Delta AP-100 User Manual

Browse online or download User Manual for Air filters Delta AP-100. ap group - Aruba Networks

  • Download
  • Add to my manuals
  • Print
  • Page
    / 126
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews

Summary of Contents

Page 2 - What’s new in 3.1?

Configuration Prior to 3.x• In AOS <3.x, the services over the air from an AP was determined by 2 major groups of settings-• Network wide setting

Page 3 - AP Names & AP Groups

Inter-Controller MobilityMasterLocalLocalLocal1. Client roams to different controller (foreign agent) 2. FA recognizes client3. FA builds tunnel to

Page 4 - • Reception

Mobility Domains• Domains define a boundary for roaming clients• Generally a controller belongs to one domain, although it can belong to more• Doma

Page 5

Mobility DomainsBuilding 2Building 1MasterLocalLocalLocalLocal

Page 6

Mobility DomainDeploying Mobility Over Large Areas AOS 2.xMasterLocalLocalLocalLocalMobility DomainMasterLocalLocalLocalLocalMobility DomainMasterLoca

Page 7 - Web UI Navigation

Deploying Mobility Over Large Areas AOS 3.xMobility DomainMasterLocalLocalLocalLocalMobility DomainMasterLocalLocalLocalLocalMobility DomainMasterLoca

Page 8 - WebUI Navigation

Domains IllustratedDomain 1 Domain 2Roaming within domain allows user to keep IP addresses, authentication, etcWhen roaming between domains, the user

Page 9

Enabling Inter-Controller L3 MobilityEnable L3 MobilityCreate new Mobility Domain (optional)

Page 10 - Configuration Prior to 3.x

Configure Mobility DomainBuild Home Agent Table

Page 11 - Profile Power

MobileIP on a per-VAP basis

Page 13 - Profiles (cont.)

Profile Power• 2.x could only have most settings network-wide:aaa dot1x auth-server foo1• Sets the 802.1x auth server for the entire networkwms asso

Page 14 - Apply Profiles to AP Group

VLAN pooling• For larger deployments, VLAN pooling can be used to maintain small broadcast domains while easing administrator burden of managing many

Page 15 - Configuration - Summary

VLAN pooling cont.• Configuration simply means assigning a range of VLANs to a Virtual AP• Pool can be a comma-delimited list or range (or combination

Page 16 - Licensing Changes

ap group “Building 1”vlan 100-101VLAN PoolingData CenterFirst FloorSecond FloorDHCPE-mail101114Mobility Controllervlan 14: 10.1.14.6/24loopback: 10.1.

Page 18 - New Voice Features

IDS Profiles• IDS settings are now in profiles• A set of default profiles have been created at a variety of levels

Page 19 - Voice Aware 802.1x / 802.11i

ClassificationBACKBONECorporation with Aruba WIPNeighboring Company or Public HotspotParking LotValidInterferingKnown InterferingRogueMobility Control

Page 20 - Voice Aware Mobility

Rogue AP Configuration

Page 22 - WEB UI Support

Troubleshooting and Management Enhancements

Page 23

Manageability - Overview• RF Trouble Shooting• Amazing tools for AP and Device debugging• Antenna Profile – Tells you which antenna transmits/receiv

Page 24

AP Groups and ProfileAP GroupAP GroupWireless LANWireless LANRF ManagementRF ManagementAPAPQoSQoSIDSIDSVirtual APPropertiesVirtual APPropertiesSSIDSSI

Page 25

Antenna Profile Test• This tests if an antenna on an AP is not connected properly or if it is malfunctioning. Packets are sent to a specific target f

Page 26

Antenna Profile Example(Aruba5000-MX25) #rft test profile antenna-connectivity ip-addr 172.16.25.251 dest-mac 00:16:ce:73:b5:37 radio 0Transaction ID:

Page 27

Link Profile Test• This test determines the most suitable data rate for a given target. Packets are sent at different rates to find the optimal rate.

