Cisco Mobile Office— On the Road Making Your Hotel Public Spaces More Valuable to Mobile Professionals Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 1 Agenda • Introducing Cisco Mobile Office—On the Road • Mobility trends • Cisco Mobile Office—On the Road program • Wireless update • Enabling technologies and standards • Products • Design requirements • Implementation • Migration • Why Cisco Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 2 Introducing Cisco Mobile Office—On the Road • Cisco Mobile Office—On the Road offers the opportunity for you to: Provide differentiated guest services to increase room occupancy Provide a platform to deploy new applications Create new sources of revenue Leverage your property investment and achieve operational benefits • How: Provide high-speed network access to guest rooms, meeting spaces, and other public spaces • In addition, operational benefits can help make the project a success Provide high-speed network access to the “back of the house” Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 3 Cisco Mobile Office — On the Road High-Speed Network Access for Hotel Guests • Internet and corporate VPN access • Converged hotel services Video on demand Guest services Interactive gaming IP telephony Networked mini-bar • Meeting Rooms Training, video conferencing • Hotel portal/ad insertion Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 4 Cisco Mobile Office — On the Road High-Speed Network Access in the Back Office • Environmental control • Web-based staff training • Roving check in/out • Mobile staff communications • Supply chain management Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 5 Requirements for Mobile Professionals • Secure • Fast • Available • Access to business applications • Video and voice integrated with data • Convenient access and accounting Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 6 Cisco Addresses the Requirements for Mobility Mobility Requirement Cisco Addresses the Requirement Secure connections • • • • • Fast, instant access to Internet/intranet • Standards-based, reliable broadband infrastructure Available any time, anywhere, to any device • Wired and wireless access solutions Easy access to data, voice, and video applications • AVVID • Content optimization Consistent user experience • Virtual networking • IP domain management • Mobile IP Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. VPN security Firewall VLANs 802.1x EAP/LEAP 7 Cisco Mobile Office— On the Road Partner Community Provide services to venues Integrators Resellers Settlement Providers CPN Service Providers Development Partners OEMs Train Stations Airports/ Airlines Hotels Enterprise Venue Partners Convention Centers Create Demand for Access and Brand Cisco Mobile Office Channel SE Hotel Venue PC Visitor-Based Networks © 2002, Cisco Systems, Inc. All rights reserved. Other Partners ASPs Content Providers Provide hardware and applications 8 Wireless ISP Roaming (WISPr) Forum • Wireless Ethernet Compatibility Alliance (WECA) • Global industry-wide representation Hardware manufacturers (Cisco, Agere, Toshiba, Funk, Intel, Nokia, Nomadix) Software vendors (Microsoft, Woodside Networks) Settlement providers (iPass, GRiC, TSI, Excilan, Fiberlink) WISPs (Wayport, Airwave, HereUare) Operators (Sprint PCS) Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 9 Objectives of WISPr • Define Wireless ISP roaming best practices: Billing and roaming Consistent end-user experience Third-party billing settlement Network-wide security • Initiate creation of standards for roaming through groups such as IEEE, ETSI or the IETF Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 10 Enabling Technologies and Standards Wireless LAN (WLAN) 802.11 Wi Fi 802.1x WLAN Security Extensible Application Protocol(EAP) Light Extensible Application Protocol (LEAP) 3DES encryption IPsec AAA RADIUS Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 11 Standards Wireless Security—802.1X • IEEE draft standard client • Overcomes limitations of 802.11 security • Leverages existing standards EAP Extensible Authentication Protocol (EAP) RADIUS AP • Available authentication types Light Extensible Authentication Protocol (LEAP) EAP-TLS 1 RADIUS 2 1 Mutual authentication RADIUS server 2 Dynamic, session-based encryption keys 3 Centralized user administration 4 Extensible authentication support Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 3 user database 4 12 Light Extensible Authentication Protocol (LEAP) AP client Start Request identity Client authenticates RADIUS key server username challenge challenge response response success success challenge challenge response response, key key length Cisco Mobile Office Channel SE Hotel Venue AP blocks all requests until LEAP completes username broadcast key © 2002, Cisco Systems, Inc. All rights reserved. RADIUS server RADIUS server authenticates client ke y AP sends client broadcast key, encrypted with session key 13 How LEAP Challenges and Responses Work Create challenge password from database challenge response A challenge one-way