Aruba Instant & Cloud Wi-Fi

Reply
New Contributor
Posts: 4
Registered: ‎07-18-2016

Is it possible to block VLANs / IP ranges for SSIDs using the Aruba IAP-205 VC interface?

We have 150+ Aruba IAP-205 access points in VC clusters for each site using different subnets.  We are looking to setup a guest network to only allow HTTP and HTTPS access.  I found a guide to help setup everything you will need to accomplish this.  I have the Guest SSID working but I don't want end users to be able to type in IP's of servers via HTTP / HTTPS.  

 

Granted, it takes them to a login screen for that service (content filter, spam filter, etc.) but I would rather they get nothing.

 

Here is what I currently have configured for Access in this order:

  • Allow dhcp to all destinations + log
  • Allow dns to all destinations + log
  • Allow http to all destinations + log
  • Allow https to all destinations + log 
  • Deny any to all destinations

I was hoping I could block our server's at the bottom of the list via VLANs or IP address range.  I didn't see anywhere to do this.

 

Thanks, experts.

 

 

 

 

Guru Elite
Posts: 8,460
Registered: ‎09-08-2010

Re: Is it possible to block VLANs / IP ranges for SSIDs using the Aruba IAP-205 VC interface?

When you're building your firewall policies, you should see a network and host options in the destination drop down.


Tim Cappalli | Aruba Security TME
@timcappalli | timcappalli.me | ACMX #367 / ACCX #480
New Contributor
Posts: 4
Registered: ‎07-18-2016

Re: Is it possible to block VLANs / IP ranges for SSIDs using the Aruba IAP-205 VC interface?

That was it.  Glad it was an easy solution.

 

Thanks for the help.

Search Airheads
Showing results for 
Search instead for 
Did you mean: