SlideShare a Scribd company logo
Enabling the Virtual Enterprise
Dave Blank
Network Engineer
Facebook
Michael Wong
Product Manager
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
2 #AirheadsConf
Wireless @ Facebook
• 6,337 employees*
• Approximately 10,000 wireless
clients every day
• 35 offices globally (11 US offices,
24 international)
• EVERYONE is mobile (open
floorplan… employees work from
anywhere)
• 1.23 billion monthly active users*
*as of Dec 2013
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
3 #AirheadsConf
Agenda
Facebook Lighthouse @ Home
RAP Zero Touch Provisioning
Configuring Zero Touch Provisioning
With Activate and CPPM
Demo
4
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Remote AP Provisioning
• AP Provisioning
.. Need I say more?
5
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Controller: Provisioning Whitelist
• Controller Provisioning Steps
– Add AP to Whitelist on each controller
– Defines a list of APs allowed to connect to controller
– RAP Whitelist Definition
• AP mac address
• AP Group
• AP Name
– CLI: whitelist-db rap add mac-address [mac-addr] ap-group [ap-grp] ap-name [ap-
name]
6
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Facebook Requirements
• Zero Touch Deployment
– Easy for a non-techie to deploy
• Performance
• Form Factor
• Standardize Global Deployment
• Deploy in Challenging RF Environments
• Support Latest Technology including IPv6
• Extend Corporate Service
– Wired IP Phone
– Wired Video Conference Endpoint
7
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Facebook: HelpDesk Provisioning Tool
• Custom Portal to Adapt to Business Workflow
8
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Facebook LightHouse@Home
9
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
To Datacenters
Client
VPN
WAN
Plug-Play Client
Enterprise
Secure
Wi-Fi
LAN
Local Connectivity
Enterprise
Secure
Wired
Remote Access Points
LAN/WAN/Internet
Access Forwarding Priority
Per User/Device/Session
Dynamic Policies via Controller
PEF
Distributed
Policy Enforcement
Firewall Engine
10
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
RAP Bootstrapping Process
• RAP obtains wired IP address using DHCP
• RAP contacts master controller using
FQDN or static IP
• RAP attempts to form IPsec connection
– Certificate (name = mac address)
• IPsec SA is established between RAP and
controller
11
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Goal: Zero Touch Provisioning
• Activate
• Device info is recorded on shipment
• Device type, serial number, mac
address
• AP-Name, AP-Group and Controller-IP
are defined
• JSON API available
• ClearPass Policy Manager
• Synchronize inventory list
• Maintains central whitelist for all
controllers
• Authorizes RAP
• Controller
• Authentication RAPs
ClearPass
Policy Manager
Cluster
Activate
http://activate.arubanetworks.com
Controller sends
auth’n requests
and
CPPM provides
auth’z info
Controller Instant AP
Instant AP
Controller
Mr. IT
JSON api
Instant AP will check
Activate at boot for
provisioning info
12
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Use Activate to Provision AP Info
13
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Aruba Activate Service
What: Activate is a free Cloud Service that enables customers to
deploy Aruba infrastructure more efficiently
• http://activate.arubanetworks.com
How: Enhances a device’s ability
to find its configuration master
Model: Device centric DB correlating
various attributes
Activate’s Inputs
14
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Activate: Define Rules
•Activate (https://activate.arubanetworks.com)
1. Identify Configuration
 IAP-to-RAP
2. Define Rules
 Controller IP
 AP-Group
15
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Activate: AP Attributes
1. Select Device
 Devices are initially assigned
the default folder
2. Assign Devices to Folder
 Define AP-Name
16
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Define ClearPass Policy for Central Whitelist
17
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
ClearPass Policy Manager
• Authentication, Authorization, Accounting
(AAA) with Policy Management
• Guest Management
• Device Onboarding
18
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
CPPM: Activate Configuration
• Provide Activate credentials in CPPM
19
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
CPPM: Add Controller
20
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
CPPM: Endpoint List
• Validate that CPPM is receiving info
21
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
CPPM: Endpoint Info
• EndPoint Info
– Orange
• Attribute for Authorization
– Yellow
• Attributes sent to Controller
22
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
CPPM: Service
• Allows ClearPass Policy Manager to test Requests
• Provide differentiation by access method, location or other
network vendor-specific attributes
23
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
CPPM: Authentication
• Controller will perform mac authentication to CPPM
– Note: RAP will still use certificate to establish IPSec tunnel
24
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
CPPM: Enforcement
• Define Authorization Conditions
25
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
CPPM: Enforcement Profile
• Define Radius Attributes (Aruba VSA)
26
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Controller Configuration
27
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Controller Configuration
• Define Authentication Server
• Define Server Group
• Assign Server Group for
RAP / IAP authentication
aaa authentication-server radius CPPM_01
host [CPPM_IP_ADDRESS]
key PASSPHRASE
!
aaa server-group CPPM_WHITELIST
auth-server CPPM_01
!
aaa authentication vpn default-iap
server-group CPPM_WHITELIST
!
aaa authentication vpn default-rap
server-group CPPM_WHITELIST
!
• Controller perform whitelist lookup on CPPM instead of local-db
28
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Goal: Zero Touch Provisioning
• Activate
• Device info is recorded on shipment
• Device type, serial number, mac
address
• AP-Name, AP-Group and Controller-IP
are defined
• JSON API available
• ClearPass Policy Manager
• Synchronize inventory list
• Maintains central whitelist for all
controllers
• Authorizes RAP
• Controller
• Authentication RAPs
ClearPass
Policy Manager
Cluster
Activate
http://activate.arubanetworks.com
Controller sends
auth’n requests
and
CPPM provides
auth’z info
Controller Instant AP
Instant AP
Controller
Mr. IT
JSON api
Instant AP will check
Activate at boot for
provisioning info
29
Thank You
#AirheadsConf
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
30

