cisco meraki 产品介绍与技术原理 PPT

合集下载

思科 Meraki MR72 802.11ac 无线访问点说明书

思科 Meraki MR72 802.11ac 无线访问点说明书

High performance cloud-managed 802.11ac wirelessThe Cisco Meraki MR72 is a three–radio, cloud-managed 2x2 MIMO 802.11acaccess point. Designed for general purpose next-generation deployments in harshoutdoor locations and industrial indoor conditions, the MR72 provides performance,security, and manageability.The MR72 provides a maximum 1.2 Gbps data rate with concurrent 802.11ac and802.11n 2x2:2 MIMO radios, and security and spectrum visibility via a third radiodedicated to 24x7 WIDS/WIPS and automated RF optimization. An integratedBluetooth low energy (BLE) radio delivers Beacon functionality and BLE devicescanning.The combination of cloud management, 802.11ac, full-time RF environmentscanning, and an integrated Bluetooth technology delivers the high throughput,reliability, and flexibility required by the most demanding business applications likevoice and high-definition streaming video, both today and tomorrow.MR72 and Meraki cloud management: A powerful comboThe MR72 is managed through the Meraki cloud, with an intuitive browser-basedinterface that enables rapid deployment without training or certifications. Since theMR72 is self-configuring and managed over the web, it can even be deployed at aremote location without on-site IT staff.The MR72 is monitored 24x7 via the Meraki cloud, which delivers real-time alertsif the network encounters problems. Remote diagnostics tools enable real-timetroubleshooting over the web, meaning multi-site, distributed networks can bemanaged remotely.The MR72’s firmware is always kept up to date from the cloud. New features, bugfixes, and enhancements are delivered seamlessly over the web, meaning nomanual software updates to download or missing security patches to worry about. Product Highlights• Ideal for outdoor and industrial indoor environments • 2x2:2 802.11ac, 1.2 Gbps aggregate dual-band data rate • 24x7 real-time WIPS/WIDS and spectrum analytics via dedicated third radio• Integrated Bluetooth low energy Beacon and scanning radio • Forms point-to-point links with optional sector antennas • Self-healing, zero-configuration mesh• Integrated enterprise security and guest access• Application-aware traffic shaping• Self-configuring, plug-and-play deploymentMR72Dual-band 2x2 MIMO 802.11ac Access Pointwith dedicated security and RF optimization radio and Bluetooth low energy Beacon and scanning radioFeaturesAggregate data rate of up to 1.2 GbpsA 5 GHz 2x2:2 802.11ac radio and a 2.4 GHz 2x2:2 802.11n radio offer a maximum combined aggregate dual-band data rate of 1.2 Gbps. Technologies like transmit beamforming and enhanced receive sensitivity allow the MR72 to support a higher client density than typical enterprise-class access points, resulting in fewer required APs for a given deployment. Band steering further enhances overall throughput, by moving 5 GHz-capable clients to the 5 GHz radio, maximizing the capacity in the 2.4 GHz range for older 802.11b/g clients.Rugged industrial designThe MR72 is designed and tested for salt spray, vibration, extreme thermal conditions, shock and dust and is IP67 rated, making it ideal for extreme environments. Despite its rugged design, MR72 has a low profile and is easy to deploy.Third radio dedicated to security and RF optimizationThe MR72’s sophisticated, dedicated dual-band third radio scans the environment continuously, characterizing RF interference and containing wireless threats like rogue access points. No more need to choose between wireless security, advanced RF analysis, and serving client data: a dedicated third radio operates without any impact to client traffic or throughput.Bluetooth low energy Beacon and scanningAn integrated Bluetooth low energy radio provides seamless deployment of BLE Beacon functionality and effortless visibility of BLE devices within range of the AP. The MR72 enables the next generation of location-aware engagement right out of the box. Automatic cloud-based RF optimizationThe MR72’s sophisticated, automated RF optimization means that there is no need for the dedicated hardware and RF expertise typically required to tune a wireless network. The real-time full-spectrum RF analysis data collected by the dedicated third radio is continuously fed back to the Meraki cloud. The Meraki cloud then automatically tunes the MR72’s channel selection, transmit power, and client connection settings for optimal performance under the most challenging RF conditions.Secure wireless environments using 24x7 Air MarshalNo longer choose between a wireless intrusion prevention system (WIPS) and serving client data: thanks to the dedicated third radio, Air Marshal, a highly optimized built-in WIPS, scans continuously for threats and remediates them as commanded, all without disrupting client service. Alarms and optional auto-containment