OmniAccess Instant AP Update Pre-Sales Expert November COPYRIGHT 2011 ALCATEL-LUCENT ENTERPRISE. ALL RIGHTS RESERVED.
AGENDA 1) OmniAccess Instant AP reminder 2) Instant AP versus Campus AP 3) Virtual Controller 4) Instant AP Roles and QoS 5) Instant AP User Traffic & Management Specifics 6) Instant AP 1.1 Features 7) Reference Documentation 2 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
OmniAccess Instant AP Reminder 3 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
OmniAccess Instant AP Reminder Controllerless WLAN solution using a Virtual Controller Each IAP is eligible to become Virtual Controller Solution based on IAP92/93 and IAP105 Scalable from up to 16 IAPs and up to 256 users (per Instant Group) Layer 2 network operation (Inter group roaming within a single site) DHCP address allocation for NATed clients What is NOT part of Instant AP features: L3 roaming between Instant Groups Per user per device based role Converged wired and wireless access Integrated VPN for remote access such as RAPs and VIA clients Integrated Spectrum Analysis and heatmaps 4 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Instant AP versus Campus AP 5 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Instant AP versus Campus AP: Overview Instant APs and Campus APs: Same Look but not the same Hardware IAP105 RESET Button AP105 IAP92/93 RESET Button AP92/93 Instant AP: - embeds a Double partition to store IAP & Campus AP images - has a Reset Button - is country specific (Restricted Regulatory domains: Israël, Japan, US & unrestricted for Rest Of World) Instant AP Reset Campus AP An Instant AP can be converted to a Campus AP (AP92/93 & AP105 to IAP92/93 & IAP105 ) Pressing the Reset button converts it back to an IAP. 6 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Instant AP versus Campus AP: Specificities An original Campus AP cannot become an Instant AP (AP92/93 & AP105 cannot be moved to IAP92/93 & IAP105) Original Campus AP Instant AP 7 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Instant AP versus Campus AP: RF coverage (2.45 GHz) Instant AP and Campus AP: same Radio and same RF coverage - Snapshots for 2.45 GHz Radio Band IAP105 (2.45 GHz) AP105 (2.45 GHz) IAP93 (2.45 GHz) AP93 (2.45 GHz) 8 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Instant AP versus Campus AP: RF coverage (5.5 GHz) Instant AP and Campus AP: have the same Radio and the same RF coverage - Snapshots for 5.5 GHz Radio Band IAP105 (5.5GHz) AP105 (5.5GHz) IAP93 (5.5GHz) AP93 (5.5GHz) 9 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Virtual Controller 10 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Virtual Controller : Overview The First Implemented IAP Becomes The Virtual Controller Initial Installation - The First installed IAP listen to Beacons - If no beacons are received, IAP takes the «Virtual Controller» role - A static IP address can be configured to manage the Instant network - This static IP address is provisioned on shadow interface of the IAP acting as Virtual Controller - When IAP becomes Virtual Controller, it sends 3 ARP messages with the static IP address and its own MAC address to update the network ARP cache 11 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Virtual Controller : New IAP Beacons (every second) IAP Listening? New IAP IAP Virtual Controller IAP IAP Normal Operation - The Virtual Controller is discovered using a Layer 2 Multicast protocol - The Virtual Controller sends beacons every second to notify that it is active - Each IAP checks for an active Virtual Controller through the received beacons (keep-alive) - The New IAP listen to the beacons to discover the Virtual Controller (if any) 12 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Virtual Controller: Election Failing No more beacons? Virtual Controller IAP IAP (e.g. uptime = 30 minutes) What is the new Virtual Controller? IAP IAP (e.g. uptime = 29 minutes) (e.g. uptime = 31 minutes Virtual Controller Election after a Virtual Controller IAP failure - IAPs do not receive Beacons anymore - VC Role Preference is given to the IAP having the Largest Uptime (in case of conflict) - No disruption to the whole WLAN network, failure is localized to the faulty IAP - Wireless users can re-associate to another IAP. 13 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Instant AP Roles & QoS 14 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Instant AP Roles & QoS 3 Network Types (linked to SSIDs/VLANs) Employee (Classic WLAN, No Captive Portal, Voice ALG) Voice (Classic WLAN, No Captive Portal, Traffic Auto prioritization) Guest (Open System or PSK based Encryption, Captive Portal) Instant AP solution supports the ALG for SIP, SVP, Vocera, Skinny and Alcatel NOE - Traffics based on these protocols are put in Voice Queue automatically - On Employee SSID, Voice ALGs are automatically applied on authenticated user traffic. (WMM tags for wireless and DSCP Tags for wired traffic). - On Voice SSID all traffic is prioritized as Voice (based on ALG) Voice aware scanning ARM supports Alcatel NOE 15 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
IAP User Traffic & Management Specifics 16 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
IAP User Traffic & Management Specifics: Employee & Guest Virtual Controller IAP Guest IAP Captive Portal (Private NAT) WAN Router/ NAT Device Internet Employee Corporate Employee Traffic Guest Traffic - Guest Traffic must go through the Virtual Controller IAP because Captive Portal function is managed by the Virtual Controller IAP - Employee traffic does not go through the Virtual Controller 17 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
IAP User Traffic & Management Specifics Internal Private NAT operation Internal DHCP server DHCP pool Virtual Controller (IAP1) WAN Router/ NAT Device Internet DHCP Request to get the IP addresses for the 3 WiFi users (private IP 1, IP 2 & IP 3 ) Private IP Addresses IAP2 IP 1 IP 2 IP 3 NAT IP 1 IP 2 IP 3 Virtual Controller IP address - Internal DHCP server provides Wireless users with IP addresses - Internal Private NAT Wireless users COPYRIGHT 2011 ALCATEL-LUCENT ENTERPRISE. ALL RIGHTS RESERVED.
