Delta AP-100 Uživatelský manuál

Procházejte online nebo si stáhněte Uživatelský manuál pro Vzduchové filtry Delta AP-100. ap group - Aruba Networks Uživatelská příručka

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 126
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků

Shrnutí obsahu

Strany 2 - What’s new in 3.1?

Configuration Prior to 3.x• In AOS <3.x, the services over the air from an AP was determined by 2 major groups of settings-• Network wide setting

Strany 3 - AP Names & AP Groups

Inter-Controller MobilityMasterLocalLocalLocal1. Client roams to different controller (foreign agent) 2. FA recognizes client3. FA builds tunnel to

Strany 4 - • Reception

Mobility Domains• Domains define a boundary for roaming clients• Generally a controller belongs to one domain, although it can belong to more• Doma

Strany 5

Mobility DomainsBuilding 2Building 1MasterLocalLocalLocalLocal

Strany 6

Mobility DomainDeploying Mobility Over Large Areas AOS 2.xMasterLocalLocalLocalLocalMobility DomainMasterLocalLocalLocalLocalMobility DomainMasterLoca

Strany 7 - Web UI Navigation

Deploying Mobility Over Large Areas AOS 3.xMobility DomainMasterLocalLocalLocalLocalMobility DomainMasterLocalLocalLocalLocalMobility DomainMasterLoca

Strany 8 - WebUI Navigation

Domains IllustratedDomain 1 Domain 2Roaming within domain allows user to keep IP addresses, authentication, etcWhen roaming between domains, the user

Strany 9

Enabling Inter-Controller L3 MobilityEnable L3 MobilityCreate new Mobility Domain (optional)

Strany 10 - Configuration Prior to 3.x

Configure Mobility DomainBuild Home Agent Table

Strany 11 - Profile Power

MobileIP on a per-VAP basis

Strany 13 - Profiles (cont.)

Profile Power• 2.x could only have most settings network-wide:aaa dot1x auth-server foo1• Sets the 802.1x auth server for the entire networkwms asso

Strany 14 - Apply Profiles to AP Group

VLAN pooling• For larger deployments, VLAN pooling can be used to maintain small broadcast domains while easing administrator burden of managing many

Strany 15 - Configuration - Summary

VLAN pooling cont.• Configuration simply means assigning a range of VLANs to a Virtual AP• Pool can be a comma-delimited list or range (or combination

Strany 16 - Licensing Changes

ap group “Building 1”vlan 100-101VLAN PoolingData CenterFirst FloorSecond FloorDHCPE-mail101114Mobility Controllervlan 14: 10.1.14.6/24loopback: 10.1.

Strany 18 - New Voice Features

IDS Profiles• IDS settings are now in profiles• A set of default profiles have been created at a variety of levels

Strany 19 - Voice Aware 802.1x / 802.11i

ClassificationBACKBONECorporation with Aruba WIPNeighboring Company or Public HotspotParking LotValidInterferingKnown InterferingRogueMobility Control

Strany 20 - Voice Aware Mobility

Rogue AP Configuration

Strany 22 - WEB UI Support

Troubleshooting and Management Enhancements

Strany 23

Manageability - Overview• RF Trouble Shooting• Amazing tools for AP and Device debugging• Antenna Profile – Tells you which antenna transmits/receiv

Strany 24

AP Groups and ProfileAP GroupAP GroupWireless LANWireless LANRF ManagementRF ManagementAPAPQoSQoSIDSIDSVirtual APPropertiesVirtual APPropertiesSSIDSSI

Strany 25

Antenna Profile Test• This tests if an antenna on an AP is not connected properly or if it is malfunctioning. Packets are sent to a specific target f

Strany 26

Antenna Profile Example(Aruba5000-MX25) #rft test profile antenna-connectivity ip-addr 172.16.25.251 dest-mac 00:16:ce:73:b5:37 radio 0Transaction ID:

Strany 27

Link Profile Test• This test determines the most suitable data rate for a given target. Packets are sent at different rates to find the optimal rate.

Strany 28 - RF Plan, FQLN, and ARM

Link Profile Examplerft test profile link-quality ip-addr 172.16.25.251 dest-mac 00:16:ce:73:b5:37 radio 1Show rft result all(Aruba5000-MX25) #rft te

Strany 29 - • ARM updates

Raw Profile Test• This test is effectively a Layer 2 ping.• A fixed number of null data packets are sent to a target and the result of the test is d

Strany 30 - APname.Floor.Building.Campus

Raw Profile Example(Aruba5000-MX25) #rft test profile raw ip-addr 172.16.25.251 dest-mac 00:16:ce:73:b5:37 radio 1Transaction ID: 5701(Aruba5000-MX25)

Strany 31 - Setting FQLN

CorporateNetworkMobility ControllerMobility ControllerClusterClusterSecuritySecurityApplianceApplianceDataCenterDataDataCenterCenterSyslogSyslog: : Vi

Strany 32 - Assign FQLN

Profiles (cont.)

Strany 33

Apply Profiles to AP Group

Strany 34 - • 4 is highest

Configuration - Summary• What does it all fundamentally mean?• Per SSID/Group Enable/disable auth method• TKIP & AES/ WPA & WPA2 any mix, a

Strany 36 - ARM Settings

Licensing changes• 3.1 adds a new “Voice Services” license. • This license adds many new voice- specific features• Voice-aware ARM scanning now req

Strany 37 - Firewall Enhancements

New Voice Features• QoS• WMM• TSpec/TCLAS• UAPSD• Bandwidth contracts• Traffic Aware ARM scanning• TSpec/ TCLAS signalling enforcement• WMM vo

Strany 38

Voice Aware 802.1x / 802.11i• 802.1x transactions can affect call quality when the device is on call. This feature allows the 802.1x transactions to

Strany 39 - Configuration

What’s new in 3.1?• AP Name/AP Group• Profiles• Licensing changes• RF Plan FQLN and location• ARM Enhancements• Firewall Enhancements• Authenti

Strany 40 - Troubleshooting

Voice Aware Mobility• Voice Awareness is now also built into the Aruba Mobility algorithm.• When a device on call moves from one controller to anoth

Strany 41

Battery Life features • Battery Boost• A wifi client in standby mode needs to wake up on regular interval to check for possible multicast frame. Thi

Strany 47

Voice Features: Voice scale and qualityQuality of Service• WMM • WMM EnforcementCall Capacity• T-Spec • Strict accuracyBattery Life• U-APSD / WMM-PS•

Strany 48 - MAC Authentication

RF Plan, FQLN, and ARM

Strany 49 - MAC Auth Methods

RF Plan changes in 3.1• FQLN• Power level display changes• .11a Channel updates• ARM updates

Strany 50 - MAC Auth Profile

AP Names & AP Groups No more B.F.N• AP Config:• AP’s now have a single GROUP• AP’s now have a single NAME• Both are alphanumeric text strings-

Strany 51 - Specify Authentication Server

FQLN• Use Fully Qualified Location Name (FQLN) to associate APs and AMs to a location• FQLN Format:APname.Floor.Building.Campus• Used to map AP to

Strany 52 - User Derivation Rules

Setting FQLNSelect building and Mapper

Strany 53 - User Derivation Rules (cont.)

Assign FQLNDropdown options appear only after Campus, Building and Floor have been createdNote: Setting FQLN reboots APs

Strany 54 - Internal Database

FQLN• NOTE: you do not have to use the FQLN mapper if you simply set the AP Name in the AP Installation menu to be the same as the AP Name in RF Plan

Strany 55 - Internal Database (continued)

Power Level Adjustment• Aruba radio power levels are adjustable between 0 and 4• 4 is highest• Calibration will automatically set the power level t

Strany 56 - Captive Portal

Channel Selection• APs operate most efficiently when they are the only AP on the channel• Calibration will automatically assign channels to each AP

Strany 57

ARM Settings

Strany 59 - Captive Portal Login

Traffic-Aware ARM scanning• Allows one to configure firewal rules that describe traffic types that should cause ARM to pause scanning on whatever AP

Strany 60

Configuration• Configuration examples(config) # ip access-list session mycriticalapp(config-sess) # any any udp <port> permit disable-scanning(

