End-to-Eend security with Palo Alto Networks (Onur Kasap, Palo Alto Networks)BAKOTECH
 
End to End Security With Palo Alto Networks (Onur Kasap, engineer Palo Alto N...
End to End Security With Palo Alto Networks (Onur Kasap, engineer Palo Alto N...End to End Security With Palo Alto Networks (Onur Kasap, engineer Palo Alto N...
End to End Security With Palo Alto Networks (Onur Kasap, engineer Palo Alto N...BAKOTECH
 

Similar to Remote & Branch Networking Fundamentals #AirheadsConf Italy (20)

Remote Wireless LANs
Remote Wireless LANsRemote Wireless LANs
Remote Wireless LANs
 
2012 ah vegas remote networking fundamentals
2012 ah vegas   remote networking fundamentals2012 ah vegas   remote networking fundamentals
2012 ah vegas remote networking fundamentals
 
Advanced Aruba ClearPass Workshop
Advanced Aruba ClearPass WorkshopAdvanced Aruba ClearPass Workshop
Advanced Aruba ClearPass Workshop
 
Next generation remote networks aruba instant gokul rajagopalan
Next generation remote networks aruba instant gokul rajagopalanNext generation remote networks aruba instant gokul rajagopalan
Next generation remote networks aruba instant gokul rajagopalan
 
Advanced Access Management with Aruba ClearPass #AirheadsConf Italy
Advanced Access Management with Aruba ClearPass #AirheadsConf ItalyAdvanced Access Management with Aruba ClearPass #AirheadsConf Italy
Advanced Access Management with Aruba ClearPass #AirheadsConf Italy
 
Sydney UC - February 2015
Sydney UC - February 2015Sydney UC - February 2015
Sydney UC - February 2015
 
Instant overview gokul_rajagopalan
Instant overview gokul_rajagopalanInstant overview gokul_rajagopalan
Instant overview gokul_rajagopalan
 
1 voice and video over wi fi-balajee krishnamurthy
1 voice and video over wi fi-balajee krishnamurthy1 voice and video over wi fi-balajee krishnamurthy
1 voice and video over wi fi-balajee krishnamurthy
 
Iwan advantage-v2-140330172853-phpapp01
Iwan advantage-v2-140330172853-phpapp01Iwan advantage-v2-140330172853-phpapp01
Iwan advantage-v2-140330172853-phpapp01
 
Advanced ClearPass Workshop
Advanced ClearPass WorkshopAdvanced ClearPass Workshop
Advanced ClearPass Workshop
 
Deploying mobile unified communications and collaboration (UCC) with Microsof...
Deploying mobile unified communications and collaboration (UCC) with Microsof...Deploying mobile unified communications and collaboration (UCC) with Microsof...
Deploying mobile unified communications and collaboration (UCC) with Microsof...
 
Access Management with Aruba ClearPass #AirheadsConf Italy
Access Management with Aruba ClearPass #AirheadsConf ItalyAccess Management with Aruba ClearPass #AirheadsConf Italy
Access Management with Aruba ClearPass #AirheadsConf Italy
 
NFV & SDN Customer Deployments
NFV & SDN Customer DeploymentsNFV & SDN Customer Deployments
NFV & SDN Customer Deployments
 
Shanghai Keynote: Keerti Demos
Shanghai Keynote: Keerti DemosShanghai Keynote: Keerti Demos
Shanghai Keynote: Keerti Demos
 
Transforming Networks into a NFV-Centric Environment
Transforming Networks into a NFV-Centric EnvironmentTransforming Networks into a NFV-Centric Environment
Transforming Networks into a NFV-Centric Environment
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus Day
 
End-to-Eend security with Palo Alto Networks (Onur Kasap, Palo Alto Networks)
End-to-Eend security with Palo Alto Networks (Onur Kasap, Palo Alto Networks)End-to-Eend security with Palo Alto Networks (Onur Kasap, Palo Alto Networks)
End-to-Eend security with Palo Alto Networks (Onur Kasap, Palo Alto Networks)
 
End to End Security With Palo Alto Networks (Onur Kasap, engineer Palo Alto N...
End to End Security With Palo Alto Networks (Onur Kasap, engineer Palo Alto N...End to End Security With Palo Alto Networks (Onur Kasap, engineer Palo Alto N...
End to End Security With Palo Alto Networks (Onur Kasap, engineer Palo Alto N...
 
2012 ah vegas mobile device fundamentals
2012 ah vegas   mobile device fundamentals2012 ah vegas   mobile device fundamentals
2012 ah vegas mobile device fundamentals
 
Access Management with Aruba ClearPass
Access Management with Aruba ClearPassAccess Management with Aruba ClearPass
Access Management with Aruba ClearPass
 

More from Aruba, a Hewlett Packard Enterprise company

More from Aruba, a Hewlett Packard Enterprise company (20)

Airheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba CentralAirheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
 
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard AgentsAirheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
 
Airheads Tech Talks: Advanced Clustering in AOS 8.x
Airheads Tech Talks: Advanced Clustering in AOS 8.xAirheads Tech Talks: Advanced Clustering in AOS 8.x
Airheads Tech Talks: Advanced Clustering in AOS 8.x
 
EMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Advance Aruba CentralEMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Advance Aruba Central
 
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.xEMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
 
EMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS SwitchEMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- Switch stacking_ ArubaOS Switch
 
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS SwitchEMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
 
Introduction to AirWave 10
Introduction to AirWave 10Introduction to AirWave 10
Introduction to AirWave 10
 
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS SwitchEMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
 
EMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- Aruba Central with Instant APEMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- Aruba Central with Instant AP
 
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.xEMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
 
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
EMEA Airheads-  Getting Started with the ClearPass REST API – CPPMEMEA Airheads-  Getting Started with the ClearPass REST API – CPPM
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
 
EMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP DeploymentEMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads - AP Discovery Logic and AP Deployment
 
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.xEMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
 
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads- Manage Devices at Branch Office (BOC)
 
EMEA Airheads - What does AirMatch do differently?v2
 EMEA Airheads - What does AirMatch do differently?v2 EMEA Airheads - What does AirMatch do differently?v2
EMEA Airheads - What does AirMatch do differently?v2
 
Airheads Meetups: 8400 Presentation
Airheads Meetups: 8400 PresentationAirheads Meetups: 8400 Presentation
Airheads Meetups: 8400 Presentation
 
Airheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau PresentationAirheads Meetups: Ekahau Presentation
Airheads Meetups: Ekahau Presentation
 
Airheads Meetups- High density WLAN
Airheads Meetups- High density WLANAirheads Meetups- High density WLAN
Airheads Meetups- High density WLAN
 
Airheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes ArubaAirheads Meetups- Avans Hogeschool goes Aruba
Airheads Meetups- Avans Hogeschool goes Aruba
 

Recently uploaded

Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?Antenna Manufacturer Coco
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 

Recently uploaded (20)

Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 

Remote & Branch Networking Fundamentals #AirheadsConf Italy

  • 1. Remote and Branch Networking Fundamentals June 9-14, 2014
  • 2. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved 2 #AirheadsConf Agenda • Challenges of Deploying Remote networks • Aruba Solution • Aruba Instant • Aruba Instant for Private WAN based Deployments • Aruba Instant-VPN • Management and Zero-Touch Deployment
  • 3. Challenges of Deploying Remote Networks
  • 4. 4 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Who should care? Branch office / Remote teleworker Retail Healthcare
  • 5. 5 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Challenges
  • 7. 7 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Aruba Solution Home Office On The RoadBranch Datacenter AirWave Aruba Mobility Controller ClearPass Access Management Instant-VPN Mobility Switch Instant Cluster Virtual Intranet Access (VIA) Client Internet / WAN Instant Cluster
  • 9. 9 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Internet Airwave and Aruba Central Campus Network Aruba Central Aruba AirWave Data Center • Advanced guest services • Mobile device onboarding • Unified wired/wireless policy Airwave ClearPas s Mobility Switch
  • 10. 10 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Aruba Activate: Zero-touch Deployment
  • 12. 12 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Aruba Instant • Redundancy for internal failure • Redundancy for external failure • Organic growth • Mobility-ready • RF optimization • Master AP selection • Over-the-air provisioning • WiFi oriented configuration Simple to deploy Self- optimizing Self- healing Scalable
  • 13. 13 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Aruba Instant Architecture • Distributed data-plane – Wireless encryption / decryption, firewall • Distributed control-plane – Authentication, DHCP, ARM, WIPS • Centralized (local) management-plane – Configuration, firmware management, GUI, SNMP
  • 14. 14 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Automatic RF Management Infrastructure control • Automatic RF optimization for coverage & capacity • Real-time spectrum analysis and interference avoidance • Load / Application awareness • Self-healing Channel 11 Channel 6 Channel 1 Client Control • Moves clients towards less congested frequency band • Distributes clients across available spectrum* • Bandwidth controls
  • 15. 15 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Security tailored for Mobility Context Aware On-boarding Role-based access Policy Enforcement • Aruba RFProtect + AirWave RAPIDS • RF Scanning, Rogue AP detection / containment, Valid-station protection • Encryption • Over-the-air AES encryption, IPSec VPN to datacenter (where applicable) • Role-based Access • Per-user, per-device access • Policy Enforcement Firewall • Segregation of business traffic from guest traffic. • Blacklisting for session violation • Centralized Monitoring and Alerting
  • 16. 16 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf • No need for separate SSID for QoS. • Session based DSCP tagging & prioritization • Multicast-to-unicast conversion for video • Media-classification for encrypted voice –Apple Facetime • AirGroup* to manage Apple AirPlay, AirPrint, etc Mobility Services: Real-time Applications Clear Pass IAP IAP IAP
  • 17. 17 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Mobility Services: Guest Access • Securely Manage Visitor Access – Streamlined workflow; No IT • Sponsored-based, Visitor Self-Registration, Pre-registration, Anonymous Guest Access • 3rd Party Integrations • APIs for integration with existing applications / CRM tools – Assignable roles, expiration times, user names, passwords • Highest Customization – Skin technology, software plugins, APIs – Targeted advertising and content delivery
  • 18. Private WAN based Deployments
  • 19. 19 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Private-WAN based Deployments
  • 20. 20 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Private-WAN based Deployments
  • 21. 21 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Auto-GRE for Guest Branch office Datacenter AirWave ClearPass Instant Cluster VRRP Link Master Standby Guest Anchor Master Active Servers MPLS Employee Traffic Guest Traffic
  • 23. 23 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Datacenter AirWave/Aruba Central Aruba Mobility Controller ClearPass solution Internet / WAN VRRP Link Master Standby DMZ Master Active Home Office Instant Home office Solution Home Office Instant
  • 24. 24 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Branch Office Solution Branch office Datacenter AirWave/Aruba Central Aruba Mobility Controller ClearPass solution Instant Cluster Internet / WAN VRRP Link Master Standby DMZ Master Active Branch office Instant Cluster
  • 25. 25 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf DHCP - How does Distributed L3 work ? Network 10.0.0.0/8 VLANs 10 to 99 Data Center Remote Branch Internet / WAN Active VPN Tunnel Client A Browsing to Intranet Browsing to Youtube Route on IAP – For 10.0.0.0/8 network, next hop is VPN terminating controller’s IP address Master IAP Memeber IAP Client B Browsing to Intranet Browsing to Youtube VLAN 250 IAP-VC is the DHCP Server DHCP Request VC SRC NATs traffic using IAPs local IPVC routes the traffic to the tunnel Intranet
  • 26. 26 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf DHCP - How does Centralized L2 work ? Network 10.0.0.0/8 VLANs 10 to 99 Data Center Remote Branch Internet / WAN Active VPN Tunnel Client A Browsing to Intranet Browsing to Youtube Route on IAP – For 10.0.0.0/8 network, next hop is VPN terminating controller’s IP address Master IAP Member IAP Client B Browsing to Intranet Browsing to Youtube VLAN 50 DHCP Request VC SRC NATs traffic using IAPs local IPVC bridges traffic in the tunnel VLAN 50 DHCP Server and Default Gateway Intranet
  • 27. 27 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf DHCP - How does Local Subnet work ? Intranet Network 10.0.0.0/8 VLANs 10 to 99 Data Center Remote Branch Internet / WAN Active VPN Tunnel Client A Browsing to Intranet Browsing to Youtube Route on IAP – For 10.0.0.0/8 network, next hop is VPN terminating controller’s IP address Master IAP Slave IAP Client B Browsing to Intranet Browsing to Youtube VLAN 200 IAP-VC is the DHCP Server DHCP Request VC SRC NATs traffic using IAPs local IPVC SRC NATs traffic using inner IP
  • 28. 28 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Recommendations IAP-VPN Modes Usage Recommendations Distributed L3 Recommended for all deployments. Local Recommended for Guest networks with centralized captive portal servers. Centralized L2 Recommended only if Multicast to branch is a requirement. If Multicast to branch networks is not required, use L3 modes.
  • 30. 31 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Single AP deployments
  • 31. 32 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Single AP deployments
  • 32. 33 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Multi-AP deployments
  • 33. 34 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Multi-AP deployments
  • 34. 35 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Thank You #AirheadsConf
  • 35. 41 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf
  • 36. 42 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Thank You #AirheadsConf

Editor's Notes

  1. llanges
  2. 30:24 – 32:44
  3. Changed middle bullet
  4. llanges
  5. The only true BYOD ready, unified wired and wireless access solution for Distributed Enterprises. The key advantages being, SIMPLICITY, RELIABILITY and SECURITY. AirWave provides the end-to-end clarity and control to manage mobile users on multi-vendor, multi-site networks. Also provides remote debugging capabilities. The first and only BYOD provisioning and onboarding framework for any network. Delivers unparalleled simplicity when managing and securing network access across wireless, wired and VPNs. Servers as VPN termination point for each of the branch IAP virtual controllers. Aruba Activate for zero touch deployment. Also, security and content filtering services integrated in Instant by partnership with OpenDNS Same role-based context aware architecture can now be extended to wired users. Easier to install than your home Wi-Fi network, Aruba RAPs provide a secure, always-on wired and wireless connection back to the corporate network. Provides investment protection and deployment flexibility for future growth into large branches by ability to convert IAPs to CAPs. Also provides site to site VPN capability. Provides enterprise grade branch solution with site survivability, high availability, and zero touch deployment option. Offers intelligent infrastructure and user management with no dependency on WAN link for control traffic. Aruba VIA client software provides secure network connectivity for smartphones, tablets and laptops. Supports Windows, OS X, iOS and Android platforms. Seen on this slide is the Aruba DE solution architecture. So let us go over the components that comprise the Aruba DE solution and how to position these solutions: So for road warriors who need to connect in to their corporate network, Aruba offers a soft VPN client “VIA” to tunnel traffic in. This works great for individuals using their laptops, tablets or smartphones to access internal corporate content and is supported on Windows, OSx, iOS as well as Android platforms. But what for the home office user, maybe someone who wants to setup a lab at home and communicate with devices on the corporate network. For that RAP’s are an ideal choice. Next is the branch office itself. There are three deployment options that the customers have here. Aruba instant clusters deployed at branches managed centrally by AirWave (and in the future potentially Athena) Aruba Instant clusters deployed at branches, with the VC at each of the branch office forming an IPSec VPN tunnel with the controller at the HQ all centrally managed by AirWave Branch controllers (600 series) deployed at each of the branch offices terminating APs for those branches and Aruba Mobility controller at HQ all centrally managed by AirWave The choice maybe obvious in some scenarios and not so obvious in other. For eg: If the customer has many small to medium branch locations with no requirement to VPN to HQ, then Instant managed by Airwave/Athena would make most sense. However, for customers that do need VPN, Instant terminating VPN on MC at HQ will be preferred. Note that as compared to conventional RAP deployment, Instant terminating to the MC creates just one tunnel from VC to MC and not on per IAP basis. And then there will be some customers who want end to end encryption and do not want to extend and manage VLANs at the edge for their branches, who would prefer the branch controller deployment model.
  6. llanges
  7. llanges
  8. Component features: Servers as VPN termination point for each of the branch IAP virtual controllers. VRRP used to provide automatic failover and high availability. Provides enterprise grade branch solution with site survivability, high availability, and zero touch deployment option. Offers intelligent infrastructure and user management with no dependency on WAN link for control traffic. AirWave provides the end-to-end clarity and control to manage mobile users on multi-vendor, multi-site networks. Also provides remote debugging capabilities. The first and only BYOD provisioning and onboarding framework for any network. Delivers unparalleled simplicity when managing and securing network access across wireless, wired and VPNs. The only true BYOD ready, unified wired and wireless access solution for Distributed Enterprises. The key advantages being, SIMPLICITY, RELIABILITY and SECURITY. Aruba Activate for zero touch deployment. Also, security and content filtering services integrated in Instant by partnership with OpenDNS.
  9. llanges
  10. Component features: Servers as VPN termination point for each of the branch IAP virtual controllers. VRRP used to provide automatic failover and high availability. Provides enterprise grade branch solution with site survivability, high availability, and zero touch deployment option. Offers intelligent infrastructure and user management with no dependency on WAN link for control traffic. AirWave provides the end-to-end clarity and control to manage mobile users on multi-vendor, multi-site networks. Also provides remote debugging capabilities. The first and only BYOD provisioning and onboarding framework for any network. Delivers unparalleled simplicity when managing and securing network access across wireless, wired and VPNs. The only true BYOD ready, unified wired and wireless access solution for Distributed Enterprises. The key advantages being, SIMPLICITY, RELIABILITY and SECURITY. Aruba Activate for zero touch deployment. Also, security and content filtering services integrated in Instant by partnership with OpenDNS.
  11. Component features: Servers as VPN termination point for each of the branch IAP virtual controllers. VRRP used to provide automatic failover and high availability. Provides enterprise grade branch solution with site survivability, high availability, and zero touch deployment option. Offers intelligent infrastructure and user management with no dependency on WAN link for control traffic. AirWave provides the end-to-end clarity and control to manage mobile users on multi-vendor, multi-site networks. Also provides remote debugging capabilities. The first and only BYOD provisioning and onboarding framework for any network. Delivers unparalleled simplicity when managing and securing network access across wireless, wired and VPNs. The only true BYOD ready, unified wired and wireless access solution for Distributed Enterprises. The key advantages being, SIMPLICITY, RELIABILITY and SECURITY. Aruba Activate for zero touch deployment. Also, security and content filtering services integrated in Instant by partnership with OpenDNS.
  12. llanges