WX6100E系列运营级核心多业务无线控制器设备外观图
WX6100E 系列运营级核心多业务无线控制器设备外观图

H3C WX6100E series new generation operational grade core multi service wireless controller

H3C WX6100E is a new generation of operational core multi service wireless controller (AC, Access Controller) product series independently developed by H3C Technology Co., Ltd. (hereinafter referred to as H3C). The WX6100E series new generation wireless controller has the characteristics of large capacity, high reliability, and rich business types. In terms of software, it adopts the H3C new generation Comware V7 network operating system platform (hereinafter referred to as V7 system). In addition to supporting refined user control management, complete RF resource management, 7X24 hour wireless security control, second and third layer fast roaming, flexible QoS control, IPv4&IPv6 dual stack and other functions of the original system, it also supports emerging wireless software features such as multi-core control plane, new generation wireless positioning, Bonjour, Hotspot 2.0, etc.
WX6100E系列运营级核心多业务无线控制器设备外观图
WX6100E 系列运营级核心多业务无线控制器设备外观图
Detailed Description

H3C WX6100E is a new generation of operational core multi service wireless controller (AC, Access Controller) product series independently developed by H3C Technology Co., Ltd. (hereinafter referred to as H3C). The WX6100E series new generation wireless controller has the characteristics of large capacity, high reliability, and rich business types. In terms of software, it adopts the H3C new generation Comware V7 network operating system platform (hereinafter referred to as V7 system). In addition to supporting refined user control management, complete RF resource management, 7X24 hour wireless security control, second and third layer fast roaming, flexible QoS control, IPv4&IPv6 dual stack and other functions of the original system, it also supports emerging wireless software features such as multi-core control plane, new generation wireless positioning, Bonjour, Hotspot 2.0, etc.

 

The H3C WX6100E series wireless controller includes three models: WX6103E, WX6108E, and WX6112E. Combined with the H3C Fit AP product series, it can meet typical wireless applications such as WLAN access, wireless metropolitan area network coverage, and hotspot coverage in large enterprise parks.

 

*For detailed purchase information, please consult the H3C local office

 

Product Features

 

Provide management for Wi Fi 6 APs (802.11ax)

The WX6100E series wireless controller not only supports the management of traditional 802.11a/b/g/n/ac APs, but also can cooperate with H3C APs based on Wi Fi 6 (802.11ax) protocol to network, breaking through the traditional wireless network serial communication mechanism, promoting the doubling of wireless spectrum resource utilization, greatly increasing the number of effective access users, effectively reducing the deployment cost of wireless networks, and greatly improving the user experience in high-density user environments.

Based on a brand new operating system

The WX6100E series wireless controller is developed using the H3C next-generation V7 system. The new operating system greatly improves the performance and reliability of the product, and can meet the increasingly complex network applications in the enterprise market. Compared with the previous generation operating system, the V7 system has multiple advantages:

 

Multi core control: In the V7 system, the allocation ratio of CPU control cores and forwarding cores can be adjusted as needed to achieve an optimal balance according to requirements, which can fully enhance the CPU's control and data computing capabilities, while providing powerful concurrent computing capabilities.

 

• Support user mode multitasking: The V7 system adopts a new software operation permission control method, and the vast majority of network services run in user mode. Different network services occupy different tasks, and each task occupies independent resources. Errors in running a task are limited to this task and do not affect other tasks, allowing the system to operate safely and reliably.

 

User mode task monitoring: The V7 system has task monitoring function, which specifically monitors the running status of various tasks in user mode. If there is an abnormal situation in the user mode task, the system will reload the task to enable quick business recovery.

 

• Adopting a new method of individual business upgrade: The V7 system supports individual business upgrades, only upgrading a single business module without updating the entire software. Compared to the previous generation operating system of the company, it can greatly reduce the number of restarts and upgrades, ensure the security of the upgrade, and effectively provide network stability.

 

Provide high-density port access

The WX6100E series wireless controller provides high-density port access in the external interface to support better integrated wired and wireless access (including user access, user authentication, billing management, and unified management of wired and wireless users). Different business interfaces are provided according to the model to meet the requirements of different markets. The product provides high-density ports and multiple port types to meet users' flexible networking and network access needs.

 

Provide flexible data forwarding methods

Traditional wireless controller deployment generally adopts a centralized forwarding mode, where AC can comprehensively control and securely supervise messages. However, all wireless business traffic needs to be processed uniformly by AC, and the core link bandwidth and AC forwarding capability can easily become bottlenecks. Especially when AP and AC are connected through a wide area network, AP is deployed as a data access device in branch offices, while AC is deployed at headquarters. All user data is sent from AP to AC, and then forwarded centrally by AC, resulting in low forwarding efficiency.

The WX6100E series wireless controller can support centralized forwarding and distributed forwarding, and users can flexibly set forwarding methods according to business needs and network conditions.

 

Support operation level wireless user access control and management

User based access control is a major feature of the WX6100E series wireless controller products. The User Profile provides a configuration template that can save preset configurations (a collection of configurations). Users can configure different content for their User Profile based on different application scenarios, such as CAR (Committed Access Rate) policies and QoS (Quality of Service) policies.

 

When users access devices, they need to perform identity authentication first. During the authentication process, the authentication server will issue the User Profile name to the device, and the device will immediately enable the specific content configured in the User Profile. When a user accesses the device through authentication, the device will restrict the user's access behavior based on these specific contents. When a user goes offline, the system will automatically disable the configuration items under the User Profile, thereby removing the restrictions on the user under the User Profile. Therefore, User Profile is applicable to restrict the access behavior of online users. When no user is online (which may be due to no user accessing, user not being authenticated, or user being offline), User Profile is a preset configuration and does not take effect.

 

In addition, the WX6100E series wireless controller also supports MAC based authentication access control, which not only allows customers to configure and modify user groups' permissions on AAA servers, but also supports the configuration of specific user permissions. This refined user permission control greatly enhances the availability of wireless networks, and network administrators can easily allocate access permissions to people of different levels or groups through this method.

 

MAC based VLANs are also a major feature of the WX6100E series wireless controllers. In terms of control strategy, administrators can assign users with the same nature (MAC) to the same VLAN, and configure security policies based on VLANs on the controller. This not only simplifies system configuration but also achieves fine-grained management at the user level.

 

For security or billing considerations, system administrators may wish to control the location of wireless users accessing the network. The WX6100E series wireless controller supports user access control based on AP location. When wireless users access the network, the authentication server can issue a list of APs that allow users to access to the AC, and access control can be performed on the AC to limit wireless users to only access APs at designated locations.

 

Support hierarchical AC architecture

The layered AC architecture is a new networking model proposed by H3C to meet the multi-level networking needs in the market. The layered AC adopts an architecture similar to the centralized control and hierarchical management of large chain enterprises. Multiple local access layer ACs are attached to a central core layer management AC, and the access layer AC is directly attached to the AP. The main functions of the access layer AC include real-time services such as AP access and data forwarding, while the core layer AC mainly performs non real time global services such as network management control and centralized authentication. In addition, the core layer AC also has the access AP and data forwarding functions of ordinary AC. The core layer AC is a high-performance AC arranged in the aggregation layer; The access layer AC can be composed of standard AC, all-in-one AC (with routing and DPI functions), or wired and wireless integrated switches, arranged at the same level as the existing network; The architecture model of layered AC pushes the concept of wired and wireless integration to a new height and can be applied to large-scale wireless network deployment. The layered AC model naturally supports the application scenarios of headquarters and branches, and the core link bandwidth and core layer AC forwarding capability are no longer bottlenecks. The core layer AC is centrally controlled, and the access layer AC and downstream AP can easily achieve automatic upgrade and configuration synchronization, greatly simplifying the version upgrade work. In roaming scenarios, the access layer AC is responsible for inter AP switching, and roaming performance is greatly improved.

