SlideShare a Scribd company logo
#ATM15 |
A-to-Z Design Guide for the
All-Wireless Workplace
Partha Narasimhan, Michael Wong
March 2015
@ArubaNetworks
2 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
#nomorephones
3 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Wireless Devices
• Wireless Devices
– 802.11n / 802.11ac
– Wireless NIC driver updates
– Roaming behavior
– 11r, 11k, 11v capabilities
4 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Wireless Office Requirements
Wireless
Office
Requirements
RF
High
Availability
Broadcast
Suppression
Visibility
Aruba
Solution
Exchange
5 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
RF Considerations
• ARM
– Channel / TX Power
• ClientMatch
– Band-Steering
– Spectrum Load-Balancing
– Sticky Client Moves
– Voice Aware
– .11v BSS transition
• Data Rates
– Remove lower rates
• Channel Width
– 20 / 40 / 80 / 160 MHz
6 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
ASE RF Solution
• Task-Oriented Configuration for RF Optimization
7 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
ASE RF Solution
• Generated Configuration can be pasted to controller
8#ATM15 |
High Availability / Redundancy
@ArubaNetworks
9 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Controller High Availability
• Client State Info is shared by a pair of controller
• 2048 APs: under a second
Client State
Sync
• ESSID stays up
• AP builds a primary tunnel and a standby tunnel
• 512 APs: ~9 sec
AP Fast
Failover
• Ensures that AP always have a controller available
• LMS / Backup LMS
• 512 APs: ~1min 20 sec
VRRP
@ArubaNetworks
10 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
Client State Sync
1. Client successfully authenticates
and generates Key and PMK-SA
(Role, VLAN)
2. Client info are synced between
the controller pair
3. AP standby tunnel becomes
active upon controller failure
4. Client is deauth and when it
reconnects, it performs a 4-way
key exchange
• Does not require full authentication to
radius servers
5. Controller deployed in Active /
Active Model
@ArubaNetworks
Authentication
ServersMaster
Local LocalX
Active GRE
Standby GRE
Active / Active Deployment
11 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Generated Configuration from ASE
12#ATM15 |
Broadcast / Multicast
Controls
@ArubaNetworks
13 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Wireless Requirements
• Design Criteria
– Mobility
• Mobile device don’t disconnect and do not understand VLANs
• User are not physically constraint to space
– RF coverage
• Boundaries are less obvious
– Decisions, Decisions
• Single VLAN or VLAN Pool?
• How large should the broadcast domain be?
• L2 Mobility
• IP Mobility
– IPv6 Clients
14 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Broadcast Domain
• “Controlling broadcast
propagation… is important
to reduce the amount of
overhead”
• Wired Network
– Broadcast Control with VLAN
segmentation
– Physically Constraint (per floor)
– Finite number of ports
15 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Problem: WLAN Broadcast Flow
• Unicast frames
– Unique for each client
• Broadcast / Multicast frames
– Clients connecting to same BSS
(AP) use the same key
– Broadcast / multicast traffic is
unnecessary flooded
Unicast Frame
Broadcast /
Multicast Frame
VLAN
16 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Problem: Multiple VLANs
• Unicast frames
– Unique for each client
• Broadcast / Multicast frames
– Clients connecting to same BSS
(AP) use the same key
– Clients can see broadcast /
multicast from other VLANs
Unicast Frame
Broadcast /
Multicast Frame
VLAN 20
VLAN 10
17 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Transition Content
AOS Broadcast / Multicast Control
Broadcast
/ Multicast
Controls
Enable IGMP snooping /
MLD
• Learn IGMP membership
• Prune multicast flows if there are no
subscribers
“broadcast-filter all”
• Packets allowed if:
•Packets originating from the wired
side with destination range of
225.0.0.0-239.255.255.255
•A station has subscribed to a multicast
group
“broadcast-filter arp”
• ARP will be flooded on the wired side
and sent as 802.11 unicast frame if
there is a match in the user table
• DHCP converted to unicast
• IPv6 NS is treated in a similar fashion
Duplicate Address Detection
• Gratuitous ARP
• IPv6 DAD
If DMO is enabled,
multicast packets will
be sent as 802.11
unicast
@ArubaNetworks
18 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
ARP Packet Flow Example (with broadcast control)
• Unicast frames encrypted with
PTK
– Unique for each client
• Broadcast / Multicast frames
are not flooded
• ARP packet sent only to
matching client entry in user
table
– ARP packet from Client A is sent to
Client B as 802.11 unicast
– Client C does not get ARP packet
Unicast Frame
Broadcast /
Multicast Frame
ARP
VLAN
Sta A:
Who has IP 10.10.10.1?
Sta B:
IP 10.10.10.1
Sta C:
19 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Bonjour and SSDP in the Enterprise
Enable Airgroup to handle Zero Configuration Networking Multicast (Bonjour
and SSDP) large campus without affecting Wi-Fi performance
• Well-known address for mDNS is 224.0.0.251
• Well-known address for SSDP is 239.255.255.250
20 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
VLAN Pooling
• When should VLAN pool be used?
– Provide additional address space for non-contiguous
• Higher chance if public IP address is being used
– All VLANs in the pool should be the same size
• Controller will automatically convert IPv6 RAs to unicast
– Conversion of RAs to unicast is necessary to prevent client from
getting address in wrong IPv6 prefix
– Unicast traffic may negatively affect battery life
21 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Summary
• Keep it simple, use a single VLAN
– The cost of managing broadcast / multicast domain for multiple
VLANs is expensive
– Use Airgroup to manage Bonjour (AirPlay) and SSDP (Chromecast /
DLNA) behavior
– Avoid potential client misbehavior
• L2 Domain should match a contiguous RF footprint
– With Mobility, devices are not constraint to a physical space
22 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Things to Keep in Mind
• Single VLAN can put additional requirements to uplink
router
– Router should be able to handle large ARP table
• DHCP server scalability / redundancy
23#ATM15 |
Visibility
@ArubaNetworks
24 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Voice / UCC Visibility
• Real time correlation between
Call Quality and Wi-Fi Quality
• Lync SDN 2.1
– additional session info provided
25 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
AppRF
26 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Aruba Solution Exchange (ASE)
• Aruba Solution Exchange (ASE)
– https://ase.arubanetworks.com
• Benefits
– Generate dynamic configuration
– Reduce time to make use of configuration
– Solution validates user input
27 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
ASE FAQ
• Who can access ASE?
– Customer, Partners, Airhead Social Users
• Is there a cost?
– ASE is free
• Documentation
– https://ase.arubanetworks.com/docs
• How can I get notification when a solution is updated?
– Follow the solution!
28 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 |
Sign up, save $200!
arubanetworks.com/atmosphere2016
Give feedback!
… Before You Go
atmosphere
2016
29#ATM15 | @ArubaNetworks
THANK YOU
30#ATM15 | @ArubaNetworks

