Controllerless Networks

last person joined: 2 days ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

Aruba Airwave DMZ design with instants connecting from internet

This thread has been viewed 0 times
  • 1.  Aruba Airwave DMZ design with instants connecting from internet

    Posted Jul 27, 2015 12:57 PM

    Hey guys, I am looking to deploy an Airwave server in a DMZ and then allow instant AP's to connect from the internet. Looking at the configuration it looks like I need to allow 443 inbound from the internet to allow this connection, however that also opens up mgmt login for users. Is there a way to designate a seperate mgmt interface so that I don't open it up for logins like with clearpass or configure instants to connect on a different port than 443 as some examples? Obviously I can lock down the firewall to only the source IP's of the instants but I am trying to avoid that initally for various reasons. 


    Thanks, 



  • 2.  RE: Aruba Airwave DMZ design with instants connecting from internet
    Best Answer

    Posted Jul 28, 2015 06:46 AM

    Hi,

     

    It is possible.

    We can configure a customised port in AMP server. AMP Setup->General-->"Aruba Instant Options" section you find an option to change the default port number 443 to any other port # ranges from 1000 to 65534.

    For your Ref :

    L_BCAE.tmp.PNG

    Try and let me know if you need any further help on this.



  • 3.  RE: Aruba Airwave DMZ design with instants connecting from internet

    Posted May 17, 2016 06:49 AM

    Thanks and good that we can use the diff TCP port to listen only for IAPs. How about the below scenario?

    1. Airwave on the Datacenter,

    2. Some of IAP Branch locations are connecting through WAN to reach Airwave at DC

    3. we have some of the IAP on the plain internet and want to manage using same airwave @ DC

     

    What is your recommendation?

    Can i seperate Internal IAP land External IAP listening ports?



  • 4.  RE: Aruba Airwave DMZ design with instants connecting from internet

    EMPLOYEE
    Posted May 17, 2016 07:49 AM

    Unfortunately, they can only use the same listening port.