 

Support star shaped IRF

The WX6100E series wireless controller can support H3C's latest developed star shaped IRF model. Compared with the ordinary cascaded IRF model, the star shaped model adopts a two-layer network (virtual as a central point) to connect multiple devices, making networking more flexible and convenient. The core idea of the star shaped IRF model is to connect multiple devices together in a star topology and virtualize them into a distributed device, which has the following advantages:

 

• Easy networking: Star shaped IRFs do not require dedicated stacking lines or ports, only need to be connected through switches or direct connections, and can establish stacking through layer 2 communication.

 

• Capability stacking: The star shaped IRF presents a virtual AC to the outside world, and the management AP and user count of the virtual AC are the stacking of the capabilities of multiple ACs.

 

• Simple configuration: The configuration on the virtual AC (the main AC, which is visible to the user) can automatically synchronize to all ACs.

 

High reliability backup: Supports N+1 backup, and a single AC failure does not affect the functionality of the virtual AC.

 

Flexible license control: One device in the star shaped IRF installs a license, which can be shared and used by other devices. The number of APs connected to the virtual AC is the sum of the number of licenses installed on the devices in the IRF; In addition, although the license is specifically bound and installed with the device, it can be easily uninstalled and migrated.

Support intelligent channel switching

In wireless local area networks, channels are a very scarce resource, and each AP can only operate on a very limited number of non overlapping channels. For example, for 2.4G networks, there are only 3 non overlapping channels, so how to intelligently allocate channels for APs is the key to wireless applications.

 

There are a large number of possible interference sources in the frequency band where wireless local area networks work, such as radar and microwave ovens, which will interfere with the normal operation of APs in the network. Through the intelligent channel switching function, it can ensure that each AP can be allocated to the optimal channel, minimizing and avoiding adjacent channel interference as much as possible. Moreover, through real-time channel interference detection, APs can avoid interference sources such as radar and microwave ovens in real time.

 

Support intelligent AP load sharing

The 802.11 protocol hands over the decision of wireless roaming to wireless clients, who usually choose APs based on their signal strength (RSSI). This can easily lead to a large number of clients connecting to the same AP simply because of the strong signal of a certain AP. Due to these clients sharing wireless media, the network throughput of each client will be significantly reduced.

 

The intelligent load sharing method can analyze the location of wireless clients in real time, dynamically determine which APs can share the load with each other at the current time and location, and achieve load sharing among these APs by controlling the APs that wireless clients access. The system not only supports load sharing based on the number of online sessions of users, but also supports load sharing based on user traffic.

 

Support 7-layer mobile security detection/defense (wIDS/wIPS)

The WX6100E series wireless controller supports mobile security defense modes such as blacklist, whitelist, Rogue defense, abnormal message detection, illegal user offline, and signature MAC layer attack detection and countermeasures based on preset upgrades (such as DoS attacks, Flood attacks, and man in the middle attacks). Combined with the massive intelligent expert knowledge base built into the wireless application console, flexible wireless security policy judgment criteria can be obtained. For clear illegal attack sources (APs or terminals, etc.), visual physical location tracking and monitoring can be achieved, as well as physical port removal of switches.

 

By cooperating with H3C professional core layer firewall/IPS devices, it is possible to achieve a 7-layer three-dimensional security defense for mobile parks, meeting the true end-to-end security protection requirements from wireless (802.11) to wired (802.3).

 

• Supports RealTime Spectrum Guard mode

RealTime Spectrum Guard (RTSG) is a professional monitoring solution proposed by H3C for wireless environment spectrum status. The entire series of wireless controllers can be integrated with Sensor APs with built-in RF acquisition modules to achieve deep RF monitoring and real-time spectrum protection.

