SlideShare a Scribd company logo
INSTANT AP – APP RF AND MIXED IAP
CLUSTER DEPLOYMENTS
Technical Climb Webinar
10:00 GMT | 11:00 CET | 13:00 GST
Aug 9th, 2016
Presenter: Barath Srinivasan
barath.srinivasan@hpe.com
2
Welcome to the Technical Climb Webinar
Listen to this webinar using the computer
audio broadcasting or dial in by phone.
The dial in number can be found in the audio
panel, click additional numbers to view local
dial in numbers.
If you experience any difficulties accessing
the webinar contact us
using the questions panel.
3
Housekeeping
This webinar will be recorded
All lines will be muted during the
webinar
How can you ask questions?
Use the question panel on your screen
The recorded presentation will be posted on Arubapedia for
Partners (https://arubapedia.arubanetworks.com/afp/)
INTRODUCTION TO IAP CLUSTERS
5
What is clustering?
IAP’s in the same VLAN will automatically find each other to form a single functioning network
managed by a virtual controller. This is the basic form of the concept called clustering in Instant AP.
Moving an IAP from one cluster to another requires a factory reset of the IAP.
Master
One IAP among the cluster is elected as the cluster master.
This access point is responsible for managing the respective cluster’s configuration
As well as WLAN functionality.
Slave
The non-master AP’s which are being a part of the cluster are called slave-IAP’s.
They rely on the master IAP for obtaining the functional configuration, Regulatory domain, etc.
6
Things you need to know about clustering
Vital points which are considered necessary to be known while implementing cluster
When a new IAP is added into an existing cluster, it can join the cluster only if the existing cluster is
running at least the minimum required version of that AP. If the existing cluster is running a version
below the minimum required version of the new AP, new AP will not come up and may reboot with the
reason Image sync fail. To recover from this condition, upgrade the existing cluster to at least the
minimum required version of the new AP first, and add the new AP.
Adding new AP’s into an existing cluster:
7
Things you need to know about clustering
8
Things you need to know about clustering
It is recommend that – Networks with more than 128 APs be designed as multiple, smaller virtual-controller
networks with Layer-3 mobility enabled between these networks.
Instant 6.4.3.1-4.2.0.0 release introduces support for few new IAP devices. These new devices do not
interoperate with Instant versions lower than 6.4.3.1-4.2.0.0. If these IAPs are placed into a cluster running
older Instant versions such as 6.4.x.x-4.1.x.x, the devices will reboot with the Image Sync Fail reason. To
resolve this issue, upgrade the existing cluster to minimum Instant 6.4.3.1-4.2.0.0 release, and then add the
new IAP devices.
Support for new hardware:
Handling large clusters:
9
Things you need to know about clustering
10
Things you need to know about clustering
Legacy AP support in latest code:
Starting with 6.4.3.1-4.2.0.0 release, Instant does not support IAP-92/93 devices.
Do not upgrade an IAP cluster running IAP-92/93 devices to 6.4.3.1-4.2.0.0 or later release version. In case
of an accidental upgrade, the IAPs will be automatically downgraded. You can manually downgrade IAPs to an
Instant 4.0 or 4.1 release, without losing the existing configuration.
Country code handling:
The Country Code window is displayed for the IAP-RW variants when you log in to the IAP UI for the first time.
The Please Specify the Country Code drop-down list displays only the supported country codes. If the IAP
cluster consists of multiple AP platforms, the country codes supported by the master IAP is displayed for all
other APs in the cluster. Not applicable for US, Israel or Japan IAP’s.
11
How does config push occur in Instant AP
Configuration change propagation across a given IAP cluster
Each command processed by the Virtual Controller is applied on all the slaves in a cluster. The changes
configured in a CLI session are saved in the CLI context. The CLI does not support the configuration data
exceeding the 4K buffer size in a CLI session. Therefore, Aruba recommends that you configure fewer changes
at a time and apply the changes at regular intervals.
12
Zone settings on an IAP
Configuring IAP Zones
All APs in a cluster use the same SSID configuration including master and slave IAPs. However, if you want to
assign an SSID to a specific IAP, you can configure zone settings for an IAP.
