Cisco Mobile Office—
On the Road
Making Your Hotel Public Spaces More
Valuable to Mobile Professionals
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
1
Agenda
• Introducing Cisco Mobile Office—On the Road
• Mobility trends
• Cisco Mobile Office—On the Road program
• Wireless update
• Enabling technologies and standards
• Products
• Design requirements
• Implementation
• Migration
• Why Cisco
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
2
Introducing
Cisco Mobile Office—On the Road
• Cisco Mobile Office—On the Road offers the
opportunity for you to:
Provide differentiated guest services to increase room occupancy
Provide a platform to deploy new applications
Create new sources of revenue
Leverage your property investment and achieve operational benefits
• How:
Provide high-speed network access to guest rooms, meeting
spaces, and other public spaces
• In addition, operational benefits can help make the
project a success
Provide high-speed network access to the “back of the house”
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
3
Cisco Mobile Office — On the Road
High-Speed Network Access for Hotel Guests
• Internet and
corporate VPN access
• Converged hotel services
Video on demand
Guest services
Interactive gaming
IP telephony
Networked mini-bar
• Meeting Rooms
Training, video conferencing
• Hotel portal/ad insertion
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
4
Cisco Mobile Office — On the Road
High-Speed Network Access in the Back Office
• Environmental
control
• Web-based staff
training
• Roving check in/out
• Mobile staff
communications
• Supply chain
management
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
5
Requirements for Mobile Professionals
• Secure
• Fast
• Available
• Access to business
applications
• Video and voice
integrated with data
• Convenient access
and accounting
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
6
Cisco Addresses the
Requirements for Mobility
Mobility Requirement
Cisco Addresses the Requirement
Secure connections
•
•
•
•
•
Fast, instant access to
Internet/intranet
• Standards-based, reliable
broadband infrastructure
Available any time,
anywhere, to any device
• Wired and wireless access solutions
Easy access to data, voice,
and video applications
• AVVID
• Content optimization
Consistent user experience
• Virtual networking
• IP domain management
• Mobile IP
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
VPN security
Firewall
VLANs
802.1x
EAP/LEAP
7
Cisco Mobile Office—
On the Road Partner Community
Provide services to
venues
Integrators
Resellers
Settlement
Providers
CPN Service
Providers
Development
Partners
OEMs
Train
Stations
Airports/
Airlines
Hotels
Enterprise
Venue
Partners
Convention
Centers
Create Demand for
Access and Brand
Cisco Mobile Office
Channel SE Hotel Venue
PC
Visitor-Based
Networks
© 2002, Cisco Systems, Inc. All rights reserved.
Other
Partners
ASPs
Content
Providers
Provide hardware
and applications
8
Wireless ISP Roaming (WISPr) Forum
• Wireless Ethernet Compatibility Alliance (WECA)
• Global industry-wide representation
Hardware manufacturers (Cisco, Agere, Toshiba, Funk,
Intel, Nokia, Nomadix)
Software vendors (Microsoft, Woodside Networks)
Settlement providers (iPass, GRiC, TSI, Excilan,
Fiberlink)
WISPs (Wayport, Airwave, HereUare)
Operators (Sprint PCS)
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
9
Objectives of WISPr
• Define Wireless ISP roaming best practices:
Billing and roaming
Consistent end-user experience
Third-party billing settlement
Network-wide security
• Initiate creation of standards for roaming
through groups such as IEEE, ETSI or the IETF
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
10
Enabling Technologies and Standards
Wireless LAN (WLAN)
802.11
Wi Fi
802.1x
WLAN Security
Extensible Application Protocol(EAP)
Light Extensible Application Protocol (LEAP)
3DES encryption
IPsec
AAA RADIUS
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
11
Standards
Wireless Security—802.1X
• IEEE draft standard
client
• Overcomes limitations of 802.11 security
• Leverages existing standards
EAP
Extensible Authentication Protocol (EAP)
RADIUS
AP
• Available authentication types
Light Extensible Authentication Protocol
(LEAP)
EAP-TLS
1
RADIUS
2
1 Mutual authentication
RADIUS
server
2 Dynamic, session-based encryption keys
3 Centralized user administration
4 Extensible authentication support
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
3
user
database
4
12
Light Extensible Authentication Protocol
(LEAP)
AP
client
Start
Request identity
Client
authenticates
RADIUS
key
server
username
challenge
challenge
response
response
success
success
challenge
challenge
response
response, key
key length
Cisco Mobile Office
Channel SE Hotel Venue
AP blocks all requests
until LEAP completes
username
broadcast key
© 2002, Cisco Systems, Inc. All rights reserved.
