This solution is fully reproducible and has been deployed in live environments.

Size: px
Start display at page:

Download "This solution is fully reproducible and has been deployed in live environments."

Transcription

1 Introduction On many occasions there is a customer requirement to provide a simple guest-only wireless solution, and rightly or wrongly, it has been decided that this network should be completely segregated from the existing corporate network. Whilst the Aruba Instant AP solution is the logical and economical solution to this, the internal captive portal on the IAP is unacceptable in look and feel for many customers, and does not provide the professional captive portal that they may want. Another alternative is to use the Clearpass Guest solution to provide a rich and highly customisable captive portal page. However, given that these solutions are on separate and new networks, the provision of an additional server to host the Clearpass VM in addition to the licencing costs makes this solution uneconomical. The inbuilt controller captive portal, whilst not as feature rich as Clearpass, is professional enough for many guest-only requirements. However, with the addition of AP and PEFNG licences for each AP, this can also cause this campus based solution uneconomical compared to other vendors. Solution The following was developed to specifically address the needs of a guest-only design, whilst still providing a professional looking captive portal page. The method outlined below makes use of the Aruba Instant VPN tunnel feature to an Aruba controller. This has the advantage of not requiring licences on the controller for each AP, but in fact only needs 1 x PEFNG licence, making this solution very economical compared to a normal campus controller based solution and IAP with Clearpass, and makes it very competitive compared to other vendors. This solution is fully reproducible and has been deployed in live environments. Although the features used herein are fully supported, TAC may initially have some trouble getting their head around this, as it is an uncommon use of such features. This setup is primarily for a guest only solution. It is possible to configure this for additional dot1x ssids, but this is not recommended. All traffic also must flow through the controller. Due to the nature of how captive portal works, it is not possible to break the traffic out locally after authentication. Although redundancy is not considered here, it may be possible with the new automatic GRE creation feature on AOS 6.4 and IAP This is outlined in section 1.8

2 1.1 Hardware The Aps are the Aruba Instant version and don t terminate on the controller, so it is possible to have many more Aps in the solution than would otherwise be possible with Campus Aps. You must however ensure that your solution is scaled properly, in particular taking note of the following parameters. Max users Max bssids (tunnels) XM 3400 Users bssids (tunnels) NOTE: 3000 series controllers are only able to have a total dhcp scope size of 512. If you expect more than 512 users, use an external dhcp server or the firewall. 1.2 Software The following versions were used for this demonstration. AOS IAP OS Previous testing/deployment was also done with AOS 6.2.x. NOTE: The 600 series controllers are not mentioned in the AOS 6.3 User Guide, Table 215, IAP-VPN Scalability. Although, this is a fully working solution, there is no guarantee that support for this model will not be removed.

3 1.3 Topology The following diagram shows the logical and physical layout of the IAP-Guest-tunnel solution. The subnet for the IAPs must NOT exist on the controller. All user traffic is tunnelled to the controller and treated as wired users. 1.4 Configuration The following outlines the steps necessary to complete the configuration Controller configuration

4 Setup ip addressing on controller with default gateway to point to the internet firewall. User subnets should be isolated on the controller with ip nat inside. Ensure the IAP subnet does NOT exist on the controller. Setup DHCP scope for users on controller or external DHCP server as appropriate. Install 1 x PEFNG licence on controller. Create a server certificate for the controller. The default cannot be used, because the IAP will also intercept the traffic and the internal IAP portal will be displayed after the controller portal. Setup tunnel configuration so that a tunnel is created to each IAP. Setup the authenticated guest role.

5 Setup captive portal profile and assign the default role created above. Setup logon role and assign captive portal profile created above. Setup aaa-profile with initial role to be the logon role created above. Create and assign user derivation rules, if it is a requirement to have certain devices bypass the captive portal.

6 Assign this aaa-profile for wired authentication IAP Configuration Configure ssid with type of corporate. Configure ssid vlan to be that configured on controller, in this case vlan 12.

7 Configure ssid security and access to be open and no restrictions respectively. Note, it is probably recommended to set the access rules, but this will also be handled by the controller. Configure the IAP DHCP scope as centralised L2.

8 Add the VPN configuration as such. The routing profile needs to point all traffic into the tunnel. This completes the configuration needed.

9 1.5 Testing A client can now be connected to the IAP. All traffic will get tunnelled to the controller, where a aaaprofile is applied and the user is placed in the guest-logon role. The captive portal from the controller is then served. Note the name on the certificate is different from the default securelogin.arubanetworks.com. After entering credentials, the user is place in the authenticated role.

10 1.6 Multiple Portals and Multi-tenanted environments It is also possible to use this deployment for the provision of different captive portals for different sites, or multi-tenanted environments. This can be achieved by applying a aaa-profile to the vlan itself. Note, that an extra vlan added to the tunnel configuration will create an additional tunnel and counts towards the platform limit. Note, there is a limit of 16 captive portal profiles on the controllers. When a user connects they are placed into the role define in the aaa-profile above instead of the default wired-aaa profile.

11 1.7 Troubleshooting There may initially be issues with the tunnels not coming up. This is generally resolved by rebooting the controller. The user should instantly connect and get an ip address from the scope on the controller. The encaps and decaps should also be seen in the output for show datapath tunnel table on the controller. 1.8 Redundancy and Failover Due to issues and inconsistent behaviour with GRE tunnels terminating on a controller VRRP, this has not been considered. The IAP VPN setup should specify the tunnel host as being the vlan ip of the controller. If a backup controller has been deployed then the appropriate tunnels should be setup on the backup controller as well. In the event of a failure of the primary controller, the VPN configuration on the IAP will need to be updated manually Automatic GRE creation and AOS 6.4 and IAP 4.0 There is an interesting new feature on the both controller and IAP for automatic GRE tunnel creation. The IAP User Guide states When this feature is enabled on the IAP, no manual configuration is required on Aruba Controller to create the GRE tunnel.

