Aruba Instant & Cloud Wi-Fi

Reply
Regular Contributor I
Posts: 237
Registered: ‎01-19-2013

IAPs with different AD Groups

Hi community,

 

I´ve a problem, we´ve 14 IAPs with 3 SSIDs.

I want to authenticate all 3 SSIDs with the same DC. (Windows 2008 R2)

 

I´ve created different (3) Groups in AD.

 

I want that the group 1 can only authenticate on the ssid 1, not ssid2 or ssid3.

group 2 only authenticate on ssid 2 not on ssid 1 and ssid3 and so on.

 

How can I make this?

Is it possible?

 

Thanks

Aruba Employee
Posts: 148
Registered: ‎11-25-2009

Re: IAPs with different AD Groups

yes with configuration of Aruba VSA and use "Aruba-ESSID" option, we can create nps policy to accomidate this. 

Vinod Kumaar AVM ACMX, ACDX
Principal Network Engineer
Customer Advocacy | Aruba Networks Inc.

Did something you read in the Community solve a problem for you? If so, click "Accept as Solution" in the bottom right hand corner of the post.
Regular Contributor I
Posts: 237
Registered: ‎01-19-2013

Re: IAPs with different AD Groups

Ok, this woks with IAPs?

 

How can I configure this? Do you haven a step by step manual or something?

Maybe you can shortly discribe the steps to configure this?

 

 

Thanks

Aruba Employee
Posts: 148
Registered: ‎11-25-2009

Re: IAPs with different AD Groups

Change in thought. the following will be much easier. 

 

Create a separate server group  and radius server config for each eSSID and the set the NAS-ID in the server group to match the eSSID. That way, you can use a standard RADIUS attribute (NAS-ID) in your IAS rules to enforce per-SSID policies. Works perfectly. The only down side would be creating multiple AAA profiles. 

Vinod Kumaar AVM ACMX, ACDX
Principal Network Engineer
Customer Advocacy | Aruba Networks Inc.

Did something you read in the Community solve a problem for you? If so, click "Accept as Solution" in the bottom right hand corner of the post.
Search Airheads
Showing results for 
Search instead for 
Did you mean: