DellPowerConnect W- Series ArubaOS 6.2 | User Guide AdvancedSecurity | 670
Chapte r 36

Advance d Security

Extreme Security (xSec)i s a cryptographically secure,Layer-2 t unnelingnetwork protocol implemented over the
802.1x protocol. The xSec protocol can be used to secure Layer-2 traffic between the D ell controllerand wi redand
wireless clients, or between Dell controllers.
NOTE:xSec i san optional ArubaOSsoftware module. You must purchase and install the license for the xSec software module on
thecontroller.
Topics in this chapter include:
l"SecuringClient Traffic" on page 670
l"SecuringController-to-ControllerCo mmunication"o n page 677
l"Configuringthe Odyssey Client on Client Machines" on page 678
xSecencrypts an original Layer-2 data frame inside a Layer-2xSec frame, the contents of which are definedby the
protocol. xSec relieso n 256-bit Advanced Encryption Standard (AES) encryption.
Upon 802.1x client authentication, xSec creates a tunnelbetween the client and the controller. The xSecframe sent
over the air or wire betweent heuser and the controller contains user and controllerinformation, as well as original IP
and MAC addresses,in encrypted form. All userinformation is secured using xSec. This concept is also extendedto
securemanagement information and data between tw o Dell controllerso n the same VLAN.
For xSectunneling between a client and controllerto work, a version of the FunkOdyssey client software that
supports xSecneeds to be installed on the client.I t is possiblet o secureclients running Windows 2000 and XP
operating systems using xSec andt heOdyssey c lient software..
NOTE:xSec i san optional licensedfeature for Dell controllers. xSec is automatically enabled on the controller when you install the
license. For information about thecurrently supported release for Funk Odyssey,please contact Juniper Networks.
xSecprovides the following advantages:
lAdvanced security as Layer-2 framesare encrypted and tunneled.
lEase of implementation of advanced encryption in a heterogeneous environment.xSec is designed to support
multipleoperating syst ems anda wide range of network interface cards (NICs). All encryption and decryption on
the client machinei s performedby the Odyssey client while the NICs are configured with NULL encryption.
This ensuresthat even older operating systems that cannot beupgraded to support WPA or WPA2
authentication can be secured using xSecand the Odyssey c lient.
lCompatible with TLS, TTLS and PEAP.
lAdvanced authentication extendedt o wired clients allowingnetwo rkmanagers to secure wired ports.

Securing Client Traff ic

You can securewireless or wired client traffic with xSec. On the client, install the OdysseyClient so ftware.The xSec
client must complete 802.1x authentication. to connect to the network. The client indicates the use of the xSec