Expanding Access Points as a Platform Capabilities
This presentation shows the features & benefits of Wi-Fi 7 APs including flex-radios, dynamic antennas, IoT, containers and more. Jerrod Howard, a hardware product manager at Aruba, introduced the concept of the Access Point (AP) as a platform, highlighting how HPE Aruba Networking is building its Wi-Fi 7 portfolio with increasingly flexible radios and complex internal technologies. He explained the drive towards more adaptable radios that can serve different regulatory regions without restriction, allowing deployment as dual band APs to maximize radio utilization. A key innovation is the development of dynamic antennas, which allow a single AP SKU to function as both an omnidirectional and directional access point, configurable via software. This flexibility is particularly beneficial for environments with varying coverage needs, such as warehouses with sloped ceilings or high-density conference rooms that transition from empty to packed.
Justin Sergi, Product Manager covering IoT, further expanded on the “AP as a platform” concept by discussing HPE Aruba Networking’s IoT and containerization strategy. The goal is to consolidate parallel IoT overlays, allowing the AP to serve as a unified IoT gateway with onboard dual IoT radios and extensible USB ports. This evolution is supported by an “App Store” within Aruba Central, enabling customers to deploy various IoT integrations (e.g., electronic shelf labels, asset tracking, access control) as container-based workloads. This decoupling of IoT integrations from the AP’s operating system through a cloud-native microservices architecture significantly accelerates development and deployment. The developer portal further empowers partners to self-publish new applications, managing their own versioning and ensuring security within a container sandbox with limited resource access.
The discussion also touched upon the Smart Antenna Module (SAM), a sensor embedded in outdoor Wi-Fi 6E and Wi-Fi 7 APs. SAM identifies the antenna, carries RPE data (gain, beamwidth), and reports heading and downtilt, providing critical telemetry about the AP’s physical orientation and performance. This data, combined with advancements in software, will become increasingly crucial for optimizing Wi-Fi 7 deployments. The overall strategy underscores HPE Aruba Networking’s commitment to simplifying network management and extending the capabilities of the access point, turning it into a versatile edge device capable of supporting diverse applications, IoT integrations, and advanced AI functionalities, all while offering flexibility in deployment and reducing operational complexity.
Presented by Jerrod Howard, Outdoor WLAN Product Manager, and Justin Sergi, IoT Product Manager. Recorded live at Networking Field Day 38 in Silicon Valley on July 10, 2025. Watch the entire presentation at https://techfieldday.com/appearance/hpe-aruba-networking-presents-at-networking-field-day-38/ or visit https://techfieldday.com/event/nfd38/ or https://www.hpe.com/us/en/networking/hpe-aruba-networking.html for more information.
Transcript
Uh, so my name is Jared Howard. I'm one of the hardware product managers at Aruba. Uh, I'm gonna impersonate my boss a little bit at the beginning to talk about some of the generic stuff that we're building.
I wa I'm not sure from your side, how many of you are kind of deep RF experts, so I tried to keep a lot of the, the complexity from the antenna systems out of the discussion for the time that we've got. But any questions that you guys have as we go, uh, please feel free to jump in. So, from a wifi seven perspective, we have been building our wifi seven portfolio for about a year now, give or take, um, there is a concerted effort to make our radios more flexible.
Uh, you know, James had mentioned it before about telemetry and, and adaptability. So making the, the radios more compliant, making them more flexible for different regions. And we'll talk about that here in a second.
There's a lot of fun that we're starting to have in, in building some complex technologies that are, that are inside these aps. And one of the things that you'll hear Aruba talk about is the concept of the AP as a platform. So within the ap we have a pretty strong network engine.
We have obviously lots of radios. There are IOT radios, USB ports for external devices right there, essentially an extension of your wired infrastructure that you can use for other elements. The discussion for today is gonna focus on some of the more physical layer stuff that we build into the aps, and I've got some eye candy that I'll pass around for you guys to look at.
So it'll probably keep you distracted while I'm talking for, for the, the majority of the 10 minutes when you Put this set around, you don't want to get it back, right? I do wanna get it back, please. They, they're not really operable 'cause of they're before we had the right software or the TPM.
So if you know how to install the TPM software go nuts, but otherwise it'll just About TPM reports. Well, not today, uh, not to my seven different bosses anyway. So we are building a full wifi seven platform.
Uh, we do have some really fun and interesting things coming in. Future products. This is just gonna be a taste of what we're doing.
