Delta AP-100 Manual de usuario

Busca en linea o descarga Manual de usuario para Filtros de aire Delta AP-100. ap group - Aruba Networks Manual de usuario

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 126
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente

Indice de contenidos

Pagina 2 - What’s new in 3.1?

Configuration Prior to 3.x• In AOS <3.x, the services over the air from an AP was determined by 2 major groups of settings-• Network wide setting

Pagina 3 - AP Names & AP Groups

Inter-Controller MobilityMasterLocalLocalLocal1. Client roams to different controller (foreign agent) 2. FA recognizes client3. FA builds tunnel to

Pagina 4 - • Reception

Mobility Domains• Domains define a boundary for roaming clients• Generally a controller belongs to one domain, although it can belong to more• Doma

Pagina 5

Mobility DomainsBuilding 2Building 1MasterLocalLocalLocalLocal

Pagina 6

Mobility DomainDeploying Mobility Over Large Areas AOS 2.xMasterLocalLocalLocalLocalMobility DomainMasterLocalLocalLocalLocalMobility DomainMasterLoca

Pagina 7 - Web UI Navigation

Deploying Mobility Over Large Areas AOS 3.xMobility DomainMasterLocalLocalLocalLocalMobility DomainMasterLocalLocalLocalLocalMobility DomainMasterLoca

Pagina 8 - WebUI Navigation

Domains IllustratedDomain 1 Domain 2Roaming within domain allows user to keep IP addresses, authentication, etcWhen roaming between domains, the user

Pagina 9

Enabling Inter-Controller L3 MobilityEnable L3 MobilityCreate new Mobility Domain (optional)

Pagina 10 - Configuration Prior to 3.x

Configure Mobility DomainBuild Home Agent Table

Pagina 11 - Profile Power

MobileIP on a per-VAP basis

Pagina 13 - Profiles (cont.)

Profile Power• 2.x could only have most settings network-wide:aaa dot1x auth-server foo1• Sets the 802.1x auth server for the entire networkwms asso

Pagina 14 - Apply Profiles to AP Group

VLAN pooling• For larger deployments, VLAN pooling can be used to maintain small broadcast domains while easing administrator burden of managing many

Pagina 15 - Configuration - Summary

VLAN pooling cont.• Configuration simply means assigning a range of VLANs to a Virtual AP• Pool can be a comma-delimited list or range (or combination

Pagina 16 - Licensing Changes

ap group “Building 1”vlan 100-101VLAN PoolingData CenterFirst FloorSecond FloorDHCPE-mail101114Mobility Controllervlan 14: 10.1.14.6/24loopback: 10.1.

Pagina 18 - New Voice Features

IDS Profiles• IDS settings are now in profiles• A set of default profiles have been created at a variety of levels

Pagina 19 - Voice Aware 802.1x / 802.11i

ClassificationBACKBONECorporation with Aruba WIPNeighboring Company or Public HotspotParking LotValidInterferingKnown InterferingRogueMobility Control

Pagina 20 - Voice Aware Mobility

Rogue AP Configuration

Pagina 22 - WEB UI Support

Troubleshooting and Management Enhancements

Pagina 23

Manageability - Overview• RF Trouble Shooting• Amazing tools for AP and Device debugging• Antenna Profile – Tells you which antenna transmits/receiv

Pagina 24

AP Groups and ProfileAP GroupAP GroupWireless LANWireless LANRF ManagementRF ManagementAPAPQoSQoSIDSIDSVirtual APPropertiesVirtual APPropertiesSSIDSSI

Pagina 25

Antenna Profile Test• This tests if an antenna on an AP is not connected properly or if it is malfunctioning. Packets are sent to a specific target f

Pagina 26

Antenna Profile Example(Aruba5000-MX25) #rft test profile antenna-connectivity ip-addr 172.16.25.251 dest-mac 00:16:ce:73:b5:37 radio 0Transaction ID:

Pagina 27

Link Profile Test• This test determines the most suitable data rate for a given target. Packets are sent at different rates to find the optimal rate.

