HPE Aruba

HPE Alba

Secure mobile solution

HPE Aruba

Centralized management of wireless LAN environment

A mobility controller (MC) centrally manages the entire wireless LAN system.
The MC handles all processing such as radio wave adjustment, authentication, encryption processing, policy control, and QoS. You can also check the operating status and communication status of each AP, as well as setting changes and version upgrades for access points (APs).
In addition, it is possible to easily check the authentication log when the user connects to the wireless LAN and the connection log such as which AP the user has connected to.

  • Centralized management of wireless LAN environment

Optimization of wireless LAN environment

The AP regularly monitors the surrounding radio wave conditions, and the MC automatically sets the optimum radio wave strength and channel.
In addition, when the channel is automatically switched, the effect on the user is minimized by, for example, switching when the client terminal is not communicating for a certain period of time.
In addition, optimizations such as preventing client terminal connections from concentrating on some APs and encouraging terminals that support both 2.4GHz and 5GHz frequencies to connect on 5GHz with less interference. do it automatically.

Optimization of wireless LAN environment

Firewall function

A stateful firewall function is implemented in MC, and access policies can be applied according to user privileges (roles).
Aruba Networks' wireless LAN employs a unique architecture that uses GRE tunnels, enabling the design of flexible access policies that minimize the impact on existing VLAN ACLs.
You can block communication that is not permitted by your access policy, or monitor and raise alerts.

Firewall function

Device and User Restrictions

User authentication (802.1x authentication) is the mainstream in wireless LAN, but there are also cases where terminal authentication is used. Terminal authentication uses MAC addresses and electronic certificates to authenticate terminals.
In the future, when an organization introduces smart devices or promotes the use of personal devices owned by users, double authentication of users and devices will become important.
For example, if you want to use MAC address authentication for terminal authentication, MC can use both user authentication (802.1x) and MAC address authentication (MAC RADIUS authentication), and these authentication information can be centrally managed by the authentication server. increase.

Device and User Restrictions

Rogue AP detection

Since the AP monitors the surrounding radio wave conditions, it is possible to detect radio waves from APs that are not managed by the company. These can be peripheral interference APs, rogue APs connected to the company's NW. You can check the SSID of these APs from the MC management screen, and you can also grasp the approximate location of the unauthorized AP by three-point positioning.
You can also purchase an optional RFP license to prevent connections to rogue APs.

Rogue AP detection

You can grasp the information of the access point that seems to be illegal. If you break down from this management screen, you can also check information on unauthorized access points and their installation locations.

Information on unauthorized access points (Image obtained from AirWave management screen)

remote access point

A remote access point (RAP) is effective in environments where a secure network path such as VPN is not secured to the head office or data center, such as a small office or commercial facility tenant.
As long as there is an environment that can connect to the Internet, RAP creates an IPsecVPN tunnel to the MC, downloads configuration information from the MC, and provides wireless LAN services. Users can connect to the same wireless LAN at headquarters and branch offices and access resources within the company. Of course, both AP and RAP can be managed by the same MC.

remote access point

Account issuance for visitors

You can easily issue a temporary account for connecting to a wireless LAN to a visitor. You can also set the account validity period in advance, and the account will automatically expire after the validity period has passed.
You can smoothly provide access to the Internet when the person in charge of an overseas business partner visits your company.

Account issuance for visitors

Inquiry/Document request

In charge of Macnica HPE Aruba

Mon-Fri 8:45-17:30