Controller Based WLANs

 View Only
last person joined: one year ago 

APs, Controllers, VIA

How do bridge or split-tunnel users access rapconsole.arubanetworks.com after an RAP is running? 

Jul 03, 2014 01:54 PM

Product and Software: This article applies to RAP2 or RAP5 and ArubaOS 5.0 and later.

After an RAP is up running, the RAP console URL "rapconsole.arubanetworks.com" is not accessible by bridge and split-tunnel users. This URL is not accessible by these users, by default, for security reasons.

However, if the URL must be accessible even after the RAP is running, make the following configuration changes:

For a bridge user, the user role needs to be:
any any any permit
or
user any any route src-nat (at the end)
or specifically, put as the first ACL:
user localip svc-http permit


For a split-tunnel user, the user role needs to be:
user any any route src-nat (at the end)
or
user localip svc-http route src-nat (at the top)


Likewise, to block user access to rapconsole.arubanetworks.com from bridge or split-tunnel users:

user localip svc-http deny(at the top)

Statistics
0 Favorited
0 Views
0 Files
0 Shares
0 Downloads

Related Entries and Links

No Related Resource entered.