SlideShare a Scribd company logo
Aruba Mobility Access Switch Workshop 
Madani Adjali & Vinay Kammar 
December 10th & 12th 2014
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
2 #AirheadsConf 
Agenda 
Platform Overview & Resources 
Role Based Access 
Zero Touch Provisioning
Introducing the Aruba 
Mobility Access Switch Family 
• Security to wired access 
– Flexible role-based access 
– Policy moves from wireless to wired 
• Operational simplicity 
– Low-touch installation and configuration 
– Dynamic configuration of user policies 
– Integration with Aruba APs 
• 802.11ac Ready 
3 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
– 802.3at on all PoE models
4 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
Mobility Access Switch 
Capabilities 
A. L2/L3 
Forwarding 
C. Wired AP 
Mobility Access 
Switch 
Access Point 
LAN Core 
AirWave 
Management 
Platform 
Mobility 
Controller 
ClearPass 
Policy 
Manager 
B. User-Role 
Download 
A. Ethernet Switch 
- Layer 2/3 forwarding 
- Native Role-based policy 
enforcement 
B. Integration with 
ClearPass 
- Downloadable Role/ACL 
- Captive Portal 
C. Wired Access Point 
- Role-based policy enforcement 
at Mobility Controller 
- Single policy for WLAN and LAN
S3500 Mobility Access Switch 
5 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
• Designed for Wired Access 
– 24/48 Port Models 
– Role-based access with user visibility 
– Per port PoE/PoE+ 
• ArubaStack 
– Stack up to 8 devices 
– Up to 384x GbE and 16x 10GbE 
• Modular Components 
– Field replaceable AC power supplies 
• Optional redundant power supply 
– Field replaceable fan tray 
– Optional 4-port uplink module 
• 1000BASE/10GBASE-x SFP/SFP+ 
SKU Ports PoE Budget 
S3500-24F 24x1000BASE-x Not Applicable 
S3500-24T 24x10/100/1000BASE-T Not Applicable 
S3500-24P 24x10/100/1000BASE-T 400W | 689W 
S3500-24PF 24x10/100/1000BASE-T 850W | 1465W 
S3500-48T 48x10/100/1000BASE-T Not Applicable 
S3500-48P 48x10/100/1000BASE-T 400W | 689W 
S3500-48PF 48x10/100/1000BASE-T 850W | 1465W
6 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
S3500: Front & Rear Views 
Optional 
Uplink Module 
S3500 Rear View 
USB 
Console 
Field-Replaceable 
Fan Tray Hot-Swappable Power Supplies 
Ethernet 
Out-of-Band 
S3500-48P Front View 
Fixed 10/100/1000BASE-T Ports 
LCD 
Display • Dimensions & Airflow 
– 1RU 
– 1.75˝ (H) x 17.5˝ (W) x 17.5˝ (D) 
– Front/Side to Rear Airflow 
• Mounting Options 
– 2 Post Rack (front & mid-mount) 
– 4 Post Rack 
– Wall Mount 
• Limited Lifetime Warranty
7 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
S2500 Mobility Access Switch 
SKU Ports PoE Budget 
S2500-24P 24x10/100/1000BASE-T 400W 
S2500-48T 48x10/100/1000BASE-T Not Applicable 
S2500-48P 48x10/100/1000BASE-T 400W 
• Designed for Wired Access 
– 24/48 Port 10/100/1000BASE-T 
– Role-based access with user visibility 
– Per port PoE/PoE+ 
• ArubaStack 
– Stack up to 8 devices 
– Up to 384x GbE and 16x 10GbE 
• Integrated Components 
– Built in fans for quiet operation 
– Fixed 4-port uplinks 
• 1000BASE/10GBASE-x SFP/SFP+
8 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
S2500: Front & Rear Views 
• Dimensions & Airflow 
– 1RU 
– 1.75˝ (H) x 17.5˝ (W) x 12.5˝ (D) 
– Side to Side Airflow 
• Mounting Options 
– 2 Post Rack (Front) 
– Wall & 2-Post Mid Mount 
• Limited Lifetime Warranty 
S2500 Front View LCD Display 
Fixed 
4x 1000BASE-x/10GBASE-x 
(SFP/SFP+) Ports 
S2500 Rear View 
Ethernet 
Out-of-Band 
RJ-45 & Mini-USB 
Console 
USB Integrated 
Power Supply 
Fixed Fans 
48x 10/100/1000 (RJ45) Ports
9 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
S1500 Mobility Access Switch 
SKU Ports PoE Budget 
S1500-12P 24x10/100/1000BASE-T 120W 
S1500-24P 24x10/100/1000BASE-T 400W 
S1500-48P 48x10/100/1000BASE-T 400W 
• Designed for Wired Access 
– 12/24/48 Port 10/100/1000BASE-T 
– Role-based access with user visibility 
– Per port PoE/PoE+ 
• ArubaStack 
– Stack up to 8 devices 
• Integrated Components 
– Built in fans for quiet operation 
(24P/48P) 
– Fanless for public spaces (12P) 
– Fixed 2-port (12P) & 4-port (24P/48P) 
uplinks 
• 1000BASE-x SFP
Mode LEDs and 
Selector 
10 
USB 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
S1500-24P/48P: Front & 
Rear Views 
• Features & Scaling 
- Same features as S2500/S3500 
- Reduced scaling vs. 
S2500/S3500 
• Dimensions & Airflow 
– 1RU 
– 1.75˝ (H) x 17.5˝ (W) x 12.5˝ (D) 
– Side to Side Airflow 
• Mounting Options 
– 2 Post Rack (Front) 
– Wall & 2-Post Mid Mount 
• Limited Lifetime Warranty 
S1500-24/48P Rear View 
Console 
Fixed 
4x 1000BASE-X 
(SFP) Ports 
48x 10/100/1000 (RJ45) Ports 
Integrated 
Power Supply 
Fixed Fans 
S1500-48P Front View
11 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
S1500-12P: Front & Rear Views 
• Features & Scaling 
- Same features as S2500/S3500 
- Reduced scaling vs. 
S2500/S3500 
• Dimensions & Airflow 
– 1.75˝ (H) x 13˝ (W) x 12.5˝ (D) 
– Fanless 
• Mounting Options 
– Desktop (Rubber feet included) 
– Rack & Wall & Mount (Included) 
– Magnet Mount (Optional) 
• Limited Lifetime Warranty 
S1500-12P - Front View 
USB 
Console 
RJ-45 
12x 10/100/1000Base-T 
With 8x PoE/PoE+) 
2x 1000BASE-x 
(SFP) 
Mode LEDs and 
Selector 
Vents for Cooling 
on Top and Bottom 
for Fanless Design 
S1500-12P - Rear View 
Integrated 
Power Supply 
Security Lock Slot
12 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
Platform Comparison 
Capability / Feature S3500-XXP S3500-XXT S2500-XXP S2500-XXT S1500-XXP S1500-12P 
Number of Ports 24/48 24/48 24/48 24/48 24/48 12 
Uplink Performance 4 x 10G SFP+ 4 x 10G SFP+ 4 x 10G SFP+ 4 x 10G SFP+ 4 x 1G SFP 2 x 1G SFP 
Uplinks Options Modular Modular Integrated Integrated Integrated Integrated 
LCD Yes Yes Yes Yes No No 
Modular Power Yes Yes No No No No 
Dual Power Yes Yes No No No No 
PoE Budget (W) 400/689/1465 N/A 400 N/A 400 120 
Max Simultaneous PoE/PoE+ 48A/48A N/A 25/13 N/A 25/13 7/4 
Modular Fan (FRU) Yes Yes No No No No 
Depth 17.5”/19.5” A 17.5” <13” <13” <13” <9” 
Ambient Sound 48dB 48dB 42dB 42dB 42dB 0dB 
List Price (24/48) $3,995B/$6,995B $3,195B/$5,495B $3,795/$6,795 $2,995/$5,195 $2,495/$4,595 $1,595 
Note A: Assumes dual 1050W power supplies | Note B: Single power supply (600W for P SKU and 350W for T SKU) and no uplink module (S3500-4x10G - List $1495)
Platform / Layer 2 Features Routing Features 
13 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
Features & Capabilities 
• Spanning Tree Protocols 
- MSTP & Rapid PVST+ 
• Link Aggregation Group 
• L2 Generic Router Encapsulation 
• Voice VLAN 
- LLDP-MED & CDP Fingerprinting 
• Port Security 
- DHCP Snooping, DAI & IPSG 
• Quality of Service 
- Strict Priority Queuing 
- 1 Rate Tri-Color Policing 
• Routed VLAN Interfaces (RVI) 
• Static Routing 
• OSPFv2 
- Summarization & Route Filtering 
• Policy Based Routing 
• Virtual Router Redundancy Protocol 
• L3 Generic Router Encapsulation 
• Multicast 
- PIM-SM & PIM-SSM 
- IGMPv1/v2/v3 Snooping 
- MLDv1
14 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
Features & Capabilities (cont.) 
Branch Features 
• Redundant Uplinks 
- L3 Interface Monitoring (ping-probe) 
- Route Metrics for DHCP Enabled L3 
Interfaces 
• Dynamic DNS Client 
• Network Address Translation 
- Source/Destination NAT via ACL 
- Interface Based Source NAT 
- NAT Pools 
• Stateful Firewall 
- Session ACLs on RVIs & User-Roles 
Branch Features (cont.) 
• Site to Site VPN 
- Standby VPN Interface 
- Default Route to VPN 
- OSPF over VPN 
• Aruba VPN 
- Certificate based VPN using Mobility 
Controller Whitelist 
• Tunneled Node over Site to Site 
or Aruba-VPN 
• DHCP Services 
- Dynamically distribute DHCP scopes 
from Mobility Controller
15 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
Features & Capabilities (cont.) 
Authentication & Security 
• Role Based User Access 
• Deny Inter User Traffic 
• User Derived Roles 
- MAC OUI, DHCP Sig. & LLDP/CDP 
Phone Match 
• AAA Authentication 
- 802.1x, MAC Auth & Captive Portal 
• External Authentication Servers 
- Radius, TACACS+ & LDAP 
• Radius Fail-Open 
Aruba Portfolio Integration 
• Mobility Controller 
- Aruba VPN 
- Tunneled Node 
- AirGroup 
• Access Points 