Page 28 - RF Plan, FQLN, and ARM

Link Profile Examplerft test profile link-quality ip-addr 172.16.25.251 dest-mac 00:16:ce:73:b5:37 radio 1Show rft result all(Aruba5000-MX25) #rft te

Page 29 - • ARM updates

Raw Profile Test• This test is effectively a Layer 2 ping.• A fixed number of null data packets are sent to a target and the result of the test is d

Page 30 - APname.Floor.Building.Campus

Raw Profile Example(Aruba5000-MX25) #rft test profile raw ip-addr 172.16.25.251 dest-mac 00:16:ce:73:b5:37 radio 1Transaction ID: 5701(Aruba5000-MX25)

Page 31 - Setting FQLN

CorporateNetworkMobility ControllerMobility ControllerClusterClusterSecuritySecurityApplianceApplianceDataCenterDataDataCenterCenterSyslogSyslog: : Vi

Page 32 - Assign FQLN

Profiles (cont.)

Page 33

Apply Profiles to AP Group

Page 34 - • 4 is highest

Configuration - Summary• What does it all fundamentally mean?• Per SSID/Group Enable/disable auth method• TKIP & AES/ WPA & WPA2 any mix, a

Page 36 - ARM Settings

Licensing changes• 3.1 adds a new “Voice Services” license. • This license adds many new voice- specific features• Voice-aware ARM scanning now req

Page 37 - Firewall Enhancements

New Voice Features• QoS• WMM• TSpec/TCLAS• UAPSD• Bandwidth contracts• Traffic Aware ARM scanning• TSpec/ TCLAS signalling enforcement• WMM vo

Page 38

Voice Aware 802.1x / 802.11i• 802.1x transactions can affect call quality when the device is on call. This feature allows the 802.1x transactions to

Page 39 - Configuration

What’s new in 3.1?• AP Name/AP Group• Profiles• Licensing changes• RF Plan FQLN and location• ARM Enhancements• Firewall Enhancements• Authenti

Page 40 - Troubleshooting

Voice Aware Mobility• Voice Awareness is now also built into the Aruba Mobility algorithm.• When a device on call moves from one controller to anoth

Page 41

Battery Life features • Battery Boost• A wifi client in standby mode needs to wake up on regular interval to check for possible multicast frame. Thi

Page 47

Voice Features: Voice scale and qualityQuality of Service• WMM • WMM EnforcementCall Capacity• T-Spec • Strict accuracyBattery Life• U-APSD / WMM-PS•

Page 48 - MAC Authentication

RF Plan, FQLN, and ARM

Page 49 - MAC Auth Methods

RF Plan changes in 3.1• FQLN• Power level display changes• .11a Channel updates• ARM updates

Page 50 - MAC Auth Profile

AP Names & AP Groups No more B.F.N• AP Config:• AP’s now have a single GROUP• AP’s now have a single NAME• Both are alphanumeric text strings-

Page 51 - Specify Authentication Server

FQLN• Use Fully Qualified Location Name (FQLN) to associate APs and AMs to a location• FQLN Format:APname.Floor.Building.Campus• Used to map AP to

Page 52 - User Derivation Rules

Setting FQLNSelect building and Mapper

Page 53 - User Derivation Rules (cont.)

Assign FQLNDropdown options appear only after Campus, Building and Floor have been createdNote: Setting FQLN reboots APs

Page 54 - Internal Database

FQLN• NOTE: you do not have to use the FQLN mapper if you simply set the AP Name in the AP Installation menu to be the same as the AP Name in RF Plan

Page 55 - Internal Database (continued)

Power Level Adjustment• Aruba radio power levels are adjustable between 0 and 4• 4 is highest• Calibration will automatically set the power level t

Page 56 - Captive Portal

Channel Selection• APs operate most efficiently when they are the only AP on the channel• Calibration will automatically assign channels to each AP

Page 57

ARM Settings

Page 59 - Captive Portal Login

Traffic-Aware ARM scanning• Allows one to configure firewal rules that describe traffic types that should cause ARM to pause scanning on whatever AP

Page 60

Configuration• Configuration examples(config) # ip access-list session mycriticalapp(config-sess) # any any udp <port> permit disable-scanning(