More Related Content

PPTX
Design Fundamentals for Remote and Branch Access Networks
PPTX
Getting the most out of the Aruba Policy Enforcement Firewall
PDF
ARUBA - Remote Branch-networking-fundamentals-2014
PPTX
New Branch IT Opportunities: Enhanced Performance & Reduced Costs
PDF
ARUBA community - WLAN design and troubleshooting
PPTX
Unified access with Aruba Mobility Access Switches – Live Demo
PPTX
Deploying mobile unified communications and collaboration (UCC) with Microsof...
PPTX
Network Management with Aruba Airwave #AirheadsConf Italy
Design Fundamentals for Remote and Branch Access Networks
Getting the most out of the Aruba Policy Enforcement Firewall
ARUBA - Remote Branch-networking-fundamentals-2014
New Branch IT Opportunities: Enhanced Performance & Reduced Costs
ARUBA community - WLAN design and troubleshooting
Unified access with Aruba Mobility Access Switches – Live Demo
Deploying mobile unified communications and collaboration (UCC) with Microsof...
Network Management with Aruba Airwave #AirheadsConf Italy

What's hot (20)

PPTX
A consolidated virtualization approach to deploying distributed cloud networks
PPTX
Advanced RF Design & Troubleshooting
PDF
EMEA Airheads – Aruba controller features used to optimize performance
PPTX
Wireless LAN Security Fundamentals
PPTX
Connect and protect building a trust based internet of things for business cr...
PPTX
Integrating Unified Communications and Collaboration on an Aruba Access Network
PPTX
Shanghai Breakout: Advanced Airwave Workshop
PPTX
Aruba WLANs 101 and design fundamentals
POTX
Packets never lie: An in-depth overview of 802.11 frames
PPTX
Securing the LAN Best practices to secure the wired access network
PDF
6 understanding aruba rf issues
PPTX
Breakout - Airheads Macau 2013 - Top 10 Tips from Aruba TAC
PPTX
Simplifying Wired Network Deployments with Software-Defined Networking (SDN)
PPTX
WLAN Architecture - Considerations
PPTX
ClearPass design scenarios that solve the toughest security policy requirements
PDF
EMEA Airheads - Aruba Central- Managing Networks from the Cloud
PPTX
Large scale, distributed access management deployment with aruba clear pass
PDF
Aruba Campus Wireless Networks
PPTX
Adapting to evolving user, security, and business needs with aruba clear pass
PDF
Aruba Atmosphere / Airheads 2014 Keerti Melkote Keynote
A consolidated virtualization approach to deploying distributed cloud networks
Advanced RF Design & Troubleshooting
EMEA Airheads – Aruba controller features used to optimize performance
Wireless LAN Security Fundamentals
Connect and protect building a trust based internet of things for business cr...
Integrating Unified Communications and Collaboration on an Aruba Access Network
Shanghai Breakout: Advanced Airwave Workshop
Aruba WLANs 101 and design fundamentals
Packets never lie: An in-depth overview of 802.11 frames
Securing the LAN Best practices to secure the wired access network
6 understanding aruba rf issues
Breakout - Airheads Macau 2013 - Top 10 Tips from Aruba TAC
Simplifying Wired Network Deployments with Software-Defined Networking (SDN)
WLAN Architecture - Considerations
ClearPass design scenarios that solve the toughest security policy requirements
EMEA Airheads - Aruba Central- Managing Networks from the Cloud
Large scale, distributed access management deployment with aruba clear pass
Aruba Campus Wireless Networks
Adapting to evolving user, security, and business needs with aruba clear pass
Aruba Atmosphere / Airheads 2014 Keerti Melkote Keynote
Ad

Similar to A-to-Z design guide for the all-wireless workplace (20)

PPTX
High-density 802.11ac Wi-Fi design and deployment for large public venues
PPTX
Extend mobility to remote branch networks with Aruba's new cloud services con...
PPTX
Transforming Networks into a NFV-Centric Environment
PPTX
Designing For Voice - #WLPC 10 talk
PDF
1 voice and video over wi fi-balajee krishnamurthy
PPTX
Secure Network Design with High-Availability & VoIP
PDF
Top 10 tips_aruba_tac_madison lee
PPTX
Mobile Experience Management and Network Services Health Check with Aruba Air...
PPTX
Roaming behavior and Client Troubleshooting
PDF
2012 ah vegas remote networking fundamentals
PDF
Arista Nuage meetup dublin 18-2
PDF
Monitoring MV& LV Distribution assets using LoRaWAN
PDF
NFV & SDN Customer Deployments
PDF
Network Functions Virtualization and CloudStack
PPT
Access Management with Aruba ClearPass
PPTX
Breakout - Airheads Macau 2013 - Microsoft Lync, Unified Communications, Clou...
PPTX
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
PDF
2012 ah vegas mobile device fundamentals
PPTX
VMworld 2015: Networking Virtual SAN's Backbone
PDF
2012 ah apj wi fi design for voice & video
High-density 802.11ac Wi-Fi design and deployment for large public venues
Extend mobility to remote branch networks with Aruba's new cloud services con...
Transforming Networks into a NFV-Centric Environment
Designing For Voice - #WLPC 10 talk
1 voice and video over wi fi-balajee krishnamurthy
Secure Network Design with High-Availability & VoIP
Top 10 tips_aruba_tac_madison lee
Mobile Experience Management and Network Services Health Check with Aruba Air...
Roaming behavior and Client Troubleshooting
2012 ah vegas remote networking fundamentals
Arista Nuage meetup dublin 18-2
Monitoring MV& LV Distribution assets using LoRaWAN
NFV & SDN Customer Deployments
Network Functions Virtualization and CloudStack
Access Management with Aruba ClearPass
Breakout - Airheads Macau 2013 - Microsoft Lync, Unified Communications, Clou...
The Aruba Tech Support Top 10: WLAN design, configuration and troubleshooting...
2012 ah vegas mobile device fundamentals
VMworld 2015: Networking Virtual SAN's Backbone
2012 ah apj wi fi design for voice & video
Ad

More from Aruba, a Hewlett Packard Enterprise company (20)

