SlideShare a Scribd company logo
Five Steps to a Faster, Smarter
Wireless LAN

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
What Drives our Market?

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Mobility Effect #1 –
More Mobile Devices

 2013: More mobile
devices than people
 2017: 19x increase in
mobile data usage

10 Exabytes. 45% Offloaded to Wi-Fi
HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Mobility Effect #2 –
Cloud Evolution

 2012: Public cloud projects surpassed $100B+

 Cloud traffic comes from mobile devices: 70% more in 2013.

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Mobility Effect #3 –
Bring Your Own

 Avg 3.3 connected
devices/employee (by 2014)

 40% devices accessing business
apps are
employee owned

 Over half the networks
were breached in 2012
due to personal devices

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Mobility Effect #4 –
There’s An App for Everything

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Attributes of Next Generation
Workplace

• Wireless Everywhere
• BYO-Everything
• Self Service

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Five Steps to a Faster,
Smarter WLAN
Session One: Building Your Wireless LAN
– Step 1: Providing faster and smarter Wi-Fi with 802.11ac
– Step 2: Planning your mobility network architecture

Break
Session Two: Supporting Your Users & Their Devices
– Step 3: Smart policy creation and BYOD enforcement
– Step 4: Device and app management
– Step 5: Extending mobile services to visitors and customers

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Step 1
Providing faster and smarter Wi-Fi
with 802.11ac

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Why 11ac ? - Capacity & Bandwidth

More devices
• Average 3
devices per
user
• Smartphone,
tablets,
laptops,
ultrabooks

More
applications per
device
• Average 40
apps per
mobile device
• Estimates >
300 billion app
downloads by
2016

More traffic

Shift in W-Fi
Usage

• HD mobile
video, video
telepresence,
collaboration
programs
• Tablet traffic ~
3.4x greater
than
smartphone
traffic

• Pervasive,
primary access
• Mission critical
• Multimedia –
Voice, IPTV,
older legacy
media
transport
systems (i.e.
cable TV)

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
802.11ac Technology Overview
Think of 11ac as an extension of 11n
11n specification:

11ac introduces

• 2.4 and 5 GHz

• 5 GHz only

• 40 MHz channels

• Wider channels (80 MHz &160 MHz)

• 64-QAM modulation

• Better modulation (256-QAM)

• Up to 4 streams

• Additional streams (up to 8)

• Explicit & implicit beam forming

• Beam forming (explicit)

• Backwards compatible w/ 11a/b/g

• Backwards compatible w/ 11a/b/g/n
• Refer to http://www.802-11.ac.net for
in-depth information

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Wider Channels
80 MHz channel widths supported in first
generation
– 80 MHz is 4.5x faster than 20 MHz
– 80 MHz is contiguous
– Per packet dynamic channel width decisions

Future releases will allow for 160 MHz channel
widths
– 160 MHz can be either contiguous or in two noncontiguous 80 MHz slices

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
802.11ac Channels (FCC)
UNII I and UNII II
2x 80 MHz
4x 40 MHz
8x 20 MHz
Channel
Freq (MHz)

Band
Edge
5150

36

40

5180

44

52

56

60

5220

5200

48
5240

5260

5280

5300

64
5320

Band
Edge
5350

UNII II extended
3x 80 MHz
6x 40 MHz
12x 20 MHz
Channel
Freq (MHz)

Band
Edge
5470

Band
Edge

100

104

108

112

116

120

124

128

132

136

140

144

5500

5520

5540

5560

5580

5600

5620

5640

5660

5680

5700

5720 5725

Channel

Band
Edge

149

153

157

161

165

Freq (MHz)

5725

5745

5765

5785

5805

5825

Band
Edge
5850

US UNII III
1x 80 MHz
2x 40 MHz
5x 20 MHz

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
More Spatial Streams
Spec allows up to 8 spatial streams (4 max in 802.11n)
– 8SS performance will only be possible where both devices have 8
antennas
– Space, power and cost constraints will dictate the number of
streams supported by the client
• Smart phones – 1 stream
• Tablets – 2 stream
• Laptops – 2 or 3 streams

– Speed of connection is decided by the device with the lowest
number of streams.

Adding spatial streams increases throughput
proportionally.
– Assuming multipath conditions are favorable:
• Two streams offer double the throughput of a single stream
• Eight streams increase throughput eight-fold
HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
AP Throughput > 1Gbps

“How fast can I go?”
– Simple question with very complicated answer
– Depends on many factors
•
•
•
•

Device type
Distance
Signal to Noise Ratio (SNR)
Access Point configuration
•
•
•
•

Channel width
Number of Spatial Streams
Short/long guard intervals
Link aggregation

– Your mileage WILL vary

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Max Data Rates per Client Type
Channel
bandwidth

Transmit – Receive
antennas

Typical client scenario

Max individual link rate

Max aggregate link
rate

40 MHz

3x3

PC

606 Mbps

606 Mbps

80 MHz

1x1

Smartphone

433 Mbps

433 Mbps

80 MHz

2x2

Tablet, PC

867 Mbps

867 Mbps

80 MHz

3x3

PC

1300 MBPS

1300 MBPS

160 MHz

1x1

Smartphone

867 Mbps

867 Mbps

160 MHz

2x2

Tablet, PC

1.73 Gbps

1.73 Gbps

160 MHz

4x Tx AP,
4 clients of 1x Rx

Multiple smartphones

867 Mbps per client

3.47 Gbps

160 MHz

8x Tx AP, 4 clients
with total of 8x Rx

Digital TV, set-top box,
tablet, PC, smartphone

867 Mbps to two 1x clients
1.73 Gbps to one 2x client
3.47 Gbps to one 4x client

6.93 Gbps

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
11ac Clients are Already Here!