12 Initial testing with this feature did not work until the tunnel configuration was manually added to the controller. Due to lack of a redundant controller, this was not tested. However, in terms of redundancy this is most promising for having a failover configuration that does not require manual intervention by an administrator. 1.9 Dot1x ssids and IAP tunnels It is also possible to have additional ssids such as a corporate dot1x tunnel through to the controller as well. Typically, the IAP-VPN is used primarily to tunnel corporate traffic back to the Aruba controller. In this case, since we are using the tunnel for guest access as well, the corporate traffic also needs to be routed into the tunnel. Although, we may be able to break out corporate traffic locally, this is not considered. The authentication needs to be handled by the IAP since the ssid needs to be WPA2-AES. Following authentication, the user is placed into a role on the controller. Since the controller is not handling the authentication, this role is simple the initial role within the aaa-profile. This initial role needs to have the appropriate rights for the corp users, typically allowall.

13 The user then has this initial role applied at the controller.

Aruba ACMP. Aruba Certified Mobility Professional

Aruba ACMP. Aruba Certified Mobility Professional Aruba ACMP Aruba Certified Mobility Professional 6.0 http://killexams.com/exam-detail/acmp Answer: C, D QUESTION: 159 An Aruba controller is configured with the correct IP address and gateway information

More information

Aruba Instant. Validated Reference Design. Chapter 2 Branch Connectivity. Version Roopesh Pavithran Andrew Tanguay

Aruba Instant. Validated Reference Design. Chapter 2 Branch Connectivity. Version Roopesh Pavithran Andrew Tanguay Aruba Instant Chapter 2 Branch Connectivity Version 2.0.1 Authors: Vishal Mann Roopesh Pavithran Andrew Tanguay Contributors: Sathya Narayana Gopal Yan Liu Validated Reference Design Copyright Information

More information

TECHNICAL NOTE MSM & CLEARPASS HOW TO CONFIGURE HPE MSM CONTROLLERS WITH ARUBA CLEARPASS VERSION 3, JUNE 2016

TECHNICAL NOTE MSM & CLEARPASS HOW TO CONFIGURE HPE MSM CONTROLLERS WITH ARUBA CLEARPASS VERSION 3, JUNE 2016 HOW TO CONFIGURE HPE MSM CONTROLLERS WITH ARUBA CLEARPASS VERSION 3, JUNE 2016 CONTENTS Introduction... 5 MSM and AP Deployment Options... 5 MSM User Interfaces... 6 Assumptions... 7 Network Diagram...

More information

ARUBA MULTIZONE DATA SHEET

ARUBA MULTIZONE DATA SHEET Aruba s centralized architecture provides a more secure Wi-Fi environment that is different from any other Wi-Fi vendor on the market today. Among the key security advantages of this architecture are:

More information

Cloudpath and Aruba Instant Integration

Cloudpath and Aruba Instant Integration Cloudpath and Aruba Instant Integration This document describes the process to use Ruckus Cloudpath to secure an Aruba Instant network. The following versions were used for this example: Ruckus Cloudpath

More information

Aruba Instant

Aruba Instant Aruba Instant 6.1.3.1-3.0.0.2 Release Notes Aruba Instant 6.1.3.1-3.0.0.2 is a patch software release that introduces fixes to many previously outstanding issues. For details on all of the features described

More information

Testkings.ACMP_ QA

Testkings.ACMP_ QA Testkings.ACMP_6.3.165.QA Number: ACMP_6.3 Passing Score: 800 Time Limit: 120 min File Version: 9.3 ACMP_6.3 Aruba Certified Mobility Professional 6.3 Provided information is extremely useful for you.

More information

Instant 3.3: BYOD and Captive portal Enhancements

Instant 3.3: BYOD and Captive portal Enhancements Instant 3.3: BYOD and Captive portal Enhancements 1 Instant 3.3: BYOD and Captive portal Enhancements BYOD on a Single SSID Instant OS 3.2 and earlier did not provide the ability to redirect a client to

More information

Aruba Instant Release Notes

Aruba Instant Release Notes Aruba Instant 6.2.1.0-3.4.0.1 Release Notes Copyright 2013 Aruba Networks, Inc. Aruba Networks trademarks include, Aruba Networks, Aruba Wireless Networks, the registered Aruba the Mobile Edge Company

More information

ACMP_6.4

ACMP_6.4 ACMP_6.4 Passing Score: 800 Time Limit: 0 min Exam A QUESTION 1 When creating a firewall rule what are valid choices for the Service/Application field? (Choose three) A. Applications B. Applications Category

More information

Testkings.ACMP_ questions. Aruba ACMP_6.3. Aruba Certified Mobility Professional 6.3

Testkings.ACMP_ questions. Aruba ACMP_6.3. Aruba Certified Mobility Professional 6.3 Testkings.ACMP_6.3.165 questions Number: ACMP_6.3 Passing Score: 800 Time Limit: 120 min File Version: 4.6 http://www.gratisexam.com/ Aruba ACMP_6.3 Aruba Certified Mobility Professional 6.3 My problem

More information

Ruckus ZoneDirector 3450 WLAN Controller (up to 500 ZoneFlex Access Points)