of rogue APs are configured via flexible remediation policies, ensuring optimal security and performance in even the most challenging wireless environments.Integrated enterprise security and guest accessThe MR72 features integrated, easy-to-use security technologies to provide secure connectivity for employees and guests alike. Advanced security features such as AES hardware-based encryption and WPA2-Enterprise authentication with 802.1X and Active Directory integration provide wire-like security while still being easy to configure. One-click guest isolation provides secure, Internet-only access for visitors. Our policy firewall (Identity Policy Manager) enables group or device-based, granular access policy control.Application-aware traffic shapingThe MR72 includes an integrated layer 7 packet inspection, classification, and control engine, enabling you to set QoS policies based on traffic type. Also included is integrated support for Wireless Multi Media (WMM), 802.1p, and DSCP. Prioritize your mission critical applications, while setting limits on recreational traffic, e.g., peer-to-peer and video streaming.High performance meshThe MR72’s advanced mesh technologies, like multi-channel routing protocols and multiple gateway support, make it possible to cover hard-to-wire areas and improve network resilience. In the event of a switch or cable failure, the MR72 will automatically revert to mesh mode.Self-configuring, self-optimizing, self-healingWhen plugged in, the MR72 automatically connects to the Meraki cloud, downloads its configuration, and joins the appropriate network. The MR72 then self-optimizes, determining the ideal channel, transmit power, and client connection parameters. As necessary, it will also self-heal, responding automatically to switch failures and other errors.Recommended Use CasesOutdoor coverage for high client-density corporate campuses, educational institutions, metro Wi-Fi, and parks• Provide high-speed access to a large number of clients• Point-to-multipoint mesh Indoor coverage for industrial areas(e.g., warehouses, manufacturingfacilities)• Reliable coverage for scanner guns,security cameras, and POS devices• High speed-access for iPads, tabletsand laptopsZero-touch point-to-point links• Build a long-distance bridge betweentwo networks• Extend hotspot networks via mesh whilesimultaneously serving clientsSpecificationsRadiosOne 2.4 GHz 802.11b/g/n, one 5 GHz 802.11a/n/ac, one dedicated for dual-band WIPS & spectrum analysis, and one dedicated to Bluetooth low energy (2.4 GHz)Concurrent operations of all radiosMax data rate 1.2 Gbit/sOperating bands:FCC (US) CE (Europe)2.412-2.484 GHz 2.412-2.484 GHz5.150-5.250 GHz (UNII-1) 5.150-5.250 GHz (UNII-1)5.725 -5.825 GHz (UNII-3) 5.250-5.350 GHZ (UNII-2)5.470-5.600, 5.660-5.725 GHz (UNII-2e)802.11ac and 802.11n Capabilities2 x 2 multiple input, multiple output (MIMO) with two spatial streamsMaximal ratio combining (MRC)Beamforming20 and 40 MHz channels (802.11n), 20, 40, and 80 MHz channels (802.11ac)Packet aggregationPowerPower over Ethe rnet: 37 - 57 V (802.3af compatible)Power consumption: 13.87 W max (802.3af)Power over Ethernet injector sold separatelyMountingMounts to walls and vertical poles.Mounting hardware includedPhysical SecuritySecurity screw includedKensington lock hard pointAnti-tamper cable bayConcealed mount plateEnvironmentOperating temperature: -40 °F to 140 °F (-40 °C to 60 °C)IP67 environmental ratingPhysical Dimensions10.1” x 6.22” x 3.3” (256 mm x 158 mm x 83 mm) including mounting bracket Weight: 3.1 lbs. (1.4 kg)Interfaces 1 x 100/1000Base-T Ethernet (RJ45)Four external N-type female antenna connectorsSecurityIntegrated policy firewall (Identity Policy Manager)Mobile device policiesAir Marshal: Real-time WIPS (wireless intrusion prevention system) with alarmsRogue AP containmentGuest isolationTeleworker VPN with IPsecPCI compliance reportingWEP, WPA, WPA2-PSK, WPA2-Enterprise with 802.1XTKIP and AES encryptionVLAN tagging (802.1q)Quality of ServiceAdvanced Power Save (U-APSD)DSCP802.1pLayer 7 application traffic shaping and firewallMobilityPMK and OKC credential support for fast Layer 2 roamingL3 roamingLED Indicators1 power/booting/firmware upgrade statusRegulatoryRoHSFor country-specific regulatory information, please contact Meraki salesWarranty1 year hardware warranty with advanced replacement includedOrdering InformationMR72-HW Meraki MR72 Cloud Managed 802.11ac APMA-INJ-4-XX Meraki 802.3at Power over Ethernet Injector (XX = US/EU/UK/AU) MA-ANT-20 Meraki Dual-Band Omni AntennasMA-ANT-21 Meraki 5 GHz Sector AntennaMA-ANT-23 Meraki 2.4 GHz Sector AntennaMA-ANT-25 Meraki Dual-Band Patch AntennaNote: Meraki Enterprise license required.RF Performance Table* Maximum hardware capability shown above. Transmit power is configurable in increments of 1 dB and is automatically limited to comply with local regulatory settings.。

