|
Management
- Wi-Fi Clear Connect
provides a system-wide approach to help ensure WLAN reliability by proactively determining and adjusting to changing RF conditions and by identifying rogue activity and enforcing prevention policies, and optimizing WLAN performance by detecting interference from Wi-Fi and non-Wi-Fi sources using spectrum analysis capabilities built into specific access points (refer to the HPE Access Point—Controller Compatibility Matrix for specific access points supported).
- Advanced radio resource management
- Automatic radio power adjustments include real-time power adjustments based on changing environmental conditions and signal coverage adjustment
- Automatic radio channel provides intelligent channel switching and real-time interference detection
- Intelligent client load balancing balances the number of clients across multiple APs to optimize AP and client throughput
- Airtime fairness helps ensure equal RF transmission time for wireless clients
- Signal detection/classification identifies source of RF interference, such as Bluetooth® , cordless phones, and microwave ovens
- Evaluation of channel quality helps detect severe channel degradation and improves the reporting of poor RF performance
- Band navigation
enables automatic redirection of 5 GHz-capable clients to the less-congested 5 GHz spectrum
- Enterprise network management
is provided by HPE Intelligent Management Center (IMC) Platform Software and the IMC Wireless Services Manager Software Module, which effectively integrate traditionally disparate management tools into one easy-to-use interface
- Secure controller management
securely manages the controller from a single location with IMC or any other SNMP management station; controller supports SNMPv3 as well as SSH and SSL for secure CLI and Web management
- Support for environments using Bonjour services
- Gateway allows discovery of Bonjour services located in a different layer-3 network
- HPE Zerocast eliminates Bonjour multicast traffic from the WLAN enabling scalable deployment of Apple devices with no performance impact on the Wi-Fi network
- Access control enables filters to be applied inbound and outbound (on the AP) to SSIDs, groups of or specific APs. User based filtering can block Bonjour traffic until the user is authenticated
- VLAN pooling
enables wireless clients to be dynamically assigned to different VLANs so administrators can assign different subnets to different clients in the same SSID. A VLAN pool can bind to multiple SSIDs
- Unified network visibility
provides visibility between a wired and wireless network using IEEE 802.1AB Link Layer Discovery Protocol (LLDP) and sFlow
- AP Plug and Play (PnP)
provides zero-configuration capability. An AP without a predefined configuration file can connect to the WLAN controller and the WLAN Controller will provision it with the correct wireless configuration
- Policy based forwarding
simplifies the deployment of centralized or local forwarding. The policy-based mode allows user to classify data traffic based on ACL and choose local or centralized forwarding. Policy-based forwarding can be applied based on SSID or user-profile. That means a forwarding policy can be applied on a SSID or a specific user or a group of users
- AP grouping
enables an admin to easily apply AP-based or radio-based configurations to all the AP that are in the same group
- Staged Firmware Upgrades
enables an admin to selectively upgrade APs, typically a group of APs, to minimize the impact of upgrading large deployments of APs to a new version of firmware}
- Custom antenna settings
allow the admin to select a custom antenna gain
Quality of Service (QoS)
- End-to-end QoS
the HPE 10500/7500 20G Unified Wired-WLAN Module supports the DiffServ standard and IPv6 QoS; the QoS DiffServ model includes traffic classification and traffic policing, and fully implements six groups of services—EF, AF1 through AF4, and BE
- IEEE 802.1p prioritization
delivers data to devices based on the priority and type of traffic
- Class of Service (CoS)
sets the IEEE 802.1p priority tag based on IP address, IP Type of Service (ToS), Layer 3 protocol, TCP/UDP port number, source port, and DiffServ
Security
- Web-based authentication
provides a browser-based environment to authenticate clients that do not support the IEEE 802.1X supplicant
- IEEE 802.1X and RADIUS network logins
support port-based and SSID-based 802.1X authentication and accounting
- WEP, WPA2, or WPA encryption
can be deployed at the AP to lock out unauthorized wireless access by authenticating users prior to granting network access; robust Advanced Encryption Standard (AES) or Temporal Key Integrity Protocol (TKIP) encryption secures the data integrity of wireless traffic
- Secure shell
encrypts all transmitted data for secure remote CLI access over IP networks
- Media access control (MAC) authentication
provides simple authentication based on a user's MAC address; supports local or RADIUS-based authentication
- Integrated Wireless Intrusion Detection System (WIDS)
provides support for hybrid and dedicated modes; detects flood, spoofing, and weak IV attacks; displays statistics (events) and history; supports configuration of detection policies
- Integrated Wireless Intrusion Prevention System (WIPS)
automatically identifies and classifies all APs and stations; enables packet-trigger containment via knowledge-based heuristics; protects against honeypot attacks and enforces STA security; detects Denial of Service (DoS) attacks via pre-defined DoS attacks, and provides a Signature mechanism which allows admins to define custom rules; enables Virtual Service Domains to deploy security policies by department or location for example
- Secure user isolation