Strany 61

The Advantage Of AP-Groups Group the APs by logical function, not by floors• APs are now grouped, however you like- not just by floor e.g• Cubicles•

Strany 62 - Create Open SSID

Troubleshooting • The best way to troubleshoot this feature is to look at the session table (“show datapath session table”) and verify that the VOIP

Strany 63

Ethertype and MAC FW policies• ArubaOS 3.1 now allows the addition of Ethertype and MAC ACLs to user roles• Simlpy create an Ethertype or MAC ACL an

Strany 64 - Customize Captive Portal Page

Per-SSID Bandwidth Contracts• Allocates “air time” to virtual APs on a given physical AP• SSIDs may burst above configured limit as long as other SS

Strany 65 - • Aruba supports 2 VPN types

Authentication and Encryption

Strany 66 - VPN Configuration Steps

Module Overview• Authentication• SSID• MAC• Captive Portal• VPN• 802.1x• Encryption• Layer 2 vs. Layer 3• Wireless security protocols• WPA•

Strany 68 - L2TP Configuration

SSID Authentication• A user can be authenticated simply by associating with a given SSID• A policy is created such that anyone associating with a gi

Strany 69 - PPTP Configuration

SSID Authentication Configuration

Strany 70 - VPN Dialer

MAC Authentication• A user’s MAC address can be used to establish Identity• However, MAC addresses can be spoofed by an attacker• Useful for device

Strany 71 - • EAP-TTLS

MAC Auth Methods• There are 2 different mechanisms for performing MAC Authentication• MAC Auth Profile• User Derivation Rules

Strany 72 - Supplicant: client station

AP Name/AP Group• AP Name and AP Group are used to determine what configuration parameters/profiles are pushed to an AP• AP Name must be unique• If

Strany 73 - EAP Overview

MAC Auth ProfileFormat sent to serverNone: aabbccddeeffDash: aa-bb-cc-dd-ee-ffColon: aa:bb:cc:dd:ee:ff

Strany 74 - EAP Exchange

Specify Authentication Server

Strany 75 - 802.1x Process

User Derivation Rules

Strany 76 - EAP Flavors

User Derivation Rules (cont.)

Strany 77 - EAP Flavors (continued)

Internal Database• Built into the controller• Simple authentication option• Can be used with EAP-offload

Strany 78

Internal Database (continued)

Strany 79 - 802.1x Configuration

Captive Portal• Web-based authentication method (SSL)• Enabled by default• Typically found in Public Hotspots, Universities• User associates (open

Strany 80 - 802.11 a/b/g

Captive Portal Configuration StepsCreate a Server Group.Create CP profileConfigure Auth ServerCreate Initial RoleStep 1: Configure the auth-server (ex

Strany 81 - EAP Offload (continued)

Create Captive Portal Profile

Strany 82 - Encryption

Captive Portal Login

Strany 83 - Configuring 802.1x/802.11i

Profiles & WebUI Navigation

Strany 84 - Guest Provisioning

Assign CP Profile to Initial Role

Strany 85 - Aruba Guest Provisioning

Define Initial Role in AAA Profile

Strany 86

Create Open SSID

Strany 87 - Guest Provisioning Interface

Assign SSID and AAA Profiles to VAP

Strany 88 - Guest Provisioning cont

Customize Captive Portal Page

Strany 89

VPN• Aruba supports 2 VPN types• PPTP (widely supported, Windows, Mac, Unix, PDA)• L2TP over IPSec (Windows 2000 and XP, Mac OSX, Unix)• Protocol

Strany 90 - Step 3: Enable DHCP server

VPN Configuration StepsCreate a server group.Configure VPN profileConfigure Auth ServerConfigure VPN settingsStep 1: Configure the external auth-serve

Strany 91

VPN ConfigurationSpecify Server group and Default Role

Strany 95 - GRE Tunnel

VPN Dialer• Captive Portal may be used for authentication• For Windows users, a ‘dialer’ application may be downloaded directly from the switch foll

Strany 96

802.1x• Standard protocol for authenticating user *prior* to granting access to L2 media• Utilizes EAP (Extensible Authentication Protocol)• Evolve