11ac Clients
– Samsung Galaxy S4 (1x1:1 11ac)
• 20 million units as of July 5th

–HTC One (1x1:1 11ac)
• 5 million sold in first 45 days
–2013 MacBook Air (2x2:2 11ac)

–USB dongles (2x2:2 11ac)
• Look for USB 3.0

No significant impact on client battery life
HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Pros and Cons of 802.11ac Spec
Pros
1. APs can accommodate more users/devices
• Increased capacity

2. Standards based Explicit Beam-forming increases SNR
• Higher data rates over longer distances

3. 256-QAM
• Increased throughput at high SNRs
• Improved modulation and coding techniques

4. Multi-User MIMO (future generations)
• Improved utilization of RF capacity

5. Use of 5 GHz spectrum
• More non-overlapping channels
• Quieter RF environment

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Pros and Cons of 802.11ac
Cons
1. Hardware update required to support 802.11ac
• Some features will not be available on legacy devices

2. 802.3at (PoE+) is required to attain full benefit of
802.11ac
• 802.3af (PoE) can be used on the AP-22x, but it will limit the full features
and functionality available with 802.11ac

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Planning for .11ac migration
1. RF bands (2.4 GHz, 5 GHz)?

2. Channel width per band (20 vs. 40 vs. 80Mhz)?
3. Apps (Voice? MC Video?) now and in the future
4. Real-time location services (RTLS)?
5. Devices per user?
6. Max devices per AP?

7. Wired network capacity & power?
8. Accessible floor plan images?
9. DFS?

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Purpose-built Aruba 220 Series

• 3x3:3 Dual Radio
• 5GHz 11ac: up to 1.3Gbps

• 2.4GHz 11n: up to 450Mbps
(600Mbps with Broadcom clients)

• 2x GE link aggregation
• Enabling >1Gbps TCP throughput

Controller-managed &
Controllerless

• Operates with 802.3af, requires
802.3at for full functionality

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
AP-225 Purpose-built = No Design
Compromises

Powerful
CPU &
memory

Custom
antenna
design

Smaller &
lighter

Cost
effective

Higher
density

Better RF
coverage

Easier to
install

$1,295

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
802.11ac TCP Download – 214 Mbps
at 120 feet

Mbps

802.11ac TCP Download Performance
800
700
600
500
400
300
200
100
0
1SS
2SS
3SS

15ft
238
572
705

30ft
235
417
640

75ft
193
402
393

100ft
161
281
283

120ft
154
202
214

Distance from AP in feet

Test Clients: Windows 7 Laptop with 3 stream 802.11ac radio, Macbook Air
with 2 stream 802.11ac client and Samsung Galaxy S4 smartphone with 1SS
Test Goal: Test TCP download performance at increasing distance from AP for
devices with varying capabilities
Test Result: Aruba AP-225 delivers peak performance of 705 Mbps. Even at
120ft, the clients gets upto 214Mbps throughput
HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
802.11n TCP Download: AP-225
Delivers 325% More
Single Macbook Pro - 3x3:3 11n
300

Mbps

250
200
150
100

50
0
AP-225
AP-135

15
275
248

30
269
230

75
186
120

120
128
30

Distance from AP (ft)

Test Client: MacbookPro with 3 stream 802.11n radio
Test Goal: Test TCP download performance at increasing distance from AP to
see if 11n client performance is improved on 11ac Access Point
Test Result: Aruba AP-225 delivers upto 325% improved performance for 11n
clients compared to 802.11n access points
HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
802.11ac Voice Performance –
Almost 400ft Range
Call dropped at 275ft

Voice call with GS4 - Skype – 5G
Call did not drop at 400ft
But could not hear voice

Voice call with GS4 - Skype – 2.4G
Call dropped at 210ft

Voice call with HTC Skype – 5G
Call dropped at 370ft

Voice call with HTC Skype – 2.4G

0

50

100

150

200

250

300

350

400ft

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
ClientMatch™
Enables 802.11ac Wi-Fi
REAL-TIME RF CORRELATION

DEVICE TYPE

LOCATION

CONGESTION

Match to
another AP

Patent:
8,401,554

INTERFERENCE

Enables use of
802.11ac Wi-Fi rates
 98% of mobile devices
with higher signal quality
 94% better performance
for “sticky” clients
 No client-side software
required

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Client Health Visibility

After
Before
ClientMatch

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Demos

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Demo 1 – RF Capacity
What you will see:
– AP distribution by channel utilization
– Channel utilization for every AP radio
– Drill down to an AP with high utilization
• Identify root cause

– Drill down to an AP with low or less utilization
• Show why this AP is in “green zone”

Why it matters
– Helps identify areas requiring additional capacity
– Identify areas that will benefit with 11ac upgrade

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Demo 2 – RF Performance and
ClientMatch
What you will see:
– Overall client health
– Drill down to unhealthy client
• Identify root cause

– Drill down to healthy client
• See ClientMatch in action

Why it matters:
– Single client with poor performance impacts entire network
performance
– Helps identify potential design changes to boost performance

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Demo 3: Aruba AppRF Technology
What You will see:
–
–
–
–
–

App usage dashboard
Identify URL traffic via DNS resolution
Heuristics and ALGs to fingerprint UC apps
Prioritize business traffic over personal
Wired/wireless/VPN

Why it Matters
–
–
–
–

Identify web services and UC traffic, and prioritize
75% better UC performance
30% more video on iPads
11x faster mobile apps

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY

WebEx
Sharepoint
Supply
Chain
Exchange
Oracle
Google
Demo 4: AirWave AppRF
What You will see:
– You can see that you will be able to get historical data of AppRF on
AirWave, allowing you to get historical trending
– You can examine new applications as they gain popularity amongst
your population

Why it Matters
– While APP RF is nice, you will likely want the history
– You can define better policy

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Demo 5: Lync Dashboard
What You will see:
– Lync visibility adds an additional level data points when examining
traffic.
– Track usage of voice protocols along side Lync
– Understand prioritization requirements on the network

Why it Matters
– Speeds up troubleshooting, points to network or client/server
issues
– Justify investments in additional equipment, validate investments in
technology
– Better Lync call traffic, higher usage, higher customer satisfaction.

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Step 2
Planning your mobility network
architecture

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Two different architectures

Controller
Controllerless

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Evolution of the architectures
1st generation
128 APs
2,048 devices

2nd generation
512 APs
8,064 devices

3rd generation
2048 APs
32,768 devices

Autonomous APs
had no coordination

Current controllerless APs have equivalent CPUs and
memory to 1st generation controller architectures
HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Deployment overview

Controllers
Complex network topologies
Centralized encryption / switching
Larger mobility domains
Advanced services at scale

Controllerless
Less complex local networks
Many individual remote sites
Simplified management
Minimal onsite HW and cost

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Mixed Architectures
Controllerless
APs at remote
sites

IAP
IAP

AP Group “BLDG#1”

IAP
Controller at main
campus

Access
Switch

WWW
Mobility
Controller

AirWave for
consolidated
management

VPN from
APs or 3rd
party VPN

Distribution
/ Core

Content
Filters

RADIUS/AD

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Convertible Architectures
Controllerless
APs directed to
the controller

IAP
IAP

IAP

AP Group “BLDG#1”

Add a controller
to the network

Mobility
Controller

Controllerless
APs software
conversion to
controller based
APs

Access
Switch

Distribution
/ Core

Content
Filters

RADIUS/AD

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Cloud Wi-Fi

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
How Does it Work?
• Zero-touch provisioning:
AP pulls configuration
from Aruba Central

Aruba Central

• AP self-selects as master
• Master performs firewall
and controller functions
Instant AP

Instant OS

• New APs automatically
join the master
HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Aruba Central Services Platform
Public cloud subscription
One interface
– Multiple sites
– Multiple clusters in a single
site

Enterprise management

– Remote monitoring &
troubleshooting
– Central configuration &
firmware management
– Compliance records and
historical data
– True Zero Touch provisioning

Comprehensive e-Support
and community

HQ

BRANCH
BRANCH

BRANCH
HOME OFFICE

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Single Architecture, Multiple Modes
Public Cloud, Private
Cloud, & Local
Management Options

Free local
management
Aruba Central

Aruba AirWave
AD / RADIUS
Mobility Access
Switch

Internet
Mobility
Controller
Mobility Access
Switch

Free local
management

Enterprise HQ

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Demo Aruba Activate & Aruba
Central

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
BREAK

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Step 3
Smart policy creation and BYOD
enforcement

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Why Network Access Control?

Smartphone
and Tablet
Growth

Users are
More Mobile

Rise of
Mobile Apps

Enterprise
and BYOD
Together

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Evolving Auth/Authz needs
New policy and AAA dynamics
– No longer just authenticating Windows domain devices.
– Use of more 802.1X to lock down open ports/SSIDs.
– Meeting SSO requirements for cloud applications (e.g. SAML,
Okta).

Why context for fine grained Authorization
– Ability to layer multiple authorization rules and conditions.
– Leverages context stored in a variety of 3rd party systems.

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Challenges with legacy RADIUS
Visibility and troubleshooting
– No capability to profile devices connecting to the network.
– No contextual awareness (e.g. posture, device type, asset type).
– Poor per session troubleshooting tools and logs.

Scalability and reliability
– Limited performance to handle EAP termination or higher loads.
– Poor active clustering technology and centralized management.

Narrow feature sets
– Limited to core AAA, TACACS+ (ACS/SBR products are
EOL/EOS)

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Network Policy Best Practices
Most organizations do a fair job of authentication (who
the user is) -- But, a poor job of authorization (what the
user is allowed to do based on context)
1. Profile and authenticate everything that connects to your network.
2. Place ClearPass close to Active Directory or other Identity/Context
servers to reduce latency.
3. Leverage context to provide fine grained authorization.
4. Utilize access infrastructure that supports CoA and role based
access control versus VLAN segmentation.
5. Use standards based protocols for enhanced network security.

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
The ClearPass Platform
High performance AAA
– Up to 300 auths/second for 802.1X with AD.
– Supports distributed, active/active clustering and bursting.
– Hardware and virtual appliance platforms.

Multi-faceted policy services
– Uses standards based Web APIs to receive additional context
from new sources (e.g. identity stores, MDM)
– Supports multiple enforcement actions.

Extensive support for emerging standards and multivendor products.

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Network Policies Based on Context
Policy Example

Use context from ClearPass &
external sources to set network
policy

• User/group
membership

• Device Profile
• Location
• Application
• Time/Date
• OS version
installed
• eg. in semester • Trusted or
• Endpoint health
untrusted
• blacklisted
• Jailbreak status
network
• Pincode/encryption
HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
ClearPass for IT-managed and BYOD
Network
Control

Device Profiling
& Visibility

Device/User
Control

App
Control

MDM
Services

Contextual
Policies

AAA – RADIUS,
TACACS+

Device
Registration

3rd-party App
Security

Policy Engine &
Management

Visitor
Management

Enterprise App
Store

BYOD
Onboarding

Work Space
Security & Privacy

Health Checks

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Demo

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Demo: Defining Policies
What you will see . . .
1. Creating a Wi-Fi service
2. Onboarding a personal
device
– Limiting a 2nd device by the
same user

3. Enabling guest selfregistration
– Keeping IT-managed devices
off the guest network

Yes

No

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Step 4
Device and App Management

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Policy Enforcement Options

NAC / AAA

•
•
•
•

VLAN
ACLs
QoS
Authentication

MDM

•
•
•
•
•
•

Device Provisioning & Onboarding
Device Policy
Device Level Encryption
Passcode
Full Wipe
App blacklist / whitelist

MAM

•
•
•
•
•
•

Authentication
App Passcode
App Wipe
App Policies
App SSO
App VPN

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Protect Your MDM Investment

3rd Party MDM

ClearPass

Exchange
endpoint context
& trigger policies

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Use ClearPass to Enhance MDM/MAM
Wi-Fi based MDM enrollment
• End reliance on SMS or e-mail invitations
• Link MDM agent to captive portal

Auto-remediate non-compliant devices
• Quarantine devices by blacklist
• Redirect to self-service portal
• Push reminders about policy violation

In-built CA for provisioning credentials
• Unique device certificates using SCEP
• No need for PKI to support BYOD

Use MDM device context for network security
• Deny/limit network access to jailbreak or rooted devices
HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Use MDM Attributes for Network
Policy

Inventory

Manufacturer:
Model:
OS Version:
UDID
Serial Number
IMEI
Phone Number
Carrier
MDM Id
Owner
Display Name
Ownership