Ruckus ZoneDirector 3450 WLAN Controller (up to 500 ZoneFlex Access Points) Product Name: Manufacturer: - Model Number: 901-3450-UK00 Ruckus ZoneDirector 3450 supporting up to 500 ZoneFlex APs (901-3450-UK00) The Ruckus ZoneDirector 3450, The First Simple and Powerful Enterprise

More information

SOLUTION OVERVIEW THE ARUBA MOBILE FIRST ARCHITECTURE

SOLUTION OVERVIEW THE ARUBA MOBILE FIRST ARCHITECTURE SOLUTION OVERVIEW THE ARUBA MOBILE FIRST ARCHITECTURE March 2018 Table of Contents Introduction...1 Design...2 Use Cases...2 Underlay...3 Overlay...3 Dynamic Segmentation...3 Non-Stop Networking...4 Summary...5

More information

Free4Dump. Free demo and valid vce dump for certification exam prep

Free4Dump.   Free demo and valid vce dump for certification exam prep Free4Dump http://www.free4dump.com Free demo and valid vce dump for certification exam prep Exam : HPE6-A44 Title : Scalable WLAN Design and Implementation (SWDI) 8 Vendor : HP Version : DEMO Get Latest

More information

Alcatel-Lucent OmniVista Cirrus Simple, secure cloud-based network management as a service

Alcatel-Lucent OmniVista Cirrus Simple, secure cloud-based network management as a service Alcatel-Lucent OmniVista Cirrus Simple, secure cloud-based network management as a service Alcatel-Lucent OmniVista Cirrus is a scalable, resilient, secure cloud-based network management for unified access

More information

Vendor: Aruba. Exam Code: ACMP_6.1. Exam Name: Aruba Certified Mobility Professional 6.1. Version: Demo

Vendor: Aruba. Exam Code: ACMP_6.1. Exam Name: Aruba Certified Mobility Professional 6.1. Version: Demo Vendor: Aruba Exam Code: ACMP_6.1 Exam Name: Aruba Certified Mobility Professional 6.1 Version: Demo Topic 1, Volume A QUESTION NO: 1 Which Aruba controllers are able to provide IEEE 802.3af POE? (Choose

More information

Integrating Meraki Networks with

Integrating Meraki Networks with Integrating Meraki Networks with Cisco Identity Services Engine Secure Access How-To guide series Authors: Tim Abbott, Colin Lowenberg Date: April 2016 Table of Contents Introduction Compatibility Matrix

More information

How to social login with Aruba controller. Bo Nielsen, CCIE #53075 (Sec) December 2016, V1.00

How to social login with Aruba controller. Bo Nielsen, CCIE #53075 (Sec) December 2016, V1.00 Bo Nielsen, CCIE #53075 (Sec) December 2016, V1.00 Overview This short document describes the basic setup for social login using Aruba ClearPass and Aruba wireless LAN controller. Aruba ClearPass, version

More information

IAP VPN TROUBLESHOOTING

IAP VPN TROUBLESHOOTING IAP VPN TROUBLESHOOTING Technical Climb Webinar 10:00 GMT 11:00 CET 13:00 GST June 27th, 2017 Presenter: Nabeel Akram Nabeel.akram@hpe.com Welcome to the Technical Climb Webinar Listen to this webinar

More information

ArubaOS Remote Networking Version 3.1

ArubaOS Remote Networking Version 3.1 ArubaOS Remote Networking Version 3.1 User Guide Copyright 2009 Aruba Networks, Inc. AirWave, Aruba Networks, Aruba Mobility Management System, Bluescanner, For Wireless That Works, Mobile Edge Architecture,

More information

Implementing Core Cisco ASA Security (SASAC)

Implementing Core Cisco ASA Security (SASAC) 1800 ULEARN (853 276) www.ddls.com.au Implementing Core Cisco ASA Security (SASAC) Length 5 days Price $6215.00 (inc GST) Overview Cisco ASA Core covers the Cisco ASA 9.0 / 9.1 core firewall and VPN features.

More information

Aruba Instant Release Notes

Aruba Instant Release Notes Aruba Instant 6.2.1.0-3.4.0.2 Release Notes Copyright 2013 Aruba Networks, Inc. Aruba Networks trademarks include, Aruba Networks, Aruba Wireless Networks, the registered Aruba the Mobile Edge Company

More information

ARUBA INSTANT Combining enterprise-class Wi-Fi with unmatched affordability and configuration simplicity

ARUBA INSTANT Combining enterprise-class Wi-Fi with unmatched affordability and configuration simplicity ARUBA INSTANT Combining enterprise-class Wi-Fi with unmatched affordability and configuration simplicity Table of Contents Introduction... 3 Aruba Instant Overview... 4 Aruba Instant APs... 4 Adaptive

More information

ARUBA INSTANT DOT1X TROUBLESHOOTING

ARUBA INSTANT DOT1X TROUBLESHOOTING ARUBA INSTANT DOT1X TROUBLESHOOTING Technical Climb Webinar 12:00 GMT 13:00 CET 15:00 GST June 21st, 2016 Presenter: Barath Srinivasan barath.srinivasan@hpe.com Welcome to the Technical Climb Webinar Listen

More information

Latest IT Exam Questions & Answers

Latest IT Exam Questions & Answers DumpKiller Latest IT Exam Questions & Answers http://www.dumpkiller.com No help, Full refund! Exam : HPE6-A29 Title : Aruba Certified Mobility Professional 6.4 Vendor : HP Version : DEMO Get Latest & Valid

More information

Aruba Instant

Aruba Instant Aruba Instant 6.4.4.4-4.2.3.2 Release Notes Copyright Copyright 2016 Hewlett Packard Enterprise Development LP Open Source Code This product includes code licensed under the GNU General Public License,