Uh, we do have a private cellular offering that's not really related to some of the creative things we're doing with the antennas, but just showing that we're enhancing our wireless portfolio and trying to grow it for what our customer needs. So for fun, let's do it this way. Uh, one of these has the cover removed, so the antennas are actually exposed.
You can go ahead and grab 'em. Just don't try to pick it up by the antenna. This is, this is still just PCBs.
Uh, try to avoid your microphones, I'm sure. Uh, those guys over there don't want to hear the thumping outside of the gym above us. Thank you.
So, so the bigger things are actually access points. So those are radios, chip sets, things like that. Inside the smaller units that I'm gonna pass around are actually external antennas that have active elements we'll talk about at the end.
I did wanna show this one slide. We're starting to accrue some destroyed access points, which is kind of fun. Uh, this one was from a customer of ours.
Unfortunately, one of their buildings burned down and when they pulled the AP out, plugged it in, it was still working and serving clients. We have others that have been run over by forklifts and dropped from ceilings and ladders and things like that. So if you ever damage one, go ahead and, and feel free to share it with us.
So my contact info is up here if you need it. Like I said before, I'm not really gonna spend a lot of time on the complexities of the rf. It is a, it is a very interesting antenna in production.
Just be aware that the s are not gonna be clear. Those are specially made for us. So I can show you guys what's inside.
They'll, they'll be normally white. So what are we from a, from a access point perspective, what we're building in Aruba, we're focusing on, on really for me, kind of three different core concepts, right? We have the idea of these flexible radios that can do more than just a static channel or a static band of rf.
You can actually make them dual five or dual six or some combination thereof. We will talk about dynamic antennas. That's what you're looking at now, uh, for the two units, the two aps that are passing around, those both have the exact same antenna board.
There's 19 antennas total, uh, that are on that board. Believe it or not, if you can find 'em all, go ahead and count. And we'll talk about this concept of a smart antenna module.
That's not really the official marketing name, but it's something that, um, we decided to build when we started working on six gig. James said it before. Telemetry is super critical and this is one area, kind of the physical RF layer, how the AP is mounted, how it's oriented.
That's something that we have never really typically had telemetry for. And we will with the smart antenna module. When you look at this map, this is not really to kind of show off countries more than it is to show you the prevalence of what we call indoor six gigahertz versus what we can do in outdoor.
From a, from a global perspective, most all countries have pretty much permitted indoor six gig. However, from an outdoor perspective, it is much, much more sparsely approved, right? We have the US and Canada, we have a couple other countries that are in consultation, but for the most part, if I wanted to deploy any of these products you see outdoors, I can't because they're not permitted.
So from a wifi vendor perspective, it creates an interesting dilemma, right? We need to design wifi seven access points that support all the latest frequencies to sell into countries that won't allow us to operate those frequencies. So the gambit that we're taking with the seven 60, this is really the first AP we've done this with, and I think probably the first from a, from a wireless vendor perspective, is to build an access point that can do or serve at least all the different regulatory regions without a restriction.
So for the seven 60, we can deploy a traditional dual band access point. 4 and five. It also supports if you need high density, just a four by four version of five gig.
However, that map of countries that we saw that had a lot of indoor opportunity or a lot of indoor permissions, we can run these aps indoors with six gig. And because they're ruggedized, because they're temperature hardened, we can run them in warehouses, freezer facilities, uh, manufacturing floors, things like that. And then finally, when those countries do permit six gig, then you can just use whichever two of the three radios you want without necessarily having to make a hard choice on which product to deploy.
Hey Jared? Yes sir. I've got a question for you based on that, um, since the current regulations around operation of six gigahertz and outdoors require a FC, do your access points lock out outdoor, uh, wifi seven, six gigahertz operation without an A FC uh, server?
Or is it basically like we're just gonna lock it out period? It's not locked out period. We, so we, this will get a little weedy.
Um, we have what's called a downloadable regulatory table, right? It's basically what controls what the aps can do, right? It's like it's setting it for like Japan operations, correct US operation kind of thing.
So if there's an AP deployed in a country where a FC is permitted, then there is a field basically in the DRT that says this AP is allowed to do this and it can turn on these channels once it talks to the automatic frequency coordination service. If it's a country where it's not permitted, it's just blocked, we do have in that one. But there would be a cover that would actually be LPI or standard power, so long as they're both indoors.