Pagina 28 - RF Plan, FQLN, and ARM

Link Profile Examplerft test profile link-quality ip-addr 172.16.25.251 dest-mac 00:16:ce:73:b5:37 radio 1Show rft result all(Aruba5000-MX25) #rft te

Pagina 29 - • ARM updates

Raw Profile Test• This test is effectively a Layer 2 ping.• A fixed number of null data packets are sent to a target and the result of the test is d

Pagina 30 - APname.Floor.Building.Campus

Raw Profile Example(Aruba5000-MX25) #rft test profile raw ip-addr 172.16.25.251 dest-mac 00:16:ce:73:b5:37 radio 1Transaction ID: 5701(Aruba5000-MX25)

Pagina 31 - Setting FQLN

CorporateNetworkMobility ControllerMobility ControllerClusterClusterSecuritySecurityApplianceApplianceDataCenterDataDataCenterCenterSyslogSyslog: : Vi

Pagina 32 - Assign FQLN

Profiles (cont.)

Pagina 33

Apply Profiles to AP Group

Pagina 34 - • 4 is highest

Configuration - Summary• What does it all fundamentally mean?• Per SSID/Group Enable/disable auth method• TKIP & AES/ WPA & WPA2 any mix, a

Pagina 36 - ARM Settings

Licensing changes• 3.1 adds a new “Voice Services” license. • This license adds many new voice- specific features• Voice-aware ARM scanning now req

Pagina 37 - Firewall Enhancements

New Voice Features• QoS• WMM• TSpec/TCLAS• UAPSD• Bandwidth contracts• Traffic Aware ARM scanning• TSpec/ TCLAS signalling enforcement• WMM vo

Pagina 38

Voice Aware 802.1x / 802.11i• 802.1x transactions can affect call quality when the device is on call. This feature allows the 802.1x transactions to

Pagina 39 - Configuration

What’s new in 3.1?• AP Name/AP Group• Profiles• Licensing changes• RF Plan FQLN and location• ARM Enhancements• Firewall Enhancements• Authenti

Pagina 40 - Troubleshooting

Voice Aware Mobility• Voice Awareness is now also built into the Aruba Mobility algorithm.• When a device on call moves from one controller to anoth

Pagina 41

Battery Life features • Battery Boost• A wifi client in standby mode needs to wake up on regular interval to check for possible multicast frame. Thi

Pagina 47

Voice Features: Voice scale and qualityQuality of Service• WMM • WMM EnforcementCall Capacity• T-Spec • Strict accuracyBattery Life• U-APSD / WMM-PS•

Pagina 48 - MAC Authentication

RF Plan, FQLN, and ARM

Pagina 49 - MAC Auth Methods

RF Plan changes in 3.1• FQLN• Power level display changes• .11a Channel updates• ARM updates

Pagina 50 - MAC Auth Profile

AP Names & AP Groups No more B.F.N• AP Config:• AP’s now have a single GROUP• AP’s now have a single NAME• Both are alphanumeric text strings-

Pagina 51 - Specify Authentication Server

FQLN• Use Fully Qualified Location Name (FQLN) to associate APs and AMs to a location• FQLN Format:APname.Floor.Building.Campus• Used to map AP to

Pagina 52 - User Derivation Rules

Setting FQLNSelect building and Mapper

Pagina 53 - User Derivation Rules (cont.)

Assign FQLNDropdown options appear only after Campus, Building and Floor have been createdNote: Setting FQLN reboots APs

Pagina 54 - Internal Database

FQLN• NOTE: you do not have to use the FQLN mapper if you simply set the AP Name in the AP Installation menu to be the same as the AP Name in RF Plan

Pagina 55 - Internal Database (continued)

Power Level Adjustment• Aruba radio power levels are adjustable between 0 and 4• 4 is highest• Calibration will automatically set the power level t

Pagina 56 - Captive Portal

Channel Selection• APs operate most efficiently when they are the only AP on the channel• Calibration will automatically assign channels to each AP

Pagina 57

ARM Settings

Pagina 59 - Captive Portal Login

Traffic-Aware ARM scanning• Allows one to configure firewal rules that describe traffic types that should cause ARM to pause scanning on whatever AP

Pagina 60

Configuration• Configuration examples(config) # ip access-list session mycriticalapp(config-sess) # any any udp <port> permit disable-scanning(

