34
Avaya WLAN 9100 Overview

1 - Avaya WLAN 9100 Overview - PT-BR

Embed Size (px)

DESCRIPTION

1 - Avaya WLAN 9100 Overview - PT-BR

Citation preview

Avaya WLAN Controller or Controllerless

Avaya WLAN 9100 Overview

1

Arquitetura Wi-Fi e fluxo do trfegoControle DistribudoControle na borda para melhor performanceSem ponto nico de falhaEscalabilidade melhoradaInteligncia distribuda

Controle CentralizadoProcessamento centralizado cria gargalos na redePonto nico de falhasEscalabilidade limitadaEstreita Inteligncia

Gerenciamento centralizado do trfego 2014 Avaya Inc. Avaya Confidential & ProprietaryDo not duplicate, publish or distribute further without the express written permission of Avaya.SPoF

Gerenciamento do trfego na bordaLet start with a brief review of WLAN architecture to understand where we stand and why Architecture has to change. On the left you have one of the most deployed architecture today. With the increase number of unwired devices plus the bandwidth over the air achievable with 802.11n up to 600Mbps and tomorrow with 11ac up to 1Gbps, a centralized architecture will start ot shows its limitations. SPOFCentral processing of the traffic.Avaya WLAN 9100, provides a distributed architecture which will remove these limitation by:Removing the SPOF. Delivering intelligence at the edge, Qos, packet filteringMuch more scalable for the next ssantdard 11ac. instead of increasing the number of AP and controller.

2Comparao da arquitetura: Inteligncia na borda

2014 Avaya Inc. Avaya Confidential & ProprietaryDo not duplicate, publish or distribute further without the express written permission of Avaya.

AvayaAlso as you can see on this slide by putting DPI at the edge on the AP we have a first level of protection at the edge in addition of what you can already have in the core like FW, UTM .Spreading DPI across AP vs having all done at the controller. DPI being a processor intensive mechanism.3Portflio WLAN 9100 - O que est disponvel?Prxima gerao de redes Wi-Fi com desempenho previsivel802.11acPlanejamento simplificado de RFControle de QoS por aplicaoArquitetura WLAN com controladora distribudaUpgrades sem troca de hardwareGerenciamento na nuvem Software nicoImplementao flexvelSuporte ao servio Bonjour WAP 9122WAP 9123WAP 9132WAP 9133WAO 9122 (Outdoor)WAP 9162/9173802.11n 2x2 AP802.11n 3x3 AP802.11ac 2x2 AP802.11ac 3x3 AP802.11n 2x2 AP802.11ac 2x2 / 3x3 2 Radios2 Radios2 Radios2 Radios2 Radios2 or 4 RadiosConjunto de funcionalidades avanadas Controladora IntegradaControle da aplicaoProvisionamento ZeroGerenciamento local ou Gerenciamento na nuvem4

2014 Avaya Inc. Avaya Confidential & ProprietaryDo not duplicate, publish or distribute further without the express written permission of Avaya. Arquitetura WLAN distribudaSo what are we launching in May? Describe the slide.4WAP 9122 & 9123 access pointsAP Indoor dual rdio com antenas omni-direcionaisModelos:WAP 9123: 3x3 11nWAP 9122: 2x2 11nRdio programvel por softwareBanda dual 2.4GHz e 5GHzMltiplos modos 802.11a/b/g/n802.11ac disponvel com upgrade de softwareControladora integradaServios Integrados:Controle de Aplicao: Visibilidade e Aplicao de PoliticasSegurana: WIDS/WIPS, Firewall, Guest AccessAnaltica: Anlise espectral, captura de pacotesUplink Gigabit Ethernet dualAlimentado por 802.3at POE+ (9122 pode usar POE)Gerenciamento e Provisionamento na Nuvem ou no local 2014 Avaya Inc. Avaya Confidential & ProprietaryDo not duplicate, publish or distribute further without the express written permission of Avaya.