- Auto AP PoE Prioritization (IAP/CAP) 
- Auto AP QoS Trust (IAP/CAP) 
- Auto AP Interface Config. (IAP/CAP) 
- Rogue AP Containment (IAP) 
- VLAN Sharing (IAP) 
• ClearPass Policy Manager 
- Downloadable Roles & Guest
16 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
Features & Capabilities (cont.) 
Management 
• Command Line Interface 
• Web UI 
• Aruba Activate 
- Cloud Provisioning Service 
- Direct Mobility Access Switch to 
Airwave or Controller for VPN 
• Aruba Central 
- Cloud Management Service 
• Airwave Management Platform 
• Discovery via DHCP 
• Discovery via Activate 
Optics & DACs 
• SFP/SFP+ Optics 
- 1000BASE-T 
- 1000BASE-SX 
- 1000BASE-LX 
- 1000BASE-EX 
- 1000BASE-ZX 
- 10GBASE-SR 
- 10GBASE-LR 
- 10GBASE-LRM 
- 10GBASE-ER 
- 10GBASE-ZR 
• Twinax/Direct Attach Copper 
- 50cm/1m/3m/5m/7m
Configuration made simple through 
intelligent wizards. 
https://ase.arubanetworks.com 
17 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
• 27 solutions and growing. 
• Solutions for Aruba Mobility Controllers, Mobility 
Access Switches, Instant APs, and CPPM/CPG. 
• 1900+ users. 75,000 views.
18 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
Role Based Access
Usernames/ 
Passwords 
19 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
AAA View of the World 
Manufacturers 
Via MAC OUI 
Operating Systems 
Via DHCP 
Fingerprinting 
Our Mobility Access Switches see… 
MAC 
Addresses 
And our security enforcement model uses… 
IP Phones 
Via Device-Type 
Fingerprinting 
User-roles 
…provisioned locally or dynamically which simplifies AAA deployments
20 
ClearPass Policy 
Manager Integration 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
Context 
• User: Joe Smith 
• Role: Guest 
Policy Enforcement Policy Definition 
Mobility 
Controller 
1. User provides their 
credentials and other 
context to Authenticate 
802.11n AP ClearPass 
Mobility Access 
Switch 
2. ClearPass Policy 
Manager returns Role 
& Policy for 
User/Device 
3. Role & Policy pushed 
to the Mobility Controller 
for Role & Policy 
Enforcement 
3. Role & Policy pushed 
to the Mobility Access 
Switch for Role & Policy 
Enforcement
21 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
Role Based Access Demo
22 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
Zero Touch Provisioning
23 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
1. Customer Enables Service 
& Inputs Provisioning Rules 
Argh! No Airwave details 
Help me Aruba Activate, 
you’re from DHCP my only either! 
hope! 
Mobility Access Switch 
#AirheadsConf 
Airwave Discovery using 
DHCP & Aruba Activate 
Branch Location 
2. Mobility Access Switch first attempts 
to download a configuration via TFTP 
Aruba 
Activate 
Airwave Management Platform 
Headquarters Location 
3. When TFTP fails, the Mobility Access 
Switch attempts to contact Airwave using 
credentials supplied by DHCP. 
5. Activate responds with 
Airwave IP, Shared Secret, 
Group Name and Folder 
Name and optional Controller 
IP for Aruba-VPN 
6. Mobility Access Switch contacts Airwave and provides 
Shared Secret, Group Name and Folder Name. 
7. Airwave contacts Mobility Access Switch 
and pushes down group configuration 
TFTP? Are 
you there? 
Hi Airwave! 
Configure Me! 
Hi Mobility 
Access Switch! 
Yippie! All 
Configured! 
Hi Mobility 
Access Switch! 
4. If no credentials are supplied via 
DHCP options, the Mobility Access 
Switch attempts to contact Activate.
AirWave Management Platform 
& Mobility Access Switch 
24 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
• Hardware Monitoring & User Visibility 
– Inventory and Uptime 
– Visibility Into Wired Network Usage 
– SNMP Trap and Syslog Support 
• Software Configuration & Firmware Management 
– Configuration Changes & Backups 
– Firmware Upgrades 
• Reporting 
– Compliance Reporting 
– Report and Track Wired Users
25 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved 
#AirheadsConf 
Zero Touch Provisioning Demo
Thank You 
26 
#AirheadsConf 
CONFIDENTIAL 
© Copyright 2014. Aruba Networks, Inc. 
All rights reserved
27

More Related Content

PPTX
Advanced Aruba Mobility Access Switch Workshop
PPTX
Advanced RF Design & Troubleshooting
PPTX
Wi-Fi Behavior of Popular Mobile Devices #AirheadsConf Italy
PDF
Air waveupdate sujathamandava
PDF
Aruba presentation solutions overview - v1
PPTX
Deploying Microsoft Lync over Wi-Fi #AirheadsConf Italy
PDF
Gigabit wifi 802.11 ac in depth_peter thornycroft
PPTX
RF characteristics and radio fundamentals
Advanced Aruba Mobility Access Switch Workshop
Advanced RF Design & Troubleshooting
Wi-Fi Behavior of Popular Mobile Devices #AirheadsConf Italy
Air waveupdate sujathamandava
Aruba presentation solutions overview - v1
Deploying Microsoft Lync over Wi-Fi #AirheadsConf Italy
Gigabit wifi 802.11 ac in depth_peter thornycroft
RF characteristics and radio fundamentals

What's hot (20)

PPTX
Roaming behavior and Client Troubleshooting
PPTX
Advanced RF Design & Troubleshooting
PPTX
WLAN Architecture - Considerations
PDF
ARUBA community - WLAN design and troubleshooting
PPTX
PPTX
Enabling AirPrint & AirPlay on Your Network
PPTX
Shanghai Breakout: Advanced RF Design and Troubleshooting
PDF
RAP Networks Validated Reference Design
PDF
2012 ah vegas wlan design for voice video
PDF
11ac and client match for the awo ash chowdappa
PDF
Optimizing wlan operations peter lane
PDF
Gigabit wi fi 802.11ac in depth onno harms
PDF
Amigopod and ArubaOS Integration
PPTX
Best Practices on Migrating to 802.11ac Wi-Fi #AirheadsConf Italy
PDF
ARUBA - Remote Branch-networking-fundamentals-2014
PDF
Base Designs Lab Setup for Validated Reference Design
PDF
Airheads scottsdale 2010 broadcast quality video over 11n
PPTX
Breakout - Airheads Macau 2013 - Top 10 Tips from Aruba TAC
PDF
2012 ah apj top 10 tips from aruba tac
PDF
Air heads rio 2010 outdoor wla-ns
Roaming behavior and Client Troubleshooting
Advanced RF Design & Troubleshooting
WLAN Architecture - Considerations
ARUBA community - WLAN design and troubleshooting
Enabling AirPrint & AirPlay on Your Network
Shanghai Breakout: Advanced RF Design and Troubleshooting
RAP Networks Validated Reference Design
2012 ah vegas wlan design for voice video
11ac and client match for the awo ash chowdappa
Optimizing wlan operations peter lane
Gigabit wi fi 802.11ac in depth onno harms
Amigopod and ArubaOS Integration
Best Practices on Migrating to 802.11ac Wi-Fi #AirheadsConf Italy
ARUBA - Remote Branch-networking-fundamentals-2014
Base Designs Lab Setup for Validated Reference Design
Airheads scottsdale 2010 broadcast quality video over 11n
Breakout - Airheads Macau 2013 - Top 10 Tips from Aruba TAC
2012 ah apj top 10 tips from aruba tac
Air heads rio 2010 outdoor wla-ns
Ad

Viewers also liked (20)