Posture

MDM Attributes
Apple
iPad2
iOS 6.1
1730235f564094186
79049XXXA4S
012416009780168
408-534-2819
Verizon
130d0f992t34
jhoward
John Howard
Employee Liable

MDM Enabled
Yes
Compromised
Not Jailbroken
Encryption Enabled
Yes
Blacklisted Apps
No
Required Apps
Yes
Last Check in HUNTING FOR FASTER, SMARTER WI-FI?
01/30/2012 9:03am
YOU’RE IN GOOD COMPANY
ClearPass MDM Integration
Using MDM device information for Policy

CoA triggers
network
enforcement

Endpoint data
replicated to
ClearPass cluster
Device type & posture
polled for policy
decisions & reporting
MDM

ClearPass
ClearPass
HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Integrating Leading MDM Vendors
• ClearPass uses public APIs for:

• Normalize MDM endpoint data across vendors

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Enterprise Policy Beyond the Network
Use Case: Compromised Device
Context
Push Notification

Enforcement

Push

Device
ClearPass
Role, Captive Portal

Identity = keerti

User

Aruba Access Network

Authorization

MDM
HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Enterprise Policy Beyond the Network
Use Case: MDM Profile Removed
Context
SMS or Voice Call

Enforcement

Big Brother

Device
ClearPass
Role, Captive Portal

Identity = student27

User

Aruba Access Network

Authorization

MDM

School Principal
HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Step 5
Extending mobile services to
visitors and customers

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Location-Based Mobile Services on
the Rise
Retail

Hospitals

80% of the world owns a mobile
phone. And we’re using them in
the venues we visit

Hotels

Campus

Transportation

27% of companies worldwide
intend to implement locationbased mobile marketing in 2013
HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Wi-Fi Concierge Inside Venues

Way-Finding

Indoor turn-by-turn
directions

Push Notifications

Time & location
relevant messaging

Analytics

Dwell-time and
traffic insights

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Wi-Fi Concierge Solution
Components
Analytics Service

Meridian Editor

Aruba Wi-Fi

“BluDot,” Nav, &
Zone-based content

Featuring Analytics &
Location Engine

Meridian App
(white-label/custom)

20+ third party
products

Active Wi-Fi
Connection Not
Needed

HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
Key Take Aways
Integrate Network, Device and App Management
• Stronger security, simplified rollouts: Complete solution
for BYOD and IT-managed network access policy
management

Ensure Multi-vendor Support
• Integration flexibility: Standards based enforcement
across any Wi-Fi, wired and VPN infrastructure

Plan for Growth and Change
• Adapt to the environment: Support a wide variety of
use-cases and phased deployment – BYOD, AAA, guest
access, compliance initiatives…
HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY
HUNTING FOR FASTER, SMARTER WI-FI?
YOU’RE IN GOOD COMPANY

More Related Content

PDF
Airheads scottsdale 2010 maximizing 11n performance
PDF
Air heads rio 2010 aruba pef overview
PDF
Aruba webinar dorm wi fi design v4
PDF
2012 ah apj wi fi design for voice & video
PDF
Rf troubleshooting advanced kelly griffin_peter lane
PDF
Advanced rf troubleshooting_peter lane
PDF
Airheads barcelona 2010 rf design for retail warehousing manufacturing
Airheads scottsdale 2010 maximizing 11n performance
Air heads rio 2010 aruba pef overview
Aruba webinar dorm wi fi design v4
2012 ah apj wi fi design for voice & video
Rf troubleshooting advanced kelly griffin_peter lane
Advanced rf troubleshooting_peter lane
Airheads barcelona 2010 rf design for retail warehousing manufacturing

What's hot (20)

PDF
4 healthcare forum deploying vocera on aruba wlan_kevin huey
PDF
2012 ah vegas mobile device fundamentals
PDF
2012 ah vegas rf troubleshooting
PDF
12012 ah apj rf fundamentals
PDF
2012 ah vegas wlan design for high density
PDF
2012 ah vegas remote networking fundamentals
PDF
Optimizing wlan operations peter lane
PDF
Security advanced rich langston_jon green
PDF
2012 ah apj rf troubleshooting
PDF
Outdoor network engineering jeffrey weaver
PDF
Mobility access switches_madani adjali
PDF
Designing for the all wireless office ash chowdappa-kelly griffin
PDF
1 voice and video over wi fi-balajee krishnamurthy
PDF
2012 ah vegas deploying byod
PDF
2012 ah apj mobile device fundamentals
PDF
2012 ah apj keynote - technology update
PDF
Instant overview gokul_rajagopalan
PDF
2012 ah emea top 10 tips from aruba tac
PDF
11ac and client match for the awo ash chowdappa
4 healthcare forum deploying vocera on aruba wlan_kevin huey
2012 ah vegas mobile device fundamentals
2012 ah vegas rf troubleshooting
12012 ah apj rf fundamentals
2012 ah vegas wlan design for high density
2012 ah vegas remote networking fundamentals
Optimizing wlan operations peter lane
Security advanced rich langston_jon green
2012 ah apj rf troubleshooting
Outdoor network engineering jeffrey weaver
Mobility access switches_madani adjali
Designing for the all wireless office ash chowdappa-kelly griffin
1 voice and video over wi fi-balajee krishnamurthy
2012 ah vegas deploying byod
2012 ah apj mobile device fundamentals
2012 ah apj keynote - technology update
Instant overview gokul_rajagopalan
2012 ah emea top 10 tips from aruba tac
11ac and client match for the awo ash chowdappa
Ad

Viewers also liked (6)

PDF
EMEA Airheads- Aruba OS- Mobile First Platform– Aruba OS 8.0 introduction
PDF
Lync over Aruba Wi-Fi Validated Reference Design Guide
PDF
PDF
RAP Networks Validated Reference Design
PDF
Aruba Remote Access Point (RAP) Networks Validated Reference Design
PDF
Aruba 802.11ac networks: Validated Reference Designs
EMEA Airheads- Aruba OS- Mobile First Platform– Aruba OS 8.0 introduction
Lync over Aruba Wi-Fi Validated Reference Design Guide
RAP Networks Validated Reference Design
Aruba Remote Access Point (RAP) Networks Validated Reference Design
Aruba 802.11ac networks: Validated Reference Designs
Ad