So this is a little weedy on the RF side, there's rules around whether they can go indoors or outdoors and how those units need to be built in this case to go indoors. It can't be weatherproof, it can't be waterproof, it can't have external antennas. So this guy, if you dunked it in a bucket, is gonna fill with water pretty quick.
Uh, but we can run it as a composite device, which is what the FCC likes to call it. So it can be LPI or standard power versus this one, which is only standard power. So if you deploy this in a country where it's not permitted, the six gig is off, but you can do whatever you want with the two, four, and five And those tables are signed so that I can't go in and correct.
Get creative with it. No. Okay.
No. And in fact, if you saw the actual unencrypted DRT, it's pretty messy. It's really, even if you could edit it, I don't think I could do it right on purpose.
Alright. But thank you. So this is a picture of the antenna board.
What makes this kind of fun is that this is both an omnidirectional and a directional access point at the same time. So before when you did RF designs, you had to pick, do I need this model that does omni or I do you need this model that is directional? And sometimes we're not sure, and you can use the RF planning tools all day long, but you may not get the answer you need versus just being able to buy one sku.
Try both, figure out which antenna you need. So we do have a connector eyes version. So obviously a connector eyes AP is not gonna have a bunch of internal antennas, uh, but it will support the external antennas for it.
So use case for this kind of going through a design exercise, I have a large warehouse, I have ceilings that are sloped and they have different heights above the floor. I may have different stacks, uh, different objects that are in the building that require me to run more directional and less omni or vice versa. So with the seven 60, I can have one SKU that I deploy in a warehouse.
Those ones that you see on the inside are the LPI model, which is at the end of the table. And then from there it's all software. I can go in and reconfigure the antennas manually.
We'll have software capabilities to actually switch between the two depending on how you've deployed or what your mode is. The overarching goal, however, is to make sure that whatever access points the customers deploy, they can use all the radios inside. We don't like selling aps where one radio sits idle all the time because they're not allowed to use six gig.
So in this case, every radio can be active. Another use case we should all be familiar with. If you've ever been to Vegas and you've been to live or discover or any of the other trade shows where you've got tens of thousands of people in these indoor conference rooms, for lack of a better term, when those are empty, we don't need a lot of coverage.
But when they fill up, all of a sudden I need tons and tons of access points, right? So with the kind of the concept of the seven 60, if you wanted to grid out and install all your aps, kind of equidistant from each other across the entire floor, when it's empty, when it's under construction, you can just turn on maybe half with all omnidirectional antennas and that provides coverage for the entire facility while all the rest of the aps are off saving, hopefully electricity and power. However, when they fill up, like you can see right here, if I've got stacks of gear, say that's a stage, say that's, you know, a wall or say that's kind of resembling people density, I can go ahead and tell the system to bring up the radios that have been idle, have them all convert to directional antennas so that I properly cellularize the coverage in that room for high density as opposed to trying to design it and statically set it as a kinda like a one size fits all.
So you said that that's basically a manual change. It's not like trying right now It's very manual. Okay.
But from a software perspective, right? It's just software, right? So a lot of what we, you know, I can kind of try to pick what I think should happen.
I would like to see a lot of feedback from our customers to say, I would like to use it like this or make it programmatic through central, right? 'cause it's just a software switch to change the antenna from one to the other, right? I, I mean it, it seems like it's, if the, if the idea would be like those, the ones that are basically idle, you're conserving power, then it's, you know, just, hey, on demand.
If I know that this one is sitting in between you, I got one, two and three, two is down right now, well these two are loaded. Okay, let's, let's switch exactly Right? Very similar, if you've ever seen our green AP feature, that's kind of a load based AP activation.
But in that case, all the aps have the same antennas. We're not actually changing the physical coverage in this case. We're actually narrowing the spotlight changing from a wide beam flashlight to a narrow beam flashlight to light up smaller areas for higher density.
So to your point, the software could be smart enough to say, once I see the user density on each AP exceed 50, him and all his neighbors switch to directional, for example, Is that a fairly switch, quick switch over changeover? So, Or is it so there's nothing preventing us from making start fast, but it's, it is a regulatory thing. So for now we would have to reboot.
So it's not something that we would want to mm-hmm. It's is, yeah, you kinda be kind of dynamic but not Right. Yeah, You know, super.
