H3C WX3520X-G Enterprise Wireless Controller
H3C WX3520X-G is a wireless controller (AC, Access Controller) product series independently developed by H3C Technology Co., Ltd. (hereinafter referred to as H3C). The WX3520X-G wireless controller is positioned in the domestic enterprise network market and features modularity, high scalability, large capacity, high reliability, and diverse business types. The new generation of H3C Comware network operating system platform is adopted to support refined user control management, perfect radio frequency resource management, 7X24 hour wireless security management and control, layer 2 and 3 fast roaming, flexible QoS control, IPv4&IPv6 dual stack and other functions. In addition, it also supports multi-core control plane, intelligent operation and maintenance, edge computing, Internet of Things, security and other integration characteristics.
Product Features
Provide management for 802.11be APs*
The WX3520X-G wireless controller supports the management of 802.11a/b/g/n/ac/acwave2/ax APs, and works in conjunction with H3C's Wi Fi 7 (802.11be) protocol APs to network *, breaking through the traditional wireless network serial communication mechanism, promoting the doubling of wireless spectrum resource utilization, greatly increasing the number of effective access users, effectively reducing the deployment cost of wireless networks, and greatly improving the user experience in high-density user environments.
Based on a brand new operating system
The WX3520X-G series wireless controller is developed using the H3C next-generation Comware system. The new operating system greatly improves the performance and reliability of the product, and can meet the increasingly complex network applications in the enterprise market. The Comware system has multiple advantages:
Multi core control: In the Comware system, the allocation ratio of CPU control cores and forwarding cores can be adjusted as needed to achieve an optimal balance according to requirements, which can fully enhance the CPU's control and data computing capabilities, while providing powerful concurrent computing capabilities.
• Support user mode multitasking: The Comware system adopts a new software operation permission control method, and the vast majority of network services run in user mode. Different network services occupy different tasks, and each task occupies independent resources. Errors in running a task are limited to this task and do not affect other tasks, allowing the system to operate safely and reliably.
User mode task monitoring: Comware system has task monitoring function, which specifically monitors the running status of various tasks in user mode. If there is an abnormal situation in user mode tasks, the system will reload the task to enable quick business recovery.
Adopting a new method of individual business upgrade: Comware system supports individual business upgrades, upgrading only a single business module without updating the entire software. Compared to the previous generation operating system of the company, it can greatly reduce the number of restarts and upgrades, ensure the security of the upgrade, and effectively provide network stability.
Support Central AC solution
Large scale parks and multi branch scenarios, with numerous AP/ACs and independent ACs, commonly face challenges such as heavy management tasks, high network failure rates, and low operational efficiency. The "Central AC" solution fully integrates the capabilities of New H3C Wireless 4i (iRadio, iStation, iEdge, iReal), and creates a more flexible and highly reliable wireless network for customer business scenarios through AC pooling and layering strategies.
AC pooling to create a highly reliable wireless network
After the controller cluster, an AC resource pool is formed, which can provide uninterrupted business upgrades, backups, expansion and other functions, improve network stability, and achieve a better user experience.
• Simpler and more flexible configuration strategies
The entire network configuration is uniformly completed on Central AC, and provides hierarchical and decentralized functions, dividing multiple levels of management permissions as needed.
4i capability, achieving network intelligence and healing
Based on RF management, terminal management, business support, network intelligence, and other aspects, strategies are issued to create a gradually optimized wireless network from multiple dimensions.
End network collaboration, focusing on real business experience
In terms of roaming, RRM, and key business dimensions, combined with end-to-end network collaboration technology, we provide a three-dimensional guarantee for the terminal business experience.
• Provide flexible data forwarding methods
The WX3520X-G wireless controller can support centralized forwarding, distributed forwarding, and policy forwarding. Users can flexibly set forwarding methods according to business needs and network conditions.
• Support operation level wireless user access control and management
User based access control is a major feature of the WX3520X-G wireless controller product. The User Profile provides a configuration template that can save preset configurations (a collection of configurations). Users can configure different content for their User Profile based on different application scenarios, such as CAR (Committed Access Rate) policies and QoS (Quality of Service) policies.
When users access devices, they need to perform identity authentication first. During the authentication process, the authentication server will issue the User Profile name to the device, and the device will immediately enable the specific content configured in the User Profile. When a user accesses the device through authentication, the device will restrict the user's access behavior based on these specific contents. When a user goes offline, the system will automatically disable the configuration items under the User Profile, thereby removing the restrictions on the user under the User Profile. Therefore, User Profile is applicable to restrict the access behavior of online users. When no user is online (which may be due to no user accessing, user not being authenticated, or user being offline), User Profile is a preset configuration and does not take effect.
