H3C WX2500X New Generation Enterprise Core Multi Service Wireless Controller
H3C WX2500X is a gateway type wireless controller (AC, Access Controller) developed by H3C Technology Co., Ltd. (hereinafter referred to as H3C) based on the Comware platform. The WX2500X series wireless controller has a wide range of service types, integrating fine user control management, comprehensive RF resource management, 7X24 hour wireless security control, second and third layer fast roaming, flexible QoS control, IPv4&IPv6 dual stack and other functions, providing powerful integrated wired and wireless access capabilities.
The H3C WX2500X series wireless controller is specifically designed for branch offices and small campus wireless network deployments. Integrating gateway and AC functions reduces the types and quantities of equipment purchased by enterprises in networking, thereby reducing investment. In conjunction with the H3C Fit AP product series, it supports functions such as WIPS and firewall. At the same time, it has a rich variety of port types, especially with a built-in USB interface, which can connect to enterprise related peripherals.
*The H3C WX2500X wireless controller, combined with the H3C Fit AP product series, can meet typical wireless applications such as WLAN access in small business parks and hotspot coverage in branch offices. And it supports H3C Fit AP and minimalist PON AP network management, reducing management nodes and improving management efficiency.
Product Features
Provide management for 802.11be APs
The WX2500X wireless controller not only supports the management of traditional 802.11a/b/g/n/ac/ac/ax APs, but also can cooperate with H3C APs based on the 802.11be protocol to network, breaking through the traditional wireless network serial communication mechanism, promoting the doubling of wireless spectrum resource utilization, greatly improving the number of effective access users, effectively reducing the deployment cost of wireless networks, and supporting AP automatic online and automatic loading of configurations. It can be plug and play, greatly improving the user experience in high-density user environments.
Support WBC wireless multi service center solution
Large scale parks and multi branch scenarios, with numerous AP/ACs and independent ACs, commonly face challenges such as heavy management tasks, high network failure rates, and low operational efficiency. The "WBC Wireless Multi Service Center" solution fully integrates the capabilities of New H3C Wireless 4i (iRadio, iStation, iEdge, iHealth), and creates a more flexible and highly reliable wireless network for customer business scenarios through clustering and layering strategies.
AC cluster, creating a highly reliable wireless network
Controller clustering provides uninterrupted business upgrades, backup, expansion, load sharing, and other functions to enhance network stability and achieve a better user experience.
• Simpler and more flexible configuration strategies
The entire network configuration is uniformly completed on Central AC, and provides hierarchical and decentralized functions, dividing multiple levels of management permissions as needed.
4i capability, achieving network intelligence and healing
Based on RF management, terminal management, business support, network intelligence, and other aspects, strategies are issued to create a gradually optimized wireless network from multiple dimensions.
End network collaboration, focusing on real business experience
In terms of roaming, RRM, and key business dimensions, combined with end-to-end network collaboration technology, we provide a three-dimensional guarantee for the terminal business experience.
Provide flexible data forwarding methods
Traditional wireless controller deployment generally adopts a centralized forwarding mode, where AC can comprehensively control and securely supervise messages. However, all wireless business traffic needs to be processed uniformly by AC, and the core link bandwidth and AC forwarding capability can easily become bottlenecks. Especially when AP and AC are connected through a wide area network, AP is deployed as a data access device in branch offices, while AC is deployed at headquarters. All user data is sent from AP to AC, and then forwarded centrally by AC, resulting in low forwarding efficiency. The WX2500X series wireless controller can support centralized forwarding, distributed forwarding, and policy forwarding. Users can flexibly set forwarding methods according to business needs and network conditions.
The WX2500X series wireless controller supports centralized authentication and local forwarding networking, providing centralized authentication and management of 802.1X and Portal in the case of local forwarding of data streams. Support system software and hardware escape function, ensuring normal internet access for online users and improving business continuity even when the hardware platform crashes.
Support operation level wireless user access control and management
User based access control is a major feature of the WX2500X wireless controller product, and the User Profile provides a configuration template that can save preset configurations (a collection of configurations). Users can configure different content for their User Profile based on different application scenarios, such as CAR (Committed Access Rate) policies and QoS (Quality of Service) policies.
When users access devices, they need to perform identity authentication first. During the authentication process, the authentication server will issue the User Profile name to the device, and the device will immediately enable the specific content configured in the User Profile. When a user accesses the device through authentication, the device will restrict the user's access behavior based on these specific contents. When a user goes offline, the system will automatically disable the configuration items under the User Profile, thereby removing the restrictions on the user under the User Profile. Therefore, User Profile is applicable to restrict the access behavior of online users. When no user is online (which may be due to no user accessing, user not being authenticated, or user being offline), User Profile is a preset configuration and does not take effect.
In addition, the WX2500X wireless controller also supports MAC based authentication access control, which not only allows customers to configure and modify user groups' permissions on the AAA server, but also supports the configuration of specific user permissions. This fine user permission control greatly enhances the availability of the wireless network, and network administrators can easily allocate access permissions to people of different levels or groups through this method.