Pagina 61

The Advantage Of AP-Groups Group the APs by logical function, not by floors• APs are now grouped, however you like- not just by floor e.g• Cubicles•

Pagina 62 - Create Open SSID

Troubleshooting • The best way to troubleshoot this feature is to look at the session table (“show datapath session table”) and verify that the VOIP

Pagina 63

Ethertype and MAC FW policies• ArubaOS 3.1 now allows the addition of Ethertype and MAC ACLs to user roles• Simlpy create an Ethertype or MAC ACL an

Pagina 64 - Customize Captive Portal Page

Per-SSID Bandwidth Contracts• Allocates “air time” to virtual APs on a given physical AP• SSIDs may burst above configured limit as long as other SS

Pagina 65 - • Aruba supports 2 VPN types

Authentication and Encryption

Pagina 66 - VPN Configuration Steps

Module Overview• Authentication• SSID• MAC• Captive Portal• VPN• 802.1x• Encryption• Layer 2 vs. Layer 3• Wireless security protocols• WPA•

Pagina 68 - L2TP Configuration

SSID Authentication• A user can be authenticated simply by associating with a given SSID• A policy is created such that anyone associating with a gi

Pagina 69 - PPTP Configuration

SSID Authentication Configuration

Pagina 70 - VPN Dialer

MAC Authentication• A user’s MAC address can be used to establish Identity• However, MAC addresses can be spoofed by an attacker• Useful for device

Pagina 71 - • EAP-TTLS

MAC Auth Methods• There are 2 different mechanisms for performing MAC Authentication• MAC Auth Profile• User Derivation Rules

Pagina 72 - Supplicant: client station

AP Name/AP Group• AP Name and AP Group are used to determine what configuration parameters/profiles are pushed to an AP• AP Name must be unique• If

Pagina 73 - EAP Overview

MAC Auth ProfileFormat sent to serverNone: aabbccddeeffDash: aa-bb-cc-dd-ee-ffColon: aa:bb:cc:dd:ee:ff

Pagina 74 - EAP Exchange

Specify Authentication Server

Pagina 75 - 802.1x Process

User Derivation Rules

Pagina 76 - EAP Flavors

User Derivation Rules (cont.)

Pagina 77 - EAP Flavors (continued)

Internal Database• Built into the controller• Simple authentication option• Can be used with EAP-offload

Pagina 78

Internal Database (continued)

Pagina 79 - 802.1x Configuration

Captive Portal• Web-based authentication method (SSL)• Enabled by default• Typically found in Public Hotspots, Universities• User associates (open

Pagina 80 - 802.11 a/b/g

Captive Portal Configuration StepsCreate a Server Group.Create CP profileConfigure Auth ServerCreate Initial RoleStep 1: Configure the auth-server (ex

Pagina 81 - EAP Offload (continued)

Create Captive Portal Profile

Pagina 82 - Encryption

Captive Portal Login

Pagina 83 - Configuring 802.1x/802.11i

Profiles & WebUI Navigation

Pagina 84 - Guest Provisioning

Assign CP Profile to Initial Role

Pagina 85 - Aruba Guest Provisioning

Define Initial Role in AAA Profile

Pagina 86

Create Open SSID

Pagina 87 - Guest Provisioning Interface

Assign SSID and AAA Profiles to VAP

Pagina 88 - Guest Provisioning cont

Customize Captive Portal Page

Pagina 89

VPN• Aruba supports 2 VPN types• PPTP (widely supported, Windows, Mac, Unix, PDA)• L2TP over IPSec (Windows 2000 and XP, Mac OSX, Unix)• Protocol

Pagina 90 - Step 3: Enable DHCP server

VPN Configuration StepsCreate a server group.Configure VPN profileConfigure Auth ServerConfigure VPN settingsStep 1: Configure the external auth-serve

Pagina 91

VPN ConfigurationSpecify Server group and Default Role

Pagina 95 - GRE Tunnel

VPN Dialer• Captive Portal may be used for authentication• For Windows users, a ‘dialer’ application may be downloaded directly from the switch foll

Pagina 96

802.1x• Standard protocol for authenticating user *prior* to granting access to L2 media• Utilizes EAP (Extensible Authentication Protocol)• Evolve