Points to remember:
• An IAP can belong to only one zone and only one zone can be configured on an SSID.
• If an SSID belongs to a zone, all IAPs in this zone can broadcast this SSID. If no IAP belongs to the zone
configured on the SSID, the SSID is not broadcast.
• If an SSID does not belong to any zone, all IAPs can broadcast this SSID.
In the Instant UI:
• On the Access Points tab, click the IAP for which you want to set the zone. The edit link is displayed.
• Click the edit link. The edit window for modifying IAP details is displayed.
• Specify the AP zone in Zone.
• Click OK.
13
AppRF - Deep packet inspection
What is DPI? Why is this significant?
AppRF is Aruba's custom built Layer 7 firewall capability. It consists of an on-board deep packet inspection and
a cloud-based Web Policy Enforcement service that allows creating firewall policies based on types of
application.
IAPs with DPI capability analyze data packets to identify applications in use and allow you to create access rules
to determine client access to applications, application categories, web categories and website URLs based on
security ratings. You can also define traffic shaping policies such as bandwidth control and QoS per application
for client roles. For example, you can block bandwidth monopolizing applications on a guest role within an
enterprise.
In the Instant UI:
• Navigate to System >General
• Select Enabled from the AppRF visibility drop-down
• Click OK
14
AppRF – Application Categories
The application category chart displays details on the client traffic towards the application categories. On clicking in the rectangle
area, you can view the relevant graphs and toggle between the chart and list views.
15
AppRF – Application charts (Client)
The application chart displays details on the client traffic towards the applications.
16
AppRF – Web Categories
The web categories chart displays
details about the client traffic to
the web categories.
17
Mixed IAP Clustering + AppRF
Things to note:
• If you mix an IAP-9x in with any other model the cluster will be limited to the lowest common denominator which is
the IAP-9x such that the cluster size max is 16
• AppRF is not fully supported on earlier models of IAPs including the IAP-105 but is fully supported on the newer
models like the IAP-225
• While performing mixed clustering, ensure that the Low capacity AP as well as the high capacity AP are using the
same firmware and the hardware supports the said firmware as well.
18
Mixed IAP Clustering + AppRF
In IAP FW v4.1 - AppRF will be the only feature in 4.1 that imposes limits on the older IAP models. All other features
will work across all models. AppRF is composed of two functions: native Deep Packet Inspection (DPI) and web-
classification / categorization.
For mixed-class deployments (web-filtering-only-supported-aps with full-AppRF-supported-aps) works as follows:
1. Each ap visualizes and enforces the traffic per capability.
• Implies, if app-classification rules are configured on a ap-105, it will be considered a NO-OP. as if that rule does
NOT exist
• But, at the same time, the same app-classification rules will be enforced in the ap-225.
2. For visualization, it is per-ap. You have to click on a AP or client to see the app-rf charts.
• So, in ap-105, the AppRF will ONLY have 2 graphs – the web-category and web-reputation
• In ap-225, all the 4 charts will be shown.
QUESTIONS
Any Questions?
THANK YOU!
21
Bonus! – Best practices
• Keep Wired and Wireless(clients) on separated vlans. Do not mix wired clients and wired clients in the same vlans.
• Enable Broadcast filter if you are able to, one of the biggest issues on the wireless network is the broadcast.
• Enable Broadcast Filter ARP
• Enable Dynamic Multicast Optimization
• Enable AirGroup (for environments where there are many iOS devices)
• Protect wired port of IAP using firewall rules to prevent someone from assigning DHCP IPs to clients by connecting a
rogue DHCP server into the wired port.
• Set any ACLs to classify Lync/Facetime or any other high priority traffic and disable scanning for the same.
• Try not using UNII-I band
• If you can pick an IAP-135 to take advantage of the higher CPU capability
• use a dedicated IAP mgmt vlan for the VC
• Alter the user limit in the ssid to 64
• Set the local probe request threshold to 20dBm
• Enable fair access
• Use VLAN pooling
Try these tips and tricks if you’re facing any issues in your IAP cluster:
THANK YOU FOR ATTENDING THE
SESSION!
(Really this time, no kidding!)