思科 Meraki MR70 双频 802.11ac Wave 2 技术规格说明书

思科 Meraki MR70 双频 802.11ac Wave 2 技术规格说明书

MR70Dual-band, 802.11ac Wave 2 ruggedized access point delivering basic enterprise wireless foroutdoor or low-density deploymentsEntry-level cloud-managed 802.11ac wirelessThe Cisco Meraki MR70 is a dual-radio, cloud-managed 2x2:2 802.11ac Wave 2 access point with MU-MIMO support. Designed for basic, best-effort deployments that require rapid installation, the MR70 provides enterprise-grade security and simple management in a ruggedized, IP67-rated form factor that sports integrated omni-directional antennas.The MR70 is ideal for municipal athletic fields, garages, public gardens, space-constrained outdoor deployments, and even rapid-response emergency kits designed to quickly deliver wireless in disaster-struck areas. The MR70 provides a maximum 1.3 Gbps* aggregate frame rate with concurrent 2.4 GHz and 5 GHz radios.MR70 and Meraki cloud management: a powerful combinationThe MR70 is managed through the Meraki cloud, with an intuitive browser-based interface that enables rapid deployment without training or certifications. Because the access point is monitored24x7 by the Meraki cloud, the MR70 can deliver real-time alertsif the network encounters problems, and diagnostic tools enable real-time troubleshooting over the web. The MR70’s firmware is always kept up to date from the cloud. New features, bug fixes, and enhancements are delivered seamlessly over the web, meaning no manual software updates to download or missing security patches to worry about.Product Highlights• 2x2 MU-MIMO 802.11ac Wave 2• 1.3 Gbps* aggregate dual-band frame rate• Integrated enterprise security and guest access • Built-in WIPS for threat detection and remediation • Application-aware traffic shaping• Self-configuring, plug-and-play deployment • Rapid, plug-and-play deployment• Integrated location analytics and heat mapFeaturesAggregate data rate of up to 1.3 Gbps*A 5 GHz 2x2:2 radio supporting 80 MHz channel widths and a2.4 GHz 2x2:2 radio supporting 40 MHz channel widths offer a combined dual-radio aggregate frame rate of 1.3 Gbps*, with up to 866 Mbps in the 5 GHz band thanks to 802.11ac Wave 2 and 400 Mbps in the 2.4 GHz band.Multi User Multiple Input Multiple Output (MU-MIMO)With support for the 802.11ac Wave 2 standard, the MR70 offers MU-MIMO for more efficient transmission to multiple clients. This increases the total network performance and the improves the end user experience.Integrated enterprise security and guest accessThe MR70 features integrated, easy-to-use security technologies to provide secure connectivity for employees and guests alike. Advanced security features such as AES hardware-based encryption and WPA2-Enterprise authentication with 802.1X provide wire-like security while still being easy to configure. One-click guest isolation provides secure, Internet-only access for visitors. Our policy firewall (Identity Policy Manager) enables group or device-based, granular access policy control.Secure wireless environments using Air MarshalThe MR70 comes equipped with Air Marshal, a built-in wireless intrusion prevention system (WIPS) for threat detection and attack remediation. MR70 access points will scan their environment opportunistically based on user-defined preferences. Alarms and auto-containment of malicious rogue APs are configured via flexible remediation policies, ensuring optimal security and performance in even the most challenging wireless environments.Application-aware traffic shapingThe MR70 includes an integrated Layer 7 packet inspection, classification, and control engine, enabling you to set QoS policies based on traffic type. Prioritize your mission critical applications, while setting limits on recreational traffic, e.g., peer-to-peer and video streaming.Self-configuring, self-optimizing, self-healingThe