Features
1-2 Introduction
Features
ThefeaturesandbenefitsoftheRBT‐4102includethefollowing:
•Localnetworkconnectionvia10/100MbpsEthernetportsor54Mbpswirelessinterface
(supportingupto255mobileusersperradio).
• IEEE802.11a,802.11b,and802.11gcompliant.
•RogueAPDetectionprovidestheabilitytoscantheairwavesandcollectinformationabout
accesspointsinthearea.Thisfeaturedetectsneighboringaccesspointsandaccesspointsnot
authorizedtoparticipateinthenetwork.
• Advancedsecurityfeatures,suchasWEP,WPA(Wi‐FiProtectedAccess),AES,WPA2,
SNMPv3,aswellasmanageabilityfeaturesthatincludeEnterasysNetSightConsole,NetSight
PolicyManagerandNetSightInventory
Managersupport,securewebmanagement,secure
Telnetmanagement,andaCLIinterface.
•Twoexternalantennaconnectorsareprovidedforusewithbothindoorandoutdoor
antennas.Point‐to‐pointandpoint‐to‐multipointconnectionsarealsosupported.
•ProvidesseamlessroamingwithintheIEEE802.11a,802.11b,and802.11gWLAN
environment.
• Automaticallyselects
theavailablechannelatpower‐up.
•AllowsyoutoconfigureuptosevenVirtualAccessPoints(VAPs)oneachradiointerfaceeach
withitsownsetofauthenticationandsecurityparameters.
• SupportsCabletronDiscoveryProtocol(CDP).
• SupportsSpectralinkVoicePriority(SVP).
• SupportspolicyclassificationrulesviatheEnterasysNetsightPolicyManager.
Policy
Policy‐basednetworksisanarchitecturethatallowsnetworkadministratorstomapnetwork
servicestoidentifiedusers,machines,peripheralsandothernetworkentities.Arole‐based
networkaccesspolicyconsistsofthreetiers:
• Classificationrulesmakeupthefirstorbottomtier.Therulesapplytodevicesinthepolicy
environment,
suchasswitches,routersandtheRoamAbout4102.Therulesaredesignedtobe
implementedatorneartheuser’spointofentrytothenetwork.Therulesaretypicallyat
Layer2,3,or4oftheISOnetworkmodel.
•ThemiddletierisServices,whichallowsmultipleclassificationrules
tobeaggregated.
Servicescanincludee‐mailandInternetaccess.
•Roles,orBehavioralProfilesmakeupthetoptier.Therolesassignservicestovariousbusiness
functionsordepartments,suchasexecutive,sales,andengineering.
Toimplementmostroles,policy‐basednetworkingrequiresauthenticationsuchasMACaddress
or802.1Xusing
EAP‐TLS,EAP‐TTLS,orEAP‐PEAP.Authorizationinformation,attachedtothe
authenticationresponse,determinestheapplicationoftheaccesspolicy.Onewaytocommunicate
theauthorizationinformationistoincludethePolicyNameinaRADIUSFilter‐IDattribute.A
securityadministratorcanalsodefinearoletobe
implementedintheabsenceofanauthenti cation
andauthorization.
TheRBT‐4102supportsthepolicyclassificationrulesviatheEnterasysPolicyProfileMIB.