aruba - remote branch-networking-fundamentals-2014

42
Remote and Branch Networking Fundamentals June 9-14, 2014

Upload: marcello-marchesini

Post on 14-May-2015

374 views

Category:

Technology


1 download

DESCRIPTION

A clear description of the technical opportunities offered by ARUBA ClearPass, AirWave, Activate and Instant. Another "pearl" from Airheads blog:

TRANSCRIPT

Page 1: ARUBA - Remote Branch-networking-fundamentals-2014

Remote and Branch Networking Fundamentals June 9-14, 2014

Page 2: ARUBA - Remote Branch-networking-fundamentals-2014

CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

2 #AirheadsConf

Agenda

•  Challenges of Deploying Remote networks •  Aruba Solution •  Aruba Instant •  Aruba Instant for Private WAN based Deployments •  Aruba Instant-VPN •  Management and Zero-Touch Deployment

Page 3: ARUBA - Remote Branch-networking-fundamentals-2014

Challenges of Deploying Remote Networks

Page 4: ARUBA - Remote Branch-networking-fundamentals-2014

4 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Who should care?

Branch office / Remote teleworker

Retail

Healthcare

Page 5: ARUBA - Remote Branch-networking-fundamentals-2014

5 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Challenges

Page 6: ARUBA - Remote Branch-networking-fundamentals-2014

Aruba Solution

Page 7: ARUBA - Remote Branch-networking-fundamentals-2014

7 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Aruba Solution

Home Office On The Road Branch

Datacenter

AirWave Aruba Mobility Controller ClearPass Access Management

Instant-VPN

Mobility Switch

Instant Cluster

Virtual Intranet Access (VIA) Client

Internet / WAN

Instant Cluster

Page 8: ARUBA - Remote Branch-networking-fundamentals-2014

Management and Zero-Touch Deployment

Page 9: ARUBA - Remote Branch-networking-fundamentals-2014

9 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Internet

Airwave and Aruba Central

Campus Network

Aruba Central Aruba AirWave

Data Center

•  Advanced  guest  services  

•  Mobile  device  onboarding    

•  Unified  wired/wireless  policy    

Airwave

ClearPass

Mobility Switch

Page 10: ARUBA - Remote Branch-networking-fundamentals-2014

10 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Aruba Activate: Zero-touch Deployment

Page 11: ARUBA - Remote Branch-networking-fundamentals-2014

Aruba Instant

Page 12: ARUBA - Remote Branch-networking-fundamentals-2014

12 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Aruba Instant

•  Redundancy for internal failure

•  Redundancy for external failure

•  Organic growth •  Mobility-ready

•  RF optimization •  Master AP

selection

•  Over-the-air provisioning

•  WiFi oriented configuration

Simple to deploy

Self-optimizing

Self-healing Scalable

Page 13: ARUBA - Remote Branch-networking-fundamentals-2014

13 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Aruba Instant Architecture

•  Distributed data-plane –  Wireless encryption / decryption, firewall

•  Distributed control-plane –  Authentication, DHCP, ARM, WIPS

•  Centralized (local) management-plane –  Configuration, firmware management, GUI, SNMP

Page 14: ARUBA - Remote Branch-networking-fundamentals-2014

14 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Automatic RF Management

Infrastructure control

•  Automatic RF optimization for coverage & capacity

•  Real-time spectrum analysis and interference avoidance

•  Load / Application awareness

•  Self-healing

Channel 11

Channel 6

Channel 1

Client Control

•  Moves clients towards less congested frequency band

•  Distributes clients across available spectrum*

•  Bandwidth controls

Page 15: ARUBA - Remote Branch-networking-fundamentals-2014

15 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Security tailored for Mobility

Context Aware

On-boarding

Role-based access

Policy Enforcement

•  Aruba RFProtect + AirWave RAPIDS •  RF Scanning, Rogue AP detection / containment, Valid-station protection

•  Encryption •  Over-the-air AES encryption, IPSec VPN to datacenter (where applicable)

•  Role-based Access •  Per-user, per-device access

•  Policy Enforcement Firewall •  Segregation of business traffic from guest traffic. •  Blacklisting for session violation

•  Centralized Monitoring and Alerting

Page 16: ARUBA - Remote Branch-networking-fundamentals-2014

16 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

•  No need for separate SSID for QoS.

•  Session based DSCP tagging & prioritization

•  Multicast-to-unicast conversion for video

•  Media-classification for encrypted voice –Apple Facetime

•  AirGroup* to manage Apple AirPlay, AirPrint, etc

Mobility Services: Real-time Applications

ClearPass

IAP

IAP IAP

Page 17: ARUBA - Remote Branch-networking-fundamentals-2014

17 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Mobility Services: Guest Access

•  Securely Manage Visitor Access –  Streamlined workflow; No IT •  Sponsored-based, Visitor Self-Registration, Pre-registration,

Anonymous Guest Access •  3rd Party Integrations

•  APIs for integration with existing applications / CRM tools –  Assignable roles, expiration times, user names, passwords

•  Highest Customization –  Skin technology, software plugins, APIs –  Targeted advertising and content delivery

Page 18: ARUBA - Remote Branch-networking-fundamentals-2014

Private WAN based Deployments

Page 19: ARUBA - Remote Branch-networking-fundamentals-2014

19 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Private-WAN based Deployments

