4. 4
HPE Aruba 始終居於市場領導定位
2016年 8月 Gartner 報告肯定 HPE Aruba 的領導地位
This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from Aruba, a Hewlett Packard Enterprise company. Gartner
does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions
of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties or merchantability or fitness for a particular purpose.
Source: Gartner Magic Quadrant for the Wired and Wireless LAN Access Infrastructure
August 2016. Tim Zimmerman, Christian Canales, Bill Menezes, Danilo Ciscato
ID Number: G00291908
• HPE Aruba與思科為僅有的兩家領導品牌
• HPE Aruba 提供單一智慧網路,網路安全,網路管
理輕鬆掌握
市
場
佔
有
率
產品技術
HPE Aruba is Here
11. 11
HPE Aruba Controller 系列
7030
Large branch
Up to 64 APs and up to 8Gbps throughput
Midsize branch with integrated switch
12 or 24 ports of PoE+ for unified branches
Up to 32 APs
Small branch
Virtualized or PoE-powered controllers
Midsize Campus
High performance, fixed form factor
Up to 256 APs, 12 Gbps throughput
Large Campus
High performance, redundant power/fan
512 – 2048 APs, up to 40Gbps throughput
7240
7220
7210
7205
7024 (24 PoE+)
7010 (12 PoE+)
7005/7008 (16 AP)
Branch
Campus
http://www.arubanetworks.com/products/networking/controllers/
12. 12
Broad Portfolio of WLAN Connectivity
飯店專用
103H/203H
2 ports
11n dual
205H/303H
3 ports
11ac dual
PSE
室內型
330 Series 11 ac WAVE 2
4x4 MU-MIMO
Smart Rate (2.5GBASE-T)
戶外型(全向/指向)
270/360 Series
Outdoor
3x3 11ac
惡劣環劣使用
228 Series
Industrial grade
3x3 11ac
HPE Aruba 無線 AP系列紅字:目前熱銷機種, 藍字:未來替代機種
310 Series 11ac WAVE 2
Carpeted space
3x3 MU-MIMO
2.1 Gbps
300 Series 11ac WAVE 2
320 Series 11ac WAVE 2
4x4 MU-MIMO
2.5 Gbps, Dual uplink
200 Series Wave 1
2x2 11ac MIMO
1.2 Gbps
103 /207 Series
Lower cost
2x2 11n /2x2 11ac
600 Mbps
Remote Access Points
RAP-3WN(攜帶型)/203R
2 ports, 2.4GHz, PSE
RAP-108/109(吊掛)
1 port, 11n dual radio
RAP-155(桌機)
4 ports, 11n dual radio, PSE
210 Series 11ac WAVE 1
3x3 MIMO
1.9 Gbps
220 Series 11ac WAVE 1
3x3 MIMO
1.9 Gbps, Dual uplink
http://www.arubanetworks.com/products/networking/access-points/
最常選用規劃的AP型號,另有IAP
版本可選用
飯店旅宿in-wall選用型號
分公司、外點辦公室選用型號,
內建VPN功能
定位系統
13. 13
Controller 集中控管 Thin AP 或
分散式無 Controller (Instant AP, IAP)
Small, temporary &
home office Wi-Fi
Remote APs,
VIA Mobile/Laptop Client
Distributed, controllerless
WLAN with Aruba Instant
Controller-based
WLAN with ArubaOS
Simplified branch
deployment with clusters
Centralized encryption with
advanced services at scale
相同的 AP 硬體
21. 21
HPE OfficeConnect 1 &10 Gigabit Smart Managed Switch
21
Entry – 1G copper only,
VLANs, link aggregation,
loop protection
1620 Switch
Series
Basic – 1G copper and 1G fiber,
VLANs, link aggregation,
STP, RSTP
1820 Switch
Series
Basic – 1G and 10G copper,
VLANs, link aggregation,
STP, RSTP
1850 Switch
Series
Advanced – 1G and 10G copper, 10G fiber,
VLANs, link aggregation, ACLs.