Similar to 5 steps to a faster, smarter wlan (20)

PPTX
Breakout - Airheads Macau 2013 - 11ac Migration (7200)
PPTX
BT WIFI NFC.pptx
PPTX
Next Generation Wi-Fi – What 802.11ac Means to You
PPTX
Best Practices on Migrating to 802.11ac Wi-Fi
PPTX
Best Practices on Migrating to 802.11ac Wi-Fi
PDF
PPTX
PLNOG14 - Wireless Cloud, a new business for operators - Jochen Müdsam
PDF
Webinar NETGEAR - Linee guida per il disegno di una rete wireless a elevate p...
PPTX
Best Practices on Migrating to 802.11ac Wi-Fi #AirheadsConf Italy
PDF
Conquering the 802.11ac Shift
PPT
12 01-nowak motorola 4 g fcc tac dec00
PPTX
5G wireless technology ppt
PPT
5G Wireless.ppt
PPT
PPTX
5G technology
PDF
Reg en-ap8232 ss
PPTX
802.11n Technology - Presented by Meru Networks and DTC
PDF
PPTX
seminar ppt.pptx
Breakout - Airheads Macau 2013 - 11ac Migration (7200)
BT WIFI NFC.pptx
Next Generation Wi-Fi – What 802.11ac Means to You
Best Practices on Migrating to 802.11ac Wi-Fi
Best Practices on Migrating to 802.11ac Wi-Fi
PLNOG14 - Wireless Cloud, a new business for operators - Jochen Müdsam
Webinar NETGEAR - Linee guida per il disegno di una rete wireless a elevate p...
Best Practices on Migrating to 802.11ac Wi-Fi #AirheadsConf Italy
Conquering the 802.11ac Shift
12 01-nowak motorola 4 g fcc tac dec00
5G wireless technology ppt
5G Wireless.ppt
5G technology
Reg en-ap8232 ss
802.11n Technology - Presented by Meru Networks and DTC
seminar ppt.pptx

More from Aruba, a Hewlett Packard Enterprise company (20)

PPTX
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
PPTX
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
PPTX
Airheads Tech Talks: Advanced Clustering in AOS 8.x
PPTX
EMEA Airheads_ Advance Aruba Central
PPTX
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
PPTX
EMEA Airheads- Switch stacking_ ArubaOS Switch
PPTX
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
PPTX
PPTX
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
PPTX
EMEA Airheads- Aruba Central with Instant AP
PPTX
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
PPTX
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
PPTX
EMEA Airheads - AP Discovery Logic and AP Deployment
PPTX
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
PPTX
EMEA Airheads- Manage Devices at Branch Office (BOC)
PPTX
EMEA Airheads - What does AirMatch do differently?v2
PPTX
Airheads Meetups: 8400 Presentation
PPTX
Airheads Meetups: Ekahau Presentation
PPTX
Airheads Meetups- High density WLAN
PPTX
Airheads Meetups- Avans Hogeschool goes Aruba
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Advanced Clustering in AOS 8.x
EMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
EMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads - What does AirMatch do differently?v2
Airheads Meetups: 8400 Presentation
Airheads Meetups: Ekahau Presentation
Airheads Meetups- High density WLAN
Airheads Meetups- Avans Hogeschool goes Aruba

Recently uploaded (20)

PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Approach and Philosophy of On baking technology
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Advanced IT Governance
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Modernizing your data center with Dell and AMD
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
NewMind AI Monthly Chronicles - July 2025
Spectral efficient network and resource selection model in 5G networks
Advanced methodologies resolving dimensionality complications for autism neur...
Understanding_Digital_Forensics_Presentation.pptx
Approach and Philosophy of On baking technology
Chapter 3 Spatial Domain Image Processing.pdf
Review of recent advances in non-invasive hemoglobin estimation
Reach Out and Touch Someone: Haptics and Empathic Computing
Network Security Unit 5.pdf for BCA BBA.
Advanced IT Governance
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Dropbox Q2 2025 Financial Results & Investor Presentation
Diabetes mellitus diagnosis method based random forest with bat algorithm
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
Mobile App Security Testing_ A Comprehensive Guide.pdf
Modernizing your data center with Dell and AMD
20250228 LYD VKU AI Blended-Learning.pptx
Unlocking AI with Model Context Protocol (MCP)
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf

5 steps to a faster, smarter wlan

  • 1. Five Steps to a Faster, Smarter Wireless LAN HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 2. What Drives our Market? HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 3. Mobility Effect #1 – More Mobile Devices  2013: More mobile devices than people  2017: 19x increase in mobile data usage 10 Exabytes. 45% Offloaded to Wi-Fi HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 4. Mobility Effect #2 – Cloud Evolution  2012: Public cloud projects surpassed $100B+  Cloud traffic comes from mobile devices: 70% more in 2013. HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 5. Mobility Effect #3 – Bring Your Own  Avg 3.3 connected devices/employee (by 2014)  40% devices accessing business apps are employee owned  Over half the networks were breached in 2012 due to personal devices HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 6. Mobility Effect #4 – There’s An App for Everything HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 7. Attributes of Next Generation Workplace • Wireless Everywhere • BYO-Everything • Self Service HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 8. Five Steps to a Faster, Smarter WLAN Session One: Building Your Wireless LAN – Step 1: Providing faster and smarter Wi-Fi with 802.11ac – Step 2: Planning your mobility network architecture Break Session Two: Supporting Your Users & Their Devices – Step 3: Smart policy creation and BYOD enforcement – Step 4: Device and app management – Step 5: Extending mobile services to visitors and customers HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 9. Step 1 Providing faster and smarter Wi-Fi with 802.11ac HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 10. Why 11ac ? - Capacity & Bandwidth More devices • Average 3 devices per user • Smartphone, tablets, laptops, ultrabooks More applications per device • Average 40 apps per mobile device • Estimates > 300 billion app downloads by 2016 More traffic Shift in W-Fi Usage • HD mobile video, video telepresence, collaboration programs • Tablet traffic ~ 3.4x greater than smartphone traffic • Pervasive, primary access • Mission critical • Multimedia – Voice, IPTV, older legacy media transport systems (i.e. cable TV) HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 11. 802.11ac Technology Overview Think of 11ac as an extension of 11n 11n specification: 11ac introduces • 2.4 and 5 GHz • 5 GHz only • 40 MHz channels • Wider channels (80 MHz &160 MHz) • 64-QAM modulation • Better modulation (256-QAM) • Up to 4 streams • Additional streams (up to 8) • Explicit & implicit beam forming • Beam forming (explicit) • Backwards compatible w/ 11a/b/g • Backwards compatible w/ 11a/b/g/n • Refer to http://www.802-11.ac.net for in-depth information HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 12. Wider Channels 80 MHz channel widths supported in first generation – 80 MHz is 4.5x faster than 20 MHz – 80 MHz is contiguous – Per packet dynamic channel width decisions Future releases will allow for 160 MHz channel widths – 160 MHz can be either contiguous or in two noncontiguous 80 MHz slices HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 13. 802.11ac Channels (FCC) UNII I and UNII II 2x 80 MHz 4x 40 MHz 8x 20 MHz Channel Freq (MHz) Band Edge 5150 36 40 5180 44 52 56 60 5220 5200 48 5240 5260 5280 5300 64 5320 Band Edge 5350 UNII II extended 3x 80 MHz 6x 40 MHz 12x 20 MHz Channel Freq (MHz) Band Edge 5470 Band Edge 100 104 108 112 116 120 124 128 132 136 140 144 5500 5520 5540 5560 5580 5600 5620 5640 5660 5680 5700 5720 5725 Channel Band Edge 149 153 157 161 165 Freq (MHz) 5725 5745 5765 5785 5805 5825 Band Edge 5850 US UNII III 1x 80 MHz 2x 40 MHz 5x 20 MHz HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 14. More Spatial Streams Spec allows up to 8 spatial streams (4 max in 802.11n) – 8SS performance will only be possible where both devices have 8 antennas – Space, power and cost constraints will dictate the number of streams supported by the client • Smart phones – 1 stream • Tablets – 2 stream • Laptops – 2 or 3 streams – Speed of connection is decided by the device with the lowest number of streams. Adding spatial streams increases throughput proportionally. – Assuming multipath conditions are favorable: • Two streams offer double the throughput of a single stream • Eight streams increase throughput eight-fold HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 15. AP Throughput > 1Gbps “How fast can I go?” – Simple question with very complicated answer – Depends on many factors • • • • Device type Distance Signal to Noise Ratio (SNR) Access Point configuration • • • • Channel width Number of Spatial Streams Short/long guard intervals Link aggregation – Your mileage WILL vary HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 16. Max Data Rates per Client Type Channel bandwidth Transmit – Receive antennas Typical client scenario Max individual link rate Max aggregate link rate 40 MHz 3x3 PC 606 Mbps 606 Mbps 80 MHz 1x1 Smartphone 433 Mbps 433 Mbps 80 MHz 2x2 Tablet, PC 867 Mbps 867 Mbps 80 MHz 3x3 PC 1300 MBPS 1300 MBPS 160 MHz 1x1 Smartphone 867 Mbps 867 Mbps 160 MHz 2x2 Tablet, PC 1.73 Gbps 1.73 Gbps 160 MHz 4x Tx AP, 4 clients of 1x Rx Multiple smartphones 867 Mbps per client 3.47 Gbps 160 MHz 8x Tx AP, 4 clients with total of 8x Rx Digital TV, set-top box, tablet, PC, smartphone 867 Mbps to two 1x clients 1.73 Gbps to one 2x client 3.47 Gbps to one 4x client 6.93 Gbps HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 17. 11ac Clients are Already Here! 11ac Clients – Samsung Galaxy S4 (1x1:1 11ac) • 20 million units as of July 5th –HTC One (1x1:1 11ac) • 5 million sold in first 45 days –2013 MacBook Air (2x2:2 11ac) –USB dongles (2x2:2 11ac) • Look for USB 3.0 No significant impact on client battery life HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 18. Pros and Cons of 802.11ac Spec Pros 1. APs can accommodate more users/devices • Increased capacity 2. Standards based Explicit Beam-forming increases SNR • Higher data rates over longer distances 3. 256-QAM • Increased throughput at high SNRs • Improved modulation and coding techniques 4. Multi-User MIMO (future generations) • Improved utilization of RF capacity 5. Use of 5 GHz spectrum • More non-overlapping channels • Quieter RF environment HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 19. Pros and Cons of 802.11ac Cons 1. Hardware update required to support 802.11ac • Some features will not be available on legacy devices 2. 802.3at (PoE+) is required to attain full benefit of 802.11ac • 802.3af (PoE) can be used on the AP-22x, but it will limit the full features and functionality available with 802.11ac HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 20. Planning for .11ac migration 1. RF bands (2.4 GHz, 5 GHz)? 2. Channel width per band (20 vs. 40 vs. 80Mhz)? 3. Apps (Voice? MC Video?) now and in the future 4. Real-time location services (RTLS)? 5. Devices per user? 6. Max devices per AP? 7. Wired network capacity & power? 8. Accessible floor plan images? 9. DFS? HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 21. Purpose-built Aruba 220 Series • 3x3:3 Dual Radio • 5GHz 11ac: up to 1.3Gbps • 2.4GHz 11n: up to 450Mbps (600Mbps with Broadcom clients) • 2x GE link aggregation • Enabling >1Gbps TCP throughput Controller-managed & Controllerless • Operates with 802.3af, requires 802.3at for full functionality HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 22. AP-225 Purpose-built = No Design Compromises Powerful CPU & memory Custom antenna design Smaller & lighter Cost effective Higher density Better RF coverage Easier to install $1,295 HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 23. 