click pentru a vedea toate pozele
Overview
The Nortel WLAN 2300 Series is a complete 802.11 solution for enterprises wishing to deploy widespread wireless coverage for today’s business, IP Telephony and converged multimedia applications.
The solution combines the latest industry standards with a centralized architecture and advanced features to create a secure, cost-effective and highly scalable WLAN infrastructure.
The WLAN 2300 Series includes the tools and features required for successful planning and implementation, whether deploying a first-time WLAN using a quick and simple approach, or graduating to a precisely engineered mobile infrastructure as part of a global enterprise mobility strategy. The Series’ three primary elements include a multi-mode access point (AP), a portfolio of WLAN Security Switches and a WLAN Management Software system. Each plays a key role in the complete mobility solution.
• The Nortel WLAN Access Point 2330 - performs 802.11a/b/g mobile connectivity, encryption/ decryption for wireless traffic, priority queuing and radio frequency (RF) monitoring, including rogue access point identification and containment. Access points exchange control and data traffic with their associated WLAN Security Switch.
• The Nortel WLAN 2300 family of security switches - controls the access points and performs key functions such as security, networking, quality of service (QoS) and roaming for mobile users. The WLAN Security Switch also correlates radio frequency data from multiple access points and coordinates their response to changing RF conditions and RF attacks.
• The Nortel WLAN Management Software system - is a comprehensive design and management tool that identifies ideal access point locations on detailed floor plans, configures all devices with a single click, and provides granular monitoring and reporting for complete visibility and control over the entire system.
Typical Applications
• Corporate-wide WLAN installations in mid-large sized enterprises
• Transportation hubs such as airports, shipping yards, train stations and bus terminals that appreciate the ability for the WLAN 2300 series to run concurrent virtual service groups from a single WLAN infrastructure
• Multi-tenant units and service providers
Key Points
Built to support Voice and Multimedia applications in today’s networks
Adheres to the latest QoS standards including SVP and WMM
• Minimizes the performance impact of 802.1x by offloading back-end AAA servers of key generation and management
• Fast, secure roaming among all APs with the minimal latency and jitter needed to support time-sensitive applications
• Dynamic RF management for service resiliency by protecting against unexpected interference,obstructions, outages and weak coverage zone
• Full n+1 redundancy of all network components to protect against service interruption Flexible policy management keeps control over roaming users
• User-based policy management option for binding individual users with centrally defined AAA policies
• Security and QoS policies to follow users as they roam anywhere on the WLAN network offering a managed service in public areas for using virtual service groups with captive portals to resell internet connectivity Certain vertical markets active in WLAN: healthcare, education, finance, logistics and government segments have unique business problems solved by WLAN
• Enforced access controls, VLAN/subnet assignments, bandwidth rate, QoS priorities and multicast memberships even if the user roams between floors and buildings
• The ability for administrators to assign time- of-day and location-based restrictions that block access from specific areas like parking lots, exam and emergency rooms
Easy implementation — from planning to production
• WLAN Management system so that network administrators have assistance in every phase of a WLAN project from planning and configuration through to monitoring, reporting, growth and
ongoing operations
• A visual map of the ideal WLAN network including radio coverage, physical topology and AP locations
• Adjusts mappings for RF obstacles such as walls, pillars, windows and office partitions
• Produces a customized bill of materials for baseline implementation or hypothetical scenarios
• Switch and access point configurations for pushing out to all system elements with a single key-stroke
• Granular monitoring and customizable reporting keeps administrators on top of all activity for troubleshooting and support
Seamless deployment in any network
• Designed to operate as an overlay to existing IP networks without the need for network reconfigurations or expensive upgrades to core switch infrastructure
• Can be configured to enforce existing RADIUS authentication policies and extensions
• Only uses standard protocols that will not impact other devices
• Installed access points on any subnet or in any wiring closet, allowing the placement to be simple, convenient and focused on providing optimal wireless coverage
• Access points attached to their controllers across the network and self-configured
• Capability for one WLAN infrastructure to be securely partitioned to form up to 32 unique service groups, each with its own web-portal, security and QoS policies
Standards-based/Open Client approach for user and application compatibility
• Adheres to the latest IEEE and de-facto industry standards to ensure strong security and QoS while maintaining compatibility with user devices
• Supports security standards such as WPA, WPA2, 802.11i/802.1x with WEP, Dynamic WEP, TKIP, CCMP, EAP-TLS, TTLS and PEAP, PEAP-TLS
• Supports QoS standards including 802.1p & DiffServ, WMM and SVP
• Advanced features — such as dynamic RF management, roaming and user policy management — compatible with all 802.11 clients
• WLAN Management Software for easy planning by recognizing floor maps in all common formats including AutoCAD® DXF™, AutoCAD DWG, JPEG or GIF file types
Features and Benefits
Nortel WLAN Security Switch 2300 Series
The WLAN 2300 Series includes a family of four security switches, each designed to meet specific needs of enterprise-wide deployments. The portfolio breadth, combined with advanced features and a common management system, provides unparalleled deployment flexibility and scalability to meet the growing demands of mobile professionals. Each switch can be deployed and managed independently, or can participate with other 2300 Security Switches in large enterprise network deployments.
