Aruba Instant & Cloud Wi-Fi

Reply
Regular Contributor II
Posts: 201
Registered: ‎01-30-2013

IAP 205 vlan and device onboard

Hi guys,

 

with ClearPass I already done several times vlan or device tag. Meaning if a device is type android and vlan is x , I send them to a role that i created.

 

Is it possible to do that on a virtual controller without Clearpass? Devices like android and belonging to a specific vlan add a different role.

 

I read that identifying  device OS types could be only done with CPPM, but as I see that IAP VC identifies the devices, I have this dought..

 

Regards

 

Regards

 

 

Guru Elite
Posts: 7,837
Registered: ‎09-08-2010

Re: IAP 205 vlan and device onboard

Yes you can. Same setup.

Tim Cappalli | Aruba ClearPass TME
@timcappalli | ACMX #367 / ACCX #480 / ACEAP / CWSP
Regular Contributor II
Posts: 201
Registered: ‎01-30-2013

Re: IAP 205 vlan and device onboard


cappalli wrote:
Yes you can. Same setup.

But without Clearpass? Client does not have Clearpass..

Where can I tell if a device is an android and comes from vlan x goes to role A?

 

Regards

Guru Elite
Posts: 7,837
Registered: ‎09-08-2010

Re: IAP 205 vlan and device onboard

Sorry, saw "Onboard" and misunderstood. If not ClearPass, what RADIUS server are you using?

Tim Cappalli | Aruba ClearPass TME
@timcappalli | ACMX #367 / ACCX #480 / ACEAP / CWSP
Regular Contributor II
Posts: 201
Registered: ‎01-30-2013

Re: IAP 205 vlan and device onboard

Hi

 

I am just seeking information on what Radius we used at the client for config an SSID "corporate" , that uses radius users to authenticate.

 

I will brief you shortly..

Regular Contributor II
Posts: 201
Registered: ‎01-30-2013

Re: IAP 205 vlan and device onboard

Got It

 

One windows for windows authentication and a tek radius for mac authentication.

Is this scenario is it possible to choose based on device and vlan? like in Clearpass?

 

Regards

Regular Contributor II
Posts: 201
Registered: ‎01-30-2013

Re: IAP 205 vlan and device onboard

[ Edited ]

cappalli wrote:
Sorry, saw "Onboard" and misunderstood. If not ClearPass, what RADIUS server are you using?

Hi,

 

One Radius for windows authentication and a tek radius for mac authentication.

In this scenario is it possible to choose based on device and vlan? like in Clearpass?

Or the cleanner way is to have ClearPAss?

 

I also saw a document in airheads , using dhcp fingerprint, but seemed confused and not "clean".

 

Regards

 
Regular Contributor II
Posts: 201
Registered: ‎01-30-2013

Re: IAP 205 vlan and device onboard

Hi

 

Is this the wright conclusion?

 

Regards

Guru Elite
Posts: 19,964
Registered: ‎03-29-2007

Re: IAP 205 vlan and device onboard

What kind of authentication are you using?

Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Validated Reference Design Guides : http://community.arubanetworks.com/t5/Validated-Reference-Design/tkb-p/Aruba-VRDs
Regular Contributor II
Posts: 201
Registered: ‎01-30-2013

Re: IAP 205 vlan and device onboard

Hi

 

I am using 802.1x with radius server

Search Airheads
Showing results for 
Search instead for 
Did you mean: