Controllerless Networks

last person joined: 2 days ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

Instant Traffic from Guest SSID tunneled back to the Company

This thread has been viewed 2 times
  • 1.  Instant Traffic from Guest SSID tunneled back to the Company

    Posted Sep 18, 2013 05:12 AM

    Hello, i want to tunnel a Guest SSID on IAP back to the Company Controller via VPN while using Local Traffic from the Corperate SSID in the branch. So my question is how is the Guest SSID matched to the Tunnel. The Documentation is not really clear i mean. I only find a VPN Routing Table, but in this Table it is not possible to assosiate only the Guest SSID to be tunneled while the rest is bridged in branche. Is there a PDF available that explaine the Config. It seems that it works over the DHCP Config but for me the Manual is also not really clear on that.

     

    Best Regards



  • 2.  RE: Instant Traffic from Guest SSID tunneled back to the Company

    EMPLOYEE
    Posted Sep 18, 2013 08:08 AM

    Do you need captive portal for this ssid?  If not, you can use the the IAP-VPN configuration.  The IAP must be whitelisted on the controller and the controller must be running 6.2 or above.  In the 6.3 user guide, this config is detailed in Chapter 41. The instant user guide includes details on that end how to set it up.  

     

    There are multiple VPN modes you can run in.  Please read the docs (or enlist a partner/Aruba SE help) to pick the best one.  The "hooks" if you will in this design are specified in the VPN section on the IAP.  First, you select the controller VPN termination points and then the routes into corp.  If you want to tunnel ALL traffic put a 0.0.0.0/0 route in this table:

     

    800px-Rapng-iap-2.png

     

    2. Then you select DHCP server and select the mode and addressing you wish to have (L3/local modes) The VLAN ID you select here is CRUCIAL

     

    800px-Rapng-iap-9.png

     

    3. In your SSID settings, the VLAN from step #2 above is mirrored here.  That is the "hook" between the WLAN config and the VPN config and how the IAPs know to place clients into a VPN configuration.

     

    800px-Rapng-iap-12.png

     



  • 3.  RE: Instant Traffic from Guest SSID tunneled back to the Company

    Posted Sep 19, 2013 04:11 AM

    Thanks a lot.

     

    For my understanding. Its the same for all DHCP Modes. Wich Traffic is send back to the Controller is configured by the matching VLAN ID or via the VPN Routing Table?

     

    So i can use the CP on Controller or on the IAP and all other Functions like common. Only the Vlan Entry on the VPN Tab shows the AP what is sent via VPN. correct?

     

    best Regards



  • 4.  RE: Instant Traffic from Guest SSID tunneled back to the Company
    Best Answer

    EMPLOYEE
    Posted Sep 19, 2013 07:35 AM

    Yes...you specify what goes into the tunnel via the VPN routing table

     

    Yes...the VLAN entry matching on BOTH the SSID and VPN "bind" the logic together.  In terms of a CP, you can use the one on the IAP, an external URL like ClearPass, OR you might be able to use one on the controller via an untrusted port/VLAN but that would have to be tested as it is something that I would consider out of scope.



  • 5.  RE: Instant Traffic from Guest SSID tunneled back to the Company

    Posted Sep 19, 2013 08:19 AM

    One additional Question. If i have the bind between the VPN and the SSID with the Vlan, is the VPN Routing Table necessary to use or only the bind.

    Because in the Case of Guest Vlan to be send through the Tunnel i had to use destination any.... and that would be a Problem if a Corperate SSID has to be local. or if the VPN Routing Table is necessary it is only used for the Vlan that is bind?

     

    Thanks a lot



  • 6.  RE: Instant Traffic from Guest SSID tunneled back to the Company

    EMPLOYEE
    Posted Sep 19, 2013 08:21 AM
    You must define the VPN routing table.


  • 7.  RE: Instant Traffic from Guest SSID tunneled back to the Company

    Posted Sep 19, 2013 08:35 AM

    ok so is the Table then used for all Traffic from AP or only for the Traffic that is in the bind Vlan?



  • 8.  RE: Instant Traffic from Guest SSID tunneled back to the Company
    Best Answer

    EMPLOYEE
    Posted Sep 19, 2013 08:42 AM
    Only traffic on that vlan