
Page 3
owsandcontroladmissiononaperuserandperSSIDbasis.With
the flexibility to provision services and enforce policies at the AP,
wireless traffic can be bi-directionally limited to user-defined thresholds,
filtered, and locally switched without the need to tunnel it back to the
controller.Inbothcases,unwantedtrafcdoesnottraversecostlyWANs
or aggregating switches before being dropped at the controller. This
isachievedbytheuniqueabilitytoperformpacketinspectionatthe
AP,wheretherequestedserviceanddestinationisidentiedandthen
used to filter, switch, or rate limit accordingly. The result is optimized
responsiveness and performance for users and services. Easily adapted
to diverse customer network configurations whether they comprise single
building, local campus or routed remote offices, the Enterasys Wireless
solutions-oriented architecture simplifies deployment and reduces
implementation costs.
Survivable Branch Office
Administrators can cost-efficiently deliver WLAN services for users at
remote sites without the need to purchase or manage a local controller.
Combining built-in user-based policy management and captive portal
capabilities, branch users, including guests experience premium
performancewithdirectaccesstolocalresourcessuchasInternet,
printers and other specialized services. Traffic filtering, rate limiting,
and exception handling of unauthorized users continues even when
connection to the controller is lost.
Dynamic Radio Management (DRM)
Each Enterasys Wireless Access Point supports DRM. Although DRM is
centrally managed and configured by the controller, DRM functions as a
fully distributed system managing channels and transmit power allowing
theWLANinfrastructuretoadapttoRFinterference(802.11and
others), heavy channel utilization, and AP failures.
Flexible Client Access (FCA)
FlexibleClientAccessisanaccesstechniquethatcansignicantly
improvethethroughputfor802.11nclientsinmixeda/b/gandn
environments.FCAoperatesbyensuringequalairtimeforallclientsin
environmentswithamixof802.11nand802.11a/b/gdevices.Network
administrators can step-wise adjust this capability on a per WLAN service
basis to improve responsiveness for all users and to maximize overall
throughput across the wireless link.
Full RF Survivability
To ensure uninterrupted access, Enterasys Wireless Access Points
automatically adjust their settings to continue to optimally service clients
when adjacent APs fail or when the link back to the controller is lost.
Inaddition,EnterasysWirelessAPscanbeconguredtodynamically
redirect traffic to a secondary wireless controller if the primary wireless
controller fails. When the failover mode is enabled, APs automatically
register to both a primary and secondary wireless controller, ensuring high
availability of the WLAN service and robustness for real-time applications
Security
Enterasys Wireless APs provide strong encryption and authentication with
the use of 802.11istandardsandcaptiveportal.
Enterasys Wireless APs can be configured as part time or full time
sensors to detect rogue APs or to detect and contain security threats with
theWirelessManagementSuite(WMS)WirelessIntrusionPrevention
System(WIPS).
Inaddition,eachAPcanbeconguredwithacerticateenablingtheAP
to authenticate to the wired network. The network is then fully protected
against attempted re-use of the Ethernet port by unplugging the AP and
connecting directly to the Ethernet cable, as a point of entry into the
corporate network.
Quality of Service (QoS)
Enterasys Wireless APs support extensive functionality to ensure the
best service for all multimedia applications. Enterasys Wireless APs use
IPDiffServ/Precedence/TOSand802.11eWMMtodifferentiateand
prioritizewirelesstrafc.Onthewiredside,IPDiffServ/Precedence/TOS,
and802.1pareusedtodifferentiateandprioritizetrafc.
For802.11trafc,EnterasysWirelessAPssupportadditionalQoS
featuresincluding802.11eTSPEC(CallAdmissionControl)andU-APSD
(automaticpowersave)toensurehighqualityandpowerefcient
services for voice, video, and data applications.
Inaddition,theoriginalpacketIPprioritizationcanbemaintainedon
both the wireless and wired networks by enabling the Adaptive QoS
mechanism. This feature allows tunneled and wireless packets to retain
theirIPprioritizationvalueend-to-end.Furthermore,EnterasysWireless
APsallowITmanagerstodenecustommappings of different types of
prioritization schemes to ensure that user traffic is properly differentiated
when entering the wired network.
Bandwidth Control and Prioritized Service Delivery
Enterasys Wireless provides administrators with the means to control
bandwidthutilizationandprioritizeservicedelivery.Unique,granular
packet inspection capabilities at the AP continuously monitor and assess
user and service destinations. Based on topology, filter rules and data
rate thresholds defined in the user policy, a packet may be tunneled back
to the controller, switched at the AP, or dropped. A user who violates a
ratelimitpolicyattributecould,forexample,bedirectedtoaquarantine
segment attached to local AP or further rate limited.
Enterasys RoamAbout Access Point Investment Protection
Previous investments in the Enterasys RoamAbout
®
4102AccessPoints
can be leveraged through software upgrades that enable Enterasys
Wireless operation.
Komentarze do niniejszej Instrukcji