More information

ARUBA OS HIGH AVAILABILITY WITH AP FAST FAILOVER

ARUBA OS HIGH AVAILABILITY WITH AP FAST FAILOVER ARUBA OS HIGH AVAILABILITY WITH AP FAST FAILOVER 10:00 GMT 11:00 CET 13:00 GST Jan 31st, 2017 Presenter: Britto Jagadesh Britto.jagadesh@hpe.com SUMMARY OF HA FEATURES IN 6.3 HA FEATURES INTRODUCED IN

More information

ClearPass NAC and Posture Assessment for Campus Networks

ClearPass NAC and Posture Assessment for Campus Networks ClearPass NAC and Posture Assessment for Campus Networks Configuring ClearPass OnGuard, Switching, and Wireless (v1.0) Dell Network Solutions Engineering September 2015 A Dell EMC Deployment and Configuration

More information

Aruba Central. Tech Webinar, October 6 th Christian Dupont, Britto Jagadesh & Barath Srinivasan

Aruba Central. Tech Webinar, October 6 th Christian Dupont, Britto Jagadesh & Barath Srinivasan Aruba Central Tech Webinar, October 6 th 2016 Christian Dupont, Britto Jagadesh & Barath Srinivasan Aruba Instant Virtualized Controller 2 Aruba Instant - Virtualized Controller Solution Manual Configuration

More information

Configure Guest Flow with ISE 2.0 and Aruba WLC

Configure Guest Flow with ISE 2.0 and Aruba WLC Configure Guest Flow with ISE 2.0 and Aruba WLC Contents Introduction Prerequisites Requirements Components Used Background Information Guest Flow Configure Step 1. Add Aruba WLC as NAD in ISE. Step 2.

More information

Aruba Instant Release Notes

Aruba Instant Release Notes Aruba Instant 6.2.1.0-3.4 Release Notes Copyright 2013 Aruba Networks, Inc. Aruba Networks trademarks include, Aruba Networks, Aruba Wireless Networks, the registered Aruba the Mobile Edge Company logo,

More information

Alcatel-Lucent OmniVista Cirrus Simple, secure cloud-based network management as a service

Alcatel-Lucent OmniVista Cirrus Simple, secure cloud-based network management as a service Alcatel-Lucent OmniVista Cirrus Simple, secure cloud-based network management as a service Alcatel-Lucent OmniVista Cirrus is a scalable, resilient, secure cloud-based network management for unified access

More information

Colubris Networks Configuration Guide

Colubris Networks Configuration Guide Colubris Networks Configuration Guide Release 5.1 (October 2006) 43-10-0000-02 Copyright 2006 Colubris Networks, Inc. All rights reserved, including those to reproduce this document or parts thereof in

More information

P ART 3. Configuring the Infrastructure

P ART 3. Configuring the Infrastructure P ART 3 Configuring the Infrastructure CHAPTER 8 Summary of Configuring the Infrastructure Revised: August 7, 2013 This part of the CVD section discusses the different infrastructure components that are

More information

Release Notes for Avaya WLAN 9100 Software Patch Release WLAN Release Notes

Release Notes for Avaya WLAN 9100 Software Patch Release WLAN Release Notes WLAN 9100 Release Notes Release Notes for Avaya WLAN 9100 Software Patch Release AP Operating System Rel 7.2.8 Wireless LAN Orchestration System Rel 7.4.2 Avaya Inc - External Distribution Avaya Inc -

More information

DATA SHEET MODEL AXC1000 HIGHLIGHTS OVERVIEW. Redefining Enterprise Wireless Management

DATA SHEET MODEL AXC1000 HIGHLIGHTS OVERVIEW. Redefining Enterprise Wireless Management DATA SHEET Redefining Enterprise Wireless MODEL AXC1000 HIGHLIGHTS OVERVIEW TurboRF maximizes WLAN performance VisualSec - a comprehensive and visible security protection mechanism FlowPath - 1-7 layer

More information

Case Study Captive Portal with QR Code authenticator assisted

Case Study Captive Portal with QR Code authenticator assisted Case Study Captive Portal with QR Code authenticator assisted Guest receives a QR code that is authenticated by an authenticator on the external RADIUS server QR Code Introduction The Captive Portal with

More information

AOS-W Instant Release Notes

AOS-W Instant Release Notes AOS-W Instant 6.1.3.4-3.1.0.1 Release Notes Copyright 2012 Alcatel-Lucent. All rights reserved. Specifications in this manual are subject to change without notice. Originated in the USA. AOS-W, Alcatel

More information

Aruba Instant Release Notes

Aruba Instant Release Notes Aruba Instant 6.2.1.0-3.4.0.4 Release Notes Copyright 2013 Aruba Networks, Inc. Aruba Networks trademarks include, Aruba Networks, Aruba Wireless Networks, the registered Aruba the Mobile Edge Company

More information

MSP Solutions Guide. Version 1.0

MSP Solutions Guide. Version 1.0 MSP Solutions Guide Version 1.0 Copyright Information Copyright 2018 Hewlett Packard Enterprise Development LP. Open Source Code This product includes code licensed under the GNU General Public License,

More information

WFS709TP Case Scenario: Wireless deployment for a Corporate and Public network

WFS709TP Case Scenario: Wireless deployment for a Corporate and Public network WFS709TP Case Scenario: Wireless deployment for a Corporate and Public network This document describes the activities undertaken to deploy a Wireless solution using the Wireless Controller WFS709TP and

More information

Aruba Campus Wireless Networks. Version 8

Aruba Campus Wireless Networks. Version 8 Version 8 Copyright 2011 Aruba Networks, Inc. AirWave, Aruba Networks, Aruba Mobility Management System, Bluescanner, For Wireless That Works, Mobile Edge Architecture, People Move. Networks Must Follow,

More information

HP0-Y44. Implementing and Troubleshooting HP Wireless Networks.

