HPE ArubaOS 8.5: технические характеристики и документация
В архивеOverview
|
ArubaOS 8.5 |
|
ArubaOS is the network operating system for Aruba Mobility Masters, Mobility Controllers and controller-managed campus access points (APs). With industry-leading software innovation, ArubaOS is engineered to deliver enterprise-grade performance and mission-critical reliability for enterprise deployments of all sizes. Aruba supports the latest Wi-Fi Alliance standards such as Wi-Fi 6 (802.11ax) and Wi-Gig (802.11ad), as well as WPA3 and Enhanced Open security protocols. Also supported are all previous standards and protocols such as 802.11a/b/g/n/ac, which enables your network to satisfy today's and tomorrow's use cases (See Table 1). Simple And Secure Access ArubaOS also serves a key role in Dynamic Segmentation, enforcing policy based on user role, device type, application and location to simplify and secure wired and wireless network access. This feature can be enabled with the ArubaOS Policy Enforcement Firewall (PEF) license and eliminates the need to manually configure SSIDs, VLANs or ACLs for each new client on the network.
For a list of detailed features refer to the release notes available here. |
|
|
|
|
|
Figure 1: ArubaOS 8 user interface |
|
|
|
key Features
|
|
|
|
Ordering Information | |
|
Description |
SKU |
|
Aruba LIC-ENT Enterprise (LIC-AP LIC-PEF LIC-RFP and LIC-AW) License Bundle E-LTU |
JW471AAE |
|
Aruba LIC-AP Controller per AP Capacity License E-LTU |
JW472AAE |
|
Aruba LIC-PEF Controller Policy Enforcement Firewall per AP License E-LTU |
JW473AAE |
|
Aruba LIC-RFP Controller RFProtect per AP License E-LTU |
JW474AAE |
|
Aruba LIC-VIA per VIA Client License E-LTU |
JZ148AAE |
|
NOTE: This license enables firewall services on a per session basis for VPN termination from Aruba VIA VPN client |
|
|
Aruba LIC-ACR Controller Advanced Cryptography 1 Session License E-LTU |
Q9B90AAE |
|
Aruba LIC-ACR-8 Controller Advanced Cryptography 8 Session License E-LTU |
JW538AAE |
|
Aruba LIC-ACR-32 Controller Advanced Cryptography 32 Session License E-LTU |
JW539AAE |
|
Aruba LIC-ACR64 Controller Advanced Cryptography 64 Session License E-LTU |
JW540AAE |
|
Aruba LIC-ACR-128 Controller Advanced Cryptography 128 Session License E-LTU |
JW541AAE |
|
Aruba LIC-ACR-256 Controller Advanced Cryptography 256 Session License E-LTU |
JW542AAE |
|
Aruba LIC-ACR-512 Controller Advanced Cryptography 512 Session License E-LTU |
JW543AAE |
|
Aruba LIC-ACR-1024 Controller Advanced Cryptography 1024 Session License E-LTU |
JW544AAE |
|
Aruba Controller Web Content Classification 1 Year Subscription E-STU |
JY028AAE |
|
Aruba Controller Web Content Classification 3 Year Subscription E-STU |
JY029AAE |
|
Aruba Controller Web Content Classification 5 Year Subscription E-STU |
JY030AAE |
|
Aruba Controller Web Content Classification 7 Year Subscription E-STU |
JY031AAE |
|
Aruba Controller Web Content Classification 10 Year Subscription E-STU |
JY032AAE |
|
Aruba LIC-7005-PEFV Controller Policy Enforcement Firewall for Aruba 7005 Controller License E-LTU |
JW495AAE |
|
Aruba LIC-7008-PEFV Controller Policy Enforcement Firewall for Aruba 7008 Controller License E-LTU |
JY342AAE |
|
Aruba LIC-7010-PEFV Controller Policy Enforcement Firewall for Aruba 7010 Controller License E-LTU |
JW496AAE |
|
Aruba LIC-7024-PEFV Controller Policy Enforcement Firewall for Aruba 7024 Controller License E-LTU |
JW497AAE |
|
Aruba LIC-7030-PEFV Controller Policy Enforcement Firewall for Aruba 7030 Controller License E-LTU |
JW498AAE |
|
Aruba LIC-7205-PEFV Controller Policy Enforcement Firewall for Aruba 7205 Controller License E-LTU |
JW499AAE |
|
Aruba LIC-7210-PEFV Controller Policy Enforcement Firewall for Aruba 7210 Controller License E-LTU |
JW500AAE |
|
Aruba LIC-7220-PEFV Controller Policy Enforcement Firewall for Aruba 7220 Controller License E-LTU |
JW501AAE |
|
Aruba LIC-7240-PEFV Controller Policy Enforcement Firewall for Aruba 7240 Controller License E-LTU |
JW502AAE |
|
| |
Standard Features
|
Features and Benefits | ||||||||||||||||
|
Advanced Cryptography (ACR) Fully FIPS 140-2 validated and Common Criteria-certified, the ACR add-on license provides Suite B cryptography which enables secure access to remote users who handle controlled unclassified, confidential and classified information. Enhanced Wi-Fi authentication security The addition of WPA3 support brings stronger encryption and authentication methods, and Enhanced Open provides per user encryption on open networks. New MPSK feature enables simpler passkey management for WPA2 devices – should the Wi-Fi password on one device type needs to be changed; no key changes are needed for other types of devices on the network. (See Table 1) Read the white paper. | ||||||||||||||||
|
| ||||||||||||||||
| ||||||||||||||||
|
| ||||||||||||||||
|
24/7 Mission-Critical Networking With the growth in cloud-based applications, services, IoT and mobile devices, end-users expect network resources to be available wherever and whenever they connect. Likewise, enterprise networks must extend beyond traditional security perimeters while delivering a seamless user experience. With the latest version of ArubaOS, controller clustering boosts network performance and ultimately helps organizations improve productivity by upwards of hundreds or even thousands of hours every year.
Controller clustering allows up to 12 Mobility Controllers to act as a single virtual instance managed by a Mobility Master – improving reliability in the rare case that a network device goes offline. User session information is shared to ensure no interruption to active voice calls, video streams, data transfers and client roaming. Live and in-service upgrades also help to eliminate or reduce maintenance windows as well as scale performance for the largest and most-demanding wireless LANs. Mobility Controllers in standalone, campus, or branch mode can also be deployed in 1:1 or 1:N VRRP-based redundant configurations. (See Table 2 and 3)
Management, configuration and troubleshooting are provided through a browser-based GUI (See Figure 1 and Table 4) or through CLI – familiar for any network manager. The Mobility Master can centrally configure and manage Mobility Controllers and APs in a large campus or distributed branch environments, and provide intuitive task-based wizards to ease configuration. | ||||||||||||||
|
| ||||||||||||||
| ||||||||||||||
|
| ||||||||||||||
| ||||||||||||||
|
| ||||||||||||||
| ||||||||||||||||||||||||||||||
|
| ||||||||||||||||||||||||||||||
|
Performance
Adaptive Radio Management (ARM) ARM maximizes an AP's Wi-Fi stability and predictability by dynamically choosing the best 802.11 channel and transmit power. This capability helps ensure optimal performance for all clients and applications, especially in environments with a large number of mobile users and performance-stringent applications that can cause network contention and interference. (See Table 5) | ||||||||||||||||||||||||||||||
|
| ||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||
|
| ||||||||||||||||||||||||||||||
|
ClientMatch A patented RF optimization technology, ClientMatch is a feature of ARM that boosts Wi-Fi client performance by alleviating sticky client issues. Client devices associate with the best-performing AP and can also be grouped based on its supported Wi-Fi standards (e.g. downlink or uplink MU-MIMO) to improve system capacity. This is ideal for environments with complex roaming requirements. | ||||||||||||||||||||||||||||||
|
| ||||||||||||||||||||||||||||||
|
Centralized tunneling To improve AP utilization (e.g. memory, processing and bandwidth) for networks with complex Layer 2 and Layer 3 requirements, AP licenses enable individual APs to forward all traffic, policy, management and control decisions to a controller. ArubaOS 8 and later releases also allow Aruba access switches to mimic the role of an AP (e.g. wired AP) – switch configuration and management is delivered through Aruba AirWave. (See Table 6) | ||||||||||||||
|
| ||||||||||||||
| ||||||||||||||
|
| ||||||||||||||
|
Context-aware controls Support for 802.11e and Wi-Fi Multimedia (WMM) ensures wireless QoS for delay-sensitive applications with mapping between WMM tags and internal hardware queues. Mobility Controllers enable mapping of 802.1p and IP DiffServ tags to hardware queues for wired-side QoS and can be instructed to apply certain 802.1p and IP DiffServ tags to different applications on demand. ArubaOS also includes device fingerprinting, which allows network managers to assign policies based on device type and firmware (e.g. iPhone, Android, etc). This allows the network to regulate which devices are provided access to the network and how these devices can be used. (See Table 7) | ||||||||||||||
|
| ||||||||||||||
| ||||||||||||||
|
| ||||||||||||||
|