MR70’s advanced mesh technologies like multi-channel routing protocols and multiple gateway support enable scalable coverage of hard-to-wire areas with zero configuration. Mesh also improves network reliability — in the event of a switch or cable failure, the MR70 will automatically revert to mesh mode, providing continued gateway connectivity to clients.Rapid, plug-and-play deploymentWhen plugged in, the MR70 automatically connects to the Meraki cloud, downloads its configuration, and joins the appropriate network. It self-optimizes, determining the ideal channel, transmit power, and client connection parameters.Integrated analyticsDrill down into the details of your network usage with highly granular traffic analytics. Extend your visibility into the physical world with built-in location analytics that enables you to view visitor numbers, dwell time, repeat visit rates, and track foot traffic trends.SpecificationsRadios2.4 GHz 802.11b/g/n/ac client access radio5 GHz 802.11a/n/ac Wave 2 client access radioSupported frequency bands (country-specific restrictions apply):• 2.412-2.484 GHz• 5.150-5.250 GHz (UNII-1)• 5.250-5.350 GHZ (UNII-2)• 5.470-5.600, 5.660-5.725 GHz (UNII-2e)• 5.725-5.825 GHz (UNII-3)802.11ac and 802.11n Capabilities2 x 2 multiple input, multiple output (MIMO) with two spatial streamsSU-MIMO and MU-MIMO supportMaximal ratio combining (MRC) & Beamforming20 and 40 MHz channels (2.4 GHz), 20, 40, and 80 MHz channels (5 GHz)Up to 256-QAM on both 2.4 GHz and 5 GHz bandsPacket aggregationPowerPower over Ethernet: 37-57 V (802.3af compatible)Power consumption: 11 W max (802.3af)Power over Ethernet injector sold separatelyMountingMounts to walls and vertical polesMounting hardware includedPhysical SecuritySecurity screw includedEnvironmentOperating temperature: -4 °F to 131 °F (-20 °C to 55 °C)IP67 environmental ratingOperating humidity: 5% to 95%Physical Dimensions9.65” x 4.53” x 1.18” (245 mm x 115 mm x 30 mm)Weight: 15.87 oz (0.45 kg)AntennaIntegrated omni-directional antennas (4.5 dBi gain at 2.4 GHz, 4.7 dBi gain at 5 GHz)Interfaces1x 100/1000 BASE-T Ethernet (RJ45)SecurityIntegrated Layer 7 firewall with mobile device policy managementReal-time WIDS/WIPS with alerting and automatic rogue AP containment with Air Marshal Flexible guest access with device isolationVLAN tagging (802.1Q) and tunneling with IPSec VPNPCI compliance reportingWEP, WPA, WPA2-PSK, WPA2-Enterprise with 802.1XEAP-TLS, EAP-TTLS, EAP-MSCHAPv2, EAP-SIMTKIP and AES encryptionEnterprise Mobility Management (EMM) & Mobile Device Management (MDM) integration Quality of ServiceAdvanced Power Save (U-APSD)WMM Access Categories with DSCP and 802.1p supportLayer 7 application traffic identification and shapingMobilityPMK, OKC, and 802.11r for fast Layer 2 roamingDistributed or centralized Layer 3 roamingLED Indicators1 power/booting/firmware upgrade statusRegulatoryRoHSEN50155: 2017 (Railway)For additional country-specific regulatory information, please contact Meraki sales Warranty1 year hardware warranty with advanced replacement includedOrdering InformationMR70-HW: Meraki MR70 Cloud Managed 802.11ac APMA-PWR-30W-XX: Meraki AC Adapter for MR Sseries (XX = US/EU/UK/AU)MA-INJ-4-XX: Cisco Meraki 802.3at Power over Ethernet Injector (XX = US/EU/UK/AU) Note: Meraki Enterprise license requiredCompliance and StandardsSafety ApprovalsUL 60950-1CAN/CSA-C22.2 No. 60950-1IEC 60950-1EN 60950-1Radio ApprovalsCanada: FCC Part 15C, 15E, RSS-247Europe: EN 300 328, EN 301 893Australia/NZ: AS/NZS 4268Mexico: NOM-121For additional country-specific regulatory information, please contact Meraki Sales EMI Approvals (Class B)Canada: FCC Part 15B, ICES-003Europe: EN 301 489-1-17, EN 55032, EN 55024Australia/NZ: CISPR 32Exposure ApprovalsCanada: FCC Part 2, RSS-102Europe: EN 50385, EN 62311Australia: AS/NZS 2772。