More Related Content

PPTX
Access Management with Aruba ClearPass #AirheadsConf Italy
PPTX
Advanced Aruba Airwave Workshop #AirheadsConf Italy
PPTX
Real-world 802.1X Deployment Challenges
PPTX
Wireless LAN Security Fundamentals #AirheadsConf Italy
PPTX
Shanghai Breakout: Advanced Airwave Workshop
PDF
Advanced rf troubleshooting_peter lane
PDF
Cisco switch setup with cppm v1.2
PPTX
Access Management with Aruba ClearPass #AirheadsConf Italy
Advanced Aruba Airwave Workshop #AirheadsConf Italy
Real-world 802.1X Deployment Challenges
Wireless LAN Security Fundamentals #AirheadsConf Italy
Shanghai Breakout: Advanced Airwave Workshop
Advanced rf troubleshooting_peter lane
Cisco switch setup with cppm v1.2

What's hot (20)

PDF
2012 ah emea top 10 tips from aruba tac
PDF
Industry breakout government military forum_jon green_stuart schulte
PPTX
Shanghai Breakout: Access Management with Aruba ClearPass
PDF
Security advanced rich langston_jon green
PPTX
Shanghai Breakout: Advanced RF Design and Troubleshooting
PPTX
Advanced Access Management with Aruba ClearPass #AirheadsConf Italy
PDF
Building an aruba proof of concept lab javier urtubia
PDF
Next generation remote networks aruba instant gokul rajagopalan
PDF
2012 ah apj wlan design fundamentals
PPTX
Advanced RF Design & Troubleshooting
PDF
Aruba instant the easy button for wireless gokul rajagopalan
PDF
Wlan designfor highdensityenvironments_chuck lukaszewski
PDF
2012 ah vegas wlan design fundamentals
PDF
Aruba networks webinar_wi-fi_without_interruption_sep20_2012
PDF
PPTX
Remote & Branch Networking Fundamentals #AirheadsConf Italy
PPTX
Shanghai Breakout: Location Analytics – Key Considerations and Use Cases
PDF
Top 10 tips_aruba_tac_madison lee
PDF
Clear passbasics derinmellor
PDF
Airheads dallas 2011 rap troubleshooting
2012 ah emea top 10 tips from aruba tac
Industry breakout government military forum_jon green_stuart schulte
Shanghai Breakout: Access Management with Aruba ClearPass
Security advanced rich langston_jon green
Shanghai Breakout: Advanced RF Design and Troubleshooting
Advanced Access Management with Aruba ClearPass #AirheadsConf Italy
Building an aruba proof of concept lab javier urtubia
Next generation remote networks aruba instant gokul rajagopalan
2012 ah apj wlan design fundamentals
Advanced RF Design & Troubleshooting
Aruba instant the easy button for wireless gokul rajagopalan
Wlan designfor highdensityenvironments_chuck lukaszewski
2012 ah vegas wlan design fundamentals
Aruba networks webinar_wi-fi_without_interruption_sep20_2012
Remote & Branch Networking Fundamentals #AirheadsConf Italy
Shanghai Breakout: Location Analytics – Key Considerations and Use Cases
Top 10 tips_aruba_tac_madison lee
Clear passbasics derinmellor
Airheads dallas 2011 rap troubleshooting
Ad

Viewers also liked (20)

