Creating Network Segmentation Profile on the vSZ Controller

Network Segmentation was designed specifically to target Multi Dwelling Unit (MDU) deployments. Network Segmentation is currently using external Dynamic Pre-shared Key (DPSK) to place a single tenant and their devices into their own individual VXLAN (iLAN).
Note: For 6.1.1.5 Smartzone Release, Network Segmentation supports Rodan/ FastIron release 10.0.10 ICX.

Data Plane (DP) will play the role of Home DP or Partner DP. Each DP plays the home DP role and has its own VXLAN Network Identifier (VNI) range. Home DP facilitates MDU UE, connect with each other based on the same VNI number.

  1. On the menu, click Services > Hotspots & Portals > Network Segmentation > Network Segmentation Profiles to display the Network Segmentation Profiles.

    Network Segmentation Profiles

  2. Click the icon to display the Create Network Segmentation dialog box.

    Editing Network Segmentation Groups in SmartZone User Interface

  3. Complete the following fields under the General dialog box:
    • Name: Enter a network segmentation profile name.
    • Data Plane: Select the data plane from the table or create a data plane by clicking the icon to display the Create Data Plane Relation dialog box.

      Creating Data Plane Relation

      Complete the following fields:

      • Normal Data Plane: Select the data plane from the list.
      • VIN Range: Enter the VNI range; ensure your VNI range is large enough to accommodate all units in the property. Each unit gets its own unique VNI.
        Note: The VNI value can be mapped from the client data in Troubleshooting from the Management Guide, if user is having issues in selecting the VNI range.
      • DHCP Profile: Select the DHCP profile from the drop down list or click the to create a DHCP Profile. refer to Creating Profile-based DHCP from the RUCKUS Traffic Management Guide.
      • DHCP Pool: Select the DHCP pool from the drop down list or click the to create a DHCP pool. Refer to Creating Profile-based DHCP from the RUCKUS Traffic Management Guide.
      • NAT Profile: Select the NAT profile from the drop down list or click the to create a NAT profile. Refer to Creating Profile-based NAT from the RUCKUS Traffic Management Guide.
      • NAT Pool: Select the NAT pool from the drop down list or click the to create a NAT pool. Refer to Creating Profile-based NAT from the RUCKUS Traffic Management Guide.
        Note: By default, the Redundant Data Plane is switched off. Switch it on to enable the Redundant Data Plane.

      Note: You can also edit and delete a data plane by selecting the options Configure and Delete respectively, from the Data Plane tab.
  4. Click Next.
  5. Complete the following fields under the Wireless dialog box:

    By defaut, the Wireless option is disabled. Switch on to enable the Wireless option.

    Selecting SSID (wireless) for Network Segmentation

    • SSID: Select the SSID for Network Segmentation from the drop down list.

      The selected SSID will be displayed in the Selected SSID field.

    • WLAN: Select WLANs (wireless) for Network Segmentation.
  6. Click Next.
  7. Complete the following fields under the AP Wired dialog box:

    By defaut, the AP Wired option is disabled. Switch on to enable the AP Wired option.

    AP Wired Ethernet Profile

    • Select the Ethernet profile: Select the ethernet profile from the drop down list or click the icon to create an ethernet profile.
      Please provide information on creation of ethernet profile. I'm not able to enable the AP Wired feature.

      The selected SSID will be displayed in the Selected SSID field.

    • Select the AP group: Select the AP group from the table.
  8. Click Next.
  9. Complete the following fields under the Switch dialog box:

    By defaut, the Switch option is disabled. Switch on to enable the Switch option.

    Selecting Switch Groups

    • Select the Switch Groups: From the table, select the switch group which is to be added to the Network Segmentation group.
      Note: To select the participated Switch Group for the segment profile, administrator can utilize the search function to filter out the groups.
    • Select Distribution Switches: Select the distribution switch from the drop down list which is to be added to the Network Segmentation group.

      Select Distribution Switches

      Note: VXLAN is supported only on higher end switches such as ICX 7850, 7650 and 7550 model with router image, so distribution switch should use the above mentioned ICX models.

      To configure the distribution switches, select the switch from the table and click Configure Icon to display the Edit Distribution Switch dialog box.

      Configure Distribution Switch

      Complete the following fields:

      • Data Plane: Select the data plane.
      • VLAN List: Enter the VLAN List.
      • Loopback Interface ID: Enter the Loopback Interface ID.
      • Loopback Interface IP: Enter the Loopback Interface IP.
      • Loopback Interface Subnet Mask: Enter the Loopback Interface Subnet Mask.
      • Keep alive: Enter the keep alive time interval to enable data plane monitor status. This option is enabled, if the Data Plane Redundancy is switched on.

        Keep alive value is restricted between the range of 1 - 20 seconds to check Data plane status by ICMP Ping.

      • Retry times: Enter the retry time interval to enable data plane monitor status. This option is enabled, if the Data Plane Redundancy is switched on.

        Retry times is restricted between the range of 1 - 5 to check Data plane status retry times if no response.

      • Available Access Switches: The available access switches are displayed in the table.
      • Selected Access Switches: Select the access switch from the interface.

        Selected Access Switches

      • Data Plane Redundancy: Administrator can disable/enable site redundancy.
        Note: The maximum size of redundancy server is seven.
      • Distribution Switch and Data Plane communicate client VNI information via VxLAN Tunnel as follows:
        1. Switch Client connect to Access Switch.
        2. Access Switch connect to the Distribution Switch.
        3. Distribution Switch establish VxLAN tunnel to the Data Plane.

        Switch Client management:

        1. Distribution Switch use loopback interface connect to Data Plane interface.

          Loopback Interface Connect to Data Plane Interface

        2. Network Routing will be carried out between Distribution Switch loopback interface and Data Plane data interface.
        3. Switch Client belonging to Access Switch should authenticate VLAN network.
        4. Browser will re-direct to Web Authentication page.
        5. After the Switch Client pass web authentication, the Distribution Switch forward the client traffic to Data Plane.

          For the Network Segmentation function of Switch part, all devices between Distribution Switch and Data Plane must enable the Jumbo mode. This includes the Distribution Switch itself and vSZ-D Data interface which belongs to the vSwitch on ESXi. Otherwise, switch client will not be able to access the internet connection.

          To enable the Jumbo mode, do the following:

          • On the menu, click Network > Wired > Switches to display the Switches window.

            Switches

          • Click Configuration > Configure to display Feature Configuration dialog box.
          • Switch ON to enable the Jumbo mode.

            Feature Configuration

          • Click OK.
        6. The data plane detects the VxLAN.
        7. Data Plane provide the DHCP/NAT service according to Switch Client VNI information.

    • Setup Access Switches: Select the access switch and apply the setting.

      Setup Access Switches

      Complete the following fields:

      • You can choose multiple switches as access switches, administrator can unify the Web Auth Page settings by clicking the Apply to all. The access switch will share the same configurations instead of configuring each switch manually.
  10. Click Next.
  11. Verify the data in the Review Page.

    Review Page

  12. Click OK.

From the table, select the network segmentation profile to view the profile settings details.

Network Segmentation Profile Settings

Functions of switches are as follows:

  • Access Switch provide Web Authentication Service and handles VLAN service.
  • Distribution Switch handles VNI/VLAN mapping and forward the traffic to Data Plane.

    The data plane handles VNI and DHCP/NAT services.

    When Switch Client access the internet by browser, most packets come back from gateway to the Data Plane. The Data Plane must add VxLAN header and then forward to the Distribution Switch.

    Note: The maximum packet length between Distribution Switch and Data Plane is 1564 (1514 general +50 VxLAN header)

Note: You can also edit and delete Network Segmentation Profiles by selecting the options Configure and Delete respectively, from the Network Segmentation Profiles window.