5

WAP 9132 & 9133 access pointsAP dual radio com antenas omni-direcionaisModelos:WAP 9133: 3x3 11acWAP 9132: 2x2 11acRdio Programvel por Software Banda dual 2.4GHz e 5GHzMltiplos modos 802.11a/b/g/n/acControladora IntegradaServios Integrados:Controle de Aplicao: Visibilidade e Aplicao de PoliticasSegurana: WIDS/WIPS, Firewall, Guest AccessAnaltica: Anlise espectral, captura de pacotes Uplink Gigabit Ethernet dualAlimentado por 802.3at POE+Gerenciamento e Provisionamento na Nuvem ou no local 2014 Avaya Inc. Avaya Confidential & ProprietaryDo not duplicate, publish or distribute further without the express written permission of Avaya. At A Glance this AP support Dual radio

2x2 802.11ac AP with 1.7Gbps total Wi-Fi bandwidth for 9132 and up to 3x3 802.11ac AP with 2.6Gbps total Wi-Fi bandwidth for 9133 Two software programmable radios for mixed 2.4/5GHz or dual concurrent 5GHz operation 802.11ac speed optimization Integrated omni-directional, internal antennas Supports up to 240 users with 2 1Gbps uplinks Integrated Controller On-premise management 6WAO 9122 access pointAP Outdoor dual radio com antena externaAntena com conector externo RP-TNC dois por rdioAntenas externas direcionais 35 / 90 graus de aberturaOmni-direcional (360 graus)Modelos:WAO 9122: 2x2 11nRdio Programvel por SoftwareBanda dual 2.4GHz and 5GHzMltiplos modos 802.11a/b/g/nControladora integradaServios Integrados:Controle de Aplicao: Visibilidade e Aplicao de Politicas Segurana: WIDS/WIPS, Firewall, Guest AccessAnaltica: Anlise espectral, captura de pacotes nico Uplink Gigabit EthernetAlimentado por 802.3af POEGerenciamento e Provisionamento na Nuvem ou no local

2014 Avaya Inc. Avaya Confidential & ProprietaryDo not duplicate, publish or distribute further without the express written permission of Avaya.

9122 Outdoor Access Point provides WLAN technology in a hardened case for harsh environments. The unique case design protects the AP electronics from rain, heat, cold, direct sun, and wind. The hardened Access Point includes two software programmable (2.4GHz and 5GHz) radios with two lightning protected RP-TNC style connectors each, integrated wireless controller, application-level intelligence, automated provisioning, and cloud management (optional) contained in a hardened case. The outdoor 9122 AP is designed to meet requirements for extending wireless coverage outdoors or in other harsh environments such as playgrounds, campus quads, stadium stands and warehouse freezers. In addition the 9122 is an ideal candidate for high speed point-to-point wireless data links directly connecting networks across streets, building. At A Glance Dual radio 300Mbps (2x2 MIMO) 802.11n AP

It is completely dust sealed and meets the requirements for IP65. The product has been tested to operate in temperatures as low as -40C and as high as +55C.72x2 e 3x3 11ac?O que significa 2x2 e 3x3 11ac?2x2 = 2 antenas, 2 fluxos de dados3x3 = 3 antenas, 3 fluxos de dados Fluxos adicionais prov banda adicional

Qual a velocidade de 2x2 e 3x3 11ac?2x2 = taxas de at 867Mbps por rdio3x3 = taxas de at 1.3Gbps por rdio11ac 3X mais rpido que 11n

2014 Avaya Inc. Avaya Confidential & ProprietaryDo not duplicate, publish or distribute further without the express written permission of Avaya. Ive been talking about the new satndard 802.11ac. Heres a high level detai lof whats coming.First of all like 11n , 11ac will be the second wlan standard to use MIMO technology. Mimo technology allows the sender to use multiple antennas and receive on multiple antennas. Therefore sending data across multiple spatial streams. By doing this it is easy to understand how we can achieve u pto 1gbps over the air. 11ac in phase 1 will allow up to 8 spatial stream vs 11n up to 4 (600Mbps). A huge number assuming that in order to achieve tis we need to have the same amount of antennas on the client side with all the implication it can have.8Lembre-se: Performance Wi-fi est limitado pelo dispositivoMaioria dos clientes BYOD so 1x1 ou 2x2 e no tem a vantagem de 3 fluxos em infraestrutura WiFi 3x3

