Controllerless Networks

last person joined: 2 days ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

IAP single SSID different roles based on AD OU membership

This thread has been viewed 2 times
  • 1.  IAP single SSID different roles based on AD OU membership

    Posted Aug 02, 2017 04:24 PM

    Implementing an IAP solution for a school district.  They want 1 SSID presented and clients to connect via 802.1x Active directory credentials. Tricky thing is I need to hand out different roles depending on their OU membership.  Not sure how in an IAP environment how I can attach the Aruba User Role to and OU.  

     

    RECAP:  

    Jim is a teacher and he connects to the SSID via his AD credentials in the STAFF OU in Active Directory. Jim would then be given the Aruba User role of Staff and given VLAN 20.

     

    Susie is a student and she connects to the same SSID as Jim via her AD credentials and she is tied to the STUDENTS OU and she would then be given the Aruba User role of STUDENT and  given VLAN 30.

     

    I know how to setup the SSID with Dynamic VLANS and tie that to roles but just not how to tie those roles to an AD OU without using Clearpass 



  • 2.  RE: IAP single SSID different roles based on AD OU membership

    EMPLOYEE
    Posted Aug 02, 2017 06:19 PM

    Which RADIUS server are you using?



  • 3.  RE: IAP single SSID different roles based on AD OU membership

    Posted Aug 02, 2017 06:54 PM
    Window RADIUS

    Sent from my iPhone


  • 4.  RE: IAP single SSID different roles based on AD OU membership

    Posted Aug 03, 2017 02:49 PM

    BUMP - any ideas? 



  • 5.  RE: IAP single SSID different roles based on AD OU membership

    EMPLOYEE
    Posted Aug 03, 2017 03:11 PM

    You have two options:

    1. Create the Aruba-User-Role VSA in your NPS server (recommended)
    2. Return a string via IETF Filter-ID and then user server derived rules on the IAP to map the filter-ID to a user role.


  • 6.  RE: IAP single SSID different roles based on AD OU membership

    Posted Aug 03, 2017 04:01 PM

    Example below.   Dynamic VLAN 
    If Aruba-User-Role  equals  KMS-STAFF assign VLAN100

     

    KMS-STAFF would be the OU in AD. 

     

    Aruba User Role.JPG



  • 7.  RE: IAP single SSID different roles based on AD OU membership

    Posted Aug 10, 2017 01:15 PM

    Any documentation on how to create the VSA in the NPS Server? 



  • 8.  RE: IAP single SSID different roles based on AD OU membership