RADIUS
server
RADIUS server
authenticates
client
ke
y
AP sends client broadcast key,
encrypted with session key
13
How LEAP Challenges and Responses Work
Create
challenge
password
from
database
challenge
response A
challenge
one-way
hash
LEAP
algorithm
password
hash
Using password from database,
generate response to own challenge
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
14
How LEAP Challenges and Responses Work
challenge
usersupplied
password
one-way
hash
password
hash
response B
response A
challenge
LEAP
algorithm
response B
If response A = response B,
then authenticate user
Why?
Using user-supplied password,
generate response to challenge
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
15
Comparing Responses
usersupplied
password
password
from
database
one-way
hash
challenge
challenge
password
hash
LEAP
algorith
m
LEAP
algorith
m
response B
response A
one-way
hash
password
hash
If response A = response B, then
user-supplied password =
password from database
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
16
Deriving the Session Key
hash (hash (password))
RADIUS response to client
client challenge to RADIUS
client response to RADIUS
RADIUS challenge to client
MD5
128-bit key
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
17
Deploying LEAP
Clients
RADIUS servers
• Cisco Aironet ® adapters
• Cisco Secure ACS
Turn on LEAP in ACU
Supports LEAP
Windows: Use Windows
Networking logon
Needs access to an NTformatted database or ODBC
connection to NT Domain
Controller or Active Directory
Others: Use ACU window
• Others: No support for LEAP
Use static WEP
On Windows XP, use EAPTLS
One AP can support LEAP,
EAP-TLS, and static WEP
With LEAP proxy in V3.0, can
interact with database
manager that supports MSCHAP* * LDAP and NDS do not support MS-CHAP
• Others:
Funk Software
Interlink Networks
Open Systems Consultants
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
18
Setting Up ACS
• ACS can handle 40+
LEAP logons per
second
• Connection from site to
ACS must be reliable
• Access to backup ACS
server is advisable
• ACS for LEAP Design
Guide provides details
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
19
Cisco Mobile Office—On the Road
Mobility from Public Access Facilities
Third-party
broadband
roaming/
settlement/
billing service
Hotel
Meeting Rooms
Enterprise
Router/
Firewall
T1/E1
In-line
powered
switch
Internet
Coffee
Shop
Wireless
Access Point
Airport
BBSM
PBX
LRE
switch
POTS
splitter
Wiring Closet
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
LRE CPE
Hotel Rooms
20
Cisco Mobile Office—On the Road
Mobility from Public Access Facilities
Third-party
broadband
roaming/
settlement/
billing service
Hotel
Meeting Rooms
Enterprise
Cisco 2600 Series
router and firewall
Cisco Aironet ®
1200 wireless
access points
T1/E1
Internet
Coffee
Shop
Airport
Catalyst ® 3524PWR XL In-line
powered switch
BBSM
PBX
Catalyst
2900 Series
LRE switch
Cisco
LRE 48
POTS
Splitter
Wiring Closet
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
Cisco 575
LRE CPE
Hotel Rooms
21
Network Options for Any Public Space
Wireless LANs for concourses, airline lounges,
concession, ticket counter, and baggage claim areas
Long-reach Ethernet for areas with category 1/2/3 wiring
and/or long runs
10/100/1000 high-speed Ethernet switching for areas with
Category 5 wiring
Cisco Building Broadband Services Manager (BBSM)
Routers for enterprise-class multi-service solutions
and managed services
Cisco Mobile Office
Channel SE Hotel Venue
Service Selection Gateway (SSG) – menu-based
service selection and billing for individual services
© 2002, Cisco Systems, Inc. All rights reserved.
22
Cisco Aironet ® Series Wireless LAN Access
• Access points
10/100 Ethernet
Cisco Aironet 1200 Series
Access Point
New!
Can be used as a repeater
Minimum setup
Maximum flexibility
Internal testing for RF link
• Client adapters
PC
LM
PCI
• Wireless bridges
8 MAC addresses
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
23
Cisco Long-Reach Ethernet (LRE)
• Cisco Catalyst ® 2900 Long-Reach
Ethernet LRE XL switch
Up to 15-Mbps symmetric Ethernet
Management
QoS, scalability, security
Supports POTS
Supports Cisco switch clustering
• Cisco Long-Reach Ethernet LRE 48
POTS Splitter
LRE and POTS on the same telephone line
• Cisco 575 Long-Reach Ethernet LRE
Customer Premise Equipment CPE
Bridges LRE and Ethernet
Small footprint
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
24
Cisco Switches
Cisco Catalyst 2900 Series
Performance
Migration path to Gigabit in the LAN
LAN-edge QoS
Multicast management
Cluster management
High availability and security
Cisco Catalyst 3500 Series XL
Stackable
10/100 and Gigabit Ethernet
Mid-sized networks
Internet business applications
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
25
Cisco Routers
Cisco 2600 Series
Cisco 7100 Series
For branch offices
Integrated VPN solution
Modular, multi-service
Routing and VPN services
Data/voice/video integration
Cisco 3600 Series
Cisco 7200 Series
For medium to large offices
For diverse VPN environments
Modular, multi-service
IOS-based services
Data/voice/video integration
VPN Acceleration module
Service Selection Gateway (SSG)
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
26
Cisco Building Broadband Service
Manager (BBSM)
• Software platform for subscriber session management
• MXU environment
• High-speed Internet access in building broadband networks
• BBSM provides
Subscriber session management
Integrated billing
Easy plug-and-play access
• Most widely deployed in-building service platform
• Compatible with broadband technologies
Ethernet
Long-reach Ethernet (LRE)
Digital subscriber line (DSL)
Cable
Wireless
Cisco Mobile Office
Channel SE Hotel Venue
Fiber
© 2002, Cisco Systems, Inc. All rights reserved.