《CISCO产品简介》PPT课件

《CISCO产品简介》PPT课件
– 思科 AS5850 通用网关
• 思科 AS5800 通用网关是目前市场上密度最高、运营商级访问服务器, 最多可以支持2688次呼叫(4XCT3s)或86条E1线路。
CISCO产品简介
• 访问服务器
– 思科 AS5800 通用访问服务器
• 思科 AS5800 可以在一个远程访问集线器产品中实现最高密度的调 制解调器集中并提供集成业务数字网络(ISDN)终接功能。
– 思科 AS5300 通用访问服务器
• 思科 AS5300 可在同一接口上终接ISDN、56k模拟调制解调器、传 真和VoIP呼叫,从而提高了大业务量真实环境中的性能标准。
CISCO产品简介
• 访问服务器
– 思科 ATA 180 系列模拟电话适配器
• 思科系列模拟电话适配器(ATA)可以将模拟电话转变为IP电话,
• 产品类型
– 访问服务器 – 附件 – 思科电缆产品 – 思科IOS软件 – CiscoWorks2000 – 内容网络设备 – 客户响应 – 客户端设备 – 集线器以及集中器 – 接口卡以及模块 – 交互软件 – 网络管理
CISCO产品简介
• 产品类型
– 光纤平台 – 路由器 – 安全组件 – 交换机 – 话音系统 – 视频 – 语音应用 – 虚拟专网(VPN)设备 – 无线设备
CISCO产品简介
• CISCOWORKS 2000
• CiscoWorks2000产品线提供了在所需要的任何时间和地点进行端对端管 理解决方案部署所需要的灵活性。CiscoWorks2000产品线包括了以下的 解决方案:
• LAN管理解决方案(LMS) • 路由WAN管理解决方案(RWAN) • VPN/安全管理解决方案(VMS) • 服务管理解决方案(SMS)

Meraki MS 系列交换机

Meraki MS 系列交换机

支持所有部署类型的强大的特性集
Meraki交换机包含高端产品所具备的所有传统Ethernet特性, 其中包括: • 用于为语音、视频等任务关键型链路划分优先级的服务质量
(QoS) • 用于实现基于端口的网络访问控制的IEEE 802.1X支持 • 基于MAC的RADIUS认证和MAC白名单 • 用于简化VoIP部署的语音VLAN • 用于以线速监测网络流量的端口镜像 • 用于防止用户在网络上添加非法DHCP服务器的DHCP监听 • 用于优化组播流量的网络性能的IGMP监听 • 用于实现大容量中继、堆叠和更高可用性的链路聚合控制协
3
Meraki 聚合交换产品组合
系列
MS410
部署类型 接口1 上行链路 电源配置 堆叠能力 路由能力
型号
1G光纤聚合
16 / 32 x 1GbE SFP
2 x 10GbE SFP+(MS410-16) 4 x 10GbE SFP+(MS410-32)
模块化 可选冗余PSU(单独出售)
160G物理 + 虚拟
设置一台Meraki交换机只需将其联网,没有必要进行重复、 基于命令的配置。交换机联网后数分钟之内就可以启动和运 行。
一个功能强大的集中管理界面可让管理员深入了解网络及其 使用情况,查看那些交换机接近数百个站点的容量,快速配 置和重配置交换机端口的安全、QoS等策略。Meraki控制面 板提供统一策略、事件日志和监测功能,便于用户管理网络 部署,而且不会对性能产生任何影响。
· 灵活堆叠,可扩展配置和提升高性能。 · 智能管理可降低成本和开销,缩短问题解决时间。 · 行业标准特性使其能够轻松整合到现有和混合基础设
施中。 · 基于角色的管理,通过web实现自动安全的固件设计。