MAC based VLAN is also a major feature of the WX2500X wireless controller. In terms of control strategy, administrators can assign users with the same nature (MAC) to the same VLAN, and configure security policies based on VLAN on the controller. This not only simplifies system configuration but also achieves fine-grained management at the user level.
For security or billing considerations, system administrators may wish to control the location of wireless users accessing the network. The WX2500X wireless controller supports user access control based on AP location. When wireless users access the network, the authentication server can issue a list of APs that allow users to access to the AC, and access control can be performed on the AC to limit wireless users to only access APs at designated locations.
In conjunction with the Oasis platform, it supports PPSK and AC can assign different PSK keys to different terminals under the same SSID without the need for other system support.
Provide reliable gateway functionality
The WX2500X is positioned as a gateway for small and medium-sized enterprises and branch offices, integrating both gateway and AC functions. The dual WAN port design provides the basic conditions for uplink backup. Meanwhile, compared to the previous generation product, the WAN port adopts a 2.5G multi rate interface, greatly improving the uplink efficiency. The WX2500X supports gateway functions such as PPPOE, NAT gateway, dynamic IP address, and static IP address settings.
Support Bonjour Gateway
The WX2500X commercial wireless controller supports Bonjour Gateway functionality, making it easy for small businesses to use Apple devices such as printers, televisions, and tablets internally.
Support intelligent channel switching
In wireless local area networks, channels are a very scarce resource, and each AP can only operate on a very limited number of non overlapping channels. For example, for 2.4G networks, there are only 3 non overlapping channels, so how to intelligently allocate channels for APs is the key to wireless applications.
There are a large number of possible interference sources in the frequency band where wireless local area networks work, such as radar and microwave ovens, which will interfere with the normal operation of APs in the network. Through the intelligent channel switching function, it can ensure that each AP can be allocated to the optimal channel, minimizing and avoiding adjacent channel interference as much as possible. Moreover, through real-time channel interference detection, APs can avoid interference sources such as radar and microwave ovens in real time.
Support intelligent AP load sharing
The 802.11 protocol hands over the decision of wireless roaming to wireless clients, who usually choose APs based on their signal strength (RSSI). This can easily lead to a large number of clients connecting to the same AP simply because of the strong signal of a certain AP. Due to these clients sharing wireless media, the network throughput of each client will be significantly reduced.
The intelligent load sharing method can analyze the location of wireless clients in real time, dynamically determine which APs can share the load with each other at the current time and location, and achieve load sharing among these APs by controlling the APs that wireless clients access. The system not only supports load sharing based on the number of online sessions of users, but also supports load sharing based on user traffic.
Support 7-layer mobile security detection/defense (WIDS/WIPS)
The WX2500X wireless controller supports mobile security defense modes such as blacklist, whitelist, Rogue defense, abnormal message detection, illegal user offline, and signature MAC layer attack detection and countermeasures based on preset upgrades (such as DoS attacks, Flood attacks, man in the middle attacks). Combined with the massive intelligent expert knowledge base built into the wireless application console, flexible wireless security policy judgment criteria can be obtained. For clear illegal attack sources (APs or terminals, etc.), visual physical location tracking and monitoring can be achieved, as well as physical port removal of switches.
By cooperating with H3C professional core layer firewall/IPS devices, it is possible to achieve a 7-layer three-dimensional security defense for mobile parks, meeting the true end-to-end security protection requirements from wireless (802.11) to wired (802.3).
Support RealTime Spectrum Guard mode
RealTime Spectrum Guard (RTSG) is a professional monitoring solution proposed by H3C for wireless environment spectrum status. The entire series of wireless controllers can be integrated with Sensor APs with built-in RF acquisition modules to achieve deep RF monitoring and real-time spectrum protection.
The RTSG console is integrated and deployed in the H3C iMC intelligent management center. It communicates and collects data with Sensor AP through CAPWAP management tunnel, achieving 7X24 hour wireless environment quality monitoring, wireless network capability trend evaluation, and unauthorized interference alarm. Through graphical representation, actively detect and identify all RF interference sources (Wi Fi or non Wi Fi) in the 2.4GHz/5GHz bands, providing real-time FFT maps, spectral density maps, spectral maps, duty cycle maps, event spectral maps, channel power, interference power, etc; Automatically identify interference sources, determine the location of problematic wireless devices, and ensure optimal performance of the wireless network. By combining H3C iAR intelligent reporting components, it is possible to store, trace, and replay RF quality history records throughout the entire coverage area, and automatically generate customized trend, compliance, and audit reports.
The deployment of RTSG scheme can flexibly adopt Local mode or Monitor mode to meet the different levels of user wireless environment supervision requirements. When working in Local Mode, normal user access and packet forwarding can be maintained while obtaining effective spectrum protection.
Support network wide AC, AP, and user experience evaluation analysis, as well as health detection and quality analysis, and provide analysis results based on total channel utilization, Wi Fi channel utilization, non Wi Fi channel utilization, number of same frequency APs, and so on.