PPTX
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
PPTX
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
PPTX
Airheads Tech Talks: Advanced Clustering in AOS 8.x
PPTX
EMEA Airheads_ Advance Aruba Central
PPTX
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
PPTX
EMEA Airheads- Switch stacking_ ArubaOS Switch
PPTX
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
PPTX
PPTX
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
PPTX
EMEA Airheads- Aruba Central with Instant AP
PPTX
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
PPTX
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
PPTX
EMEA Airheads - AP Discovery Logic and AP Deployment
PPTX
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
PPTX
EMEA Airheads- Manage Devices at Branch Office (BOC)
PPTX
EMEA Airheads - What does AirMatch do differently?v2
PPTX
Airheads Meetups: 8400 Presentation
PPTX
Airheads Meetups: Ekahau Presentation
PPTX
Airheads Meetups- High density WLAN
PPTX
Airheads Meetups- Avans Hogeschool goes Aruba
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Advanced Clustering in AOS 8.x
EMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
EMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads - What does AirMatch do differently?v2
Airheads Meetups: 8400 Presentation
Airheads Meetups: Ekahau Presentation
Airheads Meetups- High density WLAN
Airheads Meetups- Avans Hogeschool goes Aruba

Recently uploaded (20)

PDF
KodekX | Application Modernization Development
PPTX
Big Data Technologies - Introduction.pptx
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PPTX
Cloud computing and distributed systems.
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
NewMind AI Weekly Chronicles - August'25 Week I
KodekX | Application Modernization Development
Big Data Technologies - Introduction.pptx
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Digital-Transformation-Roadmap-for-Companies.pptx
Cloud computing and distributed systems.
“AI and Expert System Decision Support & Business Intelligence Systems”
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Encapsulation_ Review paper, used for researhc scholars
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Understanding_Digital_Forensics_Presentation.pptx
Mobile App Security Testing_ A Comprehensive Guide.pdf
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
NewMind AI Monthly Chronicles - July 2025
Chapter 3 Spatial Domain Image Processing.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Per capita expenditure prediction using model stacking based on satellite ima...
NewMind AI Weekly Chronicles - August'25 Week I