cisco-meraki-产品介绍与技术原理资料

cisco-meraki-产品介绍与技术原理资料
cisco meraki 产品介绍
—by 梁晓宇
目录 CONTENTS
技术原理 与其他AP对比
meraki架构
ap自动从云管理 中心下载配置文 件
产品特点
1、配置简单
管理者只需登录meraki的管理界面,即可在云端配置AP,可以在多种平台管理无线 网络,目前支持的平台有: Apple iPad, iPod Touch, and iPhone (iOS 5 or higher) Android (2.2 or higher), including Amazon’s Kindle Fire Mac OS X (10.5 or higher) Windows Pro 7, 8, 8.1, 10, Vista, XP (Service Pack 3 or higher), Server 2008,
技术原理—Air Marshal
2 预防机制:air marshal ap具备识别非授权ap的功能,这样可以使 得网络管理者在客户连接上这些非授权ap前,采用物理措施移除这些非 授权ap。具体实现如下:
产生大量这 三种类型的 数据包,用 来冒充非授 权ap,从而 迫使已经连 接上非授权 ap的客户 断开与其连 接
技术原理—应用层的可视化管理
可以看到: 使用者名称 使用的应用类型 使用者的操作系统或者设备 使用者所使用的流量
• meraki根据ip地址,主机名以及端口号范围来确定应用类型 • 对于p2p类型应用流量的分类,采用的方法是:识别到在一系列浮动的ip地址中
的简短的tcp会话( recognizes short TCP sessions across a fleeting range of IP addresses),就可以识别p2p应用 • 可以使用dscp或者pcp协议给不同应用的流量打标签,从而可以使用qos对用户 使用不同的应用进行限制或者限速 • 用户所使用应用的流量分析和配置信息等将会和网络管理数据一起上传到云管理 中心

meraki_offer_description_cn说明书

meraki_offer_description_cn说明书

产品说明产品说明:Meraki 云网络本产品说明(“产品说明”)介绍了上列出的思科 Meraki 云网络产品。

您的订用受本产品说明和/go/eula上列出的思科《最终用户许可协议》(或您和思科之间存在的类似条款)(以下称为“协议”)的约束。

本产品说明中使用但未另行定义的术语具有协议中赋予它们的含义。

1.说明思科 Meraki 云网络产品套件包括网络硬件设备(无线接入点、交换机和安全设备/防火墙)、监控摄像头、传感器、终端管理软件以及网络应用和 WAN 性能软件。

所有思科 Meraki 产品都通过一个云托管软件平台进行管理,该平台被称为 Meraki “控制板”。

控制板允许客户通过单个面板来配置、管理和监控部署在其全球网络中的 Meraki 设备。

2.补充条款和条件2.1.许可证和使用权条件要为您购买的每项硬件获得软件许可证,您需要购买和维持相关的 Meraki 云服务,否则硬件将无法运行。

您使用 Meraki 云服务的软件许可证和权利不可转让。

2.2.期限和许可模式2.2.1.在共同终止许可模式下,思科技术使用期限的开始日期是相关思科技术交付给您的日期,结束日期为以下两个日期中的较早者:(a) 共同终止日期或 (b) 使用权终止日期。

2.2.2.在按设备许可模式下,思科技术使用期限的开始日期为以下两个日期中的较早者:(a) 您通过Meraki 云服务分配相关硬件的日期或 (b) 相关思科技术交付给您之日后的第 91 天。

此类使用期限的结束日期为以下两个日期中的较早者:(1) 开始日期加上相应采购订单中规定的 Meraki云服务使用期限或 (2) 使用权终止日期。

2.3.其他使用条件您同意仅根据思科 Meraki 网站上提供的规范使用硬件和思科技术,并且您(而不是思科 Meraki)全权负责对您的 Meraki 云服务帐户实施管理控制。