Built in RF Optimization Engine (ROE)
The WX2500X wireless controller has a built-in RF Optimization Engine for APs, which effectively enhances the application acceleration capability and quality assurance effect in high-density access, streaming media transmission and other scenarios in wireless deployment through feature and protocol based RF optimization. This includes multi-user fair scheduling, mixed access fairness, interference filtering, rate optimization, spectrum navigation, multicast enhancement (IPv4/IPv6), packet by packet power control, and intelligent bandwidth guarantee.
Support 802.1x authentication, MAC address authentication, Portal authentication, etc
The WX2500X wireless controller supports multiple authentication methods:
802.1x authentication: The WX2500X wireless controller supports multiple 802.1x authentication methods such as TLS, PEAP, TTLS, MD5, SIM card, etc. It also supports local 802.1x authentication methods, providing support for mainstream authentication methods such as MD5, TLS, and PEAP. Users no longer need to configure additional AAA servers. The WX2500X wireless controller also supports dynamic authorization of VLAN and ACL functions after 802.1x authentication. User policies can be pre-set, and the system automatically configures customer permissions during user authentication.
MAC address authentication: The WX2500X wireless controller supports MAC address authentication, which is not convenient for some handheld terminals (such as Wi Fi Phone, handheld mobile terminals, etc.) to use the authentication method on the computer. MAC address authentication can easily solve this problem by configuring valid MAC addresses on the controller or AAA server. The terminals corresponding to these MAC addresses can be allowed to access the network, while unauthorized terminals that have not been configured in advance cannot access the wireless network. This function greatly facilitates applications such as wireless medical systems. MAC address authentication can ensure that only PDA working terminals in hospitals can access the wireless network, while rejecting patients' wireless PDAs from using dedicated wireless networks.
Portal authentication: The WX2500X wireless controller provides a built-in Portal authentication server. This authentication method does not require the cooperation of the client, and directly uses the web portal page of the browser as the authentication channel. After the user passes the authentication, they can flexibly jump to the designated access homepage and initiate corresponding authorization and billing.
Supports IPv4/IPv6 dual stack (Native IPv6)
The WX2500X wireless controller supports IPV6 access for wireless customers. At the starting point of the tunnel AP, due to the device's awareness of IPv6, it is possible to achieve mapping from IPv6 priority to tunnel priority; On the AC side, complex control and filtering such as ACL filtering can also be applied to IPv6 packets.
The WX2500X wireless controller can also be deployed in IPv6 networks, automatically negotiating an IPv6 tunnel between AC and AP. When AC and AP are fully operating in IPv6 state, the wireless controller can still correctly perceive IPv4 and process IPv4 packets from wireless clients. The WX2500X wireless controller has flexible adaptability to IPv4/6, which can meet various complex applications of customers in IPv4 to IPv6 network migration. It can provide IPv4 services to customers in IPv6 islands, and also allow users to easily log in to the network through the IPv6 protocol in IPv4 islands.
In response to the rampant IPv6 packet forgery attacks on campus networks, the WX2500X wireless controller supports IPv6 SAVI (Source Address Validation) technology. By listening to the address allocation protocol to obtain the user's IP address, it ensures that subsequent applications can use the correct address to access the internet and cannot forge other people's IP addresses, ensuring the reliability of the source address. At the same time, the combination of IPv6 SAVI and Portal technology further ensures the authenticity and security of all online user packets.
Provide end-to-end QoS
The WX2500X wireless controller is developed on the Comware platform, which not only fully supports the Diff Serv standard, but also adds QoS support for the IPv6 protocol.
The QoS Diff Serv model mainly includes flow classification, traffic policing, queue management, queue scheduling, etc. It fully implements the six groups of PHB and services defined in the standard, including EF, AF1~AF4, BE, etc., enabling network operators to provide users with service guarantees of different service quality levels, making the Internet truly a comprehensive network that simultaneously carries data, voice, and video services.
Support fast second and third layer roaming
H3C's centralized wireless architecture not only facilitates layer 2 roaming, but also greatly facilitates cross layer roaming. WLAN networks deployed with Fat APs have limited information transmission between APs, making it difficult to implement layer 3 roaming. The centralized architecture is very easy to solve the problem of cross layer roaming. The WX2500X wireless controller supports layer 2 and layer 3 roaming, and the roaming domain is not limited by subnets. This excellent roaming feature allows customers to plan their wireless network without worrying too much about the existing network, focusing more on wireless signal coverage. This greatly simplifies the early network planning and reduces network planning costs.
In traditional mode, when wireless user terminals use 802.1x as a means of 802.11 access authentication and key exchange, there will be a lot of interaction messages between the wireless user terminal and the AP. When a wireless user terminal roams between two APs, if the wireless user terminal fully follows the complete 802.1x interaction process during the new AP access, it will inevitably cause a long roaming switching time. For some services that are sensitive to roaming switching time (such as voice services), such long switching time is unbearable. The WX2500X wireless controller uses Key caching technology to achieve fast switching of users during roaming. Key caching technology strikes a good balance between secure access and fast roaming for users, allowing wireless user terminals to roam between two APs without the need for a complete 802.1x authentication interaction process, while ensuring user identity recognition and continuity of key usage; Wireless users adopt fast roaming mode, with a roaming time of no more than 50ms within a single AC, meeting the demanding requirements of voice services