HP0-Y44. Implementing and Troubleshooting HP Wireless Networks. HP HP0-Y44 Implementing and Troubleshooting HP Wireless Networks http://killexams.com/exam-detail/hp0-y44 C. The user s access list does not permit any traffic. D. The users egress VLAN does not match

More information

Aruba Mobility. Setup Guide

Aruba Mobility. Setup Guide Aruba Mobility Setup Guide Disclaimer THIS DOCUMENTATION AND ALL INFORMATION CONTAINED HEREIN ( MATERIAL ) IS PROVIDED FOR GENERAL INFORMATION PURPOSES ONLY. GLOBAL REACH AND ITS LICENSORS MAKE NO WARRANTY

More information

A connected workforce is a more productive workforce

A connected workforce is a more productive workforce A connected workforce is a more productive workforce D-Link wireless networking solutions enable business networks of all sizes to create highly mobile, highly productive work environments at a low total

More information

PowerConnect W-Series...Mobility Controllers. Validated Reference Design Version 8

PowerConnect W-Series...Mobility Controllers. Validated Reference Design Version 8 PowerConnect W-Series...Mobility Controllers Validated Reference Design Version 8 Copyright This document is for informational purposes only and may contain typographical errors and technical inaccuracies.

More information

Wireless Client Isolation. Overview. Bridge Mode Client Isolation. Configuration

Wireless Client Isolation. Overview. Bridge Mode Client Isolation. Configuration Wireless Client Isolation Overview Wireless Client Isolation is a security feature that prevents wireless clients from communicating with one another. This feature is useful for guest and BYOD SSIDs adding

More information

Aruba Instant Release Notes

Aruba Instant Release Notes Aruba Instant 6.2.0.0-3.2.0.1 Release Notes Copyright 2013 Aruba Networks, Inc. Aruba Networks trademarks include, Aruba Networks, Aruba Wireless Networks, the registered Aruba the Mobile Edge Company

More information

A. Post-Onboarding. the device wit be assigned the BYOQ-Provision firewall role in me Aruba Controller.

A. Post-Onboarding. the device wit be assigned the BYOQ-Provision firewall role in me Aruba Controller. Volume: 98 Questions Question: 1 Based on the ClearPass and Aruba Controller configuration settings for On boarding shown, which statement accurate describes an employee's new personal device connecting

More information

Ruckus ZoneDirector 1106 WLAN Controller (up to 6 ZoneFlex Access Points)

Ruckus ZoneDirector 1106 WLAN Controller (up to 6 ZoneFlex Access Points) Product Name: Manufacturer: - Model Number: 901-1106-UK00 Please Note: The Ruckus ZoneDirector 1106 has been discontinued. For an alternative, we recommend the Ruckus ZoneDirector 1205. Ruckus ZoneDirector

More information

Expected Outcomes Able to design the network security for the entire network Able to develop and suggest the security plan and policy

Expected Outcomes Able to design the network security for the entire network Able to develop and suggest the security plan and policy CHAPTER 9 DEVELOPING NETWORK SECURITY STRATEGIES Expected Outcomes Able to design the network security for the entire network Able to develop and suggest the security plan and policy Network Security Design

More information

Aruba Instant Release Notes

Aruba Instant Release Notes Aruba Instant 6.2.1.0-3.3 Release Notes Copyright 2013 Aruba Networks, Inc. Aruba Networks trademarks include, Aruba Networks, Aruba Wireless Networks, the registered Aruba the Mobile Edge Company logo,

More information

Creating Wireless Networks

Creating Wireless Networks WLANs, page 1 Creating Employee WLANs, page 2 Creating Guest WLANs, page 4 Internal Splash Page for Web Authentication, page 7 Managing WLAN Users, page 9 Adding MAC for Local MAC Filtering on WLANs, page

More information

Vendor: HP. Exam Code: HP2-Z32. Exam Name: Implementing HP MSM Wireless Networks. Version: Demo

Vendor: HP. Exam Code: HP2-Z32. Exam Name: Implementing HP MSM Wireless Networks. Version: Demo Vendor: HP Exam Code: HP2-Z32 Exam Name: Implementing HP MSM Wireless Networks Version: Demo QUESTION 1 A network administrator deploys several HP MSM APs and an HP MSM Controller. The APs discover the

More information

Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13

Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13 Q&A Cisco Cloud Services Router 1000V with Cisco IOS XE Software Release 3.13 Q. What is the Cisco Cloud Services Router 1000V? A. The Cisco Cloud Services Router 1000V (CSR 1000V) is a router in virtual

More information

Q&A DOCUMENT ARUBA 8.X ARCHITECTURE OVERVIEW & UI NAVIGATION

Q&A DOCUMENT ARUBA 8.X ARCHITECTURE OVERVIEW & UI NAVIGATION AIRHEADS TECHNICAL WEBINARS Q&A DOCUMENT ARUBA 8.X ARCHITECTURE OVERVIEW & UI NAVIGATION Q1: In 6.5 there is a HA mode with state sync. Where is the difference to the new HA feature, what are the benefits?