PPTX
Access Management with Aruba ClearPass #AirheadsConf Italy
PDF
3 air wave practical workshop_mike bruno_matt sidhu
PDF
Rf troubleshooting advanced kelly griffin_peter lane
PDF
1 voice and video over wi fi-balajee krishnamurthy
PPTX
Network Management with Aruba Airwave #AirheadsConf Italy
PPTX
Mobility certification through CWNP and Aruba
PPTX
Shanghai Breakout: Advanced Airwave Workshop
PPTX
Advanced Aruba Airwave Workshop #AirheadsConf Italy
PPTX
Wireless LAN Security Fundamentals
PPTX
Getting the most out of the aruba policy enforcement firewall
PPTX
Multi-Vendor Access Network Management with Aruba Airwave
POTX
Network management with Aruba AirWave
PPTX
Design Fundamentals for Remote and Branch Access Networks
PPTX
Network Management with Aruba AirWave
PPTX
Make Your Own Meridian Mobile App Workshop #AirheadsConf Italy
PPTX
PPTX
Shanghai Breakout: Access Management with Aruba ClearPass
PPTX
Make Your Own Meridian Mobile App Workshop #AirheadsConf Italy
PPTX
Enabling the Virtual Enterprise
PDF
Aruba Technical Webinar: Unplugging the Last Cord
Access Management with Aruba ClearPass #AirheadsConf Italy
3 air wave practical workshop_mike bruno_matt sidhu
Rf troubleshooting advanced kelly griffin_peter lane
1 voice and video over wi fi-balajee krishnamurthy
Network Management with Aruba Airwave #AirheadsConf Italy
Mobility certification through CWNP and Aruba
Shanghai Breakout: Advanced Airwave Workshop
Advanced Aruba Airwave Workshop #AirheadsConf Italy
Wireless LAN Security Fundamentals
Getting the most out of the aruba policy enforcement firewall
Multi-Vendor Access Network Management with Aruba Airwave
Network management with Aruba AirWave
Design Fundamentals for Remote and Branch Access Networks
Network Management with Aruba AirWave
Make Your Own Meridian Mobile App Workshop #AirheadsConf Italy
Shanghai Breakout: Access Management with Aruba ClearPass
Make Your Own Meridian Mobile App Workshop #AirheadsConf Italy
Enabling the Virtual Enterprise
Aruba Technical Webinar: Unplugging the Last Cord
Ad

Similar to Shanghai Breakout: Aruba Mobility Access Switch Workshop (20)

PPTX
Extending Role Based Policies to Wired Access
PDF
Mobility access switches_madani adjali
PPTX
Breakout - Airheads Macau 2013 - Unified Access: Deploying Mobility Access S...
PDF
Mobility switch security architecture scott calzia madani adjali
PPTX
Unified access with Aruba Mobility Access Switches – Live Demo
PPTX
Overview of Major Aruba Switching Features incl. Smart Rate for Multi-Gig Ports
PDF
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
PDF
Migrating to the 7200 controller george anderson marcus christensen
PDF
SGS-5240-48T4X Stackable Managed Switch
PDF
2012 ah vegas unified access fundamentals
PDF
Winhon Network Solution
PPTX
Aruba Netwrok(1).pptx
PPTX
Juniper round table switching and product overview
PDF
2015-02-16_HPN Sales Training
PDF
SGS-5240-20S4C4XR Stackable Managed Switch
PDF
Alcatel lucent Enterprise LAN Portfolio Overview
PDF
Introducing the Future of Data Center Interconnect Networks
PDF
Instant overview gokul_rajagopalan
PDF
IGS-6325-20S4C4X Industrial Managed Ethernet Switch
PDF
Huawei s5720 li series switches product brochure
Extending Role Based Policies to Wired Access
Mobility access switches_madani adjali
Breakout - Airheads Macau 2013 - Unified Access: Deploying Mobility Access S...
Mobility switch security architecture scott calzia madani adjali
Unified access with Aruba Mobility Access Switches – Live Demo
Overview of Major Aruba Switching Features incl. Smart Rate for Multi-Gig Ports
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Migrating to the 7200 controller george anderson marcus christensen
SGS-5240-48T4X Stackable Managed Switch
2012 ah vegas unified access fundamentals
Winhon Network Solution
Aruba Netwrok(1).pptx
Juniper round table switching and product overview
2015-02-16_HPN Sales Training
SGS-5240-20S4C4XR Stackable Managed Switch
Alcatel lucent Enterprise LAN Portfolio Overview
Introducing the Future of Data Center Interconnect Networks
Instant overview gokul_rajagopalan
IGS-6325-20S4C4X Industrial Managed Ethernet Switch
Huawei s5720 li series switches product brochure

More from Aruba, a Hewlett Packard Enterprise company (20)

PPTX
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
PPTX
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
PPTX
Airheads Tech Talks: Advanced Clustering in AOS 8.x
PPTX
EMEA Airheads_ Advance Aruba Central
PPTX
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
PPTX
EMEA Airheads- Switch stacking_ ArubaOS Switch
PPTX
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
PPTX
PPTX
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
PPTX
EMEA Airheads- Aruba Central with Instant AP
PPTX
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
PPTX
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
PPTX
EMEA Airheads - AP Discovery Logic and AP Deployment
PPTX
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
PPTX
EMEA Airheads- Manage Devices at Branch Office (BOC)
PPTX
EMEA Airheads - What does AirMatch do differently?v2
PPTX
Airheads Meetups: 8400 Presentation
PPTX
Airheads Meetups: Ekahau Presentation
PPTX
Airheads Meetups- High density WLAN
PPTX
Airheads Meetups- Avans Hogeschool goes Aruba
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Advanced Clustering in AOS 8.x
EMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
EMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads - What does AirMatch do differently?v2
Airheads Meetups: 8400 Presentation
Airheads Meetups: Ekahau Presentation
Airheads Meetups- High density WLAN
Airheads Meetups- Avans Hogeschool goes Aruba

Recently uploaded (20)

PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPT
Teaching material agriculture food technology
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PPTX
Big Data Technologies - Introduction.pptx
PPTX
A Presentation on Artificial Intelligence
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
cuic standard and advanced reporting.pdf
PPTX
Tartificialntelligence_presentation.pptx
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Group 1 Presentation -Planning and Decision Making .pptx
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
SOPHOS-XG Firewall Administrator PPT.pptx
NewMind AI Weekly Chronicles - August'25-Week II
Encapsulation_ Review paper, used for researhc scholars
MYSQL Presentation for SQL database connectivity
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Diabetes mellitus diagnosis method based random forest with bat algorithm
Unlocking AI with Model Context Protocol (MCP)
20250228 LYD VKU AI Blended-Learning.pptx
Teaching material agriculture food technology
MIND Revenue Release Quarter 2 2025 Press Release
Big Data Technologies - Introduction.pptx
A Presentation on Artificial Intelligence
Network Security Unit 5.pdf for BCA BBA.
The Rise and Fall of 3GPP – Time for a Sabbatical?
cuic standard and advanced reporting.pdf
Tartificialntelligence_presentation.pptx
Profit Center Accounting in SAP S/4HANA, S4F28 Col11

Shanghai Breakout: Aruba Mobility Access Switch Workshop

  • 1. Aruba Mobility Access Switch Workshop Madani Adjali & Vinay Kammar December 10th & 12th 2014
  • 2. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved 2 #AirheadsConf Agenda Platform Overview & Resources Role Based Access Zero Touch Provisioning
  • 3. Introducing the Aruba Mobility Access Switch Family • Security to wired access – Flexible role-based access – Policy moves from wireless to wired • Operational simplicity – Low-touch installation and configuration – Dynamic configuration of user policies – Integration with Aruba APs • 802.11ac Ready 3 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf – 802.3at on all PoE models
  • 4. 4 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Mobility Access Switch Capabilities A. L2/L3 Forwarding C. Wired AP Mobility Access Switch Access Point LAN Core AirWave Management Platform Mobility Controller ClearPass Policy Manager B. User-Role Download A. Ethernet Switch - Layer 2/3 forwarding - Native Role-based policy enforcement B. Integration with ClearPass - Downloadable Role/ACL - Captive Portal C. Wired Access Point - Role-based policy enforcement at Mobility Controller - Single policy for WLAN and LAN
  • 5. S3500 Mobility Access Switch 5 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf • Designed for Wired Access – 24/48 Port Models – Role-based access with user visibility – Per port PoE/PoE+ • ArubaStack – Stack up to 8 devices – Up to 384x GbE and 16x 10GbE • Modular Components – Field replaceable AC power supplies • Optional redundant power supply – Field replaceable fan tray – Optional 4-port uplink module • 1000BASE/10GBASE-x SFP/SFP+ SKU Ports PoE Budget S3500-24F 24x1000BASE-x Not Applicable S3500-24T 24x10/100/1000BASE-T Not Applicable S3500-24P 24x10/100/1000BASE-T 400W | 689W S3500-24PF 24x10/100/1000BASE-T 850W | 1465W S3500-48T 48x10/100/1000BASE-T Not Applicable S3500-48P 48x10/100/1000BASE-T 400W | 689W S3500-48PF 48x10/100/1000BASE-T 850W | 1465W
  • 6. 6 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf S3500: Front & Rear Views Optional Uplink Module S3500 Rear View USB Console Field-Replaceable Fan Tray Hot-Swappable Power Supplies Ethernet Out-of-Band S3500-48P Front View Fixed 10/100/1000BASE-T Ports LCD Display • Dimensions & Airflow – 1RU – 1.75˝ (H) x 17.5˝ (W) x 17.5˝ (D) – Front/Side to Rear Airflow • Mounting Options – 2 Post Rack (front & mid-mount) – 4 Post Rack – Wall Mount • Limited Lifetime Warranty
  • 7. 7 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf S2500 Mobility Access Switch SKU Ports PoE Budget S2500-24P 24x10/100/1000BASE-T 400W S2500-48T 48x10/100/1000BASE-T Not Applicable S2500-48P 48x10/100/1000BASE-T 400W • Designed for Wired Access – 24/48 Port 10/100/1000BASE-T – Role-based access with user visibility – Per port PoE/PoE+ • ArubaStack – Stack up to 8 devices – Up to 384x GbE and 16x 10GbE • Integrated Components – Built in fans for quiet operation – Fixed 4-port uplinks • 1000BASE/10GBASE-x SFP/SFP+