STP, RSTP, MSTP.
Static routing, stacking
1950 Switch
Series
Advanced – 1G copper and 1G fiber,
VLANs, link aggregation, ACLs.
STP, RSTP, MSTP.
Static routing
1920 Switch
Series
Functionality
Features
22. 22
HPE Cloud-First ToR access switches
Top-of Rack, Access
Converged
Infrastructure
FlexFabric
5950
FlexFabric
5940
FlexFabric
5930
FlexFabric
5900/CP
FlexFabric
5700
6125/6127XLG
Moonshot-45XGc
10/25/40/100GbE ToR
Native L2 VXLAN
Support
10/40/100GbE ToR
Native L2/L3 VXLAN
Support
EVPN support
10/40GbE ToR
Native L2 VXLAN
Support
1/10GbE ToR
Full Layer 3 with Data
Center Features (DCB,
FCoE, TRILL, SPB)
Converged ToR
Ethernet/FCoE/FC
(4&8 Gb/s- 5900CP)
1/10GbE ToR
Layer 2/Light Layer 3
with Data Center
features (DCB, FCoE,
TRILL)
HPE BladeSystem
Interconnect
Comware v7 based
High Performance /
Overlay
Competes against
Cisco Nexus 92xx
High Performance /
Overlay
Competes against
Cisco Nexus 92xx
High Performance /
Overlay
Competes against
Cisco Nexus 93xxx
High Performance
Competes against
Cisco Nexus
55xx/5600
Best in class TCO
Competes Against
Cisco Nexus 2K
Feature Rich
Competes against
Cisco 3120x Blade
Switch
No licensing, including
MPLS edge
Convergence every
port
VXLAN GW
No licensing, including
MPLS edge
Convergence every
port
VXLAN GW
Integration with NSX
and Helion as L2
VXLAN GW
Entire stack without
licensing, including
MPLS edge
(SP/Telcos)
Convergence on every
port with IRF
Switching at the cost of
a multiplexer
Power of Comware v7
within Moonshot
23. 23
Switching for the Mobile-First Campus
Gigabit Access Multi-Gig Access
Aruba 2920 Aruba 5400R
POE+
SDN Optimized
Smart Rate
Multi-Gig Ports
Aruba 2530
AirWave &
ClearPass
Stacking
Aruba 2930F
Central
Aruba 2540
VSF VSF
Aruba 3810
24. 24
HPE Aruba Wired & Wireless解決方案示意圖
• 外地出差
• SMALL OFFICE/HOME OFFICE
ClearPass
Airwave
HPE Aruba (Wireless)
Mobility Controller
員工
HPE Aruba
PoE Switch
HPE Aruba
Core Switch
Aruba Remote AP
AD/LDAP
Other user DB
Internet
AP
HPE Aruba Access Switch
FortiGate NGFW
HPE Aruba
802.11ac AP
Desktop User
Laptop Wired User
Soft Phone
Wireless Users
IMC
HPE Aruba
Edge Switch
27. 減少無線網路抱怨
with Aruba 802.11ac and ClientMatch
事先知道無線網路問題,而非事後被抱怨
with Aruba Clarity and AirWave
無線網路除了效能,應力求穩定與可視化管理
不是單用 AP、Controller 的技術規格來比較
應用程式可視化,重要的應用優先
with Aruba AppRF
29. Adaptive Radio Management
解決無線網路訊號及負載問題
• 自動調整最佳 Channel / Power 避免干擾,減少漏洞 (Self-Healing)
• 可識別無線Wi-Fi及非Wi-Fi的訊號干擾
• Controller 集中式的決策控管,避免 AP channel hopping 產生
微波爐
30. Match to
another AP
DEVICE TYPE INTERFERENCELOCATION CONGESTION
REAL-TIME RF CORRELATION
Enables use of
802.11ac Wi-Fi rates
✓ 98% of mobile devices
with higher SNR
✓ 94% better performance
for “sticky” clients
✓ No client-side software
required