IAP User Traffic & Management Specifics OV3600 & Web UI OV3600 or Web UI Master Controller Domain 1 APs Domain 2 Virtual Controller IAPs Local Controller APs Instant AP Network - OV3600 can manage the WLAN controllers and the Instant AP Network - A Web UI can also be used to manage the Instant Network - Instant Nework cannot be managed by a WLAN Controller (seen as separate domains) 19 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Instant AP 1.1 Features 20 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Instant AP 1.1 Features Mesh (see next slides) Per SSID & Per User Bandwidth Limits - Max percentage of airtime for the SSID - Max kbps per each radio on each AP - Max kbps per each user on the SSID The First limit reached takes effect Radius Authentication Radius server can be specified per SSID: - e.g. a Radius server for Employee SSID and another Radius server for Guest SSID - Up to 2 external Radius servers per SSID: Active/Backup or Load Balancing Internal Radius server can be selected to use built-in Employee accounts : No Secondary server in this case Role Based Access Control Role-Based assignment supports: - Pre-authenticated Role and Post-authenticated Role Users are assigned roles based on a derived Radius attribute 21 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Instant AP 1.1 Features (cont d) Adaptative Radio Management - List of valid channels based on regulatory domain - DFS channels disabled by default - Band steering on all APs - Min/Max Transmit Power can be set Air Monitor Mode - To move from IAP to AM a Reboot is required - Total number APs + AMs is limited to 16 - Improved Rogue detect & WIDS Basic SNMP Agent - SNMPv1, v2 & v3 support - Basic MIB (read-only) 22 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Instant AP 1.1 Features (cont d) Location Services - Integration with OV3600, Ekahau RTLS and Nearbuy RTLS - Aeroscout support Intrusion Detection & Containment - IDS classification (Disabled by default) - Wireless containment (Disabled by default): De-authentication frames - Wired Containment (Disabled by default): Poison ARP packets sent to rogue AP to disrupt traffic - Rogue containment (Wired + wireless) - No integration with OV3600 RAPIDS Initial Provisioning without DHCP server - IAP self-assigns unique IPs in the 169.254.x.x with SSID «Instant» - DHCP provides the users with IP addresses in 192.168.1.0/24 - Static IP address can be configured on IAP OV3600 provisioning via DHCP server - Options 60 and 43 on DHCP server are used to connect VC to OV3600 23 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Instant AP 1.1 Features (cont d) Enhanced Search - Logical sub-lists for Aps, Networks, Clients - Wildcard searches not supported - Auto-completion is supported More Radio Statistics - Neighboring APs & Clients - Per Radio & Channel statistics EAP-TLS in internal Radius server - CA certificate can be uploaded in addition to server Certificate (both required to support EAP-TLS) - Only PEM certificates are supported at this time Time Zone configuration NTP server + Time Zone can be configured: all Logs are timestamped Syslog server - Configurable level of logging (Emergency, Alert, Critical, Error, Warning, Notice, Information, Debug) AP LED control Admin can set LED behavior: all LEDs on all APs can be set to «OFF» 24 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Instant AP 1.1 Features: Mesh on Instant AP IAP105 Virtual Controller IAP105 Instant Mesh Portal IAP105 Instant Mesh Points Instant Mesh Points - Up to 8 Instant Mesh Points - Max 2 Hops Dual-Radio only (IAP-105) : Instant 1.1 image is required Not supported on IAP92/93 No software configuration: Over-the-air Provisioning (if active IAP) or over-the-wire Max hop count is 2 and up to 8 Instant Mesh Points per Instant Mesh Portal Only a Mesh Portal can be the Virtual Controller LAN Bridging or Secure wired pass-trough is not supported 25 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Instant AP 1.1 Features: Mesh on Instant AP (cont d) 802.11b/g WLAN services Instant Mesh Portal 802.11a 802.11b/g WLAN services Virtual Controller IAP105 Mesh Link IAP105 Instant Mesh Point Mesh link is not software configurable Mesh link is on 5GHz band only WLAN services (local coverage) on 2.4 GHz band Mesh Portal and Points consume AP capacity from Virtual Controller 26 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Reference Documentation 27 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Reference Documentation (available on WLAN Sharepoint) Instant 5.0.3.0-1.1.0.0 User Guide 28 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Key Takeaways 29 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Key Takeaways OmniAccess Instant AP solution without Controller and without Licenses New Features including Mesh Support with Instant 1.1 30 Central Presales OmniAccess Instant AP Update ed2 Sept 2011
Thank You www.alcatel-lucent.com/enterprise twitter.com/aluenterprise facebook.com/aluenterprise youtube.com/user/alcatellucentcorp 31 Central Presales OmniAccess Instant AP Update ed2 Sept 2011