More Related Content

PPTX
Roaming behavior and Client Troubleshooting
PDF
6 understanding aruba rf issues
PPTX
Wireless LAN Design Fundamentals in the Campus
PPTX
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
PPTX
Very High Density (vhd) 802.11ac Wireless Network Design and Deployment Basics
PPTX
EMEA Airheads- ArubaOS - Rogue AP troubleshooting
PPTX
Large scale, distributed access management deployment with aruba clear pass
Roaming behavior and Client Troubleshooting
6 understanding aruba rf issues
Wireless LAN Design Fundamentals in the Campus
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
Very High Density (vhd) 802.11ac Wireless Network Design and Deployment Basics
EMEA Airheads- ArubaOS - Rogue AP troubleshooting
Large scale, distributed access management deployment with aruba clear pass

What's hot (20)

PDF
Aruba instant 6.4.0.2 4.1 user guide
PPTX
Best Practices on Migrating to 802.11ac Wi-Fi
PPTX
Best Practices on Migrating to 802.11ac Wi-Fi
PDF
EMEA Airheads- Instant AP- Instant AP Best Practice Configuration
PPTX
EMEA Airheads ClearPass guest with MAC- caching using Time Source
PPTX
EMEA Airheads How licensing works in Aruba OS 8.x
PDF
Optimizing Aruba WLANs for Roaming Devices
PDF
EMEA Airheads- Troubleshooting 802.1x issues
PPTX
Palo Alto Networks 28.5.2013
PDF
EMEA Airheads- Instant AP traffic optimization
PPTX
Advanced RF Design & Troubleshooting
PPTX
Airheads Tech Talks: Advanced Clustering in AOS 8.x
PPTX
EMEA Airheads- ArubaOS - Cluster Manager
PPTX
Hot standby router protocol (hsrp) using
PPTX
EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
PDF
Advanced rf troubleshooting_peter lane
PPTX
Palo Alto Networks PAN-OS 4.0 New Features
PPTX
Airheads Meetups- High density WLAN
PPTX
Enabling AirPrint & AirPlay on Your Network
PDF
EMEA Airheads- ArubaOS - Understanding Control-Plane-Security
Aruba instant 6.4.0.2 4.1 user guide
Best Practices on Migrating to 802.11ac Wi-Fi
Best Practices on Migrating to 802.11ac Wi-Fi
EMEA Airheads- Instant AP- Instant AP Best Practice Configuration
EMEA Airheads ClearPass guest with MAC- caching using Time Source
EMEA Airheads How licensing works in Aruba OS 8.x
Optimizing Aruba WLANs for Roaming Devices
EMEA Airheads- Troubleshooting 802.1x issues
Palo Alto Networks 28.5.2013
EMEA Airheads- Instant AP traffic optimization
Advanced RF Design & Troubleshooting
Airheads Tech Talks: Advanced Clustering in AOS 8.x
EMEA Airheads- ArubaOS - Cluster Manager
Hot standby router protocol (hsrp) using
EMEA Airheads - Aruba Remote Access Point (RAP) Troubleshooting
Advanced rf troubleshooting_peter lane
Palo Alto Networks PAN-OS 4.0 New Features
Airheads Meetups- High density WLAN
Enabling AirPrint & AirPlay on Your Network
EMEA Airheads- ArubaOS - Understanding Control-Plane-Security
Ad

Viewers also liked (20)