A-to-Z design guide for the all-wireless workplace

  • 1. #ATM15 | A-to-Z Design Guide for the All-Wireless Workplace Partha Narasimhan, Michael Wong March 2015 @ArubaNetworks
  • 2. 2 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | #nomorephones
  • 3. 3 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Wireless Devices • Wireless Devices – 802.11n / 802.11ac – Wireless NIC driver updates – Roaming behavior – 11r, 11k, 11v capabilities
  • 4. 4 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Wireless Office Requirements Wireless Office Requirements RF High Availability Broadcast Suppression Visibility Aruba Solution Exchange
  • 5. 5 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | RF Considerations • ARM – Channel / TX Power • ClientMatch – Band-Steering – Spectrum Load-Balancing – Sticky Client Moves – Voice Aware – .11v BSS transition • Data Rates – Remove lower rates • Channel Width – 20 / 40 / 80 / 160 MHz
  • 6. 6 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | ASE RF Solution • Task-Oriented Configuration for RF Optimization
  • 7. 7 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | ASE RF Solution • Generated Configuration can be pasted to controller
  • 8. 8#ATM15 | High Availability / Redundancy @ArubaNetworks
  • 9. 9 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Controller High Availability • Client State Info is shared by a pair of controller • 2048 APs: under a second Client State Sync • ESSID stays up • AP builds a primary tunnel and a standby tunnel • 512 APs: ~9 sec AP Fast Failover • Ensures that AP always have a controller available • LMS / Backup LMS • 512 APs: ~1min 20 sec VRRP @ArubaNetworks
  • 10. 10 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content Client State Sync 1. Client successfully authenticates and generates Key and PMK-SA (Role, VLAN) 2. Client info are synced between the controller pair 3. AP standby tunnel becomes active upon controller failure 4. Client is deauth and when it reconnects, it performs a 4-way key exchange • Does not require full authentication to radius servers 5. Controller deployed in Active / Active Model @ArubaNetworks Authentication ServersMaster Local LocalX Active GRE Standby GRE Active / Active Deployment
  • 11. 11 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Generated Configuration from ASE
  • 12. 12#ATM15 | Broadcast / Multicast Controls @ArubaNetworks
  • 13. 13 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Wireless Requirements • Design Criteria – Mobility • Mobile device don’t disconnect and do not understand VLANs • User are not physically constraint to space – RF coverage • Boundaries are less obvious – Decisions, Decisions • Single VLAN or VLAN Pool? • How large should the broadcast domain be? • L2 Mobility • IP Mobility – IPv6 Clients
  • 14. 14 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Broadcast Domain • “Controlling broadcast propagation… is important to reduce the amount of overhead” • Wired Network – Broadcast Control with VLAN segmentation – Physically Constraint (per floor) – Finite number of ports
  • 15. 15 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Problem: WLAN Broadcast Flow • Unicast frames – Unique for each client • Broadcast / Multicast frames – Clients connecting to same BSS (AP) use the same key – Broadcast / multicast traffic is unnecessary flooded Unicast Frame Broadcast / Multicast Frame VLAN
  • 16. 16 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Problem: Multiple VLANs • Unicast frames – Unique for each client • Broadcast / Multicast frames – Clients connecting to same BSS (AP) use the same key – Clients can see broadcast / multicast from other VLANs Unicast Frame Broadcast / Multicast Frame VLAN 20 VLAN 10