Page 61

The Advantage Of AP-Groups Group the APs by logical function, not by floors• APs are now grouped, however you like- not just by floor e.g• Cubicles•

Page 62 - Create Open SSID

Troubleshooting • The best way to troubleshoot this feature is to look at the session table (“show datapath session table”) and verify that the VOIP

Page 63

Ethertype and MAC FW policies• ArubaOS 3.1 now allows the addition of Ethertype and MAC ACLs to user roles• Simlpy create an Ethertype or MAC ACL an

Page 64 - Customize Captive Portal Page

Per-SSID Bandwidth Contracts• Allocates “air time” to virtual APs on a given physical AP• SSIDs may burst above configured limit as long as other SS

Page 65 - • Aruba supports 2 VPN types

Authentication and Encryption

Page 66 - VPN Configuration Steps

Module Overview• Authentication• SSID• MAC• Captive Portal• VPN• 802.1x• Encryption• Layer 2 vs. Layer 3• Wireless security protocols• WPA•

Page 68 - L2TP Configuration

SSID Authentication• A user can be authenticated simply by associating with a given SSID• A policy is created such that anyone associating with a gi

Page 69 - PPTP Configuration

SSID Authentication Configuration

Page 70 - VPN Dialer

MAC Authentication• A user’s MAC address can be used to establish Identity• However, MAC addresses can be spoofed by an attacker• Useful for device

Page 71 - • EAP-TTLS

MAC Auth Methods• There are 2 different mechanisms for performing MAC Authentication• MAC Auth Profile• User Derivation Rules

Page 72 - Supplicant: client station

AP Name/AP Group• AP Name and AP Group are used to determine what configuration parameters/profiles are pushed to an AP• AP Name must be unique• If

Page 73 - EAP Overview

MAC Auth ProfileFormat sent to serverNone: aabbccddeeffDash: aa-bb-cc-dd-ee-ffColon: aa:bb:cc:dd:ee:ff

Page 74 - EAP Exchange

Specify Authentication Server

Page 75 - 802.1x Process

User Derivation Rules

Page 76 - EAP Flavors

User Derivation Rules (cont.)

Page 77 - EAP Flavors (continued)

Internal Database• Built into the controller• Simple authentication option• Can be used with EAP-offload

Page 78

Internal Database (continued)

Page 79 - 802.1x Configuration

Captive Portal• Web-based authentication method (SSL)• Enabled by default• Typically found in Public Hotspots, Universities• User associates (open

Page 80 - 802.11 a/b/g

Captive Portal Configuration StepsCreate a Server Group.Create CP profileConfigure Auth ServerCreate Initial RoleStep 1: Configure the auth-server (ex

Page 81 - EAP Offload (continued)

Create Captive Portal Profile

Page 82 - Encryption

Captive Portal Login

Page 83 - Configuring 802.1x/802.11i

Profiles & WebUI Navigation

Page 84 - Guest Provisioning

Assign CP Profile to Initial Role

Page 85 - Aruba Guest Provisioning

Define Initial Role in AAA Profile

Page 86

Create Open SSID

Page 87 - Guest Provisioning Interface

Assign SSID and AAA Profiles to VAP

Page 88 - Guest Provisioning cont

Customize Captive Portal Page

Page 89

VPN• Aruba supports 2 VPN types• PPTP (widely supported, Windows, Mac, Unix, PDA)• L2TP over IPSec (Windows 2000 and XP, Mac OSX, Unix)• Protocol

Page 90 - Step 3: Enable DHCP server

VPN Configuration StepsCreate a server group.Configure VPN profileConfigure Auth ServerConfigure VPN settingsStep 1: Configure the external auth-serve

Page 91

VPN ConfigurationSpecify Server group and Default Role

Page 95 - GRE Tunnel

VPN Dialer• Captive Portal may be used for authentication• For Windows users, a ‘dialer’ application may be downloaded directly from the switch foll

Page 96

802.1x• Standard protocol for authenticating user *prior* to granting access to L2 media• Utilizes EAP (Extensible Authentication Protocol)• Evolve