PDF
EMEA Airheads- Aruba OS- Mobile First Platform– Aruba OS 8.0 introduction
PPTX
EMEA Airheads- ArubaOS - High availability with AP Fast Failover
PDF
EMEA Airheads – Aruba controller features used to optimize performance
PDF
EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...
PDF
EMEA Airheads- ClearPass - Dot1x_ Purpose of domain joining
PDF
EMEA Airheads - Aruba Central- Managing Networks from the Cloud
PPTX
Enhancing mobile apps in the public facing enterprise with the aruba meridian...
PPTX
A consolidated virtualization approach to deploying distributed cloud networks
PPTX
Best practices in deploying and managing aruba bluetooth low energy (ble) bea...
PPTX
Working with mobile app developers to enable indoor location based services
PPTX
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
PPTX
Benefits of disaggregation and open source networking in data centers
PPTX
The new imperative in the data center with workload centric networking
PPTX
Hpe Intelligent Management Center
POTX
Packets never lie: An in-depth overview of 802.11 frames
PPTX
A-to-Z design guide for the all-wireless workplace
PPTX
Aruba WLANs 101 and design fundamentals
PPTX
EMEA Airheads- ClearPass extensions and how they can help
PPTX
Access Management with Aruba ClearPass
PPTX
New Branch IT Opportunities: Enhanced Performance & Reduced Costs
EMEA Airheads- Aruba OS- Mobile First Platform– Aruba OS 8.0 introduction
EMEA Airheads- ArubaOS - High availability with AP Fast Failover
EMEA Airheads – Aruba controller features used to optimize performance
EMEA Airheads- Aruba IAP Webinar – How AirGroup service works in Aruba Instan...
EMEA Airheads- ClearPass - Dot1x_ Purpose of domain joining
EMEA Airheads - Aruba Central- Managing Networks from the Cloud
Enhancing mobile apps in the public facing enterprise with the aruba meridian...
A consolidated virtualization approach to deploying distributed cloud networks
Best practices in deploying and managing aruba bluetooth low energy (ble) bea...
Working with mobile app developers to enable indoor location based services
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
Benefits of disaggregation and open source networking in data centers
The new imperative in the data center with workload centric networking
Hpe Intelligent Management Center
Packets never lie: An in-depth overview of 802.11 frames
A-to-Z design guide for the all-wireless workplace
Aruba WLANs 101 and design fundamentals
EMEA Airheads- ClearPass extensions and how they can help
Access Management with Aruba ClearPass
New Branch IT Opportunities: Enhanced Performance & Reduced Costs
Ad

Similar to EMEA Airheads- Instant AP- APP REF and Mixed IAP Cluster deployments (20)

PPT
Preparing Your Apps For iOS9
PDF
Airwaveand arubabestpracticesguide
PPTX
Vsc 71-se-presentation-training
PDF
IXP Automation with SaltStack and NAPALM
PDF
power9_performance_best_practices_IBM_AIX.pdf
PPTX
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
PDF
PDF
Webinar NETGEAR - WiFi 11AC gestito con il controller virtuale ENSEMBLE
PPTX
Ibm spectrum scale fundamentals workshop for americas part 1 components archi...
PDF
Webinar NETGEAR - Nuovi AP Professionali Prosafe WAC720 e WAC730
PPTX
EMEA Airheads - Multi zone ap and centralized image upgrade
PPTX
PDF
Exclusive SAP Basis Training Book | www.sapdocs.info
PDF
Introduction to Structured Streaming
PDF
Webinar NETGEAR - La gestione wireless centralizzata con la modalità Ensemble
PPTX
Webinar: How to captures and analyzes NetFlow, J-Flow and sFlow data
PPTX
stackArmor Security MicroSummit - Next Generation Firewalls for AWS
PPTX
Product Update Webinar 2009
PDF
Puertos utilizados sap
PDF
Basic concepts for_clustered_data_ontap_8.3_v1.1-lab_guide
Preparing Your Apps For iOS9
Airwaveand arubabestpracticesguide
Vsc 71-se-presentation-training
IXP Automation with SaltStack and NAPALM
power9_performance_best_practices_IBM_AIX.pdf
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
Webinar NETGEAR - WiFi 11AC gestito con il controller virtuale ENSEMBLE
Ibm spectrum scale fundamentals workshop for americas part 1 components archi...
Webinar NETGEAR - Nuovi AP Professionali Prosafe WAC720 e WAC730
EMEA Airheads - Multi zone ap and centralized image upgrade
Exclusive SAP Basis Training Book | www.sapdocs.info
Introduction to Structured Streaming
Webinar NETGEAR - La gestione wireless centralizzata con la modalità Ensemble
Webinar: How to captures and analyzes NetFlow, J-Flow and sFlow data
stackArmor Security MicroSummit - Next Generation Firewalls for AWS
Product Update Webinar 2009
Puertos utilizados sap
Basic concepts for_clustered_data_ontap_8.3_v1.1-lab_guide

