19
Copyright © 2016 Arrive Systems, Inc. All rights reserved.
5.2 Cisco Bonjour Gateway:
Bonjour
is Apple’s service discovery protocol which locates devices such as printers, other
computers, and the services that those devices offer on a local network using multicast
Domain Name System (mDNS) service records.
The Cisco Wireless LAN Controller acts as a Bonjour Gateway. The WLC listens for Bonjour
services and by caching those Bonjour advertisements (AirPlay, AirPrint etc.) from the source/
host e.g. AppleTV, responds back to Bonjour clients when a request for service is initiated.
Cisco Bonjour gateway information: http://bit.ly/1P9Go5g
6. Physical Air Wall Method
The concept of an “air wall (also called air-gap)” in computing refers to the idea of isolating
a computer installation to make it extraordinarily secure--so much so that it could almost be
considered a closed system. In this method, the corporate and guest networks are separated
by a physical air wall/gap.
To make it convenient without having to add several interfaces, two Arrive AirPoint
embedded devices are used: one for corporate users and one for guest users. Switching
presentations is done in the HDMI domain by using 1 x Arrive AMP-1041-BYMG or BYMH
wired and wireless media hub and a second AAP-1011-BYMG as the guest wireless gateway
(this eliminates using an external HDMI switcher). While extremely secure, this approach
requires more hardware between the two devices and their respective HDMI outputs (IR,
Button Panel and RS-232 control available).
AIR-WALL WiFi CONNECTED: Two separate Arrive AirPoint devices are deployed per room with one connected
to GUEST SSID and the otherto the CAMPUS SSID.
iPAD
iPAD
Surface
8.1
Surface
8.1
Guest
VLAN: 999
Campus-802.1x
VLAN: 200-204
Campus- PSK
VLAN: 100-104
Guest
VLAN: 999
Campus-802.1x
VLAN: 200-204
Campus- PSK
VLAN: 100-104
Wireless Controller configured to separate CAMPUS
(e.g. VLAN 200-204) and GUEST VLAN (e.g. VLAN: 999);
separates the GUEST and AUTHORIZED VLAN traffic as
a good practice. Note: Arrive AirPoint needs a PSK
supported SSID.
Wireless Controller receives Bonjour (mDSN) adver-
tisement from Arrive AirPoint, shares this separately
and independently with GUEST from AIRPOINT 1 and
CAMPUS SSIDs from AIRPOINT 2. Media traffic to
Arrive AirPoint Guest and Campus VLANs is completely
separated (Air-walled).
Arrive AirPoint connected to
Miracast supported devices
over WiFi Direct.
Android/Windows 8.1 devices
connected to the GUEST SSID/
VLAN, can see the Arrive
AirPoint 1. Miracast connection
to Arrive AirPoint is via WiFi
Direct.
Arrive AirPoint 1 connected to GUEST
SSID/VLAN. SAME DISPLAY IS SHARED
BETWEEN TWO ARRIVE AIRPOINT DEVICES.
iOS devices connected to the
GUEST SSID/VLAN, can see the
Arrive AirPoint 1. Airplay
connection to Arrive AirPoint
is via WiFi Guest VLAN.
Android/Windows 8.1 devices
are connected to the
CORPORATE SSID/VLAN, can
see the Arrive AirPoint 2.
Miracast connection to Arrive
AirPoint is via WiFi Direct.
iOS devices connected to the
CORPORATE SSID/VLAN, can
see only Arrive AirPoint 2.
AirPlay connection to Arrive
AirPoint is via WiFi CORPORATE
VLAN.
Core, distribution,
& access layers
Mobility Controller
GUEST
BYOD
AUTHORIZED
USER BYOD
The same display can be
shared between two Arrive
AirPoint devices using 1041-
BYMG HDMI switching. An
external AV switcher can be
added as an option.
The same display can be
shared between two Arrive
AirPoint devices using 1041-
BYMG HDMI switching. An
external AV switcher can be
added as an option.
Arrive AirPoint connected to
Miracast supported devices
over WiFi Direct.
AirPoint 2 connected to
Campus PSK SSID.
Figure 10: Physical Air-Wall method