Dispositivo2.4GHz5GHzAntenasTaxa Mx.Media Players (iPod Touch)XAlguns1x165-150 MbpsSmartphones low endX1x165 MbpsSmartphones high endXX1x1150 MbpsTablets low endX1x165 MbpsTablets high end (iPad)XX2x2300 MbpsLaptops low endXMaioria2x2300 MbpsLaptops mid/high endXX3x3450 Mbps

A very important thing to keep in mind on this slide is that not every product are born the same performance. Therefore putting all this devices on a wireless network can have a significant impact.9

Implementando diferentes tecnologias 11ac com AVAYA WLAN 9100Onde voc utilizaria 2x2 11ac vs. 3x3 11ac?Use 2x2 em clientes com baixa ou mdia densidade de usuriosUse 3x3 em reas de alta densidade ou onde se utiliza mais notebooksQual o principal benefcio do 2x2 11ac?Reduo de custos de upgrade de infraestruturatimo para conexes 1x1 & 2x2 de smartphones, tablets e laptops low end

= # streams

1.3Gbps

150Mbps

65Mbps

300Mbps

24Mbps

13Mbps

123131x

124Mbps

6Mbps

1Read the slide10Programao de 2 bandas por rdio 5GHz ou 2.4GHzProgramao de 6 modos Wi-Fi por rdio 802.11 a/b/g/n em2.4 GHz / n/ac em 5GHz

11ac11n 5GHz

11ac11ac

11ac11n 2.4GHz

11n 5GHz11n 2.4GHz

11ac11n 2.4GHz

APs dos Concorrentes:Configurao nicaAPs AvayaConfiguraes flexveisRDIOS PROGRAMVEIS POR SOFTWARE 2014 Avaya Inc. Avaya Confidential & ProprietaryDo not duplicate, publish or distribute further without the express written permission of Avaya.A very nice feature here. Normally AP comes with fix radio 2.4 and 5. On 9100 AP you can change the radio by a software and therefore be able to run 2 radio on 5Ghz and apply different combinations on each radio 11n ,, 11ac.

11802.11ac OTIMIZAO DE PERFORMANCEO ProblemaWi-Fi um meio compartilhado cliente de baixa velocidade reduzem a performance de clientes de alta velocidadeA SoluoSeparao de clientes com velocidades diferentes em rdios diferentesMaximizar a performance do sistema para TODOS os clientes 2014 Avaya Inc. Avaya Confidential & ProprietaryDo not duplicate, publish or distribute further without the express written permission of Avaya.

This station load balancing or kind of band steering+ provides several key benefits: Improved network performance available to Wi-Fi stations. Since each radio has a definedmaximum amount of bandwidth, reducing the number of users on more heavily loaded radioswill ensure more average bandwidth available per station. Better use of radio resources by ensuring more radios are servicing stations and not idle. More efficient use of Wi-Fi spectrum by reduction in packet retries and packet errors on heavilyloaded radios. Enables the AP to influence station connection decisions. Making these decisions centrally asopposed to distributed per station provides greater control over the allocation of resources.12HONEYPOT LIMPANDO O MEIO AREO

SSID = honeypothoneypothoneypothoneypot

OtherSSID

OtherSSID

OtherSSID

OtherSSIDDead VLANNo TrafficLimpando o meio areo para melhorar a performance removendo solicitaes falsas de clientes no associados

Some situations pose problems for all wireless APs. For example, iPhones will remember every SSID and flood the airwaves with probes, even when the user doesnt request or desire this behavior. In very high density deployments, these probes can consume a significant amount of the available wireless bandwidth, especially on the 2.4Ghz radio. The 9100 AP offers a feature targeting this problema honeypot SSID. Simply create an SSID named honeypot (lower-case) on the AP, with no encryption or authentication (select None/Open). Once this SSID is created and enabled, it will respond to any station probe looking for a named open SSID (unencrypted and unauthenticated) that is not configured on the AP. It will make the station go through its natural authentication and association process. 13Potncia de Transmisso (TX) de RF do APRedes de alta densidade de hoje j no esto focadas na rea mxima que um nico rdio pode cobrir. Cobertura vs. Capacidade.Incrementado o nmero de dispositivos por pessoa e por metro quadrado esto demandando ambientes pequenos, de alta capacidade, e com clulas WiFi