2.4.遵守法律如果思科 Meraki 检测到您以违反法律的方式使用硬件或思科技术,在通过电子邮件向您发出书面通知后,该硬件和/或思科技术可能会从您的 Meraki 云服务帐户中删除。

cisco meraki 产品介绍与技术原理 PPT

cisco meraki 产品介绍与技术原理 PPT
4、高安全性
用户流量不会上传到云管理中心 符合(PCI / HIPAA compliant)认证
技术原理—cloud management
云管理中心


ssl隧道,使用 802.1x/radius 认证

meraki设备与云管理中心是通过ssl隧道 连接,利用一个专有协议来管理AP等 meraki设备 将meraki设备部署在网络的边缘是为了 使得用户在上网时产生的数据流量不会 经过云管理中心,从而保证用户数据安 全 meraki将网络管理数据(例如配置,镜 像等)和用户在上网时所产生的数据分 离,仅在ssl隧道上传递网络管理数据, 且传递速度不超过1kb/s,这样保证了 即便在断开与meraki云管理中心的连接 的情况下,只要连接到网络,用户仍然 可以上网。
客户的mac地址,为了不泄露客户隐私,一旦通过cmx
api下载这些数据,云管理中心对用户的mac地址做一次
哈希运算,使得用户mac地址不能被识别出
技术原理—Air Marshal
air marshal是一个WIPS(Wireless Intrusion Prevention System)平台,用来保障meraki无线接入的安全
技术原理—Air Marshal
2 预防机制:air marshal ap具备识别非授权ap的功能,这样可以使 得网络管理者在客户连接上这些非授权ap前,采用物理措施移除这些非 授权ap。具体实现如下:
产生大量这 三种类型的 数据包,用 来冒充非授 权ap,从而 迫使已经连 接上非授权 ap的客户 断开与其连 接
802.11数据包, 类型为probe request
包含信号 强度和信 道信息
大家有疑问的,可以询问和交流

MX 智能管理路由器系列

MX 智能管理路由器系列

分支机构网关服务
• 内置DHCP、NAT、QoS和VLAN管理服务。 • Web缓存:加快常用内容的访问速度。 • 负载均衡:将多条WAN链路整合为一个高速接口,并提供 QoS、流量整形和故障切换策略。 • 智能连接监测:自动检测2层和3层中断,并进行快速故障 切换,包括3G/4G USB调制解调器。
Z1 Telecommuter Gateway
Z1 Telecommuter Gateway(远程办公网关)将Cisco Meraki控 制面板和基于远端的集中管理延伸至在家办公的IT员工和管 理人员。 借助Cisco Meraki Auto VPN专利技术,管理员可一键将VoIP、 远程桌面(RDP)等网络服务延伸至远端员工,提供有线和 无线访问,并通过 7层流量整形和优先级划分提高最终用户 的生产力。
Z1TelecommuterGateway
• 1x802.11b/g/n射频, 1x802.11a/n射频, 2x2双重空间串流 MIMO • 使用Cisco Meraki Auto VPN的站点间(IPsec)VPN • 7层应用可视性和流量整形
4
机架式型号
M X84 MX100 MX400 M X 6 00
MX智能管理路由器系列
概述
Cisco Meraki MX 路由器是那些拥有众多分散站点的企业的理想选择。由于MX是100%智能管理解决方案,其安装和远程管理都很 简单。MX拥有一整套网络服务,因此无需多个设备。这些服务包括SD-WAN、7层防火墙、web缓存、4G故障切换和Auto VPN。
基于MERAKI SD-WAN的智能站点间VPN
小型零售分支机构, 小型诊所 50 250 Mbps 25 12 x GbE(2PoE+) N/A N/A 是 桌面/壁挂 10.0” x 5.2” x1”(256mm x 132mm x25mm) 3.37 lb(1.53kg) 90W DC(含) 6W /72 W(MX65) 9W / 79W(MX65W) 32°F - 104°F (0°C - 40°C) 5%-95%
  1. 1、下载文档前请自行甄别文档内容的完整性,平台不提供额外的编辑、内容补充、找答案等附加服务。
  2. 2、"仅部分预览"的文档,不可在线预览部分如存在完整性等问题,可反馈申请退款(可完整预览的文档不适用该条件!)。
  3. 3、如文档侵犯您的权益,请联系客服反馈,我们会尽快为您处理(人工客服工作时间:9:00-18:30)。