PDF
Breakout - Airheads Macau 2013 - ClearPass Access Management Basics
PDF
Customer Keynote - Microsoft Lync
POTX
Breakout - Airheads Macau 2013 - Cloud WiFi
PPTX
Shanghai Breakout: 802.11ac Wi-Fi Fundamentals
PPTX
Make Your Own Meridian Mobile App Workshop #AirheadsConf Italy
PPTX
IDC Aruba Webinar - 3 Feb 15
PPTX
Deploying Microsoft Lync over Wi-Fi #AirheadsConf Italy
PPTX
Aruba Instant Workshop #AirheadsConf Italy
PPTX
Breakout - Airheads Macau 2013 - WLAN Management & Troubleshooting with AirWave
PDF
Aruba Atmosphere / Airheads 2014 Keerti Melkote Keynote
PPTX
WLAN Design for Location, Voice & Video
PDF
Aruba Technical Webinar: Unplugging the Last Cord
PPTX
E Rate Modernization Overview
PPTX
Meridian APPs and ALE at WFD6
PPTX
PPTX
PPTX
Make Your Own Meridian Mobile App Workshop #AirheadsConf Italy
PPTX
Advanced Aruba Mobility Access Switch Workshop #AirheadsConf Italy
PPTX
PPTX
Best Practices on Migrating to 802.11ac Wi-Fi #AirheadsConf Italy
Breakout - Airheads Macau 2013 - ClearPass Access Management Basics
Customer Keynote - Microsoft Lync
Breakout - Airheads Macau 2013 - Cloud WiFi
Shanghai Breakout: 802.11ac Wi-Fi Fundamentals
Make Your Own Meridian Mobile App Workshop #AirheadsConf Italy
IDC Aruba Webinar - 3 Feb 15
Deploying Microsoft Lync over Wi-Fi #AirheadsConf Italy
Aruba Instant Workshop #AirheadsConf Italy
Breakout - Airheads Macau 2013 - WLAN Management & Troubleshooting with AirWave
Aruba Atmosphere / Airheads 2014 Keerti Melkote Keynote
WLAN Design for Location, Voice & Video
Aruba Technical Webinar: Unplugging the Last Cord
E Rate Modernization Overview
Meridian APPs and ALE at WFD6
Make Your Own Meridian Mobile App Workshop #AirheadsConf Italy
Advanced Aruba Mobility Access Switch Workshop #AirheadsConf Italy
Best Practices on Migrating to 802.11ac Wi-Fi #AirheadsConf Italy
Ad

Similar to Enabling the Virtual Enterprise (20)

PDF
ARUBA - Remote Branch-networking-fundamentals-2014
PPTX
Enabling AirPrint & AirPlay on Your Network
PPTX
Defining Advanced AAA Policies for Access Networks
PDF
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
PPTX
Network Management with Aruba Airwave #AirheadsConf Italy
PPTX
Aruba WLANs 101 and design fundamentals
PPTX
Network Management with Aruba AirWave
PPTX
Breakout - Airheads Macau 2013 - BYOD, MDM, and MAM
PDF
Instant overview gokul_rajagopalan
PPTX
ClearPass design scenarios that solve the toughest security policy requirements
PPTX
Shanghai Keynote: Keerti Demos
PDF
Mobility switch security architecture scott calzia madani adjali
PDF
Clear pass policy manager advanced_ashwath murthy
PDF
Air waveupdate sujathamandava
PDF
RAP Networks Validated Reference Design
PDF
Aruba Remote Access Point (RAP) Networks Validated Reference Design
PDF
2012 ah vegas remote networking fundamentals
PPTX
Advanced Aruba ClearPass Workshop
ARUBA - Remote Branch-networking-fundamentals-2014
Enabling AirPrint & AirPlay on Your Network
Defining Advanced AAA Policies for Access Networks
Byod and guest access workshop enabling byod carlos gomez gallego_network ser...
Network Management with Aruba Airwave #AirheadsConf Italy
Aruba WLANs 101 and design fundamentals
Network Management with Aruba AirWave
Breakout - Airheads Macau 2013 - BYOD, MDM, and MAM
Instant overview gokul_rajagopalan
ClearPass design scenarios that solve the toughest security policy requirements
Shanghai Keynote: Keerti Demos
Mobility switch security architecture scott calzia madani adjali
Clear pass policy manager advanced_ashwath murthy
Air waveupdate sujathamandava
RAP Networks Validated Reference Design
Aruba Remote Access Point (RAP) Networks Validated Reference Design
2012 ah vegas remote networking fundamentals
Advanced Aruba ClearPass Workshop

More from Aruba, a Hewlett Packard Enterprise company (20)