Avaya fornece baixssima transmisso de potncia (menos de -15dBm) para criar clulas muito pequenas de cobertura, maximizando a performance

A medida que a densidade e a utilizao aumentamperformance das redes wireless se deterioram

Sensibilidade de recepo RF (RX) do APRedes de alta peformance requerem que clientes wireless tenham as melhores taxas de transmisso possveis e banda que a rede pode oferecer.Ajustando os valores limites de RX pode garantir que clientes com sinal muito fraco e consequentemente baixas taxas de transmisso no impactem de forma negativa em clientes com bom sinal de RF.

AP da Avaya permite ajustar a sensibilidade de recepo por rdio.Com o design de rede sem fio apropriado, voc pode garantir que todos os seus clientes tenham o melhor sinal possvel.

300Mbps

6.5Mbps

300Mbps

6.5Mbps

Como isto beneficia vocTecnologia de RF avanada prov diferenciais e proporciona uma maior diferenciao da concorrnciaPotncia de TX extremamente baixa prov:Melhor uso e reuso dos canais 2.4GHz com clulas muito pequenas (pico cell).Reduz a quantidade de interferncia co-canal dos APs no ambiente (interferncia entre rdios com o mesmo canal)Ajuste de sensibilidade de recepo RX prov:Garantia da associao de dispositivos que tem melhor conexo e banda possvel.Elimina efeitos negativos de clientes com baixo sinal.Prov zonas de RF no go. reas em que a cobertura de WiFi proibida devido s polticas da empresa.

16

MelhorPerformance

Cascata (Daisy Chain)

Menos cabos

Dispositivos locais

Menos cabos

Link Backup

Maior resilinciaModos de uplinks GigE flexveisAgregao de Link

All AP models except the outdoor AP have more than one Gigabit port.These ports may be bonded, i.e. configured to work together in sets. For example, one port may provide active backup or load balancing for another, or other options as described in this section.You may use the mirror option to have all the traffic that is ingressing and egressing one bond be transmitted by the bond you are configuring. For example, if you configure Bond2 to mirror Bond1, then all traffic going in and out of Bond1s Gigabit ports will be transmitted out of Bond2s Gigabit ports. This way of duplicating one bonds traffic to another bond is very useful for troubleshooting with a network analyzer. 802.3ad and Load Balancing modes increase the resiliency of the wired connection by providingdual active connections. If one link fails, the other will continue to service traffic. 802.3ad and Load Balancing modes achieve greater uplink performance by providing a total 2Gbps throughput connection from the AP. Bridge mode (or daisy chain)extends the reach of a wireless network by allowing AP to be wired directly toeach other in a daisy chain fashion, eliminating cable runs and wired switch ports in the wiringcloset. Link Backup provides for fail-over resiliency of the wired connection if a GigE port fails. Broadcast mode provides fault tolerance by transmitting all traffic on both GigE ports. Mirror mode simplifies network troubleshooting of your network. If Gig1 is connected to yourcorporate network, Mirror mode can be configured on that Wi-Fi Array with a wired packetcapture connected to Gig2 to monitor inbound and outbound Gig1 traffic.17Funcionalidade em destaque controle da aplicao Principais BenefciosMelhora experincia do usurio, priorizando aplicativos crticos sobre aplicativos no crticos, reduzindo carga de rede.Controle de poltica granular, bloqueando, estrangulando ou aplicando QoS para os aplicativos diretamente na borda da rede

Wireless is quickly becoming the primary access to the network. Unlike wired users, mobile users expect to connect anytime, anywhere at home, in the office, in classrooms, and at conferences with dependency on mobile applications and cloud-access now business-critical. Application downloads, online backups, and cloud application usage will continue to grow, increasing the traffic demands on networks for years to come.