目录 CONTENTS
技术原理 与其他AP对比
R2, 2012 Windows Phone 8.1
2、高延展性
云管理平台对所接入AP的数量无限制,每新增一台AP,只需将AP连接至云管理平台, 无需另外配置
3、高可靠性
客户的数据至少在三个数据中心备份 meraki的云管理平台是大规模的分布式架构,提供冗余链路 即便断开与网络的连接,meraki所管理的无线网络仍然能够连接上网
技术原理—CMX(Connected Mobile Experences)
cmx api
利用cmx 位置分析能够为管理者提供wifi用户的实时位置统计信息和报告
技术原理—CMX
1 通过扫描probe request和802.11数据包来检测开启wifi的设备
iphone设备, 没有连接到互 联网
技术原理—应用层的可视化管理
可以看到: 使用者名称 使用的应用类型 使用者的操作系统或者设备 使用者所使用的流量
• meraki根据ip地址,主机名以及端口号范围来确定应用类型 • 对于p2p类型应用流量的分类,采用的方法是:识别到在一系列浮动的ip地址中
的简短的tcp会话( recognizes short TCP sessions across a fleeting range of IP addresses),就可以识别p2p应用 • 可以使用dscp或者pcp协议给不同应用的流量打标签,从而可以使用qos对用户 使用不同的应用进行限制或者限速 • 用户所使用应用的流量分析和配置信息等将会和网络管理数据一起上传到云管 理中心
技术原理—Air Marshal
2 预防机制:air marshal ap具备识别非授权ap的功能,这样可以使 得网络管理者在客户连接上这些非授权ap前,采用物理措施移除这些非 授权ap。具体实现如下:
产生大量这 三种类型的 数据包,用 来冒充非授 权ap,从而 迫使已经连 接上非授权 ap的客户 断开与其连 接
1、监视和警告功能
air marshal会在2.4Ghz和5Ghz信道上扫描附近的未授权访问点,并形成一 个列表,这个列表也将会发给网络管理员。marshal会给特定的客户打上标 签,通过监视客户的源mac地址来跟踪它们的流量,如果发现客户的数据帧 并不是来自内部的网络,那么就会给网络的管理者发送警告邮件
根据wifi信号强度来判断路人和访客
根据所访问时间来区分路人和访客
技术原理—CMX
使用下列参数用来分析用户
技术原理—CMX 3 cmx api将从meraki的云管理中心传递所收集到的数据,传递给指定的服务

cmx api
技术原理—CMX
4
cmx 位置分析的隐私保护:由于收集到的原始数据包含有
客户的mac地址,为了不泄露客户隐私,一旦通过cmx
api下载这些数据,云管理中心对用户的mac地址做一次
哈希运算,使得用户mac地址不能被识别出
技术原理—Air Marshal
air marshal是一个WIPS(Wireless Intrusion Prevention System)平台,用来保障meraki无线接入的安全
4、高安全性
用户流量不会上传到云管理中心 符合(PCI / HIPAA complient
云管理中心


ssl隧道,使用 802.1x/radius 认证

meraki设备与云管理中心是通过ssl隧道 连接,利用一个专有协议来管理AP等 meraki设备 将meraki设备部署在网络的边缘是为了 使得用户在上网时产生的数据流量不会 经过云管理中心,从而保证用户数据安 全 meraki将网络管理数据(例如配置,镜 像等)和用户在上网时所产生的数据分 离,仅在ssl隧道上传递网络管理数据, 且传递速度不超过1kb/s,这样保证了 即便在断开与meraki云管理中心的连接 的情况下,只要连接到网络,用户仍然 可以上网。
802.11数据包, 类型为probe request
包含信号 强度和信 道信息
大家有疑问的,可以询问和交流
可以互相讨论下,但要小声点
大家有疑问的,可以询问和交流
可以互相讨论下,但要小声点
技术原理—CMX
2 云管理中心收到数据后,所有ap所接收到的数据将会聚合,聚合之后所有设
备的数据将会经过一系列的计算并会对其分类,用于之后的实时显示
cisco meraki 产品介绍
—by
目录 CONTENTS
技术原理 与其他AP对比
meraki架构
ap自动从云管理 中心下载配置文 件
产品特点
1、配置简单
管理者只需登录meraki的管理界面,即可在云端配置AP,可以在多种平台管理无线 网络,目前支持的平台有:
Apple iPad, iPod Touch, and iPhone (iOS 5 or higher) Android (2.2 or higher), including Amazon’s Kindle Fire Mac OS X (10.5 or higher) Windows Pro 7, 8, 8.1, 10, Vista, XP (Service Pack 3 or higher), Server 2008,
相关文档
最新文档