In addition, the WX3520X-G wireless controller also supports MAC based authentication access control, which not only allows customers to configure and modify user groups' permissions on AAA servers, but also supports the configuration of specific user permissions. This refined user permission control greatly enhances the availability of wireless networks, and network administrators can easily allocate access permissions to people of different levels or groups through this method.
MAC based VLAN is also a major feature of the WX3520X-G wireless controller. In terms of control strategy, administrators can assign users with the same nature (MAC) to the same VLAN, and configure security policies based on VLAN on the controller. This can simplify system configuration and achieve fine-grained management at the user level.
For security or billing considerations, system administrators may wish to control the location of wireless users accessing the network. The WX3520X-G wireless controller supports user access control based on AP location. When wireless users access the network, the authentication server can issue a list of APs that allow users to access to the AC, and access control can be performed on the AC to limit wireless users to only access APs at designated locations.
• Support intelligent channel switching
In wireless local area networks, channels are extremely scarce resources, and each AP can only operate on a very limited number of non overlapping channels. For example, for 2.4G networks, there are only three non overlapping channels. Therefore, how to intelligently allocate channels for APs is the key to wireless applications.
There are many possible sources of interference in the frequency band where wireless LAN operates, such as radar and microwave ovens, which can interfere with the normal operation of APs in the network. Through the intelligent channel switching function, it can ensure that each AP can be allocated to the optimal channel, minimizing and avoiding adjacent channel interference as much as possible. Moreover, through real-time channel interference detection, APs can avoid interference sources such as radar and microwave ovens in real time.
• Support intelligent AP load sharing
The 802.11 protocol hands over the decision of wireless roaming to wireless clients, who usually choose APs based on their signal strength (RSSI). This can easily lead to a large number of clients connecting to the same AP simply because of the strong signal of a certain AP. Due to these clients sharing wireless media, the network throughput of each client will be significantly reduced.
The intelligent load sharing method can analyze the location of wireless clients in real time, dynamically determine which APs can share the load with each other at the current time and location, and achieve load sharing among these APs by controlling the APs that wireless clients access. The system not only supports load sharing based on the number of online sessions of users, but also supports load sharing based on user traffic.
• Supports 7-layer mobile security detection/defense (WIDS/WIPS)
The WX3520X-G wireless controller supports mobile security defense modes such as blacklist, whitelist, Rogue defense, abnormal message detection, illegal user offline, and signature MAC layer attack detection and countermeasures based on preset upgrades (such as DoS attacks, Flood attacks, man in the middle attacks). Combined with the massive intelligent expert knowledge base built into the wireless application console, flexible wireless security policy judgment criteria can be obtained. For clear illegal attack sources (APs or terminals, etc.), visual physical location tracking and monitoring can be achieved, as well as physical port removal of switches.
By cooperating with H3C professional core layer firewall/IPS devices, it is possible to achieve a 7-layer three-dimensional security defense for mobile parks, meeting the true end-to-end security protection requirements from wireless (802.11) to wired (802.3).
Support 802.1x authentication, MAC address authentication, Portal authentication, etc
The WX3520X-G wireless controller supports multiple authentication methods:
802.1x authentication: The WX3520X-G wireless controller supports multiple 802.1x authentication methods such as TLS, PEAP, TTLS, MD5, SIM card, etc. It also supports local 802.1x authentication methods, providing support for mainstream authentication methods such as MD5, TLS, and PEAP. Users no longer need to configure additional AAA servers. The WX3520X-G series wireless controller also supports dynamic authorization of VLAN and ACL functions after 802.1x authentication. User policies can be pre-set, and the system automatically configures customer permissions during user authentication.
MAC Address Authentication: The WX3520X-G wireless controller supports MAC address authentication, which is not convenient for some handheld terminals (such as Wi Fi Phone, handheld mobile terminals, etc.) to use on a computer. However, MAC address authentication can easily solve this problem by configuring valid MAC addresses on the controller or AAA server. The terminals corresponding to these MAC addresses can be allowed to access the network, while unauthorized terminals that have not been configured in advance cannot access the wireless network. This function greatly facilitates applications such as wireless medical systems. MAC address authentication can ensure that only PDA working terminals in hospitals can access the wireless network, while rejecting patients' wireless PDAs from using dedicated wireless networks.