VLAN pooling Instead of configuring VLANs on every network edge switch, something in ArubaOS centralized in Mobility Controllers and tunneled to APs. Major advantages include reduced network configuration complexity and max spanning tree diameter. User membership of VLANs is load-balanced to maintain optimal network performance as large groups of users move about the network. | ||||||||||||||
|
| ||||||||||||||
|
Seamless Layer 2 and Layer 3 roaming ArubaOS includes proxy mobile IP/DHCP functions to provide seamless connectivity as users move between floors, buildings or across the entire network – even while using video and voice applications. Roaming handoff times of just 2-3 milliseconds, without reauthentication, changes to IP addresses or loss of firewall state. When ArubaOS runs on Mobility Master, roaming is enabled through Controller Clustering. (See Table 8) | ||||||||||||||||
| ||||||||||||||||
|
Security
Dynamic Segmentation For each wireless client, wired port or user on a wired port, traffic can be forwarded to a Mobility Controller or Gateway and then securely segmented based on User Firewalls. Port-based tunneling (PBT) can be used to forward all traffic from a wired port, while user-based tunneling (UBT) can forward role-specific traffic - completely eliminating the need for network administrators to locally configure ACLs, VLANs and subnets. | ||||||||||||||||
|
| ||||||||||||||||
|
Policy Enforcement Firewall (PEF) As a key component of Dynamic Segmentation, PEF is an ArubaOS license that enables user firewalls and application visibility. It delivers full policy enforcement based on user role, application, device and location awareness over WLAN, LAN and remote VPN connections for Remote APs, Instant APs and VIA VPN client services.
Policies can be manually created within ArubaOS, or centrally managed by Aruba ClearPass Policy Manager and applied to multiple networks simultaneously. | ||||||||||||||||
|
| ||||||||||||||||
|
Application visibility and control Application visibility is a feature within PEF that provides extensive visibility and control into over 3,000 apps using Deep Packet Inspection (DPI) for classification. Optimizing and limiting traffic per application is simple, and intuitive via an easy-to-use dashboard.
Unrecognized applications and categories can also be defined through Application visibility customization. (See Figure 2 and Table 9) | ||||||||||||||||
|
| ||||||||||||||||
| ||||||||||||||||
|
| ||||||||||||||||
|
|
|
Figure 2: Application traffic analysis dashboard |
|
|
|
Remote Access Point (RAP) capabilities With the same ArubaOS AP license, Aruba RAPs can be deployed in disparate locations such as small offices/home offices (SOHO) or temporary work sites. Each builds a hybrid IPSec/SSL VPN connection to a Mobility Controller, which takes on a dual-role as a VPN concentrator (VPNC) as well. (See Figure 3 and Table 10) |
|
|
|
|
|
Figure 3: Aruba RAPs for secure mobile connectivity to micro-branch and small offices |
|
|
| ||||||||||||||||||||||||||||
|
| ||||||||||||||||||||||||||||
|
Virtual Intranet Access (VIA) VPN support A VIA add-on license lets remote users securely connect to an Aruba network through a hybrid IPSec/SSL VPN client without the need for a dedicated VPNC in an enterprise DMZ. Users devices adhere to the same policies and service definitions used at headquarters or a branch. ArubaOS supports Windows, Mac, iOS, Android, and Linux, using split- or full-tunnel connections. (See Table 11) | ||||||||||||||||||||||||||||
|
| ||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||
|
| ||||||||||||||||||||||||||||
|
Web classification (WebCC) With an optional subscription, ArubaOS provides a cloud- based web content classification, policy and reputation service for URL filtering, IP reputation and geolocation filtering – which can be used to block and rate-limit connections based on Aruba's identity-based controls. (See Figure 4 and Table 12) | ||||||||||
|
| ||||||||||
|
| ||||||||||
|
Figure 4: WebCC dashboard | ||||||||||
|
| ||||||||||
| ||||||||||
|
| ||||||||||
|
WIPS/WIDS and rogue AP protection To protect against ad hoc networks, man-in-the-middle attacks, denial-of-service attacks and to distinguish between Wi-Fi and non-Wi-Fi sources, the ArubaOS RFProtect module provides integrated WIPS/WIDS/rogue AP containment and classification without requiring a separate system of RF sensors and security appliances. Aruba's rogue AP classification algorithms accurately differentiate between rogue APs connected to the network versus nearby interfering APs. | ||||||||||