Millions of Wi-Fi enabled smartphones, tablets, and laptops are activated daily, many of which make their way onto corporate networks. This led to a significant growth in user-driven, non-managed applications on these networks. Smartphone users on average have over 40 apps on their phones ranging from Facebook to Email.1

Primary Benefits With an average wireless equipment refresh cycle of 4-5 years, it is vital for customers looking to purchase a new system today to consider this down the road towards accommodating the expected continued explosion of devices and applications on their networks. Avaya Application Control, offers a number of key unique benefits. Improved user experience, Prioritize critical over best effort applications at the network edge for optimal performance throughout the network Improved visibility Identify bandwidth-hogging apps and analyze usage trends over time Superior scalability Distributed intelligence for limitless growth DPI compute power added by AP, not in a stair step fashion with centralized appliance Reduced network costs Control Internet WAN uplink network traffic by dropping or throttling at the network edge Reduced application risk Block risky or out-of-policy applications from accessing the network Superior resiliency Distributed functionality in each AP means no single point of failure for applying application control policies

18Avaya Application Control O que diferente ?Mecanismo DPI completo - Implementao DPI na camada 7Deteco bem acurada e profunda de aplicaes: 1200+Utiliza um modelo de correspondncia avanado, heurstico, e consciente de fluxo, etc.Performance superior com 2-6 ncleos de processadores por APAP tradicional tem peformance limitada, geralmente 1 ncleo de processdorOpera na borda da rede onde o controle BYOD mais requisitadoCompetidores utilizam solues implementadas com controladoras/appliances centralizadas

Firewall, apply QoS, manage 1,200 individual or groups of applications under 15 categories using Layer 7 Deep Packet Inspection (DPI) and other contextual application detection techniques. 19Funcionalidade em destaque Bonjour Director Benefcios

Permite a utilizao de servios Apple (ex.: AirPrint, AirPlay) e dispositivos (ex.: tablets, AppleTV, impressoras) na rede corporativa

Melhora performance em ambiente carregado de dispositvos Apple pelo controle do trfego mDNS que pode deteriorar a rede wirelessBonjour Director prov controle do trfego Apple mDNS que permite a utilizao de dispositivos iOS na rede corporativa

For hostnames as well as service advertisement and discovery, Apple implemented a multicast version of DNS, where devices self-assign hostnames and also advertise and request services using a specific IPv4 and IPv6 multicast address. This is referred to as mDNS and is detailed in the Internet Engineering Task Force (IETF) mDNS draft document. Apples mDNS protocol uses specific IPv4 and IPv6 multicast addresses, that are in the Local Network Control Block Multicast address space as defined in IETF RFC 5771 and IETF RFC 4291. mDNS uses the following IPv4 and IPv6 multicast addresses and port number MAC address 01:00:5E:00:00:FB IPv4 address 224.0.0.251 IPv6 address FF02::FB UDP port 5353

By using the Local Network Control Block addresses, mDNS was intended to be restricted to a single Local Area Network, as the Local Network Control Block addresses are not routed and do not need to use Internet Group Management Protocol (IGMP), as IGMP is used by IP routers and gateways to manage Multicast groups and multicast traffic in multi-subnet routed networks. This is now creating issues in larger organizations, as Apple iOS applications that use mDNS such as Airplay and Airprint, and Apple devices such as AppleTV, find their way into classrooms and meeting rooms, and their users expect them to work the same as they do in their home network environment. 20Funcionalidade em destaque Otimizao do espectro RFProteo de InvestimentoPotncia extremamente baixaEstendido controle de potncia para reduzir tamanho da clula, incrementando a densidade de usurios servidosHoneypotAssocia automaticamente dispositivos WiFi sem uso em locais pblicos para reduzir sobrecarga e incrementar capacidade de RF

5GHz2.4GHzFuturo a provaRdio Programado por SoftwareEscolhe 5GHz ou 2.4GHz para adaptar s mudanas de clientes WiFi, comparado a configurao fixa de APs tradicionais.