27
Cisco Content Transformation Engine
CTE 1400
• Solutions for:
Many device types — Connection management
Existing content not wireless-friendly — Presentation management
Connections are intermittent and many — Data management
• Leverage existing content
• Rapid deployment
• Fast, seamless installation
• Easy to use
• Line rate performance
• Scalability
• Low cost of ownership
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
28
Cisco Mobile Office—On the Road
Product and Feature Roadmap
Phase I
Q3CY01
Phase II
Q1CY02
Phase III?
Q3CY02
Features
End-to-end security
Reliability
Scalability
Network management
Phase I plus:
QoS
VoIP support
802.1 support
GSM/CDMS billing
Phase II plus:
VLAN support
Visitor-based network
WISPr support
GSM/CDMS roaming
Products
Wireless LAN access
Long-reach Ethernet
Plain old telephone
service (POTS)
Ethernet switches
Routers
Service management
RADIUS servers
VPN clients
Firewalls
Network management
Phase I plus: Cisco
CTE 1400
Catalyst 5000
Cisco IP Phone 7960
Cisco IP SoftPhone
Phase II plus:
Web collaboration
software
Cisco Aironet AP
upgrade
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
29
Design Requirements
• Traffic requirements
• Security requirements
• Interference with other networks
• Additional traffic on existing infrastructure
• Regulatory requirements
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
30
Implementation
• Site survey — a vital component
Refer to BBSU Web site:
http://www.cisco.com/warp/customer/504/index.html
• Logical segregation/prioritization of traffic
between public and private segments
• Maintenance, root access control implementation
• Set-up of walled garden, access rights, billing
and authentication (relevant to the deployment)
• Evaluate in-house resources
• Consider leveraging an integration partner
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
31
Migration
• Effects on existing backbone connection –
need to upgrade?
• Management framework for
upgrades/servicing
• Dual-mode (802.11a/b) upgrade issues
• Appropriate framework for 802.1x
• Scalability requirements for future
services
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
32
Mobility—Cisco Advantage
• End-to-end solution
From enterprise to venue
End-to-end security
• Demand generation
For venue partner
For service provider
• Market leadership
Cisco brand
World-class solution
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
33
Get Started Now
Engage in the Cisco Mobile Office—
On the Road program
On the Road
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
34
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
35
Information for Systems Engineers
• The following material is not to be
presented to the customer
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
36
Information for Systems Engineers—
Agenda
• Why sell Cisco Mobile Office—On the Road?
• Technical qualifying questions
• Overcoming technical objections
• Tools to help you sell Cisco Mobile Office—On the
Road
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
37
Why Sell Cisco Mobile Office—On the Road?
• Strong demand
• High-speed access in buildings and public
spaces is becoming a competitive
requirement
• New revenue opportunity
• First step toward multiple broadband
application (and sales) opportunities
VoIP, video, and vertical market applications
• Cisco offers complete solutions
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
38
Technical Qualifying Questions
• Is there more than one wireless Internet service provider (WISP)
delivering wireless services in the venue?
• What is your existing infrastructure?
Frame?
ATM?
Ethernet?
• Do you have shared media deployed?
• Is there a security policy in place?
• What relationships with technical partners exist, if any?
• Is there any wireless deployed?
If so, do you use SSID?
Or (name the alternative to SSID)?
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
39
Overcoming Technical Objections
• It’s not secure enough
• It may not be available all the time
• The quality of service may be unacceptable
• It could be hard to manage
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
40
Cisco Mobile Office—On the Road
Tools for Successful Selling
• Web site www.cisco.com/go/mobileoffice
White papers
Contacts
Presentations
Case studies
Partners
HotSpot Locator
• Resources for resellers
Cisco packaged services
Partner and reseller communications
Partner and Reseller Helpline
Sales Tools Central
Networking Products MarketPlace for Resellers
Cisco Resource Network for Resellers
Partner and reseller training
Cisco Mobile Office
Channel SE Hotel Venue
© 2002, Cisco Systems, Inc. All rights reserved.
41