  • 17. 17 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Transition Content AOS Broadcast / Multicast Control Broadcast / Multicast Controls Enable IGMP snooping / MLD • Learn IGMP membership • Prune multicast flows if there are no subscribers “broadcast-filter all” • Packets allowed if: •Packets originating from the wired side with destination range of 225.0.0.0-239.255.255.255 •A station has subscribed to a multicast group “broadcast-filter arp” • ARP will be flooded on the wired side and sent as 802.11 unicast frame if there is a match in the user table • DHCP converted to unicast • IPv6 NS is treated in a similar fashion Duplicate Address Detection • Gratuitous ARP • IPv6 DAD If DMO is enabled, multicast packets will be sent as 802.11 unicast @ArubaNetworks
  • 18. 18 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | ARP Packet Flow Example (with broadcast control) • Unicast frames encrypted with PTK – Unique for each client • Broadcast / Multicast frames are not flooded • ARP packet sent only to matching client entry in user table – ARP packet from Client A is sent to Client B as 802.11 unicast – Client C does not get ARP packet Unicast Frame Broadcast / Multicast Frame ARP VLAN Sta A: Who has IP 10.10.10.1? Sta B: IP 10.10.10.1 Sta C:
  • 19. 19 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Bonjour and SSDP in the Enterprise Enable Airgroup to handle Zero Configuration Networking Multicast (Bonjour and SSDP) large campus without affecting Wi-Fi performance • Well-known address for mDNS is 224.0.0.251 • Well-known address for SSDP is 239.255.255.250
  • 20. 20 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | VLAN Pooling • When should VLAN pool be used? – Provide additional address space for non-contiguous • Higher chance if public IP address is being used – All VLANs in the pool should be the same size • Controller will automatically convert IPv6 RAs to unicast – Conversion of RAs to unicast is necessary to prevent client from getting address in wrong IPv6 prefix – Unicast traffic may negatively affect battery life
  • 21. 21 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Summary • Keep it simple, use a single VLAN – The cost of managing broadcast / multicast domain for multiple VLANs is expensive – Use Airgroup to manage Bonjour (AirPlay) and SSDP (Chromecast / DLNA) behavior – Avoid potential client misbehavior • L2 Domain should match a contiguous RF footprint – With Mobility, devices are not constraint to a physical space
  • 22. 22 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Things to Keep in Mind • Single VLAN can put additional requirements to uplink router – Router should be able to handle large ARP table • DHCP server scalability / redundancy
  • 24. 24 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Voice / UCC Visibility • Real time correlation between Call Quality and Wi-Fi Quality • Lync SDN 2.1 – additional session info provided
  • 25. 25 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | AppRF
  • 26. 26 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Aruba Solution Exchange (ASE) • Aruba Solution Exchange (ASE) – https://ase.arubanetworks.com • Benefits – Generate dynamic configuration – Reduce time to make use of configuration – Solution validates user input
  • 27. 27 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | ASE FAQ • Who can access ASE? – Customer, Partners, Airhead Social Users • Is there a cost? – ASE is free • Documentation – https://ase.arubanetworks.com/docs • How can I get notification when a solution is updated? – Follow the solution!
  • 28. 28 CONFIDENTIAL © Copyright 2015. Aruba Networks, Inc. All rights reserved#ATM15 | Sign up, save $200! arubanetworks.com/atmosphere2016 Give feedback! … Before You Go atmosphere 2016
  • 30. THANK YOU 30#ATM15 | @ArubaNetworks

Editor's Notes

  • #9: Make networks mobility-defined instead of fixed
  • #10: Make networks mobility-defined instead of fixed
  • #11: Make networks mobility-defined instead of fixed
  • #13: Make networks mobility-defined instead of fixed
  • #18: Make networks mobility-defined instead of fixed
  • #24: Make networks mobility-defined instead of fixed
  • #29: Make networks mobility-defined instead of fixed
  • #30: Make networks mobility-defined instead of fixed