hash LEAP algorithm password hash Using password from database, generate response to own challenge Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 14 How LEAP Challenges and Responses Work challenge usersupplied password one-way hash password hash response B response A challenge LEAP algorithm response B If response A = response B, then authenticate user Why? Using user-supplied password, generate response to challenge Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 15 Comparing Responses usersupplied password password from database one-way hash challenge challenge password hash LEAP algorith m LEAP algorith m response B response A one-way hash password hash If response A = response B, then user-supplied password = password from database Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 16 Deriving the Session Key hash (hash (password)) RADIUS response to client client challenge to RADIUS client response to RADIUS RADIUS challenge to client MD5 128-bit key Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 17 Deploying LEAP Clients RADIUS servers • Cisco Aironet ® adapters • Cisco Secure ACS Turn on LEAP in ACU Supports LEAP Windows: Use Windows Networking logon Needs access to an NTformatted database or ODBC connection to NT Domain Controller or Active Directory Others: Use ACU window • Others: No support for LEAP Use static WEP On Windows XP, use EAPTLS One AP can support LEAP, EAP-TLS, and static WEP With LEAP proxy in V3.0, can interact with database manager that supports MSCHAP* * LDAP and NDS do not support MS-CHAP • Others: Funk Software Interlink Networks Open Systems Consultants Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 18 Setting Up ACS • ACS can handle 40+ LEAP logons per second • Connection from site to ACS must be reliable • Access to backup ACS server is advisable • ACS for LEAP Design Guide provides details Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 19 Cisco Mobile Office—On the Road Mobility from Public Access Facilities Third-party broadband roaming/ settlement/ billing service Hotel Meeting Rooms Enterprise Router/ Firewall T1/E1 In-line powered switch Internet Coffee Shop Wireless Access Point Airport BBSM PBX LRE switch POTS splitter Wiring Closet Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. LRE CPE Hotel Rooms 20 Cisco Mobile Office—On the Road Mobility from Public Access Facilities Third-party broadband roaming/ settlement/ billing service Hotel Meeting Rooms Enterprise Cisco 2600 Series router and firewall Cisco Aironet ® 1200 wireless access points T1/E1 Internet Coffee Shop Airport Catalyst ® 3524PWR XL In-line powered switch BBSM PBX Catalyst 2900 Series LRE switch Cisco LRE 48 POTS Splitter Wiring Closet Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. Cisco 575 LRE CPE Hotel Rooms 21 Network Options for Any Public Space Wireless LANs for concourses, airline lounges, concession, ticket counter, and baggage claim areas Long-reach Ethernet for areas with category 1/2/3 wiring and/or long runs 10/100/1000 high-speed Ethernet switching for areas with Category 5 wiring Cisco Building Broadband Services Manager (BBSM) Routers for enterprise-class multi-service solutions and managed services Cisco Mobile Office Channel SE Hotel Venue Service Selection Gateway (SSG) – menu-based service selection and billing for individual services © 2002, Cisco Systems, Inc. All rights reserved. 22 Cisco Aironet ® Series Wireless LAN Access • Access points 10/100 Ethernet Cisco Aironet 1200 Series Access Point New! Can be used as a repeater Minimum setup Maximum flexibility Internal testing for RF link • Client adapters PC LM PCI • Wireless bridges 8 MAC addresses Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 23 Cisco Long-Reach Ethernet (LRE) • Cisco Catalyst ® 2900 Long-Reach Ethernet LRE XL switch Up to 15-Mbps symmetric Ethernet Management QoS, scalability, security Supports POTS Supports Cisco switch clustering • Cisco Long-Reach Ethernet LRE 48 POTS Splitter LRE and POTS on the same telephone line • Cisco 575 Long-Reach Ethernet LRE Customer Premise Equipment CPE Bridges LRE and Ethernet Small footprint Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 24 Cisco Switches Cisco Catalyst 2900 Series Performance Migration path to Gigabit in the LAN LAN-edge QoS Multicast management Cluster management High availability and security Cisco Catalyst 3500 Series XL Stackable 10/100 and Gigabit Ethernet Mid-sized networks Internet business applications Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 25 Cisco Routers Cisco 2600 Series Cisco 7100 Series For branch offices Integrated VPN solution Modular, multi-service Routing and VPN services Data/voice/video integration Cisco 3600 Series Cisco 7200 Series For medium to large offices For diverse VPN environments Modular, multi-service IOS-based services Data/voice/video integration VPN Acceleration module Service Selection Gateway (SSG) Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 26 Cisco Building Broadband Service Manager (BBSM) • Software platform for subscriber session management • MXU environment • High-speed Internet access in building broadband networks • BBSM provides Subscriber session management Integrated billing Easy plug-and-play access • Most widely deployed in-building service platform • Compatible with broadband technologies Ethernet Long-reach Ethernet (LRE) Digital subscriber line (DSL) Cable Wireless Cisco Mobile Office Channel SE Hotel Venue Fiber © 2002, Cisco Systems, Inc. All rights reserved. 