Pagina 97 - Layer 2 Mobility

EAP DefinitionsSupplicant: client stationAuthenticator: Aruba controllerAuthentication Server: RADIUS Server

Pagina 98

EAP Overview1. Supplicant communicates with authentication server through the authenticator2. Authenticator reformats 802.1x to RADIUS and forwards

Pagina 99 - Layer 3 Mobility

EAP ExchangeClientAruba ControllerAuthenticationServerEAP Exchange (Controller used as pass-through doesn’t have to know EAP type)TrustedNetwork802.11

Pagina 100 - Inter-Controller Mobility

802.1x Process802.1x Access Control – Sequence of eventsClientAuthenticatorAuthentication ServerRequest IdentityResponse Identity (anonymous)Response

Pagina 101

EAP FlavorsLEAP• Cisco proprietary• Dynamic WEP• Has been broken. Not recommended for current deploymentEAP-TLS (EAP with Transport Layer Security

Pagina 102 - Mobility Domains

EAP Flavors (continued)EAP-FAST• Cisco proprietary• Uses a PSK in phase 0 to obtain a PAC file, PAC is used as credentials on network• Subject to m

Pagina 103

Configuring an SSID to use dot1xCreate a server group.Configure dot1x profileConfigure Auth ServerConfigure AAA profileStep 1: Configure the external

Pagina 104

802.1x ConfigurationSelect Profile and provision 802.1x parameters. Remember to set server group too.

Pagina 106 - Enable L3 Mobility

EAP-OffloadNASAuthenticationServerEAP Exchange TrustedNetwork802.11 a/b/gSecured LinkClient

Pagina 109 - VLAN Pooling

Configuring 802.1x/802.11i

Pagina 110 - VLAN pooling

Guest Provisioning

Pagina 111 - VLAN pooling cont

Aruba Guest Provisioning• Aruba offers a mechanism for managing guest accounts• A guest provisioning management account presents a security guard or r

Pagina 112

Create Guest Provisioning Account• Create the admin account to be used by the guard or receptionist to log into the Aruba Controller

Pagina 113

Guest Provisioning Interface1) Log in to the controller using the Guest Provisioning Account2) Click Add User, enter user info, and click “Apply andPr

Pagina 114 - IDS Profiles

Guest Provisioning cont.

Pagina 115 - Classification

Customizing Guest Provisioning

Pagina 116 - Rogue AP Configuration

Profiles• Profiles are a powerful tool that allow administrators increased flexibility over other configuration methods• All aspects of the configur

Pagina 117 - Enable Air Monitor

Guest Access Configuration StepsAssign IP addressConfigure DHCP ServerCreate VLANEnable DHCP ServerStep 1: Create user VLAN and assign IP addressStep

Pagina 118 - Management Enhancements

Captive Portal Configuration StepsCreate a Server Group.Create CP profileConfigure Auth ServerCreate Initial RoleStep 1: Configure the auth-server (ex

Pagina 119 - • Syslog API

Master-Local and Mobility

Pagina 120 - Antenna Profile Test

Master-Local IPSec Tunnel• An IPSec Tunnels are automatically created between the Master and each Local for inter-controller communication• Built fr

Pagina 121 - Antenna Profile Example

Intercontroller IPSec SetupUse default key, or create unique pairs

Pagina 122 - Link Profile Test

Multi-ControllerMasterLocalLocalAP Group Building 2Local Controller IPAP Group Building 3Local Controller IPGRE TunnelBuilding 1Building 2Building 3

Pagina 123 - Link Profile Example

Configure APs for Multi-Controller• Point lms-ip to local controllers

Pagina 124

Layer 2 Mobility141002001410020014, 100, 200VLAN 100 VLAN 100AP Group Building1vlan 100AP Group Building2vlan 200AP Group Building1 AP Group Building2

Pagina 125 - Raw Profile Example

Enabling Inter-Controller L2 Mobility

Pagina 126 - Quarantine

Layer 3 Mobility• L3 mobility should be enabled when controllers are separated by an L3 network• Controllers build mobile-IP tunnels to transmit cli

Comentarios a estos manuales

Sin comentarios