  • 8. 8 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf S2500: Front & Rear Views • Dimensions & Airflow – 1RU – 1.75˝ (H) x 17.5˝ (W) x 12.5˝ (D) – Side to Side Airflow • Mounting Options – 2 Post Rack (Front) – Wall & 2-Post Mid Mount • Limited Lifetime Warranty S2500 Front View LCD Display Fixed 4x 1000BASE-x/10GBASE-x (SFP/SFP+) Ports S2500 Rear View Ethernet Out-of-Band RJ-45 & Mini-USB Console USB Integrated Power Supply Fixed Fans 48x 10/100/1000 (RJ45) Ports
  • 9. 9 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf S1500 Mobility Access Switch SKU Ports PoE Budget S1500-12P 24x10/100/1000BASE-T 120W S1500-24P 24x10/100/1000BASE-T 400W S1500-48P 48x10/100/1000BASE-T 400W • Designed for Wired Access – 12/24/48 Port 10/100/1000BASE-T – Role-based access with user visibility – Per port PoE/PoE+ • ArubaStack – Stack up to 8 devices • Integrated Components – Built in fans for quiet operation (24P/48P) – Fanless for public spaces (12P) – Fixed 2-port (12P) & 4-port (24P/48P) uplinks • 1000BASE-x SFP
  • 10. Mode LEDs and Selector 10 USB CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf S1500-24P/48P: Front & Rear Views • Features & Scaling - Same features as S2500/S3500 - Reduced scaling vs. S2500/S3500 • Dimensions & Airflow – 1RU – 1.75˝ (H) x 17.5˝ (W) x 12.5˝ (D) – Side to Side Airflow • Mounting Options – 2 Post Rack (Front) – Wall & 2-Post Mid Mount • Limited Lifetime Warranty S1500-24/48P Rear View Console Fixed 4x 1000BASE-X (SFP) Ports 48x 10/100/1000 (RJ45) Ports Integrated Power Supply Fixed Fans S1500-48P Front View
  • 11. 11 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf S1500-12P: Front & Rear Views • Features & Scaling - Same features as S2500/S3500 - Reduced scaling vs. S2500/S3500 • Dimensions & Airflow – 1.75˝ (H) x 13˝ (W) x 12.5˝ (D) – Fanless • Mounting Options – Desktop (Rubber feet included) – Rack & Wall & Mount (Included) – Magnet Mount (Optional) • Limited Lifetime Warranty S1500-12P - Front View USB Console RJ-45 12x 10/100/1000Base-T With 8x PoE/PoE+) 2x 1000BASE-x (SFP) Mode LEDs and Selector Vents for Cooling on Top and Bottom for Fanless Design S1500-12P - Rear View Integrated Power Supply Security Lock Slot
  • 12. 12 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Platform Comparison Capability / Feature S3500-XXP S3500-XXT S2500-XXP S2500-XXT S1500-XXP S1500-12P Number of Ports 24/48 24/48 24/48 24/48 24/48 12 Uplink Performance 4 x 10G SFP+ 4 x 10G SFP+ 4 x 10G SFP+ 4 x 10G SFP+ 4 x 1G SFP 2 x 1G SFP Uplinks Options Modular Modular Integrated Integrated Integrated Integrated LCD Yes Yes Yes Yes No No Modular Power Yes Yes No No No No Dual Power Yes Yes No No No No PoE Budget (W) 400/689/1465 N/A 400 N/A 400 120 Max Simultaneous PoE/PoE+ 48A/48A N/A 25/13 N/A 25/13 7/4 Modular Fan (FRU) Yes Yes No No No No Depth 17.5”/19.5” A 17.5” <13” <13” <13” <9” Ambient Sound 48dB 48dB 42dB 42dB 42dB 0dB List Price (24/48) $3,995B/$6,995B $3,195B/$5,495B $3,795/$6,795 $2,995/$5,195 $2,495/$4,595 $1,595 Note A: Assumes dual 1050W power supplies | Note B: Single power supply (600W for P SKU and 350W for T SKU) and no uplink module (S3500-4x10G - List $1495)
  • 13. Platform / Layer 2 Features Routing Features 13 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Features & Capabilities • Spanning Tree Protocols - MSTP & Rapid PVST+ • Link Aggregation Group • L2 Generic Router Encapsulation • Voice VLAN - LLDP-MED & CDP Fingerprinting • Port Security - DHCP Snooping, DAI & IPSG • Quality of Service - Strict Priority Queuing - 1 Rate Tri-Color Policing • Routed VLAN Interfaces (RVI) • Static Routing • OSPFv2 - Summarization & Route Filtering • Policy Based Routing • Virtual Router Redundancy Protocol • L3 Generic Router Encapsulation • Multicast - PIM-SM & PIM-SSM - IGMPv1/v2/v3 Snooping - MLDv1
  • 14. 14 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Features & Capabilities (cont.) Branch Features • Redundant Uplinks - L3 Interface Monitoring (ping-probe) - Route Metrics for DHCP Enabled L3 Interfaces • Dynamic DNS Client • Network Address Translation - Source/Destination NAT via ACL - Interface Based Source NAT - NAT Pools • Stateful Firewall - Session ACLs on RVIs & User-Roles Branch Features (cont.) • Site to Site VPN - Standby VPN Interface - Default Route to VPN - OSPF over VPN • Aruba VPN - Certificate based VPN using Mobility Controller Whitelist • Tunneled Node over Site to Site or Aruba-VPN • DHCP Services - Dynamically distribute DHCP scopes from Mobility Controller