Strany 97 - Layer 2 Mobility

EAP DefinitionsSupplicant: client stationAuthenticator: Aruba controllerAuthentication Server: RADIUS Server

Strany 98

EAP Overview1. Supplicant communicates with authentication server through the authenticator2. Authenticator reformats 802.1x to RADIUS and forwards

Strany 99 - Layer 3 Mobility

EAP ExchangeClientAruba ControllerAuthenticationServerEAP Exchange (Controller used as pass-through doesn’t have to know EAP type)TrustedNetwork802.11

Strany 100 - Inter-Controller Mobility

802.1x Process802.1x Access Control – Sequence of eventsClientAuthenticatorAuthentication ServerRequest IdentityResponse Identity (anonymous)Response

Strany 101

EAP FlavorsLEAP• Cisco proprietary• Dynamic WEP• Has been broken. Not recommended for current deploymentEAP-TLS (EAP with Transport Layer Security

Strany 102 - Mobility Domains

EAP Flavors (continued)EAP-FAST• Cisco proprietary• Uses a PSK in phase 0 to obtain a PAC file, PAC is used as credentials on network• Subject to m

Strany 103

Configuring an SSID to use dot1xCreate a server group.Configure dot1x profileConfigure Auth ServerConfigure AAA profileStep 1: Configure the external

Strany 104

802.1x ConfigurationSelect Profile and provision 802.1x parameters. Remember to set server group too.

Strany 106 - Enable L3 Mobility

EAP-OffloadNASAuthenticationServerEAP Exchange TrustedNetwork802.11 a/b/gSecured LinkClient

Strany 109 - VLAN Pooling

Configuring 802.1x/802.11i

Strany 110 - VLAN pooling

Guest Provisioning

Strany 111 - VLAN pooling cont

Aruba Guest Provisioning• Aruba offers a mechanism for managing guest accounts• A guest provisioning management account presents a security guard or r

Strany 112

Create Guest Provisioning Account• Create the admin account to be used by the guard or receptionist to log into the Aruba Controller

Strany 113

Guest Provisioning Interface1) Log in to the controller using the Guest Provisioning Account2) Click Add User, enter user info, and click “Apply andPr

Strany 114 - IDS Profiles

Guest Provisioning cont.

Strany 115 - Classification

Customizing Guest Provisioning

Strany 116 - Rogue AP Configuration

Profiles• Profiles are a powerful tool that allow administrators increased flexibility over other configuration methods• All aspects of the configur

Strany 117 - Enable Air Monitor

Guest Access Configuration StepsAssign IP addressConfigure DHCP ServerCreate VLANEnable DHCP ServerStep 1: Create user VLAN and assign IP addressStep

Strany 118 - Management Enhancements

Captive Portal Configuration StepsCreate a Server Group.Create CP profileConfigure Auth ServerCreate Initial RoleStep 1: Configure the auth-server (ex

Strany 119 - • Syslog API

Master-Local and Mobility

Strany 120 - Antenna Profile Test

Master-Local IPSec Tunnel• An IPSec Tunnels are automatically created between the Master and each Local for inter-controller communication• Built fr

Strany 121 - Antenna Profile Example

Intercontroller IPSec SetupUse default key, or create unique pairs

Strany 122 - Link Profile Test

Multi-ControllerMasterLocalLocalAP Group Building 2Local Controller IPAP Group Building 3Local Controller IPGRE TunnelBuilding 1Building 2Building 3

Strany 123 - Link Profile Example

Configure APs for Multi-Controller• Point lms-ip to local controllers

Strany 124

Layer 2 Mobility141002001410020014, 100, 200VLAN 100 VLAN 100AP Group Building1vlan 100AP Group Building2vlan 200AP Group Building1 AP Group Building2

Strany 125 - Raw Profile Example

Enabling Inter-Controller L2 Mobility

Strany 126 - Quarantine

Layer 3 Mobility• L3 mobility should be enabled when controllers are separated by an L3 network• Controllers build mobile-IP tunnels to transmit cli

Komentáře k této Příručce

Žádné komentáře