Page 97 - Layer 2 Mobility

EAP DefinitionsSupplicant: client stationAuthenticator: Aruba controllerAuthentication Server: RADIUS Server

Page 98

EAP Overview1. Supplicant communicates with authentication server through the authenticator2. Authenticator reformats 802.1x to RADIUS and forwards

Page 99 - Layer 3 Mobility

EAP ExchangeClientAruba ControllerAuthenticationServerEAP Exchange (Controller used as pass-through doesn’t have to know EAP type)TrustedNetwork802.11

Page 100 - Inter-Controller Mobility

802.1x Process802.1x Access Control – Sequence of eventsClientAuthenticatorAuthentication ServerRequest IdentityResponse Identity (anonymous)Response

Page 101

EAP FlavorsLEAP• Cisco proprietary• Dynamic WEP• Has been broken. Not recommended for current deploymentEAP-TLS (EAP with Transport Layer Security

Page 102 - Mobility Domains

EAP Flavors (continued)EAP-FAST• Cisco proprietary• Uses a PSK in phase 0 to obtain a PAC file, PAC is used as credentials on network• Subject to m

Page 103

Configuring an SSID to use dot1xCreate a server group.Configure dot1x profileConfigure Auth ServerConfigure AAA profileStep 1: Configure the external

Page 104

802.1x ConfigurationSelect Profile and provision 802.1x parameters. Remember to set server group too.

Page 106 - Enable L3 Mobility

EAP-OffloadNASAuthenticationServerEAP Exchange TrustedNetwork802.11 a/b/gSecured LinkClient

Page 109 - VLAN Pooling

Configuring 802.1x/802.11i

Page 110 - VLAN pooling

Guest Provisioning

Page 111 - VLAN pooling cont

Aruba Guest Provisioning• Aruba offers a mechanism for managing guest accounts• A guest provisioning management account presents a security guard or r

Page 112

Create Guest Provisioning Account• Create the admin account to be used by the guard or receptionist to log into the Aruba Controller

Page 113

Guest Provisioning Interface1) Log in to the controller using the Guest Provisioning Account2) Click Add User, enter user info, and click “Apply andPr

Page 114 - IDS Profiles

Guest Provisioning cont.

Page 115 - Classification

Customizing Guest Provisioning

Page 116 - Rogue AP Configuration

Profiles• Profiles are a powerful tool that allow administrators increased flexibility over other configuration methods• All aspects of the configur

Page 117 - Enable Air Monitor

Guest Access Configuration StepsAssign IP addressConfigure DHCP ServerCreate VLANEnable DHCP ServerStep 1: Create user VLAN and assign IP addressStep

Page 118 - Management Enhancements

Captive Portal Configuration StepsCreate a Server Group.Create CP profileConfigure Auth ServerCreate Initial RoleStep 1: Configure the auth-server (ex

Page 119 - • Syslog API

Master-Local and Mobility

Page 120 - Antenna Profile Test

Master-Local IPSec Tunnel• An IPSec Tunnels are automatically created between the Master and each Local for inter-controller communication• Built fr

Page 121 - Antenna Profile Example

Intercontroller IPSec SetupUse default key, or create unique pairs

Page 122 - Link Profile Test

Multi-ControllerMasterLocalLocalAP Group Building 2Local Controller IPAP Group Building 3Local Controller IPGRE TunnelBuilding 1Building 2Building 3

Page 123 - Link Profile Example

Configure APs for Multi-Controller• Point lms-ip to local controllers

Page 124

Layer 2 Mobility141002001410020014, 100, 200VLAN 100 VLAN 100AP Group Building1vlan 100AP Group Building2vlan 200AP Group Building1 AP Group Building2

Page 125 - Raw Profile Example

Enabling Inter-Controller L2 Mobility

Page 126 - Quarantine

Layer 3 Mobility• L3 mobility should be enabled when controllers are separated by an L3 network• Controllers build mobile-IP tunnels to transmit cli

Comments to this Manuals

No comments