|
| ||||||||||
|
Third-party integration REST-based APIs allow for integration with firewall providers such as Palo Alto Networks and Check Point Software to ensure end-to-end security. Policies can be pre-defined for specific types of traffic and forwarded to an on-premises security firewall for additional inspection. | ||||||||||
|
| ||||||||||
|
Unified Communications & Collaboration (UCC)
Third-party integration ArubaOS provides QoS features for specific Microsoft Skype for Business/Lync traffic, such as video, voice, messaging and file-sharing. With an integrated UCC dashboard, ArubaOS provides call quality metrics (latency, jitter, packet loss) for Microsoft Skype for Business/Lync, Alcatel Lucent New Office Environment (NOE), Microsoft Teams, Apple Facetime, Cisco Jabber, Cisco Spark, Cisco Skinny Call Control Protocol (SCCP), Spectralink Voice Priority (SVP), SIP, H.323, and Vocera. This provides network managers with enhanced application visibility, as well as key Wi-Fi troubleshooting capabilities. Aruba's application fingerprinting technology also enables ArubaOS to follow encrypted signaling protocols and postpone ARM scanning and ClientMatch roaming to optimize user experience during active call sessions. (See Figure 5)
|
|
|
|
|
|
Figure 5: UCC dashboard |
|
|
|
Wi-Fi Calling support Wi-Fi Calling is used by carriers to offload cellular voice traffic on Wi-Fi networks to improve their reach inside buildings and areas of poor cellular coverage. ArubaOs treats Wi-Fi Calling as a UCC voice application and applies quality of service, blocks and throttles calls through an integrated UCC dashboard. Aruba also offers visibility on a per-user, per-device and a per-carrier basis. |
|
|
|
WAN Performance
Routing and metrics ArubaOS uses features such as Policy-based Routing, Dynamic Path Steering and compression to improve WAN health with intelligence that spans WLAN and WAN. An integrated dashboard also helps visualize key WAN metrics such as latency, jitter and packet loss across public and private uplinks. (Figure 6) |
|
|
|
|
|
Figure 6: WAN dashboard |
|
|
|
Operations
Integrated captive portal For headless client devices or those without WPA, VPN or other security software, ArubaOS supports a web browser-based captive portal that provides secure web-based authentication. Captive portal authentication is encrypted using SSL, and can support both registered users with a login and password or guest users who supply only an email address. For advanced guest access needs, refer to Aruba ClearPass Guest. |
|
|
|
MDNS and DLNA support (AirGroup) Built in software that makes it easy to use and provide access to Apple TVs, printers, Google Chromecasts, and other DNS-advertised devices across subnets. Simple configuration options ensure that these client devices can see each other, while advanced options limit access to certain devices based on physical location, time of day, role and self-provisioned sharing islands. |
|
|
|
Point-to-point and mesh capabilities ArubaOS supports a flexible, wire-free design for AP uplinks in the absence of fiber or cable runs. Most commonly deployed for point-to-point wireless backhaul, security camera use cases and for network access in on-premises locations, wireless mesh provides the same enterprise network services as standard wire-based design. Aruba uses an intelligent link management algorithm between each AP to automatically adjust and optimize traffic paths and links. Network managers can repurpose any Aruba indoor or outdoor AP, or utilize new 802.11ad technology for high-performance and extended range requirements. (See Figure 7 and Table 13) |
|
|
|
| ||||||||||||||||||||
|
Figure 7: Secure Enterprise Mesh | ||||||||||||||||||||
|
| ||||||||||||||||||||
| ||||||||||||||||||||
|
| ||||||||||||||||||||
|
IPv6 support ArubaOS supports IPv6 environments as well as dual-stack interoperability of IPv6 within an IPv4 network. This is ideal for organizations that have nearly depleted available IPv4 addresses and need to transition from IPv4 to IPv6 (which adds a much larger address space). (See Table 14) | ||||||||||||||||||||
|
| ||||||||||||||||||||
| ||||||||||||||||||||
|
| ||||||||||||||||||||
|
Multivendor network management Aruba AirWave provides unified network management for Aruba controller managed APs and multivendor wireless, wired and WAN environments. AirWave can be used for planning and deployment to monitoring, analysis and troubleshooting. It also provides long-term trending and reporting, helpdesk integration tools and customizable alerts. | ||||||||