  • 15. 15 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Features & Capabilities (cont.) Authentication & Security • Role Based User Access • Deny Inter User Traffic • User Derived Roles - MAC OUI, DHCP Sig. & LLDP/CDP Phone Match • AAA Authentication - 802.1x, MAC Auth & Captive Portal • External Authentication Servers - Radius, TACACS+ & LDAP • Radius Fail-Open Aruba Portfolio Integration • Mobility Controller - Aruba VPN - Tunneled Node - AirGroup • Access Points - Auto AP PoE Prioritization (IAP/CAP) - Auto AP QoS Trust (IAP/CAP) - Auto AP Interface Config. (IAP/CAP) - Rogue AP Containment (IAP) - VLAN Sharing (IAP) • ClearPass Policy Manager - Downloadable Roles & Guest
  • 16. 16 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Features & Capabilities (cont.) Management • Command Line Interface • Web UI • Aruba Activate - Cloud Provisioning Service - Direct Mobility Access Switch to Airwave or Controller for VPN • Aruba Central - Cloud Management Service • Airwave Management Platform • Discovery via DHCP • Discovery via Activate Optics & DACs • SFP/SFP+ Optics - 1000BASE-T - 1000BASE-SX - 1000BASE-LX - 1000BASE-EX - 1000BASE-ZX - 10GBASE-SR - 10GBASE-LR - 10GBASE-LRM - 10GBASE-ER - 10GBASE-ZR • Twinax/Direct Attach Copper - 50cm/1m/3m/5m/7m
  • 17. Configuration made simple through intelligent wizards. https://ase.arubanetworks.com 17 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf • 27 solutions and growing. • Solutions for Aruba Mobility Controllers, Mobility Access Switches, Instant APs, and CPPM/CPG. • 1900+ users. 75,000 views.
  • 18. 18 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Role Based Access
  • 19. Usernames/ Passwords 19 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf AAA View of the World Manufacturers Via MAC OUI Operating Systems Via DHCP Fingerprinting Our Mobility Access Switches see… MAC Addresses And our security enforcement model uses… IP Phones Via Device-Type Fingerprinting User-roles …provisioned locally or dynamically which simplifies AAA deployments
  • 20. 20 ClearPass Policy Manager Integration CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Context • User: Joe Smith • Role: Guest Policy Enforcement Policy Definition Mobility Controller 1. User provides their credentials and other context to Authenticate 802.11n AP ClearPass Mobility Access Switch 2. ClearPass Policy Manager returns Role & Policy for User/Device 3. Role & Policy pushed to the Mobility Controller for Role & Policy Enforcement 3. Role & Policy pushed to the Mobility Access Switch for Role & Policy Enforcement
  • 21. 21 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Role Based Access Demo
  • 22. 22 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Zero Touch Provisioning
  • 23. 23 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved 1. Customer Enables Service & Inputs Provisioning Rules Argh! No Airwave details Help me Aruba Activate, you’re from DHCP my only either! hope! Mobility Access Switch #AirheadsConf Airwave Discovery using DHCP & Aruba Activate Branch Location 2. Mobility Access Switch first attempts to download a configuration via TFTP Aruba Activate Airwave Management Platform Headquarters Location 3. When TFTP fails, the Mobility Access Switch attempts to contact Airwave using credentials supplied by DHCP. 5. Activate responds with Airwave IP, Shared Secret, Group Name and Folder Name and optional Controller IP for Aruba-VPN 6. Mobility Access Switch contacts Airwave and provides Shared Secret, Group Name and Folder Name. 7. Airwave contacts Mobility Access Switch and pushes down group configuration TFTP? Are you there? Hi Airwave! Configure Me! Hi Mobility Access Switch! Yippie! All Configured! Hi Mobility Access Switch! 4. If no credentials are supplied via DHCP options, the Mobility Access Switch attempts to contact Activate.
  • 24. AirWave Management Platform & Mobility Access Switch 24 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf • Hardware Monitoring & User Visibility – Inventory and Uptime – Visibility Into Wired Network Usage – SNMP Trap and Syslog Support • Software Configuration & Firmware Management – Configuration Changes & Backups – Firmware Upgrades • Reporting – Compliance Reporting – Report and Track Wired Users
  • 25. 25 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Zero Touch Provisioning Demo
  • 26. Thank You 26 #AirheadsConf CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved
  • 27. 27

Editor's Notes

  • #5: 30:24 – 32:44
  • #28: 21:44 – 24:16