T E C H N C A L S P E C F C A T O N S
Performan e and apa ity
• Campus-connected APs: Up to 2,048
• Remote APs: Up to 8,192
• Users: Up to 32,768
• MAC addresses: Up to 256,000
• VLAN P interfaces: 512
• Fast Ethernet ports (10/100): Up to 72
• Gigabit Ethernet ports (GB C or SFP): Up to 40
• 10 Gigabit Ethernet ports (XFP): Up to 8
• Active firewall sessions: Up to 2,097,200
• Concurrent PSec tunnels: Up to 32,768
• Firewall throughput: Up to 80 Gbps
• Encrypted throughput (3DES): Up to 32 Gbps
• Encrypted throughput (AES-CCM): Up to 16 Gbps
Wireless LAN se urity and
ontrol features
• 802.11i security (WFA-certified WPA2 and WPA)
• 802.1X user and machine authentication
• EAP-PEAP, EAP-TLS, EAP-TTLS support
• Centralized AES-CCM, TK P and WEP encryption
• 802.11i PMK caching for fast roaming applications
• EAP offload for AAA server scalability and
survivability
• Stateful 802.1X authentication for standalone APs
• MAC address, SS D and location-based
authentication
• Multi-SS D support for operation of multiple WLANs
• SS D-based RAD US server selection
• Secure AP control and management over
PSec or GRE
• CAPWAP-compatible and upgradeable
• Distributed WLAN mode for remote AP deployments
• Simultaneous centralized and distributed
WLAN support
Identity-based se urity features
• Captive portal, 802.1X and MAC address
authentication
• Username, P address, MAC address and encryption
key binding for strong network identity creation
• Per-packet identity verification to prevent
impersonation
• RAD US and LDAP-based AAA server support
• nternal user database for AAA server failover
protection
• Role-based authorization for eliminating
excess privilege
• Robust policy enforcement with stateful
packet inspection
• Per-user session accounting for usage auditing
• Web-based guest enrollment
• Configurable acceptable use policies for guest
access
• XML-based AP for external captive portal
integration
• xSec option for wired LAN authentication and
encryption(802.1X authentication, 256-bit
AES-CBC encryption)
Convergen e features
• Voice and data on a single SS D for
converged devices
• Flow-based QoS using voice flow classification (VFC)
• Alcatel-Lucent NOE, S P, Spectralink SVP, SCCP
and Vocera ALGs
• Strict priority queuing for over-the-air QoS
• 802.11e support – WMM, U-APSD and T-SPEC
• QoS policing for preventing network abuse
via 802.11e
• DiffServ marking and 802.1p support for
network QoS
• On-hook and off-hook Vo P client detection
• Vo P call admission control (CAC) using VFC
• Call reservation thresholds for mobile Vo P calls
• Voice-aware RF management for ensuring
voice quality
• Fast roaming support for ensuring mobile
voice quality
• S P early media and ringing tone generation
(RFC 3960)
• Per-user and per-role rate limits (bandwidth
contracts)
Adaptive radio management
(ARM) features
• Automatic channel and power settings for
thin APs
• Simultaneous air monitoring and end user services
• Self-healing coverage based on dynamic
RF conditions
• Dense deployment options for capacity optimization
• AP load balancing based on number of users
• AP load balancing based on bandwidth utilization
• Coverage hole and RF interference detection
• 802.11h support for radar detection and avoidance
• Automated location detection for active RF D tags
• Built-in XML-based Location AP for RF D
applications
Wireless intrusion prote tion
features
• ntegration with WLAN infrastructure
• Simultaneous or dedicated air monitoring
capabilities
• Rogue AP detection and built-in location
visualization
• Automatic rogue, interfering and valid AP
classification
• Over-the-air and over-the-wire rogue AP
containment
• Adhoc WLAN network detection and containment
• Windows client bridging and wireless bridge
detection
• Denial of service attack protection for APs
and stations
• Misconfigured standalone AP detection and
containment
• Third party AP performance monitoring and
troubleshooting
• Flexible attack signature creation for new
WLAN attacks
• EAP handshake and sequence number analysis
• Valid AP impersonation detection
• Frame floods, Fake AP and Airjack attack detection
• ASLEAP, death broadcast, null probe response
detection
• Netstumbler-based network probe detection
Stateful firewall features
• Stateful packet inspection tied to user identity
or ports
• Location and time-of-day aware policy definition
• 802.11 station awareness for WLAN firewalling
• Over-the-air policy enforcement and station
blacklisting
• Session mirroring and per-packet logs for
forensic analysis
2Alcatel-Lucent OmniAccess 6000
The OAW-6000 offers a best in class, user-centric security framework to authenticate wireless users, enforce role-base
access control policies an quarantine unsafe en points from accessing the corporate wireless network. Guest users can
be easily an safely supporte with the built-in captive portal server an a vance network services.
The OAW-6000 can create a secure networking environment without requiring a itional VPN/firewall evices using
integrate site-to-site VPN an NAT capabilities, split-tunneling an an ICSA-certifie stateful firewall. Site-to-site VPN
support can be integrate with all lea ing VPN concentrators to provi e seamless integration into existing corporate VPNs.