|
| ||||||||
|
Network analytics and assurance ArubaOS integration with Aruba NetInsight offers automated network optimization and performance enhancements. AI-powered machine learning algorithms gather data from ArubaOS, benchmarks the network against similar peer networks and recommends configuration changes as needed for RF, authentication and DHCP request performance. | ||||||||
|
| ||||||||
|
Advanced policy management ArubaOS integrates with Aruba ClearPass for policy management, AAA functions, advanced guest access and onboarding of devices across multivendor wired, wireless, and distributed remote networks. ClearPass addresses the security requirements for enterprises with increasing IoT, BYOD, and segmentation challenges. | ||||||||
|
| ||||||||
|
IoT and location-ready wireless support ArubaOS includes integration with Aruba Meridian, ALE, and third-party Wi-Fi, BLE, Zigbee and USB-based vendor solutions. Each Aruba AP serves as an IoT and location-ready gateway with no additional ArubaOS software required. | ||||||||
|
| ||||||||
|
Enhanced Mobility Master Capabilities
AI-powered RF management (AirMatch) An RF management innovation, AirMatch automates network-wide RF channels, channel width and radio power assignment. By utilizing machine learning algorithms, AirMatch proactively learns and acclimates the network based on changing environmental conditions and system capacity. (See Table 15) | ||||||||
|
| ||||||||
| ||||||||
|
| ||||||||
|
Hierarchical configuration and improved visibility ArubaOS running on the Mobility Master, uses a centralized, multi-tiered architecture that consolidates all deployment models (e.g. all-master, single-master/multiple-local, and multiple-master/local) through a dedicated management console. Network configurations can be implemented and distributed from the Mobility Master through zero-touch provisioning (ZTP) to all Mobility Controllers. The Mobility Master also allows for licensing pools that can allocate licenses to individual controllers based on site requirements. | ||||||||
|
| ||||||||
|
Hitless Failover and automated load balancing Using Controller Clusters, user sessions and AP traffic are load balanced to optimize network utilization during peak periods and maximize availability during unplanned outages. This means that users will not notice any impact to voice calls, video streaming or data transfers in an unlikely event that a controller loses connectivity. | ||||||||
|
| ||||||||
|
Live Upgrade and multiple version support With Mobility Master, ArubaOS can be upgraded while supporting active user sessions – eliminating the need for planned maintenance windows or downtime. Each Controller Cluster or individual service modules (AppRF, AirGroup, ARM, etc.) can be selectively upgraded without impacting the rest of the network. | ||||||||
|
| ||||||||
|
Multi-tenancy Wi-Fi support (MultiZone) Different controllers can be used with the same AP infrastructure to terminate different SSIDs on different Aruba controllers while maintaining complete segmentation and security for all networks, policies, management and visibility. This is ideal for multi-tenancy requirements where multiple organizations are housed in a single office space, or for a single organization that requires separate secure networks. For more information, refer to the MultiZone technical brief. |
|
|
|
Northbound APIs (NBAPI) The Mobility Master includes a full set of NBAPIs that enable deep visibility into the network. NBAPIs provide RF health metrics, app utilization, device type and user data in an easy-to-integrate format. 3rd party applications can receive this information for improved visibility and monitoring. |
|
|
Service and Support
|
Service And Warranty Information Hardware: 1 year parts/ labor, can be extended with support contract Software: 90 days, can be extended with support contract For additional information on Aruba WLAN products, please refer to:
|
|
|
Technical Specifications
|
Certifications
|
|
|
|
Standards Supported |
|
|
|
General switching and routing
|
|
|
|
QoS and policies
|
|
|
|
Wireless
|
|
|
|
Management and traffic analysis
|
|
|
|
Security and encryption
Security and encryption
|
|
|
Summary of Changes
|
Date |
Version History |
Action |
Description of Change |
|
03-Jun-2019 |
Version 1 |
New |
New QuickSpecs |
| ||||||||||||||||||



