Aruba ClientMatch™
•協助用戶端漫遊,避免沾黏於訊號差的AP:Say Goodbye to Sticky Clients
•AP自動負載平衡: 依照頻譜、AP負載量、用戶訊號等分配無線使用者連線
•Band Steering/Band Balancing:協助支援2.4及5GHz雙頻用戶端連線到5GHz頻段,充分利用
5GHz頻段較多,干擾較少的優勢。
38. 39
高擴充及系統穩定性 (ArubaOS)
Virtual Switching Framework (VSF)
2930F with VSF
5400R with VSF Simplify network operations
Scalable performance
Increases resiliency
Available on Aruba 5400R and 2930F
• 5400R – 2 chassis
• 2930F – 4 chassis
39. 40
ArubaOS Switch 免設定自動安裝 (配合 AirWave 及 DHCP server)
DHCP Server
INTERNET
1. Switch boots up and sends a DHCP Discovery with
Option 60: ARUBA 2930F
2. DHCP Server respond with DHCP offer and
populate options 46 with Airwave information :
Airwave Configuration details
Airwave IP : 10.32.202.103
Airwave Group : sko
Airwave Folder : demo
Airwave Secret : aruba123
3. Switch sends registration request to Airwave
4. Airwave Identify the switch and “push“ the
configuration template
5. Switch load the new configuration template reboots and
is now commissioned using ZTP
New Switch
43. 44
AppRF 流量可視化
自動識別 VoIP Calling, 及其他應用程式
• Custom AppRF definitions beyond the 2500
that’s automatically identified by AOS
• Update signatures without an AOS upgrade
• Automatic classification, health metrics for
Wi-Fi calling, Skype for Business, Apple
Facetime, Cisco/Avaya/ALE Voice, and more
47. 48
Aruba Solution:
單一 SSID:支援所有的企業應用程式:讓重要的應用優先
– Application awareness ensures QoS and availability
– Single SSID – multiple traffic classes
– Bi-directional QoS on wired and wireless network
– Admission control for voice and other apps ensures
QoS in the air
– Supports devices with or without WMM
Wireless
Wired
Converged Voice &
Data Packet stream
with WMM Tags
802.1p or DSCP
Prioritized Voice Packets
Data Packets
Protocol aware Voice Flow
Classification and Security
RF Management stops
channel and power
optimization when voice
clients are present
Call admission control
distributes call volume
between Access Points
Single ESSID
for Voice &
Data
Smart Phone
Voice Software
1
2
3
4
5
Deploying Wi-Fi Voice
48. 49
GRE encapsulated
packet
Network
Aruba End-to-End QoS 運作機制 - Tagging
Voice
Data
L3
TOS
L2
COS
L3 TOS bits from the
packet is copied onto
the GRE header
Downstream Traffic
Upstream Traffic
Network
Voice
Data
L3
TOS
L2
COS
Upstream ACLs: ACL on the
switch can overwrite the L2 COS
and L3 TOS
802.11 packet
Downstream ACLs: ACLd on
the switch can overwrite
the L2 COS and L3 TOS
Data TOS COS
50. 51
Aruba 自動分類並自動阻絕非法 AP
BACKBONE
Rogue AP
• 使用者私接入內部網路
• 通常沒有提供足夠安全認證
機制
• 任何可以搜尋到這顆AP並
且連線的人都能輕易繞過防
火牆進入內部網路
Neighboring
Company or
Public Hotspot
Parking Lot
Valid
Interfering
Known Interfering
Rogue
Mobility Controller
Suspected Rogue
56. 57
NEW WAY:
Create your own
Fingerprints!