In multiple switch architectures, client information and policies are shared among switches to permit fast roaming among all access points. Regardless of network size or topology, the WLAN Security
Switch 2300 family can lower equipment costs substantially by offering the right-sized product for any deployment scenario.
The WLAN Security Switch 2350 is the smallest switch in the 2300 Series and is ideally suited for extending WLAN services to small or branch office environments. The WLAN Security Switch 2350 auto-configures when first connected to the network and can control up to three access points. It offers the same features as the larger 2300 switches but in a smaller package.
The WLAN Security Switch 2360 is ideally suited for mid-size office sites or wiring closet deployments and can control up to 12 access points that can be either connected directly to one of the eight
Ethernet ports or indirectly through a Layer 2 or 3 network. A dual power supply option provides improved resiliency for converged services.
The WLAN Security Switch 2370 is designed for dense deployments of up to 40 access points, which can either be directly connected to one of the 20 Ethernet ports or indirectly connected through a Layer 2 or 3 network. The 2370 adds dual Gigabit Ethernet uplink ports and dual hot-swappable power supplies for service resiliency.
The WLAN Security Switch 2380 is the largest switch in the 2300 Series and is designed for large deployments and data center applications in enterprise and carrier environments. The 2380
can be licensed to control up to 120 access points, which are distributed across a Layer 2 or 3 network and connected through one of the four Gigabit Ethernet ports. Dual hot swappable power supplies
provide superior resiliency for voice services.
The WLAN Access Point 2330 is a multi-mode 802.11a/b/g device that is controlled by the WLAN Security Switches and can be deployed in large numbers without creating a management burden.
The 2330 is plenum-rated for ceiling installations and features an attractive enclosure that resembles a common smoke detector to blend in with office environments.
Nortel WLAN Management Software System
After deploying the WLAN 2300 system, the Administrator uses WLAN Management Software system for all the ongoing management and optimization. The tool coordinates RF sweeps to detect and locate rogues, with WLAN Management Software system displaying the newly discovered devices on the floor plan. The Administrator also uses WLAN Management Software system for user management. The tool locates users on the floor plan and displays the user’s network usage statistics, roaming history and addressing details, summarizing the Identity-Based Networking services the system provides.The WLAN Management Software system also provides the traditional management functions, detailing system-level events and statistics for the wired network, the air (RF) and users. WLAN Management Software system’s RF topology mapping and coverage-verification tools simplify ongoing optimization, making it easy to adjust coverage areas or add new ones.
Feature Description Benefit
Switched WLAN Architecture (‘thin’ AP model)
• Switch offloads AP of networking, roaming and security functions
• Device management is centralized
• WLAN 2300 features a unique traffic flow architecture • System approach forms the foundation for new capabilities such as Rf management, inter-subnet roaming and location
• Thin APs are less expensive than standalone APs
• APs can self-configure for easy implementation
Standards-based security and QoS
• 802.11 a/b/g
• 802.11i, WPA/WPA2 (certification pending)
• WMM (certification pending)
• SVP (certification pending) • Strong security and QoS capability while maintaining client interoperability
RFManagement
• Switch receives RF data from scanning APs
• Switch/WMS identifies interference, coverage outages, 80211 devices
• Switch dynamically adjusts AP channel and power • Self-optimization
• Self-healing
• Base technology for Rogue AP detection and 802.11 device location
Wireless Threat Protection
• Guards against layer 2 radio vulnerabilities like DoS, flood, jamming attacks, etc.