The RTSG console is integrated and deployed in the H3C iMC intelligent management center. It communicates and collects data with Sensor AP through CAPWAP management tunnel, achieving 7X24 hour wireless environment quality monitoring, wireless network capability trend evaluation, and unauthorized interference alarm. Through graphical representation, actively detect and identify all RF interference sources (Wi Fi or non Wi Fi) in the 2.4GHz/5GHz bands, providing real-time FFT maps, spectral density maps, spectral maps, duty cycle maps, event spectral maps, channel power, interference power, etc; Automatically identify interference sources, determine the location of problematic wireless devices, and ensure optimal performance of the wireless network. By combining H3C iAR intelligent reporting components, it is possible to store, trace, and replay RF quality history records throughout the entire coverage area, and automatically generate customized trend, compliance, and audit reports.

 

The deployment of RTSG solutions can flexibly adopt Local mode or Monitor mode to meet the different levels of user wireless environment supervision requirements. When working in Local Mode, normal user access and packet forwarding can be maintained while obtaining effective spectrum protection.

 

Support intelligent wireless service perception (wIAA)

The WX6100E series wireless controller supports intelligent perception of wireless business traffic, enabling elastic policy recognition and management based on wireless user status, and optimizing voice and video service delivery.

 

Support remote probe analysis

The WX6100E series wireless controller supports remote probe analysis for APs. Wi Fi messages within the coverage area can be intercepted, captured, and real-time mirrored to local analysis devices for network administrators to troubleshoot, optimize, and analyze. The remote probe analysis function can perform non convergence mirroring on the working channel, as well as polling sampling on all channels, flexibly meeting the requirements of wireless network monitoring and operation.

 

Built in RF Optimization Engine (ROE)

The WX6100E series wireless controller is equipped with an RF Optimization Engine for APs, which effectively enhances the application acceleration capability and quality assurance effect in high-density access, streaming media transmission and other scenarios in wireless deployment through feature and protocol based RF optimization. This includes multi-user fair scheduling, mixed access fairness, interference filtering, rate optimization, spectrum navigation, multicast enhancement (IPv4/IPv6), packet by packet power control, and intelligent bandwidth guarantee.

 

 

Support 802.1x authentication, MAC address authentication, Portal authentication, etc

The WX6100E series wireless controller supports multiple authentication methods:

 

802.1x authentication: The WX6100E series wireless controller supports multiple 802.1x authentication methods such as TLS, PEAP, TTLS, MD5, SIM card, etc. It also supports local 802.1x authentication methods, providing support for mainstream authentication methods such as MD5, TLS, and PEAP. Users no longer need to configure additional AAA servers. The WX6100E series wireless controller also supports dynamic authorization of VLAN and ACL functions after 802.1x authentication. User policies can be pre-set, and the system automatically configures customer permissions during user authentication.

 

MAC Address Authentication: The WX6100E series wireless controller supports MAC address authentication, which may not be convenient for some handheld terminals (such as Wi Fi Phone, handheld mobile terminals, etc.) to use on a computer. However, MAC address authentication can easily solve this problem by configuring valid MAC addresses on the controller or AAA server. The terminals corresponding to these MAC addresses can be allowed to access the network, while unauthorized terminals that have not been configured in advance cannot access the wireless network. This feature greatly facilitates applications such as wireless medical systems. MAC address authentication can ensure that only PDA working terminals in hospitals can access the wireless network, while rejecting patients' wireless PDAs from using dedicated wireless networks.

 

Portal authentication: The WX6100E series wireless controller provides a built-in Portal authentication server. This authentication method does not require the cooperation of the client, and directly uses the web portal page of the browser as the authentication channel. After the user passes the authentication, they can flexibly jump to the designated access homepage and initiate corresponding authorization and billing. At the same time, customized Portal pages can be flexibly pushed according to strategic requirements to achieve advertising promotion and information transmission, widely used in application scenarios such as wireless campuses, wireless cities, and visitor access.