PPTX
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
PPTX
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
PPTX
Airheads Tech Talks: Advanced Clustering in AOS 8.x
PPTX
EMEA Airheads_ Advance Aruba Central
PPTX
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
PPTX
EMEA Airheads- Switch stacking_ ArubaOS Switch
PPTX
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
PPTX
PPTX
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
PPTX
EMEA Airheads- Aruba Central with Instant AP
PPTX
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
PPTX
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
PPTX
EMEA Airheads - AP Discovery Logic and AP Deployment
PPTX
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
PPTX
EMEA Airheads- Manage Devices at Branch Office (BOC)
PPTX
EMEA Airheads - What does AirMatch do differently?v2
PPTX
Airheads Meetups: 8400 Presentation
PPTX
Airheads Meetups: Ekahau Presentation
PPTX
Airheads Meetups- High density WLAN
PPTX
Airheads Meetups- Avans Hogeschool goes Aruba
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Advanced Clustering in AOS 8.x
EMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
EMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads - What does AirMatch do differently?v2
Airheads Meetups: 8400 Presentation
Airheads Meetups: Ekahau Presentation
Airheads Meetups- High density WLAN
Airheads Meetups- Avans Hogeschool goes Aruba

Recently uploaded (20)

PPTX
Big Data Technologies - Introduction.pptx
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PPTX
sap open course for s4hana steps from ECC to s4
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
Spectroscopy.pptx food analysis technology
Big Data Technologies - Introduction.pptx
NewMind AI Weekly Chronicles - August'25 Week I
Unlocking AI with Model Context Protocol (MCP)
The Rise and Fall of 3GPP – Time for a Sabbatical?
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Digital-Transformation-Roadmap-for-Companies.pptx
Advanced methodologies resolving dimensionality complications for autism neur...
MIND Revenue Release Quarter 2 2025 Press Release
Building Integrated photovoltaic BIPV_UPV.pdf
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Review of recent advances in non-invasive hemoglobin estimation
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Mobile App Security Testing_ A Comprehensive Guide.pdf
sap open course for s4hana steps from ECC to s4
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Spectroscopy.pptx food analysis technology