• Alerts administrators of attack and locates • Complements 802.11i for improved service resiliency
Rogue aP Protection
• Identifies unauthorized AP and maps location on floor plan
• Launches containment measures from neighboring APs • Complements 802.11i for improved service resiliency
User load balancing
• Sends new users to alternate APs based on capacity utilization • Improved performance and user experience for all clients
Fast Roaming
• Special handling of encryption keys and authentication processing to avoid redundant authentication while roaming • Minimizes latency and jitter when roaming
• Delivers improved IP Telephony
Location Services
• Locates and tracks active 802.11 devices • Location-based authentication
• Asset tracking
• Site security
Resilient Design:
• Dual Ethernet ports on Access Point 2330
• Redundant hot-swappable power supplies on switches
• N+1 redundant architecture • Improved reliability of WLAN service
• Improved user up-take/service stickiness
• Allows service providers to differentiate on SLA
Symmetrical traffic flow
• Tunnels each user’s session back to originating switch while roaming • All applications continue to work when roaming
• Multi-cast
• “Push-to-talk”
• IP, IPX, AppleTalk, etc.
• Scalable - remains simple in large multi-switch deployments
• Simplifies management and troubleshooting
• Permits use of stateful firewalls in the flow — asymmetric flow can break firewalls
broad Wireless security switch portfolio:
• Each designed for a common deployment scenario
• Common software, features and management • No need to buy more product than required
• Enables a corporate standard to be implemented across all regions and offices
Feature Description Benefit
Wireless security switch 2350 branch office
• A small switch is deployed on-site to manage a few branch office aPs
• Fundamentally a different approach from deploying a “remote” thin AP • Switch is local instead of somewhere else on the network across a Wan connection
• WLAN works if WAN link fails
• No firewall/VPN reconfigurations are required to support “thin” AP control protocols over WAN link
• Faster switch responses translate into improved performanceMuch faster authentication and roaming
Flexible policy management
• By user, group, SSID, device, location, time-of-day, day of week
• Security Policies — VLAN, L3/4 filters, roaming restrictions
• QoS Policies — bandwidth, priority queuing
• AAA Policies — server, backup, grouping or local • Solution fits with existing policy architecture
• Allows identity-based networking (user-based policies), which centralizes policies on backend aaa servers for easier management and scalability
• Block access from parking lot, but not foyer
• Restrict WLAN service to secured areas only after 5PM
site Planning tool with Wlan Management Software 2300
• Imports existing floor plans - including common AutoCAD files
• Calculates required number of APs and switches and their configurations
• Identifies ideal AP locations on floor plan
• Creates a bill of materials
• Based on capacity and throughput requirements • Takes the guesswork out of AP placement and configuration
• Quicker time-to-service
• Can mitigate the need for a costly site survey
Ekahau™ Site Survey tool integration
• WMS 2300 can import site survey information • Provides a very accurate RF map based on site survey results
• More accurate planning and location services
Virtual service Groups
• Up to 32 per radio (64 per AP)
• Each has unique SSID, VLAN, Subnet, AAA and policies.