And we have logic in our live upgrade, right? If you've ever messed, I don't know how many of you're strong wireless guys, but we have in our software upgrades the ability to turn APS on and off and allow them to upgrade, move clients and shift things around. So the logic is still there.
The last thing I'll talk about before I hand it off to Justin, uh, this is the smart antenna module. This is in every outdoor AP that we sell from wifi 60 up. This is a sensor that lives either in the AP or in that case you can see the little chip, uh, in the external antenna right here.
But this thing basically identifies the antenna. It carries the antenna RPE data, which is basically gain beam width, stuff like that it reports heading. So whether it's due north due west, it reports down tilt a bunch of other telemetry, right?
To, to James's point before, if I hang this AP and it's got a heading and an azimuth, I can use that for regulatory reasons. If I can get it approved by the FCC, I could use it for my users to know, hey, that AP that we put on the water tower when the storm went through all of a sudden is facing 90 degrees the other direction or is tilting down. And you would only find that out if you went and looked.
So this is an ability to get some information and we, this is something that we built before we had the software. We kind of saw this coming with six gig standard power. So when, you know we see CNX and central develop further, as you see future wifi seven, wink, wink aps come out, the SAM will be far more critical in that.
Uh, I'll go ahead and pass it over to Justin, but if you have any other questions, we'll talk in our little sidebar. So thank you guys. Alright.
Hey everyone. I'm Justin Manager covering IOT here at HP Aruba Networking. Uh, today I wanted to talk to you a little bit about, uh, IO OT and our containerization strategy on our access points.
So three really quick things I want to cover. One is just overview of IO iot. How do we approach that?
What's our strategy? I'll talk about IOT operations and how we're sort of marrying an app based approach with the WN infrastructure. And then we'll get into the containerization piece and why edge processing is a critical use case for our customers.
So really quickly, I mean, this really is the journey. Most of our customers have been on the left side of the screen, moving to the right, it's all about collapsing the parallel overlays that have kind of pro like propagated over time to allow for the access point to simply serve as that IOT gateway consolidating all of those use cases. It's probably pretty clear why we would do that, but again, it's about how we extend the access point as an iot gateway.
So a bit of a history lesson. So working kind of from left to right, uh, thinking about what Jared showed with our, I'll call it the survivor, the, it was an 11 ac, uh, wave one access point that was, went through that fire. Um, we began our journey there, right?
And that was with a USB based IOT radio, simple BLE based plugged in. Uh, and then really what we did is we expanded out use cases and capacity all the way to our wifi seven access point. So we've gone from an external, uh, IOT radio to now on many of our seven series having dual IOT radios inside of the access point itself, and now having two USB ports for the extensible use cases.
And I would say our software has come along with it as we've gone along. A core piece of the strategy is we do not try to build every IOT integration. We have a really strong partner ecosystem.
So we wanna enable those partners to actually produce integrations that our customers need and then also make it simple. I think the real c change is the bottom right portion, and that's IOT operations. So the reason I want to call that out is, you know, really before that point we had to build each new integration into the AP image.
And you can imagine that's, that's fine for five 10 integrations. But when we were north of 30 to 40 integrations across the portfolio, um, the AP image itself became larger. And the time to actually get these in our customer's hands was lengthy, sometimes upwards of 12 months, depending upon a release vehicle.
So when we released Aruba OS seven we, or OS 10, excuse me, we were really able to then decouple from the os, right? We had a four week sprint cycle that we began delivering on, and we broke everything into a cloud native microservices architecture. And that really enabled us to accelerate the development.
This picture here is really what I think is exciting and fun about iot. Iot should be fun, by the way. This is, this is not about reading a manual.
This is about experiencing, this is our app store within Central. So these integrations, these cards all represent a different integration our customers can deploy on their wireless infrastructure, right? And it crosses many boundaries.
I mean, you've got everything from electronic shelf labels that you see typically in the retail vertical onto BLE based asset tracking for either, um, uh, high high tech fab or healthcare use cases and even onto ZigBee based access control. Many of the, the locks in the venue that we're in would obviously operate over ZigBee. Those can all be, uh, coordinated through the access point.
But the real point here is that this capacity to build an app store was the important part for our customers to accelerate how quickly they were adopting IOT. This is the critical enabler that our engineering team and product put all together, which is our developer portal, right? Because you, you can't think about decoupling from your os essentially that was our release vehicle.