Page 20: ARUBA - Remote Branch-networking-fundamentals-2014

20 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Private-WAN based Deployments

Page 21: ARUBA - Remote Branch-networking-fundamentals-2014

21 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Auto-GRE for Guest

Branch office

Datacenter

AirWave ClearPass

Instant Cluster

VRRP Link

Master Standby

Guest Anchor

Master Active Servers

MPLS

Employee Traffic

Guest Traffic

Page 22: ARUBA - Remote Branch-networking-fundamentals-2014

Aruba Instant-VPN

Page 23: ARUBA - Remote Branch-networking-fundamentals-2014

23 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Datacenter

AirWave/Aruba Central Aruba Mobility Controller ClearPass solution

Internet / WAN

VRRP Link

Master Standby

DMZ

Master Active

Home Office

Instant

Home office Solution

Home Office

Instant

Page 24: ARUBA - Remote Branch-networking-fundamentals-2014

24 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Branch Office Solution

Branch office

Datacenter

AirWave/Aruba Central Aruba Mobility Controller ClearPass solution

Instant Cluster

Internet / WAN

VRRP Link

Master Standby

DMZ

Master Active

Branch office

Instant Cluster

Page 25: ARUBA - Remote Branch-networking-fundamentals-2014

25 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

DHCP - How does Distributed L3 work ?

Network 10.0.0.0/8 VLANs 10 to 99

Data Center

Remote Branch

Internet / WAN

Active VPN Tunnel

Client A Browsing to Intranet

Browsing to Youtube

Route on IAP – For 10.0.0.0/8 network, next hop is VPN terminating controller’s IP address

Master IAP Memeber IAP

Client B Browsing to Intranet

Browsing to Youtube

VLAN 250 IAP-VC is the DHCP Server

DHCP Request

VC SRC NATs traffic using IAPs local IP VC routes the traffic to the tunnel

Intranet

Page 26: ARUBA - Remote Branch-networking-fundamentals-2014

26 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

DHCP - How does Centralized L2 work ?

Network 10.0.0.0/8 VLANs 10 to 99

Data Center

Remote Branch

Internet / WAN

Active VPN Tunnel

Client A Browsing to Intranet

Browsing to Youtube

Route on IAP – For 10.0.0.0/8 network, next hop is VPN terminating controller’s IP address

Master IAP Member IAP

Client B Browsing to Intranet

Browsing to Youtube

VLAN 50

DHCP Request

VC SRC NATs traffic using IAPs local IP VC bridges traffic in the tunnel

VLAN 50 DHCP Server and Default Gateway

Intranet

Page 27: ARUBA - Remote Branch-networking-fundamentals-2014

27 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

DHCP - How does Local Subnet work ?

Intranet

Network 10.0.0.0/8 VLANs 10 to 99

Data Center

Remote Branch

Internet / WAN

Active VPN Tunnel

Client A Browsing to Intranet

Browsing to Youtube

Route on IAP – For 10.0.0.0/8 network, next hop is VPN terminating controller’s IP address

Master IAP Slave IAP

Client B Browsing to Intranet

Browsing to Youtube

VLAN 200 IAP-VC is the DHCP Server

DHCP Request

VC SRC NATs traffic using IAPs local IP VC SRC NATs traffic using inner IP

Page 28: ARUBA - Remote Branch-networking-fundamentals-2014

28 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Recommendations

IAP-VPN Modes  

Usage Recommendations

 

Distributed L3   Recommended for all deployments.  

Local   Recommended for Guest networks with centralized captive portal servers.  

Centralized L2   Recommended only if Multicast to branch is a requirement. If Multicast to branch networks is not required, use L3 modes.  

Page 29: ARUBA - Remote Branch-networking-fundamentals-2014

29 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Branch ID Algorithm

Page 30: ARUBA - Remote Branch-networking-fundamentals-2014

Aruba Instant-VPN Design Options

Page 31: ARUBA - Remote Branch-networking-fundamentals-2014

31 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Single AP deployments

Page 32: ARUBA - Remote Branch-networking-fundamentals-2014

32 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Single AP deployments

Page 33: ARUBA - Remote Branch-networking-fundamentals-2014

33 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Multi-AP deployments

Page 34: ARUBA - Remote Branch-networking-fundamentals-2014

34 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Multi-AP deployments

Page 35: ARUBA - Remote Branch-networking-fundamentals-2014

35 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Thank You

#AirheadsConf

Page 36: ARUBA - Remote Branch-networking-fundamentals-2014

36 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Distributed-L2

Page 37: ARUBA - Remote Branch-networking-fundamentals-2014

37 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Central-L2

Page 38: ARUBA - Remote Branch-networking-fundamentals-2014

38 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Central-L3

Page 39: ARUBA - Remote Branch-networking-fundamentals-2014

39 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Dist-L3

Page 40: ARUBA - Remote Branch-networking-fundamentals-2014

40 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

Local Mode

Page 41: ARUBA - Remote Branch-networking-fundamentals-2014

41 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

#AirheadsConf

DOWNLOAD: Airheads Mobile

JOIN: community.arubanetworks.com

FOLLOW: @arubanetworks

DISCUSS: #AirheadsConf

ATMOSPHERE 2014AIRHEADS@

Page 42: ARUBA - Remote Branch-networking-fundamentals-2014

42 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved

Thank You

#AirheadsConf