More from Aruba, a Hewlett Packard Enterprise company (20)

PPTX
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
PPTX
EMEA Airheads_ Advance Aruba Central
PPTX
EMEA Airheads- Switch stacking_ ArubaOS Switch
PPTX
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
PPTX
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
PPTX
EMEA Airheads- Aruba Central with Instant AP
PPTX
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
PPTX
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
PPTX
EMEA Airheads - AP Discovery Logic and AP Deployment
PPTX
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
PPTX
EMEA Airheads- Manage Devices at Branch Office (BOC)
PPTX
EMEA Airheads - What does AirMatch do differently?v2
PPTX
Airheads Meetups: 8400 Presentation
PPTX
Airheads Meetups: Ekahau Presentation
PPTX
Airheads Meetups- Avans Hogeschool goes Aruba
PPTX
EMEA Airheads - Configuring different APIs in Aruba 8.x
PPT
Bringing up Aruba Mobility Master, Managed Device & Access Point
PPTX
EMEA Airheads- Aruba 8.x Architecture overview & UI Navigation
PDF
EMEA Airheads- Aruba Instant AP- VPN Troubleshooting
PPTX
EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
EMEA Airheads_ Advance Aruba Central
EMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
EMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads - What does AirMatch do differently?v2
Airheads Meetups: 8400 Presentation
Airheads Meetups: Ekahau Presentation
Airheads Meetups- Avans Hogeschool goes Aruba
EMEA Airheads - Configuring different APIs in Aruba 8.x
Bringing up Aruba Mobility Master, Managed Device & Access Point
EMEA Airheads- Aruba 8.x Architecture overview & UI Navigation
EMEA Airheads- Aruba Instant AP- VPN Troubleshooting
EMEA Airheads– Aruba Clarity. Because a Wi-Fi Problem's Often Not a "Wi-Fi" P...

Recently uploaded (20)

PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PPT
Teaching material agriculture food technology
PPTX
Machine Learning_overview_presentation.pptx
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
cuic standard and advanced reporting.pdf
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Encapsulation_ Review paper, used for researhc scholars
Assigned Numbers - 2025 - Bluetooth® Document
The Rise and Fall of 3GPP – Time for a Sabbatical?
Reach Out and Touch Someone: Haptics and Empathic Computing
Dropbox Q2 2025 Financial Results & Investor Presentation
Per capita expenditure prediction using model stacking based on satellite ima...
SOPHOS-XG Firewall Administrator PPT.pptx
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
Teaching material agriculture food technology
Machine Learning_overview_presentation.pptx
Accuracy of neural networks in brain wave diagnosis of schizophrenia
Diabetes mellitus diagnosis method based random forest with bat algorithm
Spectral efficient network and resource selection model in 5G networks
Digital-Transformation-Roadmap-for-Companies.pptx
cuic standard and advanced reporting.pdf
gpt5_lecture_notes_comprehensive_20250812015547.pdf
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Advanced methodologies resolving dimensionality complications for autism neur...