802.11ac TCP Download – 214 Mbps at 120 feet Mbps 802.11ac TCP Download Performance 800 700 600 500 400 300 200 100 0 1SS 2SS 3SS 15ft 238 572 705 30ft 235 417 640 75ft 193 402 393 100ft 161 281 283 120ft 154 202 214 Distance from AP in feet Test Clients: Windows 7 Laptop with 3 stream 802.11ac radio, Macbook Air with 2 stream 802.11ac client and Samsung Galaxy S4 smartphone with 1SS Test Goal: Test TCP download performance at increasing distance from AP for devices with varying capabilities Test Result: Aruba AP-225 delivers peak performance of 705 Mbps. Even at 120ft, the clients gets upto 214Mbps throughput HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 24. 802.11n TCP Download: AP-225 Delivers 325% More Single Macbook Pro - 3x3:3 11n 300 Mbps 250 200 150 100 50 0 AP-225 AP-135 15 275 248 30 269 230 75 186 120 120 128 30 Distance from AP (ft) Test Client: MacbookPro with 3 stream 802.11n radio Test Goal: Test TCP download performance at increasing distance from AP to see if 11n client performance is improved on 11ac Access Point Test Result: Aruba AP-225 delivers upto 325% improved performance for 11n clients compared to 802.11n access points HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 25. 802.11ac Voice Performance – Almost 400ft Range Call dropped at 275ft Voice call with GS4 - Skype – 5G Call did not drop at 400ft But could not hear voice Voice call with GS4 - Skype – 2.4G Call dropped at 210ft Voice call with HTC Skype – 5G Call dropped at 370ft Voice call with HTC Skype – 2.4G 0 50 100 150 200 250 300 350 400ft HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 26. ClientMatch™ Enables 802.11ac Wi-Fi REAL-TIME RF CORRELATION DEVICE TYPE LOCATION CONGESTION Match to another AP Patent: 8,401,554 INTERFERENCE Enables use of 802.11ac Wi-Fi rates  98% of mobile devices with higher signal quality  94% better performance for “sticky” clients  No client-side software required HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 27. Client Health Visibility After Before ClientMatch HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 28. Demos HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 29. Demo 1 – RF Capacity What you will see: – AP distribution by channel utilization – Channel utilization for every AP radio – Drill down to an AP with high utilization • Identify root cause – Drill down to an AP with low or less utilization • Show why this AP is in “green zone” Why it matters – Helps identify areas requiring additional capacity – Identify areas that will benefit with 11ac upgrade HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 30. Demo 2 – RF Performance and ClientMatch What you will see: – Overall client health – Drill down to unhealthy client • Identify root cause – Drill down to healthy client • See ClientMatch in action Why it matters: – Single client with poor performance impacts entire network performance – Helps identify potential design changes to boost performance HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 31. Demo 3: Aruba AppRF Technology What You will see: – – – – – App usage dashboard Identify URL traffic via DNS resolution Heuristics and ALGs to fingerprint UC apps Prioritize business traffic over personal Wired/wireless/VPN Why it Matters – – – – Identify web services and UC traffic, and prioritize 75% better UC performance 30% more video on iPads 11x faster mobile apps HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY WebEx Sharepoint Supply Chain Exchange Oracle Google
  • 32. Demo 4: AirWave AppRF What You will see: – You can see that you will be able to get historical data of AppRF on AirWave, allowing you to get historical trending – You can examine new applications as they gain popularity amongst your population Why it Matters – While APP RF is nice, you will likely want the history – You can define better policy HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 33. Demo 5: Lync Dashboard What You will see: – Lync visibility adds an additional level data points when examining traffic. – Track usage of voice protocols along side Lync – Understand prioritization requirements on the network Why it Matters – Speeds up troubleshooting, points to network or client/server issues – Justify investments in additional equipment, validate investments in technology – Better Lync call traffic, higher usage, higher customer satisfaction. HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 34. Step 2 Planning your mobility network architecture HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 35. Two different architectures Controller Controllerless HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 36. Evolution of the architectures 1st generation 128 APs 2,048 devices 2nd generation 512 APs 8,064 devices 3rd generation 2048 APs 32,768 devices Autonomous APs had no coordination Current controllerless APs have equivalent CPUs and memory to 1st generation controller architectures HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 37. Deployment overview Controllers Complex network topologies Centralized encryption / switching Larger mobility domains Advanced services at scale Controllerless Less complex local networks Many individual remote sites Simplified management Minimal onsite HW and cost HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 38. Mixed Architectures Controllerless APs at remote sites IAP IAP AP Group “BLDG#1” IAP Controller at main campus Access Switch WWW Mobility Controller AirWave for consolidated management VPN from APs or 3rd party VPN Distribution / Core Content Filters RADIUS/AD HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 39. Convertible Architectures Controllerless APs directed to the controller IAP IAP IAP AP Group “BLDG#1” Add a controller to the network Mobility Controller Controllerless APs software conversion to controller based APs Access Switch Distribution / Core Content Filters RADIUS/AD HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 40. Cloud Wi-Fi HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 41. How Does it Work? • Zero-touch provisioning: AP pulls configuration from Aruba Central Aruba Central • AP self-selects as master • Master performs firewall and controller functions Instant AP Instant OS • New APs automatically join the master HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 42. Aruba Central Services Platform Public cloud subscription One interface – Multiple sites – Multiple clusters in a single site Enterprise management – Remote monitoring & troubleshooting – Central configuration & firmware management – Compliance records and historical data – True Zero Touch provisioning Comprehensive e-Support and community HQ BRANCH BRANCH BRANCH HOME OFFICE HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 43. Single Architecture, Multiple Modes Public Cloud, Private Cloud, & Local Management Options Free local management Aruba Central Aruba AirWave AD / RADIUS Mobility Access Switch Internet Mobility Controller Mobility Access Switch Free local management Enterprise HQ HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 44. Demo Aruba Activate & Aruba Central HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 45. BREAK HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 46. Step 3 Smart policy creation and BYOD enforcement HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 47. Why Network Access Control? Smartphone and Tablet Growth Users are More Mobile Rise of Mobile Apps Enterprise and BYOD