OLD WAY:
Wait for new Fingerprints to
be made and/or manually
override devices 1:1
ClearPass 進階 Profiling 及 Policy – 解決 IoT 安全問題
58. 59
ClearPass – Profiling 自動分類設備
DHCP
SNMP
SSH
TCP
WMI
CDP, LLDP
OnGuard
Accurate Policy Decision
NMAP
• We’re adding NMAP Port-based Scanner
• On-demand or pre-scheduled scans
• Granular visibility for like devices
• Enhances our competitive advantage
Mac OUI
NMAP Scan
Two IoT Endpoints
AfterBefore
Temperature Sensor
Lighting Sensor
59. 60
Aruba Mobile First 有線無線網路整合Role-Based存取政策
不需再替有線網路埠貼標籤了
提供不只帳號認證,更提供設備自動識別認證
Aruba
ClearPass
SNMP
Enforcement
Printer Vlan Infusion Pump Vlan
現有有線無線
802.1X 認證
識別使用者角色權限
No 802.1X
• Web Portal/802.1x/MAC 認證:Role-based Access
Control
• 沒有認證的設備,自動識別
✓ ClearPass profiling:wired/wireless - IoT, laptops, mobile phones.
60. 61
ClearPass + 有線/無線網路政策一體化:
使用者角色+設備特徵權限分派示意圖
Corporate
Services
Guest
Jeff –
自帶Samsung
Jeff –
自帶 iPhone
HR
Jeff – 公司
Notebook
Virtual AP 1
SSID: Corp
Virtual AP 2
SSID: GUEST
DMZ
ClearPass
CPPM
Onboard/Profile
Captive Portal
Role-Based Firewall
Access Rights
Secure Tunnel
To DMZ
SSID-Based Access
Control
員工
合約廠商
語音設備
視訊影像
Guest
X
AD/LDAP
Aruba AP
Aruba Controller
Aruba MAS
Wired AP
Guest
員工
61. 62
網路聯防安全防護 (內部網路安全)
Adaptive Trust Defense based on real-time threat detection
** Firewall / IPS
LAN/WLAN
User connects and
uploads threat
NGFW/IPS sends
event to ClearPass
ClearPass isolates
client
• Offers enhanced user experience as ClearPass can initiate user
notifications, help-desk tickets, and update third-party security solutions
• ** Device in step 2 can be MDM/EMM, SIEM, etc.
1 2 3
62. 63
BYOD 使用憑證管理傳統與ClearPass方案比較
• Domain
• Key &
Certificate
傳統: Enterprise PKI and CA ClearPass :Built-in CA
Certificate
Authority
Validation
Authority
Registration
Authority
Active
Directory
IT-Managed
Devices
• Domain
• User
• Device
• Key & Unique
Certificate
Personal
Devices
ClearPass
AAA/CA
Certificate
Authority
ADRAVA CA
Active
Directory
AD
NPS/ACS
AAA
69. 行動感知應用:Mobile Engagement低功率藍牙室內定位技術
Meridian
SDK
Indoor maps with
content, push
notification campaigns
and centralized
beacon management
Partners:
App Development
Agencies and
Software Vendors
Smartphone with
the Meridian
powered app
(iOS, Android)
Beacon
management with
Aruba Sensors on
Wi-Fi AP
Beacon
management with
Aruba 802.11ac
access points
70. 71
Mobile Engagement 應用實例
Increase retail sales
Enable shoppers to locate
individual products in-store
Improve fan engagement
Bring indoor venue services
to where the fans are
Increase visitor satisfaction
Personal tour guides with
turn-by-turn directions
71. 72
Location Hardware
Beacons + Sensors + APs
Aruba Beacons
Blue dot directions
and notifications
based on real-time
position
Aruba AP w/
integrated Beacon
Communicates with Aruba
Beacons and Meridian
Platform
802.11ac AP
(310/300/207)
USB Beacons
Used for location +
notifications +
Management
Aruba Sensor
Used for location +
notifications +
Management on
ANY network