EMEA Airheads- Instant AP- APP REF and Mixed IAP Cluster deployments

  • 1. INSTANT AP – APP RF AND MIXED IAP CLUSTER DEPLOYMENTS Technical Climb Webinar 10:00 GMT | 11:00 CET | 13:00 GST Aug 9th, 2016 Presenter: Barath Srinivasan barath.srinivasan@hpe.com
  • 2. 2 Welcome to the Technical Climb Webinar Listen to this webinar using the computer audio broadcasting or dial in by phone. The dial in number can be found in the audio panel, click additional numbers to view local dial in numbers. If you experience any difficulties accessing the webinar contact us using the questions panel.
  • 3. 3 Housekeeping This webinar will be recorded All lines will be muted during the webinar How can you ask questions? Use the question panel on your screen The recorded presentation will be posted on Arubapedia for Partners (https://arubapedia.arubanetworks.com/afp/)
  • 5. 5 What is clustering? IAP’s in the same VLAN will automatically find each other to form a single functioning network managed by a virtual controller. This is the basic form of the concept called clustering in Instant AP. Moving an IAP from one cluster to another requires a factory reset of the IAP. Master One IAP among the cluster is elected as the cluster master. This access point is responsible for managing the respective cluster’s configuration As well as WLAN functionality. Slave The non-master AP’s which are being a part of the cluster are called slave-IAP’s. They rely on the master IAP for obtaining the functional configuration, Regulatory domain, etc.
  • 6. 6 Things you need to know about clustering Vital points which are considered necessary to be known while implementing cluster When a new IAP is added into an existing cluster, it can join the cluster only if the existing cluster is running at least the minimum required version of that AP. If the existing cluster is running a version below the minimum required version of the new AP, new AP will not come up and may reboot with the reason Image sync fail. To recover from this condition, upgrade the existing cluster to at least the minimum required version of the new AP first, and add the new AP. Adding new AP’s into an existing cluster:
  • 7. 7 Things you need to know about clustering
  • 8. 8 Things you need to know about clustering It is recommend that – Networks with more than 128 APs be designed as multiple, smaller virtual-controller networks with Layer-3 mobility enabled between these networks. Instant 6.4.3.1-4.2.0.0 release introduces support for few new IAP devices. These new devices do not interoperate with Instant versions lower than 6.4.3.1-4.2.0.0. If these IAPs are placed into a cluster running older Instant versions such as 6.4.x.x-4.1.x.x, the devices will reboot with the Image Sync Fail reason. To resolve this issue, upgrade the existing cluster to minimum Instant 6.4.3.1-4.2.0.0 release, and then add the new IAP devices. Support for new hardware: Handling large clusters:
  • 9. 9 Things you need to know about clustering
  • 10. 10 Things you need to know about clustering Legacy AP support in latest code: Starting with 6.4.3.1-4.2.0.0 release, Instant does not support IAP-92/93 devices. Do not upgrade an IAP cluster running IAP-92/93 devices to 6.4.3.1-4.2.0.0 or later release version. In case of an accidental upgrade, the IAPs will be automatically downgraded. You can manually downgrade IAPs to an Instant 4.0 or 4.1 release, without losing the existing configuration. Country code handling: The Country Code window is displayed for the IAP-RW variants when you log in to the IAP UI for the first time. The Please Specify the Country Code drop-down list displays only the supported country codes. If the IAP cluster consists of multiple AP platforms, the country codes supported by the master IAP is displayed for all other APs in the cluster. Not applicable for US, Israel or Japan IAP’s.
  • 11. 11 How does config push occur in Instant AP Configuration change propagation across a given IAP cluster Each command processed by the Virtual Controller is applied on all the slaves in a cluster. The changes configured in a CLI session are saved in the CLI context. The CLI does not support the configuration data exceeding the 4K buffer size in a CLI session. Therefore, Aruba recommends that you configure fewer changes at a time and apply the changes at regular intervals.