Enabling the Virtual Enterprise

  • 1. Enabling the Virtual Enterprise Dave Blank Network Engineer Facebook Michael Wong Product Manager
  • 2. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved 2 #AirheadsConf Wireless @ Facebook • 6,337 employees* • Approximately 10,000 wireless clients every day • 35 offices globally (11 US offices, 24 international) • EVERYONE is mobile (open floorplan… employees work from anywhere) • 1.23 billion monthly active users* *as of Dec 2013
  • 3. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved 3 #AirheadsConf Agenda Facebook Lighthouse @ Home RAP Zero Touch Provisioning Configuring Zero Touch Provisioning With Activate and CPPM Demo
  • 4. 4 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Remote AP Provisioning • AP Provisioning .. Need I say more?
  • 5. 5 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Controller: Provisioning Whitelist • Controller Provisioning Steps – Add AP to Whitelist on each controller – Defines a list of APs allowed to connect to controller – RAP Whitelist Definition • AP mac address • AP Group • AP Name – CLI: whitelist-db rap add mac-address [mac-addr] ap-group [ap-grp] ap-name [ap- name]
  • 6. 6 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Facebook Requirements • Zero Touch Deployment – Easy for a non-techie to deploy • Performance • Form Factor • Standardize Global Deployment • Deploy in Challenging RF Environments • Support Latest Technology including IPv6 • Extend Corporate Service – Wired IP Phone – Wired Video Conference Endpoint
  • 7. 7 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Facebook: HelpDesk Provisioning Tool • Custom Portal to Adapt to Business Workflow
  • 8. 8 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Facebook LightHouse@Home
  • 9. 9 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf To Datacenters Client VPN WAN Plug-Play Client Enterprise Secure Wi-Fi LAN Local Connectivity Enterprise Secure Wired Remote Access Points LAN/WAN/Internet Access Forwarding Priority Per User/Device/Session Dynamic Policies via Controller PEF Distributed Policy Enforcement Firewall Engine
  • 10. 10 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf RAP Bootstrapping Process • RAP obtains wired IP address using DHCP • RAP contacts master controller using FQDN or static IP • RAP attempts to form IPsec connection – Certificate (name = mac address) • IPsec SA is established between RAP and controller
  • 11. 11 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Goal: Zero Touch Provisioning • Activate • Device info is recorded on shipment • Device type, serial number, mac address • AP-Name, AP-Group and Controller-IP are defined • JSON API available • ClearPass Policy Manager • Synchronize inventory list • Maintains central whitelist for all controllers • Authorizes RAP • Controller • Authentication RAPs ClearPass Policy Manager Cluster Activate http://activate.arubanetworks.com Controller sends auth’n requests and CPPM provides auth’z info Controller Instant AP Instant AP Controller Mr. IT JSON api Instant AP will check Activate at boot for provisioning info
  • 12. 12 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Use Activate to Provision AP Info
  • 13. 13 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Aruba Activate Service What: Activate is a free Cloud Service that enables customers to deploy Aruba infrastructure more efficiently • http://activate.arubanetworks.com How: Enhances a device’s ability to find its configuration master Model: Device centric DB correlating various attributes Activate’s Inputs
  • 14. 14 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Activate: Define Rules •Activate (https://activate.arubanetworks.com) 1. Identify Configuration  IAP-to-RAP 2. Define Rules  Controller IP  AP-Group
  • 15. 15 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Activate: AP Attributes 1. Select Device  Devices are initially assigned the default folder 2. Assign Devices to Folder  Define AP-Name
  • 16. 16 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Define ClearPass Policy for Central Whitelist
  • 17. 17 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf ClearPass Policy Manager • Authentication, Authorization, Accounting (AAA) with Policy Management • Guest Management • Device Onboarding
  • 18. 18 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf CPPM: Activate Configuration • Provide Activate credentials in CPPM
  • 19. 19 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf CPPM: Add Controller
  • 20. 20 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf CPPM: Endpoint List • Validate that CPPM is receiving info
  • 21. 21 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf CPPM: Endpoint Info • EndPoint Info – Orange • Attribute for Authorization – Yellow • Attributes sent to Controller
  • 22. 22 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf CPPM: Service • Allows ClearPass Policy Manager to test Requests • Provide differentiation by access method, location or other network vendor-specific attributes
  • 23. 23 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf CPPM: Authentication • Controller will perform mac authentication to CPPM – Note: RAP will still use certificate to establish IPSec tunnel
  • 24. 24 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf CPPM: Enforcement • Define Authorization Conditions
  • 25. 25 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf CPPM: Enforcement Profile • Define Radius Attributes (Aruba VSA)
  • 26. 26 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Controller Configuration
  • 27. 27 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Controller Configuration • Define Authentication Server • Define Server Group • Assign Server Group for RAP / IAP authentication aaa authentication-server radius CPPM_01 host [CPPM_IP_ADDRESS] key PASSPHRASE ! aaa server-group CPPM_WHITELIST auth-server CPPM_01 ! aaa authentication vpn default-iap server-group CPPM_WHITELIST ! aaa authentication vpn default-rap server-group CPPM_WHITELIST ! • Controller perform whitelist lookup on CPPM instead of local-db
  • 28. 28 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Goal: Zero Touch Provisioning • Activate • Device info is recorded on shipment • Device type, serial number, mac address • AP-Name, AP-Group and Controller-IP are defined • JSON API available • ClearPass Policy Manager • Synchronize inventory list • Maintains central whitelist for all controllers • Authorizes RAP • Controller • Authentication RAPs ClearPass Policy Manager Cluster Activate http://activate.arubanetworks.com Controller sends auth’n requests and CPPM provides auth’z info Controller Instant AP Instant AP Controller Mr. IT JSON api Instant AP will check Activate at boot for provisioning info
  • 29. 29 Thank You #AirheadsConf CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved
  • 30. 30

Editor's Notes

  • #10: To understand more, let’s take a look at the RAP architecture:On one side, the RAP looks like a VPN client-in-a-box. Plug in to any network, it gets an address, then “dials” up a VPN tunnel to the data center so you don’t have to. VPN-in-a-box is not new – “hard clients” have been around for a while. But they usually stop at a simple connectivity model of attaching one or more wired ports to a VPN tunnel. The RAP is much more than that.On the LAN side that faces the end user, we provide wired and wireless connectivity options. The wireless side delivers the full enterprise-grade security, management, and control that Aruba is known for in its campus WLAN deployments. The wireless also provides full wireless intrusion prevention services to control rogue APs and misconfigured clients.In the middle is the most important part - our “secret sauce” – a technology we call PEF, or policy enforcement firewall. PEF is a technology we developed originally for our wireless LAN platform. It is a per user/device/session state access forwarding engine. What it does is function as a policy enforcement switch, controlling who/what can get in, who can do what, and even controls prioritization. Best of all it does this based on users and dynamic policies versus ports and subnets, thus dramatically simplifying and virtualizing service delivery and security policies to users. PEF is the key feature that makes the RAP different than simple “VPN-in-a-box.”
  • #31: 21:44 – 24:16