Funcionalidade em destaque Controle flexvel do RdioControle individual de cada rdio por:Banda configurao para operao de 2.4GHz ou 5GHzCanal Configurao manual ou automticaTamanho da clula Configurao manual ou automtica de 1 a 20dBmModo Wi-Fi Configurao para 11n somente, 11b somente, 11bgn, etc.

Associao individual dos rdios para separar os SSIDs

Funcionalidade em destaque Wireless IDS/IPSIntrusion Detection System e Instrusion Prevention System integrado em cada AP com recursos de rdio dedicadoClassificao dos Rogues (Aprovados/Conhecidos/Desconhecidos) e bloqueio opcional

Reconhecimento e alertas de ataques tipo DoS (Denial of Service) e mascaradosLimites das ameaas configurvel

Funcionalidade em destaque Anlise espectralMonitoramento dedicado nos rdios de cada APMonitoramento dos espectro em todos canais RF 24x7Atividade, rudo/interferncia, relao Sinal/Rudo, Erros, sinal mdio, etc.

WOS Wireless Orchestration System WOS est disponvel em arquivo formato .ova

O pacote Appliance Virtual deve ser instalado em VMware ou MS Hyper-V.

Para acessar, colocar no endereo do browser (URL) o endereo do servidor WOS seguido por :9090. Login=admin/admin

WOS Servidor corporativo - RecomendaesSoluo Corporativa Virtual Appliance - VMware ou Hyper-VWOS - VMINSTALAO PEQUENAINSTALAO MDIAINSTALAO GRANDEMximo APs505002000Mx. Estaes (clientes) gerenciados15001000025000Processador Mnimo Recomendado2 cores4 cores8 coresMemria RAM mnima recomendado4GB8GB16GBArmazenamento de massa mnimo recomendado150GB/Thin provision300GB/Thin provision500GB/Thin provisionVMWare OS recomendadoVMware ESXi or VSphere 5.0+Microsoft Hyper-V Server 2012 R2 (Standalone)ou Windows Server 2012 R2 com Hyper-V RoleNota: em toda nstalao VM, um tem que deve tomar cuidado no super dimensionar RAM quando usar o Virtual WOS Appliance Exemplo quando existir 3 instncias de mquinas virtuais no sistema que tem 8 GB de RAM cada, quando no sistema total deveria ter nada menos que 3*8GB = 24 GB.Funcionalidades WOSInterface Web

Wireless Heat Maps

Localizao de dispositivos

Gerenciamento de upgrade centralizado

Monitorao segurana

Relatrios

Funcionalidade WOS Interface WebDashboard view prov sumrio do status e atividade do sistema em tempo realStatus do AP e do Rdio

Banda AP/Radio

Viso geral de Rogue & ameaas

Alarmes mais recentes

Informao das estaesInterface Web prov acesso via navegador a todas as informaes e gerenciamento da rede

Funcionalidade WOS Wireless heat mapOrganiza os APs por localizao fsica em mapas carregados no sistemaPreviso de cobertura wireless de toda rede de APs

Funcionalidade WOS Localizao de dispositivosLocaliza Rogues, Dispositivos e EquipamentosA funo de localizar entra no Mapa mostrando a localizao dos dispositivoscones distinguem os tipos de dispositivos existentesClique para mostrar os detalhes e soluo de problemas

Funcionalidade WOS Monitoramento da seguranaMonitorao contnua por Rogues e dispositivos no autorizadosAlertas automticos notificam os administradores de descobertas de dispositivos

Agregao visual dos alertas do sistema IDS

Funcionalidades WOS RelatriosDzias de relatrios pr-definidos para utilizao, performance, seguranaRastreabilidade da operao da rede do ltimo dia, semana, ms, ano

Diferencial Avaya WLAN11ac disponvel em todos os rdios = 100% ACControle da aplicao = ferramenta DPI L7 com mais de 1200+ assinaturas de aplicaesProgramvel por software = 11n ou 11ac / 2.4GHz ou 5GHzControle de Banda = maximiza performance do cliente11acControladora Integrada = maximiza performance, reduz TCO

34