 

Supports IPv4/IPv6 dual stack (Native IPv6)

The WX6100E series wireless controller supports IPV6 access for wireless customers. At the starting point of the tunnel AP, due to the device's awareness of IPv6, it is possible to achieve mapping from IPv6 priority to tunnel priority; On the AC side, complex control and filtering such as ACL filtering can also be applied to IPv6 packets.

The WX6100E series wireless controller can also be deployed in IPv6 networks, automatically negotiating an IPv6 tunnel between AC and AP. When AC and AP are fully operating in IPv6 state, the wireless controller can still correctly perceive IPv4 and process IPv4 packets from wireless clients. The WX6100E series wireless controller has flexible adaptability to IPv4/6, which can meet various complex applications of customers in IPv4 to IPv6 network migration. It can provide IPv4 services to customers in IPv6 islands, and also allow users to easily log in to the network through the IPv6 protocol in IPv4 islands.

 

The WX6100E series wireless controller supports IPv6 SAVI (Source Address Validation) technology to address the rampant IPv6 packet forgery attacks on campus networks. By listening to the address allocation protocol to obtain the user's IP address, it ensures that subsequent applications can use the correct address to access the internet and cannot forge other people's IP addresses, ensuring the reliability of the source address. At the same time, the combination of IPv6 SAVI and Portal technology further ensures the authenticity and security of all online user packets.

 

Provide end-to-end QoS

The WX6100E series wireless controller is developed on the Comware platform, which not only fully supports the Diff Serv standard, but also adds QoS support for the IPv6 protocol.

 

The QoS Diff Serv model mainly includes flow classification, traffic policing, queue management, queue scheduling, etc. It fully implements the six groups of PHB and services defined in the standard, including EF, AF1~AF4, BE, etc., enabling network operators to provide users with service guarantees of different service quality levels, making the Internet truly a comprehensive network that simultaneously carries data, voice, and video services.

 

Support fast second and third layer roaming

H3C's centralized wireless architecture not only facilitates layer 2 roaming, but also greatly facilitates cross layer roaming. WLAN networks deployed with Fat APs have limited information transmission between APs, making it difficult to implement layer 3 roaming. The centralized architecture is very easy to solve the problem of cross layer roaming. The WX6100E series wireless controller supports layer 2 and layer 3 roaming, and the roaming domain is not limited by subnets. This excellent roaming feature allows customers to plan their wireless network without worrying too much about the existing network, focusing more on wireless signal coverage. This greatly simplifies the early network planning and reduces network planning costs.

 

In traditional mode, when wireless user terminals use 802.1x as a means of 802.11 access authentication and key exchange, there will be a lot of interaction messages between the wireless user terminal and the AP. When a wireless user terminal roams between two APs, if the wireless user terminal fully follows the complete 802.1x interaction process during the new AP access, it will inevitably cause a long roaming switching time. For some services that are sensitive to roaming switching time (such as voice services), such long switching time is unbearable. The WX6100E series wireless controller uses Key caching technology to achieve fast switching of users during roaming. Key caching technology strikes a good balance between secure access and fast roaming for users, allowing wireless user terminals to roam between two APs without having to go through a complete 802.1x authentication interaction process, while ensuring user identity recognition and continuity of key usage; Wireless users adopt fast roaming mode, with a roaming time of no more than 50ms within a single AC, meeting the demanding requirements of voice services.

 

Support multiple remote access scenarios for branch offices

When AC and AP are connected through a wide area network link, users can flexibly choose between centralized forwarding or local forwarding modes to improve business performance such as branch LAN printing access and terminal mutual access.

 

When there is a failure in the wide area network link or AC, online users will not be disconnected, can continue to access local resources, and can support AC escape function.

 

When the branch AP is deployed within a private network, AC can communicate with the AP through NAT.

扫二维码用手机看
未找到相应参数组,请于后台属性模板中添加