Portal authentication: The WX3520X-G wireless controller provides a built-in Portal authentication server. This authentication method does not require the cooperation of the client, and directly uses the web portal page of the browser as the authentication channel. After the user passes the authentication, they can flexibly jump to the designated access homepage and initiate corresponding authorization and billing. At the same time, customized Portal pages can be flexibly pushed according to strategic requirements to achieve advertising promotion and information transmission, widely used in application scenarios such as wireless campuses, wireless cities, and visitor access.
Supports IPv4/IPv6 dual stack (Native IPv6)
The WX3520X-G wireless controller supports IPV6 access for wireless customers. At the starting point of the tunnel AP, due to the device's awareness of IPv6, it is possible to achieve mapping from IPv6 priority to tunnel priority; On the AC side, complex control and filtering such as ACL filtering can also be applied to IPv6 packets.
The WX3520X-G wireless controller can also be deployed in IPv6 networks, automatically negotiating an IPv6 tunnel between AC and AP. When AC and AP are fully operating in IPv6 state, the wireless controller can still correctly perceive IPv4 and process IPv4 packets from wireless clients. The WX3520X-G wireless controller has flexible adaptability to IPv4/6, which can meet various complex applications of customers in IPv4 to IPv6 network migration. It can provide IPv4 services to customers in IPv6 islands, and also allow users to easily log in to the network through the IPv6 protocol in IPv4 islands.
The WX3520X-G wireless controller supports IPv6 SAVI (Source Address Validation) technology to address the rampant IPv6 packet forgery attacks on campus networks. By listening to the address allocation protocol to obtain the user's IP address, it ensures that subsequent applications can use the correct address to access the internet and cannot forge other people's IP addresses, ensuring the reliability of the source address. At the same time, the combination of IPv6 SAVI and Portal technology further ensures the authenticity and security of all online user packets.
Provide end-to-end QoS
The WX3520X-G wireless controller not only provides comprehensive support for the Diff Serv standard, but also adds QoS support for the IPv6 protocol. The QoS Diff Serv model mainly includes flow classification, traffic policing, queue management, queue scheduling, etc. It fully implements the six groups of PHB and services defined in the standard, including EF, AF1~AF4, BE, etc., enabling network operators to provide users with service guarantees of different quality of service levels, making the Internet truly a comprehensive network that simultaneously carries data, voice, and video services.
Support fast second and third layer roaming
H3C's centralized wireless architecture not only facilitates layer 2 roaming, but also greatly facilitates cross layer roaming. The WLAN network deployed with Fat AP has limited information transmission between APs, making it difficult to implement layer 3 roaming. The centralized architecture is very easy to solve the problem of cross layer roaming. The WX3520X-G wireless controller supports layer 2 and layer 3 roaming, and the roaming domain is not limited by subnets. This excellent roaming feature allows customers to plan their wireless network without worrying too much about the existing network, focusing more on wireless signal coverage. This greatly simplifies the early network planning and reduces network planning costs.
In traditional mode, when wireless user terminals use 802.1x as a means of 802.11 access authentication and key exchange, there will be a lot of interaction messages between the wireless user terminal and the AP. When a wireless user terminal roams between two APs, if the wireless user terminal fully follows the complete 802.1x interaction process during the new AP access, it will inevitably cause a long roaming switching time. For some services that are sensitive to roaming switching time (such as voice services), such long switching time is unbearable. The WX3520X-G series wireless controller uses Key caching technology to achieve fast switching of users during roaming. Key caching technology strikes a good balance between secure access and fast roaming for users, allowing wireless user terminals to roam between two APs without the need for a complete 802.1x authentication interaction process, while ensuring user identity recognition and continuity of key usage; Wireless users adopt fast roaming mode, with a roaming time of no more than 50ms within a single AC, meeting the demanding requirements of voice services.
Support collaborative roaming
Through the 802.11k protocol mechanism, AP and wireless clients perform interactive detection and perceive network topology from multiple dimensions; AC full view recognition and comprehensive calculation of wireless client roaming timing and roaming access location, negotiating handover with the client through 802.11v and 802.11r mechanisms; During the simultaneous switching period, AC ensures traffic maintenance for downstream business traffic, thereby achieving seamless switching and improving user experience.
Support multiple remote access scenarios for branch offices
When AC and AP are connected through a wide area network link, users can flexibly choose between centralized forwarding or local forwarding modes to improve business performance such as branch LAN printing access and terminal mutual access.
When there is a failure in the wide area network link or AC, online users will not be disconnected, can continue to access local resources, and can support AC escape function.
When the branch AP is deployed within a private network, AC can communicate with the AP through NAT.
*Please refer to the version manual for support capabilities