And now not having a way to create new integrations, the app developer portal, what it really did was allowed for us to allow partners to use a self-service model, right? This tool is interlaced with Aruba Central. So as they develop new applications, and again, this is in parallel, so no longer in a serial fashion, they can actually create those apps, right?
Simple, similar to an Apple app or Google Play store. And then what they're actually going to be doing is taking the templated based approach. We provide align for the use of container-based workloads and they can manage their own versioning and we can all obviously put that through our processes before it becomes available on the actual app, uh, store that I just showed.
But this app store is obviously how we became successful with our customers. Now, a simple topology diagram to just really talk about how this is all coming together. We talked app store, we talked developer portal, but really at the center of it all is the access point, right?
So this is where you're going to have the IOT observations, right? I mentioned we have onboard IOT radios. In addition, this is also where the edge processing can happen on the access point itself since we are serving container-based workloads as well.
And then finally, this is the connection point, right? This is where we're either connecting to an on-premise, uh, or a cloud-based, uh, endpoint. So the customers actually are going to be consuming much of their IOT infrastructure data from these third party partner portals.
But importantly too, we're providing all the metadata and visibility on every single IO OT device back in central. So that's really why I think that this is a, a, a really important piece for our customers. We do offer a VM based approach where instead of an access point serving those, those Linux-based apps, they could run an ESXI, uh, HyperV KVM hypervisor.
But I'll tell you, when we introduced the support for, especially for container-based workloads, many of our customers have just simplified their footprint. They said, why do I need additional VMs? Why can I not just use the access points?
And that's really the, the majority of our customers, uh, adoption has gone to the AP itself. Okay, got a few minutes left to talk. This is the exciting bit, I think for sure.
I wanna talk more about the architecture of how we work with our, uh, applications and then specifically talk about the container sandbox, which is an important piece. So quick kinda left to right, we're gonna jog through here. Number one, the access point itself.
Again, as I mentioned, it's that IOT observer, right? It's got the radios that here's BLE, ZigBee, USB based use cases. Data are ingested at that point.
We distribute that out. Typically, the first step is to do what's called kind of data parsing. And we typically do that decoding through a Lua based script, right?
So this is just taking a BLE based example, but we also serve ZigBee and USB based use cases as well. The Lewis script's going to classify the device. Is this, you know, a, an Aruba asset tag?
Is it a BLI out? Is it a menu? Whatever the vendor is.
So we get that classification and then we wanna parse the payload, right? There's typically data, maybe it's sensor data. Um, we wanna parse that.
We'll store it in a device table. Now critically to get into the container sandbox itself that's running, uh, on the app that's in the access point. We pass everything through the partner API think of that as sort of your cell membrane, right?
This is a, it's a, it's semi-permeable in that respect, right? So the partner API contains all the endpoints depending on if it's Bluetooth, ZigBee, USB, um, things like keep alive messages. All of this then passes through into the container, which is where those workloads happen.
Typically, the use cases are protocol translation, um, uh, I would say data enrichment of the device data and then sometimes deduplication, right? Because part of doing this edge processing is actually reducing the amount of data that we're sending to the cloud so that we can actually continue to keep more of that on premise and get the insights more quickly. The container sandbox itself, and I'll move on to the last slide before I run outta time here, is really, uh, uh, highly secured.
And so what I would say by that is the sandbox itself has very limited access, right? So we define the system resources it has access to, it's a non root user. Um, and then we also make sure that in terms of the communication, that the parameters that are set in that application define what endpoints it can connect to and also which endpoints can connect to it, right?
So it's very vari. It has the sort of least privileged, uh, user access on the ap. And then of course I listed down at the bottom just some partner API use cases across the, the diversity of the different endpoints.
But something really cool, and this would be before I just end here, kinda my call to action on the right side is our, uh, part of the GUI that I extracted from our developer portal. This happens to show where you set system resources like CPU, memory, uh, storage, and this is actually part of how our partners create an application and then assign the overall, um, resources it can use as part of the publishing process. So I would say for any of you, if you have access to Aruba Central, that you make sure to go ahead and request onboarding to the app, developer portal will enable you, and then you can begin just designing your own application.
You can test it on your own central account as well. And then at the end of the day, um, what we can do is also recre, excuse me, recommend a set of sensors that you could use for just some easy use case testing. So again, just to kind of highlight and recap before I close here, it really is about how we've brought containers onto the access points.
We've simplified the, the footprint of our customer's network. And then at the end of the day too, the edge processing provides more value and really extends that AP as a platform.