Together HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 48. Evolving Auth/Authz needs New policy and AAA dynamics – No longer just authenticating Windows domain devices. – Use of more 802.1X to lock down open ports/SSIDs. – Meeting SSO requirements for cloud applications (e.g. SAML, Okta). Why context for fine grained Authorization – Ability to layer multiple authorization rules and conditions. – Leverages context stored in a variety of 3rd party systems. HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 49. Challenges with legacy RADIUS Visibility and troubleshooting – No capability to profile devices connecting to the network. – No contextual awareness (e.g. posture, device type, asset type). – Poor per session troubleshooting tools and logs. Scalability and reliability – Limited performance to handle EAP termination or higher loads. – Poor active clustering technology and centralized management. Narrow feature sets – Limited to core AAA, TACACS+ (ACS/SBR products are EOL/EOS) HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 50. Network Policy Best Practices Most organizations do a fair job of authentication (who the user is) -- But, a poor job of authorization (what the user is allowed to do based on context) 1. Profile and authenticate everything that connects to your network. 2. Place ClearPass close to Active Directory or other Identity/Context servers to reduce latency. 3. Leverage context to provide fine grained authorization. 4. Utilize access infrastructure that supports CoA and role based access control versus VLAN segmentation. 5. Use standards based protocols for enhanced network security. HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 51. The ClearPass Platform High performance AAA – Up to 300 auths/second for 802.1X with AD. – Supports distributed, active/active clustering and bursting. – Hardware and virtual appliance platforms. Multi-faceted policy services – Uses standards based Web APIs to receive additional context from new sources (e.g. identity stores, MDM) – Supports multiple enforcement actions. Extensive support for emerging standards and multivendor products. HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 52. Network Policies Based on Context Policy Example Use context from ClearPass & external sources to set network policy • User/group membership • Device Profile • Location • Application • Time/Date • OS version installed • eg. in semester • Trusted or • Endpoint health untrusted • blacklisted • Jailbreak status network • Pincode/encryption HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 53. ClearPass for IT-managed and BYOD Network Control Device Profiling & Visibility Device/User Control App Control MDM Services Contextual Policies AAA – RADIUS, TACACS+ Device Registration 3rd-party App Security Policy Engine & Management Visitor Management Enterprise App Store BYOD Onboarding Work Space Security & Privacy Health Checks HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 54. Demo HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 55. Demo: Defining Policies What you will see . . . 1. Creating a Wi-Fi service 2. Onboarding a personal device – Limiting a 2nd device by the same user 3. Enabling guest selfregistration – Keeping IT-managed devices off the guest network Yes No HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 56. Step 4 Device and App Management HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 57. Policy Enforcement Options NAC / AAA • • • • VLAN ACLs QoS Authentication MDM • • • • • • Device Provisioning & Onboarding Device Policy Device Level Encryption Passcode Full Wipe App blacklist / whitelist MAM • • • • • • Authentication App Passcode App Wipe App Policies App SSO App VPN HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 58. Protect Your MDM Investment 3rd Party MDM ClearPass Exchange endpoint context & trigger policies HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 59. Use ClearPass to Enhance MDM/MAM Wi-Fi based MDM enrollment • End reliance on SMS or e-mail invitations • Link MDM agent to captive portal Auto-remediate non-compliant devices • Quarantine devices by blacklist • Redirect to self-service portal • Push reminders about policy violation In-built CA for provisioning credentials • Unique device certificates using SCEP • No need for PKI to support BYOD Use MDM device context for network security • Deny/limit network access to jailbreak or rooted devices HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 60. Use MDM Attributes for Network Policy Inventory Manufacturer: Model: OS Version: UDID Serial Number IMEI Phone Number Carrier MDM Id Owner Display Name Ownership Posture MDM Attributes Apple iPad2 iOS 6.1 1730235f564094186 79049XXXA4S 012416009780168 408-534-2819 Verizon 130d0f992t34 jhoward John Howard Employee Liable MDM Enabled Yes Compromised Not Jailbroken Encryption Enabled Yes Blacklisted Apps No Required Apps Yes Last Check in HUNTING FOR FASTER, SMARTER WI-FI? 01/30/2012 9:03am YOU’RE IN GOOD COMPANY
  • 61. ClearPass MDM Integration Using MDM device information for Policy CoA triggers network enforcement Endpoint data replicated to ClearPass cluster Device type & posture polled for policy decisions & reporting MDM ClearPass ClearPass HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 62. Integrating Leading MDM Vendors • ClearPass uses public APIs for: • Normalize MDM endpoint data across vendors HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 63. Enterprise Policy Beyond the Network Use Case: Compromised Device Context Push Notification Enforcement Push Device ClearPass Role, Captive Portal Identity = keerti User Aruba Access Network Authorization MDM HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 64. Enterprise Policy Beyond the Network Use Case: MDM Profile Removed Context SMS or Voice Call Enforcement Big Brother Device ClearPass Role, Captive Portal Identity = student27 User Aruba Access Network Authorization MDM School Principal HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 65. Step 5 Extending mobile services to visitors and customers HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 66. Location-Based Mobile Services on the Rise Retail Hospitals 80% of the world owns a mobile phone. And we’re using them in the venues we visit Hotels Campus Transportation 27% of companies worldwide intend to implement locationbased mobile marketing in 2013 HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 67. Wi-Fi Concierge Inside Venues Way-Finding Indoor turn-by-turn directions Push Notifications Time & location relevant messaging Analytics Dwell-time and traffic insights HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 68. Wi-Fi Concierge Solution Components Analytics Service Meridian Editor Aruba Wi-Fi “BluDot,” Nav, & Zone-based content Featuring Analytics & Location Engine Meridian App (white-label/custom) 20+ third party products Active Wi-Fi Connection Not Needed HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 69. Key Take Aways Integrate Network, Device and App Management • Stronger security, simplified rollouts: Complete solution for BYOD and IT-managed network access policy management Ensure Multi-vendor Support • Integration flexibility: Standards based enforcement across any Wi-Fi, wired and VPN infrastructure Plan for Growth and Change • Adapt to the environment: Support a wide variety of use-cases and phased deployment – BYOD, AAA, guest access, compliance initiatives… HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY
  • 70. HUNTING FOR FASTER, SMARTER WI-FI? YOU’RE IN GOOD COMPANY