• Each can have a unique and customizable authentication web portal (captive portal). • Share one WLAN infrastructure among multiple user groups
• Owners of public infrastructure can resell wireless connectivity to service providers
• Allows a provider-based virtual service group to offer Internet Telephony from enterprise Wlan
Controls third-party access Points from Cisco and 3Com
• Most features excluding RF management
• Authentication, user policy enforcement and inter-subnet roaming
• Cisco Aironet 350, 1100, 1200 • Faster time-to-service
• Lower cost
• Smooth transition
Scanning with external antennas
• Allows for RF scanning to be performed with external antennas • More accurate site planning through more accurate Rf mapping
• More accurate user location and rogue AP detection
802.1x/EAP Offload
• The switch terminates and processes 90% of the tasks
• Offloads these implementations: EAP-TLS, PEAP and eaP-MD5 • Decreases load on back-end RADIUS servers
• Allows for WLAN implementation w/ 802.1x without RaDIUs modifications
• Can perform local 802.1x without relying on WAN link
Guest Access Provisioning
• A streamlined “front-desk” application for provisioning a temporary guest ID
• Each ID can have access restrictions and time expirations • Allows receptionist with no technical training to offer Wlan service
• Controlled guest access provides greater security than “Guest” SSID
• Can be used to give guests access to more than just the internet
• Time expiration prevents lingering open accounts
Nortel WLAN Security Switch 2350 Nortel WLAN Security Switch 2360/2361 Nortel WLAN Security Switch 2370 Nortel WLAN Security Switch 2380
Number of Fast Ethernet ports/ Power over Ethernet 2/1 8/6 20/20 20/20
Number of Gigabit Ethernet ports — — 2 GBIC 4 GBIC/
1000base-T
Number of Access Points Supported 3 12 40 Licensed
40/80/120
Third Party AP Support Yes Yes Yes Yes
Form Factor Small 1U rack mount 2U rack mount 2U rack mount
Power Supply Single Single (2360)
Dual (2361) Dual-redundant
Hot-swappable Dual-redundant
Hot-swappable
Application SMB/ branch office Mid-size office/ Wiring Closet large site /
Wiring Closet/
Data Center Data Center
Dimensions:
(W x D x H): 125 in x 75 in x 5.75 in
3.2 cm x 19 cm x 14.6 cm 172 in x 174 in x 10.08 in
44 cm x 442 cm x 25.6 cm 35 in x 174 in x 18.2 in
8.8 cm x (W) 44.2 cm x (D) 462 cm 174 in x 182 in x 3.5 in
442 cm x 462 cm x 88 cm
Weight 15 lbs (07 kg) 85 lbs (38 kg) with one power supply
95 lbs (43 kg) with two power supplies 1950 lbs (885 kg) with no power supply
2275 lbs (1032 kg) with one power supply
2600 lbs (1179 kg) with two power supplies 2175 lbs (979 kg) with one power supply
2500 lbs (1125 kg) with two power supplies
Power External Power Supply:
Input: 100-150 VAC, 47-63 Hz, auto-sensing
Output: 48 VDC, 0.75A
Amperage draw maximums:
at 115V (RMs): 08a
At 230V (RMS): 0.4A Power VaC range, Hz range: 90-132 VAC/180-264 VAC, 50-60 Hz, auto-sensing
Amperage draw maximums:
115Vrms: 4Arms
At 230Vrms: 2Arms Power VaC range, Hz range: 90-250 VAC, 47-63 Hz to 350 watts, hot-swappable power supply
Amperage draw maximums:
At 120Vrms: 8Arms
At 230Vrms: 3.5Arms Power VaC range, Hz range:
90-250 VaC, 47-63 Hz to 350 watts, hot-swappable power supply
Amperage draw maximums:
At 120Vrms: 8Arms
At 230Vrms: 3.5Arms
Nortel WLAN Security Switch 2350 Nortel WLAN Security Switch 2360/2361 Nortel WLAN Security Switch 2370 Nortel WLAN Security Switch 2380
Operating Temperature -10ºC to +50ºC (14ºf to +122ºf)
Storage Temperature
-20ºC to +70ºC (-4ºto +158º -10ºC to +50ºC (14ºto +122º
Storage Temperature
-20ºC to +70ºC (-4ºto +158º -10ºC to +50ºC (14ºto +122º
Storage Temperature
-20ºC to +70ºC (-4ºto +158º -10ºC to +50ºC (14ºto +122º
Storage Temperature
-20ºC to +70ºC (-4ºto +158º
Nortel Access Point 2330
Radio Support 802.11 a/b/g
Power over Ethernet (802.3af) Yes
External antennas Yes - (high-gain directional antennas)
Dimensions Diameter: 66 in (1676 cm)
Height: 185 in (469 cm)
Weight 125 oz (354 g)
Power 48VDC Power over ethernet as per the 8023af standard guidelines
Operating Temperature 0ºC to +50ºC (+32ºf to +122ºf)
Storage Temperature:
-20ºC to +70ºC (-4ºto +158º