More information

Identity Services Engine Guest Portal Local Web Authentication Configuration Example

Identity Services Engine Guest Portal Local Web Authentication Configuration Example Identity Services Engine Guest Portal Local Web Authentication Configuration Example Document ID: 116217 Contributed by Marcin Latosiewicz, Cisco TAC Engineer. Jun 21, 2013 Contents Introduction Prerequisites

More information

NL Airheads AOS 8.2 Introduction. Utrecht, 27 th October 2017

NL Airheads AOS 8.2 Introduction. Utrecht, 27 th October 2017 NL Airheads AOS 8.2 Introduction Utrecht, 27 th October 2017 john.schaap@hpe.com AOS 8.2 New Features 2 AOS 8.2 New Features Hardware AP-303H, AP-203H, AP-203R, AP-365/367 Redundancy L3 redundancy for

More information

A-to-Z Design Guide for the All-Wireless Workplace

A-to-Z Design Guide for the All-Wireless Workplace A-to-Z Design Guide for the All-Wireless Workplace Partha Narasimhan, Michael Wong March 2015 @ArubaNetworks #nomorephones 2 CONFIDENTIAL Copyright 2015. Aruba Networks, Inc. All rights reserved Wireless

More information

Designing Windows Server 2008 Network and Applications Infrastructure

Designing Windows Server 2008 Network and Applications Infrastructure Designing Windows Server 2008 Network and Applications Infrastructure Course No. 6435B - 5 Days Instructor-led, Hands-on Introduction This five-day course will provide students with an understanding of

More information

Single VLAN Architecture for Wireless LAN

Single VLAN Architecture for Wireless LAN Single VLAN Architecture for Wireless LAN Author: Alap Modi Contributors: Colin Joseph Michael Wong Partha Narasimhan Peter Thornycroft Shiv Mehra Copyright Information Copyright 2016 Hewlett Packard Enterprise

More information

HiveManager Local Cloud

HiveManager Local Cloud DATA SHEET HiveManager Local Cloud Enterprise Access Network Management Offering Intuitive Configuration Workflows, Real-Time & Historical Monitoring, and Simplified Troubleshooting DATASHEET HiveManager

More information

Unified Services Routers

Unified Services Routers Product Highlights Comprehensive Management Solution Active-Active WAN port features such as auto WAN failover and load balancing, ICSA-certified firewall, and D-Link Green Technology make this a reliable,

More information

WHITE PAPER ARUBA SD-BRANCH OVERVIEW

WHITE PAPER ARUBA SD-BRANCH OVERVIEW WHITE PAPER ARUBA SD-BRANCH OVERVIEW June 2018 Table of Contents Overview of the Traditional Branch...1 Adoption of Cloud Services...1 Shift to the Internet as a Business Transport Medium...1 Increasing

More information

Cisco Exam Questions and Answers (PDF) Cisco Exam Questions BrainDumps

Cisco Exam Questions and Answers (PDF) Cisco Exam Questions BrainDumps Cisco 300-375 Dumps with Valid 300-375 Exam Questions PDF [2018] The Cisco 300-375 Securing Cisco Wireless Enterprise Networks (WISECURE) exam is an ultimate source for professionals to retain their credentials

More information

Technology Solution Guide

Technology Solution Guide Technology Solution Guide Deploying Impulse Point s SafeConnect Network Access Control (NAC) with Aruba Networks Secure Mobility Solution S/W Version : SafeConnect V5.2-2011 This document describes the

More information

D-Link Central WiFiManager Configuration Guide

D-Link Central WiFiManager Configuration Guide Table of Contents D-Link Central WiFiManager Configuration Guide Introduction... 3 System Requirements... 3 Access Point Requirement... 3 Latest CWM Modules... 3 Scenario 1 - Basic Setup... 4 1.1. Install

More information

ArubaOS RNG. Release Notes. What s New in this Release. Termination of IAP VPN tunnels. Termination of IAP GRE tunnels

ArubaOS RNG. Release Notes. What s New in this Release. Termination of IAP VPN tunnels. Termination of IAP GRE tunnels ArubaOS 6.1.3.1-RNG Release Notes ArubaOS 6.1.3.1-RNG is the companion controller release for the Aruba Instant 6.1.3.1-3.0.0.0 release. This controller release provides an ability to terminate VPN and

More information

ISE Version 1.3 Self Registered Guest Portal Configuration Example

ISE Version 1.3 Self Registered Guest Portal Configuration Example ISE Version 1.3 Self Registered Guest Portal Configuration Example Document ID: 118742 Contributed by Michal Garcarz and Nicolas Darchis, Cisco TAC Engineers. Feb 13, 2015 Contents Introduction Prerequisites

More information

https://www.fuzeqna.com/sonicwallkb/consumer/kbdetail.asp?kbid=5801

https://www.fuzeqna.com/sonicwallkb/consumer/kbdetail.asp?kbid=5801 Page 1 of 7 Home Welcome Guest Log In Unread Messages : 0 E-mail Print Subscribe? Related Bookmark Search View all items in: UTM/Firewall/VPN > 1.5 Wireless / SonicPoint > Wireless Configuration UTM/Firewall/VPN

More information

AOS-W 6.4. Quick Start Guide. Install the Switch. Initial Setup Using the WebUI Setup Wizard

AOS-W 6.4. Quick Start Guide. Install the Switch. Initial Setup Using the WebUI Setup Wizard AOS-W 6.4 Quick Start Guide This document describes the initial setup of an Alcatel-Lucent user-centric network that consists of an Alcatel-Lucent switch and Alcatel-Lucent Access Points (APs). The installation

More information

Exam HP2-Z32 Implementing HP MSM Wireless Networks Version: 7.1 [ Total Questions: 115 ]

Exam HP2-Z32 Implementing HP MSM Wireless Networks Version: 7.1 [ Total Questions: 115 ] s@lm@n HP Exam HP2-Z32 Implementing HP MSM Wireless Networks Version: 7.1 [ Total Questions: 115 ] HP HP2-Z32 : Practice Test Question No : 1 What is a proper use for an ingress VLAN in an HP MSM VSC?