virtual AP services enable the network administrator to provide specific services for different user groups, allowing effective resource sharing, and simplifying network maintenance and management
- Secure access by location
AP location-based user access control helps ensure that wireless users can access and authenticate only to preselected APs, enabling system administrators to control the locations where a wireless user can access the network
- Endpoint Admission Defense
integrated wired and wireless Endpoint Admission Defense (EAD) helps ensure that only wireless clients that comply with mandated enterprise security policies can access the network, reducing threat levels caused by infected wireless clients and improving the overall security of the wireless network
- Public Key Infrastructure (PKI)
used to control access
- Authentication, authorization, and accounting (AAA)
uses an embedded authentication server or external AAA server for local users
- Wireless Intelligent Application Aware Feature (WIAA)
provides a user role based or SSID based firewall embedded in WLAN Controller via ACL-based packet filter firewall and ASPF firewall. Protect clients from outside attacks Restrict specific users from accessing specific network resources
- Source Address Validation Improvement (SAVI)
records the wireless client's IP address and MAC address and at the next data traffic forwarding stage, SAVI will validate the client's IP address to prevent attacker spoofing other client's IP address
Connectivity
- IPv6 host enables controllers to be managed and deployed at the IPv6 network's edge
- Dual stack (IPv4 and IPv6) transitions customers from IPv4 to IPv6, supporting connectivity for both protocols
- MLD snooping directs IPv6 multicast traffic to the appropriate interface, preventing traffic flooding
- IPv6 ACL/QoS supports ACL and QoS for IPv6 network traffic
- NAT traversal helps ensure that communication between a branch office AP and module is supported when the branch uses NAT
- Integrated NAT support replaces the private source IP address with a public address; enables multiple internal addresses to be mapped to the same public IP address; permits only certain internal IP addresses to be NATed, and provides an Application Layer Gateway that supports specific application protocols without requiring the NAT platform to be modified
- IEEE 802.3ad Link Aggregation Control Protocol (LACP)
Performance
- Flexible forwarding modes
- Enable distributed and centralized traffic forwarding with centralized forwarding, wireless traffic is sent to the module for processing. With distributed mode wireless traffic is dropped off locally. In the event that connectivity to the module is lost, authenticated clients can continue to access local resources
- Support local drop off or centralization of data traffic after an HTML authentication using the built-in portal server or IMC portal authentication
- Wireless user access control and management
support defining settings such as Committed Access Rate (CAS), QoS profiles, and access control policies based on location for different applications
- Fast roaming
supports Layer 3 roaming and fast roaming, satisfying the most demanding voice service requirements
- Robust switching capacity and wire-speed processing
deliver powerful forwarding capacity to support large enterprise WLANs
Resiliency and high availability
- High reliability
the module supports 1+1, N+1, and N+N backup; the 1+1 redundancy configuration of the modules supports subsecond-level failure detection; APs establish AP-module tunnel links with both modules, but only the links to the active module are active; when the active module fails, the heartbeat mechanism between the two modules help ensure that the standby module can sense the failure in subsecond level and then informs the APs to switch over to it, thus providing service continuity
- 802.1X hot-backup
enables two controllers to sync 802.1X state information and wireless client's 802.11 information from master to backup. This feature is only supported on the HPE 850, HPE 870 and 20G Unified Module
Layer 2 switching
- VLAN support and tagging
supports IEEE 802.1Q with 4,094 simultaneous VLAN IDs
- Jumbo packet support
supports up to 4 KB frame size to improve the performance of large data transfers
Scalability
- Ease of deployment
The module uses the backplane of all network and management communications, with no need for external network power connections
- Optional 32 or 128 access-point upgrade license
- Increases support for additional access points without the need to buy additional costly hardware and use additional valuable space in a chassis.
- A reduced-cost 128-access point license is available for use on this redundant module. Refer to the Specifications and Accessories sections for more detail.
Comprehensive portfolio
- Access point support
Refer to the HPE Access Point—Controller Compatibility Matrix (http://h20195.www2.hpe.com/V2/GetDocument.aspx?docname=4AA5-0345ENW&cc=us&lc=en).
Warranty and support
- 1-year warranty
see http://www.hpe.com/networking/warrantysummary for warranty and support information included with your product purchase.
- Electronic and telephone support
1-year limited electronic and telephone support is available from HPE; to reach our support centers, refer to http://www.hpe.com/networking/contact-support; for details on the duration of support provided with your product purchase, refer to http://www.hpe.com/networking/warrantysummary
- Software releases
includes all offered software releases for as long as you own the product; to find software for your product, refer to http://www.hpe.com/networking/support; for details on the software releases available with your product purchase, refer to http://www.hpe.com/networking/warrantysummary |