27 Cisco Content Transformation Engine CTE 1400 • Solutions for: Many device types — Connection management Existing content not wireless-friendly — Presentation management Connections are intermittent and many — Data management • Leverage existing content • Rapid deployment • Fast, seamless installation • Easy to use • Line rate performance • Scalability • Low cost of ownership Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 28 Cisco Mobile Office—On the Road Product and Feature Roadmap Phase I Q3CY01 Phase II Q1CY02 Phase III? Q3CY02 Features End-to-end security Reliability Scalability Network management Phase I plus: QoS VoIP support 802.1 support GSM/CDMS billing Phase II plus: VLAN support Visitor-based network WISPr support GSM/CDMS roaming Products Wireless LAN access Long-reach Ethernet Plain old telephone service (POTS) Ethernet switches Routers Service management RADIUS servers VPN clients Firewalls Network management Phase I plus: Cisco CTE 1400 Catalyst 5000 Cisco IP Phone 7960 Cisco IP SoftPhone Phase II plus: Web collaboration software Cisco Aironet AP upgrade Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 29 Design Requirements • Traffic requirements • Security requirements • Interference with other networks • Additional traffic on existing infrastructure • Regulatory requirements Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 30 Implementation • Site survey — a vital component Refer to BBSU Web site: http://www.cisco.com/warp/customer/504/index.html • Logical segregation/prioritization of traffic between public and private segments • Maintenance, root access control implementation • Set-up of walled garden, access rights, billing and authentication (relevant to the deployment) • Evaluate in-house resources • Consider leveraging an integration partner Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 31 Migration • Effects on existing backbone connection – need to upgrade? • Management framework for upgrades/servicing • Dual-mode (802.11a/b) upgrade issues • Appropriate framework for 802.1x • Scalability requirements for future services Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 32 Mobility—Cisco Advantage • End-to-end solution From enterprise to venue End-to-end security • Demand generation For venue partner For service provider • Market leadership Cisco brand World-class solution Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 33 Get Started Now Engage in the Cisco Mobile Office— On the Road program On the Road Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 34 Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 35 Information for Systems Engineers • The following material is not to be presented to the customer Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 36 Information for Systems Engineers— Agenda • Why sell Cisco Mobile Office—On the Road? • Technical qualifying questions • Overcoming technical objections • Tools to help you sell Cisco Mobile Office—On the Road Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 37 Why Sell Cisco Mobile Office—On the Road? • Strong demand • High-speed access in buildings and public spaces is becoming a competitive requirement • New revenue opportunity • First step toward multiple broadband application (and sales) opportunities VoIP, video, and vertical market applications • Cisco offers complete solutions Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 38 Technical Qualifying Questions • Is there more than one wireless Internet service provider (WISP) delivering wireless services in the venue? • What is your existing infrastructure? Frame? ATM? Ethernet? • Do you have shared media deployed? • Is there a security policy in place? • What relationships with technical partners exist, if any? • Is there any wireless deployed? If so, do you use SSID? Or (name the alternative to SSID)? Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 39 Overcoming Technical Objections • It’s not secure enough • It may not be available all the time • The quality of service may be unacceptable • It could be hard to manage Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 40 Cisco Mobile Office—On the Road Tools for Successful Selling • Web site www.cisco.com/go/mobileoffice White papers Contacts Presentations Case studies Partners HotSpot Locator • Resources for resellers Cisco packaged services Partner and reseller communications Partner and Reseller Helpline Sales Tools Central Networking Products MarketPlace for Resellers Cisco Resource Network for Resellers Partner and reseller training Cisco Mobile Office Channel SE Hotel Venue © 2002, Cisco Systems, Inc. All rights reserved. 41