  • 12. 12 Zone settings on an IAP Configuring IAP Zones All APs in a cluster use the same SSID configuration including master and slave IAPs. However, if you want to assign an SSID to a specific IAP, you can configure zone settings for an IAP. Points to remember: • An IAP can belong to only one zone and only one zone can be configured on an SSID. • If an SSID belongs to a zone, all IAPs in this zone can broadcast this SSID. If no IAP belongs to the zone configured on the SSID, the SSID is not broadcast. • If an SSID does not belong to any zone, all IAPs can broadcast this SSID. In the Instant UI: • On the Access Points tab, click the IAP for which you want to set the zone. The edit link is displayed. • Click the edit link. The edit window for modifying IAP details is displayed. • Specify the AP zone in Zone. • Click OK.
  • 13. 13 AppRF - Deep packet inspection What is DPI? Why is this significant? AppRF is Aruba's custom built Layer 7 firewall capability. It consists of an on-board deep packet inspection and a cloud-based Web Policy Enforcement service that allows creating firewall policies based on types of application. IAPs with DPI capability analyze data packets to identify applications in use and allow you to create access rules to determine client access to applications, application categories, web categories and website URLs based on security ratings. You can also define traffic shaping policies such as bandwidth control and QoS per application for client roles. For example, you can block bandwidth monopolizing applications on a guest role within an enterprise. In the Instant UI: • Navigate to System >General • Select Enabled from the AppRF visibility drop-down • Click OK
  • 14. 14 AppRF – Application Categories The application category chart displays details on the client traffic towards the application categories. On clicking in the rectangle area, you can view the relevant graphs and toggle between the chart and list views.
  • 15. 15 AppRF – Application charts (Client) The application chart displays details on the client traffic towards the applications.
  • 16. 16 AppRF – Web Categories The web categories chart displays details about the client traffic to the web categories.
  • 17. 17 Mixed IAP Clustering + AppRF Things to note: • If you mix an IAP-9x in with any other model the cluster will be limited to the lowest common denominator which is the IAP-9x such that the cluster size max is 16 • AppRF is not fully supported on earlier models of IAPs including the IAP-105 but is fully supported on the newer models like the IAP-225 • While performing mixed clustering, ensure that the Low capacity AP as well as the high capacity AP are using the same firmware and the hardware supports the said firmware as well.
  • 18. 18 Mixed IAP Clustering + AppRF In IAP FW v4.1 - AppRF will be the only feature in 4.1 that imposes limits on the older IAP models. All other features will work across all models. AppRF is composed of two functions: native Deep Packet Inspection (DPI) and web- classification / categorization. For mixed-class deployments (web-filtering-only-supported-aps with full-AppRF-supported-aps) works as follows: 1. Each ap visualizes and enforces the traffic per capability. • Implies, if app-classification rules are configured on a ap-105, it will be considered a NO-OP. as if that rule does NOT exist • But, at the same time, the same app-classification rules will be enforced in the ap-225. 2. For visualization, it is per-ap. You have to click on a AP or client to see the app-rf charts. • So, in ap-105, the AppRF will ONLY have 2 graphs – the web-category and web-reputation • In ap-225, all the 4 charts will be shown.
  • 21. 21 Bonus! – Best practices • Keep Wired and Wireless(clients) on separated vlans. Do not mix wired clients and wired clients in the same vlans. • Enable Broadcast filter if you are able to, one of the biggest issues on the wireless network is the broadcast. • Enable Broadcast Filter ARP • Enable Dynamic Multicast Optimization • Enable AirGroup (for environments where there are many iOS devices) • Protect wired port of IAP using firewall rules to prevent someone from assigning DHCP IPs to clients by connecting a rogue DHCP server into the wired port. • Set any ACLs to classify Lync/Facetime or any other high priority traffic and disable scanning for the same. • Try not using UNII-I band • If you can pick an IAP-135 to take advantage of the higher CPU capability • use a dedicated IAP mgmt vlan for the VC • Alter the user limit in the ssid to 64 • Set the local probe request threshold to 20dBm • Enable fair access • Use VLAN pooling Try these tips and tricks if you’re facing any issues in your IAP cluster:
  • 22. THANK YOU FOR ATTENDING THE SESSION! (Really this time, no kidding!)

Editor's Notes

  • #19: http://community.arubanetworks.com/t5/Technology-Blog/Web-Content-Classification-a-powerful-new-policy-tool-for-the/ba-p/194391