More information

HPE6-A44. Scalable WLAN Design and Implementation (SWDI) 8.

HPE6-A44. Scalable WLAN Design and Implementation (SWDI) 8. HP HPE6-A44 Scalable WLAN Design and Implementation (SWDI) 8 https://killexams.com/pass4sure/exam-detail/hpe6-a44 QUESTION 60 What must an administrator configure in order for the ClearPass server to execute

More information

Guide to Configuring eduroam Using the Aruba Wireless Controller and ClearPass RADIUS

Guide to Configuring eduroam Using the Aruba Wireless Controller and ClearPass RADIUS Guide to Configuring eduroam Using the Aruba Wireless Controller and ClearPass RADIUS Best Practice Document Produced by the UNINETT-led Campus Networking working group Authors: Tom Myren (UNINETT), John-Egil

More information

Deployment Guide for Cisco Guest Access Using the Cisco Wireless LAN Controller, Release 4.1

Deployment Guide for Cisco Guest Access Using the Cisco Wireless LAN Controller, Release 4.1 Deployment Guide for Cisco Guest Access Using the Cisco Wireless LAN Controller, Release 4.1 Last revised: February 1, 2008 Contents Overview section on page 1 Configuring Guest Access on the Cisco Wireless

More information

LevelOne. Quick Installation Guide. WHG series Secure WLAN Controller. Introduction. Getting Started. Hardware Installation

LevelOne. Quick Installation Guide. WHG series Secure WLAN Controller. Introduction. Getting Started. Hardware Installation Introduction LevelOne WHG series Secure WLAN Controller LevelOne Secure WLAN Controller is the most advanced yet simple deployment and cost-effective wireless solution; it is an ideal security solution

More information

Huawei Enterprise Network esight Channel Sales Guide HUAWEI TECHNOLOGIES CO., LTD. Issue 3.2. Date

Huawei Enterprise Network esight Channel Sales Guide HUAWEI TECHNOLOGIES CO., LTD. Issue 3.2. Date Huawei Enterprise Network esight Channel Sales Guide Issue 3.2 Date 2013-11-20 HUAWEI TECHNOLOGIES CO., LTD. 2013. All rights reserved. No part of this document may be reproduced or transmitted in any

More information

Cisco Meraki Wireless Solution Comparison

Cisco Meraki Wireless Solution Comparison Solution Comparison Cisco Meraki Wireless Cisco Meraki Wireless Solution Comparison Why Cisco Meraki? Simplified cloud management Intuitive interface allows devices to be configured in minutes without

More information

Vendor: Cisco. Exam Code: Exam Name: Implementing Advanced Cisco Unified Wireless Security (IAUWS) v2.0. Version: Demo

Vendor: Cisco. Exam Code: Exam Name: Implementing Advanced Cisco Unified Wireless Security (IAUWS) v2.0. Version: Demo Vendor: Cisco Exam Code: 642-737 Exam Name: Implementing Advanced Cisco Unified Wireless Security (IAUWS) v2.0 Version: Demo QUESTION 1 Which statement describes the major difference between PEAP and EAP-FAST

More information

WAP9112/9114 Quick Start Guide

WAP9112/9114 Quick Start Guide WAP9112/9114 Quick Start Guide Release 7.6 NN47252-308 Issue 02.01 March 2016 Contents Chapter 1: Introduction... 3 Chapter 2: Required Software Components... 4 Chapter 3: Installing or Upgrading Wireless

More information

Aruba Instant in AirWave 7.7

Aruba Instant in AirWave 7.7 Aruba Instant in AirWave 7.7 Deployment Guide About this Document This document describes the Aruba Instant access point and Virtual Controller system as well as the procedure to integrate this system

More information

Document Information:

Document Information: Document Information: Document Title: WiFi On The Move (OTM) Tech Spec Document Version Date: 17/07/2017 Prepared By: Joe Nicastro Preparation Date: 02/06/2017 Document Version No: V 1.1 Content Document

More information

Mobility First How Tomorrow Moves for Education

Mobility First How Tomorrow Moves for Education Mobility First How Tomorrow Moves for Education Presented by: Sponsored by: CONFIDENTIAL Copyright 2016. Aruba Networks, an HP Company. All rights reserved GENMOBILE IS AT THE HEART OF OUR TECHNOLOGY STRATEGY

More information

CNS-207-2I Implementing Citrix NetScaler 10.5 for App and Desktop Solutions

CNS-207-2I Implementing Citrix NetScaler 10.5 for App and Desktop Solutions 1800 ULEARN (853 276) www.ddls.com.au CNS-207-2I Implementing Citrix NetScaler 10.5 for App and Desktop Solutions Length 5 days Price $5500.00 (inc GST) Overview The objective of Implementing Citrix NetScaler

More information

PASS4TEST. IT Certification Guaranteed, The Easy Way! We offer free update service for one year

PASS4TEST. IT Certification Guaranteed, The Easy Way!   We offer free update service for one year PASS4TEST \ http://www.pass4test.com We offer free update service for one year Exam : 642-737 Title : Implementing Advanced Cisco Unified Wireless Security (IAUWS) v2.0 Vendor : Cisco Version : DEMO Get

More information

Building a Secure Wireless Network. Use i and WPA to Protect the Channel and Authenticate Users. May, 2007

Building a Secure Wireless Network. Use i and WPA to Protect the Channel and Authenticate Users. May, 2007 Agenda: Securing Wireless Networks Building a Secure Wireless Network Joel M Snyder Senior Partner Opus One jms@opus1.com Using encryption and authentication Handling unauthenticated users Managing RF

More information

Network+ Guide to Networks 7 th Edition

Network+ Guide to Networks 7 th Edition Network+ Guide to Networks 7 th Edition Chapter 10 Network Segmentation and Virtualization 2016 Cengage Learning. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in

More information

GFence Integration. with Aruba ALE Configuration guide

GFence Integration. with Aruba ALE Configuration guide GFence Integration with Aruba ALE Configuration guide Location Based Services Contents Introduction 1.Prerequisites 2.Overview 3.Configuration Configuring Aruba ALE Configuring Aruba AirWave Configuring

More information

HS5200 Series AAA Hotspot Solutions

HS5200 Series AAA Hotspot Solutions + 7500 Successful Installation Authentication Authorisation Accounting HS5200 Series AAA Solutions For Educational Segment Lorem ipsum User Management & Bandwidth Management Co-Works with Any Access Points

More information

Wireless Integration Overview

Wireless Integration Overview Version: 4.1.1 Date: 12/28/2010 Copyright Notice Copyright 2010 by Bradford Networks, Inc. All rights reserved worldwide. Use, duplication, or disclosure by the United States government is subject to the

More information

Technical Whitepaper. Dynamic Segmentation. Aruba Mobile-First Infrastructure

Technical Whitepaper. Dynamic Segmentation. Aruba Mobile-First Infrastructure Technical Whitepaper Dynamic Segmentation Aruba Mobile-First Infrastructure 1 Technical Whitepaper Dynamic Segmentation Contents Role-Based Tunneling... 4 Overview... 4 Use Cases... 5 Wired Access Firewall...

More information

Compatibility Test Report of HUAWEI WLAN Solution with Aruba Clearpass

Compatibility Test Report of HUAWEI WLAN Solution with Aruba Clearpass Compatibility Test Report of HUAWEI WLAN Solution with Aruba Clearpass Huawei Technologies Co., Ltd. All rights reserved 错误! 未知的文档属性名称 i Background The Customer is one of the oldest institutions in Hong

More information

Actual4Test. Actual4test - actual test exam dumps-pass for IT exams

Actual4Test.   Actual4test - actual test exam dumps-pass for IT exams Actual4Test http://www.actual4test.com Actual4test - actual test exam dumps-pass for IT exams Exam : 642-617 Title : Deploying Cisco ASA Firewall Solutions (FIREWALL v1.0) Vendor : Cisco Version : DEMO

More information

RADIUS Configuration Note WINS : Wireless Interoperability & Network Solutions

RADIUS Configuration Note WINS : Wireless Interoperability & Network Solutions RADIUS Configuration Note WINS : Wireless Interoperability & Network Solutions MERUNETWORKS.COM February 2013 1. OVERVIEW... 3 2. AUTHENTICATION AND ACCOUNTING... 4 3. 802.1X, CAPTIVE PORTAL AND MAC-FILTERING...

More information

ARUBA, A HEWLETT PACKARD ENTERPRISE COMPANY, IS REDEFINING THE INTELLIGENT EDGE WITH MOBILITY AND IOT SOLUTIONS FOR ORGANIZATIONS

ARUBA, A HEWLETT PACKARD ENTERPRISE COMPANY, IS REDEFINING THE INTELLIGENT EDGE WITH MOBILITY AND IOT SOLUTIONS FOR ORGANIZATIONS CORPORATE OVERVIEW ARUBA, A HEWLETT PACKARD ENTERPRISE COMPANY, IS REDEFINING THE INTELLIGENT EDGE WITH MOBILITY AND IOT SOLUTIONS FOR ORGANIZATIONS of all sizes globally. The company delivers IT solutions

More information

WLAN high availability

WLAN high availability Technical white paper WLAN high availability Table of contents Overview... 2 WLAN high availability implementation... 3 Fundamental high availability technologies... 3 AP connection priority... 3 AC selection...

More information

Aruba Certified Clearpass Professional 6.5

Aruba Certified Clearpass Professional 6.5 Aruba Certified Clearpass Professional 6.5 Don t need to take any stress about the HPE6-A15 Exam. We provide you HPE6-A15 Real Exam Questions Along with Updated Test Engine. PDF + Practice Test Desktop

More information

ISE Express Installation Guide. Secure Access How -To Guides Series

ISE Express Installation Guide. Secure Access How -To Guides Series ISE Express Installation Guide Secure Access How -To Guides Series Author: Jason Kunst Date: September 10, 2015 Table of Contents About this Guide... 4 How do I get support?... 4 Using this guide... 4

More information

Cisco TrustSec How-To Guide: Universal Configuration for the Cisco Wireless LAN Controller

Cisco TrustSec How-To Guide: Universal Configuration for the Cisco Wireless LAN Controller Cisco TrustSec How-To Guide: Universal Configuration for the Cisco Wireless LAN Controller For Comments, please email: howtoguides@external.cisco.com Current Document Version: 3.0 August 27, 2012 Table

More information

PrepAwayExam. High-efficient Exam Materials are the best high pass-rate Exam Dumps

PrepAwayExam.   High-efficient Exam Materials are the best high pass-rate Exam Dumps PrepAwayExam http://www.prepawayexam.com/ High-efficient Exam Materials are the best high pass-rate Exam Dumps Exam : 250-530 Title : Administration of Symantec Network Access Control 12.1 Vendors : Symantec

More information